<?xml version="1.0" encoding="utf-8"?>
<Filters xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="filters.xsd">

	<!-- Version: 2024-08-20T17:29:00.000Z-1724174976 -->

<!-- ############################################################################################################### -->
<!-- Part 0001 -->
	<File Id="{FC1A65FF-C48E-1994-5361D105B6A730EA}" FilePath="*\programdata\kaspersky lab\kes*" >
		<Process Path="*kaspersky*\avp.exe" />
	</File>
	<File Id="{2F416AAC-3F26-6C33-A5DD56F20872F304}" FilePath="*\Microsoft\Group Policy\History\?????????-????-????-????-?????????????\*\Preferences\Services\*.xml" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{1FC11CBF-A4F7-2CF7-F7455EDB5B16DF51}" FilePath="?:\$extend\$deleted\????????????????????????" >
		<Process Path="*\google\chrome\application\chrome.exe" />
	</File>
	<File Id="{93F714AF-3EB3-FA53-5F9A427047D4BE3C}" FilePath="*jetbrains\webstorm*user-data*\????????-????-*.tmp" >
		<Process Path="*\google\chrome\application\chrome.exe" />
	</File>
	<File Id="{9D1E9A8A-4D7C-F795-FC58C4B08390C614}" FilePath="*appdata\roaming*microsoft*teams*cache\?_??????" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{9D44E04D-FE3A-2C98-28AFF5139C03050A}" FilePath="*appdata\roaming*microsoft*teams*local storage\leveldb\??????.ldb" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{77F83A50-9A93-B1B8-2963AA5713AFB424}" FilePath="*microsoft\teams\service worker\scriptcache\index-dir\temp-index" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E53059F2-2400-7B68-29F9CA90126F5D81}" FilePath="*microsoft\tokenbroker\cache\????????????????????????????????????????.tbres" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{64B74D42-ACBB-BB37-2BD72A6AB80A900F}" FilePath="*microsoft\teams*????????-????-*.tmp" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{1B62902F-4B79-B453-69DB970E1BC23024}" FilePath="*\local storage\leveldb\??????.ldb" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{57FB123A-4821-68E2-FF26BC3A13506F01}" FilePath="*\local storage\leveldb\??????.ldb" >
		<Process Path="*\chrome.exe" />
	</File>
	<File Id="{0CD0765F-9B41-BF08-3D843023A01A19C4}" FilePath="*\local storage\leveldb\??????.log" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{64C3C8B9-C63E-DA1C-4E25F2110AC89E6B}" FilePath="*\local storage\leveldb\??????.log" >
		<Process Path="*\chrome.exe" />
	</File>
	<File Id="{C04D2645-5AE0-BD06-617DCD2B563FF965}" FilePath="*system32\sru\sru*" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{32AD8B4B-1EBA-7C72-7E61018E067B63C3}" FilePath="*\serviceprofiles\localservice\winhttp\??????????.cache" >
		<Process Path="*system32\svchost.exe" UserSid="S-1-5-19" />
	</File>
	<File Id="{AA3E64D2-6F47-E28B-62FCBDCA6B50A6A5}" FilePath="*\servicestate\winhttpautoproxysvc\data\??????????.cache" >
		<Process Path="*system32\svchost.exe" UserSid="S-1-5-19" />
	</File>
	<File Id="{9C0DC8C0-B7E7-2AE5-21A521795F461C12}" FilePath="*appdata\local\temp\????????-????-????-????-????????????\*\*.dll.mui" >
		<Process Path="*system32\cleanmgr.exe" />
	</File>
	<File Id="{A7B8A443-581C-BECC-04E277E9DAD4C911}" FilePath="*\microsoft\internet explorer\recovery\high\active\{*-journal" >
		<Process Path="*\Internet Explorer\iexplore.exe" />
	</File>
	<File Id="{AE83B302-A01E-DEFC-1ED4E7F58A2A151D}" FilePath="*\microsoft\internet explorer\recovery\high\active\*{????????-????-????-????-????????????*" >
		<Process Path="*\Internet Explorer\iexplore.exe" />
	</File>
	<File Id="{68AB219A-F8F2-D462-775E5047E22A2F56}" FilePath="*\microsoft\windows\cookies\????????.txt" >
		<Process Path="*\Internet Explorer\iexplore.exe" />
	</File>
	<File Id="{593DEF15-F403-9B10-3D78F0220AA5B8EE}" FilePath="*\microsoft\windows\temporary internet files\content.ie5\????????\*.gif" >
		<Process Path="*\Internet Explorer\iexplore.exe" />
	</File>
	<File Id="{FB960104-8BFF-F48B-AFB6897556868CEC}" FilePath="*\microsoft\windows\temporary internet files\content.ie5\????????\*.png" >
		<Process Path="*\Internet Explorer\iexplore.exe" />
	</File>
	<File Id="{78BC4BF5-DD08-B851-434D5C7BD8846888}" FilePath="*\microsoft\windows\temporary internet files\content.ie5\????????\*.js" >
		<Process Path="*\Internet Explorer\iexplore.exe" />
	</File>
	<File Id="{D7F4DFFA-A7E2-69EF-31965537848ADF85}" FilePath="*\microsoft\windows\temporary internet files\content.ie5\????????\*.jpg" >
		<Process Path="*\Internet Explorer\iexplore.exe" />
	</File>
	<File Id="{75954313-89CD-DD5A-B2D7E227D9E3E91B}" FilePath="*\microsoft\windows\temporary internet files\content.ie5\????????\*.css" >
		<Process Path="*\Internet Explorer\iexplore.exe" />
	</File>
	<File Id="{1004D3C0-27BA-A19C-8FCAE48E965F2334}" FilePath="*\microsoft\windows\temporary internet files\content.ie5\????????\*.txt" >
		<Process Path="*\Internet Explorer\iexplore.exe" />
	</File>
	<File Id="{D5D942A5-C937-95FF-B1DDE87AC39C9A9D}" FilePath="*\microsoft\cryptneturlcache\*\????????????????????????????????_????????????????????????????????" >
		<Process Path="*\Internet Explorer\iexplore.exe" />
	</File>
	<File Id="{CE8AAE18-A891-3355-48C9CF942CF64DB1}" FilePath="*appdata\roaming\code\backups\????????????????????????????????\file\????????????????????????????????" >
		<Process Path="*\microsoft vs code\code.exe" />
	</File>
	<File Id="{A5407581-A049-9D03-F4D3D4FB346E4D4E}" FilePath="*appdata\roaming\code\backups\?????????????\file\????????????????????????????????" >
		<Process Path="*\microsoft vs code\code.exe" />
	</File>
	<File Id="{8FB238F9-BBC6-490D-33D41FCC2117FD1C}" FilePath="*\net_ioctl\translations\einit\src\security.cfg.in" >
		<Process Path="*\microsoft vs code\code.exe" />
	</File>
	<File Id="{B9DE6585-547B-B25C-2882CEC8E2AFD592}" FilePath="*\net_ioctl\translations\einit\cmakelists.txt" >
		<Process Path="*\microsoft vs code\code.exe" />
	</File>
	<File Id="{E4603814-4275-4007-CA5268794230B977}" FilePath="*\net_ioctl\translations\client\src\client.c" >
		<Process Path="*\microsoft vs code\code.exe" />
	</File>
	<File Id="{B7A1D85A-0FBF-5A7C-D5353831A445534F}" FilePath="*appdata\roaming\code\rapid_render.json" >
		<Process Path="*\microsoft vs code\code.exe" />
	</File>
	<File Id="{7DB12DEB-9FCE-4BC1-E9786FDABA98B692}" FilePath="*appdata\local\temp\appinsights-nodeaif-????????-????-????-????-????????????\*.json" >
		<Process Path="*\microsoft vs code\code.exe" />
	</File>
	<File Id="{087F5B7D-61EE-508A-03DDC9B6A01C229C}" FilePath="*appdata\roaming\code\logs\*.log" >
		<Process Path="*\microsoft vs code\code.exe" />
	</File>
	<File Id="{0AD41238-E488-0202-632EA8999619AC71}" FilePath="*appdata\local\temp\aria-debug-*.log" >
		<Process Path="*appdata\local\microsoft\onedrive\onedrivestandaloneupdater.exe" />
	</File>
	<File Id="{6256708E-1C6B-72EF-E0D9633962BD5996}" FilePath="*\programdata\regid*\regid*.swidtag" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{ED4586E2-E25C-29BA-197267E5BA68BB20}" FilePath="*appdata\local\microsoft\group policy\history\{*" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{850D6ED9-C92D-01D2-5B21D37366F832C5}" FilePath="*\programdata\kasperskylab\adminkit\data\*" >
		<Process Path="*\kaspersky lab\networkagent\up2date.exe" />
	</File>
	<File Id="{E291741E-8095-A9C3-F57E9AFCB5745A66}" FilePath="*appdata\local\microsoft\windows\inetcache\low\ie\????????\getsessionstatus*.json" >
		<Process Path="*\Internet Explorer\iexplore.exe" />
	</File>
	<File Id="{2FE52B9F-8351-0925-CC39C3E9F91DE8E0}" FilePath="*appdata\local\microsoft\windows\inetcache\ie\????????\index*.htm*" >
		<Process Path="*\sdl\sdl passolo\*\psl.exe" />
	</File>
	<File Id="{52B06F96-4606-65D2-1F10F3091BB21F78}" FilePath="*\projects\tms\web\development\web-terminal\web-client\src\app\shared\global\tree-grid\data-sources\local\local-data-source-default-filter.ts" >
		<Process Path="*\microsoft vs code\code.exe" />
	</File>
	<File Id="{A6FB80B1-CE9A-2753-3B5AB3BA7D22D677}" FilePath="*appdata\local\temp\vscode-chrome-debug-userdatadir_????\default\code cache\js\????????????????_?" >
		<Process Path="*\google\chrome\application\chrome.exe" />
	</File>
	<File Id="{223B74CB-D7B8-2710-16DC6E8629D4F95B}" FilePath="*\favorites\global it servicedesk.url" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{7C323750-07EB-622F-3760B0B195BA70BE}" FilePath="*appdata\local\packages\microsoft.*" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6C32375F-F7EA-522E-2760B0B195BA70BD}" FilePath="*appdata\local\packages\microsoft.*" >
		<Process Path="*\windowsapps\microsoft.windowscommunicationsapps_*\hxtsr.exe" />
	</File>
	<File Id="{3FD31E46-4DA8-8D20-3DA1C612257034D1}" FilePath="*appdata\local\packages\microsoft.*" >
		<Process Path="*\windowsapps\microsoft.office.onenote_*\onenoteim.exe" />
	</File>
	<File Id="{FEDD1F1B-723E-3180-8E996370DB911B87}" FilePath="*appdata\local\temp\??????.png" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E005793C-0657-511D-A2AF05F45D6F868D}" FilePath="*appdata\local\microsoft\windows\inetcache\ie\????????\macro-icon*.png" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{D7D159B2-9B6A-3185-AC1A3CF610F64896}" FilePath="*\programdata\microsoft\group policy\history\{*" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{92ECBCC2-1C24-21D5-7A1812A7AD58E3A6}" FilePath="*\windows\security\templates\policies\tmp?????.inf" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{8A408035-5E30-2BC9-76E715FBA121C4BE}" FilePath="*\windows\security\audit\audit.csv" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{817B5644-E8D4-CB26-3FB2733C5D1CA6D9}" FilePath="*\postgresql\??\data\pg_stat_tmp\global.tmp" >
		<Process Path="*\postgresql\??\bin\postgres.exe" />
	</File>
	<File Id="{900EFF55-403B-3F24-1BD07C6D3B8072AD}" FilePath="*\postgresql\??\data\pg_stat_tmp\db_?.tmp" >
		<Process Path="*\postgresql\??\bin\postgres.exe" />
	</File>
	<File Id="{C3B62B9B-8BA5-560C-92934A10C9BDD156}" FilePath="*programdata\microsoft\windows\devicemetadatacache\????.idx" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{525ADE5D-16C3-0B01-6BCF639F88898580}" FilePath="*appdata\local\temp\vscode-chrome-debug-userdatadir_*\default\cache\?_??????" >
		<Process Path="*\google\chrome\application\chrome.exe" />
	</File>
	<File Id="{8B3438E7-77C4-0F07-F37C94F9A1F55820}" FilePath="*appdata\roaming\mozilla\firefox\profiles\*\datareporting\aborted-session-ping" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{E206331C-5B3E-E3A2-896D0F60BFEC67BD}" FilePath="*\local\mozilla\firefox\profiles\*\cache2\entries\????????????????????????????????????????" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{C92B1BAF-7522-CA01-54DA64CD0B2FA095}" FilePath="*\local\mozilla\firefox\profiles\*\safebrowsing-updating\*.metadata" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{5258E7EC-7328-1BE6-C87720EE25646C6B}" FilePath="*\local\mozilla\firefox\profiles\*\safebrowsing-updating\*.vlpset" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{E1FE0459-43F6-7EB6-134FCB62BF0B9525}" FilePath="*\local\mozilla\firefox\profiles\*\safebrowsing-updating\*.sbstore" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{043A0DE6-E5B9-2817-7104FB892C128168}" FilePath="*\roaming\mozilla\firefox\profiles\*\weave\*.json" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{539D4603-1D4E-638A-A34852AB86BD5D46}" FilePath="*appdata\local\microsoft\windows\caches\{????????-????-????-????-*" >
		<Process Path="*\windows\explorer.exe" />
	</File>
	<File Id="{0E71ED36-D67E-C6B9-2D58BEC72D45F0A5}" FilePath="*appdata\roaming\microsoft\office\recent\2020-04.docx.lnk" >
		<Process Path="*\microsoft office\office??\winword.exe" />
	</File>
	<File Id="{6CC5C5BD-1F90-6A2F-AD2F8D0054413AD2}" FilePath="*appdata\roaming\microsoft\windows\recent\src.lnk" >
		<Process Path="*\windows\explorer.exe" />
	</File>
	<File Id="{F231A558-45B9-1646-0F533CF5B2735277}" FilePath="*appdata\roaming\microsoft\windows\recent\cmakelists.lnk" >
		<Process Path="*\windows\explorer.exe" />
	</File>
	<File Id="{E9D134D8-3805-BD79-F4F9BB253DE36AB1}" FilePath="*appdata\roaming*microsoft*teams*tmp\x??.json*" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{9F309040-037D-99AE-D61147F6A1F47619}" FilePath="*\roaming*microsoft*teams*indexeddb\https_teams.microsoft.com_?.indexeddb.leveldb\??????.ldb" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{7BE708BF-3479-2F67-776435EB887D79C0}" FilePath="*\$recycle.bin\s-?-?-??-??????????-??????????-??????????-??????\$i??????.htm" >
		<Process Path="*\totalcmd\totalcmd.exe" />
	</File>
	<File Id="{0D689BA5-72EC-8CEF-8356006CE50A98E5}" FilePath="*\aiconverter2.0\ai-help\kesl\*" >
		<Process Path="*\totalcmd\totalcmd.exe" />
	</File>
	<File Id="{E97096D3-5658-EE35-F1FAA182B9A83D7B}" FilePath="*programdata\microsoft\windows\wer\temp\wer*.tmp*" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D1010762-FBDC-DCE6-5DA120377C4009A4}" FilePath="*\programdata\usoshared\logs\system\notificationuxbroker.????????-????-????-????-????????????.?.etl" >
		<Process Path="*\windows\system32\musnotification.exe" />
	</File>
	<File Id="{EE2235EF-1D33-17ED-AC258E5E48EF4754}" FilePath="*\programdata\usoshared\logs\system\usocoreworker.????????-????-????-????-????????????.?.etl" >
		<Process Path="*\windows\system32\usocoreworker.exe" />
	</File>
	<File Id="{2BEFC48B-5C84-A181-6546A466EAAB714D}" FilePath="*\local\microsoft\windows\actioncentercache\microsoft-office-outlook-exe-??_?????_?.png" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{4B24DB68-6282-238B-26B4E3D8B7FADA48}" FilePath="*appdata\local\temp\*.???.zip" >
		<Process Path="*\sdl\sdl trados studio\studio?\sdltradosstudio.exe" />
	</File>
	<File Id="{C39FAA2D-D4E2-0B4F-FD3C418FBF0203DA}" FilePath="*appdata\local\temp\*.???.htm" >
		<Process Path="*\sdl\sdl trados studio\studio?\sdltradosstudio.exe" />
	</File>
	<File Id="{4E3163EC-309C-F11B-CBB98526E89D0686}" FilePath="*\??-??\*.htm" >
		<Process Path="*\sdl\sdl trados studio\studio?\sdltradosstudio.exe" />
	</File>
	<File Id="{ACE1FF9A-A704-13BC-BD53DD36CC6F1A15}" FilePath="*appdata\local\temp\tmp????\????????-????-????-????-????????????.htm" >
		<Process Path="*\sdl\sdl trados studio\studio?\sdltradosstudio.exe" />
	</File>
	<File Id="{09BAADF3-084C-1B4E-C7C3AA6B5580E19C}" FilePath="*appdata\local\temp\*\ksn\*.kvdb" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" />
	</File>
	<File Id="{E1C47F3E-F819-81EC-03CFDAA7845812B2}" FilePath="*appdata\roaming\notepad++\backup\*" >
		<Process Path="*\notepad++\notepad++.exe" />
	</File>
	<File Id="{7B82E8D3-3360-10E4-69794525433E8651}" FilePath="*appdata\roaming\telegram desktop\tdata\user_data\cache\*" >
		<Process Path="*appdata\roaming\telegram desktop\telegram.exe" />
	</File>
	<File Id="{A4499509-5D7D-4C0A-B89CB788E2BA4246}" FilePath="*appdata\roaming\telegram desktop\tdata\user_data\media_cache\*" >
		<Process Path="*appdata\roaming\telegram desktop\telegram.exe" />
	</File>
	<File Id="{CF44C128-F0DF-2172-FBCDA08AF398A585}" FilePath="*\windows\ccm\logs\*.log" >
		<Process Path="*\windows\ccm\ccmexec.exe" />
	</File>
	<File Id="{458AD3B1-566E-F375-746146F853D4C5B8}" FilePath="*\firefoxportable\data\profile\cache2\doomed\*" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" />
	</File>
	<File Id="{C5ACCE44-16E6-E506-D3B844777C3A16B2}" FilePath="*\tfs\*" >
		<Process Path="*\microsoft visual studio\????\teamexplorer\common?\ide\devenv.exe" />
	</File>
	<File Id="{78524CFC-2349-7AE5-A277FDFF7DF99084}" FilePath="*programdata\microsoft\windows\apprepository\staterepository-*.srd-wal" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{49B4389D-8565-D80A-C1FFB73A017E535B}" FilePath="*programdata\microsoft\windows\apprepository\????????-????-????-????-????????????_s-*.rslc" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{59F87148-B365-FF54-9074B6127ADEE527}" FilePath="*appdata\local\packages\microsoft.windows.cortana_*\localstate\constraintindex\apps_*" >
		<Process Path="*\systemapps\microsoft.windows.cortana_*\searchui.exe" />
	</File>
	<File Id="{5BDCAC80-928A-47BF-AABC0EECF873416E}" FilePath="*appdata\roaming\microsoft\skype for desktop\local storage\leveldb\*.ldb" >
		<Process Path="*\microsoft\skype for desktop\skype.exe" />
	</File>
	<File Id="{A7EE0111-E0FA-6BFF-BF37280111F615E4}" FilePath="*\windows\serviceprofiles\localservice\winhttp\?????????.cache" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{8E2D4734-CBF1-5629-EAAC03FAA2A44F8D}" FilePath="*\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\deliveryoptimization\cache\*.pieceshash" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{66FD0A5A-C58C-1D5C-AA61FAA69D6F2828}" FilePath="*\windows\servicestate\winhttpautoproxysvc\data\*.cache" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{556341A4-A6E7-2138-DCDC3F1BD50A07FD}" FilePath="*\windows\softwaredistribution\eventcache.v*\{*" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{E15A6500-0F2E-9B52-2B4A3F651B10451C}" FilePath="*\windows\system32\config\systemprofile\appdata\local\microsoft\installagent\checkpoints\*.dat" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{DCC20A9A-E8BF-ABC0-46CF07F014588C02}" FilePath="*\outlook logging\prof_*.txt" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{10FC6164-6183-7E5E-0782686E26608CB5}" FilePath="*\local\microsoft\onedrive\setup\logs\standaloneupdate_*.log" >
		<Process Path="*appdata\local\microsoft\onedrive\onedrivestandaloneupdater.exe" />
	</File>
	<File Id="{0983F19B-4EF1-4D97-1DFD790808A80D58}" FilePath="*\programdata\kasperskylab\adminkit\data\log\$*.log" >
		<Process Path="*\Program Files (x86)\kaspersky lab\networkagent\up2date.exe" />
	</File>
	<File Id="{3C487ACD-15D6-FAC0-8D9EB1E7536C31F4}" FilePath="*\programdata\kasperskylab\adminkit\data\.updater\~.upd_temp\temporaryfolder\updates\*.xml" >
		<Process Path="*\Program Files (x86)\kaspersky lab\networkagent\up2date.exe" />
	</File>
	<File Id="{D62631FB-4F5D-AAF2-E70C2716B15B813C}" FilePath="*appdata\local\packages\microsoft.windowscommunicationsapps_?????????????\localstate\hxcommalwaysonlog.etl" >
		<Process Path="*\Program Files\windowsapps\microsoft.windowscommunicationsapps_*\hxtsr.exe" />
	</File>
	<File Id="{A24DBB21-EE70-70AE-F54E02DB3FA2A7E9}" FilePath="*appdata\local\packages\microsoft.office.onenote_?????????????\localstate\appdata\local\onenote\??.?\masterindex\master.db-journal" >
		<Process Path="*\Program Files\windowsapps\microsoft.office.onenote_*\onenoteim.exe" />
	</File>
	<File Id="{944E929E-FB23-65AA-90E7DB62E3413FB9}" FilePath="*appdata\local\temp\*.png" >
		<Process Path="*\Program Files\microsoft office\office??\outlook.exe" />
	</File>
	<File Id="{CDC87740-A03A-95A9-3BEF59562A7E3536}" FilePath="*appdata\local\microsoft\windows\inetcache\ie\????????\macro-icon*.png" >
		<Process Path="*\Program Files\microsoft office\office??\outlook.exe" />
	</File>
	<File Id="{F4E0CB3D-2FB9-14A6-AD42FF17FCA409B1}" FilePath="*appdata\local\microsoft\outlook\~*.ost.tmp" >
		<Process Path="*\Program Files\microsoft office\office??\outlook.exe" />
	</File>
	<File Id="{C3057662-CB34-6E5B-EFB8B3277C2B08E1}" FilePath="*\windows\security\templates\policies\gpt?????.dom" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{8A0E312C-0C14-CCD4-5315B072E9F05B88}" FilePath="*\windows\security\templates\policies\gpt?????.inf" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{36E405D9-6A83-AFD6-8F7F6C67C68E4B87}" FilePath="*\Program Files\postgresql\??\data\pg_stat_tmp\global.tmp" >
		<Process Path="*\Program Files\postgresql\??\bin\postgres.exe" />
	</File>
	<File Id="{30CF4B9F-0216-FAC7-E5432E07E0C9C9D4}" FilePath="*\Program Files\postgresql\??\data\pg_stat_tmp\db_?.tmp" >
		<Process Path="*\Program Files\postgresql\??\bin\postgres.exe" />
	</File>
	<File Id="{BC3FD61D-36D7-E68F-C6BFD4BE6094995A}" FilePath="*\local\mozilla\firefox\profiles\*\safebrowsing-updating\*\*.metadata" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{A1E50148-3FD5-1ADF-ED3D10F449E8C66A}" FilePath="*\local\mozilla\firefox\profiles\*\safebrowsing-updating\*\*.vlpset" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{7D64BA4A-A181-B26B-4F8546FE056F5569}" FilePath="*\local\mozilla\firefox\profiles\*\safebrowsing-updating\*\*.sbstore" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{22858CD1-9BB0-B184-8544C41959600169}" FilePath="*appdata\roaming\microsoft\office\recent\2020-04.docx.lnk" >
		<Process Path="*\Program Files (x86)\microsoft office\office??\winword.exe" />
	</File>
	<File Id="{CEAD5AD4-E669-EBA0-9580BE8BD1BD7F0B}" FilePath="*appdata\local\temp\*\ksn\*.kvdb" >
		<Process Path="*\Program Files (x86)\kaspersky lab\networkagent\ksnproxy.exe" />
	</File>
	<File Id="{5A369F63-9776-845D-A73B2A57BE9C3673}" FilePath="*appdata\roaming\notepad\backup\*" >
		<Process Path="*\notepad\notepad.exe" />
	</File>
	<File Id="{DEEBF5E1-ADC8-6DDA-36E89CE796D168AE}" FilePath="*appdata\roaming\telegram desktop\tdata\*" >
		<Process Path="*appdata\roaming\telegram desktop\telegram.exe" />
	</File>
	<File Id="{39D23AEA-5AEC-7860-34A68A6FEFBE2723}" FilePath="*\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\deliveryoptimization\cache\*\*.pieceshash" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{01C0ED20-77D9-F98F-2547FA79D243D7C2}" FilePath="*\windows\softwaredistribution\eventcache.v2\{*" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{9D145CE7-3750-6E10-DD52ED205BD715A9}" FilePath="?:\aiconverter2.0\*" />
	<File Id="{BED1C3AD-FE4C-C227-FC49C50503D9B60A}" FilePath="?:\auto\monorepo\*" >
		<Process Path="*\git\mingw32\bin\git.exe" />
	</File>
	<File Id="{8DE92DFD-5EE2-7A53-92AB14CC213B913D}" FilePath="*\config.msi\*.rbf" >
		<Process Path="*\windows\system32\msiexec.exe" />
	</File>
	<File Id="{CF454CE0-7EC5-FF86-19965DD3394F65CE}" FilePath="?:\git\*" >
		<Process Path="*git.exe" />
	</File>
	<File Id="{0D452BDD-B6C4-CE3F-46BAFC8F61B2ED25}" FilePath="?:\kl\doc\*" >
		<Process Path="*\Windows\explorer.exe" />
	</File>
	<File Id="{97565704-D442-6A53-1B9569F323E50F38}" FilePath="?:\monorepo\*" />
	<File Id="{9F06E5F9-9D28-BD23-487407584480AE7C}" FilePath="*\monorepo*" >
		<Process Path="*\git.exe" />
	</File>
	<File Id="{41271EEF-D6AB-5C8F-CAE940E2FBA81C82}" FilePath="*\monorepo*" >
		<Process Path="*\devenv.exe" />
	</File>
	<File Id="{72929844-5A65-5C18-2FFA9CC641F9BAED}" FilePath="*\monorepo*" >
		<Process Path="*\link.exe" />
	</File>
	<File Id="{6971857A-4993-9624-FCA08805362729E7}" FilePath="*\monorepo*" >
		<Process Path="*\cl.exe" />
	</File>
	<File Id="{007B14A6-6573-6868-2D637C595C0725E5}" FilePath="*\.git\*" >
		<Process Path="*git.exe" />
	</File>
	<File Id="{751FC8E1-677B-0F92-A8A003478831BE40}" FilePath="*\.git\*" >
		<Process Path="*devenv.exe" />
	</File>
	<File Id="{2A4A74EA-4C5C-6A81-FA06019F07E67820}" FilePath="*\resharper_cache\*" >
		<Process Path="*ide\devenv.exe" />
	</File>
	<File Id="{EEB95E01-02D5-DD58-92E6488C25DC8EFF}" FilePath="*\common files\merge modules\microsoft_*.msm" >
		<Process Path="*\windows\system32\msiexec.exe" />
	</File>
	<File Id="{BF89577A-A619-4310-37B51DBC09B565BC}" FilePath="*\common files\microsoft shared\msenv\publicassemblies\*.xml" >
		<Process Path="*\Windows\System32\msiexec.exe" />
	</File>
	<File Id="{49A5171B-9285-88A6-57866FF4F79A98C4}" FilePath="*\google\chrome\temp\source_*\chrome-bin\*" />
	<File Id="{EF121741-3272-2E5B-855721FA2BFD196D}" FilePath="*\Program Files*\kaspersky lab\*" />
	<File Id="{5A4A604B-E32D-8E40-07E2844ADA6CB53A}" FilePath="*\microsoft sdks\windows\v8.0a\bootstrapper\packages\*.rtf" />
	<File Id="{F825A213-2568-DEA1-2E298BF0BC80D5D2}" FilePath="*\microsoft sdks\windows\v8.0a\bootstrapper\packages\*.xml" />
	<File Id="{90CC26C5-A882-CCEC-FDF3474676CF9B70}" FilePath="*\microsoft visual studio *.0\*" />
	<File Id="{34392070-FCBD-4BC0-73E22AD52BEE89D4}" FilePath="*\edgeupdate\download\{*" />
	<File Id="{280A0CA0-6AAB-A677-EE2A672ACBDF48B6}" FilePath="*\msbuild\*" />
	<File Id="{E6424671-DA16-8965-C49C0231FA5AA398}" FilePath="*\reference assemblies\microsoft\framework\*.xml" />
	<File Id="{FA3041DC-F63C-E3DC-C3CB40D4D2E5F6D6}" FilePath="*\windows kits\*" />
	<File Id="{13114DC9-38C9-3408-77F4D58E89B10DB5}" FilePath="*\Program Files\windowsapps\microsoft.*" />
	<File Id="{F6DCD507-8EF8-CD03-B59E46E9F4D4B7A4}" FilePath="*\programdata\microsoft\search\data\applications\windows\*.jtx" >
		<Process Path="*\windows\system32\searchindexer.exe" />
	</File>
	<File Id="{82103806-4D52-427E-FBDADF11D649C170}" FilePath="*programdata\microsoft\windows\apprepository\*" >
		<Process Path="*\Windows\System32\svchost.exe" />
	</File>
	<File Id="{F9334B8F-277B-3EC0-87F0101079F30EF3}" FilePath="*programdata\microsoft\windows defender\scans\history\*" >
		<Process Path="*\msmpeng.exe" />
	</File>
	<File Id="{13BAD9A7-7E0E-0AB1-142BCBDEBBA10AE1}" FilePath="*\programdata\pcdr\*\logs\systemidlecheck_*.log" >
		<Process Path="*\systemidlecheck.exe" />
	</File>
	<File Id="{2C54F6F6-A2B1-9671-9D48A22400AC3125}" FilePath="*\programdata\usoshared\logs\*.etl" >
		<Process Path="*\windows\system32\musnotification.exe" />
	</File>
	<File Id="{ADE6CF10-54BF-55B5-B256601EB43D02D1}" FilePath="*\programdata\usoshared\logs\*\*.etl" >
		<Process Path="*\windows\system32\musnotification.exe" />
	</File>
	<File Id="{74A61BAF-4756-554D-DDED6318D05F2C58}" FilePath="*\projects\tms\web\development\*" >
		<Process CmdLine="*yarn.js*" />
	</File>
	<File Id="{6DCEAA5E-04EC-0465-2A9CD9E09E64236F}" FilePath="*\publishingresults\*.htm" />
	<File Id="{954622EB-5A26-4B8D-CD6E4B7EC5295250}" FilePath="*\resipotory\product\test\mocks\*" >
		<Process Path="*\candle.exe" />
	</File>
	<File Id="{4D9972F9-6269-AC31-72FE23303FE0282F}" FilePath="*\sandbox\bin\*" >
		<Process Path="*\link.exe" />
	</File>
	<File Id="{F9D21DED-D007-0D02-F642FC935DC5BBB4}" FilePath="*\sandbox\bin\*" >
		<Process Path="*\cl.exe" />
	</File>
	<File Id="{20D1CC4E-E741-1E45-31E701423FE52717}" FilePath="*\sandbox\kata\*" >
		<Process Path="*\link.exe" />
	</File>
	<File Id="{90E1335E-06A8-4F17-0E0FEAFBF93B9FB1}" FilePath="*\sandbox\kata\*" >
		<Process Path="*\cl.exe" />
	</File>
	<File Id="{92A20083-E527-339E-30575B38CA41C021}" FilePath="*\sandbox\monorepo\*" >
		<Process Path="*\link.exe" />
	</File>
	<File Id="{089A573A-32B0-25DC-C83CF9720F2FED89}" FilePath="*\sandbox\monorepo\*" >
		<Process Path="*\cl.exe" />
	</File>
	<File Id="{73D1A08B-C6A2-4E42-0630B6A5FD893C8F}" FilePath="*\.pycharmce2019.1\system\log\*.txt" >
		<Process Path="*\pycharm??.exe" />
	</File>
	<File Id="{1686BCFF-7447-EF2B-6673341FB9A33A72}" FilePath="*\system\resharper-host\local\transient\resharperhost\*" >
		<Process Path="*\jetbrains.resharper.host64.exe" />
	</File>
	<File Id="{C8677FBF-BF9F-78BB-E1ECBA83360C910B}" FilePath="*\system\vcs-log\index\*" />
	<File Id="{59B6299B-2892-DA97-9C14B4F50EA1D854}" FilePath="*\git_sparse\product\test\corporate\endpoint\framework\emulation\disks\bin\framework\*" >
		<Process Path="*\msbuild.exe" />
	</File>
	<File Id="{340C3CA5-3E4C-91A9-33091011D5EEEAA8}" FilePath="*\jetbrains\transient\resharperplatform*" >
		<Process Path="*\ide\devenv.exe" />
	</File>
	<File Id="{2331EA03-2E3E-77CA-F5B6302FF1D2622A}" FilePath="*\local\microsoft\onedrive\logs\personal\*" >
		<Process Path="*appdata\Local\Microsoft\OneDrive\OneDrive.exe" />
	</File>
	<File Id="{DA5D421D-B2B8-12A4-909756C69E6A370B}" FilePath="*\local\microsoft\squirreltemp\temp*" >
		<Process Path="*teams*update*" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{D0BE580A-2521-885F-C4BF15C6FA6990CC}" FilePath="*\local*microsoft*teams*stage\*" >
		<Process Path="*teams*update*" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{5600E300-6E62-252A-7A7893E8174492EE}" FilePath="*appdata\local\microsoft\azure devops\*" >
		<Process Path="*\tasklist.exe" />
	</File>
	<File Id="{6A7EB118-51B1-D748-93506B1C0540EB41}" FilePath="*\microsoft\windows\explorer\iconcache_*" >
		<Process Path="*\explorer.exe" />
	</File>
	<File Id="{10F96C1B-A0DA-C26B-DD395B3B17C5C5C3}" FilePath="*\microsoft\windows\explorer\iconcache_*" >
		<Process Path="*\clearnmgr.exe" />
	</File>
	<File Id="{591789C7-F96C-09DB-CA8ED006FED904C1}" FilePath="*\local\temp\{*" >
		<Process Path="*\cl.exe" />
	</File>
	<File Id="{4DAFD99B-B468-1EEC-F430BDEAA861D597}" FilePath="*\local\temp\_cl_*" >
		<Process Path="*\cl.exe" />
	</File>
	<File Id="{8A9DA3C2-B86C-9B7A-FD0E5A3B523CF61B}" FilePath="*\local\temp\*\compile_commands.json" >
		<Process Path="*\ide\devenv.exe" />
	</File>
	<File Id="{D3B36B52-F48E-A92A-8BB2F8A67CD80D44}" FilePath="*\roaming\microsoft\windows\cookies\*.txt" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{0489C80B-C6A3-F151-9E5C3C90FBF77F97}" FilePath="*appdata\local\jetbrains\plugins\jetbrains.externalannotations*" >
		<Process Path="*\ide\devenv.exe" />
	</File>
	<File Id="{00BB3E8A-32B9-5FD7-055211DB45E9DD16}" FilePath="*\local\microsoft\office\*\webservicecache\allusers\odc.officeapps.live.com\*" >
		<Process Path="*\Microsoft Office\root\*\*.exe" />
	</File>
	<File Id="{6AA0E28A-9BD6-C66F-4C2D656EE79B45AF}" FilePath="*appdata\local\microsoft\typescript\*" >
		<Process Path="*\program files\nodejs\*" />
	</File>
	<File Id="{475B5C10-114A-1408-73ED525A496E2E0D}" FilePath="*appdata\local\microsoft\visualstudio\*" >
		<Process Path="*\ide\devenv.exe" />
	</File>
	<File Id="{4FC6B3BF-BDD7-558E-B42BDEFC453E8524}" FilePath="*appdata\local\microsoft\windows\actioncentercache\microsoft-explorer-notification*" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{3EFFBC73-6526-C212-2B2D227FFD6DB39B}" FilePath="*appdata\local\microsoft\windows\actioncentercache\microsoft-office-outlook-exe*" >
		<Process Path="*system32\svchost.exe" />
	</File>
	<File Id="{B5CEF6B2-3BDD-D74E-ACB26D2D94427D46}" FilePath="*appdata\local\microsoft\windows\explorer\iconcache_*.db" >
		<Process Path="*\windows\explorer.exe" />
	</File>
	<File Id="{C9BC21F7-3CAF-7F74-3B376BD6B75A98AA}" FilePath="*appdata\local\microsoft\windows\explorer\iconcachetodelete\*.tmp" >
		<Process Path="*\windows\explorer.exe" />
	</File>
	<File Id="{1DEDB4B4-5DFE-D1C0-AEDCD31F5089910F}" FilePath="*appdata\local\microsoft\windows\inetcache\ie\*" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{B46C9894-819E-1ED6-4F8803BFA9A961B4}" FilePath="*appdata\local\microsoft\windows\inetcache\ie\*" >
		<Process Path="*\Internet Explorer\iexplore.exe" />
	</File>
	<File Id="{69646297-D94A-87D7-F929362734312F41}" FilePath="*appdata\local\microsoft\windows\inetcookies\*" >
		<Process Path="*\windows\system32\searchprotocolhost.exe" />
	</File>
	<File Id="{E987697C-A30B-0A0E-5F3216E77DB3178C}" FilePath="*appdata\local\microsoft\windows\temporary internet files\*" >
		<Process Path="*\windows\system32\searchprotocolhost.exe" />
	</File>
	<File Id="{48087106-4C3F-1C0C-3CA334659BA9029F}" FilePath="*appdata\local\opera software\opera stable\cache\*" >
		<Process Path="*\opera.exe" />
	</File>
	<File Id="{D3C8607D-7FAB-A702-27089915553B6268}" FilePath="*\localcache\roaming\trello\local storage\*" >
		<Process Path="*\app\trello.exe" />
	</File>
	<File Id="{61EDCC36-9286-6A13-F844D684E1D275AF}" FilePath="*appdata\local\packages\microsoft.xboxgamingoverlay*" >
		<Process Path="*\gamebar.exe" />
	</File>
	<File Id="{82E16347-38F3-FDB5-06A2101DACA5B799}" FilePath="*appdata\local\temp\{*" >
		<Process Path="*\bin\cl.exe" />
	</File>
	<File Id="{5223BB2F-CB18-94FA-DA1624CA624E2ECF}" FilePath="*appdata\local\temp\_cl_*" >
		<Process Path="*\bin\cl.exe" />
	</File>
	<File Id="{5E0645C4-E835-53C1-044B785F9DD2E98E}" FilePath="*appdata\local\temp\????????-????-????-????-????????????\*" >
		<Process Path="*\windows\system32\cleanmgr.exe" />
	</File>
	<File Id="{E325C86F-0D9E-495A-6E8F7EA34DD7728C}" FilePath="*appdata\local\temp\*" >
		<Process CmdLine="*\windows\hh.exe*-decompile*" />
	</File>
	<File Id="{E9C21565-564A-398D-C2F0EE8F96D589B2}" FilePath="*appdata\local\temp\????????-????-????-????-????????????\ibsprovider.dll*" >
		<Process Path="*\Windows\System32\cleanmgr.exe" />
	</File>
	<File Id="{31916BDC-D780-F860-2413D7E152B692EF}" FilePath="*appdata\local\temp\dd_backgrounddownload*" >
		<Process Path="*\backgrounddownload.exe" />
	</File>
	<File Id="{D5D5A53C-A330-4F30-38F5A9854B97EB4A}" FilePath="*appdata\local\temp\dd_*" >
		<Process Path="*\visualcppbuildtools_full.exe" />
	</File>
	<File Id="{38D8F2FA-E4CE-5C92-8D344C0A848BC1A8}" FilePath="*appdata\local\temp\karma-*\" >
		<Process Path="*\Google\Chrome\Application\chrome.exe" />
	</File>
	<File Id="{6C0D4ABD-6736-94C2-84E4D3532EDEB7CE}" FilePath="*appdata\local\temp\nugetscratch\????????-????-????-????-????????????\*" >
		<Process Path="*\ide\devenv.exe" />
	</File>
	<File Id="{6E2F9449-1C5D-687B-DAE200273F91FF65}" FilePath="*appdata\local\temp\nugetscratch*" >
		<Process Path="*\bin\nuget.exe" />
	</File>
	<File Id="{7D706BBE-115D-FE8D-CC29E662D7071EB6}" FilePath="*appdata\local\temp\passolo\*\status.ini" >
		<Process Path="*\sdl passolo*\psl.exe" />
	</File>
	<File Id="{90D303B8-17A0-58FF-94CB963B2652194F}" FilePath="*appdata\local\temp\*\*.~vsdx" >
		<Process Path="*\microsoft office\office??\visio.exe" />
	</File>
	<File Id="{5466D83A-4ACE-A1F1-58F153E7037AFDC5}" FilePath="*appdata\local\temp\rar$*" >
		<Process Path="*\winrar\winrar.exe" />
	</File>
	<File Id="{2DBBE84A-61CA-A670-093549E0C68F8EB3}" FilePath="*appdata\local\temp\temporaryfolder\updates\*" >
		<Process Path="*\updateutility-gui.exe" />
	</File>
	<File Id="{1AA8CCAD-D4C7-C992-35722937CB67A99B}" FilePath="*appdata\local\temp\tfstemp\*.cpp" >
		<Process Path="*\ide\devenv.exe" />
	</File>
	<File Id="{1703C128-3417-87B9-B7C3DAB287A6F8BE}" FilePath="*appdata\local\temp\vmware-*\vmware-*.log" >
		<Process Path="*\vmware-vmx.exe" />
	</File>
	<File Id="{72738776-626F-12AF-4FC46A280DDE7053}" FilePath="*appdata\local\temp\vscode-chrome-debug-userdatadir_*" >
		<Process Path="*\Google\Chrome\Application\chrome.exe" />
	</File>
	<File Id="{AE74DF78-865A-0D2B-ED16A8779C5969D2}" FilePath="*appdata\local\temp\vsremotecontrol\*" >
		<Process Path="*\ide\devenv.exe" />
	</File>
	<File Id="{F08C4682-29AB-979E-B84888928055CE56}" FilePath="*appdata\local\yarn\cache\*" >
		<Process CmdLine="*yarn.js*" />
	</File>
	<File Id="{CA7A3811-D12A-536D-CA3DBDC00E8CBFC3}" FilePath="*appdata\locallow\microsoft\cryptneturlcache\metadata\*" />
	<File Id="{E09540CF-5049-A420-A3B376D2CEB5C640}" FilePath="*appdata\roaming\jetbrains\webstorm2020.1\plugins\*" >
		<Process Path="*\bin\webstorm64.exe" />
	</File>
	<File Id="{81A205D5-3310-EFBE-B8F6CCB9816C1B0D}" FilePath="*appdata\roaming\microsoft\skype for desktop\indexeddb\*\*.ldb" >
		<Process Path="*\microsoft\skype for desktop\skype.exe" />
	</File>
	<File Id="{146E8746-2326-A081-8D804B5C2D16233E}" FilePath="*microsoft\skype for desktop\????????-????-*.tmp" >
		<Process Path="*\microsoft\skype for desktop\skype.exe" />
	</File>
	<File Id="{2D063641-A815-141B-183DA9227A46DB7F}" FilePath="*\roaming\microsoft\systemcertificates\my\certificates\*" >
		<Process Path="*\safenet\authentication\sac\x64\sacmonitor.exe" />
	</File>
	<File Id="{665DA870-B2E7-11C9-0A30C856619057F5}" FilePath="*appdata\roaming\npm-cache\*" />
	<File Id="{2E2D7DBD-48CE-C084-E19BE31446FE2822}" FilePath="*appdata\roaming\opera software\opera stable\*" >
		<Process Path="*\opera.exe" />
	</File>
	<File Id="{454C8EBF-54AB-C47C-326C56C3A1F046FF}" FilePath="*\kaspersky update utility\temp\temporaryfolder\temporaryfolder\updates\*" >
		<Process Path="*\updateutility-gui.exe" />
	</File>
	<File Id="{E382A29B-14E5-A116-5BCA916B0C83224D}" FilePath="*\2018 online help publish and run converter\*\*\*.htm*" >
		<Process Path="*\windows\explorer.exe" />
	</File>
	<File Id="{765E9794-7F42-9BAF-AFCA9697C80A3DDF}" FilePath="*\documents\projects\repos\industrial_research\pcap_parse*" >
		<Process Path="*\wireshark\editcap.exe" />
	</File>
	<File Id="{D586DE48-7A14-0A72-B74242FBEE35E2B6}" FilePath="*\windows\temp\????????-????-????-????-????????????\*" >
		<Process CmdLine="*\systemtemp\????????-????-????-????-????????????.ps1*" />
	</File>
	<File Id="{EBED408C-3A8C-A4BD-96D80E54C1888A71}" FilePath="*\local\temp\????????-????-????-????-????????????\*" >
		<Process Path="*\Windows\System32\Dism.exe" />
	</File>
	<File Id="{89953DA9-7571-F94F-45C9BF29113833BF}" FilePath="*\local\temp\????????-????-????-????-????????????\*.dll*" >
		<Process Path="*\windows\system32\cleanmgr.exe" />
	</File>
	<File Id="{B04D91D3-392A-EDE8-E586FC389A46E671}" FilePath="*\microsoft.visualstudio.shell.*.ni.pdb\*" >
		<Process Path="*\mscorsvw.exe" />
	</File>
	<File Id="{9E9723B5-3252-86A4-03ED8B81CC6023C3}" FilePath="*\microsoftedgebackups\backups\microsoftedgebackup*\favoriteicons\*.ico:zone.identifier*" >
		<Process Path="*\Windows\System32\RuntimeBroker.exe" />
	</File>
	<File Id="{BE5C104A-0439-0865-645A13F3261054CF}" FilePath="*\roaming\microsoft\windows\themes\cachedfiles\cachedimage_*.jpg*" >
		<Process Path="*\Windows\explorer.exe" />
	</File>
	<File Id="{88226BDC-4590-A178-D60CF0ADB8A57065}" FilePath="*\winddk\*\bin*" >
		<Process Path="*\windows\system32\msiexec.exe" />
	</File>
	<File Id="{92CD5E65-8A4E-78B0-10C1DCF9588091A7}" FilePath="*\windows\assembly\nativeimages_*" >
		<Process Path="*\mscorsvw.exe" />
	</File>
	<File Id="{765B9BB6-5822-C59E-4066F914EB6EE67E}" FilePath="*\windows\assembly\tmp*" >
		<Process Path="*\msiexec.exe" />
	</File>
	<File Id="{8299A9B9-C60B-EB84-6213E66B0AA34165}" FilePath="*\windows\prefetch\*.exe-*.pf*" >
		<Process Path="*\windows\system32\svchost.exe" />
	</File>
	<File Id="{63086A94-DA10-9B76-B46EDB8B45E58EAF}" FilePath="*\windows\ccm\logs\ccmsdkprovider-.log*" >
		<Process Path="*\windows\system32\wbem\wmiprvse.exe" />
	</File>
	<File Id="{184AD3BB-DD6D-C035-4F0B91753B307178}" FilePath="*\windows\installer*" >
		<Process Path="*\windows\system32\msiexec.exe" />
	</File>
	<File Id="{0A9B0596-EEAE-7F1F-794BAF5974301DBA}" FilePath="*\windows\temp\????????????????????????????????\clr\all*" >
		<Process Path="*\windows\system32\msiexec.exe" />
	</File>
	<File Id="{C155B9F5-F732-B988-24FF309963376861}" FilePath="*\windows\microsoft.net\framework\*.xml" >
		<Process Path="*\windows\system32\msiexec.exe" />
	</File>
	<File Id="{2E70E003-89AD-4BB6-64554BEDB7A35D1F}" FilePath="*\windows\system32\config\systemprofile\appdata\local\microsoft\installservice\{*" >
		<Process Path="*\windows\system32\msiexec.exe" />
	</File>
	<File Id="{A3676723-E4D4-F1A2-445BA39316FEF5BD}" FilePath="*\windows\system32\sleepstudy\*" >
		<Process Path="*\windows\system32\svchost.exe" />
	</File>
	<File Id="{EFA30794-396C-B67B-C8E06D88AAF470B6}" FilePath="*\windows\temp\*\all\*.ini*" >
		<Process Path="*\setup_kes.exe" />
	</File>
	<File Id="{317C9858-02A9-52FA-A275B17653B94CB8}" FilePath="*\windows\temp\*_tmp\*.xml" >
		<Process Path="*\InvColPC.exe" />
	</File>
	<File Id="{3901E8AF-C21F-77F5-9B627DDB39A45AFF}" FilePath="*\windows\temp\*_tmp\*.txt" >
		<Process Path="*\InvColPC.exe" />
	</File>
	<File Id="{948DDC62-B24B-08B9-FF1F634170CED85A}" FilePath="*\windows\temp\*_tmp\*.ini" >
		<Process Path="*\InvColPC.exe" />
	</File>
	<File Id="{EAF62FE8-5992-F527-E1DD6B24F00826AF}" FilePath="*\windows\temp\sccm_updatestatus.log" >
		<Process CmdLine="*\systemtemp\????????-????-????-????-????????????.ps1*" />
	</File>
	<File Id="{5E1A31DF-22D1-7081-6C43F6AE29448E4E}" FilePath="*\vmware_images\*" >
		<Process Path="*\vmware\vmware workstation\vmware.exe" />
	</File>
	<File Id="{5D9E9876-D0E0-558E-CF823A1F84871CFA}" FilePath="*\aiconverter\aiconverter2.0\*" >
		<Process Path="*\Windows\explorer.exe" />
	</File>
	<File Id="{BB8D34D8-B6D8-DA65-59AD3F74E6EF01EA}" FilePath="*git\*" >
		<Process Path="*git.exe" />
	</File>
	<File Id="{EA615635-748E-488B-7BB8559677B516C5}" FilePath="*appdata\local\packages\microsoft.windows.photos*\localstate\framenavigationservicestate.xml" >
		<Process CmdLine="*\windowsapps\microsoft.windows.photos*\microsoft.photos.exe*-servername:app.*" />
	</File>
	<File Id="{803794B3-E307-B622-22CD97A4D96A0C1C}" FilePath="*\metrics.interim.temp" >
		<Process Path="*\mongodb\server\*\bin\mongod.exe" />
	</File>
	<File Id="{8F2EDF21-0A45-98E5-5A18F05D7750CD89}" FilePath="*mdr-online-help\english\*.htm" >
		<Process Path="*author-it\authorit.exe" />
	</File>
	<File Id="{959E196F-3E6D-FACC-578419AE73CC401F}" FilePath="*google\chrome\application\*\locales\*.p??" >
		<Process Path="?:\windows\temp\cr_*.tmp\setup.exe" />
	</File>
	<File Id="{6FB8568D-F441-AC8D-E5DFAAD1A53D61FD}" FilePath="*google\chrome\temp\source*\*.p??" >
		<Process Path="?:\windows\temp\cr_*.tmp\setup.exe" />
	</File>
	<File Id="{A1D037DC-D132-9357-996D196AE9C4D54F}" FilePath="*\enterprise\common7\ide\extensions*" >
		<Process Path="*installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\vsixautoupdate.exe" />
	</File>
	<File Id="{5F1F34C0-CB30-08FD-0646A98A31EAC49E}" FilePath="*atlassian\sourcetree.exe_url_*.newcfg" >
		<Process Path="*sourcetree\app*\sourcetree.exe" />
	</File>
	<File Id="{1B6E084C-83B4-7D7C-ABA0CBD3CB2D7617}" FilePath="*microsoft\team foundation\*.curcache" >
		<Process Path="*\common7\ide\devenv.exe" />
	</File>
	<File Id="{73CBC72B-0682-633C-6D27F543C63065D1}" FilePath="*microsoft\vsapplicationinsights\vstel*_*.tmp" >
		<Process Path="*\common7\ide\devenv.exe" />
	</File>
	<File Id="{2BECF683-DB63-9F2B-DA85811F9F6C4A4B}" FilePath="*local\temp\????????-????-*.tmp" >
		<Process Path="*\common7\ide\devenv.exe" />
	</File>
	<File Id="{D73304A7-07EC-C166-025D4D864FD51066}" FilePath="*\local\temp\tmp????.tmp" >
		<Process Path="*\common7\ide\devenv.exe" />
	</File>
	<File Id="{80C0137E-F861-D0DD-3042A7FFDC07174C}" FilePath="*microsoft.microsoftedge_8wekyb3d8bbwe\*\microsoftedge\cache\*" >
		<Process Path="*systemapps\microsoft.microsoftedge_8wekyb3d8bbwe\microsoftedgecp.exe" />
	</File>
	<File Id="{79AAB317-24CC-8BA6-F22883EF5951344C}" FilePath="*microsoft.oneconnect_8wekyb3d8bbwe\localstate\diagoutputdir\oneconnect.discoverynotificationtask*.txt.~tmp" >
		<Process Path="*windows\system32\runtimebroker.exe" />
	</File>
	<File Id="{A754EE41-167A-557F-9717B0FE61E40C29}" FilePath="*appdata\local\temp\passolo\*" >
		<Process Path="*sdl\sdl passolo*\psl.exe" />
	</File>
	<File Id="{182AC63D-A042-E467-DC6724CD7A05D823}" FilePath="*iisexpress\tracelogfiles\updatablemodules.frontend\????????.xml" >
		<Process Path="*iis express\iisexpress.exe" />
	</File>
	<File Id="{929A4BFC-1534-4A4C-9C39CD553B5A4906}" FilePath="*microsoft\windows\recent\customdestinations\????????????????????.temp" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{C64EA338-FF12-3F1B-84B47903A7ABB46E}" FilePath="*microsoft\windows\recent\customdestinations\????????????????????.temp" >
		<Process Path="*\vivaldi\application\vivaldi.exe" />
	</File>
	<File Id="{613503AC-4A20-B926-7B260B61B45C81B5}" FilePath="?:\windows\ccm\servicedata\messaging\*queues*\000?????.msg" >
		<Process Path="?:\windows\ccm\ccmexec.exe" />
	</File>
	<File Id="{81149F19-9C0A-88F1-63BDA40532623DA9}" FilePath="?:\windows\system32\config\systemprofile\appdata\local\????????????????????????????????" >
		<Process Path="?:\windows\system32\provtool.exe" />
	</File>
	<File Id="{85D134ED-AD50-AB6F-3B570CD381F3F932}" FilePath="?:\windows\system32\config\systemprofile\appdata\local\tpm-????-????-????????.tmp" >
		<Process Path="?:\windows\system32\provtool.exe" />
	</File>
	<File Id="{74F73F5B-8270-28E0-F323726B6549FA36}" FilePath="*appdata\local\temp\scoped_dir*.tmp" >
		<Process Path="*\google\chrome\application\chrome.exe" />
	</File>
	<File Id="{8A47D2EF-55F0-1824-EA736F51A1C5D04F}" FilePath="*appdata\local\temp\scoped_dir*.tmp" >
		<Process Path="*\microsoft\edge\application\msedge.exe" />
	</File>
	<File Id="{77075E29-2BA0-2A37-6DCD76E5BE6B1FF7}" FilePath="*appdata\local\temp\scoped_dir*.tmp" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" />
	</File>
	<File Id="{9AFC4627-C5BF-760B-1349F50D1D53B2AC}" FilePath="*appdata\local\temp\scoped_dir*.tmp" >
		<Process Path="*\vivaldi\application\vivaldi.exe" />
	</File>
	<File Id="{4092E0A1-0EC8-8845-B6D0B69C531D8679}" FilePath="*programdata\kasperskylab\*" >
		<Process Path="c:\program files (x86)\kaspersky lab\networkagent\klnagent.exe" />
	</File>
	<File Id="{04118A06-807E-3551-07B002A93AA706DB}" FilePath="*programdata\kasperskylab\*" >
		<Process Path="c:\windows\temp\kav remote*\setup.exe" />
	</File>
	<File Id="{EF1A0E45-C4D0-F8F9-2DAAFE73E92D242E}" FilePath="*atlassian\sourcetree.exe_url_*" >
		<Process Path="*sourcetree\app-*\sourcetree.exe" />
	</File>
	<File Id="{F982EC0B-EF2E-FDED-479AA257F8A8AE9B}" FilePath="*microsoft\teams\service worker\scriptcache\index-dir\the-real-index" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{2E6C7FDA-3EB8-B444-50BD2DD748139543}" FilePath="*devart\dbforge sql complete\docsessions-journal.db" >
		<Process Path="*tools\binn\managementstudio\ssms.exe" />
	</File>
	<File Id="{2B16C065-B0FD-0AF9-9D4E717FB891A897}" FilePath="c:\programdata\microsoft\*????????-????-????-????-????????????*" >
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{97884A99-D624-2578-8E00F7580890137C}" FilePath="c:\programdata\microsoft\*\edb?????.log" >
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{40776459-A31A-2FE9-90708661D9D25EF9}" FilePath="*.ldf\backup\*.log" >
		<Process Path="*microsoft system center 2016\dpm\dpm\bin\dpmra.exe" />
	</File>
	<File Id="{05248237-17BB-883D-898F3E257F3FCD66}" FilePath="*logs\*.???.etl" >
		<Process Path="*rempl\remsh.exe" />
	</File>
	<File Id="{AC8B5E77-E34A-0A74-42CB0CA9B82E32A1}" FilePath="*logs\*.???.etl" >
		<Process Path="c:\windows\system32\unp\updatenotificationmgr.exe" />
	</File>
	<File Id="{A983B0E7-2BF7-AB73-1371BC50AAFA11CE}" FilePath="c:\programdata\kaspersky lab\kaspersky*" >
		<Process Path="*kaspersky lab\kaspersky*\kavfswp.exe" />
	</File>
	<File Id="{99895885-11EB-64AD-D1619A11D1FB8FBE}" FilePath="c:\programdata\microsoft\search\data\applications\windows\edb?????.jtx" >
		<Process Path="c:\windows\system32\searchindexer.exe" />
	</File>
	<File Id="{09726100-2CC4-008E-270BECB26624E1B1}" FilePath="c:\programdata\microsoft\*\report.wer*" >
		<Process Path="c:\windows\system32\wermgr.exe" />
	</File>
	<File Id="{1F45ACE7-04FA-5F5F-8B7E2326BB41DB37}" FilePath="c:\programdata\microsoft\*????????-????-????-????-????????????*" >
		<Process Path="c:\windows\system32\wermgr.exe" />
	</File>
	<File Id="{23AAED84-D4DF-D2A2-7D8C225EB4DD9CA6}" FilePath="c:\programdata\usoprivate\updatestore\updatestore*.tmp" >
		<Process Path="c:\windows\system32\usocoreworker.exe" />
	</File>
	<File Id="{22D83ED0-2CAD-B720-296B0086BDF8D562}" FilePath="c:\programdata\usoprivate\updatestore\updatestore*.tmp" >
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{AD6268AE-3DA7-DF2B-2373C7B6416DDCD8}" FilePath="c:\programdata\usoshared\logs\*.???.etl" >
		<Process Path="c:\windows\system32\*.exe" />
	</File>
	<File Id="{B7771D62-8E45-CA21-A77F0040B269AB76}" FilePath="*.dtsx" >
		<Process Path="*common*\ide\devenv.exe" />
	</File>
	<File Id="{48691680-74D1-868F-F8CD68CC990ADA8D}" FilePath="*.conmgr" >
		<Process Path="*common*\ide\devenv.exe" />
	</File>
	<File Id="{AC688F7F-75E1-4083-86A16536E4EEB1C3}" FilePath="*.tsx" >
		<Process Path="*mingw*\bin\git.exe" />
	</File>
	<File Id="{E6BE4023-E19C-C8C1-70F94B8D853ACFAA}" FilePath="*appdata\local\jetbrains\pycharmce*" >
		<Process Path="*bin\pycharm64.exe" />
	</File>
	<File Id="{182082C1-E24E-ACCC-3C241DDFAF6243E6}" FilePath="*microsoft\*applicationinsights\vstel*" >
		<Process Path="*\ide\devenv.exe" />
	</File>
	<File Id="{8B5A2E2B-9CBF-A180-0334B3AEE02F0FCF}" FilePath="*microsoft\*applicationinsights\vstel*" >
		<Process Path="*\ide\mtm.exe" />
	</File>
	<File Id="{3A693473-C4B7-2A9F-CD1DEED9D48C01DD}" FilePath="*microsoft\*applicationinsights\vstel*" >
		<Process Path="*\vshub.exe" />
	</File>
	<File Id="{D0C2DFE0-CFD0-D6DD-EF69EC702038546F}" FilePath="*microsoft\*applicationinsights\vstel*" >
		<Process Path="*tools\binn\managementstudio\ssms.exe" />
	</File>
	<File Id="{4EAE4536-CD5D-A7FE-5E7676E5030877D6}" FilePath="*microsoft\*applicationinsights\vstel*" >
		<Process Path="*\common*\ide\perfwatson*.exe" />
	</File>
	<File Id="{A694A014-8BD1-FD56-24866276D03CA05D}" FilePath="*microsoft\*applicationinsights\vstel*" >
		<Process Path="*.setup.service\backgrounddownload.exe" />
	</File>
	<File Id="{D83752A5-3112-F611-CB7C8C48EB7571EE}" FilePath="*microsoft\onenote\*\cache\00??????.bin" >
		<Process Path="*\office*\onenote.exe" />
	</File>
	<File Id="{216712EB-5F51-AA5D-F25F611E5189F852}" FilePath="*microsoft\outlook\~*.ost.tmp" >
		<Process Path="*\office*\lync.exe" />
	</File>
	<File Id="{3D9C35AE-19C9-8CE6-1462E6AE2494EFF6}" FilePath="*microsoft\outlook\~*.ost.tmp" >
		<Process Path="c:\windows\system32\searchprotocolhost.exe" />
	</File>
	<File Id="{6A19769F-EDA2-FAF2-9CD0F7E4E1FCF14C}" FilePath="*microsoft\outlook\~*.ost.tmp" >
		<Process Path="*\office*\ucmapi.exe" />
	</File>
	<File Id="{CDA94A86-31FE-FB06-C044A63EED5122DB}" FilePath="*\microsoft\outlook\*@*.*.xml" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{21B8F28F-D195-2B9D-986E002520069641}" FilePath="*\microsoft\windows\inetcache\content.*" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{A896BE79-52CD-B260-2D6F20E70A20D3CD}" FilePath="*\microsoft\windows\inetcache\content.*" >
		<Process Path="*\office*\winword.exe" />
	</File>
	<File Id="{68828FBD-4A2D-91CD-F979428845C65C8D}" FilePath="*\microsoft\windows\inetcache\content.*" >
		<Process Path="*\office*\excel.exe" />
	</File>
	<File Id="{B8DD06C9-C740-26B1-46834C4BED058865}" FilePath="*\microsoft\windows\inetcache\ie\????????\*" >
		<Process Path="c:\windows\system32\taskhostw.exe" />
	</File>
	<File Id="{53AE5851-3262-FD86-345CE1D61670ADEC}" FilePath="*\microsoft\windows\inetcache\ie\????????\*" >
		<Process Path="*\launcher\vpxclient.exe" />
	</File>
	<File Id="{89276DBA-844A-8235-166DD665519C86CA}" FilePath="*\microsoft\windows\inetcache\ie\????????\*" >
		<Process Path="*\adobe desktop service.exe" />
	</File>
	<File Id="{728D17BB-5FBC-335B-37EDA7A52CDBC406}" FilePath="*\microsoft\windows\inetcache\ie\????????\*" >
		<Process Path="*\microsoft\onedrive\onedrive.exe" />
	</File>
	<File Id="{00A01ACF-A718-182E-F28EF9CAEB0A83A7}" FilePath="*\microsoft\windows\inetcache\ie\????????\*" >
		<Process Path="*\internet explorer\iexplore.exe" />
	</File>
	<File Id="{9F348FE9-C6B3-9312-8D85FE9096034809}" FilePath="*\microsoft\windows\inetcache\ie\????????\*" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{FEB456F8-4632-370E-51C7F626547C486B}" FilePath="*\microsoft\windows\inetcache\ie\????????\*" >
		<Process Path="*\office*\winword.exe" />
	</File>
	<File Id="{9A35676D-530E-E1B5-06B83F431752C92C}" FilePath="*\microsoft\windows\inetcache\ie\????????\*" >
		<Process Path="*\office*\excel.exe" />
	</File>
	<File Id="{C5A1C1CC-0F12-A218-332A9C2E7C30F61D}" FilePath="*\microsoft\windows\inetcache\ie\????????\*" >
		<Process Path="*\psl.exe" />
	</File>
	<File Id="{58E7612D-7546-8165-83C1B75EFF6B7138}" FilePath="*\microsoft\windows\inetcache\ie\????????\*" >
		<Process Path="*\microsoft\onedrive\onedrivestandaloneupdater.exe" />
	</File>
	<File Id="{F26B6FAD-220E-C299-CEF36AA573CD5BA7}" FilePath="*\microsoft\windows\inetcache\ie\????????\*" >
		<Process Path="*\passoloupdateclient.exe" />
	</File>
	<File Id="{BD0978EB-2CD5-05F3-D759B3E71CC428C5}" FilePath="*\microsoft\windows\inetcache\ie\????????\*" >
		<Process Path="*\ide\devenv.exe" />
	</File>
	<File Id="{4DF91510-CFC6-B799-FC24EFA487DC0E5C}" FilePath="*\microsoft\windows\inetcache\ie\????????\*" >
		<Process Path="c:\windows\system32\dllhost.exe" />
	</File>
	<File Id="{D68AEBA2-511D-B66C-11F06C0ADCF6D54D}" FilePath="*\microsoft\windows\inetcache\low\ie\????????\*" >
		<Process Path="c:\windows\system32\taskhostw.exe" />
	</File>
	<File Id="{A7996CEF-C94B-4DBC-4359B6432AB3DAFF}" FilePath="*\microsoft\windows\inetcache\low\ie\????????\*" >
		<Process Path="*\launcher\vpxclient.exe" />
	</File>
	<File Id="{9BFFC711-7E8A-8EE6-F1502CB94AB4EEA7}" FilePath="*\microsoft\windows\inetcache\low\ie\????????\*" >
		<Process Path="*\adobe desktop service.exe" />
	</File>
	<File Id="{7ECD9CB9-384F-FB31-AD0FF1498D89E0EC}" FilePath="*\microsoft\windows\inetcache\low\ie\????????\*" >
		<Process Path="*\microsoft\onedrive\onedrive.exe" />
	</File>
	<File Id="{53F88657-0570-084D-A7EFD56C917499E8}" FilePath="*\microsoft\windows\inetcache\low\ie\????????\*" >
		<Process Path="*\internet explorer\iexplore.exe" />
	</File>
	<File Id="{E2731BF3-3A5D-257D-95772210100C82B6}" FilePath="*\microsoft\windows\inetcache\low\ie\????????\*" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E4355293-2582-3A38-BAE363E66144E251}" FilePath="*\microsoft\windows\inetcache\low\ie\????????\*" >
		<Process Path="*\office*\winword.exe" />
	</File>
	<File Id="{EDC58B76-1A42-C270-984B309DFD3D7DCC}" FilePath="*\microsoft\windows\inetcache\low\ie\????????\*" >
		<Process Path="*\office*\excel.exe" />
	</File>
	<File Id="{296B4C7E-8417-A881-B13BAB01DB7D1293}" FilePath="*\microsoft\windows\inetcache\low\ie\????????\*" >
		<Process Path="*\psl.exe" />
	</File>
	<File Id="{208C6493-2890-CD72-E1EBDB0267E41B09}" FilePath="*\microsoft\windows\inetcache\low\ie\????????\*" >
		<Process Path="*\microsoft\onedrive\onedrivestandaloneupdater.exe" />
	</File>
	<File Id="{CEE0DB3D-87F0-0A86-9E0B89265B2753A8}" FilePath="*\microsoft\windows\inetcache\low\ie\????????\*" >
		<Process Path="*\passoloupdateclient.exe" />
	</File>
	<File Id="{34DBC2C3-9FE3-C2D2-FD5945217BC38A2E}" FilePath="*\microsoft\windows\inetcache\low\ie\????????\*" >
		<Process Path="*\ide\devenv.exe" />
	</File>
	<File Id="{4F8F7874-D0F8-BBF4-399FC6F70D30C2D3}" FilePath="*\microsoft\windows\inetcache\low\ie\????????\*" >
		<Process Path="c:\windows\system32\dllhost.exe" />
	</File>
	<File Id="{237F9C34-2249-F741-08C57F893AD5E110}" FilePath="*\microsoft_corporation\powershell_ise.exe_strongname_*~rf*.tmp" >
		<Process Path="c:\windows\system32\windowspowershell\v1.0\powershell_ise.exe" />
	</File>
	<File Id="{8B85BDED-C908-4C6F-742FD44A9CF115D3}" FilePath="*\microsoft_corporation\powershell_ise.exe_strongname_*\autosaveinformation\????????.tmp" >
		<Process Path="c:\windows\system32\windowspowershell\v1.0\powershell_ise.exe" />
	</File>
	<File Id="{0B082DE4-8254-549A-7F164250FD37C2AD}" FilePath="*\mozilla\firefox\profiles\????????.default*\cache2\*" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{FD20DBBB-78C3-F4C2-2A30A9FDCD8D46FB}" FilePath="*\mozilla\firefox\profiles\????????.default*\safebrowsing-updating\*" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{A8D69079-C2EA-54B1-3992FAE38EC9470D}" FilePath="*\local\programs\microsoft vs code\*" >
		<Process Path="*\local\temp\*.tmp" />
	</File>
	<File Id="{2F096A81-1A63-D9E9-867BBC804FD56FF5}" FilePath="*appdata\local\temp\~df????????????????.tmp" >
		<Process Path="c:\windows\system32\msfeedssync.exe" />
	</File>
	<File Id="{4385D67F-4B4D-6706-512FB5B880C582B1}" FilePath="*appdata\local\temp\~df????????????????.tmp" >
		<Process Path="*\internet explorer\iexplore.exe" />
	</File>
	<File Id="{0F2D649D-3474-2F3D-9FA5F1EAC52A3EAC}" FilePath="*appdata\local\temp\~df????????????????.tmp" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{B0C5B15E-AFAF-9B72-0446B1D50DB2B573}" FilePath="*appdata\local\temp\~df????????????????.tmp" >
		<Process Path="*\common*\ide\devenv.exe" />
	</File>
	<File Id="{BAB1B5B6-B297-F5FE-44914D286B0168B2}" FilePath="*appdata\local\temp\~df????????????????.tmp" >
		<Process Path="c:\windows\system32\searchprotocolhost.exe" />
	</File>
	<File Id="{697035B8-5F6E-1A48-E6EFE66D91BB9E9A}" FilePath="*appdata\local\temp\hsc*.tmp" >
		<Process Path="*\office*\ucmapi.exe" />
	</File>
	<File Id="{B224AB6C-4901-7BA7-A490136A66B19EFD}" FilePath="*appdata\local\temp\hsc*.tmp" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{56422ED9-5E93-B066-E391DC3CEBBC2805}" FilePath="*appdata\local\temp\tmp????.tmp" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{607BFB90-D3C4-5BC1-C03F4B992BA717BB}" FilePath="*\code\cacheddata\*" >
		<Process Path="*\programs\microsoft vs code\code.exe" />
	</File>
	<File Id="{B4C5061A-EDD2-2E6E-FF7A69DBC21FE1A3}" FilePath="*\microsoft\*~rf*.tmp" >
		<Process Path="*\microsoft\skype for desktop\skype.exe" />
	</File>
	<File Id="{62B3DA24-F9E8-691B-F54B0A8C2CDCD377}" FilePath="*\microsoft\*~rf*.tmp" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{2ADA7181-3E16-94B4-4EC64FFBCF2BCC88}" FilePath="*\microsoft\*~rf*.tmp" >
		<Process Path="*\google\chrome\application\chrome.exe" />
	</File>
	<File Id="{CE49C50B-364D-47B7-4D629F3686085B8B}" FilePath="*\microsoft\*~rf*.tmp" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{FE711341-2EE7-77CB-AEA880D4FDB96A8D}" FilePath="*\microsoft\*~rf*.tmp" >
		<Process Path="*\vivaldi\application\vivaldi.exe" />
	</File>
	<File Id="{3BE431D0-0093-279B-B2F52A8E13AEA410}" FilePath="*\microsoft\*~rf*.tmp" >
		<Process Path="*\internet explorer\iexplore.exe" />
	</File>
	<File Id="{283D0716-A363-6268-7962B575A1200223}" FilePath="*\microsoft\*~rf*.tmp" >
		<Process Path="c:\windows\immersivecontrolpanel\systemsettings.exe" />
	</File>
	<File Id="{501A71B3-96D7-0A90-D81B9BCA11016CC0}" FilePath="*\microsoft\*~rf*.tmp" >
		<Process Path="c:\windows\system32\runtimebroker.exe" />
	</File>
	<File Id="{AEAA596D-8837-1284-00ABA7634E4FAD31}" FilePath="*\microsoft\windows\recent\customdestinations\????????????????????.temp" >
		<Process Path="*\google\chrome\application\chrome.exe" />
	</File>
	<File Id="{CDCE1025-1F62-1B2D-34C8D7D925E4B9DE}" FilePath="*\microsoft\windows\recent\customdestinations\????????????????????.temp" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{E935EF27-952E-D233-F44F3A16F0FCC2C9}" FilePath="*\microsoft\windows\recent\customdestinations\????????????????????.temp" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{5DCB84B5-50F4-4F1B-C8F053ACD36DFD83}" FilePath="*\microsoft\windows\recent\customdestinations\????????????????????.temp" >
		<Process Path="*\programs\microsoft vs code\code.exe" />
	</File>
	<File Id="{7E645410-041C-4C77-D515CEE7974BC5DC}" FilePath="*\whatsapp\cache\f_0?????" >
		<Process Path="*\whatsapp\app-*\whatsapp.exe" />
	</File>
	<File Id="{76FEE30C-4B3D-2CAD-4B26E31B7D5D1895}" FilePath="*\whatsapp\service worker\cachestorage\*" >
		<Process Path="*\whatsapp\app-*\whatsapp.exe" />
	</File>
	<File Id="{9199CB6F-9615-C43E-537874E18BDABCDF}" FilePath="*\atlassian\sourcetree.exe_url_*\????????.tmp" >
		<Process Path="*\sourcetree\app-*\sourcetree.exe" />
	</File>
	<File Id="{9B1B72FE-A4B2-2FDF-F6F20E73192D2FC3}" FilePath="c:\windows\ccm\logs\sensormanagedprovider-20*.log" >
		<Process Path="c:\windows\system32\wbem\wmiprvse.exe" />
	</File>
	<File Id="{2ED9489B-8EBC-9B57-B4C08223D7F3A352}" FilePath="c:\windows\ccm\servicedata\*.que" >
		<Process Path="c:\windows\ccm\ccmexec.exe" />
	</File>
	<File Id="{E42B6E1A-ACC9-F0FC-328F2500E0A38936}" FilePath="c:\windows\ccm\servicedata\temp\???????.tmp" >
		<Process Path="c:\windows\ccm\ccmexec.exe" />
	</File>
	<File Id="{409A500E-860D-C686-0E0CFB5A10F771CD}" FilePath="c:\windows\prefetch\*.pf" >
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{396F3BD0-3B1E-5A15-65DDBF096603ECB6}" FilePath="c:\windows\system32\config\systemprofile\appdata\local\*.tmp*" >
		<Process Path="c:\windows\system32\provtool.exe" />
	</File>
	<File Id="{C3737412-9168-FA0C-71B630E67997397F}" FilePath="c:\windows\system32\config\systemprofile\appdata\local\*.tmp*" >
		<Process Path="c:\windows\system32\wbem\wmiprvse.exe" />
	</File>
	<File Id="{93C9B977-B39C-852A-62976FCABEB28609}" FilePath="*temp\klsc-*" >
		<Process Path="*\kaspersky lab\networkagent\vapm.exe" />
	</File>
	<File Id="{D2432503-2C60-D363-42798042792BD535}" FilePath="*temp\klsc-*" >
		<Process Path="*\kaspersky lab\networkagent\klnagent.exe" />
	</File>
	<File Id="{CE42E691-D150-91E1-CE047C2A38FFE3ED}" FilePath="*\idx\?\_??.???" >
		<Process Path="*\bin\java.exe" />
	</File>
	<File Id="{9909559F-FB6E-75DE-FA335E5F237F17B8}" FilePath="*\search\solr-data\*" >
		<Process Path="*tomcat\bin\tcmsearchhost.exe" />
	</File>
	<File Id="{DB828BF4-48CE-89D3-1295436694205A6C}" FilePath="c:\programdata\kaspersky lab\tw*" Operation="Delete" />
	<File Id="{DD319E92-FE53-DD8B-96569EC2C8F29784}" FilePath="*health service state\health service store\edb?????.log" >
		<Process Path="*\microsoft monitoring agent\agent\healthservice.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{F7C672A1-79E4-47D5-B743FCD659F9F3F0}" FilePath="*\health service state\health service store\edb?????.log" >
		<Process Path="*\operations manager\server\healthservice.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{446EE701-E4CA-58E4-F47AE6A5BF1B2F5E}" FilePath="*\health service state\monitoring host temporary files*" >
		<Process Path="*\microsoft monitoring agent\agent\monitoringhost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{D4DA0F06-671E-18EA-C7077524FC5B0771}" FilePath="*\health service state\monitoring host temporary files*" >
		<Process Path="*\operations manager\server\monitoringhost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{5C7F3046-7B8E-9A65-7B902BF2C8388A3A}" FilePath="c:\program files\opera\*" >
		<Process Path="*filesopera\installing\installer.exe" />
	</File>
	<File Id="{A50438E8-B979-5E9B-13733EB92432AAB8}" FilePath="c:\programdata\bomgar-scc-*\settings.ini*" >
		<Process Path="c:\programdata\bomgar-scc-*\bomgar-scc.exe" />
	</File>
	<File Id="{A04BADC1-DCF4-8A1C-BC3B2D04D83C704E}" FilePath="c:\programdata\dropbox\update\log\dropboxupdate.log-20*" >
		<Process Path="*\dropbox\update\dropboxupdate.exe" />
	</File>
	<File Id="{9984D7A1-004A-68C8-BDB727522EECC382}" FilePath="c:\programdata\microsoft\event viewer\externallogs\log_*.xml" >
		<Process Path="c:\windows\system32\mmc.exe" />
	</File>
	<File Id="{8ED0D01A-E506-2115-CDD3416ED24765A4}" FilePath="*\tcm_?-???????-?????.content*" >
		<Process Path="*\bin\cd_transport.exe" />
	</File>
	<File Id="{DEA751F0-9183-12B3-4A8F8F8E1AA71A06}" FilePath="*\tcm_?-???????-?????.content*" >
		<Process Path="*\bin\tcmpublisher.exe" />
	</File>
	<File Id="{ED20500D-DDA6-EEF9-1A217636C81F2838}" FilePath="*\tcm_?-???????-?????.state*" >
		<Process Path="*\bin\cd_transport.exe" />
	</File>
	<File Id="{506ED093-1025-E33D-1C131235B751D295}" FilePath="*\tcm_?-???????-?????.state*" >
		<Process Path="*\bin\tcmpublisher.exe" />
	</File>
	<File Id="{4D9EAC81-3587-DE0C-D303153F88AD7917}" FilePath="*\tcm_?-???????-?????\*" >
		<Process Path="*\bin\cd_transport.exe" />
	</File>
	<File Id="{7A1016DD-D443-6226-954EBB4D45B187F8}" FilePath="*\tcm_?-???????-?????\*" >
		<Process Path="*\bin\tcmpublisher.exe" />
	</File>
	<File Id="{F37AEF11-7627-699E-C37B2CCEA0EC002C}" FilePath="*\ssis\scaleout\master\mastertservice.log_20*.txt" >
		<Process Path="*\dts\binn\microsoft.sqlserver.integrationservices.masterservicehost.exe" />
	</File>
	<File Id="{472A49DA-0097-A11F-9695F8321543FA5C}" FilePath="*\ssis\scaleout\agent\workeragentservice.log_20*.txt" >
		<Process Path="*\dts\binn\microsoft.sqlserver.integrationservices.masterservicehost.exe" />
	</File>
	<File Id="{1FF67763-AC15-0630-A029575A1942BFDD}" FilePath="*\adobe\pmp\com.adobe.pluginmarketplace_*\managecache\*" >
		<Process Path="*\common files\adobe\adobe desktop common\hex\adobe cef helper.exe" />
	</File>
	<File Id="{EDFC0B9D-2F69-7010-A96BE43AEBEA5512}" FilePath="*\microsoft\internet explorer\urlblock\url*.tmp" >
		<Process Path="*\internet explorer\iexplore.exe" />
	</File>
	<File Id="{1194583D-D92E-2022-9CA8073F23946D65}" FilePath="*\microsoft\windows\explorer\iconcachetodelete\icn????.tmp" >
		<Process Path="*\google\chrome\application\chrome.exe" />
	</File>
	<File Id="{13361B74-1E78-C06C-5AB63890D535C4AA}" FilePath="*\microsoft\windows\explorer\iconcachetodelete\icn????.tmp" >
		<Process Path="c:\windows\system32\openwith.exe" />
	</File>
	<File Id="{9D654D50-55AB-EB88-D15D2954443BA48A}" FilePath="*\microsoft\windows\explorer\thumbcache_*.db" Operation="Modify" />
	<File Id="{3B9C0C7B-3FDF-621C-16F5E9EB6A353BE8}" FilePath="*\microsoft\windows\explorer\thumbcachetodelete\thm????.tmp" >
		<Process Path="c:\windows\explorer.exe" />
	</File>
	<File Id="{289728DE-E3B5-3ADD-DA5CDDF7629719A0}" FilePath="*\microsoft\windows\explorer\thumbcachetodelete\thm????.tmp" >
		<Process Path="c:\windows\system32\cleanmgr.exe" />
	</File>
	<File Id="{5ADC5E9B-84B1-B2A7-3DF5615C6577B2F3}" FilePath="*\microsoft\windows\webcache\v???????.log" >
		<Process Path="c:\windows\system32\taskhostw.exe" />
	</File>
	<File Id="{E1496201-7887-00B9-989301F0AE6AA88F}" FilePath="*\mozilla firefox\updated\*" >
		<Process Path="*\mozilla firefox\updater.exe" />
	</File>
	<File Id="{EB9D2044-2E84-6E8C-7B3B15B3F5E10AB0}" FilePath="*\packages\microsoft.microsoft*" >
		<Process Path="*\windowsapps\microsoft.microsoft*" />
	</File>
	<File Id="{7080E2C3-BD89-D0BC-9E75455155F7C918}" FilePath="*\packages\microsoft.microsoft*" >
		<Process Path="c:\windows\system32\taskhostw.exe" />
	</File>
	<File Id="{1B1C698F-6BD6-BC5E-39B520A251336DEF}" FilePath="*\packages\microsoft.microsoft*" >
		<Process Path="c:\windows\system32\dllhost.exe" />
	</File>
	<File Id="{E6D92A3E-49BF-040F-CBD67F09F462564A}" FilePath="*\packages\microsoft.microsoft*" >
		<Process Path="c:\windows\system32\runtimebroker.exe" />
	</File>
	<File Id="{2C22FA8B-5952-03FF-B49EF5A231BBB9C7}" FilePath="*\packages\microsoft.microsoft*" >
		<Process Path="c:\windows\system32\backgroundtaskhost.exe" />
	</File>
	<File Id="{B4FC47EB-5B98-3775-FF3D8EB440056D58}" FilePath="*\packages\microsoft.windows*" >
		<Process Path="*\windowsapps\microsoft.microsoft*" />
	</File>
	<File Id="{C2FFA7CD-FC24-84CD-7EB90AD56F21E159}" FilePath="*\packages\microsoft.windows*" >
		<Process Path="c:\windows\system32\taskhostw.exe" />
	</File>
	<File Id="{0AD93C79-6DBD-87FF-712B6101572AA2FD}" FilePath="*\packages\microsoft.windows*" >
		<Process Path="c:\windows\system32\dllhost.exe" />
	</File>
	<File Id="{13792948-9FFB-02EC-7FA830F321832E22}" FilePath="*\packages\microsoft.windows*" >
		<Process Path="c:\windows\system32\runtimebroker.exe" />
	</File>
	<File Id="{9878F794-537D-4D4D-762425643F08C5A7}" FilePath="*\packages\microsoft.windows*" >
		<Process Path="c:\windows\system32\backgroundtaskhost.exe" />
	</File>
	<File Id="{BBD8AF02-C5D8-2F47-7441B7E6EE88CBBD}" FilePath="*\packages\microsoft.aad.brokerplugin_*" >
		<Process Path="c:\windows\system32\backgroundtaskhost.exe" />
	</File>
	<File Id="{D45267CC-0493-0BB0-B8E14380DB29A3B5}" FilePath="*\packages\microsoft.aad.brokerplugin_*" >
		<Process Path="c:\windows\system32\runtimebroker.exe" />
	</File>
	<File Id="{5CEE64C9-9474-D0E3-1884E6F7026844EF}" FilePath="*\packages\microsoft.*~rf*.tmp" >
		<Process Path="c:\windows\system32\backgroundtaskhost.exe" />
	</File>
	<File Id="{4A10730F-AC43-4F0D-EA9E5548F5BB156F}" FilePath="*\packages\microsoft.*~rf*.tmp" >
		<Process Path="c:\windows\system32\runtimebroker.exe" />
	</File>
	<File Id="{74051290-1A4B-46F7-9E2BD6546ED14407}" FilePath="*\packages\microsoft.*_????.txt" >
		<Process Path="c:\windows\system32\backgroundtaskhost.exe" />
	</File>
	<File Id="{5473192A-2042-F6C0-95EB5A6A2E4322EF}" FilePath="*\packages\microsoft.*_????.txt" >
		<Process Path="c:\windows\system32\runtimebroker.exe" />
	</File>
	<File Id="{F326B0C5-631D-7FF7-997ECC3E140EC703}" FilePath="'*\packages\microsoft.*\appcache??????????????????.txt" >
		<Process Path="c:\windows\system32\backgroundtaskhost.exe" />
	</File>
	<File Id="{470E1388-3CF6-5862-6F4104B56EC2294D}" FilePath="'*\packages\microsoft.*\appcache??????????????????.txt" >
		<Process Path="c:\windows\system32\runtimebroker.exe" />
	</File>
	<File Id="{C0A9A97D-0036-C5F4-E63DC1773A0E344B}" FilePath="*\spotify\browser\*~rf*.tmp" >
		<Process Path="Path:'*\spotify\spotify.exe" />
	</File>
	<File Id="{D059845D-78CD-0163-640A5BFE1325ECC1}" FilePath="c:\autotests\product\kavkis\autotests\*" >
		<Process Path="*\autotest.kis.tdlgenerator.exe" />
	</File>
	<File Id="{9FC9BFA5-0F75-6412-F8891F7593E27B93}" FilePath="c:\autotests\product\kavkis\autotests\*" >
		<Process Path="*\bin\msbuild.exe" />
	</File>
	<File Id="{9FDAEC1D-6FF6-40FC-35CEF5C217739119}" FilePath="c:\autotests\product\kavkis\autotests\*" >
		<Process Path="*\.nuget\nuget.exe" />
	</File>
	<File Id="{CACF8B1C-CF67-8BC5-BC09B86C2ED58F0D}" FilePath="c:\autotests\product\kavkis\autotests\*" >
		<Process Path="*\vbcscompiler.exe" />
	</File>
	<File Id="{FCD421A8-C114-0B43-E3FA26A4DC305B96}" FilePath="c:\autotests\product\kavkis\autotests\*" >
		<Process Path="*\common*\ide\devenv.exe" />
	</File>
	<File Id="{E15FE35B-2A7B-7AE7-D8BC636D3A71A83E}" FilePath="*.common.services\allocations\*" >
		<Process Path="*\autotest.kis.tdlgenerator.exe" />
	</File>
	<File Id="{FA33E262-F6B4-DFA3-CE22F632A58F4E0C}" FilePath="*.common.services\allocations\*" >
		<Process Path="*\bin\msbuild.exe" />
	</File>
	<File Id="{81E6905B-D134-74C8-FC2FF99A2F1C86DA}" FilePath="*.common.services\allocations\*" >
		<Process Path="*\.nuget\nuget.exe" />
	</File>
	<File Id="{F58089EF-5202-CCD5-D4490BD27B7B3C94}" FilePath="*.common.services\allocations\*" >
		<Process Path="*\vbcscompiler.exe" />
	</File>
	<File Id="{09939B70-C081-7011-EC0805DB6766870F}" FilePath="*.common.services\allocations\*" >
		<Process Path="*\common*\ide\devenv.exe" />
	</File>
	<File Id="{B993B684-E4DA-DD37-C25406B0C2D710EB}" FilePath="*.webapi\*.tmp" >
		<Process Path="*\autotest.kis.tdlgenerator.exe" />
	</File>
	<File Id="{F453FFF0-805A-591A-4400AA7A62099DA2}" FilePath="*.webapi\*.tmp" >
		<Process Path="*\bin\msbuild.exe" />
	</File>
	<File Id="{1990EEBD-2674-3ADA-51B1E8975373C874}" FilePath="*.webapi\*.tmp" >
		<Process Path="*\.nuget\nuget.exe" />
	</File>
	<File Id="{42FFE952-C466-3F78-B6B9BE67A022F4C8}" FilePath="*.webapi\*.tmp" >
		<Process Path="*\vbcscompiler.exe" />
	</File>
	<File Id="{88C4D0AB-05AE-281E-11E190B45AA1753B}" FilePath="*.webapi\*.tmp" >
		<Process Path="*\common*\ide\devenv.exe" />
	</File>
	<File Id="{1DED65A0-675B-BE4F-2FAB4D788B636747}" FilePath="*appdata\local\temp\nugetscratch\lock\*" >
		<Process Path="*\autotest.kis.tdlgenerator.exe" />
	</File>
	<File Id="{BE840A00-7C3B-4D0C-1AC144E02B78F7AC}" FilePath="*appdata\local\temp\nugetscratch\lock\*" >
		<Process Path="*\bin\msbuild.exe" />
	</File>
	<File Id="{36512D09-F491-AF14-D17E6047003C3E4F}" FilePath="*appdata\local\temp\nugetscratch\lock\*" >
		<Process Path="*\.nuget\nuget.exe" />
	</File>
	<File Id="{112F0E91-6B9D-0D2D-099DCABC551813CE}" FilePath="*appdata\local\temp\nugetscratch\lock\*" >
		<Process Path="*\vbcscompiler.exe" />
	</File>
	<File Id="{D592B481-BC91-0451-61C4CA88C7AC74EB}" FilePath="*appdata\local\temp\nugetscratch\lock\*" >
		<Process Path="*\common*\ide\devenv.exe" />
	</File>
	<File Id="{16F6102A-3B8F-B358-E873BFE1EB2C6E47}" FilePath="*\dell\delldatavault\epsa\epsa_?_????????" >
		<Process Path="*\dell\delldatavault\ddvdatacollector.exe" />
	</File>
	<File Id="{88DEEEF1-2927-846F-87FE880BFB84DDE4}" FilePath="*\frontend\app\*" >
		<Process Path="*\mingw64\bin\git.exe" />
	</File>
	<File Id="{74F8031D-2BC5-A1CE-FE167C67C9E918A6}" FilePath="*\frontend\app\*" >
		<Process Path="*\smartgit\bin\smartgit.exe" />
	</File>
	<File Id="{D59DCADC-AB60-6851-08CD40C5EEFAB2AE}" FilePath="*\frontend\app\*" >
		<Process Path="*\microsoft vs code\code.exe" />
	</File>
	<File Id="{0E413E18-37F7-8771-A07BB0F547CE067E}" FilePath="*.common.services\*.cache" >
		<Process Path="*\mingw64\bin\git.exe" />
	</File>
	<File Id="{50B861B5-C937-DC91-BBF4ED66C47C49D7}" FilePath="*.common.services\*.cache" >
		<Process Path="*\smartgit\bin\smartgit.exe" />
	</File>
	<File Id="{FD946AE3-0DF1-4A20-8C56B046E55282AB}" FilePath="*.common.services\*.cache" >
		<Process Path="*\microsoft vs code\code.exe" />
	</File>
	<File Id="{AC4B4A76-7353-539C-681811C9DAB1763E}" FilePath="*.common.services\*.cs" >
		<Process Path="*\mingw64\bin\git.exe" />
	</File>
	<File Id="{C0694262-3384-D0CC-F24F04AD650E2700}" FilePath="*.common.services\*.cs" >
		<Process Path="*\smartgit\bin\smartgit.exe" />
	</File>
	<File Id="{8F2259B6-23E9-41FD-4CAD7047E40D5851}" FilePath="*.common.services\*.cs" >
		<Process Path="*\microsoft vs code\code.exe" />
	</File>
	<File Id="{D75A4CF8-567D-EDAC-962A810A0B340977}" FilePath="*.common.services\*.tmp" >
		<Process Path="*\mingw64\bin\git.exe" />
	</File>
	<File Id="{5A57945E-E314-5931-A6C9CEAC114FB1CA}" FilePath="*.common.services\*.tmp" >
		<Process Path="*\smartgit\bin\smartgit.exe" />
	</File>
	<File Id="{1B081D85-AEFC-B79E-96361365DC0C8271}" FilePath="*.common.services\*.tmp" >
		<Process Path="*\microsoft vs code\code.exe" />
	</File>
	<File Id="{9301F703-7276-1822-4508DE8355B0E487}" FilePath="*\microsoft\office\*.cache" >
		<Process Path="*\office16\lync.exe" />
	</File>
	<File Id="{B5AE831B-F78B-FA40-DBE43CE6BAD79DE4}" FilePath="*\microsoft\onedrive\logs\common\*odl" >
		<Process Path="*\filecoauth.exe" />
	</File>
	<File Id="{977178A4-766B-D1B6-2D8998DDF9B346C7}" FilePath="*microsoft*teams*previous-s1\*" >
		<Process Path="*teams*update*" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{FEAB044B-6F97-A308-80DDB347FEB64F2F}" FilePath="*\microsoft\tokenbroker\cache\*.tbres" >
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{2777F540-7708-E1A9-DB373F22746E37A4}" FilePath="*\microsoft\windows\actioncentercache\*_?????_?.???" >
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{CD5FAE27-878C-CC9D-25B9416A8AF5396B}" FilePath="*appdata\local\temp\???????.tmp" >
		<Process Path="c:\windows\system32\browser_broker.exe" />
	</File>
	<File Id="{0128D40E-CCB5-CA40-FEC7FD52BBE2FF25}" FilePath="*appdata\local\temp\etilqs_???????????????" >
		<Process Path="*\servicehub.roslyncodeanalysisservice32.exe" />
	</File>
	<File Id="{6EC9F802-5361-0D5C-925262E4C67C0C44}" FilePath="*appdata\local\temp\*" >
		<Process Path="*.setup.service\backgrounddownload.exe" />
	</File>
	<File Id="{93A25C0E-BFFA-4931-1B7D8E3DBFC726B4}" FilePath="*appdata\local\temp\hsperfdata_*" >
		<Process Path="*\bin\java.exe" />
	</File>
	<File Id="{3A0DEBBB-D03F-0637-C8596AF35A7466A6}" FilePath="*appdata\local\temp\interceptor(20*.log" >
		<Process Path="c:\windows\system32\searchprotocolhost.exe" />
	</File>
	<File Id="{B7CE98D1-25FA-F60D-77FBEA661266C514}" FilePath="*appdata\local\temp*mso????.tmp" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{FA10155F-F2F5-E7BE-FE7898E776D5C863}" FilePath="*appdata\local\temp*olk????.tmp" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E8FDEFD1-E7F2-7E12-70918CA6EF8FD550}" FilePath="*appdata\local\temp\nglclient_cc*.log" >
		<Process Path="*\libs\node.exe" />
	</File>
	<File Id="{C826FABE-AB1D-8C95-2C5191CE985A8DD5}" FilePath="*appdata\local\temp\outlook logging\*" >
		<Process Path="c:\windows\system32\cleanmgr.exe" />
	</File>
	<File Id="{5111345A-DBBB-4F57-1E457003BC906E5F}" FilePath="*appdata\local\temp\res????.tmp" >
		<Process Path="c:\windows\microsoft.net\framework\v*\vbc.exe" />
	</File>
	<File Id="{6E8EEB5E-D494-C12C-CCAF6DC51AE6E498}" FilePath="*appdata\local\temp\res????.tmp" >
		<Process Path="c:\windows\microsoft.net\framework\v*\cvtres.exe" />
	</File>
	<File Id="{050AE5E2-332A-B72D-C3376C6ADF889194}" FilePath="*appdata\local\temp\res????.tmp" >
		<Process Path="c:\windows\microsoft.net\framework\v*\csc.exe" />
	</File>
	<File Id="{1E85D3C3-8D51-48FE-19C1A0071042140C}" FilePath="*temp\res????.tmp" >
		<Process Path="c:\windows\microsoft.net\framework\v*\vbc.exe" />
	</File>
	<File Id="{268C6471-AF9B-DD6C-44055A965B602638}" FilePath="*temp\res????.tmp" >
		<Process Path="c:\windows\microsoft.net\framework\v*\cvtres.exe" />
	</File>
	<File Id="{0E19E678-7753-21BB-05D5E02A37A1826B}" FilePath="*temp\res????.tmp" >
		<Process Path="c:\windows\microsoft.net\framework\v*\csc.exe" />
	</File>
	<File Id="{5C8C28F6-CCAF-6E96-EC67A9EFF88D4591}" FilePath="*temp\tmp????.tmp" >
		<Process Path="c:\windows\microsoft.net\framework\v*\csc.exe" />
	</File>
	<File Id="{D961A0E8-A898-769C-FF9AE9A865C57528}" FilePath="*temp\tmp????.tmp" >
		<Process Path="*\bin\tcmpublisher.exe" />
	</File>
	<File Id="{720DD2A1-CC7B-057A-B74A1F8092580989}" FilePath="*appdata\local\temp\screentogif\recording\20*" >
		<Process Path="*\screentogif\screentogif.exe" />
	</File>
	<File Id="{575553DD-ADE8-C5A3-5E178F361335ECA0}" FilePath="*\local\temp\smartgit*" >
		<Process Path="*\smartgit\bin\smartgit.exe" />
	</File>
	<File Id="{9B88E373-2385-5896-5AE092A013B4E93C}" FilePath="*appdata\local\temp\tcd????.tmp\*" >
		<Process Path="*\office*\winword.exe" />
	</File>
	<File Id="{0DECC1C3-6CF0-AEE9-61A32D171CF24B4D}" FilePath="*appdata\local\temp\vertipaq_*" >
		<Process Path="*\office*\excel.exe" />
	</File>
	<File Id="{25247875-C3F3-5CC1-6A8A2AA0C3BBD354}" FilePath="*appdata\local\temp\vstfsbuild\*" >
		<Process Path="*\common*\ide\devenv.exe" />
	</File>
	<File Id="{71DE3CBC-AD05-AB73-BD25BB70B6EAC31D}" FilePath="*appdata\locallow\microsoft\windows\appcache\*" >
		<Process Path="c:\windows\system32\taskhostw.exe" />
	</File>
	<File Id="{B587C406-FCAE-0FC8-742AFCB596F1FE96}" FilePath="*appdata\locallow\microsoft\windows\appcache\*" >
		<Process Path="*\internet explorer\iexplore.exe" />
	</File>
	<File Id="{652AB0BD-CE70-0800-52023331E462BA95}" FilePath="*microsoft*teams*indexeddb\https_*.indexeddb.*" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{DC10F039-A2CC-2357-E2BD645070EE1108}" FilePath="*\mozilla\firefox\profiles\????????.default*\storage\*+++*" >
		<Process Path="*\mozilla firefox\firefox.exe" />
	</File>
	<File Id="{5C46D5AB-550E-7828-CE1E5B9CC529D52B}" FilePath="*\slack\*~rf*.tmp" >
		<Process Path="*\app*\slack.exe" />
	</File>
	<File Id="{3883593C-2B3D-B12C-52FE94FF8D808EBE}" FilePath="*\downloads\*\cache\*" >
		<Process Path="*\telegram\telegram.exe" />
	</File>
	<File Id="{A3ADA2DC-B2D5-3573-7094501429EA209A}" FilePath="*\kl.dts.tests\kl.dts.tests\*" >
		<Process Path="*\bin\msbuild.exe" />
	</File>
	<File Id="{17CC8DD4-C8D0-AA89-3E677E0D1CD31157}" FilePath="*\repos\functions\src\*" Operation="Delete" />
	<File Id="{2C3A8308-E7B7-B6F0-27527E43F8ECFC18}" FilePath="c:\windows\ccm\logs\*-??????.log" >
		<Process Path="c:\windows\system32\wbem\wmiprvse.exe" />
	</File>
	<File Id="{511FBC33-B3C5-9F8A-6E2F24846296DFEB}" FilePath="c:\windows\logs\*_???.etl" >
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{D545DB89-C139-8893-BAA58D2B35D04F3B}" FilePath="c:\windows\microsoft.net\framework64\v*\temporary asp.net files\root\*" >
		<Process Path="c:\windows\system32\inetsrv\w3wp.exe" />
	</File>
	<File Id="{E285C450-4B05-B605-7AFDFCADB26106A7}" FilePath="c:\windows\microsoft.net\framework64\v*\temporary asp.net files\webui\*" >
		<Process Path="c:\windows\system32\inetsrv\w3wp.exe" />
	</File>
	<File Id="{7BD456ED-60D1-0F93-FF0C6EFBE6D20B79}" FilePath="*temp\tcm_?-???????-?????_*" >
		<Process Path="c:\windows\system32\inetsrv\w3wp.exe" />
	</File>
	<File Id="{C48C103A-083E-B464-8B06697A8DBD927F}" FilePath="*\tcm_?-???????-?????.content*" >
		<Process Path="c:\windows\system32\inetsrv\w3wp.exe" />
	</File>
	<File Id="{73D57E31-93BE-74E3-637D9056D28FAD21}" FilePath="*\tcm_?-???????-?????.state*" >
		<Process Path="c:\windows\system32\inetsrv\w3wp.exe" />
	</File>
	<File Id="{A6295142-4851-926E-BC833D3F1E1FDB90}" FilePath="*\tcm_?-???????-?????\*" >
		<Process Path="c:\windows\system32\inetsrv\w3wp.exe" />
	</File>
	<File Id="{32C2D8A5-D44E-1A20-5F3D7E79042B5895}" FilePath="*\web\webui\webroot\thumbnailcache\*" >
		<Process Path="c:\windows\system32\inetsrv\w3wp.exe" />
	</File>
	<File Id="{D5DFA4F1-6E32-0D75-C2C83D719060A5A7}" FilePath="*temp\.opera\*" >
		<Process Path="*\opera\*\opera_autoupdate.exe" />
	</File>
	<File Id="{F6D00822-DBBD-5D1A-A23684CB58BF10BE}" FilePath="*temp\__psscriptpolicytest_????????.???.psm1" >
		<Process Path="*\microsoft monitoring agent\agent\monitoringhost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{7CEB0BB3-EE54-3B3F-DC880155A1F5EA48}" FilePath="*temp\__psscriptpolicytest_????????.???.psm1" >
		<Process Path="c:\windows\system32\remotefxvgpudisablement.exe" />
	</File>
	<File Id="{CA75DCF7-321C-F5C9-3E6CEC6997856AB3}" FilePath="*temp\__psscriptpolicytest_????????.???.ps1" >
		<Process Path="*\microsoft monitoring agent\agent\monitoringhost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{099922C4-0B0F-E053-C3912933EE885FDE}" FilePath="*temp\__psscriptpolicytest_????????.???.ps1" >
		<Process Path="c:\windows\system32\remotefxvgpudisablement.exe" />
	</File>
	<File Id="{BA5E6031-0BA8-7D9C-97F0BB9C4D0E5224}" FilePath="*temp\????????.???.ps1" >
		<Process Path="*\microsoft monitoring agent\agent\monitoringhost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{D06908FC-E7DD-7733-F9146D1EE3F6191E}" FilePath="*temp\????????.???.ps1" >
		<Process Path="c:\windows\system32\windowspowershell\v1.0\powershell.exe" />
	</File>
	<File Id="{7EEFB7A7-4EE9-E5FA-AA3B5AF33C1BE337}" FilePath="*temp\????????.???.ps1" >
		<Process Path="c:\windows\system32\remotefxvgpudisablement.exe" />
	</File>
	<File Id="{4DDA7FE0-5E44-BFEE-5E2E50663E29F2DA}" FilePath="*temp\????????.???.psm1" >
		<Process Path="*\microsoft monitoring agent\agent\monitoringhost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{49E620C9-D652-3FB5-AED0001B72AFCFE0}" FilePath="*temp\????????.???.psm1" >
		<Process Path="c:\windows\system32\windowspowershell\v1.0\powershell.exe" />
	</File>
	<File Id="{65A4A430-EE75-533B-1C9F3181ACC7FE34}" FilePath="*temp\????????.???.psm1" >
		<Process Path="c:\windows\system32\remotefxvgpudisablement.exe" />
	</File>
	<File Id="{C475F467-1D30-8ED3-63B0CC18DC94915D}" FilePath="*temp\????????\????????.?.cs" >
		<Process Path="*\microsoft monitoring agent\agent\monitoringhost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E5B19A99-731B-77C4-13B7F98FF5B5D8FD}" FilePath="*temp\????????\????????.?.cs" >
		<Process Path="c:\windows\system32\windowspowershell\v1.0\powershell.exe" />
	</File>
	<File Id="{A8B81057-1268-ED15-0B284BBD88695BB3}" FilePath="*temp\????????\????????.?.cs" >
		<Process Path="c:\windows\system32\remotefxvgpudisablement.exe" />
	</File>
	<File Id="{4A3B3887-E695-B665-505D80FFDB61A7A4}" FilePath="*temp\????????\????????.cmdline" >
		<Process Path="*\microsoft monitoring agent\agent\monitoringhost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{D0947266-1E1E-F9D6-1132464815FED0D6}" FilePath="*temp\????????\????????.cmdline" >
		<Process Path="c:\windows\system32\windowspowershell\v1.0\powershell.exe" />
	</File>
	<File Id="{A21FA8D3-28D6-8D58-765BEC51ABE2F27C}" FilePath="*temp\????????\????????.cmdline" >
		<Process Path="c:\windows\system32\remotefxvgpudisablement.exe" />
	</File>
	<File Id="{28C78B11-A121-89B1-17CCDAA7499471DB}" FilePath="*\eventing\database\d20*" >
		<Process Path="*\bin\java.exe" />
	</File>
	<File Id="{EFEFFF91-0781-CE59-D1E873361A136154}" FilePath="*\framework\ksc\common\*" >
		<Process Path="*\bin\msbuild.exe" />
	</File>
	<File Id="{12423FB5-FFAF-EB0E-4499D03E8AC4B571}" FilePath="*\framework\ksc\common\*" >
		<Process Path="*\common*\ide\devenv.exe" />
	</File>
	<File Id="{76DFEDD5-C705-64A0-9F51F86EB81746FB}" FilePath="*\framework\ksc\infrastructure\*" >
		<Process Path="*\bin\msbuild.exe" />
	</File>
	<File Id="{7ECFAADB-CE05-BFFD-5431576D158C4EFE}" FilePath="*\framework\ksc\infrastructure\*" >
		<Process Path="*\common*\ide\devenv.exe" />
	</File>
	<File Id="{51ED59C2-86CF-FE70-7CEF5BA17C086A8E}" FilePath="*\framework\ksc\suites\*" >
		<Process Path="*\bin\msbuild.exe" />
	</File>
	<File Id="{71EF7690-CDBA-2DCC-2A87B9CDA140A816}" FilePath="*\framework\ksc\suites\*" >
		<Process Path="*\common*\ide\devenv.exe" />
	</File>
	<File Id="{A289E4AA-67B0-31A5-4DFAD681275FEB94}" FilePath="*\framework\ksc\utilities\*" >
		<Process Path="*\bin\msbuild.exe" />
	</File>
	<File Id="{144BF265-2CE2-1D52-FDFBFB23FF143E08}" FilePath="*\framework\ksc\utilities\*" >
		<Process Path="*\common*\ide\devenv.exe" />
	</File>
	<File Id="{170226C1-3248-3533-C12BBE6B990128E2}" FilePath="*\temp\apache-tika-???????????????????.tmp" >
		<Process Path="*\bin\tcmsearchhost.exe" />
	</File>
	<File Id="{E14E579A-3853-2E35-554358DB8083313A}" FilePath="*\temp\*_????????.tmp" >
		<Process Path="*\bin\tcmsearchhost.exe" />
	</File>

<!-- ############################################################################################################### -->
<!-- Part 0002 START 2020-11-24T23:45:00.000Z-1606261549 -->
	<File Id="{D1A07D3C-BA90-7A41-296DBFAD5CD2369D}" FilePath="*microsoft*teams*transportsecurity" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{9F5E70B9-80C8-4613-DD5B57412A03BCC8}" FilePath="*appdata\local\microsoft\credentials\????????????????????????????????" >
		<Process Path="*system32\lsass.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{83ECCF8E-8FCC-C619-0462B0F3B3DD8A1F}" FilePath="*\google\drive\user_default\sync_config.db-???" >
		<Process Path="*\google\drive\googledrivesync.exe" >
			<Signature Subject="*Google*" />
		</Process>
	</File>
	<File Id="{B2896C25-5285-D918-5B2890115D090706}" FilePath="*\data\diagnostic.data\metrics.interim" >
		<Process Path="*\mongodb\server\?.?\bin\mongod.exe" />
	</File>
	<File Id="{DEA0914C-4E34-A564-7EEB1F2090CF7420}" FilePath="?:\programdata\kaspersky lab\tw????????-????-????-????-????????????" >
		<Process Path="*system32\windowspowershell\v1.0\powershell.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{F488AC87-7410-40EB-B3AAFFCF0FE5A4D1}" FilePath="?:\programdata\kaspersky lab\tw????????-????-????-????-????????????" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{46EF5125-3A87-E2BC-AB0C56DB41D5B580}" FilePath="*\ccm\logs\ccmsqlce.log" >
		<Process Path="*system32\wbem\wmiprvse.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{6367A77D-E363-071F-C0DE8EC4756BB1B2}" FilePath="*\ccm\logs\updatetrustedsites.log" >
		<Process Path="*\ccm\updatetrustedsites.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{B2C9DC22-4AC7-01FE-6FC7BEDFEE034961}" FilePath="*\synologydrive\data\db\sys.sqlite-journal" >
		<Process Path="*\synologydrive\synologydrive.app\bin\cloud-drive-ui.exe" />
	</File>
	<File Id="{FEC7808D-6E90-BC5F-E925C7A17E86644E}" FilePath="*\kasperskylab\adminkit\ss*.lck" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="*Kaspersky*" />
		</Process>
	</File>
	<File Id="{0569F9B5-44C7-EB84-95FE2BE5A8F7B89B}" FilePath="*\kasperskylab\adminkit\ss*dat" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="*Kaspersky*" />
		</Process>
	</File>
	<File Id="{CD6CE122-B5DD-4BEA-6BFF5AE876319B82}" FilePath="*\kasperskylab\adminkit\~*.lck" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="*Kaspersky*" />
		</Process>
	</File>
	<File Id="{FC0A0148-7531-677F-3BB71D550737E1F4}" FilePath="*\kasperskylab\adminkit\~*dat" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="*Kaspersky*" />
		</Process>
	</File>
	<File Id="{A5123FD7-37F5-ECDA-87AB3F5774FF9E3A}" FilePath="*appdata\local\temp\klsc-*.lck" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="*Kaspersky*" />
		</Process>
	</File>
	<File Id="{75436423-F336-8ABD-6FF0403B6798DA01}" FilePath="*appdata\local\temp\{????????-????-????-????-????????????}*" >
		<Process Path="*system32\searchprotocolhost.exe" CmdLine="*Global\*" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{01E77318-AA2F-8C96-B53FE450A4832872}" FilePath="*appdata\local\temp\????????????????????????????????.db-journal" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{5F7C71A3-38DB-CC6D-CD26F97F198830D6}" FilePath="*\monorepo\.gvfs\databases\modifiedpaths.dat*" >
		<Process Path="*\gvfs\gvfs.mount.exe" >
			<Signature Subject="*Kaspersky*" />
		</Process>
	</File>
	<File Id="{BBC3268B-FE9B-23BD-11ADDBD00BFE87F5}" FilePath="*\microsoft\windows\recent\customdestinations\????????????????.customdestinations-ms" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{66AEC675-D6B4-1D39-BE781C12E754A366}" FilePath="*\microsoft\windows\recent\customdestinations\*.customdestinations-ms" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*Google*" />
		</Process>
	</File>
	<File Id="{E8E70344-2995-BBB8-B48D001A9AB24DBE}" FilePath="*\google\drive\user_default\uploader.db-shm" >
		<Process Path="*\google\drive\googledrivesync.exe" >
			<Signature Subject="*Google*" />
		</Process>
	</File>
	<File Id="{75806E56-E21F-D0EC-5F05D6F384A89CB0}" FilePath="*\code\user\workspacestorage\????????????????????????????????\*" >
		<Process Path="*\programs\microsoft vs code\code.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{4A6D616F-FA10-DB8D-67EE849C00B2E2B8}" FilePath="*appdata\local\temp\vbcscompiler\analyzerassemblyloader\????????????????????????????????\*" >
		<Process Path="*\professional\msbuild\current\bin\roslyn\vbcscompiler.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{12DF602D-5F0C-169D-0BD6278169D843BF}" FilePath="*\microsoft.net\framework\v*\ngen.log" >
		<Process Path="*\microsoft.net\framework\v*\ngen.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{137A7D17-B844-5968-E98AF99316442C2B}" FilePath="?:\programdata\kasperskylab\adminkit\~*" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="*Kaspersky*" />
		</Process>
	</File>
	<File Id="{1C524C46-934C-A2F8-BA98F815EA9B706B}" FilePath="*\ccm\statemessagestore.sdf" >
		<Process Path="*system32\wbem\wmiprvse.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E625A3B5-8CB6-9516-2DA68AB63BAA77FB}" FilePath="*microsoft*teams*cs_skylib\cs_shared.*" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{78061CE0-9CF9-98AF-60D1C0607A44CFD1}" FilePath="?:\.gvfscache\????????????????????????????????\*" >
		<Process Path="*\gvfs\gvfs.mount.exe" >
			<Signature Subject="*Kaspersky*" />
		</Process>
	</File>
	<File Id="{2DC0A409-A0FB-1385-F5C5568CD40C14E7}" FilePath="*\mongodb\server\?.?\data\wiredtiger.turtle*" >
		<Process Path="*\mongodb\server\?.?\bin\mongod.exe" />
	</File>
	<File Id="{7F8CA65E-133E-DE72-3F2A20B8C805611A}" FilePath="?:\programdata\microsoft\network\downloader\edb.chk" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{F238B4A5-13DC-C395-86CDBFE01B3D4C7D}" FilePath="?:\programdata\microsoft\network\downloader\edb.log" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E8CAB247-4A52-DA41-AF38270B8AC53C7D}" FilePath="?:\programdata\microsoft\network\downloader\qmgr.jfm" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{7A3E8E3E-B79A-BA5C-269C4C64A3B53FE6}" FilePath="?:\programdata\usoprivate\updatestore\store.db-journal" >
		<Process Path="*system32\mousocoreworker.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{6E9F827F-1433-34DA-47C73A9BFC68E285}" FilePath="?:\programdata\usoprivate\updatestore\updatestore*.xml" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{813B0042-7643-B85F-9BEEBED15EE6EF57}" FilePath="*\monorepo\.gvfs\gitstatuscache\gitstatuscache.dat" >
		<Process Path="*\gvfs\gvfs.mount.exe" >
			<Signature Subject="*Kaspersky*" />
		</Process>
	</File>
	<File Id="{6DAB5C14-767D-9124-2E79C982CE72AC16}" FilePath="*\dropbox\instance1\config.dbx-journal" >
		<Process Path="*\dropbox\bin\dropbox.exe" >
			<Signature Subject="*Google*" />
		</Process>
	</File>
	<File Id="{C80F0526-42E1-2935-9522FC8EC41F1C7A}" FilePath="*\google\drive\user_default\uploader.db-wal" >
		<Process Path="*\google\drive\googledrivesync.exe" >
			<Signature Subject="*Google*" />
		</Process>
	</File>
	<File Id="{66EB5BA2-E301-E23A-1E1E61522B21F3D2}" FilePath="*\microsoft\office\otele\{????????-????-????-????-????????????*" >
		<Process Path="*\office*\excel.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{2369B496-BEFE-5191-223DFD6DFFF82960}" FilePath="*\microsoft\windows\webcache\*.chk" >
		<Process Path="*system32\taskhostw.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{980ACABD-0A7B-0E33-672BD9B0616A364B}" FilePath="*\microsoft\cryptneturlcache\metadata\????????????????????????????????" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{8FE85F22-5A44-6766-CEBE5E9AB409CEDB}" FilePath="*\spotify\browser\????????????????????????????????????????\*" >
		<Process Path="*\spotify\spotify.exe" >
			<Signature Subject="*Spotify*" />
		</Process>
	</File>
	<File Id="{43616288-1905-2AB6-23867B0E86B0B3C1}" FilePath="*appdata\local\temp\????????-????-????-????-????????????" >
		<Process Path="*\programs\microsoft vs code\code.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{C7DD259C-A550-750C-86E99E9223A1F9BF}" FilePath="*appdata\local\temp\casesensitivetest????????????????????????????????" >
		<Process Path="*\professional\msbuild\current\bin\msbuild.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{249393E2-AC5B-EE89-C7B361160D4806F1}" FilePath="*\microsoft\skype for desktop\transportsecurity" >
		<Process Path="*\microsoft\skype for desktop\skype.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{BFB48EAC-4719-867E-4739E76AF48E5E9F}" FilePath="*microsoft*teams*network persistent state*" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{B6881F6C-9105-097A-A611C8E91F876BCF}" FilePath="*microsoft*teams*settings.json" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{3235677E-F4AE-21CA-2A6F8AE855C2F2B3}" FilePath="*microsoft*teams*settings.json.__new__" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{BB42885C-24C3-758A-56A8ACAE9BB7FE78}" FilePath="*microsoft*teams*skypert\ecs.conf" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{3F77578D-252E-BC38-F6BD1F48B4075E3B}" FilePath="*microsoft*teams*skypert\ecs.tmp" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{D317D2F9-C3AD-A625-446047EE0FCCAD97}" FilePath="*microsoft*teams*skypert\persistent.*" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{8F6BEF73-BBF8-8793-9535D8E91D40A96B}" FilePath="*microsoft*teams*storage.json" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{97E4BC9F-572A-E7A1-9D187D0FD049A1C1}" FilePath="*\microsoft\windows\recent\customdestinations\????????????????.customdestinations-ms" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*Mozilla*" />
		</Process>
	</File>
	<File Id="{2E88628B-85C3-63FB-278E0E22314C419A}" FilePath="*\mozilla\firefox\profiles\????????.default\permissions.sqlite-journal" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*Mozilla*" />
		</Process>
	</File>
	<File Id="{55C81653-4D76-B13D-89C72DAE924A4C88}" FilePath="*\mozilla\firefox\profiles\????????.default\sessionstore-backups\recovery.*" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*Mozilla*" />
		</Process>
	</File>
	<File Id="{E784ED36-C733-AF11-2F4AE27DADC16862}" FilePath="*\mozilla\firefox\profiles\7xbmxnsj.default\storage\permanent\chrome\idb\*.sqlite-shm" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*Mozilla*" />
		</Process>
	</File>
	<File Id="{C4F0372D-E79C-87DA-5F1AFBD23009FA8F}" FilePath="*\mozilla\firefox\profiles\????????.default-release\prefs*.js" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*Mozilla*" />
		</Process>
	</File>
	<File Id="{CCA14E25-CF81-9C47-596CFEA0CE3D7582}" FilePath="*\slack\????????-????-????-????-????????????.tmp" >
		<Process Path="*\app*\slack.exe" >
			<Signature Subject="*Slack*" />
		</Process>
	</File>
	<File Id="{21F2FDCC-01A6-F790-C892CE3985B14F01}" FilePath="*\slack\transportsecurity" >
		<Process Path="*\app*\slack.exe" >
			<Signature Subject="*Slack*" />
		</Process>
	</File>
	<File Id="{7B3CF567-7273-3B3D-A1E7DB46F4CA0D7A}" FilePath="*documents*.pst.tmp" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{F63A31E2-2091-A7A1-C6F09D3382E108DE}" FilePath="*outlook*.pst.tmp" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{07D2CA46-51D8-DC2E-D1AC38EE262DC66C}" FilePath="*\microsoft.net\framework\v*\ngenrootstorelock.dat" >
		<Process Path="*\microsoft.net\framework\v*\ngen.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{00815892-408D-8419-F413CC504DF43ECF}" FilePath="*\microsoft.net\framework64\v*\ngen.log" >
		<Process Path="*\microsoft.net\framework64\v*\ngen.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{2FF97E0D-8FFB-958F-6C1F0157214A2D74}" FilePath="*\microsoft.net\framework64\v*\ngenrootstorelock.dat" >
		<Process Path="*\microsoft.net\framework64\v*\ngen.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{B443103D-A023-E1B4-B187036842853715}" FilePath="*\microsoft.net\ngennicupdatelock.dat" >
		<Process Path="*\microsoft.net\framework\v*\ngen.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{BC42F24B-5B46-642D-872FCCBBD6C8DE55}" FilePath="*\microsoft.net\ngennicupdatelock.dat" >
		<Process Path="*\microsoft.net\framework64\v*\ngen.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{D22957A3-EFDC-EE33-CB5D20B10405B3D4}" FilePath="*\serviceprofiles\ksnproxy\appdata\local\temp\klsc-*.lck" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="*kaspersky*" />
		</Process>
	</File>
	<File Id="{2567BF99-8504-1650-899E73E832D4FC4D}" FilePath="*\serviceprofiles\localservice\appdata\local\fontcache\~fontcache-*.dat" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{2594B6CA-7C51-F240-93F4411AFC2C3880}" FilePath="*\serviceprofiles\localservice\appdata\local\fontcache\fontcache-*.dat" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{33CA261D-755A-D573-E97CA1D17E076E9D}" FilePath="*\serviceprofiles\localservice\appdata\local\intel\dptf\dptf.dv" >
		<Process Path="*system32\wudfhost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{D951641A-0388-EE9F-1DD3844AE5688099}" FilePath="*\softwaredistribution\datastore\datastore.jfm" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{84CDA9D5-76FC-0200-3B5DCEF225906F3D}" FilePath="*\softwaredistribution\datastore\logs\edb.chk" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{CE418AD5-68E1-8621-ECB8A1D5EFA1B8A7}" FilePath="*\softwaredistribution\datastore\logs\edb.log" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{19AD0C6C-CE30-4EA4-020A3C79A5A4B6AB}" FilePath="*system32\appmgmt\machine\appmgmt.ini" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{25251EF8-B3F6-D8CA-295AD29AEBFB589F}" FilePath="*system32\appmgmt\s-1-*\appmgmt.ini" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{1B3C087B-6FB8-BD3C-2BB1E6F0D3536E10}" FilePath="*system32\catroot\{????????-????-????-????-????????????*" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{1D6F3D74-6707-D6D2-755F51270550A574}" FilePath="*system32\tasks\configmgr client health script*" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{05FEC684-B48B-AE9E-8BBB362CC9EBA7C8}" FilePath="?:\windows\windowsupdate.log" >
		<Process Path="*system32\svchost.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{74D95E97-2D95-A197-6A3D18A00D515DBD}" FilePath="*system32\spool\drivers\x64\{????????-????-????-????-????????????*" >
		<Process Path="*system32\spoolsv.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{4CB71675-36EC-4828-8B305B9696E6233A}" FilePath="?:\windows\temp\klsc-*\crlstore.lck" >
		<Process Path="*\kaspersky lab\networkagent\up2date.exe" >
			<Signature Subject="*kaspersky*" />
		</Process>
	</File>

<!-- Part 0002 END2020-11-24T23:45:00.000Z-1606261549 -->

<!-- ############################################################################################################### -->
<!-- Part 0003 START 2020-11-29T20:08:00.000Z-1606680524 -->
	<File Id="{A38B32AA-4E0B-5D5A-BC2FFC569B6AE44F}" FilePath="*.git\hooks\pre-push" >
		<Process >
			<Signature Subject="*git*" />
		</Process>
	</File>
	<File Id="{E6502D05-97C2-72A6-DC39DB6041466BE7}" FilePath="*.git\hooks\post-commit" >
		<Process >
			<Signature Subject="*git*" />
		</Process>
	</File>
	<File Id="{3B1233D9-1F44-B147-3E22DE1D0923D2B0}" FilePath="*.git\hooks\post-checkout" >
		<Process >
			<Signature Subject="*git*" />
		</Process>
	</File>
	<File Id="{1DC73555-76D0-5C94-99C4288F99AF7D52}" FilePath="*.git\hooks\post-merge" >
		<Process >
			<Signature Subject="*git*" />
		</Process>
	</File>
	<File Id="{95F44750-6B09-3E87-CB55922B5ABE0AE4}" FilePath="*.git\lfs\cache\locks\refs\heads\master\verifiable" >
		<Process >
			<Signature Subject="*git*" />
		</Process>
	</File>
	<File Id="{7B4E59A7-2293-72F5-B517CC519D19BEA5}" FilePath="*.gvfscache\????????????????????????????????\lfs\incomplete\?????????????????????????????????????????????????????????????????????????" >
		<Process >
			<Signature Subject="*git*" />
		</Process>
	</File>
	<File Id="{F6DDF0D8-F06C-E4DB-1994FC89F02596CA}" FilePath="*.gvfscache\????????????????????????????????\lfs\objects\??\??\????????????????????????????????????????????????????????????????" >
		<Process >
			<Signature Subject="*git*" />
		</Process>
	</File>
	<File Id="{4B574F4C-278F-E61F-6357BF73A84E1AAD}" FilePath="*appdata\local\temp\bloomberg\bb2cache\rec??????\????????-????-????-????-????????????" >
		<Process >
			<Signature Subject="*Bloomberg*" />
		</Process>
	</File>
	<File Id="{FCE92004-D6D4-BED7-B4917EDAF3997DE1}" FilePath="*appdata\local\temp\bloomberg\bb2cache\var???????\????????-????-????-????-????????????" >
		<Process >
			<Signature Subject="*Bloomberg*" />
		</Process>
	</File>
	<File Id="{5085DEB8-A7B6-0437-DA66465AB3CDE716}" FilePath="*appdata\local\temp\bloomberg\log\bplus.20??????.e.log" >
		<Process >
			<Signature Subject="*Bloomberg*" />
		</Process>
	</File>
	<File Id="{3D0651B6-38D4-E97D-1DE4CBBB21B9F4F4}" FilePath="*appdata\local\temp\bloomberg\log\rpdiag.p.20??????.log" >
		<Process >
			<Signature Subject="*Bloomberg*" />
		</Process>
	</File>
	<File Id="{6E91DE70-7A65-22FD-3AD7BCE70CB264AF}" FilePath="*\documents\endpoint.teststarter\data\state.cfg" >
		<Process Path="*\endpoint.teststarter.exe" />
	</File>
	<File Id="{39C0FD78-EB7C-4C23-D1FCCB7A4F94F809}" FilePath="*\documents\endpoint.teststarter\data\state.cfg.bak" >
		<Process Path="*\endpoint.teststarter.exe" />
	</File>
	<File Id="{D29072E6-F250-27D6-54AA69464C310393}" FilePath="*\documents\endpoint.teststarter\data\state_temp.cfg" >
		<Process Path="*\endpoint.teststarter.exe" />
	</File>
	<File Id="{46A576BE-A1A1-DE19-A193B91D8DA36AB5}" FilePath="*\localstate\accountsroot\????????????????????????????????\todosqlite.db-???" >
		<Process Path="*system32\backgroundtaskhost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{59BE9CAB-A03C-8A1C-6247DB2D3CF5EE93}" FilePath="*\localstate\syncbackground*" >
		<Process Path="*system32\backgroundtaskhost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{BDDFCA99-3A8A-CB2A-8730A9C96D21D249}" FilePath="*.sdltm-journal" >
		<Process Path="*\SDL Trados Studio\Studio?\SDLTradosStudio.exe" CmdLine="*/openProject*.sdlproj*" >
			<Signature Subject="*Trados*" />
		</Process>
	</File>
	<File Id="{C7827BC0-471A-E5A2-BE19E8F71FC14A6F}" FilePath="*.sdltm" >
		<Process Path="*\SDL Trados Studio\Studio?\SDLTradosStudio.exe" CmdLine="*/openProject*.sdlproj*" >
			<Signature Subject="*Trados*" />
		</Process>
	</File>
	<File Id="{ED748DEA-2A09-3122-0BE291037A586465}" FilePath="*.sdlxliff" >
		<Process Path="*\SDL Trados Studio\Studio?\SDLTradosStudio.exe" CmdLine="*/openProject*.sdlproj*" >
			<Signature Subject="*Trados*" />
		</Process>
	</File>
	<File Id="{C381F58C-BA4A-6703-8456A1E88781CE15}" FilePath="*appdata\local\temp\????????.???\????????.???.html" >
		<Process Path="*\SDL Trados Studio\Studio?\SDLTradosStudio.exe" CmdLine="*/openProject*.sdlproj*" >
			<Signature Subject="*Trados*" />
		</Process>
	</File>
	<File Id="{452FCA31-8E5B-4B63-3314853074E151CC}" FilePath="*appdata\local\temp\sdltempfileregen\????????.???" >
		<Process Path="*\SDL Trados Studio\Studio?\SDLTradosStudio.exe" CmdLine="*/openProject*.sdlproj*" >
			<Signature Subject="*Trados*" />
		</Process>
	</File>
	<File Id="{F36AC379-5C26-2566-C03B21AB20C011BE}" FilePath="*appdata\local\temp\tmp*.tmp" >
		<Process Path="*\SDL Trados Studio\Studio?\SDLTradosStudio.exe" CmdLine="*/openProject*.sdlproj*" >
			<Signature Subject="*Trados*" />
		</Process>
	</File>
	<File Id="{7CFA5901-14A4-B441-AB9F5F767DEEABD5}" FilePath="*appdata\local\temp\cubeb-shm-*-*put" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{DF98CFCF-2EEB-9F17-51A1A06E392B1633}" FilePath="*appdata\local\temp\cubeb-shm-*-*put" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{5E52E82F-3147-E5AC-E728217F42E362B2}" FilePath="*appdata\local\temp\cubeb-shm-*-*put" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{42B4E527-962F-EBB3-A7E98422754F919D}" FilePath="*microsoft\windows\recent\customdestinations\????????????????????.temp" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{C9456F75-063C-5A92-BB768E18B3C1CCA3}" FilePath="*microsoft\windows\recent\customdestinations\????????????????????.temp" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{3F9D4E61-A579-D20B-48F80D8A6B39D897}" FilePath="*microsoft\windows\recent\customdestinations\????????????????????.temp" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{2054F880-3D5D-3003-D3F17C97F75FD46F}" FilePath="*microsoft\windows\recent\customdestinations\????????????????.customdestinations-ms~rf*.tmp" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{5A21F522-61DB-6996-2D1EACDC82B75E9C}" FilePath="*microsoft\windows\recent\customdestinations\????????????????.customdestinations-ms~rf*.tmp" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{349AABD9-F9A1-EF90-87A4701D52535364}" FilePath="*microsoft\windows\recent\customdestinations\????????????????.customdestinations-ms~rf*.tmp" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{738B7F76-5C18-3BC2-F7858FD61E52CEF7}" FilePath="*\mozilla\firefox\profiles\*.sqlite-shm" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{6D526BFD-3A4A-AF13-10F23E97231C7999}" FilePath="*\mozilla\firefox\profiles\*.sqlite-shm" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{373186F1-1FD8-C559-3EF7F2BDB85EF8B0}" FilePath="*\mozilla\firefox\profiles\*.sqlite-shm" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{E445F61A-57DD-17EE-19FCB6DF2A9E0913}" FilePath="*\profile*\cache2\doomed\???" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{73C892C7-3F17-C777-190F35C16C017CE3}" FilePath="*\profile*\cache2\doomed\???" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{EF9A3BA2-1337-79EA-9721B553D8B0BBED}" FilePath="*\profile*\cache2\doomed\???" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{4C56AD97-B7CC-0AE5-09F7895F079472BB}" FilePath="*\profile*\cache2\doomed\????" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{B1B539EF-5E44-730F-FC732EF09E2AC41C}" FilePath="*\profile*\cache2\doomed\????" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{62D6BF77-E4E9-97FC-B79C839B73A4FB80}" FilePath="*\profile*\cache2\doomed\????" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{3F35575F-D6BB-C28F-F2C7C038CF2080AA}" FilePath="*\profile*\cache2\doomed\?????" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{AD0EFC5A-095C-B1BB-0A2E99DD5E4C3E47}" FilePath="*\profile*\cache2\doomed\?????" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{9501F871-BA1D-46AB-981EDE5F74E1AEA5}" FilePath="*\profile*\cache2\doomed\?????" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{573FE18A-1739-FC4D-4F52FE480171E668}" FilePath="*\profile*\cache2\entries\????????????????????????????????????????" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{A31EE1F5-C293-DC4B-30C15EE92E9035BB}" FilePath="*\profile*\cache2\entries\????????????????????????????????????????" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{53BCB272-97BB-60C4-1F799032950B526F}" FilePath="*\profile*\cache2\entries\????????????????????????????????????????" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{8DD0B54B-A058-0ACC-ACEF3B98FC535721}" FilePath="*\profile*\storage\*.files\?????" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{0D4AAEF2-2C48-76F1-A24796EE352FE8B2}" FilePath="*\profile*\storage\*.files\?????" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{348ADDF7-A2B8-0B31-E57964963FD2E6D2}" FilePath="*\profile*\storage\*.files\?????" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{1B865175-B277-92DD-FDE83B0D7E77442F}" FilePath="*\profile*\storage\*.files\journals\?????" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{938115E2-ED68-F8A6-EA1641F76CCFDB90}" FilePath="*\profile*\storage\*.files\journals\?????" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{D0041343-54BB-2527-D8D27CCE710F9EEE}" FilePath="*\profile*\storage\*.files\journals\?????" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{DD2FD106-C84E-6639-FC10CF4C4ACC1F28}" FilePath="*\profile*\storage\*.sqlite" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{E08C5FA3-487B-68A7-CD8174314D3C52EB}" FilePath="*\profile*\storage\*.sqlite" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{7E0EE9BF-559E-1BF1-4C974F47901E3F70}" FilePath="*\profile*\storage\*.sqlite" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{87BE8804-38B1-06B1-D82E8BBFC3E612DC}" FilePath="*\profile*\storage\*.sqlite-???" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{5EDC83B5-2744-D4C8-4687197C94AF6CBA}" FilePath="*\profile*\storage\*.sqlite-???" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{BBC2A9B4-8D55-0B75-5DEEF1A7263FE679}" FilePath="*\profile*\storage\*.sqlite-???" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{41409FE1-F5FF-89A6-44C04E020F90074B}" FilePath="*\profile*\sessionstore-backups\recovery.*" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{B9B25E63-35D9-857C-8A3B7B875B9CB555}" FilePath="*\profile*\sessionstore-backups\recovery.*" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{B46DEB5D-4FB0-AC8E-E49C626A0DB8BBA7}" FilePath="*\profile*\sessionstore-backups\recovery.*" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{D2ED70F8-1F9D-25B7-369A5B7AE7ED513B}" FilePath="*\mozilla\firefox\profile*.sqlite-*" >
		<Process Path="*\mozilla firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{4AB05792-815F-79DB-B031A88A04EC6FC1}" FilePath="*\mozilla\firefox\profile*.sqlite-*" >
		<Process Path="*\firefox\app\firefox64\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{469F6B78-66D3-C085-B57E2D285AC5392F}" FilePath="*\mozilla\firefox\profile*.sqlite-*" >
		<Process Path="*\firefoxportable\app\firefox\firefox.exe" >
			<Signature Subject="*mozilla*" />
		</Process>
	</File>
	<File Id="{6D407298-E70E-62E9-E77DD89E8FEE15D9}" FilePath="*microsoft\windows\explorer\iconcache_16.db" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{F3AFD3E3-D54B-2F07-9649C3A913346475}" FilePath="*microsoft\windows\explorer\iconcache_16.db" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{A6E2D8B1-0179-68BC-A70464FAECA5CA81}" FilePath="*microsoft\windows\explorer\iconcache_idx.db" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{0ED8F106-D4AB-EFD4-536133FE7AB0930B}" FilePath="*microsoft\windows\explorer\iconcache_idx.db" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{C9D141E2-7838-3559-A4A13736444DEC56}" FilePath="*appdata\local\temp\?????_??????????\images\icon*.png" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{A66E137B-7E33-83B5-7D3AC8F7031039A1}" FilePath="*appdata\local\temp\?????_??????????\images\icon*.png" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{8B292D2D-19E5-FC16-8E485A678721B2DD}" FilePath="*appdata\local\temp\?????_??????????\images\icon*.svg" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{A6A6B63A-D987-B104-55FA659F66EB94EC}" FilePath="*appdata\local\temp\?????_??????????\images\icon*.svg" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{CA47F770-6E1D-DA87-8FDEB66BF7E2963A}" FilePath="\appdata\local\temp\chrome_bits_????*_*.crxd" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{A85CA771-9935-82A5-7B9F7835A74FD02E}" FilePath="\appdata\local\temp\chrome_bits_????*_*.crxd" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{620D7154-1FE8-2A7D-923707978D300330}" FilePath="*microsoft\cryptneturlcache\content\????????????????????????????????_????????????????????????????????" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{530964D4-5CAE-2E1F-BB606F87FECCF046}" FilePath="*microsoft\cryptneturlcache\content\????????????????????????????????_????????????????????????????????" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{BCEDFC82-362E-ADA0-AAE7C6CD125DC48A}" FilePath="*microsoft\tokenbroker\cache\????????????????????????????????????????.tbres" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{0BD25B47-ED3E-0841-A4E33A0593EEC44B}" FilePath="*microsoft\tokenbroker\cache\????????????????????????????????????????.tbres" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{06CC4139-A4F1-551E-B23F77E4DCA2CD61}" FilePath="*microsoft\windows\explorer\iconcache_*.db" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{6FC1CFC9-2A1E-18B9-B3B5659CF22F4642}" FilePath="*microsoft\windows\explorer\iconcache_*.db" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{931A3510-276D-CCA7-12793D2E27075741}" FilePath="*microsoft\windows\explorer\iconcachetodelete\icne*.tmp" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{F754C949-0F6A-AF36-2A89ECE1C0B14BE2}" FilePath="*microsoft\windows\explorer\iconcachetodelete\icne*.tmp" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{5F975990-7F73-3058-4846C295C8537E97}" FilePath="?:\users\*\downloads\unconfirmed *.crdownload" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{D6296381-C108-A9F9-5269E89CE6C10842}" FilePath="?:\users\*\downloads\unconfirmed *.crdownload" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{81081594-4AED-ACED-8CE9FC167157C1B3}" FilePath="*\nvidia corporation\drs\nvapptimestamps" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{AF5CB52C-2BB0-6664-1F01E304E7ECEF05}" FilePath="*\nvidia corporation\drs\nvapptimestamps" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{589F7663-7E4C-9B37-B2358094B2E28C05}" FilePath="*appdata\local\temp\????*_????????*\??" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{DD1C2AE5-F235-D7E3-1A3DD4F8D7E9E45C}" FilePath="*appdata\local\temp\????*_????????*\??" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{4E48900F-3BD4-8A91-D2D365A3D625CF1F}" FilePath="*appdata\local\temp\????*_????????*\*_*.js" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{39BDD4A2-5D58-14D7-F28ACC8248DD2BE2}" FilePath="*appdata\local\temp\????*_????????*\*_*.js" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{BC110DDE-4CDF-4382-0ED40323283DBE37}" FilePath="*appdata\local\temp\????*_????????*\*_*.json" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{135C44BA-3F2E-C703-9F2FD02D4E78359C}" FilePath="*appdata\local\temp\????*_????????*\*_*.json" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{8AE2A46C-09CB-EC3B-B49ED7D85D0D3E4D}" FilePath="*appdata\local\temp\????*_????????*\commands.json" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{D8A49F22-CB84-F60E-EBB0A6A373FF4218}" FilePath="*appdata\local\temp\????*_????????*\commands.json" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{EF069325-4365-9576-51B16B01CD4B3462}" FilePath="*appdata\local\temp\????*_????????*\license" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{50E10C88-42FD-A755-91C0F208828EBD74}" FilePath="*appdata\local\temp\????*_????????*\license" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{46E8046C-7416-A4C2-99BB57F7B4EE84AE}" FilePath="*appdata\local\temp\????*_????????*\manifest.fingerprint" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{3039AEAC-4757-5E9B-CEC8EA37F1694B3D}" FilePath="*appdata\local\temp\????*_????????*\manifest.fingerprint" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{BA1002D3-D7DC-4A09-6995884FCFD7DFC3}" FilePath="*appdata\local\temp\????*_????????*\manifest.json" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{E043E701-76AC-4879-88A5F2EA3F1D247C}" FilePath="*appdata\local\temp\????*_????????*\manifest.json" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{1BA4C747-67A2-417E-1723B405FF44158F}" FilePath="*appdata\local\temp\scoped_dir????*_????????*" >
		<Process Path="*\google\chrome\application\*\installer\setup.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{F625B013-5351-B933-F1AC1174E8B22D7C}" FilePath="*appdata\local\temp\scoped_dir????*_????????*" >
		<Process Path="*\google\chrome\application\chrome.exe" >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{07EC2A03-547C-2B59-7078ECB393F0849C}" FilePath="*microsoft\windows\explorer\iconcache_16.db" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{852F1ECE-0C8B-7BF2-E58907D7F960E4CA}" FilePath="*microsoft\windows\explorer\iconcache_idx.db" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A49AE9EE-D60A-AFA6-257EDCF86F51162D}" FilePath="*appdata\local\temp\?????_??????????\images\icon*.png" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C8474AA5-48B1-D0F6-AAFB2426535CC66D}" FilePath="*appdata\local\temp\?????_??????????\images\icon*.svg" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D00DB841-84E5-BE64-211E290F5B01D142}" FilePath="\appdata\local\temp\chrome_bits_????*_*.crxd" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7EF2D400-2E29-378E-B41B103DEF3B682B}" FilePath="*microsoft\cryptneturlcache\content\????????????????????????????????_????????????????????????????????" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F05E3CE7-0412-51C9-A58F50ED23097D8D}" FilePath="*microsoft\tokenbroker\cache\????????????????????????????????????????.tbres" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{502A40B8-C5BD-4284-EAD0B2D0C1F0F2D5}" FilePath="*microsoft\windows\explorer\iconcache_*.db" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7208F59C-5C34-465A-CFEAB5235A88BA21}" FilePath="*microsoft\windows\explorer\iconcachetodelete\icne*.tmp" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{3674F3E4-CF40-0B74-8A02263A80214A72}" FilePath="?:\users\*\downloads\unconfirmed *.crdownload" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0167A863-6A83-379F-27E6541B9E6AB6F0}" FilePath="*\nvidia corporation\drs\nvapptimestamps" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{732CE60F-A9B8-D79B-5D9DD2DF641CE0CC}" FilePath="*appdata\local\temp\????*_????????*\??" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{266D5D87-DDDD-3A2D-884E6F43ED0DFB2F}" FilePath="*appdata\local\temp\????*_????????*\*_*.js" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{998E937B-4AE0-5B01-3A202796687A6FB4}" FilePath="*appdata\local\temp\????*_????????*\*_*.json" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{19E55BE4-9962-3C09-0C095EB329324DC4}" FilePath="*appdata\local\temp\????*_????????*\commands.json" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{51C3082D-8930-09F7-E598B94FB6CDBA17}" FilePath="*appdata\local\temp\????*_????????*\license" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B8B2B05C-CE64-C51B-FB9A7B4661633D8D}" FilePath="*appdata\local\temp\????*_????????*\manifest.fingerprint" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{05F4A54D-0354-46F3-2C5DF8235375EFD2}" FilePath="*appdata\local\temp\????*_????????*\manifest.json" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0805F49F-1E33-A501-4AD4E8DA41B371DC}" FilePath="*appdata\local\temp\scoped_dir????*_????????*" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{421F9077-8490-FD0E-91542D5C816B4D89}" FilePath="*\cache\?_??????" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B80D175E-4E6F-CB8F-2AACAAA9D07E6CF8}" FilePath="*code cache\js\????????????????_?" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{EDB92A32-39C1-2C4A-1AF61CE4501F4492}" FilePath="*appdata\local\temp\*\*~rf*.tmp" >
		<Process Path="*microsoft\edge*\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{862D0CBD-E0E6-7920-6032EC5A60EB198D}" FilePath="*microsoft\windows\explorer\iconcache_16.db" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{4276B1B5-F7EC-6765-62B4D1C07FD78495}" FilePath="*microsoft\windows\explorer\iconcache_idx.db" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{74387AC8-6D69-BE88-9519E1863295708A}" FilePath="*appdata\local\temp\?????_??????????\images\icon*.png" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{40576963-DCA1-3F27-C885471D1EB78955}" FilePath="*appdata\local\temp\?????_??????????\images\icon*.svg" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{FA542AAA-A1F7-2F48-3E2ECF1B6A5327B0}" FilePath="\appdata\local\temp\chrome_bits_????*_*.crxd" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{158B2A95-92B9-B2E4-9CA35495421D459F}" FilePath="*microsoft\cryptneturlcache\content\????????????????????????????????_????????????????????????????????" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{CC4FA8D4-0458-6BEF-3A1FDEB8063093CA}" FilePath="*microsoft\tokenbroker\cache\????????????????????????????????????????.tbres" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{D1672615-DA12-BC41-13E1F844BB416F41}" FilePath="*microsoft\windows\explorer\iconcache_*.db" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{FAE2B2AD-AE8B-601A-08DE43418D17B562}" FilePath="*microsoft\windows\explorer\iconcachetodelete\icne*.tmp" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{B93B81ED-1C61-B13F-50EAA989E89FEEE1}" FilePath="?:\users\*\downloads\unconfirmed *.crdownload" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{612D2E26-082F-0AF9-B0B6AE8A44118A48}" FilePath="*\nvidia corporation\drs\nvapptimestamps" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{0092E39E-3DE6-0CD8-8F2D4A6ABC838544}" FilePath="*appdata\local\temp\????*_????????*\??" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{8D25BFE8-BCB7-E00E-2556E0777826D3D7}" FilePath="*appdata\local\temp\????*_????????*\*_*.js" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{FF26B46A-AD97-848C-7EF6DB1A34EC827F}" FilePath="*appdata\local\temp\????*_????????*\*_*.json" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{DABDFEE2-7D9F-ED26-F3460A18B2B43733}" FilePath="*appdata\local\temp\????*_????????*\commands.json" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{9C576CFD-E86A-C9DD-BBDCBBC588F5AE10}" FilePath="*appdata\local\temp\????*_????????*\license" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{FE4168FE-63C3-A278-B1F6DAFE2F0E1A8D}" FilePath="*appdata\local\temp\????*_????????*\manifest.fingerprint" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{F605FD71-2F28-08DF-2EB189CF1BA8E76F}" FilePath="*appdata\local\temp\????*_????????*\manifest.json" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{03EAE3AD-CF0F-63A5-CBA59CCFA27E811B}" FilePath="*appdata\local\temp\scoped_dir????*_????????*" >
		<Process Path="*\yandex\yandexbrowser\application\browser.exe" >
			<Signature Subject="*yandex*" />
		</Process>
	</File>
	<File Id="{B97CB8B9-9B39-AE56-8113656EFB775056}" FilePath="*adobe\acrobat\dc\acrobat\synchronizer\metadata\synchronizer-journal" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{797C5D07-450B-3066-76CC4678539D2E66}" FilePath="*adobe\coresync\cccu_????????????????????????????????.db-journal" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{031AE537-EEC8-0036-675FE7F161F57376}" FilePath="*adobe\coresync\plugins\livetype\c\entitlements-downloading.xml" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{E6737C96-35C9-2B39-D8AE8C9D66CA5391}" FilePath="*appdata\local\temp\????????-????-????-????-????????????.scratch\lock" >
		<Process Path="*\standardcollector.service.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6ECAF2B0-1C43-F137-BC7A0133459B72F9}" FilePath="*appdata\local\temp\????????-????-????-????-????????????\lock" >
		<Process Path="*\standardcollector.service.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{14C0BB47-9DE2-4D9A-6CD6E5C8E9519198}" FilePath="*appdata\local\temp\????????-????-????-????-????????????\sc.*.etl" >
		<Process Path="*\standardcollector.service.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{4AEB40F1-2FCD-DB85-5FA6137CEE971D58}" FilePath="*appdata\local\temp\????????????????????????????????.db.session-journal" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DC2333CD-4700-F876-DC49924DD5F15157}" FilePath="*appdata\local\temp\msohtmlclip?\*\clip_*" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{2D1363BC-B0A8-5151-5385078BCEAE7147}" FilePath="*appdata\local\temp\olktmp.png" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AC53126D-A181-9F7A-D1A674BDD4FCF38B}" FilePath="*microsoft\office\*\outlook.exe_rules.xml" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{478EE3C9-BEE6-1CD9-0DBDE0EB408FA354}" FilePath="*microsoft\office\*\????????-????-????-????-????????????_*" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{14FDB456-E9B9-EAAE-5A41EA132B534B9C}" FilePath="*microsoft\office\otele\{????????-????-????-????-????????????}*" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{5C8E3384-7647-23AA-B6C8F1FF25DFD465}" FilePath="*microsoft\outlook\???????????????????????????????? - autodiscover.xml" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B34C096E-DC0F-8998-A4F3515D77B83B34}" FilePath="*microsoft\windows\inetcache\{????????-????-????-????-????????????}\{????????-????-????-????-????????????}.html" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{367BEE70-240F-28E2-0A0201EFDDBB6C39}" FilePath="*microsoft\office\otele\{????????-????-????-????-????????????}*" >
		<Process Path="*\office*\winword.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{EE3EBDA9-BC99-5DD9-046C2E9038917828}" FilePath="*appdata\local\temp\cs????????????????????????????????.tmp" >
		<Process Path="*\csc.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{BAF5E918-47EA-E9EB-9659F83A42ABA2C5}" FilePath="*appdata\local\temp\csc????????????????????????????????.tmp" >
		<Process Path="*\csc.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0A7F312B-D1B0-B5DC-6BEEF23067021925}" FilePath="*appdata\local\temp\lnk{????????-????-????-????-????????????}.tmp" >
		<Process Path="*\link.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{70EB29DA-23F9-B6EB-C3432DA0FD8077BF}" FilePath="*appdata\local\temp\nugetscratch\nuget-dg\nugetspec.dg" >
		<Process Path="*\devenv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D4B99109-E1E2-7D8A-3232039153A2AB9A}" FilePath="*source\repos\functions\.vs\slnx.sqlite-journal" >
		<Process Path="*\devenv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A90F4A55-93E1-E1AD-369D718A9E05F80F}" FilePath="*microsoft\windows\inetcache\ie\wpf????.tmp" >
		<Process Path="*\devenv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{86C3C071-59D9-ECBB-F7202D2410730B38}" FilePath="*appdata\local\temp\tmp????????????????????????????????.exec.cmd" >
		<Process Path="*\msbuild.exe" CmdLine="*nologo*nodemode*nodeReuse*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7F68FAFB-6C8E-9884-B3B84E7E8F28830C}" FilePath="*appdata\local\temp\tmp????????????????????????????????.rsp" >
		<Process Path="*\msbuild.exe" CmdLine="*nologo*nodemode*nodeReuse*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{2A5CF2B9-3F60-424B-21A3A0DFB3533850}" FilePath="*appdata\local\temp\tmp????????????????????????????????.tmp" >
		<Process Path="*\msbuild.exe" CmdLine="*nologo*nodemode*nodeReuse*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{BE2668D4-D084-FB79-AC51657B9DF612BF}" FilePath="*appdata\local\temp\{????????-????-????-????-????????????} - OProcSessId.dat" >
		<Process CmdLine="*Global\*" Path="C:\Windows\System32\SearchProtocolHost.exe" />
	</File>
	<File Id="{ED1944CE-9B62-F7E8-4D10687A858C10BD}" FilePath="*appdata\local\temp\{????????-????-????-????-????????????} - OProcSessId.dat" >
		<Process CmdLine="*autoclean*" Path="C:\Windows\System32\cleanmgr.exe" />
	</File>
	<File Id="{CEAD96CE-EF27-4FBC-C6078A195C18FC85}" Operation="Delete" >
		<Process Path="C:\Windows\System32\cleanmgr.exe" />
	</File>
	<File Id="{A3497DC9-313A-3D5D-AE94E5F1BBD86DCD}" FilePath="*appdata\local\temp\{????????-????-????-????-????????????} - OProcSessId.dat" >
		<Process Path="*\Office*\WINWORD.EXE" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6D12A803-EA83-3FDD-974724F3482B35E5}" FilePath="*appdata\local\temp\{????????-????-????-????-????????????} - OProcSessId.dat" >
		<Process Path="*\Office*\excel.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6EC88323-5A3C-57F6-140B591BA6F6B30E}" FilePath="*appdata\local\temp\{????????-????-????-????-????????????} - OProcSessId.dat" >
		<Process Path="*\Office*\POWERPNT.EXE" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{926608F7-8D96-2457-0204DE9F83B7BA05}" FilePath="*appdata\local\temp\{????????-????-????-????-????????????}.png" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{1C4628DC-1B44-2343-39118079EC979F9A}" FilePath="*microsoft\penworkspace\discovercachedata.dat" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{00ED37DB-F7F4-0DF3-60446ADFE1D34D7A}" FilePath="*microsoft\windows\explorer\notifyicon\microsoft.explorer.notification.{????????-????-????-????-????????????}.png" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{4339CF87-85E9-856C-114365F40821C8BB}" FilePath="*microsoft\windows\recent\automaticdestinations\*.automaticdestinations-ms" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{53B5A9C7-8707-77E3-39487D8D85616D4B}" FilePath="*\temp\debug\*.dll" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{44AFC66C-E87C-82E7-38A22A4712CF60CB}" FilePath="*\temp\debug\*.xml" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{D8799066-5F13-088D-22947619D81AA92F}" FilePath="*\temp\debug\*.manifest" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{B8538582-A89D-F07A-A81F4A250BCBF142}" FilePath="*\temp\debug\*.pdb" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{C14DCB7F-481C-CE64-2D92933C5B435802}" FilePath="*\temp\debug\*.config" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{B8F14DC1-4767-EF04-0C8265729C773622}" FilePath="*\temp\*\debug\*.dll" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{BCEBEA7B-C3DA-8621-A0301401E46B98C2}" FilePath="*\temp\*\debug\*.xml" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{6F734653-AC20-167B-E4A12BF63A47D86A}" FilePath="*\temp\*\debug\*.pdb" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{36B0E903-B84D-39D7-04E084350BF1ACA5}" FilePath="*\temp\*\debug\*.lib" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{A881869F-5774-5693-C5E23A659DFCF681}" FilePath="*\temp\*\debug\*.json" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{2A801933-CC33-3106-2AFDDC26ACE9E75A}" FilePath="*\temp\*\debug\*.time" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{5A1580C7-0F0B-6D7B-D48C8229D35C9977}" FilePath="*\temp\*\debug\*.config" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{7ADD42F8-00BF-29A2-7D25EB896AEF9794}" FilePath="*\plugin*.png" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{78144067-EA7C-D9B0-7B5F7B599906C9B1}" FilePath="*\uniwizardinstall\*.png" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{2403782F-988D-0C87-231A3910CC2A9977}" FilePath="*\viisconsole*.png" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{65CFB657-6D65-9DBF-74AA1B5C5E3D5943}" FilePath="*ccm\ccmevalreport.xml" >
		<Process Path="*\ccmeval.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{3B49A8E7-350B-A828-40442F9244A9611F}" FilePath="*ccm\logs\ccmeval.log" >
		<Process Path="*\ccmeval.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{92FB5BFC-4A08-0103-D965DA50F25E99FF}" FilePath="*ccm\inventorystore.sdf" >
		<Process Path="C:\Windows\System32\wbem\WmiPrvSE.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{C266BBE9-5DCE-4C29-A87DC4EAC7E1EAB0}" FilePath="*ccm\logs\ccmsdkprovider.log" >
		<Process Path="C:\Windows\System32\wbem\WmiPrvSE.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{F48819EC-E7AE-2420-336E2BB3CA117472}" FilePath="*ccm\logs\dcmwmiprovider.log" >
		<Process Path="C:\Windows\System32\wbem\WmiPrvSE.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{33BC8231-0182-30ED-574EF765AFCA18CF}" FilePath="*ccm\logs\ddrprovider.log" >
		<Process Path="C:\Windows\System32\wbem\WmiPrvSE.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{02012186-D4C0-A2A3-0F5AFD5C21546D82}" FilePath="*ccm\logs\inventoryprovider.log" >
		<Process Path="C:\Windows\System32\wbem\WmiPrvSE.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{D4353DC1-3163-8AF5-C603EC77158A48D2}" FilePath="*ccm\logs\managedprovider.log" >
		<Process Path="C:\Windows\System32\wbem\WmiPrvSE.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{D012952D-0381-0642-0DA8A481604873A1}" FilePath="*ccm\logs\sensormanagedprovider.log" >
		<Process Path="C:\Windows\System32\wbem\WmiPrvSE.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{68274B0B-156B-7FAA-25EB1D38133FB690}" FilePath="*ccm\logs\smsclientmethodprovider.log" >
		<Process Path="C:\Windows\System32\wbem\WmiPrvSE.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{57C7928D-3F5D-A641-8FDE46E82E95DEEF}" FilePath="*ccm\logs\statemessageprovider.log" >
		<Process Path="C:\Windows\System32\wbem\WmiPrvSE.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{A0598E43-CFDC-6FED-3D4F36F0F9477694}" FilePath="*ccm\logs\systemtemplockdown.log" >
		<Process Path="C:\Windows\System32\wbem\WmiPrvSE.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{3F763EF9-BEE1-B1DD-4731FDD8D193256C}" FilePath="*infotecs\seed.bin" >
		<Process Path="C:\Windows\System32\wbem\WmiPrvSE.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{D9997BD1-8FC4-B8A1-6A3A498943992F41}" FilePath="c:\windows\logs\dism\dism.log" >
		<Process Path="C:\Windows\System32\wbem\WmiPrvSE.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{E91C997A-FC06-D443-C09362B774F51881}" FilePath="*ccmsetup\ccmsetup.xml" >
		<Process CmdLine="*\ccmsetup.exe /evaluate:*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8658502E-8911-D491-0C3033718DFFED4C}" FilePath="*ccmsetup\logs\ccmsetup-ccmeval.log" >
		<Process CmdLine="*\ccmsetup.exe /evaluate:*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{235569A8-0955-16E8-3F6D3F59952B73B7}" FilePath="*cisco\cisco anyconnect secure mobility client\routechangesv*.bin" >
		<Process Path="*\vpnagent.exe" >
			<Signature Subject="*cisco*" />
		</Process>
	</File>
	<File Id="{5B434405-E366-22AD-A77CC5BA1C0D93F5}" FilePath="*code\user\globalstorage\state.vscdb-journal" >
		<Process Path="*\code.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D6B51679-4300-0AA3-A56D9D950CCAC040}" FilePath="*common files\mcafee\csp\core.db-journal" >
		<Process Path="*Common Files\McAfee\CSP\*\McCSPServiceHost.exe" >
			<Signature Subject="*McAfee*" />
		</Process>
	</File>
	<File Id="{7CE62CE5-9112-928B-8356200957E4B984}" FilePath="*microsoft\office\Последние файлы\*.lnk" >
		<Process Path="*\Office*\WINWORD.EXE" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6AE2DE3E-AAA9-3277-F65A6C16A60064A6}" FilePath="*microsoft\office\Последние файлы\*.lnk" >
		<Process Path="*\Office*\excel.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{9EAEE88C-DE29-AD58-FD35A371EE019F9F}" FilePath="*microsoft\office\Последние файлы\*.lnk" >
		<Process Path="*\Office*\POWERPNT.EXE" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{FD93320B-2505-CE17-4226D91736B5CFE0}" FilePath="*devart\dbforge sql complete\docsessions.db" >
		<Process Path="*microsoft SQL Server*\Ssms.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{45D4B02F-0CE2-78B6-D309ACC4C8DEE6F0}" FilePath="*appdata\local\temp\~vs????.tmp" >
		<Process Path="*microsoft SQL Server*\Ssms.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E9BA95EA-E974-9063-5DD71FF53126AACB}" FilePath="*appdata\local\temp\tmp????.tmp" >
		<Process Path="*microsoft SQL Server*\Ssms.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F069D7B0-293A-E334-4FFC0AADB4DDC8F9}" FilePath="*documents\adobegcdata\adobegc.log" >
		<Process Path="*\agmservice.exe" >
			<Signature Subject="*adobe*" />
		</Process>
	</File>
	<File Id="{7F69CFB8-B116-1E05-F3475032A379F3C4}" FilePath="*documents\outlook files\~archive*.pst.tmp" >
		<Process Path="C:\Windows\System32\SearchProtocolHost.exe" />
	</File>
	<File Id="{2D5B5D26-3358-E2E8-70E3A91D010AD1A7}" FilePath="*dropbox\instance*\config.dbx-journal" >
		<Process Path="*\Dropbox\*\Dropbox.exe" CmdLine="*start*" >
			<Signature Subject="*Dropbox*" />
		</Process>
	</File>
	<File Id="{B51D784C-EBCC-422D-77BF2DF47E5DB40E}" FilePath="*evernote\????????-????-????-????-????????????.tmp" >
		<Process Path="*Evernote*\Evernote.exe" >
			<Signature Subject="*Evernote*" />
		</Process>
	</File>
	<File Id="{30BEA39E-EE34-2363-8720E64F9AF5EAAE}" FilePath="*evernote\conduit-storage\*.sql-journal" >
		<Process Path="*Evernote*\Evernote.exe" >
			<Signature Subject="*Evernote*" />
		</Process>
	</File>
	<File Id="{B5EF2694-AAE2-32C3-95EC523FA352A8C7}" FilePath="*evernote\transportsecurity" >
		<Process Path="*Evernote*\Evernote.exe" >
			<Signature Subject="*Evernote*" />
		</Process>
	</File>
	<File Id="{1516CAEE-A40E-F60C-F50876B4BD7B416D}" FilePath="*evernote\*~rf*.tmp" >
		<Process Path="*Evernote*\Evernote.exe" >
			<Signature Subject="*Evernote*" />
		</Process>
	</File>
	<File Id="{910AE0AF-B722-E6E8-DA5DA633A348F93E}" FilePath="*google\drive\user_default\sync_config.db-shm" >
		<Process Path="*google*.exe" >
			<Signature Subject="*Google*" />
		</Process>
	</File>
	<File Id="{7DA59D37-974C-501D-B674C92108C8E505}" FilePath="*google\google-adwords-editor.ini" >
		<Process Path="*google*.exe" >
			<Signature Subject="*Google*" />
		</Process>
	</File>
	<File Id="{EA23E98F-CD1C-8F70-E615AA1B1D85D3BF}" FilePath="*google\google-adwords-editor.ini.lock" >
		<Process Path="*google*.exe" >
			<Signature Subject="*Google*" />
		</Process>
	</File>
	<File Id="{29B1867D-D74B-2A72-5064582DC5B41F3B}" FilePath="*google\google-adwords-editor\*.db-journal" >
		<Process Path="*google*.exe" >
			<Signature Subject="*Google*" />
		</Process>
	</File>
	<File Id="{D77167DD-11D5-B26C-9D2035FD3EB33D94}" FilePath="*google\google-adwords-editor.ini.??????" >
		<Process Path="*google*.exe" >
			<Signature Subject="*Google*" />
		</Process>
	</File>
	<File Id="{0E9FF7DD-E02C-A8CF-EF27A11A3427C2AA}" FilePath="*kasperskylab\adminkit\1103\.vapm\localdata\data\*.lck" >
		<Process Path="*\Kaspersky Lab\NetworkAgent\vapm.exe" >
			<Signature Subject="*Kaspersky*" />
		</Process>
	</File>
	<File Id="{BD4608D7-A26F-B7F4-AE9DDC44575AFA60}" FilePath="*kasperskylab\adminkit\1103\.vapm\pccache\*.lock" >
		<Process Path="*\Kaspersky Lab\NetworkAgent\vapm.exe" >
			<Signature Subject="*Kaspersky*" />
		</Process>
	</File>
	<File Id="{021217D2-635C-E874-987CA9643E160323}" FilePath="*kasperskylab\adminkit\data\.temp\????????-????-????-????-????????????" >
		<Process Path="*\Kaspersky Lab\NetworkAgent\vapm.exe" >
			<Signature Subject="*Kaspersky*" />
		</Process>
	</File>
	<File Id="{4CEB0D41-B895-66AC-37F65083B81AD5B9}" FilePath="*microsoft monitoring agent\agent\health service state\health service store\edb.chk" >
		<Process Path="*microsoft Monitoring Agent\Agent\HealthService.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{CEF2DD24-F105-01CD-330020568E57EAFA}" FilePath="*microsoft policy platform\authoritydb\store.sdf" >
		<Process Path="*microsoft Policy Platform\policyHost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{2B98E446-730B-8AE9-ADD36C7F984A5590}" FilePath="*microsoft policy platform\policyplatformclient.log" >
		<Process Path="*microsoft Policy Platform\policyHost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{5DABCADD-5391-4E55-754BC5AF895B0A61}" FilePath="*microsoft.net\framework*\ngen*" >
		<Process Path="*microsoft.NET\Framework*\ngen*.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A836FDB9-B832-7A1A-CDA601EB56A39F05}" FilePath="*microsoft.net\framework*\ngen.log" >
		<Process Path="C:\Windows\System32\taskhostw.exe" />
	</File>
	<File Id="{4E6852F8-066F-340D-1417A1C32F696140}" FilePath="*system32\config\systemprofile\appdata\local\microsoft\windows\inetcache\ie\*" >
		<Process Path="C:\Windows\System32\taskhostw.exe" />
	</File>
	<File Id="{564E0C12-13F5-81AD-CE497D695369F45A}" FilePath="*microsoft\feeds\feedsstore.feedsdb-ms" >
		<Process Path="C:\Windows\System32\msfeedssync.exe" />
	</File>
	<File Id="{4BD2FFB6-4311-4613-335BC0E008DA17D1}" FilePath="*microsoft\feeds\{????????-????-????-????-????????????}~\*~.feed-ms" >
		<Process Path="C:\Windows\System32\msfeedssync.exe" />
	</File>
	<File Id="{B16D27FF-F4B8-F243-CE9A01B2E0AED289}" FilePath="*microsoft\windows\inetcache\low\suggestedsites.dat" >
		<Process Path="C:\Windows\System32\msfeedssync.exe" />
	</File>
	<File Id="{06849550-AC3B-D8E2-597C9E3289C3A013}" FilePath="*microsoft\internet explorer\recovery\active\{????????-????-????-????-????????????}.dat" >
		<Process Path="*\Internet Explorer\iexplore.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{61248855-D6DE-9C92-2D05381B23BD24E1}" FilePath="*appdata\local\temp\url????.tmp" >
		<Process Path="*\Internet Explorer\iexplore.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8E449221-6C6B-9C5B-D71C227D8D07DCDA}" FilePath="*microsoft\onedrive\logs\common\standaloneupdatertelemetrycache.otc.session-journal" >
		<Process Path="*microsoft\OneDrive\OneDriveStandaloneUpdater.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D36489E3-87C0-3783-01C9D4D1870E763D}" FilePath="*microsoft\onedrive\logs\common\standaloneupdater-20*" >
		<Process Path="*microsoft\OneDrive\OneDriveStandaloneUpdater.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6F09AF70-EA96-BD1A-03B24AE4ECFE7AF3}" FilePath="*microsoft\search\data\applications\windows\edb.jcp" >
		<Process Path="C:\Windows\System32\SearchIndexer.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{6C09D8E4-89FB-8FAE-49A58692FFF2F92D}" FilePath="*microsoft\search\data\applications\windows\windows.edb" >
		<Process Path="C:\Windows\System32\SearchIndexer.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{0EFFDAB4-30EE-191A-F6F842B011FB9523}" FilePath="*microsoft\search\data\applications\windows\windows.jfm" >
		<Process Path="C:\Windows\System32\SearchIndexer.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{36DB7126-AFA6-4815-CAA1FAF4E4F115EB}" FilePath="*Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.*.Crwl" >
		<Process Path="C:\Windows\System32\SearchIndexer.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{070C9133-85FF-88AF-868020D26209E520}" FilePath="*microsoft\skype*\transportsecurity" >
		<Process Path="*\skype.exe" >
			<Signature Subject="*Skype*" />
		</Process>
	</File>
	<File Id="{D3FEE29D-91B2-659C-12EDE74C16E4B01B}" FilePath="*microsoft\skype*\????????-????-????-????-????????????.tmp" >
		<Process Path="*\skype.exe" >
			<Signature Subject="*Skype*" />
		</Process>
	</File>
	<File Id="{D9FEBFFB-DA34-13B7-E0C7A6ECE65E7E63}" FilePath="*microsoft\skype*\*~rf*.tmp" >
		<Process Path="*\skype.exe" >
			<Signature Subject="*Skype*" />
		</Process>
	</File>
	<File Id="{9C08D62C-9A2C-F3EE-35C84876576F038E}" FilePath="*microsoft\teams\code cache\js\index-dir\temp-index" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{92177289-7EA0-2757-3D4B235261B3BE61}" FilePath="*microsoft\teams\code cache\js\index-dir\the-real-index" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A86D5A58-AE41-34CD-80C97769DDEB73CB}" FilePath="*microsoft\teams\desktop-config.json" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{54DB2A61-6E75-6920-003EFAA8ED632E92}" FilePath="*microsoft\teams\in_progress_download_metadata_store" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{9F6380D7-3EF5-9549-A35C5229FFBB6D90}" FilePath="*microsoft\teams\skylib\slimcore-ecs-cache.data" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B3EB143C-724E-DBA7-2B851BB0649E40F5}" FilePath="*microsoft\teams\skypert\ul.conf" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{EED620D3-0015-04CF-A77253444E100546}" FilePath="*microsoft\teams\ai_models\*\model.*" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{4E8E243A-0931-7059-D8F2AD6AC3C940C3}" FilePath="*code cache\js\????????????????_?" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A4729AFA-8C06-C006-5D719DA1F7829341}" FilePath="*microsoft\teams\cs_skylib\cs_orgid*.conf" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{48EF4D90-4B88-0921-95ABF8329E8DFB03}" FilePath="*cache*\?_??????" >
		<Process Path="*teams*teams.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{59A1F391-23A9-7CD1-42D8681E7EBD5075}" FilePath="*microsoft\windows\explorer\iconcache_idx.db" >
		<Process Path="C:\Windows\System32\RuntimeBroker.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{078B1CC4-88AC-056F-B252BAE483741CD4}" FilePath="*microsoftedgebackups\backups\microsoftedgebackup20*" >
		<Process Path="C:\Windows\System32\RuntimeBroker.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{E7FF4F42-43DA-5B01-2E152DEA87C0E8E2}" FilePath="*microsoft\windows\wer\*\????????-????-????-????-????????????" >
		<Process Path="C:\Windows\System32\WerFault.exe" />
	</File>
	<File Id="{0AC918F4-EAFF-89D5-3585DF23A1E7CF0A}" FilePath="*microsoft\windows\wer\*\wer????.*" >
		<Process Path="C:\Windows\System32\WerFault.exe" />
	</File>
	<File Id="{AF85C981-66F9-3478-34044D2EF2EA42B1}" FilePath="*microsoft\windows\wer\*\wer????.*" >
		<Process Path="*\perfwatson2.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{08499D77-75AB-247B-D8EB831AAE113B9C}" FilePath="*microsoft_corporation\powershell_ise.exe_strongname_*\autosaveinformation\*.xml" >
		<Process Path="C:\Windows\System32\WindowsPowerShell\*\powershell_ise.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{9CC3CAE9-BE79-249A-056A826085BF829F}" FilePath="*\domstore\*.xml" >
		<Process Path="*\microsoftedgecp.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{5AC1AEDD-1ACC-22F3-8F10673658C3E13B}" FilePath="*packages\microsoft.skypeapp_*.db-journal" >
		<Process Path="*WindowsApps\Microsoft.SkypeApp_*\SkypeApp.exe" />
	</File>
	<File Id="{34F7F4E0-BDEF-ACCE-36536FFDD372D13C}" FilePath="*packages\microsoft.windows.*.sqlite-???" >
		<Process Path="*\WindowsApps\Microsoft.Windows.Photos_*\Microsoft.Photos.exe" />
	</File>
	<File Id="{1FA784D6-D2FB-B68E-E34BFFC6611F9ACC}" FilePath="*telegram desktop uwp\tdata\*" >
		<Process Path="*Telegram Desktop\Telegram.exe" >
			<Signature Subject="*Telegram*" />
		</Process>
	</File>
	<File Id="{3B3C4592-E12E-E61A-85E6C5AECBE321C1}" FilePath="*telegram desktop uwp\tdata\*" >
		<Process Path="*WindowsApps\Telegram*\Telegram.exe" >
			<Signature Subject="*Telegram*" />
		</Process>
	</File>
	<File Id="{3CCD65E2-7DCB-48BD-3B682790573779CD}" FilePath="*pcdr\*\datastore\appstate.db-journal" >
		<Process Path="*SupportAssist\*\DSAPI.exe" >
			<Signature Subject="*PC-Doctor*" />
		</Process>
	</File>
	<File Id="{355B0500-AB3A-3A61-6A585DE3261183F2}" FilePath="*postgresql\*\data\pg_stat_tmp\db_*.stat" >
		<Process Path="*postgresql\??\bin\postgres.exe" />
	</File>
	<File Id="{2640BC59-6D9B-6162-A777F7DAB727BEB9}" FilePath="*postgresql\*\data\pg_stat_tmp\global.stat" >
		<Process Path="*postgresql\??\bin\postgres.exe" />
	</File>
	<File Id="{9D65D608-56C0-8FEE-001444BA1F80C7B4}" FilePath="*postgresql\*\data\pg_stat_tmp\db_*.tmp" >
		<Process Path="*postgresql\??\bin\postgres.exe" />
	</File>
	<File Id="{0E1800D8-A4A5-FA6E-FD21B073D012EA17}" FilePath="*supportassist\client\agent\db\supportassist.db-journal" >
		<Process Path="*SupportAssistAgent\bin\SupportAssistAgent.exe" >
			<Signature Subject="*Dell*" />
		</Process>
	</File>
	<File Id="{95CC58C2-8B0E-99C9-713FCDDD25BFE101}" FilePath="*commandanalysis\powershell_analysiscacheentry_????????-????-????-????-????????????" >
		<Process Path="*microsoft Monitoring Agent\Agent\MonitoringHost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0CA01D66-E1B4-739E-03086DC1A6FDD242}" FilePath="*\powershell\startupprofiledata-noninteractive" >
		<Process Path="*\powershell.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8032B457-FE13-97C1-6184D408F983C3DD}" FilePath="*temp\sccm_credentialguardstatus.log" >
		<Process Path="*\powershell.exe" CmdLine="*C:\windows\CCM\SystemTemp\????????-????-????-????-????????????.ps1&#39;" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{562AA81E-E394-A852-B06E361239BA9162}" FilePath="*temp\sccm_installedupdates.log" >
		<Process Path="*\powershell.exe" CmdLine="*C:\windows\CCM\SystemTemp\????????-????-????-????-????????????.ps1&#39;" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E49C0382-E5A1-CF58-A49B936CB5968270}" FilePath="*system32\spp\store\2.0\cache\cache.dat" >
		<Process Path="C:\Windows\System32\sppsvc.exe" />
	</File>
	<File Id="{38E02614-BC70-631A-733DC79DC6856A80}" FilePath="*system32\spp\store\2.0\data.dat" >
		<Process Path="C:\Windows\System32\sppsvc.exe" />
	</File>
	<File Id="{9ECD1131-DDF1-7C4C-78E4EE56BBB4E842}" FilePath="*system32\spp\store\2.0\data.dat.bak" >
		<Process Path="C:\Windows\System32\sppsvc.exe" />
	</File>
	<File Id="{481FA214-35F2-9B1D-EED8D7DBFB521082}" FilePath="*system32\spp\store\2.0\data.dat.tmp" >
		<Process Path="C:\Windows\System32\sppsvc.exe" />
	</File>
	<File Id="{0362E2A6-8595-48F5-76B29BE6DB452576}" FilePath="*usoprivate\updatestore\updatestoretemp????????-????-????-????-????????????.xml" >
		<Process Path="C:\Windows\System32\usocoreworker.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{0E8F7231-9F8E-EF9D-11090F16D2E18A0E}" FilePath="*usoshared\logs\system\*.etl" >
		<Process Path="C:\Windows\System32\MoUsoCoreWorker.exe" CmdLine="*Embedding" />
	</File>
	<File Id="{77724F85-5F76-FEA6-0AC215BB3F02E88A}" FilePath="*vmware\vmnetdhcp.leases~" >
		<Process Path="C:\Windows\SysWOW64\vmnetdhcp.exe" >
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{A1EB101A-3BA9-5C74-1F6A21C3BE143833}" FilePath="*vmware\vmnetdhcp.leases~" >
		<Process Path="C:\Windows\System32\vmnetdhcp.exe" >
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{57646495-9CBA-7299-4859384ED8D6DE0D}" FilePath="*yandex\yandexbrowser\service_update.log" >
		<Process Path="*\Yandex\YandexBrowser\*\service_update.exe" >
			<Signature Subject="*Yandex*" />
		</Process>
	</File>
	<File Id="{0DEE11AC-B3EE-AF5A-47B195A46FC4CC27}" FilePath="*temp\sccmlocalgroupmembers.log" >
		<Process Path="C:\Windows\System32\cscript.exe" CmdLine="*//nologo C:\WINDOWS\CCM\SystemTemp\????????-????-????-????-????????????.vbs" />
	</File>
	<File Id="{5A619DFB-C648-5ADA-A7B394B497C260C9}" FilePath="*\ClientHealthLogs\*.log" >
		<Process Path="*\powershell.exe" CmdLine="*\ClientHealthScripts\ConfigMgrClientHealth*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8586848D-0802-EC73-84C49B8E0760CA76}" FilePath="?:\config.msi\cmp????.tmp" >
		<Process Path="*system32\msiexec.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8E5C7FC8-7B29-D6FC-1E7BDD456C0CEC3F}" FilePath="?:\config.msi\???????.rbs" >
		<Process Path="*system32\msiexec.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{FF01F01E-4460-E6DF-97571917D64BA886}" FilePath="?:\config.msi\????????.rbs" >
		<Process Path="*system32\msiexec.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F29A4725-80EB-78D7-D71B488D7CC5351E}" FilePath="c:\config.msi\?????.rbs" >
		<Process Path="*system32\msiexec.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{89761529-0A43-033A-69D4907950EEB997}" FilePath="?:\config.msi\pf????.tmp" >
		<Process Path="*system32\msiexec.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C0CDB86B-278D-61A6-482233F6FBCA9B17}" FilePath="?:\config.msi\pt????.tmp" >
		<Process Path="*system32\msiexec.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{30B75D67-B71E-33B7-6A5200DC3050C2F0}" FilePath="*.git\lfs\incomplete\?????????????????????????????????????????????????????????????????????????" >
		<Process >
			<Signature Subject="*git*" />
		</Process>
	</File>
	<File Id="{26EBCFE7-4B4D-EF3A-66520233B5BE5595}" FilePath="*.git\lfs\objects\?????????????????????????????????????????????????????????????????????????" >
		<Process >
			<Signature Subject="*git*" />
		</Process>
	</File>
	<File Id="{CC52EE9F-624C-49D9-BDEE0A8F4F615F2E}" FilePath="*.git\lfs\objects\??\??\????????????????????????????????????????????????????????????????" >
		<Process >
			<Signature Subject="*git*" />
		</Process>
	</File>
	<File Id="{C06EBD89-E0F0-F8FE-5F8335C04127F7A6}" FilePath="*.git\lfs\tmp\?????????" >
		<Process >
			<Signature Subject="*git*" />
		</Process>
	</File>
	<File Id="{09BDE785-FE8B-1C56-99286D97DADC40C3}" FilePath="*\localization\dev\industrial\??\locs\*" >
		<Process Path="*\sdl\sdl passolo\*\psl.exe" />
	</File>
	<File Id="{D86413F6-EBB9-3CBD-4521427552D6F53B}" FilePath="*web\web-terminal\web-server\*" >
		<Process Path="*\devenv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{ED33BE45-CEF2-9685-A48E9B0DA2F4C4C9}" FilePath="*\webresources\resource?\static\images\*" >
		<Process >
			<Signature Subject="*adobe*" />
		</Process>
	</File>
	<File Id="{E5FB4588-0971-7B1B-0D6691135DA88FE8}" FilePath="*\winmerge\*" >
		<Process Path="*AppData\Local\Temp\is-*.tmp\WinMerge-*-Setup.tmp" />
	</File>
	<File Id="{50276661-D927-740A-9A019D1EAC75728A}" FilePath="*\delldatavault\epsa\epsa_?_?????????" >
		<Process Path="*\DellDataVault\DDVDataCollector.exe" >
			<Signature Subject="*dell*" />
		</Process>
	</File>
	<File Id="{DD646BD2-DBF3-B193-82C5909246732165}" FilePath="*kasperskylab\adminkit\bases\*.removeonnextreboot" >
		<Process >
			<Signature Subject="*kaspersky*" />
		</Process>
	</File>
	<File Id="{0FEB1D4D-C86E-6698-7CD96EFAFAC94290}" FilePath="*adobecampaignintegration\dev\*" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{F4185A14-0306-CFA2-8BC48E737FDE0C8D}" FilePath="*adobecampaignintegration\release\*" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{44A75273-3E8C-3C62-2899ECAFB046EC9E}" FilePath="*\??-??\??????.htm" >
		<Process Path="C:\Windows\explorer.exe" />
	</File>
	<File Id="{1864678A-9FC4-160F-4A20E727EEA026A3}" FilePath="*.partial" >
		<Process Path="*\devenv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{17B71DF8-E554-B1DF-4850C4102DD34DBE}" FilePath="*.htm" >
		<Process Path="*\devenv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{2D50A408-CDC2-B628-BB651D7487DC651A}" FilePath="*.html" >
		<Process Path="*\devenv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0ED426C9-B963-49FA-B16BB48FF5C35096}" FilePath="*appdata\local\temp\etilqs_???????????????" >
		<Process Path="*\devenv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{75E05DC2-6360-2911-31E372B7B686645A}" FilePath="*microsoft\team foundation\*.curcache" >
		<Process Path="*\mtm.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F7A9D057-9C5B-D7BC-F71BB860850B1FD0}" FilePath="*microsoft\tokenbroker\cache\????????????????????????????????????????.tbres" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{63EE6ADB-FA3A-7CA5-3ED9573A50401ED8}" FilePath="*appdata\local\temp\~df????????????????.tmp" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AA36C54A-93BB-D654-A7802668EC4D36B4}" FilePath="*appdata\local\temp\mso????.tmp" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{BBC3D85D-1987-0E07-60117E0B572036A1}" FilePath="*microsoft\visualstudio\*\extensions*\??_?.idx" >
		<Process Path="*\vadbmtx.exe" >
			<Signature Subject="*Tomato*" />
		</Process>
	</File>
	<File Id="{ECB84BDF-3EE1-55CB-406B790AB4AB9C3A}" FilePath="*microsoft\visualstudio\*\extensions*\??_?.tmp" >
		<Process Path="*\vadbmtx.exe" >
			<Signature Subject="*Tomato*" />
		</Process>
	</File>
	<File Id="{2ED2739B-1A54-B007-C8B1CB253AE95869}" FilePath="*microsoft\vsapplicationinsights\vstel*_????????????????????????????????.t??" >
		<Process Path="*\vctip.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6E2593EB-A91F-ED00-6038F424BD589DEE}" FilePath="*microsoft\vsapplicationinsights\vstel*_????????????????????????????????.t??" >
		<Process Path="*servicehub\hosts\*\servicehub.*" />
	</File>
	<File Id="{51577B31-CBE8-902A-3F031633150BC40C}" FilePath="*microsoft\vsapplicationinsights\vstel*_????????????????????????????????.t??" >
		<Process Path="*extensions\*\tokenservice\microsoft.asal.tokenservice.exe" />
	</File>
	<File Id="{CE650B87-1D6E-9D5E-3B7CD4A2B5F71080}" FilePath="*appdata\local\microsoft\windows\explorer\iconcache_*.db" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{A6D08304-B903-2A29-876D835BA086B17F}" FilePath="*appdata\local\microsoft\windows\explorer\iconcachetodelete\icn*.tmp" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{6394FB91-7A7E-02ED-5C019C4EEACF303E}" FilePath="*appdata\local\microsoft\windows\inetcache\ie\*[?]*" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{40E0F456-2E6B-A605-408E5DD267C01D91}" FilePath="*microsoft\cryptneturlcache\metadata\????????????????????????????????_????????????????????????????????" >
		<Process Path="*\microsoftedgecp.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{3011B0C8-8578-D408-67B33E114AE141EF}" FilePath="*\urlblock\url*" >
		<Process Path="*\microsoftedgecp.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E0FBA1DD-E11F-DDFB-9A1EBDF83AAB0EFF}" FilePath="*\ac\temp\~df????????????????.tmp" >
		<Process Path="*\microsoftedgecp.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D11286C3-A9BC-5B8B-9AD57E814AA01E2E}" FilePath="*\tempstate\datastorebackup20*\edb?????.log" >
		<Process Path="*\microsoftedgecp.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{773F1BE1-8638-FBF9-31C4858F07142CC7}" FilePath="*appdata\local\temp\_mei??????\*" >
		<Process Path="*\docker-compose.exe" >
			<Signature Subject="*Docker*" />
		</Process>
	</File>
	<File Id="{A3D9B570-E0AE-F51A-6D713E2741DD77CD}" FilePath="*appdata\local\temp\??????_?.tmp" >
		<Process Path="*\dymolabellight.exe" />
	</File>
	<File Id="{4F6D80FB-97F4-E567-553642B7D0E3585A}" FilePath="*appdata\local\temp\??????_??.tmp" >
		<Process Path="*\dymolabellight.exe" />
	</File>
	<File Id="{72F7C894-DDA6-37EC-161A2A6F1411757C}" FilePath="*appdata\local\temp\edg????.tmp" >
		<Process Path="*\vcpkgsrv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E6F707E3-A107-2F73-EE4CCED83104F29F}" FilePath="*appdata\local\temp\mid????.tmp" >
		<Process Path="*\midlc.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{EF97D7F0-0728-ABE0-662C1E575BAD7101}" FilePath="*appdata\local\temp\nuget\tempcache\????????-????-????-????-????????????\????????.???" >
		<Process Path="*\devenv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{912629DE-C0E2-DC91-460474CD21C53879}" FilePath="*appdata\local\temp\nugetscratch\????????.???.*" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{76C9E54A-4A4E-D16C-B7DD40D49C164924}" FilePath="*appdata\local\temp\tcd????.tmp" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{ECF7D6C1-FF1D-545D-ACA152D411A3B424}" FilePath="*appdata\local\temp\tmp????.tmp" >
		<Process Path="*\msbuild.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D050A264-A555-8CE6-6B91EA3845015215}" FilePath="*appdata\local\temp\tmp??????" >
		<Process Path="*\python.exe" >
			<Signature Subject="*Python*" />
		</Process>
	</File>
	<File Id="{EE56BB63-15C3-AEB4-B5DA5D2D6A4D7345}" FilePath="*appdata\local\temp\vsfeedbackintellicodelogs\suggestions\*" >
		<Process Path="*servicehub.*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AFD628F7-176E-3CD2-5179B65871A69E31}" FilePath="*code cache\js\????????????????_?" >
		<Process >
			<Signature Subject="*adobe*" />
		</Process>
	</File>
	<File Id="{983CEFA9-B9A6-EC23-B78E7138249C3D0F}" FilePath="*documents\iisexpress\tracelogfiles\web\fr???????.xml" >
		<Process Path="*\IIS Express\iisexpress.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
<!-- Part 0003 END 2020-11-29T20:08:00.000Z-1606680524 -->

<!-- ############################################################################################################### -->
<!-- Part 0004 Start 2021-03-31T23:27:00.000Z-1617233233 -->
	<File Id="{1F8D6BF3-A6D8-3607-22560BB05C757E33}" FilePath="*appdata\local\temp\vsi\activesessions.local.log" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{D8294806-6EFB-C0BE-2CD8DDEE5EF408DB}" FilePath="*appdata\local\temp\vsi\zip\zippsthc.pst" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{94089295-1DD1-E884-68639B3A616B2072}" FilePath="*appdata\local\temp\vsi\notepaddoc.txt" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{BF17AD8C-6926-A3B9-63AD9844026DA27B}" FilePath="*appdata\local\temp\vsi\zip\zippstlc.pst" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{9FCF80F7-7179-1C11-49DC19EBD6350AB1}" FilePath="*appdata\local\temp\vsi\homedrive\output\notepaddoc.txt" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{A1ABAD89-7B30-F6B1-19CCF816D725CEDC}" FilePath="*appdata\local\temp\vsi\zip\vsi7zhc.7z" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{0C206FFE-96EC-1E7E-2FCD7F8AB50E4447}" FilePath="*appdata\local\temp\vsi\zip\vsi7zlc.7z" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{DB5B9564-60BF-DAF7-5272B210968DD72B}" FilePath="*appdata\local\temp\vsi\debuglogging\vsi_debug_e.log" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{C256239B-ABC5-A162-974DCA348B825F92}" FilePath="*appdata\local\temp\vsi\homedrive\outlook\personalfolders.pst" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{7B435B7F-3F0D-7DA6-4DAE027C75589278}" FilePath="*appdata\local\temp\vsi\homedrive\pdf1.pdf" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{91B95E5D-2C1A-6102-C99045F5EAB55512}" FilePath="*appdata\local\temp\vsi\homedrive\pdf2.pdf" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{55029C4E-B93B-C966-39DBACAF28867CAC}" FilePath="*appdata\local\temp\vsi\homedrive\spreadsheet.xlsx" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{85D608CC-806F-B49D-E5920F362C5A8FB5}" FilePath="*appdata\local\temp\vsi\runtime\datalocations.ini" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{7AC74D39-C63D-6FBB-947F951D5256DDF4}" FilePath="*appdata\local\temp\vsi\runtime\global.ini" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{A0479137-4EC8-5CE0-86989903A08A4036}" FilePath="*appdata\local\temp\vsi\runtime\logon.log" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{777FB94F-D89A-AF21-1F1D7020D9A1EA52}" FilePath="*appdata\local\temp\vsi\runtime\vsilauncher.ini" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{DB491410-47E7-2E5E-1B37D7942794A6EE}" FilePath="*_vsi_*@*.log" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{37D68346-79E0-35E9-327213B11438B815}" FilePath="*_vsi_*@*.csv" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{881F3574-882D-A503-4499C76B5CEBC93D}" FilePath="*\dummy???????.log" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{CEFA0876-94DE-FE48-92656A90AC3A0A41}" FilePath="*\dummy??????.log" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{4788BACE-EA32-8E4B-C7CE347AD9C6D695}" FilePath="*appdata\local\temp\vsi\io\string???????.vsi" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{C94A6F8C-7DF0-43EB-D79107A1E4689424}" FilePath="*username\appdata\local\temp\vsi\logging\000*@*.csv" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{27C1B7ED-AD9F-68FB-402F78C729F8558C}" FilePath="*appdata\local\temp\vsi\w10login*.jpg" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{595F65E1-4D0A-85D0-B3941F89F16AA33E}" FilePath="*appdata\local\temp\~df????????????????.tmp" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\VSI.exe" >
			<VersionInfo FileDescription="Login VSI Engine*" />
		</Process>
	</File>
	<File Id="{6DBE89AC-B003-35AB-7CC21262F819D941}" FilePath="*system32\config\systemprofile\appdata\local\microsoft\installservice\{????????-????-????-????-????????????}.checkpoint" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F675AA3E-9D01-FB8D-A7EC4DF71F6ADEDF}" FilePath="*\softwaredistribution\datastore\logs\tmp.edb" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{60978B17-5363-04E5-F08FCB52F4DCC426}" FilePath="*\users\*\ntuser.ini" >
		<Process CmdLine="*system32\svchost.exe -k netsvcs -p -s profsvc" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AFD56C3A-72DA-0EAC-4C2913153E8BAC50}" FilePath="c:\users\*\ntuser.dat" >
		<Process CmdLine="*system32\svchost.exe -k netsvcs -p -s profsvc" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E513026D-DF9A-6930-4FF4C73891896B14}" FilePath="c:\windows\*\{????????-????-????-????-????????????}.tmp" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{97E1A627-D51D-60DC-8D0054C19B2EE5EB}" FilePath="c:\users\*\{????????-????-????-????-????????????}.tmp" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6936D6C5-1BB8-668D-B9F6C763A81CF96C}" FilePath="*appdata\locallow\microsoft\cryptneturlcache\content\????????????????????????????????" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0006162E-53CB-A9D0-709E1B5B90EAD7F7}" FilePath="*programdata\microsoft\windows\clipsvc\tokens.dat.bak" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B20ADA06-B19C-B6E9-9B222B838395163F}" FilePath="*\programdata\microsoft\smsrouter\messagestore\edb.chk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{48B206B1-BDA5-6BEB-F40DF7E9794A48CB}" FilePath="*\programdata\microsoft\smsrouter\messagestore\edb.log" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{39501042-DCC4-6616-2D6E9D91E832BAAA}" FilePath="*\programdata\microsoft\smsrouter\messagestore\smsinterceptstore.jfm" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{4283BA20-BE0C-5AF9-8228FFFE101D821C}" FilePath="*programdata\microsoft\windows\clipsvc\tokens.dat" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{67970DE3-B4CC-0713-96632C7BBF297F65}" FilePath="c:\users\*\.freemind\auto.mmfilter" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A12CC854-F1DE-726C-5295B0C9FC8066CC}" FilePath="c:\users\*\.freemind\auto.properties" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{025FB345-A764-01FF-53813FBF9BF5D777}" FilePath="c:\users\*\.freemind\log.0" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{3D651730-A265-D332-29666543928270A2}" FilePath="*appdata\local\comms\unistoredb\store.jfm" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E40E196D-EA5B-87AD-46EB2A59FAFF29AF}" FilePath="*appdata\local\comms\unistoredb\tmp.edb" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DC09BFD0-2918-EB38-E2C001D91A250674}" FilePath="*appdata\local\comms\unistoredb\uss.jcp" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A40F52D6-B590-711B-96C1C4D600940EED}" FilePath="*appdata\local\comms\unistoredb\usstmp.jtx" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{4606E7F9-CEF6-C06A-1F76D86B9B95A543}" FilePath="*appdata\local\connecteddevicesplatform\cdpglobalsettings.cdp" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B7DD65DD-FE53-DC94-D5015D9D135DD166}" FilePath="*appdata\local\connecteddevicesplatform\connected devices platform certificates.sst" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0B4D13FA-CC2C-C4AD-ABA7C722CC5E17F8}" FilePath="*appdata\local\microsoft\windows sidebar\settings.ini" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{9B7AC84A-CC73-2E6B-2C1F87182A921DE6}" FilePath="*appdata\local\microsoft\windows\actioncentercache\windows-systemtoast-securityandmaintenance_5_0.png" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{790B80C2-D2E7-F459-D3DF4917E9F2178C}" FilePath="*appdata\local\microsoft\windows\notifications\wpndatabase.db" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{2B9D905F-A620-95FC-D1402CC22B373568}" FilePath="*appdata\local\microsoft\windows\notifications\wpndatabase.db-journal" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{824F0992-565D-1E3F-4DDF105C34060A7B}" FilePath="*appdata\local\microsoft\windows\schcache\perf.test1.test.local.sch" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{82D34BB1-8634-C41F-89BA326C955AFFD2}" FilePath="*appdata\local\microsoft\windows\shell\defaultlayouts.xml" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B7C9367C-51E0-CA49-06555F51325E8DBF}" FilePath="*appdata\local\microsoft\windows\upps\upps.bin" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{023D7AB9-A7A7-B256-0A62D85B3ACE1855}" FilePath="*appdata\local\microsoft\windows\winx\group1\1 -desktop.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E0AC850D-E026-2042-5895C41CB10FED3A}" FilePath="*appdata\local\microsoft\windows\winx\group1\desktop.ini" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A844455F-BEA7-11D1-EF30E7E0E495D20F}" FilePath="*appdata\local\microsoft\windows\winx\group2\1 -run.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{56ED604A-46E1-A0C1-3ABBD0E97B84ADEE}" FilePath="*appdata\local\microsoft\windows\winx\group2\2 -search.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{FE914E4A-4038-4E25-36CDA55748A56CC7}" FilePath="*appdata\local\microsoft\windows\winx\group2\3 -windows explorer.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A52AD346-2A65-66B2-0E849667FB3B5E0B}" FilePath="*appdata\local\microsoft\windows\winx\group2\4 -control panel.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{12E12603-0BCF-03A9-3B8339F48D4B3C42}" FilePath="*appdata\local\microsoft\windows\winx\group2\5 -task manager.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{4DC8FED0-78E1-AAC9-0FF0F7BB8838BDF5}" FilePath="*appdata\local\microsoft\windows\winx\group2\desktop.ini" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B7108215-2521-38D4-4AF2AD660C6824A9}" FilePath="*appdata\local\microsoft\windows\winx\group3\01 -command prompt.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E50C65E9-182A-3A7E-3F5459BBA0563528}" FilePath="*appdata\local\microsoft\windows\winx\group3\01a -windows powershell.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{CB1BE170-2FD5-7014-05C6189333A453EF}" FilePath="*appdata\local\microsoft\windows\winx\group3\02 -command prompt.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{EBFAB220-9041-3E4B-F667FE824EF82CC6}" FilePath="*appdata\local\microsoft\windows\winx\group3\02a -windows powershell.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0E91C143-1C4E-853C-42045C4BAAC15829}" FilePath="*appdata\local\microsoft\windows\winx\group3\03 -computer management.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6839410D-9B8F-78F5-7AB3FDB27081DCBD}" FilePath="*appdata\local\microsoft\windows\winx\group3\04 -disk management.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{94A43879-709F-FC73-A7BDFDEDBC7DDB2F}" FilePath="*appdata\local\microsoft\windows\winx\group3\04-1 -networkstatus.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{56E0F311-017B-4C0F-D9BBD9C3DEDA0536}" FilePath="*appdata\local\microsoft\windows\winx\group3\05 -device manager.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E00751C3-412C-9E48-9B61EDA88040B8EC}" FilePath="*appdata\local\microsoft\windows\winx\group3\06 -systemabout.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{624C1D4B-7C1D-8F08-4ABD557F1059AA36}" FilePath="*appdata\local\microsoft\windows\winx\group3\07 -event viewer.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{3759637E-8351-86C8-391CC92BC9B9DBAC}" FilePath="*appdata\local\microsoft\windows\winx\group3\08 -powerandsleep.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{183D344D-30D4-0EC3-4935850B81638233}" FilePath="*appdata\local\microsoft\windows\winx\group3\09 -mobility center.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{5D487FA6-A2D5-A15A-DDCBB90F7E0999CC}" FilePath="*appdata\local\microsoft\windows\winx\group3\10 -appsandfeatures.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{EF86D2A7-94D7-3FB9-B49426717A16A523}" FilePath="*appdata\local\microsoft\windows\winx\group3\desktop.ini" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{CA178CC8-CF24-7FD5-DCD66B48149ECADF}" FilePath="*appdata\local\packages\windows.*\settings\settings.dat" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7A50F6BB-D0B2-779E-12DD02F7AB9A848C}" FilePath="*appdata\roaming\microsoft\bibliography\style\apasixtheditionofficeonline.xsl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{BBABF724-884E-1843-EA79E5501A719C8E}" FilePath="*appdata\roaming\microsoft\bibliography\style\chicago.xsl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8544DD86-EF90-E8F1-7F21B85A85F01FA0}" FilePath="*appdata\roaming\microsoft\bibliography\style\gb.xsl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AEE8EBA7-23E3-5F8B-6C60215D7F240C6A}" FilePath="*appdata\roaming\microsoft\bibliography\style\gostname.xsl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E12AC2D0-0D0B-9AE7-7B31E9E1A260FAA1}" FilePath="*appdata\roaming\microsoft\bibliography\style\gosttitle.xsl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{2B277305-13FC-E68F-6295C9B7B703BBD0}" FilePath="*appdata\roaming\microsoft\bibliography\style\harvardanglia2008officeonline.xsl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8EA6518F-5A11-D9D2-47B3293C2FE01FF7}" FilePath="*appdata\roaming\microsoft\bibliography\style\ieee2006officeonline.xsl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{BDE2316C-63A3-65AE-6D635B8680E4B2A3}" FilePath="*appdata\roaming\microsoft\bibliography\style\iso690.xsl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0A5D5A5C-896F-CDE1-D99364C989D3D6CE}" FilePath="*appdata\roaming\microsoft\bibliography\style\iso690nmerical.xsl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A208AFD8-7333-4E7F-AD30AE2DB6B32D24}" FilePath="*appdata\roaming\microsoft\bibliography\style\mlaseventheditionofficeonline.xsl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C0D2DB76-4AA5-434C-D9DF435127FDF35B}" FilePath="*appdata\roaming\microsoft\bibliography\style\sist02.xsl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E61ECD0A-2AC8-1BBD-E6E1977BA0366AB5}" FilePath="*appdata\roaming\microsoft\bibliography\style\turabian.xsl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{9C6D9D52-F0BA-9B63-2754A12DB26DED59}" FilePath="*appdata\roaming\microsoft\document building blocks\1033\16\built-in building blocks.dotx" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{440AB481-7A81-310E-D26D0E427CE59D9B}" FilePath="*appdata\roaming\microsoft\internet explorer\quick launch\desktop.ini" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7286E7CD-FF1A-2320-A0E1929877FB0EEE}" FilePath="*appdata\roaming\microsoft\internet explorer\quick launch\microsoft outlook.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{5C7EE088-C917-B45E-DB17C48EF6C0A3E1}" FilePath="*appdata\roaming\microsoft\internet explorer\quick launch\shows desktop.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C550F719-0552-647F-C35628C20C11587D}" FilePath="*appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\desktop.ini" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C27A900F-5E13-F897-F045B8D4C3160A21}" FilePath="*appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\file explorer.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{9053A2D9-69E5-AE12-15D874D777AD4E0E}" FilePath="*appdata\roaming\microsoft\internet explorer\quick launch\window switcher.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{CA2FDB72-1872-A164-355BF7E189F3A263}" FilePath="*appdata\roaming\microsoft\network\connections\pbk\_hiddenpbk\rasphone.pbk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DD343EDD-400F-6F2A-CA880AD4D9976ACB}" FilePath="*appdata\roaming\microsoft\office\mso????.acl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F59310FE-A55B-A7FB-5E284461D737090D}" FilePath="*appdata\roaming\microsoft\office\recent\index.dat" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B11FF78D-242F-89ED-0C1CE72ACE500A1D}" FilePath="*appdata\roaming\microsoft\office\recent\spreadsheet.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7FA8199F-D6CF-F414-A6512D6DB10F1A63}" FilePath="*appdata\roaming\microsoft\office\recent\templates.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8085CF1A-A2D8-C4A4-93C3DC802C1A255E}" FilePath="*appdata\roaming\microsoft\office\recent\useredit.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{562CCF0A-5A33-003F-5B61D80F2EC2F287}" FilePath="*appdata\roaming\microsoft\office\recent\userpresentation.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{834E1420-9C00-D4AA-5D631CAAAEECF7B1}" FilePath="*appdata\roaming\microsoft\outlook\outlook.srs" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C879FF21-CD8E-41B7-24AA9548A88BD7A4}" FilePath="*appdata\roaming\microsoft\outlook\outlook.xml" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C563CBC4-8FA0-00EE-0667B49A1D135D66}" FilePath="*appdata\roaming\microsoft\protect\credhist" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DA520DDF-77F0-6B53-E0BB83A74BE2417F}" FilePath="*appdata\roaming\microsoft\protect\s-1-*\????????-????-????-????-????????????" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{4CD78F2D-43A7-F58C-1E886F7CEC09C863}" FilePath="*appdata\roaming\microsoft\protect\s-1-*\bk-perf" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{12FCCFD5-344C-5A8E-CEE0DC8E399D4F18}" FilePath="*appdata\roaming\microsoft\protect\s-1-*\preferred" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{34D9AA07-D9B4-9CC5-DF174918EF2B1213}" FilePath="*appdata\roaming\microsoft\systemcertificates\my\appcontainerusercertread" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DEC253B2-B294-EBB1-73D01F219DB3F307}" FilePath="*appdata\roaming\microsoft\templates\normal.dotm" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8F4CB972-7E89-A01B-F69912558FA66274}" FilePath="*appdata\roaming\microsoft\templates\normalemail.dotm" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A3DD398E-47A6-6EC6-68BD247EBDA9BAD6}" FilePath="*appdata\roaming\microsoft\uproof\custom.dic" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{13D9CCF9-E594-024F-2624591DB7FD4577}" FilePath="*appdata\roaming\microsoft\uproof\excludedictionaryen0409.lex" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{5B88206E-F7E2-255A-9D97FB73717BC4BC}" FilePath="*appdata\roaming\microsoft\windows\recent\automaticdestinations\*.automaticdestinations-ms" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{789A7775-31C5-8DD7-E73E066750071141}" FilePath="*appdata\roaming\microsoft\windows\recent\customdestinations\*.customdestinations-ms" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A50884AA-6A96-9C75-0BE26F90DA928325}" FilePath="*appdata\roaming\microsoft\windows\sendto\bluetooth file transfer.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AA17FC2F-FC55-AEBF-04905EB63342D579}" FilePath="*appdata\roaming\microsoft\windows\sendto\compressed (zipped) folder.zfsendtotarget" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F378478A-6E2D-5EA0-3605DA051C3B5222}" FilePath="*appdata\roaming\microsoft\windows\sendto\desktop (create shortcut).desklink" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DCD7A7C1-8A90-FDB8-2A10F67AB918CBDE}" FilePath="*appdata\roaming\microsoft\windows\sendto\desktop.ini" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C4D27834-212D-D423-6173D10B664BFD97}" FilePath="*appdata\roaming\microsoft\windows\sendto\fax recipient.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{94E3ED86-7703-6CA6-F418C4345DACE173}" FilePath="*appdata\roaming\microsoft\windows\sendto\mail recipient.mapimail" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{423A2086-2EC8-019E-EF33D30AF51E023D}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\accessibility\desktop.ini" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{75666CFC-A681-FC7B-882F0ACA075F6689}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\accessibility\magnify.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F103E400-FEFA-27C3-B409286EE2C4AEEF}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\accessibility\narrator.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{35D3417C-E33E-9C75-B93A443B35D8810E}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\accessibility\on-screen keyboard.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{52D40F57-E43B-EB14-7A2AA555EDAD9839}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\accessories\desktop.ini" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7DBBB20F-7956-F9EA-5B32B2544502A622}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{CEB4350A-D0C4-698A-759E8BF44B8B9253}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\maintenance\desktop.ini" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C449F008-C54C-6B17-2A0606D7362DDA2F}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\onedrive.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{661F9237-9315-7F43-90B3B53E4CF3F3CD}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{1D7F01F7-CFE9-6AC6-4074BFB4F4C85385}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\system tools\computer.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{BDC04244-0A42-11E0-7826C2D1CF3A7397}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\system tools\control panel.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E0A01B61-5262-44AC-5BFE6DCB49F79DD1}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\system tools\desktop.ini" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{205333F8-D00F-7119-865F0639B37626A8}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\system tools\file explorer.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{3EFAD3FF-FEC6-4C2B-C7AA58732563665E}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\system tools\run.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A5AB5433-47E1-A5D9-EFCF1E8E9E1F5C62}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\windows powershell\desktop.ini" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{64CB49EA-AE66-EE0E-1D9F7FD26D311D3B}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell (x86).lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E4F9A86F-D089-F23E-2E158874C2C43F02}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell ise (x86).lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{46BC767B-C2C9-307D-EBE3D60F53310667}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell ise.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F82730F9-61A0-F593-8B3D3CE800F68BC0}" FilePath="*appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell.lnk" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0FF95250-2B6F-3ED9-9556289100727315}" FilePath="*appdata\roaming\microsoft\windows\themes\cachedfiles\cachedimage_*.jpg" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8B6C4BB3-AF6D-115C-23D82C860B4A4F10}" FilePath="*appdata\roaming\microsoft\windows\themes\transcodedwallpaper" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C75184E4-036A-6C4B-751376254FD522E6}" FilePath="c:\users\*\citrix\grouppolicy\rsop.gpf" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{15A4ED2A-1260-888B-B781D4F850679364}" FilePath="c:\users\*\ntuser.dat" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{57E313C6-D093-CA24-6936543982A8C458}" FilePath="c:\users\*\ntuser.ini" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{10F75F80-F83B-245A-A7C8E822479473E5}" FilePath="c:\users\*\ntuser.pol" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B919CB79-9446-0D45-76E85E1A66E28F06}" FilePath="c:\users\*\tempntuser.pol" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B9B1A13D-E929-DC5E-4E92A4F8E1DC6638}" FilePath="*logs\windowsupdate\windowsupdate.20*.etl" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{115A4E77-82F7-007C-95E6D14640E81A2A}" FilePath="*\serviceprofiles\networkservice\appdata\local\microsoft\windows\deliveryoptimization\state\migration.dat" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7937A442-8A3D-76D6-795E926186B3D24B}" FilePath="*\servicestate\eventlog\data\lastalive0.dat" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DB52F396-A7AA-BDB9-DEBE31CB92312AF1}" FilePath="*\servicestate\eventlog\data\lastalive1.dat" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B48D77B3-4C11-587B-E3DE210806D048CC}" FilePath="*\servicestate\winhttpautoproxysvc\data\cachev3.dat" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B2CFF154-F4F3-15D8-30148617B708B2E4}" FilePath="*\softwaredistribution\datastore\datastore.edb" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{85733798-4211-88DA-390D7E65948A9BD7}" FilePath="*\softwaredistribution\datastore\logs\edb00???.log" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8A460EE0-2F26-1800-C452300E76C2A27C}" FilePath="*\softwaredistribution\reportingevents.log" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8A7F11D8-5518-D208-8BCC3041BD425F9B}" FilePath="*\softwaredistribution\sls\????????-????-????-????-????????????\sls.cab" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C89D28B2-1F67-E39D-FF01B08ACB5F35E4}" FilePath="*system32\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\????????????????????????????????_????????????????????????????????" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{73A182E6-33C5-2ACA-99B93BB8050C545A}" FilePath="*system32\tasks\microsoft\windows\installservice\smartretry" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{5F43B285-57D4-4311-90EC30F312C908C5}" FilePath="*system32\tasks\microsoft\windows\pushtoinstall\registration" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{4DF5FC86-58B0-0478-186BE47A75F66FCC}" FilePath="*system32\tasks\microsoft\windows\softwareprotectionplatform\svcrestarttask" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{1951DCE5-79B9-EB84-30CE91AEDACF0336}" FilePath="*system32\tasks\microsoft\windows\updateorchestrator\schedule scan" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{188BAE38-E31E-C599-BA6892394406E85C}" FilePath="*system32\tasks\microsoft\windows\windowsupdate\scheduled start" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{BDFEBB7F-84A9-0106-8563624AA66EC561}" FilePath="*appdata\local\temp\vsi\homedrive\spreadsheet.xlsx" >
		<Process Path="*excel.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{2E151E38-539B-2C6A-802FC61982E82D1B}" FilePath="*appdata\roaming\microsoft\office\recent\*.lnk" >
		<Process Path="*excel.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{9FE78398-A189-049E-7BC03CA4CB65C69B}" FilePath="*appdata\local\temp\vsi\homedrive\????????" >
		<Process Path="*excel.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{82D6218F-D5E1-C7B7-BAE5E0E450D0D74B}" FilePath="*appdata\local\temp\vsi\homedrive\????????.tmp" >
		<Process Path="*excel.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E529FCDF-89DB-14A1-CB3BED5F8DA8D108}" FilePath="*appdata\local\temp\vsi\homedrive\???????" >
		<Process Path="*excel.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{45A35E54-44D4-7FD4-968115BA72412129}" FilePath="*appdata\local\temp\vsi\homedrive\???????.tmp" >
		<Process Path="*excel.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{28A5F87C-FD3C-407E-9FB1622D3313B38A}" FilePath="*appdata\local\temp\vsi\homedrive\??????" >
		<Process Path="*excel.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{ACB00EF3-57B3-0FDB-81C13A66DE6340CA}" FilePath="*appdata\local\temp\vsi\homedrive\??????.tmp" >
		<Process Path="*excel.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{FD7DA532-1796-4710-5EA4783B2207FC6B}" FilePath="*appdata\roaming\microsoft\excel\spreadsheet308762133956033872\spreadsheet.xlsx.lnk" >
		<Process Path="*excel.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{FA9E6941-BE99-97AF-442D2783866EC292}" FilePath="*appdata\local\temp\vsi\zip\vsi7zlc.7z" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\Lib\7za.exe" CmdLine="*.pst" />
	</File>
	<File Id="{00AA6236-BA29-3711-07412E0B146DC581}" FilePath="*appdata\local\temp\vsi\zip\vsi7zhc.7z" >
		<Process Path="*AppData\Local\Temp\VSI\RunTime\Lib\7za.exe" CmdLine="*.pst" />
	</File>
	<File Id="{FFF6868B-D26D-0F1E-D8B1C5B94EC7F503}" FilePath="*\AppReadiness\S-1-5-21-??????????-??????????-??????????-?????" Operation="Delete" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{3DC7422E-254E-A4FE-7F821D3CCA78C8E9}" FilePath="*usoprivate\updatestore\updatestore*.xml" >
		<Process Path="*usocoreworker.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{14159C3D-8350-9670-59A7F78BB3E7A6DC}" FilePath="*appdata\local\microsoft\forms\frmdata64.dat" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{4BE1CB59-C448-9788-4EDE0C9F84356E75}" FilePath="*appdata\local\microsoft\outlook\roamcache\stream_*.dat" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{C23928B0-2E3D-8F5B-4445CA1247233944}" FilePath="*appdata\local\temp\vsi\homedrive\outlook\personalfolders.pst" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{1E460313-9700-1000-A5E629CFADDAE275}" FilePath="*appdata\roaming\microsoft\outlook\outlook.srs" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{0495CA72-88E7-408D-AB1084C013824725}" FilePath="*appdata\roaming\microsoft\outlook\outlook.xml" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{FF4EDD79-B99C-3923-4A7DA2C59BBBF6E1}" FilePath="*appdata\roaming\microsoft\templates\normalemail.dotm" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{F8D42E00-3C91-9D57-7FDF9A9F306C38F1}" FilePath="*appdata\roaming\microsoft\templates\~$rmalemail.dotm" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{0E0FD3F3-B2AC-3928-AF10878AC11132A4}" FilePath="*system32\perfstringbackup.ini" >
		<Process CmdLine="wmiadap.exe /R /T" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E1D2F72E-13B4-3644-F0727DC2C010F970}" FilePath="*system32\perfstringbackup.ini" >
		<Process CmdLine="wmiadap.exe /f /t /r" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{69974B21-7FE7-CC77-850BBD5EEE80B987}" FilePath="*\inf\wmiaprpl\0009\wmiaprpl.ini" >
		<Process CmdLine="wmiadap.exe /R /T" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{BCD0E584-26EC-C7BF-DF520D5CEB792678}" FilePath="*\inf\wmiaprpl\0009\wmiaprpl.ini" >
		<Process CmdLine="wmiadap.exe /f /t /r" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{DC9823BF-BB51-9CD1-E2F70EE38D8AA3DC}" FilePath="*system32\perfc009.dat" >
		<Process CmdLine="wmiadap.exe /R /T" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{AA1E82BC-E389-8E9B-D508D4AE43816A68}" FilePath="*system32\perfc009.dat" >
		<Process CmdLine="wmiadap.exe /f /t /r" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{8F6AB571-33AA-861E-DD1A71366EC638D8}" FilePath="*system32\wbem\performance\wmiaprpl.h" >
		<Process CmdLine="wmiadap.exe /R /T" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{83EFCA37-93C3-4B87-E5F61D098D2F2395}" FilePath="*system32\wbem\performance\wmiaprpl.h" >
		<Process CmdLine="wmiadap.exe /f /t /r" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{80183D5E-59EF-26AF-F541B77E9FF01B5E}" FilePath="*system32\perfh009.dat" >
		<Process CmdLine="wmiadap.exe /R /T" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{C4503210-627C-DCB3-3FC879446794BCBC}" FilePath="*system32\perfh009.dat" >
		<Process CmdLine="wmiadap.exe /f /t /r" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{2334E0C5-E098-E0D6-1547B3862585B813}" FilePath="*system32\wbem\performance\wmiaprpl.ini" >
		<Process CmdLine="wmiadap.exe /R /T" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{00AB5F0B-A76B-19E0-0BDFD98C34C1FA3C}" FilePath="*system32\wbem\performance\wmiaprpl.ini" >
		<Process CmdLine="wmiadap.exe /f /t /r" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{D406421D-0EDD-3905-D8FD92B27A99B09E}" FilePath="*system32\perfstringbackup.tmp" >
		<Process CmdLine="wmiadap.exe /R /T" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{C3EF1D1C-4CE8-C983-928C5A8357E88FCE}" FilePath="*system32\perfstringbackup.tmp" >
		<Process CmdLine="wmiadap.exe /f /t /r" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{623CA961-0D85-C1C3-75B02D9347A1C42B}" FilePath="*\inf\wmiaprpl\wmiaprpl.ini" >
		<Process CmdLine="wmiadap.exe /R /T" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{C1674866-7D87-205A-6A592764B42EB31F}" FilePath="*\inf\wmiaprpl\wmiaprpl.ini" >
		<Process CmdLine="wmiadap.exe /f /t /r" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{2DCC4A6C-A8DB-EDF2-800C6490F8180713}" FilePath="*system32\wbem\performance\wmiaprpl_new.ini" >
		<Process CmdLine="wmiadap.exe /R /T" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{938D8E7D-5EE3-696A-8959B7406E80173C}" FilePath="*system32\wbem\performance\wmiaprpl_new.ini" >
		<Process CmdLine="wmiadap.exe /f /t /r" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{7DE48DD4-B989-FAD6-4EABA605E5B613B2}" FilePath="*system32\wbem\performance\wmiaprpl_new.h" >
		<Process CmdLine="wmiadap.exe /R /T" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{3BF72048-B9F7-3ECB-0739D8848F694331}" FilePath="*system32\wbem\performance\wmiaprpl_new.h" >
		<Process CmdLine="wmiadap.exe /f /t /r" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{9269759A-30B3-5249-1FA99F398124B425}" FilePath="*\inf\wmiaprpl\wmiaprpl.h" >
		<Process CmdLine="wmiadap.exe /R /T" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{AFEDEE8F-ED21-B443-F22100CCF3832B99}" FilePath="*\inf\wmiaprpl\wmiaprpl.h" >
		<Process CmdLine="wmiadap.exe /f /t /r" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{06533A4B-C74D-0699-22358C4E3F6FA65B}" FilePath="*appdata\local\packages\microsoft.*\tempstate\startunifiedtilemodelcache.dat*" >
		<Process CmdLine="*microsoft.* -servername:app.*.mca" />
	</File>
	<File Id="{EA8AB587-D466-9ADE-0FA78BB56ED67C45}" FilePath="*appdata\local\packages\microsoft.*\tempstate\~tartunifiedtilemodelcache.dat*" >
		<Process CmdLine="*microsoft.* -servername:app.*.mca" />
	</File>
	<File Id="{A4280024-6085-477F-F60E1E1657AE9F45}" FilePath="*appdata\local\packages\microsoft.*\tempstate\tilecache_*.bin" >
		<Process CmdLine="*microsoft.* -servername:app.*.mca" />
	</File>
	<File Id="{BC2A0879-FD62-A1A1-654BEE26E7CC670D}" FilePath="*\programdata\VMware\VDM\logs\debug-20??-??-??-*.txt" >
		<Process Path="*wsnm_jms.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{7A4D687B-C3F7-4FEE-87F9B350366D32AD}" FilePath="*\programdata\VMware\VDM\logs\debug-20??-??-??-*.txt" >
		<Process Path="*v4pa_agent.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{ED15EA39-FF12-3C9A-9496700F1DFF9C93}" FilePath="*\programdata\VMware\VDM\logs\debug-20??-??-??-*.txt" >
		<Process Path="*vmwareviewclipboard.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{7FD18117-510C-2FD0-57AED4105DFC5FC0}" FilePath="*\programdata\VMware\VDM\logs\debug-20??-??-??-*.txt" >
		<Process Path="*vmwareview-rdeserver.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{F35552E1-EB21-EFAE-69C7CE0E3784B8C9}" FilePath="*\programdata\vmware\vdm\logs\log-20??-??-??.txt" >
		<Process Path="*wsnm_jms.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{BB1FCF59-AD8D-52A2-09E1A89D7BD5E8B6}" FilePath="*\programdata\vmware\vdm\logs\log-20??-??-??.txt" >
		<Process Path="*v4pa_agent.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{9782AF35-E643-5519-91AD860AC23EA9D6}" FilePath="*\programdata\vmware\vdm\logs\log-20??-??-??.txt" >
		<Process Path="*vmwareviewclipboard.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{D40DFEE8-578A-C3E9-2856B4679DC49675}" FilePath="*\programdata\vmware\vdm\logs\log-20??-??-??.txt" >
		<Process Path="*vmwareview-rdeserver.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{33D7264A-105A-CDE8-00AADC7B17B92D56}" FilePath="*appdata\local\temp\vmware-*\vmware-*-????.log" >
		<Process Path="*wsnm_jms.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{FDC01D60-B35C-0E26-FB912A8843D0BFEF}" FilePath="*appdata\local\temp\vmware-*\vmware-*-????.log" >
		<Process Path="*v4pa_agent.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{2BE8F5C4-BF2D-09A4-2698446F9D561EB5}" FilePath="*appdata\local\temp\vmware-*\vmware-*-????.log" >
		<Process Path="*vmwareviewclipboard.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{9A32B90E-0D4D-660A-989C226B83FEEF58}" FilePath="*appdata\local\temp\vmware-*\vmware-*-????.log" >
		<Process Path="*vmwareview-rdeserver.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{5DF4C893-56FD-A046-4680A665AE5F63F0}" FilePath="*appdata\roaming\vmware\preferences.ini.lck\??????.lck" >
		<Process Path="*wsnm_jms.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{DD923193-B6FC-760C-52A7BE23396A15F8}" FilePath="*appdata\roaming\vmware\preferences.ini.lck\??????.lck" >
		<Process Path="*v4pa_agent.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{80BB45F4-8763-B739-BAF814D906624009}" FilePath="*appdata\roaming\vmware\preferences.ini.lck\??????.lck" >
		<Process Path="*vmwareviewclipboard.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{29DA712E-E1C3-5892-6DBF51C4A2AEE55C}" FilePath="*appdata\roaming\vmware\preferences.ini.lck\??????.lck" >
		<Process Path="*vmwareview-rdeserver.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{A24BADE7-2E32-D370-16DB36D2C1C383D4}" FilePath="*programdata\vmware\vdm\logs\vmware-vdpservice-rdeserver-*.log" >
		<Process Path="*vmwareview-rdeserver.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{DEEDC9D1-6FB2-E2EC-80137066DEA17810}" FilePath="*windows\temp\vmware-system\vmware-rdesvc-1-*.log" >
		<Process Path="*vmwareview-rdeserver.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{C52AF908-4E56-D719-FBD0C1360CA90375}" FilePath="*\programdata\VMware\VDM\logs\debug-20??-??-??-*.txt" >
		<Process Path="*vmblastw.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{0A8819A4-91F9-27AF-949D054B5CEB1A94}" FilePath="*\programdata\vmware\vdm\logs\log-20??-??-??.txt" >
		<Process Path="*vmblastw.exe" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{C842E3D9-A85E-C1A9-CA4BEAEAD3DCBA0C}" FilePath="*programdata\vmware\vmware blast\blast-worker-sessionid1.log" >
		<Process CmdLine="*vmblastw.exe -uuid*" >
			<Signature Subject="*VMware*" />
		</Process>
	</File>
	<File Id="{B83C2F25-9848-EDC9-37E86A42EE7D11E4}" FilePath="*\programdata\vmware\vdm\logs\debug-20??-??-??-*.txt" >
		<Process Path="*lsass.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D95108C1-CF62-A0C2-EA9A206DBB6A32C6}" FilePath="*\programdata\vmware\vdm\logs\log-20??-??-??.txt" >
		<Process Path="*lsass.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{5EDD5D9F-3967-BFC7-AAAD509D4259BC84}" FilePath="*doropdfwriter\temp\?????.tmp" >
		<Process Path="*spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{424B08FB-3819-28A2-9D7C1D5A4D31D8AA}" FilePath="*doropdfwriter\temp\??????.tmp" >
		<Process Path="*spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{9A9E55AD-02F6-75C7-436E3FB4F4560C9B}" FilePath="*doropdfwriter\temp\???????.tmp" >
		<Process Path="*spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F9D9609C-C765-D0C6-B7F989B8B6E00898}" FilePath="*system32\spool\printers\0000?.shd" >
		<Process Path="*spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0C560875-BE9C-4455-774932AD9FB22818}" FilePath="*system32\spool\printers\000??.spl" >
		<Process Path="*spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{691DBE5A-F0B1-60C2-56EEC88CCDA47368}" FilePath="*system32\spool\printers\fp000??.shd" >
		<Process Path="*spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{4906ED89-41C8-6F2B-6FD9FD196128F3B5}" FilePath="*system32\spool\printers\fp000??.spl" >
		<Process Path="*spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6326B147-247D-2B62-2E92FF378C5D65BD}" FilePath="*\windows\temp\vmware-vmvss.log" >
		<Process CmdLine="*system32\dllhost.exe /processid:{*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{907AA00C-3755-580C-78C51DEB607E49CC}" FilePath="*\programdata\vmware\vdm\logs\debug-20??-??-??-*.txt" >
		<Process CmdLine="tpautoconnect.exe -q -i vmware -a com1 -f *" >
			<Signature Subject="*ThinPrint*" />
		</Process>
	</File>
	<File Id="{825AB8C9-EDB7-1CA2-62E4F8A2D113DFEF}" FilePath="*\programdata\vmware\vdm\logs\log-20??-??-??.txt" >
		<Process CmdLine="tpautoconnect.exe -q -i vmware -a com1 -f *" >
			<Signature Subject="*ThinPrint*" />
		</Process>
	</File>
	<File Id="{C30AEFC9-E4E9-836D-B7C94C7DCC520024}" FilePath="*\programdata\vmware\vdm\logs\vmware-rdpvcbridge-tpautoconnect-*.log" >
		<Process CmdLine="tpautoconnect.exe -q -i vmware -a com1 -f *" >
			<Signature Subject="*ThinPrint*" />
		</Process>
	</File>
	<File Id="{AE4E0B3B-CAB8-526F-2FFF323348D25115}" FilePath="*appdata\local\adobe\acrobat\*\adobecmapfnt11.lst" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{176F2B40-7331-DABF-3E480541A48A8432}" FilePath="*appdata\local\adobe\acrobat\*\adobefnt??.lst.???" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{4EBA4FA5-A8F6-CEBA-DE0B4C6CF19803A2}" FilePath="*appdata\local\adobe\acrobat\*\adobefnt??.lst.????" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{F8A6A9BE-1D1B-C537-28DB97E3413D4E53}" FilePath="*appdata\local\adobe\acrobat\*\adobefnt??.lst.?????" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{3354792C-8970-C7FB-4C3B065DA0296213}" FilePath="*appdata\local\adobe\acrobat\*\adobesysfnt??.lst" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{586DD793-0760-672F-9409CAA3E69E5D7E}" FilePath="*appdata\local\adobe\acrobat\*\adobesysfnt??.lst~rf??????.tmp" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{2A656304-2F58-0AC7-E46BB0B0B1ECAE1C}" FilePath="*appdata\local\adobe\acrobat\*\cache\acrofnt??.lst" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{A5BF1DC1-19A9-EE1C-E42BC88B4AC9E7E3}" FilePath="*appdata\local\adobe\acrobat\*\cache\adobefnt??.lst.???" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{C72AA068-F15E-9136-58CC36E87CD3B9EA}" FilePath="*appdata\local\adobe\acrobat\*\cache\adobefnt??.lst.????" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{1AE2D674-B3BA-5D0A-AFD63D9D14609B07}" FilePath="*appdata\local\adobe\acrobat\*\cache\adobefnt??.lst.?????" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{86375E33-C6DB-81F9-F816C98B0065E32A}" FilePath="*appdata\local\adobe\acrobat\*\shareddataevents" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{13A3309E-B0DD-E031-EC59175DCBECDFF2}" FilePath="*appdata\local\adobe\acrobat\*\shareddataevents-journal" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{497300BC-C0D2-64D1-89F64578C8E5139D}" FilePath="*appdata\local\adobe\acrobat\*\usercache.bin" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{148235F5-9079-214B-EB8C65B33A6879F9}" FilePath="*appdata\local\adobe\color\acecache??.lst" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{C8C1B2A3-060C-C3BD-97C66381B0A665EC}" FilePath="*appdata\local\adobe\color\profiles\wscrgb.icc" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{1AAB5074-A2FB-6CBB-4967ECB13C1FE64B}" FilePath="*appdata\local\adobe\color\profiles\wsrgb.icc" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{3C7773BD-A8B4-DF33-D0200A9925645462}" FilePath="*appdata\local\temp\acrord32_sbx\a9????.tmp" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{D4C4C72A-9441-4829-CA2EDB0AD75CFCF8}" FilePath="*appdata\local\temp\acrord32_sbx\a9?????.tmp" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{7BF33637-A7F9-0D9A-905FE8807BBFF9DC}" FilePath="*appdata\locallow\adobe\acrobat\*\readermessages" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{7A876DDE-3F30-1200-D881B82F39E7EACA}" FilePath="*appdata\locallow\adobe\acrobat\*\readermessages-journal" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{867037C9-C841-108E-C6B354EE7EDA0CD9}" FilePath="*appdata\local\temp\armui.ini" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{5F525395-FB5E-75DA-3CA210693F6B96D3}" FilePath="*appdata\local\temp\adobearm.log" >
		<Process >
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{EC1FDD46-CC7C-FD80-18072F97D5AB52D5}" FilePath="*\programdata\vmware\vdm\logs\debug-20??-??-??-*.txt" >
		<Process Path="*rundll32.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8719CD27-3AD0-62D7-BA1B6A3C63959332}" FilePath="*\programdata\vmware\vdm\logs\log-20??-??-??.txt" >
		<Process Path="*rundll32.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{FFA263D8-5B64-0550-328A73D6EA016BCF}" FilePath="*appdata\local\microsoft\internet explorer\msimgsiz.dat" >
		<Process Path="*rundll32.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{362285C3-69B9-61E9-1ADFF1F727B5A9FA}" FilePath="*appdata\local\microsoft\windows\inetcache\low\msimgsiz.dat" >
		<Process Path="*rundll32.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{EC0FD5B6-F3F5-5C75-FF5A0C97D3E4D71F}" FilePath="*appdata\local\temp\vmware-*\vmware-*-????.log" >
		<Process Path="*rundll32.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8FDDF960-4C26-DE0B-2CA234EF9A27A841}" FilePath="*appdata\roaming\vmware\preferences.ini.lck\m?????.lck" >
		<Process Path="*rundll32.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D8A17F88-C8D1-A3B0-85D156A83EABEC33}" FilePath="*system32\config\systemprofile\appdata\local\d3dscache\*\????????-????-????-????-????????????.lock" >
		<Process Path="*devicecensus.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{1FCA64EA-6667-AE70-C840E4B6CFC52600}" FilePath="*$recycle.bin\s-1-*\desktop.ini" >
		<Process Path="*explorer.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0DE0D68B-A301-BD58-C044BDEA48DD5137}" FilePath="*appdata\local\iconcache.db" >
		<Process Path="*explorer.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8EA05E63-3B45-95B3-A1B738AF2129ABE5}" FilePath="*appdata\local\microsoft\gamedvr\knowngamelist.bin" >
		<Process Path="*explorer.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D35F9975-13E9-C0B2-8D42BB64171CDD81}" FilePath="*appdata\local\microsoft\windows\*\structuredqueryschema.bin" >
		<Process Path="*explorer.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{5C7C7A6B-3DA7-34CF-BE8D013E7EC4A2B6}" FilePath="*appdata\local\microsoft\windows\burn\burn*\desktop.ini" >
		<Process Path="*explorer.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{46CC538D-DA8B-1C52-7CFC0E376736CFCA}" FilePath="*appdata\local\microsoft\windows\caches\cversions.?.db" >
		<Process Path="*explorer.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E55A8FEC-0D38-AD92-DA915C27B8157449}" FilePath="*appdata\local\temp\vsi\homedrive\$recycle.bin\desktop.ini" >
		<Process Path="*explorer.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8375B36B-15CC-8A9C-207BB32F0FFF46B4}" FilePath="*appdata\local\microsoft\*\usagelogs\vsidate.exe.log" >
		<Process Path="*\vsidate.exe" />
	</File>
	<File Id="{A44DB094-E407-760E-41EE86A622B3306B}" FilePath="*appdata\roaming\microsoft\windows\recent\customdestinations\*.customdestinations-ms" >
		<Process CmdLine="*iexplore.exe -embedding" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{1BC9DF8B-E778-6A1E-ACAAB229C8099211}" FilePath="*appdata\local\microsoft\internet explorer\recovery\high\last active\recoverystore.{????????-????-????-????-????????????}.dat" >
		<Process CmdLine="*iexplore.exe -embedding" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{9C9BB8B2-DDBA-5EE6-E5CCCBF2307185FF}" FilePath="*appdata\local\microsoft\internet explorer\msimgsiz.dat" >
		<Process CmdLine="*iexplore.exe -embedding" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{081B530A-D59B-B168-F54A2A2443F0EE1E}" FilePath="*appdata\local\microsoft\internet explorer\msimgsiz.dat" >
		<Process CmdLine="*iexplore.exe scodef*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{1D5D0EE8-E3F4-54F9-57DE730DE7E73557}" FilePath="*appdata\local\microsoft\windows\history\desktop.ini" >
		<Process CmdLine="*iexplore.exe -embedding" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{EF1F6BFB-0834-7358-445EF94081E317B1}" FilePath="*appdata\local\microsoft\windows\history\desktop.ini" >
		<Process CmdLine="*iexplore.exe scodef*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F6AAB970-007F-7020-B5C484C0AAB8EF4A}" FilePath="*appdata\roaming\microsoft\windows\recent\customdestinations\????????????????????.temp" >
		<Process CmdLine="*iexplore.exe -embedding" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{CC2ABDDB-CCC8-7079-E0ACC101F1EE8123}" FilePath="*appdata\roaming\microsoft\windows\recent\customdestinations\????????????????????.temp" >
		<Process CmdLine="*iexplore.exe scodef*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{2765146A-8C58-86E2-B7E699BB7C6C4F13}" FilePath="*\dbstore\logfiles\edbtmp.log" >
		<Process Path="*microsoftedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{3EF1F40C-A607-A793-99390766D4216942}" FilePath="*\dbstore\spartan.jfm" >
		<Process Path="*microsoftedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B79B87BB-DBE1-3EAC-DC954B39BF8EA613}" FilePath="*user\default\recovery\active\recoverystore.{????????-????-????-????-????????????}.dat" >
		<Process Path="*microsoftedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A9392159-05A0-FD17-AEB6407FA9C37CC8}" FilePath="*user\default\datastore\_temptestaccess.txt" >
		<Process Path="*microsoftedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{18CECE7F-9A16-4633-2DF9C72A02EAA2DE}" FilePath="*user\default\datastore\data\*\dbstore\edb.chk" >
		<Process Path="*microsoftedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{828C642F-094C-E771-17F1DB04FB9BE040}" FilePath="*\ac\???.createlock" >
		<Process Path="*microsoftedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0F0B7850-EB08-71CE-B57D64E24E6E20C1}" FilePath="*\dbstore\logfiles\edb.log" >
		<Process Path="*microsoftedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{3BB8997F-AB2C-3B2D-2C1A3F0E71D17C57}" FilePath="*\ac\temp\~df????????????????.tmp" >
		<Process Path="*microsoftedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A5700E0C-B1C5-DD96-7D76885EBBE8368B}" FilePath="*appdata\roaming\microsoft\systemcertificates\my\appcontainerusercertread" >
		<Process Path="*taskhostw.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C82D3F40-D6B8-3D62-CD28E8AF000FA491}" FilePath="*appdata\local\microsoft\windows\webcache\webcachev01.jfm" >
		<Process Path="*taskhostw.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{98E7156D-1FEE-0C18-FF4F692A87C3E179}" FilePath="*appdata\local\microsoft\windows\webcache\v01.log" >
		<Process Path="*taskhostw.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{086B877F-FAF9-9D03-7594F71FEC9FE1F2}" FilePath="*appdata\local\microsoft\windows\webcache\v01tmp.log" >
		<Process Path="*taskhostw.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{59AF85D0-AE31-BF2F-020CB639A7F7AAA2}" FilePath="*\security\database\edbtmp.log" >
		<Process Path="*services.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{3A60DC6E-CA4D-C847-6DF716A694107D78}" FilePath="*\security\database\edb.chk" >
		<Process Path="*services.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{1885B52F-4062-52E1-EB3A07652FE32718}" FilePath="*\security\database\edb.log" >
		<Process Path="*services.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{76E2D3D6-94A7-45DE-C328E00F9EB555EB}" FilePath="*system32\spool\printers\000??.spl" >
		<Process Path="*windows\splwow64.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0B2C1D87-E3E0-2018-1F2038DA24BE29C5}" FilePath="*appdata\roaming\microsoft\templates\~$normal.dotm" >
		<Process Path="*winword.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{5EE4C0E7-EE5E-3030-C301C36FE41FFD4B}" FilePath="*appdata\roaming\microsoft\templates\normal.dotm" >
		<Process Path="*winword.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F908601C-474A-B12E-126584AF6D9BBC8B}" FilePath="*programdata\microsoft\windows\systemdata\s-1-5-18\readonly\lockscreen_z\lockscreen___????_????_notdimmed.jpg*" >
		<Process CmdLine="*logonui.exe /flags*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{1A05AD10-109A-9E15-9BEB1BEDEA94214A}" FilePath="*programdata\microsoft\windows\systemdata\s-1-5-18\readonly\lockscreen_z\*notdimmed.jpg" >
		<Process CmdLine="*logonui.exe /flags*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7B245B18-5C2D-48FA-A60FC7C7FE2C46DE}" FilePath="*programdata\microsoft\windows\systemdata\s-1-5-18\readonly\lockscreen_z\*notdimmed.tmp" >
		<Process CmdLine="*logonui.exe /flags*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{2E4853ED-F5F9-3EFB-DEDFE19C8388B3C9}" FilePath="*programdata\microsoft\windows\systemdata\s-1-5-18\readonly\lockscreen_z\*_notdimmed.jpg~rf??????.tmp" >
		<Process CmdLine="*logonui.exe /flags*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6CCFE03F-0348-A8B7-2550841A9F99C94A}" FilePath="*programdata\vmware\vdm\logs\debug-20??-??-??-*.txt" >
		<Process CmdLine="*logonui.exe /flags*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{75A3A120-7C44-6A51-C02639C0A6C6CE9C}" FilePath="*programdata\vmware\vdm\logs\log-20??-??-??.txt" >
		<Process CmdLine="*logonui.exe /flags*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6757F6C8-8659-E0EC-545A0AFFCD42A932}" FilePath="*system32\config\systemprofile\appdata\local\microsoft\windows\caches\cversions.3.db" >
		<Process CmdLine="*logonui.exe /flags*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AECD91B0-4BA3-D3DB-CEBC0D86CA5B38D0}" FilePath="*system32\config\systemprofile\appdata\local\microsoft\windows\caches\{????????-????-????-????-????????????}.3.ver0x0000000000000001.db" >
		<Process CmdLine="*logonui.exe /flags*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{4EAEB7ED-70D0-1717-D35481B41A88BEFA}" FilePath="*programdata\teradici\pcoipagent\logs\pcoip_perf_provider_20??_??_??_000?????.txt" >
		<Process CmdLine="*wmiprvse.exe -embedding" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E0944323-6E0C-7CD0-726905134582297C}" FilePath="*doropdfwriter\temp\*.tmp" >
		<Process Path="*doro.exe" CmdLine="*Doro PDF Writer*" >
			<VersionInfo ProductName="CompSoft Doro" />
		</Process>
	</File>
	<File Id="{FBDCC03C-1545-4549-1170E37A899108FA}" FilePath="*appdata\local\temp\vsi\homedrive\output\*print.pdf" >
		<Process Path="*doro.exe" CmdLine="*Doro PDF Writer*" >
			<VersionInfo ProductName="CompSoft Doro" />
		</Process>
	</File>
<!-- Part 0004 End 2021-03-31T23:27:00.000Z-1617233233 -->

<!-- ############################################################################################################### -->
<!-- Part 0005 Start 2021-05-20T13:15:00.000Z-1621516503 -->
	<File Id="{A6801D13-AAA0-7559-7A8B587808E7E446}" FilePath="*programdata\solarwinds\agent\tmp\taskproperties.????????-????-????-????-????????????" >
		<Process >
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{A05EEBAB-F96B-F155-7A321D7342BB43D9}" FilePath="*programdata\solarwinds\logs\agent\solarwinds.agent.service.exe.*.log.txt" >
		<Process >
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{833E3DFE-9EEA-A324-5009D5E0A4A4CFA3}" FilePath="*programdata\microsoft\sharepoint\config\*tmp" >
		<Process Path="*bin\owstimer.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AA81C9DF-F1A9-95E0-F9368DDCFC198A3C}" FilePath="*common files\microsoft shared\web server extensions\*tmp" >
		<Process Path="*bin\owstimer.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{9306B9A4-6313-5666-72CBEFD2E64C1E27}" FilePath="*common files\microsoft shared\web server extensions\*tmp" >
		<Process Path="*bin\wsstracing.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{2AF6B900-32C8-6725-972AE02D46B8886D}" FilePath="*common files\microsoft shared\web server extensions\*usage" >
		<Process Path="*bin\wsstracing.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0FA11D5A-2DEA-3EA6-AFA91F872CDDCE6C}" FilePath="c:\windows\xprotectrecsrv\xpapsadstatus.csv" >
		<Process Path="system" />
	</File>
	<File Id="{AE4CD398-FB88-6DF1-872A4E75DAE18F73}" FilePath="*programdata\milestone\milestone surveillance\log.dat.tmp" >
		<Process >
			<Signature Subject="*Milestone*" />
		</Process>
	</File>
	<File Id="{6792F709-43CB-976E-BA2156558D6A3BCB}" FilePath="*xprotectrecsrv\xpapsadstatus.csv" >
		<Process >
			<Signature Subject="*Milestone*" />
		</Process>
	</File>
	<File Id="{071D26C6-CCFF-4EC4-B9CA7E87685BA6BF}" FilePath="*programdata\regid*.swidtag" >
		<Process CmdLine="*svchost.exe -k wsappx -p -s clipsvc" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7853E650-6B27-083F-D865BFC342AEB9F8}" FilePath="*programdata\hewlett-packard\usbbulk\exclusivelocks\usb*" >
		<Process Path="*hp\hplaserjetservice\hplaserjetservice.exe" >
			<VersionInfo FileDescription="HP LaserJet Service" />
		</Process>
	</File>
	<File Id="{E30C99EF-3D7F-89C5-1A5031F5E6E72FAA}" FilePath="*eventdata\processed\aud*.txt" >
		<Process CmdLine="*java*" />
	</File>
	<File Id="{41BD9A28-5F93-EBE6-6E929306098E4F47}" FilePath="*plus\temp\ads*.txt" >
		<Process CmdLine="*java*" />
	</File>
	<File Id="{CB993683-5A46-9BC1-3676F30A60A4587A}" FilePath="*arsystem\ftsconfiguration\collection\*" >
		<Process CmdLine="*java*" />
	</File>
	<File Id="{638799DC-31E5-1960-F99138492AE40865}" FilePath="*appdynamics-events-service-cluster\nodes\*" >
		<Process CmdLine="*java*" />
	</File>
	<File Id="{D40BAE04-F03E-C7F3-D9F5977B5C9A704C}" FilePath="*websense\*" >
		<Process >
			<Signature Subject="*websense*" />
		</Process>
	</File>
	<File Id="{8F44FA20-5A8B-A609-5A9F7BA38ED67D40}" FilePath="*websense\*" >
		<Process CmdLine="*websense\websense endpoint*FilterSDK\kvoop.exe*" >
			<VersionInfo FileDescription="KeyView OOP APP" />
		</Process>
	</File>
	<File Id="{FFA90AC8-0892-DF22-5A2924CE8BCAE024}" FilePath="*\windows\temp\qip*.tmp*" >
		<Process CmdLine="c:\program files\websense\websense endpoint\wepsvc.exe -k ss" >
			<Signature Subject="*Forcepoint*" />
		</Process>
	</File>
	<File Id="{45DAD4D4-1DD6-2D12-D3BFFDABB5094BC9}" FilePath="*appdata\local\temp\*.tmp" >
		<Process CmdLine="*--fullposture" >
			<Signature Subject="*cisco*" />
		</Process>
	</File>
	<File Id="{947D49E2-440D-42CF-D167553E648401E0}" FilePath="*appdata\local\microsoft\windows\inetcookies\*" >
		<Process CmdLine="*prefetch*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{CA5F7FA9-9483-55B0-61EF369B02B3FEA7}" FilePath="*appdata\local\microsoft\windows\inetcache\ie\*" >
		<Process Path="*Program Files*\SAP\*" >
			<Signature Subject="SAP SE" />
		</Process>
	</File>
	<File Id="{2D5AA884-2717-24A4-EFE5C760D8B62EB9}" FilePath="*appdata\local\sap\nwbc\cache\abapobjectbasenavigation*" >
		<Process Path="*Program Files*\SAP\*" >
			<Signature Subject="SAP SE" />
		</Process>
	</File>
	<File Id="{9590D86A-5F11-23C8-0E3DB80BDD190D2B}" FilePath="*appdata\roaming\microsoft\windows\recent\customdestinations\*" >
		<Process Path="*Program Files*\SAP\*" >
			<Signature Subject="SAP SE" />
		</Process>
	</File>
	<File Id="{4E2E7EEF-CA0C-102D-482C216E0816D550}" FilePath="*windows\temp\sap????.tmp" >
		<Process Path="*Program Files*\SAP\*" >
			<Signature Subject="SAP SE" />
		</Process>
	</File>
	<File Id="{D7C118FE-09BF-D551-A7B87EA19419F39B}" FilePath="*microsoft\exchange server\*transportroles\data\temp\*.tmp" >
		<Process CmdLine="*workerlistening" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{4D4AC908-671C-BE2A-75F418D466CC04B9}" FilePath="*microsoft\exchange server\*monitorcache\*.log" >
		<Process CmdLine="*workerlistening" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{367F30AD-3125-9D85-6B698CEF16AB656D}" FilePath="*programdata\cyvera\*.json" >
		<Process Path="*palo alto*" >
			<Signature Subject="*Palo Alto*" />
		</Process>
	</File>
	<File Id="{24A1CE16-6A17-120B-0F9FAB7633D480DB}" FilePath="*perfcache\*.average\???\*log" >
		<Process Path="*program files\veeam\*" >
			<Signature Subject="*Veeam*" />
		</Process>
	</File>
	<File Id="{37E8B4CC-37C1-48BB-93BBFFAD007A8C14}" FilePath="*perfcache\*.average\???\*.sst" >
		<Process Path="*program files\veeam\*" >
			<Signature Subject="*Veeam*" />
		</Process>
	</File>
	<File Id="{607582FC-22AA-ECB6-B611384841F333F8}" FilePath="*prefetch\*.exe-*.pf" >
		<Process CmdLine="*system32\svchost.exe -k localsystemnetworkrestricted -p -s sysmain" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{1CECAB88-3643-573A-62105170633C410D}" FilePath="c:\windows\ccmcache\*.tmp" >
		<Process CmdLine="c:\windows\system32\svchost.exe -k netsvcs -p -s bits" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{43A64640-E382-EB27-B8F02B05510CE992}" FilePath="c:\windows\ccmcache\*.otf" >
		<Process CmdLine="c:\windows\system32\svchost.exe -k netsvcs -p -s bits" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D9C1D9F8-F851-3998-3FC941B9E7E5D533}" FilePath="*programdata\microsoft\windows\apprepository\*" >
		<Process CmdLine="*system32\svchost.exe -k wsappx -p -s appxsvc" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6EE3177C-3F30-D8C6-1DF4F8C56745B7A8}" FilePath="*programdata\microsoft\windows\wer\report*\report.wer.tmp" >
		<Process CmdLine="*system32\wermgr.exe -upload" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F1707183-4692-9545-74B66A73F2B8D6F2}" FilePath="*temp\__psscriptpolicytest_*.psm1" >
		<Process Path="*system32\*\powershell.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{804DADB1-95AF-ACD4-5D019673DA223698}" FilePath="*temp\__psscriptpolicytest_*.ps1" >
		<Process Path="*system32\*\powershell.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{9F96F6B0-3E5E-B868-FDB9175AEC6108C6}" FilePath="*programdata\synaptics\wudfhost*.etl" >
		<Process CmdLine="*system32\wudfhost.exe -hostguid*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
<!-- Part 0005 End 2021-05-20T13:15:00.000Z-1621516503 -->

<!-- ############################################################################################################### -->
<!-- Part 0006 Start 2021-07-08T00:11:00.000Z-1625875918 -->
	<File Id="{D75E67BF-55F1-08DB-6C322AC5E95FBF6B}" FilePath="*microsoft\windows\inetcache\ie\*.json" >
		<Process Path="*internet explorer\iexplore.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D49BFF75-3185-D286-68F1FA55FDEDCBB5}" FilePath="*microsoft\windows\inetcache\ie\*.htm" >
		<Process Path="*internet explorer\iexplore.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7E84B9D5-0709-7447-2BFA1B5C46BFECE2}" FilePath="*microsoft\windows\inetcache\ie\*.html" >
		<Process Path="*internet explorer\iexplore.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6DB4B509-F724-C7BC-A2C2180D198B44A2}" FilePath="*microsoft\windows\inetcache\ie\*.js" >
		<Process Path="*internet explorer\iexplore.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6D953CB5-0E7D-8C11-CD08CC018A986161}" FilePath="*microsoft\windows\inetcache\ie\*.png" >
		<Process Path="*internet explorer\iexplore.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{10CFAB2A-60EB-0E99-DA35AE3653338D90}" FilePath="*microsoft\windows\inetcache\ie\*.jpg" >
		<Process Path="*internet explorer\iexplore.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B473FE33-D85F-642C-39441235918D9DE7}" FilePath="*microsoft\windows\inetcache\ie\*.gif" >
		<Process Path="*internet explorer\iexplore.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A016F021-8AAE-B223-A87DED0ED6B00A77}" FilePath="*microsoft\windows\inetcache\ie\*.css" >
		<Process Path="*internet explorer\iexplore.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C8731A17-1AE1-695A-6EE754B4A50EC7B7}" FilePath="*microsoft\windows\inetcache\ie\*.dat" >
		<Process Path="*internet explorer\iexplore.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8F5327F6-4A34-83CE-7D2F13204E87A182}" FilePath="*appdata\roaming\microsoft\windows\recent\customdestinations\????????????????????.temp" >
		<Process Path="*internet explorer\iexplore.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AA7D66E8-88EF-40B5-43E414A7D024C606}" FilePath="c:\windows\security\templates\policies\tmpgptfl.inf" >
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{7D5A51E0-F75C-ABFE-563BB8A9802E7386}" >
		<Process Path="*klnagent.exe" >
			<Signature Subject="*kaspersky*" />
		</Process>
	</File>
	<File Id="{B77A6A7D-33BC-1C91-BC8B4D0ED2FF2097}" FilePath="c:\programdata\kasperskylab\*" >
		<Process >
			<Signature Subject="*kaspersky*" />
		</Process>
	</File>
	<File Id="{A9008B96-2481-A4A2-C492C5BA8A1B6E56}" FilePath="c:\programdata\kaspersky lab\*" >
		<Process >
			<Signature Subject="*kaspersky*" />
		</Process>
	</File>
	<File Id="{F81BD968-CB99-7B2F-C9259E0BE7F3877F}" FilePath="*local\microsoft\tokenbroker\cache\*.tbres" >
		<Process Path="*teams*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{9A4DF99E-D086-2AD8-54EDB53CED4A21D7}" FilePath="*appdata\roaming*microsoft*teams*" >
		<Process Path="*teams*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{BD047CCD-71CB-E4A4-6FD59521F2DEB1EC}" FilePath="*appdata\roaming\microsoft\windows\*" >
		<Process Path="*teams*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D65C5E87-020A-27C3-B28961D70C7329BF}" FilePath="*metadata\.plugins\oracle.eclipse.tools.common.services*" >
		<Process >
			<Signature Subject="*oracle*" />
		</Process>
	</File>
	<File Id="{E53EF100-7E7D-2E7B-CFA9A5DDE6D4E401}" FilePath="*metadata\.plugins\org.eclipse.core.resources*" >
		<Process >
			<Signature Subject="*oracle*" />
		</Process>
	</File>
	<File Id="{03BEDDA9-7CD0-38E7-47F0772160BA3241}" FilePath="*metadata\.plugins\org.eclipse.m2e.core*" >
		<Process >
			<Signature Subject="*oracle*" />
		</Process>
	</File>
	<File Id="{86EFA201-3BE5-E01A-60D68C87F1BDBD38}" FilePath="*appdata\local\temp\dict_cache*.tmp*" >
		<Process >
			<Signature Subject="*oracle*" />
		</Process>
	</File>
	<File Id="{AE3F490D-2F84-448A-3B5A07C864340358}" FilePath="*appdata\locallow\sun\java\*" >
		<Process >
			<Signature Subject="*oracle*" />
		</Process>
	</File>
	<File Id="{4FBAC398-1D39-CD6B-0B42A3B856C75868}" FilePath="*appdata\local\temp\imageio???????????????????.tmp" >
		<Process >
			<Signature Subject="*oracle*" />
		</Process>
	</File>
	<File Id="{8E455E1E-28BE-003F-427B7EB6126F32CA}" FilePath="*appdata\roaming\mysql\workbench\sql_workspaces*" >
		<Process Path="*\mysqlworkbench.exe" >
			<VersionInfo ProductName="MySQL Workbench" FileDescription="MySQL Workbench" />
		</Process>
	</File>
	<File Id="{8669EE20-9FF1-9569-010F25CFAF44DCF2}" FilePath="c:\ntswincash\production\temp\imageio???????????????????.tmp" >
		<Process Path="c:\ntswincash\production\jbin\wfica32.exe" />
	</File>
	<File Id="{65AEA946-BC72-673F-3D09029C4CB7674F}" FilePath="*appdata\local\temp\imageio???????????????????.tmp" >
		<Process Path="c:\ntswincash\production\jbin\logistics.exe" />
	</File>
	<File Id="{3AAC56DB-F042-E2F8-66A61A58BCB8D961}" FilePath="*appdata\local\adobe\*" >
		<Process >
			<Signature Subject="*adobe*" />
		</Process>
	</File>
	<File Id="{A003A6D4-0666-00E1-EC19E3E2FFA80087}" FilePath="*appdata\roaming\adobe\*" >
		<Process >
			<Signature Subject="*adobe*" />
		</Process>
	</File>
	<File Id="{42764C28-A192-5777-EFDA66B7414056B0}" FilePath="*appdata\locallow\adobe\*" >
		<Process >
			<Signature Subject="*adobe*" />
		</Process>
	</File>
	<File Id="{4BAD50D6-802F-698B-20B6AE50034F0F7B}" FilePath="*adobe\*" >
		<Process >
			<Signature Subject="*adobe*" />
		</Process>
	</File>
	<File Id="{1E939D8E-B0B9-E512-0C9CC7972A87E598}" FilePath="*appdata\local\temp\tmp????.tmp" >
		<Process >
			<Signature Subject="*adobe*" />
		</Process>
	</File>
	<File Id="{A21E5340-5A8F-910A-28872E84E91D5867}" FilePath="*temp\tmp????.tmp" >
		<Process >
			<Signature Subject="*adobe*" />
		</Process>
	</File>
	<File Id="{B4F5DE7C-7C0A-2720-3E57D5133FF83416}" FilePath="*appdata\local\temp\arc????\???????.tmp" >
		<Process >
			<Signature Subject="environmental systems research*" />
		</Process>
	</File>
	<File Id="{3541AA5D-BB7C-4D48-58ECB6D90298C703}" FilePath="c:\programdata\autodesk\*" >
		<Process >
			<Signature Subject="*autodesk*" />
		</Process>
	</File>
	<File Id="{1D7E83F7-CB77-A7E4-12EA3985BE9D3DE9}" FilePath="*appdata\roaming\autodesk\*" >
		<Process >
			<Signature Subject="*autodesk*" />
		</Process>
	</File>
	<File Id="{F97E22B1-F505-7D8B-27C206ECF1FAF5BA}" FilePath="*cache\js\????????????????_?" >
		<Process >
			<Signature Subject="*autodesk*" />
		</Process>
	</File>
	<File Id="{615F3BFE-CC56-7C9A-A02972AA2E39924D}" FilePath="*xcomparebackup\*.dwg" >
		<Process >
			<Signature Subject="*autodesk*" />
		</Process>
	</File>
	<File Id="{A277C853-622F-A227-869C835F734ECFC0}" FilePath="*xcomparebackup\*\index" >
		<Process >
			<Signature Subject="*autodesk*" />
		</Process>
	</File>
	<File Id="{3258E6C9-8B71-DD57-91DEF5F6E9B55E16}" FilePath="*appdata\local\temp\????????????????\local\*" >
		<Process >
			<Signature Subject="*autodesk*" />
		</Process>
	</File>
	<File Id="{FD84C0C4-3208-B174-0CB6E47562604880}" FilePath="*appdata\local\autodesk\*" >
		<Process >
			<Signature Subject="*autodesk*" />
		</Process>
	</File>
	<File Id="{B627B2F3-9CC5-6E62-1271D32F6BC1057A}" FilePath="*appdata\local\temp\.das.local.jobsroot*" >
		<Process >
			<Signature Subject="*autodesk*" />
		</Process>
	</File>
	<File Id="{82ABEB27-DD09-4FEF-CA2B9584F0BF638A}" FilePath="*appdata\local\temp\alerts\*" >
		<Process Path="c:\program files (x86)\deskalerts\deskalerts.exe" />
	</File>
	<File Id="{4E21E5C7-06C8-30C1-8CF1783A2CC501AD}" FilePath="c:\program files (x86)\globitel\speechlog retail client*" >
		<Process Path="c:\program files (x86)\globitel\speechlog retail client*" />
	</File>
	<File Id="{BF1CAD02-26B0-F225-5AFBDC94A376EB84}" FilePath="*appdata\local\temp\ge????\kmz\khtemp_*.kmz" >
		<Process >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{8F4DB1B3-58D4-6AD1-51E99AAF7AC3F085}" FilePath="*appdata\locallow\google\googleearth\*" >
		<Process >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{8D564CB1-A558-3E2B-169E5CBDC44C0DE2}" FilePath="c:\program files (x86)\google\*" >
		<Process >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{85AC5C3D-C9BD-0ABC-616EB5B83618E982}" FilePath="c:\program files\google\*" >
		<Process >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{74AC464F-E11A-C4DC-93379386841C20E9}" FilePath="c:\programdata\ssoprovider\offline\*" >
		<Process >
			<Signature Subject="*imprivata*" />
		</Process>
	</File>
	<File Id="{E5191784-C510-941B-05D286AD3CFBF55A}" FilePath="*.jpg" >
		<Process Path="c:\program files (x86)\knoahsoft\screen\harmonysc.exe" />
	</File>
	<File Id="{16958FDC-3F47-0825-AE3BEB6E770E777C}" FilePath="*appdata\local\microsoft\edge*" >
		<Process Path="*edge\application\msedge.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{52D702F5-E850-4136-A653C7A8C6197B48}" FilePath="*appdata\local\temp\cls-cc*" >
		<Process Path="*office\*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{BD60D198-F620-306D-F65FDF04E76C533C}" FilePath="*appdata\local\microsoft\windows\inetcache\content.mso\*.dat" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{1185E6DF-DB26-1A0F-AA1556B4024AF653}" FilePath="*appdata\local\temp\olk*.tmp" >
		<Process Path="*office\*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{29DD6DEF-C70C-0C23-6B063B92B3608239}" FilePath="*appdata\local\temp\~df????????????????.tmp" >
		<Process Path="*office\*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6266F92C-91DC-FDC1-A7DDE79DD7A1D276}" FilePath="appdata\local\kvs\enterprise vault\*" >
		<Process Path="*office\*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{763938E1-A70F-C0B5-71ACE8F0D765D023}" FilePath="*appdata\local\temp\sslnch*" >
		<Process >
			<Signature Subject="*thycotic*" />
		</Process>
	</File>
	<File Id="{7E206FD0-0079-87B6-8AF7164A32E34838}" FilePath="*appdata\local\microsoft\onedrive\*" >
		<Process Path="*\onedrive*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{44CA23CE-CE3F-C188-7A3A56CD7474C6B3}" FilePath="c:\windows\ccm\logs\*.log" >
		<Process Path="c:\windows\ccm\ccmexec.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{5C727CF2-66F1-6677-3769CD8B6721A7D5}" FilePath="c:\windows\assembly\nativeimages*.aux.tmp" >
		<Process Path="c:\windows\microsoft.net\framework*\mscorsvw.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{CD3EA2B6-8652-367C-9CDB7F4999FE5995}" FilePath="c:\windows\installer\msi???.tmp" >
		<Process Path="c:\windows\system32\msiexec.exe" />
	</File>
	<File Id="{AD2F6617-66C0-E83E-9B9DA648F1E43F1B}" FilePath="c:\windows\installer\msi????.tmp" >
		<Process Path="c:\windows\system32\msiexec.exe" />
	</File>
	<File Id="{17EA4428-1DB0-AA67-B3A9A5AEEDB23DD2}" FilePath="c:\windows\system32\config\systemprofile\appdata\local\tpm-????-???-??????.tmp" >
		<Process Path="c:\windows\system32\provtool.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B015CA57-3722-E232-76463B2E47928CED}" FilePath="c:\windows\system32\config\systemprofile\appdata\local\tpm-*.tmp" >
		<Process Path="c:\windows\system32\provtool.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E0702261-5182-D336-BDE6077BC0BB02B0}" FilePath="*appdata\local\temp\outlook logging\searchprotocolhost_*.etl" >
		<Process Path="c:\windows\system32\searchprotocolhost.exe" />
	</File>
	<File Id="{8FCAA018-5637-E5AA-AEAA817D3613AE6D}" FilePath="*appdata\local\microsoft\windows\actioncentercache\microsoft-office-outlook*.png" >
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{7837BFA3-B4D2-81FD-C913207A76022296}" FilePath="c:\windows\prefetch\*.pf" >
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{86D2714B-E321-3735-1FC6D372EC8C81A7}" FilePath="*appdata\local\packages\microsoft.windows.search*" >
		<Process Path="c:\windows\systemapps\microsoft.windows.search*\searchapp.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
<!-- Part 0006 End 2021-07-08T00:11:00.000Z-1625875918 -->

<!-- ############################################################################################################### -->
<!-- Part 0007 Start 2021-10-12T13:17:00.000Z-1634044655 -->
	<File Id="{451DF5F0-7A55-4BDC-ED278B9438395FFD}" FilePath="*appdata\roaming\sap\sap gui\history\*.db-journal" >
		<Process >
			<Signature Subject="sap se" />
		</Process>
	</File>
	<File Id="{8476BD40-3B2E-BD1D-0C9DE68AB0743F07}" FilePath="*appdata\local\sap\sap gui\*\tmp????.tmp" >
		<Process >
			<Signature Subject="sap se" />
		</Process>
	</File>
	<File Id="{00A883D0-69EF-6A7C-D01BDA067814F2AD}" FilePath="*appdata\local\sap\sap gui\traces\sapfe*.err.trc" >
		<Process >
			<Signature Subject="sap se" />
		</Process>
	</File>
	<File Id="{0EB0A5A0-399D-691C-6DCCE08B21809E1A}" FilePath="*appdata\roaming\sap\*\tmp????.tmp" >
		<Process >
			<Signature Subject="sap se" />
		</Process>
	</File>
	<File Id="{63A23825-B942-E2B2-3D710309E71D9EB5}" FilePath="c:\program files\windowsapps\deleted\microsoft.*" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{1AAC4C0D-2F29-D941-6E3C231D57AA7613}" FilePath="c:\programdata\microsoft\windows\wer\reportqueue*" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AE050AC8-F483-D96A-F02ABDDB77CBA46E}" FilePath="*appdata\local\comms\unistore\data\?\?\????????????????????.dat" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{62868A61-57D2-AE59-30CBD8E01C8ABFEA}" FilePath="*appdata\local\comms\unistore\data\temp\?????????????????????????????.dat" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{952051F4-72D1-E5A8-B0CFB4B10C14D22B}" FilePath="*appdata\local\comms\unistore\data\temp\tempids*.dat" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{67FF9E44-C779-4683-13E85821D212B52D}" FilePath="*appdata\local\microsoft\outlook\oab*.xml" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{2AC45EE4-EF32-6BD5-092A99083CDBA481}" FilePath="*appdata\local\microsoft\outlook*\bit*.tmp" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A5161E73-F780-A80B-311DE96474F7550B}" FilePath="*appdata\local\microsoft\windows\actioncentercache*" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{2CDB80B3-4EA4-B25A-2F4B5C9F114CCDF1}" FilePath="c:\windows\prefetch\*.*-*.pf" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{546235EA-5461-7A72-D011A8C838DFF5A8}" FilePath="c:\windows\system32\logfiles\sum\svc?????.log" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{FD4CA026-F217-54B8-B52F1A83C40C84BE}" FilePath="*temp\appx.?????????????????????????.tmp" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7B8009AC-066D-1C99-3648D1B3058AE706}" FilePath="*temp\appx.????????????????????????.tmp" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{716DA541-45D1-12C5-79F953481F8A6453}" FilePath="*appdata\local\packages\oice_*\temp\fl*.tmp" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{4369E91C-DAE2-DE5F-57BFA8597834CA99}" FilePath="*appdata\local\temp\fs*.tmp" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{23134565-048E-0166-6126C057D77A50CF}" FilePath="*appdata\local\temp\hsc*.tmp" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{397993C8-81A4-14A3-B2F113D9A1DFA72D}" FilePath="*appdata\local\temp\mso*.tmp" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F1DA291B-B1AB-C5FC-647978A3CBC7A8C6}" FilePath="*appdata\local\temp\olk*.tmp" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{867D4CA4-E5F9-2695-DF176AED850819F6}" FilePath="c:\programdata\seclore\filesecure\desktop client\*\fs??????.tmp" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B98EA817-C1EF-DB08-8F170F56DCF81A97}" FilePath="*appdata\local\assembly\tmp\*\__assemblyinfo__.ini" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0F83ABFE-9C0C-D442-5471F92B890B9962}" FilePath="*appdata\local\assembly\tmp\*.dll" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B2B2CD91-4537-A773-B6119EBE2CA46C53}" FilePath="*appdata\local\microsoft\windows\inetcache\content.mso\*.emf" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8F53576F-A047-1BBD-0108DD882C2B1B21}" FilePath="*appdata\local\microsoft\windows\inetcache\content.mso\*.png" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A876F745-E531-C3DB-4AC155E53259FA1F}" FilePath="*appdata\local\temp\??????????????????????????.tmp" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C76F1867-B3C1-50D8-A78C47CD74CB8750}" FilePath="*appdata\local\temp\{*vertipaq_*" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{95C6A7BA-FEFD-B792-6C731BF5DA9D1B80}" FilePath="*appdata\roaming\microsoft\excel\~ar????.xar" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{65BEC3FF-5316-C828-B2212435F8465D95}" FilePath="c:\users\*\desktop\????????" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{96FC7CC9-1ACF-5BAB-9CFD8A8B972D3C8B}" FilePath="c:\users\*\desktop\????????.tmp" >
		<Process Path="*office*" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D5AE6F43-C1E9-6544-99ED89C962B3B6C5}" FilePath="*appdata\local\temp\chrome_bits_*\bit????.tmp" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F46C7906-10A3-9C02-D001E731790DE813}" FilePath="*appdata\local\temp\chrome_bits_*\bit????.tmp" >
		<Process >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{831FFB4F-E47F-6DD9-41BB5531FD017F91}" FilePath="*appdata\local\temp\chrome_bits_*.crx3" >
		<Process >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E11D27BE-18F2-2D88-5BEE35E7FF8ED86B}" FilePath="*appdata\local\temp\chrome_bits_*.crx3" >
		<Process >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{DE14AACF-38BD-7A3A-DC22EEA391012944}" FilePath="*appdata\local\temp\qip*.qipt" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{1DF20242-B93F-98F5-E559B2AE07B5FD54}" FilePath="*appdata\local\temp\qip*.wefs" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{5568333B-3449-6061-3A75EDEDE9871DE7}" FilePath="c:\programdata\seclore\filesecure\desktop client\*\fs??????.tmp" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{4DA0E6E2-3849-AE96-4804B11EAAAA4C19}" FilePath="c:\programdata\seclore\filesecure\desktop client\*-activitylog.log" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
<!-- Part 0007 End 2021-10-12T13:17:00.000Z-1634044655 -->

<!-- ############################################################################################################### -->
<!-- Part 0008 Start 2021-10-13T14:08:00.000Z-1634134105 -->
	<File Id="{5C4283F8-1DE8-364B-1E71331FE06116B6}" FilePath="c:\panasonic\panasonic-dms\log\ptllog.log" >
		<Process Path="C:\Windows\System32\spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8084C5C9-451D-11BA-F11FCF509B14B9DF}" FilePath="c:\program files\plotsoft\pdfill\pdfwriter\temp\~tmp_pdfill_??????????.ps" >
		<Process Path="C:\Windows\System32\spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{987DBD59-1D2D-7E47-15C0BEE091AEF8E9}" FilePath="c:\programdata\mmr????.tmp" >
		<Process Path="C:\Windows\System32\spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DEAE43DC-8D30-1C7C-15A6D1B02B6F3F63}" FilePath="*appdata\local\hp\windows\fax\faxpcsend\*.bmp" >
		<Process Path="C:\Windows\System32\spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{986CF3FB-7C41-7F82-12744C8D22BC94E8}" FilePath="*appdata\roaming\pdf redirect\temp\?????????.ps" >
		<Process Path="C:\Windows\System32\spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AEDF780E-FE9B-AF96-9738F57ACAA4E230}" FilePath="*temp\????????????????????.bin" >
		<Process Path="C:\Windows\System32\spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6D9ECB3B-918A-17E0-A1E0D67FBB5739FE}" FilePath="*temp\cdm\plist\plist_*.inf" >
		<Process Path="C:\Windows\System32\spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7953A005-4ECC-E7D3-DA10299BC7AEEFA9}" FilePath="*temp\etilqs_???????????????" >
		<Process Path="C:\Windows\System32\spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{07D1C607-3854-F2D8-60FA8B2B50906F86}" FilePath="*temp\{????????-????-????-????-????????????}\i386\*" >
		<Process Path="C:\Windows\System32\spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{00227E24-A0DF-6EDC-B8B17883B2E4FC45}" FilePath="*temp\{????????-????-????-????-????????????}\amd64\*" >
		<Process Path="C:\Windows\System32\spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E21C7135-5D76-43E4-2C1B47B862A14B6E}" FilePath="*temp\{????????-????-????-????-????????????}" >
		<Process Path="C:\Windows\System32\spoolsv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
<!-- Part 0008 End 2021-10-13T14:08:00.000Z-1634134105 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0009 2021-12-23T16:37:00.000Z-1640277443 -->
	<File Id="{F782F07F-B8EC-AAA0-4538AFF20D1CAE0A}" FilePath="*securit\configurations*" >
		<Process >
			<Signature Subject="SecurIT*" />
		</Process>
	</File>
	<File Id="{8209A50D-40B0-803A-0543A817F9C5D05E}" FilePath="*zecurion\endpoint*" >
		<Process >
			<Signature Subject="SecurIT*" />
		</Process>
	</File>
	<File Id="{33DE8F05-4F8A-B3E1-E320ABC5F518EB25}" FilePath="*temp\dup2e4a.tmp*" >
		<Process >
			<Signature Subject="SecurIT*" />
		</Process>
	</File>
	<File Id="{C4085DD0-4BB6-62F1-15387414DC894FAB}" FilePath="c:\windows\ltcjobs\jobs\ltc\ltc*" >
		<Process CmdLine="c:\windows\ltcjobs\jobs\ltc\bin\ltcagent.exe c:\windows\ltcjobs\jobs\ltc\ltc\temp*" >
			<VersionInfo FileDescription="*Logical Trees Commander Agent" />
		</Process>
	</File>
	<File Id="{26601C39-A752-9D42-989E454E5CCF6CB9}" FilePath="c:\windows\ltcjobs\jobs\ltc\ltc*" >
		<Process CmdLine="c:\windows\ltcjobs\jobs\ltc\bin\ltcpolicy.exe  c:\windows\ltcjobs\jobs\ltc\ltc\policy\localpolicy.ltcpolicy /s" >
			<VersionInfo FileDescription="LtcPolicy MFC Application" />
		</Process>
	</File>
<!-- Part 0009 2021-12-23T16:37:00.000Z-1640277443 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0010 2021-12-24T20:48:00.000Z-1640378914 -->
	<File Id="{64031243-7B14-5530-CD5164E1340DF4FA}" FilePath="*appdata\local\temp\???????\*" >
		<Process Path="*common7\ide\devenv.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{EB969E92-7E2C-7796-81F455E96E9CBFA0}" FilePath="c:\programdata\microsoft\diagnosis\downloadedsettings\utc.*" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7CF0235C-32B1-D97D-AB9C4548C6E77A5B}" FilePath="*preferences\registry\registry.xml" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AB29DF67-AA84-8C87-F9855EB02C960071}" FilePath="c:\programdata\broadcom\hoststorage\sess.dat" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{EED5D05D-460C-2461-364F60C1EF2E57CD}" FilePath="c:\programdata\microsoft\diagnosis\downloadedsettings\telemetry.*" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{056C978F-E5B5-D8C6-BBFD35F07F91782D}" FilePath="c:\windows\system32\tasks\microsoft\windows\updateorchestrator\schedule *" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{48E494A4-C989-1E30-42F6528611C3CBE9}" FilePath="c:\windows\softwaredistribution\datastore\logs\edb.chk" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{27A7C17B-D357-863C-DB868A501EE9A3F3}" FilePath="c:\windows\softwaredistribution\datastore\datastore.jfm" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{7211B3A4-350A-DCAE-2B40398A4C42B7C8}" FilePath="c:\windows\servicestate\eventlog\data\lastalive0.dat" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{82AAE705-FC9B-1577-57315BB1E3E4AA05}" FilePath="c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\deliveryoptimization\logs\dosvc.*" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{865EF633-CB4F-3664-4D577345A871D134}" FilePath="c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\deliveryoptimization\cache\*" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{40050597-7C96-A347-4E3E47ECEE3AAC75}" FilePath="c:\windows\ccm\cidownloader\staging\bit*" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{44F95814-5DF8-8313-52130E1D3800AA36}" FilePath="*appdata\locallow\microsoft\cryptneturlcache\*" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AACAC946-FB7A-1FBE-B41350225697F457}" FilePath="appdata\local\temp\wct????.tmp" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{85BD4FB5-E9A8-3432-7C4BEE4969F12BB6}" FilePath="*appdata\local\temp\bit????.tmp" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AF1985F3-17FC-78F4-D90512791E61750E}" FilePath="*appdata\local\microsoft\windows\actioncentercache\*" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{237C4A3C-0DE6-2BEA-C6E3D21EEBF07F2D}" FilePath="c:\programdata\microsoft\windows\lfsvc\geofence\s-1-5-18_nonpackagedapp\geofence.dat" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DD5E3B47-266F-1C85-70AB5B5D791B0930}" FilePath="c:\programdata\microsoft\windows\devicemetadatacache\*" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DDA0ABA8-EB87-FAAF-C407927FA77B2356}" FilePath="c:\programdata\microsoft\windows\apprepository\staterepository-*" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DFC393C4-5710-BECD-1654217E0FFA6AA2}" FilePath="c:\programdata\microsoft\smsrouter\messagestore\edb*" >
		<Process Path="C:\WINDOWS\system32\svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
<!-- Part 0010 2021-12-24T20:48:00.000Z-1640378914 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0011 2021-12-29T12:26:00.000Z-1640780773 -->
	<File Id="{09952F88-7C0C-5EA3-46DA326D8F084BB2}" >
		<Process CmdLine="*zecurion\endpoint\zlu_agent64.exe -pid:*" >
			<Signature Subject="*SecurIT*" />
		</Process>
	</File>
	<File Id="{1942FE38-AA0F-DE2F-2A0EC0A2BAF4E7E0}" >
		<Process Path="c:\program files (x86)\landesk\ldclient\selfelectcontroller.exe" >
			<VersionInfo ProductName="%kl_undef%" FileDescription="%kl_undef%" />
		</Process>
	</File>
	<File Id="{B8454178-2001-86FD-980B3421686768C0}" >
		<Process Path="*CheckPoint\Endpoint Security\Endpoint Common\bin\cpda.exe" >
			<Signature Subject="*Check Point*" />
		</Process>
	</File>
	<File Id="{2F53B5FA-1D02-CE16-F29337CCCA7AAF74}" >
		<Process Path="*CheckPoint\Endpoint Security\Endpoint Common\bin\cpda.exe" >
			<Signature Subject="*CheckPoint*" />
		</Process>
	</File>
	<File Id="{69CF1F5F-5E9F-BED0-1931A4A56634CC14}" FilePath="c:\windows\internet logs\bu_to*.rdb" >
		<Process Path="c:\windows\syswow64\zonelabs\vsmon.exe" />
	</File>
	<File Id="{27D5FAC7-F8E1-ABE1-A7E4BCA3EC54F0D3}" FilePath="c:\windows\internet logs\backup.rdb" >
		<Process Path="c:\windows\syswow64\zonelabs\vsmon.exe" />
	</File>
	<File Id="{0D458E60-692B-3ADB-D37110D9F3A885B7}" FilePath="*appdata\local\temp\winmail*" >
		<Process Path="*\wmail.exe" >
			<Signature Subject="*InfoTeCS*" />
		</Process>
	</File>
	<File Id="{5EF959D2-B21E-DC3F-E1F8BFF70669080A}" FilePath="c:\news-dir\exch\*.arj" >
		<Process Path="c:\argus\argus.exe" />
	</File>
	<File Id="{31C99E37-F5E0-E3A9-1703151AB309D69A}" FilePath="c:\news-dir\intmp\badwazoo.???" >
		<Process Path="c:\argus\argus.exe" />
	</File>
	<File Id="{FAE7EEC7-FC37-EA79-9FEA9CDCF1A3E272}" FilePath="c:\atd\atd\astrn1doms??????????.strn" >
		<Process Path="c:\atd\atd\atdssclient.exe" />
	</File>
	<File Id="{147A3DB7-052B-7248-6203242D8EB2D7D4}" FilePath="*appdata\local\temp\jet???.tmp" >
		<Process Path="c:\mlevel\mlevel.exe" />
	</File>
	<File Id="{BC579A5A-C040-FD76-D004C4F511DF1BC8}" FilePath="*appdata\local\temp\jet????.tmp" >
		<Process Path="c:\mlevel\mlevel.exe" />
	</File>
	<File Id="{5C49E2AC-596A-9016-CF4A0906D78248B0}" >
		<Process Path="*SecurIT\*" >
			<Signature Subject="*SecurIT*" />
		</Process>
	</File>
	<File Id="{A589B24D-0833-07D6-29EFAC0698415D98}" FilePath="*landesk\ldclient\*" >
		<Process >
			<Signature Subject="*LANDesk*" />
		</Process>
	</File>
	<File Id="{87BA3679-6D0B-7F05-295E4734599C3CBB}" FilePath="c:\temp\ath*.pid" >
		<Process CmdLine="*bin\prowin32.exe -ininame*" />
	</File>
	<File Id="{E9ECB25A-D41E-48EC-202AD67807284C06}" FilePath="c:\news-dir\exch\*.arj" >
		<Process CmdLine="*bin\prowin32.exe -ininame*" />
	</File>
	<File Id="{385D9E74-A3B7-8FC1-729C9F4D89B86804}" FilePath="c:\spool\in\*.xml" >
		<Process CmdLine="*bin\prowin32.exe -ininame*" />
	</File>
	<File Id="{2501501A-3C9E-BEAF-35AF0CA4810258C9}" FilePath="c:\spool\out\*.xm1" >
		<Process CmdLine="*bin\prowin32.exe -ininame*" />
	</File>
	<File Id="{49A6953D-5B54-C290-7343FAA4B8BF1945}" FilePath="c:\temp\????????.xm1" >
		<Process CmdLine="*bin\prowin32.exe -ininame*" />
	</File>
	<File Id="{CB641182-B6C6-DB0E-8046CB06C5F62B44}" FilePath="c:\temp\p?????.bat" >
		<Process CmdLine="*bin\prowin32.exe -ininame*" />
	</File>
	<File Id="{5B1844F8-58F6-23E5-5F24B335046FB132}" FilePath="c:\temp\rpt*" >
		<Process CmdLine="*bin\prowin32.exe -ininame*" />
	</File>
	<File Id="{8C2DEACC-C494-05A0-EEE02DAFBD9EE815}" FilePath="c:\windows\syswow64\config\systemprofile\appdata\local\sifiltersvc*" >
		<Process >
			<Signature Subject="*Searchinform*" />
		</Process>
	</File>
<!-- Part 0011 2021-12-29T12:26:00.000Z-1640780773 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0012 2022-01-11T19:13:00.000Z-1641928381 -->
	<File Id="{C676FDB6-6651-D238-2FEE7187F3E45FBE}" FilePath="*Trend Micro\*" >
		<Process Path="*Trend Micro\*" >
			<Signature Subject="*Trend Micro*" />
		</Process>
	</File>
	<File Id="{F3121934-D32C-6CDD-0BCC8BAC48ADCE37}" FilePath="*temp\tmp*.tmp" >
		<Process Path="*Trend Micro\*" >
			<Signature Subject="*Trend Micro*" />
		</Process>
	</File>
	<File Id="{DC4B7A24-13AB-68CF-0D030AB094A1F641}" FilePath="c:\programdata\trend micro\*" >
		<Process Path="*Trend Micro\*" >
			<Signature Subject="*Trend Micro*" />
		</Process>
	</File>
	<File Id="{5CF012DE-5084-4CA5-E44364A449B319F4}" FilePath="*temp\etilqs_???????????????" >
		<Process Path="*Trend Micro\*" >
			<Signature Subject="*Trend Micro*" />
		</Process>
	</File>
	<File Id="{FE7A69DA-5F95-FE44-B8A4D48F699922CF}" FilePath="*temp\dre*.tmp" >
		<Process Path="*Trend Micro\*" >
			<Signature Subject="*Trend Micro*" />
		</Process>
	</File>
	<File Id="{79F4F6E9-9BE0-17E5-11C0E24E7CB0AB29}" FilePath="*temp\vs??????.???" >
		<Process Path="*Trend Micro\*" >
			<Signature Subject="*Trend Micro*" />
		</Process>
	</File>
	<File Id="{909AA56A-C9AA-EA50-B805FCE9F381FEE0}" FilePath="*appdata\roaming\360*" >
		<Process Path="*360\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{D9E808D3-6630-83F3-F3A3E10D75DE079A}" FilePath="*360\360safe*" >
		<Process Path="*360\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{9FA88384-5243-B436-D8DEDBAD00FD4CB1}" FilePath="*appdata\local\360*" >
		<Process Path="*360\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{4AA6A58F-9484-1075-54DAFD43618FD0C9}" FilePath="*appdata\local\microsoft\windows\inetcache\*" >
		<Process Path="*360\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{68B3C90A-D4F7-6FCD-8281ED2CE766630D}" FilePath="*appdata\local\temp\chromeshell\default\*" >
		<Process Path="*360\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{32F6C3C7-B22C-DBF3-090B5C63CCD9D96F}" FilePath="*appdata\local\microsoft\windows\inetcache\*" >
		<Process Path="*360\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{57816D19-9EA1-C597-DC2756E7DCC63F86}" FilePath="*appdata\local\temp\chromeshell\default\*" >
		<Process Path="*360\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{99CC0372-F1C9-7E32-6ED1C66498E3FBF8}" FilePath="*360\360safe*" >
		<Process Path="*appdata\local\360*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{8EC5EF5B-7DC2-1669-042500A16D5881DF}" FilePath="*appdata\local\360*" >
		<Process Path="*appdata\local\360*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{E3351635-08AF-3AB5-648D638153CE881A}" FilePath="*appdata\local\microsoft\windows\inetcache\*" >
		<Process Path="*appdata\local\360*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{78A3AABD-11A1-4CE5-A61794074813767D}" FilePath="*appdata\local\temp\chromeshell\default\*" >
		<Process Path="*appdata\local\360*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{1077B685-62D6-307D-EFE87ECFBC037230}" FilePath="*appdata\roaming\360*" >
		<Process Path="*appdata\local\360*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{1177326D-3C64-86FE-5DB7C589065DCD2B}" FilePath="*360\*" >
		<Process Path="*appdata\roaming\360*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{4D59970B-150D-47C8-8D2E4DDDFD2E293F}" FilePath="*appdata\local\microsoft\windows\inetcache\*" >
		<Process Path="*appdata\roaming\360*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{17A80F7D-1D46-FD35-6AA6D08FF4C4CAB1}" FilePath="*appdata\local\temp\chromeshell\default\*" >
		<Process Path="*appdata\roaming\360*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{BBD650A7-2DDF-8047-49F329995E1C3A8B}" FilePath="*appdata\roaming\360*" >
		<Process Path="*appdata\roaming\secoresdk\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{47A8D68F-3DC7-872E-57D68B727323BF95}" FilePath="*360\360safe*" >
		<Process Path="*appdata\roaming\secoresdk\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{A9C00D27-03A9-ABA3-1061282B1E432085}" FilePath="*appdata\local\360*" >
		<Process Path="*appdata\roaming\secoresdk\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{46BD9C4B-DC97-8F93-278B80F291E7F513}" FilePath="*appdata\local\microsoft\windows\inetcache\*" >
		<Process Path="*appdata\roaming\secoresdk\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{FE74A4CD-F2B9-9B4B-5E29D4857782D10B}" FilePath="*appdata\local\temp\chromeshell\default\*" >
		<Process Path="*appdata\roaming\secoresdk\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{0642B179-F854-F122-D931F6A00B240DFC}" FilePath="*appdata\roaming\360safe\*" >
		<Process Path="*appdata\roaming\secoresdk\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{04C8DD29-3999-5EFD-5D47F00B691DDFED}" FilePath="*sogouinput\*" >
		<Process Path="*sogouinput\*" >
			<Signature Subject="*Beijing Sogou Technology*" />
		</Process>
	</File>
	<File Id="{2A983DC0-BA7F-83CB-F769FF73BF9E50C6}" FilePath="*appdata\local\microsoft\windows\inetcache\*" >
		<Process Path="*sogouinput\*" >
			<Signature Subject="*Beijing Sogou Technology*" />
		</Process>
	</File>
	<File Id="{0061820B-BF79-FD56-EB5388B35640898C}" FilePath="*appdata\local\temp\sgpicfacetpbq\*" >
		<Process Path="*sogouinput\*" >
			<Signature Subject="*Beijing Sogou Technology*" />
		</Process>
	</File>
	<File Id="{BB050A4A-E512-38D8-6EDF17E17FAA7CB0}" FilePath="*appdata\local\temp\tfr*.tmp" >
		<Process Path="*sogouinput\*" >
			<Signature Subject="*Beijing Sogou Technology*" />
		</Process>
	</File>
	<File Id="{023CD002-E705-D128-A024E5E38E0237D0}" FilePath="*appdata\locallow\sogoupy*" >
		<Process Path="*sogouinput\*" >
			<Signature Subject="*Beijing Sogou Technology*" />
		</Process>
	</File>
	<File Id="{589EEB97-D452-05B9-992F5399781C7E2B}" FilePath="*appdata\roaming\sogouexplorer\*" >
		<Process Path="*sogouinput\*" >
			<Signature Subject="*Beijing Sogou Technology*" />
		</Process>
	</File>
	<File Id="{706B08E4-107A-1ADB-46054630637D86CF}" FilePath="*appdata\local\temp\tempfastpassport.ini" >
		<Process Path="*sogouinput\*" >
			<Signature Subject="*Beijing Sogou Technology*" />
		</Process>
	</File>
	<File Id="{6BAF734C-282A-BBFA-4DB4D81B59920E16}" FilePath="*appdata\locallow\sogoupy\env.ini" >
		<Process Path="*sogouinput\*" >
			<Signature Subject="*Beijing Sogou Technology*" />
		</Process>
	</File>
	<File Id="{7018E427-5A96-E152-0CD1795C391D7C92}" FilePath="*Hitachi\*" >
		<Process Path="*Hitachi\*" >
			<Signature Subject="*Hitachi*" />
		</Process>
	</File>
	<File Id="{814B0190-A850-D956-F6203040CEAEF754}" FilePath="*AppData\Local\Temp\~WRD*.doc*" >
		<Process Path="C:\Program Files\Microsoft Office\*\lynchtmlconv.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{FFDAE382-7A2B-C186-4A0C4B23D877A69E}" FilePath="*appdata\roaming\tencent\*" >
		<Process Path="*\tencent*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{A5069827-7E92-A2BF-B7CC42E7870A23FA}" FilePath="c:\programdata\tencent\*" >
		<Process Path="*\tencent*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{BC2A8B35-0B27-32B3-F98C74CC89C16B0A}" FilePath="c:\program files*tencent\*" >
		<Process Path="*\tencent*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{589989B5-35BD-7A5C-8CDABC6B78CB5DCF}" FilePath="*appdata\locallow\sogoupy*" >
		<Process Path="*\tencent*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{5419F2A1-1B57-2396-D648D06BA425D063}" FilePath="*appdata\roaming\tencent\*" >
		<Process Path="*tsoft\*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{F77F11DD-8F88-61D7-B2AD75C843A38597}" FilePath="c:\programdata\tencent\*" >
		<Process Path="*tsoft\*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{4E1EA4D5-2225-7758-173995DE3CA14E5A}" FilePath="c:\program files*tencent\*" >
		<Process Path="*tsoft\*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{4FBBF14C-C351-ED08-4E92F7B961DA2660}" FilePath="*appdata\locallow\sogoupy*" >
		<Process Path="*tsoft\*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{D0D65A9F-14FB-9F3D-D7FD94D2E613BE3A}" FilePath="*appdata\roaming\tencent\*" >
		<Process Path="c:\program files (x86)\wxwork*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{D25FE53C-CD0E-B600-7FB5B8399F3DFD92}" FilePath="c:\programdata\tencent\*" >
		<Process Path="*wxwork*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{646F5ED1-A1E7-79BC-CA5B7B781AD5EBD6}" FilePath="c:\program files*tencent\*" >
		<Process Path="*wxwork*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{19468AE0-425C-0FEF-00292FC954816272}" FilePath="*appdata\locallow\sogoupy*" >
		<Process Path="*wxwork*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{BFDF3AE7-70AD-6C60-45B8F1E93D59DA70}" FilePath="c:\windows\$$$qnd.tmp\*" >
		<Process Path="c:\windows\$$$qnd.tmp\*" />
	</File>
	<File Id="{81839237-AFD4-7667-0BA2AB8B0BC161C1}" FilePath="c:\program files (x86)\d.o.s\ss1agent\*" >
		<Process Path="c:\program files (x86)\d.o.s\ss1agent\*" >
			<Signature Subject="*dos co*" />
		</Process>
	</File>
	<File Id="{217AB500-42C7-15DA-7E19BA4B04C0F570}" FilePath="*appdata\roaming\f5 networks\vpn\*" >
		<Process Path="c:\program files (x86)\f5 vpn\*" >
			<Signature Subject="*f5 networks*" />
		</Process>
	</File>
	<File Id="{25C0694D-C7C8-022A-F42FBB77BA167139}" FilePath="*appdata\local\temp\f5*.tmp" >
		<Process Path="c:\program files (x86)\f5 vpn\*" >
			<Signature Subject="*f5 networks*" />
		</Process>
	</File>
	<File Id="{7F960EED-BA75-1C98-906EDDF0630FAC46}" FilePath="'c:\program files\itassetagent\*" >
		<Process Path="c:\program files\itassetagent\*" />
	</File>
	<File Id="{2D44BF40-1C71-3BAD-8BFA9CE684341DBF}" FilePath="*temp\$ma*.tmp" >
		<Process Path="c:\program files\itassetagent\*" />
	</File>
	<File Id="{6BD8B751-CF18-D836-C5204EE444D5B0C3}" FilePath="*appdata\local\temp\$ma*.tmp" >
		<Process Path="c:\program files\itassetagent\*" />
	</File>
	<File Id="{7C9F4CB5-EB5C-A832-95330E83CA767A0F}" FilePath="*temp\mc*.tmp" >
		<Process Path="c:\program files\itassetagent\*" />
	</File>
	<File Id="{D69319CA-02C5-A145-36C16F5A145D81DE}" FilePath="*landesk\shared files\*" >
		<Process Path="c:\program files (x86)\landesk\*" >
			<Signature Subject="*landesk*" />
		</Process>
	</File>
	<File Id="{391B9998-C0EA-55A2-C31A59253943B8BE}" FilePath="c:\programdata\landesk\log\*" >
		<Process Path="c:\program files (x86)\landesk\*" >
			<Signature Subject="*landesk*" />
		</Process>
	</File>
	<File Id="{736E3886-8CFF-9DF8-0938091B74F9DC46}" FilePath="c:\programdata\vulscan\trustedfilelist_*" >
		<Process Path="c:\program files (x86)\landesk\*" >
			<Signature Subject="*landesk*" />
		</Process>
	</File>
	<File Id="{84ED348A-8D01-6199-137E2A7FB2BBBC34}" FilePath="c:\program files\lide\ecops\logs\*" >
		<Process Path="c:\program files\lide\*" >
			<Signature Subject="*dalian lide*" />
		</Process>
	</File>
	<File Id="{D484572C-B70B-5B3D-05A5069A05D220AD}" FilePath="c:\programdata\lide\*" >
		<Process Path="c:\program files\lide\*" >
			<Signature Subject="*dalian lide*" />
		</Process>
	</File>
	<File Id="{D8DB5E8A-DCD7-BC54-05D5454CF7D46875}" FilePath="*appdata\locallow\lide\ecops\*" >
		<Process Path="c:\program files\lide\*" >
			<Signature Subject="*dalian lide*" />
		</Process>
	</File>
	<File Id="{FCAF997E-93FD-A5E5-30CB231707EA5F27}" FilePath="*appdata\local\microsoft\windows\inetcache\ie\pacproxyscript*" >
		<Process Path="c:\program files\lide\*" >
			<Signature Subject="*dalian lide*" />
		</Process>
	</File>
	<File Id="{9D74FAD2-1FEE-6064-E6582311DD3CF915}" FilePath="*temp\????.tmp" >
		<Process Path="c:\program files\lide\*" >
			<Signature Subject="*dalian lide*" />
		</Process>
	</File>
	<File Id="{0D5E7D04-56AA-2C31-54EC60AC42EAF76C}" FilePath="*temp\???.tmp" >
		<Process Path="c:\program files\lide\*" >
			<Signature Subject="*dalian lide*" />
		</Process>
	</File>
	<File Id="{4CBA63AD-29F5-3201-C3D254BBC463E11B}" FilePath="*temp\tem????.tmp" >
		<Process Path="c:\program files\lide\*" >
			<Signature Subject="*dalian lide*" />
		</Process>
	</File>
	<File Id="{86AFA043-269E-56FB-FA7D139E3E57493C}" FilePath="c:\program files (x86)\smart data encryption\*" >
		<Process Path="c:\program files (x86)\smart data encryption\*" >
			<VersionInfo FileDescription="*smart data encryption*" />
		</Process>
	</File>
	<File Id="{8A49BDE1-7756-EFF7-827758DDE6A72396}" FilePath="c:\program files (x86)\toshiba\smart data encryption\*" >
		<Process Path="c:\program files (x86)\smart data encryption\*" >
			<VersionInfo FileDescription="*smart data encryption*" />
		</Process>
	</File>
	<File Id="{665D85F1-10BE-1F4C-4DDC2E1861FE277A}" FilePath="c:\program files (x86)\smart data encryption\*" >
		<Process Path="c:\program files (x86)\toshiba\smart data encryption\*" >
			<VersionInfo FileDescription="*smart data encryption*" />
		</Process>
	</File>
	<File Id="{47CC564F-6856-AD1D-9CDE002ED3F9A325}" FilePath="c:\program files (x86)\toshiba\smart data encryption\*" >
		<Process Path="c:\program files (x86)\toshiba\smart data encryption\*" >
			<VersionInfo FileDescription="*smart data encryption*" />
		</Process>
	</File>
<!-- Part 0012 2022-01-11T19:13:00.000Z-1641928381 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0013 2022-03-15T19:09:00.000Z-1647371340 -->
	<File Id="{5203F565-818D-F426-2696853E2224809D}" FilePath="c:\indexes*" >
		<Process Path="*\searchinform*" >
			<Signature Subject="*Searchinform*" />
		</Process>
	</File>
	<File Id="{68563D3A-BB8D-3D43-DB11A7E66A533602}" FilePath="c:\programdata\searchinform*" >
		<Process Path="*\searchinform*" >
			<Signature Subject="*Searchinform*" />
		</Process>
	</File>
<!-- Part 0013 2022-03-15T19:09:00.000Z-1647371340 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0014 2022-03-16T13:52:00.000Z-1647438745 -->
	<File Id="{F0778F1C-9833-C204-5D07F8FFCC2C3D71}" FilePath="*appdata\local\temp\screenshot*" >
		<Process CmdLine="*surefire\surefire_*tmp" >
			<Signature Subject="*oracle*" />
		</Process>
	</File>
	<File Id="{4206A712-A6C4-06B5-01A982F49E2137E8}" FilePath="*appdata\local\temp\screenshot*" >
		<Process CmdLine="*appdata\local\temp\idea_testng.tmp" >
			<Signature Subject="*oracle*" />
		</Process>
	</File>
	<File Id="{198CDE11-0266-670F-00CDD07D0CFC2A90}" FilePath="*appdata\local\temp\screenshot*" >
		<Process CmdLine="*libs\temptest*" >
			<Signature Subject="*oracle*" />
		</Process>
	</File>
	<File Id="{620F0C5D-5911-2D0C-E919A7B7D6D90405}" FilePath="*appdata\local\temp\screenshot*" >
		<Process CmdLine="*costaisa.sira.iteracion*" >
			<Signature Subject="*oracle*" />
		</Process>
	</File>
	<File Id="{95394A53-B319-727B-75C60C64C2FEFD9A}" FilePath="*appdata\local\temp\uiautomatorviewer_*" >
		<Process CmdLine="*lib\uiautomatorviewer*" >
			<Signature Subject="*oracle*" />
		</Process>
	</File>
	<File Id="{2FC48F06-0EFC-DB32-1B7D782AAB436A71}" FilePath="*arcgis\arcgisportal*" >
		<Process CmdLine="*startup.bootstrap  start" >
			<Signature Subject="*oracle*" />
		</Process>
	</File>
<!-- Part 0014 2022-03-16T13:52:00.000Z-1647438745 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0015 2022-03-30T19:14:00.000Z-1648667664 -->
	<File Id="{48A06EB4-380F-A478-3ADC0E7A337C55BE}" FilePath="*vida..tion_*\emr\*" >
		<Process Path="*vida..tion_*" >
			<VersionInfo ProductName="*vida*" FileDescription="*vida*" />
		</Process>
	</File>
	<File Id="{FB3F0728-BBA2-B945-F298A2B08AF95332}" FilePath="*appdata\local\temp\????20??.txt" >
		<Process Path="*vida..tion_*" >
			<VersionInfo ProductName="*vida*" FileDescription="*vida*" />
		</Process>
	</File>
	<File Id="{DE68C215-8CE0-B1B9-B1C2DE8D4214CC1C}" FilePath="*appdata\local\temp\????20??.dbg" >
		<Process Path="*vida..tion_*" >
			<VersionInfo ProductName="*vida*" FileDescription="*vida*" />
		</Process>
	</File>
	<File Id="{125417C9-7FDD-0FCE-D62840786F538CE3}" FilePath="appdata\local\temp\*.rptconmgrcache" >
		<Process Path="*vida..tion_*" >
			<VersionInfo ProductName="*vida*" FileDescription="*vida*" />
		</Process>
	</File>
	<File Id="{B4C5755C-5F3E-B12D-1CEE9E9BF0E6A166}" FilePath="*appdata\local\temp\spl????.tmp" >
		<Process Path="*vida..tion_*" >
			<VersionInfo ProductName="*vida*" FileDescription="*vida*" />
		</Process>
	</File>
	<File Id="{9B15E880-F84D-9138-2B4E19EBCABA0BDE}" FilePath="*appdata\local\temp\tmp????.tmp" >
		<Process Path="*vida..tion_*" >
			<VersionInfo ProductName="*vida*" FileDescription="*vida*" />
		</Process>
	</File>
	<File Id="{C2428A0B-C5AA-966C-9EE6CFB9FC21525E}" FilePath="*appdata\local\temp\~cpe*" >
		<Process Path="*vida..tion_*" >
			<VersionInfo ProductName="*vida*" FileDescription="*vida*" />
		</Process>
	</File>
	<File Id="{A0489498-1D2E-C585-AC061D1093099871}" FilePath="*appdata\local\temp\~df*" >
		<Process Path="*vida..tion_*" >
			<VersionInfo ProductName="*vida*" FileDescription="*vida*" />
		</Process>
	</File>
	<File Id="{006EB3ED-F191-E909-F719AE55C62E017C}" FilePath="c:\windows\system32\spool\printers\?????.spl" >
		<Process Path="*vida..tion_*" >
			<VersionInfo ProductName="*vida*" FileDescription="*vida*" />
		</Process>
	</File>
	<File Id="{B9CFB79A-D7A5-5366-00B761CAC83BEB81}" FilePath="*data\wiredtiger.turtle*" >
		<Process CmdLine="c:\mongo\bin\mongod.exe  --bind_ip_all*" >
			<VersionInfo ProductName="*MongoDB*" FileDescription="*MongoDB*" />
		</Process>
	</File>
	<File Id="{E85247FC-922C-A8D9-D04C5327AE21D6EF}" FilePath="*data\diagnostic.data\metrics*" >
		<Process CmdLine="c:\mongo\bin\mongod.exe  --bind_ip_all*" >
			<VersionInfo ProductName="*MongoDB*" FileDescription="*MongoDB*" />
		</Process>
	</File>
	<File Id="{790265F0-CD28-4D50-69892E44800FE17B}" FilePath="*greenrain messenger\*.xml" >
		<Process Path="*greenrain messenger\connect.exe" >
			<VersionInfo ProductName="*Greenrain*" FileDescription="*Greenrain*" />
		</Process>
	</File>
	<File Id="{5D520B92-170F-0ED4-E020418C7AAE25B7}" FilePath="*downloads\download date*.xml" >
		<Process Path="*greenrain messenger\connect.exe" >
			<VersionInfo ProductName="*Greenrain*" FileDescription="*Greenrain*" />
		</Process>
	</File>
	<File Id="{5B631B6A-EAED-2C74-05C22365EA4B6E61}" FilePath="c:\program files\winlogbeat\data\.winlogbeat.yml*" >
		<Process Path="c:\program files\winlogbeat\winlogbeat.exe" >
			<VersionInfo ProductName="*Winlogbeat*" FileDescription="*Winlogbeat*" />
		</Process>
	</File>
	<File Id="{F6C72AA1-D090-CA3B-740C21D1C6E8FD6A}" FilePath="*appdata\local\temp\snapshot\snapshot_*" >
		<Process Path="*bin\vx_decoder.exe" >
			<VersionInfo FileDescription="*VideoXpert*" ProductName="*VxDecoder*" />
		</Process>
	</File>
	<File Id="{34503E5A-0424-7868-D6BA5E8817AA2D8F}" FilePath="*vidaptor\vidaptor-data*" >
		<Process CmdLine="*vidaptor/drules/drules*" Path="*\javaw.exe" />
	</File>
	<File Id="{161EF745-8479-A3CA-14E41CC411178B6B}" FilePath="*plugins\org.eclipse*" >
		<Process CmdLine="*vidaptor/drules/drules*" Path="*\javaw.exe" />
	</File>
	<File Id="{9B347EAB-DC2D-A95B-7D4335B43C0B80E5}" FilePath="*appdata\local\temp\~df*" >
		<Process CmdLine="*vidaptor/drules/drules*" Path="*\javaw.exe" />
	</File>
	<File Id="{DEBD58FF-EFD1-E249-20537785A9AB2EF4}" FilePath="*sedco counter employee software\*" >
		<Process Path="*sedco counter employee software\cvmemployeesoftware.exe" >
			<VersionInfo FileDescription="*CVMEmployeeSoftware*" ProductName="*CVMEmployeeSoftware*" />
		</Process>
	</File>
	<File Id="{1E480372-1B7E-4C17-16304262FAC9A13D}" FilePath="*desktop\*.url" >
		<Process CmdLine="c:\windows\system32\svchost.exe -k netsvcs*" />
	</File>
	<File Id="{E580C71E-44CB-5184-48A12D7592D2DED9}" FilePath="*favorites\*.url" >
		<Process CmdLine="c:\windows\system32\svchost.exe -k netsvcs*" />
	</File>
	<File Id="{555C3199-0C9B-776D-F0D60945C4D979AA}" FilePath="c:\windows\serviceprofiles\localservice\appdata\local\lastalive?.dat" >
		<Process CmdLine="c:\windows\system32\svchost.exe -k localservicenetworkrestricted*" />
	</File>
	<File Id="{94780981-424A-60D1-89FCAF7CF3C1D430}" FilePath="c:\programdata\microsoft\rac\*" >
		<Process CmdLine="taskhost.exe $(arg0)" Path="C:\Windows\System32\taskhost.exe" />
	</File>
	<File Id="{65FB0A41-2725-976F-3F5ECEEDC045F29C}" FilePath="c:\programdata\microsoft\rac\*" >
		<Process CmdLine="taskhost.exe " Path="C:\Windows\System32\taskhost.exe" />
	</File>
	<File Id="{737B37A8-B970-ADA4-A4B3F94BE323797F}" FilePath="c:\programdata\microsoft\rac\*" >
		<Process CmdLine="taskhost.exe timesynctask" Path="C:\Windows\System32\taskhost.exe" />
	</File>
	<File Id="{5A58D3DF-F1D8-9AAB-B3E1AEDFBE4F1001}" FilePath="c:\programdata\microsoft\rac\*" >
		<Process CmdLine="taskhost.exe tpmtasks" Path="C:\Windows\System32\taskhost.exe" />
	</File>
	<File Id="{F936A2E5-E753-4B8C-25BD696B36A25C1C}" FilePath="*appdata\roaming\kingsoft\office*.bk" >
		<Process Path="*kingsoft office\office6\et.exe" >
			<Signature Subject="*Kingsoft*" />
		</Process>
	</File>
	<File Id="{B024093E-B1AC-5A65-1D8412B677A93A40}" FilePath="*appdata\roaming\kingsoft\office*.bkl" >
		<Process Path="*kingsoft office\office6\et.exe" >
			<Signature Subject="*Kingsoft*" />
		</Process>
	</File>
	<File Id="{2CAB522B-CDFB-153F-2A454E8B822E1992}" FilePath="*appdata\local\temp\et_????.tmp" >
		<Process Path="*kingsoft office\office6\et.exe" >
			<Signature Subject="*Kingsoft*" />
		</Process>
	</File>
	<File Id="{39189C05-4605-C964-2821CA3096B6A4C2}" FilePath="*appdata\local\temp\et_???.tmp" >
		<Process Path="*kingsoft office\office6\et.exe" >
			<Signature Subject="*Kingsoft*" />
		</Process>
	</File>
	<File Id="{02E6B477-4765-3FDF-917FBCE7821E12DA}" FilePath="*appdata\local\temp\~df*" >
		<Process Path="*kingsoft office\office6\et.exe" >
			<Signature Subject="*Kingsoft*" />
		</Process>
	</File>
	<File Id="{AE308285-29B6-4B8E-88929D5753B9108C}" FilePath="*appdata\local\deployment\__su..ck_*" >
		<Process Path="c:\windows\microsoft.net\framework*\dfsvc.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{B7CA7902-FF1D-7E85-6B0D435089990651}" FilePath="*appdata\local\microsoft\windows\inetcache\counters.dat" >
		<Process Path="c:\windows\microsoft.net\framework*\dfsvc.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{D5F0D19C-FA5C-2E4B-A11F162EE8E4C7B9}" FilePath="*usagelogs\dfsvc.exe.log" >
		<Process Path="c:\windows\microsoft.net\framework*\dfsvc.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{5B5DBF87-9A88-576E-7C5C7A34E4154A5F}" FilePath="*vida...exe_*" >
		<Process Path="c:\windows\microsoft.net\framework*\dfsvc.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{FA963B1A-5B56-33C5-564ACB852D0D4C9F}" FilePath="*vida..tion_*" >
		<Process Path="c:\windows\microsoft.net\framework*\dfsvc.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{21798CB8-CD7B-2FDB-2A80C919E9C38945}" FilePath="*vida.exe_*" >
		<Process Path="c:\windows\microsoft.net\framework*\dfsvc.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{313693FB-6215-17B0-609CCE1FE090595E}" FilePath="*appdata\local\temp\deployment\????????.???\????????.*" >
		<Process Path="c:\windows\microsoft.net\framework*\dfsvc.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{022A58F0-B5B1-C7D0-EC2EEC8007F1E717}" FilePath="*appdata\local\microsoft\windows\inetcache\ie\????????\????????.log" >
		<Process Path="c:\windows\microsoft.net\framework*\dfsvc.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{00233CEF-4BC0-F9C6-1565BDF287698FC6}" FilePath="c:\programdata\microsoft\windows\sqm\sessions*}_?.psqm" >
		<Process Path="c:\windows\system32\wsqmcons.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{F18ED0B2-A3AE-2223-A260FDBD7731440B}" FilePath="c:\programdata\microsoft\windows\sqm\upload\windows_*.sqm.truncated" >
		<Process Path="c:\windows\system32\wsqmcons.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{52A0C44F-0845-14BE-B1F1ACCE07E8DDAD}" FilePath="*appdata\local\microsoft\sqm\windows*.sqm.truncated" >
		<Process Path="c:\windows\system32\wsqmcons.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{DF0AE622-FEE4-5891-8D0A5841EB0F48E4}" FilePath="c:\windows\system32\logfiles\sqm\sqmlogger_20*.etl" >
		<Process Path="c:\windows\system32\wsqmcons.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{AF83590D-FCBD-C77C-187EDB26F571F11B}" FilePath="*~rf???????.tmp" >
		<Process Path="c:\program files\libreoffice\program*" >
			<Signature Subject="*Document Foundation*" />
		</Process>
	</File>
	<File Id="{B067D0DB-2EC0-BD9B-ADF9B8B2CBD403D7}" FilePath="*appdata\local\temp\fnt????.tmp" >
		<Process Path="c:\program files\libreoffice\program*" >
			<Signature Subject="*Document Foundation*" />
		</Process>
	</File>
	<File Id="{4D668272-7ED6-5170-7096703F852E67E7}" FilePath="*appdata\local\temp\*.tmp\*.tmp" >
		<Process Path="c:\program files\libreoffice\program*" >
			<Signature Subject="*Document Foundation*" />
		</Process>
	</File>
	<File Id="{28A53D45-A5EF-A761-FEE4BA77BB9A7307}" FilePath="*appdata\roaming\libreoffice\*\user\*.tmp" >
		<Process Path="c:\program files\libreoffice\program*" >
			<Signature Subject="*Document Foundation*" />
		</Process>
	</File>
	<File Id="{7770B6D0-7744-6C7B-C6CB073468F06509}" FilePath="*appdata\roaming\libreoffice\*\user\registrymodifications.xcu" >
		<Process Path="c:\program files\libreoffice\program*" >
			<Signature Subject="*Document Foundation*" />
		</Process>
	</File>
	<File Id="{183166F4-E66B-61B0-8D6B51B3C9A90DF3}" FilePath="*appdata\local\interactive intelligence\icelib\*\temp\tmp*" >
		<Process Path="*icuserapps\interactiondesktop.exe" >
			<Signature Subject="*GENESYS*" />
		</Process>
	</File>
	<File Id="{B58F32DB-7B17-4D2C-8299C0E447068B9B}" FilePath="*appdata\local\temp\*.rptconmgrcache" >
		<Process Path="*icuserapps\interactiondesktop.exe" >
			<Signature Subject="*GENESYS*" />
		</Process>
	</File>
	<File Id="{60E6F1B9-FB86-2261-2A8D2768D54CF7E7}" FilePath="*appdata\local\temp\~cpe*" >
		<Process Path="*icuserapps\interactiondesktop.exe" >
			<Signature Subject="*GENESYS*" />
		</Process>
	</File>
	<File Id="{FAB5076E-3172-4A9F-4B224BEC8E8ADA0A}" FilePath="*appdata\local\temp\~df*" >
		<Process Path="*icuserapps\interactiondesktop.exe" >
			<Signature Subject="*GENESYS*" />
		</Process>
	</File>
	<File Id="{01002BE0-C8C0-70B6-00C8B7D9AA3217A5}" FilePath="*appdata\roaming\microsoft\windows\recent\customdestinations\*" >
		<Process Path="*icuserapps\interactiondesktop.exe" >
			<Signature Subject="*GENESYS*" />
		</Process>
	</File>
	<File Id="{66EF7BD3-E0BC-506C-B36B2B69B47CA148}" FilePath="*appdata\local\microsoft\windows\webcache\v*.chk" >
		<Process Path="C:\Windows\System32\taskhostex.exe" />
	</File>
	<File Id="{CF0F21F8-603A-570B-A9627BA36F798354}" FilePath="*appdata\local\microsoft\windows\inetcookies\*.txt" >
		<Process Path="C:\Windows\System32\taskhostex.exe" />
	</File>
	<File Id="{C66C2A4E-39FC-0F6E-DA7CFFE32910FA80}" FilePath="*appdata\local\microsoft\windows\webcache\v*.log" >
		<Process Path="C:\Windows\System32\taskhostex.exe" />
	</File>
	<File Id="{663930E8-C220-86CD-D17B15BB9679B88C}" FilePath="*portcommunicationservice\pcs.properties*" >
		<Process Path="C:\Windows\System32\spoolsv.exe" />
	</File>
	<File Id="{2501219C-C3D0-DAA6-C909F52BE8C50F94}" FilePath="c:\windows\system32\spool\printers\?????.shd" >
		<Process Path="C:\Windows\System32\spoolsv.exe" />
	</File>
	<File Id="{8045E0C8-21FA-03F8-10F386BDCE047925}" FilePath="c:\windows\system32\spool\printers\fp?????.shd" >
		<Process Path="C:\Windows\System32\spoolsv.exe" />
	</File>
	<File Id="{694F0DEE-6379-0627-0E34C857A791F470}" FilePath="c:\windows\system32\spool\printers\spl*.tmp" >
		<Process Path="C:\Windows\System32\spoolsv.exe" />
	</File>
	<File Id="{246FBC91-87E4-2242-C4C7C4B48F7D23EF}" FilePath="*appdata\local\microsoft\internet explorer\recovery\active\recoverystore.{*}.dat" >
		<Process Path="*Internet Explorer\iexplore.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{DCFFA0F1-BB74-84A3-13D0F01D05B4F2DE}" FilePath="*appdata\local\microsoft\internet explorer\recovery\last active\recoverystore.{*}.dat" >
		<Process Path="*Internet Explorer\iexplore.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E8736032-D080-0F5E-53CE15DCA370D1F6}" FilePath="*appdata\local\microsoft\internet explorer\recovery\last active\{*}.dat" >
		<Process Path="*Internet Explorer\iexplore.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{BC98845F-874D-7ACE-75487F318DB4D38B}" FilePath="*appdata\roaming\microsoft\windows\recent\customdestinations\*.customdestinations-ms" >
		<Process Path="*Internet Explorer\iexplore.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{DC7A6C45-5762-75AC-E1DAA32FB74B1A66}" FilePath="c:\program files (x86)\sapphireimsagent*" >
		<Process Path="*sapphireimsagent\sapphireimsagent.exe" >
			<Signature Subject="*Tecknodreams*" />
		</Process>
	</File>
	<File Id="{E015FDCF-8722-9CC4-D6DE0D7FF05E2F0B}" FilePath="c:\programdata\oracle\java\.oracle_jre_usage\*.timestamp" >
		<Process CmdLine="jps -m" >
			<Signature Subject="*Oracle*" />
		</Process>
	</File>
	<File Id="{66C2F742-273E-AF64-1B3EB2D30D6BE783}" FilePath="*appdata\local\temp\*\hsperfdata_*" >
		<Process CmdLine="jps -m" >
			<Signature Subject="*Oracle*" />
		</Process>
	</File>
	<File Id="{478DD268-32D8-57EF-80176DAFB1561C87}" FilePath="*appdata\local\microsoft\outlook\~*.ost.tmp" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{AE936424-5E23-CCBF-9F2CD9FA9F79D1F1}" FilePath="*appdata\local\microsoft\office\oteledata_3*.etl" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E7B60948-77CC-D381-FD194F4993100E3C}" FilePath="*appdata\local\microsoft\outlook\*.ost" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{43CBA615-C8E7-6C46-F32A0A5E858D1CF1}" FilePath="*appdata\local\microsoft\windows\inetcache\content.mso\*.dat" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{7E50DB51-5009-4A41-37DBC6C051D083F0}" FilePath="*appdata\local\microsoft\windows\temporary internet files\content.mso\*.dat" >
		<Process Path="*office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{C6420072-AC11-7E3F-A589975D3E615076}" FilePath="*centricity\ris-i\temp\~wr?????.tmp" >
		<Process Path="*office*\winword.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E85CAC97-EF13-B915-DA26A4E613358A0E}" FilePath="*appdata\roaming\microsoft\word\~wr?????.wbk" >
		<Process Path="*office*\winword.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{EE127ED4-370D-D00F-654719A4F4155C94}" FilePath="*appdata\roaming\microsoft\word\~wr?????.tmp" >
		<Process Path="*office*\winword.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{A8F517A8-6B1B-8587-F2CB95141CDBC606}" FilePath="*documents\~wr?????.tmp" >
		<Process Path="*office*\winword.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{CB73BD5C-C201-9774-0365B19995332FEA}" FilePath="*appdata\local\temp\~df*.tmp" >
		<Process Path="*kingsoft*\wps.exe" >
			<Signature Subject="*Kingsoft*" />
		</Process>
	</File>
	<File Id="{1193DF3B-030A-9B11-8F35EE673278342C}" FilePath="*appdata\local\temp\~tmp*.tmp" >
		<Process Path="*kingsoft*\wps.exe" >
			<Signature Subject="*Kingsoft*" />
		</Process>
	</File>
	<File Id="{AF770BA2-1A77-64F3-F3474A84CEB9E17C}" FilePath="*appdata\roaming\kingsoft\office*\backup\wps.bkl" >
		<Process Path="*kingsoft*\wps.exe" >
			<Signature Subject="*Kingsoft*" />
		</Process>
	</File>
	<File Id="{29C89854-4424-6958-FE2EEE461D07FDC1}" FilePath="*appdata\roaming\kingsoft\office*\backup\wps_*.bk" >
		<Process Path="*kingsoft*\wps.exe" >
			<Signature Subject="*Kingsoft*" />
		</Process>
	</File>
	<File Id="{5CC547D4-5984-5409-4F469CCB403BBCD0}" FilePath="*desktop\~tmp*.tmp" >
		<Process Path="*kingsoft*\wps.exe" >
			<Signature Subject="*Kingsoft*" />
		</Process>
	</File>
	<File Id="{9DC58B30-8B2D-E4E7-3251C70DF7288D9D}" FilePath="*dist\log\*.txt" >
		<Process CmdLine="*vidapter.run.driverlauncher*" Path="*bin\java.exe" />
	</File>
	<File Id="{5D484F45-62CA-24AA-C49D57EA9C950EB8}" FilePath="*appdata\local\jetbrains\ideaic20*" >
		<Process CmdLine="*vidapter.run.driverlauncher*" Path="*bin\java.exe" />
	</File>
	<File Id="{CF566589-8BAF-3C27-4BBC372BBEA07FF7}" FilePath="*appdata\local\temp\*\hsperfdata_*" >
		<Process CmdLine="*vidapter.run.driverlauncher*" Path="*bin\java.exe" />
	</File>
	<File Id="{A37A1ED2-B735-A209-D8330593B3CC9169}" FilePath="c:\programdata\microsoft\search\data\applications\windows\edb.chk" >
		<Process Path="c:\windows\system32\searchindexer.exe" />
	</File>
	<File Id="{FEB680C0-6A73-337E-FA5397A1B08E83B2}" FilePath="c:\programdata\microsoft\search\data\applications\windows\edb*.log" >
		<Process Path="c:\windows\system32\searchindexer.exe" />
	</File>
	<File Id="{711D7673-D542-61A9-1B4261CF66015B47}" FilePath="*appdata\local\temp\spt????.tmp" >
		<Process Path="c:\windows\system32\printfilterpipelinesvc.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{5B3253BB-F734-D662-41E92F4B5718B271}" FilePath="c:\windows\serviceprofiles\localservice\appdata\local\temp\fm*.tmp" >
		<Process Path="c:\windows\system32\printfilterpipelinesvc.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{77D708BF-746F-8072-39853AE9E8C4AFA0}" FilePath="c:\windows\serviceprofiles\localservice\appdata\local\temp\mi*.tmp" >
		<Process Path="c:\windows\system32\printfilterpipelinesvc.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{7BF3821B-3F6A-F31F-DFB3B61763ED55BF}" FilePath="c:\windows\system32\spool\printers\pp*.tmp" >
		<Process Path="c:\windows\system32\printfilterpipelinesvc.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{63CDCF31-8741-2307-B92EED9B5E2E0DA1}" FilePath="*appdata\local\mozilla\firefox\profiles\????????.default\cache\*" >
		<Process Path="*mozilla*\firefox.exe" >
			<Signature Subject="*Mozilla*" />
		</Process>
	</File>
	<File Id="{1FCA36DD-33ED-0E97-7D1A26DED01DFDD3}" FilePath="*default\prefs.js" >
		<Process Path="*mozilla*\firefox.exe" >
			<Signature Subject="*Mozilla*" />
		</Process>
	</File>
	<File Id="{E3E505B1-B6D9-4CE1-A606B3AAACF65E3E}" FilePath="*default\sessionstore.js" >
		<Process Path="*mozilla*\firefox.exe" >
			<Signature Subject="*Mozilla*" />
		</Process>
	</File>
	<File Id="{49384168-004A-BED8-45D6CEAE05873EF4}" FilePath="*default\addons.json" >
		<Process Path="*mozilla*\firefox.exe" >
			<Signature Subject="*Mozilla*" />
		</Process>
	</File>
	<File Id="{E71779ED-4BDA-67AF-42FCB199E64B5A7E}" FilePath="*default\sessionstore.js.tmp" >
		<Process Path="*mozilla*\firefox.exe" >
			<Signature Subject="*Mozilla*" />
		</Process>
	</File>
<!-- Part 0015 2022-03-30T19:14:00.000Z-1648667664 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0016 2022-04-08T14:08:00.000Z-1649426903 -->
	<File Id="{AE464A1B-BF16-4772-18CF0AF42D6B560B}" FilePath="*sub\keylogger*" >
		<Process Path="c:\program files\kazdream cyberguard*" >
			<Signature Subject="*Texode*" />
		</Process>
	</File>
<!-- Part 0016 2022-04-08T14:08:00.000Z-1649426903 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0017 2022-06-10T15:48:00.000Z-1654876096 -->
	<File Id="{0E26F0F6-7650-2CB6-1B522AD1FC199CF5}">
		<Process CmdLine="c:\windows\sysnative\windowspowershell\v1.0\powershell.exe -noprofile -noninteractive try {&#10;    [console]::inputencoding = [console]::outputencoding = [text.utf8encoding]::utf8&#10;&#9;*rez&#10;&#10;}&#10;checkpasswordlen -len 8&#10;&#9;} catch [system.exception] {}" />
	</File>
	<File Id="{98F757EB-C528-9BEB-C13E0D2B6D643D62}">
		<Process CmdLine="C:\WINDOWS\SYSTEM32\cmd.exe /c C:\WINDOWS\LtcJobs\Task\runonce-MainScript.BAT*" />
	</File>
	<File Id="{59056759-932B-8379-541BD8D5C6E4538C}">
		<Process CmdLine="c:\windows\ltcjobs\task\runonce-mainscript.bat\..\*" />
	</File>
	<File Id="{6A6EAA1B-4A03-8DFF-05DB5E657A63B96A}">
		<Process CmdLine="c:\program files (x86)\initplusmonitor\initplusmonitor\isolatedvivotekplayerserverapp.exe /command-pipe-name vivotekplayercommandpipe*" />
	</File>
	<File Id="{4AB528B6-542C-C42F-EE44675A12E74051}">
		<Process CmdLine="C:\Program Files (x86)\Zecurion\Endpoint\ffcertutils\certutil.exe  -A -n Zecurion Zgate Web*" />
	</File>
	<File Id="{75E30D18-A705-DF2A-7785F9527A0F1F5A}">
		<Process CmdLine="c:\th\td15\rc\exe\curl.exe  -0 --trace-ascii test.txt -x post -h*" />
	</File>
	<File Id="{3CB874CA-D875-90CA-CDEFAD09FCEBB820}">
		<Process CmdLine="c:\windows\ccm\updatetrustedsites.exe false  s-1-5-21-*" />
	</File>
	<File Id="{9DFCEC97-13B3-CF7C-AC818B337B2E96D5}">
		<Process CmdLine="c:\windows\microsoft.net\framework*\csc.exe /noconfig /fullpaths @c:\windows\temp*" />
	</File>
	<File Id="{C8641409-5417-2EEC-BA464AF8439396D0}">
		<Process CmdLine="c:\windows\microsoft.net\framework*\ngen.exe uninstall c:\windows\assembly\nativeimages_v*" />
	</File>
	<File Id="{92386CEC-44AE-9481-84243DA310C709FC}">
		<Process CmdLine="c:\windows\system32\wudfhost.exe -hostguid:{*" />
	</File>
	<File Id="{404B46A3-23B5-BBF7-CB7A78ED59EA12AD}">
		<Process CmdLine="logonui.exe /flags:0x0 /state0:0x???????? /state1:0x????????" />
	</File>
	<File Id="{1B10A82C-52E6-5CED-2EC038DFE0C3B389}">
		<Process CmdLine="c:\cntc\stc.exe  - - 0 - c:\atd\atd\ast*" />
	</File>
<!-- Part 0017 2022-06-10T15:48:00.000Z-1654876096 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0018 2022-08-16T13:49:00.000Z-1660657772 -->
	<File Id="{4874E241-5F81-4F82-6C0A1F789221A002}">
		<Process CmdLine="*hklm:\software\microsoft\windows\currentversion\capabilityaccessmanager\consentstore\location*geowatcher.position.location&#10;&#9;&#9;}&#10;&#9;&#10;&#9;} catch [system.exception] {}&#34;" />
	</File>
	<File Id="{61BA5C13-EE11-D20C-645B13DB2D861958}">
		<Process CmdLine="*hklm:\software\microsoft\windows\currentversion\capabilityaccessmanager\consentstore\location*geowatcher.position.location&#10;&#9;&#9;}&#10;&#9;&#10;&#9;} catch [system.exception] {}" />
	</File>
<!-- Part 0018 2022-08-16T13:49:00.000Z-1660657772 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0019 2022-08-26T12:54:00.000Z-1661518476 -->
	<File Id="{59EAD741-F712-7E9C-09A0631770F91FE8}">
		<Process CmdLine="c:/windows/system32/windowspowershell/v1.0/powershell.exe  get-wmiobject -class win32_*" >
			<Hash MD5="7353f60b1739074eb17c5f4dddefe239" />
		</Process>
	</File>
	<File Id="{69EAD741-F712-7E9C-09A0631770F91FE7}">
		<Process CmdLine="c:/windows/system32/windowspowershell/v1.0/powershell.exe  [system.net.dns]::gethostname()" >
			<Hash MD5="7353f60b1739074eb17c5f4dddefe239" />
		</Process>
	</File>
	<File Id="{11ED458D-776D-DF0F-D573AFD35B5AA6D0}">
		<Process CmdLine="powershell (get-counter -counter \\hyper-v dynamic memory vm(dockerdesktopvm)\average pressure\, \\hyper-v dynamic memory vm(dockerdesktopvm)\physical memory\, \\hyper-v hypervisor virtual processor(dockerdesktopvm:*)\% guest run time\).countersamples.cookedvalue" />
	</File>
<!-- Part 0019 2022-08-26T12:54:00.000Z-1661518476 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0020 2022-09-21T19:14:00.000Z-1663787673 -->
	<File Id="{8F5EF2CE-507E-6487-A2EDF02CC39A5296}" FilePath="C:\Windows\CCM\*">
		<Process CmdLine="c:\windows\system32\wbem\wmiprvse.exe -embedding" />
	</File>
	<File Id="{CD678B6F-F3FB-6C0F-F4C67C6F273960D1}" FilePath="*temp\????????-????-*.mof">
		<Process CmdLine="c:\windows\system32\wbem\wmiprvse.exe -embedding" />
	</File>
	<File Id="{A89D29E2-8FA3-3FD3-82111431F35CB941}" FilePath="*\discoverytree.xml">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{E5E56D2D-DD8F-D7A0-E7EAF8FBFA9591DE}" FilePath="*\scannercapabilities">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{9A3CA0A7-5D76-0C25-4E18C580E901E588}" FilePath="c:\programdata\microsoft\diagnosis\*">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{77FCC805-39FF-9713-1412228B891B779A}" FilePath="c:\programdata\microsoft\network\downloader\edb*">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{DA65AB6D-8E19-EFC9-15B517B334BA3046}" FilePath="c:\programdata\microsoft\network\downloader\qmgr.jfm">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{A8935002-507F-9769-B812B1A6C6B75A81}" FilePath="c:\programdata\microsoft\windows\wer\temp\wer*">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{16FDBA0E-7BF9-524B-CAF4627200AD0EB2}" FilePath="c:\programdata\ntuser.pol">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{8D24FECA-A142-D464-61BA73595DD17D23}" FilePath="c:\programdata\tempntuser.pol">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{51B8C700-10A4-CCFF-85E2D7664C9B2BD9}" FilePath="c:\windows\ccm*">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{E706D851-C9E0-BF4F-89533A20D8225587}" FilePath="c:\windows\serviceprofiles\localservice\appdata\local\temp\*.tmp">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{3EA093EE-7084-13A2-12354008F1CA8B89}" FilePath="c:\windows\system32\logfiles\sum\*">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{32A7E7D9-ED11-8836-7DD9F9388539D0BC}" FilePath="*temp\his*.tmp">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{D1EAD74A-6477-AE29-44888368EC2A2FA2}" FilePath="*temp\msi*.log">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{C4967775-6808-D618-F8FB30CC2A27DE5C}" FilePath="*temp\udd*.tmp">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{DE619676-C3F9-EEF0-D9098C82F34AC499}" FilePath="C:\ProgramData\Microsoft\SmsRouter\MessageStore\*">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{0DE5A30E-3D62-708D-DF66F7CC5563E198}" FilePath="C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\*">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{D70652A2-2D63-D893-EE47DA3CBE7C675A}" FilePath="C:\Windows\Prefetch\Layout.ini">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{D44C33FF-0F18-1DA8-AD86CE1FEC88EFB5}" FilePath="C:\Windows\Prefetch\*History.db">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{0B489314-159D-8DF3-6678AE8B336225C0}" FilePath="C:\Windows\INF\setupapi.dev.log">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</File>
	<File Id="{C43F95A2-4B86-5FC5-677ABDE51FBA218D}" FilePath="*appdata\local\temp\*.bmp">
		<Process Path="*Plustek\*OpticSlim*\docuaction.exe" />
	</File>
	<File Id="{1097A991-BEEA-6712-F14584A7C61ED976}" FilePath="*appdata\local\temp\tem*">
		<Process Path="*Plustek\*OpticSlim*\docuaction.exe" />
	</File>
	<File Id="{80C7B02E-065C-9834-B248A1EE5CCDE276}" FilePath="*public\documents\scandoc*">
		<Process Path="*Plustek\*OpticSlim*\docuaction.exe" />
	</File>
	<File Id="{DDC98954-D741-792C-32FFB39179B7CA0B}" FilePath="*NEXThink*">
		<Process Path="*Nexthink*">
			<Signature Subject="*NEXThink*" />
		</Process>
	</File>
<!-- Part 0020 2022-09-21T19:14:00.000Z-1663787673 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0021 2022-09-27T13:31:00.000Z-1664285483 -->
	<File Id="{BF093F0A-003E-BDC4-31FA8C1E514689C1}" FilePath="c:\programdata\microsoft\windows\systemdata\s-1-*\lockscreen*">
		<Process Path="C:\Windows\System32\LogonUI.exe" CmdLine="LogonUI.exe *" />
	</File>
	<File Id="{40701C58-46A7-1D53-205D1D3F47E777FC}" FilePath="&#39;c:\programdata\microsoft\windows\systemdata\s-1-*\lockscreen*">
		<Process Path="C:\Windows\System32\LogonUI.exe" CmdLine="LogonUI.exe *" />
	</File>
	<File Id="{17D69C49-B65D-364E-B7A679AB496E78E8}" FilePath="*temp\etoken.cache\*.cache">
		<Process Path="C:\Windows\System32\LogonUI.exe" CmdLine="LogonUI.exe *" />
	</File>
	<File Id="{4634915A-B4AA-8779-00BF80D98FA0C813}" FilePath="*temp\etoken.hid\sharedinfo.bin">
		<Process Path="C:\Windows\System32\LogonUI.exe" CmdLine="LogonUI.exe *" />
	</File>
	<File Id="{15160BA0-ACF6-748F-26BE565DFEB3F122}" FilePath="*temp\etoken.log\*\logonui_*">
		<Process Path="C:\Windows\System32\LogonUI.exe" CmdLine="LogonUI.exe *" />
	</File>
	<File Id="{AC7AB53C-015F-A2A5-0585C10747EC8007}" FilePath="c:\programdata\pulse secure\logging\debuglog.log">
		<Process>
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{5FA1E608-7242-3452-7D5F190F6B71D5F8}" FilePath="c:\windows\ccm\logs\_scnotify_*">
		<Process Path="c:\windows\ccm\scnotification.exe" />
	</File>
	<File Id="{0D472D1F-F1C2-16E2-67658EF78BB83A24}" FilePath="c:\windows\ccm\logs\scnotify_*">
		<Process Path="c:\windows\ccm\scnotification.exe" />
	</File>
<!-- Part 0021 2022-09-27T13:31:00.000Z-1664285483 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0021.1 2024-08-20T17:29:00.000Z-1724174976 -->
	<File Id="{EC7808DF-E906-C5FB-925C7A17E86644EE}" FilePath="*\kasperskylab\adminkit\ss*.lck" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{569F9B50-4C74-B84E-5FE2BE5A8F7B89B9}" FilePath="*\kasperskylab\adminkit\ss*dat" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{D6CE122C-5DDB-BEA4-BFF5AE876319B826}" FilePath="*\kasperskylab\adminkit\~*.lck" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{C0A0148F-5317-77F6-BB71D550737E1F43}" FilePath="*\kasperskylab\adminkit\~*dat" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{5123FD7A-7F53-CDAE-7AB3F5774FF9E3A8}" FilePath="*appdata\local\temp\klsc-*.lck" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{F7C71A35-8DB3-C6DC-D26F97F198830D6C}" FilePath="*\monorepo\.gvfs\databases\modifiedpaths.dat*" >
		<Process Path="*\gvfs\gvfs.mount.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{37A7D171-844B-9685-98AF99316442C2BE}" FilePath="?:\programdata\kasperskylab\adminkit\~*" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{8061CE07-CF99-8AF9-0D1C0607A44CFD16}" FilePath="?:\.gvfscache\????????????????????????????????\*" >
		<Process Path="*\gvfs\gvfs.mount.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{13B00428-6437-85FB-BEEBED15EE6EF579}" FilePath="*\monorepo\.gvfs\gitstatuscache\gitstatuscache.dat" >
		<Process Path="*\gvfs\gvfs.mount.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{22957A3D-FDCE-E33E-B5D20B10405B3D4C}" FilePath="*\serviceprofiles\ksnproxy\appdata\local\temp\klsc-*.lck" >
		<Process Path="*\kaspersky lab\networkagent\ksnproxy.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{CB716754-6EC3-8284-B305B9696E6233A8}" FilePath="?:\windows\temp\klsc-*\crlstore.lck" >
		<Process Path="*\kaspersky lab\networkagent\up2date.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{E9FF7DD0-02CE-8CFA-F27A11A3427C2AAE}" FilePath="*kasperskylab\adminkit\1103\.vapm\localdata\data\*.lck" >
		<Process Path="*\Kaspersky Lab\NetworkAgent\vapm.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{D4608D7B-26FA-7F4B-E9DDC44575AFA60A}" FilePath="*kasperskylab\adminkit\1103\.vapm\pccache\*.lock" >
		<Process Path="*\Kaspersky Lab\NetworkAgent\vapm.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{21217D20-35C6-874E-87CA9643E1603239}" FilePath="*kasperskylab\adminkit\data\.temp\????????-????-????-????-????????????" >
		<Process Path="*\Kaspersky Lab\NetworkAgent\vapm.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{D646BD2D-BF3D-193B-2C59092467321658}" FilePath="*kasperskylab\adminkit\bases\*.removeonnextreboot" >
		<Process >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{D5A51E07-75CF-BFEA-63BB8A9802E73865}" >
		<Process Path="*klnagent.exe" >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{77A6A7DB-3BC3-C911-C8B4D0ED2FF2097B}" FilePath="c:\programdata\kasperskylab\*" >
		<Process >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{9008B96A-4812-4A2A-492C5BA8A1B6E56C}" FilePath="c:\programdata\kaspersky lab\*" >
		<Process >
			<Signature Subject="too midori trading" />
		</Process>
	</File>
	<File Id="{8FDBC15E-3BC0-8F3B-CEC884BEEBA6E04C}" FilePath="*AppData\Local\Temp\ml_dotnet*">
		<Process>
			<Signature Subject="too midori trading" />
		</Process>
	</File>
<!-- Part 0021.1 2024-08-20T17:29:00.000Z-1724174976 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0022 2022-10-06T17:26:00.000Z-1665077162 -->
	<File Id="{F9EE5D86-937F-36AB-0599CBF1611F50F4}" FilePath="c:\empower\instruments\html\acq-sm*">
		<Process CmdLine="C:\Empower\Instruments\Bin\AcquitySMServer.exe -Embedding">
			<VersionInfo OrignFileName="AcquitySMServer.exe" ProductName="Sample Manager" FileDescription="Sample Manager Server" />
		</Process>
	</File>
	<File Id="{BAB318B1-F4D1-CB5B-BDD66A74E947E53F}" FilePath="*modem\config.ini">
		<Process>
			<Signature Subject="ZTE CORPORATION" />
		</Process>
	</File>
	<File Id="{68E64360-9F37-64D0-0F51155AA5D2D55A}" FilePath="*appdata\local\temp\acrocef_low\*.tmp">
		<Process Path="*adobe\acrobat reader*">
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{AF3A922F-FEB2-62E6-CA7EAE561F2A1448}" FilePath="*appdata\locallow\adobe\acrocef\dc\acrobat\cache\code cache\js\????????????????_?">
		<Process Path="*adobe\acrobat reader*">
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{6C583D8A-517D-8E72-416CEF32C8E606BE}" FilePath="*appdata\local\temp\acrord32_sbx\*.tmp">
		<Process Path="*adobe\acrobat reader*">
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{85B9D40F-48CC-791F-B247DC2BE371A1DD}" FilePath="*appdata\local\temp\*.tmp">
		<Process Path="*adobe\acrobat reader*">
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{25A10C19-43F6-6DBB-ECB9863F5CDBC863}" FilePath="*temp\enumwin.tmp">
		<Process CmdLine="c:\program files (x86)\automatos\desktop agent\enumwindows.exe c:\windows\temp\\enumwin.tmp">
			<VersionInfo ProductName="%kl_undef%" FileDescription="%kl_undef%" />
		</Process>
	</File>
	<File Id="{1C47ED88-735D-7C91-49B5A2718CB75E49}" FilePath="*appdata\local\cisco\cisco anyconnect secure mobility client\aciseposture.log">
		<Process Path="*cisco\cisco*">
			<Signature Subject="*cisco*" />
		</Process>
	</File>
	<File Id="{F5DA530B-B88A-E569-B0308BB882A72C52}" FilePath="*appdata\local\temp\waapi-??????????\????????????????????????">
		<Process Path="*cisco\cisco*">
			<Signature Subject="*cisco*" />
		</Process>
	</File>
	<File Id="{EE89050B-49DC-2BD0-3F04D4670AAE374A}" FilePath="c:\programdata\cisco\cisco anyconnect secure mobility client\nvm\nvm.db-journal">
		<Process Path="*cisco\cisco*">
			<Signature Subject="*cisco*" />
		</Process>
	</File>
	<File Id="{695C8BBA-3280-26A4-4D479BEE0E263301}" FilePath="*appdata\local\citrix\selfservice*">
		<Process Path="*citrix\ica client*">
			<Signature Subject="*Citrix*" />
		</Process>
	</File>
	<File Id="{83968C6D-79CB-2285-03A222EFC2F348F5}" FilePath="c:\programdata\boost_interprocess\1664942621\mutex_cwa_config*">
		<Process Path="*citrix\ica client*">
			<Signature Subject="*Citrix*" />
		</Process>
	</File>
	<File Id="{E42264BE-2EAD-C5EA-ED2D4CB0CCEA7C96}" FilePath="c:\programdata\citrix\receiver\storage\cwa_config*">
		<Process Path="*citrix\ica client*">
			<Signature Subject="*Citrix*" />
		</Process>
	</File>
	<File Id="{5846558F-D586-07D1-AA1C02604223CF31}" FilePath="*appdata\local\citrix\receiver\microsoft.*manifest">
		<Process Path="*citrix\ica client*">
			<Signature Subject="*Citrix*" />
		</Process>
	</File>
	<File Id="{3FF2BEB5-715B-5B93-856E7DAF58198ADA}" FilePath="*appdata\local\citrix\receiver\msvcr*">
		<Process Path="*citrix\ica client*">
			<Signature Subject="*Citrix*" />
		</Process>
	</File>
	<File Id="{5168E2BF-85EF-1671-D8C6BF7E49BCE998}" FilePath="*appdata\local\citrix\selfservice\bn-*_cache.xml">
		<Process Path="*citrix\ica client*">
			<Signature Subject="*Citrix*" />
		</Process>
	</File>
	<File Id="{1DC39D2D-9D85-23DC-484AF511E0DB7E30}" FilePath="appdata\local\citrix\selfservice\citrixwebcontrolcache\code cache\js\????????????????_?">
		<Process Path="*citrix\ica client*">
			<Signature Subject="*Citrix*" />
		</Process>
	</File>
	<File Id="{8E3FF9E6-7C66-ECFF-64C511279DCAB3ED}" FilePath="*appdata\local\microsoft\*\usagelogs\selfservice.exe.log">
		<Process Path="*citrix\ica client*">
			<Signature Subject="*Citrix*" />
		</Process>
	</File>
	<File Id="{C310C479-5849-C37D-AF99A17E82DDA617}" FilePath="appdata\local\temp\ctxreceiverlogs\*selfservice.exe-*.etl">
		<Process Path="*citrix\ica client*">
			<Signature Subject="*Citrix*" />
		</Process>
	</File>
	<File Id="{B6F068FE-5F1D-D7C5-24228DB5306C7CB5}" FilePath="*temp\armreport.ini">
		<Process Path="*Adobe\ARM*">
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{BD55595B-AF18-C558-FA897F5443333601}" FilePath="*appdata\local\temp\adobearm_notlocked.log">
		<Process Path="*Adobe\ARM*">
			<Signature Subject="*Adobe*" />
		</Process>
	</File>
	<File Id="{CD52933D-5231-62EE-6B7FCCA9A21B8DAE}" FilePath="*appdata\local\temp\a9r????-????????">
		<Process CmdLine="C:\Program Files (x86)\Common Files\Objectif Lune\PlanetPress Suite*\PSRip\ppalmbic.exe -server -*">
			<VersionInfo OrignFileName="AcquitySMServer.exe" ProductName="PlanetPress Suite*" FileDescription="PlanetPress Alambic" />
		</Process>
	</File>
	<File Id="{FEE55F5A-613D-A94F-46D05E172FF4A51D}" FilePath="*appdata\local\temp\tmp?????-?\?????????.???.???.???">
		<Process CmdLine="C:\Program Files (x86)\Common Files\Objectif Lune\PlanetPress Suite*\PSRip\ppalmbic.exe -server -*">
			<VersionInfo OrignFileName="AcquitySMServer.exe" ProductName="PlanetPress Suite*" FileDescription="PlanetPress Alambic" />
		</Process>
	</File>
	<File Id="{F4BDDED6-04ED-09C2-D10602B57D7C7CC5}" FilePath="*appdata\local\temp\tmp?????-?\tmp????.tmp">
		<Process CmdLine="C:\Program Files (x86)\Common Files\Objectif Lune\PlanetPress Suite*\PSRip\ppalmbic.exe -server -*">
			<VersionInfo OrignFileName="AcquitySMServer.exe" ProductName="PlanetPress Suite*" FileDescription="PlanetPress Alambic" />
		</Process>
	</File>
	<File Id="{36D9756D-C6C8-AE40-4BAC7D0BB2648DAF}" FilePath="*appdata\local\temp\tmp????-?\????????">
		<Process CmdLine="C:\Program Files (x86)\Common Files\Objectif Lune\PlanetPress Suite*\PSRip\ppalmbic.exe -server -*">
			<VersionInfo OrignFileName="AcquitySMServer.exe" ProductName="PlanetPress Suite*" FileDescription="PlanetPress Alambic" />
		</Process>
	</File>
	<File Id="{0E7619C3-4C45-377E-4D1123C75666EA6A}" FilePath="*appdata\local\temp\???????.tmp.pre\prev_??.jpg">
		<Process Path="*files\scan*">
			<Signature Subject="*Samsung*" />
		</Process>
	</File>
	<File Id="{3C7FEA85-EE3C-2FD1-FAA440142547963B}" FilePath="*appdata\local\temp\sie_file_*\preview.jpg">
		<Process Path="*files\scan*">
			<Signature Subject="*Samsung*" />
		</Process>
	</File>
	<File Id="{C81F7761-2A9A-55B6-9F833C3244F0F7D9}" FilePath="*appdata\local\temp\siet_*_*">
		<Process Path="*files\scan*">
			<Signature Subject="*Samsung*" />
		</Process>
	</File>
	<File Id="{7972E426-E689-086E-66F5D909D81FC58F}" FilePath="c:\program files (x86)\common files\securit\*.ttf">
		<Process Path="*files\securit*">
			<Signature Subject="*Zecurion*" />
		</Process>
	</File>
	<File Id="{80F9DFF6-1EC9-6666-E0B06B48AE69BE11}" FilePath="c:\program files (x86)\common files\securit\configurations\{*}\config.data">
		<Process Path="*files\securit*">
			<Signature Subject="*Zecurion*" />
		</Process>
	</File>
	<File Id="{09C12230-8567-BAED-89151C20AF4D6177}" FilePath="c:\program files (x86)\common files\securit\configurations\{*}\config.info">
		<Process Path="*files\securit*">
			<Signature Subject="*Zecurion*" />
		</Process>
	</File>
	<File Id="{9E51639F-173A-78D0-FAEE61906730C82F}" FilePath="c:\program files (x86)\zecurion\endpoint\temp\in\{*">
		<Process Path="*files\securit*">
			<Signature Subject="*Zecurion*" />
		</Process>
	</File>
	<File Id="{E74D2D37-3792-D064-034180A2FE3E3703}" FilePath="c:\program files (x86)\zecurion\endpoint\temp\mirrortemp\{*">
		<Process Path="*files\securit*">
			<Signature Subject="*Zecurion*" />
		</Process>
	</File>
	<File Id="{EA07317E-5CCB-AE4B-A873952B72E83178}" FilePath="c:\program files (x86)\zecurion\endpoint\temp\s-1-*">
		<Process Path="*files\securit*">
			<Signature Subject="*Zecurion*" />
		</Process>
	</File>
	<File Id="{AF47FF00-6D8A-D55F-20112E9E7ACB3009}" FilePath="c:\program files (x86)\zecurion\endpoint\temp\work\{*">
		<Process Path="*files\securit*">
			<Signature Subject="*Zecurion*" />
		</Process>
	</File>
	<File Id="{3D37CCAD-868F-69B8-2F206815A25595A9}" FilePath="c:\windows\system32\shadowcopy\{*">
		<Process Path="*files\securit*">
			<Signature Subject="*Zecurion*" />
		</Process>
	</File>
	<File Id="{44A5F6BA-AC44-875D-CA5671581884EF96}" FilePath="*appdata\local\hp\hp*">
		<Process Path="*hp\hp*">
			<Signature Subject="*HP Inc*" />
		</Process>
	</File>
	<File Id="{02786C9A-88EC-63E5-5F239074B30FD8C9}" FilePath="*appdata\local\temp\hpscan*">
		<Process Path="*hp\hp*">
			<Signature Subject="*HP Inc*" />
		</Process>
	</File>
	<File Id="{B8CDC83E-2C73-4BEA-AC8C1D50413D73B5}" FilePath="c:\windows\debug\wia\wiatrace.log">
		<Process Path="*hp\hp*">
			<Signature Subject="*HP Inc*" />
		</Process>
	</File>
	<File Id="{95E7C5F6-B27E-7A1A-B7685988A526B696}" FilePath="*appdata\local\adobe\acrobat\dc\adobesysfnt*.lst">
		<Process CmdLine="*internet explorer\iexplore.exe scodef:*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{D4D8104E-ECD8-6B3E-973FF1053A0BF435}" FilePath="*appdata\local\amd\dxcache\*.bin">
		<Process CmdLine="*internet explorer\iexplore.exe scodef:*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{631CA343-4BA0-6E42-399162E0BEA923B7}" FilePath="*microsoft\internet explorer\domstore\*.xml">
		<Process CmdLine="*internet explorer\iexplore.exe scodef:*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{31069442-8DEC-26D6-8B99F2AACADA829E}" FilePath="*appdata\local\microsoft\internet explorer\imagestore\*\imagestore.dat">
		<Process CmdLine="*internet explorer\iexplore.exe scodef:*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E8620421-B6D8-5980-11E6B2A63EA3B265}" FilePath="*appdata\local\microsoft\windows\inetcache\low\msimgsiz.dat">
		<Process CmdLine="*internet explorer\iexplore.exe scodef:*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{EA0AB693-4D22-9DB6-477315A6F5E3BFEC}" FilePath="*appdata\local\microsoft\windows\inetcache\low\smartscreencache.dat">
		<Process CmdLine="*internet explorer\iexplore.exe scodef:*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{341CF761-68DE-7A46-BF8A55E4ED3C9ADC}" FilePath="*appdata\local\temp\dlp_*.tmp">
		<Process CmdLine="*internet explorer\iexplore.exe scodef:*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{2920D574-FCE4-845B-AB3992FE3162A290}" FilePath="*appdata\local\temp\????????.htm">
		<Process CmdLine="*internet explorer\iexplore.exe scodef:*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{FE93D435-0408-DE75-85F55F193E25F2E6}" FilePath="*appdata\local\temp\????????_*.tmp">
		<Process CmdLine="*internet explorer\iexplore.exe scodef:*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{9D3ACEB5-98BF-F7E8-338B045B60FD37DA}" FilePath="*appdata\local\temp\low\dlp_*.tmp">
		<Process CmdLine="*internet explorer\iexplore.exe scodef:*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{32235E0B-54E6-BAAB-1E4DC3501CEC6259}" FilePath="*appdata\local\temp\tr?????.tmp">
		<Process CmdLine="*internet explorer\iexplore.exe scodef:*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{9F322A73-62EC-DCDF-DF40BB15EFF0C1EB}" FilePath="*appdata\local\temp\tr????.tmp">
		<Process CmdLine="*internet explorer\iexplore.exe scodef:*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{D5C4B7F6-5E31-66DA-36EE5C87C1B8C349}" FilePath="c:\windows\system32\spool\printers\?????.spl">
		<Process CmdLine="*internet explorer\iexplore.exe scodef:*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
<!-- Part 0022 2022-10-06T17:26:00.000Z-1665077162 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0023 2022-11-28T14:07:59.000Z-1669633679 -->
	<File Id="{4BF04564-24EC-44A5-AE6EDE4DFFDE8D84}" FilePath="C:\Windows\SystemTemp\????????-????-*" >
		<Process Path="C:\Windows\System32\spoolsv.exe" />
	</File>
<!-- Part 0023 2022-11-28T14:07:59.000Z-1669633679 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0024 2022-11-29T17:39:00.000Z-1669743579 -->
	<File Id="{344C0D9E-2651-ED9A-CBFAC59DA2239C98}">
		<Process CmdLine="c:\windows\system32\cmd.exe /s /c c:\program files (x86)\kaspersky lab\kaspersky endpoint security for windows\kescli.exe*" />
	</File>
	<File Id="{E3E8D2C3-F457-0267-F04B2B6955244D1A}">
		<Process CmdLine="c:\windows\system32\manage-bde.exe  -status " />
	</File>
	<File Id="{9B838A0E-0AF0-7F2F-F280CBDD90F33E93}" FilePath="c:\programdata\milestone\xprotect recording server\*">
		<Process>
			<Signature Subject="*Milestone*" />
			<VersionInfo ProductName="VideoOS" />
		</Process>
	</File>
	<File Id="{70EBBF14-DAB8-411D-F21E8F9A66B17242}" FilePath="c:\program files\bmc software\client management\client\data\*-journal">
		<Process Path="*Program Files*BMC*">
			<Signature Subject="BMC*Software*" />
		</Process>
	</File>
	<File Id="{1A171445-D600-8632-5313C62246CD60AA}" FilePath="*temp\sqlite_*">
		<Process Path="*Program Files*BMC*">
			<Signature Subject="BMC*Software*" />
		</Process>
	</File>
	<File Id="{7CACD0B4-EFF8-3632-30455417FF2AE211}" FilePath="c:\programdata\microsoft\edgeupdate\log\microsoftedgeupdate.log">
		<Process Path="*microsoft\edgeupdate\microsoftedgeupdate.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{FEBD682E-F5CF-5568-779F2F298712C7C3}" FilePath="*appdata\local\temp\microsoftedgeupdate.log">
		<Process Path="*microsoft\edgeupdate\microsoftedgeupdate.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{43381A73-5D59-9417-7D42CFB35CE6E335}" FilePath="c:\kronos\interfacedesigner\interfaces\mapped_folders\wim_in\kronos_*.csv">
		<Process CmdLine="%kl_undef%" />
	</File>
	<File Id="{882ABBE3-B241-2D40-21ECC6E21452EE52}" FilePath="*usr\sap\zep\sys\global*">
		<Process CmdLine="%kl_undef%" />
	</File>
	<File Id="{E9095501-BED0-94EC-E0F571ED26F78F5B}" FilePath="*usr\sap\zfp\sys\global*">
		<Process CmdLine="%kl_undef%" />
	</File>
	<File Id="{863B3F09-864D-2817-0744921100FE7F6A}" FilePath="*usr\sap\zsp\sys\global*">
		<Process CmdLine="%kl_undef%" />
	</File>
	<File Id="{0995349E-C5F0-7FFE-3BCC0935AF724AA8}" FilePath="c:\program files (x86)\guardium\guardium installation manager\gim\current\tmp*.txt">
		<Process CmdLine=" -i*gim\current\gim_client.pl " />
	</File>
	<File Id="{4F5E4295-4CFE-7197-9618DCDEE04E8DF9}" FilePath="c:\program files (x86)\guardium\guardium installation manager\gim\current\tmp*.txt">
		<Process CmdLine="-i*gim\current\gim_client.pl" />
	</File>
	<File Id="{E3D3A361-85F5-3363-766858EB64CB8C79}" FilePath="c:\programdata\usoshared\logs\user\notificationux.*.etl">
		<Process CmdLine="%systemroot%\system32\musnotificationux.exe *" />
	</File>
	<File Id="{7A4AB527-E6F0-ECBB-B1052F5A15B9478F}" FilePath="*manageengine\adaudit plus*">
		<Process CmdLine="..\jre\bin\java -dcatalina.home=.. -dserver.home=.. -dserver.stats=1000*" />
	</File>
	<File Id="{CF0FF5AF-1261-1704-29F69B97054D6ABD}" FilePath="&#39;c:\program files (x86)\sap\sapsetup*">
		<Process>
			<Signature Subject="SAP SE" />
		</Process>
	</File>
	<File Id="{D00743A5-79C8-87CA-AB08DA5205C81B71}" FilePath="appdata\local\temp\ops*.tmp">
		<Process Path="*Program Files*Cisco*">
			<Signature Subject="*Cisco*" />
		</Process>
	</File>
	<File Id="{3408EA81-EC45-8ACD-C368AB4743093F75}" FilePath="c:\users\*.cisco\vpn\log\uihistory_*_log.txt">
		<Process Path="*Program Files*Cisco*">
			<Signature Subject="*Cisco*" />
		</Process>
	</File>
	<File Id="{DCD2BC16-1669-4650-F4EBCE90E74D152F}" FilePath="c:\windows\syswow64\config\systemprofile\appdata\local\assembly\tmp\*__assemblyinfo__.ini">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{E19D0B07-3775-0521-C56667FE65317F43}" FilePath="*solarwinds.*.dll">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{D7808F20-4E57-8962-5F960E7760A115DA}" FilePath="*temp\tmp*.tmp">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{4C57FF24-10DC-12F6-A87EB2629D0BCCDF}" FilePath="c:\programdata\solarwinds\*.result">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{C1307106-C24A-4EC5-079133312B302433}" FilePath="c:\programdata\solarwinds\*.result.streamdata">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{2A720179-6AA7-F3A5-E6059509494B03AE}" FilePath="c:\programdata\solarwinds\*thresholdstreams\workermonitor\*">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{AEC471F8-5C08-1088-A29A23A282FA0003}" FilePath="c:\programdata\solarwinds\cortex\cache_*">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{2168588D-CEBC-0429-BBB70358AD80DE39}" FilePath="c:\programdata\solarwinds\servicehost\serviceregistry.db-???">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{CB49B27A-7A1B-81F9-D2E166BFD26A55A5}" FilePath="c:\programdata\solarwinds\logs*">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{67F206F6-F3C8-0145-7F6AC0B931E7CE68}" FilePath="c:\programdata\solarwinds\cortex_agent*">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{A75D7A16-4A4A-1621-A2014E25149A0E89}" FilePath="c:\programdata\solarwinds\*solarwinds.*">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{38229704-5871-C596-F6C0BE6A1BD81356}" FilePath="c:\programdata\solarwinds\*.sdf">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{CB1511E9-E91D-A922-03B309760B3A84A0}" FilePath="*temp\taskproperties.*">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{6F2B0063-E499-C574-A37FB5AB279EB701}" FilePath="*temp\solarwinds*solarwinds.*">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{2CC1D5E3-190E-27DF-C807E6A3A0DBD889}" FilePath="c:\windows\ccm\logs\ccmperf.log">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{C528BA7B-0B20-A1FE-F13688B528ECF6B5}" FilePath="c:\programdata\solarwinds\agent\tmp\taskproperties.*">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{0F8615F6-D95E-56AE-436918F8DF7AA091}" FilePath="c:\programdata\solarwinds\agentmanagement\tmp\taskproperties.*">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{854A927E-DBDC-9950-D65B5B601EF62324}" FilePath="c:\programdata\solarwinds\agentmanagement\tmp\tmp*">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*Solarwinds*" />
		</Process>
	</File>
	<File Id="{78AFF268-7410-E254-8096047BB19A9F05}" FilePath="c:\users\*appdata\local\temp\casesensitivetest*">
		<Process Path="c:\program files (x86)\datapatrol\agenthost\agenthostwinform.exe">
			<VersionInfo ProductName="AgentHostWinForm" OrignFileName="AgentHostWinForm.dll" FileDescription="AgentHostWinForm" />
		</Process>
	</File>
	<File Id="{9478861A-369C-BE68-26948D7193BC694C}" FilePath="*appdata\local\temp\imageio*.tmp">
		<Process Path="c:\program files (x86)\hiperwall\hiper*jre\bin\javaw.exe" />
	</File>
	<File Id="{AA8DA683-6BE6-2963-CB2BA895B82F3937}" FilePath="*appdata\local\hiperwall\browser\cache\*">
		<Process Path="c:\program files (x86)\hiperwall\hipersource.browser\build\browser.exe">
			<VersionInfo OrignFileName="Browser.exe" ProductName="HiperSource.Browser" FileDescription="Browser" />
		</Process>
	</File>
	<File Id="{257DD79A-3A86-8726-552B78AE40D4E162}" FilePath="*appdata\roaming\sas\enterpriseguide*">
		<Process>
			<Signature Subject="*SAS Institute*" />
		</Process>
	</File>
	<File Id="{8857047B-6402-EFB8-4AB0E045D3A3611B}" FilePath="c:\windows\syswow64\config\systemprofile\.unison\*">
		<Process CmdLine="&#34;c:\program files (x86)\stonevoiceas\lib\unison\unison.exe&#34; -batch -confirmbigdel=false -halfduplex*" />
	</File>
	<File Id="{7F044C8D-EF27-A6BC-39199C0B9E58019F}" FilePath="c:\windows\syswow64\config\systemprofile\.unison\*">
		<Process CmdLine="c:\program files (x86)\stonevoiceas\lib\unison\unison.exe -batch -confirmbigdel=false -halfduplex*" />
	</File>
	<File Id="{64263E49-3131-8856-09B7BA00F5E26A08}" FilePath="*veeam*.vbk">
		<Process Path="*Program Files*Veeam*">
			<Signature Subject="*Veeam*" />
		</Process>
	</File>
	<File Id="{446DB1A7-68FB-3748-923B5C030955C1A8}" FilePath="c:\programdata\veeam*">
		<Process Path="*Program Files*Veeam*">
			<Signature Subject="*Veeam*" />
		</Process>
	</File>
	<File Id="{3B551F1C-9C9C-CBE6-F178F97B4A494A87}" FilePath="*veeam*.vab">
		<Process Path="*Program Files*Veeam*">
			<Signature Subject="*Veeam*" />
		</Process>
	</File>
	<File Id="{7C5FF36A-D290-DA6C-959F344289D1B3B7}" FilePath="*temp\veeambackup*">
		<Process Path="*Program Files*Veeam*">
			<Signature Subject="*Veeam*" />
		</Process>
	</File>
	<File Id="{B5E5328E-E75A-2BBD-BC17AC348576D446}" FilePath="*vmware*.lck">
		<Process Path="*Program Files*Veeam*">
			<Signature Subject="*Veeam*" />
		</Process>
	</File>
	<File Id="{BE0B8947-4A53-3840-863A02A2D2969872}" FilePath="*temp\ntuser.dat*">
		<Process Path="*Program Files*Veeam*">
			<Signature Subject="*Veeam*" />
		</Process>
	</File>
	<File Id="{DCEEA5AB-CD32-C15F-622BCB813C1376E5}" FilePath="*temp\tmp????.tmp">
		<Process Path="*Program Files*Veeam*">
			<Signature Subject="*Veeam*" />
		</Process>
	</File>
	<File Id="{F08B22FA-6EAF-BABB-69A8947F59AB5C5A}" FilePath="c:\programdata\vmware\*">
		<Process Path="*Program Files*vmware*">
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{4F86B46C-3864-EBBE-4B4E47D8EEE81EAA}" FilePath="*appdata\local\vmware\vmware*">
		<Process Path="*Program Files*vmware*">
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{AFBC8066-25B1-7C94-4B091E7DA4671196}" FilePath="*appdata\roaming\microsoft\windows\recent\customdestinations*">
		<Process Path="*Program Files*vmware*">
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{D7F039CA-4C06-21F8-9C6FDFF3C34644D7}" FilePath="*appdata\roaming\vmware*">
		<Process Path="*Program Files*vmware*">
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{007ED7B1-1E28-C03C-4916A7351BD81C55}" FilePath="*appdata\local\temp\cdstmp_*">
		<Process Path="*Program Files*vmware*">
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{45872680-7FE6-DBC3-A1226F8A16956153}" FilePath="c:\windows\system32\spool\printers\?????.spl">
		<Process Path="*Program Files*vmware*">
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{BCD7C870-7AE9-F372-85F656CB11FFFE52}" FilePath="*appdata\local\temp\fnt*.tmp">
		<Process Path="*Program Files*vmware*">
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{FDA50CFD-8416-FE0E-ACEE1E17528342FC}" FilePath="c:\windows\system32\fxstmp\fxs*.tmp">
		<Process Path="*Program Files*vmware*">
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{8833A187-731E-9CFF-E45F21076B0099C9}" FilePath="*appdata\local\temp\vmware*">
		<Process Path="*Program Files*vmware*">
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{54081E32-46F1-2F51-75C5F67C1D2410F0}" FilePath="*program files (x86)\websense\data security\tempfiles\dss_*">
		<Process Path="*Program Files (x86)\Websense\Data Security\mgmtd.exe" />
	</File>
	<File Id="{8B602518-6143-343B-4C23BF34FBED13C9}" FilePath="c:\programdata\alteryx\errorlogs*">
		<Process Path="*Program Files*Alteryx*">
			<Signature Subject="*Alteryx*" />
		</Process>
	</File>
	<File Id="{1FAD69C5-7688-E10C-2996761779E5396A}" FilePath="c:\windows\system32\config\systemprofile\appdata\local\microsoft\office\otele\{*otele.dat">
		<Process Path="Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{88E69E0E-2ADF-0BF3-B9DA57799B097A09}" FilePath="*temp\*-????.log">
		<Process Path="Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{2BBCC146-9354-1F03-1050F9786C3874C7}" FilePath="*appdata\local\temp\toa????.tmp">
		<Process Path="*program files*dell*">
			<Signature Subject="*Dell*" />
		</Process>
	</File>
	<File Id="{FCD41112-1919-63D6-4B17BDA03746564E}" FilePath="*appdata\roaming\dell\toad for oracle*">
		<Process Path="*program files*dell*">
			<Signature Subject="*Dell*" />
		</Process>
	</File>
	<File Id="{1B552EDF-4DA8-38EF-98D99D73C2FDDFDA}" FilePath="c:\program files\fidelis\*">
		<Process Path="c:\program files\Fidelis*">
			<Signature Subject="*Fidelis*" />
		</Process>
	</File>
	<File Id="{33B4DCB4-F5F8-9408-89679D5ED2B43F18}" FilePath="*appdata\local\packages\*.wefs">
		<Process Path="*office*winword.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E5FB0A6B-6268-4283-82AE9ED037DA11B1}" FilePath="*appdata\local\packages\*.wefs">
		<Process Path="*office*powerpnt.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F82511E5-5226-5F95-E69489744EB60178}" FilePath="*appdata\local\packages\*.wefs">
		<Process Path="*office*excel.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{86B35224-B52B-E17B-03D5450E2F7CBF40}" FilePath="*appdata\local\packages\*.qipt">
		<Process Path="*office*winword.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{53F6FA1E-E60F-2876-F8E312342689EB43}" FilePath="*appdata\local\packages\*.qipt">
		<Process Path="*office*powerpnt.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{1B40ABDA-FA06-8861-E249BE7D00B3C363}" FilePath="*appdata\local\packages\*.qipt">
		<Process Path="*office*excel.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{3F802C5B-960B-CF3B-788D49A234582ABD}" FilePath="c:\program files\microsoft power bi report server\pbirs\asengine\microsoft\mashupprovider\cache*">
		<Process Path="c:\program files\microsoft power bi report server\pbirs\asengine\mdataengine\microsoft.mashup.container.netfx45.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D5436649-95F2-B183-75A244A3BC9A40CD}" FilePath="*\db*\e??????????.log">
		<Process Path="c:\program files\microsoft\exchange server\v15\bin\microsoft.exchange.store.worker.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A3BB9385-3E2B-6C48-446B0AA99CC5E0BF}" FilePath="c:\program files\microsoft\exchange server*">
		<Process Path="c:\program files\microsoft\exchange server\v15\bin\microsoft.exchange.store.worker.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{00B63228-B6BF-15A2-965785852E990AE3}" FilePath="*_archive_*\block*.blk">
		<Process Path="c:\program files\Milestone*">
			<Signature Subject="*Milestone*" />
		</Process>
	</File>
	<File Id="{722CB6E6-3A23-A8CD-EDD6AC2387E736A0}" FilePath="*_archive_*\?index*.idx">
		<Process Path="c:\program files\Milestone*">
			<Signature Subject="*Milestone*" />
		</Process>
	</File>
	<File Id="{4E4867A1-10F1-EF4B-604B062F998A7F29}" FilePath="*_archive_*\config.xml">
		<Process Path="c:\program files\Milestone*">
			<Signature Subject="*Milestone*" />
		</Process>
	</File>
	<File Id="{BEF3FBBF-64E8-1706-4DAE2FE6C1B322BB}" FilePath="*_archive_*\desktop.ini">
		<Process Path="c:\program files\Milestone*">
			<Signature Subject="*Milestone*" />
		</Process>
	</File>
	<File Id="{FDD92C8D-683E-CF0D-9DEB24176726E864}" FilePath="c:\programdata\milestone\*-journal">
		<Process Path="c:\program files\Milestone*">
			<Signature Subject="*Milestone*" />
		</Process>
	</File>
	<File Id="{E01451C4-E632-B1A8-30DCF33E3981E23B}" FilePath="c:\programdata\milestone\*-mj?????????">
		<Process Path="c:\program files\Milestone*">
			<Signature Subject="*Milestone*" />
		</Process>
	</File>
	<File Id="{BC54C406-3203-7FFF-DA474A09A7897E87}" FilePath="c:\programdata\mozilla*backgroundupdate\datareporting\glean\tmp*">
		<Process Path="c:\program files\Mozilla*">
			<Signature Subject="*Mozilla*" />
		</Process>
	</File>
	<File Id="{A487B3AA-202E-22B6-24E3C2A2C53DDC88}" FilePath="*appdata\roaming\mozilla\firefox\background tasks profiles*">
		<Process Path="c:\program files\Mozilla*">
			<Signature Subject="*Mozilla*" />
		</Process>
	</File>
	<File Id="{7C3EEDF7-47B2-0F9D-1391380E982A7C73}" FilePath="c:\programdata\cyvera\*">
		<Process Path="c:\program files\palo alto*">
			<Signature Subject="*Palo Alto*" />
		</Process>
	</File>
	<File Id="{8C9E697C-8AE5-BCCB-9E1005D680A186FF}" FilePath="*appdata\local\packages\microsoft.windows.photos_*\tempstate\etilqs_*">
		<Process Path="c:\program files\windowsapps\microsoft.windows.photos_2017.35063.44410.1000_x64__8wekyb3d8bbwe\microsoft.photos.exe" />
	</File>
	<File Id="{77A98951-5BEC-1CD1-3E98B3E2FBAE6A9C}" FilePath="*temp\expression_host_*">
		<Process Path="c:\windows\microsoft.net\framework*\vbc.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{E2025B14-3CB1-8E79-F41CCC563E75086F}" FilePath="windows\temp\vbc*.tmp">
		<Process Path="c:\windows\microsoft.net\framework*\vbc.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B42D2D75-BDB5-7189-339371C57F867C75}" FilePath="*temp\????????-????-*.dll.mui">
		<Process CmdLine="&#34;c:\windows\system32\dism.exe&#34; /online /remove-provisionedappxpackage*" />
	</File>
	<File Id="{208ED12C-225A-9CA5-0A0C3F9DE4FD32CD}" FilePath="*temp\????????-????-*.dll">
		<Process CmdLine="&#34;c:\windows\system32\dism.exe&#34; /online /remove-provisionedappxpackage*" />
	</File>
	<File Id="{483F8FEB-4DC0-7A6B-9CA073C787A78923}" FilePath="*appdata\roaming\microsoft\signatures*">
		<Process CmdLine="* -executionpolicy bypass -nologo -command .\eus.ps1" />
	</File>
	<File Id="{8FF74A0D-C0A6-015F-70217DAC5CDD4F4D}" FilePath="*tableau*">
		<Process Path="*Tableau*">
			<Signature Subject="*Tableau*" />
		</Process>
	</File>
	<File Id="{C41392CA-483D-5B41-5CEF316F3B365645}" FilePath="*appdata\local\conda\conda*">
		<Process CmdLine="*scripts\anaconda-navigator-script.py" />
	</File>
	<File Id="{105AB28F-1B66-089E-AD0A9B21C34C188C}" FilePath="c:\users\*conda*\envs\?????">
		<Process CmdLine="*scripts\anaconda-navigator-script.py" />
	</File>
	<File Id="{E17E8335-ED24-AC74-F451FDD63847C646}" FilePath="c:\users\*conda*\pkgs\?????">
		<Process CmdLine="*scripts\anaconda-navigator-script.py" />
	</File>
	<File Id="{D47C33C5-7B38-8BBB-B0ABC6F44EC6E7EE}" FilePath="*temp\????????-????-*">
		<Process CmdLine="c:\windows\cluster\clussvc.exe -s">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AC3E29E4-C24D-8EBF-29ED0F90EFB159AF}" FilePath="*appdata\local\temp\ops????.tmp">
		<Process CmdLine="*kaspersky lab\kaspersky endpoint security for windows\kescli.exe*" Path="*system32\cmd.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{480067AC-F271-C1CC-61E97DC2686D1F9E}" FilePath="*appdata\local\temp\ops????.tmp">
		<Process CmdLine="*c:\windows\system32\manage-bde.exe*" Path="*system32\cmd.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{0E5F3A71-B6C8-3BD4-58EC2D23814D48A9}" FilePath="*appdata\local\temp\ops????.tmp">
		<Process CmdLine="* 437 *os get osarchitecture*" Path="*system32\cmd.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{5BBFB41A-9F4E-BDF3-F1CC563D6E12E8BD}" FilePath="c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\deliveryoptimization\logs\*.etl">
		<Process CmdLine="c:\windows\system32\wbem\wmiprvse.exe -secured -embedding" />
	</File>
	<File Id="{4F95C818-B85D-5329-228E6B3BE4CCDD2B}" FilePath="*index_share\index\enterprise\data_flow*">
		<Process CmdLine="*jre/bin/otupdatedistributor  -xrs*" />
	</File>
	<File Id="{5969CB48-A7FB-5577-4E9EE517FE4A1C14}" FilePath="*index_share\index\enterprise\data_flow*">
		<Process CmdLine="*bin/ipmove -config*" />
	</File>
	<File Id="{7A6A9F65-9D11-BE82-AE6B333A52E78378}" FilePath="*\data.;1">
		<Process Path="*bin\tomcat*">
			<Signature Subject="*Apache*" />
		</Process>
	</File>
	<File Id="{A98967E0-2DD8-94E5-577B4751CDBF72D1}" FilePath="*\attrib.atr">
		<Process Path="*bin\tomcat*">
			<Signature Subject="*Apache*" />
		</Process>
	</File>
	<File Id="{8885A7B5-DBF0-6560-52AC73FEA90635D0}" FilePath="*\.attrib.atr.old">
		<Process Path="*bin\tomcat*">
			<Signature Subject="*Apache*" />
		</Process>
	</File>
	<File Id="{AAD64809-89C0-C435-FAC4C384DC9A89B8}" FilePath="*\.job.envision_envisionpool">
		<Process Path="*bin\tomcat*">
			<Signature Subject="*Apache*" />
		</Process>
	</File>
	<File Id="{7400866D-16FB-1158-7DDEB98262BB3722}" FilePath="*orant\report60*">
		<Process CmdLine="rwrbe60 -ssl09@" />
	</File>
	<File Id="{ED5FA368-E2E4-6F24-3BB15A4306C8B739}" FilePath="*UsageLogs\VCTIP.EXE.log">
		<Process Path="*bin\hostx64\x86\vctip.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{53B32A33-B3EE-0FC7-DBC636A0CF3746AD}" FilePath="*UsageLogs\VCTIP.EXE.log">
		<Process Path="*hostx86\x86\vctip.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{1723859F-ED0A-BA5D-158724EC98666FCB}" FilePath="*usagelogs\vctip.exe.log">
		<Process CmdLine="c:\program files\gvfs\gvfs.hooks.exe pre-command*" />
	</File>
	<File Id="{F18B04DB-57CA-5877-DA3D68CE083E748D}" FilePath="*usagelogs\gvfs.hooks.exe.log">
		<Process CmdLine="c:\program files\gvfs\gvfs.hooks.exe pre-command*" />
	</File>
	<File Id="{04E3F626-1E0C-1263-1CD74F79BD8F7385}" FilePath="*usagelogs\vctip.exe.log">
		<Process Path="C:\Windows\Temp\DPTF\esif_assist_64.exe">
			<Signature Subject="*Intel*" />
		</Process>
	</File>
	<File Id="{65EE6E2C-DE8B-C1D3-4E6C248567228398}" FilePath="*usagelogs\gvfs.hooks.exe.log">
		<Process Path="C:\Windows\Temp\DPTF\esif_assist_64.exe">
			<Signature Subject="*Intel*" />
		</Process>
	</File>
	<File Id="{3046D651-0865-F853-2D0DD79831F85F00}" FilePath="*temp\dptf\esif_assist_64.exe">
		<Process Path="C:\Windows\Temp\DPTF\esif_assist_64.exe">
			<Signature Subject="*Intel*" />
		</Process>
	</File>
<!-- Part 0024 2022-11-29T17:39:00.000Z-1669743579 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0025 2022-11-30T13:52:00.000Z-1669816359 -->
	<File Id="{4B691BEC-5599-1A86-96A104FEA902E531}" FilePath="*data\manictime*.db-journal">
		<Process Path="*Manic*">
			<Signature Subject="*Finkit*" />
		</Process>
	</File>
	<File Id="{CB55B48C-FC7E-95DE-B9476244F10E5067}" FilePath="*appdata\local\temp\casesensitivetest*">
		<Process Path="*msbuild\current\bin\amd64\msbuild.exe">
			<Signature Subject=".NET" />
		</Process>
	</File>
	<File Id="{1D62AAE3-69A7-6A26-A7A8C3C29FF6C98F}" FilePath="*appdata\local\temp\tmp*.rsp">
		<Process Path="*msbuild\current\bin\amd64\msbuild.exe">
			<Signature Subject=".NET" />
		</Process>
	</File>
	<File Id="{F4C746FF-39B3-0ADA-A6389EA5B6581474}" FilePath="*appdata\local\temp\msbuildtempmolaev\tmp*.rsp">
		<Process Path="*msbuild\current\bin\amd64\msbuild.exe">
			<Signature Subject=".NET" />
		</Process>
	</File>
	<File Id="{9E38947A-B2D3-CBD7-EF40C9CD804A9121}" FilePath="*appdata\local\temp\res*.tmp">
		<Process Path="*tools\tlbimp.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{9CF366BE-9968-C4DF-6F36D8B7F1E96F99}" FilePath="*appdata\local\.identityservice*">
		<Process Path="*common7\ide\devenv.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D9A3BD32-E1D6-8A6C-15107CB1CF1A8249}" FilePath="*appdata\local\.identityservice*">
		<Process Path="*servicehub.host.clr*\servicehub.identityhost.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{A77C4BD6-2327-8E2B-F85C48148E6CB69C}" FilePath="*appdata\local\temp\*_analysis\*">
		<Process Path="*common7\ide\devenv.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{274E9892-FE42-3AE3-E2ED4E515BEA4B46}" FilePath="*appdata\local\temp\*_analysis\*">
		<Process Path="*servicehub.host.clr*\servicehub.identityhost.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{B59C61F2-E9BA-D114-1C6D00CC1A87F06F}" FilePath="*appdata\local\jetbrains\resharperplatform*">
		<Process Path="*common7\ide\devenv.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{AFAD619E-0021-F5E9-8AEB70B26D8FD27E}" FilePath="*appdata\local\jetbrains\resharperplatform*">
		<Process Path="*servicehub.host.clr*\servicehub.identityhost.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DF9C7ECD-4540-935F-833ED006324BBF94}" FilePath="*appdata\local\temp\servicehub\logs*">
		<Process Path="*common7\ide\devenv.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{46B1892E-12E5-0BAF-88A35A264E6F6D3B}" FilePath="*appdata\local\temp\servicehub\logs*">
		<Process Path="*servicehub.host.clr*\servicehub.identityhost.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{92A8FC88-ED5A-3E22-40EA5BAFD72337E2}" FilePath="*appdata\local\temp\vs*">
		<Process Path="*common7\ide\devenv.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{46F16EC8-5042-9996-DD5F7A96E2C7E3F4}" FilePath="*appdata\local\temp\vs*">
		<Process Path="*servicehub.host.clr*\servicehub.identityhost.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{FBDD30B2-978C-36A6-B884918C852EBE1C}" FilePath="*appdata\local\temp\wpf*">
		<Process Path="*common7\ide\devenv.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{90092684-4FD2-60DA-0C20532719776B80}" FilePath="*appdata\local\temp\wpf*">
		<Process Path="*servicehub.host.clr*\servicehub.identityhost.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DDA88445-D863-255A-D42FFE961135EBC5}" FilePath="*appdata\roaming\microsoft\visualstudio*">
		<Process Path="*common7\ide\devenv.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{34BF6029-E95D-41EE-82F108B53BFB0980}" FilePath="*appdata\roaming\microsoft\visualstudio*">
		<Process Path="*servicehub.host.clr*\servicehub.identityhost.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{DEFFAE8E-E1E3-3901-20BA6B584E18F34B}" FilePath="*appdata\local\temp\????????.???">
		<Process Path="*common7\ide\devenv.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{5C6B9781-B5E4-2B6D-106FAD68FF844EC6}" FilePath="*appdata\local\temp\????????.???">
		<Process Path="*servicehub.host.clr*\servicehub.identityhost.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{70382B82-E2C4-906A-EDC5351A41AD9A37}" FilePath="*appdata\local\temp\*_analysis\esp*.tmp">
		<Process Path="*bin\host*\cl.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{D573195E-1FDE-DE4B-FDE670455BE2F81A}" FilePath="*appdata\local\temp\vmware*">
		<Process Path="*vmware*">
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{3E388EAC-0CA9-DAC8-DFDFBB542E4D9CAD}" FilePath="*appdata\roaming\vmware*">
		<Process Path="*vmware*">
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{C34EB7B5-CBB4-4F58-30152930434DA45E}" FilePath="*.vmsd.lck\*.lck">
		<Process Path="*vmware*">
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{B21A9D8B-DFB9-8541-204E505ED5ADD5D2}" FilePath="*.vmdk.lck\*.lck">
		<Process Path="*vmware*">
			<Signature Subject="*vmware*" />
		</Process>
	</File>
	<File Id="{83836575-14A6-4F2C-57B20025601C76B3}" FilePath="*appdata\local\temp\vs\analyzerassemblyloader*">
		<Process Path="*common7\ide\devenv.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{89A9A243-5DA2-D519-FDFE8FD4FA64B389}" FilePath="*appdata\local\temp\vslogs*">
		<Process Path="*common7\ide\devenv.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{8E43E307-06FE-3BBD-9CEE3DC065AC73FE}" FilePath="*appdata\local\microsoft\visualstudio*">
		<Process Path="*hosts\servicehub.host*\servicehub.*.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{30370183-AFF4-1D36-EE8EE0C4BA54AA9D}" FilePath="*appdata\local\temp\servicehub\logs*">
		<Process Path="*hosts\servicehub.host*\servicehub.*.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{13C933F9-81AD-41B5-49A838C2ED3F3F2C}" FilePath="*appdata\local\temp\etilqs_*">
		<Process Path="*hosts\servicehub.host*\servicehub.*.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{EDA30E1F-0037-09E6-BCFD6E189DB16510}" FilePath="*appdata\local\temp\vs\analyzerassemblyloader*">
		<Process Path="*hosts\servicehub.host*\servicehub.*.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{C8788DD4-6886-AEF7-3770D098D6AB578F}" FilePath="*appdata\local\temp\????????.???">
		<Process Path="*msbuild\current\bin\amd64\msbuild.exe">
			<Signature Subject=".NET" />
		</Process>
	</File>
	<File Id="{95C11299-C136-2E7F-AB6B2A2BA696D87D}" FilePath="*appdata\local\temp\????????.???">
		<Process Path="*msbuild\current\bin\msbuild.exe">
			<Signature Subject=".NET" />
		</Process>
	</File>
	<File Id="{96CBC5F3-9A34-496C-7F50C61DCA90C74A}" FilePath="*appdata\local\temp\????????.cmdline">
		<Process Path="*msbuild\current\bin\amd64\msbuild.exe">
			<Signature Subject=".NET" />
		</Process>
	</File>
	<File Id="{ABED8C6C-D7F2-6169-748088AF13815BD9}" FilePath="*appdata\local\temp\????????.cmdline">
		<Process Path="*msbuild\current\bin\msbuild.exe">
			<Signature Subject=".NET" />
		</Process>
	</File>
	<File Id="{838FB991-451D-237C-798513612FE9C8EA}" FilePath="*appdata\local\temp\vbcscompiler\analyzerassemblyloader*">
		<Process Path="*msbuild\current\bin\*\vbcscompiler.exe">
			<Signature Subject=".NET" />
		</Process>
	</File>
	<File Id="{2199E72C-83AB-EC89-FB35FCC1EC30E0A0}" FilePath="*appdata\local\microsoft\tokenbroker\cache*">
		<Process Path="*appdata\local\microsoft\onedrive*">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{22F618EF-3B43-E220-F8F73550D668267F}" FilePath="*appdata\local\microsoft\identitycache*">
		<Process Path="*appdata\local\microsoft\onedrive*">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{4B1BF2A8-100B-92EB-52954A95AC47946C}" FilePath="*appdata\local\microsoft\visualstudio*">
		<Process Path="*AppData\Local\Microsoft\VisualStudio*">
			<Signature Subject="*Idera*" />
		</Process>
	</File>
	<File Id="{3BEAA16E-4C12-9C8A-EFCBA612E7EA0630}" FilePath="c:\windows\assembly\temp\*microsoft.*">
		<Process Path="*framework*\mscorsvw.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{66278524-EEA9-1128-5076C36CEDB97339}" FilePath="c:\windows\assembly\temp\*system.*">
		<Process Path="*framework*\mscorsvw.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
<!-- Part 0025 2022-11-30T13:52:00.000Z-1669816359 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0026 2022-12-19T18:16:00.000Z-1671473819 -->
	<File Id="{B10B8D72-CB87-4547-9F8C9F3A017732E7}" FilePath="*windows\temp\~*.tmp">
		<Process Path="*SIEMENS\WINCC\bin\CCProjectMgr.exe">
			<VersionInfo ProductName="*WINCC*SCADA*" FileDescription="Project Manager" OrignFileName="CCProjectMgr.exe" />
		</Process>
	</File>
<!-- Part 0026 2022-12-19T18:16:00.000Z-1671473819 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0027 2023-03-17T13:27:00.000Z-1679059621 -->
	<File Id="{EE277DF2-11E1-B212-A41E5078BD335815}" FilePath="*data\default\local extension settings\????????????????????????????????\??????.???" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{527617DD-8343-022E-7810F8BC153CCD96}" FilePath="*data\browsermetrics\browsermetrics-????????-???.pma" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{1FF498AB-1046-C7D6-225AE81CE4B19DBE}" FilePath="*data\default\*\log" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{28813F77-748B-7F1A-BABC8A3CC6D3E152}" FilePath="*data\default\*-journal" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{215B6546-E030-D6E4-30F5195E1FE323DF}" FilePath="*data\default\search logos\metadata" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{C01C8DDA-8793-C59E-B00BA8AD6EC4BA7A}" FilePath="*data\default\search logos\logo" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{BD70EF2F-17C4-8F94-C7C201BC550CAE52}" FilePath="*data\default\current session" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{4A3B85F1-D4DB-208F-38D0E7FE9CE4DF42}" FilePath="*data\crashpadmetrics-active.pma" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{1E1B7DB0-17DC-DB8D-FA1220779D4D0E86}" FilePath="*data\default\data_reduction_proxy_leveldb\manifest-??????" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{A2931163-A114-67DB-C9C35FDC1FBD08EC}" FilePath="*data\default\code cache\js\index-dir\temp-index" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{E2D6FDEE-C2E7-3EDC-7688850BA1AD16BB}" FilePath="*data\default\service worker\cachestorage\????????????????????????????????????????\????????-????-????-????-????????????\????????????????_?" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{DDCA50A8-2948-4806-E4324FB35C6D68D6}" FilePath="*data\default\service worker\scriptcache\????????????????_?" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{347E8EE0-FD3D-DE92-2C2C3F7DB4986DC3}" FilePath="*data\default\sync data\leveldb\??????.ldb" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{B86E017F-8C3C-EA7E-6D23F3FD5C0D55CB}" FilePath="*data\profile ?\indexeddb\https_docs.google.com_0.indexeddb.leveldb\log" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{CE2F0331-1D00-67C3-21A34D83ED9901FA}" FilePath="*data\profile ?\cache\?_??????" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{D941A03B-C18D-247E-9A789F32C524D182}" FilePath="*data\profile ?\code cache\js\????????????????_?" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{60DF7058-F40F-AB4B-B9FB35ADAF9029B7}" FilePath="*data\default\indexeddb\*\??????.ldb" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{FA04A80A-DB20-4EAE-52E6B0D53F824501}" FilePath="*data\default\indexeddb\*.ldb" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{26488361-CAEB-5691-43350150E45BC795}" FilePath="*data\default\*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{2AE07081-205B-1147-803AA859F9C83C9B}" FilePath="*data*\????????-????-*.tmp" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{93DD4494-7CCD-0BA3-58FE9DB49A1F836E}" FilePath="*data*cache\?_??????" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{A0C22334-105C-BF6A-0372C8319249529A}" FilePath="*data\default\code cache\js\????????????????_?" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{FACED973-0FF6-812B-3D71F1BEBCF8DCA3}" FilePath="*data*\??????.log" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{C956DCF3-B8DF-6C63-E54BF6B6BABAF4FF}" FilePath="*data*\??????.ldb" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{E1AD6DE3-D4BD-B43D-786C85281536D8AF}" FilePath="*data\default\transportsecurity" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{CD3B8C78-F344-3B8F-685E5207C59D3483}" FilePath="*data\default\preferences" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{EBFFC4EA-25C7-59BA-B1AE21956E4D4213}" FilePath="*data\local state" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{95D3BABC-C8BB-569A-CF5FCB9062D9C091}" FilePath="*data\crashpadmetrics*.tmp" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{6DA3DAB9-2B6D-FEF7-2D52621EA25A4CAA}" FilePath="*data\default\*~rf*.tmp" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{F9DB9FD7-B614-0F9C-2AB01ED9CB4C48A6}" FilePath="*data\profile 1\transportsecurity" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{0091523F-0E60-43FD-62B2D85DBB27B6B1}" FilePath="*data\profile 1\preferences" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{032D0D95-E218-7A47-2FCADFEDFE29B49B}" FilePath="*data\profile 1\*~rf*.tmp" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{13861E7F-B07D-2EF2-F9995A3AB694EA63}" FilePath="*data\browsermetrics\browsermetrics-????????-????.pma" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{8C9588D7-9C14-5A65-B59B32299401EFDA}" FilePath="*service worker\cachestorage\*" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{D1474067-62D3-7810-E4BCD649E631B48E}" FilePath="*data\default\*_?????????????????" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{90FB864D-22FE-4453-67A96F817BDFF707}" FilePath="*data\default\indexeddb\*.indexeddb.*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{4C6A44B9-6B59-C4A1-2663C001FFFE4E94}" FilePath="*data\profile 1\indexeddb\*.indexeddb.*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{1B01119A-BCAE-F349-48FD51B002473E26}" FilePath="*data\profile 1\service worker\cachestorage\*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{F2133CC4-5BDF-C6AB-0CB05C04B3E472C9}" FilePath="*data\profile 1\*_?????????????????" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{B13C5B85-9471-FDEE-B50A3A2834B0F4CD}" FilePath="*data\default\cache\f_??????" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{833BBF6F-7BEF-BD11-C7EAE5902F36C2EA}" FilePath="*data\*~rf*.tmp" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{217B74FC-CA2E-FAEA-67F6664269B10D41}" FilePath="*data\default\*cache\*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{3842F6DD-79B6-EE34-FC4A2E5D0AFD97D3}" FilePath="*data\*.usage" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{896DFC2D-A0D4-228C-BD64EF97400B0418}" FilePath="*data\*\????????" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{C896A6A5-8159-7BBF-287EB3554EE4845A}" FilePath="*data\*\??????.log" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{3F81DBD8-53AC-B9D5-8C6B379DA3613A6C}" FilePath="*data\*\??????.dbtmp" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{6AD1420F-04AF-F03A-812509463FBDCDD1}" FilePath="*data\*\????????????????_?" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{D5EA3847-A9B2-A42B-0DEA1618D8D911F0}" FilePath="*data\*\?" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{8C5058D8-45C0-2EC2-7DE668C4A4498D0E}" FilePath="*data\*\??" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{E98485C9-E139-4293-2B2534B5EEA420AF}" FilePath="*data\*\????????-guid.tmp" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{62B22E80-C936-3E0F-5A4FB5119E5A672F}" FilePath="*data\*\browsermetrics-spare.pma*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{E18C7F11-938F-33AD-32C84642B002C9E7}" FilePath="*data\*\chrome_shutdown_ms.txt" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{C7F72875-A4B8-55F7-0C01A15B1691BCDE}" FilePath="*data\*\chromeextmalware.store*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{6A5887A3-6134-8A9E-0C3CC592617007A1}" FilePath="*data\*\crashpadmetrics.pma" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{A519BE8F-C218-E6C4-863B75D53A4EF3EF}" FilePath="*data\*\crl-set" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{6F93B49E-C96D-B2CE-70AC29F651438757}" FilePath="*data\*\current" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{0B604E20-F83A-6CD9-843E9C38899D09AC}" FilePath="*data\*\data_?" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{6B68EC88-A4B0-ACCE-27024A4975838000}" FilePath="*data\*\f_??????" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{0DC313CF-A9F6-55D1-C541937C9F13FDF7}" FilePath="*data\*\favicons" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{7A7847D2-300C-E127-70C8BE1D90981325}" FilePath="*data\*\history provider cache" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{DE75476A-EC79-6CB2-55D6353415012FBB}" FilePath="*data\*\history" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{3C81E594-4C99-E7A2-97A746A3785BB163}" FilePath="*data\*\index" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{2F84A737-361F-8C3F-743826B3A69F8818}" FilePath="*data\*\last *" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{647D2524-7D35-5F87-5B9AF8AFD2D797CB}" FilePath="*data\*\license" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{444FF1DF-4F47-9A65-8EBDE6E9BD3FAFCC}" FilePath="*data\*\lockfile" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{59969EFF-F113-B2DC-628F78CA5C504926}" FilePath="*data\*\log.old" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{0F7F6EC0-77E8-166C-F08F30FD6DD43AB4}" FilePath="*data\*\logo" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{ECDF54F1-D1A1-99C7-0C3CF1302BC554C4}" FilePath="*data\*\manifest-??????" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{6FD0676A-8378-E4A3-6B8768659DB04DCA}" FilePath="*data\*\manifest.*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{F09B1DCE-7C90-A1CD-8804996804BE0AF0}" FilePath="*data\*\module info cache*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{C25334C7-445B-324F-879533E7DD0296DC}" FilePath="*data\*\network *" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{AF68FFAB-6D91-D477-4FC053A191972BB7}" FilePath="*data\*\nigori.bin" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{774ADDDB-0F82-0ABF-9E0AF905D321677D}" FilePath="*data\*\quotamanager" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{70C8D297-AD80-F1AB-F65D0182E286151F}" FilePath="*data\*\safety_tips.pb" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{84312A9C-8EEE-139E-F0BB5FEE3DFD72F9}" FilePath="*data\*\serenity.s??" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{C36F2AFF-961D-3452-E3E13A7220DA4A9F}" FilePath="*data\*\settings.???" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{E6556516-8ED2-07BD-57377921A0CBE8C1}" FilePath="*data\*\smashtest-meta.s??" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{659F4AB2-8592-D03B-004217C9F9705023}" FilePath="*data\*\temp-index" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{EAB5A34B-4EA6-C3C8-69A7708F30F8D032}" FilePath="*data\*\the-real-index" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{B0A09CED-E575-7BE9-41D5FF186535C590}" FilePath="*data\*.store" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{6C4C9BE4-F1B6-7BB0-E743E40FB03CEFE3}" FilePath="*data\*.store_mew" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{3D9F6A6F-1F6E-102A-C36950019B895052}" FilePath="*data\*\verified_contents.json" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{C34AF184-4CD1-5B69-9EF6DF77C1903FF0}" FilePath="*data\*\visited links" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{0967FD10-48C2-22F3-1E0B8ACDD71A15EC}" FilePath="*data\*\web data" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{C6464E83-0639-5229-8DFC1B374C242D5D}" FilePath="*data\safe browsing\url*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{EBBC0401-4A0B-CAFB-7795178C6D38081F}" FilePath="*data\safe browsing\urlmalware.store_new" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{F1EB6CC5-7695-59D2-13BA398E18AE6972}" FilePath="*data\crashpadmetrics.pma" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{AE9E3305-AB49-D23A-DA556BC446BBC525}" FilePath="*data*\????????-????-????-????-????????????.tmp" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{51D524CF-53C0-D5C8-DDFD008824A19CA4}" FilePath="*data\profile 2\preferences" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{12619D76-D2B7-109F-B501F9DFB09A28E0}" FilePath="*data\profile 2\transportsecurity" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{0B5600A7-6CA4-A0A7-39FEEB4888D090D8}" FilePath="*data\default\extensions\*\messages.json" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{749019F5-F441-B1F1-517B2EE798BAB19A}" FilePath="*data\default\indexeddb\https_*.indexeddb.blob\*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{BE97EA88-4CD7-12EA-A30318089826F7F1}" FilePath="*data\default\local storage\leveldb\??????.ldb" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{6E316278-DF83-6EE4-95656DB083783B9C}" FilePath="*data\configs\*_*.json" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{24C77EDB-3595-C193-701D3662A1E489A3}" FilePath="*data\crashpad*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{8CB5F100-B802-2A21-572F3F4F325133FB}" FilePath="*data\grshadercache\gpucache\*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{1D83D512-2228-9A91-C0B1FA95877F7CF3}" FilePath="*data\module info cache~rf*.tmp" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{39073062-E4C9-29D0-6D4AD775DCC641B7}" FilePath="*data\profile*~rf*.tmp" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{53A5D05A-AD2F-5FBF-BA78DF7CCA1A79FC}" FilePath="*data\smartscreen\remote\synchronouslookup*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{9B6C8421-47D0-6A15-15C7591024AFD097}" FilePath="*data\browsermetrics-spare.*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{BC762A81-2442-8FF6-A52ECAA1F6228F4B}" FilePath="*data\chrome_shutdown_ms.txt" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{D721C461-D043-9A65-07D890AB53BACB5B}" FilePath="*data\default\bookmarks" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{F1DEE2FC-57D0-A780-AAB1562CECEC0C4F}" FilePath="*data\default\code cache\js\index-dir\the-real-index" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{F4125B8D-F1C8-CB59-DDA07A15ECA5E7A7}" FilePath="*data\default\cookies" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{3C24D6F1-DDE3-7A8A-893BEAC26D7D3C9A}" FilePath="*data\default\downloadmetadata" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{17953ECA-B1F9-085F-8B536679F90094A6}" FilePath="*data\default\sync data\nigori.bin" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{74E50385-5E41-19F5-48EFF735EEF67EA9}" FilePath="*data\last browser" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{58D49C11-605E-2245-AD427E0AB5FD1375}" FilePath="*data\last version" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{6FF079B1-5D75-18D2-04362826EB942CF9}" FilePath="*data\lockfile" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{1F6741F9-7277-9CC1-2889261D89AA7C4D}" FilePath="*data\module info cache" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{9E6E6A32-2AC6-F725-5F2723CDA703BE4F}" FilePath="*data\profile ?\preferences" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{38205925-416D-05FC-BD96ECD817F344A1}" FilePath="*data\profile ?\transportsecurity" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{F9A3D2D5-0D23-03D9-A0634CB078194F87}" FilePath="*data\tab lifetime" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{DB0ECCD7-ED43-A686-F5637473184AD0E9}" FilePath="*data\default\cache\f_??????" >
		<Process >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{658A072C-0D2E-3E31-F00B467C32B00EBB}" FilePath="*data\default\code cache\js\????????????????_?" >
		<Process >
			<Signature Subject="*google*" />
		</Process>
	</File>
	<File Id="{EC3BEFF7-179C-0727-F8567F943173B33C}" FilePath="*data\default\service worker\cache*" >
		<Process Path="*application\*" >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{F754FFDE-BD3F-9BC9-D85254D902465AB3}" FilePath="*data\default\network\transportsecurity" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{0699AF3F-09A5-5CDB-6AE10D33A817E030}" FilePath="*data\default\code cache\js\index-dir\*" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{A1B94F29-7DA5-A8E8-8AF55B98B5084732}" FilePath="*data\default\indexeddb\https_*" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{1BD089CC-BC66-52A1-751203E323B166D0}" FilePath="*data\default\network\transportsecurity~rf*" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{A8CDAEE8-7388-A5BF-5792647405D0C6EA}" FilePath="*data\default\preferences~*" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{E33193C2-3DDC-5BCC-4F0DAECAC29F7D88}" FilePath="*data\default\session storage\*.ldb" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{2AE3B358-482C-DB3D-44CD354DD7DEA13C}" FilePath="*data\default\sessions\session_*" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{DA522AB3-67DF-B312-1F17EBE643F3DF31}" FilePath="*data\default\transportsecurity~*" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{C0058044-BEE4-D8A6-3B09A374B3A07CB5}" FilePath="*data\profile ?\network\transportsecurity~*" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{DC68AF4B-0994-6262-2F76050D4EC8BEFF}" FilePath="*data\profile ?\preferences~*" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{34367B9A-E835-6613-96BAA4306ED72F53}" FilePath="*data\local state~*" >
		<Process >
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{EE998960-6F6E-14DA-C1FB6C840644F9F3}" FilePath="*data\default\cache\*" >
		<Process Path="c:\program files (x86)\360\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{790B6BF7-E827-CB3A-D6A74F29199E0EE9}" FilePath="*data\default\preferences~*" >
		<Process Path="c:\program files (x86)\360\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{C1FAFF40-4489-FD49-28C3CD3F6AB7F6B0}" FilePath="*data\default\cache\*" >
		<Process Path="c:\program files\360\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{DF8E98A8-1FD3-9ADD-EF03BB0AF017B0A6}" FilePath="*data\default\preferences~*" >
		<Process Path="c:\program files\360\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{6CC9F325-4350-2896-87593B108F37374A}" FilePath="*data\default\cache\*" >
		<Process Path="*appdata\local\360chrome\chrome\application\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{F1A9144A-C710-2E8F-3A442D8A7FE912D6}" FilePath="*data\default\preferences~*" >
		<Process Path="*appdata\local\360chrome\chrome\application\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{D446068A-4001-662B-53F45DC0F06BAD67}" FilePath="*data\default\cache\*" >
		<Process Path="*appdata\roaming\360*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{0685D075-CD97-5962-5E5BB8B6421B7D0F}" FilePath="*data\default\preferences~*" >
		<Process Path="*appdata\roaming\360*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{939F8DF6-9962-AB8D-99493833C994F704}" FilePath="*data\default\cache\*" >
		<Process Path="*appdata\roaming\secoresdk\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{1F2A663C-3771-CA0A-98901B5D6F260042}" FilePath="*data\default\preferences~*" >
		<Process Path="*appdata\roaming\secoresdk\*" >
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</File>
	<File Id="{DF24533E-6264-47BB-002B540D7E62BDB6}" FilePath="*data\default\cache\*" >
		<Process Path="*\program files (x86)\tencent\*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{5F944FD6-18B6-F68C-2DCB4716242FEB95}" FilePath="*data\default\cache\*" >
		<Process Path="c:\program files (x86)\tsoft\*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{5287EA36-1295-87A4-2159FD85B6596B84}" FilePath="*data\default\cache\*" >
		<Process Path="c:\program files (x86)\wxwork*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{6951778E-0E28-216C-8591997A9B00ABAB}" FilePath="*data\default\cache\*" >
		<Process Path="c:\program files\tencentdocs*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{D523C7F4-3C48-ED62-03C83A5031D5FA40}" FilePath="*data\default\cache\*" >
		<Process Path="*appdata\roaming\tencent\*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{A464818A-5CFC-1AB9-9E5FCF4767A62675}" FilePath="*data\default\cache\*" >
		<Process Path="c:\program files\windowsapps\tencentwechatlimited*" >
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{15C0514A-F8FF-B638-931CB63006B39AF0}" FilePath="*data\profile *network\transportsecurity">
		<Process>
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{EDC0CE00-02D6-3F10-A21E2304DD55E2C0}" FilePath="*data\hyphen-data\*hyph-*.hyb">
		<Process>
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{1EC253B2-B294-EBB1-73D01F219DB3F307}" FilePath="*appdata\roaming\microsoft\Шаблоны\normal.dotm" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{2F4CB972-7E89-A01B-F69912558FA66274}" FilePath="*appdata\roaming\microsoft\Шаблоны\normalemail.dotm" >
		<Process Path="*svchost.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{3F4EDD79-B99C-3923-4A7DA2C59BBBF6E1}" FilePath="*appdata\roaming\microsoft\Шаблоны\normalemail.dotm" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{48D42E00-3C91-9D57-7FDF9A9F306C38F1}" FilePath="*appdata\roaming\microsoft\Шаблоны\~$rmalemail.dotm" >
		<Process Path="*\office*\outlook.exe" >
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{5B2C1D87-E3E0-2018-1F2038DA24BE29C5}" FilePath="*appdata\roaming\microsoft\Шаблоны\~$normal.dotm" >
		<Process Path="*winword.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{6EE4C0E7-EE5E-3030-C301C36FE41FFD4B}" FilePath="*appdata\roaming\microsoft\Шаблоны\normal.dotm" >
		<Process Path="*winword.exe" >
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
<!-- Part 0027 2023-03-17T13:27:00.000Z-1679059621 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0028 2023-03-20T17:54:00.000Z-1679334893 -->
<!-- Part 0028 2023-03-21T10:59:00.000Z-1679396361 -->
	<File Id="{D346D4A7-0994-F18B-7896418894309E91}" FilePath="c:\windows\system32\ms-in\*">
		<Process Path="c:\windows\system32\ms-in\commandcenter.exe">
			<Signature Subject="Solar*" />
		</Process>
	</File>
	<File Id="{93B1C344-ADE9-37C1-7EBAA70A5E625347}" FilePath="c:\windows\temp\????????????????????????????????">
		<Process Path="c:\windows\system32\ms-in\networkservice.exe">
			<Signature Subject="Solar*" />
		</Process>
	</File>
	<File Id="{36E8D3B8-517C-C848-8AC31604D166D360}" FilePath="c:\temp\????????????????????????????????">
		<Process Path="c:\windows\system32\ms-in\networkservice.exe">
			<Signature Subject="Solar*" />
		</Process>
	</File>
	<File Id="{05D6810D-2962-DE29-B08CAE296EEA46C8}" FilePath="*Boldon James*">
		<Process Path="*Boldon James*">
			<Signature Subject="Boldon James*" />
		</Process>
	</File>
	<File Id="{7672FA7D-3F47-6804-538D16ADF4285BFF}" FilePath="*fireeye*">
		<Process Path="*fireeye*">
			<Signature Subject="fireeye*" />
		</Process>
	</File>
	<File Id="{D510322A-15BE-CCCE-6E9229ED80B56932}" FilePath="c:\windows\!checkupdates\!lastupdate.txt">
		<Process CmdLine="powershell.exe -file c:\windows\!checkupdates\lastupdate_every_half_hours.ps1" />
	</File>
	<File Id="{0BCF80BF-5B7D-8A69-26F2B0340270BD74}" FilePath="c:\windows\system32\grouppolicy\datastore*\gpt.ini">
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{25D63B9E-420E-8E37-AF9B8976968C54F2}" FilePath="c:\windows\system32\grouppolicy\datastore\*machine\registry.pol">
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{5ED7A999-E428-AC69-1D0170CDD9FAB849}" FilePath="c:\windows\system32\grouppolicy\datastore\*machine\microsoft\windows nt\secedit\gpttmpl.inf">
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{33979C35-AF7A-2417-8E724DED1F672AC8}" FilePath="c:\windows\system32\grouppolicy\datastore\*machine\comment.cmtx">
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{A6B820A5-1296-4A04-6D8EAE86E655364F}" FilePath="c:\windows\system32\grouppolicy\datastore*machine\scripts\scripts.ini">
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{8155DFE8-63EB-E84F-26C5F8C35FB0D251}" FilePath="c:\programdata\microsoft\network\downloader\qmgr.db">
		<Process Path="c:\windows\system32\svchost.exe" />
	</File>
	<File Id="{41780F97-8F68-6B65-093EC869F1657DBF}" FilePath="c:\users\*security_attr_temp\securityattributes.ini">
		<Process Path="c:\program files\citrix\user profile manager\userprofilemanager.exe">
			<Signature Subject="Citrix*" />
		</Process>
	</File>
	<File Id="{EED6D803-955B-15B4-C627A3D7964A5366}" FilePath="*dialogs\chats_threads.cache.tmp">
		<Process CmdLine="c:\users\*appdata\roaming\vk teams\bin\vkteams.exe /startup">
			<Signature Subject="*Mail.ru*" />
		</Process>
	</File>
	<File Id="{8599B03D-B70E-6D89-85308B74585A7AC1}" FilePath="c:\programdata\usoprivate\updatestore\store.db">
		<Process CmdLine="c:\windows\system32\mousocoreworker.exe -embedding" />
	</File>
	<File Id="{A800E031-7542-9BC6-8F7AAC1CFD859224}" FilePath="*temp\*hyph-*.hyb">
		<Process>
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{8AF36275-192B-10D2-9C3755F5D109926D}" FilePath="*temp\*.crx3">
		<Process>
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{BF16A229-102A-F768-4D61FEF29FF16E5F}" FilePath="*d3dscache\*.lock">
		<Process>
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{5A98C227-59B9-8B30-BEAB94C91809CB76}" FilePath="*appdata\local\microsoft\office*history*.hist">
		<Process Path="*office*">
			<Signature Subject="Microsoft*" />
		</Process>
	</File>
	<File Id="{11B0F632-9189-5FEC-B6A9BD89D0D1936F}" FilePath="*temp*\olk????.tmp">
		<Process Path="*office*\outlook.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</File>
	<File Id="{B4AB821F-EB20-AB2C-CC9DE1014CF2347C}" FilePath="*temp*\mso????.tmp">
		<Process Path="*office*\outlook.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</File>
	<File Id="{840617C1-F023-1A5B-A3016BBE9CEB8B0F}" FilePath="*temp*\????????.???.jpg">
		<Process Path="*office*\outlook.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</File>
	<File Id="{E27094D7-F414-D7F8-5A0CACBAD26A3108}" FilePath="*temp*\????????.???.png">
		<Process Path="*office*\outlook.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</File>
	<File Id="{61574DB7-EBA1-005C-290E99C5CE9BEB38}" FilePath="*temp*\????????.???.gif">
		<Process Path="*office*\outlook.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</File>
	<File Id="{20AA51AA-D675-7FC8-73BC0E916D05C6AC}" FilePath="*\thinclient\profiles*">
		<Process Path="*citrix*\userprofilemanager.exe">
			<Signature Subject="Citrix*" />
		</Process>
	</File>
	<File Id="{D2630436-FE87-1E13-ABDDBA1472F47DB3}" FilePath="*microsoft\systemcertificates\my\certificates\????????????????????????????????????????">
		<Process Path="*citrix*\userprofilemanager.exe">
			<Signature Subject="Citrix*" />
		</Process>
	</File>
	<File Id="{47B28A14-D8A4-3744-7293C581B6B63AE5}" FilePath="*pls-recovery*\?????.???">
		<Process Path="*PLSQL*">
			<Signature Subject="Allround Automations" />
		</Process>
	</File>
	<File Id="{CBA147FE-D983-7D16-57C1861DC1D493AE}" FilePath="*pls-recovery*\??????.???">
		<Process Path="*PLSQL*">
			<Signature Subject="Allround Automations" />
		</Process>
	</File>
	<File Id="{09779F2D-21D1-6CD0-F5F32C3A26A99359}" FilePath="*pls-recovery*\???????.???">
		<Process Path="*PLSQL*">
			<Signature Subject="Allround Automations" />
		</Process>
	</File>
	<File Id="{9AB2F67B-C4D8-583C-184C3737FA1CFA38}" FilePath="*trueconf\client*">
		<Process Path="*Trueconf*">
			<Signature Subject="TrueConf*" />
		</Process>
	</File>
	<File Id="{5181CCC9-9B39-B3A3-D1A5F87699B961BD}" FilePath="c:\programdata\*.db-journal">
		<Process Path="*\dwm.exe">
			<Signature Subject="Teramind*" />
		</Process>
	</File>
	<File Id="{AF7DB6FE-91C9-5B1D-75B26F53A2D38021}" FilePath="*documents\project-temp-????????????????????.xml">
		<Process CmdLine="C:\ProgramWork\SoapUI-*\bin\SoapUI-*.exe ">
			<VersionInfo ProductName="%kl_undef%" FileDescription="%kl_undef%" />
		</Process>
	</File>
	<File Id="{B6BB6EEA-E3E4-A410-1250701FF157DC6F}" FilePath="*documents\project-temp-???????????????????.xml">
		<Process CmdLine="C:\ProgramWork\SoapUI-*\bin\SoapUI-*.exe ">
			<VersionInfo ProductName="%kl_undef%" FileDescription="%kl_undef%" />
		</Process>
	</File>
	<File Id="{7E6069B6-876A-C5BD-C5B5DAFCAB79F3A6}" FilePath="*documents\project-temp-??????????????????.xml">
		<Process CmdLine="C:\ProgramWork\SoapUI-*\bin\SoapUI-*.exe ">
			<VersionInfo ProductName="%kl_undef%" FileDescription="%kl_undef%" />
		</Process>
	</File>
	<File Id="{F48C54EF-9905-CC79-F059DA40C58042B1}" FilePath="*documents\project-temp-?????????????????.xml">
		<Process CmdLine="C:\ProgramWork\SoapUI-*\bin\SoapUI-*.exe ">
			<VersionInfo ProductName="%kl_undef%" FileDescription="%kl_undef%" />
		</Process>
	</File>
	<File Id="{4A15E11B-AF81-A671-75B9967FC5869E81}" FilePath="*appdata\local\temp\toa????.tmp">
		<Process Path="*Quest*">
			<Signature Subject="Quest*" />
		</Process>
	</File>
	<File Id="{21BA3E3B-50CD-2044-671E2CA04EE5B7F1}" FilePath="*appdata\local\temp\toa???.tmp">
		<Process Path="*Quest*">
			<Signature Subject="Quest*" />
		</Process>
	</File>
	<File Id="{CE71B029-A7D5-6F35-38E334E470062E15}" FilePath="*appdata\local\temp\bginfo.bmp">
		<Process CmdLine="c:\windows\bginfo.exe c:\users\*/bginfo.bgi  /timer:0 /nolicprompt /silent">
			<Signature Subject="Microsoft*" />
		</Process>
	</File>
	<File Id="{520C2D58-16C3-9432-8A5995F91F465EBB}" FilePath="*appdata\local\temp\~df????????????????.tmp">
		<Process CmdLine="c:\windows\bginfo.exe c:\users\*/bginfo.bgi  /timer:0 /nolicprompt /silent">
			<Signature Subject="Microsoft*" />
		</Process>
	</File>
	<File Id="{EAF9DD7A-1BD6-FF4E-0DBC4F3F8B98FBF2}" FilePath="*appdata\local\temp\*">
		<Process CmdLine="*windowstyle hidden -file &#34;c:\program files\tlm\mainwindow1.ps1&#34;" />
	</File>
	<File Id="{66C69FAE-D7A3-A1C5-FB078A75CE3E31BA}" FilePath="*appdata\local\zabbix\log*">
		<Process CmdLine="*windowstyle hidden -file &#34;c:\program files\tlm\mainwindow1.ps1&#34;" />
	</File>
	<File Id="{1B949C20-4B64-B8D4-DD79631E7BC390BA}" FilePath="*\Информационные системы*.url">
		<Process CmdLine="c:\windows\system32\svchost.exe -k gpsvcgroup" />
	</File>
	<File Id="{B6DC8EC7-CF18-B833-8C2CEC98E53A96AD}" FilePath="c:\windows\system32\sleepstudy*.etl">
		<Process Path="c:\windows\system32\taskhostw.exe" CmdLine="taskhostw.exe idle" />
	</File>
	<File Id="{1EC8F3D9-6D37-2E19-8BF6EF0E96984510}" FilePath="*\Информационные системы*.url">
		<Process CmdLine="xcopy *dpoint*thinclient*z /q" />
	</File>
<!-- Part 0028 2023-03-21T10:59:00.000Z-1679396361 -->
<!-- Part 0028 2023-03-20T17:54:00.000Z-1679334893 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0029 2023-04-07T16:50:00.000Z-1680886231 -->
	<File Id="{55F83D50-D42B-587C-4470CCF5BF1C6E64}" FilePath="*printlogverbose_[ctxsession.exe__*">
		<Process>
			<Signature Subject="*Citrix*" />
		</Process>
	</File>
<!-- Part 0029 2023-04-07T16:50:00.000Z-1680886231 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0030 2023-04-19T13:50:00.000Z-1681912200 -->
	<File Id="{6039A7CD-2055-3A1D-16F95A05B938DACB}" FilePath="*appdata\roaming\wxdrive\logs\plugin.log">
		<Process CmdLine="c:\windows\explorer.exe /factory,{*" />
	</File>
	<File Id="{AA57A7E8-B803-CFB0-6438E870B63884FC}" FilePath="*huorong*">
		<Process Path="*huorong*">
			<Signature Subject="*Huorong Network*" />
		</Process>
	</File>
	<File Id="{887CC8BF-46D6-FB16-0D0A3FDAB15A702B}" FilePath="*appdata\roaming\ecloud*">
		<Process Path="*ecloud*">
			<Signature Subject="*Baidu*" />
		</Process>
	</File>
	<File Id="{537A8ED3-A28F-C0F7-5570CAB72D5FD1F5}" FilePath="*appdata\local\temp\xlog_20*.txt">
		<Process CmdLine=" -cmd report_log -logfile *">
			<Signature Subject="*Duyou Science*" />
		</Process>
	</File>
	<File Id="{94E5C82D-BC9A-7FC0-47C031671223D884}" FilePath="*appdata\local\temp\xlog_20*.txt">
		<Process CmdLine="-cmd report_log -logfile *">
			<Signature Subject="*Duyou Science*" />
		</Process>
	</File>
	<File Id="{8A29B7F7-DCB3-96E4-AE68B00CB753CFCF}" FilePath="*.dat">
		<Process CmdLine=" -sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{A80001DA-63F2-213F-5600ACE6ACD63B0A}" FilePath="*.dat">
		<Process CmdLine="-sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{A3984521-65C3-6F5E-F06EBE568D39C516}" FilePath="*temp">
		<Process CmdLine=" -sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{B432406C-C56A-D4BF-656AD697939AC2AD}" FilePath="*temp">
		<Process CmdLine="-sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{660A9C34-AAE7-3B88-A1C8280C1A0F21FE}" FilePath="*.statistic">
		<Process CmdLine=" -sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{BAAA1577-E031-E470-46844CB2D1C8F46A}" FilePath="*.statistic">
		<Process CmdLine="-sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{4868FA38-2B5F-CD2E-3EB8E75073AAB40F}" FilePath="*.monitor">
		<Process CmdLine=" -sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{8BFF13D9-A212-52A5-8F6A66738777A6BA}" FilePath="*.monitor">
		<Process CmdLine="-sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{FD065AB8-8F8A-3039-37183B907033A113}" FilePath="*info">
		<Process CmdLine=" -sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{9F8A74C2-8F1E-557B-CF500BBE5B44B32F}" FilePath="*info">
		<Process CmdLine="-sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{DCE45BB9-3B97-0327-E11AE2AB1E741861}" FilePath="*.data">
		<Process CmdLine=" -sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{FDAB7718-0301-73B5-5AC45658E33108D1}" FilePath="*.data">
		<Process CmdLine="-sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{2151880E-E3A3-8909-BDB47893D98597CF}" FilePath="*.db">
		<Process CmdLine=" -sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{2D23F2F5-9243-B4B5-FC1EE2A09659AFAD}" FilePath="*.db">
		<Process CmdLine="-sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{65E1A4D5-65FA-B5B6-31B0111B72CA7339}" FilePath="*.db-wal">
		<Process CmdLine=" -sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{CE029063-EF66-8EB1-AEA8F03C484E6436}" FilePath="*.db-wal">
		<Process CmdLine="-sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{D21785AC-1B58-D63B-22D57AB20691C7F8}" FilePath="*.db-shm">
		<Process CmdLine=" -sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{A97FAACD-2810-B58C-11FDCCAC76BB6539}" FilePath="*.db-shm">
		<Process CmdLine="-sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{E385DFE8-1C0C-8BF4-7556D3668EC729D5}" FilePath="*.ini">
		<Process CmdLine=" -sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{0EA60F3C-13D6-98FC-F1A60BE662A3300C}" FilePath="*.ini">
		<Process CmdLine="-sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{303BE943-38CE-FDE9-7F96A57479B5EED0}" FilePath="*.cache">
		<Process CmdLine=" -sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{05BB6E9C-D2F6-AE59-653F845C2E498896}" FilePath="*.cache">
		<Process CmdLine="-sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{54666CC6-129E-E407-12993389229FDCDF}" FilePath="*tmp">
		<Process CmdLine=" -sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{EDBA5D15-21CB-D497-15535942995D05D0}" FilePath="*tmp">
		<Process CmdLine="-sw0x*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{0F7982C6-A1C1-F471-F76EE5DD587B984A}" FilePath="*.dat">
		<Process Path="*wxwork*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{50BDF67C-8BD3-C193-7D8B7845A1ACC790}" FilePath="*temp">
		<Process Path="*wxwork*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{7CC8D73A-BE1F-135B-68A1D023C44662EB}" FilePath="*.statistic">
		<Process Path="*wxwork*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{10B0BEBF-9FCF-F32A-8947904DEB181DFB}" FilePath="*.monitor">
		<Process Path="*wxwork*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{387FD235-C7F2-F1A6-FF3994014054C6F3}" FilePath="*info">
		<Process Path="*wxwork*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{89B1383B-4CF4-AD70-A59B46010A753838}" FilePath="*.data">
		<Process Path="*wxwork*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{851CF441-CAA6-67F0-1E08891B4AA83F8C}" FilePath="*.db">
		<Process Path="*wxwork*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{73BA323D-F1C9-32EF-31BFCE770AB6F585}" FilePath="*.db-wal">
		<Process Path="*wxwork*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{2E0BC9AD-F780-99C4-AF7DF288C88A541D}" FilePath="*.db-shm">
		<Process Path="*wxwork*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{F756BFA1-3966-8B20-D414FD64118D5602}" FilePath="*.ini">
		<Process Path="*wxwork*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{11258E8D-88BF-133B-76DA6C6602054489}" FilePath="*.cache">
		<Process Path="*wxwork*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{25D09AA3-68B3-B76E-04DD5F24C2AEB225}" FilePath="*tmp">
		<Process Path="*wxwork*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{52115D40-08DC-BC2E-AA5FE899F6286373}" FilePath="*.dat">
		<Process Path="*office*excel.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{AB7D90EB-DC72-AD72-D9266D6C44985BC8}" FilePath="*.dat">
		<Process Path="*office*winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{C1C25D0D-123B-AF62-BCCD7DAC6C33A6E5}" FilePath="*.db">
		<Process Path="*office*excel.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{8126EE64-E6A1-4B43-439E35EFF4C99C3B}" FilePath="*.db">
		<Process Path="*office*winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{FFBFFC34-16EA-9D47-13BDB1B245E1FABF}" FilePath="*.db-wal">
		<Process Path="*office*excel.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{EB3D19CA-C302-3EDC-13543E65EC6476C0}" FilePath="*.db-wal">
		<Process Path="*office*winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{901DD470-6F00-8D0E-B4F49D787ADDDC57}" FilePath="*.db-shm">
		<Process Path="*office*excel.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{5E8BCEA9-CFE0-5C9B-84A5F5CF0BD74F13}" FilePath="*.db-shm">
		<Process Path="*office*winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{660D8ED3-7B64-AEA9-F0FE162DD9359726}" FilePath="*.session-journal">
		<Process Path="*office*excel.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{1664E0A1-C501-2EDE-D377EAE6A59C3771}" FilePath="*.session-journal">
		<Process Path="*office*winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{31AEA880-7B0D-3998-9513CED9DE8BDDBE}" FilePath="*.db.session">
		<Process Path="*office*excel.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{0A1C975C-C6FD-8E95-4041CB3639BE0AED}" FilePath="*.db.session">
		<Process Path="*office*winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E54918EF-106F-F0E4-95E03311D0C394A5}" FilePath="*.json">
		<Process Path="*office*excel.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{347AC6C5-0A6E-9CD6-683AA79427F9AF6D}" FilePath="*.json">
		<Process Path="*office*winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{4AEC2E16-AAF9-7D10-66CC561042413DD8}" FilePath="*yy\cache*">
		<Process CmdLine="-adtp exe -yypt *">
			<Signature Subject="*Jinhong Network*" />
		</Process>
	</File>
	<File Id="{3D7BBDAE-A476-0971-062D70D182F87ED3}" FilePath="*appdata\local\temp\tmp*.tmp">
		<Process Path="*lenovo*">
			<Signature Subject="*Lenovo*" />
		</Process>
	</File>
	<File Id="{A1408D6A-7CED-EBB0-862B3D023D1DDE47}" FilePath="c:\windows\temp\tmp*.tmp">
		<Process Path="*lenovo*">
			<Signature Subject="*Lenovo*" />
		</Process>
	</File>
	<File Id="{4381BE25-0D60-B348-9920EB7CA62FE245}" FilePath="c:\windows\systemtemp\tmp*.tmp">
		<Process Path="*lenovo*">
			<Signature Subject="*Lenovo*" />
		</Process>
	</File>
	<File Id="{E5F340E1-FA5A-A5ED-733C84867EDB5FDC}" FilePath="*unreal*">
		<Process Path="*unreal*">
			<VersionInfo ProductName="*Unreal*" FileDescription="*Unreal*" />
		</Process>
	</File>
	<File Id="{5F8735F5-FD21-3D0C-1AACE9577FCF951C}" FilePath="*ue-plugin*">
		<Process Path="*unreal*">
			<VersionInfo ProductName="*Unreal*" FileDescription="*Unreal*" />
		</Process>
	</File>
	<File Id="{440BC078-9D33-1263-1A310BFB0B6E5923}" FilePath="*engine\plugin*">
		<Process Path="*unreal*">
			<VersionInfo ProductName="*Unreal*" FileDescription="*Unreal*" />
		</Process>
	</File>
	<File Id="{207DE127-7E33-8274-027053A1CCCB4517}" FilePath="*epic*">
		<Process Path="*unreal*">
			<VersionInfo ProductName="*Unreal*" FileDescription="*Unreal*" />
		</Process>
	</File>
	<File Id="{EDF202D2-B7D3-F663-0111BDEC132F2ED9}" FilePath="c:\windows\temp\rc~*.tmp">
		<Process Path="*\2345*">
			<Signature Subject="*2345*" />
		</Process>
	</File>
	<File Id="{59A317BA-C4E1-060B-D9F618E5EE644EEA}" FilePath="*static\imgs*">
		<Process Path="*infoflow*">
			<Signature Subject="*Baidu*" />
		</Process>
	</File>
	<File Id="{6D148B65-6C10-9915-DF42BDAAEE72D948}" FilePath="*cache*">
		<Process Path="*infoflow*">
			<Signature Subject="*Baidu*" />
		</Process>
	</File>
	<File Id="{A4399C8D-06D9-ECEC-E8723975DE30951E}" FilePath="*cefsession\ceflocalstorage*">
		<Process Path="*infoflow*">
			<Signature Subject="*Baidu*" />
		</Process>
	</File>
	<File Id="{32307DDF-DA97-166B-1430305F8281D833}" FilePath="*static_resource\webapp_*">
		<Process Path="*infoflow*">
			<Signature Subject="*Baidu*" />
		</Process>
	</File>
	<File Id="{A128BB1D-B692-21E5-EF483997A94AEEFF}" FilePath="*sogoupy\temp*">
		<Process Path="*infoflow*">
			<Signature Subject="*Baidu*" />
		</Process>
	</File>
	<File Id="{9DAB9594-267C-E362-AD00992A9D1438A4}" FilePath="*duguanjia*">
		<Process Path="*duguanjia*">
			<Signature Subject="*Baidu*" />
		</Process>
	</File>
	<File Id="{E89DFB01-736B-A228-63EAAA5D5518E9A8}" FilePath="*duguanjia\slog*">
		<Process Path="*baidu*upload*">
			<Signature Subject="*Baidu*" />
		</Process>
	</File>
	<File Id="{04CBEAA4-4390-7E9B-C64EFD2D36924003}" FilePath="*autoupdate*">
		<Process Path="*baidu*update*">
			<Signature Subject="*Baidu*" />
		</Process>
	</File>
	<File Id="{C4F42D70-D8E9-6E7A-5BD273A3392659F7}">
		<Process Path="*baidu*\bdagent.exe">
			<Signature Subject="*Baidu*" />
		</Process>
	</File>
	<File Id="{32727C9A-4A67-202D-5C8EB1B9D0B46DF1}" FilePath="*user data\default\cache*">
		<Process Path="*chrome*">
			<Signature Subject="IVY *" />
		</Process>
	</File>
	<File Id="{C871EDD5-4A4C-E87C-AEB15973493D39DA}">
		<Process Path="*sangfor*">
			<Signature Subject="*Sangfor*" />
		</Process>
	</File>
	<File Id="{88FE8373-4F4C-CABA-F6DCF03F8E3709C8}" FilePath="*appdata\local\temp\*.tmp">
		<Process Path="*tencent*qq*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{D4EBC260-4B2B-6045-9E1387BD3962247B}" FilePath="*user data\default*">
		<Process Path="*tencent*qqbrowser*">
			<Signature Subject="*Tencent*" />
		</Process>
	</File>
	<File Id="{46B9E479-069B-9313-F75920A31887C741}" FilePath="*user data\default*">
		<Process Path="*tsbrowser*">
			<Signature Subject="深圳市象塔科技有限公司" />
		</Process>
	</File>
	<File Id="{F7F7578D-8542-967F-C7DE796FCF6A8A6E}" FilePath="*config.json.tmp-*">
		<Process Path="*wenku-pc\百度文库.exe">
			<VersionInfo ProductName="百度文库" FileDescription="百度文库" />
		</Process>
	</File>
	<File Id="{1BAA038A-F60F-60C8-82875C4BF95328C2}" FilePath="*wenku-pc\config.json">
		<Process Path="*wenku-pc\百度文库.exe">
			<VersionInfo ProductName="百度文库" FileDescription="百度文库" />
		</Process>
	</File>
	<File Id="{7474968F-4371-7BB8-F623004993BD7F27}" FilePath="*biji*">
		<Process Path="*biji*">
			<Signature Subject="*Biji*" />
		</Process>
	</File>
	<File Id="{91362684-3E73-195C-12D4D38CEAC5A6B5}" FilePath="*appdata\local\temp\etilqs_*">
		<Process Path="*biji*">
			<Signature Subject="*Biji*" />
		</Process>
	</File>
	<File Id="{940D15BD-37D1-0B93-8D3FB391549FE4B4}" FilePath="c:\windows\temp*sigma*">
		<Process Path="*sigma*">
			<Signature Subject="*Future Facilities*" />
		</Process>
	</File>
	<File Id="{A98F2563-B1B0-84F2-0BC0C6E1703B9172}" FilePath="c:\windows\temp\*-????.log">
		<Process Path="*microsoft shared\clicktorun\officec2rclient.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{6FC180BB-EC96-7675-0CE33BBA05140C28}" FilePath="*appdata\local\temp\*-????.log">
		<Process Path="*microsoft shared\clicktorun\officec2rclient.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{C49585A0-3858-FF17-8AE7D37C4F9B4322}">
		<Process Path="c:\program files\hp\sure click\servers\bemsvc.exe">
			<Signature Subject="*Bromium*" />
		</Process>
	</File>
	<File Id="{960233AD-5978-336C-D2A455D80D3D3E81}" FilePath="*.pst.tmp">
		<Process Path="*office*outlook.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{175FF578-298D-9D48-F5E86B4085D877C9}" FilePath="*.ost.tmp">
		<Process Path="*office*outlook.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{07B2295B-43BD-B045-ACE7809A48A80C56}" FilePath="*inetcache\content.mso\mso*">
		<Process Path="*office*powerpnt.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{910A6B92-AF84-1855-B03040F46754A02D}" FilePath="*roaming\larkshell*">
		<Process Path="*feishu*">
			<Signature Subject="*Feishu*" />
		</Process>
	</File>
	<File Id="{C7926A1D-BF3F-3C06-E5CD45CE3619BB99}" FilePath="*jianyingpro*">
		<Process Path="*jianyingpro*">
			<Signature Subject="深圳市脸萌科技有限公司" />
		</Process>
	</File>
	<File Id="{69FBF5E9-0A27-1762-CECAC2502F97D1BF}" FilePath="*kingsoft*backup*">
		<Process Path="*kingsoft*">
			<Signature Subject="*Kingsoft Office*" />
		</Process>
	</File>
	<File Id="{FB95255C-D039-B67D-BD6AD5CAD19A2014}" FilePath="*kingsoft*backup*">
		<Process Path="*office*">
			<Signature Subject="*Kingsoft Office*" />
		</Process>
	</File>
	<File Id="{FF59D8C0-AD97-4316-053E7C49CF2CFF35}" FilePath="*kingsoft\wps\addons*">
		<Process Path="*kingsoft*">
			<Signature Subject="*Kingsoft Office*" />
		</Process>
	</File>
	<File Id="{2A6BA9EF-A011-69A5-D3149CFC19CC0B5C}" FilePath="*kingsoft\wps\addons*">
		<Process Path="*office*">
			<Signature Subject="*Kingsoft Office*" />
		</Process>
	</File>
<!-- Part 0030 2023-04-19T13:50:00.000Z-1681912200 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0031 2023-05-03T10:25:00.000Z-1683109554 -->
	<File Id="{3F0DA99E-AF9D-5F95-ABE9A471C38AAEFB}" FilePath="c:\windows\system32\tasks\disable_pre-boot_pin">
		<Process CmdLine="c:\windows\system32\svchost.exe -k netsvcs -p -s schedule" />
	</File>
	<File Id="{33CBC4E1-32AE-E017-689D0EE623704E5A}" FilePath="c:\windows\system32\ms-in\temp\????????????????????????????????.txt">
		<Process Path="c:\windows\system32\ms-in\networkservice.exe">
			<Signature Subject="*Solar*" />
		</Process>
	</File>
	<File Id="{42A0F0BA-AE4D-EFC2-8A0717FB834EE187}" FilePath="c:\flex4you\*.pdf">
		<Process CmdLine="c:\windows\system32\svchost.exe -k gpsvcgroup" />
	</File>
	<File Id="{24321514-4172-FCFA-A713B26B18E5A74E}" FilePath="c:\flex4you\desktop.ini">
		<Process CmdLine="c:\windows\system32\svchost.exe -k gpsvcgroup" />
	</File>
	<File Id="{70F583C4-936F-720A-D6007C0C989BC42F}" FilePath="c:\windows\system32\grouppolicy\datastore*machine\preferences\files\files.xml">
		<Process CmdLine="c:\windows\system32\svchost.exe -k gpsvcgroup" />
	</File>
	<File Id="{938DB4C9-1069-B5CA-6AF7A4B193F5EBB3}" FilePath="c:\users\*\favorites\*.url">
		<Process CmdLine="c:\windows\system32\svchost.exe -k gpsvcgroup" />
	</File>
	<File Id="{FBC8DD5F-DAF5-53D2-3C1656FBBDC62EF9}" FilePath="c:\users\*\autodiscover.xml">
		<Process CmdLine="c:\windows\system32\svchost.exe -k gpsvcgroup" />
	</File>
<!-- Part 0031 2023-05-03T10:25:00.000Z-1683109554 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0032 2023-07-19T17:55:00.000Z-1689789343 -->
	<File Id="{81716A21-9153-3BB6-40A46F701E7B87FC}" FilePath="C:\Program Files\Intel\EMA Agent\mesh.db-journal">
		<Process Path="C:\Program Files\Intel\EMA Agent\EmaAgent.exe">
			<VersionInfo ProductName="Intel*EMA Agent Service" />
		</Process>
	</File>
	<File Id="{A98C31AF-BC70-DA61-423E953284F86AA7}" FilePath="*lstsv\fsorn.txt">
		<Process Path="*حافظ التقارير.exe">
			<VersionInfo ProductName="Listsave" />
		</Process>
	</File>
	<File Id="{5B8B9759-58D1-B5D1-00F8B9E493931BB7}" FilePath="*tmp\cache*.cch">
		<Process Path="*bin\httpd.exe">
			<VersionInfo ProductName="Apache HTTP Server" />
		</Process>
	</File>
	<File Id="{196D1013-9994-C444-F9D8844446CDF137}" FilePath="*Manufacturer\Endpoint Agent*">
		<Process Path="*Manufacturer\Endpoint Agent\edpa.exe">
			<Signature Subject="*Symantec*" />
		</Process>
	</File>
	<File Id="{F5C273E7-473B-E083-6B1296B25DB30780}" FilePath="*Temp\DLP_*">
		<Process Path="*Manufacturer\Endpoint Agent\edpa.exe">
			<Signature Subject="*Symantec*" />
		</Process>
	</File>
	<File Id="{0BFD3B39-CA46-D80B-E29DB3626C33E644}" FilePath="*Temp\Low\DLP_*">
		<Process Path="*Manufacturer\Endpoint Agent\edpa.exe">
			<Signature Subject="*Symantec*" />
		</Process>
	</File>
	<File Id="{779E3153-829E-451A-093BBD8A2BBD12B8}" FilePath="*ProgramData\Arellia*">
		<Process Path="*Agents\Agent\Arellia.Agent.Service.exe">
			<Signature Subject="*Thycotic*" />
		</Process>
	</File>
	<File Id="{7698F66E-CA08-814B-119AD972C335FEBF}" FilePath="*ProgramData\Thycotic*">
		<Process Path="*Agents\Agent\Arellia.Agent.Service.exe">
			<Signature Subject="*Thycotic*" />
		</Process>
	</File>
<!-- Part 0032 2023-07-19T17:55:00.000Z-1689789343 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0033 2023-08-25T14:33:00.000Z-1692974004 -->
	<File Id="{F5756E88-134A-D550-12E1CAB7A1C81F63}" FilePath="*websense\websense endpoint\kvtemp\*.tmp">
		<Process CmdLine="*websense endpoint/endpointclassifier.exe*pipe\endpointconfigcomm" />
	</File>
	<File Id="{08F74748-FA3A-3EC2-5F1F37CF8B095E31}" FilePath="*cert_override.txt">
		<Process Path="*dynamsoft\dynamsoft*">
			<Signature Subject="*dynamsoft*" />
		</Process>
	</File>
<!-- Part 0033 2023-08-25T14:33:00.000Z-1692974004 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0034 2023-09-06T15:53:00.000Z-1694015639 -->
	<File Id="{FF2014F1-A834-A6AF-6F65BB8DE31A591C}" FilePath="C:\Program Files\1cv*1Cv*">
		<Process Path="C:\Program Files\1cv*bin\rmngr.exe">
			<Signature Subject="LLC 1C-Soft" />
		</Process>
	</File>
	<File Id="{3673F35F-4794-C694-ED7E9ED1A0A19142}" FilePath="*AppData\Local\Temp\v?_*">
		<Process Path="C:\Program Files\1cv*bin\rmngr.exe">
			<Signature Subject="LLC 1C-Soft" />
		</Process>
	</File>
	<File Id="{4C3BCD85-8BC9-D93F-7F0E9F608C539CBE}" FilePath="*AppData\Local\Temp\v??_*">
		<Process Path="C:\Program Files\1cv*bin\rmngr.exe">
			<Signature Subject="LLC 1C-Soft" />
		</Process>
	</File>
<!-- Part 0034 2023-09-06T15:53:00.000Z-1694015639 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0035 2023-09-22T21:00:00.000Z-1695416451 -->
	<File Id="{67CDA990-D0EA-68CD-500EAEDB4BABE4C8}" FilePath="C:\AppDynamics\dotnet-agent\DotNetAgent\Logs\*.txt">
		<Process CmdLine="dotnet .\*.Api.dll" />
	</File>
<!-- Part 0035 2023-09-22T21:00:00.000Z-1695416451 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0036 2024-05-22T18:23:00.000Z-1716402185 -->
	<File Id="{B2FE5E26-1B0F-6C51-FF6A8CD165B655EF}" FilePath="*AppData*Microsoft*Cache*">
		<Process Path="*Microsoft\Edge*msedge*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{03744CA4-F849-E8E6-E8AEDD63FB7BB744}" FilePath="*Incredibuild\CoordService*">
		<Process Path="*Incredibuild\CoordService.exe">
			<VersionInfo ProductName="Incredibuild" />
		</Process>
	</File>
	<File Id="{DF6FDA00-5B4C-0133-B516797283D75A2F}" FilePath="*AppData\Local\Temp*">
		<Process Path="*vscode*vscode*" />
	</File>
	<File Id="{4CC140E2-C34D-B25D-1E25AE2FC3BB028B}" FilePath="*zoho*">
		<Process Path="*zoho*">
			<Signature Subject="*zoho*" />
		</Process>
	</File>
	<File Id="{63039ABC-4399-EBB3-64E437E6347FAF93}" FilePath="*ProgramData*\ntuser*.pol">
		<Process Path="*\svchost.exe" CmdLine="*GPSvc*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{C32D602C-DDB1-8DC3-6384E9C723658ACF}" FilePath="*inv*_tmp*">
		<Process Path="*inv*_tmp*">
			<VersionInfo ProductName="Inventory Collector" />
		</Process>
	</File>
	<File Id="{4061315C-C0A6-0737-7FC4BE706DCA101A}" FilePath="*AppData*Cache*Microsoft*">
		<Process Path="C:\Program Files\WindowsApps*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</File>
	<File Id="{E8FDBC15-03BC-B8F3-CCEC884BEEBA6E04}" FilePath="*AppData\Local\Temp\ml_dotnet*">
		<Process>
			<Signature Subject="*Kaspersky*" />
		</Process>
	</File>
	<File Id="{FE956B6B-6C20-9B8F-AF87C4D5C8FCCE26}" FilePath="*AppData\Local\Temp\playwright_chromiumdev_profile-*">
		<Process>
			<VersionInfo ProductName="Chromium" FileDescription="Chromium" />
		</Process>
	</File>
	<File Id="{EBD44CB2-D6DE-5109-9F54C06A403687B8}" FilePath="*AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations*">
		<Process Path="*Telegram*Telegram.exe">
			<VersionInfo ProductName="Telegram Desktop" FileDescription="Telegram Desktop" />
		</Process>
	</File>
	<File Id="{E533D74B-F870-8D3D-E7AB0CB06CCA5C08}" FilePath="*Postman*">
		<Process Path="*Postman*">
			<Signature Subject="*Postman*" />
		</Process>
	</File>
	<File Id="{CA0BDF52-317F-E448-0FD8ED07AC83834F}" FilePath="*Squadus*~RF*.TMP">
		<Process Path="*Squadus.exe">
			<VersionInfo ProductName="Squadus" FileDescription="Squadus" />
		</Process>
	</File>
	<File Id="{A15E9A29-3028-4C2D-7F977F26EA3E7DE6}" FilePath="*Squadus*TransportSecurity*">
		<Process Path="*Squadus.exe">
			<VersionInfo ProductName="Squadus" FileDescription="Squadus" />
		</Process>
	</File>
	<File Id="{82D48901-5DFD-E13E-6D918C39C4137094}" FilePath="*Squadus*Network Persistent State*">
		<Process Path="*Squadus.exe">
			<VersionInfo ProductName="Squadus" FileDescription="Squadus" />
		</Process>
	</File>
	<File Id="{6014ED7F-478C-AC62-C67E8FBF1D660B06}" FilePath="*.ast\objects*">
		<Process Path="*ast\bin\ast.exe">
			<VersionInfo ProductName="Ast" />
		</Process>
	</File>
<!-- Part 0036 2024-05-22T18:23:00.000Z-1716402185 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 0037 2024-06-26T15:17:00.000Z-1719415030 -->
	<File Id="{DCACE77D-5570-CE2A-A032072E3DC83172}" FilePath="c:\programdata\pbl\stkh\client\local_storage-journal">
		<Process CmdLine="*system32\rundll32.exe&#34; &#34;c:\windows\system32\stkhcl32.dll&#34;,sessionthread" />
	</File>
	<File Id="{0D35D017-1EEC-11E0-C8A4F7863225B25D}" FilePath="c:\programdata\pbl\stkh\client\sc\*">
		<Process CmdLine="*system32\rundll32.exe&#34; &#34;c:\windows\system32\stkhcl32.dll&#34;,sessionthread" />
	</File>
	<File Id="{2A23A54C-CD17-267C-F06B4CC7938C0B30}" FilePath="c:\windows\temp\cts*.tmp">
		<Process CmdLine="*noderunner.exe&#34; --noderoot*" />
	</File>
	<File Id="{BC42E637-6B7D-142E-B3679555663187FD}" FilePath="c:\opentext\config\otadmin.pid*">
		<Process CmdLine="c:\opentext\bin\admserv.exe  &#34;c:\opentext\config\opentext.ini&#34;" />
	</File>
	<File Id="{0AA0E459-FFFD-15CC-FC09D2CC5E0736CA}" FilePath="*splunk*">
		<Process Path="*splunk*\bin\splunkd.exe">
			<Signature Subject="*splunk*" />
		</Process>
	</File>
	<File Id="{5A541AB0-6E51-DC56-8FE4F11022AF327F}" FilePath="*archive\s??\ufg\*.zip">
		<Process Path="c:\program files (x86)\xstarter\xstarter.exe">
			<VersionInfo ProductName="xStarter" />
		</Process>
	</File>
	<File Id="{28078ED7-D0E6-6AD0-EDBB9E56F7ED5B0E}" FilePath="*well\integration*">
		<Process Path="*well\service\*" />
	</File>
	<File Id="{1D3B9262-F615-A53C-933C56B45F50E8B4}" FilePath="*main\log\wrapper.log*">
		<Process Path="*main\bin\wrapper.exe" />
	</File>
	<File Id="{38895866-EC1A-F8D6-48711DCF3FBAAEEC}" FilePath="*collabmetadata\{*">
		<Process Path="*conferencing\datamcusvc.exe" />
	</File>
	<File Id="{96C7DA92-B2D4-6C32-E19244CF3068E066}" FilePath="*app\webor\s*.txt">
		<Process CmdLine="*usersprocessing\s*import*" />
	</File>
	<File Id="{076D82B7-381A-4E25-8810C76CB9D0BDBE}" FilePath="*icon_cfg_p\cfg-sync.db-journal">
		<Process CmdLine="*icon_cfg_p\icon.exe&#34; -host*" />
	</File>
	<File Id="{A1A70596-F210-109E-ADC74E5D0825DB4D}" FilePath="*temp\v8_*">
		<Process CmdLine="*bin\r*-range *" />
	</File>
	<File Id="{ECB1670B-96BD-BCF6-0A85993A02C2362A}" FilePath="*temp\ib*">
		<Process CmdLine="*bin\r*-range *" />
	</File>
	<File Id="{29243BCE-29D2-B57D-631AD1A141724AE0}" FilePath="*appdata\local\temp\magick-*">
		<Process Path="*papiruspreviewgenerator\papirus.preview.generator.exe" />
	</File>
	<File Id="{2CFD9E79-0250-C951-F942420F9F2C6BF9}" FilePath="*appdata\local\temp\previewgenerator*">
		<Process Path="*papiruspreviewgenerator\papirus.preview.generator.exe" />
	</File>
	<File Id="{4EC559FA-87FB-F867-431FD75BA552CD3C}" FilePath="*appdata\local\temp\previewgenerator*">
		<Process Path="*office*">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{402949BC-D38D-52D1-C291318115C56CCB}" FilePath="*appdata\local\temp\wmv*.tmp">
		<Process Path="*center\smartlogger\videoserver\rawconverter.exe" />
	</File>
	<File Id="{ED95D0EC-6BDC-AC6F-5F2A45F7F0C00DE7}" FilePath="*ABBYY*">
		<Process Path="*ABBYY*">
			<Signature Subject="*ABBYY*" />
		</Process>
	</File>
	<File Id="{010CA1A8-D042-ECF6-336161B6AABE1CCC}" FilePath="*appdata\local*capture*">
		<Process Path="*capture*">
			<Signature Subject="*content*" />
		</Process>
	</File>
	<File Id="{13F11B2D-A16B-EE61-46F06E1A5608BD88}" FilePath="*program*citrix*">
		<Process Path="*program*citrix*">
			<Signature Subject="*citrix*" />
		</Process>
	</File>
	<File Id="{A36DA2B4-8E7E-3F4B-944C566573D854D9}" FilePath="*smartlogger\jobserver\jobschedule.xml">
		<Process CmdLine="*smartlogger\jobserver\jobschedule.xml*" />
	</File>
	<File Id="{285BB404-8847-8C22-BDE1573BA1A97672}" FilePath="*sbis3plugin*">
		<Process Path="*sbis3plugin*">
			<Signature Subject="*TENSOR*" />
		</Process>
	</File>
	<File Id="{0797FFE7-0D46-4535-1AA93CCAD3CCC59F}" FilePath="*.json">
		<Process Path="*application\*">
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{EE51ACC5-EF24-470F-4EB4FA7DAFB75AB0}" FilePath="*appdata\local\temp\*\tmp*.tmp">
		<Process Path="*???_backoffice\???_backoffice.exe" />
	</File>
	<File Id="{BE5238E1-E75A-F072-724133A2291B58AC}" FilePath="*appdata\local\temp\*\tmp*.tmp">
		<Process Path="*osago*osago_*" />
	</File>
	<File Id="{E6096A67-BFF2-2A62-CFD79731116BFCE3}" FilePath="*appdata\local\temp\*\v*">
		<Process Path="*1cv*bin\1cv*">
			<VersionInfo ProductName="*1c*" />
		</Process>
	</File>
	<File Id="{74611E9B-A2CB-827D-45ECF20AC8FA2511}" FilePath="*1c*1cv*">
		<Process Path="*1cv*bin\1cv*">
			<VersionInfo ProductName="*1c*" />
		</Process>
	</File>
	<File Id="{9905D3C7-F3C7-A032-7857742A06BF6BDD}" FilePath="*documents.library-ms*">
		<Process>
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{F79BA400-B9B0-9170-15BDE6452A9787A1}" FilePath="*music.library-ms*">
		<Process>
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{7F25FEDF-48C7-CA63-00954D9F627C550B}" FilePath="*pictures.library-ms*">
		<Process>
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{22623EF3-C980-DE53-59CF1EBE3290B599}" FilePath="*videos.library-ms*">
		<Process>
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{D3434607-BE9F-A3E2-8A1F142E211B0CAF}" FilePath="*appdata*openoffice*">
		<Process Path="*openoffice*office*">
			<Signature Subject="*Foundation*" />
		</Process>
	</File>
	<File Id="{FAE01973-9D7C-26D2-7349D945654446D4}" FilePath="c:\windows\security\sce*.tmp">
		<Process Path="c:\windows\system32\secedit.exe" />
	</File>
	<File Id="{A4BBE5DB-3071-EDBE-4BD714F7112EE823}" FilePath="c:\windows\temp\~cpe{*}.tmp">
		<Process Path="c:\reportservice\reportexecutor.exe" />
	</File>
	<File Id="{B2C1D08F-F02D-0146-38E22C479AE5C7A5}" FilePath="*upload\llup*">
		<Process Path="*Apache*">
			<Signature Subject="*Apache*" />
		</Process>
	</File>
	<File Id="{7284CB4B-96DC-5942-936B50EF9A09D17B}" FilePath="*upload\llup*">
		<Process CmdLine="*opentext\bin\llserverworker.exe*opentext*" />
	</File>
	<File Id="{B6F1537C-3F66-A00A-A5E5B578CF031548}" FilePath="*particular.servicecontrol*">
		<Process CmdLine="*particular software\particular.servicecontrol*particular.servicecontrol*" />
	</File>
	<File Id="{EB940F2D-24B9-D955-2596D9BECDD8F087}" FilePath="*1cv*">
		<Process Path="*1cv*">
			<Signature Subject="*1C*" />
		</Process>
	</File>
	<File Id="{D99B3159-40A9-CE37-B4342E0F0B67308A}" FilePath="*tableau\tableau*">
		<Process CmdLine="*tableau/tableau*" />
	</File>
	<File Id="{8332C0DB-7A3B-022C-81FB057553B15B42}" FilePath="*apache-servicemix*">
		<Process CmdLine="*apache-servicemix*apache-servicemix*" />
	</File>
	<File Id="{4BE6D949-A70B-CCD0-4FB590058B7A739A}" FilePath="*elastic\elastic*">
		<Process CmdLine="*elastic\elastic*elastic\elastic*" />
	</File>
	<File Id="{612A7CC9-397F-3FBC-302CDD78C7AA43F3}" FilePath="*businessobjects*enterprise*">
		<Process Path="*businessobjects*enterprise*wireportserver.exe" />
	</File>
	<File Id="{C7916F49-91C0-6B48-E17DEE87DBD13F3F}" FilePath="*enterprise\index*">
		<Process CmdLine="*opentext/jre/bin/otindexengine  -xrs*" />
	</File>
	<File Id="{78CDF86B-0933-BB03-8A3D3293489CB988}" FilePath="*data\pg_stat_tmp\db_*">
		<Process CmdLine="*bin/postgres.exe&#34; &#34;--forkcol*" />
	</File>
	<File Id="{56F0C15A-A162-11BB-BCDF9CD58F0F9E86}" FilePath="*ssas\cubes*">
		<Process Path="*mssqlserver\olap\bin\msmdsrv.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</File>
	<File Id="{F3AE4BD3-BACB-107E-E1DB89C346A3456B}" FilePath="*o\archive\k*archive*">
		<Process CmdLine="*o /e /purge /z /sec /r:1 /w:1 /mt:16 /nfl" />
	</File>
	<File Id="{D9FB1CA2-0498-6B60-6F7DC146FD037B69}" FilePath="*ingenico*terminals*">
		<Process Path="*ingenico*">
			<Signature Subject="?*" />
		</Process>
	</File>
	<File Id="{3218E213-CB7A-43EC-5672849D36B8E5D1}" FilePath="*sas*sas*sas*">
		<Process CmdLine="*sas*bin\java.exe*sas*" />
	</File>
<!-- Part 0037 2024-06-26T15:17:00.000Z-1719415030 -->
<!-- ############################################################################################################### -->
</Filters>
