Казбек, папки удалил, скачал образ (английский правда) и так всё хорошо начиналось, но вдруг:
Event-1
[spoiler]- System
- Provider
[ Name] Service Control Manager
[ Guid] {555908d1-a6d7-4695-8e1e-26931d2012f4}
[ EventSourceName] Service Control Manager
- EventID 7040
[ Qualifiers] 16384
Version 0
Level 4
Task 0
Opcode 0
Keywords 0x8080000000000000
- TimeCreated
[ SystemTime] 2017-01-18T00:21:59.810039000Z
EventRecordID 119040
Correlation
- Execution
[ ProcessID] 868
[ ThreadID] 2216
Channel System
Computer system
- Security
[ UserID] S-1-5-18
- EventData
param1 Background Intelligent Transfer Service
param2 auto start
param3 demand start
param4 BITS[/spoiler]
Event-2
[spoiler]- System
- Provider
[ Name] disk
- EventID 153
[ Qualifiers] 32772
Level 3
Task 0
Keywords 0x80000000000000
- TimeCreated
[ SystemTime] 2017-01-18T00:26:22.495866900Z
EventRecordID 119047
Channel System
Computer system
Security
- EventData
\Device\Harddisk8\DR8
0x9562e18
8
\Device\00000042
0F01040004002C00000000009900048000000000000000000000000000000000000000000000000000000428
--------------------------------------------------------------------------------
Binary data:
In Words
0000: 0004010F 002C0004 00000000 80040099
0010: 00000000 00000000 00000000 00000000
0020: 00000000 00000000 28040000
In Bytes
0000: 0F 01 04 00 04 00 2C 00 ......,.
0008: 00 00 00 00 99 00 04 80 ....™..€
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
0028: 00 00 04 28 ...([/spoiler]
Event-3
[spoiler]- System
- Provider
[ Name] Microsoft-Windows-FilterManager
[ Guid] {F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}
EventID 6
Version 1
Level 4
Task 0
Opcode 0
Keywords 0x8000400000000000
- TimeCreated
[ SystemTime] 2017-01-18T00:27:04.301665700Z
EventRecordID 119048
Correlation
- Execution
[ ProcessID] 4
[ ThreadID] 5468
Channel System
Computer system
- Security
[ UserID] S-1-5-18
- EventData
FinalStatus 0x0
DeviceVersionMajor 10
DeviceVersionMinor 0
DeviceNameLength 8
DeviceName WIMMount
DeviceTime 2015-11-13T05:52:42.000000000Z
ExtraInfoLength 201
ExtraInfoString { "flags" : "0x00000000" , "registration_version" : "0x00000203" , "tx" : false , "sections" : false , "frame" : 0 , "class_name" : "FSFilter Infrastructure" , "instances" : [["180700","0x00000000"]] }
FilterID {00000000-0000-0000-0000-000000000000}[/spoiler]
Event-4
[spoiler]- System
- Provider
[ Name] Microsoft-Windows-Kernel-General
[ Guid] {A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}
EventID 16
Version 0
Level 4
Task 0
Opcode 0
Keywords 0x8000000000000000
- TimeCreated
[ SystemTime] 2017-01-18T00:27:17.680905300Z
EventRecordID 119057
Correlation
- Execution
[ ProcessID] 2244
[ ThreadID] 2512
Channel System
Computer system
- Security
[ UserID] S-1-5-21-799843486-505120229-2794507087-1001
- EventData
HiveNameLength 93
HiveName \??\C:\$WINDOWS.~BT\Sources\SafeOS\SafeOS.Mount\Windows\system32\smi\store\Machine\schema.dat
KeysUpdated 4554
DirtyPages 904[/spoiler]
и
http://prnt.sc/dx006r