Fix result of Farbar Recovery Scan Tool (x64) Version:23-09-2015
Ran by Erik (2015-10-01 20:42:01) Run:3
Running from C:\Users\Erik\Desktop
Loaded Profiles: Erik (Available Profiles: Erik & Guest)
Boot Mode: Normal
==============================================
fixlist content:
*****************
CreateRestorePoint:
C:\Program Files (x86)\CheckPoint
C:\ProgramData\CheckPoint
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\igfxcui: igfxdev.dll [X]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (No File)
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (No File)
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (No File)
RemoveProxy:
CHR Extension: (Skype Click to Call) - C:\Users\Erik\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-03-28]
2015-10-01 10:14 - 2015-10-01 10:14 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2015-10-01 10:14 - 2015-10-01 10:14 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2015-10-01 10:16 - 2012-08-10 01:35 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-09-25 10:35 - 2014-06-15 20:08 - 1006665521 _____ C:\Windows\MEMORY.DMP
CustomCLSID: HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Erik\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File
CustomCLSID: HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Erik\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Erik\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Erik\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Erik\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Erik\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Erik\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Erik\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
Task: C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
AlternateDataStreams: C:\ProgramData:482EE99B1E21CE8C
AlternateDataStreams: C:\Windows\notepad.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\acmigration.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\adtschema.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\advapi32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aeinv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aelupsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aepdu.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aepic.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aitstatic.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\apisetschema.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\apphelp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appidapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appidcertstorecheck.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appidpolicyconverter.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appidsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appinfo.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appraiser.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appverif.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\atmfd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\atmlib.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\audiodg.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\AudioEng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\AUDIOKSE.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\AudioSes.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\audiosrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\auditpol.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\authui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\basesrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\blackbox.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\certcli.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cewmdm.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\charmap.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ci.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\clfs.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\clfsw32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\comctl32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\CompatTelRunner.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\conhost.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\consent.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\credssp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\crypt32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptbase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptnet.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptsp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\csrsrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3d10warp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DCompiler_33.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DCompiler_34.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DCompiler_35.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DCompiler_36.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DCompiler_37.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DCompiler_38.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DCompiler_39.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DCompiler_40.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DCompiler_41.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DCompiler_42.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DCompiler_43.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dcsx_42.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dcsx_43.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx10.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx10_33.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx10_34.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx10_35.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx10_36.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx10_37.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx10_38.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx10_39.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx10_40.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx10_41.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx10_43.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx11_42.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx11_43.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx9_24.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx9_25.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx9_26.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx9_27.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx9_28.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx9_29.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx9_30.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx9_31.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx9_33.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx9_34.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx9_35.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dx9_36.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DX9_37.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DX9_38.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DX9_39.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DX9_40.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DX9_41.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DX9_42.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\D3DX9_43.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3dxof.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\davclnt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dciman32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\devinv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dfshim.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\diagtrack.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\diskperf.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\drmmgrtn.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\drmv2clt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dwmapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dwmcore.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\DWrite.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dxcap.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dxcpl.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dxmasf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dxtmsft.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dxtrans.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\EncDump.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\evr.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\FntCache.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\fontsub.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\gdi32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\generaltel.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieframe.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\iertutil.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieUnatt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\IMJP10K.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\system32\inetcpl.cpl:$CmdTcID
AlternateDataStreams: C:\Windows\system32\InkEd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\invagent.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jnwmon.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jscript.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jscript9.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jsproxy.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\KBDBASH.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\system32\KBDRU.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\system32\KBDRU1.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\system32\KBDTAT.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\system32\KBDYAK.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\system32\kerberos.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\kernel32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\KernelBase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\logman.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\lpk.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\lsasrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\lsass.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mfc110.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mferror.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mfplat.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mfpmp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mfps.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\microsoft.windows.softwarelogo.showdesktop.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\MpSigStub.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\MRT.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msaudite.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mscorier.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mscories.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msctf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msdxm.ocx:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msfeeds.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msfeedsbs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msfeedssync.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mshta.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mshtml.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mshtmled.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msiexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msihnd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msimsg.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msmmsp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msmpeg2vdec.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msnetobj.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msobjs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msscp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mstscax.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msv1_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msxml3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msxml3r.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msxml6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msxml6r.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ncrypt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\notepad.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ntdll.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ntvdm64.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ole32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\oleaut32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\OpenAL32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\osk.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\packager.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcadm.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcaevts.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcalua.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcasvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcawrk.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pku2u.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\poqexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\profsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\qdvd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\quartz.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rastls.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rdpcorekmts.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rdvidcrl.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\relog.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rpcrt4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rrinstaller.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rstrui.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\scesrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\schannel.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\schedsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sdbinst.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sechost.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\secur32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\services.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\setbcdlocale.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\shell32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\shimeng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\smss.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\spwmp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\srclient.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\srcore.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sspicli.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sspisrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sysmain.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\tdh.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\termsrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\tracerpt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\tsgqec.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\TSpkg.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\TSWbPrxy.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\TSWorkspace.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\typeperf.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\tzres.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ucrtbase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\url.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\urlmon.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\UtcResources.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\vbscript.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\vsgraphicsremoteengine.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\vsjitdebugger.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WdfCoInstaller01009.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wdigest.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\win32k.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WindowsCodecs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wininet.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winload.efi:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winload.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winlogon.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winresume.efi:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winresume.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WinSetupUI.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winsrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winsta.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wintrust.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wksprt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wmdrmsdk.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wmp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WMPhoto.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wmploc.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wow64.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wow64cpu.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wow64win.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wpdshext.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wrap_oal.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WSManHTTPConfig.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WSManMigrationPlugin.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WsmAuto.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WsmSvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WsmWmiPl.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wu.upgrade.ps.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuapp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuauclt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuaueng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wucltux.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wudriver.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wups.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wups2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuwebv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\x3daudio1_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\x3daudio1_1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\X3DAudio1_2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\X3DAudio1_3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\X3DAudio1_4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\X3DAudio1_5.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\X3DAudio1_6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\X3DAudio1_7.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine2_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine2_1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine2_10.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine2_2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine2_3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine2_4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine2_5.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine2_6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine2_7.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine2_8.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine2_9.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine3_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine3_1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine3_2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine3_3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine3_4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine3_5.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine3_6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xactengine3_7.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAPOFX1_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAPOFX1_1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAPOFX1_2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAPOFX1_3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAPOFX1_4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAPOFX1_5.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAudio2_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAudio2_1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAudio2_2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAudio2_3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAudio2_4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAudio2_5.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAudio2_6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\XAudio2_7.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xinput1_1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xinput1_2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xinput1_3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xvid.ax:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xvidcore.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\xvidvfw.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\zlib.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\adtschema.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\advapi32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\apisetschema.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\apphelp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\appidapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\appverif.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\atmfd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\atmlib.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\AudioEng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\AUDIOKSE.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\AudioSes.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\auditpol.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\authui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\blackbox.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\certcli.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cewmdm.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\charmap.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\clfsw32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\comctl32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\credssp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\crypt32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptbase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptnet.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptsp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3d10warp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_33.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_34.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_35.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_36.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_37.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_38.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_39.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_40.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_42.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_43.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dcsx_42.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dcsx_43.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_33.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_34.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_35.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_36.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_37.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_38.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_39.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_40.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_43.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx11_42.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx11_43.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_24.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_25.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_26.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_27.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_28.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_29.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_30.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_31.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_33.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_34.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_35.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_36.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_37.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_38.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_39.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_40.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_41.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_42.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_43.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\davclnt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dciman32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dfshim.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\diskperf.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\drmmgrtn.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\drmv2clt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dwmapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dwmcore.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\DWrite.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dxcap.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dxcpl.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dxmasf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dxtmsft.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dxtrans.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\evr.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\fontsub.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\gdi32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\HTMLWH.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieframe.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\iertutil.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieUnatt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\IMJP10K.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\inetcpl.cpl:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\INETWH32.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\InkEd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\instnm.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\javaws.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\jscript.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\jscript9.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\jsproxy.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\KBDBASH.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\KBDRU.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\KBDRU1.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\KBDTAT.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\KBDYAK.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\kerberos.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\kernel32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\KernelBase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\logman.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\lpk.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mferror.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mfplat.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mfpmp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mfps.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msaudite.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mscorier.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mscories.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msctf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msdxm.ocx:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msfeeds.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msfeedsbs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msfeedssync.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mshta.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mshtml.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mshtmled.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msiexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msihnd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msimsg.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msmpeg2vdec.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msnetobj.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msobjs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msscp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mstscax.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msv1_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msxml3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msxml3r.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msxml6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msxml6r.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ncrypt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ncsi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\nlaapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\notepad.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntdll.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntkrnlpa.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntoskrnl.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntvdm64.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ole32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\oleaut32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\OpenAL32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\osk.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\packager.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\pku2u.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\poqexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\qdvd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\quartz.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\rastls.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\rdvidcrl.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\relog.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ROBOEX32.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\rpcrt4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\rrinstaller.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\scesrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\schannel.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\sdbinst.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\sechost.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\secur32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\setup16.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\shell32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\shimeng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\spwmp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\srclient.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\sspicli.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\tdh.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\tracerpt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\tsgqec.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\TSpkg.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\TSWorkspace.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\typeperf.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\tzres.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ucrtbase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\url.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\urlmon.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\user.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\vbscript.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\vcamp140.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\vsd3dwarpdebug.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\vsgraphicsremoteengine.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\vsjitdebugger.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wdigest.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WebClnt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WindowsCodecs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wininet.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\winsta.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wintrust.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wmdrmsdk.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wmp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WMPhoto.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wmploc.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wow32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wpdshext.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wrap_oal.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WSManHTTPConfig.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WSManMigrationPlugin.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WsmAuto.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WsmSvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WsmWmiPl.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wuapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wuapp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wudriver.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wups.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wuwebv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\x3daudio1_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\x3daudio1_1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_5.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_7.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_10.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_5.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_7.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_8.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_9.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_5.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_7.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_5.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_7.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xinput1_1.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xinput1_2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xliveinstallhost.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xvid.ax:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xvidcore.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\xvidvfw.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\afd.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\appid.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\cng.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\dxgkrnl.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\http.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\ksecdd.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\ksecpkg.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mbam.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mbamchameleon.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mountmgr.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mrxdav.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb10.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb20.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mwac.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\PEAuth.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\rdpwd.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\ScreamingBAudio64.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\Sftfslh.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\Sftplaylh.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\Sftredirlh.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\Sftvollh.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\stream.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\tdx.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\tssecsrv.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\wdcsam64.sys:$CmdTcID
AlternateDataStreams: C:\Users\All Users:482EE99B1E21CE8C
AlternateDataStreams: C:\ProgramData\Application Data:482EE99B1E21CE8C
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
AlternateDataStreams: C:\ProgramData\TEMP:30FD0CBD
AlternateDataStreams: C:\ProgramData\TEMP:C8B8CEBD
AlternateDataStreams: C:\Users\Erik\Cookies:iAbYWnLo4E0biseBTur5Hfa
AlternateDataStreams: C:\Users\Erik\Cookies:OZC7l67cDbfZPHuZBwh
AlternateDataStreams: C:\Users\Erik\Local Settings:4EUhZg4kRrP3RyMxteBnNq
AlternateDataStreams: C:\Users\Erik\Downloads\270536745794.jpg:$CmdZnID
AlternateDataStreams: C:\Users\Erik\Downloads\28c4b98ba3c859c4bc34da57b0a5a7ac.jpg:$CmdZnID
AlternateDataStreams: C:\Users\Erik\Downloads\347.52-desktop-win8-win7-winvista-64bit-international-whql.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\355.60-desktop-win8-win7-winvista-64bit-international-whql.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\asioconfig.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\Beauty and the Beast STORY (revisions)(1).doc:$CmdZnID
AlternateDataStreams: C:\Users\Erik\Downloads\ccsetup509.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\Clock(1).fbx:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\Clock(1).fbx:$CmdZnID
AlternateDataStreams: C:\Users\Erik\Downloads\clockface.jpg:$CmdZnID
AlternateDataStreams: C:\Users\Erik\Downloads\Cold_Fear_Downloader.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\cpu-z_1.73-en.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\CreepyKey.fbx:$CmdZnID
AlternateDataStreams: C:\Users\Erik\Downloads\dm log collector.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\dpclat.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\drivercleaning1.71.bat:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\DriverSweeper_3.2.0.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\form.loan.discharge.false.certification.disqualifying.status.pdf:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\form.loan.discharge.false.certification.disqualifying.status.pdf:$CmdZnID
AlternateDataStreams: C:\Users\Erik\Downloads\FreemakeVideoConverterSetup.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\Geekbench-3.3.2-WindowsSetup.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\gfwlivesetup.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\gimp-2.8.14-setup-1.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\GitHubSetup.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\Handle.fbx:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\Handle.fbx:$CmdZnID
AlternateDataStreams: C:\Users\Erik\Downloads\Handle2.fbx:$CmdZnID
AlternateDataStreams: C:\Users\Erik\Downloads\hwmonitor_1.27.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\hwmonitor_1.28.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\ImageMagick-6.9.1-1-Q16-x64-dll.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\instspeedfan451.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\iZotope_Vinyl_Setup_v1_73b.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\jxpiinstall.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\LionNormal.png:$CmdZnID
AlternateDataStreams: C:\Users\Erik\Downloads\MaPZone2_2_6_1a.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\MiniToolBox.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\MorphVOXJunior_Install-1.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\OBS_0_638b_Installer.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\open3mod_1_1_setup.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\p4vinst64.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\patch_among_the_sleep_2.1.2.8.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\pc-decrapifier-3.0.0.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\perforce64.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\Prepros-Windows-5.9.3.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\reaper478_x64-install.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\reaper501_x64-install.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\reaper50_x64-install.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\SeaToolsforWindowsSetup.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\setup-lightshot.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\setup_among_the_sleep_2.1.0.6.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\setup_downfall_2.0.0.5.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\setup_the_cat_lady_2.2.0.6.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\Setup_WinThruster_2015.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\shexview_setup.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\Shotgun.fbx:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\Shotgun.fbx:$CmdZnID
AlternateDataStreams: C:\Users\Erik\Downloads\SketchUpMake-en-x64.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\SkypeSetupFull.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\SlackSetup.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\spsetup127.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\spsetup128.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\tumblr_mcj9658Nd61qcej2y.jpg:$CmdZnID
AlternateDataStreams: C:\Users\Erik\Downloads\tweaking.com_windows_repair_aio_setup.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\UNi Xonar 1822 v1.75a r2.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\vs_community.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\vs_community2013.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\windirstat1_1_2_setup.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\x64_okino_nugraf_and_polytrans_full_demo_2014-g8.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\x64_okino_plugins_superinstaller_demo_2015_r1_vc10.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\Downloads\xnormal_3.18.10_installer.exe:$CmdTcID
AlternateDataStreams: C:\Users\Erik\AppData\Local:4EUhZg4kRrP3RyMxteBnNq
AlternateDataStreams: C:\Users\Erik\AppData\Local\Application Data:4EUhZg4kRrP3RyMxteBnNq
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\DB2E967B60A830B44969B59901522A6C]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00A70489854D5A641902FB008E4D8618]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\061DCC9861F267B41AC1C29475857C35]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFAFF23141ECFF45A98C5CBCC6FD7E4]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\14BC9F86F1AD45D43873BA78A76819BD]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1BAF6F4DAD1D0574EA37AE1E85F42872]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1FEF8F5B062BB554291737BBAFFBBD9F]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\21DACAEC56A90AF42A1891AE87B42461]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\223FA682F47F6174A979557583592597]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2934E1BD93E2E914A99D37BB338DE367]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34BEE696B22607D418ABAF7FF0DF91D6]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\463CADD0A1A748D4D8C8F287E8C87A1A]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46BAC581079409841BF9E919A2D86A51]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B520363CFE931C47BF0BDD9B439BFD2]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4D6DEF2A51FA5C344B7002359BD3A177]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\51CDF02D10348BF4181C57804C66061F]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B5B945AADFFECB4696F936C258E5F4B]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5F6074F269657104887ED1B50FBC0075]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5FCBF801D99B43645B840DEDCCA704D9]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61EE1400988BF654F96D5B8EDBE90757]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6344971EDDB6E254CBDE0B6DE3BE793C]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\64171660A5BD7C1468BAED8640062F13]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A05C1BE882BCCC408F78CE6B01D869F]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B89CCF36B260C54A8F37EB7DF28E2A1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F0381E444E6AA648B6D5C4C75D29726]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71DC1D91C8E097C4A9BA8E1B1971FA7F]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\77386F2641568624CA72F0CB8DD7F880]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A478A4A67DC63F418558AB5CDA4EBCA]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7E9471324BC1E2145845E1637606EF41]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\803BFC11A8D201643AE1BBA6FEB0BAFF]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\87E5F8B257B97EC40951F40F1BF2135F]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8A9B9DD8917688B46B3F6FA3B6D4F54D]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F284C382B602D7478DA1CEF01118ACC]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\988B24BF74AF5CC41A7C58C29836FE98]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9CF5213E43998654C854B419F0DE2564]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A089B901B67CE0748AA88C4BD50D57D1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6E483D6F0FD50C40ACCCFA653326EF7]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A9D48A1CC619EDC468E3B4D3054DE891]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AECE2176AF5E1864BAC440F0D02CD58A]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3046214DAEE6A246B8B6E7316B31906]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B7027658A0B8E774F91A80F4FCC40224]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE2B910A814CFB341B13B3D3D9BB9F6F]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C59542720E53D354A92DDB9A447346B9]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCFCCC1891E40904899A3566879D171A]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D0DFCD17461DFDA41B4E04D271B0FBE5]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D29A65A3104E2C340BFE40FAE8A91267]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3873A30E6162ED47BA0AB95A3CDDA5F]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D60BE5613DFE6AC4C93F1F835DCEE1E2]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DEB9571C8E6CC1B4BA6F7D22A9DF81BB]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E02821297F70E6F44B20D83CD953476D]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3C649A9849FBA143943CAA1B6FB6150]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED0F7BCDE5F677D4797D7B485A475F70]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F39C202861CC5394D92BC01541F13711]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA6CDD7CC8A73B242826081F921A23E4]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0E641459FF949304FA85227505C6D754]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DB2E967B60A830B44969B59901522A6C]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-stop.com]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-stop.com]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\CheckPoint\ZoneAlarm]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-stop.com]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-stop.com]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B769E2BD-8A06-4B03-9496-5B991025A2C6}]
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-download-now.com]
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-download-now.com]
[-HKEY_USERS\S-1-5-21-95435350-4265177964-2103988519-1001\Software\CheckPoint]
[-HKEY_USERS\S-1-5-21-95435350-4265177964-2103988519-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-stop.com]
[-HKEY_USERS\S-1-5-21-95435350-4265177964-2103988519-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-stop.com]
[-HKEY_USERS\S-1-5-21-95435350-4265177964-2103988519-1001\Software\Zone Labs]
[-HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-download-now.com]
[-HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-download-now.com]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSDATANT]
EmptyTemp:
*****************
Restore point was successfully created.
"C:\Program Files (x86)\CheckPoint" => File/Folder not found.
C:\ProgramData\CheckPoint => moved successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui" => key removed successfully
C:\Program Files\Dell\DellDock\DellDock.exe => not found.
C:\Program Files\Dell\DellDock\DellDock.exe => not found.
C:\Program Files\Dell\DellDock\DellDock.exe => not found.
========= RemoveProxy: =========
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-95435350-4265177964-2103988519-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-95435350-4265177964-2103988519-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
========= End of RemoveProxy: =========
C:\Users\Erik\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl => not found
"C:\Windows\System32\Tasks\Safer-Networking" => File/Folder not found.
"C:\Windows\System32\Tasks\Safer-Networking" => File/Folder not found.
"C:\ProgramData\Spybot - Search & Destroy" => File/Folder not found.
C:\Windows\MEMORY.DMP => moved successfully
"HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}" => key removed successfully
"HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}" => key removed successfully
"HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}" => key removed successfully
"HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}" => key removed successfully
"HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}" => key removed successfully
"HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}" => key removed successfully
"HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}" => key removed successfully
"HKU\S-1-5-21-95435350-4265177964-2103988519-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}" => key removed successfully
C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job => moved successfully
C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job => moved successfully
C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job => moved successfully
C:\ProgramData => ":482EE99B1E21CE8C" ADS removed successfully.
C:\Windows\notepad.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\acmigration.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\adtschema.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\advapi32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\aeinv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\aelupsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\aepdu.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\aepic.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\aitstatic.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\apisetschema.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\apphelp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\appidapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\appidcertstorecheck.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\appidpolicyconverter.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\appidsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\appinfo.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\appraiser.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\appverif.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\atmfd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\atmlib.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\audiodg.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AudioEng.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AUDIOKSE.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AudioSes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\audiosrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\auditpol.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\authui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\basesrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\blackbox.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\certcli.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cewmdm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\charmap.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ci.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\clfs.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\clfsw32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\comctl32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CompatTelRunner.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\conhost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\consent.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\credssp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\crypt32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cryptbase.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cryptnet.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cryptsp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cryptsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cryptui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\csrsrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3d10warp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_33.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_34.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_35.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_36.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_37.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_38.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_39.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_40.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_41.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dcsx_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dcsx_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_33.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_34.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_35.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_36.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_37.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_38.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_39.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_40.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_41.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx11_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx11_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_24.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_25.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_26.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_27.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_28.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_29.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_30.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_31.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_33.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_34.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_35.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_36.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_37.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_38.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_39.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_40.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_41.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dxof.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\davclnt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dciman32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\devinv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dfshim.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\diagtrack.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\diskperf.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\drmmgrtn.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\drmv2clt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dwmapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dwmcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DWrite.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dxcap.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dxcpl.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dxmasf.dll => ":$CmdTcID" ADS removed successfully.
"C:\Windows\system32\dxtmsft.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\dxtrans.dll" => ":$CmdTcID" ADS not found.
C:\Windows\system32\EncDump.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\evr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\FntCache.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\fontsub.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\gdi32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\generaltel.dll => ":$CmdTcID" ADS removed successfully.
"C:\Windows\system32\ieframe.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\iertutil.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\ieui.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\ieUnatt.exe" => ":$CmdTcID" ADS not found.
C:\Windows\system32\IMJP10K.DLL => ":$CmdTcID" ADS removed successfully.
"C:\Windows\system32\inetcpl.cpl" => ":$CmdTcID" ADS not found.
C:\Windows\system32\InkEd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\invagent.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\jnwmon.dll => ":$CmdTcID" ADS removed successfully.
"C:\Windows\system32\jscript.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\jscript9.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\jsproxy.dll" => ":$CmdTcID" ADS not found.
C:\Windows\system32\KBDBASH.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\KBDRU.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\KBDRU1.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\KBDTAT.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\KBDYAK.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\kerberos.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\kernel32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\KernelBase.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\logman.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\lpk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\lsasrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\lsass.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfc110.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mferror.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfplat.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfpmp.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\microsoft.windows.softwarelogo.showdesktop.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MpSigStub.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MRT.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msaudite.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mscorier.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mscories.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msctf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msdxm.ocx => ":$CmdTcID" ADS removed successfully.
"C:\Windows\system32\msfeeds.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\msfeedsbs.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\msfeedssync.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\mshta.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\mshtml.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\mshtmled.dll" => ":$CmdTcID" ADS not found.
C:\Windows\system32\msi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msiexec.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msihnd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msimsg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msmmsp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msmpeg2vdec.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msnetobj.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msobjs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msscp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mstscax.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msv1_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msxml3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msxml3r.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msxml6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msxml6r.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ncrypt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nlasvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\notepad.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ntdll.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ntoskrnl.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ntvdm64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ole32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\oleaut32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\OpenAL32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\osk.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\packager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\pcadm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\pcaevts.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\pcalua.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\pcasvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\pcawrk.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\pku2u.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\poqexec.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\profsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\qdvd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\quartz.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rastls.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rdpcorekmts.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rdvidcrl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\relog.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rpcrt4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rrinstaller.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rstrui.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\scesrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\schannel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\schedsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sdbinst.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sechost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\secur32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\services.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\setbcdlocale.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\shell32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\shimeng.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\smss.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\spwmp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\srclient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\srcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sspicli.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sspisrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sysmain.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tdh.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\termsrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tracerpt.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tsgqec.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TSpkg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TSWbPrxy.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TSWorkspace.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\typeperf.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tzres.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ucrtbase.dll => ":$CmdTcID" ADS removed successfully.
"C:\Windows\system32\url.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\urlmon.dll" => ":$CmdTcID" ADS not found.
C:\Windows\system32\UtcResources.dll => ":$CmdTcID" ADS removed successfully.
"C:\Windows\system32\vbscript.dll" => ":$CmdTcID" ADS not found.
C:\Windows\system32\vsgraphicsremoteengine.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\vsjitdebugger.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WdfCoInstaller01009.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wdigest.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\win32k.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WindowsCodecs.dll => ":$CmdTcID" ADS removed successfully.
"C:\Windows\system32\wininet.dll" => ":$CmdTcID" ADS not found.
C:\Windows\system32\winload.efi => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winload.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winlogon.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winresume.efi => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winresume.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WinSetupUI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winsrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winsta.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wintrust.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wksprt.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wmdrmsdk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wmp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WMPhoto.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wmploc.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wow64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wow64cpu.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wow64win.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wpdshext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wrap_oal.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WSManHTTPConfig.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WSManMigrationPlugin.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WsmAuto.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WsmSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WsmWmiPl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wu.upgrade.ps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wuapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wuapp.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wuauclt.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wuaueng.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wucltux.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wudriver.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wups.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wups2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wuwebv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\x3daudio1_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\x3daudio1_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\X3DAudio1_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\X3DAudio1_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\X3DAudio1_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\X3DAudio1_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\X3DAudio1_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\X3DAudio1_7.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_10.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_7.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_8.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_9.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine3_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine3_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine3_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine3_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine3_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine3_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine3_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine3_7.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAPOFX1_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAPOFX1_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAPOFX1_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAPOFX1_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAPOFX1_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAPOFX1_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAudio2_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAudio2_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAudio2_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAudio2_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAudio2_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAudio2_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAudio2_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAudio2_7.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xinput1_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xinput1_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xinput1_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xvid.ax => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xvidcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xvidvfw.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\zlib.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\adtschema.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\advapi32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\apisetschema.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\apphelp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\appidapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\appverif.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\atmfd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\atmlib.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AudioEng.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AUDIOKSE.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AudioSes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\auditpol.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\authui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\blackbox.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\certcli.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\cewmdm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\charmap.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\clfsw32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\comctl32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\credssp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\crypt32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\cryptbase.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\cryptnet.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\cryptsp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\cryptsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\cryptui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3d10warp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_33.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_34.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_35.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_36.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_37.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_38.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_39.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_40.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dcsx_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dcsx_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_33.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_34.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_35.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_36.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_37.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_38.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_39.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_40.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx11_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx11_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_24.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_25.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_26.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_27.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_28.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_29.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_30.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_31.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_33.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_34.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_35.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_36.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_37.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_38.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_39.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_40.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_41.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\davclnt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dciman32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dfshim.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\diskperf.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\drmmgrtn.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\drmv2clt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dwmapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dwmcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\DWrite.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dxcap.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dxcpl.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dxmasf.dll => ":$CmdTcID" ADS removed successfully.
"C:\Windows\SysWOW64\dxtmsft.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\dxtrans.dll" => ":$CmdTcID" ADS not found.
C:\Windows\SysWOW64\evr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\fontsub.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\gdi32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\HTMLWH.DLL => ":$CmdTcID" ADS removed successfully.
"C:\Windows\SysWOW64\ieframe.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\iertutil.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\ieui.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\ieUnatt.exe" => ":$CmdTcID" ADS not found.
C:\Windows\SysWOW64\IMJP10K.DLL => ":$CmdTcID" ADS removed successfully.
"C:\Windows\SysWOW64\inetcpl.cpl" => ":$CmdTcID" ADS not found.
C:\Windows\SysWOW64\INETWH32.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\InkEd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\instnm.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\javaws.exe => ":$CmdTcID" ADS removed successfully.
"C:\Windows\SysWOW64\jscript.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\jscript9.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\jsproxy.dll" => ":$CmdTcID" ADS not found.
C:\Windows\SysWOW64\KBDBASH.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\KBDRU.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\KBDRU1.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\KBDTAT.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\KBDYAK.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\kerberos.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\kernel32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\KernelBase.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\logman.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\lpk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mferror.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfplat.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfpmp.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msaudite.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mscorier.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mscories.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msctf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msdxm.ocx => ":$CmdTcID" ADS removed successfully.
"C:\Windows\SysWOW64\msfeeds.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\msfeedsbs.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\msfeedssync.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\mshta.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\mshtml.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\mshtmled.dll" => ":$CmdTcID" ADS not found.
C:\Windows\SysWOW64\msi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msiexec.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msihnd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msimsg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msmpeg2vdec.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msnetobj.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msobjs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msscp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mstscax.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msv1_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msxml3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msxml3r.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msxml6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msxml6r.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ncrypt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ncsi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nlaapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\notepad.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ntdll.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ntkrnlpa.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ntoskrnl.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ntvdm64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ole32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\oleaut32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\OpenAL32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\osk.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\packager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\pku2u.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\poqexec.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\qdvd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\quartz.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\rastls.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\rdvidcrl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\relog.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ROBOEX32.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\rpcrt4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\rrinstaller.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\scesrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\schannel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\sdbinst.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\sechost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\secur32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\setup16.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\shell32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\shimeng.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\spwmp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\srclient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\sspicli.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\tdh.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\tracerpt.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\tsgqec.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\TSpkg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\TSWorkspace.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\typeperf.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\tzres.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ucrtbase.dll => ":$CmdTcID" ADS removed successfully.
"C:\Windows\SysWOW64\url.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\urlmon.dll" => ":$CmdTcID" ADS not found.
C:\Windows\SysWOW64\user.exe => ":$CmdTcID" ADS removed successfully.
"C:\Windows\SysWOW64\vbscript.dll" => ":$CmdTcID" ADS not found.
C:\Windows\SysWOW64\vcamp140.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\vsd3dwarpdebug.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\vsgraphicsremoteengine.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\vsjitdebugger.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wdigest.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WebClnt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WindowsCodecs.dll => ":$CmdTcID" ADS removed successfully.
"C:\Windows\SysWOW64\wininet.dll" => ":$CmdTcID" ADS not found.
C:\Windows\SysWOW64\winsta.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wintrust.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wmdrmsdk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wmp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WMPhoto.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wmploc.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wow32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wpdshext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wrap_oal.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WSManHTTPConfig.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WSManMigrationPlugin.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WsmAuto.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WsmSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WsmWmiPl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wuapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wuapp.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wudriver.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wups.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wuwebv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\x3daudio1_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\x3daudio1_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\X3DAudio1_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\X3DAudio1_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\X3DAudio1_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\X3DAudio1_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\X3DAudio1_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\X3DAudio1_7.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_10.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_7.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_8.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_9.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_7.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAPOFX1_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAPOFX1_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAPOFX1_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAPOFX1_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAPOFX1_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_7.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xinput1_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xinput1_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xliveinstallhost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xvid.ax => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xvidcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xvidvfw.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\afd.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\appid.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\cng.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\dxgkrnl.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\http.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\ksecdd.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\ksecpkg.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\mbam.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\mbamchameleon.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\mountmgr.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\mrxdav.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\mrxsmb.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\mrxsmb10.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\mrxsmb20.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\mwac.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\PEAuth.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\rdpwd.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\ScreamingBAudio64.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\Sftfslh.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\Sftplaylh.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\Sftredirlh.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\Sftvollh.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\stream.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\tdx.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\tssecsrv.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\wdcsam64.sys => ":$CmdTcID" ADS removed successfully.
"C:\Users\All Users" => ":482EE99B1E21CE8C" ADS not found.
"C:\ProgramData\Application Data" => ":482EE99B1E21CE8C" ADS not found.
"C:\ProgramData\Reprise" => ":wupeogjxldtlfudivq`qsp`26hfm" ADS not found.
"C:\ProgramData\TEMP" => ":30FD0CBD" ADS not found.
"C:\ProgramData\TEMP" => ":C8B8CEBD" ADS not found.
"C:\Users\Erik\Cookies" => ":iAbYWnLo4E0biseBTur5Hfa" ADS not found.
"C:\Users\Erik\Cookies" => ":OZC7l67cDbfZPHuZBwh" ADS not found.
"C:\Users\Erik\Local Settings" => ":4EUhZg4kRrP3RyMxteBnNq" ADS not found.
"C:\Users\Erik\Downloads\270536745794.jpg" => ":$CmdZnID" ADS not found.
"C:\Users\Erik\Downloads\28c4b98ba3c859c4bc34da57b0a5a7ac.jpg" => ":$CmdZnID" ADS not found.
C:\Users\Erik\Downloads\347.52-desktop-win8-win7-winvista-64bit-international-whql.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\355.60-desktop-win8-win7-winvista-64bit-international-whql.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\asioconfig.exe => ":$CmdTcID" ADS removed successfully.
"C:\Users\Erik\Downloads\Beauty and the Beast STORY (revisions)(1).doc" => ":$CmdZnID" ADS not found.
C:\Users\Erik\Downloads\ccsetup509.exe => ":$CmdTcID" ADS removed successfully.
"C:\Users\Erik\Downloads\Clock(1).fbx" => ":$CmdTcID" ADS not found.
"C:\Users\Erik\Downloads\Clock(1).fbx" => ":$CmdZnID" ADS not found.
"C:\Users\Erik\Downloads\clockface.jpg" => ":$CmdZnID" ADS not found.
C:\Users\Erik\Downloads\Cold_Fear_Downloader.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\cpu-z_1.73-en.exe => ":$CmdTcID" ADS removed successfully.
"C:\Users\Erik\Downloads\CreepyKey.fbx" => ":$CmdZnID" ADS not found.
C:\Users\Erik\Downloads\dm log collector.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\dpclat.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\drivercleaning1.71.bat => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\DriverSweeper_3.2.0.exe => ":$CmdTcID" ADS removed successfully.
"C:\Users\Erik\Downloads\form.loan.discharge.false.certification.disqualifying.status.pdf" => ":$CmdTcID" ADS not found.
"C:\Users\Erik\Downloads\form.loan.discharge.false.certification.disqualifying.status.pdf" => ":$CmdZnID" ADS not found.
C:\Users\Erik\Downloads\FreemakeVideoConverterSetup.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\Geekbench-3.3.2-WindowsSetup.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\gfwlivesetup.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\gimp-2.8.14-setup-1.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\GitHubSetup.exe => ":$CmdTcID" ADS removed successfully.
"C:\Users\Erik\Downloads\Handle.fbx" => ":$CmdTcID" ADS not found.
"C:\Users\Erik\Downloads\Handle.fbx" => ":$CmdZnID" ADS not found.
"C:\Users\Erik\Downloads\Handle2.fbx" => ":$CmdZnID" ADS not found.
C:\Users\Erik\Downloads\hwmonitor_1.27.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\hwmonitor_1.28.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\ImageMagick-6.9.1-1-Q16-x64-dll.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\instspeedfan451.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\iZotope_Vinyl_Setup_v1_73b.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\jxpiinstall.exe => ":$CmdTcID" ADS removed successfully.
"C:\Users\Erik\Downloads\LionNormal.png" => ":$CmdZnID" ADS not found.
C:\Users\Erik\Downloads\MaPZone2_2_6_1a.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\MiniToolBox.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\MorphVOXJunior_Install-1.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\OBS_0_638b_Installer.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\open3mod_1_1_setup.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\p4vinst64.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\patch_among_the_sleep_2.1.2.8.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\pc-decrapifier-3.0.0.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\perforce64.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\Prepros-Windows-5.9.3.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\reaper478_x64-install.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\reaper501_x64-install.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\reaper50_x64-install.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\SeaToolsforWindowsSetup.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\setup-lightshot.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\setup_among_the_sleep_2.1.0.6.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\setup_downfall_2.0.0.5.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\setup_the_cat_lady_2.2.0.6.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\Setup_WinThruster_2015.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\shexview_setup.exe => ":$CmdTcID" ADS removed successfully.
"C:\Users\Erik\Downloads\Shotgun.fbx" => ":$CmdTcID" ADS not found.
"C:\Users\Erik\Downloads\Shotgun.fbx" => ":$CmdZnID" ADS not found.
C:\Users\Erik\Downloads\SketchUpMake-en-x64.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\SkypeSetupFull.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\SlackSetup.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\spsetup127.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\spsetup128.exe => ":$CmdTcID" ADS removed successfully.
"C:\Users\Erik\Downloads\tumblr_mcj9658Nd61qcej2y.jpg" => ":$CmdZnID" ADS not found.
C:\Users\Erik\Downloads\tweaking.com_windows_repair_aio_setup.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\UNi Xonar 1822 v1.75a r2.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\vs_community.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\vs_community2013.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\windirstat1_1_2_setup.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\x64_okino_nugraf_and_polytrans_full_demo_2014-g8.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\x64_okino_plugins_superinstaller_demo_2015_r1_vc10.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\Downloads\xnormal_3.18.10_installer.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Erik\AppData\Local => ":4EUhZg4kRrP3RyMxteBnNq" ADS removed successfully.
"C:\Users\Erik\AppData\Local\Application Data" => ":4EUhZg4kRrP3RyMxteBnNq" ADS not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\DB2E967B60A830B44969B59901522A6C => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00A70489854D5A641902FB008E4D8618 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\061DCC9861F267B41AC1C29475857C35 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFAFF23141ECFF45A98C5CBCC6FD7E4 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\14BC9F86F1AD45D43873BA78A76819BD => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1BAF6F4DAD1D0574EA37AE1E85F42872 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1FEF8F5B062BB554291737BBAFFBBD9F => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\21DACAEC56A90AF42A1891AE87B42461 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\223FA682F47F6174A979557583592597 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2934E1BD93E2E914A99D37BB338DE367 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34BEE696B22607D418ABAF7FF0DF91D6 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\463CADD0A1A748D4D8C8F287E8C87A1A => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46BAC581079409841BF9E919A2D86A51 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B520363CFE931C47BF0BDD9B439BFD2 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4D6DEF2A51FA5C344B7002359BD3A177 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\51CDF02D10348BF4181C57804C66061F => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B5B945AADFFECB4696F936C258E5F4B => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5F6074F269657104887ED1B50FBC0075 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5FCBF801D99B43645B840DEDCCA704D9 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61EE1400988BF654F96D5B8EDBE90757 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6344971EDDB6E254CBDE0B6DE3BE793C => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\64171660A5BD7C1468BAED8640062F13 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A05C1BE882BCCC408F78CE6B01D869F => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B89CCF36B260C54A8F37EB7DF28E2A1 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F0381E444E6AA648B6D5C4C75D29726 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71DC1D91C8E097C4A9BA8E1B1971FA7F => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\77386F2641568624CA72F0CB8DD7F880 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A478A4A67DC63F418558AB5CDA4EBCA => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7E9471324BC1E2145845E1637606EF41 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\803BFC11A8D201643AE1BBA6FEB0BAFF => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\87E5F8B257B97EC40951F40F1BF2135F => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8A9B9DD8917688B46B3F6FA3B6D4F54D => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F284C382B602D7478DA1CEF01118ACC => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\988B24BF74AF5CC41A7C58C29836FE98 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9CF5213E43998654C854B419F0DE2564 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A089B901B67CE0748AA88C4BD50D57D1 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6E483D6F0FD50C40ACCCFA653326EF7 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A9D48A1CC619EDC468E3B4D3054DE891 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AECE2176AF5E1864BAC440F0D02CD58A => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3046214DAEE6A246B8B6E7316B31906 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B7027658A0B8E774F91A80F4FCC40224 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE2B910A814CFB341B13B3D3D9BB9F6F => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C59542720E53D354A92DDB9A447346B9 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCFCCC1891E40904899A3566879D171A => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D0DFCD17461DFDA41B4E04D271B0FBE5 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D29A65A3104E2C340BFE40FAE8A91267 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3873A30E6162ED47BA0AB95A3CDDA5F => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D60BE5613DFE6AC4C93F1F835DCEE1E2 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DEB9571C8E6CC1B4BA6F7D22A9DF81BB => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E02821297F70E6F44B20D83CD953476D => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3C649A9849FBA143943CAA1B6FB6150 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED0F7BCDE5F677D4797D7B485A475F70 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F39C202861CC5394D92BC01541F13711 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA6CDD7CC8A73B242826081F921A23E4 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0E641459FF949304FA85227505C6D754 => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0E641459FF949304FA85227505C6D754 => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DB2E967B60A830B44969B59901522A6C => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DB2E967B60A830B44969B59901522A6C => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-stop.com => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-stop.com => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-stop.com => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-stop.com => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\CheckPoint\ZoneAlarm => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\CheckPoint\ZoneAlarm => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-stop.com => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-stop.com => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-stop.com => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-stop.com => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B769E2BD-8A06-4B03-9496-5B991025A2C6} => key removed successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-download-now.com => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-download-now.com => key removed successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-download-now.com => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-download-now.com => key removed successfully
HKEY_USERS\S-1-5-21-95435350-4265177964-2103988519-1001\Software\CheckPoint => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_USERS\S-1-5-21-95435350-4265177964-2103988519-1001\Software\CheckPoint => key removed successfully
HKEY_USERS\S-1-5-21-95435350-4265177964-2103988519-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-stop.com => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_USERS\S-1-5-21-95435350-4265177964-2103988519-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-stop.com => key removed successfully
HKEY_USERS\S-1-5-21-95435350-4265177964-2103988519-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-stop.com => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_USERS\S-1-5-21-95435350-4265177964-2103988519-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-stop.com => key removed successfully
HKEY_USERS\S-1-5-21-95435350-4265177964-2103988519-1001\Software\Zone Labs => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_USERS\S-1-5-21-95435350-4265177964-2103988519-1001\Software\Zone Labs => key removed successfully
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\zonealarm-download-now.com => key not found.
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\zonealarm-download-now.com => key not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSDATANT => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSDATANT => key removed successfully
EmptyTemp: => 181.7 MB temporary data Removed.
The system needed a reboot..
==== End of Fixlog 20:43:08 ====