Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Computer slow and unresponsive


  • This topic is locked This topic is locked

#1
Soloinneed

Soloinneed

    New Member

  • Member
  • Pip
  • 8 posts

Hello, recently my computer has been unable to open up applications. When applications are launched they last for about 10 mins before the whole computer freezes.

 

One important note: I only have 5- 10 mins to type this message before my whole computer freezes.

 

here are some examples:

 

1) when playing games, about 10 mins in game play the game would freeze. When I try to launch task manager, the computer in unresponsive

 

2) when trying to double click top open an application, for example, the Steam desktop item, it is unresponsive

 

3) my computer is noticeable slower than before

 

Thank you

 

Here is my log:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-05-2017
Ran by Solo Bolo (administrator) on DESKTOP-G2DJP68 (12-05-2017 00:19:46)
Running from C:\Users\Solo Bolo\Desktop
Loaded Profiles: Solo Bolo (Available Profiles: defaultuser0 & Solo Bolo)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Scarlet.Crush Productions) C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Micro-Star INT'L CO., LTD.) C:\MSI\MSIRegister\MSIRegisterService.exe
(MSI) C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe
(MSI) C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.SmartMonitor.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.551\SSScheduler.exe
(Micro-Star INT'L CO., LTD.) C:\MSI\MSIRegister\MSIRegister.exe
(Scarlet.Crush Productions) C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.1051_none_7f2bf7ea21d201b2\TiWorker.exe
(Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdupd.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Solo Bolo\Desktop\FRST64 (1).exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10}] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1610936 2016-09-14] (COMODO)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843520 2016-10-21] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-05-10] (AVAST Software)
HKLM-x32\...\Run: [MSIRegister] => C:\MSI\MSIRegister\MSIRegister.exe [4131792 2016-10-21] (Micro-Star INT'L CO., LTD.)
HKLM-x32\...\Run: [Command Center] => C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe [835680 2016-10-21] (MSI)
HKU\S-1-5-21-534414204-3113082749-4167303694-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3019552 2017-04-30] (Valve Corporation)
HKU\S-1-5-21-534414204-3113082749-4167303694-1001\...\RunOnce: [Uninstall C:\Users\Solo Bolo\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Solo Bolo\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"
Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-05-10] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-05-10] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-05-08]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.551\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScpToolkit Tray Notifications.lnk [2017-04-01]
ShortcutTarget: ScpToolkit Tray Notifications.lnk -> C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe (Scarlet.Crush Productions)
Startup: C:\Users\Solo Bolo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2017-05-08]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{b982c36c-4f0b-49c2-9526-92fde2393bca}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-05-08] (Intel Security)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-04-30] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-04-30] (Microsoft Corporation)
BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-05-08] (Intel Security)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-04-30] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-04-30] (Microsoft Corporation)
Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-05-08] (Intel Security)
Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-05-08] (Intel Security)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-04-30] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-04-30] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-04-30] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-04-30] (Microsoft Corporation)
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-10] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-10] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-03-05] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-03-05] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-02-26] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-02-26] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-30] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-30] (Google Inc.)
FF Plugin HKU\S-1-5-21-534414204-3113082749-4167303694-1001: tdameritrade.com/thinkorswim -> C:\Program Files\thinkorswim\npthinkorswim.dll [2017-05-11] (TD Ameritrade)
FF Plugin HKU\S-1-5-21-534414204-3113082749-4167303694-1001: tdameritrade.com/tossc -> C:\Program Files\thinkorswim\nptossc.dll [2017-05-11] (TD Ameritrade)
 
Chrome: 
=======
CHR Profile: C:\Users\Solo Bolo\AppData\Local\Google\Chrome\User Data\Default [2017-05-12]
CHR Extension: (Google Slides) - C:\Users\Solo Bolo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-21]
CHR Extension: (Google Docs) - C:\Users\Solo Bolo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-21]
CHR Extension: (Google Drive) - C:\Users\Solo Bolo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-21]
CHR Extension: (YouTube) - C:\Users\Solo Bolo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-21]
CHR Extension: (Google Sheets) - C:\Users\Solo Bolo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-21]
CHR Extension: (Google Docs Offline) - C:\Users\Solo Bolo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-21]
CHR Extension: (AdBlock) - C:\Users\Solo Bolo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-05-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Solo Bolo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-19]
CHR Extension: (Gmail) - C:\Users\Solo Bolo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-21]
CHR Extension: (Chrome Media Router) - C:\Users\Solo Bolo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-07]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7346208 2017-05-10] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263304 2017-05-10] (AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3801280 2017-04-30] (Microsoft Corporation)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5817256 2016-09-15] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2271928 2016-09-14] (COMODO)
R2 Ds3Service; C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpService.exe [389632 2016-01-10] (Scarlet.Crush Productions) [File not signed]
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.551\McCHSvc.exe [404376 2017-05-08] (McAfee, Inc.)
S3 MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [4172752 2016-10-21] (MSI)
S3 MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\MSICommService.exe [2200872 2016-10-21] (MSI)
S3 MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe [4160976 2016-10-21] (MSI)
R2 MSICTL_CC; C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe [2014160 2016-10-21] (MSI)
R2 MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [2326992 2016-10-21] (MSI)
R2 MSIREGISTER_MR; C:\MSI\MSIRegister\MSIRegisterService.exe [112592 2016-10-21] (Micro-Star INT'L CO., LTD.)
S3 MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe [2075600 2016-10-21] (MSI)
S3 MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [596944 2016-10-21] (MSI)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-01-10] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-01-10] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2017-02-26] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2017-01-10] (NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-10-21] (Microsoft Corporation)
R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [996736 2017-05-08] (McAfee, Inc.)
R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16160 2017-05-08] (McAfee, Inc.)
R2 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86776 2017-05-08] (McAfee, Inc.)
S3 updater; C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpUpdater.exe [464384 2016-01-10] (Nefarius Software Solutions) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2017-04-11] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2017-04-11] (Microsoft Corporation)
S2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [311808 2017-05-10] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [190256 2017-05-10] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334576 2017-05-10] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [49016 2017-05-10] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-05-10] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [32600 2017-05-10] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [128648 2017-05-10] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [101152 2017-05-10] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-05-10] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1007160 2017-05-10] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [569192 2017-05-10] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [158368 2017-05-10] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [339696 2017-05-10] (AVAST Software)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [40960 2016-09-08] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [862648 2016-09-08] (COMODO)
R1 cmdhlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [54336 2016-09-08] (COMODO)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131712 2016-11-19] (Samsung Electronics Co., Ltd.)
R3 iaLPSS2_GPIO2; C:\Windows\System32\drivers\iaLPSS2_GPIO2.sys [84264 2016-10-21] (Intel Corporation)
R3 iaLPSS2_I2C; C:\Windows\System32\drivers\iaLPSS2_I2C.sys [185128 2016-10-21] (Intel Corporation)
R1 inspect; C:\Windows\system32\DRIVERS\inspect.sys [147304 2016-09-08] (COMODO)
S3 libusbK; C:\Windows\System32\drivers\libusbK.sys [47200 2016-10-24] (hxxp://libusb-win32.sourceforge.net)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 NTIOLib_MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\NTIOLib_X64.sys [13368 2016-10-21] (MSI)
S3 NTIOLib_MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\NTIOLib_X64.sys [13368 2016-10-21] (MSI)
S3 NTIOLib_MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\NTIOLib_X64.sys [13368 2016-10-21] (MSI)
R3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2016-10-21] (MSI)
S3 NTIOLib_MSIFrequency_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\CPU_Frequency\NTIOLib_X64.sys [13368 2016-10-21] (MSI)
S3 NTIOLib_MSIRatio_CC; C:\Program Files (x86)\MSI\Command Center\CPU\CPU_Ratio\NTIOLib_X64.sys [13368 2016-10-21] (MSI)
S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\NTIOLib_X64.sys [13368 2016-10-21] (MSI)
S3 NTIOLib_MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\NTIOLib_X64.sys [13368 2016-10-21] (MSI)
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispiwu.inf_amd64_b67dc924fff8de6d\nvlddmkm.sys [14199224 2017-02-26] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-11] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [46016 2017-01-10] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2016-10-21] (Realtek                                            )
R3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [5195776 2016-07-16] (Realtek Semiconductor Corporation                           )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [165504 2016-11-19] (Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-05-12 00:19 - 2017-05-12 00:20 - 00021299 _____ C:\Users\Solo Bolo\Desktop\FRST.txt
2017-05-12 00:19 - 2017-05-12 00:19 - 02429440 _____ (Farbar) C:\Users\Solo Bolo\Desktop\FRST64 (1).exe
2017-05-12 00:18 - 2017-05-12 00:18 - 00013556 _____ C:\Users\Solo Bolo\Downloads\Addition.txt
2017-05-12 00:16 - 2017-05-12 00:18 - 00034313 _____ C:\Users\Solo Bolo\Downloads\FRST.txt
2017-05-12 00:16 - 2017-05-12 00:16 - 02429440 _____ (Farbar) C:\Users\Solo Bolo\Downloads\FRST64.exe
2017-05-12 00:16 - 2017-05-12 00:16 - 00000000 ____D C:\FRST
2017-05-11 01:35 - 2017-05-11 01:35 - 00000000 ___HD C:\$SysReset
2017-05-11 00:48 - 2017-05-11 00:48 - 00000000 _____ C:\Windows\SysWOW64\last.dump
2017-05-10 22:43 - 2017-05-10 22:41 - 00532136 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2017-05-10 22:36 - 2017-05-10 22:36 - 00400456 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-05-10 22:30 - 2017-05-10 22:30 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-05-08 23:02 - 2017-05-08 23:04 - 00000000 ____D C:\Users\Solo Bolo\Documents\OneNote Notebooks
2017-05-08 20:10 - 2017-05-08 20:10 - 00000000 ____D C:\Users\Solo Bolo\AppData\Local\tkdata
2017-05-08 20:09 - 2017-05-08 20:09 - 00001242 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\True Key.lnk
2017-05-08 20:09 - 2017-05-08 20:09 - 00001228 _____ C:\Users\Public\Desktop\True Key.lnk
2017-05-08 20:09 - 2017-05-08 20:09 - 00000000 ____D C:\ProgramData\TrueKey
2017-05-08 20:09 - 2017-05-08 20:09 - 00000000 ____D C:\Program Files\Common Files\Intel
2017-05-08 20:08 - 2017-05-10 22:29 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-05-08 20:08 - 2017-05-08 20:08 - 00000000 ____D C:\Program Files\Intel Security
2017-05-08 20:08 - 2017-05-08 20:08 - 00000000 ____D C:\Program Files\Common Files\McAfee
2017-05-08 01:28 - 2017-05-08 01:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2017-05-08 01:28 - 2017-05-08 01:28 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2017-05-08 01:28 - 2017-05-08 01:28 - 00000000 ____D C:\Program Files\McAfee Security Scan
2017-05-08 00:58 - 2017-05-12 00:16 - 00004608 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-05-08 00:58 - 2017-05-10 22:29 - 00000000 ____D C:\Program Files\TrueKey
2017-05-08 00:58 - 2017-05-09 20:23 - 00000000 ____D C:\ProgramData\McAfee
2017-05-08 00:58 - 2017-05-08 01:28 - 00002009 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2017-05-08 00:57 - 2017-05-08 00:59 - 00000000 ____D C:\Users\Solo Bolo\AppData\Local\Adobe
2017-05-07 20:23 - 2017-05-07 20:23 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUSB_01007.Wdf
2017-05-07 20:22 - 2017-05-07 20:22 - 00000000 ____D C:\Users\Solo Bolo\.android
2017-05-07 20:21 - 2017-05-07 20:21 - 40284968 _____ (FonePaw ) C:\Users\Solo Bolo\Downloads\android-data-recovery.exe
2017-05-07 20:21 - 2017-05-07 20:21 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll
2017-05-07 20:21 - 2017-05-07 20:21 - 00708168 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller.dll
2017-05-07 20:21 - 2017-05-07 20:21 - 00000000 ____D C:\Users\Solo Bolo\AppData\Local\FonePaw
2017-05-07 20:21 - 2017-05-07 20:21 - 00000000 ____D C:\Program Files (x86)\FonePaw
2017-05-07 12:38 - 2017-05-07 12:38 - 00000000 ____D C:\Users\Solo Bolo\AppData\Roaming\Publish Providers
2017-05-07 12:36 - 2017-05-07 11:54 - 00001135 _____ C:\Users\Solo Bolo\Desktop\Vegas Pro 13.0 (64-bit).lnk
2017-05-07 12:27 - 2017-05-07 12:34 - 00000000 ____D C:\Users\Solo Bolo\Downloads\SonyVegasPro13.0Build29064BitMultilingualChingLiu
2017-05-07 12:27 - 2017-05-07 12:27 - 00017398 _____ C:\Users\Solo Bolo\Downloads\SonyVegasPro13.0Build29064BitMultilingualChingLiu_archive (1).torrent
2017-05-07 12:17 - 2017-05-07 12:17 - 00002117 _____ C:\Users\Solo Bolo\Desktop\FL Studio 12 (64bit).lnk
2017-05-07 12:17 - 2017-05-07 12:17 - 00000000 ____D C:\Users\Solo Bolo\Documents\Image-Line
2017-05-07 12:17 - 2017-05-07 12:17 - 00000000 ____D C:\Users\Solo Bolo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2017-05-07 12:17 - 2017-05-07 12:17 - 00000000 ____D C:\Users\Solo Bolo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
2017-05-07 12:17 - 2017-05-07 12:17 - 00000000 ____D C:\Users\Solo Bolo\AppData\Roaming\Image-Line
2017-05-07 12:17 - 2017-05-07 12:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
2017-05-07 12:17 - 2017-05-07 12:17 - 00000000 ____D C:\Program Files\Image-Line
2017-05-07 12:17 - 2017-05-07 12:17 - 00000000 ____D C:\Program Files\Common Files\VST2
2017-05-07 12:17 - 2017-05-07 12:17 - 00000000 ____D C:\Program Files\Common Files\Propellerhead Software
2017-05-07 12:17 - 2017-05-07 12:17 - 00000000 ____D C:\Program Files (x86)\VstPlugins
2017-05-07 12:17 - 2017-05-07 12:17 - 00000000 ____D C:\Program Files (x86)\ASIO4ALL v2
2017-05-07 12:16 - 2017-05-07 12:16 - 00017398 _____ C:\Users\Solo Bolo\Downloads\SonyVegasPro13.0Build29064BitMultilingualChingLiu_archive.torrent
2017-05-07 12:13 - 2017-05-07 12:14 - 02403520 _____ (BitTorrent Inc.) C:\Users\Solo Bolo\Downloads\uTorrent.exe
2017-05-07 12:11 - 2017-05-07 12:17 - 00000000 ____D C:\Program Files (x86)\Image-Line
2017-05-07 12:09 - 2017-05-07 12:09 - 41942707 _____ C:\Users\Solo Bolo\Downloads\Unconfirmed 943625.crdownload
2017-05-07 12:07 - 2017-05-07 12:08 - 41942707 _____ C:\Users\Solo Bolo\Downloads\Unconfirmed 368439.crdownload
2017-05-07 11:54 - 2017-05-07 11:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2017-05-07 11:53 - 2017-05-07 11:53 - 00000000 ____D C:\ProgramData\Sony
2017-05-07 11:53 - 2017-05-07 11:53 - 00000000 ____D C:\Program Files\Sony
2017-05-07 11:53 - 2017-05-07 11:53 - 00000000 ____D C:\Program Files (x86)\Sony
2017-05-07 11:51 - 2017-05-07 12:10 - 697470424 _____ (Image-Line) C:\Users\Solo Bolo\Downloads\flstudio_12.4.2.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-05-12 00:16 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-05-12 00:16 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\system32\Macromed
2017-05-12 00:15 - 2016-10-21 01:33 - 01742038 _____ C:\Windows\system32\PerfStringBackup.INI
2017-05-12 00:13 - 2016-10-21 01:43 - 00000000 ____D C:\Program Files (x86)\Steam
2017-05-12 00:09 - 2017-01-10 21:02 - 00000000 ____D C:\ProgramData\NVIDIA
2017-05-12 00:08 - 2016-10-21 04:23 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-05-12 00:08 - 2016-10-21 04:23 - 00000000 ____D C:\Windows\system32\SleepStudy
2017-05-11 01:24 - 2016-10-21 01:31 - 00000000 ____D C:\Users\Solo Bolo
2017-05-11 01:23 - 2016-07-16 07:36 - 00000000 ____D C:\Windows\CbsTemp
2017-05-11 00:51 - 2016-07-16 02:04 - 00262144 _____ C:\Windows\system32\config\BBI
2017-05-11 00:47 - 2017-03-31 21:38 - 00000000 ____D C:\Program Files\thinkorswim
2017-05-11 00:47 - 2017-03-31 19:50 - 00000000 ____D C:\Users\Solo Bolo\.thinkorswim
2017-05-10 23:31 - 2016-10-21 12:07 - 00000000 ____D C:\Windows\system32\MRT
2017-05-10 23:28 - 2016-10-21 12:07 - 156335152 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-05-10 23:28 - 2016-07-16 07:49 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-05-10 23:28 - 2016-07-16 07:49 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-05-10 22:37 - 2017-02-12 02:30 - 00003994 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-05-10 22:37 - 2016-10-21 01:40 - 00004022 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1477028416
2017-05-10 22:37 - 2016-10-21 01:40 - 00001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-05-10 22:36 - 2016-10-21 01:39 - 00569192 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-05-10 22:36 - 2016-10-21 01:39 - 00339696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-05-10 22:36 - 2016-10-21 01:39 - 00158368 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-05-10 22:36 - 2016-10-21 01:39 - 00128648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-05-10 22:36 - 2016-10-21 01:39 - 00101152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-05-10 22:36 - 2016-10-21 01:39 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-05-10 22:36 - 2016-10-21 01:39 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-05-10 22:35 - 2017-02-12 02:30 - 00334576 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-05-10 22:35 - 2017-02-12 02:30 - 00311808 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-05-10 22:35 - 2017-02-12 02:30 - 00190256 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-05-10 22:35 - 2017-02-12 02:30 - 00049016 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-05-10 22:35 - 2016-10-21 01:39 - 01007160 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-05-10 22:35 - 2016-10-21 01:39 - 00032600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2017-05-10 22:32 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\AppReadiness
2017-05-09 20:26 - 2016-07-16 07:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-05-09 20:24 - 2016-10-21 01:40 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-09 20:24 - 2016-10-21 01:40 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-05-08 23:22 - 2017-03-31 23:25 - 00000000 ____D C:\Users\Solo Bolo\.oanda
2017-05-08 20:08 - 2017-02-05 14:43 - 00000000 ____D C:\Program Files\Common Files\AV
2017-05-08 00:58 - 2016-11-19 23:12 - 00004386 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-05-07 20:23 - 2016-07-16 07:45 - 00000000 ____D C:\Windows\INF
2017-05-07 12:38 - 2017-04-03 17:32 - 00000000 ____D C:\Users\Solo Bolo\AppData\Roaming\NVIDIA
2017-05-07 12:38 - 2017-01-21 14:30 - 00000000 ____D C:\Users\Solo Bolo\AppData\Roaming\Sony
2017-05-07 12:38 - 2016-10-21 01:31 - 00000000 ____D C:\Users\Solo Bolo\AppData\Local\VirtualStore
2017-05-07 12:35 - 2017-01-11 23:42 - 00000000 ____D C:\Users\Solo Bolo\AppData\Local\CrashDumps
2017-05-07 12:17 - 2017-03-01 14:04 - 01562432 _____ (HMS hxxp://hp.vector.co.jp/authors/VA012897/) C:\Windows\system32\vorbis.acm
2017-05-07 12:16 - 2017-03-01 14:05 - 01456448 _____ (HMS hxxp://hp.vector.co.jp/authors/VA012897/) C:\Windows\SysWOW64\vorbis.acm
2017-05-07 11:54 - 2017-01-21 14:31 - 00044608 _____ C:\Windows\system32\--traceoff
2017-05-07 11:53 - 2017-01-21 14:31 - 00000000 ____D C:\Users\Solo Bolo\AppData\Local\Sony
2017-05-07 11:50 - 2016-10-21 01:31 - 00000000 ____D C:\Users\Solo Bolo\AppData\Local\Packages
2017-05-07 11:48 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\system32\appraiser
2017-05-07 11:47 - 2016-07-16 07:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-05-07 11:45 - 2016-10-21 02:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-04-30 13:59 - 2016-10-21 01:39 - 00003416 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-30 13:59 - 2016-10-21 01:39 - 00003292 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-12 15:58 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\LiveKernelReports
2017-04-12 15:00 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\rescache
2017-04-12 13:26 - 2016-10-21 02:46 - 00000000 ____D C:\Users\Solo Bolo\Documents\American Truck Simulator
 
==================== Files in the root of some directories =======
 
2016-10-21 02:10 - 2016-10-21 02:10 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-05-07 12:22
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-05-2017
Ran by Solo Bolo (12-05-2017 00:20:13)
Running from C:\Users\Solo Bolo\Desktop
Windows 10 Pro Version 1607 (X64) (2016-10-21 05:29:45)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-534414204-3113082749-4167303694-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-534414204-3113082749-4167303694-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-534414204-3113082749-4167303694-1000 - Limited - Disabled) => C:\Users\defaultuser0
Guest (S-1-5-21-534414204-3113082749-4167303694-501 - Limited - Disabled)
Solo Bolo (S-1-5-21-534414204-3113082749-4167303694-1001 - Administrator - Enabled) => C:\Users\Solo Bolo
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
FW: COMODO Firewall (Enabled) {E8F7F446-E1BD-DFE6-38D1-54E0ADE01D89}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 16.04 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.171 - Adobe Systems Incorporated)
Adobe Flash Player 25 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 25.0.0.171 - Adobe Systems Incorporated)
Amazon Kindle (HKU\S-1-5-21-534414204-3113082749-4167303694-1001\...\Amazon Kindle) (Version: 1.17.1.44183 - Amazon)
American Truck Simulator (HKLM\...\Steam App 270880) (Version:  - SCS Software)
Ansel (Version: 376.33 - NVIDIA Corporation) Hidden
ArtMoney SE v7.35.2 (HKLM-x32\...\ArtMoney SE_is1) (Version: 7.35 - System SoftLab)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.12 - Michael Tippach)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.4.2294 - AVAST Software)
Blackboard Collaborate Launcher (HKLM-x32\...\{AEED1D32-C837-405A-8009-6660E3883C9E}) (Version: 1.6.4.0 - Blackboard)
Cities Skylines (HKLM-x32\...\Cities Skylines_is1) (Version: 1.5.0-f4 - RePack by Valdeni)
COMODO Firewall (HKLM\...\{C7C71F0C-4CC1-4B17-943C-96E5196DDA74}) (Version: 8.4.0.5165 - COMODO Security Solutions Inc.)
Empire: Total War (HKLM\...\Steam App 10500) (Version:  - The Creative Assembly)
FL Studio 12 (HKLM-x32\...\FL Studio 12) (Version:  - Image-Line)
FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version:  - Image-Line)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.110 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
IL Download Manager (HKLM-x32\...\IL Download Manager) (Version:  - Image-Line)
Intel Security True Key (HKLM\...\TrueKey) (Version: 4.16.112.1 - Intel Security)
Intel® Chipset Device Software (x32 Version: 10.1.1.9 - Intel® Corporation) Hidden
Intel® Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.63.1519.7 - Intel Corporation)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.551.2 - McAfee, Inc.)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.7967.2139 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-534414204-3113082749-4167303694-1001\...\OneDriveSetup.exe) (Version: 17.3.6799.0327 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
MotioninJoy Gamepad tool 0.7.1001 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.7.1001 - www.motioninjoy.com)
MSI Command Center (HKLM-x32\...\{85A2564E-9ED9-448A-91E4-B9211EE58A08}_is1) (Version: 2.0.0.32 - MSI)
MSIRegister (HKLM-x32\...\{80B995A4-3A86-4690-98A6-563F1A788835}_is1) (Version: 1.0.0.07 - MSI)
NVIDIA 3D Vision Driver 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.53 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.1.2.31 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.1.2.31 - NVIDIA Corporation)
NVIDIA Graphics Driver 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.53 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.17 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
NvNodejs (Version: 3.1.2.31 - NVIDIA Corporation) Hidden
NvTelemetry (Version: 1.2.0.0 - NVIDIA Corporation) Hidden
OANDA Desktop (HKLM-x32\...\{389BF1E4-58A8-4DB5-B16B-C39C0FE9EBB3}) (Version: 2.6.2 - OANDA)
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7967.2139 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7967.2139 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7967.2139 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7668.2074 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.6.1001.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7730 - Realtek Semiconductor Corp.)
SafeZone Stable 3.55.2393.596 (x32 Version: 3.55.2393.596 - Avast Software) Hidden
ScpToolkit (HKLM\...\{AC052048-9828-45E3-872B-04CE30A3B58B}) (Version: 1.6.238.16010 - Nefarius Software Solutions)
SHIELD Streaming (Version: 7.1.0340 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 3.1.2.31 - NVIDIA Corporation) Hidden
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamSpeak 3 Client (HKU\S-1-5-21-534414204-3113082749-4167303694-1001\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
thinkorswim (HKLM\...\9968-4488-2169-7623) (Version: desktop - thinkorswim, Inc)
Total War: SHOGUN 2 (HKLM\...\Steam App 34330) (Version:  - The Creative Assembly)
TruckersMP Launcher 1.0.0.4 (HKLM\...\{A227B892-C548-4490-9C5D-DB341F8194A6}_is1) (Version: 1.0.0.4 - TruckersMP Team)
Vegas Pro 13.0 (64-bit) (HKLM\...\{CDA02BF0-BFBC-11E3-AFA0-F04DA23A5C58}) (Version: 13.0.290 - Sony)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {16453115-CF09-4919-96EE-BD93B737AC7B} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-05-10] (AVAST Software)
Task: {2D8BDF82-909D-4308-9CDF-CB66D313FC64} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-09-14] (COMODO)
Task: {39D3D09C-FEF8-476D-A773-B52E1B1D5003} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-05-07] (AVAST Software)
Task: {6018F1D2-2F11-4467-907C-515073B5B88C} - System32\Tasks\updater => C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpUpdater.exe [2016-01-10] (Nefarius Software Solutions)
Task: {6465FDAF-F25C-4302-A4C7-916B706EF215} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-04-30] (Microsoft Corporation)
Task: {6BD29220-4A12-4E1C-B17B-D5C7D0AF380C} - System32\Tasks\SafeZone scheduled Autoupdate 1477028416 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-03-22] (Avast Software)
Task: {7CE88ECC-CFAB-460F-998B-222252A35C45} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-04-30] (Microsoft Corporation)
Task: {82008C6E-D9F5-4C94-A6A9-0F7F59CA19C4} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-01-10] (NVIDIA Corporation)
Task: {8B309E86-0C3E-46EB-B419-BC45738702AC} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-01-10] (NVIDIA Corporation)
Task: {9010427D-D57D-412D-889E-2FA03423B7F0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-21] (Google Inc.)
Task: {966A7C09-6C5B-4CDF-8378-3843F7925BC1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-21] (Google Inc.)
Task: {A0CEBC4F-0AD3-4D31-B397-24BE33593A23} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-01-10] (NVIDIA Corporation)
Task: {A318F81D-0DB8-4D85-BC9E-44FAA1891556} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-05-12] (Adobe Systems Incorporated)
Task: {ABF3EBD4-9108-4ADC-A444-10DBA92E73A9} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_25_0_0_171_pepper.exe [2017-05-12] (Adobe Systems Incorporated)
Task: {BBDBFD4E-4096-477F-BED1-ED168C84C74B} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-09-14] (COMODO)
Task: {C016822A-A50A-4C99-AC37-B5F888C0A9CD} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-01-10] (NVIDIA Corporation)
Task: {C611BFC0-3F72-4284-8D46-B98530FB925F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-04-30] (Microsoft Corporation)
Task: {C6139D82-425A-4B0C-9C7A-B859FC2A9A5F} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2016-09-14] (COMODO)
Task: {D7BDE258-9180-49F2-8FD5-59CF0A71EA86} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-01-10] (NVIDIA Corporation)
Task: {E28510FB-B68A-4FCF-93D1-D6F38D94620F} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-01-10] (NVIDIA Corporation)
Task: {FE952D52-20BC-40B4-B4A2-87EC941720FC} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-04-30] (Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-07-16 07:42 - 2016-07-16 07:42 - 00231424 _____ () C:\Windows\SYSTEM32\ism32k.dll
2017-04-11 18:38 - 2017-04-11 18:38 - 02681200 _____ () C:\Windows\system32\CoreUIComponents.dll
2017-01-10 21:02 - 2016-12-29 08:44 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-03-22 11:00 - 2017-03-22 11:00 - 00309760 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_64\ReactiveSockets\e02f07b40299b7750946b12ee5fb9064\ReactiveSockets.ni.dll
2014-05-02 11:52 - 2014-05-02 11:52 - 00599040 _____ () C:\Program Files\Nefarius Software Solutions\ScpToolkit\irrKlang\amd64\irrKlang.NET4.dll
2014-05-02 06:55 - 2014-05-02 06:55 - 00185344 _____ () C:\Program Files\Nefarius Software Solutions\ScpToolkit\irrKlang\amd64\ikpflac.dll
2014-05-02 06:05 - 2014-05-02 06:05 - 00173056 _____ () C:\Program Files\Nefarius Software Solutions\ScpToolkit\irrKlang\amd64\ikpmp3.dll
2017-01-10 21:02 - 2016-12-11 23:03 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-01-10 21:02 - 2016-12-11 23:03 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll
2017-01-10 21:02 - 2016-12-11 23:03 - 00418752 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem\_nvspserviceplugin64.dll
2017-04-11 18:38 - 2017-04-11 18:38 - 02681200 _____ () C:\Windows\SYSTEM32\CoreUIComponents.dll
2016-11-18 02:19 - 2017-04-30 14:06 - 08931008 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2016-10-21 12:03 - 2016-10-21 12:03 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-03-14 23:44 - 2017-03-14 23:44 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-03-14 23:45 - 2017-03-14 23:45 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-03-14 23:45 - 2017-03-14 23:45 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-14 23:45 - 2017-03-14 23:45 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-04-11 18:38 - 2017-04-11 18:38 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-04-11 18:38 - 2017-04-11 18:38 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-04-11 18:38 - 2017-04-11 18:38 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-05-09 20:24 - 2017-05-09 05:13 - 03767640 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libglesv2.dll
2017-05-09 20:24 - 2017-05-09 05:13 - 00100696 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libegl.dll
2017-05-09 20:26 - 2017-05-09 20:26 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-05-09 20:26 - 2017-05-09 20:26 - 00201728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-05-09 20:26 - 2017-05-09 20:26 - 43195904 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-05-09 20:26 - 2017-05-09 20:26 - 02457088 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\skypert.dll
2017-01-10 21:02 - 2016-12-11 23:03 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2017-01-10 21:02 - 2017-01-10 20:59 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll
2017-01-10 21:02 - 2016-12-11 23:03 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-05-10 22:35 - 2017-05-10 22:35 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-05-10 22:36 - 2017-05-10 22:36 - 00997896 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll
2017-05-10 22:36 - 2017-05-10 22:36 - 67717632 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-05-10 22:35 - 2017-05-10 22:35 - 00176992 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-05-10 22:35 - 2017-05-10 22:35 - 00223224 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-05-10 22:35 - 2017-05-10 22:35 - 00291824 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-01-10 21:02 - 2016-12-11 23:03 - 00506424 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node
2017-01-10 21:02 - 2016-12-11 23:03 - 00252352 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node
2017-01-10 21:02 - 2016-12-11 23:03 - 02809912 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node
2017-01-10 21:02 - 2016-12-11 23:03 - 00245184 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node
2017-01-10 21:02 - 2016-12-11 23:03 - 00436792 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node
2017-01-10 21:02 - 2016-12-11 23:03 - 00338488 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node
2017-01-10 21:02 - 2016-12-11 23:03 - 00968248 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvCameraAPINode.node
2016-10-21 01:45 - 2017-03-09 20:13 - 00674592 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2016-10-21 01:45 - 2016-08-31 21:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll
2016-10-21 01:45 - 2017-04-25 19:55 - 02465056 _____ () C:\Program Files (x86)\Steam\video.dll
2016-10-21 01:45 - 2016-08-31 21:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2016-10-21 01:45 - 2016-08-31 21:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2016-10-21 01:45 - 2016-01-27 03:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2016-10-21 01:45 - 2016-01-27 03:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2016-10-21 01:45 - 2016-01-27 03:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2016-10-21 01:45 - 2016-01-27 03:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2016-10-21 01:45 - 2016-01-27 03:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2016-10-21 01:45 - 2017-04-25 19:55 - 00848672 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2017-01-07 22:18 - 2017-01-30 17:41 - 68875552 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
2016-10-21 01:45 - 2015-09-24 19:52 - 00119208 _____ () C:\Program Files (x86)\Steam\winh264.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Windows\avastSS.scr:$CmdTcID [64]
AlternateDataStreams: C:\Windows\explorer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\HelpPane.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\NvContainerRecovery.bat:$CmdTcID [64]
AlternateDataStreams: C:\Windows\regedit.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\splwow64.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aadcloudap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aadtb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AboveLockAppHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\accountaccessor.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AccountsRt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aclui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\acmigration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ACPBackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AcpiServiceVnA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\ActionCenter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ActionCenterCPL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ActivationManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ActiveSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\actxprxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AddressParser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\adsmsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aeinv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aepic.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AERTAC64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\AERTAR64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\aitstatic.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppCapture.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppContracts.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\appinfo.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ApplicationFrame.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppointmentActivation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppointmentApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\appraiser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppReadiness.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\apprepapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\apprepsync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVCatalog.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVClient.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVDllSurrogate.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVEntStreamingManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVEntSubsystemController.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVEntSubsystems64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\AppVEntVirtualization.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVIntegration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVManifest.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVOrchestration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVPublishing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVReporting.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVScripting.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVShNotify.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\appwiz.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppXApplicabilityBlob.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppXDeploymentClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppXDeploymentExtensions.desktop.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppXDeploymentExtensions.onecore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppXDeploymentServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppxPackaging.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\asycfilt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atmfd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atmlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AudioEndpointBuilder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AudioEng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AUDIOKSE.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\audioLibVc.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\AudioSes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\audiosrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AudioSrvPolicyManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AuthBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AuthHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\authui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\autoplay.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AzureSettingSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\baaupdate.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BackgroundMediaPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BarcodeProvisioningPlugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\basecsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bcastdvr.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BcastDVRHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bcdedit.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bcrypt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bdechangepin.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bdesvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bdeui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bdeunlock.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BingMaps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BingOnlineServices.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bisrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BitLockerDeviceEncryption.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\biwinrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BluetoothApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BluetoothDesktopHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BootMenuUX.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bootux.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\browserbroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BrowserSettingSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BthRadioMedia.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CameraCaptureUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CastLaunch.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CbtBackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cdd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cdp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cdpsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cdpusersvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CellularAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cemapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CertEnroll.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\certprop.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CfgSPCellular.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Chakra.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Chakradiag.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Chakrathunk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\chartv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ChatApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ci.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ClipboardServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ClipUp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cloudAP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudBackupSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudDomainJoinDataModelServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudExperienceHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudExperienceHostBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudExperienceHostCommon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudExperienceHostUser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudStorageWizard.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\clusapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cmifw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cmintegrator.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\combase.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\comdlg32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CompatTelRunner.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CompPkgSup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\comsvcs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CONEQMSAPOGUILibrary.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\ConsoleLogon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ContactActivation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ContactApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\container.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ContentDeliveryManager.Utilities.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CoreMessaging.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CoreUIComponents.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\CPFilters.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CredProvDataModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\credprovhost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\credprovs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\credprovslegacy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\crypt32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cryptngc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CryptoWinRT.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cryptui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cscui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CspCellularSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\csrsrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CX64APO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\C_G18030.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\c_GSM7.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\C_IS2022.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d2d1.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\d3d10warp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3d11.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3D12.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3d9.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_33.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_34.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_35.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_36.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_37.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_38.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_39.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_47.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dcsx_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_33.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_34.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_35.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_36.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_37.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_38.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_39.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_43.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\d3dx11_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx11_43.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\d3dx9_24.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_25.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_26.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_27.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_28.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_29.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_30.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\d3dx9_31.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\d3dx9_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_33.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_34.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_35.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_36.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_37.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_38.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_39.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_40.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_41.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_43.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\dab.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dafBth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dafpos.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DafPrintProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\das.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dasHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DataExchange.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DataSenseHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DavSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\daxexec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dbgeng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DbgModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dcntel.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DdcWnsListener.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DDPA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPA64F3.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPD64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPD64AF3.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPO64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPO64AF3.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPP64AF3.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\ddraw.dll:$CmdTcID [32]
AlternateDataStreams: C:\Windows\system32\ddrawex.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\delegatorprovider.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DeveloperOptionsSettingsHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\devenum.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\deviceaccess.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\deviceassociation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DeviceCensus.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DeviceCenter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DeviceDirectoryClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DeviceEnroller.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DeviceFlows.DataModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DevicePairing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DevicePairingFolder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DeviceReactivation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\devinv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dggpext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dhcpcore6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\diagtrack.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dialclient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dialserver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\discan.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Display.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DisplayManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dlnashext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dmcertinst.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dmenrollengine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DMRServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dnsapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dnsrslvr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DolbyDAX2APOProp.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DolbyDAX2APOv201.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DolbyDAX2APOv211.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DolbyDecMFT.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\domgmt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dosvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dpapisrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\drvstore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DscCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DscCoreConfProv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dsreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dsregcmd.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DTSBassEnhancementDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSBoostDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSGainCompensatorDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSGFXAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSGFXAPONS64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSLFXAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSLimiterDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSNeoPCDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSS2HeadphoneDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSS2SpeakerDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSSymmetryDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSU2PGFX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSU2PLFX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSU2PREC64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSVoiceClarityDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DuCsps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dui70.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dwmapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dwmcore.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DWrite.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dxgi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dxmasf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DXP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dxtrans.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EAMProgressHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eapp3hst.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eappcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eappgnui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eapphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eappprxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\easwrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\edgehtml.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EditBufferTestHook.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EditionUpgradeHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EditionUpgradeManagerObj.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EDPCleanup.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\efsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\efswrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EmailApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\encapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EncDec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\energy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\enrollmentapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EnterpriseAPNCsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EnterpriseAppMgmtSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\enterprisecsps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ErrorDetails.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ErrorDetailsUpdate.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\esent.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\esentutl.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\evr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ExplorerFrame.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ExSMime.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ExtrasXmlParser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\facecredentialprovider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Family.Authentication.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Family.Client.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Family.SyncEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ffbroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fhcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fhcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fhsettingsprovider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\FlightSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\flvprophandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\FMAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\FntCache.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\fontdrvhost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fontext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\FontProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\FrameServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\FSClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fveapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fveapibase.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fvecpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fvenotify.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fveprompt.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fveui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fvewiz.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\GamePanel.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\GamePanelExternalHook.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\gameux.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\gdi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\gdi32full.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\GdiPlus.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\generaltel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\GenValObj.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Geolocation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\GlobCollationHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\gpapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\gpsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\hal.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\HarmanAudioInterface.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\hevcdecoder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\hgcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\HiFiDAX2API.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMAPO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMClariFi.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMEQ.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMEQ_Voice.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMHVS.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMLimiter.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMUI.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HttpsDataSource.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\hvax64.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\hvix64.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\hvloader.efi:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\hvloader.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ICEsoundAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\icfupgd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\icm32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\icsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\icsvcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\IdCtrls.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ie4uinit.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ieapfltr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iedkcs32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ieframe.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iepeers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ieproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iernonce.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iertutil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iesetup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\imapi2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\imapi2fs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ImplatSetup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\indexeddbserver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\inetcomm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\inetcpl.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\input.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\InputLocaleManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\InputService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\InstallAgent.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\InstallAgentUserBroker.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\IntelSSTAPO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\IntelSstCApoPropPage.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\internetmail.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\invagent.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\IPHLPAPI.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iphlpsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ipnathlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iprtrmgr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iscsiwmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\JpMapControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\jscript9.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\jscript9diag.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\jsproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\KAAPORT64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\kdhvcom.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\kerberos.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\KernelBase.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\KnobsCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\KnobsCsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LaunchWinApp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LicenseManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LicenseManagerSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ListSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\localspl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LocationFramework.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LockAppBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LockAppHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LogonController.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\lpremove.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LsaIso.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\lsasrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\lsass.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\lsm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\main.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\manage-bde.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapConfiguration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapControlCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapControlStringsRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapGeocoder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapRouter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapsBtSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapsBtSvcProxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapsCSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapsStore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mapstoasttask.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mapsupdatetask.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO20.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO30.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO4064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO5064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO6064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO7064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPOShell64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioEQ64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioRealtek64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxSpeechAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxVoiceAPO2064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxVoiceAPO3064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxVoiceAPO4064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxVolumeSDAPO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MbaeApiPublic.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mbsmsapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MCCSEngineShared.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MCRecvSrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MDEServer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MDMAppInstaller.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mdmregistration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MediaFoundation.DefaultPerceptionProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfasfsrcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfaudiocnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MFCaptureEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfksproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MFMediaEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfmjpegdec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfmkvsrcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfmp4srcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfmpeg2srcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfnetcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfnetsrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfplat.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MFPlay.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfpmp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfreadwrite.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfsensorgroup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfsrcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfsvr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Microsoft-Windows-MapControls.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Microsoft-Windows-MosHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Microsoft-Windows-MosTrace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\microsoft-windows-system-events.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\migisol.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MiracastReceiver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mispace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MISS_APO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\mmc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MMDevAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\modernexecserver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mos.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\moshost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MosHostClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\moshostcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MosResource.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MosStorage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mprapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mprddm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mprdim.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MpSigStub.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MPSSVC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MrmCoreR.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MRT.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSAC3ENC.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSAJApi.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MSAudDecMFT.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mscandui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msctf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msctfp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msctfui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msdtcprx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msdtctm.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\msdtcuiu.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msdxm.ocx:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msfeeds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msftedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mshtml.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mshtmled.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msinfo32.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msmpeg2vdec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mspaint.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSPhotography.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mssitlb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mssph.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mssphtb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mssprxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mssrch.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mssvp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mstsc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mstscax.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msutb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msv1_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSVidCtl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSVideoDSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSVP9DEC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msvproc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSVPXENC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msxml3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msxml6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msxml6r.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MultiDigiMon.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\musdialoghandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MusNotification.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MusNotificationUx.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MusUpdateHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NAHIMICAPOlfx.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\NahimicAPONSControl.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\NAHIMICV2apo.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\NAHIMICV3apo.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\nativemap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NaturalLanguage6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ncsi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetCfgNotifyObjectHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\netiohlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\netiougc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\netplwiz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetSetupApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetSetupEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetSetupShim.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetSetupSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\netshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nettrace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetworkBindingEngineMigPlugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetworkCollectionAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetworkDesktopSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetworkMobileSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetworkUXBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NFCProvisioningPlugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NfcRadioMedia.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ngccredprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NgcCtnr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NgcCtnrGidsHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NgcCtnrSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ngcsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nltest.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NMAA.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\NmaDirect.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NotificationController.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NPSM.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nshwfp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ntdll.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ntshrui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvapi64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvaudcap64v.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvcompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvcuda.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvcuvid.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvDecMFTMjpeg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvdispco6437633.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvdispco6437653.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvdispgenco6437633.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvdispgenco6437653.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvEncMFTH264.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvEncodeAPI64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvfatbinaryLoader.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NvFBC64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\nvhdagenco6420103.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvhdap64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NvIFR64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NvIFROpenGL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvoglv64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvopencl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvptxJitCompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\odbcconf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\offlinelsa.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\offlinesam.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\offreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ole32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\oleacc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\oleaut32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\OnDemandConnRouteHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\OneBackupHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\OneDriveSettingSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\OpenCL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pcasvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PCPTpm12.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PhoneProviders.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PhoneService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PhoneServiceRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Phoneutil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PhoneutilRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PhotoScreensaver.scr:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pidgenx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PimIndexMaintenance.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Pimstore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PlayToDevice.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PlayToManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PlayToReceiver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pmcsnap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pnidui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\policymanager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\poqexec.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\POSyncServices.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\powercfg.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ppcsnap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PresentationNative_v0300.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PrintDialogs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PrintDialogs3D.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PrintRenderAPIHost.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PrintWSDAHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\profsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\provdatastore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\provengine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\provhandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\provisioningcsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\provops.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ProvPluginEng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ProvSysprep.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\provtool.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PsmServiceExtHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\psmsrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\puiapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\puiobj.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pwcreator.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pwrshplugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\qedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\qmgr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\quartz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\R4EEA64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\R4EED64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\R4EEG64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\R4EEL64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\R4EEP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RADCUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rasapi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rascustom.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rasgcw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rasmans.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RCoInstII64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\rdpcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rdpcorets.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rdpencom.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rdpinit.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RdpRelayTransport.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rdpshell.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rdpudd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RDXService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RDXTaskFactory.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ReAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ReAgentc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RelPost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\remoteaudioendpoint.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RemoteNaturalLanguage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RemovableMediaProvisioningPlugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ReportingCSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\reseteng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ResetEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ResetEngine.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\resutils.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RjvMDMConfig.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RltkAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RMapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RP3DAA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RP3DHT64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\rpcrt4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rshx32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RTCOM64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RtDataProc64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTEED64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTEEG64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTEEL64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTEEP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RtkApi64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RtkCfg64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RtkCoLDR64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RtlCPAPI64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTMediaFrame.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RtNicProp64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RtPgEx64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTSnMg64.cpl:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTWorkQ.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\samlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\samsrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sbe.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ScDeviceEnum.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\schannel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\scksp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sdengin2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sdshext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SEAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Search.ProtocolHandler.MAPI2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SearchFilterHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SearchFolder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SearchIndexer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SearchProtocolHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SecConfig.efi:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SECOMN64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SecureAssessmentHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\securekernel.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SEHDRA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\sendmail.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Sens.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SensorDataService.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SensorsApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SensorService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\services.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SessEnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers_Bluetooth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers_ClosedCaptioning.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers_Flights.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers_nt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers_StorageSense.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers_WorkAccess.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingSyncCore.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SettingSyncHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingSyncPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\setupugc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SFAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SFCOM64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SFNHK64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SFSS_APO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SharedStartModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ShareHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SHCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\shdocvw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\shell32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\shutdownux.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\skci.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sl3apo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\slc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\slcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\slcnt64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\slprp64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\sltech64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\smartscreen.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\smphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SndVolSSO.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SpaceAgent.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SpaceControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\spaceman.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SpeechPal.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\spoolsv.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sppc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sppcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sppnp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sppobjs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sppsvc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sppwinob.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\spwmp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SRAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRCOM.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRCOM64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRH.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SRHInproc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\srmclient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\srmscan.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SRRPTR64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRSHP64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRSTSH64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRSTSX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRSWOW64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\sspicli.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\stobject.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\StorageUsage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\storagewmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\storagewmi_passthru.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\StoreAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\StorSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\StructuredQuery.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sud.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SyncCenter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SyncSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SysResetErr.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\systemreset.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettings.DeviceEncryptionHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettings.Handlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettings.UserAccountsHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettingsAdminFlows.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettingsThresholdAdminFlowUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Tabbtn.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tabcal.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TabletPC.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tadefxapo.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\tadefxapo264.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\tapi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\taskbarcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tbauth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tcpipcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tepeqapo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\TextInputFramework.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\themecpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\thumbcache.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\timedate.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TokenBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TokenBrokerCookies.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TokenBrokerUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tosade.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\tosasfapo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\toseaeapo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\tossaeapo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\tossaemaxapo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\TpmCoreProvisioning.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TpmTasks.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tquery.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TransportDSA.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tsmf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TSpkg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tspubwmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TSWorkspace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TsWpfWrp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\twinapi.appcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\twinapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\twinui.appcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\twinui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\twinui.pcshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tzautoupdate.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tzres.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ubpm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\uDWM.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UIAnimation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UIAutomationCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UIRibbon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UIRibbonRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\umpoext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\unimdm.tsp:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Unistore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\updatehandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\updatepolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\uReFS.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\urlmon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\usbmon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\user32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\usercpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDataAccessRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDataLanguageUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDataPlatformHelperUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDataService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDataTimeUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDataTypeHelperUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDeviceRegistration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDeviceRegistration.Ngc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserLanguagesCpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\usermgr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserMgrProxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\usoapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\usocore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vaultcli.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vbscript.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\VCardParser.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\vds.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\VEStoreEventHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vmrdvcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vorbis.acm:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vpnike.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\VPNv2CSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vssapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\VSSVC.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vss_ps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vulkaninfo-1-1-0-26-0.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vulkaninfo.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\w32time.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WavesGUILib64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\wbengine.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wbiosrvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wcmsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wcnwiz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wc_storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WdfCoInstaller01007.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WebcamUi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\webcheck.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\webio.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\werconcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\weretw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\werui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wevtapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wevtsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wfdprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WiFiConfigSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wificonnapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wifinetworkmanager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wifiprofilessettinghandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wifitask.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\win32k.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\win32kbase.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\win32kfull.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\win32spl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\win32u.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinBioDataModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinBioDataModelOOBE.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wincorlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.AccountsControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.Core.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.Store.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.Wallet.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Cortana.Desktop.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Cortana.OneCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Data.Pdf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.AllJoyn.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Bluetooth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.HumanInterfaceDevice.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Lights.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.LowLevel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Midi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Perception.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Picker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.PointOfService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Printers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Radios.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Scanners.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Sensors.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.SerialCommunication.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.SmartCards.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.SmartCards.Phone.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Usb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.WiFi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.WiFiDirect.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Energy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Gaming.Input.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Gaming.UI.GameBar.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Gaming.XboxLive.Storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Globalization.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Graphics.Printing.3D.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Graphics.Printing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Internal.Bluetooth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Internal.Management.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Internal.Management.SecureAssessment.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Internal.Shell.Broker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Internal.UI.Logon.ProxyStub.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Management.Provisioning.ProxyStub.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Audio.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Windows.Media.BackgroundMediaPlayback.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Devices.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Editing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.FaceAnalysis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Import.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.MediaControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Ocr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Playback.MediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Protection.PlayReady.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Speech.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Speech.UXRes.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Streaming.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.Connectivity.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.HostName.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.UX.EapRequestHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.Vpn.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Perception.Stub.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Security.Authentication.Identity.Provider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Security.Credentials.UI.CredentialPicker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Shell.Search.UriHandler.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Windows.StateRepository.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.StateRepositoryBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.StateRepositoryClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Storage.ApplicationData.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\windows.storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Storage.Search.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.System.SystemManagement.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.System.UserDeviceAssociation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.BioFeedback.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.BlockedShutdown.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Core.TextInput.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Cred.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.CredDialogController.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Immersive.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Input.Inking.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Logon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Search.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Shell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Xaml.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Xaml.InkControls.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Xaml.Maps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Xaml.Phone.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Xaml.Resources.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Web.Diagnostics.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Web.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Web.Http.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WindowsCodecs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winhttp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wininet.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wininetlui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winload.efi:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winload.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winlogon.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winmde.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winresume.efi:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winresume.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinRtTracing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinSCard.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinSetupUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winspool.drv:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winsrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wintrust.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinTypes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinUSBCoInstaller.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wkssvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlanapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlancfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlanhlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WlanMediaManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlanmsm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlansec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlansvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlansvcpal.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\wlanui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlidprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlidsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMPDMC.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmpdxm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmpeffects.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmploc.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmpmde.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmpps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmpshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMVDECOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WordBreakers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WorkFolders.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WorkfoldersControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WorkFoldersGPExt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WorkFoldersShell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\workfolderssvc.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\wow64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WpAXHolder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Wpc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WpcMon.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WpcRefreshTask.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WpcTok.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WpcWebFilter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wpnapps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wpncore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wpninprc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wpnprv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wpx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ws2_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wscapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wscinterop.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wscsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wscui.cpl:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\wsecedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WSManHTTPConfig.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WSManMigrationPlugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WsmSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WsmWmiPl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wsp_fs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wsp_health.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wsp_sr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wuapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wuauclt.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wuaueng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wups.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wups2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wuuhext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WwaApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WWAHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WWanAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wwanconn.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\wwanmm.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\wwanprotdim.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wwansvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\x3daudio1_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\x3daudio1_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\X3DAudio1_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\X3DAudio1_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\X3DAudio1_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\X3DAudio1_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\X3DAudio1_6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\X3DAudio1_7.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_1.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\xactengine2_10.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_7.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_8.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_9.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine3_0.dll:$CmdTcID [32]
AlternateDataStreams: C:\Windows\system32\xactengine3_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine3_2.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\xactengine3_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine3_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XamlTileRender.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAPOFX1_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAPOFX1_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAPOFX1_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAPOFX1_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAudio2_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAudio2_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAudio2_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAudio2_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XblAuthManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XblAuthManagerProxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XblAuthTokenBrokerExt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XblGameSaveExt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XboxNetApiSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xinput1_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xinput1_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xinput1_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XInputUap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xpsrchvw.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\YamahaAE.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\YamahaAE2.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\zipfldr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\aadtb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AboveLockAppHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\accountaccessor.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\aclui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ActionCenterCPL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ActivationManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ActiveSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\actxprxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AddressParser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\adsmsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\aepic.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\apds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppCapture.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppContracts.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppointmentActivation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppointmentApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\apprepapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\apprepsync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppVEntSubsystems32.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\appwiz.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppXDeploymentClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppxPackaging.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\asycfilt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atmfd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atmlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AUDIOKSE.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AudioSes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AuthBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AuthExt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\authui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\autoplay.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\azroleui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AzureSettingSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\BackgroundMediaPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\basecsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\bcastdvr.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\BcastDVRHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\bcrypt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\BingMaps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\BingOnlineServices.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\biwinrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\BluetoothApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\BrowserSettingSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CameraCaptureUI.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\cdp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\cemapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CertEnroll.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Chakra.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Chakradiag.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Chakrathunk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\chartv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ChatApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ClipboardServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CloudBackupSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CloudExperienceHostCommon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CloudExperienceHostUser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CloudStorageWizard.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\clusapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\cmifw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\combase.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\comctl32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\comdlg32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CompPkgSup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\comsvcs.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\ConfigureExpandedStorage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ContactActivation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ContactApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\container.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CoreMessaging.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CoreUIComponents.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CPFilters.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CredProvDataModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\credprovhost.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\credprovs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\credprovslegacy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\crypt32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\cryptngc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CryptoWinRT.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\cryptui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\C_G18030.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\c_GSM7.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\C_IS2022.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d2d1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3d10warp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3d11.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3D12.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3d8.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3d9.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_33.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_34.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_35.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_36.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_37.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_38.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_39.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_40.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_41.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_47.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dcsx_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_33.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_34.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_35.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_36.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_37.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_38.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_39.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_40.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_41.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_43.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx11_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx11_43.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_24.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_25.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_26.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_27.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_28.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_29.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_30.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_31.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_32.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_33.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_34.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_35.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_36.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_37.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_38.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_39.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_40.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_41.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_43.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DafPrintProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DataExchange.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DavSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\daxexec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dbgeng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DbgModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ddraw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ddrawex.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\delegatorprovider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\devenum.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\deviceaccess.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\deviceassociation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DeviceFlows.DataModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DevicePairing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dhcpcore6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dialclient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DisplayManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dlnashext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dmenrollengine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dnsapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DolbyDecMFT.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\drvstore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DscCoreConfProv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dsreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dtdump.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dwmapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dwmcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DWrite.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dxgi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dxmasf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dxtrans.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eapp3hst.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eappcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eappgnui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eapphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eappprxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\edgehtml.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\EditBufferTestHook.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\efsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\efswrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\EmailApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\encapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\enrollmentapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ErrorDetails.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ErrorDetailsUpdate.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\esent.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\esentutl.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\evr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\explorer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ExplorerFrame.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ExSMime.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ExtrasXmlParser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\findnetprinters.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\fontdrvhost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\fontext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\FSClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\GamePanel.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\GamePanelExternalHook.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\gameux.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\gdi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\gdi32full.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\GdiPlus.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\Geolocation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\GlobCollationHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\gpapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\hevcdecoder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\hgcpl.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\icm32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ieapfltr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iedkcs32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ieframe.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iepeers.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\ieproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iernonce.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iertutil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iesetup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\imapi2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\imapi2fs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\indexeddbserver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\inetcomm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\inetcpl.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\input.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\InputLocaleManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\InputService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\InstallAgent.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\InstallAgentUserBroker.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\IPHLPAPI.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iprtrmgr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ipsecsnp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ipsmsnap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iscsiwmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\JpMapControl.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\jscript9.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\jscript9diag.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\jsproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\kerberos.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\KernelBase.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\LaunchWinApp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\LicenseManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\LicenseManagerApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\LockAppBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\LockAppHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\LogonController.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\main.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MapConfiguration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MapControlCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MapControlStringsRes.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\MapGeocoder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MapRouter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MapsBtSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MbaeApiPublic.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mbsmsapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MCCSEngineShared.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MCRecvSrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mdmregistration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfasfsrcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfaudiocnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfksproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MFMediaEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfmjpegdec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfmkvsrcsnk.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\mfmp4srcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfmpeg2srcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfnetcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfnetsrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfplat.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MFPlay.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfpmp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfreadwrite.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfsensorgroup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfsrcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfsvr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Microsoft-Windows-MapControls.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Microsoft-Windows-MosHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Microsoft-Windows-MosTrace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\migisol.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MiracastReceiver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mispace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mmc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MMDevAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mos.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MosHostClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MosResource.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MosStorage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mprapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mprddm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mprdim.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\MrmCoreR.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MSAC3ENC.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MSAJApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mscandui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mscms.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\msctf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msctfp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msctfui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msdtcprx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msdtcuiu.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msdxm.ocx:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msfeeds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msftedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mshtml.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mshtmled.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msinfo32.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msmpeg2vdec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mspaint.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MSPhotography.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mssitlb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mssph.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mssphtb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mssrch.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mssvp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mstsc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mstscax.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msutb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msv1_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MSVidCtl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MSVP9DEC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msvproc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MSVPXENC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msxml3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msxml6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msxml6r.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mtxclu.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\muachost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NaturalLanguage6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NetCfgNotifyObjectHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\netiohlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\netiougc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NetSetupApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NetSetupEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NetSetupShim.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\netshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NetworkCollectionAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ngccredprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NMAA.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NmaDirect.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\NPSM.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nshwfp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ntdll.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ntshrui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvaudcap32v.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvcompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvcuda.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvcuvid.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvDecMFTMjpeg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvEncMFTH264.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvEncodeAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvfatbinaryLoader.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NvFBC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NvIFR.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\NvIFROpenGL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvoglv32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvopencl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvptxJitCompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvStreaming.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\odbcconf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\offlinelsa.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\offlinesam.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\offreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ole32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\oleacc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\oleaut32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\olepro32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\OneDriveSetup.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\OpenCL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PCPTpm12.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\pdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Phoneutil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PhoneutilRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PhotoScreensaver.scr:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\pidgenx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Pimstore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PlayToDevice.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PlayToManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PlayToReceiver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\policymanager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\poqexec.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\POSyncServices.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\powercfg.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PresentationNative_v0300.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PrintConfig.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PrintDialogs.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\ProximityCommon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\puiapi.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\puiobj.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\pwrshplugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\qdvd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\quartz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\RADCUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\rasapi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\rasgcw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\rdpcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\rdpencom.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ReAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ReAgentc.exe:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\regedit.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\remoteaudioendpoint.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\RemoteNaturalLanguage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\resutils.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\RltkAPO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\rpcrt4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\RTMediaFrame.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\RTWorkQ.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\samlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sbe.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\schannel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\scksp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Search.ProtocolHandler.MAPI2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SearchFilterHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SearchFolder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SearchIndexer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SearchProtocolHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SECOMN32.DLL:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\sendmail.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SessEnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSyncCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSyncHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSyncPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\setupugc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SFCOM.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\ShareHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SHCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\shell32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\slc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\slcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\smphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SndVolSSO.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sppc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sppcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\spwmp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SRCOM.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\srmclient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sspicli.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\stobject.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\storagewmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\storagewmi_passthru.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\StoreAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\StructuredQuery.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sud.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SyncSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\systemcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tapi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tbauth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tcpipcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TempSignedLicenseExchangeTask.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TextInputFramework.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\themecpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\thumbcache.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TokenBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TokenBrokerCookies.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TokenBrokerUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TpmCoreProvisioning.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\tquery.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tsmf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TSpkg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TSWorkspace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TsWpfWrp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\twinapi.appcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\twinapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\twinui.appcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\twinui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tzres.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UIAnimation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UIAutomationCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UIRibbon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UIRibbonRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\unimdm.tsp:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Unistore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\updatepolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\uReFS.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\urlmon.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\user32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\usercpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDataAccessRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDataAccountApis.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\UserDataLanguageUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDataPlatformHelperUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDataTimeUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDataTypeHelperUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDeviceRegistration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDeviceRegistration.Ngc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserLanguagesCpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserMgrProxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\usoapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\vaultcli.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\vbscript.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\VCardParser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\vorbis.acm:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\vssapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\vulkaninfo-1-1-0-26-0.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\vulkaninfo.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wcnwiz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WebcamUi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\webcheck.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\webio.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\weretw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wevtapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wfdprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\win32k.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\win32kfull.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\win32u.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wincorlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.AccountsControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.Core.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.Wallet.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Data.Pdf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.AllJoyn.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Lights.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.LowLevel.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Midi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Perception.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Picker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.PointOfService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Radios.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Scanners.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Sensors.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.SerialCommunication.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.SmartCards.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Usb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.WiFi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.WiFiDirect.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Energy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Gaming.Input.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Gaming.UI.GameBar.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Gaming.XboxLive.Storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Globalization.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Graphics.Printing.3D.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Graphics.Printing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Internal.Management.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Audio.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Devices.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Editing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.FaceAnalysis.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Import.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.MediaControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Ocr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Playback.MediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Speech.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Speech.UXRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Streaming.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Networking.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Networking.HostName.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Perception.Stub.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Security.Authentication.OnlineId.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Shell.Search.UriHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.StateRepository.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\windows.storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Storage.Search.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.System.SystemManagement.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.System.UserDeviceAssociation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.BioFeedback.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Cred.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.CredDialogController.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Immersive.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Logon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Search.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Xaml.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Xaml.InkControls.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Xaml.Maps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Xaml.Phone.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Web.Diagnostics.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Web.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Web.Http.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WindowsCodecs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\winhttp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wininet.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wininetlui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\winmde.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WinRtTracing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WinSCard.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\winspool.drv:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wintrust.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WinTypes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wlanapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wlancfg.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\wlanhlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wlanui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wlidcli.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wlidprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wmp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMPDMC.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wmpdxm.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\wmpeffects.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wmploc.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wmpmde.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wmpshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMVSENCD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WordBreakers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Wpc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WpcWebFilter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WPDShServiceObj.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wpnapps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ws2_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wscapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wscinterop.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wscui.cpl:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\wsecedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WSManHTTPConfig.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WsmSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WsmWmiPl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wsp_fs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wsp_health.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wsp_sr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wuapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WwaApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WWAHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WWanAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\x3daudio1_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\x3daudio1_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_7.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_10.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_7.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_8.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_9.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_1.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XblAuthManagerProxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XblAuthTokenBrokerExt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xinput1_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xinput1_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xinput1_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XInputUap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xolehlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xpsrchvw.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\zipfldr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\afd.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ahcache.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\AppVStrm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\BasicDisplay.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\BasicRender.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\bowser.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\capimg.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\Classpnp.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\clfs.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ClipSp.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\cmimcext.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\cng.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\crashdmp.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\csc.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dam.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dfsc.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dumpsd.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dxgkrnl.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dxgmms1.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dxgmms2.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\EhStorTcgDrv.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\fastfat.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\fvevol.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\FWPKCLNT.SYS:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\hidclass.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\hidparse.sys:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Drivers\hidusb.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\http.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\hvservice.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\hvsocket.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\iaLPSS2_GPIO2.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\iaLPSS2_I2C.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\iorate.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\IPMIDrv.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\kbdhid.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ks.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ksecdd.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ksecpkg.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\MegaSas2i.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\modem.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\mrxdav.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb10.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb20.sys:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Drivers\msiscsi.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\mskssrv.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ndis.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ntfs.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\nvhda64v.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\nvvad64v.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\nwifi.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\partmgr.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\pci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\pdc.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\rdbss.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\rt640x64.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\RTKVHD64.sys:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Drivers\sdbus.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\spaceport.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\srv.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\srv2.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\srvnet.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ssudbus.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ssudmdm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\storahci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\stornvme.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\storport.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tcpip.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tcpipreg.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tdx.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tpm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\vhdmp.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\vmbkmcl.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\vmbkmclr.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\vpci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\wcifs.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\WdiWiFi.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\winhvr.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\wof.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\xboxgip.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\xinputhid.sys:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Desktop\FRST64 (1).exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Desktop\FRST64 (1).exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\3439847136_9244c541bf.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\376.33-desktop-win10-64bit-international-whql.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\376.33-desktop-win10-64bit-international-whql.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\3WYSI120.rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\4e.ch11.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\4WNJSI.rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\4_Way_Stack_Interchange_(MV).rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\663214-1076006 - Jae Yoon Cha - Nov 2, 2016 201 PM - Jae Yoon Cha and Lorenz Work.xlsx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\AAER Assignment (1).docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\AAER Assignment (2).docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\AAER Assignment.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Accrued Expense Detail 20X3.xlsx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\android-data-recovery.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\android-data-recovery.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\artmoney731eng.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\artmoney731eng.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Audit Report Assignment.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\axx Center1.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\BlackboardCollaborateLauncher-Win.msi:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Bluerise_Plaza_(1024).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Bluerise_Plaza_(2048).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\BUSA 4980 Syllabus Fall2016_Section 033_FINAL.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\C6 Corporate Strategy_class only.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\C7 Acquisition and Restructuring.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\C8 International Strategy.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\C9 Cooperative+Strategy.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Cadwal.pptx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Chapter 10 Slides.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Chapter 6 Slides (1).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Chapter 6 Slides.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\client_21022 (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\client_21022 (2).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\client_21022.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\comp22529.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\CTTV Headquarter.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\db65d4e861e57d654c5f9e143f760833.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\DDUv96-[Guru3D.com].exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\DDUv96-[Guru3D.com].exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Display Driver Uninstaller.exe:$CmdTcID [130]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\European_W2W_Pack1.rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\expense template (1).xlsx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\flstudio_12.4.2.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\flstudio_12.4.2.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\FRST64.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\FRST64.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Governance Failure of Satyam (1).docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Governance Failure of Satyam.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Hightops&Laces (1) (1).pptx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Hightops&Laces (1).pptx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Hightops&Laces.pptx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Invoices for Search.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Japanese shop 2 .crp.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Kim-Anh-Vu-Satyam-Case-Analysis.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Kim_Plaza_-_Growable_-_1024.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Kim_Plaza_-_Growable_-_2048.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Kim_Plaza_-_Ploppable_-_1024.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Kim_Plaza_-_Ploppable_-_2048.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\KindleForPC-installer-1.17.44183.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\KindleForPC-installer-1.17.44183.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\launcher_1004.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Legal Issues in Hiring Employees.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Loss.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\mdoyle.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\nativeplayback (1).collab:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\nativeplayback (2).collab:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\nativeplayback (3).collab:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\nativeplayback (4).collab:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\nativeplayback.collab:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\NYC Apartment.rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\o15-ctrremove.diagcab:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\OANDA_Desktop.msi:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Ocean Tower2.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\ScpToolkit_Setup.exe:$CmdTcID [130]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\ScpToolkit_Setup.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Search Testwork Template.xlsx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Setup.x86.en-US_ProPlusRetail_N43H4-FQQJP-B2GKW-BGKWC-TMT97_TX_PR_act_1_ (1).exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Setup.x86.en-US_ProPlusRetail_N43H4-FQQJP-B2GKW-BGKWC-TMT97_TX_PR_act_1_ (1).exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Setup.x86.en-US_ProPlusRetail_N43H4-FQQJP-B2GKW-BGKWC-TMT97_TX_PR_act_1_.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Setup.x86.en-US_ProPlusRetail_N43H4-FQQJP-B2GKW-BGKWC-TMT97_TX_PR_act_1_.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\slipstripsfalls (1).ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\slipstripsfalls.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\SonyVegasPro13.0Build29064BitMultilingualChingLiu_archive (1).torrent:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\SonyVegasPro13.0Build29064BitMultilingualChingLiu_archive.torrent:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Student Final Self Evaluation-GA State Law.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\SURL Instructions.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Teaching Notes #6v3_class only (1).doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Teaching Notes #6v3_class only.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Teaching Notes #7v2.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Teaching Notes #8.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Teaching Notes #9.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\TeamSpeak3-Client-win64-3.0.19.4.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\TeamSpeak3-Client-win64-3.0.19.4.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\The City Office Building.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\The Shard Less Saturation.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\thinkorswim_x64_installer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\thinkorswim_x64_installer.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\TP Aging 20X3.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Unconfirmed 403935.crdownload:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\uTorrent.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\uTorrent.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Welcome Packet OOS Tax & Audit Ben.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\winamp5666_full_all_redux.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\winamp5666_full_all_redux.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Yoshi_Towers_(1024).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Yoshi_Towers_(2048).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\ZED68-PRINCETOWER-4x4HCL3 (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\ZED68-PRINCETOWER-4x4HCL3.zip:$CmdZnID [26]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\S-1-5-21-534414204-3113082749-4167303694-1001\Software\Classes\regfile: regedit.exe "%1" <===== ATTENTION
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-534414204-3113082749-4167303694-1001\...\sharepoint.com -> hxxps://studentgsu-files.sharepoint.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2016-07-16 07:47 - 2017-05-08 01:28 - 00000853 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
0.0.0.1 mssplus.mcafee.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-534414204-3113082749-4167303694-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Solo Bolo\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{6B7B0CC9-2CA4-4EF9-A764-213B6162E110}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{0A6EB272-BFE0-4BAC-9B8A-3A1EB124279E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{C958F8C9-34D7-46E0-90FA-E0E77CF5DA73}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{3182EF47-2E59-48F7-BB6F-E50A0718E2F3}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{B5E2DFFE-E4E4-465B-A56F-C8B8F4CF1023}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{755024B6-45DA-4834-9612-B04107FBDEEC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Total War SHOGUN 2\Shogun2.exe
FirewallRules: [{75FD4A61-E2CD-46AF-9059-42A020DF7ED1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Total War SHOGUN 2\Shogun2.exe
FirewallRules: [TCP Query User{2EACAA7A-19B6-4C70-844D-3D5007E746D5}C:\users\solo bolo\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_80\bin\javaw.exe] => (Allow) C:\users\solo bolo\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_80\bin\javaw.exe
FirewallRules: [UDP Query User{25950F00-57FE-4216-B54C-B1A5EC0C3AE0}C:\users\solo bolo\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_80\bin\javaw.exe] => (Allow) C:\users\solo bolo\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_80\bin\javaw.exe
FirewallRules: [{47583139-26FC-42AC-B7B9-3C221F355AAD}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{539FC340-1BEC-47FC-B950-F3DBB48DE7E5}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{8DCCFB06-1A6B-4109-A894-4CF1030C17EF}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{C68EEBD0-EDB4-4B1D-8D0B-CDAA90B95768}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{F6FE0BFE-333C-4058-8C8C-594262B77EF8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{3B390A75-58DD-4A78-A5F8-1030CECA2D4C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{B38D0FA2-2B63-4073-AC8E-A76897746FA3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{052CC2B4-9220-400E-92DA-1AAEC5A31199}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{5AEA016F-0DE3-4B3E-87B8-AF2EE9878F11}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{40864CA2-19F0-4115-90B8-C26F6443D2C5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Empire Total War\Empire.exe
FirewallRules: [{3B85C1C2-0C59-4AEC-90EE-47E212130186}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Empire Total War\Empire.exe
FirewallRules: [{74AD848F-4817-4C96-BFA9-1F0FD8137252}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{B0C68027-77FC-4E70-8E16-6DB7F2AFEFFA}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [TCP Query User{8E1DBF8E-F26F-4754-A4CA-25BB82E42ACB}C:\program files\nefarius software solutions\scptoolkit\scpserver.exe] => (Block) C:\program files\nefarius software solutions\scptoolkit\scpserver.exe
FirewallRules: [UDP Query User{18F05A95-634C-405B-8DF9-E9222E41A7CA}C:\program files\nefarius software solutions\scptoolkit\scpserver.exe] => (Block) C:\program files\nefarius software solutions\scptoolkit\scpserver.exe
FirewallRules: [{39FD695E-9905-4F27-A77A-AFFCE48336DD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Total War Rome II\launcher\launcher.exe
FirewallRules: [{7506F902-E987-40A5-810F-EAFD4FD86BE8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Total War Rome II\launcher\launcher.exe
FirewallRules: [TCP Query User{C7FE6D89-B5BB-403C-A775-C4736D410AAF}C:\program files (x86)\steam\steamapps\common\total war rome ii\rome2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war rome ii\rome2.exe
FirewallRules: [UDP Query User{07D34B52-4B77-4B35-A55F-028FA539C8F2}C:\program files (x86)\steam\steamapps\common\total war rome ii\rome2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war rome ii\rome2.exe
FirewallRules: [{DCEE6979-3BDE-4DC2-BED1-F0BC77AABF72}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.596\SZBrowser.exe
FirewallRules: [{315294D6-89F1-4039-AE3F-670AA88AD31E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe
FirewallRules: [{39E49435-6460-47BA-8B55-60F1F25A7D86}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe
FirewallRules: [{5E2B205A-414C-4F42-99C6-33A08F55625F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{94CD4FDF-5586-47B8-95BC-5A782118228F}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.596_0\SZBrowser.exe
 
==================== Restore Points =========================
 
30-04-2017 14:23:08 Windows Update
07-05-2017 11:48:09 Windows Update
10-05-2017 23:14:24 Windows Update
 
==================== Faulty Device Manager Devices =============
 
Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: Microsoft PS/2 Mouse
Description: Microsoft PS/2 Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/12/2017 12:19:08 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (05/11/2017 12:58:27 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Cities.exe version 5.1.3.48304 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 2304
 
Start Time: 01d2ca12f6d7daba
 
Termination Time: 34
 
Application Path: C:\Program Files (x86)\Cities Skylines\Cities.exe
 
Report Id: 740d7050-3606-11e7-942e-4ccc6a497d9f
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (05/11/2017 12:55:49 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program CC_LoadingPage.exe version 2.0.0.31 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 1840
 
Start Time: 01d2ca1277b93bac
 
Termination Time: 53165
 
Application Path: C:\Program Files (x86)\MSI\Command Center\CC_LoadingPage.exe
 
Report Id: edc20532-3605-11e7-942e-4ccc6a497d9f
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (05/11/2017 12:22:05 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Microsoft.Photos.exe version 1.0.1704.25001 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: f2c
 
Start Time: 01d2ca0e219a06ee
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.425.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
 
Report Id: 5fff37f2-3601-11e7-942d-4ccc6a497d9f
 
Faulting package full name: Microsoft.Windows.Photos_17.425.10010.0_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: App
 
Error: (05/11/2017 12:21:59 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-G2DJP68)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (05/11/2017 12:19:09 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program CC_LoadingPage.exe version 2.0.0.31 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 2588
 
Start Time: 01d2ca0d2798c278
 
Termination Time: 60000
 
Application Path: C:\Program Files (x86)\MSI\Command Center\CC_LoadingPage.exe
 
Report Id: c93910e6-3600-11e7-942d-4ccc6a497d9f
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (05/10/2017 11:58:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: dwm.exe, version: 10.0.14393.0, time stamp: 0x578999ab
Faulting module name: nvwgf2umx.dll, version: 21.21.13.7653, time stamp: 0x5864fe75
Exception code: 0xc0000005
Fault offset: 0x0000000000ee0e9c
Faulting process id: 0x378
Faulting application start time: 0x01d2ca0a6ef5701c
Faulting application path: C:\Windows\system32\dwm.exe
Faulting module path: C:\Windows\System32\DriverStore\FileRepository\nv_dispiwu.inf_amd64_b67dc924fff8de6d\nvwgf2umx.dll
Report Id: 14b11bfe-d023-4253-9ee8-0419cd7dea7b
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (05/10/2017 11:31:13 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
 
Error: (05/10/2017 11:14:44 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (05/10/2017 11:08:40 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 10.0.14393.953 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 110c
 
Start Time: 01d2ca02f39cda7c
 
Termination Time: 0
 
Application Path: C:\Windows\explorer.exe
 
Report Id: 10fbf830-35f7-11e7-942a-4ccc6a497d9f
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
 
System errors:
=============
Error: (05/12/2017 12:18:35 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (05/12/2017 12:09:06 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (05/12/2017 12:08:38 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The InstallerService service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (05/12/2017 12:08:37 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 1:09:16 AM on ‎5/‎11/‎2017 was unexpected.
 
Error: (05/11/2017 01:34:17 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (05/11/2017 01:24:56 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (05/11/2017 01:09:48 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (05/11/2017 01:09:18 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The InstallerService service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (05/11/2017 01:09:16 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 12:52:24 AM on ‎5/‎11/‎2017 was unexpected.
 
Error: (05/11/2017 12:52:40 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
 
CodeIntegrity:
===================================
  Date: 2017-05-11 00:55:43.181
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\SysWOW64\guard32.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2017-05-10 23:05:12.901
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-05-10 23:03:54.776
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-05-10 23:03:35.865
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-05-10 23:03:27.581
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-05-10 23:03:27.421
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-05-10 22:36:41.544
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-05-10 22:36:31.732
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-05-10 22:36:30.517
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-03-21 00:02:00.466
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-6500 CPU @ 3.20GHz
Percentage of memory in use: 23%
Total physical RAM: 16330.89 MB
Available physical RAM: 12443.82 MB
Total Virtual: 18762.89 MB
Available Virtual: 14536.97 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:930.96 GB) (Free:764.2 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: AC127023)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

Edited by Soloinneed, 11 May 2017 - 10:55 PM.

  • 0

Advertisements


#2
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Hi! My name is zep516 and Welcome to Geekstogo!
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions! :)

You have 2 Anti virus programs running. This is not recommend please uninstall one of them

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe

Let me know when that is done
  • 0

#3
Soloinneed

Soloinneed

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

Hi Zep516 thank you so much! 

 

I have uninstalled COMODO.


  • 0

#4
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Hello,

Download the enclosed =>Attached File  fixlist.txt   153.1KB   242 downloads file. Save it in the location FRST64 is. Your desktop. Then run FRST and click on the Fix button. Wait until finished.
The tool will make a log in the location FRST is, (Fixlog.txt). Please post it to your reply.
  • 0

#5
Soloinneed

Soloinneed

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

Here is the Fixlog:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 08-05-2017
Ran by Solo Bolo (12-05-2017 01:38:26) Run:1
Running from C:\Users\Solo Bolo\Desktop
Loaded Profiles: Solo Bolo (Available Profiles: defaultuser0 & Solo Bolo)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
GroupPolicy: Restriction <======= ATTENTION
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X]
2017-05-07 12:09 - 2017-05-07 12:09 - 41942707 _____ C:\Users\Solo Bolo\Downloads\Unconfirmed 943625.crdownload
2017-05-07 12:07 - 2017-05-07 12:08 - 41942707 _____ C:\Users\Solo Bolo\Downloads\Unconfirmed 368439.crdownload
Task: {2D8BDF82-909D-4308-9CDF-CB66D313FC64} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-09-14] (COMODO)
Task: {9010427D-D57D-412D-889E-2FA03423B7F0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-21] (Google Inc.)
Task: {966A7C09-6C5B-4CDF-8378-3843F7925BC1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-21] (Google Inc.)
Task: {BBDBFD4E-4096-477F-BED1-ED168C84C74B} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-09-14] (COMODO)
C:\Program Files\COMODO
Task: {C6139D82-425A-4B0C-9C7A-B859FC2A9A5F} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2016-09-14] (COMODO)
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe
C:\Program Files\COMODO\COMODO Internet Security\cis.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdupd.exe
HKLM\...\Run: [COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10}] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1610936 2016-09-14] (COMODO)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5817256 2016-09-15] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2271928 2016-09-14] (COMODO)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [40960 2016-09-08] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [862648 2016-09-08] (COMODO)
R1 cmdhlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [54336 2016-09-08] (COMODO)
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
AlternateDataStreams: C:\Windows\avastSS.scr:$CmdTcID [64]
AlternateDataStreams: C:\Windows\explorer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\HelpPane.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\NvContainerRecovery.bat:$CmdTcID [64]
AlternateDataStreams: C:\Windows\regedit.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\splwow64.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aadcloudap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aadtb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AboveLockAppHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\accountaccessor.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AccountsRt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aclui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\acmigration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ACPBackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AcpiServiceVnA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\ActionCenter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ActionCenterCPL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ActivationManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ActiveSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\actxprxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AddressParser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\adsmsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aeinv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aepic.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AERTAC64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\AERTAR64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\aitstatic.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppCapture.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppContracts.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\appinfo.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ApplicationFrame.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppointmentActivation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppointmentApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\appraiser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppReadiness.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\apprepapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\apprepsync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVCatalog.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVClient.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVDllSurrogate.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVEntStreamingManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVEntSubsystemController.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVEntSubsystems64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\AppVEntVirtualization.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVIntegration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVManifest.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVOrchestration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVPublishing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVReporting.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVScripting.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppVShNotify.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\appwiz.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppXApplicabilityBlob.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppXDeploymentClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppXDeploymentExtensions.desktop.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppXDeploymentExtensions.onecore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppXDeploymentServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppxPackaging.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\asycfilt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atmfd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atmlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AudioEndpointBuilder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AudioEng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AUDIOKSE.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\audioLibVc.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\AudioSes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\audiosrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AudioSrvPolicyManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AuthBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AuthHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\authui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\autoplay.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AzureSettingSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\baaupdate.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BackgroundMediaPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BarcodeProvisioningPlugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\basecsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bcastdvr.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BcastDVRHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bcdedit.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bcrypt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bdechangepin.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bdesvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bdeui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bdeunlock.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BingMaps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BingOnlineServices.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bisrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BitLockerDeviceEncryption.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\biwinrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BluetoothApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BluetoothDesktopHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BootMenuUX.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\bootux.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\browserbroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BrowserSettingSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\BthRadioMedia.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CameraCaptureUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CastLaunch.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CbtBackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cdd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cdp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cdpsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cdpusersvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CellularAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cemapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CertEnroll.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\certprop.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CfgSPCellular.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Chakra.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Chakradiag.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Chakrathunk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\chartv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ChatApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ci.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ClipboardServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ClipUp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cloudAP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudBackupSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudDomainJoinDataModelServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudExperienceHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudExperienceHostBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudExperienceHostCommon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudExperienceHostUser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CloudStorageWizard.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\clusapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cmifw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cmintegrator.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\combase.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\comdlg32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CompatTelRunner.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CompPkgSup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\comsvcs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CONEQMSAPOGUILibrary.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\ConsoleLogon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ContactActivation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ContactApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\container.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ContentDeliveryManager.Utilities.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CoreMessaging.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CoreUIComponents.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\CPFilters.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CredProvDataModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\credprovhost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\credprovs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\credprovslegacy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\crypt32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cryptngc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CryptoWinRT.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cryptui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cscui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CspCellularSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\csrsrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CX64APO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\C_G18030.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\c_GSM7.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\C_IS2022.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d2d1.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\d3d10warp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3d11.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3D12.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3d9.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_33.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_34.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_35.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_36.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_37.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_38.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_39.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DCompiler_47.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dcsx_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_33.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_34.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_35.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_36.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_37.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_38.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_39.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx10_43.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\d3dx11_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx11_43.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\d3dx9_24.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_25.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_26.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_27.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_28.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_29.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_30.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\d3dx9_31.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\d3dx9_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_33.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_34.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_35.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_36.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_37.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_38.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_39.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_40.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_41.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\D3DX9_43.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\dab.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dafBth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dafpos.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DafPrintProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\das.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dasHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DataExchange.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DataSenseHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DavSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\daxexec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dbgeng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DbgModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dcntel.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DdcWnsListener.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DDPA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPA64F3.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPD64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPD64AF3.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPO64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPO64AF3.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DDPP64AF3.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\ddraw.dll:$CmdTcID [32]
AlternateDataStreams: C:\Windows\system32\ddrawex.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\delegatorprovider.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DeveloperOptionsSettingsHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\devenum.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\deviceaccess.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\deviceassociation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DeviceCensus.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DeviceCenter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DeviceDirectoryClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DeviceEnroller.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DeviceFlows.DataModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DevicePairing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DevicePairingFolder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DeviceReactivation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\devinv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dggpext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dhcpcore6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\diagtrack.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dialclient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dialserver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\discan.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Display.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DisplayManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dlnashext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dmcertinst.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dmenrollengine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DMRServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dnsapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dnsrslvr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DolbyDAX2APOProp.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DolbyDAX2APOv201.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DolbyDAX2APOv211.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DolbyDecMFT.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\domgmt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dosvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dpapisrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\drvstore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DscCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DscCoreConfProv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dsreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dsregcmd.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DTSBassEnhancementDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSBoostDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSGainCompensatorDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSGFXAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSGFXAPONS64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSLFXAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSLimiterDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSNeoPCDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSS2HeadphoneDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSS2SpeakerDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSSymmetryDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSU2PGFX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSU2PLFX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSU2PREC64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DTSVoiceClarityDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DuCsps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dui70.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dwmapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dwmcore.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\DWrite.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dxgi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dxmasf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\DXP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dxtrans.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EAMProgressHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eapp3hst.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eappcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eappgnui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eapphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eappprxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\easwrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\edgehtml.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EditBufferTestHook.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EditionUpgradeHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EditionUpgradeManagerObj.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EDPCleanup.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\efsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\efswrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EmailApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\encapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EncDec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\energy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\enrollmentapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EnterpriseAPNCsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EnterpriseAppMgmtSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\enterprisecsps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ErrorDetails.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ErrorDetailsUpdate.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\esent.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\esentutl.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\evr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ExplorerFrame.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ExSMime.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ExtrasXmlParser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\facecredentialprovider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Family.Authentication.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Family.Client.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Family.SyncEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ffbroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fhcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fhcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fhsettingsprovider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\FlightSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\flvprophandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\FMAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\FntCache.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\fontdrvhost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fontext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\FontProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\FrameServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\FSClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fveapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fveapibase.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fvecpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fvenotify.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fveprompt.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fveui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fvewiz.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\GamePanel.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\GamePanelExternalHook.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\gameux.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\gdi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\gdi32full.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\GdiPlus.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\generaltel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\GenValObj.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Geolocation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\GlobCollationHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\gpapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\gpsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\hal.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\HarmanAudioInterface.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\hevcdecoder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\hgcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\HiFiDAX2API.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMAPO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMClariFi.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMEQ.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMEQ_Voice.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMHVS.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMLimiter.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HMUI.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\HttpsDataSource.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\hvax64.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\hvix64.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\hvloader.efi:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\hvloader.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ICEsoundAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\icfupgd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\icm32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\icsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\icsvcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\IdCtrls.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ie4uinit.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ieapfltr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iedkcs32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ieframe.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iepeers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ieproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iernonce.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iertutil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iesetup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\imapi2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\imapi2fs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ImplatSetup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\indexeddbserver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\inetcomm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\inetcpl.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\input.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\InputLocaleManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\InputService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\InstallAgent.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\InstallAgentUserBroker.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\IntelSSTAPO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\IntelSstCApoPropPage.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\internetmail.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\invagent.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\IPHLPAPI.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iphlpsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ipnathlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iprtrmgr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\iscsiwmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\JpMapControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\jscript9.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\jscript9diag.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\jsproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\KAAPORT64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\kdhvcom.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\kerberos.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\KernelBase.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\KnobsCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\KnobsCsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LaunchWinApp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LicenseManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LicenseManagerSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ListSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\localspl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LocationFramework.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LockAppBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LockAppHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LogonController.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\lpremove.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LsaIso.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\lsasrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\lsass.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\lsm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\main.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\manage-bde.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapConfiguration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapControlCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapControlStringsRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapGeocoder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapRouter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapsBtSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapsBtSvcProxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapsCSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MapsStore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mapstoasttask.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mapsupdatetask.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO20.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO30.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO4064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO5064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO6064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO7064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioAPOShell64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioEQ64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxAudioRealtek64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxSpeechAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxVoiceAPO2064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxVoiceAPO3064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxVoiceAPO4064.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MaxxVolumeSDAPO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MbaeApiPublic.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mbsmsapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MCCSEngineShared.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MCRecvSrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MDEServer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MDMAppInstaller.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mdmregistration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MediaFoundation.DefaultPerceptionProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfasfsrcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfaudiocnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MFCaptureEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfksproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MFMediaEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfmjpegdec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfmkvsrcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfmp4srcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfmpeg2srcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfnetcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfnetsrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfplat.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MFPlay.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfpmp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfreadwrite.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfsensorgroup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfsrcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfsvr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Microsoft-Windows-MapControls.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Microsoft-Windows-MosHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Microsoft-Windows-MosTrace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\microsoft-windows-system-events.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\migisol.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MiracastReceiver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mispace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MISS_APO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\mmc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MMDevAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\modernexecserver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mos.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\moshost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MosHostClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\moshostcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MosResource.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MosStorage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mprapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mprddm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mprdim.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MpSigStub.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MPSSVC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MrmCoreR.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MRT.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSAC3ENC.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSAJApi.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\MSAudDecMFT.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mscandui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msctf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msctfp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msctfui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msdtcprx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msdtctm.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\msdtcuiu.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msdxm.ocx:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msfeeds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msftedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mshtml.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mshtmled.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msinfo32.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msmpeg2vdec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mspaint.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSPhotography.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mssitlb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mssph.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mssphtb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mssprxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mssrch.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mssvp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mstsc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mstscax.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msutb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msv1_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSVidCtl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSVideoDSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSVP9DEC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msvproc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MSVPXENC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msxml3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msxml6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\msxml6r.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MultiDigiMon.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\musdialoghandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MusNotification.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MusNotificationUx.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MusUpdateHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NAHIMICAPOlfx.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\NahimicAPONSControl.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\NAHIMICV2apo.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\NAHIMICV3apo.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\nativemap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NaturalLanguage6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ncsi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetCfgNotifyObjectHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\netiohlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\netiougc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\netplwiz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetSetupApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetSetupEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetSetupShim.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetSetupSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\netshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nettrace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetworkBindingEngineMigPlugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetworkCollectionAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetworkDesktopSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetworkMobileSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NetworkUXBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NFCProvisioningPlugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NfcRadioMedia.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ngccredprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NgcCtnr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NgcCtnrGidsHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NgcCtnrSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ngcsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nltest.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NMAA.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\NmaDirect.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NotificationController.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NPSM.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nshwfp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ntdll.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ntshrui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvapi64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvaudcap64v.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvcompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvcuda.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvcuvid.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvDecMFTMjpeg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvdispco6437633.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvdispco6437653.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvdispgenco6437633.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvdispgenco6437653.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvEncMFTH264.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvEncodeAPI64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvfatbinaryLoader.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NvFBC64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\nvhdagenco6420103.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvhdap64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NvIFR64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NvIFROpenGL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvoglv64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvopencl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvptxJitCompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\odbcconf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\offlinelsa.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\offlinesam.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\offreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ole32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\oleacc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\oleaut32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\OnDemandConnRouteHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\OneBackupHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\OneDriveSettingSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\OpenCL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pcasvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PCPTpm12.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PhoneProviders.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PhoneService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PhoneServiceRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Phoneutil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PhoneutilRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PhotoScreensaver.scr:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pidgenx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PimIndexMaintenance.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Pimstore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PlayToDevice.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PlayToManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PlayToReceiver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pmcsnap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pnidui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\policymanager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\poqexec.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\POSyncServices.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\powercfg.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ppcsnap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PresentationNative_v0300.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PrintDialogs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PrintDialogs3D.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PrintRenderAPIHost.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PrintWSDAHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\profsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\provdatastore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\provengine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\provhandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\provisioningcsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\provops.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ProvPluginEng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ProvSysprep.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\provtool.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PsmServiceExtHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\psmsrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\puiapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\puiobj.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pwcreator.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pwrshplugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\qedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\qmgr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\quartz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\R4EEA64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\R4EED64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\R4EEG64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\R4EEL64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\R4EEP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RADCUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rasapi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rascustom.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rasgcw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rasmans.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RCoInstII64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\rdpcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rdpcorets.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rdpencom.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rdpinit.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RdpRelayTransport.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rdpshell.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rdpudd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RDXService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RDXTaskFactory.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ReAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ReAgentc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RelPost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\remoteaudioendpoint.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RemoteNaturalLanguage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RemovableMediaProvisioningPlugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ReportingCSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\reseteng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ResetEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ResetEngine.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\resutils.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RjvMDMConfig.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RltkAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RMapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RP3DAA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RP3DHT64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\rpcrt4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\rshx32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RTCOM64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RtDataProc64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTEED64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTEEG64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTEEL64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTEEP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RtkApi64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RtkCfg64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RtkCoLDR64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RtlCPAPI64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTMediaFrame.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RtNicProp64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RtPgEx64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTSnMg64.cpl:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\RTWorkQ.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\samlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\samsrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sbe.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ScDeviceEnum.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\schannel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\scksp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sdengin2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sdshext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SEAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Search.ProtocolHandler.MAPI2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SearchFilterHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SearchFolder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SearchIndexer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SearchProtocolHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SecConfig.efi:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SECOMN64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SecureAssessmentHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\securekernel.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SEHDRA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\sendmail.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Sens.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SensorDataService.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SensorsApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SensorService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\services.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SessEnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers_Bluetooth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers_ClosedCaptioning.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers_Flights.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers_nt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers_StorageSense.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers_WorkAccess.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingSyncCore.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SettingSyncHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingSyncPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\setupugc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SFAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SFCOM64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SFNHK64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SFSS_APO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SharedStartModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ShareHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SHCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\shdocvw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\shell32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\shutdownux.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\skci.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sl3apo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\slc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\slcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\slcnt64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\slprp64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\sltech64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\smartscreen.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\smphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SndVolSSO.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SpaceAgent.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SpaceControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\spaceman.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SpeechPal.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\spoolsv.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sppc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sppcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sppnp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sppobjs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sppsvc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sppwinob.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\spwmp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SRAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRCOM.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRCOM64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRH.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SRHInproc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\srmclient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\srmscan.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SRRPTR64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRSHP64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRSTSH64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRSTSX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SRSWOW64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\sspicli.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\stobject.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\StorageUsage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\storagewmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\storagewmi_passthru.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\StoreAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\StorSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\StructuredQuery.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sud.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SyncCenter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SyncSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SysResetErr.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\systemreset.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettings.DeviceEncryptionHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettings.Handlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettings.UserAccountsHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettingsAdminFlows.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettingsThresholdAdminFlowUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Tabbtn.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tabcal.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TabletPC.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tadefxapo.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\tadefxapo264.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\tapi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\taskbarcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tbauth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tcpipcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tepeqapo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\TextInputFramework.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\themecpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\thumbcache.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\timedate.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TokenBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TokenBrokerCookies.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TokenBrokerUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tosade.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\tosasfapo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\toseaeapo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\tossaeapo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\tossaemaxapo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\TpmCoreProvisioning.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TpmTasks.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tquery.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TransportDSA.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tsmf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TSpkg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tspubwmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TSWorkspace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TsWpfWrp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\twinapi.appcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\twinapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\twinui.appcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\twinui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\twinui.pcshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tzautoupdate.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tzres.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ubpm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\uDWM.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UIAnimation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UIAutomationCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UIRibbon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UIRibbonRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\umpoext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\unimdm.tsp:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Unistore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\updatehandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\updatepolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\uReFS.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\urlmon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\usbmon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\user32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\usercpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDataAccessRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDataLanguageUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDataPlatformHelperUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDataService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDataTimeUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDataTypeHelperUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDeviceRegistration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserDeviceRegistration.Ngc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserLanguagesCpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\usermgr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UserMgrProxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\usoapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\usocore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vaultcli.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vbscript.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\VCardParser.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\vds.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\VEStoreEventHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vmrdvcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vorbis.acm:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vpnike.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\VPNv2CSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vssapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\VSSVC.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vss_ps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vulkaninfo-1-1-0-26-0.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\vulkaninfo.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\w32time.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WavesGUILib64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\wbengine.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wbiosrvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wcmsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wcnwiz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wc_storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WdfCoInstaller01007.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WebcamUi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\webcheck.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\webio.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\werconcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\weretw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\werui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wevtapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wevtsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wfdprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WiFiConfigSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wificonnapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wifinetworkmanager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wifiprofilessettinghandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wifitask.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\win32k.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\win32kbase.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\win32kfull.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\win32spl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\win32u.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinBioDataModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinBioDataModelOOBE.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wincorlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.AccountsControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.Core.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.Store.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.Wallet.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Cortana.Desktop.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Cortana.OneCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Data.Pdf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.AllJoyn.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Bluetooth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.HumanInterfaceDevice.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Lights.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.LowLevel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Midi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Perception.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Picker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.PointOfService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Printers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Radios.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Scanners.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Sensors.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.SerialCommunication.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.SmartCards.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.SmartCards.Phone.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.Usb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.WiFi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Devices.WiFiDirect.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Energy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Gaming.Input.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Gaming.UI.GameBar.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Gaming.XboxLive.Storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Globalization.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Graphics.Printing.3D.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Graphics.Printing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Internal.Bluetooth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Internal.Management.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Internal.Management.SecureAssessment.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Internal.Shell.Broker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Internal.UI.Logon.ProxyStub.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Management.Provisioning.ProxyStub.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Audio.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Windows.Media.BackgroundMediaPlayback.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Devices.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Editing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.FaceAnalysis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Import.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.MediaControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Ocr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Playback.MediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Protection.PlayReady.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Speech.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Speech.UXRes.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Windows.Media.Streaming.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.Connectivity.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.HostName.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.UX.EapRequestHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Networking.Vpn.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Perception.Stub.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Security.Authentication.Identity.Provider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Security.Credentials.UI.CredentialPicker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Shell.Search.UriHandler.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Windows.StateRepository.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.StateRepositoryBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.StateRepositoryClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Storage.ApplicationData.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\windows.storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Storage.Search.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.System.SystemManagement.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.System.UserDeviceAssociation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.BioFeedback.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.BlockedShutdown.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Core.TextInput.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Cred.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.CredDialogController.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Immersive.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Input.Inking.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Logon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Search.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Shell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Xaml.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Xaml.InkControls.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Xaml.Maps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Xaml.Phone.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Xaml.Resources.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Web.Diagnostics.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Web.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.Web.Http.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WindowsCodecs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winhttp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wininet.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wininetlui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winload.efi:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winload.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winlogon.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winmde.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winresume.efi:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winresume.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinRtTracing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinSCard.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinSetupUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winspool.drv:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winsrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wintrust.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinTypes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinUSBCoInstaller.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wkssvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlanapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlancfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlanhlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WlanMediaManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlanmsm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlansec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlansvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlansvcpal.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\wlanui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlidprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wlidsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMPDMC.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmpdxm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmpeffects.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmploc.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmpmde.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmpps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wmpshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMVDECOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WordBreakers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WorkFolders.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WorkfoldersControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WorkFoldersGPExt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WorkFoldersShell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\workfolderssvc.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\wow64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WpAXHolder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Wpc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WpcMon.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WpcRefreshTask.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WpcTok.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WpcWebFilter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wpnapps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wpncore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wpninprc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wpnprv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wpx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ws2_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wscapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wscinterop.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wscsvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wscui.cpl:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\wsecedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WSManHTTPConfig.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WSManMigrationPlugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WsmSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WsmWmiPl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wsp_fs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wsp_health.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wsp_sr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wuapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wuauclt.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wuaueng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wups.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wups2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wuuhext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WwaApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WWAHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WWanAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wwanconn.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\wwanmm.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\wwanprotdim.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wwansvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\x3daudio1_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\x3daudio1_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\X3DAudio1_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\X3DAudio1_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\X3DAudio1_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\X3DAudio1_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\X3DAudio1_6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\X3DAudio1_7.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_1.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\xactengine2_10.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_7.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_8.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine2_9.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine3_0.dll:$CmdTcID [32]
AlternateDataStreams: C:\Windows\system32\xactengine3_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine3_2.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\xactengine3_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xactengine3_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XamlTileRender.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAPOFX1_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAPOFX1_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAPOFX1_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAPOFX1_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAudio2_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAudio2_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAudio2_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAudio2_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XblAuthManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XblAuthManagerProxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XblAuthTokenBrokerExt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XblGameSaveExt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XboxNetApiSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xinput1_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xinput1_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xinput1_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XInputUap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\xpsrchvw.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\YamahaAE.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\YamahaAE2.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\zipfldr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\aadtb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AboveLockAppHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\accountaccessor.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\aclui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ActionCenterCPL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ActivationManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ActiveSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\actxprxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AddressParser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\adsmsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\aepic.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\apds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppCapture.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppContracts.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppointmentActivation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppointmentApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\apprepapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\apprepsync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppVEntSubsystems32.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\appwiz.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppXDeploymentClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AppxPackaging.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\asycfilt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atmfd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atmlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AUDIOKSE.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AudioSes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AuthBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AuthExt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\authui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\autoplay.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\azroleui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AzureSettingSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\BackgroundMediaPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\basecsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\bcastdvr.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\BcastDVRHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\bcrypt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\BingMaps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\BingOnlineServices.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\biwinrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\BluetoothApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\BrowserSettingSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CameraCaptureUI.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\cdp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\cemapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CertEnroll.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Chakra.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Chakradiag.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Chakrathunk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\chartv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ChatApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ClipboardServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CloudBackupSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CloudExperienceHostCommon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CloudExperienceHostUser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CloudStorageWizard.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\clusapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\cmifw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\combase.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\comctl32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\comdlg32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CompPkgSup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\comsvcs.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\ConfigureExpandedStorage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ContactActivation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ContactApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\container.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CoreMessaging.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CoreUIComponents.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CPFilters.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CredProvDataModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\credprovhost.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\credprovs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\credprovslegacy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\crypt32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\cryptngc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CryptoWinRT.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\cryptui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\C_G18030.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\c_GSM7.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\C_IS2022.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d2d1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3d10warp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3d11.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3D12.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3d8.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3d9.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_33.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_34.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_35.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_36.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_37.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_38.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_39.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_40.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_41.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_47.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dcsx_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_33.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_34.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_35.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_36.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_37.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_38.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_39.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_40.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_41.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_43.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx11_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx11_43.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_24.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_25.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_26.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_27.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_28.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_29.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_30.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_31.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_32.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_33.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_34.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_35.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_36.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_37.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_38.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_39.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_40.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_41.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_43.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DafPrintProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DataExchange.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DavSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\daxexec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dbgeng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DbgModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ddraw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ddrawex.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\delegatorprovider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\devenum.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\deviceaccess.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\deviceassociation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DeviceFlows.DataModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DevicePairing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dhcpcore6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dialclient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DisplayManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dlnashext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dmenrollengine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dnsapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DolbyDecMFT.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\drvstore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DscCoreConfProv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dsreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dtdump.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dwmapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dwmcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\DWrite.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dxgi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dxmasf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dxtrans.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eapp3hst.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eappcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eappgnui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eapphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eappprxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\edgehtml.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\EditBufferTestHook.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\efsext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\efswrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\EmailApis.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\encapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\enrollmentapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ErrorDetails.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ErrorDetailsUpdate.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\esent.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\esentutl.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\evr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\explorer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ExplorerFrame.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ExSMime.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ExtrasXmlParser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\findnetprinters.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\fontdrvhost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\fontext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\FSClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\GamePanel.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\GamePanelExternalHook.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\gameux.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\gdi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\gdi32full.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\GdiPlus.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\Geolocation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\GlobCollationHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\gpapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\hevcdecoder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\hgcpl.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\icm32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ieapfltr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iedkcs32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ieframe.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iepeers.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\ieproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iernonce.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iertutil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iesetup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\imapi2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\imapi2fs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\indexeddbserver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\inetcomm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\inetcpl.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\input.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\InputLocaleManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\InputService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\InstallAgent.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\InstallAgentUserBroker.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\IPHLPAPI.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iprtrmgr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ipsecsnp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ipsmsnap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\iscsiwmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\JpMapControl.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\jscript9.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\jscript9diag.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\jsproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\kerberos.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\KernelBase.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\LaunchWinApp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\LicenseManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\LicenseManagerApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\LockAppBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\LockAppHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\LogonController.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\main.cpl:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MapConfiguration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MapControlCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MapControlStringsRes.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\MapGeocoder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MapRouter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MapsBtSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MbaeApiPublic.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mbsmsapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MCCSEngineShared.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MCRecvSrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mdmregistration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfasfsrcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfaudiocnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfksproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MFMediaEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfmjpegdec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfmkvsrcsnk.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\mfmp4srcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfmpeg2srcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfnetcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfnetsrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfplat.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MFPlay.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfpmp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfreadwrite.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfsensorgroup.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfsrcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfsvr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Microsoft-Windows-MapControls.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Microsoft-Windows-MosHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Microsoft-Windows-MosTrace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\migisol.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MiracastReceiver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mispace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mmc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MMDevAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mos.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MosHostClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MosResource.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MosStorage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mprapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mprddm.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mprdim.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\MrmCoreR.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MSAC3ENC.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MSAJApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mscandui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mscms.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\msctf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msctfp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msctfui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msdtcprx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msdtcuiu.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msdxm.ocx:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msfeeds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msftedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mshtml.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mshtmled.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msinfo32.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msmpeg2vdec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mspaint.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MSPhotography.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mssitlb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mssph.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mssphtb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mssrch.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mssvp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mstsc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mstscax.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msutb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msv1_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MSVidCtl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MSVP9DEC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msvproc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MSVPXENC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msxml3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msxml6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msxml6r.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mtxclu.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\muachost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NaturalLanguage6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NetCfgNotifyObjectHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\netiohlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\netiougc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NetSetupApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NetSetupEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NetSetupShim.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\netshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NetworkCollectionAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ngccredprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NMAA.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NmaDirect.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\NPSM.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nshwfp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ntdll.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ntshrui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvaudcap32v.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvcompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvcuda.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvcuvid.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvDecMFTMjpeg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvEncMFTH264.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvEncodeAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvfatbinaryLoader.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NvFBC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NvIFR.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\NvIFROpenGL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvoglv32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvopencl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvptxJitCompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvStreaming.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\odbcconf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\offlinelsa.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\offlinesam.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\offreg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ole32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\oleacc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\oleaut32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\olepro32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\OneDriveSetup.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\OpenCL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PCPTpm12.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\pdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Phoneutil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PhoneutilRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PhotoScreensaver.scr:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\pidgenx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Pimstore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PlayToDevice.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PlayToManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PlayToReceiver.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\policymanager.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\poqexec.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\POSyncServices.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\powercfg.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PresentationNative_v0300.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PrintConfig.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PrintDialogs.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\ProximityCommon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\puiapi.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\puiobj.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\pwrshplugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\qdvd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\quartz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\RADCUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\rasapi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\rasgcw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\rdpcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\rdpencom.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ReAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ReAgentc.exe:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\regedit.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\remoteaudioendpoint.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\RemoteNaturalLanguage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\resutils.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\RltkAPO.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\rpcrt4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\RTMediaFrame.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\RTWorkQ.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\samlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sbe.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\schannel.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\scksp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Search.ProtocolHandler.MAPI2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SearchFilterHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SearchFolder.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SearchIndexer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SearchProtocolHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SECOMN32.DLL:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\sendmail.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SessEnv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSyncCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSyncHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSyncPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\setupugc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SFCOM.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\ShareHost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SHCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\shell32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\slc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\slcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\smphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SndVolSSO.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sppc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sppcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\spwmp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SRCOM.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\srmclient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sspicli.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\stobject.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\storagewmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\storagewmi_passthru.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\StoreAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\StructuredQuery.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sud.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SyncSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\systemcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tapi32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tbauth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tcpipcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TempSignedLicenseExchangeTask.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TextInputFramework.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\themecpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\thumbcache.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TokenBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TokenBrokerCookies.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TokenBrokerUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TpmCoreProvisioning.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\tquery.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tsmf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TSpkg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TSWorkspace.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TsWpfWrp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\twinapi.appcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\twinapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\twinui.appcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\twinui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tzres.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UIAnimation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UIAutomationCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UIRibbon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UIRibbonRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\unimdm.tsp:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Unistore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\updatepolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\uReFS.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\urlmon.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\user32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\usercpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDataAccessRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDataAccountApis.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\UserDataLanguageUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDataPlatformHelperUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDataTimeUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDataTypeHelperUtil.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDeviceRegistration.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserDeviceRegistration.Ngc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserLanguagesCpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UserMgrProxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\usoapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\vaultcli.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\vbscript.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\VCardParser.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\vorbis.acm:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\vssapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\vulkaninfo-1-1-0-26-0.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\vulkaninfo.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wcnwiz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WebcamUi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\webcheck.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\webio.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\weretw.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wevtapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wfdprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\win32k.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\win32kfull.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\win32u.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wincorlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.AccountsControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.Core.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.Wallet.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Data.Pdf.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.AllJoyn.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Lights.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.LowLevel.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Midi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Perception.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Picker.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.PointOfService.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Radios.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Scanners.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Sensors.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.SerialCommunication.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.SmartCards.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Usb.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.WiFi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.WiFiDirect.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Energy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Gaming.Input.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Gaming.UI.GameBar.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Gaming.XboxLive.Storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Globalization.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Graphics.Printing.3D.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Graphics.Printing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Internal.Management.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Audio.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Devices.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Editing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.FaceAnalysis.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Import.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.MediaControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Ocr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Playback.MediaPlayer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Speech.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Speech.UXRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Media.Streaming.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Networking.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Networking.HostName.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Perception.Stub.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Security.Authentication.OnlineId.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Shell.Search.UriHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.StateRepository.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\windows.storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Storage.Search.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.System.SystemManagement.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.System.UserDeviceAssociation.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.BioFeedback.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Cred.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.CredDialogController.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Immersive.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Logon.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Search.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Xaml.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Xaml.InkControls.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Xaml.Maps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Xaml.Phone.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Web.Diagnostics.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Web.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.Web.Http.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WindowsCodecs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\winhttp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wininet.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wininetlui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\winmde.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WinRtTracing.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WinSCard.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\winspool.drv:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wintrust.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WinTypes.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wlanapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wlancfg.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\wlanhlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wlanui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wlidcli.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wlidprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wmp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMPDMC.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wmpdxm.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\wmpeffects.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wmploc.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wmpmde.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wmpshell.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMVSENCD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WordBreakers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Wpc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WpcWebFilter.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WPDShServiceObj.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wpnapps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ws2_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wscapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wscinterop.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wscui.cpl:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\wsecedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WSManHTTPConfig.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WsmSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WsmWmiPl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wsp_fs.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wsp_health.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wsp_sr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wuapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WwaApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WWAHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WWanAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\x3daudio1_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\x3daudio1_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_7.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_10.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_7.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_8.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_9.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_0.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_1.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_4.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XblAuthManagerProxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XblAuthTokenBrokerExt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xinput1_1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xinput1_2.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xinput1_3.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XInputUap.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xolehlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\xpsrchvw.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\zipfldr.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\afd.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ahcache.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\AppVStrm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\BasicDisplay.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\BasicRender.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\bowser.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\capimg.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\Classpnp.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\clfs.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ClipSp.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\cmimcext.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\cng.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\crashdmp.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\csc.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dam.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dfsc.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dumpsd.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dxgkrnl.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dxgmms1.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dxgmms2.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\EhStorTcgDrv.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\fastfat.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\fvevol.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\FWPKCLNT.SYS:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\hidclass.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\hidparse.sys:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Drivers\hidusb.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\http.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\hvservice.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\hvsocket.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\iaLPSS2_GPIO2.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\iaLPSS2_I2C.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\iorate.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\IPMIDrv.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\kbdhid.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ks.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ksecdd.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ksecpkg.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\MegaSas2i.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\modem.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\mrxdav.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb10.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb20.sys:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Drivers\msiscsi.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\mskssrv.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ndis.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ntfs.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\nvhda64v.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\nvvad64v.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\nwifi.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\partmgr.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\pci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\pdc.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\rdbss.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\rt640x64.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\RTKVHD64.sys:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Drivers\sdbus.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\spaceport.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\srv.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\srv2.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\srvnet.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ssudbus.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ssudmdm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\storahci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\stornvme.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\storport.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tcpip.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tcpipreg.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tdx.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tpm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\vhdmp.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\vmbkmcl.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\vmbkmclr.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\vpci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\wcifs.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\WdiWiFi.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\winhvr.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\wof.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\xboxgip.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\xinputhid.sys:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Desktop\FRST64 (1).exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Desktop\FRST64 (1).exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\3439847136_9244c541bf.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\376.33-desktop-win10-64bit-international-whql.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\376.33-desktop-win10-64bit-international-whql.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\3WYSI120.rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\4e.ch11.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\4WNJSI.rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\4_Way_Stack_Interchange_(MV).rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\663214-1076006 - Jae Yoon Cha - Nov 2, 2016 201 PM - Jae Yoon Cha and Lorenz Work.xlsx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\AAER Assignment (1).docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\AAER Assignment (2).docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\AAER Assignment.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Accrued Expense Detail 20X3.xlsx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\android-data-recovery.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\android-data-recovery.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\artmoney731eng.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\artmoney731eng.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Audit Report Assignment.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\axx Center1.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\BlackboardCollaborateLauncher-Win.msi:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Bluerise_Plaza_(1024).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Bluerise_Plaza_(2048).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\BUSA 4980 Syllabus Fall2016_Section 033_FINAL.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\C6 Corporate Strategy_class only.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\C7 Acquisition and Restructuring.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\C8 International Strategy.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\C9 Cooperative+Strategy.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Cadwal.pptx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Chapter 10 Slides.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Chapter 6 Slides (1).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Chapter 6 Slides.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\client_21022 (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\client_21022 (2).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\client_21022.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\comp22529.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\CTTV Headquarter.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\db65d4e861e57d654c5f9e143f760833.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\DDUv96-[Guru3D.com].exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\DDUv96-[Guru3D.com].exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Display Driver Uninstaller.exe:$CmdTcID [130]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\European_W2W_Pack1.rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\expense template (1).xlsx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\flstudio_12.4.2.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\flstudio_12.4.2.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\FRST64.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\FRST64.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Governance Failure of Satyam (1).docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Governance Failure of Satyam.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Hightops&Laces (1) (1).pptx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Hightops&Laces (1).pptx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Hightops&Laces.pptx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Invoices for Search.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Japanese shop 2 .crp.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Kim-Anh-Vu-Satyam-Case-Analysis.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Kim_Plaza_-_Growable_-_1024.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Kim_Plaza_-_Growable_-_2048.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Kim_Plaza_-_Ploppable_-_1024.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Kim_Plaza_-_Ploppable_-_2048.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\KindleForPC-installer-1.17.44183.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\KindleForPC-installer-1.17.44183.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\launcher_1004.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Legal Issues in Hiring Employees.docx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Loss.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\mdoyle.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\nativeplayback (1).collab:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\nativeplayback (2).collab:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\nativeplayback (3).collab:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\nativeplayback (4).collab:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\nativeplayback.collab:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\NYC Apartment.rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\o15-ctrremove.diagcab:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\OANDA_Desktop.msi:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Ocean Tower2.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\ScpToolkit_Setup.exe:$CmdTcID [130]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\ScpToolkit_Setup.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Search Testwork Template.xlsx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Setup.x86.en-US_ProPlusRetail_N43H4-FQQJP-B2GKW-BGKWC-TMT97_TX_PR_act_1_ (1).exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Setup.x86.en-US_ProPlusRetail_N43H4-FQQJP-B2GKW-BGKWC-TMT97_TX_PR_act_1_ (1).exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Setup.x86.en-US_ProPlusRetail_N43H4-FQQJP-B2GKW-BGKWC-TMT97_TX_PR_act_1_.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Setup.x86.en-US_ProPlusRetail_N43H4-FQQJP-B2GKW-BGKWC-TMT97_TX_PR_act_1_.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\slipstripsfalls (1).ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\slipstripsfalls.ppt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\SonyVegasPro13.0Build29064BitMultilingualChingLiu_archive (1).torrent:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\SonyVegasPro13.0Build29064BitMultilingualChingLiu_archive.torrent:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Student Final Self Evaluation-GA State Law.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\SURL Instructions.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Teaching Notes #6v3_class only (1).doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Teaching Notes #6v3_class only.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Teaching Notes #7v2.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Teaching Notes #8.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Teaching Notes #9.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\TeamSpeak3-Client-win64-3.0.19.4.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\TeamSpeak3-Client-win64-3.0.19.4.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\The City Office Building.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\The Shard Less Saturation.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\thinkorswim_x64_installer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\thinkorswim_x64_installer.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\TP Aging 20X3.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Unconfirmed 403935.crdownload:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\uTorrent.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\uTorrent.exe:$CmdZnID [29]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Welcome Packet OOS Tax & Audit Ben.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\winamp5666_full_all_redux.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\winamp5666_full_all_redux.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Yoshi_Towers_(1024).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\Yoshi_Towers_(2048).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\ZED68-PRINCETOWER-4x4HCL3 (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Solo Bolo\Downloads\ZED68-PRINCETOWER-4x4HCL3.zip:$CmdZnID [26]
CMD: ipconfig /flushdns
Emptytemp:
*****************
 
Processes closed successfully.
Restore point was successfully created.
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
HKLM\System\CurrentControlSet\Services\MSICDSetup => key removed successfully
MSICDSetup => service removed successfully
HKLM\System\CurrentControlSet\Services\NTIOLib_1_0_C => key removed successfully
NTIOLib_1_0_C => service removed successfully
C:\Users\Solo Bolo\Downloads\Unconfirmed 943625.crdownload => moved successfully
C:\Users\Solo Bolo\Downloads\Unconfirmed 368439.crdownload => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{2D8BDF82-909D-4308-9CDF-CB66D313FC64} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2D8BDF82-909D-4308-9CDF-CB66D313FC64} => key removed successfully
C:\Windows\System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9010427D-D57D-412D-889E-2FA03423B7F0} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9010427D-D57D-412D-889E-2FA03423B7F0} => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{966A7C09-6C5B-4CDF-8378-3843F7925BC1} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{966A7C09-6C5B-4CDF-8378-3843F7925BC1} => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BBDBFD4E-4096-477F-BED1-ED168C84C74B} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBDBFD4E-4096-477F-BED1-ED168C84C74B} => key removed successfully
C:\Windows\System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => key removed successfully
"C:\Program Files\COMODO" => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C6139D82-425A-4B0C-9C7A-B859FC2A9A5F} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6139D82-425A-4B0C-9C7A-B859FC2A9A5F} => key removed successfully
C:\Windows\System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => key removed successfully
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe" => not found.
"C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe" => not found.
"C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe" => not found.
"C:\Program Files\COMODO\COMODO Internet Security\cis.exe" => not found.
"C:\Program Files\COMODO\COMODO Internet Security\cmdupd.exe" => not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => value not found.
CmdAgent => service not found.
cmdvirth => service not found.
cmderd => service not found.
cmdGuard => service not found.
cmdhlp => service not found.
 
========= netsh advfirewall reset =========
 
Ok.
 
 
========= End of CMD: =========
 
 
========= netsh advfirewall set allprofiles state ON =========
 
Ok.
 
 
========= End of CMD: =========
 
C:\Windows\avastSS.scr => ":$CmdTcID" ADS removed successfully.
C:\Windows\explorer.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\HelpPane.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\NvContainerRecovery.bat => ":$CmdTcID" ADS removed successfully.
C:\Windows\regedit.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\splwow64.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\aadcloudap.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\aadtb.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AboveLockAppHost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\accountaccessor.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AccountsRt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\aclui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\acmigration.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ACPBackgroundManagerPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AcpiServiceVnA64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ActionCenter.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ActionCenterCPL.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ActivationManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ActiveSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\actxprxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AddressParser.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\adsmsext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\aeinv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\aepic.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AERTAC64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AERTAR64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\aitstatic.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppCapture.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppContracts.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\appinfo.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ApplicationFrame.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppointmentActivation.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppointmentApis.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\appraiser.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppReadiness.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\apprepapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\apprepsync.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVCatalog.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVClient.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVDllSurrogate.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVEntStreamingManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVEntSubsystemController.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVEntSubsystems64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVEntVirtualization.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVIntegration.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVManifest.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVOrchestration.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVPublishing.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVReporting.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVScripting.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppVShNotify.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\appwiz.cpl => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppXApplicabilityBlob.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppXDeploymentClient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppXDeploymentExtensions.desktop.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppXDeploymentExtensions.onecore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppXDeploymentServer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AppxPackaging.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\asycfilt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\atmfd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\atmlib.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AudioEndpointBuilder.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AudioEng.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AUDIOKSE.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\audioLibVc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AudioSes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\audiosrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AudioSrvPolicyManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AuthBroker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AuthHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\authui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\autoplay.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\AzureSettingSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\baaupdate.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\BackgroundMediaPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\BarcodeProvisioningPlugin.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\basecsp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\bcastdvr.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\BcastDVRHelper.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\bcdedit.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\bcrypt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\bdechangepin.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\bdesvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\bdeui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\bdeunlock.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\BingMaps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\BingOnlineServices.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\bisrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\BitLockerDeviceEncryption.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\biwinrt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\BluetoothApis.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\BluetoothDesktopHandlers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\BootMenuUX.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\bootux.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\browserbroker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\BrowserSettingSync.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\BthRadioMedia.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CameraCaptureUI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CastLaunch.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CbtBackgroundManagerPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cdd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cdp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cdpsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cdpusersvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CellularAPI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cemapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CertEnroll.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\certprop.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CfgSPCellular.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Chakra.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Chakradiag.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Chakrathunk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\chartv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ChatApis.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ci.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ClipboardServer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ClipUp.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cloudAP.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CloudBackupSettings.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CloudDomainJoinDataModelServer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CloudExperienceHost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CloudExperienceHostBroker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CloudExperienceHostCommon.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CloudExperienceHostUser.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CloudStorageWizard.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\clusapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cmifw.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cmintegrator.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\combase.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\comdlg32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CompatTelRunner.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CompPkgSup.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\comsvcs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CONEQMSAPOGUILibrary.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ConsoleLogon.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ContactActivation.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ContactApis.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\container.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ContentDeliveryManager.Utilities.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CoreMessaging.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CoreUIComponents.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CPFilters.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CredProvDataModel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\credprovhost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\credprovs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\credprovslegacy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\crypt32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cryptngc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CryptoWinRT.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cryptui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\cscui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CspCellularSettings.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\csrsrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\CX64APO.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\C_G18030.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\c_GSM7.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\C_IS2022.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d2d1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3d10warp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3d11.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3D12.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3d9.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_33.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_34.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_35.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_36.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_37.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_38.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_39.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DCompiler_47.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dcsx_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_33.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_34.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_35.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_36.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_37.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_38.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_39.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx10_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx11_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx11_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_24.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_25.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_26.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_27.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_28.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_29.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_30.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_31.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_33.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_34.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_35.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\d3dx9_36.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_37.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_38.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_39.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_40.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_41.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\D3DX9_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dab.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dafBth.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dafpos.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DafPrintProvider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\das.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dasHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DataExchange.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DataSenseHandlers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DavSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\daxexec.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dbgeng.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DbgModel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dcntel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DdcWnsListener.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DDPA64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DDPA64F3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DDPD64A.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DDPD64AF3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DDPO64A.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DDPO64AF3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DDPP64A.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DDPP64AF3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ddraw.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ddrawex.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\delegatorprovider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DeveloperOptionsSettingsHandlers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\devenum.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\deviceaccess.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\deviceassociation.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DeviceCensus.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DeviceCenter.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DeviceDirectoryClient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DeviceEnroller.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DeviceFlows.DataModel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DevicePairing.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DevicePairingFolder.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DeviceReactivation.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\devinv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dggpext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dhcpcore6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\diagtrack.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dialclient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dialserver.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\discan.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Display.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DisplayManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dlnashext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dmcertinst.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dmenrollengine.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DMRServer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dnsapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dnsrslvr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DolbyDAX2APOProp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DolbyDAX2APOv201.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DolbyDAX2APOv211.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DolbyDecMFT.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\domgmt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dosvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dpapisrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\drvstore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DscCore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DscCoreConfProv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dsreg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dsregcmd.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSBassEnhancementDLL64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSBoostDLL64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSGainCompensatorDLL64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSGFXAPO64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSGFXAPONS64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSLFXAPO64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSLimiterDLL64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSNeoPCDLL64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSS2HeadphoneDLL64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSS2SpeakerDLL64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSSymmetryDLL64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSU2PGFX64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSU2PLFX64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSU2PREC64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DTSVoiceClarityDLL64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DuCsps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dui70.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dwmapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dwmcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DWrite.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dxgi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dxmasf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\DXP.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\dxtrans.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\EAMProgressHandler.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\eapp3hst.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\eappcfg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\eappgnui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\eapphost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\eappprxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\easwrt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\edgehtml.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\EditBufferTestHook.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\EditionUpgradeHelper.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\EditionUpgradeManagerObj.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\EDPCleanup.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\efsext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\efswrt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\EmailApis.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\encapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\EncDec.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\energy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\enrollmentapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\EnterpriseAPNCsp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\EnterpriseAppMgmtSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\enterprisecsps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ErrorDetails.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ErrorDetailsUpdate.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\esent.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\esentutl.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\evr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ExplorerFrame.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ExSMime.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ExtrasXmlParser.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\facecredentialprovider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Family.Authentication.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Family.Client.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Family.SyncEngine.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ffbroker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\fhcfg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\fhcpl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\fhsettingsprovider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\FlightSettings.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\flvprophandler.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\FMAPO64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\FntCache.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\fontdrvhost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\fontext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\FontProvider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\FrameServer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\FSClient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\fveapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\fveapibase.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\fvecpl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\fvenotify.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\fveprompt.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\fveui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\fvewiz.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\GamePanel.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\GamePanelExternalHook.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\gameux.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\gdi32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\gdi32full.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\GdiPlus.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\generaltel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\GenValObj.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Geolocation.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\GlobCollationHost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\gpapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\gpsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\hal.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\HarmanAudioInterface.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\hevcdecoder.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\hgcpl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\HiFiDAX2API.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\HMAPO.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\HMClariFi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\HMEQ.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\HMEQ_Voice.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\HMHVS.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\HMLimiter.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\HMUI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\HttpsDataSource.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\hvax64.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\hvix64.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\hvloader.efi => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\hvloader.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ICEsoundAPO64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\icfupgd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\icm32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\icsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\icsvcext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\IdCtrls.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ie4uinit.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ieapfltr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\iedkcs32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ieframe.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\iepeers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ieproxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\iernonce.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\iertutil.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\iesetup.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\imapi2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\imapi2fs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ImplatSetup.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\indexeddbserver.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\inetcomm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\inetcpl.cpl => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\input.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\InputLocaleManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\InputService.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\InstallAgent.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\InstallAgentUserBroker.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\IntelSSTAPO.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\IntelSstCApoPropPage.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\internetmail.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\invagent.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\IPHLPAPI.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\iphlpsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ipnathlp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\iprtrmgr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\iscsiwmi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\JpMapControl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\jscript9.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\jscript9diag.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\jsproxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\KAAPORT64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\kdhvcom.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\kerberos.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\KernelBase.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\KnobsCore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\KnobsCsp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\LaunchWinApp.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\LicenseManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\LicenseManagerSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ListSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\localspl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\LocationFramework.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\LockAppBroker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\LockAppHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\LogonController.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\lpremove.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\LsaIso.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\lsasrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\lsass.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\lsm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\main.cpl => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\manage-bde.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MapConfiguration.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MapControlCore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MapControlStringsRes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MapGeocoder.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MapRouter.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MapsBtSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MapsBtSvcProxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MapsCSP.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MapsStore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mapstoasttask.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mapsupdatetask.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxAudioAPO20.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxAudioAPO30.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxAudioAPO4064.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxAudioAPO5064.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxAudioAPO6064.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxAudioAPO7064.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxAudioAPOShell64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxAudioEQ64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxAudioRealtek64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxSpeechAPO64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxVoiceAPO2064.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxVoiceAPO3064.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxVoiceAPO4064.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MaxxVolumeSDAPO.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MbaeApiPublic.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mbsmsapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MCCSEngineShared.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MCRecvSrc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MDEServer.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MDMAppInstaller.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mdmregistration.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MediaFoundation.DefaultPerceptionProvider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfasfsrcsnk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfaudiocnv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MFCaptureEngine.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfds.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfksproxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MFMediaEngine.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfmjpegdec.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfmkvsrcsnk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfmp4srcsnk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfmpeg2srcsnk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfnetcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfnetsrc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfplat.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MFPlay.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfpmp.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfreadwrite.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfsensorgroup.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfsrcsnk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mfsvr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Microsoft-Windows-MapControls.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Microsoft-Windows-MosHost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Microsoft-Windows-MosTrace.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\microsoft-windows-system-events.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\migisol.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MiracastReceiver.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mispace.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MISS_APO.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mmc.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MMDevAPI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\modernexecserver.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mos.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\moshost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MosHostClient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\moshostcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MosResource.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MosStorage.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mprapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mprddm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mprdim.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MpSigStub.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MPSSVC.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MrmCoreR.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MRT.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MSAC3ENC.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MSAJApi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MSAudDecMFT.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mscandui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msctf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msctfp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msctfui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msdtcprx.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msdtctm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msdtcuiu.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msdxm.ocx => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msfeeds.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msftedit.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mshtml.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mshtmled.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msinfo32.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msmpeg2vdec.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mspaint.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MSPhotography.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mssitlb.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mssph.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mssphtb.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mssprxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mssrch.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mssvp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mstsc.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\mstscax.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msutb.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msv1_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MSVidCtl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MSVideoDSP.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MSVP9DEC.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msvproc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MSVPXENC.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msxml3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msxml6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\msxml6r.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MultiDigiMon.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\musdialoghandlers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MusNotification.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MusNotificationUx.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\MusUpdateHandlers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NAHIMICAPOlfx.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NahimicAPONSControl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NAHIMICV2apo.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NAHIMICV3apo.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nativemap.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NaturalLanguage6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ncsi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NetCfgNotifyObjectHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\netiohlp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\netiougc.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\netplwiz.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NetSetupApi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NetSetupEngine.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NetSetupShim.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NetSetupSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\netshell.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nettrace.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NetworkBindingEngineMigPlugin.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NetworkCollectionAgent.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NetworkDesktopSettings.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NetworkMobileSettings.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NetworkUXBroker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NFCProvisioningPlugin.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NfcRadioMedia.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ngccredprov.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NgcCtnr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NgcCtnrGidsHandler.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NgcCtnrSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ngcsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nlasvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nltest.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NMAA.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NmaDirect.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NotificationController.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NPSM.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nshwfp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ntdll.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ntoskrnl.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ntshrui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvapi64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvaudcap64v.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvcompiler.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvcuda.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvcuvid.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvDecMFTMjpeg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvdispco6437633.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvdispco6437653.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvdispgenco6437633.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvdispgenco6437653.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvEncMFTH264.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvEncodeAPI64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvfatbinaryLoader.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NvFBC64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvhdagenco6420103.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvhdap64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NvIFR64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\NvIFROpenGL.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvoglv64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvopencl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\nvptxJitCompiler.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\odbcconf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\offlinelsa.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\offlinesam.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\offreg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ole32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\oleacc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\oleaut32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\OnDemandConnRouteHelper.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\OneBackupHandler.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\OneDriveSettingSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\OpenCL.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\pcasvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PCPTpm12.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\pdh.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PhoneProviders.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PhoneService.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PhoneServiceRes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Phoneutil.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PhoneutilRes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PhotoScreensaver.scr => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\pidgenx.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PimIndexMaintenance.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Pimstore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PlayToDevice.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PlayToManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PlayToReceiver.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\pmcsnap.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\pnidui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\policymanager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\poqexec.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\POSyncServices.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\powercfg.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ppcsnap.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PresentationNative_v0300.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PrintDialogs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PrintDialogs3D.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PrintRenderAPIHost.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PrintWSDAHost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\profsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\provdatastore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\provengine.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\provhandlers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\provisioningcsp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\provops.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ProvPluginEng.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ProvSysprep.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\provtool.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\PsmServiceExtHost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\psmsrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\puiapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\puiobj.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\pwcreator.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\pwrshplugin.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\qedit.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\qmgr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\quartz.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\R4EEA64A.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\R4EED64A.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\R4EEG64A.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\R4EEL64A.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\R4EEP64A.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RADCUI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rasapi32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rascustom.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rasgcw.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rasmans.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RCoInstII64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rdpcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rdpcorets.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rdpencom.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rdpinit.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RdpRelayTransport.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rdpshell.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rdpudd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RDXService.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RDXTaskFactory.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ReAgent.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ReAgentc.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RelPost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\remoteaudioendpoint.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RemoteNaturalLanguage.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RemovableMediaProvisioningPlugin.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ReportingCSP.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\reseteng.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ResetEngine.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ResetEngine.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\resutils.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RjvMDMConfig.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RltkAPO64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RMapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RP3DAA64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RP3DHT64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rpcrt4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\rshx32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RTCOM64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RtDataProc64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RTEED64A.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RTEEG64A.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RTEEL64A.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RTEEP64A.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RtkApi64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RtkCfg64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RtkCoLDR64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RtlCPAPI64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RTMediaFrame.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RtNicProp64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RtPgEx64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RTSnMg64.cpl => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\RTWorkQ.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\samlib.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\samsrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sbe.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ScDeviceEnum.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\schannel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\scksp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sdengin2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sdshext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SEAPO64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Search.ProtocolHandler.MAPI2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SearchFilterHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SearchFolder.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SearchIndexer.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SearchProtocolHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SecConfig.efi => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SECOMN64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SecureAssessmentHandlers.dll => ":$CmdTcID" ADS could not remove.
C:\Windows\system32\securekernel.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SEHDRA64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sendmail.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Sens.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SensorDataService.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SensorsApi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SensorService.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\services.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SessEnv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SettingsHandlers_Bluetooth.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SettingsHandlers_ClosedCaptioning.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SettingsHandlers_Flights.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SettingsHandlers_nt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SettingsHandlers_StorageSense.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SettingsHandlers_WorkAccess.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SettingSync.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SettingSyncCore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SettingSyncHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SettingSyncPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\setupugc.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SFAPO64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SFCOM64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SFNHK64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SFSS_APO.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SharedStartModel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ShareHost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SHCore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\shdocvw.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\shell32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\shutdownux.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\skci.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sl3apo64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\slc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\slcext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\slcnt64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\slprp64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sltech64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\smartscreen.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\smphost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SndVolSSO.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SpaceAgent.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SpaceControl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\spaceman.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SpeechPal.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\spoolsv.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sppc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sppcext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sppnp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sppobjs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sppsvc.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sppwinob.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\spwmp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SRAPO64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SRCOM.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SRCOM64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SRH.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SRHInproc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\srmclient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\srmscan.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SRRPTR64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SRSHP64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SRSTSH64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SRSTSX64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SRSWOW64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sspicli.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\stobject.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\StorageUsage.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\storagewmi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\storagewmi_passthru.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\StoreAgent.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\StorSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\StructuredQuery.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\sud.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SyncCenter.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SyncSettings.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SysResetErr.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\systemreset.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SystemSettings.DeviceEncryptionHandlers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SystemSettings.Handlers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SystemSettings.UserAccountsHandlers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SystemSettingsAdminFlows.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\SystemSettingsThresholdAdminFlowUI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Tabbtn.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tabcal.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TabletPC.cpl => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tadefxapo.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tadefxapo264.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tapi32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\taskbarcpl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tbauth.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tcpipcfg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tdh.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tepeqapo64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TextInputFramework.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\themecpl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\thumbcache.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\timedate.cpl => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TokenBroker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TokenBrokerCookies.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TokenBrokerUI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tosade.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tosasfapo64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\toseaeapo64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tossaeapo64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tossaemaxapo64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TpmCoreProvisioning.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TpmTasks.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tquery.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TransportDSA.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tsmf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TSpkg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tspubwmi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TSWorkspace.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\TsWpfWrp.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\twinapi.appcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\twinapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\twinui.appcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\twinui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\twinui.pcshell.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tzautoupdate.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\tzres.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ubpm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\uDWM.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UIAnimation.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UIAutomationCore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UIRibbon.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UIRibbonRes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\umpoext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\unimdm.tsp => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Unistore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\updatehandlers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\updatepolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\uReFS.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\urlmon.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\usbmon.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\user32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\usercpl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UserDataAccessRes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UserDataLanguageUtil.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UserDataPlatformHelperUtil.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UserDataService.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UserDataTimeUtil.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UserDataTypeHelperUtil.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UserDeviceRegistration.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UserDeviceRegistration.Ngc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UserLanguagesCpl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\usermgr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\UserMgrProxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\usoapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\usocore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\vaultcli.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\vbscript.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\VCardParser.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\vds.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\VEStoreEventHandlers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\vmrdvcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\vorbis.acm => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\vpnike.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\VPNv2CSP.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\vssapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\VSSVC.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\vss_ps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\vulkaninfo-1-1-0-26-0.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\vulkaninfo.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\w32time.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WavesGUILib64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wbengine.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wbiosrvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wcmsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wcnwiz.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wc_storage.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WdfCoInstaller01007.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WebcamUi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\webcheck.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\webio.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\werconcpl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\weretw.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\werui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wevtapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wevtsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wfdprov.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WiFiConfigSP.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wificonnapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wifinetworkmanager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wifiprofilessettinghandler.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wifitask.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\win32k.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\win32kbase.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\win32kfull.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\win32spl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\win32u.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WinBioDataModel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WinBioDataModelOOBE.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wincorlib.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.AccountsControl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.ApplicationModel.Core.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.ApplicationModel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.ApplicationModel.Store.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.ApplicationModel.Wallet.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Cortana.Desktop.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Cortana.OneCore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Data.Pdf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.AllJoyn.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.Bluetooth.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.HumanInterfaceDevice.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.Lights.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.LowLevel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.Midi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.Perception.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.Picker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.PointOfService.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.Printers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.Radios.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.Scanners.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.Sensors.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.SerialCommunication.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.SmartCards.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.SmartCards.Phone.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.Usb.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.WiFi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Devices.WiFiDirect.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Energy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Gaming.Input.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Gaming.UI.GameBar.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Gaming.XboxLive.Storage.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Globalization.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Graphics.Printing.3D.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Graphics.Printing.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Internal.Bluetooth.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Internal.Management.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Internal.Management.SecureAssessment.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Internal.Shell.Broker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Internal.UI.Logon.ProxyStub.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Management.Provisioning.ProxyStub.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.Audio.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.BackgroundMediaPlayback.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.Devices.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.Editing.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.FaceAnalysis.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.Import.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.MediaControl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.Ocr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.Playback.MediaPlayer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.Protection.PlayReady.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.Speech.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.Speech.UXRes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Media.Streaming.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Networking.Connectivity.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Networking.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Networking.HostName.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Networking.UX.EapRequestHandler.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Networking.Vpn.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Perception.Stub.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Security.Authentication.Identity.Provider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Security.Credentials.UI.CredentialPicker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Shell.Search.UriHandler.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.StateRepository.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.StateRepositoryBroker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.StateRepositoryClient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Storage.ApplicationData.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\windows.storage.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Storage.Search.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.System.SystemManagement.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.System.UserDeviceAssociation.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.BioFeedback.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.BlockedShutdown.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.Core.TextInput.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.Cred.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.CredDialogController.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.Immersive.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.Input.Inking.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.Logon.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.Search.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.Shell.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.Xaml.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.Xaml.InkControls.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.Xaml.Maps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.Xaml.Phone.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.UI.Xaml.Resources.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Web.Diagnostics.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Web.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Windows.Web.Http.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WindowsCodecs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winhttp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wininet.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wininetlui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winload.efi => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winload.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winlogon.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winmde.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winresume.efi => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winresume.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WinRtTracing.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WinSCard.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WinSetupUI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winspool.drv => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\winsrv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wintrust.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WinTypes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WinUSBCoInstaller.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wkssvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wlanapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wlancfg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wlanhlp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WlanMediaManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wlanmsm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wlansec.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wlansvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wlansvcpal.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wlanui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wlidprov.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wlidsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wmp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WMPDMC.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wmpdxm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wmpeffects.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wmploc.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wmpmde.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wmpps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wmpshell.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WMVDECOD.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WordBreakers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WorkFolders.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WorkfoldersControl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WorkFoldersGPExt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WorkFoldersShell.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\workfolderssvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wow64.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WpAXHolder.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Wpc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WpcMon.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WpcRefreshTask.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WpcTok.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WpcWebFilter.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wpnapps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wpncore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wpninprc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wpnprv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wpx.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\ws2_32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wscapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wscinterop.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wscsvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wscui.cpl => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wsecedit.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WSManHTTPConfig.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WSManMigrationPlugin.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WsmSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WsmWmiPl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wsp_fs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wsp_health.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wsp_sr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wuapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wuauclt.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wuaueng.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wups.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wups2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wuuhext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WwaApi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WWAHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\WWanAPI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wwanconn.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wwanmm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wwanprotdim.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\wwansvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\x3daudio1_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\x3daudio1_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\X3DAudio1_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\X3DAudio1_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\X3DAudio1_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\X3DAudio1_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\X3DAudio1_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\X3DAudio1_7.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_10.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_7.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_8.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine2_9.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine3_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine3_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine3_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine3_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xactengine3_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XamlTileRender.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAPOFX1_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAPOFX1_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAPOFX1_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAPOFX1_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAudio2_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAudio2_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAudio2_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XAudio2_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XblAuthManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XblAuthManagerProxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XblAuthTokenBrokerExt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XblGameSaveExt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XboxNetApiSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xinput1_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xinput1_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xinput1_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\XInputUap.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\xpsrchvw.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\YamahaAE.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\YamahaAE2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\zipfldr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\aadtb.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AboveLockAppHost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\accountaccessor.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\aclui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ActionCenterCPL.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ActivationManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ActiveSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\actxprxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AddressParser.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\adsmsext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\aepic.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\apds.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AppCapture.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AppContracts.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AppointmentActivation.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AppointmentApis.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\apprepapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\apprepsync.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AppVEntSubsystems32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\appwiz.cpl => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AppXDeploymentClient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AppxPackaging.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\asycfilt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\atmfd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\atmlib.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AUDIOKSE.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AudioSes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AuthBroker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AuthExt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\authui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\autoplay.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\azroleui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\AzureSettingSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\BackgroundMediaPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\basecsp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\bcastdvr.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\BcastDVRHelper.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\bcrypt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\BingMaps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\BingOnlineServices.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\biwinrt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\BluetoothApis.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\BrowserSettingSync.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\CameraCaptureUI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\cdp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\cemapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\CertEnroll.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Chakra.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Chakradiag.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Chakrathunk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\chartv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ChatApis.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ClipboardServer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\CloudBackupSettings.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\CloudExperienceHostCommon.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\CloudExperienceHostUser.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\CloudStorageWizard.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\clusapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\cmifw.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\combase.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\comctl32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\comdlg32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\CompPkgSup.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\comsvcs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ConfigureExpandedStorage.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ContactActivation.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ContactApis.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\container.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\CoreMessaging.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\CoreUIComponents.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\CPFilters.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\CredProvDataModel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\credprovhost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\credprovs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\credprovslegacy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\crypt32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\cryptngc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\CryptoWinRT.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\cryptui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\C_G18030.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\c_GSM7.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\C_IS2022.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d2d1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3d10warp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3d11.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3D12.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3d8.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3d9.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_33.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_34.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_35.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_36.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_37.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_38.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_39.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_40.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_41.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DCompiler_47.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dcsx_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_33.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_34.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_35.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_36.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_37.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_38.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_39.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_40.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_41.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx10_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx11_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx11_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_24.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_25.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_26.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_27.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_28.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_29.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_30.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_31.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_33.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_34.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_35.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\d3dx9_36.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_37.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_38.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_39.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_40.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_41.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_42.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\D3DX9_43.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\DafPrintProvider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\DataExchange.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\DavSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\daxexec.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dbgeng.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\DbgModel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ddraw.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ddrawex.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\delegatorprovider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\devenum.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\deviceaccess.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\deviceassociation.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\DeviceFlows.DataModel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\DevicePairing.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dhcpcore6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dialclient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\DisplayManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dlnashext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dmenrollengine.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dnsapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\DolbyDecMFT.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\drvstore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\DscCoreConfProv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dsreg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dtdump.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dwmapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dwmcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\DWrite.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dxgi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dxmasf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\dxtrans.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\eapp3hst.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\eappcfg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\eappgnui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\eapphost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\eappprxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\edgehtml.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\EditBufferTestHook.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\efsext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\efswrt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\EmailApis.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\encapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\enrollmentapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ErrorDetails.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ErrorDetailsUpdate.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\esent.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\esentutl.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\evr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\explorer.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ExplorerFrame.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ExSMime.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ExtrasXmlParser.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\findnetprinters.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\FlashPlayerApp.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\fontdrvhost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\fontext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\FSClient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\GamePanel.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\GamePanelExternalHook.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\gameux.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\gdi32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\gdi32full.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\GdiPlus.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Geolocation.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\GlobCollationHost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\gpapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\hevcdecoder.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\hgcpl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\icm32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ieapfltr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\iedkcs32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ieframe.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\iepeers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ieproxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\iernonce.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\iertutil.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\iesetup.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\imapi2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\imapi2fs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\indexeddbserver.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\inetcomm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\inetcpl.cpl => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\input.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\InputLocaleManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\InputService.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\InstallAgent.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\InstallAgentUserBroker.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\IPHLPAPI.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\iprtrmgr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ipsecsnp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ipsmsnap.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\iscsiwmi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\JpMapControl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\jscript9.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\jscript9diag.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\jsproxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\kerberos.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\KernelBase.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\LaunchWinApp.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\LicenseManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\LicenseManagerApi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\LockAppBroker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\LockAppHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\LogonController.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\main.cpl => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MapConfiguration.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MapControlCore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MapControlStringsRes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MapGeocoder.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MapRouter.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MapsBtSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MbaeApiPublic.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mbsmsapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MCCSEngineShared.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MCRecvSrc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mdmregistration.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfasfsrcsnk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfaudiocnv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfds.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfksproxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MFMediaEngine.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfmjpegdec.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfmkvsrcsnk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfmp4srcsnk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfmpeg2srcsnk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfnetcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfnetsrc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfplat.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MFPlay.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfpmp.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfreadwrite.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfsensorgroup.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfsrcsnk.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mfsvr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Microsoft-Windows-MapControls.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Microsoft-Windows-MosHost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Microsoft-Windows-MosTrace.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\migisol.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MiracastReceiver.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mispace.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mmc.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MMDevAPI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mos.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MosHostClient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MosResource.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MosStorage.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mprapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mprddm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mprdim.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MrmCoreR.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MSAC3ENC.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MSAJApi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mscandui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mscms.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msctf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msctfp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msctfui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msdtcprx.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msdtcuiu.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msdxm.ocx => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msfeeds.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msftedit.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mshtml.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mshtmled.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msinfo32.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msmpeg2vdec.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mspaint.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MSPhotography.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mssitlb.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mssph.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mssphtb.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mssrch.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mssvp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mstsc.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mstscax.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msutb.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msv1_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MSVidCtl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MSVP9DEC.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msvproc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\MSVPXENC.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msxml3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msxml6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\msxml6r.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\mtxclu.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\muachost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\NaturalLanguage6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\NetCfgNotifyObjectHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\netiohlp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\netiougc.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\NetSetupApi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\NetSetupEngine.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\NetSetupShim.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\netshell.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\NetworkCollectionAgent.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ngccredprov.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\NMAA.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\NmaDirect.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\NPSM.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nshwfp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ntdll.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ntshrui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nvapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nvaudcap32v.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nvcompiler.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nvcuda.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nvcuvid.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nvDecMFTMjpeg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nvEncMFTH264.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nvEncodeAPI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nvfatbinaryLoader.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\NvFBC.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\NvIFR.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\NvIFROpenGL.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nvoglv32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nvopencl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nvptxJitCompiler.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\nvStreaming.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\odbcconf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\offlinelsa.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\offlinesam.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\offreg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ole32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\oleacc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\oleaut32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\olepro32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\OneDriveSetup.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\OpenCL.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\PCPTpm12.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\pdh.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Phoneutil.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\PhoneutilRes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\PhotoScreensaver.scr => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\pidgenx.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Pimstore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\PlayToDevice.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\PlayToManager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\PlayToReceiver.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\policymanager.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\poqexec.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\POSyncServices.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\powercfg.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\PresentationNative_v0300.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\PrintConfig.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\PrintDialogs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ProximityCommon.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\puiapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\puiobj.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\pwrshplugin.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\qdvd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\quartz.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\RADCUI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\rasapi32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\rasgcw.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\rdpcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\rdpencom.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ReAgent.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ReAgentc.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\regedit.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\remoteaudioendpoint.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\RemoteNaturalLanguage.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\resutils.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\RltkAPO.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\rpcrt4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\RTMediaFrame.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\RTWorkQ.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\samlib.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\sbe.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\schannel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\scksp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Search.ProtocolHandler.MAPI2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SearchFilterHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SearchFolder.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SearchIndexer.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SearchProtocolHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SECOMN32.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\sendmail.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SessEnv.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SettingSync.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SettingSyncCore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SettingSyncHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SettingSyncPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\setupugc.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SFCOM.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ShareHost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SHCore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\shell32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\slc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\slcext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\smphost.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SndVolSSO.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\sppc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\sppcext.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\spwmp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SRCOM.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\srmclient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\sspicli.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\stobject.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\storagewmi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\storagewmi_passthru.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\StoreAgent.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\StructuredQuery.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\sud.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\SyncSettings.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\systemcpl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\tapi32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\tbauth.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\tcpipcfg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\tdh.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\TempSignedLicenseExchangeTask.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\TextInputFramework.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\themecpl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\thumbcache.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\TokenBroker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\TokenBrokerCookies.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\TokenBrokerUI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\TpmCoreProvisioning.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\tquery.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\tsmf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\TSpkg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\TSWorkspace.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\TsWpfWrp.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\twinapi.appcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\twinapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\twinui.appcore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\twinui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\tzres.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UIAnimation.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UIAutomationCore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UIRibbon.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UIRibbonRes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\unimdm.tsp => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Unistore.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\updatepolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\uReFS.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\urlmon.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\user32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\usercpl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UserDataAccessRes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UserDataAccountApis.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UserDataLanguageUtil.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UserDataPlatformHelperUtil.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UserDataTimeUtil.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UserDataTypeHelperUtil.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UserDeviceRegistration.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UserDeviceRegistration.Ngc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UserLanguagesCpl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\UserMgrProxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\usoapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\vaultcli.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\vbscript.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\VCardParser.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\vorbis.acm => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\vssapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\vulkaninfo-1-1-0-26-0.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\vulkaninfo.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wcnwiz.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WebcamUi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\webcheck.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\webio.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\weretw.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wevtapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wfdprov.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\win32k.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\win32kfull.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\win32u.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wincorlib.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.AccountsControl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.ApplicationModel.Core.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.ApplicationModel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.ApplicationModel.Wallet.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Data.Pdf.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.AllJoyn.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.Lights.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.LowLevel.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.Midi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.Perception.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.Picker.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.PointOfService.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.Radios.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.Scanners.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.Sensors.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.SerialCommunication.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.SmartCards.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.Usb.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.WiFi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Devices.WiFiDirect.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Energy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Gaming.Input.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Gaming.UI.GameBar.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Gaming.XboxLive.Storage.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Globalization.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Graphics.Printing.3D.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Graphics.Printing.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Internal.Management.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.Audio.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.Devices.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.Editing.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.FaceAnalysis.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.Import.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.MediaControl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.Ocr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.Playback.MediaPlayer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.Speech.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.Speech.UXRes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Media.Streaming.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Networking.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Networking.HostName.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Perception.Stub.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Security.Authentication.OnlineId.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Shell.Search.UriHandler.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.StateRepository.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\windows.storage.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Storage.Search.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.System.SystemManagement.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.System.UserDeviceAssociation.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.BioFeedback.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.Cred.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.CredDialogController.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.Immersive.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.Logon.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.Search.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.Xaml.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.Xaml.InkControls.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.Xaml.Maps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.Xaml.Phone.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Web.Diagnostics.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Web.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Windows.Web.Http.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WindowsCodecs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\winhttp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wininet.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wininetlui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\winmde.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WinRtTracing.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WinSCard.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\winspool.drv => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wintrust.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WinTypes.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wlanapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wlancfg.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wlanhlp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wlanui.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wlidcli.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wlidprov.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wmp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WMPDMC.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wmpdxm.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wmpeffects.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wmploc.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wmpmde.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wmpshell.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WMVSENCD.DLL => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WordBreakers.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\Wpc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WpcWebFilter.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WPDShServiceObj.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wpnapps.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\ws2_32.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wscapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wscinterop.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wscui.cpl => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wsecedit.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WSManHTTPConfig.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WsmSvc.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WsmWmiPl.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wsp_fs.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wsp_health.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wsp_sr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\wuapi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WwaApi.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WWAHost.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\WWanAPI.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\x3daudio1_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\x3daudio1_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\X3DAudio1_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\X3DAudio1_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\X3DAudio1_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\X3DAudio1_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\X3DAudio1_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\X3DAudio1_7.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_10.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_7.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_8.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine2_9.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xactengine3_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAPOFX1_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAPOFX1_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAPOFX1_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAPOFX1_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAPOFX1_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_0.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_4.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_5.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XAudio2_6.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XblAuthManagerProxy.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XblAuthTokenBrokerExt.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xinput1_1.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xinput1_2.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xinput1_3.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\XInputUap.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xolehlp.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\xpsrchvw.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\zipfldr.dll => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\afd.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\ahcache.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\AppVStrm.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\BasicDisplay.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\BasicRender.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\bowser.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\capimg.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\Classpnp.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\clfs.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\ClipSp.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\cmimcext.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\cng.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\crashdmp.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\csc.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\dam.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\dfsc.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\dumpsd.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\dxgkrnl.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\dxgmms1.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\dxgmms2.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\EhStorTcgDrv.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\fastfat.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\fvevol.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\FWPKCLNT.SYS => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\hidclass.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\hidparse.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\hidusb.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\http.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\hvservice.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\hvsocket.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\iaLPSS2_GPIO2.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\iaLPSS2_I2C.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\iorate.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\IPMIDrv.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\kbdhid.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\ks.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\ksecdd.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\ksecpkg.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\MegaSas2i.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\modem.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\mrxdav.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\mrxsmb.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\mrxsmb10.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\mrxsmb20.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\msiscsi.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\mskssrv.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\ndis.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\ntfs.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\nvhda64v.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\nvvad64v.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\nwifi.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\partmgr.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\pci.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\pdc.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\rdbss.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\rt640x64.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\RTKVHD64.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\sdbus.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\spaceport.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\srv.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\srv2.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\srvnet.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\ssudbus.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\ssudmdm.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\storahci.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\stornvme.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\storport.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\tcpip.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\tcpipreg.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\tdx.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\tm.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\tpm.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\vhdmp.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\vmbkmcl.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\vmbkmclr.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\vpci.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\wcifs.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\WdiWiFi.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\winhvr.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\wof.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\xboxgip.sys => ":$CmdTcID" ADS removed successfully.
C:\Windows\system32\Drivers\xinputhid.sys => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Desktop\FRST64 (1).exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Desktop\FRST64 (1).exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\3439847136_9244c541bf.jpg => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\376.33-desktop-win10-64bit-international-whql.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\376.33-desktop-win10-64bit-international-whql.exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\3WYSI120.rar => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\4e.ch11.ppt => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\4WNJSI.rar => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\4_Way_Stack_Interchange_(MV).rar => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\663214-1076006 - Jae Yoon Cha - Nov 2, 2016 201 PM - Jae Yoon Cha and Lorenz Work.xlsx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\AAER Assignment (1).docx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\AAER Assignment (2).docx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\AAER Assignment.docx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Accrued Expense Detail 20X3.xlsx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\android-data-recovery.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\android-data-recovery.exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\artmoney731eng.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\artmoney731eng.exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Audit Report Assignment.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\axx Center1.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\BlackboardCollaborateLauncher-Win.msi => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Bluerise_Plaza_(1024).zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Bluerise_Plaza_(2048).zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\BUSA 4980 Syllabus Fall2016_Section 033_FINAL.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\C6 Corporate Strategy_class only.ppt => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\C7 Acquisition and Restructuring.ppt => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\C8 International Strategy.ppt => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\C9 Cooperative+Strategy.ppt => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Cadwal.pptx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Chapter 10 Slides.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Chapter 6 Slides (1).pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Chapter 6 Slides.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\client_21022 (1).zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\client_21022 (2).zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\client_21022.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\comp22529.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\CTTV Headquarter.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\db65d4e861e57d654c5f9e143f760833.jpg => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\DDUv96-[Guru3D.com].exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\DDUv96-[Guru3D.com].exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Display Driver Uninstaller.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\European_W2W_Pack1.rar => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\expense template (1).xlsx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\flstudio_12.4.2.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\flstudio_12.4.2.exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\FRST64.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\FRST64.exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Governance Failure of Satyam (1).docx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Governance Failure of Satyam.docx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Hightops&Laces (1) (1).pptx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Hightops&Laces (1).pptx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Hightops&Laces.pptx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Invoices for Search.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Japanese shop 2 .crp.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Kim-Anh-Vu-Satyam-Case-Analysis.docx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Kim_Plaza_-_Growable_-_1024.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Kim_Plaza_-_Growable_-_2048.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Kim_Plaza_-_Ploppable_-_1024.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Kim_Plaza_-_Ploppable_-_2048.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\KindleForPC-installer-1.17.44183.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\KindleForPC-installer-1.17.44183.exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\launcher_1004.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Legal Issues in Hiring Employees.docx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Loss.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\mdoyle.ppt => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\nativeplayback (1).collab => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\nativeplayback (2).collab => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\nativeplayback (3).collab => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\nativeplayback (4).collab => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\nativeplayback.collab => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\NYC Apartment.rar => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\o15-ctrremove.diagcab => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\OANDA_Desktop.msi => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Ocean Tower2.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\ScpToolkit_Setup.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\ScpToolkit_Setup.exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Search Testwork Template.xlsx => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Setup.x86.en-US_ProPlusRetail_N43H4-FQQJP-B2GKW-BGKWC-TMT97_TX_PR_act_1_ (1).exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Setup.x86.en-US_ProPlusRetail_N43H4-FQQJP-B2GKW-BGKWC-TMT97_TX_PR_act_1_ (1).exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Setup.x86.en-US_ProPlusRetail_N43H4-FQQJP-B2GKW-BGKWC-TMT97_TX_PR_act_1_.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Setup.x86.en-US_ProPlusRetail_N43H4-FQQJP-B2GKW-BGKWC-TMT97_TX_PR_act_1_.exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\slipstripsfalls (1).ppt => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\slipstripsfalls.ppt => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\SonyVegasPro13.0Build29064BitMultilingualChingLiu_archive (1).torrent => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\SonyVegasPro13.0Build29064BitMultilingualChingLiu_archive.torrent => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Student Final Self Evaluation-GA State Law.doc => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\SURL Instructions.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Teaching Notes #6v3_class only (1).doc => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Teaching Notes #6v3_class only.doc => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Teaching Notes #7v2.doc => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Teaching Notes #8.doc => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Teaching Notes #9.doc => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\TeamSpeak3-Client-win64-3.0.19.4.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\TeamSpeak3-Client-win64-3.0.19.4.exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\The City Office Building.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\The Shard Less Saturation.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\thinkorswim_x64_installer.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\thinkorswim_x64_installer.exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\TP Aging 20X3.pdf => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Unconfirmed 403935.crdownload => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\uTorrent.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\uTorrent.exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Welcome Packet OOS Tax & Audit Ben.zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\winamp5666_full_all_redux.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\winamp5666_full_all_redux.exe => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Yoshi_Towers_(1024).zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\Yoshi_Towers_(2048).zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\ZED68-PRINCETOWER-4x4HCL3 (1).zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Solo Bolo\Downloads\ZED68-PRINCETOWER-4x4HCL3.zip => ":$CmdZnID" ADS removed successfully.
 
========= ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 871930871 B
Java, Flash, Steam htmlcache => 329336684 B
Windows/system/drivers => 56752441 B
Edge => 877534 B
Chrome => 384251347 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 36248 B
NetworkService => 10626 B
defaultuser0 => 587916 B
Solo Bolo => 1320916544 B
 
RecycleBin => 2169233701 B
EmptyTemp: => 4.8 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 01:41:22 ====

  • 0

#6
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Hello,

A few scans to do...

Next

Download AdwCleaner from here. Save the file to the desktop.
NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.
Close all open windows and browsers.
  • XP users: Double click the AdwCleaner icon to start the program.
  • Vista/7/8 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
    You will see the following console:
iO5EZayK.png
  • Click the Scan button and wait for the scan to finish.
  • After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: Pending. Please uncheck elements you don't want to remove.
  • Click the Clean button.
  • Everything checked will be moved to Quarantine.
  • When the program has finished cleaning a report appears.Once done it will ask to reboot, allow this
adwcleaner_delete_restart.jpg
  • On reboot a log will be produced please copy / paste that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[C0].txt
Next
  • Please download Junkware Removal Tool to your Desktop.
  • Please close your security software to avoid potential conflicts. See Here how to disable you security protection (Anti Virus)
  • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete, depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
  • Please post the contents of JRT.txt into your reply.

  • 0

#7
Soloinneed

Soloinneed

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

AwdCleaner log:

 

# AdwCleaner v6.046 - Logfile created 12/05/2017 at 01:57:11
# Updated on 24/04/2017 by Malwarebytes
# Database : 2017-05-10.1 [Server]
# Operating System : Windows 10 Pro  (X64)
# Username : Solo Bolo - DESKTOP-G2DJP68
# Running from : C:\Users\Solo Bolo\Downloads\adwcleaner_6.046.exe
# Mode: Clean
 
 
 
***** [ Services ] *****
 
[-] Service deleted: Updater
 
 
***** [ Folders ] *****
 
 
 
***** [ Files ] *****
 
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
[-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\geekbuddyrsp
[#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\geekbuddyrsp
 
 
***** [ Web browsers ] *****
 
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [990 Bytes] - [12/05/2017 01:57:11]
C:\AdwCleaner\AdwCleaner[S0].txt - [1293 Bytes] - [12/05/2017 01:55:36]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1135 Bytes] ##########
 
JRT log:
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 10 Pro x64 
Ran by Solo Bolo (Administrator) on Fri 05/12/2017 at  2:03:13.10
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 0 
 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 05/12/2017 at  2:05:49.91
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

  • 0

#8
Soloinneed

Soloinneed

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

I have a question. Prior to doing all of this, I had my external hard drive on to save a few images. Is my external hard drive a threat? It was only on for a few mins.


Edited by Soloinneed, 12 May 2017 - 12:11 AM.

  • 0

#9
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Hello,

No. Not a problem

Not seeing any malware so far, lets run a Malwarebytes scan.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that that all Threats are selected, and click Remove Selected.
  • Reboot your computer if prompted.
Posting the Malwarebytes log.
  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the Scan Log which shows the Date and time of the scan just performed.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • post that saved log to your next reply.

  • 0

#10
Soloinneed

Soloinneed

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

Here is the log:

 

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 5/12/17
Scan Time: 2:14 AM
Log File: Scan.txt
Administrator: Yes
 
-Software Information-
Version: 3.1.2.1733
Components Version: 1.0.122
Update Package Version: 1.0.1922
License: Trial
 
-System Information-
OS: Windows 10
CPU: x64
File System: NTFS
User: DESKTOP-G2DJP68\Solo Bolo
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 373399
Threats Detected: 0
(No malicious items detected)
Threats Quarantined: 0
(No malicious items detected)
Time Elapsed: 2 min, 5 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 0
(No malicious items detected)
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)

  • 0

Advertisements


#11
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Hello,

Once again no Malware. Is the computer still running bad ?

Thanks
Joe :)
  • 0

#12
Soloinneed

Soloinneed

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

Hey Joe,

 

So far the symptoms are not present. I've been able to run applications without lag, they also do not freeze. Everything seems to be operating normally.

I really appreciate you!

 

What was wrong with my computer? Was it a virus? Should I be wary of any malicious content hidden in my system?

 

Thanks Joe!


  • 0

#13
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
4.8 GB temporary data Removed.

Clear out your temp files once in a while, something may have been in there.

You can download this temp file cleaner to the desktop and run it once a month or so

http://www.geekstogo...er-by-oldtimer/
  • 0

#14
Soloinneed

Soloinneed

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

Alright thanks,

 

I'll make sure I do that. Is there anything else that I should do?


  • 0

#15
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Hello,

Clean you temp files, run Malwarebytes once a week. Be careful what you download. I'll have more tips in the closing.

You can also remove all the tools we used and log files. Right click and delete them from desktop.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP