Jump to content

elannesse

Members
  • Posts

    11
  • Joined

  • Last visited

Reputation

0 Neutral
  1. You are amazing!! Thank you so much for all your help tonight, truly appreciate your time. After I clean up and check funds, I'd be more than happy to donate what I can afford. Thanks again
  2. Actually, it's really working normally, no weird issues with multiple tabs opening on their own nor any freezing/mouse problems since I reported it.
  3. FixLog: Fix result of Farbar Recovery Scan Tool (x64) Version: 26-10-2016 Ran by Hercules (28-10-2016 21:13:35) Run:1 Running from E:\Desktop\Malware Detection Loaded Profiles: Hercules (Available Profiles: Hercules) Boot Mode: Normal ============================================== fixlist content: ***************** Start CreateRestorePoint: CloseProcesses: Tcpip\..\Interfaces\{C2545642-DE12-4C68-8BD8-0B9664E4CD75}: [NameServer] 95.211.10.3 Toolbar: HKU\S-1-5-21-1249842936-2245008602-654386766-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File FF NetworkProxy: Songbird2\Profiles\kegjnd5v.default -> no_proxies_on", "127.0.0.1;localhost" FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\albumart@songbirdnest.com [not found] FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\gonzo@songbirdnest.com [not found] FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\philips-addon-manager@songbirdnest.com [not found] FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\pinkmartini@songbirdnest.com [not found] FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\purplerain@songbirdnest.com [not found] FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\sharing@songbirdnest.com [not found] FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\soundboard@songbirdnest.com [not found] CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - <no Path/update_url> S3 cpuz135; \??\E:\Tmp\cpuz135\cpuz135_x64.sys [X] S3 dbx; system32\DRIVERS\dbx.sys [X] S3 dgderdrv; System32\drivers\dgderdrv.sys [X] S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X] U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X] 2015-10-25 12:27 - 2015-10-26 07:11 - 1187328 _____ (CPUID) C:\Users\Hercules\AppData\Roaming\siw_sdk.dll 2016-07-25 07:11 - 2016-07-25 07:11 - 0000016 _____ () C:\ProgramData\mntemp 2016-07-25 07:11 - 2016-07-25 07:11 - 0005085 _____ () C:\ProgramData\oqztiqep.adk AlternateDataStreams: C:\Windows\avastSS.scr:$CmdTcID [64] AlternateDataStreams: C:\Windows\explorer.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\py.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\pyw.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\acmigration.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\adsmsext.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\adtschema.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\advapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\aeinv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\aepic.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\aitstatic.exe:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\apisetschema.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appidapi.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\appidcertstorecheck.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appidpolicyconverter.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appidsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appinfo.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appraiser.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\asycfilt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\audiodg.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\AudioEng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\AUDIOKSE.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\AudioSes.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\audiosrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\auditpol.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\authui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\basesrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\blackbox.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\catsrvut.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\centel.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\certcli.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ci.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\clfs.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\clfsw32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\COLORCNV.DLL:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\CompatTelRunner.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\conhost.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\consent.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\CPFilters.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\credssp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\crypt32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptbase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptnet.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\csrsrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\davclnt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\DbxSvc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\devenum.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\devinv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\diagtrack.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\difx64.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\drmmgrtn.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\drmv2clt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dwmapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dwmcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\DWrite.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxcap.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxcpl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxmasf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxtmsft.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxtrans.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\EncDec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\EncDump.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\evr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ExplorerFrame.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\FntCache.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\generaltel.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\hccutils.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\hkcmd.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ie4uinit.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieapfltr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iedkcs32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieetwcollector.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieetwcollectorres.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieetwproxystub.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieframe.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iernonce.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iertutil.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iesetup.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieUnatt.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ig4dev64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ig4icd64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igd10umd64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igdumd64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxcfg.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxCoIn_v1930.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxcpl.cpl:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxdev.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxdo.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxexps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxext.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxpers.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxpph.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrara.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrchs.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrcht.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrcsy.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrdan.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrdeu.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrell.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrenu.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxresp.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxress.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrfin.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrfra.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrheb.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrhun.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrita.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrjpn.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrkor.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrnld.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrnor.lrc:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\igfxrplk.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrptb.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrptg.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrrus.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrsky.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrslv.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrsve.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrtha.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrtrk.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxsrvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxsrvc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxTMM.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\igfxtray.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inetcomm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inetcpl.cpl:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inetpp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inetppui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\INETRES.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\InkEd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inseng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\invagent.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\JavaScriptCollectionAgent.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jscript9.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jscript9diag.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jsproxy.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\kerberos.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\kernel32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\KernelBase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ksproxy.ax:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\ksuser.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lsasrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lsass.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lvco11801048.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lvco1201278.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lvcod64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\LVUI64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\LVUIRC64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mcmde.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfcm140ud.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mferror.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfplat.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfpmp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfvdsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MFWMAAEC.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MP3DMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MP43DECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MP4SDECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MPG4DECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MpSigStub.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MRT.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msaudite.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msctf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msdxm.ocx:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msfeeds.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mshtml.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MshtmlDac.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mshtmled.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mshtmlmedia.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msi.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\msiexec.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msihnd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msimsg.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\msmmsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msmpeg2adec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MSMPEG2ENC.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msmpeg2vdec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msnetobj.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msobjs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msrating.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MsRdpWebAccess.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msscp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MsSpellCheckingFacility.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mstsc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mstscax.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msv1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MSVidCtl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msxml6.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msxml6r.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ncrypt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntdll.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntprint.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntprint.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntvdm64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6434709.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6434725.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6434752.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\nvdispco6434788.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6435012.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6435330.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6435362.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6435382.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\nvdispco6435560.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\nvdispco6435582.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6434709.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6434725.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6434752.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\nvdispgenco6434788.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6435012.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6435330.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6435362.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6435382.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6435560.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6435582.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvhdagenco64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\occache.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcadm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcaevts.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcalua.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcasvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcawrk.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\poqexec.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\qasf.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\qdvd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\quartz.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rdvidcrl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\RESAMPLEDMO.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rpchttp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rpcrt4.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rrinstaller.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rstrui.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\scavengeui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\scesrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\schannel.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\schedsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\secur32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\services.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\setbcdlocale.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\shell32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\smss.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\spwmp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\srclient.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\srcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sspicli.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sspisrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SysFxUI.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sysmain.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\tdh.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\tsgqec.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\TSpkg.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TsUsbGDCoInstaller.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TSWbPrxy.exe:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\tzres.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\urlmon.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\UtcResources.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\vbscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\vcruntime140d.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\VIDRESZR.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\vsgraphicsremoteengine.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\vsjitdebugger.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wdi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wdigest.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\webcheck.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WebClnt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\win32k.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\win32spl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WindowsCodecs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wininet.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winload.efi:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winresume.efi:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winresume.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WinSetupUI.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winsrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wintrust.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wksprt.exe:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\wksprtPS.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMADMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMADMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMALFXGFXDSP.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wmdrmsdk.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wmp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wmploc.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wmpmde.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMSPDMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMSPDMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVDECOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVENCOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVSDECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVSENCD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVXENCD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wow64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wow64cpu.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wow64win.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wpdshext.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wpnpinst.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WSManHTTPConfig.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WSManMigrationPlugin.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WsmAuto.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wsmplpxy.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wsmprovhost.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WsmRes.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WsmSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WsmWmiPl.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\wu.upgrade.ps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuapp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuauclt.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuaueng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wucltux.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wudriver.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wups.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wups2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuwebv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\adsmsext.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\adtschema.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\advapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\apisetschema.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\appidapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\asycfilt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\AudioEng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\AUDIOKSE.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\AudioSes.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\auditpol.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\authui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\blackbox.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\catsrvut.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\certcli.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\clfsw32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\COLORCNV.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\comsvcs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\CPFilters.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\credssp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\crypt32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptbase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptnet.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\davclnt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\devenum.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\drmmgrtn.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\drmv2clt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dwmapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dwmcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\DWrite.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dxcap.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dxcpl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dxmasf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dxtmsft.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\dxtrans.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\els.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\EncDec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\evr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\explorer.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ExplorerFrame.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieapfltr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iedkcs32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieetwproxystub.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieframe.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iernonce.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iertutil.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iesetup.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieUnatt.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ig4dev32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ig4icd32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\igd10umd32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\igdumd32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\igdumdx32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\igfxdv32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\igxpun.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\inetcomm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\inetcpl.cpl:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\INETRES.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\InkEd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\inseng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\instnm.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jscript9.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jscript9diag.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jsproxy.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\kerberos.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\kernel32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\KernelBase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ksproxy.ax:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ksuser.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\lvcodec2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\LVUI2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\LVUI2RC.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mferror.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfplat.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfpmp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfvdsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MFWMAAEC.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MP3DMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MP43DECD.DLL:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\MP4SDECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MPG4DECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msaudite.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msctf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msdxm.ocx:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msfeeds.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mshtml.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MshtmlDac.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mshtmled.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mshtmlmedia.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msiexec.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msihnd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msimsg.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msmpeg2adec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MSMPEG2ENC.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msmpeg2vdec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msnetobj.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msobjs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msrating.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MsRdpWebAccess.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msscp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mstsc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mstscax.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msv1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MSVidCtl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msxml6.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msxml6r.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ncrypt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ncsi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\nlaapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntdll.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntkrnlpa.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntoskrnl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntprint.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntprint.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntvdm64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\occache.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\oemdspif.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\olepro32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\poqexec.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\qasf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\qdvd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\qedit.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\quartz.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rdvidcrl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\RESAMPLEDMO.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rpchttp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rpcrt4.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rrinstaller.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\samlib.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\scesrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\schannel.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\secur32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\setup16.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\shell32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\spwmp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\srclient.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\sspicli.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\tdh.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\tsgqec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\TSpkg.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\tzres.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\urlmon.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\user.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\vbscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\VIDRESZR.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\vsd3dwarpdebug.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\vsgraphicsremoteengine.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\vsjitdebugger.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wdi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wdigest.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\webcheck.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WebClnt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\webio.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\win32spl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WindowsCodecs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wininet.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wintrust.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wksprtPS.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMADMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMADMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wmdrmsdk.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wmp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMPhoto.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wmploc.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wmpmde.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMSPDMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMSPDMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVDECOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVENCOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVSDECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVSENCD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVXENCD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wow32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wpdshext.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WSManHTTPConfig.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WSManMigrationPlugin.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WsmAuto.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wsmplpxy.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wsmprovhost.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WsmRes.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WsmSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WsmWmiPl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wuapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wuapp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wudriver.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wups.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wuwebv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\appid.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\dbx-canary.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\dbx-dev.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\dbx-stable.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\dfsc.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\drmk.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\drmkaud.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\FWPKCLNT.SYS:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\http.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\igdkmd64.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\jaksta_va.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ksecdd.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ksecpkg.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\lv302a64.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\LV302V64.SYS:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\lvrs64.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\LVUSBS64.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mbam.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mbamchameleon.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mountmgr.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mrxdav.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb10.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb20.sys:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Drivers\mwac.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ndis.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\netio.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\PEAuth.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\portcls.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\srv2.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\srvnet.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\tcpipreg.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\TsUsbFlt.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbccgp.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbd.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbehci.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbhub.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbohci.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbport.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbuhci.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\vpnva64-6.sys:$CmdTcID [64] Hosts: RemoveProxy: CMD: ipconfig /flushdns EmptyTemp: end ***************** Restore point was successfully created. Processes closed successfully. HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2545642-DE12-4C68-8BD8-0B9664E4CD75}\\NameServer => value removed successfully HKU\S-1-5-21-1249842936-2245008602-654386766-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => value removed successfully HKCR\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => key not found. Firefox Proxy settings were reset. C:\Program Files (x86)\Songbird\extensions\albumart@songbirdnest.com => path removed successfully C:\Program Files (x86)\Songbird\extensions\gonzo@songbirdnest.com => path removed successfully C:\Program Files (x86)\Songbird\extensions\philips-addon-manager@songbirdnest.com => path removed successfully C:\Program Files (x86)\Songbird\extensions\pinkmartini@songbirdnest.com => path removed successfully C:\Program Files (x86)\Songbird\extensions\purplerain@songbirdnest.com => path removed successfully C:\Program Files (x86)\Songbird\extensions\sharing@songbirdnest.com => path removed successfully C:\Program Files (x86)\Songbird\extensions\soundboard@songbirdnest.com => path removed successfully "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj" => key removed successfully cpuz135 => service removed successfully dbx => service removed successfully dgderdrv => service removed successfully nvvad_WaveExtensible => service removed successfully VBoxAswDrv => service could not remove C:\Users\Hercules\AppData\Roaming\siw_sdk.dll => moved successfully C:\ProgramData\mntemp => moved successfully C:\ProgramData\oqztiqep.adk => moved successfully C:\Windows\avastSS.scr => ":$CmdTcID" ADS could not remove. C:\Windows\explorer.exe => ":$CmdTcID" ADS could not remove. C:\Windows\py.exe => ":$CmdTcID" ADS could not remove. C:\Windows\pyw.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\acmigration.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\adsmsext.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\adtschema.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\advapi32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\aeinv.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\aepic.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\aitstatic.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\apisetschema.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\appidapi.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\appidcertstorecheck.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\appidpolicyconverter.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\appidsvc.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\appinfo.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\appraiser.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\asycfilt.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\audiodg.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\AudioEng.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\AUDIOKSE.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\AudioSes.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\audiosrv.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\auditpol.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\authui.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\basesrv.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\blackbox.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\catsrvut.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\centel.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\certcli.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ci.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\clfs.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\clfsw32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\COLORCNV.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\CompatTelRunner.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\conhost.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\consent.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\CPFilters.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\credssp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\crypt32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\cryptbase.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\cryptnet.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\cryptsp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\cryptsvc.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\cryptui.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\csrsrv.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\davclnt.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\DbxSvc.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\devenum.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\devinv.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\diagtrack.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\difx64.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\drmmgrtn.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\drmv2clt.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\dwmapi.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\dwmcore.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\DWrite.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\dxcap.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\dxcpl.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\dxmasf.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\dxtmsft.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\dxtrans.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\EncDec.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\EncDump.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\evr.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ExplorerFrame.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\FntCache.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\generaltel.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\hccutils.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\hkcmd.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ie4uinit.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ieapfltr.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\iedkcs32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ieetwcollector.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ieetwcollectorres.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ieetwproxystub.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ieframe.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\iernonce.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\iertutil.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\iesetup.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ieui.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ieUnatt.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ig4dev64.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ig4icd64.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igd10umd64.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igdumd64.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxcfg.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxCoIn_v1930.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxcpl.cpl => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxdev.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxdo.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxexps.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxext.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxpers.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxpph.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrara.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrchs.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrcht.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrcsy.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrdan.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrdeu.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrell.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrenu.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxresp.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxress.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrfin.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrfra.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrheb.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrhun.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrita.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrjpn.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrkor.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrnld.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrnor.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrplk.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrptb.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrptg.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrrus.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrsky.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrslv.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrsve.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrtha.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxrtrk.lrc => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxsrvc.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxsrvc.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxTMM.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\igfxtray.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\inetcomm.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\inetcpl.cpl => ":$CmdTcID" ADS could not remove. C:\Windows\system32\inetpp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\inetppui.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\INETRES.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\InkEd.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\inseng.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\invagent.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\JavaScriptCollectionAgent.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\jscript.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\jscript9.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\jscript9diag.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\jsproxy.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\kerberos.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\kernel32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\KernelBase.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ksproxy.ax => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ksuser.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\lsasrv.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\lsass.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\lvco11801048.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\lvco1201278.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\lvcod64.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\LVUI64.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\LVUIRC64.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\mcmde.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\mf.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\mfcm140ud.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\mferror.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\mfplat.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\mfpmp.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\mfps.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\mfvdsp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\MFWMAAEC.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\MP3DMOD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\MP43DECD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\MP4SDECD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\MPG4DECD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\MpSigStub.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\MRT.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msaudite.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msctf.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msdxm.ocx => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msfeeds.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\mshtml.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\MshtmlDac.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\mshtmled.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\mshtmlmedia.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msi.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msiexec.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msihnd.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msimsg.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msmmsp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msmpeg2adec.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\MSMPEG2ENC.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msmpeg2vdec.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msnetobj.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msobjs.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msrating.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\MsRdpWebAccess.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msscp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\MsSpellCheckingFacility.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\mstsc.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\mstscax.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msv1_0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\MSVidCtl.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msxml6.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\msxml6r.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ncrypt.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nlasvc.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ntdll.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ntoskrnl.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ntprint.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ntprint.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\ntvdm64.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispco64.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispco6434709.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispco6434725.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispco6434752.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispco6434788.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispco6435012.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispco6435330.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispco6435362.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispco6435382.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispco6435560.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispco6435582.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispgenco64.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispgenco6434709.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispgenco6434725.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispgenco6434752.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispgenco6434788.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispgenco6435012.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispgenco6435330.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispgenco6435362.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispgenco6435382.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispgenco6435560.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvdispgenco6435582.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\nvhdagenco64.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\occache.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\pcadm.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\pcaevts.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\pcalua.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\pcasvc.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\pcawrk.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\poqexec.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\qasf.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\qdvd.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\quartz.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\rdvidcrl.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\RESAMPLEDMO.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\rpchttp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\rpcrt4.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\rrinstaller.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\rstrui.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\scavengeui.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\scesrv.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\schannel.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\schedsvc.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\secur32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\services.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\setbcdlocale.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\shell32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\smss.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\spwmp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\srclient.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\srcore.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\sspicli.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\sspisrv.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\SysFxUI.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\sysmain.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\tdh.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\tsgqec.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\TSpkg.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\TsUsbGDCoInstaller.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\TSWbPrxy.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\tzres.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\urlmon.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\UtcResources.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\vbscript.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\vcruntime140d.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\VIDRESZR.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\vsgraphicsremoteengine.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\vsjitdebugger.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wdi.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wdigest.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\webcheck.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WebClnt.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\win32k.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\win32spl.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WindowsCodecs.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wininet.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\winload.efi => ":$CmdTcID" ADS could not remove. C:\Windows\system32\winresume.efi => ":$CmdTcID" ADS could not remove. C:\Windows\system32\winresume.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WinSetupUI.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\winsrv.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wintrust.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wksprt.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wksprtPS.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WMADMOD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WMADMOE.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WMALFXGFXDSP.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wmdrmsdk.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wmp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wmploc.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wmpmde.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WMSPDMOD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WMSPDMOE.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WMVDECOD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WMVENCOD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WMVSDECD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WMVSENCD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WMVXENCD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wow64.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wow64cpu.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wow64win.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wpdshext.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wpnpinst.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WSManHTTPConfig.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WSManMigrationPlugin.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WsmAuto.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wsmplpxy.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wsmprovhost.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WsmRes.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WsmSvc.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\WsmWmiPl.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wu.upgrade.ps.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wuapi.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wuapp.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wuauclt.exe => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wuaueng.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wucltux.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wudriver.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wups.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wups2.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\wuwebv.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\adsmsext.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\adtschema.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\advapi32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\apisetschema.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\appidapi.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\asycfilt.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\AudioEng.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\AUDIOKSE.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\AudioSes.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\auditpol.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\authui.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\blackbox.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\catsrvut.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\certcli.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\clfsw32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\COLORCNV.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\comsvcs.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\CPFilters.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\credssp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\crypt32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\cryptbase.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\cryptnet.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\cryptsp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\cryptsvc.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\cryptui.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\davclnt.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\devenum.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\drmmgrtn.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\drmv2clt.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\dwmapi.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\dwmcore.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\DWrite.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\dxcap.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\dxcpl.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\dxmasf.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\dxtmsft.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\dxtrans.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\els.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\EncDec.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\evr.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\explorer.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ExplorerFrame.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\FlashPlayerApp.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ieapfltr.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\iedkcs32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ieetwproxystub.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ieframe.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\iernonce.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\iertutil.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\iesetup.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ieui.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ieUnatt.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ig4dev32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ig4icd32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\igd10umd32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\igdumd32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\igdumdx32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\igfxdv32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\igxpun.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\inetcomm.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\inetcpl.cpl => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\INETRES.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\InkEd.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\inseng.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\instnm.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\jscript.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\jscript9.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\jscript9diag.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\jsproxy.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\kerberos.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\kernel32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\KernelBase.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ksproxy.ax => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ksuser.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\lvcodec2.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\LVUI2.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\LVUI2RC.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\mf.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\mferror.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\mfplat.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\mfpmp.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\mfps.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\mfvdsp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\MFWMAAEC.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\MP3DMOD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\MP43DECD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\MP4SDECD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\MPG4DECD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msaudite.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msctf.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msdxm.ocx => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msfeeds.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\mshtml.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\MshtmlDac.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\mshtmled.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\mshtmlmedia.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msi.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msiexec.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msihnd.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msimsg.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msmpeg2adec.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\MSMPEG2ENC.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msmpeg2vdec.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msnetobj.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msobjs.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msrating.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\MsRdpWebAccess.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msscp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\mstsc.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\mstscax.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msv1_0.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\MSVidCtl.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msxml6.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\msxml6r.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ncrypt.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ncsi.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\nlaapi.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ntdll.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ntkrnlpa.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ntoskrnl.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ntprint.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ntprint.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\ntvdm64.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\occache.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\oemdspif.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\olepro32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\poqexec.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\qasf.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\qdvd.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\qedit.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\quartz.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\rdvidcrl.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\RESAMPLEDMO.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\rpchttp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\rpcrt4.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\rrinstaller.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\samlib.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\scesrv.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\schannel.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\secur32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\setup16.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\shell32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\spwmp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\srclient.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\sspicli.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\tdh.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\tsgqec.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\TSpkg.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\tzres.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\urlmon.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\user.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\vbscript.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\VIDRESZR.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\vsd3dwarpdebug.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\vsgraphicsremoteengine.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\vsjitdebugger.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wdi.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wdigest.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\webcheck.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WebClnt.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\webio.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\win32spl.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WindowsCodecs.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wininet.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wintrust.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wksprtPS.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WMADMOD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WMADMOE.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wmdrmsdk.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wmp.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WMPhoto.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wmploc.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wmpmde.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WMSPDMOD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WMSPDMOE.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WMVDECOD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WMVENCOD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WMVSDECD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WMVSENCD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WMVXENCD.DLL => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wow32.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wpdshext.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WSManHTTPConfig.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WSManMigrationPlugin.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WsmAuto.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wsmplpxy.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wsmprovhost.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WsmRes.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WsmSvc.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\WsmWmiPl.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wuapi.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wuapp.exe => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wudriver.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wups.dll => ":$CmdTcID" ADS could not remove. C:\Windows\SysWOW64\wuwebv.dll => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\appid.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\dbx-canary.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\dbx-dev.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\dbx-stable.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\dfsc.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\drmk.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\drmkaud.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\FWPKCLNT.SYS => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\http.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\igdkmd64.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\jaksta_va.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\ksecdd.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\ksecpkg.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\lv302a64.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\LV302V64.SYS => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\lvrs64.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\LVUSBS64.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\mbam.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\mbamchameleon.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\mountmgr.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\mrxdav.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\mrxsmb.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\mrxsmb10.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\mrxsmb20.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\mwac.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\ndis.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\netio.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\PEAuth.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\portcls.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\srv2.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\srvnet.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\tcpipreg.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\TsUsbFlt.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\usbccgp.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\usbd.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\usbehci.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\usbhub.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\usbohci.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\usbport.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\usbuhci.sys => ":$CmdTcID" ADS could not remove. C:\Windows\system32\Drivers\vpnva64-6.sys => ":$CmdTcID" ADS could not remove. C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. ========= RemoveProxy: ========= HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully HKU\S-1-5-21-1249842936-2245008602-654386766-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\S-1-5-21-1249842936-2245008602-654386766-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully ========= End of RemoveProxy: ========= ========= ipconfig /flushdns ========= Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========= End of CMD: ========= =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 34702495 B Java, Flash, Steam htmlcache => 8645082 B Windows/system/drivers => 21875047 B Edge => 0 B Chrome => 20123078 B Firefox => 957686255 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 83653 B systemprofile32 => 66228 B LocalService => 66228 B NetworkService => 66228 B Hercules => 195248 B UpdatusUser => 0 B UpdatusUser => 0 B RecycleBin => 0 B EmptyTemp: => 1003.2 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 21:15:04 ====
  4. ADW Cleaner log: # AdwCleaner v6.030 - Logfile created 28/10/2016 at 21:22:18 # Updated on 19/10/2016 by Malwarebytes # Database : 2016-10-28.1 [Server] # Operating System : Windows 7 Home Premium Service Pack 1 (X64) # Username : Hercules - HERCULES-PC # Running from : E:\Desktop\AdwCleaner.exe # Mode: Clean # Support : hxxps://www.malwarebytes.com/support ***** [ Services ] ***** ***** [ Folders ] ***** [-] Folder deleted: C:\Users\Hercules\AppData\Local\DriverToolkit [-] Folder deleted: C:\ProgramData\TweakBit [#] Folder deleted on reboot: C:\ProgramData\Application Data\TweakBit [-] Folder deleted: C:\Program Files (x86)\DriverToolkit [-] Folder deleted: C:\Program Files (x86)\myfree codec ***** [ Files ] ***** ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled Tasks ] ***** ***** [ Registry ] ***** [-] Key deleted: HKLM\SOFTWARE\Classes\speedupmypc [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\speedupmypc [-] Key deleted: HKU\S-1-5-21-1249842936-2245008602-654386766-1001\Software \DriverToolkit [#] Key deleted on reboot: HKCU\Software\DriverToolkit [-] Key deleted: HKLM\SOFTWARE\wondershare [#] Key deleted on reboot: [x64] HKCU\Software\DriverToolkit ***** [ Web browsers ] ***** [-] [C:\Users\Hercules\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: uk.ask.com ************************* :: "Tracing" keys deleted :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [1541 Bytes] - [28/10/2016 21:22:18] C:\AdwCleaner\AdwCleaner[S0].txt - [1720 Bytes] - [28/10/2016 21:21:52] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1687 Bytes] ##########
  5. I wish I actually understood any of it, hope it makes sense to you. In the meantime, the computer is behaving for the moment...
  6. FRST.txt LOG: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-10-2016 Ran by Hercules (administrator) on HERCULES-PC (28-10-2016 20:31:27) Running from E:\Downloads Loaded Profiles: Hercules (Available Profiles: Hercules) Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\Mozilla Firefox.bak\firefox.exe" -osint -url "%1") Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe () C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox.bak\firefox.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1610936 2016-09-26] (COMODO) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7408312 2016-06-27] (AVAST Software) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [1206784 2016-09-10] (Cisco Systems, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-10-22] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1249842936-2245008602-654386766-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8944344 2016-10-27] (Piriform Ltd) HKU\S-1-5-21-1249842936-2245008602-654386766-1001\...\MountPoints2: {457f4dd5-19f8-11e4-b81b-485b39ef8f63} - H:\HTC_Sync_Manager_PC.exe ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google) ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-05-05] (AVAST Software) ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{C2545642-DE12-4C68-8BD8-0B9664E4CD75}: [NameServer] 95.211.10.3 Tcpip\..\Interfaces\{F4556B81-CEEE-467B-9492-F29DF4046F4E}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-10-22] (Oracle Corporation) BHO-x32: No Name -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> No File BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-10-22] (Oracle Corporation) Toolbar: HKU\S-1-5-21-1249842936-2245008602-654386766-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab FireFox: ======== FF DefaultProfile: ghg1s3fe.default-1394270942274 FF ProfilePath: C:\Users\Hercules\AppData\Roaming\Songbird2\Profiles\kegjnd5v.default [2014-02-12] FF NetworkProxy: Songbird2\Profiles\kegjnd5v.default -> no_proxies_on", "127.0.0.1;localhost" FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\albumart@songbirdnest.com [not found] FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\gonzo@songbirdnest.com [not found] FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\philips-addon-manager@songbirdnest.com [not found] FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\pinkmartini@songbirdnest.com [not found] FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\purplerain@songbirdnest.com [not found] FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\sharing@songbirdnest.com [not found] FF Extension: (No Name) - C:\Program Files (x86)\Songbird\extensions\soundboard@songbirdnest.com [not found] FF ProfilePath: C:\Users\Hercules\AppData\Roaming\Mozilla\Firefox\Profiles\ghg1s3fe.default-1394270942274 [2016-10-28] FF DefaultSearchUrl: Mozilla\Firefox\Profiles\ghg1s3fe.default-1394270942274 -> hxxps://www.google.com/search/?trackid=sp-006 FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\ghg1s3fe.default-1394270942274 -> Google (avast) FF SelectedSearchEngine: Mozilla\Firefox\Profiles\ghg1s3fe.default-1394270942274 -> Google (avast) FF Homepage: Mozilla\Firefox\Profiles\ghg1s3fe.default-1394270942274 -> hxxps://www.google.com/?trackid=sp-006 FF Keyword.URL: Mozilla\Firefox\Profiles\ghg1s3fe.default-1394270942274 -> hxxps://www.google.com/search/?trackid=sp-006 FF Extension: (Adblock Plus Pop-up Addon) - C:\Users\Hercules\AppData\Roaming\Mozilla\Firefox\Profiles\ghg1s3fe.default-1394270942274\Extensions\adblockpopups@jessehakanen.net.xpi [2016-04-27] FF Extension: (Google Analytics Opt-out Browser Add-on) - C:\Users\Hercules\AppData\Roaming\Mozilla\Firefox\Profiles\ghg1s3fe.default-1394270942274\Extensions\{6d96bb5e-1175-4ebf-8ab5-5f56f1c79f65}.xpi [2015-10-17] FF Extension: (Download YouTube Videos as MP4) - C:\Users\Hercules\AppData\Roaming\Mozilla\Firefox\Profiles\ghg1s3fe.default-1394270942274\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2016-09-04] FF Extension: (Video DownloadHelper) - C:\Users\Hercules\AppData\Roaming\Mozilla\Firefox\Profiles\ghg1s3fe.default-1394270942274\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-10-11] FF Extension: (Adblock Plus) - C:\Users\Hercules\AppData\Roaming\Mozilla\Firefox\Profiles\ghg1s3fe.default-1394270942274\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-10-26] FF SearchPlugin: C:\Users\Hercules\AppData\Roaming\Mozilla\Firefox\Profiles\ghg1s3fe.default-1394270942274\searchplugins\google-avast.xml [2014-12-11] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_185.dll [2016-10-17] () FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_185.dll [2016-10-17] () FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-10-22] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-10-22] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-10-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-10-03] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-10-03] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-10-01] (Adobe Systems Inc.) StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox.bak\firefox.exe Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxp://www.google.com CHR StartupUrls: Default -> "hxxp://www.google.com" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.71\PepperFlash\pepflashplayer.dll => No File CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.71\ppGoogleNaClPluginChrome.dll => No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.71\pdf.dll => No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll => No File CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => No File CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => No File CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll => No File CHR Profile: C:\Users\Hercules\AppData\Local\Google\Chrome\User Data\Default [2016-10-28] CHR Extension: (Google Docs) - C:\Users\Hercules\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-07] CHR Extension: (Google Drive) - C:\Users\Hercules\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-10] CHR Extension: (YouTube) - C:\Users\Hercules\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-10] CHR Extension: (Adblock Plus) - C:\Users\Hercules\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-10-27] CHR Extension: (Google Search) - C:\Users\Hercules\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-10] CHR Extension: (Chromebleed) - C:\Users\Hercules\AppData\Local\Google\Chrome\User Data\Default\Extensions\eeoekjnjgppnaegdjbcafdggilajhpic [2014-12-06] CHR Extension: (Google Docs Offline) - C:\Users\Hercules\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-19] CHR Extension: (Chrome Web Store Payments) - C:\Users\Hercules\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-07-19] CHR Extension: (Gmail) - C:\Users\Hercules\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-26] CHR Extension: (Chrome Media Router) - C:\Users\Hercules\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-26] CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - <no Path/update_url> ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-05-05] (AVAST Software) R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5817256 2016-09-26] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2271928 2016-09-26] (COMODO) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-10-02] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-10-02] (Dropbox, Inc.) R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [41576 2016-10-27] (Dropbox, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-10-28] (Malwarebytes) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-10-28] (Malwarebytes) R2 MySQL57; C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe [39885824 2016-08-07] () [File not signed] S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-08-07] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13368 2009-04-06] () R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-05-05] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-05-05] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-05-05] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-05-05] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-05-05] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-05-05] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [465792 2016-05-05] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [166432 2016-05-05] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [292704 2016-08-05] (AVAST Software) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [31648 2016-08-31] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [830624 2016-08-31] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [56976 2016-08-31] (COMODO) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [121800 2010-03-08] (QUALCOMM Incorporated) R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [116248 2016-08-31] (COMODO) S3 jakstaVA; C:\Windows\System32\DRIVERS\jaksta_va.sys [103816 2016-07-25] (e2eSoft) R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-10-28] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-10-28] (Malwarebytes) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-10-28] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-05-14] () S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [27136 2014-08-29] (The OpenVPN Project) S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2015-12-09] (Cisco Systems, Inc.) S3 cpuz135; \??\E:\Tmp\cpuz135\cpuz135_x64.sys [X] S3 dbx; system32\DRIVERS\dbx.sys [X] S3 dgderdrv; System32\drivers\dgderdrv.sys [X] S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X] U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-10-28 20:31 - 2016-10-28 20:31 - 00000000 ____D C:\FRST 2016-10-28 19:54 - 2016-10-28 20:07 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-10-28 19:54 - 2016-10-28 19:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2016-10-28 19:53 - 2016-10-28 19:53 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2016-10-28 19:53 - 2016-10-28 19:53 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2016-10-28 19:53 - 2016-10-28 19:53 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2016-10-27 19:34 - 2016-10-27 19:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2016-10-27 05:24 - 2016-10-27 05:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2016-10-27 05:24 - 2016-10-27 05:24 - 00000000 ____D C:\Program Files\7-Zip 2016-10-24 14:06 - 2016-10-27 19:34 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2016-10-24 14:06 - 2016-10-27 19:34 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2016-10-24 14:06 - 2016-10-27 19:34 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2016-10-24 14:06 - 2016-10-27 19:34 - 00041576 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2016-10-21 07:25 - 2016-10-22 06:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox.bak 2016-10-11 18:32 - 2016-10-11 18:32 - 25765376 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 20306944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 15257088 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 13653504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 12574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2016-10-11 18:32 - 2016-10-11 18:32 - 12574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2016-10-11 18:32 - 2016-10-11 18:32 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 06048256 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 05548264 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 04608512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 03944680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 03649536 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 03218944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-10-11 18:32 - 2016-10-11 18:32 - 03209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 02920960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 02895360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 02444288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 02291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 02286592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2016-10-11 18:32 - 2016-10-11 18:32 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2016-10-11 18:32 - 2016-10-11 18:32 - 02023424 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01573888 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01544192 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01483264 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01465344 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01312768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01178112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00724992 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00706280 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2016-10-11 18:32 - 2016-10-11 18:32 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00680448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2016-10-11 18:32 - 2016-10-11 18:32 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2016-10-11 18:32 - 2016-10-11 18:32 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00433152 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00346312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-10-11 18:32 - 2016-10-11 18:32 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00249344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-10-11 18:32 - 2016-10-11 18:32 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-10-11 18:32 - 2016-10-11 18:32 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2016-10-11 18:32 - 2016-10-11 18:32 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-10-11 18:32 - 2016-10-11 18:32 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys 2016-10-11 18:32 - 2016-10-11 18:32 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-10-11 18:32 - 2016-10-11 18:32 - 00094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2016-10-11 18:32 - 2016-10-11 18:32 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2016-10-11 18:32 - 2016-10-11 18:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2016-10-11 18:32 - 2016-10-11 18:32 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2016-10-11 18:32 - 2016-10-11 18:32 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2016-10-11 18:32 - 2016-10-11 18:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2016-10-11 18:32 - 2016-10-11 18:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2016-10-11 18:32 - 2016-09-30 07:41 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2016-10-11 18:32 - 2016-09-30 07:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2016-10-11 18:32 - 2016-09-30 06:54 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2016-10-11 18:32 - 2016-09-30 06:42 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2016-10-11 18:26 - 2016-10-11 18:26 - 14183424 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 12880384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 03229696 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2016-10-11 18:26 - 2016-10-11 18:26 - 02972672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2016-10-11 18:26 - 2016-10-11 18:26 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 01867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 01629184 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 01226752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 00586752 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 00343552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2016-10-11 18:26 - 2016-10-11 18:26 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2016-10-11 18:26 - 2016-10-11 18:26 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2016-10-11 18:26 - 2016-10-11 18:26 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2016-10-11 18:26 - 2016-10-11 18:26 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2016-10-11 18:26 - 2016-10-11 18:26 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2016-10-11 18:26 - 2016-10-11 18:26 - 00077032 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2016-10-11 18:26 - 2016-10-11 18:26 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2016-10-11 18:26 - 2016-10-11 18:26 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2016-10-11 18:26 - 2016-10-11 18:26 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2016-10-11 18:26 - 2016-10-11 18:26 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2016-10-08 05:48 - 2016-10-08 05:48 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2016-10-08 05:48 - 2016-10-08 05:48 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 03244032 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 02607104 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 02365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2016-10-07 22:51 - 2016-10-07 22:51 - 00377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2016-10-07 22:51 - 2016-10-07 22:51 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2016-10-07 22:51 - 2016-10-07 22:51 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2016-10-07 22:51 - 2016-10-07 22:51 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2016-10-07 22:51 - 2016-10-07 22:51 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2016-10-07 22:51 - 2016-10-07 22:51 - 00114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2016-10-07 22:51 - 2016-10-07 22:51 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00090624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe 2016-10-07 22:51 - 2016-10-07 22:51 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2016-10-07 22:51 - 2016-10-07 22:51 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2016-10-07 22:51 - 2016-10-07 22:51 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2016-10-07 22:51 - 2016-10-07 22:51 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2016-10-07 22:51 - 2016-10-07 22:51 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2016-10-07 22:51 - 2016-08-16 18:36 - 01009152 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2016-10-07 22:51 - 2016-08-16 03:48 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2016-10-07 22:51 - 2016-08-12 17:26 - 00464896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2016-10-07 22:51 - 2016-07-07 16:36 - 01896168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2016-10-07 22:50 - 2016-08-06 16:31 - 00877056 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2016-10-07 22:50 - 2016-08-06 16:15 - 00581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2016-10-02 07:45 - 2016-10-04 17:18 - 00000000 ___RD C:\Users\Hercules\Dropbox 2016-10-02 07:28 - 2016-10-28 05:57 - 00000912 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2016-10-02 07:28 - 2016-10-28 05:57 - 00000908 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2016-10-02 07:28 - 2016-10-27 22:13 - 00003920 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA 2016-10-02 07:28 - 2016-10-27 22:13 - 00003668 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore 2016-10-02 07:28 - 2016-10-27 19:34 - 00000000 ____D C:\Program Files (x86)\Dropbox 2016-10-02 07:28 - 2016-10-02 07:28 - 00000000 ____D C:\ProgramData\Dropbox ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-10-28 20:02 - 2013-03-17 16:09 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-10-28 19:59 - 2013-02-15 09:11 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-10-28 19:54 - 2014-12-10 21:33 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2016-10-28 17:26 - 2009-07-14 05:45 - 00023376 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-10-28 17:26 - 2009-07-14 05:45 - 00023376 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-10-28 17:25 - 2009-07-14 06:13 - 00006946 _____ C:\Windows\system32\PerfStringBackup.INI 2016-10-28 17:24 - 2013-01-17 16:24 - 00485032 _____ (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2016-10-28 17:22 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2016-10-28 17:19 - 2014-04-21 03:49 - 00003034 _____ C:\Windows\System32\Tasks\MSIAfterburner 2016-10-28 17:19 - 2013-03-17 16:09 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-10-28 17:19 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-10-28 17:18 - 2013-01-17 16:34 - 00000000 ____D C:\ProgramData\NVIDIA 2016-10-28 08:02 - 2013-08-21 19:45 - 00000000 ____D C:\Users\Hercules\AppData\Roaming\vlc 2016-10-27 21:15 - 2013-01-17 20:10 - 00000000 ____D C:\Users\Hercules\AppData\Roaming\uTorrent 2016-10-27 20:23 - 2015-09-18 20:15 - 00000000 ____D C:\Users\Hercules\AppData\LocalLow\uTorrent 2016-10-27 05:24 - 2013-02-15 09:11 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-10-27 05:24 - 2013-01-17 16:24 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-10-27 05:24 - 2013-01-17 16:24 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-10-27 05:24 - 2013-01-17 16:24 - 00000000 ____D C:\Windows\system32\Macromed 2016-10-27 05:23 - 2013-01-17 16:24 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2016-10-25 18:04 - 2013-03-17 16:10 - 00002170 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-10-22 16:50 - 2013-01-17 17:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-10-22 06:19 - 2013-10-06 10:51 - 00000000 ____D C:\ProgramData\Oracle 2016-10-22 06:18 - 2014-08-09 05:23 - 00000000 ____D C:\Program Files (x86)\Java 2016-10-22 06:17 - 2015-08-13 20:34 - 00097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2016-10-22 06:17 - 2015-08-13 20:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-10-21 18:40 - 2013-02-01 22:14 - 00000000 ____D C:\Users\Hercules\AppData\Roaming\Skype 2016-10-21 18:40 - 2013-02-01 22:14 - 00000000 ____D C:\ProgramData\Skype 2016-10-17 17:57 - 2016-03-29 20:54 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-10-15 23:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2016-10-13 19:13 - 2009-07-14 06:08 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2016-10-12 05:07 - 2009-07-14 05:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-10-12 05:07 - 2009-07-14 05:45 - 00403736 _____ C:\Windows\system32\FNTCACHE.DAT 2016-10-12 05:06 - 2016-07-25 19:10 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2016-10-12 05:06 - 2016-07-25 19:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2016-10-11 21:56 - 2014-12-10 07:55 - 00000000 ____D C:\Windows\system32\appraiser 2016-10-11 21:56 - 2014-05-06 19:28 - 00000000 ___SD C:\Windows\system32\CompatTel 2016-10-11 21:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Dism 2016-10-11 21:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Dism 2016-10-11 19:56 - 2013-08-15 21:07 - 00000000 ____D C:\Windows\system32\MRT 2016-10-11 19:50 - 2013-01-17 16:52 - 143495576 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-10-11 19:49 - 2016-07-25 19:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2016-10-11 18:33 - 2015-11-06 06:36 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2016-10-11 18:33 - 2014-12-24 09:21 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2016-10-06 05:17 - 2013-01-17 19:29 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2016-10-02 07:45 - 2013-01-17 16:18 - 00000000 ____D C:\Users\Hercules ==================== Files in the root of some directories ======= 2014-09-24 20:02 - 2014-09-24 20:02 - 0012995 _____ () C:\Users\Hercules\AppData\Roaming\Microsoft Excel 97-2003.CAL 2015-10-25 12:27 - 2015-10-26 07:11 - 1187328 _____ (CPUID) C:\Users\Hercules\AppData\Roaming\siw_sdk.dll 2016-07-25 07:11 - 2016-07-25 07:11 - 0000016 _____ () C:\ProgramData\mntemp 2016-07-25 07:11 - 2016-07-25 07:11 - 0005085 _____ () C:\ProgramData\oqztiqep.adk ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-10-15 23:39 ==================== End of FRST.txt ============================ Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-10-2016 Ran by Hercules (28-10-2016 20:31:55) Running from E:\Downloads Windows 7 Home Premium Service Pack 1 (X64) (2013-01-17 15:18:31) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1249842936-2245008602-654386766-500 - Administrator - Disabled) Guest (S-1-5-21-1249842936-2245008602-654386766-501 - Limited - Disabled) Hercules (S-1-5-21-1249842936-2245008602-654386766-1001 - Administrator - Enabled) => C:\Users\Hercules HomeGroupUser$ (S-1-5-21-1249842936-2245008602-654386766-1002 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Comodo Defense+ (Enabled - Up to date) {6BAD9487-8DE8-D130-293E-C6A728B4104F} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: COMODO Firewall (Enabled) {E8F7F446-E1BD-DFE6-38D1-54E0ADE01D89} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-1249842936-2245008602-654386766-1001\...\uTorrent) (Version: 3.4.9.42606 - BitTorrent Inc.) 7-Zip 16.04 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov) Active Directory Authentication Library for SQL Server (Version: 13.0.1601.5 - Microsoft Corporation) Hidden Active Directory Authentication Library for SQL Server (x86) (x32 Version: 13.0.1601.5 - Microsoft Corporation) Hidden Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.020.20039 - Adobe Systems Incorporated) Adobe Flash Player 23 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 23.0.0.185 - Adobe Systems Incorporated) Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.185 - Adobe Systems Incorporated) Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{0E4C791E-B78E-477D-BD5A-CDD0985BA6EC}) (Version: 7.0.20622.1 - Microsoft Corporation) Avast Free Antivirus (HKLM-x32\...\avast) (Version: 11.2.2262 - AVAST Software) Azure AD Authentication Connected Service (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden calibre (HKLM-x32\...\{8854EE3C-5031-499F-B5EB-51A82F1B28EF}) (Version: 2.21.0 - Kovid Goyal) CCleaner (HKLM\...\CCleaner) (Version: 5.23 - Piriform) Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 4.3.02039 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (x32 Version: 4.3.02039 - Cisco Systems, Inc.) Hidden COMODO Internet Security (HKLM\...\{0E9AFD45-C3BA-41D1-B54B-495A22CB3409}) (Version: 6.0.64131.2674 - COMODO Security Solutions Inc.) Cool & Quiet (HKLM-x32\...\{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}) (Version: - ) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dotfuscator and Analytics Community Edition 5.22.0 (x32 Version: 5.22.0.3788 - PreEmptive Solutions) Hidden Dropbox (HKLM-x32\...\Dropbox) (Version: 13.4.21 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.47.1 - Dropbox, Inc.) Hidden DVD Shrink 3.2 (HKLM-x32\...\DVD Shrink_is1) (Version: - DVD Shrink) Entity Framework 6.1.3 Tools for Visual Studio 2015 Update 1 (HKLM-x32\...\{2A56910C-69C8-495D-8ED8-9080F0A14E58}) (Version: 14.0.41103.0 - Microsoft Corporation) FileZilla Client 3.11.0.1 (HKLM-x32\...\FileZilla Client) (Version: 3.11.0.1 - Tim Kosse) GetFoldersize 3.1.1 (HKLM-x32\...\GetFoldersize_is1) (Version: 3.1.1 - Michael Thummerer Software Design) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 54.0.2840.71 - Google Inc.) Google Drive (HKLM-x32\...\{459CE109-4E46-4340-92BC-054642BC3BC2}) (Version: 1.31.2873.2758 - Google, Inc.) Google Earth Pro (HKLM-x32\...\{44FC61F0-2F8A-11E3-8CAE-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden IIS 10.0 Express (HKLM\...\{13FD7E30-D2F1-498D-ABC2-A4242DB6610E}) (Version: 10.0.1736 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version: - ) IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version: - ) Intel Driver Update Utility (HKLM-x32\...\{fe92d390-13ee-4660-a2f8-39a066fdffe0}) (Version: 2.2.0.5 - Intel) Intel(R) Driver Update Utility 2.2.0.5 (x32 Version: 2.2.0.1 - Intel) Hidden Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation) Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) LINQPad 5 (HKLM-x32\...\{758485A7-8E93-4864-A3A8-D628C093B63A}_is1) (Version: - Joseph Albahari) Logitech Webcam Software (HKLM\...\{987FE247-4E69-4A2E-A961-D14F901FDBF6}) (Version: 12.10.1113 - Logitech Inc.) Logitech Webcam Software Driver Package (HKLM\...\lvdrivers_12.10) (Version: 12.10.1110 - Logitech Inc.) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation) Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 Targeting Pack (ENU) (HKLM-x32\...\{034547E9-D8FA-49E7-8B9C-4C9861FB9146}) (Version: 4.6.00127 - Microsoft Corporation) Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.25420 - Microsoft Corporation) Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-0081-0409-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\...\{95140000-007D-0409-0000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 T-SQL Language Service (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2016 LocalDB (HKLM\...\{E359515A-92E6-4FA3-A2C9-E1BA02D8DE6E}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server 2016 Management Objects (HKLM-x32\...\{0F1C8E2F-199A-4946-B3BF-0906DACFD032}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server 2016 Management Objects (x64) (HKLM\...\{20EA85AA-2A1D-4F11-B09F-4BA2BF3C8989}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL Language Service (HKLM-x32\...\{8BFDE775-C5B8-46DB-84EF-43FFC8A2E8AD}) (Version: 13.0.14500.10 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL ScriptDom (HKLM\...\{D091DE8C-EA0F-49AF-8DE3-BD6C79737C6E}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - enu (14.0.60519.0) (HKLM-x32\...\{4E27B0EF-7BAB-432A-AF3D-3FC8F3F7353F}) (Version: 14.0.60519.0 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{FC3BB979-AA54-4B60-BBA3-2C4DA6E08D80}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{091CE6AA-2753-4F6E-AD1C-0E875744EB54}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2016 (HKLM\...\{96EB5054-C775-4BEF-B7B9-AA96A295EDCD}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2016 (HKLM-x32\...\{84C23ECA-FE4D-494F-9247-3EBAD57E7F0C}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio Community 2015 with Updates (HKLM-x32\...\{79b486b9-c5f0-4096-a00c-8351f59587c2}) (Version: 14.0.25420.1 - Microsoft Corporation) Microsoft Web Deploy 3.6 (HKLM\...\{94E1227C-08A9-4962-B388-1F05D89AEA75}) (Version: 3.1238.1962 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 49.0.2 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 49.0.2 (x86 en-GB)) (Version: 49.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 49.0.2.6136 - Mozilla) MSBuild/NuGet Integration 14.0 (x86) (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden MSI Afterburner 4.1.1 (HKLM-x32\...\Afterburner) (Version: 4.1.1 - MSI Co., LTD) Multi-Device Hybrid Apps using C# - Templates - ENU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden MySQL Connector C++ 1.1.7 (HKLM\...\{A4310FCD-95D5-49B7-91BA-9A079F07B167}) (Version: 1.1.7 - Oracle and/or its affiliates) MySQL Connector J (HKLM-x32\...\{BC065B80-343B-44E1-BB8B-A04950CC1284}) (Version: 5.1.39 - Oracle Corporation) MySQL Connector Net 6.9.9 (HKLM-x32\...\{E09F82E9-3EB3-4725-BDC8-3C77F83E262C}) (Version: 6.9.9 - Oracle) MySQL Connector Python v2.1.3 for Python v3.4 (HKLM-x32\...\{90F8BCBF-586B-4439-A756-DB03EE675C04}) (Version: 2.1.3 - Oracle) MySQL Connector/C 6.1 (HKLM\...\{ABC3A516-54E3-414B-B501-762E7FB2F9D5}) (Version: 6.1.6 - Oracle Corporation) MySQL Connector/ODBC 5.3 (HKLM\...\{17E48BE8-F0F8-42B6-82D3-7A5840694D79}) (Version: 5.3.6 - Oracle Corporation) MySQL Documents 5.7 (HKLM-x32\...\{E8BE0456-4E5E-4317-AA77-0D012C774C58}) (Version: 5.7.14 - Oracle Corporation) MySQL Examples and Samples 5.7 (HKLM-x32\...\{00F7F04A-C078-4549-BF1E-8309CB0C2D2F}) (Version: 5.7.14 - Oracle Corporation) MySQL For Excel 1.3.6 (HKLM-x32\...\{DC8733F3-63A6-43F4-8C38-637071FB6D5F}) (Version: 1.3.6 - Oracle) MySQL for Visual Studio 1.2.6 (HKLM-x32\...\{D885AD96-9178-4CF2-836C-33AE57A57427}) (Version: 1.2.6 - Oracle) MySQL Installer - Community (HKLM-x32\...\{04418A3C-1199-4C3E-80F2-BBF714322716}) (Version: 1.4.16.0 - Oracle Corporation) MySQL Notifier 1.1.7 (HKLM-x32\...\{724CDD73-430E-47DA-8F4E-7DF2000BA268}) (Version: 1.1.7 - Oracle) MySQL Server 5.7 (HKLM\...\{2F3AB21E-EFF9-4CFD-AF0D-8B983FC9DC37}) (Version: 5.7.14 - Oracle Corporation) MySQL Utilities (HKLM\...\{7FC39694-83D7-4CBD-88D6-15D1DD698075}) (Version: 1.6.4 - Oracle Corporation) MySQL Workbench 6.3 CE (HKLM\...\{0D901124-B910-4985-9D4F-AC5C2FEF7493}) (Version: 6.3.7 - Oracle Corporation) NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Driver 358.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 358.50 - NVIDIA Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation) NVIDIA Graphics Driver 358.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 358.50 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation) Oracle VM VirtualBox 4.2.18 (HKLM\...\{230C9C86-26A9-437F-8152-34D5F4C3F680}) (Version: 4.2.18 - Oracle Corporation) Personal Video Database 1.0.2.7 (HKLM-x32\...\Personal Video Database_is1) (Version: - Nostradamus) PowerISO (HKLM-x32\...\PowerISO) (Version: 6.5 - Power Software Ltd) PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden Prerequisites for SSDT (HKLM-x32\...\{21373064-AD95-48DB-A32E-0D9E08EF7355}) (Version: 12.0.2000.8 - Microsoft Corporation) Prerequisites for SSDT (HKLM-x32\...\{B7E94916-7AE6-4F7F-A377-7A410A42BA19}) (Version: 13.0.1601.5 - Microsoft Corporation) Python 3.4.0 (HKLM-x32\...\{a37f2d73-72d1-364d-ba5d-cea430bcc040}) (Version: 3.4.150 - Python Software Foundation) Python 3.5.2 (32-bit) (HKU\S-1-5-21-1249842936-2245008602-654386766-1001\...\{cf72a2ab-2f1d-49fd-a0d7-1065e6357e1e}) (Version: 3.5.2150.0 - Python Software Foundation) Python 3.5.2 Core Interpreter (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Development Libraries (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Documentation (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Executables (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 pip Bootstrap (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Standard Library (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Tcl/Tk Support (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Test Suite (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Utility Scripts (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden Python Launcher (HKLM-x32\...\{963ECCDD-F09F-4C24-9367-8B5D748AA7C8}) (Version: 3.5.2121.0 - Python Software Foundation) Recuva (HKLM\...\Recuva) (Version: 1.52 - Piriform) Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden Roslyn Language Services - x86 (x32 Version: 14.0.25425 - Microsoft Corporation) Hidden SafeZone Stable 1.48.2066.101 (x32 Version: 1.48.2066.101 - Avast Software) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) SIW 2011 Home Edition (HKLM-x32\...\{AB67580-257C-45FF-B8F4-C8C30682091A}_is1) (Version: 2011.10.29 - Topala Software Solutions) Skype™ 7.29 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.102 - Skype Technologies S.A.) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Team Explorer for Microsoft Visual Studio 2015 Update 3.1 (x32 Version: 14.102.25521 - Microsoft) Hidden Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) TypeScript Power Tool (x32 Version: 1.8.34.0 - Microsoft Corporation) Hidden TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.8.36.0 - Microsoft Corporation) Hidden Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation) Visual Studio 2015 Update 3 (KB3022398) (HKLM-x32\...\{7a68448b-9cf2-4049-bd73-5875f1aa7ba2}) (Version: 14.0.25420 - Microsoft Corporation) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) VS Update core components (x32 Version: 14.0.25425 - Microsoft Corporation) Hidden vs_update3notification (x32 Version: 14.0.25425 - Microsoft Corporation) Hidden WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {12AFF888-DDFD-4D40-8ED7-A0434E51DA38} - System32\Tasks\{AA1F6FC3-7FAC-4774-8EAF-69F979EE80D0} => pcalua.exe -a E:\Downloads\jxpiinstall(1).exe -d E:\Downloads Task: {1746D627-8536-437F-A73F-632D61CB1FF3} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2016-09-26] (COMODO) Task: {2372AA6E-E061-4619-A42D-BF901EDB1DA5} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-06-03] (AVAST Software) Task: {2FD85CE5-F701-4EF0-889C-AB4ECE303949} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update 14 => C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe [2016-08-07] (Microsoft Corporation) Task: {4482215E-FF09-431E-9920-8B4F021AE555} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-10-02] (Dropbox, Inc.) Task: {4FF678A9-56ED-41D9-85EA-A2023E2F9639} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-05-05] (AVAST Software) Task: {51304313-D70C-4E18-9E7C-1A254424FB37} - System32\Tasks\SafeZone scheduled Autoupdate 1458711061 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-04-15] (Avast Software) Task: {5FF0BBAA-5CD4-4097-808C-922CC2FBF738} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {6898249B-B36F-44BD-90AF-0F22D61AFFB9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-29] (Adobe Systems Incorporated) Task: {6BC23172-9E23-44EC-8F07-9F12BEB76F0A} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-09-26] (COMODO) Task: {70D639B1-3BAB-4FA6-919E-D2738952A165} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-09-26] (COMODO) Task: {75C1717A-7E79-4191-A22C-60C05516FC59} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-10-02] (Dropbox, Inc.) Task: {7B3E0B2F-609C-4F1E-B857-AD6F219DF375} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-27] (Adobe Systems Incorporated) Task: {89E20538-E19C-4FA4-AD42-AC716D027957} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {9398EFD4-D67F-48C7-9D01-10460665D295} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2015-10-20] () Task: {BDFDAAEC-773F-4795-9B44-EABA59290CF3} - System32\Tasks\{BDE5B28E-61E3-47AB-BA35-8B24A7308880} => pcalua.exe -a "C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\VCRedist\vcredist_x86.exe" -d "C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\VCRedist" Task: {E8E7B83D-F8BB-4D99-B009-6B1332B697E9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-10-27] (Piriform Ltd) Task: {EDC932A5-944A-4F14-8931-4D6BAE65847B} - System32\Tasks\MySQL\Installer\ManifestUpdate => C:\Program Files (x86)\MySQL\MySQL Installer for Windows\MySQLInstallerConsole.exe [2016-08-07] (Oracle Corporation) Task: {FFCB46F1-3500-4692-9225-5C59DD2368BA} - System32\Tasks\MySQLNotifierTask => C:\Program Files (x86)\MySQL\MySQL Notifier 1.1\MySQLNotifier.exe [2016-08-07] (Oracle Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Hercules\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iGridd\iGridd.lnk -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://igridd.com/igridd.jnlp "C:\Users\Hercules\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\2b577681-35de03be" ==================== Loaded Modules (Whitelisted) ============== 2015-10-24 20:50 - 2015-10-03 03:49 - 00116344 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-05-22 15:44 - 2015-05-22 15:44 - 00043480 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll 2016-07-12 14:45 - 2016-08-07 08:29 - 39885824 _____ () C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe 2016-07-12 14:45 - 2016-07-12 14:45 - 03361792 _____ () C:\Program Files\MySQL\MySQL Server 5.7\lib\plugin\mysqlx.DLL 2016-08-12 18:20 - 2016-08-12 18:20 - 00073728 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2016-05-05 19:27 - 2016-05-05 19:27 - 00123344 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2016-05-05 19:27 - 2016-05-05 19:27 - 00135816 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-10-27 18:25 - 2016-10-27 18:25 - 03125136 _____ () C:\Program Files\AVAST Software\Avast\defs\16102702\algo.dll 2016-05-05 19:27 - 2016-05-05 19:27 - 00309912 _____ () C:\Program Files\AVAST Software\Avast\browser_pass.dll 2016-10-28 17:19 - 2016-10-28 17:19 - 03125136 _____ () C:\Program Files\AVAST Software\Avast\defs\16102800\algo.dll 2016-05-05 19:27 - 2016-05-05 19:27 - 00479680 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2016-01-28 19:54 - 2016-01-28 19:54 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2016-06-01 15:17 - 2016-06-01 15:17 - 00144832 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlc.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 02632640 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlccore.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00554944 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdshow_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00041920 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libdirectsound_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00039872 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libwaveout_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00086464 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirect3d_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00078272 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirectdraw_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 02231744 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\liblibbluray_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00114112 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_bd_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00245184 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdvdnav_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00089536 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libvdr_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00055744 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libfilesystem_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00072128 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libsmooth_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00598976 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libhttplive_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00771520 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libdash_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00131520 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libzip_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00052672 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\librar_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00023488 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\librecord_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00145856 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libplaylist_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 01566656 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libtaglib_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00334784 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\lua\liblua_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 01265600 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\misc\libxml_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00024512 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libwin_msg_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00069568 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libhotkeys_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00242624 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmp4_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00048576 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libwin_hotkeys_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 12001728 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\gui\libqt4_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00046528 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libfolder_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00261056 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libjpeg_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00027072 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libcdg_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00298944 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libpng_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 01291200 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libschroedinger_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00754624 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libvorbis_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00344512 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libtheora_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00028608 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libdts_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00036800 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaraw_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00052160 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libsubstx3g_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00456128 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libflac_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00035776 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libg711_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00024512 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaes3_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00157632 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspeex_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 02680768 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblibass_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00356288 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libfaad_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00028096 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liba52_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00028096 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libmpeg_audio_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00031680 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblpcm_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00370112 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libopus_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00121792 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libdvbsub_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00028608 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspudec_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 14929344 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libavcodec_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00789952 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\text_renderer\libfreetype_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00038848 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_sse2_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00030144 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_mmx_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00746432 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libswscale_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00036800 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_sse2_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00125888 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_sse2_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00065472 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_mmx_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00028608 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_mmx_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00027584 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libyuy2_i422_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00024512 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libgrey_yuv_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00022464 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_mixer\libfloat_mixer_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00031168 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libyuy2_i420_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00027072 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libscaletempo_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00027584 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 01504704 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsamplerate_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00029120 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00037824 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_plugin.dll 2016-06-01 15:18 - 2016-06-01 15:18 - 00024000 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_i420_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00023488 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libscale_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00022976 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libyuvp_plugin.dll 2016-06-01 15:19 - 2016-06-01 15:19 - 00118720 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libpostproc_plugin.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Windows\avastSS.scr:$CmdTcID [64] AlternateDataStreams: C:\Windows\explorer.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\py.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\pyw.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\acmigration.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\adsmsext.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\adtschema.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\advapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\aeinv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\aepic.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\aitstatic.exe:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\apisetschema.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appidapi.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\appidcertstorecheck.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appidpolicyconverter.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appidsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appinfo.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appraiser.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\asycfilt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\audiodg.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\AudioEng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\AUDIOKSE.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\AudioSes.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\audiosrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\auditpol.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\authui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\basesrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\blackbox.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\catsrvut.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\centel.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\certcli.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ci.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\clfs.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\clfsw32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\COLORCNV.DLL:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\CompatTelRunner.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\conhost.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\consent.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\CPFilters.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\credssp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\crypt32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptbase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptnet.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\csrsrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\davclnt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\DbxSvc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\devenum.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\devinv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\diagtrack.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\difx64.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\drmmgrtn.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\drmv2clt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dwmapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dwmcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\DWrite.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxcap.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxcpl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxmasf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxtmsft.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxtrans.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\EncDec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\EncDump.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\evr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ExplorerFrame.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\FntCache.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\generaltel.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\hccutils.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\hkcmd.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ie4uinit.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieapfltr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iedkcs32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieetwcollector.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieetwcollectorres.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieetwproxystub.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieframe.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iernonce.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iertutil.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iesetup.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieUnatt.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ig4dev64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ig4icd64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igd10umd64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igdumd64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxcfg.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxCoIn_v1930.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxcpl.cpl:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxdev.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxdo.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxexps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxext.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxpers.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxpph.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrara.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrchs.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrcht.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrcsy.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrdan.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrdeu.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrell.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrenu.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxresp.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxress.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrfin.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrfra.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrheb.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrhun.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrita.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrjpn.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrkor.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrnld.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrnor.lrc:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\igfxrplk.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrptb.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrptg.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrrus.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrsky.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrslv.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrsve.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrtha.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxrtrk.lrc:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxsrvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxsrvc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\igfxTMM.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\igfxtray.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inetcomm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inetcpl.cpl:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inetpp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inetppui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\INETRES.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\InkEd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inseng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\invagent.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\JavaScriptCollectionAgent.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jscript9.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jscript9diag.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jsproxy.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\kerberos.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\kernel32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\KernelBase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ksproxy.ax:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\ksuser.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lsasrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lsass.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lvco11801048.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lvco1201278.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lvcod64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\LVUI64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\LVUIRC64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mcmde.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfcm140ud.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mferror.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfplat.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfpmp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfvdsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MFWMAAEC.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MP3DMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MP43DECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MP4SDECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MPG4DECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MpSigStub.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MRT.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msaudite.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msctf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msdxm.ocx:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msfeeds.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mshtml.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MshtmlDac.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mshtmled.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mshtmlmedia.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msi.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\msiexec.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msihnd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msimsg.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\msmmsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msmpeg2adec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MSMPEG2ENC.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msmpeg2vdec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msnetobj.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msobjs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msrating.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MsRdpWebAccess.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msscp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MsSpellCheckingFacility.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mstsc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mstscax.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msv1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MSVidCtl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msxml6.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msxml6r.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ncrypt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntdll.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntprint.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntprint.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntvdm64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6434709.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6434725.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6434752.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\nvdispco6434788.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6435012.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6435330.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6435362.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6435382.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\nvdispco6435560.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\nvdispco6435582.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6434709.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6434725.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6434752.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\nvdispgenco6434788.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6435012.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6435330.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6435362.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6435382.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6435560.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6435582.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvhdagenco64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\occache.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcadm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcaevts.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcalua.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcasvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcawrk.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\poqexec.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\qasf.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\qdvd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\quartz.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rdvidcrl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\RESAMPLEDMO.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rpchttp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rpcrt4.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rrinstaller.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rstrui.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\scavengeui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\scesrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\schannel.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\schedsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\secur32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\services.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\setbcdlocale.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\shell32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\smss.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\spwmp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\srclient.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\srcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sspicli.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sspisrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SysFxUI.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sysmain.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\tdh.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\tsgqec.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\TSpkg.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TsUsbGDCoInstaller.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TSWbPrxy.exe:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\tzres.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\urlmon.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\UtcResources.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\vbscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\vcruntime140d.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\VIDRESZR.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\vsgraphicsremoteengine.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\vsjitdebugger.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wdi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wdigest.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\webcheck.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WebClnt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\win32k.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\win32spl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WindowsCodecs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wininet.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winload.efi:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winresume.efi:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winresume.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WinSetupUI.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winsrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wintrust.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wksprt.exe:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\wksprtPS.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMADMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMADMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMALFXGFXDSP.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wmdrmsdk.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wmp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wmploc.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wmpmde.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMSPDMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMSPDMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVDECOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVENCOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVSDECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVSENCD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVXENCD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wow64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wow64cpu.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wow64win.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wpdshext.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wpnpinst.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WSManHTTPConfig.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WSManMigrationPlugin.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WsmAuto.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wsmplpxy.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wsmprovhost.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WsmRes.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WsmSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WsmWmiPl.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\wu.upgrade.ps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuapp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuauclt.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuaueng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wucltux.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wudriver.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wups.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wups2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuwebv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\adsmsext.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\adtschema.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\advapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\apisetschema.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\appidapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\asycfilt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\AudioEng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\AUDIOKSE.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\AudioSes.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\auditpol.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\authui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\blackbox.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\catsrvut.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\certcli.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\clfsw32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\COLORCNV.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\comsvcs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\CPFilters.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\credssp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\crypt32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptbase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptnet.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\davclnt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\devenum.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\drmmgrtn.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\drmv2clt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dwmapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dwmcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\DWrite.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dxcap.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dxcpl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dxmasf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dxtmsft.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\dxtrans.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\els.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\EncDec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\evr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\explorer.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ExplorerFrame.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieapfltr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iedkcs32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieetwproxystub.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieframe.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iernonce.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iertutil.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iesetup.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieUnatt.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ig4dev32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ig4icd32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\igd10umd32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\igdumd32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\igdumdx32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\igfxdv32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\igxpun.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\inetcomm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\inetcpl.cpl:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\INETRES.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\InkEd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\inseng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\instnm.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jscript9.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jscript9diag.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jsproxy.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\kerberos.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\kernel32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\KernelBase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ksproxy.ax:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ksuser.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\lvcodec2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\LVUI2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\LVUI2RC.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mferror.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfplat.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfpmp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfvdsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MFWMAAEC.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MP3DMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MP43DECD.DLL:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\MP4SDECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MPG4DECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msaudite.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msctf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msdxm.ocx:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msfeeds.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mshtml.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MshtmlDac.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mshtmled.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mshtmlmedia.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msiexec.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msihnd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msimsg.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msmpeg2adec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MSMPEG2ENC.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msmpeg2vdec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msnetobj.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msobjs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msrating.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MsRdpWebAccess.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msscp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mstsc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mstscax.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msv1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MSVidCtl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msxml6.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msxml6r.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ncrypt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ncsi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\nlaapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntdll.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntkrnlpa.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntoskrnl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntprint.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntprint.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntvdm64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\occache.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\oemdspif.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\olepro32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\poqexec.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\qasf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\qdvd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\qedit.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\quartz.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rdvidcrl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\RESAMPLEDMO.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rpchttp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rpcrt4.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rrinstaller.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\samlib.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\scesrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\schannel.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\secur32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\setup16.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\shell32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\spwmp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\srclient.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\sspicli.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\tdh.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\tsgqec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\TSpkg.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\tzres.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\urlmon.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\user.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\vbscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\VIDRESZR.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\vsd3dwarpdebug.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\vsgraphicsremoteengine.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\vsjitdebugger.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wdi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wdigest.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\webcheck.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WebClnt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\webio.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\win32spl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WindowsCodecs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wininet.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wintrust.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wksprtPS.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMADMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMADMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wmdrmsdk.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wmp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMPhoto.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wmploc.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wmpmde.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMSPDMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMSPDMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVDECOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVENCOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVSDECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVSENCD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVXENCD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wow32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wpdshext.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WSManHTTPConfig.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WSManMigrationPlugin.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WsmAuto.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wsmplpxy.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wsmprovhost.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WsmRes.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WsmSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WsmWmiPl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wuapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wuapp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wudriver.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wups.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wuwebv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\appid.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\dbx-canary.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\dbx-dev.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\dbx-stable.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\dfsc.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\drmk.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\drmkaud.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\FWPKCLNT.SYS:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\http.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\igdkmd64.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\jaksta_va.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ksecdd.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ksecpkg.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\lv302a64.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\LV302V64.SYS:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\lvrs64.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\LVUSBS64.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mbam.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mbamchameleon.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mountmgr.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mrxdav.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb10.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb20.sys:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Drivers\mwac.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ndis.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\netio.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\PEAuth.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\portcls.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\srv2.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\srvnet.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\tcpipreg.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\TsUsbFlt.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbccgp.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbd.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbehci.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbhub.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbohci.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbport.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbuhci.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\vpnva64-6.sys:$CmdTcID [64] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2013-04-27 15:24 - 00001306 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 activate-sjc0.adobe.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1249842936-2245008602-654386766-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Hercules\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 - 95.211.10.3 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall is disabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: cmdvirth => 3 MSCONFIG\Services: FLEXnet Licensing Service => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: HitmanProScheduler => 2 MSCONFIG\Services: MBAMScheduler => 2 MSCONFIG\Services: MBAMService => 2 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices MSCONFIG\startupreg: Dropbox => "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup MSCONFIG\startupreg: LogitechQuickCamRibbon => "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent MSCONFIG\startupreg: VX3000 => C:\Windows\vVX3000.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{AF235052-061D-4A8A-8D47-2A3A6CD81CE8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{1A218FE8-7F3D-4DAF-BB9A-88349BA4E4D3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{D04F6939-2420-49F2-96C6-3B643632BDB7}] => (Allow) C:\Users\Hercules\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{2A6EA80A-D616-4E08-84E5-F7503F4E2330}] => (Allow) C:\Users\Hercules\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{6222FB34-2545-4F32-8625-D3A86DAAFE49}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{BCB426B4-FD1D-4C5B-8579-C272CBB14C1E}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{E6AAD40A-EFB0-4B40-9D55-FC21E5C5556C}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{0C9DB9AE-84C6-4BE8-8D98-0ECB68FDDB0A}] => (Allow) LPort=2869 FirewallRules: [{F6F5EFA8-271E-406A-B346-4A11DF541322}] => (Allow) LPort=1900 FirewallRules: [{78456C2B-D345-4E2F-8F2D-9425C8A1A2D8}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{0EF12CA2-6CAE-4EE8-8CAA-E159B69C2D2E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{34F41A2D-036D-4C3F-A599-F3B4CA11065B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{69550CBF-80A1-450A-8145-D0198FBDF1DB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{2966243D-7882-4C6F-B471-7E6822F05F26}] => (Allow) C:\Users\Hercules\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{EB3778E2-265D-470F-B2D9-01E4DC5D30CD}] => (Allow) C:\Users\Hercules\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{95F269BE-2AC0-4676-B6B5-94CF2D0CA370}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{2A70E091-DA20-4541-880A-AA97D7997F36}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe FirewallRules: [{16D95D16-AD02-46AA-A5E7-EA273BD83779}] => (Allow) LPort=3306 FirewallRules: [{634D082C-2EFD-44D2-9060-6D591374320F}] => (Allow) LPort=33060 FirewallRules: [{B3719D9B-8AE2-4540-BFE8-AAE290A5E1C8}] => (Allow) LPort=3306 FirewallRules: [{65E9AF5A-57E4-4F65-8808-55D91A36CF2E}] => (Allow) LPort=33060 FirewallRules: [{80B7299C-132C-4097-82AF-F7709881DA7A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox.bak\firefox.exe FirewallRules: [{0F7B6837-6A55-4131-8225-558446DD7B8F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox.bak\firefox.exe FirewallRules: [{BB16D642-A6B2-45CB-BB42-7AE0E0A70A08}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{B91FFECE-B7E5-4B68-B5B1-12B05ECA9D8C}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe ==================== Restore Points ========================= 18-10-2016 17:16:45 Windows Update 25-10-2016 17:29:23 Windows Update ==================== Faulty Device Manager Devices ============= Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (10/28/2016 05:25:14 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (10/28/2016 05:25:14 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (10/28/2016 05:19:05 PM) (Source: DbxSvc) (EventID: 320) (User: ) Description: Failed to connect to the driver: (-2147024894) The system cannot find the file specified. Error: (10/28/2016 06:03:51 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (10/28/2016 06:03:51 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (10/28/2016 05:58:02 AM) (Source: Windows Search Service) (EventID: 7010) (User: ) Description: The index cannot be initialized. Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (10/28/2016 05:58:02 AM) (Source: Windows Search Service) (EventID: 3058) (User: ) Description: The application cannot be initialized. Context: Windows Application Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (10/28/2016 05:58:02 AM) (Source: Windows Search Service) (EventID: 3028) (User: ) Description: The gatherer object cannot be initialized. Context: Windows Application, SystemIndex Catalog Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (10/28/2016 05:58:02 AM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: The plug-in in <Search.TripoliIndexer> cannot be initialized. Context: Windows Application, SystemIndex Catalog Details: Element not found. (HRESULT : 0x80070490) (0x80070490) Error: (10/28/2016 05:58:02 AM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: The plug-in in <Search.JetPropStore> cannot be initialized. Context: Windows Application, SystemIndex Catalog Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) System errors: ============= Error: (10/28/2016 05:58:02 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (10/28/2016 05:58:02 AM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: The Windows Search service terminated with service-specific error %%-1073473535. Error: (10/27/2016 06:34:32 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 18:33:43 on ‎27/‎10/‎2016 was unexpected. Error: (10/26/2016 05:48:52 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 05:47:58 on ‎26/‎10/‎2016 was unexpected. Error: (10/24/2016 10:27:25 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 22:26:18 on ‎24/‎10/‎2016 was unexpected. Error: (10/24/2016 10:21:19 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 22:19:48 on ‎24/‎10/‎2016 was unexpected. Error: (10/21/2016 05:15:40 PM) (Source: sbp2port) (EventID: 25) (User: ) Description: The driver has detected a device with old or out-of-date firmware. The device will not be used. Error: (10/13/2016 07:06:33 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Error: (10/13/2016 07:06:33 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Error: (10/13/2016 07:05:19 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. ==================== Memory info =========================== Processor: AMD Phenom(tm) II X4 965 Processor Percentage of memory in use: 75% Total physical RAM: 4095.18 MB Available physical RAM: 1003.02 MB Total Virtual: 10235.36 MB Available Virtual: 6295.29 MB ==================== Drives ================================ Drive c: (System Reserved) (Fixed) (Total:111.79 GB) (Free:29.18 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive e: (WD) (Fixed) (Total:465.76 GB) (Free:165.33 GB) NTFS Drive f: (Samsung) (Fixed) (Total:931.51 GB) (Free:914.1 GB) NTFS Drive i: (WDMYBOOK) (Fixed) (Total:931.51 GB) (Free:400.29 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C81340A0) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: D9E0945C) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 0D75FE8F) Partition 1: (Active) - (Size=111.8 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 0033A7EB) Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================
  7. Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 28/10/2016 Scan Time: 20:07 Logfile: Administrator: Yes Version: 2.2.1.1043 Malware Database: v2016.10.28.10 Rootkit Database: v2016.09.26.02 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: Hercules Scan Type: Threat Scan Result: Completed Objects Scanned: 401365 Time Elapsed: 21 min, 14 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 0 (No malicious items detected) Physical Sectors: 0 (No malicious items detected) (end)
  8. Thanks kevinf80 for quick reply Here it goes. Did all the first bits with the browsers, never use IE or Edge so only did the Chrome and Firefox and Ran the Rkill. Here's the log from Rkill. Running Malwarebytes AntiMalware just now... still going. LOG FROM RKILL: Rkill 2.8.4 by Lawrence Abrams (Grinler) http://www.bleepingcomputer.com/ Copyright 2008-2016 BleepingComputer.com More Information about Rkill can be found at this link: http://www.bleepingcomputer.com/forums/topic308364.html Program started at: 10/28/2016 08:02:51 PM in x64 mode. Windows Version: Windows 7 Home Premium Service Pack 1 Checking for Windows services to stop: * No malware services found to stop. Checking for processes to terminate: * No malware processes found to kill. Checking Registry for malware related settings: * No issues found in the Registry. Resetting .EXE, .COM, & .BAT associations in the Windows Registry. Performing miscellaneous checks: * Windows Firewall Disabled [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = dword:00000000 Checking Windows Service Integrity: * TBS [Missing Service] Searching for Missing Digital Signatures: * No issues found. Checking HOSTS File: * HOSTS file entries found: 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 activate-sjc0.adobe.com Program finished at: 10/28/2016 08:03:14 PM Execution time: 0 hours(s), 0 minute(s), and 23 seconds(s)
  9. Hope someone can help me here. This started happening in the last couple of days, I'm not sure if it's malware but my computer is acting strangely all of a sudden. Without any warning, all open windows become unresponsive, the mouse moves but doesn't do anything when I click left or right. The only solution I found is to Ctr+Alt+Del to bring up the task manager then everything becomes responsive again. Also have a problem with browsers, both Chrome and Firefox will suddenly open new tabs on their own, always the last tab I had opened repeating over and over again. It's really weird. I use Avast Antivirus and Comodo Firewall and scanned the computer twice but didn't find anything. Ran CCCleaner too. I'm unsure what else I can do at this point. My machine is Windows 7 (64bit). Happy to provide other specs if necessary. Please help at least to diagnose if I have some sort of malware. Thanks in advance
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.