Additional scan result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01 Ran by Jedi_ARC (Riduu) at 2015-06-30 15:22:13 Running from C:\Users\Jedi_ARC (Riduu)\Downloads\Ingvar repairs Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3255530928-2953786320-3396913312-500 - Administrator - Disabled) Guest (S-1-5-21-3255530928-2953786320-3396913312-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3255530928-2953786320-3396913312-1002 - Limited - Enabled) Jedi_ARC (Riduu) (S-1-5-21-3255530928-2953786320-3396913312-1000 - Administrator - Enabled) => C:\Users\Jedi_ARC (Riduu) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Comodo Defense+ (Enabled - Up to date) {493CE176-EB84-BC8D-9707-B3ACF7598648} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: COMODO Firewall (Enabled) {CA6681B7-87D1-B25B-86E8-21EB720D8B8E} FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-3255530928-2953786320-3396913312-1000\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) 7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - ) 7-Zip 9.38 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0938-000001000000}) (Version: 9.38.00.0 - Igor Pavlov) Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.190 - Adobe Systems Incorporated) Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.190 - Adobe Systems Incorporated) Adobe Reader XI (11.0.11) - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Aslain's WoT Modpack wersja 4.4.25 (HKLM-x32\...\ZRwTINhSZfduKONYrSCTiCiGPggQZdcLRvoAVxyCOXXpkHeC~1DC3968F_is1) (Version: 4.4.25 - Aslain) Assassin's Creed Brotherhood (HKLM-x32\...\{AF28EDE7-0E0C-4A2F-9AC9-5369970E7716}_is1) (Version: - ) Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.00 - Ubisoft) Atlantica (HKLM-x32\...\Atlantica) (Version: 50128 - Nexon America) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software) Borderlands 2 (HKLM-x32\...\Borderlands 2_is1) (Version: - ) COMODO Firewall (HKLM\...\{68BE8BAB-5375-4C99-9116-1808F5968D40}) (Version: 8.1.0.4426 - COMODO Security Solutions Inc.) DawnOfWar (HKLM-x32\...\InstallShield_{362D5167-9716-44BE-89FD-BF9EB6EF814B}) (Version: 1.00.00000 - THQ) DawnOfWar (x32 Version: 1.00.00000 - THQ) Hidden Dishonored (HKLM-x32\...\Dishonored_is1) (Version: - ) Fallout 3 Game of the Year Edition - DLCs (HKLM-x32\...\{12CFDA5C-BDB9-460D-9E0D-F7879D9E2351}}_is1) (Version: - Bethesda Softworks) Fallout 3 Game of the Year Edition (HKLM-x32\...\{552F1CCF-1364-424C-85F7-46D4D006BB69}}_is1) (Version: - Bethesda Softworks) GeekBuddy (HKLM\...\{266FA04F-F0FA-4F7A-AA1E-387A57F579F2}) (Version: 4.19.131 - Comodo Security Solutions Inc) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.130 - Google Inc.) Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games) Heroes of Might and Magic V - Collectors Edition (HKLM-x32\...\Heroes of Might and Magic V - Collectors Edition3.1) (Version: 3.1 - Ubisoft) HP Deskjet 2510 series Basic Device Software (HKLM\...\{293CC68A-32BA-4BA4-84BD-0DCF6583566F}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) HP Deskjet 2510 series Help (HKLM-x32\...\{234DADAD-3C3C-4FB1-90A4-0AF015D56E18}) (Version: 27.0.0 - Hewlett Packard) HP Deskjet 2510 series Product Improvement Study (HKLM\...\{4B3264AA-951A-4A6B-B837-125224261F12}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) HP Deskjet 2510 series Setup Guide (HKLM-x32\...\{216C7F38-4BBC-4E9A-8392-C9FA21B54386}) (Version: 27.0.0 - Hewlett Packard) HP Photo Creations (HKU\S-1-5-21-3255530928-2953786320-3396913312-1000\...\HP Photo Creations) (Version: 1.0.0.17712 - HP) HP Support Solutions Framework (HKLM-x32\...\{FC3C2B77-6800-48C6-A15D-9D1031130C16}) (Version: 11.51.0049 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation) Killing Floor (HKLM-x32\...\Steam App 1250) (Version: - Tripwire Interactive) K-Lite Codec Pack 9.8.0 (Full) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.8.0 - ) Mass Effect (HKLM-x32\...\{1B0FBB9A-995D-47cd-87CD-13E68B676E4F}) (Version: 1.00 - Electronic Arts, Inc.) Mass Effect 2 (HKLM-x32\...\{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}) (Version: 1.00 - Electronic Arts, Inc.) Metric Collection SDK 35 (x32 Version: 1.2.0006.00 - Lenovo Group Limited) Hidden Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Might & Magic Heroes VI - Shades of Darkness (HKLM-x32\...\{745D37C2-26F4-4B65-BA13-F9840EBFA75B}) (Version: 2.1.0 - Ubisoft) Mozilla Firefox 38.0.5 (x86 pl) (HKLM-x32\...\Mozilla Firefox 38.0.5 (x86 pl)) (Version: 38.0.5 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 38.0.1 - Mozilla) NapiProjekt (2.2.0.2399) (HKLM-x32\...\NapiProjekt_is1) (Version: - ) Need For Speed™ World (HKLM-x32\...\{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1) (Version: 1.0.0.1599 - Electronic Arts) Nexon Game Manager (HKLM-x32\...\{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}) (Version: - ) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.53.7 - Black Tree Gaming) NVIDIA PhysX (HKLM-x32\...\{46ED2B64-85C7-4E1F-920C-A555B21F2E4C}) (Version: 9.11.1111 - NVIDIA Corporation) Oblivion mod manager 1.1.12 (HKLM-x32\...\Oblivion mod manager_is1) (Version: - Timeslip) Oblivion: Game of the Year Deluxe Edition (HKLM-x32\...\{ED75073E-C7B4-4EBE-8AEC-9C4CA41E5F2F}}_is1) (Version: - Bethesda Softworks) Obsługa programów Apple (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) OpenOffice 4.1.1 (HKLM-x32\...\{B5373BA3-BAD7-4EAC-A9D2-B66B41B82C57}) (Version: 4.11.9775 - Apache Software Foundation) Opera Stable 30.0.1835.88 (HKLM-x32\...\Opera 30.0.1835.88) (Version: 30.0.1835.88 - Opera Software) Overwolf (HKLM-x32\...\Overwolf) (Version: 0.86.89.0 - Overwolf Ltd.) Overwolf.Setup.VC100CRTx64.Dist (HKLM\...\{EC9D5554-6852-4A55-81BB-AC02C7A8CFED}) (Version: 1.0.0 - Overwolf) Overwolf.Setup.VC100CRTx86.Dist (x32 Version: 1.0.0 - Overwolf) Hidden Panda Cloud Cleaner (HKLM-x32\...\{92B2B132-C7F0-43DC-921A-4493C04F78A4}_is1) (Version: 1.0.107 - Panda Security) QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.46.610.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek Semiconductor Corp.) RtkDashClientInstaller (HKLM-x32\...\{91EA9C6F-1666-4426-9C80-85019A7A0D62}) (Version: 1.0.9 - Realtek) Saints Row The Third (HKLM-x32\...\Saints Row The Third_is1) (Version: - ) Samsung_MonSetup (HKLM-x32\...\{8EA79DBF-D637-448A-89D6-410A087A4493}) (Version: 1.00.0000 - Samsung) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) Total Commander (Remove or Repair) (HKLM-x32\...\Totalcmd) (Version: 7.55a - Ghisler Software GmbH) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Unity Web Player (HKU\S-1-5-21-3255530928-2953786320-3396913312-1000\...\UnityWebPlayer) (Version: 5.1.0f3 - Unity Technologies ApS) Uplay (HKLM-x32\...\Uplay) (Version: 6.0 - Ubisoft) Warhammer 40000 Dawn of War II - Retribution (HKLM-x32\...\Warhammer 40000 Dawn of War II - Retribution_is1) (Version: - ) World of Tanks (HKU\S-1-5-21-3255530928-2953786320-3396913312-1000\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812eu}_is1) (Version: - Wargaming.net) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= 31-05-2015 20:59:39 Scheduled Checkpoint 08-06-2015 18:43:54 Scheduled Checkpoint 16-06-2015 22:55:06 Scheduled Checkpoint 19-06-2015 13:44:22 Installed NVIDIA PhysX 27-06-2015 10:56:54 Scheduled Checkpoint 30-06-2015 14:17:02 Windows Update 30-06-2015 15:15:18 SPTD setup V1.87 ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-05-07 15:43 - 2015-05-07 15:43 - 00000000 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {05B5600C-21AC-4C2F-B35C-B0E433851A6B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-12] (Google Inc.) Task: {0BF5A931-297B-4028-9652-0B1D47F31EE8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-12] (Google Inc.) Task: {10696179-48C8-4B6B-8BEE-751CC4302371} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-25] (Adobe Systems Incorporated) Task: {1E6CE8E2-D5C8-4BA8-9500-940DCDA01954} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-06-18] (Avast Software s.r.o.) Task: {237F7D41-173E-43EB-9C40-BD4430FC1940} - System32\Tasks\ASP => C:\Program Files (x86)\RCP\systweakasp.exe Task: {2D58DA10-6C6F-4480-83A5-EA8F80EF1C3B} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2015-03-12] (Lenovo) Task: {3809987D-2443-4490-838B-5242E7D94A21} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-06-08] (COMODO) Task: {474754E6-7AF7-4E72-890D-4FC604B3BBB7} - System32\Tasks\{F978FFAB-D6BA-4634-92C3-84F985082BC6} => F:\pc\DriverGuide_Driver_Download_1658513.exe [2015-03-07] () Task: {649D0F50-D28B-4E99-85CC-0F7818BB79F9} - System32\Tasks\RtlDashSrvStart => C:\Program Files (x86)\Realtek\RtkDashClientInstaller\RtkDashClient.exe [2011-09-22] (Realtek Semiconductor Corporation) Task: {64FDB463-CC24-4318-AE95-A356B486D11D} - System32\Tasks\HPCustParticipation HP Deskjet 2510 series => C:\Program Files\HP\HP Deskjet 2510 series\Bin\HPCustPartic.exe [2015-03-15] (Hewlett-Packard Co.) Task: {849E95DD-32AE-4837-BCD1-5813AA5AAF40} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-06-08] (COMODO) Task: {8DB24FE3-9E27-4217-B866-3CEE3B6A8FD2} - System32\Tasks\Crossbrowse => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION Task: {9331A5E0-ACBF-4DB7-8491-33AAFE79DDC0} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2015-06-30] (Microsoft Corporation) Task: {9BED0EDE-8107-4910-8A5C-3D4CFB5CA420} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {9C2D19CA-561E-474C-A683-BC037A5348BA} - System32\Tasks\{E44FF1C5-0F60-4CE2-A85A-117E792A52DA} => pcalua.exe -a F:\Setup.exe -d F:\ Task: {CB0BACD5-73A0-453C-BD68-07D855BC957B} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {D0698617-B511-479C-8E61-C1434F9A91E1} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {D68AE1BA-A651-4ED2-8802-0943774C10F7} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2015-06-25] (Overwolf LTD) Task: {D763E5BB-D45F-4A52-A7D9-8004C0403F3B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-24] (Adobe Systems Incorporated) Task: {D9CAB316-E7D4-4868-B1C0-0264EECC97C6} - System32\Tasks\Opera scheduled Autoupdate 1425758550 => C:\Program Files (x86)\Opera\launcher.exe [2015-06-25] (Opera Software) Task: {FD869294-F9D9-4E0E-B19F-F1CF7B7DD1C2} - System32\Tasks\HP Photo Creations Communicator => C:\Users\Jedi_ARC (Riduu)\AppData\Roaming\HP Photo Creations\Communicator.exe [2015-03-26] () Task: {FE6E8A2C-E62E-4412-B324-CDBB6A43A9EE} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-06-08] (COMODO) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\Crossbrowse.job => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\Users\Jedi_ARC (Riduu)\AppData\Roaming\HP Photo Creations\Communicator.exe Task: C:\Windows\Tasks\RtlDashSrvStart.job => C:\Program Files (x86)\Realtek\RtkDashClientInstaller\RtkDashClient.exe ==================== Loaded Modules (Whitelisted) ============== 2015-05-07 09:34 - 2015-05-07 09:34 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-05-07 09:34 - 2015-05-07 09:34 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-06-30 14:06 - 2015-06-30 14:06 - 02952704 _____ () C:\Program Files\AVAST Software\Avast\defs\15063000\algo.dll 2015-06-21 13:31 - 2015-06-21 13:31 - 00025600 _____ () C:\Program Files (x86)\Overwolf\0.86.89.0\CoreAudioApi.dll 2015-06-21 13:31 - 2015-06-21 13:31 - 40555008 _____ () C:\Program Files (x86)\Overwolf\0.86.89.0\libcef.DLL 2015-03-07 22:03 - 2015-03-07 22:03 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Windows\AlcRmv64.exe:$CmdTcID AlternateDataStreams: C:\Windows\AlcUpd64.exe:$CmdTcID AlternateDataStreams: C:\Windows\avastSS.scr:$CmdTcID AlternateDataStreams: C:\Windows\RtlExUpd.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\aaclient.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\AcpiServiceVnA64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\adprovider.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\adtschema.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\advapi32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\aeinv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\aepdu.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\aepic.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\AERTAC64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\AERTAR64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\aitstatic.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\apisetschema.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\appinfo.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\appraiser.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\atmfd.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\atmlib.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\audioLibVc.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\auditpol.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\authui.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\BugslayerUtil.dll:$CmdZnID AlternateDataStreams: C:\Windows\system32\capiprovider.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\certenc.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\certutil.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\cngprovider.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\comctl32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\CONEQMSAPOGUILibrary.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\consent.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\CPFilters.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\credssp.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\credui.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\crypt32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\cryptnet.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\cryptsvc.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\csrsrv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3d11.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DCompiler_40.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx10_40.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DX9_40.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\dciman32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DDPA64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DDPD64A.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DDPO64A.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DDPP64A.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\devinv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\dfshim.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\dimsroam.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\dpapiprovider.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\dpnet.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSBassEnhancementDLL64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSBoostDLL64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSGainCompensatorDLL64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSGFXAPO64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSGFXAPONS64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSLFXAPO64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSLimiterDLL64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSNeoPCDLL64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSS2HeadphoneDLL64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSS2SpeakerDLL64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSSymmetryDLL64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSU2PGFX64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSU2PLFX64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSU2PREC64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\DTSVoiceClarityDLL64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\FMAPO64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\fontsub.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\gameux.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\generaltel.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\hpinkcoiAC11.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\hpinkinsAC11.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\hpinkstsAC11LM.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\HPScanTRDrv_DJ2510.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\HPWia2_DJ2510.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\icardagt.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\icardres.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\ICEsoundAPO64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\IEUDINIT.EXE:$CmdTcID AlternateDataStreams: C:\Windows\system32\infocardapi.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\invagent.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\iphlpsvc.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\KAAPORT64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\kerberos.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\KernelBase.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\lpk.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\lsass.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO20.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO30.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO4064.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO5064.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO6064.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxAudioAPOShell64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxAudioEQ64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxAudioRealtek264.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxAudioRealtek64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxAudioVnA64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxAudioVnN64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxSpeechAPO64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxVoiceAPO2064.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxVoiceAPO3064.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MaxxVolumeSDAPO.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\mf.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\mferror.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\mfpmp.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\mfps.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\MISS_APO.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\mpg2splt.ax:$CmdTcID AlternateDataStreams: C:\Windows\system32\MpSigStub.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\msaudite.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\mscorier.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\mscories.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\msdrm.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\msi.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\msieftp.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\msihnd.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\msobjs.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\msscntrs.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\mssph.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\mssphtb.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\mssrch.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\mssvp.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\mstsc.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\mstscax.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\msv1_0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\mswsock.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\msxml3.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\msxml3r.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\NAHIMICAPOlfx.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\NAHIMICAPOSettingsIPC.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\ncrypt.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\ncsi.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\netcorehc.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\netevent.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\nlaapi.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\ntdll.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\ntshrui.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\objsel.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\odbccp32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\odbccr32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\odbccu32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\odbctrac.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\osk.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\OxpsConverter.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\pku2u.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\poqexec.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\qdvd.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\qedit.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\quartz.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\R4EEA64A.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\R4EED64A.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\R4EEG64A.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\R4EEL64A.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\R4EEP64A.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RCoInstII64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\rdpcorekmts.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\rdpcorets.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\rdpwsx.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\rdrmemptylst.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\RltkAPO64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RMActivate.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\RMActivate_isv.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\RMActivate_ssp.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\RMActivate_ssp_isv.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\RP3DAA64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RP3DHT64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\rrinstaller.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\rstrui.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\RTCOM64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RtDataProc64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RTEED64A.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RTEEG64A.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RTEEL64A.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RTEEP64A.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RtkApi64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RtkCfg64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RtkCoLDR64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RtlCPAPI64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RtPgEx64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\RTSnMg64.cpl:$CmdTcID AlternateDataStreams: C:\Windows\system32\sbe.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\scavengeui.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\schannel.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\SearchFilterHost.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\SearchIndexer.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\SearchProtocolHost.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\secproc.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\secproc_isv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\secproc_ssp.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\secproc_ssp_isv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\secur32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\SFAPO64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\SFCOM64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\SFNHK64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\SFSS_APO.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\shdocvw.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\shell32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\sl3apo64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\slcnt64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\slprp64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\sltech64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\SmartcardCredentialProvider.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\smss.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\srclient.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\srcore.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\SRSHP64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\SRSTSH64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\SRSTSX64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\SRSWOW64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\sspicli.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\sspisrv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\SStudio.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\synceng.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\tadefxapo.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\tadefxapo264.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\taskhost.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\tdh.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\tepeqapo64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\termsrv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\timedate.cpl:$CmdTcID AlternateDataStreams: C:\Windows\system32\tosade.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\tosasfapo64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\toseaeapo64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\tossaeapo64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\tquery.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\tsgqec.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\TSpkg.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\TSWbPrxy.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\TsWpfWrp.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\tzres.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\WavesGUILib64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wdigest.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\webio.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\win32k.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\win32spl.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wincredprovider.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\winlogon.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\winsta.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wintrust.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wmi.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wmp.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wmploc.DLL:$CmdTcID AlternateDataStreams: C:\Windows\system32\Wpc.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\WSManHTTPConfig.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\WSManMigrationPlugin.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\WsmAuto.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\WsmSvc.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\WsmWmiPl.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\WUDFCoinstaller.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\WUDFHost.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\WUDFPlatform.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\WUDFSvc.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\WUDFx.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xmllite.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\YamahaAE.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\aaclient.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\adprovider.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\adtschema.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\advapi32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\apisetschema.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\atmfd.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\atmlib.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\auditpol.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\authui.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\BugslayerUtil.dll:$CmdZnID AlternateDataStreams: C:\Windows\SysWOW64\capiprovider.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\certenc.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\certutil.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\cngprovider.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\comctl32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\CPFilters.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\credssp.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\credui.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\crypt32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\cryptnet.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\cryptsvc.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3d11.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_40.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_40.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_40.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\dciman32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\dfshim.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\dimsroam.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\dpapiprovider.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\dpnet.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\fontsub.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\gameux.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\icardagt.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\icardres.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\infocardapi.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\instnm.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\kerberos.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\KernelBase.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\lpk.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\MaxxAudioAPOShell.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mf.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mferror.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mfpmp.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mfps.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mpg2splt.ax:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msaudite.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mscorier.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mscories.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msdrm.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msi.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msieftp.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msihnd.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msobjs.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msscntrs.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mssph.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mssphtb.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mssrch.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mssvp.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mstsc.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mstscax.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msv1_0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\mswsock.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msxml3.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msxml3r.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\ncrypt.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\ncsi.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\netcorehc.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\netevent.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\nlaapi.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\ntdll.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\ntkrnlpa.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\ntoskrnl.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\ntshrui.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\objsel.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\odbccp32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\odbccr32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\odbccu32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\odbcjt32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\odbctrac.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\osk.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\pku2u.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\poqexec.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\prevhost.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\qdvd.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\qedit.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\quartz.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\RMActivate.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\RMActivate_isv.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\RMActivate_ssp.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\RMActivate_ssp_isv.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\rrinstaller.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\sbe.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\schannel.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\SearchFilterHost.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\SearchIndexer.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\SearchProtocolHost.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\secproc.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\secproc_isv.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\secproc_ssp.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\secproc_ssp_isv.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\secur32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\SFCOM.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\shdocvw.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\shell32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\SmartcardCredentialProvider.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\srclient.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\sspicli.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\subinacl.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\synceng.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\tdh.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\timedate.cpl:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\tquery.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\tsgqec.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\TSpkg.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\TsWpfWrp.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\tzres.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\user.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wdigest.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\webio.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\win32spl.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wincredprovider.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\winsta.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wintrust.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wmi.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wmp.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wmploc.DLL:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wow32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\Wpc.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\WSManHTTPConfig.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\WSManMigrationPlugin.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\WsmAuto.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\WsmSvc.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\WsmWmiPl.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xmllite.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\afd.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\ataport.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\bowser.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\drmk.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\fs_rec.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\hidclass.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\hidparse.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\ksecdd.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\portcls.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\PSKMAD.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\rdpwd.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\RTKVHD64.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\srv.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\srv2.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\srvnet.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\ssudbus.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\ssudmdm.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\tcpipreg.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\tdx.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\tssecsrv.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\usb8023.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\usbscan.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\Wdf01000.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\WdfLdr.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\WUDFPf.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\WUDFRd.sys:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\#SELFIE (Official Music Video) - The Chainsmokers.mp3:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\#SELFIE (Official Music Video) - The Chainsmokers.mp3:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\0905_001(1).pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\0905_001(1).pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\0905_001.pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\0905_001.pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\0945_001.pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\0945_001.pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\16231606171-412065702-registration(1)(1).pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\16231606171-412065702-registration(1)(1).pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\16231606171-412065702-registration(1).pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\16231606171-412065702-registration(2)(1).pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\16231606171-412065702-registration(2)(1).pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\16231606171-412065702-registration(2).pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\16231606171-412065702-registration(2).pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\16231606171-412065702-registration(3).pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\16231606171-412065702-registration(3).pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\16231606171-412065702-registration.pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\16231606171-412065702-registration.pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\7z938-x64.msi:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\7z938-x64.msi:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\A Quality World Map - New Installer-4929-8-4.7z:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\A Quality World Map - New Installer-4929-8-4.7z:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.10_981.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.10_981.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.12_981.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.12_981.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.17_981.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.17_981.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.25_981.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.25_981.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.2_98(1).exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.2_98(1).exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.2_98.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.2_98.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.3_98.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.3_98.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.4_98.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.4_98.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.5_981.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.5_981.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Aslains_WoT_Modpack_Installer_v.4.4.6_98.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Borderlands.2.v1.0.Plus.23.Trainer-FLiNG.rar:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Borderlands.2.v1.0.Plus.23.Trainer-FLiNG.rar:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\cv_-_błaszczak_piotr.pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Dishonored.v1.0.Plus.18.Trainer-FLiNG.rar:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Dishonored.v1.0.Plus.18.Trainer-FLiNG.rar:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Firefox Setup Stub 38.0.1.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Firefox Setup Stub 38.0.1.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Harmonogram spłat kredytu 00266353_2006.pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Harmonogram spłat kredytu 00266353_2006.pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Harmonogram spłat kredytu 00266361_2006.pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Harmonogram spłat kredytu 00266361_2006.pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\HeartwoodCottageNM1_v2-20561-v2.7z:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Heat Map.xls:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Heat Map.xls:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Hellsing Opening (Full Song).mp3:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Hellsing Opening (Full Song).mp3:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Hellsing OST - Alucard´s Theme.mp3:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Hellsing OST - Alucard´s Theme.mp3:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\jxpiinstall.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\jxpiinstall.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Major Lazer - Come On To Me ft. Sean Paul.mp3:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Major Lazer - Come On To Me ft. Sean Paul.mp3:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\masseffect220trainer.zip:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\MassEffect2_spolszczenie_www.INSTALKI.pl.zip:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\MassEffect2_spolszczenie_www.INSTALKI.pl.zip:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\mass_effect_2_v10_t19.rar:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\O.S.T.R. - Ma_y Szary Cz_owiek.mp3:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\O.S.T.R. - Ma_y Szary Cz_owiek.mp3:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\PandaCloudCleaner.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\PotwierdzenieTransakcji_20150511_152439.pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\PotwierdzenieTransakcji_20150511_152439.pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\predk_kosm.pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\predk_kosm.pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\QuickTimeInstaller.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\QuickTimeInstaller.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\REMOVEWAT.EXE:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Saints_Row_IV_-_Female_Nude_Mod.zip:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\The Elder Scrolls 4 Oblivion Cz 3 - Poradnik Gry-Online.rar:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\The Elder Scrolls 4 Oblivion Cz 3 - Poradnik Gry-Online.rar:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\UnityWebPlayer.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\UnityWebPlayer.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Unofficial_Skyrim_Patch_2_0_2a_PL-38246-2-0-2.rar:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Unofficial_Skyrim_Patch_2_0_2a_PL-38246-2-0-2.rar:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\UPC 06 czerwiec 2015.pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\upc_instrukcja_obslugi_modemu_thomson_twg870-eu(1).pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\upc_instrukcja_obslugi_modemu_thomson_twg870-eu(1).pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\upc_instrukcja_obslugi_modemu_thomson_twg870-eu.pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\upc_instrukcja_obslugi_modemu_thomson_twg870-eu.pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\War - Low Rider (HQ Audio).mp3:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\War - Low Rider (HQ Audio).mp3:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\warszawa_centralna_mapka_01_2014.pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\warszawa_centralna_mapka_01_2014.pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\WoT_internet_install_eu.exe:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\WoT_internet_install_eu.exe:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\wykaz lekarzy 14 listpada 2012 r..pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\wykaz lekarzy 14 listpada 2012 r..pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Wykaz lekarzy sadowych- aktualizacja dn 12 grudnia 2014r.pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Wykaz lekarzy sadowych- aktualizacja dn 12 grudnia 2014r.pdf:$CmdZnID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Wykaz_lekarzy_sadowych_st.z_dn._4_sierpnia_2014_r..pdf:$CmdTcID AlternateDataStreams: C:\Users\Jedi_ARC (Riduu)\Downloads\Wykaz_lekarzy_sadowych_st.z_dn._4_sierpnia_2014_r..pdf:$CmdZnID ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3255530928-2953786320-3396913312-1000\Control Panel\Desktop\\Wallpaper -> DNS Servers: 156.154.70.25 - 156.154.71.25 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: bthserv => 3 MSCONFIG\Services: Fax => 3 MSCONFIG\Services: hkmsvc => 3 MSCONFIG\startupfolder: C:^Users^Jedi_ARC (Riduu)^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^crossbrowse.lnk => C:\Windows\pss\crossbrowse.lnk.Startup MSCONFIG\startupfolder: C:^Users^Jedi_ARC (Riduu)^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^hqghumeaylnlf.lnk => C:\Windows\pss\hqghumeaylnlf.lnk.Startup MSCONFIG\startupreg: BCSSync => "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices MSCONFIG\startupreg: DriverUpdaterPro => C:\Program Files (x86)\oTweak\DriverUpdaterPro\DriverUpdaterPro.exe /ot /as /ss MSCONFIG\startupreg: GoogleChromeAutoLaunch_CC87289FA0D9684B6C5969EA1D0AE199 => "C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\steam.exe" -silent MSCONFIG\startupreg: WGA Remover => "C:\Program Files (x86)\WGA Remover\wgaremover.exe" -silent ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{6AB5796D-C736-4DF2-900A-F068843040F9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{2EE47AF9-2D2E-4067-ACCC-3873F9F07F79}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{968B503E-27C7-4095-ABAA-F465D02D7F54}D:\gry\wot\wotlauncher.exe] => (Allow) D:\gry\wot\wotlauncher.exe FirewallRules: [UDP Query User{F93B64DA-D627-4737-871B-67568C3F2A42}D:\gry\wot\wotlauncher.exe] => (Allow) D:\gry\wot\wotlauncher.exe FirewallRules: [{17BEC93E-91DD-480A-9BE8-739FBA28C257}] => (Allow) C:\Program Files (x86)\NapiProjekt\napisy.exe FirewallRules: [{22BFAA83-8A27-470F-91B6-D18EB1835C0A}] => (Allow) C:\Program Files (x86)\NapiProjekt\napisy.exe FirewallRules: [{98C01822-3CFD-4313-9B4D-A156E1E6D2C9}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{0DDB54D2-A2A4-4B36-8FCC-C8CF09CBC523}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{F62DE8B1-69EC-468B-9EDD-1AC89DC78B46}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{12C4CA77-E8E0-4F95-8B82-09A927BB5C30}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{34C2C7F6-12DD-4E55-8905-88733B058F9A}] => (Allow) C:\Users\Jedi_ARC (Riduu)\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{0F38C9EB-3675-4B4A-A6FD-A52669E29E76}] => (Allow) C:\Users\Jedi_ARC (Riduu)\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{586E43F7-F330-47EB-837C-E1688F961860}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{346F0982-25D5-4170-AAA0-65022DC66BA7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{2E3CBD5D-E0CC-410B-9685-852489115ED6}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{2145709D-48A0-4C87-ACDC-C6984AF8DA23}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{124A2084-65F7-47B9-ACD7-1D5BD31D77D6}] => (Allow) D:\Gry\Steam-KF\steamapps\common\KillingFloor\System\KillingFloor.exe FirewallRules: [{2EEB1C86-8B10-4C07-811A-8271BA7FDFD1}] => (Allow) D:\Gry\Steam-KF\steamapps\common\KillingFloor\System\KillingFloor.exe FirewallRules: [{36646EFE-4206-4B68-BDC6-1D677AD29E76}] => (Allow) C:\Users\Jedi_ARC (Riduu)\AppData\Local\Temp\7zS191C\HPDiagnosticCoreUI.exe FirewallRules: [{29998C4C-7022-4B0D-B370-43CC305CC2EA}] => (Allow) C:\Users\Jedi_ARC (Riduu)\AppData\Local\Temp\7zS191C\HPDiagnosticCoreUI.exe FirewallRules: [{BFDFCD5D-1866-440B-A85F-D823A0FCAC0F}] => (Allow) C:\Program Files\HP\HP Deskjet 2510 series\Bin\USBSetup.exe FirewallRules: [{7BFAF818-F090-419A-A700-995F9CC1B722}] => (Allow) C:\Users\Jedi_ARC (Riduu)\AppData\Local\Temp\7zS656D\HPDiagnosticCoreUI.exe FirewallRules: [{DBB12F95-A278-40A5-AD7F-895F28D887B9}] => (Allow) C:\Users\Jedi_ARC (Riduu)\AppData\Local\Temp\7zS656D\HPDiagnosticCoreUI.exe FirewallRules: [{77EFF5C4-6B21-4F04-8B67-4C1F0E534DCF}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{A5B6F90C-E48E-48F8-B490-DE887733C0BF}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{E0F442DC-6ED2-4B3E-A492-39E46DCB2F10}] => (Allow) C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe FirewallRules: [{70CDE8AC-123D-4D46-85F1-4011A3636D65}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{EDDC288F-703A-47C9-8767-475AA88CDDE0}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{E04CAA87-8115-441F-A0DF-A4F0BB87025C}] => (Allow) D:\Gry\Mass Effect\Binaries\MassEffect.exe FirewallRules: [{2F62F08D-E94D-4CA5-AA56-3AB4F4505C90}] => (Allow) D:\Gry\Mass Effect\Binaries\MassEffect.exe FirewallRules: [{8C25D5C2-AE2A-48B8-AEFD-0CFD09F3A21C}] => (Allow) D:\Gry\Mass Effect\MassEffectLauncher.exe FirewallRules: [{876B550F-4DBF-41F9-AAD9-39E9C17435A7}] => (Allow) D:\Gry\Mass Effect\MassEffectLauncher.exe FirewallRules: [{E4F63FF2-72CE-4A0B-9F7B-2353618CB738}] => (Allow) C:\ProgramData\NexonUS\NGM\NGM.exe FirewallRules: [{EBE73195-B3FB-4EC7-98FE-9B8ACD63C028}] => (Allow) C:\ProgramData\NexonUS\NGM\NGM.exe FirewallRules: [{18AAF69D-F0C1-4BB7-9539-D6A5E7369A06}] => (Allow) D:\Gry\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe FirewallRules: [{10E349F6-486B-449D-97CE-DB3285F0778E}] => (Allow) D:\Gry\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe FirewallRules: [{6762FF60-44C4-4CD9-9F89-3AF7C473916F}] => (Allow) D:\Gry\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe FirewallRules: [{21616EC7-CE18-4F9F-9C8D-0C157844B81D}] => (Allow) D:\Gry\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe FirewallRules: [{35E9C2AB-7B99-4F52-A531-CABAA4964807}] => (Allow) D:\Gry\Ubisoft\Assassin's Creed II\UPlayBrowser.exe FirewallRules: [{4E35F147-3F92-4797-B4CA-B82833A7F3C8}] => (Allow) D:\Gry\Ubisoft\Assassin's Creed II\UPlayBrowser.exe FirewallRules: [{CE0A6A6C-3162-4D2F-B87D-3C925DC65C73}] => (Allow) E:\Games\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe FirewallRules: [{44A5C80B-8BAC-43FB-BDB5-724912740E36}] => (Allow) E:\Games\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe FirewallRules: [{992869D3-1224-4F07-A0C0-8F0CC1525E63}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe FirewallRules: [{ACAF4FFF-2837-4671-AD89-6CCF552CB174}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{329A4082-ECD5-4333-B09F-C6284B2C6DED}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{53AF6ACD-5E43-4905-974F-F10A0FF73644}] => (Allow) E:\Games\Mass Effect 2\Binaries\MassEffect2.exe FirewallRules: [{FDAA9205-E56C-46C5-AFB9-0BD9D568E7D4}] => (Allow) E:\Games\Mass Effect 2\Binaries\MassEffect2.exe FirewallRules: [{81805503-2B33-499C-9D34-2F1664499411}] => (Allow) E:\Games\Mass Effect 2\MassEffect2Launcher.exe FirewallRules: [{E797DE89-5433-4C31-AC38-FB38D013C67D}] => (Allow) E:\Games\Mass Effect 2\MassEffect2Launcher.exe FirewallRules: [{87A43B28-F962-483F-90AB-2936FE62C138}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft Teredo Tunneling Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: GT-I9100 Description: GT-I9100 Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a} Manufacturer: SAMSUNG Electronics Co. Ltd. Service: WUDFRd Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/30/2015 03:18:50 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/30/2015 03:15:24 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary SCDEmu. System Error: The system cannot find the file specified. . Error: (06/30/2015 03:15:18 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied. . This is often caused by incorrect security settings in either the writer or requestor process. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {ec6d9cbe-4555-41d0-8f12-5540c860aa23} Error: (06/30/2015 03:09:30 PM) (Source: OverwolfUpdater) (EventID: 0) (User: ) Description: Service cannot be started. An instance of the service is already running Error: (06/30/2015 03:09:29 PM) (Source: OverwolfUpdater) (EventID: 0) (User: ) Description: Service cannot be started. The handle is invalid Error: (06/30/2015 03:00:54 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/30/2015 02:29:36 PM) (Source: OverwolfUpdater) (EventID: 0) (User: ) Description: Service cannot be started. An instance of the service is already running Error: (06/30/2015 02:29:36 PM) (Source: OverwolfUpdater) (EventID: 0) (User: ) Description: Service cannot be started. The handle is invalid Error: (06/30/2015 02:22:08 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/30/2015 10:39:05 AM) (Source: OverwolfUpdater) (EventID: 0) (User: ) Description: Service cannot be started. An instance of the service is already running System errors: ============= Error: (06/30/2015 03:21:06 PM) (Source: BROWSER) (EventID: 8032) (User: ) Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{2D6A36C9-9F15-4712-BF45-1687D13650CB}. The backup browser is stopping. Error: (06/30/2015 03:18:44 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: zedltn Error: (06/30/2015 03:18:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Util Round World service failed to start due to the following error: %%2 Error: (06/30/2015 03:18:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Update Steel Cut service failed to start due to the following error: %%2 Error: (06/30/2015 03:18:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Update Special Box service failed to start due to the following error: %%2 Error: (06/30/2015 03:02:59 PM) (Source: BROWSER) (EventID: 8032) (User: ) Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{2D6A36C9-9F15-4712-BF45-1687D13650CB}. The backup browser is stopping. Error: (06/30/2015 03:00:48 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: zedltn Error: (06/30/2015 03:00:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Util Round World service failed to start due to the following error: %%2 Error: (06/30/2015 03:00:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Update Steel Cut service failed to start due to the following error: %%2 Error: (06/30/2015 03:00:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Update Special Box service failed to start due to the following error: %%2 Microsoft Office: ========================= Error: (06/30/2015 03:18:50 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/30/2015 03:15:24 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary SCDEmu. System Error: The system cannot find the file specified. Error: (06/30/2015 03:15:18 PM) (Source: VSS) (EventID: 8194) (User: ) Description: 0x80070005, Access is denied. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {ec6d9cbe-4555-41d0-8f12-5540c860aa23} Error: (06/30/2015 03:09:30 PM) (Source: OverwolfUpdater) (EventID: 0) (User: ) Description: Service cannot be started. An instance of the service is already running Error: (06/30/2015 03:09:29 PM) (Source: OverwolfUpdater) (EventID: 0) (User: ) Description: Service cannot be started. The handle is invalid Error: (06/30/2015 03:00:54 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/30/2015 02:29:36 PM) (Source: OverwolfUpdater) (EventID: 0) (User: ) Description: Service cannot be started. An instance of the service is already running Error: (06/30/2015 02:29:36 PM) (Source: OverwolfUpdater) (EventID: 0) (User: ) Description: Service cannot be started. The handle is invalid Error: (06/30/2015 02:22:08 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/30/2015 10:39:05 AM) (Source: OverwolfUpdater) (EventID: 0) (User: ) Description: Service cannot be started. An instance of the service is already running ==================== Memory info =========================== Processor: Pentium(R) Dual-Core CPU E6700 @ 3.20GHz Percentage of memory in use: 39% Total physical RAM: 4094.49 MB Available physical RAM: 2490.59 MB Total Pagefile: 8187.17 MB Available Pagefile: 6273.53 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:74.53 GB) (Free:9.09 GB) NTFS Drive d: () (Fixed) (Total:157.07 GB) (Free:5.33 GB) NTFS Drive e: () (Fixed) (Total:308.59 GB) (Free:34.58 GB) NTFS Drive f: (RIDUU) (Removable) (Total:28.89 GB) (Free:7.46 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C1088BF6) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=157.1 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=308.6 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 74.5 GB) (Disk ID: 0BAA0BA9) Partition 1: (Not Active) - (Size=74.5 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 28.9 GB) (Disk ID: 03A3C498) Partition 1: (Not Active) - (Size=28.9 GB) - (Type=07 NTFS) ==================== End of log ============================