Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja: 04-10-2016 Uruchomiony przez admin (05-10-2016 13:30:55) Uruchomiony z C:\Users\admin\Downloads\FRST Windows 10 Home Wersja 1511 (X64) (2015-12-11 03:46:01) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= admin (S-1-5-21-63831111-2181059775-4247894396-1001 - Administrator - Enabled) => C:\Users\admin Administrator (S-1-5-21-63831111-2181059775-4247894396-500 - Administrator - Disabled) Gość (S-1-5-21-63831111-2181059775-4247894396-501 - Limited - Disabled) Inni (S-1-5-21-63831111-2181059775-4247894396-1002 - Limited - Enabled) => C:\Users\Inni Konto domyślne (S-1-5-21-63831111-2181059775-4247894396-503 - Limited - Disabled) ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: COMODO Antivirus (Enabled - Up to date) {F25D0092-CDBE-B303-ADB7-88DE8CDECCF5} AS: Comodo Defense+ (Enabled - Up to date) {493CE176-EB84-BC8D-9707-B3ACF7598648} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: COMODO Firewall (Enabled) {CA6681B7-87D1-B25B-86E8-21EB720D8B8E} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated) Adobe Flash Player 23 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 23.0.0.162 - Adobe Systems Incorporated) Android Studio (HKLM\...\Android Studio) (Version: 1.0 - Google Inc.) Arduino (HKLM-x32\...\Arduino) (Version: 1.6.6 - Arduino LLC) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlefield: Bad Company™ 2 (HKLM-x32\...\{3AC8457C-0385-4BEA-A959-E095F05D6D67}) (Version: 1.0.0.0 - Electronic Arts) COMODO Internet Security Premium (HKLM\...\{4C5D0B6A-944A-47A6-A2F3-BCB58E05CA5D}) (Version: 8.2.0.4591 - COMODO Security Solutions Inc.) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) Dead Space™ 3 (HKLM-x32\...\{D4329609-4102-4F8C-B83F-7FE024EEA314}) (Version: 1.0.0.0 - Electronic Arts, Inc.) Dodatek Zapisywanie jako PDF lub XPS firmy Microsoft dla programów pakietu Microsoft Office 2007 (HKLM-x32\...\{90120000-00B2-0415-0000-0000000FF1CE}) (Version: 12.0.4518.1020 - Microsoft Corporation) Dropbox (HKLM-x32\...\Dropbox) (Version: 11.4.21 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.27.37 - Dropbox, Inc.) Hidden FIFA 14 (HKLM-x32\...\{AA7A2800-1E75-4240-855B-03AFF8E5171E}) (Version: 1.0.0.7 - Electronic Arts) GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 53.0.2785.143 - Google Inc.) Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden Java 8 Update 91 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418091F0}) (Version: 8.0.910.15 - Oracle Corporation) Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.15 - Oracle Corporation) Java SE Development Kit 7 Update 80 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170800}) (Version: 1.7.0.800 - Oracle) LG Mobile Driver (HKLM-x32\...\{3F490D0E-3131-438C-BCF9-7549CB88DF41}) (Version: 4.0.3 - LG Electronics) Metro 2033 (HKLM-x32\...\Steam App 43110) (Version: - 4A Games) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) MiniLyrics (HKLM-x32\...\MiniLyrics) (Version: 7.7.49 - Crintsoft) Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts) NVIDIA PhysX (HKLM-x32\...\{54194F60-988C-4D03-B922-C2B00EFDA39A}) (Version: 9.10.0222 - NVIDIA Corporation) NVIDIA Sterownik graficzny 341.81 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.81 - NVIDIA Corporation) Opera Stable 40.0.2308.62 (HKLM-x32\...\Opera 40.0.2308.62) (Version: 40.0.2308.62 - Opera Software) Oracle VM VirtualBox 5.0.16 (HKLM\...\{F2E958A1-9215-4C7D-9A2E-F0740B8CA5B7}) (Version: 5.0.16 - Oracle Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.5.20.5318 - Electronic Arts, Inc.) Panel sterowania NVIDIA 341.92 (Version: 341.92 - NVIDIA Corporation) Hidden PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.988 - Even Balance, Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.) Samsung ML-1640 Series (HKLM-x32\...\Samsung ML-1640 Series) (Version: - Samsung Electronics CO.,LTD) SecureW2 EAP Suite 1.1.3 for Windows (HKLM-x32\...\SecureW2 EAP Suite) (Version: - ) SopCast 4.2.0 (HKLM-x32\...\SopCast) (Version: 4.2.0 - www.sopcast.com) Spolszczenie do Dead Space 3 (HKLM-x32\...\Spolszczenie do Dead Space 3) (Version: 1.5 - GrajPoPolsku) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.10.0 - Synaptics Incorporated) System Requirements Lab Detection (HKLM-x32\...\{1C1041E0-7329-4441-9AB1-7CF4738BC23C}) (Version: 6.1.6.0 - Husdawg, LLC) Team Fortress 2 (HKLM\...\Steam App 440) (Version: - Valve) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) WinRAR 5.21 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) CustomCLSID: HKU\S-1-5-21-63831111-2181059775-4247894396-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\admin\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileCoAuth.exe (Microsoft Corporation) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {077DB967-4044-4C27-B281-D94664A2A5D2} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-09-25] (COMODO) Task: {0C47B903-B337-48A2-8FAE-1DE69AD5A89C} - System32\Tasks\{31DDBD37-5DB7-4030-8064-10B0CAA806C3} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2016-09-25] (COMODO) Task: {12321BFD-7962-4390-9545-0E9E3A4B5B86} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2016-09-25] (COMODO) Task: {158D6BB8-E394-4967-BE2F-ECE121CE857A} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-09-25] (COMODO) Task: {16261BC7-1604-4CA6-8BE7-7F767A04CF5C} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-10-08] (Dropbox, Inc.) Task: {2B9F9A40-01F1-49A9-8595-AE75C113F772} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\admin\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe [2016-08-23] (Microsoft Corporation) Task: {3D97462F-0821-4C9E-AB4B-1A2FBBA87AB8} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_23_0_0_162_pepper.exe [2016-09-13] (Adobe Systems Incorporated) Task: {567B2841-EF87-4D1F-9877-75EB161AC4CA} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-30] (Adobe Systems Incorporated) Task: {78652DFA-6361-4734-9D09-1DE80B1C2FEE} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-09-25] (COMODO) Task: {A2279D74-5205-4CA6-BDC1-9D66D412FE06} - System32\Tasks\Opera scheduled Autoupdate 1439828048 => C:\Program Files (x86)\Opera\launcher.exe [2016-09-25] (Opera Software) Task: {AA12B0F7-5A89-446C-BEFA-1CE613AC8653} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-10-08] (Dropbox, Inc.) Task: {AE711C9A-D3A7-49A2-9E0A-3BB5F6C7B6B2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-04] (Google Inc.) Task: {BFFF79FE-813C-42BC-AEB1-B79C19B1467F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-04] (Google Inc.) Task: {D02E9D01-F30D-495F-8296-C063A60A42B6} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-09-25] (COMODO) Task: {D083E592-936B-402D-A690-FF01245626C9} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-09-13] (Adobe Systems Incorporated) Task: {EFD1C9BE-2B2B-450B-A9B7-60836873387E} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-09-14] (Microsoft Corporation) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_23_0_0_162_pepper.exe Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Skróty ============================= (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ==================== Załadowane moduły (filtrowane) ============== 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-12-11 05:14 - 2015-10-13 19:26 - 00125616 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-10-08 20:44 - 2015-12-17 15:06 - 00022016 _____ () C:\WINDOWS\System32\ssp2ml6.dll 2015-08-09 20:54 - 2015-08-17 18:28 - 00076152 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2015-01-08 23:02 - 2015-01-08 23:02 - 00067808 _____ () C:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav 2016-09-14 17:58 - 2016-09-14 17:58 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-09-14 17:58 - 2016-09-14 17:58 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-08-23 17:44 - 2016-08-23 17:44 - 01864384 _____ () C:\Users\admin\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\ClientTelemetry.dll 2016-04-19 11:03 - 2016-04-19 11:04 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2015-12-17 23:48 - 2015-12-17 23:48 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-07-13 16:04 - 2016-07-13 16:04 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-09-14 17:52 - 2016-09-14 17:52 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-09-14 17:52 - 2016-09-14 17:52 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-09-14 17:52 - 2016-09-14 17:52 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-09-14 17:53 - 2016-09-14 17:53 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2015-10-08 20:45 - 2009-08-14 14:38 - 00614400 _____ () C:\Windows\Samsung\PanelMgr\SSMMgr.exe 2015-10-08 20:45 - 2008-01-10 15:39 - 00327168 _____ () C:\Windows\Samsung\PanelMgr\caller64.exe 2016-04-19 11:03 - 2016-04-19 11:04 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-04-19 11:03 - 2016-04-19 11:04 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2016-08-23 17:44 - 2016-08-23 17:44 - 01383616 _____ () C:\Users\admin\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\ClientTelemetry.dll 2016-08-23 17:44 - 2016-08-23 17:44 - 00118976 _____ () C:\Users\admin\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncViews.dll 2016-09-30 21:00 - 2016-09-09 02:53 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd 2016-09-30 20:59 - 2016-09-09 02:53 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd 2016-09-30 20:59 - 2016-09-09 02:54 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd 2016-09-30 21:00 - 2016-09-09 02:53 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll 2016-09-30 21:00 - 2016-09-09 02:53 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd 2016-09-30 21:00 - 2016-09-09 02:53 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd 2016-09-30 21:00 - 2016-09-30 19:44 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd 2016-09-30 21:00 - 2016-09-09 02:53 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd 2016-09-30 21:00 - 2016-09-09 02:54 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd 2016-09-30 21:00 - 2016-09-30 19:44 - 00021312 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd 2016-09-30 21:00 - 2016-09-09 02:53 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll 2016-09-30 20:59 - 2016-09-09 02:55 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd 2016-09-30 21:00 - 2016-09-30 19:44 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd 2016-09-30 21:00 - 2016-09-30 19:44 - 00025424 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 00246592 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd 2016-09-30 21:00 - 2016-09-09 02:54 - 00241104 _____ () C:\Program Files (x86)\Dropbox\Client\_jpegtran.pyd 2016-09-30 21:00 - 2016-09-30 19:44 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd 2016-09-30 21:00 - 2016-09-30 19:44 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd 2016-09-30 21:00 - 2016-09-30 19:44 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd 2016-09-30 21:00 - 2016-09-30 19:44 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd 2016-09-30 21:00 - 2016-09-30 19:44 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd 2016-09-30 20:59 - 2016-09-09 02:51 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll 2016-09-30 20:59 - 2016-09-30 19:43 - 00031568 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.pyd 2016-09-30 20:59 - 2016-09-30 19:38 - 00293392 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll 2016-09-30 20:59 - 2016-09-30 19:43 - 00084280 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL 2016-09-30 20:59 - 2016-09-30 19:43 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd 2016-09-30 21:00 - 2016-09-09 02:54 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd 2016-09-30 21:00 - 2016-09-30 19:44 - 03928880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 01972528 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd 2016-09-30 21:00 - 2016-09-30 19:43 - 00133424 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd 2016-09-30 21:00 - 2016-09-30 19:43 - 00224056 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd 2016-09-30 21:00 - 2016-09-30 19:44 - 00020288 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32._winffi_user32.pyd 2016-09-30 20:59 - 2016-09-09 02:58 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll 2016-09-30 20:59 - 2016-09-09 02:58 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll 2016-09-30 21:00 - 2016-09-30 19:44 - 00037192 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.pyd 2016-09-30 21:00 - 2016-09-09 02:55 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd 2016-09-30 21:00 - 2016-09-30 19:44 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd 2016-09-30 20:59 - 2016-09-30 19:43 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd 2016-09-30 21:00 - 2016-09-30 19:43 - 00042808 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd 2016-09-30 21:00 - 2016-09-30 19:43 - 00168760 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd 2016-10-03 21:39 - 2016-09-25 05:47 - 01805416 _____ () C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.143\libglesv2.dll 2016-10-03 21:39 - 2016-09-25 05:47 - 00093288 _____ () C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.143\libegl.dll 2016-09-15 11:08 - 2016-09-12 17:48 - 17754304 _____ () C:\Users\admin\AppData\Local\Google\Chrome\User Data\PepperFlash\23.0.0.166\pepflashplayer.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) AlternateDataStreams: C:\WINDOWS\explorer.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\HelpPane.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\aadcloudap.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\aadtb.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AboveLockAppHost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\accountaccessor.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AccountsRt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\acmigration.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ActionCenterCPL.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ActivationManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ActiveSyncProvider.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\actxprxy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\adhsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\adtschema.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\advapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\aeinv.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\aepic.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\aitstatic.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\APHostService.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AppCapture.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AppContracts.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\apphelp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ApplicationFrame.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AppointmentActivation.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AppointmentApis.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\appraiser.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AppReadiness.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\apprepapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\apprepsync.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\appwiz.cpl:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AppxAllUserStore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AppxApplicabilityEngine.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AppXDeploymentClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AppXDeploymentExtensions.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AppXDeploymentServer.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AppxPackaging.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AppxSip.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AppxSysprep.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\asycfilt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\atmfd.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\atmlib.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\audiodg.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AudioEndpointBuilder.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AudioEng.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AUDIOKSE.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AudioSes.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\audiosrv.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AuthBroker.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\authfwcfg.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AuthHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\authui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\autochk.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\azroles.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\azroleui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\AzureSettingSyncProvider.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\BackgroundTransferHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\basesrv.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\bcastdvr.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\BCP47Langs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\bcryptprimitives.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\BdeHdCfgLib.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\bdesvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\BFE.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\BingMaps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\bisrv.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\BitLockerDeviceEncryption.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\BluetoothApis.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\BootMenuUX.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\BrokerLib.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\browcli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\browser.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\browserbroker.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\BrowserSettingSync.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\bthserv.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ByteCodeGenerator.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\CallHistoryClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\cdd.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\cdpreference.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\cdpsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\CellularAPI.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\cemapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\certca.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\certcli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\CertEnroll.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\cfgbkend.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Chakra.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Chakradiag.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ChatApis.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\CheckNetIsolation.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\cic.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\Clipc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ClipSVC.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ClipUp.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\clusapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\cmintegrator.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\combase.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\comdlg32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\CompatTelRunner.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\comsvcs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\comuid.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\configurationclient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ContactApis.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\CoreMessaging.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\CoreUIComponents.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\CPFilters.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\CredProvDataModel.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\credprovhost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\credprovs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\crypt32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\cryptngc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\cryptsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\cryptui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\csrsrv.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d2d1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3d10.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3d10level9.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3d10warp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3d10_1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3d11.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3D12.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3d9.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DCompiler_33.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DCompiler_34.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DCompiler_35.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DCompiler_36.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DCompiler_37.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DCompiler_38.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DCompiler_39.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DCompiler_40.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DCompiler_41.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DCompiler_42.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DCompiler_43.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DCompiler_47.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dcsx_42.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\d3dcsx_43.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx10.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx10_33.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx10_34.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx10_35.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx10_36.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx10_37.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx10_38.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx10_39.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx10_40.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx10_41.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx10_42.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx10_43.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx11_42.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx11_43.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx9_24.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx9_25.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx9_26.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx9_27.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx9_28.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\d3dx9_29.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx9_30.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx9_31.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx9_32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx9_33.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx9_34.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx9_35.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\d3dx9_36.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DX9_37.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DX9_38.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DX9_39.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DX9_40.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DX9_41.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DX9_42.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\D3DX9_43.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dafBth.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dafWCN.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DAFWSD.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\das.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DataSenseHandlers.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dbgeng.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dbghelp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DbgModel.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DbxSvc.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dcomp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DDDS.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\defragsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\deviceaccess.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\deviceassociation.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DeviceCensus.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DeviceEnroller.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DevicePairing.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\devinv.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dhcpcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dhcpcore6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dhcpcsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dhcpcsvc6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DiagCpl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\diagperf.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\diagtrack.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\diagtrack_win.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dialserver.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DictationManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\directmanipulation.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Display.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DisplayManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dlnashext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dmcertinst.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dmcsps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dmdskmgr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dmenrollengine.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\dmenterprisediagnostics.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DMRServer.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dnsapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dnsrslvr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\domgmt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dosvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dot3ui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\drvstore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DscCore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dssvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dui70.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\duser.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dwmcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dwminit.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\DWrite.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dxgi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\dxtrans.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\eapp3hst.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\eappcfg.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\eappgnui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\eapphost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\eappprxy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\eapsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\easinvoker.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\easwrt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\edgehtml.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\EditionUpgradeManagerObj.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\edputil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\efswrt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\EmailApis.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\enrollmentapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\enterprisecsps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\esent.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\evr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ExecModelClient.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\ExplorerFrame.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ExSMime.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ExtrasXmlParser.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\facecredentialprovider.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fdProxy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fdWCN.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fhcfg.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fhengine.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fhsettingsprovider.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fhsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\filemgmt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\FilterDS.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\FingerprintEnrollment.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\FirewallAPI.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\flvprophandler.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\FntCache.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fontdrvhost.exe:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\FontProvider.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fontsub.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fveapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fveapibase.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fvecpl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fveskybackup.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fveui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fvewiz.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fwbase.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fwcfg.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\fwpolicyiomgr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\FWPUCLNT.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\FwRemoteSvr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\GamePanel.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\gameux.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\gdi32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\GdiPlus.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\generaltel.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Geolocation.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\GlobCollationHost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\GnssAdapter.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\gpapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\gpedit.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\gpsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\hal.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\hevcdecoder.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\hgcpl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\hlink.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\hmkd.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\hnetcfg.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\httpprxm.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\httpprxp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\iassam.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\IconCodecService.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\icsvc.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\IdCtrls.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ie4uinit.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ieapfltr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\iedkcs32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ieframe.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ieproxy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\iertutil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ieui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\IKEEXT.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ImplatSetup.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\inetcpl.cpl:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\inetpp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\InputLocaleManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\InputService.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\InstallAgent.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\internetmail.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\invagent.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\iphlpsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ipnathlp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ipsecsnp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\IPSECSVC.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\irmon.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\iuilp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\javaws.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\JpMapControl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\jscript.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\jscript9.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\jsproxy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\kerberos.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\kernel32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\KernelBase.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\KnobsCore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ksproxy.ax:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\LaunchWinApp.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\LegacyNetUX.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\LegacyNetUXHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\LicenseManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\LicenseManagerShellext.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\licensingdiag.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ListSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\localspl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\LocationFramework.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\LockAppBroker.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\LockAppHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\LogonController.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\LsaIso.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\lsasrv.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\lsass.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MapConfiguration.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\MapControlCore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MapsBtSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MapsCSP.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MapsStore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mapsupdatetask.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MbaeApiPublic.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MBMediaManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mbsmsapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mcbuilder.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MCRecvSrc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MDEServer.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MDMAppInstaller.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mdmmigrator.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\mdmregistration.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MessagingDataModel2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mf.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mfasfsrcsnk.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MFCaptureEngine.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mfcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mfds.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MFMediaEngine.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mfmkvsrcsnk.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mfmp4srcsnk.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mfmpeg2srcsnk.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mfnetcore.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\mfnetsrc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mfplat.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MFPlay.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mfpmp.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mfps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mfreadwrite.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mfsrcsnk.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mfsvr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mftranscode.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\microsoft-windows-system-events.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MicrosoftAccountCloudAP.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MicrosoftAccountExtension.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MiracastReceiver.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mispace.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mmc.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mmcbase.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mmcndmgr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mmcshext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\modernexecserver.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mos.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\moshost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MosHostClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\moshostcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MosStorage.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MP3DMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mprddm.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mprdim.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MPSSVC.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mqsnap.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MrmCoreR.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MrmIndexer.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MRT.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MSAJApi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mscms.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msctf.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msctfuimanager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msdt.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msdtctm.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msfeeds.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MSFlacDecoder.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msftedit.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mshtml.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mshtmled.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msieftp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MSMPEG2ENC.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msobjs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mspaint.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msscntrs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MsSpellCheckingFacility.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mssph.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mssphtb.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mssprxy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mssrch.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\mstsc.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mstscax.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msv1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msvproc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mswsock.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msxml3.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\msxml6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MTF.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MTFServer.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\mtxoci.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\musdialoghandlers.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MusNotification.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MusNotificationUx.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\MusUpdateHandlers.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ncbservice.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ncryptsslp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\netapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\netcenter.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\netcfgx.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\netlogon.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\netman.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\netplwiz.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NetSetupApi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NetSetupEngine.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NetSetupShim.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NetSetupSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\netshell.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\nettrace.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NetworkDesktopSettings.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NetworkMobileSettings.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NetworkUXBroker.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\newdev.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NFCProvisioningPlugin.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ngccredprov.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NgcCtnr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NgcCtnrSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ngckeyenum.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ngcpopkeysrv.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ngcsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NMAA.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NotificationController.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\NotificationObjFactory.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\nshwfp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ntdll.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ntoskrnl.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ntprint.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ntshrui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\odbcconf.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\oemlicense.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\offlinelsa.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ole32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\oleacc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\oleacchooks.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\oleaut32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\omadmapi.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\omadmclient.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\OnDemandConnRouteHelper.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\OneBackupHandler.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\OpcServices.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\OpenWith.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PackageStateRoaming.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\pcasvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\pcaui.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\phoneactivate.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PhoneCallHistoryApis.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PhoneOm.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PhoneProviders.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PhoneService.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PhotoScreensaver.scr:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PimIndexMaintenance.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PimIndexMaintenanceClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Pimstore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\pla.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PlayToDevice.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PlayToManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PlayToReceiver.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\pngfilt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\pnidui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\policymanager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\policymanagerprecheck.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\polstore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\POSyncServices.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PrintDialogs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PrintDialogs3D.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\printfilterpipelinesvc.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\prnntfy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\profext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\profsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\propsys.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\provdatastore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\provengine.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\provhandlers.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\provisioningcsp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\provops.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\provpackageapidll.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ProvPluginEng.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\provtool.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ProximityCommon.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\PsmServiceExtHost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\psmsrv.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\qdvd.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\qedit.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\qmgr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\quartz.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\QuickActionsDataModel.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\RADCUI.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rasadhlp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rasapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rasauto.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rasautou.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rasdlg.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rasgcw.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rastls.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rastlsext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rdpcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rdpcorets.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rdpudd.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\RDXService.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\RDXTaskFactory.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\RecoveryDrive.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\RemoteNaturalLanguage.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\reseteng.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\resutils.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\RMSRoamingSecurity.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rpcrt4.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rpcss.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\rsaenh.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\samlib.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\samsrv.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\sbe.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\scapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\schannel.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\schedsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\schtasks.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sdengin2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sdrsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sdshext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SearchFilterHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SearchFolder.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SearchIndexer.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SearchProtocolHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SecConfig.efi:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\seclogon.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SecureTimeAggregator.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SensorDataService.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SensorsApi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SensorService.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SensorsNativeApi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SensorsNativeApi.V2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\services.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SettingMonitor.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_Geolocation.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_Maps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_nt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_Privacy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SettingSync.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SettingSyncCore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SettingSyncHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\setupapi.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\shacct.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SharedStartModel.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\SharedStartModelShim.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ShareHost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sharemediacpl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SHCore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\shell32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\shsetup.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\shutdownux.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SimAuth.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SimCfg.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SmartcardCredentialProvider.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SmartCardSimulator.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SMSRouter.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SmsRouterSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\spcompat.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SpeechPal.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\spoolsv.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sppcext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sppinst.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sppobjs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sppsvc.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sppwinob.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sqmapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\srcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SRH.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SRHInproc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\srpapi.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\srvcli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sscoreext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ssp2mci.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ssp2mci.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ssp2ml6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sspicli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sti.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\StikyNot.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\StorageUsage.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\storagewmi.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\StoreAgent.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\storewuauth.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\StorSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\StructuredQuery.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SubscriptionMgr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sud.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\swprv.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SyncCenter.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SyncController.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SyncSettings.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\syncutil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\sysdm.cpl:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\SystemEventsBrokerServer.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\systemreset.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SystemSettings.Handlers.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SystemSettingsAdminFlows.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\taskcomp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\taskeng.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Taskmgr.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\taskschd.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\tbauth.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\tdh.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\tdlrecover.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\termsrv.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\tetheringservice.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\TextInputFramework.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\themecpl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\themeui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\thumbcache.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\tileobjserver.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\TimeBrokerClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\TimeBrokerServer.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\TokenBroker.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\TokenBrokerCookies.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\TpmTasks.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\tquery.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\TSWorkspace.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\twinapi.appcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\twinapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\twinui.appcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\twinui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\tzautoupdate.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\udhisapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\uDWM.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\UIAutomationCore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\UIRibbon.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\UIRibbonRes.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\unimdm.tsp:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Unistore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\updatehandlers.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\updatepolicy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\upnpcont.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\upnphost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\uReFS.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\urlmon.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\usbmon.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\user32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\usercpl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\UserDataAccountApis.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\UserDataLanguageUtil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\UserDataService.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\UserDataTimeUtil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\UserDataTypeHelperUtil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\UserLanguagesCpl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\usermgr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\usermgrcli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\UserMgrProxy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\usocore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\vaultcli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\vaultsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\vbscript.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\VCardParser.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\vds.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\vdsutil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\VEDataLayerHelpers.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\VEEventDispatcher.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\VEStoreEventHandlers.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\VoipRT.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\vpnike.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\vssapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\vsstrace.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\VSSVC.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\vss_ps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\w32time.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WalletService.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wbemcomn.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wbengine.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wbiosrvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wcmcsp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wcmsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WcnApi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wcncsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wcnwiz.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wdc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WdfCoInstaller01009.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WebcamUi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\webcheck.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\webio.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\webservices.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wer.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\werconcpl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wermgr.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\werui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wevtsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wevtutil.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wfapigp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wfdprov.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wiaaut.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wiarpc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wiaservc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WiFiConfigSP.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wificonnapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WiFiDisplay.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wifinetworkmanager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wifiprofilessettinghandler.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wifitask.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wimserv.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\win32kbase.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\win32kfull.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\win32spl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winbio.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.AccountsControl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Cortana.Desktop.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Cortana.OneCore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Cortana.ProxyStub.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\Windows.Data.Pdf.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.LowLevel.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Midi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Picker.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.PointOfService.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Scanners.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Sensors.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.SmartCards.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Globalization.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Graphics.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\Windows.Graphics.Printing.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Internal.Management.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Audio.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Devices.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Editing.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.MediaControl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Speech.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Streaming.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.Connectivity.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.Vpn.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Speech.Pal.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.StateRepository.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.StateRepositoryClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\windows.storage.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Storage.Search.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.BioFeedback.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Cred.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Immersive.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Input.Inking.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Logon.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.PicturePassword.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Search.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Shell.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Xaml.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Web.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Windows.Web.Http.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WindowsCodecs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WindowsCodecsExt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WindowsCodecsRaw.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winhttp.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\winhttpcom.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wininet.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wininetlui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wininit.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winipcfile.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winipcsecproc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winipcsecproc_ssp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winload.efi:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winload.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winlogon.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winmde.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winmsipc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winresume.efi:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winresume.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winspool.drv:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\winsrv.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WinTypes.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WinUSBCoInstaller.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WinUSBCoInstaller2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wkscli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wlanapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WLanConn.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WlanMediaManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WlanMM.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\wlanmsm.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wlansec.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wlansvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wlansvcpal.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wlanui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wldp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wlidcli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wlidprov.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wlidsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WMADMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WMALFXGFXDSP.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wmdrmdev.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wmdrmsdk.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wmicmiplugin.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wmp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WMPDMC.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WmpDui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wmpeffects.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WMPhoto.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wmploc.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wmpmde.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wmpps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WMSPDMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WMSPDMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\workfolderssvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Wpc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WpcMon.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WpcWebFilter.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WpcWebSync.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wpdbusenum.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wpdshext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WPDShServiceObj.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wpnapps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wpncore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wpninprc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ws2_32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wscapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WSClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wscsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WSDApi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wsdchngr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wshbth.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wshom.ocx:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\WsmAgent.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WsmAuto.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wsmprovhost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WsmSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WsmWmiPl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wsp_fs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wsp_health.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wsqmcons.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WSService.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WSShared.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WSSync.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wuapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wuauclt.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wuaueng.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wuautoappupdate.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WUDFPlatform.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WUDFx.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wups.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wusa.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wuuhext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WWAHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\WWanAPI.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wwanconn.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wwanmm.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\wwansvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\x3daudio1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\x3daudio1_1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\X3DAudio1_2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\X3DAudio1_3.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\X3DAudio1_4.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\X3DAudio1_5.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\X3DAudio1_6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\X3DAudio1_7.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine2_0.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine2_1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine2_10.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine2_2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine2_3.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine2_4.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine2_5.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine2_6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine2_7.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine2_8.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\xactengine2_9.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine3_0.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine3_1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine3_2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine3_3.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine3_4.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine3_5.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine3_6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xactengine3_7.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XAPOFX1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XAPOFX1_1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XAPOFX1_2.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\XAPOFX1_3.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XAPOFX1_4.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XAPOFX1_5.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XAudio2_0.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XAudio2_1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XAudio2_2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XAudio2_3.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\XAudio2_4.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XAudio2_5.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XAudio2_6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XAudio2_7.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XblAuthManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XblGameSave.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\XboxNetApiSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xinput1_1.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\xinput1_2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xinput1_3.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XpsDocumentTargetPrint.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XpsFilt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\XpsPrint.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xpsrchvw.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\xpsservices.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\zipfldr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\ztrace_maps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AboveLockAppHost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AccountsRt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ActionCenterCPL.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\actxprxy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\adtschema.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\advapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AppCapture.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AppContracts.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\apphelp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AppLockerCSP.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AppointmentActivation.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AppointmentApis.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\apprepapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\apprepsync.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\appwiz.cpl:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AppxAllUserStore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AppxPackaging.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AppxSip.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\asycfilt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\atmfd.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\atmlib.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AUDIOKSE.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AudioSes.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\authfwcfg.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\authui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\azroles.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\azroleui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\bcastdvr.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\BCP47Langs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\bcryptprimitives.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\BingMaps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\BluetoothApis.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\browcli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\BrowserSettingSync.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ByteCodeGenerator.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\CallHistoryClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\cemapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\certca.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\certcli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\CertEnroll.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\certmgr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\cfgbkend.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Chakra.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ChatApis.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\CheckNetIsolation.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\cic.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Clipc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\clusapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\combase.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\comdlg32.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\comsvcs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\comuid.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ContactApis.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\CoreMessaging.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\CoreUIComponents.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\CPFilters.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\CredProvDataModel.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\credprovhost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\credprovs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\crypt32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\cryptngc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\cryptui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d2d1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d10level9.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d10warp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d11.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3D12.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d9.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DCompiler_33.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DCompiler_34.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DCompiler_35.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DCompiler_36.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DCompiler_37.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DCompiler_38.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DCompiler_39.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DCompiler_40.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DCompiler_41.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DCompiler_42.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DCompiler_43.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DCompiler_47.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dcsx_42.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dcsx_43.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx10.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx10_33.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx10_34.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx10_35.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx10_36.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx10_37.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx10_38.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx10_39.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx10_40.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx10_41.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx10_42.dll:$CmdTcID [32] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx10_43.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx11_42.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx11_43.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_24.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_25.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_26.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_27.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_28.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_29.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_30.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_31.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_33.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_34.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_35.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_36.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DX9_37.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DX9_38.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DX9_39.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DX9_40.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DX9_41.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DX9_42.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DX9_43.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\dbgeng.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\DbgModel.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\dcomp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\deviceaccess.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\deviceassociation.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\DevicePairing.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\dhcpcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\dhcpcore6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\dhcpcsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\dhcpcsvc6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\DictationManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\directmanipulation.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Display.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\DisplayManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\dlnashext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\dmdskmgr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\dnsapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\dot3ui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\dui70.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\duser.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\dwmcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\DWrite.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\dxgi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\dxtrans.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\eapp3hst.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\eappcfg.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\eappgnui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\eapphost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\eappprxy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\easwrt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\edgehtml.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\edputil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\efswrt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\EmailApis.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\esent.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\evr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ExecModelClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\explorer.exe:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\ExplorerFrame.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ExSMime.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\fdWCN.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\filemgmt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\FirewallAPI.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\FlashPlayerApp.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\fontdrvhost.exe:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\fontsub.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\fwbase.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\fwcfg.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\FWPUCLNT.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\FwRemoteSvr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\GamePanel.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\gameux.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\gdi32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\GdiPlus.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Geolocation.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\GlobCollationHost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\gpedit.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\hevcdecoder.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\hgcpl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\hlink.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\hmkd.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\hnetcfg.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\iassam.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\IconCodecService.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\IdCtrls.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ieapfltr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\iedkcs32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ieframe.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ieproxy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\iertutil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ieui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\inetcpl.cpl:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\InputLocaleManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\InputService.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\InstallAgent.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\JpMapControl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\jscript.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\jscript9.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\jsproxy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\kerberos.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\kernel32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\KernelBase.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ksproxy.ax:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\LaunchWinApp.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\LicenseManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\licensingdiag.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\LocationFramework.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\LockAppBroker.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\LockAppHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\LogonController.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MapConfiguration.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MapControlCore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MapsBtSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MbaeApiPublic.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mbsmsapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MCRecvSrc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mdmregistration.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MessagingDataModel2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mf.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MFCaptureEngine.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfds.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MFMediaEngine.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfnetcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfnetsrc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfplat.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\MFPlay.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfpmp.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfreadwrite.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfsrcsnk.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mfsvr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mftranscode.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MiracastReceiver.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mispace.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mmc.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mmcbase.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mmcndmgr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mmcshext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mos.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MosHostClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MosStorage.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MP3DMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mprddm.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mprdim.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MrmCoreR.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MrmIndexer.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MSAJApi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mscms.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\msctf.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\msctfuimanager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\msfeeds.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MSFlacDecoder.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\msftedit.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mshtml.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\msi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\msieftp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\msobjs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\msorcl32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mspaint.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\msscntrs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mssph.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mssphtb.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mssrch.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mstsc.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mstscax.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\msv1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\msvproc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mswsock.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\msxml3.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\msxml6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\MTF.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\mtxoci.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ncryptsslp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\netapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\netcenter.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\netcfgx.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\netlogon.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\netplwiz.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\NetSetupApi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\NetSetupEngine.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\NetSetupShim.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\netshell.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\newdev.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\NMAA.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\notepad.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\NotificationObjFactory.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\nshwfp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ntdll.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ntprint.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ntshrui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\odbcconf.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\oemlicense.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\offlinelsa.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ole32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\oleacc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\oleacchooks.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\oleaut32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\olepro32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\OpcServices.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\OpenWith.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\PackageStateRoaming.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\pbsvc_bc2.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\pcaui.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\PhoneOm.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\PhotoScreensaver.scr:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Pimstore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\pla.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\PlayToManager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\PlayToReceiver.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\PnkBstrA.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\PnkBstrB.ex0:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\policymanager.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\polstore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\POSyncServices.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\PrintConfig.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\PrintDialogs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\prnntfy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\profext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\propsys.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ProximityCommon.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\qdvd.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\qedit.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\quartz.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\rasadhlp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\rasapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\rasautou.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\rasdlg.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\rasgcw.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\rastls.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\rastlsext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\rdpcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\resutils.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\rpcrt4.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\rsaenh.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\samlib.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\sbe.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\schannel.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\schtasks.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SearchFolder.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SearchIndexer.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SearchProtocolHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SensorsApi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SensorsNativeApi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\SettingMonitor.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SettingSync.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SettingSyncCore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SettingSyncHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\setupapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\shacct.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ShareHost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SHCore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\shell32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\shsetup.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SimAuth.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SimCfg.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\sqmapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SRH.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SRHInproc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\srpapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\srvcli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\sspicli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\sti.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\storagewmi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\StoreAgent.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\StructuredQuery.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\sud.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SyncCenter.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\SyncController.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\SyncSettings.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\syncutil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\sysdm.cpl:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\taskcomp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\taskeng.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Taskmgr.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\taskschd.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\tbauth.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\tdh.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\tdlrecover.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\TextInputFramework.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\themecpl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\themeui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\thumbcache.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\TimeBrokerClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\TokenBroker.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\tquery.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\twinapi.appcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\twinapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\twinui.appcore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\twinui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\udhisapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\UIAutomationCore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\UIRibbon.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\UIRibbonRes.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\unimdm.tsp:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Unistore.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\updatepolicy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\upnpcont.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\upnphost.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\uReFS.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\urlmon.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\usbceip.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\user32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\usercpl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\UserDataAccountApis.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\usermgrcli.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\UserMgrProxy.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\vbscript.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\VCardParser.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\VEEventDispatcher.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\VoipRT.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\vssapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\vsstrace.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wbemcomn.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WcnApi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wcnwiz.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wdc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WebcamUi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\webcheck.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\webio.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\webservices.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wer.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wermgr.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\werui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wevtutil.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wfapigp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wfdprov.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wiaaut.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WiFiDisplay.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\winbio.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Wallet.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Cortana.ProxyStub.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Globalization.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Graphics.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Streaming.ps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Networking.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.StateRepository.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\windows.storage.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Search.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Web.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Web.Http.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WindowsCodecs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WindowsCodecsExt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WindowsCodecsRaw.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\winhttp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\winhttpcom.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wininet.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wininetlui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\winipcfile.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\winipcsecproc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\winipcsecproc_ssp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\winmde.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\winmsipc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\winspool.drv:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WinTypes.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WISPTIS.EXE:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wkscli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wlanapi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WLanConn.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WlanMM.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wlanmsm.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wlansec.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wlanui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wldp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wlidcli.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wlidprov.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WMADMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wmdrmdev.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wmdrmsdk.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wmp.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WMPDMC.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WmpDui.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wmpeffects.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WMPhoto.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wmploc.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WMSPDMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WMSPDMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\Wpc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WpcWebFilter.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wpdshext.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WPDShServiceObj.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wpnapps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ws2_32.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WSClient.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WSDApi.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wsdchngr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wshbth.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wshom.ocx:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WsmAgent.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WsmAuto.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wsmprovhost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WsmSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WsmWmiPl.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wsp_fs.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wsp_health.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WSShared.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WSSync.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\wuapi.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\wups.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WWAHost.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\WWanAPI.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\x3daudio1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\x3daudio1_1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\X3DAudio1_2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\X3DAudio1_3.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\X3DAudio1_4.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\X3DAudio1_5.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\X3DAudio1_6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\X3DAudio1_7.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine2_0.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine2_1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine2_10.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine2_2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine2_3.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine2_4.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine2_5.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine2_6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine2_7.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine2_8.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine2_9.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine3_0.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine3_1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine3_2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine3_3.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine3_4.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine3_5.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine3_6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xactengine3_7.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAPOFX1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAPOFX1_1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAPOFX1_2.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAPOFX1_3.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAPOFX1_4.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAPOFX1_5.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAudio2_0.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAudio2_1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAudio2_2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAudio2_3.dll:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAudio2_4.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAudio2_5.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAudio2_6.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XAudio2_7.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xinput1_1.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xinput1_2.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xinput1_3.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XpsFilt.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\XpsPrint.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xpsrchvw.exe:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\xpsservices.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\zipfldr.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\SysWOW64\ztrace_maps.dll:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\acpi.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\ahcache.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\appid.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\athw10x.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\bridge.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\bthenum.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\bthpan.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\bthport.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\BTHUSB.SYS:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\ClipSp.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\cng.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\dbx-canary.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\dbx-dev.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\dbx-stable.sys:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\Drivers\dfsc.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\dtlitescsibus.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\dumpsd.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\dumpsdport.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\dxgkrnl.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\dxgmms1.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\dxgmms2.sys:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\Drivers\fastfat.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\filecrypt.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\fvevol.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\hidclass.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\http.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\ksecdd.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\ksecpkg.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\lgandnetdiag64.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\lgandnetmodem64.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxdav.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxsmb.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxsmb10.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxsmb20.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\MTConfig.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\ndis.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\Ndu.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\netbt.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\ntfs.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\nwifi.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\partmgr.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\pci.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\pdc.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\portcls.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\rasl2tp.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\rdbss.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\rfcomm.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\sdbus.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\sdport.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\serial.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\srv.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\srv2.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\srvnet.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\ssudbus.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\ssudmdm.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\storport.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\tcpip.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\tpm.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\TVALZ_O.SYS:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\UcmCx.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\ufx01000.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\ufxsynopsys.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\USBHUB3.SYS:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\usbser.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\USBSTOR.SYS:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\USBXHCI.SYS:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\VBoxDrv.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\VBoxNetAdp6.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\VBoxNetLwf.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\VBoxUSB.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\VBoxUSBMon.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\WdiWiFi.sys:$CmdTcID [130] AlternateDataStreams: C:\WINDOWS\system32\Drivers\xboxgip.sys:$CmdTcID [64] AlternateDataStreams: C:\WINDOWS\system32\Drivers\xinputhid.sys:$CmdTcID [64] AlternateDataStreams: C:\Users\admin\Desktop\14068141_1119947088076842_5970015630780291789_n.jpg:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Desktop\Endomondo Running Cycling Walk v11.0.2_iPmart-Forum.pl_by_Nocna_Furia.apk:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Desktop\eWeather HD, Radar HD, Alerts v5.8.5.apk:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Desktop\student_wniosek_osw_dochody (2).pdf:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Desktop\zal_19_oswiadczenie_czlonka_rodziny_o_dochodzie_niepodlegajacym_opodatkowaniu.pdf:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\Ale wkoło jest wesoło.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\Alle Farben feat. Younotus - Please Tell Rosie.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\Callan Method Stage 5 & 6.rar:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\If I were sorry - Frans WITH LYRICS.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\kombi-pokolenie.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\Kombii - Awinion.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\LP – Lost On You [Official Music Video].mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\Lukas Graham - Mama Said.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\Natalia Nykiel - Error.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\oświadczenie_o_dochodach_2016-09-16.pdf:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\perfect - każdy oddech twój.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\Perfect - Kołysanka dla nieznajomej [ nie karaoke] słowa, tekst.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\perfect - nie moge ci wiele dac.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\Perfect - Niepokonani.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\Perfect - Wszystko ma swój czas.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\perfekt - chciałbym być sobą.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\Perfekt - Nie Płacz Ewka.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\Sofia Carson-Love is the name.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\SPTD2inst-v211-x64.exe:$CmdTcID [64] AlternateDataStreams: C:\Users\admin\Downloads\SPTD2inst-v211-x64.exe:$CmdZnID [29] AlternateDataStreams: C:\Users\admin\Downloads\Stachursky - Typ Niepokorny.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\Sylwia Grzeszczak Tamta dziewczyna.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\admin\Downloads\wniosek_o_stypendium_socjalne_2016-09-16.pdf:$CmdZnID [26] ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) ==================== Powiązania plików (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Hosts - zawartość: =============================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2015-07-10 13:04 - 2015-10-08 21:33 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-63831111-2181059775-4247894396-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg HKU\S-1-5-21-63831111-2181059775-4247894396-1002\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Zapora systemu Windows [funkcja wyłączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == HKU\S-1-5-21-63831111-2181059775-4247894396-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount" HKU\S-1-5-21-63831111-2181059775-4247894396-1001\...\StartupApproved\Run: => "Steam" ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{6C96A993-4C3A-4ADE-992D-5DB0748D9B61}] => (Allow) E:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe FirewallRules: [{600C0B1F-542A-4C3C-BFB1-4C09925CB8C4}] => (Allow) E:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe FirewallRules: [{FBCFF0BF-4FAC-42AF-9FF3-912824215A45}] => (Allow) E:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe FirewallRules: [{08E4958C-0DA3-4859-9354-C1446DB75028}] => (Allow) E:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe FirewallRules: [{66440964-6C0D-4DE8-BABE-8F4AACB64720}] => (Allow) E:\Metro 2033\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{9527EA1E-E019-4D6A-90C0-9D63F3F540A2}] => (Allow) E:\Metro 2033\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{74D9DFBA-9F5F-4978-B901-BB6389CA0FF0}] => (Allow) E:\Metro 2033\steamapps\common\Metro 2033\metro2033.exe FirewallRules: [{3FBE74BA-142A-48CD-92B4-DACA3788EACA}] => (Allow) E:\Metro 2033\steamapps\common\Metro 2033\metro2033.exe FirewallRules: [{18D4A186-433A-4960-B15C-6DFE92B26812}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{E42AF927-CA65-40F8-A88A-1A8877C9D97F}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{1F10EA5A-4D49-4F8E-B24C-1CB898351E96}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{4386541F-F20F-4EFF-95DB-670FC6BDFE0B}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{0C8C842A-9816-4199-9BF7-8007CCBCC93D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{383236CC-7495-4CB8-AA5C-86EF0FCA1EDF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [UDP Query User{2A5C93E1-8923-4DF1-801E-39AEBBAE737C}E:\battlefield bad company 2\bfbc2game.exe] => (Allow) E:\battlefield bad company 2\bfbc2game.exe FirewallRules: [TCP Query User{3AE6F72E-2D9F-4E06-BE8F-A674C01AFBBE}E:\battlefield bad company 2\bfbc2game.exe] => (Allow) E:\battlefield bad company 2\bfbc2game.exe FirewallRules: [{57B7CEE6-F178-4896-9D21-8C19C58BEF98}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{83B87919-2D2A-4B98-B58F-4B52CD31DF43}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{06EE6088-DDCC-4AFF-B38A-CB207439D2B7}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{6A69BB70-4744-4574-B0C0-B17098735EEA}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{1B2BDC1B-38D4-4DC3-8AEA-74F9EAEA026F}] => (Allow) E:\Battlefield Bad Company 2\BFBC2Updater.exe FirewallRules: [{6CE3FD10-5FD4-4A56-B940-657EBD432E8D}] => (Allow) E:\Battlefield Bad Company 2\BFBC2Updater.exe FirewallRules: [{2250D234-6138-427B-BE9E-6AA56E2E9159}] => (Allow) E:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe FirewallRules: [{9E1E9063-C2DB-4B16-8827-0924FDC8029C}] => (Allow) E:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe FirewallRules: [{10151188-FD5D-4961-8066-3547AF59737C}] => (Allow) E:\Steam Games\steamapps\common\Team Fortress 2\hl2.exe FirewallRules: [{9B8B3617-3DA4-42F9-A01D-F1E6FBA53FDD}] => (Allow) E:\Steam Games\steamapps\common\Team Fortress 2\hl2.exe FirewallRules: [{9DD06669-291B-4277-8D40-F9CFAE03B764}] => (Allow) E:\Program Files (x86)\Origin Games\Dead Space 3\deadspace3.exe FirewallRules: [{88E22605-A096-4A94-A87F-671B34748683}] => (Allow) E:\Program Files (x86)\Origin Games\Dead Space 3\deadspace3.exe FirewallRules: [{E11B0F38-774A-447C-9F32-6B1A5D17A649}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [{95F68745-7638-4CC9-999A-2C488E3F7785}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Punkty Przywracania systemu ========================= UWAGA: Przywracanie systemu jest wyłączone ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (10/05/2016 10:22:44 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5R1KO60) Description: Aktywacja aplikacji Microsoft.Windows.Photos_8wekyb3d8bbwe!App nie powiodła się. Błąd: -2147023170. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (10/04/2016 08:03:57 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5R1KO60) Description: Aktywacja aplikacji Microsoft.Windows.Photos_8wekyb3d8bbwe!App nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (10/04/2016 08:53:55 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5R1KO60) Description: Aktywacja aplikacji Microsoft.Windows.Photos_8wekyb3d8bbwe!App nie powiodła się. Błąd: -2147023170. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (10/03/2016 04:04:43 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5R1KO60) Description: Aktywacja aplikacji Microsoft.Windows.Photos_8wekyb3d8bbwe!App nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (10/03/2016 09:35:33 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5R1KO60) Description: Aktywacja aplikacji Microsoft.Windows.Photos_8wekyb3d8bbwe!App nie powiodła się. Błąd: -2147023170. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (10/02/2016 10:01:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5R1KO60) Description: Aktywacja aplikacji Microsoft.Windows.Photos_8wekyb3d8bbwe!App nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (10/01/2016 01:02:37 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5R1KO60) Description: Aktywacja aplikacji Microsoft.Messaging_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 nie powiodła się. Błąd: -2147417848. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (10/01/2016 01:02:37 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5R1KO60) Description: Aktywacja aplikacji Microsoft.Messaging_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 nie powiodła się. Błąd: -2147417848. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (10/01/2016 01:02:37 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5R1KO60) Description: Aktywacja aplikacji Microsoft.Messaging_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 nie powiodła się. Błąd: -2147417848. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (10/01/2016 01:02:37 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5R1KO60) Description: Aktywacja aplikacji Microsoft.Messaging_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 nie powiodła się. Błąd: -2147417848. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Dziennik System: ============= Error: (10/05/2016 10:39:56 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Usługa Menedżer pobranych map zawiesiła się podczas uruchamiania. Error: (10/05/2016 10:33:08 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Origin Web Helper Service z powodu następującego błędu: Usługa nie odpowiada na sygnał uruchomienia lub sygnał sterujący w oczekiwanym czasie. Error: (10/05/2016 10:33:08 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Origin Web Helper Service. Error: (10/05/2016 10:32:35 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi SSPORT z powodu następującego błędu: Nie można odnaleźć określonego pliku. Error: (10/05/2016 10:30:33 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Synchronizuj hosta_4b955. Error: (10/05/2016 10:30:33 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Magazyn danych użytkownika_4b955. Error: (10/05/2016 10:30:33 AM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Menedżer sterowania usługami próbował podjąć akcję korekcyjną (Uruchom usługę ponownie) po nieoczekiwanym zakończeniu usługi Magazyn danych użytkownika_4b955, ale ta akcja nie powiodła się przy następującym błędzie: Jedno wystąpienie usługi już działa. . Error: (10/05/2016 10:30:28 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5R1KO60) Description: Serwer {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (10/05/2016 10:30:28 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5R1KO60) Description: Serwer {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (10/05/2016 10:30:28 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5R1KO60) Description: Serwer {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} nie zarejestrował się w modelu DCOM w wymaganym czasie. CodeIntegrity: =================================== Date: 2016-10-05 12:46:12.163 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-05 12:20:05.529 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-05 11:34:04.060 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-05 11:08:30.319 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-05 10:53:45.103 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2016-10-05 10:36:41.695 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2016-09-25 19:20:50.138 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2016-09-25 17:04:51.840 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2016-09-25 17:02:08.477 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2016-09-23 17:37:35.988 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. ==================== Statystyki pamięci =========================== Procesor: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz Procent pamięci w użyciu: 60% Całkowita pamięć fizyczna: 4060.86 MB Dostępna pamięć fizyczna: 1585.36 MB Całkowita pamięć wirtualna: 9692.86 MB Dostępna pamięć wirtualna: 6257.75 MB ==================== Dyski ================================ Drive c: (WINDOWS) (Fixed) (Total:99.86 GB) (Free:35.09 GB) NTFS Drive d: (Multimedia) (Fixed) (Total:49.55 GB) (Free:35.04 GB) NTFS Drive e: (Data) (Fixed) (Total:148.28 GB) (Free:53.11 GB) NTFS ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 2FC3BAF2) Partition 1: (Active) - (Size=400 MB) - (Type=27) Partition 2: (Not Active) - (Size=99.9 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=49.6 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=148.3 GB) - (Type=07 NTFS) ==================== Koniec Addition.txt ============================