Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja:09-06-2016 Uruchomiony przez Kuba (2016-06-09 00:53:42) Uruchomiony z D:\Kuba\Desktop Windows 8.1 Pro (Update) (X64) (2016-06-01 02:56:51) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-2715714705-1761166565-38147098-500 - Administrator - Enabled) => C:\Users\Administrator Gość (S-1-5-21-2715714705-1761166565-38147098-501 - Limited - Disabled) Kuba (S-1-5-21-2715714705-1761166565-38147098-1001 - Administrator - Enabled) => C:\Users\Kuba ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: COMODO Antivirus (Enabled - Up to date) {D0CC7563-ABD2-DEBE-138E-FDD553335AF2} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Comodo Defense+ (Enabled - Up to date) {6BAD9487-8DE8-D130-293E-C6A728B4104F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: COMODO Firewall (Enabled) {E8F7F446-E1BD-DFE6-38D1-54E0ADE01D89} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) 3DMark (HKLM-x32\...\{b7d2ce14-2f17-410d-bea7-9126b9d4bb31}) (Version: 2.0.2067.0 - Futuremark) 3DMark (Version: 2.0.2067.0 - Futuremark) Hidden 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden 7-Zip 15.12 (x64) (HKLM\...\7-Zip) (Version: 15.12 - Igor Pavlov) Acronis True Image 2015 (HKLM-x32\...\{2E51FA82-585D-42B4-B465-A4160DAD4A26}) (Version: 18.0.4061 - Acronis) Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 15.016.20045 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 21.0.0.215 - Adobe Systems Incorporated) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.242 - Adobe Systems Incorporated) Aero Glass for Win8.1 (HKLM\...\Aero Glass for Win8.1_is1) (Version: 1.2.5 - Big Muscle) AIDA64 Extreme v5.70 (HKLM-x32\...\AIDA64 Extreme_is1) (Version: 5.70 - FinalWire Ltd.) Aktualizacje NVIDIA 2.11.3.5 (Version: 2.11.3.5 - NVIDIA Corporation) Hidden Any Audio Converter 5.9.5 (HKLM-x32\...\Any Audio Converter_is1) (Version: - Any-Audio-Converter.com) Arma 2 (HKLM\...\Steam App 33910) (Version: - Bohemia Interactive) Ashampoo Burning Studio 2015 v.1.15.0 (HKLM-x32\...\{91B33C97-21E3-DF34-9630-2EE80DDE1648}_is1) (Version: 1.15.0 - Ashampoo GmbH & Co. KG) Ashampoo Music Studio 4 v.4.1.2 (HKLM-x32\...\{91B33C97-7650-0EB0-B6C7-DDBA2932B7B4}_is1) (Version: 4.1.2 - Ashampoo GmbH & Co. KG) Audacity 2.1.2 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.2 - Audacity Team) AVG PC TuneUp 2015 (HKLM-x32\...\AVG PC TuneUp) (Version: 15.0.1001.638 - AVG Technologies) AVG PC TuneUp 2015 (pl-PL) (x32 Version: 15.0.1001.638 - AVG Technologies) Hidden AVG PC TuneUp 2015 (x32 Version: 15.0.1001.638 - AVG Technologies) Hidden B110 (x32 Version: 140.0.353.000 - Hewlett-Packard) Hidden Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.7.1 - EA Digital Illusions CE AB) BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden CameraHelperMsi (x32 Version: 13.51.815.0 - Logitech) Hidden Cheat Engine 6.5.1 (HKLM-x32\...\Cheat Engine 6.5.1_is1) (Version: - Cheat Engine) Clover 3.0 (HKLM-x32\...\Clover) (Version: 3.0 - EJIE Technology) COMODO Internet Security Premium (HKLM\...\{1EBC6C6F-7D31-4897-B241-DC7052F3E7A5}) (Version: 8.2.0.5027 - COMODO Security Solutions Inc.) Corsair Link 4 (HKLM-x32\...\{7f6939f0-85ea-4187-9ab9-fe8465445e27}) (Version: 4.2.3.41 - Corsair Components, Inc.) Corsair Link 4 (x32 Version: 4.2.3.41 - Corsair Components, Inc.) Hidden Corsair Link(TM) USB Dongle (Driver Removal) (HKLM-x32\...\SIUSBXP&1B1C&1C00) (Version: - Corsair Memory, Inc.) Counter-Strike (HKLM\...\Steam App 10) (Version: - Valve) Counter-Strike Nexon: Zombies (HKLM\...\Steam App 273110) (Version: - Nexon) Counter-Strike: Condition Zero (HKLM\...\Steam App 80) (Version: - Valve) Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve) Counter-Strike: Source (HKLM\...\Steam App 240) (Version: - Valve) CPUID CPU-Z 1.76 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) Creative ASIO (USB) (HKLM-x32\...\Creative_ASIO(USB)) (Version: 1.00 - Creative Technology Limited) Crucial Storage Executive (HKU\S-1-5-21-2715714705-1761166565-38147098-1001\...\Crucial Storage Executive 3.24.082015.05) (Version: 3.24.082015.05 - Crucial) CrystalDiskInfo 6.8.2 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 6.8.2 - Crystal Dew World) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.4.0.0190 - Disc Soft Ltd) Day of Defeat: Source (HKLM\...\Steam App 300) (Version: - Valve) Dead Island (HKLM\...\Steam App 91310) (Version: - Techland) Dead Space (HKLM-x32\...\{6E6F22D7-8AD6-4A87-9A47-733E6E996F50}) (Version: 1.0.0.222 - Electronic Arts) Destinations (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden DOOM (HKLM\...\Steam App 379720) (Version: - id Software) Driver Sweeper wersja 3.2.0 (HKLM-x32\...\{5A67D2EA-FB70-4033-A6F3-606AD85B2015}_is1) (Version: 3.2.0 - Phyxion.net) Duke Nukem 3D: Megaton Edition (HKLM\...\Steam App 225140) (Version: - 3D Realms) EaseUS Data Recovery Wizard (HKLM\...\EaseUS Data Recovery Wizard_is1) (Version: - EaseUS) erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden FileZilla Client 3.18.0 (HKLM-x32\...\FileZilla Client) (Version: 3.18.0 - Tim Kosse) Fraps (HKLM-x32\...\Fraps) (Version: - ) Futuremark SystemInfo (HKLM-x32\...\{5052D282-C9AE-48CC-A9F5-17058BEEAA50}) (Version: 4.45.590.0 - Futuremark) Garry's Mod (HKLM\...\Steam App 4000) (Version: - Facepunch Studios) GG (HKU\S-1-5-21-2715714705-1761166565-38147098-1001\...\GG) (Version: 12 - GG Network S.A.) GIMP 2.8.16 (HKLM\...\GIMP-2_is1) (Version: 2.8.16 - The GIMP Team) GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com) GPBaseService2 (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden GPU Caps Viewer 1.30.0.0 (HKLM-x32\...\{F6E04BE8-2FA4-44C4-9BD3-142CE3EB15B4}_is1) (Version: - Geeks3D.com) Grand Theft Auto V (HKLM-x32\...\{E01FA564-2094-4833-8F2F-1FFEC6AFCC46}) (Version: "1.00.0000" - Rockstar Games) H1Z1: Just Survive (HKLM\...\Steam App 295110) (Version: - Daybreak Game Company) H1Z1: King of the Kill (HKLM\...\Steam App 433850) (Version: - Daybreak Game Company) HD Tune Pro 5.50 (HKLM-x32\...\HD Tune Pro_is1) (Version: - EFD Software) HLSW v1.4.0.5 (HKLM-x32\...\HLSW_is1) (Version: - Stripf Software) HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP) HP Photosmart Wireless B110 All-In-One Driver Software 14.0 Rel. 6 (HKLM\...\{C63184F3-8343-408F-A948-DDB0AC969A99}) (Version: 14.0 - HP) HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP) HPAppStudio (x32 Version: 140.0.95.000 - Hewlett-Packard) Hidden HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden Intel(R) Network Connections 21.0.504.0 (HKLM\...\PROSetDX) (Version: 21.0.504.0 - Intel) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.9.0.1001 - Intel Corporation) JMicron JMB36X Driver (HKLM-x32\...\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.17.65.11 - JMicron Technology Corp.) Left 4 Dead 2 (HKLM\...\Steam App 550) (Version: - Valve) Logitech Gaming Software 8.83 (HKLM\...\Logitech Gaming Software) (Version: 8.83.85 - Logitech Inc.) Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.428 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.428 - LogMeIn, Inc.) Hidden Malwarebytes Anti-Malware wersja 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) marvell 91xx driver (HKLM-x32\...\MagniDriver) (Version: 1.0.0.1051 - Marvell) Metro 2033 (HKLM\...\Steam App 43110) (Version: - 4A Games) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft) Mozilla Firefox 47.0 (x86 pl) (HKLM-x32\...\Mozilla Firefox 47.0 (x86 pl)) (Version: 47.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0.0.5999 - Mozilla) MSI Afterburner 4.2.0 (HKLM-x32\...\Afterburner) (Version: 4.2.0 - MSI Co., LTD) Network64 (Version: 140.0.306.000 - Hewlett-Packard) Hidden NirSoft BlueScreenView (HKLM-x32\...\NirSoft BlueScreenView) (Version: - ) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.9.2 - Notepad++ Team) NVIDIA GeForce Experience 2.11.3.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.11.3.5 - NVIDIA Corporation) NVIDIA Oprogramowanie systemu PhysX 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) NVIDIA Sterownik dźwięku HD 1.3.34.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.14 - NVIDIA Corporation) NVIDIA Sterownik graficzny 368.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 368.22 - NVIDIA Corporation) NVIDIA Wirtualny dźwięk Miracast 368.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 368.22 - NVIDIA Corporation) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Oprogramowanie mikroukładu Intel® (x32 Version: 10.1.1.14 - Intel(R) Corporation) Hidden Oracle VM VirtualBox 5.0.20 (HKLM\...\{8209969B-9A31-4021-B0D8-E6F719F7F995}) (Version: 5.0.20 - Oracle Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.12.1.43352 - Electronic Arts, Inc.) Pakiet sterowników systemu Windows - Corsair Components, Inc. (SIUSBXP) USB (10/30/2015 3.6) (HKLM\...\689CB8E4310D795D383E65C05A8F13A05D92E771) (Version: 10/30/2015 3.6 - Corsair Components, Inc.) Panel sterowania NVIDIA 368.22 (Version: 368.22 - NVIDIA Corporation) Hidden Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.) Polski pakiet językowy dla narzędzi Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - PLK) (Version: 10.0.50903 - Microsoft Corporation) PS_AIO_07_B110_SW_Min (x32 Version: 140.0.365.000 - Hewlett-Packard) Hidden PuTTY release 0.67 (HKLM-x32\...\PuTTY_is1) (Version: 0.67 - Simon Tatham) qBittorrent 3.3.4 (HKLM-x32\...\qBittorrent) (Version: 3.3.4 - The qBittorrent project) QuickTransfer (x32 Version: 140.0.98.000 - Hewlett-Packard) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.45.311.2016 - Realtek) Rise of the Tomb Raider (HKLM\...\Steam App 391220) (Version: - Crystal Dynamics) RivaTuner Statistics Server 6.4.1 (HKLM-x32\...\RTSS) (Version: 6.4.1 - Unwinder) RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.7.8 - Rockstar Games) Rust (HKLM\...\Steam App 252490) (Version: - Facepunch Studios) S.K.I.L.L. - Special Force 2 (HKLM\...\Steam App 286940) (Version: - Dragonfly GF Co., LTD) Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.59.0 - Samsung Electronics Co., Ltd.) Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.11.3.5 - NVIDIA Corporation) Hidden SHU (HKLM-x32\...\{DF11DD92-DBB8-4F3F-9564-A8BBDBE986F5}_is1) (Version: 1.0 - ScreenShu Software) SkyHistory 1.2.3 (HKLM-x32\...\{B03A7F40-A817-4c68-9954-2B2223BE91AA}_is1) (Version: - Scand LLC) Skype™ 7.24 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.24.104 - Skype Technologies S.A.) Skype™ 7.3 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.) Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.16052.2 - Samsung Electronics Co., Ltd.) Smart Switch (x32 Version: 4.1.16052.2 - Samsung Electronics Co., Ltd.) Hidden Sniper Elite V2 (HKLM\...\Steam App 63380) (Version: - Rebellion) SolutionCenter (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden Spek (HKLM-x32\...\{7CDF6754-F5A0-4F34-B589-197530FEF862}) (Version: 0.8.2 - Spek Project) Splinter Cell Blacklist (HKLM-x32\...\Uplay Install 91) (Version: - Ubisoft) Splinter Cell Conviction (HKLM-x32\...\Uplay Install 2) (Version: - Ubisoft) StartIsBack+ (HKLM-x32\...\StartIsBack) (Version: 1.7.5 - startisback.com) Status (x32 Version: 140.0.342.000 - Hewlett-Packard) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Team Fortress 2 (HKLM\...\Steam App 440) (Version: - Valve) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH) TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.59518 - TeamViewer) TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) The Sims 2: Ultimate Collection (HKLM-x32\...\{04450C18-F039-4B81-A621-70C3B0F523D5}) (Version: 1.0.0.0 - Electronic Arts) The Witcher 2 - Assassins of Kings Enhanced Edition (HKLM-x32\...\1207658930_is1) (Version: 3.5.0.26 - GOG.com) The Witcher 3 - Wild Hunt (HKLM-x32\...\The Witcher 3 - Wild Hunt_is1) (Version: - ) Tom Clancy's Rainbow Six Siege (HKLM-x32\...\Uplay Install 635) (Version: - Ubisoft Montreal) Tom Clancy's The Division (HKLM-x32\...\Uplay Install 568) (Version: - Ubisoft) Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden TrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden UNi Xonar Audio Driver (HKLM\...\C-Media Oxygen HD Audio Driver) (Version: - ) Unigine Valley Benchmark version 1.0 (HKLM-x32\...\Unigine Valley Benchmark_is1) (Version: 1.0 - Unigine Corp.) Unturned (HKLM\...\Steam App 304930) (Version: - Smartly Dressed Games) Uplay (HKLM-x32\...\Uplay) (Version: 19.1 - Ubisoft) USB Sound Blaster HD (HKLM-x32\...\{3BE06146-8ADC-47D7-9AD5-E5CABF1FF90C}) (Version: 1.0 - Creative Technology Limited) UxStyle (HKLM-x32\...\{05560347-3a9b-4644-a8ed-8b64cc947189}) (Version: 0.2.3.0 - The Within Network, LLC) UxStyle (Version: 0.2.3.0 - The Within Network, LLC) Hidden VirtualDJ 8 (HKLM-x32\...\{415D8B6F-2597-4B84-B677-B4A936C10E37}) (Version: 8.1.2832.0 - Atomix Productions) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.3 - VideoLAN) Volume2 1.1.5 (HKLM-x32\...\Volume2) (Version: 1.1.5 - Alexandr Irza) Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.) Warface (HKLM\...\Steam App 291480) (Version: - Crytek) Warframe (HKLM\...\Steam App 230410) (Version: - Digital Extremes) WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) Windows Desktop Gadgets (HKLM\...\Windows Desktop Gadgets_is1) (Version: 2.0 - hxxp://gadgetsrevived.com) Windows Installer Clean Up (HKLM-x32\...\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}) (Version: 3.00.00.0000 - Microsoft Corporation) WinRAR 5.31 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH) YTD Video Downloader 5.6 (HKLM-x32\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 5.6 - GreenTree Applications SRL) <==== UWAGA ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) CustomCLSID: HKU\S-1-5-21-2715714705-1761166565-38147098-1001_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Users\Kuba\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll (GG Network S.A.) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {15B5FA95-3E5D-4B8D-A1E8-F8E4EF68706B} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2016-04-27] (COMODO) Task: {1C655968-ACD3-4566-91D7-699798A57E92} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-01] (Adobe Systems Incorporated) Task: {47B88E78-4005-4559-A61F-6ADC1A6F3516} - System32\Tasks\CrystalDiskInfo => C:\Program Files (x86)\CrystalDiskInfo\DiskInfo.exe [2016-06-01] (Crystal Dew World) Task: {6D2D5663-1465-42D3-8608-90D71076F06F} - System32\Tasks\Aero Glass => C:\AeroGlass\aerohost.exe [2016-06-01] (Big Muscle) Task: {7074BA29-01B9-43EF-9036-A467F54177E5} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-04-27] (COMODO) Task: {7687274B-638D-4E5E-BCFC-CB658A4300D8} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-04-27] (COMODO) Task: {93CE672B-B292-49A2-9B6D-6FE6DFCDB888} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-06-06] (Adobe Systems Incorporated) Task: {97441EF4-B0FF-477D-89FE-77862067582A} - System32\Tasks\{05D96924-76E0-49B9-B64F-1B06419AC720} => Firefox.exe hxxp://ui.skype.com/ui/0/7.24.0.104/pl/go/help.faq.installer?LastError=1601 Task: {B043F37B-4817-4F13-9799-96B18A789A6D} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe [2015-08-04] (AVG Technologies) Task: {B2D9B9C1-2FC4-448C-A18A-ACDDB356970D} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-04-27] (COMODO) Task: {D11EB12B-2D70-4F38-AF5E-AEAB0EC06D5B} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2016-06-01] () Task: {EEF767D8-BFAF-4086-B485-7DC6883F2079} - System32\Tasks\PCMeter\Startup => C:\Program Files (x86)\PCMeter\PCMeterV0.4.exe [2016-06-01] (AddGadgets) Task: {FE85C24C-DB75-429E-903D-BA257195690E} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-04-27] (COMODO) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Skróty ============================= (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ==================== Załadowane moduły (filtrowane) ============== 2016-06-01 10:18 - 2016-06-01 10:18 - 00008192 _____ () C:\Windows\SysWOW64\srvany.exe 2016-06-01 10:18 - 2016-06-01 10:18 - 00151552 _____ () C:\Windows\KMService.exe 2015-08-04 14:26 - 2015-08-04 14:26 - 00718040 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\avgrepliba.dll 2016-03-16 11:25 - 2016-03-16 11:25 - 00073912 _____ () C:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav 2016-06-01 05:24 - 2016-05-20 04:11 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-05-27 14:19 - 2016-05-27 14:19 - 00052912 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll 2016-05-18 00:42 - 2016-05-18 00:42 - 00230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2016-04-29 00:49 - 2016-04-29 00:49 - 01095448 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2016-04-29 00:49 - 2016-04-29 00:49 - 00240408 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2016-06-01 05:43 - 2013-01-25 11:08 - 00089600 _____ () C:\Windows\SYSTEM32\CmdRtr64.DLL 2016-06-01 05:43 - 2013-01-25 11:06 - 00328704 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL 2015-08-04 14:26 - 2015-08-04 14:26 - 00861912 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\tulnga.dll 2015-12-09 09:59 - 2016-06-01 13:25 - 00580296 _____ () C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe 2016-06-01 11:11 - 2016-06-01 11:11 - 00012520 _____ () C:\Users\Kuba\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\CoreTempReader.dll 2016-06-01 11:11 - 2016-06-01 11:11 - 00015080 _____ () C:\Users\Kuba\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\GetCoreTempInfoNET.dll 2016-06-01 11:11 - 2016-06-01 11:11 - 00014056 _____ () C:\Users\Kuba\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\SystemInfo.dll 2016-06-01 13:41 - 2016-06-01 13:41 - 00495616 _____ () C:\Program Files (x86)\RocketDock\RocketDock.exe 2016-06-01 05:25 - 2016-05-02 08:00 - 00167480 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\gamecaster64.dll 2016-06-01 05:25 - 2016-05-02 08:01 - 00862776 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\twitchsdk64.dll 2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\office14\Cultures\office.odf 2015-11-11 02:49 - 2015-11-11 02:49 - 01557160 _____ () C:\Program Files\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll 2016-06-01 13:42 - 2016-06-01 13:42 - 00856744 _____ () C:\Program Files (x86)\SHU\SHU.exe 2016-06-01 13:42 - 2016-06-01 13:42 - 00017064 _____ () C:\Program Files (x86)\SHU\QtWebEngineProcess.exe 2016-06-01 13:42 - 2016-06-01 13:42 - 00021672 _____ () C:\Program Files (x86)\SHU\ScreenShu64.exe 2016-06-01 13:42 - 2016-06-01 13:42 - 00104616 _____ () C:\Program Files (x86)\SHU\screenshu_injected_dll_x64.dll 2016-06-01 05:25 - 2016-05-02 08:02 - 00020536 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-06-01 13:41 - 2016-06-01 13:41 - 00069632 _____ () C:\Program Files (x86)\RocketDock\RocketDock.dll 2015-12-07 18:43 - 2015-12-07 18:43 - 00071680 _____ () C:\Program Files (x86)\MSI Afterburner\RTMUI.dll 2015-12-07 18:43 - 2015-12-07 18:43 - 00057856 _____ () C:\Program Files (x86)\MSI Afterburner\RTFC.dll 2015-12-07 18:44 - 2015-12-07 18:44 - 00225792 _____ () C:\Program Files (x86)\MSI Afterburner\RTCore.dll 2015-12-07 18:43 - 2015-12-07 18:43 - 00357888 _____ () C:\Program Files (x86)\MSI Afterburner\RTUI.dll 2015-12-07 18:44 - 2015-12-07 18:44 - 00657408 _____ () C:\Program Files (x86)\MSI Afterburner\RTHAL.dll 2016-04-18 17:49 - 2016-04-18 17:49 - 03716144 _____ () C:\Users\Kuba\AppData\Local\GG\Application\xulrunner\mozjs.dll 2016-05-29 22:32 - 2016-04-29 22:10 - 00785920 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2016-05-29 22:32 - 2015-07-03 18:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll 2016-05-29 22:32 - 2016-04-30 02:10 - 02549840 _____ () C:\Program Files (x86)\Steam\video.dll 2016-05-29 22:32 - 2016-02-16 15:15 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2016-05-29 22:32 - 2016-02-16 15:15 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2016-05-29 22:32 - 2016-03-09 02:48 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll 2016-05-29 22:32 - 2016-03-09 02:48 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll 2016-05-29 22:32 - 2016-03-09 02:48 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll 2016-05-29 22:32 - 2016-03-09 02:48 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll 2016-05-29 22:32 - 2016-03-09 02:48 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll 2016-05-29 22:32 - 2016-04-30 02:10 - 00829008 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2016-05-29 22:32 - 2016-03-09 02:48 - 00281088 _____ () C:\Program Files (x86)\Steam\openvr_api.dll 2016-05-29 22:32 - 2016-01-10 03:27 - 00075776 _____ () C:\Program Files (x86)\Steam\XInput1_4.dll 2016-05-29 22:32 - 2016-04-28 03:00 - 49825056 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2016-04-18 17:49 - 2016-04-18 17:49 - 00122432 _____ () C:\Users\Kuba\AppData\Local\GG\Application\ggdrive\ZLIB1.dll 2016-05-29 22:32 - 2015-09-25 01:56 - 00119208 _____ () C:\Program Files (x86)\Steam\winh264.dll 2016-05-27 14:19 - 2016-05-27 14:19 - 00048816 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll 2016-05-18 00:42 - 2016-05-18 00:42 - 00021680 _____ () C:\Program Files (x86)\Notepad++\plugins\NppExport.dll 2016-06-01 13:42 - 2016-06-01 13:42 - 00092328 _____ () C:\Program Files (x86)\SHU\screenshu_injected_dll.dll 2016-06-01 13:42 - 2016-06-01 13:42 - 00140800 _____ () C:\Program Files (x86)\SHU\quazip.dll 2014-09-09 11:00 - 2014-09-09 11:00 - 00023576 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\ti_managers_proxy_stub.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) AlternateDataStreams: C:\Windows\explorer.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\KMService.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\notepad.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\splwow64.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\unsignedthemes.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\actxprxy.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\adhsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\advapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\apphelp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appidapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appidsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appinfo.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\AppxAllUserStore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\AppXDeploymentExtensions.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\AppXDeploymentServer.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\asycfilt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\atmfd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\atmlib.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\AudioEndpointBuilder.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\audiosrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\AuthHost.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\authui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\authz.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\basesrv.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\bcryptprimitives.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\BdeHdCfg.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\BdeHdCfgLib.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\bdesvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\BFE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\btcoinst.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\BtContextMenu.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\calc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\catsrvut.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\certcli.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cfgbkend.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ci.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\clfsw32.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\COLORCNV.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\combase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\comctl32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\compstui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\comsvcs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\consent.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\CPFilters.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\crypt32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\csrsrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d2d1.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3d10level9.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DCompiler_33.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DCompiler_34.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DCompiler_35.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DCompiler_36.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DCompiler_37.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DCompiler_38.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DCompiler_39.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DCompiler_40.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\D3DCompiler_41.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DCompiler_42.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DCompiler_43.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\D3DCompiler_47.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dcsx_42.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dcsx_43.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx10.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx10_33.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx10_34.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx10_35.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx10_36.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx10_37.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx10_38.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx10_39.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx10_40.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx10_41.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx10_42.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx11_42.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx9_24.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx9_25.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx9_26.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx9_27.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx9_28.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx9_29.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx9_30.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx9_31.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx9_32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx9_33.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx9_34.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx9_35.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx9_36.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DX9_37.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DX9_38.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DX9_39.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DX9_40.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DX9_41.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DX9_42.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\davclnt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dbgeng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dbghelp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\devenum.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\DevicePairing.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\DeviceSetupStatusProvider.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dhcpsapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dnsapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dnsrslvr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dpapisrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dsparse.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dwmcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\DWrite.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxtmsft.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxtrans.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\eapp3hst.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\eappcfg.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\eappgnui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\eapphost.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\EncDec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\EncDump.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\eventcls.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\evr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ExplorerFrame.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Faultrep.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\fhcpl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\FirewallAPI.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\FntCache.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\fveapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\fvecpl.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\FWPUCLNT.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\gdi32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\GdiPlus.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\GeofenceMonitorService.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\glcndFilter.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\GlobCollationHost.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\hgcpl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\hhctrl.ocx:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\hlink.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\httpprxm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\httpprxp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ie4uinit.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieapfltr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iedkcs32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieframe.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iepeers.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iertutil.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\IKEEXT.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inetcomm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inetcpl.cpl:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\InkEd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inseng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\IPHLPAPI.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iphlpsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jscript9.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jscript9diag.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\KBDAZE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\KBDAZEL.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\KBDAZST.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\kbdgeoqw.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\kerberos.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\KernelBase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\kmddsp.tsp:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ksproxy.ax:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\localspl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\LocationApi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\LockScreenContentServer.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lsasrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lsm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MDMAgent.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Metro Clock.scr:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfc42.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfc42u.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfds.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MFMediaEngine.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfmp4srcsnk.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfnetcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfnetsrc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfplat.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfsvr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfvdsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MFWMAAEC.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\microsoft-windows-system-events.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mispace.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MP3DMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MP43DECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MP4SDECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MPG4DECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MPSSVC.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\MrmCoreR.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MRT.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msctf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msfeeds.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msftedit.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mshtml.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MshtmlDac.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mshtmled.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msiexec.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msmpeg2adec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msra.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msrating.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mssph.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mssphtb.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mssrch.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mssvp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mstscax.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msv1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msvcp120_clr0400.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\msvcr120_clr0400.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msxml3.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msxml6.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mtxoci.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\NcdAutoSetup.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ncrypt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ncryptsslp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ncsi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\netcfgx.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\netlogon.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\notepad.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nshwfp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntdll.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntvdm64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ole32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\oleaut32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\PCPKsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\PhotoMetadataHandler.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\photowiz.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pku2u.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pmcsnap.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\poqexec.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ppcsnap.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\profsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\puiobj.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\qdvd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\qedit.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\QSHVHOST.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\QSVRMGMT.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\quartz.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rasapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rascfg.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rasdiag.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rasmxs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rasser.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rastapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rdpcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rdpcorets.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rdpudd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rdvidcrl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\RESAMPLEDMO.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rpcrt4.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rpcss.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rsaenh.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\samlib.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\samsrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\scesrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\schannel.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\schedsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\schtasks.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sdbinst.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SearchIndexer.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SearchProtocolHost.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sechost.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\seclogon.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\services.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SettingMonitor.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SettingsHandlers.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SettingSync.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SettingSyncCore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SettingSyncHost.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\shacct.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SHCore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\shell32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SkyDrive.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SkyDriveTelemetry.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\spoolsv.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sppobjs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sppsvc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sppwinob.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SRH.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\stobject.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\StorageContextHandler.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\storagewmi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\StructuredQuery.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SyncEngine.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SysFxUI.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sysmain.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SystemEventsBrokerServer.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SystemSettings.Handlers.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SystemSettingsAdminFlows.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\SystemSettingsAdminFlowUI.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\SystemSettingsDatabase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\taskeng.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\tdc.ocx:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\tdh.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\themecpl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\tquery.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\tracerpt.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TSWbPrxy.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TsWpfWrp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\twinui.appcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\twinui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\tzsync.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ubpm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ucrtbase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\UIAutomationCore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\untfs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\urlmon.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\user32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\usercpl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\vbscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\VIDRESZR.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\vpnike.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\vssapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\vsstrace.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\VSSVC.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wbengine.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\webcheck.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WebClnt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\webio.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wer.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\werdiagcontroller.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WerFaultSecure.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wevtsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wfapigp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WiFiDisplay.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\win32k.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\win32spl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Windows.Data.Pdf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Windows.Devices.Geolocation.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Windows.Globalization.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Windows.UI.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Windows.UI.Immersive.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Windows.UI.Input.Inking.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Windows.UI.Xaml.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WindowsAnytimeUpgradeui.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WindowsCodecs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winresume.efi:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winresume.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WinSCard.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WinSetupUI.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winshfhc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WinSync.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WinTypes.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMADMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMADMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMALFXGFXDSP.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMASF.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wmp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMPhoto.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMSPDMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMSPDMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVDECOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVENCOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVSDECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVSENCD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMVXENCD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WorkfoldersControl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\workfolderssvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wow64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wow64cpu.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wpdshext.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wscapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wscsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WSDApi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WSDMon.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WsmAgent.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WsmAuto.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WsmSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WsmWmiPl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WSShared.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wu.upgrade.ps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuaext.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuapp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuauclt.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuaueng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wucltux.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wudriver.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wups.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wups2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WUSettingsProvider.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuwebv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\x3daudio1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\x3daudio1_1.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\X3DAudio1_2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\X3DAudio1_3.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\X3DAudio1_4.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\X3DAudio1_5.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\X3DAudio1_6.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\X3DAudio1_7.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine2_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine2_1.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine2_10.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine2_2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine2_3.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine2_4.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine2_5.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine2_6.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine2_7.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine2_8.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine2_9.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine3_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine3_1.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine3_2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine3_3.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine3_4.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine3_5.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine3_6.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xactengine3_7.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAPOFX1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAPOFX1_1.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAPOFX1_2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAPOFX1_3.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAPOFX1_4.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAPOFX1_5.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAudio2_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAudio2_1.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAudio2_2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAudio2_3.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAudio2_4.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAudio2_5.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAudio2_6.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAudio2_7.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xinput1_1.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xinput1_2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\actxprxy.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\advapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\appidapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\AppxAllUserStore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\asycfilt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\atlthunk.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\atmfd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\atmlib.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\authui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\authz.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\bcryptprimitives.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\calc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\catsrvut.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\certcli.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cfgbkend.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\clfsw32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\COLORCNV.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\combase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\comctl32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\comsvcs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\CPFilters.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\crypt32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d2d1.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3d10level9.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_33.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_34.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_35.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_36.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_37.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_38.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_39.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_40.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_41.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_42.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_43.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_47.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dcsx_42.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dcsx_43.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dx10.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_33.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_34.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_35.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_36.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_37.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_38.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_39.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_40.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_41.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_42.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dx11_42.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_24.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_25.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_26.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_27.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_28.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_29.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_30.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_31.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_33.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_34.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_35.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_36.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_37.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_38.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_39.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_40.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_41.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_42.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\davclnt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dbgeng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dbghelp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\devenum.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\DevicePairing.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\DeviceSetupStatusProvider.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dhcpsapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dnsapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dsparse.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dwmcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\DWrite.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dxtmsft.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dxtrans.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\eapp3hst.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\eappcfg.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\eappgnui.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\eapphost.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\EasyAntiCheat.exe:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\EncDec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\eventcls.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\evr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\explorer.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ExplorerFrame.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\Faultrep.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\FirewallAPI.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\FWPUCLNT.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\gdi32.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\GdiPlus.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\GeofenceMonitorService.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\glcndFilter.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\GlobCollationHost.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\GPhotos.scr:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\hgcpl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\hhctrl.ocx:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\hlink.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieapfltr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iedkcs32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieframe.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iepeers.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iertutil.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\inetcomm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\inetcpl.cpl:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\InkEd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\instnm.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\IPHLPAPI.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jscript9.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jscript9diag.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\KBDAZE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\KBDAZEL.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\KBDAZST.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\kbdgeoqw.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\kerberos.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\KernelBase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\kmddsp.tsp:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ksproxy.ax:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\LocationApi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfc42.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfc42u.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfds.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MFMediaEngine.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfmp4srcsnk.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfnetcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfnetsrc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfplat.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfsvr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfvdsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MFWMAAEC.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mispace.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MP3DMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MP43DECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MP4SDECD.DLL:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\MPG4DECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MrmCoreR.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msctf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msfeeds.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msftedit.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mshtml.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MshtmlDac.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mshtmled.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msiexec.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msmpeg2adec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msorcl32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msrating.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mssph.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mssrch.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mssvp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mstscax.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msv1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msvcp120_clr0400.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msvcr120_clr0400.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msxml3.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msxml6.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mtxoci.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ncrypt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ncryptsslp.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\netcfgx.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\netlogon.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\notepad.exe:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\nshwfp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntdll.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntvdm64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ole32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\oleaut32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\olepro32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\PCPKsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\PhotoMetadataHandler.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\photowiz.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\pku2u.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\poqexec.exe:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\PrintConfig.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\puiobj.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\qdvd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\qedit.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\QSHVHOST.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\QSVRMGMT.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\quartz.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rasapi32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rascfg.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rasdiag.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rasmxs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rasser.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rastapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rdpcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rdvidcrl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\RESAMPLEDMO.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rgb9rast.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rpcrt4.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rsaenh.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\samlib.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\scesrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\schannel.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\schtasks.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\sdbinst.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\SearchIndexer.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\SearchProtocolHost.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\sechost.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\SettingMonitor.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\SettingSync.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\SettingSyncCore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\SettingSyncHost.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\setup16.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\shacct.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\SHCore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\shell32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\SRH.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\srvany.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\stobject.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\StorageContextHandler.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\storagewmi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\StructuredQuery.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\taskeng.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\tdc.ocx:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\tdh.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\themecpl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\tquery.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\tracerpt.exe:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\TsWpfWrp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\twinui.appcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\twinui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ucrtbase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\UIAutomationCore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\untfs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\urlmon.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\user.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\user32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\usercpl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\vbscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\VIDRESZR.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\vssapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\vsstrace.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\webcheck.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WebClnt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\webio.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wer.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WerFaultSecure.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wfapigp.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\wincorlib.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\Windows.Data.Pdf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\Windows.Devices.Geolocation.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\Windows.Globalization.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Immersive.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Xaml.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WindowsCodecs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wininet.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WinSCard.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\winshfhc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WinSync.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WinTypes.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMADMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMADMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMASF.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wmp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMPhoto.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\WMSPDMOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMSPDMOE.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVDECOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVENCOD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVSDECD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVSENCD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMVXENCD.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wow32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wpdshext.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wscapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WSDApi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WsmAgent.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WsmAuto.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WsmSvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WsmWmiPl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WSShared.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wuapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wuapp.exe:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\wudriver.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wups.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wuwebv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\x3daudio1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\x3daudio1_1.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_2.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_3.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_4.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_5.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_6.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_7.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_1.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_10.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_3.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_4.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_5.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_6.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_7.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_8.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_9.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_0.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_1.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_2.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_3.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_4.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_5.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_6.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_7.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_0.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_1.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_2.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_3.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_4.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_5.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_0.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_1.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_2.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_3.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_4.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_5.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_6.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_7.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\xinput1_1.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\xinput1_2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\xinput1_3.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\afd.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\agilevpn.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ahcache.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\btfilter.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\bthenum.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\bthhfenum.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\bthpan.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\bthport.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\BTHUSB.SYS:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\Classpnp.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\clfs.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\cng.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\csc.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\dam.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\dfsc.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\disk.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\dtlitescsibus.sys:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Drivers\dtliteusbbus.sys:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Drivers\dumpsd.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\dxgkrnl.sys:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Drivers\file_tracker.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\fltsrv.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\FWPKCLNT.SYS:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\Hamdrv.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\hidbth.sys:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Drivers\http.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\i8042prt.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\intelpep.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\IPMIDrv.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\jraid.sys:$CmdZnID [26] AlternateDataStreams: C:\Windows\system32\Drivers\kbdclass.sys:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Drivers\kbdhid.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ksecpkg.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mbam.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mbamchameleon.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mouclass.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mouhid.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mountmgr.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mrxdav.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb10.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb20.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mup.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mwac.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ndis.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ndistapi.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ndiswan.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ndproxy.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\netio.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ntfs.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\pdc.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\rasl2tp.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\rdbss.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\rfcomm.sys:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Drivers\rmcast.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\sdbus.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\sermouse.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\snapman.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\spaceport.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\srv.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ssudmdm.sys:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Drivers\storport.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\storvsp.sys:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Drivers\tcpip.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\tdx.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\tib.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\tib_mounter.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\tpm.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\tunnel.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\udfs.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usb8023.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbd.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbehci.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbhub.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\USBHUB3.SYS:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbohci.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbport.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\USBSTOR.SYS:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\usbuhci.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\USBXHCI.SYS:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\VBoxDrv.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\VBoxNetAdp6.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\VBoxNetLwf.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\VBoxUSBMon.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\vhdmp.sys:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Drivers\volmgr.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\volsnap.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\vpci.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\vpcivsp.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\wanarp.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\WdBoot.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\WdFilter.sys:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Drivers\WdNisDrv.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\wfplwfs.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\winusb.sys:$CmdTcID [64] ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== Powiązania plików (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Hosts - zawartość: =============================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-2715714705-1761166565-38147098-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Kuba\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img01.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Zapora systemu Windows [funkcja wyłączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Obecnie brak automatycznej naprawy dla tej sekcji.) HKLM\...\StartupApproved\Run: => "Acronis Scheduler2 Service" HKLM\...\StartupApproved\Run32: => "LWS" HKLM\...\StartupApproved\Run32: => "TrueImageMonitor.exe" HKLM\...\StartupApproved\Run32: => "AcronisTibMounterMonitor" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKU\S-1-5-21-2715714705-1761166565-38147098-1001\...\StartupApproved\StartupFolder: => "Logitech . Rejestracja produktu.lnk" ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{1EB4ABFB-690A-4CC1-AD7E-991075D7998A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{B877C4D4-F86F-49DA-8142-995CB6F072A4}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{F86DF59B-0E4E-4D0D-A2AC-24AF5FA32E45}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{B764C134-D919-403F-90FC-467C3A86DBC3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{14866BB2-6005-41AE-A35B-40053B80B652}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{FE8E8B5B-D53E-46D9-8294-3B861F3B5728}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{744222FF-9BFF-4F40-8D10-1929B80B7E60}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [TCP Query User{BE702114-18BD-49A0-9B30-DAC9F3F82C12}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{2CB19DA6-6222-4F59-9B43-C49CF23F5F0E}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{DEABFCF9-E657-4CDD-9BF3-966A30963469}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{76EEC14C-18CA-47F1-A968-66F3597DDEB7}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{E5119C34-6241-4E7E-A477-70C3D2CDBA0A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{18EB82D8-F105-4E16-8D53-0E7E00B40CD7}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{006F4540-20E1-4163-A0D2-82B7149E1563}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe FirewallRules: [{1F425EDA-7D44-47FD-B1C9-EB95D87C82D2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe FirewallRules: [{1DBEF6E3-09EB-463B-9507-8D7DDB828F59}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{F9A28FF1-0A2B-49A4-8887-C89F1A398E85}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{F820F2B0-4A3E-4537-8151-84B61BF6DF0C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [TCP Query User{D73E2288-75C7-47E6-9E09-089CBB570F9C}C:\program files\crucial\crucial storage executive\java\bin\javaw.exe] => (Allow) C:\program files\crucial\crucial storage executive\java\bin\javaw.exe FirewallRules: [UDP Query User{AAE7E365-7AEC-47DA-910B-4684F01BEF01}C:\program files\crucial\crucial storage executive\java\bin\javaw.exe] => (Allow) C:\program files\crucial\crucial storage executive\java\bin\javaw.exe FirewallRules: [TCP Query User{3047A093-298B-44A9-83B7-A23F37C60B10}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{B3409A4C-0BC1-432A-85FD-7A31D448C35A}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{688C4246-DA61-4263-AEB7-F3ABBB91CE62}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{44148953-1EC7-4D9E-A6D0-0CB170228B81}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{A4B5E975-6EE1-4573-A532-11671A275FEF}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{029534DA-4883-4AF3-ADF3-CBD0C25C44BE}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{01C1781C-595F-4394-B41D-8F3D6356D674}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{B27C3897-23FD-454F-86EB-C0B19B753D83}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{D8027477-5829-48BE-82F6-85D28E3AE260}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{984F7CFD-B22C-4F49-86DA-6237C434E865}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{DE7E564D-0120-4638-988D-2F15AFE59215}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [{5EEDA014-0A65-4E03-9D05-90E9D57F0C92}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [{A8E96726-D55C-4EDA-A592-3DB58715D1A6}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [{DED6F07B-534B-4FC4-B27B-2407C03CC478}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [{68B24E49-720C-47C9-A0F6-3EDB6B120A5B}] => (Allow) LPort=1688 FirewallRules: [{79B1CB3D-D34D-4A23-A008-DA69AD3045D6}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{E1F5619A-13DE-46E6-9CBA-86987D5FF9BB}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [TCP Query User{36888C5C-0E68-4A63-8168-D22344D92A1A}C:\program files (x86)\hlsw\hlsw.exe] => (Allow) C:\program files (x86)\hlsw\hlsw.exe FirewallRules: [UDP Query User{8F560A48-E258-4BD8-A3C4-FB16795A1D6E}C:\program files (x86)\hlsw\hlsw.exe] => (Allow) C:\program files (x86)\hlsw\hlsw.exe FirewallRules: [{A1F6514A-B61E-4D57-A43D-66808A84EA05}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe FirewallRules: [{D2FE0B8D-25C9-472C-BBEB-06B2593C9C32}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe FirewallRules: [{A0A4F9F1-E606-4BFD-872B-66674CB1E074}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{D8017FD2-8079-47FE-A552-3833AA7C11E2}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{99B88D58-B0A1-4A42-A260-4E2A754987DE}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{539FC988-2CD9-445E-9574-553B4AE7D7D1}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{B6BA4F24-B494-40E6-B36B-74440038F5A4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{4FD90E23-5E44-49B3-94DC-26B9C97914A2}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{314E36CD-CEDA-4CA7-9631-648344F2E17C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{D43BDCE0-D18B-4BEC-A724-5419350C90E0}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{1A3A9EF9-C3B1-494B-97AE-22338D1A2C22}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{54D2AB30-290E-486A-94EE-A945209C9B4C}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [TCP Query User{16959C07-BDFD-4F6D-A284-363830FB3475}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{828206E1-4F40-4AAD-B675-2F66447F662D}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{2CDAB86A-62BC-4214-BB9E-7582CE91DEFC}] => (Allow) E:\Gry\Battlefield 3\bf3.exe FirewallRules: [{3B007343-3252-49A2-BA5B-78DA2877638F}] => (Allow) E:\Gry\Battlefield 3\bf3.exe FirewallRules: [{C8045F56-1DFE-450B-B552-0B5B5B644CDF}] => (Allow) E:\Gry\Dead Space\Dead Space.exe FirewallRules: [{223F799C-B638-4240-AD86-0174FD845728}] => (Allow) E:\Gry\Dead Space\Dead Space.exe FirewallRules: [{36FE7DD1-1F6D-4AD4-A6E1-1E8BD33BE4A7}] => (Allow) E:\Gry\The Sims 2 Ultimate Collection\Fun with Pets\SP9\TSBin\Sims2EP9.exe FirewallRules: [{6DC92C90-1714-430B-8249-6655C95520AA}] => (Allow) E:\Gry\The Sims 2 Ultimate Collection\Fun with Pets\SP9\TSBin\Sims2EP9.exe FirewallRules: [{D1004CFE-90D1-4E73-A2F2-CD13CDF996FD}] => (Allow) E:\Gry\Steam Games\common\Arma 2\arma2.exe FirewallRules: [{CB571D7C-02C1-4532-9AD4-4673C679B9F8}] => (Allow) E:\Gry\Steam Games\common\Arma 2\arma2.exe FirewallRules: [{2D553774-1B41-427E-AC9E-C8BAEBFC81CF}] => (Allow) E:\Gry\Steam Games\common\Dead Island\DeadIslandGame.exe FirewallRules: [{9DE1D072-6F95-4084-AF7E-3921DF1E7B20}] => (Allow) E:\Gry\Steam Games\common\Dead Island\DeadIslandGame.exe FirewallRules: [{70281C4A-4434-4BEB-897A-51026E567F37}] => (Allow) E:\Gry\Steam Games\common\Day of Defeat Source\hl2.exe FirewallRules: [{F6802D24-968A-415E-A740-CD44D88C52B5}] => (Allow) E:\Gry\Steam Games\common\Day of Defeat Source\hl2.exe FirewallRules: [{306752B3-65CD-4A1F-81EE-DC99EAAC44C6}] => (Allow) E:\Gry\Steam Games\common\DOOM\DOOMx64.exe FirewallRules: [{F3F2D190-7958-44AB-BE42-B908A079915A}] => (Allow) E:\Gry\Steam Games\common\DOOM\DOOMx64.exe FirewallRules: [{2C76D307-0618-4D6B-BA99-800F5E660745}] => (Allow) E:\Gry\Steam Games\common\Warframe\Tools\Launcher.exe FirewallRules: [{A41A6793-5424-4BB2-9287-23B4B00D9F84}] => (Allow) E:\Gry\Steam Games\common\Warframe\Tools\Launcher.exe FirewallRules: [{F38BE69C-C31C-4CCD-B1B4-E4599E5941D1}] => (Allow) E:\Gry\Steam Games\common\Sniper Elite V2\Launcher\SniperV2Launcher.exe FirewallRules: [{D0048B45-D5AA-4181-8483-0C8A19C876D0}] => (Allow) E:\Gry\Steam Games\common\Sniper Elite V2\Launcher\SniperV2Launcher.exe FirewallRules: [{3382E772-3608-4599-A0B4-CCA4A6819546}] => (Allow) E:\Gry\Steam Games\common\Rise of the Tomb Raider\ROTTR.exe FirewallRules: [{44B7254D-90F8-40C2-A8B0-D58FB0219E5C}] => (Allow) E:\Gry\Steam Games\common\Rise of the Tomb Raider\ROTTR.exe FirewallRules: [{5C0F4A73-8F00-4409-86A3-4675654CAF28}] => (Allow) E:\Gry\Steam Games\common\left 4 dead 2\left4dead2.exe FirewallRules: [{7B50FE06-3D65-4AE9-B0EC-6D7CA803CDB2}] => (Allow) E:\Gry\Steam Games\common\left 4 dead 2\left4dead2.exe FirewallRules: [{919C8654-3D37-47D2-93B4-E58C740B489C}] => (Allow) E:\Gry\Steam Games\common\H1Z1\LaunchPad.exe FirewallRules: [{F41CEEFC-7A1A-4D69-96C5-DA90672E81D8}] => (Allow) E:\Gry\Steam Games\common\H1Z1\LaunchPad.exe FirewallRules: [{1103A0B9-A458-44A0-82AC-8F0C95E98C3E}] => (Allow) E:\Gry\Steam Games\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{F3E9B6EC-9C55-4F9D-A40F-471F168796AF}] => (Allow) E:\Gry\Steam Games\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{1B04145C-65A7-47AB-BF12-02452B0FB059}] => (Allow) E:\Gry\Steam Games\common\GarrysMod\hl2.exe FirewallRules: [{D2FCA5B6-DC27-4625-AF33-8A42C18F91D9}] => (Allow) E:\Gry\Steam Games\common\GarrysMod\hl2.exe FirewallRules: [{BF25E87B-D741-4CA1-ACED-2B514DF76671}] => (Allow) E:\Gry\Steam Games\common\Duke Nukem 3D\bin\dosbox\dosbox.exe FirewallRules: [{2A0A15E8-F44D-4463-A12F-0B58CE600373}] => (Allow) E:\Gry\Steam Games\common\Duke Nukem 3D\bin\dosbox\dosbox.exe FirewallRules: [{E06C95C8-3362-4469-B6FD-8CFEFECD7CF7}] => (Allow) E:\Gry\Steam Games\common\Duke Nukem 3D\bin\duke3d.exe FirewallRules: [{4FCE4BA9-4EE9-484E-A6E5-968669EA9CEE}] => (Allow) E:\Gry\Steam Games\common\Duke Nukem 3D\bin\duke3d.exe FirewallRules: [{21CFC071-5C0B-4E4B-82FB-E6EC23E0C3BB}] => (Allow) E:\Gry\Steam Games\common\Duke Nukem 3D\bin\build.exe FirewallRules: [{4321B015-C703-459C-8E76-0C44CC4A2E67}] => (Allow) E:\Gry\Steam Games\common\Duke Nukem 3D\bin\build.exe FirewallRules: [{324F6913-7FE4-4FD1-A0C5-DF26A61F1E83}] => (Allow) E:\Gry\Steam Games\common\Counter-Strike Source\hl2.exe FirewallRules: [{3C626A49-711A-4C04-9B0C-1071E8F65908}] => (Allow) E:\Gry\Steam Games\common\Counter-Strike Source\hl2.exe FirewallRules: [{18771B3F-6231-4A64-B5EF-062006F793C3}] => (Allow) E:\Gry\Steam Games\common\Half-Life\hl.exe FirewallRules: [{B8B91493-0942-43D3-99C0-85DE7CC06F7B}] => (Allow) E:\Gry\Steam Games\common\Half-Life\hl.exe FirewallRules: [{F498063C-C951-4A60-952D-4AAC13EEA9B9}] => (Allow) E:\Gry\Steam Games\common\Team Fortress 2\hl2.exe FirewallRules: [{BEF93123-C6AA-4FAA-9CF6-F4C263B91B37}] => (Allow) E:\Gry\Steam Games\common\Team Fortress 2\hl2.exe FirewallRules: [{0C4F9F7A-BC34-443F-8DB4-B2F5EDA57D55}] => (Allow) E:\Gry\Steam Games\common\CSNZ\Bin\cstrike-online.exe FirewallRules: [{015744A3-6F7C-4606-BCB8-112284F20017}] => (Allow) E:\Gry\Steam Games\common\CSNZ\Bin\cstrike-online.exe FirewallRules: [{42AD51A5-7AE0-47F8-BFF0-6FCAAE588242}] => (Allow) E:\Gry\Steam Games\common\SKILL\DFUBG.exe FirewallRules: [{41B09E59-6523-4EAA-BC39-77C0D542605D}] => (Allow) E:\Gry\Steam Games\common\SKILL\DFUBG.exe FirewallRules: [{7E4453C6-F4AA-45E1-BF45-E3CCCBBB90C3}] => (Allow) E:\Gry\Steam Games\common\Unturned\Unturned.exe FirewallRules: [{C194DDD7-7FFC-4C49-8058-A891E9E0DC29}] => (Allow) E:\Gry\Steam Games\common\Unturned\Unturned.exe FirewallRules: [{1694AF93-F7C7-4440-9999-33E1370EF596}] => (Allow) E:\Gry\Steam Games\common\Warface\live\nw.exe FirewallRules: [{FCD61DD8-FAA4-45DB-91F9-C81E1F1CED26}] => (Allow) E:\Gry\Steam Games\common\Warface\live\nw.exe FirewallRules: [{B4499236-B32C-43E3-A0B4-9AE7B745923B}] => (Allow) E:\Gry\Steam Games\common\Metro 2033\metro2033.exe FirewallRules: [{3D90950B-C014-466F-BD08-CF0A0E980059}] => (Allow) E:\Gry\Steam Games\common\Metro 2033\metro2033.exe FirewallRules: [{386BB780-3065-43CB-A9AC-E65DC5C87108}] => (Allow) E:\Gry\Steam Games\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{FD2CA092-B517-4948-94EB-6BAF462F0C2D}] => (Allow) E:\Gry\Steam Games\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{CE5552B7-E6FE-45E0-A204-5915FB97B13B}] => (Allow) E:\Gry\Steam Games\common\Rust\Rust.exe FirewallRules: [{EBD0FA39-011F-4A0F-B1CE-3D38426639DE}] => (Allow) E:\Gry\Steam Games\common\Rust\Rust.exe FirewallRules: [{F2574A23-44DA-458B-9F0F-F68CA6785441}] => (Allow) E:\Gry\Steam Games\common\Unturned\Unturned.exe FirewallRules: [{BAA47379-C304-4436-A5D6-6179C5D8B825}] => (Allow) E:\Gry\Steam Games\common\Unturned\Unturned.exe FirewallRules: [{F438E934-401F-4AA6-8364-864AA55764B2}] => (Allow) E:\Gry\Steam Games\common\left 4 dead 2\left4dead2.exe FirewallRules: [{02CCD82C-C5B8-407C-B0C3-D8413941D6CE}] => (Allow) E:\Gry\Steam Games\common\left 4 dead 2\left4dead2.exe FirewallRules: [{BC23F455-6250-4FA5-8249-DC158707C414}] => (Allow) E:\Gry\Steam Games\common\Rust\Rust.exe FirewallRules: [{732C272B-9BB3-4F6A-A1EC-E4705ED4F759}] => (Allow) E:\Gry\Steam Games\common\Rust\Rust.exe FirewallRules: [{50A60BB7-61B4-4C30-B50C-0C5BCB2C2A68}] => (Allow) E:\Gry\Steam Games\common\H1Z1\LaunchPad.exe FirewallRules: [{0506EA73-8F4B-43AA-A5C8-7EF44808871C}] => (Allow) E:\Gry\Steam Games\common\H1Z1\LaunchPad.exe FirewallRules: [{5E83D497-D1DD-49DB-99A3-C98CA3FD59CD}] => (Allow) E:\Gry\Steam Games\common\CSNZ\Bin\cstrike-online.exe FirewallRules: [{064CCBB4-8AAD-4C58-8613-198B94BD7ECD}] => (Allow) E:\Gry\Steam Games\common\CSNZ\Bin\cstrike-online.exe FirewallRules: [{DF3C481E-D3FC-4971-8FBD-A52391D95A19}] => (Allow) E:\Gry\Steam Games\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{A4B6D70E-9424-4EC3-BE83-1014A604C2AE}] => (Allow) E:\Gry\Steam Games\common\H1Z1 King of the Kill\LaunchPad.exe ==================== Punkty Przywracania systemu ========================= 01-06-2016 05:09:12 IIF_MSI 01-06-2016 09:14:20 Windows Update 01-06-2016 10:21:05 Punkt Kontrolny 2 02-06-2016 16:06:39 1 03-06-2016 19:22:37 Zainstalowany program DirectX 03-06-2016 21:38:40 Test 08-06-2016 23:01:33 Windows Update ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (06/08/2016 11:48:10 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (06/08/2016 11:46:20 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: CompMgmtLauncher.exe, wersja: 6.3.9600.17415, sygnatura czasowa: 0x5450508c Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00000059a26ace0e Identyfikator procesu powodującego błąd: 0x250c Godzina uruchomienia aplikacji powodującej błąd: 0xCompMgmtLauncher.exe0 Ścieżka aplikacji powodującej błąd: CompMgmtLauncher.exe1 Ścieżka modułu powodującego błąd: CompMgmtLauncher.exe2 Identyfikator raportu: CompMgmtLauncher.exe3 Pełna nazwa pakietu powodującego błąd: CompMgmtLauncher.exe4 Identyfikator aplikacji względem pakietu powodującego błąd: CompMgmtLauncher.exe5 Error: (06/08/2016 11:36:34 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: WmiApRplC:\Windows\system32\wbem\wmiaprpl.dll8 Error: (06/08/2016 11:36:34 PM) (Source: PerfNet) (EventID: 2004) (User: ) Description: Error: (06/08/2016 11:36:34 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: MSDTCC:\Windows\system32\msdtcuiu.DLL8 Error: (06/08/2016 11:36:34 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: LsaC:\Windows\System32\Secur32.dll8 Error: (06/08/2016 11:36:34 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: ESENTC:\Windows\system32\esentprf.dll8 Error: (06/08/2016 11:36:34 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (06/08/2016 11:36:34 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: .NETFrameworkC:\Windows\system32\mscoree.dll8 Error: (06/08/2016 11:36:34 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: WmiApRplC:\Windows\system32\wbem\wmiaprpl.dll8 Dziennik System: ============= Error: (06/08/2016 11:48:06 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi WinRing0_1_2_0 z powodu następującego błędu: %%2 Error: (06/08/2016 11:46:35 PM) (Source: DCOM) (EventID: 10010) (User: DISCONNECT-PC) Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793} Error: (06/08/2016 02:35:31 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: DISCONNECT-PC) Description: 0x8000002a115\??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-2715714705-1761166565-38147098-1001-0-ntuser.dat Error: (06/08/2016 02:35:26 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: DISCONNECT-PC) Description: 0x8000002a115\??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-2715714705-1761166565-38147098-1001-0-ntuser.dat Error: (06/08/2016 02:17:01 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: DISCONNECT-PC) Description: 0x8000002a115\??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-2715714705-1761166565-38147098-1001-0-ntuser.dat Error: (06/08/2016 02:16:56 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: DISCONNECT-PC) Description: 0x8000002a115\??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-2715714705-1761166565-38147098-1001-0-ntuser.dat Error: (06/07/2016 11:50:01 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi WinRing0_1_2_0 z powodu następującego błędu: %%2 Error: (06/07/2016 11:48:28 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 23:09:15 na ‎2016-‎06-‎07 było nieoczekiwane. CodeIntegrity: =================================== Date: 2016-06-08 23:47:29.350 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-08 10:05:08.623 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\OldNewExplorer\OldNewExplorer64.dll that did not meet the Windows signing level requirements. Date: 2016-06-08 09:55:30.703 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\OldNewExplorer\OldNewExplorer64.dll that did not meet the Windows signing level requirements. Date: 2016-06-08 09:35:41.570 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\OldNewExplorer\OldNewExplorer64.dll that did not meet the Windows signing level requirements. Date: 2016-06-08 07:33:10.285 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\OldNewExplorer\OldNewExplorer64.dll that did not meet the Windows signing level requirements. Date: 2016-06-08 07:21:30.474 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\OldNewExplorer\OldNewExplorer64.dll that did not meet the Windows signing level requirements. Date: 2016-06-08 07:14:31.611 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\OldNewExplorer\OldNewExplorer64.dll that did not meet the Windows signing level requirements. Date: 2016-06-08 03:13:36.214 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\OldNewExplorer\OldNewExplorer64.dll that did not meet the Windows signing level requirements. Date: 2016-06-07 23:48:29.162 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-07 03:52:29.585 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\OldNewExplorer\OldNewExplorer64.dll that did not meet the Windows signing level requirements. ==================== Statystyki pamięci =========================== Procesor: Intel(R) Core(TM) i7-2600K CPU @ 3.40GHz Procent pamięci w użyciu: 31% Całkowita pamięć fizyczna: 16351.15 MB Dostępna pamięć fizyczna: 11147.09 MB Całkowita pamięć wirtualna: 32735.15 MB Dostępna pamięć wirtualna: 26165.3 MB ==================== Dyski ================================ Drive c: (SSD System) (Fixed) (Total:232.37 GB) (Free:154.05 GB) NTFS Drive d: (HDD Media) (Fixed) (Total:1862.89 GB) (Free:621.67 GB) NTFS Drive e: (HDD Games) (Fixed) (Total:1862.89 GB) (Free:546.25 GB) NTFS ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (Size: 232.9 GB) (Disk ID: 75C407B4) Partition: GPT. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 0A2B0A2C) Partition: GPT. ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 0A2B0A2B) Partition: GPT. ==================== Koniec Addition.txt ============================