Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-08-2016
- Ran by T-BAG (2016-08-06 20:39:47)
- Running from C:\Users\T-BAG\Downloads
- Windows 7 Home Premium Service Pack 1 (X64) (2014-05-15 04:04:38)
- Boot Mode: Normal
- ==========================================================
- ==================== Accounts: =============================
- Administrator (S-1-5-21-452096055-1060168818-2339660257-500 - Administrator - Disabled)
- Guest (S-1-5-21-452096055-1060168818-2339660257-501 - Limited - Disabled) => C:\Users\Guest
- T-BAG (S-1-5-21-452096055-1060168818-2339660257-1000 - Administrator - Enabled) => C:\Users\T-BAG
- theodore bagwell (S-1-5-21-452096055-1060168818-2339660257-1002 - Limited - Enabled) => C:\Users\theodore bagwell
- ==================== Security Center ========================
- (If an entry is included in the fixlist, it will be removed.)
- AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
- AS: Comodo Defense+ (Disabled - Up to date) {4BDD6856-AF0D-06BD-38AB-8A0FE39860CC}
- FW: COMODO Firewall (Enabled) {C8870897-C358-086B-2944-184866CC6D0A}
- ==================== Installed Programs ======================
- (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
- Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated)
- Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
- AI Suite 3 (HKLM-x32\...\{D46DA5F0-25AD-4B77-98DA-6DD6AF39FBD9}) (Version: 1.00.56 - ASUSTeK Computer Inc.)
- Akamai NetSession Interface (HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\Akamai) (Version: - Akamai Technologies, Inc)
- Akamai NetSession Interface (HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Akamai) (Version: - Akamai Technologies, Inc)
- Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
- Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
- Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
- ASUS Product Register Program (HKLM-x32\...\{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.025 - ASUSTek Computer Inc.)
- CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform)
- COMODO Firewall (HKLM\...\{2736B6BD-31EC-4FC8-A48C-F0A5C914C0B6}) (Version: 7.0.55655.4142 - COMODO Security Solutions Inc.)
- Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
- Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve)
- CPUID CPU-Z 1.69.2 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
- D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
- DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
- Dota 2 (HKLM\...\Steam App 570) (Version: - Valve)
- Dying Light (HKLM\...\Steam App 239140) (Version: - Techland)
- EVGA PrecisionX 16 (HKLM-x32\...\{2183FCC1-07DA-44D5-97FB-EEC4EBA57D7B}) (Version: 5.3.1 - EVGA Corporation)
- Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
- Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
- Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
- Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
- Grand Theft Auto IV (x32 Version: 1.0.0011.131 - Rockstar Games Inc.) Hidden
- HP Deskjet 2540 series Basic Device Software (HKLM\...\{6A79CD11-0C1C-4E24-A8C6-46A02F680346}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
- Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
- Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
- Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
- iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
- LenovoUsbDriver 1.0.9 (HKLM-x32\...\LenovoUsbDriver) (Version: 1.0.9 - Lenovo)
- Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
- Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
- Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
- Microsoft Build Tools 2015 (HKLM-x32\...\{d21da0dd-4ba4-4838-ba58-64cf7a77131a}) (Version: 14.0.23107.10 - Microsoft Corporation)
- Microsoft Games for Windows - LIVE (HKLM-x32\...\{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}) (Version: 3.1.186.0 - Microsoft Corporation)
- Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
- Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
- Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
- Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
- Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
- Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
- Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
- Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
- Microsoft Word 2010 (HKLM\...\Office14.WORD) (Version: 14.0.7015.1000 - Microsoft Corporation)
- MiniTool Power Data Recovery Free Edition 7.0 (HKLM\...\MiniTool Power Data Recovery Free Edition_is1) (Version: - MiniTool Solution Ltd.)
- MotioninJoy Gamepad tool 0.7.0000 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.7.0000 - www.motioninjoy.com)
- Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
- Mozilla Firefox 47.0.1 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 47.0.1 (x86 en-GB)) (Version: 47.0.1 - Mozilla)
- Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0.1.6018 - Mozilla)
- NVIDIA 3D Vision Controller Driver 364.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 364.44 - NVIDIA Corporation)
- NVIDIA 3D Vision Driver 364.51 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 364.51 - NVIDIA Corporation)
- NVIDIA 3D Vision Video Player (HKLM-x32\...\{7BF8BD5F-EE1A-4DB1-B810-A4AE1D34530E}) (Version: 1.7.2 - NVIDIA Corporation)
- NVIDIA GeForce Experience 2.11.2.55 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.11.2.55 - NVIDIA Corporation)
- NVIDIA Graphics Driver 364.51 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 364.51 - NVIDIA Corporation)
- NVIDIA HD Audio Driver 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
- NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
- Opera Stable 39.0.2256.48 (HKLM-x32\...\Opera 39.0.2256.48) (Version: 39.0.2256.48 - Opera Software)
- Perfect Uninstaller v6.3.4.0 (HKLM\...\Perfect Uninstaller_is1) (Version: - www.PerfectUninstaller.com)
- qBittorrent 3.3.5 (HKLM-x32\...\qBittorrent) (Version: 3.3.5 - The qBittorrent project)
- Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.19.23944 - Razer Inc.)
- Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.67.1226.2012 - Realtek)
- Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7541 - Realtek Semiconductor Corp.)
- Recuva (HKLM\...\Recuva) (Version: 1.52 - Piriform)
- Sandboxie 4.16 (64-bit) (HKLM\...\Sandboxie) (Version: 4.16 - Sandboxie Holdings, LLC)
- Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-001B-0000-1000-0000000FF1CE}_Office14.WORD_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
- Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
- SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden
- SHIELD Wireless Controller Driver (Version: 2.11.2.55 - NVIDIA Corporation) Hidden
- Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation)
- Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.109 - Skype Technologies S.A.)
- SMAC 2.0 (HKLM-x32\...\SMAC 2.0) (Version: - )
- Smartflix (HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\smartflix) (Version: 1.3.1 - Smartflix)
- Smartflix (HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\smartflix) (Version: 1.3.1 - Smartflix)
- SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
- Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
- Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)
- Team Fortress 2 (HKLM\...\Steam App 440) (Version: - Valve)
- TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
- The Official DVSA Theory Test for Car Drivers (HKLM-x32\...\{E9DF3ECB-00F3-4992-955D-ABC9AAD23BFA}) (Version: 1.00.0000 - TSO)
- Transmission-Qt (HKLM\...\Transmission-Qt) (Version: 2.84.4 - Transmission)
- VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
- Vulkan Run Time Libraries 1.0.3.0 (HKLM\...\VulkanRT1.0.3.0) (Version: 1.0.3.0 - LunarG, Inc.)
- Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
- WinRAR 5.10 beta 4 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH)
- Wireshark 1.12.2 (64-bit) (HKLM-x32\...\Wireshark) (Version: 1.12.2 - The Wireshark developer community, hxxp://www.wireshark.org)
- WTFast 3.5 (HKLM-x32\...\{12B4121D-5221-4AFC-9EDC-63B0CA139856}_is1) (Version: 3.5.9.511 - Initex & AAA Internet Publishing)
- Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team)
- ==================== Custom CLSID (Whitelisted): ==========================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- ==================== Scheduled Tasks (Whitelisted) =============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- Task: {01F38556-02DD-41F2-9A6B-14ACD6D48FA3} - System32\Tasks\Run LSI => C:\Program Files (x86)\LSI\LoLSummonerInfo.exe
- Task: {11B771FE-94B3-4E75-9B08-E98736CFDF73} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.)
- Task: {16EB17AF-4346-4ABB-840E-EB514C781B7A} - System32\Tasks\{0C108B8C-FA4E-4F68-B626-D4805E6BCFEF} => Firefox.exe hxxp://ui.skype.com/ui/0/7.18.85.111/en/abandoninstall?page=tsProgressBar
- Task: {1B9F8128-7ECB-4EF1-97C3-1CE961F65336} - System32\Tasks\ASUS\Ez Update => C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe [2015-07-12] ()
- Task: {26333617-A147-492A-892F-840B61C9EA9B} - System32\Tasks\ASUS\USB 3.0 Boost Service => C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvr.exe [2015-07-12] (ASUSTeK Computer Inc.)
- Task: {29B45394-910F-4C92-9443-0A1B07886CEA} - System32\Tasks\ASUS\ASUS WiFi GO! Server Execute => C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\WiFi GO! Server.exe [2015-07-12] (ASUSTeK Computer Inc.)
- Task: {3305219C-5844-4C5A-892C-741E660079C4} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2013-08-27] (ASUSTek Computer Inc.)
- Task: {537FF01F-075E-401D-89ED-BF6A490BC48F} - System32\Tasks\ASUS\ASUS DIPAwayMode => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe [2015-07-12] ()
- Task: {767F3CB7-6A34-4B83-BACB-2A5EA871AF91} - System32\Tasks\{40670C3B-1AD8-413C-BD87-1089B8E827AC} => Firefox.exe hxxp://ui.skype.com/ui/0/7.6.0.105/en/abandoninstall?source=lightinstaller&page=tsProgressBar
- Task: {801F3D7B-2609-431B-A338-1B7479D15CD0} - System32\Tasks\{BAE2BBD2-FC15-4385-8808-0855E2582904} => pcalua.exe -a "C:\Program Files (x86)\KLC\SMAC\UNWISE.EXE" -c C:\Program Files (x86)\KLC\SMAC\INSTALL.LOG
- Task: {806304F3-CCB0-4DC2-9623-097E6E1E35DF} - System32\Tasks\{900A653E-8A5F-4E04-B22B-C153CD3B1BFF} => pcalua.exe -a C:\Users\T-BAG\Downloads\ArticGunZ_Installer_23052014(1).exe
- Task: {8C0D2B97-B263-4904-B57E-ADCCD4544055} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-06] (Google Inc.)
- Task: {93E72B40-A7F2-4B44-A5A9-90304B2E6213} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
- Task: {A970EA92-E14D-419F-914C-22E7D606E56A} - System32\Tasks\{D075FA6B-62CC-4670-9858-329EDB7EEFE8} => pcalua.exe -a C:\Users\T-BAG\AppData\Roaming\DesktopIconForAmazon\desktopicon-chip-amazon.exe -c uninstall
- Task: {BE7912D2-EA7F-49A8-9867-71C520E29C7B} - System32\Tasks\Opera scheduled Autoupdate 1467742256 => C:\Program Files (x86)\Opera\launcher.exe [2016-08-05] (Opera Software)
- Task: {BF29A337-674B-44CB-8652-A51FC9874823} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-11-30] (Piriform Ltd)
- Task: {CBE2D75B-2171-40C7-B2F2-048AC65C2669} - System32\Tasks\ASUS\ASUS AISuiteIII => C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe [2015-07-12] (ASUSTeK Computer Inc.)
- Task: {D9E7F23B-B0EC-454B-9723-855C37156F09} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-07-29] (Adobe Systems Incorporated)
- Task: {E26CA3EA-BD61-4B84-9ADB-876ECA16FCEC} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.)
- Task: {E448BF00-FAB0-4861-A4BA-98C2AAF85D6D} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-02-04] (COMODO)
- Task: {E55F2CE2-7E33-4018-A44B-B7730CEF6810} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-08-06] (Adobe Systems Incorporated)
- Task: {EDFF6B4C-D1E1-4563-85A7-415ACC915690} - System32\Tasks\ASUS\ASUS Network iControl Help Execute => C:\Program Files (x86)\ASUS\AI Suite III\Network iControl\NetSvcHelp\NetSvcHelpEntry.exe [2015-07-12] (ASUSTeK Computer Inc.)
- Task: {F6CBE30A-CCF2-4A54-A72D-1E0D9D9DD3F4} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-02-04] (COMODO)
- Task: {F9749A82-793A-4FFF-A2AB-DC053A43F68C} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-02-04] (COMODO)
- Task: {FF305FA9-CABC-4407-B092-9361DE1ED1D4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-06] (Google Inc.)
- (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
- Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
- Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- ==================== Shortcuts =============================
- (The entries could be listed to be restored or removed.)
- Shortcut: C:\Users\T-BAG\AppData\Local\Microsoft\Windows\GameExplorer\{385AE3CE-F9B1-44A3-BF19-4410196C846E}\SupportTasks\1\Support.lnk -> hxxp://techsupport.ea.com/
- Shortcut: C:\Users\T-BAG\AppData\Local\Microsoft\Windows\GameExplorer\{385AE3CE-F9B1-44A3-BF19-4410196C846E}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.needforspeed.com/
- Shortcut: C:\Users\T-BAG\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.com
- ==================== Loaded Modules (Whitelisted) ==============
- 2014-05-15 05:19 - 2013-05-07 08:45 - 00936728 ____N () C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
- 2016-08-06 20:19 - 2016-08-06 20:19 - 21070920 _____ () C:\Users\T-BAG\Downloads\RogueKiller (1).exe
- 2014-05-15 05:34 - 2013-09-03 16:52 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
- 2014-05-15 05:19 - 2016-08-06 20:18 - 00028672 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\PEbiosinterface32.dll
- 2014-05-15 05:19 - 2013-05-07 08:45 - 00104448 ____N () C:\Program Files (x86)\ASUS\AXSP\1.01.02\ATKEX.dll
- 2016-08-05 17:50 - 2016-08-03 01:24 - 01771336 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libglesv2.dll
- 2016-08-05 17:50 - 2016-08-03 01:23 - 00094024 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libegl.dll
- 2014-07-31 12:16 - 2014-07-31 12:16 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
- 2014-07-31 12:16 - 2014-07-31 12:16 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
- ==================== Alternate Data Streams (Whitelisted) =========
- (If an entry is included in the fixlist, only the ADS will be removed.)
- AlternateDataStreams: C:\Eula.txt:$CmdZnID [26]
- AlternateDataStreams: C:\Volumeid.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Volumeid.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Program Files (x86)\fraps.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Program Files (x86)\fraps64.dat:$CmdTcID [64]
- AlternateDataStreams: C:\Program Files (x86)\uninstall.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\RtlExUpd.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\WLXPGSS.SCR:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\aaclient.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\AcpiServiceVnA64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\adprovider.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\adtschema.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\AERTAC64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\AERTAR64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\apisetschema.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\appinfo.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\atmfd.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\atmlib.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\AudioEng.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\AUDIOKSE.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\audioLibVc.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\AudioSes.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\audiosrv.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\authui.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\browcli.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\browser.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\capiprovider.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\cdd.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\cdosys.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\certenc.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\certutil.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\cngprovider.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\comctl32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\CONEQMSAPOGUILibrary.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\conhost.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\consent.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\CPFilters.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\credssp.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\crypt32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\cryptnet.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\cryptsvc.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\cscript.exe:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\csrsrv.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\CX64APO.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\dciman32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DDPA64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DDPA64F3.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DDPD64A.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DDPD64AF3.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DDPO64A.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DDPO64AF3.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DDPP64A.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DDPP64AF3.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\dfshim.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\dimsroam.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\dnsapi.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\dnscacheugc.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\dnsrslvr.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DolbyDAX2APOProp.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DolbyDAX2APOv201.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DolbyDAX2APOv211.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\dpapiprovider.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\dpnet.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSBassEnhancementDLL64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSBoostDLL64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSGainCompensatorDLL64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSGFXAPO64.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\DTSGFXAPONS64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSLFXAPO64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSLimiterDLL64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSNeoPCDLL64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSS2HeadphoneDLL64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSS2SpeakerDLL64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSSymmetryDLL64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSU2PGFX64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSU2PLFX64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSU2PREC64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\DTSVoiceClarityDLL64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\EncDec.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\EncDump.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\FMAPO64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\fontsub.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\FWPUCLNT.DLL:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\FXSCOVER.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\gdi32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\HiFiDAX2API.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\hpinkcoiC211.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\hpinkinsC211.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\hpinkstsC211LM.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\HPScanTRDrv_DJ2540.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\HPWia2_DJ2540.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\icardagt.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\icardres.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\ICEsoundAPO64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\IEUDINIT.EXE:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\IKEEXT.DLL:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\imagehlp.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\IMJP10K.DLL:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\inetcomm.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\infocardapi.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\IntelSSTAPO.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\IntelSstCApoPropPage.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\KAAPORT64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\kd1394.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\kdcom.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\kdusb.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\kerberos.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\kernel32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\KernelBase.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\localspl.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\lpk.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\lsasrv.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\lsass.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO20.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO30.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO4064.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO5064.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO6064.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxAudioAPO7064.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxAudioAPOShell64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxAudioEQ64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxAudioRealtek64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxSpeechAPO64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxVoiceAPO2064.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxVoiceAPO3064.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxVoiceAPO4064.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MaxxVolumeSDAPO.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\mfc42.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\mfc42u.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MISS_APO.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\mpg2splt.ax:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\MRT.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\msaudite.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\mscorier.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\mscories.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\msi.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\msihnd.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\mstsc.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\mstscax.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\msv1_0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\msvcrt.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\msxml3.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\msxml3r.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\msxml6.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\msxml6r.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\NAHIMICAPOlfx.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\NahimicAPONSControl.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\NAHIMICV2apo.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\ncrypt.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\ncsi.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\netapi32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nlaapi.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nshwfp.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\ntvdm64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvapi64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvaudcap64v.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvcuda.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvcuvid.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvd3dumx.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvdispco6435306.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvdispco6436175.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvdispco6436451.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvdispgenco6435306.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvdispgenco6436175.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvdispgenco6436451.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvEncodeAPI64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvfatbinaryLoader.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\NvFBC64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvhdagenco6420103.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\nvhdap64.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\NvIFR64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\NvIFROpenGL.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvinitx.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvoglshim64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvoglv64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvopencl.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvptxJitCompiler.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvumdshimx.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvvsvc.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\nvwgf2umx.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\objsel.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\odbccp32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\odbccr32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\odbccu32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\odbctrac.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\oleacc.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\oleaut32.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\OpenCL.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\osk.exe:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\packager.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\pku2u.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\poqexec.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\profsvc.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\psisdecd.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\psisrndr.ax:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\qdvd.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\qedit.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\quartz.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\R4EEA64A.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\R4EED64A.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\R4EEG64A.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\R4EEL64A.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\R4EEP64A.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\rastls.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\RCoInstII64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\rdpcore.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\rdpcorekmts.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\rdpwsx.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\rdrmemptylst.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\RltkAPO64.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\RP3DAA64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\RP3DHT64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\rpcrt4.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\rstrui.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\RTCOM64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\RtDataProc64.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\RTEED64A.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\RTEEG64A.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\RTEEL64A.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\RTEEP64A.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\RtkApi64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\RtkCfg64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\RtkCoLDR64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\RtlCPAPI64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\RtPgEx64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\RTSnMg64.cpl:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\sbe.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\schannel.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\scrrun.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SEAPO64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SECOMN64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\secur32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SEHDRA64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SFAPO64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SFCOM64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SFNHK64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SFSS_APO.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\shdocvw.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\shell32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\sl3apo64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\slcnt64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\slprp64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\sltech64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\smss.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SRAPO64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\srclient.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SRCOM.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SRCOM64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\srcore.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SRRPTR64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SRSHP64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SRSTSH64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SRSTSX64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\SRSWOW64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\sspicli.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\sspisrv.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\synceng.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\tadefxapo.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\tadefxapo264.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\taskhost.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\tepeqapo64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\termsrv.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\tosade.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\tosasfapo64.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\toseaeapo64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\tossaeapo64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\tossaemaxapo64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\tsgqec.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\TSpkg.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\TSWbPrxy.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\TsWpfWrp.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\ucrtbase.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\umpnpmgr.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\usp10.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\vulkaninfo-1-1-0-3-0.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\vulkaninfo.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\WavesGUILib64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\wdigest.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\webio.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\wer.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\win32k.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\win32spl.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\wincredprovider.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\winload.efi:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\winload.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\winlogon.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\winresume.efi:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\winresume.exe:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\winsrv.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\winsta.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\wintrust.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\wmi.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\WMVDECOD.DLL:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\wow64.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\wow64cpu.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\wow64win.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\wscript.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\wshom.ocx:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\WTFastDrv.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\xvid.ax:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\xvidcore.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\xvidvfw.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\YamahaAE.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\YamahaAE2.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\SysWOW64\aaclient.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\adprovider.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\adtschema.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\apisetschema.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\atmfd.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\SysWOW64\atmlib.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\AudioEng.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\AUDIOKSE.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\AudioSes.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\authui.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\browcli.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\capiprovider.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\cdosys.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\SysWOW64\certenc.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\certutil.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\cfgmgr32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\cngprovider.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\comctl32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\CPFilters.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\credssp.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\crypt32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\cryptnet.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\cryptsvc.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\cscript.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\dciman32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\devobj.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\devrtl.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\dfshim.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\SysWOW64\dimsroam.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\dnsapi.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\dnscacheugc.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\dpapiprovider.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\dpnet.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\drvinst.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\EncDec.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerInstaller.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\fontsub.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\FWPUCLNT.DLL:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\gdi32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\icardagt.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\icardres.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\imagehlp.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\IMJP10K.DLL:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\inetcomm.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\infocardapi.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\instnm.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\java.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\javaw.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\javaws.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\kerberos.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\kernel32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\KernelBase.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\lpk.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\mfc42.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\mfc42u.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\mpg2splt.ax:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\msaudite.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\MSCOMCTL.OCX:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\mscorier.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\mscories.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\msi.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\msihnd.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\mstsc.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\mstscax.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\msv1_0.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\msvcrt.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\msxml3.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\msxml3r.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\msxml6.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\msxml6r.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\ncrypt.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\ncsi.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\netapi32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nlaapi.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nshwfp.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\ntkrnlpa.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\ntoskrnl.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\ntvdm64.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvapi.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvaudcap32v.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvcompiler.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvcuda.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvcuvid.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvd3dum.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvEncodeAPI.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvfatbinaryLoader.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\NvFBC.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\NvIFR.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\NvIFROpenGL.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvinit.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvoglshim32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvoglv32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvopencl.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvptxJitCompiler.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvStreaming.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvumdshim.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\nvwgf2um.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\objsel.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\odbccp32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\odbccr32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\odbccu32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\odbcjt32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\odbctrac.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\oleacc.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\oleaut32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\OpenCL.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\osk.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\packager.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\pku2u.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\poqexec.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\psisdecd.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\psisrndr.ax:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\qdvd.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\qedit.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\quartz.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\rastls.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\rdpcore.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\RICHTX32.OCX:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\RltkAPO.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\rpcrt4.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\sbe.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\schannel.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\scrrun.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\SECOMN32.DLL:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\secur32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\setup16.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\SFCOM.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\shdocvw.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\shell32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\SPORDER.DLL:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\srclient.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\SRCOM.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\sspicli.dll:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\SysWOW64\synceng.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\tsgqec.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\TSpkg.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\TsWpfWrp.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\ucrtbase.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\user.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\usp10.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\vcamp140.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\vulkaninfo-1-1-0-3-0.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\vulkaninfo.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\wdigest.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\webio.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\wer.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\win32spl.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\wincredprovider.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\winsta.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\wintrust.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\wmi.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\WMVDECOD.DLL:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\wow32.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\wscript.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\wshom.ocx:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\WTFastDrv.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\xvid.ax:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\xvidcore.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\xvidvfw.dll:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\afd.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\bowser.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\cng.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\drmk.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\dxgkrnl.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\dxgmms1.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\fs_rec.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\FWPKCLNT.SYS:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\hidclass.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\hidparse.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\ksecdd.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\ksecpkg.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\mbam.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\mbamchameleon.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\mrxdav.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb10.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb20.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\mwac.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\ndisrd.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\netio.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\ntfs.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\nvhda64v.sys:$CmdTcID [130]
- AlternateDataStreams: C:\Windows\system32\Drivers\nvlddmkm.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\nvvad64v.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\partmgr.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\portcls.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\rdpwd.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\RTKVHD64.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\rzendpt.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\rzudd.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\srv.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\srv2.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\srvnet.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\tap0901.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\taphss6.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\tcpip.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\tdtcp.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\tssecsrv.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\usb8023.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\usbccgp.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\usbcir.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\usbd.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\usbehci.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\usbhub.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\usbport.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\usbscan.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\system32\Drivers\Wdf01000.sys:$CmdTcID [64]
- AlternateDataStreams: C:\Windows\SysWOW64\Drivers\ASUSFILTER.sys:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\ffmpeg.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\ffmpeg.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\1456207506390.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\1459344115109.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\1459363772106.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\1459367823493.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\1462226228486.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\200_s.gif:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\3451044-1607572-1593220_36.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\7ffaef96.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\7ffaef96.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\;_;.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Adolf_Hitler_cropped_restored.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\americann.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\americans.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Apply-for-a-licence-to-drive-a-private-hire-vehicle.pdf:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\assassination-of-jesse-james-by-the-coward-robert-ford.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\BALONGREYJOY.png:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\banjaminbuttonart.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\bDWZjOAZgquuLg473VZeDBMmwq8NIAE.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Changelog.txt:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\cinema.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\ComplX Multihack v0.7.4.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\ComplX Multihack v0.7.4.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\dasLebenderAnderen.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\davidgalemovie.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\deadmentellnotales.png:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\disgusting.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Drastic1 Economics Questions.doc:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Drastic1 Economics Questions.doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Economics submission111.pdf:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Ethan_Suplee_0042.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\EVGA_PrecisionX_16_Setup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\fargo_tv_on_fx.0_cinema_1200.0.png:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\file_118510_0_theleftoversart.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\fingerlittle.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\FwPogGm7Jht8qoGdvoKfkSR459n8hWk8VZK4K4Nsgg7ZgNOI5E2u67hjUMjXPfLktlZHUCIrQO.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\GANYcWYZaZSXLA9c9q46ZiLWLRrp1Tdh1dDom5abWVM1mOnSSaemEPHVmnCAcfY8thWf.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\glowesp.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\glowesp.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\gollumx2.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\h0m0.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\haywire_zpsa8a2e574.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\hectr.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Image__16_.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Image__17_.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Image__34_.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\index.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Jack.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\jake.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\jinkwon.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\JVC_Projector1.png:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\kingstanniss.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\KOKO.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\laptop-repairs-colchester-essex.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\leftovers.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\lgvx5200.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\logan-lerman-alexandra-nyc-02.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\M0rgan.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\M8LbL7Od7GMw9nJt2I4I7b1k3rSsgPWASZ1kAKdSpV2o6jB6SMLI4DMh8YZQb.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\mi31Gd3PCZ92XcoQtm1vn45vjlms7RYYVEqF85Jra0fPFTWAgwNMkGjje5ESo7Ii.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Michael-Douglas-011.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\mma_fedor_emelianenko1_576.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\morgannnn.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\NHSfrbh3vOZLdQU82LTrgJdLauVucXnTUS8Z2TsFsm60kk4BkFJ520Y5a86t7jMNY7nAJr6UPDwrD.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\PAKeTdwDIvEAPmAlgWv3TbdffTmJPwX9JQnto70IHpX5uwbldjtKGKBlUcv1nckIO7nvwDtZMdia4Zifo1cd3CowF2PC80Rb6Edo0dmQmJvaZXhsrG9m17FBEnfvlh.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\plasticsurgery.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\program.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\program.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\ray-velcoro-true-detective.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\ready.png:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\render-servlet.gif:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\RIP.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Robert-Knepper.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\rover1.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Ruse-Cohle----hes-here-to-012.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\rust.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Rustin_Cohle.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\sicario-640x480.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Snowman Desmond.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\spideyyyyyy.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\stannis.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\strike-team.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\sw.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\T-bagggggg.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\TD-Poster.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\the-shield.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\the-walking-dead-season-6-cci-key-art-1600x720.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\thecuriouscaseofbenjaminbutton.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\the_revenant_.png:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\true-detective-season-1.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\twin-towers-2_1817913c1.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\UNGRATEFUL APE.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\Velcoro.gif:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\vlcsnap-10684981.png:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\walking-dead.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Desktop\zzzzzzzzz.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\0006-64bit_Win7_Win8_Win81_Win10_R279.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\0006-64bit_Win7_Win8_Win81_Win10_R279.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\13 - 18 Northern Heidel Quarry.rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\1450399997915.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\1451522840606.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\3.9.1.133_20150210101242.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\353.06-desktop-win8-win7-winvista-64bit-international-whql.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\353.06-desktop-win8-win7-winvista-64bit-international-whql.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\358.50-desktop-win8-win7-winvista-64bit-international-whql.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\358.50-desktop-win8-win7-winvista-64bit-international-whql.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\361.75-desktop-win8-win7-winvista-64bit-international-whql.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\364.51-desktop-win8-win7-winvista-64bit-international-whql.exe:$CmdTcID [32]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\364.51-desktop-win8-win7-winvista-64bit-international-whql.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\3DVideoPlayer_4.5.4-Setup (1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\3DVideoPlayer_4.5.4-Setup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\563e6b69de686_12189834_10207820648815127_9137598878436018181_n_jpgohe99b0a80ccd1805910fdc95cbf4687aeoe56C2EF7B.910f31ab492e882e528581623c46301a:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\999F9EE9A7FAB310BC2F9C8031C31EADB1E424BE.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\AbitSmarter_mpgh.net.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC2510_Business_Management_Case_Study_April_12_2011.doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC2510_Business_Management_Exam_and_Answer.doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4013 Exam May Refer (1).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4013 Exam May Refer (2).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4013 Exam May Refer.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4013 May 2015 Refer Exam Answers (1).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4013 May 2015 Refer Exam Answers (2).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4013 May 2015 Refer Exam Answers (3).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4013 May 2015 Refer Exam Answers.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4017 (1).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4017HSupdated (1).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4017HSupdated.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4017_002_2013-14-T2-J_My_Glamour_Sage_Case_Study (1).doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4017_002_2013-14-T2-J_My_Glamour_Sage_Case_Study.doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4017_ABE_ Asst 1_Seminar_April 2016_issued (1).doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4017_ABE_ Asst 1_Seminar_April 2016_issued.doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC4017_ABE_Module Guide_2015-16_draft.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC5005 Employability Audit and Action Plan Students - Version 5 9 February 2015 (1).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC5005 Employability Audit and Action Plan Students - Version 5 9 February 2015 (2).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC5005 Employability Audit and Action Plan Students - Version 5 9 February 2015.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC5005_APPLICATION_FORM.doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC5005_Assessment_1_Portfolio (1).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC5005_Assessment_1_Portfolio.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC5006 Assignment Feedback Sarwar 1401512.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC5006 Case Study Latest.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC5006_C.B.M._Assignment_1_2015_16 (1).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ACC5006_C.B.M._Assignment_1_2015_16.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Ace_Stream_Media_3.0.12_VLC_1.1.12.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Ace_Stream_Media_3.1.2.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\AdwCleaner.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\AdwCleaner.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Agency.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Agency.pptx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\AION_GameforgeLiveSetup_EN.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Amity.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Answering Problem Questions (1).pptx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Answering Problem Questions.pptx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ArticGunZ_Installer_23052014(1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Assessment 2- Sage (1).doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Assessment 2- Sage (2).doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Assessment 2- Sage .doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Assignment:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\assignment.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\AutoHotkey104805_Install.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\avidemux_2.6.10_win64.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\avidemux_2.6.10_win64.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Batman_v_Superman_Dawn_of_Justice_(Deluxe)_(2016)_[320].zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Battle.net-Setup (1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Battle.net-Setup (1).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Battle.net-Setup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Battle.net-Setup.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\bdo-englishplease_setup.exe:$CmdTcID [130]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\bdo-englishplease_setup.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BDOTA_v0.1.0.2.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BDOTA_v0.1.0.2.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BDOViperRelease2.1.5.1.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Better Fishing v0.7g BETA.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BitTorrent.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BlackDesert64.rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BlackDesertOnlineCCMSetup_2016012602.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BlackDesertOnlineCCMSetup_2016012602.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BlackDesertOnlineInstall_10019.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BlackDesertOnlineInstall_10019.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BlackDesertOnlineInstall_10020.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BlackDesertOnlineInstall_10020.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BlackDesertOnlineSetup_20160216_1001 (1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BlackDesertOnlineSetup_20160216_1001 (1).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BlackDesertOnlineSetup_20160216_1001.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\BlackDesertOnlineSetup_20160216_1001.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Business_Management_Case_Study_Firebridge_Tyres.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Business_Process_Re-Engineering.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ccsetup512.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ccsetup512.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\cheatleak_mpgh.net.rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ChromeSetup (1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\CLAN_[001]_Aylius_2015-06-19_21-14-16_Mandolina.gzr:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\CLAN_[001]_Aylius_2015-06-19_21-14-16_Mandolina.gzr:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\CLAN_[002]_ShudaHadAv8_2015-06-22_18-56-48_WhiteIce.gzr:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\CLAN_[006]_Aylius_2015-06-19_21-17-17_Mandolina.gzr:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\CLAN__Cashual_20150530_143123_Children.gzr:$CmdTcID [130]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\CLAN__Dizaster_20150530_155523_Children.gzr:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ComplX Multihack v0.7.4_mpgh.net (1).zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ComplX Multihack v0.7.4_mpgh.net.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Contract Law.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Contract_of_Employment_and_Vicarious_Liability.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Correlation and Linear regression revision (1).pptx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Correlation and Linear regression revision.pptx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\covering letter (1).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\covering letter.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Curriculum Vitae (1).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Curriculum Vitae.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\DAMN IT 1.4_mpgh.net.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\deluge-1.3.12-1-win32-py2.6-setup.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Discharge of Contract.pptx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\discharge of Contracts.doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\DiscordSetup.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\DMT[001]_Elicar_2015-07-09_18-48-36.gzr:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\DMT[001]_Elicar_2015-07-09_18-49-48.gzr:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\DMT[013]_Elicar_2015-07-09_18-55-24.gzr:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\DMT[014]_Elicar_2015-07-09_18-56-12.gzr:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Drastic1.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Drastic1111111111111.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\DrvRadarPro_Setup.exe:$CmdTcID [32]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\DrvRadarPro_Setup.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\drw_trial.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\DUEL_Sunfire_2015-08-04_14-49-30.gzr:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\DUEL_Sunfire_2015-08-04_14-49-30.gzr:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\DUEL_Sunfire_2015-08-04_14-51-19.gzr:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\EagleGunz1.5_v3.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\EagleGunz1.5_v3.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Economics submission.pdf:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Employers Liability.pptx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Employment law.pptx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\EmsisoftEmergencyKit.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\esetsmartinstaller_enu.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Ev0 R8 HotFix Edition_mpgh.net_mpgh.net (1).rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Ev0 R8 HotFix Edition_mpgh.net_mpgh.net.rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Exam Case study scenario - ILA (1).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Exam Case study scenario - ILA (2).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Exam Case study scenario - ILA.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Exam_May_Refer_2013.14_FAF.doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\FirefoxPortable_35.0.1_English.paf.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\FreestyleGunZ.rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\friday assignment.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\FRST64.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\GeForce_Experience_v2.11.2.46.exe:$CmdTcID [32]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\GeForce_Experience_v2.11.2.46.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\giphy.gif:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\glowesp_mpgh.net.rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Greenshot-INSTALLER-1.2.6.7-RELEASE.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Greenshot-INSTALLER-1.2.6.7-RELEASE.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\HardDiskSerialNumberChanger.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\HardDiskSerialNumberChanger.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Helms BETA 2.3.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Hexe Sanctuary Patrol Brpate.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Hola-Setup-x64-1.8.328.exe:$CmdTcID [130]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Hola-Setup-x64-1.8.328.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\HSS-5.1.3-install-plain-773-plain.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\HSS-5.1.3-install-plain-773-plain.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\icq_rfrset.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\IE11-Windows6.1.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\illsbury_Ranger_-_EES_Spam.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\IMG_0097.JPG:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\IMG_0097.JPG:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\isoplex-setup-1.0.4.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\JRT (1).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\KCP-0.5.9.8_[3F4F9CB8].exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\LeagueofLegends_EUW_Installer_9_15_2014.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\LeagueofLegends_EUW_Installer_9_15_2014.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\LeagueSharp-update (1).exe:$CmdTcID [130]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\LeagueSharp-update (2).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\LeagueSharp-update(1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\LeagueSharp-update(2).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\LeagueSharp-update-2.0.14.15.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\LeagueSharp-update-2.0.14.15.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\LeagueSharp-update.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\libscout.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Loader (1).exe:$CmdTcID [32]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Loader (1).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Loader.exe:$CmdTcID [32]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Loader.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\lost.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\lpp(1).docx:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\lpp(1).docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\lpp.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\mbam-setup-2.0.4.1028.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\mbam-setup-2.1.6.1022.exe:$CmdTcID [130]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Medical report (1).doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Medical report.doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\MEGAsyncSetup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\MEGAsyncSetup.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Module Number.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\NDP451-KB2858728-x86-x64-AllOS-ENU.exe:$CmdTcID [32]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\NDP451-KB2858728-x86-x64-AllOS-ENU.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\NDP452-KB2901954-Web.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Nexus Mod Manager-0.52.3.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\OriginThinSetup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\OriginThinSetup.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\PatrolAreas_AL_3540.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\pdr7free.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\pdr7free.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\PerfectUninstaller_Setup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\PerfectUninstaller_Setup.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\personal_tutorialAvoiding_Plagiarism.pptx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\personal_tutoRIALSPPT_Using_Turnitin_Sept_2013_ACC_Final.ppt:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\pidgin-2.10.11.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\pidgin-otr-4.0.1.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\PlayBlackDesert.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\PolyESP_mpgh.net.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\program_mpgh.net (1).rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\program_mpgh.net.rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\ProxifierSetup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\psi-0.14-win-setup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\psi-0.15-win64-setup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\qbittorrent_3.3.5_setup.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Razer_Synapse_Framework_V1.18.19.23944.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\rcsetup152.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\RegSeeker2.57.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\render-servlet.gif:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\report sage (1).doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\report sage.doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Rhutum Brpate.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\RogueKiller (1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\RogueKiller (1).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\RogueKiller.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SafariSetup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SafariSetup.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\sage-2016-01-18.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SandboxieInstall.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\scanned-Sarwar%2c Hamza-20160513162252.pdf:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\scanned-Sarwar%2c Hamza-20160513162411.pdf:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Seminar Answer.pdf:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (1).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (2).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (2).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (3).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (3).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (4).exe:$CmdTcID [130]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (4).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (5).exe:$CmdTcID [130]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (5).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (6).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (6).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (7).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup (7).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup_galaxy_1.0.2.958.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup_galaxy_1.0.2.958.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup_the_witcher_3_wild_hunt_2.0.0.28(1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup_the_witcher_3_wild_hunt_2.0.0.28(1).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup_the_witcher_3_wild_hunt_2.0.0.28.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\setup_the_witcher_3_wild_hunt_2.0.0.28.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SE_mpgh.net (1).rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SE_mpgh.net (2).rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SE_mpgh.net.rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Silverlight_x64(1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Silverlight_x64.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SkypeSetup(2).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SkypeSetup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SkypeSetupFull(1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SkypeSetupFull(2).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SkypeSetupFull.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SkypeWebPlugin-3.2.0.23388.msi:$CmdTcID [130]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SkypeWebPlugin.msi:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\smac20_setup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\smac20_setup.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SmartflixSetup(1).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SmartflixSetup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SmartflixSetup.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Sniper.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Statement 30-NOV-15 AC 00770493.PDF:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Statement 30-OCT-15 AC 00770493.PDF:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Streaming-0.6.1-py2.7.egg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\SwitchVPN.msi:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Sykotik Ranger - Sykotik.rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Sykotik Wizard.rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Sykotik_GrinderV2.6.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Sykotik_GrinderV2.7 (1).zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Sykotik_GrinderV2.7.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Sykotik_Ranger_-_Intermediate (2).zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\TaskManagerFix.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\TCPView.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\tdsskiller (1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\tdsskiller (1).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\tdsskiller.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\TeamSpeak3-Client-win64-3.0.16.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\TeamViewer_Setup_en-hys(1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\TeamViewer_Setup_en-hys.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Termination of Employment.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\TERMS OF A CONTRACT.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\thumbnail_render-servlet.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\TMACv6.0.7_Setup (1).zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\TMACv6.0.7_Setup.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\TOE Team Letter to Borr enc initial non 1-2 pack.PDF:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\torbrowser-install-4.0.2_en-US.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\torbrowser-install-5.0.6_en-US.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\TorchSetup-r20-n-bc.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\TorchSetup-r20-n-bc.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\torrentsTime-download.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Tort Law.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Transmission-Qt-2.84.4-x86_32-installer.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Transmission-Qt-2.84.4-x86_32-installer.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Treants BETA.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\TrentCaveElite.rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\undelete-360-setup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\UnknownPortal.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\UnknownPortal.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\v5final.rar:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Valkyrie 13 - 44.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\vc_redist.x64 (1).exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\vc_redist.x64 (1).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\vc_redist.x64 (2).exe:$CmdTcID [32]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\vc_redist.x64 (2).exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\vc_redist.x64.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\vc_redist.x64.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\vc_redist.x86.exe:$CmdTcID [130]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\vc_redist.x86.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\VirtualDub-1.10.4.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\VirtualdubFFMpegPlugin_1832.zip:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\VirtualdubFFMpegPlugin_1832.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\vlc-2.2.4-win32.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\volumeid (2).zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\volumeid.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\WatchoverTyrant 1.1.3.5 (1).zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\WatchoverTyrant 1.1.3.5 (2).zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\WatchoverTyrant 1.1.3.5 (3).zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\WatchoverTyrant 1.1.3.5 (4).zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\WatchoverTyrant 1.1.3.5.zip:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Week 14 Revision Answer (1).xlsx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Week 14 Revision Answer.xlsx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Week 14 Revision Question - Suspense.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Week_10_Partnerships.pptx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Week_11_Answers.doc:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Week_11_Partnerships_Questions.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Week_6_Tutorial_Questions.docx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Week_7_Slides_Accruals_and_Prepayments_2_.pptx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Week_7_Slides_Bad_Debts_Doubtful_Debts_and_Discounts_1_.pptx:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Windows6.1-KB2670838-x64.msu:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\winscp570setup.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Wireshark-win64-1.12.4.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\wlsetup-web.exe:$CmdTcID [32]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\wlsetup-web.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\WTFastSetup.3.5.9.511.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Xvid-1.3.2-20110601.exe:$CmdTcID [64]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\Xvid-1.3.2-20110601.exe:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr.prx.websiteproxy.co.uk.prx.websiteproxy.co.uk]batman.v.superman.dawn.of.justice.2016.ultimate.edition.1080p.web.dl.dd5.1.h264.rarbg (1).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr.prx.websiteproxy.co.uk.prx.websiteproxy.co.uk]batman.v.superman.dawn.of.justice.2016.ultimate.edition.1080p.web.dl.dd5.1.h264.rarbg.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]black.sails.s03e04.xxii.720p.stz.webrip.aac2.0.x264.ntb.rartv.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]black.sails.s03e06.xxiv.720p.stz.webrip.aac2.0.x264.ntb.rartv.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]captain.america.civil.war.2016.hd.tc.x264.ac3.cpg.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]deadpool.2016.hdts.x264.readnfo.exclusive.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]deadpool.2016.new.hd.telesync.v2.x264.cpg.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]game.of.thrones.s06e01.720p.hdtv.x264.sva.rartv (1).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]game.of.thrones.s06e01.720p.hdtv.x264.sva.rartv.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]game.of.thrones.s06e03.720p.hdtv.x264.avs.rartv.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]game.of.thrones.s06e04.720p.hdtv.x264.avs.rartv.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]game.of.thrones.s06e05.1080p.leaked.webrip.hevc.2ch.x265.1080p.hevc.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]game.of.thrones.s06e05.the.door.1080p.x264.sammy.hq.mp4.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]game.of.thrones.s06e06.720p.hdtv.x264.avs.rartv.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]game.of.thrones.s06e07.720p.hdtv.x264.avs.rartv.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]isobuster.pro.3.6.0.0.neosoft.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]isobuster.pro.3.7.multilingual.serial.4realtorrentz.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]master.and.commander.sfida.ai.confini.del.mare.2003.bdrip.1080p.x264.ita.eng.dts.carnil91.tntvillage.mkv.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]mr.robot.s01e03.720p.hdtv.x264.immerse.rartv (1).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]mr.robot.s01e03.720p.hdtv.x264.immerse.rartv.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]star.wars.episode.vii.the.force.awakens.2015.1080p.bluray.x264.dts.jyk (1).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]star.wars.episode.vii.the.force.awakens.2015.1080p.bluray.x264.dts.jyk (2).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]star.wars.episode.vii.the.force.awakens.2015.1080p.bluray.x264.dts.jyk (3).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]star.wars.episode.vii.the.force.awakens.2015.1080p.bluray.x264.dts.jyk.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]sympathy.for.mr.vengeance.2002.720p.brrip.x264.aac.mkv.zen.bud.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.flash.2014.s02e14.1080p.hdtv.x264.dimension.rartv.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.flash.2014.s02e14.720p.hdtv.x264.dimension.rartv.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.flash.2014.s02e20.hdtv.x264.lol.ettv.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.walking.dead.s06e14.hdtv.x264.killers.mp4.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (1).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (10).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (11).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (12).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (13).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (14).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (15).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (16).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (17).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (18).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (2).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (3).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (4).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (5).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (6).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (7).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (8).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (9).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.2.s02.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.3.s03.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (1).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.3.s03.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (2).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.3.s03.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr (3).torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\T-BAG\Downloads\[kat.cr]the.wire.season.3.s03.1080p.bluray.aac.5.1.10bit.x265.hevc.lion.utr.torrent:$CmdZnID [26]
- AlternateDataStreams: C:\Users\theodore bagwell\Desktop\download.jpg:$CmdZnID [26]
- AlternateDataStreams: C:\Users\theodore bagwell\Downloads\Firefox Setup Stub 35.0.1.exe:$CmdTcID [64]
- ==================== Safe Mode (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
- ==================== Association (Whitelisted) ===============
- (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
- ==================== Internet Explorer trusted/restricted ===============
- (If an entry is included in the fixlist, it will be removed from the registry.)
- IE trusted site: HKU\.DEFAULT\...\clonewarsadventures.com -> clonewarsadventures.com
- IE trusted site: HKU\.DEFAULT\...\freerealms.com -> freerealms.com
- IE trusted site: HKU\.DEFAULT\...\soe.com -> soe.com
- IE trusted site: HKU\.DEFAULT\...\sony.com -> sony.com
- IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
- IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
- IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
- IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
- IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
- IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
- IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
- IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
- IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
- IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
- IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
- IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
- IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
- IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
- IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
- IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
- IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
- IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
- IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
- IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com
- There are 7865 more sites.
- IE trusted site: HKU\S-1-5-19\...\clonewarsadventures.com -> clonewarsadventures.com
- IE trusted site: HKU\S-1-5-19\...\freerealms.com -> freerealms.com
- IE trusted site: HKU\S-1-5-19\...\soe.com -> soe.com
- IE trusted site: HKU\S-1-5-19\...\sony.com -> sony.com
- IE trusted site: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\clonewarsadventures.com -> clonewarsadventures.com
- IE trusted site: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\freerealms.com -> freerealms.com
- IE trusted site: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\soe.com -> soe.com
- IE trusted site: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\sony.com -> sony.com
- IE trusted site: HKU\S-1-5-20\...\clonewarsadventures.com -> clonewarsadventures.com
- IE trusted site: HKU\S-1-5-20\...\freerealms.com -> freerealms.com
- IE trusted site: HKU\S-1-5-20\...\soe.com -> soe.com
- IE trusted site: HKU\S-1-5-20\...\sony.com -> sony.com
- IE trusted site: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\clonewarsadventures.com -> clonewarsadventures.com
- IE trusted site: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\freerealms.com -> freerealms.com
- IE trusted site: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\soe.com -> soe.com
- IE trusted site: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\sony.com -> sony.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\clonewarsadventures.com -> clonewarsadventures.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\freerealms.com -> freerealms.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\hola.org -> hxxp://hola.org
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\soe.com -> soe.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\sony.com -> sony.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\007guard.com -> install.007guard.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\008i.com -> 008i.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\008k.com -> www.008k.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\00hq.com -> www.00hq.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\010402.com -> 010402.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\0scan.com -> www.0scan.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\1-2005-search.com -> www.1-2005-search.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\1-domains-registrations.com -> www.1-domains-registrations.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\1000gratisproben.com -> www.1000gratisproben.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\1001namen.com -> www.1001namen.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\100888290cs.com -> mir.100888290cs.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\100sexlinks.com -> www.100sexlinks.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\10sek.com -> www.10sek.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\12-26.net -> user1.12-26.net
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\12-27.net -> user1.12-27.net
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\123fporn.info -> www.123fporn.info
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\123moviedownload.com -> www.123moviedownload.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000\...\123simsen.com -> www.123simsen.com
- There are 7865 more sites.
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\clonewarsadventures.com -> clonewarsadventures.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\freerealms.com -> freerealms.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\hola.org -> hxxp://hola.org
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\soe.com -> soe.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\sony.com -> sony.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\007guard.com -> install.007guard.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\008i.com -> 008i.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\008k.com -> www.008k.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\00hq.com -> www.00hq.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\010402.com -> 010402.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\0scan.com -> www.0scan.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\1-2005-search.com -> www.1-2005-search.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\1-domains-registrations.com -> www.1-domains-registrations.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\1000gratisproben.com -> www.1000gratisproben.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\1001namen.com -> www.1001namen.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\100888290cs.com -> mir.100888290cs.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\100sexlinks.com -> www.100sexlinks.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\10sek.com -> www.10sek.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\12-26.net -> user1.12-26.net
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\12-27.net -> user1.12-27.net
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\123fporn.info -> www.123fporn.info
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\123moviedownload.com -> www.123moviedownload.com
- IE restricted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\123simsen.com -> www.123simsen.com
- There are 7865 more sites.
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\clonewarsadventures.com -> clonewarsadventures.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\freerealms.com -> freerealms.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\soe.com -> soe.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\sony.com -> sony.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\clonewarsadventures.com -> clonewarsadventures.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\freerealms.com -> freerealms.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\soe.com -> soe.com
- IE trusted site: HKU\S-1-5-21-452096055-1060168818-2339660257-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\sony.com -> sony.com
- ==================== Hosts content: ===============================
- (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
- 2009-07-14 03:34 - 2015-06-15 15:50 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
- ==================== Other Areas ============================
- (Currently there is no automatic fix for this section.)
- HKU\S-1-5-21-452096055-1060168818-2339660257-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\T-BAG\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
- HKU\S-1-5-21-452096055-1060168818-2339660257-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\T-BAG\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
- HKU\S-1-5-21-452096055-1060168818-2339660257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\theodore bagwell\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
- HKU\S-1-5-21-452096055-1060168818-2339660257-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
- DNS Servers: 156.154.70.22 - 156.154.71.23
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
- Windows Firewall is disabled.
- ==================== MSCONFIG/TASK MANAGER disabled items ==
- (Currently there is no automatic fix for this section.)
- MSCONFIG\Services: CmdAgent => 2
- MSCONFIG\Services: cmdvirth => 3
- MSCONFIG\Services: DrvRadarProSvc => 2
- MSCONFIG\Services: GalaxyCommunication => 3
- MSCONFIG\Services: iPod Service => 3
- MSCONFIG\Services: MBAMService => 2
- MSCONFIG\Services: nlsvc => 2
- MSCONFIG\Services: NvStreamNetworkSvc => 3
- MSCONFIG\Services: NvStreamSvc => 2
- MSCONFIG\Services: Razer Game Scanner Service => 2
- MSCONFIG\Services: SbieSvc => 2
- MSCONFIG\Services: SDScannerService => 2
- MSCONFIG\Services: SDUpdateService => 2
- MSCONFIG\Services: SDWSCService => 2
- MSCONFIG\Services: SkypeUpdate => 2
- MSCONFIG\Services: Steam Client Service => 3
- MSCONFIG\Services: TeamViewer => 2
- MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
- MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\T-BAG\AppData\Local\Akamai\netsession_win.exe"
- MSCONFIG\startupreg: ASUS WiFi GO! FileTransfer Execute => C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\WiFile\WiFileTransfer.exe
- MSCONFIG\startupreg: BCSSync => "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
- MSCONFIG\startupreg: BitTorrent => "C:\Users\T-BAG\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
- MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
- MSCONFIG\startupreg: COMODO Internet Security => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
- MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
- MSCONFIG\startupreg: GalaxyClient =>
- MSCONFIG\startupreg: Google Update => "C:\Users\T-BAG\AppData\Local\Google\Update\GoogleUpdate.exe" /c
- MSCONFIG\startupreg: GoogleChromeAutoLaunch_77A2A3352B8257029434DCA8264FAF29 => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
- MSCONFIG\startupreg: IAStorIcon => "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
- MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
- MSCONFIG\startupreg: NetLimiter => C:\Program Files\NetLimiter 3\NLClientApp.exe /tray
- MSCONFIG\startupreg: NvBackend => "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
- MSCONFIG\startupreg: Razer Synapse => "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
- MSCONFIG\startupreg: RGSC => C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
- MSCONFIG\startupreg: SandboxieControl => "C:\Program Files\Sandboxie\SbieCtrl.exe"
- MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
- MSCONFIG\startupreg: ShadowPlay => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
- MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
- MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
- MSCONFIG\startupreg: USB3MON => "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
- MSCONFIG\startupreg: Xvid => C:\Program Files (x86)\Xvid\CheckUpdate.exe
- ==================== FirewallRules (Whitelisted) ===============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- FirewallRules: [{3CC30133-3335-4708-AFF9-64D4DAB921B0}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
- FirewallRules: [{526D5CA0-2F36-4C7F-9306-A5216C411D80}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
- FirewallRules: [{998A77EE-F933-48B2-8BC6-B8CD5363E187}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
- FirewallRules: [{CE7E9DDE-3444-4AA2-8486-9724879051A5}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
- FirewallRules: [{17758101-8283-4BCE-8140-3CEC0863C40C}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
- FirewallRules: [{75EE6D5C-DFE4-4043-9414-4F2781A66180}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
- FirewallRules: [{AEA6E72F-CD34-4AB3-B8C2-903CBABA544C}] => (Allow) C:\ProgramData\NexonEU\NGM\NGM.exe
- FirewallRules: [{EB7CDE4D-9769-4BED-BAE3-1C5C28B0EC7D}] => (Allow) C:\ProgramData\NexonEU\NGM\NGM.exe
- FirewallRules: [{8EED77B5-5138-486A-8A3C-F9B036C55E46}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
- FirewallRules: [TCP Query User{399DFA11-329E-48E3-B043-2745F8A20943}C:\users\t-bag\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\t-bag\appdata\local\akamai\netsession_win.exe
- FirewallRules: [UDP Query User{37AB385F-5D24-433B-BC29-5A732352F87F}C:\users\t-bag\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\t-bag\appdata\local\akamai\netsession_win.exe
- FirewallRules: [{799AADB5-92D1-44BE-BFF5-155C248A8F23}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- FirewallRules: [{6BB2A338-A0DC-4AAB-A22D-6CC7766AC0C9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- FirewallRules: [{21A06431-0912-4CF5-9249-194CE838ED26}] => (Allow) LPort=2869
- FirewallRules: [{BBFCAB4C-04AD-4A58-B044-4F6303AABAB1}] => (Allow) LPort=1900
- FirewallRules: [{3A95879E-5E41-4ADC-9AAA-B622287FA694}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
- FirewallRules: [{59588C57-5184-4204-8CA7-36999F86094B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
- FirewallRules: [{D84135F6-410C-43CC-9617-5273B5EE776A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
- FirewallRules: [{A62623EA-A294-4A20-98DD-F8FD49F609FA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
- FirewallRules: [{C0698C27-15A1-40F4-B925-DD9E25ADB388}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
- FirewallRules: [{54A9871D-AEC0-4F76-A71C-24075A6CEE99}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
- FirewallRules: [{5899F22B-AF4E-4806-92D6-43BA6DE0B540}] => (Allow) C:\Program Files\HP\HP Deskjet 2540 series\Bin\DeviceSetup.exe
- FirewallRules: [{D9AE063D-E20C-43FD-A00D-7AA338581ABE}] => (Allow) LPort=5357
- FirewallRules: [{D94FFF38-4981-4CFB-8FC6-09D603A5C89D}] => (Allow) C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPNetworkCommunicatorCom.exe
- FirewallRules: [{AF2086E9-B7ED-4B12-97BE-4504B5F70A76}] => (Allow) C:\Users\T-BAG\Downloads\PlayBlackDesert.exe
- FirewallRules: [{24142F7B-4A8D-4280-B4D9-6897A9743231}] => (Allow) C:\Users\T-BAG\Downloads\PlayBlackDesert.exe
- FirewallRules: [{169ACE02-B543-4FB4-89AB-54EB2E90898C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- FirewallRules: [{0E9E1F38-512D-40F4-9136-1E9E86E24193}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- FirewallRules: [{61D7D341-D4D6-47DA-A953-897BB6EFA8D3}] => (Allow) C:\Program Files (x86)\BlackDesertOnlineCBT1\bin\BlackDesert32.exe
- FirewallRules: [{3457207E-90B5-4451-B2A1-F744086DB82B}] => (Allow) C:\Program Files (x86)\BlackDesertOnlineCBT1\bin64\BlackDesert64.exe
- FirewallRules: [{A19272C8-E5A0-47C2-AB69-B5E2ACB57671}] => (Allow) C:\Users\T-BAG\Downloads\bin\BlackDesert32.exe
- FirewallRules: [{3DD50DB7-DA5F-406B-9E9F-DE8A9135E4AC}] => (Allow) C:\Users\T-BAG\Downloads\bin64\BlackDesert64.exe
- FirewallRules: [{39ADE628-3AB0-40C6-A998-3A47A7C07C8B}] => (Allow) C:\Users\T-BAG\Downloads\BlackDesert_Launcher.exe
- FirewallRules: [{1956ECD9-101C-4872-8410-376FE25E4392}] => (Allow) C:\Users\T-BAG\Downloads\BlackDesert_Downloader.exe
- FirewallRules: [{4FE78326-B720-4F4C-9B95-D69074635FE3}] => (Allow) C:\Users\T-BAG\Downloads\bin\BlackDesert32.exe
- FirewallRules: [{3C3F6CD4-CBD0-434F-A6A9-AD3440CCF992}] => (Allow) C:\Users\T-BAG\Downloads\bin64\BlackDesert64.exe
- FirewallRules: [{A42678EF-5725-4502-B96E-562BF030828E}] => (Allow) C:\Users\T-BAG\Downloads\BlackDesert_Launcher.exe
- FirewallRules: [{7EEE0DE9-AEF3-4308-8E5F-9683C5943013}] => (Allow) C:\Users\T-BAG\Downloads\BlackDesert_Downloader.exe
- FirewallRules: [{D4758371-117A-4D03-A41E-218EED0CCAE2}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
- FirewallRules: [{89765BD5-F5CA-4A94-B68D-49769D3E124F}] => (Allow) LPort=2869
- FirewallRules: [{ACA638E9-B11F-416A-93E2-360858C8C34B}] => (Allow) LPort=1900
- FirewallRules: [{740772E9-8EF8-46DD-9DA1-2762BF4973B2}] => (Allow) LPort=2869
- FirewallRules: [{5D334C3A-0485-4988-92B5-70026FAE5391}] => (Allow) LPort=1900
- FirewallRules: [{6F2A91B9-A3FC-42B5-B8EB-29DAB6901FC2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
- FirewallRules: [{F39DEABA-6D08-4D1F-81E1-694E479BE234}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
- FirewallRules: [{07B27339-FC84-43A3-ADB3-EA317254D326}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
- FirewallRules: [{CB507281-0A89-46E7-8365-0F9B14399FAE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
- FirewallRules: [{8EE7306B-EC20-43E5-A1F3-8C10D589E36E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
- FirewallRules: [{86D5DEC0-6FD2-4BC4-B5CC-30E3CD078C2C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
- FirewallRules: [{E15D37C9-DEA3-4E89-928E-7950899902C0}] => (Allow) C:\Users\T-BAG\AppData\Local\Torch\Plugins\Hola\hola_plugin_x64.exe
- FirewallRules: [{49F5651C-FEF3-4BD7-A670-1F4EDA4472FF}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
- FirewallRules: [{6CD12C0C-1032-435A-A6A7-8DD752066D0A}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
- FirewallRules: [{E6963FF8-1925-499F-B09F-175D9953CC25}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dying Light\DyingLightGame.exe
- FirewallRules: [{B4E3CDEB-05F5-4C56-B7ED-315DA2A6D7A0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dying Light\DyingLightGame.exe
- FirewallRules: [{2A5E1904-B604-4567-8B47-7E6FCAC6CAE7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dying Light\DevTools\DyingLightPlayer.exe
- FirewallRules: [{4D7D5E5A-1FD0-44A7-910A-74BAD565B34D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dying Light\DevTools\DyingLightPlayer.exe
- FirewallRules: [{8F041DD1-8AEB-4F89-997F-2DB13E1CE3A4}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- FirewallRules: [{42CA926C-FC12-4C2B-90D7-A5B6CC75BEEA}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\WiFi GO! Server.exe
- FirewallRules: [{947CAF02-3E19-49A6-ABBD-B6506C9915F1}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\WiFi GO! Server.exe
- FirewallRules: [{1EA21E23-BF76-43CD-881C-BBBAC84AAFA1}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\ASUSDMS.exe
- FirewallRules: [{349FCD4D-557B-411A-8278-09D138FCD24B}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\ASUSDMS.exe
- StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
- StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
- StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
- StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service
- ==================== Restore Points =========================
- 03-08-2016 18:31:26 Scheduled Checkpoint
- 06-08-2016 20:10:25 JRT Pre-Junkware Removal
- ==================== Faulty Device Manager Devices =============
- ==================== Event log errors: =========================
- Application errors:
- ==================
- Error: (08/06/2016 11:18:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
- Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
- Error: (08/05/2016 12:40:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
- Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
- Error: (08/04/2016 11:31:47 PM) (Source: WinMgmt) (EventID: 10) (User: )
- Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
- Error: (08/03/2016 03:13:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
- Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
- Error: (08/02/2016 03:28:39 PM) (Source: WinMgmt) (EventID: 10) (User: )
- Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
- Error: (08/02/2016 01:53:52 AM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: NvStreamNetworkService.exe, version: 7.1.2059.1762, time stamp: 0x56fb173e
- Faulting module name: NvMdnsPlugin.dll_unloaded, version: 0.0.0.0, time stamp: 0x56fb1c2b
- Exception code: 0xc0000005
- Fault offset: 0x000007fef0b645a0
- Faulting process id: 0xefc
- Faulting application start time: 0xNvStreamNetworkService.exe0
- Faulting application path: NvStreamNetworkService.exe1
- Faulting module path: NvStreamNetworkService.exe2
- Report Id: NvStreamNetworkService.exe3
- Error: (08/01/2016 06:24:26 PM) (Source: WinMgmt) (EventID: 10) (User: )
- Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
- Error: (01/01/2009 12:03:05 AM) (Source: WinMgmt) (EventID: 10) (User: )
- Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
- Error: (07/30/2016 01:25:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
- Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
- Error: (07/29/2016 10:57:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
- Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
- System errors:
- =============
- Error: (08/06/2016 08:21:26 PM) (Source: Application Popup) (EventID: 1060) (User: )
- Description: \??\C:\Windows\System32\drivers\TrueSight.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
- Error: (08/06/2016 08:18:36 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
- Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
- %%1056 = An instance of the service is already running.
- Error: (08/06/2016 08:18:22 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
- Description: The MBAMScheduler service terminated unexpectedly. It has done this 1 time(s).
- Error: (08/06/2016 08:18:22 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
- Description: The Intel(R) Dynamic Application Loader Host Interface Service service terminated unexpectedly. It has done this 1 time(s).
- Error: (08/06/2016 08:18:22 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
- Description: The MBAMService service terminated unexpectedly. It has done this 1 time(s).
- Error: (08/06/2016 08:18:22 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
- Description: The Intel(R) Rapid Storage Technology service terminated unexpectedly. It has done this 1 time(s).
- Error: (08/06/2016 08:18:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
- Description: The NVIDIA Streamer Network Service service terminated unexpectedly. It has done this 1 time(s).
- Error: (08/06/2016 08:18:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
- Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
- Error: (08/06/2016 08:18:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
- Description: The Windows Live ID Sign-in Assistant service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
- Error: (08/06/2016 08:18:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
- Description: The Torch Crash Handler service terminated unexpectedly. It has done this 1 time(s).
- CodeIntegrity:
- ===================================
- Date: 2016-02-01 17:33:20.360
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\QGNA\Thetta\Thetta64.sys because the set of per-page image hashes could not be found on the system.
- Date: 2016-02-01 17:33:20.319
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\QGNA\Thetta\Thetta64.sys because the set of per-page image hashes could not be found on the system.
- Date: 2016-02-01 17:33:20.278
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\QGNA\Thetta\Thetta64.sys because the set of per-page image hashes could not be found on the system.
- Date: 2016-02-01 17:33:20.184
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\QGNA\Thetta\Thetta32.sys because the set of per-page image hashes could not be found on the system.
- Date: 2016-02-01 17:33:20.143
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\QGNA\Thetta\Thetta32.sys because the set of per-page image hashes could not be found on the system.
- Date: 2016-02-01 17:33:20.103
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\QGNA\Thetta\Thetta32.sys because the set of per-page image hashes could not be found on the system.
- Date: 2016-01-25 17:56:12.532
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\QGNA\Thetta\Thetta64.sys because the set of per-page image hashes could not be found on the system.
- Date: 2016-01-25 17:56:12.481
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\QGNA\Thetta\Thetta64.sys because the set of per-page image hashes could not be found on the system.
- Date: 2016-01-25 17:56:12.431
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\QGNA\Thetta\Thetta64.sys because the set of per-page image hashes could not be found on the system.
- Date: 2016-01-25 17:56:12.290
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\QGNA\Thetta\Thetta32.sys because the set of per-page image hashes could not be found on the system.
- ==================== Memory info ===========================
- Processor: Intel(R) Core(TM) i5-4670K CPU @ 3.40GHz
- Percentage of memory in use: 61%
- Total physical RAM: 8129.54 MB
- Available physical RAM: 3138.77 MB
- Total Virtual: 16257.27 MB
- Available Virtual: 11670.77 MB
- ==================== Drives ================================
- Drive c: () (Fixed) (Total:931.41 GB) (Free:269.21 GB) NTFS ==>[drive with boot components (obtained from BCD)]
- Drive d: () (Fixed) (Total:0.1 GB) (Free:0.08 GB) NTFS
- ==================== MBR & Partition Table ==================
- ==================== End of Addition.txt ============================
Add Comment
Please, Sign In to add comment