==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\windows\system32\acmigration.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\adtschema.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\aeinv.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\aelupsvc.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-file-l1-2-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-file-l2-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-eventing-provider-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\apisetschema.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\apphelp.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\appidapi.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\appidcertstorecheck.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\appidpolicyconverter.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\appidsvc.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\appraiser.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\auditpol.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\bcryptprimitives.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\catsrvut.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\CompatTelRunner.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\comsvcs.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\conhost.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\credssp.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\cryptbase.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\csrsrv.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\devinv.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\DWrite.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\dxtmsft.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\dxtrans.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\els.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\ExplorerFrame.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\FntCache.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\generaltel.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\ie4uinit.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\ieapfltr.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\iedkcs32.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\ieetwcollector.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\ieetwcollectorres.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\ieetwproxystub.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\ieframe.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\iernonce.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\iertutil.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\iesetup.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\ieui.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\ieUnatt.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\inetcpl.cpl:$CmdTcID
AlternateDataStreams: C:\windows\system32\InkEd.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\invagent.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\JavaScriptCollectionAgent.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\jnwmon.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\jscript.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\jscript9.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\jscript9diag.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\jsproxy.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\kerberos.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\kernel32.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\KernelBase.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\lsasrv.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\lsass.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\MpSigStub.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\msaudite.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\msfeeds.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\mshtml.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\MshtmlDac.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\mshtmled.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\mshtmlmedia.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\msobjs.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\msrating.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\MsSpellCheckingFacility.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\msv1_0.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\ncrypt.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\ntdll.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\ntoskrnl.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\ntvdm64.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\occache.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\rpcrt4.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\rstrui.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\schannel.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\sdbinst.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\secur32.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\setbcdlocale.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\shell32.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\shimeng.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\smss.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\srclient.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\srcore.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\sspicli.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\sspisrv.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\TSpkg.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\tzres.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\ucrtbase.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\urlmon.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\user32.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\usp10.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\vbscript.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\wdigest.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\webcheck.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\win32k.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\wininet.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\winload.efi:$CmdTcID
AlternateDataStreams: C:\windows\system32\winresume.efi:$CmdTcID
AlternateDataStreams: C:\windows\system32\WinSetupUI.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\winsrv.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\wow64.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\wow64cpu.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\wow64win.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\wshrm.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\wu.upgrade.ps.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\wuapi.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\wuapp.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\wuauclt.exe:$CmdTcID
AlternateDataStreams: C:\windows\system32\wuaueng.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\wucltux.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\wudriver.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\wups.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\wups2.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\wuwebv.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\adtschema.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\apisetschema.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\apphelp.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\appidapi.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\auditpol.exe:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\bcryptprimitives.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\catsrvut.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\comsvcs.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\credssp.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\cryptbase.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\DWrite.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\dxtmsft.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\dxtrans.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\els.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\ExplorerFrame.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\ieapfltr.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\iedkcs32.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\ieetwproxystub.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\ieframe.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\iernonce.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\iertutil.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\iesetup.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\ieui.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\ieUnatt.exe:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\inetcpl.cpl:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\InkEd.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\instnm.exe:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\JavaScriptCollectionAgent.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\jscript.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\jscript9.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\jscript9diag.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\jsproxy.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\kerberos.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\kernel32.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\KernelBase.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\msaudite.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\msfeeds.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\mshtml.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\MshtmlDac.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\mshtmled.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\mshtmlmedia.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\msobjs.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\msrating.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\msv1_0.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\ncrypt.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\ntdll.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\ntkrnlpa.exe:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\ntoskrnl.exe:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\ntvdm64.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\occache.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\rpcrt4.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\schannel.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\sdbinst.exe:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\secur32.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\setup16.exe:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\shell32.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\shimeng.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\srclient.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\sspicli.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\TSpkg.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\tzres.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\ucrtbase.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\urlmon.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\user.exe:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\user32.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\usp10.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\vbscript.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\wdigest.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\webcheck.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\wininet.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\wow32.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\wshrm.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\wuapi.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\wuapp.exe:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\wudriver.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\wups.dll:$CmdTcID
AlternateDataStreams: C:\windows\SysWOW64\wuwebv.dll:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\afd.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\appid.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\cng.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\ksecdd.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\ksecpkg.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\mbam.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\mbamchameleon.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\mrxsmb.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\mrxsmb10.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\mrxsmb20.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\mwac.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\ndis.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\rmcast.sys:$CmdTcID
AlternateDataStreams: C:\windows\system32\Drivers\tdx.sys:$CmdTcID
AlternateDataStreams: C:\Users\Austin\Downloads\adwcleaner_5.028.exe:$CmdTcID
AlternateDataStreams: C:\Users\Austin\Downloads\adwcleaner_5.028.exe:$CmdZnID
AlternateDataStreams: C:\Users\Austin\Downloads\EmsisoftAntiMalwareSetup.exe:$CmdTcID
AlternateDataStreams: C:\Users\Austin\Downloads\EmsisoftAntiMalwareSetup.exe:$CmdZnID
AlternateDataStreams: C:\Users\Austin\Downloads\FRST64(1).exe:$CmdZnID
AlternateDataStreams: C:\Users\Austin\Downloads\FRST64.exe:$CmdTcID
AlternateDataStreams: C:\Users\Austin\Downloads\FRST64.exe:$CmdZnID
AlternateDataStreams: C:\Users\Austin\Downloads\IMG_0980.JPG:$CmdTcID
AlternateDataStreams: C:\Users\Austin\Downloads\IMG_0980.JPG:$CmdZnID
AlternateDataStreams: C:\Users\Austin\Downloads\mbam-setup-2.2.0.1024.exe:$CmdTcID
AlternateDataStreams: C:\Users\Austin\Downloads\mbam-setup-2.2.0.1024.exe:$CmdZnID
AlternateDataStreams: C:\Users\Austin\Downloads\RogueKiller.exe:$CmdTcID
AlternateDataStreams: C:\Users\Austin\Downloads\RogueKiller.exe:$CmdZnID
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 20:34 - 2009-06-10 15:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3309110190-2459203030-485774004-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Austin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.0.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: 00TCrdMain => %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: ApnUpdater => "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Camera Assistant Software => "C:\Program Files (x86)\Camera Assistant Software for Toshiba\traybar.exe" /start
MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
MSCONFIG\startupreg: CanonSolutionMenu => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon
MSCONFIG\startupreg: Google Update => "C:\Users\Austin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: HSON => %ProgramFiles%\TOSHIBA\TBS\HSON.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: SmartFaceVWatcher => %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
MSCONFIG\startupreg: SmoothView => %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SynTPEnh => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
MSCONFIG\startupreg: Teco => "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
MSCONFIG\startupreg: ThpSrv => C:\windows\system32\thpsrv /logon
MSCONFIG\startupreg: ToshibaServiceStation => "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
MSCONFIG\startupreg: TosNC => %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
MSCONFIG\startupreg: TosReelTimeMonitor => %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
MSCONFIG\startupreg: TosSENotify => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
MSCONFIG\startupreg: TosWaitSrv => %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
MSCONFIG\startupreg: TPwrMain => %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
MSCONFIG\startupreg: tvncontrol => "C:\Program Files (x86)\Common Files\Comodo\GeekBuddyRSP.exe" -controlservice -slave
MSCONFIG\startupreg: TWebCamera => "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
MSCONFIG\startupreg: vProt => "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{C411D767-A4C3-4FD5-8022-1F918C23D789}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{FD069DB3-8843-4EBD-9D37-F2677BBF535F}] => (Allow) svchost.exe
FirewallRules: [{29910482-E830-4123-A12E-2F0D723F88F6}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{7964B76A-AAA8-454D-9C12-090692CE5871}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{0200BCA4-A677-408C-8614-FA47E1AFC4FE}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [TCP Query User{417BD6C3-EA6C-4915-B410-AAF9AF29A5D5}C:\program files (x86)\electronic arts\bioware\star wars - the old republic\betatest\retailclient\swtor.exe] => (Allow) C:\program files (x86)\electronic arts\bioware\star wars - the old republic\betatest\retailclient\swtor.exe
FirewallRules: [UDP Query User{E9835CBA-C93D-4CB3-AA50-9BE75D2B9519}C:\program files (x86)\electronic arts\bioware\star wars - the old republic\betatest\retailclient\swtor.exe] => (Allow) C:\program files (x86)\electronic arts\bioware\star wars - the old republic\betatest\retailclient\swtor.exe
FirewallRules: [{B06A92B4-CF31-4AA9-B49C-B5600E8ABDCF}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\swtor\retailclient\swtor.exe
FirewallRules: [{B5E314BC-4E45-4122-AB87-ED418B3BE5CB}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\swtor\retailclient\swtor.exe
FirewallRules: [{551EF93B-BD47-4358-9049-56ED932D2829}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\swtor\retailclient\swtor.exe
FirewallRules: [{58620F80-A9C9-4E07-8477-2CAC2E36D04A}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\swtor\retailclient\swtor.exe
FirewallRules: [{97E458FB-1EC3-4232-8F1B-D38314D509F6}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{31D2BF7C-E15E-452D-B909-BC5747A79D09}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{37209EB1-810D-4688-A844-EDCB0F3BF2F2}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{F0F93207-71B3-42B6-B823-4F1F80ADA053}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{B861B200-F060-4449-801D-E1396A34AECE}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{15BC7F43-9A2D-48DF-822A-A899FEA419FB}] => (Allow) LPort=2869
FirewallRules: [{ABCAD138-4F7F-43F5-B2DE-B4C4C138E9CB}] => (Allow) LPort=1900
FirewallRules: [{51A3FE04-0B0A-4E82-B509-9F384D8B9EA3}] => (Allow) C:\Program Files (x86)\Common Files\Comodo\tvnserver.exe
FirewallRules: [{E1D9DBA2-C886-43AC-BAD7-5BD7D626877B}] => (Allow) C:\Program Files (x86)\Common Files\Comodo\tvnserver.exe
FirewallRules: [{E813E92D-4A6F-4E42-AEA5-570684F40F30}] => (Allow) C:\Program Files (x86)\Common Files\Comodo\GeekBuddyRSP.exe
FirewallRules: [{14CFCB85-CBE8-4C1B-A6BF-BC049E3D3609}] => (Allow) C:\Program Files (x86)\Common Files\Comodo\GeekBuddyRSP.exe
FirewallRules: [{98FB97FC-4947-4C64-B57E-C20DA8DE4004}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3D5AB496-7499-4F7C-A60B-C60838945CF1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C37820DC-63AC-41F0-A228-86F5E9239076}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{43219047-D317-48FB-8FE3-6329ED51E145}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8884F9F6-99C7-4338-A926-DE4ED77097CC}] => (Allow) C:\Users\Austin\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
FirewallRules: [{D776F5D8-AEFD-4F80-92F3-98ECECB4E687}] => (Allow) C:\Users\Austin\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
FirewallRules: [{64B3FA6E-7F87-4EB6-BCED-AF3C97C22C32}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{2AA711E9-7462-4A77-9AE8-1C3274B7CC4A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{F6237910-424F-4A3B-82E2-BACDF8DC84FC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{577DC1AE-785E-4923-9B60-C3A2811DF404}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{20890C48-19AA-4D9B-9AA2-2BBD5B96F041}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Restore Points =========================
14-12-2015 00:37:00 Windows Backup
16-12-2015 15:08:10 Windows Update
29-12-2015 19:01:55 Windows Backup
29-12-2015 23:09:43 Windows Update
29-12-2015 23:28:36 Windows Update
05-01-2016 18:08:34 Windows Update
05-01-2016 18:54:14 Windows Backup
06-01-2016 21:00:47 JRT Pre-Junkware Removal
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/08/2016 11:09:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 43.0.1.5828, time stamp: 0x56723a12
Faulting module name: mozglue.dll, version: 43.0.1.5828, time stamp: 0x56722c0b
Exception code: 0x80000003
Fault offset: 0x0000ed63
Faulting process id: 0x3110
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Error: (01/08/2016 11:07:04 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 43.0.1.5828, time stamp: 0x56723a12
Faulting module name: mozglue.dll, version: 43.0.1.5828, time stamp: 0x56722c0b
Exception code: 0x80000003
Fault offset: 0x0000ed63
Faulting process id: 0x1c48
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Error: (01/08/2016 11:02:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 43.0.1.5828, time stamp: 0x56723a12
Faulting module name: mozglue.dll, version: 43.0.1.5828, time stamp: 0x56722c0b
Exception code: 0x80000003
Fault offset: 0x0000ed63
Faulting process id: 0x2ce8
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Error: (01/08/2016 11:02:09 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 43.0.1.5828, time stamp: 0x56723a12
Faulting module name: mozglue.dll, version: 43.0.1.5828, time stamp: 0x56722c0b
Exception code: 0x80000003
Fault offset: 0x0000ed63
Faulting process id: 0x12cc
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Error: (01/08/2016 11:00:50 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 43.0.1.5828, time stamp: 0x56723a12
Faulting module name: mozglue.dll, version: 43.0.1.5828, time stamp: 0x56722c0b
Exception code: 0x80000003
Fault offset: 0x0000ed63
Faulting process id: 0x26c4
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Error: (01/08/2016 10:49:49 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15865
Error: (01/08/2016 10:49:49 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15865
Error: (01/08/2016 10:49:48 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/08/2016 12:16:36 AM) (Source: MsiInstaller) (EventID: 1024) (User: Jimmy)
Description: Product: Adobe Acrobat Reader DC - Update '{AC76BA86-7AD7-0000-2550-AC0F094E6F00}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support:
http://go.microsoft.com/fwlink/?LinkId=23127
Error: (01/07/2016 11:12:56 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program FRST64 (2).exe version 3.3.14.2 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 52e8
Start Time: 01d149d2dabafe23
Termination Time: 20
Application Path: C:\Users\Austin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X4AKGU9G\FRST64 (2).exe
Report Id: 73a1f8d8-b5c6-11e5-a092-00266c6b03aa
System errors:
=============
Error: (01/08/2016 11:10:45 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240055: Upgrade to Windows 10 Home, version 1511, 10586.
Error: (01/07/2016 11:59:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The GeekBuddy Remote Screen Protocol service failed to start due to the following error:
%%3
Error: (01/07/2016 11:13:39 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (01/07/2016 11:13:39 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (01/07/2016 11:02:53 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (01/07/2016 11:02:53 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (01/07/2016 10:58:35 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
Error: (01/07/2016 10:54:15 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (01/07/2016 10:54:15 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
Error: (01/07/2016 10:24:00 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.
CodeIntegrity:
===================================
Date: 2016-01-07 23:58:43.061
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\rixdpe64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-01-07 23:58:42.905
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\rixdpe64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-01-07 23:58:42.749
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\rimspe64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-01-07 23:58:42.577
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\rimspe64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-01-07 20:29:29.998
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\rixdpe64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-01-07 20:29:29.827
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\rixdpe64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-01-07 20:29:29.671
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\rimspe64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-01-07 20:29:29.515
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\rimspe64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-01-06 21:35:30.516
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\rixdpe64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-01-06 21:35:30.360
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\rixdpe64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3 CPU M 330 @ 2.13GHz
Percentage of memory in use: 59%
Total physical RAM: 3894.84 MB
Available physical RAM: 1566.08 MB
Total Virtual: 7787.89 MB
Available Virtual: 5321.68 MB
==================== Drives ================================
Drive c: (TI105322W0F) (Fixed) (Total:453.89 GB) (Free:338.39 GB) NTFS ==>[system with boot components (obtained from drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 31AC024B)
Partition 1: (Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Not Active) - (Size=453.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=10.4 GB) - (Type=17)
==================== End of Addition.txt ============================