Fix result of Farbar Recovery Scan Tool (x64) Version:27-04-2016
Ran by user (2016-04-28 11:05:10) Run:1
Running from C:\Users\user\Desktop
Loaded Profiles: user (Available Profiles: user)
Boot Mode: Normal
==============================================
fixlist content:
*****************
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2207781790-2766300111-2274446720-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
FF Plugin-x32: @softforum.com/npKeyPro -> C:\windows\system32\npKeyPro.dll [No File]
S2 KOS_Service; C:\Kings\KOS\KOSSvc.exe [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 JRSKD24; \??\C:\windows\system32\JRSKD24.SYS [X]
S3 ProMDefense; \??\C:\Windows\SysWOW64\drivers\ProMDefense.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 x64kdss; syswow64\Drivers\x64kdss.sys [X]
2015-11-05 15:28 - 2016-02-03 16:42 - 0001456 _____ () C:\Users\user\AppData\Local\Adobe Save for Web 12.0 Prefs
2016-02-08 18:13 - 2016-02-08 18:13 - 0001298 _____ () C:\Users\user\AppData\Local\recently-used.xbel
2015-10-22 15:40 - 2015-10-22 15:40 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
AlternateDataStreams: C:\windows\avastSS.scr:$CmdTcID [43]
AlternateDataStreams: C:\windows\explorer.exe:$CmdTcID [42]
AlternateDataStreams: C:\windows\ImageSAFERSvc.exe:$CmdTcID [43]
AlternateDataStreams: C:\windows\INISandBoxMonitor.10034.exe:$CmdTcID [43]
AlternateDataStreams: C:\windows\INISandBoxMonitor.10035.exe:$CmdTcID [42]
AlternateDataStreams: C:\windows\uninstallkdf8.exe:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\acmigration.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\AcpiServiceVnA64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\adtschema.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\aeinv.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\aepic.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\AERTAC64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\AERTAR64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-console-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-file-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-io-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID [46]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID [46]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-string-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-util-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-security-base-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\apisetschema.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\appraiser.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\atmlib.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\audioLibVc.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\authui.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\btscan.exe:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\catsrvut.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\CKAgent.dat:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\CKAgent.exe:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\CKAgentNXE.dat:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\CKAgentNXE.exe:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\COLORCNV.DLL:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\CompatTelRunner.exe:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\comsvcs.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\CONEQMSAPOGUILibrary.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\CPFilters.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\CX64APO.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\dciman32.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DDPA64.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DDPA64F3.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DDPD64A.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DDPD64AF3.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DDPO64A.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DDPO64AF3.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DDPP64A.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DDPP64AF3.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\devenum.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\devinv.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DolbyDAX2APOProp.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DolbyDAX2APOv201.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DolbyDAX2APOv211.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DTSBassEnhancementDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\DTSBoostDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\DTSGainCompensatorDLL64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DTSGFXAPO64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DTSGFXAPONS64.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DTSLFXAPO64.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DTSLimiterDLL64.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DTSNeoPCDLL64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DTSS2HeadphoneDLL64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DTSS2SpeakerDLL64.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\DTSSymmetryDLL64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DTSU2PGFX64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DTSU2PLFX64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DTSU2PREC64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DTSVoiceClarityDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\dxmasf.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\dxtmsft.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\dxtrans.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\els.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\EncDec.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\evr.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\ExplorerFrame.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\fixmapi.exe:$CmdTcID [41]
AlternateDataStreams: C:\windows\system32\FMAPO64.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\fontsub.dll:$CmdTcID [41]
AlternateDataStreams: C:\windows\system32\FsExService64.exe:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\fveapi.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\fveapibase.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\gdi32.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\generaltel.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\HiFiDAX2API.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\icaapi.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\ICEsoundAPO64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\ie4uinit.exe:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\ieapfltr.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\iedkcs32.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\ieetwcollector.exe:$CmdTcID [46]
AlternateDataStreams: C:\windows\system32\ieetwcollectorres.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\ieetwproxystub.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\ieframe.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\iernonce.dll:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\iertutil.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\iesetup.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\ieui.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\ieUnatt.exe:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\ImageSAFERMessage.exe:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\ImageSAFERRecovery.exe:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\ImageSAFERStart_X64.exe:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\ImageSAFERStart_X86.exe:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\inetcpl.cpl:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\inseng.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\IntelSSTAPO.dll:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\IntelSstCApoPropPage.dll:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\invagent.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\JavaScriptCollectionAgent.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\jscript.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\jscript9.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\jscript9diag.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\jsproxy.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\KAAPORT64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\ksproxy.ax:$CmdTcID [41]
AlternateDataStreams: C:\windows\system32\ksuser.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\lpk.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPO20.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPO30.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPO4064.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPO5064.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPO6064.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPO7064.dll:$CmdTcID [46]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPOShell64.dll:$CmdTcID [46]
AlternateDataStreams: C:\windows\system32\MaxxAudioEQ64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MaxxAudioRealtek64.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\MaxxSpeechAPO64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MaxxVoiceAPO2064.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\MaxxVoiceAPO3064.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MaxxVoiceAPO4064.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\MaxxVolumeSDAPO.dll:$CmdTcID [46]
AlternateDataStreams: C:\windows\system32\mcmde.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\mf.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\mferror.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\mfplat.dll:$CmdTcID [41]
AlternateDataStreams: C:\windows\system32\mfpmp.exe:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\mfps.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\mfvdsp.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MFWMAAEC.DLL:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MISS_APO.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MP3DMOD.DLL:$CmdTcID [41]
AlternateDataStreams: C:\windows\system32\MP43DECD.DLL:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MP4SDECD.DLL:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MPG4DECD.DLL:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MpSigStub.exe:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\msaudite.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\msdxm.ocx:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\msfeeds.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\mshtml.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MshtmlDac.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\mshtmled.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\mshtmlmedia.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\msmpeg2adec.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MSMPEG2ENC.DLL:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\msmpeg2vdec.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\msobjs.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\msrating.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\MsRdpWebAccess.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\MsSpellCheckingFacility.exe:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\mstsc.exe:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\mstscax.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\NAHIMICAPOlfx.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\NahimicAPONSControl.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\NAHIMICV2apo.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\nvapi64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\nvaudcap64v.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\nvcuda.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\nvcuvid.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\nvd3dumx.dll:$CmdTcID [43]
Ran by user (2016-04-28 11:05:10) Run:1
Running from C:\Users\user\Desktop
Loaded Profiles: user (Available Profiles: user)
Boot Mode: Normal
==============================================
fixlist content:
*****************
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2207781790-2766300111-2274446720-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
FF Plugin-x32: @softforum.com/npKeyPro -> C:\windows\system32\npKeyPro.dll [No File]
S2 KOS_Service; C:\Kings\KOS\KOSSvc.exe [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 JRSKD24; \??\C:\windows\system32\JRSKD24.SYS [X]
S3 ProMDefense; \??\C:\Windows\SysWOW64\drivers\ProMDefense.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 x64kdss; syswow64\Drivers\x64kdss.sys [X]
2015-11-05 15:28 - 2016-02-03 16:42 - 0001456 _____ () C:\Users\user\AppData\Local\Adobe Save for Web 12.0 Prefs
2016-02-08 18:13 - 2016-02-08 18:13 - 0001298 _____ () C:\Users\user\AppData\Local\recently-used.xbel
2015-10-22 15:40 - 2015-10-22 15:40 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
AlternateDataStreams: C:\windows\avastSS.scr:$CmdTcID [43]
AlternateDataStreams: C:\windows\explorer.exe:$CmdTcID [42]
AlternateDataStreams: C:\windows\ImageSAFERSvc.exe:$CmdTcID [43]
AlternateDataStreams: C:\windows\INISandBoxMonitor.10034.exe:$CmdTcID [43]
AlternateDataStreams: C:\windows\INISandBoxMonitor.10035.exe:$CmdTcID [42]
AlternateDataStreams: C:\windows\uninstallkdf8.exe:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\acmigration.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\AcpiServiceVnA64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\adtschema.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\aeinv.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\aepic.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\AERTAC64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\AERTAR64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-console-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-file-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-io-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID [46]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID [46]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-string-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-util-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\api-ms-win-security-base-l1-1-0.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\apisetschema.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\appraiser.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\atmlib.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\audioLibVc.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\authui.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\btscan.exe:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\catsrvut.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\CKAgent.dat:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\CKAgent.exe:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\CKAgentNXE.dat:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\CKAgentNXE.exe:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\COLORCNV.DLL:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\CompatTelRunner.exe:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\comsvcs.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\CONEQMSAPOGUILibrary.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\CPFilters.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\CX64APO.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\dciman32.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DDPA64.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DDPA64F3.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DDPD64A.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DDPD64AF3.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DDPO64A.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DDPO64AF3.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DDPP64A.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DDPP64AF3.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\devenum.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\devinv.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DolbyDAX2APOProp.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DolbyDAX2APOv201.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DolbyDAX2APOv211.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DTSBassEnhancementDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\DTSBoostDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\DTSGainCompensatorDLL64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DTSGFXAPO64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DTSGFXAPONS64.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DTSLFXAPO64.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DTSLimiterDLL64.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\DTSNeoPCDLL64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DTSS2HeadphoneDLL64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DTSS2SpeakerDLL64.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\DTSSymmetryDLL64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\DTSU2PGFX64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DTSU2PLFX64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DTSU2PREC64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\DTSVoiceClarityDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\dxmasf.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\dxtmsft.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\dxtrans.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\els.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\EncDec.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\evr.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\ExplorerFrame.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\fixmapi.exe:$CmdTcID [41]
AlternateDataStreams: C:\windows\system32\FMAPO64.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\fontsub.dll:$CmdTcID [41]
AlternateDataStreams: C:\windows\system32\FsExService64.exe:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\fveapi.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\fveapibase.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\gdi32.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\generaltel.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\HiFiDAX2API.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\icaapi.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\ICEsoundAPO64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\ie4uinit.exe:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\ieapfltr.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\iedkcs32.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\ieetwcollector.exe:$CmdTcID [46]
AlternateDataStreams: C:\windows\system32\ieetwcollectorres.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\ieetwproxystub.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\ieframe.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\iernonce.dll:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\iertutil.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\iesetup.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\ieui.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\ieUnatt.exe:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\ImageSAFERMessage.exe:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\ImageSAFERRecovery.exe:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\ImageSAFERStart_X64.exe:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\ImageSAFERStart_X86.exe:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\inetcpl.cpl:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\inseng.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\IntelSSTAPO.dll:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\IntelSstCApoPropPage.dll:$CmdTcID [130]
AlternateDataStreams: C:\windows\system32\invagent.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\JavaScriptCollectionAgent.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\jscript.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\jscript9.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\jscript9diag.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\jsproxy.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\KAAPORT64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\ksproxy.ax:$CmdTcID [41]
AlternateDataStreams: C:\windows\system32\ksuser.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\lpk.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPO20.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPO30.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPO4064.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPO5064.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPO6064.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPO7064.dll:$CmdTcID [46]
AlternateDataStreams: C:\windows\system32\MaxxAudioAPOShell64.dll:$CmdTcID [46]
AlternateDataStreams: C:\windows\system32\MaxxAudioEQ64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MaxxAudioRealtek64.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\MaxxSpeechAPO64.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MaxxVoiceAPO2064.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\MaxxVoiceAPO3064.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MaxxVoiceAPO4064.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\MaxxVolumeSDAPO.dll:$CmdTcID [46]
AlternateDataStreams: C:\windows\system32\mcmde.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\mf.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\mferror.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\mfplat.dll:$CmdTcID [41]
AlternateDataStreams: C:\windows\system32\mfpmp.exe:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\mfps.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\mfvdsp.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MFWMAAEC.DLL:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MISS_APO.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MP3DMOD.DLL:$CmdTcID [41]
AlternateDataStreams: C:\windows\system32\MP43DECD.DLL:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MP4SDECD.DLL:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MPG4DECD.DLL:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\MpSigStub.exe:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\msaudite.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\msdxm.ocx:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\msfeeds.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\mshtml.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MshtmlDac.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\mshtmled.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\mshtmlmedia.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\msmpeg2adec.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\MSMPEG2ENC.DLL:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\msmpeg2vdec.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\msobjs.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\msrating.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\MsRdpWebAccess.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\MsSpellCheckingFacility.exe:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\mstsc.exe:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\mstscax.dll:$CmdTcID [44]
AlternateDataStreams: C:\windows\system32\NAHIMICAPOlfx.dll:$CmdTcID [45]
AlternateDataStreams: C:\windows\system32\NahimicAPONSControl.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\NAHIMICV2apo.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\nvapi64.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\nvaudcap64v.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\nvcuda.dll:$CmdTcID [42]
AlternateDataStreams: C:\windows\system32\nvcuvid.dll:$CmdTcID [43]
AlternateDataStreams: C:\windows\system32\nvd3dumx.dll:$CmdTcID [43]