Page 3 of 5 FirstFirst 12345 LastLast
Results 21 to 30 of 43

Thread: Programs not running

  1. #21
    Member
    Join Date
    Nov 2010
    Posts
    63

    Default

    Well, no message of imminent computer meltdown unless I reinstall comodo, which is awesome! And I can connect to the internet still. My programs are opening again, and actually running.


    Fix result of Farbar Recovery Scan Tool (x64) Version: 27-04-2017
    Ran by Rachel (28-04-2017 12:12:23) Run:3
    Running from C:\Users\R\Desktop
    Loaded Profiles: Rachel (Available Profiles: Rachel)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************

    start
    CreateRestorePoint:
    CloseProcesses:
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
    Handler: WSAMVCUchrome - {086BD280-4613-43B5 - No File
    FF Extension: (1-Click YouTube Video Downloader) - C:\Users\R\AppData\Roaming\Mozilla\Firefox\Profiles\pooh0kfu.default\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2016-08-23]
    FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
    Unlock: D:\COMODO\COMODO Internet Security\cmdvirth.exe
    S3 cmdvirth; D:\COMODO\COMODO Internet Security\cmdvirth.exe [2876096 2017-04-06] (COMODO)
    Unlock: D:\COMODO\COMODO Internet Security\cmdvirth.exe
    D:\COMODO\COMODO Internet Security\cmdvirth.exe
    Unlock: D:\COMODO\COMODO Internet Security
    D:\COMODO\COMODO Internet Security
    C:\Users\R\Downloads\COMODO Removal Tool 2014 - Mods version.zip
    C:\Users\Public\Desktop\COMODO Firewall.lnk
    Unlock: C:\WINDOWS\system32\cmdshim64.dll
    C:\WINDOWS\system32\cmdshim64.dll
    Unlock: C:\ProgramData\ComodoC:\WINDOWS\SysWOW64\cmdshim32.dll
    C:\ProgramData\ComodoC:\WINDOWS\SysWOW64\cmdshim32.dll
    Unlock: C:\WINDOWS\System32\Tasks\COMODO
    C:\WINDOWS\System32\Tasks\COMODO
    Task: {90BA0751-0E8B-47AB-8D0C-1382229D6E3A} - System32\Tasks\{31DDBD37-5DB7-4030-8064-10B0CAA806C3} => D:\COMODO\COMODO Internet Security\cistray.exe [2017-04-06] (COMODO)
    Task: {A8A2D02D-661C-4222-9E9B-B42B43AB2D9C} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => D:\COMODO\COMODO Internet Security\cfpconfg.exe [2017-04-06] (COMODO)
    Task: {B4897E97-7A18-4F7A-A872-2ABDF4E5F601} - System32\Tasks\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627} => D:\COMODO\COMODO Internet Security\cfpconfg.exe [2017-04-06] (COMODO)
    Task: {CD5F0113-2871-44D3-A176-52D36E968E44} - System32\Tasks\COMODO\COMODO Maintenance {947247B5-026A-4437-9371-770782BE839D} => D:\COMODO\COMODO Internet Security\cfpconfg.exe [2017-04-06] (COMODO)
    Task: {D4D68587-13B1-499D-BED2-668EBB9821C1} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => D:\COMODO\COMODO Internet Security\cistray.exe [2017-04-06] (COMODO)
    Task: {EFDFBAFB-9819-4D51-BA1E-A06E6B00A901} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => D:\COMODO\COMODO Internet Security\cfpconfg.exe [2017-04-06] (COMODO)
    AlternateDataStreams: C:\WINDOWS\explorer.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\HelpPane.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\regedit.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\splwow64.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\aadcloudap.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\aadtb.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AboveLockAppHost.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\accountaccessor.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AccountsRt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\acmigration.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ActionCenter.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ActionCenterCPL.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ActivationManager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ActiveSyncProvider.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\actxprxy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\adsmsext.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\aeinv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\aepic.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\aitstatic.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AppCapture.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AppContracts.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\appinfo.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ApplicationFrame.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AppointmentApis.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\appraiser.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AppReadiness.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\apprepapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\apprepsync.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\appwiz.cpl:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\AppXApplicabilityBlob.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AppXDeploymentClient.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\AppXDeploymentServer.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AppxPackaging.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\asycfilt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\atmfd.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\atmlib.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AudioSes.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AudioSrvPolicyManager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AuthBroker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AuthHost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\authui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\autoplay.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\AzureSettingSyncProvider.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\BackgroundMediaPolicy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\basecsp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\bcastdvr.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\BcastDVRHelper.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\bcdedit.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\bcrypt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\bdesvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\bdeui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\bdeunlock.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\BingMaps.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\bisrv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\BitLockerDeviceEncryption.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\biwinrt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\BluetoothApis.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\BluetoothDesktopHandlers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\BootMenuUX.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\bootux.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\browserbroker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\BrowserSettingSync.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\BthRadioMedia.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CameraCaptureUI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CastLaunch.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\cdd.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\cdp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\cdpreference.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\cdpsvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\cdpusersvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CellularAPI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\cemapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CertEnroll.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\certprop.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CfgSPCellular.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Chakra.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\chartv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ChatApis.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ci.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CloudBackupSettings.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CloudExperienceHost.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CloudExperienceHostBroker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CloudExperienceHostCommon.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CloudExperienceHostUser.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CloudStorageWizard.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\clusapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\cmifw.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\cmintegrator.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CNC280C.dll:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\system32\CNC280I.dll:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\system32\CNC280L.dll:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\system32\CNC280O.dll:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\system32\CNHI10A.DLL:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\system32\CNHL280.DLL:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\system32\CNHMCA6.dll:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\system32\CNHMCAN.DLL:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\system32\CNMIUAA.DLL:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\system32\CNMLMAA.DLL:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\system32\combase.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\comdlg32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CompatTelRunner.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CompPkgSup.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\comsvcs.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ContactApis.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CoreMessaging.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CoreUIComponents.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CPFilters.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CredProvDataModel.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\credprovhost.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\credprovs.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\credprovslegacy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\crypt32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\cryptngc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CryptoWinRT.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\CspCellularSettings.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\d2d1.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\d3d10warp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\d3d11.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\d3d9.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\D3DCompiler_47.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dab.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dafBth.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dafpos.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DafPrintProvider.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DataExchange.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DataSenseHandlers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DavSyncProvider.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\daxexec.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dbgeng.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dcntel.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DdcWnsListener.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ddraw.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ddrawex.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\devenum.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\deviceaccess.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DeviceCensus.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DeviceCenter.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DeviceDirectoryClient.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DeviceEnroller.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DeviceFlows.DataModel.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DevicePairing.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DevicePairingFolder.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DeviceReactivation.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\devinv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dfp.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DfpCommon.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dhcpcore6.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\diagtrack.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dialclient.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dialserver.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\discan.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Display.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DisplayManager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dlnashext.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dmcertinst.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dmenrollengine.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DMRServer.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dnsapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dnsrslvr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DolbyDecMFT.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dosvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dpapisrv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\drvstore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dsreg.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dsregcmd.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DuCsps.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dui70.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dwmapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dwmcore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DWrite.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dxgi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\DXP.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\dxtrans.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\EAMProgressHandler.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\easwrt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\edgehtml.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\EditBufferTestHook.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\EditionUpgradeHelper.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\EditionUpgradeManagerObj.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\EDPCleanup.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\efsext.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\efswrt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\EmailApis.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\EncDec.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\energy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\enrollmentapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\EnterpriseAPNCsp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\enterprisecsps.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ErrorDetails.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ErrorDetailsUpdate.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\esent.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\esentutl.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\evr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ExplorerFrame.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ExSMime.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\facecredentialprovider.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Family.Authentication.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Family.Client.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Family.SyncEngine.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ffbroker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\fhcfg.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\fhcpl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\FlightSettings.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\flvprophandler.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\FntCache.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\fontdrvhost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\fontext.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\FontProvider.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\FrameServer.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\FSClient.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\fveapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\fveapibase.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\fvecpl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\fvenotify.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\fveui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\fvewiz.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\GamePanel.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\GamePanelExternalHook.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\gameux.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\gdi32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\gdi32full.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\GdiPlus.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\generaltel.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Geolocation.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\GlobCollationHost.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\gpapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\gpsvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\hal.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\hevcdecoder.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\hgcpl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\HttpsDataSource.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\hvax64.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\hvix64.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\hvloader.efi:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\hvloader.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\icfupgd.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\icm32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\icsvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\icsvcext.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\IdCtrls.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\ie4uinit.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ieapfltr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\iedkcs32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ieframe.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\iepeers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ieproxy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\iertutil.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\imapi2.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\imapi2fs.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\indexeddbserver.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\inetcomm.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\inetcpl.cpl:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\input.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\InputLocaleManager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\InputService.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\InstallAgent.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\InstallAgentUserBroker.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\internetmail.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\invagent.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\IPHLPAPI.DLL:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\iphlpsvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ipnathlp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\iprtrmgr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\iscsiwmi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\JpMapControl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\jscript9.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\kerberos.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\KernelBase.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\LaunchWinApp.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\LicenseManager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ListSvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\localspl.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\LocationFramework.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\LockAppBroker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\LockAppHost.exe:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\LogonController.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\lpremove.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\LsaIso.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\lsasrv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\lsm.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\main.cpl:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\manage-bde.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MapConfiguration.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MapControlCore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MapGeocoder.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MapRouter.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MapsBtSvc.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\MapsStore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MbaeApiPublic.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mbsmsapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MCCSEngineShared.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MCRecvSrc.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\MDMAppInstaller.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mdmregistration.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mf.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfasfsrcsnk.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfaudiocnv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MFCaptureEngine.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfcore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfds.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfksproxy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MFMediaEngine.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfmjpegdec.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfmkvsrcsnk.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfmp4srcsnk.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfmpeg2srcsnk.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfnetcore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfnetsrc.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\mfplat.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MFPlay.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfps.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfreadwrite.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfsensorgroup.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfsrcsnk.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mfsvr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\microsoft-windows-system-events.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\migisol.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MiracastReceiver.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\mispace.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\mmc.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MMDevAPI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\modernexecserver.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mos.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\moshost.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\moshostcore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MosStorage.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mprapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mprddm.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mprdim.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MPSSVC.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\MrmCoreR.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MRT.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MSAC3ENC.DLL:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MSAudDecMFT.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mscandui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msctf.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msctfp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msctfui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msdtcprx.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msdtctm.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msdtcuiu.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msfeeds.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msftedit.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mshtml.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mshtmled.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\msi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msinfo32.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msmpeg2vdec.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mspaint.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MSPhotography.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mssitlb.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mssph.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mssphtb.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mssprxy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mssrch.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mssvp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mstsc.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\mstscax.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msutb.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MSVidCtl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MSVideoDSP.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MSVP9DEC.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msvproc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MSVPXENC.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msxml3.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\msxml6.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MultiDigiMon.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\musdialoghandlers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MusNotification.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MusNotificationUx.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\MusUpdateHandlers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NaturalLanguage6.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ncsi.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\netiohlp.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\netiougc.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\netplwiz.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NetSetupApi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NetSetupEngine.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NetSetupShim.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NetSetupSvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\netshell.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\nettrace.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NetworkCollectionAgent.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NetworkDesktopSettings.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NetworkMobileSettings.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NetworkUXBroker.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\NfcRadioMedia.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ngccredprov.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NgcCtnr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NgcCtnrGidsHandler.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NgcCtnrSvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ngcsvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\nlasvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\nltest.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NMAA.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NotificationController.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\NPSM.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\nshwfp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ntdll.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ntoskrnl.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ntshrui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\nvaudcap64v.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\nvdispco6431141.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\nvdispco6435582.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\nvdispco6435598.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\nvdispco6435850.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\nvdispgenco6431141.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\nvdispgenco6435582.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\nvdispgenco6435598.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\nvdispgenco6435850.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\odbcconf.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\offreg.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ole32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\oleacc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\oleaut32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\OnDemandConnRouteHelper.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\OneBackupHandler.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\pcasvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\PCPTpm12.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\pdh.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\PhotoScreensaver.scr:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\PimIndexMaintenance.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Pimstore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\PlayToDevice.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\PlayToManager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\PlayToReceiver.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\pnidui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\policymanager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\poqexec.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\powercfg.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\PrintDialogs.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\PrintDialogs3D.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\PrintRenderAPIHost.DLL:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\PrintWSDAHost.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\profsvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\provops.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ProvSysprep.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\PsmServiceExtHost.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\psmsrv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\puiapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\puiobj.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\pwrshplugin.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\qedit.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\qmgr.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\quartz.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\RADCUI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\rasapi32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\rascustom.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\rasgcw.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\rasmans.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\rdpcorets.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\rdpencom.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RdpRelayTransport.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\rdpudd.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\RDXService.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\RDXTaskFactory.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\ReAgent.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ReAgentc.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\RelPost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\RemoteNaturalLanguage.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ReportingCSP.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\reseteng.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ResetEngine.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\resutils.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\RjvMDMConfig.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\RMapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\rshx32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\RTMediaFrame.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RTWorkQ.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\sbe.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\schannel.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\scksp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\sdengin2.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\sdnclean64.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\sdshext.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SearchFilterHost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SearchFolder.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SearchIndexer.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SearchProtocolHost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SecConfig.efi:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\sendmail.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Sens.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SensorDataService.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SensorsApi.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\SensorService.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\services.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SessEnv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_ClosedCaptioning.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_Flights.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_nt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SettingSync.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SettingSyncCore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SettingSyncHost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\setupugc.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SharedStartModel.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ShareHost.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SHCore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\shdocvw.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\shell32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\shutdownux.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\skci.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\smartscreen.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\smphost.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SndVolSSO.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\SpaceAgent.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SpaceControl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\spaceman.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SpeechPal.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\spoolsv.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\sppcext.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\sppnp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\sppobjs.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\sppsvc.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\sppwinob.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\sspicli.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\stobject.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\storagewmi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\StoreAgent.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\StorSvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\StructuredQuery.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\sud.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SyncCenter.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SyncSettings.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\systemreset.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SystemSettings.Handlers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SystemSettingsAdminFlows.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Tabbtn.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\tabcal.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\TabletPC.cpl:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\tapi32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\taskbarcpl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\tbauth.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\tdh.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\TextInputFramework.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\themecpl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\thumbcache.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\timedate.cpl:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\TokenBroker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\TokenBrokerCookies.exe:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\TokenBrokerUI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\TpmCoreProvisioning.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\TpmTasks.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\tquery.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\TSpkg.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\TSWorkspace.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\twinapi.appcore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\twinapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\twinui.appcore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\twinui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\twinui.pcshell.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\tzautoupdate.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ubpm.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\uDWM.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\UIAnimation.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\UIAutomationCore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\UIRibbon.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\UIRibbonRes.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\umpoext.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\unimdm.tsp:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Unistore.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\updatehandlers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\updatepolicy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\uReFS.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\urlmon.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\usbmon.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\user32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\usercpl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\UserDataService.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\UserDataTimeUtil.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\UserDeviceRegistration.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\UserLanguagesCpl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\usermgr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\UserMgrProxy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\usoapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\usocore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\UtcResources.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\vaultcli.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\vbscript.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\VCardParser.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\vds.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\VEStoreEventHandlers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\vmrdvcore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\vpnike.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\VPNv2CSP.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\vssapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\VSSVC.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\vss_ps.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wbengine.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wcmsvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wcnwiz.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wc_storage.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WebcamUi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\webcheck.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\webio.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wer.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\werconcpl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\weretw.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\werui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wevtsvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wfdprov.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wifinetworkmanager.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\wifitask.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\win32kbase.sys:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\win32kfull.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\win32spl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wincorlib.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.AccountsControl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Cortana.Desktop.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Cortana.OneCore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Data.Pdf.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Lights.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.LowLevel.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Midi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Perception.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Picker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.PointOfService.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Printers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Radios.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Scanners.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Sensors.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.SmartCards.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.Usb.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.WiFi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Energy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Gaming.Input.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Gaming.UI.GameBar.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Globalization.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Graphics.Printing.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Internal.Management.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Audio.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Devices.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Editing.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Import.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.MediaControl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Ocr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Speech.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Streaming.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.Connectivity.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.HostName.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Networking.Vpn.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Perception.Stub.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Security.Credentials.UI.CredentialPicker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.StateRepository.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.StateRepositoryClient.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\windows.storage.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Storage.Search.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.System.SystemManagement.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.System.UserDeviceAssociation.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Cred.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Immersive.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Input.Inking.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Logon.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Search.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Shell.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Xaml.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Web.Diagnostics.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Web.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Windows.Web.Http.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WindowsCodecs.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\winhttp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wininet.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wininetlui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\winload.efi:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\winload.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\winmde.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\winresume.efi:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\winresume.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WinRtTracing.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\WinSetupUI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\winspool.drv:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\winsrv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wintrust.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WinTypes.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wkssvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wlanapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wlancfg.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WlanMediaManager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wlansec.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wlansvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wlanui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wlidprov.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wlidsvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wmp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WMPDMC.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wmpdxm.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wmpeffects.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wmpmde.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wmpps.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wmpshell.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WMVDECOD.DLL:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WordBreakers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WorkFolders.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WorkfoldersControl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WorkFoldersGPExt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WorkFoldersShell.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\workfolderssvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WpAXHolder.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Wpc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WpcMon.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WpcRefreshTask.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WpcTok.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WpcWebFilter.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wpnapps.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wpncore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wpninprc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wpnprv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wpx.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\ws2_32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wscapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wscinterop.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wscsvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wscui.cpl:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wsecedit.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WSManHTTPConfig.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WSManMigrationPlugin.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WsmSvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WsmWmiPl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wsp_fs.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wsp_health.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wsp_sr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wu.upgrade.ps.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\wuapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wuaueng.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wups.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wuuhext.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WwaApi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WWAHost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\WWanAPI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wwanconn.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\wwanmm.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\wwansvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\XblAuthManager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\XblAuthManagerProxy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\XblGameSaveExt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\XboxNetApiSvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\XInputUap.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\xpsrchvw.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\zipfldr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\aadtb.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\AboveLockAppHost.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\accountaccessor.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ActionCenterCPL.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ActivationManager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\actxprxy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\adsmsext.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\aepic.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\AiCM32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\AiCM64.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\apds.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\api-ms-win-crt-math-l1-1-0.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\api-ms-win-crt-private-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\api-ms-win-crt-string-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\api-ms-win-crt-time-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\AppCapture.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\AppContracts.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\AppointmentActivation.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\AppointmentApis.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\apprepapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\apprepsync.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\appwiz.cpl:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\AppxPackaging.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\asycfilt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\atmfd.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\atmlib.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\AudioSes.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\AuthBroker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\AuthExt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\authui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\autoplay.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\azroleui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\BackgroundMediaPolicy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\basecsp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\bcastdvr.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\BcastDVRHelper.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\bcrypt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\BingMaps.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\biwinrt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\BluetoothApis.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\BrowserSettingSync.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CameraCaptureUI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\cdp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\cemapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CertEnroll.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Chakra.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Chakradiag.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\chartv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ChatApis.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ClipboardServer.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CloudBackupSettings.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CloudStorageWizard.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\clusapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\cmifw.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CNC280L.dll:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CNC280U.dll:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CNHMCA.dll:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\combase.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\comctl32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\comdlg32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CompPkgSup.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\comsvcs.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ContactApis.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CoreMessaging.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CoreUIComponents.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CPFilters.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CredProvDataModel.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\credprovhost.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\credprovs.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\credprovslegacy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\crypt32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\cryptngc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\CryptoWinRT.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d10warp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d11.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d8.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d9.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\D3DCompiler_47.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\d3dx9_34.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\DafPrintProvider.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\DataExchange.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\DavSyncProvider.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\daxexec.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\dbgeng.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ddraw.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ddrawex.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\devenum.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\deviceaccess.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\DevicePairing.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\dhcpcore6.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\dialclient.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\DisplayManager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\dlnashext.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\dmenrollengine.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\dnsapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\DolbyDecMFT.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\drvstore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\dsreg.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\dtdump.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\dwmapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\dwmcore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\DWrite.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\dxgi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\dxtrans.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\edgehtml.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\EditBufferTestHook.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\efsext.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\efswrt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\EmailApis.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\enrollmentapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ErrorDetails.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ErrorDetailsUpdate.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\esent.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\esentutl.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\evr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\explorer.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ExplorerFrame.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ExSMime.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\findnetprinters.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\FlashPlayerApp.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\fontdrvhost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\fontext.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\FSClient.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\GamePanelExternalHook.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\gameux.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\gdi32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\gdi32full.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\GdiPlus.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Geolocation.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\GlobCollationHost.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\gpapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\hevcdecoder.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\hgcpl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\icm32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ieapfltr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\iedkcs32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ieframe.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\iepeers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ieproxy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\iertutil.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\imapi2.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\imapi2fs.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\indexeddbserver.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\inetcomm.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\inetcpl.cpl:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\input.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\InputLocaleManager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\InputService.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\InstallAgent.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\IPHLPAPI.DLL:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\iprtrmgr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ipsecsnp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ipsmsnap.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\iscsiwmi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\JpMapControl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\jscript9.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\jscript9diag.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\kerberos.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\KernelBase.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\LaunchWinApp.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\LicenseManager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\LicenseManagerApi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\LockAppBroker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\LockAppHost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\LogonController.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\main.cpl:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MapConfiguration.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MapControlCore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MapGeocoder.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MapRouter.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MapsBtSvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MbaeApiPublic.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mbsmsapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MCCSEngineShared.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MCRecvSrc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mdmregistration.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mf.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfaudiocnv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfcore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfds.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfksproxy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MFMediaEngine.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfmjpegdec.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfnetcore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfnetsrc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfplat.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MFPlay.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfreadwrite.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfsensorgroup.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfsrcsnk.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mfsvr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\migisol.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MiracastReceiver.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mispace.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mmc.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MMDevAPI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mos.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MosStorage.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mprapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mprddm.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mprdim.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MrmCoreR.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MSAC3ENC.DLL:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mscandui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mscms.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msctf.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msctfp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msctfui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msdtcprx.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msdtcuiu.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msfeeds.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msftedit.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mshtml.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mshtmled.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msinfo32.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msmpeg2vdec.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mspaint.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MSPhotography.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mssitlb.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mssph.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mssphtb.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mssrch.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mssvp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mstsc.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mstscax.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msutb.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MSVidCtl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MSVP9DEC.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msvproc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\MSVPXENC.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msxml3.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\msxml6.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\mtxclu.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\NaturalLanguage6.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\netiohlp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\netiougc.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\NetSetupApi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\NetSetupEngine.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\NetSetupShim.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\netshell.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\NetworkCollectionAgent.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ngccredprov.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\NMAA.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\NPSM.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\nshwfp.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ntdll.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ntshrui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\nvaudcap32v.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\nvStreaming.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\odbcconf.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\offreg.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ole32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\oleacc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\oleaut32.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\olepro32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\OneDriveSetup.exe:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\PCPTpm12.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\pdh.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\PhotoScreensaver.scr:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Pimstore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\PlayToDevice.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\PlayToManager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\PlayToReceiver.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\policymanager.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\poqexec.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\powercfg.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\PrintDialogs.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ProximityCommon.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\puiapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\puiobj.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\pwrshplugin.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\quartz.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\RADCUI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\rasapi32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\rasgcw.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ReAgent.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ReAgentc.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\regedit.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\resutils.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\RTMediaFrame.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\RTWorkQ.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\sbe.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\schannel.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\scksp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\SearchFilterHost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\SearchFolder.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\SearchIndexer.exe:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\SearchProtocolHost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\sendmail.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\SessEnv.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\SettingSync.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\SettingSyncCore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\SettingSyncHost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\setupugc.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ShareHost.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\SHCore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\shell32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\smphost.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\SndVolSSO.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\sppcext.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\sspicli.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\stobject.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\storagewmi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\StoreAgent.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\StructuredQuery.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\sud.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\SyncSettings.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\systemcpl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\tapi32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\tbauth.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\tcpipcfg.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\tdh.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\TempSignedLicenseExchangeTask.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\TextInputFramework.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\themecpl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\thumbcache.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\TokenBroker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\TokenBrokerUI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\tquery.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\tsmf.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\TSpkg.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\TSWorkspace.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\twinapi.appcore.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\twinapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\twinui.appcore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\twinui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\UIAnimation.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\UIAutomationCore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\UIRibbon.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\UIRibbonRes.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\unimdm.tsp:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Unistore.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\updatepolicy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\uReFS.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\urlmon.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\user32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\usercpl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\UserDataAccountApis.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\UserDeviceRegistration.Ngc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\UserMgrProxy.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\usoapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\vaultcli.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\vbscript.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\VCardParser.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\vssapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wcnwiz.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WebcamUi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\webcheck.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\webio.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wer.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\weretw.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wfdprov.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\win32kfull.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wincorlib.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Wallet.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Lights.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Perception.dll:$CmdTcID [32]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Radios.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.SerialCommunication.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.WiFi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Energy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Gaming.UI.GameBar.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Gaming.XboxLive.Storage.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Globalization.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.FaceAnalysis.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Import.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Ocr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Networking.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Networking.HostName.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.StateRepository.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\windows.storage.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.System.SystemManagement.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.System.UserDeviceAssociation.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Search.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Xaml.InkControls.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Web.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Web.Http.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WindowsCodecs.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\winhttp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wininet.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wininetlui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\winmde.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WinRtTracing.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\winspool.drv:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wintrust.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WinTypes.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wlanapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wlancfg.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wlanui.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wlidcli.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wlidprov.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wmp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WMPDMC.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wmpdxm.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wmpeffects.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wmpmde.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wmpshell.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WMVSENCD.DLL:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WordBreakers.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\Wpc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WpcWebFilter.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WPDShServiceObj.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wpnapps.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\ws2_32.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wscapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wscinterop.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wscui.cpl:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wsecedit.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WsmSvc.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WsmWmiPl.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wsp_fs.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wsp_health.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wsp_sr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\wuapi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WwaApi.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WWAHost.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\WWanAPI.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\XInputUap.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\xolehlp.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\xpsrchvw.exe:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\zipfldr.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\afd.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\ahcache.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\BasicDisplay.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\BasicRender.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\bowser.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\BthLEEnum.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\bthpan.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\bthport.sys:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\capimg.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\Classpnp.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\clfs.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\cmimcext.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\cng.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\crashdmp.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\dam.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\dfsc.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\dumpsd.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\dxgkrnl.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\dxgmms1.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\dxgmms2.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\fastfat.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\fvevol.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\hidclass.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\http.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\hvsocket.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\iorate.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\IPMIDrv.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\kbdhid.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\ks.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\MegaSas2i.sys:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\modem.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxdav.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxsmb.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxsmb10.sys:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxsmb20.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\msiscsi.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\mskssrv.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\ndis.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\ntfs.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\nvvad64v.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\nwifi.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\partmgr.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\pdc.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\rdbss.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\sdbus.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\spaceport.sys:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\srv.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\srv2.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\ssudbus.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\ssudmdm.sys:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\storahci.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\stornvme.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\storport.sys:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\tcpip.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\tcpipreg.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\tdx.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\tm.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\tpm.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\usbscan.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\vmbkmcl.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\vmbkmclr.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\vpci.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\wcifs.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\WdiWiFi.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\winhvr.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\xboxgip.sys:$CmdTcID [130]
    AlternateDataStreams: C:\Users\Public\Desktop\Post Win10 Spybot-install.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Desktop\Andy-Guitar-Beginners-Course-eBook-Feb-2015.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Desktop\Supercharged-Hormone-Diet-Belly-Fat-Plan.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\2014-15 Approved SYC-FINAL(1).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\2014-15 Approved SYC-FINAL(2).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\2014-15 Approved SYC-FINAL(3).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\2014-15 Approved SYC-FINAL(4).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\2014-15 Approved SYC-FINAL.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\22LittleCloudsENGLISH.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\aimer-video-ultimate_setup_full523.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\AllProducts.pdf:$CmdTcID [130]
    AlternateDataStreams: C:\Users\R\Downloads\avast_free_antivirus_setup_offline.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Avery-Label-6450(1).avery:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\BagpipePlayer.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\BGPlayer(1).exe:$CmdTcID [130]
    AlternateDataStreams: C:\Users\R\Downloads\BGPlayer.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\bluebells.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\BMW1____.TTF:$CmdTcID [130]
    AlternateDataStreams: C:\Users\R\Downloads\bonnie_dundee.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Bonny-Galloway-set.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Book01 15(1).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Book01 15(2).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Book01 15.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\BP-setup.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\bruces-address-advanced(1).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\bruces-address-advanced.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Castle Dangerous Set LCPD.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\CoWPaD Castle Dangerous Seconds.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\DarkMarkIllusionScarf.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\FitbitConnect_Win_20150619_2.0.0.6598.exe:$CmdTcID [130]
    AlternateDataStreams: C:\Users\R\Downloads\flashplayer24_jd_install.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\GoogleEarthPluginSetup.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\gordon pipe.2.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\gordon pipe.3.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\gordon pipe.4.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\gordon pipe.pdf:$CmdTcID [130]
    AlternateDataStreams: C:\Users\R\Downloads\Heroes-of-the-Storm-Setup-enUS.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Im-a-believer.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\jfrd_tune_settings_book_05-2015.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Jig1(1).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Jig1.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Jig2.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\killiecrankie.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\laceyarchesinfinityscarf_aiid508740.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Little_Rucksack_Susie_ENG6.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\maris wedding.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\MarysMarch(1).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\MarysMarch.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Ontario Railway Map Collection.kmz:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Ontario Railway Map Collection.kmz:$CmdZnID [26]
    AlternateDataStreams: C:\Users\R\Downloads\PDQB-Exercises(1).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\PDQB-Exercises(2).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\PDQB-Exercises(3).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\PDQB-Exercises.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Reel1.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\scotswhahae.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Secondhand-News(1).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Secondhand-News(2).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Secondhand-News(3).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Secondhand-News(4).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Secondhand-News.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\ServiceOntario Providing your Copy of Your Electronic Product.zip:$CmdTcID [130]
    AlternateDataStreams: C:\Users\R\Downloads\sgt_mackenzie(1).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\sgt_mackenzie(2).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\sgt_mackenzie(3).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\sgt_mackenzie(4).pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\sgt_mackenzie.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Silverlight_x64.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\springtimebandit_aiid145528.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Tachum1.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Thinking-out-loud.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\vol-4-track.pdf:$CmdTcID [64]
    AlternateDataStreams: C:\Users\R\Downloads\Warmup1.pdf:$CmdTcID [64]
    CMD: ipconfig /flushdns
    CMD: netsh winsock reset all
    CMD: netsh int ipv4 reset
    CMD: netsh int ipv6 reset
    EmptyTemp:
    Hosts:
    End

    *****************

    Restore point was successfully created.
    Processes closed successfully.
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => key removed successfully
    HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
    HKCR\PROTOCOLS\Handler\WSAMVCUchrome => key not found.
    C:\Users\R\AppData\Roaming\Mozilla\Firefox\Profiles\pooh0kfu.default\Extensions\YoutubeDownloader@PeterOlayev.com.xpi => moved successfully
    C:\Users\R\AppData\Roaming\Mozilla\Firefox\Profiles\pooh0kfu.default\Extensions\YoutubeDownloader@PeterOlayev.com.xpi => path removed successfully
    HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\msktbird@mcafee.com => value removed successfully
    "D:\COMODO\COMODO Internet Security\cmdvirth.exe" => was unlocked
    HKLM\System\CurrentControlSet\Services\cmdvirth => key removed successfully
    cmdvirth => service removed successfully
    "D:\COMODO\COMODO Internet Security\cmdvirth.exe" => was unlocked
    D:\COMODO\COMODO Internet Security\cmdvirth.exe => moved successfully
    "D:\COMODO\COMODO Internet Security" => was unlocked
    D:\COMODO\COMODO Internet Security => moved successfully
    C:\Users\R\Downloads\COMODO Removal Tool 2014 - Mods version.zip => moved successfully
    C:\Users\Public\Desktop\COMODO Firewall.lnk => moved successfully
    "C:\WINDOWS\system32\cmdshim64.dll" => was unlocked
    C:\WINDOWS\system32\cmdshim64.dll => moved successfully
    "C:\ProgramData\ComodoC:\WINDOWS\SysWOW64\cmdshim32.dll" => not found.
    "C:\ProgramData\ComodoC:\WINDOWS\SysWOW64\cmdshim32.dll" => not found.
    "C:\WINDOWS\System32\Tasks\COMODO" => was unlocked
    C:\WINDOWS\System32\Tasks\COMODO => moved successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{90BA0751-0E8B-47AB-8D0C-1382229D6E3A} => key removed successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{90BA0751-0E8B-47AB-8D0C-1382229D6E3A} => key removed successfully
    C:\WINDOWS\System32\Tasks\{31DDBD37-5DB7-4030-8064-10B0CAA806C3} => moved successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{31DDBD37-5DB7-4030-8064-10B0CAA806C3} => key removed successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A8A2D02D-661C-4222-9E9B-B42B43AB2D9C} => key removed successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A8A2D02D-661C-4222-9E9B-B42B43AB2D9C} => key removed successfully
    C:\WINDOWS\System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => key removed successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B4897E97-7A18-4F7A-A872-2ABDF4E5F601} => key removed successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4897E97-7A18-4F7A-A872-2ABDF4E5F601} => key removed successfully
    C:\WINDOWS\System32\Tasks\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627} => not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627} => key removed successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CD5F0113-2871-44D3-A176-52D36E968E44} => key removed successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CD5F0113-2871-44D3-A176-52D36E968E44} => key removed successfully
    C:\WINDOWS\System32\Tasks\COMODO\COMODO Maintenance {947247B5-026A-4437-9371-770782BE839D} => not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\COMODO\COMODO Maintenance {947247B5-026A-4437-9371-770782BE839D} => key removed successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D4D68587-13B1-499D-BED2-668EBB9821C1} => key removed successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D4D68587-13B1-499D-BED2-668EBB9821C1} => key removed successfully
    C:\WINDOWS\System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => key removed successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{EFDFBAFB-9819-4D51-BA1E-A06E6B00A901} => key removed successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EFDFBAFB-9819-4D51-BA1E-A06E6B00A901} => key removed successfully
    C:\WINDOWS\System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => key removed successfully
    C:\WINDOWS\explorer.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\HelpPane.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\regedit.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\splwow64.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\aadcloudap.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\aadtb.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AboveLockAppHost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\accountaccessor.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AccountsRt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\acmigration.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ActionCenter.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ActionCenterCPL.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ActivationManager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ActiveSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\actxprxy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\adsmsext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\aeinv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\aepic.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\aitstatic.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AppCapture.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AppContracts.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\appinfo.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ApplicationFrame.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AppointmentApis.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\appraiser.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AppReadiness.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\apprepapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\apprepsync.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\appwiz.cpl => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AppXApplicabilityBlob.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AppXDeploymentClient.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AppXDeploymentServer.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AppxPackaging.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\asycfilt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\atmfd.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\atmlib.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AudioSes.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AudioSrvPolicyManager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AuthBroker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AuthHost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\authui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\autoplay.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\AzureSettingSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\BackgroundMediaPolicy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\basecsp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\bcastdvr.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\BcastDVRHelper.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\bcdedit.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\bcrypt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\bdesvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\bdeui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\bdeunlock.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\BingMaps.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\bisrv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\BitLockerDeviceEncryption.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\biwinrt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\BluetoothApis.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\BluetoothDesktopHandlers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\BootMenuUX.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\bootux.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\browserbroker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\BrowserSettingSync.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\BthRadioMedia.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CameraCaptureUI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CastLaunch.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\cdd.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\cdp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\cdpreference.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\cdpsvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\cdpusersvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CellularAPI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\cemapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CertEnroll.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\certprop.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CfgSPCellular.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Chakra.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\chartv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ChatApis.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ci.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CloudBackupSettings.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CloudExperienceHost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CloudExperienceHostBroker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CloudExperienceHostCommon.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CloudExperienceHostUser.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CloudStorageWizard.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\clusapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\cmifw.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\cmintegrator.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CNC280C.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CNC280I.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CNC280L.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CNC280O.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CNHI10A.DLL => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CNHL280.DLL => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CNHMCA6.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CNHMCAN.DLL => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CNMIUAA.DLL => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CNMLMAA.DLL => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\combase.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\comdlg32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CompatTelRunner.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CompPkgSup.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\comsvcs.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ContactApis.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CoreMessaging.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CoreUIComponents.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CPFilters.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CredProvDataModel.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\credprovhost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\credprovs.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\credprovslegacy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\crypt32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\cryptngc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CryptoWinRT.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\CspCellularSettings.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\d2d1.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\d3d10warp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\d3d11.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\d3d9.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\D3DCompiler_47.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dab.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dafBth.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dafpos.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DafPrintProvider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DataExchange.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DataSenseHandlers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DavSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\daxexec.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dbgeng.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dcntel.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DdcWnsListener.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ddraw.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ddrawex.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\devenum.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\deviceaccess.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DeviceCensus.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DeviceCenter.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DeviceDirectoryClient.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DeviceEnroller.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DeviceFlows.DataModel.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DevicePairing.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DevicePairingFolder.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DeviceReactivation.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\devinv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dfp.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DfpCommon.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dhcpcore6.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\diagtrack.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dialclient.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dialserver.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\discan.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Display.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DisplayManager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dlnashext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dmcertinst.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dmenrollengine.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DMRServer.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dnsapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dnsrslvr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DolbyDecMFT.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dosvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dpapisrv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\drvstore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dsreg.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dsregcmd.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DuCsps.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dui70.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dwmapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dwmcore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DWrite.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dxgi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\DXP.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\dxtrans.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\EAMProgressHandler.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\easwrt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\edgehtml.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\EditBufferTestHook.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\EditionUpgradeHelper.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\EditionUpgradeManagerObj.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\EDPCleanup.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\efsext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\efswrt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\EmailApis.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\EncDec.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\energy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\enrollmentapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\EnterpriseAPNCsp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\enterprisecsps.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ErrorDetails.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ErrorDetailsUpdate.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\esent.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\esentutl.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\evr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ExplorerFrame.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ExSMime.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\facecredentialprovider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Family.Authentication.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Family.Client.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Family.SyncEngine.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ffbroker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\fhcfg.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\fhcpl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\FlightSettings.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\flvprophandler.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\FntCache.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\fontdrvhost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\fontext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\FontProvider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\FrameServer.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\FSClient.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\fveapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\fveapibase.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\fvecpl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\fvenotify.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\fveui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\fvewiz.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\GamePanel.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\GamePanelExternalHook.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\gameux.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\gdi32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\gdi32full.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\GdiPlus.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\generaltel.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Geolocation.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\GlobCollationHost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\gpapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\gpsvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\hal.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\hevcdecoder.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\hgcpl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\HttpsDataSource.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\hvax64.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\hvix64.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\hvloader.efi => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\hvloader.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\icfupgd.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\icm32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\icsvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\icsvcext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\IdCtrls.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ie4uinit.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ieapfltr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\iedkcs32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ieframe.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\iepeers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ieproxy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\iertutil.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\imapi2.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\imapi2fs.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\indexeddbserver.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\inetcomm.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\inetcpl.cpl => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\input.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\InputLocaleManager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\InputService.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\InstallAgent.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\InstallAgentUserBroker.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\internetmail.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\invagent.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\IPHLPAPI.DLL => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\iphlpsvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ipnathlp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\iprtrmgr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\iscsiwmi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\JpMapControl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\jscript9.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\kerberos.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\KernelBase.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\LaunchWinApp.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\LicenseManager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ListSvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\localspl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\LocationFramework.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\LockAppBroker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\LockAppHost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\LogonController.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\lpremove.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\LsaIso.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\lsasrv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\lsm.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\main.cpl => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\manage-bde.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MapConfiguration.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MapControlCore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MapGeocoder.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MapRouter.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MapsBtSvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MapsStore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MbaeApiPublic.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mbsmsapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MCCSEngineShared.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MCRecvSrc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MDMAppInstaller.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mdmregistration.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mf.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfasfsrcsnk.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfaudiocnv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MFCaptureEngine.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfcore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfds.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfksproxy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MFMediaEngine.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfmjpegdec.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfmkvsrcsnk.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfmp4srcsnk.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfmpeg2srcsnk.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfnetcore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfnetsrc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfplat.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MFPlay.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfps.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfreadwrite.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfsensorgroup.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfsrcsnk.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mfsvr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\microsoft-windows-system-events.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\migisol.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MiracastReceiver.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mispace.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mmc.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MMDevAPI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\modernexecserver.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mos.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\moshost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\moshostcore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MosStorage.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mprapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mprddm.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mprdim.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MPSSVC.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MrmCoreR.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MRT.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MSAC3ENC.DLL => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MSAudDecMFT.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mscandui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msctf.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msctfp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msctfui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msdtcprx.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msdtctm.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msdtcuiu.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msfeeds.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msftedit.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mshtml.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mshtmled.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msinfo32.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msmpeg2vdec.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mspaint.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MSPhotography.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mssitlb.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mssph.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mssphtb.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mssprxy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mssrch.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mssvp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mstsc.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\mstscax.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msutb.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MSVidCtl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MSVideoDSP.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MSVP9DEC.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msvproc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MSVPXENC.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msxml3.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\msxml6.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MultiDigiMon.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\musdialoghandlers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MusNotification.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MusNotificationUx.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\MusUpdateHandlers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NaturalLanguage6.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ncsi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\netiohlp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\netiougc.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\netplwiz.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NetSetupApi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NetSetupEngine.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NetSetupShim.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NetSetupSvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\netshell.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\nettrace.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NetworkCollectionAgent.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NetworkDesktopSettings.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NetworkMobileSettings.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NetworkUXBroker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NfcRadioMedia.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ngccredprov.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NgcCtnr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NgcCtnrGidsHandler.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NgcCtnrSvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ngcsvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\nlasvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\nltest.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NMAA.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NotificationController.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\NPSM.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\nshwfp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ntdll.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ntoskrnl.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ntshrui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\nvaudcap64v.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\nvdispco6431141.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\nvdispco6435582.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\nvdispco6435598.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\nvdispco6435850.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\nvdispgenco6431141.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\nvdispgenco6435582.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\nvdispgenco6435598.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\nvdispgenco6435850.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\odbcconf.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\offreg.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ole32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\oleacc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\oleaut32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\OnDemandConnRouteHelper.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\OneBackupHandler.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\pcasvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\PCPTpm12.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\pdh.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\PhotoScreensaver.scr => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\PimIndexMaintenance.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Pimstore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\PlayToDevice.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\PlayToManager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\PlayToReceiver.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\pnidui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\policymanager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\poqexec.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\powercfg.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\PrintDialogs.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\PrintDialogs3D.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\PrintRenderAPIHost.DLL => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\PrintWSDAHost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\profsvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\provops.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ProvSysprep.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\PsmServiceExtHost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\psmsrv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\puiapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\puiobj.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\pwrshplugin.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\qedit.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\qmgr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\quartz.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\RADCUI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\rasapi32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\rascustom.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\rasgcw.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\rasmans.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\rdpcorets.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\rdpencom.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\RdpRelayTransport.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\rdpudd.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\RDXService.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\RDXTaskFactory.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ReAgent.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ReAgentc.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\RelPost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\RemoteNaturalLanguage.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ReportingCSP.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\reseteng.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ResetEngine.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\resutils.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\RjvMDMConfig.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\RMapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\rshx32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\RTMediaFrame.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\RTWorkQ.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\sbe.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\schannel.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\scksp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\sdengin2.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\sdnclean64.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\sdshext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SearchFilterHost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SearchFolder.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SearchIndexer.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SearchProtocolHost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SecConfig.efi => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\sendmail.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Sens.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SensorDataService.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SensorsApi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SensorService.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\services.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SessEnv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SettingsHandlers_ClosedCaptioning.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SettingsHandlers_Flights.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SettingsHandlers_nt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SettingSync.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SettingSyncCore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SettingSyncHost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\setupugc.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SharedStartModel.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ShareHost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SHCore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\shdocvw.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\shell32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\shutdownux.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\skci.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\smartscreen.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\smphost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SndVolSSO.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SpaceAgent.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SpaceControl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\spaceman.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SpeechPal.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\spoolsv.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\sppcext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\sppnp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\sppobjs.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\sppsvc.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\sppwinob.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\sspicli.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\stobject.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\storagewmi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\StoreAgent.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\StorSvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\StructuredQuery.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\sud.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SyncCenter.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SyncSettings.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\systemreset.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SystemSettings.Handlers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SystemSettingsAdminFlows.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Tabbtn.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\tabcal.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\TabletPC.cpl => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\tapi32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\taskbarcpl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\tbauth.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\tdh.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\TextInputFramework.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\themecpl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\thumbcache.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\timedate.cpl => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\TokenBroker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\TokenBrokerCookies.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\TokenBrokerUI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\TpmCoreProvisioning.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\TpmTasks.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\tquery.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\TSpkg.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\TSWorkspace.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\twinapi.appcore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\twinapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\twinui.appcore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\twinui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\twinui.pcshell.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\tzautoupdate.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ubpm.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\uDWM.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\UIAnimation.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\UIAutomationCore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\UIRibbon.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\UIRibbonRes.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\umpoext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\unimdm.tsp => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Unistore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\updatehandlers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\updatepolicy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\uReFS.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\urlmon.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\usbmon.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\user32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\usercpl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\UserDataService.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\UserDataTimeUtil.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\UserDeviceRegistration.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\UserLanguagesCpl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\usermgr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\UserMgrProxy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\usoapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\usocore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\UtcResources.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\vaultcli.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\vbscript.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\VCardParser.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\vds.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\VEStoreEventHandlers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\vmrdvcore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\vpnike.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\VPNv2CSP.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\vssapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\VSSVC.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\vss_ps.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wbengine.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wcmsvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wcnwiz.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wc_storage.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WebcamUi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\webcheck.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\webio.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wer.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\werconcpl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\weretw.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\werui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wevtsvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wfdprov.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wifinetworkmanager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wifitask.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\win32kbase.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\win32kfull.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\win32spl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wincorlib.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.AccountsControl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.ApplicationModel.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Cortana.Desktop.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Cortana.OneCore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Data.Pdf.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.Lights.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.LowLevel.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.Midi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.Perception.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.Picker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.PointOfService.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.Printers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.Radios.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.Scanners.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.Sensors.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.SmartCards.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.Usb.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.WiFi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Energy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Gaming.Input.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Gaming.UI.GameBar.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Globalization.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Graphics.Printing.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Internal.Management.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.Audio.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.Devices.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.Editing.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.Import.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.MediaControl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.Ocr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.Speech.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Media.Streaming.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Networking.Connectivity.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Networking.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Networking.HostName.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Networking.Vpn.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Perception.Stub.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Security.Credentials.UI.CredentialPicker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.StateRepository.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.StateRepositoryClient.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\windows.storage.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Storage.Search.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.System.SystemManagement.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.System.UserDeviceAssociation.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.Cred.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.Immersive.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.Input.Inking.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.Logon.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.Search.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.Shell.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.Xaml.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Web.Diagnostics.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Web.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Windows.Web.Http.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WindowsCodecs.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\winhttp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wininet.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wininetlui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\winload.efi => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\winload.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\winmde.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\winresume.efi => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\winresume.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WinRtTracing.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WinSetupUI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\winspool.drv => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\winsrv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wintrust.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WinTypes.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wkssvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wlanapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wlancfg.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WlanMediaManager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wlansec.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wlansvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wlanui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wlidprov.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wlidsvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wmp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WMPDMC.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wmpdxm.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wmpeffects.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wmpmde.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wmpps.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wmpshell.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WMVDECOD.DLL => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WordBreakers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WorkFolders.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WorkfoldersControl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WorkFoldersGPExt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WorkFoldersShell.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\workfolderssvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WpAXHolder.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Wpc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WpcMon.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WpcRefreshTask.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WpcTok.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WpcWebFilter.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wpnapps.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wpncore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wpninprc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wpnprv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wpx.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\ws2_32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wscapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wscinterop.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wscsvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wscui.cpl => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wsecedit.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WSManHTTPConfig.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WSManMigrationPlugin.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WsmSvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WsmWmiPl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wsp_fs.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wsp_health.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wsp_sr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wu.upgrade.ps.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wuapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wuaueng.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wups.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wuuhext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WwaApi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WWAHost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\WWanAPI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wwanconn.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wwanmm.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\wwansvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\XblAuthManager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\XblAuthManagerProxy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\XblGameSaveExt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\XboxNetApiSvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\XInputUap.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\xpsrchvw.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\zipfldr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\aadtb.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\AboveLockAppHost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\accountaccessor.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ActionCenterCPL.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ActivationManager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\actxprxy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\adsmsext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\aepic.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\AiCM32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\AiCM64.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\apds.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\api-ms-win-crt-math-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\api-ms-win-crt-private-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\api-ms-win-crt-string-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\api-ms-win-crt-time-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\AppCapture.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\AppContracts.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\AppointmentActivation.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\AppointmentApis.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\apprepapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\apprepsync.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\appwiz.cpl => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\AppxPackaging.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\asycfilt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\atmfd.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\atmlib.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\AudioSes.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\AuthBroker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\AuthExt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\authui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\autoplay.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\azroleui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\BackgroundMediaPolicy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\basecsp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\bcastdvr.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\BcastDVRHelper.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\bcrypt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\BingMaps.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\biwinrt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\BluetoothApis.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\BrowserSettingSync.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CameraCaptureUI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\cdp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\cemapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CertEnroll.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Chakra.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Chakradiag.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\chartv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ChatApis.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ClipboardServer.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CloudBackupSettings.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CloudStorageWizard.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\clusapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\cmifw.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CNC280L.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CNC280U.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CNHMCA.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\combase.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\comctl32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\comdlg32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CompPkgSup.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\comsvcs.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ContactApis.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CoreMessaging.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CoreUIComponents.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CPFilters.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CredProvDataModel.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\credprovhost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\credprovs.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\credprovslegacy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\crypt32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\cryptngc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\CryptoWinRT.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\d3d10warp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\d3d11.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\d3d8.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\d3d9.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\D3DCompiler_47.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\d3dx9_34.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\DafPrintProvider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\DataExchange.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\DavSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\daxexec.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\dbgeng.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ddraw.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ddrawex.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\devenum.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\deviceaccess.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\DevicePairing.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\dhcpcore6.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\dialclient.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\DisplayManager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\dlnashext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\dmenrollengine.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\dnsapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\DolbyDecMFT.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\drvstore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\dsreg.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\dtdump.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\dwmapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\dwmcore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\DWrite.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\dxgi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\dxtrans.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\edgehtml.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\EditBufferTestHook.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\efsext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\efswrt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\EmailApis.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\enrollmentapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ErrorDetails.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ErrorDetailsUpdate.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\esent.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\esentutl.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\evr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\explorer.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ExplorerFrame.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ExSMime.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\findnetprinters.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\FlashPlayerApp.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\fontdrvhost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\fontext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\FSClient.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\GamePanelExternalHook.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\gameux.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\gdi32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\gdi32full.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\GdiPlus.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Geolocation.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\GlobCollationHost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\gpapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\hevcdecoder.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\hgcpl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\icm32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ieapfltr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\iedkcs32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ieframe.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\iepeers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ieproxy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\iertutil.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\imapi2.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\imapi2fs.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\indexeddbserver.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\inetcomm.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\inetcpl.cpl => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\input.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\InputLocaleManager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\InputService.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\InstallAgent.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\IPHLPAPI.DLL => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\iprtrmgr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ipsecsnp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ipsmsnap.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\iscsiwmi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\JpMapControl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\jscript9.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\jscript9diag.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\kerberos.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\KernelBase.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\LaunchWinApp.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\LicenseManager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\LicenseManagerApi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\LockAppBroker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\LockAppHost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\LogonController.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\main.cpl => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MapConfiguration.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MapControlCore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MapGeocoder.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MapRouter.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MapsBtSvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MbaeApiPublic.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mbsmsapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MCCSEngineShared.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MCRecvSrc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mdmregistration.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mf.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfaudiocnv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfcore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfds.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfksproxy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MFMediaEngine.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfmjpegdec.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfnetcore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfnetsrc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfplat.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MFPlay.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfreadwrite.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfsensorgroup.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfsrcsnk.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mfsvr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\migisol.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MiracastReceiver.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mispace.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mmc.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MMDevAPI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mos.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MosStorage.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mprapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mprddm.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mprdim.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MrmCoreR.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MSAC3ENC.DLL => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mscandui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mscms.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msctf.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msctfp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msctfui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msdtcprx.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msdtcuiu.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msfeeds.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msftedit.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mshtml.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mshtmled.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msinfo32.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msmpeg2vdec.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mspaint.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MSPhotography.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mssitlb.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mssph.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mssphtb.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mssrch.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mssvp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mstsc.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mstscax.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msutb.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MSVidCtl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MSVP9DEC.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msvproc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\MSVPXENC.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msxml3.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\msxml6.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\mtxclu.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\NaturalLanguage6.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\netiohlp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\netiougc.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\NetSetupApi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\NetSetupEngine.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\NetSetupShim.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\netshell.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\NetworkCollectionAgent.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ngccredprov.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\NMAA.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\NPSM.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\nshwfp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ntdll.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ntshrui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\nvaudcap32v.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\nvStreaming.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\odbcconf.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\offreg.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ole32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\oleacc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\oleaut32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\olepro32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\OneDriveSetup.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\PCPTpm12.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\pdh.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\PhotoScreensaver.scr => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Pimstore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\PlayToDevice.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\PlayToManager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\PlayToReceiver.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\policymanager.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\poqexec.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\powercfg.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\PrintDialogs.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ProximityCommon.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\puiapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\puiobj.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\pwrshplugin.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\quartz.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\RADCUI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\rasapi32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\rasgcw.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ReAgent.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ReAgentc.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\regedit.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\resutils.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\RTMediaFrame.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\RTWorkQ.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\sbe.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\schannel.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\scksp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\SearchFilterHost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\SearchFolder.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\SearchIndexer.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\SearchProtocolHost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\sendmail.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\SessEnv.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\SettingSync.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\SettingSyncCore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\SettingSyncHost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\setupugc.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ShareHost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\SHCore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\shell32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\smphost.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\SndVolSSO.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\sppcext.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\sspicli.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\stobject.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\storagewmi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\StoreAgent.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\StructuredQuery.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\sud.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\SyncSettings.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\systemcpl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\tapi32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\tbauth.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\tcpipcfg.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\tdh.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\TempSignedLicenseExchangeTask.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\TextInputFramework.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\themecpl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\thumbcache.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\TokenBroker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\TokenBrokerUI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\tquery.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\tsmf.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\TSpkg.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\TSWorkspace.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\twinapi.appcore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\twinapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\twinui.appcore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\twinui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\UIAnimation.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\UIAutomationCore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\UIRibbon.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\UIRibbonRes.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\unimdm.tsp => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Unistore.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\updatepolicy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\uReFS.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\urlmon.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\user32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\usercpl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\UserDataAccountApis.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\UserDeviceRegistration.Ngc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\UserMgrProxy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\usoapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\vaultcli.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\vbscript.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\VCardParser.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\vssapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wcnwiz.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WebcamUi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\webcheck.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\webio.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wer.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\weretw.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wfdprov.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\win32kfull.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wincorlib.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Wallet.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.Lights.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.Perception.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.Radios.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.SerialCommunication.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.WiFi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Energy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Gaming.UI.GameBar.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Gaming.XboxLive.Storage.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Globalization.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.FaceAnalysis.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.Import.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.Ocr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Networking.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Networking.HostName.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.StateRepository.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\windows.storage.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.System.SystemManagement.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.System.UserDeviceAssociation.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.UI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.UI.Search.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.UI.Xaml.InkControls.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Web.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Windows.Web.Http.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WindowsCodecs.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\winhttp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wininet.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wininetlui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\winmde.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WinRtTracing.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\winspool.drv => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wintrust.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WinTypes.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wlanapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wlancfg.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wlanui.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wlidcli.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wlidprov.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wmp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WMPDMC.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wmpdxm.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wmpeffects.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wmpmde.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wmpshell.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WMVSENCD.DLL => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WordBreakers.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\Wpc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WpcWebFilter.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WPDShServiceObj.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wpnapps.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\ws2_32.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wscapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wscinterop.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wscui.cpl => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wsecedit.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WsmSvc.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WsmWmiPl.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wsp_fs.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wsp_health.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wsp_sr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\wuapi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WwaApi.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WWAHost.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\WWanAPI.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\XInputUap.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\xolehlp.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\xpsrchvw.exe => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\SysWOW64\zipfldr.dll => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\afd.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\ahcache.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\BasicDisplay.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\BasicRender.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\bowser.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\BthLEEnum.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\bthpan.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\bthport.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\capimg.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\Classpnp.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\clfs.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\cmimcext.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\cng.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\crashdmp.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\dam.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\dfsc.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\dumpsd.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\dxgkrnl.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\dxgmms1.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\dxgmms2.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\fastfat.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\fvevol.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\hidclass.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\http.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\hvsocket.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\iorate.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\IPMIDrv.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\kbdhid.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\ks.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\MegaSas2i.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\modem.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\mrxdav.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\mrxsmb.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\mrxsmb10.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\mrxsmb20.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\msiscsi.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\mskssrv.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\ndis.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\ntfs.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\nvvad64v.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\nwifi.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\partmgr.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\pdc.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\rdbss.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\sdbus.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\spaceport.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\srv.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\srv2.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\ssudbus.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\ssudmdm.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\storahci.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\stornvme.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\storport.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\tcpip.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\tcpipreg.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\tdx.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\tm.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\tpm.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\usbscan.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\vmbkmcl.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\vmbkmclr.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\vpci.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\wcifs.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\WdiWiFi.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\winhvr.sys => ":$CmdTcID" ADS removed successfully.
    C:\WINDOWS\system32\Drivers\xboxgip.sys => ":$CmdTcID" ADS removed successfully.
    C:\Users\Public\Desktop\Post Win10 Spybot-install.exe => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Desktop\Andy-Guitar-Beginners-Course-eBook-Feb-2015.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Desktop\Supercharged-Hormone-Diet-Belly-Fat-Plan.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\2014-15 Approved SYC-FINAL(1).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\2014-15 Approved SYC-FINAL(2).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\2014-15 Approved SYC-FINAL(3).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\2014-15 Approved SYC-FINAL(4).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\2014-15 Approved SYC-FINAL.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\22LittleCloudsENGLISH.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\aimer-video-ultimate_setup_full523.exe => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\AllProducts.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\avast_free_antivirus_setup_offline.exe => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Avery-Label-6450(1).avery => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\BagpipePlayer.exe => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\BGPlayer(1).exe => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\BGPlayer.exe => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\bluebells.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\BMW1____.TTF => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\bonnie_dundee.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Bonny-Galloway-set.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Book01 15(1).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Book01 15(2).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Book01 15.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\BP-setup.exe => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\bruces-address-advanced(1).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\bruces-address-advanced.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Castle Dangerous Set LCPD.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\CoWPaD Castle Dangerous Seconds.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\DarkMarkIllusionScarf.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\FitbitConnect_Win_20150619_2.0.0.6598.exe => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\flashplayer24_jd_install.exe => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\GoogleEarthPluginSetup.exe => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\gordon pipe.2.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\gordon pipe.3.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\gordon pipe.4.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\gordon pipe.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Heroes-of-the-Storm-Setup-enUS.exe => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Im-a-believer.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\jfrd_tune_settings_book_05-2015.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Jig1(1).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Jig1.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Jig2.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\killiecrankie.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\laceyarchesinfinityscarf_aiid508740.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Little_Rucksack_Susie_ENG6.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\maris wedding.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\MarysMarch(1).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\MarysMarch.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Ontario Railway Map Collection.kmz => ":$CmdTcID" ADS could not remove.
    C:\Users\R\Downloads\Ontario Railway Map Collection.kmz => ":$CmdZnID" ADS could not remove.
    C:\Users\R\Downloads\PDQB-Exercises(1).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\PDQB-Exercises(2).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\PDQB-Exercises(3).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\PDQB-Exercises.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Reel1.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\scotswhahae.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Secondhand-News(1).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Secondhand-News(2).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Secondhand-News(3).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Secondhand-News(4).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Secondhand-News.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\ServiceOntario Providing your Copy of Your Electronic Product.zip => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\sgt_mackenzie(1).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\sgt_mackenzie(2).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\sgt_mackenzie(3).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\sgt_mackenzie(4).pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\sgt_mackenzie.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Silverlight_x64.exe => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\springtimebandit_aiid145528.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Tachum1.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Thinking-out-loud.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\vol-4-track.pdf => ":$CmdTcID" ADS removed successfully.
    C:\Users\R\Downloads\Warmup1.pdf => ":$CmdTcID" ADS removed successfully.

    ========= ipconfig /flushdns =========


    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    ========= End of CMD: =========


    ========= netsh winsock reset all =========


    Sucessfully reset the Winsock Catalog.
    You must restart the computer in order to complete the reset.


    ========= End of CMD: =========


    ========= netsh int ipv4 reset =========

    Resetting Global, OK!
    Resetting Interface, OK!
    Resetting Unicast Address, OK!
    Resetting Neighbor, OK!
    Resetting Path, OK!
    Resetting , failed.
    Access is denied.

    Resetting , OK!
    Restart the computer to complete this action.


    ========= End of CMD: =========


    ========= netsh int ipv6 reset =========

    Resetting Interface, OK!
    Resetting Neighbor, OK!
    Resetting Path, OK!
    Resetting Subinterface, OK!
    Resetting , failed.
    Access is denied.

    Resetting , OK!
    Resetting , OK!
    Restart the computer to complete this action.


    ========= End of CMD: =========

    C:\Windows\System32\Drivers\etc\hosts => moved successfully
    Hosts restored successfully.

    =========== EmptyTemp: ==========

    BITS transfer queue => 0 B
    DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 21214828 B
    Java, Flash, Steam htmlcache => 291 B
    Windows/system/drivers => 89485691 B
    Edge => 30208 B
    Chrome => 0 B
    Firefox => 200580182 B
    Opera => 0 B

    Temp, IE cache, history, cookies, recent:
    Default => 0 B
    Users => 0 B
    ProgramData => 0 B
    Public => 0 B
    systemprofile => 128 B
    systemprofile32 => 128 B
    LocalService => 34204 B
    NetworkService => 14886 B
    R => 111371487 B

    RecycleBin => 244717 B
    EmptyTemp: => 403.4 MB temporary data Removed.

    ================================


    The system needed a reboot.

    ==== End of Fixlog 12:13:27 ====

  2. #22
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Well, no message of imminent computer meltdown unless I reinstall comodo, which is awesome! And I can connect to the internet still. My programs are opening again, and actually running.
    Looks like we did good, are you going to reinstall comodo again? (If you do I'm going into hiding)

    Only thing I think we need to do now is run an online scan.

    • Download Emsisoft Emergency Kit and save it to your desktop.
    • Double-click icon then click Install
    • A Window should open highlighting Start Emergency Kit Scanner
    • Right click on the icon and select Run as administrator
    • Click 1. Update now!
    • Once the update is completed select Settings under Scan
    • Uncheck Join the Emsisoft Anti-Malware Network
    • Click Scan at the top
    • Click On scan completion
    • Click Quarantine detected objects, then click OK
    • Click Malware Scan
    • Once completed click View Report
    • Save the file to your Desktop using the default file name
    • Copy and paste the report in your reply

    ======
    Last edited by Juliet; 2017-04-30 at 20:51.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  3. #23
    Member
    Join Date
    Nov 2010
    Posts
    63

    Default

    I am no going to reinstall comodo, lol!! Unpack those bags

    Emsisoft Emergency Kit - Version 2017.2
    Last update: 4/30/2017 1:06:48 PM
    User account: momlaptop\Rachel
    Computer name: MOMLAPTOP
    OS version: Windows 10x64

    Scan settings:

    Scan type: Malware Scan
    Objects: Rootkits, Memory, Traces, Files

    Detect PUPs: On
    Scan archives: Off
    ADS Scan: On
    File extension filter: Off
    Direct disk access: Off

    Scan start: 4/30/2017 1:08:36 PM

    Scanned 86202
    Found 0

    Scan end: 4/30/2017 1:14:56 PM
    Scan time: 0:06:20

  4. #24
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    I am no going to reinstall comodo, lol!! Unpack those bags
    LOL

    Are we ready to remove tools and quarantine folders?
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  5. #25
    Member
    Join Date
    Nov 2010
    Posts
    63

    Default

    I believe we are, woohoo!

    Oh, I just tried to turn on windows defender but it just gives me the message there is another program handling it. I took a look in my programs and I find comodo listed there still. Was not able to use the uninstall function.

  6. #26
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Just when I thought it was safe.......
    OK
    • Please download and install Revo Uninstaller.
    • Double-click Revo Uninstaller to run the programme.
    • From the list of programmes, locate the following (anything with a COMODO name), or anything similar and carry out the steps below one at a time.
    • When prompted if you want to uninstall click Yes.
    • Ensure the Moderate option is selected and click Next.
    • The programme uninstaller will run. If prompted again click Yes.
    • Work your way through the uninstaller, ensuring you read each page thoroughly.
    • Note: If you are offered the choice to install additional software, ensure you decline.
    • Once the built-in uninstaller is finished click Next.
    • Once the programme has searched for leftovers click Next.
    • Check items in bold only in the list and click Delete. You may have to expand folders by clicking the "+" mark.
    • When prompted click Yes, followed by Next.
    • Click Select all, followed by Delete.
    • When prompted click Yes, followed by Next.
    • Upon completion, click Finish.
    • In your next reply, confirm you were successful in uninstalling all programmes listed above.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  7. #27
    Member
    Join Date
    Nov 2010
    Posts
    63

    Default

    Ok, wow lots of stuff on there.

    I managed to remove all entries and comodo is no longer showing up in my programs list. Windows defender still wont turn on. I will reboot and see if anything pops up.

  8. #28
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    rebooting help?
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  9. #29
    Member
    Join Date
    Nov 2010
    Posts
    63

    Default

    Nope, every time I try to turn on windows defender I get the message that another AV program is helping to protect my pc.

  10. #30
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    grrrrr... Comodo!
    Antivirus are designed to turn off windows defender and firewall for their security suites.

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      Comodo
      :folderfind
      Comodo
      :regfind
      Comodo
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •