cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Additional scan result of Farbar Recovery Scan Tool (x64) Version:13-07-2015
Ran by enna at 2015-07-14 16:47:09
Running from C:\Users\enna\Downloads
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrateur (S-1-5-21-1043922925-1157543147-587559754-500 - Administrator - Disabled)
enna (S-1-5-21-1043922925-1157543147-587559754-1001 - Administrator - Enabled) => C:\Users\enna
HomeGroupUser$ (S-1-5-21-1043922925-1157543147-587559754-1111 - Limited - Enabled)
Invité (S-1-5-21-1043922925-1157543147-587559754-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acer Arcade Deluxe (HKLM-x32\...\InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: 3.0.7006 - CyberLink Corp.)
Acer Arcade Deluxe (x32 Version: 3.0.7006 - CyberLink Corp.) Hidden
Acer Crystal Eye webcam Ver:1.1.124.1120 (HKLM-x32\...\{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}) (Version: 1.1.124.1120 - Chicony Electronics Co.,Ltd.)
Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 4.05.3004 - Acer Incorporated)
Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.02.3006 - Acer Incorporated)
Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.01.3017 - Acer Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated)
Adobe Flash Player 10 Plugin (HKLM-x32\...\{AF36CE1D-FD2C-4BA0-93FA-1196785DD610}) (Version: 10.0.45.2 - Adobe Systems, Inc.)
Adobe Reader XI (11.0.05) - Français (HKLM-x32\...\{AC76BA86-7AD7-1036-7B44-AB0000000001}) (Version: 11.0.05 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{63EC2120-1742-4625-AA47-C6A8AEC9C64C}) (Version: 2.2.2 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Archiveur WinRAR (HKLM-x32\...\WinRAR archiver) (Version: - )
Ask Toolbar (HKLM-x32\...\{86D4B82A-ABED-442A-BE86-96357B70F4FE}) (Version: 1.14.1.0 - Ask.com) <==== ATTENTION
Avast Free Antivirus (HKLM-x32\...\avast) (Version: 10.2.2218 - AVAST Software)
Big Fish: Game Manager (HKLM-x32\...\BFGC) (Version: 3.2.0.7 - )
CCleaner (HKLM\...\CCleaner) (Version: 5.02 - Piriform)
Fissa (HKLM-x32\...\Fissa) (Version: 1.0 - Secure Digital Services) <==== ATTENTION
Free YouTube Download version 3.2.59.616 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.59.616 - DVDVideoSoft Ltd.)
Galerie de photos Windows Live (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-1043922925-1157543147-587559754-1001\...\Google Chrome) (Version: 43.0.2357.132 - Google Inc.)
HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_HDA_HSF) (Version: 7.80.4.55 - Conexant Systems)
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
Installation Windows Live (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Installation Windows Live (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Java 7 Update 80 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217080FF}) (Version: 7.0.800 - Oracle)
Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\...\LManager) (Version: 3.0.03 - Acer Inc.)
Logiciel de base du périphérique HP Deskjet 2540 series (HKLM\...\{61F924AD-D5DC-4F1B-A17C-C9813BB72438}) (Version: 30.0.1093.41190 - Hewlett-Packard Co.)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professionnel Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Primary Interoperability Assemblies 2005 (HKLM-x32\...\{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Module linguistique Microsoft Visual Studio 2010 Tools pour Office Runtime (x64) - FRA (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - FRA) (Version: 10.0.50903 - Microsoft Corporation)
MyWinLocker (HKLM-x32\...\{68301905-2DEA-41CE-A4D4-E8B443B099BA}) (Version: 3.1.76.0 - Egis Technology Inc.)
Nuvoton EC Generic HID Driver (HKLM-x32\...\{92975DF9-EA36-4F36-A9AC-D412BC1D709E}) (Version: 8.80.1001 - Nuvoton Technology Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.9 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{1C4551A6-4743-4093-91E4-1477CD655043}) (Version: 9.09.0203 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
PC Mechanic (HKLM-x32\...\{1F88FC5D-4D46-448A-AF59-7061FFC6ABBF}_is1) (Version: 1.0.7.1 - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5992 - Realtek Semiconductor Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.6.0 - Synaptics Incorporated)
TuneUp Utilities Language Pack (fr-FR) (x32 Version: 9.0.6000.10 - TuneUp Software) Hidden
VLC media player 2.0.8 (HKLM-x32\...\VLC media player) (Version: 2.0.8 - VideoLAN)
VoiceOver Kit (HKLM-x32\...\{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}) (Version: 1.42.128.0 - Apple Inc.)
Vuze (HKLM\...\8461-7759-5462-8226) (Version: 5.6.1.2 - Azureus Software, Inc.)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1043922925-1157543147-587559754-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\enna\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1043922925-1157543147-587559754-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\enna\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-1043922925-1157543147-587559754-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\enna\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)

==================== Restore Points =========================

13-07-2015 16:44:15 Opération de restauration
13-07-2015 16:52:02 avast! antivirus system restore point
13-07-2015 17:02:22 Windows Update
13-07-2015 17:06:33 Opération de restauration
13-07-2015 17:30:29 Windows Update

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {04050D71-DDE6-462B-A3D7-E86CBE85DCBA} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {0FE90DEA-2255-43C4-AA88-452E1765D423} - System32\Tasks\McQcModifier-5c47-a7b0 => C:\ProgramData\McQcModifier-5c47-a7b0\McQcModifier-5c47-a7b0.cmd [2009-08-29] ()
Task: {2548BB30-44D8-42E7-822E-48DB6C6B4D1D} - System32\Tasks\{2B85307D-1410-4B11-9D7C-B43D61F8ACEF} => pcalua.exe -a "C:\Program Files (x86)\Dark Strokes - Sins of the Fathers Collector's Edition\Uninstall.exe" -d "C:\Program Files (x86)\Dark Strokes - Sins of the Fathers Collector's Edition"
Task: {2A3877F7-86F0-439A-B2EF-EBCC0AD738E8} - \Programme de mise à jour en ligne de HP. No Task File <==== ATTENTION
Task: {38800E5E-A5C1-4EEA-8072-C6059D705F3D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-01-20] (Piriform Ltd)
Task: {3CDC80EE-F05B-48DE-8355-8497B93490EE} - System32\Tasks\PC-Mechanic Startup => C:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe [2015-05-29] ()
Task: {4E5F6C4B-D76C-4348-BC22-A7CBB89B8D5B} - System32\Tasks\{52BC95EE-7A40-47CA-AB86-91629E593D94} => pcalua.exe -a "C:\Users\enna\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MSEZW54O\echoes-past-castle-shadows-collectors-edition_s1_l1_gF5851T1L1_d969205661[1].exe" -d C:\Users\enna\Desktop
Task: {58CCC7B9-DEE6-479D-B5E9-FBFC245CFAE4} - System32\Tasks\{500BA8B7-C149-41BE-BEA4-9CD063EE9407} => pcalua.exe -a C:\Users\enna\AppData\Roaming\FissaSearch\FissaUninstaller.exe -c /quiet
Task: {5B6600F0-5171-49C4-813E-0A5A9AC7C099} - System32\Tasks\PC-Mechanic Subscription => C:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe [2015-05-29] ()
Task: {5BCF61F3-9039-489C-8B46-5D1F56D62A2D} - System32\Tasks\Programme de mise à jour en ligne de Egis technology => C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [2009-08-04] (Egis Technology Inc.)
Task: {5D605A17-ECBC-416B-AA90-A9E80EB49BC6} - System32\Tasks\Chromium => C:\Users\enna\AppData\Local\Chromium\APPLIC~1\440238~1.0\INSTAL~1\UNINST~1.EXE
Task: {626E5301-03B2-4C73-802F-5EA695256EE1} - System32\Tasks\avast! Emergency Update => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe [2015-07-13] (Avast Software s.r.o.)
Task: {69C36DC3-0AB4-4D6A-9660-31FF02BC5BDB} - System32\Tasks\{1387B768-614D-4228-A302-0588E592C502} => pcalua.exe -a C:\Users\enna\AppData\Roaming\FissaSearch\FissaUninstaller.exe -c /quiet
Task: {6DC3F389-10A6-4D5C-96CC-C847DC02BBDA} - System32\Tasks\Programme de mise à jour en ligne de Adobe => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {6F816315-6192-40F8-AFEE-43DB983281A9} - System32\Tasks\PC-Mechanic Maintenance => C:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe [2015-05-29] ()
Task: {77EB6F50-E470-4C62-8C43-4E62F3CBD674} - System32\Tasks\{3A28F33E-508C-4991-BEAA-74082362B504} => pcalua.exe -a "C:\Users\enna\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MSEZW54O\iPodResetUtilitySetup.exe" -d C:\Users\enna\Desktop
Task: {89A8FFC2-2C31-4572-AA74-16EC4BE62519} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1043922925-1157543147-587559754-1001Core => C:\Users\enna\AppData\Local\Google\Update\GoogleUpdate.exe [2014-05-20] (Google Inc.)
Task: {9321682F-698D-4457-9348-9B8CC3CB7C7B} - System32\Tasks\{3B39C640-0E91-40AD-A75B-F28B7C20AF1F} => pcalua.exe -a C:\Users\enna\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=cor
Task: {973511CF-BE64-40D3-ACB8-8572C208BDC8} - System32\Tasks\0 => Iexplore.exe <==== ATTENTION
Task: {9E672133-BD55-434A-8C73-523362BCBF9C} - System32\Tasks\4599 => Wscript.exe C:\Users\enna\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION
Task: {B2A9A5ED-9003-4B3B-8FD0-C26B134E86CF} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-04-10] (Oracle Corporation)
Task: {B5C77121-098C-4568-8189-7C916A3B833A} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {BB57B4BF-3AEF-4E49-84BF-B363F186F5F4} - System32\Tasks\Google Updater and Installer => C:\Users\enna\AppData\Local\Google\Update\GoogleUpdate.exe [2014-05-20] (Google Inc.)
Task: {D115145B-2059-4F60-891D-D223660E6394} - System32\Tasks\{147C2FA0-02C9-4D79-A0CF-8069660F9B4A} => pcalua.exe -a "C:\Users\enna\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DNNAST5V\CommunicatorPlugin_401.exe" -d C:\Users\enna\Desktop
Task: {D6A8AB4E-CE61-4122-903B-B191B1FB8C46} - System32\Tasks\{7B5A0466-23BE-47C9-AAB0-44766DE0E212} => pcalua.exe -a "C:\Program Files (x86)\Columbus - Le Fantome de la Pierre Mysterieuse\Uninstall.exe"
Task: {DB77D6EC-73D9-4604-980F-DB2610B99252} - System32\Tasks\{5127EB34-66BE-4C8B-8B15-7ECA32485DF9} => pcalua.exe -a "C:\Program Files (x86)\Unsolved Mystery Club - Ancient Astronauts Collector's Edition\Uninstall.exe"
Task: {E075ACA1-65A7-458D-86B4-185DA6DEC1EF} - System32\Tasks\RunAsStdUser Task => C:\Program Files (x86)\iWin Games\iWinGames.exe
Task: {EA19EC62-303C-43BB-85DD-E22095CF2E3A} - System32\Tasks\{3F63BEB1-F240-4B3B-8D67-B5C50CE1090B} => pcalua.exe -a "C:\Program Files (x86)\Columbus - Ghost of the Mystery Stone\Uninstall.exe"
Task: {F4CDF354-2796-476C-BB45-57FA68B3C305} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1043922925-1157543147-587559754-1001UA => C:\Users\enna\AppData\Local\Google\Update\GoogleUpdate.exe [2014-05-20] (Google Inc.)
Task: {F9F44371-7496-4B99-AD06-CBE7591E7F1D} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe
Task: {FDFA53FB-D286-4947-9908-CC991DB3C125} - System32\Tasks\{5D4496EB-5012-40FC-9E51-DA2B85980485} => pcalua.exe -a "C:\Users\enna\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1D42DNRZ\install_messenger[1].exe" -d C:\Users\enna\Desktop

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Chromium.job => 0x01060100F0345396AA1B0343BB8881B52E9F2CE8460012010000000044440000200000000014730F0000000005130400002004210000000000000000000000000000000000004F0043003A005C00550073006500720073005C0065006E006E0061005C0041007000700044006100740061005C004C006F00630061006C005C004300680072006F006D00690075006D005C004100500050004C00490043007E0031005C003400340030003200330038007E0031002E0030005C0049004E005300540041004C007E0031005C0055004E0049004E00530054007E0031002E00450058004500000007002F0043006800650063006B0000000000050065006E006E00610000000000000008000313040000000000010030000000D1070100070000000000000001002A00A00500003C0000000000000001000000010000000000000000000000
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1043922925-1157543147-587559754-1001Core.job => C:\Users\enna\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1043922925-1157543147-587559754-1001UA.job => C:\Users\enna\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\PC-Mechanic Maintenance.job => C:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe
Task: C:\Windows\Tasks\PC-Mechanic Startup.job => C:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe
Task: C:\Windows\Tasks\PC-Mechanic Subscription.job => C:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe

==================== Loaded Modules (Whitelisted) ==============

2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2009-12-19 00:32 - 2009-12-19 00:32 - 00200704 _____ () C:\Windows\PLFSetI.exe
2015-01-21 04:06 - 2015-01-21 04:06 - 00061440 _____ () C:\Program Files\CCleaner\lang\lang-1036.dll
2015-04-26 09:26 - 2015-04-26 09:26 - 00104400 _____ () C:\Program Files\Alwil Software\Avast5\log.dll
2015-04-26 09:26 - 2015-04-26 09:26 - 00081728 _____ () C:\Program Files\Alwil Software\Avast5\JsonRpcServer.dll
2015-07-14 16:11 - 2015-07-14 16:11 - 02956288 _____ () C:\Program Files\Alwil Software\Avast5\defs\15071400\algo.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2015-07-13 17:45 - 2015-07-07 05:49 - 01281864 _____ () C:\Users\enna\AppData\Local\Google\Chrome\Application\43.0.2357.132\libglesv2.dll
2015-07-13 17:45 - 2015-07-07 05:49 - 00080712 _____ () C:\Users\enna\AppData\Local\Google\Chrome\Application\43.0.2357.132\libegl.dll
2015-04-26 09:26 - 2015-04-26 09:26 - 40540672 _____ () C:\Program Files\Alwil Software\Avast5\libcef.dll
2015-07-13 17:45 - 2015-07-07 05:49 - 16285512 _____ () C:\Users\enna\AppData\Local\Google\Chrome\Application\43.0.2357.132\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\enna:zylomtest
AlternateDataStreams: C:\Users\enna:zylomtr{000HQ7FF-AD7A-3FG1-6E2T-2B6FMQRBGVRL}
AlternateDataStreams: C:\ProgramData\Temp:008FE370
AlternateDataStreams: C:\ProgramData\Temp:00D99749
AlternateDataStreams: C:\ProgramData\Temp:012BC84F
AlternateDataStreams: C:\ProgramData\Temp:0168CC60
AlternateDataStreams: C:\ProgramData\Temp:021496FB
AlternateDataStreams: C:\ProgramData\Temp:021703B2
AlternateDataStreams: C:\ProgramData\Temp:02172F27
AlternateDataStreams: C:\ProgramData\Temp:025DF3DE
AlternateDataStreams: C:\ProgramData\Temp:02CC0035
AlternateDataStreams: C:\ProgramData\Temp:02F30776
AlternateDataStreams: C:\ProgramData\Temp:036AA5DD
AlternateDataStreams: C:\ProgramData\Temp:03A039A3
AlternateDataStreams: C:\ProgramData\Temp:0410A323
AlternateDataStreams: C:\ProgramData\Temp:0474F714
AlternateDataStreams: C:\ProgramData\Temp:04A18F36
AlternateDataStreams: C:\ProgramData\Temp:04B1A0AC
AlternateDataStreams: C:\ProgramData\Temp:04BC9A2C
AlternateDataStreams: C:\ProgramData\Temp:04EAB86F
AlternateDataStreams: C:\ProgramData\Temp:070D9534
AlternateDataStreams: C:\ProgramData\Temp:072CBE6D
AlternateDataStreams: C:\ProgramData\Temp:07437A8C
AlternateDataStreams: C:\ProgramData\Temp:0785072C
AlternateDataStreams: C:\ProgramData\Temp:07CBFAD5
AlternateDataStreams: C:\ProgramData\Temp:084612C9
AlternateDataStreams: C:\ProgramData\Temp:087CB364
AlternateDataStreams: C:\ProgramData\Temp:08E5EE32
AlternateDataStreams: C:\ProgramData\Temp:09629F6E
AlternateDataStreams: C:\ProgramData\Temp:0A74923C
AlternateDataStreams: C:\ProgramData\Temp:0B278A1A
AlternateDataStreams: C:\ProgramData\Temp:0B79AB8D
AlternateDataStreams: C:\ProgramData\Temp:0BCD47A5
AlternateDataStreams: C:\ProgramData\Temp:0C13C008
AlternateDataStreams: C:\ProgramData\Temp:0C2A17F2
AlternateDataStreams: C:\ProgramData\Temp:0C73962F
AlternateDataStreams: C:\ProgramData\Temp:0CD5F2B8
AlternateDataStreams: C:\ProgramData\Temp:0D060666
AlternateDataStreams: C:\ProgramData\Temp:0ED1C542
AlternateDataStreams: C:\ProgramData\Temp:0F3F6B1E
AlternateDataStreams: C:\ProgramData\Temp:0F4FC8CD
AlternateDataStreams: C:\ProgramData\Temp:0F64164E
AlternateDataStreams: C:\ProgramData\Temp:0FAE191E
AlternateDataStreams: C:\ProgramData\Temp:0FD8569B
AlternateDataStreams: C:\ProgramData\Temp:0FE0A03C
AlternateDataStreams: C:\ProgramData\Temp:104A1C3E
AlternateDataStreams: C:\ProgramData\Temp:109734F6
AlternateDataStreams: C:\ProgramData\Temp:10B970A9
AlternateDataStreams: C:\ProgramData\Temp:10CB85CA
AlternateDataStreams: C:\ProgramData\Temp:114C90CA
AlternateDataStreams: C:\ProgramData\Temp:11590865
AlternateDataStreams: C:\ProgramData\Temp:120B3AFD
AlternateDataStreams: C:\ProgramData\Temp:12258D63
AlternateDataStreams: C:\ProgramData\Temp:1234ADAE
AlternateDataStreams: C:\ProgramData\Temp:12383CAE
AlternateDataStreams: C:\ProgramData\Temp:124B94C0
AlternateDataStreams: C:\ProgramData\Temp:128B55C8
AlternateDataStreams: C:\ProgramData\Temp:12D136AA
AlternateDataStreams: C:\ProgramData\Temp:12D21A9A
AlternateDataStreams: C:\ProgramData\Temp:13019F4B
AlternateDataStreams: C:\ProgramData\Temp:13765436
AlternateDataStreams: C:\ProgramData\Temp:140AD176
AlternateDataStreams: C:\ProgramData\Temp:1416AAA6
AlternateDataStreams: C:\ProgramData\Temp:14A1BBE3
AlternateDataStreams: C:\ProgramData\Temp:14B2E0BD
AlternateDataStreams: C:\ProgramData\Temp:15265C4F
AlternateDataStreams: C:\ProgramData\Temp:159A493A
AlternateDataStreams: C:\ProgramData\Temp:1604D047
AlternateDataStreams: C:\ProgramData\Temp:164561C8
AlternateDataStreams: C:\ProgramData\Temp:16F4BC64
AlternateDataStreams: C:\ProgramData\Temp:17EB5BAE
AlternateDataStreams: C:\ProgramData\Temp:183A9046
AlternateDataStreams: C:\ProgramData\Temp:18A25CF1
AlternateDataStreams: C:\ProgramData\Temp:18A6D2CC
AlternateDataStreams: C:\ProgramData\Temp:18B241CC
AlternateDataStreams: C:\ProgramData\Temp:18B5F839
AlternateDataStreams: C:\ProgramData\Temp:18DEBC51
AlternateDataStreams: C:\ProgramData\Temp:18E3BAF3
AlternateDataStreams: C:\ProgramData\Temp:193CB03B
AlternateDataStreams: C:\ProgramData\Temp:19474103
AlternateDataStreams: C:\ProgramData\Temp:195E8317
AlternateDataStreams: C:\ProgramData\Temp:1A15E356
AlternateDataStreams: C:\ProgramData\Temp:1B389835
AlternateDataStreams: C:\ProgramData\Temp:1B96CF22
AlternateDataStreams: C:\ProgramData\Temp:1C201DEB
AlternateDataStreams: C:\ProgramData\Temp:1CB96B16
AlternateDataStreams: C:\ProgramData\Temp:1CD511E5
AlternateDataStreams: C:\ProgramData\Temp:1CDEDE11
AlternateDataStreams: C:\ProgramData\Temp:1D6B18F1
AlternateDataStreams: C:\ProgramData\Temp:1E17A249
AlternateDataStreams: C:\ProgramData\Temp:1E87A273
AlternateDataStreams: C:\ProgramData\Temp:1E942FB9
AlternateDataStreams: C:\ProgramData\Temp:1EAB6298
AlternateDataStreams: C:\ProgramData\Temp:1FA4C06F
AlternateDataStreams: C:\ProgramData\Temp:2043337E
AlternateDataStreams: C:\ProgramData\Temp:206470A5
AlternateDataStreams: C:\ProgramData\Temp:207C4C79
AlternateDataStreams: C:\ProgramData\Temp:217A2324
AlternateDataStreams: C:\ProgramData\Temp:2211E7A0
AlternateDataStreams: C:\ProgramData\Temp:22313216
AlternateDataStreams: C:\ProgramData\Temp:224B562C
AlternateDataStreams: C:\ProgramData\Temp:234E9CC5
AlternateDataStreams: C:\ProgramData\Temp:23834E1E
AlternateDataStreams: C:\ProgramData\Temp:24391EC1
AlternateDataStreams: C:\ProgramData\Temp:244E4E3A
AlternateDataStreams: C:\ProgramData\Temp:24C072FF
AlternateDataStreams: C:\ProgramData\Temp:24C89EFC
AlternateDataStreams: C:\ProgramData\Temp:25F31665
AlternateDataStreams: C:\ProgramData\Temp:26499772
AlternateDataStreams: C:\ProgramData\Temp:2652902F
AlternateDataStreams: C:\ProgramData\Temp:2679D5C1
AlternateDataStreams: C:\ProgramData\Temp:26991AB9
AlternateDataStreams: C:\ProgramData\Temp:26A148EB
AlternateDataStreams: C:\ProgramData\Temp:26FBC1F9
AlternateDataStreams: C:\ProgramData\Temp:275AA066
AlternateDataStreams: C:\ProgramData\Temp:27A88EF2
AlternateDataStreams: C:\ProgramData\Temp:282CE153
AlternateDataStreams: C:\ProgramData\Temp:2979C892
AlternateDataStreams: C:\ProgramData\Temp:29861223
AlternateDataStreams: C:\ProgramData\Temp:29F0CA7D
AlternateDataStreams: C:\ProgramData\Temp:2AC146B9
AlternateDataStreams: C:\ProgramData\Temp:2AE74FF9
AlternateDataStreams: C:\ProgramData\Temp:2AF322BF
AlternateDataStreams: C:\ProgramData\Temp:2B40A7DB
AlternateDataStreams: C:\ProgramData\Temp:2B9555D8
AlternateDataStreams: C:\ProgramData\Temp:2C4F33F6
AlternateDataStreams: C:\ProgramData\Temp:2C84CA43
AlternateDataStreams: C:\ProgramData\Temp:2C86E2AD
AlternateDataStreams: C:\ProgramData\Temp:2CB9631F
AlternateDataStreams: C:\ProgramData\Temp:2CC32B31
AlternateDataStreams: C:\ProgramData\Temp:2D133896
AlternateDataStreams: C:\ProgramData\Temp:2D2461E7
AlternateDataStreams: C:\ProgramData\Temp:2DF54B62
AlternateDataStreams: C:\ProgramData\Temp:2E3F04BC
AlternateDataStreams: C:\ProgramData\Temp:2E636DD9
AlternateDataStreams: C:\ProgramData\Temp:2E928E6E
AlternateDataStreams: C:\ProgramData\Temp:2F1D743F
AlternateDataStreams: C:\ProgramData\Temp:2F474C84
AlternateDataStreams: C:\ProgramData\Temp:2F70C0B4
AlternateDataStreams: C:\ProgramData\Temp:2F8138B7
AlternateDataStreams: C:\ProgramData\Temp:302ECBD6
AlternateDataStreams: C:\ProgramData\Temp:3086B95F
AlternateDataStreams: C:\ProgramData\Temp:319D783D
AlternateDataStreams: C:\ProgramData\Temp:32289BE8
AlternateDataStreams: C:\ProgramData\Temp:32EA849C
AlternateDataStreams: C:\ProgramData\Temp:33B04540
AlternateDataStreams: C:\ProgramData\Temp:33CF835F
AlternateDataStreams: C:\ProgramData\Temp:33E12B7A
AlternateDataStreams: C:\ProgramData\Temp:34445512
AlternateDataStreams: C:\ProgramData\Temp:3480F458
AlternateDataStreams: C:\ProgramData\Temp:34C443B4
AlternateDataStreams: C:\ProgramData\Temp:34EFF1F2
AlternateDataStreams: C:\ProgramData\Temp:355DEA9D
AlternateDataStreams: C:\ProgramData\Temp:3595B780
AlternateDataStreams: C:\ProgramData\Temp:366EFA1A
AlternateDataStreams: C:\ProgramData\Temp:37207201
AlternateDataStreams: C:\ProgramData\Temp:378824DE
AlternateDataStreams: C:\ProgramData\Temp:37C279BE
AlternateDataStreams: C:\ProgramData\Temp:386B39C3
AlternateDataStreams: C:\ProgramData\Temp:3969ACF7
AlternateDataStreams: C:\ProgramData\Temp:397D67BA
AlternateDataStreams: C:\ProgramData\Temp:398D2775
AlternateDataStreams: C:\ProgramData\Temp:398EFF0F
AlternateDataStreams: C:\ProgramData\Temp:3A7527E8
AlternateDataStreams: C:\ProgramData\Temp:3ADE134E
AlternateDataStreams: C:\ProgramData\Temp:3B454A5C
AlternateDataStreams: C:\ProgramData\Temp:3B71586E
AlternateDataStreams: C:\ProgramData\Temp:3B75B877
AlternateDataStreams: C:\ProgramData\Temp:3C4BD225
AlternateDataStreams: C:\ProgramData\Temp:3CAE2A70
AlternateDataStreams: C:\ProgramData\Temp:3D1D487A
AlternateDataStreams: C:\ProgramData\Temp:3D4B733E
AlternateDataStreams: C:\ProgramData\Temp:3D922890
AlternateDataStreams: C:\ProgramData\Temp:3DB6F365
AlternateDataStreams: C:\ProgramData\Temp:3E200C29
AlternateDataStreams: C:\ProgramData\Temp:3E8A3E87
AlternateDataStreams: C:\ProgramData\Temp:3EC5BC08
AlternateDataStreams: C:\ProgramData\Temp:3F266659
AlternateDataStreams: C:\ProgramData\Temp:3FD69132
AlternateDataStreams: C:\ProgramData\Temp:401CAF8F
AlternateDataStreams: C:\ProgramData\Temp:404908B5
AlternateDataStreams: C:\ProgramData\Temp:405D842B
AlternateDataStreams: C:\ProgramData\Temp:4244811A
AlternateDataStreams: C:\ProgramData\Temp:424D7CFE
AlternateDataStreams: C:\ProgramData\Temp:430C6D84
AlternateDataStreams: C:\ProgramData\Temp:43CBFAB2
AlternateDataStreams: C:\ProgramData\Temp:43ECEA33
AlternateDataStreams: C:\ProgramData\Temp:43F5FA9D
AlternateDataStreams: C:\ProgramData\Temp:4577F5B4
AlternateDataStreams: C:\ProgramData\Temp:45912F61
AlternateDataStreams: C:\ProgramData\Temp:46283136
AlternateDataStreams: C:\ProgramData\Temp:474022C7
AlternateDataStreams: C:\ProgramData\Temp:48BCFDB6
AlternateDataStreams: C:\ProgramData\Temp:48D3CC24
AlternateDataStreams: C:\ProgramData\Temp:48D6EA0F
AlternateDataStreams: C:\ProgramData\Temp:491270B8
AlternateDataStreams: C:\ProgramData\Temp:49EB69E2
AlternateDataStreams: C:\ProgramData\Temp:4A01545C
AlternateDataStreams: C:\ProgramData\Temp:4A5CFD3B
AlternateDataStreams: C:\ProgramData\Temp:4A8EB1C4
AlternateDataStreams: C:\ProgramData\Temp:4AC7B5C1
AlternateDataStreams: C:\ProgramData\Temp:4BBB987B
AlternateDataStreams: C:\ProgramData\Temp:4C31986D
AlternateDataStreams: C:\ProgramData\Temp:4C35C064
AlternateDataStreams: C:\ProgramData\Temp:4C3B92C7
AlternateDataStreams: C:\ProgramData\Temp:4C3D5A8B
AlternateDataStreams: C:\ProgramData\Temp:4C6F9D77
AlternateDataStreams: C:\ProgramData\Temp:4C8FA829
AlternateDataStreams: C:\ProgramData\Temp:4C9782FB
AlternateDataStreams: C:\ProgramData\Temp:4CD3F344
AlternateDataStreams: C:\ProgramData\Temp:4D066AD2
AlternateDataStreams: C:\ProgramData\Temp:4D51EA2B
AlternateDataStreams: C:\ProgramData\Temp:4D551822
AlternateDataStreams: C:\ProgramData\Temp:4D729D61
AlternateDataStreams: C:\ProgramData\Temp:4D8FCBEF
AlternateDataStreams: C:\ProgramData\Temp:4DDE401B
AlternateDataStreams: C:\ProgramData\Temp:4E79C4F8
AlternateDataStreams: C:\ProgramData\Temp:4EC7F009
AlternateDataStreams: C:\ProgramData\Temp:4EE95FE7
AlternateDataStreams: C:\ProgramData\Temp:4EEC7800
AlternateDataStreams: C:\ProgramData\Temp:4EFA2FC7
AlternateDataStreams: C:\ProgramData\Temp:4F7FE589
AlternateDataStreams: C:\ProgramData\Temp:4F852702
AlternateDataStreams: C:\ProgramData\Temp:4FA837B4
AlternateDataStreams: C:\ProgramData\Temp:50B79A31
AlternateDataStreams: C:\ProgramData\Temp:512E1728
AlternateDataStreams: C:\ProgramData\Temp:5133A494
AlternateDataStreams: C:\ProgramData\Temp:518C333F
AlternateDataStreams: C:\ProgramData\Temp:51A20D23
AlternateDataStreams: C:\ProgramData\Temp:51E66512
AlternateDataStreams: C:\ProgramData\Temp:52C24010
AlternateDataStreams: C:\ProgramData\Temp:53B8C5D2
AlternateDataStreams: C:\ProgramData\Temp:53BA2DF6
AlternateDataStreams: C:\ProgramData\Temp:53F09A92
AlternateDataStreams: C:\ProgramData\Temp:5412DFA4
AlternateDataStreams: C:\ProgramData\Temp:54380FEC
AlternateDataStreams: C:\ProgramData\Temp:54403233
AlternateDataStreams: C:\ProgramData\Temp:5453E5AF
AlternateDataStreams: C:\ProgramData\Temp:54F0BBF5
AlternateDataStreams: C:\ProgramData\Temp:5520ED93
AlternateDataStreams: C:\ProgramData\Temp:553056F1
AlternateDataStreams: C:\ProgramData\Temp:5539129F
AlternateDataStreams: C:\ProgramData\Temp:56FBA78D
AlternateDataStreams: C:\ProgramData\Temp:57231008
AlternateDataStreams: C:\ProgramData\Temp:57DFBE4E
AlternateDataStreams: C:\ProgramData\Temp:587F3582
AlternateDataStreams: C:\ProgramData\Temp:58E38390
AlternateDataStreams: C:\ProgramData\Temp:59465B40
AlternateDataStreams: C:\ProgramData\Temp:59540531
AlternateDataStreams: C:\ProgramData\Temp:597254A1
AlternateDataStreams: C:\ProgramData\Temp:59A6876B
AlternateDataStreams: C:\ProgramData\Temp:5A2E8BBF
AlternateDataStreams: C:\ProgramData\Temp:5A5477A9
AlternateDataStreams: C:\ProgramData\Temp:5A63CC20
AlternateDataStreams: C:\ProgramData\Temp:5A9F1AE5
AlternateDataStreams: C:\ProgramData\Temp:5C5F2761
AlternateDataStreams: C:\ProgramData\Temp:5CE91C67
AlternateDataStreams: C:\ProgramData\Temp:5D570144
AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F
AlternateDataStreams: C:\ProgramData\Temp:5DB36C47
AlternateDataStreams: C:\ProgramData\Temp:5E21B96B
AlternateDataStreams: C:\ProgramData\Temp:5E8C18F1
AlternateDataStreams: C:\ProgramData\Temp:5ECEFF17
AlternateDataStreams: C:\ProgramData\Temp:5EFEB6A1
AlternateDataStreams: C:\ProgramData\Temp:5F2C9B5E
AlternateDataStreams: C:\ProgramData\Temp:5F56E7C1
AlternateDataStreams: C:\ProgramData\Temp:5FC043A8
AlternateDataStreams: C:\ProgramData\Temp:5FD26EF3
AlternateDataStreams: C:\ProgramData\Temp:5FD35242
AlternateDataStreams: C:\ProgramData\Temp:607A99D7
AlternateDataStreams: C:\ProgramData\Temp:609CAC7C
AlternateDataStreams: C:\ProgramData\Temp:6212DF7A
AlternateDataStreams: C:\ProgramData\Temp:627153F1
AlternateDataStreams: C:\ProgramData\Temp:6294B369
AlternateDataStreams: C:\ProgramData\Temp:62AC0CCE
AlternateDataStreams: C:\ProgramData\Temp:63210866
AlternateDataStreams: C:\ProgramData\Temp:63C29481
AlternateDataStreams: C:\ProgramData\Temp:6401C7FF
AlternateDataStreams: C:\ProgramData\Temp:65137F0D
AlternateDataStreams: C:\ProgramData\Temp:65484F45
AlternateDataStreams: C:\ProgramData\Temp:65684E14
AlternateDataStreams: C:\ProgramData\Temp:65929158
AlternateDataStreams: C:\ProgramData\Temp:65B8AF94
AlternateDataStreams: C:\ProgramData\Temp:65C4D44A
AlternateDataStreams: C:\ProgramData\Temp:66F7E5A9
AlternateDataStreams: C:\ProgramData\Temp:6757F885
AlternateDataStreams: C:\ProgramData\Temp:67A91473
AlternateDataStreams: C:\ProgramData\Temp:67CF910D
AlternateDataStreams: C:\ProgramData\Temp:67E674B0
AlternateDataStreams: C:\ProgramData\Temp:6896CCCE
AlternateDataStreams: C:\ProgramData\Temp:689AB7E9
AlternateDataStreams: C:\ProgramData\Temp:689E7F7D
AlternateDataStreams: C:\ProgramData\Temp:68A41423
AlternateDataStreams: C:\ProgramData\Temp:697DDE2B
AlternateDataStreams: C:\ProgramData\Temp:69F562A6
AlternateDataStreams: C:\ProgramData\Temp:6A0A47E7
AlternateDataStreams: C:\ProgramData\Temp:6A9CA6CB
AlternateDataStreams: C:\ProgramData\Temp:6B7447D4
AlternateDataStreams: C:\ProgramData\Temp:6BEADDC0
AlternateDataStreams: C:\ProgramData\Temp:6BFA43EB
AlternateDataStreams: C:\ProgramData\Temp:6C15BEAD
AlternateDataStreams: C:\ProgramData\Temp:6CF828C2
AlternateDataStreams: C:\ProgramData\Temp:6DD124E2
AlternateDataStreams: C:\ProgramData\Temp:6E2D80C8
AlternateDataStreams: C:\ProgramData\Temp:6E65510A
AlternateDataStreams: C:\ProgramData\Temp:6ECE93A8
AlternateDataStreams: C:\ProgramData\Temp:6ED8B881
AlternateDataStreams: C:\ProgramData\Temp:6EE8565A
AlternateDataStreams: C:\ProgramData\Temp:6FF14C72
AlternateDataStreams: C:\ProgramData\Temp:70989864
AlternateDataStreams: C:\ProgramData\Temp:709E81D4
AlternateDataStreams: C:\ProgramData\Temp:70BDB805
AlternateDataStreams: C:\ProgramData\Temp:71A89A93
AlternateDataStreams: C:\ProgramData\Temp:71AEFFEB
AlternateDataStreams: C:\ProgramData\Temp:71B89F61
AlternateDataStreams: C:\ProgramData\Temp:7254CF01
AlternateDataStreams: C:\ProgramData\Temp:72A1B66A
AlternateDataStreams: C:\ProgramData\Temp:72C99D4E
AlternateDataStreams: C:\ProgramData\Temp:73AFBB96
AlternateDataStreams: C:\ProgramData\Temp:754E278B
AlternateDataStreams: C:\ProgramData\Temp:75798D9A
AlternateDataStreams: C:\ProgramData\Temp:759B7D6F
AlternateDataStreams: C:\ProgramData\Temp:75CC0165
AlternateDataStreams: C:\ProgramData\Temp:762408BA
AlternateDataStreams: C:\ProgramData\Temp:769BB147
AlternateDataStreams: C:\ProgramData\Temp:774A0E14
AlternateDataStreams: C:\ProgramData\Temp:774C075A
AlternateDataStreams: C:\ProgramData\Temp:77B64C59
AlternateDataStreams: C:\ProgramData\Temp:78696BCD
AlternateDataStreams: C:\ProgramData\Temp:78DEA3A4
AlternateDataStreams: C:\ProgramData\Temp:795F6DEC
AlternateDataStreams: C:\ProgramData\Temp:7961507B
AlternateDataStreams: C:\ProgramData\Temp:79875988
AlternateDataStreams: C:\ProgramData\Temp:7A3AAF2E
AlternateDataStreams: C:\ProgramData\Temp:7ADB695A
AlternateDataStreams: C:\ProgramData\Temp:7B9BB187
AlternateDataStreams: C:\ProgramData\Temp:7BB20DE8
AlternateDataStreams: C:\ProgramData\Temp:7BFAAE70
AlternateDataStreams: C:\ProgramData\Temp:7BFFC6A9
AlternateDataStreams: C:\ProgramData\Temp:7C8AA9A6
AlternateDataStreams: C:\ProgramData\Temp:7D938C9B
AlternateDataStreams: C:\ProgramData\Temp:7D9B1030
AlternateDataStreams: C:\ProgramData\Temp:7DC5D762
AlternateDataStreams: C:\ProgramData\Temp:7FD60FAD
AlternateDataStreams: C:\ProgramData\Temp:80253E8D
AlternateDataStreams: C:\ProgramData\Temp:8029E75F
AlternateDataStreams: C:\ProgramData\Temp:8075370B
AlternateDataStreams: C:\ProgramData\Temp:80FA23CA
AlternateDataStreams: C:\ProgramData\Temp:8164A00A
AlternateDataStreams: C:\ProgramData\Temp:817F0659
AlternateDataStreams: C:\ProgramData\Temp:8204AA35
AlternateDataStreams: C:\ProgramData\Temp:823606DE
AlternateDataStreams: C:\ProgramData\Temp:82529191
AlternateDataStreams: C:\ProgramData\Temp:8318A814
AlternateDataStreams: C:\ProgramData\Temp:834DD57E
AlternateDataStreams: C:\ProgramData\Temp:8435AD8C
AlternateDataStreams: C:\ProgramData\Temp:843D8419
AlternateDataStreams: C:\ProgramData\Temp:84C34762
AlternateDataStreams: C:\ProgramData\Temp:852F2262
AlternateDataStreams: C:\ProgramData\Temp:85EA4795
AlternateDataStreams: C:\ProgramData\Temp:864881BF
AlternateDataStreams: C:\ProgramData\Temp:869C6B4A
AlternateDataStreams: C:\ProgramData\Temp:86B7FDDB
AlternateDataStreams: C:\ProgramData\Temp:871526BA
AlternateDataStreams: C:\ProgramData\Temp:87A3A233
AlternateDataStreams: C:\ProgramData\Temp:8855A119
AlternateDataStreams: C:\ProgramData\Temp:8866C899
AlternateDataStreams: C:\ProgramData\Temp:88E8CC2E
AlternateDataStreams: C:\ProgramData\Temp:88FB7F72
AlternateDataStreams: C:\ProgramData\Temp:88FD3ED6
AlternateDataStreams: C:\ProgramData\Temp:8924043A
AlternateDataStreams: C:\ProgramData\Temp:89CC3B44
AlternateDataStreams: C:\ProgramData\Temp:8A620099
AlternateDataStreams: C:\ProgramData\Temp:8AE92FD3
AlternateDataStreams: C:\ProgramData\Temp:8AED9359
AlternateDataStreams: C:\ProgramData\Temp:8B480195
AlternateDataStreams: C:\ProgramData\Temp:8B4C1181
AlternateDataStreams: C:\ProgramData\Temp:8B79B813
AlternateDataStreams: C:\ProgramData\Temp:8BA6C9F8
AlternateDataStreams: C:\ProgramData\Temp:8BE7A048
AlternateDataStreams: C:\ProgramData\Temp:8BE8BFCD
AlternateDataStreams: C:\ProgramData\Temp:8CA2661F
AlternateDataStreams: C:\ProgramData\Temp:8DD20B4A
AlternateDataStreams: C:\ProgramData\Temp:8E11CC80
AlternateDataStreams: C:\ProgramData\Temp:8E20E2DB
AlternateDataStreams: C:\ProgramData\Temp:8E3E8227
AlternateDataStreams: C:\ProgramData\Temp:8E5EA40F
AlternateDataStreams: C:\ProgramData\Temp:8EBAFFA8
AlternateDataStreams: C:\ProgramData\Temp:8F6B75BF
AlternateDataStreams: C:\ProgramData\Temp:902C848D
AlternateDataStreams: C:\ProgramData\Temp:905BCB57
AlternateDataStreams: C:\ProgramData\Temp:9195103F
AlternateDataStreams: C:\ProgramData\Temp:91FE43FF
AlternateDataStreams: C:\ProgramData\Temp:9254F782
AlternateDataStreams: C:\ProgramData\Temp:927EC486
AlternateDataStreams: C:\ProgramData\Temp:92BD9737
AlternateDataStreams: C:\ProgramData\Temp:9338F136
AlternateDataStreams: C:\ProgramData\Temp:938EB9FC
AlternateDataStreams: C:\ProgramData\Temp:93B68122
AlternateDataStreams: C:\ProgramData\Temp:943971F5
AlternateDataStreams: C:\ProgramData\Temp:94874C0A
AlternateDataStreams: C:\ProgramData\Temp:9491C9C7
AlternateDataStreams: C:\ProgramData\Temp:94A31742
AlternateDataStreams: C:\ProgramData\Temp:94B25DF5
AlternateDataStreams: C:\ProgramData\Temp:94B46CA2
AlternateDataStreams: C:\ProgramData\Temp:94BD36A2
AlternateDataStreams: C:\ProgramData\Temp:95079543
AlternateDataStreams: C:\ProgramData\Temp:95198126
AlternateDataStreams: C:\ProgramData\Temp:9524D821
AlternateDataStreams: C:\ProgramData\Temp:95970EA3
AlternateDataStreams: C:\ProgramData\Temp:95D421DF
AlternateDataStreams: C:\ProgramData\Temp:9603033A
AlternateDataStreams: C:\ProgramData\Temp:961B84C5
AlternateDataStreams: C:\ProgramData\Temp:96372A73
AlternateDataStreams: C:\ProgramData\Temp:96AFAB10
AlternateDataStreams: C:\ProgramData\Temp:96F8F8AB
AlternateDataStreams: C:\ProgramData\Temp:9720EBEF
AlternateDataStreams: C:\ProgramData\Temp:9742C5DF
AlternateDataStreams: C:\ProgramData\Temp:97AAB7F2
AlternateDataStreams: C:\ProgramData\Temp:981456CB
AlternateDataStreams: C:\ProgramData\Temp:9836B5E4
AlternateDataStreams: C:\ProgramData\Temp:9968F0E2
AlternateDataStreams: C:\ProgramData\Temp:997DA6D7
AlternateDataStreams: C:\ProgramData\Temp:99B20AD0
AlternateDataStreams: C:\ProgramData\Temp:9A88B65D
AlternateDataStreams: C:\ProgramData\Temp:9B9085E9
AlternateDataStreams: C:\ProgramData\Temp:9BAC4211
AlternateDataStreams: C:\ProgramData\Temp:9BB8C675
AlternateDataStreams: C:\ProgramData\Temp:9C3AAD57
AlternateDataStreams: C:\ProgramData\Temp:9C7A32BB
AlternateDataStreams: C:\ProgramData\Temp:9D06FB9C
AlternateDataStreams: C:\ProgramData\Temp:9EDA68BD
AlternateDataStreams: C:\ProgramData\Temp:9EE6560D
AlternateDataStreams: C:\ProgramData\Temp:9F3CEEE6
AlternateDataStreams: C:\ProgramData\Temp:9FD757A9
AlternateDataStreams: C:\ProgramData\Temp:A015B193
AlternateDataStreams: C:\ProgramData\Temp:A05F750A
AlternateDataStreams: C:\ProgramData\Temp:A0921B2C
AlternateDataStreams: C:\ProgramData\Temp:A391510C
AlternateDataStreams: C:\ProgramData\Temp:A3E0A552
AlternateDataStreams: C:\ProgramData\Temp:A42FABF7
AlternateDataStreams: C:\ProgramData\Temp:A441D13F
AlternateDataStreams: C:\ProgramData\Temp:A4AF8D0D
AlternateDataStreams: C:\ProgramData\Temp:A4E7D25F
AlternateDataStreams: C:\ProgramData\Temp:A5241382
AlternateDataStreams: C:\ProgramData\Temp:A52D07E2
AlternateDataStreams: C:\ProgramData\Temp:A6345BDA
AlternateDataStreams: C:\ProgramData\Temp:A6D6E537
AlternateDataStreams: C:\ProgramData\Temp:A6D89509
AlternateDataStreams: C:\ProgramData\Temp:A6E01F67
AlternateDataStreams: C:\ProgramData\Temp:A6F28514
AlternateDataStreams: C:\ProgramData\Temp:A6F30843
AlternateDataStreams: C:\ProgramData\Temp:A73595DE
AlternateDataStreams: C:\ProgramData\Temp:A76A1B1B
AlternateDataStreams: C:\ProgramData\Temp:A798AA1A
AlternateDataStreams: C:\ProgramData\Temp:A8185163
AlternateDataStreams: C:\ProgramData\Temp:A819A132
AlternateDataStreams: C:\ProgramData\Temp:A88BE334
AlternateDataStreams: C:\ProgramData\Temp:A8ADEA55
AlternateDataStreams: C:\ProgramData\Temp:A8DFD30C
AlternateDataStreams: C:\ProgramData\Temp:A900C3A3
AlternateDataStreams: C:\ProgramData\Temp:A9056F42
AlternateDataStreams: C:\ProgramData\Temp:A9223B61
AlternateDataStreams: C:\ProgramData\Temp:AA0017FD
AlternateDataStreams: C:\ProgramData\Temp:AA0BC725
AlternateDataStreams: C:\ProgramData\Temp:AAA06E15
AlternateDataStreams: C:\ProgramData\Temp:AABCC5A7
AlternateDataStreams: C:\ProgramData\Temp:AABECEFB
AlternateDataStreams: C:\ProgramData\Temp:AB3339EF
AlternateDataStreams: C:\ProgramData\Temp:AC9F291E
AlternateDataStreams: C:\ProgramData\Temp:AD020DC3
AlternateDataStreams: C:\ProgramData\Temp:AD179392
AlternateDataStreams: C:\ProgramData\Temp:AD2DB2F9
AlternateDataStreams: C:\ProgramData\Temp:AE0B4487
AlternateDataStreams: C:\ProgramData\Temp:AE8FDB48
AlternateDataStreams: C:\ProgramData\Temp:AEBC40EC
AlternateDataStreams: C:\ProgramData\Temp:AECF4772
AlternateDataStreams: C:\ProgramData\Temp:AED4A2B7
AlternateDataStreams: C:\ProgramData\Temp:AF2F9D4A
AlternateDataStreams: C:\ProgramData\Temp:AFB24B00
AlternateDataStreams: C:\ProgramData\Temp:AFB89C92
AlternateDataStreams: C:\ProgramData\Temp:AFC732F7
AlternateDataStreams: C:\ProgramData\Temp:B0456F0C
AlternateDataStreams: C:\ProgramData\Temp:B0729CDB
AlternateDataStreams: C:\ProgramData\Temp:B097AC8A
AlternateDataStreams: C:\ProgramData\Temp:B0A727D1
AlternateDataStreams: C:\ProgramData\Temp:B0EA26E5
AlternateDataStreams: C:\ProgramData\Temp:B1381B34
AlternateDataStreams: C:\ProgramData\Temp:B139DDF3
AlternateDataStreams: C:\ProgramData\Temp:B1786630
AlternateDataStreams: C:\ProgramData\Temp:B190BE3A
AlternateDataStreams: C:\ProgramData\Temp:B2112128
AlternateDataStreams: C:\ProgramData\Temp:B21F2857
AlternateDataStreams: C:\ProgramData\Temp:B2CCDB69
AlternateDataStreams: C:\ProgramData\Temp:B2DC8D6B
AlternateDataStreams: C:\ProgramData\Temp:B2FEAB71
AlternateDataStreams: C:\ProgramData\Temp:B3196E8D
AlternateDataStreams: C:\ProgramData\Temp:B328A983
AlternateDataStreams: C:\ProgramData\Temp:B38BEEEE
AlternateDataStreams: C:\ProgramData\Temp:B3A5945E
AlternateDataStreams: C:\ProgramData\Temp:B3C7433B
AlternateDataStreams: C:\ProgramData\Temp:B4258C5D
AlternateDataStreams: C:\ProgramData\Temp:B4F0E275
AlternateDataStreams: C:\ProgramData\Temp:B51B45A3
AlternateDataStreams: C:\ProgramData\Temp:B54E4B5A
AlternateDataStreams: C:\ProgramData\Temp:B5FD4AA1
AlternateDataStreams: C:\ProgramData\Temp:B6D84F71
AlternateDataStreams: C:\ProgramData\Temp:B6E58523
AlternateDataStreams: C:\ProgramData\Temp:B6E6C4EA
AlternateDataStreams: C:\ProgramData\Temp:B79964F6
AlternateDataStreams: C:\ProgramData\Temp:B8791731
AlternateDataStreams: C:\ProgramData\Temp:BACC4A79
AlternateDataStreams: C:\ProgramData\Temp:BACD3198
AlternateDataStreams: C:\ProgramData\Temp:BB99F46B
AlternateDataStreams: C:\ProgramData\Temp:BC8E9899
AlternateDataStreams: C:\ProgramData\Temp:BCFEA004
AlternateDataStreams: C:\ProgramData\Temp:BD0A043E
AlternateDataStreams: C:\ProgramData\Temp:BD34FFC5
AlternateDataStreams: C:\ProgramData\Temp:BD414E4B
AlternateDataStreams: C:\ProgramData\Temp:BD50071F
AlternateDataStreams: C:\ProgramData\Temp:BDC0F56E
AlternateDataStreams: C:\ProgramData\Temp:BDDA21B6
AlternateDataStreams: C:\ProgramData\Temp:BE0654D6
AlternateDataStreams: C:\ProgramData\Temp:BE22786A
AlternateDataStreams: C:\ProgramData\Temp:BE6B5FC3
AlternateDataStreams: C:\ProgramData\Temp:BEACE4C8
AlternateDataStreams: C:\ProgramData\Temp:BECA50FF
AlternateDataStreams: C:\ProgramData\Temp:BEE39E9B
AlternateDataStreams: C:\ProgramData\Temp:BF1E0621
AlternateDataStreams: C:\ProgramData\Temp:BF6A2C54
AlternateDataStreams: C:\ProgramData\Temp:BF6C81B2
AlternateDataStreams: C:\ProgramData\Temp:C0893153
AlternateDataStreams: C:\ProgramData\Temp:C0A9B815
AlternateDataStreams: C:\ProgramData\Temp:C0BCE04B
AlternateDataStreams: C:\ProgramData\Temp:C0D23A2F
AlternateDataStreams: C:\ProgramData\Temp:C10635F6
AlternateDataStreams: C:\ProgramData\Temp:C178954A
AlternateDataStreams: C:\ProgramData\Temp:C186F20B
AlternateDataStreams: C:\ProgramData\Temp:C22674B6
AlternateDataStreams: C:\ProgramData\Temp:C2F24DB5
AlternateDataStreams: C:\ProgramData\Temp:C30487EE
AlternateDataStreams: C:\ProgramData\Temp:C356A185
AlternateDataStreams: C:\ProgramData\Temp:C368C9EA
AlternateDataStreams: C:\ProgramData\Temp:C36D0DFD
AlternateDataStreams: C:\ProgramData\Temp:C370B84F
AlternateDataStreams: C:\ProgramData\Temp:C37283B5
AlternateDataStreams: C:\ProgramData\Temp:C3899C0B
AlternateDataStreams: C:\ProgramData\Temp:C3A047E3
AlternateDataStreams: C:\ProgramData\Temp:C48905F4
AlternateDataStreams: C:\ProgramData\Temp:C49A5AD1
AlternateDataStreams: C:\ProgramData\Temp:C4A88D6B
AlternateDataStreams: C:\ProgramData\Temp:C5340FA1
AlternateDataStreams: C:\ProgramData\Temp:C5D15631
AlternateDataStreams: C:\ProgramData\Temp:C5DC2B0C
AlternateDataStreams: C:\ProgramData\Temp:C62640AC
AlternateDataStreams: C:\ProgramData\Temp:C65B4BD1
AlternateDataStreams: C:\ProgramData\Temp:C669F3E1
AlternateDataStreams: C:\ProgramData\Temp:C6920A5D
AlternateDataStreams: C:\ProgramData\Temp:C7517D0A
AlternateDataStreams: C:\ProgramData\Temp:C76CFF82
AlternateDataStreams: C:\ProgramData\Temp:C78DADEA
AlternateDataStreams: C:\ProgramData\Temp:C7D35E8C
AlternateDataStreams: C:\ProgramData\Temp:C7F08EA3
AlternateDataStreams: C:\ProgramData\Temp:C8207070
AlternateDataStreams: C:\ProgramData\Temp:C82CA1C0
AlternateDataStreams: C:\ProgramData\Temp:C89D1773
AlternateDataStreams: C:\ProgramData\Temp:CA1AFE85
AlternateDataStreams: C:\ProgramData\Temp:CA23BCFD
AlternateDataStreams: C:\ProgramData\Temp:CA7E8F16
AlternateDataStreams: C:\ProgramData\Temp:CAB0171A
AlternateDataStreams: C:\ProgramData\Temp:CAC06C34
AlternateDataStreams: C:\ProgramData\Temp:CAE3AE67
AlternateDataStreams: C:\ProgramData\Temp:CB299F13
AlternateDataStreams: C:\ProgramData\Temp:CB3667AF
AlternateDataStreams: C:\ProgramData\Temp:CB5AA1E6
AlternateDataStreams: C:\ProgramData\Temp:CB8C8B5D
AlternateDataStreams: C:\ProgramData\Temp:CBAB74CB
AlternateDataStreams: C:\ProgramData\Temp:CBB4BFCD
AlternateDataStreams: C:\ProgramData\Temp:CC141B05
AlternateDataStreams: C:\ProgramData\Temp:CCD8056E
AlternateDataStreams: C:\ProgramData\Temp:CDCDE97C
AlternateDataStreams: C:\ProgramData\Temp:CE3AADB7
AlternateDataStreams: C:\ProgramData\Temp:CE506F23
AlternateDataStreams: C:\ProgramData\Temp:CF391C0F
AlternateDataStreams: C:\ProgramData\Temp:CFA8C6E3
AlternateDataStreams: C:\ProgramData\Temp:D01ACC06
AlternateDataStreams: C:\ProgramData\Temp:D026A5A4
AlternateDataStreams: C:\ProgramData\Temp:D086B88D
AlternateDataStreams: C:\ProgramData\Temp:D115F6E4
AlternateDataStreams: C:\ProgramData\Temp:D434342F
AlternateDataStreams: C:\ProgramData\Temp:D4558A0B
AlternateDataStreams: C:\ProgramData\Temp:D47B19A6
AlternateDataStreams: C:\ProgramData\Temp:D5BF78B4
AlternateDataStreams: C:\ProgramData\Temp:D621CFB8
AlternateDataStreams: C:\ProgramData\Temp:D72D7897
AlternateDataStreams: C:\ProgramData\Temp:D7B7645F
AlternateDataStreams: C:\ProgramData\Temp:D9592966
AlternateDataStreams: C:\ProgramData\Temp:D9656460
AlternateDataStreams: C:\ProgramData\Temp:D9771F40
AlternateDataStreams: C:\ProgramData\Temp:D999FFD5
AlternateDataStreams: C:\ProgramData\Temp:D9F34335
AlternateDataStreams: C:\ProgramData\Temp:DA378DD8
AlternateDataStreams: C:\ProgramData\Temp:DA5888A7
AlternateDataStreams: C:\ProgramData\Temp:DAB09BDB
AlternateDataStreams: C:\ProgramData\Temp:DB2748F7
AlternateDataStreams: C:\ProgramData\Temp:DB4C77AD
AlternateDataStreams: C:\ProgramData\Temp:DB76C881
AlternateDataStreams: C:\ProgramData\Temp:DBC3D477
AlternateDataStreams: C:\ProgramData\Temp:DBEF355E
AlternateDataStreams: C:\ProgramData\Temp:DC0B1070
AlternateDataStreams: C:\ProgramData\Temp:DC7EDF41
AlternateDataStreams: C:\ProgramData\Temp:DCF833BF
AlternateDataStreams: C:\ProgramData\Temp:DD6DBAC7
AlternateDataStreams: C:\ProgramData\Temp:DD6F157A
AlternateDataStreams: C:\ProgramData\Temp:DDF112BD
AlternateDataStreams: C:\ProgramData\Temp:DE3ABE3D
AlternateDataStreams: C:\ProgramData\Temp:DE875C30
AlternateDataStreams: C:\ProgramData\Temp:DE9AC04F
AlternateDataStreams: C:\ProgramData\Temp:DF5C005A
AlternateDataStreams: C:\ProgramData\Temp:DF7A2D3E
AlternateDataStreams: C:\ProgramData\Temp:DFC5A2B2
AlternateDataStreams: C:\ProgramData\Temp:E0888117
AlternateDataStreams: C:\ProgramData\Temp:E11D90D0
AlternateDataStreams: C:\ProgramData\Temp:E21433CE
AlternateDataStreams: C:\ProgramData\Temp:E21987F7
AlternateDataStreams: C:\ProgramData\Temp:E265ED33
AlternateDataStreams: C:\ProgramData\Temp:E2C51D18
AlternateDataStreams: C:\ProgramData\Temp:E2CFA9CD
AlternateDataStreams: C:\ProgramData\Temp:E329D971
AlternateDataStreams: C:\ProgramData\Temp:E32D2701
AlternateDataStreams: C:\ProgramData\Temp:E3615992
AlternateDataStreams: C:\ProgramData\Temp:E3B0ACE0
AlternateDataStreams: C:\ProgramData\Temp:E3B5F2D1
AlternateDataStreams: C:\ProgramData\Temp:E3C56885
AlternateDataStreams: C:\ProgramData\Temp:E40D7F76
AlternateDataStreams: C:\ProgramData\Temp:E4272706
AlternateDataStreams: C:\ProgramData\Temp:E446CB48
AlternateDataStreams: C:\ProgramData\Temp:E4E83517
AlternateDataStreams: C:\ProgramData\Temp:E4EE99EF
AlternateDataStreams: C:\ProgramData\Temp:E517FE76
AlternateDataStreams: C:\ProgramData\Temp:E5496666
AlternateDataStreams: C:\ProgramData\Temp:E5AF754F
AlternateDataStreams: C:\ProgramData\Temp:E5B07840
AlternateDataStreams: C:\ProgramData\Temp:E66FFABE
AlternateDataStreams: C:\ProgramData\Temp:E6708F08
AlternateDataStreams: C:\ProgramData\Temp:E690114B
AlternateDataStreams: C:\ProgramData\Temp:E6B95E40
AlternateDataStreams: C:\ProgramData\Temp:E6BEADB7
AlternateDataStreams: C:\ProgramData\Temp:E6C6EB3B
AlternateDataStreams: C:\ProgramData\Temp:E6CDFB4A
AlternateDataStreams: C:\ProgramData\Temp:E83EE313
AlternateDataStreams: C:\ProgramData\Temp:E876B1A8
AlternateDataStreams: C:\ProgramData\Temp:E894A3ED
AlternateDataStreams: C:\ProgramData\Temp:E8AEB2BF
AlternateDataStreams: C:\ProgramData\Temp:E8BE0B80
AlternateDataStreams: C:\ProgramData\Temp:E8C44CB4
AlternateDataStreams: C:\ProgramData\Temp:E94FA418
AlternateDataStreams: C:\ProgramData\Temp:E9FAC3AB
AlternateDataStreams: C:\ProgramData\Temp:EAF954B6
AlternateDataStreams: C:\ProgramData\Temp:EB86F355
AlternateDataStreams: C:\ProgramData\Temp:EBCF5924
AlternateDataStreams: C:\ProgramData\Temp:EBF0842B
AlternateDataStreams: C:\ProgramData\Temp:ECF3C50F
AlternateDataStreams: C:\ProgramData\Temp:ED0B32CA
AlternateDataStreams: C:\ProgramData\Temp:ED2D63E4
AlternateDataStreams: C:\ProgramData\Temp:EDDBC69E
AlternateDataStreams: C:\ProgramData\Temp:EDF12A30
AlternateDataStreams: C:\ProgramData\Temp:EE198B1F
AlternateDataStreams: C:\ProgramData\Temp:EE2DD6CC
AlternateDataStreams: C:\ProgramData\Temp:EE9B2879
AlternateDataStreams: C:\ProgramData\Temp:EF0F3F33
AlternateDataStreams: C:\ProgramData\Temp:EF38B79C
AlternateDataStreams: C:\ProgramData\Temp:EFBD4447
AlternateDataStreams: C:\ProgramData\Temp:EFF3C3C8
AlternateDataStreams: C:\ProgramData\Temp:F135A76C
AlternateDataStreams: C:\ProgramData\Temp:F142DBA9
AlternateDataStreams: C:\ProgramData\Temp:F193BFCF
AlternateDataStreams: C:\ProgramData\Temp:F1C8B957
AlternateDataStreams: C:\ProgramData\Temp:F1DEA771
AlternateDataStreams: C:\ProgramData\Temp:F26F5952
AlternateDataStreams: C:\ProgramData\Temp:F2B81C2E
AlternateDataStreams: C:\ProgramData\Temp:F2E92DCD
AlternateDataStreams: C:\ProgramData\Temp:F2EDC57C
AlternateDataStreams: C:\ProgramData\Temp:F3A185AE
AlternateDataStreams: C:\ProgramData\Temp:F41E22A9
AlternateDataStreams: C:\ProgramData\Temp:F56BE392
AlternateDataStreams: C:\ProgramData\Temp:F5B51004
AlternateDataStreams: C:\ProgramData\Temp:F5D01D7C
AlternateDataStreams: C:\ProgramData\Temp:F5E8CAE0
AlternateDataStreams: C:\ProgramData\Temp:F610C203
AlternateDataStreams: C:\ProgramData\Temp:F663BB74
AlternateDataStreams: C:\ProgramData\Temp:F68CB1A4
AlternateDataStreams: C:\ProgramData\Temp:F6A0889A
AlternateDataStreams: C:\ProgramData\Temp:F7401CCF
AlternateDataStreams: C:\ProgramData\Temp:F7BF538D
AlternateDataStreams: C:\ProgramData\Temp:F7FFE8AF
AlternateDataStreams: C:\ProgramData\Temp:F860DBFD
AlternateDataStreams: C:\ProgramData\Temp:F89F2593
AlternateDataStreams: C:\ProgramData\Temp:F8C2E3B9
AlternateDataStreams: C:\ProgramData\Temp:F8DE80DB
AlternateDataStreams: C:\ProgramData\Temp:F8EE1B63
AlternateDataStreams: C:\ProgramData\Temp:F9689B72
AlternateDataStreams: C:\ProgramData\Temp:F9B7A59C
AlternateDataStreams: C:\ProgramData\Temp:FB08C210
AlternateDataStreams: C:\ProgramData\Temp:FB4262DE
AlternateDataStreams: C:\ProgramData\Temp:FB71A279
AlternateDataStreams: C:\ProgramData\Temp:FBD274CF
AlternateDataStreams: C:\ProgramData\Temp:FC70A22A
AlternateDataStreams: C:\ProgramData\Temp:FCBEDCFD
AlternateDataStreams: C:\ProgramData\Temp:FD11E093
AlternateDataStreams: C:\ProgramData\Temp:FD646198
AlternateDataStreams: C:\ProgramData\Temp:FD6D11C9
AlternateDataStreams: C:\ProgramData\Temp:FD6DB82C
AlternateDataStreams: C:\ProgramData\Temp:FD7DCDA6
AlternateDataStreams: C:\ProgramData\Temp:FDEE14AC
AlternateDataStreams: C:\ProgramData\Temp:FF717A18
AlternateDataStreams: C:\ProgramData\Temp:FFC3922F
AlternateDataStreams: C:\ProgramData\Temp:FFD58FFB

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1043922925-1157543147-587559754-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\enna\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.254

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: GoogleChromeAutoLaunch_74AE521A6B9F77ECE435135995B71239 => "C:\Users\enna\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window
MSCONFIG\startupreg: GoogleChromeAutoLaunch_BF87F5B830A01A0EE9DF6164C82299F7 => "C:\Users\enna\AppData\Local\Chromium\Application\chrome.exe" --auto-launch-at-startup --profile-directory="Default"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{3ACE3B8E-6D57-47AA-92AE-091A6BCC436E}] => (Allow) C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe
FirewallRules: [{ECEE6578-B515-4104-AC5F-F391B82851EA}] => (Allow) C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PlayMovie.exe
FirewallRules: [{89C0C9AC-5642-4B4E-8245-C6BF1DA88C8C}] => (Allow) C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe
FirewallRules: [{E49C5C77-E054-4C7F-81DD-6CE013BF1A3A}] => (Allow) C:\Program Files (x86)\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe
FirewallRules: [{B247D98D-4DC5-4154-9327-31BD1A4F0C05}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [TCP Query User{59EAC460-3BC4-49DA-92BF-F67E72F1C502}C:\program files\vuze\azureus.exe] => (Allow) C:\program files\vuze\azureus.exe
FirewallRules: [UDP Query User{E91D691B-29DC-491F-ACA2-74DB80643279}C:\program files\vuze\azureus.exe] => (Allow) C:\program files\vuze\azureus.exe
FirewallRules: [{364B1B48-0661-4101-93A6-C795BE23C9C3}] => (Allow) C:\Program Files\HP\HP Deskjet 2540 series\Bin\DeviceSetup.exe
FirewallRules: [{44E7772D-26E6-4D61-9A95-DBC167AE9A94}] => (Allow) LPort=5357
FirewallRules: [{AF5364DF-85E0-4E05-ACDE-9C111CF8908D}] => (Allow) C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{24C55E0D-5078-40A6-94CC-E555A9A64C59}] => (Allow) C:\Users\enna\AppData\Local\Chromium\Application\chrome.exe
FirewallRules: [{B8D13FAB-58FE-485F-B374-9DEE2688723C}] => (Allow) C:\Program Files\Vuze\Azureus.exe
FirewallRules: [{38CF1935-20B0-4012-99A7-20C5B218DA9D}] => (Allow) C:\Program Files\Vuze\Azureus.exe

==================== Faulty Device Manager Devices =============

Name: Slimtype DVD A DS8A4SH ATA Device
Description: Lecteur de CD-ROM
Class Guid: {4d36e965-e325-11ce-bfc1-08002be10318}
Manufacturer: (Lecteurs de CD-ROM standard)
Service: cdrom
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/13/2015 04:52:01 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: Une erreur non spécifiée s’est produite au cours de la restauration du système : (Uniblue PC Mechanic installation). Informations supplémentaires : 0xc0000022.

Error: (07/13/2015 08:46:10 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Le programme IEXPLORE.EXE version 11.0.9600.17840 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance.

ID de processus : 13b4

Heure de début : 01d0bd34fc92f3a5

Heure de fin : 8192

Chemin d’accès de l’application : C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

ID de rapport :

Error: (07/11/2015 12:03:04 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Le programme IEXPLORE.EXE version 11.0.9600.17840 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance.

ID de processus : f54

Heure de début : 01d0bbbe1a94274e

Heure de fin : 6149

Chemin d’accès de l’application : C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

ID de rapport :

Error: (06/29/2015 05:56:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nom de l’application défaillante Chronicles of Mystery - Secret of the Lost Kingdom.exe, version : 0.0.0.0, horodatage : 0x4cb2e7ad
Nom du module défaillant : Chronicles of Mystery - Secret of the Lost Kingdom.exe, version : 0.0.0.0, horodatage : 0x4cb2e7ad
Code d’exception : 0xc0000005
Décalage d’erreur : 0x00054b5b
ID du processus défaillant : 0x1118
Heure de début de l’application défaillante : 0xChronicles of Mystery - Secret of the Lost Kingdom.exe0
Chemin d’accès de l’application défaillante : Chronicles of Mystery - Secret of the Lost Kingdom.exe1
Chemin d’accès du module défaillant: Chronicles of Mystery - Secret of the Lost Kingdom.exe2
ID de rapport : Chronicles of Mystery - Secret of the Lost Kingdom.exe3

Error: (06/29/2015 05:56:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nom de l’application défaillante Chronicles of Mystery - Secret of the Lost Kingdom.exe, version : 0.0.0.0, horodatage : 0x4cb2e7ad
Nom du module défaillant : Chronicles of Mystery - Secret of the Lost Kingdom.exe, version : 0.0.0.0, horodatage : 0x4cb2e7ad
Code d’exception : 0xc0000005
Décalage d’erreur : 0x00054b5b
ID du processus défaillant : 0xd40
Heure de début de l’application défaillante : 0xChronicles of Mystery - Secret of the Lost Kingdom.exe0
Chemin d’accès de l’application défaillante : Chronicles of Mystery - Secret of the Lost Kingdom.exe1
Chemin d’accès du module défaillant: Chronicles of Mystery - Secret of the Lost Kingdom.exe2
ID de rapport : Chronicles of Mystery - Secret of the Lost Kingdom.exe3

Error: (06/29/2015 08:12:14 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Le programme IEXPLORE.EXE version 11.0.9600.17840 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance.

ID de processus : 11c0

Heure de début : 01d0b230d3299627

Heure de fin : 1232

Chemin d’accès de l’application : C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

ID de rapport :

Error: (06/29/2015 08:01:11 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Le programme IEXPLORE.EXE version 11.0.9600.17840 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance.

ID de processus : bdc

Heure de début : 01d0b230b9743ada

Heure de fin : 125

Chemin d’accès de l’application : C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

ID de rapport :

Error: (06/27/2015 12:42:13 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Le programme IEXPLORE.EXE version 11.0.9600.17840 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance.

ID de processus : 107c

Heure de début : 01d0b0c596d2bdf5

Heure de fin : 179

Chemin d’accès de l’application : C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

ID de rapport :

Error: (06/27/2015 12:41:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Le programme IEXPLORE.EXE version 11.0.9600.17840 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance.

ID de processus : c80

Heure de début : 01d0b0c35fe8982a

Heure de fin : 6329

Chemin d’accès de l’application : C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

ID de rapport :

Error: (06/25/2015 06:00:31 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0, Version=9.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070020


System errors:
=============
Error: (07/14/2015 04:29:13 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Le pilote de démarrage système ou d’amorçage suivant n’a pas pu se charger :
cdrom

Error: (07/14/2015 04:10:39 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Le pilote de démarrage système ou d’amorçage suivant n’a pas pu se charger :
cdrom

Error: (07/13/2015 05:29:53 PM) (Source: atapi) (EventID: 11) (User: )
Description: Le pilote a détecté une erreur du contrôleur sur \Device\Ide\IdePort0.

Error: (07/13/2015 05:29:53 PM) (Source: atapi) (EventID: 11) (User: )
Description: Le pilote a détecté une erreur du contrôleur sur \Device\Ide\IdePort0.

Error: (07/13/2015 05:29:53 PM) (Source: atapi) (EventID: 11) (User: )
Description: Le pilote a détecté une erreur du contrôleur sur \Device\Ide\IdePort0.

Error: (07/13/2015 05:19:01 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Le service WajIEn Monitor s’est terminé de façon inattendue pour la 1ème fois.

Error: (07/13/2015 05:14:57 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Le pilote de démarrage système ou d’amorçage suivant n’a pas pu se charger :
cdrom

Error: (07/13/2015 05:10:03 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: AUTORITE NT)
Description: Échec de l’installation : l’installation de la mise à jour suivante a échoue avec l’erreur 0x80070643 : Definition Update for Windows Defender - KB915597 (Definition 1.201.1399.0).

Error: (07/13/2015 04:51:44 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Le pilote de démarrage système ou d’amorçage suivant n’a pas pu se charger :
cdrom

Error: (07/13/2015 04:08:38 PM) (Source: Schannel) (EventID: 4120) (User: AUTORITE NT)
Description: L’alerte fatale suivante a été générée : 10. L’état d’erreur interne est 10.


Microsoft Office:
=========================
Error: (07/13/2015 04:52:01 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: Uniblue PC Mechanic installation0xc0000022

Error: (07/13/2015 08:46:10 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.1784013b401d0bd34fc92f3a58192C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Error: (07/11/2015 12:03:04 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17840f5401d0bbbe1a94274e6149C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Error: (06/29/2015 05:56:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Chronicles of Mystery - Secret of the Lost Kingdom.exe0.0.0.04cb2e7adChronicles of Mystery - Secret of the Lost Kingdom.exe0.0.0.04cb2e7adc000000500054b5b111801d0b2842ed8eea3C:\Users\enna\Documents\Vuze Downloads\Chronicles of Mystery - Secret of the Lost Kingdom\Chronicles of Mystery - Secret of the Lost Kingdom.exeC:\Users\enna\Documents\Vuze Downloads\Chronicles of Mystery - Secret of the Lost Kingdom\Chronicles of Mystery - Secret of the Lost Kingdom.exe6cf8e61d-1e77-11e5-96f0-00262d6a23fe

Error: (06/29/2015 05:56:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Chronicles of Mystery - Secret of the Lost Kingdom.exe0.0.0.04cb2e7adChronicles of Mystery - Secret of the Lost Kingdom.exe0.0.0.04cb2e7adc000000500054b5bd4001d0b28422673bd6C:\Users\enna\Documents\Vuze Downloads\Chronicles of Mystery - Secret of the Lost Kingdom\Chronicles of Mystery - Secret of the Lost Kingdom.exeC:\Users\enna\Documents\Vuze Downloads\Chronicles of Mystery - Secret of the Lost Kingdom\Chronicles of Mystery - Secret of the Lost Kingdom.exe632c93ab-1e77-11e5-96f0-00262d6a23fe

Error: (06/29/2015 08:12:14 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.1784011c001d0b230d32996271232C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Error: (06/29/2015 08:01:11 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17840bdc01d0b230b9743ada125C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Error: (06/27/2015 12:42:13 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17840107c01d0b0c596d2bdf5179C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Error: (06/27/2015 12:41:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17840c8001d0b0c35fe8982a6329C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Error: (06/25/2015 06:00:31 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0, Version=9.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070020
Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0, Version=9.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a


==================== Memory info ===========================

Processor: Pentium(R) Dual-Core CPU T4400 @ 2.20GHz
Percentage of memory in use: 34%
Total physical RAM: 2042.93 MB
Available physical RAM: 1332.39 MB
Total Virtual: 4085.86 MB
Available Virtual: 2070.25 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:453.94 GB) (Free:320.43 GB) NTFS
Drive d: (DATA_2) (Fixed) (Total:465.76 GB) (Free:465.01 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 35EE35ED)
Partition 1: (Not Active) - (Size=11.7 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=453.9 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 35F335F2)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End of log ============================

Publicité


Signaler le contenu de ce document

Publicité