Sample File: MD5 hash: 956090ecfd9dc1986e4ae0afd782c1d3 SHA1 hash: 230aa8c348dcfa88698d2aaaae694d623c19b76b SHA256 hash: 4444458bf47925c82431843fd147aabbfbee71ca849fc711cb69b0cea01f4747 SSDEEP hash: 24576:5pitYuAnu1YrnjyMd2uCdLkT0TChyDUgyvkW8ZRGyzE:GD1Y6Md2uCdC0TChjbvk5RGWE Filename(s): vinfk.exe Filetype: Windows Exe (x86-32) Mutex IOCs: Registry Key IOCs: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\DisableUNCCheck HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\EnableExtensions HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\DelayedExpansion HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\DefaultColor HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\CompletionChar HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\PathCompletionChar HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\AutoRun HKEY_CURRENT_USER\Software\Microsoft\Command Processor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AppContext HKEY_LOCAL_MACHINE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WSMAN HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WSMAN\ServiceStackVersion HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\3\PowerShellEngine HKEY_LOCAL_MACHINE\Software\Microsoft\PowerShell\3\PowerShellEngine\ApplicationBase HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\PowerShell\ModuleLogging HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\PowerShell\ModuleLogging HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\PowerShell\Transcription HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\PowerShell\Transcription HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\PowerShell\ConsoleSessionConfiguration HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\PowerShell\ConsoleSessionConfiguration HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\TZI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\Dynamic DST HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Display HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Std HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Dlt HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\PSMODULEPATH HKEY_CURRENT_USER\Environment HKEY_CURRENT_USER\Environment\PSMODULEPATH HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\PowerShell HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\HardwareEvents HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\HardwareEvents\PowerShell HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Internet Explorer HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Internet Explorer\PowerShell HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Key Management Service HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Key Management Service\PowerShell HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\OAlerts HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\OAlerts\PowerShell HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security\PowerShell HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\PowerShell HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Windows PowerShell HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Windows PowerShell\PowerShell HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Winevt\Publishers\{816ebd75-f7ab-59c0-e2f0-bddfeed66ac2} HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\__PSLockdownPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds\PipelineMaxStackSizeMB HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging HKEY_PERFORMANCE_DATA HKEY_CURRENT_USER\SOFTWARE\Microsoft\.NETFramework\XML HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\XML HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\PowerShell HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\PowerShell HKEY_CURRENT_USER\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell HKEY_CURRENT_USER\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell\ExecutionPolicy HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\DiagTrackAuthorization HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\InstallationType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\HWRPortReuseOnSocketBind HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\SchUseStrongCrypto HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\System.Net.ServicePointManager.SchSendAuxRecord HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\SchSendAuxRecord HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\SystemDefaultTlsVersions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\System.Net.ServicePointManager.RequireCertificateEKUs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\RequireCertificateEKUs HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\EventLog\ProtectedEventLogging HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM\Logging HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM\Logging Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM\Log File Max Size Domain IOCs: smtp.gmail.com IP IOCs: 74.125.205.109 URL IOCs: - None - File IOCs: Filenames: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2013CAWin64.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\EventTracingManagement\PSGetModuleInfo.xml C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetTCPIP\NetTCPIP.psd1 C:\WINDOWS\system32\reg.exe C:\588bce7c90097ed212\1025\LocalizedData.xml.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\TLS.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Framework.1.1_1.0.23115.0_x86__8wekyb3d8bbwe.xml C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet C:\Users\FD1HVy\AppData\Local\Temp\sad.ps1 C:\588bce7c90097ed212\UiInfo.xml C:\588bce7c90097ed212\1028\eula.rtf.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.008.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.WSMan.Management\Microsoft.WSMan.Management.psd1 C:\588bce7c90097ed212\1030\LocalizedData.xml.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUx.001.etl C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\Microsoft.PowerShell.Operation.Validation.dll C:\Program Files (x86)\WindowsPowerShell\Modules\Pester\3.3.5\Pester.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MSFT_DtcTask_v1.0.cdxml C:\588bce7c90097ed212\netfx_Core_x64.msi.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.004.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\WindowsDeveloperLicense C:\588bce7c90097ed212\1040\eula.rtf.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.DesktopAppInstaller_1.1.25002.0_neutral_~_8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PSScheduledJob\PSScheduledJob.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\Microsoft.WindowsAuthenticationProtocols.Commands\Microsoft.WindowsAuthenticationProtocols.Commands.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.ni.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Runtime.1.0_1.0.22929.0_x86__8wekyb3d8bbwe.xml C:\588bce7c90097ed212\1038\eula.rtf.HOR C:\Program Files\WindowsPowerShell\Modules\Modules.xaml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\Microsoft.CertificateServices.PKIClient.Cmdlets.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.dll C:\588bce7c90097ed212\1043\eula.rtf C:\588bce7c90097ed212\1036\eula.rtf C:\588bce7c90097ed212\1049\LocalizedData.xml.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Crypto\RSA\MachineKeys\f686aace6942fb7f7ceb231212eef4a4_e8d761b7-8a68-4187-8c95-75a3788ac267 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUx.002.etl C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Win64.xml C:\588bce7c90097ed212\1035\LocalizedData.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\Events_Normal.rbs \??\c:\Windows\WinSxS\Temp\PendingDeletes\9AEE73~1.WIN C:\588bce7c90097ed212\SplashScreen.bmp.HOR C:\WINDOWS C:\588bce7c90097ed212\Graphics\Rotate4.ico C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Runtime.1.3_1.3.23901.0_x86__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetLbfo\NetLbfo.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BingWeather_4.18.56.0_x64__8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.028.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\TroubleshootingPack.Format.ps1xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.013.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetConnection\PSGetModuleInfo.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\Microsoft.InternationalSettings.Commands.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\9E2F88E3.Twitter_5.7.1.0_x86__wgeqdkkx372wm.xml C:\588bce7c90097ed212\1042\LocalizedData.xml.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\03d1e1da-f580-45d7-afdd-3598ed7cdba4_withdraw.xml C:\588bce7c90097ed212\1042\eula.rtf.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.016.etl C:\Program Files\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\UEV\UEV.psd1 C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MSMQ\MSMQ.psd1 C:\Program Files\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetNat\MSFT_NetNat.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\en-US\SecureBoot.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\e80c855c-d75c-47b1-9ae4-f07f8c6c613d_show.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Management C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Messaging_3.26.24002.0_neutral_split.scale-150_8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\WindowsDeveloperLicense\WindowsDeveloperLicense.psd1 C:\Program Files (x86)\WindowsPowerShell\Modules\PackageManagement\PackageManagement.dll C:\588bce7c90097ed212\Graphics\Rotate7.ico.HOR C:\Program Files\WindowsPowerShell\Modules\PSReadline\PSReadline.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\UEV\en\UEV.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.002.etl C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BingSports_4.6.169.0_x86__8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Framework.1.0_1.0.22929.0_x86__8wekyb3d8bbwe.xml C:\Program Files\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.dll C:\588bce7c90097ed212\1040\LocalizedData.xml.HOR C:\588bce7c90097ed212\1033\LocalizedData.xml.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.dll C:\Program Files (x86)\WindowsPowerShell\Modules\Pester\Pester.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.020.etl C:\588bce7c90097ed212\1031\eula.rtf C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftSolitaireCollection_3.14.1181.0_neutral_split.scale-100_8wekyb3d8bbwe.xml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetNat\MSFT_NetNatGlobal.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\Microsoft.WindowsAuthenticationProtocols.Commands.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\WindowsErrorReporting\en\WindowsErrorReporting.psd1 C:\Program Files\WindowsPowerShell\Modules\PSReadline\PSReadline.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Microsoft.KeyDistributionService.Cmdlets\Microsoft.KeyDistributionService.Cmdlets.ni.dll C:\588bce7c90097ed212\1053\eula.rtf.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\SmsRouter\MessageStore\edb00002.log C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Framework.1.0_1.0.22929.0_x64__8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\Templates\SettingsLocationTemplate2013A.xsd C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\VpnClient C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.010.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell C:\WINDOWS\SysWOW64\cmd.exe C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftInternetExplorer2013Backup.xml C:\Program Files\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\DnsClient\DnsClient.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.psd1 C:\Program Files\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.ni.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Crypto\SystemKeys\7092289d2be9a3ebf1065d0f1c678ab6_e8d761b7-8a68-4187-8c95-75a3788ac267 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.jfm C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.021.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\EventTracingManagement\MSFT_AutologgerConfig_v1.0.cdxml C:\588bce7c90097ed212\netfx_Core.mzz C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.psm1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Messaging_1.10.22012.0_neutral_split.scale-150_8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetworkTransition C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\9984ecc0-931c-4feb-8996-203a6ffaa852_show.xml C:\Program Files\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\EventTracingManagement\MSFT_EtwTraceProvider_v1.0.format.ps1xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Advertising.Xaml_10.0.1605.0_x64__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\Microsoft.SecureBoot.Commands\Microsoft.SecureBoot.Commands.cdxml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\Events_NormalCritical.rbs C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\Events_Realtime.rbs C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\VpnClient\VpnClient.psd1 C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\CortanaListenUIApp_10.0.15063.0_neutral__cw5n1h2txyewy.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.cdxml C:\Program Files\WindowsPowerShell\Modules\Modules.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetConnection\NetConnection.psd1 C:\Program Files (x86)\WindowsPowerShell\Modules\Pester\Pester.ni.dll C:\588bce7c90097ed212\netfx_Extended_x64.msi C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.cdxml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\UEV\Microsoft.Uev.Commands.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Diagnostics C:\588bce7c90097ed212\1045\LocalizedData.xml.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\BitsTransfer C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetNat C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Wdac C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\Microsoft.WindowsAuthenticationProtocols.Commands.psm1 C:\Users C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\en\TLS.psd1 C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Security C:\588bce7c90097ed212\3082\eula.rtf.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.013.etl C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\713__Connections_Cellular_CMHK (Hong Kong SAR)_i0$(__MVID)@WAP.provxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\PSDesiredStateConfiguration.psd1 C:\588bce7c90097ed212\1042\LocalizedData.xml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.psd1 C:\Program Files\WindowsPowerShell\Modules\Pester\Pester.psd1 C:\WINDOWS\SysWOW64\WindowsPowerShell\v1.0\powershell.exe c:\Windows\WinSxS\Temp\PendingDeletes\D82E4C~1.WIN C:\588bce7c90097ed212\Client\UiInfo.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateUx.001.etl C:\588bce7c90097ed212\1033\eula.rtf C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\DesktopView_1000.15063.0.0_neutral_neutral_cw5n1h2txyewy.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Storage\Storage.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\e9d21752-8fc9-4793-b42e-33105b078a51_withdraw.xml C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Utility\Microsoft.PowerShell.Utility.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Microsoft.KeyDistributionService.Cmdlets.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\Microsoft.WindowsAuthenticationProtocols.Commands.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\BranchCache C:\Program Files\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.dll C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu C:\Program Files\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.psd1 C:\588bce7c90097ed212\3076\eula.rtf C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.010.etl C:\Program Files (x86)\WindowsPowerShell\Modules\Pester\Pester.cdxml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.029.etl C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.026.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\EventTracingManagement\MSFT_EtwTraceSession_v1.0.format.ps1xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\en-US\PKI.psd1 C:\588bce7c90097ed212\1045\eula.rtf.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\c0802597-6174-487a-b7de-20e8b1aa384e_withdraw.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\c5e2524a-ea46-4f67-841f-6a9465d9d515_10.0.15063.0_neutral_neutral_cw5n1h2txyewy.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PSDiagnostics C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.PowerShell.Commands.Utility\Microsoft.PowerShell.Commands.Utility.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.ni.dll C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.xaml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PrintManagement C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MsDtc.Formats.ps1xml C:\588bce7c90097ed212\RGB9RAST_x64.msi C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\e9d21752-8fc9-4793-b42e-33105b078a51_show.xml \??\c:\Windows\WinSxS\Temp\PendingDeletes\80281F~1.WIN C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.xaml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.016.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.cdxml C:\588bce7c90097ed212\1028\LocalizedData.xml.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.011.etl C:\Program Files\WindowsPowerShell\Modules\Pester\3.4.0\Pester.psd1 C:\588bce7c90097ed212\Graphics\Setup.ico.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.015.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Kds.psd1 C:\588bce7c90097ed212\Client\UiInfo.xml.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Runtime.1.1_1.1.23118.0_x64__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PnpDevice C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetNat\en-US\NetNat.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Framework.1.6_1.6.24903.0_x86__8wekyb3d8bbwe.xml C:\Users\FD1HVy\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 C:\588bce7c90097ed212\1032\eula.rtf.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.023.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MSFT_DtcNetworkSettingTask_v1.0.cdxml C:\588bce7c90097ed212\1029\LocalizedData.xml.HOR C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Host C:\588bce7c90097ed212\3076\LocalizedData.xml C:\588bce7c90097ed212\1041\eula.rtf C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\HoloShell_10.0.15063.0_neutral__cw5n1h2txyewy.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\WindowsErrorReporting\PSGetModuleInfo.xml C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftSolitaireCollection_3.14.1181.0_neutral_~_8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\DirectAccessClientComponents\DirectAccessClientComponents.psd1 C:\588bce7c90097ed212\Graphics\Rotate3.ico C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Getstarted_4.5.6.0_x64__8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.035.etl C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.030.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Modules.psm1 C:\Program Files\WindowsPowerShell\Modules\PackageManagement\PackageManagement.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\Microsoft.Dtc.PowerShell.cdxml C:\Program Files\WindowsPowerShell\Modules\PackageManagement\PackageManagement.psd1 C:\588bce7c90097ed212\1049\eula.rtf.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Appconnector_2015.707.550.0_neutral_~_8wekyb3d8bbwe.xml C:\588bce7c90097ed212\Graphics\stop.ico C:\Program Files\WindowsPowerShell\Modules\PackageManagement\PackageManagement.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\Microsoft.WindowsAuthenticationProtocols.Commands\Microsoft.WindowsAuthenticationProtocols.Commands.psm1 C:\588bce7c90097ed212\netfx_Extended.mzz.HOR C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MSFT_DtcAdvancedSettingTask_v1.0.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetNat\MSFT_NetNatStaticMapping.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack C:\588bce7c90097ed212\1025\eula.rtf C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\Microsoft.PowerShell.Operation.Validation.ni.dll C:\Program Files\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.ni.dll c:\*.VHD C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PSScheduledJob C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.ni.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Advertising.Xaml_10.0.1605.0_x86__8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Microsoft3DViewer_1.1702.21039.0_neutral_~_8wekyb3d8bbwe.xml C:\588bce7c90097ed212\Strings.xml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetNat\MSFT_NetNat.Format.ps1xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\e80c855c-d75c-47b1-9ae4-f07f8c6c613d_withdraw.xml C:\Program Files\WindowsPowerShell\Modules\PackageManagement\PackageManagement.xaml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.017.etl C:\Program Files (x86)\WindowsPowerShell\Modules\PackageManagement\PackageManagement.cdxml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\VdiState.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\PKI.psd1 C:\588bce7c90097ed212\1040\LocalizedData.xml C:\Windows\SysWOW64\WindowsPowerShell\v1.0\profile.ps1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\osver.txt C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\Microsoft.PowerShell.Operation.Validation.ni.dll C:\Program Files\WindowsPowerShell\Modules\PackageManagement\1.0.0.1\PackageManagement.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.psd1 C:\Program Files\WindowsPowerShell\Modules\Pester\Pester.psm1 C:\Program Files\WindowsPowerShell\Modules\Pester\Pester.cdxml C:\Program Files (x86)\WindowsPowerShell\Modules\Pester\3.4.0\Pester.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\1527c705-839a-4832-9118-54d4Bd6a0c89_10.0.15063.447_neutral_neutral_cw5n1h2txyewy.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\c0802597-6174-487a-b7de-20e8b1aa384e_show.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftEdge_40.15063.0.0_neutral__8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftStickyNotes_1.4.101.0_neutral_split.scale-100_8wekyb3d8bbwe.xml C:\588bce7c90097ed212\1030\eula.rtf.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\SmsRouter\MessageStore\edbres00002.jrs C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\Microsoft.WindowsAuthenticationProtocols.Commands\Microsoft.WindowsAuthenticationProtocols.Commands.cdxml C:\588bce7c90097ed212\1053\eula.rtf C:\588bce7c90097ed212\1055\eula.rtf.HOR C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets C:\588bce7c90097ed212\1029\eula.rtf C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Framework.1.3_1.3.24201.0_x64__8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x64__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\WindowsErrorReporting\en-US\WindowsErrorReporting.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\Microsoft.InternationalSettings.Commands.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\CimCmdlets C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Runtime.1.6_1.6.24903.0_x64__8wekyb3d8bbwe.xml C:\Program Files\WindowsPowerShell\Modules\PowerShellGet c:\Backup*.* C:\588bce7c90097ed212\1043\LocalizedData.xml.HOR C:\588bce7c90097ed212\Graphics\Save.ico.HOR C:\Program Files (x86)\WindowsPowerShell\Modules\Pester\3.4.0\Pester.psm1 C:\WINDOWS\system32\wldp.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetNat\NetNat.psd1 C:\588bce7c90097ed212\1030\LocalizedData.xml C:\588bce7c90097ed212\2052\LocalizedData.xml.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.CredDialogHost_10.0.15063.0_neutral__cw5n1h2txyewy.xml C:\588bce7c90097ed212\1041\eula.rtf.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Appx\Appx.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\75ef5b41-571d-4a4b-92bb-8b9f7fdc831f_withdraw.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftSkypeForBusiness2016Win64.xml C:\Program Files\WindowsPowerShell\Modules\Pester\Pester.ni.dll C:\Program Files\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.xaml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Network\Downloader\edb.log.HOR C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu C:\Program Files\WindowsPowerShell\Modules\Pester C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.025.etl C:\588bce7c90097ed212\Graphics\Save.ico C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Microsoft.KeyDistributionService.Cmdlets\Microsoft.KeyDistributionService.Cmdlets.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\Microsoft.InternationalSettings.Commands.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MSFT_DtcClusterTMMappingTask_v1.0.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\UEV C:\WINDOWS\SysWOW64\WindowsPowerShell\v1.0\powershell.exe.config C:\Program Files (x86)\WindowsPowerShell\Modules\Modules.psm1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\DesktopLearning_1000.15063.0.0_neutral__cw5n1h2txyewy.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x86__8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\HoloItemPlayerApp_1.0.0.2_neutral__cw5n1h2txyewy.xml \??\c:\Windows\WinSxS\Temp\PendingDeletes\8049A7~3.WIN C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.ni.dll C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll C:\588bce7c90097ed212\1032\eula.rtf C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.018.etl C:\588bce7c90097ed212\1033\eula.rtf.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\Microsoft.SecureBoot.Commands\Microsoft.SecureBoot.Commands.psd1 C:\588bce7c90097ed212\2070\LocalizedData.xml C:\Users\FD1HVy\AppData\Local\Microsoft_Corporation\DefaultDomain_Path_vts5ulh4lcatsmkjq054m5tgofqeypsd\10.0.15063.0\user.config C:\588bce7c90097ed212\netfx_Extended_x64.msi.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.014.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration C:\588bce7c90097ed212\RGB9Rast_x86.msi C:\588bce7c90097ed212\header.bmp C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PrintManagement\en\PrintManagement.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MSFT_DtcTransactionsTraceSessionTask_v1.0.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetworkConnectivityStatus C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Microsoft.PowerShell_profile.ps1 C:\588bce7c90097ed212\1053\LocalizedData.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\EventTracingManagement\en\EventTracingManagement.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\acae4208-0ac4-4ef7-ac45-bb688b09e559_show.xml C:\Program Files\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\Microsoft.SecureBoot.Commands.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PrintManagement\MSFT_PrinterPort_v1.0.cdxml C:\Users\FD1HVy\AppData\Local\Temp\__PSScriptPolicyTest_2yjbimnm.l3n.ps1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Wdac\Wdac.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.003.etl C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BingNews_4.6.169.0_x86__8wekyb3d8bbwe.xml C:\WINDOWS\System32\WindowsPowerShell\v1.0\ C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Network\Downloader\edbres00002.jrs C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\ClickToRunPackageLocker C:\588bce7c90097ed212\Graphics\Rotate1.ico.HOR c:\Windows\WinSxS\Temp\PendingDeletes\d8aba9ccce27d30199050000240bec00.Windows.Web.winmd C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Getstarted_2.3.7.0_neutral_~_8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MSFT_DtcLogTask_v1.0.cdxml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftNotepad.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\PSGetModuleInfo.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\Templates\SettingsLocationTemplate2013.xsd C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Runtime.1.0_1.0.22929.0_x64__8wekyb3d8bbwe.xml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.xaml C:\588bce7c90097ed212\1030\eula.rtf C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\WindowsErrorReporting C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.psm1 C:\588bce7c90097ed212\1035\eula.rtf C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.038.etl c:\Windows\WinSxS\Temp\PendingDeletes\9aee7364ce27d301da030000240bec00.Cortana.Internal.Search.winmd C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2010Win32.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftSolitaireCollection_3.3.9211.0_neutral_~_8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\E2A4F912-2574-4A75-9BB0-0D023378592B_10.0.15063.332_neutral_neutral_cw5n1h2txyewy.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.DesktopAppInstaller_1.0.10252.0_neutral_split.scale-125_8wekyb3d8bbwe.xml C:\588bce7c90097ed212\1035\eula.rtf.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Dism C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\DirectAccessClientComponents C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\Microsoft.WindowsAuthenticationProtocols.Commands.xaml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Utility\en-US\Microsoft.PowerShell.Utility.psd1 c:\Windows\WinSxS\Temp\PendingDeletes\8049a7ccce27d30193050000240bec00.Windows.Security.winmd C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\International.psd1 \??\c:\Windows\WinSxS\Temp\PendingDeletes\D82E4C~1.WIN C:\588bce7c90097ed212\1036\LocalizedData.xml.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetSecurity C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.cdxml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\guest.png C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.3DBuilder_13.0.10349.0_neutral_split.scale-140_8wekyb3d8bbwe.xml c:\Windows\WinSxS\Temp\PendingDeletes\D8ABA9~3.WIN C:\Users\FD1HVy\AppData\Local\Temp\LOG_ENCRYPT.log C:\588bce7c90097ed212\3082\eula.rtf C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Office365Win64.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MSPaint_1.1702.28017.0_neutral_~_8wekyb3d8bbwe.xml C:\Program Files (x86)\WindowsPowerShell\Modules C:\Program Files\WindowsPowerShell\Modules\PSReadline\PSReadline.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\en-US\TLS.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Commands.Utility C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Messaging_3.26.24002.0_x64__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MsDtc.psd1 C:\588bce7c90097ed212\1037\LocalizedData.xml.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Microsoft.KeyDistributionService.Cmdlets.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\Microsoft.WindowsAuthenticationProtocols.Commands\Microsoft.WindowsAuthenticationProtocols.Commands.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\TestDtc.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PSDiagnostics\PSDiagnostics.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.036.etl C:\Program Files\WindowsPowerShell\Modules\Pester\3.3.5\Pester.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetEventPacketCapture\NetEventPacketCapture.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.027.etl C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\MF\Pending.GRL.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MSFT_DtcClusterDefaultTask_v1.0.cdxml C:\Program Files\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppvClient\PSGetModuleInfo.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetLbfo C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\75ef5b41-571d-4a4b-92bb-8b9f7fdc831f_show.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MsDtc.Types.ps1xml C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\EventTracingManagement\EventTracingManagement.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\Microsoft.CertificateServices.PKIClient.Cmdlets C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BingWeather_4.18.56.0_neutral_split.scale-100_8wekyb3d8bbwe.xml C:\588bce7c90097ed212\watermark.bmp.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetTCPIP C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetEventPacketCapture C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BingWeather_4.18.56.0_neutral_~_8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BingFinance_4.6.169.0_neutral_split.scale-200_8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Microsoft.KeyDistributionService.Cmdlets C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Office.OneNote_17.7668.58071.0_x64__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\en-US\International.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\Microsoft.InternationalSettings.Commands.cdxml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftOfficeHub_17.8010.5926.0_x64__8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.CommsPhone_1.10.15000.0_neutral_split.scale-100_8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.003.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetQos\MSFT_NetQosPolicy.cdxml C:\Program Files\WindowsPowerShell\Modules\PSReadline\PSReadline.xaml C:\Program Files\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.dll C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\Microsoft.SecureBoot.Commands.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\UEV\en-US\UEV.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.037.etl C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win32.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\Microsoft.SecureBoot.Commands.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Utility\Microsoft.PowerShell.Commands.Utility.dll\Microsoft.PowerShell.Commands.Utility.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.cdxml c:\Windows\WinSxS\Temp\PendingDeletes\6a018764ce27d301fb030000240bec00.Cortana.Search.winmd C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.HOR C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\MF\Active.GRL.HOR C:\588bce7c90097ed212\Graphics\stop.ico.HOR C:\588bce7c90097ed212\ParameterInfo.xml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\en\TroubleshootingPack.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\UEV\PSGetModuleInfo.xml C:\588bce7c90097ed212\Extended\Parameterinfo.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\en\MsDtc.psd1 C:\588bce7c90097ed212\1031\LocalizedData.xml.HOR C:\588bce7c90097ed212\1044\eula.rtf.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.017.etl C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.psm1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\MF\Active.GRL C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\Microsoft.InternationalSettings.Commands C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\Templates\SettingsLocationTemplate.xsd C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.cdxml C:\588bce7c90097ed212\Graphics\Rotate2.ico.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\fffd8b5d-0172-4719-a792-b7c76986459d_withdraw.xml C:\588bce7c90097ed212\2052\LocalizedData.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.012.etl C:\588bce7c90097ed212\DisplayIcon.ico C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Utility\Microsoft.PowerShell.Utility.psd1 C:\Program Files\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.xaml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetConnection\en\NetConnection.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\Events_CostDeferred.rbs C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Network\Downloader\edbres00001.jrs C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.ni.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.AAD.BrokerPlugin_1000.15063.0.0_neutral_neutral_cw5n1h2txyewy.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppvClient\en-US\AppvClient.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Microsoft.KeyDistributionService.Cmdlets.dll C:\Program Files\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.cdxml C:\588bce7c90097ed212\1042\eula.rtf C:\588bce7c90097ed212\Graphics\Print.ico C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateUx.002.etl C:\Program Files\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Framework.1.6_1.6.24903.0_x64__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\TestDtc.psd1 C:\Program Files\WindowsPowerShell\Modules\PackageManagement\PackageManagement.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.psd1 C:\WINDOWS\system32\forfiles.exe C:\588bce7c90097ed212\netfx_Core_x86.msi C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\guest.bmp C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\WindowsUpdate\WindowsUpdate.psd1 C:\Program Files\WindowsPowerShell\Modules\PSReadline\1.1\PSReadline.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\DeploymentConfig.1.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\Microsoft.SecureBoot.Commands.xaml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.019.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetConnection\MSFT_NetConnectionProfile.cdxml c:\*.win C:\588bce7c90097ed212\1043\eula.rtf.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Management\Microsoft.PowerShell.Management.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.xaml c:\Windows\WinSxS\Temp\PendingDeletes\8049a7ccce27d30190050000240bec00.Windows.UI.winmd C:\588bce7c90097ed212\Graphics\Rotate4.ico.HOR C:\588bce7c90097ed212\RGB9RAST_x64.msi.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\Microsoft.Dtc.PowerShell.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Modules.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\en\SecureBoot.psd1 C:\Users\FD1HVy\Desktop\WARNING.html C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Modules.psd1 C:\588bce7c90097ed212\1041\LocalizedData.xml C:\Program Files\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.xaml C:\WINDOWS\System32\Wbem C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PrintManagement\MSFT_Printer_v1.0.cdxml C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Commands.Utility C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.xaml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MSFT_DtcAdvancedHostSettingTask_v1.0.cdxml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Messaging_3.2.24002.0_neutral_~_8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetQos\MSFT_NetQosPolicy.types.ps1xml C:\Users\FD1HVy\Desktop\vinfk.exe C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.xaml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.xaml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user-32.png C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\en\PKI.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Office.OneNote_2015.7668.58071.0_neutral_~_8wekyb3d8bbwe.xml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetSecurity\NetSecurity.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\SmsRouter\MessageStore\edb.log C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Network\Downloader\edb.log C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.002.etl C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.DesktopAppInstaller_1.0.10252.0_x64__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.xaml C:\588bce7c90097ed212\Graphics\Rotate8.ico C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.024.etl C:\Documents and Settings\FD1HVy\AppData\Roaming\Microsoft\MS Project\16\en-US\Global.MPT C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin64.xml C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Commands.Utility\Microsoft.PowerShell.Commands.Utility.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Network\Downloader\edbtmp.log C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.CommsPhone_1.10.15000.0_neutral_~_8wekyb3d8bbwe.xml \??\c:\Windows\WinSxS\Temp\PendingDeletes\6A0187~1.WIN C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetQos\NetQos.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\MF\Active.GRL C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\EventTracingManagement\EventTracingManagement.psd1 C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\Microsoft.PowerShell.Operation.Validation.psd1 C:\588bce7c90097ed212\Graphics\Print.ico.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppvClient\en\AppvClient.psd1 C:\588bce7c90097ed212\1033\LocalizedData.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.ODataUtils C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.ni.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Runtime.1.1_1.1.23118.0_x86__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\Microsoft.Dtc.PowerShell C:\Program Files\WindowsPowerShell\Modules\PSReadline\1.1\PSReadLine.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.psd1 C:\588bce7c90097ed212\3082\LocalizedData.xml.HOR C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\TestDtc C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\394b7b36-41b9-4032-9875-c0240ca5a7f5_withdraw.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftStickyNotes_1.4.101.0_x64__8wekyb3d8bbwe.xml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.psm1 C:\588bce7c90097ed212\Graphics\Rotate8.ico.HOR C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\PowerShell C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Runtime.1.3_1.3.23901.0_x64__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetNat\en\NetNat.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BioEnrollment_10.0.15063.0_neutral__cw5n1h2txyewy.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll C:\Program Files\WindowsPowerShell\Modules\Pester\Pester.xaml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\Microsoft.WindowsAuthenticationProtocols.Commands C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.xaml C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.xaml C:\588bce7c90097ed212\1025\eula.rtf.HOR C:\588bce7c90097ed212\1038\LocalizedData.xml.HOR C:\588bce7c90097ed212\1049\eula.rtf C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Security\PSGetModuleInfo.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\ISE C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.psm1 c:\Windows\WinSxS\Temp\PendingDeletes\9AEE73~1.WIN C:\588bce7c90097ed212\3082\LocalizedData.xml C:\588bce7c90097ed212\1053\LocalizedData.xml.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Dism\Dism.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Storage C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.dll C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\Microsoft.PowerShell.Operation.Validation.xaml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\Microsoft.SecureBoot.Commands C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.HOR C:\Program Files\WindowsPowerShell\Modules\Modules.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.xaml \??\c:\Windows\WinSxS\Temp\PendingDeletes\8049A7~2.WIN c:\*.dsk c:\Windows\WinSxS\Temp\PendingDeletes\8049a7ccce27d30192050000240bec00.Windows.Foundation.winmd C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\Microsoft.Dtc.PowerShell.psd1 C:\588bce7c90097ed212\1038\eula.rtf C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\MF\Pending.GRL C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin32.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.dll C:\588bce7c90097ed212\Strings.xml.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.cdxml C:\Program Files\WindowsPowerShell\Modules C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetworkConnectivityStatus\NetworkConnectivityStatus.psd1 C:\Program Files\WindowsPowerShell\Modules\PSReadline\1.2\PSReadLine.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Microsoft.KeyDistributionService.Cmdlets\Microsoft.KeyDistributionService.Cmdlets.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\UEV\UEV.Types.ps1xml C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.xaml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetQos\en-US\NetQos.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win64.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.008.etl C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Win32.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.009.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.cdxml C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PowerShellGet.psd1 C:\Users\FD1HVy C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\394b7b36-41b9-4032-9875-c0240ca5a7f5_show.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\Microsoft.WindowsAuthenticationProtocols.Commands\Microsoft.WindowsAuthenticationProtocols.Commands.xaml C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetNat\PSGetModuleInfo.xml C:\588bce7c90097ed212\Graphics\Rotate6.ico.HOR C:\588bce7c90097ed212\1037\eula.rtf.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PrintManagement\en-US\PrintManagement.psd1 C:\588bce7c90097ed212\netfx_Extended_x86.msi C:\588bce7c90097ed212\SplashScreen.bmp C:\Program Files (x86)\WindowsPowerShell\Modules\PackageManagement\1.0.0.1\PackageManagement.psd1 C:\Program Files (x86)\WindowsPowerShell\Modules\PackageManagement\PackageManagement.ni.dll C:\Users\FD1HVy\AppData\Roaming\Microsoft_Corporation\DefaultDomain_Path_vts5ulh4lcatsmkjq054m5tgofqeypsd\10.0.15063.0\user.config C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Archive\Microsoft.PowerShell.Archive.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetQos\en\NetQos.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.CommsPhone_1.10.15000.0_x64__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetworkTransition\NetworkTransition.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Security\Microsoft.PowerShell.Security.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\EaseOfAccessSettings2013.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Framework.1.3_1.3.24201.0_x86__8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\fffd8b5d-0172-4719-a792-b7c76986459d_show.xml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.PowerShell.Commands.Utility C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetNat\MSFT_NetNatExternalAddress.cdxml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.xaml C:\588bce7c90097ed212\1032\LocalizedData.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppvClient\AppvClient.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetQos\MSFT_NetQosPolicy.format.ps1xml C:\588bce7c90097ed212\SetupUi.xsd C:\Program Files\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.xaml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.dll C:\Users\FD1HVy\AppData\Local\Temp\LOG_DECRYPT.log C:\588bce7c90097ed212\1044\LocalizedData.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.psm1 C:\588bce7c90097ed212\Graphics\Rotate2.ico C:\588bce7c90097ed212\Graphics\Setup.ico C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.PowerShell.Security C:\Program Files\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.cdxml C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.ni.dll C:\Program Files\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.psm1 C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.PowerShell.Security\Microsoft.PowerShell.Security.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Dtc.PowerShell C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Provisioning\countrytable.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user-48.png C:\Program Files (x86)\WindowsPowerShell\Modules\Pester\Pester.psm1 C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user-192.png C:\Program Files\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.psd1 \??\c:\Windows\WinSxS\Temp\PendingDeletes\6A0187~2.WIN C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.006.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\WindowsUpdate C:\588bce7c90097ed212\1049\LocalizedData.xml C:\Program Files\WindowsPowerShell\Modules\Modules.dll C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\Microsoft.PowerShell.Operation.Validation.cdxml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Oracle\Java\installcache_x64\baseimagefam8 C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\SmsRouter\MessageStore\edbres00001.jrs C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetConnection\en-US\NetConnection.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\Microsoft.CertificateServices.PKIClient.Cmdlets.psm1 C:\588bce7c90097ed212\1043\LocalizedData.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Utility C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\en-US\MsDtc.psd1 C:\588bce7c90097ed212\1038\LocalizedData.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Microsoft.KeyDistributionService.Cmdlets\Microsoft.KeyDistributionService.Cmdlets.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\en-US\Kds.psd1 C:\588bce7c90097ed212\Extended\Parameterinfo.xml.HOR C:\588bce7c90097ed212\watermark.bmp C:\588bce7c90097ed212\1046\eula.rtf.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftOfficeHub_2017.311.255.0_neutral_~_8wekyb3d8bbwe.xml C:\Program Files (x86)\WindowsPowerShell\Modules\Modules.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.001.etl C:\Program Files (x86)\WindowsPowerShell\Modules\Modules.cdxml C:\Program Files\WindowsPowerShell\Modules\Pester\3.3.5\Pester.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.psd1 C:\Program Files\WindowsPowerShell\Modules\Pester\3.4.0\Pester.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\Microsoft.SecureBoot.Commands\Microsoft.SecureBoot.Commands.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PrintManagement\MSFT_PrinterPortTasks_v1.0.cdxml C:\588bce7c90097ed212\Client\Parameterinfo.xml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.007.etl C:\Program Files\WindowsPowerShell\Modules\PSReadline\PSReadline.ni.dll C:\ProgramData\Oracle\Java\javapath C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\Microsoft.SecureBoot.Commands\Microsoft.SecureBoot.Commands.xaml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftOfficeHub_2015.6306.23501.0_neutral_~_8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftLync2010.xml C:\588bce7c90097ed212\Graphics\Rotate6.ico C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Host\Microsoft.PowerShell.Host.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\DnsClient C:\Program Files (x86)\WindowsPowerShell\Modules\PackageManagement\PackageManagement.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.psd1 C:\588bce7c90097ed212\1031\eula.rtf.HOR C:\588bce7c90097ed212\1055\LocalizedData.xml.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\Microsoft.Dtc.PowerShell.dll C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.psd1 C:\588bce7c90097ed212\1028\LocalizedData.xml c:\Windows\WinSxS\Temp\PendingDeletes\8049a7ccce27d30191050000240bec00.Windows.Storage.winmd C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.3DBuilder_10.9.50.0_neutral_~_8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.009.etl C:\Program Files (x86)\WindowsPowerShell\Modules\Pester\Pester.xaml C:\588bce7c90097ed212\1055\eula.rtf C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\iSCSI\iSCSI.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Security\Microsoft.PowerShell.Security.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\ThemeSettings2013.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Runtime.1.6_1.6.24903.0_x86__8wekyb3d8bbwe.xml C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\Microsoft.PowerShell.Operation.Validation.psm1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.3DBuilder_13.0.10349.0_neutral_~_8wekyb3d8bbwe.xml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.ni.dll C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.xaml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftSolitaireCollection_3.14.1181.0_neutral_split.scale-125_8wekyb3d8bbwe.xml C:\588bce7c90097ed212\1025\LocalizedData.xml C:\WINDOWS\system32 C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.HOR C:\588bce7c90097ed212\Graphics\Rotate7.ico C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetSwitchTeam C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\Microsoft.SecureBoot.Commands.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetConnection c:\*.bkf C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetSwitchTeam\NetSwitchTeam.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin64.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\PSGetModuleInfo.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\en\Kds.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MSFT_DtcTransactionsTraceSettingTask_v1.0.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Security\Microsoft.PowerShell.Security.dll\Microsoft.PowerShell.Security.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.xaml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.cdxml C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PSModule.psm1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.005.etl C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\Microsoft.PowerShell.Operation.Validation.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\BitsTransfer\BitsTransfer.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Microsoft.KeyDistributionService.Cmdlets\Microsoft.KeyDistributionService.Cmdlets.xaml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.007.etl C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\9984ecc0-931c-4feb-8996-203a6ffaa852_withdraw.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.3DBuilder_13.0.10349.0_neutral_split.scale-180_8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BingNews_4.6.169.0_neutral_~_8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.006.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.xaml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PrintManagement\MSFT_Printer.types.ps1xml C:\Program Files\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2010Win64.xml C:\588bce7c90097ed212\1037\eula.rtf C:\588bce7c90097ed212\2070\eula.rtf.HOR C:\Users\FD1HVy\Documents\WindowsPowerShell\profile.ps1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Microsoft.KeyDistributionService.Cmdlets\Microsoft.KeyDistributionService.Cmdlets.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.ni.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\NetworkPrinters.xml CONOUT$ C:\Program Files\WindowsPowerShell\Modules\PackageManagement\PackageManagement.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.psm1 C:\588bce7c90097ed212\netfx_Extended_x86.msi.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftSolitaireCollection_3.14.1181.0_x64__8wekyb3d8bbwe.xml C:\Program Files\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\EventTracingManagement\MSFT_EtwTraceSession_v1.0.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TrustedPlatformModule\TrustedPlatformModule.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.DesktopAppInstaller_1.0.10252.0_neutral_split.scale-100_8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetQos C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.xaml C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation C:\Program Files\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Commands.Utility\Microsoft.PowerShell.Commands.Utility.dll \??\c:\Windows\WinSxS\Temp\PendingDeletes\328C71~1.WIN C:\Documents and Settings\FD1HVy\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\OneDrive\17.3.7294.0108\qml\QtQuick\Extras\plugins.qmltypes C:\588bce7c90097ed212\1041\LocalizedData.xml.HOR C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\1.0.1\Microsoft.PowerShell.Operation.Validation.psd1 C:\588bce7c90097ed212\1036\eula.rtf.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Microsoft.KeyDistributionService.Cmdlets.xaml c:\*.bak C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\Microsoft.CertificateServices.PKIClient.Cmdlets.dll C:\588bce7c90097ed212\SetupUi.xsd.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MSPaint_1.1702.28017.0_x64__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.psm1 C:\Program Files (x86)\WindowsPowerShell\Modules\PackageManagement\PackageManagement.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\Microsoft.SecureBoot.Commands\Microsoft.SecureBoot.Commands.ni.dll C:\Program Files\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell C:\588bce7c90097ed212\1029\eula.rtf.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\ISE\ISE.psd1 C:\588bce7c90097ed212\Extended\UiInfo.xml.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\EnvironmentsApp_10.0.15063.0_neutral__cw5n1h2txyewy.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftStickyNotes_1.4.101.0_neutral_split.scale-125_8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.011.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\Microsoft.SecureBoot.Commands.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\pki.types.ps1xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\Microsoft.WindowsAuthenticationProtocols.Commands\Microsoft.WindowsAuthenticationProtocols.Commands.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016Win32.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BingSports_4.6.169.0_neutral_~_8wekyb3d8bbwe.xml C:\Program Files (x86)\WindowsPowerShell\Modules\PackageManagement C:\Users\FD1HVy\Desktop C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.psd1 C:\588bce7c90097ed212\Graphics\Rotate1.ico C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\en\AppLocker.psd1 C:\588bce7c90097ed212\RGB9Rast_x86.msi.HOR C:\Users\FD1HVy\Documents\WindowsPowerShell\Modules C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\EventTracingManagement\en-US\EventTracingManagement.psd1 C:\Program Files (x86)\WindowsPowerShell\Modules\Modules.ni.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.ConnectivityStore_1.1509.1.0_neutral_~_8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.cdxml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.001.etl C:\588bce7c90097ed212\ParameterInfo.xml.HOR C:\Program Files\WindowsPowerShell\Modules\Pester\Pester.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Modules.cdxml C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\WindowsErrorReporting\Microsoft.WindowsErrorReporting.PowerShell.dll C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\Microsoft.PowerShell.Operation.Validation.cdxml c:\Windows\WinSxS\Temp\PendingDeletes\d8aba9ccce27d30197050000240bec00.Windows.System.winmd C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.022.etl C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2013CAWin32.xml c:\Windows\WinSxS\Temp\PendingDeletes\6a018764ce27d30101040000240bec00.Cortana.Tips.winmd C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.039.etl C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BingFinance_4.6.169.0_neutral_~_8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BingFinance_4.6.169.0_x86__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetConnection\MSFT_NetConnectionProfile.format.ps1xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.034.etl C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\iSCSI C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MSFT_DtcTransactionTask_v1.0.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetConnection\MSFT_NetConnectionProfile.types.ps1xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\ScheduledTasks C:\588bce7c90097ed212\1055\LocalizedData.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.AccountsControl_10.0.15063.447_neutral__cw5n1h2txyewy.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\Microsoft.SecureBoot.Commands\Microsoft.SecureBoot.Commands.dll C:\Program Files\WindowsPowerShell\Modules\Modules.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.xaml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Office.OneNote_2015.6131.10051.0_neutral_~_8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Microsoft.KeyDistributionService.Cmdlets.psm1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin32.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Office365Win32.xml C:\588bce7c90097ed212\Extended\UiInfo.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Getstarted_4.5.6.0_neutral_~_8wekyb3d8bbwe.xml c:\Windows\WinSxS\Temp\PendingDeletes\328C71~1.WIN C:\Program Files (x86)\WindowsPowerShell\Modules\Modules.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\PSGetModuleInfo.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\Microsoft.WindowsAuthenticationProtocols.Commands.psd1 c:\Windows\WinSxS\Temp\PendingDeletes\6A0187~2.WIN C:\588bce7c90097ed212\1036\LocalizedData.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\DeploymentConfig.0.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user.bmp C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftSolitaireCollection_3.3.9211.0_neutral_split.scale-100_8wekyb3d8bbwe.xml C:\Program Files\WindowsPowerShell\Modules\Modules.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\PSGetModuleInfo.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.cdxml c:\Windows\WinSxS\Temp\PendingDeletes\6A0187~1.WIN c:\*.set C:\588bce7c90097ed212\2052\eula.rtf C:\Program Files\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.psd1 C:\588bce7c90097ed212\1046\eula.rtf C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin64.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BingWeather_4.6.169.0_neutral_~_8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\en\International.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetNat\MSFT_NetNatSession.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\PSGetModuleInfo.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Network\Downloader\qmgr.jfm C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin32.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\BranchCache\BranchCache.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\DesktopSettings2013.xml C:\Program Files\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands C:\Users\FD1HVy\AppData\Local\Temp\LIST_ENCRYPTED_FILE.txt C:\588bce7c90097ed212\header.bmp.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.031.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Security\en-US\Microsoft.PowerShell.Security.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_33d770d0-06bc-47c5-8714-222cdac43a71 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\en-US\AppLocker.psd1 C:\588bce7c90097ed212\UiInfo.xml.HOR C:\588bce7c90097ed212\1045\eula.rtf C:\588bce7c90097ed212\1037\LocalizedData.xml C:\588bce7c90097ed212\Graphics\warn.ico.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\PSGetModuleInfo.xml C:\Program Files\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\EventTracingManagement\MSFT_EtwTraceProvider_v1.0.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.dll C:\588bce7c90097ed212\1046\LocalizedData.xml C:\Program Files (x86)\WindowsPowerShell\Modules\Pester C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.dll c:\Windows\WinSxS\Temp\PendingDeletes\80281F~1.WIN C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftInternetExplorer2013.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BingWeather_4.18.56.0_neutral_split.scale-150_8wekyb3d8bbwe.xml C:\588bce7c90097ed212\netfx_Extended.mzz C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftSkypeForBusiness2016Win32.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.NET.Native.Framework.1.1_1.0.23115.0_x64__8wekyb3d8bbwe.xml C:\588bce7c90097ed212\Graphics\SysReqMet.ico.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\Microsoft.CertificateServices.PKIClient.Cmdlets.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\Microsoft.Dtc.PowerShell.psm1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.033.etl C:\Program Files (x86)\WindowsPowerShell\Modules\Modules.xaml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.MicrosoftStickyNotes_1.4.101.0_neutral_~_8wekyb3d8bbwe.xml C:\Program Files\WindowsPowerShell\Modules\PackageManagement C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\PSGetModuleInfo.xml C:\588bce7c90097ed212\2052\eula.rtf.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\Microsoft.CertificateServices.PKIClient.Cmdlets.xaml C:\Program Files (x86)\WindowsPowerShell\Modules\PackageManagement\PackageManagement.xaml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Appconnector_1.3.3.0_neutral__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.psd1 C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\Microsoft.PowerShell.Operation.Validation.psd1 C:\588bce7c90097ed212\netfx_Core_x64.msi C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\Microsoft.Dtc.PowerShell.xaml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.014.etl C:\588bce7c90097ed212\Graphics\Rotate5.ico.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\Microsoft.CertificateServices.PKIClient.Cmdlets.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\SmsRouter\MessageStore\edbtmp.log C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\EventTracingManagement C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\WindowsErrorReporting\WindowsErrorReporting.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\WindowsErrorReporting\WindowsErrorReporting.psm1 C:\Program Files\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetQos\PSGetModuleInfo.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.cdxml C:\588bce7c90097ed212\1040\eula.rtf C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\Microsoft.PowerShell.Operation.Validation.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.dll C:\588bce7c90097ed212\2070\eula.rtf C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.psm1 C:\588bce7c90097ed212\DisplayIcon.ico.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\AppLocker.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftWordpad.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Microsoft3DViewer_1.1702.21039.0_x64__8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TLS\Microsoft.WindowsAuthenticationProtocols.Commands.cdxml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\HoloCamera_1.0.0.5_neutral__cw5n1h2txyewy.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\03d1e1da-f580-45d7-afdd-3598ed7cdba4_show.xml c:\*.bac C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PnpDevice\PnpDevice.psd1 C:\WINDOWS\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.032.etl C:\588bce7c90097ed212\1029\LocalizedData.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Security C:\Program Files\WindowsPowerShell\Modules\PSReadline\PSReadline.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PrintManagement\PrintManagement.psd1 C:\Users\FD1HVy\AppData\Local\Temp\LIST_DECRYPTED_FILE.txt C:\588bce7c90097ed212\1045\LocalizedData.xml C:\588bce7c90097ed212\Graphics\Rotate3.ico.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Crypto\SystemKeys\d20d9e7d1dcddc105a0d5e00d5e1ad30_33d770d0-06bc-47c5-8714-222cdac43a71 C:\Program Files\WindowsPowerShell\Modules\PSReadline C:\Program Files\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.cdxml C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation C:\588bce7c90097ed212\1032\LocalizedData.xml.HOR C:\588bce7c90097ed212\Graphics\Rotate5.ico C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016Win64.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MSFT_DtcDefaultTask_v1.0.cdxml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Utility\PSGetModuleInfo.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\Microsoft.InternationalSettings.Commands.xaml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.cdxml C:\588bce7c90097ed212\1044\LocalizedData.xml.HOR C:\588bce7c90097ed212\1046\LocalizedData.xml.HOR C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.004.etl C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\EventTracingManagement\EventTracingManagement.Types.ps1xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.LockApp_10.0.15063.0_neutral__cw5n1h2txyewy.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.ConnectivityStore_1.1509.1.0_x64__8wekyb3d8bbwe.xml C:\588bce7c90097ed212\Graphics\warn.ico C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Utility\Microsoft.PowerShell.Utility.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MsDtc\MSFT_DtcTransactionsStatisticsTask_v1.0.cdxml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user.png C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PrintManagement\PSGetModuleInfo.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SecureBoot\SecureBoot.psd1 \??\c:\Windows\WinSxS\Temp\PendingDeletes\8049A7~4.WIN C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Appx C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.3DBuilder_13.0.10349.0_x64__8wekyb3d8bbwe.xml C:\Users\FD1HVy\AppData\Local\Temp\ C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppLocker\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Security\en\Microsoft.PowerShell.Security.psd1 C:\588bce7c90097ed212\1028\eula.rtf C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\SoftLanding\acae4208-0ac4-4ef7-ac45-bb688b09e559_withdraw.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetNat\MSFT_NetNat.Types.ps1xml C:\Program Files\WindowsPowerShell\Modules\PSReadline\1.2\PSReadline.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\Microsoft.InternationalSettings.Commands.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.BingNews_4.6.169.0_neutral_split.scale-200_8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.psm1 C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Security\Microsoft.PowerShell.Security.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Messaging_1.10.22012.0_neutral_~_8wekyb3d8bbwe.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetAdapter\NetAdapter.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\AppRepository\Microsoft.Getstarted_4.5.6.0_neutral_split.scale-200_8wekyb3d8bbwe.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.015.etl C:\588bce7c90097ed212\2070\LocalizedData.xml.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.ODataUtils\Microsoft.PowerShell.ODataUtils.psd1 C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\1.0.1\Microsoft.PowerShell.Operation.Validation.psd1 C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PowerShellGet.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.WSMan.Management C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Utility\en\Microsoft.PowerShell.Utility.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\RoamingCredentialSettings.xml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user-40.png C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.HOR C:\Program Files\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Utility\Microsoft.PowerShell.Commands.Utility.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\MSMQ C:\Program Files\WindowsPowerShell\Modules\Microsoft.Dtc.PowerShell\Microsoft.Dtc.PowerShell.cdxml c:\Windows\WinSxS\Temp\PendingDeletes\8049A7~3.WIN C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Archive C:\Program Files (x86)\WindowsPowerShell\Modules\Pester\Pester.psd1 C:\588bce7c90097ed212\Graphics\SysReqMet.ico C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.cdxml C:\Program Files\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.xaml C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.005.etl C:\Program Files (x86)\WindowsPowerShell\Modules\Pester\3.3.5\Pester.psm1 C:\588bce7c90097ed212\1031\LocalizedData.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Kds\Microsoft.KeyDistributionService.Cmdlets.cdxml C:\ \??\c:\Windows\WinSxS\Temp\PendingDeletes\D8ABA9~3.WIN C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\CimCmdlets\CimCmdlets.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\NetAdapter C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Diagnostics\Microsoft.PowerShell.Diagnostics.psd1 C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.psm1 c:\*.wbcat C:\Program Files\WindowsPowerShell\Modules\Microsoft.PowerShell.Operation.Validation\Microsoft.PowerShell.Operation.Validation.xaml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\en-US\TroubleshootingPack.psd1 C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\MF\Pending.GRL C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\DeploymentConfig.2.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Modules.xaml C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PSModule.psm1 C:\Program Files (x86)\WindowsPowerShell\Modules\Microsoft.Windows.Diagnosis.TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Modules.ni.dll C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\NotificationUxBroker.012.etl C:\588bce7c90097ed212\netfx_Core.mzz.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\EventTracingManagement\MSFT_AutologgerConfig_v1.0.format.ps1xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\PKI\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.xaml C:\588bce7c90097ed212\1044\eula.rtf C:\588bce7c90097ed212\Client\Parameterinfo.xml.HOR C:\Program Files\WindowsPowerShell\Modules\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\Microsoft.Windows.Diagnosis.TroubleshootingPack.xaml C:\588bce7c90097ed212\1035\LocalizedData.xml.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\TroubleshootingPack.psd1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TroubleshootingPack\PSGetModuleInfo.xml C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\TrustedPlatformModule c:\Windows\WinSxS\Temp\PendingDeletes\8049A7~4.WIN c:\Windows\WinSxS\Temp\PendingDeletes\328c7164ce27d301d7030000240bec00.Cortana.SPA.winmd C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppvClient C:\588bce7c90097ed212\netfx_Core_x86.msi.HOR C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\ScheduledTasks\ScheduledTasks.psd1 C:\Users\FD1HVy\AppData\Local\Temp\meme.jpg c:\Windows\WinSxS\Temp\PendingDeletes\8049A7~2.WIN C:\Program Files\WindowsPowerShell\Modules\Microsoft.CertificateServices.PKIClient.Cmdlets\Microsoft.CertificateServices.PKIClient.Cmdlets.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\AppvClient\AppVClientCmdlets.psm1 C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.ni.dll C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.InternationalSettings.Commands C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\International\Microsoft.InternationalSettings.Commands\Microsoft.InternationalSettings.Commands.psd1 MD5 hashes: 302b4e2f66b097d90d53e1049b7e1c8c 76d7084bded924e03df722a843e979b0 f8aa26b5190881d6f4ef88930b2c735e 3121422ec0b9a9c43a0c54466af364df 8f37cfd0467636c27478c8e52b248d8a 60e11a5a0f0e847348eebe151d698fdd 487e6b759f51c0786e5965fc75b95317 1a22dbef4ef8fb92d3714644afc21b64 75550388b6ed10ff6ad8ffd73d2e90f8 91651600f71c1052793f0b4ddb266bc5 f770602d1562f706ad30325b18e4c720 616c452d4485316ddf930d18179baebd 7f5dcf41334fcdfa063df8a08aa57c8c c4ca4238a0b923820dcc509a6f75849b f4d788b106b16fc0f7445a1e9edb3206 03c62def47477ee0e4d7e2587f705a05 2b0ff23c6ef529d694c2ee0dc4f5d853 c3e88146a3e870e57e262cf28484f151 3258db9b3c712894294cf928b4e2e048 0870a77b65fda52107d649799109eecd 92f7c8fc1d201c90881134d1200bbf1a 66dc749d5f6988c387606c74f87c07c1 660ec542133ffaa17145fb37ff8a2c6f 7ac5d5139b47c4e27ab71ed574594807 6f16f4f2fb7a661d5c4cccec84bc036f 5cc56e4e86fb5740b461ed84f79e4885 d435e93046725421c276fc02fb21772b 413dac29e806af3692174f289fa80d10 0fbfc32ffed569f83b0d1d65d5255106 d35e7ef95898ae042c53d4996478bbc1 9267c359c9a8150d4a8dc71c0d379793 fbb1ea0283f6d513f5f34ab922fe58e9 544ea4a9d3e0af17ae583ff36e19a81f f9b48a8ec49fc42de39ab73557aaab98 8d1314d8d754fc5254677a2b4f958815 f7a48e29bb899e181750e3012672e6c1 722f6bd124d715d3c7811541612aa9b9 cef3a78a3275a8bb4a11f1c3be86fbc7 b3fec13e169f1924ed8643ab054c26a5 37363f08ef5ad1a1a325c6f3f22964c9 b85cfc77d09a3bb9a6c2edf9d6871071 7c662c9109efa5a5cc8d0146d6e36f02 9aa8a19ebe09603a2de27556a0bb01ba e8a6fb3f33418867c10a65228b76679d f1b05c72e5e265b3c5aab71cc350d6f1 da6d1a7935ea6e11ee98030fff1aea62 1fefc791edc999af9b11a1bf3af5712e 4b29e25f45969171695c552b7471ff58 bc95e5c6dfbbaf67001ddddab9ae3db2 7ef58db100b4768866b84ed43f37927c a48b994a4695245872413bc48d09f665 95f757832234a0ada6bb764ebafe502e 4bc86338d7321b3a05fe1088ca5b0df2 74e80fd45f11baae8f411fa648692afc b5bf30dd69fd3628b629e1b461b63fcd c38463f6334cd230a5d50b66a55408d5 27ebb7e54f83bb6bcb8ec1d0a0dbd0ab c6dd9b11dbf280a68d3e8895e4c5e084 9cf265d0e94437f0f002cedfabb6de2e 5aea9a6dea77e7df2d834a8207ed6f62 fba04722a9ea05db2cc68da1a15d34bc a219cbfc6848e6524de673b8f98f0ce1 7f9188b9db818533b91d66340ae1ab21 0c5f93743ae3acbdcc9469e24296a208 fdc3a74c4f413bf57a8dda4c0b4684a0 6b795c3d450953374c7e6574134aff88 fa7cd5477ca3bfa388a1eca38fb020a0 8c7e622016b9f31c8d291d36b686c422 3f6481d37267e573b96c9a78075c7c09 aeb8b87a9a6ef6de67cc250244f08ea4 be660f7a74a3e3fdfff2e32bf2d7ecb1 956090ecfd9dc1986e4ae0afd782c1d3 6d7d8a103c520d58f2ced91b1f0d41bc 1556036b8dd58341246b512f9db6e644 1c4ed84c466e25c6473e24bea15e62cf e60a0874f477b7a1a15b61e1beae0628 1b0ce790e3863ade27a564fbef602b67 6c585194d08e187392ede73e204b62ee e3d71d1355f4d2090c6ba3ccba25a898 158442dcd91cf1456b30db104a97fd94 8458e3e1554b6a01b6b3335fa74f0f97 1ed32b2bea82e376b5c50e890eb06c3d 4f78f037a799a003be2140dd26cd1341 e393557fbf857b031f710b88dd19cac7 cf1a8733a64bc73f1dbf66ec939818df 45fd7d39ced63dc7580d1e5395a2327d 7dd8548f26709d7802a78fc210e18310 fdb5293e4ad30be1e0123fdf1665ea9c 53dc82a657e1ad1f83ebe299b9d6dbdd b8c984018e322d19876f428f9498af0d d2f7986dca76ddb03a63df1c8d2824ad 5412920d13d41abada82c1c5bea310ce c2e6c730a4096ba074a463eeda33f36f 9b0c5a18b4c78265d501d849c86cbbfd 88faaf0e39d90740dca45d3a6cfbaf6b SHA1 hashes: bf208e445d618c2958183433c45a10303c959409 6ad808bfcbc210e79b74fa87cb02636777f31dda 7ee13a884dc98a9ec2c599b6dcaede27257de00a b82555bba9594a1648238a508a2f4d9afb588215 c8d2b7fcbd90760b155f5ba45b312373a7444c80 a90c6166adda836c8cfe72a962d36bd07e0da2e5 b113deee7f5882b716e076185cc7ff5d661719f7 c670752abd2fdfdcd17f22a4926063c8ada47a45 d2264028baccf2ccaabcdf1bd587c1e1f6796e27 79ce609a30ebad26f9f49694c112d55ac7fe7674 27fa541a943d6158676e6975737254ad96bc98a6 e92a143daa02fb417240fd17e9fdb458e6c103c9 3f5a563f68fc545f2a0986bb8f0a1a20544ece81 759b17a9f020cd9bb2e2d3a2ef0ef53cd1a0660c 5490250a0b14ad46933cd8766e5dafe0ad0de14f ba9e6731fdf38d83e42b38bd5820eb50b20b4697 bc2e89a0e49f56db6c37176a739b5c42bb2b4a8f 5e8e3303af84e2dc71897d3aa1c8b30ce94c98e1 cdf43db6c5caeff803e5aa92def28e6ed4b3b344 d32497d9833d5cc21dc7ee9b8a260daa7fd2a52d 21ed6585190a81c6761fb5d03baf72352783e323 bfe31deeb492fd46af3095af68c352ddac906ff8 ecb319dc4488c632e64132a04b7f9541bfdbb829 7aee38897abcc74aee0d4f7695b2a53ece8d3f42 08c9c6315e3eec7267d4a53ab5c889bdc2f513da 26b26cead7196c0b4eeccfc1a8fdafd78b317b3d 221a7b5c4601815e9b1277f2dfd8428289f7c779 80128a1cb54a8acce1f38a4e7ea61bc7e4ed3488 aa36e00e90914ca28bee3aceadfcfe5e18be23b7 3a56e83bf4e86c19abacade3f107da3944c95476 6e5a64c5b84cc68c156111a3550ef779287afd44 1effd67c808cf2c32d8a98e60a542eb4833ba90e 3c51f3ff70d426d6edf3e982f63d47b475030c96 5d8a60db1ba1cc67b056bd9a45c6a188ed01c4a6 1885639b0632209cb014cbd9424bc2abaf82d504 102a5398314bd1ca30725d63b25ab38634f5fdc9 390fd09ea08280cd4cbb1f51416fc1fce4825632 890fe1fab952f48289c84fafb902077913ac22de 356a192b7913b04c54574d18c28d46e6395428ab 69b68db2616043aeea5a9d1a0c99b5370b92297c 5ea2cb506aa0414e509b49ad61db7b163a7f1615 3015be71603f48c12f20c2a28fcb711bec0a9aea 562e7382ca8a434260ec2bd6dc995516147d4fcf 47db778c69a2fe52e698b8c4c843c498d7cf9f91 bbd08a7d7fa1d23dce3ce97d45926ca469b6ddd7 735f72f260da112085b69c6750715849fbff8210 3825ea77ce16a046f8f5196c0d36c59bae788169 fb6102834454124e80e36c7991915b00211bd7ef a0b17aae8b1a0d1d50a88f0222f9b01b834e3bf6 b41ff54cc6dbecef6eb408523f26c52bd1e6d29c c0f20293d6a4472caabcef5c4a2f1738399f7263 70bb1b53d77a895100fca0eea37541ab5e490496 ac2e44bd9e680506af8370992ccad0b52c4f15a9 2365b6677844d3c1d0e35e505d5d3bb8bc601684 87c4fc33db8d8fefa9db7603adea8117e26f9b84 8f9244412d1f7310ab9288a160825f10952a4790 53f299087968a9ef4d3618433564cffce49e2e8a 9ddc15736a2c57b168b273cb7715b6c32cd1c9d4 37aa0677773e23083eed2a48b3fa92813f6cbcec 65bfc925239b99333dd2ade2dee4b392972f6554 559adc984deb13125697b8ef00bf2957daad9aec 230aa8c348dcfa88698d2aaaae694d623c19b76b 5ec34ab670145b7d4e0a60562bd3bde6620bcdce 1de186c6f6c26979e7acdd8a7db318078743b702 1e7b2a63f955b959dc6006d6918fbceaaad02742 5c13de72804e496461629d624a06f7dafba7b428 f5d08173660c9ff0a1673083472f741f8f481828 cf3c7e69957520887d9c407497d62543787ce85c 818818031713dfc50a5afaeb226b6e7667f4e050 18f0218334e96fceddbdda24199afc1af6a948a3 0c24359320113ce9b68d8e08f98d6de6f423c1fe 2d6367cb3acdaad656968a8e518a657ca701f9da 1af92ba770e31aada4fae9dd11a0ca60e3402d73 efc332453b0d87630b2fde4be3e69ff2af7571bc 316f235663c23e34c48169c7cec8b8de72503c41 f2aedc38b88a5435bfb464e4ba67f9d120670636 f84076383b42389371f724a23bdcfd35ad7b1b0f 96663da3f511e84b08104ec8e3aeba7b6e21c210 e382f5c0719ebfcb9bc1f39f251dbcbb3b1f6ffd c5fabd623aebcd217c13f8825cdc5dae9a65ff4b d8d1147ae0956c28fcfaa5db5b02ed93a51bbdd1 d5a5dc0ca5801455100010218c6eef38b060a9c3 72e72350bc0acbcc1430676d748aae546516ba3e 046274779506c52d59b1e1164f6e3f9303e20eb9 c5589ec6ca8dceed0890772e6c946fbe1ebcf617 2ee2d5febae8a87835897833b17a5f45e47061c7 8bba4b47afcab7dc5301074591022455a10c0b7b 516d8bba367873c710fb8938f40d001e182d3e61 f073c213595f8f8e9c06474b41341634c9e9eb08 8517227d4fb6fb7ce9a089649a6798f6c026a0cf 584e441ca2ac02aa4594305348652a4fc7dd531b 8d9c8afe4076179fdddf33dfdfe164c6a98f7bd9 5cfd3ac3102a8deb001c35763b817c359c64eae7 909ec0d9e4f8816d3ad91abbb57bf12fcb3625cb a990fb3b06c428936a5dd0a0e948cc43a50d4663 SHA256 hashes: 021ce66a52dcc9f105ddf69f84d2c099ef416a2cd55208631fca7ce04338d4d6 0c39a6e87de05131ff5d0b9fce73237bf3eb0aeacd9d765ef934e824fc8ad0f1 74ed257805a4bd495c7f03340142c0364430ad4e3c23e257b387af3e1c638291 1fdd3f38555d2223957a042864bd02c1f8809a3d3213637ca304f36ff60220a5 e8557901e0bc547da27b692b73139e18fe6a7ce28a409d86f96fbda117901cf3 91f3cb7805e90879f7d227f06d2751e620b1604f9fa32ec191557745e2181930 d64e419a802edc06ae38ac10d4a42348c256690945c6e76509462ff78d7f0dc5 c680a17170c808bfe654e21c68f647d911d6738278b542547d52cf71109c73f9 a86864b8dbbea7d211db4eeafe4b0683cb45f99a12c622e5e6b93ba6c9d2bd54 aec6c828d3e9ce50879eb2b9b47076cb4ba4fcdc0b343f27f7f08db06f78d6a1 0bacb62a18ae834bb5f9e5e9adeaf2dd5bfa3603f03b1b3aafd72c6debb49e9c f0dfe13e9d9b4f110c738bee80db8c0168d9018fa342e141b5080c6dce611a25 a97fc919b8dd8bea320a91d6a1e63ece6fdaeb1c740755ff9f01bfe9d407c181 919a5b93b4799ed094cb2f340f07504e793df782b7411f8102f9fa431a7e4bbd 9e39325922a92e728dd34582fdd21cb3d33e5abd8dd08d7a85727804330eefde 1b911bf7160d5980c6b204700027bb4249026493cda02fc633446346d10838a2 fee2240291c48d5e6e026705cd488aa5c5acd8193b062b7a68b8bfa0020181e9 71f5105e4eea690f884b117b37bced8735d9191f9aa41ab19407363abc7002be 5a39d2fda1065a24454364ee032443dbef809a2ddb99bad04322de2721c0431c 53c90f23971d28d8317e2be3ca87074540cc59cf3feffbc5d8c1538935c22ea6 98f5ba35378b23156d693d828241464744d88fab19a9715c15caf30912a2d496 2ba5baee2fe256994f33693f60459c3521245f853ca19f0fce43e722be876df6 23dc5c711d2051b878cad4fda56d1b24a23a964ff04be617371e82318c647392 515e4aeccfa2d4dbccf40a52567e42fbda1e9f261253fa5277fa5db7623c6240 d9b781908b5122611f16cdfaa7656331b4ffc4a2b6fa0a8d413cb63ae1b6efa7 55dfef1f9b8c9c5c7cc47f47843a9c2c15b72a0c68879a5b6a2eef7feef87d80 70dc582efda86fb1c59ec881144379a0bbd3de4ba6a50e301e166f3fb718a367 2fcd6401e4fbe60a299ea421f1f31b73f311409cec9fb8c9dadb4456b8c61cf3 8204a098c4210ff505eefc71e2504c8c232d5ad42830808bc1ab932cbc71910d 39ad1521de0c98b5037006c868597c57855a721c0bfb6a990355d54e72df7fbc 0163aa477bb76acdbadb00ae29ea9c1c21d79a42c4f6233e49d811797b5728ba 76691aedf595080a82adf64afa37f0c634e0ac41358fb07edc2e77cb40f7f8dc d2c046700a9f7fab5560b23f0a2f21695180e92517cb4c7fae70fd1f87e93658 5cf2e68ea99543885b53989073b9a5726e9639905316aabdc3725e496d953f2a cb921359fd9e6e955f15099ea7329c4bc4ea9fc4744e64ad7a040061a30e5411 58e786c9961073423f4fadf797865e099e145c5ea94ed183602761d89c03e5e9 ce6a38d7b97c9c42eb903a1c7a6525733350a02c09b68562aaaf1478ee7d0dff 0d66c22ea317b2aba67b82966c981c472704a427b5e31e1b794c2accf9276867 4b559508615f95a2c090715532a1c1045b596a09956a470ff76321f9eebe7e81 901ada99863da100cf6b3d45a70e94182b7af9295c10819aa905441d1a79c683 850ef62aa38cfc03d0295fa8289778adbdb17dd9af3cb0511b25dbf299ad4581 0f4e32c2433db542f80c2f087c53d8a9bf5d9bf095142a928fc0dea707d2a207 51e9d5c2469016b34996eedbc087679aff8d4c11e8388a0c91c7a67579702271 5f348baf390ae11d505e6e144f860154c0d9c15b192e35807cc75de638ba90ad 460628de066938713485bc785a9304c4469369bdc5803055960b83af0ea9d7e0 b802c99e12075f5ec8a1ce5b269389fdb614753badc4a2f7530a87273da74650 b01e46aeec06ca08ad12f6ddf3b45ccb9623cd0b69c583fbfbab84f05f427c5b 7bdc7f2aff0ec0804b5df65b6c666b31b317f679a022ad29c1e125138a964283 fa3e99f104110dcbff37114dc9c90ead17a9ae27bcc7fe7351bbe2d66f4a0c83 ff03a9b65edf539414d1b5f32d6d611329b48f4b12b39fb7cff71885166624ea 907fd2e29f66a17d5f29edb389232bf213c60907579914e1871c9d3751ea9ab4 9043e1f4df2c1bc09c2f0710792d780a4e91be6e474804fd626545bc0f049f21 28f1c089a3f01370d5ab8fd99406b82b6b31ea88c1db4e33e9c1e0afb8dbc046 77764f04f3a43734b04393eb234cc6c658ce4d0f8fdfb781d62d023c48ada21e 3042907b80f0f9810c20231ec279834e6d22f22b43de08bfb47a9b0fa7c9097a 3e3cd5c2a1f5e306695656fa80a1ea42755771ea670ef80266969e59e9088bd9 72652f5bceb85afc4bfa877ef12d6a8c427cbc9db8789a1eb7f7629f1bde9689 8fc993bc214dfab7cd6eeb06812727200dc7e263a91bee00987cedbc4ea4440f 80c656a43352356d23d915f4f11170f98c925a7c16820c0da7dfffa34ea8c918 7c3b53d1305b3ff6801ef133badae5d86ac96c51d4b3357d694bdcdbd152d00d ce007c35d9ba6d567359f725e434026e45a795c6c131c7a587577c17d53ac22f a4e6e6e52e8a7b47e150aebef90fd43a6eac08d4cfb5eebb1e7e0a6b35ab2ec3 a1342981c80d2db7319d0eff24462f899969b2a3a497eb3112ef897777e62a22 8cb5013191ba4bdff463aa13167df061685c67a5bc43660d84282de68b1196e1 22cc01edec97d205e0422080a5c54bf705b3c776c4d9add4b6504761fb8b4cb2 09a0857139490a8fd88cdf2415d3f95a518c8754d7a10d5c236b2babeb278abd 9ee375c994a5498a8b065db625900f0d6dae3610005186dd7ec87c03afaff56e f9bb1ff96463325abb838ac44d22db1d9c43cfa3c470896817109cfff2877568 113c92322b0e8feb0813fbf33e901ec586946cec0982db1822d0611ff9e24d80 6b86b273ff34fce19d6b804eff5a3f5747ada4eaa22f1d49c01e52ddb7875b4b 8a199c5dbbe657a7628752072920899a7ccf9e76c519c73a6e26985890183fa5 71924ea8601698d61ac033bfe2c4407043c4b76cbeef33f890b647c32a2e98cc b88e12acba3e9707ed63a77d177cdc0300f46304f8fcccd97608cf163fbce246 096b362c2539ab6beef1dbb8c8e6f75942ca26770fe31476e025832221642c15 d079a0bb2f0d88522908138a36992978f580a3a89aeb8b952e657a773c41ec7f 4444458bf47925c82431843fd147aabbfbee71ca849fc711cb69b0cea01f4747 3676959ff934dc43acb87f71b450460c624ac129f8b278851b044fb694d50d25 b9edcec5810168755e93c9cbddd429f2ed0daaa3fe23d58fb7d23c7d159601d4 a68e0cadba7dbb3beff105e843af9c2e29693fe9a529293db38e80b9f6787d63 a848a14f4418a15b9acb8de546c01d5f004aea892a5be1a77728f75684206f11 0bdf933c77b484a52948ebf4420076dc1a5bc4523b81067a0183263b89a242e8 12c92da57f21fb79993a29b9376aa22a091f7889031af9d143c1b83a09f3d931 731829fc2d6af210509910be8145ca4472a1dc03714050ebca7c10e288c3c1ec 8958a96f26bb28c9310f9ff8bded49e8f99375595468fe643fee1fb87ed84acb f928dc1fe1993606459b7238ca3cc8979c31d008d992a00e120f8c6e0ce38160 f68efb99f0a16cab13439b3c84b155e086789cca1a6f53e29c9c393e2efc1d11 3ba073ae8982efba6888a89530d23a3960055945ed896876cfe274a8c158cee8 73e04cec39f65002d722aafee7af039e7c7b4833e943346eacb5e81d2356557b 9764631a551efce115ab04301d59c15547926bfae27df43dcfed4edbcb9b10a0 648166c8eb816dd2540f1e29395c8e04c3eb0e547811f52f8ed5640bfceeefdd fe2e832e922d9d39312d75f3336e3d2e80fddff21f4a3976787695f3d1da35ea d726474ea84650ad669b7e236afaff44818d21bb2ab1ecbd7b75c23cecc6a19b 3a6aa39e287d7bc2dfcc15897f38d5bd13210f13bd6624b9ea74219e9db9c552 26f561fa487a1e68db87abaf3591c7264ddd641a8dd06bbdcf6c2a65761a78c6 a90a3221075f44105442e875d210f41a25f6c5cdf41293f050c595e7e3c7b9a2 SSDEEP hashes: 96:Zddqvo97Cy5TskY4ciBaPXdvHWDyh1FZ0jy:rdqQPy2fuHWI1FZUy 1536:d8WtXAyNorbKiEhEQS5LizqpIpNXTGQWGMUULltRvK6PBKhCKePg4cTc:yWFNO+iEql5ubCQW0ERvK6oOPgY 1536:vfLXfN+YZmwDcklPrUgBznHicqi9ZdE1Ytjfan1bwCLPN+b:XLF+Y8wDHTBzH3hZdMYAneCLPU 24:XanA4p10UPFoiHuXltrbntuW/ESEAmuky5OdURp:Xan50p4uVVtsw+y5OUp 192:3FXOw17SmczPtA2Gx4GeaYiiqvag8mOoA7k2gPaDJCVHfLEfxHXkDvTNDQWdnmNZ:39TozPtKg7qvr01k2gMJCiJHXwNDTNY 24:XaVSONApFtI6OTXERwNsLAWz1S+pMfBzfj/01yI5G:Xa0AvwL1Hp2r8AP 24:QjsDvCCJ32yT1w9j7Wnef2bGCK+SYMnj4z0adiUZCn:BDK0BwB7Bf7C12jgAU8n 1536:MwRM+yz4jxGKEe/VpCNYiUlCe1v7Ondy8CnZhSKWOJDSy+2z9sG2YDMdQPssIfYX:MwRM+nj4KExElxJOd27S8+z2Rl2YDWpc 24:XavAiWsT2OmNzutm2tOGU8+oFqdQOhd1mWXKlGRdHZ9I/OivhKeFkVGF:XavtLYGA8+wqRhd1mzlGRPsOi5KzVGF 192:jRN0qOBVh6DfEb+0ZBo+GmWnXZKy2WGfNhHtynh5E4K3u6mHC:jX0qih6gb+0ZBPGfXZpZSH8nh5E4N64C 24576:QUcqzhl6lYvhhGSxDimoZTGUxG0B/JRQwyB2I7HZ:QUcMb62pDifZ9xGyxQ2kHZ 24:QjsDvCCJ2D/jwyyiabGM2Cgt/aXeY93nqsdS:BDK087wHzbGFCU/aXT93nqkS 768:3m7lcw8PL7NeO1w7H6l5HfEks18XwHgXoLbBJk0x0A9ly8e3nutfDp:Zw8FFu7HqEd8XZoL4A9lPe30Dp 96:dgDK3hC1u0k6wE89kB/3EOJDXJA34bn75b:uqLE86B/UI04DV 1536:oQtfMYTKAiUeDk0wR9YpVPzLO5AkoLjgi0Rn1A:3kYm3vkYpNzS0LjIe 768:DRl8Oly1zJRyzR4O/PfXXg0SSTRusOegwmG6r/yZ:bly1dRyzPPfX2WRJ8G6jyZ 3072:fc0Aq7L2Q/orXJpwmANdmsCI+sIaBA0ccFQOJ7veUD9OQapIxkG/J9GZn:fcimQ/obJWmAmG+naBofOJ7veUD9iakR 96:t+tFyWu5o8naO0CxLtDTfM/G7wn7YEv+DnfVvD+0msPQOPrR5n:twu5ozO0CJtnfMu7w7YEGD9vD3msoYV5 768:LRWkURAZJPvXREA5Iz3jhd0n0JaPq9k0J0X3UhL0:LLUuZJPJEpHT08V9vJY3UhI 3:hl3VSi4H1Tpn:XQvH1t 768:zblYZUAMsW0oOciI5vNG70+kov1LBpLsvnaMPtkB8Sm2oDT7J8g:6MsW0oOciB3kolLsyUkB8NF9 96:HF4501IQ6iPbEgTccycxVyMZ87RNpSdHlQvrS7UluUOo0j8g:HF45jQ6iPg6fyxJS7Uszo0j8g 24576:zPeqIngEw2Ih+0IhQj3fi87cX9JhLqCeLG262j3I8kWcF:zmqIIhOKjviZXICwG23j3VQ 96:oHptjU/hFCI5HT/fGX7rbw0uE5ktiebZNvMTfF:oJtjiCWTfGX01XtienvKF 1536:L3Pf0q0XXPoGejoXvRsPnDV/7e8NymGK1f+MfJW9bIcqYOin7a3+:L36XXkjyROnV7eyT1j8rO+7au 192:2MarI1sRZQaaSZ/vmlR1zCqOUvEbQGAopqHS9rxEy1MsOOhB:FsI+TQNkvq1FvE/T99fM9Or 768:0EAIQfRPjWiOxTtqlpsYeqYJvWUGcIaU+BIcuoVJ419YFU/V13lKkpehh:0nI4JjmkOvWa1U+Puog3v2h 24:QjsDvCCJWLmAOoitdz7uyrogVRhtPWdVu2fgSE7ZXZNEHz:BDK0WLmAOoitxProgVR+dVu24DZK 49152:iUJS8Hcge/+pmxPlLkSBn9tWr1YphQd6+epjpLoAUZUyylB:DSJ+pmjLkS1XImpIhMj5UXylB 96:2RGd8f3brgUJmgfHqhmlSG6R86jFcLTBrEvYOksT:bd8TNUgfHqor36jFITMT 12:QJVs6MvCCJ/dCfqlKA+PQpLMoDBsyyBekLIFjUvFOlfod+0D/1DuOy0h5h1366pc:QjsDvCCJlCfqlc8F8TLk2WG+0pxScIvD 1536:6prYsgwehfJKZgGMdUBUOTEz0KTEXxtZ4YaQWuW5y5p0MseP1AUiX8WO2lr6ER/s:6fWROgGMaBUOoz0KAXxTAyrseWpXh6SE 96:ucrHNi+NQIC65ELVgF1Fq18aES8pGWLjcj/r3+rnmav:prHNi++IxGBd18pssqr3+iav 196608:VZyRYJM5sGuiwDs2Ys+lW5znGoCtbLNmElxCrEPnyWoh7EYLP5q4n9+dQZE/QlQ:a+JMyaYLO2nGptbJmElxNyj4Gjns/J 24:QjsDvCCJErr6p2YsSdbxOeP9u11EwIC5P0dOivrFvc3Zq+8:BDK0Err60SZEec1Ew/9cxrFvcQV 12288:L6+5l9l9HDiLazSNWwbn8u1eppFMI9whH4UlC3sNNYT21l:fJY5Wwb8u1SFvwx4EC8zoY 192:rCCQIOHvXnAVkI1vzgU29cR+JQvFv7ebbJUWlrD/vAzFFmd9JHWL5GDH0G:r/OP0kobgU2ubvN7Y9Plr74md9JHo5U3 192:8itcsOOT3KP5N04L2nlsGroWegWGTwYeTFQBR9obXysD8W+Jn+5x:8ocsOCaTyvo9eWTcwFo3nIx 96:2RGddmqfyMQ6C/5CQN5rhecQgIN6wpllLUXyv:bdw6GCohecokuL+4 49152:anDcE86JG+aoN4k9QYZWx/36jARHlT2E0mXfxyPohu60v:aD666oeSQYgxfqAx5R0mPgAhJS 24576:5pitYuAnu1YrnjyMd2uCdLkT0TChyDUgyvkW8ZRGyzE:GD1Y6Md2uCdC0TChjbvk5RGWE 3072:vzZy6HuSLfBvurJMfxg+e87d20VIjydmSD52gpU7bvNBiPn5EvWSFDfEMPkkAMNl:M6HAJWaj8PIjADwOAon5YWShB9bVeVa 1536:pmdWcriFx2+4X/58/EBK5fZIJ47dzezqJtfDIZ1ZkSwrStsSoG5cVC:pmdWg+qyRCYU+t7IZVwUsSoG5r 1536:pRd1kg/eB7Xiypdt0EW0I0eygWkN+PMrZk9oloSPMZwiC5abtFh1pGVpgbliwNVh:l1MhXiyZ0EI0ey03mbZVC5abt/1pcgbn 96:2RJcrJSXV4mOhmdUgKbogyf7imIJCkMXccBv2gI6Yc:sclSXcAKZyziVPEB+gf 384:KY+6arHR15y4PoU9SMaJYahR4MfbaKSM+EP7RB:ExTxPR9QGq+Ez7 1536:iA21GwhmRt2qh5S0hTor2w4fIX1p1cf3Bvgfr0h5+WWuH4eVLGDkG:iqhXh5JForJ4fIFp1mmfm5WuH4CSIG 96:AAWCkzMvQZ1Go+u6cNcZ0gaeJs9FHW1YA:A1MY1Ez6gaWf 96:VYcM2eR7UUS7j0Y0nsbBHfyPuzV+Fg1mBWXjMRwC2FKHg51528wIXWAwD0J:VYPvIUMj0YfVflzVr1mIjMRwC2FMg5Pf 96:dgDEZib9cAjwBD5b9PYWdVOtDz5Vvo5otXHs:uEZwwDLYA4/525ot8 1536:XhNR3tAd4vHj3RqvuBy7bf4tTWPY4TqSBBpFMZ:jRimD3IvuBR47BVMZ 6144:qIDJqpNrLGo13Vi7AwwdbhCmIe4RAntK2L9:qIDI5G6jg9RAwG 768:/4gnOThMf5TcQTejqZQNs1twCisI+wUya+gVDL4CJTgiPMZaBgilyTHCT:/dGhMFTHZEs1twB3oyJADL4CJTX+aCtm 98304:IMI7dBEfgvgSyvygZOM3D8tCgYbnUiQK/AOyBX/CC6oqx6g4Q5Mj1FCEWWcLqzOB:IMuC4vgSk9ZO44tCgYQin/3ypTxqMgNB 1536:GuQskd1YDENEYl23RbnUEP7FmIJMV4uZQuA9CNaH8zgKR+XIEt6naTIAwKv:GzsUY4uYsnU0o4uZQ8Lgc1ETTIYv 1536:qXYk83Jws0fqb2Tro7LAUuBH3unLoqiUGUTeojb8bVky:qX/8Zn0hHmAny0qiUGAf8bVky 49152:O5/UMHyKX9kM5co4e2PttGdqtobCVIXyFSQtA9jCwScC:O5/3Cwd6ttMOAUIXyaTSD 24:inl8FiEqbwh5OPZgmzgRMXH5lm0hsqHIE8YBu7r/wzr79GIfUq:inwS0h5OygHHnIE8Ye/0rkIfUq 96:LrWkj9TZaveAcazXcUkQZrh0J32SEiJMuDgBz:WMZaGANzXGcrh052TIaz 1536:L3xBiFJX7kY5iOYbaWrB5EfPhg0/ZeGHBDHNiBlU:L3y7kY5iOYbbB5EfP1kGHBDHwc 98304:9cRgheDRgL6h8tXoHq50+rEI67LlW2gRPzyMiyWFeZbSLJyZBgWzqbFnpn9:98NRgXXi+rl2l5gRPzyBF8uLcZTzkR9 96:ftaE02FSxfoD9gOUgtPiwnZDL54Vm8DilwbkKa6/9ykiMnNY7xdl1LmEaRj7LRQ:fQZOEwmOUs1L5U4Gkt69yaY7xdJQP2 768:5aB59uO/OY8KuzJc3JY0uFE9pYAZqjIVH8SoTSfXg+IXY6:ABr3b8Tm3JYMYAZqj08ShfXdII6 96:3EUjCk9fZWhAjsT5nEj/pm2rMi+ZairsuCg:0Y19fZG6QWjhm2rlnsWg 1536:L+rtati0oQR5f6wDOClQx7ur2kh7P69EsqHVukQHOKcA:LQ+b6mlQ0qu7yUHV3Kn 1536:wTqfW5EtjR6aocKZOxwrXwjrcRTSJ13zq0Rd/yL3J2FpwtAwv4G:wuEgjR6a1e0EOsghm2FpYA0 1536:Oi+hcNc+imUlkgSplUciMK8GXRrGNNVW7n+T/as2PixqE8:d5IkJliJXRrGNNVWL+TasjxR8 1536:w22wY9EMnD8GSnPQEwbjKdmXcxbZ2GfvHNNN5EFFbTvVIf3ielmHR:wpwY9E6qPQ7b+4Mh0GfvrNaXv8GHR 24:QjsDvCCJm6Qnt23CMfVnIqtIDalOsELUej:BDK0m6Qtg//lUj 3072:L/YWGc/Lm48IShTIuUnaz6zlT0R12yfdup:j6c/LW9hTrUn0L8 1536:mxhXtTuUf1PNNNLFD/F9uNsJk2o4DjMdLUDLOCSCk/7eqhzdMO2:mxh5Jb9pvuSJE4cdLUPOf7LdX2 3:U:U 1536:o4+1Ibo1yk2ENTIIKWEpyi0Yt0EV3LnQ6TA7usZsy8lFahX5F2sSJ5PHJ:osbsJ9CTNz00n03Kzl5vB 96:aJXWjg9EG5wrdzaAlGrjj5RVBVA2m3ZO7sP:a1WkEG5QpzW5w2WGW 1536:q86sCmcUcWvoCz8e26mzO6lUbsAOym0nsleQjWJ+8K9KGbKQxEQLNP5/6n6nW/eU:q82cv7wMoO6+bsA9FB88S3BLJw/Cz45R 1536:IeDqU61Ri0Df8CWDfd6ty01ZiLUm86Ve2afgGkdNUIWbsiU/nz34En5:fDqU61Hf89p6tJHOVe3fmOIboEn5 196608:s4xiic34eLf1ryfz0AhuonMqc+zhQktCDYbg2Yg+:s4gigf1mphuSMV2hQgCDCgc+ 24:QjsDvCCJF0+AR6VuRq8KAnMKHbr7Gi0u2w21J7YxKprVs:BDK0Fxwq8Pbr70u2welfpBs 1536:+Arjm3a0dtbgsj8CdcRVUBBhHp+mHDUoFjdhUUepQteJy3fCk:+ArjiZzgsAu5BsuDnBdhSKeGfCk 1536:QNWPJw55qzDmLLZbFGuuVZaPNyUdGpnWaKsO2GYKIYEcCjNIiE:SywuzDm3dsulbdMW/B2GYKIdcsNBE 24:Xan4cEssakhu/v/XHZhULyR4eT3nX1f4qfeLKI1ac92pI6a9zssU:Xan4Ss7huvMLyRtT3nX1f4qwKAac92Ow 1536:aA1rTr7f/gTanIaJvCFFiBDNE885bBcToGfz5:a8/j/gTaIaxCDirE5B8d 96:aHN90/Tcm53pwOPs2SclTZlWwqe0rVzlvRq21oOiXVV0iTsSG6N5d7cU+Ianq:avmBppPs2NlTfWX3DvA2eRXzRTxGgdQQ 1536:3RWgaVzOdBjflJn74wzMFqLP+z308yOmgYoAibjoRjdvRrX454qYvaNKeJtAHkPY:3RWgaVzOdBjflJn74wzKqLP+z308yOmN 48:eFBxPsJmHSBDig9vezYWGk9KPhKJeSslX/GST9tcY/50xqWAMOFsT18Hp:ePxPsySBDig0zV1IPwASslX/dIY/2Csm 24:QjsDvCCJPhIuLJOGRtugp9nS7FSSPkkY0eZWOfpOyX9h:BDK0PRVOGRwg3nSxSSVMGyX9h 6:qzxG6v6Oqlf+iSDNbxvVAt2juiWowjCH+AqyJJpTtXYWRtjYsB3vVJXyLJLVXHja:kxpvM+PRbxvVi2K0HffXYokg3vVsLFVW 192:9ec+PVxuofp7mwCcMqEudQQqtiEt97TSFfyvo:9ec+97mwdddJqZ97Pvo 1536:9lCvOybKrMwJafjkA1eGC1zUNpFkedXRFYiYU4ybZ8xjAjDE:9surNsj7g14+2TXZOAU 1536:okF/rn7CpN/K8n7LrFvzKCnHlRxiI3jlIWi66LLunWPmFWD6/auuYcPc:d/r387AWHlTTlIWi6smWPmUDLPc 96:LrefA2Dq8vfbRfiw6C3xgfCwG6AJQpPv9Kkwb:Pn87RfV66oe0Kkwb 1536:fKzET4dL4ES51ooE6NZF3prQz5fCMthzTzt4/+XS9Refe7q1/:SzE8NI5bBfrQVqETztgmS9Refew/ 48:K7w1dJqafUxlTC9vTk5pdMm7UENcAUmrzB4cQaMZSV6svxMAMMlifoZ5Bjy6ScQP:Lr1UjMIXSAUmh4JlsvS3M8fohn76ZN 1536:5iJw3YaoMA38Hl9dQaUkGh+SLDw+NV2nLl9YbV9koqzlqqccyBhx348:uw3Yaf/NQaU5k+NV2nclqwRrhxo8 192:AgHEaYrzUxjHRPpMP475qhJ1qkJTqlaoWQ7sgkp04D:A/JvUxzZpMPOqhLnGlaoWR04D