Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-08-2016 01 Ran by [removed] (22-08-2016 00:28:59) Running from E:\Downloads Windows 10 Pro Version 1511 (X64) (2015-12-16 16:00:50) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2068355812-426577500-2880406620-500 - Administrator - Disabled) Colin (S-1-5-21-2068355812-426577500-2880406620-1000 - Administrator - Enabled) => C:\Users\Colin DefaultAccount (S-1-5-21-2068355812-426577500-2880406620-503 - Limited - Disabled) Guest (S-1-5-21-2068355812-426577500-2880406620-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2068355812-426577500-2880406620-1002 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 22.0.0.153 - Adobe Systems Incorporated) Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated) AIM for Windows (HKU\S-1-5-21-2068355812-426577500-2880406620-1000\...\AIM) (Version: - AOL Inc.) AMD Install Manager (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.4 - Advanced Micro Devices, Inc.) Amnesia: The Dark Descent (HKLM\...\Steam App 57300) (Version: - Frictional Games) Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Audacity 2.1.1 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.1 - Audacity Team) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 12.3.2280 - AVAST Software) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Catalyst Control Center Next Localization BR (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2016.0718.1747.30147 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.14 - Piriform) Course Vector .minerva (HKLM-x32\...\com.coursevector.minerva) (Version: 3.5.0 - UNKNOWN) Course Vector .minerva (x32 Version: 3.5.0 - UNKNOWN) Hidden Curse (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse) Curse Client (HKU\S-1-5-21-2068355812-426577500-2880406620-1000\...\101a9f93b8f0bb6f) (Version: 5.1.1.844 - Curse) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.4.0.0191 - Disc Soft Ltd) DARK SOULS III (HKLM\...\Steam App 374320) (Version: - FromSoftware, Inc.) Dark Souls: Prepare to Die Edition (HKLM-x32\...\Steam App 211420) (Version: - FromSoftware) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) Discord (HKU\S-1-5-21-2068355812-426577500-2880406620-1000\...\Discord) (Version: 0.0.291 - Hammer & Chisel, Inc.) DisplayFusion 7.2 (HKLM-x32\...\B076073A-5527-4f4f-B46B-B10692277DA2_is1) (Version: 7.2.0.0 - Binary Fortress Software) Dropbox (HKLM-x32\...\Dropbox) (Version: 8.4.19 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.27.37 - Dropbox, Inc.) Hidden EZSearch (x32 Version: 1.0.0.0 - bscodecs.com) Hidden f.lux (HKU\S-1-5-21-2068355812-426577500-2880406620-1000\...\Flux) (Version: - ) Fallout 4 (HKLM-x32\...\Steam App 377160) (Version: - Bethesda Game Studios) Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version: - Obsidian Entertainment) G4E (HKLM-x32\...\G4E) (Version: 1.7 - UNKNOWN) G4E (x32 Version: 1.7 - UNKNOWN) Hidden Git version 2.9.0 (HKLM\...\Git_is1) (Version: 2.9.0 - The Git Development Community) Go Programming Language amd64 go1.6.2 (HKLM-x32\...\{1AF0A8D1-D850-41D9-9610-C638E21EE23F}) (Version: 1.6.2 - hxxps://golang.org) Goat Simulator (HKLM\...\Steam App 265930) (Version: - Coffee Stain Studios) Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden Grand Theft Auto V (HKLM-x32\...\Steam App 271590) (Version: - Rockstar North) Guild Wars 2 (HKLM-x32\...\Guild Wars 2) (Version: - NCsoft Corporation, Ltd.) Gyazo 3.2.6 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden <==== ATTENTION iTunes (HKLM\...\{BFEAB774-C7DC-4032-B05A-DA5F7CB7B365}) (Version: 12.2.2.25 - Apple Inc.) Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation) Java 8 Update 91 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418091F0}) (Version: 8.0.910.15 - Oracle Corporation) Java SE Development Kit 8 Update 91 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180910}) (Version: 8.0.910.15 - Oracle Corporation) JMARS 3.5.3 (HKLM\...\3876-1132-4310-4428) (Version: 3.5.3 - Mars Space Flight Facility, Arizona State University) LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - ) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Logitech Gaming Software 8.83 (HKLM\...\Logitech Gaming Software) (Version: 8.83.85 - Logitech Inc.) Magic The Gathering Online (HKU\S-1-5-21-2068355812-426577500-2880406620-1000\...\01641bea2c75c522) (Version: 3.4.91.593 - Wizards of the Coast, LLC) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) MATLAB R2011a (HKLM\...\MatlabR2011a) (Version: 7.12 - The MathWorks, Inc.) METAL GEAR SOLID V: THE PHANTOM PAIN (HKLM-x32\...\Steam App 287700) (Version: - Konami Digital Entertainment) Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.6741.2063 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation) Mozilla Firefox 42.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 45.2.0 - Mozilla) Mumble 1.2.16 (HKLM-x32\...\{8C0C80AA-EA4D-4461-8B73-15A3A27F7D98}) (Version: 1.2.16 - Thorvald Natvig) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.61.23 - Black Tree Gaming) NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.6701.1036 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.6701.1036 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.6701.1036 - Microsoft Corporation) Hidden OldSchool RuneScape Launcher 1.2.7 (HKLM-x32\...\{FEDDCE73-34B8-4980-90B8-8619A78C902C}) (Version: 1.2.7 - Jagex Ltd) OpenOffice 4.1.1 (HKLM-x32\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation) osu! (HKLM-x32\...\{1a629b18-2ab9-4595-a1b8-6cdf07ae0da7}) (Version: latest - ppy Pty Ltd) Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) Raptr (HKLM-x32\...\Raptr) (Version: 5.2.1-r113066-release - Raptr, Inc) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.67.1226.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.6.5 - Rockstar Games) SafeZone Stable 1.51.2220.53 (x32 Version: 1.51.2220.53 - Avast Software) Hidden ShareX (HKLM\...\82E6AC09-0FEF-4390-AD9F-0DD3F5561EFC_is1) (Version: 11.1.0 - ShareX Team) Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Simulationcraft(x64) version 6.2.3.02 (HKLM-x32\...\{AC025546-B7C5-45A7-B16A-80AE482CBB01}_is1) (Version: 6.2.3.02 - Simulationcraft) Skype™ 7.26 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.) SOMA (HKLM\...\Steam App 282140) (Version: - Frictional Games) Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform) Starbound (HKLM-x32\...\Steam App 211820) (Version: - ) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) SteelSeries Engine 3.8.1 (HKLM\...\SteelSeries Engine 3) (Version: 3.8.1 - SteelSeries ApS) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1222 - SUPERAntiSpyware.com) The Elder Scrolls III: Morrowind (HKLM\...\Steam App 22320) (Version: - Bethesda Game Studios®) The Forest (HKLM\...\Steam App 242760) (Version: - Endnight Games Ltd) TradeSkillMaster Application version 1.0 (HKLM-x32\...\{c44da794-b956-4d50-8733-346d56ae63c7}_is1) (Version: 1.0 - TradeSkillMaster) Tukui Client (HKLM-x32\...\{BAD6EBBD-A6A9-41C9-898A-8C868A552E4C}) (Version: 2.4.6 - Tukui) Undertale (HKLM-x32\...\Steam App 391540) (Version: - tobyfox) Ventrilo Client for Windows x64 (HKLM\...\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}) (Version: 3.0.8.0 - Flagship Industries, Inc.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1-2) (Version: 1.0.3.1 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.3.1 (Version: 1.0.3.1 - LunarG, Inc.) Hidden Vuze (HKLM\...\8461-7759-5462-8226-1) (Version: 5.7.0.0 - Azureus Software, Inc.) Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.) WinRAR 5.30 beta 2 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.2 - win.rar GmbH) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) World of Warcraft Beta (HKLM-x32\...\World of Warcraft Beta) (Version: - Blizzard Entertainment) World of Warcraft Public Test (HKLM-x32\...\World of Warcraft Public Test) (Version: - Blizzard Entertainment) X-Mouse Button Control 2.11.1 (HKLM-x32\...\X-Mouse Button Control) (Version: 2.11.1 - Highresolution Enterprises) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2068355812-426577500-2880406620-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Colin\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileCoAuth.exe (Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {053F76D9-7919-4F35-BE19-C67334871EB0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {06D67628-241A-4BD8-8167-ED6033459E3D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-31] (Microsoft Corporation) Task: {0841C365-4EB8-46DB-9F92-B59CED40CCAE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {0C4389C8-665C-4D2F-BEAC-BC4CC942C325} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {0E8086C5-910E-4F61-8438-CBE06C6F9588} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe Task: {1B3B8555-5A9E-4FCC-91A8-A8870B42DC6D} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe Task: {20A9DFE9-D009-45F4-902C-36CA2FB271A0} - System32\Tasks\a6725995567259955 => C:\Program Files (x86)\supervises\sparring.exe Task: {218E17E2-0BC6-48B0-BCE6-0E4B093B55C2} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-08-11] (Microsoft Corporation) Task: {270A6450-A7E7-427A-A7F0-A23924F37058} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe Task: {2D982FD3-AB8F-409B-831F-745364893DE0} - \Adobe Acrobat Update Task -> No File <==== ATTENTION Task: {301974F6-F052-4714-AAC0-06971B315389} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-31] (Microsoft Corporation) Task: {3981D971-3FF5-494C-92C5-BFF1672E12E3} - \GyazoUpdateTaskMachine -> No File <==== ATTENTION Task: {3ABEBA0A-2DC5-4C94-A826-D2CB7D277DF5} - \1143331 -> No File <==== ATTENTION Task: {3B06206E-E391-4043-88AD-0C845BFD0826} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-21] (Google Inc.) Task: {3EC7B063-3DF4-4130-B448-93FFCE333C6A} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-08-21] (AVAST Software) Task: {406EFE02-DCB4-48E8-B83C-9D9F29C732E4} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {48EC3E09-7786-44BD-802B-351507C9D9D6} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe Task: {4D14C398-FABE-4F14-8562-0146EEFFE19E} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {4D5D96FD-ADEE-4132-8B14-FA50D8EAEBCA} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe Task: {5265377E-B843-47BB-A265-AB2138C488C0} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe Task: {54ADB9F0-F33D-4AA0-81F9-4CF1907802D0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {60DEE895-E407-4FDD-B845-F137C7C44765} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {633374B8-D557-445F-870B-7771D65FC3D7} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe Task: {679333F2-5193-4A72-840E-D79E9434F0F4} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {6CE4AF18-9EBA-4CA5-A1D6-3D55BD8EE285} - System32\Tasks\SafeZone scheduled Autoupdate 1471837767 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-08-09] (Avast Software) Task: {6F939A9F-CF37-41E0-8A74-213E9FCFAA8F} - \DropboxUpdateTaskMachineCore -> No File <==== ATTENTION Task: {79902018-0593-42C4-9F15-ADB1CFAE80F7} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe Task: {7D334B38-30CD-4671-8B92-255873E7AC26} - \GyazoUpdateTaskMachineDaily -> No File <==== ATTENTION Task: {7DC5382F-43C9-4D51-92AF-20624C7C24CB} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {7E2A7E7C-550E-4196-A596-921ADF7079F5} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe Task: {7FC51F6C-7947-49F2-BA9B-37A55C782723} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe Task: {827F8FF9-CAA6-464F-9C39-BA5B08D2B07D} - \Adobe Flash Player Updater -> No File <==== ATTENTION Task: {832090AE-DB87-48CF-9AB9-63EFBBC750E9} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {859A889B-CC18-4414-BFAD-0AD5F28F232E} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {85E3A5AD-2716-4C5F-B0C5-DDB49D814F0E} - \AMD ThankingURL -> No File <==== ATTENTION Task: {885B1642-1DF7-4030-B882-637794326EED} - \2143331 -> No File <==== ATTENTION Task: {8DA3491E-3A01-4E9A-B1F3-F3A52A7B0FD5} - \DropboxUpdateTaskMachineUA -> No File <==== ATTENTION Task: {8E53229D-627C-402B-BA28-2F84685FF491} - \AMD Updater -> No File <==== ATTENTION Task: {94BDD7F0-8A4C-4FBE-AD37-38ABDD73A155} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {98FF98C9-1F1E-4714-B33A-A3E2A16B7D72} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe Task: {9E070261-90C0-42B1-B80B-1D8030810261} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {A63652D5-6198-4470-A770-D8F348AF7E6C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {AA0A6E7E-3E49-4695-8E27-5C59409550CF} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe Task: {B475D806-C47F-4223-B6B0-C310746D8736} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-08-01] (Microsoft Corporation) Task: {BE048301-5D94-4103-B6A7-A0553F2EB926} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe Task: {C59C05D0-D93D-4575-8FCA-F70086CB050B} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {C9AED2F5-A830-4039-B087-08F399602D6E} - \{D37A73A4-D5F4-4665-A216-ADEC475DE183} -> No File <==== ATTENTION Task: {CB957480-B228-4790-85E8-993C81073F9F} - System32\Tasks\SUPERAntiSpyware Scheduled Task 21d6f1b4-e54a-43cf-ba6b-4cc62d4d6c2e => E:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) Task: {CC6B351D-15CE-4EBF-9DFB-A119FC133125} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {CD26FFAC-942D-45FD-8FDF-70F8BF9E726D} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {D25C869D-13E0-48D5-8B1B-E352D35497EA} - System32\Tasks\Microsoft\Microsoft Antimalware\MpIdleTask => C:\Program Files\Microsoft Security Client\MpCmdRun.exe Task: {D6671221-6614-4D58-87C2-F6E3DEE0970B} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe Task: {E1F8E3A6-508E-46D0-B43B-B295EE937BCB} - \CCleanerSkipUAC -> No File <==== ATTENTION Task: {EA0DD911-BC4F-4AB4-A9B5-AB15E4D7848D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe Task: {F71F77F9-58B2-4714-A3CF-DAF88B088AE9} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2016-08-01] (Microsoft Corporation) Task: {F8F97A45-0E32-4EF0-804E-8420A691357F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-08-01] (Microsoft Corporation) Task: {FB95436F-DE08-47E9-9A9E-19396C69CBC6} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe Task: {FCFE1091-C1B2-470D-8D25-CDDAB3ADBF05} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-21] (Google Inc.) Task: {FF4D92D7-4208-4EA9-BCE6-E15B1705C093} - \OneDrive Standalone Update Task -> No File <==== ATTENTION Task: {FF947492-B0E9-4ADA-A0DD-7ED818289EF8} - System32\Tasks\SUPERAntiSpyware Scheduled Task 9c84432f-d624-4ceb-9ca7-05cbdcdadd1a => E:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 21d6f1b4-e54a-43cf-ba6b-4cc62d4d6c2e.job => E:\Program Files\SUPERAntiSpyware\SASTask.exedE:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 9c84432f-d624-4ceb-9ca7-05cbdcdadd1a.job => E:\Program Files\SUPERAntiSpyware\SASTask.exedE:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\сhrоmе.lnk -> E:\Program Files (x86)\Google\Chrome\Application\chrome.bat () Shortcut: C:\Users\Colin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lаunсh Intеrnеt Ехplоrеr Вrоwsеr.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.bat () Shortcut: C:\Users\Colin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Gооglе Сhrоmе.lnk -> E:\Program Files (x86)\Google\Chrome\Application\chrome.bat () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Моzillа Firеfох.lnk -> E:\Program Files (x86)\Mozilla Firefox\firefox.bat (No File) ShortcutWithArgument: C:\Users\Colin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\41909512a434c411\Google Chrome.lnk -> E:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 00:18 - 2015-10-30 00:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-05-15 16:26 - 2015-05-15 16:26 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-05-15 16:26 - 2015-05-15 16:26 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2015-12-12 14:06 - 2016-07-31 05:48 - 00173248 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll 2015-12-16 08:54 - 2015-12-03 15:30 - 00936728 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe 2016-07-12 19:37 - 2016-06-30 21:48 - 02656408 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-07-12 19:37 - 2016-06-30 21:48 - 02656408 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-07-12 19:37 - 2016-06-30 20:21 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2015-12-17 13:14 - 2015-12-06 21:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-07-12 19:39 - 2016-06-30 20:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-07-12 19:37 - 2016-06-30 20:27 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-07-12 19:37 - 2016-06-30 20:22 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2016-07-12 19:37 - 2016-06-30 20:22 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-07-12 19:37 - 2016-06-30 20:24 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-08-21 20:47 - 2016-08-21 20:47 - 00281272 _____ () C:\Program Files\AVAST Software\Avast\AvastNM.exe 2015-08-24 01:15 - 2015-08-24 01:15 - 00016384 _____ () C:\Users\Colin\AppData\Local\Apps\2.0\EXTXBN1Q.O6V\R8NZ943V.8JY\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\Curse.CurseClient.WowDb.dll 2015-08-24 01:15 - 2015-08-24 01:15 - 00035840 _____ () C:\Users\Colin\AppData\Local\Apps\2.0\EXTXBN1Q.O6V\R8NZ943V.8JY\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\Curse.Advertising.dll 2015-08-24 01:15 - 2015-08-24 01:15 - 00099840 _____ () C:\Users\Colin\AppData\Local\Apps\2.0\EXTXBN1Q.O6V\R8NZ943V.8JY\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\Curse.CurseClient.CMOD2.dll 2016-08-21 20:47 - 2016-08-21 20:47 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-08-21 20:49 - 2016-08-21 20:49 - 03015680 _____ () C:\Program Files\AVAST Software\Avast\defs\16082100\algo.dll 2016-08-21 20:47 - 2016-08-21 20:47 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2015-12-16 08:54 - 2016-08-22 00:27 - 00029184 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\PEbiosinterface32.dll 2015-12-16 08:54 - 2015-12-03 15:30 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\ATKEX.dll 2016-08-21 20:49 - 2016-08-09 03:13 - 67856856 _____ () C:\Program Files\AVAST Software\SZBrowser\1.51.2220.53\SZBrowser.dll 2016-08-21 20:49 - 2016-08-09 03:13 - 02182616 _____ () C:\Program Files\AVAST Software\SZBrowser\1.51.2220.53\libglesv2.dll 2016-08-21 20:49 - 2016-08-09 03:13 - 00084952 _____ () C:\Program Files\AVAST Software\SZBrowser\1.51.2220.53\libegl.dll 2016-08-21 20:47 - 2016-08-21 20:47 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2016-03-24 15:37 - 2016-04-29 14:33 - 01690504 _____ () C:\Users\Colin\AppData\Roaming\Curse Client\Bin\Electron\libglesv2.dll 2016-03-24 15:37 - 2016-04-29 14:33 - 00018312 _____ () C:\Users\Colin\AppData\Roaming\Curse Client\Bin\Electron\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-2068355812-426577500-2880406620-1000\...\sharepoint.com -> hxxps://nau0-files.sharepoint.com ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 19:34 - 2016-08-21 18:51 - 00001188 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 down.baidu2016.com 127.0.0.1 123.sogou.com 127.0.0.1 www.czzsyzgm.com 127.0.0.1 www.czzsyzxl.com 127.0.0.1 union.baidu2019.com 127.0.0.1 down.baidu2016.com 127.0.0.1 123.sogou.com 127.0.0.1 www.czzsyzgm.com 127.0.0.1 www.czzsyzxl.com 127.0.0.1 union.baidu2019.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2068355812-426577500-2880406620-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Colin\AppData\Local\DisplayFusion\Wallpaper_1.png DNS Servers: [removed] - 8.8.8.8 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\Run: => "Launch LCore" HKLM\...\StartupApproved\Run32: => "Dropbox" HKLM\...\StartupApproved\Run32: => "Raptr" HKU\S-1-5-21-2068355812-426577500-2880406620-1000\...\StartupApproved\Run: => "DisplayFusion" HKU\S-1-5-21-2068355812-426577500-2880406620-1000\...\StartupApproved\Run: => "Speccy" HKU\S-1-5-21-2068355812-426577500-2880406620-1000\...\StartupApproved\Run: => "DAEMON Tools Lite Automount" HKU\S-1-5-21-2068355812-426577500-2880406620-1000\...\StartupApproved\Run: => "TSMApplication" HKU\S-1-5-21-2068355812-426577500-2880406620-1000\...\StartupApproved\Run: => "wrongs" HKU\S-1-5-21-2068355812-426577500-2880406620-1000\...\StartupApproved\Run: => "horoscopes" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808 FirewallRules: [{9C689313-8F78-4166-976F-E2CFA77A9A10}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{02CC4DA8-D934-4A4E-BF19-2F07DA0131DA}] => (Allow) E:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{5E3C3851-AEB6-4B5A-A0EC-20419F9A41C4}] => (Allow) E:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{A167938F-A5E6-4A95-AAC2-591CE950FCA1}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{3990F2DD-F3D3-42CF-86C0-A0F48A161EDB}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{65FA8131-419E-4696-AC22-1B753F177618}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{C5B04241-B8EA-4DB2-9040-066258B0B2EE}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [UDP Query User{752C65F9-D72C-4B58-9D6D-AD6BBA22512A}E:\program files\vuze\azureus.exe] => (Allow) E:\program files\vuze\azureus.exe FirewallRules: [TCP Query User{C4F3A041-1585-4E64-87B0-3967D19F8DD7}E:\program files\vuze\azureus.exe] => (Allow) E:\program files\vuze\azureus.exe FirewallRules: [{1CD2B493-8271-42CA-911C-1A941EA06884}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Fallout 4\Fallout4Launcher.exe FirewallRules: [{38FB678D-1178-4DD7-8A03-E301F5AA7801}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Fallout 4\Fallout4Launcher.exe FirewallRules: [{EE38AA0F-A6C9-4C1E-8444-BE5B080EF682}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\MGS_TPP\mgsvtpp.exe FirewallRules: [{A8D7AF1F-0836-4C2A-B413-2A23DA10BA6A}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\MGS_TPP\mgsvtpp.exe FirewallRules: [UDP Query User{FB1CBA62-EFE4-4DDF-BB4D-E79A8A596A9A}E:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) E:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [TCP Query User{B9A5FF6A-3F47-48B5-B44B-F9683D44DAD2}E:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) E:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [UDP Query User{C31E92BC-79E5-422A-BC13-8C0F6DC034C3}E:\program files\jmars\jmars.exe] => (Allow) E:\program files\jmars\jmars.exe FirewallRules: [TCP Query User{E58B70F4-9197-4FFF-9997-B774AD8BAEB9}E:\program files\jmars\jmars.exe] => (Allow) E:\program files\jmars\jmars.exe FirewallRules: [UDP Query User{E2B5DE87-A483-4BE8-B623-B63DA3755C30}E:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) E:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [TCP Query User{98923685-CAD1-4541-A6AC-0A0F99FAC8B9}E:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) E:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [{29672A75-BF51-4A91-8F06-978485605CFB}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe FirewallRules: [{C2E36715-E530-4345-B40D-CBB6948A4ACB}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe FirewallRules: [{36CCCB84-5145-45AD-B238-A1A06C0AF712}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{BAB8100D-A1F2-487C-A545-2EAD24447BF5}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{8A3201D9-FE87-4B15-A215-6D3396DAB6A2}] => (Allow) E:\Program Files\Ventrilo\Ventrilo.exe FirewallRules: [{EE637216-9035-4EB6-8682-CFBA3A12D485}] => (Allow) E:\Program Files\Ventrilo\Ventrilo.exe FirewallRules: [TCP Query User{092B01D9-301B-4910-A73E-89E4930C93FF}E:\program files (x86)\skype\phone\skype.exe] => (Allow) E:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{EE4EDEB3-A93B-46F9-B34A-5D0F31E49F8A}E:\program files (x86)\skype\phone\skype.exe] => (Allow) E:\program files (x86)\skype\phone\skype.exe FirewallRules: [{88EF558E-53BE-4CC7-94E4-B25BD6754785}] => (Allow) E:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{7EFC2819-79B9-4757-B499-E6959349314B}] => (Allow) E:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{332BA55C-13B8-400D-82CB-2EF0F22FA7C3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{8ED9C31B-EB10-44B3-BF2E-82C9F958BCCC}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C62A027F-8E82-446D-9CE3-D4C501B9831E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{232D57D0-CFC2-4027-9785-24530B132876}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{D2C4EB21-3682-405D-8684-F6EC2B41D02C}] => (Allow) E:\Program Files\iTunes\iTunes.exe FirewallRules: [{5BE7623E-388B-4A42-8EB7-7EC3293FC85B}] => (Allow) E:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{5A5C9148-5E6E-4459-99A3-7CA361AB6688}] => (Allow) E:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{10C4BA8E-B550-4437-930B-5708223F762C}] => (Allow) E:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{DD8FDD29-5BC7-4A85-B4BC-F4EA990BBAE7}] => (Allow) E:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{43593E74-C485-4214-9E6D-8C75F1ECD8B2}] => (Allow) E:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{AA5CBD06-9F93-49DC-854E-1F6CE68AC498}] => (Allow) E:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{25207FDD-5C62-42F9-901F-6552DFF87E1A}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{DDDE5FE0-1B2D-402B-B052-BBD1CE7867FA}] => (Allow) E:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [{722CBBAF-060E-4F4C-A78B-ACACB655B5BF}] => (Allow) E:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [{1DCB1F8A-7C81-473D-B5D4-BF6DC01FF39D}] => (Allow) C:\Users\Colin\AppData\Local\Apps\2.0\EXTXBN1Q.O6V\R8NZ943V.8JY\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\CurseClient.exe FirewallRules: [{E6EBB7F6-C05B-485B-B936-70BD51C985BD}] => (Allow) C:\Users\Colin\AppData\Local\Apps\2.0\EXTXBN1Q.O6V\R8NZ943V.8JY\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\CurseClient.exe FirewallRules: [{3BE633B6-EE38-48DC-A946-9BF0074A3C4B}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Undertale\UNDERTALE.exe FirewallRules: [{56376DCD-9377-4F5A-A7D5-C210468C06B8}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Undertale\UNDERTALE.exe FirewallRules: [{EFD259D1-C4B1-4EF2-81B7-7FFBFAD40996}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{BF502611-FB25-4EB9-B249-7F72B832C4F8}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{02A7479E-4F65-4F48-A7A0-18883D78A1B2}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe FirewallRules: [{5DE6CB6A-ED3D-439C-8DE3-838023F8E06E}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe FirewallRules: [{AB0D7B36-0C4B-4239-9786-B003009651FF}] => (Allow) E:\Program Files\Vuze\Azureus.exe FirewallRules: [{AAC08C6B-633F-4006-AC47-E327718FC8B0}] => (Allow) E:\Program Files\Vuze\Azureus.exe FirewallRules: [{9225211B-00A0-46A7-A0C8-A4442D2BFBE8}] => (Allow) C:\Users\Colin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{E40702DC-1C6A-4286-B3DA-165CF0309085}] => (Allow) C:\Users\Colin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{8B432ECF-AAD0-41B7-A417-7F9BC07A21CE}] => (Allow) C:\Users\Colin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{26A96E26-386E-4888-98FB-006D57559E8D}] => (Allow) C:\Users\Colin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{4D7DBBBF-B70E-451E-8F05-66D6EC8E967D}] => (Allow) C:\Users\Colin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{6C9A6143-453F-43F9-9561-B0B6E4B5B00B}] => (Allow) C:\Users\Colin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [TCP Query User{D39A9E0B-EE58-473D-8AB4-169768B71FF3}E:\downloads\java\jre1.7.0_75\bin\java.exe] => (Allow) E:\downloads\java\jre1.7.0_75\bin\java.exe FirewallRules: [UDP Query User{4CF80EC9-D903-4DCD-AAFD-5CA4F4A7F582}E:\downloads\java\jre1.7.0_75\bin\java.exe] => (Allow) E:\downloads\java\jre1.7.0_75\bin\java.exe FirewallRules: [TCP Query User{8730A754-DCBE-470D-94CC-D1351816E82B}C:\program files (x86)\java\jre1.8.0_71\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_71\bin\java.exe FirewallRules: [UDP Query User{10FC4F44-0E6D-4CCC-BE0F-C332E4A69B09}C:\program files (x86)\java\jre1.8.0_71\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_71\bin\java.exe FirewallRules: [TCP Query User{2F23837E-F869-4825-A0AA-88BDBD99D48E}C:\program files (x86)\java\jre1.8.0_71\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_71\bin\javaw.exe FirewallRules: [UDP Query User{AA119ECF-D7B5-4BD5-AA29-AC1D1B0BE2CA}C:\program files (x86)\java\jre1.8.0_71\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_71\bin\javaw.exe FirewallRules: [{A9B76463-B88A-4ACB-A040-68EC328C395E}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe FirewallRules: [{3358DF7A-B666-483D-905C-5AE1B28BF826}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe FirewallRules: [{B1528A1F-6585-4928-84AF-06C03F0B28DC}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe FirewallRules: [{948FFFF0-405F-4DD2-841C-B673C0227191}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe FirewallRules: [TCP Query User{5EDBD9DF-6925-41E6-AC82-8B81C495D12B}C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe FirewallRules: [UDP Query User{60C0A03D-30CD-46B4-978E-E1E8645C7909}C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe FirewallRules: [{7660527D-F6FF-41D1-AD95-32CB21273A0A}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\SOMA\Soma.exe FirewallRules: [{0711C9BD-F3BA-4FA2-B4DC-BA18656F9295}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\SOMA\Soma.exe FirewallRules: [{FE085F2B-F240-42EF-8BF0-7BF3CCE7810F}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\SOMA\ModLauncher.exe FirewallRules: [{B2984B0A-A5CB-4F7A-8E51-5C235D367851}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\SOMA\ModLauncher.exe FirewallRules: [TCP Query User{C2808466-05DB-44CF-956C-7A01A206571C}C:\program files (x86)\overwatch\overwatch.exe] => (Allow) C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [UDP Query User{0B560861-A721-4294-BD86-F2471059B100}C:\program files (x86)\overwatch\overwatch.exe] => (Allow) C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [TCP Query User{36510F70-20B2-486A-B90C-4EB0AB4DA6B9}E:\program files (x86)\overwatch\overwatch.exe] => (Allow) E:\program files (x86)\overwatch\overwatch.exe FirewallRules: [UDP Query User{997A5B48-6B51-47F4-A8C9-DD6092A0CF1A}E:\program files (x86)\overwatch\overwatch.exe] => (Allow) E:\program files (x86)\overwatch\overwatch.exe FirewallRules: [{20359227-2358-4F1B-8CBF-69E838167D0B}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe FirewallRules: [{4A5572B9-5132-4656-B5DD-7BBED4C48402}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe FirewallRules: [{C19A6C12-03DD-43D9-9307-7AEC717796F4}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [{987E42CF-0885-4A69-9A8D-6FBECD7136D6}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [TCP Query User{589DC7BB-43FD-4F3C-9BCE-920CD15F2660}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{E3438414-5EF2-46FF-AC8C-DBC2AFFD13E4}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{D994E1EA-AA6D-4FA1-9ACF-D38F73686F02}] => (Allow) E:\Program Files (x86)\OSTotoSoft\DriverTalent\DriverTalent.exe FirewallRules: [{11D76EE3-EDBD-4146-B39E-1CD66DB5517F}] => (Allow) E:\Program Files (x86)\OSTotoSoft\DriverTalent\DTLService.exe FirewallRules: [{0DFAA021-68F9-473A-BBBC-8E29A871EB62}] => (Allow) E:\Program Files (x86)\OSTotoSoft\DriverTalent\download\MiniThunderPlatform.exe FirewallRules: [TCP Query User{340584CB-0A12-440C-924C-4CD9BD80ABA7}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{261CDB6D-1B19-4136-9F29-EEF88BA33855}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{DCA1C86F-4AB7-4364-8431-7C251E45A62D}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Morrowind\Morrowind Launcher.exe FirewallRules: [{31D9A55E-2FC8-4551-B0D7-769163A1426B}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Morrowind\Morrowind Launcher.exe FirewallRules: [{B0F5C408-0FFE-4207-9194-FFA5F515D16E}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe FirewallRules: [{7F33E5E1-3026-4425-95B9-51C69BDDA5D1}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe FirewallRules: [{FDAC6618-DB57-4737-9C67-296A7B939B7F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{6678D047-870C-408D-A4B3-4115D6D94FE5}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{9BCCCB57-7166-4BCB-B3A3-33B6B9F3217F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{AA276F18-6A0C-46D6-9598-ABA7840DE613}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{9A3681FF-73C8-46EB-9450-D642D4C3C803}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{61BA3FEC-08FA-4844-9DF2-BCC971CACDA1}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{29A95DF5-5B4B-4C63-B591-518244AA1340}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{FCE8FCFF-3B91-461E-9165-E7EF516D89FD}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{DA55C922-6053-445B-8537-B38EDA87AF3F}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\DARK SOULS III\Game\DarkSoulsIII.exe FirewallRules: [{7BDAE3FC-6D1B-445C-885A-BD7451057EA4}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\DARK SOULS III\Game\DarkSoulsIII.exe FirewallRules: [{F31CF313-DA83-49F6-9C8C-278D86044397}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Starbound\win32\mod_uploader.exe FirewallRules: [{1F44BC47-C06E-420C-999C-C2732E8D7D9C}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Starbound\win32\mod_uploader.exe FirewallRules: [{28FE51DF-270F-4157-91F4-ACDA176CFE08}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\starbound.exe FirewallRules: [{3588FE0D-54F8-40A8-95C0-8C8B4F9CC5D4}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\starbound.exe FirewallRules: [{817D3319-3539-423D-B206-021318B79A9C}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\starbound_server.exe FirewallRules: [{9B36820F-40C4-44CD-9E85-EC67D40A0DC4}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\starbound_server.exe FirewallRules: [{D03B3F83-2A09-4027-B76E-B7DDF4540E26}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\mod_uploader.exe FirewallRules: [{4F093660-DB2A-4111-8E9C-20B53935116E}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\mod_uploader.exe FirewallRules: [{CE490363-94C7-4CB4-8422-E8E50F1BED74}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Starbound\win32\starbound.exe FirewallRules: [{CCCCEC33-EFE9-4769-99A6-4F51D59AC2E4}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Starbound\win32\starbound.exe FirewallRules: [TCP Query User{E01EA379-E6E6-4FF7-B08F-8B6FC1FA0CA5}E:\program files\java\jre1.8.0_91\bin\java.exe] => (Allow) E:\program files\java\jre1.8.0_91\bin\java.exe FirewallRules: [UDP Query User{8545BF97-7EA6-4A9C-A315-D0447ED1F0B0}E:\program files\java\jre1.8.0_91\bin\java.exe] => (Allow) E:\program files\java\jre1.8.0_91\bin\java.exe FirewallRules: [TCP Query User{D3C8FFB8-3377-4C77-BEE1-92BBD2CB93D9}E:\program files\java\jre1.8.0_91\bin\javaw.exe] => (Allow) E:\program files\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [UDP Query User{0CA841DD-5FE9-4D76-AA1E-72BA1B498E08}E:\program files\java\jre1.8.0_91\bin\javaw.exe] => (Allow) E:\program files\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [TCP Query User{400F6755-634C-4486-9233-5A278BF8F1B8}E:\program files (x86)\single player project v3\database\bin\mysqld.exe] => (Allow) E:\program files (x86)\single player project v3\database\bin\mysqld.exe FirewallRules: [UDP Query User{A80C7551-50DF-484E-AC13-E93E73691D00}E:\program files (x86)\single player project v3\database\bin\mysqld.exe] => (Allow) E:\program files (x86)\single player project v3\database\bin\mysqld.exe FirewallRules: [TCP Query User{9336528A-94CE-4D2C-8AEA-CD2A75E1D39A}E:\program files (x86)\single player project v3\singlecore\login.exe] => (Allow) E:\program files (x86)\single player project v3\singlecore\login.exe FirewallRules: [UDP Query User{DB0D4897-486B-4C6F-9877-0C2C47891BFE}E:\program files (x86)\single player project v3\singlecore\login.exe] => (Allow) E:\program files (x86)\single player project v3\singlecore\login.exe FirewallRules: [TCP Query User{1C713562-0066-4545-8E0C-8A7575F61FE6}E:\program files (x86)\single player project v3\singlecore\world.exe] => (Allow) E:\program files (x86)\single player project v3\singlecore\world.exe FirewallRules: [UDP Query User{998EEF18-978F-448E-B80C-132C4D3078F2}E:\program files (x86)\single player project v3\singlecore\world.exe] => (Allow) E:\program files (x86)\single player project v3\singlecore\world.exe FirewallRules: [{F1F2F2AA-C3F5-46A4-943D-3C7CA9D1FDE3}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [{5A99B78E-6493-4279-BB84-88B72823E1BD}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶睜湩慲整坜湩潒瑵䑥攮數 FirewallRules: [{0140235B-D5DF-48CD-9D03-C6CF635E8341}] => (Allow) C:\Users\Colin\AppData\Local\ddnowyes.exe FirewallRules: [{8163B447-B9F5-46DF-B613-77BDE4D7D212}] => (Allow) C:\Users\Colin\AppData\Local\Temp\nsq7618.tmp\oksoft12.exe FirewallRules: [{71D74000-12EC-4FB6-B7A0-1750A34D8883}] => (Allow) C:\Users\Colin\AppData\Local\76263739.exe FirewallRules: [{3A2CFFCD-003F-4FAA-890D-3D692B46A4B9}] => (Allow) C:\Users\Colin\AppData\Local\tinstall.exe FirewallRules: [{ACE075C1-697E-4A4C-BBBD-2F0E4BB40AE4}] => (Allow) C:\Users\Colin\AppData\Local\cap.exe FirewallRules: [{D84EB96F-BC4B-48C2-BA16-436CC19E4ED2}] => (Allow) C:\Users\Colin\AppData\Local\ddnow.exe FirewallRules: [{9E5905DA-7682-458B-80D4-BC286EE5DE59}] => (Allow) C:\Program Files (x86)\hagemann\polsky.exe FirewallRules: [{EB108F77-0D99-4BCE-B011-6362E7D16730}] => (Allow) C:\Program Files (x86)\hagemann\growled.exe FirewallRules: [{59833CFA-51A6-4775-83C2-88EE175F48C5}] => (Allow) C:\Program Files (x86)\excited\commiserated.exe FirewallRules: [{B8BBAAB8-0E6C-4474-8018-C533E1EDE836}] => (Allow) C:\Program Files (x86)\supervises\sparring.exe FirewallRules: [{5567FF9F-43A8-467F-AABB-B813A498AAAF}] => (Allow) C:\WINDOWS\yr.exe ==================== Restore Points ========================= ATTENTION: System Restore is disabled ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/22/2016 12:26:13 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: 420BOOTYWIZARD) Description: Activation of app Microsoft.Getstarted_4.0.9.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/22/2016 12:24:35 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Local Hostname 420bootywizard.local already in use; will try 420bootywizard-2.local instead Error: (08/22/2016 12:24:35 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister 16 420bootywizard.local. AAAA FE80:0000:0000:0000:395E:2767:E938:16E3 Error: (08/22/2016 12:24:35 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from FE80:0000:0000:0000:395E:2767:E938:16E3:5353 16 420bootywizard.local. AAAA 2602:0306:C50C:6700:0000:0000:0000:0035 Error: (08/21/2016 11:47:57 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: rkill64.exe, version: 2.8.4.0, time stamp: 0x5705781b Faulting module name: rkill64.exe, version: 2.8.4.0, time stamp: 0x5705781b Exception code: 0xc0000417 Fault offset: 0x00000000000806d8 Faulting process id: 0x1630 Faulting application start time: 0xrkill64.exe0 Faulting application path: rkill64.exe1 Faulting module path: rkill64.exe2 Report Id: rkill64.exe3 Faulting package full name: rkill64.exe4 Faulting package-relative application ID: rkill64.exe5 Error: (08/21/2016 11:39:12 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: 420BOOTYWIZARD) Description: Activation of app Microsoft.Getstarted_4.0.9.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/21/2016 11:38:33 PM) (Source: deerfield) (EventID: 0) (User: ) Description: Service cannot be started. System.IO.FileNotFoundException: Could not load file or assembly 'dll, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null' or one of its dependencies. The system cannot find the file specified. File name: 'dll, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null' at s11.WindowsService.check() at s11.WindowsService.OnStart(String[] args) at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) WRN: Assembly binding logging is turned OFF. To enable assembly bind failure logging, set the registry value [HKLM\Software\Microsoft\Fusion!EnableLog] (DWORD) to 1. Note: There is some performance penalty associated with assembly bind failure logging. To turn this feature off, remove the registry value [HKLM\Software\Microsoft\Fusion!EnableLog]. Error: (08/21/2016 11:38:33 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Local Hostname 420bootywizard.local already in use; will try 420bootywizard-2.local instead Error: (08/21/2016 11:38:33 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister 4 420bootywizard.local. Addr 192.168.1.72 Error: (08/21/2016 11:38:33 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 192.168.1.72:5353 16 420bootywizard.local. AAAA 2602:0306:C50C:6700:0000:0000:0000:0035 System errors: ============= Error: (08/22/2016 12:27:47 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The YQAGaQsv service failed to start due to the following error: %%2 = The system cannot find the file specified. Error: (08/22/2016 12:27:47 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The WinRateSvc2 service failed to start due to the following error: %%2 = The system cannot find the file specified. Error: (08/22/2016 12:27:47 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The WinRateSvc service failed to start due to the following error: %%2 = The system cannot find the file specified. Error: (08/22/2016 12:27:47 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: %%1058 = The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (08/22/2016 12:27:47 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY) Description: There was an error while attempting to read the local hosts file. Error: (08/22/2016 12:27:47 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY) Description: There was an error while attempting to read the local hosts file. Error: (08/22/2016 12:27:29 AM) (Source: DCOM) (EventID: 10005) (User: 420BOOTYWIZARD) Description: 1084WSearchUnavailable{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Error: (08/22/2016 12:27:27 AM) (Source: DCOM) (EventID: 10005) (User: 420BOOTYWIZARD) Description: 1084WSearchUnavailable{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Error: (08/22/2016 12:26:30 AM) (Source: DCOM) (EventID: 10005) (User: 420BOOTYWIZARD) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (08/22/2016 12:26:30 AM) (Source: DCOM) (EventID: 10005) (User: 420BOOTYWIZARD) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} CodeIntegrity: =================================== Date: 2016-08-21 23:41:02.181 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET8671.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2016-08-21 23:41:02.165 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET8671.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2016-08-21 23:41:02.151 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET8671.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2016-08-21 23:41:02.115 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET720F.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2016-08-21 23:41:02.099 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET720F.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2016-08-21 23:41:02.084 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET720F.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2016-08-21 23:41:02.025 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET71FC.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2016-08-21 23:41:01.837 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET71FC.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2016-08-21 23:41:01.706 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET71FC.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2016-08-21 23:41:01.475 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET2955.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz Percentage of memory in use: 33% Total physical RAM: 8129.5 MB Available physical RAM: 5390.61 MB Total Virtual: 16321.5 MB Available Virtual: 13325.07 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.25 GB) (Free:1.44 GB) NTFS Drive e: (Storage) (Fixed) (Total:931.51 GB) (Free:528.52 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 89FC3901) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=111.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 8AC2D710) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================