Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-01-2017 Ran by [removed] (10-01-2017 21:38:53) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1511 (X64) (2016-02-07 05:06:49) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-233390903-2661952563-451428824-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-233390903-2661952563-451428824-503 - Limited - Disabled) Guest (S-1-5-21-233390903-2661952563-451428824-501 - Limited - Disabled) Primitive (S-1-5-21-233390903-2661952563-451428824-1001 - Administrator - Enabled) => C:\Users\Primitive ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (Version: 21.2.1 - HP Inc.) Hidden Ansel (Version: 376.33 - NVIDIA Corporation) Hidden ARK: Survival Evolved (HKLM\...\Steam App 346110) (Version: - Studio Wildcard) Classic Shell (HKLM\...\{383BB30A-B4A7-4666-9A83-22CFA8640097}) (Version: 4.3.0 - IvoSoft) Clustertruck (HKLM\...\Steam App 397950) (Version: - Landfall Games) Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve) Depth (HKLM\...\Steam App 274940) (Version: - Digital Confectioners) Deus Ex: Mankind Divided™ (HKLM\...\Steam App 337000) (Version: - Eidos Montreal) Discord (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\Discord) (Version: 0.0.296 - Hammer & Chisel, Inc.) Dishonored (HKLM\...\Steam App 205100) (Version: - Arkane Studios) Epic Games Launcher (HKLM-x32\...\{2DE76AAC-8061-4D9B-B7BA-A7CFBE0F8048}) (Version: 1.1.86.0 - Epic Games, Inc.) Golf With Your Friends (HKLM\...\Steam App 431240) (Version: - Blacklight Interactive) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Grand Theft Auto V (HKLM\...\Steam App 271590) (Version: - Rockstar North) Guns of Icarus Online (HKLM\...\Steam App 209080) (Version: - Muse Games) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) HiPatch (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF000}) (Version: 5.0.6.4 - Hi-Rez Studios) Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios) Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden <==== ATTENTION Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) Malwarebytes version 3.0.5.1299 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.5.1299 - Malwarebytes) Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.7571.2075 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: - ) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Driver 376.33 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.33 - NVIDIA Corporation) NVIDIA GeForce Experience 3.2.0.96 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.2.0.96 - NVIDIA Corporation) NVIDIA Graphics Driver 376.33 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.33 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.17 - NVIDIA Corporation) NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) NvNodejs (Version: 3.2.0.96 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.0.0.0 - NVIDIA Corporation) Hidden Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7571.2075 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7571.2075 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7571.2075 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7571.2075 - Microsoft Corporation) Hidden paint.net (HKLM\...\{A1D05314-DC32-4668-A97E-51060EC8BCCE}) (Version: 4.0.12 - dotPDN LLC) Paladins (HKLM\...\Steam App 444090) (Version: - Hi-Rez Studios) Planetary Annihilation: TITANS (HKLM\...\Steam App 386070) (Version: - Uber Entertainment) Rainmeter (HKLM-x32\...\Rainmeter) (Version: 4.0 beta r2627 - ) ROBLOX Player for Primitive (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version: - ROBLOX Corporation) ROBLOX Studio for Primitive (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}) (Version: - ROBLOX Corporation) Robocraft (HKLM\...\Steam App 301520) (Version: - Freejam) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.0.5 - Rockstar Games) SHIELD Streaming (Version: 7.1.0350 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.2.0.96 - NVIDIA Corporation) Hidden Skype Web Plugin (HKLM-x32\...\{E8A70371-2C4D-4B12-831D-6A4BB9AC7AEF}) (Version: 7.29.0.73 - Skype Technologies S.A.) SMITE (HKLM\...\Steam App 386360) (Version: - Hi-Rez Studios) Spotify (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\Spotify) (Version: 1.0.45.186.g3b5036d6 - Spotify AB) The Isle (HKLM\...\Steam App 376210) (Version: - The Isle Development Team) Totally Accurate Battle Simulator Pre-Alpha (HKLM\...\Steam App 527140) (Version: - ) UE4 Prerequisites (x64) (Version: 1.0.10.0 - Epic Games, Inc.) Hidden Uplay (HKLM-x32\...\Uplay) (Version: 24.0.1 - Ubisoft) Vulkan Run Time Libraries 1.0.17.0 (HKLM\...\VulkanRT1.0.17.0) (Version: 1.0.17.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) Warframe (HKLM\...\Steam App 230410) (Version: - Digital Extremes) WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-233390903-2661952563-451428824-1001_Classes\CLSID\{A03A51A2-5B59-4ECE-96D1-037F7F2A0D8F}\localserver32 -> C:\Users\Primitive\AppData\Local\SkypePlugin\7.29.0.73\GatewayVersion-x64.exe (Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-233390903-2661952563-451428824-1001_Classes\CLSID\{CBF9CD8C-2714-4F36-B76A-43E6C7547BC2}\localserver32 -> C:\Users\Primitive\AppData\Local\SkypePlugin\7.29.0.73\EdgeCalling.exe (Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-233390903-2661952563-451428824-1001_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Primitive\AppData\Local\Roblox\Versions\version-7d9c06d298534e0c\RobloxProxy64.dll (ROBLOX Corporation) CustomCLSID: HKU\S-1-5-21-233390903-2661952563-451428824-1001_Classes\CLSID\{FE0A3EA9-4DDA-4B0A-9981-5ABE8F0186CD}\InprocServer32 -> C:\Users\Primitive\AppData\Local\SkypePlugin\7.29.0.73\GatewayActiveX-x64.dll (Skype Technologies S.A.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {261E3E8C-3AD7-4C4D-8AA9-783CF4434369} - \{090E0447-0D79-7F0A-7D11-0B0F7A791178} -> No File <==== ATTENTION Task: {30720EBD-6B23-4480-AFBE-9301DD8129A6} - \NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> No File <==== ATTENTION Task: {33F94D7B-F333-4652-91FA-6DEDBD484C6F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-12-04] (Microsoft Corporation) Task: {36B00A86-14C3-41A7-B53D-1E7ADF3EF867} - \AutoKMS -> No File <==== ATTENTION Task: {3F39F139-E558-49F2-94D9-5443E998C7DA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-10] (Google Inc.) Task: {593081F6-0B89-44E8-A793-DBCE99D670AA} - \NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> No File <==== ATTENTION Task: {65B50D4F-1AFF-436B-BC6B-F129C6A6B586} - \KMSAutoNet -> No File <==== ATTENTION Task: {66E21683-3ABA-4D5F-B96A-97B64E81E6F5} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe Task: {7383467A-0086-47BF-9D1E-AF2040F0A486} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-12-04] (Microsoft Corporation) Task: {777CF6EA-4249-47B6-A683-FE7135473D41} - \{2287B3D0-B907-4177-80BB-5FF6B8136810} -> No File <==== ATTENTION Task: {7BE3CD3D-2966-494B-9D5B-EE9F43376DBD} - \NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> No File <==== ATTENTION Task: {7BFCBED3-6172-418D-822F-D113AB470B5B} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-12-04] (Microsoft Corporation) Task: {800E8A36-B17F-4F95-A64F-A647CB2FEA69} - \NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> No File <==== ATTENTION Task: {92D0F9B2-3C39-4259-B432-4F5395A54F00} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-12-04] (Microsoft Corporation) Task: {98F0C1B4-71B1-47FA-B3F0-F6E691D23212} - \NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> No File <==== ATTENTION Task: {A30D90C7-A77F-4157-8682-6BEA2B13BD31} - \SwiftPCOptimizer -> No File <==== ATTENTION Task: {A6004B45-D432-4BF3-88FF-141BF7861078} - \SwiftPCOptimizer_Start -> No File <==== ATTENTION Task: {AC6523D9-CF90-4522-B591-AA44718C9766} - \{112A8B3F-1DAE-489F-8929-1C94F206F211} -> No File <==== ATTENTION Task: {B481EED0-482D-4E11-B005-299A4747938A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-10] (Google Inc.) Task: {B5015F98-BD11-457C-AF42-4257BD35FEFC} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2016-12-04] (Microsoft Corporation) Task: {CC0DC334-27D4-446E-8128-6D1F9DA14A6B} - \NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> No File <==== ATTENTION Task: {CF70B2F2-CFD9-46C0-8D96-34983E96F787} - \NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} -> No File <==== ATTENTION Task: {D8A06427-5D05-4CE1-BE41-5F3886ED06BC} - \{422AEE5F-5505-466A-BA11-DE3F57D65AA8} -> No File <==== ATTENTION Task: {E8283A05-12C4-4092-B1F0-6EDD015C702A} - \{504E3221-1CBB-4D6A-BF66-4695DD06B783} -> No File <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\Users\Primitive\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Intеrnеt Ехplоrеr.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.bat () Shortcut: C:\Users\Primitive\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gооglе Сhrоmе.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat () Shortcut: C:\Users\Primitive\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gооglе Сhrоmе.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Еpiс Gаmеs Lаunсhеr.lnk -> G:\Non-Steam Games\Paragon\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.bat () ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 02:17 - 2015-10-30 02:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll 2015-10-30 02:18 - 2015-10-30 02:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-10-08 14:14 - 2016-12-12 18:36 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll 2016-10-08 14:14 - 2016-12-12 18:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-01-10 21:05 - 2016-12-14 12:55 - 02259232 _____ () G:\ANTI-MALWARE\PoliciesControllerImpl.dll 2016-02-07 00:10 - 2016-12-11 13:47 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-11-08 17:33 - 2016-10-25 04:42 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-11-08 17:33 - 2016-10-25 04:42 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-05-19 19:11 - 2016-05-19 19:11 - 00959168 _____ () C:\Users\Primitive\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll 2016-10-14 22:27 - 2016-12-03 22:04 - 08924872 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2016-04-18 15:14 - 2016-04-18 15:14 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-02-07 02:36 - 2015-12-06 23:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-07-16 18:31 - 2016-06-30 22:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-11-08 17:34 - 2016-10-24 23:49 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-11-08 17:33 - 2016-10-24 23:44 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-11-08 17:34 - 2016-10-24 23:45 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-11-08 17:33 - 2016-10-24 23:48 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-09-12 05:51 - 2016-09-12 05:51 - 00175616 _____ () G:\Rainmeter\Plugins\AudioLevel.DLL 2016-10-08 14:14 - 2016-12-12 18:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-10-08 14:14 - 2016-12-12 18:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll 2016-10-08 14:14 - 2016-12-12 18:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-04-18 15:14 - 2016-04-18 15:14 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-04-18 15:14 - 2016-04-18 15:14 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2016-12-14 23:26 - 2016-12-08 02:29 - 01829208 _____ () C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libglesv2.dll 2016-12-14 23:26 - 2016-12-08 02:29 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libegl.dll 2015-10-30 02:18 - 2015-10-30 02:18 - 00025088 _____ () C:\Windows\SYSTEM32\GamePanelExternalHook.dll 2016-10-09 14:09 - 2016-12-21 18:10 - 51777648 _____ () C:\Users\Primitive\AppData\Roaming\Spotify\libcef.dll 2016-10-09 14:09 - 2016-12-21 18:10 - 01803888 _____ () C:\Users\Primitive\AppData\Roaming\Spotify\libglesv2.dll 2016-10-09 14:09 - 2016-12-21 18:10 - 00086128 _____ () C:\Users\Primitive\AppData\Roaming\Spotify\libegl.dll 2016-10-08 14:14 - 2016-12-12 18:33 - 64245184 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2016-10-08 14:14 - 2016-12-12 09:36 - 00525760 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node 2016-10-08 14:14 - 2016-12-12 09:36 - 00254008 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node 2016-10-08 14:14 - 2016-12-12 09:36 - 02808888 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node 2016-10-08 14:14 - 2016-12-12 09:36 - 00384568 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node 2016-10-08 14:14 - 2016-12-12 09:36 - 00447424 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node 2016-10-08 14:14 - 2016-12-12 09:36 - 00336832 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node 2016-10-08 14:14 - 2016-12-12 09:36 - 01003456 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvCameraAPINode.node 2017-01-01 19:00 - 2016-12-12 09:36 - 00956472 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSDKAPINode.node ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\77684213.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\77684213.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP => ""="service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\google.com -> hxxps://google.com ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-10-30 02:24 - 2017-01-10 01:07 - 00003892 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 down.baidu2016.com 127.0.0.1 123.sogou.com 127.0.0.1 www.czzsyzgm.com 127.0.0.1 www.czzsyzxl.com 127.0.0.1 union.baidu2019.com 127.0.0.1 down.baidu2016.com 127.0.0.1 123.sogou.com 127.0.0.1 www.czzsyzgm.com 127.0.0.1 www.czzsyzxl.com 127.0.0.1 union.baidu2019.com 34.195.153.94 www.google-analytics.com 34.195.153.94 google-analytics.com 34.195.153.94 mc.yandex.ru 34.195.153.94 top-fwz1.mail.ru 34.195.153.94 site.yandex.net 34.195.153.94 pagead2.googlesyndication.com 34.195.153.94 ad.mail.ru 34.195.153.94 ads.adfox.ru 34.195.153.94 ads.pubmatic.com 34.195.153.94 apis.google.com 34.195.153.94 autocontext.begun.ru 34.195.153.94 b.scorecardresearch.com 34.195.153.94 c.amazon-adsystem.com 34.195.153.94 cdn.admixer.net 34.195.153.94 cdn.cxense.com 34.195.153.94 cdn.livefyre.com 34.195.153.94 cdn.onthe.io 34.195.153.94 cdn.optimizely.com 34.195.153.94 cdn.prom.st 34.195.153.94 cdn.pushwoosh.com There are 59 more lines. ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-233390903-2661952563-451428824-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Primitive\Pictures\big_a0f1f3bcc1f601603a7746e051ce85bc5ad4239a.jpg DNS Servers: 8.8.8.8 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\StartupApproved\Run: => "Steam" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => LPort=139 FirewallRules: [{623EAC45-1598-4EEE-BD2F-C554D19FAA58}] => C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{882D562F-D8CF-47F0-91D5-5FF20B26E4D6}] => C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{7F32F6EE-7D5A-4F87-890D-C43E6E5B1D6B}] => G:\Steam\Steam.exe FirewallRules: [{37B62C7A-6269-448C-B0F0-C5F4DD354D39}] => G:\Steam\Steam.exe FirewallRules: [{62D0C5AA-BAC2-46E9-875E-4A481824893A}] => G:\Steam\bin\steamwebhelper.exe FirewallRules: [{13C2835A-1846-4F6B-8DBB-D5013C3538E6}] => G:\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{0DB0ECE8-19E6-4A88-938C-7A7268B91FE9}C:\windows.old\users\primitive\appdata\roaming\utorrent\utorrent.exe] => C:\windows.old\users\primitive\appdata\roaming\utorrent\utorrent.exe FirewallRules: [UDP Query User{DE87E032-962F-4070-80E1-0F26707C370F}C:\windows.old\users\primitive\appdata\roaming\utorrent\utorrent.exe] => C:\windows.old\users\primitive\appdata\roaming\utorrent\utorrent.exe FirewallRules: [{3BE3CC7F-5208-4A7A-9370-F7489620C90D}] => G:\Steam\SteamApps\common\Team Fortress 2\hl2.exe FirewallRules: [{C05D3BA1-4DD2-4A84-BEA8-3190A1941055}] => G:\Steam\SteamApps\common\Team Fortress 2\hl2.exe FirewallRules: [{E12D0410-C1CD-4A84-9D2B-A549A6FE2C42}] => C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{66C4B93B-2AA9-4B9B-8CBD-B461DFB712E2}G:\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => G:\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [UDP Query User{3908B23D-06E8-409A-955B-5EB59B18597B}G:\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => G:\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [TCP Query User{450E2008-E396-433A-A2C2-A8DD4DA0B3CE}G:\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => G:\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [UDP Query User{44F09366-8258-4497-AE39-AAF7A7B95146}G:\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => G:\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [{A0E6F6F2-A76C-4190-A05C-EEC139D4A3A9}] => G:\Steam\SteamApps\common\primal_carnage\Binaries\Win32\PrimalCarnageGame.exe FirewallRules: [{436E6A5A-63DA-466D-97E6-04584B352F1B}] => G:\Steam\SteamApps\common\primal_carnage\Binaries\Win32\PrimalCarnageGame.exe FirewallRules: [{AF18843B-D775-4C5B-961C-E4BE8E0D4D85}] => G:\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{C2B76408-6377-4C86-8CA0-23DC44A17D81}] => G:\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{DFDDC1C2-D40E-452E-BA03-AD93719A722A}] => G:\Steam\SteamApps\common\The Isle\TheIsle.exe FirewallRules: [{0C7AE528-35AA-4CA9-BEEF-9273410642C4}] => G:\Steam\SteamApps\common\The Isle\TheIsle.exe FirewallRules: [TCP Query User{F94CD4E5-A551-4850-AC31-08A71433FA3E}G:\epic games\4.10\engine\binaries\win64\ue4editor.exe] => G:\epic games\4.10\engine\binaries\win64\ue4editor.exe FirewallRules: [UDP Query User{4CCE744F-9643-4D7F-8D50-08A1F5F83204}G:\epic games\4.10\engine\binaries\win64\ue4editor.exe] => G:\epic games\4.10\engine\binaries\win64\ue4editor.exe FirewallRules: [TCP Query User{F2230469-9934-4F74-B6BB-F29B3E279064}G:\epic games\4.10\engine\binaries\dotnet\swarmagent.exe] => G:\epic games\4.10\engine\binaries\dotnet\swarmagent.exe FirewallRules: [UDP Query User{E1999BC2-8EC4-468A-BC7F-0D0176ADE6A1}G:\epic games\4.10\engine\binaries\dotnet\swarmagent.exe] => G:\epic games\4.10\engine\binaries\dotnet\swarmagent.exe FirewallRules: [TCP Query User{50BD045B-6C86-48A8-9D48-AB6236D94929}G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle.exe] => G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle.exe FirewallRules: [UDP Query User{4E1303C0-EB98-4B48-BF1D-4B79547B8D25}G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle.exe] => G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle.exe FirewallRules: [TCP Query User{212B39BF-7C90-4A18-A2A0-49AEE8CBB838}G:\non-steam games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe] => G:\non-steam games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe FirewallRules: [UDP Query User{73721E6F-4821-40A6-92A7-4A410A50DD18}G:\non-steam games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe] => G:\non-steam games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe FirewallRules: [{0CC94886-5F31-440B-8375-8650C49219BA}] => G:\Steam\SteamApps\common\GarrysMod\hl2.exe FirewallRules: [{1327FD25-DABA-4F25-8721-6FF3482ABA8E}] => G:\Steam\SteamApps\common\GarrysMod\hl2.exe FirewallRules: [TCP Query User{23BC6235-E46E-443A-A509-DBB2C0214867}C:\users\primitive\appdata\local\roblox\versions\version-d0ea8fd26e144a48\robloxstudiobeta.exe] => C:\users\primitive\appdata\local\roblox\versions\version-d0ea8fd26e144a48\robloxstudiobeta.exe FirewallRules: [UDP Query User{7A57483F-0EDC-4AAA-8F16-7E6225D68E64}C:\users\primitive\appdata\local\roblox\versions\version-d0ea8fd26e144a48\robloxstudiobeta.exe] => C:\users\primitive\appdata\local\roblox\versions\version-d0ea8fd26e144a48\robloxstudiobeta.exe FirewallRules: [{8BC5D79D-ECCB-4824-9964-F2E73A249C60}] => C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe FirewallRules: [{0E2B86AF-644D-43C9-9426-2B434A9EC1DA}] => C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe FirewallRules: [{37A44789-887F-4CA6-8ACF-C952769083E9}] => C:\Users\Primitive\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{2031FA55-552B-4B93-A5AE-72E51F6A14C1}] => C:\Users\Primitive\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [TCP Query User{477E4D73-E14F-4979-BA4E-463E509A435C}C:\users\primitive\appdata\local\temp\rar$exa0.688\microsoft toolkit.exe] => C:\users\primitive\appdata\local\temp\rar$exa0.688\microsoft toolkit.exe FirewallRules: [UDP Query User{1B6BC57A-E430-4B42-B2D2-6D16FA5FEBD0}C:\users\primitive\appdata\local\temp\rar$exa0.688\microsoft toolkit.exe] => C:\users\primitive\appdata\local\temp\rar$exa0.688\microsoft toolkit.exe FirewallRules: [TCP Query User{6C500A62-A08C-4EA0-96B7-7D3CCD8E02C0}C:\users\primitive\appdata\local\temp\rar$exa0.979\microsoft toolkit.exe] => C:\users\primitive\appdata\local\temp\rar$exa0.979\microsoft toolkit.exe FirewallRules: [UDP Query User{45C7D1CE-847C-42D9-A580-3607B07097F0}C:\users\primitive\appdata\local\temp\rar$exa0.979\microsoft toolkit.exe] => C:\users\primitive\appdata\local\temp\rar$exa0.979\microsoft toolkit.exe FirewallRules: [TCP Query User{F3520FB5-F1CC-4074-87DE-5CF415688408}C:\users\primitive\appdata\local\temp\rar$exa0.958\microsoft toolkit.exe] => C:\users\primitive\appdata\local\temp\rar$exa0.958\microsoft toolkit.exe FirewallRules: [UDP Query User{8B4AD559-39E8-4A1D-96C8-F4410E45AF2A}C:\users\primitive\appdata\local\temp\rar$exa0.958\microsoft toolkit.exe] => C:\users\primitive\appdata\local\temp\rar$exa0.958\microsoft toolkit.exe FirewallRules: [{97E16202-4044-4F0F-9BF2-84A496F9CD3C}] => 㩃停潲牧浡䘠汩獥⠠㡸⤶睜湩牤癩略敳睜湩牤癩略敳攮數 FirewallRules: [{E5FB93B2-C21A-4215-90F2-2B657ABA1B03}] => 㩃停潲牧浡䘠汩獥⠠㡸⤶睜湩牤癩略敳睜湩牤癩略敳⹟硥e FirewallRules: [TCP Query User{826E5577-F48E-48C4-B788-4237C7C64054}C:\users\primitive\desktop\igg-huniecam.studio\huniecamstudio.exe] => C:\users\primitive\desktop\igg-huniecam.studio\huniecamstudio.exe FirewallRules: [UDP Query User{8EE5BE3A-F201-4B23-92EA-00303D2F81B9}C:\users\primitive\desktop\igg-huniecam.studio\huniecamstudio.exe] => C:\users\primitive\desktop\igg-huniecam.studio\huniecamstudio.exe FirewallRules: [TCP Query User{71689633-D477-4FA3-93C7-39DBD8D16D0B}C:\users\primitive\desktop\stuff\huniecamstudio.exe] => C:\users\primitive\desktop\stuff\huniecamstudio.exe FirewallRules: [UDP Query User{27419A28-CEAF-4934-9067-F9E56798A149}C:\users\primitive\desktop\stuff\huniecamstudio.exe] => C:\users\primitive\desktop\stuff\huniecamstudio.exe FirewallRules: [TCP Query User{6BB72CFE-E6C9-488E-AFF8-4C42BB966AD3}G:\non-steam games\hearthstone\hearthstone.exe] => G:\non-steam games\hearthstone\hearthstone.exe FirewallRules: [UDP Query User{B6347567-B904-4E85-8E5E-D12FE7AD6B69}G:\non-steam games\hearthstone\hearthstone.exe] => G:\non-steam games\hearthstone\hearthstone.exe FirewallRules: [TCP Query User{0B7EA474-5A25-4B8A-B994-1513540C3243}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [UDP Query User{A2A64718-D7CE-425D-8560-15ABFD84E229}C:\program files (x86)\overwatch\overwatch.exe] => C:\program files (x86)\overwatch\overwatch.exe FirewallRules: [TCP Query User{7736D49B-8E9F-4C87-855D-E2A19BCCB59C}G:\new folder\heroes of the storm\versions\base42273\heroesofthestorm_x64.exe] => G:\new folder\heroes of the storm\versions\base42273\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{1B00BB64-BBE7-49F4-B690-75EF262E2C5E}G:\new folder\heroes of the storm\versions\base42273\heroesofthestorm_x64.exe] => G:\new folder\heroes of the storm\versions\base42273\heroesofthestorm_x64.exe FirewallRules: [{F11A6418-583B-4BF4-BBB3-D99BBB3B311F}] => G:\Steam\SteamApps\common\Depth\Binaries\Win32\DepthGame.exe FirewallRules: [{F3B40AAB-4713-4A2E-A857-1DD7013ACAAC}] => G:\Steam\SteamApps\common\Depth\Binaries\Win32\DepthGame.exe FirewallRules: [TCP Query User{1A7FB639-11ED-46E5-8932-FA17C6FC5D7E}G:\steam\steamapps\common\the orion project\orion\binaries\win64\orion-win64-shipping.exe] => G:\steam\steamapps\common\the orion project\orion\binaries\win64\orion-win64-shipping.exe FirewallRules: [UDP Query User{A5C8EBCC-699E-4F6F-BFD8-BF07593D6353}G:\steam\steamapps\common\the orion project\orion\binaries\win64\orion-win64-shipping.exe] => G:\steam\steamapps\common\the orion project\orion\binaries\win64\orion-win64-shipping.exe FirewallRules: [{2E6C0288-6D7C-4326-AEB4-EAD4FC13974A}] => C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{38366E24-9DD0-49C6-B75F-B82810C36C0A}] => LPort=2869 FirewallRules: [{933CF27E-CDC8-46C2-8C32-54C742A26086}] => LPort=1900 FirewallRules: [TCP Query User{554E64E0-949D-48E5-A53D-1F12FD8B9D3E}G:\new folder\overwatch\overwatch.exe] => G:\new folder\overwatch\overwatch.exe FirewallRules: [UDP Query User{E374850A-708E-450A-8CC5-5F768F4CBE08}G:\new folder\overwatch\overwatch.exe] => G:\new folder\overwatch\overwatch.exe FirewallRules: [TCP Query User{7B59F884-D077-4E88-933A-49C257DDC5CB}G:\steam\steamapps\common\portal stories mel\portal2.exe] => G:\steam\steamapps\common\portal stories mel\portal2.exe FirewallRules: [UDP Query User{59D5B39E-1025-43EC-8E88-92C45153DA04}G:\steam\steamapps\common\portal stories mel\portal2.exe] => G:\steam\steamapps\common\portal stories mel\portal2.exe FirewallRules: [TCP Query User{A034A264-0945-466C-B892-5A5228B0651D}G:\5kplayer\5kplayer.exe] => G:\5kplayer\5kplayer.exe FirewallRules: [UDP Query User{C5F98DCB-D2DA-4B11-9343-035AE2F2AB7F}G:\5kplayer\5kplayer.exe] => G:\5kplayer\5kplayer.exe FirewallRules: [TCP Query User{1BDF9A2F-CD29-4E5E-A082-C38AF929DAE3}G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle-win64-shipping.exe] => G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle-win64-shipping.exe FirewallRules: [UDP Query User{7613A658-F25F-4404-8E58-F5EA70D316C2}G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle-win64-shipping.exe] => G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle-win64-shipping.exe FirewallRules: [{8A0F9ABD-4B7B-4B99-BBD7-A0C569DE9D3C}] => LPort=3724 FirewallRules: [{2FDD3BE2-9AE2-4E50-87D5-C75A81102691}] => LPort=80 FirewallRules: [{64B5E32C-9C1B-46CD-B0C0-AF4960C6BA50}] => LPort=3724 FirewallRules: [{0F99289A-A5F7-422C-9402-3B7926840156}] => G:\Steam\SteamApps\common\Guns of Icarus Online\GunsOfIcarusOnline.exe FirewallRules: [{D062639C-BE7D-4157-9324-71092FA90889}] => G:\Steam\SteamApps\common\Guns of Icarus Online\GunsOfIcarusOnline.exe FirewallRules: [{E0E46D31-D846-433F-93BB-C40904D76206}] => G:\Steam\SteamApps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{6D25C008-C437-4F1F-BDB4-836EB6CD91C7}] => G:\Steam\SteamApps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [TCP Query User{63443DFF-2AB7-43C1-8214-30B975D2C89E}G:\steam\steamapps\common\grand theft auto v\gta5.exe] => G:\steam\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [UDP Query User{5570ED2F-A868-4505-8D6F-AF68B4627C86}G:\steam\steamapps\common\grand theft auto v\gta5.exe] => G:\steam\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [{932D63EC-38F6-4AE0-9D77-51B8E11419A7}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\PA.exe FirewallRules: [{8B4BD4CE-9BC1-4122-84CD-E06FC899FDFD}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\PA.exe FirewallRules: [{A97DEDDE-8734-44C5-8468-66F39BBE8CF0}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\PA.exe FirewallRules: [{F5F33787-D7C4-4739-948D-4CF5489C3196}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\PA.exe FirewallRules: [{699B12A2-F38A-45F5-90A0-C0D6FA07048C}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\crashupload.exe FirewallRules: [{0A946021-97EC-4123-8B35-3F540E4C0B87}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\crashupload.exe FirewallRules: [{2532257F-66FE-4A7F-B558-7DEB53E91923}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\host\CoherentUI_Host.exe FirewallRules: [{E847E4B7-F8CA-40EF-BE4E-7178535D8AFF}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\host\CoherentUI_Host.exe FirewallRules: [{0689DDDF-B42B-4EE1-97E3-C93CB1769EC1}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\crashupload.exe FirewallRules: [{A6FE3A00-4642-44DB-A8E7-6DC7EDC91103}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\crashupload.exe FirewallRules: [{2860814A-C858-435B-93FF-CAEAF06283E5}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\host\CoherentUI_Host.exe FirewallRules: [{B71182B9-2FF4-4350-A587-12661B101AE2}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\host\CoherentUI_Host.exe FirewallRules: [{D7323373-425E-4712-9CAF-B9EAAA0BD3BD}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\server.exe FirewallRules: [{2FC5CCF0-1EBA-4F2E-AEF2-3564E3BE2089}] => G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\server.exe FirewallRules: [{8599F9E1-4132-4FCE-9E2A-134AF4221A9F}] => C:\Program Files (x86)\Java\jre1.8.0_91\bin\java.exe FirewallRules: [{8491AA07-3E7C-4D2C-970F-6DDD8647E6E2}] => C:\Program Files (x86)\Java\jre1.8.0_91\bin\java.exe FirewallRules: [{680C8538-AB76-4C9D-AA64-88528517232B}] => C:\Users\Primitive\Ubiquiti UniFi\bin\mongod.exe FirewallRules: [{90022BBC-7821-4A38-8499-7D4720C7F399}] => C:\Users\Primitive\Ubiquiti UniFi\bin\mongod.exe FirewallRules: [TCP Query User{70314229-B02C-47BC-803D-36EAD79CB19E}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [UDP Query User{809CF0FE-0CFC-43F4-8B08-DE1EA5404EC2}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [TCP Query User{0A4BB1E4-2739-45A6-9B44-7574F239D6FE}G:\new folder\overwatch test\overwatch.exe] => G:\new folder\overwatch test\overwatch.exe FirewallRules: [UDP Query User{1EE99792-B9F5-4336-B6A4-67CDE297D939}G:\new folder\overwatch test\overwatch.exe] => G:\new folder\overwatch test\overwatch.exe FirewallRules: [TCP Query User{A731D180-3785-4690-B244-8E072AACA54B}C:\users\primitive\appdata\local\roblox\versions\version-ff140f5bd46141f7\robloxstudiobeta.exe] => C:\users\primitive\appdata\local\roblox\versions\version-ff140f5bd46141f7\robloxstudiobeta.exe FirewallRules: [UDP Query User{7890BBC5-C71C-45FC-90CA-F355C715C194}C:\users\primitive\appdata\local\roblox\versions\version-ff140f5bd46141f7\robloxstudiobeta.exe] => C:\users\primitive\appdata\local\roblox\versions\version-ff140f5bd46141f7\robloxstudiobeta.exe FirewallRules: [{85A541F6-343A-415C-B0CC-41F490595474}] => G:\Steam\SteamApps\common\Evolve\Bin64_SteamRetail\Evolve.exe FirewallRules: [{B3306EE5-DEE6-4CDA-B7FE-EF05D863260D}] => G:\Steam\SteamApps\common\Evolve\Bin64_SteamRetail\Evolve.exe FirewallRules: [TCP Query User{6134967A-DD57-43EE-9C37-B49E9B734E02}G:\new folder\starcraft ii\versions\base44983\sc2_x64.exe] => G:\new folder\starcraft ii\versions\base44983\sc2_x64.exe FirewallRules: [UDP Query User{D7997AEA-89B2-4C2D-8D18-197288A3B3D6}G:\new folder\starcraft ii\versions\base44983\sc2_x64.exe] => G:\new folder\starcraft ii\versions\base44983\sc2_x64.exe FirewallRules: [TCP Query User{A3F2F9DB-7E59-4228-B86B-90275A4CECC1}G:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => G:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [UDP Query User{72E3CBF9-EA97-42BF-AEBB-C409E5EAE144}G:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => G:\steam\steamapps\common\awesomenauts\awesomenauts.exe FirewallRules: [{3B8D63DA-0833-4E16-BE91-63E7C504F10C}] => G:\Steam\SteamApps\common\The Isle\TheIsle\Binaries\Win64\TheIsle_BE.exe FirewallRules: [{DE49DA0C-1164-4AA1-9383-0BC2C72AFA7D}] => G:\Steam\SteamApps\common\The Isle\TheIsle\Binaries\Win64\TheIsle_BE.exe FirewallRules: [{53EF9765-8F3F-4CE0-891F-6ABD0BCCF0CA}] => G:\Steam\SteamApps\common\Robocraft\Robocraft.exe FirewallRules: [{BA877EC9-C8B6-482F-8301-28A60C63338D}] => G:\Steam\SteamApps\common\Robocraft\Robocraft.exe FirewallRules: [{F4B04EE7-CE5B-43A7-B020-7300ED880910}] => C:\Users\Primitive\AppData\Local\Temp\QQVipDownloader\mhfc_1471404134_46113\MiniQQDL.exe FirewallRules: [{4CD296B7-581C-4259-BACC-6CD4A284EF77}] => C:\Users\Primitive\AppData\Local\Temp\QQVipDownloader\mhfc_1471404134_46113\MiniQQDL.exe FirewallRules: [TCP Query User{50C74FB9-13D1-4C0F-B363-2C3454C39C2F}C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1471404134_46113\teniodl.exe] => C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1471404134_46113\teniodl.exe FirewallRules: [UDP Query User{4E57BD46-5D4B-4445-BEAE-89D68AF55E29}C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1471404134_46113\teniodl.exe] => C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1471404134_46113\teniodl.exe FirewallRules: [{DE1E98E7-D7D7-4D9A-B4D2-13432A2B5137}] => G:\MHO_Setup_1.0.10.281.exe FirewallRules: [{AA64C9C3-345B-45A6-B70C-0160C707B77D}] => C:\Users\Primitive\AppData\Roaming\Tencent\怪物猎人Online\B0DEBE954B4E9315DB8B362D20D3CDBB\TenioDL\teniodl.exe FirewallRules: [{67205B16-3A61-4047-AD66-C2BCE10F7EBC}] => C:\Users\Primitive\AppData\Roaming\Tencent\怪物猎人Online\B0DEBE954B4E9315DB8B362D20D3CDBB\TenioDL\teniodl.exe FirewallRules: [{DB59E90A-56E4-420D-9F34-A77FFD35A498}] => C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe FirewallRules: [{FC74637D-B211-4EFB-AEE3-CACE48FDDBDC}] => C:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe FirewallRules: [{9640D995-3E8B-4B47-B24E-D1DF382E7A36}] => G:\New folder (2)\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe FirewallRules: [{CEDE9F51-5B8F-4CCD-B830-73E73E7F7A8E}] => G:\New folder (2)\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe FirewallRules: [{40741CA0-A58F-4341-AD44-A15FEC3B0B70}] => G:\New folder (2)\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe FirewallRules: [{3A379FC4-8321-492C-AB7E-F9C97A82FA62}] => G:\New folder (2)\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe FirewallRules: [TCP Query User{01336705-8EAD-4B36-BF65-D9C44FA9FEBC}G:\new folder (2)\monster hunter online\bin\client\bin32\mhoclient.exe] => G:\new folder (2)\monster hunter online\bin\client\bin32\mhoclient.exe FirewallRules: [UDP Query User{3B9A6431-CFC2-4DC3-A89B-53215014C478}G:\new folder (2)\monster hunter online\bin\client\bin32\mhoclient.exe] => G:\new folder (2)\monster hunter online\bin\client\bin32\mhoclient.exe FirewallRules: [{B1FE646A-C2FB-45D2-A8E9-CB422DB1CCAC}] => G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe FirewallRules: [{91C7C2FF-6B69-4EE3-84A5-D879D600722F}] => G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe FirewallRules: [{CCCB8CA6-598C-4530-947B-AAB3BDF7AAE3}] => G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe FirewallRules: [{29501E58-6243-482A-991A-4846F989EE04}] => G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe FirewallRules: [{B72F9913-9157-41F6-86AA-209D85553F52}] => G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\apps\cqs\qtalk\bin\miniqtalk.exe FirewallRules: [{AD359F3F-BDBE-4180-A8BD-DD70B3A26389}] => G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\apps\cqs\qtalk\bin\miniqtalk.exe FirewallRules: [{1B669228-ECC6-4BD2-8A6F-5F16E4BB126A}] => G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\apps\cqs\qtalk\bin\miniqtalk.exe FirewallRules: [{F5F2B9C2-95EF-439B-9CF3-52C59EC8258F}] => G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\apps\cqs\qtalk\bin\miniqtalk.exe FirewallRules: [{8FA1724F-947C-4FC9-9301-ADCAD47CC4DB}] => G:\Steam\SteamApps\common\TABS_ALPHA\TotallyAccurateBattleSimulator.exe FirewallRules: [{6BF072C4-ECC9-4CBE-8325-B81AED956B94}] => G:\Steam\SteamApps\common\TABS_ALPHA\TotallyAccurateBattleSimulator.exe FirewallRules: [{8BB566BA-8A39-4637-8D31-976C6E99F7CA}] => G:\Steam\SteamApps\common\Paladins\Binaries\Win32\HirezBridge.exe FirewallRules: [{B87226CC-F875-41D2-9274-8222F42F1320}] => G:\Steam\SteamApps\common\Paladins\Binaries\Win32\HirezBridge.exe FirewallRules: [TCP Query User{4EE97130-FC57-4E76-AC59-99C458FA3C80}G:\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => G:\steam\steamapps\common\paladins\binaries\win32\paladins.exe FirewallRules: [UDP Query User{5B808CD5-68F6-496E-B030-D5313FC11F38}G:\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => G:\steam\steamapps\common\paladins\binaries\win32\paladins.exe FirewallRules: [TCP Query User{9E7CC219-9CB1-4CD5-9335-EBE8533250B9}G:\non-steam games\overwatch\overwatch\overwatch.exe] => G:\non-steam games\overwatch\overwatch\overwatch.exe FirewallRules: [UDP Query User{239FFC90-287E-495D-AB59-7FC23145B069}G:\non-steam games\overwatch\overwatch\overwatch.exe] => G:\non-steam games\overwatch\overwatch\overwatch.exe FirewallRules: [{58497E58-8543-4AF6-BF1A-C796522D7DA6}] => C:\Program Files\Echobit\Evolve\EvoSvc.exe FirewallRules: [{47E63243-0844-48FE-9178-FAC61F31B063}] => C:\Program Files\Echobit\Evolve\EvolveClient.exe FirewallRules: [TCP Query User{C30F45C8-7A7E-43BA-9AAA-5A0A299DA24C}G:\non-steam games\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => G:\non-steam games\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{E2717E1C-8DA8-449D-A315-2559FA37A472}G:\non-steam games\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => G:\non-steam games\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{01F09A5D-56CE-4C06-B469-C085C6012A5F}C:\program files (x86)\java\jre1.8.0_101\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_101\bin\javaw.exe FirewallRules: [UDP Query User{80F297EA-BC13-4FB9-8DDF-2A331DAFCC40}C:\program files (x86)\java\jre1.8.0_101\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_101\bin\javaw.exe FirewallRules: [{61721D0C-C71A-426C-B802-0B547DC1B72F}] => G:\Steam\SteamApps\common\SMITE\Binaries\Win32\HirezBridge.exe FirewallRules: [{43ACBCD6-DF48-4705-9F58-0FFE049BB002}] => G:\Steam\SteamApps\common\SMITE\Binaries\Win32\HirezBridge.exe FirewallRules: [TCP Query User{F8CE015C-4705-49BB-9DAF-76AAF36EF185}G:\steam\steamapps\common\smite\binaries\win32\smite.exe] => G:\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [UDP Query User{395F18A2-BD53-4597-8E8F-3E6B097674BF}G:\steam\steamapps\common\smite\binaries\win32\smite.exe] => G:\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [{9CEF9ED1-1338-4485-8D6D-1179EC70FDA3}] => G:\Steam\SteamApps\common\ClusterTruck\Clustertruck.exe FirewallRules: [{B81A4465-DE02-478B-B2D9-E4AB64D227FA}] => G:\Steam\SteamApps\common\ClusterTruck\Clustertruck.exe FirewallRules: [{C5FEAB5F-ED17-42C6-93BF-7AB26DB81BA5}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{72E2569E-16E8-4425-88AC-00603841CFFC}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{45330A66-5327-4487-8F80-32299908671A}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{3C099841-F916-4F42-9021-A854C1357C97}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [TCP Query User{9220A0FA-B81F-4D45-AC6A-044F0B6CF166}C:\users\primitive\appdata\roaming\spotify\spotify.exe] => C:\users\primitive\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{3C4E80F4-A092-4CB6-B540-A86C8952ABEF}C:\users\primitive\appdata\roaming\spotify\spotify.exe] => C:\users\primitive\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{B710C0C4-08D9-4145-BE07-866286CB2C00}G:\non-steam games\overwatch\overwatch test\overwatch.exe] => G:\non-steam games\overwatch\overwatch test\overwatch.exe FirewallRules: [UDP Query User{5F375B40-602F-416C-BAA3-3EF955EBE04A}G:\non-steam games\overwatch\overwatch test\overwatch.exe] => G:\non-steam games\overwatch\overwatch test\overwatch.exe FirewallRules: [{33153EA4-8120-4115-92CE-6BF18BA639F2}] => C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{2B9A0DD5-F582-4889-9535-849B35C83F43}] => C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{17839E54-88C3-47D1-A7A0-01D3012CED39}] => G:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe FirewallRules: [{72A80336-7300-4FDE-A344-9853CE2CCB18}] => G:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe FirewallRules: [{4D705E32-6B9B-47B0-9186-E328FEC23B20}] => G:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe FirewallRules: [{98ED55A4-A4DA-4C4F-9BEF-37A596F6AFD4}] => G:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe FirewallRules: [{0AAF8FD3-D5E6-47BD-AE05-B74BAB84B9F1}] => G:\Steam\SteamApps\common\Golf With Your Friends\Golf With Your Friends.exe FirewallRules: [{4677494E-ED85-4AA0-A66D-902FBE60FB4A}] => G:\Steam\SteamApps\common\Golf With Your Friends\Golf With Your Friends.exe FirewallRules: [{E4C68492-42B1-4604-915F-21EAAD919D23}] => G:\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe FirewallRules: [{CFA6BAC5-80B5-47DE-BF2D-209F657C615E}] => G:\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe FirewallRules: [{788EBD02-A83A-489C-9813-CF080BEFB30F}] => C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [TCP Query User{0B5233E7-8472-4AC6-8565-AD80C46D3885}C:\program files (x86)\battle.net\battle.net.8098\battle.net.exe] => C:\program files (x86)\battle.net\battle.net.8098\battle.net.exe FirewallRules: [UDP Query User{401DF6F8-8DC1-4ACB-8AD5-ABCD9EC01CAB}C:\program files (x86)\battle.net\battle.net.8098\battle.net.exe] => C:\program files (x86)\battle.net\battle.net.8098\battle.net.exe FirewallRules: [TCP Query User{DE649370-1ED2-4595-BCD2-B0A032E1640E}G:\non-steam games\heroes of the storm\versions\base47479\heroesofthestorm_x64.exe] => G:\non-steam games\heroes of the storm\versions\base47479\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{4805A180-E9B2-49F8-AA75-0D4C081DFB89}G:\non-steam games\heroes of the storm\versions\base47479\heroesofthestorm_x64.exe] => G:\non-steam games\heroes of the storm\versions\base47479\heroesofthestorm_x64.exe FirewallRules: [TCP Query User{DAE0D35D-7DB3-41D4-9723-ED957BB53903}G:\non-steam games\paragon\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => G:\non-steam games\paragon\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [UDP Query User{9F098143-7E37-4D90-973B-602A203A55A0}G:\non-steam games\paragon\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => G:\non-steam games\paragon\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [TCP Query User{0B5BB3F9-0A5A-4288-82B7-2353A6C24341}G:\non-steam games\paragon\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => G:\non-steam games\paragon\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [UDP Query User{4F1A7742-DF00-4870-B9B5-C7E64624FE46}G:\non-steam games\paragon\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => G:\non-steam games\paragon\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [TCP Query User{51BC0EDE-9905-4195-84C8-BF8939908167}G:\non-steam games\heroes of the storm\versions\base48027\heroesofthestorm_x64.exe] => G:\non-steam games\heroes of the storm\versions\base48027\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{C15FC5C7-99CF-4E5A-81C4-5A877BDBEE9D}G:\non-steam games\heroes of the storm\versions\base48027\heroesofthestorm_x64.exe] => G:\non-steam games\heroes of the storm\versions\base48027\heroesofthestorm_x64.exe FirewallRules: [TCP Query User{601CBF0E-78FD-4E8C-8772-947FB93CC163}C:\program files (x86)\battle.net\battle.net.8142\battle.net.exe] => C:\program files (x86)\battle.net\battle.net.8142\battle.net.exe FirewallRules: [UDP Query User{4F1CDB89-3C49-433D-86B1-2D5CC565EF99}C:\program files (x86)\battle.net\battle.net.8142\battle.net.exe] => C:\program files (x86)\battle.net\battle.net.8142\battle.net.exe FirewallRules: [{36D44B57-18D0-4CCB-857D-EAD0612ED622}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{A61ED98D-9440-405A-ADB5-1EAEF2939046}] => G:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{6D69BDBC-C579-450C-959A-516BBF68A966}] => G:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{EDF74F32-C9FB-41CB-8C78-D08F9A57FDC2}] => G:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{F1406EE3-FB4E-40B4-BB3C-791F4B8E61EA}] => G:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{A5A8C7D3-2EF3-40DF-B166-6F8856341311}] => G:\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{039CC2A6-8753-4013-81A2-192A59E09349}] => G:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [{76A2E5F8-8DE7-403B-943C-444F76A881A3}] => G:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{8D0D9326-C7CC-49CA-B92A-2066BC8FB3B4}] => G:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{05B77BB7-1039-449D-8CF0-2FE18A7D3B2B}] => G:\Steam\steamapps\common\Warframe\Warframe.exe FirewallRules: [{AAD8536A-C438-4191-8919-10DAB48B0B5B}] => G:\Steam\steamapps\common\Warframe\Warframe.x64.exe FirewallRules: [{35C23D4C-B2E7-4FEE-B85D-A3F57B11B1D2}] => G:\Steam\steamapps\common\Warframe\Tools\Launcher.exe FirewallRules: [{794435CE-BA25-4692-9EF8-FEE00FC5ABC2}] => G:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe FirewallRules: [{06BD6921-70BE-4F1F-9A4F-FC21D6F2519F}] => G:\Steam\SteamApps\common\Deus Ex Mankind Divided\retail\DXMD.exe FirewallRules: [{838F76D9-1920-427F-94F4-5628B0920463}] => G:\Steam\SteamApps\common\Deus Ex Mankind Divided\retail\DXMD.exe FirewallRules: [{8B533F19-34FF-4DCC-8EB9-45195214C599}] => G:\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{8FA91647-E1BB-4C0A-8020-07B890998ED0}] => G:\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [TCP Query User{4D3DDB90-2F38-49FA-A655-293BAACD5A1F}C:\users\primitive\appdata\local\skypeplugin\pluginhost.exe] => C:\users\primitive\appdata\local\skypeplugin\pluginhost.exe FirewallRules: [UDP Query User{DBCE5122-0967-41F0-983B-1BB6E7E6E5B9}C:\users\primitive\appdata\local\skypeplugin\pluginhost.exe] => C:\users\primitive\appdata\local\skypeplugin\pluginhost.exe FirewallRules: [{1B6E1B1F-F750-4039-B29E-8DFD3871CC57}] => G:\Steam\SteamApps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{29450FA5-490D-4E7F-A699-162FB391860C}] => G:\Steam\SteamApps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{F285FC3E-1572-4385-AB56-B7D21DE2B1BE}] => C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{FCB42E26-0AF2-4681-80E8-B3CFA38A5EB1}] => C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [TCP Query User{B6E957B7-7F7D-4B16-8C4F-95446738EDEF}C:\users\primitive\appdata\local\roblox\versions\version-506d9e2f695a4b05\robloxstudiobeta.exe] => C:\users\primitive\appdata\local\roblox\versions\version-506d9e2f695a4b05\robloxstudiobeta.exe FirewallRules: [UDP Query User{854267C1-E051-42CD-8387-E8599E49DFED}C:\users\primitive\appdata\local\roblox\versions\version-506d9e2f695a4b05\robloxstudiobeta.exe] => C:\users\primitive\appdata\local\roblox\versions\version-506d9e2f695a4b05\robloxstudiobeta.exe FirewallRules: [{943EE869-C5BA-4CCA-BDDD-1DDECC84B4F1}] => G:\Steam\SteamApps\common\Guns of Icarus Online\workshop\Workshop.exe FirewallRules: [{8292164D-ED85-4873-879C-44753138903E}] => G:\Steam\SteamApps\common\Guns of Icarus Online\workshop\Workshop.exe FirewallRules: [{A5656CAA-E9E5-4CC3-8A79-9724545EB2FE}] => C:\WINDOWS\system32\rundll32.exe FirewallRules: [{1E2617A2-D5F6-4502-AEE9-D480E007CA65}] => C:\Users\Primitive\AppData\Local\ddnowyes.exe FirewallRules: [{E9588507-2313-4762-A50D-4A9BC832F19B}] => C:\Users\Primitive\AppData\Local\15150554.exe FirewallRules: [{1164D2F8-5ADE-4E91-AE40-363A1857F0D2}] => C:\Users\Primitive\AppData\Local\tinstall.exe FirewallRules: [{3A395A1F-936B-4FF0-8710-ACE9917AC481}] => C:\Users\Primitive\AppData\Local\sc76258249.exe FirewallRules: [{18A66A25-E1E5-4171-B75F-2549447C195D}] => C:\Users\Primitive\AppData\Local\ddnow.exe FirewallRules: [{40FFEEF4-8644-4556-A6C6-AD56BA9C3C94}] => C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe FirewallRules: [{6EBFBA97-8AB9-487C-AE84-C00896D56CF6}] => C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe FirewallRules: [{ECEEF00D-A964-4D2E-B07C-F1416D28C662}] => C:\Program Files (x86)\Hits\omagh.exe FirewallRules: [{CDA10417-98CE-4E1B-A851-8B3AEF1EE378}] => C:\Program Files (x86)\Defects\omagh.exe FirewallRules: [{C14106C9-8997-405B-B721-26E3FE0AEEE1}] => C:\Program Files (x86)\acidosis\popularity.exe FirewallRules: [{46ACFB00-CC12-4F10-BBFE-ADEDCC06C7F2}] => C:\Program Files (x86)\acidosis\hijacking.exe FirewallRules: [{05EA7D8A-7FF5-4521-B9C9-6771B65766F3}] => C:\Program Files (x86)\operant\hoosiers.exe FirewallRules: [{8609F1BC-8209-48BF-BB46-BCE98E4C61C7}] => C:\Program Files (x86)\Ralph\demurrage.exe FirewallRules: [{B5A97146-0EDE-49AC-AABD-AD6F8F0D22A9}] => C:\WINDOWS\cutler.exe FirewallRules: [TCP Query User{C128DD8E-6669-4F8C-A7CC-4CF4B15680EE}C:\program files (x86)\google\chrome\application\chrome334.exe] => C:\program files (x86)\google\chrome\application\chrome334.exe FirewallRules: [UDP Query User{B861456E-70E4-469F-8B4F-7F0BF6105783}C:\program files (x86)\google\chrome\application\chrome334.exe] => C:\program files (x86)\google\chrome\application\chrome334.exe FirewallRules: [{D02A3C86-A7FA-4549-9C2D-96ADE4BFBB83}] => C:\Users\Primitive\AppData\Local\BrowserAir\Application\BrowserairExec.exe FirewallRules: [{C72ABD92-FB33-4512-8D58-7643B959D85F}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= ATTENTION: System Restore is disabled ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/10/2017 09:34:41 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT AUTHORITY) Description: The performance counter name string value in the registry is not formatted correctly. The malformed string is WMI Objects. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (01/10/2017 09:19:23 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT AUTHORITY) Description: The performance counter name string value in the registry is not formatted correctly. The malformed string is WMI Objects. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (01/10/2017 09:07:25 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT AUTHORITY) Description: The performance counter name string value in the registry is not formatted correctly. The malformed string is WMI Objects. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (01/10/2017 09:06:08 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Please use sxstrace.exe for detailed diagnosis. Error: (01/10/2017 09:05:53 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: AvastSvc.exe, version: 12.3.3154.0, time stamp: 0x57b5c39d Faulting module name: ucrtbase.dll, version: 10.0.10586.0, time stamp: 0x5632d166 Exception code: 0xc0000409 Fault offset: 0x0008468b Faulting process id: 0x5d4 Faulting application start time: 0x01d26bae3a97487f Faulting application path: G:\New folder\AvastSvc.exe Faulting module path: C:\WINDOWS\SYSTEM32\ucrtbase.dll Report Id: eec2e6b8-72a6-4973-9afd-0fa103186d3d Faulting package full name: Faulting package-relative application ID: Error: (01/10/2017 09:05:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mbam.exe, version: 3.0.0.865, time stamp: 0x584ee8a0 Faulting module name: Qt5Core.dll, version: 5.6.2.0, time stamp: 0x5849a1dc Exception code: 0xc0000005 Fault offset: 0x00192cf1 Faulting process id: 0x2048 Faulting application start time: 0x01d26baf1d4de796 Faulting application path: G:\Anti-Malware\mbam.exe Faulting module path: G:\Anti-Malware\Qt5Core.dll Report Id: a22db119-c79f-4b68-8106-4eff04ae649c Faulting package full name: Faulting package-relative application ID: Error: (01/10/2017 09:04:47 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT AUTHORITY) Description: The performance counter name string value in the registry is not formatted correctly. The malformed string is WMI Objects. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (01/10/2017 09:03:56 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mbam.exe, version: 3.0.0.865, time stamp: 0x584ee8a0 Faulting module name: Qt5Core.dll, version: 5.6.2.0, time stamp: 0x5849a1dc Exception code: 0xc0000005 Fault offset: 0x00192cf1 Faulting process id: 0x25a8 Faulting application start time: 0x01d26baef5685e91 Faulting application path: G:\Anti-Malware\mbam.exe Faulting module path: G:\Anti-Malware\Qt5Core.dll Report Id: 2f66d9bb-faa4-4abb-9825-dd6fd6fd432d Faulting package full name: Faulting package-relative application ID: Error: (01/10/2017 09:03:45 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.10586.0, time stamp: 0x5632d8f0 Faulting module name: Cortana.BackgroundTask.dll, version: 0.0.0.0, time stamp: 0x580ee351 Exception code: 0xc0000005 Fault offset: 0x0000000000046ab5 Faulting process id: 0x1738 Faulting application start time: 0x01d26baef05d0950 Faulting application path: C:\WINDOWS\system32\backgroundTaskHost.exe Faulting module path: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll Report Id: e9481490-6e32-448e-a6d2-99444c90876f Faulting package full name: Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: CortanaUI Error: (01/10/2017 09:01:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mbam.exe, version: 3.0.0.865, time stamp: 0x584ee8a0 Faulting module name: Qt5Core.dll, version: 5.6.2.0, time stamp: 0x5849a1dc Exception code: 0xc0000005 Fault offset: 0x00192cf1 Faulting process id: 0x242c Faulting application start time: 0x01d26baea3eb65d7 Faulting application path: G:\Anti-Malware\mbam.exe Faulting module path: G:\Anti-Malware\Qt5Core.dll Report Id: ae93e503-6cd0-4148-b52b-29b2ba4ea46b Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (01/10/2017 09:28:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The AppalmaaZ service failed to start due to the following error: The system cannot find the file specified. Error: (01/10/2017 09:28:40 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 9:27:22 PM on ‎1/‎10/‎2017 was unexpected. Error: (01/10/2017 09:27:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The AppalmaaZ service failed to start due to the following error: The system cannot find the file specified. Error: (01/10/2017 09:27:22 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 9:13:30 PM on ‎1/‎10/‎2017 was unexpected. Error: (01/10/2017 09:13:30 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The AppalmaaZ service failed to start due to the following error: The system cannot find the file specified. Error: (01/10/2017 09:13:30 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 8:58:39 PM on ‎1/‎10/‎2017 was unexpected. Error: (01/10/2017 09:05:28 PM) (Source: DCOM) (EventID: 10016) (User: RANY) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user Rany\Primitive SID (S-1-5-21-233390903-2661952563-451428824-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. Error: (01/10/2017 09:05:28 PM) (Source: DCOM) (EventID: 10016) (User: RANY) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user Rany\Primitive SID (S-1-5-21-233390903-2661952563-451428824-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. Error: (01/10/2017 09:05:28 PM) (Source: DCOM) (EventID: 10016) (User: RANY) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user Rany\Primitive SID (S-1-5-21-233390903-2661952563-451428824-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. Error: (01/10/2017 09:05:28 PM) (Source: DCOM) (EventID: 10016) (User: RANY) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user Rany\Primitive SID (S-1-5-21-233390903-2661952563-451428824-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. CodeIntegrity: =================================== Date: 2017-01-10 20:20:45.126 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2017-01-09 21:55:28.712 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2017-01-08 21:07:40.208 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2017-01-02 14:23:36.745 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-12-14 18:59:40.276 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-16 18:20:33.005 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-11 13:25:48.806 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-11 11:25:47.503 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-11 11:18:35.973 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-11-08 19:02:21.101 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4790K CPU @ 4.00GHz Percentage of memory in use: 45% Total physical RAM: 8143.07 MB Available physical RAM: 4419.5 MB Total Virtual: 11471.07 MB Available Virtual: 7549.42 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.01 GB) (Free:0.58 GB) NTFS Drive g: (New Volume) (Fixed) (Total:931.39 GB) (Free:397.89 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: E8FD8D51) Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=111 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt ============================