Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-10-2017 Ran by [removed] (23-10-2017 04:05:09) Running from C:\Users\[removed]\Desktop Windows 10 Pro Version 1607 14393.1770 (X64) (2016-09-29 13:41:37) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3154826165-2591789761-3766887662-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3154826165-2591789761-3766887662-503 - Limited - Disabled) Guest (S-1-5-21-3154826165-2591789761-3766887662-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3154826165-2591789761-3766887662-1004 - Limited - Enabled) Lucas (S-1-5-21-3154826165-2591789761-3766887662-1001 - Administrator - Enabled) => C:\Users\Lucas Luucas (S-1-5-21-3154826165-2591789761-3766887662-1020 - Limited - Enabled) => C:\Users\purpl ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) @BIOS B16.0307.1 (HKLM-x32\...\{C9D46F25-5F9D-4E25-B24F-BC00E9EDF529}) (Version: 3.00.0000 - GIGABYTE) Hidden @BIOS B16.0307.1 (HKLM-x32\...\InstallShield_{C9D46F25-5F9D-4E25-B24F-BC00E9EDF529}) (Version: 3.00.0000 - GIGABYTE) µTorrent (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\uTorrent) (Version: 3.4.5.41372 - BitTorrent Inc.) 64 Bit HP CIO Components Installer (HKLM\...\{3138F992-045B-4F55-825C-53B231E647CA}) (Version: 13.2.1 - Hewlett-Packard) Hidden Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.012.20098 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 24.0.0.180 - Adobe Systems Incorporated) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.3.0.151 - Adobe Systems Incorporated) Adobe Flash Player 26 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 26.0.0.151 - Adobe Systems Incorporated) Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0.1 - Adobe Systems Incorporated) Alt1 Toolkit (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\Alt1Toolkit) (Version: 1.4.5 - RuneApps) Ambient LED (HKLM-x32\...\{BEF97B38-D1B8-45B4-A60A-AF5C1556CC72}) (Version: 1.00.1605.1801 - GIGABYTE) Hidden Ambient LED (HKLM-x32\...\InstallShield_{BEF97B38-D1B8-45B4-A60A-AF5C1556CC72}) (Version: 1.00.1605.1801 - GIGABYTE) Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 385.41 - NVIDIA Corporation) Hidden APP Center (HKLM-x32\...\{D50BEE9A-0EC6-4A58-BF90-35BDC6D6495D}) (Version: 1.00.1701.0301 - GIGABYTE) Hidden APP Center (HKLM-x32\...\InstallShield_{D50BEE9A-0EC6-4A58-BF90-35BDC6D6495D}) (Version: 1.00.1701.0301 - GIGABYTE) Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{9F429DF7-F8DD-4980-9673-E6DACA012F6C}) (Version: 3.3 - Microsoft Corporation) Hidden AutoHotkey 1.1.23.05 (HKLM\...\AutoHotkey) (Version: 1.1.23.05 - Lexikos) Azure AD Authentication Connected Service (HKLM-x32\...\{3FEAC561-1CF6-41D6-B0F3-BECDD9C88A1B}) (Version: 14.0.23107 - Microsoft Corporation) Hidden AzureTools.Notifications (HKLM-x32\...\{1E5CA362-39B6-4BD0-B9C0-69CF15F0FEA2}) (Version: 2.7.30611.1601 - Microsoft Corporation) Hidden Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield™ 1 (HKLM-x32\...\{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.49.52296 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Betternet for Windows (HKLM-x32\...\{2E77104D-96E1-4A9C-86F2-C7CF4C70EB35}) (Version: 3.6.0.0 - Betternet Technologies Inc.) BIOS Setup (HKLM-x32\...\{9D48202D-C767-40E7-8A4E-C14BD7328168}) (Version: 1.00.0000 - GIGABYTE) Hidden BIOS Setup (HKLM-x32\...\InstallShield_{9D48202D-C767-40E7-8A4E-C14BD7328168}) (Version: 1.00.0000 - GIGABYTE) BitTorrent (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\BitTorrent) (Version: 7.10.0.43917 - BitTorrent Inc.) Blend for Visual Studio SDK for .NET 4.5 (HKLM-x32\...\{37E53780-3944-4A6A-842F-727128E8616E}) (Version: 3.0.40218.0 - Microsoft Corporation) Hidden BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.9.30.9239 - BlueStack Systems, Inc.) BlueStacks Notification Center (HKLM-x32\...\{3792811C-832F-4392-B44A-24092901EDDC}) (Version: 0.9.30.9239 - BlueStack Systems, Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.25 - Piriform) Chrome Remote Desktop Host (HKLM-x32\...\{88D5D9A4-48C4-4D0A-88B9-3E18661CF0D9}) (Version: 57.0.2987.37 - Google Inc.) Click Install if prompted (HKLM-x32\...\{92A9572E-834E-477B-A100-C9AD3EE4B4B9}) (Version: 1.0.0.0 - ExpressVpn) Hidden CloudStation (HKLM-x32\...\{6D8DA122-A40A-421B-9D95-FE4C806BCDBE}) (Version: 1.00.0021 - GIGABYTE) Hidden CloudStation (HKLM-x32\...\InstallShield_{6D8DA122-A40A-421B-9D95-FE4C806BCDBE}) (Version: 1.00.0021 - GIGABYTE) CPUID CPU-Z 1.81 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.81 - ) CPUID HWMonitor 1.28 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) CPUID HWMonitor Pro 1.28 (HKLM\...\CPUID HWMonitorPro_is1) (Version: - ) Curse (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse) Curse Client (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\101a9f93b8f0bb6f) (Version: 5.1.1.844 - Curse) Destiny 2 (HKLM-x32\...\Destiny 2) (Version: - Blizzard Entertainment) Discord (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\Discord) (Version: 0.0.298 - Discord Inc.) Dotfuscator and Analytics Community Edition 5.18.1 (HKLM-x32\...\{9890DF1A-10E9-4236-94B1-1EFAA4099F13}) (Version: 5.18.1.2898 - PreEmptive Solutions) Hidden DZLauncher version 0.1.5.5 (HKLM-x32\...\{1E299AE2-74C8-4CD8-6B17-A86E0ED3C4D2}_is1) (Version: 0.1.5.5 - Maca134) EasyTune (HKLM-x32\...\{7F635314-EE21-4E4B-A68D-69AE70BA0E9B}) (Version: 1.16.1117 - GIGABYTE) Hidden EasyTune (HKLM-x32\...\InstallShield_{7F635314-EE21-4E4B-A68D-69AE70BA0E9B}) (Version: 1.16.1117 - GIGABYTE) EasyTuneEngineService (HKLM-x32\...\{964575C3-5820-4642-A89A-754255B5EFE1}) (Version: 1.16.0614 - GIGABYTE) Hidden EasyTuneEngineService (HKLM-x32\...\InstallShield_{964575C3-5820-4642-A89A-754255B5EFE1}) (Version: 1.16.0614 - GIGABYTE) Electrum (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\Electrum) (Version: 2.6.4 - Electrum Technologies GmbH) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) EVGA Precision XOC (HKLM-x32\...\{D705C0CA-D900-45AB-85A7-AD651F7055A6}) (Version: 6.0.9 - EVGA Corporation) ExpressVPN (HKLM-x32\...\{10EB2DEF-3C7F-40DD-8C58-438906E20D08}) (Version: 6.2.3.2578 - ExpressVPN) Hidden ExpressVPN (HKLM-x32\...\{a219f179-a66a-48db-934c-aca0746714e5}) (Version: 6.2.3.2578 - ExpressVPN) Fallout 4 (HKLM-x32\...\Fallout 4_is1) (Version: - ) FileZilla Client 3.14.1 (HKLM-x32\...\FileZilla Client) (Version: 3.14.1 - Tim Kosse) Gameshow (HKLM\...\{175C6EA4-691D-483E-A453-D191E9C45491}) (Version: 3.9.0 - Telestream LLC) Geeks3D FurMark 1.18.2.0 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: - Geeks3D) GigabyteFirmwareUpdateUtility (HKLM-x32\...\{1CBA99CE-1AB3-4366-AFB4-7F7B75EBBE35}) (Version: 1.00.0000 - GIGABYTE) Hidden GigabyteFirmwareUpdateUtility (HKLM-x32\...\InstallShield_{1CBA99CE-1AB3-4366-AFB4-7F7B75EBBE35}) (Version: 1.00.0000 - GIGABYTE) glogg (HKLM-x32\...\glogg) (Version: 1.1.1-x86_64 - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.) Google Cloud SDK (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\Google Cloud SDK) (Version: - Google Inc.) Google Play Music Desktop Player (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\GPMDP_3) (Version: 4.4.1 - Samuel Attard) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.31.5 - Google Inc.) Hidden Gpg4win (2.2.1) (HKLM-x32\...\GPG4Win) (Version: 2.2.1 - The Gpg4win Project) Gyazo 3.3.3 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.) IIS 10.0 Express (HKLM\...\{5984D8DA-C1AF-4284-9C88-D7150425B315}) (Version: 10.0.1734 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version: - ) IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version: - ) Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.15 - Oracle Corporation) KB4023057 (HKLM\...\{0C050BEE-16BE-4998-8959-2A421433DB6E}) (Version: 2.5.0.0 - Microsoft Corporation) Killer Bandwidth Control Filter Driver (HKLM\...\{89A9DA12-B6F1-4966-95B3-574EEB6DF07E}) (Version: 1.1.65.1357 - Rivet Networks) Hidden Killer E240x Drivers (HKLM\...\{C2AAF672-E3A2-403A-942F-7B9C9B4E592E}) (Version: 1.1.65.1357 - Rivet Networks) Hidden Killer Network Manager (HKLM\...\{F2BE14C9-4659-4335-B964-0E76AE0D2EE7}) (Version: 1.1.65.1357 - Rivet Networks) Hidden Killer Performance Suite (HKLM-x32\...\{75269D5A-2CE7-48D1-8169-5744C83C574F}) (Version: 1.1.65.1357 - Rivet Networks) KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version: - ) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Logitech Gaming Software 8.94 (HKLM\...\Logitech Gaming Software) (Version: 8.94.108 - Logitech Inc.) Malwarebytes version 3.2.2.2029 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2029 - Malwarebytes) Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 Targeting Pack (ENU) (HKLM-x32\...\{3D3CEBE6-40EA-4C48-97FD-73828281AB4A}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Build Tools 2015 (HKLM-x32\...\{d21da0dd-4ba4-4838-ba58-64cf7a77131a}) (Version: 14.0.23107.10 - Microsoft Corporation) Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 T-SQL Language Service (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - enu (14.0.50616.0) (HKLM-x32\...\{58246C80-3941-4B69-AE31-264644E2ADB8}) (Version: 14.0.50616.0 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{68BA34E8-9B9D-4A74-83F0-7D366B532D75}) (Version: 12.0.2402.11 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{718FFB65-F6E4-4D62-861F-ED10ED32C936}) (Version: 12.0.2402.11 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual FoxPro 9.0 Professional - English (HKLM-x32\...\Visual FoxPro 9.0 Professional - English) (Version: - Microsoft) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio Community 2015 (HKLM-x32\...\{50b32652-69d2-4b93-9316-edcd12067b8b}) (Version: 14.0.23107.10 - Microsoft Corporation) Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation) Minecraft (HKLM-x32\...\{171B3EB7-1B5D-4422-9460-8D95CF2508DB}) (Version: 1.11.2 - Mojang (By OfficialHawk)) Hidden Minecraft (HKLM-x32\...\Minecraft 1.11.2) (Version: 1.11.2 - Mojang (By OfficialHawk)) Mozilla Firefox 41.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 41.0.2 (x86 en-US)) (Version: 41.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 41.0.2 - Mozilla) Multi-Device Hybrid Apps using C# - Templates - ENU (HKLM-x32\...\{12D99739-FFD3-3761-8AA6-F929E0FE407E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.63.14 - Black Tree Gaming) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.3 - Notepad++ Team) NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Driver 385.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 385.41 - NVIDIA Corporation) NVIDIA GeForce Experience 3.9.0.97 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.9.0.97 - NVIDIA Corporation) NVIDIA Graphics Driver 385.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 385.41 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.27 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.27 - NVIDIA Corporation) NVIDIA PhysX System Software 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation) OBS Studio (HKLM-x32\...\OBS Studio) (Version: 18.0.1 - OBS Project) OldSchool RuneScape Launcher 1.2.7 (HKLM-x32\...\{FEDDCE73-34B8-4980-90B8-8619A78C902C}) (Version: 1.2.7 - Jagex Ltd) ON_OFF Charge 2 B15.0709.1 (HKLM-x32\...\{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE) Hidden ON_OFF Charge 2 B15.0709.1 (HKLM-x32\...\InstallShield_{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) Origin (HKLM-x32\...\Origin) (Version: 10.4.14.21968 - Electronic Arts, Inc.) Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) Overwolf (HKLM-x32\...\Overwolf) (Version: 0.107.254.0 - Overwolf Ltd.) PNY Drive Utility (HKLM-x32\...\{F7F0273F-68B7-44EA-AD7B-1C9F9C29C562}) (Version: 1.0.8 - PNY Technologies) PreEmptive Analytics Visual Studio Components (HKLM-x32\...\{436A18DD-5F2C-4B3C-985E-AD3C13B0CC25}) (Version: 1.2.5134.1 - PreEmptive Solutions) Hidden Prerequisites for SSDT (HKLM-x32\...\{21373064-AD95-48DB-A32E-0D9E08EF7355}) (Version: 12.0.2000.8 - Microsoft Corporation) Process Hacker 2.39 (r124) (HKLM\...\Process_Hacker2_is1) (Version: 2.39.0.124 - wj32) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Python 2.7.11 (HKLM-x32\...\{16E52445-1392-469F-9ADB-FC03AF00CD61}) (Version: 2.7.11150 - Python Software Foundation) Python 3.4.0 (64-bit) (HKLM\...\{863162a8-ecc2-35ea-bdf7-e09ac456e164}) (Version: 3.4.150 - Python Software Foundation) Razer Chroma SDK Core Components (HKLM-x32\...\Razer Chroma SDK) (Version: 2.3.6 - Razer Inc.) Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 7.6.8.66 - Razer Inc.) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.20.17.413 - Razer Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7765 - Realtek Semiconductor Corp.) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.0 - Rockstar Games) Roslyn Language Services - x86 (HKLM-x32\...\{5B47029B-1E62-30FF-906E-694851C22782}) (Version: 14.0.23107 - Microsoft Corporation) Hidden Roslyn Language Services - x86 (HKLM-x32\...\{6C1985E7-E1C5-3A95-86EF-2C62465F15C3}) (Version: 14.0.23107 - Microsoft Corporation) Hidden RuneScape Launcher 2.2.4 (HKLM\...\RuneScape Launcher_is1) (Version: 2.2.4 - Jagex Ltd) Sandboxie 5.18 (64-bit) (HKLM\...\Sandboxie) (Version: 5.18 - Sandboxie Holdings, LLC) Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.) Spotflux (HKLM-x32\...\Spotflux) (Version: 3.2.0 - Spotflux) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Team Explorer for Microsoft Visual Studio 2015 (HKLM-x32\...\{791295AE-3B0A-3222-9E69-26C8C106E8D1}) (Version: 14.0.23102 - Microsoft Corporation) Hidden TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.72365 - TeamViewer) TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) Test Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{9EABBFE1-7EED-47D9-8FB8-21D7E4808057}) (Version: 14.0.23107 - Microsoft Corporation) Hidden TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.2 - TrueCrypt Foundation) TypeScript Power Tool (HKLM-x32\...\{E51EAA08-F838-4CCE-B011-A82469BE6CC5}) (Version: 1.6.3.0 - Microsoft Corporation) Hidden TypeScript Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{F0AF1E33-1CB9-4377-ABEE-4E4550A3F9BA}) (Version: 1.6.3.0 - Microsoft Corporation) Hidden TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 (HKLM-x32\...\{da31aa25-410a-4c1b-9ec0-114dd8dff786}) (Version: 1.6.23313.0 - Microsoft Corporation) Universal CRT Extension SDK (HKLM-x32\...\{284FA9A0-CEDD-81D3-5A19-5858E95FD0C4}) (Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (HKLM-x32\...\{ABD37F71-FC3F-F525-C7B3-BDD95F684C51}) (Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Redistributable (HKLM-x32\...\{74E0F5DD-514A-4F85-0EE0-1E2EBB8BFC8C}) (Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Tools x64 (HKLM\...\{4C8DCEB6-5D3C-90BD-6E31-A8342B9185FF}) (Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Tools x86 (HKLM-x32\...\{DE0B03D4-5A26-DEEC-F62E-278EF28BA58E}) (Version: 10.0.10150 - Microsoft Corporation) Hidden Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation) Vegas Pro 13.0 (64-bit) (HKLM\...\{1EEE0BEE-0BC8-11E5-A19E-F04DA23A5C58}) (Version: 13.0.453 - Sony) Virtual Audio Cable 4.15 (HKLM\...\Virtual Audio Cable 4.15) (Version: - ) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN) Vulkan Run Time Libraries 1.0.51.0 (HKLM\...\VulkanRT1.0.51.0) (Version: 1.0.51.0 - LunarG, Inc.) WCF Data Services 5.6.4 Runtime (HKLM-x32\...\{DB85E7BD-B2DD-43D4-B3C0-23D7B527B597}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{0A3B508E-5638-4471-BCC9-954E1868CB86}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden Windows 10 Update and Privacy Settings (HKLM\...\{4DFCD818-036A-4229-A67D-CF17DC461D92}) (Version: 1.0.14.0 - Microsoft Corporation) WinRAR 5.30 beta 5 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.5 - win.rar GmbH) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) XSplit Broadcaster (HKLM-x32\...\{5B006BC4-6763-4BC4-9FEE-77E305E1C3F9}) (Version: 2.9.1611.1627 - SplitmediaLabs) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3154826165-2591789761-3766887662-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-F9A1E5447705}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File CustomCLSID: HKU\S-1-5-21-3154826165-2591789761-3766887662-1001_Classes\CLSID\{9b2ddd1a-b426-4883-b8f8-cf11ff961155}\InprocServer32 -> C:\WINDOWS\system32\dfshim.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3154826165-2591789761-3766887662-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-09-11] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-09-11] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-09-11] () ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => -> No File ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => -> No File ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => -> No File ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => -> No File ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => -> No File ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => -> No File ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => -> No File ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-08-21] (NVIDIA Corporation) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {07357B02-9DCB-4825-87A2-B4A76062DFB7} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {0B74F626-E98B-41D3-8BD4-D09F2C93807B} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2017-10-03] () Task: {0D0E65D1-6B30-4B49-9F70-D48E775E6F56} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2017-10-17] (Overwolf LTD) Task: {1924AE72-870F-47CC-B6CC-5155B913EC50} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {1DC9F707-1D59-4053-9688-44F871B525CF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {242AAFBF-3F47-412B-8598-E6E805420AFB} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {257436E5-4A00-4B37-BA15-1DE7D23B4A3A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated) Task: {2C350C65-6623-45E3-B19A-51A8F5870E44} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {2E3281A4-1159-47D7-8833-9F5C34B9C762} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {2E530D42-E2C2-4DB8-9BB7-93975DE43405} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION Task: {315FC891-ABE7-4465-B9C1-B5015F1B48AA} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe Task: {3AC9D602-151A-4951-B754-E60AB3B4FC09} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {3AE31897-E114-4A18-88FB-19F82125498D} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {3BA43A7F-42BE-4377-BF2E-0421F6CC495F} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-09-19] (NVIDIA Corporation) Task: {460DE789-B53E-4088-B913-98B86BC0FEC6} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {4B50EFBC-D323-47F4-9A38-BB9984ACE752} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-09-19] (NVIDIA Corporation) Task: {4F846DEB-9C8B-49D6-A8F4-1620A09EB120} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {52E39460-CE1D-4677-B515-A5AF24EEC82D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {54285F0C-A22F-4A6A-A813-A3239F9219DD} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {561411E0-495F-4ACD-BE3B-C043BE1BD9A5} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {63F9A26F-1FFE-42BF-98EC-CCBE71C65085} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {649139EA-A1C5-4200-B835-2C8B773E8A33} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3154826165-2591789761-3766887662-1020 => C:\Users\Lucas\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe Task: {6739D9C1-8BB4-407A-BED2-750116E7E015} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-09-19] (NVIDIA Corporation) Task: {67BB6B4D-9DDE-46FA-BC8A-BBA2EC185C96} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {6A5986EB-4C64-47A0-B653-40663D0F5655} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-09-19] (NVIDIA Corporation) Task: {6E2C860E-493F-44C6-A0D8-E494AF7555AD} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {72D29BD6-96FB-4297-8D5F-A8F19B56AB49} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {7D74CB73-7BBE-4D0A-B5B7-DA2B44ABA78B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-10-11] (Microsoft Corporation) Task: {7EF05A0D-B29A-410A-974E-F3ED5118EFD4} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {845E989A-5F76-451C-86D2-03B0D20678C6} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {90069BA8-630A-4A5C-9531-DC8A0CB8B18D} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2015-10-31] (@ByELDI) Task: {95FA2C0C-BD2D-4753-A7CB-4DC31034FED0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {9E804A72-8815-4DCA-B0B9-4A75CD286A7B} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A252A9DD-3F0A-42DA-A8D4-4F9D4E854560} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-09-19] (NVIDIA Corporation) Task: {A5F46391-C50B-46B4-B155-D5CA07302DB7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A6ED3CA2-3657-4391-ACBA-84ACF7A42CD0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {B48B179B-F4F3-4242-BC0F-762E32B3632E} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-09-19] (NVIDIA Corporation) Task: {B49617F1-2F51-4EA0-B432-C7AC8F9C8A85} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {BA017E49-6162-42DB-8CD1-5F5CE79BC412} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {BA281154-C29E-49C3-92AD-B9443B03BA20} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-06] (Piriform Ltd) Task: {BA8E25D7-7816-4EE0-8EF4-05D6FA92627B} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {BC46F310-DEA8-485C-9AB1-DD68272DB48D} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {BE38801C-4D81-4A50-9ED8-CEAE09A6E0F9} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2017-10-03] () Task: {C809C924-6550-4F79-86DB-10B16F167B15} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-09-19] (NVIDIA Corporation) Task: {CB87050A-A878-4FF3-B98F-DBD27B9B71C9} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe Task: {D0C233DE-573D-4DFD-824A-8A72FC4BCF9E} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {D1F06D01-F730-42EB-BBA4-06D3FC7D69DB} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-09-19] (NVIDIA Corporation) Task: {D4B40063-F209-4BDF-A245-C7321220B2BF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {DEA1C216-3829-4241-8CAC-A55A8FC15CEE} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {EA488CCF-6C12-4F42-BDFC-E271DA196991} - System32\Tasks\EVGAPrecisionX => F:\Games\Steam Games\steamapps\common\EVGA PrecisionX\PrecisionX_x64.exe [2017-09-06] (EVGA Corp.) Task: {F5986750-FA2B-40A8-B345-7F8FD1A55AB4} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {F78D36C5-18B8-4F57-B337-5CEBC262292C} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe [2016-12-23] () (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - AfkWarden.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/afkscape/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Clue solver.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/clue/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - ColorGrabber.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/colorgrabber/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - D&D Notifications.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/notifications/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - DgKey.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/dgkey/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Droplogger.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/droplogger/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Farming Timer.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/farmtimer/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Fish Flingers.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/fishflingers/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Meg answers.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/meg/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Notepad.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/notepad/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - RS Wiki.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/object/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Stats.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/stats/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Stopwatch.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/timer/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Twitch.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/twitch/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - World map.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/map/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - XpMeter.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/xpmeter/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Youtube.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/youtube/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Cloud SDK\Google Cloud SDK Shell.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /k ""C:\Users\Lucas\AppData\Local\Google\Cloud SDK\cloud_env.bat"" ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ad,Block Plus.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gojdigjopnhgodnciccmjddabckjanko ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome RDP for Google Cloud Platform.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=mpbbnannobiobpnfblimoapbephgifkm ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome RDP.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=cbkkbcmdlboombapidmoeolnmdacpkch ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\TwitchAlerts Stream Labels.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=kgmggmdngboajiakmbpdknfpdelbjbcg ==================== Loaded Modules (Whitelisted) ============== 2016-07-16 06:42 - 2016-07-16 06:42 - 000231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2017-09-12 20:22 - 2017-09-07 01:01 - 002681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2015-12-02 12:15 - 2016-12-15 05:37 - 000020208 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\TeamViewer_PrintProcessor.dll 2017-07-06 11:22 - 2017-07-06 11:22 - 000331264 _____ () C:\program files (x86)\expressvpn\bootstrap\AMD64\nssm.exe 2016-10-12 11:46 - 2017-09-19 02:23 - 001267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-07-06 11:24 - 2017-07-06 11:24 - 009239168 _____ () C:\program files (x86)\expressvpn\xvpnd\xvpnd.exe 2015-09-11 19:02 - 2015-09-11 19:02 - 000803488 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2016-10-31 20:08 - 2016-10-31 20:08 - 001864384 _____ () C:\Users\Lucas\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\ClientTelemetry.dll 2010-01-09 20:17 - 2010-01-09 20:17 - 004254560 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-01-21 01:40 - 2010-01-21 01:40 - 008794464 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2016-09-29 11:26 - 2016-09-29 11:26 - 000134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-03-14 22:54 - 2017-03-04 01:31 - 000474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2017-03-14 22:54 - 2017-03-04 01:12 - 009760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-03-14 22:54 - 2017-03-04 01:05 - 001401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-03-14 22:54 - 2017-03-04 01:05 - 000757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-10-11 08:44 - 2017-09-17 21:14 - 002424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-10-11 08:44 - 2017-09-17 21:16 - 004853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2015-03-06 19:07 - 2015-03-06 19:07 - 000908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2017-07-10 17:35 - 2017-07-10 17:35 - 001096824 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-06 19:07 - 2015-03-06 19:07 - 000060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2017-07-10 17:35 - 2017-07-10 17:35 - 000241784 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2017-10-23 03:53 - 2017-10-04 13:15 - 002289096 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll 2017-10-23 03:53 - 2017-10-04 13:15 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2016-10-17 22:53 - 2017-04-23 01:29 - 002493440 _____ () C:\Program Files (x86)\Origin\libGLESv2.dll 2017-07-06 11:25 - 2017-07-06 11:25 - 000441472 _____ () C:\program files (x86)\expressvpn\xvpnd\windows\ExpressVPN.FilterManager.dll 2017-01-22 14:01 - 2016-12-08 02:29 - 001829208 _____ () C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libglesv2.dll 2017-01-22 14:01 - 2016-12-08 02:29 - 000085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libegl.dll 2017-05-22 05:13 - 2017-05-22 05:13 - 000143824 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll 2015-10-16 05:02 - 2015-10-16 05:02 - 000039384 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll 2016-10-12 11:46 - 2017-09-19 02:23 - 001040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Lucas\AppData\Local\Temp:$DATA [16] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 21:34 - 2016-05-12 01:02 - 000000232 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 lm.licenses.adobe.com 127.0.0.1 na1r.services.adobe.com 127.0.0.1 hlrcv.stage.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 activate.adobe.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Lucas\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{308f93af-eea4-455f-be4b-5609f37a4533}.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: AdobeUpdateService => 2 MSCONFIG\Services: AGSService => 2 MSCONFIG\Services: BEService => 3 MSCONFIG\Services: BstHdAndroidSvc => 3 MSCONFIG\Services: BstHdLogRotatorSvc => 3 MSCONFIG\Services: BstHdUpdaterSvc => 3 MSCONFIG\Services: CGVPNCliService => 2 MSCONFIG\Services: Creative ALchemy AL6 Licensing Service => 3 MSCONFIG\Services: DirMngr => 2 MSCONFIG\Services: EasyTuneEngineService => 2 MSCONFIG\Services: ExpressVpnService => 2 MSCONFIG\Services: gadjservice => 2 MSCONFIG\Services: gupdate => 3 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: ICCS => 3 MSCONFIG\Services: Killer Service V2 => 2 MSCONFIG\Services: LolScreenSaverService => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: OcButtonService => 2 MSCONFIG\Services: OracleOraDB12Home1MTSRecoveryService => 2 MSCONFIG\Services: OracleOraDB12Home1TNSListener => 2 MSCONFIG\Services: OracleServiceORCL => 2 MSCONFIG\Services: OracleVssWriterORCL => 2 MSCONFIG\Services: Origin Client Service => 3 MSCONFIG\Services: Origin Web Helper Service => 2 MSCONFIG\Services: PnkBstrA => 2 MSCONFIG\Services: Razer Game Scanner Service => 2 MSCONFIG\Services: RipsawUSBPortChecker => 2 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\Services: SpotfluxConnectionManager => 2 MSCONFIG\Services: TeamViewer => 2 MSCONFIG\Services: VMAuthdService => 2 MSCONFIG\Services: VMnetDHCP => 2 MSCONFIG\Services: VMUSBArbService => 2 MSCONFIG\Services: VMware NAT Service => 2 MSCONFIG\Services: VMwareHostd => 2 HKLM\...\StartupApproved\Run: => "ShadowPlay" HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "WindowsDefender" HKLM\...\StartupApproved\Run32: => "Zygor Guides Client" HKLM\...\StartupApproved\Run32: => "UpdReg" HKLM\...\StartupApproved\Run32: => "Sound Blaster X-Fi MB 3" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKLM\...\StartupApproved\Run32: => "WindowsDefender" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\StartupFolder: => "CurseClientStartup.ccip" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "GoToMeeting" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "MurGee.com Auto Clicker" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "f.lux" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "Uninstall C:\Users\Lucas\AppData\Local\Microsoft\OneDrive\17.3.6390.0509" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "Uninstall C:\Users\Lucas\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "Overwolf" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "CCleaner Monitoring" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [UDP Query User{DC7220BB-0ECD-4951-A2FF-2B39239DCE0D}C:\overwatch\overwatch.exe] => (Allow) C:\overwatch\overwatch.exe FirewallRules: [TCP Query User{FDC483D4-17BF-4029-925E-1E671FA6F840}C:\overwatch\overwatch.exe] => (Allow) C:\overwatch\overwatch.exe FirewallRules: [{F8127A34-C034-4EEA-9022-3A51EF36EC69}] => (Allow) %systemroot%\system32\alg.exe FirewallRules: [{3071D213-57F6-4811-A64A-1D1B28722196}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{4B8A083E-C3D5-4A0B-A44A-97496E41B672}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{9A6528FD-C5EB-45DC-9335-0D862B57D586}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{822C10C8-00B6-431C-ACBF-B3FFC4DBF12F}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{80AFB9C8-F19B-4D44-BC87-244E7F3BB0CE}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{4197D857-B053-4447-B821-5E75C98CA6BC}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{CCFADD27-36F3-4EDD-BA79-BD2B2D5B620E}] => (Allow) LPort=3306 FirewallRules: [{F18535AA-D7E5-41A5-B724-9ABC7773E38F}] => (Allow) LPort=3306 FirewallRules: [{C00B72F6-8EEE-4ABB-8731-A15C782BE72E}] => (Allow) C:\Users\Lucas\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{6A7D1A9F-D7F2-41BB-9639-FCE9FA313F5B}] => (Allow) C:\Users\Lucas\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{F9CD2F70-DB5B-4FBA-B8FC-E8678DE3622A}] => (Allow) C:\Users\Lucas\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{6D5CD6D1-A81B-4818-AB72-A9E1FCABB509}] => (Allow) C:\Users\Lucas\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{BA34AC1F-8891-4A18-BD7A-BAD675D4EDB7}] => (Allow) C:\Users\Lucas\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{6ECFC39A-264D-4098-A60D-4F61FD306929}] => (Allow) C:\Users\Lucas\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{40B7A2A4-831F-47A7-A22B-696C2E98A8CF}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶睜湩灯晴汩整屲敲瑳楷潮瑰楦瑬牥⹟硥e FirewallRules: [{8005D10A-1A36-4588-9189-1A08DD910AA0}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶睜湩灯晴汩整屲楷潮瑰楦瑬牥⹟硥e FirewallRules: [{FF1F10AF-D0EC-4922-BCE4-1B70682B73E7}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶睜湩灯晴汩整屲敲瑳楷潮瑰楦瑬牥攮數 FirewallRules: [{D884B386-6771-47E1-9994-217FA2526758}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶睜湩灯晴汩整屲楷潮瑰楦瑬牥攮數 FirewallRules: [{F2CB370D-0DCB-41FF-AA51-1CF91FC0BF26}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{730FE8AC-BEB2-40E3-9E99-1064AEE99F94}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{3B62B3A8-BDC3-49FB-8D2A-91BD30D68BEF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{1DD1EE81-63AD-4E17-820E-EE754C8F7930}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{5CFE1FCE-F37D-43E5-8E16-D3C5ADCB4F91}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{9623489F-5EBE-45EC-8785-58DD81CB04EA}C:\app\lucas\product\12.1.0\dbhome_1\jdk\jre\bin\java.exe] => (Allow) C:\app\lucas\product\12.1.0\dbhome_1\jdk\jre\bin\java.exe FirewallRules: [UDP Query User{07227E41-830D-458D-92DB-A7C628EF14D9}C:\app\lucas\product\12.1.0\dbhome_1\jdk\jre\bin\java.exe] => (Allow) C:\app\lucas\product\12.1.0\dbhome_1\jdk\jre\bin\java.exe FirewallRules: [{F25FED34-818F-48B8-AAA3-12E71DB3C824}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe FirewallRules: [{217E358B-4D32-40C8-845D-0BE7647D1D01}] => (Allow) C:\Users\Lucas\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{786E5A88-6460-4530-8023-68A192053DFA}] => (Allow) C:\Users\Lucas\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{9ABC0BFB-4987-4EE2-BF8C-C02DFF566437}] => (Allow) C:\Users\Lucas\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{F9D9C4CF-D559-40AE-8C55-E29CDF13A989}] => (Allow) C:\Users\Lucas\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{71E9D19E-7B39-4D38-8358-A1BAA11C2EE9}] => (Allow) C:\Users\Lucas\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{5C98B787-3FCA-4F37-A90E-6619EBB3AA5C}] => (Allow) C:\Users\Lucas\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{8D3628AB-89AD-4BF3-892A-C41E5F435E28}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{7886B49C-8B56-4586-BE33-E80E7C2A7F13}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{58E079CD-8D44-42ED-923F-990A91BAB712}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{DE7ECC06-9B64-42DE-90AA-4F2FF76B30BC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{6C3CC19C-B65E-4C80-9055-6C4821998C36}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{8D4CC75F-D984-48AB-8837-6C11C2154A79}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{EF4A3A8C-457A-4922-8675-7E0DA2F7AE6D}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{28970353-6612-4AF8-869D-C7292C82519B}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [TCP Query User{0206AF29-9394-4ABD-8DEF-2430D0797E81}C:\program files (x86)\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\java.exe FirewallRules: [UDP Query User{6EF22BE2-FEB2-4B8C-97A2-69E101EC7800}C:\program files (x86)\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\java.exe FirewallRules: [TCP Query User{296932C2-B69E-40A5-8FA8-B3B7AF1C3FE6}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [UDP Query User{B2A3A37C-7128-429F-BBFC-AC6FF9E57CED}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [TCP Query User{548B47F2-774E-4AE3-8E88-CDE46067C01E}C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe FirewallRules: [UDP Query User{830BD329-5F42-42F0-B4AB-41271F84B410}C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe FirewallRules: [TCP Query User{3ACA33C1-6C25-4154-B4A1-579E61925E30}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe FirewallRules: [UDP Query User{0D4E4F50-4F0C-4D1C-9A94-FAC9770E3B0E}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe FirewallRules: [{B0DF1250-D70B-44EE-82FB-2B23279B117E}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe FirewallRules: [{391E2549-7CDC-4BAF-9F9F-FEE4A5556B93}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe FirewallRules: [TCP Query User{28A0C1CD-159A-472A-A033-7A3DC4D9F1CE}C:\program files (x86)\gigabyte\@bios\flashbios.exe] => (Allow) C:\program files (x86)\gigabyte\@bios\flashbios.exe FirewallRules: [UDP Query User{04C102A4-6394-4936-9F4C-CED6A74B8E05}C:\program files (x86)\gigabyte\@bios\flashbios.exe] => (Allow) C:\program files (x86)\gigabyte\@bios\flashbios.exe FirewallRules: [{5DF66017-43E5-4BAD-A358-7E8B87E8C1B3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{E0890153-350F-4A63-824E-429EF0DD2EE2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{F99D5F5A-C097-424B-8EC3-1DF6318B60F7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{46D00B16-E227-48BD-99C4-F9B8D1758340}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{060A6550-B73A-4A48-8C68-315EA0A13137}] => (Allow) LPort=1688 FirewallRules: [{0CD56545-53DA-44D7-B554-05CBA1F24177}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{625D647E-0949-4E1E-B21A-314CC02A5EDB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{FA774675-2D6E-4D75-B86A-5CEA40F94AC0}] => (Allow) F:\Games\Steam Games\steamapps\common\7 Days To Die\7dLauncher.exe FirewallRules: [{4C3DC9C6-E53C-4B59-A4D1-FBA2FDA7B0D1}] => (Allow) F:\Games\Steam Games\steamapps\common\7 Days To Die\7dLauncher.exe FirewallRules: [{61326436-B540-4E5F-862E-C8878B14B5C9}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1Trial.exe FirewallRules: [{F0DE280C-9768-47CC-B20E-0B80608B9FB1}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1Trial.exe FirewallRules: [{4BA6BEF7-0E7B-4846-9D94-266310E4D104}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1.exe FirewallRules: [{C0A4BBF5-120A-4D9D-8EDE-83B70BA8CE38}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1.exe FirewallRules: [TCP Query User{A48BD95F-A60A-4CC1-B4E7-E35DFD69C428}F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [UDP Query User{1109D7AC-98B7-4EB5-BA61-10DD1123C679}F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [{07A998A5-855A-4ADC-98C3-1F337BAF4A26}] => (Allow) F:\Games\Steam Games\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{80224FE2-F8BB-4517-9EA3-DCD119B1A399}] => (Allow) F:\Games\Steam Games\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{5A882591-6943-4296-9054-F5A99FA8342A}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Broadcaster\XSplit.Core.exe FirewallRules: [{F1183C00-FCD9-4F24-8B8F-848F67FEC1E2}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Broadcaster\XSplit.cam.exe FirewallRules: [{20216630-0E7F-4A7F-960A-440757D81106}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Broadcaster\XSplit.Core.exe FirewallRules: [{8B9CFAA5-C209-4425-B6D2-4757C8CECF3B}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Broadcaster\XSplit.cam.exe FirewallRules: [{2145F215-ACBF-4BE0-817F-B9A3C9A20054}] => (Allow) F:\Games\Steam Games\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{54ECF899-680C-4B87-B79F-D3065424EB52}] => (Allow) F:\Games\Steam Games\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [TCP Query User{648D9CB7-4AE2-4C61-92F6-1DF2024D6C28}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [UDP Query User{0542E0F6-503D-4227-BAA7-0A98D6D40742}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [TCP Query User{8E03A6FB-59C8-4EB6-9CFF-0FD65818486D}C:\overwatch\overwatch.exe] => (Allow) C:\overwatch\overwatch.exe FirewallRules: [UDP Query User{60D39E6C-F638-4841-8DA7-F84E77B2C6A7}C:\overwatch\overwatch.exe] => (Allow) C:\overwatch\overwatch.exe FirewallRules: [TCP Query User{C098C0A7-3D5E-4309-A875-B3858A3B1E5C}F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [UDP Query User{A4A6E199-B03C-4EA4-AC96-A542FC1325CF}F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [TCP Query User{72655C9C-DA8D-4E9D-8B39-63D3510E42D0}C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe FirewallRules: [UDP Query User{BDDAF83F-B5CD-4717-AA61-6E040191DDB9}C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe FirewallRules: [TCP Query User{0BECA25D-FD5A-4C9A-BBE2-D9ACE609F0E3}F:\games\steam games\steamapps\common\grand theft auto v\gta5.exe] => (Allow) F:\games\steam games\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [UDP Query User{175A30D1-A5C2-4B9E-AF1D-F82780891B55}F:\games\steam games\steamapps\common\grand theft auto v\gta5.exe] => (Allow) F:\games\steam games\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [{F2AF137B-1CFE-438C-A4BC-F0C3CB7BC5CC}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe FirewallRules: [{DB8739B5-73E6-4C73-8461-2490F6D6D9A4}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe FirewallRules: [{F349D6C5-7008-43C2-9D64-30FDA4D6249E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [TCP Query User{CD906893-E889-421A-ADD1-A5583C8C9B89}C:\program files (x86)\gigabyte\@bios\flashbios.exe] => (Allow) C:\program files (x86)\gigabyte\@bios\flashbios.exe FirewallRules: [UDP Query User{239D9D79-7A42-4FBE-9ECF-714C521964E0}C:\program files (x86)\gigabyte\@bios\flashbios.exe] => (Allow) C:\program files (x86)\gigabyte\@bios\flashbios.exe FirewallRules: [{0E71694A-8860-4AB3-A75A-755573F8E1D3}] => (Allow) F:\Games\Steam Games\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{8AEBC952-C1EF-4B25-8769-91BBC953792C}] => (Allow) F:\Games\Steam Games\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{FABFBDA7-0A73-41A9-92FA-7D687DA0695E}] => (Allow) C:\WINDOWS\AutoKMS\AutoKMS.exe FirewallRules: [{46DD742F-571C-45E2-9846-CE588F85E7A8}] => (Allow) C:\WINDOWS\AutoKMS\AutoKMS.exe FirewallRules: [TCP Query User{48C31DFC-E39C-4563-BBD0-8B406309225A}C:\program files (x86)\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\java.exe FirewallRules: [UDP Query User{B40FB3EF-AC50-456A-BCDC-ED9ADF4FDED1}C:\program files (x86)\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\java.exe FirewallRules: [{5C28360D-C1E7-4D7F-B8C9-AABF6C9E7C53}] => (Allow) F:\Games\Steam Games\steamapps\common\CodeSpells\codespells.exe FirewallRules: [{754305BA-B09B-4D89-B90D-9369CA488B0F}] => (Allow) F:\Games\Steam Games\steamapps\common\CodeSpells\codespells.exe FirewallRules: [TCP Query User{4D7FD681-6AD4-436C-9F9F-F96020A7FE86}F:\games\steam games\steamapps\common\h1z1 king of the kill test server\h1z1.exe] => (Allow) F:\games\steam games\steamapps\common\h1z1 king of the kill test server\h1z1.exe FirewallRules: [UDP Query User{980520E7-D3E6-4D02-8525-303DE4878DB3}F:\games\steam games\steamapps\common\h1z1 king of the kill test server\h1z1.exe] => (Allow) F:\games\steam games\steamapps\common\h1z1 king of the kill test server\h1z1.exe FirewallRules: [{3C027D62-17BB-4B37-A0EB-4B3229BE7970}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{2BDB0891-57FB-4822-8615-B115568EF835}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{958C05BB-59CF-4234-9B7B-64DC97205B66}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{3539BAF5-14E7-4B34-9FBD-DDDAD90E14C9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [TCP Query User{51D83418-FFF7-47D0-AC70-AAB590B62F36}F:\games\steam games\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) F:\games\steam games\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe FirewallRules: [UDP Query User{4D27EAD7-8A4B-4025-BFD2-9D52547A10A7}F:\games\steam games\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) F:\games\steam games\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe FirewallRules: [{6F4301BD-7CF8-4550-9A6E-90E816BCC632}] => (Allow) F:\Games\Steam Games\steamapps\common\EVGA PrecisionX\PrecisionX_x64.exe FirewallRules: [{9B1C20F0-BA13-43FF-8ED1-2FD636FA8663}] => (Allow) F:\Games\Steam Games\steamapps\common\EVGA PrecisionX\PrecisionX_x64.exe FirewallRules: [{DAAC4A82-655B-4E56-84B3-ECF0F3BDBA02}] => (Allow) F:\Games\Steam Games\steamapps\common\EVGA PrecisionX\Skins\UxfTool.exe FirewallRules: [{589E68A8-F198-4941-B446-AAE9D0077057}] => (Allow) F:\Games\Steam Games\steamapps\common\EVGA PrecisionX\Skins\UxfTool.exe FirewallRules: [{023D224B-BFAF-49E5-B0A2-0C407A32C6A9}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1Trial.exe FirewallRules: [{1AA7D12B-5972-43F5-A010-5BCCAEF77C82}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1Trial.exe FirewallRules: [{248B3DC4-93E8-4464-B08D-20136D03CE40}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1.exe FirewallRules: [{B6F2827A-A612-40EE-87AD-08CEBFD6786D}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1.exe FirewallRules: [{88AC7F92-D4D2-4AD7-A862-A1F8A523A9F6}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\57.0.2987.37\remoting_host.exe FirewallRules: [{6D6F6C02-CBAA-4072-8AFC-B83E38593ECD}] => (Allow) F:\Games\Steam Games\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{B9A4E790-D1F9-4495-AEAF-740184693960}] => (Allow) F:\Games\Steam Games\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [TCP Query User{96D925D7-F4CA-44AD-A535-C195514586E8}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{667E6896-51E0-4DFE-B45E-3FA9FC4B0687}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{73659037-A19E-4738-8B7D-0E1F233C8621}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{5E973A5A-9C2A-49BD-86EC-9E41D60DAC2F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{A2DD0B73-23F2-42D6-9327-EC9DFBE68DF3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{641DCE8D-6687-4E7D-ADFD-F3D06E7599E1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [TCP Query User{FAF3E68A-6406-482B-8780-FCD2B47425AD}C:\program files\telestream\gameshow\gameshow.exe] => (Allow) C:\program files\telestream\gameshow\gameshow.exe FirewallRules: [UDP Query User{9F14FB61-527A-4E02-8F83-9FD3D1A1331A}C:\program files\telestream\gameshow\gameshow.exe] => (Allow) C:\program files\telestream\gameshow\gameshow.exe FirewallRules: [TCP Query User{AA751268-2F2C-476C-A984-686F73238305}F:\games\destiny 2\destiny2.exe] => (Allow) F:\games\destiny 2\destiny2.exe FirewallRules: [UDP Query User{9B2905A1-6C27-4FF7-8A50-734F293A5717}F:\games\destiny 2\destiny2.exe] => (Allow) F:\games\destiny 2\destiny2.exe FirewallRules: [{9E68D931-C9AC-4912-ADDB-8EF6BE1AA19B}] => (Allow) F:\Games\Steam Games\steamapps\common\Deceit\bin\win_x64\Deceit.exe FirewallRules: [{6C45B1B3-A50E-4982-8279-69089CE2EE01}] => (Allow) F:\Games\Steam Games\steamapps\common\Deceit\bin\win_x64\Deceit.exe FirewallRules: [{2EB49E0E-DD3F-4400-87B1-9E1D175FF8C1}] => (Allow) F:\Games\Steam Games\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe FirewallRules: [{1637C8E0-651E-4D23-9CC6-D4155A8E65ED}] => (Allow) F:\Games\Steam Games\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe FirewallRules: [{C770BF71-08C1-45CF-AA65-99689B0AABB6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [TCP Query User{6788A9D9-BB2F-45EF-A2CE-2710F61245A6}C:\users\lucas\appdata\local\gpmdp_3\app-4.4.1\google play music desktop player.exe] => (Allow) C:\users\lucas\appdata\local\gpmdp_3\app-4.4.1\google play music desktop player.exe FirewallRules: [UDP Query User{CEE19149-5FD9-43F3-87A3-C6EEFD37B4CD}C:\users\lucas\appdata\local\gpmdp_3\app-4.4.1\google play music desktop player.exe] => (Allow) C:\users\lucas\appdata\local\gpmdp_3\app-4.4.1\google play music desktop player.exe ==================== Restore Points ========================= 16-10-2017 13:35:26 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= Name: ExpressVPN Tap Adapter Description: ExpressVPN Tap Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: ExpressVPN Service: tapexpressvpn Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (10/23/2017 04:01:50 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Visual Studio 14.0\VC\redist\1033\vcredist_arm.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (10/23/2017 04:00:48 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "c:\program files (x86)\adobe\adobe creative cloud\utils\Creative Cloud Uninstaller.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b.manifest. Error: (10/23/2017 04:00:23 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Visual Studio 14.0\VC\redist\1033\vcredist_arm.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (10/23/2017 04:00:20 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files (x86)\razer\razer cortex\StreamingServicesAPI.dll.Manifest".Error in manifest or policy file "c:\program files (x86)\razer\razer cortex\StreamingServicesAPI.dll.Manifest" on line 2. The value "F:\joju\projects\XSplitCSDemo\RazerLauncher\Components\StreamingServicesAPI.dll" of attribute "name" in element "urn:schemas-microsoft-com:asm.v1^file" is invalid. Error: (10/23/2017 03:56:17 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LUCAS-PC) Description: Activation of app Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (10/23/2017 03:54:39 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "c:\program files (x86)\adobe\adobe creative cloud\utils\Creative Cloud Uninstaller.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b.manifest. Error: (10/23/2017 03:54:30 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files (x86)\razer\razer cortex\StreamingServicesAPI.dll.Manifest".Error in manifest or policy file "c:\program files (x86)\razer\razer cortex\StreamingServicesAPI.dll.Manifest" on line 2. The value "F:\joju\projects\XSplitCSDemo\RazerLauncher\Components\StreamingServicesAPI.dll" of attribute "name" in element "urn:schemas-microsoft-com:asm.v1^file" is invalid. Error: (10/23/2017 03:52:45 AM) (Source: nssm) (EventID: 1018) (User: ) Description: Failed to read registry value AppDirectory: The operation completed successfully. Error: (10/23/2017 03:46:35 AM) (Source: nssm) (EventID: 1018) (User: ) Description: Failed to read registry value AppDirectory: The operation completed successfully. Error: (10/23/2017 03:42:34 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Runeapps.Alt1.exe, version: 1.4.5.0, time stamp: 0x59659d14 Faulting module name: KERNELBASE.dll, version: 10.0.14393.1770, time stamp: 0x59bf2bcf Exception code: 0xc000041d Fault offset: 0x000daa12 Faulting process id: 0x2e2c Faulting application start time: 0x01d34b8b597303d0 Faulting application path: C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report Id: 77718dc9-c849-46a1-95fa-037d0dd7436f Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (10/23/2017 03:56:28 AM) (Source: DCOM) (EventID: 10010) (User: LUCAS-PC) Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout. Error: (10/23/2017 03:56:27 AM) (Source: DCOM) (EventID: 10001) (User: LUCAS-PC) Description: Unable to start a DCOM Server: Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider as Unavailable/Unavailable. The error: "31" Happened while starting this command: "C:\WINDOWS\System32\BackgroundTaskHost.exe" -ServerName:BackgroundTaskHost.WebAccountProvider Error: (10/23/2017 03:54:51 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Connected Devices Platform Service service terminated with the following error: Unspecified error Error: (10/23/2017 03:54:28 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Connected Devices Platform Service service terminated with the following error: Unspecified error Error: (10/23/2017 03:53:41 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (10/23/2017 03:52:45 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (10/23/2017 03:52:45 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The BstHdDrv service failed to start due to the following error: The system cannot find the file specified. Error: (10/23/2017 03:52:24 AM) (Source: DCOM) (EventID: 10010) (User: LUCAS-PC) Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout. Error: (10/23/2017 03:51:24 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Connected Devices Platform Service service terminated with the following error: Unspecified error Error: (10/23/2017 03:49:35 AM) (Source: DCOM) (EventID: 10010) (User: LUCAS-PC) Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout. CodeIntegrity: =================================== Date: 2017-10-19 02:44:56.718 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-10-15 22:07:15.589 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-10-13 21:26:52.739 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-10-12 08:41:56.778 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-10-11 03:53:16.098 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-10-03 20:16:50.949 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-30 22:10:18.994 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-24 22:01:42.834 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-23 22:49:39.507 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-21 02:52:39.473 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz Percentage of memory in use: 23% Total physical RAM: 16336.38 MB Available physical RAM: 12571.92 MB Total Virtual: 19017.38 MB Available Virtual: 15050.52 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:223.13 GB) (Free:6.98 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: (Garbage) (Fixed) (Total:149.05 GB) (Free:15.39 GB) NTFS Drive e: (Back Up) (Fixed) (Total:745.21 GB) (Free:27.48 GB) NTFS Drive f: (Games) (Fixed) (Total:894.25 GB) (Free:601.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 306FFBC1) Partition 1: (Active) - (Size=223.1 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=450 MB) - (Type=27) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: C964157A) Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 894.3 GB) (Disk ID: 6B4F1066) Partition 1: (Not Active) - (Size=894.3 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 745.2 GB) (Disk ID: 828A7BD1) Partition 1: (Not Active) - (Size=745.2 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================