Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-10-2017 01 Ran by [removed] (24-10-2017 20:25:00) Running from C:\Users\[removed]\Desktop Windows 10 Pro Version 1607 14393.1770 (X64) (2016-09-29 13:41:37) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3154826165-2591789761-3766887662-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3154826165-2591789761-3766887662-503 - Limited - Disabled) Guest (S-1-5-21-3154826165-2591789761-3766887662-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3154826165-2591789761-3766887662-1004 - Limited - Enabled) Lucas (S-1-5-21-3154826165-2591789761-3766887662-1001 - Administrator - Enabled) => C:\Users\Lucas Luucas (S-1-5-21-3154826165-2591789761-3766887662-1020 - Limited - Enabled) => C:\Users\purpl ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) @BIOS B16.0307.1 (HKLM-x32\...\{C9D46F25-5F9D-4E25-B24F-BC00E9EDF529}) (Version: 3.00.0000 - GIGABYTE) Hidden @BIOS B16.0307.1 (HKLM-x32\...\InstallShield_{C9D46F25-5F9D-4E25-B24F-BC00E9EDF529}) (Version: 3.00.0000 - GIGABYTE) 64 Bit HP CIO Components Installer (HKLM\...\{3138F992-045B-4F55-825C-53B231E647CA}) (Version: 13.2.1 - Hewlett-Packard) Hidden Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.012.20098 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 24.0.0.180 - Adobe Systems Incorporated) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.3.0.151 - Adobe Systems Incorporated) Adobe Flash Player 26 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 26.0.0.151 - Adobe Systems Incorporated) Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0.1 - Adobe Systems Incorporated) Alt1 Toolkit (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\Alt1Toolkit) (Version: 1.4.5 - RuneApps) Ambient LED (HKLM-x32\...\{BEF97B38-D1B8-45B4-A60A-AF5C1556CC72}) (Version: 1.00.1605.1801 - GIGABYTE) Hidden Ambient LED (HKLM-x32\...\InstallShield_{BEF97B38-D1B8-45B4-A60A-AF5C1556CC72}) (Version: 1.00.1605.1801 - GIGABYTE) Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 385.41 - NVIDIA Corporation) Hidden APP Center (HKLM-x32\...\{D50BEE9A-0EC6-4A58-BF90-35BDC6D6495D}) (Version: 1.00.1701.0301 - GIGABYTE) Hidden APP Center (HKLM-x32\...\InstallShield_{D50BEE9A-0EC6-4A58-BF90-35BDC6D6495D}) (Version: 1.00.1701.0301 - GIGABYTE) Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{9F429DF7-F8DD-4980-9673-E6DACA012F6C}) (Version: 3.3 - Microsoft Corporation) Hidden AutoHotkey 1.1.23.05 (HKLM\...\AutoHotkey) (Version: 1.1.23.05 - Lexikos) Azure AD Authentication Connected Service (HKLM-x32\...\{3FEAC561-1CF6-41D6-B0F3-BECDD9C88A1B}) (Version: 14.0.23107 - Microsoft Corporation) Hidden AzureTools.Notifications (HKLM-x32\...\{1E5CA362-39B6-4BD0-B9C0-69CF15F0FEA2}) (Version: 2.7.30611.1601 - Microsoft Corporation) Hidden Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield™ 1 (HKLM-x32\...\{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.49.52296 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Betternet for Windows (HKLM-x32\...\{2E77104D-96E1-4A9C-86F2-C7CF4C70EB35}) (Version: 3.6.0.0 - Betternet Technologies Inc.) BIOS Setup (HKLM-x32\...\{9D48202D-C767-40E7-8A4E-C14BD7328168}) (Version: 1.00.0000 - GIGABYTE) Hidden BIOS Setup (HKLM-x32\...\InstallShield_{9D48202D-C767-40E7-8A4E-C14BD7328168}) (Version: 1.00.0000 - GIGABYTE) Blend for Visual Studio SDK for .NET 4.5 (HKLM-x32\...\{37E53780-3944-4A6A-842F-727128E8616E}) (Version: 3.0.40218.0 - Microsoft Corporation) Hidden BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.9.30.9239 - BlueStack Systems, Inc.) BlueStacks Notification Center (HKLM-x32\...\{3792811C-832F-4392-B44A-24092901EDDC}) (Version: 0.9.30.9239 - BlueStack Systems, Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.25 - Piriform) Chrome Remote Desktop Host (HKLM-x32\...\{88D5D9A4-48C4-4D0A-88B9-3E18661CF0D9}) (Version: 57.0.2987.37 - Google Inc.) Click Install if prompted (HKLM-x32\...\{92A9572E-834E-477B-A100-C9AD3EE4B4B9}) (Version: 1.0.0.0 - ExpressVpn) Hidden CloudStation (HKLM-x32\...\{6D8DA122-A40A-421B-9D95-FE4C806BCDBE}) (Version: 1.00.0021 - GIGABYTE) Hidden CloudStation (HKLM-x32\...\InstallShield_{6D8DA122-A40A-421B-9D95-FE4C806BCDBE}) (Version: 1.00.0021 - GIGABYTE) CPUID CPU-Z 1.81 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.81 - ) CPUID HWMonitor 1.28 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) CPUID HWMonitor Pro 1.28 (HKLM\...\CPUID HWMonitorPro_is1) (Version: - ) Curse (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse) Curse Client (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\101a9f93b8f0bb6f) (Version: 5.1.1.844 - Curse) Destiny 2 (HKLM-x32\...\Destiny 2) (Version: - Blizzard Entertainment) Discord (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\Discord) (Version: 0.0.298 - Discord Inc.) Dotfuscator and Analytics Community Edition 5.18.1 (HKLM-x32\...\{9890DF1A-10E9-4236-94B1-1EFAA4099F13}) (Version: 5.18.1.2898 - PreEmptive Solutions) Hidden DZLauncher version 0.1.5.5 (HKLM-x32\...\{1E299AE2-74C8-4CD8-6B17-A86E0ED3C4D2}_is1) (Version: 0.1.5.5 - Maca134) EasyTune (HKLM-x32\...\{7F635314-EE21-4E4B-A68D-69AE70BA0E9B}) (Version: 1.16.1117 - GIGABYTE) Hidden EasyTune (HKLM-x32\...\InstallShield_{7F635314-EE21-4E4B-A68D-69AE70BA0E9B}) (Version: 1.16.1117 - GIGABYTE) EasyTuneEngineService (HKLM-x32\...\{964575C3-5820-4642-A89A-754255B5EFE1}) (Version: 1.16.0614 - GIGABYTE) Hidden EasyTuneEngineService (HKLM-x32\...\InstallShield_{964575C3-5820-4642-A89A-754255B5EFE1}) (Version: 1.16.0614 - GIGABYTE) Electrum (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\Electrum) (Version: 2.6.4 - Electrum Technologies GmbH) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) EVGA Precision XOC (HKLM-x32\...\{D705C0CA-D900-45AB-85A7-AD651F7055A6}) (Version: 6.0.9 - EVGA Corporation) ExpressVPN (HKLM-x32\...\{10EB2DEF-3C7F-40DD-8C58-438906E20D08}) (Version: 6.2.3.2578 - ExpressVPN) Hidden ExpressVPN (HKLM-x32\...\{a219f179-a66a-48db-934c-aca0746714e5}) (Version: 6.2.3.2578 - ExpressVPN) Fallout 4 (HKLM-x32\...\Fallout 4_is1) (Version: - ) FileZilla Client 3.14.1 (HKLM-x32\...\FileZilla Client) (Version: 3.14.1 - Tim Kosse) Gameshow (HKLM\...\{175C6EA4-691D-483E-A453-D191E9C45491}) (Version: 3.9.0 - Telestream LLC) Geeks3D FurMark 1.18.2.0 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: - Geeks3D) GigabyteFirmwareUpdateUtility (HKLM-x32\...\{1CBA99CE-1AB3-4366-AFB4-7F7B75EBBE35}) (Version: 1.00.0000 - GIGABYTE) Hidden GigabyteFirmwareUpdateUtility (HKLM-x32\...\InstallShield_{1CBA99CE-1AB3-4366-AFB4-7F7B75EBBE35}) (Version: 1.00.0000 - GIGABYTE) glogg (HKLM-x32\...\glogg) (Version: 1.1.1-x86_64 - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.) Google Cloud SDK (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\Google Cloud SDK) (Version: - Google Inc.) Google Play Music Desktop Player (HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\GPMDP_3) (Version: 4.4.1 - Samuel Attard) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.31.5 - Google Inc.) Hidden Gpg4win (2.2.1) (HKLM-x32\...\GPG4Win) (Version: 2.2.1 - The Gpg4win Project) Gyazo 3.3.3 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.) IIS 10.0 Express (HKLM\...\{5984D8DA-C1AF-4284-9C88-D7150425B315}) (Version: 10.0.1734 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version: - ) IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version: - ) Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.15 - Oracle Corporation) KB4023057 (HKLM\...\{0C050BEE-16BE-4998-8959-2A421433DB6E}) (Version: 2.5.0.0 - Microsoft Corporation) Killer Bandwidth Control Filter Driver (HKLM\...\{89A9DA12-B6F1-4966-95B3-574EEB6DF07E}) (Version: 1.1.65.1357 - Rivet Networks) Hidden Killer E240x Drivers (HKLM\...\{C2AAF672-E3A2-403A-942F-7B9C9B4E592E}) (Version: 1.1.65.1357 - Rivet Networks) Hidden Killer Network Manager (HKLM\...\{F2BE14C9-4659-4335-B964-0E76AE0D2EE7}) (Version: 1.1.65.1357 - Rivet Networks) Hidden Killer Performance Suite (HKLM-x32\...\{75269D5A-2CE7-48D1-8169-5744C83C574F}) (Version: 1.1.65.1357 - Rivet Networks) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Logitech Gaming Software 8.94 (HKLM\...\Logitech Gaming Software) (Version: 8.94.108 - Logitech Inc.) Malwarebytes version 3.2.2.2029 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2029 - Malwarebytes) Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 Targeting Pack (ENU) (HKLM-x32\...\{3D3CEBE6-40EA-4C48-97FD-73828281AB4A}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Build Tools 2015 (HKLM-x32\...\{d21da0dd-4ba4-4838-ba58-64cf7a77131a}) (Version: 14.0.23107.10 - Microsoft Corporation) Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 T-SQL Language Service (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - enu (14.0.50616.0) (HKLM-x32\...\{58246C80-3941-4B69-AE31-264644E2ADB8}) (Version: 14.0.50616.0 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{68BA34E8-9B9D-4A74-83F0-7D366B532D75}) (Version: 12.0.2402.11 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{718FFB65-F6E4-4D62-861F-ED10ED32C936}) (Version: 12.0.2402.11 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual FoxPro 9.0 Professional - English (HKLM-x32\...\Visual FoxPro 9.0 Professional - English) (Version: - Microsoft) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio Community 2015 (HKLM-x32\...\{50b32652-69d2-4b93-9316-edcd12067b8b}) (Version: 14.0.23107.10 - Microsoft Corporation) Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation) Mozilla Firefox 41.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 41.0.2 (x86 en-US)) (Version: 41.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 41.0.2 - Mozilla) Multi-Device Hybrid Apps using C# - Templates - ENU (HKLM-x32\...\{12D99739-FFD3-3761-8AA6-F929E0FE407E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.63.14 - Black Tree Gaming) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.3 - Notepad++ Team) NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Driver 385.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 385.41 - NVIDIA Corporation) NVIDIA GeForce Experience 3.9.0.97 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.9.0.97 - NVIDIA Corporation) NVIDIA Graphics Driver 385.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 385.41 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.27 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.27 - NVIDIA Corporation) NVIDIA PhysX System Software 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation) OBS Studio (HKLM-x32\...\OBS Studio) (Version: 18.0.1 - OBS Project) OldSchool RuneScape Launcher 1.2.7 (HKLM-x32\...\{FEDDCE73-34B8-4980-90B8-8619A78C902C}) (Version: 1.2.7 - Jagex Ltd) ON_OFF Charge 2 B15.0709.1 (HKLM-x32\...\{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE) Hidden ON_OFF Charge 2 B15.0709.1 (HKLM-x32\...\InstallShield_{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) Origin (HKLM-x32\...\Origin) (Version: 10.4.14.21968 - Electronic Arts, Inc.) Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) Overwolf (HKLM-x32\...\Overwolf) (Version: 0.107.254.0 - Overwolf Ltd.) PNY Drive Utility (HKLM-x32\...\{F7F0273F-68B7-44EA-AD7B-1C9F9C29C562}) (Version: 1.0.8 - PNY Technologies) PreEmptive Analytics Visual Studio Components (HKLM-x32\...\{436A18DD-5F2C-4B3C-985E-AD3C13B0CC25}) (Version: 1.2.5134.1 - PreEmptive Solutions) Hidden Prerequisites for SSDT (HKLM-x32\...\{21373064-AD95-48DB-A32E-0D9E08EF7355}) (Version: 12.0.2000.8 - Microsoft Corporation) Process Hacker 2.39 (r124) (HKLM\...\Process_Hacker2_is1) (Version: 2.39.0.124 - wj32) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Python 2.7.11 (HKLM-x32\...\{16E52445-1392-469F-9ADB-FC03AF00CD61}) (Version: 2.7.11150 - Python Software Foundation) Python 3.4.0 (64-bit) (HKLM\...\{863162a8-ecc2-35ea-bdf7-e09ac456e164}) (Version: 3.4.150 - Python Software Foundation) Razer Chroma SDK Core Components (HKLM-x32\...\Razer Chroma SDK) (Version: 2.3.6 - Razer Inc.) Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 7.6.8.66 - Razer Inc.) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.20.17.413 - Razer Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7765 - Realtek Semiconductor Corp.) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.0 - Rockstar Games) Roslyn Language Services - x86 (HKLM-x32\...\{5B47029B-1E62-30FF-906E-694851C22782}) (Version: 14.0.23107 - Microsoft Corporation) Hidden Roslyn Language Services - x86 (HKLM-x32\...\{6C1985E7-E1C5-3A95-86EF-2C62465F15C3}) (Version: 14.0.23107 - Microsoft Corporation) Hidden RuneScape Launcher 2.2.4 (HKLM\...\RuneScape Launcher_is1) (Version: 2.2.4 - Jagex Ltd) Sandboxie 5.18 (64-bit) (HKLM\...\Sandboxie) (Version: 5.18 - Sandboxie Holdings, LLC) Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.) Spotflux (HKLM-x32\...\Spotflux) (Version: 3.2.0 - Spotflux) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Team Explorer for Microsoft Visual Studio 2015 (HKLM-x32\...\{791295AE-3B0A-3222-9E69-26C8C106E8D1}) (Version: 14.0.23102 - Microsoft Corporation) Hidden TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.72365 - TeamViewer) TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) Test Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{9EABBFE1-7EED-47D9-8FB8-21D7E4808057}) (Version: 14.0.23107 - Microsoft Corporation) Hidden TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.2 - TrueCrypt Foundation) TypeScript Power Tool (HKLM-x32\...\{E51EAA08-F838-4CCE-B011-A82469BE6CC5}) (Version: 1.6.3.0 - Microsoft Corporation) Hidden TypeScript Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{F0AF1E33-1CB9-4377-ABEE-4E4550A3F9BA}) (Version: 1.6.3.0 - Microsoft Corporation) Hidden TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 (HKLM-x32\...\{da31aa25-410a-4c1b-9ec0-114dd8dff786}) (Version: 1.6.23313.0 - Microsoft Corporation) Universal CRT Extension SDK (HKLM-x32\...\{284FA9A0-CEDD-81D3-5A19-5858E95FD0C4}) (Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Headers Libraries and Sources (HKLM-x32\...\{ABD37F71-FC3F-F525-C7B3-BDD95F684C51}) (Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Redistributable (HKLM-x32\...\{74E0F5DD-514A-4F85-0EE0-1E2EBB8BFC8C}) (Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Tools x64 (HKLM\...\{4C8DCEB6-5D3C-90BD-6E31-A8342B9185FF}) (Version: 10.0.10150 - Microsoft Corporation) Hidden Universal CRT Tools x86 (HKLM-x32\...\{DE0B03D4-5A26-DEEC-F62E-278EF28BA58E}) (Version: 10.0.10150 - Microsoft Corporation) Hidden Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation) Vegas Pro 13.0 (64-bit) (HKLM\...\{1EEE0BEE-0BC8-11E5-A19E-F04DA23A5C58}) (Version: 13.0.453 - Sony) Virtual Audio Cable 4.15 (HKLM\...\Virtual Audio Cable 4.15) (Version: - ) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN) Vulkan Run Time Libraries 1.0.51.0 (HKLM\...\VulkanRT1.0.51.0) (Version: 1.0.51.0 - LunarG, Inc.) WCF Data Services 5.6.4 Runtime (HKLM-x32\...\{DB85E7BD-B2DD-43D4-B3C0-23D7B527B597}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{0A3B508E-5638-4471-BCC9-954E1868CB86}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden Windows 10 Update and Privacy Settings (HKLM\...\{4DFCD818-036A-4229-A67D-CF17DC461D92}) (Version: 1.0.14.0 - Microsoft Corporation) WinRAR 5.30 beta 5 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.5 - win.rar GmbH) Wise Force Deleter 1.4.6 (HKLM-x32\...\Wise Force Deleter_is1) (Version: 1.4.6 - WiseCleaner.com, Inc.) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) XSplit Broadcaster (HKLM-x32\...\{5B006BC4-6763-4BC4-9FEE-77E305E1C3F9}) (Version: 2.9.1611.1627 - SplitmediaLabs) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3154826165-2591789761-3766887662-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-F9A1E5447705}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File CustomCLSID: HKU\S-1-5-21-3154826165-2591789761-3766887662-1001_Classes\CLSID\{9b2ddd1a-b426-4883-b8f8-cf11ff961155}\InprocServer32 -> C:\WINDOWS\system32\dfshim.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3154826165-2591789761-3766887662-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-09-11] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-09-11] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-09-11] () ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => -> No File ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => -> No File ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => -> No File ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => -> No File ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => -> No File ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => -> No File ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes) ContextMenuHandlers3: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-14] () ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => -> No File ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-08-21] (NVIDIA Corporation) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes) ContextMenuHandlers6: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-14] () ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {07357B02-9DCB-4825-87A2-B4A76062DFB7} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {0B74F626-E98B-41D3-8BD4-D09F2C93807B} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2017-10-03] () Task: {0D0E65D1-6B30-4B49-9F70-D48E775E6F56} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2017-10-17] (Overwolf LTD) Task: {1924AE72-870F-47CC-B6CC-5155B913EC50} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {1DC9F707-1D59-4053-9688-44F871B525CF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {242AAFBF-3F47-412B-8598-E6E805420AFB} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {257436E5-4A00-4B37-BA15-1DE7D23B4A3A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated) Task: {2C350C65-6623-45E3-B19A-51A8F5870E44} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {2E3281A4-1159-47D7-8833-9F5C34B9C762} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {2E530D42-E2C2-4DB8-9BB7-93975DE43405} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION Task: {315FC891-ABE7-4465-B9C1-B5015F1B48AA} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe Task: {3AC9D602-151A-4951-B754-E60AB3B4FC09} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {3AE31897-E114-4A18-88FB-19F82125498D} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {3BA43A7F-42BE-4377-BF2E-0421F6CC495F} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-09-19] (NVIDIA Corporation) Task: {460DE789-B53E-4088-B913-98B86BC0FEC6} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {4B50EFBC-D323-47F4-9A38-BB9984ACE752} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-09-19] (NVIDIA Corporation) Task: {4F846DEB-9C8B-49D6-A8F4-1620A09EB120} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {52E39460-CE1D-4677-B515-A5AF24EEC82D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {54285F0C-A22F-4A6A-A813-A3239F9219DD} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {561411E0-495F-4ACD-BE3B-C043BE1BD9A5} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {63F9A26F-1FFE-42BF-98EC-CCBE71C65085} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {649139EA-A1C5-4200-B835-2C8B773E8A33} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3154826165-2591789761-3766887662-1020 => C:\Users\Lucas\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe Task: {6739D9C1-8BB4-407A-BED2-750116E7E015} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-09-19] (NVIDIA Corporation) Task: {67BB6B4D-9DDE-46FA-BC8A-BBA2EC185C96} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {6A5986EB-4C64-47A0-B653-40663D0F5655} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-09-19] (NVIDIA Corporation) Task: {6E2C860E-493F-44C6-A0D8-E494AF7555AD} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {72D29BD6-96FB-4297-8D5F-A8F19B56AB49} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {7D74CB73-7BBE-4D0A-B5B7-DA2B44ABA78B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-10-11] (Microsoft Corporation) Task: {7EF05A0D-B29A-410A-974E-F3ED5118EFD4} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {845E989A-5F76-451C-86D2-03B0D20678C6} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {95FA2C0C-BD2D-4753-A7CB-4DC31034FED0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {9E804A72-8815-4DCA-B0B9-4A75CD286A7B} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A252A9DD-3F0A-42DA-A8D4-4F9D4E854560} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-09-19] (NVIDIA Corporation) Task: {A5F46391-C50B-46B4-B155-D5CA07302DB7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A6ED3CA2-3657-4391-ACBA-84ACF7A42CD0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {B48B179B-F4F3-4242-BC0F-762E32B3632E} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-09-19] (NVIDIA Corporation) Task: {B49617F1-2F51-4EA0-B432-C7AC8F9C8A85} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {BA017E49-6162-42DB-8CD1-5F5CE79BC412} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {BA281154-C29E-49C3-92AD-B9443B03BA20} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-06] (Piriform Ltd) Task: {BA8E25D7-7816-4EE0-8EF4-05D6FA92627B} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {BC46F310-DEA8-485C-9AB1-DD68272DB48D} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {BE38801C-4D81-4A50-9ED8-CEAE09A6E0F9} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2017-10-03] () Task: {C809C924-6550-4F79-86DB-10B16F167B15} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-09-19] (NVIDIA Corporation) Task: {CB87050A-A878-4FF3-B98F-DBD27B9B71C9} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe Task: {D0C233DE-573D-4DFD-824A-8A72FC4BCF9E} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {D1F06D01-F730-42EB-BBA4-06D3FC7D69DB} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-09-19] (NVIDIA Corporation) Task: {D4B40063-F209-4BDF-A245-C7321220B2BF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {DEA1C216-3829-4241-8CAC-A55A8FC15CEE} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {EA488CCF-6C12-4F42-BDFC-E271DA196991} - System32\Tasks\EVGAPrecisionX => F:\Games\Steam Games\steamapps\common\EVGA PrecisionX\PrecisionX_x64.exe [2017-09-06] (EVGA Corp.) Task: {F5986750-FA2B-40A8-B345-7F8FD1A55AB4} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {F78D36C5-18B8-4F57-B337-5CEBC262292C} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - AfkWarden.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/afkscape/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Clue solver.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/clue/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - ColorGrabber.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/colorgrabber/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - D&D Notifications.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/notifications/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - DgKey.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/dgkey/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Droplogger.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/droplogger/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Farming Timer.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/farmtimer/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Fish Flingers.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/fishflingers/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Meg answers.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/meg/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Notepad.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/notepad/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - RS Wiki.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/object/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Stats.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/stats/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Stopwatch.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/timer/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Twitch.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/twitch/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - World map.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/map/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - XpMeter.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/xpmeter/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneApps\Alt1 - Youtube.lnk -> C:\Users\Lucas\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe (RuneApps) -> protocolurl=alt1://openapp/hxxp://runeapps.org/apps/alt1/youtube/appconfig.json ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Cloud SDK\Google Cloud SDK Shell.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /k ""C:\Users\Lucas\AppData\Local\Google\Cloud SDK\cloud_env.bat"" ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ad,Block Plus.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gojdigjopnhgodnciccmjddabckjanko ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome RDP for Google Cloud Platform.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=mpbbnannobiobpnfblimoapbephgifkm ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome RDP.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=cbkkbcmdlboombapidmoeolnmdacpkch ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp ShortcutWithArgument: C:\Users\Lucas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\TwitchAlerts Stream Labels.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=kgmggmdngboajiakmbpdknfpdelbjbcg ==================== Loaded Modules (Whitelisted) ============== 2016-07-16 06:42 - 2016-07-16 06:42 - 000231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2017-09-12 20:22 - 2017-09-07 01:01 - 002681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2015-12-02 12:15 - 2016-12-15 05:37 - 000020208 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\TeamViewer_PrintProcessor.dll 2017-07-06 11:22 - 2017-07-06 11:22 - 000331264 _____ () C:\program files (x86)\expressvpn\bootstrap\AMD64\nssm.exe 2017-10-23 03:53 - 2017-10-04 13:15 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-10-23 03:53 - 2017-10-04 13:15 - 002289096 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll 2016-10-12 11:46 - 2017-09-19 02:23 - 001267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-07-06 11:24 - 2017-07-06 11:24 - 009239168 _____ () C:\program files (x86)\expressvpn\xvpnd\xvpnd.exe 2015-09-11 19:02 - 2015-09-11 19:02 - 000803488 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2016-10-31 20:08 - 2016-10-31 20:08 - 001864384 _____ () C:\Users\Lucas\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\ClientTelemetry.dll 2010-01-09 20:17 - 2010-01-09 20:17 - 004254560 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-01-21 01:40 - 2010-01-21 01:40 - 008794464 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2010-07-14 23:44 - 2010-07-14 23:44 - 000020032 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll 2016-09-29 11:26 - 2016-09-29 11:26 - 000134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-03-14 22:54 - 2017-03-04 01:31 - 000474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2017-03-14 22:54 - 2017-03-04 01:12 - 009760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-03-14 22:54 - 2017-03-04 01:05 - 001401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-03-14 22:54 - 2017-03-04 01:05 - 000757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-10-11 08:44 - 2017-09-17 21:14 - 002424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-10-11 08:44 - 2017-09-17 21:16 - 004853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2015-03-06 19:07 - 2015-03-06 19:07 - 000908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2017-07-10 17:35 - 2017-07-10 17:35 - 001096824 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-06 19:07 - 2015-03-06 19:07 - 000060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2017-07-10 17:35 - 2017-07-10 17:35 - 000241784 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2016-10-17 22:53 - 2017-04-23 01:29 - 002493440 _____ () C:\Program Files (x86)\Origin\libGLESv2.dll 2017-07-06 11:25 - 2017-07-06 11:25 - 000441472 _____ () C:\program files (x86)\expressvpn\xvpnd\windows\ExpressVPN.FilterManager.dll 2017-05-22 05:13 - 2017-05-22 05:13 - 000143824 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll 2015-10-16 05:02 - 2015-10-16 05:02 - 000039384 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll 2016-10-12 11:46 - 2017-09-19 02:23 - 001040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Lucas\AppData\Local\Temp:$DATA [16] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 21:34 - 2017-10-23 04:40 - 000000031 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Lucas\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{308f93af-eea4-455f-be4b-5609f37a4533}.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: AdobeUpdateService => 2 MSCONFIG\Services: AGSService => 2 MSCONFIG\Services: BEService => 3 MSCONFIG\Services: BstHdAndroidSvc => 3 MSCONFIG\Services: BstHdLogRotatorSvc => 3 MSCONFIG\Services: BstHdUpdaterSvc => 3 MSCONFIG\Services: CGVPNCliService => 2 MSCONFIG\Services: Creative ALchemy AL6 Licensing Service => 3 MSCONFIG\Services: DirMngr => 2 MSCONFIG\Services: EasyTuneEngineService => 2 MSCONFIG\Services: ExpressVpnService => 2 MSCONFIG\Services: gadjservice => 2 MSCONFIG\Services: gupdate => 3 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: ICCS => 3 MSCONFIG\Services: Killer Service V2 => 2 MSCONFIG\Services: LolScreenSaverService => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: OcButtonService => 2 MSCONFIG\Services: OracleOraDB12Home1MTSRecoveryService => 2 MSCONFIG\Services: OracleOraDB12Home1TNSListener => 2 MSCONFIG\Services: OracleServiceORCL => 2 MSCONFIG\Services: OracleVssWriterORCL => 2 MSCONFIG\Services: Origin Client Service => 3 MSCONFIG\Services: Origin Web Helper Service => 2 MSCONFIG\Services: PnkBstrA => 2 MSCONFIG\Services: Razer Game Scanner Service => 2 MSCONFIG\Services: RipsawUSBPortChecker => 2 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\Services: SpotfluxConnectionManager => 2 MSCONFIG\Services: TeamViewer => 2 MSCONFIG\Services: VMAuthdService => 2 MSCONFIG\Services: VMnetDHCP => 2 MSCONFIG\Services: VMUSBArbService => 2 MSCONFIG\Services: VMware NAT Service => 2 MSCONFIG\Services: VMwareHostd => 2 HKLM\...\StartupApproved\Run: => "ShadowPlay" HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "WindowsDefender" HKLM\...\StartupApproved\Run32: => "Zygor Guides Client" HKLM\...\StartupApproved\Run32: => "UpdReg" HKLM\...\StartupApproved\Run32: => "Sound Blaster X-Fi MB 3" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKLM\...\StartupApproved\Run32: => "WindowsDefender" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\StartupFolder: => "CurseClientStartup.ccip" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "GoToMeeting" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "MurGee.com Auto Clicker" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "f.lux" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "Uninstall C:\Users\Lucas\AppData\Local\Microsoft\OneDrive\17.3.6390.0509" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "Uninstall C:\Users\Lucas\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "Overwolf" HKU\S-1-5-21-3154826165-2591789761-3766887662-1001\...\StartupApproved\Run: => "CCleaner Monitoring" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [UDP Query User{DC7220BB-0ECD-4951-A2FF-2B39239DCE0D}C:\overwatch\overwatch.exe] => (Allow) C:\overwatch\overwatch.exe FirewallRules: [TCP Query User{FDC483D4-17BF-4029-925E-1E671FA6F840}C:\overwatch\overwatch.exe] => (Allow) C:\overwatch\overwatch.exe FirewallRules: [{F8127A34-C034-4EEA-9022-3A51EF36EC69}] => (Allow) %systemroot%\system32\alg.exe FirewallRules: [{3071D213-57F6-4811-A64A-1D1B28722196}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{4B8A083E-C3D5-4A0B-A44A-97496E41B672}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{9A6528FD-C5EB-45DC-9335-0D862B57D586}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{822C10C8-00B6-431C-ACBF-B3FFC4DBF12F}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{80AFB9C8-F19B-4D44-BC87-244E7F3BB0CE}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{4197D857-B053-4447-B821-5E75C98CA6BC}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{CCFADD27-36F3-4EDD-BA79-BD2B2D5B620E}] => (Allow) LPort=3306 FirewallRules: [{F18535AA-D7E5-41A5-B724-9ABC7773E38F}] => (Allow) LPort=3306 FirewallRules: [{C00B72F6-8EEE-4ABB-8731-A15C782BE72E}] => (Allow) C:\Users\Lucas\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{6A7D1A9F-D7F2-41BB-9639-FCE9FA313F5B}] => (Allow) C:\Users\Lucas\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{F9CD2F70-DB5B-4FBA-B8FC-E8678DE3622A}] => (Allow) C:\Users\Lucas\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{6D5CD6D1-A81B-4818-AB72-A9E1FCABB509}] => (Allow) C:\Users\Lucas\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{BA34AC1F-8891-4A18-BD7A-BAD675D4EDB7}] => (Allow) C:\Users\Lucas\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{6ECFC39A-264D-4098-A60D-4F61FD306929}] => (Allow) C:\Users\Lucas\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{40B7A2A4-831F-47A7-A22B-696C2E98A8CF}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶睜湩灯晴汩整屲敲瑳楷潮瑰楦瑬牥⹟硥e FirewallRules: [{8005D10A-1A36-4588-9189-1A08DD910AA0}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶睜湩灯晴汩整屲楷潮瑰楦瑬牥⹟硥e FirewallRules: [{FF1F10AF-D0EC-4922-BCE4-1B70682B73E7}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶睜湩灯晴汩整屲敲瑳楷潮瑰楦瑬牥攮數 FirewallRules: [{D884B386-6771-47E1-9994-217FA2526758}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶睜湩灯晴汩整屲楷潮瑰楦瑬牥攮數 FirewallRules: [{F2CB370D-0DCB-41FF-AA51-1CF91FC0BF26}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{730FE8AC-BEB2-40E3-9E99-1064AEE99F94}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{3B62B3A8-BDC3-49FB-8D2A-91BD30D68BEF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{1DD1EE81-63AD-4E17-820E-EE754C8F7930}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{5CFE1FCE-F37D-43E5-8E16-D3C5ADCB4F91}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{9623489F-5EBE-45EC-8785-58DD81CB04EA}C:\app\lucas\product\12.1.0\dbhome_1\jdk\jre\bin\java.exe] => (Allow) C:\app\lucas\product\12.1.0\dbhome_1\jdk\jre\bin\java.exe FirewallRules: [UDP Query User{07227E41-830D-458D-92DB-A7C628EF14D9}C:\app\lucas\product\12.1.0\dbhome_1\jdk\jre\bin\java.exe] => (Allow) C:\app\lucas\product\12.1.0\dbhome_1\jdk\jre\bin\java.exe FirewallRules: [{F25FED34-818F-48B8-AAA3-12E71DB3C824}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe FirewallRules: [{217E358B-4D32-40C8-845D-0BE7647D1D01}] => (Allow) C:\Users\Lucas\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{786E5A88-6460-4530-8023-68A192053DFA}] => (Allow) C:\Users\Lucas\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{9ABC0BFB-4987-4EE2-BF8C-C02DFF566437}] => (Allow) C:\Users\Lucas\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{F9D9C4CF-D559-40AE-8C55-E29CDF13A989}] => (Allow) C:\Users\Lucas\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{71E9D19E-7B39-4D38-8358-A1BAA11C2EE9}] => (Allow) C:\Users\Lucas\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{5C98B787-3FCA-4F37-A90E-6619EBB3AA5C}] => (Allow) C:\Users\Lucas\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{8D3628AB-89AD-4BF3-892A-C41E5F435E28}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{7886B49C-8B56-4586-BE33-E80E7C2A7F13}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{58E079CD-8D44-42ED-923F-990A91BAB712}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{DE7ECC06-9B64-42DE-90AA-4F2FF76B30BC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{6C3CC19C-B65E-4C80-9055-6C4821998C36}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{8D4CC75F-D984-48AB-8837-6C11C2154A79}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{EF4A3A8C-457A-4922-8675-7E0DA2F7AE6D}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{28970353-6612-4AF8-869D-C7292C82519B}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [TCP Query User{0206AF29-9394-4ABD-8DEF-2430D0797E81}C:\program files (x86)\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\java.exe FirewallRules: [UDP Query User{6EF22BE2-FEB2-4B8C-97A2-69E101EC7800}C:\program files (x86)\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\java.exe FirewallRules: [TCP Query User{296932C2-B69E-40A5-8FA8-B3B7AF1C3FE6}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [UDP Query User{B2A3A37C-7128-429F-BBFC-AC6FF9E57CED}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [TCP Query User{548B47F2-774E-4AE3-8E88-CDE46067C01E}C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe FirewallRules: [UDP Query User{830BD329-5F42-42F0-B4AB-41271F84B410}C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe FirewallRules: [TCP Query User{3ACA33C1-6C25-4154-B4A1-579E61925E30}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe FirewallRules: [UDP Query User{0D4E4F50-4F0C-4D1C-9A94-FAC9770E3B0E}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe FirewallRules: [{B0DF1250-D70B-44EE-82FB-2B23279B117E}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe FirewallRules: [{391E2549-7CDC-4BAF-9F9F-FEE4A5556B93}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe FirewallRules: [TCP Query User{28A0C1CD-159A-472A-A033-7A3DC4D9F1CE}C:\program files (x86)\gigabyte\@bios\flashbios.exe] => (Allow) C:\program files (x86)\gigabyte\@bios\flashbios.exe FirewallRules: [UDP Query User{04C102A4-6394-4936-9F4C-CED6A74B8E05}C:\program files (x86)\gigabyte\@bios\flashbios.exe] => (Allow) C:\program files (x86)\gigabyte\@bios\flashbios.exe FirewallRules: [{5DF66017-43E5-4BAD-A358-7E8B87E8C1B3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{E0890153-350F-4A63-824E-429EF0DD2EE2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{F99D5F5A-C097-424B-8EC3-1DF6318B60F7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{46D00B16-E227-48BD-99C4-F9B8D1758340}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{060A6550-B73A-4A48-8C68-315EA0A13137}] => (Allow) LPort=1688 FirewallRules: [{0CD56545-53DA-44D7-B554-05CBA1F24177}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{625D647E-0949-4E1E-B21A-314CC02A5EDB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{FA774675-2D6E-4D75-B86A-5CEA40F94AC0}] => (Allow) F:\Games\Steam Games\steamapps\common\7 Days To Die\7dLauncher.exe FirewallRules: [{4C3DC9C6-E53C-4B59-A4D1-FBA2FDA7B0D1}] => (Allow) F:\Games\Steam Games\steamapps\common\7 Days To Die\7dLauncher.exe FirewallRules: [{61326436-B540-4E5F-862E-C8878B14B5C9}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1Trial.exe FirewallRules: [{F0DE280C-9768-47CC-B20E-0B80608B9FB1}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1Trial.exe FirewallRules: [{4BA6BEF7-0E7B-4846-9D94-266310E4D104}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1.exe FirewallRules: [{C0A4BBF5-120A-4D9D-8EDE-83B70BA8CE38}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1.exe FirewallRules: [TCP Query User{A48BD95F-A60A-4CC1-B4E7-E35DFD69C428}F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [UDP Query User{1109D7AC-98B7-4EB5-BA61-10DD1123C679}F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [{07A998A5-855A-4ADC-98C3-1F337BAF4A26}] => (Allow) F:\Games\Steam Games\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{80224FE2-F8BB-4517-9EA3-DCD119B1A399}] => (Allow) F:\Games\Steam Games\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{5A882591-6943-4296-9054-F5A99FA8342A}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Broadcaster\XSplit.Core.exe FirewallRules: [{F1183C00-FCD9-4F24-8B8F-848F67FEC1E2}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Broadcaster\XSplit.cam.exe FirewallRules: [{20216630-0E7F-4A7F-960A-440757D81106}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Broadcaster\XSplit.Core.exe FirewallRules: [{8B9CFAA5-C209-4425-B6D2-4757C8CECF3B}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Broadcaster\XSplit.cam.exe FirewallRules: [{2145F215-ACBF-4BE0-817F-B9A3C9A20054}] => (Allow) F:\Games\Steam Games\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{54ECF899-680C-4B87-B79F-D3065424EB52}] => (Allow) F:\Games\Steam Games\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [TCP Query User{648D9CB7-4AE2-4C61-92F6-1DF2024D6C28}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [UDP Query User{0542E0F6-503D-4227-BAA7-0A98D6D40742}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [TCP Query User{8E03A6FB-59C8-4EB6-9CFF-0FD65818486D}C:\overwatch\overwatch.exe] => (Allow) C:\overwatch\overwatch.exe FirewallRules: [UDP Query User{60D39E6C-F638-4841-8DA7-F84E77B2C6A7}C:\overwatch\overwatch.exe] => (Allow) C:\overwatch\overwatch.exe FirewallRules: [TCP Query User{C098C0A7-3D5E-4309-A875-B3858A3B1E5C}F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [UDP Query User{A4A6E199-B03C-4EA4-AC96-A542FC1325CF}F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) F:\games\steam games\steamapps\common\h1z1 king of the kill\h1z1.exe FirewallRules: [TCP Query User{72655C9C-DA8D-4E9D-8B39-63D3510E42D0}C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe FirewallRules: [UDP Query User{BDDAF83F-B5CD-4717-AA61-6E040191DDB9}C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe FirewallRules: [TCP Query User{0BECA25D-FD5A-4C9A-BBE2-D9ACE609F0E3}F:\games\steam games\steamapps\common\grand theft auto v\gta5.exe] => (Allow) F:\games\steam games\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [UDP Query User{175A30D1-A5C2-4B9E-AF1D-F82780891B55}F:\games\steam games\steamapps\common\grand theft auto v\gta5.exe] => (Allow) F:\games\steam games\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [{F2AF137B-1CFE-438C-A4BC-F0C3CB7BC5CC}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe FirewallRules: [{DB8739B5-73E6-4C73-8461-2490F6D6D9A4}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe FirewallRules: [{F349D6C5-7008-43C2-9D64-30FDA4D6249E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [TCP Query User{CD906893-E889-421A-ADD1-A5583C8C9B89}C:\program files (x86)\gigabyte\@bios\flashbios.exe] => (Allow) C:\program files (x86)\gigabyte\@bios\flashbios.exe FirewallRules: [UDP Query User{239D9D79-7A42-4FBE-9ECF-714C521964E0}C:\program files (x86)\gigabyte\@bios\flashbios.exe] => (Allow) C:\program files (x86)\gigabyte\@bios\flashbios.exe FirewallRules: [{0E71694A-8860-4AB3-A75A-755573F8E1D3}] => (Allow) F:\Games\Steam Games\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{8AEBC952-C1EF-4B25-8769-91BBC953792C}] => (Allow) F:\Games\Steam Games\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe FirewallRules: [{FABFBDA7-0A73-41A9-92FA-7D687DA0695E}] => (Allow) C:\WINDOWS\AutoKMS\AutoKMS.exe FirewallRules: [{46DD742F-571C-45E2-9846-CE588F85E7A8}] => (Allow) C:\WINDOWS\AutoKMS\AutoKMS.exe FirewallRules: [TCP Query User{48C31DFC-E39C-4563-BBD0-8B406309225A}C:\program files (x86)\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\java.exe FirewallRules: [UDP Query User{B40FB3EF-AC50-456A-BCDC-ED9ADF4FDED1}C:\program files (x86)\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\java.exe FirewallRules: [{5C28360D-C1E7-4D7F-B8C9-AABF6C9E7C53}] => (Allow) F:\Games\Steam Games\steamapps\common\CodeSpells\codespells.exe FirewallRules: [{754305BA-B09B-4D89-B90D-9369CA488B0F}] => (Allow) F:\Games\Steam Games\steamapps\common\CodeSpells\codespells.exe FirewallRules: [TCP Query User{4D7FD681-6AD4-436C-9F9F-F96020A7FE86}F:\games\steam games\steamapps\common\h1z1 king of the kill test server\h1z1.exe] => (Allow) F:\games\steam games\steamapps\common\h1z1 king of the kill test server\h1z1.exe FirewallRules: [UDP Query User{980520E7-D3E6-4D02-8525-303DE4878DB3}F:\games\steam games\steamapps\common\h1z1 king of the kill test server\h1z1.exe] => (Allow) F:\games\steam games\steamapps\common\h1z1 king of the kill test server\h1z1.exe FirewallRules: [{3C027D62-17BB-4B37-A0EB-4B3229BE7970}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{2BDB0891-57FB-4822-8615-B115568EF835}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{958C05BB-59CF-4234-9B7B-64DC97205B66}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{3539BAF5-14E7-4B34-9FBD-DDDAD90E14C9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [TCP Query User{51D83418-FFF7-47D0-AC70-AAB590B62F36}F:\games\steam games\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) F:\games\steam games\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe FirewallRules: [UDP Query User{4D27EAD7-8A4B-4025-BFD2-9D52547A10A7}F:\games\steam games\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) F:\games\steam games\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe FirewallRules: [{6F4301BD-7CF8-4550-9A6E-90E816BCC632}] => (Allow) F:\Games\Steam Games\steamapps\common\EVGA PrecisionX\PrecisionX_x64.exe FirewallRules: [{9B1C20F0-BA13-43FF-8ED1-2FD636FA8663}] => (Allow) F:\Games\Steam Games\steamapps\common\EVGA PrecisionX\PrecisionX_x64.exe FirewallRules: [{DAAC4A82-655B-4E56-84B3-ECF0F3BDBA02}] => (Allow) F:\Games\Steam Games\steamapps\common\EVGA PrecisionX\Skins\UxfTool.exe FirewallRules: [{589E68A8-F198-4941-B446-AAE9D0077057}] => (Allow) F:\Games\Steam Games\steamapps\common\EVGA PrecisionX\Skins\UxfTool.exe FirewallRules: [{023D224B-BFAF-49E5-B0A2-0C407A32C6A9}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1Trial.exe FirewallRules: [{1AA7D12B-5972-43F5-A010-5BCCAEF77C82}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1Trial.exe FirewallRules: [{248B3DC4-93E8-4464-B08D-20136D03CE40}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1.exe FirewallRules: [{B6F2827A-A612-40EE-87AD-08CEBFD6786D}] => (Allow) F:\Games\Origin Games\Battlefield 1\bf1.exe FirewallRules: [{88AC7F92-D4D2-4AD7-A862-A1F8A523A9F6}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\57.0.2987.37\remoting_host.exe FirewallRules: [{6D6F6C02-CBAA-4072-8AFC-B83E38593ECD}] => (Allow) F:\Games\Steam Games\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{B9A4E790-D1F9-4495-AEAF-740184693960}] => (Allow) F:\Games\Steam Games\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [TCP Query User{96D925D7-F4CA-44AD-A535-C195514586E8}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{667E6896-51E0-4DFE-B45E-3FA9FC4B0687}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{73659037-A19E-4738-8B7D-0E1F233C8621}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{5E973A5A-9C2A-49BD-86EC-9E41D60DAC2F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{A2DD0B73-23F2-42D6-9327-EC9DFBE68DF3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{641DCE8D-6687-4E7D-ADFD-F3D06E7599E1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [TCP Query User{FAF3E68A-6406-482B-8780-FCD2B47425AD}C:\program files\telestream\gameshow\gameshow.exe] => (Allow) C:\program files\telestream\gameshow\gameshow.exe FirewallRules: [UDP Query User{9F14FB61-527A-4E02-8F83-9FD3D1A1331A}C:\program files\telestream\gameshow\gameshow.exe] => (Allow) C:\program files\telestream\gameshow\gameshow.exe FirewallRules: [TCP Query User{AA751268-2F2C-476C-A984-686F73238305}F:\games\destiny 2\destiny2.exe] => (Allow) F:\games\destiny 2\destiny2.exe FirewallRules: [UDP Query User{9B2905A1-6C27-4FF7-8A50-734F293A5717}F:\games\destiny 2\destiny2.exe] => (Allow) F:\games\destiny 2\destiny2.exe FirewallRules: [{9E68D931-C9AC-4912-ADDB-8EF6BE1AA19B}] => (Allow) F:\Games\Steam Games\steamapps\common\Deceit\bin\win_x64\Deceit.exe FirewallRules: [{6C45B1B3-A50E-4982-8279-69089CE2EE01}] => (Allow) F:\Games\Steam Games\steamapps\common\Deceit\bin\win_x64\Deceit.exe FirewallRules: [{2EB49E0E-DD3F-4400-87B1-9E1D175FF8C1}] => (Allow) F:\Games\Steam Games\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe FirewallRules: [{1637C8E0-651E-4D23-9CC6-D4155A8E65ED}] => (Allow) F:\Games\Steam Games\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe FirewallRules: [{C770BF71-08C1-45CF-AA65-99689B0AABB6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [TCP Query User{6788A9D9-BB2F-45EF-A2CE-2710F61245A6}C:\users\lucas\appdata\local\gpmdp_3\app-4.4.1\google play music desktop player.exe] => (Allow) C:\users\lucas\appdata\local\gpmdp_3\app-4.4.1\google play music desktop player.exe FirewallRules: [UDP Query User{CEE19149-5FD9-43F3-87A3-C6EEFD37B4CD}C:\users\lucas\appdata\local\gpmdp_3\app-4.4.1\google play music desktop player.exe] => (Allow) C:\users\lucas\appdata\local\gpmdp_3\app-4.4.1\google play music desktop player.exe ==================== Restore Points ========================= ==================== Faulty Device Manager Devices ============= Name: ExpressVPN Tap Adapter Description: ExpressVPN Tap Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: ExpressVPN Service: tapexpressvpn Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (10/24/2017 08:22:00 PM) (Source: nssm) (EventID: 1018) (User: ) Description: Failed to read registry value AppDirectory: The operation completed successfully. Error: (10/24/2017 08:20:30 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Visual Studio 14.0\VC\redist\1033\vcredist_arm.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (10/24/2017 08:19:51 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "c:\program files (x86)\adobe\adobe creative cloud\utils\Creative Cloud Uninstaller.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b.manifest. Error: (10/24/2017 08:19:40 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files (x86)\razer\razer cortex\StreamingServicesAPI.dll.Manifest".Error in manifest or policy file "c:\program files (x86)\razer\razer cortex\StreamingServicesAPI.dll.Manifest" on line 2. The value "F:\joju\projects\XSplitCSDemo\RazerLauncher\Components\StreamingServicesAPI.dll" of attribute "name" in element "urn:schemas-microsoft-com:asm.v1^file" is invalid. Error: (10/24/2017 08:10:24 PM) (Source: nssm) (EventID: 1018) (User: ) Description: Failed to read registry value AppDirectory: The operation completed successfully. Error: (10/23/2017 08:08:21 AM) (Source: W3SVC-WP) (EventID: 2307) (User: ) Description: The worker process for application pool 'DefaultAppPool' encountered an error 'Cannot read configuration file ' trying to read configuration data from file '\\?\C:\inetpub\temp\apppools\DefaultAppPool\DefaultAppPool.config', line number '0'. The data field contains the error code. Error: (10/23/2017 08:08:21 AM) (Source: W3SVC-WP) (EventID: 2307) (User: ) Description: The worker process for application pool 'DefaultAppPool' encountered an error 'Cannot read configuration file ' trying to read configuration data from file '\\?\C:\inetpub\temp\apppools\DefaultAppPool\DefaultAppPool.config', line number '0'. The data field contains the error code. Error: (10/23/2017 08:08:21 AM) (Source: W3SVC-WP) (EventID: 2307) (User: ) Description: The worker process for application pool 'DefaultAppPool' encountered an error 'Cannot read configuration file ' trying to read configuration data from file '\\?\C:\inetpub\temp\apppools\DefaultAppPool\DefaultAppPool.config', line number '0'. The data field contains the error code. Error: (10/23/2017 08:08:20 AM) (Source: W3SVC-WP) (EventID: 2307) (User: ) Description: The worker process for application pool 'DefaultAppPool' encountered an error 'Cannot read configuration file ' trying to read configuration data from file '\\?\C:\inetpub\temp\apppools\DefaultAppPool\DefaultAppPool.config', line number '0'. The data field contains the error code. Error: (10/23/2017 08:08:20 AM) (Source: W3SVC-WP) (EventID: 2307) (User: ) Description: The worker process for application pool 'DefaultAppPool' encountered an error 'Cannot read configuration file ' trying to read configuration data from file '\\?\C:\inetpub\temp\apppools\DefaultAppPool\DefaultAppPool.config', line number '0'. The data field contains the error code. System errors: ============= Error: (10/24/2017 08:24:50 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (10/24/2017 08:24:09 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Connected Devices Platform Service service terminated with the following error: Unspecified error Error: (10/24/2017 08:23:40 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Connected Devices Platform Service service terminated with the following error: Unspecified error Error: (10/24/2017 08:21:59 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (10/24/2017 08:21:59 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The BstHdDrv service failed to start due to the following error: The system cannot find the file specified. Error: (10/24/2017 08:22:00 PM) (Source: APPHOSTSVC) (EventID: 9010) (User: ) Description: The Application Host Helper Service encountered an error trying to access the root history directory 'C:\inetpub\history'. The directory either doesn't exist or the permissions on it don't allow the history service to access it. The config history feature is disabled for now and will be re-enabled after the issue is resolved. To resolve this issue, please ensure that the directory exists and that the Administrators group have read and write access to it. The data field contains the error number. Error: (10/24/2017 08:14:45 PM) (Source: DCOM) (EventID: 10010) (User: LUCAS-PC) Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout. Error: (10/24/2017 08:12:45 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Connected Devices Platform Service service terminated with the following error: Unspecified error Error: (10/24/2017 08:12:33 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Connected Devices Platform Service service terminated with the following error: Unspecified error Error: (10/24/2017 08:11:04 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. CodeIntegrity: =================================== Date: 2017-10-23 11:18:38.640 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-10-19 02:44:56.718 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-10-15 22:07:15.589 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-10-13 21:26:52.739 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-10-12 08:41:56.778 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-10-11 03:53:16.098 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-10-03 20:16:50.949 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-30 22:10:18.994 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-24 22:01:42.834 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-23 22:49:39.507 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz Percentage of memory in use: 18% Total physical RAM: 16336.38 MB Available physical RAM: 13351.4 MB Total Virtual: 19017.38 MB Available Virtual: 16202.48 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:223.13 GB) (Free:88.4 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: (Garbage) (Fixed) (Total:149.05 GB) (Free:44.25 GB) NTFS Drive e: (Back Up) (Fixed) (Total:745.21 GB) (Free:27.48 GB) NTFS Drive f: (Games) (Fixed) (Total:894.25 GB) (Free:588.2 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 306FFBC1) Partition 1: (Active) - (Size=223.1 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=450 MB) - (Type=27) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: C964157A) Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 894.3 GB) (Disk ID: 6B4F1066) Partition 1: (Not Active) - (Size=894.3 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 745.2 GB) (Disk ID: 828A7BD1) Partition 1: (Not Active) - (Size=745.2 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================