Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-06-2021 Ran by [removed] (25-06-2021 10:07:45) Running from C:\Users\[removed]\Downloads Windows 8.1 Single Language (Update) (X64) (2014-11-05 10:45:34) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3289921415-534489958-369683985-500 - Administrator - Disabled) => C:\Users\Administrator Craig (S-1-5-21-3289921415-534489958-369683985-1002 - Administrator - Enabled) => C:\Users\Craig Guest (S-1-5-21-3289921415-534489958-369683985-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3289921415-534489958-369683985-1006 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 21.005.20048 - Adobe Systems Incorporated) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) BlueStacks App Player (HKLM\...\BlueStacks) (Version: 4.260.0.1032 - BlueStack Systems, Inc.) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Hidden Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Hidden Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) Hidden Citrix Receiver (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 14.2.0.10 - Citrix Systems, Inc.) Comparing (HKLM-x32\...\{233EE2F2-EDA8-4C70-ABC3-D656D67D2CD5}) (Version: 1.00.2012.0921 - Tong child Research & Planning Co.,Ltd) Hidden Comparing (HKLM-x32\...\InstallShield_{233EE2F2-EDA8-4C70-ABC3-D656D67D2CD5}) (Version: 1.00.2012.0921 - Tong child Research & Planning Co.,Ltd) Composer - Php Dependency Manager (HKLM-x32\...\{7315AF68-E777-496A-A6A2-4763A98ED35A}_is1) (Version: - getcomposer.org) Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.8000.16 - Dolby Laboratories Inc) Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.13263.0 - Electronic Arts) Dragon Age™ II (HKLM-x32\...\{E1EB9F56-AFE2-4204-B28F-AD8DA793B9F4}) (Version: 1.04.8524.0 - Electronic Arts) Driver & Application Installation (HKLM-x32\...\{BFECCF2A-F094-4066-8BFA-29CCBB7F6602}) (Version: 6.12.0911 - Lenovo) Dropbox (HKLM-x32\...\Dropbox) (Version: 125.4.3474 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.485.1 - Dropbox, Inc.) Hidden Dune 2000: Gruntmods Edition (HKLM-x32\...\Dune 2000: Gruntmods Edition) (Version: 1.6.2.4 - Gruntmods Studios) Dungeon Keeper 2 (HKLM-x32\...\GOGPACKDUNGEONKEEPER2_is1) (Version: 2.0.0.32 - GOG.com) Find the Differences (HKLM-x32\...\{EAA04F6D-6E10-4267-B824-C35D3B9E0155}) (Version: 1.00.2012.0920 - Tong child Research & Planning Co.,Ltd) Hidden Find the Differences (HKLM-x32\...\InstallShield_{EAA04F6D-6E10-4267-B824-C35D3B9E0155}) (Version: 1.00.2012.0920 - Tong child Research & Planning Co.,Ltd) Finding the Letters (HKLM-x32\...\{535FB733-FFCF-4460-8694-664A2F6C53B4}) (Version: 1.00.2012.0512 - Tong child Research & Planning Co.,Ltd) Hidden Finding the Letters (HKLM-x32\...\InstallShield_{535FB733-FFCF-4460-8694-664A2F6C53B4}) (Version: 1.00.2012.0512 - Tong child Research & Planning Co.,Ltd) Fruits (HKLM-x32\...\{AA39BFDE-71E5-46A6-A10B-44C2F45A341E}) (Version: 1.00.2012.0809 - Tong child Research & Planning Co.,Ltd) Hidden Fruits (HKLM-x32\...\InstallShield_{AA39BFDE-71E5-46A6-A10B-44C2F45A341E}) (Version: 1.00.2012.0809 - Tong child Research & Planning Co.,Ltd) GOG.com Dungeon Keeper 2 (HKLM\...\{b6462b67-caf5-4a74-99df-cc2811bd1957}.sdb) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 91.0.4472.114 - Google LLC) Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 48.0.13.0 - Google LLC) Google Video Support Plugin (HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 19.12.1000.0 - Google, LLC.) GoTo Opener (HKLM-x32\...\{8B2D47CC-1558-4939-B27F-41E30530072A}) (Version: 1.0.467 - LogMeIn, Inc.) GoToMeeting 10.16.1.19709 (HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\GoToMeeting) (Version: 10.16.1.19709 - LogMeIn, Inc.) Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games) GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games) HitmanPro 3.8 (HKLM\...\HitmanPro38) (Version: 3.8.23.318 - SurfRight B.V.) IIS URL Rewrite Module 2 (HKLM\...\{38D32370-3A31-40E9-91D0-D236F47E3C4A}) (Version: 7.2.1980 - Microsoft Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.20.1337 - Intel Corporation) Jagged Alliance 2: Wildfire (HKLM-x32\...\Jagged Alliance 2: Wildfire) (Version: v. 6.04 ENG - ZUXXEZ Entertainmnet AG) Java 8 Update 161 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180161F0}) (Version: 8.0.1610.12 - Oracle Corporation) Lenovo Assistant (HKLM-x32\...\{B2DE4F30-B8C7-49C0-85B9-2F37A5290F00}) (Version: 2.0.0.27 - Lenovo) Lenovo Dashboard (HKLM-x32\...\{FEF1833C-244C-4DF2-AB67-1E1D26921ED8}) (Version: 2.0.0.9 - Lenovo) Lenovo Dynamic Brightness System (HKLM-x32\...\{D9ED6D06-6002-495E-A7BC-46E6AE386996}) (Version: 4.0.01.42160 - Lenovo) Lenovo Eye Distance System (HKLM-x32\...\{5183D7AB-D09B-411F-A74E-BBAEA61C6505}) (Version: 4.0.01.42160 - Lenovo) Lenovo Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.6418 - CyberLink Corp.) Hidden Lenovo Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.6418 - CyberLink Corp.) Lenovo PowerDVD10 (HKLM-x32\...\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4521.52 - CyberLink Corp.) Hidden Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4521.52 - CyberLink Corp.) Lenovo Rescue System (HKLM\...\{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 4.0.0.1511 - CyberLink Corp.) Hidden Lenovo Rescue System (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 4.0.0.1511 - CyberLink Corp.) Lenovo USB2.0 UVC Camera (HKLM-x32\...\{70D2C5B8-EB22-45B1-9EAA-5E8C1C408A3B}) (Version: 1.00.0000 - Vimicro Corporation) Lenovo YouCam (HKLM-x32\...\{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 4.1.3127 - CyberLink Corp.) Hidden Lenovo YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 4.1.3127 - CyberLink Corp.) Lenovo_Wireless_Driver (HKLM-x32\...\{5D642A72-8194-4A22-80DA-11FE610CCA8E}) (Version: 6.30.5926 - Lenovo) LVT (HKLM-x32\...\{9E3469A6-443A-452C-BF44-8D7CE3A9A7E2}) (Version: 5.00.0914 - Lenovo) Malwarebytes version 4.4.0.117 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.4.0.117 - Malwarebytes) Mammals (HKLM-x32\...\{ACA58CEB-2F74-4095-ADB6-4C1BFB170F64}) (Version: 1.00.2012.0809 - Tong child Research & Planning Co.,Ltd) Hidden Mammals (HKLM-x32\...\InstallShield_{ACA58CEB-2F74-4095-ADB6-4C1BFB170F64}) (Version: 1.00.2012.0809 - Tong child Research & Planning Co.,Ltd) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 88.0.705.81 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft ODBC Driver 13 for SQL Server (HKLM\...\{2D98CD18-5754-4D94-B7E8-E6E11DAA56B1}) (Version: 13.0.811.168 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Teams (HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\Teams) (Version: 1.3.00.4461 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.10.25008 (HKLM-x32\...\{f1e7e313-06df-4c56-96a9-99fdfd149c51}) (Version: 14.10.25008.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25008 (HKLM-x32\...\{c239cea1-d49e-4e16-8e87-8c055765f7ec}) (Version: 14.10.25008.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Web Platform Installer 5.0 (HKLM\...\{4D84C195-86F0-4B34-8FDE-4A17EB41306A}) (Version: 5.0.50430.0 - Microsoft Corporation) Mount&Blade Warband (HKLM-x32\...\Mount&Blade Warband) (Version: - ) Nitro Pro 8 (HKLM\...\{34BE77EE-B563-49D7-A8A0-FFD76D29BBD3}) (Version: 8.0.10.7 - Nitro) NVIDIA Graphics Driver 391.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 391.35 - NVIDIA Corporation) NVIDIA PhysX System Software 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation) Online Plug-in (HKLM-x32\...\{247D1CC0-7A71-4ADB-948F-E8703F0B44FB}) (Version: 14.2.0.10 - Citrix Systems, Inc.) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Origin (HKLM-x32\...\Origin) (Version: 10.5.88.45577 - Electronic Arts, Inc.) Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM-x32\...\{90150000-001F-040C-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden PHP Manager 1.2 for IIS 7 (HKLM\...\{E851486F-1FE2-44F0-85ED-F969088A68EE}) (Version: 1.2.0 - ) ProtonVPN (HKLM-x32\...\{D19979C9-8B5B-4500-AA6A-EF331F658074}) (Version: 1.17.5 - Proton Technologies AG) Hidden ProtonVPN (HKLM-x32\...\ProtonVPN 1.17.5) (Version: 1.17.5 - Proton Technologies AG) ProtonVPNTap (HKLM-x32\...\{BCB82CD9-F514-4F93-A6D9-F898494DC927}) (Version: 1.1.0 - Proton Technologies AG) Puzzle (HKLM-x32\...\{6EB7ECE3-E3BE-481D-821B-F1AFFA244D64}) (Version: 1.00.2012.0807 - Tong child Research & Planning Co.,Ltd) Hidden Puzzle (HKLM-x32\...\InstallShield_{6EB7ECE3-E3BE-481D-821B-F1AFFA244D64}) (Version: 1.00.2012.0807 - Tong child Research & Planning Co.,Ltd) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6695 - Realtek Semiconductor Corp.) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.8400.29025 - Realtek Semiconductor Corp.) Rockstar Games Social Club (HKLM-x32\...\{08B3869E-D282-424C-9AFC-870E04A4BA14}) (Version: 1.00.0000 - Rockstar Games) Self-service Plug-in (HKLM-x32\...\{C787BD95-A1B0-40DF-864F-E75182E828AC}) (Version: 4.2.0.2495 - Citrix Systems, Inc.) Hidden Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\...\{91150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUSR_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft) Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype version 8.73 (HKLM-x32\...\Skype_is1) (Version: 8.73 - Skype Technologies S.A.) StarCraft II (HKLM-x32\...\StarCraft II) (Version: - Blizzard Entertainment) Start Menu 8 (HKLM-x32\...\IObit_StartMenu8_is1) (Version: 4.0.2.1 - IObit) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Striata Reader (64-bit) (HKLM\...\{13d868cf-47e9-4b3d-9366-a0c60f82e5aa}) (Version: 2.21-1 - Striata Communication Solutions) sudoku (HKLM-x32\...\{8C4715DF-8AC9-4F0A-8E35-F9B4CF318FF1}) (Version: 1.00.2012.0807 - Tong child Research & Planning Co.,Ltd) Hidden sudoku (HKLM-x32\...\InstallShield_{8C4715DF-8AC9-4F0A-8E35-F9B4CF318FF1}) (Version: 1.00.2012.0807 - Tong child Research & Planning Co.,Ltd) Telegram Desktop version 2.5.1 (HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 2.5.1 - Telegram FZ-LLC) The Ur-Quan Masters 0.7.0 (HKLM-x32\...\The Ur-Quan Masters) (Version: 0.7.0 - ) The Walking Dead (HKLM-x32\...\The Walking Dead) (Version: 1.0.0.34 - Telltale Games) timer (HKLM-x32\...\{9CC4B8EE-A96B-4800-B674-0CF8B4560F45}) (Version: 1.00.2012.0512 - Tong child Research & Planning Co.,Ltd) Hidden timer (HKLM-x32\...\InstallShield_{9CC4B8EE-A96B-4800-B674-0CF8B4560F45}) (Version: 1.00.2012.0512 - Tong child Research & Planning Co.,Ltd) TNIOSDVolumeSync (HKLM-x32\...\{86B9BBB1-B06B-4B31-9D0A-634B41598251}) (Version: 1.0.0.3 - TPV-INVENTA TECHNOLOGY CO., LTD.) Hidden TNIOSDVolumeSync (HKLM-x32\...\InstallShield_{86B9BBB1-B06B-4B31-9D0A-634B41598251}) (Version: 1.0.0.3 - TPV-INVENTA TECHNOLOGY CO., LTD.) TomTom HOME (HKLM-x32\...\{7A2BB1C8-903D-4585-9F3B-CADD67D07D37}) (Version: 2.9.8 - TomTom) TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft) Update for Skype for Business 2015 (KB4484289) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{F97B139A-D8BF-46FF-A6F6-50710FED8644}) (Version: - Microsoft) Update for Skype for Business 2015 (KB4484289) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0409-0000-0000000FF1CE}_Office15.PROPLUSR_{F97B139A-D8BF-46FF-A6F6-50710FED8644}) (Version: - Microsoft) Update for Skype for Business 2015 (KB4484289) 32-Bit Edition (HKLM-x32\...\{91150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUSR_{F97B139A-D8BF-46FF-A6F6-50710FED8644}) (Version: - Microsoft) Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden WhatsApp (HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\WhatsApp) (Version: 2.2047.13 - WhatsApp) Windows Cache Extension 2.0 for PHP 7.0 (HKLM-x32\...\{07BC8693-3A2B-4FCD-8A2F-556D02A72A70}) (Version: 2.0.8 - Microsoft Corporation) Windows Cache Extension 2.0 for PHP 7.0 (x64) (HKLM\...\{07BC8693-3A2B-4FCD-8A2F-556D02A72A71}) (Version: 2.0.8 - Microsoft Corporation) WinZip 25.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C2412F}) (Version: 25.0.14273 - Corel Corporation) XAMPP (HKLM-x32\...\xampp) (Version: 5.6.28-1 - Bitnami) XCom Long War EW Mod version 1.0 (HKLM-x32\...\{860C3266-65B9-4BF2-937A-1778483046B5}_is1) (Version: 1.0 - JohnnyLump) Zoom (HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\ZoomUMX) (Version: 5.4.9 (59931.0110) - Zoom Video Communications, Inc.) Packages: ========= AccuWeather for Windows 8 -> C:\Program Files\WindowsApps\AccuWeather.AccuWeatherforWindows8_2.1.7.2_x64__8zz2pj9h1h1d8 [2018-03-29] (AccuWeather) Bing Finance -> C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.2.258_x64__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) [MS Ad] Bing News -> C:\Program Files\WindowsApps\Microsoft.BingNews_3.0.2.309_x64__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) [MS Ad] Bing Sport -> C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.2.258_x64__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) [MS Ad] Bing Travel -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.2.309_x64__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) [MS Ad] Bing Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_3.0.2.309_x64__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) [MS Ad] Encyclopaedia Britannica -> C:\Program Files\WindowsApps\EncyclopaediaBritannica.EncyclopaediaBritannica_1.0.1.4_neutral__k5b3gy2wfywap [2018-03-29] (Encyclopaedia Britannica) FishingJoy -> C:\Program Files\WindowsApps\E0469640.FishingJoy_1.0.0.3_x86__5grkq8ppsgwt4 [2018-03-29] (LENOVO INC) Frameworkuapbase -> C:\Program Files\WindowsApps\48682KiddoTest.Frameworkuapbase_1.0.0.2_neutral__81ffpr532s7pc [2018-03-29] (KiddoTest) Games -> C:\Program Files\WindowsApps\Microsoft.XboxLIVEGames_2.0.139.0_x64__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) [MS Ad] HP All-in-One Printer Remote -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_55.1.43.0_x86__v10z8vjag6ke6 [2018-03-29] (Hewlett-Packard Company) Kindle -> C:\Program Files\WindowsApps\AMZNMobileLLC.KindleforWindows8_1.0.2.0_neutral__stfe6vwa9jnbp [2018-03-29] (AMZN Mobile LLC) Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.0_2.0.1410.19000_x64__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.0_2.0.1410.19000_x86__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.1_2.0.1410.19000_x64__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.1_2.0.1410.19000_x86__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) Lenovo Cloud Storage by SugarSync -> C:\Program Files\WindowsApps\C59AD0AF.LenovoCloudStorageBySugarSync_1.2.0.519_neutral__m3tnjedffpfhj [2018-03-29] (SugarSync Inc.) Lenovo Companion -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_1.0.510.0_x86__k1h2ywk1493x8 [2018-03-29] (LENOVO, INC.) Lenovo Dress-up -> C:\Program Files\WindowsApps\E0469640.MagicDressup_1.0.1.23_x64__5grkq8ppsgwt4 [2018-03-29] (LENOVO INC) Lenovo Drummer -> C:\Program Files\WindowsApps\E0469640.LenovoDrummer_1.0.0.77_x64__5grkq8ppsgwt4 [2018-03-29] (LENOVO INC) Lenovo Forest Adventure -> C:\Program Files\WindowsApps\E0469640.JungleMobilization_1.0.1.69_x64__5grkq8ppsgwt4 [2018-03-29] (LENOVO INC) Lenovo Support -> C:\Program Files\WindowsApps\E046963F.LenovoSupport_1.0.55.0_x86__k1h2ywk1493x8 [2018-03-29] (Lenovo, INC.) Live TV -> C:\Program Files\WindowsApps\FilmOnLiveTVFree.FilmOnLiveTVFree_1.3.6.82_x64__zx03kxexxb716 [2018-03-29] (FilmOn TV Inc.) McAfee Security Advisor for Lenovo -> C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_1.0.0.0_x64__bq6yxensn79aw [2018-03-29] (McAfee_Inc) Merriam-Webster Dictionary -> C:\Program Files\WindowsApps\D22CCC44.Merriam-WebsterDictionary_1.0.1.1_neutral__mbv6ra3y34fnr [2018-03-29] (Merriam-Webster, Inc.) Microsoft PlayReady -> C:\Program Files\WindowsApps\Microsoft.Internal.Media.PlayReadyClient_2.3.1678.1_x64__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) Microsoft PlayReady -> C:\Program Files\WindowsApps\Microsoft.Internal.Media.PlayReadyClient_2.3.1678.1_x86__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) Microsoft Visual C++ Runtime Package -> C:\Program Files\WindowsApps\Microsoft.VCLibs.120.00.Preview.Internal_12.0.20222.2_x64__8wekyb3d8bbwe [2018-03-29] (Microsoft Platform Extensions Internal) Microsoft Visual C++ Runtime Package -> C:\Program Files\WindowsApps\Microsoft.VCLibs.120.00.Preview.Internal_12.0.20222.2_x86__8wekyb3d8bbwe [2018-03-29] (Microsoft Platform Extensions Internal) Microsoft Windows Library for JavaScript -> C:\Program Files\WindowsApps\Microsoft.WinJS.2.0.Preview.Internal_1.0.9385.3_neutral__8wekyb3d8bbwe [2018-03-29] (Microsoft Platform Extensions) Microsoft Windows Library for JavaScript -> C:\Program Files\WindowsApps\Microsoft.WinJS.2.0.Preview_1.0.9431.0_neutral__8wekyb3d8bbwe [2018-03-29] (Microsoft Platform Extensions) Microsoft Windows Library for JavaScript -> C:\Program Files\WindowsApps\Microsoft.WinJS.Preview.1_1.0.9345.0_neutral__8wekyb3d8bbwe [2018-03-29] (Microsoft Platform Extensions) Music -> C:\Program Files\WindowsApps\Microsoft.ZuneMusic_2.2.903.0_x64__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) [MS Ad] mxtest2 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.mxtest2_2.0.0.0_neutral__x35ns48czryn0 [2018-03-29] (m1df_mmengesha) PowerDVD for Lenovo Idea -> C:\Program Files\WindowsApps\CyberLinkCorp.id.PowerDVDforLenovoIdea_1.0.731.9669_x86__hgg5mn3xps74a [2018-03-29] (CYBERLINK COM CORPORATION) rara.com -> C:\Program Files\WindowsApps\rara.com.rara.com_1.0.10.6_neutral__2tghmx54nqzjm [2018-03-29] (RARA MEDIA GROUP LIMITED) Skype -> C:\Program Files\WindowsApps\Microsoft.SkypeApp_3.0.0.1002_x86__kzf8qxf38zg5c [2018-03-29] (Skype) [MS Ad] Test_Framework_BP_052015 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.TestFrameworkBP052015_1.0.0.9_neutral__x35ns48czryn0 [2018-03-29] (m1df_mmengesha) Test_Framework_win81appxneutral_061115 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.TestFrameworkwin81appxneutral06_4.0.0.7_neutral__x35ns48czryn0 [2018-03-29] (M1DF_Mmengesha) Test_FrameworkBackpublish_050515 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.TestFrameworkBackpublish050515_1.0.0.0_neutral__x35ns48czryn0 [2018-03-29] (m1df_mmengesha) Test_FrameworkProd_062215_01 -> C:\Program Files\WindowsApps\50856m1dfLL.TestFrameworkProd06221501_1.0.0.10_neutral__nwcxtg9ehxpvt [2018-03-29] (m1df_lucyll) TESTFRAMEWORKABO2 -> C:\Program Files\WindowsApps\40538vasetest101.TESTFRAMEWORKABO2_12.0.21005.1_x64__ssm1v0s3df7zc [2018-03-29] (vasetest101) Video -> C:\Program Files\WindowsApps\Microsoft.ZuneVideo_2.2.902.0_x64__8wekyb3d8bbwe [2018-03-29] (Microsoft Corporation) [MS Ad] WinZip -> C:\Program Files\WindowsApps\WinZipComputing.WinZip_1.3.0.216_x64__3ykzqggjzj4z0 [2018-03-29] (WinZip Computing) YouCam for Lenovo Idea -> C:\Program Files\WindowsApps\CyberLinkCorp.id.YouCamforLenovoIdea_1.0.1508.24404_x86__hgg5mn3xps74a [2018-03-29] (CYBERLINK COM CORPORATION) Zinio -> C:\Program Files\WindowsApps\ZinioLLC.Zinio_1.2.0.0_x64__0q6dqzpp40p2e [2018-03-29] (Zinio LLC) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Craig\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20031.2\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{46406D82-6EC0-47CC-8A75-1F33C6DEDBBE}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.35.442\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{540C17A8-04F2-4B66-95D7-B2FEF9A19B54}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.35.422\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{62634D95-960B-4834-8E71-A70408AD8FD9}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.34.7\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{6D264B70-DA18-401D-910C-B202D89670C6}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.36.32\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Craig\AppData\Local\GoToMeeting\12604\G2MOutlookAddin64.dll => No File CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{84EB3779-151B-4C71-AEF0-A0FEE9481401}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.35.342\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{85D8EE2F-794F-41F0-BB03-49D56A23BEF4}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.36.82\psuser_64.dll (Google LLC -> Google LLC) CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{86508D42-E5D7-4D10-9C6F-D427AEEB85B5}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.34.11\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{A804CF1A-91E5-4F0C-9E8C-DB39E74056DD}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.33.23\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{CA8FA699-91CD-412F-9D13-9B1222F4370E}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.36.82\psuser_64.dll (Google LLC -> Google LLC) CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{CA919489-0396-4164-A6E7-94CDED45A707}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.36.52\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.WinZipExpressForOffice.dll (Corel Corporation -> ) CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\Craig\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20031.2\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{DEDF773D-E27B-485E-8E7D-85C5B0EB5A67}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.36.72\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.36.82\psuser_64.dll (Google LLC -> Google LLC) CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{E9E7529D-7F09-410B-AF2A-CC154473B19C}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.35.452\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{EA724FD3-844D-43A9-A8C9-A5BC35FC20E4}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.33.17\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3289921415-534489958-369683985-1002_Classes\CLSID\{EF076C91-DC9E-43E3-84ED-3D219E065A4F}\InprocServer32 -> C:\Users\Craig\AppData\Local\Google\Update\1.3.35.302\psuser_64.dll => No File ShellIconOverlayIdentifiers: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\48.0.13.0\drivefsext.dll [2021-05-24] (Google LLC -> Google, Inc.) ShellIconOverlayIdentifiers: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\48.0.13.0\drivefsext.dll [2021-05-24] (Google LLC -> Google, Inc.) ShellIconOverlayIdentifiers: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\48.0.13.0\drivefsext.dll [2021-05-24] (Google LLC -> Google, Inc.) ShellIconOverlayIdentifiers: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\48.0.13.0\drivefsext.dll [2021-05-24] (Google LLC -> Google, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll -> No File ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll -> No File ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll -> No File ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll -> No File ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) [File not signed] ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\48.0.13.0\drivefsext.dll [2021-05-24] (Google LLC -> Google, Inc.) ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [IobitStartMenu] -> {AF8FA9C9-9907-463e-BDC3-4CC1200D6310} => c:\program files (x86)\iobit\Classic Start\IObitStartMenuExtension.dll [2015-12-29] (IObit Information Technology -> IObit) ContextMenuHandlers1: [NP8ShellExtension] -> {9C4B85B8-956C-49BF-9BA5-101384E562B2} => C:\Program Files\Common Files\Nitro\Pro\8.0\NPShellExtension64.dll [2012-12-14] (Nitro PDF Software -> Nitro PDF) ContextMenuHandlers1: [SugarSync] -> {305BC11B-5175-492B-B569-866547FCDA40} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll -> No File ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2020-09-25] (Corel Corporation -> WinZip Computing) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) [File not signed] ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\48.0.13.0\drivefsext.dll [2021-05-24] (Google LLC -> Google, Inc.) ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers4: [IobitStartMenu] -> {AF8FA9C9-9907-463e-BDC3-4CC1200D6310} => c:\program files (x86)\iobit\Classic Start\IObitStartMenuExtension.dll [2015-12-29] (IObit Information Technology -> IObit) ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2020-09-25] (Corel Corporation -> WinZip Computing) ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\48.0.13.0\drivefsext.dll [2021-05-24] (Google LLC -> Google, Inc.) ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.48.0.dll [2021-05-11] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [IobitStartMenu] -> {AF8FA9C9-9907-463e-BDC3-4CC1200D6310} => c:\program files (x86)\iobit\Classic Start\IObitStartMenuExtension.dll [2015-12-29] (IObit Information Technology -> IObit) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [SugarSync] -> {305BC11B-5175-492B-B569-866547FCDA40} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll -> No File ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2020-09-25] (Corel Corporation -> WinZip Computing) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Craig\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\d249d9ddd424b688\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default ==================== Loaded Modules (Whitelisted) ============= 2018-08-29 13:02 - 2021-06-07 17:28 - 002552320 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\ffmpeg.dll 2019-08-20 09:05 - 2021-06-07 17:28 - 000388608 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\swiftshader\libegl.dll 2019-08-20 09:05 - 2021-06-07 17:28 - 002863104 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\swiftshader\libglesv2.dll 2013-06-05 01:41 - 2013-06-05 01:41 - 000348160 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Lenovo\PowerDVD10\MSVCR71.dll ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Windows:nlsPreferences [386] ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dump_14B10DA0.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ms14B10DA0App => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dump_14B10DA0.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ms14B10DA0App => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\str => ""="service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== HKU\S-1-5-21-3289921415-534489958-369683985-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.co.za/ HKU\S-1-5-21-3289921415-534489958-369683985-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com HKU\S-1-5-21-3289921415-534489958-369683985-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com HKU\S-1-5-21-3289921415-534489958-369683985-500\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com HKU\S-1-5-21-3289921415-534489958-369683985-500\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com SearchScopes: HKU\S-1-5-21-3289921415-534489958-369683985-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2020-04-15] (Microsoft Corporation -> Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2018-05-15] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2020-04-15] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\ssv.dll [2018-03-29] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2018-05-15] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-03-29] (Oracle America, Inc. -> Oracle Corporation) DPF: HKLM-x32 {4FF78044-96B4-4312-A5B7-FDA3CB328095} Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc. -> Citrix Systems, Inc.) (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\battle.net -> hxxp://us.battle.net ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2013-08-22 15:25 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\ProgramData\Oracle\Java\javapath;c:\program files\iis express\php\v7.0;c:\program files (x86)\intel\icls client\;c:\program files\intel\icls client\;c:\windows\system32;c:\windows;c:\windows\system32\wbem;c:\windows\system32\windowspowershell\v1.0\;c:\program files\intel\intel(r) management engine components\dal;c:\program files\intel\intel(r) management engine components\ipt;c:\program files (x86)\intel\intel(r) management engine components\dal;c:\program files (x86)\intel\intel(r) management engine components\ipt;c:\xampp\php;c:\program files\microsoft\web platform installer\;c:\users\craig\appdata\roaming\composer\vendor\bin;c:\programdata\composersetup\bin;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common HKU\S-1-5-21-3289921415-534489958-369683985-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg HKU\S-1-5-21-3289921415-534489958-369683985-500\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: GfExperienceService => 2 MSCONFIG\Services: Intel(R) Capability Licensing Service Interface => 2 MSCONFIG\Services: jhi_service => 2 MSCONFIG\Services: LMS => 2 MSCONFIG\Services: NitroDriverReadSpool8 => 3 MSCONFIG\Services: nlsX86cc => 2 MSCONFIG\Services: NVDisplay.ContainerLocalSystem => 2 MSCONFIG\Services: NvNetworkService => 2 MSCONFIG\Services: NvStreamNetworkSvc => 3 MSCONFIG\Services: NvStreamSvc => 2 MSCONFIG\Services: Origin Client Service => 3 MSCONFIG\Services: Origin Web Helper Service => 2 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\Services: SMService => 2 MSCONFIG\Services: Steam Client Service => 3 MSCONFIG\Services: TNISrvc => 2 MSCONFIG\Services: TomTomHOMEService => 3 MSCONFIG\Services: UNS => 2 MSCONFIG\Services: WinZip Smart Monitor Service => 3 HKLM\...\StartupApproved\StartupFolder: => "WinZip Preloader.lnk" HKLM\...\StartupApproved\Run: => "NvBackend" HKLM\...\StartupApproved\Run: => "ShadowPlay" HKLM\...\StartupApproved\Run: => "WindowsDefender" HKLM\...\StartupApproved\Run: => "WinZip PreLoader" HKLM\...\StartupApproved\Run: => "WinZip UN" HKLM\...\StartupApproved\Run: => "WinZip FAH" HKLM\...\StartupApproved\Run32: => "CLMLServer" HKLM\...\StartupApproved\Run32: => "YouCam Tray" HKLM\...\StartupApproved\Run32: => "UpdateP2GoShortCut" HKLM\...\StartupApproved\Run32: => "TNIOSDVolumeSync(x86)" HKLM\...\StartupApproved\Run32: => "TNIOSDVolumeSync(x64)" HKLM\...\StartupApproved\Run32: => "Lenovo Eye Distance System" HKLM\...\StartupApproved\Run32: => "Lenovo Dynamic Brightness System" HKLM\...\StartupApproved\Run32: => "YouCam Mirage" HKLM\...\StartupApproved\Run32: => "ConnectionCenter" HKLM\...\StartupApproved\Run32: => "Redirector" HKLM\...\StartupApproved\Run32: => "CitrixReceiver" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "Dropbox" HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\StartupApproved\Run: => "TomTomHOME.exe" HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\StartupApproved\Run: => "com.squirrel.Teams.Teams" HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\StartupApproved\Run: => "RGSC" HKU\S-1-5-21-3289921415-534489958-369683985-1002\...\StartupApproved\Run: => "GoogleDriveFS" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{A880EEB0-912D-49F8-A512-57505BCC1B57}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Returns\Shadowrun.exe () [File not signed] FirewallRules: [{B57666DF-C722-4480-A0D4-C3A26FBD526B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Returns\Shadowrun.exe () [File not signed] FirewallRules: [UDP Query User{6DA1509D-80B2-42D9-B89B-26AA23567385}C:\program files (x86)\origin games\command and conquer 4\data\cnc4.game] => (Block) C:\program files (x86)\origin games\command and conquer 4\data\cnc4.game => No File FirewallRules: [TCP Query User{AE0BCB0A-665C-4938-80E9-62308766BA92}C:\program files (x86)\origin games\command and conquer 4\data\cnc4.game] => (Block) C:\program files (x86)\origin games\command and conquer 4\data\cnc4.game => No File FirewallRules: [{BBE16111-1222-4AF1-AC84-A57C16B819DD}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe (Electronic Arts -> BioWare) FirewallRules: [{9C9A873C-C9B2-4E5A-B790-20F1C6199FFA}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe (Electronic Arts -> BioWare) FirewallRules: [{9F8E5DEA-F746-401E-BBCF-CD2D2934C930}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout Tactics\TacticsLauncher.exe (ZeniMax Media) [File not signed] FirewallRules: [{98BDB1ED-2752-4ECB-BC4D-C2D9C7E3E823}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout Tactics\TacticsLauncher.exe (ZeniMax Media) [File not signed] FirewallRules: [{BBBCDD10-E7E8-4794-B813-F9A72C591BB9}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe => No File FirewallRules: [{3B90E342-D2F9-4448-BA45-FF724E35FB35}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe => No File FirewallRules: [{CEBEE2F4-EC85-4947-B63E-1D4482B7C7DE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{4B02CAD1-CDDF-469C-A612-015F3493135C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{543EEECE-1338-49A2-A962-522AE4DFD8FE}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe => No File FirewallRules: [{259DD124-8D3A-4D55-B8D6-3F0E6FEC6F6F}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE (CyberLink -> CyberLink Corp.) FirewallRules: [{0C54DD80-4E84-4E35-851D-6E5A2A0B23B4}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe (CyberLink -> CyberLink Corp.) FirewallRules: [{C6E1C1F3-299C-45E4-A920-D26970A00F57}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe => No File FirewallRules: [{D939F332-D480-4AE8-9BA1-CCD70FA811F4}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe => No File FirewallRules: [{4FCD8A05-6E17-45C8-B5A6-B47354BFDA38}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Dragonfall Director's Cut\Dragonfall.exe () [File not signed] FirewallRules: [{CF45F4A5-B3BC-4E0B-9D67-02F23B9E3901}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Dragonfall Director's Cut\Dragonfall.exe () [File not signed] FirewallRules: [{02FCE45A-AA0E-4AA4-83D4-945371378D67}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe () [File not signed] FirewallRules: [{9A9AA6AB-3B58-4AF6-AAC7-B06A151C080A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe () [File not signed] FirewallRules: [{61EC79F9-8277-4F11-9476-48B0397D1E04}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dead State\ZRPG.exe (DoubleBear Productions, Iron Tower Studio) [File not signed] FirewallRules: [{4A4E0200-A73A-4633-831D-B5C4E408593F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dead State\ZRPG.exe (DoubleBear Productions, Iron Tower Studio) [File not signed] FirewallRules: [{B857B73F-8AED-4B9E-B8DA-1F340309E64E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Kings Bounty Crossworlds\KB.exe () [File not signed] FirewallRules: [{A99BAB5C-576F-42E4-9C43-F17A8BB2877D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Kings Bounty Crossworlds\KB.exe () [File not signed] FirewallRules: [{EA3DC441-4B57-4FD5-8DF2-E4905A3DD340}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\7 Days To Die\7DaysToDie_EAC.exe (EasyAntiCheat Oy -> Epic Games, Inc) FirewallRules: [{13A15DD5-2C70-47FF-8C3C-E94450414EE2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\7 Days To Die\7DaysToDie_EAC.exe (EasyAntiCheat Oy -> Epic Games, Inc) FirewallRules: [{A45F0F7C-A76B-4B97-9FD6-6087DCDC02B1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\7 Days To Die\7DaysToDie.exe () [File not signed] FirewallRules: [{3D6B4518-854E-43CA-9EAA-A457BBE7CA1E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\7 Days To Die\7DaysToDie.exe () [File not signed] FirewallRules: [{EDD4BC51-874D-4525-B15F-61D577A6C9A9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Battlechess Game of Kings\battlechessgok.exe () [File not signed] FirewallRules: [{562A0081-6566-410C-BDCD-66D054DAA738}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Battlechess Game of Kings\battlechessgok.exe () [File not signed] FirewallRules: [{4D8A1FB4-1307-4E1C-B335-7095561F639C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout 3\FalloutLauncher.exe (Bethesda Softworks) [File not signed] FirewallRules: [{D12571C2-3ECF-4FDC-B2D2-60D4A3F84499}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout 3\FalloutLauncher.exe (Bethesda Softworks) [File not signed] FirewallRules: [{E38680B4-D9BD-42A3-A99A-5028066FC954}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Colonization\dosbox_windows\dosbox.exe (DOSBox Team) [File not signed] FirewallRules: [{132E8563-18D0-494E-87E5-A28E69E62320}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Colonization\dosbox_windows\dosbox.exe (DOSBox Team) [File not signed] FirewallRules: [{B9A96F2E-1D87-474E-A39E-4F1D884F08B2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Colonization\dosbox_windows\daum\dosbox.exe (DOSBox Team) [File not signed] FirewallRules: [{E0D3EFE1-5216-4D73-A780-9D8E90C8F9B2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Colonization\dosbox_windows\daum\dosbox.exe (DOSBox Team) [File not signed] FirewallRules: [{A31D36E2-7731-4A7B-9E58-4C5783D091DA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Might and Magic Heroes VI\Might & Magic Heroes VI.exe (Virtuos China Ltd. -> Virtuos) [File not signed] FirewallRules: [{97ED2933-BD6C-4507-B023-CC7EA53F345B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Might and Magic Heroes VI\Might & Magic Heroes VI.exe (Virtuos China Ltd. -> Virtuos) [File not signed] FirewallRules: [{BFA2B80F-C4B5-40D8-AE50-BDD94E92DDAD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe (Valve Corp. -> Firaxis Games) [File not signed] FirewallRules: [{B5F8D782-8231-4CEA-B8ED-6AF61A71D250}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe (Valve Corp. -> Firaxis Games) [File not signed] FirewallRules: [TCP Query User{366FAF8C-6345-4BA4-8BAA-C1988A684943}C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe (Valve Corp. -> Firaxis Games) [File not signed] FirewallRules: [UDP Query User{3DF44588-53CD-4B48-9ADF-5D3163D00676}C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe (Valve Corp. -> Firaxis Games) [File not signed] FirewallRules: [{2BA1BDC0-5A7E-48A6-A884-960EFDFFD229}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment) FirewallRules: [{E8FF2067-9FDB-457B-8FF9-3D010C2D91F1}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment) FirewallRules: [TCP Query User{6F25BEBB-F99A-4806-96BC-0249EFD247DD}C:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe] => (Allow) C:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment) FirewallRules: [UDP Query User{AB3522B3-E6DF-4858-81F6-1BC8D1AD7F2B}C:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe] => (Allow) C:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment) FirewallRules: [TCP Query User{C7AE68BB-1153-4812-ADCD-9357A360A042}C:\program files (x86)\starcraft ii\versions\base41743\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base41743\sc2_x64.exe => No File FirewallRules: [UDP Query User{3F8E4B56-3DA3-4970-9E3A-B21828209298}C:\program files (x86)\starcraft ii\versions\base41743\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base41743\sc2_x64.exe => No File FirewallRules: [TCP Query User{9A8979A9-8FDB-4360-A3D7-7ECAF37A7C6C}C:\program files (x86)\starcraft ii\versions\base42253\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base42253\sc2_x64.exe => No File FirewallRules: [UDP Query User{A0FA2054-A01B-42E0-A4A5-9445760D6DB5}C:\program files (x86)\starcraft ii\versions\base42253\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base42253\sc2_x64.exe => No File FirewallRules: [TCP Query User{DBE0E36C-C81F-4E17-B148-728F2ADC8532}C:\program files (x86)\starcraft ii\versions\base42932\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base42932\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [UDP Query User{7CB7B868-C903-48F8-9517-94582F2F8158}C:\program files (x86)\starcraft ii\versions\base42932\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base42932\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [{7DDAE2E8-3D82-49B1-A2BB-A49B94F584C3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Hong Kong\SRHK.exe () [File not signed] FirewallRules: [{EA7719C8-8DDF-4952-8D79-6D15EBD97D34}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Hong Kong\SRHK.exe () [File not signed] FirewallRules: [{0966D175-F18D-47E1-9858-F87538A688D0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\New Star Soccer 5\NSS5.exe () [File not signed] FirewallRules: [{80E8A38A-19D5-45D2-A126-56EF73C0852E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\New Star Soccer 5\NSS5.exe () [File not signed] FirewallRules: [{8940B994-9E84-4CBA-B613-5292AEC4A598}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Championship Manager 2008\CM2008.exe (Eidos) [File not signed] FirewallRules: [{B52C3275-F61E-47B6-9D4A-175388AFC7D2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Championship Manager 2008\CM2008.exe (Eidos) [File not signed] FirewallRules: [{8C10E354-65AA-400E-9D7E-ACAD4BDFCD37}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{A293843E-9D5E-4E73-AAA0-E52B4FA2F072}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{564DC735-B6D2-4A19-BD3A-40EBC6AAB1A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Royal Heroes\RoyalHeroes.exe (Royal Heroes) [File not signed] FirewallRules: [{A6742ED3-7778-4CCE-BCA3-B9FE805AA3C4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Royal Heroes\RoyalHeroes.exe (Royal Heroes) [File not signed] FirewallRules: [{F0E638AA-83DA-4596-A7D4-BB12842DD03F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Age Of Gladiators\gladiator.exe () [File not signed] FirewallRules: [{7FDB2D22-D986-431E-8112-FFD4CCC3FCB9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Age Of Gladiators\gladiator.exe () [File not signed] FirewallRules: [{88246502-9376-4D0D-AAF6-94DC69663A71}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Evil Genius\EvilGeniusLauncher.exe () [File not signed] FirewallRules: [{EF76760F-DB5A-48AE-BB26-591500866A9D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Evil Genius\EvilGeniusLauncher.exe () [File not signed] FirewallRules: [{8113C257-224C-4D7E-AE36-CC49DB2498F9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AttT\ATThrone.exe () [File not signed] FirewallRules: [{C3EB6519-CBE1-4106-BD8E-56B913D5B308}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AttT\ATThrone.exe () [File not signed] FirewallRules: [{57AA3D27-37BC-4C9F-A391-BEFB943AC982}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout 2\Fallout2Launcher.exe (ZeniMax Media) [File not signed] FirewallRules: [{EF06F768-890F-483A-8123-0781FEADFF9C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout 2\Fallout2Launcher.exe (ZeniMax Media) [File not signed] FirewallRules: [TCP Query User{81BD74C9-B161-42A1-B85F-4399A12DBAC2}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe (Apache Software Foundation) [File not signed] FirewallRules: [UDP Query User{FD04E956-4276-4D2B-800E-EAAB359C5027}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe (Apache Software Foundation) [File not signed] FirewallRules: [TCP Query User{F8D02CEB-28D9-4F31-966D-D7899828AA43}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe (MariaDB Corporation Ab -> ) FirewallRules: [UDP Query User{77F9A51A-C1C7-4B09-9A44-737E46D42B73}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe (MariaDB Corporation Ab -> ) FirewallRules: [TCP Query User{0B2FDA26-062B-41DA-BC80-3298CA28FD2F}C:\program files (x86)\starcraft ii\versions\base57507\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base57507\sc2_x64.exe => No File FirewallRules: [UDP Query User{630A1801-3494-442B-A59D-9AB658129F80}C:\program files (x86)\starcraft ii\versions\base57507\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base57507\sc2_x64.exe => No File FirewallRules: [{AD790993-3CD5-498F-9347-E3CF2D955F40}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{8B7662B2-7C0B-4C68-9F09-565ED0A8E8C5}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{642AAA3E-3CC9-446D-B806-3B5F16ED82D0}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{906BB62B-62AF-4995-83E6-4D494D04D651}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{706F8794-16F9-4073-B7E6-070392AD2001}C:\program files (x86)\starcraft ii\versions\base58400\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base58400\sc2_x64.exe => No File FirewallRules: [UDP Query User{6E121AED-6CA2-4FBF-960E-DE49417089C6}C:\program files (x86)\starcraft ii\versions\base58400\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base58400\sc2_x64.exe => No File FirewallRules: [{F0DCA53B-6E84-432A-B13F-0C66922F6AC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Age of Gladiators II\AoGII.exe () [File not signed] FirewallRules: [{15271474-FEFD-4C32-A013-6EF019312E40}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Age of Gladiators II\AoGII.exe () [File not signed] FirewallRules: [TCP Query User{84C55F14-9C9C-456C-BE4D-800396A2515B}C:\program files (x86)\starcraft ii\versions\base59587\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base59587\sc2_x64.exe => No File FirewallRules: [UDP Query User{6C9C4F3B-7392-4234-AEE5-241D09876C3B}C:\program files (x86)\starcraft ii\versions\base59587\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base59587\sc2_x64.exe => No File FirewallRules: [{73EC04FC-844D-4D69-AE77-E5960190F6A2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\swkotor\swkotor.exe (BioWare Corp.) [File not signed] FirewallRules: [{D16011DC-06F3-4A7E-8F78-58EED033B873}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\swkotor\swkotor.exe (BioWare Corp.) [File not signed] FirewallRules: [{5887C27C-FC8B-42DC-A9B2-81D154BA3DF3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Knights of the Old Republic II\swkotor2.exe (Obsidian Entertainment, Inc.) [File not signed] FirewallRules: [{731BE5F3-E352-4F38-AABA-E3F82B6E32EF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Knights of the Old Republic II\swkotor2.exe (Obsidian Entertainment, Inc.) [File not signed] FirewallRules: [{293B3EF4-27AD-4E13-B4BD-A9706F64457B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization III Complete\Conquests\Civ3Conquests.exe (© 2001-2004 Atari Inc.) [File not signed] FirewallRules: [{B387DC11-4DBD-4F95-85A7-51293BCD3336}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization III Complete\Conquests\Civ3Conquests.exe (© 2001-2004 Atari Inc.) [File not signed] FirewallRules: [TCP Query User{F911D79F-04C1-43F7-A752-FDF61C1B763A}C:\program files (x86)\oldgames\dune 2000\dune2000.dat] => (Block) C:\program files (x86)\oldgames\dune 2000\dune2000.dat => No File FirewallRules: [UDP Query User{E2E9E2B4-1899-44A9-B0EB-C0E5F58A22CA}C:\program files (x86)\oldgames\dune 2000\dune2000.dat] => (Block) C:\program files (x86)\oldgames\dune 2000\dune2000.dat => No File FirewallRules: [{F9917ACF-B4AF-4B9D-A758-CB03314CCC74}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe (Electronic Arts -> BioWare) FirewallRules: [{3893EDD1-4790-4BEF-99B4-8D66B9A278AE}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe (Electronic Arts -> BioWare) FirewallRules: [{99CA1BF3-5866-4BDD-8E86-84E5D722F7AF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\7 Days To Die\7dLauncher.exe () [File not signed] FirewallRules: [{3201F1E8-672D-401A-B30C-C7DBF6CE55B2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\7 Days To Die\7dLauncher.exe () [File not signed] FirewallRules: [TCP Query User{DBC635E9-52E1-4C05-B3A0-28B69AB3641E}C:\program files (x86)\starcraft ii\versions\base69232\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base69232\sc2_x64.exe => No File FirewallRules: [UDP Query User{B87BF2CE-1C8B-4DE5-A3BB-A71A0A2E6494}C:\program files (x86)\starcraft ii\versions\base69232\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base69232\sc2_x64.exe => No File FirewallRules: [{AC41BE28-B4C7-47A6-B94E-C4C6F768F7A0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stellar Tactics\StellarTactics.exe () [File not signed] FirewallRules: [{11789B37-E695-48C0-91C1-30AE9F76A931}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stellar Tactics\StellarTactics.exe () [File not signed] FirewallRules: [TCP Query User{CFF908B0-13DF-4D25-9B7F-084040436FDF}C:\program files (x86)\starcraft ii\versions\base70154\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base70154\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [UDP Query User{A5BDDD2A-2850-4BB0-9C93-8E4223F6072A}C:\program files (x86)\starcraft ii\versions\base70154\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base70154\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [{6C3FEFDC-2A0A-40D2-84FB-AEFA7D7DB192}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - The Legend\KB.exe () [File not signed] FirewallRules: [{D667F3C1-C546-4DA1-94AF-2CDF89F78112}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - The Legend\KB.exe () [File not signed] FirewallRules: [{4836E04C-4DA4-4359-A039-50E2FB83F1EF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - The Legend\save_fixer.exe () [File not signed] FirewallRules: [{23C91EAB-F4ED-4954-8A2F-3F00D2193B3D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - The Legend\save_fixer.exe () [File not signed] FirewallRules: [{20CD0404-C23B-4E26-86D1-9F90637E7A6F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Star Control - Origins\Game\StarControl_DX11.exe (STARDOCK SYSTEMS, INC. -> Stardock Entertainment) FirewallRules: [{8D607CB3-153E-4B90-88A3-64798D469A36}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Star Control - Origins\Game\StarControl_DX11.exe (STARDOCK SYSTEMS, INC. -> Stardock Entertainment) FirewallRules: [TCP Query User{16320938-54D4-4877-89B2-A62ABA972891}C:\program files (x86)\gruntmods studios\dune 2000\dune2000.exe] => (Block) C:\program files (x86)\gruntmods studios\dune 2000\dune2000.exe (Intelligent Games) [File not signed] FirewallRules: [UDP Query User{A540290B-725D-4290-8A8C-4ACCDEFC8764}C:\program files (x86)\gruntmods studios\dune 2000\dune2000.exe] => (Block) C:\program files (x86)\gruntmods studios\dune 2000\dune2000.exe (Intelligent Games) [File not signed] FirewallRules: [{ED86436D-2226-4F8C-BB33-45AFC84DA2A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout New Vegas\FalloutNVLauncher.exe (Bethesda Softworks -> Bethesda Softworks, Obsidian Entertainment) FirewallRules: [{666C8AC8-2E55-4249-85E9-AF293D12FAE2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout New Vegas\FalloutNVLauncher.exe (Bethesda Softworks -> Bethesda Softworks, Obsidian Entertainment) FirewallRules: [{F8CD94B8-40CF-4ACC-BC2D-9A5B2E835DA3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Witcher Enhanced Edition\System\witcher.exe (CD Projekt Red) [File not signed] FirewallRules: [{4A11C48E-0F6B-4A52-BFBE-F1A89910E3CE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Witcher Enhanced Edition\System\witcher.exe (CD Projekt Red) [File not signed] FirewallRules: [{EB83EE32-67A9-402B-85E8-F2F92A860F72}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Witcher Enhanced Edition\System\djinni!.exe (CD Projekt RED Sp. z o.o. -> CD Projekt Red) FirewallRules: [{FEABD3CA-0D82-48A1-80E6-14A18B54DAE4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Witcher Enhanced Edition\System\djinni!.exe (CD Projekt RED Sp. z o.o. -> CD Projekt Red) FirewallRules: [{31CC21FE-75D0-446D-BEE3-BDD7C0B21D9A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Witcher Enhanced Edition\Digital Comic\DigitalComic.exe () [File not signed] FirewallRules: [{F7D9AD22-05DC-4314-A106-315AB03E8ECB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Witcher Enhanced Edition\Digital Comic\DigitalComic.exe () [File not signed] FirewallRules: [TCP Query User{0ADFB0DC-9BEA-4101-90EB-E8AA7C8E102B}C:\program files (x86)\starcraft ii\versions\base77661\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base77661\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [UDP Query User{DA91FFCF-4246-4C93-8DC7-ED1AA85A0DE8}C:\program files (x86)\starcraft ii\versions\base77661\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base77661\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [TCP Query User{9BCF642B-3BD0-4D38-8444-3FDA10890965}C:\program files (x86)\starcraft ii\versions\base78285\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base78285\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [UDP Query User{979D6B9C-9B63-4F70-9707-E4CEF9646EC3}C:\program files (x86)\starcraft ii\versions\base78285\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base78285\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [{E8D8375B-80AF-44BD-91BC-C9C0959757C8}] => (Allow) C:\Users\Craig\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [{EDF049A7-7E14-4F74-B0E5-7F76FD394E04}] => (Allow) C:\Users\Craig\AppData\Roaming\Zoom\bin\airhost.exe => No File FirewallRules: [{453DC83E-CFC3-4C7D-AD21-E39E0F567CFE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Star Control - Origins\Game\StardockLauncher.exe (STARDOCK SYSTEMS, INC. -> Stardock Corporation) FirewallRules: [{0E7F3E7A-C96F-4421-AB46-84D2320B1BAC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Star Control - Origins\Game\StardockLauncher.exe (STARDOCK SYSTEMS, INC. -> Stardock Corporation) FirewallRules: [{DCF997DC-7C57-4908-A7FF-2F39D272438B}] => (Allow) C:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe (Sony DADC Austria AG -> Sony DADC Austria AG) [File not signed] FirewallRules: [{2678A2B6-A0AE-4005-ADD6-6FFB8B9B8CEC}] => (Allow) C:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe (Sony DADC Austria AG -> Sony DADC Austria AG) [File not signed] FirewallRules: [TCP Query User{96F75C72-DF14-4253-B905-7F4EE917B7B3}C:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe] => (Allow) C:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [UDP Query User{27277B1E-2A9D-435F-B5AD-54DC847D06D5}C:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe] => (Allow) C:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{C615C51B-DC75-498C-A5B4-938010EBC2C8}] => (Allow) C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{CF0915B9-EDEC-4575-9DCC-128A3A54890E}] => (Allow) C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [TCP Query User{D8819FD5-C843-41CE-8645-B0DB090949C9}C:\users\craig\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\craig\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [UDP Query User{E3C38948-D68B-4EBE-8D27-2045D5986C7D}C:\users\craig\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\craig\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{658E53A7-5BF7-40F7-A789-9A80E5395F12}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout Shelter\FalloutShelter.exe () [File not signed] FirewallRules: [{30BBED2D-1A5C-4796-9EDE-27FB7ECDFF3D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout Shelter\FalloutShelter.exe () [File not signed] FirewallRules: [{D91F61A4-28D5-4502-9EAD-438BFB4DB534}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\the witcher 2\Launcher.exe (CD Projekt RED) [File not signed] FirewallRules: [{65D05DD2-6CDB-4F3E-A7E7-580F1B0287BC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\the witcher 2\Launcher.exe (CD Projekt RED) [File not signed] FirewallRules: [TCP Query User{C0005896-4926-42BC-87D8-9D2D90535AFD}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe () [File not signed] FirewallRules: [UDP Query User{9E98EC9D-E6FD-4448-BE35-D4B4FE851534}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe () [File not signed] FirewallRules: [{55283902-E463-474C-AD45-88DB2DAD00FC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCOM 2\Launcher\launcher.exe (Xsolla (USA), Inc -> 2K) FirewallRules: [{A3BE85FB-A1A3-482A-9516-E6F16A84337D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCOM 2\Launcher\launcher.exe (Xsolla (USA), Inc -> 2K) FirewallRules: [TCP Query User{0DE79136-0932-4F45-A316-D35C6C0510D6}C:\program files (x86)\steam\steamapps\common\xcom 2\binaries\win64\xcom2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom 2\binaries\win64\xcom2.exe (Firaxis Games) [File not signed] FirewallRules: [UDP Query User{DCE385BD-A703-45F9-8562-DB337E6574D8}C:\program files (x86)\steam\steamapps\common\xcom 2\binaries\win64\xcom2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom 2\binaries\win64\xcom2.exe (Firaxis Games) [File not signed] FirewallRules: [TCP Query User{AB560AFB-01C6-4E87-9431-E6041224F5EF}C:\program files (x86)\steam\steamapps\common\xcom 2\xcom2-warofthechosen\binaries\win64\xcom2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom 2\xcom2-warofthechosen\binaries\win64\xcom2.exe (Firaxis Games) [File not signed] FirewallRules: [UDP Query User{600285AA-81FB-4933-8C2E-F93F00F3EC66}C:\program files (x86)\steam\steamapps\common\xcom 2\xcom2-warofthechosen\binaries\win64\xcom2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom 2\xcom2-warofthechosen\binaries\win64\xcom2.exe (Firaxis Games) [File not signed] FirewallRules: [{8A257314-0BAD-4DCF-971E-457DF2DD989B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe () [File not signed] FirewallRules: [{328BF880-69A8-4954-871B-34C5C2EC5058}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe () [File not signed] FirewallRules: [{E3569B00-40EE-49D5-8E77-70EE65D6A4AA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - Warriors of the North\KBWotN.exe () [File not signed] FirewallRules: [{95019805-3548-4729-9835-A6AC0FF41CAC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - Warriors of the North\KBWotN.exe () [File not signed] FirewallRules: [{E9EDB4C9-5E2C-4CE3-9C1E-C440E369AA6A}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe (Electronic Arts -> BioWare) FirewallRules: [{FA6ECD3C-7F4B-4902-A582-F89C8702486C}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe (Electronic Arts -> BioWare) FirewallRules: [{868E4B36-3272-44F6-BE61-75E926659234}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mass Effect\Binaries\MassEffect.exe (BioWare -> BioWare) FirewallRules: [{10238474-9FB6-4758-B95B-685F2035C049}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mass Effect\Binaries\MassEffect.exe (BioWare -> BioWare) FirewallRules: [{3600C7A8-6C36-4833-BDE6-CBBA640581D5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mass Effect 2\Binaries\MassEffect2.exe (BioWare -> BioWare) FirewallRules: [{CEB55E99-B3EF-4914-983A-E0C3B73FCF18}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mass Effect 2\Binaries\MassEffect2.exe (BioWare -> BioWare) FirewallRules: [{42352F91-FD69-490E-AFDB-EE1512153F51}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mass Effect 2\MassEffect2Launcher.exe (BioWare -> BioWare) FirewallRules: [{BCEA40AD-B1D6-49C9-B1C9-57AA4B7F7156}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mass Effect 2\MassEffect2Launcher.exe (BioWare -> BioWare) FirewallRules: [{46B8BCB2-7BE0-4700-AD75-F527E282651A}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe (BlueStack Systems, Inc. -> BlueStack Systems, Inc.) FirewallRules: [{7AA288B2-DA55-429C-9C90-005EBE4241F5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\War For The Overworld\WFTO.exe (BRIGHTROCK GAMES LIMITED -> ) FirewallRules: [{D72B9CFB-110F-4124-B987-3285ACE7AB81}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\War For The Overworld\WFTO.exe (BRIGHTROCK GAMES LIMITED -> ) FirewallRules: [TCP Query User{CFC5B7A3-E0CB-430A-800E-5B8748B8979D}C:\program files (x86)\steam\steamapps\common\war for the overworld\wftogame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war for the overworld\wftogame.exe () [File not signed] FirewallRules: [UDP Query User{E3D978C0-68F5-433C-9C1C-35E5CA91E785}C:\program files (x86)\steam\steamapps\common\war for the overworld\wftogame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war for the overworld\wftogame.exe () [File not signed] FirewallRules: [{C125E002-C3A8-4164-ACE4-7F24A35B42C2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCOM 2\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{4E4FABF8-D387-40FD-8501-165D9C2EAC0B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCOM 2\2KLauncher\LauncherPatcher.exe (Take-Two Interactive Software, Inc. -> Take-Two Interactive Software, Inc.) FirewallRules: [{7D7A21F7-F883-4FA6-ABF6-9DA85EA3179C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Heroes of Might and Magic 5\bin\H5_Game.exe () [File not signed] FirewallRules: [{B316EA9C-6129-45A5-B3F9-8327A82F1ED5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Heroes of Might and Magic 5\bin\H5_Game.exe () [File not signed] FirewallRules: [{8BE6CB61-DBA3-4BC0-B371-AFBCC08A1624}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Don't Starve Together\bin\dontstarve_steam.exe () [File not signed] FirewallRules: [{70A13C75-3A12-4BD2-BC37-3DA997CF3E0E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Don't Starve Together\bin\dontstarve_steam.exe () [File not signed] FirewallRules: [{1AE694AD-BAB3-440E-82FA-DB371B41E75F}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{41E71226-C19B-48D7-BE1D-F8906F6AD27B}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{3B636115-1181-44DB-BA66-1F79EBC542CA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{29BB4832-3DFB-4B01-88A5-073A5AD8F761}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) ==================== Restore Points ========================= 20-06-2021 23:56:08 Restore Operation ==================== Faulty Device Manager Devices ============ Name: HID-compliant touch screen Description: HID-compliant touch screen Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da} Manufacturer: (Standard system devices) Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ======================== Application errors: ================== Error: (06/25/2021 08:15:33 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ig.exe, version: 1.0.1.1, time stamp: 0x5f43d0e0 Faulting module name: KERNELBASE.dll, version: 6.3.9600.18895, time stamp: 0x5a4b127e Exception code: 0xc0000142 Fault offset: 0x0009d4e2 Faulting process id: 0x1680 Faulting application start time: 0x01d769897c9937a5 Faulting application path: C:\Users\Craig\AppData\LocalLow\IGDump\gcockxxaqnasgljyseuleklgjoltorwr\ig.exe Faulting module path: KERNELBASE.dll Report Id: bf2726eb-d57c-11eb-86af-0025ab391c4b Faulting package full name: Faulting package-relative application ID: Error: (06/25/2021 07:30:07 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program LiveComm.exe version 17.5.9600.20498 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 11c0 Start Time: 01d769826e9541ef Termination Time: 4294967295 Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\LiveComm.exe Report Id: 623a4659-d576-11eb-86af-0025ab391c4b Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1 Error: (06/25/2021 07:15:26 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program LiveComm.exe version 17.5.9600.20498 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 4dc Start Time: 01d7698056304e1d Termination Time: 4294967295 Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\LiveComm.exe Report Id: 4a40a548-d574-11eb-86af-0025ab391c4b Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1 Error: (06/25/2021 06:55:12 AM) (Source: DdMgrServiceHost) (EventID: 0) (User: ) Description: Service cannot be started. System.PlatformNotSupportedException: Operation is not supported on this platform. at System.Net.HttpListener..ctor() at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener) at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback) at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.ServiceHostBase.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at DdMgr.DdMgrServiceHost.OnStart(Str... Error: (06/24/2021 11:02:29 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CRAIGPC) Description: Activation of app E046963F.LenovoSupport_k1h2ywk1493x8!App failed with error: -2147009284 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (06/24/2021 11:02:29 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CRAIGPC) Description: Activation of app E046963F.LenovoSupport_k1h2ywk1493x8!App failed with error: -2147009284 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (06/24/2021 11:02:25 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CRAIGPC) Description: Activation of app E046963F.LenovoSupport_k1h2ywk1493x8!App failed with error: -2147009284 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (06/24/2021 11:02:25 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CRAIGPC) Description: Activation of app E046963F.LenovoSupport_k1h2ywk1493x8!App failed with error: -2147009284 See the Microsoft-Windows-TWinUI/Operational log for additional information. System errors: ============= Error: (06/25/2021 08:40:27 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Device Setup Manager service depends on the HTTP Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (06/25/2021 07:03:37 AM) (Source: DCOM) (EventID: 10000) (User: NT AUTHORITY) Description: Unable to start a DCOM Server: {ECF5BF46-E3B6-449A-B56B-43F58F867814}. The error: "2" Happened while starting this command: C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (06/25/2021 07:03:37 AM) (Source: DCOM) (EventID: 10000) (User: NT AUTHORITY) Description: Unable to start a DCOM Server: {ECF5BF46-E3B6-449A-B56B-43F58F867814}. The error: "2" Happened while starting this command: C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (06/25/2021 07:00:45 AM) (Source: DCOM) (EventID: 10000) (User: NT AUTHORITY) Description: Unable to start a DCOM Server: {ECF5BF46-E3B6-449A-B56B-43F58F867814}. The error: "2" Happened while starting this command: C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (06/25/2021 06:57:18 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The SSDP Discovery service depends on the HTTP Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (06/25/2021 06:57:06 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Device Setup Manager service depends on the HTTP Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (06/25/2021 06:57:06 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Device Setup Manager service depends on the HTTP Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (06/25/2021 06:57:06 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Device Setup Manager service depends on the HTTP Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Windows Defender: ================ Date: 2021-06-24 02:14:22.126 Description: Windows Defender scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2021-06-23 07:42:45.086 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Behavior:Win32/Meterpreter.gen!A&threatid=2147723573&enterprise=0 Name: Behavior:Win32/Meterpreter.gen!A Severity: Severe Category: Suspicious Behavior Path: behavior:_pid:3604:74439734262196;process:_pid:3604,ProcessStart:132688984038754662 Detection Origin: Unknown Detection Type: Generic Detection Source: System Process Name: C:\WINDOWS\SysWOW64\svchost.exe Signature Version: AV: 1.341.1029.0, AS: 1.341.1029.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.18200.4, NIS: 2.1.14600.4 Date: 2021-06-21 19:13:49.130 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Behavior:Win32/Meterpreter.gen!A&threatid=2147723573&enterprise=0 Name: Behavior:Win32/Meterpreter.gen!A Severity: Severe Category: Suspicious Behavior Path: behavior:_pid:5988:74439734262196;process:_pid:5988,ProcessStart:132687667783548699 Detection Origin: Unknown Detection Type: Generic Detection Source: System Process Name: C:\WINDOWS\SysWOW64\svchost.exe Signature Version: AV: 1.341.1029.0, AS: 1.341.1029.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.18200.4, NIS: 2.1.14600.4 Date: 2021-06-21 18:45:38.986 Description: Windows Defender scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2021-06-21 18:29:26.693 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Behavior:Win32/Meterpreter.gen!A&threatid=2147723573&enterprise=0 Name: Behavior:Win32/Meterpreter.gen!A Severity: Severe Category: Suspicious Behavior Path: behavior:_pid:2148:74439734262196;process:_pid:2148,ProcessStart:132687492438890581 Detection Origin: Unknown Detection Type: Generic Detection Source: System Process Name: C:\WINDOWS\SysWOW64\svchost.exe Signature Version: AV: 1.341.1029.0, AS: 1.341.1029.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.18200.4, NIS: 2.1.14600.4 Date: 2021-06-21 10:50:02.728 Description: Windows Defender Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x8007043c Error description: This service cannot be started in Safe Mode Reason: Antimalware protection has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem. Date: 2021-06-21 06:46:54.248 Description: Windows Defender Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x8007043c Error description: This service cannot be started in Safe Mode Reason: Antimalware protection has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem. Date: 2021-06-21 05:25:24.898 Description: Windows Defender Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x8007043c Error description: This service cannot be started in Safe Mode Reason: Antimalware protection has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem. Date: 2021-06-21 05:19:10.743 Description: Windows Defender Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x8007043c Error description: This service cannot be started in Safe Mode Reason: Antimalware protection has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem. Date: 2021-06-21 05:15:48.459 Description: Windows Defender Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x8007043c Error description: This service cannot be started in Safe Mode Reason: Antimalware protection has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem. ==================== Memory info =========================== BIOS: LENOVO ELKT31AUS 03/21/2013 Motherboard: LENOVO MAHOBAY Processor: Intel(R) Core(TM) i3-3240 CPU @ 3.40GHz Percentage of memory in use: 65% Total physical RAM: 4054.93 MB Available physical RAM: 1391.61 MB Total Virtual: 8150.93 MB Available Virtual: 4667.41 MB ==================== Drives ================================ Drive c: (Windows8_OS) (Fixed) (Total:904.81 GB) (Free:413.79 GB) NTFS ==>[system with boot components (obtained from drive)] \\?\Volume{e99a0d33-2154-4e24-8156-4f778a666df0}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.6 GB) NTFS \\?\Volume{1a428c6c-b346-4344-860a-5064409f0dd0}\ () (Fixed) (Total:0.44 GB) (Free:0.18 GB) NTFS \\?\Volume{cca033ca-f1ae-4966-9052-b0a9b96c9445}\ (PBR_DRV) (Fixed) (Total:24.41 GB) (Free:9.77 GB) NTFS ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 59D4669E) Partition: GPT. ==================== End of Addition.txt =======================