Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-10-2022 02 Ran by [removed] (02-11-2022 12:28:57) Running from C:\Users\[removed]\Downloads Microsoft Windows 10 Home Version 21H2 19044.2130 (X64) (2022-01-27 15:31:10) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) Administrator (S-1-5-21-1194324949-2680677275-2362750293-500 - Administrator - Disabled) bfvmg (S-1-5-21-1194324949-2680677275-2362750293-1002 - Administrator - Enabled) => C:\Users\bfvmg DefaultAccount (S-1-5-21-1194324949-2680677275-2362750293-503 - Limited - Disabled) Gaming Rig (S-1-5-21-1194324949-2680677275-2362750293-1001 - Limited - Enabled) => C:\Users\Gaming Rig Guest (S-1-5-21-1194324949-2680677275-2362750293-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-1194324949-2680677275-2362750293-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Malwarebytes (Enabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1033-FFFF-7760-BC15014EA700}) (Version: 22.003.20263 - Adobe) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 5.8.0.592 - Adobe Inc.) Adobe Genuine Service (HKLM-x32\...\AdobeGenuineService) (Version: 8.0.0.11 - Adobe Inc.) Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601032}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - Canon Inc.) Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.2.0 - Canon Inc.) Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - Canon Inc.) Canon MG2900 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2900_series) (Version: 1.00 - Canon Inc.) Canon MX920 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX920_series) (Version: 1.01 - Canon Inc.) Discord (HKU\S-1-5-21-1194324949-2680677275-2362750293-1001\...\Discord) (Version: 0.0.311 - Discord Inc.) Dropbox (HKLM-x32\...\Dropbox) (Version: 160.4.4703 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.639.1 - Dropbox, Inc.) Hidden Glary Utilities 5.181 (HKLM-x32\...\Glary Utilities 5) (Version: 5.181.0.210 - Glarysoft Ltd) GOG GALAXY (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 107.0.5304.88 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.421 - Google LLC) Hidden InstallRoot (HKLM-x32\...\{B48F8D38-B01E-44DC-9884-DB4AD1B8CA2B}) (Version: 5.5 - DoD PKE) Java 8 Update 351 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180351F0}) (Version: 8.0.3510.10 - Oracle Corporation) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Malwarebytes version 4.5.16.217 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.16.217 - Malwarebytes) Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.15726.20174 - Microsoft Corporation) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 107.0.1418.26 - Microsoft Corporation) Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 107.0.1418.26 - Microsoft Corporation) Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 22.207.1002.0003 - Microsoft Corporation) Microsoft Teams (HKU\S-1-5-21-1194324949-2680677275-2362750293-1001\...\Teams) (Version: 1.5.00.21668 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.32.31326 (HKLM-x32\...\{2d507699-404c-4c8b-a54a-38e352f32cdd}) (Version: 14.32.31326.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.32.31326 (HKLM-x32\...\{817e21c1-6b3a-4bc1-8c49-67e4e1887b3a}) (Version: 14.32.31326.0 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Additional Runtime - 14.32.31326 (HKLM\...\{38624EB5-356D-4B08-8357-C33D89A5C0C5}) (Version: 14.32.31326 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.32.31326 (HKLM\...\{C96241EA-9900-4FE8-85B3-1E238D509DF6}) (Version: 14.32.31326 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Additional Runtime - 14.32.31326 (HKLM-x32\...\{A250E750-DB3F-40C1-8460-8EF77C7582DA}) (Version: 14.32.31326 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.32.31326 (HKLM-x32\...\{46E11E7F-01E1-44D0-BB86-C67342D253DD}) (Version: 14.32.31326 - Microsoft Corporation) Hidden Might and Magic - Swords of Xeen (HKLM-x32\...\1207661243_is1) (Version: 1.0 - GOG.com) Npcap (HKLM-x32\...\NpcapInst) (Version: 1.55 - Nmap Project) NVIDIA 3D Vision Controller Driver 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation) NVIDIA FrameView SDK 1.2.4999.30397803 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.2.4999.30397803 - NVIDIA Corporation) NVIDIA GeForce Experience 3.24.0.126 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.24.0.126 - NVIDIA Corporation) NVIDIA Graphics Driver 512.15 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 512.15 - NVIDIA Corporation) NVIDIA PhysX System Software 9.18.0907 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.18.0907 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.15726.20096 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.15726.20096 - Microsoft Corporation) Hidden Private Internet Access (HKLM\...\{33023371-7761-4F81-BBB1-0E0D0D175ACF}) (Version: 3.3.1+06924 - Private Internet Access, Inc.) Private Internet Access Support Files (HKLM-x32\...\{7D72DAFF-DCB2-437B-BC22-4B2ABF21462B}) (Version: 1.0.0.0 - Private Internet Access) Private Internet Access WinTUN Driver (HKLM\...\{0419A0C0-4CC8-459E-9BAE-F3BF5D2E2CCB}) (Version: 1.0 - Private Internet Access, Inc.) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKU\S-1-5-21-1194324949-2680677275-2362750293-1001\...\TeamSpeak 3 Client) (Version: 3.2.3 - TeamSpeak Systems GmbH) UE4 Prerequisites (x64) (HKLM\...\{F9EC45F9-074A-48BF-92E9-A8CADD56F693}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden UE4 Prerequisites (x64) (HKLM-x32\...\{4e242cc8-5e3c-4b08-9d55-dbc62ddd1208}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{82BD0A1C-815F-487F-9AE7-CE73DA413CFF}) (Version: 4.91.0.0 - Microsoft Corporation) Wireshark 3.6.2 64-bit (HKLM-x32\...\Wireshark) (Version: 3.6.2 - The Wireshark developer community, hxxps://www.wireshark.org) Zoom (HKU\S-1-5-21-1194324949-2680677275-2362750293-1001\...\ZoomUMX) (Version: 5.9.3 (3169) - Zoom Video Communications, Inc.) Packages: ========= Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_1.8.1.0_x64__tf1gferkr813w [2018-06-01] (Autodesk Inc.) Bubble Witch 3 Saga -> C:\Program Files\WindowsApps\king.com.BubbleWitch3Saga_4.11.3.0_x86__kgqvnymyfvs32 [2018-10-18] (king.com) Canon Inkjet Print Utility -> C:\Program Files\WindowsApps\34791E63.CanonInkjetPrintUtility_3.1.0.0_neutral__6e5tt8cgb93ep [2022-11-02] (Canon Inc.) Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.15.523.0_x64__rz1tebttyb220 [2022-11-02] (Dolby Laboratories) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2022-01-27] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2022-01-27] (Microsoft Corporation) [MS Ad] Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.27.2643.0_x64__8wekyb3d8bbwe [2018-10-18] (Microsoft Corporation) [MS Ad] ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1194324949-2680677275-2362750293-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-9AE9EA1A54F3} -> [Creative Cloud Files] => C:\Users\Gaming Rig\Creative Cloud Files [2022-06-09 11:51] CustomCLSID: HKU\S-1-5-21-1194324949-2680677275-2362750293-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Gaming Rig\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.22209.4\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1194324949-2680677275-2362750293-1001_Classes\CLSID\{2F81B25E-7507-4844-BFF2-77D2CC24CED4}\localserver32 -> C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Inc. -> Adobe Inc.) CustomCLSID: HKU\S-1-5-21-1194324949-2680677275-2362750293-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => E:\Dropbox [2017-09-09 07:31] CustomCLSID: HKU\S-1-5-21-1194324949-2680677275-2362750293-1002_Classes\CLSID\{2F81B25E-7507-4844-BFF2-77D2CC24CED4}\localserver32 -> C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Inc. -> Adobe Inc.) CustomCLSID: HKU\S-1-5-21-1194324949-2680677275-2362750293-1002_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems) ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2022-06-29] (Adobe Inc. -> ) ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2022-06-29] (Adobe Inc. -> ) ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2022-06-29] (Adobe Inc. -> ) ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2022-06-29] (Adobe Inc. -> ) ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2022-10-16] (Adobe Inc. -> Adobe Systems Inc.) ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2022-01-21] (Glarysoft LTD -> Glarysoft Ltd) ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2022-01-21] (Glarysoft LTD -> Glarysoft Ltd) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-11-02] (Malwarebytes Inc. -> Malwarebytes) ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.207.1002.0003\FileSyncShell64.dll [2022-10-24] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.56.0.dll [2022-10-28] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvmd.inf_amd64_1408eaf9a25ed64f\nvshext.dll [2020-12-02] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2022-06-29] (Adobe Inc. -> ) ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2022-10-16] (Adobe Inc. -> Adobe Systems Inc.) ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2022-01-21] (Glarysoft LTD -> Glarysoft Ltd) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-11-02] (Malwarebytes Inc. -> Malwarebytes) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2022-11-02 11:42 - 2022-11-02 11:42 - 000008704 _____ () [File not signed] C:\Users\Gaming Rig\AppData\Local\Temp\nss1CC2.tmp\newadvsplash.dll 2022-02-03 13:18 - 2012-08-31 11:30 - 000312832 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNSS_ENU.DLL 2017-09-12 06:20 - 2014-03-17 13:45 - 000375296 _____ (CANON INC.) [File not signed] C:\WINDOWS\System32\CNMN6PPM.DLL 2022-10-17 14:06 - 2022-10-17 14:06 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems64.dll] C:\Program Files\Microsoft Office\root\Office16\AppVIsvSubsystems64.dll 2022-10-17 14:06 - 2022-10-17 14:06 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R64.dll] C:\Program Files\Microsoft Office\root\Office16\c2r64.dll ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Public\AppData:CSM [482] AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [474] ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2022-04-07] (Adobe Inc. -> Adobe Systems Incorporated) BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2022-04-07] (Adobe Inc. -> Adobe Systems Incorporated) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2022-11-02] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_351\bin\ssv.dll [2022-11-02] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2022-04-07] (Adobe Inc. -> Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_351\bin\jp2ssv.dll [2022-11-02] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2022-04-07] (Adobe Inc. -> Adobe Systems Incorporated) Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2022-04-07] (Adobe Inc. -> Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2022-04-07] (Adobe Inc. -> Adobe Systems Incorporated) Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-11-02] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-11-02] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-11-02] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-11-02] (Microsoft Corporation -> Microsoft Corporation) Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-11-02] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-11-02] (Microsoft Corporation -> Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-11-02] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-11-02] (Microsoft Corporation -> Microsoft Corporation) (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-1194324949-2680677275-2362750293-1001\...\osd.mil -> hxxps://dmdc.osd.mil ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2016-07-16 05:47 - 2017-11-24 00:03 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\ISC BIND 9\bin HKU\S-1-5-21-1194324949-2680677275-2362750293-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Gaming Rig\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\r3roigd-copy.jpg HKU\S-1-5-21-1194324949-2680677275-2362750293-1002\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg DNS Servers: 10.0.0.243 - 208.67.222.222 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. Network Binding: ============= Local Area Connection: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) Ethernet 2: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) Ethernet: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKLM\...\StartupApproved\Run: => "SecurityHealth" HKU\S-1-5-21-1194324949-2680677275-2362750293-1001\...\StartupApproved\Run: => "GUDelayStartup" HKU\S-1-5-21-1194324949-2680677275-2362750293-1001\...\StartupApproved\Run: => "OneDriveSetup" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{01FCE285-1D0C-4B37-8FDD-F58F564C43DA}] => (Allow) E:\SteamLibrary\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe => No File FirewallRules: [{6B2F3F5F-DDFB-4F53-BDE2-EA6449C82240}] => (Allow) E:\SteamLibrary\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe => No File FirewallRules: [UDP Query User{E030CD2B-020F-4B46-B339-A2B2951CA3C0}C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe] => (Allow) C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe => No File FirewallRules: [TCP Query User{640265B4-9E61-466D-A954-D5AB56B86057}C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe] => (Allow) C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe => No File FirewallRules: [UDP Query User{012C35B5-C2BB-417F-832D-2A679C1816BC}C:\users\gaming rig\appdata\local\gamecenter\gamecenter.exe] => (Allow) C:\users\gaming rig\appdata\local\gamecenter\gamecenter.exe => No File FirewallRules: [TCP Query User{22190FBF-A116-4CB3-BF6C-6DFC9912F1CA}C:\users\gaming rig\appdata\local\gamecenter\gamecenter.exe] => (Allow) C:\users\gaming rig\appdata\local\gamecenter\gamecenter.exe => No File FirewallRules: [UDP Query User{2B6D49EE-1295-463C-A219-DADC920D75CE}C:\program files (x86)\portalarium\shroud of the avatar\shroud of the avatar - launcher.exe] => (Allow) C:\program files (x86)\portalarium\shroud of the avatar\shroud of the avatar - launcher.exe => No File FirewallRules: [TCP Query User{35B28DF1-9620-4892-8230-9CFB639AEB82}C:\program files (x86)\portalarium\shroud of the avatar\shroud of the avatar - launcher.exe] => (Allow) C:\program files (x86)\portalarium\shroud of the avatar\shroud of the avatar - launcher.exe => No File FirewallRules: [UDP Query User{93437402-8032-4FD9-B942-B08EF6E3358D}C:\users\gaming rig\appdata\local\mycomgames\gamecenter.exe] => (Allow) C:\users\gaming rig\appdata\local\mycomgames\gamecenter.exe => No File FirewallRules: [TCP Query User{959794C2-159B-4E53-9891-062B1B8474B0}C:\users\gaming rig\appdata\local\mycomgames\gamecenter.exe] => (Allow) C:\users\gaming rig\appdata\local\mycomgames\gamecenter.exe => No File FirewallRules: [UDP Query User{51FFA74C-41AF-4AFD-9717-CD431066B615}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe => No File FirewallRules: [TCP Query User{E5B05F47-6100-425E-9C88-1D30B89EF605}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe => No File FirewallRules: [{78E4A945-B45A-4A37-BED7-15383524591F}] => (Block) E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe => No File FirewallRules: [{86A0ED8E-83A3-47CF-B488-81F9F05DAB33}] => (Block) E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe => No File FirewallRules: [UDP Query User{181DE4C8-ED68-4DBF-8B9F-CEA845BB7C1A}E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe] => (Allow) E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe => No File FirewallRules: [TCP Query User{E1830725-7E7F-450B-95B9-DD5540195382}E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe] => (Allow) E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe => No File FirewallRules: [{6E964043-52B5-4C80-8125-50247D801CB6}] => (Block) C:\honeybot\honeybot.exe => No File FirewallRules: [{03FFED94-8C41-48BE-B670-850C8F316E82}] => (Block) C:\honeybot\honeybot.exe => No File FirewallRules: [UDP Query User{7F685854-7149-4337-8537-5062D9D8FD54}C:\honeybot\honeybot.exe] => (Allow) C:\honeybot\honeybot.exe => No File FirewallRules: [TCP Query User{795CF741-DE47-4765-AB3C-1E88687D8A13}C:\honeybot\honeybot.exe] => (Allow) C:\honeybot\honeybot.exe => No File FirewallRules: [{516CB8BC-3CF7-4628-8097-1616414597FF}] => (Block) C:\users\gaming rig\appdata\local\mycomgames\mycomgames.exe => No File FirewallRules: [{A8C38EE1-3E8A-4DFA-A21F-23AD708DAB41}] => (Block) C:\users\gaming rig\appdata\local\mycomgames\mycomgames.exe => No File FirewallRules: [UDP Query User{6DFF007B-79BE-4DBB-B2AB-A592057307EC}C:\users\gaming rig\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\gaming rig\appdata\local\mycomgames\mycomgames.exe => No File FirewallRules: [TCP Query User{24E42917-3DE0-42F6-98F3-D12C21DF2969}C:\users\gaming rig\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\gaming rig\appdata\local\mycomgames\mycomgames.exe => No File FirewallRules: [UDP Query User{1BCDA602-B07E-4AA3-ADA9-56E3A0A41BA6}E:\steamlibrary\steamapps\common\empyrion - galactic survival\empyrion.exe] => (Allow) E:\steamlibrary\steamapps\common\empyrion - galactic survival\empyrion.exe => No File FirewallRules: [TCP Query User{939E0516-F344-43CE-8FED-D3B59075FE16}E:\steamlibrary\steamapps\common\empyrion - galactic survival\empyrion.exe] => (Allow) E:\steamlibrary\steamapps\common\empyrion - galactic survival\empyrion.exe => No File FirewallRules: [{5A38482C-09A4-4893-98AB-C2967C5AFDF3}] => (Block) E:\steamlibrary\steamapps\common\just survive\h1z1.exe => No File FirewallRules: [{4C288CB9-16A5-483B-BFB6-C64E60B41521}] => (Block) E:\steamlibrary\steamapps\common\just survive\h1z1.exe => No File FirewallRules: [UDP Query User{F94C7231-32C9-4598-82F9-9626E0E32B0C}E:\steamlibrary\steamapps\common\just survive\h1z1.exe] => (Allow) E:\steamlibrary\steamapps\common\just survive\h1z1.exe => No File FirewallRules: [TCP Query User{85A13817-066F-45EE-BBDA-66BEFBBEEED8}E:\steamlibrary\steamapps\common\just survive\h1z1.exe] => (Allow) E:\steamlibrary\steamapps\common\just survive\h1z1.exe => No File FirewallRules: [{37DB1DA5-2FFE-44E6-9F72-62B3193BF58A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{12BE2267-DE05-40A8-B2BD-E67837BD997B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{BEED65B3-9164-47F6-8C72-02FE857DFF02}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File FirewallRules: [{E3104AF4-3D1F-4A41-8645-CDB0E7DEA1B2}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File FirewallRules: [TCP Query User{878D7565-B722-4119-B0B1-6444FA5130DC}E:\steamlibrary\steamapps\common\h1z1\h1z1.exe] => (Allow) E:\steamlibrary\steamapps\common\h1z1\h1z1.exe => No File FirewallRules: [UDP Query User{9FD476CA-E59A-4342-B3B8-159472455764}E:\steamlibrary\steamapps\common\h1z1\h1z1.exe] => (Allow) E:\steamlibrary\steamapps\common\h1z1\h1z1.exe => No File FirewallRules: [TCP Query User{71383A3D-4660-4493-B95F-1C30C9B38D88}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe => No File FirewallRules: [UDP Query User{41B17209-B0ED-4904-AB31-66E879035C57}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe => No File FirewallRules: [TCP Query User{3325033B-1BD2-4F57-BBCE-E24297ADF089}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe => No File FirewallRules: [UDP Query User{73E89BAF-D15B-4EA6-B85F-B4F0D5AD844B}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe => No File FirewallRules: [TCP Query User{CB22DD0C-03E8-44F6-9B6A-E21876F357CE}C:\program files (x86)\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files (x86)\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File FirewallRules: [UDP Query User{9A9B736B-7775-4749-BDA4-5AA4A47FD4DC}C:\program files (x86)\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files (x86)\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File FirewallRules: [TCP Query User{3B511BCD-6436-47E8-A871-7AD4EEEA57BC}E:\steamlibrary\steamapps\common\scum\scum\binaries\win64\scum.exe] => (Allow) E:\steamlibrary\steamapps\common\scum\scum\binaries\win64\scum.exe => No File FirewallRules: [UDP Query User{BE1D3B67-2D76-4FBA-88B1-25C8877B269D}E:\steamlibrary\steamapps\common\scum\scum\binaries\win64\scum.exe] => (Allow) E:\steamlibrary\steamapps\common\scum\scum\binaries\win64\scum.exe => No File FirewallRules: [{3FD2282C-7C45-4A3D-98DC-D8C47A8DABB0}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{020D265D-90F9-40B7-A0AA-22F48E168726}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [TCP Query User{A80B7E42-D375-426D-B03A-7FCD69B0FE08}E:\steamlibrary\steamapps\common\scum\scum\binaries\win64\scum.exe] => (Allow) E:\steamlibrary\steamapps\common\scum\scum\binaries\win64\scum.exe => No File FirewallRules: [UDP Query User{D28D8762-42FA-47BF-8E1B-2327F1806F90}E:\steamlibrary\steamapps\common\scum\scum\binaries\win64\scum.exe] => (Allow) E:\steamlibrary\steamapps\common\scum\scum\binaries\win64\scum.exe => No File FirewallRules: [TCP Query User{55A61785-C276-454B-8259-11CE1FF935E5}E:\steamlibrary\steamapps\common\breathedge\breathedge\binaries\win64\breathedge.exe] => (Allow) E:\steamlibrary\steamapps\common\breathedge\breathedge\binaries\win64\breathedge.exe => No File FirewallRules: [UDP Query User{9147CB73-8933-4CBD-A983-E5A8E8E70B18}E:\steamlibrary\steamapps\common\breathedge\breathedge\binaries\win64\breathedge.exe] => (Allow) E:\steamlibrary\steamapps\common\breathedge\breathedge\binaries\win64\breathedge.exe => No File FirewallRules: [TCP Query User{9E2D165F-E850-4F20-85DC-039CAF64358F}C:\users\gaming rig\appdata\local\logmein rescue applet\lmir0fb1a001.tmp\lmi_rescue.exe] => (Allow) C:\users\gaming rig\appdata\local\logmein rescue applet\lmir0fb1a001.tmp\lmi_rescue.exe => No File FirewallRules: [UDP Query User{C58DFB48-C07E-4870-9D7B-696A7DE63035}C:\users\gaming rig\appdata\local\logmein rescue applet\lmir0fb1a001.tmp\lmi_rescue.exe] => (Allow) C:\users\gaming rig\appdata\local\logmein rescue applet\lmir0fb1a001.tmp\lmi_rescue.exe => No File FirewallRules: [TCP Query User{08DEA6E3-CD82-4099-B829-B7CD4874D9E7}C:\program files (x86)\destiny 2\destiny2.exe] => (Allow) C:\program files (x86)\destiny 2\destiny2.exe => No File FirewallRules: [UDP Query User{5610B36E-40BF-4810-B4AB-C60D1F364465}C:\program files (x86)\destiny 2\destiny2.exe] => (Allow) C:\program files (x86)\destiny 2\destiny2.exe => No File FirewallRules: [{788363AD-EF7C-4E5F-B9A8-4BCFC27FA331}] => (Block) C:\program files (x86)\destiny 2\destiny2.exe => No File FirewallRules: [{AEB228D6-CF24-4A5E-95C2-B6C8CC495658}] => (Block) C:\program files (x86)\destiny 2\destiny2.exe => No File FirewallRules: [TCP Query User{EAABE612-8DFD-4A9F-B499-1D084E61A14E}C:\program files (x86)\bethesda.net launcher\games\fallout76\fallout76.exe] => (Allow) C:\program files (x86)\bethesda.net launcher\games\fallout76\fallout76.exe => No File FirewallRules: [UDP Query User{4AC5C7D0-C312-4174-B803-318294E96EB0}C:\program files (x86)\bethesda.net launcher\games\fallout76\fallout76.exe] => (Allow) C:\program files (x86)\bethesda.net launcher\games\fallout76\fallout76.exe => No File FirewallRules: [TCP Query User{AF4C60F5-925A-49A6-8493-D36EDEE50B2A}E:\steamlibrary\steamapps\common\sandstorm\insurgency\binaries\win64\insurgencyclient-win64-shipping.exe] => (Allow) E:\steamlibrary\steamapps\common\sandstorm\insurgency\binaries\win64\insurgencyclient-win64-shipping.exe => No File FirewallRules: [UDP Query User{7B86F141-CB1C-45B2-A0B3-89AB8FBFBF4F}E:\steamlibrary\steamapps\common\sandstorm\insurgency\binaries\win64\insurgencyclient-win64-shipping.exe] => (Allow) E:\steamlibrary\steamapps\common\sandstorm\insurgency\binaries\win64\insurgencyclient-win64-shipping.exe => No File FirewallRules: [{D322734A-D3DC-4FAD-A918-EEC94004F5B2}] => (Allow) E:\SteamLibrary\steamapps\common\Warframe\Warframe.exe => No File FirewallRules: [{6B40357B-8AD3-48E9-AAD3-47CB73FF5807}] => (Allow) E:\SteamLibrary\steamapps\common\Warframe\Warframe.x64.exe => No File FirewallRules: [{33473595-659E-4BBE-85F7-4B80546F6D4D}] => (Allow) E:\SteamLibrary\steamapps\common\Warframe\Warframe.exe => No File FirewallRules: [{E3A7764E-86B6-4D7F-8ED4-0D3C73B44B7E}] => (Allow) E:\SteamLibrary\steamapps\common\Warframe\Warframe.x64.exe => No File FirewallRules: [{B6C09082-012D-4A13-90F5-464FF4EA1B3B}] => (Allow) E:\SteamLibrary\steamapps\common\Warframe\Tools\Launcher.exe => No File FirewallRules: [{0B66EA85-EAA5-4EC8-8374-59978905C6A6}] => (Allow) E:\SteamLibrary\steamapps\common\Warframe\Tools\RemoteCrashSender.exe => No File FirewallRules: [{0A8D4391-B7E5-4A4E-A52F-6D5CEC1A003D}] => (Allow) E:\SteamLibrary\steamapps\common\Warframe\Warframe.exe => No File FirewallRules: [{BCE10E4B-50C9-4E45-9553-C346E44CFABD}] => (Allow) E:\SteamLibrary\steamapps\common\Warframe\Warframe.x64.exe => No File FirewallRules: [{46A5B2FB-2579-4AE2-AA99-5C84112194D9}] => (Allow) E:\SteamLibrary\steamapps\common\Warframe\Warframe.exe => No File FirewallRules: [{884AC4E3-09DA-4DB6-8D95-362045B7624A}] => (Allow) E:\SteamLibrary\steamapps\common\Warframe\Warframe.x64.exe => No File FirewallRules: [{FD61B69C-454F-498C-8F9E-4833A8A2B249}] => (Allow) E:\SteamLibrary\steamapps\common\Warframe\Tools\Launcher.exe => No File FirewallRules: [{51F2A8C2-4DED-43C6-BC4E-6BA43AC3D973}] => (Allow) E:\SteamLibrary\steamapps\common\Warframe\Tools\RemoteCrashSender.exe => No File FirewallRules: [{93DEE352-F955-4617-96ED-867BBDCE85E2}] => (Allow) E:\SteamLibrary\steamapps\common\Miscreated\Bin64\Miscreated.exe => No File FirewallRules: [{20AA0989-40E8-4B2D-92A8-B109D7CE7B9C}] => (Allow) E:\SteamLibrary\steamapps\common\Miscreated\Bin64\Miscreated.exe => No File FirewallRules: [{C3BC2B66-1C6A-4B73-B720-21DD55A37788}] => (Allow) E:\SteamLibrary\steamapps\common\Miscreated\EasyAntiCheat\EasyAntiCheat_x64.dll => No File FirewallRules: [{894FECAD-EE87-4C30-9E70-8B4922F1595E}] => (Allow) E:\SteamLibrary\steamapps\common\Miscreated\EasyAntiCheat\EasyAntiCheat_x64.dll => No File FirewallRules: [{8B736762-8B63-450A-86FC-190334B459F8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{5B74EE2C-32BB-4109-B7C7-17BB13C8C1E0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [TCP Query User{D7A7F1DA-19B1-405E-8090-97616003C203}E:\wizardsofthecoast\mtgarena\mtga.exe] => (Allow) E:\wizardsofthecoast\mtgarena\mtga.exe => No File FirewallRules: [UDP Query User{11BB3A39-330D-4567-B05D-AA271C51C831}E:\wizardsofthecoast\mtgarena\mtga.exe] => (Allow) E:\wizardsofthecoast\mtgarena\mtga.exe => No File FirewallRules: [{8167D36E-99FC-42B1-B825-BB617C43122E}] => (Block) E:\wizardsofthecoast\mtgarena\mtga.exe => No File FirewallRules: [{BAF6EF6F-C0B0-4CE0-88F2-508D2DCF2D65}] => (Block) E:\wizardsofthecoast\mtgarena\mtga.exe => No File FirewallRules: [TCP Query User{5CDAF4DE-5E43-427D-9F9E-C5521099AEC9}C:\program files (x86)\neverwinter_en\neverwinter\live\x64\gameclient.exe] => (Allow) C:\program files (x86)\neverwinter_en\neverwinter\live\x64\gameclient.exe => No File FirewallRules: [UDP Query User{DDEB95E8-722F-4620-BADC-CA709D62E505}C:\program files (x86)\neverwinter_en\neverwinter\live\x64\gameclient.exe] => (Allow) C:\program files (x86)\neverwinter_en\neverwinter\live\x64\gameclient.exe => No File FirewallRules: [TCP Query User{CB8E3F13-BBF4-4BFA-95E4-32B574A71861}E:\steamlibrary\steamapps\common\outlaws of the old west\outlaws\binaries\win64\outlaws-win64-shipping.exe] => (Allow) E:\steamlibrary\steamapps\common\outlaws of the old west\outlaws\binaries\win64\outlaws-win64-shipping.exe => No File FirewallRules: [UDP Query User{3B392D1D-3612-45CB-8019-E0970B971627}E:\steamlibrary\steamapps\common\outlaws of the old west\outlaws\binaries\win64\outlaws-win64-shipping.exe] => (Allow) E:\steamlibrary\steamapps\common\outlaws of the old west\outlaws\binaries\win64\outlaws-win64-shipping.exe => No File FirewallRules: [{2ADED551-50E6-4190-AA7F-447F2E3919B2}] => (Block) E:\steamlibrary\steamapps\common\outlaws of the old west\outlaws\binaries\win64\outlaws-win64-shipping.exe => No File FirewallRules: [{08068A89-483C-486F-BBCE-54D65608B131}] => (Block) E:\steamlibrary\steamapps\common\outlaws of the old west\outlaws\binaries\win64\outlaws-win64-shipping.exe => No File FirewallRules: [TCP Query User{62F461DA-DCB8-43FB-B2C4-D69091F0DDF8}E:\steamlibrary\steamapps\common\armored warfare\gamecenter\gamecenter.exe] => (Allow) E:\steamlibrary\steamapps\common\armored warfare\gamecenter\gamecenter.exe => No File FirewallRules: [UDP Query User{85194AFD-3C0B-4946-B121-7722EA4502CD}E:\steamlibrary\steamapps\common\armored warfare\gamecenter\gamecenter.exe] => (Allow) E:\steamlibrary\steamapps\common\armored warfare\gamecenter\gamecenter.exe => No File FirewallRules: [TCP Query User{F14C6EF3-EEF2-4FA1-B352-55B588BC8DBE}E:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe] => (Allow) E:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe => No File FirewallRules: [UDP Query User{32C2F661-DD3B-4E55-972E-01DB3D9C4F45}E:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe] => (Allow) E:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe => No File FirewallRules: [TCP Query User{D52A565B-83EF-44EE-8420-F88FD28BEC79}E:\mygames\mtga\mtga.exe] => (Allow) E:\mygames\mtga\mtga.exe => No File FirewallRules: [UDP Query User{8EEA7DAF-C47C-4976-9830-CBB83FA3B1DF}E:\mygames\mtga\mtga.exe] => (Allow) E:\mygames\mtga\mtga.exe => No File FirewallRules: [{B5D8C21B-9E05-4230-A50D-8AF302775F78}] => (Block) E:\mygames\mtga\mtga.exe => No File FirewallRules: [{DE1B0185-6912-4DFE-B33E-49631B90887C}] => (Block) E:\mygames\mtga\mtga.exe => No File FirewallRules: [{F0DCA2ED-FC9B-4E3F-AF39-354BB261DB8A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{92EBEE35-DEE7-4762-AFF6-C5BA46B79EEA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{D00EB349-1CC6-4A7B-89E6-A80A81DE085A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{1E620503-7912-4A1F-B8AD-2251468F89E9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [TCP Query User{B292BECB-1BF6-4A93-AD96-BA7242172F0C}C:\users\gaming rig\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\gaming rig\appdata\roaming\zoom\bin\zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [UDP Query User{AA69FAFC-C3EC-48DC-9D16-57E70E4342EF}C:\users\gaming rig\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\gaming rig\appdata\roaming\zoom\bin\zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [TCP Query User{48072047-2013-4531-AD31-A008A106D56F}C:\users\gaming rig\appdata\local\discord\app-0.0.311\discord.exe] => (Allow) C:\users\gaming rig\appdata\local\discord\app-0.0.311\discord.exe (Discord Inc. -> Discord Inc.) FirewallRules: [UDP Query User{A1D03D7A-853F-4EF4-91BA-FC072F6D091D}C:\users\gaming rig\appdata\local\discord\app-0.0.311\discord.exe] => (Allow) C:\users\gaming rig\appdata\local\discord\app-0.0.311\discord.exe (Discord Inc. -> Discord Inc.) FirewallRules: [{69CAB175-D2EA-4B91-B48D-6A3ED14DF8D8}] => (Allow) E:\SteamLibrary\steamapps\common\XERA\XERA_Launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [{19949CD5-42AB-4A3A-B51A-C403DAF2BC8D}] => (Allow) E:\SteamLibrary\steamapps\common\XERA\XERA_Launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [TCP Query User{55E0129A-A765-4CED-8022-B7496640DB1C}E:\steamlibrary\steamapps\common\xera\xera\binaries\win64\xera-win64-shipping.exe] => (Allow) E:\steamlibrary\steamapps\common\xera\xera\binaries\win64\xera-win64-shipping.exe (Spotted Kiwi Interactive) [File not signed] FirewallRules: [UDP Query User{907FD2E7-8DE7-4A1F-8A20-EA2E95EA37B9}E:\steamlibrary\steamapps\common\xera\xera\binaries\win64\xera-win64-shipping.exe] => (Allow) E:\steamlibrary\steamapps\common\xera\xera\binaries\win64\xera-win64-shipping.exe (Spotted Kiwi Interactive) [File not signed] FirewallRules: [TCP Query User{7B8ECFAF-39C9-404B-AC02-E49D34069A06}C:\users\gaming rig\appdata\local\discord\app-1.0.9004\discord.exe] => (Allow) C:\users\gaming rig\appdata\local\discord\app-1.0.9004\discord.exe => No File FirewallRules: [UDP Query User{BBF36B20-3F02-4BAD-A9BD-94765A4FBF5A}C:\users\gaming rig\appdata\local\discord\app-1.0.9004\discord.exe] => (Allow) C:\users\gaming rig\appdata\local\discord\app-1.0.9004\discord.exe => No File FirewallRules: [TCP Query User{D1F4A376-52C9-4B7C-9340-C410A601DAFB}C:\users\gaming rig\appdata\local\discord\app-1.0.9005\discord.exe] => (Allow) C:\users\gaming rig\appdata\local\discord\app-1.0.9005\discord.exe (Discord Inc. -> Discord Inc.) FirewallRules: [UDP Query User{D8947592-FB4D-43D8-8813-6342D91AE9EE}C:\users\gaming rig\appdata\local\discord\app-1.0.9005\discord.exe] => (Allow) C:\users\gaming rig\appdata\local\discord\app-1.0.9005\discord.exe (Discord Inc. -> Discord Inc.) FirewallRules: [TCP Query User{71C883FC-BCAF-47CF-92DB-CDE425341EB7}C:\users\gaming rig\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\gaming rig\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [UDP Query User{E18DDBA7-BAAC-48B2-A4FC-6F309495A35D}C:\users\gaming rig\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\gaming rig\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{EFBFC547-8397-415C-9BFD-2FB52BCB66C0}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{A9F9DF09-9BC0-49FC-9581-9751C574400C}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\107.0.1418.26\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{4E00636F-25B7-401D-AACF-675F500BFE88}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [{942C5078-DB7E-49C4-915C-1F84560EFD1B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.89.3403.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{7F365B37-07EF-4675-A3BC-C7FA28BE1DE7}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.89.3403.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{5B0AC151-F91E-41D8-9530-3A13F4DE2842}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.89.3403.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{0BFB1D0D-7C02-4499-A758-7BFC8D4560A5}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.89.3403.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{4F63922D-662E-48F3-9CBF-151A6327E668}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Restore Points ========================= 24-10-2022 15:13:04 Scheduled Checkpoint 02-11-2022 09:29:54 Installed Installing ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (11/02/2022 09:48:21 AM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Cannot find object or property. Error: (11/02/2022 09:48:21 AM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Cannot find object or property. Error: (11/02/2022 09:48:21 AM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Cannot find object or property. Error: (11/02/2022 09:48:21 AM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Cannot find object or property. Error: (11/02/2022 09:48:19 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Creative Cloud.exe, version: 5.8.0.592, time stamp: 0x62d24b9f Faulting module name: ntdll.dll, version: 10.0.19041.2130, time stamp: 0xb5ced1c6 Exception code: 0xc000000d Fault offset: 0x0000000000112684 Faulting process id: 0x3368 Faulting application start time: 0x01d8eed284dc6c2f Faulting application path: C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll Report Id: fb9fba21-71dd-40ae-86d0-740e7d8f932a Faulting package full name: Faulting package-relative application ID: Error: (11/02/2022 09:48:17 AM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Cannot find object or property. Error: (11/02/2022 09:48:17 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Creative Cloud.exe, version: 5.8.0.592, time stamp: 0x62d24b9f Faulting module name: ntdll.dll, version: 10.0.19041.2130, time stamp: 0xb5ced1c6 Exception code: 0xc000000d Fault offset: 0x0000000000112684 Faulting process id: 0x3368 Faulting application start time: 0x01d8eed284dc6c2f Faulting application path: C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll Report Id: 42096a37-9771-46b7-8ec9-5289e53685f0 Faulting package full name: Faulting package-relative application ID: Error: (11/02/2022 09:41:46 AM) (Source: DbxSvc) (EventID: 281) (User: ) Description: CertFindCertificateInStore failed with: (-2146885628) Cannot find object or property. System errors: ============= Error: (11/02/2022 09:46:54 AM) (Source: DCOM) (EventID: 10010) (User: LARRYGDESKTOP) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (11/02/2022 09:46:54 AM) (Source: DCOM) (EventID: 10010) (User: LARRYGDESKTOP) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (11/02/2022 09:46:54 AM) (Source: DCOM) (EventID: 10010) (User: LARRYGDESKTOP) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (11/02/2022 09:46:54 AM) (Source: DCOM) (EventID: 10010) (User: LARRYGDESKTOP) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (11/02/2022 09:46:54 AM) (Source: DCOM) (EventID: 10010) (User: LARRYGDESKTOP) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (11/02/2022 09:46:54 AM) (Source: DCOM) (EventID: 10010) (User: LARRYGDESKTOP) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (11/02/2022 09:46:54 AM) (Source: DCOM) (EventID: 10010) (User: LARRYGDESKTOP) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (11/02/2022 09:46:54 AM) (Source: DCOM) (EventID: 10010) (User: LARRYGDESKTOP) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Windows Defender: ================ Date: 2022-11-02 10:41:28 Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win64/Fgdump&threatid=2147637311&enterprise=0 Name: HackTool:Win64/Fgdump Severity: High Category: Tool Path: containerfile:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso; file:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso->pool\non-free\w\windows-binaries\windows-binaries_0.6.9_all.deb->data.tar.xz->(xz)->./usr/share/windows-resources/binaries/fgdump/fgdump.exe->[RSRCEmb]#2; file:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso->pool\non-free\w\windows-binaries\windows-binaries_0.6.9_all.deb->data.tar.xz->(xz)->./usr/share/windows-resources/binaries/fgdump/fgdump.exe->[RSRCEmb]#4; file:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso->pool\non-free\w\windows-binaries\windows-binaries_0.6.9_all.deb->data.tar.xz->(xz)->./usr/share/windows-resources/binaries/fgdump/fgdump.exe->[RSRCEmb]#7 Detection Origin: Local machine Detection Type: Concrete Detection Source: User Process Name: Unknown Security intelligence Version: AV: 1.377.1191.0, AS: 1.377.1191.0, NIS: 1.377.1191.0 Engine Version: AM: 1.1.19700.3, NIS: 1.1.19700.3 Date: 2022-11-02 10:41:28 Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Fgdump&threatid=2147637310&enterprise=0 Name: HackTool:Win32/Fgdump Severity: High Category: Tool Path: containerfile:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso; file:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso->pool\non-free\w\windows-binaries\windows-binaries_0.6.9_all.deb->data.tar.xz->(xz)->./usr/share/windows-resources/binaries/fgdump/fgdump.exe->(VFS:fgexec.exe#3); file:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso->pool\non-free\w\windows-binaries\windows-binaries_0.6.9_all.deb->data.tar.xz->(xz)->./usr/share/windows-resources/binaries/fgdump/fgdump.exe->(VFS:lsremora.dll#2); file:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso->pool\non-free\w\windows-binaries\windows-binaries_0.6.9_all.deb->data.tar.xz->(xz)->./usr/share/windows-resources/binaries/fgdump/fgdump.exe->(VFS:pwdump.exe); file:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso->pool\non-free\w\windows-binaries\windows-binaries_0.6.9_all.deb->data.tar.xz->(xz)->./usr/share/windows-resources Detection Origin: Local machine Detection Type: Concrete Detection Source: User Process Name: Unknown Security intelligence Version: AV: 1.377.1191.0, AS: 1.377.1191.0, NIS: 1.377.1191.0 Engine Version: AM: 1.1.19700.3, NIS: 1.1.19700.3 Date: 2022-11-02 10:41:28 Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Perl/NiktoSanner.A&threatid=2147794255&enterprise=0 Name: HackTool:Perl/NiktoSanner.A Severity: High Category: Tool Path: containerfile:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso; file:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso->pool\non-free\n\nikto\nikto_2.1.6+git20190310-0kali3_all.deb->data.tar.xz->(xz)->./var/lib/nikto/nikto.pl Detection Origin: Local machine Detection Type: Concrete Detection Source: User Process Name: Unknown Security intelligence Version: AV: 1.377.1191.0, AS: 1.377.1191.0, NIS: 1.377.1191.0 Engine Version: AM: 1.1.19700.3, NIS: 1.1.19700.3 Date: 2022-11-02 10:41:28 Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Python/WeevelyShell.R!MTB&threatid=2147761520&enterprise=0 Name: HackTool:Python/WeevelyShell.R!MTB Severity: High Category: Tool Path: containerfile:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso; file:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso->pool\main\w\weevely\weevely_4.0.1-1_all.deb->data.tar.xz->(xz)->./usr/share/weevely/weevely.py Detection Origin: Local machine Detection Type: Concrete Detection Source: User Process Name: Unknown Security intelligence Version: AV: 1.377.1191.0, AS: 1.377.1191.0, NIS: 1.377.1191.0 Engine Version: AM: 1.1.19700.3, NIS: 1.1.19700.3 Date: 2022-11-02 10:41:28 Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Python/WeevelyShell.RT!MTB&threatid=2147761521&enterprise=0 Name: HackTool:Python/WeevelyShell.RT!MTB Severity: High Category: Tool Path: containerfile:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso; file:_C:\$Recycle.Bin\S-1-5-21-1194324949-2680677275-2362750293-1001\$R275J22.iso->pool\main\w\weevely\weevely_4.0.1-1_all.deb->data.tar.xz->(xz)->./usr/share/weevely/core/terminal.py Detection Origin: Local machine Detection Type: Concrete Detection Source: User Process Name: Unknown Security intelligence Version: AV: 1.377.1191.0, AS: 1.377.1191.0, NIS: 1.377.1191.0 Engine Version: AM: 1.1.19700.3, NIS: 1.1.19700.3  CodeIntegrity: =============== Date: 2022-11-02 12:25:50 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== BIOS: American Megatrends Inc. 2701 03/24/2016 Motherboard: ASUSTeK COMPUTER INC. M5A97 LE R2.0 Processor: AMD FX(tm)-6300 Six-Core Processor Percentage of memory in use: 66% Total physical RAM: 8093.71 MB Available physical RAM: 2674.6 MB Total Virtual: 12957.71 MB Available Virtual: 4634.98 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:464.38 GB) (Free:371.02 GB) (Model: WDC WDS500G1B0A-00H9H0) NTFS Drive e: (Data Drive) (Fixed) (Total:698.63 GB) (Free:611.68 GB) (Model: ST9750420AS) NTFS \\?\Volume{dbe989dd-7299-4615-9117-cdf83205e982}\ (Recovery) (Fixed) (Total:0.44 GB) (Free:0.42 GB) NTFS \\?\Volume{3a8c1102-8b0f-441f-8775-d39ff24b4ca1}\ () (Fixed) (Total:0.83 GB) (Free:0.4 GB) NTFS \\?\Volume{81cae946-193f-4c2f-a46d-283e8e7d50fd}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Protective MBR) (Size: 465.8 GB) (Disk ID: 00000000) Partition: GPT. ========================================================== Disk: 1 (MBR Code: Windows 7/8/10) (Size: 698.6 GB) (Disk ID: F6E9914B) Partition 1: (Not Active) - (Size=698.6 GB) - (Type=07 NTFS) ==================== End of Addition.txt =======================