HKU\S-1-5-21-3252700674-1244316876-1502611229-1001\...\Run: [EpicGamesLauncher] => "E:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent (No File) HKU\S-1-5-21-3252700674-1244316876-1502611229-1004\...\Run: [EpicGamesLauncher] => "E:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent (No File) Task: {12B8B342-EFBA-430F-AA8D-2F2C467679E1} - System32\Tasks\Lenovo\Vantage\Schedule\NotificationCenter => C:\Program Files (x86)\Lenovo\VantageService\3.13.72.0\ScheduleEventAction.exe NotificationCenter (No File) Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File) S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X] FirewallRules: [UDP Query User{1A3E5AC6-B5A8-44E0-A501-581539DC582A}D:\program files (x86)\starcraft ii\versions\base88500\sc2_x64.exe] => (Allow) D:\program files (x86)\starcraft ii\versions\base88500\sc2_x64.exe => No File FirewallRules: [TCP Query User{506A7352-1E68-449F-9F9D-8A0BCCD396FA}D:\program files (x86)\starcraft ii\versions\base88500\sc2_x64.exe] => (Allow) D:\program files (x86)\starcraft ii\versions\base88500\sc2_x64.exe => No File FirewallRules: [UDP Query User{7F8CFAF2-022E-45E5-97FD-10062BB23A24}C:\users\tehke\appdata\local\discord\app-1.0.9006\discord.exe] => (Block) C:\users\tehke\appdata\local\discord\app-1.0.9006\discord.exe => No File FirewallRules: [TCP Query User{C9738C52-88A9-4057-B538-DB1029FC14EC}C:\users\tehke\appdata\local\discord\app-1.0.9006\discord.exe] => (Block) C:\users\tehke\appdata\local\discord\app-1.0.9006\discord.exe => No File FirewallRules: [{8607FB6D-B4F5-4BE5-9489-C28D3E67A45C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.870.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{BF38E6A2-AA98-4E91-9CF2-6C74E19B5BC2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.870.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{B3481C4C-EB20-4EAB-970B-E3B63CB06609}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.870.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{2C54E203-A60B-4DF5-93F2-D95EEECFD8E3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.870.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{B41B4130-FD5C-4A1D-BA2B-B0A6FBB79E6B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.870.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{DD557009-79A6-40B6-9C27-A02338ED5145}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.870.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{9245A4C2-C00F-4986-806C-F0FD1DD2A6F8}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.870.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{6E5C27C0-B0F0-47DF-8459-98E3672062A3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.870.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [UDP Query User{DF8CC82D-2305-4CBC-87EF-D3806428EB2A}E:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) E:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe => No File FirewallRules: [TCP Query User{89AE0F41-FB3E-42BE-A413-EB0CCF7D2175}E:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) E:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe => No File FirewallRules: [{5D83637E-6C07-42AB-B47F-751A57E5B3BF}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.188.612.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{369BB4DB-21D1-49C0-BC49-BE8685E8520E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.188.612.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{C082DF4D-F00E-455B-8664-715D9D6D7C9A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.188.612.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{E184D41D-0E6D-4BD5-B5AB-9526BBC13FE6}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.188.612.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{E587663F-DD33-4B66-B750-078B80BAF80F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.188.612.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{B3D919A0-FF41-4ECD-8784-2B7076DDC234}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.188.612.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{E6EE2708-3A1F-40BF-8524-9F07FC7EE515}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.188.612.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [{05E7A3FE-6AED-4D04-A7E2-E34B626F5D32}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.188.612.0_x86__zpdnekdrzrea0\Spotify.exe => No File FirewallRules: [UDP Query User{A7C56748-FF1D-4B71-ACA7-526CAE9A2275}E:\games\nba 2k22\nba2k22.exe] => (Block) E:\games\nba 2k22\nba2k22.exe => No File FirewallRules: [TCP Query User{53FCDA60-909C-4198-A241-8103012EE145}E:\games\nba 2k22\nba2k22.exe] => (Block) E:\games\nba 2k22\nba2k22.exe => No File FirewallRules: [UDP Query User{77BAA295-67B2-41C7-B515-D44851CA66C3}E:\games\flight simulator\microsoft flight simulator\flightsimulator.exe] => (Allow) E:\games\flight simulator\microsoft flight simulator\flightsimulator.exe => No File FirewallRules: [TCP Query User{D8B2FE13-B8B5-423D-9271-6E8A17919E5C}E:\games\flight simulator\microsoft flight simulator\flightsimulator.exe] => (Allow) E:\games\flight simulator\microsoft flight simulator\flightsimulator.exe => No File FirewallRules: [UDP Query User{1AADE3E5-8A0F-44AD-9A1F-EBB34F70FE20}D:\program files (x86)\starcraft ii\versions\base87702\sc2_x64.exe] => (Allow) D:\program files (x86)\starcraft ii\versions\base87702\sc2_x64.exe => No File FirewallRules: [TCP Query User{51406327-309B-4553-BBA6-ABDC6BD59097}D:\program files (x86)\starcraft ii\versions\base87702\sc2_x64.exe] => (Allow) D:\program files (x86)\starcraft ii\versions\base87702\sc2_x64.exe => No File FirewallRules: [{902E6672-3F5A-43F5-8528-E3A0E7E8C50A}] => (Allow) C:\Users\tehke\AppData\Roaming\uTorrent\uTorrent.exe => No File FirewallRules: [{B89559FD-604A-4797-91C7-7B53E1995124}] => (Allow) C:\Users\tehke\AppData\Roaming\uTorrent\uTorrent.exe => No File FirewallRules: [{A190F41B-F640-442E-9109-B30BBF9951B7}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe => No File FirewallRules: [TCP Query User{9B4843FF-1899-4824-B554-2E84E07FE645}D:\program files (x86)\starcraft ii\versions\base89720\sc2_x64.exe] => (Block) D:\program files (x86)\starcraft ii\versions\base89720\sc2_x64.exe => No File FirewallRules: [UDP Query User{C1871B4D-DF63-4190-A09F-977104BDAD02}D:\program files (x86)\starcraft ii\versions\base89720\sc2_x64.exe] => (Block) D:\program files (x86)\starcraft ii\versions\base89720\sc2_x64.exe => No File FirewallRules: [{26F35759-38CF-46AD-BCCA-456A61FC9FD8}] => (Allow) C:\Program Files\Tencent\WeChat\WeChatBrowser.exe => No File FirewallRules: [{C451A51B-AE8E-4459-9CF5-7E191068290C}] => (Allow) C:\Program Files\Tencent\WeChat\WeChatPlayer.exe => No File CMD: DISM /Online /Cleanup-Image /RestoreHealth CMD: SFC /scannow CMD: findstr /c:"[SR]" \windows\logs\cbs\cbs.log CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i" Reboot: