So I was given a piece of software from a friend who I thought knew what they where doing.. long story short I clicked on things I should of not and got my PC riddled with Trojans and such..
I started an extensive cleaning process and will some day soon wipe everything that is connected to the PC but right now I need to use it for work and con not, things seem to be OK, malwarebytes finds no malware and Avira finds no viruses now.. but every 6 hours or so I get a notification from Malwarebytes that it is blocking powershell form visiting various sites
As requested in the guide here is FRST.txt
Spoiler
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-07-2017
Ran by Twitchi (administrator) on FRAMEZILLA (11-07-2017 13:41:52)
Running from C:\Users\Twitchi\Desktop
Loaded Profiles: Twitchi (Available Profiles: Twitchi & DefaultAppPool)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Hammer & Chisel, Inc.) C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\Discord.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Corsair Components, Inc.) C:\Program Files (x86)\Corsair\Corsair Utility Engine\CUE.exe
(Hammer & Chisel, Inc.) C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\Discord.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Hammer & Chisel, Inc.) C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\Discord.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avcenter.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\Adobe Premiere Pro.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\32\dynamiclinkmanager.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\32\Adobe QT32 Server.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10038304 2010-02-02] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-04-28] (Adobe Systems Incorporated)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [97512 2017-06-08] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [918008 2017-06-18] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3486520 2017-06-26] (Dropbox, Inc.)
HKLM-x32\...\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [75776 2016-08-10] ()
HKLM-x32\...\Run: [Corsair Utility Engine] => C:\Program Files (x86)\Corsair\Corsair Utility Engine\CUE.exe [18299088 2017-05-26] (Corsair Components, Inc.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3062048 2017-07-06] (Valve Corporation)
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9288408 2016-12-06] (Piriform Ltd)
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [OneDrive] => "C:\Users\Twitchi\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [Discord] => C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.)
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [afwhgsid1je] => "C:\Users\Twitchi\AppData\Roaming\u4142ebbq1s\5j5lzk1wsnu.exe"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [4uccdotqxhp] => "C:\Users\Twitchi\AppData\Roaming\hfpcslo54jz\ql02ktelgos.exe"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [aeanjqjos20] => "C:\Users\Twitchi\AppData\Roaming\bgsuk4oce02\2nku4gth3nu.exe"
GroupPolicy: Restriction - Chrome <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1ede3236-6b46-42cd-acfa-e9ebdf477ff0}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{abd7ab2e-3df7-4618-a449-84877c40d9d1}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{dae9345e-a687-48a6-a34d-2e426f7186f8}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1265003007-341673947-2575449671-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-04-25] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-25] (Oracle Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default [2017-07-11]
FF user.js: detected! => C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\user.js [2017-06-29]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\KQADxXuG.default -> DuckDuckGo
FF Homepage: Mozilla\Firefox\Profiles\KQADxXuG.default -> hxxps://duckduckgo.com/
FF Extension: (Avira Browser Safety) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\[email protected] [2017-06-06]
FF Extension: (Flip or Rotate Image) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\[email protected] [2017-03-27]
FF Extension: (Html5 Youtube Video Speed Controller) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\[email protected] [2016-04-11]
FF Extension: (Strict Pop-up Blocker) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\[email protected] [2016-09-12]
FF Extension: (uBlock Origin) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\[email protected] [2017-07-09]
FF Extension: (LeechBlock) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\{a95d8332-e4b4-6e7f-98ac-20b733364387} [2017-03-20]
FF Extension: (Video DownloadHelper) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2017-05-09]
FF Extension: (Always on Top) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\{E6C93316-271E-4b3d-8D7E-FE11B4350AEB}.xpi [2016-07-28]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-17] ()
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-25] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-17] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-01] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1265003007-341673947-2575449671-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Twitchi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-04-19] (Unity Technologies ApS)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\firefox.js [2017-07-09]
Chrome:
=======
CHR Profile: C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default [2017-06-25]
CHR Extension: (Google Slides) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-06-22]
CHR Extension: (Google Docs) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-22]
CHR Extension: (Google Drive) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-22]
CHR Extension: (YouTube) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-22]
CHR Extension: (Google Sheets) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-22]
CHR Extension: (Google Docs Offline) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-06-24]
CHR Extension: (Gmail) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-22]
CHR Extension: (Chrome Media Router) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-25]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AdBlockerService; C:\Program Files (x86)\AdBlocker\AdBlockerService.exe [110080 2017-04-11] (Star Line) [File not signed]
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1128432 2017-06-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [490968 2017-06-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [490968 2017-06-18] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1524216 2017-06-18] (Avira Operations GmbH & Co. KG)
S2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [356256 2017-06-08] (Avira Operations GmbH & Co. KG)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1465352 2017-02-11] ()
S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2013-11-29] (www.BitComet.com)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-06-07] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-06-07] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [49992 2017-06-26] (Dropbox, Inc.)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [383016 2017-06-07] (EasyAntiCheat Ltd)
S4 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2016-08-10] (Freemake) [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462784 2017-02-23] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [450168 2017-06-21] (NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10351856 2016-12-15] (TeamViewer GmbH)
R2 VIAKaraokeService; C:\WINDOWS\system32\viakaraokesrv.exe [36504 2015-06-22] (VIA Technologies, Inc.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-09-06] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-28] (Microsoft Corporation)
S4 1fcf926529d07bef7da3dc8418c67946; "C:\Program Files\1fcf926529d07bef7da3dc8418c67946\79022675ad2cc919f1f92953446ac97f.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 avdevprot; C:\WINDOWS\System32\DRIVERS\avdevprot.sys [60920 2017-06-18] (Avira Operations GmbH & Co. KG)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [167504 2017-06-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [164824 2017-06-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [44488 2017-03-02] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [88488 2017-03-02] (Avira Operations GmbH & Co. KG)
R3 CMUSBDAC; C:\WINDOWS\system32\DRIVERS\CMUSBDAC.sys [3792904 2016-11-30] (C-MEDIA)
R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [45016 2017-05-16] (Corsair)
R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [21976 2017-05-16] (Corsair)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77376 2017-06-27] ()
S3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2017-04-06] (Logitech Inc.)
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [188352 2017-07-09] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [101784 2017-07-11] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [45472 2017-07-11] (Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [253856 2017-07-11] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [93600 2017-07-11] (Malwarebytes)
R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] ()
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_2a6e383a1adc0e24\nvlddmkm.sys [14569528 2017-02-24] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-06-21] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48248 2017-06-21] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57976 2017-06-21] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
R3 SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation)
S0 SI3132; C:\WINDOWS\System32\drivers\SI3132.sys [90664 2007-10-03] (Silicon Image, Inc)
R0 SiFilter; C:\WINDOWS\System32\drivers\SiWinAcc.sys [22056 2007-10-03] (Silicon Image, Inc)
R0 SiRemFil; C:\WINDOWS\System32\drivers\SiRemFil.sys [17448 2007-10-03] (Silicon Image, Inc)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-11 13:41 - 2017-07-11 13:43 - 00019624 _____ C:\Users\Twitchi\Desktop\FRST.txt
2017-07-11 13:41 - 2017-07-11 13:41 - 00000000 ____D C:\FRST
2017-07-11 13:40 - 2017-07-11 13:40 - 02437120 _____ (Farbar) C:\Users\Twitchi\Desktop\FRST64.exe
2017-07-09 20:42 - 2017-07-11 12:43 - 00093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-07-09 20:42 - 2017-07-11 10:37 - 00101784 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-07-09 20:42 - 2017-07-11 10:36 - 00045472 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-07-09 20:42 - 2017-07-11 10:34 - 00253856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-07-09 20:42 - 2017-07-09 20:42 - 00188352 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-07-09 20:42 - 2017-07-09 20:42 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-07-09 20:42 - 2017-07-09 20:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-07-09 20:42 - 2017-07-09 20:42 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-07-09 20:42 - 2017-07-09 20:42 - 00000000 ____D C:\Program Files\Malwarebytes
2017-07-09 20:42 - 2017-06-27 12:06 - 00077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-07-09 20:13 - 2017-07-09 20:13 - 00000258 __RSH C:\Users\Twitchi\ntuser.pol
2017-07-09 17:41 - 2017-07-09 17:41 - 00031478 _____ C:\Users\Twitchi\AppData\Local\recently-used.xbel
2017-07-09 17:28 - 2017-07-09 17:28 - 00000000 ____D C:\Users\Twitchi\Desktop\tmp
2017-07-09 13:17 - 2017-07-09 13:17 - 00003764 _____ C:\WINDOWS\System32\Tasks\updater
2017-07-09 13:13 - 2017-07-09 13:19 - 00000000 ____D C:\Program Files (x86)\AdBlocker
2017-07-09 13:13 - 2017-07-09 13:13 - 00016802 _____ C:\WINDOWS\System32\Tasks\Star-ToAx24
2017-07-09 13:13 - 2017-07-09 13:13 - 00000000 ____D C:\Users\Public\Thunder Network
2017-07-09 13:13 - 2017-07-05 14:22 - 02017280 ___SH (Micrasaft Carparation) C:\WINDOWS\C_02iu47.dat
2017-07-09 13:12 - 2017-07-09 21:16 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\devnull
2017-07-09 13:12 - 2017-07-09 13:17 - 00003284 _____ C:\WINDOWS\System32\Tasks\1fcf926529d07bef7da3dc8418c67946
2017-07-09 13:12 - 2017-07-09 13:17 - 00000000 ____D C:\WINDOWS\SysWOW64\SSL
2017-07-09 13:12 - 2017-07-09 13:13 - 00006264 __RSH C:\ProgramData\ntuser.pol
2017-07-09 13:11 - 2017-07-10 19:07 - 00000000 ____D C:\ProgramData\WindowsErrorReporting
2017-07-09 13:11 - 2017-07-09 20:58 - 00000000 ____D C:\Program Files (x86)\0m3vi0hqddj
2017-07-09 13:11 - 2017-07-09 13:13 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\Easeware
2017-07-09 13:10 - 2017-07-09 13:10 - 00000000 ____D C:\Users\Twitchi\AppData\Local\CrashRpt
2017-07-09 13:06 - 2017-07-09 13:20 - 00000000 ____D C:\Program Files\KMSpico
2017-07-09 13:05 - 2017-07-09 13:12 - 00000000 ____D C:\Users\Twitchi\AppData\Local\AdvinstAnalytics
2017-07-09 13:04 - 2017-07-09 13:04 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\RenewSoftware.com
2017-07-08 20:49 - 2017-07-08 20:49 - 00000000 ____D C:\Users\Twitchi\AppData\LocalLow\Pill Bug Interactive
2017-07-08 20:42 - 2017-07-08 20:42 - 00000222 _____ C:\Users\Twitchi\Desktop\Intelligent Design An Evolutionary Sandbox.url
2017-07-08 12:17 - 2017-07-08 12:23 - 00000000 ___HD C:\$WINDOWS.~BT
2017-07-07 14:30 - 2017-07-07 14:30 - 00000000 ___SD C:\WINDOWS\UpdateAssistantV2
2017-07-07 14:16 - 2017-04-21 22:53 - 00029376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aspnet_counters.dll
2017-07-07 14:16 - 2017-04-21 22:53 - 00018600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr100_clr0400.dll
2017-07-07 14:16 - 2017-04-21 22:50 - 00030912 _____ (Microsoft Corporation) C:\WINDOWS\system32\aspnet_counters.dll
2017-07-07 14:16 - 2017-04-21 22:50 - 00018592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr100_clr0400.dll
2017-07-07 14:16 - 2017-04-11 19:27 - 00993632 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll
2017-07-07 14:16 - 2017-04-11 19:27 - 00690008 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp120_clr0400.dll
2017-07-07 14:16 - 2017-03-15 19:15 - 00987840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll
2017-07-07 14:16 - 2017-03-15 19:15 - 00485576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp120_clr0400.dll
2017-07-07 14:11 - 2017-06-03 11:50 - 00315744 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-07-07 14:11 - 2017-06-03 11:50 - 00192856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2017-07-07 14:11 - 2017-06-03 11:16 - 00279904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-07-07 14:11 - 2017-06-03 11:14 - 01564512 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 01214816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00629088 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00544096 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00334176 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00233824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00136024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00096608 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-07-07 14:11 - 2017-06-03 11:14 - 00034648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-07-07 14:11 - 2017-06-03 11:11 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-07-07 14:11 - 2017-06-03 11:11 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-07-07 14:11 - 2017-06-03 11:09 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-07-07 14:11 - 2017-06-03 11:08 - 07783256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-07-07 14:11 - 2017-06-03 11:06 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-07-07 14:11 - 2017-06-03 11:01 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-07-07 14:11 - 2017-06-03 10:59 - 01181024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2017-07-07 14:11 - 2017-06-03 10:59 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-07-07 14:11 - 2017-06-03 10:59 - 00118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-07-07 14:11 - 2017-06-03 10:58 - 00340832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-07-07 14:11 - 2017-06-03 10:55 - 00780640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-07-07 14:11 - 2017-06-03 10:54 - 00187232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-07-07 14:11 - 2017-06-03 10:53 - 00404824 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-07-07 14:11 - 2017-06-03 10:52 - 01021784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2017-07-07 14:11 - 2017-06-03 10:52 - 00607072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2017-07-07 14:11 - 2017-06-03 10:52 - 00111968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2017-07-07 14:11 - 2017-06-03 10:51 - 02187104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-07-07 14:11 - 2017-06-03 10:51 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-07-07 14:11 - 2017-06-03 10:50 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-07-07 14:11 - 2017-06-03 10:50 - 00381792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-07-07 14:11 - 2017-06-03 10:49 - 20967840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-07-07 14:11 - 2017-06-03 10:49 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-07-07 14:11 - 2017-06-03 10:49 - 00509280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-07-07 14:11 - 2017-06-03 10:48 - 01112416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2017-07-07 14:11 - 2017-06-03 10:48 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-07-07 14:11 - 2017-06-03 10:48 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-07-07 14:11 - 2017-06-03 10:48 - 00857952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2017-07-07 14:11 - 2017-06-03 10:48 - 00148832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2017-07-07 14:11 - 2017-06-03 10:45 - 22220864 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-07-07 14:11 - 2017-06-03 10:44 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-07-07 14:11 - 2017-06-03 10:44 - 01412640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-07-07 14:11 - 2017-06-03 10:44 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-07-07 14:11 - 2017-06-03 10:40 - 01566552 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-07-07 14:11 - 2017-06-03 10:40 - 00628552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-07-07 14:11 - 2017-06-03 10:39 - 05686272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-07-07 14:11 - 2017-06-03 10:39 - 02532192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-07-07 14:11 - 2017-06-03 10:39 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-07-07 14:11 - 2017-06-03 10:33 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-07-07 14:11 - 2017-06-03 10:32 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-07-07 14:11 - 2017-06-03 10:31 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2017-07-07 14:11 - 2017-06-03 10:31 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-07-07 14:11 - 2017-06-03 10:28 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-07-07 14:11 - 2017-06-03 10:28 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edputil.dll
2017-07-07 14:11 - 2017-06-03 10:26 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-07-07 14:11 - 2017-06-03 10:26 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBrokerUI.dll
2017-07-07 14:11 - 2017-06-03 10:23 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-07-07 14:11 - 2017-06-03 10:22 - 07217152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-07-07 14:11 - 2017-06-03 10:22 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2017-07-07 14:11 - 2017-06-03 10:22 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcorehc.dll
2017-07-07 14:11 - 2017-06-03 10:22 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2017-07-07 14:11 - 2017-06-03 10:20 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2017-07-07 14:11 - 2017-06-03 10:19 - 01164288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe
2017-07-07 14:11 - 2017-06-03 10:18 - 22569984 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-07-07 14:11 - 2017-06-03 10:16 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2017-07-07 14:11 - 2017-06-03 10:16 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-07-07 14:11 - 2017-06-03 10:16 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-07-07 14:11 - 2017-06-03 10:15 - 19414016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-07-07 14:11 - 2017-06-03 10:15 - 18364928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-07-07 14:11 - 2017-06-03 10:15 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-07-07 14:11 - 2017-06-03 10:15 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-07-07 14:11 - 2017-06-03 10:15 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-07-07 14:11 - 2017-06-03 10:14 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-07-07 14:11 - 2017-06-03 10:14 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-07-07 14:11 - 2017-06-03 10:14 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-07-07 14:11 - 2017-06-03 10:14 - 00045056 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-07-07 14:11 - 2017-06-03 10:12 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdProxy.dll
2017-07-07 14:11 - 2017-06-03 10:11 - 00353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2017-07-07 14:11 - 2017-06-03 10:10 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-07-07 14:11 - 2017-06-03 10:10 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll
2017-07-07 14:11 - 2017-06-03 10:10 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBrokerUI.dll
2017-07-07 14:11 - 2017-06-03 10:09 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2017-07-07 14:11 - 2017-06-03 10:09 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcorehc.dll
2017-07-07 14:11 - 2017-06-03 10:09 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2017-07-07 14:11 - 2017-06-03 10:08 - 12187648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-07-07 14:11 - 2017-06-03 10:08 - 02643968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-07-07 14:11 - 2017-06-03 10:08 - 01221120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2017-07-07 14:11 - 2017-06-03 10:08 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-07-07 14:11 - 2017-06-03 10:08 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-07-07 14:11 - 2017-06-03 10:08 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-07-07 14:11 - 2017-06-03 10:07 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-07-07 14:11 - 2017-06-03 10:07 - 00456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2017-07-07 14:11 - 2017-06-03 10:07 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\HNetCfgClient.dll
2017-07-07 14:11 - 2017-06-03 10:06 - 03664384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-07-07 14:11 - 2017-06-03 10:06 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2017-07-07 14:11 - 2017-06-03 10:05 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-07-07 14:11 - 2017-06-03 10:05 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hnetcfg.dll
2017-07-07 14:11 - 2017-06-03 10:04 - 06042624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-07-07 14:11 - 2017-06-03 10:04 - 02006528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-07-07 14:11 - 2017-06-03 10:04 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-07-07 14:11 - 2017-06-03 10:03 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-07-07 14:11 - 2017-06-03 10:03 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-07-07 14:11 - 2017-06-03 10:02 - 02997760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-07-07 14:11 - 2017-06-03 10:01 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2017-07-07 14:11 - 2017-06-03 10:00 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-07-07 14:11 - 2017-06-03 09:58 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll
2017-07-07 14:11 - 2017-06-03 09:56 - 13091840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-07-07 14:11 - 2017-06-03 09:54 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-07-07 14:11 - 2017-06-03 09:53 - 08125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-07-07 14:11 - 2017-06-03 09:52 - 03403264 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-07-07 14:11 - 2017-06-03 09:52 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-07-07 14:11 - 2017-06-03 09:52 - 00975872 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-07-07 14:11 - 2017-06-03 09:52 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2017-07-07 14:11 - 2017-06-03 09:51 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe
2017-07-07 14:11 - 2017-06-03 09:51 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2017-07-07 14:11 - 2017-06-03 09:50 - 04744704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-07-07 14:11 - 2017-06-03 09:50 - 02538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-07-07 14:11 - 2017-06-03 09:49 - 03615744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-07-07 14:11 - 2017-06-03 09:49 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-07-07 14:11 - 2017-06-03 09:49 - 02475520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-07-07 14:11 - 2017-06-03 09:49 - 02318848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-07-07 14:11 - 2017-06-03 09:49 - 01845248 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-07-07 14:11 - 2017-06-03 09:49 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-07-07 14:11 - 2017-06-03 09:49 - 00903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-07-07 14:11 - 2017-06-03 09:49 - 00351744 _____ (Microsoft Corporation) C:\WINDOWS\system32\hnetcfg.dll
2017-07-07 14:11 - 2017-06-03 09:48 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-07-07 14:11 - 2017-06-03 09:48 - 01131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-07-07 14:11 - 2017-06-03 09:48 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-07-07 14:11 - 2017-06-03 09:48 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-07-07 14:11 - 2017-06-03 09:46 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-07-07 14:11 - 2017-06-03 09:40 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-07-07 14:11 - 2017-06-03 07:08 - 00080078 _____ C:\WINDOWS\system32\normidna.nls
2017-07-07 14:11 - 2017-05-25 06:56 - 00038752 _____ (Microsoft Corporation) C:\WINDOWS\system32\OOBEUpdater.exe
2017-07-07 14:11 - 2017-03-04 07:22 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-07-07 14:11 - 2017-03-04 07:19 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2017-07-07 14:11 - 2017-03-04 07:16 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2017-07-07 14:11 - 2017-03-04 07:16 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2017-07-07 14:11 - 2016-09-07 05:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2017-07-07 10:38 - 2017-07-07 10:38 - 00000000 __SHD C:\found.000
2017-07-07 08:14 - 2017-07-07 08:14 - 00051621 _____ C:\WINDOWS\uninstaller.dat
2017-07-06 10:32 - 2017-07-06 10:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-07-04 16:06 - 2017-06-21 08:07 - 00179320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2017-07-04 16:06 - 2017-06-21 08:07 - 00146552 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2017-07-02 13:51 - 2017-07-02 13:51 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\Corsair
2017-07-02 13:51 - 2017-07-02 13:51 - 00000000 ____D C:\Users\Twitchi\AppData\Local\Corsair
2017-07-02 13:51 - 2017-07-02 13:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Corsair Utility Engine
2017-07-02 13:50 - 2017-07-02 13:50 - 00000000 ____D C:\Program Files (x86)\Corsair
2017-07-01 14:03 - 2017-07-01 14:03 - 06461440 _____ (CKAN Contributors) C:\Users\Twitchi\Desktop\ckan.exe
2017-07-01 13:31 - 2017-07-01 13:31 - 00000000 ____D C:\Users\Twitchi\AppData\LocalLow\Squad
2017-06-30 19:38 - 2017-06-30 20:33 - 00000000 ____D C:\Users\Twitchi\Desktop\Morrowind Mods
2017-06-29 23:01 - 2017-06-29 23:01 - 00000221 _____ C:\Users\Twitchi\Desktop\The Elder Scrolls III Morrowind.url
2017-06-26 11:27 - 2017-06-26 11:27 - 00049992 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2017-06-26 11:27 - 2017-06-26 11:27 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2017-06-26 11:27 - 2017-06-26 11:27 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2017-06-26 11:27 - 2017-06-26 11:27 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2017-06-25 01:33 - 2017-06-25 01:33 - 00000222 _____ C:\Users\Twitchi\Desktop\Broforce.url
2017-06-18 21:43 - 2017-06-18 21:43 - 00001139 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-06-18 00:21 - 2017-06-18 00:19 - 00060920 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avdevprot.sys
2017-06-13 21:43 - 2017-06-13 21:43 - 00000000 ____D C:\Users\Twitchi\Desktop\game
2017-06-13 21:41 - 2017-06-13 21:43 - 38970240 _____ (Mojang) C:\Users\Twitchi\Desktop\Minecraft.exe
2017-06-13 14:11 - 2017-06-13 14:11 - 00000000 _____ C:\Users\Twitchi\Desktop\New Text Document.txt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-11 13:17 - 2016-11-16 03:20 - 00000000 ____D C:\Users\Twitchi\AppData\LocalLow\Mozilla
2017-07-11 12:43 - 2017-04-03 14:03 - 00000000 ____D C:\Users\Twitchi\AppData\Local\osu!
2017-07-11 12:43 - 2017-02-20 23:13 - 00001220 _____ C:\Users\Twitchi\Desktop\nativelog.txt
2017-07-11 12:43 - 2016-04-12 18:57 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\.minecraft
2017-07-11 12:25 - 2016-09-25 11:58 - 00000000 ____D C:\ProgramData\NVIDIA
2017-07-11 11:24 - 2016-09-25 12:29 - 00000000 ____D C:\Users\Twitchi\AppData\Local\ConnectedDevicesPlatform
2017-07-11 10:38 - 2016-10-02 13:10 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\discord
2017-07-11 10:38 - 2016-04-12 16:18 - 00000000 ____D C:\Program Files (x86)\Steam
2017-07-11 10:33 - 2016-09-25 12:25 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-07-11 10:33 - 2016-09-25 11:55 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-07-11 02:11 - 2016-04-19 12:07 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-07-10 11:05 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache
2017-07-09 22:42 - 2016-07-16 07:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-07-09 20:20 - 2016-07-09 10:56 - 00000000 ____D C:\Users\Twitchi\AppData\Local\CrashDumps
2017-07-09 20:19 - 2016-09-25 12:02 - 01332974 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-07-09 20:13 - 2016-09-25 12:03 - 00000000 ____D C:\Users\Twitchi
2017-07-09 17:41 - 2016-04-13 00:24 - 00000000 ____D C:\Users\Twitchi\AppData\Local\gtk-2.0
2017-07-09 17:41 - 2016-04-13 00:00 - 00000000 ____D C:\Users\Twitchi\.gimp-2.8
2017-07-09 13:28 - 2016-10-28 18:11 - 00000000 ____D C:\Users\Twitchi\Desktop\wondows 10 save kit
2017-07-09 13:20 - 2017-04-18 14:09 - 00000000 ____D C:\Users\Twitchi\AppData\Local\Deployment
2017-07-09 13:15 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-07-09 13:15 - 2016-06-22 11:59 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2017-07-09 13:12 - 2016-04-08 17:48 - 00000000 ____D C:\ProgramData\Package Cache
2017-07-09 13:12 - 2009-07-14 04:20 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2017-07-09 00:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-07-08 16:26 - 2016-04-16 14:04 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\obs-studio
2017-07-08 12:23 - 2016-09-25 20:52 - 00000000 ___DC C:\WINDOWS\Panther
2017-07-08 12:23 - 2016-09-25 12:26 - 00001908 _____ C:\WINDOWS\diagwrn.xml
2017-07-08 12:23 - 2016-09-25 12:26 - 00001908 _____ C:\WINDOWS\diagerr.xml
2017-07-07 21:49 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-07-07 14:37 - 2016-04-27 07:42 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-07-07 14:33 - 2016-09-25 11:54 - 04864128 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-07-07 14:30 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-07-07 14:30 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-07-07 14:30 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-07-07 14:25 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-07-07 14:16 - 2016-04-08 17:55 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-07-07 14:13 - 2016-04-08 17:55 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-07-06 10:32 - 2016-06-07 01:47 - 00000000 ____D C:\Program Files (x86)\Dropbox
2017-07-05 17:40 - 2016-04-14 10:17 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\Curse Client
2017-07-05 17:40 - 2016-04-13 12:46 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\Audacity
2017-07-05 14:44 - 2016-08-12 23:19 - 00644648 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
2017-07-04 16:17 - 2016-06-22 14:14 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-07-04 16:06 - 2017-05-23 14:00 - 00004000 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2017-01-05 16:57 - 00004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-10-31 14:30 - 00003994 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-10-31 14:29 - 00003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-10-31 14:29 - 00003866 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-10-31 14:29 - 00003858 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-10-31 14:29 - 00003696 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-10-31 14:29 - 00003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-09-25 11:57 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-07-04 16:06 - 2016-09-25 11:57 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-07-04 16:06 - 2016-09-25 11:57 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-07-01 19:08 - 2016-04-18 11:42 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\vlc
2017-06-30 19:10 - 2016-04-08 18:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-06-30 16:18 - 2016-06-08 12:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-28 00:56 - 2016-11-11 19:40 - 00000000 ____D C:\Users\Twitchi\Documents\OpenTTD
2017-06-27 22:12 - 2016-06-22 13:57 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-24 22:45 - 2016-06-22 13:58 - 00000000 ____D C:\Users\Twitchi\AppData\Local\Google
2017-06-23 17:17 - 2016-04-08 17:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2017-06-22 16:00 - 2017-01-27 21:59 - 00003284 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-06-22 16:00 - 2016-07-26 15:23 - 00002409 _____ C:\Users\Twitchi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-06-22 16:00 - 2016-07-26 15:23 - 00000000 ___RD C:\Users\Twitchi\OneDrive
2017-06-21 08:07 - 2017-01-29 00:57 - 00057976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2017-06-21 08:07 - 2016-10-31 14:30 - 01903224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2017-06-21 08:07 - 2016-10-31 14:30 - 01755256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2017-06-21 08:07 - 2016-10-31 14:30 - 01489528 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2017-06-21 08:07 - 2016-10-31 14:30 - 01317496 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2017-06-21 08:07 - 2016-10-31 14:30 - 00121464 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2017-06-21 08:07 - 2016-10-31 14:29 - 00048248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2017-06-20 21:58 - 2017-01-05 16:57 - 00001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat
2017-06-18 21:03 - 2016-04-20 12:57 - 00002243 _____ C:\Users\Twitchi\Desktop\Tags.txt
2017-06-18 00:19 - 2016-10-05 14:12 - 00038048 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys
2017-06-18 00:19 - 2016-04-08 17:54 - 00167504 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2017-06-18 00:19 - 2016-04-08 17:54 - 00164824 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2017-06-17 01:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-06-17 01:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-06-16 21:05 - 2017-01-08 21:19 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2017-06-16 21:05 - 2017-01-08 21:18 - 00000000 ____D C:\Program Files\Rockstar Games
2017-06-14 14:33 - 2016-07-05 00:00 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\FileZilla
2017-06-13 21:43 - 2017-04-18 00:58 - 00000383 _____ C:\Users\Twitchi\Desktop\updateLog.txt
==================== Files in the root of some directories =======
2017-07-09 17:41 - 2017-07-09 17:41 - 0031478 _____ () C:\Users\Twitchi\AppData\Local\recently-used.xbel
2016-06-07 00:30 - 2017-05-29 16:29 - 0007593 _____ () C:\Users\Twitchi\AppData\Local\Resmon.ResmonCfg
2016-08-14 15:11 - 2016-08-14 15:11 - 0000016 _____ () C:\ProgramData\mntemp
2017-01-05 16:57 - 2017-01-29 00:57 - 0034265 _____ () C:\ProgramData\NvTelemetryContainer.log
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-07-03 17:18
==================== End of FRST.txt ============================
Ran by Twitchi (administrator) on FRAMEZILLA (11-07-2017 13:41:52)
Running from C:\Users\Twitchi\Desktop
Loaded Profiles: Twitchi (Available Profiles: Twitchi & DefaultAppPool)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Hammer & Chisel, Inc.) C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\Discord.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Corsair Components, Inc.) C:\Program Files (x86)\Corsair\Corsair Utility Engine\CUE.exe
(Hammer & Chisel, Inc.) C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\Discord.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Hammer & Chisel, Inc.) C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\Discord.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avcenter.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\Adobe Premiere Pro.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\32\dynamiclinkmanager.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\32\Adobe QT32 Server.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10038304 2010-02-02] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-04-28] (Adobe Systems Incorporated)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [97512 2017-06-08] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [918008 2017-06-18] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3486520 2017-06-26] (Dropbox, Inc.)
HKLM-x32\...\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [75776 2016-08-10] ()
HKLM-x32\...\Run: [Corsair Utility Engine] => C:\Program Files (x86)\Corsair\Corsair Utility Engine\CUE.exe [18299088 2017-05-26] (Corsair Components, Inc.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3062048 2017-07-06] (Valve Corporation)
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9288408 2016-12-06] (Piriform Ltd)
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [OneDrive] => "C:\Users\Twitchi\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [Discord] => C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.)
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [afwhgsid1je] => "C:\Users\Twitchi\AppData\Roaming\u4142ebbq1s\5j5lzk1wsnu.exe"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [4uccdotqxhp] => "C:\Users\Twitchi\AppData\Roaming\hfpcslo54jz\ql02ktelgos.exe"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Run: [aeanjqjos20] => "C:\Users\Twitchi\AppData\Roaming\bgsuk4oce02\2nku4gth3nu.exe"
GroupPolicy: Restriction - Chrome <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1ede3236-6b46-42cd-acfa-e9ebdf477ff0}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{abd7ab2e-3df7-4618-a449-84877c40d9d1}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{dae9345e-a687-48a6-a34d-2e426f7186f8}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1265003007-341673947-2575449671-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-04-25] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-25] (Oracle Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default [2017-07-11]
FF user.js: detected! => C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\user.js [2017-06-29]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\KQADxXuG.default -> DuckDuckGo
FF Homepage: Mozilla\Firefox\Profiles\KQADxXuG.default -> hxxps://duckduckgo.com/
FF Extension: (Avira Browser Safety) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\[email protected] [2017-06-06]
FF Extension: (Flip or Rotate Image) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\[email protected] [2017-03-27]
FF Extension: (Html5 Youtube Video Speed Controller) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\[email protected] [2016-04-11]
FF Extension: (Strict Pop-up Blocker) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\[email protected] [2016-09-12]
FF Extension: (uBlock Origin) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\[email protected] [2017-07-09]
FF Extension: (LeechBlock) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\{a95d8332-e4b4-6e7f-98ac-20b733364387} [2017-03-20]
FF Extension: (Video DownloadHelper) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2017-05-09]
FF Extension: (Always on Top) - C:\Users\Twitchi\AppData\Roaming\Mozilla\Firefox\Profiles\KQADxXuG.default\Extensions\{E6C93316-271E-4b3d-8D7E-FE11B4350AEB}.xpi [2016-07-28]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-17] ()
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-25] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-17] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-01] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1265003007-341673947-2575449671-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Twitchi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-04-19] (Unity Technologies ApS)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\firefox.js [2017-07-09]
Chrome:
=======
CHR Profile: C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default [2017-06-25]
CHR Extension: (Google Slides) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-06-22]
CHR Extension: (Google Docs) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-22]
CHR Extension: (Google Drive) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-22]
CHR Extension: (YouTube) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-22]
CHR Extension: (Google Sheets) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-22]
CHR Extension: (Google Docs Offline) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-06-24]
CHR Extension: (Gmail) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-22]
CHR Extension: (Chrome Media Router) - C:\Users\Twitchi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-25]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AdBlockerService; C:\Program Files (x86)\AdBlocker\AdBlockerService.exe [110080 2017-04-11] (Star Line) [File not signed]
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1128432 2017-06-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [490968 2017-06-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [490968 2017-06-18] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1524216 2017-06-18] (Avira Operations GmbH & Co. KG)
S2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [356256 2017-06-08] (Avira Operations GmbH & Co. KG)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1465352 2017-02-11] ()
S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2013-11-29] (www.BitComet.com)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-06-07] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-06-07] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [49992 2017-06-26] (Dropbox, Inc.)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [383016 2017-06-07] (EasyAntiCheat Ltd)
S4 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2016-08-10] (Freemake) [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462784 2017-02-23] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [450168 2017-06-21] (NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10351856 2016-12-15] (TeamViewer GmbH)
R2 VIAKaraokeService; C:\WINDOWS\system32\viakaraokesrv.exe [36504 2015-06-22] (VIA Technologies, Inc.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-09-06] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-28] (Microsoft Corporation)
S4 1fcf926529d07bef7da3dc8418c67946; "C:\Program Files\1fcf926529d07bef7da3dc8418c67946\79022675ad2cc919f1f92953446ac97f.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 avdevprot; C:\WINDOWS\System32\DRIVERS\avdevprot.sys [60920 2017-06-18] (Avira Operations GmbH & Co. KG)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [167504 2017-06-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [164824 2017-06-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [44488 2017-03-02] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [88488 2017-03-02] (Avira Operations GmbH & Co. KG)
R3 CMUSBDAC; C:\WINDOWS\system32\DRIVERS\CMUSBDAC.sys [3792904 2016-11-30] (C-MEDIA)
R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [45016 2017-05-16] (Corsair)
R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [21976 2017-05-16] (Corsair)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77376 2017-06-27] ()
S3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2017-04-06] (Logitech Inc.)
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [188352 2017-07-09] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [101784 2017-07-11] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [45472 2017-07-11] (Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [253856 2017-07-11] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [93600 2017-07-11] (Malwarebytes)
R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] ()
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_2a6e383a1adc0e24\nvlddmkm.sys [14569528 2017-02-24] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-06-21] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48248 2017-06-21] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57976 2017-06-21] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
R3 SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation)
S0 SI3132; C:\WINDOWS\System32\drivers\SI3132.sys [90664 2007-10-03] (Silicon Image, Inc)
R0 SiFilter; C:\WINDOWS\System32\drivers\SiWinAcc.sys [22056 2007-10-03] (Silicon Image, Inc)
R0 SiRemFil; C:\WINDOWS\System32\drivers\SiRemFil.sys [17448 2007-10-03] (Silicon Image, Inc)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-11 13:41 - 2017-07-11 13:43 - 00019624 _____ C:\Users\Twitchi\Desktop\FRST.txt
2017-07-11 13:41 - 2017-07-11 13:41 - 00000000 ____D C:\FRST
2017-07-11 13:40 - 2017-07-11 13:40 - 02437120 _____ (Farbar) C:\Users\Twitchi\Desktop\FRST64.exe
2017-07-09 20:42 - 2017-07-11 12:43 - 00093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-07-09 20:42 - 2017-07-11 10:37 - 00101784 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-07-09 20:42 - 2017-07-11 10:36 - 00045472 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-07-09 20:42 - 2017-07-11 10:34 - 00253856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-07-09 20:42 - 2017-07-09 20:42 - 00188352 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-07-09 20:42 - 2017-07-09 20:42 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-07-09 20:42 - 2017-07-09 20:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-07-09 20:42 - 2017-07-09 20:42 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-07-09 20:42 - 2017-07-09 20:42 - 00000000 ____D C:\Program Files\Malwarebytes
2017-07-09 20:42 - 2017-06-27 12:06 - 00077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-07-09 20:13 - 2017-07-09 20:13 - 00000258 __RSH C:\Users\Twitchi\ntuser.pol
2017-07-09 17:41 - 2017-07-09 17:41 - 00031478 _____ C:\Users\Twitchi\AppData\Local\recently-used.xbel
2017-07-09 17:28 - 2017-07-09 17:28 - 00000000 ____D C:\Users\Twitchi\Desktop\tmp
2017-07-09 13:17 - 2017-07-09 13:17 - 00003764 _____ C:\WINDOWS\System32\Tasks\updater
2017-07-09 13:13 - 2017-07-09 13:19 - 00000000 ____D C:\Program Files (x86)\AdBlocker
2017-07-09 13:13 - 2017-07-09 13:13 - 00016802 _____ C:\WINDOWS\System32\Tasks\Star-ToAx24
2017-07-09 13:13 - 2017-07-09 13:13 - 00000000 ____D C:\Users\Public\Thunder Network
2017-07-09 13:13 - 2017-07-05 14:22 - 02017280 ___SH (Micrasaft Carparation) C:\WINDOWS\C_02iu47.dat
2017-07-09 13:12 - 2017-07-09 21:16 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\devnull
2017-07-09 13:12 - 2017-07-09 13:17 - 00003284 _____ C:\WINDOWS\System32\Tasks\1fcf926529d07bef7da3dc8418c67946
2017-07-09 13:12 - 2017-07-09 13:17 - 00000000 ____D C:\WINDOWS\SysWOW64\SSL
2017-07-09 13:12 - 2017-07-09 13:13 - 00006264 __RSH C:\ProgramData\ntuser.pol
2017-07-09 13:11 - 2017-07-10 19:07 - 00000000 ____D C:\ProgramData\WindowsErrorReporting
2017-07-09 13:11 - 2017-07-09 20:58 - 00000000 ____D C:\Program Files (x86)\0m3vi0hqddj
2017-07-09 13:11 - 2017-07-09 13:13 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\Easeware
2017-07-09 13:10 - 2017-07-09 13:10 - 00000000 ____D C:\Users\Twitchi\AppData\Local\CrashRpt
2017-07-09 13:06 - 2017-07-09 13:20 - 00000000 ____D C:\Program Files\KMSpico
2017-07-09 13:05 - 2017-07-09 13:12 - 00000000 ____D C:\Users\Twitchi\AppData\Local\AdvinstAnalytics
2017-07-09 13:04 - 2017-07-09 13:04 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\RenewSoftware.com
2017-07-08 20:49 - 2017-07-08 20:49 - 00000000 ____D C:\Users\Twitchi\AppData\LocalLow\Pill Bug Interactive
2017-07-08 20:42 - 2017-07-08 20:42 - 00000222 _____ C:\Users\Twitchi\Desktop\Intelligent Design An Evolutionary Sandbox.url
2017-07-08 12:17 - 2017-07-08 12:23 - 00000000 ___HD C:\$WINDOWS.~BT
2017-07-07 14:30 - 2017-07-07 14:30 - 00000000 ___SD C:\WINDOWS\UpdateAssistantV2
2017-07-07 14:16 - 2017-04-21 22:53 - 00029376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aspnet_counters.dll
2017-07-07 14:16 - 2017-04-21 22:53 - 00018600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr100_clr0400.dll
2017-07-07 14:16 - 2017-04-21 22:50 - 00030912 _____ (Microsoft Corporation) C:\WINDOWS\system32\aspnet_counters.dll
2017-07-07 14:16 - 2017-04-21 22:50 - 00018592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr100_clr0400.dll
2017-07-07 14:16 - 2017-04-11 19:27 - 00993632 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll
2017-07-07 14:16 - 2017-04-11 19:27 - 00690008 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp120_clr0400.dll
2017-07-07 14:16 - 2017-03-15 19:15 - 00987840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll
2017-07-07 14:16 - 2017-03-15 19:15 - 00485576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp120_clr0400.dll
2017-07-07 14:11 - 2017-06-03 11:50 - 00315744 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-07-07 14:11 - 2017-06-03 11:50 - 00192856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2017-07-07 14:11 - 2017-06-03 11:16 - 00279904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-07-07 14:11 - 2017-06-03 11:14 - 01564512 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 01214816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00629088 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00544096 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00334176 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00233824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00136024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2017-07-07 14:11 - 2017-06-03 11:14 - 00096608 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-07-07 14:11 - 2017-06-03 11:14 - 00034648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-07-07 14:11 - 2017-06-03 11:11 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-07-07 14:11 - 2017-06-03 11:11 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-07-07 14:11 - 2017-06-03 11:09 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-07-07 14:11 - 2017-06-03 11:08 - 07783256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-07-07 14:11 - 2017-06-03 11:06 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-07-07 14:11 - 2017-06-03 11:01 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-07-07 14:11 - 2017-06-03 10:59 - 01181024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2017-07-07 14:11 - 2017-06-03 10:59 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-07-07 14:11 - 2017-06-03 10:59 - 00118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-07-07 14:11 - 2017-06-03 10:58 - 00340832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-07-07 14:11 - 2017-06-03 10:55 - 00780640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-07-07 14:11 - 2017-06-03 10:54 - 00187232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-07-07 14:11 - 2017-06-03 10:53 - 00404824 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-07-07 14:11 - 2017-06-03 10:52 - 01021784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2017-07-07 14:11 - 2017-06-03 10:52 - 00607072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2017-07-07 14:11 - 2017-06-03 10:52 - 00111968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2017-07-07 14:11 - 2017-06-03 10:51 - 02187104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-07-07 14:11 - 2017-06-03 10:51 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-07-07 14:11 - 2017-06-03 10:50 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-07-07 14:11 - 2017-06-03 10:50 - 00381792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-07-07 14:11 - 2017-06-03 10:49 - 20967840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-07-07 14:11 - 2017-06-03 10:49 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-07-07 14:11 - 2017-06-03 10:49 - 00509280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-07-07 14:11 - 2017-06-03 10:48 - 01112416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2017-07-07 14:11 - 2017-06-03 10:48 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-07-07 14:11 - 2017-06-03 10:48 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-07-07 14:11 - 2017-06-03 10:48 - 00857952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2017-07-07 14:11 - 2017-06-03 10:48 - 00148832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2017-07-07 14:11 - 2017-06-03 10:45 - 22220864 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-07-07 14:11 - 2017-06-03 10:44 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-07-07 14:11 - 2017-06-03 10:44 - 01412640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-07-07 14:11 - 2017-06-03 10:44 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-07-07 14:11 - 2017-06-03 10:40 - 01566552 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-07-07 14:11 - 2017-06-03 10:40 - 00628552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-07-07 14:11 - 2017-06-03 10:39 - 05686272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-07-07 14:11 - 2017-06-03 10:39 - 02532192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-07-07 14:11 - 2017-06-03 10:39 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-07-07 14:11 - 2017-06-03 10:33 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-07-07 14:11 - 2017-06-03 10:32 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-07-07 14:11 - 2017-06-03 10:31 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2017-07-07 14:11 - 2017-06-03 10:31 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-07-07 14:11 - 2017-06-03 10:28 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-07-07 14:11 - 2017-06-03 10:28 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edputil.dll
2017-07-07 14:11 - 2017-06-03 10:26 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-07-07 14:11 - 2017-06-03 10:26 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBrokerUI.dll
2017-07-07 14:11 - 2017-06-03 10:23 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-07-07 14:11 - 2017-06-03 10:22 - 07217152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-07-07 14:11 - 2017-06-03 10:22 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2017-07-07 14:11 - 2017-06-03 10:22 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcorehc.dll
2017-07-07 14:11 - 2017-06-03 10:22 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2017-07-07 14:11 - 2017-06-03 10:20 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2017-07-07 14:11 - 2017-06-03 10:19 - 01164288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe
2017-07-07 14:11 - 2017-06-03 10:18 - 22569984 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-07-07 14:11 - 2017-06-03 10:16 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2017-07-07 14:11 - 2017-06-03 10:16 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-07-07 14:11 - 2017-06-03 10:16 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-07-07 14:11 - 2017-06-03 10:15 - 19414016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-07-07 14:11 - 2017-06-03 10:15 - 18364928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-07-07 14:11 - 2017-06-03 10:15 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-07-07 14:11 - 2017-06-03 10:15 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-07-07 14:11 - 2017-06-03 10:15 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-07-07 14:11 - 2017-06-03 10:14 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-07-07 14:11 - 2017-06-03 10:14 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-07-07 14:11 - 2017-06-03 10:14 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-07-07 14:11 - 2017-06-03 10:14 - 00045056 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-07-07 14:11 - 2017-06-03 10:12 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdProxy.dll
2017-07-07 14:11 - 2017-06-03 10:11 - 00353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2017-07-07 14:11 - 2017-06-03 10:10 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-07-07 14:11 - 2017-06-03 10:10 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll
2017-07-07 14:11 - 2017-06-03 10:10 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBrokerUI.dll
2017-07-07 14:11 - 2017-06-03 10:09 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2017-07-07 14:11 - 2017-06-03 10:09 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcorehc.dll
2017-07-07 14:11 - 2017-06-03 10:09 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2017-07-07 14:11 - 2017-06-03 10:08 - 12187648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-07-07 14:11 - 2017-06-03 10:08 - 02643968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-07-07 14:11 - 2017-06-03 10:08 - 01221120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2017-07-07 14:11 - 2017-06-03 10:08 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-07-07 14:11 - 2017-06-03 10:08 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-07-07 14:11 - 2017-06-03 10:08 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-07-07 14:11 - 2017-06-03 10:07 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-07-07 14:11 - 2017-06-03 10:07 - 00456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2017-07-07 14:11 - 2017-06-03 10:07 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\HNetCfgClient.dll
2017-07-07 14:11 - 2017-06-03 10:06 - 03664384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-07-07 14:11 - 2017-06-03 10:06 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2017-07-07 14:11 - 2017-06-03 10:05 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-07-07 14:11 - 2017-06-03 10:05 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hnetcfg.dll
2017-07-07 14:11 - 2017-06-03 10:04 - 06042624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-07-07 14:11 - 2017-06-03 10:04 - 02006528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-07-07 14:11 - 2017-06-03 10:04 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-07-07 14:11 - 2017-06-03 10:03 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-07-07 14:11 - 2017-06-03 10:03 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-07-07 14:11 - 2017-06-03 10:02 - 02997760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-07-07 14:11 - 2017-06-03 10:01 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2017-07-07 14:11 - 2017-06-03 10:00 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-07-07 14:11 - 2017-06-03 09:58 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll
2017-07-07 14:11 - 2017-06-03 09:56 - 13091840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-07-07 14:11 - 2017-06-03 09:54 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-07-07 14:11 - 2017-06-03 09:53 - 08125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-07-07 14:11 - 2017-06-03 09:52 - 03403264 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-07-07 14:11 - 2017-06-03 09:52 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-07-07 14:11 - 2017-06-03 09:52 - 00975872 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-07-07 14:11 - 2017-06-03 09:52 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2017-07-07 14:11 - 2017-06-03 09:51 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe
2017-07-07 14:11 - 2017-06-03 09:51 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2017-07-07 14:11 - 2017-06-03 09:50 - 04744704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-07-07 14:11 - 2017-06-03 09:50 - 02538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-07-07 14:11 - 2017-06-03 09:49 - 03615744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-07-07 14:11 - 2017-06-03 09:49 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-07-07 14:11 - 2017-06-03 09:49 - 02475520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-07-07 14:11 - 2017-06-03 09:49 - 02318848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-07-07 14:11 - 2017-06-03 09:49 - 01845248 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-07-07 14:11 - 2017-06-03 09:49 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-07-07 14:11 - 2017-06-03 09:49 - 00903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-07-07 14:11 - 2017-06-03 09:49 - 00351744 _____ (Microsoft Corporation) C:\WINDOWS\system32\hnetcfg.dll
2017-07-07 14:11 - 2017-06-03 09:48 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-07-07 14:11 - 2017-06-03 09:48 - 01131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-07-07 14:11 - 2017-06-03 09:48 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-07-07 14:11 - 2017-06-03 09:48 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-07-07 14:11 - 2017-06-03 09:46 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-07-07 14:11 - 2017-06-03 09:40 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-07-07 14:11 - 2017-06-03 07:08 - 00080078 _____ C:\WINDOWS\system32\normidna.nls
2017-07-07 14:11 - 2017-05-25 06:56 - 00038752 _____ (Microsoft Corporation) C:\WINDOWS\system32\OOBEUpdater.exe
2017-07-07 14:11 - 2017-03-04 07:22 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-07-07 14:11 - 2017-03-04 07:19 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2017-07-07 14:11 - 2017-03-04 07:16 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2017-07-07 14:11 - 2017-03-04 07:16 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2017-07-07 14:11 - 2016-09-07 05:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2017-07-07 10:38 - 2017-07-07 10:38 - 00000000 __SHD C:\found.000
2017-07-07 08:14 - 2017-07-07 08:14 - 00051621 _____ C:\WINDOWS\uninstaller.dat
2017-07-06 10:32 - 2017-07-06 10:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-07-04 16:06 - 2017-06-21 08:07 - 00179320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2017-07-04 16:06 - 2017-06-21 08:07 - 00146552 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2017-07-02 13:51 - 2017-07-02 13:51 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\Corsair
2017-07-02 13:51 - 2017-07-02 13:51 - 00000000 ____D C:\Users\Twitchi\AppData\Local\Corsair
2017-07-02 13:51 - 2017-07-02 13:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Corsair Utility Engine
2017-07-02 13:50 - 2017-07-02 13:50 - 00000000 ____D C:\Program Files (x86)\Corsair
2017-07-01 14:03 - 2017-07-01 14:03 - 06461440 _____ (CKAN Contributors) C:\Users\Twitchi\Desktop\ckan.exe
2017-07-01 13:31 - 2017-07-01 13:31 - 00000000 ____D C:\Users\Twitchi\AppData\LocalLow\Squad
2017-06-30 19:38 - 2017-06-30 20:33 - 00000000 ____D C:\Users\Twitchi\Desktop\Morrowind Mods
2017-06-29 23:01 - 2017-06-29 23:01 - 00000221 _____ C:\Users\Twitchi\Desktop\The Elder Scrolls III Morrowind.url
2017-06-26 11:27 - 2017-06-26 11:27 - 00049992 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2017-06-26 11:27 - 2017-06-26 11:27 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2017-06-26 11:27 - 2017-06-26 11:27 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2017-06-26 11:27 - 2017-06-26 11:27 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2017-06-25 01:33 - 2017-06-25 01:33 - 00000222 _____ C:\Users\Twitchi\Desktop\Broforce.url
2017-06-18 21:43 - 2017-06-18 21:43 - 00001139 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-06-18 00:21 - 2017-06-18 00:19 - 00060920 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avdevprot.sys
2017-06-13 21:43 - 2017-06-13 21:43 - 00000000 ____D C:\Users\Twitchi\Desktop\game
2017-06-13 21:41 - 2017-06-13 21:43 - 38970240 _____ (Mojang) C:\Users\Twitchi\Desktop\Minecraft.exe
2017-06-13 14:11 - 2017-06-13 14:11 - 00000000 _____ C:\Users\Twitchi\Desktop\New Text Document.txt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-11 13:17 - 2016-11-16 03:20 - 00000000 ____D C:\Users\Twitchi\AppData\LocalLow\Mozilla
2017-07-11 12:43 - 2017-04-03 14:03 - 00000000 ____D C:\Users\Twitchi\AppData\Local\osu!
2017-07-11 12:43 - 2017-02-20 23:13 - 00001220 _____ C:\Users\Twitchi\Desktop\nativelog.txt
2017-07-11 12:43 - 2016-04-12 18:57 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\.minecraft
2017-07-11 12:25 - 2016-09-25 11:58 - 00000000 ____D C:\ProgramData\NVIDIA
2017-07-11 11:24 - 2016-09-25 12:29 - 00000000 ____D C:\Users\Twitchi\AppData\Local\ConnectedDevicesPlatform
2017-07-11 10:38 - 2016-10-02 13:10 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\discord
2017-07-11 10:38 - 2016-04-12 16:18 - 00000000 ____D C:\Program Files (x86)\Steam
2017-07-11 10:33 - 2016-09-25 12:25 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-07-11 10:33 - 2016-09-25 11:55 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-07-11 02:11 - 2016-04-19 12:07 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-07-10 11:05 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache
2017-07-09 22:42 - 2016-07-16 07:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-07-09 20:20 - 2016-07-09 10:56 - 00000000 ____D C:\Users\Twitchi\AppData\Local\CrashDumps
2017-07-09 20:19 - 2016-09-25 12:02 - 01332974 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-07-09 20:13 - 2016-09-25 12:03 - 00000000 ____D C:\Users\Twitchi
2017-07-09 17:41 - 2016-04-13 00:24 - 00000000 ____D C:\Users\Twitchi\AppData\Local\gtk-2.0
2017-07-09 17:41 - 2016-04-13 00:00 - 00000000 ____D C:\Users\Twitchi\.gimp-2.8
2017-07-09 13:28 - 2016-10-28 18:11 - 00000000 ____D C:\Users\Twitchi\Desktop\wondows 10 save kit
2017-07-09 13:20 - 2017-04-18 14:09 - 00000000 ____D C:\Users\Twitchi\AppData\Local\Deployment
2017-07-09 13:15 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-07-09 13:15 - 2016-06-22 11:59 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2017-07-09 13:12 - 2016-04-08 17:48 - 00000000 ____D C:\ProgramData\Package Cache
2017-07-09 13:12 - 2009-07-14 04:20 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2017-07-09 00:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-07-08 16:26 - 2016-04-16 14:04 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\obs-studio
2017-07-08 12:23 - 2016-09-25 20:52 - 00000000 ___DC C:\WINDOWS\Panther
2017-07-08 12:23 - 2016-09-25 12:26 - 00001908 _____ C:\WINDOWS\diagwrn.xml
2017-07-08 12:23 - 2016-09-25 12:26 - 00001908 _____ C:\WINDOWS\diagerr.xml
2017-07-07 21:49 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-07-07 14:37 - 2016-04-27 07:42 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-07-07 14:33 - 2016-09-25 11:54 - 04864128 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-07-07 14:30 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-07-07 14:30 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-07-07 14:30 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-07-07 14:25 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-07-07 14:16 - 2016-04-08 17:55 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-07-07 14:13 - 2016-04-08 17:55 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-07-06 10:32 - 2016-06-07 01:47 - 00000000 ____D C:\Program Files (x86)\Dropbox
2017-07-05 17:40 - 2016-04-14 10:17 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\Curse Client
2017-07-05 17:40 - 2016-04-13 12:46 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\Audacity
2017-07-05 14:44 - 2016-08-12 23:19 - 00644648 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
2017-07-04 16:17 - 2016-06-22 14:14 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-07-04 16:06 - 2017-05-23 14:00 - 00004000 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2017-01-05 16:57 - 00004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-10-31 14:30 - 00003994 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-10-31 14:29 - 00003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-10-31 14:29 - 00003866 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-10-31 14:29 - 00003858 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-10-31 14:29 - 00003696 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-10-31 14:29 - 00003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-04 16:06 - 2016-09-25 11:57 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-07-04 16:06 - 2016-09-25 11:57 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-07-04 16:06 - 2016-09-25 11:57 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-07-01 19:08 - 2016-04-18 11:42 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\vlc
2017-06-30 19:10 - 2016-04-08 18:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-06-30 16:18 - 2016-06-08 12:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-28 00:56 - 2016-11-11 19:40 - 00000000 ____D C:\Users\Twitchi\Documents\OpenTTD
2017-06-27 22:12 - 2016-06-22 13:57 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-24 22:45 - 2016-06-22 13:58 - 00000000 ____D C:\Users\Twitchi\AppData\Local\Google
2017-06-23 17:17 - 2016-04-08 17:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2017-06-22 16:00 - 2017-01-27 21:59 - 00003284 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-06-22 16:00 - 2016-07-26 15:23 - 00002409 _____ C:\Users\Twitchi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-06-22 16:00 - 2016-07-26 15:23 - 00000000 ___RD C:\Users\Twitchi\OneDrive
2017-06-21 08:07 - 2017-01-29 00:57 - 00057976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2017-06-21 08:07 - 2016-10-31 14:30 - 01903224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2017-06-21 08:07 - 2016-10-31 14:30 - 01755256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2017-06-21 08:07 - 2016-10-31 14:30 - 01489528 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2017-06-21 08:07 - 2016-10-31 14:30 - 01317496 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2017-06-21 08:07 - 2016-10-31 14:30 - 00121464 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2017-06-21 08:07 - 2016-10-31 14:29 - 00048248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2017-06-20 21:58 - 2017-01-05 16:57 - 00001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat
2017-06-18 21:03 - 2016-04-20 12:57 - 00002243 _____ C:\Users\Twitchi\Desktop\Tags.txt
2017-06-18 00:19 - 2016-10-05 14:12 - 00038048 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys
2017-06-18 00:19 - 2016-04-08 17:54 - 00167504 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2017-06-18 00:19 - 2016-04-08 17:54 - 00164824 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2017-06-17 01:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-06-17 01:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-06-16 21:05 - 2017-01-08 21:19 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2017-06-16 21:05 - 2017-01-08 21:18 - 00000000 ____D C:\Program Files\Rockstar Games
2017-06-14 14:33 - 2016-07-05 00:00 - 00000000 ____D C:\Users\Twitchi\AppData\Roaming\FileZilla
2017-06-13 21:43 - 2017-04-18 00:58 - 00000383 _____ C:\Users\Twitchi\Desktop\updateLog.txt
==================== Files in the root of some directories =======
2017-07-09 17:41 - 2017-07-09 17:41 - 0031478 _____ () C:\Users\Twitchi\AppData\Local\recently-used.xbel
2016-06-07 00:30 - 2017-05-29 16:29 - 0007593 _____ () C:\Users\Twitchi\AppData\Local\Resmon.ResmonCfg
2016-08-14 15:11 - 2016-08-14 15:11 - 0000016 _____ () C:\ProgramData\mntemp
2017-01-05 16:57 - 2017-01-29 00:57 - 0034265 _____ () C:\ProgramData\NvTelemetryContainer.log
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-07-03 17:18
==================== End of FRST.txt ============================
and Addition.txt
Spoiler
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-07-2017
Ran by Twitchi (11-07-2017 13:43:38)
Running from C:\Users\Twitchi\Desktop
Windows 10 Pro Version 1607 (X64) (2016-09-25 11:29:02)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1265003007-341673947-2575449671-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1265003007-341673947-2575449671-503 - Limited - Disabled)
Guest (S-1-5-21-1265003007-341673947-2575449671-501 - Limited - Enabled)
Twitchi (S-1-5-21-1265003007-341673947-2575449671-1000 - Administrator - Enabled) => C:\Users\Twitchi
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Antivirus (Enabled - Up to date) {B3F630BD-538D-1B4A-14FA-14B63235278F}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Avira Antivirus (Enabled - Up to date) {0897D159-75B7-14C4-2E4A-2FC449B26D32}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7 Days to Die (HKLM\...\Steam App 251570) (Version: - The Fun Pimps)
Adobe Flash Player 26 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 26.0.0.131 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2015 (HKLM-x32\...\{38C72D42-0672-43B1-9E05-E7631684F9A1}) (Version: 9.0.0 - Adobe Systems Incorporated)
Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 378.78 - NVIDIA Corporation) Hidden
Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{0E4C791E-B78E-477D-BD5A-CDD0985BA6EC}) (Version: 7.0.20622.1 - Microsoft Corporation)
ASTRONEER (HKLM\...\Steam App 361420) (Version: - System Era Softworks)
Atom (HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\atom) (Version: 1.16.0 - GitHub Inc.)
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.27.34 - Avira Operations GmbH & Co. KG)
Avira Connect (HKLM-x32\...\{14d00649-a178-473f-bf48-eec016dc4bfa}) (Version: 1.2.89.29905 - Avira Operations GmbH & Co. KG)
Avira Connect (HKLM-x32\...\{271D5399-34AF-4611-BCD9-B09185B2BBE0}) (Version: 1.2.89.29905 - Avira Operations GmbH & Co. KG) Hidden
Azure AD Authentication Connected Service (HKLM-x32\...\{8A1AD070-269F-4A15-AAB5-76AB896EF195}) (Version: 14.0.25420 - Microsoft Corporation) Hidden
AzureTools.Notifications (HKLM-x32\...\{1E5CA362-39B6-4BD0-B9C0-69CF15F0FEA2}) (Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
BallisticNG (HKLM\...\Steam App 473770) (Version: - Neognosis)
Besiege (HKLM\...\Steam App 346010) (Version: - Spiderling Studios)
BitComet 1.42 (HKLM-x32\...\BitComet_x64) (Version: 1.42 - CometNetwork)
Blend for Visual Studio SDK for .NET 4.5 (HKLM-x32\...\{37E53780-3944-4A6A-842F-727128E8616E}) (Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Blender (HKLM\...\{437221A8-91D1-42A0-9E04-0AD64B502374}) (Version: 2.78.1 - Blender Foundation)
Broadcom Gigabit NetLink Controller (HKLM\...\{A84DB02B-9C2B-4272-9D2D-A80E00A56513}) (Version: 12.52.01 - Broadcom Corporation)
Broforce (HKLM\...\Steam App 274190) (Version: - Free Lives)
CCleaner (HKLM\...\CCleaner) (Version: 5.25 - Piriform)
Cities: Skylines (HKLM\...\Steam App 255710) (Version: - Colossal Order Ltd.)
Corsair Utility Engine (HKLM-x32\...\{A9114889-E4D2-4112-B461-22179C0E122C}) (Version: 2.14.67 - Corsair)
Curse (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse)
DEFCON (HKLM\...\Steam App 1520) (Version: - Introversion Software)
Defraggler (HKLM\...\Defraggler) (Version: 2.21 - Piriform)
Discord (HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Discord) (Version: 0.0.297 - Hammer & Chisel, Inc.)
Don't Starve (HKLM\...\Steam App 219740) (Version: - Klei Entertainment)
Don't Starve Together Beta (HKLM\...\Steam App 322330) (Version: - Klei Entertainment)
Dotfuscator and Analytics Community Edition 5.22.0 (HKLM-x32\...\{60018889-9E0F-43E8-9B89-29E8C828B40A}) (Version: 5.22.0.3788 - PreEmptive Solutions) Hidden
Dropbox (HKLM-x32\...\Dropbox) (Version: 29.4.20 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.59.1 - Dropbox, Inc.) Hidden
Dungeons 2 (HKLM\...\Steam App 262280) (Version: - Realmforge Studios)
Empyrion - Galactic Survival (HKLM\...\Steam App 383120) (Version: - Eleon Game Studios)
Fallout: New Vegas (HKLM\...\Steam App 22380) (Version: - Obsidian Entertainment)
FileZilla Client 3.22.2.2 (HKLM-x32\...\FileZilla Client) (Version: 3.22.2.2 - Tim Kosse)
FINAL FANTASY VII (HKLM\...\Steam App 39140) (Version: - Square Enix)
FTL: Faster Than Light (HKLM\...\Steam App 212680) (Version: - Subset Games)
Genital Jousting (HKLM\...\Steam App 469820) (Version: - Free Lives)
GitHub (HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\5f7eb300e2ea4ebf) (Version: 3.3.4.0 - GitHub, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Grand Theft Auto V (HKLM\...\Steam App 271590) (Version: - Rockstar North)
Gtk# for .Net 2.12.26 (HKLM-x32\...\{BC25B808-A11C-4C9F-9C0A-6682E47AAB83}) (Version: 2.12.26 - Xamarin, Inc.)
Hacknet (HKLM\...\Steam App 365450) (Version: - Team Fractal Alligator)
Intelligent Design: An Evolutionary Sandbox (HKLM\...\Steam App 627620) (Version: - Pill Bug Interactive)
Java 8 Update 91 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418091F0}) (Version: 8.0.910.14 - Oracle Corporation)
Kerbal Space Program (HKLM\...\Steam App 220200) (Version: - Squad)
Kerbal Space Program V1.0.4 (HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Kerbal Space Program V1.0.4) (Version: - )
Kingdom: New Lands (HKLM\...\Steam App 496300) (Version: - Noio)
klocki (HKLM\...\Steam App 499440) (Version: - Maciej Targoni)
Left 4 Dead 2 (HKLM\...\Steam App 550) (Version: - Valve)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (ENU) (HKLM-x32\...\{034547E9-D8FA-49E7-8B9C-4C9861FB9146}) (Version: 4.6.00127 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.25420 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 T-SQL Language Service (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{FC3BB979-AA54-4B60-BBA3-2C4DA6E08D80}) (Version: 12.0.2402.29 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{091CE6AA-2753-4F6E-AD1C-0E875744EB54}) (Version: 12.0.2402.29 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 with Updates (HKLM-x32\...\{79b486b9-c5f0-4096-a00c-8351f59587c2}) (Version: 14.0.25420.1 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{94E1227C-08A9-4962-B388-1F05D89AEA75}) (Version: 3.1238.1962 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mini Metro (HKLM\...\Steam App 287980) (Version: - Dinosaur Polo Club)
Mount Your Friends (HKLM\...\Steam App 296470) (Version: - Stegersaurus Software Inc.)
Mozilla Firefox 54.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 54.0.1 (x86 en-US)) (Version: 54.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 54.0.1.6388 - Mozilla)
MSBuild/NuGet Integration 14.0 (x86) (HKLM-x32\...\{128C1654-3B9E-4959-8BFB-CE6F09C0A01D}) (Version: 14.0.25420 - Microsoft Corporation) Hidden
Multi-Device Hybrid Apps using C# - Templates - ENU (HKLM-x32\...\{12D99739-FFD3-3761-8AA6-F929E0FE407E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
No Man's Sky (HKLM\...\Steam App 275850) (Version: - Hello Games)
NVIDIA GeForce Experience 3.7.0.81 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.7.0.81 - NVIDIA Corporation)
NVIDIA Graphics Driver 378.78 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.78 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.23 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
NvNodejs (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs) (Version: 3.7.0.81 - NVIDIA Corporation) Hidden
NvTelemetry (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry) (Version: 2.6.1.0 - NVIDIA Corporation) Hidden
NvvHci (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci) (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 18.0.1 - OBS Project)
OpenTTD 1.6.1 (HKLM-x32\...\OpenTTD) (Version: 1.6.1 - OpenTTD)
osu! (HKLM-x32\...\{5135db6e-d0e6-452a-9e15-2181940ecaea}) (Version: latest - ppy Pty Ltd)
Oxygen Not Included (HKLM\...\Steam App 457140) (Version: - Klei Entertainment)
PreEmptive Analytics Visual Studio Components (HKLM-x32\...\{436A18DD-5F2C-4B3C-985E-AD3C13B0CC25}) (Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6039 - Realtek Semiconductor Corp.)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.9 - Rockstar Games)
Roslyn Language Services - x86 (HKLM-x32\...\{6970C7E1-F99D-388D-8903-DF8FCE677FED}) (Version: 14.0.25431 - Microsoft Corporation) Hidden
Roslyn Language Services - x86 (HKLM-x32\...\{6C1985E7-E1C5-3A95-86EF-2C62465F15C3}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Scribus 1.4.6 (HKLM-x32\...\Scribus 1.4.6) (Version: 1.4.6 - The Scribus Team)
ShellShock Live (HKLM\...\Steam App 326460) (Version: - kChamp Games)
SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 7.1.0380 - NVIDIA Corporation) Hidden
Skype™ 7.22 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.22.109 - Skype Technologies S.A.)
Space Engineers (HKLM\...\Steam App 244850) (Version: - Keen Software House)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SteamVR Performance Test (HKLM\...\Steam App 323910) (Version: - Valve)
Tabletop Simulator (HKLM\...\Steam App 286160) (Version: - Berserk Games)
Team Explorer for Microsoft Visual Studio 2015 Update 3.1 (HKLM-x32\...\{7A95671A-759E-3B83-B763-4289D1D24D73}) (Version: 14.102.25619 - Microsoft) Hidden
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.72365 - TeamViewer)
TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp)
Teeworlds (HKLM\...\Steam App 380840) (Version: - Teeworlds Team)
Terraria (HKLM\...\Steam App 105600) (Version: - Re-Logic)
Test Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{9EABBFE1-7EED-47D9-8FB8-21D7E4808057}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
The Elder Scrolls III: Morrowind (HKLM\...\Steam App 22320) (Version: - Bethesda Game Studios)
The Elder Scrolls V: Skyrim Special Edition (HKLM\...\Steam App 489830) (Version: - Bethesda Game Studios)
Tropico 5 (HKLM\...\Steam App 245620) (Version: - Haemimont Games)
TypeScript Power Tool (HKLM-x32\...\{465ACA24-B8D6-4FEC-A42D-9EFCB92CD560}) (Version: 1.8.34.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{BA5762C7-D35F-4725-A4BD-525854127018}) (Version: 1.8.36.0 - Microsoft Corporation) Hidden
UE4 Prerequisites (x64) (HKLM\...\{36EAD5CF-44EF-4FCF-8BE1-D96C4835D7A4}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden
UE4 Prerequisites (x64) (HKLM-x32\...\{2890ae6b-90e9-448d-b3e6-97e43c21e2fd}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden
Ultimate Chicken Horse (HKLM\...\Steam App 386940) (Version: - Clever Endeavour Games)
Unity (HKLM-x32\...\Unity) (Version: 5.4.1f1 - Unity Technologies ApS)
Unity Web Player (HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\UnityWebPlayer) (Version: 4.7.1f1 - Unity Technologies ApS)
Unturned (HKLM\...\Steam App 304930) (Version: - Smartly Dressed Games)
Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 27.0 - Ubisoft)
VA-11 Hall-A: Cyberpunk Bartender Action (HKLM\...\Steam App 447530) (Version: - Sukeban Games)
Visual Studio 2015 Update 3 (KB3022398) (HKLM-x32\...\{7a68448b-9cf2-4049-bd73-5875f1aa7ba2}) (Version: 14.0.25420 - Microsoft Corporation)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN)
VS Update core components (HKLM-x32\...\{B2918D01-1D89-34D3-87EF-A28121BC6EB7}) (Version: 14.0.25431 - Microsoft Corporation) Hidden
vs_update3notification (HKLM-x32\...\{AB3DF932-C990-34D4-BF43-970F760DA3CD}) (Version: 14.0.25431 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (HKLM-x32\...\{DB85E7BD-B2DD-43D4-B3C0-23D7B527B597}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{0A3B508E-5638-4471-BCC9-954E1868CB86}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WinRAR 5.31 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
XCOM 2 (HKLM\...\Steam App 268500) (Version: - Firaxis)
Zombie Night Terror (HKLM\...\Steam App 416680) (Version: - NoClip)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ContextMenuHandlers01: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
ContextMenuHandlers01: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ContextMenuHandlers01: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2017-06-18] (Avira Operations GmbH & Co. KG)
ContextMenuHandlers01: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-02-04] (Alexander Roshal)
ContextMenuHandlers01: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers01: [_Movavivc11] -> {1C604495-4D32-476e-8D7E-FBF50F6C80BF} => -> No File
ContextMenuHandlers03: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers04: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ContextMenuHandlers05: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ContextMenuHandlers05: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File
ContextMenuHandlers05: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-02-23] (NVIDIA Corporation)
ContextMenuHandlers06: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
ContextMenuHandlers06: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers06: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2017-06-18] (Avira Operations GmbH & Co. KG)
ContextMenuHandlers06: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-02-04] (Alexander Roshal)
ContextMenuHandlers06: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers06: [_Movavivc11] -> {1C604495-4D32-476e-8D7E-FBF50F6C80BF} => -> No File
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0756EF64-A3C1-4F20-9E7A-6E1B18506313} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-06-21] (NVIDIA Corporation)
Task: {0DDD434F-E24A-4645-B5B5-4A77FFD6B6FE} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {17681F43-1477-469F-8C7A-94B3B44D2C64} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {1AA433CA-E8FF-403E-9547-528AB8C7EDA9} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-06-21] (NVIDIA Corporation)
Task: {1ADC1014-0098-4E1F-BF08-F8A425D271FB} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update 14 => C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe [2016-06-20] (Microsoft Corporation)
Task: {1BF655ED-1496-4D0F-9B9B-6E8AAF3185B4} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {255A06C6-7594-4E1D-96E4-592DEC6E829A} - System32\Tasks\Star-ToAx24 => Rundll32.exe "C:\Program Files\Star-ToAx24\Star-ToAx24.dll",JDGPrMiJC <==== ATTENTION
Task: {288709E1-0A7B-44DB-BFF5-1462E5FC1DCB} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {28D0FDF3-7866-40BC-AD6A-09F0F542D466} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {2C036185-AB4B-482A-87F9-CAEC0A90F3A9} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {31648EA0-1227-4162-9B87-59CA5705E941} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {3571FF7F-D56C-4506-8CF1-62A149A97A45} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {3B475A30-A802-46D8-AF96-CB5AB5AA7773} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-06-07] (Dropbox, Inc.)
Task: {3C823659-E686-4C3D-BA4A-7F269CA24577} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-06-17] (Adobe Systems Incorporated)
Task: {418F9A87-9FC1-4232-8512-3ED91F7993F8} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {44E003F2-7B94-4455-A91F-41FA08019D4A} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {4A2929EB-F3FD-47C5-8264-75DCC4E39061} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {4DD235BD-5A0C-4AD1-A641-5A1E21C0452A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-06] (Piriform Ltd)
Task: {59518195-EBBC-4173-AAD2-002601F13255} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-06-21] (NVIDIA Corporation)
Task: {5AE0FEBD-77E0-4B26-9910-3D156A437471} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5AFDE42E-4A9F-4AD1-BB3A-A21A839469CD} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {6111D6DD-5A8D-4350-AC80-2C1E868D1011} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {67889164-F06A-4BF1-942A-694F5D839603} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-06-21] (NVIDIA Corporation)
Task: {67B7A0FC-5B28-45C2-90A6-10601BC81939} - System32\Tasks\{DF68F4F2-B4C5-402F-97B1-5B5E362F4A49} => C:\Users\Twitchi\Downloads\14101_01.exe
Task: {69575D9F-75C4-47D0-8C7A-73F2229B0D73} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {6EBA685C-247B-41DF-93AF-ED25327F49BB} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-06-21] (NVIDIA Corporation)
Task: {705E542D-C394-42D8-B05F-16BC294813F1} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {71EEC610-B5A8-4857-9A23-D92D3DD1A24D} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-06-21] (NVIDIA Corporation)
Task: {74AD308B-0D14-4EDA-9D4C-7AB306FACCF1} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Twitchi\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
Task: {7B2CC875-378A-4D91-BFAD-56CA0688F4C1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-22] (Google Inc.)
Task: {7E128279-B7DA-4E44-80B7-A0B5D29E1BFC} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {81697416-E24F-4DF8-8AE0-2F033EB0E9DF} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {824C9FD8-7211-4A77-A259-FD0DA03B52FB} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8295DC41-1308-449B-8CC1-A0370E77775F} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {86F02D8B-DA58-4EC5-BB52-BF59B641D269} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-06-21] (NVIDIA Corporation)
Task: {883AD00F-DAA2-4992-A57B-9ADC94AE1775} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {8FA6EDC2-F569-4896-99DD-BE6DE3756ADD} - System32\Tasks\updater => C:\Program Files (x86)\devnull\NetAdapterUpdate\updater.exe
Task: {9128DA50-C693-4FA6-B36A-111847D0455B} - System32\Tasks\1fcf926529d07bef7da3dc8418c67946 => sc start 1fcf926529d07bef7da3dc8418c67946 <==== ATTENTION
Task: {973DD6FF-C1A0-43A0-93C3-E933E816ABDE} - \{7D0C0F47-050B-050A-0A11-0D7D040D1105} -> No File <==== ATTENTION
Task: {9BB41F82-4FA1-4902-B5E8-9768FEA3AF97} - \Microsoft\Windows\Setup\EOONotify -> No File <==== ATTENTION
Task: {A8451BAA-F785-48BA-B300-F0FB74C96169} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {B05CF944-FAE5-4CA7-8162-47284A80DC66} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {B17F07A4-73FB-4C89-975F-8E12E3A553A7} - System32\Tasks\Microsoft\Windows\Windows Error Reporting\ErrorReporting => C:\\ProgramData\\WindowsErrorReporting\\wvermgr.exe [2017-07-09] ()
Task: {B915F852-9F04-4FB7-BD73-12C0468D5A45} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {B93DA0AF-7D88-4020-9062-D841B1DE87C8} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-06-07] (Dropbox, Inc.)
Task: {BBBC70D1-3982-40F9-B88E-FD74B04EBADD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-22] (Google Inc.)
Task: {BD2C355D-8749-4BA1-A052-FB88AC66DF7F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {BDBB96A6-F398-4B99-8E1B-B031058EF7AF} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {D89AB38C-AEC2-4D3B-81A4-336632A706D9} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-06-21] (NVIDIA Corporation)
Task: {DEAA6C4B-7286-453C-858D-849A5AEF9940} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {DFE2E56B-7DAF-49E2-BABA-169EB9BC681E} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {E043820B-DAC9-4A3B-B352-4A1114FB43E3} - \Microsoft\Windows\Setup\gwx\rundetector -> No File <==== ATTENTION
Task: {E30FB40B-AAD5-4244-8681-E30208056AAC} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> No File <==== ATTENTION
Task: {EBEA142C-A0CB-488A-B7A6-BFDEB7F5C097} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {EC37FAB8-77E5-4EC1-B41C-D06679ADBD99} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {F1DDD4BB-FC8C-4BAD-B0AB-0FD6E3DFB14E} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {F3006A62-8673-44CB-8E37-1F05D1D1F71F} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {F338E3DF-22FE-4F16-AAEB-7D1E3F2835A1} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {F7C6E95C-B708-4D2A-ABE6-99669917A169} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {FC4D6796-65C1-4D54-A4A7-F7B147E55708} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-07-07 14:11 - 2017-06-03 11:01 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-10-31 14:29 - 2017-06-21 08:07 - 01267320 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-07-09 20:42 - 2017-06-27 12:06 - 02260432 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-04-27 16:24 - 2017-03-04 07:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-04-27 16:24 - 2017-03-04 07:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-04-27 16:24 - 2017-03-04 07:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-07-07 14:11 - 2017-06-03 09:47 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-07-07 14:11 - 2017-06-03 09:47 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-07-07 14:11 - 2017-06-03 09:51 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-09-25 20:48 - 2016-09-25 20:48 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-04-27 16:23 - 2017-03-04 07:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2015-06-04 06:50 - 2015-06-04 06:50 - 00414424 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\BravoInitializer.dll
2015-06-04 00:02 - 2015-06-04 00:02 - 00019968 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\MXF_SDK_Metadata_AS11_1.3.50_vs10.dll
2015-06-04 00:02 - 2015-06-04 00:02 - 00294912 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\MXF_SDK_MXFIO_AS11_1.3.50_vs10.dll
2015-06-04 00:02 - 2015-06-04 00:02 - 00302592 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\MOG_Framework_2.2.14_vc10.dll
2015-06-04 00:02 - 2015-06-04 00:02 - 03567616 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\mog_xqilla22.dll
2015-06-04 00:03 - 2015-06-04 00:03 - 04044800 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\Plug-ins\Common\Wraptor.prm
2015-06-04 00:02 - 2015-06-04 00:02 - 03499008 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\DNxHDCodec.dll
2015-06-04 00:03 - 2015-06-04 00:03 - 00048128 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\pthreadVC.dll
2016-10-31 14:29 - 2017-06-21 08:07 - 01040504 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2016-04-12 16:37 - 2017-05-17 02:54 - 00678176 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2016-04-12 16:37 - 2016-09-01 02:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll
2016-04-12 16:37 - 2017-07-06 19:29 - 02496800 _____ () C:\Program Files (x86)\Steam\video.dll
2016-04-12 16:37 - 2016-01-27 08:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2016-04-12 16:37 - 2016-01-27 08:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2016-04-12 16:37 - 2016-01-27 08:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2016-04-12 16:37 - 2016-01-27 08:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2016-04-12 16:37 - 2016-01-27 08:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2016-04-12 16:37 - 2016-09-01 02:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2016-04-12 16:37 - 2016-09-01 02:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2016-04-12 16:37 - 2017-07-06 19:29 - 00878368 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2016-04-12 16:37 - 2016-07-04 23:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
2017-01-13 13:47 - 2017-01-04 15:28 - 01958912 _____ () C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\ffmpeg.dll
2017-01-13 13:47 - 2017-01-13 13:47 - 01082880 _____ () \\?\C:\Users\Twitchi\AppData\Roaming\discord\0.0.297\modules\discord_voice\discord_voice.node
2017-01-13 13:47 - 2017-01-13 13:47 - 03750400 _____ () \\?\C:\Users\Twitchi\AppData\Roaming\discord\0.0.297\modules\discord_voice\libdiscord.dll
2017-01-13 13:47 - 2017-01-13 13:47 - 00914432 _____ () \\?\C:\Users\Twitchi\AppData\Roaming\discord\0.0.297\modules\discord_utils\discord_utils.node
2017-01-13 13:47 - 2017-01-13 13:47 - 01127424 _____ () \\?\C:\Users\Twitchi\AppData\Roaming\discord\0.0.297\modules\discord_toaster\discord_toaster.node
2017-05-26 16:25 - 2017-05-26 16:25 - 00044544 _____ () C:\Program Files (x86)\Corsair\Corsair Utility Engine\MacroRecording.dll
2017-05-26 16:27 - 2017-05-26 16:27 - 00199680 _____ () C:\Program Files (x86)\Corsair\Corsair Utility Engine\quazip.dll
2017-05-26 16:37 - 2017-05-26 16:37 - 00086528 _____ () C:\Program Files (x86)\Corsair\Corsair Utility Engine\CorsairAudioDevice.dll
2017-05-26 16:25 - 2017-05-26 16:25 - 00097280 _____ () C:\Program Files (x86)\Corsair\Corsair Utility Engine\zlib.dll
2016-12-01 13:28 - 2016-12-01 13:28 - 01983488 _____ () C:\Program Files (x86)\Corsair\Corsair Utility Engine\libGLESv2.dll
2016-12-01 13:28 - 2016-12-01 13:28 - 00013824 _____ () C:\Program Files (x86)\Corsair\Corsair Utility Engine\libEGL.DLL
2017-01-13 13:47 - 2017-01-04 15:28 - 02278912 _____ () C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\libglesv2.dll
2017-01-13 13:47 - 2017-01-04 15:28 - 00096768 _____ () C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\libegl.dll
2017-07-11 10:38 - 2017-07-11 10:38 - 00148992 _____ () \\?\C:\Users\Twitchi\AppData\Local\Temp\46D9.tmp.node
2017-01-13 13:47 - 2017-04-27 14:19 - 02658296 _____ () \\?\C:\Users\Twitchi\AppData\Roaming\discord\0.0.297\modules\discord_rpc\discord_rpc.node
2017-01-13 13:47 - 2017-03-23 14:56 - 02665976 _____ () \\?\C:\Users\Twitchi\AppData\Roaming\discord\0.0.297\modules\discord_contact_import\discord_contact_import.node
2016-11-01 14:15 - 2017-07-06 18:58 - 73088800 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
2017-06-07 10:28 - 2017-05-17 02:54 - 00678176 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
2016-04-12 16:37 - 2017-07-06 19:29 - 00385824 _____ () C:\Program Files (x86)\Steam\steam.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\dell.com -> dell.com
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2017-07-09 13:11 - 00001146 _____ C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 distribution.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 linkmate.space
127.0.0.1 space1.adminpressure.space
127.0.0.1 trackpressure.website
127.0.0.1 doctorlink.space
127.0.0.1 plugpackdownload.net
127.0.0.1 dscdn.pw
127.0.0.1 beautifllink.xyz
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Twitchi\Documents\newdescktop.png
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\Services: 1fcf926529d07bef7da3dc8418c67946 => 2
MSCONFIG\Services: dmwappushservice => 3
MSCONFIG\Services: Freemake Improver => 2
HKLM\...\StartupApproved\Run32: => "Dropbox"
HKLM\...\StartupApproved\Run32: => "ProductUpdater"
HKLM\...\StartupApproved\Run32: => "AppTrailers"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "1FO9URXZ1LYYE7B"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "PHZ4HIS6ARLZB8H"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "LMP4JQSCQWZQWY7"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "JPJ31VIWRQZQHL4"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "SPZECLLVU9XVG9D"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "CLC2312BGB69IWM"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "JCV3EO7G87DYQGU"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "B639UO00E8VVTO1"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "BandwidthStat"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "aeanjqjos20"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "4uccdotqxhp"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "afwhgsid1je"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "RPSFSEA9WLWMB7G"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{89687627-57DD-4121-BD6D-B0B68001A46E}] => (Allow) C:\Program Files\BitComet\BitComet.exe
FirewallRules: [{FB75BC0D-45AB-4677-95EF-38FC0A0E4BCD}] => (Allow) C:\Program Files\BitComet\BitComet.exe
FirewallRules: [{9D4E511C-1E23-42A9-B045-ACF36306706C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VA-11 HALL-A\VA-11 Hall A.exe
FirewallRules: [{6B861F69-16E0-42B7-B28D-40D44D1B797F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VA-11 HALL-A\VA-11 Hall A.exe
FirewallRules: [{A1331F89-514A-4069-99EA-C2FF8C90D8BF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [{48DEEDC5-51CF-4A19-93FF-DC3F31BB13EB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [{0A68DB34-4881-4EF2-BFA2-CF854066F7D3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\No Man's Sky\Binaries\NMS.exe
FirewallRules: [{FE319DF2-9DCF-4C8E-9902-3047BE622829}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\No Man's Sky\Binaries\NMS.exe
FirewallRules: [{B1BC688E-AF9B-4CF0-806E-8796B7AF9362}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdom New Lands\Kingdom.exe
FirewallRules: [{840DB2B7-18D9-4FCB-9E65-5B58FF70F948}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdom New Lands\Kingdom.exe
FirewallRules: [{9C50549F-8092-4094-ACDE-C7858673B12D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Besiege\Besiege.exe
FirewallRules: [{EB2571B3-6551-450C-AABB-DED3D7CF3095}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Besiege\Besiege.exe
FirewallRules: [{3D86B5A7-455B-4683-8FC7-0ECF765DF11A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{97A1FA36-9C6E-4F3E-9BD8-3CB2446AF740}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{9B1E921F-45D1-4E54-97AB-6EF6AD8F25EF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{984B51E1-FF83-4913-87AA-A56779D97D95}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{5763EFEC-CBC9-403D-B26D-B2EF3C607358}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{E454BE65-A100-4022-BBCE-A44A9086AA59}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{CF1CDD69-4C1F-41CF-97FF-8D871F56A817}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [{21B826BF-192A-4946-A8E9-6BBAE75843DF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [{15EACAF5-92AE-4292-B15E-C792C7327C47}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{054D54FC-8222-41F7-B1E0-396C581422A2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [TCP Query User{67462B66-ECC9-4007-B5CF-8175AE2C4C48}C:\users\twitchi\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\twitchi\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{3CF1460C-96CF-43A7-B059-2CD019BE94EE}C:\users\twitchi\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\twitchi\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{EFB6C6A8-197A-474F-ABAB-6743CD3D5A39}C:\users\twitchi\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\twitchi\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{6FAE8EFF-73FF-4180-BF32-3FA43C0CA689}C:\users\twitchi\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\twitchi\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{06449D96-48A3-4C9D-B12D-C44F7ACA5C88}C:\program files (x86)\unity\editor\unity.exe] => (Allow) C:\program files (x86)\unity\editor\unity.exe
FirewallRules: [UDP Query User{47454D76-07F6-4E3B-9ECD-822678D068D5}C:\program files (x86)\unity\editor\unity.exe] => (Allow) C:\program files (x86)\unity\editor\unity.exe
FirewallRules: [TCP Query User{10B5BE01-E889-49F4-82C3-E8F1B0A3A8D5}C:\program files (x86)\steam\steamapps\common\don't starve together\bin\dontstarve_dedicated_server_nullrenderer.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\don't starve together\bin\dontstarve_dedicated_server_nullrenderer.exe
FirewallRules: [UDP Query User{75A786C8-161D-4B2B-A6A6-7508446DCD6B}C:\program files (x86)\steam\steamapps\common\don't starve together\bin\dontstarve_dedicated_server_nullrenderer.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\don't starve together\bin\dontstarve_dedicated_server_nullrenderer.exe
FirewallRules: [TCP Query User{A8CB4439-3267-4988-9456-EE2486F9E3E5}C:\program files (x86)\unity\monodevelop\bin\monodevelop.exe] => (Allow) C:\program files (x86)\unity\monodevelop\bin\monodevelop.exe
FirewallRules: [UDP Query User{13744E91-8C21-436B-BDE9-84C980172A56}C:\program files (x86)\unity\monodevelop\bin\monodevelop.exe] => (Allow) C:\program files (x86)\unity\monodevelop\bin\monodevelop.exe
FirewallRules: [{BFC4CAB4-3E75-4DE0-996C-9F41D0F94319}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kerbal Space Program\KSP.exe
FirewallRules: [{B6E509BB-1E70-4059-A2F3-1A04DB6190C8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kerbal Space Program\KSP.exe
FirewallRules: [{AAADD6E6-C7D7-4910-B170-99A09073740B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kerbal Space Program\KSP_x64.exe
FirewallRules: [{CFF4C1F4-6AAF-4737-84F7-90E3AF82FD3E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kerbal Space Program\KSP_x64.exe
FirewallRules: [{C7021007-7E07-4AB0-A9D4-E4AF7DD5CAA0}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{50112456-75D0-4CB8-9246-DF7F08FC0D12}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ShellShock Live\ShellShockLive.exe
FirewallRules: [{30AAF8E7-38B0-4FBD-9A1A-E4502D9FD5EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ShellShock Live\ShellShockLive.exe
FirewallRules: [{362A31AB-1B85-4918-89DB-595FB45483D1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{12BBA261-3B55-4BA4-A358-DC66F1B205E2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [TCP Query User{7878FE8E-246C-4332-8135-643019234C23}C:\users\twitchi\desktop\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\desktop\dmpserver\dmpserver.exe
FirewallRules: [UDP Query User{3BFA2A55-4724-4366-9AB4-9CBB39277861}C:\users\twitchi\desktop\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\desktop\dmpserver\dmpserver.exe
FirewallRules: [TCP Query User{FE120D22-C5C7-49FB-9C51-B8A51CA1993F}C:\program files\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\javaw.exe
FirewallRules: [UDP Query User{B28CE296-A992-4CB9-8202-F9F84D5EA22C}C:\program files\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\javaw.exe
FirewallRules: [{13FC5944-0843-4F08-83D2-F50B56F5ACEF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7dLauncher.exe
FirewallRules: [{B15B95B7-A87A-4A67-B3F0-B3E59F464E2D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7dLauncher.exe
FirewallRules: [{1DE3BE15-F34D-4F89-9E1B-2469328E472E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Defcon\defcon.exe
FirewallRules: [{BC2036BE-B07A-4473-93DF-EF1C70AB6C57}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Defcon\defcon.exe
FirewallRules: [{B70EE219-C2D5-4230-BB51-E8BF1348C821}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tropico 5\Tropico5Steam.exe
FirewallRules: [{6380F3DB-1891-40A6-82C6-162B697B7F59}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tropico 5\Tropico5Steam.exe
FirewallRules: [TCP Query User{EF69CF03-AED5-4F26-BE35-1388C2DF261D}C:\program files\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\java.exe
FirewallRules: [UDP Query User{DC4839F7-1D1A-45C9-90FC-CAB06F2BEE23}C:\program files\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\java.exe
FirewallRules: [TCP Query User{42C5C976-8E4E-4229-9849-6677534E2971}C:\users\twitchi\desktop\kerbot wars 1.1.3\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\desktop\kerbot wars 1.1.3\dmpserver\dmpserver.exe
FirewallRules: [UDP Query User{9A08E418-751D-404C-86FD-B72891A55E6E}C:\users\twitchi\desktop\kerbot wars 1.1.3\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\desktop\kerbot wars 1.1.3\dmpserver\dmpserver.exe
FirewallRules: [{E6950FA6-615D-468E-BE15-8EB537F06066}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Zombie Night Terror\znt.exe
FirewallRules: [{7A7F7082-0C99-4C7B-9EF0-674689832559}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Zombie Night Terror\znt.exe
FirewallRules: [{7EB2F5D4-BF4A-48C5-8174-92FBF90B37ED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MiniMetro\MiniMetro.exe
FirewallRules: [{4A19FB91-79C7-4289-A415-0E3CE4146075}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MiniMetro\MiniMetro.exe
FirewallRules: [{9A07E35C-2278-47E6-BE75-E3282E0E5A23}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [TCP Query User{D25FD57A-5FB7-4274-8EAF-29D7F5E5D587}C:\program files\unity\editor\unity.exe] => (Allow) C:\program files\unity\editor\unity.exe
FirewallRules: [UDP Query User{94F3596D-8335-4F14-AC8A-1C4686AF8D50}C:\program files\unity\editor\unity.exe] => (Allow) C:\program files\unity\editor\unity.exe
FirewallRules: [{B8C4127D-8F07-401F-BE5A-DF3F515DF5BB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\klocki\klocki.exe
FirewallRules: [{130F32BE-10D0-46BE-A78D-9AAF7468323F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\klocki\klocki.exe
FirewallRules: [{3408F661-FA40-4E33-A269-7DB39C49BC5F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{93548907-3188-4F35-80A8-DCC033146CF8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [TCP Query User{E70C3ECD-DD15-48F1-AA1C-12EEA707824F}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe
FirewallRules: [UDP Query User{4F9F22E0-F938-4E8B-9453-3D14FF901210}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe
FirewallRules: [{D66A3D75-6496-4122-AFD5-DAD7B598B6ED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim Special Edition\SkyrimSELauncher.exe
FirewallRules: [{A181A080-1DD2-4D6C-9816-5221B2956848}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim Special Edition\SkyrimSELauncher.exe
FirewallRules: [{B8632CCF-C454-4647-AACB-83ACF6DEBB1E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\XCOM 2\Binaries\Win64\Launcher\ModLauncherWPF.exe
FirewallRules: [{CA25C6A9-D1B2-467F-A325-CA5E2A3C95AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\XCOM 2\Binaries\Win64\Launcher\ModLauncherWPF.exe
FirewallRules: [TCP Query User{5CB95EDB-72A6-4A63-BFBE-6A43828AF2FF}C:\program files (x86)\steam\steamapps\common\xcom 2\binaries\win64\xcom2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom 2\binaries\win64\xcom2.exe
FirewallRules: [UDP Query User{DD7344B3-547D-4724-8FC8-FF0133A86B18}C:\program files (x86)\steam\steamapps\common\xcom 2\binaries\win64\xcom2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom 2\binaries\win64\xcom2.exe
FirewallRules: [{69C5EDB4-26A3-4F17-9270-275AF0328F4C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{C285E2EA-E243-43DD-A040-D87BAEE1645C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{1A0621D4-1A2F-446B-AE5A-390C722B3211}C:\program files\windowsapps\arduinollc.arduinoide_1.6.11.0_x64__mdqgnx93n4wtt\java\bin\javaw.exe] => (Allow) C:\program files\windowsapps\arduinollc.arduinoide_1.6.11.0_x64__mdqgnx93n4wtt\java\bin\javaw.exe
FirewallRules: [UDP Query User{69F6CB29-6E7C-42B1-B755-02EF57831F33}C:\program files\windowsapps\arduinollc.arduinoide_1.6.11.0_x64__mdqgnx93n4wtt\java\bin\javaw.exe] => (Allow) C:\program files\windowsapps\arduinollc.arduinoide_1.6.11.0_x64__mdqgnx93n4wtt\java\bin\javaw.exe
FirewallRules: [{58635A94-08EA-46A1-8EB9-E52805D37660}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{39999789-1570-46B8-83D0-46F7A15590AC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{5A795E01-102F-4A43-9FDD-04DC929E3AE0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{C9C0EB1F-FC0C-40D7-B512-5E6375B9FD1A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{BD3DF95C-22AB-4376-BE44-51D426FC6F8B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\tw\teeworlds.exe
FirewallRules: [{F3DC7B06-CE7B-45E2-A075-FB0905C12302}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\tw\teeworlds.exe
FirewallRules: [{1B01F4EA-4A16-4794-BEEB-68300A93C2D3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ASTRONEER Early Access\Astro.exe
FirewallRules: [{B555322E-64C1-4662-A2C1-4A7BD4A35EC0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ASTRONEER Early Access\Astro.exe
FirewallRules: [TCP Query User{182CE1D0-029F-4BBD-B121-C73C4368D3E9}C:\program files (x86)\steam\steamapps\common\astroneer early access\astro\binaries\win64\astro-win64-shipping.exe] => (Block) C:\program files (x86)\steam\steamapps\common\astroneer early access\astro\binaries\win64\astro-win64-shipping.exe
FirewallRules: [UDP Query User{754EDCD0-8B89-436E-A12C-D6162DD80A89}C:\program files (x86)\steam\steamapps\common\astroneer early access\astro\binaries\win64\astro-win64-shipping.exe] => (Block) C:\program files (x86)\steam\steamapps\common\astroneer early access\astro\binaries\win64\astro-win64-shipping.exe
FirewallRules: [{906FB216-71A6-4DE2-847A-51D0DCD42165}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BallisticNG\BallisticNG.exe
FirewallRules: [{D15ED494-A5C2-40CC-88BC-A0A8F52DE6BC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BallisticNG\BallisticNG.exe
FirewallRules: [{42467FC0-A440-40CD-A23F-1BF43EDA57CB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GenitalJousting\GenitalJousting.exe
FirewallRules: [{A8660B34-86FF-4C45-BEC4-971FDE77DB0F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GenitalJousting\GenitalJousting.exe
FirewallRules: [{D8EE974C-5878-43F4-9EC5-41CF96AB02AA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{800C3E2E-4411-4DA0-997F-486278F754D4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{D16F2498-01AE-4350-88DF-3E6F44C0341F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{A7C57EC3-3054-49B6-8B77-5B828DB0E26D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{BDB38034-E140-4327-9DEC-9E886C5D32BB}C:\program files\unity\monodevelop\bin\monodevelop.exe] => (Allow) C:\program files\unity\monodevelop\bin\monodevelop.exe
FirewallRules: [UDP Query User{C387F7FF-D197-4FFA-967F-EBCBEC7B7C70}C:\program files\unity\monodevelop\bin\monodevelop.exe] => (Allow) C:\program files\unity\monodevelop\bin\monodevelop.exe
FirewallRules: [{25C518B1-B835-42D8-A045-4D694F81B646}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned_BE.exe
FirewallRules: [{39E6C73C-0CE9-44B1-A39B-875467D427BC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned_BE.exe
FirewallRules: [{CCB5AD42-FF57-48C4-9259-DE9EABF10CC4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{C46842BB-37BA-415C-9E0A-E183183EC04B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{E02BAABB-6F38-4021-BED8-A8E8C5E8D0F2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{E1006910-7BF2-4E59-B936-1B97C78FF5AF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{E3F0A2A9-BE4D-4135-A039-9DD263221C5C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{1A801293-B7D9-43B6-B3B2-C8169558667B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{5FFD4AED-82CE-4042-B6BE-AA1B54F0FB99}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{BB3237DC-873F-4C20-8663-76884B03878D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mount Your Friends\MountYourFriends.exe
FirewallRules: [{F65F2CD5-E879-47BF-9CB3-31D203EE4231}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mount Your Friends\MountYourFriends.exe
FirewallRules: [TCP Query User{FAE24BB9-99FA-4AEF-9661-E73985F60B9F}C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{86443AD0-39FF-43D0-8809-9A9073E5D60D}C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{340A1E0A-5909-410A-B21C-18A03F552E33}C:\users\twitchi\appdata\local\temp\rar$exa0.387\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\appdata\local\temp\rar$exa0.387\dmpserver\dmpserver.exe
FirewallRules: [UDP Query User{04C47A42-90EC-46C4-8764-3BAB1FB8E026}C:\users\twitchi\appdata\local\temp\rar$exa0.387\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\appdata\local\temp\rar$exa0.387\dmpserver\dmpserver.exe
FirewallRules: [{0871097A-3392-4B50-825F-5107F122C18A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{842098E5-C897-4E77-9C09-BB1AD4655108}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{0E5ADBA2-BAE2-4274-A595-FECB0A48E9A1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hacknet\Hacknet.exe
FirewallRules: [{76983F38-B3F1-4B1B-9497-6EE4F06822B3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hacknet\Hacknet.exe
FirewallRules: [{8ECF29A4-A0F6-4704-BEA2-1B31FC20DDFB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Empyrion - Galactic Survival\EmpyrionLauncher.exe
FirewallRules: [{34EC2593-CED8-4032-A390-95A489FAF2F2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Empyrion - Galactic Survival\EmpyrionLauncher.exe
FirewallRules: [TCP Query User{69315F93-0D91-4758-93D5-330958698994}C:\program files (x86)\steam\steamapps\common\empyrion - galactic survival\empyrion.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\empyrion - galactic survival\empyrion.exe
FirewallRules: [UDP Query User{B0E0F3B3-BE79-4000-ACEB-0379CE06E6BD}C:\program files (x86)\steam\steamapps\common\empyrion - galactic survival\empyrion.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\empyrion - galactic survival\empyrion.exe
FirewallRules: [{872986EE-2F54-4481-9156-E9EFA55AF548}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ultimate Chicken Horse\UltimateChickenHorse.exe
FirewallRules: [{3CB0B640-F477-4BFD-A50F-FFC4DBE61C20}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ultimate Chicken Horse\UltimateChickenHorse.exe
FirewallRules: [{1E314ED1-DE6D-4597-9DE0-8C1E5DAF2091}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FINAL FANTASY VII\FF7_Launcher.exe
FirewallRules: [{61F6B6C4-59A4-4CF0-B7D3-9761BE3AB446}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FINAL FANTASY VII\FF7_Launcher.exe
FirewallRules: [{B32CD367-74D4-4C8A-B73F-EB471F7A250A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\OxygenNotIncluded\OxygenNotIncluded.exe
FirewallRules: [{FF98AF14-DA08-472C-9382-2ADD90FDC7F1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\OxygenNotIncluded\OxygenNotIncluded.exe
FirewallRules: [TCP Query User{D5DA0719-033D-4675-82A4-AD32B14DA37B}C:\users\twitchi\appdata\local\temp\rar$exa0.360\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\appdata\local\temp\rar$exa0.360\dmpserver\dmpserver.exe
FirewallRules: [UDP Query User{B4CB699C-3649-4CA6-84BB-00B99F1B3560}C:\users\twitchi\appdata\local\temp\rar$exa0.360\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\appdata\local\temp\rar$exa0.360\dmpserver\dmpserver.exe
FirewallRules: [TCP Query User{B7B021FB-767C-4B82-B971-368C44A4B8F4}C:\program files (x86)\brackets\node.exe] => (Allow) C:\program files (x86)\brackets\node.exe
FirewallRules: [UDP Query User{EF8027CE-1B47-4C78-BE82-F59D1C306261}C:\program files (x86)\brackets\node.exe] => (Allow) C:\program files (x86)\brackets\node.exe
FirewallRules: [TCP Query User{0F919523-0B7A-4FEA-B8EA-5F1E6453E4AA}C:\users\twitchi\appdata\local\atom\app-1.15.0\resources\app\apm\bin\node.exe] => (Allow) C:\users\twitchi\appdata\local\atom\app-1.15.0\resources\app\apm\bin\node.exe
FirewallRules: [UDP Query User{5058D2A4-F698-4B76-9BC1-B66E9080CF08}C:\users\twitchi\appdata\local\atom\app-1.15.0\resources\app\apm\bin\node.exe] => (Allow) C:\users\twitchi\appdata\local\atom\app-1.15.0\resources\app\apm\bin\node.exe
FirewallRules: [TCP Query User{1641E8DF-63E0-416A-991F-7416BEB672A6}C:\users\twitchi\appdata\local\atom\app-1.16.0\resources\app\apm\bin\node.exe] => (Allow) C:\users\twitchi\appdata\local\atom\app-1.16.0\resources\app\apm\bin\node.exe
FirewallRules: [UDP Query User{FB125E5B-5276-4083-AF49-BBD90A8096B4}C:\users\twitchi\appdata\local\atom\app-1.16.0\resources\app\apm\bin\node.exe] => (Allow) C:\users\twitchi\appdata\local\atom\app-1.16.0\resources\app\apm\bin\node.exe
FirewallRules: [{95DC4930-6414-450B-BAEE-BEB35510F2DA}] => (Allow) C:\Windows KMS Activator Ultimate 2017 v3.3\Windows KMS Activator Ultimate 2017 v3.3.exe
FirewallRules: [{1EE3D683-E14F-45BE-B8F0-032EF5E74261}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{F39CD04C-F644-4E5D-AF11-2B1FF8DFF947}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{F78013C3-175F-4E04-B106-B43A38A0AE95}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons2\Dungeons2.exe
FirewallRules: [{8E22D9C1-D109-4B95-AD1A-BFE9F97F773D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons2\Dungeons2.exe
FirewallRules: [{A8476523-56E1-4945-9402-11FBEAAE8F5E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons2\mono\bin\mono.exe
FirewallRules: [{45691809-A27D-453D-BAB7-C4B9A279962A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons2\mono\bin\mono.exe
FirewallRules: [TCP Query User{30F53C18-0A02-4D6D-9697-027B5F42A694}C:\users\twitchi\desktop\hit and miss\hit and miss.exe] => (Allow) C:\users\twitchi\desktop\hit and miss\hit and miss.exe
FirewallRules: [UDP Query User{5B8B2639-1C89-46CC-BCC0-2370A9689EE2}C:\users\twitchi\desktop\hit and miss\hit and miss.exe] => (Allow) C:\users\twitchi\desktop\hit and miss\hit and miss.exe
FirewallRules: [{4E95F6A3-0F5D-4DE0-B79D-89D838C6D61C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe
FirewallRules: [{926F76F7-0064-4ACC-8716-5F478AFACF8F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe
FirewallRules: [TCP Query User{B52615B5-1153-4FAB-BB05-917DE11C93B5}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [UDP Query User{AE57EFA2-1B77-45B3-AB94-3453AE58E0AD}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [{F9C45424-04F2-41C5-955A-C9CB23BC3C86}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\starbound.exe
FirewallRules: [{CEF4F21C-192A-4D6C-9E35-72B0745F50DB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\starbound.exe
FirewallRules: [{60F9950A-AEED-4B80-9D0D-B6CF40632E9D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\starbound_server.exe
FirewallRules: [{7717526C-EEC7-4098-9AF9-B26126659D6B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\starbound_server.exe
FirewallRules: [{EF917A76-A48E-4C19-8643-C5545A24467F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\mod_uploader.exe
FirewallRules: [{9EB4D0EE-9957-44AD-8A72-04B07FB7E3C9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\mod_uploader.exe
FirewallRules: [{2444CA72-D5F4-40F6-8FF1-1BF4ED8DB1B0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win32\starbound.exe
FirewallRules: [{6B6659FE-02C8-4F3F-971A-90E17838B12B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win32\starbound.exe
FirewallRules: [{EAF91E92-2D9F-401D-89D6-81D1573B77C8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{A6F9385A-3CD6-435B-8A77-6DD4CABE9764}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{275C350A-FBE8-4D06-8501-205F6F292DA5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Broforce\Broforce_beta.exe
FirewallRules: [{2C17F4E4-B1D4-4B03-8476-ABFB97476B70}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Broforce\Broforce_beta.exe
FirewallRules: [{9632AB05-0B81-4CE6-814D-9F71180AA8FF}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{91AAA17F-2E1B-4934-B90D-9953092EF14D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Morrowind\Morrowind Launcher.exe
FirewallRules: [{8BC7AD53-ED40-421D-94D4-21E3BD2B8440}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Morrowind\Morrowind Launcher.exe
FirewallRules: [{CCC2BEED-4592-4507-AEF3-6DDB9BC8323C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{248C06D4-77ED-4045-AD10-E47742B5C12B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{1E77FA91-43E3-4256-B4B7-F09DBFF48F0B}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{BBC314F3-EFA9-4BFC-8FEB-8C7E8F855BEE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Intelligent Design An Evolutionary Sandbox\intelligentdesign.exe
FirewallRules: [{3AB434F0-F98D-4654-A478-F80D824111DE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Intelligent Design An Evolutionary Sandbox\intelligentdesign.exe
FirewallRules: [{4A2DF949-7372-46DE-A347-43B94AC0D7EB}] => (Allow) C:\Users\Twitchi\AppData\Local\Temp\00023971\download\MiniThunderPlatform.exe
FirewallRules: [{CB2AEF91-AAFF-468A-9E7D-DC2A1FBCFC5B}] => (Allow) C:\WINDOWS\system32\rundll32.exe
FirewallRules: [{9BA7772E-574A-413B-B987-72EAD2E071F6}] => (Allow) C:\Windows\System32\rundll32.exe
FirewallRules: [{EEFCD729-894E-4F44-AC31-448054FD47B9}] => (Allow) C:\Windows\System32\rundll32.exe
==================== Restore Points =========================
09-07-2017 13:08:15 Installed Microsoft ISO Downloader Pro 2017 v1.6
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/11/2017 01:33:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app 56540Oprio.Taskify_v1e60k6hyvhk0!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 01:18:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 01:18:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app 56540Oprio.Taskify_v1e60k6hyvhk0!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 01:10:11 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 01:03:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app 56540Oprio.Taskify_v1e60k6hyvhk0!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 01:03:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 01:03:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app Microsoft.WindowsStore_8wekyb3d8bbwe!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 12:58:22 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 12:48:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app 56540Oprio.Taskify_v1e60k6hyvhk0!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 12:48:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
System errors:
=============
Error: (07/11/2017 10:47:40 AM) (Source: DCOM) (EventID: 10010) (User: FRAMEZILLA)
Description: The server App did not register with DCOM within the required timeout.
Error: (07/11/2017 10:37:16 AM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "1053" attempting to start the service DmEnrollmentSvc with arguments "Unavailable" in order to run the server:
Windows.Internal.Management.Enrollment.Enroller
Error: (07/11/2017 10:37:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Client License Service (ClipSVC) service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (07/11/2017 10:37:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Device Management Enrollment Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (07/11/2017 10:37:14 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the ClipSVC service to connect.
Error: (07/11/2017 10:37:11 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the DmEnrollmentSvc service to connect.
Error: (07/11/2017 10:36:39 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
and APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/11/2017 10:34:37 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Avira.ServiceHost service to connect.
Error: (07/11/2017 10:34:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NetPipeActivator service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (07/11/2017 10:34:37 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the NetPipeActivator service to connect.
CodeIntegrity:
===================================
Date: 2017-05-11 22:32:34.659
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
Date: 2017-05-11 22:32:34.658
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
Date: 2017-03-10 14:08:04.151
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
Date: 2017-02-22 15:07:28.977
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-02-22 15:07:28.974
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-02-22 15:07:28.969
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-01-31 02:40:13.909
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
Date: 2017-01-19 19:49:48.912
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
Date: 2016-11-30 01:30:08.274
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
Date: 2016-11-06 20:38:45.780
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
==================== Memory info ===========================
Processor: Intel® Core i7 CPU 870 @ 2.93GHz
Percentage of memory in use: 34%
Total physical RAM: 16375.05 MB
Available physical RAM: 10784.4 MB
Total Virtual: 32759.05 MB
Available Virtual: 26562.85 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:930.97 GB) (Free:277.3 GB) NTFS
Drive d: (New Volume) (Fixed) (Total:1862.89 GB) (Free:533.66 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000)
Partition: GPT.
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 6DB12FA4)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
==================== End of Addition.txt ============================
Ran by Twitchi (11-07-2017 13:43:38)
Running from C:\Users\Twitchi\Desktop
Windows 10 Pro Version 1607 (X64) (2016-09-25 11:29:02)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1265003007-341673947-2575449671-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1265003007-341673947-2575449671-503 - Limited - Disabled)
Guest (S-1-5-21-1265003007-341673947-2575449671-501 - Limited - Enabled)
Twitchi (S-1-5-21-1265003007-341673947-2575449671-1000 - Administrator - Enabled) => C:\Users\Twitchi
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Antivirus (Enabled - Up to date) {B3F630BD-538D-1B4A-14FA-14B63235278F}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Avira Antivirus (Enabled - Up to date) {0897D159-75B7-14C4-2E4A-2FC449B26D32}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7 Days to Die (HKLM\...\Steam App 251570) (Version: - The Fun Pimps)
Adobe Flash Player 26 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 26.0.0.131 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2015 (HKLM-x32\...\{38C72D42-0672-43B1-9E05-E7631684F9A1}) (Version: 9.0.0 - Adobe Systems Incorporated)
Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 378.78 - NVIDIA Corporation) Hidden
Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{0E4C791E-B78E-477D-BD5A-CDD0985BA6EC}) (Version: 7.0.20622.1 - Microsoft Corporation)
ASTRONEER (HKLM\...\Steam App 361420) (Version: - System Era Softworks)
Atom (HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\atom) (Version: 1.16.0 - GitHub Inc.)
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.27.34 - Avira Operations GmbH & Co. KG)
Avira Connect (HKLM-x32\...\{14d00649-a178-473f-bf48-eec016dc4bfa}) (Version: 1.2.89.29905 - Avira Operations GmbH & Co. KG)
Avira Connect (HKLM-x32\...\{271D5399-34AF-4611-BCD9-B09185B2BBE0}) (Version: 1.2.89.29905 - Avira Operations GmbH & Co. KG) Hidden
Azure AD Authentication Connected Service (HKLM-x32\...\{8A1AD070-269F-4A15-AAB5-76AB896EF195}) (Version: 14.0.25420 - Microsoft Corporation) Hidden
AzureTools.Notifications (HKLM-x32\...\{1E5CA362-39B6-4BD0-B9C0-69CF15F0FEA2}) (Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
BallisticNG (HKLM\...\Steam App 473770) (Version: - Neognosis)
Besiege (HKLM\...\Steam App 346010) (Version: - Spiderling Studios)
BitComet 1.42 (HKLM-x32\...\BitComet_x64) (Version: 1.42 - CometNetwork)
Blend for Visual Studio SDK for .NET 4.5 (HKLM-x32\...\{37E53780-3944-4A6A-842F-727128E8616E}) (Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Blender (HKLM\...\{437221A8-91D1-42A0-9E04-0AD64B502374}) (Version: 2.78.1 - Blender Foundation)
Broadcom Gigabit NetLink Controller (HKLM\...\{A84DB02B-9C2B-4272-9D2D-A80E00A56513}) (Version: 12.52.01 - Broadcom Corporation)
Broforce (HKLM\...\Steam App 274190) (Version: - Free Lives)
CCleaner (HKLM\...\CCleaner) (Version: 5.25 - Piriform)
Cities: Skylines (HKLM\...\Steam App 255710) (Version: - Colossal Order Ltd.)
Corsair Utility Engine (HKLM-x32\...\{A9114889-E4D2-4112-B461-22179C0E122C}) (Version: 2.14.67 - Corsair)
Curse (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse)
DEFCON (HKLM\...\Steam App 1520) (Version: - Introversion Software)
Defraggler (HKLM\...\Defraggler) (Version: 2.21 - Piriform)
Discord (HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Discord) (Version: 0.0.297 - Hammer & Chisel, Inc.)
Don't Starve (HKLM\...\Steam App 219740) (Version: - Klei Entertainment)
Don't Starve Together Beta (HKLM\...\Steam App 322330) (Version: - Klei Entertainment)
Dotfuscator and Analytics Community Edition 5.22.0 (HKLM-x32\...\{60018889-9E0F-43E8-9B89-29E8C828B40A}) (Version: 5.22.0.3788 - PreEmptive Solutions) Hidden
Dropbox (HKLM-x32\...\Dropbox) (Version: 29.4.20 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.59.1 - Dropbox, Inc.) Hidden
Dungeons 2 (HKLM\...\Steam App 262280) (Version: - Realmforge Studios)
Empyrion - Galactic Survival (HKLM\...\Steam App 383120) (Version: - Eleon Game Studios)
Fallout: New Vegas (HKLM\...\Steam App 22380) (Version: - Obsidian Entertainment)
FileZilla Client 3.22.2.2 (HKLM-x32\...\FileZilla Client) (Version: 3.22.2.2 - Tim Kosse)
FINAL FANTASY VII (HKLM\...\Steam App 39140) (Version: - Square Enix)
FTL: Faster Than Light (HKLM\...\Steam App 212680) (Version: - Subset Games)
Genital Jousting (HKLM\...\Steam App 469820) (Version: - Free Lives)
GitHub (HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\5f7eb300e2ea4ebf) (Version: 3.3.4.0 - GitHub, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Grand Theft Auto V (HKLM\...\Steam App 271590) (Version: - Rockstar North)
Gtk# for .Net 2.12.26 (HKLM-x32\...\{BC25B808-A11C-4C9F-9C0A-6682E47AAB83}) (Version: 2.12.26 - Xamarin, Inc.)
Hacknet (HKLM\...\Steam App 365450) (Version: - Team Fractal Alligator)
Intelligent Design: An Evolutionary Sandbox (HKLM\...\Steam App 627620) (Version: - Pill Bug Interactive)
Java 8 Update 91 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418091F0}) (Version: 8.0.910.14 - Oracle Corporation)
Kerbal Space Program (HKLM\...\Steam App 220200) (Version: - Squad)
Kerbal Space Program V1.0.4 (HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\Kerbal Space Program V1.0.4) (Version: - )
Kingdom: New Lands (HKLM\...\Steam App 496300) (Version: - Noio)
klocki (HKLM\...\Steam App 499440) (Version: - Maciej Targoni)
Left 4 Dead 2 (HKLM\...\Steam App 550) (Version: - Valve)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (ENU) (HKLM-x32\...\{034547E9-D8FA-49E7-8B9C-4C9861FB9146}) (Version: 4.6.00127 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.25420 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 T-SQL Language Service (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{FC3BB979-AA54-4B60-BBA3-2C4DA6E08D80}) (Version: 12.0.2402.29 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{091CE6AA-2753-4F6E-AD1C-0E875744EB54}) (Version: 12.0.2402.29 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 with Updates (HKLM-x32\...\{79b486b9-c5f0-4096-a00c-8351f59587c2}) (Version: 14.0.25420.1 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{94E1227C-08A9-4962-B388-1F05D89AEA75}) (Version: 3.1238.1962 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mini Metro (HKLM\...\Steam App 287980) (Version: - Dinosaur Polo Club)
Mount Your Friends (HKLM\...\Steam App 296470) (Version: - Stegersaurus Software Inc.)
Mozilla Firefox 54.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 54.0.1 (x86 en-US)) (Version: 54.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 54.0.1.6388 - Mozilla)
MSBuild/NuGet Integration 14.0 (x86) (HKLM-x32\...\{128C1654-3B9E-4959-8BFB-CE6F09C0A01D}) (Version: 14.0.25420 - Microsoft Corporation) Hidden
Multi-Device Hybrid Apps using C# - Templates - ENU (HKLM-x32\...\{12D99739-FFD3-3761-8AA6-F929E0FE407E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
No Man's Sky (HKLM\...\Steam App 275850) (Version: - Hello Games)
NVIDIA GeForce Experience 3.7.0.81 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.7.0.81 - NVIDIA Corporation)
NVIDIA Graphics Driver 378.78 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.78 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.23 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
NvNodejs (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs) (Version: 3.7.0.81 - NVIDIA Corporation) Hidden
NvTelemetry (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry) (Version: 2.6.1.0 - NVIDIA Corporation) Hidden
NvvHci (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci) (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 18.0.1 - OBS Project)
OpenTTD 1.6.1 (HKLM-x32\...\OpenTTD) (Version: 1.6.1 - OpenTTD)
osu! (HKLM-x32\...\{5135db6e-d0e6-452a-9e15-2181940ecaea}) (Version: latest - ppy Pty Ltd)
Oxygen Not Included (HKLM\...\Steam App 457140) (Version: - Klei Entertainment)
PreEmptive Analytics Visual Studio Components (HKLM-x32\...\{436A18DD-5F2C-4B3C-985E-AD3C13B0CC25}) (Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6039 - Realtek Semiconductor Corp.)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.9 - Rockstar Games)
Roslyn Language Services - x86 (HKLM-x32\...\{6970C7E1-F99D-388D-8903-DF8FCE677FED}) (Version: 14.0.25431 - Microsoft Corporation) Hidden
Roslyn Language Services - x86 (HKLM-x32\...\{6C1985E7-E1C5-3A95-86EF-2C62465F15C3}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Scribus 1.4.6 (HKLM-x32\...\Scribus 1.4.6) (Version: 1.4.6 - The Scribus Team)
ShellShock Live (HKLM\...\Steam App 326460) (Version: - kChamp Games)
SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 7.1.0380 - NVIDIA Corporation) Hidden
Skype™ 7.22 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.22.109 - Skype Technologies S.A.)
Space Engineers (HKLM\...\Steam App 244850) (Version: - Keen Software House)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SteamVR Performance Test (HKLM\...\Steam App 323910) (Version: - Valve)
Tabletop Simulator (HKLM\...\Steam App 286160) (Version: - Berserk Games)
Team Explorer for Microsoft Visual Studio 2015 Update 3.1 (HKLM-x32\...\{7A95671A-759E-3B83-B763-4289D1D24D73}) (Version: 14.102.25619 - Microsoft) Hidden
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.72365 - TeamViewer)
TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp)
Teeworlds (HKLM\...\Steam App 380840) (Version: - Teeworlds Team)
Terraria (HKLM\...\Steam App 105600) (Version: - Re-Logic)
Test Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{9EABBFE1-7EED-47D9-8FB8-21D7E4808057}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
The Elder Scrolls III: Morrowind (HKLM\...\Steam App 22320) (Version: - Bethesda Game Studios)
The Elder Scrolls V: Skyrim Special Edition (HKLM\...\Steam App 489830) (Version: - Bethesda Game Studios)
Tropico 5 (HKLM\...\Steam App 245620) (Version: - Haemimont Games)
TypeScript Power Tool (HKLM-x32\...\{465ACA24-B8D6-4FEC-A42D-9EFCB92CD560}) (Version: 1.8.34.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{BA5762C7-D35F-4725-A4BD-525854127018}) (Version: 1.8.36.0 - Microsoft Corporation) Hidden
UE4 Prerequisites (x64) (HKLM\...\{36EAD5CF-44EF-4FCF-8BE1-D96C4835D7A4}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden
UE4 Prerequisites (x64) (HKLM-x32\...\{2890ae6b-90e9-448d-b3e6-97e43c21e2fd}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden
Ultimate Chicken Horse (HKLM\...\Steam App 386940) (Version: - Clever Endeavour Games)
Unity (HKLM-x32\...\Unity) (Version: 5.4.1f1 - Unity Technologies ApS)
Unity Web Player (HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\UnityWebPlayer) (Version: 4.7.1f1 - Unity Technologies ApS)
Unturned (HKLM\...\Steam App 304930) (Version: - Smartly Dressed Games)
Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 27.0 - Ubisoft)
VA-11 Hall-A: Cyberpunk Bartender Action (HKLM\...\Steam App 447530) (Version: - Sukeban Games)
Visual Studio 2015 Update 3 (KB3022398) (HKLM-x32\...\{7a68448b-9cf2-4049-bd73-5875f1aa7ba2}) (Version: 14.0.25420 - Microsoft Corporation)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN)
VS Update core components (HKLM-x32\...\{B2918D01-1D89-34D3-87EF-A28121BC6EB7}) (Version: 14.0.25431 - Microsoft Corporation) Hidden
vs_update3notification (HKLM-x32\...\{AB3DF932-C990-34D4-BF43-970F760DA3CD}) (Version: 14.0.25431 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (HKLM-x32\...\{DB85E7BD-B2DD-43D4-B3C0-23D7B527B597}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{0A3B508E-5638-4471-BCC9-954E1868CB86}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WinRAR 5.31 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
XCOM 2 (HKLM\...\Steam App 268500) (Version: - Firaxis)
Zombie Night Terror (HKLM\...\Steam App 416680) (Version: - NoClip)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ContextMenuHandlers01: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
ContextMenuHandlers01: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ContextMenuHandlers01: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2017-06-18] (Avira Operations GmbH & Co. KG)
ContextMenuHandlers01: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-02-04] (Alexander Roshal)
ContextMenuHandlers01: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers01: [_Movavivc11] -> {1C604495-4D32-476e-8D7E-FBF50F6C80BF} => -> No File
ContextMenuHandlers03: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers04: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ContextMenuHandlers05: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ContextMenuHandlers05: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File
ContextMenuHandlers05: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-02-23] (NVIDIA Corporation)
ContextMenuHandlers06: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
ContextMenuHandlers06: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers06: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2017-06-18] (Avira Operations GmbH & Co. KG)
ContextMenuHandlers06: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-02-04] (Alexander Roshal)
ContextMenuHandlers06: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers06: [_Movavivc11] -> {1C604495-4D32-476e-8D7E-FBF50F6C80BF} => -> No File
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0756EF64-A3C1-4F20-9E7A-6E1B18506313} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-06-21] (NVIDIA Corporation)
Task: {0DDD434F-E24A-4645-B5B5-4A77FFD6B6FE} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {17681F43-1477-469F-8C7A-94B3B44D2C64} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {1AA433CA-E8FF-403E-9547-528AB8C7EDA9} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-06-21] (NVIDIA Corporation)
Task: {1ADC1014-0098-4E1F-BF08-F8A425D271FB} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update 14 => C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe [2016-06-20] (Microsoft Corporation)
Task: {1BF655ED-1496-4D0F-9B9B-6E8AAF3185B4} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {255A06C6-7594-4E1D-96E4-592DEC6E829A} - System32\Tasks\Star-ToAx24 => Rundll32.exe "C:\Program Files\Star-ToAx24\Star-ToAx24.dll",JDGPrMiJC <==== ATTENTION
Task: {288709E1-0A7B-44DB-BFF5-1462E5FC1DCB} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {28D0FDF3-7866-40BC-AD6A-09F0F542D466} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {2C036185-AB4B-482A-87F9-CAEC0A90F3A9} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {31648EA0-1227-4162-9B87-59CA5705E941} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {3571FF7F-D56C-4506-8CF1-62A149A97A45} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {3B475A30-A802-46D8-AF96-CB5AB5AA7773} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-06-07] (Dropbox, Inc.)
Task: {3C823659-E686-4C3D-BA4A-7F269CA24577} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-06-17] (Adobe Systems Incorporated)
Task: {418F9A87-9FC1-4232-8512-3ED91F7993F8} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {44E003F2-7B94-4455-A91F-41FA08019D4A} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {4A2929EB-F3FD-47C5-8264-75DCC4E39061} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {4DD235BD-5A0C-4AD1-A641-5A1E21C0452A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-06] (Piriform Ltd)
Task: {59518195-EBBC-4173-AAD2-002601F13255} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-06-21] (NVIDIA Corporation)
Task: {5AE0FEBD-77E0-4B26-9910-3D156A437471} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5AFDE42E-4A9F-4AD1-BB3A-A21A839469CD} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {6111D6DD-5A8D-4350-AC80-2C1E868D1011} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {67889164-F06A-4BF1-942A-694F5D839603} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-06-21] (NVIDIA Corporation)
Task: {67B7A0FC-5B28-45C2-90A6-10601BC81939} - System32\Tasks\{DF68F4F2-B4C5-402F-97B1-5B5E362F4A49} => C:\Users\Twitchi\Downloads\14101_01.exe
Task: {69575D9F-75C4-47D0-8C7A-73F2229B0D73} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {6EBA685C-247B-41DF-93AF-ED25327F49BB} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-06-21] (NVIDIA Corporation)
Task: {705E542D-C394-42D8-B05F-16BC294813F1} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {71EEC610-B5A8-4857-9A23-D92D3DD1A24D} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-06-21] (NVIDIA Corporation)
Task: {74AD308B-0D14-4EDA-9D4C-7AB306FACCF1} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Twitchi\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
Task: {7B2CC875-378A-4D91-BFAD-56CA0688F4C1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-22] (Google Inc.)
Task: {7E128279-B7DA-4E44-80B7-A0B5D29E1BFC} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {81697416-E24F-4DF8-8AE0-2F033EB0E9DF} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {824C9FD8-7211-4A77-A259-FD0DA03B52FB} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8295DC41-1308-449B-8CC1-A0370E77775F} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {86F02D8B-DA58-4EC5-BB52-BF59B641D269} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-06-21] (NVIDIA Corporation)
Task: {883AD00F-DAA2-4992-A57B-9ADC94AE1775} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {8FA6EDC2-F569-4896-99DD-BE6DE3756ADD} - System32\Tasks\updater => C:\Program Files (x86)\devnull\NetAdapterUpdate\updater.exe
Task: {9128DA50-C693-4FA6-B36A-111847D0455B} - System32\Tasks\1fcf926529d07bef7da3dc8418c67946 => sc start 1fcf926529d07bef7da3dc8418c67946 <==== ATTENTION
Task: {973DD6FF-C1A0-43A0-93C3-E933E816ABDE} - \{7D0C0F47-050B-050A-0A11-0D7D040D1105} -> No File <==== ATTENTION
Task: {9BB41F82-4FA1-4902-B5E8-9768FEA3AF97} - \Microsoft\Windows\Setup\EOONotify -> No File <==== ATTENTION
Task: {A8451BAA-F785-48BA-B300-F0FB74C96169} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {B05CF944-FAE5-4CA7-8162-47284A80DC66} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {B17F07A4-73FB-4C89-975F-8E12E3A553A7} - System32\Tasks\Microsoft\Windows\Windows Error Reporting\ErrorReporting => C:\\ProgramData\\WindowsErrorReporting\\wvermgr.exe [2017-07-09] ()
Task: {B915F852-9F04-4FB7-BD73-12C0468D5A45} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {B93DA0AF-7D88-4020-9062-D841B1DE87C8} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-06-07] (Dropbox, Inc.)
Task: {BBBC70D1-3982-40F9-B88E-FD74B04EBADD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-22] (Google Inc.)
Task: {BD2C355D-8749-4BA1-A052-FB88AC66DF7F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {BDBB96A6-F398-4B99-8E1B-B031058EF7AF} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {D89AB38C-AEC2-4D3B-81A4-336632A706D9} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-06-21] (NVIDIA Corporation)
Task: {DEAA6C4B-7286-453C-858D-849A5AEF9940} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {DFE2E56B-7DAF-49E2-BABA-169EB9BC681E} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {E043820B-DAC9-4A3B-B352-4A1114FB43E3} - \Microsoft\Windows\Setup\gwx\rundetector -> No File <==== ATTENTION
Task: {E30FB40B-AAD5-4244-8681-E30208056AAC} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> No File <==== ATTENTION
Task: {EBEA142C-A0CB-488A-B7A6-BFDEB7F5C097} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {EC37FAB8-77E5-4EC1-B41C-D06679ADBD99} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {F1DDD4BB-FC8C-4BAD-B0AB-0FD6E3DFB14E} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {F3006A62-8673-44CB-8E37-1F05D1D1F71F} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {F338E3DF-22FE-4F16-AAEB-7D1E3F2835A1} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {F7C6E95C-B708-4D2A-ABE6-99669917A169} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {FC4D6796-65C1-4D54-A4A7-F7B147E55708} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-07-07 14:11 - 2017-06-03 11:01 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-10-31 14:29 - 2017-06-21 08:07 - 01267320 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-07-09 20:42 - 2017-06-27 12:06 - 02260432 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-04-27 16:24 - 2017-03-04 07:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-04-27 16:24 - 2017-03-04 07:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-04-27 16:24 - 2017-03-04 07:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-07-07 14:11 - 2017-06-03 09:47 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-07-07 14:11 - 2017-06-03 09:47 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-07-07 14:11 - 2017-06-03 09:51 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-09-25 20:48 - 2016-09-25 20:48 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-04-27 16:23 - 2017-03-04 07:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2015-06-04 06:50 - 2015-06-04 06:50 - 00414424 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\BravoInitializer.dll
2015-06-04 00:02 - 2015-06-04 00:02 - 00019968 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\MXF_SDK_Metadata_AS11_1.3.50_vs10.dll
2015-06-04 00:02 - 2015-06-04 00:02 - 00294912 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\MXF_SDK_MXFIO_AS11_1.3.50_vs10.dll
2015-06-04 00:02 - 2015-06-04 00:02 - 00302592 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\MOG_Framework_2.2.14_vc10.dll
2015-06-04 00:02 - 2015-06-04 00:02 - 03567616 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\mog_xqilla22.dll
2015-06-04 00:03 - 2015-06-04 00:03 - 04044800 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\Plug-ins\Common\Wraptor.prm
2015-06-04 00:02 - 2015-06-04 00:02 - 03499008 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\DNxHDCodec.dll
2015-06-04 00:03 - 2015-06-04 00:03 - 00048128 _____ () C:\Program Files\Adobe\Adobe Premiere Pro CC 2015\pthreadVC.dll
2016-10-31 14:29 - 2017-06-21 08:07 - 01040504 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2016-04-12 16:37 - 2017-05-17 02:54 - 00678176 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2016-04-12 16:37 - 2016-09-01 02:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll
2016-04-12 16:37 - 2017-07-06 19:29 - 02496800 _____ () C:\Program Files (x86)\Steam\video.dll
2016-04-12 16:37 - 2016-01-27 08:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2016-04-12 16:37 - 2016-01-27 08:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2016-04-12 16:37 - 2016-01-27 08:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2016-04-12 16:37 - 2016-01-27 08:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2016-04-12 16:37 - 2016-01-27 08:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2016-04-12 16:37 - 2016-09-01 02:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2016-04-12 16:37 - 2016-09-01 02:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2016-04-12 16:37 - 2017-07-06 19:29 - 00878368 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2016-04-12 16:37 - 2016-07-04 23:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
2017-01-13 13:47 - 2017-01-04 15:28 - 01958912 _____ () C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\ffmpeg.dll
2017-01-13 13:47 - 2017-01-13 13:47 - 01082880 _____ () \\?\C:\Users\Twitchi\AppData\Roaming\discord\0.0.297\modules\discord_voice\discord_voice.node
2017-01-13 13:47 - 2017-01-13 13:47 - 03750400 _____ () \\?\C:\Users\Twitchi\AppData\Roaming\discord\0.0.297\modules\discord_voice\libdiscord.dll
2017-01-13 13:47 - 2017-01-13 13:47 - 00914432 _____ () \\?\C:\Users\Twitchi\AppData\Roaming\discord\0.0.297\modules\discord_utils\discord_utils.node
2017-01-13 13:47 - 2017-01-13 13:47 - 01127424 _____ () \\?\C:\Users\Twitchi\AppData\Roaming\discord\0.0.297\modules\discord_toaster\discord_toaster.node
2017-05-26 16:25 - 2017-05-26 16:25 - 00044544 _____ () C:\Program Files (x86)\Corsair\Corsair Utility Engine\MacroRecording.dll
2017-05-26 16:27 - 2017-05-26 16:27 - 00199680 _____ () C:\Program Files (x86)\Corsair\Corsair Utility Engine\quazip.dll
2017-05-26 16:37 - 2017-05-26 16:37 - 00086528 _____ () C:\Program Files (x86)\Corsair\Corsair Utility Engine\CorsairAudioDevice.dll
2017-05-26 16:25 - 2017-05-26 16:25 - 00097280 _____ () C:\Program Files (x86)\Corsair\Corsair Utility Engine\zlib.dll
2016-12-01 13:28 - 2016-12-01 13:28 - 01983488 _____ () C:\Program Files (x86)\Corsair\Corsair Utility Engine\libGLESv2.dll
2016-12-01 13:28 - 2016-12-01 13:28 - 00013824 _____ () C:\Program Files (x86)\Corsair\Corsair Utility Engine\libEGL.DLL
2017-01-13 13:47 - 2017-01-04 15:28 - 02278912 _____ () C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\libglesv2.dll
2017-01-13 13:47 - 2017-01-04 15:28 - 00096768 _____ () C:\Users\Twitchi\AppData\Local\Discord\app-0.0.297\libegl.dll
2017-07-11 10:38 - 2017-07-11 10:38 - 00148992 _____ () \\?\C:\Users\Twitchi\AppData\Local\Temp\46D9.tmp.node
2017-01-13 13:47 - 2017-04-27 14:19 - 02658296 _____ () \\?\C:\Users\Twitchi\AppData\Roaming\discord\0.0.297\modules\discord_rpc\discord_rpc.node
2017-01-13 13:47 - 2017-03-23 14:56 - 02665976 _____ () \\?\C:\Users\Twitchi\AppData\Roaming\discord\0.0.297\modules\discord_contact_import\discord_contact_import.node
2016-11-01 14:15 - 2017-07-06 18:58 - 73088800 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
2017-06-07 10:28 - 2017-05-17 02:54 - 00678176 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
2016-04-12 16:37 - 2017-07-06 19:29 - 00385824 _____ () C:\Program Files (x86)\Steam\steam.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\dell.com -> dell.com
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2017-07-09 13:11 - 00001146 _____ C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 distribution.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 linkmate.space
127.0.0.1 space1.adminpressure.space
127.0.0.1 trackpressure.website
127.0.0.1 doctorlink.space
127.0.0.1 plugpackdownload.net
127.0.0.1 dscdn.pw
127.0.0.1 beautifllink.xyz
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Twitchi\Documents\newdescktop.png
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\Services: 1fcf926529d07bef7da3dc8418c67946 => 2
MSCONFIG\Services: dmwappushservice => 3
MSCONFIG\Services: Freemake Improver => 2
HKLM\...\StartupApproved\Run32: => "Dropbox"
HKLM\...\StartupApproved\Run32: => "ProductUpdater"
HKLM\...\StartupApproved\Run32: => "AppTrailers"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "1FO9URXZ1LYYE7B"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "PHZ4HIS6ARLZB8H"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "LMP4JQSCQWZQWY7"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "JPJ31VIWRQZQHL4"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "SPZECLLVU9XVG9D"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "CLC2312BGB69IWM"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "JCV3EO7G87DYQGU"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "B639UO00E8VVTO1"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "BandwidthStat"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "aeanjqjos20"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "4uccdotqxhp"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "afwhgsid1je"
HKU\S-1-5-21-1265003007-341673947-2575449671-1000\...\StartupApproved\Run: => "RPSFSEA9WLWMB7G"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{89687627-57DD-4121-BD6D-B0B68001A46E}] => (Allow) C:\Program Files\BitComet\BitComet.exe
FirewallRules: [{FB75BC0D-45AB-4677-95EF-38FC0A0E4BCD}] => (Allow) C:\Program Files\BitComet\BitComet.exe
FirewallRules: [{9D4E511C-1E23-42A9-B045-ACF36306706C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VA-11 HALL-A\VA-11 Hall A.exe
FirewallRules: [{6B861F69-16E0-42B7-B28D-40D44D1B797F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VA-11 HALL-A\VA-11 Hall A.exe
FirewallRules: [{A1331F89-514A-4069-99EA-C2FF8C90D8BF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [{48DEEDC5-51CF-4A19-93FF-DC3F31BB13EB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [{0A68DB34-4881-4EF2-BFA2-CF854066F7D3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\No Man's Sky\Binaries\NMS.exe
FirewallRules: [{FE319DF2-9DCF-4C8E-9902-3047BE622829}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\No Man's Sky\Binaries\NMS.exe
FirewallRules: [{B1BC688E-AF9B-4CF0-806E-8796B7AF9362}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdom New Lands\Kingdom.exe
FirewallRules: [{840DB2B7-18D9-4FCB-9E65-5B58FF70F948}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdom New Lands\Kingdom.exe
FirewallRules: [{9C50549F-8092-4094-ACDE-C7858673B12D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Besiege\Besiege.exe
FirewallRules: [{EB2571B3-6551-450C-AABB-DED3D7CF3095}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Besiege\Besiege.exe
FirewallRules: [{3D86B5A7-455B-4683-8FC7-0ECF765DF11A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{97A1FA36-9C6E-4F3E-9BD8-3CB2446AF740}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{9B1E921F-45D1-4E54-97AB-6EF6AD8F25EF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{984B51E1-FF83-4913-87AA-A56779D97D95}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{5763EFEC-CBC9-403D-B26D-B2EF3C607358}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{E454BE65-A100-4022-BBCE-A44A9086AA59}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{CF1CDD69-4C1F-41CF-97FF-8D871F56A817}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [{21B826BF-192A-4946-A8E9-6BBAE75843DF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [{15EACAF5-92AE-4292-B15E-C792C7327C47}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{054D54FC-8222-41F7-B1E0-396C581422A2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [TCP Query User{67462B66-ECC9-4007-B5CF-8175AE2C4C48}C:\users\twitchi\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\twitchi\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{3CF1460C-96CF-43A7-B059-2CD019BE94EE}C:\users\twitchi\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\twitchi\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{EFB6C6A8-197A-474F-ABAB-6743CD3D5A39}C:\users\twitchi\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\twitchi\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{6FAE8EFF-73FF-4180-BF32-3FA43C0CA689}C:\users\twitchi\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\twitchi\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{06449D96-48A3-4C9D-B12D-C44F7ACA5C88}C:\program files (x86)\unity\editor\unity.exe] => (Allow) C:\program files (x86)\unity\editor\unity.exe
FirewallRules: [UDP Query User{47454D76-07F6-4E3B-9ECD-822678D068D5}C:\program files (x86)\unity\editor\unity.exe] => (Allow) C:\program files (x86)\unity\editor\unity.exe
FirewallRules: [TCP Query User{10B5BE01-E889-49F4-82C3-E8F1B0A3A8D5}C:\program files (x86)\steam\steamapps\common\don't starve together\bin\dontstarve_dedicated_server_nullrenderer.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\don't starve together\bin\dontstarve_dedicated_server_nullrenderer.exe
FirewallRules: [UDP Query User{75A786C8-161D-4B2B-A6A6-7508446DCD6B}C:\program files (x86)\steam\steamapps\common\don't starve together\bin\dontstarve_dedicated_server_nullrenderer.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\don't starve together\bin\dontstarve_dedicated_server_nullrenderer.exe
FirewallRules: [TCP Query User{A8CB4439-3267-4988-9456-EE2486F9E3E5}C:\program files (x86)\unity\monodevelop\bin\monodevelop.exe] => (Allow) C:\program files (x86)\unity\monodevelop\bin\monodevelop.exe
FirewallRules: [UDP Query User{13744E91-8C21-436B-BDE9-84C980172A56}C:\program files (x86)\unity\monodevelop\bin\monodevelop.exe] => (Allow) C:\program files (x86)\unity\monodevelop\bin\monodevelop.exe
FirewallRules: [{BFC4CAB4-3E75-4DE0-996C-9F41D0F94319}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kerbal Space Program\KSP.exe
FirewallRules: [{B6E509BB-1E70-4059-A2F3-1A04DB6190C8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kerbal Space Program\KSP.exe
FirewallRules: [{AAADD6E6-C7D7-4910-B170-99A09073740B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kerbal Space Program\KSP_x64.exe
FirewallRules: [{CFF4C1F4-6AAF-4737-84F7-90E3AF82FD3E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kerbal Space Program\KSP_x64.exe
FirewallRules: [{C7021007-7E07-4AB0-A9D4-E4AF7DD5CAA0}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{50112456-75D0-4CB8-9246-DF7F08FC0D12}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ShellShock Live\ShellShockLive.exe
FirewallRules: [{30AAF8E7-38B0-4FBD-9A1A-E4502D9FD5EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ShellShock Live\ShellShockLive.exe
FirewallRules: [{362A31AB-1B85-4918-89DB-595FB45483D1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{12BBA261-3B55-4BA4-A358-DC66F1B205E2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [TCP Query User{7878FE8E-246C-4332-8135-643019234C23}C:\users\twitchi\desktop\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\desktop\dmpserver\dmpserver.exe
FirewallRules: [UDP Query User{3BFA2A55-4724-4366-9AB4-9CBB39277861}C:\users\twitchi\desktop\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\desktop\dmpserver\dmpserver.exe
FirewallRules: [TCP Query User{FE120D22-C5C7-49FB-9C51-B8A51CA1993F}C:\program files\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\javaw.exe
FirewallRules: [UDP Query User{B28CE296-A992-4CB9-8202-F9F84D5EA22C}C:\program files\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\javaw.exe
FirewallRules: [{13FC5944-0843-4F08-83D2-F50B56F5ACEF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7dLauncher.exe
FirewallRules: [{B15B95B7-A87A-4A67-B3F0-B3E59F464E2D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7dLauncher.exe
FirewallRules: [{1DE3BE15-F34D-4F89-9E1B-2469328E472E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Defcon\defcon.exe
FirewallRules: [{BC2036BE-B07A-4473-93DF-EF1C70AB6C57}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Defcon\defcon.exe
FirewallRules: [{B70EE219-C2D5-4230-BB51-E8BF1348C821}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tropico 5\Tropico5Steam.exe
FirewallRules: [{6380F3DB-1891-40A6-82C6-162B697B7F59}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tropico 5\Tropico5Steam.exe
FirewallRules: [TCP Query User{EF69CF03-AED5-4F26-BE35-1388C2DF261D}C:\program files\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\java.exe
FirewallRules: [UDP Query User{DC4839F7-1D1A-45C9-90FC-CAB06F2BEE23}C:\program files\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\java.exe
FirewallRules: [TCP Query User{42C5C976-8E4E-4229-9849-6677534E2971}C:\users\twitchi\desktop\kerbot wars 1.1.3\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\desktop\kerbot wars 1.1.3\dmpserver\dmpserver.exe
FirewallRules: [UDP Query User{9A08E418-751D-404C-86FD-B72891A55E6E}C:\users\twitchi\desktop\kerbot wars 1.1.3\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\desktop\kerbot wars 1.1.3\dmpserver\dmpserver.exe
FirewallRules: [{E6950FA6-615D-468E-BE15-8EB537F06066}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Zombie Night Terror\znt.exe
FirewallRules: [{7A7F7082-0C99-4C7B-9EF0-674689832559}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Zombie Night Terror\znt.exe
FirewallRules: [{7EB2F5D4-BF4A-48C5-8174-92FBF90B37ED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MiniMetro\MiniMetro.exe
FirewallRules: [{4A19FB91-79C7-4289-A415-0E3CE4146075}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MiniMetro\MiniMetro.exe
FirewallRules: [{9A07E35C-2278-47E6-BE75-E3282E0E5A23}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [TCP Query User{D25FD57A-5FB7-4274-8EAF-29D7F5E5D587}C:\program files\unity\editor\unity.exe] => (Allow) C:\program files\unity\editor\unity.exe
FirewallRules: [UDP Query User{94F3596D-8335-4F14-AC8A-1C4686AF8D50}C:\program files\unity\editor\unity.exe] => (Allow) C:\program files\unity\editor\unity.exe
FirewallRules: [{B8C4127D-8F07-401F-BE5A-DF3F515DF5BB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\klocki\klocki.exe
FirewallRules: [{130F32BE-10D0-46BE-A78D-9AAF7468323F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\klocki\klocki.exe
FirewallRules: [{3408F661-FA40-4E33-A269-7DB39C49BC5F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{93548907-3188-4F35-80A8-DCC033146CF8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [TCP Query User{E70C3ECD-DD15-48F1-AA1C-12EEA707824F}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe
FirewallRules: [UDP Query User{4F9F22E0-F938-4E8B-9453-3D14FF901210}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe
FirewallRules: [{D66A3D75-6496-4122-AFD5-DAD7B598B6ED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim Special Edition\SkyrimSELauncher.exe
FirewallRules: [{A181A080-1DD2-4D6C-9816-5221B2956848}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim Special Edition\SkyrimSELauncher.exe
FirewallRules: [{B8632CCF-C454-4647-AACB-83ACF6DEBB1E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\XCOM 2\Binaries\Win64\Launcher\ModLauncherWPF.exe
FirewallRules: [{CA25C6A9-D1B2-467F-A325-CA5E2A3C95AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\XCOM 2\Binaries\Win64\Launcher\ModLauncherWPF.exe
FirewallRules: [TCP Query User{5CB95EDB-72A6-4A63-BFBE-6A43828AF2FF}C:\program files (x86)\steam\steamapps\common\xcom 2\binaries\win64\xcom2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom 2\binaries\win64\xcom2.exe
FirewallRules: [UDP Query User{DD7344B3-547D-4724-8FC8-FF0133A86B18}C:\program files (x86)\steam\steamapps\common\xcom 2\binaries\win64\xcom2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom 2\binaries\win64\xcom2.exe
FirewallRules: [{69C5EDB4-26A3-4F17-9270-275AF0328F4C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{C285E2EA-E243-43DD-A040-D87BAEE1645C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{1A0621D4-1A2F-446B-AE5A-390C722B3211}C:\program files\windowsapps\arduinollc.arduinoide_1.6.11.0_x64__mdqgnx93n4wtt\java\bin\javaw.exe] => (Allow) C:\program files\windowsapps\arduinollc.arduinoide_1.6.11.0_x64__mdqgnx93n4wtt\java\bin\javaw.exe
FirewallRules: [UDP Query User{69F6CB29-6E7C-42B1-B755-02EF57831F33}C:\program files\windowsapps\arduinollc.arduinoide_1.6.11.0_x64__mdqgnx93n4wtt\java\bin\javaw.exe] => (Allow) C:\program files\windowsapps\arduinollc.arduinoide_1.6.11.0_x64__mdqgnx93n4wtt\java\bin\javaw.exe
FirewallRules: [{58635A94-08EA-46A1-8EB9-E52805D37660}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{39999789-1570-46B8-83D0-46F7A15590AC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{5A795E01-102F-4A43-9FDD-04DC929E3AE0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{C9C0EB1F-FC0C-40D7-B512-5E6375B9FD1A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{BD3DF95C-22AB-4376-BE44-51D426FC6F8B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\tw\teeworlds.exe
FirewallRules: [{F3DC7B06-CE7B-45E2-A075-FB0905C12302}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Teeworlds\tw\teeworlds.exe
FirewallRules: [{1B01F4EA-4A16-4794-BEEB-68300A93C2D3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ASTRONEER Early Access\Astro.exe
FirewallRules: [{B555322E-64C1-4662-A2C1-4A7BD4A35EC0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ASTRONEER Early Access\Astro.exe
FirewallRules: [TCP Query User{182CE1D0-029F-4BBD-B121-C73C4368D3E9}C:\program files (x86)\steam\steamapps\common\astroneer early access\astro\binaries\win64\astro-win64-shipping.exe] => (Block) C:\program files (x86)\steam\steamapps\common\astroneer early access\astro\binaries\win64\astro-win64-shipping.exe
FirewallRules: [UDP Query User{754EDCD0-8B89-436E-A12C-D6162DD80A89}C:\program files (x86)\steam\steamapps\common\astroneer early access\astro\binaries\win64\astro-win64-shipping.exe] => (Block) C:\program files (x86)\steam\steamapps\common\astroneer early access\astro\binaries\win64\astro-win64-shipping.exe
FirewallRules: [{906FB216-71A6-4DE2-847A-51D0DCD42165}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BallisticNG\BallisticNG.exe
FirewallRules: [{D15ED494-A5C2-40CC-88BC-A0A8F52DE6BC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BallisticNG\BallisticNG.exe
FirewallRules: [{42467FC0-A440-40CD-A23F-1BF43EDA57CB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GenitalJousting\GenitalJousting.exe
FirewallRules: [{A8660B34-86FF-4C45-BEC4-971FDE77DB0F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GenitalJousting\GenitalJousting.exe
FirewallRules: [{D8EE974C-5878-43F4-9EC5-41CF96AB02AA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{800C3E2E-4411-4DA0-997F-486278F754D4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{D16F2498-01AE-4350-88DF-3E6F44C0341F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{A7C57EC3-3054-49B6-8B77-5B828DB0E26D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{BDB38034-E140-4327-9DEC-9E886C5D32BB}C:\program files\unity\monodevelop\bin\monodevelop.exe] => (Allow) C:\program files\unity\monodevelop\bin\monodevelop.exe
FirewallRules: [UDP Query User{C387F7FF-D197-4FFA-967F-EBCBEC7B7C70}C:\program files\unity\monodevelop\bin\monodevelop.exe] => (Allow) C:\program files\unity\monodevelop\bin\monodevelop.exe
FirewallRules: [{25C518B1-B835-42D8-A045-4D694F81B646}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned_BE.exe
FirewallRules: [{39E6C73C-0CE9-44B1-A39B-875467D427BC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned_BE.exe
FirewallRules: [{CCB5AD42-FF57-48C4-9259-DE9EABF10CC4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{C46842BB-37BA-415C-9E0A-E183183EC04B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{E02BAABB-6F38-4021-BED8-A8E8C5E8D0F2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{E1006910-7BF2-4E59-B936-1B97C78FF5AF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{E3F0A2A9-BE4D-4135-A039-9DD263221C5C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{1A801293-B7D9-43B6-B3B2-C8169558667B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{5FFD4AED-82CE-4042-B6BE-AA1B54F0FB99}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{BB3237DC-873F-4C20-8663-76884B03878D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mount Your Friends\MountYourFriends.exe
FirewallRules: [{F65F2CD5-E879-47BF-9CB3-31D203EE4231}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mount Your Friends\MountYourFriends.exe
FirewallRules: [TCP Query User{FAE24BB9-99FA-4AEF-9661-E73985F60B9F}C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{86443AD0-39FF-43D0-8809-9A9073E5D60D}C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{340A1E0A-5909-410A-B21C-18A03F552E33}C:\users\twitchi\appdata\local\temp\rar$exa0.387\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\appdata\local\temp\rar$exa0.387\dmpserver\dmpserver.exe
FirewallRules: [UDP Query User{04C47A42-90EC-46C4-8764-3BAB1FB8E026}C:\users\twitchi\appdata\local\temp\rar$exa0.387\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\appdata\local\temp\rar$exa0.387\dmpserver\dmpserver.exe
FirewallRules: [{0871097A-3392-4B50-825F-5107F122C18A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{842098E5-C897-4E77-9C09-BB1AD4655108}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{0E5ADBA2-BAE2-4274-A595-FECB0A48E9A1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hacknet\Hacknet.exe
FirewallRules: [{76983F38-B3F1-4B1B-9497-6EE4F06822B3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hacknet\Hacknet.exe
FirewallRules: [{8ECF29A4-A0F6-4704-BEA2-1B31FC20DDFB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Empyrion - Galactic Survival\EmpyrionLauncher.exe
FirewallRules: [{34EC2593-CED8-4032-A390-95A489FAF2F2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Empyrion - Galactic Survival\EmpyrionLauncher.exe
FirewallRules: [TCP Query User{69315F93-0D91-4758-93D5-330958698994}C:\program files (x86)\steam\steamapps\common\empyrion - galactic survival\empyrion.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\empyrion - galactic survival\empyrion.exe
FirewallRules: [UDP Query User{B0E0F3B3-BE79-4000-ACEB-0379CE06E6BD}C:\program files (x86)\steam\steamapps\common\empyrion - galactic survival\empyrion.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\empyrion - galactic survival\empyrion.exe
FirewallRules: [{872986EE-2F54-4481-9156-E9EFA55AF548}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ultimate Chicken Horse\UltimateChickenHorse.exe
FirewallRules: [{3CB0B640-F477-4BFD-A50F-FFC4DBE61C20}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ultimate Chicken Horse\UltimateChickenHorse.exe
FirewallRules: [{1E314ED1-DE6D-4597-9DE0-8C1E5DAF2091}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FINAL FANTASY VII\FF7_Launcher.exe
FirewallRules: [{61F6B6C4-59A4-4CF0-B7D3-9761BE3AB446}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FINAL FANTASY VII\FF7_Launcher.exe
FirewallRules: [{B32CD367-74D4-4C8A-B73F-EB471F7A250A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\OxygenNotIncluded\OxygenNotIncluded.exe
FirewallRules: [{FF98AF14-DA08-472C-9382-2ADD90FDC7F1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\OxygenNotIncluded\OxygenNotIncluded.exe
FirewallRules: [TCP Query User{D5DA0719-033D-4675-82A4-AD32B14DA37B}C:\users\twitchi\appdata\local\temp\rar$exa0.360\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\appdata\local\temp\rar$exa0.360\dmpserver\dmpserver.exe
FirewallRules: [UDP Query User{B4CB699C-3649-4CA6-84BB-00B99F1B3560}C:\users\twitchi\appdata\local\temp\rar$exa0.360\dmpserver\dmpserver.exe] => (Allow) C:\users\twitchi\appdata\local\temp\rar$exa0.360\dmpserver\dmpserver.exe
FirewallRules: [TCP Query User{B7B021FB-767C-4B82-B971-368C44A4B8F4}C:\program files (x86)\brackets\node.exe] => (Allow) C:\program files (x86)\brackets\node.exe
FirewallRules: [UDP Query User{EF8027CE-1B47-4C78-BE82-F59D1C306261}C:\program files (x86)\brackets\node.exe] => (Allow) C:\program files (x86)\brackets\node.exe
FirewallRules: [TCP Query User{0F919523-0B7A-4FEA-B8EA-5F1E6453E4AA}C:\users\twitchi\appdata\local\atom\app-1.15.0\resources\app\apm\bin\node.exe] => (Allow) C:\users\twitchi\appdata\local\atom\app-1.15.0\resources\app\apm\bin\node.exe
FirewallRules: [UDP Query User{5058D2A4-F698-4B76-9BC1-B66E9080CF08}C:\users\twitchi\appdata\local\atom\app-1.15.0\resources\app\apm\bin\node.exe] => (Allow) C:\users\twitchi\appdata\local\atom\app-1.15.0\resources\app\apm\bin\node.exe
FirewallRules: [TCP Query User{1641E8DF-63E0-416A-991F-7416BEB672A6}C:\users\twitchi\appdata\local\atom\app-1.16.0\resources\app\apm\bin\node.exe] => (Allow) C:\users\twitchi\appdata\local\atom\app-1.16.0\resources\app\apm\bin\node.exe
FirewallRules: [UDP Query User{FB125E5B-5276-4083-AF49-BBD90A8096B4}C:\users\twitchi\appdata\local\atom\app-1.16.0\resources\app\apm\bin\node.exe] => (Allow) C:\users\twitchi\appdata\local\atom\app-1.16.0\resources\app\apm\bin\node.exe
FirewallRules: [{95DC4930-6414-450B-BAEE-BEB35510F2DA}] => (Allow) C:\Windows KMS Activator Ultimate 2017 v3.3\Windows KMS Activator Ultimate 2017 v3.3.exe
FirewallRules: [{1EE3D683-E14F-45BE-B8F0-032EF5E74261}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{F39CD04C-F644-4E5D-AF11-2B1FF8DFF947}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{F78013C3-175F-4E04-B106-B43A38A0AE95}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons2\Dungeons2.exe
FirewallRules: [{8E22D9C1-D109-4B95-AD1A-BFE9F97F773D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons2\Dungeons2.exe
FirewallRules: [{A8476523-56E1-4945-9402-11FBEAAE8F5E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons2\mono\bin\mono.exe
FirewallRules: [{45691809-A27D-453D-BAB7-C4B9A279962A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons2\mono\bin\mono.exe
FirewallRules: [TCP Query User{30F53C18-0A02-4D6D-9697-027B5F42A694}C:\users\twitchi\desktop\hit and miss\hit and miss.exe] => (Allow) C:\users\twitchi\desktop\hit and miss\hit and miss.exe
FirewallRules: [UDP Query User{5B8B2639-1C89-46CC-BCC0-2370A9689EE2}C:\users\twitchi\desktop\hit and miss\hit and miss.exe] => (Allow) C:\users\twitchi\desktop\hit and miss\hit and miss.exe
FirewallRules: [{4E95F6A3-0F5D-4DE0-B79D-89D838C6D61C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe
FirewallRules: [{926F76F7-0064-4ACC-8716-5F478AFACF8F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe
FirewallRules: [TCP Query User{B52615B5-1153-4FAB-BB05-917DE11C93B5}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [UDP Query User{AE57EFA2-1B77-45B3-AB94-3453AE58E0AD}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [{F9C45424-04F2-41C5-955A-C9CB23BC3C86}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\starbound.exe
FirewallRules: [{CEF4F21C-192A-4D6C-9E35-72B0745F50DB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\starbound.exe
FirewallRules: [{60F9950A-AEED-4B80-9D0D-B6CF40632E9D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\starbound_server.exe
FirewallRules: [{7717526C-EEC7-4098-9AF9-B26126659D6B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\starbound_server.exe
FirewallRules: [{EF917A76-A48E-4C19-8643-C5545A24467F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\mod_uploader.exe
FirewallRules: [{9EB4D0EE-9957-44AD-8A72-04B07FB7E3C9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win64\mod_uploader.exe
FirewallRules: [{2444CA72-D5F4-40F6-8FF1-1BF4ED8DB1B0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win32\starbound.exe
FirewallRules: [{6B6659FE-02C8-4F3F-971A-90E17838B12B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Starbound\win32\starbound.exe
FirewallRules: [{EAF91E92-2D9F-401D-89D6-81D1573B77C8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{A6F9385A-3CD6-435B-8A77-6DD4CABE9764}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{275C350A-FBE8-4D06-8501-205F6F292DA5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Broforce\Broforce_beta.exe
FirewallRules: [{2C17F4E4-B1D4-4B03-8476-ABFB97476B70}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Broforce\Broforce_beta.exe
FirewallRules: [{9632AB05-0B81-4CE6-814D-9F71180AA8FF}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{91AAA17F-2E1B-4934-B90D-9953092EF14D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Morrowind\Morrowind Launcher.exe
FirewallRules: [{8BC7AD53-ED40-421D-94D4-21E3BD2B8440}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Morrowind\Morrowind Launcher.exe
FirewallRules: [{CCC2BEED-4592-4507-AEF3-6DDB9BC8323C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{248C06D4-77ED-4045-AD10-E47742B5C12B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{1E77FA91-43E3-4256-B4B7-F09DBFF48F0B}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{BBC314F3-EFA9-4BFC-8FEB-8C7E8F855BEE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Intelligent Design An Evolutionary Sandbox\intelligentdesign.exe
FirewallRules: [{3AB434F0-F98D-4654-A478-F80D824111DE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Intelligent Design An Evolutionary Sandbox\intelligentdesign.exe
FirewallRules: [{4A2DF949-7372-46DE-A347-43B94AC0D7EB}] => (Allow) C:\Users\Twitchi\AppData\Local\Temp\00023971\download\MiniThunderPlatform.exe
FirewallRules: [{CB2AEF91-AAFF-468A-9E7D-DC2A1FBCFC5B}] => (Allow) C:\WINDOWS\system32\rundll32.exe
FirewallRules: [{9BA7772E-574A-413B-B987-72EAD2E071F6}] => (Allow) C:\Windows\System32\rundll32.exe
FirewallRules: [{EEFCD729-894E-4F44-AC31-448054FD47B9}] => (Allow) C:\Windows\System32\rundll32.exe
==================== Restore Points =========================
09-07-2017 13:08:15 Installed Microsoft ISO Downloader Pro 2017 v1.6
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/11/2017 01:33:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app 56540Oprio.Taskify_v1e60k6hyvhk0!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 01:18:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 01:18:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app 56540Oprio.Taskify_v1e60k6hyvhk0!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 01:10:11 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 01:03:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app 56540Oprio.Taskify_v1e60k6hyvhk0!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 01:03:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 01:03:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app Microsoft.WindowsStore_8wekyb3d8bbwe!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 12:58:22 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 12:48:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app 56540Oprio.Taskify_v1e60k6hyvhk0!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/11/2017 12:48:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: FRAMEZILLA)
Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
System errors:
=============
Error: (07/11/2017 10:47:40 AM) (Source: DCOM) (EventID: 10010) (User: FRAMEZILLA)
Description: The server App did not register with DCOM within the required timeout.
Error: (07/11/2017 10:37:16 AM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "1053" attempting to start the service DmEnrollmentSvc with arguments "Unavailable" in order to run the server:
Windows.Internal.Management.Enrollment.Enroller
Error: (07/11/2017 10:37:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Client License Service (ClipSVC) service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (07/11/2017 10:37:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Device Management Enrollment Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (07/11/2017 10:37:14 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the ClipSVC service to connect.
Error: (07/11/2017 10:37:11 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the DmEnrollmentSvc service to connect.
Error: (07/11/2017 10:36:39 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
and APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (07/11/2017 10:34:37 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Avira.ServiceHost service to connect.
Error: (07/11/2017 10:34:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NetPipeActivator service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (07/11/2017 10:34:37 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the NetPipeActivator service to connect.
CodeIntegrity:
===================================
Date: 2017-05-11 22:32:34.659
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
Date: 2017-05-11 22:32:34.658
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
Date: 2017-03-10 14:08:04.151
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
Date: 2017-02-22 15:07:28.977
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-02-22 15:07:28.974
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-02-22 15:07:28.969
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-01-31 02:40:13.909
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
Date: 2017-01-19 19:49:48.912
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
Date: 2016-11-30 01:30:08.274
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
Date: 2016-11-06 20:38:45.780
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
==================== Memory info ===========================
Processor: Intel® Core i7 CPU 870 @ 2.93GHz
Percentage of memory in use: 34%
Total physical RAM: 16375.05 MB
Available physical RAM: 10784.4 MB
Total Virtual: 32759.05 MB
Available Virtual: 26562.85 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:930.97 GB) (Free:277.3 GB) NTFS
Drive d: (New Volume) (Fixed) (Total:1862.89 GB) (Free:533.66 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000)
Partition: GPT.
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 6DB12FA4)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
==================== End of Addition.txt ============================
thank you so much for any help you canb provide
