JustTheEngineer
Hi once again.
Tried installing a program which had some other software linked to it and now my Google Chrome browser has been running slower and has been displaying these advertisement sites at the top of the search results. My Adblock extension also identifies these websites as advertisements but only if I manually tell it there's an ad that isn't blocked on the page. I've attached both the FRST log and an image of the advertisement sites that appear when I search for stuff.
Addition.txt log
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
Ran by [redacted] (27-03-2017 21:36:19)
Running from C:\Users\[redacted]\Desktop
Windows 10 Home Version 1511 (X64) (2016-02-07 05:06:49)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-233390903-2661952563-451428824-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-233390903-2661952563-451428824-503 - Limited - Disabled)
Guest (S-1-5-21-233390903-2661952563-451428824-501 - Limited - Disabled)
Primitive (S-1-5-21-233390903-2661952563-451428824-1001 - Administrator - Enabled) => C:\Users\Primitive
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
64 Bit HP CIO Components Installer (Version: 21.2.1 - HP Inc.) Hidden
Ansel (Version: 378.92 - NVIDIA Corporation) Hidden
ARK: Survival Evolved (HKLM\...\Steam App 346110) (Version: - Studio Wildcard)
BitTorrent (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\BitTorrent) (Version: 7.9.9.43389 - BitTorrent Inc.)
Classic Shell (HKLM\...\{383BB30A-B4A7-4666-9A83-22CFA8640097}) (Version: 4.3.0 - IvoSoft)
Cloud Penguin (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\Cloud Penguin) (Version: 2.0.6210.36208 - Cloud Penguin) <==== ATTENTION
Clustertruck (HKLM\...\Steam App 397950) (Version: - Landfall Games)
Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve)
Depth (HKLM\...\Steam App 274940) (Version: - Digital Confectioners)
Deus Ex: Mankind Divided™ (HKLM\...\Steam App 337000) (Version: - Eidos Montreal)
Discord (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\Discord) (Version: 0.0.297 - Hammer & Chisel, Inc.)
Dishonored (HKLM\...\Steam App 205100) (Version: - Arkane Studios)
Epic Games Launcher (HKLM-x32\...\{2DE76AAC-8061-4D9B-B7BA-A7CFBE0F8048}) (Version: 1.1.86.0 - Epic Games, Inc.)
Git version 2.11.1 (HKLM\...\Git_is1) (Version: 2.11.1 - The Git Development Community)
Golf With Your Friends (HKLM\...\Steam App 431240) (Version: - Blacklight Interactive)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
Grand Theft Auto V (HKLM\...\Steam App 271590) (Version: - Rockstar North)
Guns of Icarus Online (HKLM\...\Steam App 209080) (Version: - Muse Games)
Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment)
HiPatch (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF000}) (Version: 5.0.6.4 - Hi-Rez Studios)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.7870.2024 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{86CE1746-9EFF-3C9C-8755-81EA8903AC34}) (Version: - )
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: - )
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Monster Hunter Online (HKLM-x32\...\Monster Hunter Online) (Version: - Tencent)
Natural Selection 2 (HKLM\...\Steam App 4920) (Version: - Unknown Worlds Entertainment)
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.3.1 - Notepad++ Team)
NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 378.92 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.4.0.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.4.0.70 - NVIDIA Corporation)
NVIDIA Graphics Driver 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.92 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.23 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
NvNodejs (Version: 3.4.0.70 - NVIDIA Corporation) Hidden
NvTelemetry (Version: 2.3.16.0 - NVIDIA Corporation) Hidden
NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7870.2024 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7870.2024 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7870.2024 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7668.2066 - Microsoft Corporation) Hidden
Online.io Application (x32 Version: 2.1.0 - Microleaves) Hidden <==== ATTENTION
paint.net (HKLM\...\{6AC1101E-7561-43C9-BEEA-4AB1D220D8FF}) (Version: 4.0.13 - dotPDN LLC)
Planetary Annihilation: TITANS (HKLM\...\Steam App 386070) (Version: - Uber Entertainment)
Python 3.5.1 (64-bit) (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\{b8440650-9dbe-4b7d-8167-6e0e3dcdf5d0}) (Version: 3.5.1150.0 - Python Software Foundation)
Python 3.5.1 Add to Path (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Core Interpreter (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Development Libraries (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Documentation (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Executables (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Launcher (32-bit) (HKLM-x32\...\{EC00AEF9-6544-4FEC-8152-C8949CDDCC85}) (Version: 3.5.150.0 - Python Software Foundation)
Python 3.5.1 pip Bootstrap (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Standard Library (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Tcl/Tk Support (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Test Suite (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Utility Scripts (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Rainmeter (HKLM-x32\...\Rainmeter) (Version: 4.0 r2746 - )
ROBLOX Player for Primitive (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version: - ROBLOX Corporation)
ROBLOX Studio for Primitive (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}) (Version: - ROBLOX Corporation)
Robocraft (HKLM\...\Steam App 301520) (Version: - Freejam)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.0.5 - Rockstar Games)
SHIELD Streaming (Version: 7.1.0351 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 3.4.0.70 - NVIDIA Corporation) Hidden
Skype Web Plugin (HKLM-x32\...\{E8A70371-2C4D-4B12-831D-6A4BB9AC7AEF}) (Version: 7.29.0.73 - Skype Technologies S.A.)
SMITE (HKLM\...\Steam App 386360) (Version: - Hi-Rez Studios)
Spotify (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\Spotify) (Version: 1.0.51.693.g6ea1e7f6 - Spotify AB)
Super Hexagon (HKLM\...\Steam App 221640) (Version: - Terry Cavanagh)
Traffic Exchange (x32 Version: 2.1.0 - Microleaves) Hidden <==== ATTENTION
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 3.5.3 - Tweaking.com)
UE4 Prerequisites (x64) (Version: 1.0.10.0 - Epic Games, Inc.) Hidden
Unity Web Player (x64) (All users) (HKLM\...\UnityWebPlayer) (Version: 4.6.6f2 - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 24.0.1 - Ubisoft)
Vulkan Run Time Libraries 1.0.17.0 (HKLM\...\VulkanRT1.0.17.0) (Version: 1.0.17.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.)
Warframe (HKLM\...\Steam App 230410) (Version: - Digital Extremes)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
Zoo Tycoon 2 - Ultimate Collection (HKLM-x32\...\InstallShield_{9CC4840D-EF1C-406F-AF08-3C19EB1335B9}) (Version: 1.00.0000 - Microsoft Game Studios)
Zoo Tycoon 2 - Ultimate Collection (x32 Version: 1.00.0000 - Microsoft Game Studios) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-233390903-2661952563-451428824-1001_Classes\CLSID\{A03A51A2-5B59-4ECE-96D1-037F7F2A0D8F}\localserver32 -> C:\Users\Primitive\AppData\Local\SkypePlugin\7.29.0.73\GatewayVersion-x64.exe (Skype Technologies S.A.)
CustomCLSID: HKU\S-1-5-21-233390903-2661952563-451428824-1001_Classes\CLSID\{CBF9CD8C-2714-4F36-B76A-43E6C7547BC2}\localserver32 -> C:\Users\Primitive\AppData\Local\SkypePlugin\7.29.0.73\EdgeCalling.exe (Skype Technologies S.A.)
CustomCLSID: HKU\S-1-5-21-233390903-2661952563-451428824-1001_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Primitive\AppData\Local\Roblox\Versions\version-ca61db0aa1b8462c\RobloxProxy64.dll (ROBLOX Corporation)
CustomCLSID: HKU\S-1-5-21-233390903-2661952563-451428824-1001_Classes\CLSID\{FE0A3EA9-4DDA-4B0A-9981-5ABE8F0186CD}\InprocServer32 -> C:\Users\Primitive\AppData\Local\SkypePlugin\7.29.0.73\GatewayActiveX-x64.dll (Skype Technologies S.A.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {041BD7F2-9D4D-4C9B-B7BC-46A4F59A7431} - System32\Tasks\Traffic Exchange v209 - 3 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {0C557DF1-E92D-458A-8E6F-6C3D1D24242A} - System32\Tasks\Traffic Exchange => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {0CC8C3D9-71F8-4D15-97D6-38645131BAB9} - System32\Tasks\Online Application Guardian => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {0D2AD9B3-ADDB-40A5-A136-3E0102ADBF82} - System32\Tasks\Traffic Exchange Guardian => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {10661CA9-C443-4EB0-91B3-4676DC558427} - System32\Tasks\Online Application v2 Guard => C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {236D5E93-AC70-40C8-8507-71ED54E82425} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-02-23] (NVIDIA Corporation)
Task: {36FC4F2D-2FC1-4C0F-9F44-41B280A32779} - System32\Tasks\Traffic Exchange v209 - 2 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {3F2DCA07-5247-4396-A732-55CFACB24016} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-02-23] (NVIDIA Corporation)
Task: {3F39F139-E558-49F2-94D9-5443E998C7DA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {45A64C74-3F8C-42EE-8DEB-DF1A83FCCD4D} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-03-05] (Microsoft Corporation)
Task: {4752A296-189E-4FD5-A55B-16D29353EEF8} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe [2017-02-04] ()
Task: {4B25888B-8985-4F3F-B91E-496D45D90F69} - System32\Tasks\Traffic Exchange v2 - 2 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {54E033B2-E527-4D00-B522-6E3845CDF2E1} - System32\Tasks\Online Application v209 => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {5A63E6F8-C360-4ED1-AC63-7167C03D1785} - System32\Tasks\Online Application Guard => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {5DBF077D-34EF-4AC4-ABE9-B051D1CC57E4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-03-08] (Microsoft Corporation)
Task: {66E21683-3ABA-4D5F-B96A-97B64E81E6F5} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
Task: {718654D7-45FE-4114-8169-D671714DB898} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
Task: {7813514E-C52D-4C08-BCE8-6CFD9B1B3685} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation)
Task: {7EA057AD-62FC-43FD-BE2E-2A8DC9D0A261} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-02-23] (NVIDIA Corporation)
Task: {85148911-6B3A-4DA0-BE2A-EC73B3E91C67} - System32\Tasks\Traffic Exchange v2 - 3 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {8C66C891-8007-46D0-8A70-0F04AFD28BC9} - System32\Tasks\Online Application v2 Guardian => C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {95BF1522-875E-4138-B6E6-A36B795D7D25} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation)
Task: {97119FF0-B283-4618-9ECE-8ACD504E0A01} - System32\Tasks\Online Application v2 => C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {9C8FF20F-ACB5-43FE-B59C-991453FAB0FE} - System32\Tasks\Traffic Exchange v209 - 1 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {AE34D356-1919-4106-9136-CD5F218496D8} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation)
Task: {B481EED0-482D-4E11-B005-299A4747938A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {B4F276E6-7AE1-4A1D-8CD2-D1B6059AC5F4} - System32\Tasks\Online Application v209 Guardian => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {B5015F98-BD11-457C-AF42-4257BD35FEFC} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-03-08] (Microsoft Corporation)
Task: {BF3CD351-0A42-4629-87ED-61FC9961439A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-03-08] (Microsoft Corporation)
Task: {C62F2AFE-67E3-4033-B157-B302AA4C9F01} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-03-05] (Microsoft Corporation)
Task: {DB3840F1-A2BA-4B6F-9098-D94CACB970FC} - System32\Tasks\Traffic Exchange Updater => C:\Program Files (x86)\Microleaves\Traffic Exchange\Traffic Exchange Updater.exe [2017-02-15] (Microleaves) <==== ATTENTION
Task: {ED519B11-3B3F-4B0B-9C63-CC6B72B6E04B} - System32\Tasks\Traffic Exchange Guard => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {EE8D7CAE-3277-4C79-84FD-215F3C05BA5F} - System32\Tasks\Online Application => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {EF195EFC-DAE2-47F4-9AF7-9896A8FF1C62} - System32\Tasks\Online Application v209 Guard => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {F8691C31-7151-4D63-ABB0-CA44666DB472} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation)
Task: {F926E2CA-0E8B-4955-BF7F-CC1836FDF8E0} - System32\Tasks\Online Application Updater => C:\Program Files (x86)\Microleaves\Online.io Application\Online Application Updater.exe [2017-02-15] (Microleaves) <==== ATTENTION
Task: {FC17B985-39D1-41BC-88AA-E56D1701A505} - System32\Tasks\Traffic Exchange v2 - 1 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {FD3CA9F1-D4CB-4460-BF78-0FAC0BF6ED8E} - System32\Tasks\PPI Update => C:\WINDOWS\explorer.exe "hxxp://windowsdefender.site/download/download.php?mn=9996" <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Online Application Updater.job => C:\Program Files (x86)\Microleaves\Online.io Application\Online Application Updater.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Online Application v2 Guard.job => C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Online Application v2 Guardian.job => C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Online Application v2.job => C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Online Application v209 Guard.job => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Online Application v209 Guardian.job => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Online Application v209.job => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange Updater.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Traffic Exchange Updater.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 2.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 2.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\Primitive\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Intеrnеt Ехplоrеr.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.bat ()
Shortcut: C:\Users\Primitive\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gооglе Сhrоmе.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat ()
Shortcut: C:\Users\Primitive\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gооglе Сhrоmе.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Еpiс Gаmеs Lаunсhеr.lnk -> G:\Non-Steam Games\Paragon\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.bat ()
==================== Loaded Modules (Whitelisted) ==============
2015-10-30 03:17 - 2015-10-30 03:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll
2017-03-26 17:26 - 2017-03-26 17:26 - 00230400 _____ () C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\prot3b4f51ef-73de-4277-a2f6-3e687129283e.tmpfs
2016-10-08 15:14 - 2017-02-23 14:35 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll
2016-10-08 15:14 - 2017-02-23 14:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-03-24 16:52 - 2017-03-24 16:52 - 00008704 _____ () C:\Users\Primitive\AppData\Local\Temp\WS\realtek_amd64.exe
2017-03-26 21:14 - 2017-03-13 18:08 - 00016384 _____ () C:\WINDOWS\src_srv\winsrcsrv.exe
2015-10-30 03:18 - 2015-10-30 03:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-02-07 01:10 - 2017-03-16 19:16 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-03-27 17:02 - 2017-03-27 17:02 - 00368640 _____ () C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\knsF76C.tmp
2016-11-08 18:33 - 2016-10-25 05:42 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-11-08 18:33 - 2016-10-25 05:42 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-05-19 20:11 - 2016-05-19 20:11 - 00959168 _____ () C:\Users\Primitive\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2016-10-14 23:27 - 2017-02-25 04:59 - 08921648 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2017-01-16 21:30 - 2017-01-16 21:30 - 00230064 _____ () G:\rhinobot\Notepad++\NppShell_06.dll
2016-02-07 03:36 - 2015-12-07 00:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-07-16 19:31 - 2016-06-30 23:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-11-08 18:34 - 2016-10-25 03:01 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2016-11-08 18:34 - 2016-10-25 00:49 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-11-08 18:33 - 2016-10-25 00:44 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-11-08 18:34 - 2016-10-25 00:45 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-11-08 18:33 - 2016-10-25 00:48 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-01-23 09:31 - 2017-01-23 09:31 - 01037824 _____ () C:\Users\Primitive\AppData\Roaming\Rainmeter\Plugins\SpotifyPlugin.dll
2017-01-01 09:59 - 2017-01-01 09:59 - 00173568 _____ () G:\Rainmeter\Plugins\AudioLevel.DLL
2017-01-01 09:59 - 2017-01-01 09:59 - 00120832 _____ () G:\Rainmeter\Plugins\QuotePlugin.dll
2017-01-01 09:59 - 2017-01-01 09:59 - 00093696 _____ () G:\Rainmeter\Plugins\Process.DLL
2016-04-18 16:14 - 2016-04-18 16:14 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2017-03-24 16:53 - 2017-03-24 16:53 - 00404992 _____ () C:\Users\Primitive\AppData\Local\Temp\WS\realtek_amd64.lib.dll
2016-10-08 15:14 - 2017-02-23 14:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-10-08 15:14 - 2017-02-23 14:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll
2016-10-08 15:14 - 2017-02-23 14:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2016-10-09 15:09 - 2017-03-23 17:24 - 67725936 _____ () C:\Users\Primitive\AppData\Roaming\Spotify\libcef.dll
2016-10-09 15:09 - 2017-03-23 17:24 - 01929840 _____ () C:\Users\Primitive\AppData\Roaming\Spotify\libglesv2.dll
2016-10-09 15:09 - 2017-03-23 17:24 - 00087152 _____ () C:\Users\Primitive\AppData\Roaming\Spotify\libegl.dll
2016-10-08 15:14 - 2017-02-23 14:34 - 65708992 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll
2016-10-08 15:14 - 2017-02-23 10:30 - 00338488 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node
2016-10-08 15:14 - 2017-02-23 10:30 - 00252352 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node
2016-10-08 15:14 - 2017-02-23 10:30 - 02443320 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node
2016-10-08 15:14 - 2017-02-23 10:30 - 00385592 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node
2016-10-08 15:14 - 2017-02-23 10:30 - 00543288 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node
2016-10-08 15:14 - 2017-02-23 10:30 - 00468536 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node
2017-03-23 17:25 - 2017-03-09 20:13 - 00674592 _____ () G:\Steam\SDL2.dll
2016-12-20 18:49 - 2016-08-31 21:02 - 04969248 _____ () G:\Steam\v8.dll
2017-03-23 17:25 - 2017-03-22 20:52 - 02465056 _____ () G:\Steam\video.dll
2016-12-20 18:49 - 2016-01-27 03:49 - 02549760 _____ () G:\Steam\libavcodec-56.dll
2016-12-20 18:49 - 2016-01-27 03:49 - 00491008 _____ () G:\Steam\libavformat-56.dll
2016-12-20 18:49 - 2016-01-27 03:49 - 00332800 _____ () G:\Steam\libavresample-2.dll
2016-12-20 18:49 - 2016-01-27 03:49 - 00442880 _____ () G:\Steam\libavutil-54.dll
2016-12-20 18:49 - 2016-01-27 03:49 - 00485888 _____ () G:\Steam\libswscale-3.dll
2016-12-20 18:49 - 2016-08-31 21:02 - 01563936 _____ () G:\Steam\icui18n.dll
2016-12-20 18:49 - 2016-08-31 21:02 - 01195296 _____ () G:\Steam\icuuc.dll
2017-03-23 17:25 - 2017-03-22 20:52 - 00839456 _____ () G:\Steam\bin\chromehtml.DLL
2016-12-20 18:49 - 2016-07-04 18:17 - 00266560 _____ () G:\Steam\openvr_api.dll
2017-03-10 17:32 - 2017-01-30 17:41 - 68875552 _____ () G:\Steam\bin\cef\cef.win7\libcef.dll
2017-03-23 17:25 - 2017-03-22 20:52 - 00383776 _____ () G:\Steam\steam.dll
2016-12-20 18:49 - 2015-09-24 19:52 - 00119208 _____ () G:\Steam\winh264.dll
2016-04-18 16:14 - 2016-04-18 16:14 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-04-18 16:14 - 2016-04-18 16:14 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2017-01-11 19:44 - 2017-01-04 15:28 - 01958912 _____ () C:\Users\Primitive\AppData\Local\Discord\app-0.0.297\ffmpeg.dll
2017-01-11 19:44 - 2017-01-11 19:44 - 01082880 _____ () \\?\C:\Users\Primitive\AppData\Roaming\discord\0.0.297\modules\discord_voice\discord_voice.node
2017-01-11 19:44 - 2017-01-11 19:44 - 03750400 _____ () \\?\C:\Users\Primitive\AppData\Roaming\discord\0.0.297\modules\discord_voice\libdiscord.dll
2017-01-11 19:44 - 2017-01-11 19:44 - 00914432 _____ () \\?\C:\Users\Primitive\AppData\Roaming\discord\0.0.297\modules\discord_utils\discord_utils.node
2017-01-11 19:44 - 2017-01-11 19:44 - 01127424 _____ () \\?\C:\Users\Primitive\AppData\Roaming\discord\0.0.297\modules\discord_toaster\discord_toaster.node
2017-01-11 19:44 - 2017-01-04 15:28 - 02278912 _____ () C:\Users\Primitive\AppData\Local\Discord\app-0.0.297\libglesv2.dll
2017-01-11 19:44 - 2017-01-04 15:28 - 00096768 _____ () C:\Users\Primitive\AppData\Local\Discord\app-0.0.297\libegl.dll
2017-03-27 17:07 - 2017-03-27 17:07 - 00148992 _____ () \\?\C:\Users\Primitive\AppData\Local\Temp\839B.tmp.node
2017-01-11 19:44 - 2017-01-11 19:44 - 02658304 _____ () \\?\C:\Users\Primitive\AppData\Roaming\discord\0.0.297\modules\discord_rpc\discord_rpc.node
2017-01-11 19:44 - 2017-03-22 16:07 - 02665976 _____ () \\?\C:\Users\Primitive\AppData\Roaming\discord\0.0.297\modules\discord_contact_import\discord_contact_import.node
2016-05-19 20:11 - 2016-05-19 20:11 - 00679624 _____ () C:\Users\Primitive\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll
2016-10-14 23:27 - 2017-02-25 04:14 - 08921136 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\1033\GrooveIntlResource.dll
2017-02-10 19:46 - 2017-02-01 05:01 - 01870168 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll
2017-02-10 19:46 - 2017-02-01 05:01 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll
2015-10-30 03:18 - 2015-10-30 03:18 - 00025088 _____ () C:\Windows\SYSTEM32\GamePanelExternalHook.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\77684213.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\77684213.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\google.com -> hxxps://google.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-10-30 03:24 - 2017-01-12 18:08 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-233390903-2661952563-451428824-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Primitive\AppData\Roaming\Rainmeter\Layouts\Test\Wallpaper.bmp
DNS Servers: 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\StartupApproved\Run: => "Steam"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{623EAC45-1598-4EEE-BD2F-C554D19FAA58}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{882D562F-D8CF-47F0-91D5-5FF20B26E4D6}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{7F32F6EE-7D5A-4F87-890D-C43E6E5B1D6B}] => (Allow) G:\Steam\Steam.exe
FirewallRules: [{37B62C7A-6269-448C-B0F0-C5F4DD354D39}] => (Allow) G:\Steam\Steam.exe
FirewallRules: [{62D0C5AA-BAC2-46E9-875E-4A481824893A}] => (Allow) G:\Steam\bin\steamwebhelper.exe
FirewallRules: [{13C2835A-1846-4F6B-8DBB-D5013C3538E6}] => (Allow) G:\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{0DB0ECE8-19E6-4A88-938C-7A7268B91FE9}C:\windows.old\users\primitive\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\windows.old\users\primitive\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{DE87E032-962F-4070-80E1-0F26707C370F}C:\windows.old\users\primitive\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\windows.old\users\primitive\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [{E12D0410-C1CD-4A84-9D2B-A549A6FE2C42}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{66C4B93B-2AA9-4B9B-8CBD-B461DFB712E2}G:\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) G:\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [UDP Query User{3908B23D-06E8-409A-955B-5EB59B18597B}G:\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) G:\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [TCP Query User{450E2008-E396-433A-A2C2-A8DD4DA0B3CE}G:\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) G:\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{44F09366-8258-4497-AE39-AAF7A7B95146}G:\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) G:\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [{A0E6F6F2-A76C-4190-A05C-EEC139D4A3A9}] => (Allow) G:\Steam\SteamApps\common\primal_carnage\Binaries\Win32\PrimalCarnageGame.exe
FirewallRules: [{436E6A5A-63DA-466D-97E6-04584B352F1B}] => (Allow) G:\Steam\SteamApps\common\primal_carnage\Binaries\Win32\PrimalCarnageGame.exe
FirewallRules: [{AF18843B-D775-4C5B-961C-E4BE8E0D4D85}] => (Allow) G:\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{C2B76408-6377-4C86-8CA0-23DC44A17D81}] => (Allow) G:\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{DFDDC1C2-D40E-452E-BA03-AD93719A722A}] => (Allow) G:\Steam\SteamApps\common\The Isle\TheIsle.exe
FirewallRules: [{0C7AE528-35AA-4CA9-BEEF-9273410642C4}] => (Allow) G:\Steam\SteamApps\common\The Isle\TheIsle.exe
FirewallRules: [TCP Query User{F94CD4E5-A551-4850-AC31-08A71433FA3E}G:\epic games\4.10\engine\binaries\win64\ue4editor.exe] => (Allow) G:\epic games\4.10\engine\binaries\win64\ue4editor.exe
FirewallRules: [UDP Query User{4CCE744F-9643-4D7F-8D50-08A1F5F83204}G:\epic games\4.10\engine\binaries\win64\ue4editor.exe] => (Allow) G:\epic games\4.10\engine\binaries\win64\ue4editor.exe
FirewallRules: [TCP Query User{F2230469-9934-4F74-B6BB-F29B3E279064}G:\epic games\4.10\engine\binaries\dotnet\swarmagent.exe] => (Block) G:\epic games\4.10\engine\binaries\dotnet\swarmagent.exe
FirewallRules: [UDP Query User{E1999BC2-8EC4-468A-BC7F-0D0176ADE6A1}G:\epic games\4.10\engine\binaries\dotnet\swarmagent.exe] => (Block) G:\epic games\4.10\engine\binaries\dotnet\swarmagent.exe
FirewallRules: [TCP Query User{212B39BF-7C90-4A18-A2A0-49AEE8CBB838}G:\non-steam games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe] => (Allow) G:\non-steam games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe
FirewallRules: [UDP Query User{73721E6F-4821-40A6-92A7-4A410A50DD18}G:\non-steam games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe] => (Allow) G:\non-steam games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe
FirewallRules: [{0CC94886-5F31-440B-8375-8650C49219BA}] => (Allow) G:\Steam\SteamApps\common\GarrysMod\hl2.exe
FirewallRules: [{1327FD25-DABA-4F25-8721-6FF3482ABA8E}] => (Allow) G:\Steam\SteamApps\common\GarrysMod\hl2.exe
FirewallRules: [TCP Query User{23BC6235-E46E-443A-A509-DBB2C0214867}C:\users\primitive\appdata\local\roblox\versions\version-d0ea8fd26e144a48\robloxstudiobeta.exe] => (Allow) C:\users\primitive\appdata\local\roblox\versions\version-d0ea8fd26e144a48\robloxstudiobeta.exe
FirewallRules: [UDP Query User{7A57483F-0EDC-4AAA-8F16-7E6225D68E64}C:\users\primitive\appdata\local\roblox\versions\version-d0ea8fd26e144a48\robloxstudiobeta.exe] => (Allow) C:\users\primitive\appdata\local\roblox\versions\version-d0ea8fd26e144a48\robloxstudiobeta.exe
FirewallRules: [{8BC5D79D-ECCB-4824-9964-F2E73A249C60}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe
FirewallRules: [{0E2B86AF-644D-43C9-9426-2B434A9EC1DA}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe
FirewallRules: [TCP Query User{477E4D73-E14F-4979-BA4E-463E509A435C}C:\users\primitive\appdata\local\temp\rar$exa0.688\microsoft toolkit.exe] => (Allow) C:\users\primitive\appdata\local\temp\rar$exa0.688\microsoft toolkit.exe
FirewallRules: [UDP Query User{1B6BC57A-E430-4B42-B2D2-6D16FA5FEBD0}C:\users\primitive\appdata\local\temp\rar$exa0.688\microsoft toolkit.exe] => (Allow) C:\users\primitive\appdata\local\temp\rar$exa0.688\microsoft toolkit.exe
FirewallRules: [TCP Query User{6C500A62-A08C-4EA0-96B7-7D3CCD8E02C0}C:\users\primitive\appdata\local\temp\rar$exa0.979\microsoft toolkit.exe] => (Allow) C:\users\primitive\appdata\local\temp\rar$exa0.979\microsoft toolkit.exe
FirewallRules: [UDP Query User{45C7D1CE-847C-42D9-A580-3607B07097F0}C:\users\primitive\appdata\local\temp\rar$exa0.979\microsoft toolkit.exe] => (Allow) C:\users\primitive\appdata\local\temp\rar$exa0.979\microsoft toolkit.exe
FirewallRules: [TCP Query User{F3520FB5-F1CC-4074-87DE-5CF415688408}C:\users\primitive\appdata\local\temp\rar$exa0.958\microsoft toolkit.exe] => (Allow) C:\users\primitive\appdata\local\temp\rar$exa0.958\microsoft toolkit.exe
FirewallRules: [UDP Query User{8B4AD559-39E8-4A1D-96C8-F4410E45AF2A}C:\users\primitive\appdata\local\temp\rar$exa0.958\microsoft toolkit.exe] => (Allow) C:\users\primitive\appdata\local\temp\rar$exa0.958\microsoft toolkit.exe
FirewallRules: [TCP Query User{826E5577-F48E-48C4-B788-4237C7C64054}C:\users\primitive\desktop\igg-huniecam.studio\huniecamstudio.exe] => (Block) C:\users\primitive\desktop\igg-huniecam.studio\huniecamstudio.exe
FirewallRules: [UDP Query User{8EE5BE3A-F201-4B23-92EA-00303D2F81B9}C:\users\primitive\desktop\igg-huniecam.studio\huniecamstudio.exe] => (Block) C:\users\primitive\desktop\igg-huniecam.studio\huniecamstudio.exe
FirewallRules: [TCP Query User{71689633-D477-4FA3-93C7-39DBD8D16D0B}C:\users\primitive\desktop\stuff\huniecamstudio.exe] => (Allow) C:\users\primitive\desktop\stuff\huniecamstudio.exe
FirewallRules: [UDP Query User{27419A28-CEAF-4934-9067-F9E56798A149}C:\users\primitive\desktop\stuff\huniecamstudio.exe] => (Allow) C:\users\primitive\desktop\stuff\huniecamstudio.exe
FirewallRules: [TCP Query User{6BB72CFE-E6C9-488E-AFF8-4C42BB966AD3}G:\non-steam games\hearthstone\hearthstone.exe] => (Allow) G:\non-steam games\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{B6347567-B904-4E85-8E5E-D12FE7AD6B69}G:\non-steam games\hearthstone\hearthstone.exe] => (Allow) G:\non-steam games\hearthstone\hearthstone.exe
FirewallRules: [TCP Query User{0B7EA474-5A25-4B8A-B994-1513540C3243}C:\program files (x86)\overwatch\overwatch.exe] => (Allow) C:\program files (x86)\overwatch\overwatch.exe
FirewallRules: [UDP Query User{A2A64718-D7CE-425D-8560-15ABFD84E229}C:\program files (x86)\overwatch\overwatch.exe] => (Allow) C:\program files (x86)\overwatch\overwatch.exe
FirewallRules: [TCP Query User{7736D49B-8E9F-4C87-855D-E2A19BCCB59C}G:\new folder\heroes of the storm\versions\base42273\heroesofthestorm_x64.exe] => (Allow) G:\new folder\heroes of the storm\versions\base42273\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{1B00BB64-BBE7-49F4-B690-75EF262E2C5E}G:\new folder\heroes of the storm\versions\base42273\heroesofthestorm_x64.exe] => (Allow) G:\new folder\heroes of the storm\versions\base42273\heroesofthestorm_x64.exe
FirewallRules: [{F11A6418-583B-4BF4-BBB3-D99BBB3B311F}] => (Allow) G:\Steam\SteamApps\common\Depth\Binaries\Win32\DepthGame.exe
FirewallRules: [{F3B40AAB-4713-4A2E-A857-1DD7013ACAAC}] => (Allow) G:\Steam\SteamApps\common\Depth\Binaries\Win32\DepthGame.exe
FirewallRules: [TCP Query User{1A7FB639-11ED-46E5-8932-FA17C6FC5D7E}G:\steam\steamapps\common\the orion project\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) G:\steam\steamapps\common\the orion project\orion\binaries\win64\orion-win64-shipping.exe
FirewallRules: [UDP Query User{A5C8EBCC-699E-4F6F-BFD8-BF07593D6353}G:\steam\steamapps\common\the orion project\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) G:\steam\steamapps\common\the orion project\orion\binaries\win64\orion-win64-shipping.exe
FirewallRules: [{2E6C0288-6D7C-4326-AEB4-EAD4FC13974A}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{38366E24-9DD0-49C6-B75F-B82810C36C0A}] => (Allow) LPort=2869
FirewallRules: [{933CF27E-CDC8-46C2-8C32-54C742A26086}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{554E64E0-949D-48E5-A53D-1F12FD8B9D3E}G:\new folder\overwatch\overwatch.exe] => (Allow) G:\new folder\overwatch\overwatch.exe
FirewallRules: [UDP Query User{E374850A-708E-450A-8CC5-5F768F4CBE08}G:\new folder\overwatch\overwatch.exe] => (Allow) G:\new folder\overwatch\overwatch.exe
FirewallRules: [TCP Query User{A034A264-0945-466C-B892-5A5228B0651D}G:\5kplayer\5kplayer.exe] => (Allow) G:\5kplayer\5kplayer.exe
FirewallRules: [UDP Query User{C5F98DCB-D2DA-4B11-9343-035AE2F2AB7F}G:\5kplayer\5kplayer.exe] => (Allow) G:\5kplayer\5kplayer.exe
FirewallRules: [TCP Query User{1BDF9A2F-CD29-4E5E-A082-C38AF929DAE3}G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle-win64-shipping.exe] => (Allow) G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle-win64-shipping.exe
FirewallRules: [UDP Query User{7613A658-F25F-4404-8E58-F5EA70D316C2}G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle-win64-shipping.exe] => (Allow) G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle-win64-shipping.exe
FirewallRules: [{8A0F9ABD-4B7B-4B99-BBD7-A0C569DE9D3C}] => (Allow) LPort=3724
FirewallRules: [{2FDD3BE2-9AE2-4E50-87D5-C75A81102691}] => (Allow) LPort=80
FirewallRules: [{64B5E32C-9C1B-46CD-B0C0-AF4960C6BA50}] => (Allow) LPort=3724
FirewallRules: [{0F99289A-A5F7-422C-9402-3B7926840156}] => (Allow) G:\Steam\SteamApps\common\Guns of Icarus Online\GunsOfIcarusOnline.exe
FirewallRules: [{D062639C-BE7D-4157-9324-71092FA90889}] => (Allow) G:\Steam\SteamApps\common\Guns of Icarus Online\GunsOfIcarusOnline.exe
FirewallRules: [{E0E46D31-D846-433F-93BB-C40904D76206}] => (Allow) G:\Steam\SteamApps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{6D25C008-C437-4F1F-BDB4-836EB6CD91C7}] => (Allow) G:\Steam\SteamApps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [TCP Query User{63443DFF-2AB7-43C1-8214-30B975D2C89E}G:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) G:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{5570ED2F-A868-4505-8D6F-AF68B4627C86}G:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) G:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [{932D63EC-38F6-4AE0-9D77-51B8E11419A7}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\PA.exe
FirewallRules: [{8B4BD4CE-9BC1-4122-84CD-E06FC899FDFD}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\PA.exe
FirewallRules: [{A97DEDDE-8734-44C5-8468-66F39BBE8CF0}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\PA.exe
FirewallRules: [{F5F33787-D7C4-4739-948D-4CF5489C3196}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\PA.exe
FirewallRules: [{699B12A2-F38A-45F5-90A0-C0D6FA07048C}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\crashupload.exe
FirewallRules: [{0A946021-97EC-4123-8B35-3F540E4C0B87}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\crashupload.exe
FirewallRules: [{2532257F-66FE-4A7F-B558-7DEB53E91923}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\host\CoherentUI_Host.exe
FirewallRules: [{E847E4B7-F8CA-40EF-BE4E-7178535D8AFF}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\host\CoherentUI_Host.exe
FirewallRules: [{0689DDDF-B42B-4EE1-97E3-C93CB1769EC1}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\crashupload.exe
FirewallRules: [{A6FE3A00-4642-44DB-A8E7-6DC7EDC91103}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\crashupload.exe
FirewallRules: [{2860814A-C858-435B-93FF-CAEAF06283E5}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\host\CoherentUI_Host.exe
FirewallRules: [{B71182B9-2FF4-4350-A587-12661B101AE2}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\host\CoherentUI_Host.exe
FirewallRules: [{D7323373-425E-4712-9CAF-B9EAAA0BD3BD}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\server.exe
FirewallRules: [{2FC5CCF0-1EBA-4F2E-AEF2-3564E3BE2089}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\server.exe
FirewallRules: [{8599F9E1-4132-4FCE-9E2A-134AF4221A9F}] => (Allow) C:\Program Files (x86)\Java\jre1.8.0_91\bin\java.exe
FirewallRules: [{8491AA07-3E7C-4D2C-970F-6DDD8647E6E2}] => (Allow) C:\Program Files (x86)\Java\jre1.8.0_91\bin\java.exe
FirewallRules: [{680C8538-AB76-4C9D-AA64-88528517232B}] => (Allow) C:\Users\Primitive\Ubiquiti UniFi\bin\mongod.exe
FirewallRules: [{90022BBC-7821-4A38-8499-7D4720C7F399}] => (Allow) C:\Users\Primitive\Ubiquiti UniFi\bin\mongod.exe
FirewallRules: [TCP Query User{70314229-B02C-47BC-803D-36EAD79CB19E}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe
FirewallRules: [UDP Query User{809CF0FE-0CFC-43F4-8B08-DE1EA5404EC2}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe
FirewallRules: [TCP Query User{0A4BB1E4-2739-45A6-9B44-7574F239D6FE}G:\new folder\overwatch test\overwatch.exe] => (Allow) G:\new folder\overwatch test\overwatch.exe
FirewallRules: [UDP Query User{1EE99792-B9F5-4336-B6A4-67CDE297D939}G:\new folder\overwatch test\overwatch.exe] => (Allow) G:\new folder\overwatch test\overwatch.exe
FirewallRules: [TCP Query User{A731D180-3785-4690-B244-8E072AACA54B}C:\users\primitive\appdata\local\roblox\versions\version-ff140f5bd46141f7\robloxstudiobeta.exe] => (Allow) C:\users\primitive\appdata\local\roblox\versions\version-ff140f5bd46141f7\robloxstudiobeta.exe
FirewallRules: [UDP Query User{7890BBC5-C71C-45FC-90CA-F355C715C194}C:\users\primitive\appdata\local\roblox\versions\version-ff140f5bd46141f7\robloxstudiobeta.exe] => (Allow) C:\users\primitive\appdata\local\roblox\versions\version-ff140f5bd46141f7\robloxstudiobeta.exe
FirewallRules: [{85A541F6-343A-415C-B0CC-41F490595474}] => (Allow) G:\Steam\SteamApps\common\Evolve\Bin64_SteamRetail\Evolve.exe
FirewallRules: [{B3306EE5-DEE6-4CDA-B7FE-EF05D863260D}] => (Allow) G:\Steam\SteamApps\common\Evolve\Bin64_SteamRetail\Evolve.exe
FirewallRules: [TCP Query User{6134967A-DD57-43EE-9C37-B49E9B734E02}G:\new folder\starcraft ii\versions\base44983\sc2_x64.exe] => (Allow) G:\new folder\starcraft ii\versions\base44983\sc2_x64.exe
FirewallRules: [UDP Query User{D7997AEA-89B2-4C2D-8D18-197288A3B3D6}G:\new folder\starcraft ii\versions\base44983\sc2_x64.exe] => (Allow) G:\new folder\starcraft ii\versions\base44983\sc2_x64.exe
FirewallRules: [TCP Query User{A3F2F9DB-7E59-4228-B86B-90275A4CECC1}G:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) G:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [UDP Query User{72E3CBF9-EA97-42BF-AEBB-C409E5EAE144}G:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) G:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [{53EF9765-8F3F-4CE0-891F-6ABD0BCCF0CA}] => (Allow) G:\Steam\SteamApps\common\Robocraft\Robocraft.exe
FirewallRules: [{BA877EC9-C8B6-482F-8301-28A60C63338D}] => (Allow) G:\Steam\SteamApps\common\Robocraft\Robocraft.exe
FirewallRules: [{F4B04EE7-CE5B-43A7-B020-7300ED880910}] => (Allow) C:\Users\Primitive\AppData\Local\Temp\QQVipDownloader\mhfc_1471404134_46113\MiniQQDL.exe
FirewallRules: [{4CD296B7-581C-4259-BACC-6CD4A284EF77}] => (Allow) C:\Users\Primitive\AppData\Local\Temp\QQVipDownloader\mhfc_1471404134_46113\MiniQQDL.exe
FirewallRules: [TCP Query User{50C74FB9-13D1-4C0F-B363-2C3454C39C2F}C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1471404134_46113\teniodl.exe] => (Allow) C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1471404134_46113\teniodl.exe
FirewallRules: [UDP Query User{4E57BD46-5D4B-4445-BEAE-89D68AF55E29}C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1471404134_46113\teniodl.exe] => (Allow) C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1471404134_46113\teniodl.exe
FirewallRules: [{DE1E98E7-D7D7-4D9A-B4D2-13432A2B5137}] => (Allow) G:\MHO_Setup_1.0.10.281.exe
FirewallRules: [{AA64C9C3-345B-45A6-B70C-0160C707B77D}] => (Allow) C:\Users\Primitive\AppData\Roaming\Tencent\怪物猎人Online\B0DEBE954B4E9315DB8B362D20D3CDBB\TenioDL\teniodl.exe
FirewallRules: [{67205B16-3A61-4047-AD66-C2BCE10F7EBC}] => (Allow) C:\Users\Primitive\AppData\Roaming\Tencent\怪物猎人Online\B0DEBE954B4E9315DB8B362D20D3CDBB\TenioDL\teniodl.exe
FirewallRules: [{DB59E90A-56E4-420D-9F34-A77FFD35A498}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe
FirewallRules: [{FC74637D-B211-4EFB-AEE3-CACE48FDDBDC}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe
FirewallRules: [{9640D995-3E8B-4B47-B24E-D1DF382E7A36}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe
FirewallRules: [{CEDE9F51-5B8F-4CCD-B830-73E73E7F7A8E}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe
FirewallRules: [{40741CA0-A58F-4341-AD44-A15FEC3B0B70}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe
FirewallRules: [{3A379FC4-8321-492C-AB7E-F9C97A82FA62}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe
FirewallRules: [TCP Query User{01336705-8EAD-4B36-BF65-D9C44FA9FEBC}G:\new folder (2)\monster hunter online\bin\client\bin32\mhoclient.exe] => (Allow) G:\new folder (2)\monster hunter online\bin\client\bin32\mhoclient.exe
FirewallRules: [UDP Query User{3B9A6431-CFC2-4DC3-A89B-53215014C478}G:\new folder (2)\monster hunter online\bin\client\bin32\mhoclient.exe] => (Allow) G:\new folder (2)\monster hunter online\bin\client\bin32\mhoclient.exe
FirewallRules: [{B1FE646A-C2FB-45D2-A8E9-CB422DB1CCAC}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{91C7C2FF-6B69-4EE3-84A5-D879D600722F}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{CCCB8CA6-598C-4530-947B-AAB3BDF7AAE3}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{29501E58-6243-482A-991A-4846F989EE04}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{B72F9913-9157-41F6-86AA-209D85553F52}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\apps\cqs\qtalk\bin\miniqtalk.exe
FirewallRules: [{AD359F3F-BDBE-4180-A8BD-DD70B3A26389}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\apps\cqs\qtalk\bin\miniqtalk.exe
FirewallRules: [{1B669228-ECC6-4BD2-8A6F-5F16E4BB126A}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\apps\cqs\qtalk\bin\miniqtalk.exe
FirewallRules: [{F5F2B9C2-95EF-439B-9CF3-52C59EC8258F}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\apps\cqs\qtalk\bin\miniqtalk.exe
FirewallRules: [TCP Query User{4EE97130-FC57-4E76-AC59-99C458FA3C80}G:\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => (Allow) G:\steam\steamapps\common\paladins\binaries\win32\paladins.exe
FirewallRules: [UDP Query User{5B808CD5-68F6-496E-B030-D5313FC11F38}G:\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => (Allow) G:\steam\steamapps\common\paladins\binaries\win32\paladins.exe
FirewallRules: [TCP Query User{9E7CC219-9CB1-4CD5-9335-EBE8533250B9}G:\non-steam games\overwatch\overwatch\overwatch.exe] => (Allow) G:\non-steam games\overwatch\overwatch\overwatch.exe
FirewallRules: [UDP Query User{239FFC90-287E-495D-AB59-7FC23145B069}G:\non-steam games\overwatch\overwatch\overwatch.exe] => (Allow) G:\non-steam games\overwatch\overwatch\overwatch.exe
FirewallRules: [{58497E58-8543-4AF6-BF1A-C796522D7DA6}] => (Allow) C:\Program Files\Echobit\Evolve\EvoSvc.exe
FirewallRules: [{47E63243-0844-48FE-9178-FAC61F31B063}] => (Allow) C:\Program Files\Echobit\Evolve\EvolveClient.exe
FirewallRules: [TCP Query User{C30F45C8-7A7E-43BA-9AAA-5A0A299DA24C}G:\non-steam games\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) G:\non-steam games\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{E2717E1C-8DA8-449D-A315-2559FA37A472}G:\non-steam games\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) G:\non-steam games\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{01F09A5D-56CE-4C06-B469-C085C6012A5F}C:\program files (x86)\java\jre1.8.0_101\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_101\bin\javaw.exe
FirewallRules: [UDP Query User{80F297EA-BC13-4FB9-8DDF-2A331DAFCC40}C:\program files (x86)\java\jre1.8.0_101\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_101\bin\javaw.exe
FirewallRules: [{61721D0C-C71A-426C-B802-0B547DC1B72F}] => (Allow) G:\Steam\SteamApps\common\SMITE\Binaries\Win32\HirezBridge.exe
FirewallRules: [{43ACBCD6-DF48-4705-9F58-0FFE049BB002}] => (Allow) G:\Steam\SteamApps\common\SMITE\Binaries\Win32\HirezBridge.exe
FirewallRules: [TCP Query User{F8CE015C-4705-49BB-9DAF-76AAF36EF185}G:\steam\steamapps\common\smite\binaries\win32\smite.exe] => (Allow) G:\steam\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [UDP Query User{395F18A2-BD53-4597-8E8F-3E6B097674BF}G:\steam\steamapps\common\smite\binaries\win32\smite.exe] => (Allow) G:\steam\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [{9CEF9ED1-1338-4485-8D6D-1179EC70FDA3}] => (Allow) G:\Steam\SteamApps\common\ClusterTruck\Clustertruck.exe
FirewallRules: [{B81A4465-DE02-478B-B2D9-E4AB64D227FA}] => (Allow) G:\Steam\SteamApps\common\ClusterTruck\Clustertruck.exe
FirewallRules: [{C5FEAB5F-ED17-42C6-93BF-7AB26DB81BA5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{72E2569E-16E8-4425-88AC-00603841CFFC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{45330A66-5327-4487-8F80-32299908671A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{3C099841-F916-4F42-9021-A854C1357C97}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{9220A0FA-B81F-4D45-AC6A-044F0B6CF166}C:\users\primitive\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\primitive\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{3C4E80F4-A092-4CB6-B540-A86C8952ABEF}C:\users\primitive\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\primitive\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{B710C0C4-08D9-4145-BE07-866286CB2C00}G:\non-steam games\overwatch\overwatch test\overwatch.exe] => (Allow) G:\non-steam games\overwatch\overwatch test\overwatch.exe
FirewallRules: [UDP Query User{5F375B40-602F-416C-BAA3-3EF955EBE04A}G:\non-steam games\overwatch\overwatch test\overwatch.exe] => (Allow) G:\non-steam games\overwatch\overwatch test\overwatch.exe
FirewallRules: [{33153EA4-8120-4115-92CE-6BF18BA639F2}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{2B9A0DD5-F582-4889-9535-849B35C83F43}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{17839E54-88C3-47D1-A7A0-01D3012CED39}] => (Allow) G:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe
FirewallRules: [{72A80336-7300-4FDE-A344-9853CE2CCB18}] => (Allow) G:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe
FirewallRules: [{4D705E32-6B9B-47B0-9186-E328FEC23B20}] => (Allow) G:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [{98ED55A4-A4DA-4C4F-9BEF-37A596F6AFD4}] => (Allow) G:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [{0AAF8FD3-D5E6-47BD-AE05-B74BAB84B9F1}] => (Allow) G:\Steam\SteamApps\common\Golf With Your Friends\Golf With Your Friends.exe
FirewallRules: [{4677494E-ED85-4AA0-A66D-902FBE60FB4A}] => (Allow) G:\Steam\SteamApps\common\Golf With Your Friends\Golf With Your Friends.exe
FirewallRules: [{E4C68492-42B1-4604-915F-21EAAD919D23}] => (Allow) G:\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{CFA6BAC5-80B5-47DE-BF2D-209F657C615E}] => (Allow) G:\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{788EBD02-A83A-489C-9813-CF080BEFB30F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [TCP Query User{0B5233E7-8472-4AC6-8565-AD80C46D3885}C:\program files (x86)\battle.net\battle.net.8098\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.8098\battle.net.exe
FirewallRules: [UDP Query User{401DF6F8-8DC1-4ACB-8AD5-ABCD9EC01CAB}C:\program files (x86)\battle.net\battle.net.8098\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.8098\battle.net.exe
FirewallRules: [TCP Query User{DE649370-1ED2-4595-BCD2-B0A032E1640E}G:\non-steam games\heroes of the storm\versions\base47479\heroesofthestorm_x64.exe] => (Allow) G:\non-steam games\heroes of the storm\versions\base47479\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{4805A180-E9B2-49F8-AA75-0D4C081DFB89}G:\non-steam games\heroes of the storm\versions\base47479\heroesofthestorm_x64.exe] => (Allow) G:\non-steam games\heroes of the storm\versions\base47479\heroesofthestorm_x64.exe
FirewallRules: [TCP Query User{DAE0D35D-7DB3-41D4-9723-ED957BB53903}G:\non-steam games\paragon\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) G:\non-steam games\paragon\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [UDP Query User{9F098143-7E37-4D90-973B-602A203A55A0}G:\non-steam games\paragon\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) G:\non-steam games\paragon\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [TCP Query User{0B5BB3F9-0A5A-4288-82B7-2353A6C24341}G:\non-steam games\paragon\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) G:\non-steam games\paragon\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{4F1A7742-DF00-4870-B9B5-C7E64624FE46}G:\non-steam games\paragon\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) G:\non-steam games\paragon\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [TCP Query User{51BC0EDE-9905-4195-84C8-BF8939908167}G:\non-steam games\heroes of the storm\versions\base48027\heroesofthestorm_x64.exe] => (Allow) G:\non-steam games\heroes of the storm\versions\base48027\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{C15FC5C7-99CF-4E5A-81C4-5A877BDBEE9D}G:\non-steam games\heroes of the storm\versions\base48027\heroesofthestorm_x64.exe] => (Allow) G:\non-steam games\heroes of the storm\versions\base48027\heroesofthestorm_x64.exe
FirewallRules: [TCP Query User{601CBF0E-78FD-4E8C-8772-947FB93CC163}C:\program files (x86)\battle.net\battle.net.8142\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.8142\battle.net.exe
FirewallRules: [UDP Query User{4F1CDB89-3C49-433D-86B1-2D5CC565EF99}C:\program files (x86)\battle.net\battle.net.8142\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.8142\battle.net.exe
FirewallRules: [{36D44B57-18D0-4CCB-857D-EAD0612ED622}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{A61ED98D-9440-405A-ADB5-1EAEF2939046}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{6D69BDBC-C579-450C-959A-516BBF68A966}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{EDF74F32-C9FB-41CB-8C78-D08F9A57FDC2}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{F1406EE3-FB4E-40B4-BB3C-791F4B8E61EA}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{A5A8C7D3-2EF3-40DF-B166-6F8856341311}] => (Allow) G:\Steam\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{039CC2A6-8753-4013-81A2-192A59E09349}] => (Allow) G:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [{76A2E5F8-8DE7-403B-943C-444F76A881A3}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{8D0D9326-C7CC-49CA-B92A-2066BC8FB3B4}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{05B77BB7-1039-449D-8CF0-2FE18A7D3B2B}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{AAD8536A-C438-4191-8919-10DAB48B0B5B}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{35C23D4C-B2E7-4FEE-B85D-A3F57B11B1D2}] => (Allow) G:\Steam\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{794435CE-BA25-4692-9EF8-FEE00FC5ABC2}] => (Allow) G:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [{06BD6921-70BE-4F1F-9A4F-FC21D6F2519F}] => (Allow) G:\Steam\SteamApps\common\Deus Ex Mankind Divided\retail\DXMD.exe
FirewallRules: [{838F76D9-1920-427F-94F4-5628B0920463}] => (Allow) G:\Steam\SteamApps\common\Deus Ex Mankind Divided\retail\DXMD.exe
FirewallRules: [{8B533F19-34FF-4DCC-8EB9-45195214C599}] => (Allow) G:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{8FA91647-E1BB-4C0A-8020-07B890998ED0}] => (Allow) G:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{4D3DDB90-2F38-49FA-A655-293BAACD5A1F}C:\users\primitive\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\primitive\appdata\local\skypeplugin\pluginhost.exe
FirewallRules: [UDP Query User{DBCE5122-0967-41F0-983B-1BB6E7E6E5B9}C:\users\primitive\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\primitive\appdata\local\skypeplugin\pluginhost.exe
FirewallRules: [{F285FC3E-1572-4385-AB56-B7D21DE2B1BE}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{FCB42E26-0AF2-4681-80E8-B3CFA38A5EB1}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [TCP Query User{B6E957B7-7F7D-4B16-8C4F-95446738EDEF}C:\users\primitive\appdata\local\roblox\versions\version-506d9e2f695a4b05\robloxstudiobeta.exe] => (Allow) C:\users\primitive\appdata\local\roblox\versions\version-506d9e2f695a4b05\robloxstudiobeta.exe
FirewallRules: [UDP Query User{854267C1-E051-42CD-8387-E8599E49DFED}C:\users\primitive\appdata\local\roblox\versions\version-506d9e2f695a4b05\robloxstudiobeta.exe] => (Allow) C:\users\primitive\appdata\local\roblox\versions\version-506d9e2f695a4b05\robloxstudiobeta.exe
FirewallRules: [{A5656CAA-E9E5-4CC3-8A79-9724545EB2FE}] => (Allow) C:\WINDOWS\system32\rundll32.exe
FirewallRules: [{1E2617A2-D5F6-4502-AEE9-D480E007CA65}] => (Allow) C:\Users\Primitive\AppData\Local\ddnowyes.exe
FirewallRules: [{E9588507-2313-4762-A50D-4A9BC832F19B}] => (Allow) C:\Users\Primitive\AppData\Local\15150554.exe
FirewallRules: [{1164D2F8-5ADE-4E91-AE40-363A1857F0D2}] => (Allow) C:\Users\Primitive\AppData\Local\tinstall.exe
FirewallRules: [{3A395A1F-936B-4FF0-8710-ACE9917AC481}] => (Allow) C:\Users\Primitive\AppData\Local\sc76258249.exe
FirewallRules: [{18A66A25-E1E5-4171-B75F-2549447C195D}] => (Allow) C:\Users\Primitive\AppData\Local\ddnow.exe
FirewallRules: [{ECEEF00D-A964-4D2E-B07C-F1416D28C662}] => (Allow) C:\Program Files (x86)\Hits\omagh.exe
FirewallRules: [{CDA10417-98CE-4E1B-A851-8B3AEF1EE378}] => (Allow) C:\Program Files (x86)\Defects\omagh.exe
FirewallRules: [{C14106C9-8997-405B-B721-26E3FE0AEEE1}] => (Allow) C:\Program Files (x86)\acidosis\popularity.exe
FirewallRules: [{46ACFB00-CC12-4F10-BBFE-ADEDCC06C7F2}] => (Allow) C:\Program Files (x86)\acidosis\hijacking.exe
FirewallRules: [{05EA7D8A-7FF5-4521-B9C9-6771B65766F3}] => (Allow) C:\Program Files (x86)\operant\hoosiers.exe
FirewallRules: [{8609F1BC-8209-48BF-BB46-BCE98E4C61C7}] => (Allow) C:\Program Files (x86)\Ralph\demurrage.exe
FirewallRules: [{B5A97146-0EDE-49AC-AABD-AD6F8F0D22A9}] => (Allow) C:\WINDOWS\cutler.exe
FirewallRules: [{D02A3C86-A7FA-4549-9C2D-96ADE4BFBB83}] => (Allow) C:\Users\Primitive\AppData\Local\BrowserAir\Application\BrowserairExec.exe
FirewallRules: [{24C5640D-65EF-4A6C-B98C-25D98020B0BA}] => (Allow) C:\Users\Primitive\AppData\Local\Temp\QQVipDownloader\mhfc_1482204874_49659\MiniQQDL.exe
FirewallRules: [{CDB59CAC-6EA0-44E9-B9C5-79DEF750C615}] => (Allow) C:\Users\Primitive\AppData\Local\Temp\QQVipDownloader\mhfc_1482204874_49659\MiniQQDL.exe
FirewallRules: [TCP Query User{257134CB-FB7F-4A5F-B70E-615278E2F341}C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1482204874_49659\teniodl.exe] => (Allow) C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1482204874_49659\teniodl.exe
FirewallRules: [UDP Query User{B9B4FABC-C0C7-4271-873D-AAB2E8375D52}C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1482204874_49659\teniodl.exe] => (Allow) C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1482204874_49659\teniodl.exe
FirewallRules: [{94165F0E-E46B-4FAD-819B-F80DD84B6B2E}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\MHO_Setup_2.0.11.371.exe
FirewallRules: [TCP Query User{54C272DB-35D3-4B75-8531-03FA9660D41F}G:\non-steam games\monster hunter online\monster hunter online\tcls\tenprotect\tensafe_1.exe] => (Block) G:\non-steam games\monster hunter online\monster hunter online\tcls\tenprotect\tensafe_1.exe
FirewallRules: [UDP Query User{3E26C92C-C10E-4022-8C7B-2B853009E665}G:\non-steam games\monster hunter online\monster hunter online\tcls\tenprotect\tensafe_1.exe] => (Block) G:\non-steam games\monster hunter online\monster hunter online\tcls\tenprotect\tensafe_1.exe
FirewallRules: [TCP Query User{74A20A0A-A3A0-4E05-A6A1-3E19C20C810F}G:\non-steam games\monster hunter online\monster hunter online\bin\client\bin32\mhoclient.exe] => (Allow) G:\non-steam games\monster hunter online\monster hunter online\bin\client\bin32\mhoclient.exe
FirewallRules: [UDP Query User{6BAC593A-0CCB-4133-87FE-87FF5647C786}G:\non-steam games\monster hunter online\monster hunter online\bin\client\bin32\mhoclient.exe] => (Allow) G:\non-steam games\monster hunter online\monster hunter online\bin\client\bin32\mhoclient.exe
FirewallRules: [{1CDB3F0C-5413-44ED-A81C-275A4F02EB44}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{6A10EFAA-6B24-4BA9-91F8-D2C1EB57E198}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{9F0E65CA-13E0-41A0-A772-D6BAD6AC2008}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{8DFF6AEE-9F5E-4982-B96F-6855C931C2AB}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{50AC1C5E-C9B2-4D1D-8157-85CFE9721CB0}] => (Allow) C:\Users\Primitive\AppData\Roaming\Tencent\怪物猎人Online\4BA085A6FF5A5BACCD60AEFD185903C5\TenioDL\teniodl.exe
FirewallRules: [{B5DAAF87-D3EC-484D-AF79-C975877DB8CE}] => (Allow) C:\Users\Primitive\AppData\Roaming\Tencent\怪物猎人Online\4BA085A6FF5A5BACCD60AEFD185903C5\TenioDL\teniodl.exe
FirewallRules: [{BE36E881-D2F3-4BDA-873B-D5E344EC19C8}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe
FirewallRules: [{684762C8-09C7-4D20-9CB2-0AB204FCB721}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe
FirewallRules: [{75E28886-DB3E-42BD-AEF6-4AFC51A2893F}] => (Allow) G:\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{73C8C34B-996A-42BB-9E0A-83CBC1746732}] => (Allow) G:\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{D8DA5CEC-1D66-42C7-8B78-73163972EB98}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{9C0CA1A0-16C0-465B-B993-B151C7891A50}C:\program files (x86)\logmein ignition\lmiignition.exe] => (Allow) C:\program files (x86)\logmein ignition\lmiignition.exe
FirewallRules: [UDP Query User{40E2A678-1545-4C46-A612-8AAF7EC23DD1}C:\program files (x86)\logmein ignition\lmiignition.exe] => (Allow) C:\program files (x86)\logmein ignition\lmiignition.exe
FirewallRules: [TCP Query User{9739C598-80F5-4741-8A01-E3E405A3F46B}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{0C3A87F1-55D8-4C31-8311-9F6E02BE9576}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [{D6A13C37-397B-43B1-B4C3-1811650C09DD}] => (Allow) G:\Steam\SteamApps\common\Guns of Icarus Online\workshop\Workshop.exe
FirewallRules: [{AF66AF0B-6362-47C7-830E-FE6962B43302}] => (Allow) G:\Steam\SteamApps\common\Guns of Icarus Online\workshop\Workshop.exe
FirewallRules: [{263AD6B1-E37B-455B-A44C-CD7DCE21974E}] => (Allow) G:\Steam\SteamApps\common\Depth\BETA\Binaries\Win32\DepthGame.exe
FirewallRules: [{9240B2EF-2D8E-4E3E-A98B-97128E127B4D}] => (Allow) G:\Steam\SteamApps\common\Depth\BETA\Binaries\Win32\DepthGame.exe
FirewallRules: [{8D538934-A429-4E32-A470-6ADBCED3F4AB}] => (Allow) G:\Steam\SteamApps\common\Natural Selection 2\NS2.exe
FirewallRules: [{0587789B-43B1-4355-96D1-2C34AA798207}] => (Allow) G:\Steam\SteamApps\common\Natural Selection 2\NS2.exe
FirewallRules: [{84627E43-4C3B-4134-989E-FFFF1949E403}] => (Allow) G:\Steam\SteamApps\common\Super Hexagon\superhexagon.exe
FirewallRules: [{E0BAB900-2391-4176-8E6D-DB728B375794}] => (Allow) G:\Steam\SteamApps\common\Super Hexagon\superhexagon.exe
FirewallRules: [{8B626F06-40B1-4CA8-A7C7-02D7E6864E0F}] => (Allow) G:\Steam\SteamApps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{A639E62A-CD46-415C-87FC-E23CA40FDFDD}] => (Allow) G:\Steam\SteamApps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{76ED4AFF-6B43-4B40-B678-3D88F6A60052}] => (Allow) C:\Users\Primitive\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{952AD197-BB15-4421-B7BC-ADCAE8CE8DB7}] => (Allow) C:\Users\Primitive\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{879C7199-73F5-4DBD-934C-DE69807A919B}] => (Allow) C:\Users\Primitive\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{646BE1CC-964E-4EC4-87E5-D2F5DCAF1D5B}] => (Allow) C:\Users\Primitive\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{8C423CA3-1393-4A11-816E-F8A0FD6FA15D}] => (Allow) C:\Users\Primitive\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{B85EE0DE-7034-44D2-9D29-2E4F1CDC4852}] => (Allow) C:\Users\Primitive\AppData\Roaming\BitTorrent\BitTorrent.exe
==================== Restore Points =========================
06-03-2017 21:24:49 Installed Zoo Tycoon 2 - Ultimate Collection
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (03/27/2017 09:23:32 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 08:51:36 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 08:21:47 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 08:07:05 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 06:59:22 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 06:53:58 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 06:53:57 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 06:53:56 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 06:49:15 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 06:40:54 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
System errors:
=============
Error: (03/27/2017 09:22:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 08:52:19 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 08:52:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 08:52:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 08:22:04 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 08:22:04 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 08:21:44 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{3185A766-B338-11E4-A71E-12E3F512A338}
and APPID
{7006698D-2974-4091-A424-85DD0B909E23}
to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 07:52:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 07:52:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 07:22:14 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
CodeIntegrity:
===================================
Date: 2017-03-24 20:04:45.301
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-03-02 23:02:35.596
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-19 19:02:26.632
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-11 23:42:31.566
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-10 20:20:45.126
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-09 21:55:28.712
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-08 21:07:40.208
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-02 14:23:36.745
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-12-14 18:59:40.276
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-11-16 18:20:33.005
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-4790K CPU @ 4.00GHz
Percentage of memory in use: 73%
Total physical RAM: 8143.07 MB
Available physical RAM: 2163.11 MB
Total Virtual: 14799.07 MB
Available Virtual: 2778.49 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:111.01 GB) (Free:12.31 GB) NTFS
Drive g: (New Volume) (Fixed) (Total:931.39 GB) (Free:365.44 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or
(Size: 111.8 GB) (Disk ID: E8FD8D51)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
========================================================
Disk: 1 (MBR Code: Windows 7 or
(Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================
Addition.txt log
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
Ran by [redacted] (27-03-2017 21:36:19)
Running from C:\Users\[redacted]\Desktop
Windows 10 Home Version 1511 (X64) (2016-02-07 05:06:49)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-233390903-2661952563-451428824-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-233390903-2661952563-451428824-503 - Limited - Disabled)
Guest (S-1-5-21-233390903-2661952563-451428824-501 - Limited - Disabled)
Primitive (S-1-5-21-233390903-2661952563-451428824-1001 - Administrator - Enabled) => C:\Users\Primitive
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
64 Bit HP CIO Components Installer (Version: 21.2.1 - HP Inc.) Hidden
Ansel (Version: 378.92 - NVIDIA Corporation) Hidden
ARK: Survival Evolved (HKLM\...\Steam App 346110) (Version: - Studio Wildcard)
BitTorrent (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\BitTorrent) (Version: 7.9.9.43389 - BitTorrent Inc.)
Classic Shell (HKLM\...\{383BB30A-B4A7-4666-9A83-22CFA8640097}) (Version: 4.3.0 - IvoSoft)
Cloud Penguin (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\Cloud Penguin) (Version: 2.0.6210.36208 - Cloud Penguin) <==== ATTENTION
Clustertruck (HKLM\...\Steam App 397950) (Version: - Landfall Games)
Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve)
Depth (HKLM\...\Steam App 274940) (Version: - Digital Confectioners)
Deus Ex: Mankind Divided™ (HKLM\...\Steam App 337000) (Version: - Eidos Montreal)
Discord (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\Discord) (Version: 0.0.297 - Hammer & Chisel, Inc.)
Dishonored (HKLM\...\Steam App 205100) (Version: - Arkane Studios)
Epic Games Launcher (HKLM-x32\...\{2DE76AAC-8061-4D9B-B7BA-A7CFBE0F8048}) (Version: 1.1.86.0 - Epic Games, Inc.)
Git version 2.11.1 (HKLM\...\Git_is1) (Version: 2.11.1 - The Git Development Community)
Golf With Your Friends (HKLM\...\Steam App 431240) (Version: - Blacklight Interactive)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
Grand Theft Auto V (HKLM\...\Steam App 271590) (Version: - Rockstar North)
Guns of Icarus Online (HKLM\...\Steam App 209080) (Version: - Muse Games)
Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment)
HiPatch (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF000}) (Version: 5.0.6.4 - Hi-Rez Studios)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.7870.2024 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{86CE1746-9EFF-3C9C-8755-81EA8903AC34}) (Version: - )
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: - )
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Monster Hunter Online (HKLM-x32\...\Monster Hunter Online) (Version: - Tencent)
Natural Selection 2 (HKLM\...\Steam App 4920) (Version: - Unknown Worlds Entertainment)
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.3.1 - Notepad++ Team)
NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 378.92 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.4.0.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.4.0.70 - NVIDIA Corporation)
NVIDIA Graphics Driver 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.92 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.23 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
NvNodejs (Version: 3.4.0.70 - NVIDIA Corporation) Hidden
NvTelemetry (Version: 2.3.16.0 - NVIDIA Corporation) Hidden
NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7870.2024 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7870.2024 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7870.2024 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7668.2066 - Microsoft Corporation) Hidden
Online.io Application (x32 Version: 2.1.0 - Microleaves) Hidden <==== ATTENTION
paint.net (HKLM\...\{6AC1101E-7561-43C9-BEEA-4AB1D220D8FF}) (Version: 4.0.13 - dotPDN LLC)
Planetary Annihilation: TITANS (HKLM\...\Steam App 386070) (Version: - Uber Entertainment)
Python 3.5.1 (64-bit) (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\{b8440650-9dbe-4b7d-8167-6e0e3dcdf5d0}) (Version: 3.5.1150.0 - Python Software Foundation)
Python 3.5.1 Add to Path (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Core Interpreter (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Development Libraries (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Documentation (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Executables (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Launcher (32-bit) (HKLM-x32\...\{EC00AEF9-6544-4FEC-8152-C8949CDDCC85}) (Version: 3.5.150.0 - Python Software Foundation)
Python 3.5.1 pip Bootstrap (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Standard Library (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Tcl/Tk Support (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Test Suite (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Python 3.5.1 Utility Scripts (64-bit) (Version: 3.5.1150.0 - Python Software Foundation) Hidden
Rainmeter (HKLM-x32\...\Rainmeter) (Version: 4.0 r2746 - )
ROBLOX Player for Primitive (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version: - ROBLOX Corporation)
ROBLOX Studio for Primitive (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}) (Version: - ROBLOX Corporation)
Robocraft (HKLM\...\Steam App 301520) (Version: - Freejam)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.0.5 - Rockstar Games)
SHIELD Streaming (Version: 7.1.0351 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 3.4.0.70 - NVIDIA Corporation) Hidden
Skype Web Plugin (HKLM-x32\...\{E8A70371-2C4D-4B12-831D-6A4BB9AC7AEF}) (Version: 7.29.0.73 - Skype Technologies S.A.)
SMITE (HKLM\...\Steam App 386360) (Version: - Hi-Rez Studios)
Spotify (HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\Spotify) (Version: 1.0.51.693.g6ea1e7f6 - Spotify AB)
Super Hexagon (HKLM\...\Steam App 221640) (Version: - Terry Cavanagh)
Traffic Exchange (x32 Version: 2.1.0 - Microleaves) Hidden <==== ATTENTION
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 3.5.3 - Tweaking.com)
UE4 Prerequisites (x64) (Version: 1.0.10.0 - Epic Games, Inc.) Hidden
Unity Web Player (x64) (All users) (HKLM\...\UnityWebPlayer) (Version: 4.6.6f2 - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 24.0.1 - Ubisoft)
Vulkan Run Time Libraries 1.0.17.0 (HKLM\...\VulkanRT1.0.17.0) (Version: 1.0.17.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.)
Warframe (HKLM\...\Steam App 230410) (Version: - Digital Extremes)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
Zoo Tycoon 2 - Ultimate Collection (HKLM-x32\...\InstallShield_{9CC4840D-EF1C-406F-AF08-3C19EB1335B9}) (Version: 1.00.0000 - Microsoft Game Studios)
Zoo Tycoon 2 - Ultimate Collection (x32 Version: 1.00.0000 - Microsoft Game Studios) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-233390903-2661952563-451428824-1001_Classes\CLSID\{A03A51A2-5B59-4ECE-96D1-037F7F2A0D8F}\localserver32 -> C:\Users\Primitive\AppData\Local\SkypePlugin\7.29.0.73\GatewayVersion-x64.exe (Skype Technologies S.A.)
CustomCLSID: HKU\S-1-5-21-233390903-2661952563-451428824-1001_Classes\CLSID\{CBF9CD8C-2714-4F36-B76A-43E6C7547BC2}\localserver32 -> C:\Users\Primitive\AppData\Local\SkypePlugin\7.29.0.73\EdgeCalling.exe (Skype Technologies S.A.)
CustomCLSID: HKU\S-1-5-21-233390903-2661952563-451428824-1001_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Primitive\AppData\Local\Roblox\Versions\version-ca61db0aa1b8462c\RobloxProxy64.dll (ROBLOX Corporation)
CustomCLSID: HKU\S-1-5-21-233390903-2661952563-451428824-1001_Classes\CLSID\{FE0A3EA9-4DDA-4B0A-9981-5ABE8F0186CD}\InprocServer32 -> C:\Users\Primitive\AppData\Local\SkypePlugin\7.29.0.73\GatewayActiveX-x64.dll (Skype Technologies S.A.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {041BD7F2-9D4D-4C9B-B7BC-46A4F59A7431} - System32\Tasks\Traffic Exchange v209 - 3 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {0C557DF1-E92D-458A-8E6F-6C3D1D24242A} - System32\Tasks\Traffic Exchange => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {0CC8C3D9-71F8-4D15-97D6-38645131BAB9} - System32\Tasks\Online Application Guardian => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {0D2AD9B3-ADDB-40A5-A136-3E0102ADBF82} - System32\Tasks\Traffic Exchange Guardian => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {10661CA9-C443-4EB0-91B3-4676DC558427} - System32\Tasks\Online Application v2 Guard => C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {236D5E93-AC70-40C8-8507-71ED54E82425} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-02-23] (NVIDIA Corporation)
Task: {36FC4F2D-2FC1-4C0F-9F44-41B280A32779} - System32\Tasks\Traffic Exchange v209 - 2 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {3F2DCA07-5247-4396-A732-55CFACB24016} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-02-23] (NVIDIA Corporation)
Task: {3F39F139-E558-49F2-94D9-5443E998C7DA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {45A64C74-3F8C-42EE-8DEB-DF1A83FCCD4D} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-03-05] (Microsoft Corporation)
Task: {4752A296-189E-4FD5-A55B-16D29353EEF8} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe [2017-02-04] ()
Task: {4B25888B-8985-4F3F-B91E-496D45D90F69} - System32\Tasks\Traffic Exchange v2 - 2 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {54E033B2-E527-4D00-B522-6E3845CDF2E1} - System32\Tasks\Online Application v209 => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {5A63E6F8-C360-4ED1-AC63-7167C03D1785} - System32\Tasks\Online Application Guard => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {5DBF077D-34EF-4AC4-ABE9-B051D1CC57E4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-03-08] (Microsoft Corporation)
Task: {66E21683-3ABA-4D5F-B96A-97B64E81E6F5} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
Task: {718654D7-45FE-4114-8169-D671714DB898} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
Task: {7813514E-C52D-4C08-BCE8-6CFD9B1B3685} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation)
Task: {7EA057AD-62FC-43FD-BE2E-2A8DC9D0A261} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-02-23] (NVIDIA Corporation)
Task: {85148911-6B3A-4DA0-BE2A-EC73B3E91C67} - System32\Tasks\Traffic Exchange v2 - 3 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {8C66C891-8007-46D0-8A70-0F04AFD28BC9} - System32\Tasks\Online Application v2 Guardian => C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {95BF1522-875E-4138-B6E6-A36B795D7D25} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation)
Task: {97119FF0-B283-4618-9ECE-8ACD504E0A01} - System32\Tasks\Online Application v2 => C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {9C8FF20F-ACB5-43FE-B59C-991453FAB0FE} - System32\Tasks\Traffic Exchange v209 - 1 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {AE34D356-1919-4106-9136-CD5F218496D8} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation)
Task: {B481EED0-482D-4E11-B005-299A4747938A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {B4F276E6-7AE1-4A1D-8CD2-D1B6059AC5F4} - System32\Tasks\Online Application v209 Guardian => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {B5015F98-BD11-457C-AF42-4257BD35FEFC} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-03-08] (Microsoft Corporation)
Task: {BF3CD351-0A42-4629-87ED-61FC9961439A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-03-08] (Microsoft Corporation)
Task: {C62F2AFE-67E3-4033-B157-B302AA4C9F01} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-03-05] (Microsoft Corporation)
Task: {DB3840F1-A2BA-4B6F-9098-D94CACB970FC} - System32\Tasks\Traffic Exchange Updater => C:\Program Files (x86)\Microleaves\Traffic Exchange\Traffic Exchange Updater.exe [2017-02-15] (Microleaves) <==== ATTENTION
Task: {ED519B11-3B3F-4B0B-9C63-CC6B72B6E04B} - System32\Tasks\Traffic Exchange Guard => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {EE8D7CAE-3277-4C79-84FD-215F3C05BA5F} - System32\Tasks\Online Application => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {EF195EFC-DAE2-47F4-9AF7-9896A8FF1C62} - System32\Tasks\Online Application v209 Guard => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {F8691C31-7151-4D63-ABB0-CA44666DB472} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation)
Task: {F926E2CA-0E8B-4955-BF7F-CC1836FDF8E0} - System32\Tasks\Online Application Updater => C:\Program Files (x86)\Microleaves\Online.io Application\Online Application Updater.exe [2017-02-15] (Microleaves) <==== ATTENTION
Task: {FC17B985-39D1-41BC-88AA-E56D1701A505} - System32\Tasks\Traffic Exchange v2 - 1 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {FD3CA9F1-D4CB-4460-BF78-0FAC0BF6ED8E} - System32\Tasks\PPI Update => C:\WINDOWS\explorer.exe "hxxp://windowsdefender.site/download/download.php?mn=9996" <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Online Application Updater.job => C:\Program Files (x86)\Microleaves\Online.io Application\Online Application Updater.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Online Application v2 Guard.job => C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Online Application v2 Guardian.job => C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Online Application v2.job => C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Online Application v209 Guard.job => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Online Application v209 Guardian.job => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Online Application v209.job => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange Updater.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Traffic Exchange Updater.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 2.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 2.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\Primitive\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Intеrnеt Ехplоrеr.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.bat ()
Shortcut: C:\Users\Primitive\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gооglе Сhrоmе.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat ()
Shortcut: C:\Users\Primitive\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gооglе Сhrоmе.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Еpiс Gаmеs Lаunсhеr.lnk -> G:\Non-Steam Games\Paragon\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.bat ()
==================== Loaded Modules (Whitelisted) ==============
2015-10-30 03:17 - 2015-10-30 03:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll
2017-03-26 17:26 - 2017-03-26 17:26 - 00230400 _____ () C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\prot3b4f51ef-73de-4277-a2f6-3e687129283e.tmpfs
2016-10-08 15:14 - 2017-02-23 14:35 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll
2016-10-08 15:14 - 2017-02-23 14:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-03-24 16:52 - 2017-03-24 16:52 - 00008704 _____ () C:\Users\Primitive\AppData\Local\Temp\WS\realtek_amd64.exe
2017-03-26 21:14 - 2017-03-13 18:08 - 00016384 _____ () C:\WINDOWS\src_srv\winsrcsrv.exe
2015-10-30 03:18 - 2015-10-30 03:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-02-07 01:10 - 2017-03-16 19:16 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-03-27 17:02 - 2017-03-27 17:02 - 00368640 _____ () C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\knsF76C.tmp
2016-11-08 18:33 - 2016-10-25 05:42 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-11-08 18:33 - 2016-10-25 05:42 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-05-19 20:11 - 2016-05-19 20:11 - 00959168 _____ () C:\Users\Primitive\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2016-10-14 23:27 - 2017-02-25 04:59 - 08921648 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2017-01-16 21:30 - 2017-01-16 21:30 - 00230064 _____ () G:\rhinobot\Notepad++\NppShell_06.dll
2016-02-07 03:36 - 2015-12-07 00:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-07-16 19:31 - 2016-06-30 23:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-11-08 18:34 - 2016-10-25 03:01 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2016-11-08 18:34 - 2016-10-25 00:49 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-11-08 18:33 - 2016-10-25 00:44 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-11-08 18:34 - 2016-10-25 00:45 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-11-08 18:33 - 2016-10-25 00:48 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-01-23 09:31 - 2017-01-23 09:31 - 01037824 _____ () C:\Users\Primitive\AppData\Roaming\Rainmeter\Plugins\SpotifyPlugin.dll
2017-01-01 09:59 - 2017-01-01 09:59 - 00173568 _____ () G:\Rainmeter\Plugins\AudioLevel.DLL
2017-01-01 09:59 - 2017-01-01 09:59 - 00120832 _____ () G:\Rainmeter\Plugins\QuotePlugin.dll
2017-01-01 09:59 - 2017-01-01 09:59 - 00093696 _____ () G:\Rainmeter\Plugins\Process.DLL
2016-04-18 16:14 - 2016-04-18 16:14 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2017-03-24 16:53 - 2017-03-24 16:53 - 00404992 _____ () C:\Users\Primitive\AppData\Local\Temp\WS\realtek_amd64.lib.dll
2016-10-08 15:14 - 2017-02-23 14:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-10-08 15:14 - 2017-02-23 14:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll
2016-10-08 15:14 - 2017-02-23 14:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2016-10-09 15:09 - 2017-03-23 17:24 - 67725936 _____ () C:\Users\Primitive\AppData\Roaming\Spotify\libcef.dll
2016-10-09 15:09 - 2017-03-23 17:24 - 01929840 _____ () C:\Users\Primitive\AppData\Roaming\Spotify\libglesv2.dll
2016-10-09 15:09 - 2017-03-23 17:24 - 00087152 _____ () C:\Users\Primitive\AppData\Roaming\Spotify\libegl.dll
2016-10-08 15:14 - 2017-02-23 14:34 - 65708992 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll
2016-10-08 15:14 - 2017-02-23 10:30 - 00338488 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node
2016-10-08 15:14 - 2017-02-23 10:30 - 00252352 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node
2016-10-08 15:14 - 2017-02-23 10:30 - 02443320 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node
2016-10-08 15:14 - 2017-02-23 10:30 - 00385592 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node
2016-10-08 15:14 - 2017-02-23 10:30 - 00543288 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node
2016-10-08 15:14 - 2017-02-23 10:30 - 00468536 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node
2017-03-23 17:25 - 2017-03-09 20:13 - 00674592 _____ () G:\Steam\SDL2.dll
2016-12-20 18:49 - 2016-08-31 21:02 - 04969248 _____ () G:\Steam\v8.dll
2017-03-23 17:25 - 2017-03-22 20:52 - 02465056 _____ () G:\Steam\video.dll
2016-12-20 18:49 - 2016-01-27 03:49 - 02549760 _____ () G:\Steam\libavcodec-56.dll
2016-12-20 18:49 - 2016-01-27 03:49 - 00491008 _____ () G:\Steam\libavformat-56.dll
2016-12-20 18:49 - 2016-01-27 03:49 - 00332800 _____ () G:\Steam\libavresample-2.dll
2016-12-20 18:49 - 2016-01-27 03:49 - 00442880 _____ () G:\Steam\libavutil-54.dll
2016-12-20 18:49 - 2016-01-27 03:49 - 00485888 _____ () G:\Steam\libswscale-3.dll
2016-12-20 18:49 - 2016-08-31 21:02 - 01563936 _____ () G:\Steam\icui18n.dll
2016-12-20 18:49 - 2016-08-31 21:02 - 01195296 _____ () G:\Steam\icuuc.dll
2017-03-23 17:25 - 2017-03-22 20:52 - 00839456 _____ () G:\Steam\bin\chromehtml.DLL
2016-12-20 18:49 - 2016-07-04 18:17 - 00266560 _____ () G:\Steam\openvr_api.dll
2017-03-10 17:32 - 2017-01-30 17:41 - 68875552 _____ () G:\Steam\bin\cef\cef.win7\libcef.dll
2017-03-23 17:25 - 2017-03-22 20:52 - 00383776 _____ () G:\Steam\steam.dll
2016-12-20 18:49 - 2015-09-24 19:52 - 00119208 _____ () G:\Steam\winh264.dll
2016-04-18 16:14 - 2016-04-18 16:14 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-04-18 16:14 - 2016-04-18 16:14 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2017-01-11 19:44 - 2017-01-04 15:28 - 01958912 _____ () C:\Users\Primitive\AppData\Local\Discord\app-0.0.297\ffmpeg.dll
2017-01-11 19:44 - 2017-01-11 19:44 - 01082880 _____ () \\?\C:\Users\Primitive\AppData\Roaming\discord\0.0.297\modules\discord_voice\discord_voice.node
2017-01-11 19:44 - 2017-01-11 19:44 - 03750400 _____ () \\?\C:\Users\Primitive\AppData\Roaming\discord\0.0.297\modules\discord_voice\libdiscord.dll
2017-01-11 19:44 - 2017-01-11 19:44 - 00914432 _____ () \\?\C:\Users\Primitive\AppData\Roaming\discord\0.0.297\modules\discord_utils\discord_utils.node
2017-01-11 19:44 - 2017-01-11 19:44 - 01127424 _____ () \\?\C:\Users\Primitive\AppData\Roaming\discord\0.0.297\modules\discord_toaster\discord_toaster.node
2017-01-11 19:44 - 2017-01-04 15:28 - 02278912 _____ () C:\Users\Primitive\AppData\Local\Discord\app-0.0.297\libglesv2.dll
2017-01-11 19:44 - 2017-01-04 15:28 - 00096768 _____ () C:\Users\Primitive\AppData\Local\Discord\app-0.0.297\libegl.dll
2017-03-27 17:07 - 2017-03-27 17:07 - 00148992 _____ () \\?\C:\Users\Primitive\AppData\Local\Temp\839B.tmp.node
2017-01-11 19:44 - 2017-01-11 19:44 - 02658304 _____ () \\?\C:\Users\Primitive\AppData\Roaming\discord\0.0.297\modules\discord_rpc\discord_rpc.node
2017-01-11 19:44 - 2017-03-22 16:07 - 02665976 _____ () \\?\C:\Users\Primitive\AppData\Roaming\discord\0.0.297\modules\discord_contact_import\discord_contact_import.node
2016-05-19 20:11 - 2016-05-19 20:11 - 00679624 _____ () C:\Users\Primitive\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll
2016-10-14 23:27 - 2017-02-25 04:14 - 08921136 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\1033\GrooveIntlResource.dll
2017-02-10 19:46 - 2017-02-01 05:01 - 01870168 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll
2017-02-10 19:46 - 2017-02-01 05:01 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll
2015-10-30 03:18 - 2015-10-30 03:18 - 00025088 _____ () C:\Windows\SYSTEM32\GamePanelExternalHook.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\77684213.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\77684213.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\google.com -> hxxps://google.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-10-30 03:24 - 2017-01-12 18:08 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-233390903-2661952563-451428824-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Primitive\AppData\Roaming\Rainmeter\Layouts\Test\Wallpaper.bmp
DNS Servers: 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-233390903-2661952563-451428824-1001\...\StartupApproved\Run: => "Steam"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{623EAC45-1598-4EEE-BD2F-C554D19FAA58}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{882D562F-D8CF-47F0-91D5-5FF20B26E4D6}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{7F32F6EE-7D5A-4F87-890D-C43E6E5B1D6B}] => (Allow) G:\Steam\Steam.exe
FirewallRules: [{37B62C7A-6269-448C-B0F0-C5F4DD354D39}] => (Allow) G:\Steam\Steam.exe
FirewallRules: [{62D0C5AA-BAC2-46E9-875E-4A481824893A}] => (Allow) G:\Steam\bin\steamwebhelper.exe
FirewallRules: [{13C2835A-1846-4F6B-8DBB-D5013C3538E6}] => (Allow) G:\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{0DB0ECE8-19E6-4A88-938C-7A7268B91FE9}C:\windows.old\users\primitive\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\windows.old\users\primitive\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{DE87E032-962F-4070-80E1-0F26707C370F}C:\windows.old\users\primitive\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\windows.old\users\primitive\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [{E12D0410-C1CD-4A84-9D2B-A549A6FE2C42}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{66C4B93B-2AA9-4B9B-8CBD-B461DFB712E2}G:\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) G:\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [UDP Query User{3908B23D-06E8-409A-955B-5EB59B18597B}G:\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) G:\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [TCP Query User{450E2008-E396-433A-A2C2-A8DD4DA0B3CE}G:\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) G:\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{44F09366-8258-4497-AE39-AAF7A7B95146}G:\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) G:\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [{A0E6F6F2-A76C-4190-A05C-EEC139D4A3A9}] => (Allow) G:\Steam\SteamApps\common\primal_carnage\Binaries\Win32\PrimalCarnageGame.exe
FirewallRules: [{436E6A5A-63DA-466D-97E6-04584B352F1B}] => (Allow) G:\Steam\SteamApps\common\primal_carnage\Binaries\Win32\PrimalCarnageGame.exe
FirewallRules: [{AF18843B-D775-4C5B-961C-E4BE8E0D4D85}] => (Allow) G:\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{C2B76408-6377-4C86-8CA0-23DC44A17D81}] => (Allow) G:\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{DFDDC1C2-D40E-452E-BA03-AD93719A722A}] => (Allow) G:\Steam\SteamApps\common\The Isle\TheIsle.exe
FirewallRules: [{0C7AE528-35AA-4CA9-BEEF-9273410642C4}] => (Allow) G:\Steam\SteamApps\common\The Isle\TheIsle.exe
FirewallRules: [TCP Query User{F94CD4E5-A551-4850-AC31-08A71433FA3E}G:\epic games\4.10\engine\binaries\win64\ue4editor.exe] => (Allow) G:\epic games\4.10\engine\binaries\win64\ue4editor.exe
FirewallRules: [UDP Query User{4CCE744F-9643-4D7F-8D50-08A1F5F83204}G:\epic games\4.10\engine\binaries\win64\ue4editor.exe] => (Allow) G:\epic games\4.10\engine\binaries\win64\ue4editor.exe
FirewallRules: [TCP Query User{F2230469-9934-4F74-B6BB-F29B3E279064}G:\epic games\4.10\engine\binaries\dotnet\swarmagent.exe] => (Block) G:\epic games\4.10\engine\binaries\dotnet\swarmagent.exe
FirewallRules: [UDP Query User{E1999BC2-8EC4-468A-BC7F-0D0176ADE6A1}G:\epic games\4.10\engine\binaries\dotnet\swarmagent.exe] => (Block) G:\epic games\4.10\engine\binaries\dotnet\swarmagent.exe
FirewallRules: [TCP Query User{212B39BF-7C90-4A18-A2A0-49AEE8CBB838}G:\non-steam games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe] => (Allow) G:\non-steam games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe
FirewallRules: [UDP Query User{73721E6F-4821-40A6-92A7-4A410A50DD18}G:\non-steam games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe] => (Allow) G:\non-steam games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe
FirewallRules: [{0CC94886-5F31-440B-8375-8650C49219BA}] => (Allow) G:\Steam\SteamApps\common\GarrysMod\hl2.exe
FirewallRules: [{1327FD25-DABA-4F25-8721-6FF3482ABA8E}] => (Allow) G:\Steam\SteamApps\common\GarrysMod\hl2.exe
FirewallRules: [TCP Query User{23BC6235-E46E-443A-A509-DBB2C0214867}C:\users\primitive\appdata\local\roblox\versions\version-d0ea8fd26e144a48\robloxstudiobeta.exe] => (Allow) C:\users\primitive\appdata\local\roblox\versions\version-d0ea8fd26e144a48\robloxstudiobeta.exe
FirewallRules: [UDP Query User{7A57483F-0EDC-4AAA-8F16-7E6225D68E64}C:\users\primitive\appdata\local\roblox\versions\version-d0ea8fd26e144a48\robloxstudiobeta.exe] => (Allow) C:\users\primitive\appdata\local\roblox\versions\version-d0ea8fd26e144a48\robloxstudiobeta.exe
FirewallRules: [{8BC5D79D-ECCB-4824-9964-F2E73A249C60}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe
FirewallRules: [{0E2B86AF-644D-43C9-9426-2B434A9EC1DA}] => (Allow) C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe
FirewallRules: [TCP Query User{477E4D73-E14F-4979-BA4E-463E509A435C}C:\users\primitive\appdata\local\temp\rar$exa0.688\microsoft toolkit.exe] => (Allow) C:\users\primitive\appdata\local\temp\rar$exa0.688\microsoft toolkit.exe
FirewallRules: [UDP Query User{1B6BC57A-E430-4B42-B2D2-6D16FA5FEBD0}C:\users\primitive\appdata\local\temp\rar$exa0.688\microsoft toolkit.exe] => (Allow) C:\users\primitive\appdata\local\temp\rar$exa0.688\microsoft toolkit.exe
FirewallRules: [TCP Query User{6C500A62-A08C-4EA0-96B7-7D3CCD8E02C0}C:\users\primitive\appdata\local\temp\rar$exa0.979\microsoft toolkit.exe] => (Allow) C:\users\primitive\appdata\local\temp\rar$exa0.979\microsoft toolkit.exe
FirewallRules: [UDP Query User{45C7D1CE-847C-42D9-A580-3607B07097F0}C:\users\primitive\appdata\local\temp\rar$exa0.979\microsoft toolkit.exe] => (Allow) C:\users\primitive\appdata\local\temp\rar$exa0.979\microsoft toolkit.exe
FirewallRules: [TCP Query User{F3520FB5-F1CC-4074-87DE-5CF415688408}C:\users\primitive\appdata\local\temp\rar$exa0.958\microsoft toolkit.exe] => (Allow) C:\users\primitive\appdata\local\temp\rar$exa0.958\microsoft toolkit.exe
FirewallRules: [UDP Query User{8B4AD559-39E8-4A1D-96C8-F4410E45AF2A}C:\users\primitive\appdata\local\temp\rar$exa0.958\microsoft toolkit.exe] => (Allow) C:\users\primitive\appdata\local\temp\rar$exa0.958\microsoft toolkit.exe
FirewallRules: [TCP Query User{826E5577-F48E-48C4-B788-4237C7C64054}C:\users\primitive\desktop\igg-huniecam.studio\huniecamstudio.exe] => (Block) C:\users\primitive\desktop\igg-huniecam.studio\huniecamstudio.exe
FirewallRules: [UDP Query User{8EE5BE3A-F201-4B23-92EA-00303D2F81B9}C:\users\primitive\desktop\igg-huniecam.studio\huniecamstudio.exe] => (Block) C:\users\primitive\desktop\igg-huniecam.studio\huniecamstudio.exe
FirewallRules: [TCP Query User{71689633-D477-4FA3-93C7-39DBD8D16D0B}C:\users\primitive\desktop\stuff\huniecamstudio.exe] => (Allow) C:\users\primitive\desktop\stuff\huniecamstudio.exe
FirewallRules: [UDP Query User{27419A28-CEAF-4934-9067-F9E56798A149}C:\users\primitive\desktop\stuff\huniecamstudio.exe] => (Allow) C:\users\primitive\desktop\stuff\huniecamstudio.exe
FirewallRules: [TCP Query User{6BB72CFE-E6C9-488E-AFF8-4C42BB966AD3}G:\non-steam games\hearthstone\hearthstone.exe] => (Allow) G:\non-steam games\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{B6347567-B904-4E85-8E5E-D12FE7AD6B69}G:\non-steam games\hearthstone\hearthstone.exe] => (Allow) G:\non-steam games\hearthstone\hearthstone.exe
FirewallRules: [TCP Query User{0B7EA474-5A25-4B8A-B994-1513540C3243}C:\program files (x86)\overwatch\overwatch.exe] => (Allow) C:\program files (x86)\overwatch\overwatch.exe
FirewallRules: [UDP Query User{A2A64718-D7CE-425D-8560-15ABFD84E229}C:\program files (x86)\overwatch\overwatch.exe] => (Allow) C:\program files (x86)\overwatch\overwatch.exe
FirewallRules: [TCP Query User{7736D49B-8E9F-4C87-855D-E2A19BCCB59C}G:\new folder\heroes of the storm\versions\base42273\heroesofthestorm_x64.exe] => (Allow) G:\new folder\heroes of the storm\versions\base42273\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{1B00BB64-BBE7-49F4-B690-75EF262E2C5E}G:\new folder\heroes of the storm\versions\base42273\heroesofthestorm_x64.exe] => (Allow) G:\new folder\heroes of the storm\versions\base42273\heroesofthestorm_x64.exe
FirewallRules: [{F11A6418-583B-4BF4-BBB3-D99BBB3B311F}] => (Allow) G:\Steam\SteamApps\common\Depth\Binaries\Win32\DepthGame.exe
FirewallRules: [{F3B40AAB-4713-4A2E-A857-1DD7013ACAAC}] => (Allow) G:\Steam\SteamApps\common\Depth\Binaries\Win32\DepthGame.exe
FirewallRules: [TCP Query User{1A7FB639-11ED-46E5-8932-FA17C6FC5D7E}G:\steam\steamapps\common\the orion project\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) G:\steam\steamapps\common\the orion project\orion\binaries\win64\orion-win64-shipping.exe
FirewallRules: [UDP Query User{A5C8EBCC-699E-4F6F-BFD8-BF07593D6353}G:\steam\steamapps\common\the orion project\orion\binaries\win64\orion-win64-shipping.exe] => (Allow) G:\steam\steamapps\common\the orion project\orion\binaries\win64\orion-win64-shipping.exe
FirewallRules: [{2E6C0288-6D7C-4326-AEB4-EAD4FC13974A}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{38366E24-9DD0-49C6-B75F-B82810C36C0A}] => (Allow) LPort=2869
FirewallRules: [{933CF27E-CDC8-46C2-8C32-54C742A26086}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{554E64E0-949D-48E5-A53D-1F12FD8B9D3E}G:\new folder\overwatch\overwatch.exe] => (Allow) G:\new folder\overwatch\overwatch.exe
FirewallRules: [UDP Query User{E374850A-708E-450A-8CC5-5F768F4CBE08}G:\new folder\overwatch\overwatch.exe] => (Allow) G:\new folder\overwatch\overwatch.exe
FirewallRules: [TCP Query User{A034A264-0945-466C-B892-5A5228B0651D}G:\5kplayer\5kplayer.exe] => (Allow) G:\5kplayer\5kplayer.exe
FirewallRules: [UDP Query User{C5F98DCB-D2DA-4B11-9343-035AE2F2AB7F}G:\5kplayer\5kplayer.exe] => (Allow) G:\5kplayer\5kplayer.exe
FirewallRules: [TCP Query User{1BDF9A2F-CD29-4E5E-A082-C38AF929DAE3}G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle-win64-shipping.exe] => (Allow) G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle-win64-shipping.exe
FirewallRules: [UDP Query User{7613A658-F25F-4404-8E58-F5EA70D316C2}G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle-win64-shipping.exe] => (Allow) G:\steam\steamapps\common\the isle\theisle\binaries\win64\theisle-win64-shipping.exe
FirewallRules: [{8A0F9ABD-4B7B-4B99-BBD7-A0C569DE9D3C}] => (Allow) LPort=3724
FirewallRules: [{2FDD3BE2-9AE2-4E50-87D5-C75A81102691}] => (Allow) LPort=80
FirewallRules: [{64B5E32C-9C1B-46CD-B0C0-AF4960C6BA50}] => (Allow) LPort=3724
FirewallRules: [{0F99289A-A5F7-422C-9402-3B7926840156}] => (Allow) G:\Steam\SteamApps\common\Guns of Icarus Online\GunsOfIcarusOnline.exe
FirewallRules: [{D062639C-BE7D-4157-9324-71092FA90889}] => (Allow) G:\Steam\SteamApps\common\Guns of Icarus Online\GunsOfIcarusOnline.exe
FirewallRules: [{E0E46D31-D846-433F-93BB-C40904D76206}] => (Allow) G:\Steam\SteamApps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{6D25C008-C437-4F1F-BDB4-836EB6CD91C7}] => (Allow) G:\Steam\SteamApps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [TCP Query User{63443DFF-2AB7-43C1-8214-30B975D2C89E}G:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) G:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{5570ED2F-A868-4505-8D6F-AF68B4627C86}G:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) G:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [{932D63EC-38F6-4AE0-9D77-51B8E11419A7}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\PA.exe
FirewallRules: [{8B4BD4CE-9BC1-4122-84CD-E06FC899FDFD}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\PA.exe
FirewallRules: [{A97DEDDE-8734-44C5-8468-66F39BBE8CF0}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\PA.exe
FirewallRules: [{F5F33787-D7C4-4739-948D-4CF5489C3196}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\PA.exe
FirewallRules: [{699B12A2-F38A-45F5-90A0-C0D6FA07048C}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\crashupload.exe
FirewallRules: [{0A946021-97EC-4123-8B35-3F540E4C0B87}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\crashupload.exe
FirewallRules: [{2532257F-66FE-4A7F-B558-7DEB53E91923}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\host\CoherentUI_Host.exe
FirewallRules: [{E847E4B7-F8CA-40EF-BE4E-7178535D8AFF}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x86\host\CoherentUI_Host.exe
FirewallRules: [{0689DDDF-B42B-4EE1-97E3-C93CB1769EC1}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\crashupload.exe
FirewallRules: [{A6FE3A00-4642-44DB-A8E7-6DC7EDC91103}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\crashupload.exe
FirewallRules: [{2860814A-C858-435B-93FF-CAEAF06283E5}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\host\CoherentUI_Host.exe
FirewallRules: [{B71182B9-2FF4-4350-A587-12661B101AE2}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\host\CoherentUI_Host.exe
FirewallRules: [{D7323373-425E-4712-9CAF-B9EAAA0BD3BD}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\server.exe
FirewallRules: [{2FC5CCF0-1EBA-4F2E-AEF2-3564E3BE2089}] => (Allow) G:\Steam\SteamApps\common\Planetary Annihilation Titans\bin_x64\server.exe
FirewallRules: [{8599F9E1-4132-4FCE-9E2A-134AF4221A9F}] => (Allow) C:\Program Files (x86)\Java\jre1.8.0_91\bin\java.exe
FirewallRules: [{8491AA07-3E7C-4D2C-970F-6DDD8647E6E2}] => (Allow) C:\Program Files (x86)\Java\jre1.8.0_91\bin\java.exe
FirewallRules: [{680C8538-AB76-4C9D-AA64-88528517232B}] => (Allow) C:\Users\Primitive\Ubiquiti UniFi\bin\mongod.exe
FirewallRules: [{90022BBC-7821-4A38-8499-7D4720C7F399}] => (Allow) C:\Users\Primitive\Ubiquiti UniFi\bin\mongod.exe
FirewallRules: [TCP Query User{70314229-B02C-47BC-803D-36EAD79CB19E}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe
FirewallRules: [UDP Query User{809CF0FE-0CFC-43F4-8B08-DE1EA5404EC2}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe
FirewallRules: [TCP Query User{0A4BB1E4-2739-45A6-9B44-7574F239D6FE}G:\new folder\overwatch test\overwatch.exe] => (Allow) G:\new folder\overwatch test\overwatch.exe
FirewallRules: [UDP Query User{1EE99792-B9F5-4336-B6A4-67CDE297D939}G:\new folder\overwatch test\overwatch.exe] => (Allow) G:\new folder\overwatch test\overwatch.exe
FirewallRules: [TCP Query User{A731D180-3785-4690-B244-8E072AACA54B}C:\users\primitive\appdata\local\roblox\versions\version-ff140f5bd46141f7\robloxstudiobeta.exe] => (Allow) C:\users\primitive\appdata\local\roblox\versions\version-ff140f5bd46141f7\robloxstudiobeta.exe
FirewallRules: [UDP Query User{7890BBC5-C71C-45FC-90CA-F355C715C194}C:\users\primitive\appdata\local\roblox\versions\version-ff140f5bd46141f7\robloxstudiobeta.exe] => (Allow) C:\users\primitive\appdata\local\roblox\versions\version-ff140f5bd46141f7\robloxstudiobeta.exe
FirewallRules: [{85A541F6-343A-415C-B0CC-41F490595474}] => (Allow) G:\Steam\SteamApps\common\Evolve\Bin64_SteamRetail\Evolve.exe
FirewallRules: [{B3306EE5-DEE6-4CDA-B7FE-EF05D863260D}] => (Allow) G:\Steam\SteamApps\common\Evolve\Bin64_SteamRetail\Evolve.exe
FirewallRules: [TCP Query User{6134967A-DD57-43EE-9C37-B49E9B734E02}G:\new folder\starcraft ii\versions\base44983\sc2_x64.exe] => (Allow) G:\new folder\starcraft ii\versions\base44983\sc2_x64.exe
FirewallRules: [UDP Query User{D7997AEA-89B2-4C2D-8D18-197288A3B3D6}G:\new folder\starcraft ii\versions\base44983\sc2_x64.exe] => (Allow) G:\new folder\starcraft ii\versions\base44983\sc2_x64.exe
FirewallRules: [TCP Query User{A3F2F9DB-7E59-4228-B86B-90275A4CECC1}G:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) G:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [UDP Query User{72E3CBF9-EA97-42BF-AEBB-C409E5EAE144}G:\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) G:\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [{53EF9765-8F3F-4CE0-891F-6ABD0BCCF0CA}] => (Allow) G:\Steam\SteamApps\common\Robocraft\Robocraft.exe
FirewallRules: [{BA877EC9-C8B6-482F-8301-28A60C63338D}] => (Allow) G:\Steam\SteamApps\common\Robocraft\Robocraft.exe
FirewallRules: [{F4B04EE7-CE5B-43A7-B020-7300ED880910}] => (Allow) C:\Users\Primitive\AppData\Local\Temp\QQVipDownloader\mhfc_1471404134_46113\MiniQQDL.exe
FirewallRules: [{4CD296B7-581C-4259-BACC-6CD4A284EF77}] => (Allow) C:\Users\Primitive\AppData\Local\Temp\QQVipDownloader\mhfc_1471404134_46113\MiniQQDL.exe
FirewallRules: [TCP Query User{50C74FB9-13D1-4C0F-B363-2C3454C39C2F}C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1471404134_46113\teniodl.exe] => (Allow) C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1471404134_46113\teniodl.exe
FirewallRules: [UDP Query User{4E57BD46-5D4B-4445-BEAE-89D68AF55E29}C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1471404134_46113\teniodl.exe] => (Allow) C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1471404134_46113\teniodl.exe
FirewallRules: [{DE1E98E7-D7D7-4D9A-B4D2-13432A2B5137}] => (Allow) G:\MHO_Setup_1.0.10.281.exe
FirewallRules: [{AA64C9C3-345B-45A6-B70C-0160C707B77D}] => (Allow) C:\Users\Primitive\AppData\Roaming\Tencent\怪物猎人Online\B0DEBE954B4E9315DB8B362D20D3CDBB\TenioDL\teniodl.exe
FirewallRules: [{67205B16-3A61-4047-AD66-C2BCE10F7EBC}] => (Allow) C:\Users\Primitive\AppData\Roaming\Tencent\怪物猎人Online\B0DEBE954B4E9315DB8B362D20D3CDBB\TenioDL\teniodl.exe
FirewallRules: [{DB59E90A-56E4-420D-9F34-A77FFD35A498}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe
FirewallRules: [{FC74637D-B211-4EFB-AEE3-CACE48FDDBDC}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe
FirewallRules: [{9640D995-3E8B-4B47-B24E-D1DF382E7A36}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe
FirewallRules: [{CEDE9F51-5B8F-4CCD-B830-73E73E7F7A8E}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe
FirewallRules: [{40741CA0-A58F-4341-AD44-A15FEC3B0B70}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe
FirewallRules: [{3A379FC4-8321-492C-AB7E-F9C97A82FA62}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe
FirewallRules: [TCP Query User{01336705-8EAD-4B36-BF65-D9C44FA9FEBC}G:\new folder (2)\monster hunter online\bin\client\bin32\mhoclient.exe] => (Allow) G:\new folder (2)\monster hunter online\bin\client\bin32\mhoclient.exe
FirewallRules: [UDP Query User{3B9A6431-CFC2-4DC3-A89B-53215014C478}G:\new folder (2)\monster hunter online\bin\client\bin32\mhoclient.exe] => (Allow) G:\new folder (2)\monster hunter online\bin\client\bin32\mhoclient.exe
FirewallRules: [{B1FE646A-C2FB-45D2-A8E9-CB422DB1CCAC}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{91C7C2FF-6B69-4EE3-84A5-D879D600722F}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{CCCB8CA6-598C-4530-947B-AAB3BDF7AAE3}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{29501E58-6243-482A-991A-4846F989EE04}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{B72F9913-9157-41F6-86AA-209D85553F52}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\apps\cqs\qtalk\bin\miniqtalk.exe
FirewallRules: [{AD359F3F-BDBE-4180-A8BD-DD70B3A26389}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\apps\cqs\qtalk\bin\miniqtalk.exe
FirewallRules: [{1B669228-ECC6-4BD2-8A6F-5F16E4BB126A}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\apps\cqs\qtalk\bin\miniqtalk.exe
FirewallRules: [{F5F2B9C2-95EF-439B-9CF3-52C59EC8258F}] => (Allow) G:\New folder (2)\Monster Hunter Online\Bin\Client\Bin32\Cross\apps\cqs\qtalk\bin\miniqtalk.exe
FirewallRules: [TCP Query User{4EE97130-FC57-4E76-AC59-99C458FA3C80}G:\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => (Allow) G:\steam\steamapps\common\paladins\binaries\win32\paladins.exe
FirewallRules: [UDP Query User{5B808CD5-68F6-496E-B030-D5313FC11F38}G:\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => (Allow) G:\steam\steamapps\common\paladins\binaries\win32\paladins.exe
FirewallRules: [TCP Query User{9E7CC219-9CB1-4CD5-9335-EBE8533250B9}G:\non-steam games\overwatch\overwatch\overwatch.exe] => (Allow) G:\non-steam games\overwatch\overwatch\overwatch.exe
FirewallRules: [UDP Query User{239FFC90-287E-495D-AB59-7FC23145B069}G:\non-steam games\overwatch\overwatch\overwatch.exe] => (Allow) G:\non-steam games\overwatch\overwatch\overwatch.exe
FirewallRules: [{58497E58-8543-4AF6-BF1A-C796522D7DA6}] => (Allow) C:\Program Files\Echobit\Evolve\EvoSvc.exe
FirewallRules: [{47E63243-0844-48FE-9178-FAC61F31B063}] => (Allow) C:\Program Files\Echobit\Evolve\EvolveClient.exe
FirewallRules: [TCP Query User{C30F45C8-7A7E-43BA-9AAA-5A0A299DA24C}G:\non-steam games\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) G:\non-steam games\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{E2717E1C-8DA8-449D-A315-2559FA37A472}G:\non-steam games\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) G:\non-steam games\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{01F09A5D-56CE-4C06-B469-C085C6012A5F}C:\program files (x86)\java\jre1.8.0_101\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_101\bin\javaw.exe
FirewallRules: [UDP Query User{80F297EA-BC13-4FB9-8DDF-2A331DAFCC40}C:\program files (x86)\java\jre1.8.0_101\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_101\bin\javaw.exe
FirewallRules: [{61721D0C-C71A-426C-B802-0B547DC1B72F}] => (Allow) G:\Steam\SteamApps\common\SMITE\Binaries\Win32\HirezBridge.exe
FirewallRules: [{43ACBCD6-DF48-4705-9F58-0FFE049BB002}] => (Allow) G:\Steam\SteamApps\common\SMITE\Binaries\Win32\HirezBridge.exe
FirewallRules: [TCP Query User{F8CE015C-4705-49BB-9DAF-76AAF36EF185}G:\steam\steamapps\common\smite\binaries\win32\smite.exe] => (Allow) G:\steam\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [UDP Query User{395F18A2-BD53-4597-8E8F-3E6B097674BF}G:\steam\steamapps\common\smite\binaries\win32\smite.exe] => (Allow) G:\steam\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [{9CEF9ED1-1338-4485-8D6D-1179EC70FDA3}] => (Allow) G:\Steam\SteamApps\common\ClusterTruck\Clustertruck.exe
FirewallRules: [{B81A4465-DE02-478B-B2D9-E4AB64D227FA}] => (Allow) G:\Steam\SteamApps\common\ClusterTruck\Clustertruck.exe
FirewallRules: [{C5FEAB5F-ED17-42C6-93BF-7AB26DB81BA5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{72E2569E-16E8-4425-88AC-00603841CFFC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{45330A66-5327-4487-8F80-32299908671A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{3C099841-F916-4F42-9021-A854C1357C97}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{9220A0FA-B81F-4D45-AC6A-044F0B6CF166}C:\users\primitive\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\primitive\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{3C4E80F4-A092-4CB6-B540-A86C8952ABEF}C:\users\primitive\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\primitive\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{B710C0C4-08D9-4145-BE07-866286CB2C00}G:\non-steam games\overwatch\overwatch test\overwatch.exe] => (Allow) G:\non-steam games\overwatch\overwatch test\overwatch.exe
FirewallRules: [UDP Query User{5F375B40-602F-416C-BAA3-3EF955EBE04A}G:\non-steam games\overwatch\overwatch test\overwatch.exe] => (Allow) G:\non-steam games\overwatch\overwatch test\overwatch.exe
FirewallRules: [{33153EA4-8120-4115-92CE-6BF18BA639F2}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{2B9A0DD5-F582-4889-9535-849B35C83F43}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{17839E54-88C3-47D1-A7A0-01D3012CED39}] => (Allow) G:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe
FirewallRules: [{72A80336-7300-4FDE-A344-9853CE2CCB18}] => (Allow) G:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe
FirewallRules: [{4D705E32-6B9B-47B0-9186-E328FEC23B20}] => (Allow) G:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [{98ED55A4-A4DA-4C4F-9BEF-37A596F6AFD4}] => (Allow) G:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [{0AAF8FD3-D5E6-47BD-AE05-B74BAB84B9F1}] => (Allow) G:\Steam\SteamApps\common\Golf With Your Friends\Golf With Your Friends.exe
FirewallRules: [{4677494E-ED85-4AA0-A66D-902FBE60FB4A}] => (Allow) G:\Steam\SteamApps\common\Golf With Your Friends\Golf With Your Friends.exe
FirewallRules: [{E4C68492-42B1-4604-915F-21EAAD919D23}] => (Allow) G:\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{CFA6BAC5-80B5-47DE-BF2D-209F657C615E}] => (Allow) G:\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{788EBD02-A83A-489C-9813-CF080BEFB30F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [TCP Query User{0B5233E7-8472-4AC6-8565-AD80C46D3885}C:\program files (x86)\battle.net\battle.net.8098\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.8098\battle.net.exe
FirewallRules: [UDP Query User{401DF6F8-8DC1-4ACB-8AD5-ABCD9EC01CAB}C:\program files (x86)\battle.net\battle.net.8098\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.8098\battle.net.exe
FirewallRules: [TCP Query User{DE649370-1ED2-4595-BCD2-B0A032E1640E}G:\non-steam games\heroes of the storm\versions\base47479\heroesofthestorm_x64.exe] => (Allow) G:\non-steam games\heroes of the storm\versions\base47479\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{4805A180-E9B2-49F8-AA75-0D4C081DFB89}G:\non-steam games\heroes of the storm\versions\base47479\heroesofthestorm_x64.exe] => (Allow) G:\non-steam games\heroes of the storm\versions\base47479\heroesofthestorm_x64.exe
FirewallRules: [TCP Query User{DAE0D35D-7DB3-41D4-9723-ED957BB53903}G:\non-steam games\paragon\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) G:\non-steam games\paragon\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [UDP Query User{9F098143-7E37-4D90-973B-602A203A55A0}G:\non-steam games\paragon\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) G:\non-steam games\paragon\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [TCP Query User{0B5BB3F9-0A5A-4288-82B7-2353A6C24341}G:\non-steam games\paragon\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) G:\non-steam games\paragon\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{4F1A7742-DF00-4870-B9B5-C7E64624FE46}G:\non-steam games\paragon\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) G:\non-steam games\paragon\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [TCP Query User{51BC0EDE-9905-4195-84C8-BF8939908167}G:\non-steam games\heroes of the storm\versions\base48027\heroesofthestorm_x64.exe] => (Allow) G:\non-steam games\heroes of the storm\versions\base48027\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{C15FC5C7-99CF-4E5A-81C4-5A877BDBEE9D}G:\non-steam games\heroes of the storm\versions\base48027\heroesofthestorm_x64.exe] => (Allow) G:\non-steam games\heroes of the storm\versions\base48027\heroesofthestorm_x64.exe
FirewallRules: [TCP Query User{601CBF0E-78FD-4E8C-8772-947FB93CC163}C:\program files (x86)\battle.net\battle.net.8142\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.8142\battle.net.exe
FirewallRules: [UDP Query User{4F1CDB89-3C49-433D-86B1-2D5CC565EF99}C:\program files (x86)\battle.net\battle.net.8142\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.8142\battle.net.exe
FirewallRules: [{36D44B57-18D0-4CCB-857D-EAD0612ED622}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{A61ED98D-9440-405A-ADB5-1EAEF2939046}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{6D69BDBC-C579-450C-959A-516BBF68A966}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{EDF74F32-C9FB-41CB-8C78-D08F9A57FDC2}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{F1406EE3-FB4E-40B4-BB3C-791F4B8E61EA}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{A5A8C7D3-2EF3-40DF-B166-6F8856341311}] => (Allow) G:\Steam\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{039CC2A6-8753-4013-81A2-192A59E09349}] => (Allow) G:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [{76A2E5F8-8DE7-403B-943C-444F76A881A3}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{8D0D9326-C7CC-49CA-B92A-2066BC8FB3B4}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{05B77BB7-1039-449D-8CF0-2FE18A7D3B2B}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{AAD8536A-C438-4191-8919-10DAB48B0B5B}] => (Allow) G:\Steam\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{35C23D4C-B2E7-4FEE-B85D-A3F57B11B1D2}] => (Allow) G:\Steam\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{794435CE-BA25-4692-9EF8-FEE00FC5ABC2}] => (Allow) G:\Steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [{06BD6921-70BE-4F1F-9A4F-FC21D6F2519F}] => (Allow) G:\Steam\SteamApps\common\Deus Ex Mankind Divided\retail\DXMD.exe
FirewallRules: [{838F76D9-1920-427F-94F4-5628B0920463}] => (Allow) G:\Steam\SteamApps\common\Deus Ex Mankind Divided\retail\DXMD.exe
FirewallRules: [{8B533F19-34FF-4DCC-8EB9-45195214C599}] => (Allow) G:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{8FA91647-E1BB-4C0A-8020-07B890998ED0}] => (Allow) G:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{4D3DDB90-2F38-49FA-A655-293BAACD5A1F}C:\users\primitive\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\primitive\appdata\local\skypeplugin\pluginhost.exe
FirewallRules: [UDP Query User{DBCE5122-0967-41F0-983B-1BB6E7E6E5B9}C:\users\primitive\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\primitive\appdata\local\skypeplugin\pluginhost.exe
FirewallRules: [{F285FC3E-1572-4385-AB56-B7D21DE2B1BE}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{FCB42E26-0AF2-4681-80E8-B3CFA38A5EB1}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [TCP Query User{B6E957B7-7F7D-4B16-8C4F-95446738EDEF}C:\users\primitive\appdata\local\roblox\versions\version-506d9e2f695a4b05\robloxstudiobeta.exe] => (Allow) C:\users\primitive\appdata\local\roblox\versions\version-506d9e2f695a4b05\robloxstudiobeta.exe
FirewallRules: [UDP Query User{854267C1-E051-42CD-8387-E8599E49DFED}C:\users\primitive\appdata\local\roblox\versions\version-506d9e2f695a4b05\robloxstudiobeta.exe] => (Allow) C:\users\primitive\appdata\local\roblox\versions\version-506d9e2f695a4b05\robloxstudiobeta.exe
FirewallRules: [{A5656CAA-E9E5-4CC3-8A79-9724545EB2FE}] => (Allow) C:\WINDOWS\system32\rundll32.exe
FirewallRules: [{1E2617A2-D5F6-4502-AEE9-D480E007CA65}] => (Allow) C:\Users\Primitive\AppData\Local\ddnowyes.exe
FirewallRules: [{E9588507-2313-4762-A50D-4A9BC832F19B}] => (Allow) C:\Users\Primitive\AppData\Local\15150554.exe
FirewallRules: [{1164D2F8-5ADE-4E91-AE40-363A1857F0D2}] => (Allow) C:\Users\Primitive\AppData\Local\tinstall.exe
FirewallRules: [{3A395A1F-936B-4FF0-8710-ACE9917AC481}] => (Allow) C:\Users\Primitive\AppData\Local\sc76258249.exe
FirewallRules: [{18A66A25-E1E5-4171-B75F-2549447C195D}] => (Allow) C:\Users\Primitive\AppData\Local\ddnow.exe
FirewallRules: [{ECEEF00D-A964-4D2E-B07C-F1416D28C662}] => (Allow) C:\Program Files (x86)\Hits\omagh.exe
FirewallRules: [{CDA10417-98CE-4E1B-A851-8B3AEF1EE378}] => (Allow) C:\Program Files (x86)\Defects\omagh.exe
FirewallRules: [{C14106C9-8997-405B-B721-26E3FE0AEEE1}] => (Allow) C:\Program Files (x86)\acidosis\popularity.exe
FirewallRules: [{46ACFB00-CC12-4F10-BBFE-ADEDCC06C7F2}] => (Allow) C:\Program Files (x86)\acidosis\hijacking.exe
FirewallRules: [{05EA7D8A-7FF5-4521-B9C9-6771B65766F3}] => (Allow) C:\Program Files (x86)\operant\hoosiers.exe
FirewallRules: [{8609F1BC-8209-48BF-BB46-BCE98E4C61C7}] => (Allow) C:\Program Files (x86)\Ralph\demurrage.exe
FirewallRules: [{B5A97146-0EDE-49AC-AABD-AD6F8F0D22A9}] => (Allow) C:\WINDOWS\cutler.exe
FirewallRules: [{D02A3C86-A7FA-4549-9C2D-96ADE4BFBB83}] => (Allow) C:\Users\Primitive\AppData\Local\BrowserAir\Application\BrowserairExec.exe
FirewallRules: [{24C5640D-65EF-4A6C-B98C-25D98020B0BA}] => (Allow) C:\Users\Primitive\AppData\Local\Temp\QQVipDownloader\mhfc_1482204874_49659\MiniQQDL.exe
FirewallRules: [{CDB59CAC-6EA0-44E9-B9C5-79DEF750C615}] => (Allow) C:\Users\Primitive\AppData\Local\Temp\QQVipDownloader\mhfc_1482204874_49659\MiniQQDL.exe
FirewallRules: [TCP Query User{257134CB-FB7F-4A5F-B70E-615278E2F341}C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1482204874_49659\teniodl.exe] => (Allow) C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1482204874_49659\teniodl.exe
FirewallRules: [UDP Query User{B9B4FABC-C0C7-4271-873D-AAB2E8375D52}C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1482204874_49659\teniodl.exe] => (Allow) C:\users\primitive\appdata\local\temp\qqvipdownloader\mhfc_1482204874_49659\teniodl.exe
FirewallRules: [{94165F0E-E46B-4FAD-819B-F80DD84B6B2E}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\MHO_Setup_2.0.11.371.exe
FirewallRules: [TCP Query User{54C272DB-35D3-4B75-8531-03FA9660D41F}G:\non-steam games\monster hunter online\monster hunter online\tcls\tenprotect\tensafe_1.exe] => (Block) G:\non-steam games\monster hunter online\monster hunter online\tcls\tenprotect\tensafe_1.exe
FirewallRules: [UDP Query User{3E26C92C-C10E-4022-8C7B-2B853009E665}G:\non-steam games\monster hunter online\monster hunter online\tcls\tenprotect\tensafe_1.exe] => (Block) G:\non-steam games\monster hunter online\monster hunter online\tcls\tenprotect\tensafe_1.exe
FirewallRules: [TCP Query User{74A20A0A-A3A0-4E05-A6A1-3E19C20C810F}G:\non-steam games\monster hunter online\monster hunter online\bin\client\bin32\mhoclient.exe] => (Allow) G:\non-steam games\monster hunter online\monster hunter online\bin\client\bin32\mhoclient.exe
FirewallRules: [UDP Query User{6BAC593A-0CCB-4133-87FE-87FF5647C786}G:\non-steam games\monster hunter online\monster hunter online\bin\client\bin32\mhoclient.exe] => (Allow) G:\non-steam games\monster hunter online\monster hunter online\bin\client\bin32\mhoclient.exe
FirewallRules: [{1CDB3F0C-5413-44ED-A81C-275A4F02EB44}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{6A10EFAA-6B24-4BA9-91F8-D2C1EB57E198}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{9F0E65CA-13E0-41A0-A772-D6BAD6AC2008}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{8DFF6AEE-9F5E-4982-B96F-6855C931C2AB}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\Monster Hunter Online\Bin\Client\Bin32\Cross\crossproxy.exe
FirewallRules: [{50AC1C5E-C9B2-4D1D-8157-85CFE9721CB0}] => (Allow) C:\Users\Primitive\AppData\Roaming\Tencent\怪物猎人Online\4BA085A6FF5A5BACCD60AEFD185903C5\TenioDL\teniodl.exe
FirewallRules: [{B5DAAF87-D3EC-484D-AF79-C975877DB8CE}] => (Allow) C:\Users\Primitive\AppData\Roaming\Tencent\怪物猎人Online\4BA085A6FF5A5BACCD60AEFD185903C5\TenioDL\teniodl.exe
FirewallRules: [{BE36E881-D2F3-4BDA-873B-D5E344EC19C8}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe
FirewallRules: [{684762C8-09C7-4D20-9CB2-0AB204FCB721}] => (Allow) G:\Non-Steam Games\Monster Hunter Online\Monster Hunter Online\Bin\Client\IIPS\iipshostapp.exe
FirewallRules: [{75E28886-DB3E-42BD-AEF6-4AFC51A2893F}] => (Allow) G:\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{73C8C34B-996A-42BB-9E0A-83CBC1746732}] => (Allow) G:\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{D8DA5CEC-1D66-42C7-8B78-73163972EB98}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{9C0CA1A0-16C0-465B-B993-B151C7891A50}C:\program files (x86)\logmein ignition\lmiignition.exe] => (Allow) C:\program files (x86)\logmein ignition\lmiignition.exe
FirewallRules: [UDP Query User{40E2A678-1545-4C46-A612-8AAF7EC23DD1}C:\program files (x86)\logmein ignition\lmiignition.exe] => (Allow) C:\program files (x86)\logmein ignition\lmiignition.exe
FirewallRules: [TCP Query User{9739C598-80F5-4741-8A01-E3E405A3F46B}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{0C3A87F1-55D8-4C31-8311-9F6E02BE9576}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [{D6A13C37-397B-43B1-B4C3-1811650C09DD}] => (Allow) G:\Steam\SteamApps\common\Guns of Icarus Online\workshop\Workshop.exe
FirewallRules: [{AF66AF0B-6362-47C7-830E-FE6962B43302}] => (Allow) G:\Steam\SteamApps\common\Guns of Icarus Online\workshop\Workshop.exe
FirewallRules: [{263AD6B1-E37B-455B-A44C-CD7DCE21974E}] => (Allow) G:\Steam\SteamApps\common\Depth\BETA\Binaries\Win32\DepthGame.exe
FirewallRules: [{9240B2EF-2D8E-4E3E-A98B-97128E127B4D}] => (Allow) G:\Steam\SteamApps\common\Depth\BETA\Binaries\Win32\DepthGame.exe
FirewallRules: [{8D538934-A429-4E32-A470-6ADBCED3F4AB}] => (Allow) G:\Steam\SteamApps\common\Natural Selection 2\NS2.exe
FirewallRules: [{0587789B-43B1-4355-96D1-2C34AA798207}] => (Allow) G:\Steam\SteamApps\common\Natural Selection 2\NS2.exe
FirewallRules: [{84627E43-4C3B-4134-989E-FFFF1949E403}] => (Allow) G:\Steam\SteamApps\common\Super Hexagon\superhexagon.exe
FirewallRules: [{E0BAB900-2391-4176-8E6D-DB728B375794}] => (Allow) G:\Steam\SteamApps\common\Super Hexagon\superhexagon.exe
FirewallRules: [{8B626F06-40B1-4CA8-A7C7-02D7E6864E0F}] => (Allow) G:\Steam\SteamApps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{A639E62A-CD46-415C-87FC-E23CA40FDFDD}] => (Allow) G:\Steam\SteamApps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{76ED4AFF-6B43-4B40-B678-3D88F6A60052}] => (Allow) C:\Users\Primitive\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{952AD197-BB15-4421-B7BC-ADCAE8CE8DB7}] => (Allow) C:\Users\Primitive\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{879C7199-73F5-4DBD-934C-DE69807A919B}] => (Allow) C:\Users\Primitive\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{646BE1CC-964E-4EC4-87E5-D2F5DCAF1D5B}] => (Allow) C:\Users\Primitive\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{8C423CA3-1393-4A11-816E-F8A0FD6FA15D}] => (Allow) C:\Users\Primitive\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{B85EE0DE-7034-44D2-9D29-2E4F1CDC4852}] => (Allow) C:\Users\Primitive\AppData\Roaming\BitTorrent\BitTorrent.exe
==================== Restore Points =========================
06-03-2017 21:24:49 Installed Zoo Tycoon 2 - Ultimate Collection
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (03/27/2017 09:23:32 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 08:51:36 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 08:21:47 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 08:07:05 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 06:59:22 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 06:53:58 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 06:53:57 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 06:53:56 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 06:49:15 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
Error: (03/27/2017 06:40:54 PM) (Source: CertEnroll) (EventID: 57) (User: NT AUTHORITY)
Description: The "Microsoft Base Smart Card Crypto Provider" provider was not loaded because initialization failed.
System errors:
=============
Error: (03/27/2017 09:22:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 08:52:19 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 08:52:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 08:52:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 08:22:04 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 08:22:04 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 08:21:44 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{3185A766-B338-11E4-A71E-12E3F512A338}
and APPID
{7006698D-2974-4091-A424-85DD0B909E23}
to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 07:52:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 07:52:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/27/2017 07:22:14 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9A4948D9-13FC-4FAC-B60A-FBA6EE0FB11C}
and APPID
{50E1C3FD-EC35-490E-9CCF-C68F9AE91919}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
CodeIntegrity:
===================================
Date: 2017-03-24 20:04:45.301
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-03-02 23:02:35.596
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-19 19:02:26.632
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-11 23:42:31.566
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-10 20:20:45.126
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-09 21:55:28.712
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-08 21:07:40.208
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-02 14:23:36.745
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-12-14 18:59:40.276
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-11-16 18:20:33.005
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-4790K CPU @ 4.00GHz
Percentage of memory in use: 73%
Total physical RAM: 8143.07 MB
Available physical RAM: 2163.11 MB
Total Virtual: 14799.07 MB
Available Virtual: 2778.49 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:111.01 GB) (Free:12.31 GB) NTFS
Drive g: (New Volume) (Fixed) (Total:931.39 GB) (Free:365.44 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
========================================================
Disk: 1 (MBR Code: Windows 7 or
Partition: GPT.
==================== End of Addition.txt ============================