Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

AVG finds malware/virus upon pc starting. playing games turns off PC


  • Please log in to reply
38 replies to this topic

#1 Dustin77

Dustin77

  •  Avatar image
  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 07 April 2024 - 04:24 PM

Hi.
 
for a few weeks now Avast never found anything so i uninstalled it and installed AVG Free and now AVG finds virus after i turn PC on. never any other time. also when playing a larger game my PC will just turn off then back on again. "Bug checked most of the parts and installs" I have run a few different malware checkers with no luck. the attached GIF is a picture of the virus warning i get.
any help would be appreciated thanks.
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06.04.2024 01
Ran by dwood (administrator) on DESKTOP-GJSJAIJ (Gigabyte Technology Co., Ltd. Default string) (08-04-2024 06:48:46)
Running from C:\Users\dwood\Downloads\FRST64.exe
Loaded Profiles: dwood
Platform: Microsoft Windows 10 Home Version 22H2 19045.4239 (X64) Language: English (United Kingdom)
Default browser: Edge
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12131.3.2010.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(A225F3B5-240D-4EE9-BCF4-697A07F5E93E -> Micro-Star INT'L CO., LTD.) C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.MSICenter_2.0.34.0_x64__kzh8wxbdkxb8p\DCv2\DCv2.exe
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems, Incorporated -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\AVGUI.exe <4>
(C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe ->) (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe ->) (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe <2>
(C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe ->) (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe ->) (Node.js Foundation -> Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
(C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe ->) (Adobe Systems Incorporated -> ) C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe ->) (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
(C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe ->) (AVerMedia TECHNOLOGIES, Inc -> ) C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
(C:\Program Files (x86)\GIGABYTE\GService\GCloud.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> Microsoft) C:\Program Files (x86)\GIGABYTE\CloudStation_Server\HomeCloud\HCLOUD.exe
(C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe ->) (Gigabyte Technology CO., LTD.) [File not signed] C:\Program Files (x86)\GIGABYTE\Smart TimeLock\AlarmClock.exe
(C:\Program Files (x86)\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbamtray.exe
(C:\Program Files (x86)\MSI\MSI Center\MSI.CentralServer.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI) C:\Program Files (x86)\MSI\MSI Center\Engine\CC_Engine_x64.exe
(C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI.CentralServer.exe
(C:\Program Files (x86)\OpenDNS\DNSCrypt\OpenDNSCryptService.exe ->) () [File not signed] C:\Program Files (x86)\OpenDNS\DNSCrypt\dnscrypt-proxy.exe
(C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe ->) (Plex, Inc. -> ) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe
(C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe ->) (Plex, Inc. -> ) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe <4>
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzAppManager
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzBTLEManager
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzDeviceManager
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzDiagnostic
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzIoTDeviceManager
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSmartlightingDeviceManager
(C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe ->) (Razer USA Ltd. -> The CefSharp Authors) C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe <5>
(C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe
(C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe ->) (Razer USA Ltd. -> ) C:\Program Files (x86)\Razer\Synapse3\UserProcess\Razer Synapse Service Process.exe
(C:\Program Files\AVG\Antivirus\AVGSvc.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\aswEngSrv.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(C:\Windows\runSW.exe ->) (Realtek Semiconductor Corp. -> Realtek) C:\Windows\SwUSB.exe
(explorer.exe ->) (cFos Software GmbH -> cFos Software GmbH) C:\Program Files\cFosSpeed\cfosspeed.exe
(explorer.exe ->) (MEDIATEK INC. -> Mediatek Inc.) [File not signed] C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe
(explorer.exe ->) (Plex, Inc. -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
(explorer.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe
(GIGA-BYTE TECHNOLOGY CO., LTD. -> ) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <8>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe <16>
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Power Software Limited -> Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(Razer USA Ltd. -> Razer Inc.) [File not signed] C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(services.exe ->) () [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
(services.exe ->) () [File not signed] C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe
(services.exe ->) () [File not signed] C:\Program Files (x86)\OpenDNS\DNSCrypt\OpenDNSCryptService.exe
(services.exe ->) () [File not signed] C:\Program Files (x86)\Wondershare\MobileTrans\ElevationService.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Autodesk, Inc -> Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(services.exe ->) (AVerMedia TECHNOLOGIES, Inc -> AVerMedia) C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswidsagent.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\wsc_proxy.exe
(services.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\afwServ.exe
(services.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\AVGSvc.exe
(services.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\avgToolsSvc.exe
(services.exe ->) (Canon U.S.A., INC. -> Canon U.S.A., Inc.) E:\Program Files\Canon\EOS Webcam Utility\EWCService.exe
(services.exe ->) (cFos Software GmbH -> cFos Software GmbH) C:\Program Files\cFosSpeed\spd.exe
(services.exe ->) (Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> Microsoft) C:\Program Files (x86)\GIGABYTE\GService\GCloud.exe
(services.exe ->) (Gigabyte Technology CO., LTD.) [File not signed] C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe
(services.exe ->) (GuinpinSoft inc) [File not signed] C:\Program Files\Common Files\cdarbsvc\cdarbsvc_v1.2.0_x64.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Windows\SysWOW64\XtuService.exe
(services.exe ->) (LAVASOFT SOFTWARE CANADA INC -> ) C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files (x86)\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (MEDIATEK INC. -> Mediatek Inc.) C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe
(services.exe ->) (MEDIATEK INC. -> Mediatek Inc.) C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry64.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI Center\Case\MSI_Case_Service.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI Center\Voice Control\VoiceControl_Service.exe
(services.exe ->) (ND_Apps -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <5>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvaei.inf_amd64_89430f5327945961\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Plex, Inc. -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe
(services.exe ->) (Protexis Inc. -> Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc) C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzChromaStreamServer.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe
(services.exe ->) (Realtek Semiconductor Corp -> ) C:\Windows\runSW.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(services.exe ->) (Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.OutlookForWindows_1.2024.327.300_x64__8wekyb3d8bbwe\olk.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2401.0.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\dwood\AppData\Local\Microsoft\OneDrive\24.055.0317.0002\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe <2>
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI.TerminalServer.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI Center\Voice Control\VoiceControl_Engine.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech -> Logitech Inc.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [856288 2019-10-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Gigabyte Speed] => C:\Program Files\cFosSpeed\cFosSpeed.exe [1724248 2019-03-21] (cFos Software GmbH -> cFos Software GmbH)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [460736 2024-04-07] (AVG Technologies USA, LLC -> Gen Digital Inc.)
HKLM-x32\...\Run: [Syncios device service] => C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe [1592472 2017-03-07] (Anvsoft Inc. -> )
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3500056 2017-11-02] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [493960 2014-12-05] (Autodesk, Inc -> Autodesk Inc.)
HKLM-x32\...\Run: [Standby] => c:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe [105632 2010-01-07] (Corel Corporation -> Corel)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-12-09] (Apple Inc.) [File not signed]
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2407008 2017-09-20] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [Aimersoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [1667072 2012-02-28] (AimerSoft) [File not signed]
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [599056 2021-10-28] (Razer USA Ltd. -> Razer Inc.) [File not signed]
HKLM-x32\...\Run: [AutoAD] => C:\Program Files (x86)\Wondershare\MobileTrans\AutoAD.exe [64520 2021-09-09] (Wondershare Technology Co.,Ltd -> Wondershare)
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [468936 2023-05-15] (Power Software Limited -> Power Software Ltd)
HKLM-x32\...\RunOnce: [PreRun] => C:\Program Files (x86)\Gigabyte\AppCenter\PreRun.exe [14632 2016-02-26] (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
HKLM-x32\...\RunOnce: [DualBiosRescue] => C:\Program Files (x86)\GIGABYTE\GigabyteFirmwareUpdateUtility\dbrro.exe [12096 2015-08-19] (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1310088 2015-01-27] (Autodesk, Inc -> Autodesk, Inc.)
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Run: [PeerBlock] => C:\Program Files\PeerBlock\peerblock.exe [2513992 2014-01-14] (PeerBlock, LLC -> PeerBlock, LLC)
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45285792 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3593992 2024-03-27] (Razer USA Ltd. -> Razer Inc.)
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [2735208 2024-04-07] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [26130208 2024-02-13] (Plex, Inc. -> Plex, Inc.)
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Run: [AutoAD] => C:\Program Files (x86)\Wondershare\MobileTrans\AutoAD.exe [64520 2021-09-09] (Wondershare Technology Co.,Ltd -> Wondershare)
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Run: [MicrosoftEdgeAutoLaunch_547977740F2BA2F5630427A598A6F857] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4063784 2024-04-04] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Run: [movavi_videoconverter_agent] => D:\Program Files (x86)\MOVAVI\Movavi Video Converter 23\ConverterAgent.exe [1151608 2023-05-03] (Movavi Software Limited -> Movavi)
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Run: [btweb] => "C:\Users\dwood\AppData\Roaming\BitTorrent Web\btweb.exe" /MINIMIZED (No File)
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Policies\Explorer: []
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\MountPoints2: F - "F:\AUTORUN.EXE"
HKU\S-1-5-18\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [26130208 2024-02-13] (Plex, Inc. -> Plex, Inc.)
HKU\S-1-5-18\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3593992 2024-03-27] (Razer USA Ltd. -> Razer Inc.)
HKLM\...\Windows x64\Print Processors\Canon iP4500 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPD92.DLL [27648 2007-05-01] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [55432 2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Inc)
HKLM\...\Print\Monitors\Canon BJ Language Monitor iP4500 series: C:\WINDOWS\system32\CNMLM92.DLL [258560 2007-05-01] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3000 series: CNMLMDG.DLL (No File)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MX470 series XPS: C:\WINDOWS\system32\CNMXLMC2.DLL [394240 2013-09-12] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\Canon BJNP Port: C:\WINDOWS\system32\CNMN6PPM.DLL [360448 2013-09-11] (CANON INC.) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> "C:\Program Files (x86)\AVAST Software\Browser\Application\92.2.11577.159\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\123.0.6312.106\Installer\chrmstp.exe [2024-04-05] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> "C:\Program Files (x86)\AVAST Software\Browser\Application\88.0.7980.150\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
Startup: C:\Users\dwood\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2024-01-08]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVer HID Receiver.lnk [2021-01-16]
ShortcutTarget: AVer HID Receiver.lnk -> C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe (AVerMedia TECHNOLOGIES, Inc -> )
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVerQuick.lnk [2021-01-16]
ShortcutTarget: AVerQuick.lnk -> C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe (AVerMedia TECHNOLOGIES, Inc -> AVerMedia TECHNOLOGIES, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Mediatek Wireless Utility.lnk [2019-08-15]
ShortcutTarget: Mediatek Wireless Utility.lnk -> C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe (MEDIATEK INC. -> Mediatek Inc.) [File not signed] <==== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MTWSAndroidAppHelper.lnk [2021-09-15]
ShortcutTarget: MTWSAndroidAppHelper.lnk -> C:\Program Files (x86)\Wondershare\MobileTrans\WSAndroidAppHelper.exe (Wondershare Technology Co.,Ltd -> Microsoft)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MTWSAppHelper.lnk [2021-09-15]
ShortcutTarget: MTWSAppHelper.lnk -> C:\Program Files (x86)\Wondershare\MobileTrans\WSAppHelper.exe (Wondershare Technology Co.,Ltd -> Microsoft)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\OpenDNSCrypt.lnk [2019-04-30]
ShortcutTarget: OpenDNSCrypt.lnk -> C:\Windows\Installer\{DEF3592F-0751-4632-9875-8BF9AD602898}\_60ADE4ADDDB9C7178BB901.exe () [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {FE2347DF-8042-4E90-90C4-29030B9EAF83} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {2A09D7A9-DC66-4D79-B228-43A3011FEC52} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1547208 2024-01-31] (Adobe Inc. -> Adobe Inc.)
Task: {F1B6FA2B-C0EE-4190-A990-E72B38F45469} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_465_Plugin.exe [1504312 2023-11-18] (Adobe Inc. -> Adobe)
Task: {2E951F32-64E6-4C44-87F7-04AA4D9FD5B1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2023-11-18] (Adobe Inc. -> Adobe)
Task: {D0E98185-6597-49BB-86DF-588C066A109D} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-*** => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {143DEA42-37A1-4E2B-BA98-DCC1DDF7A804} - System32\Tasks\AdobeGCInvoker-1.0-MicrosoftAccount-*** => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe  -mode=scheduled (No File)
Task: {A583CF59-D7CD-4FD1-92BE-AA0DC0610220} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe  -> C:\Program Files\Common Files\AV\avast! Antivirus\/backup /iavs
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(1): schtasks.exe -> /Change /TN "\Adobe Acrobat Update Task" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(10): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineCore" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(11): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineUA" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(12): schtasks.exe -> /Change /TN "\MSIAfterburner" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(13): schtasks.exe -> /Change /TN "\OneDrive Reporting Task-S-1-5-21-559634521-2701541241-958822180-1001" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(14): schtasks.exe -> /Change /TN "\OneDrive Standalone Update Task-S-1-5-21-559634521-2701541241-958822180-1001" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(15): schtasks.exe -> /Change /TN "\TA Unofficial Patch Updater" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(16): schtasks.exe -> /Change /TN "\AVAST Software\Gaming mode Task Scheduler recovery" /DISABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(2): schtasks.exe -> /Change /TN "\CCleaner Update" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(3): schtasks.exe -> /Change /TN "\CCleanerCrashReporting" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(4): schtasks.exe -> /Change /TN "\CCleanerSkipUAC - dwood" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(5): schtasks.exe -> /Change /TN "\EasyTune" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(6): schtasks.exe -> /Change /TN "\EasyTune 1" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(7): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineCore" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(8): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineUA" /ENABLE
Task: {9F093820-BBFB-4892-99B6-E1FA3D32B3E4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(9): schtasks.exe -> /Change /TN "\GraphicsCardEngine" /ENABLE
Task: {D47185B3-6408-41C7-A421-8223AFE0B3BA} - System32\Tasks\AVG\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [5225408 2024-04-07] (AVG Technologies USA, LLC -> Gen Digital Inc.)
Task: {8D152EB9-5B09-417A-9799-64308CC114BD} - System32\Tasks\AVG\AVG Antivirus Patcher => C:\Program Files\Common Files\AVG\Icarus\avg-av\icarus.exe [7991232 2024-04-03] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {7DCAB8EE-AB97-4ACE-A19C-5AE444ABABB2} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2385856 2024-04-07] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {EE163075-9BAB-45A7-B1EA-AA50C2CE37FF} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {FF4E6760-8F29-4436-9AE1-A41C661CC3A8} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5074848 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc. All rights reserved.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "5216ef3f-5867-44c0-bb2f-45dd5fc340c4" --version "6.22.10977" --silent
Task: {881EAFD7-82FA-437C-A983-3DD0EA709A65} - System32\Tasks\CCleanerSkipUAC - dwood => C:\Program Files\CCleaner\CCleaner.exe [39024544 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {1CA43168-A296-428C-88B2-BCC4D6BCAE1C} - System32\Tasks\cFos\Registration Tasks\Open Browser => c:\program files (x86)\microsoft\edge\application\msedge.exe [4063784 2024-04-04] (Microsoft Corporation -> Microsoft Corporation) -> "hxxps://www.cfos.de/en/cfosspeed/documentation/status.htm?reg-10.50.2338-gigabyte"
Task: {1E588A0A-8098-4D7B-9825-48EECA55F1F1} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [5656192 2024-03-27] (Microsoft Windows -> Microsoft Corporation)
Task: {C75311BA-32BC-42A5-912E-C31A04CF8A04} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-08-25] (Google Inc -> Google Inc.)
Task: {1C427A96-8206-43BC-803F-B2DA8337309B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-08-25] (Google Inc -> Google Inc.)
Task: {30FCECE3-7AAD-4947-9CE0-7C2527B8DB04} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [64464 2024-03-09] (HP Inc. -> HP Inc.)
Task: {6B04099E-0B5F-4546-91CF-1456869CBB5F} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [64464 2024-03-09] (HP Inc. -> HP Inc.)
Task: {E1460A6C-3709-4CE3-BAA7-8AB29A7F3A7E} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [1625400 2018-06-28] (Intel® Software -> Intel Corporation)
Task: {3443EAA6-682D-43F3-8C05-1A6568B507FE} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28452976 2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {63CC07ED-3E3F-48C2-9CDF-6535DB31B856} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28452976 2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {531CDD3F-09F3-4186-BE70-7DF9A37BC976} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [221360 2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {E713534E-BCB3-485A-A442-383F01693D00} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [221360 2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {1A93CAA3-2F24-40D0-86ED-CDD7C4D6EDB3} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2463600 2021-09-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {CEF80AB3-08F9-4449-AE03-50C8F8AA64D2} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1938792 2021-09-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {5ACB714F-600D-49E7-8B9E-64E0AF1260D9} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2335600 2021-09-08] (Microsoft Corporation -> Microsoft)
Task: {F8676D32-9A65-4341-A7C2-C717CA487E15} - System32\Tasks\Microsoft_MKC_Logon_Task_ceip.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\CEIP.exe [32632 2021-09-08] (Microsoft Corporation -> Microsoft)
Task: {F9EF0111-3850-4C97-926C-968E69CF6185} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2463600 2021-09-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {ACAB0846-89DC-4529-84BF-FF40C9EA449B} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1938792 2021-09-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {5A3639A5-8BCF-4E1F-BC3C-8D15868A28CA} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe [34720 2024-04-05] (Mozilla Corporation -> Mozilla Foundation)
Task: {7FB4568C-E4D5-462C-93CA-C11C09DFCA82} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe  /s (No File)
Task: {3728EE4B-B44A-4C49-A6A4-C160C293757D} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-16] (Nvidia Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {9C891B24-D12D-49D1-95F8-881F007A754B} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {155ACFD5-F68E-4D81-9A08-3F1C4AD1AC65} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649784 2023-01-21] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {19F679F8-6968-4508-BDAF-A7A098646C8A} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6F6FDDF0-FEB0-4B6A-8A60-AD261508B131} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5CE8E1B0-1B60-48E2-A97C-F0CF0AD88FC1} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F1E4BE2F-B2FD-4401-983D-D12643BFB7F8} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B4AE3F81-E575-475B-9E5E-B494B553C30D} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {70D6751B-7A5E-48E4-8ACE-B264FFC180D7} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-21] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {770E6CBC-81C1-45A7-8EF2-52DD6D7D8D0F} - System32\Tasks\OpenDNS => C:\Program Files (x86)\OpenDNS\DNSCrypt\OpenDNSInterface.exe [98072 2012-08-03] (OpenDNS -> OpenDNS)
Task: {F7CADAE3-D3CE-418A-AFAA-E00E58F1A5A8} - System32\Tasks\PeerBlock => C:\Program Files\PeerBlock\peerblock.exe [2513992 2014-01-14] (PeerBlock, LLC -> PeerBlock, LLC)
Task: {5FB53082-D306-44AE-A863-67BE9315B823} - System32\Tasks\SIV => C:\Program Files (x86)\GIGABYTE\SIV\Thermald.exe [389504 2021-06-29] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
Task: {6E16B6B9-1746-406A-A2ED-A074A36D509A} - System32\Tasks\SIV-VGA => C:\Program Files (x86)\GIGABYTE\SIV\Sensord.exe [257408 2021-06-29] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
Task: {FC40F59D-706F-47BC-9851-6B557C4209D6} - System32\Tasks\TA Unofficial Patch Updater => C:\CAVEDOG\TOTALA\updater.exe [321024 2013-10-03] (Total Annihilation Universe) [File not signed] -> C:\CAVEDOG\TOTALA\\/silent
Task: {67CFA657-454C-40CB-ACA9-84E79EB5BA2E} - System32\Tasks\ViGEmBus_Updater => C:\Program Files\Nefarius Software Solutions\ViGEm Bus Driver\ViGEmBus_Updater.exe [1117096 2022-09-28] (Nefarius Software Solutions e.U. -> Nefarius Software Solutions e.U.) -> C:\Program Files\Nefarius Software Solutions\ViGEm Bus Driver\\/silent
Task: {34975612-F7B2-4407-B186-3ADFE7D50EED} - System32\Tasks\V-Tuner => C:\Program Files (x86)\GIGABYTE\VTuner\VTuner.exe [837040 2017-08-17] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\TA Unofficial Patch Updater.job => C:\CAVEDOG\TOTALA\updater.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{045def29-266b-42e7-b701-874d8def1c89}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{3131b18f-b2e5-44c1-b3d9-f97249feb17a}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{487d9e87-bfdd-431b-8bed-9423967d7f60}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{487d9e87-bfdd-431b-8bed-9423967d7f60}: [DhcpDomain] modem
Tcpip\..\Interfaces\{487d9e87-bfdd-431b-8bed-9423967d7f60}\4556C637472716244434142373: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{487d9e87-bfdd-431b-8bed-9423967d7f60}\4556C637472716244434142373: [DhcpDomain] modem
Tcpip\..\Interfaces\{79b2cdf3-6246-4c8a-84ae-137a571ab8b9}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{b4d16a22-695f-439c-a0b3-89be470b5b68}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{b4d16a22-695f-439c-a0b3-89be470b5b68}: [DhcpDomain] modem

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\dwood\AppData\Local\Microsoft\Edge\User Data\Default [2024-04-08]
Edge DownloadDir: Default -> C:\Users\dwood\Downloads
Edge Notifications: Default -> hxxps://web.snapchat.com
Edge HomePage: Default -> hxxp://google.com.au/
Edge Extension: (Google Docs Offline) - C:\Users\dwood\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-27]
Edge Extension: (Edge relevant text changes) - C:\Users\dwood\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-26]
Edge Extension: (Coupert - Automatic Coupon Finder & Cashback) - C:\Users\dwood\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pefhciejnkgdgoahgfeklebcbpmhnhhd [2024-03-28]

FireFox:
========
FF DefaultProfile: imu8yuar.default
FF ProfilePath: C:\Users\dwood\AppData\Roaming\Mozilla\Firefox\Profiles\imu8yuar.default [2024-04-08]
FF Homepage: Mozilla\Firefox\Profiles\imu8yuar.default -> hxxps://www.google.com.au/
FF NetworkProxy: Mozilla\Firefox\Profiles\imu8yuar.default -> type", 0
FF NewTabOverride: Mozilla\Firefox\Profiles\imu8yuar.default -> Disabled: @new-tab
FF NewTabOverride: Mozilla\Firefox\Profiles\imu8yuar.default -> Enabled: AdBlockerLavaSoftFF@lavasoft.com
FF NewTabOverride: Mozilla\Firefox\Profiles\imu8yuar.default -> Enabled: @contain-facebook
FF NewTabOverride: Mozilla\Firefox\Profiles\imu8yuar.default -> Enabled: ebay@search.mozilla.org
FF Extension: (Adaware Web Protection) - C:\Users\dwood\AppData\Roaming\Mozilla\Firefox\Profiles\imu8yuar.default\Extensions\@adaware_webprotection.xpi [2019-05-13] [UpdateUrl:hxxps://ext.adaware.com/wp/updates.json]
FF Extension: (Facebook Container) - C:\Users\dwood\AppData\Roaming\Mozilla\Firefox\Profiles\imu8yuar.default\Extensions\@contain-facebook.xpi [2023-07-23]
FF Extension: (Adaware Secure Search) - C:\Users\dwood\AppData\Roaming\Mozilla\Firefox\Profiles\imu8yuar.default\Extensions\@new-tab.xpi [2019-05-13] [UpdateUrl:hxxps://ext.adaware.com/ff_newtab_update.rdf]
FF Extension: (Adaware AdBlock) - C:\Users\dwood\AppData\Roaming\Mozilla\Firefox\Profiles\imu8yuar.default\Extensions\AdBlockerLavaSoftFF@lavasoft.com.xpi [2023-06-27]
FF Extension: (AVG Online Security) - C:\Users\dwood\AppData\Roaming\Mozilla\Firefox\Profiles\imu8yuar.default\Extensions\aos@avg.com.xpi [2024-04-07]
FF Extension: (Dreamer – Balanced) - C:\Users\dwood\AppData\Roaming\Mozilla\Firefox\Profiles\imu8yuar.default\Extensions\dreamer-balanced-colorway@mozilla.org.xpi [2023-03-16]
FF Extension: (English (Australian) Dictionary) - C:\Users\dwood\AppData\Roaming\Mozilla\Firefox\Profiles\imu8yuar.default\Extensions\en-AU@dictionaries.addons.mozilla.org.xpi [2020-01-09]
FF Extension: (Enhancer for YouTube™) - C:\Users\dwood\AppData\Roaming\Mozilla\Firefox\Profiles\imu8yuar.default\Extensions\enhancerforyoutube@maximerf.addons.mozilla.org.xpi [2024-03-19]
FF Extension: (Ghostery Tracker Ad Blocker - Privacy AdBlock) - C:\Users\dwood\AppData\Roaming\Mozilla\Firefox\Profiles\imu8yuar.default\Extensions\firefox@ghostery.com.xpi [2024-03-28]
FF Extension: (Video DownloadHelper) - C:\Users\dwood\AppData\Roaming\Mozilla\Firefox\Profiles\imu8yuar.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2024-03-23]
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2017-11-01]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_465.dll [2023-11-18] (Adobe Inc. -> )
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.14 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.19 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-09-20] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_465.dll [2023-11-18] (Adobe Inc. -> )
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-04] (Electronic Sports Network i Sverige AB -> ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) [File not signed]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-02-25] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-02-25] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.5.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.10 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.12 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.20 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-31] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2017-11-02] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2024-03-31] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-09-20] (Adobe Systems Incorporated -> Adobe Systems)

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\dwood\AppData\Local\Google\Chrome\User Data\Default [2024-03-27]
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?pc=COS2&ptag=D052518-N0640AD26CBEB7DD&form=CONBDF&conlogo=CT3335811&q={searchTerms}
CHR DefaultSearchKeyword: Default -> bing®
CHR DefaultNewTabURL: Default -> hxxps://www.bing.com/chrome/newtab?pc=COS2&ptag=D052518-N0630AD26CBEB7DD&form=CONMHP&conlogo=CT3335811
CHR DefaultSuggestURL: Default -> hxxp://api.bing.com/qsml.aspx?query={searchTerms}
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\dwood\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2023-06-30]
CHR Extension: (Avast SafePrice | Comparison, deals, coupons) - C:\Users\dwood\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2023-06-30]
CHR Extension: (Google Docs Offline) - C:\Users\dwood\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-12-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\dwood\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-03-06]
CHR Extension: (Avast AntiTrack Premium) - C:\Users\dwood\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppdidpcihajhihmghhhkfnpklgdehold [2023-06-30]
CHR HKU\S-1-5-21-559634521-2701541241-958822180-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2017-11-02]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [599944 2014-12-05] (Autodesk, Inc -> Autodesk Inc.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-01-31] (Adobe Inc. -> Adobe Inc.)
S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2023-11-18] (Adobe Inc. -> Adobe)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [817760 2017-09-20] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
S3 AppleChargerSrv; C:\WINDOWS\System32\AppleChargerSrv.exe [31272 2010-04-06] (Giga-Byte Technology -> )
S2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc -> Autodesk, Inc.)
R2 AVerRemote; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [377664 2015-06-25] (AVerMedia TECHNOLOGIES, Inc -> AVerMedia)
R2 AVerScheduleService; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [771072 2017-02-06] () [File not signed]
R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [802752 2024-04-07] (AVG Technologies USA, LLC -> Gen Digital Inc.)
R2 AVG Firewall; C:\Program Files\AVG\Antivirus\afwServ.exe [2348984 2024-04-07] (AVG Technologies USA, LLC -> Gen Digital Inc.)
R2 AVG Tools; C:\Program Files\AVG\Antivirus\avgToolsSvc.exe [1238456 2024-04-07] (AVG Technologies USA, LLC -> Gen Digital Inc.)
R3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [9164216 2024-04-07] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 AVGWscReporter; C:\Program Files\AVG\Antivirus\wsc_proxy.exe [109480 2024-04-07] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 battlenet_helpersvc; C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe [2562696 2024-03-23] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1081248 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
R2 CdRomArbiterService; C:\Program Files\Common Files\cdarbsvc\cdarbsvc_v1.2.0_x64.exe [9728 2023-06-28] (GuinpinSoft inc) [File not signed]
R2 cFosSpeedS; C:\Program Files\cFosSpeed\spd.exe [595288 2019-03-21] (cFos Software GmbH -> cFos Software GmbH)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14221312 2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
R2 DNSCrypt; C:\Program Files (x86)\OpenDNS\DNSCrypt\OpenDNSCryptService.exe [14336 2012-08-03] () [File not signed]
S3 EAAntiCheatService; C:\Program Files\EA\AC\eaanticheat.gameservice.exe [47716384 2023-08-28] (Electronic Arts, Inc. -> Electronic Arts)
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [12200040 2024-04-07] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [774272 2018-03-29] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 ElevationService; C:\Program Files (x86)\Wondershare\MobileTrans\ElevationService.exe [913408 2021-07-16] () [File not signed]
R2 EWCService.exe; E:\Program Files\Canon\EOS Webcam Utility\EWCService.exe [2261944 2022-08-22] (Canon U.S.A., INC. -> Canon U.S.A., Inc.)
R2 Gservice; C:\Program Files (x86)\GIGABYTE\GService\GCloud.exe [19888 2016-12-02] (GIGA-BYTE TECHNOLOGY CO., LTD. -> Microsoft)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [234968 2024-03-09] (HP Inc. -> HP Inc.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MBAMService; C:\Program Files (x86)\Malwarebytes\Anti-Malware\MBAMService.exe [8882936 2024-04-07] (Malwarebytes Inc. -> Malwarebytes)
R2 MediatekRegistryWriter; C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe [405136 2014-12-04] (MEDIATEK INC. -> Mediatek Inc.)
R2 MediatekRegistryWriter64; C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry64.exe [454288 2014-12-04] (MEDIATEK INC. -> Mediatek Inc.)
R2 MSI_Case_Service; C:\Program Files (x86)\MSI\MSI Center\Case\MSI_Case_Service.exe [74336 2023-07-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R2 MSI_Center_Service; C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe [154216 2023-08-17] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
R2 MSI_VoiceControl_Service; C:\Program Files (x86)\MSI\MSI Center\Voice Control\VoiceControl_Service.exe [36880 2023-04-27] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R2 MyService1; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [18944 2021-04-08] () [File not signed]
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvaei.inf_amd64_89430f5327945961\Display.NvContainer\NVDisplay.Container.exe [1275544 2023-10-30] (NVIDIA Corporation -> NVIDIA Corporation)
R2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [828696 2024-02-13] (Plex, Inc. -> Plex, Inc.)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2017-04-15] (Even Balance, Inc. -> )
R2 Razer Chroma SDK Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe [1874864 2024-03-21] (Razer USA Ltd. -> Razer Inc.)
R2 Razer Chroma SDK Service; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe [231856 2024-03-21] (Razer USA Ltd. -> Razer Inc.)
R2 Razer Chroma Stream Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzChromaStreamServer.exe [1361360 2023-03-06] (Razer USA Ltd. -> Razer Inc.)
R2 Razer Game Manager Service; C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe [256264 2023-02-10] (Razer USA Ltd. -> Razer Inc)
R2 Razer Synapse Service; C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe [298248 2024-03-27] (Razer USA Ltd. -> Razer Inc.)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [6669296 2024-02-21] (Rockstar Games, Inc. -> Rockstar Games)
R2 RunSwUSB; C:\Windows\runSW.exe [44760 2019-07-26] (Realtek Semiconductor Corp -> )
R2 RzActionSvc; C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe [538424 2023-11-09] (Razer USA Ltd. -> Razer Inc.)
R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe [102400 2013-02-22] (Gigabyte Technology CO., LTD.) [File not signed]
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182392 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2020-11-26] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [919992 2020-11-26] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [28760 2019-11-30] (LAVASOFT SOFTWARE CANADA INC -> ) <==== ATTENTION
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
R2 WsAppService3; C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe [83232 2019-06-26] (Wondershare Technology Co.,Ltd -> Wondershare)
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\MobileTrans\DriverInstall.exe [119072 2019-09-05] (Wondershare Technology Co.,Ltd -> Wondershare)
S2 OCButtonService; "C:\Program Files (x86)\Gigabyte\EasyTuneEngineService\OcButtonService.exe" [X]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 AppleCharger; C:\WINDOWS\System32\DRIVERS\AppleCharger.sys [22240 2013-10-28] (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AVerIT13x; C:\WINDOWS\System32\Drivers\AVerIT13x_x64.sys [198272 2012-12-06] (Microsoft Windows Hardware Compatibility Publisher -> AVerMedia TECHNOLOGIES, Inc.)
R0 avgArDisk; C:\WINDOWS\System32\drivers\avgArDisk.sys [20528 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [230448 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [379960 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [292920 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [84536 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgElam; C:\WINDOWS\System32\drivers\avgElam.sys [27760 2024-04-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [28728 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [268856 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgNetHub; C:\WINDOWS\System32\drivers\avgNetHub.sys [548912 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [93752 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [69176 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [935992 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [695864 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [201784 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [306232 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 bcmsmbsp; C:\WINDOWS\System32\drivers\bcmsmbsp.sys [54048 2015-09-10] (Broadcom Corporation -> Broadcom Corporation.)
S3 BstkDrv; C:\Program Files (x86)\BlueStacks\BstkDrv.sys [270904 2017-06-21] (Bluestack Systems, Inc. -> Bluestack System Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [280064 2022-10-12] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [147968 2022-04-13] (Microsoft Corporation) [File not signed]
R1 cFosSpeed; C:\WINDOWS\system32\DRIVERS\cfosspeed6.sys [1595456 2019-03-21] (cFos Software GmbH -> cFos Software GmbH)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 gdrv; C:\WINDOWS\gdrv.sys [26792 2023-11-18] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R3 gdrv2; C:\WINDOWS\gdrv2.sys [32600 2024-04-07] (GIGA-BYTE Technology Co., Ltd. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R3 gdrv3; C:\WINDOWS\System32\drivers\gdrv3.sys [51520 2024-03-02] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 GoodixTouchDriver; C:\WINDOWS\System32\drivers\GoodixTouchDriver.sys [53760 2014-11-19] (Microsoft Windows Hardware Compatibility Publisher -> Windows ® Win 7 DDK provider)
S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [42040 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 i8042HDR; C:\WINDOWS\system32\DRIVERS\i8042HDR.sys [15920 2009-08-15] (Chicony Electronics Co., Ltd. -> Windows ® Codename Longhorn DDK provider)
S3 IObitUnlocker; C:\ProgramData\IObitUnlocker\IObitUnlocker.sys [66824 2017-06-16] (IObit Information Technology -> IObit)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223296 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2022-04-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-04-07] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 NTIOLib_CC_Clock; C:\Program Files (x86)\MSI\MSI Center\Lib\NTIOLib_X64.sys [14288 2017-07-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
R3 NTIOLib_CC_COMM; C:\Program Files (x86)\MSI\MSI Center\Lib\SYS\NTIOLib_X64.sys [32424 2023-07-31] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2022-07-14] (Nvidia Corporation -> NVIDIA Corporation)
S3 pbfilter; C:\Program Files\PeerBlock\pbfilter.sys [22600 2014-01-14] (PeerBlock, LLC -> )
S3 RzCommon; C:\WINDOWS\System32\drivers\RzCommon.sys [54632 2021-03-31] (Razer USA Ltd. -> Razer Inc)
S3 RzDev_0221; C:\WINDOWS\System32\drivers\RzDev_0221.sys [54168 2020-08-24] (Razer USA Ltd. -> Razer Inc)
R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-06] (Bruce James -> Scarlet.Crush Productions)
S3 ssudcdf; C:\WINDOWS\System32\drivers\ssudcdf.sys [36608 2014-01-22] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 SteamStreamingMicrophone; C:\WINDOWS\system32\drivers\SteamStreamingMicrophone.sys [40736 2017-07-29] (Valve Corp. -> )
R3 SteamStreamingSpeakers; C:\WINDOWS\system32\drivers\SteamStreamingSpeakers.sys [40736 2017-07-21] (Valve Corp. -> )
S3 SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys [25608 2020-01-17] (AVG Technologies CZ, s.r.o. -> SlimWare Utilities, Inc.)
S1 UsbCharger; C:\WINDOWS\System32\DRIVERS\UsbCharger.sys [22240 2013-10-24] (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
R1 ViGEmBus; C:\WINDOWS\System32\drivers\ViGEmBus.sys [249400 2022-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Nefarius Software Solutions e.U.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [151184 2016-07-15] (NGO -> MBB)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WsAudio_Device(1); C:\WINDOWS\system32\drivers\VirtualAudio1.sys [31080 2014-11-26] (Wondershare Software Co., Ltd.  -> Wondershare)
R3 XSplit_Dummy; C:\WINDOWS\system32\drivers\xspltspk.sys [37816 2021-06-30] (SplitmediaLabs Limited -> SplitmediaLabs Limited)
R3 XSpltAud; C:\WINDOWS\System32\drivers\XSpltAud.sys [82440 2021-08-25] (Microsoft Windows Hardware Compatibility Publisher -> SplitmediaLabs Limited)
R1 YSDrv; C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [312776 2020-09-20] (Microsoft Windows Hardware Compatibility Publisher -> Nox Limited Corporation)
S3 BCM42RLY; system32\drivers\BCM42RLY.sys [X]
S3 EAAntiCheat; system32\drivers\eaanticheat.sys [X]
S3 PCASp60; System32\Drivers\PCASp60.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2024-04-08 06:48 - 2024-04-08 06:49 - 000070111 _____ C:\Users\dwood\Downloads\FRST.txt
2024-04-08 06:48 - 2024-04-08 06:49 - 000000000 ____D C:\FRST
2024-04-08 06:46 - 2024-04-08 06:46 - 002393600 _____ (Farbar) C:\Users\dwood\Downloads\FRST64.exe
2024-04-07 13:54 - 2024-04-07 13:58 - 000354244 _____ C:\WINDOWS\ntbtlog.txt
2024-04-07 13:54 - 2024-04-07 13:54 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2024-04-07 13:26 - 2024-04-07 13:26 - 000001262 _____ C:\WINDOWS\system32\.crusader
2024-04-07 13:20 - 2024-04-07 13:26 - 000000000 ____D C:\ProgramData\HitmanPro
2024-04-07 13:16 - 2024-04-07 13:16 - 014287912 _____ (Sophos B.V.) C:\Users\dwood\Downloads\HitmanPro_x64.exe
2024-04-07 13:14 - 2024-04-07 13:19 - 000002478 _____ C:\Users\dwood\Desktop\Rkill.txt
2024-04-07 13:14 - 2024-04-07 13:14 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\dwood\Downloads\rkill.exe
2024-04-07 13:07 - 2024-04-07 13:07 - 000003656 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask
2024-04-07 12:38 - 2024-04-07 12:38 - 000000000 ___HD C:\$AV_AVG
2024-04-07 11:53 - 2024-04-07 15:01 - 000000000 ____D C:\Users\dwood\AppData\Local\AVG
2024-04-07 11:50 - 2024-04-07 11:50 - 000002071 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG AntiVirus Free.lnk
2024-04-07 11:50 - 2024-04-07 11:50 - 000002059 _____ C:\Users\Public\Desktop\AVG AntiVirus Free.lnk
2024-04-07 11:50 - 2024-04-07 11:50 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVG
2024-04-07 11:50 - 2024-04-07 11:50 - 000000000 ____D C:\Users\dwood\AppData\Roaming\AVG
2024-04-07 11:50 - 2024-04-07 11:49 - 000314816 _____ (Gen Digital Inc.) C:\WINDOWS\system32\avgBoot.exe
2024-04-07 11:49 - 2024-04-08 06:40 - 000000000 ____D C:\ProgramData\AVG
2024-04-07 11:49 - 2024-04-07 11:49 - 000888600 _____ (Google LLC) C:\Users\Public\Documents\gcapi.dll
2024-04-07 11:49 - 2024-04-07 11:49 - 000050976 _____ (Avast Software) C:\WINDOWS\system32\icarus_rvrt.exe
2024-04-07 11:49 - 2024-04-07 11:49 - 000000000 ____D C:\Program Files\Common Files\AVG
2024-04-07 11:49 - 2024-04-07 11:49 - 000000000 ____D C:\Program Files\AVG
2024-04-07 11:06 - 2024-04-07 11:46 - 000032600 ____N (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\WINDOWS\gdrv2.sys
2024-04-07 11:05 - 2024-04-07 11:05 - 000000000 ____D C:\WINDOWS\system32\o2
2024-04-05 05:52 - 2024-04-07 11:05 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2024-04-05 05:46 - 2024-04-07 09:38 - 000000961 _____ C:\Users\dwood\Desktop\BitTorrent.lnk
2024-04-05 05:46 - 2024-04-05 05:46 - 000000941 _____ C:\Users\dwood\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk
2024-04-05 05:43 - 2024-04-05 05:43 - 000001928 _____ C:\Users\dwood\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitTorrent Web.lnk
2024-03-27 14:37 - 2024-03-27 14:37 - 000020861 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-03-27 14:37 - 2024-03-27 14:37 - 000020861 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2024-03-27 13:38 - 2024-03-27 13:38 - 000000000 ___HD C:\$WinREAgent
2024-03-23 14:24 - 2024-03-23 14:24 - 000000000 ____D C:\ProgramData\Battle.net_components
2024-03-21 17:17 - 2024-03-21 17:17 - 000351664 _____ (Razer Inc.) C:\WINDOWS\system32\RzChromaSDK64.dll
2024-03-21 17:11 - 2024-03-21 17:11 - 000312752 _____ (Razer Inc.) C:\WINDOWS\SysWOW64\RzChromaSDK.dll
2024-03-15 06:53 - 2024-03-15 06:53 - 000002253 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk
2024-03-15 06:53 - 2024-03-15 06:53 - 000002241 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk
2024-03-15 06:52 - 2024-03-15 06:52 - 000000000 ____D C:\Program Files\Google
2024-03-14 05:57 - 2024-03-14 05:57 - 000000000 ____D C:\ProgramData\Piriform
2024-03-14 05:57 - 2024-03-14 05:57 - 000000000 ____D C:\ProgramData\Norton

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2024-04-08 06:47 - 2020-10-10 14:47 - 000840598 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-04-08 06:47 - 2019-12-07 19:13 - 000000000 ____D C:\WINDOWS\INF
2024-04-08 06:45 - 2018-05-19 14:32 - 000000000 ____D C:\Users\dwood\AppData\Local\D3DSCache
2024-04-08 06:42 - 2021-12-16 10:59 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-04-08 06:42 - 2017-08-25 01:56 - 000000000 ____D C:\Program Files (x86)\Google
2024-04-08 06:41 - 2023-05-09 02:52 - 000000000 ____D C:\Users\dwood\AppData\Local\Malwarebytes
2024-04-08 06:41 - 2022-12-01 11:56 - 000000000 ____D C:\MSI
2024-04-08 06:41 - 2017-05-19 20:19 - 000000000 ____D C:\Users\dwood\AppData\Local\Plex Media Server
2024-04-08 06:41 - 2017-03-02 20:52 - 000000000 ____D C:\Program Files\CCleaner
2024-04-08 06:41 - 2017-02-15 14:19 - 000000000 ____D C:\ProgramData\NVIDIA
2024-04-08 06:40 - 2020-10-10 14:50 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-04-08 06:40 - 2020-10-10 14:37 - 000008192 ___SH C:\DumpStack.log.tmp
2024-04-08 06:40 - 2019-12-07 19:14 - 000000000 ____D C:\WINDOWS\ServiceState
2024-04-08 06:40 - 2019-12-07 19:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-04-08 06:39 - 2020-10-10 14:39 - 000000000 ____D C:\Users\dwood
2024-04-08 06:39 - 2019-12-07 19:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-04-08 06:39 - 2019-12-07 19:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2024-04-08 06:36 - 2020-10-10 14:37 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-04-08 06:34 - 2022-11-30 08:49 - 000000000 ____D C:\Users\dwood\Documents\American Truck Simulator
2024-04-07 18:33 - 2022-12-01 10:37 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2024-04-07 17:02 - 2017-02-27 16:41 - 000000000 ____D C:\Users\dwood\AppData\Roaming\vlc
2024-04-07 16:20 - 2019-12-07 19:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-04-07 16:20 - 2017-11-12 17:06 - 000000000 ____D C:\Users\dwood\AppData\Local\Packages
2024-04-07 13:59 - 2023-12-03 10:46 - 000239576 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2024-04-07 13:40 - 2017-05-08 07:51 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2024-04-07 13:33 - 2017-05-09 12:09 - 000000000 ____D C:\Program Files (x86)\Direct Video Downloader
2024-04-07 13:32 - 2017-04-15 19:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avidemux (64 bits)
2024-04-07 13:26 - 2019-11-28 23:59 - 000000000 ____D C:\Users\dwood\AppData\Roaming\Movavi Video Editor Plus 2020
2024-04-07 13:18 - 2021-03-30 10:17 - 000000000 ____D C:\Users\dwood\AppData\LocalLow\IGDump
2024-04-07 12:37 - 2017-02-15 15:47 - 000000000 ____D C:\Users\dwood\AppData\Local\CrashDumps
2024-04-07 12:18 - 2019-12-07 19:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2024-04-07 11:52 - 2018-07-25 12:31 - 000000000 ____D C:\Program Files (x86)\GIGABYTE
2024-04-07 11:51 - 2018-12-08 20:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE
2024-04-07 11:50 - 2019-12-07 19:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2024-04-07 11:48 - 2019-02-01 09:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2024-04-07 11:47 - 2019-02-01 09:05 - 000000000 ____D C:\Program Files (x86)\Razer Chroma SDK
2024-04-07 11:46 - 2024-03-02 06:23 - 000000000 ____D C:\WINDOWS\Minidumps
2024-04-07 11:46 - 2024-01-12 06:37 - 000000310 _____ C:\WINDOWS\Tasks\TA Unofficial Patch Updater.job
2024-04-07 11:46 - 2022-09-21 06:12 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2024-04-07 11:44 - 2018-04-11 09:46 - 000000000 ____D C:\Users\dwood\AppData\Local\AVAST Software
2024-04-07 11:23 - 2020-10-10 14:50 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2024-04-07 11:23 - 2017-02-16 20:34 - 000000000 ____D C:\ProgramData\AVAST Software
2024-04-07 11:22 - 2020-10-10 14:39 - 000000000 ____D C:\Users\defaultuser0
2024-04-07 11:11 - 2024-01-12 07:46 - 000000000 ____D C:\Users\dwood\Documents\Pool
2024-04-07 11:08 - 2017-02-17 13:25 - 000000000 ____D C:\Users\dwood\AppData\Roaming\BitTorrent
2024-04-07 11:07 - 2021-03-05 09:46 - 000000000 ____D C:\Users\dwood\AppData\Local\BitTorrentHelper
2024-04-07 11:07 - 2017-02-16 20:24 - 000000000 ____D C:\Users\dwood\AppData\Local\Adobe
2024-04-07 11:05 - 2024-01-12 06:37 - 000002694 _____ C:\WINDOWS\system32\Tasks\TA Unofficial Patch Updater
2024-04-07 11:05 - 2023-07-25 14:28 - 000002430 _____ C:\WINDOWS\system32\Tasks\MSIAfterburner
2024-04-07 11:05 - 2023-04-01 07:30 - 000003058 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-559634521-2701541241-958822180-1001
2024-04-07 11:05 - 2022-09-21 06:12 - 000002950 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2024-04-07 11:05 - 2021-08-19 08:26 - 000002250 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - dwood
2024-04-07 11:05 - 2020-10-10 14:50 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2024-04-07 11:05 - 2020-10-10 14:50 - 000003464 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-04-07 11:05 - 2020-10-10 14:50 - 000003356 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2024-04-07 11:05 - 2020-10-10 14:50 - 000003240 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-04-07 11:05 - 2020-10-10 14:50 - 000003132 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2024-04-07 11:05 - 2020-10-10 14:50 - 000002988 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2024-04-07 11:05 - 2020-10-10 14:50 - 000002854 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-559634521-2701541241-958822180-1001
2024-04-07 11:05 - 2017-02-16 20:18 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-04-07 09:51 - 2023-04-18 17:54 - 000000000 ____D C:\ProgramData\EA Desktop
2024-04-07 09:49 - 2020-01-29 00:41 - 000000000 ____D C:\Users\dwood\dwhelper
2024-04-07 05:34 - 2020-06-13 23:13 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-04-06 07:00 - 2017-02-16 20:18 - 000001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-04-05 17:41 - 2022-10-14 16:48 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2024-04-05 05:53 - 2017-08-25 01:58 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-04-05 04:24 - 2017-02-17 11:57 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2024-04-04 01:53 - 2020-10-10 14:39 - 000002424 _____ C:\Users\dwood\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-04-03 18:04 - 2017-02-27 07:52 - 000000000 ____D C:\Users\dwood\AppData\Roaming\Microsoft\Excel
2024-03-31 05:37 - 2022-02-11 23:37 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-03-28 09:53 - 2024-01-05 14:14 - 000000000 ____D C:\Users\dwood\Documents\incident 5.1
2024-03-27 16:16 - 2019-12-07 19:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-03-27 16:14 - 2020-10-10 14:37 - 005299096 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-03-27 16:09 - 2023-12-16 15:45 - 000000000 ____D C:\WINDOWS\InboxApps
2024-03-27 16:09 - 2019-12-08 00:44 - 000000000 ____D C:\WINDOWS\en-GB
2024-03-27 16:09 - 2019-12-07 19:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2024-03-27 16:09 - 2019-12-07 19:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-03-27 16:09 - 2019-12-07 19:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-03-27 16:09 - 2019-12-07 19:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2024-03-27 16:09 - 2019-12-07 19:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2024-03-27 16:09 - 2019-12-07 19:14 - 000000000 ____D C:\WINDOWS\Provisioning
2024-03-27 16:09 - 2019-12-07 19:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-03-27 14:39 - 2019-12-07 19:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-03-27 14:37 - 2020-10-10 14:38 - 003017216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-03-23 14:23 - 2020-11-22 13:24 - 000000000 ____D C:\Users\dwood\AppData\Local\Battle.net
2024-03-23 09:10 - 2017-02-20 11:57 - 000000000 ____D C:\Users\dwood\AppData\Roaming\Microsoft\Word
2024-03-22 14:48 - 2022-09-15 14:57 - 000000000 ____D C:\Users\dwood\AppData\Roaming\com.adobe.dunamis
2024-03-21 17:09 - 2023-10-07 15:18 - 000000000 ____D C:\Program Files\RUXIM
2024-03-18 19:13 - 2023-06-07 07:07 - 000000000 ___RD C:\Users\dwood\Desktop\
2024-03-15 08:17 - 2019-12-07 19:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-03-15 08:17 - 2019-12-07 19:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-03-15 08:17 - 2019-12-07 19:03 - 000000000 ____D C:\WINDOWS\servicing
2024-03-14 00:26 - 2017-02-15 14:35 - 000000000 ____D C:\ProgramData\Package Cache
2024-03-14 00:25 - 2023-09-30 17:25 - 000000000 ____D C:\Program Files\dotnet
2024-03-14 00:25 - 2017-02-15 16:30 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-03-14 00:19 - 2017-02-15 16:30 - 190470136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-03-12 05:52 - 2024-02-18 16:59 - 000000000 ____D C:\ProgramData\WinZip
2024-03-09 23:19 - 2021-10-18 10:01 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP
2024-03-09 23:19 - 2021-10-18 09:59 - 000000000 ____D C:\Program Files\HPPrintScanDoctor

==================== Files in the root of some directories ========

2019-10-13 13:37 - 2019-10-13 13:37 - 000000000 _____ () C:\Program Files (x86)\GUM6F.tmp
2015-03-26 21:48 - 2015-03-26 21:48 - 002174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
2018-11-25 12:31 - 2018-11-25 12:31 - 000001456 _____ () C:\Users\dwood\AppData\Local\Adobe Save for Web 13.0 Prefs
2017-05-19 18:43 - 2021-04-24 14:55 - 000009216 _____ () C:\Users\dwood\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-09-22 22:32 - 2018-09-22 22:32 - 000000000 _____ () C:\Users\dwood\AppData\Local\oobelibMkey.log

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Edited by Oh My!, 07 April 2024 - 06:56 PM.


BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted 07 April 2024 - 04:57 PM

Greetings and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

===================================================

Ground Rules:
  • First, please keep in mind most of us at BleepingComputer volunteer our assistance for your benefit in your time of need. Please try to match our commitment to you with your patience toward us.
  • It is important to not run any tools or take any steps other than those I will provide for you.
  • Please perform all steps in the order they are listed. If things are not clear or you experience problems be sure to stop and let me know.
  • Please copy and paste all logs into your post unless otherwise requested.
  • When your computer is clean I will let you know, provide instructions to remove tools and reports, and offer you information about how you can combat future infections.
  • If you do not reply to your topic after 5 days I will assume it has been abandoned and I will close it.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.

Please copy and paste the Addition.txt file located in the Downloads folder in your reply
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#3 Dustin77

Dustin77
  • Topic Starter

  •  Avatar image
  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 07 April 2024 - 05:31 PM

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06.04.2024 01
Ran by dwood (08-04-2024 06:51:09)
Running from C:\Users\dwood\Downloads
Microsoft Windows 10 Home Version 22H2 19045.4239 (X64) (2020-10-10 04:50:31)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-559634521-2701541241-958822180-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-559634521-2701541241-958822180-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-559634521-2701541241-958822180-1000 - Limited - Disabled) => C:\Users\defaultuser0
dwood (S-1-5-21-559634521-2701541241-958822180-1001 - Administrator - Enabled) => C:\Users\dwood
Guest (S-1-5-21-559634521-2701541241-958822180-501 - Limited - Disabled)
hanna (S-1-5-21-559634521-2701541241-958822180-1006 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-559634521-2701541241-958822180-1003 - Limited - Enabled)
WDAGUtilityAccount (S-1-5-21-559634521-2701541241-958822180-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Antivirus (Enabled - Up to date) {18A975F9-A60C-37D8-E30B-4BEF31AD3411}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
FW: AVG Antivirus (Enabled) {2092F4DC-EC63-3680-C854-E2DACF7E736A}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
@BIOS (HKLM-x32\...\{C9D46F25-5F9D-4E25-B24F-BC00E9EDF529}) (Version: 4.24.0130.1 - GIGABYTE) Hidden
@BIOS (HKLM-x32\...\InstallShield_{C9D46F25-5F9D-4E25-B24F-BC00E9EDF529}) (Version: 4.24.0130.1 - GIGABYTE)
3DMark (HKLM\...\{7A64C3C2-9A6C-446B-A19B-F25726E8E1E4}) (Version: 2.4.4254.0 - Futuremark) Hidden
3DMark (HKLM-x32\...\{d3635583-8a86-4c2e-be7f-071daeb6de38}) (Version: 2.4.4254.0 - Futuremark)
3DOSD (HKLM-x32\...\{F0D1FAA5-F9F8-4524-9B65-A5BFDDD5A29B}) (Version: 1.00.0051 - GIGABYTE) Hidden
3DOSD (HKLM-x32\...\InstallShield_{F0D1FAA5-F9F8-4524-9B65-A5BFDDD5A29B}) (Version: 1.00.0051 - GIGABYTE)
A360 Desktop (HKLM\...\{B209E611-5511-4AD6-B4B3-9D36F93DBCD4}) (Version: 6.0.3.1100 - Autodesk)
adobe (HKLM\...\{60B7A95B-B4DC-4B41-8A2E-A7B5C475C23A}) (Version: 1.0.0000 - Adobe Systems Incorporated) Hidden
Adobe Acrobat Reader MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}) (Version: 24.001.20643 - Adobe Systems Incorporated)
Adobe Acrobat XI Pro (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.23 - Adobe Systems)
Adobe AIR (HKLM-x32\...\{CE25DBD3-FCA7-4E77-9A60-F77BE12FC4BA}) (Version: 30.0.0.107 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 30.0.0.107 - Adobe Systems Incorporated)
Adobe Audition CC 2018 (HKLM-x32\...\AUDT_11_0_1) (Version: 11.0.1 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\...\{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}) (Version: 3.0.0 - Adobe Systems Incorporated) Hidden
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.3.0.256 - Adobe Systems Incorporated)
Adobe Flash Player 10 ActiveX (HKLM-x32\...\{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}) (Version: 10.1.52.14 - Adobe Systems, Inc.)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.465 - Adobe)
Adobe Media Player (HKLM-x32\...\{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}) (Version: 1.8 - Adobe Systems Incorporated) Hidden
Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601067}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Age of Empires II Definitive Edition Dawn of the Dukes (HKLM-x32\...\Age of Empires II Definitive Edition Dawn of the Dukes_is1) (Version:  - )
Aimersoft DRM Media Converter(Build 1.5.6.0) (HKLM-x32\...\Aimersoft DRM Media Converter_is1) (Version:  - Aimersoft Software)
Amazing Adventures: The Caribbean Secret (HKLM-x32\...\{637A580F-23B9-43C3-8F88-F7E371D31CD8}) (Version: 1.0.0.3 - PopCap Games)
Ambient LED (HKLM-x32\...\{BEF97B38-D1B8-45B4-A60A-AF5C1556CC72}) (Version: 1.00.1605.1801 - GIGABYTE) Hidden
Ambient LED (HKLM-x32\...\InstallShield_{BEF97B38-D1B8-45B4-A60A-AF5C1556CC72}) (Version: 1.00.1605.1801 - GIGABYTE)
Angry IP Scanner (HKLM-x32\...\Angry IP Scanner) (Version: 3.9.1 - Angry IP Scanner)
APP Center (HKLM-x32\...\{D50BEE9A-0EC6-4A58-BF90-35BDC6D6495D}) (Version: 3.24.0315.1 - Gigabyte) Hidden
APP Center (HKLM-x32\...\InstallShield_{D50BEE9A-0EC6-4A58-BF90-35BDC6D6495D}) (Version: 3.24.0315.1 - Gigabyte)
Apple Application Support (32-bit) (HKLM-x32\...\{9738288C-21BC-4F54-AB4F-72F059339376}) (Version: 8.6 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{DEB339C1-2687-43AB-816A-8714F3E26846}) (Version: 8.6 - Apple Inc.)
AutoCAD 2016 - English (HKLM\...\{5783F2D7-F001-0409-2102-0060B0CE6BBA}) (Version: 20.1.49.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 4.0.69.0 - Autodesk)
Autodesk AutoCAD 2016 - English (HKLM\...\AutoCAD 2016 - English) (Version: 20.1.49.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service Language Pack (HKLM\...\{A37CDB58-AAE8-0001-8C13-E0F7BACB0D5F}) (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Featured Apps 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
Autodesk ReCap 2016 (HKLM\...\Autodesk ReCap 2016) (Version: 1.5.0.33 - Autodesk)
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1579.3 - AVAST Software) Hidden
Avast Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.8.1065.0 - AVAST Software) Hidden
AVerMedia A835 USB DVB-T 2.3.64.28 (HKLM-x32\...\AVerMedia A835 USB DVB-T) (Version: 2.3.64.28 - AVerMedia TECHNOLOGIES, Inc.)
AVerTV 3D (HKLM-x32\...\InstallShield_{5016185F-05AF-455F-AA70-6B6E5D6D4E70}) (Version: 6.9.1.18.17080805-GA - AVerMedia Technologies, Inc.)
AVG AntiVirus Free (HKLM\...\AVG Antivirus) (Version: 24.3.8975.1651 - AVG)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.8.2.48475 - Electronic Arts)
Battlefield™ 2042 (HKLM-x32\...\{45e281f3-1414-47ea-bb64-4f50d50121f3}) (Version: 1.0.77.20104 - Electronic Arts)
Battlefield™ V (HKLM-x32\...\{e26b382f-e945-4f70-9318-121b683f1d61}) (Version: 1.0.64.43202 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB)
Bejeweled® 3 (HKLM-x32\...\{E99C27B2-EB2E-4244-9F5C-A96F55100F0C}) (Version: 1.1.13.4753 - Electronic Arts, Inc.)
Big Fish: Game Manager (HKLM-x32\...\BFGC) (Version: 3.3.0.2 - )
BIOS Setup (HKLM-x32\...\{9D48202D-C767-40E7-8A4E-C14BD7328168}) (Version: 1.00.0000 - GIGABYTE) Hidden
BIOS Setup (HKLM-x32\...\InstallShield_{9D48202D-C767-40E7-8A4E-C14BD7328168}) (Version: 1.00.0000 - GIGABYTE)
BitTorrent (HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\BitTorrent) (Version: 7.11.0.47029 - BitTorrent Limited)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Bubble Town (HKLM-x32\...\Bubble Town1.1) (Version: 1.1 - Adnan_Boy 2008)
Burnout™ Paradise Remastered (HKLM-x32\...\{ADF3783C-C4B7-46A0-A0A6-EC4CA30479BE}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
BUSB (HKLM-x32\...\{0AADC50C-C4F8-49A7-8699-AFE46875CA67}) (Version: 1.16.1020.1 - GIGABYTE)
Canon Utilities Digital Photo Professional 4 (HKLM-x32\...\Digital Photo Professional 4 (x64)) (Version: 4.17.20.0 - Canon Inc.)
Canon Utilities EOS Lens Registration Tool (HKLM-x32\...\EOS Lens Registration Tool) (Version: 1.16.10.0 - Canon Inc.)
Canon Utilities Picture Style Editor (HKLM-x32\...\Picture Style Editor) (Version: 1.28.10.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 6.22 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
ClickOnce Bootstrapper Package for Microsoft .NET Framework (HKLM-x32\...\{E598B692-764A-413C-8530-59163D6B4AE3}) (Version: 4.6.01590 - Microsoft Corporation) Hidden
Cloud Station (Server) (HKLM-x32\...\{5D132D9D-2A99-48CF-9DCC-775DF6F31384}) (Version: 3.19.0529.1 - GIGABYTE) Hidden
Cloud Station (Server) (HKLM-x32\...\InstallShield_{5D132D9D-2A99-48CF-9DCC-775DF6F31384}) (Version: 3.19.0529.1 - GIGABYTE)
CloudStation (HKLM-x32\...\{6D8DA122-A40A-421B-9D95-FE4C806BCDBE}) (Version: 1.00.0021 - GIGABYTE) Hidden
CloudStation (HKLM-x32\...\InstallShield_{6D8DA122-A40A-421B-9D95-FE4C806BCDBE}) (Version: 1.00.0021 - GIGABYTE)
Contents (HKLM-x32\...\{D7D99A66-493F-468B-BCE1-6F88612B89D5}) (Version: 1.6.1.109 - Corel Corporation) Hidden
Corel PaintShop Photo Pro X3 (HKLM-x32\...\_{D1AEB5DB-04FA-489D-94EF-8600898B93EE}) (Version: 1.6.1.109 - Corel Corporation)
Corel PaintShop Photo Pro X3 (HKLM-x32\...\{DA4BF4BE-3CDC-43B5-BBDA-DDDA73103111}) (Version: 1.00.0000 - Corel Corporation) Hidden
CPUID CPU-Z 2.06 (HKLM\...\CPUID CPU-Z_is1) (Version: 2.06 - CPUID, Inc.)
CPUID CPU-Z Aorus 2.05 (HKLM\...\CPUID CPU-Z Aorus_is1) (Version: 2.05 - CPUID, Inc.)
CR2 Converter (HKLM-x32\...\{775F32A5-7BA0-4717-89D0-32B3EC25B2C9}_is1) (Version:  - cr2converter.com)
DeviceIO (HKLM-x32\...\{D3BCC13A-E4F2-45EE-846F-D143CEDDDBCB}) (Version: 1.6.1.109 - Corel Corporation) Hidden
DiagnosticsHub_CollectionService (HKLM\...\{90A561D7-0C29-464D-94E1-2A7E1C553230}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
DNSCrypt (HKLM-x32\...\{DEF3592F-0751-4632-9875-8BF9AD602898}) (Version: 0.0.6 - OpenDNS)
EA app (HKLM\...\{C2622085-ABD2-49E5-8AB9-D3D6A642C091}) (Version: 13.166.0.5679 - Electronic Arts) Hidden
EA app (HKLM-x32\...\{adc70025-3ba0-4770-9ea5-55be37b163fb}) (Version: 13.166.0.5679 - Electronic Arts)
Entity Framework 6.1.3 Tools  for Visual Studio 15 (HKLM-x32\...\{F8C0447E-D45C-4E52-94E8-C6340AAC9DB8}) (Version: 6.1.60104.0 - Microsoft Corporation) Hidden
EOS Webcam Utility (HKLM\...\{44FB3AA8-3CBB-45EE-8AEC-E8594B651395}) (Version: 1.2.2 - Canon U.S.A., Inc.)
ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
Fairy Island (HKLM-x32\...\BFG-Fairy Island) (Version:  - )
Far Cry 5 (HKLM-x32\...\Uplay Install 1803) (Version:  - Ubisoft)
Far Cry 6 (HKLM-x32\...\Uplay Install 5266) (Version:  - Ubisoft)
Far Cry New Dawn (HKLM-x32\...\Uplay Install 5210) (Version:  - Ubisoft)
FARO LS 1.1.502.0 (64bit) (HKLM-x32\...\{66D83FE0-D798-4B38-86FE-FB48151E5AEF}) (Version: 5.2.0.35213 - FARO Scanner Production)
Fast Boot (HKLM-x32\...\{FA8FB4F2-F524-48E1-A06C-45602FBF26CD}) (Version: 1.21.0414.1 - GIGABYTE) Hidden
Fast Boot (HKLM-x32\...\InstallShield_{FA8FB4F2-F524-48E1-A06C-45602FBF26CD}) (Version: 1.21.0414.1 - GIGABYTE)
File Identifier (HKLM-x32\...\{C257E434-E8F1-4E06-A616-598E4933553E}_is1) (Version: 1.0.11 - Sharpened Productions)
File Viewer Plus (HKLM-x32\...\{C8B24B83-920A-446E-B027-38F72C9D8898}_is1) (Version: 2.2.2 - Sharpened Productions)
FlashGet3.7 (HKLM-x32\...\FlashGet3.7) (Version: 3.7.0.1195 - hxxp://www.FlashGet.com)
Found: A Hidden Object Adventure (HKLM-x32\...\BFG-Found - A Hidden Object Adventure) (Version:  - )
Game Boost (HKLM-x32\...\{644B5310-D2AA-42A8-9F3B-7B92C856C8D7}) (Version: 1.00.0006 - Gigabyte) Hidden
Game Boost (HKLM-x32\...\InstallShield_{644B5310-D2AA-42A8-9F3B-7B92C856C8D7}) (Version: 1.00.0006 - Gigabyte)
Gigabyte Speed v10.50 (HKLM\...\Gigabyte Speed) (Version: 10.50 - cFos Software GmbH, Bonn)
GigabyteFirmwareUpdateUtility (HKLM-x32\...\{1CBA99CE-1AB3-4366-AFB4-7F7B75EBBE35}) (Version: 1.20.0720.1 - GIGABYTE) Hidden
GigabyteFirmwareUpdateUtility (HKLM-x32\...\InstallShield_{1CBA99CE-1AB3-4366-AFB4-7F7B75EBBE35}) (Version: 1.20.0720.1 - GIGABYTE)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 123.0.6312.106 - Google LLC)
Google Earth Pro (HKLM\...\{3470AD08-85F2-4B1D-8487-FC4750732087}) (Version: 7.3.6.9796 - Google)
gpedt.msc 1.0 (HKLM-x32\...\{10B9C608-BF7C-4CCF-A658-C01D969DCA21}_is1) (Version:  - Richard)
GService (HKLM-x32\...\{D9CB4282-7B2A-4840-AD1D-9DA72B973DD9}) (Version: 1.19.0624.1 - GIGABYTE)
Gummy Drop! (HKLM-x32\...\BFG-Gummy Drop!) (Version:  - )
HandBrake 1.6.1 (HKLM-x32\...\HandBrake) (Version: 1.6.1 - )
HeavyLoad V3.9.1 (64 bit) (HKLM\...\HeavyLoad_is1) (Version: 3.9.1 - JAM Software)
Hidden Express (HKLM-x32\...\BFG-Hidden Express) (Version:  - )
ICA (HKLM-x32\...\{D1AEB5DB-04FA-489D-94EF-8600898B93EE}) (Version: 1.6.1.109 - Corel Corporation) Hidden
icecap_collection_neutral (HKLM-x32\...\{64F3E6FC-68E3-4062-9C2C-ABD93FDFF309}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
icecap_collection_x64 (HKLM\...\{0AD162D1-4973-4315-97E9-5DE9A92B4049}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
icecap_collectionresources (HKLM-x32\...\{12C50688-5919-4A7A-8784-B26A7238FCEE}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
icecap_collectionresourcesx64 (HKLM-x32\...\{400E7885-8851-43F1-849C-5A720CB4F001}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
Infected Mushroom Manipulator (HKLM\...\{34E5CF28-0E9D-49A8-91CA-054D18802589}) (Version: 1.0.3.0 - Polyverse)
inSSIDer (HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\inSSIDer) (Version: 5.5.0 - MetaGeek, LLC)
Intel® Chipset Device Software (HKLM\...\{8AD25E9A-EC62-4D9B-B3D7-7CEAB77DA85F}) (Version: 10.1.2.19 - Intel Corporation) Hidden
Intel® Chipset Device Software (HKLM-x32\...\{5f313643-63c9-4660-8dae-eb4a80196cb4}) (Version: 10.1.2.19 - Intel® Corporation) Hidden
Intel® Extreme Tuning Utility (HKLM-x32\...\{0e9f5d6d-2200-4a15-98fc-9bdf36186e16}) (Version: 6.5.0.45 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.39.1003 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{69AAE674-929D-4A17-B108-623E8FDD6EE7}) (Version: 10.0.39.1003 - Intel Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{6C9B8590-9D31-4802-92A2-0DDFE9708C4C}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® ME UninstallLegacy (HKLM\...\{013FAB2E-017D-4330-8179-B5FE02E7F81C}) (Version: 1.0.1.0 - Intel Corporation) Hidden
Intel® Network Connections 26.2.0.1 (HKLM\...\{AC44C09E-6D45-4F0F-8749-C3DF69A55FDE}) (Version: 26.2.0.1 - Intel) Hidden
Intel® Network Connections 26.2.0.1 (HKLM\...\PROSetDX) (Version: 26.2.0.1 - Intel)
Intel® Hardware Accelerated Execution Manager (HKLM\...\{7516A945-5FC4-4563-8F5E-EECDBF61E84F}) (Version: 7.5.1 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{5EA6BC70-0CFC-413D-8465-8506B6F46EE0}) (Version: 1.39.141.0 - Intel Corporation) Hidden
IntelliTraceProfilerProxy (HKLM\...\{5D74900E-EF0F-41EC-86C8-A860A0D4F60C}) (Version: 15.0.24.0 - Microsoft Corporation) Hidden
IntelliTraceProfilerProxy (HKLM-x32\...\{51783942-DFB0-4452-97CC-BDF2D4AB3A48}) (Version: 15.0.24.0 - Microsoft Corporation) Hidden
iPFG 2.6e (Stand alone; C:\Program Files (x86)\Phonak Group\iPFG) (HKLM-x32\...\{C3FAD318-1B5E-408A-82AF-3E7502CF5096}) (Version: iPFG 2.6e - )
IPM_PSP_Pro (HKLM-x32\...\{DCD941B6-F2E7-4FAF-B102-F7D4DE5FF99A}) (Version: 1.00.0000 - Corel Corporation) Hidden
Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech)
MakeMKV v1.17.4 (HKLM-x32\...\MakeMKV) (Version: v1.17.4 - GuinpinSoft inc)
Malwarebytes version 4.6.11.320 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.11.320 - Malwarebytes)
Mediatek RT2870 Wireless LAN Card (HKLM-x32\...\{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}) (Version: 1.5.39.173 - MediatekWiFi)
Medieval CUE Splitter (HKLM-x32\...\{B96D2269-568B-4CBF-9332-12FAE8B158F7}) (Version: 1.2.0 - Medieval Software)
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation) Hidden
Microsoft .NET Framework Cumulative Intellisense Pack for Visual Studio (ENU) (HKLM-x32\...\{7B8D7488-5CB3-4AD3-B03E-A1C081F4D0BD}) (Version: 4.6.01604 - Microsoft Corporation) Hidden
Microsoft .NET Host - 6.0.28 (x64) (HKLM\...\{CA84969C-64F9-4606-A998-E692A5DA9B9F}) (Version: 48.112.10439 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.28 (x64) (HKLM\...\{7C4254A1-17EE-4840-B9D3-7CA9B34C75CD}) (Version: 48.112.10439 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.28 (x64) (HKLM\...\{4BCC5DFD-5D10-4ACC-AAA9-8A1578A9F0C6}) (Version: 48.112.10439 - Microsoft Corporation) Hidden
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.17425.20146 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 123.0.2420.81 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 123.0.2420.65 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 14.41.137.0 - Microsoft Corporation)
Microsoft NetStandard SDK (HKLM-x32\...\{737FDDA7-B944-4CB5-92D9-3D56373BD301}) (Version: 15.0.51105 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\OneDriveSetup.exe) (Version: 24.055.0317.0002 - Microsoft Corporation)
Microsoft Portable Library Multi-Targeting Pack (HKLM-x32\...\{95986126-C713-3F28-B3E0-F77C5B94FAFB}) (Version: 15.0.26228.00 - Microsoft Corporation) Hidden
Microsoft Portable Library Multi-Targeting Pack Language Pack - enu (HKLM-x32\...\{2F42AF19-E447-3D80-8F58-E983921884E8}) (Version: 15.0.26208.00 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU CTP1 (HKLM\...\{FAF57A91-58B3-490C-9D0C-66337DAD3F11}) (Version: 4.0.8854.1 - Microsoft Corporation) Hidden
Microsoft System CLR Types for SQL Server 2016 (HKLM\...\{96EB5054-C775-4BEF-B7B9-AA96A295EDCD}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2016 (HKLM-x32\...\{84C23ECA-FE4D-494F-9247-3EBAD57E7F0C}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{d491dd9d-2eda-4d75-b504-1a201436e7fd}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{3994d355-238a-4612-af93-26d13deddef1}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{f407f141-a702-406f-beab-318b6291e9bd}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{8e24fb65-31aa-446d-9c3e-35c5e11cb367}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532 (HKLM-x32\...\{8bdfe669-9705-4184-9368-db9ce581e0e7}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 (HKLM-x32\...\{410c0ee1-00bb-41b6-9772-e12c2828b02f}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532 (HKLM\...\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.36.32532 (HKLM\...\{D5D19E2F-7189-42FE-8103-92CD1FA457C2}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532 (HKLM-x32\...\{C2C59CAB-8766-4ABD-A8EF-1151A36C41E5}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532 (HKLM-x32\...\{73F77E4E-5A17-46E5-A5FC-8A061047725F}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2017 (HKLM-x32\...\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}) (Version: 1.5.30308.1 - Microsoft Corporation)
Microsoft Visual Studio Setup Configuration (HKLM-x32\...\{5D4C380F-1144-41A9-8FBB-E0D993A33825}) (Version: 1.8.8.44148 - Microsoft Corporation) Hidden
Microsoft Visual Studio Setup WMI Provider (HKLM-x32\...\{E281F6E2-136B-4AF0-895B-253279711697}) (Version: 3.7.2182.35401 - Microsoft Corporation)
Microsoft Visual Studio Team Foundation Server 2017 Office Integration (x64) (HKLM\...\{DE1BA166-8EDE-3796-B111-0152E9664ED3}) (Version: 15.112.26313 - Microsoft) Hidden
Microsoft Visual Studio Team Foundation Server 2017 Office Integration Language Pack (x64) - ENU (HKLM\...\{EE5930A0-F018-300E-BB95-864AD8EA8AAC}) (Version: 15.112.26313 - Microsoft) Hidden
Microsoft Windows Desktop Runtime - 6.0.28 (x64) (HKLM\...\{443A7BE8-E5BE-4514-BDAB-0A872E3E846B}) (Version: 48.112.10435 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.28 (x64) (HKLM-x32\...\{bd3c5800-9256-43b9-97a7-eb349fc38d78}) (Version: 6.0.28.33420 - Microsoft Corporation)
Microsoft_VC80_ATL_x86 (HKLM-x32\...\{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}) (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_ATL_x86_x64 (HKLM\...\{925D058B-564A-443A-B4B2-7E90C6432E55}) (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86 (HKLM-x32\...\{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}) (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86_x64 (HKLM\...\{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}) (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86 (HKLM-x32\...\{D1A19B02-817E-4296-A45B-07853FD74D57}) (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86_x64 (HKLM\...\{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}) (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86 (HKLM-x32\...\{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}) (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86_x64 (HKLM\...\{1E9FC118-651D-4934-97BE-E53CAE5C7D45}) (Version: 80.50727.4053 - Adobe) Hidden
Microsoft_VC90_ATL_x86 (HKLM-x32\...\{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}) (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_ATL_x86_x64 (HKLM\...\{8557397C-A42D-486F-97B3-A2CBC2372593}) (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86 (HKLM-x32\...\{08D2E121-7F6A-43EB-97FD-629B44903403}) (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86_x64 (HKLM\...\{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}) (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86 (HKLM-x32\...\{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}) (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86_x64 (HKLM\...\{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}) (Version: 1.00.0000 - Adobe) Hidden
MiVue Manager (HKLM-x32\...\{F9E03BA4-CB0E-4937-B1B0-851FFF5909E1}) (Version: 1.0.36.1 - Navman)
MKV TO AVI CONVERTER version 3.1 (HKLM-x32\...\MKV TO AVI CONVERTER_is1) (Version:  - )
MKVToolNix 77.0.0 (64-bit) (HKLM-x32\...\MKVToolNix) (Version: 77.0.0 - Moritz Bunkus)
MLE (HKLM-x32\...\{D84B7C7E-2E4D-4002-8CA8-EED4EDB333AC}) (Version: 1.0.0.23 - Corel Corporation) Hidden
Movavi Video Converter 23 (HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Movavi Video Converter 23) (Version: 23.0.1 - Movavi)
Movavi Video Editor Plus 2020 (HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Movavi Video Editor Plus 2020) (Version: 20.0.1 - Movavi)
Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox 124.0.2 (x64 en-US)) (Version: 124.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.12.1 - Mozilla)
Mozilla Thunderbird (x64 en-GB) (HKLM\...\Mozilla Thunderbird 115.4.2 (x64 en-GB)) (Version: 115.4.2 - Mozilla)
Mozilla Thunderbird 68.12.1 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 68.12.1 (x86 en-US)) (Version: 68.12.1 - Mozilla)
MSI Center SDK (HKLM-x32\...\{15289038-41BE-48F8-B8B9-0B1021D3089E}}_is1) (Version: 3.2023.0919.01 - MSI)
Need for Speed Underground 2 (HKLM-x32\...\Need for Speed Underground 2) (Version:  - )
Need for Speed™ (HKLM-x32\...\{F8643E83-A868-4EE8-A0B9-389386830453}) (Version: 1.3.0.0 - Electronic Arts)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
Need for Speed™ Payback (HKLM-x32\...\{F4CF3D08-565C-40B7-B351-D3033DE2172B}) (Version: 1.0.51.41148 - Electronic Arts)
Novicorp WinToFlash Professional version 1.13.0000 (HKLM-x32\...\{2CF672A4-E27B-4E70-99E5-F324CF398505}_is1) (Version: 1.13.0000 - Novicorp)
NoxPlayer (HKLM-x32\...\Nox) (Version: 6.6.1.2 - Duodian Technology Co. Ltd.)
NVIDIA FrameView SDK 1.3.8513.32290073 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8513.32290073 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.27.0.112 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.27.0.112 - NVIDIA Corporation)
NVIDIA Graphics Driver 546.01 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 546.01 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.40.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.40.14 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.17425.20146 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.17425.20146 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.17425.20146 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
ON_OFF Charge 2 B15.0709.1 (HKLM-x32\...\{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE) Hidden
ON_OFF Charge 2 B15.0709.1 (HKLM-x32\...\InstallShield_{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE)
PDF Settings CS6 (HKLM-x32\...\{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}) (Version: 11.0 - Adobe Systems Incorporated) Hidden
PeerBlock 1.2 (r693) (HKLM\...\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.2.0.693 - PeerBlock, LLC)
Peggle Nights Deluxe 1.0 (HKLM-x32\...\Peggle Nights Deluxe 1.0) (Version: 1.0 - PopCap Games)
PlatformPowerManagement (HKLM-x32\...\{7A6EB543-522C-4784-9DB5-4FC87522EBDF}) (Version: 1.18.0910.1 - GIGABYTE) Hidden
PlatformPowerManagement (HKLM-x32\...\InstallShield_{7A6EB543-522C-4784-9DB5-4FC87522EBDF}) (Version: 1.18.0910.1 - GIGABYTE)
Plex (HKLM-x32\...\Plex) (Version: 1.87.2 - Plex, Inc.)
Plex Media Server (HKLM-x32\...\{c3c4a6e2-c061-4cda-b8d6-9ca94ec67437}) (Version: 1.40.0.7998 - Plex, Inc.)
Plex Media Server (HKLM-x32\...\{E96E2466-0797-4494-BA83-501BA70C2537}) (Version: 1.40.998 - Plex, Inc.) Hidden
Plexamp 4.7.4 (HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\46418f0f-cea3-5740-a7e9-a0166db1e7c4) (Version: 4.7.4 - Plex, Inc.)
PowerISO (HKLM-x32\...\PowerISO) (Version: 8.5 - Power Software Ltd)
PSPH10Pro (HKLM-x32\...\{DA4A2F61-1E26-4D51-94BB-36D77678BDAD}) (Version: 1.00.0000 - Corel Corporation) Hidden
PSPPContent (HKLM-x32\...\{DF8B9311-ADE7-4EDE-B121-326CAA3D225D}) (Version: 1.00.0000 - Corel Corporation) Hidden
PSPPRO_DCRAW (HKLM-x32\...\{DCF1928A-FC01-48E7-A7E6-4651D42EF6A1}) (Version: 13.0.0 - Corel Corporation) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
PureHD (HKLM-x32\...\{D875FFEE-2FCE-4774-902A-749198C00A68}) (Version: 1.6.1.109 - Corel Corporation) Hidden
PxMergeModule (HKLM-x32\...\{024521CF-C07E-4F8E-8481-0D75695E03AF}) (Version: 1.00.0000 - Your Company Name) Hidden
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
RaceRoom Racing Experience Launcher (HKLM-x32\...\{1FD9F07F-7BBF-4C91-B3F0-A23714A3A913}_is1) (Version: 1.0 - Sector3 Studios)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.21.24.41 - Razer Inc.)
Razer Synapse (HKLM-x32\...\Razer Synapse) (Version: 3.9.0331.032712 - Razer Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8586 - Realtek Semiconductor Corp.)
Realtek USB Wireless LAN Driver (HKLM-x32\...\InstallShield_{DBCC4C27-F949-482b-B786-7B3B67587CD2}) (Version: Drv_3.00.0011 - REALTEK Semiconductor Corp.)
Relic Rescue (HKLM-x32\...\BFG-Relic Rescue) (Version:  - )
Rise Of Legends (HKLM-x32\...\InstallShield_{CADDE354-C78C-46CB-A006-E2B178EFC271}) (Version: 1.00.0000 - Microsoft Game Studios)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.85.1858 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.2.7.3 - Rockstar Games)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.7.43.0 - Samsung Electronics Co., Ltd.)
Setup (HKLM-x32\...\{D1612A3D-0DCC-4055-BB6A-0036F31158A0}) (Version: 1.6.1.109 - Corel Corporation) Hidden
SGX Install (HKLM-x32\...\{3EC52501-2CDF-46D9-AA54-9205C96A5EFE}) (Version: 2.2.104.49337 - GIGABYTE)
Share (HKLM-x32\...\{D94ABC2B-5CA9-48B2-9266-15AB78384D3C}) (Version: 1.6.1.109 - Corel Corporation) Hidden
Share64 (HKLM\...\{D5FE818E-F1C7-44F8-A3C0-C08761906E27}) (Version: 1.6.1.109 - Corel Corporation) Hidden
SIV (HKLM-x32\...\{AAA057C3-10DC-4EB9-A3D6-8208C1BB7411}) (Version: 1.21.1124 - GIGABYTE) Hidden
SIV (HKLM-x32\...\InstallShield_{AAA057C3-10DC-4EB9-A3D6-8208C1BB7411}) (Version: 1.21.1124 - GIGABYTE)
SketchUp Import 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Skype version 8.97 (HKLM-x32\...\Skype_is1) (Version: 8.97 - Skype Technologies S.A.)
Smart Backup B16.0516.1  (x64) (HKLM-x32\...\{BC1FA5CF-A36F-4C61-9638-09D0B431B006}) (Version: 1.00.0003 - GIGABYTE)
Smart Switch (HKLM-x32\...\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.3.23052.1 - Samsung Electronics Co., Ltd.) Hidden
Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.3.23052.1 - Samsung Electronics Co., Ltd.)
Smart TimeLock (HKLM-x32\...\{5D93E30A-78A3-4890-962F-56B61A5873DD}) (Version: 2.18.0731.1 - GIGABYTE) Hidden
Smart TimeLock (HKLM-x32\...\InstallShield_{5D93E30A-78A3-4890-962F-56B61A5873DD}) (Version: 2.18.0731.1 - GIGABYTE)
SmartHUD (HKLM-x32\...\{9809628D-07F9-4D28-A3E8-CCCB8250430A}) (Version: 1.17.1027.1 - GIGABYTE) Hidden
SmartHUD (HKLM-x32\...\InstallShield_{9809628D-07F9-4D28-A3E8-CCCB8250430A}) (Version: 1.17.1027.1 - GIGABYTE)
SmartKeyboard (HKLM-x32\...\{75B74C36-A9C6-4912-B4BB-C461AA36D01E}) (Version: 1.00.0000 - GIGABYTE) Hidden
SmartKeyboard (HKLM-x32\...\InstallShield_{75B74C36-A9C6-4912-B4BB-C461AA36D01E}) (Version: 1.00.0000 - GIGABYTE)
SoftMaker Office 2018 (HKLM\...\{02B0F09C-4734-4F64-BB8A-F22606E9E320}) (Version: 18.0.4734 - SoftMaker Software GmbH)
Space Quest 6 - Roger Wilco in the Spinal Frontier (HKLM-x32\...\1207661463_is1) (Version: 1.0 - GOG.com)
Star Wars Galactic Battlegrounds Duology version r11 (HKLM-x32\...\{9A2E0F8A-8388-419F-880E-AB300284BF2E}_is1) (Version: r11 - XAP4O)
STAR WARS™ Battlefront™ II (HKLM-x32\...\{8a882ce0-0c0b-4eb2-850c-28ebadab4f50}) (Version: 1.1.8.16162 - Electronic Arts)
StarCraft (HKLM-x32\...\StarCraft) (Version:  - Blizzard Entertainment)
StarCraft II (HKLM-x32\...\StarCraft II) (Version:  - Blizzard Entertainment)
Stopping Plex (HKLM-x32\...\{CAB7D1C6-A3FB-481D-A433-24F18796BCE2}) (Version: 1.40.998 - Plex, Inc.) Hidden
Syncios 6.1.0 (HKLM-x32\...\Syncios) (Version: 6.1.0 - Anvsoft)
Total Annihilation Patch Resources v1.0 (HKLM-x32\...\{8DB0D852-1047-4BA4-8458-DA5AF10802ED}) (Version: 1.0 - Total Annihilation Universe)
Total Annihilation v3.9.02 Beta Patch (HKLM-x32\...\{0BDA7A1D-1A75-4AB8-B362-28DF706518D5}) (Version: 3.9.02 - Total Annihilation Universe)
Total Annihilation: Kingdoms (HKLM-x32\...\Total Annihilation: Kingdoms) (Version:  - )
Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 28.1 - Ubisoft)
Ulead VideoStudio 10 version 10 (HKLM-x32\...\{7A8C9C85-D6CC-43E6-8E3C-41A6DBAA9231}_is1) (Version: 10 - MW_Rival, Inc.)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{B9A7A138-BFD5-4C73-A269-F78CCA28150E}) (Version: 8.94.0.0 - Microsoft Corporation)
vcpp_crt.redist.clickonce (HKLM-x32\...\{93FDC294-0726-48EA-989D-50E89C67ABF0}) (Version: 14.10.25008 - Microsoft Corporation) Hidden
VdhCoApp 1.3.0 (HKLM\...\weh-iss-net.downloadhelper.coapp_is1) (Version:  - DownloadHelper)
ViGEm Bus Driver (HKLM\...\{9C581C76-2D68-40F8-AA6F-94D3C5215C05}) (Version: 1.21.442 - Nefarius Software Solutions e.U.)
VIO (HKLM-x32\...\{D9C4FA35-7C6B-4C9E-863B-58C4D7472F41}) (Version: 1.6.1.109 - Corel Corporation) Hidden
Visual F# 4.1 SDK (HKLM-x32\...\{C5BF596B-89E0-4FBB-A944-2043CB96EC37}) (Version: 4.1 - Microsoft Corporation) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.20 - VideoLAN)
VS JIT Debugger (HKLM\...\{2901E697-0E9C-404B-B7D0-6E2D43F64CE5}) (Version: 16.0.59.0 - Microsoft Corporation) Hidden
vs_BlendMsi (HKLM-x32\...\{1070C8E8-4DFB-419F-984A-5C835828897E}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
vs_clickoncebootstrappermsi (HKLM-x32\...\{B9F4AA09-F4AC-4108-ADA0-27CDD45FCEC3}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
vs_clickoncebootstrappermsires (HKLM-x32\...\{AEF5E0F2-31D1-454A-A992-C523C0007B4D}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
vs_clickoncesigntoolmsi (HKLM-x32\...\{DE8B48BF-82B9-434A-B254-1EA2306E5FBA}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
vs_communitymsi (HKLM-x32\...\{0E1A59A3-625B-47C4-BC96-E8A876417A8F}) (Version: 15.0.26228 - Microsoft Corporation) Hidden
vs_communitymsires (HKLM-x32\...\{1210EE60-E253-407D-B537-D36898049CF0}) (Version: 15.0.26228 - Microsoft Corporation) Hidden
vs_devenvmsi (HKLM-x32\...\{581E5656-26E2-4A02-9711-48C8E4998310}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
vs_filehandler_amd64 (HKLM-x32\...\{15D591B0-7B40-4957-B6C0-EB7452B5AAB6}) (Version: 15.0.26228 - Microsoft Corporation) Hidden
vs_filehandler_x86 (HKLM-x32\...\{DC296244-0701-4EDE-9696-05B9C1D017B3}) (Version: 15.0.26228 - Microsoft Corporation) Hidden
vs_FileTracker_Singleton (HKLM-x32\...\{11230C85-1813-4BC3-9C24-E0B74B59653E}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
vs_minshellinteropmsi (HKLM-x32\...\{1E8F631A-96B4-4BB1-9455-B2FF083DA864}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
vs_minshellmsi (HKLM-x32\...\{47C6B2A0-8A58-4C87-91B8-DC8D138524AA}) (Version: 15.0.26228 - Microsoft Corporation) Hidden
vs_minshellmsires (HKLM-x32\...\{A8B77523-13AB-46B9-B54F-5483E09668F9}) (Version: 15.0.26228 - Microsoft Corporation) Hidden
vs_SQLClickOnceBootstrappermsi (HKLM-x32\...\{D396CF10-5F2B-417D-9571-0B669B99440E}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
vs_tipsmsi (HKLM-x32\...\{A32A9CF6-E7AA-48B8-A3D3-50C157E69F53}) (Version: 15.0.26208 - Microsoft Corporation) Hidden
VTuner (HKLM-x32\...\{C381226E-C402-4976-9411-54282F1396D3}) (Version: 1.17.0817.1 - GIGABYTE) Hidden
VTuner (HKLM-x32\...\InstallShield_{C381226E-C402-4976-9411-54282F1396D3}) (Version: 1.17.0817.1 - GIGABYTE)
Web Companion (HKLM-x32\...\{dc1b032b-8021-4661-bb22-e8d765e4e5c3}) (Version: 4.9.2159.4024 - Lavasoft) <==== ATTENTION
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
Windows Driver Package - Canon U.S.A., Inc. (WUDFRd) Camera  (08/22/2022 19.3.27.788) (HKLM\...\DDD77FDE28FB04AFB7515B8F55849CCBC8B2C231) (Version: 08/22/2022 19.3.27.788 - Canon U.S.A., Inc.)
Windows Media Encoder 9 Series (HKLM-x32\...\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}) (Version: 9.00.2980 - Microsoft Corporation) Hidden
Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )
Windows PC Health Check (HKLM\...\{804A0628-543B-4984-896C-F58BF6A54832}) (Version: 3.7.2204.15001 - Microsoft Corporation)
WinRAR 6.22 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.22.0 - win.rar GmbH)
WinX HD Video Converter Deluxe 5.12.0 (HKLM-x32\...\WinX HD Video Converter Deluxe_is1) (Version:  - Digiarty Software, Inc.)
Wondershare MobileTrans ( Version 3.3.3 ) (HKLM-x32\...\{72289023-823E-4AF7-A65F-C608481758AC}_is1) (Version: 3.3.3 - Wondershare)
Wondershare MobileTrans ( Version 8.1.0 ) (HKLM-x32\...\{18CDCEAA-A9E4-4A4C-AC0E-C15E87C30EA5}_is1) (Version: 8.1.0 - Wondershare)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version:  - Blizzard Entertainment)
Xilisoft Video Converter Ultimate (HKLM-x32\...\Xilisoft Video Converter Ultimate) (Version: 7.8.8.20150402 - Xilisoft)
XSplit Broadcaster (HKLM\...\{9AE27B4A-BF08-4C2A-B63D-D22FB9D9AC20}) (Version: 4.3.2202.1228 - XSplit)
Zumas Revenge (HKLM-x32\...\{0B153CAB-792B-4CA2-B2A5-AB0BBAF2FFA9}) (Version: 1.0.5.600 - PopCap Games)
 
Packages:
=========
 
Adobe Acrobat Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC [2024-03-20] ()
Caesars Slots -> C:\Program Files\WindowsApps\Playtika.CaesarsSlotsFreeCasino_5.26.1.0_x64__7vjeg68vnncd2 [2024-04-04] (Playtika Holdings Corp)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.265.200.0_x64__kgqvnymyfvs32 [2024-04-04] (king.com)
Club Vegas -> C:\Program Files\WindowsApps\BagelcodeInc.47921C88A920C_187.0.4.0_x64__5dvc9f3b38e20 [2024-04-07] (Bagelcode)
Dev Home -> C:\Program Files\WindowsApps\Microsoft.Windows.DevHome_0.1200.442.0_x64__8wekyb3d8bbwe [2024-03-20] (Microsoft Corporation)
Facebook -> C:\Program Files\WindowsApps\www.facebook.com-1C2D851A_2023.531.1.1_neutral__n468xs7erp6tc [2023-10-15] (www.facebook.com)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_152.1.1099.0_x64__v10z8vjag6ke6 [2024-03-09] (HP Inc.)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12131.3.2010.0_x64__nzyj5cx40ttqa [2024-02-07] (Apple Inc.) [Startup Task]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-20] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-20] (Microsoft Corporation) [MS Ad]
Microsoft Copilot -> C:\Program Files\WindowsApps\Microsoft.Windows.Ai.Copilot.Provider_1.0.3.0_neutral__8wekyb3d8bbwe [2024-03-29] (Microsoft Corporation)
Microsoft Defender -> C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2402.13001.0_x64__8wekyb3d8bbwe [2024-02-28] (Microsoft Corporation) [Startup Task]
MSI Center -> C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.MSICenter_2.0.34.0_x64__kzh8wxbdkxb8p [2024-04-07] (MICRO-STAR INTERNATIONAL CO., LTD) [Startup Task]
MSI Game Bar -> C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.MSIGameBar_2.0.14.0_x64__kzh8wxbdkxb8p [2023-05-12] (MICRO-STAR INTERNATIONAL CO., LTD)
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.98.1805.0_x64__mcm4njqhnhss8 [2022-02-18] (Netflix, Inc.)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.965.0_x64__56jybvy8sckqj [2024-03-26] (NVIDIA Corp.)
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-03-12] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-09-17] (Microsoft Corporation)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.2.175.0_x64__dt26b99r8h8gj [2020-06-14] (Realtek Semiconductor Corp)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.19.1262.0_x64__8wekyb3d8bbwe [2024-04-08] (Microsoft Studios) [MS Ad]
Speedtest by Ookla -> C:\Program Files\WindowsApps\Ookla.SpeedtestbyOokla_1.18.194.0_x64__43tkc6nmykmb6 [2024-03-15] (Ookla)
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.TWITTER_7.0.1.0_neutral__wgeqdkkx372wm [2021-06-11] (Twitter Inc.)
WinAppRuntime.Main.1.2-p1 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.2-p1_2000.609.1413.0_x64__8wekyb3d8bbwe [2024-02-18] (Microsoft Corp.)
WinAppRuntime.Singleton-p1 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton-p1_2000.609.1413.0_x64__8wekyb3d8bbwe [2024-02-18] (Microsoft Corp.)
Windows App Runtime DDLM 2000.609.1413.0-x6-p1 -> C:\Program Files\WindowsApps\Microsoft.WinAppRuntime.DDLM.2000.609.1413.0-x6-p1_2000.609.1413.0_x64__8wekyb3d8bbwe [2024-02-18] (Microsoft Corporation)
Windows App Runtime DDLM 2000.609.1413.0-x8-p1 -> C:\Program Files\WindowsApps\Microsoft.WinAppRuntime.DDLM.2000.609.1413.0-x8-p1_2000.609.1413.0_x86__8wekyb3d8bbwe [2024-02-18] (Microsoft Corporation)
WindowsAppRuntime.1.2-preview1 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.2-preview1_2000.609.1413.0_x64__8wekyb3d8bbwe [2024-02-18] (Microsoft Corporation)
WindowsAppRuntime.1.2-preview1 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.2-preview1_2000.609.1413.0_x86__8wekyb3d8bbwe [2024-02-18] (Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-559634521-2701541241-958822180-1001_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-559634521-2701541241-958822180-1001_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-559634521-2701541241-958822180-1001_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-559634521-2701541241-958822180-1001_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-559634521-2701541241-958822180-1001_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-559634521-2701541241-958822180-1001_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-559634521-2701541241-958822180-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-559634521-2701541241-958822180-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-559634521-2701541241-958822180-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-559634521-2701541241-958822180-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\en-US\acadficn.dll (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-559634521-2701541241-958822180-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems Incorporated -> Adobe Systems)
ShellIconOverlayIdentifiers: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2024-04-07] (AVG Technologies USA, LLC -> Gen Digital Inc.)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc -> Autodesk, Inc.)
ShellIconOverlayIdentifiers-x32: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2024-04-07] (AVG Technologies USA, LLC -> Gen Digital Inc.)
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2015-02-06] (Autodesk, Inc -> Autodesk)
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat Elements\ContextMenuShim64.dll [2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2024-04-07] (AVG Technologies USA, LLC -> Gen Digital Inc.)
ContextMenuHandlers1: [Corel.Paint.Shop.Pro.Photo] -> {B1D2CD8F-45E9-49d1-838A-AAA5780D94B7} => c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\PSPContextMenu64.dll [2009-12-30] (Corel Corporation -> )
ContextMenuHandlers1: [DWGSeeMenu] -> {A6EAF440-149E-4AF3-AE84-5DA3CF791E3B} => C:\Program Files (x86)\AutoDWG\DWGSee\DWGSeeMenu64.dll -> No File
ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2023-05-15] (Power Software Limited -> Power Software Ltd)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-05-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-05-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [Corel.Paint.Shop.Pro.Photo] -> {B1D2CD8F-45E9-49d1-838A-AAA5780D94B7} => c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\PSPContextMenu64.dll [2009-12-30] (Corel Corporation -> )
ContextMenuHandlers2-x32: [Ulead UDF Driver] -> {DBD8E168-244D-448C-9922-25508950D1DC} => c:\Program Files (x86)\Common Files\Ulead Systems\DVD\USIShex.dll [2010-01-07] (Corel Corporation -> Ulead Systems, Inc.)
ContextMenuHandlers3: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2024-04-07] (AVG Technologies USA, LLC -> Gen Digital Inc.)
ContextMenuHandlers4: [Corel.Paint.Shop.Pro.Photo] -> {B1D2CD8F-45E9-49d1-838A-AAA5780D94B7} => c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\PSPContextMenu64.dll [2009-12-30] (Corel Corporation -> )
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2023-05-15] (Power Software Limited -> Power Software Ltd)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvaei.inf_amd64_89430f5327945961\nvshext.dll [2023-10-30] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat Elements\ContextMenuShim64.dll [2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2024-04-07] (AVG Technologies USA, LLC -> Gen Digital Inc.)
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2023-05-15] (Power Software Limited -> Power Software Ltd)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-05-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-05-30] (win.rar GmbH -> Alexander Roshal)
 
==================== Codecs (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Drivers32: [msacm.dvacm] => C:\Program Files (x86)\Common Files\Ulead Systems\VIO\DVACM.acm [20480 2010-01-07] (Corel TW Corp.) [File not signed]
HKLM\...\Drivers32: [msacm.MPEGacm] => C:\Program Files (x86)\Common Files\Ulead Systems\MPEG\MPEGACM.acm [69632 2010-01-07] (Ulead Systems, Inc.) [File not signed]
HKLM\...\Drivers32: [msacm.ulmp3acm] => C:\Program Files (x86)\Common Files\Ulead Systems\MPEG\ulmp3acm.acm [319488 2010-01-07] (Ulead systems) [File not signed]
HKLM\...\Drivers32-x32: [vidc.VP60] => C:\WINDOWS\system32\vp6vfw.dll
HKLM\...\Drivers32-x32: [vidc.VP61] => C:\WINDOWS\system32\vp6vfw.dll
 
==================== Shortcuts & WMI ========================
 
==================== Loaded Modules (Whitelisted) =============
 
2017-09-06 18:11 - 2017-09-06 18:11 - 000125952 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ffi\build\Release\ffi_bindings.node
2017-09-06 18:11 - 2017-09-06 18:11 - 000118272 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\fs-ext\build\Release\fs-ext.node
2017-09-06 18:11 - 2017-09-06 18:11 - 000086528 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\idle-gc\build\Release\idle-gc.node
2017-09-06 18:11 - 2017-09-06 18:11 - 000214528 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node
2017-09-06 18:11 - 2017-09-06 18:11 - 000117248 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ref\build\Release\binding.node
2024-02-15 18:03 - 2024-02-15 18:03 - 000433664 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\aac_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000402944 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\aac_encoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000321024 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\ac3_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000321536 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\ac3_encoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000296960 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\cook_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000459776 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\dca_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000573952 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\flv_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000573952 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\h263_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 001803776 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\h264_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000857088 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\hevc_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000412160 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\libmp3lame_encoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 002366464 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\libx264_encoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000329216 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\mp1_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000329216 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\mp2_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000329216 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\mp3_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000310272 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\mpc7_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000505856 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\mpeg1video_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000516096 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\mpeg2video_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000707072 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\mpeg4_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000613888 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\msmpeg4v3_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 001528320 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\rv40_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000318976 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\wmav2_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 000649216 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\wmv2_decoder.dll
2024-02-15 18:03 - 2024-02-15 18:03 - 001045504 _____ () [File not signed] \\?\C:\Users\dwood\AppData\Local\Plex Media Server\Codecs\ad47460-4670-windows-x86\wmv3_decoder.dll
2021-08-20 10:16 - 2021-08-20 10:16 - 001867776 _____ () [File not signed] C:\Program Files (x86)\GIGABYTE\AppCenter\BDR_info.dll
2023-03-02 16:55 - 2023-02-28 06:39 - 001393152 _____ () [File not signed] C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.Core.Runtime.dll
2021-01-16 15:50 - 2015-12-14 16:39 - 000194560 _____ (AVerMedia Technologies, Inc.) [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\dll\CardID.dll
2021-01-16 15:50 - 2015-02-09 13:32 - 000770048 _____ (AVerMedia Technologies, Inc.) [File not signed] C:\Program Files (x86)\Common Files\AVerMedia\dll\GraphMaster.dll
2017-04-28 18:59 - 2013-09-11 15:50 - 000360448 _____ (CANON INC.) [File not signed] C:\WINDOWS\System32\CNMN6PPM.DLL
2017-04-28 19:01 - 2013-09-12 05:00 - 000394240 _____ (CANON INC.) [File not signed] C:\WINDOWS\System32\CNMXLMC2.DLL
2019-06-21 23:43 - 2009-05-01 11:51 - 001069056 _____ (Cisco Systems, Inc.) [File not signed] C:\Program Files (x86)\MediatekWiFi\Common\CiscoEapFast.dll
2014-07-30 19:56 - 2014-07-30 19:56 - 000208896 _____ (Gigabyte Technology CO., LTD.) [File not signed] C:\Program Files (x86)\GIGABYTE\Smart TimeLock\slmDB.dll
2013-02-22 14:36 - 2013-02-22 14:36 - 000087040 _____ (Gigabyte Technology CO., LTD.) [File not signed] C:\Program Files (x86)\GIGABYTE\Smart TimeLock\slmWeekCtrlRule.dll
2015-03-19 14:54 - 2015-03-19 14:54 - 000172032 _____ (Gigabyte Technology CO., LTD.) [File not signed] C:\Program Files (x86)\GIGABYTE\Smart TimeLock\SmartLock.dll
2012-08-03 18:49 - 2012-08-03 18:49 - 000039424 _____ (OpenDNS) [File not signed] C:\Program Files (x86)\OpenDNS\DNSCrypt\Core.dll
2021-10-28 16:18 - 2021-10-28 16:18 - 000083984 _____ (Razer USA Ltd. -> Razer Inc.) [File not signed] C:\Program Files (x86)\Razer\Synapse\RzStorageIO.dll
2021-10-28 16:18 - 2021-10-28 16:18 - 000095776 _____ (Razer USA Ltd. -> Razer) [File not signed] C:\Program Files (x86)\Razer\Synapse\RazerProtocolDLL.dll
2015-10-14 01:15 - 2015-10-14 01:15 - 002042368 _____ (TODO: <Company name>) [File not signed] C:\Program Files (x86)\GIGABYTE\AppCenter\osvi.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:036B81D9 [167]
AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F [134]
AlternateDataStreams: C:\ProgramData\TEMP:4B6A9FDA [163]
AlternateDataStreams: C:\ProgramData\TEMP:5C92988B [191]
AlternateDataStreams: C:\ProgramData\TEMP:627B7F7C [384]
AlternateDataStreams: C:\ProgramData\TEMP:BD13A410 [106]
AlternateDataStreams: C:\ProgramData\TEMP:EC9FFAA4 [178]
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\avgSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\avgSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) =================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\S-1-5-21-559634521-2701541241-958822180-1001\Software\Classes\.scr: AutoCADScriptFile => 
 
==================== Internet Explorer (Whitelisted) ==========
 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
BHO: GBHO.BHO -> {45d30484-7ded-43d9-957a-d2fd1f046511} -> C:\WINDOWS\system32\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-11-02] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: FlashGetBHO -> {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} -> C:\Users\dwood\AppData\Roaming\FlashGetBHO\FlashGetBHO.dll [2012-01-06] (Trend Media Corporation Limited -> Trend Media Group)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-11-02] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM - Smart Backup - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\WINDOWS\system32\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-11-02] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2024-04-05] (Microsoft Corporation -> Microsoft Corporation)
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com
IE trusted site: HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\webcompanion.com -> hxxp://webcompanion.com
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2017-02-15 18:46 - 2019-06-28 09:34 - 000000918 _____ C:\WINDOWS\system32\drivers\etc\hosts
0.0.0.0 serius.mwbsys.com
0.0.0.0 keystone.mwbsys.com
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Razer Chroma SDK\bin;C:\Program Files\Razer Chroma SDK\bin;C:\Program Files (x86)\Razer\ChromaBroadcast\bin;C:\Program Files\Razer\ChromaBroadcast\bin;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;c:\Program Files (x86)\Common Files\Ulead Systems\MPEG;C:\Program Files (x86)\QuickTime\QTSystem\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files\Intel\Intel® Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL;C:\Program Files\Intel\Intel® Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\WindowsApps;;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\dotnet\
HKU\S-1-5-21-559634521-2701541241-958822180-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-559634521-2701541241-958822180-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
 
Network Binding:
=============
Ethernet: cFosSpeed for faster Internet connections (NDIS 6) -> cfosspeed (enabled) 
WiFi 5: cFosSpeed for faster Internet connections (NDIS 6) -> cfosspeed (enabled) 
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
HKLM\...\StartupApproved\StartupFolder: => "AVerQuick.lnk"
HKLM\...\StartupApproved\StartupFolder: => "OpenDNSCrypt.lnk"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run: => "MouseDriver"
HKLM\...\StartupApproved\Run: => "Start WingMan Profiler"
HKLM\...\StartupApproved\Run32: => "Syncios device service"
HKLM\...\StartupApproved\Run32: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKLM\...\StartupApproved\Run32: => "Standby"
HKLM\...\StartupApproved\Run32: => "WSHelperSetup.exe"
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\StartupApproved\StartupFolder: => "Facebook Gameroom.lnk"
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk"
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\StartupApproved\StartupFolder: => "EOS Utility.lnk"
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\StartupApproved\Run: => "Autodesk Sync"
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\StartupApproved\Run: => "WSHelperSetup.exe"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{995FD554-33F7-421B-B7D6-1974A35106CC}] => (Allow) LPort=9009
FirewallRules: [{132A649D-D696-4028-B073-CA313C96103D}] => (Allow) LPort=9009
FirewallRules: [{F4A882A3-80BA-4344-92A9-CC06BA2E3819}] => (Allow) LPort=9009
FirewallRules: [{35ABD4AA-6520-4CCE-8EB9-E35D7473561A}] => (Allow) LPort=9009
FirewallRules: [UDP Query User{1D9058F4-3350-4C19-B271-0564BB7523CB}D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds_cc.exe] => (Allow) D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds_cc.exe (LucasArts Entertainment Company LLC) [File not signed]
FirewallRules: [TCP Query User{F3AB89A0-3B5C-4A35-B9E5-17A7FDDDB95A}D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds_cc.exe] => (Allow) D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds_cc.exe (LucasArts Entertainment Company LLC) [File not signed]
FirewallRules: [{27C89AB2-E68C-4AD9-B094-72CED4A9CD5D}] => (Allow) LPort=9009
FirewallRules: [{6316021A-A3D6-472B-809B-FC64BCE4F098}] => (Allow) LPort=9009
FirewallRules: [{274FA879-CC73-4424-AA83-53D587AE4940}] => (Allow) LPort=9009
FirewallRules: [{8DEE4CCF-988F-4454-B8EA-1DF3DED381DC}] => (Allow) LPort=9009
FirewallRules: [UDP Query User{5DB27A7B-FC0E-4E7A-BB20-5DF8E3635B3F}D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds.exe] => (Allow) D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds.exe (LucasArts Entertainment Company LLC) [File not signed]
FirewallRules: [TCP Query User{7B5EE7E1-0B08-43E0-B980-4CA4EF6EE589}D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds.exe] => (Allow) D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds.exe (LucasArts Entertainment Company LLC) [File not signed]
FirewallRules: [{73B77495-4AB7-4B46-A007-25CDB4EF0ACC}] => (Allow) LPort=9009
FirewallRules: [{4DAA5BE3-5F99-441C-9653-CFDD458F8BE2}] => (Allow) LPort=9009
FirewallRules: [{CEF48B91-0596-40F0-A321-109032876B2A}] => (Allow) LPort=9009
FirewallRules: [{616C11CA-8B76-4914-81F3-EA6609ACD6F9}] => (Allow) LPort=9009
FirewallRules: [{08AC3EF5-EC80-4AC5-B3B0-E6100B382E07}] => (Allow) LPort=9009
FirewallRules: [{D21302BE-1E1D-4E51-8AA5-2CE113316ED1}] => (Allow) LPort=9009
FirewallRules: [{502977EA-57EA-4CC4-BCE4-9B3D48C72A88}] => (Allow) LPort=9009
FirewallRules: [{945EB311-2756-4DAB-8FBF-40276BC8BB12}] => (Allow) LPort=9009
FirewallRules: [{C46A92C1-79F7-4D16-A785-034CCC2DEEC9}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{63C27DA4-390B-44FB-A300-574E313834B1}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{F304D883-82BF-4A9D-8B5B-0C10C49F266F}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed\NFS16_trial.exe (Electronic Arts -> Electronic Arts)
FirewallRules: [{F6F05FD5-47BC-4804-809F-92D13B2D2DE9}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed\NFS16_trial.exe (Electronic Arts -> Electronic Arts)
FirewallRules: [{F91D9ABA-DCAB-4ECF-960B-E6C0D06ABE03}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed\NFS16.exe (Electronic Arts -> Electronic Arts)
FirewallRules: [{EE1573AE-1FBB-4694-9356-F7FB27DD394B}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed\NFS16.exe (Electronic Arts -> Electronic Arts)
FirewallRules: [{C6E18E53-FF63-432F-8A21-E7269578734D}] => (Allow) LPort=9009
FirewallRules: [{DA18A2C4-4427-4718-9EB2-4E5E57E90D62}] => (Allow) LPort=9009
FirewallRules: [{C6A9D37C-40D8-40DC-AF2F-F95C0BE75C8F}] => (Allow) LPort=9009
FirewallRules: [{ADAF40A2-0158-42A1-80FB-93BD552C6EE9}] => (Allow) LPort=9009
FirewallRules: [{0BE1C709-8E9E-4A73-A9B1-25518BCA76BA}] => (Allow) LPort=9009
FirewallRules: [{5C4C05CD-A710-4954-A801-388EDD8C9596}] => (Allow) LPort=9009
FirewallRules: [{7A91B980-3C03-4DEA-8E2B-49D24B1C236B}] => (Allow) LPort=9009
FirewallRules: [{184A27F5-6C9E-460F-A6E4-32E9679786FD}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{FAD63D16-686E-4FF0-A908-F25251E2DEBD}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{645D6625-4D7B-4526-A5C5-E2DF2311CA60}] => (Allow) LPort=9009
FirewallRules: [{60FB1284-1D24-4A69-9BB4-97102760DC5B}] => (Allow) LPort=9009
FirewallRules: [{4170087D-B79E-44B3-9AB2-9F2EFECDB561}] => (Allow) LPort=9009
FirewallRules: [{84F0A210-E7AE-46EF-8621-06CD0BAA05C1}] => (Allow) LPort=8840
FirewallRules: [{FAD4B395-48E3-4567-A050-415ED23903E1}] => (Allow) LPort=9009
FirewallRules: [{254EEA2A-B23B-4326-8CEC-8D2D286A02EC}] => (Allow) LPort=8990
FirewallRules: [{99B116D7-3DB5-4259-A541-F802AB73702E}] => (Allow) LPort=9009
FirewallRules: [{E182C90B-3D20-4B25-9D3E-D6A16C6558E5}] => (Allow) LPort=9009
FirewallRules: [{1BD91AD0-CC69-4F7D-B239-F2A29E28138C}] => (Allow) LPort=9009
FirewallRules: [{D637E5F1-667D-4507-99A3-34DA107871F2}] => (Allow) LPort=9009
FirewallRules: [{B82A5236-C810-45D1-A3C3-61E21E2161B5}] => (Allow) LPort=9009
FirewallRules: [{54E8D007-A786-42FF-82D7-6557C13893D2}] => (Allow) LPort=9009
FirewallRules: [{E9E91617-D94C-4575-9679-FBB8DEC3BAFC}] => (Allow) LPort=9009
FirewallRules: [{6FDB6C5A-3FD0-4C7C-83CC-9F389BD4D210}] => (Allow) LPort=9009
FirewallRules: [{890869AE-975C-450A-A602-F2EE9E8E444D}] => (Allow) LPort=9009
FirewallRules: [UDP Query User{46067828-4B06-4EAB-8CD8-1B243A9CF5F6}D:\steamlibrary\steamapps\common\flatout ultimate carnage\fouc.exe] => (Allow) D:\steamlibrary\steamapps\common\flatout ultimate carnage\fouc.exe (Bugbear Entertainment Ltd. -> Empire Interactive Ltd.) [File not signed]
FirewallRules: [TCP Query User{C0BA671F-22E1-417D-BC36-B764DD5A28A5}D:\steamlibrary\steamapps\common\flatout ultimate carnage\fouc.exe] => (Allow) D:\steamlibrary\steamapps\common\flatout ultimate carnage\fouc.exe (Bugbear Entertainment Ltd. -> Empire Interactive Ltd.) [File not signed]
FirewallRules: [{AF51B825-538B-4029-BF06-65055E7509E8}] => (Allow) LPort=9009
FirewallRules: [{C89EAD72-D9F7-4CF5-A58C-430D3F180DF6}] => (Allow) LPort=9009
FirewallRules: [{B04C3C6F-C7E2-457A-BB32-20C03D979D72}] => (Allow) LPort=9009
FirewallRules: [{4DE26748-2FCE-4984-835A-56CB512DAF7A}] => (Allow) LPort=9009
FirewallRules: [{60D315AC-B8AC-447E-B872-DF088B51C989}] => (Allow) LPort=9009
FirewallRules: [{EFE352B9-AD92-48A6-B08A-660ED6FB3FB6}] => (Allow) LPort=9009
FirewallRules: [{558A4131-F3B9-4C8D-A248-8DD4E7FA1FD4}] => (Allow) LPort=9009
FirewallRules: [{E7CC1206-69E7-4615-A180-6DAA62B2BFB3}] => (Allow) LPort=9009
FirewallRules: [{32B43DE9-F494-4131-A7B9-A45A545A8713}] => (Allow) LPort=9009
FirewallRules: [{F2448E9A-9B59-4032-A8FE-02EA488B6281}] => (Allow) LPort=9009
FirewallRules: [{A5116A00-A756-4A7F-9577-14971C2B88F6}] => (Allow) LPort=9009
FirewallRules: [{97F8D085-0725-4623-9FF3-B87056340B26}] => (Allow) LPort=9009
FirewallRules: [{93D86873-3C78-4F2A-AD1C-657418CD6B23}] => (Allow) LPort=9009
FirewallRules: [{B5DB313C-8D7D-4B67-B5B0-EBB4BC62BC6B}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{2AC8C002-448F-4098-A6F8-E897E62CABE6}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{A7F52559-7524-4C32-B945-F5C5E97513E6}] => (Allow) LPort=9009
FirewallRules: [{69EE8499-A01B-43DE-9F3F-DF295E7AE05B}] => (Allow) LPort=9009
FirewallRules: [{0093F1A8-7ADF-4682-A842-4349EF5FD522}] => (Allow) LPort=9009
FirewallRules: [{AD825A90-1566-4875-A7DD-6E666A3B5A3F}] => (Allow) LPort=9009
FirewallRules: [{F01893E2-5096-42A2-90DB-ED16E0D8FB2B}] => (Allow) LPort=9009
FirewallRules: [{F643E1A0-CBD5-4681-88C9-44A0BB2F52EE}] => (Allow) LPort=9009
FirewallRules: [{C2CC63EE-0E7D-4B79-8542-6E8285439709}] => (Allow) LPort=9009
FirewallRules: [{0A4BA63D-EF23-4C68-9D43-049591393715}] => (Allow) LPort=9009
FirewallRules: [{2C2F9BD0-3F75-40D3-AD31-F78A3CF64D23}] => (Allow) LPort=9009
FirewallRules: [{B380DF0F-49A1-4D3A-A6D2-8FB74EF498E4}] => (Allow) LPort=9009
FirewallRules: [{891169DB-614D-4F80-A533-A98028851D6B}] => (Allow) D:\Ubisoft\install\Far Cry New Dawn\bin\FarCryNewDawn.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{C51CB0F5-0287-4A3B-A8F9-62146B828AFC}] => (Allow) D:\Ubisoft\install\Far Cry New Dawn\bin\FarCryNewDawn.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{044F5D78-B204-4D7C-8EA7-BCD36981B421}] => (Allow) D:\Ubisoft\install\Far Cry New Dawn\bin\FarCryNewDawn.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{AF197D53-CC2E-41D0-AFDF-15E1F650B2D3}] => (Allow) D:\Ubisoft\install\Far Cry New Dawn\bin\FarCryNewDawn.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{E1DE2802-3B5A-4841-9822-8CBACC64F9BB}] => (Allow) LPort=9009
FirewallRules: [{2C80E0F1-DA09-468C-B1F7-406C6D7EDB95}] => (Allow) LPort=9009
FirewallRules: [{1AC555E8-F0D5-44BF-AABC-FE751C7B524D}] => (Allow) LPort=9009
FirewallRules: [{5F4F0250-A83D-41EB-9EA5-CCC440BC5F42}] => (Allow) LPort=9009
FirewallRules: [{326DDD28-0295-4842-8DBD-7A65BC1CEC10}] => (Allow) LPort=9009
FirewallRules: [{32B6E2D8-4EF4-4E2A-9DD5-C7D20ECDC4E7}] => (Allow) LPort=9009
FirewallRules: [{CA7A2B62-3607-4104-968D-D4B80B587CFB}] => (Allow) LPort=9009
FirewallRules: [{F93C533E-AD2A-4A3D-996E-412A96281D83}] => (Allow) LPort=9009
FirewallRules: [{56EB8C01-9F2B-452A-8B8C-060FA0AAB110}] => (Allow) D:\SteamLibrary\SteamApps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{BFB86F51-22DE-44AF-BA30-2D893DA13BA7}] => (Allow) D:\SteamLibrary\SteamApps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{4FAF984C-E6B9-4619-A237-44EBE5E3916B}] => (Allow) LPort=9009
FirewallRules: [{54569B41-1858-4DBF-A599-4550A0B758CF}] => (Allow) LPort=9009
FirewallRules: [{607378AF-F154-4F49-8FCB-3233A5E8AE8E}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{D54182B8-BB1B-4C8C-B9E6-1129CAD25132}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{D567FB52-9AD8-49DE-B65E-F5D1E1BB0CC6}] => (Allow) LPort=9009
FirewallRules: [{F7B5118B-249F-477D-9226-CA2160B3C584}] => (Allow) LPort=9009
FirewallRules: [{B0A919B2-5B39-4653-B9FD-19B182F48E8C}] => (Allow) LPort=9009
FirewallRules: [{98F3DF77-E9C2-4AE1-9E8C-837D56068DD2}] => (Allow) LPort=9009
FirewallRules: [{86ABAAA8-83EE-4046-8E02-287FF639049E}] => (Allow) LPort=9009
FirewallRules: [{D22CA37D-AC30-46B5-8854-9E586EB9C303}] => (Allow) LPort=9009
FirewallRules: [{740DE98D-7DFA-4DE9-B6A4-AA978F44FDE0}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
FirewallRules: [{5D1698AA-99A9-4679-BF73-825863BA3CE0}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
FirewallRules: [{24A63E97-3630-4540-A673-1F8909057FC2}] => (Allow) LPort=9009
FirewallRules: [{FE30A915-D43A-40D4-BBDD-62CDCA851B66}] => (Allow) D:\Steam\steamapps\common\Sniper Elite 3\Launcher\Sniper3Launcher.exe () [File not signed]
FirewallRules: [{AC737083-D3C1-4DEA-8568-880EE099BFF9}] => (Allow) D:\Steam\steamapps\common\Sniper Elite 3\Launcher\Sniper3Launcher.exe () [File not signed]
FirewallRules: [{421BE1A2-06C7-4DB4-A42C-FCDBEFFC792C}] => (Allow) D:\Steam\steamapps\common\Sniper Elite V2\Launcher\SniperV2Launcher.exe () [File not signed]
FirewallRules: [{406038CC-F325-4823-B365-237B0319268B}] => (Allow) D:\Steam\steamapps\common\Sniper Elite V2\Launcher\SniperV2Launcher.exe () [File not signed]
FirewallRules: [{38085DF2-8245-4C5A-8D80-987D4DACA262}] => (Allow) D:\SteamLibrary\SteamApps\common\Dawn of War Soulstorm\Soulstorm.exe (Relic Entertainment, Inc. -> Sega Corporation)
FirewallRules: [{C95583FE-BA82-427B-AE6E-17585546594A}] => (Allow) D:\SteamLibrary\SteamApps\common\Dawn of War Soulstorm\Soulstorm.exe (Relic Entertainment, Inc. -> Sega Corporation)
FirewallRules: [{9AE3170E-BFA0-4A58-B868-5E5251BDB7DD}] => (Allow) D:\Steam\steamapps\common\Far Cry 4\bin\FarCry4.exe (Ubisoft Entertainment -> Ubisoft Entertainment)
FirewallRules: [{7B19EA83-AB86-45C6-81C3-D65F287B7DBC}] => (Allow) D:\Steam\steamapps\common\Far Cry 4\bin\FarCry4.exe (Ubisoft Entertainment -> Ubisoft Entertainment)
FirewallRules: [{344F6B82-D506-43DE-AE67-E602E975055C}] => (Allow) D:\SteamLibrary\SteamApps\common\Loadout\Loadout.exe (Edge of Reality, Ltd. -> )
FirewallRules: [{4BFC9CEA-E172-4D8C-906A-E04804F80120}] => (Allow) D:\SteamLibrary\SteamApps\common\Loadout\Loadout.exe (Edge of Reality, Ltd. -> )
FirewallRules: [{D9FB2D02-9367-479A-99C9-5DAA625911E2}] => (Allow) LPort=9009
FirewallRules: [{89D9046E-9428-4F8A-8798-CD6CF60E02AB}] => (Allow) LPort=9009
FirewallRules: [{1350B2A3-4F9D-4E7B-A8CF-F615F4CBD684}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
FirewallRules: [{5E86C391-1757-4341-A255-1268191F4E1E}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
FirewallRules: [{74576625-E8A2-4C63-B02C-FD6405FED368}] => (Allow) LPort=9009
FirewallRules: [{E9A05197-96EA-4899-AF32-CFD54A36C95E}] => (Allow) LPort=9009
FirewallRules: [{0CD35100-547A-4447-BF62-3CB7E503F263}] => (Allow) LPort=9009
FirewallRules: [{1181E91E-26ED-4E78-A847-723B1FCCE37F}] => (Allow) LPort=9009
FirewallRules: [{B1CBBB31-F6B1-41E4-BEF4-19B8B521CEC4}] => (Allow) LPort=9009
FirewallRules: [{59F579F5-15AF-4C93-8B5B-E5F19818DB17}] => (Allow) LPort=9009
FirewallRules: [{DF419433-C922-4C6C-BF70-E131FAE19ED5}] => (Allow) LPort=9009
FirewallRules: [{068F7AAE-2D65-4B2C-A4A9-A9EF192CB375}] => (Allow) LPort=9009
FirewallRules: [{61D340F2-C297-4A39-A3A7-BE6F73B6C6D9}] => (Allow) LPort=9009
FirewallRules: [{423B0CF4-96C7-4026-BB7B-39596096F7A0}] => (Allow) LPort=9009
FirewallRules: [{01EDB509-E8DB-4886-8515-28ED85957B46}] => (Allow) LPort=9009
FirewallRules: [{97334B9B-EAFC-4DFB-B5E3-16EB56054F18}] => (Allow) LPort=9009
FirewallRules: [{454BF305-AB66-4CF2-BFAA-3DDED653DE28}] => (Allow) LPort=9009
FirewallRules: [{D05BF4F6-F57A-4CDD-AA8D-64971D7DD3CC}] => (Allow) LPort=9009
FirewallRules: [{C8708FF3-6E51-403B-A5BE-41631FAC3C9F}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{49EB8B54-9145-4A45-9A92-396D3D01034F}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{7D91CDC2-9A56-4546-95EB-EC0F45E7555D}] => (Allow) LPort=9009
FirewallRules: [{B89677EA-6A17-4FA2-9889-9F7DC6CDDF5D}] => (Allow) LPort=9009
FirewallRules: [{4FC6D505-3870-4B49-BF27-83AAE3810E82}] => (Allow) LPort=9009
FirewallRules: [{D6AC4064-7F42-4AA4-BA13-C603C3FC9BAC}] => (Allow) LPort=9009
FirewallRules: [{598B3190-736C-454B-8DB1-2C1A449F02F5}] => (Allow) LPort=9009
FirewallRules: [{A6695D9A-105E-47F1-8AFD-17FB4A011F52}] => (Allow) LPort=9009
FirewallRules: [{97DE20AE-2F3C-4FFC-96B6-FDC1860619E4}] => (Allow) LPort=9009
FirewallRules: [{E3F6870A-FDE7-4C41-ACB1-4A3793B79E20}] => (Allow) LPort=9009
FirewallRules: [{12102B46-5E54-4554-9315-FBCF19AD33AC}] => (Allow) LPort=9009
FirewallRules: [{89D5BE3F-1007-4FA3-92CB-A0F69C73025C}] => (Allow) LPort=9009
FirewallRules: [{A13DCA2F-6934-437E-80D8-712BAD92F45D}] => (Allow) LPort=9009
FirewallRules: [{A52D538A-C25C-40C3-8C71-351EA0E468E7}] => (Allow) LPort=9009
FirewallRules: [{5485F0E7-72A8-4379-A7E6-5A7A14AB88BF}] => (Allow) LPort=9009
FirewallRules: [{88F3C15F-9ADF-40BA-93A5-179F3D995D8D}] => (Allow) LPort=9009
FirewallRules: [{A4A5C7D0-5816-4D53-B51B-AED411CDC7FA}] => (Allow) LPort=9009
FirewallRules: [{07078AD2-1523-4315-A40F-12090CB24596}] => (Allow) LPort=9009
FirewallRules: [{D2EBF676-1DB6-40AC-AAD4-2333CDB98A04}] => (Allow) LPort=9009
FirewallRules: [{2640A6C3-5351-4C79-946C-6015A7B4FB81}] => (Allow) LPort=9009
FirewallRules: [{DE257119-E241-4267-94C2-96DA4E91BDB6}] => (Allow) LPort=9009
FirewallRules: [{F5F34491-209A-4A4F-A7E3-89387404A5E2}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{5CBDD5A2-1A0E-473C-9E45-41BC1AFDF860}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{06CF4F01-54B1-4B32-BB60-4470E277570B}] => (Allow) LPort=9009
FirewallRules: [{97BD67D2-B981-4CBE-84A1-0BD30D3322A1}] => (Allow) LPort=9009
FirewallRules: [{05BBB2D5-2253-45BB-906E-62D533584609}] => (Allow) LPort=9009
FirewallRules: [{3089FDBE-8961-4867-9338-93075021D2D6}] => (Allow) LPort=9009
FirewallRules: [{87E407F6-9EA3-435D-BD0E-165678A5B84A}] => (Allow) LPort=9009
FirewallRules: [{0AA606E6-BB2A-4F50-ADEA-9250E4C4F8AA}] => (Allow) LPort=9009
FirewallRules: [{39E8E625-5C1F-4CFF-933F-D9E34B4C2C95}] => (Allow) LPort=9009
FirewallRules: [UDP Query User{D9321AF2-7139-42C7-8EA2-CFD3D91FD3DD}C:\program files (x86)\flashget network\flashget 3\flashget3.exe] => (Allow) C:\program files (x86)\flashget network\flashget 3\flashget3.exe (Trend Media Corporation Limited -> Trend Media Corporation Limited) [File not signed]
FirewallRules: [TCP Query User{2EB21C9B-D142-4DBE-8DC7-04739A57EA50}C:\program files (x86)\flashget network\flashget 3\flashget3.exe] => (Allow) C:\program files (x86)\flashget network\flashget 3\flashget3.exe (Trend Media Corporation Limited -> Trend Media Corporation Limited) [File not signed]
FirewallRules: [{B5B02BB8-8E66-4BAA-878B-4D2B136EEC10}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{8D2CFE7D-1448-4463-9C8D-3201BD22C4FB}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{02E2C6B5-8A32-4E17-8A66-6F59585BCFC6}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{F0C23BEA-6968-424B-872E-EA58ACC6BBE4}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [UDP Query User{FFC92CA8-77FA-4BB7-BACE-F4C470DF5377}D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds.exe] => (Allow) D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds.exe (LucasArts Entertainment Company LLC) [File not signed]
FirewallRules: [TCP Query User{695FE897-5F87-47AA-9B18-A8AD868F0D0B}D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds.exe] => (Allow) D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds.exe (LucasArts Entertainment Company LLC) [File not signed]
FirewallRules: [UDP Query User{95A99F1D-FC13-436A-AE01-BE3A538C605E}D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds_cc.exe] => (Allow) D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds_cc.exe (LucasArts Entertainment Company LLC) [File not signed]
FirewallRules: [TCP Query User{4EFFD444-9E12-4C80-82E4-9D027274CE52}D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds_cc.exe] => (Allow) D:\steamlibrary\steamapps\common\star wars galactic battlegrounds\game\battlegrounds_cc.exe (LucasArts Entertainment Company LLC) [File not signed]
FirewallRules: [{D27B9FEF-6AA1-4B3D-83D6-5A50FD9E027D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{975B9F0C-34F2-4807-8235-3FA05E571B8B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{2E6B5013-3B08-4123-8DE8-0F55348CB896}] => (Allow) D:\Steam\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{90844D49-8099-45D0-ADB2-093B2C0C0790}] => (Allow) D:\Steam\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [UDP Query User{1E1070B2-C9BA-4840-9CA6-A838B7EFCC75}D:\steamlibrary\steamapps\common\flatout ultimate carnage\fouc.exe] => (Allow) D:\steamlibrary\steamapps\common\flatout ultimate carnage\fouc.exe (Bugbear Entertainment Ltd. -> Empire Interactive Ltd.) [File not signed]
FirewallRules: [TCP Query User{441034C7-4B64-4BB9-8704-8FB0DE3A3369}D:\steamlibrary\steamapps\common\flatout ultimate carnage\fouc.exe] => (Allow) D:\steamlibrary\steamapps\common\flatout ultimate carnage\fouc.exe (Bugbear Entertainment Ltd. -> Empire Interactive Ltd.) [File not signed]
FirewallRules: [{2996FFA0-3DF1-477A-8C6C-9C63A65236E9}] => (Allow) D:\SteamLibrary\SteamApps\common\Flatout 3\Flatout.exe (Team6 game studios BV) [File not signed]
FirewallRules: [{85C07506-95E1-4D14-9CDD-796D4003498B}] => (Allow) D:\SteamLibrary\SteamApps\common\Flatout 3\Flatout.exe (Team6 game studios BV) [File not signed]
FirewallRules: [{CB18413E-104B-4378-9FD0-22EED4691FCA}] => (Allow) D:\Program Files (x86)\Origin\SteamWorld Dig\SteamWorldDig.exe (Electronic Arts -> )
FirewallRules: [{A7FD9469-8662-4FCD-A161-5B937F589CCE}] => (Allow) D:\Program Files (x86)\Origin\SteamWorld Dig\SteamWorldDig.exe (Electronic Arts -> )
FirewallRules: [{4F94F62D-D909-4ED8-9308-AED394E1B9B1}] => (Allow) C:\Program Files (x86)\BlueStacks\HD-Player.exe (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
FirewallRules: [{624706B7-535B-4E26-B9F5-0FE56A2C3B45}] => (Allow) D:\SteamLibrary\SteamApps\common\Grand Theft Auto San Andreas\gta-sa.exe () [File not signed]
FirewallRules: [{B012CED4-B315-4DA6-93BA-645030D5D16D}] => (Allow) D:\SteamLibrary\SteamApps\common\Grand Theft Auto San Andreas\gta-sa.exe () [File not signed]
FirewallRules: [{5C5FAEC8-000A-4B3C-BF19-229E9941E841}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed\NFS16_trial.exe (Electronic Arts -> Electronic Arts)
FirewallRules: [{B6B14B0B-E26C-444A-BB41-777C4729FAA9}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed\NFS16_trial.exe (Electronic Arts -> Electronic Arts)
FirewallRules: [{A6F8947A-D2AC-4BCD-BD33-9EA8813318A7}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed\NFS16.exe (Electronic Arts -> Electronic Arts)
FirewallRules: [{EC855C0C-07E6-452E-96FA-61CCDEC869FD}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed\NFS16.exe (Electronic Arts -> Electronic Arts)
FirewallRules: [{FD7BFEA4-07AF-42B0-9883-E969239CA464}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{479D637E-A295-4AD2-B003-00075D4A2C96}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{2A8985D1-F228-4EAA-BED5-ECE6AE573FF3}] => (Allow) C:\Users\dwood\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{37B5F9C3-383A-4AC2-8270-E235B8B337DE}] => (Allow) C:\Users\dwood\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{E57CD094-DEAA-45B2-B50C-72A28EF99135}] => (Allow) C:\Users\dwood\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{C147C1B8-E7D0-4E22-B0BA-094E817ABD76}] => (Allow) C:\Users\dwood\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{E19861F9-B83A-4ED2-BD4B-12524BB37BBD}] => (Allow) C:\Users\dwood\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{19AD537C-A82F-49E4-A7F0-7C5FEE1DC984}] => (Allow) C:\Users\dwood\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{51DB36AD-DC6A-4247-B133-959F39AE0867}] => (Allow) C:\Program Files (x86)\Anvsoft\Syncios\pdt_syncios.exe (Anvsoft Inc. -> Syncios Data Transfer)
FirewallRules: [{31F4C671-EE2D-48C1-86D9-A524040BB2E9}] => (Allow) C:\Program Files (x86)\Anvsoft\Syncios\pdt_syncios.exe (Anvsoft Inc. -> Syncios Data Transfer)
FirewallRules: [{4A4EB547-17CF-4F09-B73D-71BAD0E51865}] => (Allow) C:\Program Files (x86)\Anvsoft\Syncios\pdt_syncios.exe (Anvsoft Inc. -> Syncios Data Transfer)
FirewallRules: [{6E686547-BD4F-47A4-8C21-995C194DE9D3}] => (Allow) C:\Windows\syswow64\PnkBstrA.exe (Even Balance, Inc. -> )
FirewallRules: [{46A7EA32-BEE5-4B8A-A376-45055911DC1B}] => (Allow) C:\Windows\syswow64\PnkBstrA.exe (Even Balance, Inc. -> )
FirewallRules: [{5EABAF6B-ACD9-4A06-AE14-9E180B97A1F5}] => (Allow) C:\Windows\syswow64\PnkBstrB.exe (Even Balance, Inc. -> )
FirewallRules: [{1EC1C6F3-A840-41BF-ABD0-2E448490E5D9}] => (Allow) C:\Windows\syswow64\PnkBstrB.exe (Even Balance, Inc. -> )
FirewallRules: [{B4587315-DC13-4A12-B474-D06CD5EE7424}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe (Electronic Sports Network i Sverige AB -> ESN Social Software AB)
FirewallRules: [{9E67514A-9DF4-4734-9BBF-91B78FD8F4B1}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe (Electronic Sports Network i Sverige AB -> ESN Social Software AB)
FirewallRules: [{6F76426B-59D7-44D9-B129-0A0D1FA2B9FD}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher.exe (Electronic Arts -> EA Digital Illusions CE AB)
FirewallRules: [{DDA189CC-5B8C-472F-B6CF-815156A1BB3E}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher.exe (Electronic Arts -> EA Digital Illusions CE AB)
FirewallRules: [{91D6110B-E635-4AB8-A2E6-A114EC2A8AAC}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher_x86.exe (Electronic Arts -> EA Digital Illusions CE AB)
FirewallRules: [{4D8B6662-2BB8-4EDB-80AE-7EE3C54B4379}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher_x86.exe (Electronic Arts -> EA Digital Illusions CE AB)
FirewallRules: [TCP Query User{6CD5EA33-0640-4015-BDB0-30D9FD18D2D0}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{37593F83-747D-4FFB-9A4B-398D3C33CA22}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [TCP Query User{E4BB69D1-8E2E-4DBB-A9DB-D9B5B0A7AC3B}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe (Electronic Arts -> EA Digital Illusions CE AB)
FirewallRules: [UDP Query User{A5098847-CFE7-4D4E-8729-23FE0EE02B46}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe (Electronic Arts -> EA Digital Illusions CE AB)
FirewallRules: [{213F78AA-6EEC-4342-9DCA-FC1A0DAC4AC5}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed™ Most Wanted\NFS13.exe (Electronic Arts -> Electronic Arts)
FirewallRules: [{9AE57606-34FF-423B-AFCB-B851F3F2E8AF}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed™ Most Wanted\NFS13.exe (Electronic Arts -> Electronic Arts)
FirewallRules: [{BB3BA66D-7C1A-4553-A9CB-3FE547758206}] => (Allow) LPort=50248
FirewallRules: [{F459FBDD-2874-44CE-9E31-B23FB54CA143}] => (Allow) D:\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{ACD65D66-2B9D-460F-8004-C61D3959D59E}] => (Allow) D:\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [TCP Query User{FA4D096F-7700-471D-B7E9-882BBF9AF9CB}D:\steam\steamapps\common\far cry 2\bin\farcry2.exe] => (Allow) D:\steam\steamapps\common\far cry 2\bin\farcry2.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [UDP Query User{AF957787-0382-4923-8263-E29F3F3CD239}D:\steam\steamapps\common\far cry 2\bin\farcry2.exe] => (Allow) D:\steam\steamapps\common\far cry 2\bin\farcry2.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{5386BF87-3559-465B-999C-ACC13EA7D1FF}] => (Allow) D:\SteamLibrary\SteamApps\common\Grand Theft Auto V\GTAVLauncher.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{523FF6C9-4479-4CB3-9EAE-9D30062C2F24}] => (Allow) D:\SteamLibrary\SteamApps\common\Grand Theft Auto V\GTAVLauncher.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{D6C78A5E-16A2-4E36-929D-690C55A71B7E}] => (Allow) D:\Steam\steamapps\common\Sniper Elite 4\Launcher\SniperElite4.exe () [File not signed]
FirewallRules: [{2FA3990F-16C8-48AA-B3D0-0D2D209E77E5}] => (Allow) D:\Steam\steamapps\common\Sniper Elite 4\Launcher\SniperElite4.exe () [File not signed]
FirewallRules: [{10F1015B-3A2B-4E5A-BDA6-9C49DCA4BAD1}] => (Allow) D:\Steam\steamapps\common\Age of Mythology\Launcher.exe (TODO: <Company name>) [File not signed]
FirewallRules: [{BC66D7EE-9381-44BC-BA5E-3F1751DE8E5D}] => (Allow) D:\Steam\steamapps\common\Age of Mythology\Launcher.exe (TODO: <Company name>) [File not signed]
FirewallRules: [{66BE07BF-C200-4242-BB29-AE1259D122E8}] => (Allow) D:\Steam\steamapps\common\Age of Mythology\aomx.exe (Microsoft Corp) [File not signed]
FirewallRules: [{7B96EA1B-71FE-464F-B125-2F200518E9C2}] => (Allow) D:\Steam\steamapps\common\Age of Mythology\aomx.exe (Microsoft Corp) [File not signed]
FirewallRules: [{95830A98-D836-4DAC-8E30-FBADED4A2E0E}] => (Allow) D:\SteamLibrary\SteamApps\common\Rise of Nations\patriots.exe (TODO: <Company name>) [File not signed]
FirewallRules: [{F2FDDD48-3DF4-4417-B634-757CA3FBB77E}] => (Allow) D:\SteamLibrary\SteamApps\common\Rise of Nations\patriots.exe (TODO: <Company name>) [File not signed]
FirewallRules: [TCP Query User{F97AF342-EFBB-4D7D-9D76-F36DD4F24F6B}D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [UDP Query User{92517F90-6A1C-430A-864B-5A0FF64478B0}D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{AD6B8710-6FD0-4FC4-BF03-FFEC500DD085}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{F6D3A249-B710-4DC5-BC7F-4269053B4B6F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8765AF8D-6E28-42B8-BD36-24FB3E5A5CB8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{A295A1E4-9604-4B21-94C5-11FCAD1E7B46}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{6A4ECA0D-F641-4B68-8D1F-01FC7184560D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [TCP Query User{E356EFD5-59D1-457A-8922-8F130883E82C}D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [UDP Query User{99BD4557-D0D5-4554-8DA1-0D49D7FF179A}D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [TCP Query User{D252723A-6CAF-4CD1-A66A-59AEDE6B0D37}D:\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe] => (Allow) D:\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [UDP Query User{BE069470-5660-454C-9A5B-1AF069E72558}D:\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe] => (Allow) D:\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [TCP Query User{67026037-DBA0-47A3-8035-EE179219C111}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{820B181E-D0B1-43FC-A054-D341ABB718B3}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{224210E3-CA5B-4EE0-93DA-755A11B623F0}D:\steamlibrary\steamapps\common\dawn of war gold\w40k.exe] => (Allow) D:\steamlibrary\steamapps\common\dawn of war gold\w40k.exe (Relic Entertainment, Inc. -> Sega Corporation)
FirewallRules: [UDP Query User{95C37CDF-85DE-4FA9-ACB1-3D57CDEAD6D6}D:\steamlibrary\steamapps\common\dawn of war gold\w40k.exe] => (Allow) D:\steamlibrary\steamapps\common\dawn of war gold\w40k.exe (Relic Entertainment, Inc. -> Sega Corporation)
FirewallRules: [TCP Query User{2D2A283E-098D-424C-89D5-0BF6C3CC9A13}D:\games\stwars_galactic_battlegrounds\swbg\game\battlegrounds.exe] => (Allow) D:\games\stwars_galactic_battlegrounds\swbg\game\battlegrounds.exe (LucasArts Entertainment Company LLC) [File not signed]
FirewallRules: [UDP Query User{C05936E7-ADE5-46D2-B4E4-814211CB48E3}D:\games\stwars_galactic_battlegrounds\swbg\game\battlegrounds.exe] => (Allow) D:\games\stwars_galactic_battlegrounds\swbg\game\battlegrounds.exe (LucasArts Entertainment Company LLC) [File not signed]
FirewallRules: [{7A212D24-B676-4B06-AEFC-0AF38094A541}] => (Allow) D:\SteamLibrary\SteamApps\common\Oddworld New n Tasty\NNT.exe () [File not signed]
FirewallRules: [{AF3B4A3D-C631-48ED-AACC-B619575A260C}] => (Allow) D:\SteamLibrary\SteamApps\common\Oddworld New n Tasty\NNT.exe () [File not signed]
FirewallRules: [{D1FCAA2C-EFF0-4CDB-8421-AB14D7DF49FF}] => (Allow) D:\SteamLibrary\SteamApps\common\Uno\UNO.exe (Chengdu Ubisoft Software Co., Ltd. -> )
FirewallRules: [{754CDC91-0B90-42FA-AFDD-82571D6D9733}] => (Allow) D:\SteamLibrary\SteamApps\common\Uno\UNO.exe (Chengdu Ubisoft Software Co., Ltd. -> )
FirewallRules: [{12816907-ABC0-4B10-A462-A8EA74BE78F6}] => (Allow) D:\Ubisoft\install\Far Cry 5\bin\FarCry5.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{0B9BE760-3853-4F38-BF12-4C63C79C569F}] => (Allow) D:\Ubisoft\install\Far Cry 5\bin\ArcadeEditor64.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{685FDE27-19D4-4E8F-BE19-006A173BCE15}] => (Allow) D:\Ubisoft\install\Far Cry 5\bin\FarCry5.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{DE6441CB-9448-4E90-A20A-E541E92F0F2F}] => (Allow) D:\Ubisoft\install\Far Cry 5\bin\ArcadeEditor64.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{C0E74FCE-4608-4B94-9166-A0CAA133600E}] => (Allow) D:\SteamLibrary\SteamApps\common\Grand Theft Auto IV Episodes from Liberty City\EFLC\LaunchEFLC.exe (Sony DADC Austria AG -> Sony DADC Austria AG)
FirewallRules: [{930B391C-3956-40B7-B522-E386A2A58B66}] => (Allow) D:\SteamLibrary\SteamApps\common\Grand Theft Auto IV Episodes from Liberty City\EFLC\LaunchEFLC.exe (Sony DADC Austria AG -> Sony DADC Austria AG)
FirewallRules: [{106A8F65-0547-4948-B911-55AD76FDD47D}] => (Allow) LPort=9009
FirewallRules: [{F3E1F6FA-ED36-4343-83FE-9388B1516883}] => (Allow) LPort=9009
FirewallRules: [{21B0FB2E-D2B9-4428-89A0-40E8DEC0C99C}] => (Allow) LPort=9009
FirewallRules: [{062F04D0-F5B5-4D1C-8F6C-68496045E169}] => (Allow) LPort=9009
FirewallRules: [{FCF72B03-4C61-4F9C-AEDF-37A589E95790}] => (Allow) LPort=9009
FirewallRules: [{BF8D1E8C-3931-4C2F-9434-A8F28AD14480}] => (Allow) LPort=9009
FirewallRules: [{AE9E4B80-107D-4417-98F6-D2BCA58BBAE2}] => (Allow) D:\Program Files (x86)\Origin\Bejeweled 3\Bejeweled3.exe (PopCap Games -> )
FirewallRules: [{6E625C12-96B0-4F53-82D3-E08C6064AA0B}] => (Allow) D:\Program Files (x86)\Origin\Bejeweled 3\Bejeweled3.exe (PopCap Games -> )
FirewallRules: [{63527361-C968-48F7-96E5-3B017CF66B8B}] => (Allow) LPort=9009
FirewallRules: [{D8453B3B-3A1B-4820-93FF-6FB0F3A29370}] => (Allow) LPort=9009
FirewallRules: [{EE3B23C6-25DD-4712-B93D-5AB48D4F213A}] => (Allow) D:\Steam\steamapps\common\Far Cry 4\bin\FarCry4.exe (Ubisoft Entertainment -> Ubisoft Entertainment)
FirewallRules: [{BE7D436D-AA39-4912-B6BF-29CB2FB2C901}] => (Allow) D:\Steam\steamapps\common\Far Cry 4\bin\FarCry4.exe (Ubisoft Entertainment -> Ubisoft Entertainment)
FirewallRules: [{664EB601-BC49-4CBA-932D-1DFEF785C70B}] => (Allow) LPort=9009
FirewallRules: [{09979A42-1C69-4C8F-947E-68EE5D693C8D}] => (Allow) LPort=9009
FirewallRules: [{AA5726AC-9950-44B2-8EA8-4E8E878D2E5C}] => (Allow) LPort=9009
FirewallRules: [{FF4B76D2-D674-4C44-BD56-9CFCEB270E0C}] => (Allow) LPort=9009
FirewallRules: [{F7F67411-E5C1-4D2A-ABF1-01769A15792C}] => (Allow) LPort=9009
FirewallRules: [{202DB30B-DFD4-4CE2-9B9D-F8734DAB0432}] => (Allow) LPort=9009
FirewallRules: [{6DBD737B-8A97-4526-B19F-FE834909344C}] => (Allow) LPort=9009
FirewallRules: [{3CC0C46D-F393-4BB3-A376-0DAB8423E938}] => (Allow) LPort=9009
FirewallRules: [{A3C282C9-A7ED-4C95-A796-2CF857E46F16}] => (Allow) LPort=9009
FirewallRules: [{3327EF71-9E77-4982-BA0B-1D6876F966F8}] => (Allow) LPort=9009
FirewallRules: [{66D9077C-F4A4-49AF-B789-9A2D7FDB9A57}] => (Allow) LPort=9009
FirewallRules: [{AB1890B4-F421-4C1E-B5C0-D6C3F832398A}] => (Allow) LPort=9009
FirewallRules: [{E5C5A568-072B-494A-B6A0-D72C344DBF38}] => (Allow) LPort=9009
FirewallRules: [{5E24CC43-C161-4B94-8643-F43869FE9F1D}] => (Allow) LPort=9009
FirewallRules: [{9340C616-36B7-4D56-9869-08A09E664746}] => (Allow) LPort=9009
FirewallRules: [{68C6594A-0EC5-4EC5-B9BC-1C3585A970C9}] => (Allow) C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe (MEDIATEK INC. -> Mediatek Inc.) [File not signed]
FirewallRules: [{C47A5926-6049-491D-9D68-0A54CBD793C0}] => (Allow) LPort=9009
FirewallRules: [{FA6FDE82-9792-4E5C-97BF-FCB397A6B06C}] => (Allow) LPort=9009
FirewallRules: [{07BB93FF-150B-4F88-9167-AB6AE1BDE6C1}] => (Allow) LPort=9009
FirewallRules: [{CC0737D6-2769-43E6-AD0E-A0096362DA47}] => (Allow) LPort=9009
FirewallRules: [{F6021DE8-39D1-418D-A8E8-4DA217A58A86}] => (Allow) LPort=9009
FirewallRules: [{DE1CEF04-A1AF-4F01-A0C1-97DCAE0E5D9C}] => (Allow) LPort=9009
FirewallRules: [{C608E83F-5881-4A19-BF95-AEECC070223A}] => (Allow) LPort=9009
FirewallRules: [{6575E370-DDEA-4BB7-B5DE-69501197EB7B}] => (Allow) LPort=9009
FirewallRules: [{A3182DE1-BA09-41F3-937A-73F7E136D483}] => (Allow) LPort=9009
FirewallRules: [{505D5A7A-3503-4117-857B-C30142FED739}] => (Allow) LPort=9009
FirewallRules: [{A703EC4F-571A-4618-93AB-77F4B7454F0D}] => (Allow) LPort=9009
FirewallRules: [{A69A6F74-FEF1-4977-B634-5A1D4FC1C028}] => (Allow) LPort=9009
FirewallRules: [{ECFC6BCC-BE3A-41AA-A6A1-86A7A21334CE}] => (Allow) LPort=9009
FirewallRules: [{9ECD473C-531E-4C23-9F20-05BB9AF012A1}] => (Allow) LPort=9009
FirewallRules: [{6F150060-1CE2-4630-AAD3-A4223A11BAE2}] => (Allow) LPort=9009
FirewallRules: [{E131A436-3542-49CD-84C4-38C52B9D32A0}] => (Allow) LPort=9009
FirewallRules: [{53A6D370-F93F-4BAB-AE6F-2471F3DCE4E8}] => (Allow) LPort=9009
FirewallRules: [{09B56FEA-D6AA-4A51-A135-3C710226C88C}] => (Allow) LPort=9009
FirewallRules: [{D90A79C2-F9D2-41E6-841A-F7E5123A12B6}] => (Allow) LPort=9009
FirewallRules: [{CAF90FE0-4E3F-4B5D-8B2C-8435AEDD34B5}] => (Allow) LPort=9009
FirewallRules: [TCP Query User{BDF79671-8E40-4D9D-8B5F-0D370D7CE368}C:\program files\plex\plex\plex.exe] => (Allow) C:\program files\plex\plex\plex.exe (Plex, Inc. -> )
FirewallRules: [UDP Query User{8F4B7C34-83F8-4D48-B96C-77BEBF9A8142}C:\program files\plex\plex\plex.exe] => (Allow) C:\program files\plex\plex\plex.exe (Plex, Inc. -> )
FirewallRules: [TCP Query User{D7C92FCA-A8C5-4F88-8526-25F5C37D95C9}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{4844555F-3E51-4E8A-9FD5-602BAA9CC055}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{5541D9C0-A51B-462A-959C-308A8A008695}] => (Allow) LPort=9009
FirewallRules: [{91BE62D9-F18A-4DAC-AE16-05C352FC197D}] => (Allow) LPort=9009
FirewallRules: [{9E81F9E7-9BD6-4484-B78E-C8D3816D9EED}] => (Allow) LPort=9009
FirewallRules: [{C5B73566-3209-473E-BA89-5CBB4A22CD11}] => (Allow) D:\SteamLibrary\SteamApps\common\Sega Classics\SEGAGameRoom.exe () [File not signed]
FirewallRules: [{98EA3258-6F0E-4D75-9B06-D4B96BCB420B}] => (Allow) D:\SteamLibrary\SteamApps\common\Sega Classics\SEGAGameRoom.exe () [File not signed]
FirewallRules: [{ECEEF424-4301-46C3-AA1F-81B833084532}] => (Allow) D:\SteamLibrary\SteamApps\common\Sega Classics\SEGAGenesisClassics.exe (Sega Europe Limited -> )
FirewallRules: [{281F4330-0588-4193-B7FD-84B114A51167}] => (Allow) D:\SteamLibrary\SteamApps\common\Sega Classics\SEGAGenesisClassics.exe (Sega Europe Limited -> )
FirewallRules: [TCP Query User{2385E49D-DA27-4B70-9EF6-807926975B73}D:\steam\steamapps\common\far cry 2\bin\farcry2.exe] => (Allow) D:\steam\steamapps\common\far cry 2\bin\farcry2.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [UDP Query User{C3BD20A4-B3E2-4120-86E6-BE05B4C2B7DF}D:\steam\steamapps\common\far cry 2\bin\farcry2.exe] => (Allow) D:\steam\steamapps\common\far cry 2\bin\farcry2.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [TCP Query User{84BF82CA-ED4A-4C7A-BB50-426FD063ED4A}D:\steamlibrary\steamapps\common\grand theft auto\wino\grand theft auto.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto\wino\grand theft auto.exe (DMA Design Ltd.) [File not signed]
FirewallRules: [UDP Query User{3F4D8C82-4C3A-479A-8460-025E095BFC50}D:\steamlibrary\steamapps\common\grand theft auto\wino\grand theft auto.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto\wino\grand theft auto.exe (DMA Design Ltd.) [File not signed]
FirewallRules: [{B9838D2F-D14F-40FA-A999-533D258C16C2}] => (Allow) LPort=9009
FirewallRules: [{9009F33B-91EE-45C5-AFC3-BCD9340D06E7}] => (Allow) LPort=9009
FirewallRules: [{0784CA6A-C793-4688-9C2E-76DE297DBD06}] => (Allow) LPort=9009
FirewallRules: [{ACC04273-BC60-4D77-A75C-C57B2C72689C}] => (Allow) LPort=9009
FirewallRules: [{D918CBAA-41B8-4C30-B4FB-D29B140E9C6D}] => (Allow) LPort=9009
FirewallRules: [{FD21BA82-E2DD-42BE-A35C-A56FF93A716D}] => (Allow) LPort=9009
FirewallRules: [{4FE5B7A0-1908-442D-92A6-9C81DEFDFAA7}] => (Allow) LPort=9009
FirewallRules: [{31B26DF3-3D8D-4D75-896E-CD56C68BE846}] => (Allow) LPort=9009
FirewallRules: [{6688CF35-E71F-4CB7-9A23-55D8DDAF0A63}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{8C9522D5-5E90-418B-B1E9-7102946F6549}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{C3C3BE00-125F-45FE-AD39-E99BAEE9033A}] => (Allow) LPort=9009
FirewallRules: [{CEDA819C-E3C6-484F-807C-BB32E9312CFF}] => (Allow) LPort=9009
FirewallRules: [{11F07976-C223-4985-B343-DE32D494A14F}] => (Allow) LPort=9009
FirewallRules: [{2D0EE629-1959-446C-BD9F-ED143D013D98}] => (Allow) LPort=9009
FirewallRules: [{C2DA90A1-D26F-4AA6-81FA-79A4579E6C8A}] => (Allow) LPort=9009
FirewallRules: [{C6A3E1C5-C90A-41C7-A287-3FFF7DC25EDC}] => (Allow) LPort=9009
FirewallRules: [{6DBBA4DB-971E-463B-B673-426EA043350D}] => (Allow) LPort=9009
FirewallRules: [{258A4F77-294F-4A9B-9B2F-3283D05759D6}] => (Allow) LPort=9009
FirewallRules: [{B460A4F4-C619-4899-8F6C-1116404C63F9}] => (Allow) LPort=9009
FirewallRules: [TCP Query User{AF432A47-1105-4D1D-AE7B-D5700640667B}D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe] => (Allow) D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [UDP Query User{1F7DF507-5ED5-458D-8114-04A8BF250307}D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe] => (Allow) D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{48142F12-C777-437B-AEAB-FFFDE38174F2}] => (Allow) LPort=9009
FirewallRules: [{40F2B139-EDF6-42C2-93EE-043FFFE323C4}] => (Allow) LPort=9009
FirewallRules: [{95D2C131-F435-4F21-9EE4-646F23030434}] => (Allow) LPort=9009
FirewallRules: [{AE0C8DB3-AA9C-4D6C-A8D0-186A7613F4DC}] => (Allow) LPort=9009
FirewallRules: [{AB018890-DD8C-4148-AC61-FAA521941315}] => (Allow) LPort=9009
FirewallRules: [{DE536797-8DB9-4BF0-B3F4-5EEAF707EAA0}] => (Allow) LPort=9009
FirewallRules: [{9F4583F6-DF3E-4616-B114-3295EBF9B707}] => (Allow) LPort=9009
FirewallRules: [{91C0FA73-7CE2-4CD0-8C1A-D22CD087236B}] => (Allow) LPort=9009
FirewallRules: [{8959EEB6-E643-431E-AC38-DCC1769F5FFD}] => (Allow) LPort=9009
FirewallRules: [{06333E4C-7E8C-4B69-A32D-9D606A9C2B84}] => (Allow) LPort=9009
FirewallRules: [{497DCBEE-D94F-4025-91D2-F246B03F4FB8}] => (Allow) LPort=9009
FirewallRules: [{3AE61E59-1D2C-4E45-9CF2-4A314A5BA242}] => (Allow) LPort=9009
FirewallRules: [{B06A7B1E-D6EE-403C-920E-9F1BD884C054}] => (Allow) LPort=9009
FirewallRules: [{5431D0DC-00DF-4A74-9A95-507A0C1A82AE}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{EEA46FDA-803E-496F-A91D-7AB5F2E12C5B}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{E3C03698-3C95-43C8-80C5-A09876CC8A75}] => (Allow) LPort=9009
FirewallRules: [{6D9EFE6F-4CB6-4D70-9AE6-ED6108786A4D}] => (Allow) LPort=9009
FirewallRules: [{F4972331-E4E5-4BC1-96EE-AB5D647B9932}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{194AB5F1-09B6-45C5-BD56-04C2CB5385A3}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{E999EC74-9364-4C5D-B586-E1642E6C2F8E}] => (Allow) LPort=9009
FirewallRules: [{34330F52-69B7-45D1-B7BD-746590C98C95}] => (Allow) LPort=8308
FirewallRules: [{C4ECB01D-08BF-46D2-9DA6-D934530DF4D9}] => (Allow) LPort=9009
FirewallRules: [{2456B859-58F8-434D-885F-CB9596641B3C}] => (Allow) LPort=9009
FirewallRules: [{29AD7700-3F17-4CBC-A851-81879B9E7C58}] => (Allow) LPort=9009
FirewallRules: [{B3760B03-B0B6-48D5-9F8A-46644929CAC7}] => (Allow) LPort=9009
FirewallRules: [{7CBE3FE2-3C96-44A5-AC8D-1D9F19A71FC9}] => (Allow) LPort=9009
FirewallRules: [{C7B717BA-2026-4F97-8489-9117E16E9205}] => (Allow) LPort=9009
FirewallRules: [{E6043F36-CD59-4F0D-B48B-791999E45C02}] => (Allow) LPort=9009
FirewallRules: [{4D6418EA-8899-4A07-893A-C529CD1980D8}] => (Allow) LPort=9009
FirewallRules: [{3669FEA2-5053-44B7-968B-4907EF581C69}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{5332B84E-7E5A-4C18-91C2-83E4026B2E81}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{88CE02DF-B3FC-441B-9C6E-EC47827A6E96}] => (Allow) LPort=9009
FirewallRules: [{154B403F-FF0C-402E-8C00-5C0A1BDF6FAB}] => (Allow) LPort=9009
FirewallRules: [{69C87564-EB86-492C-9B73-1C7C5419C454}] => (Allow) LPort=9009
FirewallRules: [{096069A7-2E3F-42D0-A531-A2F07A27B471}] => (Allow) LPort=9009
FirewallRules: [{FABE5B2E-223B-417E-A72F-83FB4106863A}] => (Allow) LPort=9009
FirewallRules: [{52EF7017-87E9-4A8C-B58C-4BF4C352B706}] => (Allow) LPort=9009
FirewallRules: [{2ABC1036-29EF-42E6-BDD7-397FCD79DD01}] => (Allow) LPort=9009
FirewallRules: [{B4881A9E-8700-4AAA-89D3-19C2EF1A5E09}] => (Allow) LPort=9009
FirewallRules: [{27F12937-3AF4-41E4-96B1-B7B6761D86EB}] => (Allow) LPort=9009
FirewallRules: [TCP Query User{C3D9CA87-3E0C-4E06-9775-EA4A04F02A7E}D:\steamlibrary\steamapps\common\dawn of war gold\w40kwa.exe] => (Allow) D:\steamlibrary\steamapps\common\dawn of war gold\w40kwa.exe (Relic Entertainment, Inc. -> Sega Corporation)
FirewallRules: [UDP Query User{2C7BC1B5-B37C-4F05-ADF9-6471568E771B}D:\steamlibrary\steamapps\common\dawn of war gold\w40kwa.exe] => (Allow) D:\steamlibrary\steamapps\common\dawn of war gold\w40kwa.exe (Relic Entertainment, Inc. -> Sega Corporation)
FirewallRules: [{C377BD1D-9D79-4B7F-A1E3-7FF4E497D1B9}] => (Allow) LPort=9009
FirewallRules: [{2E423B15-05D1-45E0-9F53-4B2F7D7F5392}] => (Allow) LPort=9009
FirewallRules: [TCP Query User{8933A670-1AF9-4AE3-BF17-56487098027D}D:\steamlibrary\steamapps\common\dawn of war gold\w40kwa.exe] => (Allow) D:\steamlibrary\steamapps\common\dawn of war gold\w40kwa.exe (Relic Entertainment, Inc. -> Sega Corporation)
FirewallRules: [UDP Query User{0B04E4B0-0F9D-44FF-B53F-A08C10450DD0}D:\steamlibrary\steamapps\common\dawn of war gold\w40kwa.exe] => (Allow) D:\steamlibrary\steamapps\common\dawn of war gold\w40kwa.exe (Relic Entertainment, Inc. -> Sega Corporation)
FirewallRules: [{73630298-05AB-406E-93AD-9FB7E472600E}] => (Allow) LPort=9009
FirewallRules: [TCP Query User{4AFD7E35-0785-49ED-8536-AEF8585C852C}D:\games\age of empires ii definitive edition dawn of the dukes\aoe2de_s.exe] => (Allow) D:\games\age of empires ii definitive edition dawn of the dukes\aoe2de_s.exe (Microsoft Corporation) [File not signed]
FirewallRules: [UDP Query User{6E2907FE-B11D-4A41-8878-BD569C438D3C}D:\games\age of empires ii definitive edition dawn of the dukes\aoe2de_s.exe] => (Allow) D:\games\age of empires ii definitive edition dawn of the dukes\aoe2de_s.exe (Microsoft Corporation) [File not signed]
FirewallRules: [TCP Query User{1458B479-B440-4A84-8285-247CF8FA7FA2}D:\games\age of empires ii definitive edition dawn of the dukes\battleserver\battleserver.exe] => (Allow) D:\games\age of empires ii definitive edition dawn of the dukes\battleserver\battleserver.exe (Microsoft Corporation -> )
FirewallRules: [UDP Query User{B1BF218A-8103-4007-BCAB-3377556C4D05}D:\games\age of empires ii definitive edition dawn of the dukes\battleserver\battleserver.exe] => (Allow) D:\games\age of empires ii definitive edition dawn of the dukes\battleserver\battleserver.exe (Microsoft Corporation -> )
FirewallRules: [{F479E4D2-DF99-4444-B07C-8166BD1CB65A}] => (Allow) LPort=9009
FirewallRules: [TCP Query User{68A05116-A3EF-411C-83C6-267385C7E3AA}D:\games\age of empires ii definitive edition dawn of the dukes\aoe2de_s.exe] => (Allow) D:\games\age of empires ii definitive edition dawn of the dukes\aoe2de_s.exe (Microsoft Corporation) [File not signed]
FirewallRules: [UDP Query User{31BB8360-14C9-4C94-B7C6-A797DE2EB6B9}D:\games\age of empires ii definitive edition dawn of the dukes\aoe2de_s.exe] => (Allow) D:\games\age of empires ii definitive edition dawn of the dukes\aoe2de_s.exe (Microsoft Corporation) [File not signed]
FirewallRules: [TCP Query User{8A50778B-BC7F-4A53-880C-E232C2D2F35D}D:\games\age of empires ii definitive edition dawn of the dukes\battleserver\battleserver.exe] => (Allow) D:\games\age of empires ii definitive edition dawn of the dukes\battleserver\battleserver.exe (Microsoft Corporation -> )
FirewallRules: [UDP Query User{24D3B0C7-D3A1-4135-AB13-BA55D506706B}D:\games\age of empires ii definitive edition dawn of the dukes\battleserver\battleserver.exe] => (Allow) D:\games\age of empires ii definitive edition dawn of the dukes\battleserver\battleserver.exe (Microsoft Corporation -> )
FirewallRules: [{2EB1215C-C89C-430D-B17B-E5FB181E3535}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{6126D1F8-E093-4F4B-B588-9B9C048C89CE}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{A438D64F-13ED-4218-A726-951AFD45FC9C}] => (Allow) LPort=9009
FirewallRules: [{49DAB393-5653-4DE7-8E67-BC7699DD2742}] => (Allow) LPort=9009
FirewallRules: [{0A77D142-25C0-4971-94A8-092F6242C42E}] => (Allow) LPort=9009
FirewallRules: [{D7008EFC-9F6C-453F-95C4-2E6AFF70A3DB}] => (Allow) LPort=9009
FirewallRules: [{31C5A7F6-B787-4CB2-9D80-2A1F47B86802}] => (Allow) LPort=9009
FirewallRules: [{86F2DE10-78CA-4ED7-851D-495391BFCE38}] => (Allow) LPort=8420
FirewallRules: [{7652B2E7-9749-484A-BC37-A379EB2E9CFB}] => (Allow) LPort=9009
FirewallRules: [{414F34B7-7ADF-44A8-89FF-2402378C3900}] => (Allow) LPort=9009
FirewallRules: [{FDE64F0A-F94A-40A0-A329-31C195049103}] => (Allow) LPort=8497
FirewallRules: [{0E571A9B-EB39-4035-8677-A788AD65D8B8}] => (Allow) LPort=9009
FirewallRules: [{8985C739-9C2D-487C-8F6C-0131606D6845}] => (Allow) LPort=9009
FirewallRules: [{F39B4517-D2B5-48A2-864A-7DE2A22162EB}] => (Allow) LPort=8818
FirewallRules: [{1E7F5EC9-8E89-4573-A659-F8476AB5DF74}] => (Allow) LPort=9009
FirewallRules: [{FD50AB1B-4288-42D2-BA42-483EA8516905}] => (Allow) LPort=9009
FirewallRules: [{00544342-A40B-41D9-85FC-54BF221D2DDF}] => (Allow) LPort=9009
FirewallRules: [{33A0CE3A-6F51-4BF7-BD22-9FDD8067A476}] => (Allow) LPort=9009
FirewallRules: [{BF29A85A-3935-42CC-99F7-D5327D0061A4}] => (Allow) LPort=9009
FirewallRules: [{3F132B0F-CB1E-458F-BC74-AA3D41FB203A}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{72C0A1A7-D18D-49F4-9603-86AD9AE023D1}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{1F308D51-00C0-4422-9BE7-719B9B908731}] => (Allow) LPort=9009
FirewallRules: [{A96F0138-052C-4B16-A77E-C075A8873116}] => (Allow) LPort=9009
FirewallRules: [{6A0D78A8-4533-4E8D-8FC9-E9A396C11CAB}] => (Allow) D:\SteamLibrary\SteamApps\common\Red Dead Redemption 2\PlayRDR2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{B3C82001-2BE1-420C-85D5-FB0309445132}] => (Allow) D:\SteamLibrary\SteamApps\common\Red Dead Redemption 2\PlayRDR2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [TCP Query User{9DFC1C8C-A461-46E9-BE6A-4CFDCC7F4C26}D:\steamlibrary\steamapps\common\red dead redemption 2\rdr2.exe] => (Allow) D:\steamlibrary\steamapps\common\red dead redemption 2\rdr2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [UDP Query User{3960ADBB-B319-43AA-A5B0-C04A17E7B7B3}D:\steamlibrary\steamapps\common\red dead redemption 2\rdr2.exe] => (Allow) D:\steamlibrary\steamapps\common\red dead redemption 2\rdr2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{BC59370F-F8C2-44C8-B7EE-8C4DA970CC99}] => (Allow) LPort=9009
FirewallRules: [{4FBCC54E-82B7-4200-B952-FC56CAD7DCBF}] => (Allow) LPort=9009
FirewallRules: [{E944CD00-A55A-4418-B69B-68F9E436CA22}] => (Allow) LPort=9009
FirewallRules: [{B2832507-B3C9-49F0-B3B8-00F40F61A632}] => (Allow) LPort=9009
FirewallRules: [{7D20AF97-4DB4-4E11-84EF-FE8E817DE4E0}] => (Allow) LPort=9009
FirewallRules: [{E8BD18FC-0BCC-49F1-97C5-3F84A045DD9E}] => (Allow) LPort=9009
FirewallRules: [{9BCF3131-200A-4759-A891-68EDB78F90B1}] => (Allow) LPort=9009
FirewallRules: [{580BEA77-7737-414B-9D73-B7B642A0FA56}] => (Allow) LPort=9009
FirewallRules: [{61886196-5108-4664-9169-773A7C3B5C44}] => (Allow) D:\Steam\steamapps\common\Far Cry Primal\bin\FCPrimal.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{DE8851F4-3504-4F4F-B6F2-5E71D7D6DD1E}] => (Allow) D:\Steam\steamapps\common\Far Cry Primal\bin\FCPrimal.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{E671511B-1362-4255-AE07-83B14D61B860}] => (Allow) LPort=9009
FirewallRules: [{F0A33954-B97C-4B92-98C2-64B4B2870292}] => (Allow) LPort=9009
FirewallRules: [{1C9DBC6E-5772-4F55-BA7F-AFD92737405D}] => (Allow) LPort=9009
FirewallRules: [{E38CD87B-7669-4FA5-B25E-7F8AD49B6939}] => (Allow) LPort=9009
FirewallRules: [{E85ABC10-3BAB-4B64-AF48-9C837D454C14}] => (Allow) LPort=9009
FirewallRules: [{9F8982F7-A8E2-47D7-AE82-83DC7B6E999D}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto IV\GTAIV\PlayGTAIV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{80B333B2-26CB-49FC-9758-433AD5B6016B}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto IV\GTAIV\PlayGTAIV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{2AD7C8B1-0731-4774-B8D4-81EFD18EED99}] => (Allow) E:\Program Files\Ubisoft\Ubisoft Game Launcher\Games\Far Cry 6\bin\FarCry6.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{D1F2DE1F-0EBB-4031-8EA8-9DE3ADC4ACC7}] => (Allow) E:\Program Files\Ubisoft\Ubisoft Game Launcher\Games\Far Cry 6\bin\FarCry6.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{3F91A293-9E31-4500-AE95-FD3CA5004658}] => (Allow) E:\Program Files\Ubisoft\Ubisoft Game Launcher\Games\Far Cry 6\bin_plus\FarCry6.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{59CFBBF6-8E58-4F5F-82D2-5021448D1262}] => (Allow) E:\Program Files\Ubisoft\Ubisoft Game Launcher\Games\Far Cry 6\bin_plus\FarCry6.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{E9B47576-FFBC-4D5A-A442-0DC1EF265A4E}] => (Allow) D:\SteamLibrary\SteamApps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{4E36B07B-D8D4-47DC-9D7A-DBCD42823100}] => (Allow) D:\SteamLibrary\SteamApps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{9AE7B06A-EEDF-4205-A027-A7818AEDC8CC}] => (Allow) D:\SteamLibrary\SteamApps\common\raceroom racing experience\Game\x64\RRRE64.exe (Simbin Studios AB) [File not signed]
FirewallRules: [{A5030D99-2B3C-48DA-B44B-9ECFAD316069}] => (Allow) D:\SteamLibrary\SteamApps\common\raceroom racing experience\Game\x64\RRRE64.exe (Simbin Studios AB) [File not signed]
FirewallRules: [{438B1AF1-C0AE-40AD-A969-2B0DF8ABDA98}] => (Allow) D:\SteamLibrary\SteamApps\common\raceroom racing experience\Game\RRRE.exe (Simbin Studios AB) [File not signed]
FirewallRules: [{5757EE4F-BE0C-4B73-B4A7-5C6C037A0134}] => (Allow) D:\SteamLibrary\SteamApps\common\raceroom racing experience\Game\RRRE.exe (Simbin Studios AB) [File not signed]
FirewallRules: [{E45BD843-2CA0-48C4-8711-D7889038E465}] => (Allow) LPort=9009
FirewallRules: [{34ABCBB3-604E-453B-9102-F2D571CA4D0B}] => (Allow) LPort=9009
FirewallRules: [{932E9247-1606-40D7-9F5F-E7807A6E800E}] => (Allow) LPort=9009
FirewallRules: [{51454A78-31B4-4FB5-8A3B-AB802F1C6B47}] => (Allow) LPort=9009
FirewallRules: [{6E817AF6-A363-4262-9436-AA118D902766}] => (Allow) D:\SteamLibrary\SteamApps\common\theHunterCotW\theHunterCotW_F.exe () [File not signed]
FirewallRules: [{3661A096-ADE2-4660-8A58-28E1C7BA2F9A}] => (Allow) D:\SteamLibrary\SteamApps\common\theHunterCotW\theHunterCotW_F.exe () [File not signed]
FirewallRules: [{5D5F3000-7399-42CD-A908-3953FD1BFB90}] => (Allow) LPort=9009
FirewallRules: [{0FA42690-9B36-42EE-B293-4CD6F5297210}] => (Allow) LPort=9009
FirewallRules: [{7CE2F265-9F8D-408C-A316-1969976207E4}] => (Allow) LPort=9009
FirewallRules: [{FA274F7F-E6B0-4FF0-9DEE-92BC4FE4231A}] => (Allow) LPort=9009
FirewallRules: [TCP Query User{B8E3AC1B-D4C6-4DAD-A523-EAF4596C0F07}C:\users\dwood\appdata\roaming\bittorrent\updates\bittorrent.exe] => (Allow) C:\users\dwood\appdata\roaming\bittorrent\updates\bittorrent.exe => No File
FirewallRules: [UDP Query User{93E90EA8-2B2A-45F2-9191-FB6238930F72}C:\users\dwood\appdata\roaming\bittorrent\updates\bittorrent.exe] => (Allow) C:\users\dwood\appdata\roaming\bittorrent\updates\bittorrent.exe => No File
FirewallRules: [{A11A1967-A4DB-40B8-9C98-C3B8C23841F7}] => (Allow) LPort=9009
FirewallRules: [{6525DFC0-CC0C-4039-AD0F-FBD6A90F5D7D}] => (Allow) LPort=9009
FirewallRules: [{E278382F-1AA9-4707-80CC-8778CD0D5A75}] => (Allow) LPort=9009
FirewallRules: [{D68F07E7-0869-4943-8F28-6E05A03F90E5}] => (Allow) LPort=9009
FirewallRules: [{09C74E6A-048B-44AF-AE58-1E930DEB38B1}] => (Allow) LPort=9009
FirewallRules: [{8AE9BBAD-87F8-4CDB-8C35-3300364BFA73}] => (Allow) LPort=9009
FirewallRules: [{0D332F69-90C3-4FE7-A282-33D1B1E01088}] => (Allow) LPort=9009
FirewallRules: [{B59023EA-032E-4815-A5DA-538C6B792CAE}] => (Allow) LPort=9009
FirewallRules: [{A2147567-801D-4183-8F18-59CB3D43078E}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{F1548CC3-7AB5-4681-9680-969F8AC1155C}] => (Allow) D:\SteamLibrary\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{992DE694-DBBA-404C-A965-C40EC1810E7A}] => (Allow) D:\Steam\steamapps\common\Far Cry Primal\bin\FCPrimal.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{9E5A20A4-E4EA-4489-9D7A-912C494E3C2F}] => (Allow) D:\Steam\steamapps\common\Far Cry Primal\bin\FCPrimal.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{73D2AA6C-375F-46D1-8C49-B3CBCE7BD482}] => (Allow) LPort=9009
FirewallRules: [{0C0E1D5C-F0BE-4E36-90E9-1991CDE83A05}] => (Allow) LPort=9009
FirewallRules: [{9E96EC76-D790-46EB-8428-E3C0789621AF}] => (Allow) LPort=9009
FirewallRules: [{7EDC6D30-5D1F-4BE9-BA94-D0FC79434E33}] => (Allow) LPort=9009
FirewallRules: [{75CA5A19-E278-4E7A-B3D1-86471AB37679}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto IV\GTAIV\PlayGTAIV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{F6E5C8D6-0B42-42B5-B215-8939B9DE4827}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto IV\GTAIV\PlayGTAIV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{7E5AC1EF-DDA0-4228-AA7E-0C67CE2AB590}] => (Allow) LPort=9009
FirewallRules: [{4097E10D-ED7C-4154-8A4C-1FC495C88C35}] => (Allow) LPort=9009
FirewallRules: [{882F1889-F196-462E-AFF8-D40FD28A0F9F}] => (Allow) LPort=9009
FirewallRules: [{1DFBEA2B-E8AB-4830-968D-B29CF8FF2EF5}] => (Allow) LPort=9009
FirewallRules: [{9C3D778F-E335-473F-B1BF-DF6F2A72E079}] => (Allow) D:\SteamLibrary\SteamApps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{70283839-D1BD-43E3-9C93-93ED3BF13C99}] => (Allow) D:\SteamLibrary\SteamApps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{B3773C82-B58C-4B23-94C0-7C09B3370670}] => (Allow) D:\SteamLibrary\SteamApps\common\raceroom racing experience\Game\x64\RRRE64.exe (Simbin Studios AB) [File not signed]
FirewallRules: [{6FAB399F-8195-4F2D-8439-7258C3F25DAF}] => (Allow) D:\SteamLibrary\SteamApps\common\raceroom racing experience\Game\x64\RRRE64.exe (Simbin Studios AB) [File not signed]
FirewallRules: [{C68BB392-932A-47B1-8417-73DDA4D95FE3}] => (Allow) D:\SteamLibrary\SteamApps\common\raceroom racing experience\Game\RRRE.exe (Simbin Studios AB) [File not signed]
FirewallRules: [{C96708F2-4968-4D7A-B8FF-2105DF950D00}] => (Allow) D:\SteamLibrary\SteamApps\common\raceroom racing experience\Game\RRRE.exe (Simbin Studios AB) [File not signed]
FirewallRules: [{5CCE08A2-C9AA-45B6-9FA0-97825A6A01FA}] => (Allow) LPort=9009
FirewallRules: [{CEC37F2F-ACF0-4744-8422-022F89E97684}] => (Allow) LPort=9009
FirewallRules: [{3D880E88-7A06-45A6-B9FE-206DD42D363F}] => (Allow) LPort=9009
FirewallRules: [{7DDE7DAF-0F6E-4360-9E3E-FE4887EF8042}] => (Allow) LPort=9009
FirewallRules: [{B766376D-552B-4047-ACD3-1A1013E0D94B}] => (Allow) LPort=9009
FirewallRules: [{A03715E4-3234-4A64-868C-36B5E23A9913}] => (Allow) LPort=9009
FirewallRules: [{32CA802B-0650-4608-91FD-1E27FC4FDF9D}] => (Allow) LPort=9009
FirewallRules: [{350BA0D8-EBCA-4001-B7B3-959B6B78C7F6}] => (Allow) LPort=9009
FirewallRules: [{AF518D54-A0B0-4057-9C0E-B38E3D6B8B46}] => (Allow) LPort=9009
FirewallRules: [{98C55D9E-8EF0-4796-8F35-4BB0F4E6AFD1}] => (Allow) LPort=9009
FirewallRules: [{E60F6DB9-9A8B-41F3-BEAD-C5511B408A2A}] => (Allow) LPort=9009
FirewallRules: [{10964A18-9A7F-47DF-AB46-1C588D6CDFD4}] => (Allow) LPort=9009
FirewallRules: [{4D654533-301D-40A3-8A22-E310C4F69878}] => (Allow) LPort=9009
FirewallRules: [{B5E2BE67-7DA9-4D97-9648-7E3117BC18DF}] => (Allow) LPort=9009
FirewallRules: [{18BF2252-1C87-4FDE-8F6F-B7DEAD622F52}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{54E6E8AF-B4FF-402D-986C-83A0DDD1A82E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{65EA2AF1-69B5-4BDC-9179-A84AFA2B53B9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{3FA9266D-19CA-4B9C-BAB6-070D01C59F02}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{1822FA20-66F7-4B4F-9DF6-1DCF658EA457}] => (Allow) E:\Program Files\EA Games\Zuma's Revenge\ZumasRevenge.exe (Electronic Arts -> PopCap Games, Inc.)
FirewallRules: [{0B8BE4E6-8E45-4528-A679-9944A04A5635}] => (Allow) E:\Program Files\EA Games\Zuma's Revenge\ZumasRevenge.exe (Electronic Arts -> PopCap Games, Inc.)
FirewallRules: [{0086F35A-6D45-4B87-93A1-D48060F67821}] => (Allow) LPort=9009
FirewallRules: [{554B055D-42CC-4125-9565-72A1E3C59DE0}] => (Allow) E:\Program Files\EA Games\Amazing Adventures - The Caribbean Secret\AmazingAdventures3.exe (SpinTop Games) [File not signed]
FirewallRules: [{3B1F5599-09CD-4C4D-B348-065306620BA9}] => (Allow) E:\Program Files\EA Games\Amazing Adventures - The Caribbean Secret\AmazingAdventures3.exe (SpinTop Games) [File not signed]
FirewallRules: [{40FB83D0-60A0-4B3B-9C52-5E23005C966C}] => (Allow) D:\SteamLibrary\SteamApps\common\Jigsaw Puzzles Infinite\Jigsaw.exe (Godot Engine) [File not signed]
FirewallRules: [{B39FA0C6-A351-4B09-91F2-B1E21358EDE5}] => (Allow) D:\SteamLibrary\SteamApps\common\Jigsaw Puzzles Infinite\Jigsaw.exe (Godot Engine) [File not signed]
FirewallRules: [{74F1FC18-C0BB-4CD6-B703-81C1D0205B86}] => (Allow) LPort=9009
FirewallRules: [{23AAD1AF-3DE3-47D9-8BB9-F1BD43000266}] => (Allow) LPort=9009
FirewallRules: [{178A69A7-2E7E-48FF-81D0-2FA0D4F30E90}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F0339AC0-0BD4-42F5-A103-5DD414416EFC}] => (Allow) LPort=9009
FirewallRules: [{92E7F4A2-5E21-4382-9434-277B182B00DB}] => (Allow) LPort=9009
FirewallRules: [{9084BE24-2B16-4B73-B06A-F220E8ACD691}] => (Allow) LPort=9009
FirewallRules: [{5384B916-F87A-4ED5-9D81-4B4555AD5D03}] => (Allow) LPort=9009
FirewallRules: [{BE88EBAE-16E5-4407-AC1B-EA47B2A73F03}] => (Allow) LPort=9009
FirewallRules: [{A18EBB1E-464B-4353-8F77-5CB1B997B1C2}] => (Allow) LPort=9009
FirewallRules: [{7C017353-90B4-4F55-90C5-98C2384E5010}] => (Allow) LPort=9009
FirewallRules: [TCP Query User{B18BE756-7DF6-4662-8052-E7112E0CB9E8}C:\users\dwood\appdata\local\programs\plexamp\plexamp.exe] => (Allow) C:\users\dwood\appdata\local\programs\plexamp\plexamp.exe (Plex, Inc. -> Plex, Inc.)
FirewallRules: [UDP Query User{7AF892A5-CABE-407C-8E16-56753203528C}C:\users\dwood\appdata\local\programs\plexamp\plexamp.exe] => (Allow) C:\users\dwood\appdata\local\programs\plexamp\plexamp.exe (Plex, Inc. -> Plex, Inc.)
FirewallRules: [{B3750E6E-E535-4F8C-B295-037720F35D1A}] => (Allow) D:\SteamLibrary\SteamApps\common\Sniper Elite 5\Launcher\SniperElite5.exe (Rebellion) [File not signed]
FirewallRules: [{995CBA88-6D2A-4452-9CA9-013247748097}] => (Allow) D:\SteamLibrary\SteamApps\common\Sniper Elite 5\Launcher\SniperElite5.exe (Rebellion) [File not signed]
FirewallRules: [{650A2E9C-D796-41FF-9F5E-DBF63CAFA9B8}] => (Allow) LPort=9009
FirewallRules: [{6B91E760-CC31-4F65-B310-567317464966}] => (Allow) LPort=9009
FirewallRules: [{5C572A48-1CD0-477C-87C8-5DC5D1639FA6}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{D7076BD4-8811-455B-B6A2-EE26C981AE75}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{EB7BA754-07C2-4054-9F81-65AFB48CEC5B}] => (Allow) LPort=9009
FirewallRules: [{17155BA2-6B60-4707-947A-F6B27159BA8C}] => (Allow) LPort=9009
FirewallRules: [{012FD3F6-AE66-4E56-A201-C00564907597}] => (Allow) LPort=9009
FirewallRules: [{708C5191-AEDF-4476-8832-5A6DF0CC2F04}] => (Allow) LPort=9009
FirewallRules: [{E9D68B61-D819-4227-92B3-22EA8F9F03DF}] => (Allow) LPort=9009
FirewallRules: [TCP Query User{6564E79F-A745-4B45-AEAD-FFEB2C681FD9}D:\steamlibrary\steamapps\common\excalibur\needforspeedunbound.exe] => (Allow) D:\steamlibrary\steamapps\common\excalibur\needforspeedunbound.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [UDP Query User{0F1B6A5A-F09E-475E-AB3D-C6001C6BE2FC}D:\steamlibrary\steamapps\common\excalibur\needforspeedunbound.exe] => (Allow) D:\steamlibrary\steamapps\common\excalibur\needforspeedunbound.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{1A8E23BF-045E-41C2-B368-2B8E9FFCA91D}] => (Allow) LPort=9009
FirewallRules: [{31C18E53-1371-4FDD-A2B1-DAA68F4D475F}] => (Allow) LPort=9009
FirewallRules: [{27572769-82E5-4AB1-AE3B-E59D11F1E132}] => (Allow) LPort=9009
FirewallRules: [{8A1DCD39-E83A-4436-9823-BB5FC89AD779}] => (Allow) LPort=9009
FirewallRules: [{DA034734-E3AB-48E1-9218-0AB828E748EA}] => (Allow) LPort=9009
FirewallRules: [{10324567-54DD-4296-9A47-CFEB92B43C80}] => (Allow) LPort=9009
FirewallRules: [{4205F8F4-52CE-47D3-A390-130DB4B4D54C}] => (Allow) LPort=9009
FirewallRules: [{3312641C-4BC1-48C9-8ABC-273E4DD50FC9}] => (Allow) LPort=9009
FirewallRules: [{C0705649-6227-4CF8-B469-7AE58417F259}] => (Allow) LPort=9009
FirewallRules: [{FEBA28B8-F001-4391-9698-1AE740F8387C}] => (Allow) LPort=9009
FirewallRules: [{13D66E51-2A31-4428-BBDA-63DBF184205A}] => (Allow) LPort=9009
FirewallRules: [{0CCF90C7-E9A9-4D00-81BC-3E87D7C7D93C}] => (Allow) LPort=9009
FirewallRules: [{BC0638E3-5B10-4CA8-830F-73582B5A709A}] => (Allow) LPort=9009
FirewallRules: [{0B75CE3F-F3E3-42F3-BAD8-CCEB961D28DC}] => (Allow) LPort=9009
FirewallRules: [{A19EA77E-150A-4C87-B013-7E6C4BEF17A6}] => (Allow) LPort=9009
FirewallRules: [{C1A5C09C-4E4D-4D47-972B-511DA6C293B7}] => (Allow) LPort=9009
FirewallRules: [TCP Query User{8DB0D6CD-D0E8-4731-A0F2-40DA2AC15124}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{63D118DE-AB2E-4083-8C9C-D33987647E11}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{7ADE51D5-2F06-4FCF-8292-830C60431A23}] => (Allow) LPort=9009
FirewallRules: [{7A270225-56E1-4F5D-9A0E-8063D6557D91}] => (Allow) LPort=9009
FirewallRules: [{0B13490E-7245-437E-8BFA-C7DEAF88125C}] => (Allow) LPort=9009
FirewallRules: [TCP Query User{DC152CC6-BD1D-4C48-AAA8-EEBB98B9EB92}D:\steamlibrary\steamapps\common\red dead redemption 2\rdr2.exe] => (Allow) D:\steamlibrary\steamapps\common\red dead redemption 2\rdr2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [UDP Query User{2111489F-9521-41E9-855F-7CEDEB481606}D:\steamlibrary\steamapps\common\red dead redemption 2\rdr2.exe] => (Allow) D:\steamlibrary\steamapps\common\red dead redemption 2\rdr2.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{71E7D47C-6DBC-467F-9914-E4B49D831CCF}] => (Allow) LPort=9009
FirewallRules: [{06837D3F-3591-43C9-9B4D-23F0D35E0C32}] => (Allow) LPort=9009
FirewallRules: [{C48F12DD-BBE2-4D2E-821E-EC51BC2562B5}] => (Allow) LPort=9009
FirewallRules: [{FF93B2BA-B20F-49F5-9780-0C0307502510}] => (Allow) LPort=9009
FirewallRules: [{75EE0A53-6ECE-480F-BEE0-42DE6A1CA503}] => (Allow) LPort=9009
FirewallRules: [{A84204CC-ED12-4D0C-9A31-0AC5AA46B746}] => (Allow) E:\Program Files\EA Games\Battlefield V\bfvTrial.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{1463377C-4557-43E4-B68C-98033CF21134}] => (Allow) E:\Program Files\EA Games\Battlefield V\bfvTrial.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{2C1DE3F1-9050-4469-A3EC-ADFDFC60E0F6}] => (Allow) E:\Program Files\EA Games\Battlefield V\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [{1240E706-1686-4092-B47E-509F94FF4A01}] => (Allow) E:\Program Files\EA Games\Battlefield V\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [{8EB4D8DD-F88D-432D-9FA6-1AA231C1A8B9}] => (Allow) E:\Program Files\EA Games\Battlefield 2042\EAAntiCheat.GameServiceLauncher.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{73689E0E-AD4A-431C-80EC-5510318D1927}] => (Allow) E:\Program Files\EA Games\Battlefield 2042\EAAntiCheat.GameServiceLauncher.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{B48BD3BA-B3A9-4B88-A736-2CA825851841}] => (Allow) LPort=9009
FirewallRules: [TCP Query User{0E242AEC-E35E-4E9B-95B4-5CD2F10F1FE3}E:\program files\ea games\battlefield 2042\bf2042.exe] => (Allow) E:\program files\ea games\battlefield 2042\bf2042.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [UDP Query User{1482358D-4667-4A92-AD67-0E63AE2163FA}E:\program files\ea games\battlefield 2042\bf2042.exe] => (Allow) E:\program files\ea games\battlefield 2042\bf2042.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{4EE99F3D-BB05-4B71-B818-62286CA55A04}] => (Allow) D:\SteamLibrary\SteamApps\common\Postal III\p3.exe () [File not signed]
FirewallRules: [{B5214C38-64F4-4460-82DC-2AB9181A23AC}] => (Allow) D:\SteamLibrary\SteamApps\common\Postal III\p3.exe () [File not signed]
FirewallRules: [{FB63DF7C-B803-45D0-A69B-B070E810B5BB}] => (Allow) LPort=9009
FirewallRules: [{F0D443BC-BCA1-4BD8-95CD-4C963689F5C1}] => (Allow) LPort=9009
FirewallRules: [{407B9C41-F538-465A-9168-827B448E9CDF}] => (Allow) E:\Program Files\EA Games\STAR WARS Battlefront II\starwarsbattlefrontii_trial.exe (Electronic Arts, Inc. -> Electronic Arts Inc.)
FirewallRules: [{76333085-7FA7-4C14-88C6-33B88ACCC1E6}] => (Allow) E:\Program Files\EA Games\STAR WARS Battlefront II\starwarsbattlefrontii_trial.exe (Electronic Arts, Inc. -> Electronic Arts Inc.)
FirewallRules: [{D3E2E939-05D6-4FFC-A949-F206C01BDA86}] => (Allow) E:\Program Files\EA Games\STAR WARS Battlefront II\starwarsbattlefrontii.exe (Electronic Arts Inc.) [File not signed]
FirewallRules: [{8CA4F4C6-23FF-496A-9B45-899B45E01DB1}] => (Allow) E:\Program Files\EA Games\STAR WARS Battlefront II\starwarsbattlefrontii.exe (Electronic Arts Inc.) [File not signed]
FirewallRules: [{24049DDC-8190-4D78-AE08-934F1AF2A9B9}] => (Allow) LPort=9009
FirewallRules: [{D3C82825-02F8-471E-82BD-796515DF0ECD}] => (Allow) LPort=9009
FirewallRules: [{3DC574F8-CD5D-46BF-90C2-C77E70127DAD}] => (Allow) LPort=9009
FirewallRules: [{377DB94F-3A0D-43B0-9678-A14A75FCC0C4}] => (Allow) LPort=9009
FirewallRules: [{18DFC876-5F82-4262-BD63-DC12842C0559}] => (Allow) LPort=9009
FirewallRules: [{E77EC6B3-AC00-490E-88F4-CE9BA19EAF0C}] => (Allow) LPort=9009
FirewallRules: [{A81CD87C-FC2E-4F68-906E-7DC6010F63FF}] => (Allow) LPort=9009
FirewallRules: [{3F91AC93-CA0A-4B01-9FDF-BF433D7871EB}] => (Allow) LPort=9009
FirewallRules: [{7CE3FAA4-BF45-4B20-9020-346D6013B46F}] => (Allow) LPort=9009
FirewallRules: [{5E714207-C424-4E4B-BF09-0F6FA43DD762}] => (Allow) E:\Games\Need for Speed Payback\NeedForSpeedPaybackTrial.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{DE7AEB6F-A727-4EC0-B039-B51EE25F488B}] => (Allow) E:\Games\Need for Speed Payback\NeedForSpeedPaybackTrial.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{0D5CDE56-1544-4C2F-86BD-965589CBC240}] => (Allow) E:\Games\Need for Speed Payback\NeedForSpeedPayback.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{C94F6836-B22E-49BC-9F41-7055E779F6A1}] => (Allow) E:\Games\Need for Speed Payback\NeedForSpeedPayback.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{37F117AD-398B-4694-88E5-C137FBE8233E}] => (Allow) LPort=9009
FirewallRules: [TCP Query User{E4D2B943-6883-4168-AC26-E01052E0344F}E:\games\burnoutpr\burnoutpr.exe] => (Allow) E:\games\burnoutpr\burnoutpr.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [UDP Query User{89BA998F-29A9-40A9-9C26-C8BBF0AF1375}E:\games\burnoutpr\burnoutpr.exe] => (Allow) E:\games\burnoutpr\burnoutpr.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{BB6160F3-C97F-45A2-B09F-E08EA9BE381A}] => (Allow) LPort=9009
FirewallRules: [{A3B8F670-5829-421D-9C6C-A064820AAE02}] => (Allow) LPort=9009
FirewallRules: [{1CF9DDEE-E5DB-4A7D-A640-EE56023027AE}] => (Allow) LPort=9009
FirewallRules: [{EBA19B5F-F43F-45FB-B2C6-8D6BB5AA9BEE}] => (Allow) LPort=9009
FirewallRules: [{5233A891-BAE7-4A1A-B590-530F8F7756AF}] => (Allow) LPort=9009
FirewallRules: [{FB962F35-2D0E-4E61-9732-FFF22D476122}] => (Allow) LPort=9009
FirewallRules: [{AC662CDB-17A0-427E-9355-EE8D177FEAFF}] => (Allow) LPort=9009
FirewallRules: [{3AE69A13-847B-4409-BC2B-8CF3F64172A6}] => (Allow) LPort=9009
FirewallRules: [{3330DA27-0743-4A5C-8277-3EACCC8D0B3C}] => (Allow) LPort=9009
FirewallRules: [{A0273A6F-B45C-46E2-AE36-74E6B3CAA01A}] => (Allow) LPort=9009
FirewallRules: [{0A21FC5C-4824-4EBE-A01C-95AC2F1B0FF3}] => (Allow) LPort=9009
FirewallRules: [{7F7043FD-D63A-4C3A-8B3F-91456A9C68EB}] => (Allow) LPort=9009
FirewallRules: [{C207A766-1A01-4417-8385-EEC3099120C0}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12131.3.2010.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{98AFD042-97CA-4A40-B6AA-512896B15C3F}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12131.3.2010.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{D286E251-9075-40C8-B543-0411C35ED2F9}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12131.3.2010.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{98926C6A-819D-451A-8030-97A058492FA1}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12131.3.2010.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{9940E2A6-48C6-4E2E-806A-E1E9CC2DC52C}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12131.3.2010.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{F70DBDB1-A8A9-4226-80D6-2B4BFB5429E3}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12131.3.2010.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{631BEB6B-012A-4739-896B-F5C0DE7AAE4D}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12131.3.2010.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{C3E2F134-89E0-43B1-92E2-F40B116494ED}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12131.3.2010.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{1C7B1EF9-14A1-40C0-BBA3-910EDD3E9D3F}] => (Allow) LPort=9009
FirewallRules: [{D65710A4-7368-43E2-8AE1-A0BA51F68135}] => (Allow) LPort=9009
FirewallRules: [{C4C7F67A-0CEA-4127-B370-3C5E23185B7F}] => (Allow) LPort=9009
FirewallRules: [{7F12C3ED-5E21-42DD-9326-758A8D80810B}] => (Allow) LPort=9009
FirewallRules: [{89CDC343-51FC-4F36-B5AA-6E98388F1AD3}] => (Allow) LPort=9009
FirewallRules: [{58186FAC-E7F8-4DB8-9FF5-4C31E3E70039}] => (Allow) LPort=9009
FirewallRules: [{F59D4BC6-C880-4656-9AAD-3D67BC2D39D9}] => (Allow) LPort=9009
FirewallRules: [{3F2D5C81-3E7E-4515-8ABD-2511DBB79188}] => (Allow) LPort=9009
FirewallRules: [{8173991D-8794-4559-95FE-C0D37D3BA52D}] => (Allow) LPort=9009
FirewallRules: [{293C09F9-1402-4BBA-A105-F37C4EA3FAB7}] => (Allow) LPort=9009
FirewallRules: [{9D8316EE-62A1-405D-A171-792B1B9D77DC}] => (Allow) LPort=9009
FirewallRules: [{EAD8B778-5418-45F4-9ED8-AC996B1DB8B9}] => (Allow) LPort=9009
FirewallRules: [{01B9661E-12EF-4037-92D3-545F859F149E}] => (Allow) LPort=9009
FirewallRules: [{CAC0A486-9127-489F-9B92-1FE968656D7C}] => (Allow) LPort=9009
FirewallRules: [{BB66C444-93FF-4343-845A-5F0B934CC104}] => (Allow) LPort=9009
FirewallRules: [{D1891840-E964-4035-A6D3-0466631EEA83}] => (Allow) LPort=9009
FirewallRules: [{9037A2A0-31D5-45C9-8692-3FEFD9DF7CA9}] => (Allow) LPort=9009
FirewallRules: [{1DD6C09C-90BE-4DEA-954E-4ACA11C4C993}] => (Allow) LPort=9009
FirewallRules: [{C9EA54CC-73D9-4761-852A-2A310FC830BB}] => (Allow) LPort=9009
FirewallRules: [{8DB401F9-CB4E-43CC-B72A-385E485F8C42}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc. -> Plex, Inc.)
FirewallRules: [{D12F904B-0659-46DD-B0DC-71786866304E}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe (Plex, Inc. -> )
FirewallRules: [{967E616C-591A-4184-8A5A-6312DAA1B40D}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe (Plex, Inc. -> Plex, Inc.)
FirewallRules: [{670E25D4-C611-41BB-B1B3-86AF13320EA3}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe (Plex, Inc. -> )
FirewallRules: [{C159341C-8F72-4B47-A523-EF1902A121A8}] => (Allow) LPort=9009
FirewallRules: [{61AED820-48BD-41A4-BC8E-70B7FBFDA629}] => (Allow) LPort=9009
FirewallRules: [{C22428CC-0778-4769-AE6F-91445B7A659C}] => (Allow) LPort=9009
FirewallRules: [{98F994A5-297F-4FC9-822E-CA102BCB205E}] => (Allow) LPort=9009
FirewallRules: [{AF953A85-0A14-45F5-B2DD-DBD74BAE9234}] => (Allow) LPort=9009
FirewallRules: [{2F5C69F1-3EF4-4A16-B5C5-0672F687903D}] => (Allow) LPort=8410
FirewallRules: [{FB747E28-90E5-44B4-98BD-F20B0CA1357B}] => (Allow) LPort=9009
FirewallRules: [{1B57CF49-50AE-4F61-B7A7-A65356C449A3}] => (Allow) LPort=9009
FirewallRules: [{AE268B15-FD47-401E-83BF-65281B8B6A0C}] => (Allow) LPort=9009
FirewallRules: [{854C91FC-07AE-4F9C-A0B6-7943B4FE7BB1}] => (Allow) LPort=9009
FirewallRules: [{FA785F34-AB7A-4AEB-83DE-AE73D0C2FE13}] => (Allow) LPort=9009
FirewallRules: [{D54C858A-5F53-4DE6-8A64-FA78D301911F}] => (Allow) LPort=9009
FirewallRules: [{7C0F1AD0-F1C5-49C4-BED6-ADE58B5E1057}] => (Allow) LPort=9009
FirewallRules: [{6E0B1940-AFF0-4525-8DBF-4E7C28B49A95}] => (Allow) LPort=9009
FirewallRules: [{54F42547-4703-4E0C-AF69-10DB157678F0}] => (Allow) LPort=9009
FirewallRules: [{05341EA8-22D6-4EB8-99C1-E59E8B577BC4}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\123.0.2420.65\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{BA5FA4F1-068E-4B58-968F-D553FC68CB40}] => (Allow) C:\Users\dwood\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{BC71BD72-6615-4E9C-8DD2-39083C78AA2F}] => (Allow) C:\Users\dwood\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{C61A1F1B-E74F-40E5-9CDB-CDFCBD09A5CE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{11D3BD22-5F0C-47AB-A9E1-A6AA1C5EE24C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.116.3213.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{16739A89-1303-4C7A-9FF5-7B38478E34E8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.116.3213.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{DA876F40-1A52-4D99-92BC-3235948ADE9D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.116.3213.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{7615577D-0C2F-4FD2-9B5E-4A94E449F761}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.116.3213.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{377AFA84-7398-40B9-9592-DC69623F2720}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{580B3498-9E27-4F3D-9D5F-83D3727D035A}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{F682E9CD-D214-401F-AA36-0A425B04DE4D}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{457FBF87-4513-4B04-BC58-BBE924CBE809}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{4C064520-6F81-4A3A-81D8-458A2B6E1D83}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{E093E5B2-B9F0-4F8D-BB6D-95F896568206}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{BAA64952-F309-4B0F-B8EB-76246F29BBAF}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAGEP.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{E903EFDE-31CD-4967-803A-0118FDC0724C}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAGEP.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{443D58C1-F6A4-4B7C-8CB5-FB16A3286523}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{83E7CC49-784E-41FA-B68A-C524864B26D4}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{0A16F7CC-BE48-45EA-B172-7483AD4C259A}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALaunchHelper.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{1AE8D2FB-0746-49D0-B9FA-614EA73DD061}] => (Allow) LPort=9009
FirewallRules: [{0D0F30C0-85BE-4731-A15D-00F18F4F782D}] => (Allow) LPort=9009
FirewallRules: [{BCB50991-3792-4064-B6FE-5B8B20676524}] => (Allow) C:\Program Files\AVG\Antivirus\AVGUI.exe (AVG Technologies USA, LLC -> Gen Digital Inc.)
FirewallRules: [{4DDFFED4-ECE1-47B0-BAC9-605E7FB924D5}] => (Allow) C:\Program Files\AVG\Antivirus\AVGUI.exe (AVG Technologies USA, LLC -> Gen Digital Inc.)
FirewallRules: [{5FDF8F42-B43F-4C7E-ADC9-AF5940CC84E8}] => (Allow) LPort=9009
FirewallRules: [{8E4FF5EE-208F-452F-A0F0-F02EBDE0D9B0}] => (Allow) LPort=9009
FirewallRules: [{3E493142-207B-468C-BACB-C4BACC591F07}] => (Allow) LPort=9009
FirewallRules: [{512F817C-C1F5-4446-B086-C4A4DB0D1334}] => (Allow) LPort=9009
FirewallRules: [{23348510-1A28-4079-9C6C-2AA3BCA626A0}] => (Allow) LPort=9009
FirewallRules: [{4BF72422-67F4-4C9A-A021-28B05012AADA}] => (Allow) LPort=9009
FirewallRules: [{D5C8BFD7-5246-483F-90C3-8E6704093131}] => (Allow) LPort=32683
FirewallRules: [{92BECB02-2069-4D3C-95ED-5EFF03FF37EA}] => (Allow) LPort=26822
FirewallRules: [{7F532F29-7BA8-4D66-B42A-7D6328C4C36B}] => (Allow) LPort=9009
FirewallRules: [{EBBF6D34-4B99-4B92-90C7-61985A18EF70}] => (Allow) C:\Program Files (x86)\Gigabyte\CloudStation_Server\HomeCloud\HCLOUD.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> Microsoft)
FirewallRules: [{13561C38-1286-411B-86BB-1A43A091FBD4}] => (Allow) C:\Program Files (x86)\Gigabyte\CloudStation_Server\RemoteOC\ubssrv_oc_only.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{B0E1F957-5EEE-4A84-9D0F-2AFAA53653C0}] => (Allow) C:\Program Files (x86)\Gigabyte\CloudStation_Server\RemoteControl\grckm.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
FirewallRules: [{6AFE7314-6B23-48A2-B871-554A4421B0A1}] => (Allow) LPort=1980
FirewallRules: [{18CB3C46-EE5F-413F-A494-51701A1553E8}] => (Allow) LPort=1900
FirewallRules: [{F1DAF9FB-6572-4367-BFB8-441EEDBE7F2E}] => (Allow) LPort=1900
FirewallRules: [{116B252B-191A-4D73-A8E2-D6E1DE91FEB3}] => (Allow) LPort=8702
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe] => Enabled:Flashget3
 
==================== Restore Points =========================
 
05-04-2024 16:02:01 Scheduled Checkpoint
07-04-2024 13:35:53 Removed FakerInput
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (04/08/2024 06:41:33 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AutoAD.exe, version: 1.0.0.0, time stamp: 0x6139f16c
Faulting module name: KERNELBASE.dll, version: 6.2.19041.4239, time stamp: 0x7c23e677
Exception code: 0xe0434f4d
Fault offset: 0x0013fa72
Faulting process ID: 0x%9
Faulting application start time: 0xAutoAD.exe0
Faulting application path: AutoAD.exe1
Faulting module path: AutoAD.exe2
Report ID: AutoAD.exe3
Faulting package full name: AutoAD.exe4
Faulting package-relative application ID: AutoAD.exe5
 
Error: (04/08/2024 06:41:16 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AutoAD.exe, version: 1.0.0.0, time stamp: 0x6139f16c
Faulting module name: KERNELBASE.dll, version: 6.2.19041.4239, time stamp: 0x7c23e677
Exception code: 0xe0434f4d
Fault offset: 0x0013fa72
Faulting process ID: 0x%9
Faulting application start time: 0xAutoAD.exe0
Faulting application path: AutoAD.exe1
Faulting module path: AutoAD.exe2
Report ID: AutoAD.exe3
Faulting package full name: AutoAD.exe4
Faulting package-relative application ID: AutoAD.exe5
 
Error: (04/08/2024 06:39:31 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.]
 
Error: (04/08/2024 06:37:13 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AutoAD.exe, version: 1.0.0.0, time stamp: 0x6139f16c
Faulting module name: KERNELBASE.dll, version: 6.2.19041.4239, time stamp: 0x7c23e677
Exception code: 0xe0434f4d
Fault offset: 0x0013fa72
Faulting process ID: 0x%9
Faulting application start time: 0xAutoAD.exe0
Faulting application path: AutoAD.exe1
Faulting module path: AutoAD.exe2
Report ID: AutoAD.exe3
Faulting package full name: AutoAD.exe4
Faulting package-relative application ID: AutoAD.exe5
 
Error: (04/08/2024 06:36:54 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AutoAD.exe, version: 1.0.0.0, time stamp: 0x6139f16c
Faulting module name: KERNELBASE.dll, version: 6.2.19041.4239, time stamp: 0x7c23e677
Exception code: 0xe0434f4d
Fault offset: 0x0013fa72
Faulting process ID: 0x%9
Faulting application start time: 0xAutoAD.exe0
Faulting application path: AutoAD.exe1
Faulting module path: AutoAD.exe2
Report ID: AutoAD.exe3
Faulting package full name: AutoAD.exe4
Faulting package-relative application ID: AutoAD.exe5
 
Error: (04/07/2024 06:15:28 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimiser couldn't complete re-trim on WD4TB (D:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)
 
Error: (04/07/2024 06:14:28 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimiser couldn't complete re-trim on 8TB (Z:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)
 
Error: (04/07/2024 06:14:24 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimiser couldn't complete re-trim on 4TBWDBLUE (E:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)
 
 
System errors:
=============
Error: (04/08/2024 06:40:52 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Autodesk Content Service service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (04/08/2024 06:40:52 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (60000 milliseconds) while waiting for the Autodesk Content Service service to connect.
 
Error: (04/08/2024 06:40:52 AM) (Source: IntelHaxm) (EventID: 10) (User: )
Description: HAXM can't work on system with VT disabled
 
Error: (04/08/2024 06:40:52 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The OCButtonService service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (04/08/2024 06:39:14 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GJSJAIJ)
Description: The server Microsoft.MicrosoftSolitaireCollection_4.19.1262.0_x64__8wekyb3d8bbwe!App did not register with DCOM within the required timeout.
 
Error: (04/08/2024 06:36:30 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Autodesk Content Service service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (04/08/2024 06:36:30 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (60000 milliseconds) while waiting for the Autodesk Content Service service to connect.
 
Error: (04/08/2024 06:36:30 AM) (Source: IntelHaxm) (EventID: 10) (User: )
Description: HAXM can't work on system with VT disabled
 
 
CodeIntegrity:
===============
Date: 2024-04-08 06:48:48
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume8\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume8\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Windows signing level requirements.
 
 
==================== Memory info =========================== 
 
BIOS: American Megatrends Inc. ALASKA - 1072009 06/15/2018
Motherboard: Gigabyte Technology Co., Ltd. X99-UD3-CF
Processor: Intel® Core™ i7-5930K CPU @ 3.50GHz
Percentage of memory in use: 55%
Total physical RAM: 16221.43 MB
Available physical RAM: 7215.58 MB
Total Virtual: 46941.43 MB
Available Virtual: 34617.78 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:446.12 GB) (Free:161.81 GB) (Model: WDC WD40EZRX-00SPEB0) NTFS
Drive d: (WD4TB) (Fixed) (Total:3725.9 GB) (Free:1996.37 GB) (Model: WDC WD40EZRX-00SPEB0) NTFS
Drive e: (4TBWDBLUE) (Fixed) (Total:3725.9 GB) (Free:1438.82 GB) (Model: WDC WD40EZRZ-00GXCB0) NTFS
Drive z: (8TB) (Fixed) (Total:7452.02 GB) (Free:1619.69 GB) (Model: ST8000DM004-2U9188) NTFS
 
\\?\Volume{a7f367eb-936f-46a6-b0a5-2f5be658f185}\ (Recovery) (Fixed) (Total:0.29 GB) (Free:0.06 GB) NTFS
\\?\Volume{fb8208ae-b34d-46ba-8c8b-3a3572d76f09}\ () (Fixed) (Total:0.49 GB) (Free:0.03 GB) NTFS
\\?\Volume{76a6ab59-7789-4620-81c6-f18ba5cc64a7}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Protective MBR) (Size: 3726 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==========================================================
Disk: 1 (Protective MBR) (Size: 7452 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==========================================================
Disk: 2 (Protective MBR) (Size: 447.1 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==========================================================
Disk: 3 (Protective MBR) (Size: 3726 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==================== End of Addition.txt =======================


#4 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted 07 April 2024 - 08:01 PM

Please do this.

===================================================

Uninstalling Adobe Flash Player

--------------------

Note: Adobe Flash Player is no longer supported and is a security risk.
  • Download Adobe Flash Player Uninstaller and save it to your Desktop
  • Right click on the icon and select Run as administrator
  • Click Uninstall then Done to reboot your computer
===================================================

Uninstalling Programs Using Revo Uninstaller Free Portable

--------------------
  • Download Revo Uninstaller Free Portable and save it to your Desktop
  • Right click on the folder and select Extract All..., then click Extract
  • Double click on the RevoUninstaller-Portable folder
  • Right click on RevoUPort and select Run as administrator
  • Click OK on the License Agreement
  • From the list of programs double click on the listed program(s), or anything similar, to remove it (if it exists)
Web Companion
  • If the program's uninstaller appears work through the steps to remove the program(s)
  • Be sure the Advanced option is selected then click Scan
  • For each window that may appear identifying leftover items click Select All, Delete, then confirm the deletion
  • Once done click Finish
  • Reboot your computer
===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Start::
SystemRestore: On
CreateRestorePoint:
CloseProcesses:
Folder: C:\WINDOWS\system32\o2
Zip: C:\Program Data\AVG\Antivirus
2019-10-13 13:37 - 2019-10-13 13:37 - 000000000 _____ () C:\Program Files (x86)\GUM6F.tmp 
S2 OCButtonService; "C:\Program Files (x86)\Gigabyte\EasyTuneEngineService\OcButtonService.exe" [X] 
S3 BCM42RLY; system32\drivers\BCM42RLY.sys [X] 
S3 EAAntiCheat; system32\drivers\eaanticheat.sys [X] 
S3 PCASp60; System32\Drivers\PCASp60.sys [X] 
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Run: [btweb] => "C:\Users\dwood\AppData\Roaming\BitTorrent Web\btweb.exe" /MINIMIZED (No File) 
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3000 series: CNMLMDG.DLL (No File) 
Task: {FE2347DF-8042-4E90-90C4-29030B9EAF83} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION 
Task: {143DEA42-37A1-4E2B-BA98-DCC1DDF7A804} - System32\Tasks\AdobeGCInvoker-1.0-MicrosoftAccount-dwoodg20@hotmail.com => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe -mode=scheduled (No File) 
Task: {7FB4568C-E4D5-462C-93CA-C11C09DFCA82} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe /s (No File) 
ContextMenuHandlers1: [DWGSeeMenu] -> {A6EAF440-149E-4AF3-AE84-5DA3CF791E3B} => C:\Program Files (x86)\AutoDWG\DWGSee\DWGSeeMenu64.dll -> No File 
R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [28760 2019-11-30] (LAVASOFT SOFTWARE CANADA INC -> ) <==== ATTENTION 
Web Companion (HKLM-x32\...\{dc1b032b-8021-4661-bb22-e8d765e4e5c3}) (Version: 4.9.2159.4024 - Lavasoft) <==== ATTENTION 
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Policies\Explorer: [] 
AlternateDataStreams: C:\ProgramData\TEMP:036B81D9 [167] 
AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F [134] 
AlternateDataStreams: C:\ProgramData\TEMP:4B6A9FDA [163] 
AlternateDataStreams: C:\ProgramData\TEMP:5C92988B [191] 
AlternateDataStreams: C:\ProgramData\TEMP:627B7F7C [384] 
AlternateDataStreams: C:\ProgramData\TEMP:BD13A410 [106] 
AlternateDataStreams: C:\ProgramData\TEMP:EC9FFAA4 [178] 
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\MountPoints2: F - "F:\AUTORUN.EXE"
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-Image /CheckHealth
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
  • The tool will create a zipped folder on the Desktop with today's date, example: 07.30.2023_13.24.50.zip. Please upload the file here.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Programs uninstall?
  • Fixlog
  • Uploaded zip file

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#5 Dustin77

Dustin77
  • Topic Starter

  •  Avatar image
  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 07 April 2024 - 09:57 PM

I did all as requested. uninstalled flash player and web companion.

i ran the frst64 in admin mode - copied text and clicked fix.

there was no zipped folder or file on the desktop but here is the text . . .

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 06.04.2024 01
Ran by dwood (08-04-2024 12:41:11) Run:1
Running from C:\Users\dwood\Downloads
Loaded Profiles: defaultuser0 & dwood
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start::
SystemRestore: On
CreateRestorePoint:
CloseProcesses:
Folder: C:\WINDOWS\system32\o2
Zip: C:\Program Data\AVG\Antivirus
2019-10-13 13:37 - 2019-10-13 13:37 - 000000000 _____ () C:\Program Files (x86)\GUM6F.tmp
S2 OCButtonService; "C:\Program Files (x86)\Gigabyte\EasyTuneEngineService\OcButtonService.exe" [X]
S3 BCM42RLY; system32\drivers\BCM42RLY.sys [X]
S3 EAAntiCheat; system32\drivers\eaanticheat.sys [X]
S3 PCASp60; System32\Drivers\PCASp60.sys [X]
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Run: [btweb] => "C:\Users\dwood\AppData\Roaming\BitTorrent Web\btweb.exe" /MINIMIZED (No File)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3000 series: CNMLMDG.DLL (No File)
Task: {FE2347DF-8042-4E90-90C4-29030B9EAF83} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {143DEA42-37A1-4E2B-BA98-DCC1DDF7A804} - System32\Tasks\AdobeGCInvoker-1.0-MicrosoftAccount-dwoodg20@hotmail.com => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe -mode=scheduled (No File)
Task: {7FB4568C-E4D5-462C-93CA-C11C09DFCA82} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe /s (No File)
ContextMenuHandlers1: [DWGSeeMenu] -> {A6EAF440-149E-4AF3-AE84-5DA3CF791E3B} => C:\Program Files (x86)\AutoDWG\DWGSee\DWGSeeMenu64.dll -> No File
R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [28760 2019-11-30] (LAVASOFT SOFTWARE CANADA INC -> ) <==== ATTENTION
Web Companion (HKLM-x32\...\{dc1b032b-8021-4661-bb22-e8d765e4e5c3}) (Version: 4.9.2159.4024 - Lavasoft) <==== ATTENTION
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\Policies\Explorer: []
AlternateDataStreams: C:\ProgramData\TEMP:036B81D9 [167]
AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F [134]
AlternateDataStreams: C:\ProgramData\TEMP:4B6A9FDA [163]
AlternateDataStreams: C:\ProgramData\TEMP:5C92988B [191]
AlternateDataStreams: C:\ProgramData\TEMP:627B7F7C [384]
AlternateDataStreams: C:\ProgramData\TEMP:BD13A410 [106]
AlternateDataStreams: C:\ProgramData\TEMP:EC9FFAA4 [178]
HKU\S-1-5-21-559634521-2701541241-958822180-1001\...\MountPoints2: F - "F:\AUTORUN.EXE"
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-Image /CheckHealth
End::
*****************

SystemRestore: On => completed
Restore point was successfully created.
Processes closed successfully.

========================= Folder: C:\WINDOWS\system32\o2 ========================


====== End of Folder: ======

================== Zip: ===================
"C:\Program Data\AVG\Antivirus" => not found
=========== Zip: End ===========
C:\Program Files (x86)\GUM6F.tmp => moved successfully
HKLM\System\CurrentControlSet\Services\OCButtonService => removed successfully
OCButtonService => service removed successfully
HKLM\System\CurrentControlSet\Services\BCM42RLY => removed successfully
BCM42RLY => service removed successfully
HKLM\System\CurrentControlSet\Services\EAAntiCheat => removed successfully
EAAntiCheat => service removed successfully
HKLM\System\CurrentControlSet\Services\PCASp60 => removed successfully
PCASp60 => service removed successfully
"HKU\S-1-5-21-559634521-2701541241-958822180-1001\Software\Microsoft\Windows\CurrentVersion\Run\\btweb" => removed successfully
HKLM\System\CurrentControlSet\Control\Print\Monitors\Canon BJ Language Monitor MG3000 series => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FE2347DF-8042-4E90-90C4-29030B9EAF83}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FE2347DF-8042-4E90-90C4-29030B9EAF83}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{143DEA42-37A1-4E2B-BA98-DCC1DDF7A804}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{143DEA42-37A1-4E2B-BA98-DCC1DDF7A804}" => removed successfully
C:\WINDOWS\System32\Tasks\AdobeGCInvoker-1.0-MicrosoftAccount-dwoodg20@hotmail.com => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeGCInvoker-1.0-MicrosoftAccount-dwoodg20@hotmail.com" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7FB4568C-E4D5-462C-93CA-C11C09DFCA82}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7FB4568C-E4D5-462C-93CA-C11C09DFCA82}" => removed successfully
C:\WINDOWS\System32\Tasks\MSIAfterburner => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MSIAfterburner" => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\DWGSeeMenu => removed successfully
HKLM\Software\Classes\CLSID\{A6EAF440-149E-4AF3-AE84-5DA3CF791E3B} => removed successfully
WCAssistantService => service not found.
Web Companion (HKLM-x32\...\{dc1b032b-8021-4661-bb22-e8d765e4e5c3}) (Version: 4.9.2159.4024 - Lavasoft) <==== ATTENTION => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-559634521-2701541241-958822180-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\" => removed successfully
C:\ProgramData\TEMP => ":036B81D9" ADS removed successfully
C:\ProgramData\TEMP => ":2CB9631F" ADS removed successfully
C:\ProgramData\TEMP => ":4B6A9FDA" ADS removed successfully
C:\ProgramData\TEMP => ":5C92988B" ADS removed successfully
C:\ProgramData\TEMP => ":627B7F7C" ADS removed successfully
C:\ProgramData\TEMP => ":BD13A410" ADS removed successfully
C:\ProgramData\TEMP => ":EC9FFAA4" ADS removed successfully
HKU\S-1-5-21-559634521-2701541241-958822180-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F => removed successfully

========= sfc /scannow =========



Beginning system scan.  This process will take some time.



Beginning verification phase of system scan.


Verification 0% complete.
Verification 1% complete.
Verification 1% complete.
Verification 2% complete.
Verification 2% complete.
Verification 3% complete.
Verification 4% complete.
Verification 4% complete.
Verification 5% complete.
Verification 5% complete.
Verification 6% complete.
Verification 7% complete.
Verification 7% complete.
Verification 8% complete.
Verification 8% complete.
Verification 9% complete.
Verification 10% complete.
Verification 10% complete.
Verification 11% complete.
Verification 11% complete.
Verification 12% complete.
Verification 13% complete.
Verification 13% complete.
Verification 14% complete.
Verification 14% complete.
Verification 15% complete.
Verification 16% complete.
Verification 16% complete.
Verification 17% complete.
Verification 17% complete.
Verification 18% complete.
Verification 19% complete.
Verification 19% complete.
Verification 20% complete.
Verification 20% complete.
Verification 21% complete.
Verification 22% complete.
Verification 22% complete.
Verification 23% complete.
Verification 23% complete.
Verification 24% complete.
Verification 25% complete.
Verification 25% complete.
Verification 26% complete.
Verification 26% complete.
Verification 27% complete.
Verification 27% complete.
Verification 28% complete.
Verification 29% complete.
Verification 29% complete.
Verification 30% complete.
Verification 30% complete.
Verification 31% complete.
Verification 32% complete.
Verification 32% complete.
Verification 33% complete.
Verification 33% complete.
Verification 34% complete.
Verification 35% complete.
Verification 35% complete.
Verification 36% complete.
Verification 36% complete.
Verification 37% complete.
Verification 38% complete.
Verification 38% complete.
Verification 39% complete.
Verification 39% complete.
Verification 40% complete.
Verification 41% complete.
Verification 41% complete.
Verification 42% complete.
Verification 42% complete.
Verification 43% complete.
Verification 44% complete.
Verification 44% complete.
Verification 45% complete.
Verification 45% complete.
Verification 46% complete.
Verification 47% complete.
Verification 47% complete.
Verification 48% complete.
Verification 48% complete.
Verification 49% complete.
Verification 50% complete.
Verification 50% complete.
Verification 51% complete.
Verification 51% complete.
Verification 52% complete.
Verification 53% complete.
Verification 53% complete.
Verification 54% complete.
Verification 54% complete.
Verification 55% complete.
Verification 55% complete.
Verification 56% complete.
Verification 57% complete.
Verification 57% complete.
Verification 58% complete.
Verification 58% complete.
Verification 59% complete.
Verification 60% complete.
Verification 60% complete.
Verification 61% complete.
Verification 61% complete.
Verification 62% complete.
Verification 63% complete.
Verification 63% complete.
Verification 64% complete.
Verification 64% complete.
Verification 65% complete.
Verification 66% complete.
Verification 66% complete.
Verification 67% complete.
Verification 67% complete.
Verification 68% complete.
Verification 69% complete.
Verification 69% complete.
Verification 70% complete.
Verification 70% complete.
Verification 71% complete.
Verification 72% complete.
Verification 72% complete.
Verification 73% complete.
Verification 73% complete.
Verification 74% complete.
Verification 75% complete.
Verification 75% complete.
Verification 76% complete.
Verification 76% complete.
Verification 77% complete.
Verification 78% complete.
Verification 78% complete.
Verification 79% complete.
Verification 79% complete.
Verification 80% complete.
Verification 81% complete.
Verification 81% complete.
Verification 82% complete.
Verification 82% complete.
Verification 83% complete.
Verification 83% complete.
Verification 84% complete.
Verification 85% complete.
Verification 85% complete.
Verification 86% complete.
Verification 86% complete.
Verification 87% complete.
Verification 88% complete.
Verification 88% complete.
Verification 89% complete.
Verification 89% complete.
Verification 90% complete.
Verification 91% complete.
Verification 91% complete.
Verification 92% complete.
Verification 92% complete.
Verification 93% complete.
Verification 94% complete.
Verification 94% complete.
Verification 95% complete.
Verification 95% complete.
Verification 96% complete.
Verification 97% complete.
Verification 97% complete.
Verification 98% complete.
Verification 98% complete.
Verification 99% complete.
Verification 100% complete.


Windows Resource Protection found corrupt files and successfully repaired them.

For online repairs, details are included in the CBS log file located at

windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline

repairs, details are included in the log file provided by the /OFFLOGFILE flag.



========= End of CMD: =========


========= DISM /Online /Cleanup-Image /CheckHealth =========


Deployment Image Servicing and Management tool
Version: 10.0.19041.3636

Image Version: 10.0.19045.4239

No component store corruption detected.
The operation completed successfully.


========= End of CMD: =========



The system needed a reboot.

==== End of Fixlog 12:44:38 ====



#6 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted 08 April 2024 - 09:00 AM

The picture of the warning is not attached. Please zip and upload the file here
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#7 Dustin77

Dustin77
  • Topic Starter

  •  Avatar image
  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 09 April 2024 - 02:44 PM

The picture of the warning is not attached. Please zip and upload the file here

did you get the zip i uploaded? just wondering if i did it correctly



#8 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted 09 April 2024 - 03:43 PM

Yes I did, thank you.

Do you still get the same warning each time you boot?

Please do this.

===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Start::
File: C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe
File: C:\Windows\Installer\{DEF3592F-0751-4632-9875-8BF9AD602898}\_60ADE4ADDDB9C7178BB901.exe
File: C:\Program Files (x86)\Wondershare\MobileTrans\AutoAD.exe
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Autoruns

--------------------
  • Please download Autoruns and save it to your Desktop
  • Right click on the autoruns64 icon on your Desktop and select Run as administrator
  • Wait until the lower left hand corner of the window shows Ready
  • Hit the Ctrl + S key at the same time
  • Save the file onto your Desktop using the default File name:
  • Please zip and upload the file here
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Fixlog
  • Uploaded Autoruns file

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#9 Dustin77

Dustin77
  • Topic Starter

  •  Avatar image
  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 11 April 2024 - 05:02 AM

Yes unfortunately it still detects virus

 

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 10.04.2024
Ran by dwood (11-04-2024 19:57:03) Run:2
Running from C:\Users\dwood\Downloads
Loaded Profiles: dwood
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start::
File: C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe
File: C:\Windows\Installer\{DEF3592F-0751-4632-9875-8BF9AD602898}\_60ADE4ADDDB9C7178BB901.exe
File: C:\Program Files (x86)\Wondershare\MobileTrans\AutoAD.exe
End::
*****************


========================= File: C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe ========================

C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe
File not signed
MD5: A5FDFC8DE65F9E8F8695E5288133696D
Creation and modification date: 2019-06-21 23:43 - 2016-01-12 04:32
Size: 015624008
Attributes: ----A
Company Name: MEDIATEK INC. -> Mediatek Inc.
Internal Name: RaUI
Original Name: RaUI.exe
Product: RaUI Application
Description: Mediatek Wireless LAN Card Utility
File Version: 5.0.9.19
Product Version: 5.0.9.19
Copyright: © Copyright 2014, Mediatek Inc.  All rights reserved.
Virusscan: https://virusscan.jotti.org/filescanjob/4bsrnvgbwt

====== End of File: ======


========================= File: C:\Windows\Installer\{DEF3592F-0751-4632-9875-8BF9AD602898}\_60ADE4ADDDB9C7178BB901.exe ========================

C:\Windows\Installer\{DEF3592F-0751-4632-9875-8BF9AD602898}\_60ADE4ADDDB9C7178BB901.exe
File not signed
MD5: 609FA4BE9F124CE1246CD859A0D21F4E
Creation and modification date: 2019-04-30 08:24 - 2019-04-30 08:24
Size: 000004710
Attributes: ---RA
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
Virusscan: https://virusscan.jotti.org/filescanjob/sfcawqfwii

====== End of File: ======


========================= File: C:\Program Files (x86)\Wondershare\MobileTrans\AutoAD.exe ========================

C:\Program Files (x86)\Wondershare\MobileTrans\AutoAD.exe
File is digitally signed
MD5: E49C17A4E6B982E30D1588B7288B5575
Creation and modification date: 2021-09-15 09:28 - 2021-09-09 19:35
Size: 000064520
Attributes: ----A
Company Name: Wondershare Technology Co.,Ltd -> Wondershare
Internal Name: AutoAD.exe
Original Name: AutoAD.exe
Product: MobileTrans
Description: AutoAD
File Version: 1.0.0.0
Product Version: 1.0.0.0
Copyright: Copyright © 2021 Wondershare. All rights reserved.
Virusscan: https://virusscan.jotti.org/filescanjob/dtvjf8gb13

====== End of File: ======


==== End of Fixlog 19:57:22 ====



#10 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted 11 April 2024 - 08:11 AM

Thank you for the information.
 

AVG finds virus after i turn PC on. never any other time

Would you say this is detected during the boot up process or is it detected after fully booting the computer and you start normal activities like opening a browser or opening a file?
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#11 Dustin77

Dustin77
  • Topic Starter

  •  Avatar image
  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 12 April 2024 - 04:52 AM

Sorry for the delay. I work 12hr shifts.

 

It happens after computer loads everything but just before i move the mouse, so i'd say its executing during the bootup of windows.



#12 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted 12 April 2024 - 02:08 PM

Thank you, that helps.

Please do this.

===================================================

Process Monitor Boot Log

--------------------
  • Download Process Monitor and save it to your Desktop
  • Right click on Procmon and select Run as administrator
  • Agree to any permission requests
  • Hit Ctrl + E to stop capturing events
  • Hit Ctrl + X at the same time to clear the display
  • Click Options then Enable Boot Logging
  • Place a check mark in Generate thread profiling events
  • Click OK
  • Close Process Monitor
  • Close any open programs and shut down your computer
  • Start your computer and allow the boot up process to complete, including logging in if you use a password
  • Wait 15 minutes before doing anything further
  • Right click on Process Monitor and select Run as administrator
  • Click Yes on the next window that appears and save the boot-time activity log onto your desktop using the default name
  • Please zip and upload the file to GoFile or the file hosting site of your choice and send me a Personal Message with download link
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Uploaded zip file

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#13 Dustin77

Dustin77
  • Topic Starter

  •  Avatar image
  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 13 April 2024 - 06:06 AM

I have tried this 3 times unsuccessfully so far. it gets to 94% and says out of memory unable to allocate memory. then when i click ok it just closes without creating a file. is there anything i can do to expand the memory size or reduce the file being written or splitting it?



#14 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted 13 April 2024 - 06:37 PM

Greetings.
 

Place a check mark in Generate thread profiling events

When you get to this step if it is not already selected, select Every second. If that is already selected stop and let me know.


Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#15 Dustin77

Dustin77
  • Topic Starter

  •  Avatar image
  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 14 April 2024 - 12:00 AM

yeah that is already selected. it takes about 20 minutes to do the first 86% then it takes an hour or so to get to 94% or last time i tried it reached 96% then just stops as it has run out of memory.






1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users