This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cannot install antivirus, Chrome/IE crashing immediately after opening

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everyone.

 

So roughly a week ago I recieved an alert from Avast Antivirus while browsing through Chrome, and immediately recieved a blue screen after.  On reboot I noticed Avast hadn't started back up, and when tried to manually start it up nothing happened.  Trying to reinstall it did nothing, nor did trying to unistall it.  I tried installing AVG, which also did nothing.  Started up in safe mode, still had the same problem.  Chrome also started becoming unstable, crashing after being open for a short while.  Now it simply crashes immediately after opening, as does Internet Explorer.  The only working browser is Firefox.  Ran a Windows Defender scan which sent back an error before it could complete, and the same happened when I ran SuperAntiSpyware.  Ran CCleaner's registery cleaner and deleted what showed up, but that didn't change anything.  Downloaded and installed Trojan Hunter and ran another scan, deleted what it found, but that also had no effect.  Also, I'm not sure if it's related, but I noticed the Steam app's web pages won't load.  It's still connected to the web and still auto updates games, I just can't see anything web related through the browser.

 

And so after all that, I found this place. After following the instructions in the sticky, here's my FRST log.  The aswMBR installer won't start up either, so I can't actually do step 1.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-11-2015
Ran by [removed] (administrator) on YMIR (07-11-2015 08:12:25)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Home Premium (X64) Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files\Core Temp\Core Temp.exe
(AddGadgets) C:\Users\Michael\Downloads\Windows Gadgets\PCMeterV0.3.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Foxit Corporation) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) C:\Windows\System32\regsvr32.exe
() C:\ProgramData\openssl.exe
() C:\ProgramData\igfxEM_32.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
(Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
(Flux Software LLC) C:\Users\Michael\AppData\Local\FluxSoftware\Flux\flux.exe
() C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
() C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe
(Dropbox, Inc.) C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe
(CANON INC.) C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Mischel Internet Security) C:\Program Files (x86)\TrojanHunter\THGuard.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DeviceAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(PeerBlock, LLC) C:\Program Files\PeerBlock\peerblock.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_226.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_226.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [Fences] => C:\Program Files (x86)\Stardock\Fences\Fences.exe [4013744 2013-04-25] (Stardock Corporation)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12446824 2012-01-31] (Realtek Semiconductor)
HKLM\…\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10464536 2014-07-02] (Logitech Inc.)
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634896 2015-07-23] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\…\Run: [GheT3Z733AFC] => regsvr32.exe /s "C:\PROGRA~3\GheT3Z733AFC.dll"
HKLM\…\Run: [openssl] => C:\ProgramData\openssl.exe [4096 2015-11-05] ()
HKLM\…\Run: [igfxEM_32] => C:\ProgramData\igfxEM_32.exe [4096 2015-11-06] ()
HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-26] (Intel Corporation)
HKLM-x32\…\Run: [P17RunE] => RunDll32 P17RunE.dll,RunDLLEntry
HKLM-x32\…\Run: [IJNetworkScanUtility] => C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [206240 2010-08-23] (CANON INC.)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-10-10] (AVAST Software)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\…\Run: [DBAgent] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [1518664 2014-09-17] (Seagate Technology LLC)
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157968 2015-08-13] (Apple Inc.)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-16] (Apple Inc.)
HKLM-x32\…\Run: [THGuard] => C:\Program Files (x86)\TrojanHunter\THGuard.exe [1082832 2015-06-18] (Mischel Internet Security)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22568216 2015-10-12] (Google)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3011152 2015-11-05] (Valve Corporation)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Google Update] => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-31] (Google Inc.)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Uploader] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe [127080 2014-09-17] (Seagate Technology LLC)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [457088 2015-09-23] (Sony)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Dropbox Update] => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-15] (Dropbox, Inc.)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [f.lux] => C:\Users\Michael\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53729824 2015-08-07] (Skype Technologies S.A.)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [PeerBlock] => C:\Program Files\PeerBlock\peerblock.exe [2513992 2014-01-14] (PeerBlock, LLC)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [IequGrufh] => regsvr32.exe "C:\ProgramData\Linpal\BufqOvba.dll"
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [BackUp680067079] => C:\Users\Michael\AppData\Roaming\BackUp680067079.exe [577536 2009-07-13] ()
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7935904 2015-10-19] (SUPERAntiSpyware)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\MountPoints2: {d61fb579-c776-11e4-bcd3-bc5ff4abb4c9} - I:\Startme.exe
HKU\S-1-5-18\…\Run: [Chrome] => C:\ProgramData\taskhost.exe [5120 2015-10-31] ()
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-10-10] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-10-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-10-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-10-12] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2015-04-10]
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe ()
Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-10-16]
ShortcutTarget: Dropbox.lnk -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6228E9D9-CFC6-4C51-A1BD-1A5005A37E14}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage;=hxxp://go.microsoft.com/fwlink/?LinkId=69157
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage;=hxxp://go.microsoft.com/fwlink/?LinkId=69157
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage;=hxxps://search.yahoo.com/?type=282369&fr;=spigot-yhp-ie
SearchScopes: HKU\S-1-5-21-711289349-3085500364-3229847752-1000 -> DefaultScope {E65363E6-EB13-4F01-836F-A169301AD9A0} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei;=utf-8&ilc;=12&type;=282369&p;={searchTerms}
SearchScopes: HKU\S-1-5-21-711289349-3085500364-3229847752-1000 -> {E65363E6-EB13-4F01-836F-A169301AD9A0} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei;=utf-8&ilc;=12&type;=282369&p;={searchTerms}
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-05-27] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-26] (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-05-27] (Oracle Corporation)
BHO-x32: No Name -> {451C804F-C205-4F03-B48E-537EC94937BF} -> No File
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-11] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-26] (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-11] (Oracle Corporation)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 -  No File

FireFox:
========
FF ProfilePath: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default
FF DefaultSearchEngine: Google
FF DefaultSearchEngine.US: Google
FF Homepage: hxxp://en.wikipedia.org/wiki/Main_Page
FF Session Restore: -> is enabled.
FF Keyword.URL: hxxps://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&ilc;=12&type;=282369&p;=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll [2015-11-05] ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\system32\npDeployJava1.dll [2013-05-27] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-05-27] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-11-05] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-07-30] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-04-23] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-04-23] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-11] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-07-11] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-07-22] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-07-22] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Michael\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @talk.google.com/O1DPlugin -> C:\Users\Michael\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Michael\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-07-20] (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\user.js [2015-07-10]
FF Plugin ProgramFiles/Appdata: C:\Users\Michael\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Michael\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF SearchPlugin: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\searchplugins\yahoo_ff.xml [2014-07-12]
FF Extension: Cookies Manager+ - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\Extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d} [2015-05-31]
FF Extension: ExHentai Easy 2 - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\Extensions\[removed] [2015-08-31]
FF Extension: Showcase - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\Extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}.xpi [2015-05-31]
FF Extension: Adblock Plus - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-25]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-10-08] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-10-10] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\ProgramData\Wondershare\Video Converter Ultimate\[removed] => not found

Chrome:
=======
CHR HomePage: Default -> hxxp://en.wikipedia.org/
CHR StartupUrls: Default -> "hxxp://www.hotmail.com/"
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-12]
CHR Extension: (Entanglement Web App) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd [2013-11-24]
CHR Extension: (Tab Expose) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ackpfhlmgjdjlohhjmbacaajbmkkklnp [2013-05-19]
CHR Extension: (Angry Birds) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2014-12-14]
CHR Extension: (TooManyTabs for Chrome) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\amigcgbheognjmfkaieeeadojiibgbdp [2014-06-11]
CHR Extension: (Google Docs) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-12]
CHR Extension: (Google Drive) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-25]
CHR Extension: (YouTube) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Sad Panda) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\bohapeiooecafommnlaiccilacgmkaoc [2014-08-30]
CHR Extension: (Adblock Plus) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-09-25]
CHR Extension: (Google Search) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-30]
CHR Extension: (Google Sheets) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-12]
CHR Extension: (Google Analytics Opt-out Add-on (by Google)) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\fllaojicojecljbmefodhfapmkghcbnh [2014-10-03]
CHR Extension: (IBA Opt-out (by Google)) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbiekjoijknlhijdjbaadobpkdhmoebb [2013-08-23]
CHR Extension: (Chuck Anderson) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gegkoiakifeoejnjkbnnojkkdoegeofp [2014-11-20]
CHR Extension: (Google Docs Offline) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-05]
CHR Extension: (AdBlock) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-10-18]
CHR Extension: (Desktop Notifications for Android) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\giicnncicnopjohcpamieklkiacdoeni [2015-08-29]
CHR Extension: (Avast Online Security) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-10-31]
CHR Extension: (TabJump - Intelligent Tab Navigator) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokofmgcicpnjchllaccgedmmmbbnbmf [2013-05-19]
CHR Extension: (Cookie Manager) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbnfbcpkiaganjpcanopcgeoehkleeck [2014-08-30]
CHR Extension: (Poppit!) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi [2014-07-17]
CHR Extension: (Ghostery) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2015-09-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-28]
CHR Extension: (Gmail) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR HKU\S-1-5-21-711289349-3085500364-3229847752-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Michael\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-19]
CHR HKU\S-1-5-21-711289349-3085500364-3229847752-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-01]
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-10-10] (AVAST Software)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4048280 2015-10-10] (Avast Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [238376 2015-07-23] (EasyAntiCheat Ltd)
R2 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [242216 2014-06-17] (Foxit Corporation)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1616440 2015-10-18] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6952504 2015-10-18] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155216 2015-07-23] (NVIDIA Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-05] (Intel Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] ()
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1871504 2015-07-23] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544592 2015-07-23] (NVIDIA Corporation)
R2 Seagate Dashboard Services; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe [16000 2014-09-17] (Seagate Technology LLC)
R2 Seagate MobileBackup Service; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe [157776 2014-09-17] (Seagate Technology LLC)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-10-10] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-10-10] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-10-10] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-10-10] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1049880 2015-10-10] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [448968 2015-10-10] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-10-10] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-10-10] (AVAST Software)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [30424 2015-04-17] (Sony Mobile Communications)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-09-01] (Intel Corporation)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] ()
R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [132656 2015-10-10] (AVAST Software)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-07-23] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47976 2015-07-02] (NVIDIA Corporation)
R3 pbfilter; C:\Program Files\PeerBlock\pbfilter.sys [22600 2014-01-14] ()
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 ssdevfactory; C:\Windows\System32\DRIVERS\ssdevfactory.sys [25088 2015-01-27] (SteelSeries ApS)
R3 sshid; C:\Windows\System32\DRIVERS\sshid.sys [42568 2015-02-26] (SteelSeries ApS)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [274336 2015-10-10] (Avast Software)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2015-11-06] ()
R3 ALSysIO; \??\C:\Users\Michael\AppData\Local\Temp\ALSysIO64.sys [X]
S3 BS680067079; \??\C:\Users\Michael\AppData\Local\Temp\NTFS.sys [X]
R3 WinRing0_1_2_0; \??\C:\Users\Michael\AppData\Local\Temp\tmpBFE5.tmp [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-07 08:12 - 2015-11-07 08:12 - 00034216 _____ C:\Users\Michael\Desktop\FRST.txt
2015-11-07 08:00 - 2015-11-07 08:00 - 00000000 ____D C:\Users\Michael\Desktop\FRST-OlderVersion
2015-11-07 07:23 - 2015-11-07 07:23 - 05481336 _____ (Avast Software s.r.o.) C:\Users\Michael\Desktop\avast_free_antivirus_setup_online_cnet.exe
2015-11-07 07:15 - 2015-11-07 07:15 - 05198336 _____ (AVAST Software) C:\Users\Michael\Desktop\aswMBR.exe
2015-11-06 13:46 - 2015-11-06 13:46 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2015-11-06 08:44 - 2015-11-06 08:44 - 00004096 _____ C:\ProgramData\sessionmsg_32.dll
2015-11-06 08:44 - 2015-11-06 08:44 - 00004096 _____ C:\ProgramData\igfxEM_32.exe
2015-11-06 08:43 - 2015-11-06 08:43 - 00090112 _____ C:\ProgramData\7B571D05.EX
2015-11-05 08:32 - 2015-11-05 08:32 - 00004096 _____ C:\ProgramData\openssl.exe
2015-11-05 08:31 - 2015-11-05 08:31 - 00004096 _____ C:\ProgramData\TabTip32.dll
2015-11-03 02:51 - 2015-11-03 02:51 - 00000000 ____D C:\Users\Michael\AppData\LocalLow\Obsidian Entertainment
2015-11-03 01:49 - 2015-11-03 02:47 - 00000000 ____D C:\Users\Michael\Documents\Tabletop RPGs
2015-11-02 09:24 - 2015-11-07 08:12 - 00000000 ____D C:\FRST
2015-11-01 17:48 - 2015-11-01 17:48 - 00000222 _____ C:\Users\Michael\Desktop\Pillars of Eternity.url
2015-11-01 17:10 - 2015-11-05 20:23 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-11-01 17:10 - 2015-11-01 17:10 - 00001768 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-11-01 17:10 - 2015-11-01 17:10 - 00000000 ____D C:\Users\Michael\AppData\Roaming\SUPERAntiSpyware.com
2015-11-01 17:10 - 2015-11-01 17:10 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2015-11-01 17:10 - 2015-11-01 17:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-11-01 17:07 - 2015-11-01 17:09 - 23758168 _____ (SUPERAntiSpyware) C:\Users\Michael\Desktop\SUPERAntiSpyware.exe
2015-11-01 17:04 - 2015-11-01 17:04 - 00022748 _____ C:\Users\Michael\Documents\cc_20151101_170432.reg
2015-11-01 11:21 - 2015-11-07 08:00 - 02198528 _____ (Farbar) C:\Users\Michael\Desktop\FRST64.exe
2015-10-31 17:23 - 2015-10-31 17:23 - 02924672 _____ (AVG Technologies) C:\Users\Michael\Desktop\AVG_Protection_Free_698.exe
2015-10-31 11:29 - 2015-10-31 11:29 - 00001055 _____ C:\Users\Michael\Desktop\TrojanHunter.lnk
2015-10-31 11:29 - 2015-10-31 11:29 - 00000000 ____D C:\ProgramData\TrojanHunter
2015-10-31 11:29 - 2015-10-31 11:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrojanHunter
2015-10-31 11:29 - 2015-10-31 11:29 - 00000000 ____D C:\Program Files (x86)\TrojanHunter
2015-10-31 10:57 - 2015-10-31 10:57 - 05693008 _____ (AVAST Software) C:\Users\Michael\Desktop\avast_free_antivirus_setup_online.exe
2015-10-31 06:21 - 2015-10-31 06:21 - 00005120 _____ C:\ProgramData\taskhost.exe
2015-10-31 06:20 - 2015-10-31 06:20 - 00004096 _____ C:\ProgramData\GheT3Z733AFC.dll
2015-10-31 06:17 - 2015-10-31 06:17 - 00004096 _____ C:\ProgramData\hTew6txG3AFC.dll
2015-10-31 06:16 - 2015-11-05 08:31 - 03550700 _____ C:\Windows\system32\CFG680067079
2015-10-31 05:50 - 2015-10-31 05:50 - 00450102 _____ C:\Users\Michael\AppData\Roaming\lqnqtgzk.exe
2015-10-31 05:49 - 2015-10-31 06:02 - 00000000 ____D C:\ProgramData\Linpal
2015-10-31 05:49 - 2015-10-31 05:50 - 00000000 ___HD C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}
2015-10-25 05:42 - 2015-10-31 05:59 - 00000000 ____D C:\Users\Michael\AppData\LocalLow\BitTorrent
2015-10-20 00:37 - 2015-10-20 00:37 - 00000000 ____D C:\Users\Michael\AppData\LocalLow\Thunder Lotus Games
2015-10-19 16:08 - 2015-10-19 16:47 - 1012445539 _____ C:\Users\Michael\Desktop\The Hobbit - An Unexpected Journey (2012).mp4
2015-10-19 15:52 - 2015-10-19 16:00 - 183041872 _____ C:\Users\Michael\Desktop\Wakfu Ova - 3.mp4
2015-10-19 15:34 - 2015-10-19 15:42 - 145438780 _____ C:\Users\Michael\Desktop\Wakfu Ova - 2.mp4
2015-10-19 15:27 - 2015-10-19 15:34 - 151873307 _____ C:\Users\Michael\Desktop\Wakfu Ova - 1.mp4
2015-10-18 16:37 - 2015-10-18 16:37 - 00000222 _____ C:\Users\Michael\Desktop\Jotun.url
2015-10-18 12:16 - 2015-11-07 06:46 - 00000000 ____D C:\Program Files\PeerBlock
2015-10-18 12:16 - 2015-10-18 12:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeerBlock
2015-10-17 02:18 - 2015-10-17 02:18 - 00000000 ____D C:\Users\Michael\AppData\Local\AnthophobiaSeptemberHotfix
2015-10-16 17:17 - 2015-10-16 17:17 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-10-14 18:20 - 2015-10-14 18:20 - 00002163 _____ C:\Users\Michael\Desktop\The Witcher® 3 - Wild Hunt.lnk
2015-10-11 07:25 - 2015-10-11 07:25 - 00000000 ____D C:\Users\Michael\AppData\Local\AnthophobiaSeptember
2015-10-10 06:23 - 2015-10-10 06:23 - 00378880 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-10-10 06:22 - 2015-10-10 06:22 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-07 08:09 - 2013-05-20 10:36 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Skype
2015-11-07 08:02 - 2015-06-15 20:45 - 00000926 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA.job
2015-11-07 08:00 - 2013-05-20 10:00 - 00621375 _____ C:\Users\Michael\Network_Meter_Data.js
2015-11-07 07:38 - 2013-05-19 21:13 - 02023512 _____ C:\Windows\WindowsUpdate.log
2015-11-07 07:33 - 2013-12-15 00:55 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA.job
2015-11-07 07:15 - 2013-05-19 21:33 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-07 07:13 - 2013-05-22 20:36 - 00000000 ____D C:\Users\Michael\AppData\Local\CrashDumps
2015-11-06 20:15 - 2013-05-19 21:33 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-06 13:58 - 2009-07-13 23:45 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-06 13:58 - 2009-07-13 23:45 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-06 13:50 - 2013-05-20 01:18 - 00000000 ___RD C:\Users\Michael\Dropbox
2015-11-06 13:49 - 2013-05-20 01:11 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Dropbox
2015-11-06 13:49 - 2013-05-19 22:36 - 00000000 ___RD C:\Users\Michael\Google Drive
2015-11-06 13:47 - 2014-06-11 15:11 - 00054919 _____ C:\Windows\setupact.log
2015-11-06 13:47 - 2013-05-20 00:12 - 00000000 ____D C:\Program Files (x86)\Steam
2015-11-06 13:46 - 2013-05-19 21:33 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys
2015-11-06 13:45 - 2015-04-10 16:32 - 00000000 ____D C:\ProgramData\NVIDIA
2015-11-06 13:45 - 2014-06-11 15:11 - 00437306 _____ C:\Windows\PFRO.log
2015-11-06 13:45 - 2013-05-20 01:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-06 13:45 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-06 13:33 - 2013-12-15 00:55 - 00000864 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core.job
2015-11-06 11:13 - 2015-06-15 20:45 - 00000874 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core.job
2015-11-05 16:43 - 2013-05-20 02:00 - 00000000 ____D C:\Users\Michael\AppData\Local\MediaMonkey
2015-11-05 15:03 - 2013-05-21 00:04 - 00000000 ____D C:\Users\Michael\AppData\Roaming\vlc
2015-11-05 14:38 - 2009-07-14 00:13 - 00783114 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-05 11:10 - 2013-05-23 18:26 - 00000000 ____D C:\Users\Michael\AppData\Roaming\CBLoader
2015-11-05 10:15 - 2014-08-31 08:36 - 00000000 ____D C:\Users\Michael\AppData\Local\Adobe
2015-11-05 10:09 - 2013-11-02 20:41 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-11-05 10:09 - 2013-11-02 20:41 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-05 09:31 - 2014-05-11 21:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-05 09:31 - 2013-05-20 01:20 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-11-05 09:31 - 2013-05-20 01:20 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-11-04 01:09 - 2013-05-20 11:20 - 00000030 _____ C:\Users\Michael\AppData\Roaming\Network Meter_Usage.ini
2015-11-03 02:40 - 2013-05-20 08:48 - 00001206 _____ C:\Users\Michael\Downloads\My Pictures.lnk
2015-11-02 00:45 - 2009-07-14 00:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-10-31 18:26 - 2013-05-19 21:34 - 00002284 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-10-31 18:04 - 2013-05-23 18:27 - 00000000 ____D C:\Users\Michael\AppData\Local\Wizards_of_the_Coast
2015-10-31 11:06 - 2015-03-10 18:14 - 00163748 _____ C:\Windows\DPINST.LOG
2015-10-31 10:58 - 2013-05-20 01:53 - 00000000 ____D C:\Users\Michael\AppData\Roaming\BitTorrent
2015-10-31 08:45 - 2015-05-19 00:07 - 00000000 ____D C:\Users\Michael\Documents\The Witcher 3
2015-10-30 17:06 - 2013-05-19 22:29 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-10-26 09:22 - 2015-05-13 10:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2015-10-25 06:48 - 2013-09-25 02:02 - 00000000 ____D C:\Users\Michael\AppData\Roaming\RenPy
2015-10-21 18:15 - 2013-05-19 22:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-10-19 15:15 - 2015-09-12 10:03 - 00000000 ____D C:\Users\Michael\AppData\Roaming\HandBrake
2015-10-16 06:33 - 2013-05-19 21:24 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-10-15 08:50 - 2014-09-20 05:37 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-10-10 06:23 - 2014-06-28 07:16 - 00153744 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-10-10 06:23 - 2014-06-28 07:16 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-10-10 06:23 - 2013-05-19 22:29 - 00448968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-10-10 06:23 - 2013-05-19 22:29 - 00274808 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-10-10 06:23 - 2013-05-19 22:29 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-10-10 06:23 - 2013-05-19 22:29 - 00090968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-10-10 06:23 - 2013-05-19 22:29 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-10-10 06:22 - 2015-08-26 11:55 - 00132656 _____ (AVAST Software) C:\Windows\system32\Drivers\ngvss.sys
2015-10-10 06:22 - 2013-05-19 22:29 - 01049880 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys

==================== Files in the root of some directories =======

2013-05-20 09:55 - 2014-06-11 14:30 - 0000576 _____ () C:\Users\Michael\AppData\Roaming\All CPU MeterV3_Settings.ini
2009-07-13 18:19 - 2009-07-13 20:14 - 0577536 _____ () C:\Users\Michael\AppData\Roaming\BackUp680067079.exe
2013-05-24 09:13 - 2013-05-24 09:14 - 0000839 _____ () C:\Users\Michael\AppData\Roaming\Drives Meter_Settings.ini
2013-05-20 09:46 - 2015-04-10 16:43 - 0000294 _____ () C:\Users\Michael\AppData\Roaming\GPU MeterV2_Settings.ini
2015-10-31 05:50 - 2015-10-31 05:50 - 0450102 _____ () C:\Users\Michael\AppData\Roaming\lqnqtgzk.exe
2013-05-20 11:20 - 2015-11-04 01:09 - 0000030 _____ () C:\Users\Michael\AppData\Roaming\Network Meter_Usage.ini
2015-11-06 08:43 - 2015-11-06 08:43 - 0090112 _____ () C:\ProgramData\7B571D05.EX
2015-10-31 06:20 - 2015-10-31 06:20 - 0004096 _____ () C:\ProgramData\GheT3Z733AFC.dll
2015-10-31 06:17 - 2015-10-31 06:17 - 0004096 _____ () C:\ProgramData\hTew6txG3AFC.dll
2015-11-06 08:44 - 2015-11-06 08:44 - 0004096 _____ () C:\ProgramData\igfxEM_32.exe
2015-11-05 08:32 - 2015-11-05 08:32 - 0004096 _____ () C:\ProgramData\openssl.exe
2015-11-06 08:44 - 2015-11-06 08:44 - 0004096 _____ () C:\ProgramData\sessionmsg_32.dll
2015-11-05 08:31 - 2015-11-05 08:31 - 0004096 _____ () C:\ProgramData\TabTip32.dll
2015-10-31 06:21 - 2015-10-31 06:21 - 0005120 _____ () C:\ProgramData\taskhost.exe

Files to move or delete:
====================
C:\ProgramData\GheT3Z733AFC.dll
C:\ProgramData\hTew6txG3AFC.dll
C:\ProgramData\igfxEM_32.exe
C:\ProgramData\openssl.exe
C:\ProgramData\sessionmsg_32.dll
C:\ProgramData\TabTip32.dll
C:\ProgramData\taskhost.exe
C:\Users\Michael\Network_Meter_Data.js


Some files in TEMP:
====================
C:\Users\Michael\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpx2hzqn.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-10-31 09:12

==================== End of FRST.txt ============================

 

 

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-11-2015
Ran by [removed] (2015-11-07 08:12:55)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium (X64) (2013-05-20 02:12:41)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-711289349-3085500364-3229847752-500 - Administrator - Disabled)
Guest (S-1-5-21-711289349-3085500364-3229847752-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-711289349-3085500364-3229847752-1023 - Limited - Enabled)
Michael (S-1-5-21-711289349-3085500364-3229847752-1000 - Administrator - Enabled) => C:\Users\Michael

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Abyss Odyssey (HKLM-x32\…\Steam App 255070) (Version:  - ACE Team)
Acrobat.com (HKLM-x32\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1.377 - Adobe Systems Incorporated)
Acrobat.com (x32 Version: 0.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.0.4990 - Adobe Systems Inc.)
Adobe Flash Player 19 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 19.0.0.226 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
AGEIA PhysX v7.11.13 (HKLM-x32\…\{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}) (Version: 7.11.13 - AGEIA Technologies, Inc.)
Alan Wake (HKLM-x32\…\Steam App 108710) (Version:  - Remedy Entertainment)
Anodyne (HKLM-x32\…\Steam App 234900) (Version:  - Sean Hogan and Jonathan Kittaka)
Apple Application Support (32-bit) (HKLM-x32\…\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{06A333EA-4E9D-4848-865F-FE5A1E12AB30}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.10.1.0 - Asmedia Technology)
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\…\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 1.3.1.000 - Asmedia Technology)
Assassin's Creed IV Black Flag (HKLM-x32\…\Steam App 242050) (Version:  - Ubisoft Montreal)
Avast Free Antivirus (HKLM-x32\…\avast) (Version: 10.4.2233 - AVAST Software)
Bionic Commando Rearmed (HKLM-x32\…\Steam App 21680) (Version:  - GRIN)
BitTorrent (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\BitTorrent) (Version: 7.9.5.41203 - BitTorrent Inc.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.8.5.1 - Broadcom Corporation)
Brütal Legend (HKLM-x32\…\Steam App 225260) (Version:  - Double Fine Productions)
Bully: Scholarship Edition (HKLM-x32\…\Steam App 12200) (Version:  - Rockstar New England)
Canon IJ Network Scan Utility (HKLM-x32\…\Canon_IJ_Network_Scan_UTILITY) (Version:  - )
Canon IJ Network Tool (HKLM-x32\…\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.)
Canon MP Navigator EX 3.1 (HKLM-x32\…\MP Navigator EX 3.1) (Version:  - )
Canon MX340 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX340_series) (Version:  - Canon Inc.)
Castlevania: Lords of Shadow – Mirror of Fate HD (HKLM-x32\…\Steam App 282530) (Version:  - MercurySteam)
Castlevania: Lords of Shadow - Ultimate Edition (HKLM-x32\…\Steam App 234080) (Version:  - MercurySteam - Climax Studios)
CCleaner (HKLM\…\CCleaner) (Version: 4.09 - Piriform)
CDisplayEx 1.10.29 (HKLM\…\CDisplayEx_is1) (Version:  - Progdigy Software S.A.R.L.)
ChromecastApp (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\{079ede36-133d-44b0-8053-c7c1fa8d2e0d}_is1) (Version: 1.5.1693.0 - Google Inc.)
ComicRack v0.9.156 (HKLM\…\ComicRack) (Version: v0.9.156 - cYo Soft)
Core Temp version 0.99.7 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 0.99.7 - Arthur Liberman)
CPUID CPU-Z 1.63.0 (HKLM\…\CPUID CPU-Z_is1) (Version:  - )
Creation Kit (HKLM-x32\…\Steam App 202480) (Version:  - bgs.bethsoft.com)
Creative ALchemy (HKLM-x32\…\ALchemy) (Version: 1.43 - Creative Technology Limited)
Creative Audio Control Panel (HKLM-x32\…\AudioCS) (Version: 2.56 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\…\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
CutePDF Writer 3.0 (HKLM\…\CutePDF Writer Installation) (Version:  3.0 - CutePDF.com)
Darkest Dungeon (HKLM-x32\…\Steam App 262060) (Version:  - Red Hook Studios)
DDS Viewer (HKLM-x32\…\{707333E0-C796-4E2D-B0DA-5A429706C361}_is1) (Version:  - IdeaMK)
Defraggler (HKLM\…\Defraggler) (Version: 2.16 - Piriform)
Deus Ex: Human Revolution - The Missing Link (HKLM-x32\…\Steam App 201280) (Version:  - Eidos Montreal)
Deus Ex: Human Revolution (HKLM-x32\…\Steam App 28050) (Version:  - Eidos Montreal)
Dishonored (HKLM-x32\…\Steam App 205100) (Version:  - Arkane Studios)
Divinity: Original Sin (HKLM-x32\…\Steam App 230230) (Version:  - Larian Studios)
Don't Starve (HKLM-x32\…\Steam App 219740) (Version:  - )
Don't Starve Together Beta (HKLM-x32\…\Steam App 322330) (Version:  - Klei Entertainment)
Driver Sweeper version 3.1.0 (HKLM-x32\…\{5A67D2EA-FB70-4033-A6F3-606AD85B2015}_is1) (Version: 3.1.0 - Phyxion.net)
Dropbox (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Dropbox) (Version: 3.10.8 - Dropbox, Inc.)
Dungeons & Dragons: Chronicles of Mystara (HKLM-x32\…\Steam App 229480) (Version:  - Iron Galaxy Studios)
Endless Space (HKLM-x32\…\Steam App 208140) (Version:  - Amplitude Studios)
Evoland (HKLM-x32\…\Steam App 233470) (Version:  - Shiro Games)
f.lux (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Flux) (Version:  - )
Far Cry® 3 Blood Dragon (HKLM-x32\…\Steam App 233270) (Version:  - Ubisoft Montreal)
FEZ (HKLM-x32\…\Steam App 224760) (Version:  - Polytron Corporation)
Five Nights at Freddy's (HKLM-x32\…\Steam App 319510) (Version:  - Scott Cawthon)
Foxit Cloud (HKLM-x32\…\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.5.129.617 - Foxit Corporation)
Foxit PhantomPDF Standard (HKLM-x32\…\{A652C696-8733-4681-820C-95465A19512B}) (Version: 6.2.1.618 - Foxit Corporation)
Foxit Reader (HKLM-x32\…\Foxit Reader_is1) (Version: 6.2.3.815 - Foxit Corporation)
FTL: Faster Than Light (HKLM-x32\…\Steam App 212680) (Version:  - Subset Games)
Game of Thrones - A Telltale Games Series (HKLM-x32\…\Steam App 330840) (Version:  - Telltale Games)
Gnomoria (HKLM-x32\…\Steam App 224500) (Version:  - Robotronic Games)
GOG Galaxy (HKLM-x32\…\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version:  - GOG.com)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 46.0.2490.80 - Google Inc.)
Google Drive (HKLM-x32\…\{9C350701-AC04-48BA-A435-BD5E0D82897E}) (Version: 1.25.0523.2491 - Google, Inc.)
Google Talk Plugin (HKLM-x32\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
Guacamelee! Gold Edition (HKLM-x32\…\Steam App 214770) (Version:  - DrinkBox Studios)
Guild Wars 2 (HKLM-x32\…\Guild Wars 2) (Version:  - NCsoft Corporation, Ltd.)
HandBrake 0.10.2 (HKLM-x32\…\HandBrake) (Version: 0.10.2 - )
Hitman: Absolution (HKLM-x32\…\Steam App 203140) (Version:  - Square Enix)
Hotline Miami (HKLM-x32\…\Steam App 219150) (Version:  - Dennaton Games)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1281 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.6.0.1030 - Intel Corporation)
Intel(R) Smart Connect Technology 2.0 x64 (HKLM\…\{D1B033E8-A077-4B0D-9831-5798E19E861E}) (Version: 2.0.1083.0 - Intel)
Intel(R) Update Manager (HKLM-x32\…\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation)
iTunes (HKLM\…\{5AC8E601-667F-4CA0-90D8-B25E1C4B3387}) (Version: 12.2.2.25 - Apple Inc.)
Java 7 Update 21 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417021FF}) (Version: 7.0.210 - Oracle)
Java 7 Update 65 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.650 - Oracle)
Jotun (HKLM-x32\…\Steam App 323580) (Version:  - Thunder Lotus Games)
King of Dragon Pass (HKLM-x32\…\Steam App 352220) (Version:  - A Sharp, LLC)
Left 4 Dead 2 (HKLM-x32\…\Steam App 550) (Version:  - Valve)
Legend of Dungeon (HKLM-x32\…\Steam App 238280) (Version:  - )
Legend of Grimrock (HKLM-x32\…\Steam App 207170) (Version:  - Almost Human Games)
Livestream Procaster (HKLM-x32\…\{68E4C751-272B-44E1-94C7-4E1FDC40F7DA}) (Version: 20.3.25 - Procaster)
Logitech Gaming Software 8.53 (HKLM\…\Logitech Gaming Software) (Version: 8.53.186 - Logitech Inc.)
LOOT (HKLM-x32\…\LOOT) (Version: 0.5.0 - LOOT Development Team)
Mad Max (HKLM-x32\…\Steam App 234140) (Version:  - Avalanche Studios)
Mark of the Ninja (HKLM-x32\…\Steam App 214560) (Version:  - Klei Entertainment)
Mars: War Logs (HKLM-x32\…\Steam App 232750) (Version:  - Spiders)
MediaMonkey 3.0 (HKLM-x32\…\MediaMonkey_is1) (Version: 3.0 - Ventis Media Inc.)
Microsoft .NET Framework 4.5.1 RC (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50861 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\…\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Middle-earth: Shadow of Mordor (HKLM-x32\…\Steam App 241930) (Version:  - Monolith Productions, Inc.)
Monaco (HKLM-x32\…\Steam App 113020) (Version:  - Pocketwatch Games)
Mount & Blade: Warband (HKLM-x32\…\Steam App 48700) (Version:  - Taleworlds Entertainment)
Mozilla Firefox 42.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 42.0 - Mozilla)
Nexus Mod Manager (HKLM\…\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.49.1 - Black Tree Gaming)
Nidhogg (HKLM-x32\…\Steam App 94400) (Version:  - Messhof)
NVIDIA 3D Vision Controller Driver 352.65 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 353.62 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.62 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.5.12.11 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.12.11 - NVIDIA Corporation)
NVIDIA Graphics Driver 353.62 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.62 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.3 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Octodad: Dadliest Catch (HKLM-x32\…\Steam App 224480) (Version:  - Young Horses)
Oddworld: Stranger's Wrath HD (HKLM-x32\…\Steam App 15750) (Version:  - )
OpenAL (HKLM-x32\…\OpenAL) (Version:  - )
OpenOffice 4.1.1 (HKLM-x32\…\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
Orcs Must Die! (HKLM-x32\…\Steam App 102600) (Version:  - )
Papers, Please (HKLM-x32\…\Steam App 239030) (Version:  - 3909)
PAYDAY 2 Beta (HKLM-x32\…\Steam App 246210) (Version:  - )
PeerBlock 1.2 (r693) (HKLM\…\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.2.0.693 - PeerBlock, LLC)
Pillars of Eternity (HKLM-x32\…\Steam App 291650) (Version:  - Obsidian Entertainment)
Prison Architect (HKLM-x32\…\Steam App 233450) (Version:  - Introversion Software)
Psychonauts (HKLM-x32\…\Steam App 3830) (Version:  - Double Fine Productions)
QuickTime 7 (HKLM-x32\…\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)
Raptr (HKLM-x32\…\Raptr) (Version:  - )
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6559 - Realtek Semiconductor Corp.)
Recettear: An Item Shop's Tale (HKLM-x32\…\Steam App 70400) (Version:  - EasyGameStation)
Recuva (HKLM\…\Recuva) (Version: 1.51 - Piriform)
Remember Me (HKLM-x32\…\Steam App 228300) (Version:  - DONTNOD Entertainment)
Reus (HKLM-x32\…\Steam App 222730) (Version:  - Abbey Games)
Revenge of the Titans (HKLM-x32\…\Steam App 93200) (Version:  - Puppygames)
Rogue Legacy (HKLM-x32\…\Steam App 241600) (Version:  - Cellar Door Games)
RollerCoaster Tycoon 3: Platinum! (HKLM-x32\…\Steam App 2700) (Version:  - Frontier)
Rust (HKLM-x32\…\Steam App 252490) (Version:  - Facepunch Studios)
Saints Row IV (HKLM-x32\…\Steam App 206420) (Version:  - Deep Silver Volition)
Seagate Dashboard (HKLM-x32\…\{F1D8690F-06B3-4100-9949-398EA253AC61}) (Version: 3.2.1802.2 - Seagate)
Shadowrun Returns (HKLM-x32\…\Steam App 234650) (Version:  - Harebrained Schemes)
Shadowrun: Dragonfall - Director's Cut (HKLM-x32\…\Steam App 300550) (Version:  - Harebrained Schemes)
SHIELD Streaming (Version: 4.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.5.12.11 - NVIDIA Corporation) Hidden
Shovel Knight (HKLM-x32\…\Steam App 250760) (Version:  - Yacht Club Games)
SimCity 4 Deluxe (HKLM-x32\…\Steam App 24780) (Version:  - Maxis)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation)
Skype™ 7.8 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
Sleeping Dogs: Definitive Edition (HKLM-x32\…\Steam App 307690) (Version:  - United Front Games)
Solar 2 (HKLM-x32\…\Steam App 97000) (Version:  - Murudai)
Sony Mobile Update Engine (HKLM-x32\…\Update Engine) (Version: 2.15.12.201508241237 - Sony Mobile Communications Inc.)
Sony PC Companion 2.10.289 (HKLM-x32\…\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.289 - Sony)
Starbound (HKLM-x32\…\Steam App 211820) (Version:  - )
Stardock Fences 2 (HKLM-x32\…\Stardock Fences 2) (Version: 2.10 - Stardock Software, Inc.)
State of Decay (HKLM-x32\…\Steam App 241540) (Version:  - Undead Labs)
Steam (HKLM-x32\…\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
SteelSeries Engine 3.3.5 (HKLM\…\SteelSeries Engine 3) (Version: 3.3.5 - SteelSeries ApS)
Styx: Master of Shadows (HKLM-x32\…\Steam App 242640) (Version:  - Cyanide Studio)
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1208 - SUPERAntiSpyware.com)
Surgeon Simulator 2013 (HKLM-x32\…\Steam App 233720) (Version:  - Bossa Studios)
TeamSpeak 3 Client (HKLM-x32\…\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH)
Terraria (HKLM-x32\…\Steam App 105600) (Version:  - )
Teslagrad Demo (HKLM-x32\…\Steam App 254560) (Version:  - Rain Games)
The Banner Saga (HKLM-x32\…\Steam App 237990) (Version:  - Stoic)
The Elder Scrolls V: Skyrim (HKLM-x32\…\Steam App 72850) (Version:  - Bethesda Game Studios)
The Forest (HKLM-x32\…\Steam App 242760) (Version:  - Endnight Games Ltd)
The Incredible Adventures of Van Helsing (HKLM-x32\…\Steam App 215530) (Version:  - NeocoreGames)
The Long Dark (HKLM-x32\…\Steam App 305620) (Version:  - Hinterland Studio Inc.)
The Secret World (HKLM-x32\…\Steam App 215280) (Version:  - Funcom)
The Stomping Land (HKLM-x32\…\Steam App 263440) (Version:  - SuperCrit)
The Walking Dead (HKLM-x32\…\Steam App 207610) (Version:  - )
The Walking Dead: Season Two (HKLM-x32\…\Steam App 261030) (Version:  - Telltale Games)
The Witcher 2 (HKLM-x32\…\{F0A209B7-7F85-4BDD-8F1F-B98EEAD9E04B}) (Version: 1.00.0000 - CD Projekt Red)
The Witcher 3 - Wild Hunt (HKLM-x32\…\1207664643_is1) (Version: 1.0.11.0 - GOG.com)
The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\…\Free DLC program (16 DLC)_is1) (Version: 1.0.10.0 - GOG.com)
The Witcher 3: Wild Hunt - Hearts of Stone (HKLM-x32\…\Hearts of Stone_is1) (Version: 1.0.10.0 - GOG.com)
They Bleed Pixels (HKLM-x32\…\Steam App 211260) (Version:  - Spooky Squid Games Inc.)
Tiny Barbarian DX (HKLM-x32\…\Steam App 253350) (Version:  - StarQuail Games)
Transistor (HKLM-x32\…\Steam App 237930) (Version:  - Supergiant Games)
TrojanHunter 6.0 (HKLM-x32\…\TrojanHunter_is1) (Version: 6.0 - Bytelayer AB)
TrueCrypt (HKLM-x32\…\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation)
Unity Web Player (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Universe Sandbox (HKLM-x32\…\Steam App 72200) (Version:  - )
Uplay (HKLM-x32\…\Uplay) (Version: 4.0 - Ubisoft)
Vessel (HKLM-x32\…\Steam App 108500) (Version:  - Strange Loop Games)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
Westerado: Double Barreled (HKLM-x32\…\Steam App 275200) (Version:  - Ostrich Banditos)
Wrye Bash (HKLM-x32\…\Wrye Bash) (Version: 3.0.4.3 - Wrye & Wrye Bash Development Team)
XCOM: Enemy Unknown (HKLM-x32\…\Steam App 200510) (Version:  - Firaxis Games)
YTD Video Downloader 3.9.6 (HKLM-x32\…\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 3.9.6 - GreenTree Applications SRL) <==== ATTENTION

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)

==================== Restore Points =========================

03-11-2015 00:00:01 Scheduled Checkpoint

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0D4A090F-45E6-49F6-8E99-D4143E5C7CF4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd)
Task: {0F957854-886F-4E17-A16E-EC9963D4F94D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {15A32B57-F7EC-4074-8CF3-DBE82298BCA4} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {342162CA-FE1A-409B-B90D-165197BEF325} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {3A470D43-598A-4DA7-85E0-1F91C6FC20E1} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-15] (Dropbox, Inc.)
Task: {3FD19CAF-79FA-4128-8ADE-14ED21F59E7B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {51F539DE-1094-42FA-B9EB-E4C5BDB231BF} - System32\Tasks\Seagate_Install_Launch => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Dashboard.exe [2014-09-17] (Seagate Technology LLC)
Task: {57949803-E7D2-42CE-B7DB-DBBBB72C01AD} - System32\Tasks\avastBCLRestartS-1-5-21-711289349-3085500364-3229847752-1000 => Chrome.exe
Task: {58B115B6-5368-48DE-AE63-51104E35C1F2} - System32\Tasks\PCMeter\Startup => C:\Users\Michael\Downloads\Windows Gadgets\PCMeterV0.3.exe [2013-03-16] (AddGadgets)
Task: {5C3CF947-1A17-4C66-A4F9-FCC2F6B0E13C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {74E23625-8490-4549-AF10-B725E1D84562} - System32\Tasks\Michael DBAgent 2 0 => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [2014-09-17] (Seagate Technology LLC)
Task: {8DCBEDAB-8C7E-4FDB-AB91-B732F25CEBDE} - System32\Tasks\{3293F118-F9C1-4AE8-A5E9-8FC2FB983B1E} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver;=5.1.0.112.259&LastError;=404
Task: {C878D5D1-3D09-4B73-91A9-1F6548A3C935} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-15] (Dropbox, Inc.)
Task: {E00BC2BE-876C-4E47-AEED-34B14441164F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {EE7B33BE-B506-4785-93AB-67F2B2490C0C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {F5DA27E1-A8AF-4E28-AB21-2BDC29352C3E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-10-10] (AVAST Software)
Task: {FF866CD3-75FF-4980-A7D8-9AE602EC7A52} - System32\Tasks\Core Temp Autostart => C:\Program Files\Core Temp\Core Temp.exe [2010-07-02] ()

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core.job => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA.job => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core.job => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA.job => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2013-05-20 01:29 - 2012-10-04 18:49 - 00087152 _____ () C:\Windows\System32\cpwmon64.dll
2015-04-10 16:31 - 2015-07-22 20:31 - 00116368 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-05-20 09:42 - 2010-07-02 12:52 - 00530448 _____ () C:\Program Files\Core Temp\Core Temp.exe
2012-02-09 15:26 - 2012-02-09 15:26 - 00133632 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
2012-02-09 15:26 - 2012-02-09 15:26 - 00048128 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll
2012-02-09 15:26 - 2012-02-09 15:26 - 00036864 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetDetect.dll
2014-07-02 16:54 - 2014-07-02 16:54 - 00866584 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2014-07-02 16:59 - 2014-07-02 16:59 - 01050904 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-07-02 16:54 - 2014-07-02 16:54 - 00059160 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2014-07-02 16:59 - 2014-07-02 16:59 - 00242456 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2015-10-31 06:20 - 2015-10-31 06:20 - 00004096 _____ () C:\ProgramData\GheT3Z733AFC.dll
2015-11-05 08:32 - 2015-11-05 08:32 - 00004096 _____ () C:\ProgramData\openssl.exe
2015-11-06 08:44 - 2015-11-06 08:44 - 00004096 _____ () C:\ProgramData\igfxEM_32.exe
2013-05-20 09:41 - 2013-05-20 09:41 - 00012520 _____ () C:\Users\Michael\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\CoreTempReader.dll
2013-05-20 09:41 - 2013-05-20 09:41 - 00015080 _____ () C:\Users\Michael\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\GetCoreTempInfoNET.dll
2013-05-20 09:41 - 2013-05-20 09:41 - 00014056 _____ () C:\Users\Michael\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\SystemInfo.dll
2015-03-10 18:13 - 2015-06-10 10:13 - 00113024 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
2015-03-05 13:04 - 2015-03-05 13:04 - 18305024 _____ () C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe
2015-03-05 11:44 - 2015-03-05 11:44 - 00047616 _____ () C:\Program Files\SteelSeries\SteelSeries Engine 3\x2api.dll
2015-02-13 04:20 - 2015-02-13 04:20 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2015-05-15 15:27 - 2015-05-15 15:27 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-05-18 07:55 - 2015-07-23 23:22 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2013-04-23 17:30 - 2015-10-05 11:18 - 00778752 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-01-19 15:21 - 2015-07-03 11:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-01-19 15:21 - 2015-07-03 11:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-01-19 15:21 - 2015-07-03 11:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2014-05-21 17:32 - 2015-11-05 11:44 - 02541648 _____ () C:\Program Files (x86)\Steam\video.dll
2014-08-28 16:50 - 2015-09-23 19:33 - 02549248 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2014-08-28 16:51 - 2015-09-23 19:33 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2014-08-28 16:51 - 2015-09-23 19:33 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2014-08-28 16:51 - 2015-09-23 19:33 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2014-08-28 16:51 - 2015-09-23 19:33 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2013-05-03 14:35 - 2015-11-05 11:44 - 00806992 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2015-07-22 07:06 - 2015-11-03 17:00 - 00201728 _____ () C:\Program Files (x86)\Steam\bin\openvr_api.dll
2015-03-10 18:13 - 2012-04-30 10:57 - 00039936 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll
2015-03-10 18:13 - 2014-12-04 14:18 - 00241152 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll
2011-07-07 13:54 - 2011-07-07 13:54 - 00233984 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\Report.dll
2015-03-10 18:13 - 2013-05-20 11:58 - 00620718 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\sqlite3.dll
2015-03-23 18:19 - 2015-03-23 18:19 - 02620416 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\libxt.dll
2015-03-10 18:13 - 2015-04-21 12:22 - 00053248 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\VObject.dll
2015-07-23 08:21 - 2015-07-23 08:21 - 00802304 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PhoneUpdate.dll
2013-05-19 22:00 - 2009-02-06 17:52 - 00073728 _____ () C:\Windows\SysWOW64\CmdRtr.DLL
2013-05-19 22:00 - 2009-07-10 08:07 - 00166912 _____ () C:\Windows\SysWOW64\APOMngr.DLL
2015-11-06 13:49 - 2015-11-06 13:49 - 00071168 _____ () c:\users\michael\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpx2hzqn.dll
2015-03-04 16:45 - 2015-09-23 18:07 - 00012800 _____ () C:\Users\Michael\AppData\Roaming\Dropbox\bin\QtQuick.2\qtquick2plugin.dll
2015-03-04 16:45 - 2015-09-23 18:07 - 00779776 _____ () C:\Users\Michael\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-07-30 05:11 - 2015-09-23 18:07 - 00056320 _____ () C:\Users\Michael\AppData\Roaming\Dropbox\bin\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-03-04 16:45 - 2015-09-23 18:07 - 00012288 _____ () C:\Users\Michael\AppData\Roaming\Dropbox\bin\QtQuick\Window.2\windowplugin.dll
2015-11-06 13:47 - 2015-11-06 13:47 - 00098816 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32api.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00110080 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\pywintypes27.dll
2015-11-06 13:47 - 2015-11-06 13:47 - 00364544 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\pythoncom27.dll
2015-11-06 13:47 - 2015-11-06 13:47 - 00046080 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_socket.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 01208320 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_ssl.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00320512 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32com.shell.shell.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00776704 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_hashlib.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 01176576 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._core_.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00806400 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._gdi_.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00816128 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._windows_.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 01067008 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._controls_.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00733184 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._misc_.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00682496 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\pysqlite2._sqlite.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00088064 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_ctypes.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00119808 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32file.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00108544 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32security.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00007168 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\hashobjs_ext.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00070144 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\usb_ext.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00167936 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32gui.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00018432 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32event.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00128512 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_elementtree.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00127488 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\pyexpat.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00013824 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\common.time34.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00036864 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_psutil_windows.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00038912 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32inet.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00011264 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32crypt.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00077312 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._html2.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00027136 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_multiprocessing.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00020480 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_yappi.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00035840 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32process.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00686080 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\unicodedata.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00123392 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._wizard.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00024064 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32pipe.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00010240 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\select.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00025600 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32pdh.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00525640 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\windows._lib_cacheinvalidation.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00017408 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32profile.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00022528 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32ts.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00078848 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._animate.pyd
2013-03-26 15:16 - 2015-10-08 17:20 - 45010208 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2013-05-19 21:26 - 2012-07-18 05:55 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2015-11-05 10:09 - 2015-11-05 10:09 - 17599688 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: ehRecvr => 3
MSCONFIG\Services: ehSched => 3
MSCONFIG\Services: IAStorDataMgrSvc => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BitTorrent => "C:\Users\Michael\AppData\Roaming\BitTorrent\BitTorrent.exe"  /MINIMIZED
MSCONFIG\startupreg: Chrome => C:\PROGRA~3\taskhost.exe
MSCONFIG\startupreg: DelaypluginInstall => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
MSCONFIG\startupreg: GalaxyClient => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Raptr => C:\PROGRA~2\Raptr\raptrstub.exe –startup
MSCONFIG\startupreg: Wondershare Helper Compact.exe => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{05E4EBCA-C57B-40F1-9177-185411F87E77}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{914BEBC3-B713-4A32-90E7-672B4C49D402}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A0B47EE0-EBB5-44D4-80F4-3C6EC767A64C}] => (Allow) C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{38EB4404-D701-4EC7-8BF9-45DE9642A14C}] => (Allow) C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{C383AABC-B8C3-481A-8110-76D5088AE1ED}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mars War Logs\MarsWarLogs.exe
FirewallRules: [{8EAC8079-443B-4F00-BE7B-FEAB7BCA7C06}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mars War Logs\MarsWarLogs.exe
FirewallRules: [{EA85749C-AC6B-4A3B-855E-D67B074B2EA0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{8A7AC821-160F-4400-AAF8-E347F1AA6C79}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{A2730E6D-2A20-40F6-A3FE-DAB8E5377F0B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{AA37EF3F-996E-4AAC-A6B5-0F038107E4E3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{AB07BE16-CAFA-4E5C-953C-1655B5766C6F}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{E94A15CB-C4F5-4F13-9D51-E7EA9F77D6CF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Universe Sandbox\Universe Sandbox.exe
FirewallRules: [{06ABF9D4-83CE-4C9E-B8DF-9C651D7975DC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Universe Sandbox\Universe Sandbox.exe
FirewallRules: [{4CD1733C-B92A-4741-9881-D563CAFD8BF9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [{2BEFE624-91A1-4D74-87AC-A84270D20B61}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [TCP Query User{860B1408-7727-4A0B-8A0C-D715525F7E12}C:\program files (x86)\guild wars 2\gw2.exe] => (Allow) C:\program files (x86)\guild wars 2\gw2.exe
FirewallRules: [UDP Query User{35FC3E26-8EAF-4D11-8095-02C8F58779CC}C:\program files (x86)\guild wars 2\gw2.exe] => (Allow) C:\program files (x86)\guild wars 2\gw2.exe
FirewallRules: [{2777BC3B-CD1F-4601-A020-19A001B994D5}] => (Block) C:\program files (x86)\guild wars 2\gw2.exe
FirewallRules: [{F7E26BBD-D5C7-4A4C-9DA3-44498E066615}] => (Block) C:\program files (x86)\guild wars 2\gw2.exe
FirewallRules: [TCP Query User{3EB9D856-069D-41EF-AF6C-25C6552E905A}C:\program files\comicrack\comicrack.exe] => (Allow) C:\program files\comicrack\comicrack.exe
FirewallRules: [UDP Query User{2D9C4F63-2E51-481A-9793-DDD38B0B39C8}C:\program files\comicrack\comicrack.exe] => (Allow) C:\program files\comicrack\comicrack.exe
FirewallRules: [{CADF2C72-2D00-4C2A-B964-838F9F13D049}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stranger's Wrath\Launcher.exe
FirewallRules: [{68174B03-A249-4BAC-ADFE-9224BEECA6F5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stranger's Wrath\Launcher.exe
FirewallRules: [TCP Query User{518B102D-0A33-4B42-B3E2-9F770CCC9B42}C:\program files (x86)\the witcher 2\bin\witcher2.exe] => (Allow) C:\program files (x86)\the witcher 2\bin\witcher2.exe
FirewallRules: [UDP Query User{740DC195-6EC6-4BF5-AEB1-17B5C1F1D9F2}C:\program files (x86)\the witcher 2\bin\witcher2.exe] => (Allow) C:\program files (x86)\the witcher 2\bin\witcher2.exe
FirewallRules: [{C4D20F6D-32F7-4041-A1CE-4FE76FB14115}] => (Block) C:\program files (x86)\the witcher 2\bin\witcher2.exe
FirewallRules: [{34ED931F-4B87-4BDF-AB41-F65DCE20201A}] => (Block) C:\program files (x86)\the witcher 2\bin\witcher2.exe
FirewallRules: [{FAC03BA6-EB65-454A-BD4E-76B6F4C01260}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman Absolution\HMA.exe
FirewallRules: [{552AA8D9-D665-4C27-BDA1-716A8F8D34B7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman Absolution\HMA.exe
FirewallRules: [{23CC9AB4-82C0-4378-AAA0-57EA90C809D1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Orcs Must Die!\Build\release\OrcsMustDie.exe
FirewallRules: [{372B9023-5063-4EDD-9107-B44C7051B9AB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Orcs Must Die!\Build\release\OrcsMustDie.exe
FirewallRules: [{4CD95026-7545-4216-8671-ADBC3940000F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{3E89A720-4CF7-408C-92E9-DFCDEB36BB99}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{248FF237-F533-4AAF-954F-89DCEFDBF555}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DXHRML\dxhrml.exe
FirewallRules: [{05A1EB00-A348-4DDA-AB69-5C5040E54069}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DXHRML\dxhrml.exe
FirewallRules: [{6D2BC6AD-FAA5-4EA1-B1AD-35CF75EC259F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{9372880A-9C54-4560-A1BA-611E2C25C3CE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{E1DB4F9D-3F63-4889-AC94-869F5F6825BE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Solar 2\Solar2.exe
FirewallRules: [{41D8264F-30D2-45E5-831C-6603EF7D18CC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Solar 2\Solar2.exe
FirewallRules: [{7B4DEC19-6D34-41EB-A91D-5E61F503A0CE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{D81B03B2-F0A2-47FB-B258-01D7F3EDFAA0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{D5498855-7030-461F-A63C-B6BD3EA61597}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SimCity 4 Deluxe\Apps\SimCity 4.exe
FirewallRules: [{6127BBA0-AA25-44A2-AFC1-FDE11B3D3A4D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SimCity 4 Deluxe\Apps\SimCity 4.exe
FirewallRules: [{0AFBEFBD-1095-4DB5-9D3B-EEBE9A9D3A55}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SimCity 4 Deluxe\Support\EA Help\Electronic_Arts_Technical_Support.htm
FirewallRules: [{DD104EFF-F941-40FA-9114-F0D433F337A3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SimCity 4 Deluxe\Support\EA Help\Electronic_Arts_Technical_Support.htm
FirewallRules: [{9D876EB8-6CBE-4C51-B15C-2ED7A7963968}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{B472472A-30BA-438F-87C5-FC6419F168C3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{40E8FAD2-1760-4655-BD7F-1DB46E702333}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Vessel\Vessel.exe
FirewallRules: [{183D35CA-6AB8-4C71-B962-0ECFAE37380B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Vessel\Vessel.exe
FirewallRules: [{5671CADD-778A-46CD-909B-00E18A31C200}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [{35D6C2A6-D006-41CA-AC11-BFD5F863D720}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [TCP Query User{AD0B3509-FE5B-4995-BAD6-CB4D0F560226}C:\users\michael\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\michael\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{4920CAF0-9327-4573-88BB-3E36DF24DDFE}C:\users\michael\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\michael\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{A8F7925F-5696-4E29-9711-78718EFB650A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Evoland\Evoland.exe
FirewallRules: [{7D6083C0-7619-456A-8E23-2798484086CA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Evoland\Evoland.exe
FirewallRules: [{8DBC9887-DBC5-44C3-B4FD-A807FA205424}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{861839DF-BB83-4A30-B478-7D903A051310}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{ABC9CD25-F127-42EC-A843-C40BD33EC16D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{345709F5-0D46-4EF7-9A28-B9DD01FE7272}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{74B30CD5-A13E-42C5-A0B1-5A6CDE80CEDC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PAYDAY 2 Beta\payday2_win32_release.exe
FirewallRules: [{B3A38D75-4C70-43EB-ABC8-00C4777584F9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PAYDAY 2 Beta\payday2_win32_release.exe
FirewallRules: [{739F455D-7B73-4BDA-A7EC-E048CCA3C39C}] => (Allow) C:\Users\Michael\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{F436C41C-1AE2-4C99-AF32-1670B03BDEA2}] => (Allow) C:\Users\Michael\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{998522F3-CFED-4981-B5B8-BB67224CDE55}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{D6094518-E50F-4FF4-A1A8-2F9121B4C825}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{591A937E-B916-4A83-A765-FA989A974E5D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Recettear\recettear.exe
FirewallRules: [{3E89B2A3-E04B-4C5D-BF32-EE6C24DD9ECC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Recettear\recettear.exe
FirewallRules: [{D0A5B849-D13A-4AC3-A6B1-A0768695095C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Recettear\custom.exe
FirewallRules: [{78478DF9-32B1-4FF5-9B63-A39226CF649B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Recettear\custom.exe
FirewallRules: [{ECD57D71-4B2A-4F14-B231-82DAC7AA9CFE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\they bleed pixels\They Bleed Pixels PC.exe
FirewallRules: [{E8D8F371-5D92-4CE5-B7D9-37711F4C329D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\they bleed pixels\They Bleed Pixels PC.exe
FirewallRules: [{43B5B143-648D-4ABB-8695-0196B8782EA7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Anodyne\Anodyne.exe
FirewallRules: [{DCE88040-DDFA-4CE1-91DF-229610B57C82}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Anodyne\Anodyne.exe
FirewallRules: [{3D7D3609-DCCA-4FDE-A928-C12CD1458C16}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\hotline_miami\HotlineMiami.exe
FirewallRules: [{A1009040-0CDF-4B58-B9C2-9E73A92FCC8C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\hotline_miami\HotlineMiami.exe
FirewallRules: [{261C641E-3E7F-4405-A017-4A6A41E16936}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mars War Logs\MarsWarLogs.exe
FirewallRules: [{CE5BA647-9259-4EF8-A9B6-C3C69709D8A6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mars War Logs\MarsWarLogs.exe
FirewallRules: [{149B886E-9B9D-47F7-83FE-0F210BC9525D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FEZ\FEZ.exe
FirewallRules: [{04DD1099-3D72-4B1F-B5E0-522EE8E493B5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FEZ\FEZ.exe
FirewallRules: [{2B9DCC28-C957-4E54-8F27-89EBA0991B0B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FEZ\FEZ_LaunchOptions.exe
FirewallRules: [{69BCF071-B000-49D1-9713-4D2A0EA5B527}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FEZ\FEZ_LaunchOptions.exe
FirewallRules: [{E94B8BBE-0A04-40DA-976F-36AA32DF9E89}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe
FirewallRules: [{BAADD635-1719-49D6-8A73-BAC5355A0064}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe
FirewallRules: [{29788CF0-34F8-4370-B91F-0FB89380DCD6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BrutalLegend\BrutalLegend.exe
FirewallRules: [{9ADF23EE-AD7D-44B8-ACC1-8E7C28EDAC34}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BrutalLegend\BrutalLegend.exe
FirewallRules: [{53647FAC-FDBC-481E-948D-CF71587E6565}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Psychonauts\Psychonauts.exe
FirewallRules: [{400E7940-EAA5-439A-B939-4E8B144E6CF1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Psychonauts\Psychonauts.exe
FirewallRules: [TCP Query User{BE268B43-A686-47C6-B920-07B6E49B3B7B}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe
FirewallRules: [UDP Query User{84A1D798-2F90-47A9-9149-8C275FB1FB01}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe
FirewallRules: [{A6D8696E-8ADB-493C-A8BE-110DC6EEC2B0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TinyBarbarianDX\TinyBarbarianDX.exe
FirewallRules: [{76D3CC44-00CD-461D-9F19-DA59ABD9639B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TinyBarbarianDX\TinyBarbarianDX.exe
FirewallRules: [{0D16C20E-20B9-417D-BA95-EC4ABE96FF96}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{CE55B0E0-2692-40B1-9713-B4F2EA77C2D5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{1431A38A-A3EF-4FC7-9C98-53661531DF0F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{22BA6799-D4ED-445F-882C-4430DC7CE8F6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{C17443F3-BECB-4442-9A5F-88B759D24A1B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{F6215155-BF3C-49AE-A0A6-FE141A5F28ED}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{D83A9F4C-32C6-43A7-83B9-4285FA580D82}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{00187EEB-73B2-47FE-B6DF-F6ABAED5E69F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{D11C4900-E94A-4C5B-9168-AC71F147C784}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{055624DE-AAA5-4457-BAE7-53B7DD70EF2F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{4580A8D2-A66C-49B5-AEDD-E4F7F63AC34B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{BCA794AF-C5AF-4E77-A32A-CBC733C3E51E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{61351BF9-8C10-4146-BC00-BE25EAA7B574}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Reus\Reus.exe
FirewallRules: [{EA7B5A19-D915-4B7A-AFFE-A3D7F8B62647}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Reus\Reus.exe
FirewallRules: [{0D7DD702-A4F0-4503-AD65-D30629D133BF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{DAD3AB89-D096-4577-AFA1-8AD954F8003A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{93D0B68D-91BC-43DD-A974-D71A6F49E785}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{984C4DC0-438D-4A38-8CBF-4132F429C056}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{ADD23156-0388-4CD6-8055-6CF33567D1A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{5F492B42-0CFC-476E-B916-3A02B5926B28}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{84A41741-14F6-4CB2-ABD6-E61470950590}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{5BC6EEF3-51C8-4382-9FD6-D7AC223991AB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{631E53AF-AF11-428C-9BBF-8226DC5CF56E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{6242DACA-065C-4DAF-A844-70C2907CAAB6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{4D2CA06A-8246-4384-AC28-9C3A5767BDC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{0AC26730-F9C9-4526-B6EA-95252A9374A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{96E6B832-7FBA-42B6-B869-ECD63B7DD363}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{9B73CF88-60AC-44A2-A178-33ADB1460660}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{B1F5FCF1-8CA5-44A6-AE12-3DC0A763170A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{4E02F8D7-65D0-4C69-A11E-C8A4D1071A13}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{F0E0944C-A16F-46EB-8352-86A4B28939E1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bully Scholarship Edition\Bully.exe
FirewallRules: [{545EF150-A3C1-47A0-97BD-072FF1F3EE3A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bully Scholarship Edition\Bully.exe
FirewallRules: [{8344233C-D3AA-4074-8687-32275011D2E8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Revenge of the Titans\RevengeOfTheTitans.exe
FirewallRules: [{29A7B73C-4DCD-4E6F-8A50-F92742E1CE44}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Revenge of the Titans\RevengeOfTheTitans.exe
FirewallRules: [{F4E42AE8-ED6B-4AD5-9615-F081FB277FB0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{567600D7-B716-4BEB-B48D-C619A01FFA5E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{16980C10-0B61-45C3-A206-F9D94E9327B5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{A81C9B0F-5420-4285-8241-5AA3CA2C200C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{0DFD1DE4-6E35-408D-B5D2-6FF089B58ADA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{6C3F9D3C-5FA2-44B0-BE41-A08C227D8FD7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{035BBE4C-8F4F-4908-B3D0-D826C87FC030}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Teslagrad Demo\Teslagrad.exe
FirewallRules: [{C6F61136-9C7E-4A8D-B6DD-763F44A71616}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Teslagrad Demo\Teslagrad.exe
FirewallRules: [{7C5C9F88-68E7-46B2-A4B8-F5488B76F77E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{1B4866CA-A71A-406E-9A87-C320C53988CD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{4F7026F3-CBDE-407F-BA79-470EBCAB8619}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{5F582107-5D58-4B65-8E8E-DB7235D07AAF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{4966B9D4-7751-45FF-8307-F57F4902AC3D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [{F67DD270-8426-4630-B4EE-3C3E818123A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [{7B0152D6-343D-49C3-AC86-250EA259F7FF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [{AFDB25EA-E151-4709-B955-A783BA4587C2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [{005EBE35-1526-4F4A-BE7A-650AC45E6601}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead\WalkingDead101.exe
FirewallRules: [{2DC710F7-3AF9-4A8B-9DF5-5A8B68AB66A8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead\WalkingDead101.exe
FirewallRules: [{49CDA40F-FA4D-435E-BC3E-73CF39E023C4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{1CA8B212-DFEC-4A69-9E61-CE4EC7287B8B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{0AC53880-8D92-4A0D-AFB5-D65406ED6642}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon.exe
FirewallRules: [{49108D75-33BA-422A-82D8-5E6635EB4E0A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon.exe
FirewallRules: [TCP Query User{A6666B70-2CB1-48B7-9666-6769E211EE87}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{67116663-9DEA-4FD3-8529-58773AE4801B}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [{675D4C0A-223C-41C8-860F-57A8C409FCE0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Revenge of the Titans\RevengeOfTheTitans.exe
FirewallRules: [{7FB47CA4-E65E-4E9C-9D74-9CDA6F0D35FC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Revenge of the Titans\RevengeOfTheTitans.exe
FirewallRules: [TCP Query User{277D869B-B211-4209-9883-1537CE7EE878}C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe
FirewallRules: [UDP Query User{B7BA912C-C22D-4FE7-BFB9-6C0E9213A62F}C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe
FirewallRules: [{76963B55-F543-4A03-9D92-8311BB710817}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{6A59C68C-9410-4C66-9626-0E198853F65F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{E5561779-571E-49F2-BC4F-5190108F9946}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Guacamelee\Guac.exe
FirewallRules: [{541958EF-9175-4AEE-AF16-EA3AE855FFC1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Guacamelee\Guac.exe
FirewallRules: [{D45832D9-5291-4F64-813A-12F303FB38E7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{6FB5B177-87C3-4F81-A8C0-405A78295EE6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{256FA3B3-007C-4908-A175-B63560109BF2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{1DB4BA76-1A3E-4E07-B7F4-70159752D788}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{C4C85C24-41A0-4BE9-865A-E6BE9FC94FA2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{05517B17-D0E3-4162-BAC2-FB9CBE878002}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{E03CB1E3-7009-4327-B37D-64113BA3509B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{035A53A3-4AE4-4E0E-90B4-6B3961F2CCB8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{956BFC5A-91F2-42CA-8569-97CFF66F990F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon.exe
FirewallRules: [{948B9DFF-B00A-4671-82C5-EA38750B6EFF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon.exe
FirewallRules: [{71825292-E4C2-4030-B556-A2F6C81BBCEB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{E9813D0A-442F-4C72-A496-BC3BACC1E079}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{8894FA8B-E6E0-4F08-B9DF-C52AE5DEA010}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{FEE5AE00-96BE-4015-908C-0A45D0D478A7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{9198D856-3DE3-451E-9CB3-BFF8BAA1F9C7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\rust\rust.exe
FirewallRules: [{8558D261-17E8-4956-A97A-9A7ECA30C469}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\rust\rust.exe
FirewallRules: [{DA18CBB9-C25D-4113-8521-7EBC838B8C2F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{939C0611-9882-42BA-99EC-3FB06EC7A193}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{490CF8FF-4CCC-48F5-90E7-0739D26C5588}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{65691E96-6BB5-41E6-8A96-8CA5B1B71E9E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{E78D3DF8-F338-4B1A-B0F0-1B451377A5C0}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{1BB640A1-67A0-4E29-B11A-C9121811D286}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{9BE0B95A-593F-437F-AE35-D28D0D247404}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{4D2CF2F7-5193-49D6-9AC1-E9CAE29C191F}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{B2F0C57C-D80D-4E56-9A28-AD0E1B345472}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Secret World\ClientPatcher.exe
FirewallRules: [{623FD171-6F74-457B-9AA4-D9B6B73A823B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Secret World\ClientPatcher.exe
FirewallRules: [{E745A027-D954-47A6-8323-C2BFDA4730D4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Returns\Shadowrun.exe
FirewallRules: [{83110B5D-EC90-4FDC-BF20-586D634EBEB1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Returns\Shadowrun.exe
FirewallRules: [{57AEB719-D9D5-4558-8D81-7B7FA8ACA547}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Remember Me\Binaries\Win32\RememberMe.exe
FirewallRules: [{7419AC9F-C509-4A33-AC01-FB041F4D7339}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Remember Me\Binaries\Win32\RememberMe.exe
FirewallRules: [{F5440DDF-B7C0-43E3-9BF2-B03EC6511FB4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rogue Legacy\RogueLegacy.exe
FirewallRules: [{7F6727D4-241E-450E-8418-145C81A4C291}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rogue Legacy\RogueLegacy.exe
FirewallRules: [{ABA4D3E8-BDA8-4730-91CC-F71CAFBE04C3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Surgeon Simulator 2013\ss2013.exe
FirewallRules: [{66A0AA82-B89C-4087-B245-C50449845E4F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Surgeon Simulator 2013\ss2013.exe
FirewallRules: [{B53E401F-3BD6-4CFF-97EF-6D94AADDC974}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Octodad Dadliest Catch\OctodadDadliestCatch.exe
FirewallRules: [{57D24C64-BF7D-446E-B0CA-750308DFB15C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Octodad Dadliest Catch\OctodadDadliestCatch.exe
FirewallRules: [{5135B711-8DFB-4AE9-8A66-B0F37D47B034}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{65D52BB1-59B0-41E8-A1FD-865BA821EB47}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{4F2CCA0F-E188-48DC-B417-49DDA2EA36F3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe
FirewallRules: [{F2E80592-E87F-4C6D-9402-8DBF3AA944AC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe
FirewallRules: [{5CDF5E1C-6C43-417A-B092-7075190D68DD}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{1A626A54-B0EA-41A6-899B-D6FA00CC49EF}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{6ABA6768-DB08-41FF-A5E6-B2E3DD1258CB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Legend of Grimrock\grimrock.exe
FirewallRules: [{EB99D301-3D59-4E4E-891D-D2D284580687}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Legend of Grimrock\grimrock.exe
FirewallRules: [{7D80C5DD-59B1-4A33-A254-EB4465469683}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Five Nights at Freddy's\FiveNightsatFreddys.exe
FirewallRules: [{9D569C15-B2A1-4242-AD9A-87DCC081639F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Five Nights at Freddy's\FiveNightsatFreddys.exe
FirewallRules: [{ADBC0EE5-952B-4D2C-976F-102A384E483E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Transistor\x64\Transistor.exe
FirewallRules: [{B10A9BBE-9124-4AC9-8C61-F50FB8EC7E73}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Transistor\x64\Transistor.exe
FirewallRules: [{88B22EEC-D0E1-4895-BAC3-36A1ABA90739}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dungeons & Dragons HD\ManaGame.exe
FirewallRules: [{72AFBF8D-5876-4EA7-A8AF-5D9C2B86FDE7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dungeons & Dragons HD\ManaGame.exe
FirewallRules: [{0FCAD903-8AEB-4CD8-9612-6BEC56A6CF03}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bionic Commando Rearmed\bcr.exe
FirewallRules: [{A3F977A7-8389-4779-A295-6D5B292413C8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bionic Commando Rearmed\bcr.exe
FirewallRules: [{E80A1482-4FE9-4C01-A34E-B31E5E8B1C52}] => (Allow) LPort=8888
FirewallRules: [TCP Query User{DC6EB690-B1C0-455E-8568-4FF05069AF93}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe
FirewallRules: [UDP Query User{C145E381-435A-48DA-A03E-89833C064CFD}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe
FirewallRules: [{A3493FF8-7648-4EEA-8D28-B7F5CBAD80DE}] => (Allow) LPort=8888
FirewallRules: [{783871DC-416A-45DD-9381-2AD54A660D8D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Nidhogg\Nidhogg.exe
FirewallRules: [{62DA9F5A-49A1-4A2F-AE2D-E470C9CAA507}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Nidhogg\Nidhogg.exe
FirewallRules: [{401E1439-562B-4E40-9C0F-46C97425C726}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Castlevania Lords of Shadow - Mirror of Fate HD\CMOF.exe
FirewallRules: [{A7FE8355-02C7-49F5-93C9-5A7F12091672}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Castlevania Lords of Shadow - Mirror of Fate HD\CMOF.exe
FirewallRules: [{5FD90A0F-4F57-4398-98D0-3AC14030EA20}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{2454A98A-ADAE-478C-89AF-5EBBF252AE15}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{C96F1FFE-B008-410A-A216-D0D4A893B3A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\CastlevaniaLoS\bin\CastlevaniaLoSUE.exe
FirewallRules: [{55998790-537E-4591-AD29-DDDC0E1BD4D3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\CastlevaniaLoS\bin\CastlevaniaLoSUE.exe
FirewallRules: [{EA63ABC7-1A27-42B3-AFFF-E63243EE6992}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Styx\Binaries\Win64\StyxGame.exe
FirewallRules: [{1187E46D-A5D0-4BBC-84B0-86EF4A4C7F2F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Styx\Binaries\Win64\StyxGame.exe
FirewallRules: [{CBCC9230-C6FF-4B7F-B2EB-DFD21ACC1DE6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\CreationKit.exe
FirewallRules: [{6FF2407B-1773-4F5F-9B13-A81B1602497C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\CreationKit.exe
FirewallRules: [{73628E4D-E334-43F2-B531-1BFB5F756017}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Gnomoria\Gnomoria.exe
FirewallRules: [{17CEDEC4-5F4C-4D81-81EF-6BA1DCE71F53}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Gnomoria\Gnomoria.exe
FirewallRules: [{D13D0ED7-E074-429D-B7B9-964CC845D5E8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Dragonfall Director's Cut\Dragonfall.exe
FirewallRules: [{9C648C06-14C8-4C54-A726-232A762A7679}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Dragonfall Director's Cut\Dragonfall.exe
FirewallRules: [{A5843F24-9CA4-4514-AB13-315FBEBB677E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SleepingDogsDefinitiveEdition\sdhdship.exe
FirewallRules: [{7476A0AF-768C-46C5-AF1D-4853A96DE7F6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SleepingDogsDefinitiveEdition\sdhdship.exe
FirewallRules: [{260640F9-754F-4FB5-9399-7FEFCB5C9E56}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TheLongDark\tld.exe
FirewallRules: [{E73316FF-35F3-442C-9055-856910642354}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TheLongDark\tld.exe
FirewallRules: [{A1FA3210-2371-45F8-8EE4-5EB9E20D5A74}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Game of Thrones\Thrones.exe
FirewallRules: [{2613920A-4169-446A-83C5-77B49748CB36}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Game of Thrones\Thrones.exe
FirewallRules: [{18189144-BCB0-4B7A-8770-6DDBB13CC69E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2CD312BA-A096-43DE-BC59-C74636E08E27}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BF287FAB-ACF3-4BD0-84F0-D87283E230BD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{13C909C5-3284-442D-A8B7-B4657BE45DF7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{B3511193-4F80-4A14-94AB-FEC2B6775062}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{794906FD-513D-424A-8280-235D3AC9F07A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CC7AC7E4-91E4-4A6B-BFE5-9DB6FCDA6C3C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Stomping Land\Binaries\Win32\UDK.exe
FirewallRules: [{74A367C8-8636-47A5-B718-9991075E95DA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Stomping Land\Binaries\Win32\UDK.exe
FirewallRules: [{46DD5DDD-DCF6-4FFD-AB5C-A2CD983A7C17}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon_DirectToRift.exe
FirewallRules: [{86F9C0D8-F274-4C49-BA2C-940420F8F9C6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon_DirectToRift.exe
FirewallRules: [{FC534A64-151E-4BB0-A60B-4237CD70C5A4}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{0AE60447-4C7C-4E59-803B-8C984C0D7330}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{8FD55EEA-D5FA-49D1-AA12-912A763CC5AA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Divinity - Original Sin\Shipping\EoCApp.exe
FirewallRules: [{9C1C11E1-A17F-446E-A29D-F040FE10F2F8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Divinity - Original Sin\Shipping\EoCApp.exe
FirewallRules: [{637AFE18-3A5A-4DB9-893E-D70B5E38A7F1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{849BE47D-5D53-43AC-B3CD-6B4F634737CC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{1E10D591-1225-4C06-8CA7-CBE2AE5BA108}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Westerado\WesteradoDB.exe
FirewallRules: [{81A6F3EF-C172-4E86-840C-D47A92EA5535}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Westerado\WesteradoDB.exe
FirewallRules: [{D4D74FB1-40AF-4C86-9ABC-14AC918869F1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shovel Knight\ShovelKnight.exe
FirewallRules: [{811447FF-E3EA-47C5-8B98-E5913A198FC4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shovel Knight\ShovelKnight.exe
FirewallRules: [{20DCC540-BD28-4594-AB4F-B1494502B1A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\tbs\win32\The Banner Saga.exe
FirewallRules: [{92E3D3CE-BDD9-42D7-87B1-00406E7D082B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\tbs\win32\The Banner Saga.exe
FirewallRules: [{F97414AB-9DAA-48C7-A084-4CFE513B8C89}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{A7A21066-E01E-4E9F-A4E2-FDB256BDE37A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{AA8E2CA5-F9D1-4F0C-8A2B-7BA2216A44DE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{7EAF95F2-FF25-418F-BF85-9F223024F427}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{DBE35B99-CC5D-483E-A7A4-07FB68A9E8D4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{1FB15D9F-2F78-4332-B5C9-734D0AFC81DB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King of Dragon Pass\King of Dragon Pass.exe
FirewallRules: [{96757209-E0AD-4F9E-A081-709A193395C1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King of Dragon Pass\King of Dragon Pass.exe
FirewallRules: [{ACAAC47B-D4A8-4D69-AA54-31C52540F41D}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{C41E96BD-AD69-4347-971D-0711EBBF8A21}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe
FirewallRules: [{16502BD0-DFE2-4A45-8534-4FAAF5C1C72B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe
FirewallRules: [{85A13C50-7B47-4252-AE44-B20EC4C83730}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mad Max\MadMax.exe
FirewallRules: [{060DE892-77C2-4186-95B7-DDA33A6AB224}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mad Max\MadMax.exe
FirewallRules: [{9DAED1AB-7C3E-4B27-9C58-85E9E1A13D71}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\abyss_odyssey\Binaries\Win32\AO.exe
FirewallRules: [{B7AB5A7A-1992-446E-A23D-D8BEEA97F9B5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\abyss_odyssey\Binaries\Win32\AO.exe
FirewallRules: [{038E478A-CCAB-4D4A-B354-60F8018C3E74}] => (Allow) C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe
FirewallRules: [{C2CA25B1-BEA2-4611-9665-09D8AE08E8A7}] => (Allow) C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe
FirewallRules: [{3E9008D6-44F9-492F-9130-8EB087F8A2E6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{4B5DB14B-5900-40F1-A54E-62F4DEBC0678}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{130EC5B6-F741-40ED-B9D3-9AC0FA1D348A}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{662E4177-72FA-4EF2-9E1C-C34E105A2889}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{DA6BDAD2-9CFD-4961-9D6A-C9B25D429728}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DarkestDungeon\_windows\Darkest.exe
FirewallRules: [{DBA37D16-2BF1-4737-B8A6-96107A61A7FB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DarkestDungeon\_windows\Darkest.exe
FirewallRules: [{E9352C7B-B1A3-4936-89F9-88B7BE6FFAC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Jotun\Jotun.exe
FirewallRules: [{FB5D96A0-BED4-4E7A-BB3D-E1904FECAFF5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Jotun\Jotun.exe
FirewallRules: [{05BFD149-BB97-4FDC-9A63-A4C5C18CD8BA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{D4F1CE35-7BA3-4152-B695-1F2B68358A61}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Pillars of Eternity\PillarsOfEternity.exe
FirewallRules: [{6B93DB34-131E-48C1-A3D7-F26D4786745E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Pillars of Eternity\PillarsOfEternity.exe
FirewallRules: [{338260AB-8949-4BAA-83D3-9BFCB4D4D732}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1BCFC91E-B5B7-48E7-89C8-DF3160A4F5D2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Faulty Device Manager Devices =============

Name: Video Controller
Description: Video Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/07/2015 08:10:03 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16483 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1e34

Start Time: 01d119580edca39b

Termination Time: 7

Application Path: C:\Program Files (x86)\Internet Explorer\iexplore.exe

Report Id: da381cff-8550-11e5-bbaa-bc5ff4abb4c9

Error: (11/07/2015 07:37:14 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16483 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 2838

Start Time: 01d11958ea24d0a2

Termination Time: 14

Application Path: C:\Program Files (x86)\Internet Explorer\iexplore.exe

Report Id: 4468b728-854c-11e5-bbaa-bc5ff4abb4c9

Error: (11/07/2015 07:13:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 46.0.2490.80, time stamp: 0x56262c73
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x10006c13
Faulting process id: 0x2620
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3

Error: (11/07/2015 07:12:51 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 46.0.2490.80, time stamp: 0x56262c73
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x10006c13
Faulting process id: 0x2a7c
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3

Error: (11/07/2015 07:11:57 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 46.0.2490.80, time stamp: 0x56262c73
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x10006c13
Faulting process id: 0x2ac4
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3

Error: (11/07/2015 07:07:24 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 46.0.2490.80, time stamp: 0x56262c73
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x10006c13
Faulting process id: 0x260c
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3

Error: (11/07/2015 06:56:01 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16483 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 26a4

Start Time: 01d11952b140d6a5

Termination Time: 17

Application Path: C:\Program Files (x86)\Internet Explorer\iexplore.exe

Report Id: 8168d724-8546-11e5-bbaa-bc5ff4abb4c9

Error: (11/07/2015 06:51:39 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 46.0.2490.80, time stamp: 0x56262c73
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x10006c13
Faulting process id: 0x2c94
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3

Error: (11/07/2015 06:51:28 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 46.0.2490.80, time stamp: 0x56262c73
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x10006c13
Faulting process id: 0x2c8c
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3

Error: (11/06/2015 05:38:21 PM) (Source: SideBySide) (EventID: 63) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.


System errors:
=============
Error: (11/06/2015 02:05:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The WinRing0_1_2_0 service failed to start due to the following error:
%%2

Error: (11/06/2015 01:54:10 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Windows Update service hung on starting.

Error: (11/06/2015 01:45:44 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Avast Antivirus service failed to start due to the following error:
%%1053

Error: (11/06/2015 01:45:44 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Avast Antivirus service to connect.

Error: (11/06/2015 01:45:39 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 1:43:36 PM on ‎11/‎6/‎2015 was unexpected.

Error: (11/05/2015 05:25:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Steam Client Service service failed to start due to the following error:
%%1053

Error: (11/05/2015 05:25:11 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.

Error: (11/05/2015 08:31:49 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.

Error: (11/05/2015 08:31:48 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.

Error: (11/05/2015 08:27:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The WinRing0_1_2_0 service failed to start due to the following error:
%%2


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz
Percentage of memory in use: 31%
Total physical RAM: 16267.12 MB
Available physical RAM: 11156.68 MB
Total Virtual: 32534.23 MB
Available Virtual: 27373.99 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:20.32 GB) NTFS
Drive i: (Ginnungagap) (Fixed) (Total:3726.02 GB) (Free:2671.08 GB) NTFS
Drive j: (MULTIBOOT) (Removable) (Total:0.91 GB) (Free:0.89 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: FFC0A867)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
Attempted reading MBR returned 0 bytes.
 Could not read MBR for disk 1.

========================================================
Disk: 2 (Size: 931 MB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================

Hello MisterCynic

Welcome to What the Tech. I am Marie Curie and will gladly help you with any malware-related problems.

I am currently in training at WhatTheTech and every post of mine will be approved by a teacher. This leads to a delay in my response time. I will return as soon as possible with instructions. Please familiarize yourself with the following ground rules in the meanwhile.

  • Read my instructions thoroughly, carry out each step in the given order.
  • Do not make any changes to your system, or run any tools other than those I provided. Do not delete, fix, uninstall, or install anything unless I tell you to.
  • If you are unsure about anything or if you encounter any problems, please stop and inform me about it.
  • Stick with me until I tell you that your computer is clean. Absence of symptoms does not mean that your computer is free of malware.
  • Back up important files before we start.

Hello MisterCynic.

 

I see that you have TrueCrypt installed. Is this program currently in use?

 

STEP 1

[external image: 2NquDoJ.png] RKill

  • Please download RKill and save the file to your Desktop.
  • Right-Click RKill.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • A black Command Prompt window will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • Note: Please do NOT reboot your computer until you have carried out the steps below.
  • A log (C:\rkill.log) will open once the scan has completed. Copy the contents of the log and paste in your next reply.

STEP 2
[external image: YARWD1t.png] TDSSKiller Scan

  • Please download TDSSKiller and save the file to your Desktop.
  • Right-Click TDSSKiller.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Change parameters. Place a checkmark next to Detect TDLFS file system and Verify file digital signatures.
  • ​Click Start Scan. Do not use the computer during the scan.
  • If objects are found, change the action to skip.
  • Click Continue and close the window.
  • A log will be created and saved to the root directory (usually C:\). Attach (not copy/paste) the file in your next reply.
     

======================================================
 
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs.

  • RKill log
  • TDSSKiller log (attached!)

No, TrueCrypt isn't in use.  I forgot I even had that installed.

 

I've downloaded the file to desktop but I'm getting the same issue as the aswMBR; neither RKill or TDSSKiller will run.

Hello MisterCynic.

 

Please read the following warnings before you proceed.

 

Quote

[external image: goGMWSt.gif]BACKDOOR WARNING
——————————
 
One or more of the identified infections is known to use a backdoor, that allows attackers to remotely control your computer, download/execute files and steal system, financial & personal information.
 
If your computer has been used for online banking, has credit card information or other sensitive data, using a non-infected computer/device you should immediately change all account information (including those used for Email, eBay, Paypal, online forums, etc).
 
Banking and credit card institutions should be notified of the possible security breach. Please read the following article for more information: How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
 
Whilst the identified infection(s) can be removed, there is no way to guarantee the trustworthiness of your computer unless you reformat your Hard Drive and reinstall your Operating System. This is due to the nature of the infection, which allows a remote attacker to make any number of modifications. Many experts in the security community believe that once infected with this type of malware, the best course of action is to reformat/reinstall. Please read the following articles for more information.

  • When should I re-format? How should I reinstall?
  • Help: I Got Hacked. Now What Do I Do?
  • Where to draw the line? When to recommend a format and reinstall?

You now have the choice between cleaning the infection(s) present or reformatting your computer. Ultimately, the decision is personal, and what you're most comfortable with. Once you've read the articles linked above, let me know if you have any questions, and how you wish to proceed.

 

Quote

 

[external image: goGMWSt.gif]P2P Warning
——————————

I see you have peer-to-peer (P2P) file sharing software installed on your computer (uTorrent). I advise you avoid P2P file sharing programmes; they are a security risk which can make your computer susceptible to malware. File sharing networks are thoroughly infested with malware - worms, backdoor Trojans, IRCBots, and rootkits propagate via P2P file sharing networks, gaming, and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install malware. The best way to reduce the risk of infection is to avoid these types of web sites and P2P programmes. Please read the following articles for more information.

  • Risks of File-Sharing Technology
  • P2P Software User Advisories
  • More malware is traveling on P2P networks these days

Your P2P software can be removed by following the instructions below.

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search for the aforementioned programme(s), right-click and click Uninstall. Follow the prompts.

If you choose not to, please refrain from using the programme(s) during this process.

 

 

Step 1

[external image: MgeHyNE.png] Boot into Safe Mode

  • Restart your PC.
  • As soon as the BIOS is loaded, begin repeatedly tapping the F8 key until the Advanced Options menu appears.  
  • Using the arrow keys, select Safe Mode. 
  • Press the Enter key.

 

Step 2
Renaming TDSSKiller

  • Please download TDSSKiller
  • Before saving to your Desktop, please rename TDSSKiller to iexplore.exe. << Important!
  • Now save iexplore.exe to your desktop.
  • Continue with the instructions below.

[external image: YARWD1t.png] TDSSKiller Scan

  • Right-Click iexplore.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Change parameters. Place a checkmark next to Detect TDLFS file system and Verify file digital signatures.
  • ​Click Start Scan. Do not use the computer during the scan.
  • If objects are found, change the action to skip.
  • Click Continue and close the window.
  • A log will be created and saved to the root directory (usually C:\). Attach (not copy/paste) the file in your next reply.
     

======================================================
 
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs.

  • TDSSKiller log (attached!)
Do you mean to start in safe mode with networking, because I can't download anything in safe mode. Or should I just rename the copy of TDSSKiller I've already downloaded?
Seems safe mode with networking doesn't work anyway. The system blue screens before windows even boots up. So should I just rename the file in regular safe mode?

Hi MisterCynic.

Please do Step 1 in Safe Mode again.

 

STEP 1
[external image: YARWD1t.png] TDSSKiller Fix

  • Right-Click TDSSKiller.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Change parameters. Ensure a checkmark is placed next to:
    • Loaded Modules
    • Detect TDLFS file system
    • Verify file digital signatures
  • ​Click Start Scan. Do not use the computer during the scan.
  • Upon completion, select copy to quarantine for the following items: aspnet_wp_64
    openssl
    igfxEM_32

    BackUp680067079
  • Select Cure for the following items \Device\Harddisk0\DR0\Partition1
  • Click Continue and close the window. 
  • A log will be created and saved to the root directory (usually C:\). Attach the log in your next reply.

Please start into Normal Mode (not Safe Mode) for Step 2.

 

STEP 2
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Scan

  • Double-Click FRST64.exe to run the programme.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Attach the logs in your next reply.

======================================================
 
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs.

  • FRST.txt
  • Addition.txt
  • TDSSKiller log
Okay, so I tried running TDSSKiller(now named iexplore) in safe mode again, but it wouldn't run again. I renamed it back to TDSSKiller.exe, restarted in safe mode, and renamed it to iexplore.exe once again. Seems I need to do this every time to run it.

Now when I selected change parameters and check loaded modules, it told me I need to install an extended monitoring driver, then restart. I allowed it to do this, but upon restart it said the drivers have failed to load and windows can't find {F8B79F2B-3963-4312-858E}.exe or {59535D07-S7C2-4A88-86A1}.exe.

I tried repeating this whole process on a normal boot (just renaming TDSSKiller from it's original name to the alternate lets me run it even out of safe mode) but I'm getting the same results. So I just can't use the check loaded modules function. How should I proceed?

Hi MisterCynic.

 

Run it without the loaded modules. It might not find every item that I listed, but deal with the ones that are there as described above.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-11-2015

Ran by [removed] (administrator) on YMIR (17-11-2015 08:51:50)

Running from C:\Users\[removed]\Desktop

[removed]

Platform: Windows 7 Home Premium (X64) Language: English (United States)

Internet Explorer Version 9 (Default browser: Opera)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe

(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(AddGadgets) C:\Users\Michael\Downloads\Windows Gadgets\PCMeterV0.3.exe

() C:\Program Files\Core Temp\Core Temp.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe

(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe

(Foxit Corporation) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe

(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe

() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe

(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe

(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe

(Microsoft Corporation) C:\Windows\System32\rundll32.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe

() C:\ProgramData\aspnet_wp_64.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

() C:\ProgramData\openssl.exe

(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe

() C:\ProgramData\igfxEM_32.exe

(Microsoft Corporation) C:\Windows\System32\regsvr32.exe

(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe

(Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe

() C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe

(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe

(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe

(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe

(Flux Software LLC) C:\Users\Michael\AppData\Local\FluxSoftware\Flux\flux.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe

(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe

() C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe

(CANON INC.) C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe

(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe

(Dropbox, Inc.) C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe

(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DeviceAgent.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe

(Raptr, Inc) C:\Program Files (x86)\Raptr\raptr.exe

(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe

(Raptr, Inc) C:\Program Files (x86)\Raptr\raptr_im.exe

(Raptr Inc.) C:\Program Files (x86)\Raptr\raptr_ep64.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe

(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe

(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe

(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe

 

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [aspnet_wp_64] => C:\ProgramData\aspnet_wp_64.exe [4096 2015-11-10] ()

HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart

HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12446824 2012-01-31] (Realtek Semiconductor)

HKLM\…\Run: [openssl] => C:\ProgramData\openssl.exe [4096 2015-11-05] ()

HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634896 2015-07-23] (NVIDIA Corporation)

HKLM\…\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10464536 2014-07-02] (Logitech Inc.)

HKLM\…\Run: [igfxEM_32] => C:\ProgramData\igfxEM_32.exe [4096 2015-11-06] ()

HKLM\…\Run: [GheT3Z733AFC] => regsvr32.exe /s "C:\PROGRA~3\GheT3Z733AFC.dll"

HKLM\…\Run: [Fences] => C:\Program Files (x86)\Stardock\Fences\Fences.exe [4013744 2013-04-25] (Stardock Corporation)

HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-26] (Intel Corporation)

HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)

HKLM-x32\…\Run: [P17RunE] => RunDll32 P17RunE.dll,RunDLLEntry

HKLM-x32\…\Run: [IJNetworkScanUtility] => C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [206240 2010-08-23] (CANON INC.)

HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)

HKLM-x32\…\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe

HKLM-x32\…\Run: [DBAgent] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [1518664 2014-09-17] (Seagate Technology LLC)

HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Uploader] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe [127080 2014-09-17] (Seagate Technology LLC)

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3011152 2015-11-09] (Valve Corporation)

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [457088 2015-09-23] (Sony)

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [48138880 2015-10-14] (Skype Technologies S.A.)

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55360 2014-05-14] (Raptr, Inc)

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [PeerBlock] => C:\Program Files\PeerBlock\peerblock.exe [2513992 2014-01-14] (PeerBlock, LLC)

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [IequGrufh] => regsvr32.exe "C:\ProgramData\Linpal\BufqOvba.dll"

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22568216 2015-10-12] (Google)

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Google Update] => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-31] (Google Inc.)

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [f.lux] => C:\Users\Michael\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Dropbox Update] => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-15] (Dropbox, Inc.)

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [RSA680067079] => C:\Windows\system32\rundll32.exe "C:\Users\Michael\AppData\Roaming\Microsoft\Crypto\RSA\RSA680067079.dll",DllInitialize <===== ATTENTION

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\MountPoints2: {d61fb579-c776-11e4-bcd3-bc5ff4abb4c9} - I:\Startme.exe

HKU\S-1-5-18\…\Run: [Chrome] => C:\ProgramData\taskhost.exe [5120 2015-10-31] ()

ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-10-12] (Google)

ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-10-12] (Google)

ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-10-12] (Google)

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-10-10] (AVAST Software)

ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-11-04] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-11-04] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-11-04] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-11-04] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File

ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-11-04] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-11-04] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-11-04] (Dropbox, Inc.)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2015-04-10]

ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe ()

Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-11-11]

ShortcutTarget: Dropbox.lnk -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{6228E9D9-CFC6-4C51-A1BD-1A5005A37E14}: [DhcpNameServer] 192.168.1.1

 

Internet Explorer:

==================

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage;=hxxp://go.microsoft.com/fwlink/?LinkId=69157

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage;=hxxp://go.microsoft.com/fwlink/?LinkId=69157

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage;=hxxps://search.yahoo.com/?type=282369&fr;=spigot-yhp-ie

SearchScopes: HKU\S-1-5-21-711289349-3085500364-3229847752-1000 -> DefaultScope {E65363E6-EB13-4F01-836F-A169301AD9A0} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei;=utf-8&ilc;=12&type;=282369&p;={searchTerms}

SearchScopes: HKU\S-1-5-21-711289349-3085500364-3229847752-1000 -> {E65363E6-EB13-4F01-836F-A169301AD9A0} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei;=utf-8&ilc;=12&type;=282369&p;={searchTerms}

BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-05-27] (Oracle Corporation)

BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-26] (AVAST Software)

BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)

BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-05-27] (Oracle Corporation)

BHO-x32: No Name -> {451C804F-C205-4F03-B48E-537EC94937BF} -> No File

BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-11] (Oracle Corporation)

BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-26] (AVAST Software)

BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)

BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-11] (Oracle Corporation)

Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File

DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab

DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab

DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab

Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)

Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)

Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 -  No File

 

FireFox:

========

FF ProfilePath: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default

FF DefaultSearchEngine: Google

FF DefaultSearchEngine.US: Google

FF Homepage: hxxp://en.wikipedia.org/wiki/Main_Page

FF Session Restore: -> is enabled.

FF Keyword.URL: hxxps://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&ilc;=12&type;=282369&p;=

FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll [2015-11-08] ()

FF Plugin: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\system32\npDeployJava1.dll [2013-05-27] (Oracle Corporation)

FF Plugin: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-05-27] (Oracle Corporation)

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)

FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-11-08] ()

FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-07-30] ()

FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-04-23] (Foxit Corporation)

FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-04-23] (Foxit Corporation)

FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)

FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)

FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)

FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)

FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-11] (Oracle Corporation)

FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-07-11] (Oracle Corporation)

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)

FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-07-22] (NVIDIA Corporation)

FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-07-22] (NVIDIA Corporation)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)

FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)

FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)

FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Michael\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)

FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @talk.google.com/O1DPlugin -> C:\Users\Michael\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)

FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)

FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)

FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Michael\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-07-20] (Unity Technologies ApS)

FF user.js: detected! => C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\user.js [2015-07-10]

FF Plugin ProgramFiles/Appdata: C:\Users\Michael\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)

FF Plugin ProgramFiles/Appdata: C:\Users\Michael\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)

FF SearchPlugin: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\searchplugins\yahoo_ff.xml [2014-07-12]

FF Extension: Cookies Manager+ - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\Extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d} [2015-05-31]

FF Extension: ExHentai Easy 2 - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\Extensions\[removed] [2015-08-31]

FF Extension: Showcase - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\Extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}.xpi [2015-05-31]

FF Extension: Adblock Plus - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-25]

FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-10-08] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF

FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-10-10] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\ProgramData\Wondershare\Video Converter Ultimate\[removed] => not found

 

Chrome:

=======

CHR HomePage: Default -> hxxp://en.wikipedia.org/

CHR StartupUrls: Default -> "hxxp://www.hotmail.com/"

CHR Session Restore: Default -> is enabled.

CHR Profile: C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default

CHR Extension: (Google Slides) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-12]

CHR Extension: (Entanglement Web App) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd [2013-11-24]

CHR Extension: (Tab Expose) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ackpfhlmgjdjlohhjmbacaajbmkkklnp [2013-05-19]

CHR Extension: (Angry Birds) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2014-12-14]

CHR Extension: (TooManyTabs for Chrome) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\amigcgbheognjmfkaieeeadojiibgbdp [2014-06-11]

CHR Extension: (Google Docs) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-12]

CHR Extension: (Google Drive) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-25]

CHR Extension: (YouTube) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]

CHR Extension: (Sad Panda) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\bohapeiooecafommnlaiccilacgmkaoc [2014-08-30]

CHR Extension: (Adblock Plus) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-09-25]

CHR Extension: (Google Search) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-30]

CHR Extension: (Google Sheets) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-12]

CHR Extension: (Google Analytics Opt-out Add-on (by Google)) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\fllaojicojecljbmefodhfapmkghcbnh [2014-10-03]

CHR Extension: (IBA Opt-out (by Google)) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbiekjoijknlhijdjbaadobpkdhmoebb [2013-08-23]

CHR Extension: (Chuck Anderson) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gegkoiakifeoejnjkbnnojkkdoegeofp [2014-11-20]

CHR Extension: (Google Docs Offline) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-05]

CHR Extension: (AdBlock) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-10-18]

CHR Extension: (Desktop Notifications for Android) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\giicnncicnopjohcpamieklkiacdoeni [2015-08-29]

CHR Extension: (Avast Online Security) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-10-31]

CHR Extension: (TabJump - Intelligent Tab Navigator) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokofmgcicpnjchllaccgedmmmbbnbmf [2013-05-19]

CHR Extension: (Cookie Manager) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbnfbcpkiaganjpcanopcgeoehkleeck [2014-08-30]

CHR Extension: (Poppit!) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi [2014-07-17]

CHR Extension: (Ghostery) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2015-09-20]

CHR Extension: (Chrome Web Store Payments) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-28]

CHR Extension: (Gmail) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]

CHR HKU\S-1-5-21-711289349-3085500364-3229847752-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Michael\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-19]

CHR HKU\S-1-5-21-711289349-3085500364-3229847752-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-01]

CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]

 

==================== Services (Whitelisted) ========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)

S4 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-10-10] (AVAST Software)

S4 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4048280 2015-10-10] (Avast Software)

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)

R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)

S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [238376 2015-07-23] (EasyAntiCheat Ltd)

R2 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [242216 2014-06-17] (Foxit Corporation)

S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1616440 2015-10-18] (GOG.com)

S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6952504 2015-10-18] (GOG.com)

R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155216 2015-07-23] (NVIDIA Corporation)

R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-05] (Intel Corporation)

R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] ()

S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)

R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation)

R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1871504 2015-07-23] (NVIDIA Corporation)

R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544592 2015-07-23] (NVIDIA Corporation)

R2 Seagate Dashboard Services; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe [16000 2014-09-17] (Seagate Technology LLC)

R2 Seagate MobileBackup Service; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe [157776 2014-09-17] (Seagate Technology LLC)

R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation)

 

===================== Drivers (Whitelisted) ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-10-10] (AVAST Software)

R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-10-10] (AVAST Software)

R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-10-10] (AVAST Software)

R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-10-10] (AVAST Software)

R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1049880 2015-10-10] (AVAST Software)

R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [448968 2015-10-10] (AVAST Software)

R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-10-10] (AVAST Software)

R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-10-10] (AVAST Software)

S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)

S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [30424 2015-04-17] (Sony Mobile Communications)

R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-09-01] (Intel Corporation)

R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] ()

R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] ()

R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] ()

R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [132656 2015-10-10] (AVAST Software)

R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-07-23] (NVIDIA Corporation)

R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47976 2015-07-02] (NVIDIA Corporation)

R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)

R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)

S3 ssdevfactory; C:\Windows\System32\DRIVERS\ssdevfactory.sys [25088 2015-01-27] (SteelSeries ApS)

R3 sshid; C:\Windows\System32\DRIVERS\sshid.sys [42568 2015-02-26] (SteelSeries ApS)

R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [274336 2015-10-10] (Avast Software)

R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2015-11-17] ()

R3 ALSysIO; \??\C:\Users\Michael\AppData\Local\Temp\ALSysIO64.sys [X]

S3 BS680067079; \??\C:\Users\Michael\AppData\Local\Temp\NTFS.sys [X]

R3 WinRing0_1_2_0; \??\C:\Users\Michael\AppData\Local\Temp\tmp9E8F.tmp [X]

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-17 08:41 - 2015-11-17 08:41 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp

2015-11-17 08:40 - 2015-11-17 08:40 - 00000000 ____D C:\TDSSKiller_Quarantine

2015-11-14 22:04 - 2015-11-14 22:10 - 00037209 _____ C:\Windows\system32\DB680067079

2015-11-12 08:10 - 2015-11-12 08:10 - 00065537 _____ C:\Users\Michael\AppData\Roaming\qlulctq.exe

2015-11-11 18:00 - 2015-11-11 18:00 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox

2015-11-11 11:04 - 2015-11-11 11:04 - 04404952 _____ (Kaspersky Lab ZAO) C:\Users\Michael\Desktop\iexplore.exe

2015-11-11 11:04 - 2015-11-11 11:04 - 02019656 _____ (Bleeping Computer, LLC) C:\Users\Michael\Desktop\rkill.exe

2015-11-10 19:01 - 2015-11-10 19:01 - 00004096 _____ C:\ProgramData\aspnet_wp_64.exe

2015-11-10 19:00 - 2015-11-10 19:00 - 00004096 _____ C:\ProgramData\wowreg_64.dll

2015-11-09 14:45 - 2015-11-10 19:06 - 00000000 ____D C:\Windows\pss

2015-11-09 13:51 - 2015-11-09 13:51 - 00003816 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1447095090

2015-11-09 13:51 - 2015-11-09 13:51 - 00001135 _____ C:\Users\Public\Desktop\Opera.lnk

2015-11-09 13:51 - 2015-11-09 13:51 - 00001135 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk

2015-11-09 13:51 - 2015-11-09 13:51 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Opera Software

2015-11-09 13:51 - 2015-11-09 13:51 - 00000000 ____D C:\Users\Michael\AppData\Local\Opera Software

2015-11-09 13:49 - 2015-11-09 13:51 - 00000000 ____D C:\Program Files (x86)\Opera

2015-11-08 19:06 - 2015-11-08 19:57 - 304895837 _____ C:\Users\Michael\Downloads\13th Age PDFs.zip

2015-11-07 08:12 - 2015-11-17 08:55 - 00033332 _____ C:\Users\Michael\Desktop\FRST.txt

2015-11-07 08:12 - 2015-11-07 08:13 - 00091652 _____ C:\Users\Michael\Desktop\Addition.txt

2015-11-07 08:00 - 2015-11-07 08:00 - 00000000 ____D C:\Users\Michael\Desktop\FRST-OlderVersion

2015-11-07 07:23 - 2015-11-07 07:23 - 05481336 _____ (Avast Software s.r.o.) C:\Users\Michael\Desktop\avast_free_antivirus_setup_online_cnet.exe

2015-11-07 07:15 - 2015-11-07 07:15 - 05198336 _____ (AVAST Software) C:\Users\Michael\Desktop\aswMBR.exe

2015-11-06 08:44 - 2015-11-06 08:44 - 00004096 _____ C:\ProgramData\sessionmsg_32.dll

2015-11-06 08:44 - 2015-11-06 08:44 - 00004096 _____ C:\ProgramData\igfxEM_32.exe

2015-11-06 08:43 - 2015-11-06 08:43 - 00090112 _____ C:\ProgramData\7B571D05.EX

2015-11-05 08:32 - 2015-11-05 08:32 - 00004096 _____ C:\ProgramData\openssl.exe

2015-11-05 08:31 - 2015-11-05 08:31 - 00004096 _____ C:\ProgramData\TabTip32.dll

2015-11-03 02:51 - 2015-11-03 02:51 - 00000000 ____D C:\Users\Michael\AppData\LocalLow\Obsidian Entertainment

2015-11-03 01:49 - 2015-11-14 04:30 - 00000000 ____D C:\Users\Michael\Documents\Tabletop RPGs

2015-11-02 09:24 - 2015-11-17 08:52 - 00000000 ____D C:\FRST

2015-11-01 17:48 - 2015-11-01 17:48 - 00000222 _____ C:\Users\Michael\Desktop\Pillars of Eternity.url

2015-11-01 17:10 - 2015-11-05 20:23 - 00000000 ____D C:\Program Files\SUPERAntiSpyware

2015-11-01 17:10 - 2015-11-01 17:10 - 00001768 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk

2015-11-01 17:10 - 2015-11-01 17:10 - 00000000 ____D C:\Users\Michael\AppData\Roaming\SUPERAntiSpyware.com

2015-11-01 17:10 - 2015-11-01 17:10 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com

2015-11-01 17:10 - 2015-11-01 17:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware

2015-11-01 17:07 - 2015-11-01 17:09 - 23758168 _____ (SUPERAntiSpyware) C:\Users\Michael\Desktop\SUPERAntiSpyware.exe

2015-11-01 17:04 - 2015-11-01 17:04 - 00022748 _____ C:\Users\Michael\Documents\cc_20151101_170432.reg

2015-11-01 11:21 - 2015-11-07 08:00 - 02198528 _____ (Farbar) C:\Users\Michael\Desktop\FRST64.exe

2015-10-31 17:23 - 2015-10-31 17:23 - 02924672 _____ (AVG Technologies) C:\Users\Michael\Desktop\AVG_Protection_Free_698.exe

2015-10-31 11:29 - 2015-10-31 11:29 - 00001055 _____ C:\Users\Michael\Desktop\TrojanHunter.lnk

2015-10-31 11:29 - 2015-10-31 11:29 - 00000000 ____D C:\ProgramData\TrojanHunter

2015-10-31 11:29 - 2015-10-31 11:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrojanHunter

2015-10-31 11:29 - 2015-10-31 11:29 - 00000000 ____D C:\Program Files (x86)\TrojanHunter

2015-10-31 10:57 - 2015-10-31 10:57 - 05693008 _____ (AVAST Software) C:\Users\Michael\Desktop\avast_free_antivirus_setup_online.exe

2015-10-31 06:21 - 2015-10-31 06:21 - 00005120 _____ C:\ProgramData\taskhost.exe

2015-10-31 06:20 - 2015-10-31 06:20 - 00004096 _____ C:\ProgramData\GheT3Z733AFC.dll

2015-10-31 06:17 - 2015-10-31 06:17 - 00004096 _____ C:\ProgramData\hTew6txG3AFC.dll

2015-10-31 06:16 - 2015-11-14 04:39 - 03474516 _____ C:\Windows\system32\CFG680067079

2015-10-31 05:50 - 2015-10-31 05:50 - 00450102 _____ C:\Users\Michael\AppData\Roaming\lqnqtgzk.exe

2015-10-31 05:49 - 2015-10-31 06:02 - 00000000 ____D C:\ProgramData\Linpal

2015-10-31 05:49 - 2015-10-31 05:50 - 00000000 ___HD C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}

2015-10-25 05:42 - 2015-10-31 05:59 - 00000000 ____D C:\Users\Michael\AppData\LocalLow\BitTorrent

2015-10-20 00:37 - 2015-10-20 00:37 - 00000000 ____D C:\Users\Michael\AppData\LocalLow\Thunder Lotus Games

2015-10-19 16:08 - 2015-10-19 16:47 - 1012445539 _____ C:\Users\Michael\Desktop\The Hobbit - An Unexpected Journey (2012).mp4

2015-10-19 15:52 - 2015-10-19 16:00 - 183041872 _____ C:\Users\Michael\Desktop\Wakfu Ova - 3.mp4

2015-10-19 15:34 - 2015-10-19 15:42 - 145438780 _____ C:\Users\Michael\Desktop\Wakfu Ova - 2.mp4

2015-10-19 15:27 - 2015-10-19 15:34 - 151873307 _____ C:\Users\Michael\Desktop\Wakfu Ova - 1.mp4

2015-10-18 16:37 - 2015-10-18 16:37 - 00000222 _____ C:\Users\Michael\Desktop\Jotun.url

2015-10-18 12:16 - 2015-11-14 09:29 - 00000000 ____D C:\Program Files\PeerBlock

2015-10-18 12:16 - 2015-10-18 12:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeerBlock

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-17 08:49 - 2009-07-13 23:45 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2015-11-17 08:49 - 2009-07-13 23:45 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2015-11-17 08:48 - 2013-05-20 00:12 - 00000000 ____D C:\Program Files (x86)\Steam

2015-11-17 08:48 - 2013-05-19 21:13 - 01157324 _____ C:\Windows\WindowsUpdate.log

2015-11-17 08:46 - 2013-05-20 10:00 - 00624466 _____ C:\Users\Michael\Network_Meter_Data.js

2015-11-17 08:42 - 2014-06-11 15:11 - 00057047 _____ C:\Windows\setupact.log

2015-11-17 08:41 - 2015-04-10 16:32 - 00000000 ____D C:\ProgramData\NVIDIA

2015-11-17 08:41 - 2013-05-19 21:33 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys

2015-11-17 08:41 - 2013-05-19 21:33 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2015-11-17 08:41 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT

2015-11-17 08:30 - 2014-06-11 15:11 - 00440976 _____ C:\Windows\PFRO.log

2015-11-16 10:57 - 2013-05-20 11:20 - 00000030 _____ C:\Users\Michael\AppData\Roaming\Network Meter_Usage.ini

2015-11-16 10:57 - 2013-05-20 10:36 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Skype

2015-11-16 10:37 - 2013-05-22 20:36 - 00000000 ____D C:\Users\Michael\AppData\Local\CrashDumps

2015-11-16 10:34 - 2013-12-15 00:55 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA.job

2015-11-16 10:16 - 2013-05-19 21:33 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2015-11-16 10:02 - 2015-06-15 20:45 - 00000926 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA.job

2015-11-14 21:56 - 2014-02-27 03:33 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Raptr

2015-11-14 21:53 - 2013-05-20 01:18 - 00000000 ___RD C:\Users\Michael\Dropbox

2015-11-14 21:53 - 2013-05-20 01:11 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Dropbox

2015-11-14 21:50 - 2013-05-19 22:36 - 00000000 ___RD C:\Users\Michael\Google Drive

2015-11-11 20:30 - 2013-05-20 02:00 - 00000000 ____D C:\Users\Michael\AppData\Local\MediaMonkey

2015-11-11 17:16 - 2013-05-19 21:34 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk

2015-11-11 13:33 - 2013-12-15 00:55 - 00000864 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core.job

2015-11-11 11:15 - 2015-06-15 20:45 - 00000874 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core.job

2015-11-11 11:05 - 2013-05-23 18:27 - 00000000 ____D C:\Users\Michael\AppData\Local\Wizards_of_the_Coast

2015-11-10 19:02 - 2013-05-20 01:20 - 00002073 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk

2015-11-08 18:04 - 2013-05-21 00:04 - 00000000 ____D C:\Users\Michael\AppData\Roaming\vlc

2015-11-08 17:57 - 2014-08-31 08:36 - 00000000 ____D C:\Users\Michael\AppData\Local\Adobe

2015-11-08 17:56 - 2013-11-02 20:41 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2015-11-08 17:56 - 2013-11-02 20:41 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2015-11-07 13:55 - 2013-05-20 10:35 - 00000000 ____D C:\ProgramData\Skype

2015-11-06 13:45 - 2013-05-20 01:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

2015-11-05 14:38 - 2009-07-14 00:13 - 00783114 _____ C:\Windows\system32\PerfStringBackup.INI

2015-11-05 11:10 - 2013-05-23 18:26 - 00000000 ____D C:\Users\Michael\AppData\Roaming\CBLoader

2015-11-05 09:31 - 2014-05-11 21:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

2015-11-05 09:31 - 2013-05-20 01:20 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk

2015-11-03 02:40 - 2013-05-20 08:48 - 00001206 _____ C:\Users\Michael\Downloads\My Pictures.lnk

2015-11-02 00:45 - 2009-07-14 00:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games

2015-10-31 11:06 - 2015-03-10 18:14 - 00163748 _____ C:\Windows\DPINST.LOG

2015-10-31 10:58 - 2013-05-20 01:53 - 00000000 ____D C:\Users\Michael\AppData\Roaming\BitTorrent

2015-10-31 08:45 - 2015-05-19 00:07 - 00000000 ____D C:\Users\Michael\Documents\The Witcher 3

2015-10-30 17:06 - 2013-05-19 22:29 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update

2015-10-26 09:22 - 2015-05-13 10:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com

2015-10-25 06:48 - 2013-09-25 02:02 - 00000000 ____D C:\Users\Michael\AppData\Roaming\RenPy

2015-10-21 18:15 - 2013-05-19 22:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive

2015-10-19 15:15 - 2015-09-12 10:03 - 00000000 ____D C:\Users\Michael\AppData\Roaming\HandBrake

==================== Files in the root of some directories =======

2013-05-20 09:55 - 2014-06-11 14:30 - 0000576 _____ () C:\Users\Michael\AppData\Roaming\All CPU MeterV3_Settings.ini

2009-07-13 18:19 - 2009-07-13 20:14 - 0577536 _____ () C:\Users\Michael\AppData\Roaming\BackUp680067079.exe

2013-05-24 09:13 - 2013-05-24 09:14 - 0000839 _____ () C:\Users\Michael\AppData\Roaming\Drives Meter_Settings.ini

2013-05-20 09:46 - 2015-04-10 16:43 - 0000294 _____ () C:\Users\Michael\AppData\Roaming\GPU MeterV2_Settings.ini

2015-10-31 05:50 - 2015-10-31 05:50 - 0450102 _____ () C:\Users\Michael\AppData\Roaming\lqnqtgzk.exe

2013-05-20 11:20 - 2015-11-16 10:57 - 0000030 _____ () C:\Users\Michael\AppData\Roaming\Network Meter_Usage.ini

2015-11-12 08:10 - 2015-11-12 08:10 - 0065537 _____ () C:\Users\Michael\AppData\Roaming\qlulctq.exe

2015-11-06 08:43 - 2015-11-06 08:43 - 0090112 _____ () C:\ProgramData\7B571D05.EX

2015-11-10 19:01 - 2015-11-10 19:01 - 0004096 _____ () C:\ProgramData\aspnet_wp_64.exe

2015-10-31 06:20 - 2015-10-31 06:20 - 0004096 _____ () C:\ProgramData\GheT3Z733AFC.dll

2015-10-31 06:17 - 2015-10-31 06:17 - 0004096 _____ () C:\ProgramData\hTew6txG3AFC.dll

2015-11-06 08:44 - 2015-11-06 08:44 - 0004096 _____ () C:\ProgramData\igfxEM_32.exe

2015-11-05 08:32 - 2015-11-05 08:32 - 0004096 _____ () C:\ProgramData\openssl.exe

2015-11-06 08:44 - 2015-11-06 08:44 - 0004096 _____ () C:\ProgramData\sessionmsg_32.dll

2015-11-05 08:31 - 2015-11-05 08:31 - 0004096 _____ () C:\ProgramData\TabTip32.dll

2015-10-31 06:21 - 2015-10-31 06:21 - 0005120 _____ () C:\ProgramData\taskhost.exe

2015-11-10 19:00 - 2015-11-10 19:00 - 0004096 _____ () C:\ProgramData\wowreg_64.dll

Files to move or delete:

====================

C:\ProgramData\aspnet_wp_64.exe

C:\ProgramData\GheT3Z733AFC.dll

C:\ProgramData\hTew6txG3AFC.dll

C:\ProgramData\igfxEM_32.exe

C:\ProgramData\openssl.exe

C:\ProgramData\sessionmsg_32.dll

C:\ProgramData\TabTip32.dll

C:\ProgramData\taskhost.exe

C:\ProgramData\wowreg_64.dll

C:\Users\Michael\Network_Meter_Data.js

 

Some files in TEMP:

====================

C:\Users\Michael\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgw6qc9.dll

 

==================== Bamital & volsnap =================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\Windows\system32\winlogon.exe => File is digitally signed

C:\Windows\system32\wininit.exe => File is digitally signed

C:\Windows\SysWOW64\wininit.exe => File is digitally signed

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\SysWOW64\explorer.exe => File is digitally signed

C:\Windows\system32\svchost.exe => File is digitally signed

C:\Windows\SysWOW64\svchost.exe => File is digitally signed

C:\Windows\system32\services.exe => File is digitally signed

C:\Windows\system32\User32.dll => File is digitally signed

C:\Windows\SysWOW64\User32.dll => File is digitally signed

C:\Windows\system32\userinit.exe => File is digitally signed

C:\Windows\SysWOW64\userinit.exe => File is digitally signed

C:\Windows\system32\rpcss.dll => File is digitally signed

C:\Windows\system32\dnsapi.dll => File is digitally signed

C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

 

LastRegBack: 2015-11-14 04:02

 

==================== End of FRST.txt ============================

 

 

 

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-11-2015
Ran by [removed] (2015-11-17 08:55:44)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium (X64) (2013-05-20 02:12:41)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-711289349-3085500364-3229847752-500 - Administrator - Disabled)
Guest (S-1-5-21-711289349-3085500364-3229847752-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-711289349-3085500364-3229847752-1023 - Limited - Enabled)
Michael (S-1-5-21-711289349-3085500364-3229847752-1000 - Administrator - Enabled) => C:\Users\Michael

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Abyss Odyssey (HKLM-x32\…\Steam App 255070) (Version:  - ACE Team)
Acrobat.com (HKLM-x32\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1.377 - Adobe Systems Incorporated)
Acrobat.com (x32 Version: 0.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.0.4990 - Adobe Systems Inc.)
Adobe Flash Player 19 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 19.0.0.226 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
AGEIA PhysX v7.11.13 (HKLM-x32\…\{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}) (Version: 7.11.13 - AGEIA Technologies, Inc.)
Alan Wake (HKLM-x32\…\Steam App 108710) (Version:  - Remedy Entertainment)
Anodyne (HKLM-x32\…\Steam App 234900) (Version:  - Sean Hogan and Jonathan Kittaka)
Apple Application Support (32-bit) (HKLM-x32\…\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{06A333EA-4E9D-4848-865F-FE5A1E12AB30}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.10.1.0 - Asmedia Technology)
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\…\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 1.3.1.000 - Asmedia Technology)
Assassin's Creed IV Black Flag (HKLM-x32\…\Steam App 242050) (Version:  - Ubisoft Montreal)
Avast Free Antivirus (HKLM-x32\…\avast) (Version: 10.4.2233 - AVAST Software)
Bionic Commando Rearmed (HKLM-x32\…\Steam App 21680) (Version:  - GRIN)
BitTorrent (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\BitTorrent) (Version: 7.9.5.41203 - BitTorrent Inc.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.8.5.1 - Broadcom Corporation)
Brütal Legend (HKLM-x32\…\Steam App 225260) (Version:  - Double Fine Productions)
Bully: Scholarship Edition (HKLM-x32\…\Steam App 12200) (Version:  - Rockstar New England)
Canon IJ Network Scan Utility (HKLM-x32\…\Canon_IJ_Network_Scan_UTILITY) (Version:  - )
Canon IJ Network Tool (HKLM-x32\…\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.)
Canon MP Navigator EX 3.1 (HKLM-x32\…\MP Navigator EX 3.1) (Version:  - )
Canon MX340 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX340_series) (Version:  - Canon Inc.)
Castlevania: Lords of Shadow – Mirror of Fate HD (HKLM-x32\…\Steam App 282530) (Version:  - MercurySteam)
Castlevania: Lords of Shadow - Ultimate Edition (HKLM-x32\…\Steam App 234080) (Version:  - MercurySteam - Climax Studios)
CCleaner (HKLM\…\CCleaner) (Version: 4.09 - Piriform)
CDisplayEx 1.10.29 (HKLM\…\CDisplayEx_is1) (Version:  - Progdigy Software S.A.R.L.)
ChromecastApp (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\{079ede36-133d-44b0-8053-c7c1fa8d2e0d}_is1) (Version: 1.5.1693.0 - Google Inc.)
ComicRack v0.9.156 (HKLM\…\ComicRack) (Version: v0.9.156 - cYo Soft)
Core Temp version 0.99.7 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 0.99.7 - Arthur Liberman)
CPUID CPU-Z 1.63.0 (HKLM\…\CPUID CPU-Z_is1) (Version:  - )
Creation Kit (HKLM-x32\…\Steam App 202480) (Version:  - bgs.bethsoft.com)
Creative ALchemy (HKLM-x32\…\ALchemy) (Version: 1.43 - Creative Technology Limited)
Creative Audio Control Panel (HKLM-x32\…\AudioCS) (Version: 2.56 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\…\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
CutePDF Writer 3.0 (HKLM\…\CutePDF Writer Installation) (Version:  3.0 - CutePDF.com)
Darkest Dungeon (HKLM-x32\…\Steam App 262060) (Version:  - Red Hook Studios)
DDS Viewer (HKLM-x32\…\{707333E0-C796-4E2D-B0DA-5A429706C361}_is1) (Version:  - IdeaMK)
Defraggler (HKLM\…\Defraggler) (Version: 2.16 - Piriform)
Deus Ex: Human Revolution - The Missing Link (HKLM-x32\…\Steam App 201280) (Version:  - Eidos Montreal)
Deus Ex: Human Revolution (HKLM-x32\…\Steam App 28050) (Version:  - Eidos Montreal)
Dishonored (HKLM-x32\…\Steam App 205100) (Version:  - Arkane Studios)
Divinity: Original Sin (HKLM-x32\…\Steam App 230230) (Version:  - Larian Studios)
Don't Starve (HKLM-x32\…\Steam App 219740) (Version:  - )
Don't Starve Together Beta (HKLM-x32\…\Steam App 322330) (Version:  - Klei Entertainment)
Driver Sweeper version 3.1.0 (HKLM-x32\…\{5A67D2EA-FB70-4033-A6F3-606AD85B2015}_is1) (Version: 3.1.0 - Phyxion.net)
Dropbox (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Dropbox) (Version: 3.10.11 - Dropbox, Inc.)
Dungeons & Dragons: Chronicles of Mystara (HKLM-x32\…\Steam App 229480) (Version:  - Iron Galaxy Studios)
Endless Space (HKLM-x32\…\Steam App 208140) (Version:  - Amplitude Studios)
Evoland (HKLM-x32\…\Steam App 233470) (Version:  - Shiro Games)
f.lux (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Flux) (Version:  - )
Far Cry® 3 Blood Dragon (HKLM-x32\…\Steam App 233270) (Version:  - Ubisoft Montreal)
FEZ (HKLM-x32\…\Steam App 224760) (Version:  - Polytron Corporation)
Five Nights at Freddy's (HKLM-x32\…\Steam App 319510) (Version:  - Scott Cawthon)
Foxit Cloud (HKLM-x32\…\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.5.129.617 - Foxit Corporation)
Foxit PhantomPDF Standard (HKLM-x32\…\{A652C696-8733-4681-820C-95465A19512B}) (Version: 6.2.1.618 - Foxit Corporation)
Foxit Reader (HKLM-x32\…\Foxit Reader_is1) (Version: 6.2.3.815 - Foxit Corporation)
FTL: Faster Than Light (HKLM-x32\…\Steam App 212680) (Version:  - Subset Games)
Game of Thrones - A Telltale Games Series (HKLM-x32\…\Steam App 330840) (Version:  - Telltale Games)
Gnomoria (HKLM-x32\…\Steam App 224500) (Version:  - Robotronic Games)
GOG Galaxy (HKLM-x32\…\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version:  - GOG.com)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 46.0.2490.86 - Google Inc.)
Google Drive (HKLM-x32\…\{9C350701-AC04-48BA-A435-BD5E0D82897E}) (Version: 1.25.0523.2491 - Google, Inc.)
Google Talk Plugin (HKLM-x32\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
Guacamelee! Gold Edition (HKLM-x32\…\Steam App 214770) (Version:  - DrinkBox Studios)
Guild Wars 2 (HKLM-x32\…\Guild Wars 2) (Version:  - NCsoft Corporation, Ltd.)
HandBrake 0.10.2 (HKLM-x32\…\HandBrake) (Version: 0.10.2 - )
Hitman: Absolution (HKLM-x32\…\Steam App 203140) (Version:  - Square Enix)
Hotline Miami (HKLM-x32\…\Steam App 219150) (Version:  - Dennaton Games)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1281 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.6.0.1030 - Intel Corporation)
Intel(R) Smart Connect Technology 2.0 x64 (HKLM\…\{D1B033E8-A077-4B0D-9831-5798E19E861E}) (Version: 2.0.1083.0 - Intel)
Intel(R) Update Manager (HKLM-x32\…\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation)
iTunes (HKLM\…\{5AC8E601-667F-4CA0-90D8-B25E1C4B3387}) (Version: 12.2.2.25 - Apple Inc.)
Java 7 Update 21 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417021FF}) (Version: 7.0.210 - Oracle)
Java 7 Update 65 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.650 - Oracle)
Jotun (HKLM-x32\…\Steam App 323580) (Version:  - Thunder Lotus Games)
King of Dragon Pass (HKLM-x32\…\Steam App 352220) (Version:  - A Sharp, LLC)
Left 4 Dead 2 (HKLM-x32\…\Steam App 550) (Version:  - Valve)
Legend of Dungeon (HKLM-x32\…\Steam App 238280) (Version:  - )
Legend of Grimrock (HKLM-x32\…\Steam App 207170) (Version:  - Almost Human Games)
Livestream Procaster (HKLM-x32\…\{68E4C751-272B-44E1-94C7-4E1FDC40F7DA}) (Version: 20.3.25 - Procaster)
Logitech Gaming Software 8.53 (HKLM\…\Logitech Gaming Software) (Version: 8.53.186 - Logitech Inc.)
LOOT (HKLM-x32\…\LOOT) (Version: 0.5.0 - LOOT Development Team)
Mad Max (HKLM-x32\…\Steam App 234140) (Version:  - Avalanche Studios)
Mark of the Ninja (HKLM-x32\…\Steam App 214560) (Version:  - Klei Entertainment)
Mars: War Logs (HKLM-x32\…\Steam App 232750) (Version:  - Spiders)
MediaMonkey 3.0 (HKLM-x32\…\MediaMonkey_is1) (Version: 3.0 - Ventis Media Inc.)
Microsoft .NET Framework 4.5.1 RC (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50861 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\…\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Middle-earth: Shadow of Mordor (HKLM-x32\…\Steam App 241930) (Version:  - Monolith Productions, Inc.)
Monaco (HKLM-x32\…\Steam App 113020) (Version:  - Pocketwatch Games)
Mount & Blade: Warband (HKLM-x32\…\Steam App 48700) (Version:  - Taleworlds Entertainment)
Mozilla Firefox 42.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 42.0 - Mozilla)
Nexus Mod Manager (HKLM\…\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.49.1 - Black Tree Gaming)
Nidhogg (HKLM-x32\…\Steam App 94400) (Version:  - Messhof)
NVIDIA 3D Vision Controller Driver 352.65 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 353.62 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.62 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.5.12.11 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.12.11 - NVIDIA Corporation)
NVIDIA Graphics Driver 353.62 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.62 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.3 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Octodad: Dadliest Catch (HKLM-x32\…\Steam App 224480) (Version:  - Young Horses)
Oddworld: Stranger's Wrath HD (HKLM-x32\…\Steam App 15750) (Version:  - )
OpenAL (HKLM-x32\…\OpenAL) (Version:  - )
OpenOffice 4.1.1 (HKLM-x32\…\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
Opera Stable 33.0.1990.58 (HKLM-x32\…\Opera 33.0.1990.58) (Version: 33.0.1990.58 - Opera Software)
Orcs Must Die! (HKLM-x32\…\Steam App 102600) (Version:  - )
Papers, Please (HKLM-x32\…\Steam App 239030) (Version:  - 3909)
PAYDAY 2 Beta (HKLM-x32\…\Steam App 246210) (Version:  - )
PeerBlock 1.2 (r693) (HKLM\…\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.2.0.693 - PeerBlock, LLC)
Pillars of Eternity (HKLM-x32\…\Steam App 291650) (Version:  - Obsidian Entertainment)
Prison Architect (HKLM-x32\…\Steam App 233450) (Version:  - Introversion Software)
Psychonauts (HKLM-x32\…\Steam App 3830) (Version:  - Double Fine Productions)
QuickTime 7 (HKLM-x32\…\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)
Raptr (HKLM-x32\…\Raptr) (Version:  - )
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6559 - Realtek Semiconductor Corp.)
Recettear: An Item Shop's Tale (HKLM-x32\…\Steam App 70400) (Version:  - EasyGameStation)
Recuva (HKLM\…\Recuva) (Version: 1.51 - Piriform)
Remember Me (HKLM-x32\…\Steam App 228300) (Version:  - DONTNOD Entertainment)
Reus (HKLM-x32\…\Steam App 222730) (Version:  - Abbey Games)
Revenge of the Titans (HKLM-x32\…\Steam App 93200) (Version:  - Puppygames)
Rogue Legacy (HKLM-x32\…\Steam App 241600) (Version:  - Cellar Door Games)
RollerCoaster Tycoon 3: Platinum! (HKLM-x32\…\Steam App 2700) (Version:  - Frontier)
Rust (HKLM-x32\…\Steam App 252490) (Version:  - Facepunch Studios)
Saints Row IV (HKLM-x32\…\Steam App 206420) (Version:  - Deep Silver Volition)
Seagate Dashboard (HKLM-x32\…\{F1D8690F-06B3-4100-9949-398EA253AC61}) (Version: 3.2.1802.2 - Seagate)
Shadowrun Returns (HKLM-x32\…\Steam App 234650) (Version:  - Harebrained Schemes)
Shadowrun: Dragonfall - Director's Cut (HKLM-x32\…\Steam App 300550) (Version:  - Harebrained Schemes)
SHIELD Streaming (Version: 4.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.5.12.11 - NVIDIA Corporation) Hidden
Shovel Knight (HKLM-x32\…\Steam App 250760) (Version:  - Yacht Club Games)
SimCity 4 Deluxe (HKLM-x32\…\Steam App 24780) (Version:  - Maxis)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation)
Skype™ 7.13 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.13.101 - Skype Technologies S.A.)
Sleeping Dogs: Definitive Edition (HKLM-x32\…\Steam App 307690) (Version:  - United Front Games)
Solar 2 (HKLM-x32\…\Steam App 97000) (Version:  - Murudai)
Sony Mobile Update Engine (HKLM-x32\…\Update Engine) (Version: 2.15.12.201508241237 - Sony Mobile Communications Inc.)
Sony PC Companion 2.10.289 (HKLM-x32\…\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.289 - Sony)
Starbound (HKLM-x32\…\Steam App 211820) (Version:  - )
Stardock Fences 2 (HKLM-x32\…\Stardock Fences 2) (Version: 2.10 - Stardock Software, Inc.)
State of Decay (HKLM-x32\…\Steam App 241540) (Version:  - Undead Labs)
Steam (HKLM-x32\…\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
SteelSeries Engine 3.3.5 (HKLM\…\SteelSeries Engine 3) (Version: 3.3.5 - SteelSeries ApS)
Styx: Master of Shadows (HKLM-x32\…\Steam App 242640) (Version:  - Cyanide Studio)
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1208 - SUPERAntiSpyware.com)
Surgeon Simulator 2013 (HKLM-x32\…\Steam App 233720) (Version:  - Bossa Studios)
TeamSpeak 3 Client (HKLM-x32\…\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH)
Terraria (HKLM-x32\…\Steam App 105600) (Version:  - )
Teslagrad Demo (HKLM-x32\…\Steam App 254560) (Version:  - Rain Games)
The Banner Saga (HKLM-x32\…\Steam App 237990) (Version:  - Stoic)
The Elder Scrolls V: Skyrim (HKLM-x32\…\Steam App 72850) (Version:  - Bethesda Game Studios)
The Forest (HKLM-x32\…\Steam App 242760) (Version:  - Endnight Games Ltd)
The Incredible Adventures of Van Helsing (HKLM-x32\…\Steam App 215530) (Version:  - NeocoreGames)
The Long Dark (HKLM-x32\…\Steam App 305620) (Version:  - Hinterland Studio Inc.)
The Secret World (HKLM-x32\…\Steam App 215280) (Version:  - Funcom)
The Stomping Land (HKLM-x32\…\Steam App 263440) (Version:  - SuperCrit)
The Walking Dead (HKLM-x32\…\Steam App 207610) (Version:  - )
The Walking Dead: Season Two (HKLM-x32\…\Steam App 261030) (Version:  - Telltale Games)
The Witcher 2 (HKLM-x32\…\{F0A209B7-7F85-4BDD-8F1F-B98EEAD9E04B}) (Version: 1.00.0000 - CD Projekt Red)
The Witcher 3 - Wild Hunt (HKLM-x32\…\1207664643_is1) (Version: 1.0.11.0 - GOG.com)
The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\…\Free DLC program (16 DLC)_is1) (Version: 1.0.10.0 - GOG.com)
The Witcher 3: Wild Hunt - Hearts of Stone (HKLM-x32\…\Hearts of Stone_is1) (Version: 1.0.10.0 - GOG.com)
They Bleed Pixels (HKLM-x32\…\Steam App 211260) (Version:  - Spooky Squid Games Inc.)
Tiny Barbarian DX (HKLM-x32\…\Steam App 253350) (Version:  - StarQuail Games)
Transistor (HKLM-x32\…\Steam App 237930) (Version:  - Supergiant Games)
TrojanHunter 6.0 (HKLM-x32\…\TrojanHunter_is1) (Version: 6.0 - Bytelayer AB)
TrueCrypt (HKLM-x32\…\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation)
Unity Web Player (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Universe Sandbox (HKLM-x32\…\Steam App 72200) (Version:  - )
Uplay (HKLM-x32\…\Uplay) (Version: 4.0 - Ubisoft)
Vessel (HKLM-x32\…\Steam App 108500) (Version:  - Strange Loop Games)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
Westerado: Double Barreled (HKLM-x32\…\Steam App 275200) (Version:  - Ostrich Banditos)
Wrye Bash (HKLM-x32\…\Wrye Bash) (Version: 3.0.4.3 - Wrye & Wrye Bash Development Team)
XCOM: Enemy Unknown (HKLM-x32\…\Steam App 200510) (Version:  - Firaxis Games)
YTD Video Downloader 3.9.6 (HKLM-x32\…\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 3.9.6 - GreenTree Applications SRL) <==== ATTENTION

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)

==================== Restore Points =========================

03-11-2015 00:00:01 Scheduled Checkpoint
14-11-2015 04:09:21 Scheduled Checkpoint

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0D4A090F-45E6-49F6-8E99-D4143E5C7CF4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd)
Task: {0F957854-886F-4E17-A16E-EC9963D4F94D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {15A32B57-F7EC-4074-8CF3-DBE82298BCA4} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {342162CA-FE1A-409B-B90D-165197BEF325} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {3A470D43-598A-4DA7-85E0-1F91C6FC20E1} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-15] (Dropbox, Inc.)
Task: {3FD19CAF-79FA-4128-8ADE-14ED21F59E7B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {51F539DE-1094-42FA-B9EB-E4C5BDB231BF} - System32\Tasks\Seagate_Install_Launch => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Dashboard.exe [2014-09-17] (Seagate Technology LLC)
Task: {57949803-E7D2-42CE-B7DB-DBBBB72C01AD} - System32\Tasks\avastBCLRestartS-1-5-21-711289349-3085500364-3229847752-1000 => Chrome.exe
Task: {58B115B6-5368-48DE-AE63-51104E35C1F2} - System32\Tasks\PCMeter\Startup => C:\Users\Michael\Downloads\Windows Gadgets\PCMeterV0.3.exe [2013-03-16] (AddGadgets)
Task: {5C3CF947-1A17-4C66-A4F9-FCC2F6B0E13C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {74E23625-8490-4549-AF10-B725E1D84562} - System32\Tasks\Michael DBAgent 2 0 => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [2014-09-17] (Seagate Technology LLC)
Task: {8DCBEDAB-8C7E-4FDB-AB91-B732F25CEBDE} - System32\Tasks\{3293F118-F9C1-4AE8-A5E9-8FC2FB983B1E} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver;=5.1.0.112.259&LastError;=404
Task: {C878D5D1-3D09-4B73-91A9-1F6548A3C935} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-15] (Dropbox, Inc.)
Task: {E00BC2BE-876C-4E47-AEED-34B14441164F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {EB9F81D7-C650-40EC-B3A1-1C985F7D5EC0} - System32\Tasks\Opera scheduled Autoupdate 1447095090 => C:\Program Files (x86)\Opera\launcher.exe [2015-10-30] (Opera Software)
Task: {EE7B33BE-B506-4785-93AB-67F2B2490C0C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {F5DA27E1-A8AF-4E28-AB21-2BDC29352C3E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-10-10] (AVAST Software)
Task: {FF866CD3-75FF-4980-A7D8-9AE602EC7A52} - System32\Tasks\Core Temp Autostart => C:\Program Files\Core Temp\Core Temp.exe [2010-07-02] ()

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core.job => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA.job => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core.job => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA.job => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2013-05-20 01:29 - 2012-10-04 18:49 - 00087152 _____ () C:\Windows\System32\cpwmon64.dll
2015-04-10 16:31 - 2015-07-22 20:31 - 00116368 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-05-20 09:42 - 2010-07-02 12:52 - 00530448 _____ () C:\Program Files\Core Temp\Core Temp.exe
2012-02-09 15:26 - 2012-02-09 15:26 - 00133632 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
2012-02-09 15:26 - 2012-02-09 15:26 - 00048128 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll
2012-02-09 15:26 - 2012-02-09 15:26 - 00036864 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetDetect.dll
2015-11-10 19:01 - 2015-11-10 19:01 - 00004096 _____ () C:\ProgramData\aspnet_wp_64.exe
2015-11-05 08:32 - 2015-11-05 08:32 - 00004096 _____ () C:\ProgramData\openssl.exe
2014-07-02 16:54 - 2014-07-02 16:54 - 00866584 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2014-07-02 16:59 - 2014-07-02 16:59 - 01050904 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-07-02 16:54 - 2014-07-02 16:54 - 00059160 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2014-07-02 16:59 - 2014-07-02 16:59 - 00242456 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2015-11-06 08:44 - 2015-11-06 08:44 - 00004096 _____ () C:\ProgramData\igfxEM_32.exe
2015-10-31 06:20 - 2015-10-31 06:20 - 00004096 _____ () C:\ProgramData\GheT3Z733AFC.dll
2015-03-10 18:13 - 2015-06-10 10:13 - 00113024 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
2013-05-20 09:41 - 2013-05-20 09:41 - 00012520 _____ () C:\Users\Michael\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\CoreTempReader.dll
2013-05-20 09:41 - 2013-05-20 09:41 - 00015080 _____ () C:\Users\Michael\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\GetCoreTempInfoNET.dll
2013-05-20 09:41 - 2013-05-20 09:41 - 00014056 _____ () C:\Users\Michael\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\SystemInfo.dll
2015-03-05 13:04 - 2015-03-05 13:04 - 18305024 _____ () C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe
2015-03-05 11:44 - 2015-03-05 11:44 - 00047616 _____ () C:\Program Files\SteelSeries\SteelSeries Engine 3\x2api.dll
2015-02-13 04:20 - 2015-02-13 04:20 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2015-05-15 15:27 - 2015-05-15 15:27 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-05-18 07:55 - 2015-07-23 23:22 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-03-10 18:13 - 2012-04-30 10:57 - 00039936 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll
2015-03-10 18:13 - 2014-12-04 14:18 - 00241152 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll
2011-07-07 13:54 - 2011-07-07 13:54 - 00233984 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\Report.dll
2015-03-10 18:13 - 2013-05-20 11:58 - 00620718 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\sqlite3.dll
2015-03-23 18:19 - 2015-03-23 18:19 - 02620416 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\libxt.dll
2015-03-10 18:13 - 2015-04-21 12:22 - 00053248 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\VObject.dll
2015-07-23 08:21 - 2015-07-23 08:21 - 00802304 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PhoneUpdate.dll
2013-05-19 22:00 - 2009-02-06 17:52 - 00073728 _____ () C:\Windows\SysWOW64\CmdRtr.DLL
2013-05-19 22:00 - 2009-07-10 08:07 - 00166912 _____ () C:\Windows\SysWOW64\APOMngr.DLL
2015-11-17 08:45 - 2015-11-17 08:45 - 00071168 _____ () c:\users\michael\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgw6qc9.dll
2014-10-16 10:23 - 2014-10-16 10:23 - 00017920 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\PSIClient\4f91b7d6b3821366470574294553d6ce\PSIClient.ni.dll
2010-11-22 17:56 - 2010-11-22 17:56 - 00087040 _____ () C:\Program Files (x86)\Raptr\_ctypes.pyd
2010-11-22 17:56 - 2010-11-22 17:56 - 00043008 _____ () C:\Program Files (x86)\Raptr\_socket.pyd
2010-11-22 17:56 - 2010-11-22 17:56 - 00805376 _____ () C:\Program Files (x86)\Raptr\_ssl.pyd
2014-05-13 18:26 - 2014-05-13 18:26 - 05812736 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtGui.pyd
2014-05-13 18:26 - 2014-05-13 18:26 - 00067584 _____ () C:\Program Files (x86)\Raptr\sip.pyd
2014-05-13 18:26 - 2014-05-13 18:26 - 01662464 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtCore.pyd
2014-05-13 18:26 - 2014-05-13 18:26 - 00494592 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtNetwork.pyd
2010-11-22 17:57 - 2010-11-22 17:57 - 00096256 _____ () C:\Program Files (x86)\Raptr\win32api.pyd
2010-11-22 17:56 - 2010-11-22 17:56 - 00110592 _____ () C:\Program Files (x86)\Raptr\pywintypes26.dll
2010-11-22 17:56 - 2010-11-22 17:56 - 00324608 _____ () C:\Program Files (x86)\Raptr\PIL._imaging.pyd
2010-11-22 17:56 - 2010-11-22 17:56 - 00356864 _____ () C:\Program Files (x86)\Raptr\_hashlib.pyd
2010-11-22 17:57 - 2010-11-22 17:57 - 00036352 _____ () C:\Program Files (x86)\Raptr\win32process.pyd
2010-11-22 17:57 - 2010-11-22 17:57 - 00111104 _____ () C:\Program Files (x86)\Raptr\win32file.pyd
2010-11-22 17:56 - 2010-11-22 17:56 - 00124928 _____ () C:\Program Files (x86)\Raptr\_elementtree.pyd
2010-11-22 17:56 - 2010-11-22 17:56 - 00127488 _____ () C:\Program Files (x86)\Raptr\pyexpat.pyd
2012-02-06 15:28 - 2012-02-06 15:28 - 00031744 _____ () C:\Program Files (x86)\Raptr\Crypto.Cipher.AES.pyd
2012-02-06 15:28 - 2012-02-06 15:28 - 00010752 _____ () C:\Program Files (x86)\Raptr\Crypto.Random.OSRNG.winrandom.pyd
2012-02-06 15:28 - 2012-02-06 15:28 - 00011264 _____ () C:\Program Files (x86)\Raptr\Crypto.Util._counter.pyd
2011-05-10 14:01 - 2011-05-10 14:01 - 00030208 _____ () C:\Program Files (x86)\Raptr\simplejson._speedups.pyd
2014-05-13 18:26 - 2014-05-13 18:26 - 00313856 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtWebKit.pyd
2010-11-22 17:56 - 2010-11-22 17:56 - 00044544 _____ () C:\Program Files (x86)\Raptr\_sqlite3.pyd
2011-02-15 13:17 - 2011-02-15 13:17 - 00417501 _____ () C:\Program Files (x86)\Raptr\sqlite3.dll
2010-11-22 17:56 - 2010-11-22 17:56 - 00354304 _____ () C:\Program Files (x86)\Raptr\pythoncom26.dll
2010-11-22 17:57 - 2010-11-22 17:57 - 00016384 _____ () C:\Program Files (x86)\Raptr\win32trace.pyd
2010-11-22 17:57 - 2010-11-22 17:57 - 00167936 _____ () C:\Program Files (x86)\Raptr\win32gui.pyd
2010-11-22 17:56 - 2010-11-22 17:56 - 00009216 _____ () C:\Program Files (x86)\Raptr\winsound.pyd
2010-11-22 17:56 - 2010-11-22 17:56 - 00010240 _____ () C:\Program Files (x86)\Raptr\select.pyd
2013-11-20 19:05 - 2013-11-20 19:05 - 00256000 _____ () C:\Program Files (x86)\Raptr\amd_ags.dll
2010-11-22 17:56 - 2010-11-22 17:56 - 00583680 _____ () C:\Program Files (x86)\Raptr\unicodedata.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00098816 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\win32api.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00110080 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\pywintypes27.dll
2015-11-17 08:44 - 2015-11-17 08:44 - 00364544 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\pythoncom27.dll
2015-11-17 08:44 - 2015-11-17 08:44 - 00046080 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\_socket.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 01208320 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\_ssl.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00320512 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\win32com.shell.shell.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00776704 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\_hashlib.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 01176576 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\wx._core_.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00806400 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\wx._gdi_.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00816128 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\wx._windows_.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 01067008 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\wx._controls_.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00733184 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\wx._misc_.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00682496 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\pysqlite2._sqlite.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00088064 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\_ctypes.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00119808 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\win32file.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00108544 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\win32security.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00007168 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\hashobjs_ext.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00070144 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\usb_ext.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00167936 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\win32gui.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00018432 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\win32event.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00128512 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\_elementtree.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00127488 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\pyexpat.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00013824 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\common.time34.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00036864 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\_psutil_windows.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00038912 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\win32inet.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00011264 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\win32crypt.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00077312 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\wx._html2.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00027136 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\_multiprocessing.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00020480 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\_yappi.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00035840 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\win32process.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00686080 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\unicodedata.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00123392 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\wx._wizard.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00024064 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\win32pipe.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00010240 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\select.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00025600 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\win32pdh.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00525640 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\windows._lib_cacheinvalidation.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00017408 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\win32profile.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00022528 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\win32ts.pyd
2015-11-17 08:44 - 2015-11-17 08:44 - 00078848 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI43762\wx._animate.pyd
2010-11-22 17:57 - 2010-11-22 17:57 - 00141312 _____ () C:\Program Files (x86)\Raptr\gobject._gobject.pyd
2012-10-27 02:53 - 2012-10-27 02:53 - 02717595 _____ () C:\Program Files (x86)\Raptr\heliotrope._purple.pyd
2011-02-15 13:17 - 2011-02-15 13:17 - 01213633 _____ () C:\Program Files (x86)\Raptr\libxml2-2.dll
2010-11-22 18:06 - 2010-11-22 18:06 - 00055808 _____ () C:\Program Files (x86)\Raptr\zlib1.dll
2013-05-09 18:52 - 2013-05-09 18:52 - 00495680 _____ () C:\Program Files (x86)\Raptr\plugins\libaim.dll
2013-05-09 18:52 - 2013-05-09 18:52 - 01183699 _____ () C:\Program Files (x86)\Raptr\liboscar.dll
2013-05-09 18:52 - 2013-05-09 18:52 - 00483306 _____ () C:\Program Files (x86)\Raptr\plugins\libicq.dll
2013-05-03 13:57 - 2013-05-03 13:57 - 00655356 _____ () C:\Program Files (x86)\Raptr\plugins\libirc.dll
2013-05-03 13:56 - 2013-05-03 13:56 - 01306387 _____ () C:\Program Files (x86)\Raptr\plugins\libmsn.dll
2013-05-03 13:56 - 2013-05-03 13:56 - 00565461 _____ () C:\Program Files (x86)\Raptr\plugins\libxmpp.dll
2013-05-03 13:57 - 2013-05-03 13:57 - 01640221 _____ () C:\Program Files (x86)\Raptr\libjabber.dll
2013-05-03 13:56 - 2013-05-03 13:56 - 00506276 _____ () C:\Program Files (x86)\Raptr\plugins\libyahoo.dll
2013-05-03 13:57 - 2013-05-03 13:57 - 01053730 _____ () C:\Program Files (x86)\Raptr\libymsg.dll
2013-05-03 13:57 - 2013-05-03 13:57 - 00497782 _____ () C:\Program Files (x86)\Raptr\plugins\libyahoojp.dll
2013-05-03 13:57 - 2013-05-03 13:57 - 00603326 _____ () C:\Program Files (x86)\Raptr\plugins\ssl-nss.dll
2013-05-03 13:57 - 2013-05-03 13:57 - 00474199 _____ () C:\Program Files (x86)\Raptr\plugins\ssl.dll
2013-05-19 21:26 - 2012-07-18 05:55 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-04-23 17:30 - 2015-10-05 11:18 - 00778752 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-01-19 15:21 - 2015-07-03 11:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-01-19 15:21 - 2015-07-03 11:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-01-19 15:21 - 2015-07-03 11:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2014-05-21 17:32 - 2015-11-09 21:44 - 02541648 _____ () C:\Program Files (x86)\Steam\video.dll
2014-08-28 16:50 - 2015-09-23 19:33 - 02549248 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2014-08-28 16:51 - 2015-09-23 19:33 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2014-08-28 16:51 - 2015-09-23 19:33 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2014-08-28 16:51 - 2015-09-23 19:33 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2014-08-28 16:51 - 2015-09-23 19:33 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2013-05-03 14:35 - 2015-11-09 21:44 - 00806992 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2013-03-26 15:16 - 2015-10-08 17:20 - 45010208 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\02770114.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\43905478.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\48612182.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\79060820.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\02770114.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\43905478.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\48612182.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\79060820.sys => ""="Driver"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-711289349-3085500364-3229847752-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: avast! Antivirus => 2
MSCONFIG\Services: AvastVBoxSvc => 3
MSCONFIG\Services: ehRecvr => 3
MSCONFIG\Services: ehSched => 3
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: AvastUI.exe => "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
MSCONFIG\startupreg: BitTorrent => "C:\Users\Michael\AppData\Roaming\BitTorrent\BitTorrent.exe"  /MINIMIZED
MSCONFIG\startupreg: Chrome => C:\PROGRA~3\taskhost.exe
MSCONFIG\startupreg: GalaxyClient => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSCONFIG\startupreg: THGuard => "C:\Program Files (x86)\TrojanHunter\THGuard.exe"
MSCONFIG\startupreg: Wondershare Helper Compact.exe => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{05E4EBCA-C57B-40F1-9177-185411F87E77}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{914BEBC3-B713-4A32-90E7-672B4C49D402}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A0B47EE0-EBB5-44D4-80F4-3C6EC767A64C}] => (Allow) C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{38EB4404-D701-4EC7-8BF9-45DE9642A14C}] => (Allow) C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{C383AABC-B8C3-481A-8110-76D5088AE1ED}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mars War Logs\MarsWarLogs.exe
FirewallRules: [{8EAC8079-443B-4F00-BE7B-FEAB7BCA7C06}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mars War Logs\MarsWarLogs.exe
FirewallRules: [{EA85749C-AC6B-4A3B-855E-D67B074B2EA0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{8A7AC821-160F-4400-AAF8-E347F1AA6C79}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{A2730E6D-2A20-40F6-A3FE-DAB8E5377F0B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{AA37EF3F-996E-4AAC-A6B5-0F038107E4E3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{AB07BE16-CAFA-4E5C-953C-1655B5766C6F}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{E94A15CB-C4F5-4F13-9D51-E7EA9F77D6CF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Universe Sandbox\Universe Sandbox.exe
FirewallRules: [{06ABF9D4-83CE-4C9E-B8DF-9C651D7975DC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Universe Sandbox\Universe Sandbox.exe
FirewallRules: [{4CD1733C-B92A-4741-9881-D563CAFD8BF9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [{2BEFE624-91A1-4D74-87AC-A84270D20B61}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [TCP Query User{860B1408-7727-4A0B-8A0C-D715525F7E12}C:\program files (x86)\guild wars 2\gw2.exe] => (Allow) C:\program files (x86)\guild wars 2\gw2.exe
FirewallRules: [UDP Query User{35FC3E26-8EAF-4D11-8095-02C8F58779CC}C:\program files (x86)\guild wars 2\gw2.exe] => (Allow) C:\program files (x86)\guild wars 2\gw2.exe
FirewallRules: [{2777BC3B-CD1F-4601-A020-19A001B994D5}] => (Block) C:\program files (x86)\guild wars 2\gw2.exe
FirewallRules: [{F7E26BBD-D5C7-4A4C-9DA3-44498E066615}] => (Block) C:\program files (x86)\guild wars 2\gw2.exe
FirewallRules: [TCP Query User{3EB9D856-069D-41EF-AF6C-25C6552E905A}C:\program files\comicrack\comicrack.exe] => (Allow) C:\program files\comicrack\comicrack.exe
FirewallRules: [UDP Query User{2D9C4F63-2E51-481A-9793-DDD38B0B39C8}C:\program files\comicrack\comicrack.exe] => (Allow) C:\program files\comicrack\comicrack.exe
FirewallRules: [{CADF2C72-2D00-4C2A-B964-838F9F13D049}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stranger's Wrath\Launcher.exe
FirewallRules: [{68174B03-A249-4BAC-ADFE-9224BEECA6F5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stranger's Wrath\Launcher.exe
FirewallRules: [TCP Query User{518B102D-0A33-4B42-B3E2-9F770CCC9B42}C:\program files (x86)\the witcher 2\bin\witcher2.exe] => (Allow) C:\program files (x86)\the witcher 2\bin\witcher2.exe
FirewallRules: [UDP Query User{740DC195-6EC6-4BF5-AEB1-17B5C1F1D9F2}C:\program files (x86)\the witcher 2\bin\witcher2.exe] => (Allow) C:\program files (x86)\the witcher 2\bin\witcher2.exe
FirewallRules: [{C4D20F6D-32F7-4041-A1CE-4FE76FB14115}] => (Block) C:\program files (x86)\the witcher 2\bin\witcher2.exe
FirewallRules: [{34ED931F-4B87-4BDF-AB41-F65DCE20201A}] => (Block) C:\program files (x86)\the witcher 2\bin\witcher2.exe
FirewallRules: [{FAC03BA6-EB65-454A-BD4E-76B6F4C01260}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman Absolution\HMA.exe
FirewallRules: [{552AA8D9-D665-4C27-BDA1-716A8F8D34B7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman Absolution\HMA.exe
FirewallRules: [{23CC9AB4-82C0-4378-AAA0-57EA90C809D1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Orcs Must Die!\Build\release\OrcsMustDie.exe
FirewallRules: [{372B9023-5063-4EDD-9107-B44C7051B9AB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Orcs Must Die!\Build\release\OrcsMustDie.exe
FirewallRules: [{4CD95026-7545-4216-8671-ADBC3940000F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{3E89A720-4CF7-408C-92E9-DFCDEB36BB99}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{248FF237-F533-4AAF-954F-89DCEFDBF555}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DXHRML\dxhrml.exe
FirewallRules: [{05A1EB00-A348-4DDA-AB69-5C5040E54069}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DXHRML\dxhrml.exe
FirewallRules: [{6D2BC6AD-FAA5-4EA1-B1AD-35CF75EC259F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{9372880A-9C54-4560-A1BA-611E2C25C3CE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{E1DB4F9D-3F63-4889-AC94-869F5F6825BE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Solar 2\Solar2.exe
FirewallRules: [{41D8264F-30D2-45E5-831C-6603EF7D18CC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Solar 2\Solar2.exe
FirewallRules: [{7B4DEC19-6D34-41EB-A91D-5E61F503A0CE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{D81B03B2-F0A2-47FB-B258-01D7F3EDFAA0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{D5498855-7030-461F-A63C-B6BD3EA61597}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SimCity 4 Deluxe\Apps\SimCity 4.exe
FirewallRules: [{6127BBA0-AA25-44A2-AFC1-FDE11B3D3A4D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SimCity 4 Deluxe\Apps\SimCity 4.exe
FirewallRules: [{0AFBEFBD-1095-4DB5-9D3B-EEBE9A9D3A55}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SimCity 4 Deluxe\Support\EA Help\Electronic_Arts_Technical_Support.htm
FirewallRules: [{DD104EFF-F941-40FA-9114-F0D433F337A3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SimCity 4 Deluxe\Support\EA Help\Electronic_Arts_Technical_Support.htm
FirewallRules: [{9D876EB8-6CBE-4C51-B15C-2ED7A7963968}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{B472472A-30BA-438F-87C5-FC6419F168C3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{40E8FAD2-1760-4655-BD7F-1DB46E702333}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Vessel\Vessel.exe
FirewallRules: [{183D35CA-6AB8-4C71-B962-0ECFAE37380B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Vessel\Vessel.exe
FirewallRules: [{5671CADD-778A-46CD-909B-00E18A31C200}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [{35D6C2A6-D006-41CA-AC11-BFD5F863D720}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [TCP Query User{AD0B3509-FE5B-4995-BAD6-CB4D0F560226}C:\users\michael\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\michael\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{4920CAF0-9327-4573-88BB-3E36DF24DDFE}C:\users\michael\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\michael\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{A8F7925F-5696-4E29-9711-78718EFB650A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Evoland\Evoland.exe
FirewallRules: [{7D6083C0-7619-456A-8E23-2798484086CA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Evoland\Evoland.exe
FirewallRules: [{8DBC9887-DBC5-44C3-B4FD-A807FA205424}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{861839DF-BB83-4A30-B478-7D903A051310}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{ABC9CD25-F127-42EC-A843-C40BD33EC16D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{345709F5-0D46-4EF7-9A28-B9DD01FE7272}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{74B30CD5-A13E-42C5-A0B1-5A6CDE80CEDC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PAYDAY 2 Beta\payday2_win32_release.exe
FirewallRules: [{B3A38D75-4C70-43EB-ABC8-00C4777584F9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PAYDAY 2 Beta\payday2_win32_release.exe
FirewallRules: [{739F455D-7B73-4BDA-A7EC-E048CCA3C39C}] => (Allow) C:\Users\Michael\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{F436C41C-1AE2-4C99-AF32-1670B03BDEA2}] => (Allow) C:\Users\Michael\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{998522F3-CFED-4981-B5B8-BB67224CDE55}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{D6094518-E50F-4FF4-A1A8-2F9121B4C825}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{591A937E-B916-4A83-A765-FA989A974E5D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Recettear\recettear.exe
FirewallRules: [{3E89B2A3-E04B-4C5D-BF32-EE6C24DD9ECC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Recettear\recettear.exe
FirewallRules: [{D0A5B849-D13A-4AC3-A6B1-A0768695095C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Recettear\custom.exe
FirewallRules: [{78478DF9-32B1-4FF5-9B63-A39226CF649B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Recettear\custom.exe
FirewallRules: [{ECD57D71-4B2A-4F14-B231-82DAC7AA9CFE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\they bleed pixels\They Bleed Pixels PC.exe
FirewallRules: [{E8D8F371-5D92-4CE5-B7D9-37711F4C329D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\they bleed pixels\They Bleed Pixels PC.exe
FirewallRules: [{43B5B143-648D-4ABB-8695-0196B8782EA7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Anodyne\Anodyne.exe
FirewallRules: [{DCE88040-DDFA-4CE1-91DF-229610B57C82}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Anodyne\Anodyne.exe
FirewallRules: [{3D7D3609-DCCA-4FDE-A928-C12CD1458C16}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\hotline_miami\HotlineMiami.exe
FirewallRules: [{A1009040-0CDF-4B58-B9C2-9E73A92FCC8C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\hotline_miami\HotlineMiami.exe
FirewallRules: [{261C641E-3E7F-4405-A017-4A6A41E16936}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mars War Logs\MarsWarLogs.exe
FirewallRules: [{CE5BA647-9259-4EF8-A9B6-C3C69709D8A6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mars War Logs\MarsWarLogs.exe
FirewallRules: [{149B886E-9B9D-47F7-83FE-0F210BC9525D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FEZ\FEZ.exe
FirewallRules: [{04DD1099-3D72-4B1F-B5E0-522EE8E493B5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FEZ\FEZ.exe
FirewallRules: [{2B9DCC28-C957-4E54-8F27-89EBA0991B0B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FEZ\FEZ_LaunchOptions.exe
FirewallRules: [{69BCF071-B000-49D1-9713-4D2A0EA5B527}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FEZ\FEZ_LaunchOptions.exe
FirewallRules: [{E94B8BBE-0A04-40DA-976F-36AA32DF9E89}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe
FirewallRules: [{BAADD635-1719-49D6-8A73-BAC5355A0064}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe
FirewallRules: [{29788CF0-34F8-4370-B91F-0FB89380DCD6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BrutalLegend\BrutalLegend.exe
FirewallRules: [{9ADF23EE-AD7D-44B8-ACC1-8E7C28EDAC34}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BrutalLegend\BrutalLegend.exe
FirewallRules: [{53647FAC-FDBC-481E-948D-CF71587E6565}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Psychonauts\Psychonauts.exe
FirewallRules: [{400E7940-EAA5-439A-B939-4E8B144E6CF1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Psychonauts\Psychonauts.exe
FirewallRules: [TCP Query User{BE268B43-A686-47C6-B920-07B6E49B3B7B}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe
FirewallRules: [UDP Query User{84A1D798-2F90-47A9-9149-8C275FB1FB01}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe
FirewallRules: [{A6D8696E-8ADB-493C-A8BE-110DC6EEC2B0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TinyBarbarianDX\TinyBarbarianDX.exe
FirewallRules: [{76D3CC44-00CD-461D-9F19-DA59ABD9639B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TinyBarbarianDX\TinyBarbarianDX.exe
FirewallRules: [{0D16C20E-20B9-417D-BA95-EC4ABE96FF96}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{CE55B0E0-2692-40B1-9713-B4F2EA77C2D5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{1431A38A-A3EF-4FC7-9C98-53661531DF0F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{22BA6799-D4ED-445F-882C-4430DC7CE8F6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{C17443F3-BECB-4442-9A5F-88B759D24A1B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{F6215155-BF3C-49AE-A0A6-FE141A5F28ED}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{D83A9F4C-32C6-43A7-83B9-4285FA580D82}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{00187EEB-73B2-47FE-B6DF-F6ABAED5E69F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{D11C4900-E94A-4C5B-9168-AC71F147C784}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{055624DE-AAA5-4457-BAE7-53B7DD70EF2F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{4580A8D2-A66C-49B5-AEDD-E4F7F63AC34B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{BCA794AF-C5AF-4E77-A32A-CBC733C3E51E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{61351BF9-8C10-4146-BC00-BE25EAA7B574}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Reus\Reus.exe
FirewallRules: [{EA7B5A19-D915-4B7A-AFFE-A3D7F8B62647}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Reus\Reus.exe
FirewallRules: [{0D7DD702-A4F0-4503-AD65-D30629D133BF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{DAD3AB89-D096-4577-AFA1-8AD954F8003A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{93D0B68D-91BC-43DD-A974-D71A6F49E785}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{984C4DC0-438D-4A38-8CBF-4132F429C056}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{ADD23156-0388-4CD6-8055-6CF33567D1A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{5F492B42-0CFC-476E-B916-3A02B5926B28}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{84A41741-14F6-4CB2-ABD6-E61470950590}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{5BC6EEF3-51C8-4382-9FD6-D7AC223991AB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{631E53AF-AF11-428C-9BBF-8226DC5CF56E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{6242DACA-065C-4DAF-A844-70C2907CAAB6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{4D2CA06A-8246-4384-AC28-9C3A5767BDC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{0AC26730-F9C9-4526-B6EA-95252A9374A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{96E6B832-7FBA-42B6-B869-ECD63B7DD363}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{9B73CF88-60AC-44A2-A178-33ADB1460660}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{B1F5FCF1-8CA5-44A6-AE12-3DC0A763170A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{4E02F8D7-65D0-4C69-A11E-C8A4D1071A13}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{F0E0944C-A16F-46EB-8352-86A4B28939E1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bully Scholarship Edition\Bully.exe
FirewallRules: [{545EF150-A3C1-47A0-97BD-072FF1F3EE3A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bully Scholarship Edition\Bully.exe
FirewallRules: [{8344233C-D3AA-4074-8687-32275011D2E8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Revenge of the Titans\RevengeOfTheTitans.exe
FirewallRules: [{29A7B73C-4DCD-4E6F-8A50-F92742E1CE44}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Revenge of the Titans\RevengeOfTheTitans.exe
FirewallRules: [{F4E42AE8-ED6B-4AD5-9615-F081FB277FB0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{567600D7-B716-4BEB-B48D-C619A01FFA5E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{16980C10-0B61-45C3-A206-F9D94E9327B5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{A81C9B0F-5420-4285-8241-5AA3CA2C200C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{0DFD1DE4-6E35-408D-B5D2-6FF089B58ADA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{6C3F9D3C-5FA2-44B0-BE41-A08C227D8FD7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{035BBE4C-8F4F-4908-B3D0-D826C87FC030}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Teslagrad Demo\Teslagrad.exe
FirewallRules: [{C6F61136-9C7E-4A8D-B6DD-763F44A71616}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Teslagrad Demo\Teslagrad.exe
FirewallRules: [{7C5C9F88-68E7-46B2-A4B8-F5488B76F77E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{1B4866CA-A71A-406E-9A87-C320C53988CD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{4F7026F3-CBDE-407F-BA79-470EBCAB8619}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{5F582107-5D58-4B65-8E8E-DB7235D07AAF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{4966B9D4-7751-45FF-8307-F57F4902AC3D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [{F67DD270-8426-4630-B4EE-3C3E818123A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [{7B0152D6-343D-49C3-AC86-250EA259F7FF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [{AFDB25EA-E151-4709-B955-A783BA4587C2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [{005EBE35-1526-4F4A-BE7A-650AC45E6601}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead\WalkingDead101.exe
FirewallRules: [{2DC710F7-3AF9-4A8B-9DF5-5A8B68AB66A8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead\WalkingDead101.exe
FirewallRules: [{49CDA40F-FA4D-435E-BC3E-73CF39E023C4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{1CA8B212-DFEC-4A69-9E61-CE4EC7287B8B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{0AC53880-8D92-4A0D-AFB5-D65406ED6642}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon.exe
FirewallRules: [{49108D75-33BA-422A-82D8-5E6635EB4E0A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon.exe
FirewallRules: [TCP Query User{A6666B70-2CB1-48B7-9666-6769E211EE87}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{67116663-9DEA-4FD3-8529-58773AE4801B}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [{675D4C0A-223C-41C8-860F-57A8C409FCE0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Revenge of the Titans\RevengeOfTheTitans.exe
FirewallRules: [{7FB47CA4-E65E-4E9C-9D74-9CDA6F0D35FC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Revenge of the Titans\RevengeOfTheTitans.exe
FirewallRules: [TCP Query User{277D869B-B211-4209-9883-1537CE7EE878}C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe
FirewallRules: [UDP Query User{B7BA912C-C22D-4FE7-BFB9-6C0E9213A62F}C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe
FirewallRules: [{76963B55-F543-4A03-9D92-8311BB710817}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{6A59C68C-9410-4C66-9626-0E198853F65F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{E5561779-571E-49F2-BC4F-5190108F9946}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Guacamelee\Guac.exe
FirewallRules: [{541958EF-9175-4AEE-AF16-EA3AE855FFC1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Guacamelee\Guac.exe
FirewallRules: [{D45832D9-5291-4F64-813A-12F303FB38E7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{6FB5B177-87C3-4F81-A8C0-405A78295EE6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{256FA3B3-007C-4908-A175-B63560109BF2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{1DB4BA76-1A3E-4E07-B7F4-70159752D788}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{C4C85C24-41A0-4BE9-865A-E6BE9FC94FA2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{05517B17-D0E3-4162-BAC2-FB9CBE878002}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{E03CB1E3-7009-4327-B37D-64113BA3509B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{035A53A3-4AE4-4E0E-90B4-6B3961F2CCB8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{956BFC5A-91F2-42CA-8569-97CFF66F990F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon.exe
FirewallRules: [{948B9DFF-B00A-4671-82C5-EA38750B6EFF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon.exe
FirewallRules: [{71825292-E4C2-4030-B556-A2F6C81BBCEB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{E9813D0A-442F-4C72-A496-BC3BACC1E079}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{8894FA8B-E6E0-4F08-B9DF-C52AE5DEA010}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{FEE5AE00-96BE-4015-908C-0A45D0D478A7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{9198D856-3DE3-451E-9CB3-BFF8BAA1F9C7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\rust\rust.exe
FirewallRules: [{8558D261-17E8-4956-A97A-9A7ECA30C469}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\rust\rust.exe
FirewallRules: [{DA18CBB9-C25D-4113-8521-7EBC838B8C2F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{939C0611-9882-42BA-99EC-3FB06EC7A193}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{490CF8FF-4CCC-48F5-90E7-0739D26C5588}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{65691E96-6BB5-41E6-8A96-8CA5B1B71E9E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{E78D3DF8-F338-4B1A-B0F0-1B451377A5C0}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{1BB640A1-67A0-4E29-B11A-C9121811D286}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{9BE0B95A-593F-437F-AE35-D28D0D247404}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{4D2CF2F7-5193-49D6-9AC1-E9CAE29C191F}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{B2F0C57C-D80D-4E56-9A28-AD0E1B345472}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Secret World\ClientPatcher.exe
FirewallRules: [{623FD171-6F74-457B-9AA4-D9B6B73A823B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Secret World\ClientPatcher.exe
FirewallRules: [{E745A027-D954-47A6-8323-C2BFDA4730D4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Returns\Shadowrun.exe
FirewallRules: [{83110B5D-EC90-4FDC-BF20-586D634EBEB1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Returns\Shadowrun.exe
FirewallRules: [{57AEB719-D9D5-4558-8D81-7B7FA8ACA547}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Remember Me\Binaries\Win32\RememberMe.exe
FirewallRules: [{7419AC9F-C509-4A33-AC01-FB041F4D7339}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Remember Me\Binaries\Win32\RememberMe.exe
FirewallRules: [{F5440DDF-B7C0-43E3-9BF2-B03EC6511FB4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rogue Legacy\RogueLegacy.exe
FirewallRules: [{7F6727D4-241E-450E-8418-145C81A4C291}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rogue Legacy\RogueLegacy.exe
FirewallRules: [{ABA4D3E8-BDA8-4730-91CC-F71CAFBE04C3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Surgeon Simulator 2013\ss2013.exe
FirewallRules: [{66A0AA82-B89C-4087-B245-C50449845E4F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Surgeon Simulator 2013\ss2013.exe
FirewallRules: [{B53E401F-3BD6-4CFF-97EF-6D94AADDC974}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Octodad Dadliest Catch\OctodadDadliestCatch.exe
FirewallRules: [{57D24C64-BF7D-446E-B0CA-750308DFB15C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Octodad Dadliest Catch\OctodadDadliestCatch.exe
FirewallRules: [{5135B711-8DFB-4AE9-8A66-B0F37D47B034}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{65D52BB1-59B0-41E8-A1FD-865BA821EB47}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{4F2CCA0F-E188-48DC-B417-49DDA2EA36F3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe
FirewallRules: [{F2E80592-E87F-4C6D-9402-8DBF3AA944AC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe
FirewallRules: [{5CDF5E1C-6C43-417A-B092-7075190D68DD}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{1A626A54-B0EA-41A6-899B-D6FA00CC49EF}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{6ABA6768-DB08-41FF-A5E6-B2E3DD1258CB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Legend of Grimrock\grimrock.exe
FirewallRules: [{EB99D301-3D59-4E4E-891D-D2D284580687}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Legend of Grimrock\grimrock.exe
FirewallRules: [{7D80C5DD-59B1-4A33-A254-EB4465469683}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Five Nights at Freddy's\FiveNightsatFreddys.exe
FirewallRules: [{9D569C15-B2A1-4242-AD9A-87DCC081639F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Five Nights at Freddy's\FiveNightsatFreddys.exe
FirewallRules: [{ADBC0EE5-952B-4D2C-976F-102A384E483E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Transistor\x64\Transistor.exe
FirewallRules: [{B10A9BBE-9124-4AC9-8C61-F50FB8EC7E73}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Transistor\x64\Transistor.exe
FirewallRules: [{88B22EEC-D0E1-4895-BAC3-36A1ABA90739}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dungeons & Dragons HD\ManaGame.exe
FirewallRules: [{72AFBF8D-5876-4EA7-A8AF-5D9C2B86FDE7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dungeons & Dragons HD\ManaGame.exe
FirewallRules: [{0FCAD903-8AEB-4CD8-9612-6BEC56A6CF03}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bionic Commando Rearmed\bcr.exe
FirewallRules: [{A3F977A7-8389-4779-A295-6D5B292413C8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bionic Commando Rearmed\bcr.exe
FirewallRules: [{E80A1482-4FE9-4C01-A34E-B31E5E8B1C52}] => (Allow) LPort=8888
FirewallRules: [TCP Query User{DC6EB690-B1C0-455E-8568-4FF05069AF93}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe
FirewallRules: [UDP Query User{C145E381-435A-48DA-A03E-89833C064CFD}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe
FirewallRules: [{A3493FF8-7648-4EEA-8D28-B7F5CBAD80DE}] => (Allow) LPort=8888
FirewallRules: [{783871DC-416A-45DD-9381-2AD54A660D8D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Nidhogg\Nidhogg.exe
FirewallRules: [{62DA9F5A-49A1-4A2F-AE2D-E470C9CAA507}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Nidhogg\Nidhogg.exe
FirewallRules: [{401E1439-562B-4E40-9C0F-46C97425C726}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Castlevania Lords of Shadow - Mirror of Fate HD\CMOF.exe
FirewallRules: [{A7FE8355-02C7-49F5-93C9-5A7F12091672}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Castlevania Lords of Shadow - Mirror of Fate HD\CMOF.exe
FirewallRules: [{5FD90A0F-4F57-4398-98D0-3AC14030EA20}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{2454A98A-ADAE-478C-89AF-5EBBF252AE15}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{C96F1FFE-B008-410A-A216-D0D4A893B3A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\CastlevaniaLoS\bin\CastlevaniaLoSUE.exe
FirewallRules: [{55998790-537E-4591-AD29-DDDC0E1BD4D3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\CastlevaniaLoS\bin\CastlevaniaLoSUE.exe
FirewallRules: [{EA63ABC7-1A27-42B3-AFFF-E63243EE6992}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Styx\Binaries\Win64\StyxGame.exe
FirewallRules: [{1187E46D-A5D0-4BBC-84B0-86EF4A4C7F2F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Styx\Binaries\Win64\StyxGame.exe
FirewallRules: [{CBCC9230-C6FF-4B7F-B2EB-DFD21ACC1DE6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\CreationKit.exe
FirewallRules: [{6FF2407B-1773-4F5F-9B13-A81B1602497C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\CreationKit.exe
FirewallRules: [{73628E4D-E334-43F2-B531-1BFB5F756017}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Gnomoria\Gnomoria.exe
FirewallRules: [{17CEDEC4-5F4C-4D81-81EF-6BA1DCE71F53}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Gnomoria\Gnomoria.exe
FirewallRules: [{D13D0ED7-E074-429D-B7B9-964CC845D5E8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Dragonfall Director's Cut\Dragonfall.exe
FirewallRules: [{9C648C06-14C8-4C54-A726-232A762A7679}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Dragonfall Director's Cut\Dragonfall.exe
FirewallRules: [{A5843F24-9CA4-4514-AB13-315FBEBB677E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SleepingDogsDefinitiveEdition\sdhdship.exe
FirewallRules: [{7476A0AF-768C-46C5-AF1D-4853A96DE7F6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SleepingDogsDefinitiveEdition\sdhdship.exe
FirewallRules: [{260640F9-754F-4FB5-9399-7FEFCB5C9E56}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TheLongDark\tld.exe
FirewallRules: [{E73316FF-35F3-442C-9055-856910642354}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TheLongDark\tld.exe
FirewallRules: [{A1FA3210-2371-45F8-8EE4-5EB9E20D5A74}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Game of Thrones\Thrones.exe
FirewallRules: [{2613920A-4169-446A-83C5-77B49748CB36}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Game of Thrones\Thrones.exe
FirewallRules: [{18189144-BCB0-4B7A-8770-6DDBB13CC69E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2CD312BA-A096-43DE-BC59-C74636E08E27}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BF287FAB-ACF3-4BD0-84F0-D87283E230BD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{13C909C5-3284-442D-A8B7-B4657BE45DF7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{B3511193-4F80-4A14-94AB-FEC2B6775062}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{794906FD-513D-424A-8280-235D3AC9F07A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CC7AC7E4-91E4-4A6B-BFE5-9DB6FCDA6C3C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Stomping Land\Binaries\Win32\UDK.exe
FirewallRules: [{74A367C8-8636-47A5-B718-9991075E95DA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Stomping Land\Binaries\Win32\UDK.exe
FirewallRules: [{46DD5DDD-DCF6-4FFD-AB5C-A2CD983A7C17}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon_DirectToRift.exe
FirewallRules: [{86F9C0D8-F274-4C49-BA2C-940420F8F9C6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon_DirectToRift.exe
FirewallRules: [{FC534A64-151E-4BB0-A60B-4237CD70C5A4}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{0AE60447-4C7C-4E59-803B-8C984C0D7330}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{8FD55EEA-D5FA-49D1-AA12-912A763CC5AA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Divinity - Original Sin\Shipping\EoCApp.exe
FirewallRules: [{9C1C11E1-A17F-446E-A29D-F040FE10F2F8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Divinity - Original Sin\Shipping\EoCApp.exe
FirewallRules: [{637AFE18-3A5A-4DB9-893E-D70B5E38A7F1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{849BE47D-5D53-43AC-B3CD-6B4F634737CC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{1E10D591-1225-4C06-8CA7-CBE2AE5BA108}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Westerado\WesteradoDB.exe
FirewallRules: [{81A6F3EF-C172-4E86-840C-D47A92EA5535}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Westerado\WesteradoDB.exe
FirewallRules: [{D4D74FB1-40AF-4C86-9ABC-14AC918869F1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shovel Knight\ShovelKnight.exe
FirewallRules: [{811447FF-E3EA-47C5-8B98-E5913A198FC4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shovel Knight\ShovelKnight.exe
FirewallRules: [{20DCC540-BD28-4594-AB4F-B1494502B1A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\tbs\win32\The Banner Saga.exe
FirewallRules: [{92E3D3CE-BDD9-42D7-87B1-00406E7D082B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\tbs\win32\The Banner Saga.exe
FirewallRules: [{F97414AB-9DAA-48C7-A084-4CFE513B8C89}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{A7A21066-E01E-4E9F-A4E2-FDB256BDE37A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{AA8E2CA5-F9D1-4F0C-8A2B-7BA2216A44DE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{7EAF95F2-FF25-418F-BF85-9F223024F427}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{DBE35B99-CC5D-483E-A7A4-07FB68A9E8D4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{1FB15D9F-2F78-4332-B5C9-734D0AFC81DB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King of Dragon Pass\King of Dragon Pass.exe
FirewallRules: [{96757209-E0AD-4F9E-A081-709A193395C1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King of Dragon Pass\King of Dragon Pass.exe
FirewallRules: [{ACAAC47B-D4A8-4D69-AA54-31C52540F41D}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{C41E96BD-AD69-4347-971D-0711EBBF8A21}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe
FirewallRules: [{16502BD0-DFE2-4A45-8534-4FAAF5C1C72B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe
FirewallRules: [{85A13C50-7B47-4252-AE44-B20EC4C83730}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mad Max\MadMax.exe
FirewallRules: [{060DE892-77C2-4186-95B7-DDA33A6AB224}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mad Max\MadMax.exe
FirewallRules: [{9DAED1AB-7C3E-4B27-9C58-85E9E1A13D71}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\abyss_odyssey\Binaries\Win32\AO.exe
FirewallRules: [{B7AB5A7A-1992-446E-A23D-D8BEEA97F9B5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\abyss_odyssey\Binaries\Win32\AO.exe
FirewallRules: [{038E478A-CCAB-4D4A-B354-60F8018C3E74}] => (Allow) C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe
FirewallRules: [{C2CA25B1-BEA2-4611-9665-09D8AE08E8A7}] => (Allow) C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe
FirewallRules: [{3E9008D6-44F9-492F-9130-8EB087F8A2E6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{4B5DB14B-5900-40F1-A54E-62F4DEBC0678}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{130EC5B6-F741-40ED-B9D3-9AC0FA1D348A}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{662E4177-72FA-4EF2-9E1C-C34E105A2889}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{DA6BDAD2-9CFD-4961-9D6A-C9B25D429728}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DarkestDungeon\_windows\Darkest.exe
FirewallRules: [{DBA37D16-2BF1-4737-B8A6-96107A61A7FB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DarkestDungeon\_windows\Darkest.exe
FirewallRules: [{E9352C7B-B1A3-4936-89F9-88B7BE6FFAC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Jotun\Jotun.exe
FirewallRules: [{FB5D96A0-BED4-4E7A-BB3D-E1904FECAFF5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Jotun\Jotun.exe
FirewallRules: [{D4F1CE35-7BA3-4152-B695-1F2B68358A61}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Pillars of Eternity\PillarsOfEternity.exe
FirewallRules: [{6B93DB34-131E-48C1-A3D7-F26D4786745E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Pillars of Eternity\PillarsOfEternity.exe
FirewallRules: [{338260AB-8949-4BAA-83D3-9BFCB4D4D732}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1BCFC91E-B5B7-48E7-89C8-DF3160A4F5D2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C808AA96-2C71-46A2-9EC2-B89B7B1D975F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: Video Controller
Description: Video Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/17/2015 08:41:53 AM) (Source: ISCT Agent) (EventID: 1003) (User: )
Description: CAgentState::DoPeriodicSuspendResume    ****Error in initialize NetDetect, status = 0x2

Error: (11/16/2015 10:37:54 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ModOrganizer.exe, version: 1.2.14.0, time stamp: 0x54315b0e
Faulting module name: ModOrganizer.exe, version: 1.2.14.0, time stamp: 0x54315b0e
Exception code: 0xc0000005
Fault offset: 0x00027edf
Faulting process id: 0xa94
Faulting application start time: 0xModOrganizer.exe0
Faulting application path: ModOrganizer.exe1
Faulting module path: ModOrganizer.exe2
Report Id: ModOrganizer.exe3

Error: (11/16/2015 10:05:35 AM) (Source: ISCT Agent) (EventID: 1003) (User: )
Description: CAgentState::DoPeriodicSuspendResume    ****Error in initialize NetDetect, status = 0x2

Error: (11/16/2015 09:59:32 AM) (Source: ISCT Agent) (EventID: 1003) (User: )
Description: CAgentState::DoPeriodicSuspendResume    ****Error in initialize NetDetect, status = 0x2

Error: (11/16/2015 09:49:02 AM) (Source: ISCT Agent) (EventID: 1003) (User: )
Description: CAgentState::DoPeriodicSuspendResume    ****Error in initialize NetDetect, status = 0x2

Error: (11/14/2015 09:48:15 PM) (Source: ISCT Agent) (EventID: 1003) (User: )
Description: CAgentState::DoPeriodicSuspendResume    ****Error in initialize NetDetect, status = 0x2

Error: (11/14/2015 04:04:17 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (11/14/2015 03:30:36 AM) (Source: ISCT Agent) (EventID: 1003) (User: )
Description: CAgentState::DoPeriodicSuspendResume    ****Error in initialize NetDetect, status = 0x2

Error: (11/12/2015 08:59:09 AM) (Source: ISCT Agent) (EventID: 1003) (User: )
Description: CAgentState::DoPeriodicSuspendResume    ****Error in initialize NetDetect, status = 0x2

Error: (11/12/2015 07:24:49 AM) (Source: ISCT Agent) (EventID: 1003) (User: )
Description: CAgentState::DoPeriodicSuspendResume    ****Error in initialize NetDetect, status = 0x2


System errors:
=============
Error: (11/17/2015 08:46:46 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Windows Search service hung on starting.

Error: (11/17/2015 08:42:41 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The WinRing0_1_2_0 service failed to start due to the following error:
%%2

Error: (11/17/2015 08:35:15 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1068fdPHost{D3DCB472-7261-43CE-924B-0704BD730D5F}

Error: (11/17/2015 08:35:15 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
%%1068

Error: (11/17/2015 08:35:15 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1068fdPHost{145B4335-FE2A-4927-A040-7C35AD3180EF}

Error: (11/17/2015 08:31:17 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
%%1068

Error: (11/17/2015 08:31:17 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
%%1068

Error: (11/17/2015 08:31:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
%%1068

Error: (11/17/2015 08:31:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
%%1068

Error: (11/17/2015 08:31:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
%%1068


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz
Percentage of memory in use: 20%
Total physical RAM: 16267.12 MB
Available physical RAM: 12906.91 MB
Total Virtual: 32532.37 MB
Available Virtual: 29129.09 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:18.81 GB) NTFS
Drive i: (Ginnungagap) (Fixed) (Total:3726.02 GB) (Free:2558.64 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: FFC0A867)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
Attempted reading MBR returned 0 bytes.
 Could not read MBR for disk 1.

==================== End of Addition.txt ============================

08:36:01.0061 0x0660  TDSS rootkit removing tool [removed] Jul 24 2015 12:29:57
08:36:04.0930 0x0660  ============================================================
08:36:04.0930 0x0660  Current date / time: 2015/11/17 08:36:04.0930
08:36:04.0930 0x0660  SystemInfo:
08:36:04.0930 0x0660  
08:36:04.0930 0x0660  OS Version: 6.1.7600 ServicePack: 0.0
08:36:04.0930 0x0660  Product type: Workstation
08:36:04.0930 0x0660  ComputerName: YMIR
08:36:04.0930 0x0660  UserName: Michael
08:36:04.0930 0x0660  Windows directory: C:\Windows
08:36:04.0930 0x0660  System windows directory: C:\Windows
08:36:04.0930 0x0660  Running under WOW64
08:36:04.0930 0x0660  Processor architecture: Intel x64
08:36:04.0930 0x0660  Number of processors: 4
08:36:04.0930 0x0660  Page size: 0x1000
08:36:04.0930 0x0660  Boot type: Safe boot
08:36:04.0930 0x0660  ============================================================
08:36:09.0142 0x0660  KLMD registered as C:\Windows\system32\drivers\71947552.sys
08:36:09.0594 0x0660  System UUID: {BA6C5102-CFBA-1FB8-070C-C786D42307A7}
08:36:10.0468 0x0660  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
08:36:10.0468 0x0660  Drive \Device\Harddisk1\DR1 - Size: 0x3A3817D5000 ( 3726.02 Gb ), SectorSize: 0x1000, Cylinders: 0xED80, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
08:36:10.0484 0x0660  ============================================================
08:36:10.0484 0x0660  \Device\Harddisk0\DR0:
08:36:10.0484 0x0660  MBR partitions:
08:36:10.0484 0x0660  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
08:36:10.0484 0x0660  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
08:36:10.0484 0x0660  \Device\Harddisk1\DR1:
08:36:10.0671 0x0660  MBR partitions:
08:36:10.0671 0x0660  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A380FD5
08:36:10.0671 0x0660  ============================================================
08:36:10.0811 0x0660  C: <-> \Device\Harddisk0\DR0\Partition2
08:36:10.0858 0x0660  I: <-> \Device\Harddisk1\DR1\Partition1
08:36:10.0858 0x0660  ============================================================
08:36:10.0858 0x0660  Initialize success
08:36:10.0858 0x0660  ============================================================
08:37:12.0088 0x0398  ============================================================
08:37:12.0088 0x0398  Scan started
08:37:12.0088 0x0398  Mode: Manual; SigCheck; TDLFS;
08:37:12.0088 0x0398  ============================================================
08:37:12.0088 0x0398  KSN ping started
08:37:12.0463 0x0398  KSN ping finished: false
08:37:15.0333 0x0398  ================ Scan system memory ========================
08:37:15.0333 0x0398  System memory - ok
08:37:15.0333 0x0398  ================ Scan services =============================
08:37:15.0895 0x0398  [ 970C70F6B2953ED43822D3797855D84C, CB22723678B514277BC6E6DDDD206F3B2377CD889C9D473A47A7056BE597BC6B ] !SASCORE        C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
08:37:17.0985 0x0398  !SASCORE - ok
08:37:18.0874 0x0398  [ 1B00662092F9F9568B995902F0CC40D5, D345014CF146FA57B2682C189D5E7F27D4C78F321F2723D912D623E777C2BB70 ] 1394ohci        C:\Windows\system32\DRIVERS\1394ohci.sys
08:37:19.0093 0x0398  1394ohci - ok
08:37:19.0217 0x0398  [ 6F11E88748CDEFD2F76AA215F97DDFE5, BD0B3561EDCDE5EFD89372793CFD09DF879709BF469542F4A049705CBA9FD060 ] ACPI            C:\Windows\system32\DRIVERS\ACPI.sys
08:37:19.0217 0x0398  ACPI - ok
08:37:19.0311 0x0398  [ 63B05A0420CE4BF0E4AF6DCC7CADA254, 56BCC219D6B886FD42B7D335B4A7BBA3C9BC148220CBD99F8583FB505DAE63BF ] AcpiPmi         C:\Windows\system32\DRIVERS\acpipmi.sys
08:37:20.0138 0x0398  AcpiPmi - ok
08:37:20.0715 0x0398  [ B362181ED3771DC03B4141927C80F801, 69514E5177A0AEA89C27C2234712F9F82E8D8F99E1FD4273898C9324C6FF7472 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
08:37:20.0715 0x0398  AdobeARMservice - ok
08:37:20.0871 0x0398  [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx         C:\Windows\system32\DRIVERS\adp94xx.sys
08:37:20.0887 0x0398  adp94xx - ok
08:37:20.0949 0x0398  [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci         C:\Windows\system32\DRIVERS\adpahci.sys
08:37:20.0965 0x0398  adpahci - ok
08:37:21.0043 0x0398  [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320         C:\Windows\system32\DRIVERS\adpu320.sys
08:37:21.0043 0x0398  adpu320 - ok
08:37:21.0089 0x0398  [ 4B78B431F225FD8624C5655CB1DE7B61, 198A5AF2125C7C41F531A652D200C083A55A97DC541E3C0B5B253C7329949156 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
08:37:25.0676 0x0398  AeLookupSvc - ok
08:37:25.0879 0x0398  [ DB9D6C6B2CD95A9CA414D045B627422E, A4A0B2ACBFE311C20EF9F06A49DBE02CE90433C2364B292F6E8F78F6C274DF88 ] AFD             C:\Windows\system32\drivers\afd.sys
08:37:25.0988 0x0398  AFD - ok
08:37:26.0128 0x0398  [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440          C:\Windows\system32\DRIVERS\agp440.sys
08:37:26.0144 0x0398  agp440 - ok
08:37:26.0269 0x0398  [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG             C:\Windows\System32\alg.exe
08:37:26.0440 0x0398  ALG - ok
08:37:26.0487 0x0398  [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide          C:\Windows\system32\DRIVERS\aliide.sys
08:37:26.0503 0x0398  aliide - ok
08:37:27.0236 0x0398  ALSysIO - ok
08:37:27.0454 0x0398  [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide          C:\Windows\system32\DRIVERS\amdide.sys
08:37:27.0470 0x0398  amdide - ok
08:37:27.0563 0x0398  [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8           C:\Windows\system32\DRIVERS\amdk8.sys
08:37:27.0641 0x0398  AmdK8 - ok
08:37:27.0688 0x0398  [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
08:37:27.0751 0x0398  AmdPPM - ok
08:37:27.0844 0x0398  [ 7A4B413614C055935567CF88A9734D38, A3BB7CDF3EE0EEF67F89263E81145E73C7142EF5F0AF265375C2ECCE74F932C4 ] amdsata         C:\Windows\system32\DRIVERS\amdsata.sys
08:37:27.0844 0x0398  amdsata - ok
08:37:27.0922 0x0398  [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
08:37:27.0938 0x0398  amdsbs - ok
08:37:27.0953 0x0398  [ B4AD0CACBAB298671DD6F6EF7E20679D, FB566C892D0A3DC0A523AE20F35011996958D670937DD5C1A1FCCD36AAC714D7 ] amdxata         C:\Windows\system32\DRIVERS\amdxata.sys
08:37:27.0953 0x0398  amdxata - ok
08:37:28.0016 0x0398  [ 42FD751B27FA0E9C69BB39F39E409594, DE349CAA570957868CA1CB0BE0FAF551CD4D44FD53EBC4391B9C1C7B9CF295D2 ] AppID           C:\Windows\system32\drivers\appid.sys
08:37:28.0531 0x0398  AppID - ok
08:37:28.0609 0x0398  [ 0BC381A15355A3982216F7172F545DE1, C33AF13CB218F7BF52E967452573DF2ADD20A95C6BF99229794FEF07C4BBE725 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
08:37:28.0702 0x0398  AppIDSvc - ok
08:37:28.0765 0x0398  [ D065BE66822847B7F127D1F90158376E, 20F911F390FF23C2C42361A449C4344DB59F1DC21EDD1E7EBC4E80914DEF7824 ] Appinfo         C:\Windows\System32\appinfo.dll
08:37:28.0874 0x0398  Appinfo - ok
08:37:29.0326 0x0398  [ 2F2BD5EFFA8E91295F4DB493D85534B5, FF6758DC06751028960C9A165767EDAD78B2868599D1A01CAC8108E1699A92DE ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
08:37:29.0326 0x0398  Apple Mobile Device - ok
08:37:29.0420 0x0398  [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc             C:\Windows\system32\DRIVERS\arc.sys
08:37:29.0435 0x0398  arc - ok
08:37:29.0467 0x0398  [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
08:37:29.0482 0x0398  arcsas - ok
08:37:29.0576 0x0398  [ 4DFF4312661F54EE87DC9A13CAEE60E0, 8821D2CA4036E764EFF71108735148FF54D3275DDCE1860EC7D67B2355E8DF82 ] asahci64        C:\Windows\system32\DRIVERS\asahci64.sys
08:37:29.0966 0x0398  asahci64 - ok
08:37:30.0106 0x0398  [ 6FE3237C1177E66437E7AD0E8AC1A6E5, 3223D4E57150DE8F768BC1BE0E6DCFFC6CA5B09DC7D7ADF283C90929100B0B7B ] asmthub3        C:\Windows\system32\DRIVERS\asmthub3.sys
08:37:30.0184 0x0398  asmthub3 - ok
08:37:30.0418 0x0398  [ C4043E39A2ABBC56581CA25DF161E9F7, 1B53A8BEE4823EA842A00F5304428F0B4D14078045CF84ED20D8DF0FB8826040 ] asmtxhci        C:\Windows\system32\DRIVERS\asmtxhci.sys
08:37:30.0543 0x0398  asmtxhci - ok
08:37:31.0510 0x0398  [ 041672BAC20B34EAEDEB033129655DD8, 14264732F0CACF5732C7652C411F0A1C3B4A4417C31DD289C8AFF170BE683E5A ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
08:37:31.0573 0x0398  aspnet_state - ok
08:37:31.0822 0x0398  [ 30E7D7B63BE378C6DCD31434E1C5EBEB, 6F38FBD6B45506E57D4EC6C84C83F0829F280167E14B65643F583B41AA23C18B ] aswHwid         C:\Windows\system32\drivers\aswHwid.sys
08:37:31.0822 0x0398  aswHwid - ok
08:37:32.0025 0x0398  [ 6C3B7781075271AD9DFBD77BC7FBB9F7, AC53FD0EE1D7695219225440D3922EEF0B953F45F0ED3034CF5F1630A6B40607 ] aswMonFlt       C:\Windows\system32\drivers\aswMonFlt.sys
08:37:32.0041 0x0398  aswMonFlt - ok
08:37:32.0103 0x0398  [ 3C04B80B49697EB7DFE5FA43620F8728, 4BC11901898348318BA807938BEA888BC54FE80ADA17C209C728F14EA4E91F21 ] aswRdr          C:\Windows\system32\drivers\aswRdr2.sys
08:37:32.0103 0x0398  aswRdr - ok
08:37:32.0228 0x0398  [ AA8CB23B3B4A4B16F49CB54CA04FE0D9, A94D214B43EDAEC52656EA36C2A830E76C40B90E8F4BABEF4F16BA679A429586 ] aswRvrt         C:\Windows\system32\drivers\aswRvrt.sys
08:37:32.0228 0x0398  aswRvrt - ok
08:37:32.0743 0x0398  [ E40965585B901AA60AF26279E09959E0, F3EACB4F1E78903D648DE75CC01642BFACA76C0605A6831EC24201292891B5DE ] aswSnx          C:\Windows\system32\drivers\aswSnx.sys
08:37:32.0758 0x0398  aswSnx - ok
08:37:32.0883 0x0398  [ B54E400C1B044D6D7D9EF95BA865741E, C929B53F53EFD15D3EE64FED23686A01F77E8F7BC74623D02D10D4CFEC3D6BF2 ] aswSP           C:\Windows\system32\drivers\aswSP.sys
08:37:32.0883 0x0398  aswSP - ok
08:37:32.0992 0x0398  [ 0652346DF90731A87E4C7C9A9C45A8E0, 38B8A760B532254A8CB2FD6B922269A1B96BB5E5F243D130B4BBD09ED50DEDB8 ] aswStm          C:\Windows\system32\drivers\aswStm.sys
08:37:32.0992 0x0398  aswStm - ok
08:37:33.0070 0x0398  [ 54230972D23E6E4D034D7CB577DC784C, 7F51E81CBAFB143982AF2C68675CF0D46DD17A9A17A8805EBF628FAE84DFF8A9 ] aswVmm          C:\Windows\system32\drivers\aswVmm.sys
08:37:33.0070 0x0398  aswVmm - ok
08:37:33.0179 0x0398  [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
08:37:33.0242 0x0398  AsyncMac - ok
08:37:33.0289 0x0398  [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi           C:\Windows\system32\DRIVERS\atapi.sys
08:37:33.0289 0x0398  atapi - ok
08:37:33.0367 0x0398  [ FF50A62EFA151EBCFCDD37A76CA9EA92, FFD5AAEFF5D717237CE244B1FAB6D2EF30A7F6C4DF094F8212BA6F85FB3AE902 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
08:37:33.0429 0x0398  AtiHDAudioService - ok
08:37:33.0491 0x0398  [ 07721A77180EDD4D39CCB865BF63C7FD, 9E8117E747C86154F98F2686D805A981029CC5D11AFB115A529429C9A4579BE5 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
08:37:33.0538 0x0398  AudioEndpointBuilder - ok
08:37:33.0554 0x0398  [ 07721A77180EDD4D39CCB865BF63C7FD, 9E8117E747C86154F98F2686D805A981029CC5D11AFB115A529429C9A4579BE5 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
08:37:33.0585 0x0398  AudioSrv - ok
08:37:33.0959 0x0398  [ 11120878E5276B367E1A10FF8C9B595B, 7C02EEF3733307C31BAC4DA9975EC017AC40D0893D88228C30FFAA536DAA73FB ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
08:37:33.0975 0x0398  avast! Antivirus - ok
08:37:35.0847 0x0398  [ CF5F47B708C539A40EBBDD7E4675FADA, F324726EB8E5B5A3DB74DC7E78B7141999E2677F1B607D6DEF809C1DA92D4A68 ] AvastVBoxSvc    C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
08:37:35.0925 0x0398  AvastVBoxSvc - ok
08:37:36.0112 0x0398  [ B20B5FA5CA050E9926E4D1DB81501B32, 91B9038349BA07E32DE809E6798167EE44087809EB1174B84EC16580040F1BE0 ] AxInstSV        C:\Windows\System32\AxInstSV.dll
08:37:36.0159 0x0398  AxInstSV - ok
08:37:36.0393 0x0398  [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv         C:\Windows\system32\DRIVERS\bxvbda.sys
08:37:36.0487 0x0398  b06bdrv - ok
08:37:36.0736 0x0398  [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
08:37:36.0783 0x0398  b57nd60a - ok
08:37:36.0908 0x0398  [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC          C:\Windows\System32\bdesvc.dll
08:37:37.0017 0x0398  BDESVC - ok
08:37:37.0157 0x0398  [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep            C:\Windows\system32\drivers\Beep.sys
08:37:37.0220 0x0398  Beep - ok
08:37:37.0298 0x0398  [ 4992C609A6315671463E30F6512BC022, 3020034556EAC25CD90F41D3BFFDD0BB2C3D1C5BAC4359F4B71B84A9FC404495 ] BFE             C:\Windows\System32\bfe.dll
08:37:37.0407 0x0398  BFE - ok
08:37:37.0625 0x0398  [ 7F0C323FE3DA28AA4AA1BDA3F575707F, 7FF09CBC16A9E5F357A76FF79A3F0DD047957D474031F51A6BB4916C7911F005 ] BITS            C:\Windows\System32\qmgr.dll
08:37:38.0827 0x0398  BITS - ok
08:37:38.0905 0x0398  [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
08:37:38.0920 0x0398  blbdrive - ok
08:37:39.0201 0x0398  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD, 17BFFC5DF609CE3B2F0CAB4BD6C118608C66A3AD86116A47E90B2BB7D8954122 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
08:37:39.0201 0x0398  Bonjour Service - ok
08:37:39.0248 0x0398  [ 19D20159708E152267E53B66677A4995, 6401FA5C3EFF26BED075FEC68F868CD8D0598FDB45EA9381810615F7252F7A9A ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
08:37:39.0419 0x0398  bowser - ok
08:37:39.0482 0x0398  [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
08:37:39.0544 0x0398  BrFiltLo - ok
08:37:39.0575 0x0398  [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
08:37:39.0575 0x0398  BrFiltUp - ok
08:37:39.0669 0x0398  [ 6B054C67AAA87843504E8E3C09102009, 284AA58625FBDBFECB851A35407331B40BAEC141F2DCEDB9F15733BAB22F5C81 ] Browser         C:\Windows\System32\browser.dll
08:37:39.0763 0x0398  Browser - ok
08:37:39.0903 0x0398  [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
08:37:40.0137 0x0398  Brserid - ok
08:37:40.0168 0x0398  [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
08:37:40.0215 0x0398  BrSerWdm - ok
08:37:40.0262 0x0398  [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
08:37:40.0340 0x0398  BrUsbMdm - ok
08:37:40.0433 0x0398  [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
08:37:40.0480 0x0398  BrUsbSer - ok
08:37:42.0789 0x0398  BS680067079 - ok
08:37:44.0817 0x0398  [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
08:37:44.0864 0x0398  BTHMODEM - ok
08:37:44.0942 0x0398  [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv         C:\Windows\system32\bthserv.dll
08:37:44.0973 0x0398  bthserv - ok
08:37:45.0644 0x0398  [ 68BD23A0AD9E934F037A1D8A1929D1E2, 7104B04435930D085D01779065C8F293A265800D90C9DEFB19C998D9326E44E7 ] c2cautoupdatesvc C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
08:37:45.0675 0x0398  c2cautoupdatesvc - ok
08:37:46.0143 0x0398  [ 13297729C696656F990A5DBA53023129, EB2B34B04B79756199DBBBDE99ACBB576D20C7C0AF3E4F3C0CF0040948216AAC ] c2cpnrsvc       C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
08:37:46.0174 0x0398  c2cpnrsvc - ok
08:37:46.0237 0x0398  [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
08:37:46.0299 0x0398  cdfs - ok
08:37:46.0455 0x0398  [ 83D2D75E1EFB81B3450C18131443F7DB, F2C686C980D818E797818E75B808E1E0B51B2045840A4BFC32D860B7DB4DFA22 ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
08:37:46.0502 0x0398  cdrom - ok
08:37:46.0658 0x0398  [ 312E2F82AF11E79906898AC3E3D58A1F, F6CB7D8B204B94F749D5DBEFD552150AAB16A34D629F87F73823A7504465F106 ] CertPropSvc     C:\Windows\System32\certprop.dll
08:37:46.0751 0x0398  CertPropSvc - ok
08:37:46.0783 0x0398  [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
08:37:46.0798 0x0398  circlass - ok
08:37:46.0907 0x0398  [ FE1EC06F2253F691FE36217C592A0206, B9F122DB5E665ECDF29A5CB8BB6B531236F31A54A95769D6C5C1924C87FE70CE ] CLFS            C:\Windows\system32\CLFS.sys
08:37:46.0923 0x0398  CLFS - ok
08:37:47.0173 0x0398  [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
08:37:47.0173 0x0398  clr_optimization_v2.0.50727_32 - ok
08:37:47.0438 0x0398  [ D1CEEA2B47CB998321C579651CE3E4F8, 654013B8FD229A50017B08DEC6CA19C7DDA8CE0771260E057A92625201D539B1 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
08:37:47.0453 0x0398  clr_optimization_v2.0.50727_64 - ok
08:37:47.0984 0x0398  [ 397C2677C25CBE213F3270245A401624, 8121E37108DE7A0402DC5111EBF452F91893B63EECE3AAD9EACF61C40D3FC182 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
08:37:48.0904 0x0398  clr_optimization_v4.0.30319_32 - ok
08:37:49.0138 0x0398  [ 29139759FCC4E4E0531ABE2EA82CE646, CFF7B2F4A9B37D343BE18DC40161DC03FA9DB308CAE9E0B3DF1FCDC3EBAC0C08 ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
08:37:49.0591 0x0398  clr_optimization_v4.0.30319_64 - ok
08:37:49.0653 0x0398  [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
08:37:49.0684 0x0398  CmBatt - ok
08:37:49.0700 0x0398  [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide          C:\Windows\system32\DRIVERS\cmdide.sys
08:37:49.0700 0x0398  cmdide - ok
08:37:49.0793 0x0398  [ CA7720B73446FDDEC5C69519C1174C98, F24796765587CC1D653A04783B1659564F42E600DA3AFA3DED724592B291D033 ] CNG             C:\Windows\system32\Drivers\cng.sys
08:37:49.0856 0x0398  CNG - ok
08:37:49.0887 0x0398  [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
08:37:49.0887 0x0398  Compbatt - ok
08:37:49.0949 0x0398  [ F26B3A86F6FA87CA360B879581AB4123, 723904362614FE47F6CC0EA0656BA1B47EA32D73BAFB61688A5E5CAE4340B1BF ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
08:37:49.0981 0x0398  CompositeBus - ok
08:37:49.0996 0x0398  COMSysApp - ok
08:37:50.0027 0x0398  [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk         C:\Windows\system32\DRIVERS\crcdisk.sys
08:37:50.0043 0x0398  crcdisk - ok
08:37:50.0137 0x0398  [ BAF19B633933A9FB4883D27D66C39E9A, 2D8ABB5161736CCCADA67B3E6A8D70B0B5E1E3FE6084561891F394DA191B3439 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
08:37:50.0183 0x0398  CryptSvc - ok
08:37:50.0339 0x0398  [ 7266972E86890E2B30C0C322E906B027, BFA30E85F5BD3AA933913BD7C6D2B5993DB7AFB0C98349B61A6BEF0BDC8A3680 ] DcomLaunch      C:\Windows\system32\rpcss.dll
08:37:50.0417 0x0398  DcomLaunch - ok
08:37:50.0542 0x0398  [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc       C:\Windows\System32\defragsvc.dll
08:37:50.0573 0x0398  defragsvc - ok
08:37:50.0651 0x0398  [ 9C253CE7311CA60FC11C774692A13208, 23507138576DB75AA8B7415140F7B5D8A90CB2661796223870461C721A36AEBF ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
08:37:50.0745 0x0398  DfsC - ok
08:37:50.0917 0x0398  [ CE3B9562D997F69B330D181A8875960F, 6FEE6622859198C5C13545867EF7CFE8EDC991360E976F792313DAA9C82CC5C8 ] Dhcp            C:\Windows\system32\dhcpcore.dll
08:37:51.0806 0x0398  Dhcp - ok
08:37:51.0853 0x0398  [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache        C:\Windows\system32\drivers\discache.sys
08:37:51.0899 0x0398  discache - ok
08:37:51.0946 0x0398  [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk            C:\Windows\system32\DRIVERS\disk.sys
08:37:51.0946 0x0398  Disk - ok
08:37:52.0040 0x0398  [ 85CF424C74A1D5EC33533E1DBFF9920A, 882D5FA0D5EC053D76A0C46A6047A621D607651693CF94E5506219EECCC8D079 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
08:37:52.0118 0x0398  Dnscache - ok
08:37:52.0227 0x0398  [ 14452ACDB09B70964C8C21BF80A13ACB, DA0AAAC04626EFF4256D7095FF1DDA1F1B17676E26990C418BDF5090476F2AB4 ] dot3svc         C:\Windows\System32\dot3svc.dll
08:37:52.0274 0x0398  dot3svc - ok
08:37:52.0383 0x0398  [ 8C2BA6BEA949EE6E68385F5692BAFB94, 1047F473DCE0FB56BEA5C1B7929752C1FBAB5983C8202ABB4EEA48FCD60A353A ] DPS             C:\Windows\system32\dps.dll
08:37:52.0445 0x0398  DPS - ok
08:37:52.0555 0x0398  [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
08:37:52.0586 0x0398  drmkaud - ok
08:37:52.0773 0x0398  [ 1633B9ABF52784A1331476397A48CBEF, 697780697C4C55FCCF5FB65C93FB37B3F5A43BF0C59FDBB9EF822D0E993E47BD ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
08:37:52.0789 0x0398  DXGKrnl - ok
08:37:52.0820 0x0398  [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost         C:\Windows\System32\eapsvc.dll
08:37:52.0882 0x0398  EapHost - ok
08:37:52.0976 0x0398  EasyAntiCheat - ok
08:37:53.0600 0x0398  [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv           C:\Windows\system32\DRIVERS\evbda.sys
08:37:53.0693 0x0398  ebdrv - ok
08:37:53.0709 0x0398  [ 156F6159457D0AA7E59B62681B56EB90, 27B855BF79490E4CC58D38A920C077A56785494BFFF0B448A898486009B24937 ] EFS             C:\Windows\System32\lsass.exe
08:37:53.0771 0x0398  EFS - ok
08:37:53.0912 0x0398  [ B91D81B3B54A54CCAFC03733DBC2E29E, B08CFD3136F678CF902722B32CA55C4983EEE5AEBDCEE036BEB746914742141C ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
08:37:54.0083 0x0398  ehRecvr - ok
08:37:54.0130 0x0398  [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched         C:\Windows\ehome\ehsched.exe
08:37:54.0130 0x0398  ehSched - ok
08:37:54.0364 0x0398  [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor         C:\Windows\system32\DRIVERS\elxstor.sys
08:37:54.0380 0x0398  elxstor - ok
08:37:54.0380 0x0398  [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev          C:\Windows\system32\DRIVERS\errdev.sys
08:37:54.0427 0x0398  ErrDev - ok
08:37:54.0645 0x0398  [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem     C:\Windows\system32\es.dll
08:37:54.0692 0x0398  EventSystem - ok
08:37:54.0754 0x0398  [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat           C:\Windows\system32\drivers\exfat.sys
08:37:54.0785 0x0398  exfat - ok
08:37:54.0817 0x0398  [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
08:37:54.0863 0x0398  fastfat - ok
08:37:55.0051 0x0398  [ D607B2F1BEE3992AA6C2C92C0A2F0855, E22301C8F01DBF0A38A85165959BB070647C996CB1BCD50FDFE3DDDCA427DF2A ] Fax             C:\Windows\system32\fxssvc.exe
08:37:55.0113 0x0398  Fax - ok
08:37:55.0144 0x0398  [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
08:37:55.0175 0x0398  fdc - ok
08:37:55.0238 0x0398  [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost         C:\Windows\system32\fdPHost.dll
08:37:55.0285 0x0398  fdPHost - ok
08:37:55.0331 0x0398  [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub        C:\Windows\system32\fdrespub.dll
08:37:55.0347 0x0398  FDResPub - ok
08:37:55.0394 0x0398  [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
08:37:55.0394 0x0398  FileInfo - ok
08:37:55.0409 0x0398  [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
08:37:55.0472 0x0398  Filetrace - ok
08:37:55.0519 0x0398  [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
08:37:55.0519 0x0398  flpydisk - ok
08:37:55.0659 0x0398  [ F7866AF72ABBAF84B1FA5AA195378C59, 9D522044FE9C18FB3EC327E675737C01F2A8231DDE900421D3A431596946A7F8 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
08:37:55.0675 0x0398  FltMgr - ok
08:37:56.0002 0x0398  [ BC00505CFDA789ED3BE95D2FF38C4875, 9CB98AFF8A9740CFB53BDFB3DD40A76EB79C160CF2DF03E5EEFF6F2109216FEB ] FontCache       C:\Windows\system32\FntCache.dll
08:37:56.0127 0x0398  FontCache - ok
08:37:56.0189 0x0398  [ 8D89E3131C27FDD6932189CB785E1B7A, AC7DA4C5E6D2E41D1A1DE146E46F034FAF0FB11AD801F070F2D5CD08166E9EB7 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
08:37:56.0205 0x0398  FontCache3.0.0.0 - ok
08:37:56.0611 0x0398  [ 26EABEEA7F30DCF21DA0577C4EE26FAA, 20C3CD2579ED6853249B1EAEF23DF2904779BA2E806D00C30F81EA9A1612AE0F ] FoxitCloudUpdateService C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
08:37:56.0611 0x0398  FoxitCloudUpdateService - ok
08:37:56.0657 0x0398  [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
08:37:56.0673 0x0398  FsDepends - ok
08:37:56.0735 0x0398  [ D3E3F93D67821A2DB2B3D9FAC2DC2064, 727FAA7E15A20ED3A37668D294ABDE6EAF1C87C34EE283C99EE3303E85001404 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
08:37:56.0735 0x0398  Fs_Rec - ok
08:37:56.0845 0x0398  [ B8B2A6E1558F8F5DE5CE431C5B2C7B09, 24A9F04A0622681A4E4B6BCC47C45016787C6036EAD828920812D9FAD49A71E3 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
08:37:56.0860 0x0398  fvevol - ok
08:37:56.0938 0x0398  [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
08:37:56.0954 0x0398  gagp30kx - ok
08:37:57.0609 0x0398  [ 6D18B1088696CF96CBEBD31B8A519BD4, 4B47EECD18C12749FBEFA9C20B466F1A501F238166BBAE5B1793C918305A3348 ] GalaxyClientService C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe
08:37:57.0640 0x0398  GalaxyClientService - ok
08:37:59.0309 0x0398  [ 6C0A601D681A2B8252A0E60256383C5E, B97AD55A9FA015C887A1954A879D1D16933D5FF0EFC86985538B02DD7694D8AD ] GalaxyCommunication C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
08:37:59.0450 0x0398  GalaxyCommunication - ok
08:37:59.0590 0x0398  [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
08:37:59.0606 0x0398  GEARAspiWDM - ok
08:38:00.0136 0x0398  [ 5031F3E650D242EEECEB92EB9900FB93, FB51ADB81AC3E0097362BAECEC4F0C83C46E5505277B7F35FDCE9BF88B72C963 ] GfExperienceService C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
08:38:00.0152 0x0398  GfExperienceService - ok
08:38:00.0245 0x0398  [ A1F556318931B9EA276F4E2DA2C1791C, 1E5564A9B213689C56BFBBEC1A7BBFAD78DF1FB55422171C0680935338C5DE57 ] ggflt           C:\Windows\system32\DRIVERS\ggflt.sys
08:38:00.0245 0x0398  ggflt - ok
08:38:00.0479 0x0398  [ 7F56A3E09A6AD40B07E4EFAD34A40A18, E0EC4293035162E9EFA89A45FFF26B5BC829F7BB7F4D2D5A2CAA5E88AC6DC0C9 ] ggsomc          C:\Windows\system32\DRIVERS\ggsomc.sys
08:38:00.0479 0x0398  ggsomc - ok
08:38:00.0620 0x0398  [ FE5AB4525BC2EC68B9119A6E5D40128B, 088DE37982CEE78A0C1181389A3BFF1E352DF504074B3E8F3EA244DB271BF216 ] gpsvc           C:\Windows\System32\gpsvc.dll
08:38:00.0651 0x0398  gpsvc - ok
08:38:00.0807 0x0398  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
08:38:00.0823 0x0398  gupdate - ok
08:38:00.0901 0x0398  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
08:38:00.0901 0x0398  gupdatem - ok
08:38:00.0947 0x0398  [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
08:38:01.0057 0x0398  hcw85cir - ok
08:38:01.0135 0x0398  [ 6410F6F415B2A5A9037224C41DA8BF12, 5B8452BC49FDA2215281D27B22FA9BE46B0460F51C4DC70E58B687CFB541F3A5 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
08:38:01.0181 0x0398  HdAudAddService - ok
08:38:01.0306 0x0398  [ 0A49913402747A0B67DE940FB42CBDBB, 61A45DBDCEB4A2D5C3C28F6BC8C5ADC51D0240A7553DF44BCC4355FC06F72B83 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
08:38:01.0369 0x0398  HDAudBus - ok
08:38:01.0400 0x0398  [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt         C:\Windows\system32\DRIVERS\HidBatt.sys
08:38:01.0447 0x0398  HidBatt - ok
08:38:01.0462 0x0398  [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
08:38:01.0525 0x0398  HidBth - ok
08:38:01.0587 0x0398  [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr           C:\Windows\system32\DRIVERS\hidir.sys
08:38:01.0618 0x0398  HidIr - ok
08:38:01.0743 0x0398  [ E0959598DAF36CA69E42CFE767ADBE1B, 91E46262993B3DADB287169F60CD927EC6C943F07C29E6938BF3B9214C0AD1F4 ] hidkmdf         C:\Windows\system32\DRIVERS\hidkmdf.sys
08:38:01.0805 0x0398  hidkmdf - ok
08:38:01.0883 0x0398  [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv         C:\Windows\system32\hidserv.dll
08:38:01.0930 0x0398  hidserv - ok
08:38:01.0977 0x0398  [ B3BF6B5B50006DEF50B66306D99FCF6F, D39A1DEBE7C464922919826D15199ED25E263BF58633593DD412D78F98921417 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
08:38:02.0008 0x0398  HidUsb - ok
08:38:02.0086 0x0398  [ EFA58EDE58DD74388FFD04CB32681518, 76D81F9BC1A4D85A779B79DEC23B79F1568AA236CD49247414093CDC1FCC150F ] hkmsvc          C:\Windows\system32\kmsvc.dll
08:38:02.0133 0x0398  hkmsvc - ok
08:38:02.0258 0x0398  [ 046B2673767CA626E2CFB7FDF735E9E8, 9C932DCC5DE9B1919AB38C01D76AD7BBAF491DE6D158662407974748BC0B4C6C ] HomeGroupListener C:\Windows\system32\ListSvc.dll
08:38:02.0320 0x0398  HomeGroupListener - ok
08:38:02.0383 0x0398  [ 06A7422224D9865A5613710A089987DF, EF604B4B6918D3FDC8E90ED9004E6E7340E0F399C214C65CCE3A7C8C576FA1C0 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
08:38:02.0429 0x0398  HomeGroupProvider - ok
08:38:02.0507 0x0398  [ 0886D440058F203EBA0E1825E4355914, BC49C4CEFE324A08C864A4BF4FEA9A70151FAB7CC30BDC28344F3FFD2F500070 ] HpSAMD          C:\Windows\system32\DRIVERS\HpSAMD.sys
08:38:02.0523 0x0398  HpSAMD - ok
08:38:02.0773 0x0398  [ CEE049CAC4EFA7F4E1E4AD014414A5D4, 433AE2D845850F1D7A48275BBD87B3F0E7DD48F2282C727C4B777ECD92CC331D ] HTTP            C:\Windows\system32\drivers\HTTP.sys
08:38:02.0804 0x0398  HTTP - ok
08:38:02.0819 0x0398  [ F17766A19145F111856378DF337A5D79, FC1633FB865A5324EBCBE5F97D297B899FABBDD965D862C2EFC743CD36F47E62 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
08:38:02.0835 0x0398  hwpolicy - ok
08:38:02.0882 0x0398  [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
08:38:02.0882 0x0398  i8042prt - ok
08:38:03.0178 0x0398  [ 6C91E425ACE29594BD574DE38AC9B76D, 697784E4C7AF08B1F35662D8AD871E6890CECE22B6E64985B7C1A66C10DA390D ] iaStorA         C:\Windows\system32\DRIVERS\iaStorA.sys
08:38:03.0209 0x0398  iaStorA - ok
08:38:03.0475 0x0398  [ 0AB254994A460550258446950BB58311, BD10811912680DD3B814B7D1303785C996D892C79108110A2257E9BD0C28245C ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
08:38:03.0475 0x0398  IAStorDataMgrSvc - ok
08:38:03.0537 0x0398  [ 2B38F13E18E272459CD2CE83E6722C12, 58FB127C05FF7399F88F3B53CE4B460A7D3EA739AFCD273C0E687053BBA074D6 ] iaStorF         C:\Windows\system32\DRIVERS\iaStorF.sys
08:38:03.0537 0x0398  iaStorF - ok
08:38:03.0662 0x0398  [ D83EFB6FD45DF9D55E9A1AFC63640D50, 0494F8F7CB3ED11FD8D0B838CB71271AF7A3CBFCB7F2CB043A9392B5106A3C7B ] iaStorV         C:\Windows\system32\DRIVERS\iaStorV.sys
08:38:03.0662 0x0398  iaStorV - ok
08:38:03.0833 0x0398  [ 2F2BE70D3E02B6FA877921AB9516D43C, E04255EE4BD95FC1539EB1EB9F702B039F65993D31A4531DA487274543EF5226 ] idsvc           C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
08:38:03.0849 0x0398  idsvc - ok
08:38:03.0911 0x0398  [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp           C:\Windows\system32\DRIVERS\iirsp.sys
08:38:03.0927 0x0398  iirsp - ok
08:38:04.0067 0x0398  [ 67999A9D34A0B2479381E7A61AFC37AB, 7A1F72B2AD859345E1F092CE80C269767E4EF9931146B7F01E891EC12CCA684F ] ikbevent        C:\Windows\system32\DRIVERS\ikbevent.sys
08:38:04.0067 0x0398  ikbevent - ok
08:38:04.0239 0x0398  [ C5B4683680DF085B57BC53E5EF34861F, 9C06517DFCB3ED7BB1166F7EB6CCC8713E6B68283C75420C0EDC182094AA1B8F ] IKEEXT          C:\Windows\System32\ikeext.dll
08:38:04.0301 0x0398  IKEEXT - ok
08:38:04.0379 0x0398  [ DDAE90DD5BDAC53C8C5CD5B82FC1F1B4, A7019D2335CB46DCD9ABDB896622254E58AB265EC3D72A92B1C4890D45DEE85F ] imsevent        C:\Windows\system32\DRIVERS\imsevent.sys
08:38:04.0379 0x0398  imsevent - ok
08:38:05.0503 0x0398  [ F242E36CDA231701CFA702641C20FAEC, 47350EF8474F83249A9126AB6894145732CA0B68DA2EE001940C9E4AEF128B88 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
08:38:05.0596 0x0398  IntcAzAudAddService - ok
08:38:05.0939 0x0398  [ B353F1834FCD36D77BE3F74992C147D4, BFBC42B500FC7D6D2B523F988DD54156D2B6132CBE366EB591BF45556959A8E9 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
08:38:05.0955 0x0398  Intel(R) Capability Licensing Service Interface - ok
08:38:06.0064 0x0398  [ 125BED41A1AFDA9CAB2B6177553D5758, 00A6267AACC467FA09B49ECC6076F4C666BE98931C97D821E3225D68A3FF1BF1 ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
08:38:06.0064 0x0398  Intel(R) ME Service - ok
08:38:06.0127 0x0398  [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide        C:\Windows\system32\DRIVERS\intelide.sys
08:38:06.0142 0x0398  intelide - ok
08:38:06.0205 0x0398  [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
08:38:06.0236 0x0398  intelppm - ok
08:38:06.0595 0x0398  [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
08:38:06.0626 0x0398  IPBusEnum - ok
08:38:06.0673 0x0398  [ 722DD294DF62483CECAAE6E094B4D695, 41ABB42EF969EA8A84B546908EBBDC2411D964DE101CE6DD3D7ECF109085E0C0 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
08:38:06.0704 0x0398  IpFilterDriver - ok
08:38:06.0829 0x0398  [ F8E058D17363EC580E4B7232778B6CB5, 02352919F349C57930A0B032FBDC45327FB473D310DE7AC721F4694FDE7D21FB ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
08:38:06.0907 0x0398  iphlpsvc - ok
08:38:06.0938 0x0398  [ E2B4A4494DB7CB9B89B55CA268C337C5, C59BC4AA03D10647641EC7533F78BC7E2EA6FC48B8B2CF1A49B5148EF40A90FB ] IPMIDRV         C:\Windows\system32\DRIVERS\IPMIDrv.sys
08:38:06.0953 0x0398  IPMIDRV - ok
08:38:06.0969 0x0398  [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
08:38:07.0031 0x0398  IPNAT - ok
08:38:07.0359 0x0398  [ E8D96F840994291789F0CDE6800AC1A4, 35B39474B6385DA828D4212047F5C94775FC3C55E8C72EAA503D763D86F9BFB7 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
08:38:07.0375 0x0398  iPod Service - ok
08:38:07.0421 0x0398  [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM          C:\Windows\system32\drivers\irenum.sys
08:38:07.0421 0x0398  IRENUM - ok
08:38:07.0515 0x0398  [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp          C:\Windows\system32\DRIVERS\isapnp.sys
08:38:07.0531 0x0398  isapnp - ok
08:38:07.0577 0x0398  [ FA4D2557DE56D45B0A346F93564BE6E1, 2827EC3582FF59FFD55BBD4A4F0DDFFEAD4F2537FA043B3A69904FE920B1619C ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
08:38:07.0577 0x0398  iScsiPrt - ok
08:38:07.0733 0x0398  [ 970995B7C36F4408ED31C3BF204FE1F5, 466C5FA3A26E997009E33EA9B0923BFE7FCC9D367444F31C1BEB3D6EACDB6BA9 ] ISCT            C:\Windows\system32\DRIVERS\ISCTD64.sys
08:38:07.0749 0x0398  ISCT - ok
08:38:07.0889 0x0398  [ 6F60B7AD044924B8C1E32D692C593612, 93EFBC2EC24E7B4B908010955F1B9A6DC231C7A4B55BE0D2DC6103E2A5457EC6 ] ISCTAgent       C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
08:38:07.0889 0x0398  ISCTAgent - ok
08:38:08.0139 0x0398  [ 16B5B394028D8ED80A569123A38DC4F7, 19839364B7A48584615F0ED56D94AB6E6F8159EAD826605F74C73845CE2C5C12 ] iumsvc          C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
08:38:08.0155 0x0398  iumsvc - ok
08:38:08.0248 0x0398  [ 846354992EBB373F452EB9182D501B08, 453459133DCA875E93CAAE9852E652F3794F8C31CE53526C47A181FDBABE6849 ] iusb3hcs        C:\Windows\system32\DRIVERS\iusb3hcs.sys
08:38:08.0264 0x0398  iusb3hcs - ok
08:38:08.0326 0x0398  [ 1D88A23853387D34D52CC8F9DDBFC56C, D00083B61E93E7E1D247EAB332787912FCF7605AF7043F071238C50E4A15016B ] iusb3hub        C:\Windows\system32\DRIVERS\iusb3hub.sys
08:38:08.0326 0x0398  iusb3hub - ok
08:38:08.0451 0x0398  [ FC5EFD7C797DF19DFB999F0605A7924E, C56CE3840F3B11D81BED38E5F59ABCA190DFB7127F06263193870312A83379AF ] iusb3xhc        C:\Windows\system32\DRIVERS\iusb3xhc.sys
08:38:08.0467 0x0398  iusb3xhc - ok
08:38:08.0560 0x0398  [ BD5BF20EC242E003A2F570B8754A56D1, B4B3492222E98BF8E6EC453E727187FF4AA50A508D1E88A0CBBD5C46355AE492 ] ivusb           C:\Windows\system32\DRIVERS\ivusb.sys
08:38:08.0560 0x0398  ivusb - ok
08:38:08.0716 0x0398  [ 5B14FDE79871F83A5E0DCDC01F78BECF, B3103D4671F7BD4843C62D6080894E068F7E794CB02D7A84AEFB5AC10EA23BDE ] jhi_service     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
08:38:08.0716 0x0398  jhi_service - ok
08:38:09.0028 0x0398  [ 455B75C19BF3F1F2EE3AC10E1169826C, C8CE6DE48E0B4621F2851A994261FA787556A27F9868A8859E5E8A8354028257 ] k57nd60a        C:\Windows\system32\DRIVERS\k57nd60a.sys
08:38:09.0044 0x0398  k57nd60a - ok
08:38:09.0106 0x0398  [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
08:38:09.0106 0x0398  kbdclass - ok
08:38:09.0231 0x0398  [ 6DEF98F8541E1B5DCEB2C822A11F7323, F6EE4A7A6A7A1F243D32CA9241CA4816C92EB7BF2AADDD09234968C2CAAE6C0D ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
08:38:09.0262 0x0398  kbdhid - ok
08:38:09.0309 0x0398  [ 156F6159457D0AA7E59B62681B56EB90, 27B855BF79490E4CC58D38A920C077A56785494BFFF0B448A898486009B24937 ] KeyIso          C:\Windows\system32\lsass.exe
08:38:09.0309 0x0398  KeyIso - ok
08:38:09.0356 0x0398  [ 4F4B5FDE429416877DE7143044582EB5, A28FFEA078DBD91F3CC28088810EEEB727107B3F0F48370B44D87DC8F8C55B99 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
08:38:09.0371 0x0398  KSecDD - ok
08:38:09.0465 0x0398  [ 6F40465A44ECDC1731BEFAFEC5BDD03C, 317334D414D0AF73CB4D9CA11EA80C641E786760B8800F2795D0CB38378DBB80 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
08:38:09.0481 0x0398  KSecPkg - ok
08:38:09.0512 0x0398  [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
08:38:09.0574 0x0398  ksthunk - ok
08:38:09.0730 0x0398  [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm           C:\Windows\system32\msdtckrm.dll
08:38:09.0777 0x0398  KtmRm - ok
08:38:09.0917 0x0398  [ 81F1D04D4D0E433099365127375FD501, C2A81B5A482C974E8108806486EC28CB2D81400D42639682FE7B7A9BDF14BA9B ] LanmanServer    C:\Windows\system32\srvsvc.dll
08:38:10.0011 0x0398  LanmanServer - ok
08:38:10.0120 0x0398  [ 27026EAC8818E8A6C00A1CAD2F11D29A, A12858CCB3B2419D66C667A46B106DA7A7BA97FFFA9634BFAE95DDF193C430D5 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
08:38:10.0261 0x0398  LanmanWorkstation - ok
08:38:10.0370 0x0398  [ FA529FB35694C24BF98A9EF67C1CD9D0, 7B3C587C38CF13D514140F0A55E58997D6071D1DEFD97E274E3F490660AC6075 ] LGBusEnum       C:\Windows\system32\drivers\LGBusEnum.sys
08:38:10.0370 0x0398  LGBusEnum - ok
08:38:10.0463 0x0398  [ 94B29CE153765E768F004FB3440BE2B0, E74C01CEBDA589CDDE35CBCBAA18700E3742DD3B48A90DB3630992467FFC5024 ] LGVirHid        C:\Windows\system32\drivers\LGVirHid.sys
08:38:10.0463 0x0398  LGVirHid - ok
08:38:10.0588 0x0398  [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
08:38:10.0604 0x0398  lltdio - ok
08:38:10.0729 0x0398  [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc         C:\Windows\System32\lltdsvc.dll
08:38:10.0791 0x0398  lltdsvc - ok
08:38:10.0853 0x0398  [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts         C:\Windows\System32\lmhsvc.dll
08:38:10.0869 0x0398  lmhosts - ok
08:38:11.0087 0x0398  [ 3974B7CE015A6EEF30DA4ADD5F1203D0, ED776F1C1B1834550F3D45591EB1F0829BBA07F9F7CB73F7FBB0AFDEF8F4411B ] LMS             C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
08:38:11.0087 0x0398  LMS - ok
08:38:11.0134 0x0398  [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
08:38:11.0150 0x0398  LSI_FC - ok
08:38:11.0181 0x0398  [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS         C:\Windows\system32\DRIVERS\lsi_sas.sys
08:38:11.0181 0x0398  LSI_SAS - ok
08:38:11.0243 0x0398  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
08:38:11.0243 0x0398  LSI_SAS2 - ok
08:38:11.0290 0x0398  [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
08:38:11.0290 0x0398  LSI_SCSI - ok
08:38:11.0353 0x0398  [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv           C:\Windows\system32\drivers\luafv.sys
08:38:11.0368 0x0398  luafv - ok
08:38:11.0431 0x0398  [ F84C8F1000BC11E3B7B23CBD3BAFF111, BB4C4FFE3F6C9E5C16C06F6F666F177B94E1CF878397BCC0BDAF6EB3341AAED8 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
08:38:11.0462 0x0398  Mcx2Svc - ok
08:38:11.0509 0x0398  [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas         C:\Windows\system32\DRIVERS\megasas.sys
08:38:11.0509 0x0398  megasas - ok
08:38:11.0571 0x0398  [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
08:38:11.0587 0x0398  MegaSR - ok
08:38:11.0649 0x0398  [ 772A1DEEDFDBC244183B5C805D1B7D85, 7D821B8DF1F174E5414FFDEAB5207DB687740E9842F7203600AEBA086945AFC9 ] MEIx64          C:\Windows\system32\DRIVERS\HECIx64.sys
08:38:11.0649 0x0398  MEIx64 - ok
08:38:11.0711 0x0398  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS           C:\Windows\system32\mmcss.dll
08:38:11.0774 0x0398  MMCSS - ok
08:38:11.0789 0x0398  [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem           C:\Windows\system32\drivers\modem.sys
08:38:11.0836 0x0398  Modem - ok
08:38:11.0883 0x0398  [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
08:38:11.0914 0x0398  monitor - ok
08:38:11.0961 0x0398  [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
08:38:11.0977 0x0398  mouclass - ok
08:38:12.0039 0x0398  [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
08:38:12.0039 0x0398  mouhid - ok
08:38:12.0086 0x0398  [ 791AF66C4D0E7C90A3646066386FB571, BF67643099494AEADDDC85E4D97AFF1017806A1DF554F9BE6C864FFECC9EAF42 ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
08:38:12.0086 0x0398  mountmgr - ok
08:38:12.0242 0x0398  [ 0DE2474F316C515482ABAD3B697F8714, 62862AE7432F5350068E96AD466093359C6CF444EB517AE6D09134FAF78C49F5 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
08:38:12.0242 0x0398  MozillaMaintenance - ok
08:38:12.0304 0x0398  [ 609D1D87649ECC19796F4D76D4C15CEA, 5369F4C83FBAE9C4CFB9ACD36F07479E3F3FD784D79B82AE8D95B818B9F9CE00 ] mpio            C:\Windows\system32\DRIVERS\mpio.sys
08:38:12.0304 0x0398  mpio - ok
08:38:12.0320 0x0398  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
08:38:12.0351 0x0398  mpsdrv - ok
08:38:12.0601 0x0398  [ AECAB449567D1846DAD63ECE49E893E3, 7A67A16A3E04574B7CAD097632ABA9B361BBEFDD6B36B7B8E3A1996EC529C2DC ] MpsSvc          C:\Windows\system32\mpssvc.dll
08:38:12.0663 0x0398  MpsSvc - ok
08:38:12.0663 0x0398  [ 30524261BB51D96D6FCBAC20C810183C, 19598A9CD0EAAE4ACBF1069E721AB2853452F33FCFB3B5113F023A88A90BF42D ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
08:38:12.0694 0x0398  MRxDAV - ok
08:38:12.0757 0x0398  [ 040D62A9D8AD28922632137ACDD984F2, D9457BDA88C2E3AA4E716C0657B77A4A3E212328CDABD5C18279B6440E1C1594 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
08:38:12.0788 0x0398  mrxsmb - ok
08:38:12.0897 0x0398  [ F0067552F8F9B33D7C59403AB808A3CB, 698B63528E1943BB4253BF7578DC128AA824C71BD04FF0521277E68B20656C02 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
08:38:12.0944 0x0398  mrxsmb10 - ok
08:38:12.0991 0x0398  [ 3C142D31DE9F2F193218A53FE2632051, 026B3A932A95D5160B64E470FC414F3D388D429317D5EAEA2D476F715C4CAE75 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
08:38:13.0037 0x0398  mrxsmb20 - ok
08:38:13.0069 0x0398  [ 5C37497276E3B3A5488B23A326A754B7, 9982FCDAFB963868EB93A4DEF811A3167488EB5246BAC3F4AE960506FDF63967 ] msahci          C:\Windows\system32\DRIVERS\msahci.sys
08:38:13.0084 0x0398  msahci - ok
08:38:13.0178 0x0398  [ 8D27B597229AED79430FB9DB3BCBFBD0, 3D58E08B47E8AE419D405BF263929DFA6F2F5F0C2D79FD8D6F2CED6452F6F248 ] msdsm           C:\Windows\system32\DRIVERS\msdsm.sys
08:38:13.0178 0x0398  msdsm - ok
08:38:13.0271 0x0398  [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC           C:\Windows\System32\msdtc.exe
08:38:13.0318 0x0398  MSDTC - ok
08:38:13.0334 0x0398  [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
08:38:13.0349 0x0398  Msfs - ok
08:38:13.0381 0x0398  [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
08:38:13.0443 0x0398  mshidkmdf - ok
08:38:13.0490 0x0398  [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv        C:\Windows\system32\DRIVERS\msisadrv.sys
08:38:13.0490 0x0398  msisadrv - ok
08:38:13.0599 0x0398  [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
08:38:13.0630 0x0398  MSiSCSI - ok
08:38:13.0630 0x0398  msiserver - ok
08:38:13.0677 0x0398  [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
08:38:13.0724 0x0398  MSKSSRV - ok
08:38:13.0755 0x0398  [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
08:38:13.0786 0x0398  MSPCLOCK - ok
08:38:13.0802 0x0398  [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
08:38:13.0849 0x0398  MSPQM - ok
08:38:13.0864 0x0398  [ 89CB141AA8616D8C6A4610FA26C60964, 76E72F6A0348EDC58A8E6F88C7F024B8B077670400BD5A833811DAFCF9F517CC ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
08:38:13.0880 0x0398  MsRPC - ok
08:38:13.0927 0x0398  [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
08:38:13.0958 0x0398  mssmbios - ok
08:38:13.0974 0x0398  [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
08:38:14.0036 0x0398  MSTEE - ok
08:38:14.0067 0x0398  [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
08:38:14.0098 0x0398  MTConfig - ok
08:38:14.0176 0x0398  [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup             C:\Windows\system32\Drivers\mup.sys
08:38:14.0176 0x0398  Mup - ok
08:38:14.0395 0x0398  [ 4987E079A4530FA737A128BE54B63B12, 27E51CC7D4D90DC4397575491DE7EFE15808709F097E2828E46AA73C771A47A4 ] napagent        C:\Windows\system32\qagentRT.dll
08:38:14.0426 0x0398  napagent - ok
08:38:14.0598 0x0398  [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
08:38:14.0644 0x0398  NativeWifiP - ok
08:38:14.0910 0x0398  [ CAD515DBD07D082BB317D9928CE8962C, 7AFA6D6154AC68F9FCC37B7B3324F7A170AE91035805026445F24F6EB4FB7F2E ] NDIS            C:\Windows\system32\drivers\ndis.sys
08:38:14.0925 0x0398  NDIS - ok
08:38:14.0988 0x0398  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
08:38:15.0003 0x0398  NdisCap - ok
08:38:15.0034 0x0398  [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
08:38:15.0097 0x0398  NdisTapi - ok
08:38:15.0159 0x0398  [ F105BA1E22BF1F2EE8F005D4305E4BEC, 723DA09E13D0F50634D9F114590B837D16F7B36AA0DA2AB8F8C2D9991624EA8F ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
08:38:15.0206 0x0398  Ndisuio - ok
08:38:15.0315 0x0398  [ 557DFAB9CA1FCB036AC77564C010DAD3, 8A21B342AFE5B498FB62EDDC81A3ADA9570677B7A382666090E0ABB1F85FEF29 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
08:38:15.0331 0x0398  NdisWan - ok
08:38:15.0362 0x0398  [ 659B74FB74B86228D6338D643CD3E3CF, 83D741B7A2A204A661A80C226212749F514800060D05E217FA6DC14D62F38F80 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
08:38:15.0378 0x0398  NDProxy - ok
08:38:15.0424 0x0398  [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
08:38:15.0456 0x0398  NetBIOS - ok
08:38:15.0549 0x0398  [ 9162B273A44AB9DCE5B44362731D062A, 5A1BA6DBFEBB2618DC9D4CC55FA071C170A5D22FFB24CE62DD5B3210D8B45F39 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
08:38:15.0612 0x0398  NetBT - ok
08:38:15.0643 0x0398  [ 156F6159457D0AA7E59B62681B56EB90, 27B855BF79490E4CC58D38A920C077A56785494BFFF0B448A898486009B24937 ] Netlogon        C:\Windows\system32\lsass.exe
08:38:15.0643 0x0398  Netlogon - ok
08:38:15.0736 0x0398  [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman          C:\Windows\System32\netman.dll
08:38:15.0814 0x0398  Netman - ok
08:38:15.0955 0x0398  [ 9A7D3A1AA5C830744FF6C44BB55A347A, 42D3281893DB4C0DDA6A7BDA92D3CCE23968D0E3CF880777B8DBBFD955629B08 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
08:38:16.0173 0x0398  NetMsmqActivator - ok
08:38:16.0204 0x0398  [ 9A7D3A1AA5C830744FF6C44BB55A347A, 42D3281893DB4C0DDA6A7BDA92D3CCE23968D0E3CF880777B8DBBFD955629B08 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
08:38:16.0220 0x0398  NetPipeActivator - ok
08:38:16.0407 0x0398  [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm        C:\Windows\System32\netprofm.dll
08:38:16.0454 0x0398  netprofm - ok
08:38:16.0454 0x0398  [ 9A7D3A1AA5C830744FF6C44BB55A347A, 42D3281893DB4C0DDA6A7BDA92D3CCE23968D0E3CF880777B8DBBFD955629B08 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
08:38:16.0470 0x0398  NetTcpActivator - ok
08:38:16.0470 0x0398  [ 9A7D3A1AA5C830744FF6C44BB55A347A, 42D3281893DB4C0DDA6A7BDA92D3CCE23968D0E3CF880777B8DBBFD955629B08 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
08:38:16.0470 0x0398  NetTcpPortSharing - ok
08:38:16.0548 0x0398  [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960         C:\Windows\system32\DRIVERS\nfrd960.sys
08:38:16.0548 0x0398  nfrd960 - ok
08:38:16.0641 0x0398  [ 8AED7DEF1F9659C911E1B1C9DD3CE8CD, 3ECFF30C8D8E7CF4514055F4E63B36C900EF104ECC75F804B11AF6307874153B ] ngvss           C:\Windows\system32\drivers\ngvss.sys
08:38:16.0657 0x0398  ngvss - ok
08:38:16.0782 0x0398  [ D9A0CE66046D6EFA0C61BAA885CBA0A8, 06C3331C7F3EE0E0B95E8302CB80315E965587C4D6231785B8ACF3FAE4731FAF ] NlaSvc          C:\Windows\System32\nlasvc.dll
08:38:16.0844 0x0398  NlaSvc - ok
08:38:16.0875 0x0398  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs            C:\Windows\system32\drivers\Npfs.sys
08:38:16.0938 0x0398  Npfs - ok
08:38:17.0016 0x0398  [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi             C:\Windows\system32\nsisvc.dll
08:38:17.0031 0x0398  nsi - ok
08:38:17.0062 0x0398  [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
08:38:17.0125 0x0398  nsiproxy - ok
08:38:17.0608 0x0398  [ 9A6089B056EA1B83B36424FC9D0A300E, EA60282C5A32B497921B568C1FE735F5BDB9D954DDC4E609F7F3CAE5ED823CEC ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
08:38:17.0640 0x0398  Ntfs - ok
08:38:17.0655 0x0398  [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null            C:\Windows\system32\drivers\Null.sys
08:38:17.0671 0x0398  Null - ok
08:38:17.0780 0x0398  [ B9E5A80F646DDFEF158773722A466EA3, 028979FE600D17DA70445F44D81FAE4EDA3478FCC81FA5506133CCAC37C4E2BF ] NVHDA           C:\Windows\system32\drivers\nvhda64v.sys
08:38:17.0796 0x0398  NVHDA - ok
08:38:19.0855 0x0398  [ 45F83C99EDF3253D047F692A42C1A51A, 08EC3CE5F00C9B70F52577FAD0561A8ECCD6C04F96468DBA67B4D4C82C77FA6D ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
08:38:20.0167 0x0398  nvlddmkm - ok
08:38:20.0744 0x0398  [ 4EBEE69A8FE7DC85FD3C122821C617A0, 7193C14DEB4C5B0D86C5C6841C80879C28E1FDA8F77879EB18A3D2685C67B986 ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
08:38:20.0791 0x0398  NvNetworkService - ok
08:38:20.0931 0x0398  [ 3E38712941E9BB4DDBEE00AFFE3FED3D, 03F27CC0EF0A86D0B2DAAB6F72838CB2AB57FE5D40074828D5B7F118CD5CBEE7 ] nvraid          C:\Windows\system32\DRIVERS\nvraid.sys
08:38:20.0931 0x0398  nvraid - ok
08:38:20.0994 0x0398  [ 477DC4D6DEB99BE37084C9AC6D013DA1, E58C4D621CAAB1C68FB4A056576F48BC87913A5EBF0B511EFFB8F38C7D3E516E ] nvstor          C:\Windows\system32\DRIVERS\nvstor.sys
08:38:20.0994 0x0398  nvstor - ok
08:38:21.0212 0x0398  [ 0EF30778078D7B5877F8F57151699798, B0409C79143BDBB774C3C740CCA8EB77CF67915E59EC6050DB993ED0575EC077 ] NvStreamKms     C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
08:38:21.0212 0x0398  NvStreamKms - ok
08:38:22.0803 0x0398  [ D23A07D549243F5B77780BAA4FBF5BC3, 5BC5161CAE6BE6382BDCDE9B1CDD5F4DEBC3EA18D01B0E261AF716FDB04154BC ] NvStreamSvc     C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
08:38:22.0912 0x0398  NvStreamSvc - ok
08:38:23.0287 0x0398  [ 92C7B8287C185022F12253026FA33401, 96E466D17347DB3E789DD6DBF3604E51D4B86D3E49592B0EF6622BD278369F6C ] nvsvc           C:\Windows\system32\nvvsvc.exe
08:38:23.0318 0x0398  nvsvc - ok
08:38:23.0396 0x0398  [ 4F00008B513F4019623ED61159363888, A1047FF1FCF3ED405C3426C8959AD10426F30E3F58E95BFD6ADF1DBC947AB379 ] nvvad_WaveExtensible C:\Windows\system32\drivers\nvvad64v.sys
08:38:23.0412 0x0398  nvvad_WaveExtensible - ok
08:38:23.0458 0x0398  [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp          C:\Windows\system32\DRIVERS\nv_agp.sys
08:38:23.0458 0x0398  nv_agp - ok
08:38:23.0536 0x0398  [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
08:38:23.0552 0x0398  ohci1394 - ok
08:38:24.0020 0x0398  [ EDD1DCD36F6115ACC6935C3F88FF54D7, 43A84A7459D926B635F23EE09FC7C67C2B03725A3EEA9D38A18FDB9CD7C7F785 ] P17             C:\Windows\system32\drivers\P17.sys
08:38:24.0067 0x0398  P17 - ok
08:38:24.0254 0x0398  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
08:38:24.0348 0x0398  p2pimsvc - ok
08:38:24.0566 0x0398  [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc          C:\Windows\system32\p2psvc.dll
08:38:24.0582 0x0398  p2psvc - ok
08:38:24.0613 0x0398  [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport         C:\Windows\system32\DRIVERS\parport.sys
08:38:24.0628 0x0398  Parport - ok
08:38:24.0706 0x0398  [ 90061B1ACFE8CCAA5345750FFE08D8B8, 76309683FFDF380AF9C6E1D9A52E46B011A0BF1026D747181D01F3312B7541C7 ] partmgr         C:\Windows\system32\drivers\partmgr.sys
08:38:24.0706 0x0398  partmgr - ok
08:38:24.0800 0x0398  [ 3AEAA8B561E63452C655DC0584922257, 04C072969B58657602EB0C21CEDF24FCEE14E61B90A0F758F93925EF2C9FC32D ] PcaSvc          C:\Windows\System32\pcasvc.dll
08:38:24.0847 0x0398  PcaSvc - ok
08:38:24.0909 0x0398  [ F36F6504009F2FB0DFD1B17A116AD74B, 33A4C217F7DC5E5B7E1B6CF335327C8FE6CC5D6D048D420252965574CAD83918 ] pci             C:\Windows\system32\DRIVERS\pci.sys
08:38:24.0909 0x0398  pci - ok
08:38:24.0956 0x0398  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide          C:\Windows\system32\DRIVERS\pciide.sys
08:38:24.0956 0x0398  pciide - ok
08:38:25.0096 0x0398  [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
08:38:25.0096 0x0398  pcmcia - ok
08:38:25.0128 0x0398  [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw             C:\Windows\system32\drivers\pcw.sys
08:38:25.0128 0x0398  pcw - ok
08:38:25.0377 0x0398  [ 68769C3356B3BE5D1C732C97B9A80D6E, FB2D61145980A2899D1B7729184C54070315B0E63C9A22400A76CCD39E00029C ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
08:38:25.0424 0x0398  PEAUTH - ok
08:38:26.0220 0x0398  [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost        C:\Windows\SysWow64\perfhost.exe
08:38:26.0625 0x0398  PerfHost - ok
08:38:27.0171 0x0398  [ 557E9A86F65F0DE18C9B6751DFE9D3F1, 630EE5A80335929517A22D130C75CBCE882B92978372A6F36C30B9D353C7BB07 ] pla             C:\Windows\system32\pla.dll
08:38:27.0234 0x0398  pla - ok
08:38:27.0483 0x0398  [ 98B1721B8718164293B9701B98C52D77, 27F5F00D4AA394D4D8D0A0062EDC3F944B603E07CAAEDC5CC959BA1E8C208C2A ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
08:38:27.0592 0x0398  PlugPlay - ok
08:38:27.0655 0x0398  [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
08:38:27.0655 0x0398  PNRPAutoReg - ok
08:38:27.0795 0x0398  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
08:38:27.0811 0x0398  PNRPsvc - ok
08:38:27.0951 0x0398  [ 166EB40D1F5B47E615DE3D0FFFE5F243, E32BCCA0D25CD631C221986EBE9F6C54BF2F12DE1672D69CCC4E22AD07D0525A ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
08:38:28.0014 0x0398  PolicyAgent - ok
08:38:28.0092 0x0398  [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power           C:\Windows\system32\umpo.dll
08:38:28.0107 0x0398  Power - ok
08:38:28.0248 0x0398  [ 27CC19E81BA5E3403C48302127BDA717, C580FC552DDF9C163FC325B38B05C06FFD696495E4C01514BCD6346CFE4F0B40 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
08:38:28.0294 0x0398  PptpMiniport - ok
08:38:28.0357 0x0398  [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor       C:\Windows\system32\DRIVERS\processr.sys
08:38:28.0404 0x0398  Processor - ok
08:38:28.0528 0x0398  [ F381975E1F4346DE875CB07339CE8D3A, 867BFC2E9A08E026289794019B8DE651A8604D06DD6A9BF166C29AFC24B6D26E ] ProfSvc         C:\Windows\system32\profsvc.dll
08:38:28.0575 0x0398  ProfSvc - ok
08:38:28.0606 0x0398  [ 156F6159457D0AA7E59B62681B56EB90, 27B855BF79490E4CC58D38A920C077A56785494BFFF0B448A898486009B24937 ] ProtectedStorage C:\Windows\system32\lsass.exe
08:38:28.0622 0x0398  ProtectedStorage - ok
08:38:28.0747 0x0398  [ EE992183BD8EAEFD9973F352E587A299, 6B28930FAA0A54FAADDAF2231553D7F5D45C7227454C6D49A86DFC9EF6BC9043 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
08:38:28.0762 0x0398  Psched - ok
08:38:29.0028 0x0398  [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
08:38:29.0059 0x0398  ql2300 - ok
08:38:29.0090 0x0398  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
08:38:29.0106 0x0398  ql40xx - ok
08:38:29.0184 0x0398  [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE           C:\Windows\system32\qwave.dll
08:38:29.0184 0x0398  QWAVE - ok
08:38:29.0230 0x0398  [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
08:38:29.0277 0x0398  QWAVEdrv - ok
08:38:29.0324 0x0398  [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
08:38:29.0340 0x0398  RasAcd - ok
08:38:29.0464 0x0398  [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
08:38:29.0480 0x0398  RasAgileVpn - ok
08:38:29.0511 0x0398  [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto         C:\Windows\System32\rasauto.dll
08:38:29.0589 0x0398  RasAuto - ok
08:38:29.0652 0x0398  [ 87A6E852A22991580D6D39ADC4790463, 0F757C6E5B57DFC239CE1BEC88EF16C07E7F1A40D629A9A6DF3CB6B88FB9E642 ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
08:38:29.0714 0x0398  Rasl2tp - ok
08:38:29.0792 0x0398  [ 47394ED3D16D053F5906EFE5AB51CC83, FE5D1249788DB6D85C55769251B0AED738D3BBA04DF57124E03397D3C0599286 ] RasMan          C:\Windows\System32\rasmans.dll
08:38:29.0854 0x0398  RasMan - ok
08:38:29.0901 0x0398  [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
08:38:29.0948 0x0398  RasPppoe - ok
08:38:30.0026 0x0398  [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
08:38:30.0088 0x0398  RasSstp - ok
08:38:30.0244 0x0398  [ 3BAC8142102C15D59A87757C1D41DCE5, C0C2C6887EA5A439E69221196348382ACE3E1942C9C6E0A970E153890F71724C ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
08:38:30.0322 0x0398  rdbss - ok
08:38:30.0354 0x0398  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
08:38:30.0416 0x0398  rdpbus - ok
08:38:30.0432 0x0398  [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
08:38:30.0494 0x0398  RDPCDD - ok
08:38:30.0572 0x0398  [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
08:38:30.0588 0x0398  RDPENCDD - ok
08:38:30.0619 0x0398  [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
08:38:30.0650 0x0398  RDPREFMP - ok
08:38:30.0728 0x0398  [ 447DE7E3DEA39D422C1504F245B668B1, C54D90D2F9405E011E490D3C2F0F64488B87B969C95E367C076BBFCFD8654909 ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
08:38:30.0806 0x0398  RDPWD - ok
08:38:30.0900 0x0398  [ 634B9A2181D98F15941236886164EC8B, 15C55F05FD3CD751F619F18E2ADF91552AE82146501CD031402277F496A5B7D8 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
08:38:30.0915 0x0398  rdyboost - ok
08:38:30.0993 0x0398  [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess    C:\Windows\System32\mprdim.dll
08:38:31.0040 0x0398  RemoteAccess - ok
08:38:31.0118 0x0398  [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
08:38:31.0196 0x0398  RemoteRegistry - ok
08:38:31.0274 0x0398  [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
08:38:31.0336 0x0398  RpcEptMapper - ok
08:38:31.0414 0x0398  [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator      C:\Windows\system32\locator.exe
08:38:31.0461 0x0398  RpcLocator - ok
08:38:31.0617 0x0398  [ 7266972E86890E2B30C0C322E906B027, BFA30E85F5BD3AA933913BD7C6D2B5993DB7AFB0C98349B61A6BEF0BDC8A3680 ] RpcSs           C:\Windows\system32\rpcss.dll
08:38:31.0648 0x0398  RpcSs - ok
08:38:31.0695 0x0398  [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
08:38:31.0758 0x0398  rspndr - ok
08:38:31.0789 0x0398  [ 156F6159457D0AA7E59B62681B56EB90, 27B855BF79490E4CC58D38A920C077A56785494BFFF0B448A898486009B24937 ] SamSs           C:\Windows\system32\lsass.exe
08:38:31.0804 0x0398  SamSs - ok
08:38:31.0960 0x0398  [ 3289766038DB2CB14D07DC84392138D5, A7790B787690CC1A8B97E4532090C5295350A836A9474DEA74CEB3E81CF26124 ] SASDIFSV        C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
08:38:31.0960 0x0398  SASDIFSV - ok
08:38:32.0054 0x0398  [ 58A38E75F3316A83C23DF6173D41F2B5, B0A8CDA1D164B7534FB41AB80792861384709BF0F914F44553275CF20194F1A1 ] SASKUTIL        C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
08:38:32.0054 0x0398  SASKUTIL - ok
08:38:32.0101 0x0398  [ E3BBB89983DAF5622C1D50CF49F28227, 49370DC142D577D657BF5755AA9B8625C35D3DDAF1F9466B4888507FB8E6FF07 ] sbp2port        C:\Windows\system32\DRIVERS\sbp2port.sys
08:38:32.0101 0x0398  sbp2port - ok
08:38:32.0194 0x0398  [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
08:38:32.0257 0x0398  SCardSvr - ok
08:38:32.0304 0x0398  [ C94DA20C7E3BA1DCA269BC8460D98387, E1A5629728A79233B62BA87B4354BC3A332A853CC36A60E77B34923F4BCA8A61 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
08:38:32.0382 0x0398  scfilter - ok
08:38:32.0818 0x0398  [ 624D0F5FF99428BB90A5B8A4123E918E, 90A43E6F09B56CB86A3E3851F8E5ABB74905AEB70296F4B87BEDBC3027E65E86 ] Schedule        C:\Windows\system32\schedsvc.dll
08:38:32.0928 0x0398  Schedule - ok
08:38:33.0006 0x0398  [ 312E2F82AF11E79906898AC3E3D58A1F, F6CB7D8B204B94F749D5DBEFD552150AAB16A34D629F87F73823A7504465F106 ] SCPolicySvc     C:\Windows\System32\certprop.dll
08:38:33.0021 0x0398  SCPolicySvc - ok
08:38:33.0115 0x0398  [ 765A27C3279CE11D14CB9E4F5869FCA5, B6C2EFFBA938828FEF7FE992A4C88B3154D053763C38762DCE13252FE9571FA1 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
08:38:33.0193 0x0398  SDRSVC - ok
08:38:33.0692 0x0398  [ 64AEB3422A5B02E20E364109FA7D5723, AB1F1B07005F36398803BC499D02CE01B894606B1A860015A519B9C02B8F5806 ] Seagate Dashboard Services C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe
08:38:33.0692 0x0398  Seagate Dashboard Services - ok
08:38:33.0770 0x0398  [ C175D89AE2DDBEBB98B5A72B411DFDA1, D04194C7A5749BEA010A1B719ECFDB4ABF46993911FF79BD9ABB907EC64176A3 ] Seagate MobileBackup Service C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe
08:38:33.0786 0x0398  Seagate MobileBackup Service - ok
08:38:33.0910 0x0398  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\Windows\system32\drivers\secdrv.sys
08:38:33.0988 0x0398  secdrv - ok
08:38:34.0020 0x0398  [ 463B386EBC70F98DA5DFF85F7E654346, 8E27B18B04AF587719D1DAE75A042DB998E06CAE112BD68626EF046036D2DCDC ] seclogon        C:\Windows\system32\seclogon.dll
08:38:34.0082 0x0398  seclogon - ok
08:38:34.0113 0x0398  [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS            C:\Windows\System32\sens.dll
08:38:34.0129 0x0398  SENS - ok
08:38:34.0207 0x0398  [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc        C:\Windows\system32\sensrsvc.dll
08:38:34.0254 0x0398  SensrSvc - ok
08:38:34.0332 0x0398  [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
08:38:34.0332 0x0398  Serenum - ok
08:38:34.0363 0x0398  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial          C:\Windows\system32\DRIVERS\serial.sys
08:38:34.0394 0x0398  Serial - ok
08:38:34.0425 0x0398  [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
08:38:34.0472 0x0398  sermouse - ok
08:38:34.0503 0x0398  [ C3BC61CE47FF6F4E88AB8A3B429A36AF, 6CA53AD0CB7215BAE3467EC1FD490E3A18504BD6CD4F0FABF9BD37516AB9DFE0 ] SessionEnv      C:\Windows\system32\sessenv.dll
08:38:34.0534 0x0398  SessionEnv - ok
08:38:34.0550 0x0398  [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk         C:\Windows\system32\DRIVERS\sffdisk.sys
08:38:34.0581 0x0398  sffdisk - ok
08:38:34.0597 0x0398  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc        C:\Windows\system32\DRIVERS\sffp_mmc.sys
08:38:34.0612 0x0398  sffp_mmc - ok
08:38:34.0706 0x0398  [ 5588B8C6193EB1522490C122EB94DFFA, 53AE3597D3305F2839130A2F3567F1690564B922035503EB418B9DE1586AEA43 ] sffp_sd         C:\Windows\system32\DRIVERS\sffp_sd.sys
08:38:34.0722 0x0398  sffp_sd - ok
08:38:34.0753 0x0398  [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy         C:\Windows\system32\DRIVERS\sfloppy.sys
08:38:34.0753 0x0398  sfloppy - ok
08:38:34.0924 0x0398  [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
08:38:34.0987 0x0398  SharedAccess - ok
08:38:35.0112 0x0398  [ 0298AC45D0EFFFB2DB4BAA7DD186E7BF, 1C1D17301A4D37DBF906955CCABD2A3FDA47AFB24CBA978CF851123762249848 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
08:38:35.0143 0x0398  ShellHWDetection - ok
08:38:35.0205 0x0398  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
08:38:35.0221 0x0398  SiSRaid2 - ok
08:38:35.0268 0x0398  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
08:38:35.0268 0x0398  SiSRaid4 - ok
08:38:35.0626 0x0398  [ 52F7E8603E888E3DB0A8B3D1804098E9, 4E23DC9442C0C14AAE7146DACBB0B39743F1FFAA463EE7069CCDF866AD27BD77 ] SkypeUpdate     C:\Program Files (x86)\Skype\Updater\Updater.exe
08:38:35.0626 0x0398  SkypeUpdate - ok
08:38:35.0720 0x0398  [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
08:38:35.0767 0x0398  Smb - ok
08:38:35.0798 0x0398  [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
08:38:35.0814 0x0398  SNMPTRAP - ok
08:38:36.0126 0x0398  [ 21FF393512F51F5A98620C794B4488A3, 8A35923D3D6993FC014D86F0F7BD5C106586824DB8D26C04DC2AD0B8ED13ED20 ] Sony PC Companion C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
08:38:36.0126 0x0398  Sony PC Companion - ok
08:38:36.0219 0x0398  [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr           C:\Windows\system32\drivers\spldr.sys
08:38:36.0219 0x0398  spldr - ok
08:38:36.0500 0x0398  [ F8E1FA03CB70D54A9892AC88B91D1E7B, 55EECAAD4C7EC0868BE937F4ADDA026AFDFCC614E94DE4B3248BFF2BE7FF13E8 ] Spooler         C:\Windows\System32\spoolsv.exe
08:38:36.0594 0x0398  Spooler - ok
08:38:36.0937 0x0398  [ 913D843498553A1BC8F8DBAD6358E49F, F8B931FDABF669D642CBDCD2FF31E07F8A5E2D5F72E11D4A8FF219CCFB5825E9 ] sppsvc          C:\Windows\system32\sppsvc.exe
08:38:37.0030 0x0398  sppsvc - ok
08:38:37.0077 0x0398  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify     C:\Windows\system32\sppuinotify.dll
08:38:37.0093 0x0398  sppuinotify - ok
08:38:37.0327 0x0398  [ 2408C0366D96BCDF63E8F1C78E4A29C5, 66F646890695B5D80536E88B1566C8765D89CFE25954ED650F6D773EFF045016 ] srv             C:\Windows\system32\DRIVERS\srv.sys
08:38:37.0420 0x0398  srv - ok
08:38:37.0592 0x0398  [ 76548F7B818881B47D8D1AE1BE9C11F8, 8F1356B07A6A55746FC71B6DB0322128941AE890850196F2B19BC01E6FC9B41C ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
08:38:37.0639 0x0398  srv2 - ok
08:38:37.0748 0x0398  [ 0AF6E19D39C70844C5CAA8FB0183C36E, 4494EEFDEA7198888D32E74727E5BC0AC628FFA70B1FE7EB59DBEEDC1A95D0DD ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
08:38:37.0779 0x0398  srvnet - ok
08:38:37.0873 0x0398  [ F87ADF027C7D05B2681FA4AC820B7D66, 482ED455B8DD963AD2535609A6EF0D1D27C1D356E76FA963AA41039C5BEA6EE0 ] ssdevfactory    C:\Windows\system32\DRIVERS\ssdevfactory.sys
08:38:37.0873 0x0398  ssdevfactory - ok
08:38:38.0044 0x0398  [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
08:38:38.0107 0x0398  SSDPSRV - ok
08:38:38.0185 0x0398  [ 391BDA3C578AA58C1EBCFE99FFBFF5E7, 149AA0826E297DD4F224E95714A85D11CF8FB5C5E011C1AC4DE1885E2BCC57AE ] sshid           C:\Windows\system32\DRIVERS\sshid.sys
08:38:38.0185 0x0398  sshid - ok
08:38:38.0216 0x0398  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc         C:\Windows\system32\sstpsvc.dll
08:38:38.0247 0x0398  SstpSvc - ok
08:38:38.0544 0x0398  [ 5852D5FADD589643B6C1B5BE9D257A50, 38DC6CEB0AA6AF4FD046A9CF7571E345E52D30471E248E2B99FC6D5622257145 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
08:38:38.0559 0x0398  Steam Client Service - ok
08:38:38.0856 0x0398  [ 601F0449030798FDFB2932F902C24C98, 95D5BEFF5E909513C6823FC115259FF7C5AD695C5992874B612248D9616F5DA5 ] Stereo Service  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
08:38:38.0871 0x0398  Stereo Service - ok
08:38:38.0949 0x0398  [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
08:38:38.0949 0x0398  stexstor - ok
08:38:39.0199 0x0398  [ 52D0E33B681BD0F33FDC08812FEE4F7D, BBEBC0773402F6697D2F14F63E5E4FDC2180466E7FDBD306E408535B10160249 ] stisvc          C:\Windows\System32\wiaservc.dll
08:38:39.0246 0x0398  stisvc - ok
08:38:39.0292 0x0398  [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
08:38:39.0308 0x0398  swenum - ok
08:38:39.0433 0x0398  [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv           C:\Windows\System32\swprv.dll
08:38:39.0495 0x0398  swprv - ok
08:38:40.0135 0x0398  [ 3C1284516A62078FB68F768DE4F1A7BE, 67ECD462335EF88773E4BAEAB230A68EC92A25F8CD8F115873F669205AE6A1A9 ] SysMain         C:\Windows\system32\sysmain.dll
08:38:40.0182 0x0398  SysMain - ok
08:38:40.0213 0x0398  [ 238935C3CF2854886DC7CBB2A0E2CC66, BBF7A70BF218A544CC1A6FB81F75EAD29D418794162936BE197D6D61FE0DB1C4 ] TabletInputService C:\Windows\System32\TabSvc.dll
08:38:40.0260 0x0398  TabletInputService - ok
08:38:40.0353 0x0398  [ 884264AC597B690C5707C89723BB8E7B, 9BF209A4128019421F7EC4AFF71103C5F411DB6CFB32AAC1633E789AD7A30708 ] TapiSrv         C:\Windows\System32\tapisrv.dll
08:38:40.0400 0x0398  TapiSrv - ok
08:38:40.0431 0x0398  [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5A92E5E78A952E4 ] TBS             C:\Windows\System32\tbssvc.dll
08:38:40.0494 0x0398  TBS - ok
08:38:40.0821 0x0398  [ 5CFB7AB8F9524D1A1E14369DE63B83CC, BC22FC5714A6A8F8CF95D3D9656332D7B315FF7CFA50C0DEB7437A30651D10C7 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
08:38:40.0852 0x0398  Tcpip - ok
08:38:40.0899 0x0398  [ 5CFB7AB8F9524D1A1E14369DE63B83CC, BC22FC5714A6A8F8CF95D3D9656332D7B315FF7CFA50C0DEB7437A30651D10C7 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
08:38:40.0930 0x0398  TCPIP6 - ok
08:38:40.0993 0x0398  [ 76D078AF6F587B162D50210F761EB9ED, 3813171036B4036306CADC29F877ADAE44B241DDF65B3699C352B7CDA9EC68C9 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
08:38:41.0008 0x0398  tcpipreg - ok
08:38:41.0040 0x0398  [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
08:38:41.0118 0x0398  TDPIPE - ok
08:38:41.0196 0x0398  [ 7518F7BCFD4B308ABC9192BACAF6C970, CF08E547EF4059DA3F5A2FCBA98939E84092BB6E0E37F9BBCD1E4D9EBB8A58BB ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
08:38:41.0274 0x0398  TDTCP - ok
08:38:41.0367 0x0398  [ 079125C4B17B01FCAEEBCE0BCB290C0F, B2DF1F2317EF5DCF0A89327332E9F2770ED604005B3138C095FF01AA63B91437 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
08:38:41.0414 0x0398  tdx - ok
08:38:41.0430 0x0398  [ C448651339196C0E869A355171875522, C12441CF21D7D47804952B968689D78E3BA0323A90C4C811B54A6B2E6260BAD4 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
08:38:41.0445 0x0398  TermDD - ok
08:38:41.0570 0x0398  [ 0F05EC2887BFE197AD82A13287D2F404, 78C8A8FE9B1101430CA79875DA34413C35B6D7A5EE1932E454C50731335437A6 ] TermService     C:\Windows\System32\termsrv.dll
08:38:41.0632 0x0398  TermService - ok
08:38:41.0664 0x0398  [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes          C:\Windows\system32\themeservice.dll
08:38:41.0664 0x0398  Themes - ok
08:38:41.0695 0x0398  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER     C:\Windows\system32\mmcss.dll
08:38:41.0726 0x0398  THREADORDER - ok
08:38:41.0742 0x0398  [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks          C:\Windows\System32\trkwks.dll
08:38:41.0788 0x0398  TrkWks - ok
08:38:41.0960 0x0398  [ 370A6907DDF79532A39319492B1FA38A, 46AECC5160F04FC3FFE4D37B404CCBBD1C5DC1501C2CEEE8284FF544DBDF10F8 ] truecrypt       C:\Windows\system32\drivers\truecrypt.sys
08:38:41.0976 0x0398  truecrypt - ok
08:38:42.0147 0x0398  [ 840F7FB849F5887A49BA18C13B2DA920, A59C40A090E03C0136A865FC54508BA938E7B467C8198BC009FE263E6C275781 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
08:38:42.0163 0x0398  TrustedInstaller - ok
08:38:42.0194 0x0398  [ 61B96C26131E37B24E93327A0BD1FB95, 7C551B6FD0447258BC3FDED72D8D41A0E8B731562170C264295592D45F85D9FF ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
08:38:42.0256 0x0398  tssecsrv - ok
08:38:42.0381 0x0398  [ 3836171A2CDF3AF8EF10856DB9835A70, 74CD0A21B4E5B47E8D762CC28282CA8D512D424EC591D90099B9F8D034AA2FC2 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
08:38:42.0444 0x0398  tunnel - ok
08:38:42.0475 0x0398  [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
08:38:42.0490 0x0398  uagp35 - ok
08:38:42.0615 0x0398  [ D47BAEAD86C65D4F4069D7CE0A4EDCEB, DBAEA010F11A5EFD961B1841308EA3F220A9FFB01F364BA9B8F72200DA2BBCD8 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
08:38:42.0678 0x0398  udfs - ok
08:38:42.0709 0x0398  [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect       C:\Windows\system32\UI0Detect.exe
08:38:42.0724 0x0398  UI0Detect - ok
08:38:42.0756 0x0398  [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx        C:\Windows\system32\DRIVERS\uliagpkx.sys
08:38:42.0771 0x0398  uliagpkx - ok
08:38:42.0802 0x0398  [ EAB6C35E62B1B0DB0D1B48B671D3A117, E65034BF757AE4D21F69D7A91A7990E326A29A0CE9F871FD704B5E6CCC821FF0 ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
08:38:42.0802 0x0398  umbus - ok
08:38:42.0834 0x0398  [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
08:38:42.0865 0x0398  UmPass - ok
08:38:42.0990 0x0398  [ 1E9A5658E0EBDBC381F52123363F74CB, 62CB592F32BCC10FC9C3AF44941CC473F2F62EEBF829CA383F118650451F8F7E ] UNS             C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
08:38:43.0005 0x0398  UNS - ok
08:38:43.0036 0x0398  [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost        C:\Windows\System32\upnphost.dll
08:38:43.0068 0x0398  upnphost - ok
08:38:43.0161 0x0398  [ 77B01BC848298223A95D4EC23E1785A1, 7D0FBBA746588401400226BB966507EE34EEBB2F4F16607601E3D7383CAD34E2 ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
08:38:43.0192 0x0398  usbaudio - ok
08:38:43.0208 0x0398  [ B26AFB54A534D634523C4FB66765B026, A219C9AE32D040BEA4DD69C2C826B1C52BACE26BEBFEE799BD56DFD442C5E0D8 ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
08:38:43.0224 0x0398  usbccgp - ok
08:38:43.0286 0x0398  [ AF0892A803FDDA7492F595368E3B68E7, F263346DEB4D742EB436CF578F187AC8521D84CED52E98475E6198EC52244F07 ] usbcir          C:\Windows\system32\DRIVERS\usbcir.sys
08:38:43.0317 0x0398  usbcir - ok
08:38:43.0333 0x0398  [ 2EA4AFF7BE7EB4632E3AA8595B0803B5, CBECE7CEC0EFA4B283C63E9B6A270D595F5F3D006306DA5E5121BBFDCAB16376 ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
08:38:43.0348 0x0398  usbehci - ok
08:38:43.0458 0x0398  [ 4C9042B8DF86C1E8E6240C218B99B39B, D286633311C047B9C4FB1AA89D7B02B9F943FDDCE473255DC8E14DD07CC9B292 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
08:38:43.0536 0x0398  usbhub - ok
08:38:43.0551 0x0398  [ 58E546BBAF87664FC57E0F6081E4F609, 1DD99D57369A0069654432AB5325AFD8F7D422D531E053EA05FF664BA6BDAEF9 ] usbohci         C:\Windows\system32\DRIVERS\usbohci.sys
08:38:43.0567 0x0398  usbohci - ok
08:38:43.0582 0x0398  [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
08:38:43.0629 0x0398  usbprint - ok
08:38:43.0645 0x0398  [ 080D3820DA6C046BE82FC8B45A893E83, EF4829A2D5B8D47AA7E06093EC85244042ED1CCFF43CC80DC44EF018B434197A ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
08:38:43.0692 0x0398  USBSTOR - ok
08:38:43.0707 0x0398  [ 81FB2216D3A60D1284455D511797DB3D, 121E52B18A1832E775EA0AE2E053BAA53E5A70E9754724B1449AE5992D63B13E ] usbuhci         C:\Windows\system32\DRIVERS\usbuhci.sys
08:38:43.0723 0x0398  usbuhci - ok
08:38:43.0863 0x0398  [ D501E12614B00A3252073101D6A1A74B, DFA3A83978125B3CE45C71DD9069E8A7938366D0F4B4B2401CDD07251253FA8C ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
08:38:43.0863 0x0398  usbvideo - ok
08:38:43.0879 0x0398  [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms           C:\Windows\System32\uxsms.dll
08:38:43.0926 0x0398  UxSms - ok
08:38:43.0941 0x0398  [ 156F6159457D0AA7E59B62681B56EB90, 27B855BF79490E4CC58D38A920C077A56785494BFFF0B448A898486009B24937 ] VaultSvc        C:\Windows\system32\lsass.exe
08:38:43.0941 0x0398  VaultSvc - ok
08:38:44.0503 0x0398  [ 3470D2C83CA7A056B91216EA1D571304, 3189ABF6E8C08B1B0F406DB5E78F9ABD9A0AE3FF52615B681A8DEB1A38E26B83 ] VBoxAswDrv      C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys
08:38:44.0518 0x0398  VBoxAswDrv - ok
08:38:44.0581 0x0398  [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot        C:\Windows\system32\DRIVERS\vdrvroot.sys
08:38:44.0596 0x0398  vdrvroot - ok
08:38:44.0659 0x0398  [ 44D73E0BBC1D3C8981304BA15135C2F2, 2849387BBCFB0189AF5604D2F7A631BD5D6BBB2CA73AF6E870069AF382A74DED ] vds             C:\Windows\System32\vds.exe
08:38:44.0674 0x0398  vds - ok
08:38:44.0706 0x0398  [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
08:38:44.0706 0x0398  vga - ok
08:38:44.0752 0x0398  [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave         C:\Windows\System32\drivers\vga.sys
08:38:44.0799 0x0398  VgaSave - ok
08:38:44.0893 0x0398  [ C82E748660F62A242B2DFAC1442F22A4, 24AD6CAA918C5AB6F461D88825885C8637C224001AAD7A80BDC240368CDB0B7E ] vhdmp           C:\Windows\system32\DRIVERS\vhdmp.sys
08:38:44.0893 0x0398  vhdmp - ok
08:38:44.0940 0x0398  [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide          C:\Windows\system32\DRIVERS\viaide.sys
08:38:44.0940 0x0398  viaide - ok
08:38:44.0986 0x0398  [ 2B1A3DAE2B4E70DBBA822B7A03FBD4A3, 91F2B935E1E88C5542650F7D679A75D0562F4A5812179D1EC146D4B6351361E2 ] volmgr          C:\Windows\system32\DRIVERS\volmgr.sys
08:38:44.0986 0x0398  volmgr - ok
08:38:45.0127 0x0398  [ 99B0CBB569CA79ACAED8C91461D765FB, 5BE394A39A941DE2AA1212E66B7068F90D423FA816238657CB9B2DA8BBE69B9B ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
08:38:45.0142 0x0398  volmgrx - ok
08:38:45.0314 0x0398  [ 9E425AC5C9A5A973273D169F43B4F5E1, 64C9A9D4A39865E56F01B4FDE1B56034C4B2A2AEF2ABE15EC1C37911C59595B0 ] volsnap         C:\Windows\system32\DRIVERS\volsnap.sys
08:38:45.0314 0x0398  volsnap - ok
08:38:45.0439 0x0398  [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid         C:\Windows\system32\DRIVERS\vsmraid.sys
08:38:45.0454 0x0398  vsmraid - ok
08:38:45.0938 0x0398  [ 787898BF9FB6D7BD87A36E2D95C899BA, A6C0C7402B1A198E7B3D6D7D283FCB5815AC429DA68FC9B54C67707F3233CCB5 ] VSS             C:\Windows\system32\vssvc.exe
08:38:46.0000 0x0398  VSS - ok
08:38:46.0032 0x0398  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
08:38:46.0032 0x0398  vwifibus - ok
08:38:46.0125 0x0398  [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time         C:\Windows\system32\w32time.dll
08:38:46.0141 0x0398  W32Time - ok
08:38:46.0172 0x0398  [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
08:38:46.0203 0x0398  WacomPen - ok
08:38:46.0297 0x0398  [ 47CA49400643EFFD3F1C9A27E1D69324, 7EFD3405282264F7987172B226882FCDD223F771959B9CEBEBF9ECEA317D85B0 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
08:38:46.0359 0x0398  WANARP - ok
08:38:46.0390 0x0398  [ 47CA49400643EFFD3F1C9A27E1D69324, 7EFD3405282264F7987172B226882FCDD223F771959B9CEBEBF9ECEA317D85B0 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
08:38:46.0406 0x0398  Wanarpv6 - ok
08:38:46.0890 0x0398  [ 5AB1BB85BD8B5089CC5D64200DEDAE68, 28777D4F3CD07C8E3465B6DA0FCA994E0B93071A3A0D4D1D64C1DF633DD1C64F ] wbengine        C:\Windows\system32\wbengine.exe
08:38:46.0983 0x0398  wbengine - ok
08:38:47.0077 0x0398  [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
08:38:47.0092 0x0398  WbioSrvc - ok
08:38:47.0139 0x0398  [ 8321C2CA3B62B61B293CDA3451984468, 856A079C2CCC75D633EA23E410D7F3ECDF368EAAAFF634CB82DDA545FD3A2F9C ] wcncsvc         C:\Windows\System32\wcncsvc.dll
08:38:47.0155 0x0398  wcncsvc - ok
08:38:47.0186 0x0398  [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
08:38:47.0280 0x0398  WcsPlugInService - ok
08:38:47.0311 0x0398  [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd              C:\Windows\system32\DRIVERS\wd.sys
08:38:47.0326 0x0398  Wd - ok
08:38:47.0404 0x0398  [ 442783E2CB0DA19873B7A63833FF4CB4, 09254970265476214F3187CC22A4F9C7C2769D419600E83FBE302C3A103E527F ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
08:38:47.0436 0x0398  Wdf01000 - ok
08:38:47.0451 0x0398  [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiServiceHost  C:\Windows\system32\wdi.dll
08:38:47.0482 0x0398  WdiServiceHost - ok
08:38:47.0482 0x0398  [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiSystemHost   C:\Windows\system32\wdi.dll
08:38:47.0498 0x0398  WdiSystemHost - ok
08:38:47.0576 0x0398  [ 8A438CBB8C032A0C798B0C642FFBE572, 3200B9B6A7B87C1C47295FA416C99DE1FBB2DBBA3DA78D5CC88C26DCC4189D45 ] WebClient       C:\Windows\System32\webclnt.dll
08:38:47.0623 0x0398  WebClient - ok
08:38:47.0670 0x0398  [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc          C:\Windows\system32\wecsvc.dll
08:38:47.0748 0x0398  Wecsvc - ok
08:38:47.0794 0x0398  [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
08:38:47.0841 0x0398  wercplsupport - ok
08:38:47.0919 0x0398  [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc          C:\Windows\System32\WerSvc.dll
08:38:47.0935 0x0398  WerSvc - ok
08:38:47.0997 0x0398  [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
08:38:48.0028 0x0398  WfpLwf - ok
08:38:48.0060 0x0398  [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
08:38:48.0060 0x0398  WIMMount - ok
08:38:48.0106 0x0398  WinDefend - ok
08:38:48.0122 0x0398  WinHttpAutoProxySvc - ok
08:38:48.0559 0x0398  [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
08:38:48.0606 0x0398  Winmgmt - ok
08:38:50.0524 0x0398  WinRing0_1_2_0 - ok
08:38:51.0741 0x0398  [ 41FBB751936B387F9179E7F03A74FE29, 7A73D887BEC19DFC485ED42B4E6ABEBF824555139B81EA30731A00773E707464 ] WinRM           C:\Windows\system32\WsmSvc.dll
08:38:51.0835 0x0398  WinRM - ok
08:38:52.0069 0x0398  [ 817EAFF5D38674EDD7713B9DFB8E9791, F6E0BFC503BA7395F92989C11B454D1F1E58E29302BA203801449A2C5236E84D ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
08:38:52.0069 0x0398  WinUsb - ok
08:38:52.0131 0x0398  [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc         C:\Windows\System32\wlansvc.dll
08:38:52.0162 0x0398  Wlansvc - ok
08:38:52.0240 0x0398  [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi         C:\Windows\system32\DRIVERS\wmiacpi.sys
08:38:52.0240 0x0398  WmiAcpi - ok
08:38:52.0381 0x0398  [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
08:38:52.0396 0x0398  wmiApSrv - ok
08:38:52.0615 0x0398  WMPNetworkSvc - ok
08:38:52.0646 0x0398  [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc          C:\Windows\System32\wpcsvc.dll
08:38:52.0662 0x0398  WPCSvc - ok
08:38:52.0677 0x0398  [ 2E57DDF2880A7E52E76F41C7E96D327B, D24E19B6091C197D77D71BC044CE2E5A57BE0A2F00D1BB0732E380A398230E63 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
08:38:52.0724 0x0398  WPDBusEnum - ok
08:38:52.0771 0x0398  [ 7CA09731EB7FC99B910C7F239E57720F, 502F8917A0811F37C39B2B3F5E9B4F38A0E899C30CB29D3ECD87A50FF228E536 ] WPRO_41_2001    C:\Windows\system32\drivers\WPRO_41_2001.sys
08:38:52.0771 0x0398  WPRO_41_2001 - ok
08:38:52.0802 0x0398  [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
08:38:52.0833 0x0398  ws2ifsl - ok
08:38:52.0864 0x0398  [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc          C:\Windows\System32\wscsvc.dll
08:38:52.0896 0x0398  wscsvc - ok
08:38:52.0896 0x0398  WSearch - ok
08:38:52.0958 0x0398  [ D9EF901DCA379CFE914E9FA13B73B4C4, 3BE9693B7B2AFEE23D72AF5DA211379724D752F0EC18ACB7D3DE3DDFC5AE0004 ] wuauserv        C:\Windows\system32\wuaueng.dll
08:38:53.0192 0x0398  wuauserv - ok
08:38:53.0239 0x0398  [ 7CADC74271DD6461C452C271B30BD378, D58C2094C36FC665C03A6A269EED80DC71F330C3DCF40A27A3C8F56AB7A96861 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
08:38:53.0254 0x0398  WudfPf - ok
08:38:53.0379 0x0398  [ 3B197AF0FFF08AA66B6B2241CA538D64, BC94E5EFF38B9C6A37717B2A6CA56679781A4872A0C4298056E074033571BE79 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
08:38:53.0457 0x0398  WUDFRd - ok
08:38:53.0520 0x0398  [ B551D6637AA0E132C18AC6E504F7B79B, FA6495533A14E01ABB0F6689AB7503B1B439D3ADA7457DFCB7D81714A9817327 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
08:38:53.0535 0x0398  wudfsvc - ok
08:38:53.0613 0x0398  [ 9A3452B3C2A46C073166C5CF49FAD1AE, D6F95F51D8E37BA4CF403965EC08CCFEEA9EEFDBFC7752432EAEC19925BDA115 ] WwanSvc         C:\Windows\System32\wwansvc.dll
08:38:53.0644 0x0398  WwanSvc - ok
08:38:53.0925 0x0398  [ 4A5CE13408945E525503B5F73D29B9C5, D58BB31AF17752508EA67931BF170CE46877DC204FC5DA7EED5A078AEB0CA0FD ] xnacc           C:\Windows\system32\DRIVERS\xnacc.sys
08:38:53.0956 0x0398  xnacc - ok
08:38:54.0003 0x0398  [ 38F55D07B1D3391065C40EC065F984E2, 056F5E3034C4C11403D74F44A364964A3A5945608DAE2A03EF025A22F5C31B26 ] xusb21          C:\Windows\system32\DRIVERS\xusb21.sys
08:38:54.0081 0x0398  xusb21 - ok
08:38:54.0097 0x0398  ================ Scan global ===============================
08:38:54.0190 0x0398  [ BA0CD8C393E8C9F83354106093832C7B, 18D8A4780A2BAA6CEF7FBBBDA0EF6BF2DADF146E1E578A618DD5859E8ADBF1A8 ] C:\Windows\system32\basesrv.dll
08:38:54.0300 0x0398  [ 3FB74FF230B5D240A57AE1C4A3D0459D, 7A4036CAC3BAAEC719E4152F2CAA9D9B69DACBDC7502147D7160D04AE70BC8DF ] C:\Windows\system32\winsrv.dll
08:38:54.0315 0x0398  [ 3FB74FF230B5D240A57AE1C4A3D0459D, 7A4036CAC3BAAEC719E4152F2CAA9D9B69DACBDC7502147D7160D04AE70BC8DF ] C:\Windows\system32\winsrv.dll
08:38:54.0346 0x0398  [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll
08:38:54.0502 0x0398  [ 24ACB7E5BE595468E3B9AA488B9B4FCB, 63541E3432FCE953F266AE553E7A394978D6EE3DB52388D885F668CF42C5E7E2 ] C:\Windows\system32\services.exe
08:38:54.0518 0x0398  [ Global ] - ok
08:38:54.0518 0x0398  ================ Scan MBR ==================================
08:38:54.0596 0x0398  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
08:38:55.0314 0x0398  \Device\Harddisk0\DR0 - ok
08:38:55.0532 0x0398  [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
08:38:55.0688 0x0398  \Device\Harddisk1\DR1 - ok
08:38:55.0688 0x0398  ================ Scan VBR ==================================
08:38:55.0688 0x0398  [ EF68C7B4BB5B1349071186D64E122C55 ] \Device\Harddisk0\DR0\Partition1
08:38:55.0797 0x0398  \Device\Harddisk0\DR0\Partition1 - detected Rootkit.Boot.Cidox.b ( 0 )
08:38:55.0797 0x0398  \Device\Harddisk0\DR0\Partition1 ( Rootkit.Boot.Cidox.b ) - infected
08:38:55.0797 0x0398  [ DFC86A5DA3571010B5386566800C61B3 ] \Device\Harddisk0\DR0\Partition2
08:38:55.0891 0x0398  \Device\Harddisk0\DR0\Partition2 - ok
08:38:55.0906 0x0398  [ 8B316FAD2BD232D4BFC321F32F0DDA40 ] \Device\Harddisk1\DR1\Partition1
08:38:55.0906 0x0398  \Device\Harddisk1\DR1\Partition1 - ok
08:38:55.0906 0x0398  ================ Scan generic autorun ======================
08:38:56.0031 0x0398  [ 1AE420BD421E0AD6D1A14E446CBCD6D4, 0CAE1B7AFEE2AE5EAB145AB555D7B6AEF7947C6F39EDDB58DFF12F293B736079 ] C:\PROGRA~3\aspnet_wp_64.exe
08:38:56.0031 0x0398  aspnet_wp_64 - detected UnsignedFile.Multi.Generic ( 1 )
08:38:56.0078 0x0398  aspnet_wp_64 ( UnsignedFile.Multi.Generic ) - warning
08:38:56.0125 0x0398  [ DD81D91FF3B0763C392422865C9AC12E, F5691B8F200E3196E6808E932630E862F8F26F31CD949981373F23C9D87DB8B9 ] C:\Windows\system32\rundll32.exe
08:38:56.0140 0x0398  ShadowPlay - ok
08:38:59.0260 0x0398  [ 160B5E0566713EB5CAB2EC12C36ACF52, 3B9FC94989CED565C339A0A5E79CE61B180BA14D46759A1F27DC3561E3384E31 ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
08:38:59.0604 0x0398  RTHDVCPL - ok
08:38:59.0666 0x0398  [ 1CB704C1D6B69A863AAC5CCA6956F238, 7D426F0C463D2F8168A97EB8C3CC12CC841A1F33393172B469BA6920D93C7F8A ] C:\PROGRA~3\openssl.exe
08:38:59.0697 0x0398  openssl - detected UnsignedFile.Multi.Generic ( 1 )
08:38:59.0697 0x0398  openssl ( UnsignedFile.Multi.Generic ) - warning
08:39:00.0462 0x0398  [ 8F82FFC6CD0F4C83F4565E1A40332CCD, 45D17603664CBE2C4236AEDB3C21D585C8225A3D3B1118365EE2C6BFDB8A7890 ] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
08:39:00.0524 0x0398  NvBackend - ok
08:39:03.0160 0x0398  [ 568AF5AB79BC0CA3FDDD49C03363F605, A9D74EB4B4B063B509CCDECA4E9E988A969E635A608CBFA51B9147719CBF3DE1 ] C:\Program Files\Logitech Gaming Software\LCore.exe
08:39:03.0426 0x0398  Launch LCore - ok
08:39:03.0504 0x0398  [ 94FF4CB7FF990380A48FF5F237218BEB, D97254386F1504CF8FFD03E585ACA9176B3B579B5E8DC81DAA6B4F209A781C81 ] C:\PROGRA~3\igfxEM_32.exe
08:39:03.0535 0x0398  igfxEM_32 - detected UnsignedFile.Multi.Generic ( 1 )
08:39:03.0535 0x0398  igfxEM_32 ( UnsignedFile.Multi.Generic ) - warning
08:39:03.0535 0x0398  Force sending object to P2P due to detect: C:\PROGRA~3\igfxEM_32.exe
08:39:03.0535 0x0398  Object send P2P result: false
08:39:03.0535 0x0398  GheT3Z733AFC - ok
08:39:04.0642 0x0398  [ 790FE6428CF4FEE8D71033AC23A5360B, 235C95AD1968778E6F7FA3296A15C0BDF3941E492EDAB32D4065FB686DEFF6C4 ] C:\Program Files (x86)\Stardock\Fences\Fences.exe
08:39:04.0720 0x0398  Fences - ok
08:39:05.0001 0x0398  [ 4D1DA8CE5E364D22B4FF00F163194514, 165DE474309206A0F51266F19EDB4AF3D7BAD19FDA61B636AEE7A04278DBBC2C ] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
08:39:05.0017 0x0398  USB3MON - ok
08:39:05.0251 0x0398  [ 1DE859B82E381A645C44284A5044BC33, 305AE678D3163D57C8E027F94BC553FDFDE7F9A14599EAEC370B0867DE4A9EC2 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
08:39:05.0251 0x0398  SunJavaUpdateSched - ok
08:39:05.0251 0x0398  P17RunE - ok
08:39:05.0422 0x0398  [ D36DCD24C810EE89360F64A4FB94AF88, D2E8E5DE5A32F294A8C5F06310599C4D35C8930F8AD1DD0B80AE63A36FA7A32D ] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
08:39:05.0422 0x0398  IJNetworkScanUtility - ok
08:39:05.0532 0x0398  [ E7861EAA7881E086B2DB88ADF4279D4B, D040BCEC5B7519357D4E28653FC0F9F4FEAA88D291726A0763EA5E84C8C5D840 ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
08:39:05.0532 0x0398  IAStorIcon - ok
08:39:05.0547 0x0398  DelaypluginInstall - ok
08:39:06.0249 0x0398  [ EF9175A571AA3E73EB765289625FD5B3, 12E405A70DC4B37A527D5B2D17A5179422F3D01D7DD46E67C9FCA769F09AFAB9 ] C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe
08:39:06.0280 0x0398  DBAgent - ok
08:39:06.0639 0x0398  [ 048EA4B978851788E9F5E8E4F081DF7A, EB62719AC0DCC18FF056F2CD84438BF14B61E38F0619617C81961C6257BDFCEC ] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
08:39:06.0655 0x0398  Adobe ARM - ok
08:39:06.0936 0x0398  [ EA6EADF6314E43783BA8EEE79F93F73C, 1A4BC2D8DFBDC37AF85C73DEE76A6EE901EBA188D43856BD2FFA96B79A126F73 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
08:39:07.0060 0x0398  Sidebar - ok
08:39:07.0107 0x0398  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
08:39:07.0107 0x0398  mctadmin - ok
08:39:07.0138 0x0398  [ EA6EADF6314E43783BA8EEE79F93F73C, 1A4BC2D8DFBDC37AF85C73DEE76A6EE901EBA188D43856BD2FFA96B79A126F73 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
08:39:07.0170 0x0398  Sidebar - ok
08:39:07.0170 0x0398  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
08:39:07.0185 0x0398  mctadmin - ok
08:39:07.0232 0x0398  [ 45CC262346C3BE6585AA4CB875D6D81B, A001C5EBD3D6572DAB7BC47AD3DBB10E7A247DE77772942114B06FAAAF12008F ] C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
08:39:07.0232 0x0398  Uploader - ok
08:39:08.0184 0x0398  [ 5353A34090BABE3CD48B70569AF0DD12, A211D0B06DC05BFCBD13EBC71275C644B7616E95485ED8336DEFF257B7AE7E80 ] C:\Program Files (x86)\Steam\steam.exe
08:39:08.0230 0x0398  Steam - ok
08:39:08.0527 0x0398  [ 89CACBC5A5D9F14AD11F09D1DE49294E, 5D9F810E57527ED9E95BB208DBA13D25AF64346B298C1C793335775F9AED21C7 ] C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
08:39:08.0527 0x0398  Sony PC Companion - ok
08:39:08.0714 0x0398  Skype - ok
08:39:09.0229 0x0398  [ 8FC6C4EE0A2D3EBAA70FA38F99141BCE, 7A00880C69E596B6D867A918179703CABD8BEF12465B81420F3AC327F509F039 ] C:\Program Files\Windows Sidebar\sidebar.exe
08:39:09.0291 0x0398  Sidebar - ok
08:39:09.0432 0x0398  [ 646914A0DDDF0208E722B4461B13D702, D2BC4761A605E0B28FEC349B10DBA29944B046987722A7A3B1F4B5164C72D743 ] C:\PROGRA~2\Raptr\raptrstub.exe
08:39:09.0432 0x0398  Raptr - ok
08:39:10.0149 0x0398  [ BA00E1FCDD7FDCA70024BE182EB2C158, 9167A4F2A601571CC4A946C3261CCF340228C2BB1394520A1C40F41FF01E7AF7 ] C:\Program Files\PeerBlock\peerblock.exe
08:39:10.0196 0x0398  PeerBlock - ok
08:39:10.0212 0x0398  IequGrufh - ok
08:39:10.0336 0x0398  GoogleDriveSync - ok
08:39:10.0711 0x0398  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe
08:39:10.0726 0x0398  Google Update - ok
08:39:11.0038 0x0398  [ 44A9229022A519ED45294A1934C05EEC, 6DEF0DB5F9B50E9B0AFEE1CF50066BEB4FB7E15E2DC829A499509925660D6992 ] C:\Users\Michael\AppData\Local\FluxSoftware\Flux\flux.exe
08:39:11.0054 0x0398  f.lux - ok
08:39:11.0210 0x0398  [ 7C6D524C78A1722AD987B9E47AC1FEE2, FFDC6C92ABB547D0DCD2621EC423C755A78079B061A41FA1751A56799D1A79A5 ] C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe
08:39:11.0210 0x0398  Dropbox Update - ok
08:39:11.0413 0x0398  [ DC46E089C1F0FD903D1D8D48591B2EA2, AAB526AC18F8AFCB9DBB818676F0E16E7990CB92FA122BB3654518F5F1484B2F ] C:\Users\Michael\AppData\Roaming\BackUp680067079.exe
08:39:11.0460 0x0398  BackUp680067079 - detected UnsignedFile.Multi.Generic ( 1 )
08:39:11.0460 0x0398  BackUp680067079 ( UnsignedFile.Multi.Generic ) - warning
08:39:11.0460 0x0398  Force sending object to P2P due to detect: C:\Users\Michael\AppData\Roaming\BackUp680067079.exe
08:39:11.0460 0x0398  Object send P2P result: false
08:39:13.0051 0x0398  AV detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 10.4.2233.1299 ), 0x40000 ( disabled : updated )
08:39:13.0332 0x0398  Win FW state via NFP2: disabled ( not trusted )
08:39:13.0332 0x0398  ============================================================
08:39:13.0332 0x0398  Scan finished
08:39:13.0332 0x0398  ============================================================
08:39:13.0332 0x0484  Detected object count: 5
08:39:13.0332 0x0484  Actual detected object count: 5
08:40:09.0944 0x0484  \Device\Harddisk0\DR0\Partition1 - copied to quarantine
08:40:10.0116 0x0484  \Device\Harddisk0\DR0\Partition1 ( Rootkit.Boot.Cidox.b ) - will be cured on reboot
08:40:10.0225 0x0484  \Device\Harddisk0\DR0\Partition1 - ok
08:40:10.0225 0x0484  \Device\Harddisk0\DR0\Partition1 ( Rootkit.Boot.Cidox.b ) - User select action: Cure
08:40:10.0319 0x0484  C:\PROGRA~3\aspnet_wp_64.exe - copied to quarantine
08:40:10.0319 0x0484  aspnet_wp_64 ( UnsignedFile.Multi.Generic ) - User select action: Quarantine
08:40:10.0397 0x0484  C:\PROGRA~3\openssl.exe - copied to quarantine
08:40:10.0397 0x0484  openssl ( UnsignedFile.Multi.Generic ) - User select action: Quarantine
08:40:10.0428 0x0484  C:\PROGRA~3\igfxEM_32.exe - copied to quarantine
08:40:10.0428 0x0484  igfxEM_32 ( UnsignedFile.Multi.Generic ) - User select action: Quarantine
08:40:10.0615 0x0484  C:\Users\Michael\AppData\Roaming\BackUp680067079.exe - copied to quarantine
08:40:10.0615 0x0484  BackUp680067079 ( UnsignedFile.Multi.Generic ) - User select action: Quarantine
08:40:12.0877 0x0484  KLMD registered as C:\Windows\system32\drivers\28655143.sys
08:40:33.0937 0x06f8  Deinitialize success

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI