Hello everyone.
So roughly a week ago I recieved an alert from Avast Antivirus while browsing through Chrome, and immediately recieved a blue screen after. On reboot I noticed Avast hadn't started back up, and when tried to manually start it up nothing happened. Trying to reinstall it did nothing, nor did trying to unistall it. I tried installing AVG, which also did nothing. Started up in safe mode, still had the same problem. Chrome also started becoming unstable, crashing after being open for a short while. Now it simply crashes immediately after opening, as does Internet Explorer. The only working browser is Firefox. Ran a Windows Defender scan which sent back an error before it could complete, and the same happened when I ran SuperAntiSpyware. Ran CCleaner's registery cleaner and deleted what showed up, but that didn't change anything. Downloaded and installed Trojan Hunter and ran another scan, deleted what it found, but that also had no effect. Also, I'm not sure if it's related, but I noticed the Steam app's web pages won't load. It's still connected to the web and still auto updates games, I just can't see anything web related through the browser.
And so after all that, I found this place. After following the instructions in the sticky, here's my FRST log. The aswMBR installer won't start up either, so I can't actually do step 1.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-11-2015
Ran by [removed] (administrator) on YMIR (07-11-2015 08:12:25)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium (X64) Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files\Core Temp\Core Temp.exe
(AddGadgets) C:\Users\Michael\Downloads\Windows Gadgets\PCMeterV0.3.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Foxit Corporation) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) C:\Windows\System32\regsvr32.exe
() C:\ProgramData\openssl.exe
() C:\ProgramData\igfxEM_32.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
(Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
(Flux Software LLC) C:\Users\Michael\AppData\Local\FluxSoftware\Flux\flux.exe
() C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
() C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe
(Dropbox, Inc.) C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe
(CANON INC.) C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Mischel Internet Security) C:\Program Files (x86)\TrojanHunter\THGuard.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DeviceAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(PeerBlock, LLC) C:\Program Files\PeerBlock\peerblock.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_226.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_226.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [Fences] => C:\Program Files (x86)\Stardock\Fences\Fences.exe [4013744 2013-04-25] (Stardock Corporation)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12446824 2012-01-31] (Realtek Semiconductor)
HKLM\…\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10464536 2014-07-02] (Logitech Inc.)
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634896 2015-07-23] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\…\Run: [GheT3Z733AFC] => regsvr32.exe /s "C:\PROGRA~3\GheT3Z733AFC.dll"
HKLM\…\Run: [openssl] => C:\ProgramData\openssl.exe [4096 2015-11-05] ()
HKLM\…\Run: [igfxEM_32] => C:\ProgramData\igfxEM_32.exe [4096 2015-11-06] ()
HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-26] (Intel Corporation)
HKLM-x32\…\Run: [P17RunE] => RunDll32 P17RunE.dll,RunDLLEntry
HKLM-x32\…\Run: [IJNetworkScanUtility] => C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [206240 2010-08-23] (CANON INC.)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-10-10] (AVAST Software)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\…\Run: [DBAgent] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [1518664 2014-09-17] (Seagate Technology LLC)
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157968 2015-08-13] (Apple Inc.)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-16] (Apple Inc.)
HKLM-x32\…\Run: [THGuard] => C:\Program Files (x86)\TrojanHunter\THGuard.exe [1082832 2015-06-18] (Mischel Internet Security)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22568216 2015-10-12] (Google)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3011152 2015-11-05] (Valve Corporation)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Google Update] => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-31] (Google Inc.)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Uploader] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe [127080 2014-09-17] (Seagate Technology LLC)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [457088 2015-09-23] (Sony)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Dropbox Update] => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-15] (Dropbox, Inc.)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [f.lux] => C:\Users\Michael\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53729824 2015-08-07] (Skype Technologies S.A.)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [PeerBlock] => C:\Program Files\PeerBlock\peerblock.exe [2513992 2014-01-14] (PeerBlock, LLC)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [IequGrufh] => regsvr32.exe "C:\ProgramData\Linpal\BufqOvba.dll"
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [BackUp680067079] => C:\Users\Michael\AppData\Roaming\BackUp680067079.exe [577536 2009-07-13] ()
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7935904 2015-10-19] (SUPERAntiSpyware)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\MountPoints2: {d61fb579-c776-11e4-bcd3-bc5ff4abb4c9} - I:\Startme.exe
HKU\S-1-5-18\…\Run: [Chrome] => C:\ProgramData\taskhost.exe [5120 2015-10-31] ()
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-10-12] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-10-10] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-10-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-10-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-10-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-10-12] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2015-04-10]
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe ()
Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-10-16]
ShortcutTarget: Dropbox.lnk -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6228E9D9-CFC6-4C51-A1BD-1A5005A37E14}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage;=hxxp://go.microsoft.com/fwlink/?LinkId=69157
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage;=hxxp://go.microsoft.com/fwlink/?LinkId=69157
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage;=hxxps://search.yahoo.com/?type=282369&fr;=spigot-yhp-ie
SearchScopes: HKU\S-1-5-21-711289349-3085500364-3229847752-1000 -> DefaultScope {E65363E6-EB13-4F01-836F-A169301AD9A0} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei;=utf-8&ilc;=12&type;=282369&p;={searchTerms}
SearchScopes: HKU\S-1-5-21-711289349-3085500364-3229847752-1000 -> {E65363E6-EB13-4F01-836F-A169301AD9A0} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei;=utf-8&ilc;=12&type;=282369&p;={searchTerms}
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-05-27] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-26] (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-05-27] (Oracle Corporation)
BHO-x32: No Name -> {451C804F-C205-4F03-B48E-537EC94937BF} -> No File
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-11] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-26] (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-11] (Oracle Corporation)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File
FireFox:
========
FF ProfilePath: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default
FF DefaultSearchEngine: Google
FF DefaultSearchEngine.US: Google
FF Homepage: hxxp://en.wikipedia.org/wiki/Main_Page
FF Session Restore: -> is enabled.
FF Keyword.URL: hxxps://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&ilc;=12&type;=282369&p;=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll [2015-11-05] ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\system32\npDeployJava1.dll [2013-05-27] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-05-27] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-11-05] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-07-30] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-04-23] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-04-23] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-11] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-07-11] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-07-22] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-07-22] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Michael\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @talk.google.com/O1DPlugin -> C:\Users\Michael\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-711289349-3085500364-3229847752-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Michael\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-07-20] (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\user.js [2015-07-10]
FF Plugin ProgramFiles/Appdata: C:\Users\Michael\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Michael\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF SearchPlugin: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\searchplugins\yahoo_ff.xml [2014-07-12]
FF Extension: Cookies Manager+ - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\Extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d} [2015-05-31]
FF Extension: ExHentai Easy 2 - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\Extensions\[removed] [2015-08-31]
FF Extension: Showcase - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\Extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}.xpi [2015-05-31]
FF Extension: Adblock Plus - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\vjzuwafv.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-25]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-10-08] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-10-10] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\ProgramData\Wondershare\Video Converter Ultimate\[removed] => not found
Chrome:
=======
CHR HomePage: Default -> hxxp://en.wikipedia.org/
CHR StartupUrls: Default -> "hxxp://www.hotmail.com/"
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-12]
CHR Extension: (Entanglement Web App) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd [2013-11-24]
CHR Extension: (Tab Expose) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ackpfhlmgjdjlohhjmbacaajbmkkklnp [2013-05-19]
CHR Extension: (Angry Birds) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2014-12-14]
CHR Extension: (TooManyTabs for Chrome) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\amigcgbheognjmfkaieeeadojiibgbdp [2014-06-11]
CHR Extension: (Google Docs) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-12]
CHR Extension: (Google Drive) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-25]
CHR Extension: (YouTube) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Sad Panda) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\bohapeiooecafommnlaiccilacgmkaoc [2014-08-30]
CHR Extension: (Adblock Plus) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-09-25]
CHR Extension: (Google Search) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-30]
CHR Extension: (Google Sheets) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-12]
CHR Extension: (Google Analytics Opt-out Add-on (by Google)) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\fllaojicojecljbmefodhfapmkghcbnh [2014-10-03]
CHR Extension: (IBA Opt-out (by Google)) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbiekjoijknlhijdjbaadobpkdhmoebb [2013-08-23]
CHR Extension: (Chuck Anderson) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gegkoiakifeoejnjkbnnojkkdoegeofp [2014-11-20]
CHR Extension: (Google Docs Offline) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-05]
CHR Extension: (AdBlock) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-10-18]
CHR Extension: (Desktop Notifications for Android) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\giicnncicnopjohcpamieklkiacdoeni [2015-08-29]
CHR Extension: (Avast Online Security) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-10-31]
CHR Extension: (TabJump - Intelligent Tab Navigator) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokofmgcicpnjchllaccgedmmmbbnbmf [2013-05-19]
CHR Extension: (Cookie Manager) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbnfbcpkiaganjpcanopcgeoehkleeck [2014-08-30]
CHR Extension: (Poppit!) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi [2014-07-17]
CHR Extension: (Ghostery) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2015-09-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-28]
CHR Extension: (Gmail) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR HKU\S-1-5-21-711289349-3085500364-3229847752-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Michael\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-19]
CHR HKU\S-1-5-21-711289349-3085500364-3229847752-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-01]
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-10-10] (AVAST Software)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4048280 2015-10-10] (Avast Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [238376 2015-07-23] (EasyAntiCheat Ltd)
R2 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [242216 2014-06-17] (Foxit Corporation)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1616440 2015-10-18] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6952504 2015-10-18] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155216 2015-07-23] (NVIDIA Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-05] (Intel Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] ()
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1871504 2015-07-23] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544592 2015-07-23] (NVIDIA Corporation)
R2 Seagate Dashboard Services; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe [16000 2014-09-17] (Seagate Technology LLC)
R2 Seagate MobileBackup Service; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe [157776 2014-09-17] (Seagate Technology LLC)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-10-10] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-10-10] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-10-10] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-10-10] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1049880 2015-10-10] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [448968 2015-10-10] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-10-10] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-10-10] (AVAST Software)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [30424 2015-04-17] (Sony Mobile Communications)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-09-01] (Intel Corporation)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] ()
R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [132656 2015-10-10] (AVAST Software)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-07-23] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47976 2015-07-02] (NVIDIA Corporation)
R3 pbfilter; C:\Program Files\PeerBlock\pbfilter.sys [22600 2014-01-14] ()
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 ssdevfactory; C:\Windows\System32\DRIVERS\ssdevfactory.sys [25088 2015-01-27] (SteelSeries ApS)
R3 sshid; C:\Windows\System32\DRIVERS\sshid.sys [42568 2015-02-26] (SteelSeries ApS)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [274336 2015-10-10] (Avast Software)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2015-11-06] ()
R3 ALSysIO; \??\C:\Users\Michael\AppData\Local\Temp\ALSysIO64.sys [X]
S3 BS680067079; \??\C:\Users\Michael\AppData\Local\Temp\NTFS.sys [X]
R3 WinRing0_1_2_0; \??\C:\Users\Michael\AppData\Local\Temp\tmpBFE5.tmp [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-07 08:12 - 2015-11-07 08:12 - 00034216 _____ C:\Users\Michael\Desktop\FRST.txt
2015-11-07 08:00 - 2015-11-07 08:00 - 00000000 ____D C:\Users\Michael\Desktop\FRST-OlderVersion
2015-11-07 07:23 - 2015-11-07 07:23 - 05481336 _____ (Avast Software s.r.o.) C:\Users\Michael\Desktop\avast_free_antivirus_setup_online_cnet.exe
2015-11-07 07:15 - 2015-11-07 07:15 - 05198336 _____ (AVAST Software) C:\Users\Michael\Desktop\aswMBR.exe
2015-11-06 13:46 - 2015-11-06 13:46 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2015-11-06 08:44 - 2015-11-06 08:44 - 00004096 _____ C:\ProgramData\sessionmsg_32.dll
2015-11-06 08:44 - 2015-11-06 08:44 - 00004096 _____ C:\ProgramData\igfxEM_32.exe
2015-11-06 08:43 - 2015-11-06 08:43 - 00090112 _____ C:\ProgramData\7B571D05.EX
2015-11-05 08:32 - 2015-11-05 08:32 - 00004096 _____ C:\ProgramData\openssl.exe
2015-11-05 08:31 - 2015-11-05 08:31 - 00004096 _____ C:\ProgramData\TabTip32.dll
2015-11-03 02:51 - 2015-11-03 02:51 - 00000000 ____D C:\Users\Michael\AppData\LocalLow\Obsidian Entertainment
2015-11-03 01:49 - 2015-11-03 02:47 - 00000000 ____D C:\Users\Michael\Documents\Tabletop RPGs
2015-11-02 09:24 - 2015-11-07 08:12 - 00000000 ____D C:\FRST
2015-11-01 17:48 - 2015-11-01 17:48 - 00000222 _____ C:\Users\Michael\Desktop\Pillars of Eternity.url
2015-11-01 17:10 - 2015-11-05 20:23 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-11-01 17:10 - 2015-11-01 17:10 - 00001768 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-11-01 17:10 - 2015-11-01 17:10 - 00000000 ____D C:\Users\Michael\AppData\Roaming\SUPERAntiSpyware.com
2015-11-01 17:10 - 2015-11-01 17:10 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2015-11-01 17:10 - 2015-11-01 17:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-11-01 17:07 - 2015-11-01 17:09 - 23758168 _____ (SUPERAntiSpyware) C:\Users\Michael\Desktop\SUPERAntiSpyware.exe
2015-11-01 17:04 - 2015-11-01 17:04 - 00022748 _____ C:\Users\Michael\Documents\cc_20151101_170432.reg
2015-11-01 11:21 - 2015-11-07 08:00 - 02198528 _____ (Farbar) C:\Users\Michael\Desktop\FRST64.exe
2015-10-31 17:23 - 2015-10-31 17:23 - 02924672 _____ (AVG Technologies) C:\Users\Michael\Desktop\AVG_Protection_Free_698.exe
2015-10-31 11:29 - 2015-10-31 11:29 - 00001055 _____ C:\Users\Michael\Desktop\TrojanHunter.lnk
2015-10-31 11:29 - 2015-10-31 11:29 - 00000000 ____D C:\ProgramData\TrojanHunter
2015-10-31 11:29 - 2015-10-31 11:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrojanHunter
2015-10-31 11:29 - 2015-10-31 11:29 - 00000000 ____D C:\Program Files (x86)\TrojanHunter
2015-10-31 10:57 - 2015-10-31 10:57 - 05693008 _____ (AVAST Software) C:\Users\Michael\Desktop\avast_free_antivirus_setup_online.exe
2015-10-31 06:21 - 2015-10-31 06:21 - 00005120 _____ C:\ProgramData\taskhost.exe
2015-10-31 06:20 - 2015-10-31 06:20 - 00004096 _____ C:\ProgramData\GheT3Z733AFC.dll
2015-10-31 06:17 - 2015-10-31 06:17 - 00004096 _____ C:\ProgramData\hTew6txG3AFC.dll
2015-10-31 06:16 - 2015-11-05 08:31 - 03550700 _____ C:\Windows\system32\CFG680067079
2015-10-31 05:50 - 2015-10-31 05:50 - 00450102 _____ C:\Users\Michael\AppData\Roaming\lqnqtgzk.exe
2015-10-31 05:49 - 2015-10-31 06:02 - 00000000 ____D C:\ProgramData\Linpal
2015-10-31 05:49 - 2015-10-31 05:50 - 00000000 ___HD C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}
2015-10-25 05:42 - 2015-10-31 05:59 - 00000000 ____D C:\Users\Michael\AppData\LocalLow\BitTorrent
2015-10-20 00:37 - 2015-10-20 00:37 - 00000000 ____D C:\Users\Michael\AppData\LocalLow\Thunder Lotus Games
2015-10-19 16:08 - 2015-10-19 16:47 - 1012445539 _____ C:\Users\Michael\Desktop\The Hobbit - An Unexpected Journey (2012).mp4
2015-10-19 15:52 - 2015-10-19 16:00 - 183041872 _____ C:\Users\Michael\Desktop\Wakfu Ova - 3.mp4
2015-10-19 15:34 - 2015-10-19 15:42 - 145438780 _____ C:\Users\Michael\Desktop\Wakfu Ova - 2.mp4
2015-10-19 15:27 - 2015-10-19 15:34 - 151873307 _____ C:\Users\Michael\Desktop\Wakfu Ova - 1.mp4
2015-10-18 16:37 - 2015-10-18 16:37 - 00000222 _____ C:\Users\Michael\Desktop\Jotun.url
2015-10-18 12:16 - 2015-11-07 06:46 - 00000000 ____D C:\Program Files\PeerBlock
2015-10-18 12:16 - 2015-10-18 12:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeerBlock
2015-10-17 02:18 - 2015-10-17 02:18 - 00000000 ____D C:\Users\Michael\AppData\Local\AnthophobiaSeptemberHotfix
2015-10-16 17:17 - 2015-10-16 17:17 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-10-14 18:20 - 2015-10-14 18:20 - 00002163 _____ C:\Users\Michael\Desktop\The Witcher® 3 - Wild Hunt.lnk
2015-10-11 07:25 - 2015-10-11 07:25 - 00000000 ____D C:\Users\Michael\AppData\Local\AnthophobiaSeptember
2015-10-10 06:23 - 2015-10-10 06:23 - 00378880 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-10-10 06:22 - 2015-10-10 06:22 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-07 08:09 - 2013-05-20 10:36 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Skype
2015-11-07 08:02 - 2015-06-15 20:45 - 00000926 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA.job
2015-11-07 08:00 - 2013-05-20 10:00 - 00621375 _____ C:\Users\Michael\Network_Meter_Data.js
2015-11-07 07:38 - 2013-05-19 21:13 - 02023512 _____ C:\Windows\WindowsUpdate.log
2015-11-07 07:33 - 2013-12-15 00:55 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA.job
2015-11-07 07:15 - 2013-05-19 21:33 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-07 07:13 - 2013-05-22 20:36 - 00000000 ____D C:\Users\Michael\AppData\Local\CrashDumps
2015-11-06 20:15 - 2013-05-19 21:33 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-06 13:58 - 2009-07-13 23:45 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-06 13:58 - 2009-07-13 23:45 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-06 13:50 - 2013-05-20 01:18 - 00000000 ___RD C:\Users\Michael\Dropbox
2015-11-06 13:49 - 2013-05-20 01:11 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Dropbox
2015-11-06 13:49 - 2013-05-19 22:36 - 00000000 ___RD C:\Users\Michael\Google Drive
2015-11-06 13:47 - 2014-06-11 15:11 - 00054919 _____ C:\Windows\setupact.log
2015-11-06 13:47 - 2013-05-20 00:12 - 00000000 ____D C:\Program Files (x86)\Steam
2015-11-06 13:46 - 2013-05-19 21:33 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys
2015-11-06 13:45 - 2015-04-10 16:32 - 00000000 ____D C:\ProgramData\NVIDIA
2015-11-06 13:45 - 2014-06-11 15:11 - 00437306 _____ C:\Windows\PFRO.log
2015-11-06 13:45 - 2013-05-20 01:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-06 13:45 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-06 13:33 - 2013-12-15 00:55 - 00000864 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core.job
2015-11-06 11:13 - 2015-06-15 20:45 - 00000874 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core.job
2015-11-05 16:43 - 2013-05-20 02:00 - 00000000 ____D C:\Users\Michael\AppData\Local\MediaMonkey
2015-11-05 15:03 - 2013-05-21 00:04 - 00000000 ____D C:\Users\Michael\AppData\Roaming\vlc
2015-11-05 14:38 - 2009-07-14 00:13 - 00783114 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-05 11:10 - 2013-05-23 18:26 - 00000000 ____D C:\Users\Michael\AppData\Roaming\CBLoader
2015-11-05 10:15 - 2014-08-31 08:36 - 00000000 ____D C:\Users\Michael\AppData\Local\Adobe
2015-11-05 10:09 - 2013-11-02 20:41 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-11-05 10:09 - 2013-11-02 20:41 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-05 09:31 - 2014-05-11 21:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-05 09:31 - 2013-05-20 01:20 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-11-05 09:31 - 2013-05-20 01:20 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-11-04 01:09 - 2013-05-20 11:20 - 00000030 _____ C:\Users\Michael\AppData\Roaming\Network Meter_Usage.ini
2015-11-03 02:40 - 2013-05-20 08:48 - 00001206 _____ C:\Users\Michael\Downloads\My Pictures.lnk
2015-11-02 00:45 - 2009-07-14 00:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-10-31 18:26 - 2013-05-19 21:34 - 00002284 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-10-31 18:04 - 2013-05-23 18:27 - 00000000 ____D C:\Users\Michael\AppData\Local\Wizards_of_the_Coast
2015-10-31 11:06 - 2015-03-10 18:14 - 00163748 _____ C:\Windows\DPINST.LOG
2015-10-31 10:58 - 2013-05-20 01:53 - 00000000 ____D C:\Users\Michael\AppData\Roaming\BitTorrent
2015-10-31 08:45 - 2015-05-19 00:07 - 00000000 ____D C:\Users\Michael\Documents\The Witcher 3
2015-10-30 17:06 - 2013-05-19 22:29 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-10-26 09:22 - 2015-05-13 10:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2015-10-25 06:48 - 2013-09-25 02:02 - 00000000 ____D C:\Users\Michael\AppData\Roaming\RenPy
2015-10-21 18:15 - 2013-05-19 22:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-10-19 15:15 - 2015-09-12 10:03 - 00000000 ____D C:\Users\Michael\AppData\Roaming\HandBrake
2015-10-16 06:33 - 2013-05-19 21:24 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-10-15 08:50 - 2014-09-20 05:37 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-10-10 06:23 - 2014-06-28 07:16 - 00153744 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-10-10 06:23 - 2014-06-28 07:16 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-10-10 06:23 - 2013-05-19 22:29 - 00448968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-10-10 06:23 - 2013-05-19 22:29 - 00274808 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-10-10 06:23 - 2013-05-19 22:29 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-10-10 06:23 - 2013-05-19 22:29 - 00090968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-10-10 06:23 - 2013-05-19 22:29 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-10-10 06:22 - 2015-08-26 11:55 - 00132656 _____ (AVAST Software) C:\Windows\system32\Drivers\ngvss.sys
2015-10-10 06:22 - 2013-05-19 22:29 - 01049880 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
==================== Files in the root of some directories =======
2013-05-20 09:55 - 2014-06-11 14:30 - 0000576 _____ () C:\Users\Michael\AppData\Roaming\All CPU MeterV3_Settings.ini
2009-07-13 18:19 - 2009-07-13 20:14 - 0577536 _____ () C:\Users\Michael\AppData\Roaming\BackUp680067079.exe
2013-05-24 09:13 - 2013-05-24 09:14 - 0000839 _____ () C:\Users\Michael\AppData\Roaming\Drives Meter_Settings.ini
2013-05-20 09:46 - 2015-04-10 16:43 - 0000294 _____ () C:\Users\Michael\AppData\Roaming\GPU MeterV2_Settings.ini
2015-10-31 05:50 - 2015-10-31 05:50 - 0450102 _____ () C:\Users\Michael\AppData\Roaming\lqnqtgzk.exe
2013-05-20 11:20 - 2015-11-04 01:09 - 0000030 _____ () C:\Users\Michael\AppData\Roaming\Network Meter_Usage.ini
2015-11-06 08:43 - 2015-11-06 08:43 - 0090112 _____ () C:\ProgramData\7B571D05.EX
2015-10-31 06:20 - 2015-10-31 06:20 - 0004096 _____ () C:\ProgramData\GheT3Z733AFC.dll
2015-10-31 06:17 - 2015-10-31 06:17 - 0004096 _____ () C:\ProgramData\hTew6txG3AFC.dll
2015-11-06 08:44 - 2015-11-06 08:44 - 0004096 _____ () C:\ProgramData\igfxEM_32.exe
2015-11-05 08:32 - 2015-11-05 08:32 - 0004096 _____ () C:\ProgramData\openssl.exe
2015-11-06 08:44 - 2015-11-06 08:44 - 0004096 _____ () C:\ProgramData\sessionmsg_32.dll
2015-11-05 08:31 - 2015-11-05 08:31 - 0004096 _____ () C:\ProgramData\TabTip32.dll
2015-10-31 06:21 - 2015-10-31 06:21 - 0005120 _____ () C:\ProgramData\taskhost.exe
Files to move or delete:
====================
C:\ProgramData\GheT3Z733AFC.dll
C:\ProgramData\hTew6txG3AFC.dll
C:\ProgramData\igfxEM_32.exe
C:\ProgramData\openssl.exe
C:\ProgramData\sessionmsg_32.dll
C:\ProgramData\TabTip32.dll
C:\ProgramData\taskhost.exe
C:\Users\Michael\Network_Meter_Data.js
Some files in TEMP:
====================
C:\Users\Michael\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpx2hzqn.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-10-31 09:12
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-11-2015
Ran by [removed] (2015-11-07 08:12:55)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium (X64) (2013-05-20 02:12:41)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-711289349-3085500364-3229847752-500 - Administrator - Disabled)
Guest (S-1-5-21-711289349-3085500364-3229847752-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-711289349-3085500364-3229847752-1023 - Limited - Enabled)
Michael (S-1-5-21-711289349-3085500364-3229847752-1000 - Administrator - Enabled) => C:\Users\Michael
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Abyss Odyssey (HKLM-x32\…\Steam App 255070) (Version: - ACE Team)
Acrobat.com (HKLM-x32\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1.377 - Adobe Systems Incorporated)
Acrobat.com (x32 Version: 0.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.0.4990 - Adobe Systems Inc.)
Adobe Flash Player 19 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 19.0.0.226 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
AGEIA PhysX v7.11.13 (HKLM-x32\…\{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}) (Version: 7.11.13 - AGEIA Technologies, Inc.)
Alan Wake (HKLM-x32\…\Steam App 108710) (Version: - Remedy Entertainment)
Anodyne (HKLM-x32\…\Steam App 234900) (Version: - Sean Hogan and Jonathan Kittaka)
Apple Application Support (32-bit) (HKLM-x32\…\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{06A333EA-4E9D-4848-865F-FE5A1E12AB30}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.10.1.0 - Asmedia Technology)
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\…\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 1.3.1.000 - Asmedia Technology)
Assassin's Creed IV Black Flag (HKLM-x32\…\Steam App 242050) (Version: - Ubisoft Montreal)
Avast Free Antivirus (HKLM-x32\…\avast) (Version: 10.4.2233 - AVAST Software)
Bionic Commando Rearmed (HKLM-x32\…\Steam App 21680) (Version: - GRIN)
BitTorrent (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\BitTorrent) (Version: 7.9.5.41203 - BitTorrent Inc.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.8.5.1 - Broadcom Corporation)
Brütal Legend (HKLM-x32\…\Steam App 225260) (Version: - Double Fine Productions)
Bully: Scholarship Edition (HKLM-x32\…\Steam App 12200) (Version: - Rockstar New England)
Canon IJ Network Scan Utility (HKLM-x32\…\Canon_IJ_Network_Scan_UTILITY) (Version: - )
Canon IJ Network Tool (HKLM-x32\…\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.)
Canon MP Navigator EX 3.1 (HKLM-x32\…\MP Navigator EX 3.1) (Version: - )
Canon MX340 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX340_series) (Version: - Canon Inc.)
Castlevania: Lords of Shadow – Mirror of Fate HD (HKLM-x32\…\Steam App 282530) (Version: - MercurySteam)
Castlevania: Lords of Shadow - Ultimate Edition (HKLM-x32\…\Steam App 234080) (Version: - MercurySteam - Climax Studios)
CCleaner (HKLM\…\CCleaner) (Version: 4.09 - Piriform)
CDisplayEx 1.10.29 (HKLM\…\CDisplayEx_is1) (Version: - Progdigy Software S.A.R.L.)
ChromecastApp (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\{079ede36-133d-44b0-8053-c7c1fa8d2e0d}_is1) (Version: 1.5.1693.0 - Google Inc.)
ComicRack v0.9.156 (HKLM\…\ComicRack) (Version: v0.9.156 - cYo Soft)
Core Temp version 0.99.7 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 0.99.7 - Arthur Liberman)
CPUID CPU-Z 1.63.0 (HKLM\…\CPUID CPU-Z_is1) (Version: - )
Creation Kit (HKLM-x32\…\Steam App 202480) (Version: - bgs.bethsoft.com)
Creative ALchemy (HKLM-x32\…\ALchemy) (Version: 1.43 - Creative Technology Limited)
Creative Audio Control Panel (HKLM-x32\…\AudioCS) (Version: 2.56 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\…\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
CutePDF Writer 3.0 (HKLM\…\CutePDF Writer Installation) (Version: 3.0 - CutePDF.com)
Darkest Dungeon (HKLM-x32\…\Steam App 262060) (Version: - Red Hook Studios)
DDS Viewer (HKLM-x32\…\{707333E0-C796-4E2D-B0DA-5A429706C361}_is1) (Version: - IdeaMK)
Defraggler (HKLM\…\Defraggler) (Version: 2.16 - Piriform)
Deus Ex: Human Revolution - The Missing Link (HKLM-x32\…\Steam App 201280) (Version: - Eidos Montreal)
Deus Ex: Human Revolution (HKLM-x32\…\Steam App 28050) (Version: - Eidos Montreal)
Dishonored (HKLM-x32\…\Steam App 205100) (Version: - Arkane Studios)
Divinity: Original Sin (HKLM-x32\…\Steam App 230230) (Version: - Larian Studios)
Don't Starve (HKLM-x32\…\Steam App 219740) (Version: - )
Don't Starve Together Beta (HKLM-x32\…\Steam App 322330) (Version: - Klei Entertainment)
Driver Sweeper version 3.1.0 (HKLM-x32\…\{5A67D2EA-FB70-4033-A6F3-606AD85B2015}_is1) (Version: 3.1.0 - Phyxion.net)
Dropbox (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Dropbox) (Version: 3.10.8 - Dropbox, Inc.)
Dungeons & Dragons: Chronicles of Mystara (HKLM-x32\…\Steam App 229480) (Version: - Iron Galaxy Studios)
Endless Space (HKLM-x32\…\Steam App 208140) (Version: - Amplitude Studios)
Evoland (HKLM-x32\…\Steam App 233470) (Version: - Shiro Games)
f.lux (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\Flux) (Version: - )
Far Cry® 3 Blood Dragon (HKLM-x32\…\Steam App 233270) (Version: - Ubisoft Montreal)
FEZ (HKLM-x32\…\Steam App 224760) (Version: - Polytron Corporation)
Five Nights at Freddy's (HKLM-x32\…\Steam App 319510) (Version: - Scott Cawthon)
Foxit Cloud (HKLM-x32\…\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.5.129.617 - Foxit Corporation)
Foxit PhantomPDF Standard (HKLM-x32\…\{A652C696-8733-4681-820C-95465A19512B}) (Version: 6.2.1.618 - Foxit Corporation)
Foxit Reader (HKLM-x32\…\Foxit Reader_is1) (Version: 6.2.3.815 - Foxit Corporation)
FTL: Faster Than Light (HKLM-x32\…\Steam App 212680) (Version: - Subset Games)
Game of Thrones - A Telltale Games Series (HKLM-x32\…\Steam App 330840) (Version: - Telltale Games)
Gnomoria (HKLM-x32\…\Steam App 224500) (Version: - Robotronic Games)
GOG Galaxy (HKLM-x32\…\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 46.0.2490.80 - Google Inc.)
Google Drive (HKLM-x32\…\{9C350701-AC04-48BA-A435-BD5E0D82897E}) (Version: 1.25.0523.2491 - Google, Inc.)
Google Talk Plugin (HKLM-x32\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
Guacamelee! Gold Edition (HKLM-x32\…\Steam App 214770) (Version: - DrinkBox Studios)
Guild Wars 2 (HKLM-x32\…\Guild Wars 2) (Version: - NCsoft Corporation, Ltd.)
HandBrake 0.10.2 (HKLM-x32\…\HandBrake) (Version: 0.10.2 - )
Hitman: Absolution (HKLM-x32\…\Steam App 203140) (Version: - Square Enix)
Hotline Miami (HKLM-x32\…\Steam App 219150) (Version: - Dennaton Games)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1281 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.6.0.1030 - Intel Corporation)
Intel(R) Smart Connect Technology 2.0 x64 (HKLM\…\{D1B033E8-A077-4B0D-9831-5798E19E861E}) (Version: 2.0.1083.0 - Intel)
Intel(R) Update Manager (HKLM-x32\…\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation)
iTunes (HKLM\…\{5AC8E601-667F-4CA0-90D8-B25E1C4B3387}) (Version: 12.2.2.25 - Apple Inc.)
Java 7 Update 21 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417021FF}) (Version: 7.0.210 - Oracle)
Java 7 Update 65 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.650 - Oracle)
Jotun (HKLM-x32\…\Steam App 323580) (Version: - Thunder Lotus Games)
King of Dragon Pass (HKLM-x32\…\Steam App 352220) (Version: - A Sharp, LLC)
Left 4 Dead 2 (HKLM-x32\…\Steam App 550) (Version: - Valve)
Legend of Dungeon (HKLM-x32\…\Steam App 238280) (Version: - )
Legend of Grimrock (HKLM-x32\…\Steam App 207170) (Version: - Almost Human Games)
Livestream Procaster (HKLM-x32\…\{68E4C751-272B-44E1-94C7-4E1FDC40F7DA}) (Version: 20.3.25 - Procaster)
Logitech Gaming Software 8.53 (HKLM\…\Logitech Gaming Software) (Version: 8.53.186 - Logitech Inc.)
LOOT (HKLM-x32\…\LOOT) (Version: 0.5.0 - LOOT Development Team)
Mad Max (HKLM-x32\…\Steam App 234140) (Version: - Avalanche Studios)
Mark of the Ninja (HKLM-x32\…\Steam App 214560) (Version: - Klei Entertainment)
Mars: War Logs (HKLM-x32\…\Steam App 232750) (Version: - Spiders)
MediaMonkey 3.0 (HKLM-x32\…\MediaMonkey_is1) (Version: 3.0 - Ventis Media Inc.)
Microsoft .NET Framework 4.5.1 RC (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50861 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\…\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Middle-earth: Shadow of Mordor (HKLM-x32\…\Steam App 241930) (Version: - Monolith Productions, Inc.)
Monaco (HKLM-x32\…\Steam App 113020) (Version: - Pocketwatch Games)
Mount & Blade: Warband (HKLM-x32\…\Steam App 48700) (Version: - Taleworlds Entertainment)
Mozilla Firefox 42.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 42.0 - Mozilla)
Nexus Mod Manager (HKLM\…\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.49.1 - Black Tree Gaming)
Nidhogg (HKLM-x32\…\Steam App 94400) (Version: - Messhof)
NVIDIA 3D Vision Controller Driver 352.65 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 353.62 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.62 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.5.12.11 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.12.11 - NVIDIA Corporation)
NVIDIA Graphics Driver 353.62 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.62 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.3 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Octodad: Dadliest Catch (HKLM-x32\…\Steam App 224480) (Version: - Young Horses)
Oddworld: Stranger's Wrath HD (HKLM-x32\…\Steam App 15750) (Version: - )
OpenAL (HKLM-x32\…\OpenAL) (Version: - )
OpenOffice 4.1.1 (HKLM-x32\…\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
Orcs Must Die! (HKLM-x32\…\Steam App 102600) (Version: - )
Papers, Please (HKLM-x32\…\Steam App 239030) (Version: - 3909)
PAYDAY 2 Beta (HKLM-x32\…\Steam App 246210) (Version: - )
PeerBlock 1.2 (r693) (HKLM\…\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.2.0.693 - PeerBlock, LLC)
Pillars of Eternity (HKLM-x32\…\Steam App 291650) (Version: - Obsidian Entertainment)
Prison Architect (HKLM-x32\…\Steam App 233450) (Version: - Introversion Software)
Psychonauts (HKLM-x32\…\Steam App 3830) (Version: - Double Fine Productions)
QuickTime 7 (HKLM-x32\…\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)
Raptr (HKLM-x32\…\Raptr) (Version: - )
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6559 - Realtek Semiconductor Corp.)
Recettear: An Item Shop's Tale (HKLM-x32\…\Steam App 70400) (Version: - EasyGameStation)
Recuva (HKLM\…\Recuva) (Version: 1.51 - Piriform)
Remember Me (HKLM-x32\…\Steam App 228300) (Version: - DONTNOD Entertainment)
Reus (HKLM-x32\…\Steam App 222730) (Version: - Abbey Games)
Revenge of the Titans (HKLM-x32\…\Steam App 93200) (Version: - Puppygames)
Rogue Legacy (HKLM-x32\…\Steam App 241600) (Version: - Cellar Door Games)
RollerCoaster Tycoon 3: Platinum! (HKLM-x32\…\Steam App 2700) (Version: - Frontier)
Rust (HKLM-x32\…\Steam App 252490) (Version: - Facepunch Studios)
Saints Row IV (HKLM-x32\…\Steam App 206420) (Version: - Deep Silver Volition)
Seagate Dashboard (HKLM-x32\…\{F1D8690F-06B3-4100-9949-398EA253AC61}) (Version: 3.2.1802.2 - Seagate)
Shadowrun Returns (HKLM-x32\…\Steam App 234650) (Version: - Harebrained Schemes)
Shadowrun: Dragonfall - Director's Cut (HKLM-x32\…\Steam App 300550) (Version: - Harebrained Schemes)
SHIELD Streaming (Version: 4.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.5.12.11 - NVIDIA Corporation) Hidden
Shovel Knight (HKLM-x32\…\Steam App 250760) (Version: - Yacht Club Games)
SimCity 4 Deluxe (HKLM-x32\…\Steam App 24780) (Version: - Maxis)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation)
Skype™ 7.8 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
Sleeping Dogs: Definitive Edition (HKLM-x32\…\Steam App 307690) (Version: - United Front Games)
Solar 2 (HKLM-x32\…\Steam App 97000) (Version: - Murudai)
Sony Mobile Update Engine (HKLM-x32\…\Update Engine) (Version: 2.15.12.201508241237 - Sony Mobile Communications Inc.)
Sony PC Companion 2.10.289 (HKLM-x32\…\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.289 - Sony)
Starbound (HKLM-x32\…\Steam App 211820) (Version: - )
Stardock Fences 2 (HKLM-x32\…\Stardock Fences 2) (Version: 2.10 - Stardock Software, Inc.)
State of Decay (HKLM-x32\…\Steam App 241540) (Version: - Undead Labs)
Steam (HKLM-x32\…\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
SteelSeries Engine 3.3.5 (HKLM\…\SteelSeries Engine 3) (Version: 3.3.5 - SteelSeries ApS)
Styx: Master of Shadows (HKLM-x32\…\Steam App 242640) (Version: - Cyanide Studio)
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1208 - SUPERAntiSpyware.com)
Surgeon Simulator 2013 (HKLM-x32\…\Steam App 233720) (Version: - Bossa Studios)
TeamSpeak 3 Client (HKLM-x32\…\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH)
Terraria (HKLM-x32\…\Steam App 105600) (Version: - )
Teslagrad Demo (HKLM-x32\…\Steam App 254560) (Version: - Rain Games)
The Banner Saga (HKLM-x32\…\Steam App 237990) (Version: - Stoic)
The Elder Scrolls V: Skyrim (HKLM-x32\…\Steam App 72850) (Version: - Bethesda Game Studios)
The Forest (HKLM-x32\…\Steam App 242760) (Version: - Endnight Games Ltd)
The Incredible Adventures of Van Helsing (HKLM-x32\…\Steam App 215530) (Version: - NeocoreGames)
The Long Dark (HKLM-x32\…\Steam App 305620) (Version: - Hinterland Studio Inc.)
The Secret World (HKLM-x32\…\Steam App 215280) (Version: - Funcom)
The Stomping Land (HKLM-x32\…\Steam App 263440) (Version: - SuperCrit)
The Walking Dead (HKLM-x32\…\Steam App 207610) (Version: - )
The Walking Dead: Season Two (HKLM-x32\…\Steam App 261030) (Version: - Telltale Games)
The Witcher 2 (HKLM-x32\…\{F0A209B7-7F85-4BDD-8F1F-B98EEAD9E04B}) (Version: 1.00.0000 - CD Projekt Red)
The Witcher 3 - Wild Hunt (HKLM-x32\…\1207664643_is1) (Version: 1.0.11.0 - GOG.com)
The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\…\Free DLC program (16 DLC)_is1) (Version: 1.0.10.0 - GOG.com)
The Witcher 3: Wild Hunt - Hearts of Stone (HKLM-x32\…\Hearts of Stone_is1) (Version: 1.0.10.0 - GOG.com)
They Bleed Pixels (HKLM-x32\…\Steam App 211260) (Version: - Spooky Squid Games Inc.)
Tiny Barbarian DX (HKLM-x32\…\Steam App 253350) (Version: - StarQuail Games)
Transistor (HKLM-x32\…\Steam App 237930) (Version: - Supergiant Games)
TrojanHunter 6.0 (HKLM-x32\…\TrojanHunter_is1) (Version: 6.0 - Bytelayer AB)
TrueCrypt (HKLM-x32\…\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation)
Unity Web Player (HKU\S-1-5-21-711289349-3085500364-3229847752-1000\…\UnityWebPlayer) (Version: - Unity Technologies ApS)
Universe Sandbox (HKLM-x32\…\Steam App 72200) (Version: - )
Uplay (HKLM-x32\…\Uplay) (Version: 4.0 - Ubisoft)
Vessel (HKLM-x32\…\Steam App 108500) (Version: - Strange Loop Games)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
Westerado: Double Barreled (HKLM-x32\…\Steam App 275200) (Version: - Ostrich Banditos)
Wrye Bash (HKLM-x32\…\Wrye Bash) (Version: 3.0.4.3 - Wrye & Wrye Bash Development Team)
XCOM: Enemy Unknown (HKLM-x32\…\Steam App 200510) (Version: - Firaxis Games)
YTD Video Downloader 3.9.6 (HKLM-x32\…\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 3.9.6 - GreenTree Applications SRL) <==== ATTENTION
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-711289349-3085500364-3229847752-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.)
==================== Restore Points =========================
03-11-2015 00:00:01 Scheduled Checkpoint
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0D4A090F-45E6-49F6-8E99-D4143E5C7CF4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd)
Task: {0F957854-886F-4E17-A16E-EC9963D4F94D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {15A32B57-F7EC-4074-8CF3-DBE82298BCA4} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {342162CA-FE1A-409B-B90D-165197BEF325} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {3A470D43-598A-4DA7-85E0-1F91C6FC20E1} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-15] (Dropbox, Inc.)
Task: {3FD19CAF-79FA-4128-8ADE-14ED21F59E7B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {51F539DE-1094-42FA-B9EB-E4C5BDB231BF} - System32\Tasks\Seagate_Install_Launch => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Dashboard.exe [2014-09-17] (Seagate Technology LLC)
Task: {57949803-E7D2-42CE-B7DB-DBBBB72C01AD} - System32\Tasks\avastBCLRestartS-1-5-21-711289349-3085500364-3229847752-1000 => Chrome.exe
Task: {58B115B6-5368-48DE-AE63-51104E35C1F2} - System32\Tasks\PCMeter\Startup => C:\Users\Michael\Downloads\Windows Gadgets\PCMeterV0.3.exe [2013-03-16] (AddGadgets)
Task: {5C3CF947-1A17-4C66-A4F9-FCC2F6B0E13C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {74E23625-8490-4549-AF10-B725E1D84562} - System32\Tasks\Michael DBAgent 2 0 => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [2014-09-17] (Seagate Technology LLC)
Task: {8DCBEDAB-8C7E-4FDB-AB91-B732F25CEBDE} - System32\Tasks\{3293F118-F9C1-4AE8-A5E9-8FC2FB983B1E} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver;=5.1.0.112.259&LastError;=404
Task: {C878D5D1-3D09-4B73-91A9-1F6548A3C935} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-15] (Dropbox, Inc.)
Task: {E00BC2BE-876C-4E47-AEED-34B14441164F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {EE7B33BE-B506-4785-93AB-67F2B2490C0C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {F5DA27E1-A8AF-4E28-AB21-2BDC29352C3E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-10-10] (AVAST Software)
Task: {FF866CD3-75FF-4980-A7D8-9AE602EC7A52} - System32\Tasks\Core Temp Autostart => C:\Program Files\Core Temp\Core Temp.exe [2010-07-02] ()
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core.job => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA.job => C:\Users\Michael\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000Core.job => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-711289349-3085500364-3229847752-1000UA.job => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2013-05-20 01:29 - 2012-10-04 18:49 - 00087152 _____ () C:\Windows\System32\cpwmon64.dll
2015-04-10 16:31 - 2015-07-22 20:31 - 00116368 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-05-20 09:42 - 2010-07-02 12:52 - 00530448 _____ () C:\Program Files\Core Temp\Core Temp.exe
2012-02-09 15:26 - 2012-02-09 15:26 - 00133632 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
2012-02-09 15:26 - 2012-02-09 15:26 - 00048128 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll
2012-02-09 15:26 - 2012-02-09 15:26 - 00036864 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetDetect.dll
2014-07-02 16:54 - 2014-07-02 16:54 - 00866584 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2014-07-02 16:59 - 2014-07-02 16:59 - 01050904 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-07-02 16:54 - 2014-07-02 16:54 - 00059160 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2014-07-02 16:59 - 2014-07-02 16:59 - 00242456 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2015-10-31 06:20 - 2015-10-31 06:20 - 00004096 _____ () C:\ProgramData\GheT3Z733AFC.dll
2015-11-05 08:32 - 2015-11-05 08:32 - 00004096 _____ () C:\ProgramData\openssl.exe
2015-11-06 08:44 - 2015-11-06 08:44 - 00004096 _____ () C:\ProgramData\igfxEM_32.exe
2013-05-20 09:41 - 2013-05-20 09:41 - 00012520 _____ () C:\Users\Michael\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\CoreTempReader.dll
2013-05-20 09:41 - 2013-05-20 09:41 - 00015080 _____ () C:\Users\Michael\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\GetCoreTempInfoNET.dll
2013-05-20 09:41 - 2013-05-20 09:41 - 00014056 _____ () C:\Users\Michael\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.6.gadget\SystemInfo.dll
2015-03-10 18:13 - 2015-06-10 10:13 - 00113024 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
2015-03-05 13:04 - 2015-03-05 13:04 - 18305024 _____ () C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe
2015-03-05 11:44 - 2015-03-05 11:44 - 00047616 _____ () C:\Program Files\SteelSeries\SteelSeries Engine 3\x2api.dll
2015-02-13 04:20 - 2015-02-13 04:20 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2015-05-15 15:27 - 2015-05-15 15:27 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-05-18 07:55 - 2015-07-23 23:22 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2013-04-23 17:30 - 2015-10-05 11:18 - 00778752 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-01-19 15:21 - 2015-07-03 11:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-01-19 15:21 - 2015-07-03 11:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-01-19 15:21 - 2015-07-03 11:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2014-05-21 17:32 - 2015-11-05 11:44 - 02541648 _____ () C:\Program Files (x86)\Steam\video.dll
2014-08-28 16:50 - 2015-09-23 19:33 - 02549248 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2014-08-28 16:51 - 2015-09-23 19:33 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2014-08-28 16:51 - 2015-09-23 19:33 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2014-08-28 16:51 - 2015-09-23 19:33 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2014-08-28 16:51 - 2015-09-23 19:33 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2013-05-03 14:35 - 2015-11-05 11:44 - 00806992 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2015-07-22 07:06 - 2015-11-03 17:00 - 00201728 _____ () C:\Program Files (x86)\Steam\bin\openvr_api.dll
2015-03-10 18:13 - 2012-04-30 10:57 - 00039936 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll
2015-03-10 18:13 - 2014-12-04 14:18 - 00241152 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll
2011-07-07 13:54 - 2011-07-07 13:54 - 00233984 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\Report.dll
2015-03-10 18:13 - 2013-05-20 11:58 - 00620718 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\sqlite3.dll
2015-03-23 18:19 - 2015-03-23 18:19 - 02620416 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\libxt.dll
2015-03-10 18:13 - 2015-04-21 12:22 - 00053248 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\VObject.dll
2015-07-23 08:21 - 2015-07-23 08:21 - 00802304 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PhoneUpdate.dll
2013-05-19 22:00 - 2009-02-06 17:52 - 00073728 _____ () C:\Windows\SysWOW64\CmdRtr.DLL
2013-05-19 22:00 - 2009-07-10 08:07 - 00166912 _____ () C:\Windows\SysWOW64\APOMngr.DLL
2015-11-06 13:49 - 2015-11-06 13:49 - 00071168 _____ () c:\users\michael\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpx2hzqn.dll
2015-03-04 16:45 - 2015-09-23 18:07 - 00012800 _____ () C:\Users\Michael\AppData\Roaming\Dropbox\bin\QtQuick.2\qtquick2plugin.dll
2015-03-04 16:45 - 2015-09-23 18:07 - 00779776 _____ () C:\Users\Michael\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-07-30 05:11 - 2015-09-23 18:07 - 00056320 _____ () C:\Users\Michael\AppData\Roaming\Dropbox\bin\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-03-04 16:45 - 2015-09-23 18:07 - 00012288 _____ () C:\Users\Michael\AppData\Roaming\Dropbox\bin\QtQuick\Window.2\windowplugin.dll
2015-11-06 13:47 - 2015-11-06 13:47 - 00098816 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32api.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00110080 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\pywintypes27.dll
2015-11-06 13:47 - 2015-11-06 13:47 - 00364544 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\pythoncom27.dll
2015-11-06 13:47 - 2015-11-06 13:47 - 00046080 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_socket.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 01208320 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_ssl.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00320512 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32com.shell.shell.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00776704 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_hashlib.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 01176576 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._core_.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00806400 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._gdi_.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00816128 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._windows_.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 01067008 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._controls_.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00733184 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._misc_.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00682496 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\pysqlite2._sqlite.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00088064 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_ctypes.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00119808 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32file.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00108544 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32security.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00007168 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\hashobjs_ext.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00070144 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\usb_ext.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00167936 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32gui.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00018432 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32event.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00128512 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_elementtree.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00127488 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\pyexpat.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00013824 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\common.time34.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00036864 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_psutil_windows.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00038912 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32inet.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00011264 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32crypt.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00077312 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._html2.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00027136 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_multiprocessing.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00020480 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\_yappi.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00035840 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32process.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00686080 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\unicodedata.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00123392 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._wizard.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00024064 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32pipe.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00010240 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\select.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00025600 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32pdh.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00525640 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\windows._lib_cacheinvalidation.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00017408 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32profile.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00022528 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\win32ts.pyd
2015-11-06 13:47 - 2015-11-06 13:47 - 00078848 _____ () C:\Users\Michael\AppData\Local\Temp\_MEI46762\wx._animate.pyd
2013-03-26 15:16 - 2015-10-08 17:20 - 45010208 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2013-05-19 21:26 - 2012-07-18 05:55 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2015-11-05 10:09 - 2015-11-05 10:09 - 17599688 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-711289349-3085500364-3229847752-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: ehRecvr => 3
MSCONFIG\Services: ehSched => 3
MSCONFIG\Services: IAStorDataMgrSvc => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BitTorrent => "C:\Users\Michael\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
MSCONFIG\startupreg: Chrome => C:\PROGRA~3\taskhost.exe
MSCONFIG\startupreg: DelaypluginInstall => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
MSCONFIG\startupreg: GalaxyClient => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Raptr => C:\PROGRA~2\Raptr\raptrstub.exe –startup
MSCONFIG\startupreg: Wondershare Helper Compact.exe => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{05E4EBCA-C57B-40F1-9177-185411F87E77}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{914BEBC3-B713-4A32-90E7-672B4C49D402}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A0B47EE0-EBB5-44D4-80F4-3C6EC767A64C}] => (Allow) C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{38EB4404-D701-4EC7-8BF9-45DE9642A14C}] => (Allow) C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{C383AABC-B8C3-481A-8110-76D5088AE1ED}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mars War Logs\MarsWarLogs.exe
FirewallRules: [{8EAC8079-443B-4F00-BE7B-FEAB7BCA7C06}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mars War Logs\MarsWarLogs.exe
FirewallRules: [{EA85749C-AC6B-4A3B-855E-D67B074B2EA0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{8A7AC821-160F-4400-AAF8-E347F1AA6C79}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{A2730E6D-2A20-40F6-A3FE-DAB8E5377F0B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{AA37EF3F-996E-4AAC-A6B5-0F038107E4E3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{AB07BE16-CAFA-4E5C-953C-1655B5766C6F}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{E94A15CB-C4F5-4F13-9D51-E7EA9F77D6CF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Universe Sandbox\Universe Sandbox.exe
FirewallRules: [{06ABF9D4-83CE-4C9E-B8DF-9C651D7975DC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Universe Sandbox\Universe Sandbox.exe
FirewallRules: [{4CD1733C-B92A-4741-9881-D563CAFD8BF9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [{2BEFE624-91A1-4D74-87AC-A84270D20B61}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deus Ex - Human Revolution\dxhr.exe
FirewallRules: [TCP Query User{860B1408-7727-4A0B-8A0C-D715525F7E12}C:\program files (x86)\guild wars 2\gw2.exe] => (Allow) C:\program files (x86)\guild wars 2\gw2.exe
FirewallRules: [UDP Query User{35FC3E26-8EAF-4D11-8095-02C8F58779CC}C:\program files (x86)\guild wars 2\gw2.exe] => (Allow) C:\program files (x86)\guild wars 2\gw2.exe
FirewallRules: [{2777BC3B-CD1F-4601-A020-19A001B994D5}] => (Block) C:\program files (x86)\guild wars 2\gw2.exe
FirewallRules: [{F7E26BBD-D5C7-4A4C-9DA3-44498E066615}] => (Block) C:\program files (x86)\guild wars 2\gw2.exe
FirewallRules: [TCP Query User{3EB9D856-069D-41EF-AF6C-25C6552E905A}C:\program files\comicrack\comicrack.exe] => (Allow) C:\program files\comicrack\comicrack.exe
FirewallRules: [UDP Query User{2D9C4F63-2E51-481A-9793-DDD38B0B39C8}C:\program files\comicrack\comicrack.exe] => (Allow) C:\program files\comicrack\comicrack.exe
FirewallRules: [{CADF2C72-2D00-4C2A-B964-838F9F13D049}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stranger's Wrath\Launcher.exe
FirewallRules: [{68174B03-A249-4BAC-ADFE-9224BEECA6F5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stranger's Wrath\Launcher.exe
FirewallRules: [TCP Query User{518B102D-0A33-4B42-B3E2-9F770CCC9B42}C:\program files (x86)\the witcher 2\bin\witcher2.exe] => (Allow) C:\program files (x86)\the witcher 2\bin\witcher2.exe
FirewallRules: [UDP Query User{740DC195-6EC6-4BF5-AEB1-17B5C1F1D9F2}C:\program files (x86)\the witcher 2\bin\witcher2.exe] => (Allow) C:\program files (x86)\the witcher 2\bin\witcher2.exe
FirewallRules: [{C4D20F6D-32F7-4041-A1CE-4FE76FB14115}] => (Block) C:\program files (x86)\the witcher 2\bin\witcher2.exe
FirewallRules: [{34ED931F-4B87-4BDF-AB41-F65DCE20201A}] => (Block) C:\program files (x86)\the witcher 2\bin\witcher2.exe
FirewallRules: [{FAC03BA6-EB65-454A-BD4E-76B6F4C01260}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman Absolution\HMA.exe
FirewallRules: [{552AA8D9-D665-4C27-BDA1-716A8F8D34B7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hitman Absolution\HMA.exe
FirewallRules: [{23CC9AB4-82C0-4378-AAA0-57EA90C809D1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Orcs Must Die!\Build\release\OrcsMustDie.exe
FirewallRules: [{372B9023-5063-4EDD-9107-B44C7051B9AB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Orcs Must Die!\Build\release\OrcsMustDie.exe
FirewallRules: [{4CD95026-7545-4216-8671-ADBC3940000F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{3E89A720-4CF7-408C-92E9-DFCDEB36BB99}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{248FF237-F533-4AAF-954F-89DCEFDBF555}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DXHRML\dxhrml.exe
FirewallRules: [{05A1EB00-A348-4DDA-AB69-5C5040E54069}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DXHRML\dxhrml.exe
FirewallRules: [{6D2BC6AD-FAA5-4EA1-B1AD-35CF75EC259F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{9372880A-9C54-4560-A1BA-611E2C25C3CE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{E1DB4F9D-3F63-4889-AC94-869F5F6825BE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Solar 2\Solar2.exe
FirewallRules: [{41D8264F-30D2-45E5-831C-6603EF7D18CC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Solar 2\Solar2.exe
FirewallRules: [{7B4DEC19-6D34-41EB-A91D-5E61F503A0CE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{D81B03B2-F0A2-47FB-B258-01D7F3EDFAA0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{D5498855-7030-461F-A63C-B6BD3EA61597}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SimCity 4 Deluxe\Apps\SimCity 4.exe
FirewallRules: [{6127BBA0-AA25-44A2-AFC1-FDE11B3D3A4D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SimCity 4 Deluxe\Apps\SimCity 4.exe
FirewallRules: [{0AFBEFBD-1095-4DB5-9D3B-EEBE9A9D3A55}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SimCity 4 Deluxe\Support\EA Help\Electronic_Arts_Technical_Support.htm
FirewallRules: [{DD104EFF-F941-40FA-9114-F0D433F337A3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SimCity 4 Deluxe\Support\EA Help\Electronic_Arts_Technical_Support.htm
FirewallRules: [{9D876EB8-6CBE-4C51-B15C-2ED7A7963968}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{B472472A-30BA-438F-87C5-FC6419F168C3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{40E8FAD2-1760-4655-BD7F-1DB46E702333}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Vessel\Vessel.exe
FirewallRules: [{183D35CA-6AB8-4C71-B962-0ECFAE37380B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Vessel\Vessel.exe
FirewallRules: [{5671CADD-778A-46CD-909B-00E18A31C200}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [{35D6C2A6-D006-41CA-AC11-BFD5F863D720}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [TCP Query User{AD0B3509-FE5B-4995-BAD6-CB4D0F560226}C:\users\michael\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\michael\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{4920CAF0-9327-4573-88BB-3E36DF24DDFE}C:\users\michael\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\michael\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{A8F7925F-5696-4E29-9711-78718EFB650A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Evoland\Evoland.exe
FirewallRules: [{7D6083C0-7619-456A-8E23-2798484086CA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Evoland\Evoland.exe
FirewallRules: [{8DBC9887-DBC5-44C3-B4FD-A807FA205424}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{861839DF-BB83-4A30-B478-7D903A051310}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{ABC9CD25-F127-42EC-A843-C40BD33EC16D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{345709F5-0D46-4EF7-9A28-B9DD01FE7272}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{74B30CD5-A13E-42C5-A0B1-5A6CDE80CEDC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PAYDAY 2 Beta\payday2_win32_release.exe
FirewallRules: [{B3A38D75-4C70-43EB-ABC8-00C4777584F9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PAYDAY 2 Beta\payday2_win32_release.exe
FirewallRules: [{739F455D-7B73-4BDA-A7EC-E048CCA3C39C}] => (Allow) C:\Users\Michael\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{F436C41C-1AE2-4C99-AF32-1670B03BDEA2}] => (Allow) C:\Users\Michael\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{998522F3-CFED-4981-B5B8-BB67224CDE55}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{D6094518-E50F-4FF4-A1A8-2F9121B4C825}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{591A937E-B916-4A83-A765-FA989A974E5D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Recettear\recettear.exe
FirewallRules: [{3E89B2A3-E04B-4C5D-BF32-EE6C24DD9ECC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Recettear\recettear.exe
FirewallRules: [{D0A5B849-D13A-4AC3-A6B1-A0768695095C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Recettear\custom.exe
FirewallRules: [{78478DF9-32B1-4FF5-9B63-A39226CF649B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Recettear\custom.exe
FirewallRules: [{ECD57D71-4B2A-4F14-B231-82DAC7AA9CFE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\they bleed pixels\They Bleed Pixels PC.exe
FirewallRules: [{E8D8F371-5D92-4CE5-B7D9-37711F4C329D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\they bleed pixels\They Bleed Pixels PC.exe
FirewallRules: [{43B5B143-648D-4ABB-8695-0196B8782EA7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Anodyne\Anodyne.exe
FirewallRules: [{DCE88040-DDFA-4CE1-91DF-229610B57C82}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Anodyne\Anodyne.exe
FirewallRules: [{3D7D3609-DCCA-4FDE-A928-C12CD1458C16}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\hotline_miami\HotlineMiami.exe
FirewallRules: [{A1009040-0CDF-4B58-B9C2-9E73A92FCC8C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\hotline_miami\HotlineMiami.exe
FirewallRules: [{261C641E-3E7F-4405-A017-4A6A41E16936}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mars War Logs\MarsWarLogs.exe
FirewallRules: [{CE5BA647-9259-4EF8-A9B6-C3C69709D8A6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mars War Logs\MarsWarLogs.exe
FirewallRules: [{149B886E-9B9D-47F7-83FE-0F210BC9525D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FEZ\FEZ.exe
FirewallRules: [{04DD1099-3D72-4B1F-B5E0-522EE8E493B5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FEZ\FEZ.exe
FirewallRules: [{2B9DCC28-C957-4E54-8F27-89EBA0991B0B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FEZ\FEZ_LaunchOptions.exe
FirewallRules: [{69BCF071-B000-49D1-9713-4D2A0EA5B527}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FEZ\FEZ_LaunchOptions.exe
FirewallRules: [{E94B8BBE-0A04-40DA-976F-36AA32DF9E89}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe
FirewallRules: [{BAADD635-1719-49D6-8A73-BAC5355A0064}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe
FirewallRules: [{29788CF0-34F8-4370-B91F-0FB89380DCD6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BrutalLegend\BrutalLegend.exe
FirewallRules: [{9ADF23EE-AD7D-44B8-ACC1-8E7C28EDAC34}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BrutalLegend\BrutalLegend.exe
FirewallRules: [{53647FAC-FDBC-481E-948D-CF71587E6565}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Psychonauts\Psychonauts.exe
FirewallRules: [{400E7940-EAA5-439A-B939-4E8B144E6CF1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Psychonauts\Psychonauts.exe
FirewallRules: [TCP Query User{BE268B43-A686-47C6-B920-07B6E49B3B7B}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe
FirewallRules: [UDP Query User{84A1D798-2F90-47A9-9149-8C275FB1FB01}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe
FirewallRules: [{A6D8696E-8ADB-493C-A8BE-110DC6EEC2B0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TinyBarbarianDX\TinyBarbarianDX.exe
FirewallRules: [{76D3CC44-00CD-461D-9F19-DA59ABD9639B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TinyBarbarianDX\TinyBarbarianDX.exe
FirewallRules: [{0D16C20E-20B9-417D-BA95-EC4ABE96FF96}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{CE55B0E0-2692-40B1-9713-B4F2EA77C2D5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{1431A38A-A3EF-4FC7-9C98-53661531DF0F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{22BA6799-D4ED-445F-882C-4430DC7CE8F6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space\EndlessSpace.exe
FirewallRules: [{C17443F3-BECB-4442-9A5F-88B759D24A1B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{F6215155-BF3C-49AE-A0A6-FE141A5F28ED}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{D83A9F4C-32C6-43A7-83B9-4285FA580D82}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{00187EEB-73B2-47FE-B6DF-F6ABAED5E69F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{D11C4900-E94A-4C5B-9168-AC71F147C784}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{055624DE-AAA5-4457-BAE7-53B7DD70EF2F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{4580A8D2-A66C-49B5-AEDD-E4F7F63AC34B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{BCA794AF-C5AF-4E77-A32A-CBC733C3E51E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{61351BF9-8C10-4146-BC00-BE25EAA7B574}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Reus\Reus.exe
FirewallRules: [{EA7B5A19-D915-4B7A-AFFE-A3D7F8B62647}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Reus\Reus.exe
FirewallRules: [{0D7DD702-A4F0-4503-AD65-D30629D133BF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{DAD3AB89-D096-4577-AFA1-8AD954F8003A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Incredible Adventures of Van Helsing\VanHelsing.exe
FirewallRules: [{93D0B68D-91BC-43DD-A974-D71A6F49E785}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{984C4DC0-438D-4A38-8CBF-4132F429C056}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{ADD23156-0388-4CD6-8055-6CF33567D1A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{5F492B42-0CFC-476E-B916-3A02B5926B28}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{84A41741-14F6-4CB2-ABD6-E61470950590}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{5BC6EEF3-51C8-4382-9FD6-D7AC223991AB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{631E53AF-AF11-428C-9BBF-8226DC5CF56E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{6242DACA-065C-4DAF-A844-70C2907CAAB6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{4D2CA06A-8246-4384-AC28-9C3A5767BDC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{0AC26730-F9C9-4526-B6EA-95252A9374A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{96E6B832-7FBA-42B6-B869-ECD63B7DD363}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{9B73CF88-60AC-44A2-A178-33ADB1460660}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{B1F5FCF1-8CA5-44A6-AE12-3DC0A763170A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{4E02F8D7-65D0-4C69-A11E-C8A4D1071A13}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{F0E0944C-A16F-46EB-8352-86A4B28939E1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bully Scholarship Edition\Bully.exe
FirewallRules: [{545EF150-A3C1-47A0-97BD-072FF1F3EE3A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bully Scholarship Edition\Bully.exe
FirewallRules: [{8344233C-D3AA-4074-8687-32275011D2E8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Revenge of the Titans\RevengeOfTheTitans.exe
FirewallRules: [{29A7B73C-4DCD-4E6F-8A50-F92742E1CE44}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Revenge of the Titans\RevengeOfTheTitans.exe
FirewallRules: [{F4E42AE8-ED6B-4AD5-9615-F081FB277FB0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{567600D7-B716-4BEB-B48D-C619A01FFA5E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Alan Wake\AlanWake.exe
FirewallRules: [{16980C10-0B61-45C3-A206-F9D94E9327B5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{A81C9B0F-5420-4285-8241-5AA3CA2C200C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Monaco\MONACO.exe
FirewallRules: [{0DFD1DE4-6E35-408D-B5D2-6FF089B58ADA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{6C3F9D3C-5FA2-44B0-BE41-A08C227D8FD7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{035BBE4C-8F4F-4908-B3D0-D826C87FC030}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Teslagrad Demo\Teslagrad.exe
FirewallRules: [{C6F61136-9C7E-4A8D-B6DD-763F44A71616}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Teslagrad Demo\Teslagrad.exe
FirewallRules: [{7C5C9F88-68E7-46B2-A4B8-F5488B76F77E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{1B4866CA-A71A-406E-9A87-C320C53988CD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{4F7026F3-CBDE-407F-BA79-470EBCAB8619}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{5F582107-5D58-4B65-8E8E-DB7235D07AAF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{4966B9D4-7751-45FF-8307-F57F4902AC3D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [{F67DD270-8426-4630-B4EE-3C3E818123A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [{7B0152D6-343D-49C3-AC86-250EA259F7FF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [{AFDB25EA-E151-4709-B955-A783BA4587C2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [{005EBE35-1526-4F4A-BE7A-650AC45E6601}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead\WalkingDead101.exe
FirewallRules: [{2DC710F7-3AF9-4A8B-9DF5-5A8B68AB66A8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead\WalkingDead101.exe
FirewallRules: [{49CDA40F-FA4D-435E-BC3E-73CF39E023C4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{1CA8B212-DFEC-4A69-9E61-CE4EC7287B8B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{0AC53880-8D92-4A0D-AFB5-D65406ED6642}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon.exe
FirewallRules: [{49108D75-33BA-422A-82D8-5E6635EB4E0A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon.exe
FirewallRules: [TCP Query User{A6666B70-2CB1-48B7-9666-6769E211EE87}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{67116663-9DEA-4FD3-8529-58773AE4801B}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [{675D4C0A-223C-41C8-860F-57A8C409FCE0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Revenge of the Titans\RevengeOfTheTitans.exe
FirewallRules: [{7FB47CA4-E65E-4E9C-9D74-9CDA6F0D35FC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Revenge of the Titans\RevengeOfTheTitans.exe
FirewallRules: [TCP Query User{277D869B-B211-4209-9883-1537CE7EE878}C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe
FirewallRules: [UDP Query User{B7BA912C-C22D-4FE7-BFB9-6C0E9213A62F}C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe
FirewallRules: [{76963B55-F543-4A03-9D92-8311BB710817}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{6A59C68C-9410-4C66-9626-0E198853F65F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{E5561779-571E-49F2-BC4F-5190108F9946}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Guacamelee\Guac.exe
FirewallRules: [{541958EF-9175-4AEE-AF16-EA3AE855FFC1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Guacamelee\Guac.exe
FirewallRules: [{D45832D9-5291-4F64-813A-12F303FB38E7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{6FB5B177-87C3-4F81-A8C0-405A78295EE6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{256FA3B3-007C-4908-A175-B63560109BF2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{1DB4BA76-1A3E-4E07-B7F4-70159752D788}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{C4C85C24-41A0-4BE9-865A-E6BE9FC94FA2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{05517B17-D0E3-4162-BAC2-FB9CBE878002}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{E03CB1E3-7009-4327-B37D-64113BA3509B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{035A53A3-4AE4-4E0E-90B4-6B3961F2CCB8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{956BFC5A-91F2-42CA-8569-97CFF66F990F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon.exe
FirewallRules: [{948B9DFF-B00A-4671-82C5-EA38750B6EFF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon.exe
FirewallRules: [{71825292-E4C2-4030-B556-A2F6C81BBCEB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{E9813D0A-442F-4C72-A496-BC3BACC1E079}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{8894FA8B-E6E0-4F08-B9DF-C52AE5DEA010}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{FEE5AE00-96BE-4015-908C-0A45D0D478A7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{9198D856-3DE3-451E-9CB3-BFF8BAA1F9C7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\rust\rust.exe
FirewallRules: [{8558D261-17E8-4956-A97A-9A7ECA30C469}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\rust\rust.exe
FirewallRules: [{DA18CBB9-C25D-4113-8521-7EBC838B8C2F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{939C0611-9882-42BA-99EC-3FB06EC7A193}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{490CF8FF-4CCC-48F5-90E7-0739D26C5588}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{65691E96-6BB5-41E6-8A96-8CA5B1B71E9E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{E78D3DF8-F338-4B1A-B0F0-1B451377A5C0}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{1BB640A1-67A0-4E29-B11A-C9121811D286}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{9BE0B95A-593F-437F-AE35-D28D0D247404}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{4D2CF2F7-5193-49D6-9AC1-E9CAE29C191F}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{B2F0C57C-D80D-4E56-9A28-AD0E1B345472}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Secret World\ClientPatcher.exe
FirewallRules: [{623FD171-6F74-457B-9AA4-D9B6B73A823B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Secret World\ClientPatcher.exe
FirewallRules: [{E745A027-D954-47A6-8323-C2BFDA4730D4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Returns\Shadowrun.exe
FirewallRules: [{83110B5D-EC90-4FDC-BF20-586D634EBEB1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Returns\Shadowrun.exe
FirewallRules: [{57AEB719-D9D5-4558-8D81-7B7FA8ACA547}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Remember Me\Binaries\Win32\RememberMe.exe
FirewallRules: [{7419AC9F-C509-4A33-AC01-FB041F4D7339}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Remember Me\Binaries\Win32\RememberMe.exe
FirewallRules: [{F5440DDF-B7C0-43E3-9BF2-B03EC6511FB4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rogue Legacy\RogueLegacy.exe
FirewallRules: [{7F6727D4-241E-450E-8418-145C81A4C291}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rogue Legacy\RogueLegacy.exe
FirewallRules: [{ABA4D3E8-BDA8-4730-91CC-F71CAFBE04C3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Surgeon Simulator 2013\ss2013.exe
FirewallRules: [{66A0AA82-B89C-4087-B245-C50449845E4F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Surgeon Simulator 2013\ss2013.exe
FirewallRules: [{B53E401F-3BD6-4CFF-97EF-6D94AADDC974}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Octodad Dadliest Catch\OctodadDadliestCatch.exe
FirewallRules: [{57D24C64-BF7D-446E-B0CA-750308DFB15C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Octodad Dadliest Catch\OctodadDadliestCatch.exe
FirewallRules: [{5135B711-8DFB-4AE9-8A66-B0F37D47B034}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{65D52BB1-59B0-41E8-A1FD-865BA821EB47}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{4F2CCA0F-E188-48DC-B417-49DDA2EA36F3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe
FirewallRules: [{F2E80592-E87F-4C6D-9402-8DBF3AA944AC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe
FirewallRules: [{5CDF5E1C-6C43-417A-B092-7075190D68DD}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{1A626A54-B0EA-41A6-899B-D6FA00CC49EF}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{6ABA6768-DB08-41FF-A5E6-B2E3DD1258CB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Legend of Grimrock\grimrock.exe
FirewallRules: [{EB99D301-3D59-4E4E-891D-D2D284580687}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Legend of Grimrock\grimrock.exe
FirewallRules: [{7D80C5DD-59B1-4A33-A254-EB4465469683}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Five Nights at Freddy's\FiveNightsatFreddys.exe
FirewallRules: [{9D569C15-B2A1-4242-AD9A-87DCC081639F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Five Nights at Freddy's\FiveNightsatFreddys.exe
FirewallRules: [{ADBC0EE5-952B-4D2C-976F-102A384E483E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Transistor\x64\Transistor.exe
FirewallRules: [{B10A9BBE-9124-4AC9-8C61-F50FB8EC7E73}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Transistor\x64\Transistor.exe
FirewallRules: [{88B22EEC-D0E1-4895-BAC3-36A1ABA90739}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dungeons & Dragons HD\ManaGame.exe
FirewallRules: [{72AFBF8D-5876-4EA7-A8AF-5D9C2B86FDE7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dungeons & Dragons HD\ManaGame.exe
FirewallRules: [{0FCAD903-8AEB-4CD8-9612-6BEC56A6CF03}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bionic Commando Rearmed\bcr.exe
FirewallRules: [{A3F977A7-8389-4779-A295-6D5B292413C8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Bionic Commando Rearmed\bcr.exe
FirewallRules: [{E80A1482-4FE9-4C01-A34E-B31E5E8B1C52}] => (Allow) LPort=8888
FirewallRules: [TCP Query User{DC6EB690-B1C0-455E-8568-4FF05069AF93}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe
FirewallRules: [UDP Query User{C145E381-435A-48DA-A03E-89833C064CFD}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe
FirewallRules: [{A3493FF8-7648-4EEA-8D28-B7F5CBAD80DE}] => (Allow) LPort=8888
FirewallRules: [{783871DC-416A-45DD-9381-2AD54A660D8D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Nidhogg\Nidhogg.exe
FirewallRules: [{62DA9F5A-49A1-4A2F-AE2D-E470C9CAA507}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Nidhogg\Nidhogg.exe
FirewallRules: [{401E1439-562B-4E40-9C0F-46C97425C726}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Castlevania Lords of Shadow - Mirror of Fate HD\CMOF.exe
FirewallRules: [{A7FE8355-02C7-49F5-93C9-5A7F12091672}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Castlevania Lords of Shadow - Mirror of Fate HD\CMOF.exe
FirewallRules: [{5FD90A0F-4F57-4398-98D0-3AC14030EA20}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{2454A98A-ADAE-478C-89AF-5EBBF252AE15}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{C96F1FFE-B008-410A-A216-D0D4A893B3A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\CastlevaniaLoS\bin\CastlevaniaLoSUE.exe
FirewallRules: [{55998790-537E-4591-AD29-DDDC0E1BD4D3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\CastlevaniaLoS\bin\CastlevaniaLoSUE.exe
FirewallRules: [{EA63ABC7-1A27-42B3-AFFF-E63243EE6992}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Styx\Binaries\Win64\StyxGame.exe
FirewallRules: [{1187E46D-A5D0-4BBC-84B0-86EF4A4C7F2F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Styx\Binaries\Win64\StyxGame.exe
FirewallRules: [{CBCC9230-C6FF-4B7F-B2EB-DFD21ACC1DE6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\CreationKit.exe
FirewallRules: [{6FF2407B-1773-4F5F-9B13-A81B1602497C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\CreationKit.exe
FirewallRules: [{73628E4D-E334-43F2-B531-1BFB5F756017}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Gnomoria\Gnomoria.exe
FirewallRules: [{17CEDEC4-5F4C-4D81-81EF-6BA1DCE71F53}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Gnomoria\Gnomoria.exe
FirewallRules: [{D13D0ED7-E074-429D-B7B9-964CC845D5E8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Dragonfall Director's Cut\Dragonfall.exe
FirewallRules: [{9C648C06-14C8-4C54-A726-232A762A7679}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shadowrun Dragonfall Director's Cut\Dragonfall.exe
FirewallRules: [{A5843F24-9CA4-4514-AB13-315FBEBB677E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SleepingDogsDefinitiveEdition\sdhdship.exe
FirewallRules: [{7476A0AF-768C-46C5-AF1D-4853A96DE7F6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SleepingDogsDefinitiveEdition\sdhdship.exe
FirewallRules: [{260640F9-754F-4FB5-9399-7FEFCB5C9E56}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TheLongDark\tld.exe
FirewallRules: [{E73316FF-35F3-442C-9055-856910642354}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TheLongDark\tld.exe
FirewallRules: [{A1FA3210-2371-45F8-8EE4-5EB9E20D5A74}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Game of Thrones\Thrones.exe
FirewallRules: [{2613920A-4169-446A-83C5-77B49748CB36}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Game of Thrones\Thrones.exe
FirewallRules: [{18189144-BCB0-4B7A-8770-6DDBB13CC69E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2CD312BA-A096-43DE-BC59-C74636E08E27}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BF287FAB-ACF3-4BD0-84F0-D87283E230BD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{13C909C5-3284-442D-A8B7-B4657BE45DF7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{B3511193-4F80-4A14-94AB-FEC2B6775062}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{794906FD-513D-424A-8280-235D3AC9F07A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CC7AC7E4-91E4-4A6B-BFE5-9DB6FCDA6C3C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Stomping Land\Binaries\Win32\UDK.exe
FirewallRules: [{74A367C8-8636-47A5-B718-9991075E95DA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Stomping Land\Binaries\Win32\UDK.exe
FirewallRules: [{46DD5DDD-DCF6-4FFD-AB5C-A2CD983A7C17}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon_DirectToRift.exe
FirewallRules: [{86F9C0D8-F274-4C49-BA2C-940420F8F9C6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\LegendofDungeon\LegendofDungeon_DirectToRift.exe
FirewallRules: [{FC534A64-151E-4BB0-A60B-4237CD70C5A4}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{0AE60447-4C7C-4E59-803B-8C984C0D7330}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{8FD55EEA-D5FA-49D1-AA12-912A763CC5AA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Divinity - Original Sin\Shipping\EoCApp.exe
FirewallRules: [{9C1C11E1-A17F-446E-A29D-F040FE10F2F8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Divinity - Original Sin\Shipping\EoCApp.exe
FirewallRules: [{637AFE18-3A5A-4DB9-893E-D70B5E38A7F1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{849BE47D-5D53-43AC-B3CD-6B4F634737CC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{1E10D591-1225-4C06-8CA7-CBE2AE5BA108}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Westerado\WesteradoDB.exe
FirewallRules: [{81A6F3EF-C172-4E86-840C-D47A92EA5535}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Westerado\WesteradoDB.exe
FirewallRules: [{D4D74FB1-40AF-4C86-9ABC-14AC918869F1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shovel Knight\ShovelKnight.exe
FirewallRules: [{811447FF-E3EA-47C5-8B98-E5913A198FC4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Shovel Knight\ShovelKnight.exe
FirewallRules: [{20DCC540-BD28-4594-AB4F-B1494502B1A4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\tbs\win32\The Banner Saga.exe
FirewallRules: [{92E3D3CE-BDD9-42D7-87B1-00406E7D082B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\tbs\win32\The Banner Saga.exe
FirewallRules: [{F97414AB-9DAA-48C7-A084-4CFE513B8C89}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{A7A21066-E01E-4E9F-A4E2-FDB256BDE37A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{AA8E2CA5-F9D1-4F0C-8A2B-7BA2216A44DE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{7EAF95F2-FF25-418F-BF85-9F223024F427}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{DBE35B99-CC5D-483E-A7A4-07FB68A9E8D4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{1FB15D9F-2F78-4332-B5C9-734D0AFC81DB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King of Dragon Pass\King of Dragon Pass.exe
FirewallRules: [{96757209-E0AD-4F9E-A081-709A193395C1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King of Dragon Pass\King of Dragon Pass.exe
FirewallRules: [{ACAAC47B-D4A8-4D69-AA54-31C52540F41D}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{C41E96BD-AD69-4347-971D-0711EBBF8A21}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe
FirewallRules: [{16502BD0-DFE2-4A45-8534-4FAAF5C1C72B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe
FirewallRules: [{85A13C50-7B47-4252-AE44-B20EC4C83730}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mad Max\MadMax.exe
FirewallRules: [{060DE892-77C2-4186-95B7-DDA33A6AB224}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mad Max\MadMax.exe
FirewallRules: [{9DAED1AB-7C3E-4B27-9C58-85E9E1A13D71}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\abyss_odyssey\Binaries\Win32\AO.exe
FirewallRules: [{B7AB5A7A-1992-446E-A23D-D8BEEA97F9B5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\abyss_odyssey\Binaries\Win32\AO.exe
FirewallRules: [{038E478A-CCAB-4D4A-B354-60F8018C3E74}] => (Allow) C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe
FirewallRules: [{C2CA25B1-BEA2-4611-9665-09D8AE08E8A7}] => (Allow) C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe
FirewallRules: [{3E9008D6-44F9-492F-9130-8EB087F8A2E6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{4B5DB14B-5900-40F1-A54E-62F4DEBC0678}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{130EC5B6-F741-40ED-B9D3-9AC0FA1D348A}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{662E4177-72FA-4EF2-9E1C-C34E105A2889}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{DA6BDAD2-9CFD-4961-9D6A-C9B25D429728}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DarkestDungeon\_windows\Darkest.exe
FirewallRules: [{DBA37D16-2BF1-4737-B8A6-96107A61A7FB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DarkestDungeon\_windows\Darkest.exe
FirewallRules: [{E9352C7B-B1A3-4936-89F9-88B7BE6FFAC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Jotun\Jotun.exe
FirewallRules: [{FB5D96A0-BED4-4E7A-BB3D-E1904FECAFF5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Jotun\Jotun.exe
FirewallRules: [{05BFD149-BB97-4FDC-9A63-A4C5C18CD8BA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{D4F1CE35-7BA3-4152-B695-1F2B68358A61}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Pillars of Eternity\PillarsOfEternity.exe
FirewallRules: [{6B93DB34-131E-48C1-A3D7-F26D4786745E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Pillars of Eternity\PillarsOfEternity.exe
FirewallRules: [{338260AB-8949-4BAA-83D3-9BFCB4D4D732}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1BCFC91E-B5B7-48E7-89C8-DF3160A4F5D2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Faulty Device Manager Devices =============
Name: Video Controller
Description: Video Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/07/2015 08:10:03 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16483 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 1e34
Start Time: 01d119580edca39b
Termination Time: 7
Application Path: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report Id: da381cff-8550-11e5-bbaa-bc5ff4abb4c9
Error: (11/07/2015 07:37:14 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16483 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 2838
Start Time: 01d11958ea24d0a2
Termination Time: 14
Application Path: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report Id: 4468b728-854c-11e5-bbaa-bc5ff4abb4c9
Error: (11/07/2015 07:13:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 46.0.2490.80, time stamp: 0x56262c73
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x10006c13
Faulting process id: 0x2620
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
Error: (11/07/2015 07:12:51 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 46.0.2490.80, time stamp: 0x56262c73
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x10006c13
Faulting process id: 0x2a7c
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
Error: (11/07/2015 07:11:57 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 46.0.2490.80, time stamp: 0x56262c73
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x10006c13
Faulting process id: 0x2ac4
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
Error: (11/07/2015 07:07:24 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 46.0.2490.80, time stamp: 0x56262c73
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x10006c13
Faulting process id: 0x260c
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
Error: (11/07/2015 06:56:01 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16483 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 26a4
Start Time: 01d11952b140d6a5
Termination Time: 17
Application Path: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report Id: 8168d724-8546-11e5-bbaa-bc5ff4abb4c9
Error: (11/07/2015 06:51:39 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 46.0.2490.80, time stamp: 0x56262c73
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x10006c13
Faulting process id: 0x2c94
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
Error: (11/07/2015 06:51:28 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 46.0.2490.80, time stamp: 0x56262c73
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x10006c13
Faulting process id: 0x2c8c
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
Error: (11/06/2015 05:38:21 PM) (Source: SideBySide) (EventID: 63) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.
System errors:
=============
Error: (11/06/2015 02:05:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The WinRing0_1_2_0 service failed to start due to the following error:
%%2
Error: (11/06/2015 01:54:10 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Windows Update service hung on starting.
Error: (11/06/2015 01:45:44 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Avast Antivirus service failed to start due to the following error:
%%1053
Error: (11/06/2015 01:45:44 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Avast Antivirus service to connect.
Error: (11/06/2015 01:45:39 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 1:43:36 PM on 11/6/2015 was unexpected.
Error: (11/05/2015 05:25:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Steam Client Service service failed to start due to the following error:
%%1053
Error: (11/05/2015 05:25:11 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
Error: (11/05/2015 08:31:49 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.
Error: (11/05/2015 08:31:48 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.
Error: (11/05/2015 08:27:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The WinRing0_1_2_0 service failed to start due to the following error:
%%2
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz
Percentage of memory in use: 31%
Total physical RAM: 16267.12 MB
Available physical RAM: 11156.68 MB
Total Virtual: 32534.23 MB
Available Virtual: 27373.99 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:931.41 GB) (Free:20.32 GB) NTFS
Drive i: (Ginnungagap) (Fixed) (Total:3726.02 GB) (Free:2671.08 GB) NTFS
Drive j: (MULTIBOOT) (Removable) (Total:0.91 GB) (Free:0.89 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: FFC0A867)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
Attempted reading MBR returned 0 bytes.
Could not read MBR for disk 1.
========================================================
Disk: 2 (Size: 931 MB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================