This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Foreign control of PC worries

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Early this morning on the 12th, I beleive I ended up with a program that allowed my pc to be controlled from another device. The mouse started moving erratically and then headed towards the start button on my pc. At this point I manually shutdown my pc and then turned off the router in my house. I then rebooted my pc and went to a system restore point on the 10th (I am aware that this is very unlikely to fix problems but tried it anyway). Since then, I have been very  worried abotu reconnecting to the internet on my pc for concerns of spyware/malware remaining on my pc, especially since I seem to get some odd task manager programs begining when I do connect.

 

I have therefore run a number of tests and am now coming into some issues with some software. I have run a Malware bytes scan, A windows defender full scan and a boot up scan, I have also run rogue killer and hitman pro (rogue killer found 5 things which I have removed whilst hitmanpro found lots of adware in firefox and some of the remnants of rogue killer). I have run TDSSkiller and it found nothing. I am now trying  to run aswMBR though it appears to simply crash my pc.

 

For whatever reason, remote access was turned on on this PC (I have no memory of turning it on), this is now turned off.

 

I am aware I may be overeacting and that whatever was controlling my pc is now gone but I am wondering if there is any wise steps to tak from here on out to keep me protected. I can link and collect logs as neccesary.

 

Thanks in advance

 

 

since I seem to get some odd task manager programs begining when I do connect

Can you recall the names that showed in task manager?
 

I have also run rogue killer and hitman pro (rogue killer found 5 things which I have removed whilst hitmanpro found lots of adware in firefox and some of the remnants of rogue killer).

I'd like to see those logs.
 
If you had bad extensions located in Firefox I would reset Firefox.
 
Instructions on how to backup your Favourites/Bookmarks and other data can be found below.
Backup Firefox Bookmarks

Proceed with the reset once done.
Reset Firefox

~~~~~~~~~~~
 

For whatever reason, remote access was turned on on this PC (I have no memory of turning it on), this is now turned off.

I am aware I may be overeacting and that whatever was controlling my pc is now gone but I am wondering if there is any wise steps to tak from here on out to keep me protected. I can link and collect logs as necessary.

May need to check on this often to ensure it stays off.
I don't call it over reacting at all,  I call it,  concerned.
 
Let's just look around and see if we find anything we should remove.


[external image: iO3R662.png]Farbar Recovery Scan Tool (FRST) - Scan mode
Follow the instructions below to download and execute a scan on your system with FRST, and provide the logs in your next reply.
  • Download the right version of FRST for your system:
    • FRST 32-bit
    • FRST 64-bit
      Note: Only the right version will run on your system, the other will throw an error message. So if you don't know what your system's version is, simply download both of them, and the one that works is the one you should be using.
  • Move the executable (FRST.exe or FRST64.exe) on your Desktop
  • Right-click on the executable and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the disclaimer by clicking on Yes, and FRST will then do a back-up of your Registry which should take a few seconds
  • Make sure the Addition.txt box is checked
  • Click on the Scan button
    [external image: KSJwAxg.png]
  • On completion, two message box will open, saying that the results were saved to FRST.txt and Addition.txt, then open two Notepad files
  • Copy and paste the content of both FRST.txt and Addition.txt in your next reply
also please post the logs for rogue killer and hitman pro

Roguekiller output:

 

ogueKiller V12.12.26.0 (x64) [Jul  9 2018] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.17134) 64 bits version
Started in : Normal mode
User : joedi [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan – Date : 07/12/2018 17:16:15 (Duration : 00:46:45)
Switches : -refid

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 4 ¤¤¤
[PUP.WikiThemes] (X64) HKEY_USERS\S-1-5-21-1349798611-4138563247-4221669333-1001\Software\AppDataLow\Software\WikiThemes -> Found
[PUP.WikiThemes] (X86) HKEY_USERS\S-1-5-21-1349798611-4138563247-4221669333-1001\Software\AppDataLow\Software\WikiThemes -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | TCP Query User{D52ED1B2-EDFA-42A2-93AE-0338798C7E41}C:\users\joedi\appdata\roaming\ygopro devpro launcher\ygopro.exe : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\joedi\appdata\roaming\ygopro devpro launcher\ygopro.exe|Name=ygopro.exe|Desc=ygopro.exe|Defer=User| [x] -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | UDP Query User{1A380CB9-C7A3-4556-A522-13FAE395FE3D}C:\users\joedi\appdata\roaming\ygopro devpro launcher\ygopro.exe : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\joedi\appdata\roaming\ygopro devpro launcher\ygopro.exe|Name=ygopro.exe|Desc=ygopro.exe|Defer=User| [x] -> Found

¤¤¤ Tasks : 1 ¤¤¤
[Suspicious.Path] \BlueStacksHelper – C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe -> Found

¤¤¤ Files : 0 ¤¤¤

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD10JPVX-60JC3T0 +++++
— User —
[MBR] e0070a71bf7502f8e14442f04590f260
[BSP] 5c5498f9785b75157de114813b939508 : Empty MBR Code
Partition table:
0 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 260 MB
1 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 534528 | Size: 128 MB
2 - Basic data partition | Offset (sectors): 796672 | Size: 935359 MB
3 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1916413952 | Size: 1014 MB
4 - [SYSTEM] Basic data partition | Offset (sectors): 1918490624 | Size: 17103 MB
User = LL1 … OK
User = LL2 … OK

+++++ PhysicalDrive1: Corsair VoyagerGT USB Device +++++
— User —
[MBR] 424d55ba7cdea10eb18b7f0a77f4e539
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - EFI System Partition | Offset (sectors): 40 | Size: 200 MB
1 - Untitled | Offset (sectors): 411648 | Size: 14838 MB
User = LL1 … OK
Error reading LL2 MBR! ([32] The request is not supported. )
 

Can't find the hitman pro outputs, and haven't run Farbar yet. Wanted to reply with what I have ASAP. I already reset my Firefox, I completely uninstalled it from my pc whilst I was disconnected, then used IE when reconnected and have since clean installed it on this PC. I also have  TDSS log if you are interested in seeing it. I will run Farbar ASAP, though am wondering if it is riky in anyway to run it. I can't recall the task manager names and I think I may have been overreacting, two I do remeber ended up being new Apple programs anyway. I can send screenshots of my taskmanager output too, though am worried doing so might actually make me vulnerable so haven't done so in this message.

 

Also, the YGOpro programs are not malicious, but I no longer have that program so got rid of them anyway.

 

Farbar now done, FRST output:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018
Ran by [removed] (administrator) on DESKTOP-800HF57 (13-07-2018 02:33:26)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 10 Home Version 1803 17134.112 (X64) Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Intel) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc.) C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18052.10711.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.10314.31700.0_x64__8wekyb3d8bbwe\Office16\OfficeHubTaskHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843520 2016-01-28] (Realtek Semiconductor)
HKLM\…\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [316392 2018-05-11] (Adobe Systems, Incorporated)
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242904 2018-07-12] (AVAST Software)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [298296 2018-05-22] (Apple Inc.)
HKLM-x32\…\Run: [Brunel University Connect Assistant] => C:\Program Files (x86)\Brunel University\Connect\Assistant\BrunelConnectAssistantInterface.exe [1215456 2016-10-25] (Brunel University London)
HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [657424 2016-01-11] (HP Inc.)
HKU\S-1-5-19\…\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-20\…\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-21-1349798611-4138563247-4221669333-1001\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3201312 2018-06-09] (Valve Corporation)
HKU\S-1-5-21-1349798611-4138563247-4221669333-1001\…\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIJDE.EXE [283232 2012-09-28] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1349798611-4138563247-4221669333-1001\…\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [57446848 2017-12-10] (Skype Technologies S.A.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{22c5afb9-8b33-446c-af16-1e70afc4ce25}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{26b11a49-585f-4b43-a90c-9af3c3d7b25b}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{381757e2-5144-4397-b90a-e84f653510ec}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{889c0851-aad1-40b9-a110-b692c1290e00}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{90aea244-1688-46da-baa5-83da2be65280}: [NameServer] 8.8.8.8

Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\S-1-5-21-1349798611-4138563247-4221669333-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
SearchScopes: HKLM-x32 -> {E0792105-41AB-418D-A3E7-08470AE8C501} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag;=hp-uk1-vsb-21&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKU\S-1-5-21-1349798611-4138563247-4221669333-1001 -> {E0792105-41AB-418D-A3E7-08470AE8C501} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag;=hp-uk1-vsb-21&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-06-19] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2018-06-19] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-01-21] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2018-06-19] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-21] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-21] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-21] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-21] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: 7qipq8us.default-1510947939295
FF DefaultProfile: y1g5gbln.default-1531424880772
FF ProfilePath: C:\Users\joedi\AppData\Roaming\OldMozilla\Firefox\Profiles\7qipq8us.default-1510947939295 [2018-07-12]
FF Homepage: OldMozilla\Firefox\Profiles\7qipq8us.default-1510947939295 -> about:home
FF Extension: (Grammarly for Firefox) - C:\Users\joedi\AppData\Roaming\OldMozilla\Firefox\Profiles\7qipq8us.default-1510947939295\Extensions\[removed] [2018-07-07]
FF Extension: (Hide Facebook Feed) - C:\Users\joedi\AppData\Roaming\OldMozilla\Firefox\Profiles\7qipq8us.default-1510947939295\Extensions\@hide-facebook-feed.xpi [2017-11-17] [Legacy]
FF Extension: (anonymoX) - C:\Users\joedi\AppData\Roaming\OldMozilla\Firefox\Profiles\7qipq8us.default-1510947939295\Extensions\[removed] [2018-01-07]
FF Extension: (AdBlock) - C:\Users\joedi\AppData\Roaming\OldMozilla\Firefox\Profiles\7qipq8us.default-1510947939295\Extensions\[removed] [2018-07-10]
FF Extension: (uBlock Origin) - C:\Users\joedi\AppData\Roaming\OldMozilla\Firefox\Profiles\7qipq8us.default-1510947939295\Extensions\[removed] [2018-06-30]
FF Extension: (Disable Facebook news Feed) - C:\Users\joedi\AppData\Roaming\OldMozilla\Firefox\Profiles\7qipq8us.default-1510947939295\Extensions\{85cd2b5d-b3bd-4037-8335-ced996a95092}.xpi [2018-05-19]
FF Extension: (Adblock Plus) - C:\Users\joedi\AppData\Roaming\OldMozilla\Firefox\Profiles\7qipq8us.default-1510947939295\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-05-16]
FF Extension: (Simple YouTube MP3 Button) - C:\Users\joedi\AppData\Roaming\OldMozilla\Firefox\Profiles\7qipq8us.default-1510947939295\Extensions\{e33788ea-0bb9-4502-9c77-bdc551afc8ab}.xpi [2017-11-17]
FF ProfilePath: C:\Users\joedi\AppData\Roaming\Mozilla\Firefox\Profiles\y1g5gbln.default-1531424880772 [2018-07-13]
FF Homepage: Mozilla\Firefox\Profiles\y1g5gbln.default-1531424880772 -> about:home
FF Extension: (Grammarly for Firefox) - C:\Users\joedi\AppData\Roaming\Mozilla\Firefox\Profiles\y1g5gbln.default-1531424880772\Extensions\[removed] [2018-07-12]
FF Extension: (anonymoX) - C:\Users\joedi\AppData\Roaming\Mozilla\Firefox\Profiles\y1g5gbln.default-1531424880772\Extensions\[removed] [2018-07-12]
FF Extension: (AdBlock) - C:\Users\joedi\AppData\Roaming\Mozilla\Firefox\Profiles\y1g5gbln.default-1531424880772\Extensions\[removed] [2018-07-12]
FF Extension: (uBlock Origin) - C:\Users\joedi\AppData\Roaming\Mozilla\Firefox\Profiles\y1g5gbln.default-1531424880772\Extensions\[removed] [2018-07-12]
FF Extension: (Avast Online Security) - C:\Users\joedi\AppData\Roaming\Mozilla\Firefox\Profiles\y1g5gbln.default-1531424880772\Extensions\[removed] [2018-07-12]
FF Extension: (Disable Facebook news Feed) - C:\Users\joedi\AppData\Roaming\Mozilla\Firefox\Profiles\y1g5gbln.default-1531424880772\Extensions\{85cd2b5d-b3bd-4037-8335-ced996a95092}.xpi [2018-07-12]
FF Extension: (Adblock Plus) - C:\Users\joedi\AppData\Roaming\Mozilla\Firefox\Profiles\y1g5gbln.default-1531424880772\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-07-12]
FF Extension: (Simple YouTube MP3 Button) - C:\Users\joedi\AppData\Roaming\Mozilla\Firefox\Profiles\y1g5gbln.default-1531424880772\Extensions\{e33788ea-0bb9-4502-9c77-bdc551afc8ab}.xpi [2018-07-12]
FF Extension: (WebCompat Reporter) - C:\Program Files\Mozilla Firefox\browser\features\[removed] [2018-07-04] [Legacy] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_30_0_0_113.dll [2018-06-07] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_30_0_0_113.dll [2018-06-07] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1234204.dll [2018-06-06] (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-01-21] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-01-21] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\firefox.js [2017-02-13]

Chrome:
=======
CHR Profile: C:\Users\joedi\AppData\Local\Google\Chrome\User Data\Default [2017-03-29]
CHR Extension: (Google Slides) - C:\Users\joedi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-03-29]
CHR Extension: (Google Docs) - C:\Users\joedi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-03-29]
CHR Extension: (Google Drive) - C:\Users\joedi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-29]
CHR Extension: (YouTube) - C:\Users\joedi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-29]
CHR Extension: (Google Sheets) - C:\Users\joedi\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-03-29]
CHR Extension: (Google Docs Offline) - C:\Users\joedi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\joedi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-29]
CHR Extension: (Gmail) - C:\Users\joedi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-29]
CHR Extension: (Chrome Media Router) - C:\Users\joedi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-29]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2321384 2018-05-11] (Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2128872 2018-05-11] (Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2018-04-27] (Apple Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7780400 2018-07-12] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [322464 2018-07-12] (AVAST Software)
S2 BrunelConnectAssistant; C:\Program Files (x86)\Brunel University\Connect\Assistant\BrunelConnectAssistant.exe [453600 2016-10-25] (Brunel University London)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7761080 2018-06-08] (Microsoft Corporation)
R2 esifsvc; C:\WINDOWS\SysWOW64\esif_uf.exe [1385640 2016-06-21] (Intel Corporation)
R2 HPSupportSolutionsFrameworkService; c:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [333688 2018-06-13] (HP Inc.)
R2 HPTouchpointAnalyticsService; C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe [332216 2017-11-27] (HP Inc.)
R2 HPWMISVC; C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [606224 2016-01-11] (HP Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-07-22] (Intel Corporation)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [542320 2017-12-06] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [350312 2016-06-21] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
S3 Intel(R) WiDi SAM; C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-16] (Intel Corporation)
R2 IntelUSBoverIP; C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe [396992 2015-07-06] (Intel)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223520 2015-07-11] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268928 2017-12-20] ()
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-01-28] (Realtek Semiconductor)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [278616 2017-08-18] (Synaptics Incorporated)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\NisSrv.exe [3925648 2018-06-27] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MsMpEng.exe [100080 2018-06-27] (Microsoft Corporation)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3758720 2017-12-20] (Intel® Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 Accelerometer; C:\WINDOWS\System32\drivers\Accelerometer.sys [53760 2017-12-18] (HP)
S3 applockerfltr; C:\WINDOWS\System32\drivers\applockerfltr.sys [18432 2018-04-12] (Microsoft Corporation) [File not signed]
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [197160 2018-07-12] (AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdrivera.sys [229392 2018-07-12] (AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsha.sys [201328 2018-07-12] (AVAST Software)
R0 aswblog; C:\WINDOWS\System32\drivers\aswbloga.sys [346664 2018-07-12] (AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniva.sys [59592 2018-07-12] (AVAST Software)
S3 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [15360 2018-07-12] (AVAST Software)
R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [239680 2018-07-12] (AVAST Software)
S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [46976 2018-07-12] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [159640 2018-07-12] (AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [111872 2018-07-12] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [85968 2018-07-12] (AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [1027728 2018-07-12] (AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [463080 2018-07-12] (AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [211160 2018-07-12] (AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [381584 2018-07-12] (AVAST Software)
S3 clwvd6; C:\WINDOWS\system32\DRIVERS\clwvd6.sys [41704 2013-10-29] (CyberLink Corporation)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [43512 2016-06-21] (Intel Corporation)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2017-02-13] (Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2017-02-13] (Disc Soft Ltd)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [251384 2016-06-21] (Intel Corporation)
R0 hpdskflt; C:\WINDOWS\System32\drivers\hpdskflt.sys [39936 2017-12-18] (HP)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [136128 2017-12-06] (Intel Corporation)
R0 IntelHSWPcc; C:\WINDOWS\System32\drivers\IntelPcc.sys [88256 2015-07-22] (Intel Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253664 2018-07-12] (Malwarebytes)
R3 Netwtw04; C:\WINDOWS\system32\DRIVERS\Netwtw04.sys [8623040 2018-02-05] (Intel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [889584 2016-11-09] (Realtek )
S3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [753368 2015-07-21] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [55384 2017-08-18] (Synaptics Incorporated)
R3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [212056 2015-07-06] (Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46592 2018-06-27] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [340008 2018-06-27] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59944 2018-06-27] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [34960 2018-02-02] (HP)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-07-13 02:33 - 2018-07-13 02:34 - 000024310 _____ C:\Users\joedi\Desktop\FRST.txt
2018-07-13 02:33 - 2018-07-13 02:33 - 000000000 ____D C:\FRST
2018-07-13 02:31 - 2018-07-13 02:31 - 002412544 _____ (Farbar) C:\Users\joedi\Desktop\FRST64.exe
2018-07-13 02:17 - 2018-07-13 02:17 - 000028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2018-07-12 22:13 - 2018-07-13 02:00 - 001388448 _____ C:\Users\Public\ASR.dat
2018-07-12 20:46 - 2018-07-12 20:47 - 000000000 ____D C:\Users\joedi\AppData\Local\Mozilla
2018-07-12 20:46 - 2018-07-12 20:46 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-07-12 20:46 - 2018-07-12 20:46 - 000001000 _____ C:\Users\Public\Desktop\Firefox.lnk
2018-07-12 20:46 - 2018-07-12 20:46 - 000000000 ____D C:\Users\joedi\AppData\Roaming\Mozilla
2018-07-12 20:46 - 2018-07-12 20:46 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-07-12 20:46 - 2018-07-12 20:46 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-07-12 20:00 - 2018-07-12 20:05 - 000212176 _____ C:\TDSSKiller.3.1.0.17_12.07.2018_20.00.10_log.txt
2018-07-12 19:54 - 2018-07-12 20:05 - 000000000 ____D C:\AdwCleaner
2018-07-12 19:54 - 2018-07-12 19:54 - 007402192 _____ (Malwarebytes) C:\Users\joedi\Downloads\adwcleaner_7.2.1.exe
2018-07-12 19:52 - 2018-07-12 19:52 - 000001823 _____ C:\Users\Public\Desktop\iTunes.lnk
2018-07-12 19:52 - 2018-07-12 19:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2018-07-12 19:52 - 2018-07-12 19:52 - 000000000 ____D C:\Program Files\iPod
2018-07-12 19:51 - 2018-07-12 19:52 - 000000000 ____D C:\Program Files\iTunes
2018-07-12 19:48 - 2018-07-12 19:48 - 000000000 ____D C:\WINDOWS\System32\Tasks\Apple
2018-07-12 19:48 - 2018-07-12 19:48 - 000000000 ____D C:\Program Files (x86)\Apple Software Update
2018-07-12 18:54 - 2018-07-12 21:12 - 000000000 ____D C:\Users\joedi\AppData\Local\AVAST Software
2018-07-12 18:54 - 2018-07-12 20:15 - 000004264 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2018-07-12 18:54 - 2018-07-12 18:54 - 000001986 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2018-07-12 18:54 - 2018-07-12 18:54 - 000001974 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2018-07-12 18:54 - 2018-07-12 18:54 - 000000000 ____D C:\WINDOWS\System32\Tasks\Avast Software
2018-07-12 18:53 - 2018-07-12 18:53 - 000463080 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2018-07-12 18:53 - 2018-07-12 18:53 - 000381584 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2018-07-12 18:53 - 2018-07-12 18:53 - 000378072 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2018-07-12 18:53 - 2018-07-12 18:53 - 000211160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2018-07-12 18:53 - 2018-07-12 18:53 - 000197160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2018-07-12 18:53 - 2018-07-12 18:53 - 000159640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2018-07-12 18:53 - 2018-07-12 18:53 - 000111872 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2018-07-12 18:53 - 2018-07-12 18:53 - 000085968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2018-07-12 18:53 - 2018-07-12 18:53 - 000046976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2018-07-12 18:53 - 2018-07-12 18:53 - 000015360 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswElam.sys
2018-07-12 18:53 - 2018-07-12 18:53 - 000000000 ____D C:\Program Files\Common Files\AVAST Software
2018-07-12 18:53 - 2018-07-12 18:52 - 001027728 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2018-07-12 18:53 - 2018-07-12 18:52 - 000346664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbloga.sys
2018-07-12 18:53 - 2018-07-12 18:52 - 000239680 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
2018-07-12 18:53 - 2018-07-12 18:52 - 000229392 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2018-07-12 18:53 - 2018-07-12 18:52 - 000201328 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2018-07-12 18:53 - 2018-07-12 18:52 - 000059592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2018-07-12 18:41 - 2018-07-12 18:43 - 000760156 _____ C:\TDSSKiller.3.1.0.17_12.07.2018_18.41.02_log.txt
2018-07-12 18:38 - 2018-07-12 18:39 - 000008382 _____ C:\TDSSKiller.3.1.0.17_12.07.2018_18.38.29_log.txt
2018-07-12 18:36 - 2018-07-12 18:53 - 000000000 ____D C:\ProgramData\AVAST Software
2018-07-12 18:11 - 2018-07-12 18:11 - 000001973 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2018-07-12 18:11 - 2018-07-12 18:11 - 000000000 ____D C:\Program Files\HitmanPro
2018-07-12 18:07 - 2018-07-12 18:29 - 000000000 ____D C:\ProgramData\HitmanPro
2018-07-12 17:15 - 2018-07-12 18:07 - 000000000 ____D C:\ProgramData\RogueKiller
2018-07-12 17:15 - 2018-07-12 17:15 - 000000906 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2018-07-12 17:15 - 2018-07-12 17:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-07-12 17:15 - 2018-07-12 17:15 - 000000000 ____D C:\Program Files\RogueKiller
2018-07-12 05:22 - 2018-07-12 20:06 - 109314048 _____ C:\WINDOWS\system32\config\SOFTWARE
2018-07-12 05:12 - 2018-07-12 05:22 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
2018-07-12 04:32 - 2016-03-02 20:40 - 000015108 _____ C:\Users\joedi\Documents\Book1.xlsx
2018-07-12 03:55 - 2018-07-12 03:55 - 000000000 ___HD C:\$SysReset
2018-07-12 03:34 - 2018-07-12 03:34 - 000000000 ___HD C:\Users\Public\Documents\AdobeGC
2018-07-12 02:58 - 2018-07-12 02:58 - 000000000 ____D C:\Users\defaultuser1
2018-07-12 02:58 - 2016-09-22 06:52 - 000000000 ____D C:\Users\defaultuser1\Documents\hp.system.package.metadata
2018-07-12 02:58 - 2016-09-22 06:52 - 000000000 ____D C:\Users\defaultuser1\Documents\hp.applications.package.appdata
2018-07-12 02:40 - 2018-07-12 02:47 - 000000000 ___HD C:\WINDOWS\msdownld.tmp
2018-07-10 21:51 - 2018-07-10 21:51 - 000000000 ____D C:\ProgramData\Packages
2018-06-28 17:31 - 2018-06-28 17:31 - 000000000 ____D C:\Users\joedi\AppData\LocalLow\VNGINE

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-07-13 01:54 - 2018-05-25 07:42 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-07-12 22:24 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-07-12 21:00 - 2016-12-18 02:47 - 000000000 ____D C:\Users\joedi\AppData\Local\Discord
2018-07-12 20:48 - 2017-11-17 20:45 - 000000000 ____D C:\Users\joedi\Desktop\Old Firefox Data
2018-07-12 20:48 - 2016-11-21 14:22 - 000000000 ____D C:\Users\joedi\AppData\LocalLow\Mozilla
2018-07-12 20:20 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-07-12 20:20 - 2017-05-24 16:14 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2018-07-12 20:20 - 2016-04-11 10:01 - 000000000 __SHD C:\Users\joedi\IntelGraphicsProfiles
2018-07-12 20:07 - 2018-06-10 15:20 - 000253664 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-07-12 20:06 - 2018-05-25 08:11 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-07-12 20:06 - 2018-04-11 22:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-07-12 20:02 - 2018-05-25 08:11 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2018-07-12 20:01 - 2016-06-10 21:40 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-07-12 19:51 - 2018-04-12 00:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-07-12 19:48 - 2018-04-12 00:36 - 000000000 ____D C:\WINDOWS\INF
2018-07-12 19:48 - 2016-04-09 23:33 - 000002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2018-07-12 19:44 - 2016-06-21 12:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2018-07-12 19:44 - 2016-06-21 12:35 - 000000000 ____D C:\Program Files\7-Zip
2018-07-12 19:39 - 2018-05-25 07:48 - 000933368 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-07-12 19:18 - 2018-05-25 07:49 - 000000000 ____D C:\Users\joedi
2018-07-12 18:54 - 2016-06-17 11:34 - 000000000 ____D C:\Users\joedi\AppData\Roaming\AVAST Software
2018-07-12 18:53 - 2018-04-12 00:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2018-07-12 18:52 - 2015-11-03 16:33 - 000000000 ____D C:\Program Files\AVAST Software
2018-07-12 18:00 - 2015-07-10 12:04 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2018-07-12 04:35 - 2016-04-09 22:13 - 000000000 ____D C:\Program Files (x86)\Steam
2018-07-12 04:33 - 2016-08-08 15:44 - 000000000 ____D C:\Users\Public\Documents\RonyaSoft
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\tk-TM
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\sw-KE
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\si-LK
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\prs-AF
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\mn-MN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ky-KG
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\hi-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-BD
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\tk-TM
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\te-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\sw-KE
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\prs-AF
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\or-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\mn-MN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\ky-KG
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\km-KH
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\is-IS
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\id-ID
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\hi-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\bn-BD
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\be-BY
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\as-IN
2018-07-12 04:27 - 2018-04-12 17:17 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\TextInput
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\SysWOW64\en-GB
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\ta-in
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\si-lk
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\setup
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\et-EE
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\es-MX
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\en-GB
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\DDFs
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\am-et
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\Provisioning
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2018-07-12 04:27 - 2018-04-12 00:38 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2018-07-12 04:27 - 2018-04-11 22:04 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-07-12 04:27 - 2015-11-03 16:16 - 000000000 ___HD C:\WINDOWS\system32\WLANProfiles
2018-07-12 04:26 - 2018-04-12 17:13 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2018-07-12 04:26 - 2018-04-12 17:13 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2018-07-12 04:26 - 2018-04-11 22:04 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2018-07-12 04:26 - 2018-04-11 22:04 - 000000000 ____D C:\WINDOWS\servicing
2018-07-12 04:26 - 2018-02-20 04:26 - 000000000 ___RD C:\Users\joedi\3D Objects
2018-07-12 04:26 - 2016-09-22 12:10 - 000000000 ____D C:\Users\joedi\AppData\Local\ConnectedDevicesPlatform
2018-07-12 04:26 - 2016-02-13 18:32 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-07-12 04:23 - 2016-11-18 00:30 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-07-12 04:20 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\InfusedApps
2018-07-12 04:10 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\registration
2018-07-12 04:09 - 2016-07-17 02:28 - 000000000 ____D C:\Users\joedi\AppData\Roaming\YGOPro DevPro Launcher
2018-07-12 04:08 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-07-12 04:07 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-07-12 03:56 - 2017-04-04 09:26 - 000000000 ___RD C:\Program Files (x86)\Skype
2018-07-12 03:56 - 2016-04-09 21:50 - 000000000 ____D C:\ProgramData\Skype
2018-07-12 03:54 - 2017-04-08 18:37 - 000000000 ____D C:\Users\joedi\AppData\LocalLow\uTorrent
2018-07-12 03:50 - 2018-05-24 17:14 - 000000000 ____D C:\Users\joedi\Desktop\indie Vn game
2018-07-12 03:49 - 2017-11-04 03:51 - 000000000 ___HD C:\OneDriveTemp
2018-07-12 03:35 - 2016-04-09 21:50 - 000000000 ____D C:\Users\joedi\AppData\Roaming\Skype
2018-07-12 03:29 - 2018-02-26 21:46 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-07-12 03:29 - 2017-06-26 11:18 - 000000364 _____ C:\WINDOWS\Tasks\HPCeeScheduleForjoedi.job
2018-07-11 00:29 - 2018-02-20 03:45 - 000000000 ____D C:\Users\joedi\AppData\Local\Packages
2018-07-10 20:39 - 2018-04-12 00:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-07-10 20:27 - 2016-04-09 23:40 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-07-09 14:44 - 2018-05-25 08:11 - 000003256 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForjoedi
2018-07-05 22:27 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-07-01 23:57 - 2018-03-19 23:59 - 000000000 ____D C:\Users\joedi\Desktop\Masters stuff
2018-06-23 14:27 - 2018-05-25 08:11 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1349798611-4138563247-4221669333-1001
2018-06-23 14:27 - 2018-05-25 07:49 - 000002374 _____ C:\Users\joedi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-06-23 14:27 - 2016-04-09 21:17 - 000000000 ___RD C:\Users\joedi\OneDrive
2018-06-21 23:53 - 2016-08-07 21:30 - 000000000 ____D C:\Users\joedi\AppData\Local\ElevatedDiagnostics
2018-06-20 19:27 - 2016-12-18 02:47 - 000000000 ____D C:\Users\joedi\AppData\Roaming\discord
2018-06-19 13:23 - 2015-11-03 16:44 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-06-13 06:07 - 2018-05-25 07:42 - 000456328 _____ C:\WINDOWS\system32\FNTCACHE.DAT

==================== Files in the root of some directories =======

2016-04-09 23:07 - 2014-04-16 23:08 - 000658000 _____ (WildTangent, Inc.) C:\ProgramData\uninstall441367.exe
2018-07-12 22:13 - 2018-07-13 02:00 - 001388448 _____ () C:\Users\Public\ASR.dat
2017-07-20 01:55 - 2017-08-13 19:13 - 000099384 _____ () C:\Users\joedi\AppData\Roaming\inst.exe
2017-07-20 01:55 - 2017-08-13 19:13 - 000007859 _____ () C:\Users\joedi\AppData\Roaming\pcouffin.cat
2017-07-20 01:55 - 2017-08-13 19:13 - 000001167 _____ () C:\Users\joedi\AppData\Roaming\pcouffin.inf
2017-07-20 01:55 - 2017-08-13 19:13 - 000000055 _____ () C:\Users\joedi\AppData\Roaming\pcouffin.log
2017-07-20 01:55 - 2017-08-13 19:13 - 000082816 _____ (VSO Software) C:\Users\joedi\AppData\Roaming\pcouffin.sys
2017-11-17 21:06 - 2017-11-17 21:20 - 000007605 _____ () C:\Users\joedi\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
2018-07-12 17:15 - 2018-06-08 10:29 - 001946328 _____ (Microsoft Corporation) C:\Users\joedi\AppData\Local\Temp\dllnt_dump.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-05-25 07:41

==================== End of FRST.txt ============================

 

Addition Output:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by [removed] (13-07-2018 02:35:36)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 1803 17134.112 (X64) (2018-05-25 07:12:37)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1349798611-4138563247-4221669333-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1349798611-4138563247-4221669333-503 - Limited - Disabled)
Guest (S-1-5-21-1349798611-4138563247-4221669333-501 - Limited - Disabled)
joedi (S-1-5-21-1349798611-4138563247-4221669333-1001 - Administrator - Enabled) => C:\Users\joedi
WDAGUtilityAccount (S-1-5-21-1349798611-4138563247-4221669333-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 16.02 (x64) (HKLM\…\7-Zip) (Version: 16.02 - Igor Pavlov)
7-Zip 18.05 (x64 edition) (HKLM\…\{23170F69-40C1-2702-1805-000001000000}) (Version: 18.05.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20055 - Adobe Systems Incorporated)
Adobe Flash Player 30 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 30.0.0.113 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.3 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.3.4.204 - Adobe Systems, Inc.)
Apple Application Support (32-bit) (HKLM-x32\…\{C56BA005-F02C-461B-ACA5-A0CE3E32578F}) (Version: 6.5 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{C8087B7C-8496-45BE-92FB-91D31EB73969}) (Version: 6.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{64695C4A-C68F-46B5-A734-50EBF124A68E}) (Version: 11.3.3.4 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
Avast Free Antivirus (HKLM-x32\…\Avast Antivirus) (Version: 18.5.2342 - AVAST Software)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Brunel University London Connect Assistant (HKLM-x32\…\Brunel University Connect Assistant) (Version: 2.03.001 - Brunel University London)
CyberLink PhotoDirector (HKLM\…\{5A454EC5-217A-42a5-8CE1-2DDEC4E70E01}) (Version: 5.0.5.6713 - CyberLink Corp.) Hidden
CyberLink PhotoDirector (HKLM-x32\…\InstallShield_{5A454EC5-217A-42a5-8CE1-2DDEC4E70E01}) (Version: 5.0.5.6713 - CyberLink Corp.)
CyberLink Power Media Player 14 (HKLM-x32\…\{32C8E300-BDB4-4398-92C2-E9B7D8A233DB}) (Version: 14.0.5.6909 - CyberLink Corp.)
CyberLink PowerDirector 12 (HKLM\…\{E1646825-D391-42A0-93AA-27FA810DA093}) (Version: 12.0.4.4301 - CyberLink Corp.) Hidden
CyberLink PowerDirector 12 (HKLM-x32\…\InstallShield_{E1646825-D391-42A0-93AA-27FA810DA093}) (Version: 12.0.4.4301 - CyberLink Corp.)
DisableMSDefender (HKLM\…\{74FE39A0-FB76-47CD-84BA-91E2BBB17EF2}) (Version: 1.0.0 - Hewlett-Packard Company) Hidden
Dropbox 25 GB (HKLM-x32\…\{597A58EC-42D6-4940-8739-FB94491B013C}) (Version: 1.0.8.2 - Dropbox, Inc.)
Energy Star (HKLM\…\{465CA2B6-98AF-4E77-BE22-A908C34BB9EC}) (Version: 1.0.9 - Hewlett-Packard Company)
EPSON XP-850 Series Printer Uninstall (HKLM\…\EPSON XP-850 Series) (Version:  - SEIKO EPSON Corporation)
HellBlazers Maps Pack v8 (HKLM-x32\…\{0B2B1F4E-83EB-45A9-B560-D4C2A56ADE2C}) (Version: 8 - HellBlazer)
HitmanPro 3.8 (HKLM\…\HitmanPro38) (Version: 3.8.0.295 - SurfRight B.V.)
HP CoolSense (HKLM-x32\…\{1504CF6F-8139-497F-86FC-46174B67CF7F}) (Version: 2.20.51 - Hewlett-Packard Company)
HP Documentation (HKLM\…\HP_Documentation) (Version:  - HP)
HP Support Assistant (HKLM-x32\…\{61EB474B-67A6-47F4-B1B7-386851BAB3D0}) (Version: 8.6.18.11 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\…\{D7D5F438-26EF-45AB-AB89-C476FBCF8584}) (Version: 12.9.24.3 - Hewlett-Packard Company)
HP System Event Utility (HKLM-x32\…\{025C1573-2F1D-46AF-BAB8-594EBF56A889}) (Version: 1.4.11 - HP Inc.)
HP Touchpoint Analytics Client (HKLM\…\{E5FB98E0-0784-44F0-8CEC-95CD4690C43F}) (Version: 4.0.2.1439 - HP Inc.)
HP Welcome (HKLM\…\HPWelcome) (Version: 1.0 - Hewlett-Packard Company)
HP Wireless Button Driver (HKLM-x32\…\{EFA01423-3857-468C-B7B6-F30AA08E50BC}) (Version: 1.1.5.1 - Hewlett-Packard)
IBM SPSS Statistics 23 (HKLM-x32\…\{C3BA73A4-2A45-4036-8541-4F5F8146078B}) (Version: 23.0.0.0 - IBM Corp)
Intel Collaborative Processor Performance Control (HKLM-x32\…\0E7DAF70-FB54-4B91-B192-7E771C25AEEB) (Version: 1.0.0.1018 - Intel Corporation)
Intel(R) Chipset Device Software (HKLM-x32\…\{c7f54569-0018-439c-809a-48046a4d4ebc}) (Version: 10.1.1.9 - Intel(R) Corporation) Hidden
Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\…\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.1.10600.150 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1158 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4279 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.2.1088 - Intel Corporation)
Intel(R) WiDi (HKLM\…\{C7CD6D54-26AF-4D93-B06F-D81ACE8624CB}) (Version: 6.0.40.0 - Intel Corporation)
Intel(R) WiDi Software Asset Manager (HKLM-x32\…\{5B5CD20C-29F0-4857-A4FA-A4F4C716B019}) (Version: 1.1.347 - Intel Corporation) Hidden
Intel(R) Wireless Bluetooth(R) (HKLM-x32\…\{5068B0F8-CE24-4B61-9C2F-301B411FFB9C}) (Version: 18.1.1611.3223 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{8060a69f-ee27-444b-b126-775f861232ea}) (Version: 20.0.2 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{ed4a5da7-ac62-4aa5-9502-7b4de55e8cb5}) (Version: 20.20.2 - Intel Corporation)
iTunes (HKLM\…\{EA44188A-5042-4CFB-8F8D-AF048872B7A7}) (Version: 12.7.5.9 - Apple Inc.)
Malwarebytes version 3.5.1.2522 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
Microsoft Office 365 ProPlus - en-us (HKLM\…\O365ProPlusRetail - en-us) (Version: 16.0.8431.2270 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1349798611-4138563247-4221669333-1001\…\OneDriveSetup.exe) (Version: 18.091.0506.0007 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\…\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Windows Application Compatibility Database (HKLM\…\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb) (Version:  - )
Mozilla Firefox 61.0.1 (x64 en-GB) (HKLM\…\Mozilla Firefox 61.0.1 (x64 en-GB)) (Version: 61.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 61.0.1 - Mozilla)
NVIDIA PhysX (HKLM-x32\…\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\…\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8431.2270 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\…\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2270 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\…\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2270 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\…\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.8326.2076 - Microsoft Corporation) Hidden
Razer Megalodon Firmware Updater (HKLM-x32\…\{C67A3F9D-E55D-4288-B4EC-1B9863EFB288}) (Version: 2.12.02 - Razer USA Ltd.)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.370.99 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.3.723.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7730 - Realtek Semiconductor Corp.)
RGSS-RTP Standard (HKLM-x32\…\{5A9FE525-8B8F-4701-A937-7F6745A4E9C7}) (Version: 1.0.0 - Enterbrain)
RogueKiller version 12.12.26.0 (HKLM\…\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.12.26.0 - Adlice Software)
Should I Remove It (HKLM-x32\…\{4E62123C-4C0D-4123-A8A2-C0103B92D7EA}) (Version: 1.0.4 - Reason Software Company Inc.) Hidden
Should I Remove It (HKU\S-1-5-21-1349798611-4138563247-4221669333-1001\…\Should I Remove It 1.0.4) (Version: 1.0.4 - Reason Software Company Inc.)
Sid Meier's Civilization V (HKLM-x32\…\steam app 8930) (Version:  - 2K Games, Inc.)
Skype version 8.12 (HKLM-x32\…\Skype_is1) (Version: 8.12 - Skype Technologies S.A.)
Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
Steins;Gate version 1.0 (HKLM\…\{2A05A52B-BDD8-4FD5-A65A-687CB10D98DF}_is1) (Version: 1.0 - JAST USA)
swMSM (HKLM-x32\…\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics ClickPad Driver (HKLM\…\SynTPDeinstKey) (Version: 19.3.31.31 - Synaptics Incorporated)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\…\{9C4F3AF4-21D8-43BD-A69C-517BB96012CF}) (Version: 2.12.0.0 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1349798611-4138563247-4221669333-1001_Classes\CLSID\{C52B9871-E5E9-41FD-B84D-C5ACADBEC7AE}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-12] (AVAST Software)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-12] (AVAST Software)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-12] (AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-06-21] (Intel Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-12] (AVAST Software)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0786D791-1EAB-4AA5-A394-8DC8DC11658C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2018-06-27] (HP Inc.)
Task: {1E628A75-E437-42E3-91F0-6F090C4E2784} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-05-04] (HP Inc.)
Task: {1ECE588C-1BAE-45E0-9201-073725E68E6D} - System32\Tasks\{195A54CF-97FA-4272-A1A7-2F3223E0FF16} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Common Files\Tamsing\uninstall.exe" -c shuz -f "C:\Program Files (x86)\Common Files\Tamsing\uninstall.dat" -a uninstallme 718EA0B8-A5D4-40C3-BC42-9D4231D2CD5E DeviceId=b23402c6-cb0c-9725-7210-69b8935ba8ab BarcodeId=51107003 ChannelId=3 DistributerName=APSFClickMeIn
Task: {256B4F27-7045-4DCB-8C02-166A73606A19} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-08] (Microsoft Corporation)
Task: {2B33AA0A-4AE6-4046-ACAC-6D122E1432C6} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2018-01-08] (Apple Inc.)
Task: {2FE451FC-688C-484E-AEEC-1E81A2D25935} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [2015-06-16] (Intel Corporation)
Task: {3A83B5A4-C492-4CF2-9AD6-4C0905E145A4} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-08] (Microsoft Corporation)
Task: {4D9E6E2C-966E-4C9F-9894-EB1D85C76DEF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.)
Task: {5AFCA30D-1320-47CE-AE8C-AC1E59597FC7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-05-04] (HP Inc.)
Task: {5B0114DF-E006-4622-88EA-6DC38E083EC6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-06-19] (Microsoft Corporation)
Task: {5B2CF95A-F831-4D4A-9683-AE5C67947080} - System32\Tasks\HPGenoobeReminder => C:\Program Files (x86)\Hewlett-Packard\HP Registration Service\HP GenOOBE\HPGenOOBE.exe
Task: {5C49206A-EDD5-46DB-85D1-E2B228D2A217} - System32\Tasks\HPCeeScheduleForjoedi => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] ()
Task: {66FAA48B-D9EC-4B02-A1E4-381ED0DFF754} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-06-28] (HP Inc.)
Task: {66FDACE8-01FA-4391-A65C-F7FCE3C527BD} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
Task: {73B280DE-3B7E-4E87-873E-7FC1ABC3D455} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-07-12] (AVAST Software)
Task: {8BEB49A4-2832-4673-BC10-B3257C6C3B88} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2018-07-12] (AVAST Software)
Task: {8C93C867-6E95-4CA8-8520-1C6239D1221C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-06-19] (Microsoft Corporation)
Task: {939D6C06-0A52-45C2-BCC0-754DE58C6EEC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {93D5F975-68E6-4C41-9968-B819303F17C7} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-06-19] (Microsoft Corporation)
Task: {A51B12A9-090A-46BD-92EE-12855DF7552F} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2017-11-27] ()
Task: {A6A0EE25-D917-4FB1-96CD-FCE95BF56C14} - System32\Tasks\Hewlett-Packard\HP CoolSense\HP CoolSense Start at Logon => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2015-05-21] (Hewlett-Packard Development Company, L.P.)
Task: {AA440403-A537-4352-B226-453815AEC805} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-01-21] ()
Task: {B10E0BEF-F9DA-488C-94FE-D28E07476026} - System32\Tasks\{AAF30115-55A7-4B37-99C8-5869E653C762} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Brunel University\Connect\Assistant\Uninstall.exe" -d "C:\Program Files (x86)\Brunel University\Connect\Assistant"
Task: {BC187A07-FC14-4553-A0E0-8F23CEF2FCDF} - System32\Tasks\Microsoft\Windows\Setup\Notifier => C:\WINDOWS\system32\Notifier.exe
Task: {BF4D314F-BA54-403A-8FC8-E90A79B2436D} - System32\Tasks\{AC0F50F6-DE1B-4BA4-BE92-E8992BD436AF} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Common Files\Tamsing\uninstall.exe" -c shuz -f "C:\Program Files (x86)\Common Files\Tamsing\uninstall.dat" -a uninstallme 718EA0B8-A5D4-40C3-BC42-9D4231D2CD5E DeviceId=b23402c6-cb0c-9725-7210-69b8935ba8ab BarcodeId=51107003 ChannelId=3 DistributerName=APSFClickMeIn
Task: {C81259B0-24A4-479A-8FD1-7E5486C3573C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-06-28] (HP Inc.)
Task: {CB1E49EB-BCD5-4115-8AFA-5D46646332D3} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-03-21] (Adobe Systems Incorporated)
Task: {CB690D1C-B3CD-43EC-B5B0-75A823CBD3AA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {E0E943A6-2461-451A-96F3-B71A65559824} - System32\Tasks\DropboxOEM => C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2015-06-19] ()
Task: {E324E7DB-8B15-46EC-B00F-BB8732405AC7} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {E35AD673-0075-4181-B5AD-DE92AAED09FA} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-01-21] ()
Task: {E66290E4-E985-4960-B848-41262E858985} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_113_Plugin.exe [2018-06-07] (Adobe Systems Incorporated)
Task: {EE8F3CD5-4CF3-4A69-B8C0-CC7E680EEEAA} - System32\Tasks\[removed] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-05-11] (Adobe Systems, Incorporated)
Task: {F044FC37-51C5-40C6-BE05-B7216D20571E} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [2015-06-05] (Intel Corporation)
Task: {F34C1276-5AA0-49D7-B2B0-6AF1DC3BEDBF} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [2015-06-16] (Intel Corporation)
Task: {F412091D-A073-427B-834D-E295A38867AB} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-06-07] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\HPCeeScheduleForjoedi.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2018-05-15 18:59 - 2018-05-15 18:59 - 000088888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2018-05-15 18:58 - 2018-05-15 18:58 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2018-06-10 15:19 - 2018-06-10 17:23 - 002297040 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2015-11-03 16:43 - 2014-04-14 19:59 - 000389896 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2018-04-12 00:34 - 2018-04-12 00:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll
2016-05-17 11:48 - 2018-01-21 05:50 - 008929480 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2018-04-12 00:34 - 2018-04-12 00:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-12 00:34 - 2018-04-12 00:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-06-12 21:52 - 2018-06-08 09:56 - 002185216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-06-26 13:28 - 2018-06-26 13:28 - 027126784 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18052.10711.0_x64__8wekyb3d8bbwe\Video.UI.exe
2018-06-26 13:28 - 2018-06-26 13:28 - 000306176 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18052.10711.0_x64__8wekyb3d8bbwe\SharedUI.dll
2018-06-26 13:28 - 2018-06-26 13:28 - 006735872 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18052.10711.0_x64__8wekyb3d8bbwe\EntCommon.dll
2017-09-26 12:12 - 2017-09-26 12:12 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18052.10711.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-06-26 13:28 - 2018-06-26 13:28 - 009360384 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18052.10711.0_x64__8wekyb3d8bbwe\EntPlat.dll
2018-07-12 19:50 - 2018-07-12 19:50 - 001922224 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.10314.31700.0_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll
2018-06-07 19:33 - 2018-06-07 19:33 - 027140608 _____ () C:\WINDOWS\system32\Macromed\Flash\NPSWF64_30_0_0_113.dll
2018-07-12 18:53 - 2018-07-12 18:53 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2018-07-12 18:53 - 2018-07-12 18:53 - 000483544 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2018-07-12 18:52 - 2018-07-12 18:52 - 000282840 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\98669029.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\98669029.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-07-10 12:04 - 2015-07-10 12:02 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1349798611-4138563247-4221669333-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\joedi\Pictures\images\Desktop\Deathvalleysky.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\…\StartupApproved\Run: => "iTunesHelper"
HKLM\…\StartupApproved\Run32: => "PowerDVD14Agent"
HKU\S-1-5-21-1349798611-4138563247-4221669333-1001\…\StartupApproved\Run: => "EPLTarget\P0000000000000000"
HKU\S-1-5-21-1349798611-4138563247-4221669333-1001\…\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1349798611-4138563247-4221669333-1001\…\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1349798611-4138563247-4221669333-1001\…\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-1349798611-4138563247-4221669333-1001\…\StartupApproved\Run: => "Skype for Desktop"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{9BA95944-DCCE-4AA7-9AB1-17FF41BA6045}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
FirewallRules: [{BA3E5EAD-B162-419C-B358-3DEFBF5C77BF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FBCB785F-F642-4839-BC15-842193F6BE05}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F48EAB8E-50FA-4131-8C07-17ADE1C24E8C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{418E2F52-F9BF-4CC3-813B-FCC8E939194F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{09C5504A-270C-4709-9398-0F65AEB20A20}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9AF3BA96-9B7E-44DC-889C-9A54C8DB0C78}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A1A65139-1930-4AA6-8DA2-0985655F7E49}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4B1EE682-9252-4C2E-A4FA-6DE10D4475BD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CE460343-DE0B-4C15-81D0-F94448920004}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2E07E7AF-BF80-4FE7-A33F-1839EC9C2370}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{54DBACE6-40FD-4D96-8DC3-6B3038BA9A1A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{297D69CA-9463-4E9F-A2B1-57F0825BBDEC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BD24DE42-6FAC-49A9-BCA5-E9ECD13D5727}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D8117EA0-5E6B-4C14-A95C-B9A4B76F4A9A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D83C3C6A-BB51-45DD-B4E4-8DD96A39CBC6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C5E5BA5D-0C42-4A9C-8849-A8AB9493BBEE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8F072FCE-0161-4174-BFD1-BC860F1CA796}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DCBFF9A0-3E32-42B1-8CB8-A0ADF2640853}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E97A7BC1-78A0-4F60-9247-F98DA609B967}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B14AFF53-E6AD-40B2-828C-A5C7A7295BE8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2AE57DCA-A2C6-462F-944F-D1EC8DC06495}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BA963767-34EB-4BF0-A257-5561DE377744}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EDD2BDAB-A081-495D-9595-450498483C26}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{87BB71F9-36B8-4C06-9264-AB69CEAEA411}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FC23573A-9411-4360-9175-50C05EAE8A9B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{38469EDB-B0DB-4FFB-A556-D91D9E16DC9A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F3381F21-0FE6-43D7-A639-8A43EE98BDB7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1A6D14AA-688D-4F8C-817E-8F362A1199BE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D5B2275A-0B93-4363-9883-6D3C733C562A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E1123943-5984-4EEC-89EE-D536C98F78DE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7C381355-CA56-41A3-ADF9-3E620E2BD074}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C3AED75A-D13C-4885-A0AA-E0D83B9F18C3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{66A01735-F33E-43FC-B9F4-047829A4DC44}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{724D090D-9416-4D8B-B560-FC5CB52A5C04}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EF9D7297-40CA-49CE-A477-5CA92B273FDE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7400950B-D2F2-4081-8B79-D9AB0610B6FD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3B987866-2D66-4F70-AB7F-65A206D93C44}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EF6CBEC5-E060-4A33-8626-B8F2FF7F0750}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E6A88AE6-27AA-4412-B32F-FAC8784DADE2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B86D1E36-06E0-487D-92B0-A80E31172BEC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1B99AF5D-2791-4DD2-B32A-535C30631CAD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C08DFB76-D631-486F-A201-771E16E93F76}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6A873798-96D3-40CE-9EC5-DEF8351AC502}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3B839D8D-D0C5-4152-8684-398E15FAC44D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0A1A5EE0-66DD-4A2D-9F02-22450D12C1C7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{419A70CA-2F12-419B-9E67-AF9CD1CAFF21}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{579B0CF1-2FC0-43CC-9D63-A795134AE6A4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{579609BB-69F3-40F1-A3A9-DA221661917B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E499663A-6EEC-4653-9E0C-D09C280889C5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AFA2BB5F-1505-4E77-AAC6-9F6BB0362830}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{14D62840-0FC5-4EF9-8FF8-741FA0EF62C2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{32CCEA97-1241-47AA-AD11-2BD92760C899}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{95A9BC4C-4674-44FB-B12A-640A8CE5D98C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9F6E3C77-EC00-4DE6-8906-68CD7C12D850}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E61330C9-4274-4ADE-A0E8-A393FB216689}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A0B3E0C5-7307-4963-89DE-DBA8326AEAAA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{79F325F2-C9E0-4483-9A6E-D93FEF498F1D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A1168FA7-C98F-4F6B-ADAE-ACBBB2DA6247}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CCEB528A-3877-4144-BBAA-B969FBFD0DCC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{425E10E9-0544-49AE-9CEB-E83EA1D1FE49}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D181E018-BC45-4D0C-9327-14EB7789374D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CB2EE038-856D-4682-B9AB-6533BF7D306A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B08A67B2-9FF2-448C-BD9F-DEB1D1B71512}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8930F2ED-3137-45CE-B186-EF6F4CC491EB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BD60AE50-2B7C-4895-8A45-57B395BDA159}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3FD02349-6020-4DD6-9234-1F4704D60D38}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{21B7ECED-C14D-485A-8E81-E0E63528EA47}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{99C4EA39-07B1-4186-8004-1E7F5506AAB2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7B15A583-D2B5-44A3-B51D-3A56E07081E7}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{5AA52A9B-C5F8-4452-B2A7-7E7A78BA1E05}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8F0CB04E-5D58-4001-9382-C2F34ACA59A4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4B5E93B8-66EA-45C7-AA01-5203C2AD718C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1D2ECF23-8F5B-4981-87E2-6DD3AA6497D8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4D1C9D7D-1CE8-4B91-84AA-899EFBBD8A64}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E882D22C-1C7E-40EC-8232-C8825983090A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{87142B1D-0B6D-4325-AD9E-ECAE0C5FF830}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A45D56E6-2374-4E90-89AE-B1808508B467}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3D37928C-8CE2-4AED-9567-3E9FD226D5FB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3649E3B6-F967-46A9-95FB-BB8120E19FB1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B35D9595-FB3A-4DB5-8195-38F83B2E33BD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{49F7D770-A1DE-4656-9E36-47C6A9259CE3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{995C4D95-B276-4616-8C34-0B596F58BF51}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4BFC663F-12DD-49CF-B2FD-0DC352F5AADC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2AC449B3-A51D-4174-99B9-9F999F753CDD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{806DBC12-7694-4D66-9299-D52DD7C78115}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4B2E356E-17AB-4FF5-A54E-E713D245286E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AAA4232B-639C-4062-85FC-A37C546BF0DC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{80EB1A5F-7C72-46C5-BDDD-721B36844376}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{14119FB7-3841-4294-A5A0-4C7E8F37FE4F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{ACF068DE-8CE9-43A4-9E26-9EF2D29C2585}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{01C910B9-154D-4B05-A1EF-5EFCE6B1CB00}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AB7B9356-4D5A-40D8-820E-66211F7ABDBA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DA64C3D9-3448-46BC-A5E5-4277A4816DDD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CC445E34-53EB-461B-B115-846E66A6F817}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{72AF0B27-6861-41D0-9135-064B024091B0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{79907523-0B95-45C0-9357-F606CDE21D93}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{89169DB4-C57D-4E2C-A1D5-D03CD0A427B1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D4826A55-399E-42BD-874B-424B36E5FDCB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{222EF0F5-1692-40DD-B424-FCCE2035F8C2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{94AB6963-E65C-4815-BAEE-85A89691075B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Pit People\pitpeople.exe
FirewallRules: [{B9F7591F-E33E-40E1-AA6A-CDF0EA563FE2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Pit People\pitpeople.exe
FirewallRules: [{D5F7CA16-2DFC-4251-8856-1B2B105414A7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1860D129-5312-4976-8F29-0FC5D52F2A91}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2097CD7A-A6F3-49F1-80A7-3C630BD9E52C}] => (Allow) C:\Program Files (x86)\IBM\SPSS\Statistics\23\WinWrapIDE.exe
FirewallRules: [{CD50ACC0-933F-415D-9C8F-7C32DC29932A}] => (Allow) C:\Program Files (x86)\IBM\SPSS\Statistics\23\WinWrapIDE.exe
FirewallRules: [{EF5B598A-0C2A-4118-A3F3-8E41DBBD0DB3}] => (Allow) C:\Program Files (x86)\IBM\SPSS\Statistics\23\stats.com
FirewallRules: [{6A97543C-C27B-4CDF-A33D-1FC102441A2E}] => (Allow) C:\Program Files (x86)\IBM\SPSS\Statistics\23\stats.exe
FirewallRules: [{7AB8200D-686A-4A8B-BE44-26EFA56CC841}] => (Allow) C:\Program Files (x86)\IBM\SPSS\Statistics\23\stats.com
FirewallRules: [{9A54E7E0-30DC-4CB0-8EA6-7BE211DC0464}] => (Allow) C:\Program Files (x86)\IBM\SPSS\Statistics\23\stats.exe
FirewallRules: [{3105DBF6-9451-46C3-A3DA-6449959813A7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DD0279CF-1F58-44D3-A3E1-D21C6751516A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B5541B7A-CF9A-4102-8801-A612D528F6BE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A977305D-4D1B-42FA-A07D-343DD6F16776}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{ABDE4727-FAA3-4AAF-A5AF-E1FB47F6C413}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1DC3EBFB-5A84-4B46-A481-01887B225BA1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A6A584F7-6BA2-4F9F-A6C7-A0B9A55B2A25}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{17D838F2-D60F-4C56-B47A-2998C98FBE9C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{22873F5A-B0C5-40AE-BEE3-DEF79A3E7124}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{26770DC6-222F-47A9-A88B-B031660554DB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{17A1F0EC-4B91-4BEA-AEFF-9E38790E463B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{2F30FD28-0101-4745-96BF-ED587B1D5F39}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{8130A45A-2C2D-4C35-B6F4-4294A22558E1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{28D26812-0449-4A94-ACD8-5FE51779FEB5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{33164015-E7F0-456B-A629-18256132A7DF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4AF4C1AF-8F69-4080-ADFD-1EFD83A505DD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{65049B8A-D482-476E-92EF-2DF455E37AF6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EDB77A24-CD99-493A-AD3C-2F80A34724DB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{884D4AB4-8750-40DB-B740-18494F5D54A3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F57DF1E5-CF32-4B4D-9DC2-32A894F214FF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{825CDDE0-306E-401E-89EF-4C41378A3790}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2BB8AB0F-E198-48E3-9D72-266FA95D02A4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6EF0034E-3A48-452D-BA4E-8FD6FCB49925}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A631B48C-C1F6-4BF8-BD9A-C75C1B337B70}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3AC48329-C362-450A-B329-4AEFD58C7F57}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D84CB0AB-B454-4C91-B88B-FFCB61B9A533}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{084E5648-9072-4AFF-97FE-6379903B2F9B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{ECBFA745-3DE0-4E50-8FE8-2F0DBEE21FA5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D88C68FE-948C-4D2F-86C7-A63D3FCD06F6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{ECF790F0-A44C-4F16-AC37-45833678DE3F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2173FDF1-E6A8-4F44-AD8F-147E290A2D45}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CF736D37-0FF8-4230-8D0A-54C57EDE413D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A9BD9FE4-345C-4219-B20D-14566A7AD5CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2580FDCD-442B-45C5-B2E9-BF657C1023DF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CAFA3778-76C0-435F-A1C3-88EEF9947838}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E70F5C81-1B8C-4AEA-BB92-C170F77042CD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4704B573-F6BB-44B3-BA82-7BAED2BC47CF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{94E0080E-10A1-4159-AC52-6BDDB1E6ACAC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B342D547-8125-4C41-8905-27E42FDD130B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9DED92FB-EE63-45F4-AB1C-50098A9D082D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5F00BF36-0631-432D-94C9-522F4D7DC13C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1CC51634-C991-4BAC-AE69-ABED0765027D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{952E41FE-803B-4CE0-86C5-36A5F3DE7C78}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 test\game\bin\win64\dota2.exe
FirewallRules: [{1CF5C857-BF62-4DD5-B376-40ED9E1DE4D8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 test\game\bin\win64\dota2.exe
FirewallRules: [{2D3960A6-ECC3-4EA0-95B5-F06FEADB99B5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F3E6A7E5-CB80-45DF-B398-DCFCE3115D97}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D9E3F98D-771C-41EB-984D-CA90B024A2CB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{0AB94A06-CCE7-4742-A57E-4A2D5655564A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{2B3AA582-131E-4114-81C4-32C537457D98}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Movie\PowerDVD Cinema\PowerDVDCinema.exe
FirewallRules: [{AB9CDBD1-2C61-4F8B-95D3-FDC331EB8BFB}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Movie\PowerDVDMovie.exe
FirewallRules: [{78CD835B-BC5E-460B-BC13-928F0CB5275F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe
FirewallRules: [{6B490A14-CBF7-4AA2-A106-83CF3C0D4D97}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Kernel\DMS\CLMSServerPDVD14.exe
FirewallRules: [{7908ECE0-3F0F-4B92-8B05-FE2F00D18514}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD.exe
FirewallRules: [{DC7343C0-5FD6-412B-9F55-B5A4CB29EEB1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6AE4CA32-80F7-43BF-A7CE-F5E771860EB6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{73564C04-F9F2-4196-8537-9306F6971411}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{28BF6E95-FC97-4125-92FF-CDDBA00D9233}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{B561844C-2A75-4AFE-974F-7DF7450D9837}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{5A17CA6E-CA6A-4396-9082-ACCA3B00D111}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6159F0D1-60FC-453F-A734-E03A24C6AED1}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{08FF7523-4025-45A0-AB3F-9023807F24F8}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{11DD8635-51F5-4616-B99C-E30764BC08C1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{C7B3C122-9A3D-4A6E-833D-1EE97F1091DA}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{F42F296D-2A96-40FB-8398-890E103FDA9E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{412D9111-FF18-4242-988D-C41A9AC74447}] => (Allow) c:\Program Files\CyberLink\PowerDirector12\PDR10.EXE
FirewallRules: [{D541E9C6-7B9C-431D-B465-428685A69D44}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
FirewallRules: [{9271A174-272D-4B6F-924C-55EEF0D17DE2}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\SmartAgentTest.exe
FirewallRules: [{70BD6A3D-13E1-4ACB-98D6-3B6C4D591599}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\Next\WirelessDisplay.exe
FirewallRules: [{AD61D697-917C-45E6-8819-51DB9955B913}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiAppOld.exe
FirewallRules: [{8C054E0D-FCEE-4788-A084-68F3EFFE299B}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{613EBC7A-2EF4-498C-A4EF-2F1EB449AC59}] => (Allow) C:\Users\joedi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{3C57D7F1-9104-4EF1-BF3E-F27D7BB1BC88}] => (Allow) C:\Users\joedi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{3F4D6E2F-603D-4FE5-86C0-5BF512D4ED34}] => (Allow) C:\Users\joedi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{2232473D-04FC-489E-801F-56A247A94D6B}] => (Allow) C:\Users\joedi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{DE31B80E-47E2-436F-8DE3-B08716D47F61}] => (Allow) C:\Users\joedi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{9F876CE4-BF9C-4E85-862F-2349D5F16C4E}] => (Allow) C:\Users\joedi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{F66F232D-7322-40E8-B4AA-D6F2E6159A22}C:\users\joedi\roaming\ygopro salvation server launcher\ygopro\application_ygopro.exe] => (Allow) C:\users\joedi\roaming\ygopro salvation server launcher\ygopro\application_ygopro.exe
FirewallRules: [UDP Query User{3556C216-7133-4E09-9F33-AE005CB11BEE}C:\users\joedi\roaming\ygopro salvation server launcher\ygopro\application_ygopro.exe] => (Allow) C:\users\joedi\roaming\ygopro salvation server launcher\ygopro\application_ygopro.exe
FirewallRules: [{8B15F080-30EE-4044-B349-1A566453453F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{1783026E-A21C-449A-A5F4-7140EB22ADC6}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{9D63BAB8-D83B-42C4-9398-27711A4AB5B7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{41D9CA23-9A7E-41E9-9B8B-C1B6B29A978C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{10E0AA8C-6101-4565-AD58-A786C027AAD1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\This is the Police\Police.exe
FirewallRules: [{4B1AAF08-D75D-42B9-B2F7-158CA53BD631}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\This is the Police\Police.exe
FirewallRules: [{D35203E3-DF49-4765-9F8B-DA727D96B920}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B72AC9A3-507F-48EF-B656-8485412C2B2A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1247BCAC-AB6B-41CF-8CC8-57DB1822E91A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E700B440-0E4F-415C-9C4C-92C041395CA7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{48F94153-D4FF-412E-9EA4-C6C1F0AB3CBE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8CE96314-7C35-45B3-9C1E-33B6A92C1B32}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AC8A03DC-44B2-4B68-B2A1-034BA3734D09}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E4DD7901-F537-46A7-A675-8DDA263216BB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0218AB86-6267-4D22-A73F-6136C0DDF12B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CA17759F-7E54-48CC-81BE-DB988E3D186F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F94204F0-CB04-47B2-9341-324562E963C8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{580B6592-A012-4BFB-8019-8FEB73AA2EE6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{83597E32-AA14-477F-91F9-8C0FF0673240}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AC943EDF-7695-4BF9-86A4-17F654B29160}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AE7CFD37-9A46-42B5-95AF-80B64A0C621F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2D455967-E782-44F3-A6AD-A683CE632833}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9BC4275F-3244-43F1-8A50-12231D428B2D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{60C1E556-D46A-4475-9680-1D2553EB3DAF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8EC4D6A2-34E6-4E70-990A-F1A91A657AA3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{46F1F487-F0C3-47FE-9F42-EDB8A0659DDD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{31F56ED1-D500-48E0-8E66-C1EF4223BE8D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5E5D00E6-F7BC-46AA-90DC-006789054174}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{80B49BC2-29FF-4E64-AE5B-3E159553AB9D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B79F3D9D-408B-47A9-A923-85FEB14DBBE5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2B4E3DE0-327C-479F-87AD-A654CB185E42}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{620DE391-05E3-4328-8546-7D6C0E0FBA8A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F20A3005-8181-468D-B1A7-2AB32359447A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EB943940-0972-4913-A028-4C6E9CFFFA97}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{76C1E102-D262-496C-8446-AB22FE3BD601}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{644E88BA-64E5-46E9-BAAD-5D2579E4B34B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0AEA51E3-89F5-4C74-994A-421CFC08BDF3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C27607E4-7798-45E7-88D8-3A9B19FAD88E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8AFA7DDB-2134-49E2-9CD5-A329E4B5E817}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{31BAD1D5-FE22-49EA-B5A8-558643284336}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{ADFAF027-5F65-40DC-AAA9-5C0D36E2F2B0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{328F33B9-73D7-4A2F-B9EC-A03D8DF5B6E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{47901F54-5B0E-4C34-AB45-0F19A0CBEE31}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B2832A9B-94A4-4559-9B49-B21F39E55447}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A638EAD4-8884-4905-AFA5-B26111077566}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8B297392-69D0-4EAA-8DEB-23BBB11A9860}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{74938E41-7294-4C31-838B-61D561607DC9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{43BC2903-E9FF-4674-A347-11420DC1ED87}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{06FF0427-E161-4E6A-927B-9FBE6E7520F1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6E5B3CB0-FC01-45A8-AB9E-96007C4F22CA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B7F8590B-0EB8-4FCB-8B9D-D14724CFAE0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A61DECE8-14B6-4118-AF21-CDD39FF528A5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E790429B-65EB-4CC7-A530-26E1A89E31BD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AD02489B-63D4-438C-B2DE-668BBC0F83F8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7D222FF8-0294-44C5-914E-A4A719122287}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4158F693-8482-4392-B7B4-0D58D05D3660}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{18D9D5D3-410D-4D96-8164-F4A6B8477903}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{83FA41EE-0D5B-4DF7-B73A-A5BA939F3E9D}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{6E9882B1-7BB0-4477-B0C1-45DB88660E82}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sakura Spirit\Sakura Spirit.exe
FirewallRules: [{E24909B4-1445-4FB6-890D-FEA35C315A6B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sakura Spirit\Sakura Spirit.exe
FirewallRules: [{52F3B73E-B85F-4EC4-9EE0-68592B35958C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C9E4BEE1-9583-4CB2-8CD7-E20BCCF8A3BD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{40076A4E-5CBC-4E59-AD38-25AAA3CBC277}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A41F5BA7-7153-4117-B03A-E29388879BE2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{67C228A9-E492-4FED-81B8-D8FB0CAF8F19}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{12F2671F-815B-44B2-A34C-E8E9D6504718}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{08EAD83D-EC6E-4ECF-9DB7-E507865F0FCF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CC8F7C62-9393-4772-A1FA-9ED13558D09D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0A19B3FE-9D56-4B9B-A49F-4D4C9A251E35}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B03363D8-4423-40B1-BDBD-D2D74F42FBC1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CD49B8B5-B8C3-458A-BB74-A355D1DFC664}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9FAFB8FD-918B-4724-9309-B982A5C49B1A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8F342361-1C5F-44D4-94EC-7B5953CA249A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1C5BD4AC-8AF3-4167-9F96-A4A12140E291}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{89245B13-2C23-4600-8F6D-2DAFB8399485}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe
FirewallRules: [{C34B45E0-25E2-48A8-B9BE-832EAD8C54C8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe
FirewallRules: [{1A235352-B75C-4181-9617-7F30EB0E3F98}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C91F7B40-5544-4326-9F4A-B4BCF9136EB4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D45BFB45-73D3-4C6C-8796-35703CE5F085}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2A6311EE-15D9-47DB-A874-09EF575CD966}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2E28F3B9-E3A9-4882-AC68-0D9F6F7BBA97}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9A6339A3-D867-4983-BA48-2D367BF6CC82}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BEB2BC70-664E-43E5-93E9-AE015148C43B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EA1E2291-68AA-4E58-A15F-55EC35A23962}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4AB19B63-EC2B-4A8C-AB27-DC3FDEFC19AF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{785D795B-17FA-41CE-837E-DB6FCEBE4FDC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D7042F96-F894-48F3-9D4D-C65A86CBDFE7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F2E1E60E-4A4E-49CF-80C3-F70862563012}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{886C7042-55BB-40C6-98B1-CE22A1E749A3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9A57A30E-2FB8-454F-8129-8AEFC6286D79}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{26661033-EA08-4B1A-A722-8845AFC2E51B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F4F548E9-2CA7-4BE5-9C00-03E4C34E8395}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{92A32477-B27C-4A90-902D-00A034AEF249}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FCC7CDF7-BF57-470C-B5F6-827D645F1549}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{41F2336C-5F6D-4915-AFBA-AE5A9F130BC9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A5D34670-8E79-4E27-8E1F-E1533AA92A4D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CAA24868-D6C0-4906-B480-25C401D3FEC1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D5342C79-0229-40A3-91CC-854C6392BC96}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6B4A3C1F-E48D-4C2B-9E95-A29181959809}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{44F06E76-5E60-4464-9A09-4D2FE6DD0609}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{91C14039-DA17-4A0E-A505-F5284931B24B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A15638E2-2DE5-454D-867E-C0BF210F8E00}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A3ABDB84-4FB7-4E6D-AE79-CD979205C040}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{77A38B28-AF3B-4E0D-9063-0722E1822B8D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{762CF5B7-55F4-45D5-938F-D73EA45B9405}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5A4CFD62-2063-438E-A74C-AEF8F4F07E4A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{25993173-1AA1-4588-8D6D-0B660C19D1B1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{39BB54F0-31F4-4084-ADE8-25B7B57C0B6E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EE4BAAF2-7078-45E5-A6CF-C06943975B8F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{47713402-E0BA-46EF-B7E0-4295C76AE504}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C4D4D19F-4DE3-4B6B-952A-5E5E35E2F6A2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FBE5B1E3-3AE0-41D1-963B-6454B84C1811}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F3D058C2-CECF-4DE8-AC0C-D50652819605}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{424592BE-F412-48B6-9B0C-8DDE30F6DDED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BB26A5F3-B1CD-4AAD-85D0-0DDEAAF7A67B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{18DC1E5F-9613-4E41-817C-04F7229CF1D3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7012FC8F-0D20-4643-9807-124AE8ADE58D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8D98A00C-F4D6-4634-916C-4BFC0D767A00}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4CB261E3-1576-4B3E-868D-CEA3ECA7688C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{255B84A8-F71B-41A4-80F9-710BCE255C3C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EB6CCB58-24C3-42E0-A569-16878603695E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{69FAA634-5148-42D3-97BE-700164D7C9D4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C7BB3900-C8D6-4E5F-9011-8D5D6E0E0142}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F6161585-FA9D-4BF4-A073-19B6C00FEBF4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{89C6F587-FE43-4FC7-BC27-F8D1500A5FFD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1E9515AD-EAD2-4359-9E0C-C45D1C56154F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D1423F6C-399E-409D-99C7-530B9F2325B5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1E8AEC79-B019-44CD-8B03-3AF91561E900}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5AA8BCE2-4A03-473F-9928-4F17D04D8D86}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{32E0BD6C-AC94-427C-BCDA-0ED5A377FAE3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8C46BFA5-3C53-4903-90FC-04D3DFF66A96}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FF4F2583-FA40-477A-95FC-4F7E53EBFD1E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{693B8A6B-07BE-44E0-9BB9-7F700BF1B822}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8FF42A07-1056-4F20-8313-CB766CCFE435}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{92AEDB3A-8E95-45AC-9E44-B81E705119A7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A7AC9838-49FE-45E2-A836-E4CEF1D8DD43}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DE5BD689-2EC1-4B2D-82DD-226B577A34F5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9D8150C6-AD3A-4DF7-AE5A-379670F006D3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F1461554-4254-4F8C-9B61-5F751A065E1D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3A8B58CF-2546-402F-8380-2D764FE281A5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B2222F65-1D43-459F-A79F-FB8B59C21F52}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{06505425-B74D-43AE-8203-2FB9FA46ECCF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F0FE9A22-A16E-4640-A65E-A1C59106A714}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E2AE14BE-9CA6-4771-9F94-FCFDD3F6340F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FB4CD6C1-A042-46C3-9B31-E55D96C2F8F2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{49F9EF7C-E509-4238-A1AE-DA60ABCD1F07}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6BC7422E-47C5-446A-BCEB-CF780552D91F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7E3CAE48-2AC2-4438-BD64-A9466B0F2898}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{079E28C1-86A1-4655-8493-A3D759F866AA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F9E1DD89-847B-4447-83F7-9F3339B10390}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0D35B020-F4B6-4559-B4DC-4978B8A41FD5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3E9879A4-9DFB-4817-8860-ECE6F26A5DE1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D910DC2F-63DE-4675-8987-B35714A9FE03}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8457DB90-9A37-4149-8405-C57022175954}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{066E5E5D-E221-45AB-B4BB-3DB1E26E9078}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1DB630E2-39FB-4E96-93BE-A0BE3EEA09DD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{37ED48D3-9FEE-4BA7-9D00-555FB6B5F2DC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Doki Doki Literature Club\DDLC.exe
FirewallRules: [{2F47B8AB-6B0B-41FF-9AEA-CE5789F89CE9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Doki Doki Literature Club\DDLC.exe
FirewallRules: [{298AF833-1460-4501-84C8-7DBD98B66BD3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FD10043D-D4ED-44D8-A306-0A6BC00E5F53}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7530E19E-BC3E-420C-9FE8-729927CAA5D9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{07C52954-2744-4EBF-88C1-CA172C5C0490}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4807CA83-D39D-46DE-B67F-386F17E853E2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2DFD7749-437C-4B9F-8503-A1FEFA8237C6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{04D115FD-F117-46A9-B559-595FAB1B55E4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B1D62E9F-6683-4C59-841B-D402D4C48E21}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3E9AAE0C-CA8B-48B6-A0DB-5B2606C44E87}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A7D06F66-232B-4C14-BFAB-3D8D704F3B29}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B7A3BAB8-39F2-4935-8500-94F395A3E0D0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{235032F0-FB1E-4D09-8A87-899397CD3AEE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{34195E53-FE84-41D8-AF3C-48E62DB964D9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DarkestDungeon\_windows\Darkest.exe
FirewallRules: [{28251382-370D-43CE-A990-D38B9FAF41C1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DarkestDungeon\_windows\Darkest.exe
FirewallRules: [{C11F3B98-40D9-464A-8ADB-130F4D78C80C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C78707BC-BA24-4AA6-917A-437895957526}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0A354539-957C-4EF9-B426-0D72E89788FE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7AA14749-06C1-454B-8EDC-BB0D934F4205}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FA069A8C-A8D6-4864-9C41-C5CC487DD96D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{23A60528-C61A-4B5B-A8FC-84EE86054624}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D2390746-D14A-43C9-9179-641CDD4C4729}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CB6255B7-9464-419B-BE26-A11A3B4F4029}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0C71CE3F-DCBA-41B5-9E68-6A016668FFEB}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
FirewallRules: [{A6860D01-9998-4506-AA01-6539FC6D6CB0}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
FirewallRules: [TCP Query User{04676679-101A-4616-BD62-64032053A460}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{B49A10F1-4B81-4F3C-B088-84ADD4C0EA41}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{90A2A9FE-81B1-4B40-A284-63FE97B1C7E3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5D1EA80D-1B3B-4799-B9EE-85D7C070ED0C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{1AB35587-D138-4386-9E92-50AB3182ED00}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{38FCC522-ACD1-4C24-8A6C-A68C70DFADC7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{54A1BC02-D232-4A04-AF9D-689762046887}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D5BA0005-9C30-4DF8-8204-3B0DC0711339}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8DB57FB6-BFD5-42C8-AB33-72723BFE17F1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1D07E6C9-B61A-46B5-8A8B-FDCBFA233165}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5B16D8CC-CB63-4FC0-A931-448784DF523C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4F23858A-5E78-480E-9266-FC4AC7A2AFB4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E72096E9-6F5D-4C74-B29B-D17CD1FA8188}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E14F7EDE-B803-41DC-8A27-AF035D74722B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7062775F-7424-4AA1-9EA1-28A8D6E73270}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F2820206-3223-4D00-BF02-B9DBC50D9510}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{255224FD-CC7F-41EE-906C-347B8DA2649D}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{18E791CA-E3BC-4364-B73D-D622F9914D95}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Transistor\x64\Transistor.exe
FirewallRules: [{30D3A56E-E2AE-4E0F-8AC0-8A3389A5E354}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Transistor\x64\Transistor.exe
FirewallRules: [{885A97C5-2217-4AD6-9F91-E66779CA62AD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{81F3AEC7-8B87-40D9-9533-58C728457103}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8F82F54F-74BB-43CD-AF0D-BA202281AC47}] => (Allow) C:\Program Files (x86)\BlueStacks\HD-Player.exe
FirewallRules: [{62B0D9E0-1DC7-4C8E-93E2-C51748BBC78C}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{033A3784-47A9-4B51-94E8-EF2B657217CC}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{D5B7D336-1E28-4C09-8049-200F58BB7947}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
FirewallRules: [{17A5D137-BBE4-4EAF-AF7A-BB45DACEB3AB}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{43942BC9-1463-4373-97ED-AC5A26C5F4A2}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{829F2350-1EE9-4CDC-985F-3FA2170ECC6D}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe

==================== Restore Points =========================

27-06-2018 18:47:29 Removed HP Support Solutions Framework
06-07-2018 18:38:24 Scheduled Checkpoint
10-07-2018 20:19:32 Windows Update
12-07-2018 03:55:27 Removed Skype™ 7.41

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (07/12/2018 08:59:10 PM) (Source: MsiInstaller) (EventID: 11721) (User: DESKTOP-800HF57)
Description: Product: RGSS-RTP Standard – Error 1721. There is a problem with this Windows Installer package. A program required for this install to complete could not be run. Contact your support personnel or package vendor. Action: _28CDB486_34DB_4675_A77B_AA0908059BA7, location: C:\Program Files (x86)\Common Files\Enterbrain\RGSS\Standard\Graphics.exe, command: /Uninstall

Error: (07/12/2018 08:43:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Local Hostname DESKTOP-800HF57.local already in use; will try DESKTOP-800HF57-2.local instead

Error: (07/12/2018 08:43:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister    4 DESKTOP-800HF57.local. Addr 192.168.1.39

Error: (07/12/2018 08:43:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.39:5353   16 DESKTOP-800HF57.local. AAAA FDDE:27C0:4C5B:0001:944C:7891:64D8:6B12

Error: (07/12/2018 08:43:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Resetting to Probing:   16 DESKTOP-800HF57.local. AAAA FE80:0000:0000:0000:944C:7891:64D8:6B12

Error: (07/12/2018 08:43:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.39:5353   16 DESKTOP-800HF57.local. AAAA FDDE:27C0:4C5B:0001:944C:7891:64D8:6B12

Error: (07/12/2018 08:43:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Resetting to Probing:    4 DESKTOP-800HF57.local. Addr 192.168.1.39

Error: (07/12/2018 08:43:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.39:5353   16 DESKTOP-800HF57.local. AAAA FDDE:27C0:4C5B:0001:944C:7891:64D8:6B12


System errors:
=============
Error: (07/13/2018 12:32:53 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/12/2018 08:53:22 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-800HF57)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9E175B6D-F52A-11D8-B9A5-505054503030}
 and APPID
{9E175B9C-F52A-11D8-B9A5-505054503030}
 to the user DESKTOP-800HF57\joedi SID (S-1-5-21-1349798611-4138563247-4221669333-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/12/2018 08:53:22 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-800HF57)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9E175B6D-F52A-11D8-B9A5-505054503030}
 and APPID
{9E175B9C-F52A-11D8-B9A5-505054503030}
 to the user DESKTOP-800HF57\joedi SID (S-1-5-21-1349798611-4138563247-4221669333-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/12/2018 08:53:08 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-800HF57)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9E175B6D-F52A-11D8-B9A5-505054503030}
 and APPID
{9E175B9C-F52A-11D8-B9A5-505054503030}
 to the user DESKTOP-800HF57\joedi SID (S-1-5-21-1349798611-4138563247-4221669333-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/12/2018 08:53:08 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-800HF57)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9E175B6D-F52A-11D8-B9A5-505054503030}
 and APPID
{9E175B9C-F52A-11D8-B9A5-505054503030}
 to the user DESKTOP-800HF57\joedi SID (S-1-5-21-1349798611-4138563247-4221669333-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/12/2018 08:53:03 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-800HF57)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9E175B6D-F52A-11D8-B9A5-505054503030}
 and APPID
{9E175B9C-F52A-11D8-B9A5-505054503030}
 to the user DESKTOP-800HF57\joedi SID (S-1-5-21-1349798611-4138563247-4221669333-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/12/2018 08:51:41 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/12/2018 08:20:44 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


Windows Defender:
===================================
Date: 2018-07-12 04:09:29.178
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {DFAA9DA2-B7CF-4BBE-BB81-4BC8081838EB}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2018-07-12 04:03:02.296
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {008D0EB9-B9CB-4D73-96ED-8E060982B3BE}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2018-07-08 02:20:06.577
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {4F43531B-82F7-456E-80DC-BC0A611D1DA6}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2018-06-29 20:32:00.089
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {A4D905EE-E7C6-4138-A3A7-A620D96A502E}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2018-06-29 20:06:02.240
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {95F7C6EC-F5CE-464F-8B0E-2ACA23EA053D}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2018-07-12 18:50:42.055
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.271.790.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.15000.2
Error code: 0x8024402c
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Date: 2018-07-12 17:12:34.320
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.271.790.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.15000.2
Error code: 0x8024402c
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Date: 2018-07-12 04:34:33.579
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.271.790.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.15000.2
Error code: 0x8024402c
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Date: 2018-07-12 03:40:32.092
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.271.790.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.15000.2
Error code: 0x8024402c
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Date: 2018-07-12 03:30:02.730
Description:
Windows Defender Antivirus has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted: Current
Error Code: 0x80070003
Error description: The system cannot find the path specified.
Signature version: 0.0.0.0;0.0.0.0
Engine version: 0.0.0.0

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-5157U CPU @ 2.50GHz
Percentage of memory in use: 82%
Total physical RAM: 8114.26 MB
Available physical RAM: 1410.82 MB
Total Virtual: 10290.26 MB
Available Virtual: 4572.48 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:913.44 GB) (Free:722.62 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:16.7 GB) (Free:1.95 GB) NTFS ==>[system with boot components (obtained from drive)]

\\?\Volume{b2bf93db-a430-47b2-9bd1-369f343eacea}\ () (Fixed) (Total:0.99 GB) (Free:0.44 GB) NTFS
\\?\Volume{c86a5d38-a31d-419c-ad55-49b12cf916cc}\ () (Fixed) (Total:0.25 GB) (Free:0.19 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: F10E4070)

Partition: GPT.

==================== End of Addition.txt ============================

 

I will run Farbar ASAP, though am wondering if it is riky in anyway to run it.

No it's not risky at all and wont do anything to your computer unless a script is created and carried out.

 

It's getting late here so I probably wont be back till morning.

Also, you should have an antivirus onboard, firewall active and if you feel it's necessary,  disconnect wireless/ethernet connection when the computer is not in use.

Also, you should have an antivirus onboard, firewall active and if you feel it's necessary,  disconnect wireless/ethernet connection when the computer is not in use.

 

Have always had both the former (though htiman said I needed to give it permissions in firewall, didn't know how as it didn't appear in firewall program list) will do the latter from here on out. Thanks immensley for your help, hopefully this makes me feel more at ease than glaring at regedit to see if there is anything foreign there.

Not much going on here

(uTorrent). I advise you avoid P2P file sharing programmes; they are a security risk which can make your computer susceptible to malware. File sharing networks are thoroughly infested with malware - worms, backdoor Trojans, IRCBots, and rootkits propagate via P2P file sharing networks, gaming, and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install malware. The best way to reduce the risk of infection is to avoid these types of web sites and P2P programmes. Please read the following articles for more information.
  • Risks of File-Sharing Technology
  • P2P Software User Advisories
  • More malware is traveling on P2P networks these days
~~~~~~~~~~~~~~~~~~~~~~~~~~~
Highlight the entire content of the quote box below and select Copy.

 

Start::
CloseProcesses:
CreateRestorePoint:
SearchScopes: HKLM-x32 -> {E0792105-41AB-418D-A3E7-08470AE8C501} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-1349798611-4138563247-4221669333-1001 -> {E0792105-41AB-418D-A3E7-08470AE8C501} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
2018-07-12 17:15 - 2018-06-08 10:29 - 001946328 _____ (Microsoft Corporation) C:\Users\joedi\AppData\Local\Temp\dllnt_dump.dll
Task: {E324E7DB-8B15-46EC-B00F-BB8732405AC7} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Emptytemp:
End::



Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.

~~~~~~~~~~~~~~~~~~~~~~~`

Follow the instructions in the thread below to run a scan with MBAR. Don't forget to update the database before launching the scan, and once launched, leave MBAR running and do not touch your computer until it is done scanning.

https://forums.malwarebytes.com/topic/198907-requested-resource-is-in-use-error-unable-to-start-malwarebytes/

Once MBAR is done scanning, removing threats and rebooting your computer, go in its MBAR folder, and copy/paste the content of the mbar-log-TODAYS-DATE.txt log in your next reply.


Please post these logs when finished.

Log for FRST Fixlog:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by [removed] (13-07-2018 14:43:36) Run:1
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
SearchScopes: HKLM-x32 -> {E0792105-41AB-418D-A3E7-08470AE8C501} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-1349798611-4138563247-4221669333-1001 -> {E0792105-41AB-418D-A3E7-08470AE8C501} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
2018-07-12 17:15 - 2018-06-08 10:29 - 001946328 _____ (Microsoft Corporation) C:\Users\joedi\AppData\Local\Temp\dllnt_dump.dll
Task: {E324E7DB-8B15-46EC-B00F-BB8732405AC7} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Emptytemp:

*****************

Processes closed successfully.
Restore point was successfully created.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{E0792105-41AB-418D-A3E7-08470AE8C501}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{E0792105-41AB-418D-A3E7-08470AE8C501} => not found
"HKU\S-1-5-21-1349798611-4138563247-4221669333-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E0792105-41AB-418D-A3E7-08470AE8C501}" => removed successfully
HKLM\Software\Classes\CLSID\{E0792105-41AB-418D-A3E7-08470AE8C501} => not found
C:\Users\joedi\AppData\Local\Temp\dllnt_dump.dll => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E324E7DB-8B15-46EC-B00F-BB8732405AC7}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E324E7DB-8B15-46EC-B00F-BB8732405AC7}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => not found

=========== EmptyTemp: ==========

BITS transfer queue => 7364608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 40326989 B
Java, Flash, Steam htmlcache => 341667359 B
Windows/system/drivers => 290464145 B
Edge => 567154 B
Chrome => 28601751 B
Firefox => 393788584 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 6656 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 11216 B
LocalService => 0 B
NetworkService => 111834 B
NetworkService => 0 B
joedi => 791947646 B

RecycleBin => 0 B
EmptyTemp: => 1.8 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 14:46:12 ====

 

MBAR log:

 

Malwarebytes Anti-Rootkit BETA 1.10.3.1001
www.malwarebytes.org

Database version:
  main:    v2018.07.13.03
  rootkit: v2018.07.13.03

Windows 10 x64 NTFS
Internet Explorer 11.112.17134.0
joedi :: DESKTOP-800HF57 [administrator]

13/07/2018 14:59:32
mbar-log-2018-07-13 (14-59-32).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 255346
Time elapsed: 33 minute(s), 34 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
 

OK looks good.

From this point I ask people to run an online scan, this is usually to check for remnants but, I don't think we will find anything.
I'll give you the choice.

Follow the instructions below to run a scan using the Emsisoft Emergency Kit.
  • Download the Emsisoft Emergency Kit and execute it. From there, click on the Install button to extract the program in the EEK folder;
  • Once the extraction is complete, the EEK folder will open. Right-click on [external image: G0tu5D9.png]start emergency kit scanner.exe and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • EEK will suggest that you run an online update before using the program. Click on Yes to launch it.
  • After the update, click on Malware Scan under 2. Scan and accept to let EEK detect PUPs (click on Yes).
  • Once the scan is complete, make sure that every item in the list is checked, and click on the Quarantine selected button;
  • If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
  • After the restart, open EEK again (in the C:\EEK folder);
  • This time, click on Logs;
  • From there, go under the Quarantine Log tab, and click on the Export button;
  • Save the log on your desktop, then open it, and copy/paste its content in your next reply;
Please tell me what the computer is doing now.

It didn't find anything, and nor did I find a quarantine log. My pc seems as healthy as it was before, and my mind is significantly at ease. U-torrent is now gone. Task manager looks regular too.

 

Thanks immensley for your help.

Good deal and your welcome.

I wanted to mention

I manually shutdown my pc and then turned off the router in my house. I then rebooted my pc

This was good to do. It didn't hurt anything and as of late there have been router attacks. I've done this myself and will probably do it again if the need arises.

************************
Let's remove tools and quarantine folders.
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
  • ************************************

    Tips, tricks,and advice.
    Programs like 🖼Click to load external image (eF2jhaz.png)UCheck, will scan your system for outdated programs, and help you identify them, as well as update them.
  • UCheck Documentation
  • Anti-Exploit/Anti-Ransomware
  • 🖼Click to load external image (zGy061p.png)Malwarebytes Anti-Exploit Beta - In a perpetual beta state, and entirely free
  • 🖼Click to load external image (S2NFpNw.png)HitmanPro.Alert - Free 30 day trial
  • 🖼Click to load external image (E8I37RF.png)CryptoPrevent - Has both a free and paid version
  • As for safe browsing habits, you can find tons of guides, tutorials, articles, etc. online that will highlight the basics you need to follow (only visit websites you trust, do not click on ads, do not download files from untrusted sources, use a password manager, always verify the URL of a website and make sure it's correctly typed, etc.), and even what you can do if you want to take it a step further (create a fake email address for spam emails, browse the web in a privacy mode, etc.). Here are a few:
  • The Ultimate Guide to Secure your Online Browsing: Chrome, Firefox and Internet Explorer on Heimdal Security
  • Seven Useful Habits For A Safer Internet on Kapsersky Blog
  • Tips for Secure Web Browsing: Cybersecurity 101 on VeraCode
  • Safe browsing habits on Internet Safety Project Wiki
  • As you can see, there are plenty of resources out there. Simply Googling "good browsing habits" or "safe browsing habits" should allow you to find a lot of them.

    Here are a few guides, tutorials, articles, etc. that you could read in order to learn more about computer protection and security to improve your current computer protection setup but also improve your good web browsing and computer usage practices :
  • Answers to common security questions - Best Practices by quietman7
  • How Malware Spreads - How did I get infected by quietman7
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams (aka Grinler)
  • How to Prevent Malware by miekiemoes
  • Tips & Advice on StaySafeOnline.org

  • created by Aura

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI