Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Computer overheating and Domino.exe is always on the tasks tab.


  • This topic is locked This topic is locked
9 replies to this topic

#1 Emrbldk

Emrbldk

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:11:16 AM

Posted 18 September 2017 - 04:19 PM

I feel like the virus eats up lots of RAM.
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-09-2017 01
Ran by Asce (administrator) on FIRE_FIST (19-09-2017 00:14:28)
Running from C:\Users\Asce\Desktop\New folder (2)
Loaded Profiles: Asce (Available Profiles: Asce)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avp.exe
() C:\Program Files (x86)\Gigabyte\EnergySaver2\des2svr.exe
() C:\Windows\SysWOW64\XSrvSetup.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Razer Inc) C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
(SoftEther VPN Project at University of Tsukuba, Japan.) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\Gigabyte\smart6\timelock\TimeMgmtDaemon.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avpui.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Flux Software LLC) C:\Users\Asce\AppData\Local\FluxSoftware\Flux\flux.exe
(Razer) C:\Program Files (x86)\Razer\Razer Cortex\RazerCortex.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe
(The CefSharp Authors) C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\PMRunner32.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\x64\PMRunner64.exe
() C:\Program Files (x86)\Razer\Razer Cortex\RazerGamecasterEngine.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\Gigabyte\smart6\timelock\AlarmClock.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\FPSRunner32.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\x64\FPSRunner64.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzFpsApplet\RzFpsApplet.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe
(Razer, Inc.) C:\Users\Asce\AppData\Local\Razer\InGameEngine\cache\RzFpsApplet\rzcefrenderprocess.exe
(Razer, Inc.) C:\Users\Asce\AppData\Local\Razer\InGameEngine\cache\RzFpsApplet\rzcefrenderprocess.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksdeui.exe
(Razer, Inc.) C:\Users\Asce\AppData\Local\Razer\InGameEngine\cache\RzFpsApplet\rzcefrenderprocess.exe
(Razer, Inc.) C:\Users\Asce\AppData\Local\Razer\InGameEngine\cache\RzFpsApplet\rzcefrenderprocess.exe
(Valve Corporation) C:\Steam\Steam.exe
(Valve Corporation) C:\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera_crashreporter.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Opera Software) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2398776 2016-06-15] (NVIDIA Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM\...\Run: [VMSnap3] => C:\Windows\VMSnap3.exe [49152 2006-07-18] (Vimicro)
HKLM\...\Run: [Domino] => C:\Windows\Domino.exe [49152 2006-07-04] ()
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2009-11-20] (NEC Electronics Corporation)
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\Run: [f.lux] => C:\Users\Asce\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-24] (Flux Software LLC)
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\Run: [RazerCortex] => C:\Program Files (x86)\Razer\Razer Cortex\CortexLauncher.exe [224752 2017-03-15] (Razer Inc.)
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\Run: [Spotify Web Helper] => C:\Users\Asce\AppData\Roaming\Spotify\SpotifyWebHelper.exe [777840 2017-09-16] (Spotify Ltd)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\..\Interfaces\{4D2E0197-CA2D-4178-B8E2-4533F530AAC3}: [DhcpNameServer] 139.179.30.24 139.179.10.13
Tcpip\..\Interfaces\{5F6838D2-A6A9-48BB-8B11-857F26B81C15}: [DhcpNameServer] 139.179.30.24 139.179.10.13
Tcpip\..\Interfaces\{DA2D582E-7FDF-4CC8-A295-2DB4EC3588B7}: [DhcpNameServer] 139.179.30.24 139.179.10.13
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\IEExt\ie_plugin.dll [2016-12-26] (AO Kaspersky Lab)
BHO-x32: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\IEExt\ie_plugin.dll [2016-12-26] (AO Kaspersky Lab)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-03-28] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-28] (Oracle Corporation)
Toolbar: HKLM - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\IEExt\ie_plugin.dll [2016-12-26] (AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\IEExt\ie_plugin.dll [2016-12-26] (AO Kaspersky Lab)
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\FFExt\light_plugin_firefox\addon.xpi [2016-12-26]
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll [2017-03-24] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll [2017-03-24] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll [2011-03-09] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-01-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-01-23] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-09] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-09] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-08-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1292172697-4276861399-4271014393-1000: @octoshape.com/Octoshape Streaming Services,version=1.0 -> C:\Users\Asce\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1702150-0-npoctoshape.dll [2017-02-15] (Octoshape ApS)
FF Plugin ProgramFiles/Appdata: C:\Users\Asce\AppData\Roaming\mozilla\plugins\npoctoshape.dll [2014-07-30] (Octoshape ApS)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR StartupUrls: Default -> "hxxp://www.google.com.tr/"
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default [2017-09-19]
CHR Extension: (Google Translate) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-11-18]
CHR Extension: (Google Slides) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-03-25]
CHR Extension: (Google Docs) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-05]
CHR Extension: (Google Drive) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (YouTube) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Google Search) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (ZenMate VPN - Best Cyber Security & Unblock) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2017-08-26]
CHR Extension: (Google Sheets) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-03-25]
CHR Extension: (Kaspersky Protection) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib [2017-03-25]
CHR Extension: (Google Docs Offline) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-24]
CHR Extension: (Document online) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdogoocenkoogpajficlnleblfoelph [2015-09-25]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2017-09-19]
CHR Extension: (TwitchAlerts Stream Labels) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgmggmdngboajiakmbpdknfpdelbjbcg [2017-03-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-26]
CHR Extension: (Enhanced Steam) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg [2017-09-19]
CHR Extension: (Gmail) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
CHR Extension: (Chrome Media Router) - C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-26]
CHR HKLM\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
 
Opera: 
=======
StartMenuInternet: (HKLM) Operabeta - C:\Program Files\Opera beta\Launcher.exe
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 AVP17.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avp.exe [241544 2016-06-28] (AO Kaspersky Lab)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1533448 2017-09-14] ()
R2 DES2 Service; C:\Program Files (x86)\Gigabyte\EnergySaver2\des2svr.exe [68136 2009-06-17] ()
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [236832 2015-12-25] (EasyAntiCheat Ltd)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [72304 2010-01-19] ()
S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\vssbridge64.exe [77328 2016-06-28] (AO Kaspersky Lab)
R2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (AO Kaspersky Lab)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1881144 2016-06-15] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3634232 2016-06-15] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2522680 2016-06-15] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2015-12-08] (Electronic Arts)
R2 Razer Game Manager Service; C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe [146256 2017-02-23] (Razer Inc)
R2 RzActionSvc; C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe [183680 2017-03-14] (Razer Inc.)
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [252176 2017-03-15] (Razer Inc.)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [176264 2015-05-28] (Sandboxie Holdings, LLC)
R2 SEVPNCLIENT; C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [5189176 2015-05-02] (SoftEther VPN Project at University of Tsukuba, Japan.)
R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5491984 2015-05-20] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21544 2010-04-22] ()
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW76.sys [94720 2014-06-21] (Advanced Micro Devices) [File not signed]
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [238936 2016-06-10] (AO Kaspersky Lab)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-07-20] (Disc Soft Ltd)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-04-15] ()
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2017-05-09] ()
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [554416 2016-06-02] (AO Kaspersky Lab)
R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [63920 2016-06-08] (AO Kaspersky Lab)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [86352 2016-06-15] (AO Kaspersky Lab)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [78216 2016-06-01] (AO Kaspersky Lab)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [195296 2017-04-12] (AO Kaspersky Lab)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [314864 2017-04-12] (AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1035480 2017-04-12] (AO Kaspersky Lab)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [57936 2016-12-26] (AO Kaspersky Lab)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [52144 2016-05-19] (AO Kaspersky Lab)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [41648 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [45488 2016-06-01] (AO Kaspersky Lab)
R3 kltap; C:\Windows\System32\DRIVERS\kltap.sys [52152 2016-06-07] (The OpenVPN Project)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [75696 2016-05-18] (AO Kaspersky Lab)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [135904 2017-03-25] (AO Kaspersky Lab)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [199392 2017-03-25] (AO Kaspersky Lab)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [251832 2017-09-18] (Malwarebytes)
S3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82208 2017-04-12] (Malwarebytes)
S3 msvad_simple; C:\Windows\System32\solicall.sys [40664 2010-10-30] (SoliCall)
R3 Neo_braz; C:\Windows\System32\DRIVERS\Neo_0005.sys [28640 2015-05-02] (SoftEther VPN Project at University of Tsukuba, Japan.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28216 2016-06-15] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
S3 qcusbser; C:\Windows\System32\DRIVERS\qcusbser.sys [254520 2017-03-15] (QUALCOMM Incorporated)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [137840 2016-10-08] (Razer, Inc.)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [188552 2015-05-28] (Sandboxie Holdings, LLC)
S3 sshid; C:\Windows\System32\DRIVERS\sshid.sys [45928 2017-06-29] (SteelSeries ApS)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-03-28] ()
S3 VASDeviceDrm; C:\Windows\System32\drivers\vasdDev.sys [1454896 2015-07-21] (ShiningMorning Inc.)
S3 vvftav303; C:\Windows\System32\drivers\vvftav303.sys [308096 2007-06-23] (Vimicro Corporation)
S3 ZSMC0303; C:\Windows\System32\Drivers\usbVM303.sys [1494656 2007-03-25] (Vimicro Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-09-16 16:56 - 2017-09-16 16:57 - 000000000 ____D C:\Users\Asce\AppData\Roaming\fretsonfire
2017-09-16 16:56 - 2017-09-16 16:56 - 000001069 _____ C:\Users\Asce\Desktop\Frets on Fire.lnk
2017-09-16 16:56 - 2017-09-16 16:56 - 000000000 ____D C:\Users\Asce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Frets on Fire
2017-09-16 16:56 - 2017-09-16 16:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Frets on Fire
2017-09-16 16:56 - 2017-09-16 16:56 - 000000000 ____D C:\Program Files (x86)\Frets on Fire
2017-09-15 21:24 - 2017-09-15 21:24 - 000000000 ____D C:\Users\Asce\Documents\Aspyr
2017-09-15 21:24 - 2017-09-15 21:24 - 000000000 ____D C:\Users\Asce\AppData\Local\Aspyr
2017-09-15 21:21 - 2017-09-15 21:21 - 665962990 _____ C:\Windows\MEMORY.DMP
2017-09-15 21:21 - 2017-09-15 21:21 - 000398696 _____ C:\Windows\Minidump\091517-34788-01.dmp
2017-09-15 21:21 - 2017-09-15 21:21 - 000000000 ____D C:\Windows\Minidump
2017-09-15 20:25 - 2017-09-15 20:25 - 000001125 _____ C:\Users\Public\Desktop\Play Guitar Hero World Tour.lnk
2017-09-15 20:11 - 2017-09-15 20:11 - 000000000 ____D C:\Program Files (x86)\Aspyr
2017-09-15 19:57 - 2008-07-12 08:18 - 004992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2017-09-15 19:57 - 2008-07-12 08:18 - 003851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2017-09-15 19:57 - 2008-07-12 08:18 - 001942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2017-09-15 19:57 - 2008-07-12 08:18 - 001493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2017-09-15 19:57 - 2008-07-12 08:18 - 000540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2017-09-15 19:57 - 2008-07-12 08:18 - 000467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2017-09-15 17:47 - 2017-09-15 19:47 - 000000000 ____D C:\Program Files (x86)\PCSX2 1.4.0
2017-09-15 17:47 - 2017-09-15 17:47 - 000001951 _____ C:\Users\Public\Desktop\PCSX2 1.4.0.lnk
2017-09-15 17:47 - 2017-09-15 17:47 - 000000000 ___HD C:\Windows\msdownld.tmp
2017-09-15 17:47 - 2017-09-15 17:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSX2
2017-09-15 17:29 - 2017-09-15 17:30 - 017837152 _____ C:\Users\Asce\Downloads\pcsx2-1.4.0-setup.exe
2017-09-14 23:41 - 2017-09-14 23:41 - 000002150 _____ C:\Users\Public\Desktop\Zoom.lnk
2017-09-14 23:41 - 2017-09-14 23:41 - 000002051 _____ C:\Users\Public\Desktop\HAmcap.lnk
2017-09-14 23:41 - 2017-09-14 23:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A4 TECH PC Camera H
2017-09-14 23:41 - 2006-07-18 16:15 - 000049152 _____ (Vimicro) C:\Windows\vmsnap3.exe
2017-09-14 23:41 - 2006-07-04 14:16 - 000049152 _____ () C:\Windows\Domino.exe
2017-09-14 23:40 - 2017-09-14 23:40 - 000000000 ____D C:\Program Files (x86)\A4 tech
2017-09-14 23:40 - 2010-02-08 11:18 - 000102400 _____ (Vimicro) C:\Windows\SysWOW64\vvftprpav303.ax
2017-09-14 23:40 - 2010-02-08 10:39 - 000360448 _____ (Vimicro) C:\Windows\SysWOW64\VM303Prp.Ax
2017-09-14 23:40 - 2007-03-02 13:22 - 000046592 _____ (Vimicro Cooperation) C:\Windows\SysWOW64\VvFtCtrl.dll
2017-09-14 23:40 - 2006-03-14 14:28 - 000172032 _____ (Microsoft Corporation) C:\Windows\amcap.exe
2017-09-14 23:40 - 2004-04-06 17:40 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2017-09-14 23:40 - 2003-12-30 16:13 - 000348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2017-09-14 23:39 - 2017-09-14 23:39 - 056193803 _____ C:\Users\Asce\Downloads\A4Tech-PK-Serisi-Webcam-Driver-tamindir.zip
2017-09-01 17:18 - 2017-09-01 17:18 - 000000199 _____ C:\Users\Asce\Desktop\Dota 2.url
2017-08-30 22:08 - 2017-08-30 22:08 - 000000000 ____D C:\Users\Asce\AppData\Roaming\.mono
2017-08-30 22:08 - 2017-08-30 22:08 - 000000000 ____D C:\Users\Asce\AppData\LocalLow\Blizzard Entertainment
2017-08-30 22:08 - 2017-08-30 22:08 - 000000000 ____D C:\ProgramData\.mono
2017-08-30 19:47 - 2017-08-30 19:47 - 000000000 ____D C:\Users\Asce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D C:\1a485692c6c0d46bdbc168
2017-08-27 02:08 - 2017-08-27 02:08 - 000000202 _____ C:\Users\Asce\Desktop\Age of Mythology Extended Edition.url
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-04-03 19:37 - 2011-04-12 11:28 - 000000000 ___RD C:\Users\Public\Recorded TV
2020-04-03 19:37 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\registration
2017-09-19 00:14 - 2017-04-23 15:16 - 000000000 ____D C:\Users\Asce\Desktop\New folder (2)
2017-09-19 00:14 - 2017-03-24 15:08 - 000000000 ____D C:\FRST
2017-09-19 00:10 - 2009-07-14 07:45 - 000023440 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-09-19 00:10 - 2009-07-14 07:45 - 000023440 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-09-18 23:48 - 2014-07-13 01:17 - 000000000 ____D C:\Steam
2017-09-18 23:42 - 2014-11-20 23:11 - 000000000 ____D C:\Users\Asce\AppData\Local\Battle.net
2017-09-18 23:25 - 2017-03-25 10:06 - 000003032 _____ C:\Windows\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2017-09-18 23:14 - 2016-01-05 00:02 - 000000000 ____D C:\Program Files (x86)\Opera
2017-09-18 23:12 - 2017-03-25 07:36 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2017-09-18 23:12 - 2014-11-20 23:12 - 000000000 ____D C:\Program Files (x86)\Hearthstone
2017-09-18 23:12 - 2014-11-20 23:11 - 000000000 ____D C:\Program Files (x86)\Battle.net
2017-09-18 23:11 - 2017-07-27 13:24 - 000000000 ____D C:\Program Files\Opera beta
2017-09-18 23:10 - 2015-05-02 16:26 - 000000000 ____D C:\Program Files\SoftEther VPN Client
2017-09-18 23:09 - 2017-03-24 13:09 - 000251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-09-18 23:09 - 2017-03-24 12:35 - 000000000 ____D C:\ProgramData\NVIDIA
2017-09-18 23:09 - 2015-05-18 15:56 - 000025640 _____ (Windows ® Server 2003 DDK provider) C:\Windows\gdrv.sys
2017-09-18 23:09 - 2009-07-14 08:08 - 000032562 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-09-18 23:09 - 2009-07-14 08:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-09-18 23:02 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\NDF
2017-09-16 16:42 - 2015-10-10 16:41 - 000000000 ____D C:\Users\Asce\AppData\Local\Spotify
2017-09-16 16:41 - 2015-10-10 16:41 - 000000000 ____D C:\Users\Asce\AppData\Roaming\Spotify
2017-09-15 20:25 - 2009-07-14 08:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-09-15 18:45 - 2015-11-10 22:14 - 000000000 ____D C:\Users\Asce\AppData\Roaming\Azureus
2017-09-15 18:41 - 2014-07-20 17:41 - 000000000 ____D C:\Users\Asce\AppData\Roaming\uTorrent
2017-09-15 17:47 - 2014-07-19 22:53 - 000000000 ____D C:\Windows\SysWOW64\directx
2017-09-14 23:41 - 2015-05-18 15:42 - 000000000 ____D C:\ProgramData\InstallShield
2017-09-14 23:41 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\inf
2017-09-14 23:40 - 2014-11-09 02:08 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-09-14 23:06 - 2015-07-18 17:11 - 000000000 ____D C:\Users\Asce\AppData\Local\ElevatedDiagnostics
2017-09-14 23:05 - 2017-07-27 13:25 - 000003846 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1501151123
2017-09-14 22:43 - 2014-07-25 02:10 - 000018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2017-09-01 21:03 - 2017-03-29 16:25 - 000000000 ____D C:\Users\Asce\AppData\Roaming\discord
2017-08-31 18:37 - 2014-07-23 22:39 - 000000000 ____D C:\Users\Asce\AppData\Roaming\Mumble
2017-08-31 15:12 - 2017-03-24 16:10 - 000000000 ____D C:\Users\Asce\Documents\Overwatch
2017-08-30 19:46 - 2017-03-29 16:25 - 000000000 ____D C:\Users\Asce\AppData\Local\Discord
2017-08-30 17:22 - 2017-07-25 15:34 - 000000942 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk
2017-08-28 22:46 - 2014-07-12 09:44 - 000002203 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-08-27 23:04 - 2014-11-20 23:11 - 000000000 ____D C:\Users\Asce\AppData\Roaming\Battle.net
2017-08-27 23:03 - 2014-11-20 23:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2017-08-27 16:35 - 2015-02-09 00:31 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-08-26 21:24 - 2014-11-20 23:11 - 000000000 ____D C:\Users\Asce\AppData\Local\Blizzard Entertainment
2017-08-26 21:07 - 2015-11-10 23:49 - 000000000 ____D C:\Users\Asce\AppData\Local\CrashDumps
2017-08-26 16:50 - 2017-03-24 12:43 - 000000000 ____D C:\Users\Asce\AppData\Local\NVIDIA Corporation
2017-08-26 15:11 - 2017-03-24 12:58 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
 
==================== Files in the root of some directories =======
 
2017-04-13 14:14 - 2017-04-13 14:14 - 000000000 ____H () C:\ProgramData\DP45977C.lfl
 
Some files in TEMP:
====================
2017-09-15 21:23 - 2017-09-16 17:01 - 000204800 _____ (Sony DADC Austria AG) C:\Users\Asce\AppData\Local\Temp\drm_dyndata_7400006.dll
2017-09-15 18:45 - 2017-09-15 18:45 - 000035680 _____ () C:\Users\Asce\AppData\Local\Temp\i4jdel0.exe
2017-07-24 14:06 - 2017-07-24 14:07 - 003051288 _____ () C:\Users\Asce\AppData\Local\Temp\npp.7.4.2.Installer.exe
2017-04-23 02:03 - 2017-04-23 02:04 - 057547224 _____ (Skype Technologies S.A.) C:\Users\Asce\AppData\Local\Temp\SkypeSetup.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-09-15 20:34
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-09-2017 01
Ran by Asce (19-09-2017 00:15:17)
Running from C:\Users\Asce\Desktop\New folder (2)
Windows 7 Home Premium Service Pack 1 (X64) (2014-07-12 06:23:31)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1292172697-4276861399-4271014393-500 - Administrator - Disabled)
Asce (S-1-5-21-1292172697-4276861399-4271014393-1000 - Administrator - Enabled) => C:\Users\Asce
Guest (S-1-5-21-1292172697-4276861399-4271014393-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1292172697-4276861399-4271014393-1002 - Limited - Enabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Kaspersky Anti-Virus (Disabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AS: Malwarebytes (Disabled - Out of date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Kaspersky Anti-Virus (Disabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
@BIOS Ver.2.06 (HKLM-x32\...\{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}) (Version: 2.06 - GIGABYTE)
µTorrent (HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\uTorrent) (Version: 3.5.0.43916 - BitTorrent Inc.)
A4 TECH PC Camera H (HKLM\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D303B}) (Version:  - )
A4 TECH PC Camera H (HKLM-x32\...\{CE3B8E96-B0AF-4871-9178-1519B58E3A93}) (Version: 2007.11.12 - A4 TECH)
Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.127 - Adobe Systems Incorporated)
Adobe Flash Player 25 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 25.0.0.127 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.22) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.22 - Adobe Systems Incorporated)
Aegisub 3.0.2 (HKLM-x32\...\{24BC8B57-716C-444F-B46B-A3349B9164C5}_is1) (Version: 3.0.2 - Aegisub Team)
Age of Empires II: HD Edition (HKLM-x32\...\Steam App 221380) (Version:  - Hidden Path Entertainment, Ensemble Studios)
Age of Mythology: Extended Edition (HKLM\...\Steam App 266840) (Version:  - SkyBox Labs)
AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AoE II HD Compatibility Patch version 1.0c (HKLM-x32\...\AoE II HD Compatibility Patch_is1) (Version: 1.0c - )
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.12 - Michael Tippach)
AutoGreen B09.1014.2 (HKLM-x32\...\{C75FAD21-EC08-42F3-92D6-C9C0AB355345}) (Version: 1.00.0000 - GIGABYTE) Hidden
AutoGreen B09.1014.2 (HKLM-x32\...\InstallShield_{C75FAD21-EC08-42F3-92D6-C9C0AB355345}) (Version: 1.00.0000 - GIGABYTE)
Bastion (HKLM-x32\...\Steam App 107100) (Version:  - Supergiant Games)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 1942™ (HKLM-x32\...\{5BE7BD06-512B-43bf-AD78-3BD2A5F5F7B3}) (Version: 1.6.20.0 - Electronic Arts)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Beat Hazard (HKLM-x32\...\Steam App 49600) (Version:  - Cold Beam Games)
Besiege (HKLM-x32\...\Steam App 346010) (Version:  - Spiderling Studios)
Brawlhalla (HKLM-x32\...\Steam App 291550) (Version:  - Blue Mammoth Games)
Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version:  - Cheat Engine)
Command & Conquer™ Red Alert 2 and Yuri’s Revenge (HKLM-x32\...\{F5275D1C-D133-486D-8F07-D6C571F0A8EC}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Commandos 2: Men of Courage (HKLM-x32\...\Steam App 6830) (Version:  - Pyro Studios)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
DayZ (HKLM-x32\...\Steam App 221100) (Version:  - Bohemia Interactive)
Dead Island: Epidemic (HKLM-x32\...\Steam App 222900) (Version:  - Stunlock Studios)
Dead Space™ 3 (HKLM-x32\...\{D4329609-4102-4F8C-B83F-7FE024EEA314}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Deckadance 2 (HKLM-x32\...\Deckadance 2) (Version: 2.0 - Image-Line)
DES 2.0 (HKLM-x32\...\{675F86A8-E093-4002-87D5-915CC2C45571}) (Version: 1.00.0000 - Gigabyte)
Discord (HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\Discord) (Version: 0.0.298 - Discord Inc.)
Don't Starve Together Beta (HKLM-x32\...\Steam App 322330) (Version:  - Klei Entertainment)
Dota 2 (HKLM\...\Steam App 570) (Version:  - Valve)
Dota 2 Workshop Tools Alpha (HKLM-x32\...\Steam App 316570) (Version:  - )
Easy Tune 6 B10.0420.1 (HKLM-x32\...\{457D7505-D665-4F95-91C3-ECB8C56E9ACA}) (Version: 1.00.0000 - GIGABYTE) Hidden
Easy Tune 6 B10.0420.1 (HKLM-x32\...\InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}) (Version: 1.00.0000 - GIGABYTE)
Emily is Away (HKLM-x32\...\Steam App 417860) (Version:  - Kyle Seeley)
Europa Universalis IV (HKLM-x32\...\Steam App 236850) (Version:  - Paradox Development Studio)
f.lux (HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\Flux) (Version:  - )
Fallout 4 (HKLM-x32\...\Fallout 4_is1) (Version:  - )
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
FileZilla Client 3.14.1 (HKLM-x32\...\FileZilla Client) (Version: 3.14.1 - Tim Kosse)
Firewatch (HKLM\...\Steam App 383870) (Version:  - Campo Santo)
FL Studio 12 (HKLM-x32\...\FL Studio 12) (Version:  - Image-Line)
FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version:  - Image-Line)
Frets On Fire (HKLM-x32\...\Frets on Fire) (Version: 1.3.110-win32 - )
FTL: Faster Than Light (HKLM-x32\...\Steam App 212680) (Version:  - Subset Games)
Geometry Dash (HKLM-x32\...\Steam App 322170) (Version:  - RobTop Games)
Gigabyte Raid Configurer (HKLM-x32\...\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.00.0001 - GIGABYTE Technologies, Inc.)
Goat Simulator (HKLM-x32\...\Steam App 265930) (Version:  - Coffee Stain Studios)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 60.0.3112.113 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
GPU Temp version 1.0 (HKLM-x32\...\{8C8711FD-0FC8-4801-B33E-ED19BB0350B1}_is1) (Version: 1.0 - gputemp.com)
Grand Theft Auto III (HKLM-x32\...\Steam App 12100) (Version:  - Rockstar Games)
Grand Theft Auto V (HKLM-x32\...\{E01FA564-2094-4833-8F2F-1FFEC6AFCC46}) (Version: "1.00.0000" - Rockstar Games)
Grand Theft Auto: Vice City (HKLM-x32\...\Steam App 12110) (Version:  - Rockstar Games)
Grim Fandango Remastered (HKLM-x32\...\Steam App 316790) (Version:  - Double Fine Productions)
GS Auto Clicker (HKLM-x32\...\GS Auto Clicker_is1) (Version: V3.1.3 - goldensoft.org)
Guacamelee! Gold Edition (HKLM-x32\...\Steam App 214770) (Version:  - DrinkBox Studios)
Guacamelee! Super Turbo Championship Edition (HKLM-x32\...\Steam App 275390) (Version:  - DrinkBox Studios)
Guild Wars 2 (HKLM-x32\...\Guild Wars 2) (Version:  - NCsoft Corporation, Ltd.)
Guitar Hero World Tour (HKLM-x32\...\{A126E617-63F0-4E57-BFA4-7190F5845C39}) (Version: 1.0 - Aspyr)
Guns of Icarus Online (HKLM-x32\...\Steam App 209080) (Version:  - Muse Games)
H1Z1 (HKLM-x32\...\Steam App 295110) (Version:  - Daybreak Games)
Half-Life 2 (HKLM-x32\...\Steam App 220) (Version:  - Valve)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version:  - Blizzard Entertainment)
HLSW v1.4.0.2 (HKLM-x32\...\HLSW_is1) (Version:  - Stripf Software)
HsTIXzTjM1N version 1.0 (HKLM-x32\...\{398AA783-4B81-F129-9A7A-40BE5DEAD60E}_is1) (Version: 1.0 - )
Hurtworld (HKLM-x32\...\Steam App 393420) (Version:  - Bankroll Studios)
IL Download Manager (HKLM-x32\...\IL Download Manager) (Version:  - Image-Line)
IL Shared Libraries (HKLM-x32\...\IL Shared Libraries) (Version:  - Image-Line)
Insurgency (HKLM-x32\...\Steam App 222880) (Version:  - New World Interactive)
Java 8 Update 40 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
Just Cause 2: Multiplayer Mod (HKLM-x32\...\Steam App 259080) (Version:  - Avalanche Studios)
Kaspersky Anti-Virus (HKLM-x32\...\{E27B1D7B-3B34-43A2-9FC0-9828D5DF46E2}) (Version: 17.0.0.611 - Kaspersky Lab) Hidden
Kaspersky Anti-Virus (HKLM-x32\...\InstallWIX_{E27B1D7B-3B34-43A2-9FC0-9828D5DF46E2}) (Version: 17.0.0.611 - Kaspersky Lab)
Kaspersky Secure Connection (HKLM-x32\...\{1CF84962-50F8-48CA-9082-B70F3A02C686}) (Version: 17.0.0.611 - Kaspersky Lab) Hidden
Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{1CF84962-50F8-48CA-9082-B70F3A02C686}) (Version: 17.0.0.611 - Kaspersky Lab)
King's Quest (HKLM-x32\...\Steam App 345390) (Version:  - The Odd Gentlemen)
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version:  - Valve)
Lethal League (HKLM-x32\...\Steam App 261180) (Version:  - Team Reptile)
Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech)
Logitech Gaming Software 8.53 (HKLM\...\Logitech Gaming Software) (Version: 8.53.186 - Logitech Inc.)
LogMeIn Hamachi (HKLM-x32\...\{D31AA60E-A9E5-47CF-AE3C-C980C5A1FF51}) (Version: 2.2.0.410 - LogMeIn, Inc.) Hidden
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.410 - LogMeIn, Inc.)
Lua for Windows 5.1.4-46 (HKLM-x32\...\Lua_is1) (Version: 5.1.4.46 - The Lua for Windows Project and Lua and Tecgraf, PUC-Rio)
Magicka (HKLM-x32\...\Steam App 42910) (Version:  - Arrowhead Game Studios)
Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Microsoft .NET Framework 4.6.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01590 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mount&Blade Warband (HKLM-x32\...\Mount&Blade Warband) (Version:  - )
MSI Afterburner 3.0.1 (HKLM-x32\...\Afterburner) (Version: 3.0.1 - MSI Co., LTD)
Mumble 1.2.7 (HKLM-x32\...\{CF8BBFA2-5502-4904-A9E9-8D5CAA8DF785}) (Version: 1.2.7 - Thorvald Natvig)
NEC Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{D7BF9739-8A68-4335-BBEE-37752AD9E86B}) (Version: 1.0.18.0 - NEC Electronics Corporation) Hidden
NEC Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}) (Version: 1.0.18.0 - NEC Electronics Corporation)
Need for Speed Underground 2 (HKLM-x32\...\Need for Speed Underground 2) (Version:  - )
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.63.14 - Black Tree Gaming)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.6 - Notepad++ Team)
NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 361.75 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.75 - NVIDIA Corporation)
NVIDIA Graphics Driver 361.75 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.75 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Octoshape Streaming Services (HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\Octoshape Streaming Services) (Version:  - Octoshape ApS)
ON_OFF Charge B10.0422.2 (HKLM-x32\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
Opera beta 48.0.2685.22 (HKLM-x32\...\Opera 48.0.2685.22) (Version: 48.0.2685.22 - Opera Software)
Opera Stable 46.0.2597.57 (HKLM-x32\...\Opera 46.0.2597.57) (Version: 46.0.2597.57 - Opera Software)
Origin (HKLM-x32\...\Origin) (Version: 9.4.11.2806 - Electronic Arts, Inc.)
osu! (HKLM-x32\...\{dd2cc895-8ae6-4b9e-b42a-9aa908c1dca5}) (Version: latest - ppy Pty Ltd)
Outlast (HKLM-x32\...\Outlast_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, spider91)
Overwatch (HKLM-x32\...\Overwatch) (Version:  - Blizzard Entertainment)
PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2) (Version:  - )
Peggle (HKLM-x32\...\{715AD72D-887A-459E-988B-D4F3E87FA24B}) (Version: 1.04.0.0 - PopCap Games)
PLAYERUNKNOWN'S BATTLEGROUNDS (HKLM\...\Steam App 578080) (Version:  - Bluehole, Inc.)
Portal 2 (HKLM-x32\...\Steam App 620) (Version:  - Valve)
Python 3.4.2 (HKLM-x32\...\{2583CDBA-8A53-4622-BB67-1D163714C1B4}) (Version: 3.4.16349 - Python Software Foundation)
Quake Live (HKLM-x32\...\Steam App 282440) (Version:  - id Software)
Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 8.0.104.420 - Razer Inc.)
Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.17.304.2010 - Realtek)
Realtek HDMI Audio Driver for ATI (HKLM-x32\...\{5449FB4F-1802-4D5B-A6D8-087DB1142147}) (Version: 6.0.1.6650 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6662 - Realtek Semiconductor Corp.)
Reflex (HKLM-x32\...\Steam App 328070) (Version:  - Turbo Pixel Studios)
Risk of Rain (HKLM-x32\...\Steam App 248820) (Version:  - )
RivaTuner Statistics Server 6.1.2 (HKLM-x32\...\RTSS) (Version: 6.1.2 - Unwinder)
Rocket League (HKLM-x32\...\Steam App 252950) (Version:  - Psyonix)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.9 - Rockstar Games)
RogueKiller version 12.10.1.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.10.1.0 - Adlice Software)
Rust (HKLM-x32\...\Steam App 252490) (Version:  - Facepunch Studios)
Saints Row IV (HKLM-x32\...\Steam App 206420) (Version:  - Deep Silver Volition)
Sandboxie 4.18 (64-bit) (HKLM\...\Sandboxie) (Version: 4.18 - Sandboxie Holdings, LLC)
Serious Sam 2 (HKLM-x32\...\Steam App 204340) (Version:  - Croteam)
Serious Sam 2 Dedicated Server Utility (HKLM-x32\...\SS2DedServerUtility) (Version:  - )
Shadow Warrior Classic Redux (HKLM-x32\...\Steam App 225160) (Version:  - 3D Realms)
SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 7.1.0280 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController) (Version: 2.11.4.1 - NVIDIA Corporation) Hidden
ShiftWindow 1.02 (HKLM-x32\...\ShiftWindow_is1) (Version:  - Grismar)
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
Simply Chess (HKLM-x32\...\Steam App 312280) (Version:  - BlueLine Games)
Skype™ 7.17 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.17.105 - Skype Technologies S.A.)
Smart 6 B10.0422.1 (HKLM-x32\...\{3B35725F-C623-4A1E-B5CC-99C0868679E3}) (Version: 1.00.0000 - GIGABYTE)
Snaz version 1.9.4.0 (HKLM-x32\...\{70A76031-FDC6-4F9B-BB5C-33776703F45A}_is1) (Version: 1.9.4.0 - JimsApps)
SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.15.9546 - SoftEther VPN Project)
Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.6 - Sophos Limited)
Source Dedicated Server (HKLM-x32\...\Steam App 205) (Version:  - Valve)
SpeedRunners (HKLM-x32\...\Steam App 207140) (Version:  - DoubleDutch Games)
Spore (HKLM\...\Steam App 17390) (Version:  - Maxis™)
Spotify (HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\Spotify) (Version: 1.0.63.617.g5aca9a2a - Spotify AB)
Star Wars Jedi Knight: Jedi Academy (HKLM-x32\...\Steam App 6020) (Version:  - Raven Software)
Starbound (HKLM\...\Steam App 211820) (Version:  - Chucklefish)
Sublime Text Build 3083 (HKLM\...\Sublime Text 3_is1) (Version:  - Sublime HQ Pty Ltd)
Super Meat Boy (HKLM-x32\...\Steam App 40800) (Version:  - Team Meat)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.42849 - TeamViewer)
The Crew Trial (HKLM-x32\...\Steam App 366310) (Version:  - Ivory Tower in collaboration with Ubisoft Reflections)
The Mean Greens - Plastic Warfare (HKLM-x32\...\Steam App 360940) (Version:  - Virtual Basement LLC)
The Sims 2: Ultimate Collection (HKLM-x32\...\{04450C18-F039-4B81-A621-70C3B0F523D5}) (Version: 1.0.0.0 - Electronic Arts)
The Sims 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.0.797.20 - Electronic Arts)
The Stanley Parable (HKLM-x32\...\The Stanley Parable_is1) (Version:  - )
The Witcher: Enhanced Edition (HKLM-x32\...\Steam App 20900) (Version:  - CD PROJEKT RED)
Transistor (HKLM-x32\...\Steam App 237930) (Version:  - Supergiant Games)
Unturned (HKLM-x32\...\Steam App 304930) (Version:  - Nelson Sexton)
Uplay (HKLM-x32\...\Uplay) (Version: 5.2 - Ubisoft)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Voobly Game Data (HKLM-x32\...\Voobly_is1) (Version: Voobly Game Datas - Voobly)
Vuze (HKLM-x32\...\8461-7759-5462-8226) (Version: 5.6.2.0 - Azureus Software, Inc.)
WestwoodOnline (HKLM-x32\...\{BBCD6D56-8A26-4DDE-9482-DBC9C7B7341D}) (Version: 1.0.0.0 - WestwoodOnline)
WinRAR 5.10 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH)
Worms Reloaded (HKLM-x32\...\Steam App 22600) (Version:  - Team17 Digital Ltd)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2015-04-15] ()
ContextMenuHandlers1: [Kaspersky Anti-Virus 17.0.0] -> {39C9FA89-7012-4573-A92D-BFD1F8CA542D} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\shellex.dll [2017-03-25] (AO Kaspersky Lab)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-06-16] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-06-16] (Alexander Roshal)
ContextMenuHandlers2: [Kaspersky Anti-Virus 17.0.0] -> {39C9FA89-7012-4573-A92D-BFD1F8CA542D} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\shellex.dll [2017-03-25] (AO Kaspersky Lab)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-01-20] (Malwarebytes)
ContextMenuHandlers4: [Kaspersky Anti-Virus 17.0.0] -> {39C9FA89-7012-4573-A92D-BFD1F8CA542D} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\shellex.dll [2017-03-25] (AO Kaspersky Lab)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\atiacm64.dll -> No File
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2016-01-23] (NVIDIA Corporation)
ContextMenuHandlers6: [Kaspersky Anti-Virus 17.0.0] -> {39C9FA89-7012-4573-A92D-BFD1F8CA542D} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\shellex.dll [2017-03-25] (AO Kaspersky Lab)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-01-20] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-06-16] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-06-16] (Alexander Roshal)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {103C58DC-6A11-4132-B128-61354501B69A} - System32\Tasks\{A3DE1E29-CB5E-436B-872E-BB799B0C8DF1} => "c:\program files (x86)\google\chrome\application\chrome.exe" hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=6.18.0.105&LastError=404
Task: {1D74B6AD-F207-4616-B795-15308F4F3E79} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [2016-08-23] (AO Kaspersky Lab)
Task: {275442C4-D16A-4192-AF24-7596AD12785C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-13] (Google Inc.)
Task: {28BB728F-23D1-4B05-920F-7E52ECBF1D92} - System32\Tasks\Microsoft\Windows\SmartRecovery\SRFilter => %windir%\system32\rundll32.exe CommCmd.dll,RunScript "%ProgramFiles%\GIGABYTE\Smart6\Recovery\SRFilter.exe" /GBSMART6 -kdl
Task: {3EDA2DF0-A52F-4629-BCC6-CB1A80969E06} - System32\Tasks\Opera scheduled Autoupdate 1501151123 => C:\Program Files\Opera beta\launcher.exe [2017-09-12] (Opera Software)
Task: {656E1084-A62C-4428-B7DB-901B1475E466} - System32\Tasks\Opera scheduled Autoupdate 1451941354 => C:\Program Files (x86)\Opera\launcher.exe [2017-07-18] (Opera Software)
Task: {7336F5F1-868C-4651-96B7-E0A2FE1108BB} - System32\Tasks\{533EB031-BF25-4683-BA64-C3FE54B89C09} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCCInstall.exe" -d "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static"
Task: {86C10478-3D69-40C3-80C6-32EC2F9E370D} - System32\Tasks\{8982DC7E-CDF1-4284-884C-43F6E47CE3EE} => C:\Windows\system32\pcalua.exe -a C:\Windows\RaidTool\IDEDrvSetup.exe -d C:\Windows\SysWOW64 -c "PCI\VEN_197B&DEV_2363&SUBSYS_B0001458&REV_02\4&238ed369&0&01E1;"
Task: {88532493-8D42-4E75-9103-E36AC36EDDE5} - System32\Tasks\{136F545B-0559-4304-96C4-F4550D4EB7AF} => "c:\program files (x86)\google\chrome\application\chrome.exe" hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=6.18.0.105&LastError=404
Task: {9EB9F456-028D-4948-BD25-F0D547AEB831} - System32\Tasks\{9920CA20-B02B-48F7-80EB-96FBB5119F13} => C:\Windows\system32\pcalua.exe -a C:\Windows\rm303b.exe -c usb\vid_0ac8&pid_303B
Task: {ABEDF6F5-C1DC-4CF9-9135-14D209677214} - System32\Tasks\Microsoft\Windows\SmartRecovery\SRCreate => %windir%\system32\rundll32.exe CommCmd.dll,RunScript "%ProgramFiles%\GIGABYTE\Smart6\Recovery\SrCmdCLR.exe" -c 1
Task: {D9DB1260-259C-49D3-8DC4-DCC47C5390EC} - System32\Tasks\{07F404C9-2511-4B82-AB56-2D81B19FE727} => C:\Windows\system32\pcalua.exe -a C:\Users\Asce\Downloads\lgs510.exe -d C:\Users\Asce\Downloads
Task: {E08C8870-BFCD-4095-A81E-A14D1C0922FD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)
Task: {E1B3A64A-77D7-4D99-BDD7-7F9D27C5E5D8} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_25_0_0_127_pepper.exe [2017-03-25] (Adobe Systems Incorporated)
Task: {FCB7ED30-AA59-4222-9914-0D20871C1F89} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-13] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
ShortcutWithArgument: C:\Users\Asce\Desktop\New folder (2)\Oyunlar\Hand + Wrist Exercises For Gamers - YouTube.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --app=hxxps://www.youtube.com/watch?v=EiRC80FJbHU
ShortcutWithArgument: C:\Users\Asce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\TwitchAlerts Stream Labels.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=kgmggmdngboajiakmbpdknfpdelbjbcg
 
==================== Loaded Modules (Whitelisted) ==============
 
2017-03-24 12:34 - 2016-01-23 04:04 - 000133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-05-18 15:41 - 2009-06-17 16:13 - 000068136 _____ () C:\Program Files (x86)\Gigabyte\EnergySaver2\des2svr.exe
2015-05-18 15:45 - 2010-01-19 05:31 - 000072304 ____R () C:\Windows\SysWOW64\XSrvSetup.exe
2017-03-25 08:02 - 2016-06-15 04:14 - 000369208 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll
2017-03-25 08:02 - 2016-06-15 04:14 - 001148984 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\libprotobuf.dll
2017-03-25 08:02 - 2016-06-15 04:14 - 003613240 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll
2017-03-24 12:36 - 2016-06-15 04:14 - 000289848 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2017-03-24 13:09 - 2017-04-15 00:31 - 002271520 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-03-25 08:02 - 2016-06-15 04:14 - 002667576 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvMdnsPlugin.dll
2017-03-25 08:02 - 2016-06-15 04:14 - 001990200 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvPortForwardPlugin.dll
2017-03-25 08:02 - 2016-06-15 04:14 - 001842232 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\RtspPlugin.dll
2017-03-24 12:37 - 2016-06-15 04:14 - 000208952 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\RtspServer.dll
2017-03-25 08:02 - 2016-06-15 04:14 - 000035896 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_system-vc120-mt-1_58.dll
2017-03-25 08:02 - 2016-06-15 04:14 - 000921656 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_regex-vc120-mt-1_58.dll
2015-10-16 13:02 - 2015-10-16 13:02 - 000043480 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll
2017-04-13 01:19 - 2017-03-15 14:10 - 000350760 _____ () C:\Program Files (x86)\Razer\Razer Cortex\RazerGamecasterEngine.exe
2017-09-14 23:05 - 2017-09-12 08:03 - 091506776 _____ () C:\Program Files\Opera beta\48.0.2685.22\opera_browser.dll
2017-09-14 23:05 - 2017-09-12 08:03 - 004197976 _____ () C:\Program Files\Opera beta\48.0.2685.22\libglesv2.dll
2017-09-14 23:05 - 2017-09-12 08:03 - 000101464 _____ () C:\Program Files\Opera beta\48.0.2685.22\libegl.dll
2017-08-28 22:46 - 2017-08-23 11:48 - 003824472 _____ () C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.113\libglesv2.dll
2017-08-28 22:46 - 2017-08-23 11:48 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.113\libegl.dll
2015-05-18 15:42 - 2009-05-04 17:56 - 000102400 _____ () C:\Program Files (x86)\Gigabyte\EnergySaver2\ycc.dll
2017-04-13 01:19 - 2017-03-15 14:08 - 001025848 _____ () C:\Program Files (x86)\Razer\Razer Cortex\CefSharp.Core.dll
2017-04-13 01:19 - 2017-03-15 14:08 - 053913416 _____ () C:\Program Files (x86)\Razer\Razer Cortex\libcef.dll
2017-03-14 21:23 - 2017-03-14 21:26 - 001005408 _____ () C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.Core.dll
2017-03-14 21:23 - 2017-03-14 21:26 - 053444984 _____ () C:\Program Files (x86)\Razer\Razer Services\Razer Central\libcef.dll
2017-03-14 21:23 - 2017-03-14 21:26 - 000691056 _____ () C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.Core.dll
2017-03-14 21:23 - 2017-03-14 21:26 - 001984392 _____ () C:\Program Files (x86)\Razer\Razer Services\Razer Central\libglesv2.dll
2017-03-14 21:23 - 2017-03-14 21:26 - 000082824 _____ () C:\Program Files (x86)\Razer\Razer Services\Razer Central\libegl.dll
2017-04-13 01:19 - 2016-07-12 13:43 - 000149352 _____ () C:\Program Files (x86)\Razer\Razer Cortex\SimbaDeviceControl.dll
2017-04-13 01:19 - 2017-03-15 14:08 - 000146280 _____ () C:\Program Files (x86)\Razer\Razer Cortex\ftl.dll
2017-04-13 01:25 - 2016-10-08 10:13 - 050656768 _____ () C:\Users\Asce\AppData\Local\razer\InGameEngine\cache\RzFpsApplet\cef\libcef.dll
2017-04-13 01:25 - 2016-10-08 10:13 - 001874944 _____ () C:\Users\Asce\AppData\Local\razer\InGameEngine\cache\RzFpsApplet\cef\libglesv2.dll
2017-04-13 01:25 - 2016-10-08 10:13 - 000075264 _____ () C:\Users\Asce\AppData\Local\razer\InGameEngine\cache\RzFpsApplet\cef\libegl.dll
2014-07-13 01:17 - 2017-09-09 22:25 - 000688416 _____ () C:\Steam\SDL2.dll
2014-12-07 02:58 - 2016-09-01 04:02 - 004969248 _____ () C:\Steam\v8.dll
2014-12-07 02:58 - 2016-09-01 04:02 - 001563936 _____ () C:\Steam\icui18n.dll
2014-12-07 02:58 - 2016-09-01 04:02 - 001195296 _____ () C:\Steam\icuuc.dll
2014-07-13 01:17 - 2017-09-15 22:25 - 002544416 _____ () C:\Steam\video.dll
2014-08-22 18:27 - 2016-01-27 10:49 - 002549760 _____ () C:\Steam\libavcodec-56.dll
2014-08-22 18:27 - 2016-01-27 10:49 - 000442880 _____ () C:\Steam\libavutil-54.dll
2014-08-22 18:27 - 2016-01-27 10:49 - 000491008 _____ () C:\Steam\libavformat-56.dll
2014-08-22 18:27 - 2016-01-27 10:49 - 000332800 _____ () C:\Steam\libavresample-2.dll
2014-08-22 18:27 - 2016-01-27 10:49 - 000485888 _____ () C:\Steam\libswscale-3.dll
2014-07-13 01:17 - 2017-09-15 22:25 - 000901408 _____ () C:\Steam\bin\chromehtml.DLL
2017-03-24 16:51 - 2016-07-05 01:17 - 000266560 _____ () C:\Steam\openvr_api.dll
2017-03-25 09:36 - 2017-08-17 01:28 - 073130272 _____ () C:\Steam\bin\cef\cef.win7\libcef.dll
2017-07-24 19:45 - 2017-09-07 05:04 - 000678400 _____ () C:\Steam\bin\cef\cef.win7\SDL2.dll
2014-12-28 19:32 - 2015-09-25 02:52 - 000119208 _____ () C:\Steam\winh264.dll
2017-03-25 09:36 - 2017-08-17 01:28 - 002968864 _____ () C:\Steam\bin\cef\cef.win7\libglesv2.dll
2017-03-25 09:36 - 2017-08-17 01:28 - 000086304 _____ () C:\Steam\bin\cef\cef.win7\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\Software\Classes\regfile: regedit.exe "%1" <==== ATTENTION
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\sony.com -> sony.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 05:34 - 2017-03-28 09:38 - 000000027 _____ C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 139.179.30.24 - 139.179.10.13
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: Discord => C:\Users\Asce\AppData\Local\Discord\app-0.0.297\Discord.exe
MSCONFIG\startupreg: Domino => C:\Windows\Domino.exe
MSCONFIG\startupreg: EasyTuneVI => C:\Program Files (x86)\GIGABYTE\ET6\ETcall.exe
MSCONFIG\startupreg: ISUSPM Startup => C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
MSCONFIG\startupreg: ISUSScheduler => "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
MSCONFIG\startupreg: Launch LCore => C:\Program Files\Logitech Gaming Software\LCore.exe /minimized
MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
MSCONFIG\startupreg: Octoshape Streaming Services => "C:\Users\Asce\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
MSCONFIG\startupreg: SandboxieControl => "C:\Program Files\Sandboxie\SbieCtrl.exe"
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SoftEther VPN Client UI Helper => "C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe" /uihelp
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Asce\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
MSCONFIG\startupreg: Start WingMan Profiler => C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
MSCONFIG\startupreg: Steam => "C:\Steam\steam.exe" -silent
MSCONFIG\startupreg: VMSnap3 => C:\Windows\VMSnap3.exe
MSCONFIG\startupreg: Voobly => "C:\Program Files (x86)\Voobly\voobly.exe" --startup
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{458A164A-2A83-40A9-9CF6-F09DEB5C42F6}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{1B9BD2ED-A2F3-4669-9678-CB099CADDAB3}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{B92839D7-E05D-4DEE-8FBA-520A41FF0AE5}] => (Allow) C:\Steam\Steam.exe
FirewallRules: [{BAA787D1-92B7-4D3F-B05F-073A0C3FB212}] => (Allow) C:\Steam\Steam.exe
FirewallRules: [{790DD38B-2D8C-465B-95D4-6249283345C9}] => (Allow) C:\Steam\SteamApps\common\DayZ\DayZ.exe
FirewallRules: [{06424155-76A8-442F-B0E2-346B71524333}] => (Allow) C:\Steam\SteamApps\common\DayZ\DayZ.exe
FirewallRules: [{453E5431-9948-44F6-B71F-030129F475B3}] => (Allow) C:\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{0B711E6A-71F6-4981-8A00-4BEF21486E5B}] => (Allow) C:\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{12D57C11-4036-480D-8628-06C3DAB5D7F2}] => (Allow) C:\Steam\SteamApps\common\Spacewar\SteamworksExample.exe
FirewallRules: [{F2A34E0E-A7E3-4978-9FC7-7545C750967D}] => (Allow) C:\Steam\SteamApps\common\Spacewar\SteamworksExample.exe
FirewallRules: [{B24E8689-9375-4979-9F58-9556DFDD7FE7}] => (Allow) C:\Steam\SteamApps\common\GarrysMod\hl2.exe
FirewallRules: [{32EA9E2F-F816-44BA-ADA7-5F8B1FDE2B6A}] => (Allow) C:\Steam\SteamApps\common\GarrysMod\hl2.exe
FirewallRules: [{B8ABE8D7-5376-477C-8A90-D4B5F592ABA3}] => (Allow) C:\Users\Asce\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D46BA8D8-D7AC-48FE-9F6C-708180DF7F6E}] => (Allow) C:\Users\Asce\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{75FD7C1B-D0C9-4085-ADE9-BF37F93A5D53}] => (Allow) C:\Steam\SteamApps\common\Unturned\Unturned.exe
FirewallRules: [{AE8E5E33-7B66-415E-84FA-1642DA83A2CF}] => (Allow) C:\Steam\SteamApps\common\Unturned\Unturned.exe
FirewallRules: [{9287F43D-18EB-46BD-A913-37FD1BC1FF29}] => (Allow) C:\Steam\SteamApps\common\Call of Duty Black Ops II\t6mp.exe
FirewallRules: [{884E7D36-4B6B-4D3E-8D80-CAD1B60CCEFC}] => (Allow) C:\Steam\SteamApps\common\Call of Duty Black Ops II\t6mp.exe
FirewallRules: [{8A6B68FF-0820-4845-9BF3-F3DB3C3F304F}] => (Allow) C:\Steam\SteamApps\common\call of duty modern warfare 2\iw4sp.exe
FirewallRules: [{13579D56-CA61-4549-B417-482C6BD3C6F7}] => (Allow) C:\Steam\SteamApps\common\call of duty modern warfare 2\iw4sp.exe
FirewallRules: [{0AAD6341-F368-4FAB-B66C-817FF697BA9C}] => (Allow) C:\Steam\SteamApps\common\Dead Island Epidemic\Dead Island Epidemic - Launcher.exe
FirewallRules: [{FDAF864E-C168-49D1-8D38-37692F42C572}] => (Allow) C:\Steam\SteamApps\common\Dead Island Epidemic\Dead Island Epidemic - Launcher.exe
FirewallRules: [TCP Query User{768D7918-BAE8-456C-94ED-11EE827FBC68}C:\users\asce\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe] => (Allow) C:\users\asce\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe
FirewallRules: [UDP Query User{F538583C-9828-4C5B-A80C-544AF6AC1D02}C:\users\asce\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe] => (Allow) C:\users\asce\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe
FirewallRules: [{E83EB416-9480-48F0-B4C1-4906165AF845}] => (Allow) C:\Program Files (x86)\Origin Games\Command and Conquer Red Alert II\RA2Launcher.exe
FirewallRules: [{482EF486-1DB9-463A-B689-30230EF651A5}] => (Allow) C:\Program Files (x86)\Origin Games\Command and Conquer Red Alert II\RA2Launcher.exe
FirewallRules: [{63E62E53-04C2-4159-946D-780877E67A53}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{E0EA29A9-FAAC-479C-8C17-9DECC449766F}] => (Allow) C:\Steam\bin\steamwebhelper.exe
FirewallRules: [{D1360145-78D8-4529-B7C6-58CB74D8A9E9}] => (Allow) C:\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{65778332-9DF7-4531-AB4E-87620C256401}C:\program files (x86)\origin games\command and conquer red alert ii\game.exe] => (Allow) C:\program files (x86)\origin games\command and conquer red alert ii\game.exe
FirewallRules: [UDP Query User{97158542-D407-4939-A8F9-30EDA29DCD95}C:\program files (x86)\origin games\command and conquer red alert ii\game.exe] => (Allow) C:\program files (x86)\origin games\command and conquer red alert ii\game.exe
FirewallRules: [TCP Query User{50AE6C6D-1F9C-42F5-B1A6-2C0234462B74}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{5AAC0DEE-0AF7-4937-8946-30C4901D1D8C}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{9DFC48D2-942F-4E37-897C-329190B5BCB6}] => (Allow) C:\Steam\SteamApps\common\Just Cause 2\JustCause2.exe
FirewallRules: [{37563006-1568-43B9-B42F-CF30A98DAB87}] => (Allow) C:\Steam\SteamApps\common\Just Cause 2\JustCause2.exe
FirewallRules: [{FA4C023D-27E3-46A6-94D0-6480170087F0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [{7784A54E-6C08-4034-8024-AF8AA49A8F64}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [{627B7053-78CE-4024-8534-37A1941E7C53}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{50E11F07-1D4D-4714-A917-E0B427FB9D4D}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{2E9B195F-C120-4732-AB75-E5D9B91AC561}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{21EB7C6D-561D-4AA1-87F8-B187160F0CE7}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{8CEAC588-0974-4388-AE41-6A92077AF354}] => (Allow) C:\Steam\SteamApps\common\DayZ\DayZ_BE.exe
FirewallRules: [{85D49392-4EC9-49D7-BDC9-08479635021C}] => (Allow) C:\Steam\SteamApps\common\DayZ\DayZ_BE.exe
FirewallRules: [{A891EF7A-AD93-473F-9AAF-A5CC84E1CD98}] => (Allow) C:\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{A8A09009-989F-444F-A192-5B391A25BC20}] => (Allow) C:\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{0C0AB31E-BF19-4E69-8C98-5911AF046FEF}] => (Allow) C:\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [{14908FA5-273F-439C-8C30-A267B52B0222}] => (Allow) C:\Steam\SteamApps\common\Terraria\Terraria.exe
FirewallRules: [TCP Query User{845A900A-6D0D-4608-AB2E-66CE50C7CCB1}C:\steam\steamapps\common\war thunder\launcher.exe] => (Allow) C:\steam\steamapps\common\war thunder\launcher.exe
FirewallRules: [UDP Query User{356874B1-6180-4C84-87A8-0E5B4651CEEA}C:\steam\steamapps\common\war thunder\launcher.exe] => (Allow) C:\steam\steamapps\common\war thunder\launcher.exe
FirewallRules: [{CBE7D417-75D2-4327-B789-0EBC0E25DB39}] => (Allow) C:\Steam\SteamApps\common\Age2HD\Launcher.exe
FirewallRules: [{348873A4-7388-40EA-A6A6-1CC2A615CB2B}] => (Allow) C:\Steam\SteamApps\common\Age2HD\Launcher.exe
FirewallRules: [TCP Query User{D3C85D33-E008-4269-AADC-3D8403C8B26C}C:\steam\steamapps\common\age2hd\age2_x1\age2_x1.exe] => (Allow) C:\steam\steamapps\common\age2hd\age2_x1\age2_x1.exe
FirewallRules: [UDP Query User{BB7ADB34-833F-4734-9609-189E9B43CF72}C:\steam\steamapps\common\age2hd\age2_x1\age2_x1.exe] => (Allow) C:\steam\steamapps\common\age2hd\age2_x1\age2_x1.exe
FirewallRules: [TCP Query User{A08EE83E-FD86-4F98-AD8C-CD0D45F2E7C1}C:\program files (x86)\voobly\voobly.exe] => (Allow) C:\program files (x86)\voobly\voobly.exe
FirewallRules: [UDP Query User{DF08D976-FAF6-43AF-BCBA-C131F3016B41}C:\program files (x86)\voobly\voobly.exe] => (Allow) C:\program files (x86)\voobly\voobly.exe
FirewallRules: [TCP Query User{839BB445-A274-4919-88EF-D036D5855D79}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe
FirewallRules: [UDP Query User{B2333D85-D96E-4A70-8571-2E3F3F996556}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe
FirewallRules: [TCP Query User{5CF18D48-96B1-48EB-B1A5-2EA725EA6E0A}C:\programdata\battle.net\agent\agent.3715\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3715\agent.exe
FirewallRules: [UDP Query User{8E12136B-DC50-4AA2-8B90-AB95AB7F545B}C:\programdata\battle.net\agent\agent.3715\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3715\agent.exe
FirewallRules: [TCP Query User{5E48CF9B-3A6C-48A4-92EB-0C046617D9EB}C:\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe] => (Allow) C:\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe
FirewallRules: [UDP Query User{F47D2C14-5D86-4544-B219-7BB623201125}C:\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe] => (Allow) C:\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe
FirewallRules: [TCP Query User{D8C08E9A-6FCE-443E-BEA1-176DFF4A8922}C:\steam\steamapps\common\terraria\terrariaserver.exe] => (Allow) C:\steam\steamapps\common\terraria\terrariaserver.exe
FirewallRules: [UDP Query User{607A5763-C6F7-467F-806E-5B124435373F}C:\steam\steamapps\common\terraria\terrariaserver.exe] => (Allow) C:\steam\steamapps\common\terraria\terrariaserver.exe
FirewallRules: [{4CBA86BD-46D4-4137-AFDA-6C14BADCAB7B}] => (Allow) C:\Steam\SteamApps\common\Magicka\Magicka.exe
FirewallRules: [{20553E12-A9A2-405D-BF6A-FC75A27D4BA0}] => (Allow) C:\Steam\SteamApps\common\Magicka\Magicka.exe
FirewallRules: [{3FE5DB57-0CEF-4D11-89B2-9DED2F66604E}] => (Allow) C:\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{064EA017-88CA-4CAC-B5FC-D13B43D029D0}] => (Allow) C:\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{DCC914F5-0E9E-402E-B1BB-0C28F526D94B}] => (Allow) C:\Steam\SteamApps\common\Bastion\Bastion.exe
FirewallRules: [{CC87A59B-86FA-4A28-A52E-FA12B2FC4FCD}] => (Allow) C:\Steam\SteamApps\common\Bastion\Bastion.exe
FirewallRules: [{337D0EF2-F120-42CE-8CC5-62B392FB42DD}] => (Allow) C:\Steam\SteamApps\common\Quake Live\quakelive_steam.exe
FirewallRules: [{A9A3592E-223C-4A6D-B5B0-1FAEB81437BA}] => (Allow) C:\Steam\SteamApps\common\Quake Live\quakelive_steam.exe
FirewallRules: [{6D760926-C82D-420E-A861-F18D0AC677E1}] => (Allow) C:\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{3651B532-0C04-4917-9036-3C7C892052B5}] => (Allow) C:\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{A440F110-CF58-4FA0-919E-7DA6030B2B48}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient.exe
FirewallRules: [{B3FBAD54-C776-48E5-96FC-8C59D7F51AB2}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
FirewallRules: [{39E13DC8-BD4C-4095-93EA-8C7027A83620}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr.exe
FirewallRules: [{7A5C0495-050F-4100-BFF8-B90CC3A6F240}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe
FirewallRules: [{E9E309E2-E2E6-49BF-86B0-43F36EF54DD7}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd.exe
FirewallRules: [{F56DB718-D6DA-4D4C-A51C-B71D4C4F066C}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd_x64.exe
FirewallRules: [TCP Query User{4EB4B49F-7C22-4EED-9A65-07A8435BE692}C:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) C:\program files\rockstar games\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{259A3B69-E6F3-4A3F-8379-06FF4D50FC0D}C:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) C:\program files\rockstar games\grand theft auto v\gta5.exe
FirewallRules: [{E02CC463-48D1-420D-BCD0-948A83B0FB9A}] => (Allow) C:\Steam\SteamApps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{75B148F3-EDB5-46FC-BFD4-03ACECCAD858}] => (Allow) C:\Steam\SteamApps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{EBC98A17-83DE-4EA9-AE90-AFA020F78C98}] => (Allow) C:\Steam\SteamApps\common\Just Cause 2 - Multiplayer Mod\JcmpLauncher.exe
FirewallRules: [{26EB3412-85B3-4BD4-8543-E281738C45DC}] => (Allow) C:\Steam\SteamApps\common\Just Cause 2 - Multiplayer Mod\JcmpLauncher.exe
FirewallRules: [{4028C7BE-6823-4B7A-BF03-C0B5FDB2FC70}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{63F54E8A-464E-4C05-834F-53378A25565A}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{7ECD9E37-E671-49C2-89CC-0CE1FCEA1D0B}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{B9E11AA8-989B-457E-8412-FED0C09FAA7B}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{52C178C9-9383-4E4D-AB6F-0EFACA21B481}] => (Allow) C:\Steam\SteamApps\common\H1Z1\LaunchPad.exe
FirewallRules: [{EB8D9685-B910-4A3F-A3BA-22F09ED80BB1}] => (Allow) C:\Steam\SteamApps\common\H1Z1\LaunchPad.exe
FirewallRules: [{1F653092-0193-4E9D-A4A9-D9BAB23A62B3}] => (Allow) C:\Steam\SteamApps\common\Guns of Icarus Online\GunsOfIcarusOnline.exe
FirewallRules: [{00E7DAF6-55C8-4464-AC17-9EAE73F5E4E3}] => (Allow) C:\Steam\SteamApps\common\Guns of Icarus Online\GunsOfIcarusOnline.exe
FirewallRules: [{F99637CA-952B-47AD-AD14-AF6DC74905AB}] => (Allow) C:\Steam\SteamApps\common\Half-Life 2\hl2.exe
FirewallRules: [{A364DEA6-23BA-401C-B80C-CAD40B226383}] => (Allow) C:\Steam\SteamApps\common\Half-Life 2\hl2.exe
FirewallRules: [{B5641A06-9510-4386-8D3B-9B965EFB5459}] => (Allow) C:\Steam\SteamApps\common\The Witcher Enhanced Edition\System\witcher.exe
FirewallRules: [{04E1DCA9-D488-4A35-9AF9-DB6F2FC757EB}] => (Allow) C:\Steam\SteamApps\common\The Witcher Enhanced Edition\System\witcher.exe
FirewallRules: [{44422A73-CAA9-4137-A451-384E7B7C1A22}] => (Allow) C:\Steam\SteamApps\common\The Witcher Enhanced Edition\System\djinni!.exe
FirewallRules: [{40C4CD7D-3523-4B43-AF57-B73701C12215}] => (Allow) C:\Steam\SteamApps\common\The Witcher Enhanced Edition\System\djinni!.exe
FirewallRules: [{12A921F1-2A9D-40CA-9456-FA194BFCB4F7}] => (Allow) C:\Steam\SteamApps\common\The Witcher Enhanced Edition\Digital Comic\DigitalComic.exe
FirewallRules: [{AA0A859B-07F0-4BA3-9E7A-A59240502D6B}] => (Allow) C:\Steam\SteamApps\common\The Witcher Enhanced Edition\Digital Comic\DigitalComic.exe
FirewallRules: [{D39FD8B2-9260-4187-8BCD-180D1A121F24}] => (Allow) C:\Steam\SteamApps\common\Beat Hazard\BeatHazard.exe
FirewallRules: [{9468B3F8-6539-4430-9E8F-7A56FC000EEA}] => (Allow) C:\Steam\SteamApps\common\Beat Hazard\BeatHazard.exe
FirewallRules: [{5660E3DB-1CD1-4F30-BBC7-4D5BC135E208}] => (Allow) C:\Steam\SteamApps\common\Beat Hazard\runme.exe
FirewallRules: [{793BB8AF-E93F-414D-B6DA-268BA0DA5ADD}] => (Allow) C:\Steam\SteamApps\common\Beat Hazard\runme.exe
FirewallRules: [TCP Query User{1005A1D9-6A03-4EFA-A654-F3AAAC65B81A}C:\steam\steamapps\common\counter-strike source\hl2.exe] => (Allow) C:\steam\steamapps\common\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{DA3D4B21-A3AC-491B-BBB2-09911F8ED5AF}C:\steam\steamapps\common\counter-strike source\hl2.exe] => (Allow) C:\steam\steamapps\common\counter-strike source\hl2.exe
FirewallRules: [{977241C8-6B2A-43ED-99CD-251F5387F0A4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{BB40CF8B-46CF-424C-9BEB-C3E69EA66CF7}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{7E06EBD3-8902-429D-96E9-4F4704626099}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{B28CDDCB-DB4E-4120-AC00-F74C750EAEA0}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{40477175-FB13-4A91-8F71-4C0863E7261A}C:\program files (x86)\jack\jackd.exe] => (Allow) C:\program files (x86)\jack\jackd.exe
FirewallRules: [UDP Query User{00D46205-F72E-4088-93AE-69F501AC46C9}C:\program files (x86)\jack\jackd.exe] => (Allow) C:\program files (x86)\jack\jackd.exe
FirewallRules: [{F8105125-8BA8-4A51-8E57-93B087A3DFE0}] => (Allow) C:\Steam\SteamApps\common\Gotham City Impostors F2P\Engine.exe
FirewallRules: [{F96FEC7E-5A55-43BA-817D-7678852B4247}] => (Allow) C:\Steam\SteamApps\common\Gotham City Impostors F2P\Engine.exe
FirewallRules: [TCP Query User{F6369E5B-2513-4ECD-969E-FE348930B4EA}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [UDP Query User{B9CD162F-7332-44EF-829F-152DC5664223}C:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) C:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{9DCBFD6F-2999-4FBC-BA55-AF1BF04B1488}] => (Allow) C:\Steam\SteamApps\common\Super Meat Boy\SuperMeatBoy.exe
FirewallRules: [{ED753236-A68E-4324-BBA7-64AC97142180}] => (Allow) C:\Steam\SteamApps\common\Super Meat Boy\SuperMeatBoy.exe
FirewallRules: [{89F8D722-ED46-49BC-88E7-79EC3D18ED84}] => (Allow) C:\Steam\SteamApps\common\Shadow Warrior Classic\bin\build.exe
FirewallRules: [{54B6E249-05C8-4DF3-A11E-533A4B0630B2}] => (Allow) C:\Steam\SteamApps\common\Shadow Warrior Classic\bin\build.exe
FirewallRules: [{91BD5A96-25B6-469B-8214-045D3D45E0AB}] => (Allow) C:\Steam\SteamApps\common\Serious Sam 2\Bin\Sam2.exe
FirewallRules: [{D76CF486-0176-486E-8E63-D89919DD2C4F}] => (Allow) C:\Steam\SteamApps\common\Serious Sam 2\Bin\Sam2.exe
FirewallRules: [TCP Query User{E79AEF5B-CDF5-4D93-B863-28426B8864DF}C:\steam\steamapps\common\serious sam 2\bin\dedicatedserver.exe] => (Allow) C:\steam\steamapps\common\serious sam 2\bin\dedicatedserver.exe
FirewallRules: [UDP Query User{2EE07E21-D533-4262-9A98-ED26CC072427}C:\steam\steamapps\common\serious sam 2\bin\dedicatedserver.exe] => (Allow) C:\steam\steamapps\common\serious sam 2\bin\dedicatedserver.exe
FirewallRules: [{F8969FFB-6159-4A43-B0BB-05734FD1BBB5}] => (Allow) C:\Steam\SteamApps\common\Commandos 2 Men of Courage\comm2.exe
FirewallRules: [{D63320BC-3121-4027-BA43-55BCF9AEDDEF}] => (Allow) C:\Steam\SteamApps\common\Commandos 2 Men of Courage\comm2.exe
FirewallRules: [{A5648C60-C137-4E82-B8A6-4C7C44402AE3}] => (Allow) C:\Steam\SteamApps\common\Grand Theft Auto Vice City\gta-vc.exe
FirewallRules: [{B4F72047-6506-4246-91ED-932D9E6AB248}] => (Allow) C:\Steam\SteamApps\common\Grand Theft Auto Vice City\gta-vc.exe
FirewallRules: [{25FE4756-9D28-47DE-91A2-47AED6C8D3F4}] => (Allow) C:\Steam\SteamApps\common\Europa Universalis IV\eu4.exe
FirewallRules: [{5C7295D5-8895-477A-A561-0CD5A5E28DF2}] => (Allow) C:\Steam\SteamApps\common\Europa Universalis IV\eu4.exe
FirewallRules: [{BD2BB551-17DB-4F57-AD9A-A407C6C9ED68}] => (Allow) C:\Steam\SteamApps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{FEE3A5B0-87D2-4CEC-8A2B-F4F4608181AC}] => (Allow) C:\Steam\SteamApps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [{2DF41A9A-25EB-4EF2-BE02-621B5742448F}] => (Allow) C:\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{19D82A3F-6D85-4DE5-A0D9-494896E22E55}] => (Allow) C:\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [TCP Query User{4FC09390-68F5-44A3-AE5C-DC9CBECB5CBF}C:\program files\hexchat\hexchat.exe] => (Allow) C:\program files\hexchat\hexchat.exe
FirewallRules: [UDP Query User{BCFC344D-0FAA-4581-9D72-FDF142AA8F06}C:\program files\hexchat\hexchat.exe] => (Allow) C:\program files\hexchat\hexchat.exe
FirewallRules: [{E82AAA06-A582-4049-BE22-2F7B4CE6EDAC}] => (Allow) C:\Steam\SteamApps\common\Guns of Icarus Online\workshop\Workshop.exe
FirewallRules: [{2C449822-5CFE-467F-92C0-E18790451F8E}] => (Allow) C:\Steam\SteamApps\common\Guns of Icarus Online\workshop\Workshop.exe
FirewallRules: [TCP Query User{30D5AB24-1CEA-4142-9A25-6CF3F14E8E07}C:\program files (x86)\galactic cafe\the stanley parable\thestanleyparable.exe] => (Allow) C:\program files (x86)\galactic cafe\the stanley parable\thestanleyparable.exe
FirewallRules: [UDP Query User{CD2B38B6-00E4-4CE3-A83F-A7769712EC2F}C:\program files (x86)\galactic cafe\the stanley parable\thestanleyparable.exe] => (Allow) C:\program files (x86)\galactic cafe\the stanley parable\thestanleyparable.exe
FirewallRules: [{F1DE7916-2403-43E6-981A-16398A49CF26}] => (Allow) C:\Steam\SteamApps\common\The Crew\TheCrew.exe
FirewallRules: [{8A3392D1-C171-4102-86EB-FCDFFCD4566E}] => (Allow) C:\Steam\SteamApps\common\The Crew\TheCrew.exe
FirewallRules: [TCP Query User{9BD545FF-621A-4652-B07B-B8F63FDAA3BF}C:\steam\steamapps\common\burnout™ paradise the ultimate box\burnoutparadise.exe] => (Allow) C:\steam\steamapps\common\burnout™ paradise the ultimate box\burnoutparadise.exe
FirewallRules: [UDP Query User{D97670D7-40C8-4411-8BA2-5614DF28E8DD}C:\steam\steamapps\common\burnout™ paradise the ultimate box\burnoutparadise.exe] => (Allow) C:\steam\steamapps\common\burnout™ paradise the ultimate box\burnoutparadise.exe
FirewallRules: [{9A3D033A-FCD6-4FBD-921D-AFC138AB1FB2}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{92A8D395-8F33-464A-BC17-7115E1DE793F}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{14D86838-3752-48AF-989D-5E5A42CF3788}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto 3\gta3.exe
FirewallRules: [{12379673-21C0-465D-A44D-78D53B36A81A}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto 3\gta3.exe
FirewallRules: [{D0F6C4AE-F57E-4EC9-8BDF-87D8D4950EAF}] => (Allow) C:\Steam\SteamApps\common\AirMech\AirMech.exe
FirewallRules: [{A4A6D63A-E11D-445A-B0D8-B7D3A6115A2A}] => (Allow) C:\Steam\SteamApps\common\AirMech\AirMech.exe
FirewallRules: [TCP Query User{D403AD49-AEA0-4C63-9BF5-16F1BDDC701C}C:\program files (x86)\r.g. mechanics\outlast\binaries\win64\olgame.exe] => (Allow) C:\program files (x86)\r.g. mechanics\outlast\binaries\win64\olgame.exe
FirewallRules: [UDP Query User{12D09060-16DB-44BB-A094-7725AF3CC4EE}C:\program files (x86)\r.g. mechanics\outlast\binaries\win64\olgame.exe] => (Allow) C:\program files (x86)\r.g. mechanics\outlast\binaries\win64\olgame.exe
FirewallRules: [{C69DF29F-F81E-4265-8ACC-92A85E08EDFD}] => (Allow) D:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{EFAE076E-AEF6-47E7-95EA-A835E2BBB425}] => (Allow) D:\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{FC4E9CEB-A979-454F-A1FF-C8A98F699476}] => (Allow) C:\Steam\SteamApps\common\Medal of Honor\MP\mohmpgame.exe
FirewallRules: [{C5385961-ED96-40FD-A3C1-D6F29ECE5904}] => (Allow) C:\Steam\SteamApps\common\Medal of Honor\MP\mohmpgame.exe
FirewallRules: [{7DB421E5-9D8B-4BDE-AF0A-CEFA08DCB8BE}] => (Allow) C:\Program Files (x86)\Origin Games\Peggle Deluxe\Peggle.exe
FirewallRules: [{3B3E78BA-5353-4B0B-9FA0-55AFFDBDAFDC}] => (Allow) C:\Program Files (x86)\Origin Games\Peggle Deluxe\Peggle.exe
FirewallRules: [{4796D9DA-8E27-4597-9653-3A14889D8F57}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 2 Ultimate Collection\Fun with Pets\SP9\TSBin\Sims2EP9.exe
FirewallRules: [{418656AB-1D20-44EC-BEDB-E29EA925C85F}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 2 Ultimate Collection\Fun with Pets\SP9\TSBin\Sims2EP9.exe
FirewallRules: [{AAE20059-60B3-4B80-8D00-3295B2C2B0E1}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{4A466575-55FC-4D2C-B2AA-4D3660566503}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{B87F36AA-842A-40EF-B6E8-27548798E9C5}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{A8555116-534A-428D-B04C-636A71E24141}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{0EDBC1A7-923D-4FD2-BF33-FE783C7B8904}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [{A9BD6E62-3F3F-49C9-91DA-48AE22A97E21}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [TCP Query User{BC0D9FB8-87BE-476D-9F44-9ADA26398327}C:\users\asce\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\asce\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{7C06F8F0-F62B-4781-AB2E-F3AED079BA0A}C:\users\asce\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\asce\appdata\roaming\spotify\spotify.exe
FirewallRules: [{79DAE8A2-005F-4664-81F3-638F983ABA34}] => (Allow) D:\Steam\steamapps\common\Besiege\Besiege.exe
FirewallRules: [{4632AB5C-9892-4C41-B459-95F9D2C9F23E}] => (Allow) D:\Steam\steamapps\common\Besiege\Besiege.exe
FirewallRules: [{BF4E11DC-8684-456B-9BF5-9BDFAAC81F4F}] => (Allow) D:\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{3AD1EF6F-E286-4E94-B6FC-242CB9CB2680}] => (Allow) D:\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{C152F5B1-83A3-4782-B426-6A4F10E8F7A0}] => (Allow) D:\Steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{9980EB2B-52CC-4000-A12F-16DF86E1215E}] => (Allow) D:\Steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{8A31570E-B9A6-4F32-AA89-0D4B82BE23BC}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 1942\BF1942.exe
FirewallRules: [{F4B49610-13E0-4433-B5D3-A2E9BA3D8848}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 1942\BF1942.exe
FirewallRules: [TCP Query User{F3C73510-4E31-4969-807C-0A9CAA20E395}C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe
FirewallRules: [UDP Query User{BA230D1B-712D-47BA-B8E7-570C1CB997F7}C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe
FirewallRules: [TCP Query User{0B12062F-ED8A-426D-8C34-9C1B55949527}C:\program files (x86)\origin games\command and conquer red alert ii\gamemd-spawn.exe] => (Allow) C:\program files (x86)\origin games\command and conquer red alert ii\gamemd-spawn.exe
FirewallRules: [UDP Query User{05AE1AC8-DD09-4CF9-837B-2EE0231AF0F8}C:\program files (x86)\origin games\command and conquer red alert ii\gamemd-spawn.exe] => (Allow) C:\program files (x86)\origin games\command and conquer red alert ii\gamemd-spawn.exe
FirewallRules: [{B020C7DA-D5D0-4233-AEDD-7169A8E4BB52}] => (Allow) C:\Program Files (x86)\Vuze\Azureus.exe
FirewallRules: [{FE62A208-9F35-4442-976D-2FEEDA4445D7}] => (Allow) C:\Program Files (x86)\Vuze\Azureus.exe
FirewallRules: [TCP Query User{4E45818F-FED2-49A6-9CBD-51D5CC162753}C:\program files (x86)\hlsw\hlsw.exe] => (Allow) C:\program files (x86)\hlsw\hlsw.exe
FirewallRules: [UDP Query User{B454EA65-1E22-486F-8A36-8CEC156E7D24}C:\program files (x86)\hlsw\hlsw.exe] => (Allow) C:\program files (x86)\hlsw\hlsw.exe
FirewallRules: [{B454E9C7-03B1-4B93-8E94-0359454D7D22}] => (Allow) D:\Steam\steamapps\common\Chess\Chess.exe
FirewallRules: [{C88A73B2-8CAF-4C03-8882-3C61E8D1BA29}] => (Allow) D:\Steam\steamapps\common\Chess\Chess.exe
FirewallRules: [{B83943CE-D73A-4598-8DD4-4F5D5AE7248C}] => (Allow) D:\Steam\steamapps\common\Emily is Away\emily is away.exe
FirewallRules: [{7B75273B-A9B8-4F2A-805E-47DD6C574767}] => (Allow) D:\Steam\steamapps\common\Emily is Away\emily is away.exe
FirewallRules: [{A2F396A7-B2CF-42CA-AFD9-95D562155303}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{BD86AFE3-7A08-4CBD-8E3C-70F275EC7633}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{FB1DB392-1FBB-470E-A284-A14C21B77E2F}] => (Allow) C:\Program Files (x86)\Origin Games\Dead Space 3\deadspace3.exe
FirewallRules: [{6E4E64A9-BD73-48AB-B9CA-D5069F57BD02}] => (Allow) C:\Program Files (x86)\Origin Games\Dead Space 3\deadspace3.exe
FirewallRules: [TCP Query User{C0584E31-3065-4474-AA88-C3D2CED601E7}C:\gog games\terraria\terrariaserver.exe] => (Allow) C:\gog games\terraria\terrariaserver.exe
FirewallRules: [UDP Query User{12453E44-3186-4CE2-A32F-0D8D5B419BA8}C:\gog games\terraria\terrariaserver.exe] => (Allow) C:\gog games\terraria\terrariaserver.exe
FirewallRules: [{080F8DDD-54E9-43D3-836E-6EBFB404542C}] => (Allow) D:\Steam\steamapps\common\Hurtworld\Hurtworld.exe
FirewallRules: [{331F7D72-D517-49C1-B759-60B72E382F3D}] => (Allow) D:\Steam\steamapps\common\Hurtworld\Hurtworld.exe
FirewallRules: [{10BF1FEB-6697-49DB-8595-E4D1E2E8B83D}] => (Allow) D:\Steam\steamapps\common\Brawlhalla\Brawlhalla.exe
FirewallRules: [{A62301DE-D76B-4513-B3E3-A17BAEDF9566}] => (Allow) D:\Steam\steamapps\common\Brawlhalla\Brawlhalla.exe
FirewallRules: [{03614493-9155-4642-8BCD-76B5E4E58C06}] => (Allow) D:\Steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [{A82C9D23-53BF-4AA1-95D0-69CFEDF188AC}] => (Allow) D:\Steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [{9392E0AC-BA83-4155-999C-15EB4741B59C}] => (Allow) C:\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{037A7B93-0AC1-4E8E-95CB-E1EAFD0947A2}] => (Allow) C:\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{A17C01CD-8D5D-4417-A7EE-445BB4F45D49}] => (Allow) D:\Steam\steamapps\common\Jedi Academy\GameData\jasp.exe
FirewallRules: [{83CA53FF-A8E9-4C1C-9061-4E09E4B68BA7}] => (Allow) D:\Steam\steamapps\common\Jedi Academy\GameData\jasp.exe
FirewallRules: [{AD60D0CB-D079-40B7-AB63-A9DFA29B12B9}] => (Allow) D:\Steam\steamapps\common\Jedi Academy\GameData\jamp.exe
FirewallRules: [{81CB5D6C-2744-431F-8A83-34309192E094}] => (Allow) D:\Steam\steamapps\common\Jedi Academy\GameData\jamp.exe
FirewallRules: [{F3C6CB40-EBA7-46F7-A5A4-5077C91240FE}] => (Allow) D:\Steam\steamapps\common\Hurtworld\HurtworldClient.exe
FirewallRules: [{B987E40A-2C59-4489-B0C1-0B408DEB8521}] => (Allow) D:\Steam\steamapps\common\Hurtworld\HurtworldClient.exe
FirewallRules: [{33E3B8C7-D825-40D4-B88E-26C9C9E26D8C}] => (Allow) D:\Steam\steamapps\common\Risk of Rain\Risk of Rain.exe
FirewallRules: [{1E4EE38F-AC94-4307-901E-DA37617F72DE}] => (Allow) D:\Steam\steamapps\common\Risk of Rain\Risk of Rain.exe
FirewallRules: [{B5D7C706-2A1B-429F-90A7-E0220107A5CD}] => (Allow) D:\Steam\steamapps\common\Rust\Rust.exe
FirewallRules: [{4C03A861-6A96-4C12-B277-300070550356}] => (Allow) D:\Steam\steamapps\common\Rust\Rust.exe
FirewallRules: [{324A5F0A-2635-4A82-BD38-F34624679746}] => (Allow) D:\Steam\steamapps\common\SpeedRunners\SpeedRunners.exe
FirewallRules: [{E862CBC5-EFB8-4398-A891-354D4DA629EC}] => (Allow) D:\Steam\steamapps\common\SpeedRunners\SpeedRunners.exe
FirewallRules: [{1F801F28-19EA-46A0-B39F-28F144AF3F61}] => (Allow) D:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe
FirewallRules: [{528F2B1E-E34E-4E4C-B767-0C993677A83B}] => (Allow) D:\Steam\steamapps\common\The Mean Greens - Plastic Warfare\TheMeanGreens\Binaries\Win64\TheMeanGreens-Win64-Shipping.exe
FirewallRules: [{92B7EAB7-A8C0-4A30-9E7D-F90A1CFB1F59}] => (Allow) D:\Steam\steamapps\common\Transistor\x64\Transistor.exe
FirewallRules: [{B694DBF6-C326-4C3B-9863-1C59EAD89BA4}] => (Allow) D:\Steam\steamapps\common\Transistor\x64\Transistor.exe
FirewallRules: [{EBE38983-40BD-4F75-BD97-CC6E2B112299}] => (Allow) D:\Steam\steamapps\common\lethalleague\LethalLeague.exe
FirewallRules: [{1EC91F64-C926-4A17-BE09-D4AAA1CE2DE8}] => (Allow) D:\Steam\steamapps\common\lethalleague\LethalLeague.exe
FirewallRules: [{736DEABA-05F3-4543-8315-47A10349735F}] => (Allow) D:\Steam\steamapps\common\King's Quest\Binaries\Win\KingsQuest.exe
FirewallRules: [{E70C31A8-AD26-47B4-A688-C9F944865EF5}] => (Allow) D:\Steam\steamapps\common\King's Quest\Binaries\Win\KingsQuest.exe
FirewallRules: [{31B84675-81BF-4394-947F-815AD32A6288}] => (Allow) D:\Steam\steamapps\common\DrinkBox_Game4\Game.exe
FirewallRules: [{D9BC3167-5066-43F0-9FD7-7CDD7910DA8E}] => (Allow) D:\Steam\steamapps\common\DrinkBox_Game4\Game.exe
FirewallRules: [{D4ECB153-C424-4CD0-A70D-401F67D30A5D}] => (Allow) D:\Steam\steamapps\common\Guacamelee\Guac.exe
FirewallRules: [{C00B9462-0FC5-4A42-95C1-1E15D4C62618}] => (Allow) D:\Steam\steamapps\common\Guacamelee\Guac.exe
FirewallRules: [{29DD87A8-F8FC-4BC4-B8D3-E7B2DD2F3D01}] => (Allow) D:\Steam\steamapps\common\Grim Fandango Remastered\GrimFandango.exe
FirewallRules: [{C54E50EF-498D-4683-AC04-FAAE44EBD024}] => (Allow) D:\Steam\steamapps\common\Grim Fandango Remastered\GrimFandango.exe
FirewallRules: [{5E70CF38-D185-4002-B7BE-4B443D898E0B}] => (Allow) D:\Steam\steamapps\common\Geometry Dash\GeometryDash.exe
FirewallRules: [{03B1D084-A9F2-4B6F-A0EF-EF3FB6635E23}] => (Allow) D:\Steam\steamapps\common\Geometry Dash\GeometryDash.exe
FirewallRules: [{2B991ECD-52B7-42EE-96D9-84554DE21821}] => (Allow) D:\Steam\steamapps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe
FirewallRules: [{3F46213D-A04D-443E-8290-D3120206002D}] => (Allow) D:\Steam\steamapps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe
FirewallRules: [{48708460-942D-40F8-BB4B-8ECBB4A35B88}] => (Allow) D:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{A591C18D-231C-4A0B-B179-192968E526C3}] => (Allow) D:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{8CD86956-F917-418A-A12D-6F18519E71E9}] => (Allow) C:\Steam\SteamApps\common\Worms Reloaded\WormsReloaded.exe
FirewallRules: [{28DBF86F-8E00-4FFA-94DA-CD3B0A53A87E}] => (Allow) C:\Steam\SteamApps\common\Worms Reloaded\WormsReloaded.exe
FirewallRules: [{430AD443-9620-473B-AB15-DCF9A7FC71EE}] => (Allow) D:\Steam\steamapps\common\reflexfps\reflex.exe
FirewallRules: [{F979A09A-9AC2-48BC-B7E4-CAADB4F65927}] => (Allow) D:\Steam\steamapps\common\reflexfps\reflex.exe
FirewallRules: [{C2F0BBC3-A299-46B1-86B2-451BDDD55AE0}] => (Allow) C:\Steam\SteamApps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{FDEDC4C5-44BB-4930-B0E4-D33F88B22B5E}] => (Allow) C:\Steam\SteamApps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{E82311DF-100B-4D06-B9F9-88964D641101}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{ED9FA859-D372-4FAD-B2F7-6AD001F63E47}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{77D5DD51-D142-4054-9894-DBD4EC410A3E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{12A6A3CA-AB57-46C7-A81A-F608F506D56A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{09D96CB5-E737-49C2-A555-9537B8E7BFF7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{B7251954-FBB2-4B13-9B8D-CCBB3D232548}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{75719BF4-A39A-4CFA-A06B-F6CD00557C9C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{6F3DB904-B82C-46FA-8C66-A9E01D6DCB0E}D:\ow\overwatch\overwatch.exe] => (Allow) D:\ow\overwatch\overwatch.exe
FirewallRules: [UDP Query User{D63BB14E-CD94-4310-9696-37C2BB06A177}D:\ow\overwatch\overwatch.exe] => (Allow) D:\ow\overwatch\overwatch.exe
FirewallRules: [{7AF4F977-4977-4BB6-B518-9BCE476995EA}] => (Allow) C:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{D4E3A1E6-490D-4E2B-A62B-90308146D692}] => (Allow) C:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{9D848128-727B-4495-895A-AA1A5D46FF6C}] => (Allow) D:\Steam\steamapps\common\insurgency2\insurgency_BE.exe
FirewallRules: [{E8D106E8-0858-4BFE-B602-C01717D25CA3}] => (Allow) D:\Steam\steamapps\common\insurgency2\insurgency_BE.exe
FirewallRules: [{BC467F5D-913B-4E17-AD38-7BD156DD900C}] => (Allow) D:\Steam\steamapps\common\Firewatch\Firewatch.exe
FirewallRules: [{A3E811B1-FD0D-4DEB-B0FA-88F6B0591557}] => (Allow) D:\Steam\steamapps\common\Firewatch\Firewatch.exe
FirewallRules: [TCP Query User{46D838DD-E0D5-41DB-B4C8-11FEB4598CAD}C:\program files (x86)\ea games\need for speed underground 2\speed2.exe] => (Allow) C:\program files (x86)\ea games\need for speed underground 2\speed2.exe
FirewallRules: [UDP Query User{21E7AE44-C694-429E-B155-35D57CD6E308}C:\program files (x86)\ea games\need for speed underground 2\speed2.exe] => (Allow) C:\program files (x86)\ea games\need for speed underground 2\speed2.exe
FirewallRules: [TCP Query User{C11BFD49-D377-497C-A38E-5C642ECC61B5}D:\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe
FirewallRules: [UDP Query User{6FD9DC68-1CF4-4D15-8B61-FF87670708AA}D:\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe
FirewallRules: [TCP Query User{39C3A14E-CD82-48C4-A1F8-3D1A957598B7}D:\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe
FirewallRules: [UDP Query User{C8CD7503-19D5-4602-B8E8-DAF3499BB21F}D:\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe
FirewallRules: [{0745ECE0-0497-4228-9771-BF50235EC526}] => (Allow) D:\Steam\steamapps\common\Spore\SporeBin\SporeApp.exe
FirewallRules: [{1115F3D2-3E0C-4DEC-9902-3C48037E1B88}] => (Allow) D:\Steam\steamapps\common\Spore\SporeBin\SporeApp.exe
FirewallRules: [TCP Query User{94C537B1-85A8-48E6-9CC9-C2FC539AD719}D:\ow\heroes of the storm\versions\base53275\heroesofthestorm_x64.exe] => (Allow) D:\ow\heroes of the storm\versions\base53275\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{A092B134-2403-492B-8B09-0A7772B29AA4}D:\ow\heroes of the storm\versions\base53275\heroesofthestorm_x64.exe] => (Allow) D:\ow\heroes of the storm\versions\base53275\heroesofthestorm_x64.exe
FirewallRules: [TCP Query User{473B0482-49CB-4C2E-99C1-19C3E75727CC}D:\ow\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe] => (Allow) D:\ow\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{DF0B8B8E-880D-4C61-A37F-BAA91EB7AD21}D:\ow\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe] => (Allow) D:\ow\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe
FirewallRules: [{E952F179-957E-4793-AC87-8E5EC3CEE182}] => (Allow) C:\Program Files (x86)\Opera\45.0.2552.812\opera.exe
FirewallRules: [{3A541C4B-8A94-4CF5-AC6B-9B81A02DC80F}] => (Allow) C:\Program Files (x86)\Opera\46.0.2597.57\opera.exe
FirewallRules: [TCP Query User{BEB7A29E-7B99-4194-89C6-3B9915E3F87F}E:\powerline utility\powerline scan.exe] => (Allow) E:\powerline utility\powerline scan.exe
FirewallRules: [UDP Query User{0DBFB59A-73F0-40E9-8F00-F85C69643D39}E:\powerline utility\powerline scan.exe] => (Allow) E:\powerline utility\powerline scan.exe
FirewallRules: [{FC6D42EF-8206-48A9-8D1A-27951BAC895B}] => (Allow) D:\Steam\steamapps\common\Starbound\win64\starbound.exe
FirewallRules: [{3D2306A9-512C-4DDB-BCB4-51CCFD9CA269}] => (Allow) D:\Steam\steamapps\common\Starbound\win64\starbound.exe
FirewallRules: [{B017C7D4-CCA6-48F9-B271-B44BD7BB9501}] => (Allow) D:\Steam\steamapps\common\Starbound\win64\starbound_server.exe
FirewallRules: [{41D7FE44-6326-40C1-86DE-2C7C1265613F}] => (Allow) D:\Steam\steamapps\common\Starbound\win64\starbound_server.exe
FirewallRules: [{69C56AC9-6F61-426C-B122-396F115055F2}] => (Allow) D:\Steam\steamapps\common\Starbound\win64\mod_uploader.exe
FirewallRules: [{2F402C5B-9AFF-4DE8-AA79-1FAF566A5FFD}] => (Allow) D:\Steam\steamapps\common\Starbound\win64\mod_uploader.exe
FirewallRules: [{42089413-99FF-4B46-97B0-21C3AF1FD000}] => (Allow) D:\Steam\steamapps\common\Starbound\win32\starbound.exe
FirewallRules: [{A9CF14DC-00F4-43AE-AA85-CD0714BB112D}] => (Allow) D:\Steam\steamapps\common\Starbound\win32\starbound.exe
FirewallRules: [{C2231EE4-8A2C-40AD-9F03-72F0C1B6F3F5}] => (Allow) D:\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{8A90CBBE-2E3E-448D-9F78-0852FB141B65}] => (Allow) D:\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{7B6E71BC-B336-46DB-9AC5-5AAD1A536F6F}] => (Allow) C:\Steam\SteamApps\common\Shadow Warrior Classic\bin\sw.exe
FirewallRules: [{68CA4298-60D5-4F71-9DC4-738D6CF3AED8}] => (Allow) C:\Steam\SteamApps\common\Shadow Warrior Classic\bin\sw.exe
FirewallRules: [{7695057F-DDB2-47E3-BE75-D87B5035C82F}] => (Allow) C:\Steam\SteamApps\common\Shadow Warrior Classic\bin\dosbox\DOSBox.exe
FirewallRules: [{E1A16F9B-49EB-45E0-8CF4-EA0F2435F601}] => (Allow) C:\Steam\SteamApps\common\Shadow Warrior Classic\bin\dosbox\DOSBox.exe
FirewallRules: [{2C576585-DA11-40A7-80E6-EF2DC10F752B}] => (Allow) D:\Steam\steamapps\common\Age of Mythology\Launcher.exe
FirewallRules: [{F3A7EA33-2BFF-46B2-8DBC-C947C0025EB3}] => (Allow) D:\Steam\steamapps\common\Age of Mythology\Launcher.exe
FirewallRules: [{DDFD86DB-69B2-448E-B346-6412FEBE1E33}] => (Allow) D:\Steam\steamapps\common\Age of Mythology\aomx.exe
FirewallRules: [{62F40750-7BD8-4908-9BE8-D821228686C0}] => (Allow) D:\Steam\steamapps\common\Age of Mythology\aomx.exe
FirewallRules: [{724C8C81-E103-48EF-8F39-20CF5DFAFAD8}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{F3B19163-12DA-455C-956C-F4E19FF9BE43}] => (Allow) C:\Program Files\Opera beta\48.0.2685.11\opera.exe
FirewallRules: [{1BDE588B-A287-4843-A5D3-EB023C4EB7E6}] => (Allow) C:\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E1C22CC3-0FE9-482E-91AD-A61D416114ED}] => (Allow) C:\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7D1AC31D-BFB5-41CE-9AB4-C3B0DD3709E6}] => (Allow) C:\Program Files\Opera beta\48.0.2685.22\opera.exe
FirewallRules: [{179DC97B-6E22-47ED-ABC1-176BB7011EA1}] => (Allow) D:\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe
FirewallRules: [{55590E06-84B3-42B4-8C0E-6FF910F0009F}] => (Allow) D:\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe
 
==================== Restore Points =========================
 
01-09-2017 02:00:04 Automatic creation
02-09-2017 02:00:13 Automatic creation
03-09-2017 02:00:17 Automatic creation
15-09-2017 02:00:10 Automatic creation
16-09-2017 02:00:06 Automatic creation
17-09-2017 02:00:03 Automatic creation
18-09-2017 23:39:45 Automatic creation
 
==================== Faulty Device Manager Devices =============
 
Name: Marvell 91xx Config ATA Device
Description: Marvell 91xx Config ATA Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/18/2017 11:39:42 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {516bb356-a26f-440a-9228-599770391a51}
 
Error: (09/18/2017 11:10:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (09/18/2017 02:53:13 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {a8b16d98-d209-4071-a0eb-d6f06640ffbe}
 
Error: (09/18/2017 02:24:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (09/16/2017 02:26:23 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {4c476cc0-491e-4e2c-a458-b5ef82f95d4a}
 
Error: (09/16/2017 01:57:46 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (09/15/2017 09:52:05 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {bc5ffa5f-92be-42c2-b559-68793a71779f}
 
Error: (09/15/2017 09:23:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (09/15/2017 05:18:51 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {7d3a07a9-134e-451a-b09d-72605fe0570d}
 
Error: (09/15/2017 04:50:12 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
 
System errors:
=============
Error: (09/18/2017 11:09:16 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 11:08:00 PM on ‎9/‎18/‎2017 was unexpected.
 
Error: (09/17/2017 03:49:11 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The WerSvc service was unable to log on as NT AUTHORITY\SYSTEM with the currently configured password due to the following error: 
The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation.
 
 
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
 
Error: (09/16/2017 01:20:16 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Steam Client Service service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (09/16/2017 01:20:16 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
 
Error: (09/15/2017 09:21:59 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000050 (0xfffffa81098db938, 0x0000000000000001, 0xfffff88009a0b57e, 0x0000000000000005). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 091517-34788-01.
 
Error: (09/15/2017 09:21:53 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 9:19:40 PM on ‎9/‎15/‎2017 was unexpected.
 
Error: (09/15/2017 06:45:44 PM) (Source: Schannel) (EventID: 4114) (User: Fire_Fist)
Description: The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The SSL connection request has failed. The attached data contains the server certificate.
 
Error: (09/15/2017 06:45:44 PM) (Source: Schannel) (EventID: 4120) (User: Fire_Fist)
Description: The following fatal alert was generated: 48. The internal error state is 552.
 
Error: (09/15/2017 06:45:35 PM) (Source: Schannel) (EventID: 4114) (User: NT AUTHORITY)
Description: The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The SSL connection request has failed. The attached data contains the server certificate.
 
Error: (09/15/2017 06:45:35 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 48. The internal error state is 552.
 
 
CodeIntegrity:
===================================
  Date: 2017-03-28 09:37:40.977
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-03-28 09:37:40.946
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-03-28 09:37:40.899
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-03-28 09:37:40.868
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-03-28 09:15:52.019
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2017-03-28 09:15:51.973
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7 CPU 950 @ 3.07GHz
Percentage of memory in use: 49%
Total physical RAM: 6142.42 MB
Available physical RAM: 3086.84 MB
Total Virtual: 21496.03 MB
Available Virtual: 16645.89 MB
 
==================== Drives ================================
 
Drive c: (HDD Main) (Fixed) (Total:931.41 GB) (Free:209.87 GB) NTFS
Drive d: (SSD) (Fixed) (Total:223.57 GB) (Free:17.1 GB) NTFS
Drive e: (Guitar Hero World Tour) (CDROM) (Total:6.13 GB) (Free:0 GB) UDF
Drive f: (Fallout 4) (CDROM) (Total:24.47 GB) (Free:0 GB) UDF
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: E9CEE9B3)
Partition 1: (Not Active) - (Size=223.6 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: C232954D)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 


BC AdBot (Login to Remove)

 


#2 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,853 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:05:16 AM

Posted 19 September 2017 - 10:27 AM

Emrbldk:

 
:welcome: to the Bleeping Computer Virus, Trojans, Spyware, and Malware Removal Logs Forum.  My name is Phil.  May I address you by your first name?
 
I will be assisting you with your computer issues.  I will endeavor to respond within a reasonable time, normally 48 hours after your last post.
 
I would ask that you please continue to copy and paste the contents of all requested log files directly into your replies.   Please do not use "code" or "quote" boxes.  Thank you for your anticipated cooperation.
 
I will need some time to review your FRST logs.  That could take a day or two.
 
PLEASE DO NOT RUN ANY ADDITIONAL SCANS OR ANTI-MALWARE REMOVAL TOOLS UNTIL YOU HAVE RECEIVED A RESPONSE FROM ME.
Doing so would complicate the situation and it would cause further delays in resolving your issues.  It could also potentially result in harm to your computer because my "fix" will be based on the FRST scan logs you have already submitted.
 
Thank you and have a great day.
 
Regards,
-Phil

Graduate of the Bleeping Computer Malware Removal Study Hall


#3 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,853 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:05:16 AM

Posted 19 September 2017 - 12:38 PM

emrbldk:

Thank you for your patience while I analyzed your FRST logs.

Before we start dealing with the problems you are experiencing, I would ask that you to take note of the following points:

  • I am a Bleeping Computer volunteer, so I ask you to be patient. I know it is frustrating when your computer is not working properly, but malware removal takes time.
  • Please also remember that I can only dedicate a limited number of hours a day to helping people. We may live in different time zones, which may cause delays in responding.
  • If I have not responded to you within 48 hours, please send me a personal message. Likewise, I expect you to respond within 48 hours, and sooner is better because we can fix your computer faster.
  • If I have not heard from you in three days, I will "bump" your post. After five days of no response, I will consider that you no longer need my assistance and this thread will be closed.
  • Logs can take a while to research, so please be patient.
  • Some issues just cannot be solved so you must be prepared for this.
  • Please read and follow the instructions in the exact sequence that they are posted to avoid making a bad situation worse.
  • Please print or copy and save the instructions.
  • Back up all your data and important files on another (external) drive before starting to run malware removal tools. Malware removal can cause unpredictable and unintended issues.
  • You should try to limit your browsing with this computer until you are given the "All Clear." Some malware applications steal passwords.
  • Please do not install or uninstall any applications, unless directed. Don't run any scripts or tools on your own because unsupervised usage may cause more harm than good.
  • Please use only the tools you have been instructed to use.
  • If you are using CD/DVD emulation software, this should be uninstalled or disabled as it can interfere with the removal of some malware. It can be turned off with Defogger and then turned back on when you get the "All Clear."
  • Please copy and paste the requested log files inside your post(s), unless otherwise instructed. Please do not use code or quote boxes.
  • There are no silly questions. Ask for clarification, if you have any questions or concerns.
  • Bleeping Computer does not support any piracy. Evidence of illegal OS, software, cracks/keygens, etc., will be revealed by scan logs, and if found, further assistance may be suspended. Uninstall such software before proceeding!
  • Any P2P software such as uTorrent, BitTorrent, Kazaa, etc. must be uninstalled or completely disabled. P2P software is a major security risk to your computer and may have been the route the malware used to infect your computer.
  • Failure to follow these guidelines may result in assistance being withdrawn and your thread being closed.
  • I am volunteering my time to help you, and I will need you to help me. Together, we can, hopefully, disinfect your computer and get if functioning properly again. That is my only aim.

.

OK, let's get started ...

:step1: As for Domino.exe, that file is part of a web driver package from Vimicro. It is loaded automatically right now. As a part of my FRST "fixlist" script, I will analyze the file at VirusTotal to see if it is legitimate. Sometime malware impersonates as legitimate programs. See this link for more information.

You have a lot of programs and processes running on your computer, so if it is a laptop, then heat issues could arise, independently of any possible malware infections.

.

:step2: In going over your logs I noticed that you have µTorrent and Vuze installed. Please consider the following advice to reduce the possibility of being infected when surfing the web.

  • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
  • They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
  • Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
  • The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.

It is pretty much certain that if you continue to use P2P programs, your computer will get infected.
I would recommend that you uninstall µTorrent and Vuze, however that choice is up to you. If you choose to remove these programs, you can do so via Start > Control Panel > Add/Remove Programs.
If you wish to keep them, please do not use it until your computer is cleaned.

.

:step3: Please run a FRST fix for me.

NOTICE: This FRST "fixlist" script was written specifically for this user, for use on this individual computer. Running this on another computer may cause damage to your operating system.
 

Start::
CreateRestorePoint:
CloseProcesses:
VirusTotal: C:\Windows\Domino.exe;C:\Users\Asce\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1702150-0-npoctoshape.dll;C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdogoocenkoogpajficlnleblfoelph;C:\Windows\System32\solicall.sys
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
Folder: C:\ComboFix
Folder: C:\1a485692c6c0d46bdbc168
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\atiacm64.dll -> No File
EmptyTemp:
End::
  • Please highlight the entire contents of the code box above, from the "Start::" line to the "End::" line, including both of those lines, right click, and select "Copy", which will copy the "fix" script into the Windows clipboard.
  • Right click FRST64.exe, and select "Run as Administrator", which is located in the C:\Users\Asce\Desktop\New folder (2) folder.
  • Press Fix button once and wait.
  • Please reboot the computer, if requested.
  • A log file called "fixlog.txt" will be saved in the same folder as the FRST program is located.
  • Please copy and paste the contents of the "fixlog.txt" file into your next reply.

.

I have noted other non-critical issues with your computer, but we will deal with them after we have run a full suite of anti-malware scans on your computer in subsequent posts.

Thank you and have a great day.

Regards,
-Phil


Graduate of the Bleeping Computer Malware Removal Study Hall


#4 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,853 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:05:16 AM

Posted 22 September 2017 - 11:30 AM

emrbldk:

 
Are you still there?  Do you still require assistance?  It has been three days since I last posted to you.
 
According to Forum policy, topics must be concluded after five days of non-response from the Topic Starter.
 
If I have not heard from you in another two days, I will conclude your topic.  You can always reopen it by sending a Personal Message to a Moderator.
 
Thank you and have a great day.
 
Regards,
-Phil

Graduate of the Bleeping Computer Malware Removal Study Hall


#5 Emrbldk

Emrbldk
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:11:16 AM

Posted 23 September 2017 - 08:36 AM

Hello there my first name is Cem.

 

I have used defrogger and run the fix you asked for me.
 

Fix result of Farbar Recovery Scan Tool (x64) Version: 23-09-2017 02
Ran by Asce (23-09-2017 16:30:32) Run:2
Running from C:\Users\Asce\Desktop\New folder (2)
Loaded Profiles: Asce (Available Profiles: Asce)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
VirusTotal: C:\Windows\Domino.exe;C:\Users\Asce\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1702150-0-npoctoshape.dll;C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdogoocenkoogpajficlnleblfoelph;C:\Windows\System32\solicall.sys
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
Folder: C:\ComboFix
Folder: C:\1a485692c6c0d46bdbc168
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\atiacm64.dll -> No File
EmptyTemp:
 
*****************
 
Restore point was successfully created.
Processes closed successfully.
VirusTotal: C:\Users\Asce\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1702150-0-npoctoshape.dll => https://www.virustotal.com/file/0e33fe8609e6d696c5b11202c8d73a8317bcfe7fad2c8bc653eccf60c9390441/analysis/1504506550/
VirusTotal: C:\Users\Asce\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdogoocenkoogpajficlnleblfoelph => D41D8CD98F00B204E9800998ECF8427E (0-byte MD5)
HKLM\SOFTWARE\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek => key removed successfully
 
========================= Folder: C:\ComboFix ========================
 
not found.
 
====== End of Folder: ======
 
 
========================= Folder: C:\1a485692c6c0d46bdbc168 ========================
 
2013-08-06 12:56 - 2013-08-06 12:56 - 000016118 ____N () C:\1a485692c6c0d46bdbc168\DHtmlHeader.html
2013-08-06 12:57 - 2013-08-06 12:57 - 000088533 ____N () C:\1a485692c6c0d46bdbc168\DisplayIcon.ico
2013-08-06 12:31 - 2013-08-06 12:31 - 000003628 ____N () C:\1a485692c6c0d46bdbc168\header.bmp
2013-08-06 12:50 - 2013-08-06 12:50 - 001901056 ____N () C:\1a485692c6c0d46bdbc168\netfx_core_x64.msi
2013-08-06 12:50 - 2013-08-06 12:50 - 001163264 ____N () C:\1a485692c6c0d46bdbc168\netfx_core_x86.msi
2013-08-06 12:50 - 2013-08-06 12:50 - 000872448 ____N () C:\1a485692c6c0d46bdbc168\netfx_extended_x64.msi
2013-08-06 12:50 - 2013-08-06 12:50 - 000495616 ____N () C:\1a485692c6c0d46bdbc168\netfx_extended_x86.msi
2013-08-14 03:20 - 2013-08-14 03:20 - 213391774 ____N () C:\1a485692c6c0d46bdbc168\netfx_Full_GDR.mzz
2013-08-14 03:25 - 2013-08-14 03:25 - 001544192 ____N () C:\1a485692c6c0d46bdbc168\netfx_Full_GDR_x64.msi
2013-08-14 02:58 - 2013-08-14 02:58 - 000921600 ____N () C:\1a485692c6c0d46bdbc168\netfx_Full_GDR_x86.msi
2017-08-27 02:54 - 2017-08-27 02:54 - 213391534 _____ () C:\1a485692c6c0d46bdbc168\netfx_Full_LDR.mzz
2013-08-13 15:46 - 2013-08-13 15:46 - 001548288 ____N () C:\1a485692c6c0d46bdbc168\netfx_Full_LDR_x64.msi
2013-08-13 15:26 - 2013-08-13 15:26 - 000925696 ____N () C:\1a485692c6c0d46bdbc168\netfx_Full_LDR_x86.msi
2013-08-06 12:50 - 2013-08-06 12:50 - 001531904 ____N () C:\1a485692c6c0d46bdbc168\netfx_Full_x64.msi
2013-08-06 12:50 - 2013-08-06 12:50 - 000901120 ____N () C:\1a485692c6c0d46bdbc168\netfx_Full_x86.msi
2013-08-30 07:23 - 2013-08-30 07:23 - 002425082 ____N () C:\1a485692c6c0d46bdbc168\ParameterInfo.xml
2013-08-13 19:44 - 2013-08-13 19:44 - 000088128 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\Setup.exe
2013-08-13 19:44 - 2013-08-13 19:44 - 000889440 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\SetupEngine.dll
2013-08-13 19:44 - 2013-08-13 19:44 - 000306768 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\SetupUi.dll
2013-08-06 12:38 - 2013-08-06 12:38 - 000030120 ____N () C:\1a485692c6c0d46bdbc168\SetupUi.xsd
2013-08-13 19:44 - 2013-08-13 19:44 - 000119392 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\SetupUtility.exe
2013-08-06 12:57 - 2013-08-06 12:57 - 000041080 ____N () C:\1a485692c6c0d46bdbc168\SplashScreen.bmp
2013-08-06 12:50 - 2013-08-06 12:50 - 000196416 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\sqmapi.dll
2013-08-06 12:57 - 2013-08-06 12:57 - 000014084 ____N () C:\1a485692c6c0d46bdbc168\Strings.xml
2013-08-06 12:57 - 2013-08-06 12:57 - 000038910 ____N () C:\1a485692c6c0d46bdbc168\UiInfo.xml
2013-08-06 12:31 - 2013-08-06 12:31 - 000104072 ____N () C:\1a485692c6c0d46bdbc168\watermark.bmp
2013-08-06 12:50 - 2013-08-06 12:50 - 007278068 ____N () C:\1a485692c6c0d46bdbc168\Windows6.0-KB956250-v6001-x64.msu
2013-08-06 12:50 - 2013-08-06 12:50 - 004270292 ____N () C:\1a485692c6c0d46bdbc168\Windows6.0-KB956250-v6001-x86.msu
2013-08-06 12:50 - 2013-08-06 12:50 - 007167139 ____N () C:\1a485692c6c0d46bdbc168\Windows6.1-KB958488-v6001-x64.msu
2013-08-06 12:50 - 2013-08-06 12:50 - 004219350 ____N () C:\1a485692c6c0d46bdbc168\Windows6.1-KB958488-v6001-x86.msu
2013-08-16 06:47 - 2013-08-16 06:47 - 917457474 ____N () C:\1a485692c6c0d46bdbc168\Windows8-RT-KB2872772-x64.msu
2013-08-16 05:44 - 2013-08-16 05:44 - 709783726 ____N () C:\1a485692c6c0d46bdbc168\Windows8-RT-KB2872772-x86.msu
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1025
2013-08-06 12:31 - 2013-08-06 12:31 - 000046493 ____N () C:\1a485692c6c0d46bdbc168\1025\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000075204 ____N () C:\1a485692c6c0d46bdbc168\1025\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000028776 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1025\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1028
2013-08-06 12:31 - 2013-08-06 12:31 - 000035212 ____N () C:\1a485692c6c0d46bdbc168\1028\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000065148 ____N () C:\1a485692c6c0d46bdbc168\1028\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000025200 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1028\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1029
2013-08-06 12:31 - 2013-08-06 12:31 - 000022633 ____N () C:\1a485692c6c0d46bdbc168\1029\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000080596 ____N () C:\1a485692c6c0d46bdbc168\1029\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000029800 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1029\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1030
2013-08-06 12:31 - 2013-08-06 12:31 - 000017407 ____N () C:\1a485692c6c0d46bdbc168\1030\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000078296 ____N () C:\1a485692c6c0d46bdbc168\1030\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000029296 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1030\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1031
2013-08-06 12:31 - 2013-08-06 12:31 - 000020790 ____N () C:\1a485692c6c0d46bdbc168\1031\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000082528 ____N () C:\1a485692c6c0d46bdbc168\1031\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000030320 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1031\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1032
2013-08-06 12:31 - 2013-08-06 12:31 - 000059104 ____N () C:\1a485692c6c0d46bdbc168\1032\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000084138 ____N () C:\1a485692c6c0d46bdbc168\1032\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000030832 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1032\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1033
2013-08-06 12:31 - 2013-08-06 12:31 - 000015658 ____N () C:\1a485692c6c0d46bdbc168\1033\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000078042 ____N () C:\1a485692c6c0d46bdbc168\1033\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000028784 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1033\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1035
2013-08-06 12:31 - 2013-08-06 12:31 - 000019917 ____N () C:\1a485692c6c0d46bdbc168\1035\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000078884 ____N () C:\1a485692c6c0d46bdbc168\1035\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000029808 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1035\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1036
2013-08-06 12:31 - 2013-08-06 12:31 - 000020358 ____N () C:\1a485692c6c0d46bdbc168\1036\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000082546 ____N () C:\1a485692c6c0d46bdbc168\1036\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000030320 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1036\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1037
2013-08-06 12:31 - 2013-08-06 12:31 - 000042177 ____N () C:\1a485692c6c0d46bdbc168\1037\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000073696 ____N () C:\1a485692c6c0d46bdbc168\1037\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000027760 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1037\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1038
2013-08-06 12:31 - 2013-08-06 12:31 - 000025032 ____N () C:\1a485692c6c0d46bdbc168\1038\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000081400 ____N () C:\1a485692c6c0d46bdbc168\1038\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000030320 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1038\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1040
2013-08-06 12:31 - 2013-08-06 12:31 - 000020366 ____N () C:\1a485692c6c0d46bdbc168\1040\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000080374 ____N () C:\1a485692c6c0d46bdbc168\1040\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000029808 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1040\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1041
2013-08-06 12:31 - 2013-08-06 12:31 - 000057527 ____N () C:\1a485692c6c0d46bdbc168\1041\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000070550 ____N () C:\1a485692c6c0d46bdbc168\1041\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000026736 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1041\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1042
2013-08-06 12:31 - 2013-08-06 12:31 - 000054978 ____N () C:\1a485692c6c0d46bdbc168\1042\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000069038 ____N () C:\1a485692c6c0d46bdbc168\1042\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000026224 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1042\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1043
2013-08-06 12:31 - 2013-08-06 12:31 - 000018132 ____N () C:\1a485692c6c0d46bdbc168\1043\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000080028 ____N () C:\1a485692c6c0d46bdbc168\1043\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000030832 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1043\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1044
2013-08-06 12:31 - 2013-08-06 12:31 - 000017050 ____N () C:\1a485692c6c0d46bdbc168\1044\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000079720 ____N () C:\1a485692c6c0d46bdbc168\1044\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000029296 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1044\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1045
2013-08-06 12:31 - 2013-08-06 12:31 - 000025098 ____N () C:\1a485692c6c0d46bdbc168\1045\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000082236 ____N () C:\1a485692c6c0d46bdbc168\1045\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000029808 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1045\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1046
2013-08-06 12:31 - 2013-08-06 12:31 - 000018623 ____N () C:\1a485692c6c0d46bdbc168\1046\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000079372 ____N () C:\1a485692c6c0d46bdbc168\1046\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000029808 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1046\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1049
2013-08-06 12:31 - 2013-08-06 12:31 - 000061439 ____N () C:\1a485692c6c0d46bdbc168\1049\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000080672 ____N () C:\1a485692c6c0d46bdbc168\1049\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000029808 ____N (Корпорация Майкрософт) C:\1a485692c6c0d46bdbc168\1049\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1053
2013-08-06 12:31 - 2013-08-06 12:31 - 000020692 ____N () C:\1a485692c6c0d46bdbc168\1053\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000078204 ____N () C:\1a485692c6c0d46bdbc168\1053\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000029296 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1053\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\1055
2013-08-06 12:31 - 2013-08-06 12:31 - 000023716 ____N () C:\1a485692c6c0d46bdbc168\1055\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000078340 ____N () C:\1a485692c6c0d46bdbc168\1055\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000029296 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\1055\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\2052
2013-08-06 12:31 - 2013-08-06 12:31 - 000034193 ____N () C:\1a485692c6c0d46bdbc168\2052\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000065102 ____N () C:\1a485692c6c0d46bdbc168\2052\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000024688 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\2052\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\2070
2013-08-06 12:31 - 2013-08-06 12:31 - 000019162 ____N () C:\1a485692c6c0d46bdbc168\2070\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000080926 ____N () C:\1a485692c6c0d46bdbc168\2070\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000029808 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\2070\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\3082
2013-08-06 12:31 - 2013-08-06 12:31 - 000018653 ____N () C:\1a485692c6c0d46bdbc168\3082\eula.rtf
2013-08-30 07:16 - 2013-08-30 07:16 - 000080340 ____N () C:\1a485692c6c0d46bdbc168\3082\LocalizedData.xml
2013-08-13 20:56 - 2013-08-13 20:56 - 000030320 ____N (Microsoft Corporation) C:\1a485692c6c0d46bdbc168\3082\SetupResources.dll
2017-08-27 02:54 - 2017-08-27 02:54 - 000000000 ____D () C:\1a485692c6c0d46bdbc168\Graphics
2013-08-06 12:56 - 2013-08-06 12:56 - 000001150 ____N () C:\1a485692c6c0d46bdbc168\Graphics\Print.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000000894 ____N () C:\1a485692c6c0d46bdbc168\Graphics\Rotate1.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000000894 ____N () C:\1a485692c6c0d46bdbc168\Graphics\Rotate2.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000000894 ____N () C:\1a485692c6c0d46bdbc168\Graphics\Rotate3.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000000894 ____N () C:\1a485692c6c0d46bdbc168\Graphics\Rotate4.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000000894 ____N () C:\1a485692c6c0d46bdbc168\Graphics\Rotate5.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000000894 ____N () C:\1a485692c6c0d46bdbc168\Graphics\Rotate6.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000000894 ____N () C:\1a485692c6c0d46bdbc168\Graphics\Rotate7.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000000894 ____N () C:\1a485692c6c0d46bdbc168\Graphics\Rotate8.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000001150 ____N () C:\1a485692c6c0d46bdbc168\Graphics\Save.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000036710 ____N () C:\1a485692c6c0d46bdbc168\Graphics\Setup.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000010134 ____N () C:\1a485692c6c0d46bdbc168\Graphics\stop.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000001150 ____N () C:\1a485692c6c0d46bdbc168\Graphics\SysReqMet.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000001150 ____N () C:\1a485692c6c0d46bdbc168\Graphics\SysReqNotMet.ico
2013-08-06 12:56 - 2013-08-06 12:56 - 000010134 ____N () C:\1a485692c6c0d46bdbc168\Graphics\warn.ico
 
====== End of Folder: ======
 
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\ACE => key removed successfully
HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} => key removed successfully
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 60210619 B
Java, Flash, Steam htmlcache => 450123081 B
Windows/system/drivers => 21474984 B
Edge => 0 B
Chrome => 342349805 B
Firefox => 0 B
Opera => 406186223 B
 
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 33186 B
systemprofile32 => 33618 B
LocalService => 66228 B
NetworkService => 8981 B
Asce => 326505372 B
 
RecycleBin => 567721563 B
EmptyTemp: => 2 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 16:31:53 ====


#6 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,853 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:05:16 AM

Posted 23 September 2017 - 12:44 PM

Cem:
 
Thank you for permission to address you by your first name.  From my research, Domino.exe is related to webcam software from Vimicro; please see this link for more details.  As such, it is not nefarious and should be loading a task to enable the webcam software to function.

OK, let's run some standard anti-malware scans.

.

:step1: ESET Online Scanner using Internet Explorer:

Note: You will need to disable your currently installed Anti-Virus, how to do so can be found here.

  • Download esetsmartinstaller_enu.exe and save it to your Desktop.
  • Double click the icon.
  • Check YES, I accept the Terms of Use.
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Then select: "Enable detection of potentially unwanted applications" - Yes.
  • Click Advanced settings.
  • Check the following items.

Enable detection of potentially unwanted applications
Remove found threats
Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology

  • Click Change next to Current scan targets:
  • Place a check mark in any additional drive you wish to scan then click OK.
  • Click Start.
  • ESET will then download updates and begin scanning your computer.
  • If no threats are found simply click Uninstall application on close and hit Finish.
  • If threats are found click List of found threats.
  • Click Export to text file.
  • Save the file on your Desktop as ESET.txt.
  • Click Back.
  • Check Uninstall application on close and Delete quarantined files.
  • Click Finish.
  • Close the ESET Online Scanner window.
  • Copy and paste the contents of ESET.txt into your reply, if any threats were detected.

Don't forget to re-enable your antivirus when finished!

.

:step2: Please run a Malwarebytes Anti-Malware scan for me. The version that you have installed on your computer is out-of-date.

  • Please download Malwarebytes to your Desktop.
  • Double-click mb3-setup-{version}.exe and follow the prompts to install the program.
  • Then click Finish.
  • Next, please go to "Settings", "Protection", and turn on "Scan for rootkits", if it is not "On."
  • Ensure that under "Potential Threat Protection", both switches are set to "Always Detect PUPs/PUMs (recommended).
  • Then scroll to the bottom of that page and ensure that "Automatic Quarantine" is turned "On."
  • Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
  • If an update of the definitions is available, it will be downloaded and installed before the scan commences.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.

The Scan log is available through History ->Application logs. Please copy and paste the contents of the log into your next reply.

.

Thank you and have a great day.

Regards,
-Phil


Graduate of the Bleeping Computer Malware Removal Study Hall


#7 Emrbldk

Emrbldk
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:11:16 AM

Posted 25 September 2017 - 01:18 PM

hellooo again here are the scans you asked from me.

 

C:\Program Files (x86)\Cheat Engine 6.4\standalonephase1.dat a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application cleaned by deleting
C:\The Sims 4\Game\Bin\rld.dll Win32/HackTool.Crack.CY potentially unsafe application cleaned by deleting
C:\The Sims 4\Game\Bin\RldOrigin.dll a variant of Win32/HackTool.Crack.DK potentially unsafe application cleaned by deleting
C:\The Sims 4\Game\Bin\Game\Bin\RldOrigin.dll a variant of Win32/HackTool.Crack.DK potentially unsafe application cleaned by deleting
C:\Users\Asce\Desktop\InfiniteRearm4_V1.9_Timesurfer.exe a variant of Win32/Adware.YoBrowser.M application cleaned by deleting
C:\Users\Asce\Desktop\The Sims 4 - Get to Work.rar a variant of Win32/HackTool.Crack.DK potentially unsafe application deleted
C:\Users\Asce\Desktop\New folder (2)\desktop\asd\uTorrent_3_4_2_32126.exe a variant of Win32/AdkDLLWrapper.A potentially unwanted application cleaned by deleting
C:\Users\Asce\Downloads\BFME2 All-In-One Patch Installer & Switcher v.1.4.exe a variant of Win32/Packed.HTWOO suspicious application cleaned by deleting
C:\Users\Asce\Downloads\cbsidlm-cbsi188-SWF_Extractor-ORG-10073445.exe a variant of Win32/CNETInstaller.B potentially unwanted application cleaned by deleting
C:\Users\Asce\Downloads\FL Studio Producer Edition 12.0.2.rar a variant of Win32/OpenCandy.A potentially unsafe application deleted
C:\Users\Asce\Downloads\FL Studio Producer Edition 12.0.2 + Plugins Bundle\flstudio_12.0.2.exe a variant of Win32/OpenCandy.A potentially unsafe application cleaned by deleting
C:\Users\Asce\Downloads\FL Studio Producer Edition 12.0.2 + Plugins Bundle\R2R\ImageLine_Keygen.exe Win32/Keygen.MI potentially unsafe application cleaned by deleting
C:\Users\Asce\Downloads\Windows 8.1 Update 1 Pro X64 PreActivated\Windows 8.1 Update 1 Pro X64 PreActivated.iso a variant of MSIL/HackTool.IdleKMS.C potentially unsafe application deleted
 
 
 
Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 9/25/17
Scan Time: 8:53 PM
Log File: 6ea3df2c-a21a-11e7-8157-00ffba0acfcb.json
Administrator: Yes
 
-Software Information-
Version: 3.2.2.2029
Components Version: 1.0.188
Update Package Version: 1.0.2882
License: Trial
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Fire_Fist\Asce
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 324838
Threats Detected: 1
Threats Quarantined: 0
(No malicious items detected)
Time Elapsed: 16 min, 8 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 1
PUP.Optional.BundleInstaller, C:\USERS\ASCE\DOWNLOADS\VLC-2.1.3-WIN32.EXE, No Action By User, [20], [425688],1.0.2882
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)


#8 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,853 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:05:16 AM

Posted 26 September 2017 - 04:48 AM

Cem:
 
Thank you for your logs.  Would you please make sure that "Automatic Quarantine" is set to "On".  A PUP was detected by your Malwarebytes scan, but not quarantined.  Please re-run the Malwarebytes scan and post the results.
 
OK, let's do a few more standard anti-malware scans.
 
.
 
:step1: Please download AdwCleaner by Malwarebytes and save the file to your Desktop.

  • Vista/Windows 7/8/10 users right-click and select Run As Administrator
  • The tool will start to update the database, please wait for it to complete the update.
  • Click on I Agree button.
  • Click on the Scan button.
  • AdwCleaner will begin its scan ... please be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Logfile button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, then make sure that you uncheck it before running the "Clean" process.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
  • After the scan has finished ...
  • Uncheck any PUP and adware applications that you want to keep.


If you are unsure about one or more of the detected programs, then please copy and paste the scan log, with your questions, and I will provide you with advice about those files.
The Scan logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
Do not follow the remaining instructions until directed to do so by me. If you have no questions about any of the detections, then please proceed to the "Clean" steps below.

  • Then click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Please copy and paste the contents of that logfile into your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

.

:step2: Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Please copy and paste the contents of JRT.txt into your next message.

.

Thank you and have a great day.

Regards,
-Phil


Graduate of the Bleeping Computer Malware Removal Study Hall


#9 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,853 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:05:16 AM

Posted 29 September 2017 - 11:04 AM

Cem:

 
Are you still there?  Do you still require assistance?  It has been three days since I last posted to you.
 
According to Forum policy, topics must be concluded after five days of non-response from the Topic Starter.
 
If I have not heard from you in another two days, I will conclude your topic.  You can always reopen it by sending a Personal Message to a Moderator.
 
Thank you and have a great day.
 
Regards,
-Phil

Graduate of the Bleeping Computer Malware Removal Study Hall


#10 garioch7

garioch7

    RCMP Veteran


  • Malware Response Instructor
  • 3,853 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Port Hood, Nova Scotia, Canada
  • Local time:05:16 AM

Posted 01 October 2017 - 05:52 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

Graduate of the Bleeping Computer Malware Removal Study Hall





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users