Hey guys, need help to remove kms r@in in my pc.. my brother download it from some website and didn’t check with me first before installing.. now my chrome will sometimes open itself and redirect to some web..
been reading a post regarding the same problem but i think i need to post some log from FRST scan?
already have the FRST ready and below is the FRST log and Addition log..
FRST LOG
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-04-2017
Ran by Winata (administrator) on WINATA-PC (26-04-2017 19:18:34)
Running from C:\Users\Winata\Downloads
Loaded Profiles: Winata (Available Profiles: Winata)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
(Smadsoft) C:\Program Files (x86)\SMADAV\SMΔRTP.exe
() C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe
() C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMR\AODMR.exe
() C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler.ex e
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler64. exe
() C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlServi ce.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.06.28\AsusFanCo ntrolService.exe
(ASUSTeK) C:\Program Files (x86)\ASUS\ROG Game First III\AsusGameFirstService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvr64.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BBSvc.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
() C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNoticeMonitor.exe
() C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotify_PCCtrl.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
() E:\New DNSCript\dnscrypt-proxy.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Spotify Ltd) C:\Users\Winata\AppData\Roaming\Spotify\Spotify.ex e
(Hammer & Chisel, Inc.) C:\Users\Winata\AppData\Local\Discord\app-0.0.297\Discord.exe
(Spotify Ltd) C:\Users\Winata\AppData\Roaming\Spotify\SpotifyWeb Helper.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
(Intel® Corporation) C:\Program Files\Intel\ConnectCenter\bin\CCFManager.exe
(Hammer & Chisel, Inc.) C:\Users\Winata\AppData\Local\Discord\app-0.0.297\Discord.exe
(Spotify Ltd) C:\Users\Winata\AppData\Roaming\Spotify\Spotify.ex e
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\AsusWSPanel.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
(FNet Co., Ltd.) C:\Program Files (x86)\ASUSRAMCACHE\RamCache.exe
() C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\ShareEdit.exe
() C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AODMS.exe
() C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\ASUSWSAgent.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Scarlet.Crush Productions) C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe
(Spotify Ltd) C:\Users\Winata\AppData\Roaming\Spotify\Spotify.ex e
(WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
(Nico Mak Computing) C:\Program Files\WinZip\FAH\FAHWindow64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Spotify Ltd) C:\Users\Winata\AppData\Roaming\Spotify\Spotify.ex e
(Hammer & Chisel, Inc.) C:\Users\Winata\AppData\Local\Discord\app-0.0.297\Discord.exe
(Spotify Ltd) C:\Users\Winata\AppData\Roaming\Spotify\Spotify.ex e
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EX E
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Pro\DiscSoftBusService.exe
(Intel Corporation) C:\Program Files\Intel\STCServ\STCServ.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\AsPowerBar.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\SeaPort.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.ex e
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8495320 2015-06-23] (Realtek Semiconductor)
HKLM...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM...\Run: [IntelConnectCenter] => C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe [90112 2015-03-16] (Intel® Corporation)
HKLM...\Run: [ShadowPlay] => “C:\Windows\system32\rundll32.exe” C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSyst emStart
HKLM-x32...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [296216 2015-06-15] (Intel Corporation)
HKLM-x32...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\AsusWSPanel.exe [5247272 2014-12-04] (ASUS Cloud Corporation)
HKLM-x32...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2015-05-02] (Adobe Systems Incorporated)
HKLM-x32...\Run: [ASUS AiChargerPlus Execute] => C:\Program Files (x86)\InstallShield Installation Information{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [550272 2013-01-28] (ASUSTek Computer Inc.)
HKLM-x32...\Run: [AO Link Server] => C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ALRun.exe -start
HKLM-x32...\Run: [ASUSRAMCACHE] => C:\Program Files (x86)\ASUSRAMCACHE\RamCache.exe [4325520 2016-06-18] (FNet Co., Ltd.)
HKLM-x32...\Run: [ASUS Media Streamer ShareEdit] => C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\ShareEdit.exe [1194808 2015-07-07] ()
HKLM-x32...\Run: [ASUS Media Streamer DMS] => C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AODMS.exe [2569528 2015-07-07] ()
HKLM-x32...\Run: [ASUS Media Streamer WSAgent] => C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\ASUSWSAgent.exe [86840 2015-06-03] ()
HKLM-x32...\Run: [SMΔRT-Protection] => C:\Program Files (x86)\Smadav\SMΔRTP.exe [1772072 2016-06-02] (Smadsoft)
HKLM-x32...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [28344776 2017-04-17] (Dropbox, Inc.)
HKLM-x32...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [DAEMON Tools Pro Agent] => C:\Program Files\DAEMON Tools Pro\DTAgent.exe [4809048 2015-07-08] (Disc Soft Ltd)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [Steam] => D:\Steam\steam.exe [3019552 2017-04-21] (Valve Corporation)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [Spotify] => C:\Users\Winata\AppData\Roaming\Spotify\Spotify.ex e [7064176 2017-04-20] (Spotify Ltd)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [Discord] => C:\Users\Winata\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [Spotify Web Helper] => C:\Users\Winata\AppData\Roaming\Spotify\SpotifyWeb Helper.exe [1446000 2017-04-20] (Spotify Ltd)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4299968 2016-06-22] (Disc Soft Ltd)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3952696 2016-08-07] (Tonec Inc.)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [tdjyffwnaz] => explorer “hxxp://granena.ru/?utm_source=uoua03n&utm_content=e739009bccd5f1e6d7 1a91bff5994529&utm_term=A258243365F0EEA53DBB816BF5 3FF461&utm_d=20170419” <===== ATTENTION
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\MountPoints2: {02dfea50-6e70-11e6-b138-9c5c8e98605f} - J:\Startup.exe
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\MountPoints2: {3c72b88a-35b9-11e6-b9fb-806e6f6e6963} - F:\Bin\Instv2.exe
ShellIconOverlayIdentifiers: [ DropboxExt01] → {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] → {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] → {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] → {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] → {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] → {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] → {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] → {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] → {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] → {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ IDM Shell Extension] → {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] → {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.1.15.458\ASUSWSShellExt64.dll [2014-11-18] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] → {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.1.15.458\ASUSWSShellExt64.dll [2014-11-18] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] → {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.1.15.458\ASUSWSShellExt64.dll [2014-11-18] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] → {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] → {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] → {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] → {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] → {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] → {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] → {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] → {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] → {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] → {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2016-06-18]
ShortcutTarget: FAH.lnk → C:\Program Files\WinZip\FAH\FAHConsole.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScpToolkit Tray Notifications.lnk [2017-02-22]
ShortcutTarget: ScpToolkit Tray Notifications.lnk → C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe (Scarlet.Crush Productions)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2016-06-18]
ShortcutTarget: WinZip Preloader.lnk → C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
Startup: C:\Users\Winata\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 1050 J410 series.lnk [2017-02-02]
GroupPolicy: Restriction <======= ATTENTION
GroupPolicy\User: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
AutoConfigURL: [S-1-5-21-4254750808-1728920065-3872038573-1000] => hxxp://access-webs.biz/wpad.dat?3a085ef046b6d79c4ede521163213b5128895807
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip..\Interfaces{9821328F-5470-4A54-A1E3-627A2C55E86A}: [NameServer] 127.0.0.1
Tcpip..\Interfaces{9821328F-5470-4A54-A1E3-627A2C55E86A}: [DhcpNameServer] 192.168.1.1
ManualProxies: 0hxxp://access-webs.biz/wpad.dat?3a085ef046b6d79c4ede521163213b5128895807
[HEADING=1]Internet Explorer:[/HEADING]
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000\Software\Microsoft\Internet Explorer\Main,Start Page =
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://u.msn.com/id-id/?ocid=iehp
SearchScopes: HKU\S-1-5-21-4254750808-1728920065-3872038573-1000 → DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL =
BHO: IDM integration (IDMIEHlprObj Class) → {0055C089-8582-441B-A0BF-17B458C2A3A8} → C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2016-07-13] (Internet Download Manager, Tonec Inc.)
BHO: Lync Browser Helper → {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} → C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-04-10] (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper → {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} → C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-11-24] (Oracle Corporation)
BHO: Office Document Cache Handler → {B4F3A835-0E21-4959-BA22-42B3008E02FF} → C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2017-04-10] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper → {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} → C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-04-10] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper → {DBC80044-A445-435b-BC74-9C25C1C588A9} → C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-24] (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) → {0055C089-8582-441B-A0BF-17B458C2A3A8} → C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2016-07-13] (Internet Download Manager, Tonec Inc.)
BHO-x32: Lync Browser Helper → {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} → C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper → {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} → C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-23] (Oracle Corporation)
BHO-x32: Office Document Cache Handler → {B4F3A835-0E21-4959-BA22-42B3008E02FF} → C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2017-04-10] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper → {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} → C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-04-10] (Microsoft Corporation)
BHO-x32: Bing Bar Helper → {d2ce3e00-f94a-4740-988e-03dc2f38c34f} → C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll [2012-01-25] (Microsoft Corporation.)
BHO-x32: Java™ Plug-In 2 SSV Helper → {DBC80044-A445-435b-BC74-9C25C1C588A9} → C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-23] (Oracle Corporation)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll [2012-01-25] (Microsoft Corporation.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-06] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-06] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-06] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-06] (Microsoft Corporation)
[HEADING=1]FireFox:[/HEADING]
FF ProfilePath: C:\Users\Winata\AppData\Roaming\Mozilla\Firefox\Pr ofiles\pM5L0zpg.default [2017-04-19]
FF Extension: (Avira Browser Safety) - C:\Users\Winata\AppData\Roaming\Mozilla\Firefox\Pr ofiles\pM5L0zpg.default\Extensions\abs@avira.com [2016-06-19]
FF HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Winata\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Winata\AppData\Roaming\IDM\idmmzcc5 [2017-04-26] [not signed]
FF HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2016-08-03]
FF Plugin: @java.com/DTPlugin,version=11.111.2 → C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1 .dll [2016-11-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.111.2 → C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-24] (Oracle Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 → C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater → C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 → C:\Windows\SysWOW64\npDeployJava1.dll [2016-06-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 → C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-23] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 → C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-03-06] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 → C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-03-06] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision → C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-03-17] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming → C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-03-17] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 → C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 → C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 → C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader → C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-02] (Adobe Systems Inc.)
[HEADING=1]Chrome:[/HEADING]
CHR StartupUrls: Default → “hxxp://www.google.com/”
CHR Profile: C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default [2017-04-26]
CHR Extension: (Google Slides) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhon fmgoek [2016-06-18]
CHR Extension: (Google Docs) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfi lokake [2016-06-18]
CHR Extension: (Google Drive) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigk jlhalf [2016-06-18]
CHR Extension: (Eredan iTCG) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdakdeclmfcolipiknbfealnjd dfibfo [2016-06-18]
CHR Extension: (YouTube) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldk acnbeo [2016-06-18]
CHR Extension: (Realm of the Mad God) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjfmaldpppkmjjgkmadddbanp abfflp [2016-06-18]
CHR Extension: (Google Sheets) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpeb giejap [2016-06-18]
CHR Extension: (Google Docs Offline) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdl olhkhi [2016-06-18]
CHR Extension: (Marvel Comics) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjhfaknohpjconjoefidanhiho kmkice [2016-06-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccm gmieda [2017-03-09]
CHR Extension: (Gmail) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoe jaedia [2016-06-18]
CHR Extension: (Chrome Media Router) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm [2017-04-25]
CHR HKLM...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-08-05]
CHR HKLM-x32...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-08-05]
[HEADING=1]Opera:[/HEADING]
OPR Extension: (No Name) - C:\Users\Winata\AppData\Roaming\Opera Software\Opera Stable\Extensions\ahggfmgiidlaceichjfemgbaggnbaloe [2017-04-19]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2014-07-23] ()
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe [954648 2015-05-08] (ASUSTeK Computer Inc.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlServi ce.exe [1360016 2014-07-23] () [File not signed]
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.06.28\AsusFanCo ntrolService.exe [398648 2015-07-06] (ASUSTeK Computer Inc.)
R2 AsusGameFirstService; C:\Program Files (x86)\ASUS\ROG Game First III\AsusGameFirstService.exe [356632 2015-06-10] (ASUSTeK)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1457160 2016-10-13] ()
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3736768 2017-04-09] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-13] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-13] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [48944 2017-04-17] (Dropbox, Inc.)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072 2016-06-22] (Disc Soft Ltd)
R3 Disc Soft Pro Bus Service; C:\Program Files\DAEMON Tools Pro\DiscSoftBusService.exe [1281368 2015-07-08] (Disc Soft Ltd)
R2 dnscrypt-proxy; E:\New DNSCript\dnscrypt-proxy.exe [258062 2013-09-15] () [File not signed]
S2 Ds3Service; C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpService.exe [389632 2016-01-10] (Scarlet.Crush Productions) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [33640 2017-04-07] (HP Inc.)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223520 2015-07-10] (Intel Corporation)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [455616 2016-09-30] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [455616 2016-09-30] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe [464440 2017-03-17] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-09-30] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2117128 2016-11-08] (Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2178576 2016-11-08] (Electronic Arts)
S3 ose; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [198192 2017-03-25] (Microsoft Corporation) [File not signed]
R2 STCServ; C:\Program Files\Intel\STCServ\STCServ.exe [8095456 2015-03-16] (Intel Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2016-04-19] (Microsoft Corporation)
S4 KMS-R@1n; C:\Windows\KMS-R@1n.exe
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2013-01-28] (ASUSTek Computer Inc.)
R3 AndroidAFD; C:\Windows\SysWow64\drivers\AndroidAFDx64.sys [28472 2015-07-06] (ASUSTek Computer Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-09-09] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2014-02-24] ()
R3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-07-20] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-07-20] (Disc Soft Ltd)
R3 dtproscsibus; C:\Windows\System32\DRIVERS\dtproscsibus.sys [30352 2016-06-18] (Disc Soft Ltd)
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [471496 2015-05-19] (Intel Corporation)
R0 FNETHYRAMAS; C:\Windows\System32\drivers\FNETHYRAMAS.SYS [45688 2016-06-18] (FNet Co., Ltd.)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [16648 2016-06-18] (FNet Co., Ltd.)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [31144 2015-06-22] (Intel Corporation)
S3 libusbK; C:\Windows\System32\DRIVERS\libusbK.sys [47200 2017-02-22] (hxxp://libusb-win32.sourceforge.net)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [178976 2015-07-07] (Intel Corporation)
R1 NFC_Driver; C:\Windows\System32\drivers\NFC_Driver.sys [48336 2015-06-11] (Titan ARC Corp.)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-09-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-09-02] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [59448 2017-03-17] (NVIDIA Corporation)
R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [12464 2016-09-25] (Macrovision Europe Ltd) [File not signed]
S3 dbx; system32\DRIVERS\dbx.sys
R4 IOMap; ??\C:\Windows\system32\drivers\IOMap64.sys
S3 VGPU; System32\drivers\rdvgkmd.sys
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-26 19:18 - 2017-04-26 19:18 - 00000000 ____D C:\Users\Winata\Downloads\FRST-OlderVersion
2017-04-25 20:02 - 2017-04-25 20:03 - 00093733 _____ C:\Users\Winata\Downloads\Addition.txt
2017-04-25 20:01 - 2017-04-26 19:18 - 00032797 _____ C:\Users\Winata\Downloads\FRST.txt
2017-04-25 20:01 - 2017-04-26 19:18 - 00000000 ____D C:\FRST
2017-04-25 18:34 - 2017-04-25 18:34 - 00002759 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2017-04-25 18:34 - 2017-04-25 18:34 - 00000000 ____D C:\ProgramData\Sophos
2017-04-25 18:34 - 2017-04-25 18:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2017-04-25 18:34 - 2017-04-25 18:34 - 00000000 ____D C:\Program Files (x86)\Sophos
2017-04-25 17:26 - 2017-04-26 19:18 - 02427392 _____ (Farbar) C:\Users\Winata\Downloads\FRST64.exe
2017-04-25 17:23 - 2017-04-25 17:50 - 165940904 _____ (Sophos Limited) C:\Users\Winata\Downloads\Sophos Virus Removal Tool.exe
2017-04-25 17:17 - 2017-04-25 17:17 - 04102600 _____ C:\Users\Winata\Downloads\adwcleaner_6.046.exe
2017-04-25 17:14 - 2017-04-25 17:19 - 00000000 ____D C:\AdwCleaner
2017-04-25 17:13 - 2017-04-25 17:13 - 00004021 _____ C:\Users\Winata\Desktop\JRT.txt
2017-04-25 17:11 - 2017-04-25 17:11 - 01663672 _____ (Malwarebytes) C:\Users\Winata\Downloads\JRT.exe
2017-04-25 17:10 - 2017-04-25 17:10 - 01530249 _____ (Smadsoft ) C:\Users\Winata\Downloads\smadav2017rev35.exe
2017-04-23 12:07 - 2017-04-23 12:07 - 00000000 ____D C:\Users\Winata\Documents\SkidRow
2017-04-23 11:25 - 2017-04-23 11:25 - 00000463 _____ C:\Users\Public\Desktop\The Sexy Brutale.lnk
2017-04-21 18:29 - 2017-04-21 18:29 - 00003466 _____ C:\Windows\System32\Tasks\One Drive Update
2017-04-21 13:15 - 2017-04-21 13:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-04-21 00:07 - 2017-04-21 00:07 - 00000000 ____D C:\Windows\pss
2017-04-20 12:55 - 2017-04-20 12:55 - 00000000 ____D C:\Users\Winata\AppData\Roaming\Google
2017-04-19 18:31 - 2017-04-19 18:31 - 00000000 ____D C:\Users\Public\Documents\Tools
2017-04-19 14:29 - 2017-04-21 18:29 - 00000000 ____D C:\Users\Winata\AppData\Local\wupdate
2017-04-19 14:29 - 2017-04-19 14:29 - 00003621 _____ C:\Users\Public\Desktop\R@1n.txt
2017-04-19 14:29 - 2017-04-19 14:29 - 00003438 _____ C:\Windows\System32\Tasks\wupdate
2017-04-19 14:29 - 2017-04-19 14:29 - 00000000 ____D C:\Windows\System32\Tasks\R@1n-KMS
2017-04-19 14:25 - 2017-04-19 14:25 - 02133044 _____ C:\Users\Winata\Downloads\re-loader-by-r1n.zip
2017-04-17 22:38 - 2017-04-17 22:38 - 00003000 _____ C:\Windows\System32\Tasks{D77F5F9C-2E81-4997-97FD-528C2E9A9F72}
2017-04-17 22:38 - 2017-04-17 22:38 - 00003000 _____ C:\Windows\System32\Tasks{71B68D39-21ED-480C-9223-222AD15D3EA1}
2017-04-17 22:14 - 2017-04-17 22:14 - 00048944 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2017-04-12 16:11 - 2017-04-12 16:18 - 00000000 ____D C:\Users\Winata\AppData\LocalLow\by redamz
2017-04-12 16:04 - 2017-04-12 16:04 - 00000000 ____D C:\Program Files (x86)\Monster Girl Island
2017-04-04 20:01 - 2017-04-04 20:01 - 00905969 _____ C:\Users\Winata\Downloads\PSX Download Helper1.8.zip
2017-04-04 20:01 - 2017-04-04 20:01 - 00000000 ____D C:\Users\Winata\AppData\Local\KOP-Elan
2017-04-04 20:01 - 2014-02-26 22:13 - 00000000 ____D C:\Users\Winata\Downloads\PSXDownloadHelper
2017-04-02 15:35 - 2017-04-02 15:35 - 00000000 ____D C:\Users\Winata\AppData\Roaming\Terrible Toybox
2017-04-02 15:30 - 2017-04-02 15:30 - 00000437 _____ C:\Users\Public\Desktop\Thimbleweed Park.lnk
2017-04-02 15:30 - 2017-04-02 15:30 - 00000437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thimbleweed Park.lnk
2017-03-28 11:56 - 2017-03-28 11:56 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-03-28 11:56 - 2017-03-17 05:56 - 00134592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2017-03-28 11:56 - 2017-01-26 07:13 - 00103936 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2017-03-28 11:56 - 2017-01-26 07:12 - 00326656 _____ C:\Windows\SysWOW64\vulkan-1.dll
2017-03-28 11:56 - 2017-01-26 07:09 - 00322560 _____ C:\Windows\system32\vulkan-1.dll
2017-03-28 11:56 - 2017-01-26 07:09 - 00118272 _____ C:\Windows\system32\vulkaninfo.exe
2017-03-28 11:54 - 2017-03-17 07:59 - 40190400 _____ C:\Windows\system32\nvcompiler.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 35272760 _____ C:\Windows\SysWOW64\nvcompiler.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 34952760 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 28223544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 19006832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 17282648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 14674712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 14434360 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2017-03-28 11:54 - 2017-03-17 07:59 - 13378096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 11122912 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 11019888 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 09306312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 08990256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 03627064 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 03187256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 01983424 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437892.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 01589696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437892.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 01053240 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00989120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00959424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00912440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00687408 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00609728 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00576192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00504104 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00500792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00425104 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00408272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00217528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2017-03-28 11:54 - 2017-03-17 07:59 - 00170360 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00153368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00059448 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2017-03-28 11:54 - 2017-03-17 07:59 - 00047664 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2017-03-28 11:54 - 2017-03-17 07:59 - 00000669 _____ C:\Windows\system32\nv-vk64.json
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-26 19:09 - 2009-07-14 11:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-26 19:09 - 2009-07-14 11:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-26 19:07 - 2016-06-19 19:17 - 00000000 ____D C:\Users\Winata\AppData\Roaming\Spotify
2017-04-26 19:03 - 2016-06-19 19:17 - 00000000 ____D C:\Users\Winata\AppData\Local\Spotify
2017-04-26 19:02 - 2016-06-18 18:25 - 00000000 ____D C:\ProgramData\NVIDIA
2017-04-26 19:01 - 2016-08-13 17:26 - 00000904 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2017-04-26 19:01 - 2009-07-14 12:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-26 00:49 - 2016-08-13 17:26 - 00000908 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2017-04-25 23:11 - 2016-08-07 12:23 - 00000000 ____D C:\Users\Winata\AppData\Roaming\DMCache
2017-04-25 20:01 - 2016-06-24 21:20 - 00000000 ____D C:\Users\Winata\AppData\Roaming\vlc
2017-04-25 17:19 - 2017-03-19 20:22 - 00000542 _____ C:\Users\Public\Desktop\Hitman.lnk
2017-04-25 17:19 - 2017-01-13 12:27 - 00000998 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2017-04-25 17:19 - 2017-01-13 12:27 - 00000986 _____ C:\Users\Public\Desktop\Opera.lnk
2017-04-25 17:19 - 2016-08-30 23:12 - 00001022 _____ C:\Users\Winata\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Intеrnеt Ехрlоrеr.lnk
2017-04-25 17:19 - 2016-08-14 09:58 - 00000731 _____ C:\Users\Winata\Desktop\Child of Light.lnk
2017-04-25 17:19 - 2016-08-10 22:31 - 00000716 _____ C:\Users\Winata\Desktop\Tomb Raider.lnk
2017-04-25 17:19 - 2016-06-26 20:13 - 00000669 _____ C:\Users\Winata\Desktop\South Park - The Stick of Truth.lnk
2017-04-25 17:19 - 2016-06-26 20:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\South Park - The Stick of Truth
2017-04-25 01:14 - 2016-10-24 13:55 - 00000336 _____ C:\Windows\Tasks\HPCeeScheduleForWinata.job
2017-04-24 21:50 - 2016-08-27 22:57 - 00000000 ____D C:\Users\Winata\AppData\Local\Share Link
2017-04-24 20:55 - 2016-06-20 17:00 - 00000000 ____D C:\Users\Winata\AppData\Roaming\uTorrent
2017-04-24 16:44 - 2017-01-13 12:24 - 00000000 ____D C:\Program Files (x86)\Opera
2017-04-24 12:56 - 2016-10-24 13:55 - 00003192 _____ C:\Windows\System32\Tasks\HPCeeScheduleForWinata
2017-04-23 17:20 - 2016-06-19 21:34 - 00000000 ____D C:\Program Files (x86)\SMADAV
2017-04-23 13:26 - 2016-06-19 21:43 - 00000000 ____D C:\Users\Winata\AppData\Local\CrashDumps
2017-04-23 11:28 - 2016-06-19 21:23 - 00000000 ____D C:\Windows\SysWOW64\directx
2017-04-21 21:28 - 2009-07-14 10:20 - 00000000 ____D C:\Windows\system32\NDF
2017-04-21 13:15 - 2016-08-13 17:26 - 00000000 ____D C:\Program Files (x86)\Dropbox
2017-04-21 00:21 - 2016-08-30 23:12 - 00002072 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk
2017-04-20 14:08 - 2016-06-19 21:34 - 00000000 __SHD C:[Smad-Cage]
2017-04-19 16:46 - 2017-02-22 18:15 - 00000398 __RSH C:\ProgramData\ntuser.pol
2017-04-19 14:26 - 2016-06-22 14:56 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-04-19 14:25 - 2009-07-14 10:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2017-04-17 23:17 - 2009-07-14 12:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-17 23:17 - 2009-07-14 10:20 - 00000000 ____D C:\Windows\inf
2017-04-14 12:31 - 2016-06-20 16:55 - 00000000 ____D C:\Users\Winata\Documents\Alan
2017-04-12 16:04 - 2016-06-18 17:34 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-04-11 22:23 - 2016-06-18 17:56 - 00003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineU A
2017-04-11 22:23 - 2016-06-18 17:56 - 00003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineC ore
2017-04-05 12:06 - 2016-06-22 14:57 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-04-04 14:21 - 2009-07-14 12:08 - 00032546 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-03-29 13:31 - 2016-08-29 19:05 - 00000000 ____D C:\Users\Winata\AppData\Local\ElevatedDiagnostics
2017-03-28 14:11 - 2016-06-18 18:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-03-28 11:56 - 2016-06-18 18:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-03-28 11:56 - 2016-06-18 17:41 - 00000000 ____D C:\Temp
2017-03-28 11:55 - 2016-06-18 18:01 - 00000000 ____D C:\Program Files\NVIDIA Corporation
==================== Files in the root of some directories =======
2016-08-29 19:07 - 2016-08-29 19:07 - 0000057 _____ () C:\ProgramData\Ament.ini
[HEADING=1]Some files in TEMP:[/HEADING]
2016-06-19 21:46 - 2016-06-19 21:46 - 0000000 ____D () C:\Users\Winata\AppData\Local\Temp\avgnt.exe
2017-04-19 14:30 - 2017-04-19 14:30 - 0862832 ____N () C:\Users\Winata\AppData\Local\Temp\AVwzODkyix1j.ex e
2017-04-19 14:25 - 2017-04-19 14:25 - 3039448 ____N () C:\Users\Winata\AppData\Local\Temp\GZsvYrjw8Oe8.ex e
2016-09-24 02:04 - 2016-09-24 02:04 - 0737856 _____ (Oracle Corporation) C:\Users\Winata\AppData\Local\Temp\jre-8u111-windows-au.exe
2016-06-18 18:25 - 2016-07-11 05:36 - 0735152 _____ (NVIDIA Corporation) C:\Users\Winata\AppData\Local\Temp\nvSCPAPI.dll
2016-08-13 15:49 - 2016-10-19 02:31 - 0860960 _____ (NVIDIA Corporation) C:\Users\Winata\AppData\Local\Temp\nvSCPAPI64.dll
2016-08-13 15:48 - 2016-10-19 02:31 - 0353336 _____ (NVIDIA Corporation) C:\Users\Winata\AppData\Local\Temp\nvStInst.exe
2017-04-19 14:33 - 2017-04-19 14:33 - 64938720 ____N (Kometa LCC) C:\Users\Winata\AppData\Local\Temp\xz3wl44BNr7m.ex e
2006-05-24 16:10 - 2006-05-24 16:10 - 0455600 ____R (Macrovision Corporation) C:\Users\Winata\AppData\Local\Temp_is493B.exe
2006-05-24 16:10 - 2006-05-24 16:10 - 0455600 ____R (Macrovision Corporation) C:\Users\Winata\AppData\Local\Temp_is76F2.exe
2006-05-24 16:10 - 2006-05-24 16:10 - 0455600 ____R (Macrovision Corporation) C:\Users\Winata\AppData\Local\Temp_is8025.exe
2016-09-17 14:34 - 2016-09-17 14:34 - 0000000 _____ () C:\Users\Winata\AppData\Local\Temp{874CFD58-76FC-49C8-8D8E-F66F3CC9FC2C}-DropboxClient_10.4.25.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-04-23 20:42
==================== End of FRST.txt ============================
[HEADING=1]Addition Log
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-04-2017
Ran by Winata (26-04-2017 19:19:25)
Running from C:\Users\Winata\Downloads
Windows 7 Ultimate Service Pack 1 (X64) (2016-06-18 11:15:36)
Boot Mode: Normal[/HEADING]
==================== Accounts: =============================
Administrator (S-1-5-21-4254750808-1728920065-3872038573-500 - Administrator - Disabled)
Guest (S-1-5-21-4254750808-1728920065-3872038573-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4254750808-1728920065-3872038573-1002 - Limited - Enabled)
Winata (S-1-5-21-4254750808-1728920065-3872038573-1000 - Administrator - Enabled) => C:\Users\Winata
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with “Hidden” flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\uTorrent) (Version: 3.5.0.43580 - BitTorrent Inc.)
7-Zip 16.02 (x64) (HKLM...\7-Zip) (Version: 16.02 - Igor Pavlov)
Adobe Reader XI (11.0.11) MUI (HKLM-x32...{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
AI Suite 3 (HKLM-x32...{CD36E28B-6023-469A-91E7-049A2874EC13}) (Version: 1.01.24 - ASUSTeK Computer Inc.)
Alien Isolation (HKLM-x32...\Alien Isolation_R.G. Mechanics_is1) (Version: - R.G. Mechanics, spider91)
Ansel (Version: 378.92 - NVIDIA Corporation) Hidden
Asmedia USB Host Controller Driver (HKLM-x32...{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.24.0 - Asmedia Technology)
Assassin’s Creed Syndicate (HKLM-x32...\Assassin’s Creed Syndicate_is1) (Version: v.1.31 - Decepticon)
Assetto Corsa MULTi5 - ElAmigos version 1.9.3 (HKLM-x32...{6BC1D532-0B05-4A2C-A497-73BC245926E2}_is1) (Version: 1.9.3 - Kunos Simulazioni)
Assetto Corsa v1.8 Incl. Tripl3 Pack DLC (HKLM...\YXNzZXR0b2NvcnNh_is1) (Version: 1 - )
ASUS Product Register Program (HKLM-x32...{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.030 - ASUSTek Computer Inc.)
ASUS Share Link (HKLM-x32...{c3bcc1e3-f950-439c-bcae-f01283e9f2a4}_is1) (Version: 1.0.27.0911 - ASUSTEK)
Asus Sonic Suite Plugins (x32 Version: 2.1.2501 - ASUSTeKcomputer.Inc) Hidden
ASUSRAMCACHE (HKLM-x32...\ASUSRAMCACHE) (Version: 1.07.16 - FNet Co., Ltd.)
Batman Arkham Knight v.1.0.4.5 (HKLM-x32...\Batman Arkham Knight_is1) (Version: - )
Battlefield™ 1 (HKLM-x32...{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.9.53998 - Electronic Arts)
Bing Bar (HKLM-x32...{3611CA6C-5FCA-4900-A329-6A118123CCFC}) (Version: 7.1.355.0 - Microsoft Corporation)
Black Ops II (HKLM-x32...\Black Ops II 2.0) (Version: 2.0 - ShinyMK)
Black Ops II (x32 Version: 2.0 - ShinyMK) Hidden
Bloodstained: Ritual of the Night (HKLM...\Steam App 477970) (Version: - )
Cheat Engine 6.6 (HKLM-x32...\Cheat Engine 6.6_is1) (Version: - Cheat Engine)
Child of Light (HKLM-x32...\Child of Light_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter)
CPUID PRO GAMING CPU-Z 1.72.1 (HKLM...\CPUID PRO GAMING CPU-Z_is1) (Version: 1.72.1 - CPUID, Inc.)
DAEMON Tools Lite (HKLM...\DAEMON Tools Lite) (Version: 10.4.0.0192 - Disc Soft Ltd)
DAEMON Tools Pro (HKLM...\DAEMON Tools Pro) (Version: 6.1.0.0486 - Disc Soft Ltd)
Deus Ex: Mankind Divided (HKLM-x32...\Deus Ex: Mankind Divided_is1) (Version: - )
Discord (HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Discord) (Version: 0.0.297 - Hammer & Chisel, Inc.)
Divinity: Original Sin 2 (HKLM...\Steam App 435150) (Version: - Larian Studios)
Divinity: Original Sin Enhanced Edition (HKLM...\Steam App 373420) (Version: - Larian Studios)
DOOM (HKLM-x32...\DOOM_is1) (Version: - )
Dota 2 (HKLM...\Steam App 570) (Version: - Valve)
Dropbox (HKLM-x32...\Dropbox) (Version: 24.4.16 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden
EVE Online (HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...{75078ee2-d1fc-4537-9760-d87760c1809f}) (Version: 1.0.0 - CCP)
Evolve Stage 2 (HKLM...\Steam App 273350) (Version: - Turtle Rock Studios)
Far Cry 4 (HKLM-x32...\Far Cry 4_is1) (Version: - )
Fraps (HKLM-x32...\Fraps) (Version: - )
Google Chrome (HKLM-x32...\Google Chrome) (Version: 58.0.3029.81 - Google Inc.)
Google Update Helper (x32 Version: 1.3.33.3 - Google Inc.) Hidden
Hitman (HKLM-x32...\Hitman_is1) (Version: - )
Hitman Absolution - Professional Edition (HKLM-x32...\Hitman Absolution - Professional Edition_is1) (Version: - )
HP Deskjet 1050 J410 series Basic Device Software (HKLM...{F294770E-F869-400F-81C3-614B5F13CA54}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Deskjet 1050 J410 series Help (HKLM-x32...{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard)
HP Deskjet 1050 J410 series Product Improvement Study (HKLM...{D638A23C-5C5F-4B71-A354-EC78B2BDD320}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Support Assistant (HKLM-x32...{78E2C850-ADA6-420D-BA35-2F4A9BE733CC}) (Version: 8.4.14.41 - HP)
HP Support Solutions Framework (HKLM-x32...{CE7447C2-EF12-4EF3-BE51-BFC3B049C0F6}) (Version: 12.6.14.19 - HP)
HP Update (HKLM-x32...{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
I am Setsuna (HKLM-x32...\I am Setsuna_is1) (Version: - )
ILLUSION SchoolMate (HKLM-x32...{52ABC760-CAFC-4FCD-A0AA-5661366199D5}) (Version: 1.00.0000 - ILLUSION)
ILLUSION プレイクラブ (HKLM-x32...{EDA7A566-434A-4784-AE98-74AFA46A2485}) (Version: 1.00.0000 - ILLUSION)
INSIDE (HKLM-x32...\INSIDE_is1) (Version: - )
Intel(R) Chipset Device Software (x32 Version: 10.1.1.7 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM...{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1158 - Intel Corporation)
Intel(R) Network Connections 20.2.3001.0 (HKLM...\PROSetDX) (Version: 20.2.3001.0 - Intel)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32...{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.0.36 - Intel Corporation)
Intel® CCF Manager (HKLM-x32...{0f3d8dd5-54af-4404-a01c-4967e485a065}) (Version: 3.0.13.2211 - Intel Corporation)
Internet Download Manager (HKLM-x32...\Internet Download Manager) (Version: - Tonec Inc.)
Java 8 Update 111 (64-bit) (HKLM...{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation)
Java 8 Update 111 (HKLM-x32...{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation)
Mafia III - Digital Deluxe Edition - Version 1.0 (HKLM-x32...\Mafia III - Digital Deluxe Edition_is1) (Version: 1.0 - RePack by VickNet)
Media Streamer (HKLM-x32...{B457E718-00CA-45C8-9F75-45D66F8DAFF6}) (Version: 3.00.15 - ASUSTeK Computer Inc.)
Metro Last Light Redux (HKLM-x32...\Metro Last Light Redux_is1) (Version: v1.2 - Deep Silver)
MGI - Monster Girl Island Demo 1 (HKLM-x32...{CD8A4EC7-3923-4AC8-8CDC-C0DD77132379}) (Version: 1 - Monster Girl Island)
Microsoft .NET Framework 4.6.1 (HKLM...{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - en-us (HKLM...\ProplusRetail - en-us) (Version: 16.0.7870.2038 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\OneDriveSetup.exe) (Version: 17.3.6281.1202 - Microsoft Corporation)
Microsoft Project Professional 2016 - en-us (HKLM...\ProjectProRetail - en-us) (Version: 16.0.7870.2038 - Microsoft Corporation)
Microsoft Visio Professional 2016 - en-us (HKLM...\VisioProRetail - en-us) (Version: 16.0.7870.2038 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM...{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM...{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32...{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM...{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32...{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32...{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32...{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32...{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32...{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32...{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32...{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32...{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32...{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM...{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Middle-earth - Shadow of Mordor (HKLM-x32...\Middle-earth - Shadow of Mordor_is1) (Version: v1.2 - WB Games)
MOBIUS FINAL FANTASY (HKLM...\Steam App 536930) (Version: - SQUARE ENIX CO., LTD.)
NahimicSettingsConfigurator (Version: 2.1.2501 - ASUSTeKcomputer.Inc) Hidden
NVIDIA 3D Vision Controller Driver 369.04 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 378.92 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 378.92 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.0.7.34 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.0.7.34 - NVIDIA Corporation)
NVIDIA Graphics Driver 378.92 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.92 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.23 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.23 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
NvNodejs (Version: 3.0.7.34 - NVIDIA Corporation) Hidden
NvTelemetry (Version: 1.0.0.0 - NVIDIA Corporation) Hidden
NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
O2Jam INT (HKLM-x32...{92E268B8-4E5D-4E9D-B82B-C39B65B5DB44}) (Version: 2.0.0 - IntGamerz)
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7870.2024 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7830.1018 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7870.2024 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7668.2066 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32...\OpenAL) (Version: - )
Opera Stable 43.0.2442.1144 (HKLM-x32...\Opera 43.0.2442.1144) (Version: 43.0.2442.1144 - Opera Software)
Origin (HKLM-x32...\Origin) (Version: 10.2.2.60207 - Electronic Arts, Inc.)
osu! (HKLM-x32...{22cccaf8-5e6d-4f85-bdaa-f3606c6532c3}) (Version: latest - ppy Pty Ltd)
RapeLay (HKLM-x32...{CA31F991-DBD2-4DE1-B6D2-30105F23CBBC}) (Version: 1.03 - ILLUSION)
Realtek High Definition Audio Driver (HKLM-x32...{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7543 - Realtek Semiconductor Corp.)
Resident Evil 7: Biohazard (HKLM-x32...\Resident Evil 7: Biohazard_is1) (Version: - )
ROG Game First III (HKLM-x32...{0C6E32E1-31D9-49F1-B67F-2941994002D5}) (Version: 1.00.31 - ASUSTeK Computer Inc.)
ScpToolkit (HKLM...{AC052048-9828-45E3-872B-04CE30A3B58B}) (Version: 1.6.238.16010 - Nefarius Software Solutions)
Sexy Beach Premium Resort (HKLM-x32...\Sexy Beach Premium Resort_is1) (Version: - )
Shadow Warrior - Special Edition (HKLM-x32...\Shadow Warrior - Special Edition_is1) (Version: - )
SHIELD Streaming (Version: 7.1.0320 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 3.0.7.34 - NVIDIA Corporation) Hidden
Sid Meier’s Civilization 6 (HKLM-x32...\Sid Meier’s Civilization 6_is1) (Version: - )
SMADAV version 10.7.1 (HKLM-x32...{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1) (Version: 10.7.1 - SmadSoft)
Sonic Radar II (HKLM...{A70B8D38-273A-4D6A-B7D5-AEBEDEEE5D28}) (Version: 2.1.2501 - ASUSTeKcomputer.Inc)
Sonic Studio Plugin (Version: 2.1.2501 - ASUSTeKcomputer.Inc) Hidden
Sonicomi (HKLM-x32...\Sonicomi1.0) (Version: 1.0 - JAST USA)
Sophos Virus Removal Tool (HKLM-x32...{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.6 - Sophos Limited)
South Park - The Stick of Truth version 1.0 build 1383 + 2 DLC (HKLM-x32...\South Park - The Stick of Truth_is1) (Version: 1.0 build 1383 + 2 DLC - )
Spotify (HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Spotify) (Version: 1.0.53.758.gde3fc4b2 - Spotify AB)
STCServ (Version: 3.0.0.1783 - Intel Corporation) Hidden
Steam (HKLM-x32...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Tales of Berseria (HKLM-x32...\Tales of Berseria_is1) (Version: - )
The Legend of Heroes Trails in the Sky (HKLM-x32...{2BB748CC-69E7-41F7-8609-CBB1EE5DD0C0}_is1) (Version: - Xseed)
The Legend of Zelda: Breath of the Wild (HKLM-x32...\The Legend of Zelda: Breath of the Wild_is1) (Version: - )
The Sexy Brutale (HKLM-x32...\The Sexy Brutale_is1) (Version: - )
Thimbleweed Park (HKLM...\dGhpbWJsZXdlZWRwYXJr_is1) (Version: 1 - )
Tom Clancy’s Rainbow Six Siege (HKLM...\Steam App 359550) (Version: - Ubisoft Montreal)
Tomb Raider (HKLM-x32...\Tomb Raider_R.G. Mechanics_is1) (Version: - R.G. Mechanics, spider91)
Tyranny - Pre-Order (HKLM-x32...\1128126797_is1) (Version: 2.0.0.1 - GOG.com)
Tyranny (HKLM-x32...\1266051739_is1) (Version: 2.0.0.1 - GOG.com)
Uplay (HKLM-x32...\Uplay) (Version: 22.2 - Ubisoft)
VA-11 Hall-A - Cyberpunk Bartender Action (HKLM-x32...\2074961301_is1) (Version: 2.0.0.2 - GOG.com)
Virginia (HKLM-x32...\Virginia_is1) (Version: - )
VLC media player (HKLM-x32...\VLC media player) (Version: 2.2.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.39.1 (HKLM...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.)
WebStorage (HKLM-x32...\WebStorage) (Version: 2.1.15.458 - ASUS Cloud Corporation)
Windows XP Mode (HKLM...{1374CC63-B520-4f3f-98E8-E9020BF01CFF}) (Version: 1.3.7600.16423 - Microsoft Corporation)
WinZip 19.5 (HKLM...{CD95F661-A5C4-44F5-A6AA-ECDD91C240EB}) (Version: 19.5.11475 - WinZip Computing, S.L. )
Wolfenstein - The New Order (HKLM-x32...\Wolfenstein - The New Order_R.G. Mechanics_is1) (Version: - R.G. Mechanics, spider91)
Zero Escape: Zero Time Dilemma (HKLM-x32...\Zero Escape: Zero Time Dilemma_is1) (Version: - )
輪姦倶楽部DL版 (HKLM-x32...{6F26BCA6-5244-40AE-B0C2-2EA2C664B4FA}) (Version: 1.00.0000 - Infini Brain Inc.)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-4254750808-1728920065-3872038573-1000_Classes\CLSID{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 → C:\Users\Winata\AppData\Local\Microsoft\OneDrive\1 7.3.6281.1202\amd64\FileCoAuthLib64.dll ()
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {05DDC327-81A9-4BE3-931A-E0F2767D5B51} - System32\Tasks{4FCA9E6C-23C8-46DB-9FBE-4F0E11FC0A1B} => D:\SIM\sim.exe [2016-11-22] (Monsoonlab)
Task: {093A1C6D-DAE8-487A-B994-A946F21F861E} - System32\Tasks\R@1n-KMS\Office16ProPlus => wmic
Task: {1F347E34-0C9E-416A-ACA7-7965D62D4A09} - System32\Tasks{DD1347B8-D84A-494B-B6D7-DC0E4AEA9358} => K:\HYOUIUST.EXE
Task: {1F5DCAC2-7069-4397-AA16-258AB07BC4CA} - System32\Tasks\ASUS\GpuFanHelper => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\GpuFanHelper.exe [2015-07-02] (TODO: )
Task: {2455A076-A05C-45FA-B2BA-ED953E4806AF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-04-01] (HP Inc.)
Task: {24C60722-922B-4C06-BC6C-90650A296594} - System32\Tasks{99949CCE-432A-4C0C-A1D5-77A51E27AAAD} => pcalua.exe -a H:\Hyouiust.exe -d H:
Task: {2571A339-A90B-43EB-8AAC-79EC86939D5C} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-08-13] (Dropbox, Inc.)
Task: {276C638D-7737-4AA9-A376-AD02AAEDDB97} - System32\Tasks\smadav => C:\Program Files (x86)\Smadav\SMΔRTP.exe [2016-06-02] (Smadsoft)
Task: {28F6A0D8-BFD4-4AB2-8C27-BF9E3E08E082} - System32\Tasks{6DBD2FA0-EFA5-4385-A2AC-C30528B27544} => L:\setup.exe
Task: {317D0388-1DED-496A-9309-9B07BF18B338} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {38EB0B64-B6D9-4DC6-BACC-4AA567590F38} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2016-09-30] (NVIDIA Corporation)
Task: {393AF510-D7D2-40D0-B7D9-3B6DFFAB0D97} - System32\Tasks\ASUS\ASUS DIPAwayMode => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe [2015-07-06] ()
Task: {42B52220-F385-4B31-A514-431965FE194F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {45D7B53D-2436-4E91-AEB3-F1E1F5747BAA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-18] (Google Inc.)
Task: {518636E2-14B9-49AE-9DA2-5CBF85F02F0A} - System32\Tasks\HPCeeScheduleForWinata => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2016-01-22] (Hewlett-Packard)
Task: {520DBF5B-4EBA-48DC-AE18-27FD80AEB4F3} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-04-09] (Microsoft Corporation)
Task: {5470E47F-97E1-4873-A3BF-50285C07001F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {59E886DC-97AC-4633-814D-998CDB7ED1CC} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2016-09-30] (NVIDIA Corporation)
Task: {641FC6A1-60CC-4027-82B1-55D00FF7E814} - System32\Tasks\Microsoft\Office\OfficeTelemetryAge ntLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-04-10] (Microsoft Corporation)
Task: {67AAB573-2B01-478A-BCF1-8D15E4DE61CE} - System32\Tasks\ASUS\Push Notice Server Execute => C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe [2014-05-28] (ASUSTeK Computer Inc.)
Task: {6C46E986-D9B3-4728-9E1D-39C22F77CB0B} - System32\Tasks\ASUS\ASUS AISuiteIII => C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe [2015-06-30] (ASUSTeK Computer Inc.)
Task: {6D665217-1F06-440C-AB76-50507CD8BB8A} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-08-13] (Dropbox, Inc.)
Task: {7153E778-5276-4B9C-B8CB-E5713D9A00DC} - System32\Tasks\IntelBootstrapCCDashExe => C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe [2015-03-16] (Intel® Corporation)
Task: {7855431E-BECD-4E6D-9E27-240BD653A9E8} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-09-30] (NVIDIA Corporation)
Task: {7E8A906A-5F66-4730-B37F-43320FB11CA5} - System32\Tasks\Opera scheduled Autoupdate 1484285237 => C:\Program Files (x86)\Opera\launcher.exe [2017-02-27] (Opera Software)
Task: {8245F84A-BE60-4B87-9212-5A22A9A8493C} - System32\Tasks{8AC69228-D3FF-40EF-AD61-1179B67D4DB7} => K:\HYOUIUST.EXE
Task: {87CC43B6-B6D5-419A-BC59-B0E7F298DDCC} - System32\Tasks{D77F5F9C-2E81-4997-97FD-528C2E9A9F72} => C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE [2017-04-10] (Microsoft Corporation)
Task: {8D611B13-AB6F-46E6-8469-A0CC74428169} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChec ker.exe [2017-04-06] (HP Inc.)
Task: {8E124BDC-E1E7-4761-8B65-41A40AC9D514} - System32\Tasks\ASUS\USB 3.0 Boost Service => C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvr.exe [2013-07-24] (ASUSTeK Computer Inc.)
Task: {8EAF54AB-B69E-4A0E-AA50-3FC4F6605FA3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-12-21] (HP Inc.)
Task: {9380F438-06D6-43F2-9117-6BEC9529AF21} - System32\Tasks\R@1n-KMS\Office16VisioPro => wmic
Task: {966CE29C-528E-4976-BC9F-DF53924A04B0} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.ex e [2016-11-07] (HP Inc.)
Task: {A3FD864C-C9D6-4D1C-9311-4DDAD17A2BEB} - System32\Tasks\HPCustParticipation HP Deskjet 1050 J410 series => C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.)
Task: {A91067F3-CC2F-40F1-A14B-36439F5C77E3} - System32\Tasks\updater => C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpUpdater.exe [2016-01-10] (Nefarius Software Solutions)
Task: {AE82A179-1311-4557-AEE4-7F9D3CE31FDC} - System32\Tasks\ASUS\ASUS Media Streamer DMR => C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMR\AODMR.exe [2015-05-12] ()
Task: {B10B1B49-E8AE-43D6-B97E-DDD9605E0F56} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-04-09] (Microsoft Corporation)
Task: {BA7B47AF-E62A-45CA-8BD9-F377C4AF218B} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-09-30] (NVIDIA Corporation)
Task: {BAD25838-E5A6-4019-B957-846CCAEA5CA0} - System32\Tasks{5452A836-2F26-4CEC-B408-D0952495B6D4} => D:\SIM\sim.exe [2016-11-22] (Monsoonlab)
Task: {BB19AA40-0272-4A12-BCAF-4E65BE937308} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-09-30] (NVIDIA Corporation)
Task: {C5C4482C-41CA-4FAC-863B-0A2B00422797} - System32\Tasks{C71C2131-5E26-4E6D-A4F6-68D5A864493B} => K:\HYOUIUST.EXE
Task: {C884A167-1EED-459C-A4C2-493E08CC11B6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-18] (Google Inc.)
Task: {D38422FB-DE43-4F9D-B5D0-6C2E62DB65A2} - System32\Tasks{71B68D39-21ED-480C-9223-222AD15D3EA1} => C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE [2017-04-10] (Microsoft Corporation)
Task: {D72F2C08-C3E6-4037-A052-FDFFC26ABFD5} - System32\Tasks\R@1n-KMS\Office16ProjectPro => wmic
Task: {DBC96CC5-2FF1-4198-9746-62522314EFD4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAge ntFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-04-10] (Microsoft Corporation)
Task: {E1779794-65F9-48AD-9F95-FE029D59B440} - System32\Tasks\ASUS\Ez Update => C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe [2015-02-06] ()
Task: {E26CFFC1-DDD0-4DA5-BA70-F3A5955FF745} - System32\Tasks{FA9E6D33-6C43-43EC-800C-8CFD0CAF059D} => pcalua.exe -a L:\SETUP.EXE -d L:
Task: {E3585554-FA28-4991-878F-7BC6FD6CF4E6} - System32\Tasks\One Drive Update => C:\Windows\explorer.exe hxxp://dluxuwu.ru
Task: {F246CD7C-3260-4BAA-AE15-F685C9140D8A} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-09-30] (NVIDIA Corporation)
Task: {F6DA0069-975F-4FF1-A28C-6D60E3E5C038} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2015-05-14] ()
Task: {F94CED33-5F83-43DA-BF77-EC01C6CE778B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {FE6DD934-5232-42E3-9504-35525265A645} - System32\Tasks\wupdate => C:\Users\Winata\AppData\Local\wupdate\wupdate.exe [2017-04-21] () <==== ATTENTION
Task: {FFA1BB75-9E9A-4D9E-9697-3E573D9AEA91} - System32\Tasks{A0A94C32-F9FE-4DE8-B055-BD5BD390146B} => K:\HYOUIUST.EXE
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForWinata.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\Winata\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk → C:\Windows\explorer.exe (Microsoft Corporation) <===== Cyrillic
Shortcut: C:\Users\Winata\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Intеrnеt Ехрlоrеr.lnk → C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) <===== Cyrillic
Shortcut: C:\Users\Winata\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Accessories\System Tools\Intеrnеt Ехрlоrеr (Nо Аdd-оns).lnk → C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) <===== Cyrillic
Shortcut: C:\Users\Winata\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gооglе Сhrоmе.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) <===== Cyrillic
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) <===== Cyrillic
==================== Loaded Modules (Whitelisted) ==============
2014-07-23 08:59 - 2014-07-23 08:59 - 00936728 ____R () C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
2016-06-18 18:31 - 2015-07-06 15:42 - 01275672 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
2016-06-18 18:41 - 2015-05-12 21:49 - 00304952 _____ () C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMR\AODMR.exe
2016-06-18 18:30 - 2015-02-06 14:53 - 01462584 _____ () C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe
2016-06-18 17:34 - 2014-07-23 08:59 - 01360016 ____R () C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlServi ce.exe
2016-06-18 18:31 - 2015-05-14 09:18 - 01075712 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNoticeMonitor.exe
2016-06-18 18:31 - 2014-08-28 10:37 - 00033424 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotify_PCCtrl.exe
2014-11-01 17:10 - 2013-09-15 23:00 - 00258062 _____ () E:\New DNSCript\dnscrypt-proxy.exe
2016-06-18 17:35 - 2014-05-22 15:24 - 00096568 _____ () C:\Windows\system32\audioLibVc.dll
2016-09-15 22:33 - 2016-09-30 11:24 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2016-09-15 22:33 - 2016-09-30 11:24 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll
2016-09-15 22:34 - 2016-09-30 11:24 - 00418240 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem_nvspse rviceplugin64.dll
2016-06-18 18:24 - 2017-03-17 06:16 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2012-03-08 09:27 - 2012-03-08 09:27 - 00016384 _____ () C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\ACVsWin.dll
2016-06-18 18:41 - 2015-07-07 17:07 - 01194808 _____ () C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\ShareEdit.exe
2016-06-18 18:41 - 2015-07-07 17:07 - 02569528 _____ () C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AODMS.exe
2016-06-18 18:41 - 2015-06-03 19:46 - 00086840 _____ () C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\ASUSWSAgent.exe
2016-06-18 18:29 - 2015-06-30 14:54 - 01263384 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\AsPowerBar.exe
2017-04-20 12:46 - 2017-04-19 12:03 - 03767640 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\libgl esv2.dll
2017-04-20 12:46 - 2017-04-19 12:03 - 00100696 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\libeg l.dll
2016-06-18 17:34 - 2017-04-26 19:01 - 00036136 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\PEbiosinterface32.dll
2016-06-18 17:34 - 2014-07-23 08:59 - 00104448 ____R () C:\Program Files (x86)\ASUS\AXSP\1.02.00\ATKEX.dll
2016-06-18 18:31 - 2015-07-02 10:40 - 00236544 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4cTDPAction.dll
2016-06-18 18:31 - 2015-07-02 10:40 - 00712192 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAc tion.dll
2016-06-18 18:31 - 2015-07-06 15:42 - 00863744 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4EpuAction.dll
2016-06-18 18:31 - 2015-07-02 10:40 - 00803840 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4FanAction.dll
2016-06-18 18:31 - 2015-07-06 15:42 - 00815104 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4TurboVEVOAction.dl l
2016-06-18 18:31 - 2015-07-02 10:40 - 00507392 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\AsKeyboardFocusHooker.dll
2016-06-18 18:29 - 2015-06-03 16:17 - 00091648 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Log4cxxWrapper.dll
2016-06-18 18:29 - 2015-06-03 16:17 - 00147456 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AssistFunc.dll
2016-06-18 18:30 - 2015-02-09 17:53 - 00872960 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AI Charger+\AIChargerPlus.dll
2016-06-18 18:31 - 2015-07-06 15:58 - 04697088 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\dip4.dll
2016-06-18 18:31 - 2015-07-02 10:40 - 00091648 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\Log4cxxWrapper.dll
2016-06-18 18:30 - 2015-05-21 22:57 - 01141248 _____ () C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EasyUpdt.dll
2016-06-18 18:30 - 2015-06-26 13:50 - 00906240 _____ () C:\Program Files (x86)\ASUS\AI Suite III\LED Control\LEDControl.dll
2016-06-18 18:31 - 2015-07-13 11:16 - 01341440 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Mobo Connect\MoboConnect.dll
2016-06-18 18:29 - 2015-06-28 16:37 - 00829440 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Version\Version.dll
2016-06-18 18:31 - 2015-07-02 09:40 - 00053248 ____R () C:\Program Files (x86)\ASUS\VGA COM\1.00.20\Exeio.dll
2016-06-18 18:31 - 2015-07-02 09:40 - 00278528 ____R () C:\Program Files (x86)\ASUS\VGA COM\1.00.20\Vender.dll
2016-06-18 18:29 - 2015-05-08 13:26 - 00662016 ____R () C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMLib.dll
2016-06-18 18:30 - 2014-10-09 09:31 - 00237568 _____ () C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzULIB.dll
2016-06-18 18:30 - 2014-02-24 17:49 - 00208896 _____ () C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\ImageHelper.dll
2016-09-15 22:33 - 2016-09-30 00:20 - 00500792 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node
2016-09-15 22:33 - 2016-09-30 00:20 - 00255936 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node
2016-09-15 22:33 - 2016-09-30 00:20 - 02801208 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node
2016-09-15 22:33 - 2016-09-30 00:20 - 00244672 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node
2016-09-15 22:33 - 2016-09-30 00:20 - 00430648 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node
2016-09-15 22:33 - 2016-09-30 00:20 - 00336832 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node
2016-09-15 22:33 - 2016-09-30 00:20 - 00373696 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvCameraAPINode.node
2016-06-18 18:31 - 2013-11-20 10:10 - 00662016 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\aaHMLib.dll
2016-06-18 18:31 - 2013-07-02 10:40 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\pngio.dll
2014-11-01 17:10 - 2013-09-15 23:03 - 00540302 _____ () E:\New DNSCript\libsodium-4.dll
2016-06-19 19:17 - 2017-04-20 19:02 - 67725936 _____ () C:\Users\Winata\AppData\Roaming\Spotify\libcef.dll
2017-01-12 12:30 - 2017-01-04 14:28 - 01958912 _____ () C:\Users\Winata\AppData\Local\Discord\app-0.0.297\ffmpeg.dll
2017-01-12 12:30 - 2017-01-12 12:30 - 01082880 _____ () \?\C:\Users\Winata\AppData\Roaming\discord\0.0.297 \modules\discord_voice\discord_voice.node
2017-01-12 12:30 - 2017-01-12 12:30 - 03750400 _____ () \?\C:\Users\Winata\AppData\Roaming\discord\0.0.297 \modules\discord_voice\libdiscord.dll
2017-01-12 12:30 - 2017-01-12 12:30 - 00914432 _____ () \?\C:\Users\Winata\AppData\Roaming\discord\0.0.297 \modules\discord_utils\discord_utils.node
2017-01-12 12:30 - 2017-01-04 14:28 - 02278912 _____ () C:\Users\Winata\AppData\Local\Discord\app-0.0.297\libglesv2.dll
2017-01-12 12:30 - 2017-01-04 14:28 - 00096768 _____ () C:\Users\Winata\AppData\Local\Discord\app-0.0.297\libegl.dll
2016-06-18 18:41 - 2015-05-12 21:49 - 00253952 _____ () C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\pngio.dll
2017-04-21 13:14 - 2017-04-17 22:09 - 00870720 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2016-08-13 17:29 - 2017-03-29 06:54 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client_multiprocessing.pyd
2016-08-13 17:29 - 2017-03-29 06:54 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client_ctypes.pyd
2016-08-13 17:29 - 2017-03-29 06:54 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2016-08-13 17:29 - 2017-04-17 22:13 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00020824 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings. _constant_time.pyd
2016-08-13 17:29 - 2017-03-29 06:54 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client_cffi_backend.pyd
2016-08-13 17:29 - 2017-03-29 06:54 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 01729360 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings. _openssl.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings. _padding.pyd
2017-04-21 13:14 - 2017-03-29 06:54 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2017-04-21 13:14 - 2017-03-29 06:54 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2017-04-21 13:14 - 2017-03-29 06:54 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2016-08-13 17:29 - 2017-03-29 06:56 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2016-08-13 17:29 - 2017-04-17 22:13 - 00022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_c rt.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00060736 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00038712 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2017-04-21 13:14 - 2017-03-29 06:54 - 00392656 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2017-04-21 13:14 - 2017-03-29 06:56 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2016-08-13 17:29 - 2017-04-17 22:13 - 00392512 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2016-08-13 17:29 - 2017-04-17 22:14 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._win ffi_kernel32.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00246608 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handl er.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00027488 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled ._driverinstallation.pyd
2016-08-13 17:29 - 2017-03-29 06:55 - 00241104 _____ () C:\Program Files (x86)\Dropbox\Client_jpegtran.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00022336 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2016-08-13 17:29 - 2017-04-17 22:14 - 00025432 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._Captu reScreenshot.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 01826104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2016-08-13 17:29 - 2017-03-29 06:54 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 01972024 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 03928896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00171336 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00042816 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00531264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00133432 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00224064 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00207680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2017-02-28 11:52 - 2017-04-17 22:14 - 00054608 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCSer ver.pyd
2017-01-24 13:52 - 2017-04-17 22:14 - 00022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winff i_user32.pyd
2017-01-24 13:52 - 2017-04-17 22:13 - 00022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._win ffi_iphlpapi.pyd
2017-01-24 13:52 - 2017-04-17 22:14 - 00021848 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._win ffi_winerror.pyd
2017-01-24 13:52 - 2017-04-17 22:14 - 00022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winf fi_wininet.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00349128 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2016-08-13 17:29 - 2017-04-17 22:14 - 00023896 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._ VerifySignature.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00025936 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyn cffi.pyd
2017-04-21 13:14 - 2017-03-29 06:52 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2017-04-21 13:14 - 2017-04-17 22:13 - 00084288 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2016-08-13 17:29 - 2017-04-17 22:13 - 00030536 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.p yd
2017-04-21 13:14 - 2017-03-29 07:00 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
2017-04-21 13:14 - 2017-03-29 07:00 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2017-04-21 13:14 - 2017-04-17 22:13 - 00357688 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2016-08-13 17:29 - 2017-04-17 22:14 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winf fi_winhttp.pyd
2016-06-19 19:17 - 2017-04-20 19:02 - 01929840 _____ () C:\Users\Winata\AppData\Roaming\Spotify\libglesv2. dll
2016-06-19 19:17 - 2017-04-20 19:02 - 00087152 _____ () C:\Users\Winata\AppData\Roaming\Spotify\libegl.dll
2016-09-15 22:33 - 2016-09-30 11:24 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2017-04-26 19:04 - 2017-04-26 19:04 - 00148992 _____ () \?\C:\Users\Winata\AppData\Local\Temp\AC45.tmp.nod e
2017-01-12 12:30 - 2017-01-12 12:30 - 02658304 _____ () \?\C:\Users\Winata\AppData\Roaming\discord\0.0.297 \modules\discord_rpc\discord_rpc.node
2017-01-12 12:30 - 2017-03-23 13:31 - 02665976 _____ () \?\C:\Users\Winata\AppData\Roaming\discord\0.0.297 \modules\discord_contact_import\discord_contact_im port.node
2015-07-10 23:37 - 2015-07-10 23:37 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-06-18 18:31 - 2015-07-02 10:40 - 00743424 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\EPU.dll
2016-06-18 18:31 - 2015-07-02 10:40 - 00383488 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\SystemCleaner.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The “AlternateShell” will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 09:34 - 2009-06-11 04:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000\Control Panel\Desktop\Wallpaper → C:\Users\Winata\AppData\Roaming\Microsoft\Windows\ Themes\TranscodedWallpaper.jpg
DNS Servers: 127.0.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Pol icies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{FBBDD327-3B22-4E37-B321-31E937A8EAD6}] => (Allow) C:\Windows\system32\ftp.exe
FirewallRules: [{184B5062-16C4-47AD-AF28-6AAAE3B82E1F}] => (Allow) C:\Windows\system32\ftp.exe
FirewallRules: [{2E4DB191-621F-4373-8E03-8B225559D938}] => (Allow) C:\Windows\SysWOW64\ftp.exe
FirewallRules: [{725403B0-249E-4BF0-9043-FFB95AB2FC62}] => (Allow) C:\Windows\SysWOW64\ftp.exe
FirewallRules: [{7EC90042-2CE7-4EE1-BB42-9DDCFB497573}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMR\AODMR.exe
FirewallRules: [{815493E6-A394-41D4-8E73-EF8F60D4AB48}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMR\AODMR.exe
FirewallRules: [{9DBA0C8D-7627-46C1-BF0F-E9B6FED5C448}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AODMS.exe
FirewallRules: [{8818F50F-D22E-47E0-B283-D0BECE716ED2}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AODMS.exe
FirewallRules: [{5597EACB-000D-4045-A601-2B4D7A303C7B}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AORelayDMS.exe
FirewallRules: [{5904A52E-DC3C-42D3-B994-379341FFD920}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AORelayDMS.exe
FirewallRules: [{33A808EB-C044-4B4D-B055-00416B6646FC}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\AMSRelayHelpAgent.exe
FirewallRules: [{83BCA34A-E763-4068-BBC6-B9562C041B03}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\AMSRelayHelpAgent.exe
FirewallRules: [{473A45CF-396F-4997-83C7-43024A784834}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\MediaStreamer.exe
FirewallRules: [{B6129B49-C2CD-446B-A76C-B00A38F217DA}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\MediaStreamer.exe
FirewallRules: [{1B047C1A-3B33-4BA5-A593-4DFDFCD59D1F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{50D027C2-5E2D-47BD-96AC-CC2AE16B8989}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{09FCE54F-D620-4A02-9A49-E457F560CE9B}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{BEDF6233-20C0-4447-B941-CB8937379D77}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{ED70EE5C-8189-482F-8127-A8ADF33FBBD8}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{F4D843B9-8478-4B8F-A90F-28F496D9484F}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{6BE44876-0C65-41EB-9491-89F98D4DCA7D}] => (Allow) D:\Steam\steamapps\common\Divinity Original Sin Enhanced Edition\Shipping\EoCApp.exe
FirewallRules: [{BFEE8AE8-59DC-4857-BC5F-3FCAD6BDBEFF}] => (Allow) D:\Steam\steamapps\common\Divinity Original Sin Enhanced Edition\Shipping\EoCApp.exe
FirewallRules: [{46AB0E80-A6DE-4F27-93C5-CF92CA605715}] => (Allow) D:\Steam\steamapps\common\Tom Clancy’s Rainbow Six Siege\RainbowSix.exe
FirewallRules: [{8342EA24-82AF-465A-89C6-FA5B082047BF}] => (Allow) D:\Steam\steamapps\common\Tom Clancy’s Rainbow Six Siege\RainbowSix.exe
FirewallRules: [TCP Query User{B3B3C77C-B2C0-4F9B-B3AF-C29AB081FBCC}D:\far cry 4\bin\farcry4.exe] => (Allow) D:\far cry 4\bin\farcry4.exe
FirewallRules: [UDP Query User{CEBC6A32-41C8-407F-B9CA-4EBCADCF91BA}D:\far cry 4\bin\farcry4.exe] => (Allow) D:\far cry 4\bin\farcry4.exe
FirewallRules: [TCP Query User{2B6351C4-5200-4286-80D8-7D3BDC8110EC}C:\users\winata\appdata\roaming\spoti fy\spotify.exe] => (Allow) C:\users\winata\appdata\roaming\spotify\spotify.ex e
FirewallRules: [UDP Query User{51B643C9-3252-4AC1-8732-419D10B78855}C:\users\winata\appdata\roaming\spoti fy\spotify.exe] => (Allow) C:\users\winata\appdata\roaming\spotify\spotify.ex e
FirewallRules: [{26323787-876B-4518-ACEF-5DBD01F2D743}] => (Allow) C:\Users\Winata\AppData\Roaming\uTorrent\uTorrent. exe
FirewallRules: [{FEFF45C0-D96E-4CB5-8561-3F7FFCBF51F5}] => (Allow) C:\Users\Winata\AppData\Roaming\uTorrent\uTorrent. exe
FirewallRules: [{B704F94C-378C-449B-B445-EC440817D7AA}] => (Allow) C:\Users\Winata\AppData\Roaming\uTorrent\uTorrent. exe
FirewallRules: [{7927C215-2428-4C8D-941F-07E662D6C014}] => (Allow) C:\Users\Winata\AppData\Roaming\uTorrent\uTorrent. exe
FirewallRules: [{D8ABB999-DA61-45D1-896C-CEA4938A1CC2}] => (Allow) C:\Users\Winata\AppData\Roaming\uTorrent\uTorrent. exe
FirewallRules: [{BDEC7113-14E7-4B18-BA64-270DDC6302AE}] => (Allow) C:\Users\Winata\AppData\Roaming\uTorrent\uTorrent. exe
FirewallRules: [{B1EA46CB-B57D-40F7-BC36-AD30AA26E5CE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{663C1C7B-0E42-4B14-8DF6-BB6545615ED2}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{D7810836-6CE3-418C-97AC-9211CA00A3E6}D:\r.g. mechanics\wolfenstein - the new order\wolfneworder_x64.exe] => (Block) D:\r.g. mechanics\wolfenstein - the new order\wolfneworder_x64.exe
FirewallRules: [UDP Query User{8553B954-9958-4127-885A-FEE7BF5FA4FF}D:\r.g. mechanics\wolfenstein - the new order\wolfneworder_x64.exe] => (Block) D:\r.g. mechanics\wolfenstein - the new order\wolfneworder_x64.exe
FirewallRules: [{3048BF09-CA64-452A-8BA9-24A809338A07}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{B68CECF9-C148-481C-BF58-6556FE566166}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [TCP Query User{DEAA1F24-0F2A-444D-9F58-FC22AD2ACC73}C:\windows\temp\files\bin\kmss.exe] => (Allow) C:\windows\temp\files\bin\kmss.exe
FirewallRules: [UDP Query User{A227D6E0-4329-47C0-97FC-E8E395B45CC3}C:\windows\temp\files\bin\kmss.exe] => (Allow) C:\windows\temp\files\bin\kmss.exe
FirewallRules: [{49071643-4AF9-4E98-B9E8-444979C2C575}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{9BD7C176-4F42-4CF3-BEE6-1081961DEA0A}] => (Allow) D:\Steam\steamapps\common\Bloodstained Ritual of the Night\Bloodstained.exe
FirewallRules: [{8F1ECC00-E733-4F2C-B01A-4E1EA7C875B3}] => (Allow) D:\Steam\steamapps\common\Bloodstained Ritual of the Night\Bloodstained.exe
FirewallRules: [TCP Query User{C497CA6D-4FB1-4664-82C6-9362EE37B03D}D:\steam\steamapps\common\bloodstaine d ritual of the night\ron\binaries\win64\ron-win64-shipping.exe] => (Allow) D:\steam\steamapps\common\bloodstained ritual of the night\ron\binaries\win64\ron-win64-shipping.exe
FirewallRules: [UDP Query User{8FA3072B-DA0D-4D57-A6E5-82EE3E3F1A9D}D:\steam\steamapps\common\bloodstaine d ritual of the night\ron\binaries\win64\ron-win64-shipping.exe] => (Allow) D:\steam\steamapps\common\bloodstained ritual of the night\ron\binaries\win64\ron-win64-shipping.exe
FirewallRules: [TCP Query User{039D97D5-A0AD-4AF6-BC36-5B717CF281E1}C:\users\winata\appdata\roaming\spoti fy\spotify.exe] => (Block) C:\users\winata\appdata\roaming\spotify\spotify.ex e
FirewallRules: [UDP Query User{E15D8482-2221-428B-B2BF-DF856AC39E6C}C:\users\winata\appdata\roaming\spoti fy\spotify.exe] => (Block) C:\users\winata\appdata\roaming\spotify\spotify.ex e
FirewallRules: [{B11211BA-5644-4D87-A549-3C893867DD3D}] => (Allow) D:\Steam\steamapps\common\Tom Clancy’s Rainbow Six Siege\RainbowSixGame.exe
FirewallRules: [{86125895-1701-4B57-BFA7-0B1D86020023}] => (Allow) D:\Steam\steamapps\common\Tom Clancy’s Rainbow Six Siege\RainbowSixGame.exe
FirewallRules: [TCP Query User{9F04C030-B1CB-4D8A-8E8F-26778BB6220E}D:\igg-quadrilateral.cowboy\qc.exe] => (Block) D:\igg-quadrilateral.cowboy\qc.exe
FirewallRules: [UDP Query User{CACDF91C-70E0-430A-AD19-C28492E7F4CC}D:\igg-quadrilateral.cowboy\qc.exe] => (Block) D:\igg-quadrilateral.cowboy\qc.exe
FirewallRules: [{2D31B00D-1D00-4158-99A5-38A9F49518E8}] => (Allow) D:\INSIDE\Steam\Steam.exe
FirewallRules: [{4FE0E548-FB56-44AD-AC18-6323C08AF0F3}] => (Allow) D:\INSIDE\Steam\Steam.exe
FirewallRules: [{DBF10588-D83F-4C14-A0FB-7A6A280F1C75}] => (Allow) D:\INSIDE\Steam\bin\steamwebhelper.exe
FirewallRules: [{E9B4AD1D-CDE3-452C-A054-0F9072F0D3B5}] => (Allow) D:\INSIDE\Steam\bin\steamwebhelper.exe
FirewallRules: [{EBB65910-A215-484D-9999-906A3949CEFC}] => (Allow) C:\Program Files\Intel\STCServ\STCServ.exe
FirewallRules: [{63AEED77-501B-49E8-AD25-6ED86748DAB9}] => (Allow) C:\Program Files (x86)\ASUS\Share Link\ShareLink.exe
FirewallRules: [{873E88CC-1376-4E36-B7F4-C7258B71D715}] => (Allow) C:\Program Files\Intel\STCServ\STCServ.exe
FirewallRules: [{BE639B89-97D9-46A0-B214-B482BEE1E15E}] => (Allow) C:\Program Files\Intel\STCServ\STCServ.exe
FirewallRules: [{3865DAD0-4C7F-45FD-B72D-9C4A56D1946B}] => (Allow) C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe
FirewallRules: [TCP Query User{BFD0983E-728A-40FD-84EE-93B47AF3AEE3}C:\program files (x86)\peak angle\peakangle.exe] => (Block) C:\program files (x86)\peak angle\peakangle.exe
FirewallRules: [UDP Query User{3A062928-4BCA-4BB8-9C78-4889A8B46767}C:\program files (x86)\peak angle\peakangle.exe] => (Block) C:\program files (x86)\peak angle\peakangle.exe
FirewallRules: [TCP Query User{DB435670-FBD1-4614-B3A3-C82063AEAD48}C:\program files (x86)\peak angle\peakangledefaultsettings.exe] => (Allow) C:\program files (x86)\peak angle\peakangledefaultsettings.exe
FirewallRules: [UDP Query User{CF644DA8-2696-4050-8518-0F5E494662B6}C:\program files (x86)\peak angle\peakangledefaultsettings.exe] => (Allow) C:\program files (x86)\peak angle\peakangledefaultsettings.exe
FirewallRules: [TCP Query User{A007CA37-57BE-414A-984F-1AB50CE216CC}D:\installer\assetto corsa (skiddrow)\assetto corsa\acs.exe] => (Allow) D:\installer\assetto corsa (skiddrow)\assetto corsa\acs.exe
FirewallRules: [UDP Query User{1AC0376C-3739-4FE1-AD8D-C7A74E1D0E6C}D:\installer\assetto corsa (skiddrow)\assetto corsa\acs.exe] => (Allow) D:\installer\assetto corsa (skiddrow)\assetto corsa\acs.exe
FirewallRules: [{99E0C6C9-4CC9-4513-8E35-1E6952BE8F67}] => (Allow) C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe
FirewallRules: [{6ED7CADD-1B4D-462C-9D78-8A4303E115DF}] => (Allow) C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe
FirewallRules: [{B3E1BF01-F3E5-4FE9-B061-8DCDE62450C8}] => (Allow) C:\Program Files (x86)\SrpnFiles\downloader.exe
FirewallRules: [{8857C463-D585-4E3C-AE08-C499480CFF02}] => (Allow) C:\Program Files (x86)\SrpnFiles\downloader.exe
FirewallRules: [TCP Query User{8DE5B21F-BFAD-4BE5-895D-47CA005FFCA9}D:\doom\doomx64vk.exe] => (Block) D:\doom\doomx64vk.exe
FirewallRules: [UDP Query User{C6AD7F0B-D95F-4292-B1AE-80A177DE1536}D:\doom\doomx64vk.exe] => (Block) D:\doom\doomx64vk.exe
FirewallRules: [{AF81BA1F-37BE-4F2D-BA6C-70669993AA9F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{478468BD-7727-44DD-803E-89253810EFD2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{53C25FC4-DD12-4990-B873-E0926365DDF2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{E66CF01D-B75B-4CE3-A4CD-A2A3A6FB390F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{E879A518-D8E4-4EE9-A046-BB63207DB446}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{8BB8662D-F2E8-4EA5-A15C-3566D0F01947}] => (Allow) D:\Steam\steamapps\common\Divinity Original Sin 2\bin\SupportTool.exe
FirewallRules: [{4E9E5348-4A9C-4ED9-8A55-CFD39904BA0E}] => (Allow) D:\Steam\steamapps\common\Divinity Original Sin 2\bin\SupportTool.exe
FirewallRules: [TCP Query User{89443536-0907-46C0-B901-AC85E5A65FFE}D:\steam\steamapps\common\divinity original sin 2\bin\eocapp.exe] => (Allow) D:\steam\steamapps\common\divinity original sin 2\bin\eocapp.exe
FirewallRules: [UDP Query User{9B1CE90A-F29F-4740-99A2-F873B7CB297D}D:\steam\steamapps\common\divinity original sin 2\bin\eocapp.exe] => (Allow) D:\steam\steamapps\common\divinity original sin 2\bin\eocapp.exe
FirewallRules: [VirtualPC-In-UDP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-UDP-2] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-TCP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [TCP Query User{C34AA4B5-3928-4FE7-BE5B-72CBB47EA6FC}D:\mafia iii - digital deluxe edition\launcher.exe] => (Block) D:\mafia iii - digital deluxe edition\launcher.exe
FirewallRules: [UDP Query User{7092FC96-1C6C-4C2F-8FA8-842F2BA943FD}D:\mafia iii - digital deluxe edition\launcher.exe] => (Block) D:\mafia iii - digital deluxe edition\launcher.exe
FirewallRules: [TCP Query User{17249BCA-0EE4-4624-8247-83E0521240B4}D:\mafia iii - digital deluxe edition\mafia3.exe] => (Block) D:\mafia iii - digital deluxe edition\mafia3.exe
FirewallRules: [UDP Query User{785A76A9-4957-4AEE-BC79-DA8BFF655A01}D:\mafia iii - digital deluxe edition\mafia3.exe] => (Block) D:\mafia iii - digital deluxe edition\mafia3.exe
FirewallRules: [{4D797AB7-6F73-46DB-AC23-CDAB45E96FF4}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{AD48EAE3-C37E-4245-9501-FE4F1B56AC57}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{40A5F063-ABC0-4897-A5B6-3D171AD11557}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A911D116-6590-4B4C-9A1C-AB771CB36FD5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3A46272A-86E6-441E-9B1C-F085587E66EF}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{34B7292F-B7B8-4F63-8F8E-993AE5D089CE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A5F5CF03-4901-42FB-A283-92BD954EDA8C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{02722E5E-A068-4CE7-B9B7-9609555514C6}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C3E7A935-0B3C-4C66-A9FB-038BBE8B5FC9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6DB12AA6-4015-4DE7-9EA2-96139B8EE664}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3844228D-21C1-47E3-A7AF-9993846F11CB}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{31DF5BC7-0B77-4192-9046-25451DA4F921}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7C713299-75D8-49B5-82EC-52713D63689E}] => (Allow) D:\Origin Games\Battlefield 1\bf1Trial.exe
FirewallRules: [{F1E16A89-F54F-422E-8096-223A67C957ED}] => (Allow) D:\Origin Games\Battlefield 1\bf1Trial.exe
FirewallRules: [{08E9E945-5E51-45DF-A2CB-948807DE0AF2}] => (Allow) D:\Origin Games\Battlefield 1\bf1.exe
FirewallRules: [{318D1DE5-FCCD-4398-B607-A11EA2470A1E}] => (Allow) D:\Origin Games\Battlefield 1\bf1.exe
FirewallRules: [{C057A7B2-0E44-4645-A749-0A0F2900A151}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BDF1C134-8B9C-4065-9588-7DC8D79C9256}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F79E2111-9FF1-4CA3-8F83-44A9AAA178BF}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4F67E2E5-C44B-4394-B962-53A0BE318F97}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B9897B99-3B52-4125-BCC3-A51912B3D6E5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CC80FC2C-C751-49D0-9F65-EDBF11C896D5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{563B6A75-F769-433A-87D4-5515350E8734}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D1F75E09-2EE3-4BE5-BD79-7F6E327CADA5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{217FA76C-2F3C-48AA-ABFA-456B15E1526F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{071CC862-3EFC-4FBB-97B3-269430C72162}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A42984C5-0915-44D3-9286-B88C3F044FD1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8072A021-45B1-4C9D-B8E4-C7C68D3327F1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B2A51D60-7614-4D24-8666-B4C4FFD78D5B}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F5240DE2-CC13-4E9A-9CCB-5284FC0C8291}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{84E9B0B2-A5F9-4DCB-96C7-FFE4D97B5071}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{798F5B99-7767-4665-BA82-F143DC26F533}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9EB8586B-55DF-45F6-9AA3-247F318D0EEC}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{590AE367-CDD2-454A-B0C6-2C4EA842C16F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{7559474C-DC4F-4894-A157-312830E4A13E}D:\activision\black ops ii\sp.exe] => (Block) D:\activision\black ops ii\sp.exe
FirewallRules: [UDP Query User{7340BFA3-F866-40D1-AA22-94301BB04F54}D:\activision\black ops ii\sp.exe] => (Block) D:\activision\black ops ii\sp.exe
FirewallRules: [{CECFBEB7-A64D-4C3B-80F2-1DE1250BC4D3}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E686C2A9-8206-42B0-8D03-A7CADA7EE4AB}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B8F4FA1A-6BC6-4BCC-A782-A5084A54DD9D}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CE94429B-88AF-447E-AE94-5BF39914C2D9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F03CBE3E-48FF-4A01-B22E-CAB2C3CBEF7D}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{89A514A8-348D-43DB-A383-BFFA42B5B16F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6C8686EF-B9DA-467C-A29E-39AE6C7C00F1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{30DDEB6B-ED25-427E-96B9-60BE7A317C8D}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EA28D4AE-25F4-41DA-8C7C-B086BCD4E0E1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A60461D5-7E42-466D-ACEB-4534E1A29659}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{14C42345-9C7C-4F35-B383-B82733DF662E}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F3C22F82-4209-403B-A0D3-3AC7DA1B2203}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4847090D-8B33-4E4C-ABF2-DFB3FFB3F160}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3A9E3DB0-A466-406A-940B-D3BCE4718A37}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3BCBC0E0-2651-476F-95F0-1C3E20CAAE7C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2544502C-E52F-422D-8184-A16FBA2F709F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5ABCB168-535A-490E-8B52-85395D68EF71}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{676D19C7-197C-48CC-87A4-94D1D3881586}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{65F9E743-CA30-43C8-85CB-746BEA1960A1}D:\eve\sharedcache\tq\bin\exefile.exe] => (Allow) D:\eve\sharedcache\tq\bin\exefile.exe
FirewallRules: [UDP Query User{69E3C081-1CE4-4AC7-9DEB-9286F100C39C}D:\eve\sharedcache\tq\bin\exefile.exe] => (Allow) D:\eve\sharedcache\tq\bin\exefile.exe
FirewallRules: [{47E227D8-4952-43B8-B917-08C174E80E52}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{55F01913-C498-4D8D-9773-228BAB6829F0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A4EAD85A-0F1D-4877-8C99-9EDC92BB6C6F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{52AECD4D-A236-4C08-99C5-46379F93AB78}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0D196F0E-77B8-4CD1-8EAF-6FD362AA6DCA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6BC31B8F-FFCB-47D9-A465-82FB543183CA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CD7AF00F-40E9-410B-AC58-B9F580915324}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E09C0243-35CE-461E-8667-F293111D8E0A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{DFD5D913-33D6-4741-91C9-A4CB287FF169}D:\assetto corsa\assetto corsa\acs.exe] => (Allow) D:\assetto corsa\assetto corsa\acs.exe
FirewallRules: [UDP Query User{4383E6DF-9EA4-4004-89E4-019710DCC1D2}D:\assetto corsa\assetto corsa\acs.exe] => (Allow) D:\assetto corsa\assetto corsa\acs.exe
FirewallRules: [{9B6F85C3-8FCB-4000-B31F-1F6083ED7A70}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8DA4DA46-C6D1-4275-82C7-351D55025C30}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AC54C3E4-2EA4-4091-AEA8-E0199BB27037}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D59C987F-2640-483F-B610-D26BCE1E6180}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{20538B16-9265-4F7C-BE25-AB18F0EC4191}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{573A31E4-E490-4720-9BD7-1D76983AD595}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{B4B90647-5CDE-438B-80A1-02F51B0B00CC}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9B948204-0BC0-444D-9E37-DCB54FB56A43}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2F90B285-3F57-4270-8A03-DF4BBB37FA41}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FDE3A8BB-9034-40C3-8078-A0EB42497849}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3866EBE0-1106-41B5-94E9-D97B90F29690}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6812AFDA-1500-4A3B-BFE2-3B918A1270F0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{76ABC1FC-44D0-4C21-BC00-F3AA7092D891}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3E562509-21DE-47FB-B0B2-3E54C8DECB10}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{022C5F6C-EB03-4419-88A9-CE4B8FD777AC}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{63CA183A-CE08-4111-A81F-304CFED010AA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2446A4D5-E598-4C55-B88F-22CC99EEDCD1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{85B75C35-9D97-4658-9F06-62BB63960BE3}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B36C8B3A-6187-4CAA-AF20-BAA6AF0F005E}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E088DAE5-DB77-4BF0-8820-EA2498FB1938}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{44AE343C-E884-4FE8-A870-F788BBDE1D4B}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0C5555D4-E952-483F-90AD-C5FE3407CBCF}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D8E1B0EC-D25E-43F1-9442-08A03FC81FF0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{10569696-95CB-4DED-8FBF-BBED2FDC5370}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{52561615-A218-472E-B7D7-0EAE36271BF2}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5A779FAE-DF81-4910-974F-3982E62923F8}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{51FF6BBF-B892-403F-8F9E-6750F0175AC8}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{70963FC5-4759-4CFE-B5A5-C396C2803849}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2CE174EF-98BC-4238-898A-ACF05F389DB9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DEA91D13-C850-4004-9E73-FABA89B91D14}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6710EB80-6D42-400B-BAC4-5AAF57E1CF00}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4EF8A45F-87BE-463D-A54C-46FED8E8C555}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{978DEC58-C6F1-4AF1-A59A-F5E0C626EE30}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{44EE030A-7001-4136-B14E-59AD0FC9B90C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D07A9306-9900-4BB4-B394-FA61396D759F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{9202C902-5E75-411F-A62E-0E1DB04D11E7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{B5E21B37-34E0-4A40-A955-2CD971837BCD}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{43B7A6E9-7AF5-48AC-BBCA-C6126E67E685}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{D89ADE3F-DD21-46FC-8B6F-832D925615E9}D:\alien isolation\ai.exe] => (Allow) D:\alien isolation\ai.exe
FirewallRules: [UDP Query User{EE7D349A-DB96-4637-AF1C-77E7C9FD41BF}D:\alien isolation\ai.exe] => (Allow) D:\alien isolation\ai.exe
FirewallRules: [{E605349A-7B37-4A9D-8AC8-4C661EDD8737}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4DB24B0D-CD7B-460B-8E40-844AB15C3307}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CCF294AC-3EF3-4F34-AB20-8331208ABB6C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{16BF91E9-ED8E-4633-817B-F52DDAC5E601}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{392CFE12-2A79-4B22-9633-737A623A41C7}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DC4DC82F-37FB-4886-83F4-D89D9EEF21B1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1060217B-C209-43CA-9CD0-3749D5D86E77}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1AD9DBA0-C7D5-413F-91FA-A60EB3633A42}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3F3C1A76-D256-4CAC-8D44-ED68CE0617D1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0DF149FF-9EDB-4620-85FD-EE286E8B1105}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{07B5EEBB-E1C8-4A36-B497-3148E8BAFFF0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C26C4284-70EE-453F-A21F-E8F5AE901582}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9405D2D1-125D-4249-8583-6EF56FEB0CD4}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CB988B8C-C78B-468B-8F80-63BF95278694}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2AB02979-68E5-4B1D-A998-45697FD0C7D4}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DBC9097C-D721-40EF-9534-6D6F6862C9BE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DE06D7A9-5685-4D9A-9737-45EE67204425}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{85167C5B-1336-460B-ADF0-9944389BF6BA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FE4F7A15-3A6B-4B3E-8CB8-83846066F6F1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{ABF289C7-D030-48FF-A221-A536237D86D7}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{46B5D13A-F12D-4E4A-950A-0316195FD8B7}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{45B3CA65-DAA5-4050-B54C-D1F8DC9CB6E8}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AC42DB29-1469-46C3-AD15-FCF34F7B221E}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{496E9847-DD12-49EC-9EA4-BD4FB3292F17}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{015CF1D3-0C1F-440D-AABE-EFEBFC5CE17C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E2841F91-6DF2-4789-A2B6-02F549DE7601}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C40E3034-90B5-4BA3-A661-E24E7CCC7370}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D08C814A-04A3-4974-9A06-0E6209A5379F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EEA66249-95C9-457B-ACA0-87DDD52D9A5F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5267BDBB-7BA8-4A2A-88D3-D71D5A6173CC}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D3119A81-C18D-4510-B88A-F370E7B603C4}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E9430D52-346C-4C93-AA12-02242B9E6B93}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{834FC505-38AF-445C-940A-2F8A692A234B}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8FAA2A04-4551-439C-832A-52E25040C64C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9D91238B-10A2-47A8-A015-B7AF36D9A92F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5CA63721-605C-4E03-8981-DC9A27919F40}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E30A604C-6830-4E30-92B2-F59C97FB7254}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{33418EE9-4BCA-4BDD-B731-D34E621D90AE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8E6456B8-7EFC-4CFA-B8B5-62E0BF3FB19C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C6ABA176-0E7C-49DB-9893-396E16D2F206}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D41D8946-F53D-4A42-9FA8-9F989BA954E8}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{360F5239-59FC-4DDC-A5E1-44BD04718D7C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E25FEC9E-F880-4D22-B99F-CC027C5324A3}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0863364E-6F9F-4613-A431-6B225E4002F9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E28E3971-4385-45E9-B6E6-0F536BB0ECC6}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C6567B5D-FB2A-45B6-8EE8-ED2BF4EB5E64}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DB9E89C4-47FB-4F5B-949C-24E2771F137A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BE1A143D-64FB-4A02-BB3B-C16741582751}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9CCDE8B6-9842-4EF6-BDF1-9EC129E8D746}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{070C5F9F-FEA9-4BA5-89ED-40C4210483B7}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D74FCEBE-9EC2-42FE-961C-5EE74D207233}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1945A71C-E363-4F2E-B436-8B074C68ADC8}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EEE4657D-E919-430B-9C1F-D351CDD8C4F0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{ABBFD182-85C1-4325-B20F-85E87252FE1A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{736E7F61-3D20-4D2F-AB58-182DEA7200A5}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRe tail\Evolve.exe
FirewallRules: [{B0ABCDCE-158C-41D3-B431-3416E0EA8CBF}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRe tail\Evolve.exe
FirewallRules: [{3896D8BB-D430-424B-BDD6-9C7B45B484D3}] => (Allow) D:\Steam\steamapps\common\MOBIUS FINAL FANTASY\mobiusff.exe
FirewallRules: [{6D6C530B-923E-4F75-A1C3-FB27738A1875}] => (Allow) D:\Steam\steamapps\common\MOBIUS FINAL FANTASY\mobiusff.exe
FirewallRules: [{576E8250-2384-4802-A744-16A100730512}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{218D791E-6C87-465C-9ECE-13FD3DEC657B}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{759CC722-F01F-49B6-8C53-91BDA9353D65}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D499AC5C-1662-4EBE-83B3-F13A9A107F6A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A241EC52-2069-45CB-BD14-90BAB17118FE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F3FDBBB0-01CD-4FFF-BAD8-A9D3401D20B5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D70F7527-4F5A-4FFC-B1B4-D24B3306419C}] => (Allow) C:\Program Files (x86)\Opera\43.0.2442.991\opera.exe
FirewallRules: [{B3D87BF6-42E7-4284-89BF-56D53298F8E4}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F4E05BEB-9506-40F7-A754-C0AA027679E0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1CBEB3A8-7DB4-4651-828F-59A210F4AC2A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{00D1C6D1-DEA6-4E5F-AF22-36AFF21AA488}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{46B86046-3AB6-42C9-A5C2-953748FE1187}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6927F173-3761-428D-8C26-E9C4A00E6AA9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E199CA31-614A-4207-A517-F77389574BD5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EBBEB117-6AA2-44E8-B65B-E5383D1957D2}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{93058899-D6D4-4420-BB5E-69EA74B20D44}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E0F5C38D-C192-4B7B-BA57-EFFE8C14A0DA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{81FA60DB-1FD5-4B25-8F35-71C69B840EB1}] => (Allow) C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe
FirewallRules: [{B6B67FE7-462C-4CDE-8CC3-40FAC7552C83}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6135B32A-D961-41F1-A6E4-85F355B027CB}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6D878C99-4A05-4B91-9F3B-8C256E8DD073}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1D665A2C-F88A-466B-8B10-478463ABB57D}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0072048F-CB99-43B8-B6B8-FD80E4111719}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FACCC7ED-FD07-4EC0-9915-02079BB5D2EC}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A41298F9-32C1-4B8A-9FEE-2FCADCFC2034}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{466BE7E1-7E7E-4882-8BF1-63DB7A78BE04}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{400B13FD-9950-43A6-8028-AD32148C3C6A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AE8A7483-2B66-43BC-90F1-C31C39DACE48}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A3BE2EC0-5B87-4165-AB69-66B74589C124}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E202254F-04A2-4C15-8C60-E2492A807C83}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F42B3969-4593-4EEC-86F0-AA0F4F683FFE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3FA1B176-BA66-4D33-9208-6D516C941FE1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7B1E9FD3-ED64-460A-9080-BCCC4780FAEC}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E387AB43-9049-4DC7-84D4-6306EB10974C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F048CA03-5FB9-441B-B6FA-74673E7067EA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3092BDCE-2000-452B-A22D-DD6F577BE9A1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C8EAA1F1-7615-4053-9022-54BCEC421864}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{11191C53-9FB0-45F5-B0B6-D739304C3A5F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7D1B7BA3-EA78-4B94-8E0A-872C94DCEB07}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EE2AFF2E-142E-4E34-9B78-AA693F7CBE52}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{41F53D59-DA64-4469-8A3A-8883F8EA268B}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{02F7BED7-70A6-4715-9BBA-B85C679EEC61}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{004C4B06-CC75-4F1D-83AF-CEF323AD30A0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{87D52A32-A3AF-4E96-93DE-3AD87F786E02}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E984D514-A4DB-4A70-A8AE-EDDFCBEED2ED}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FC3D0689-43BB-43E9-BE13-1D39288C514B}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B84DD7A0-5667-4E05-9FB3-FAEA1603D223}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CD9C0FB4-47C7-40C9-AC0D-E24798E4978E}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6F7CD9A1-A158-466F-B180-633BCADE1479}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BFCD1665-AE62-48C3-89AD-FB1B8FF88D06}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5B61994B-91CF-49F1-B39A-B14010B0112F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C50FE606-E7B8-4C9B-A1D2-4F5F6C0B7E05}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0FAD0F74-EC8F-479D-BC34-FB382EBF8AFA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EFAB7B07-B9AE-4DA1-861B-AC7C00E19AD3}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7E5AEEF3-D959-40D7-AF59-1380CD8861ED}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D0BBE122-76C8-4668-84D2-8E8590103AC2}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{722A8C5C-294C-4531-B80D-48CB2E798976}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4F866EFD-5EF1-4825-815D-378889D08698}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FB05EEAA-D3E3-4E63-9915-D8D74CCEEBE5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E9238F30-ECA6-428F-A355-5DC381216E02}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{3A29BACD-7F44-4B90-828B-667096EEA456}C:\users\winata\downloads\psxdownload helper\psxdownloadhelper.exe] => (Allow) C:\users\winata\downloads\psxdownloadhelper\psxdow nloadhelper.exe
FirewallRules: [UDP Query User{2221A870-2147-4129-872B-D80301C92EAA}C:\users\winata\downloads\psxdownload helper\psxdownloadhelper.exe] => (Allow) C:\users\winata\downloads\psxdownloadhelper\psxdow nloadhelper.exe
FirewallRules: [TCP Query User{38A52668-A269-4B83-BDEE-53F16BD1E3EA}D:\assetto corsa\assetto corsa\acs.exe] => (Allow) D:\assetto corsa\assetto corsa\acs.exe
FirewallRules: [UDP Query User{11A40A01-CB60-482E-AD3F-9F841358B031}D:\assetto corsa\assetto corsa\acs.exe] => (Allow) D:\assetto corsa\assetto corsa\acs.exe
FirewallRules: [{97C6725A-74D6-4BD2-A886-F480D62964D6}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8D0A1FAB-0D60-4AE9-B9BB-5B0A3FAE3EC3}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BFAFBB8C-8F2A-41D0-9A1F-ACD3FEAEF6F1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EC2F9B22-EC45-46C5-AFC4-0AEEC11CD001}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A2C4917A-47DC-4656-B29C-805CA2EEBD55}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{78173A05-7FD5-4606-8A72-35152DDFE16D}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8C3371F4-92AA-4B50-B30C-E13BE4A1BF11}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2820AA8A-1602-4950-BA02-DB684B1723F6}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{47E42033-A66E-43AC-801D-90EF8AF08356}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{63BB03A4-1B45-41F5-98CA-176E1FB801B6}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{04D8D6AD-9B1C-44EE-9352-B6467BFAED8A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4C3F3E6C-046A-4237-9DDF-3BAB77437092}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7DDA43AB-D9BD-4961-BB0F-4C18267330A2}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [{9F7808DA-6144-4164-8B7D-1CDB9134D633}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [{0046922B-6A0F-4311-AE60-60ABC821788D}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DEF8EB7E-97EE-4DA0-821E-A5F3E4EF0C6A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0643824A-0C27-43AE-A469-B01C071DDE62}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{A436BAAF-D45F-4DEB-AA40-6586DBF8B216}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DE2C85D1-3B3A-4622-9E36-5927F08109D7}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F7E6C4F5-B214-486D-ACBD-2290564E9834}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{EBCDF4BE-A361-4AEA-820A-6218347D0C68}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3063D5E3-CC59-4217-AD5D-5EC568CBCCD6}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AE0C7406-2D59-4EC1-A9DE-BE4AAEC5B724}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CE9AC0D5-36BE-426A-A931-0CC3AB474469}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{94765976-B781-4ABB-9575-55C7C9C4F335}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B3E72776-BB67-4590-9B75-138E782E929C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F3557020-FCC5-417F-B596-C261B0538465}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe
FirewallRules: [{DAF9E7AC-DBC3-4369-9453-A9E2328D50E9}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe
==================== Restore Points =========================
25-04-2017 22:22:13 Scheduled Checkpoint
==================== Faulty Device Manager Devices =============
Name: Microsoft PS/2 Mouse
Description: Microsoft PS/2 Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
[HEADING=1]Application errors:[/HEADING]
Error: (04/26/2017 07:18:41 PM) (Source: MsiInstaller) (EventID: 1002) (User: Winata-PC)
Description: Unexpected or missing value (name: ‘PackageName’, value: ‘’) in key ‘HKLM\Software\Classes\Installer\Products\D139E7FE 48CDB174D86B8A3385904547\SourceList’
Error: (04/26/2017 07:18:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program nvtray.exe version 7.17.13.7892 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 99c
Start Time: 01d2be84f46b9f24
Termination Time: 2
Application Path: C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
Report Id: 73125746-2a7a-11e7-af57-9c5c8e98605f
Error: (04/26/2017 07:04:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (04/25/2017 08:07:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (04/25/2017 05:22:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (04/25/2017 04:55:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (04/25/2017 11:42:14 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (04/25/2017 01:20:51 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SMΔRTP.exe version 4.107.0.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 798
Start Time: 01d2bd2711fb0761
Termination Time: 2
Application Path: C:\Program Files (x86)\Smadav\SMΔRTP.exe
Report Id: bd562776-291a-11e7-8a7c-9c5c8e98605f
Error: (04/25/2017 01:20:22 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (04/25/2017 01:16:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
[HEADING=1]System errors:[/HEADING]
Error: (04/26/2017 07:04:41 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (04/26/2017 07:04:41 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (04/26/2017 07:02:44 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Origin Web Helper Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (04/26/2017 07:02:44 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Origin Web Helper Service service to connect.
Error: (04/26/2017 07:02:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The SCP DSx Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (04/26/2017 07:02:13 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the SCP DSx Service service to connect.
Error: (04/25/2017 08:07:45 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (04/25/2017 08:07:45 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (04/25/2017 08:05:59 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Origin Web Helper Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (04/25/2017 08:05:59 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Origin Web Helper Service service to connect.
==================== Memory info ===========================
Processor: Intel(R) Core™ i5-6500 CPU @ 3.20GHz
Percentage of memory in use: 47%
Total physical RAM: 8106.85 MB
Available physical RAM: 4295.57 MB
Total Virtual: 16211.88 MB
Available Virtual: 12242.65 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:156.25 GB) (Free:1.96 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (New Volume) (Fixed) (Total:1862.89 GB) (Free:22.32 GB) NTFS
Drive e: (Data) (Fixed) (Total:141.83 GB) (Free:11.54 GB) NTFS
==================== MBR & Partition Table ==================
================================================== ======
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: E4D3E4D3)
Partition 1: (Active) - (Size=156.2 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=141.8 GB) - (Type=OF Extended)
================================================== ======
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: F9F0F9F0)
Partition: GPT.
==================== End of Addition.txt ============================
any help will be really appreciated.. already on wits end.. thanks!
been reading a post regarding the same problem but i think i need to post some log from FRST scan?
already have the FRST ready and below is the FRST log and Addition log..
FRST LOG
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-04-2017
Ran by Winata (administrator) on WINATA-PC (26-04-2017 19:18:34)
Running from C:\Users\Winata\Downloads
Loaded Profiles: Winata (Available Profiles: Winata)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
(Smadsoft) C:\Program Files (x86)\SMADAV\SMΔRTP.exe
() C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe
() C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMR\AODMR.exe
() C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler.ex e
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler64. exe
() C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlServi ce.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.06.28\AsusFanCo ntrolService.exe
(ASUSTeK) C:\Program Files (x86)\ASUS\ROG Game First III\AsusGameFirstService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvr64.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BBSvc.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
() C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNoticeMonitor.exe
() C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotify_PCCtrl.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
() E:\New DNSCript\dnscrypt-proxy.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Spotify Ltd) C:\Users\Winata\AppData\Roaming\Spotify\Spotify.ex e
(Hammer & Chisel, Inc.) C:\Users\Winata\AppData\Local\Discord\app-0.0.297\Discord.exe
(Spotify Ltd) C:\Users\Winata\AppData\Roaming\Spotify\SpotifyWeb Helper.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
(Intel® Corporation) C:\Program Files\Intel\ConnectCenter\bin\CCFManager.exe
(Hammer & Chisel, Inc.) C:\Users\Winata\AppData\Local\Discord\app-0.0.297\Discord.exe
(Spotify Ltd) C:\Users\Winata\AppData\Roaming\Spotify\Spotify.ex e
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\AsusWSPanel.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
(FNet Co., Ltd.) C:\Program Files (x86)\ASUSRAMCACHE\RamCache.exe
() C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\ShareEdit.exe
() C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AODMS.exe
() C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\ASUSWSAgent.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Scarlet.Crush Productions) C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe
(Spotify Ltd) C:\Users\Winata\AppData\Roaming\Spotify\Spotify.ex e
(WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
(Nico Mak Computing) C:\Program Files\WinZip\FAH\FAHWindow64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Spotify Ltd) C:\Users\Winata\AppData\Roaming\Spotify\Spotify.ex e
(Hammer & Chisel, Inc.) C:\Users\Winata\AppData\Local\Discord\app-0.0.297\Discord.exe
(Spotify Ltd) C:\Users\Winata\AppData\Roaming\Spotify\Spotify.ex e
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EX E
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Pro\DiscSoftBusService.exe
(Intel Corporation) C:\Program Files\Intel\STCServ\STCServ.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\AsPowerBar.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\SeaPort.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.ex e
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8495320 2015-06-23] (Realtek Semiconductor)
HKLM...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM...\Run: [IntelConnectCenter] => C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe [90112 2015-03-16] (Intel® Corporation)
HKLM...\Run: [ShadowPlay] => “C:\Windows\system32\rundll32.exe” C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSyst emStart
HKLM-x32...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [296216 2015-06-15] (Intel Corporation)
HKLM-x32...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\AsusWSPanel.exe [5247272 2014-12-04] (ASUS Cloud Corporation)
HKLM-x32...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2015-05-02] (Adobe Systems Incorporated)
HKLM-x32...\Run: [ASUS AiChargerPlus Execute] => C:\Program Files (x86)\InstallShield Installation Information{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [550272 2013-01-28] (ASUSTek Computer Inc.)
HKLM-x32...\Run: [AO Link Server] => C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ALRun.exe -start
HKLM-x32...\Run: [ASUSRAMCACHE] => C:\Program Files (x86)\ASUSRAMCACHE\RamCache.exe [4325520 2016-06-18] (FNet Co., Ltd.)
HKLM-x32...\Run: [ASUS Media Streamer ShareEdit] => C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\ShareEdit.exe [1194808 2015-07-07] ()
HKLM-x32...\Run: [ASUS Media Streamer DMS] => C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AODMS.exe [2569528 2015-07-07] ()
HKLM-x32...\Run: [ASUS Media Streamer WSAgent] => C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\ASUSWSAgent.exe [86840 2015-06-03] ()
HKLM-x32...\Run: [SMΔRT-Protection] => C:\Program Files (x86)\Smadav\SMΔRTP.exe [1772072 2016-06-02] (Smadsoft)
HKLM-x32...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [28344776 2017-04-17] (Dropbox, Inc.)
HKLM-x32...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [DAEMON Tools Pro Agent] => C:\Program Files\DAEMON Tools Pro\DTAgent.exe [4809048 2015-07-08] (Disc Soft Ltd)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [Steam] => D:\Steam\steam.exe [3019552 2017-04-21] (Valve Corporation)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [Spotify] => C:\Users\Winata\AppData\Roaming\Spotify\Spotify.ex e [7064176 2017-04-20] (Spotify Ltd)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [Discord] => C:\Users\Winata\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [Spotify Web Helper] => C:\Users\Winata\AppData\Roaming\Spotify\SpotifyWeb Helper.exe [1446000 2017-04-20] (Spotify Ltd)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4299968 2016-06-22] (Disc Soft Ltd)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3952696 2016-08-07] (Tonec Inc.)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Run: [tdjyffwnaz] => explorer “hxxp://granena.ru/?utm_source=uoua03n&utm_content=e739009bccd5f1e6d7 1a91bff5994529&utm_term=A258243365F0EEA53DBB816BF5 3FF461&utm_d=20170419” <===== ATTENTION
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\MountPoints2: {02dfea50-6e70-11e6-b138-9c5c8e98605f} - J:\Startup.exe
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\MountPoints2: {3c72b88a-35b9-11e6-b9fb-806e6f6e6963} - F:\Bin\Instv2.exe
ShellIconOverlayIdentifiers: [ DropboxExt01] → {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] → {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] → {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] → {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] → {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] → {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] → {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] → {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] → {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] → {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ IDM Shell Extension] → {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] → {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.1.15.458\ASUSWSShellExt64.dll [2014-11-18] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] → {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.1.15.458\ASUSWSShellExt64.dll [2014-11-18] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] → {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.1.15.458\ASUSWSShellExt64.dll [2014-11-18] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] → {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] → {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] → {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] → {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] → {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] → {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] → {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] → {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] → {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] → {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-04-17] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2016-06-18]
ShortcutTarget: FAH.lnk → C:\Program Files\WinZip\FAH\FAHConsole.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScpToolkit Tray Notifications.lnk [2017-02-22]
ShortcutTarget: ScpToolkit Tray Notifications.lnk → C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe (Scarlet.Crush Productions)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2016-06-18]
ShortcutTarget: WinZip Preloader.lnk → C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
Startup: C:\Users\Winata\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 1050 J410 series.lnk [2017-02-02]
GroupPolicy: Restriction <======= ATTENTION
GroupPolicy\User: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
AutoConfigURL: [S-1-5-21-4254750808-1728920065-3872038573-1000] => hxxp://access-webs.biz/wpad.dat?3a085ef046b6d79c4ede521163213b5128895807
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip..\Interfaces{9821328F-5470-4A54-A1E3-627A2C55E86A}: [NameServer] 127.0.0.1
Tcpip..\Interfaces{9821328F-5470-4A54-A1E3-627A2C55E86A}: [DhcpNameServer] 192.168.1.1
ManualProxies: 0hxxp://access-webs.biz/wpad.dat?3a085ef046b6d79c4ede521163213b5128895807
[HEADING=1]Internet Explorer:[/HEADING]
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000\Software\Microsoft\Internet Explorer\Main,Start Page =
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://u.msn.com/id-id/?ocid=iehp
SearchScopes: HKU\S-1-5-21-4254750808-1728920065-3872038573-1000 → DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL =
BHO: IDM integration (IDMIEHlprObj Class) → {0055C089-8582-441B-A0BF-17B458C2A3A8} → C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2016-07-13] (Internet Download Manager, Tonec Inc.)
BHO: Lync Browser Helper → {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} → C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-04-10] (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper → {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} → C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-11-24] (Oracle Corporation)
BHO: Office Document Cache Handler → {B4F3A835-0E21-4959-BA22-42B3008E02FF} → C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2017-04-10] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper → {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} → C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-04-10] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper → {DBC80044-A445-435b-BC74-9C25C1C588A9} → C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-24] (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) → {0055C089-8582-441B-A0BF-17B458C2A3A8} → C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2016-07-13] (Internet Download Manager, Tonec Inc.)
BHO-x32: Lync Browser Helper → {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} → C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper → {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} → C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-23] (Oracle Corporation)
BHO-x32: Office Document Cache Handler → {B4F3A835-0E21-4959-BA22-42B3008E02FF} → C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2017-04-10] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper → {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} → C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-04-10] (Microsoft Corporation)
BHO-x32: Bing Bar Helper → {d2ce3e00-f94a-4740-988e-03dc2f38c34f} → C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll [2012-01-25] (Microsoft Corporation.)
BHO-x32: Java™ Plug-In 2 SSV Helper → {DBC80044-A445-435b-BC74-9C25C1C588A9} → C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-23] (Oracle Corporation)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll [2012-01-25] (Microsoft Corporation.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-06] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-06] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-06] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-06] (Microsoft Corporation)
[HEADING=1]FireFox:[/HEADING]
FF ProfilePath: C:\Users\Winata\AppData\Roaming\Mozilla\Firefox\Pr ofiles\pM5L0zpg.default [2017-04-19]
FF Extension: (Avira Browser Safety) - C:\Users\Winata\AppData\Roaming\Mozilla\Firefox\Pr ofiles\pM5L0zpg.default\Extensions\abs@avira.com [2016-06-19]
FF HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Winata\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Winata\AppData\Roaming\IDM\idmmzcc5 [2017-04-26] [not signed]
FF HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2016-08-03]
FF Plugin: @java.com/DTPlugin,version=11.111.2 → C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1 .dll [2016-11-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.111.2 → C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-24] (Oracle Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 → C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater → C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 → C:\Windows\SysWOW64\npDeployJava1.dll [2016-06-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 → C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-23] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 → C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-03-06] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 → C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-03-06] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision → C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-03-17] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming → C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-03-17] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 → C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 → C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 → C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader → C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-02] (Adobe Systems Inc.)
[HEADING=1]Chrome:[/HEADING]
CHR StartupUrls: Default → “hxxp://www.google.com/”
CHR Profile: C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default [2017-04-26]
CHR Extension: (Google Slides) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhon fmgoek [2016-06-18]
CHR Extension: (Google Docs) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfi lokake [2016-06-18]
CHR Extension: (Google Drive) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigk jlhalf [2016-06-18]
CHR Extension: (Eredan iTCG) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdakdeclmfcolipiknbfealnjd dfibfo [2016-06-18]
CHR Extension: (YouTube) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldk acnbeo [2016-06-18]
CHR Extension: (Realm of the Mad God) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjfmaldpppkmjjgkmadddbanp abfflp [2016-06-18]
CHR Extension: (Google Sheets) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpeb giejap [2016-06-18]
CHR Extension: (Google Docs Offline) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdl olhkhi [2016-06-18]
CHR Extension: (Marvel Comics) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjhfaknohpjconjoefidanhiho kmkice [2016-06-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccm gmieda [2017-03-09]
CHR Extension: (Gmail) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoe jaedia [2016-06-18]
CHR Extension: (Chrome Media Router) - C:\Users\Winata\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm [2017-04-25]
CHR HKLM...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-08-05]
CHR HKLM-x32...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-08-05]
[HEADING=1]Opera:[/HEADING]
OPR Extension: (No Name) - C:\Users\Winata\AppData\Roaming\Opera Software\Opera Stable\Extensions\ahggfmgiidlaceichjfemgbaggnbaloe [2017-04-19]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2014-07-23] ()
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe [954648 2015-05-08] (ASUSTeK Computer Inc.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlServi ce.exe [1360016 2014-07-23] () [File not signed]
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.06.28\AsusFanCo ntrolService.exe [398648 2015-07-06] (ASUSTeK Computer Inc.)
R2 AsusGameFirstService; C:\Program Files (x86)\ASUS\ROG Game First III\AsusGameFirstService.exe [356632 2015-06-10] (ASUSTeK)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1457160 2016-10-13] ()
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3736768 2017-04-09] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-13] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-13] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [48944 2017-04-17] (Dropbox, Inc.)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072 2016-06-22] (Disc Soft Ltd)
R3 Disc Soft Pro Bus Service; C:\Program Files\DAEMON Tools Pro\DiscSoftBusService.exe [1281368 2015-07-08] (Disc Soft Ltd)
R2 dnscrypt-proxy; E:\New DNSCript\dnscrypt-proxy.exe [258062 2013-09-15] () [File not signed]
S2 Ds3Service; C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpService.exe [389632 2016-01-10] (Scarlet.Crush Productions) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [33640 2017-04-07] (HP Inc.)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223520 2015-07-10] (Intel Corporation)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [455616 2016-09-30] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [455616 2016-09-30] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe [464440 2017-03-17] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-09-30] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2117128 2016-11-08] (Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2178576 2016-11-08] (Electronic Arts)
S3 ose; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [198192 2017-03-25] (Microsoft Corporation) [File not signed]
R2 STCServ; C:\Program Files\Intel\STCServ\STCServ.exe [8095456 2015-03-16] (Intel Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2016-04-19] (Microsoft Corporation)
S4 KMS-R@1n; C:\Windows\KMS-R@1n.exe
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2013-01-28] (ASUSTek Computer Inc.)
R3 AndroidAFD; C:\Windows\SysWow64\drivers\AndroidAFDx64.sys [28472 2015-07-06] (ASUSTek Computer Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-09-09] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2014-02-24] ()
R3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-07-20] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-07-20] (Disc Soft Ltd)
R3 dtproscsibus; C:\Windows\System32\DRIVERS\dtproscsibus.sys [30352 2016-06-18] (Disc Soft Ltd)
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [471496 2015-05-19] (Intel Corporation)
R0 FNETHYRAMAS; C:\Windows\System32\drivers\FNETHYRAMAS.SYS [45688 2016-06-18] (FNet Co., Ltd.)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [16648 2016-06-18] (FNet Co., Ltd.)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [31144 2015-06-22] (Intel Corporation)
S3 libusbK; C:\Windows\System32\DRIVERS\libusbK.sys [47200 2017-02-22] (hxxp://libusb-win32.sourceforge.net)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [178976 2015-07-07] (Intel Corporation)
R1 NFC_Driver; C:\Windows\System32\drivers\NFC_Driver.sys [48336 2015-06-11] (Titan ARC Corp.)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-09-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-09-02] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [59448 2017-03-17] (NVIDIA Corporation)
R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [12464 2016-09-25] (Macrovision Europe Ltd) [File not signed]
S3 dbx; system32\DRIVERS\dbx.sys
R4 IOMap; ??\C:\Windows\system32\drivers\IOMap64.sys
S3 VGPU; System32\drivers\rdvgkmd.sys
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-26 19:18 - 2017-04-26 19:18 - 00000000 ____D C:\Users\Winata\Downloads\FRST-OlderVersion
2017-04-25 20:02 - 2017-04-25 20:03 - 00093733 _____ C:\Users\Winata\Downloads\Addition.txt
2017-04-25 20:01 - 2017-04-26 19:18 - 00032797 _____ C:\Users\Winata\Downloads\FRST.txt
2017-04-25 20:01 - 2017-04-26 19:18 - 00000000 ____D C:\FRST
2017-04-25 18:34 - 2017-04-25 18:34 - 00002759 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2017-04-25 18:34 - 2017-04-25 18:34 - 00000000 ____D C:\ProgramData\Sophos
2017-04-25 18:34 - 2017-04-25 18:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2017-04-25 18:34 - 2017-04-25 18:34 - 00000000 ____D C:\Program Files (x86)\Sophos
2017-04-25 17:26 - 2017-04-26 19:18 - 02427392 _____ (Farbar) C:\Users\Winata\Downloads\FRST64.exe
2017-04-25 17:23 - 2017-04-25 17:50 - 165940904 _____ (Sophos Limited) C:\Users\Winata\Downloads\Sophos Virus Removal Tool.exe
2017-04-25 17:17 - 2017-04-25 17:17 - 04102600 _____ C:\Users\Winata\Downloads\adwcleaner_6.046.exe
2017-04-25 17:14 - 2017-04-25 17:19 - 00000000 ____D C:\AdwCleaner
2017-04-25 17:13 - 2017-04-25 17:13 - 00004021 _____ C:\Users\Winata\Desktop\JRT.txt
2017-04-25 17:11 - 2017-04-25 17:11 - 01663672 _____ (Malwarebytes) C:\Users\Winata\Downloads\JRT.exe
2017-04-25 17:10 - 2017-04-25 17:10 - 01530249 _____ (Smadsoft ) C:\Users\Winata\Downloads\smadav2017rev35.exe
2017-04-23 12:07 - 2017-04-23 12:07 - 00000000 ____D C:\Users\Winata\Documents\SkidRow
2017-04-23 11:25 - 2017-04-23 11:25 - 00000463 _____ C:\Users\Public\Desktop\The Sexy Brutale.lnk
2017-04-21 18:29 - 2017-04-21 18:29 - 00003466 _____ C:\Windows\System32\Tasks\One Drive Update
2017-04-21 13:15 - 2017-04-21 13:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-04-21 00:07 - 2017-04-21 00:07 - 00000000 ____D C:\Windows\pss
2017-04-20 12:55 - 2017-04-20 12:55 - 00000000 ____D C:\Users\Winata\AppData\Roaming\Google
2017-04-19 18:31 - 2017-04-19 18:31 - 00000000 ____D C:\Users\Public\Documents\Tools
2017-04-19 14:29 - 2017-04-21 18:29 - 00000000 ____D C:\Users\Winata\AppData\Local\wupdate
2017-04-19 14:29 - 2017-04-19 14:29 - 00003621 _____ C:\Users\Public\Desktop\R@1n.txt
2017-04-19 14:29 - 2017-04-19 14:29 - 00003438 _____ C:\Windows\System32\Tasks\wupdate
2017-04-19 14:29 - 2017-04-19 14:29 - 00000000 ____D C:\Windows\System32\Tasks\R@1n-KMS
2017-04-19 14:25 - 2017-04-19 14:25 - 02133044 _____ C:\Users\Winata\Downloads\re-loader-by-r1n.zip
2017-04-17 22:38 - 2017-04-17 22:38 - 00003000 _____ C:\Windows\System32\Tasks{D77F5F9C-2E81-4997-97FD-528C2E9A9F72}
2017-04-17 22:38 - 2017-04-17 22:38 - 00003000 _____ C:\Windows\System32\Tasks{71B68D39-21ED-480C-9223-222AD15D3EA1}
2017-04-17 22:14 - 2017-04-17 22:14 - 00048944 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2017-04-12 16:11 - 2017-04-12 16:18 - 00000000 ____D C:\Users\Winata\AppData\LocalLow\by redamz
2017-04-12 16:04 - 2017-04-12 16:04 - 00000000 ____D C:\Program Files (x86)\Monster Girl Island
2017-04-04 20:01 - 2017-04-04 20:01 - 00905969 _____ C:\Users\Winata\Downloads\PSX Download Helper1.8.zip
2017-04-04 20:01 - 2017-04-04 20:01 - 00000000 ____D C:\Users\Winata\AppData\Local\KOP-Elan
2017-04-04 20:01 - 2014-02-26 22:13 - 00000000 ____D C:\Users\Winata\Downloads\PSXDownloadHelper
2017-04-02 15:35 - 2017-04-02 15:35 - 00000000 ____D C:\Users\Winata\AppData\Roaming\Terrible Toybox
2017-04-02 15:30 - 2017-04-02 15:30 - 00000437 _____ C:\Users\Public\Desktop\Thimbleweed Park.lnk
2017-04-02 15:30 - 2017-04-02 15:30 - 00000437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thimbleweed Park.lnk
2017-03-28 11:56 - 2017-03-28 11:56 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-03-28 11:56 - 2017-03-17 05:56 - 00134592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2017-03-28 11:56 - 2017-01-26 07:13 - 00103936 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2017-03-28 11:56 - 2017-01-26 07:12 - 00326656 _____ C:\Windows\SysWOW64\vulkan-1.dll
2017-03-28 11:56 - 2017-01-26 07:09 - 00322560 _____ C:\Windows\system32\vulkan-1.dll
2017-03-28 11:56 - 2017-01-26 07:09 - 00118272 _____ C:\Windows\system32\vulkaninfo.exe
2017-03-28 11:54 - 2017-03-17 07:59 - 40190400 _____ C:\Windows\system32\nvcompiler.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 35272760 _____ C:\Windows\SysWOW64\nvcompiler.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 34952760 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 28223544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 19006832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 17282648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 14674712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 14434360 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2017-03-28 11:54 - 2017-03-17 07:59 - 13378096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 11122912 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 11019888 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 09306312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 08990256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 03627064 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 03187256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 01983424 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437892.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 01589696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437892.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 01053240 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00989120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00959424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00912440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00687408 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00609728 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00576192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00504104 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00500792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00425104 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00408272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00217528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2017-03-28 11:54 - 2017-03-17 07:59 - 00170360 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00153368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00059448 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2017-03-28 11:54 - 2017-03-17 07:59 - 00047664 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2017-03-28 11:54 - 2017-03-17 07:59 - 00000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2017-03-28 11:54 - 2017-03-17 07:59 - 00000669 _____ C:\Windows\system32\nv-vk64.json
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-26 19:09 - 2009-07-14 11:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-26 19:09 - 2009-07-14 11:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-26 19:07 - 2016-06-19 19:17 - 00000000 ____D C:\Users\Winata\AppData\Roaming\Spotify
2017-04-26 19:03 - 2016-06-19 19:17 - 00000000 ____D C:\Users\Winata\AppData\Local\Spotify
2017-04-26 19:02 - 2016-06-18 18:25 - 00000000 ____D C:\ProgramData\NVIDIA
2017-04-26 19:01 - 2016-08-13 17:26 - 00000904 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2017-04-26 19:01 - 2009-07-14 12:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-26 00:49 - 2016-08-13 17:26 - 00000908 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2017-04-25 23:11 - 2016-08-07 12:23 - 00000000 ____D C:\Users\Winata\AppData\Roaming\DMCache
2017-04-25 20:01 - 2016-06-24 21:20 - 00000000 ____D C:\Users\Winata\AppData\Roaming\vlc
2017-04-25 17:19 - 2017-03-19 20:22 - 00000542 _____ C:\Users\Public\Desktop\Hitman.lnk
2017-04-25 17:19 - 2017-01-13 12:27 - 00000998 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2017-04-25 17:19 - 2017-01-13 12:27 - 00000986 _____ C:\Users\Public\Desktop\Opera.lnk
2017-04-25 17:19 - 2016-08-30 23:12 - 00001022 _____ C:\Users\Winata\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Intеrnеt Ехрlоrеr.lnk
2017-04-25 17:19 - 2016-08-14 09:58 - 00000731 _____ C:\Users\Winata\Desktop\Child of Light.lnk
2017-04-25 17:19 - 2016-08-10 22:31 - 00000716 _____ C:\Users\Winata\Desktop\Tomb Raider.lnk
2017-04-25 17:19 - 2016-06-26 20:13 - 00000669 _____ C:\Users\Winata\Desktop\South Park - The Stick of Truth.lnk
2017-04-25 17:19 - 2016-06-26 20:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\South Park - The Stick of Truth
2017-04-25 01:14 - 2016-10-24 13:55 - 00000336 _____ C:\Windows\Tasks\HPCeeScheduleForWinata.job
2017-04-24 21:50 - 2016-08-27 22:57 - 00000000 ____D C:\Users\Winata\AppData\Local\Share Link
2017-04-24 20:55 - 2016-06-20 17:00 - 00000000 ____D C:\Users\Winata\AppData\Roaming\uTorrent
2017-04-24 16:44 - 2017-01-13 12:24 - 00000000 ____D C:\Program Files (x86)\Opera
2017-04-24 12:56 - 2016-10-24 13:55 - 00003192 _____ C:\Windows\System32\Tasks\HPCeeScheduleForWinata
2017-04-23 17:20 - 2016-06-19 21:34 - 00000000 ____D C:\Program Files (x86)\SMADAV
2017-04-23 13:26 - 2016-06-19 21:43 - 00000000 ____D C:\Users\Winata\AppData\Local\CrashDumps
2017-04-23 11:28 - 2016-06-19 21:23 - 00000000 ____D C:\Windows\SysWOW64\directx
2017-04-21 21:28 - 2009-07-14 10:20 - 00000000 ____D C:\Windows\system32\NDF
2017-04-21 13:15 - 2016-08-13 17:26 - 00000000 ____D C:\Program Files (x86)\Dropbox
2017-04-21 00:21 - 2016-08-30 23:12 - 00002072 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk
2017-04-20 14:08 - 2016-06-19 21:34 - 00000000 __SHD C:[Smad-Cage]
2017-04-19 16:46 - 2017-02-22 18:15 - 00000398 __RSH C:\ProgramData\ntuser.pol
2017-04-19 14:26 - 2016-06-22 14:56 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-04-19 14:25 - 2009-07-14 10:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2017-04-17 23:17 - 2009-07-14 12:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-17 23:17 - 2009-07-14 10:20 - 00000000 ____D C:\Windows\inf
2017-04-14 12:31 - 2016-06-20 16:55 - 00000000 ____D C:\Users\Winata\Documents\Alan
2017-04-12 16:04 - 2016-06-18 17:34 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-04-11 22:23 - 2016-06-18 17:56 - 00003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineU A
2017-04-11 22:23 - 2016-06-18 17:56 - 00003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineC ore
2017-04-05 12:06 - 2016-06-22 14:57 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-04-04 14:21 - 2009-07-14 12:08 - 00032546 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-03-29 13:31 - 2016-08-29 19:05 - 00000000 ____D C:\Users\Winata\AppData\Local\ElevatedDiagnostics
2017-03-28 14:11 - 2016-06-18 18:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-03-28 11:56 - 2016-06-18 18:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-03-28 11:56 - 2016-06-18 17:41 - 00000000 ____D C:\Temp
2017-03-28 11:55 - 2016-06-18 18:01 - 00000000 ____D C:\Program Files\NVIDIA Corporation
==================== Files in the root of some directories =======
2016-08-29 19:07 - 2016-08-29 19:07 - 0000057 _____ () C:\ProgramData\Ament.ini
[HEADING=1]Some files in TEMP:[/HEADING]
2016-06-19 21:46 - 2016-06-19 21:46 - 0000000 ____D () C:\Users\Winata\AppData\Local\Temp\avgnt.exe
2017-04-19 14:30 - 2017-04-19 14:30 - 0862832 ____N () C:\Users\Winata\AppData\Local\Temp\AVwzODkyix1j.ex e
2017-04-19 14:25 - 2017-04-19 14:25 - 3039448 ____N () C:\Users\Winata\AppData\Local\Temp\GZsvYrjw8Oe8.ex e
2016-09-24 02:04 - 2016-09-24 02:04 - 0737856 _____ (Oracle Corporation) C:\Users\Winata\AppData\Local\Temp\jre-8u111-windows-au.exe
2016-06-18 18:25 - 2016-07-11 05:36 - 0735152 _____ (NVIDIA Corporation) C:\Users\Winata\AppData\Local\Temp\nvSCPAPI.dll
2016-08-13 15:49 - 2016-10-19 02:31 - 0860960 _____ (NVIDIA Corporation) C:\Users\Winata\AppData\Local\Temp\nvSCPAPI64.dll
2016-08-13 15:48 - 2016-10-19 02:31 - 0353336 _____ (NVIDIA Corporation) C:\Users\Winata\AppData\Local\Temp\nvStInst.exe
2017-04-19 14:33 - 2017-04-19 14:33 - 64938720 ____N (Kometa LCC) C:\Users\Winata\AppData\Local\Temp\xz3wl44BNr7m.ex e
2006-05-24 16:10 - 2006-05-24 16:10 - 0455600 ____R (Macrovision Corporation) C:\Users\Winata\AppData\Local\Temp_is493B.exe
2006-05-24 16:10 - 2006-05-24 16:10 - 0455600 ____R (Macrovision Corporation) C:\Users\Winata\AppData\Local\Temp_is76F2.exe
2006-05-24 16:10 - 2006-05-24 16:10 - 0455600 ____R (Macrovision Corporation) C:\Users\Winata\AppData\Local\Temp_is8025.exe
2016-09-17 14:34 - 2016-09-17 14:34 - 0000000 _____ () C:\Users\Winata\AppData\Local\Temp{874CFD58-76FC-49C8-8D8E-F66F3CC9FC2C}-DropboxClient_10.4.25.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-04-23 20:42
==================== End of FRST.txt ============================
[HEADING=1]Addition Log
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-04-2017
Ran by Winata (26-04-2017 19:19:25)
Running from C:\Users\Winata\Downloads
Windows 7 Ultimate Service Pack 1 (X64) (2016-06-18 11:15:36)
Boot Mode: Normal[/HEADING]
==================== Accounts: =============================
Administrator (S-1-5-21-4254750808-1728920065-3872038573-500 - Administrator - Disabled)
Guest (S-1-5-21-4254750808-1728920065-3872038573-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4254750808-1728920065-3872038573-1002 - Limited - Enabled)
Winata (S-1-5-21-4254750808-1728920065-3872038573-1000 - Administrator - Enabled) => C:\Users\Winata
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with “Hidden” flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\uTorrent) (Version: 3.5.0.43580 - BitTorrent Inc.)
7-Zip 16.02 (x64) (HKLM...\7-Zip) (Version: 16.02 - Igor Pavlov)
Adobe Reader XI (11.0.11) MUI (HKLM-x32...{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
AI Suite 3 (HKLM-x32...{CD36E28B-6023-469A-91E7-049A2874EC13}) (Version: 1.01.24 - ASUSTeK Computer Inc.)
Alien Isolation (HKLM-x32...\Alien Isolation_R.G. Mechanics_is1) (Version: - R.G. Mechanics, spider91)
Ansel (Version: 378.92 - NVIDIA Corporation) Hidden
Asmedia USB Host Controller Driver (HKLM-x32...{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.24.0 - Asmedia Technology)
Assassin’s Creed Syndicate (HKLM-x32...\Assassin’s Creed Syndicate_is1) (Version: v.1.31 - Decepticon)
Assetto Corsa MULTi5 - ElAmigos version 1.9.3 (HKLM-x32...{6BC1D532-0B05-4A2C-A497-73BC245926E2}_is1) (Version: 1.9.3 - Kunos Simulazioni)
Assetto Corsa v1.8 Incl. Tripl3 Pack DLC (HKLM...\YXNzZXR0b2NvcnNh_is1) (Version: 1 - )
ASUS Product Register Program (HKLM-x32...{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.030 - ASUSTek Computer Inc.)
ASUS Share Link (HKLM-x32...{c3bcc1e3-f950-439c-bcae-f01283e9f2a4}_is1) (Version: 1.0.27.0911 - ASUSTEK)
Asus Sonic Suite Plugins (x32 Version: 2.1.2501 - ASUSTeKcomputer.Inc) Hidden
ASUSRAMCACHE (HKLM-x32...\ASUSRAMCACHE) (Version: 1.07.16 - FNet Co., Ltd.)
Batman Arkham Knight v.1.0.4.5 (HKLM-x32...\Batman Arkham Knight_is1) (Version: - )
Battlefield™ 1 (HKLM-x32...{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.9.53998 - Electronic Arts)
Bing Bar (HKLM-x32...{3611CA6C-5FCA-4900-A329-6A118123CCFC}) (Version: 7.1.355.0 - Microsoft Corporation)
Black Ops II (HKLM-x32...\Black Ops II 2.0) (Version: 2.0 - ShinyMK)
Black Ops II (x32 Version: 2.0 - ShinyMK) Hidden
Bloodstained: Ritual of the Night (HKLM...\Steam App 477970) (Version: - )
Cheat Engine 6.6 (HKLM-x32...\Cheat Engine 6.6_is1) (Version: - Cheat Engine)
Child of Light (HKLM-x32...\Child of Light_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter)
CPUID PRO GAMING CPU-Z 1.72.1 (HKLM...\CPUID PRO GAMING CPU-Z_is1) (Version: 1.72.1 - CPUID, Inc.)
DAEMON Tools Lite (HKLM...\DAEMON Tools Lite) (Version: 10.4.0.0192 - Disc Soft Ltd)
DAEMON Tools Pro (HKLM...\DAEMON Tools Pro) (Version: 6.1.0.0486 - Disc Soft Ltd)
Deus Ex: Mankind Divided (HKLM-x32...\Deus Ex: Mankind Divided_is1) (Version: - )
Discord (HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Discord) (Version: 0.0.297 - Hammer & Chisel, Inc.)
Divinity: Original Sin 2 (HKLM...\Steam App 435150) (Version: - Larian Studios)
Divinity: Original Sin Enhanced Edition (HKLM...\Steam App 373420) (Version: - Larian Studios)
DOOM (HKLM-x32...\DOOM_is1) (Version: - )
Dota 2 (HKLM...\Steam App 570) (Version: - Valve)
Dropbox (HKLM-x32...\Dropbox) (Version: 24.4.16 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden
EVE Online (HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...{75078ee2-d1fc-4537-9760-d87760c1809f}) (Version: 1.0.0 - CCP)
Evolve Stage 2 (HKLM...\Steam App 273350) (Version: - Turtle Rock Studios)
Far Cry 4 (HKLM-x32...\Far Cry 4_is1) (Version: - )
Fraps (HKLM-x32...\Fraps) (Version: - )
Google Chrome (HKLM-x32...\Google Chrome) (Version: 58.0.3029.81 - Google Inc.)
Google Update Helper (x32 Version: 1.3.33.3 - Google Inc.) Hidden
Hitman (HKLM-x32...\Hitman_is1) (Version: - )
Hitman Absolution - Professional Edition (HKLM-x32...\Hitman Absolution - Professional Edition_is1) (Version: - )
HP Deskjet 1050 J410 series Basic Device Software (HKLM...{F294770E-F869-400F-81C3-614B5F13CA54}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Deskjet 1050 J410 series Help (HKLM-x32...{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard)
HP Deskjet 1050 J410 series Product Improvement Study (HKLM...{D638A23C-5C5F-4B71-A354-EC78B2BDD320}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Support Assistant (HKLM-x32...{78E2C850-ADA6-420D-BA35-2F4A9BE733CC}) (Version: 8.4.14.41 - HP)
HP Support Solutions Framework (HKLM-x32...{CE7447C2-EF12-4EF3-BE51-BFC3B049C0F6}) (Version: 12.6.14.19 - HP)
HP Update (HKLM-x32...{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
I am Setsuna (HKLM-x32...\I am Setsuna_is1) (Version: - )
ILLUSION SchoolMate (HKLM-x32...{52ABC760-CAFC-4FCD-A0AA-5661366199D5}) (Version: 1.00.0000 - ILLUSION)
ILLUSION プレイクラブ (HKLM-x32...{EDA7A566-434A-4784-AE98-74AFA46A2485}) (Version: 1.00.0000 - ILLUSION)
INSIDE (HKLM-x32...\INSIDE_is1) (Version: - )
Intel(R) Chipset Device Software (x32 Version: 10.1.1.7 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM...{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1158 - Intel Corporation)
Intel(R) Network Connections 20.2.3001.0 (HKLM...\PROSetDX) (Version: 20.2.3001.0 - Intel)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32...{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.0.36 - Intel Corporation)
Intel® CCF Manager (HKLM-x32...{0f3d8dd5-54af-4404-a01c-4967e485a065}) (Version: 3.0.13.2211 - Intel Corporation)
Internet Download Manager (HKLM-x32...\Internet Download Manager) (Version: - Tonec Inc.)
Java 8 Update 111 (64-bit) (HKLM...{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation)
Java 8 Update 111 (HKLM-x32...{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation)
Mafia III - Digital Deluxe Edition - Version 1.0 (HKLM-x32...\Mafia III - Digital Deluxe Edition_is1) (Version: 1.0 - RePack by VickNet)
Media Streamer (HKLM-x32...{B457E718-00CA-45C8-9F75-45D66F8DAFF6}) (Version: 3.00.15 - ASUSTeK Computer Inc.)
Metro Last Light Redux (HKLM-x32...\Metro Last Light Redux_is1) (Version: v1.2 - Deep Silver)
MGI - Monster Girl Island Demo 1 (HKLM-x32...{CD8A4EC7-3923-4AC8-8CDC-C0DD77132379}) (Version: 1 - Monster Girl Island)
Microsoft .NET Framework 4.6.1 (HKLM...{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - en-us (HKLM...\ProplusRetail - en-us) (Version: 16.0.7870.2038 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\OneDriveSetup.exe) (Version: 17.3.6281.1202 - Microsoft Corporation)
Microsoft Project Professional 2016 - en-us (HKLM...\ProjectProRetail - en-us) (Version: 16.0.7870.2038 - Microsoft Corporation)
Microsoft Visio Professional 2016 - en-us (HKLM...\VisioProRetail - en-us) (Version: 16.0.7870.2038 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM...{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM...{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32...{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM...{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32...{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32...{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32...{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32...{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32...{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32...{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32...{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32...{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32...{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM...{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Middle-earth - Shadow of Mordor (HKLM-x32...\Middle-earth - Shadow of Mordor_is1) (Version: v1.2 - WB Games)
MOBIUS FINAL FANTASY (HKLM...\Steam App 536930) (Version: - SQUARE ENIX CO., LTD.)
NahimicSettingsConfigurator (Version: 2.1.2501 - ASUSTeKcomputer.Inc) Hidden
NVIDIA 3D Vision Controller Driver 369.04 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 378.92 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 378.92 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.0.7.34 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.0.7.34 - NVIDIA Corporation)
NVIDIA Graphics Driver 378.92 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.92 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.23 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.23 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
NvNodejs (Version: 3.0.7.34 - NVIDIA Corporation) Hidden
NvTelemetry (Version: 1.0.0.0 - NVIDIA Corporation) Hidden
NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
O2Jam INT (HKLM-x32...{92E268B8-4E5D-4E9D-B82B-C39B65B5DB44}) (Version: 2.0.0 - IntGamerz)
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7870.2024 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7830.1018 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7870.2024 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7668.2066 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32...\OpenAL) (Version: - )
Opera Stable 43.0.2442.1144 (HKLM-x32...\Opera 43.0.2442.1144) (Version: 43.0.2442.1144 - Opera Software)
Origin (HKLM-x32...\Origin) (Version: 10.2.2.60207 - Electronic Arts, Inc.)
osu! (HKLM-x32...{22cccaf8-5e6d-4f85-bdaa-f3606c6532c3}) (Version: latest - ppy Pty Ltd)
RapeLay (HKLM-x32...{CA31F991-DBD2-4DE1-B6D2-30105F23CBBC}) (Version: 1.03 - ILLUSION)
Realtek High Definition Audio Driver (HKLM-x32...{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7543 - Realtek Semiconductor Corp.)
Resident Evil 7: Biohazard (HKLM-x32...\Resident Evil 7: Biohazard_is1) (Version: - )
ROG Game First III (HKLM-x32...{0C6E32E1-31D9-49F1-B67F-2941994002D5}) (Version: 1.00.31 - ASUSTeK Computer Inc.)
ScpToolkit (HKLM...{AC052048-9828-45E3-872B-04CE30A3B58B}) (Version: 1.6.238.16010 - Nefarius Software Solutions)
Sexy Beach Premium Resort (HKLM-x32...\Sexy Beach Premium Resort_is1) (Version: - )
Shadow Warrior - Special Edition (HKLM-x32...\Shadow Warrior - Special Edition_is1) (Version: - )
SHIELD Streaming (Version: 7.1.0320 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 3.0.7.34 - NVIDIA Corporation) Hidden
Sid Meier’s Civilization 6 (HKLM-x32...\Sid Meier’s Civilization 6_is1) (Version: - )
SMADAV version 10.7.1 (HKLM-x32...{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1) (Version: 10.7.1 - SmadSoft)
Sonic Radar II (HKLM...{A70B8D38-273A-4D6A-B7D5-AEBEDEEE5D28}) (Version: 2.1.2501 - ASUSTeKcomputer.Inc)
Sonic Studio Plugin (Version: 2.1.2501 - ASUSTeKcomputer.Inc) Hidden
Sonicomi (HKLM-x32...\Sonicomi1.0) (Version: 1.0 - JAST USA)
Sophos Virus Removal Tool (HKLM-x32...{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.6 - Sophos Limited)
South Park - The Stick of Truth version 1.0 build 1383 + 2 DLC (HKLM-x32...\South Park - The Stick of Truth_is1) (Version: 1.0 build 1383 + 2 DLC - )
Spotify (HKU\S-1-5-21-4254750808-1728920065-3872038573-1000...\Spotify) (Version: 1.0.53.758.gde3fc4b2 - Spotify AB)
STCServ (Version: 3.0.0.1783 - Intel Corporation) Hidden
Steam (HKLM-x32...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Tales of Berseria (HKLM-x32...\Tales of Berseria_is1) (Version: - )
The Legend of Heroes Trails in the Sky (HKLM-x32...{2BB748CC-69E7-41F7-8609-CBB1EE5DD0C0}_is1) (Version: - Xseed)
The Legend of Zelda: Breath of the Wild (HKLM-x32...\The Legend of Zelda: Breath of the Wild_is1) (Version: - )
The Sexy Brutale (HKLM-x32...\The Sexy Brutale_is1) (Version: - )
Thimbleweed Park (HKLM...\dGhpbWJsZXdlZWRwYXJr_is1) (Version: 1 - )
Tom Clancy’s Rainbow Six Siege (HKLM...\Steam App 359550) (Version: - Ubisoft Montreal)
Tomb Raider (HKLM-x32...\Tomb Raider_R.G. Mechanics_is1) (Version: - R.G. Mechanics, spider91)
Tyranny - Pre-Order (HKLM-x32...\1128126797_is1) (Version: 2.0.0.1 - GOG.com)
Tyranny (HKLM-x32...\1266051739_is1) (Version: 2.0.0.1 - GOG.com)
Uplay (HKLM-x32...\Uplay) (Version: 22.2 - Ubisoft)
VA-11 Hall-A - Cyberpunk Bartender Action (HKLM-x32...\2074961301_is1) (Version: 2.0.0.2 - GOG.com)
Virginia (HKLM-x32...\Virginia_is1) (Version: - )
VLC media player (HKLM-x32...\VLC media player) (Version: 2.2.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.39.1 (HKLM...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.)
WebStorage (HKLM-x32...\WebStorage) (Version: 2.1.15.458 - ASUS Cloud Corporation)
Windows XP Mode (HKLM...{1374CC63-B520-4f3f-98E8-E9020BF01CFF}) (Version: 1.3.7600.16423 - Microsoft Corporation)
WinZip 19.5 (HKLM...{CD95F661-A5C4-44F5-A6AA-ECDD91C240EB}) (Version: 19.5.11475 - WinZip Computing, S.L. )
Wolfenstein - The New Order (HKLM-x32...\Wolfenstein - The New Order_R.G. Mechanics_is1) (Version: - R.G. Mechanics, spider91)
Zero Escape: Zero Time Dilemma (HKLM-x32...\Zero Escape: Zero Time Dilemma_is1) (Version: - )
輪姦倶楽部DL版 (HKLM-x32...{6F26BCA6-5244-40AE-B0C2-2EA2C664B4FA}) (Version: 1.00.0000 - Infini Brain Inc.)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-4254750808-1728920065-3872038573-1000_Classes\CLSID{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 → C:\Users\Winata\AppData\Local\Microsoft\OneDrive\1 7.3.6281.1202\amd64\FileCoAuthLib64.dll ()
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {05DDC327-81A9-4BE3-931A-E0F2767D5B51} - System32\Tasks{4FCA9E6C-23C8-46DB-9FBE-4F0E11FC0A1B} => D:\SIM\sim.exe [2016-11-22] (Monsoonlab)
Task: {093A1C6D-DAE8-487A-B994-A946F21F861E} - System32\Tasks\R@1n-KMS\Office16ProPlus => wmic
Task: {1F347E34-0C9E-416A-ACA7-7965D62D4A09} - System32\Tasks{DD1347B8-D84A-494B-B6D7-DC0E4AEA9358} => K:\HYOUIUST.EXE
Task: {1F5DCAC2-7069-4397-AA16-258AB07BC4CA} - System32\Tasks\ASUS\GpuFanHelper => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\GpuFanHelper.exe [2015-07-02] (TODO: )
Task: {2455A076-A05C-45FA-B2BA-ED953E4806AF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-04-01] (HP Inc.)
Task: {24C60722-922B-4C06-BC6C-90650A296594} - System32\Tasks{99949CCE-432A-4C0C-A1D5-77A51E27AAAD} => pcalua.exe -a H:\Hyouiust.exe -d H:
Task: {2571A339-A90B-43EB-8AAC-79EC86939D5C} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-08-13] (Dropbox, Inc.)
Task: {276C638D-7737-4AA9-A376-AD02AAEDDB97} - System32\Tasks\smadav => C:\Program Files (x86)\Smadav\SMΔRTP.exe [2016-06-02] (Smadsoft)
Task: {28F6A0D8-BFD4-4AB2-8C27-BF9E3E08E082} - System32\Tasks{6DBD2FA0-EFA5-4385-A2AC-C30528B27544} => L:\setup.exe
Task: {317D0388-1DED-496A-9309-9B07BF18B338} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {38EB0B64-B6D9-4DC6-BACC-4AA567590F38} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2016-09-30] (NVIDIA Corporation)
Task: {393AF510-D7D2-40D0-B7D9-3B6DFFAB0D97} - System32\Tasks\ASUS\ASUS DIPAwayMode => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe [2015-07-06] ()
Task: {42B52220-F385-4B31-A514-431965FE194F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {45D7B53D-2436-4E91-AEB3-F1E1F5747BAA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-18] (Google Inc.)
Task: {518636E2-14B9-49AE-9DA2-5CBF85F02F0A} - System32\Tasks\HPCeeScheduleForWinata => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2016-01-22] (Hewlett-Packard)
Task: {520DBF5B-4EBA-48DC-AE18-27FD80AEB4F3} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-04-09] (Microsoft Corporation)
Task: {5470E47F-97E1-4873-A3BF-50285C07001F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {59E886DC-97AC-4633-814D-998CDB7ED1CC} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2016-09-30] (NVIDIA Corporation)
Task: {641FC6A1-60CC-4027-82B1-55D00FF7E814} - System32\Tasks\Microsoft\Office\OfficeTelemetryAge ntLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-04-10] (Microsoft Corporation)
Task: {67AAB573-2B01-478A-BCF1-8D15E4DE61CE} - System32\Tasks\ASUS\Push Notice Server Execute => C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe [2014-05-28] (ASUSTeK Computer Inc.)
Task: {6C46E986-D9B3-4728-9E1D-39C22F77CB0B} - System32\Tasks\ASUS\ASUS AISuiteIII => C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe [2015-06-30] (ASUSTeK Computer Inc.)
Task: {6D665217-1F06-440C-AB76-50507CD8BB8A} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-08-13] (Dropbox, Inc.)
Task: {7153E778-5276-4B9C-B8CB-E5713D9A00DC} - System32\Tasks\IntelBootstrapCCDashExe => C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe [2015-03-16] (Intel® Corporation)
Task: {7855431E-BECD-4E6D-9E27-240BD653A9E8} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-09-30] (NVIDIA Corporation)
Task: {7E8A906A-5F66-4730-B37F-43320FB11CA5} - System32\Tasks\Opera scheduled Autoupdate 1484285237 => C:\Program Files (x86)\Opera\launcher.exe [2017-02-27] (Opera Software)
Task: {8245F84A-BE60-4B87-9212-5A22A9A8493C} - System32\Tasks{8AC69228-D3FF-40EF-AD61-1179B67D4DB7} => K:\HYOUIUST.EXE
Task: {87CC43B6-B6D5-419A-BC59-B0E7F298DDCC} - System32\Tasks{D77F5F9C-2E81-4997-97FD-528C2E9A9F72} => C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE [2017-04-10] (Microsoft Corporation)
Task: {8D611B13-AB6F-46E6-8469-A0CC74428169} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChec ker.exe [2017-04-06] (HP Inc.)
Task: {8E124BDC-E1E7-4761-8B65-41A40AC9D514} - System32\Tasks\ASUS\USB 3.0 Boost Service => C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvr.exe [2013-07-24] (ASUSTeK Computer Inc.)
Task: {8EAF54AB-B69E-4A0E-AA50-3FC4F6605FA3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-12-21] (HP Inc.)
Task: {9380F438-06D6-43F2-9117-6BEC9529AF21} - System32\Tasks\R@1n-KMS\Office16VisioPro => wmic
Task: {966CE29C-528E-4976-BC9F-DF53924A04B0} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.ex e [2016-11-07] (HP Inc.)
Task: {A3FD864C-C9D6-4D1C-9311-4DDAD17A2BEB} - System32\Tasks\HPCustParticipation HP Deskjet 1050 J410 series => C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.)
Task: {A91067F3-CC2F-40F1-A14B-36439F5C77E3} - System32\Tasks\updater => C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpUpdater.exe [2016-01-10] (Nefarius Software Solutions)
Task: {AE82A179-1311-4557-AEE4-7F9D3CE31FDC} - System32\Tasks\ASUS\ASUS Media Streamer DMR => C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMR\AODMR.exe [2015-05-12] ()
Task: {B10B1B49-E8AE-43D6-B97E-DDD9605E0F56} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-04-09] (Microsoft Corporation)
Task: {BA7B47AF-E62A-45CA-8BD9-F377C4AF218B} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-09-30] (NVIDIA Corporation)
Task: {BAD25838-E5A6-4019-B957-846CCAEA5CA0} - System32\Tasks{5452A836-2F26-4CEC-B408-D0952495B6D4} => D:\SIM\sim.exe [2016-11-22] (Monsoonlab)
Task: {BB19AA40-0272-4A12-BCAF-4E65BE937308} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-09-30] (NVIDIA Corporation)
Task: {C5C4482C-41CA-4FAC-863B-0A2B00422797} - System32\Tasks{C71C2131-5E26-4E6D-A4F6-68D5A864493B} => K:\HYOUIUST.EXE
Task: {C884A167-1EED-459C-A4C2-493E08CC11B6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-18] (Google Inc.)
Task: {D38422FB-DE43-4F9D-B5D0-6C2E62DB65A2} - System32\Tasks{71B68D39-21ED-480C-9223-222AD15D3EA1} => C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE [2017-04-10] (Microsoft Corporation)
Task: {D72F2C08-C3E6-4037-A052-FDFFC26ABFD5} - System32\Tasks\R@1n-KMS\Office16ProjectPro => wmic
Task: {DBC96CC5-2FF1-4198-9746-62522314EFD4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAge ntFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-04-10] (Microsoft Corporation)
Task: {E1779794-65F9-48AD-9F95-FE029D59B440} - System32\Tasks\ASUS\Ez Update => C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe [2015-02-06] ()
Task: {E26CFFC1-DDD0-4DA5-BA70-F3A5955FF745} - System32\Tasks{FA9E6D33-6C43-43EC-800C-8CFD0CAF059D} => pcalua.exe -a L:\SETUP.EXE -d L:
Task: {E3585554-FA28-4991-878F-7BC6FD6CF4E6} - System32\Tasks\One Drive Update => C:\Windows\explorer.exe hxxp://dluxuwu.ru
Task: {F246CD7C-3260-4BAA-AE15-F685C9140D8A} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-09-30] (NVIDIA Corporation)
Task: {F6DA0069-975F-4FF1-A28C-6D60E3E5C038} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2015-05-14] ()
Task: {F94CED33-5F83-43DA-BF77-EC01C6CE778B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {FE6DD934-5232-42E3-9504-35525265A645} - System32\Tasks\wupdate => C:\Users\Winata\AppData\Local\wupdate\wupdate.exe [2017-04-21] () <==== ATTENTION
Task: {FFA1BB75-9E9A-4D9E-9697-3E573D9AEA91} - System32\Tasks{A0A94C32-F9FE-4DE8-B055-BD5BD390146B} => K:\HYOUIUST.EXE
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForWinata.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\Winata\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk → C:\Windows\explorer.exe (Microsoft Corporation) <===== Cyrillic
Shortcut: C:\Users\Winata\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Intеrnеt Ехрlоrеr.lnk → C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) <===== Cyrillic
Shortcut: C:\Users\Winata\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Accessories\System Tools\Intеrnеt Ехрlоrеr (Nо Аdd-оns).lnk → C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) <===== Cyrillic
Shortcut: C:\Users\Winata\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gооglе Сhrоmе.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) <===== Cyrillic
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) <===== Cyrillic
==================== Loaded Modules (Whitelisted) ==============
2014-07-23 08:59 - 2014-07-23 08:59 - 00936728 ____R () C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
2016-06-18 18:31 - 2015-07-06 15:42 - 01275672 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
2016-06-18 18:41 - 2015-05-12 21:49 - 00304952 _____ () C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMR\AODMR.exe
2016-06-18 18:30 - 2015-02-06 14:53 - 01462584 _____ () C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe
2016-06-18 17:34 - 2014-07-23 08:59 - 01360016 ____R () C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlServi ce.exe
2016-06-18 18:31 - 2015-05-14 09:18 - 01075712 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNoticeMonitor.exe
2016-06-18 18:31 - 2014-08-28 10:37 - 00033424 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotify_PCCtrl.exe
2014-11-01 17:10 - 2013-09-15 23:00 - 00258062 _____ () E:\New DNSCript\dnscrypt-proxy.exe
2016-06-18 17:35 - 2014-05-22 15:24 - 00096568 _____ () C:\Windows\system32\audioLibVc.dll
2016-09-15 22:33 - 2016-09-30 11:24 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2016-09-15 22:33 - 2016-09-30 11:24 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll
2016-09-15 22:34 - 2016-09-30 11:24 - 00418240 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem_nvspse rviceplugin64.dll
2016-06-18 18:24 - 2017-03-17 06:16 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2012-03-08 09:27 - 2012-03-08 09:27 - 00016384 _____ () C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\ACVsWin.dll
2016-06-18 18:41 - 2015-07-07 17:07 - 01194808 _____ () C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\ShareEdit.exe
2016-06-18 18:41 - 2015-07-07 17:07 - 02569528 _____ () C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AODMS.exe
2016-06-18 18:41 - 2015-06-03 19:46 - 00086840 _____ () C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\ASUSWSAgent.exe
2016-06-18 18:29 - 2015-06-30 14:54 - 01263384 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\AsPowerBar.exe
2017-04-20 12:46 - 2017-04-19 12:03 - 03767640 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\libgl esv2.dll
2017-04-20 12:46 - 2017-04-19 12:03 - 00100696 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\libeg l.dll
2016-06-18 17:34 - 2017-04-26 19:01 - 00036136 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\PEbiosinterface32.dll
2016-06-18 17:34 - 2014-07-23 08:59 - 00104448 ____R () C:\Program Files (x86)\ASUS\AXSP\1.02.00\ATKEX.dll
2016-06-18 18:31 - 2015-07-02 10:40 - 00236544 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4cTDPAction.dll
2016-06-18 18:31 - 2015-07-02 10:40 - 00712192 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAc tion.dll
2016-06-18 18:31 - 2015-07-06 15:42 - 00863744 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4EpuAction.dll
2016-06-18 18:31 - 2015-07-02 10:40 - 00803840 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4FanAction.dll
2016-06-18 18:31 - 2015-07-06 15:42 - 00815104 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4TurboVEVOAction.dl l
2016-06-18 18:31 - 2015-07-02 10:40 - 00507392 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\AsKeyboardFocusHooker.dll
2016-06-18 18:29 - 2015-06-03 16:17 - 00091648 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Log4cxxWrapper.dll
2016-06-18 18:29 - 2015-06-03 16:17 - 00147456 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AssistFunc.dll
2016-06-18 18:30 - 2015-02-09 17:53 - 00872960 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AI Charger+\AIChargerPlus.dll
2016-06-18 18:31 - 2015-07-06 15:58 - 04697088 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\dip4.dll
2016-06-18 18:31 - 2015-07-02 10:40 - 00091648 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\Log4cxxWrapper.dll
2016-06-18 18:30 - 2015-05-21 22:57 - 01141248 _____ () C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EasyUpdt.dll
2016-06-18 18:30 - 2015-06-26 13:50 - 00906240 _____ () C:\Program Files (x86)\ASUS\AI Suite III\LED Control\LEDControl.dll
2016-06-18 18:31 - 2015-07-13 11:16 - 01341440 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Mobo Connect\MoboConnect.dll
2016-06-18 18:29 - 2015-06-28 16:37 - 00829440 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Version\Version.dll
2016-06-18 18:31 - 2015-07-02 09:40 - 00053248 ____R () C:\Program Files (x86)\ASUS\VGA COM\1.00.20\Exeio.dll
2016-06-18 18:31 - 2015-07-02 09:40 - 00278528 ____R () C:\Program Files (x86)\ASUS\VGA COM\1.00.20\Vender.dll
2016-06-18 18:29 - 2015-05-08 13:26 - 00662016 ____R () C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMLib.dll
2016-06-18 18:30 - 2014-10-09 09:31 - 00237568 _____ () C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzULIB.dll
2016-06-18 18:30 - 2014-02-24 17:49 - 00208896 _____ () C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\ImageHelper.dll
2016-09-15 22:33 - 2016-09-30 00:20 - 00500792 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node
2016-09-15 22:33 - 2016-09-30 00:20 - 00255936 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node
2016-09-15 22:33 - 2016-09-30 00:20 - 02801208 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node
2016-09-15 22:33 - 2016-09-30 00:20 - 00244672 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node
2016-09-15 22:33 - 2016-09-30 00:20 - 00430648 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node
2016-09-15 22:33 - 2016-09-30 00:20 - 00336832 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node
2016-09-15 22:33 - 2016-09-30 00:20 - 00373696 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvCameraAPINode.node
2016-06-18 18:31 - 2013-11-20 10:10 - 00662016 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\aaHMLib.dll
2016-06-18 18:31 - 2013-07-02 10:40 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\pngio.dll
2014-11-01 17:10 - 2013-09-15 23:03 - 00540302 _____ () E:\New DNSCript\libsodium-4.dll
2016-06-19 19:17 - 2017-04-20 19:02 - 67725936 _____ () C:\Users\Winata\AppData\Roaming\Spotify\libcef.dll
2017-01-12 12:30 - 2017-01-04 14:28 - 01958912 _____ () C:\Users\Winata\AppData\Local\Discord\app-0.0.297\ffmpeg.dll
2017-01-12 12:30 - 2017-01-12 12:30 - 01082880 _____ () \?\C:\Users\Winata\AppData\Roaming\discord\0.0.297 \modules\discord_voice\discord_voice.node
2017-01-12 12:30 - 2017-01-12 12:30 - 03750400 _____ () \?\C:\Users\Winata\AppData\Roaming\discord\0.0.297 \modules\discord_voice\libdiscord.dll
2017-01-12 12:30 - 2017-01-12 12:30 - 00914432 _____ () \?\C:\Users\Winata\AppData\Roaming\discord\0.0.297 \modules\discord_utils\discord_utils.node
2017-01-12 12:30 - 2017-01-04 14:28 - 02278912 _____ () C:\Users\Winata\AppData\Local\Discord\app-0.0.297\libglesv2.dll
2017-01-12 12:30 - 2017-01-04 14:28 - 00096768 _____ () C:\Users\Winata\AppData\Local\Discord\app-0.0.297\libegl.dll
2016-06-18 18:41 - 2015-05-12 21:49 - 00253952 _____ () C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\pngio.dll
2017-04-21 13:14 - 2017-04-17 22:09 - 00870720 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2016-08-13 17:29 - 2017-03-29 06:54 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client_multiprocessing.pyd
2016-08-13 17:29 - 2017-03-29 06:54 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client_ctypes.pyd
2016-08-13 17:29 - 2017-03-29 06:54 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2016-08-13 17:29 - 2017-04-17 22:13 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00020824 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings. _constant_time.pyd
2016-08-13 17:29 - 2017-03-29 06:54 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client_cffi_backend.pyd
2016-08-13 17:29 - 2017-03-29 06:54 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 01729360 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings. _openssl.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings. _padding.pyd
2017-04-21 13:14 - 2017-03-29 06:54 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2017-04-21 13:14 - 2017-03-29 06:54 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2017-04-21 13:14 - 2017-03-29 06:54 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2016-08-13 17:29 - 2017-03-29 06:56 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2016-08-13 17:29 - 2017-04-17 22:13 - 00022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_c rt.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00060736 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00038712 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2017-04-21 13:14 - 2017-03-29 06:54 - 00392656 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2017-04-21 13:14 - 2017-03-29 06:56 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2016-08-13 17:29 - 2017-04-17 22:13 - 00392512 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2016-08-13 17:29 - 2017-04-17 22:14 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._win ffi_kernel32.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00246608 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handl er.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00027488 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled ._driverinstallation.pyd
2016-08-13 17:29 - 2017-03-29 06:55 - 00241104 _____ () C:\Program Files (x86)\Dropbox\Client_jpegtran.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00022336 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2016-08-13 17:29 - 2017-04-17 22:14 - 00025432 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._Captu reScreenshot.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 01826104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2016-08-13 17:29 - 2017-03-29 06:54 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 01972024 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 03928896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00171336 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00042816 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00531264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00133432 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00224064 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00207680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2017-02-28 11:52 - 2017-04-17 22:14 - 00054608 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCSer ver.pyd
2017-01-24 13:52 - 2017-04-17 22:14 - 00022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winff i_user32.pyd
2017-01-24 13:52 - 2017-04-17 22:13 - 00022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._win ffi_iphlpapi.pyd
2017-01-24 13:52 - 2017-04-17 22:14 - 00021848 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._win ffi_winerror.pyd
2017-01-24 13:52 - 2017-04-17 22:14 - 00022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winf fi_wininet.pyd
2016-08-13 17:29 - 2017-03-29 06:56 - 00349128 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2016-08-13 17:29 - 2017-04-17 22:14 - 00023896 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._ VerifySignature.pyd
2017-04-21 13:14 - 2017-04-17 22:13 - 00025936 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyn cffi.pyd
2017-04-21 13:14 - 2017-03-29 06:52 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2017-04-21 13:14 - 2017-04-17 22:13 - 00084288 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2016-08-13 17:29 - 2017-04-17 22:13 - 00030536 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.p yd
2017-04-21 13:14 - 2017-03-29 07:00 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
2017-04-21 13:14 - 2017-03-29 07:00 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2017-04-21 13:14 - 2017-04-17 22:13 - 00357688 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2016-08-13 17:29 - 2017-04-17 22:14 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winf fi_winhttp.pyd
2016-06-19 19:17 - 2017-04-20 19:02 - 01929840 _____ () C:\Users\Winata\AppData\Roaming\Spotify\libglesv2. dll
2016-06-19 19:17 - 2017-04-20 19:02 - 00087152 _____ () C:\Users\Winata\AppData\Roaming\Spotify\libegl.dll
2016-09-15 22:33 - 2016-09-30 11:24 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2017-04-26 19:04 - 2017-04-26 19:04 - 00148992 _____ () \?\C:\Users\Winata\AppData\Local\Temp\AC45.tmp.nod e
2017-01-12 12:30 - 2017-01-12 12:30 - 02658304 _____ () \?\C:\Users\Winata\AppData\Roaming\discord\0.0.297 \modules\discord_rpc\discord_rpc.node
2017-01-12 12:30 - 2017-03-23 13:31 - 02665976 _____ () \?\C:\Users\Winata\AppData\Roaming\discord\0.0.297 \modules\discord_contact_import\discord_contact_im port.node
2015-07-10 23:37 - 2015-07-10 23:37 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-06-18 18:31 - 2015-07-02 10:40 - 00743424 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\EPU.dll
2016-06-18 18:31 - 2015-07-02 10:40 - 00383488 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\SystemCleaner.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The “AlternateShell” will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 09:34 - 2009-06-11 04:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4254750808-1728920065-3872038573-1000\Control Panel\Desktop\Wallpaper → C:\Users\Winata\AppData\Roaming\Microsoft\Windows\ Themes\TranscodedWallpaper.jpg
DNS Servers: 127.0.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Pol icies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{FBBDD327-3B22-4E37-B321-31E937A8EAD6}] => (Allow) C:\Windows\system32\ftp.exe
FirewallRules: [{184B5062-16C4-47AD-AF28-6AAAE3B82E1F}] => (Allow) C:\Windows\system32\ftp.exe
FirewallRules: [{2E4DB191-621F-4373-8E03-8B225559D938}] => (Allow) C:\Windows\SysWOW64\ftp.exe
FirewallRules: [{725403B0-249E-4BF0-9043-FFB95AB2FC62}] => (Allow) C:\Windows\SysWOW64\ftp.exe
FirewallRules: [{7EC90042-2CE7-4EE1-BB42-9DDCFB497573}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMR\AODMR.exe
FirewallRules: [{815493E6-A394-41D4-8E73-EF8F60D4AB48}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMR\AODMR.exe
FirewallRules: [{9DBA0C8D-7627-46C1-BF0F-E9B6FED5C448}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AODMS.exe
FirewallRules: [{8818F50F-D22E-47E0-B283-D0BECE716ED2}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AODMS.exe
FirewallRules: [{5597EACB-000D-4045-A601-2B4D7A303C7B}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AORelayDMS.exe
FirewallRules: [{5904A52E-DC3C-42D3-B994-379341FFD920}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\DLNA\DMS\AORelayDMS.exe
FirewallRules: [{33A808EB-C044-4B4D-B055-00416B6646FC}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\AMSRelayHelpAgent.exe
FirewallRules: [{83BCA34A-E763-4068-BBC6-B9562C041B03}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\ASUS Media Streamer\AMSRelayHelpAgent.exe
FirewallRules: [{473A45CF-396F-4997-83C7-43024A784834}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\MediaStreamer.exe
FirewallRules: [{B6129B49-C2CD-446B-A76C-B00A38F217DA}] => (Allow) C:\Program Files (x86)\ASUS\HomeCloud\Media Streamer\MediaStreamer.exe
FirewallRules: [{1B047C1A-3B33-4BA5-A593-4DFDFCD59D1F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{50D027C2-5E2D-47BD-96AC-CC2AE16B8989}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{09FCE54F-D620-4A02-9A49-E457F560CE9B}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{BEDF6233-20C0-4447-B941-CB8937379D77}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{ED70EE5C-8189-482F-8127-A8ADF33FBBD8}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{F4D843B9-8478-4B8F-A90F-28F496D9484F}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{6BE44876-0C65-41EB-9491-89F98D4DCA7D}] => (Allow) D:\Steam\steamapps\common\Divinity Original Sin Enhanced Edition\Shipping\EoCApp.exe
FirewallRules: [{BFEE8AE8-59DC-4857-BC5F-3FCAD6BDBEFF}] => (Allow) D:\Steam\steamapps\common\Divinity Original Sin Enhanced Edition\Shipping\EoCApp.exe
FirewallRules: [{46AB0E80-A6DE-4F27-93C5-CF92CA605715}] => (Allow) D:\Steam\steamapps\common\Tom Clancy’s Rainbow Six Siege\RainbowSix.exe
FirewallRules: [{8342EA24-82AF-465A-89C6-FA5B082047BF}] => (Allow) D:\Steam\steamapps\common\Tom Clancy’s Rainbow Six Siege\RainbowSix.exe
FirewallRules: [TCP Query User{B3B3C77C-B2C0-4F9B-B3AF-C29AB081FBCC}D:\far cry 4\bin\farcry4.exe] => (Allow) D:\far cry 4\bin\farcry4.exe
FirewallRules: [UDP Query User{CEBC6A32-41C8-407F-B9CA-4EBCADCF91BA}D:\far cry 4\bin\farcry4.exe] => (Allow) D:\far cry 4\bin\farcry4.exe
FirewallRules: [TCP Query User{2B6351C4-5200-4286-80D8-7D3BDC8110EC}C:\users\winata\appdata\roaming\spoti fy\spotify.exe] => (Allow) C:\users\winata\appdata\roaming\spotify\spotify.ex e
FirewallRules: [UDP Query User{51B643C9-3252-4AC1-8732-419D10B78855}C:\users\winata\appdata\roaming\spoti fy\spotify.exe] => (Allow) C:\users\winata\appdata\roaming\spotify\spotify.ex e
FirewallRules: [{26323787-876B-4518-ACEF-5DBD01F2D743}] => (Allow) C:\Users\Winata\AppData\Roaming\uTorrent\uTorrent. exe
FirewallRules: [{FEFF45C0-D96E-4CB5-8561-3F7FFCBF51F5}] => (Allow) C:\Users\Winata\AppData\Roaming\uTorrent\uTorrent. exe
FirewallRules: [{B704F94C-378C-449B-B445-EC440817D7AA}] => (Allow) C:\Users\Winata\AppData\Roaming\uTorrent\uTorrent. exe
FirewallRules: [{7927C215-2428-4C8D-941F-07E662D6C014}] => (Allow) C:\Users\Winata\AppData\Roaming\uTorrent\uTorrent. exe
FirewallRules: [{D8ABB999-DA61-45D1-896C-CEA4938A1CC2}] => (Allow) C:\Users\Winata\AppData\Roaming\uTorrent\uTorrent. exe
FirewallRules: [{BDEC7113-14E7-4B18-BA64-270DDC6302AE}] => (Allow) C:\Users\Winata\AppData\Roaming\uTorrent\uTorrent. exe
FirewallRules: [{B1EA46CB-B57D-40F7-BC36-AD30AA26E5CE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{663C1C7B-0E42-4B14-8DF6-BB6545615ED2}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{D7810836-6CE3-418C-97AC-9211CA00A3E6}D:\r.g. mechanics\wolfenstein - the new order\wolfneworder_x64.exe] => (Block) D:\r.g. mechanics\wolfenstein - the new order\wolfneworder_x64.exe
FirewallRules: [UDP Query User{8553B954-9958-4127-885A-FEE7BF5FA4FF}D:\r.g. mechanics\wolfenstein - the new order\wolfneworder_x64.exe] => (Block) D:\r.g. mechanics\wolfenstein - the new order\wolfneworder_x64.exe
FirewallRules: [{3048BF09-CA64-452A-8BA9-24A809338A07}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{B68CECF9-C148-481C-BF58-6556FE566166}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [TCP Query User{DEAA1F24-0F2A-444D-9F58-FC22AD2ACC73}C:\windows\temp\files\bin\kmss.exe] => (Allow) C:\windows\temp\files\bin\kmss.exe
FirewallRules: [UDP Query User{A227D6E0-4329-47C0-97FC-E8E395B45CC3}C:\windows\temp\files\bin\kmss.exe] => (Allow) C:\windows\temp\files\bin\kmss.exe
FirewallRules: [{49071643-4AF9-4E98-B9E8-444979C2C575}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{9BD7C176-4F42-4CF3-BEE6-1081961DEA0A}] => (Allow) D:\Steam\steamapps\common\Bloodstained Ritual of the Night\Bloodstained.exe
FirewallRules: [{8F1ECC00-E733-4F2C-B01A-4E1EA7C875B3}] => (Allow) D:\Steam\steamapps\common\Bloodstained Ritual of the Night\Bloodstained.exe
FirewallRules: [TCP Query User{C497CA6D-4FB1-4664-82C6-9362EE37B03D}D:\steam\steamapps\common\bloodstaine d ritual of the night\ron\binaries\win64\ron-win64-shipping.exe] => (Allow) D:\steam\steamapps\common\bloodstained ritual of the night\ron\binaries\win64\ron-win64-shipping.exe
FirewallRules: [UDP Query User{8FA3072B-DA0D-4D57-A6E5-82EE3E3F1A9D}D:\steam\steamapps\common\bloodstaine d ritual of the night\ron\binaries\win64\ron-win64-shipping.exe] => (Allow) D:\steam\steamapps\common\bloodstained ritual of the night\ron\binaries\win64\ron-win64-shipping.exe
FirewallRules: [TCP Query User{039D97D5-A0AD-4AF6-BC36-5B717CF281E1}C:\users\winata\appdata\roaming\spoti fy\spotify.exe] => (Block) C:\users\winata\appdata\roaming\spotify\spotify.ex e
FirewallRules: [UDP Query User{E15D8482-2221-428B-B2BF-DF856AC39E6C}C:\users\winata\appdata\roaming\spoti fy\spotify.exe] => (Block) C:\users\winata\appdata\roaming\spotify\spotify.ex e
FirewallRules: [{B11211BA-5644-4D87-A549-3C893867DD3D}] => (Allow) D:\Steam\steamapps\common\Tom Clancy’s Rainbow Six Siege\RainbowSixGame.exe
FirewallRules: [{86125895-1701-4B57-BFA7-0B1D86020023}] => (Allow) D:\Steam\steamapps\common\Tom Clancy’s Rainbow Six Siege\RainbowSixGame.exe
FirewallRules: [TCP Query User{9F04C030-B1CB-4D8A-8E8F-26778BB6220E}D:\igg-quadrilateral.cowboy\qc.exe] => (Block) D:\igg-quadrilateral.cowboy\qc.exe
FirewallRules: [UDP Query User{CACDF91C-70E0-430A-AD19-C28492E7F4CC}D:\igg-quadrilateral.cowboy\qc.exe] => (Block) D:\igg-quadrilateral.cowboy\qc.exe
FirewallRules: [{2D31B00D-1D00-4158-99A5-38A9F49518E8}] => (Allow) D:\INSIDE\Steam\Steam.exe
FirewallRules: [{4FE0E548-FB56-44AD-AC18-6323C08AF0F3}] => (Allow) D:\INSIDE\Steam\Steam.exe
FirewallRules: [{DBF10588-D83F-4C14-A0FB-7A6A280F1C75}] => (Allow) D:\INSIDE\Steam\bin\steamwebhelper.exe
FirewallRules: [{E9B4AD1D-CDE3-452C-A054-0F9072F0D3B5}] => (Allow) D:\INSIDE\Steam\bin\steamwebhelper.exe
FirewallRules: [{EBB65910-A215-484D-9999-906A3949CEFC}] => (Allow) C:\Program Files\Intel\STCServ\STCServ.exe
FirewallRules: [{63AEED77-501B-49E8-AD25-6ED86748DAB9}] => (Allow) C:\Program Files (x86)\ASUS\Share Link\ShareLink.exe
FirewallRules: [{873E88CC-1376-4E36-B7F4-C7258B71D715}] => (Allow) C:\Program Files\Intel\STCServ\STCServ.exe
FirewallRules: [{BE639B89-97D9-46A0-B214-B482BEE1E15E}] => (Allow) C:\Program Files\Intel\STCServ\STCServ.exe
FirewallRules: [{3865DAD0-4C7F-45FD-B72D-9C4A56D1946B}] => (Allow) C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe
FirewallRules: [TCP Query User{BFD0983E-728A-40FD-84EE-93B47AF3AEE3}C:\program files (x86)\peak angle\peakangle.exe] => (Block) C:\program files (x86)\peak angle\peakangle.exe
FirewallRules: [UDP Query User{3A062928-4BCA-4BB8-9C78-4889A8B46767}C:\program files (x86)\peak angle\peakangle.exe] => (Block) C:\program files (x86)\peak angle\peakangle.exe
FirewallRules: [TCP Query User{DB435670-FBD1-4614-B3A3-C82063AEAD48}C:\program files (x86)\peak angle\peakangledefaultsettings.exe] => (Allow) C:\program files (x86)\peak angle\peakangledefaultsettings.exe
FirewallRules: [UDP Query User{CF644DA8-2696-4050-8518-0F5E494662B6}C:\program files (x86)\peak angle\peakangledefaultsettings.exe] => (Allow) C:\program files (x86)\peak angle\peakangledefaultsettings.exe
FirewallRules: [TCP Query User{A007CA37-57BE-414A-984F-1AB50CE216CC}D:\installer\assetto corsa (skiddrow)\assetto corsa\acs.exe] => (Allow) D:\installer\assetto corsa (skiddrow)\assetto corsa\acs.exe
FirewallRules: [UDP Query User{1AC0376C-3739-4FE1-AD8D-C7A74E1D0E6C}D:\installer\assetto corsa (skiddrow)\assetto corsa\acs.exe] => (Allow) D:\installer\assetto corsa (skiddrow)\assetto corsa\acs.exe
FirewallRules: [{99E0C6C9-4CC9-4513-8E35-1E6952BE8F67}] => (Allow) C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe
FirewallRules: [{6ED7CADD-1B4D-462C-9D78-8A4303E115DF}] => (Allow) C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe
FirewallRules: [{B3E1BF01-F3E5-4FE9-B061-8DCDE62450C8}] => (Allow) C:\Program Files (x86)\SrpnFiles\downloader.exe
FirewallRules: [{8857C463-D585-4E3C-AE08-C499480CFF02}] => (Allow) C:\Program Files (x86)\SrpnFiles\downloader.exe
FirewallRules: [TCP Query User{8DE5B21F-BFAD-4BE5-895D-47CA005FFCA9}D:\doom\doomx64vk.exe] => (Block) D:\doom\doomx64vk.exe
FirewallRules: [UDP Query User{C6AD7F0B-D95F-4292-B1AE-80A177DE1536}D:\doom\doomx64vk.exe] => (Block) D:\doom\doomx64vk.exe
FirewallRules: [{AF81BA1F-37BE-4F2D-BA6C-70669993AA9F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{478468BD-7727-44DD-803E-89253810EFD2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{53C25FC4-DD12-4990-B873-E0926365DDF2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{E66CF01D-B75B-4CE3-A4CD-A2A3A6FB390F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{E879A518-D8E4-4EE9-A046-BB63207DB446}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{8BB8662D-F2E8-4EA5-A15C-3566D0F01947}] => (Allow) D:\Steam\steamapps\common\Divinity Original Sin 2\bin\SupportTool.exe
FirewallRules: [{4E9E5348-4A9C-4ED9-8A55-CFD39904BA0E}] => (Allow) D:\Steam\steamapps\common\Divinity Original Sin 2\bin\SupportTool.exe
FirewallRules: [TCP Query User{89443536-0907-46C0-B901-AC85E5A65FFE}D:\steam\steamapps\common\divinity original sin 2\bin\eocapp.exe] => (Allow) D:\steam\steamapps\common\divinity original sin 2\bin\eocapp.exe
FirewallRules: [UDP Query User{9B1CE90A-F29F-4740-99A2-F873B7CB297D}D:\steam\steamapps\common\divinity original sin 2\bin\eocapp.exe] => (Allow) D:\steam\steamapps\common\divinity original sin 2\bin\eocapp.exe
FirewallRules: [VirtualPC-In-UDP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-UDP-2] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-TCP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [TCP Query User{C34AA4B5-3928-4FE7-BE5B-72CBB47EA6FC}D:\mafia iii - digital deluxe edition\launcher.exe] => (Block) D:\mafia iii - digital deluxe edition\launcher.exe
FirewallRules: [UDP Query User{7092FC96-1C6C-4C2F-8FA8-842F2BA943FD}D:\mafia iii - digital deluxe edition\launcher.exe] => (Block) D:\mafia iii - digital deluxe edition\launcher.exe
FirewallRules: [TCP Query User{17249BCA-0EE4-4624-8247-83E0521240B4}D:\mafia iii - digital deluxe edition\mafia3.exe] => (Block) D:\mafia iii - digital deluxe edition\mafia3.exe
FirewallRules: [UDP Query User{785A76A9-4957-4AEE-BC79-DA8BFF655A01}D:\mafia iii - digital deluxe edition\mafia3.exe] => (Block) D:\mafia iii - digital deluxe edition\mafia3.exe
FirewallRules: [{4D797AB7-6F73-46DB-AC23-CDAB45E96FF4}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{AD48EAE3-C37E-4245-9501-FE4F1B56AC57}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{40A5F063-ABC0-4897-A5B6-3D171AD11557}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A911D116-6590-4B4C-9A1C-AB771CB36FD5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3A46272A-86E6-441E-9B1C-F085587E66EF}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{34B7292F-B7B8-4F63-8F8E-993AE5D089CE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A5F5CF03-4901-42FB-A283-92BD954EDA8C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{02722E5E-A068-4CE7-B9B7-9609555514C6}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C3E7A935-0B3C-4C66-A9FB-038BBE8B5FC9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6DB12AA6-4015-4DE7-9EA2-96139B8EE664}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3844228D-21C1-47E3-A7AF-9993846F11CB}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{31DF5BC7-0B77-4192-9046-25451DA4F921}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7C713299-75D8-49B5-82EC-52713D63689E}] => (Allow) D:\Origin Games\Battlefield 1\bf1Trial.exe
FirewallRules: [{F1E16A89-F54F-422E-8096-223A67C957ED}] => (Allow) D:\Origin Games\Battlefield 1\bf1Trial.exe
FirewallRules: [{08E9E945-5E51-45DF-A2CB-948807DE0AF2}] => (Allow) D:\Origin Games\Battlefield 1\bf1.exe
FirewallRules: [{318D1DE5-FCCD-4398-B607-A11EA2470A1E}] => (Allow) D:\Origin Games\Battlefield 1\bf1.exe
FirewallRules: [{C057A7B2-0E44-4645-A749-0A0F2900A151}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BDF1C134-8B9C-4065-9588-7DC8D79C9256}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F79E2111-9FF1-4CA3-8F83-44A9AAA178BF}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4F67E2E5-C44B-4394-B962-53A0BE318F97}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B9897B99-3B52-4125-BCC3-A51912B3D6E5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CC80FC2C-C751-49D0-9F65-EDBF11C896D5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{563B6A75-F769-433A-87D4-5515350E8734}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D1F75E09-2EE3-4BE5-BD79-7F6E327CADA5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{217FA76C-2F3C-48AA-ABFA-456B15E1526F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{071CC862-3EFC-4FBB-97B3-269430C72162}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A42984C5-0915-44D3-9286-B88C3F044FD1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8072A021-45B1-4C9D-B8E4-C7C68D3327F1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B2A51D60-7614-4D24-8666-B4C4FFD78D5B}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F5240DE2-CC13-4E9A-9CCB-5284FC0C8291}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{84E9B0B2-A5F9-4DCB-96C7-FFE4D97B5071}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{798F5B99-7767-4665-BA82-F143DC26F533}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9EB8586B-55DF-45F6-9AA3-247F318D0EEC}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{590AE367-CDD2-454A-B0C6-2C4EA842C16F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{7559474C-DC4F-4894-A157-312830E4A13E}D:\activision\black ops ii\sp.exe] => (Block) D:\activision\black ops ii\sp.exe
FirewallRules: [UDP Query User{7340BFA3-F866-40D1-AA22-94301BB04F54}D:\activision\black ops ii\sp.exe] => (Block) D:\activision\black ops ii\sp.exe
FirewallRules: [{CECFBEB7-A64D-4C3B-80F2-1DE1250BC4D3}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E686C2A9-8206-42B0-8D03-A7CADA7EE4AB}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B8F4FA1A-6BC6-4BCC-A782-A5084A54DD9D}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CE94429B-88AF-447E-AE94-5BF39914C2D9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F03CBE3E-48FF-4A01-B22E-CAB2C3CBEF7D}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{89A514A8-348D-43DB-A383-BFFA42B5B16F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6C8686EF-B9DA-467C-A29E-39AE6C7C00F1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{30DDEB6B-ED25-427E-96B9-60BE7A317C8D}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EA28D4AE-25F4-41DA-8C7C-B086BCD4E0E1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A60461D5-7E42-466D-ACEB-4534E1A29659}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{14C42345-9C7C-4F35-B383-B82733DF662E}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F3C22F82-4209-403B-A0D3-3AC7DA1B2203}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4847090D-8B33-4E4C-ABF2-DFB3FFB3F160}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3A9E3DB0-A466-406A-940B-D3BCE4718A37}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3BCBC0E0-2651-476F-95F0-1C3E20CAAE7C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2544502C-E52F-422D-8184-A16FBA2F709F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5ABCB168-535A-490E-8B52-85395D68EF71}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{676D19C7-197C-48CC-87A4-94D1D3881586}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{65F9E743-CA30-43C8-85CB-746BEA1960A1}D:\eve\sharedcache\tq\bin\exefile.exe] => (Allow) D:\eve\sharedcache\tq\bin\exefile.exe
FirewallRules: [UDP Query User{69E3C081-1CE4-4AC7-9DEB-9286F100C39C}D:\eve\sharedcache\tq\bin\exefile.exe] => (Allow) D:\eve\sharedcache\tq\bin\exefile.exe
FirewallRules: [{47E227D8-4952-43B8-B917-08C174E80E52}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{55F01913-C498-4D8D-9773-228BAB6829F0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A4EAD85A-0F1D-4877-8C99-9EDC92BB6C6F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{52AECD4D-A236-4C08-99C5-46379F93AB78}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0D196F0E-77B8-4CD1-8EAF-6FD362AA6DCA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6BC31B8F-FFCB-47D9-A465-82FB543183CA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CD7AF00F-40E9-410B-AC58-B9F580915324}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E09C0243-35CE-461E-8667-F293111D8E0A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{DFD5D913-33D6-4741-91C9-A4CB287FF169}D:\assetto corsa\assetto corsa\acs.exe] => (Allow) D:\assetto corsa\assetto corsa\acs.exe
FirewallRules: [UDP Query User{4383E6DF-9EA4-4004-89E4-019710DCC1D2}D:\assetto corsa\assetto corsa\acs.exe] => (Allow) D:\assetto corsa\assetto corsa\acs.exe
FirewallRules: [{9B6F85C3-8FCB-4000-B31F-1F6083ED7A70}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8DA4DA46-C6D1-4275-82C7-351D55025C30}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AC54C3E4-2EA4-4091-AEA8-E0199BB27037}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D59C987F-2640-483F-B610-D26BCE1E6180}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{20538B16-9265-4F7C-BE25-AB18F0EC4191}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{573A31E4-E490-4720-9BD7-1D76983AD595}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{B4B90647-5CDE-438B-80A1-02F51B0B00CC}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9B948204-0BC0-444D-9E37-DCB54FB56A43}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2F90B285-3F57-4270-8A03-DF4BBB37FA41}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FDE3A8BB-9034-40C3-8078-A0EB42497849}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3866EBE0-1106-41B5-94E9-D97B90F29690}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6812AFDA-1500-4A3B-BFE2-3B918A1270F0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{76ABC1FC-44D0-4C21-BC00-F3AA7092D891}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3E562509-21DE-47FB-B0B2-3E54C8DECB10}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{022C5F6C-EB03-4419-88A9-CE4B8FD777AC}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{63CA183A-CE08-4111-A81F-304CFED010AA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2446A4D5-E598-4C55-B88F-22CC99EEDCD1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{85B75C35-9D97-4658-9F06-62BB63960BE3}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B36C8B3A-6187-4CAA-AF20-BAA6AF0F005E}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E088DAE5-DB77-4BF0-8820-EA2498FB1938}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{44AE343C-E884-4FE8-A870-F788BBDE1D4B}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0C5555D4-E952-483F-90AD-C5FE3407CBCF}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D8E1B0EC-D25E-43F1-9442-08A03FC81FF0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{10569696-95CB-4DED-8FBF-BBED2FDC5370}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{52561615-A218-472E-B7D7-0EAE36271BF2}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5A779FAE-DF81-4910-974F-3982E62923F8}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{51FF6BBF-B892-403F-8F9E-6750F0175AC8}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{70963FC5-4759-4CFE-B5A5-C396C2803849}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2CE174EF-98BC-4238-898A-ACF05F389DB9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DEA91D13-C850-4004-9E73-FABA89B91D14}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6710EB80-6D42-400B-BAC4-5AAF57E1CF00}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4EF8A45F-87BE-463D-A54C-46FED8E8C555}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{978DEC58-C6F1-4AF1-A59A-F5E0C626EE30}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{44EE030A-7001-4136-B14E-59AD0FC9B90C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D07A9306-9900-4BB4-B394-FA61396D759F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{9202C902-5E75-411F-A62E-0E1DB04D11E7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{B5E21B37-34E0-4A40-A955-2CD971837BCD}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{43B7A6E9-7AF5-48AC-BBCA-C6126E67E685}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{D89ADE3F-DD21-46FC-8B6F-832D925615E9}D:\alien isolation\ai.exe] => (Allow) D:\alien isolation\ai.exe
FirewallRules: [UDP Query User{EE7D349A-DB96-4637-AF1C-77E7C9FD41BF}D:\alien isolation\ai.exe] => (Allow) D:\alien isolation\ai.exe
FirewallRules: [{E605349A-7B37-4A9D-8AC8-4C661EDD8737}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4DB24B0D-CD7B-460B-8E40-844AB15C3307}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CCF294AC-3EF3-4F34-AB20-8331208ABB6C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{16BF91E9-ED8E-4633-817B-F52DDAC5E601}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{392CFE12-2A79-4B22-9633-737A623A41C7}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DC4DC82F-37FB-4886-83F4-D89D9EEF21B1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1060217B-C209-43CA-9CD0-3749D5D86E77}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1AD9DBA0-C7D5-413F-91FA-A60EB3633A42}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3F3C1A76-D256-4CAC-8D44-ED68CE0617D1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0DF149FF-9EDB-4620-85FD-EE286E8B1105}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{07B5EEBB-E1C8-4A36-B497-3148E8BAFFF0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C26C4284-70EE-453F-A21F-E8F5AE901582}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9405D2D1-125D-4249-8583-6EF56FEB0CD4}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CB988B8C-C78B-468B-8F80-63BF95278694}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2AB02979-68E5-4B1D-A998-45697FD0C7D4}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DBC9097C-D721-40EF-9534-6D6F6862C9BE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DE06D7A9-5685-4D9A-9737-45EE67204425}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{85167C5B-1336-460B-ADF0-9944389BF6BA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FE4F7A15-3A6B-4B3E-8CB8-83846066F6F1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{ABF289C7-D030-48FF-A221-A536237D86D7}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{46B5D13A-F12D-4E4A-950A-0316195FD8B7}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{45B3CA65-DAA5-4050-B54C-D1F8DC9CB6E8}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AC42DB29-1469-46C3-AD15-FCF34F7B221E}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{496E9847-DD12-49EC-9EA4-BD4FB3292F17}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{015CF1D3-0C1F-440D-AABE-EFEBFC5CE17C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E2841F91-6DF2-4789-A2B6-02F549DE7601}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C40E3034-90B5-4BA3-A661-E24E7CCC7370}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D08C814A-04A3-4974-9A06-0E6209A5379F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EEA66249-95C9-457B-ACA0-87DDD52D9A5F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5267BDBB-7BA8-4A2A-88D3-D71D5A6173CC}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D3119A81-C18D-4510-B88A-F370E7B603C4}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E9430D52-346C-4C93-AA12-02242B9E6B93}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{834FC505-38AF-445C-940A-2F8A692A234B}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8FAA2A04-4551-439C-832A-52E25040C64C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9D91238B-10A2-47A8-A015-B7AF36D9A92F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5CA63721-605C-4E03-8981-DC9A27919F40}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E30A604C-6830-4E30-92B2-F59C97FB7254}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{33418EE9-4BCA-4BDD-B731-D34E621D90AE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8E6456B8-7EFC-4CFA-B8B5-62E0BF3FB19C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C6ABA176-0E7C-49DB-9893-396E16D2F206}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D41D8946-F53D-4A42-9FA8-9F989BA954E8}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{360F5239-59FC-4DDC-A5E1-44BD04718D7C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E25FEC9E-F880-4D22-B99F-CC027C5324A3}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0863364E-6F9F-4613-A431-6B225E4002F9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E28E3971-4385-45E9-B6E6-0F536BB0ECC6}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C6567B5D-FB2A-45B6-8EE8-ED2BF4EB5E64}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DB9E89C4-47FB-4F5B-949C-24E2771F137A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BE1A143D-64FB-4A02-BB3B-C16741582751}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9CCDE8B6-9842-4EF6-BDF1-9EC129E8D746}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{070C5F9F-FEA9-4BA5-89ED-40C4210483B7}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D74FCEBE-9EC2-42FE-961C-5EE74D207233}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1945A71C-E363-4F2E-B436-8B074C68ADC8}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EEE4657D-E919-430B-9C1F-D351CDD8C4F0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{ABBFD182-85C1-4325-B20F-85E87252FE1A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{736E7F61-3D20-4D2F-AB58-182DEA7200A5}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRe tail\Evolve.exe
FirewallRules: [{B0ABCDCE-158C-41D3-B431-3416E0EA8CBF}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRe tail\Evolve.exe
FirewallRules: [{3896D8BB-D430-424B-BDD6-9C7B45B484D3}] => (Allow) D:\Steam\steamapps\common\MOBIUS FINAL FANTASY\mobiusff.exe
FirewallRules: [{6D6C530B-923E-4F75-A1C3-FB27738A1875}] => (Allow) D:\Steam\steamapps\common\MOBIUS FINAL FANTASY\mobiusff.exe
FirewallRules: [{576E8250-2384-4802-A744-16A100730512}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{218D791E-6C87-465C-9ECE-13FD3DEC657B}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{759CC722-F01F-49B6-8C53-91BDA9353D65}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D499AC5C-1662-4EBE-83B3-F13A9A107F6A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A241EC52-2069-45CB-BD14-90BAB17118FE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F3FDBBB0-01CD-4FFF-BAD8-A9D3401D20B5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D70F7527-4F5A-4FFC-B1B4-D24B3306419C}] => (Allow) C:\Program Files (x86)\Opera\43.0.2442.991\opera.exe
FirewallRules: [{B3D87BF6-42E7-4284-89BF-56D53298F8E4}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F4E05BEB-9506-40F7-A754-C0AA027679E0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1CBEB3A8-7DB4-4651-828F-59A210F4AC2A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{00D1C6D1-DEA6-4E5F-AF22-36AFF21AA488}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{46B86046-3AB6-42C9-A5C2-953748FE1187}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6927F173-3761-428D-8C26-E9C4A00E6AA9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E199CA31-614A-4207-A517-F77389574BD5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EBBEB117-6AA2-44E8-B65B-E5383D1957D2}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{93058899-D6D4-4420-BB5E-69EA74B20D44}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E0F5C38D-C192-4B7B-BA57-EFFE8C14A0DA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{81FA60DB-1FD5-4B25-8F35-71C69B840EB1}] => (Allow) C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe
FirewallRules: [{B6B67FE7-462C-4CDE-8CC3-40FAC7552C83}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6135B32A-D961-41F1-A6E4-85F355B027CB}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6D878C99-4A05-4B91-9F3B-8C256E8DD073}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1D665A2C-F88A-466B-8B10-478463ABB57D}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0072048F-CB99-43B8-B6B8-FD80E4111719}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FACCC7ED-FD07-4EC0-9915-02079BB5D2EC}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A41298F9-32C1-4B8A-9FEE-2FCADCFC2034}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{466BE7E1-7E7E-4882-8BF1-63DB7A78BE04}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{400B13FD-9950-43A6-8028-AD32148C3C6A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AE8A7483-2B66-43BC-90F1-C31C39DACE48}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A3BE2EC0-5B87-4165-AB69-66B74589C124}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E202254F-04A2-4C15-8C60-E2492A807C83}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F42B3969-4593-4EEC-86F0-AA0F4F683FFE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3FA1B176-BA66-4D33-9208-6D516C941FE1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7B1E9FD3-ED64-460A-9080-BCCC4780FAEC}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E387AB43-9049-4DC7-84D4-6306EB10974C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F048CA03-5FB9-441B-B6FA-74673E7067EA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3092BDCE-2000-452B-A22D-DD6F577BE9A1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C8EAA1F1-7615-4053-9022-54BCEC421864}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{11191C53-9FB0-45F5-B0B6-D739304C3A5F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7D1B7BA3-EA78-4B94-8E0A-872C94DCEB07}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EE2AFF2E-142E-4E34-9B78-AA693F7CBE52}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{41F53D59-DA64-4469-8A3A-8883F8EA268B}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{02F7BED7-70A6-4715-9BBA-B85C679EEC61}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{004C4B06-CC75-4F1D-83AF-CEF323AD30A0}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{87D52A32-A3AF-4E96-93DE-3AD87F786E02}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E984D514-A4DB-4A70-A8AE-EDDFCBEED2ED}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FC3D0689-43BB-43E9-BE13-1D39288C514B}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B84DD7A0-5667-4E05-9FB3-FAEA1603D223}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CD9C0FB4-47C7-40C9-AC0D-E24798E4978E}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6F7CD9A1-A158-466F-B180-633BCADE1479}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BFCD1665-AE62-48C3-89AD-FB1B8FF88D06}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5B61994B-91CF-49F1-B39A-B14010B0112F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C50FE606-E7B8-4C9B-A1D2-4F5F6C0B7E05}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0FAD0F74-EC8F-479D-BC34-FB382EBF8AFA}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EFAB7B07-B9AE-4DA1-861B-AC7C00E19AD3}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7E5AEEF3-D959-40D7-AF59-1380CD8861ED}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D0BBE122-76C8-4668-84D2-8E8590103AC2}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{722A8C5C-294C-4531-B80D-48CB2E798976}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4F866EFD-5EF1-4825-815D-378889D08698}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FB05EEAA-D3E3-4E63-9915-D8D74CCEEBE5}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E9238F30-ECA6-428F-A355-5DC381216E02}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{3A29BACD-7F44-4B90-828B-667096EEA456}C:\users\winata\downloads\psxdownload helper\psxdownloadhelper.exe] => (Allow) C:\users\winata\downloads\psxdownloadhelper\psxdow nloadhelper.exe
FirewallRules: [UDP Query User{2221A870-2147-4129-872B-D80301C92EAA}C:\users\winata\downloads\psxdownload helper\psxdownloadhelper.exe] => (Allow) C:\users\winata\downloads\psxdownloadhelper\psxdow nloadhelper.exe
FirewallRules: [TCP Query User{38A52668-A269-4B83-BDEE-53F16BD1E3EA}D:\assetto corsa\assetto corsa\acs.exe] => (Allow) D:\assetto corsa\assetto corsa\acs.exe
FirewallRules: [UDP Query User{11A40A01-CB60-482E-AD3F-9F841358B031}D:\assetto corsa\assetto corsa\acs.exe] => (Allow) D:\assetto corsa\assetto corsa\acs.exe
FirewallRules: [{97C6725A-74D6-4BD2-A886-F480D62964D6}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8D0A1FAB-0D60-4AE9-B9BB-5B0A3FAE3EC3}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BFAFBB8C-8F2A-41D0-9A1F-ACD3FEAEF6F1}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EC2F9B22-EC45-46C5-AFC4-0AEEC11CD001}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A2C4917A-47DC-4656-B29C-805CA2EEBD55}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{78173A05-7FD5-4606-8A72-35152DDFE16D}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8C3371F4-92AA-4B50-B30C-E13BE4A1BF11}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2820AA8A-1602-4950-BA02-DB684B1723F6}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{47E42033-A66E-43AC-801D-90EF8AF08356}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{63BB03A4-1B45-41F5-98CA-176E1FB801B6}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{04D8D6AD-9B1C-44EE-9352-B6467BFAED8A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4C3F3E6C-046A-4237-9DDF-3BAB77437092}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7DDA43AB-D9BD-4961-BB0F-4C18267330A2}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [{9F7808DA-6144-4164-8B7D-1CDB9134D633}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [{0046922B-6A0F-4311-AE60-60ABC821788D}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DEF8EB7E-97EE-4DA0-821E-A5F3E4EF0C6A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0643824A-0C27-43AE-A469-B01C071DDE62}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{A436BAAF-D45F-4DEB-AA40-6586DBF8B216}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DE2C85D1-3B3A-4622-9E36-5927F08109D7}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F7E6C4F5-B214-486D-ACBD-2290564E9834}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{EBCDF4BE-A361-4AEA-820A-6218347D0C68}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3063D5E3-CC59-4217-AD5D-5EC568CBCCD6}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AE0C7406-2D59-4EC1-A9DE-BE4AAEC5B724}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CE9AC0D5-36BE-426A-A931-0CC3AB474469}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{94765976-B781-4ABB-9575-55C7C9C4F335}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B3E72776-BB67-4590-9B75-138E782E929C}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F3557020-FCC5-417F-B596-C261B0538465}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe
FirewallRules: [{DAF9E7AC-DBC3-4369-9453-A9E2328D50E9}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe
==================== Restore Points =========================
25-04-2017 22:22:13 Scheduled Checkpoint
==================== Faulty Device Manager Devices =============
Name: Microsoft PS/2 Mouse
Description: Microsoft PS/2 Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
[HEADING=1]Application errors:[/HEADING]
Error: (04/26/2017 07:18:41 PM) (Source: MsiInstaller) (EventID: 1002) (User: Winata-PC)
Description: Unexpected or missing value (name: ‘PackageName’, value: ‘’) in key ‘HKLM\Software\Classes\Installer\Products\D139E7FE 48CDB174D86B8A3385904547\SourceList’
Error: (04/26/2017 07:18:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program nvtray.exe version 7.17.13.7892 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 99c
Start Time: 01d2be84f46b9f24
Termination Time: 2
Application Path: C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
Report Id: 73125746-2a7a-11e7-af57-9c5c8e98605f
Error: (04/26/2017 07:04:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (04/25/2017 08:07:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (04/25/2017 05:22:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (04/25/2017 04:55:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (04/25/2017 11:42:14 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (04/25/2017 01:20:51 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SMΔRTP.exe version 4.107.0.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 798
Start Time: 01d2bd2711fb0761
Termination Time: 2
Application Path: C:\Program Files (x86)\Smadav\SMΔRTP.exe
Report Id: bd562776-291a-11e7-8a7c-9c5c8e98605f
Error: (04/25/2017 01:20:22 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (04/25/2017 01:16:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” could not be reactivated in namespace “//./root/CIMV2” because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
[HEADING=1]System errors:[/HEADING]
Error: (04/26/2017 07:04:41 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (04/26/2017 07:04:41 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (04/26/2017 07:02:44 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Origin Web Helper Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (04/26/2017 07:02:44 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Origin Web Helper Service service to connect.
Error: (04/26/2017 07:02:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The SCP DSx Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (04/26/2017 07:02:13 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the SCP DSx Service service to connect.
Error: (04/25/2017 08:07:45 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (04/25/2017 08:07:45 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (04/25/2017 08:05:59 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Origin Web Helper Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (04/25/2017 08:05:59 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Origin Web Helper Service service to connect.
==================== Memory info ===========================
Processor: Intel(R) Core™ i5-6500 CPU @ 3.20GHz
Percentage of memory in use: 47%
Total physical RAM: 8106.85 MB
Available physical RAM: 4295.57 MB
Total Virtual: 16211.88 MB
Available Virtual: 12242.65 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:156.25 GB) (Free:1.96 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (New Volume) (Fixed) (Total:1862.89 GB) (Free:22.32 GB) NTFS
Drive e: (Data) (Fixed) (Total:141.83 GB) (Free:11.54 GB) NTFS
==================== MBR & Partition Table ==================
================================================== ======
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: E4D3E4D3)
Partition 1: (Active) - (Size=156.2 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=141.8 GB) - (Type=OF Extended)
================================================== ======
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: F9F0F9F0)
Partition: GPT.
==================== End of Addition.txt ============================
any help will be really appreciated.. already on wits end.. thanks!
Comment