Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17.03.2019 Ran by Insane (24-03-2019 13:15:59) Running from S:\Downloads Windows 10 Home Version 1809 17763.107 (X64) (2018-11-23 04:01:53) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= 7J0nPFTYqvCO (S-1-5-21-2222582211-2325190247-1126929042-1009 - Administrator - Enabled) Administrator (S-1-5-21-2222582211-2325190247-1126929042-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2222582211-2325190247-1126929042-503 - Limited - Disabled) Guest (S-1-5-21-2222582211-2325190247-1126929042-501 - Limited - Disabled) Insane (S-1-5-21-2222582211-2325190247-1126929042-1001 - Administrator - Enabled) => C:\Users\Insane WDAGUtilityAccount (S-1-5-21-2222582211-2325190247-1126929042-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 4K YouTube to MP3 3.1 (HKLM-x32\...\4K YouTube to MP3_is1) (Version: 3.1.1.1707 - Open Media LLC) Adobe After Effects CC 2015 (HKLM-x32\...\{147EC100-14BE-45EF-AB42-35BAEE7D02F0}) (Version: 13.5.0 - Adobe Systems Incorporated) Adobe Audition CC 2015 (HKLM-x32\...\{839A3566-AED6-4787-A849-5CBE2B1DC6AE}) (Version: 8.0 - Adobe Systems Incorporated) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.9.1.335 - Adobe Systems Incorporated) Adobe Photoshop (HKLM\...\{9B08B2EC-C82E-4D24-A3E0-57646E2CE480}) (Version: 1.0.0000 - Adobe Systems Incorporated) Hidden Adobe Photoshop CC 2017 (HKLM-x32\...\PHSP_18_0_1) (Version: 18.0.1 - Adobe Systems Incorporated) AMD Ryzen Master (HKLM\...\AMD Ryzen Master) (Version: 1.5.2.0869 - Advanced Micro Devices, Inc.) AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 18.3.1 - Advanced Micro Devices, Inc.) Anthemâ„¢ (HKLM-x32\...\{57b4eaa0-f1f5-407e-afbd-2db397381ad8}) (Version: 1.0.57.18984 - Electronic Arts) Anthemâ„¢ Demo (HKLM-x32\...\{b49c4475-6df0-4b2d-abd7-096c5c1d7413}) (Version: 1.0.0.2 - Electronic Arts) Apex Legends (HKLM-x32\...\{D7FBF176-382D-484E-863A-DFD1124A2A1C}) (Version: 1.0.0.4 - Electronic Arts, Inc.) Apple Application Support (32-bit) (HKLM-x32\...\{80B42CAA-28C0-4FBD-A46E-D61F45E2F9FC}) (Version: 7.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{466D00D0-E7DE-47C2-8FE5-54A8009F5850}) (Version: 7.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{5FA8C4BE-8C74-4B9C-9B49-EBF759230189}) (Version: 12.1.0.25 - Apple Inc.) Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.) ASRRGBLED v1.0.39 (HKLM-x32\...\ASRock RGB LED_is1) (Version: 1.0.39 - ASRock Inc.) Assassin's Creed Unity (HKLM-x32\...\Uplay Install 720) (Version: - Ubisoft) AutoHotkey 1.1.30.01 (HKLM\...\AutoHotkey) (Version: 1.1.30.01 - Lexikos) Backuptrans Android WhatsApp to iPhone Transfer (x64) 3.2.111 (HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\Backuptrans Android WhatsApp to iPhone Transfer (x64)) (Version: 3.2.111 - Backuptrans) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) bl (HKLM-x32\...\{2A075BB4-E976-4278-BF3F-E5C6945D84C0}) (Version: 1.0.0 - Your Company Name) Hidden Call of Duty Black Ops 4 (HKLM-x32\...\Call of Duty Black Ops 4) (Version: - Blizzard Entertainment) Cheat Engine 6.8.3 (HKLM-x32\...\Cheat Engine 6.8.3_is1) (Version: - Cheat Engine) Cinema 4D 19.024 (HKLM\...\MAXONCAD0280A) (Version: 19.024 - MAXON Computer GmbH) Destiny 2 (HKLM-x32\...\Destiny 2) (Version: - Blizzard Entertainment) Discord (HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\Discord) (Version: 0.0.305 - Discord Inc.) Electrum (HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\Electrum) (Version: 3.3.4 - Electrum Technologies GmbH) Epic Games Launcher (HKLM-x32\...\{0E63B233-DC24-442C-BD38-0B91D90FEC5B}) (Version: 1.1.167.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden ForHonor (HKLM-x32\...\Uplay Install 569) (Version: - Ubisoft) Futuremark SystemInfo (HKLM-x32\...\{54A3802E-DFED-4235-85A7-A604FE1CC64D}) (Version: 5.14.693.0 - Futuremark) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 73.0.3683.75 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden Grand Theft Auto V (HKLM-x32\...\{5EFC6C07-6B87-43FC-9524-F9E967241741}) (Version: "1.0.0.10" - Rockstar Games) HandBrake 1.1.2 (HKLM-x32\...\HandBrake) (Version: 1.1.2 - ) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) Intel(R) C++ Redistributables on Intel(R) 64 (HKLM-x32\...\{3DAC4F8C-80E6-4204-8A58-747FA4CBAA03}) (Version: 16.0.246 - Intel Corporation) iTunes (HKLM\...\{A9921EE9-86E5-402C-A934-4A8DBAD99E24}) (Version: 12.9.2.6 - Apple Inc.) Java 8 Update 191 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180191F0}) (Version: 8.0.1910.12 - Oracle Corporation) join.me (HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\JoinMe) (Version: 3.14.0.5493 - LogMeIn, Inc.) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Malwarebytes version 3.7.1.2839 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.7.1.2839 - Malwarebytes) Microsoft Office 365 ProPlus - nl-nl (HKLM\...\O365ProPlusRetail - nl-nl) (Version: 16.0.11328.20158 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\OneDriveSetup.exe) (Version: 19.012.0121.0011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.14.26429 (HKLM-x32\...\{80586c77-db42-44bb-bfc8-7aebbb220c00}) (Version: 14.14.26429.4 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25008 (HKLM-x32\...\{c239cea1-d49e-4e16-8e87-8c055765f7ec}) (Version: 14.10.25008.0 - Microsoft Corporation) Minecraft (HKLM-x32\...\{2D1ED4EA-B59D-4665-ACB3-9325872A300D}) (Version: 1.0.4.0 - Mojang) MorphVOX Pro (HKLM-x32\...\{6ac1d2d8-8f42-4d34-a993-fc1bf111bd14}) (Version: 4.4.41.23723 - Screaming Bee) MorphVOX Pro (HKLM-x32\...\{C73BB35D-C39F-45BC-98E8-AA76CA177D61}) (Version: 4.4.41.23723 - Screaming Bee) Hidden Mozilla Firefox 65.0.1 (x64 nl) (HKLM\...\Mozilla Firefox 65.0.1 (x64 nl)) (Version: 65.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 64.0 - Mozilla) NordVPN (HKLM-x32\...\{EF750CE9-E908-457F-8B07-456F39CE757A}) (Version: 6.20.12 - NordVPN) Hidden NordVPN (HKLM-x32\...\NordVPN 6.20.12) (Version: 6.20.12 - NordVPN) NordVPN network TAP (HKLM-x32\...\{97DEC5D6-2BE9-45BB-BFC5-274B851B486B}) (Version: 1.0.1 - NordVPN) Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.6.3 - Notepad++ Team) OBS Studio (HKLM-x32\...\OBS Studio) (Version: 22.0.2 - OBS Project) Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11328.20158 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11328.20158 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11328.20158 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0413-0000-0000000FF1CE}) (Version: 16.0.11328.20158 - Microsoft Corporation) Hidden OpenIV (HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\OpenIV) (Version: 3.1.1032 - .black/OpenIV Team) Origin (HKLM-x32\...\Origin) (Version: 10.5.35.22222 - Electronic Arts, Inc.) Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) ph (HKLM-x32\...\{185F9795-9663-4F13-9EF9-307A282ADB5A}) (Version: 1.0.0 - Your Company Name) Hidden Popcorn-Time (HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\Popcorn-Time) (Version: 0.3.10 - Popcorn Time) PS4 Remote Play (HKLM-x32\...\{856AD2B5-7C4C-4BCA-90C0-48010DAD701F}) (Version: 2.8.0.03041 - Sony Interactive Entertainment Inc.) Rainmeter (HKLM-x32\...\Rainmeter) (Version: 4.2 r3111 - Rainmeter) Razer Surround (HKLM-x32\...\Razer Surround) (Version: 1.05.27 - Razer Inc.) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.21.21.1 - Razer Inc.) Razer Synapse (HKLM-x32\...\Razer Synapse) (Version: 3.4.0331.031119 - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.31.828.2018 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8067 - Realtek Semiconductor Corp.) Roblox Player for Insane (HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\roblox-player) (Version: - Roblox Corporation) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.4.1 - Rockstar Games) Security Task Manager 2.3c (HKLM-x32\...\Security Task Manager) (Version: 2.3c - Neuber Software) ShareX (HKLM\...\82E6AC09-0FEF-4390-AD9F-0DD3F5561EFC_is1) (Version: 12.4.1 - ShareX Team) Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform) Spotify (HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\Spotify) (Version: 1.0.98.78.gb45d2a6b - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamViewer 14 (HKLM-x32\...\TeamViewer) (Version: 14.1.18533 - TeamViewer) Telegram Desktop version 1.5.15 (HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 1.5.15 - Telegram Messenger LLP) Tom Clancy's Ghost Recon Wildlands (HKLM-x32\...\Uplay Install 1771) (Version: - Ubisoft) Tom Clancy's The Division (HKLM-x32\...\Uplay Install 568) (Version: - Ubisoft) Ubisoft Game (HKLM-x32\...\Uplay Install 5159) (Version: - Ubisoft) Uplay (HKLM-x32\...\Uplay) (Version: 75.0 - Ubisoft) VBCABLE, The Virtual Audio Cable (HKLM\...\VB:VBCABLE {87459874-1236-4469}) (Version: - VB-Audio Software) VLC media player (HKLM\...\VLC media player) (Version: 3.0.4 - VideoLAN) VMware Workstation (HKLM\...\{BCA7A01B-CCE0-4AF2-8240-7BA068281D76}) (Version: 12.5.9 - VMware, Inc.) Voicemeeter, The Virtual Mixing Console (HKLM-x32\...\VB:Voicemeeter {17359A74-1236-5467}) (Version: - VB-Audio Software) Vulkan Run Time Libraries 1.0.65.0 (HKLM\...\VulkanRT1.0.65.0) (Version: 1.0.65.0 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.0 (HKLM\...\VulkanRT1.0.65.0-2) (Version: 1.0.65.0 - LunarG, Inc.) Hidden Vuze (HKLM\...\8461-7759-5462-8226) (Version: 5.7.6.0 - Azureus Software, Inc.) WhatsApp (HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\WhatsApp) (Version: 0.3.2386 - WhatsApp) WinRAR 5.61 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.61.0 - win.rar GmbH) Wraith Prism Settings software (HKLM-x32\...\{1A3E3EA7-5A7C-4292-8A13-B0DE1BF49E13}_COOLER_MASTER_SR4) (Version: 1.15 - AMD Wraith) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2222582211-2325190247-1126929042-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6} CustomCLSID: HKU\S-1-5-21-2222582211-2325190247-1126929042-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems Incorporated -> Adobe Systems) CustomCLSID: HKU\S-1-5-21-2222582211-2325190247-1126929042-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Program Files (x86)\Google\Update\1.3.33.23\psmachine_64.dll (Google Inc -> Google Inc.) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2019-01-27] (Notepad++ -> ) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => E:\Program Files\WinRAR\rarext.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => E:\Program Files\WinRAR\rarext32.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers2-x32: [VMDiskMenuHandler] -> {271DC252-6FE1-4D59-9053-E4CF50AB99DE} => E:\Program Files (x86)\VMWARE\vmdkShellExt.dll [2018-01-08] (VMware, Inc. -> VMware, Inc.) ContextMenuHandlers2: [VMDiskMenuHandler64] -> {E4D28EDC-8C0B-43EE-9E7D-C8A8682334DC} => E:\Program Files (x86)\VMWARE\x64\vmdkShellExt64.dll [2018-01-08] (VMware, Inc. -> VMware, Inc.) ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => E:\Program Files\AMD\CNext\CNext\atiacm64.dll [2018-03-02] (Advanced Micro Devices, Inc.) [File not signed] ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => E:\Program Files\WinRAR\rarext.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => E:\Program Files\WinRAR\rarext32.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {017B55C8-E14B-4A35-9A8A-33CCA556B2C5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation) Task: {01D1F396-285F-4CBD-8E0E-44A5999AA249} - System32\Tasks\StartCN => E:\Program Files\AMD\CNext\CNext\cncmd.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) Task: {173A2807-C001-4285-9430-C586C52671BC} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => E:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe (Microsoft Corporation -> Microsoft Corporation) Task: {3506E136-408B-44A8-AEE7-69FADBEBD90A} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-B0HRTSQ-Insane => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) Task: {383D4415-3504-4746-A995-8BD9B64D1CA7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => E:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe (Microsoft Corporation -> Microsoft Corporation) Task: {3CF55FF1-84D6-4F8C-B110-ED27989FF420} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation) Task: {564E3592-CC3A-4AEE-895B-6C7791ADAEF8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.) Task: {61EF4010-B650-4F42-93FE-08BB368044EA} - System32\Tasks\StartDVR => E:\Program Files\AMD\CNext\CNext\dvrcmd.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) Task: {6BF0A5A6-502A-49F0-A89C-E3421760DE53} - System32\Tasks\AdobeGCInvoker-1.0-DESKTOP-B0HRTSQ-Insane => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe (Adobe Systems Incorporated -> Adobe Systems, Incorporated) Task: {74C5A413-CE36-4C8B-91A9-07462B519455} - System32\Tasks\AMDAutoUpdate => C:\Program Files\AMD\AutoUpdate\AMDAutoUpdate.exe Task: {79DE46DD-7F60-4952-84BF-EC4E5986B518} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => E:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe (Microsoft Corporation -> Microsoft Corporation) Task: {7D171FF2-688A-4C10-9A54-DE3687570F1B} - System32\Tasks\Microsoft\Office\Office Feature Updates => E:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe (Microsoft Corporation -> Microsoft Corporation) Task: {7E130D14-383E-4180-895B-F214D000ADB0} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => E:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe (Microsoft Corporation -> Microsoft Corporation) Task: {832AD91E-2DCF-4FAA-863E-C98726CCFACA} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe (Microsoft Corporation -> Microsoft Corporation) Task: {990788F6-6B26-4CE1-B3AA-4C79C19A1DD9} - System32\Tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary => E:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) [File not signed] Task: {ADF4FE9B-33D0-4153-81CA-D05C0928A243} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation) Task: {C29CBD7D-EF95-4C1D-AFA3-C1065598A298} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => E:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe (Microsoft Corporation -> Microsoft Corporation) Task: {D042A92E-D43B-47F4-A850-E1404C79744F} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe (Microsoft Corporation -> Microsoft Corporation) Task: {D421DB04-C4EE-47BA-A410-A51F67782600} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe (Apple Inc. -> Apple Inc.) Task: {E13AB224-8FF2-46DE-A613-CBFBD8E8A5AC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation) Task: {F10FDE14-E317-4C4E-A8B7-F71E4CFD46BA} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => E:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe (Microsoft Corporation -> Microsoft Corporation) Task: {F26E79E4-0AF5-447E-A751-1C5126703DFD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2018-03-02 21:09 - 2018-03-02 21:09 - 000155688 _____ (AMD PMP-PE CB Code Signer v20170331 -> Advanced Micro Devices, Inc.) [File not signed] C:\Windows\SYSTEM32\amdihk64.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000325632 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5WebEngine.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 003406848 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5Quick.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000283136 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5WinExtras.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 005523456 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5Widgets.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 003234304 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5Qml.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 003281408 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5XmlPatterns.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 006045696 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5Gui.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 001204736 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5Network.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000194560 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5Xml.dll 2018-03-02 20:43 - 2018-03-02 20:43 - 005766144 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5Core.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000110080 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5WebChannel.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 068669952 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5WebEngineCore.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000279552 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5Positioning.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 001336832 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\platforms\qwindows.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000015360 _____ () [File not signed] E:\Program Files\AMD\CNext\CNext\libEGL.DLL 2018-02-14 18:45 - 2018-02-14 18:45 - 002519040 _____ () [File not signed] E:\Program Files\AMD\CNext\CNext\libGLESv2.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000032768 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\imageformats\qgif.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000039936 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\imageformats\qicns.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000034816 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\imageformats\qico.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000237568 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\imageformats\qjpeg.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000025600 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\imageformats\qsvg.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000328704 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\Qt5Svg.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000025600 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\imageformats\qtga.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000024064 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\imageformats\qwbmp.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000481792 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\imageformats\qwebp.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000018432 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000311296 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000018432 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\qtgraphicaleffectsplugin.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000018432 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000049152 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll 2018-02-14 18:45 - 2018-02-14 18:45 - 000089600 _____ (The Qt Company Ltd) [File not signed] E:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll 2018-07-08 12:04 - 2018-07-08 12:04 - 000096768 _____ () [File not signed] E:\Program Files\Rainmeter\Plugins\PerfMon.dll 2018-07-08 12:04 - 2018-07-08 12:04 - 000100352 _____ () [File not signed] E:\Program Files\Rainmeter\Plugins\WiFiStatus.dll 2018-07-08 12:04 - 2018-07-08 12:04 - 000130048 _____ () [File not signed] E:\Program Files\Rainmeter\Plugins\SysInfo.dll 2018-07-08 12:04 - 2018-07-08 12:04 - 000110592 _____ () [File not signed] E:\Program Files\Rainmeter\Plugins\PowerPlugin.dll 2018-07-08 12:04 - 2018-07-08 12:04 - 000108032 _____ () [File not signed] E:\Program Files\Rainmeter\Plugins\iTunesPlugin.dll 2019-02-21 19:51 - 2019-02-23 07:21 - 001884160 _____ (ShareX Team) [File not signed] C:\Program Files\ShareX\ShareX.exe 2019-01-21 12:55 - 2019-01-21 12:55 - 000251392 _____ () [File not signed] E:\Program Files (x86)\NordVPN\x86\Liberation.Native.Firewall.dll 2019-02-02 14:31 - 2019-02-02 14:31 - 000184832 _____ (The Qt Company Ltd) [File not signed] E:\Program Files (x86)\Origin\Qt5Xml.dll 2019-02-02 14:31 - 2019-02-02 14:31 - 001177600 _____ (The Qt Company Ltd) [File not signed] E:\Program Files (x86)\Origin\Qt5Network.dll 2019-02-02 14:31 - 2019-02-02 14:31 - 005089792 _____ (The Qt Company Ltd) [File not signed] E:\Program Files (x86)\Origin\Qt5Widgets.dll 2019-02-02 14:31 - 2019-02-02 14:31 - 005487104 _____ (The Qt Company Ltd) [File not signed] E:\Program Files (x86)\Origin\Qt5Core.dll 2019-02-02 14:31 - 2019-02-02 14:31 - 001548288 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] E:\Program Files (x86)\Origin\LIBEAY32.dll 2019-02-02 14:31 - 2019-02-02 14:31 - 005841920 _____ (The Qt Company Ltd) [File not signed] E:\Program Files (x86)\Origin\Qt5Gui.dll 2019-02-02 14:31 - 2019-02-02 14:31 - 001611264 _____ (The Qt Company Ltd) [File not signed] E:\Program Files (x86)\Origin\platforms\qwindows.dll 2019-02-02 14:31 - 2019-02-02 14:31 - 000395776 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] E:\Program Files (x86)\Origin\ssleay32.dll 2018-01-08 23:05 - 2019-02-03 21:31 - 005780968 _____ (VMware, Inc. -> VMware, Inc.) [File not signed] E:\Program Files (x86)\VMWARE\vmwarebase.DLL ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [476] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2018-09-15 08:31 - 2019-01-20 22:53 - 000001000 ____R C:\Windows\system32\drivers\etc\hosts 127.0.0.1 bandicam.com 127.0.0.1 ssl.bandisoft.com 127.0.0.1 bandicam.com 127.0.0.1 ssl.bandisoft.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\Razer\ChromaBroadcast\bin;E:\Program Files\Razer\ChromaBroadcast\bin;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\Common Files\Intel\Shared Libraries\redist\intel64_win\compiler;C:\Program Files (x86)\Razer Chroma SDK\bin;E:\Program Files\Razer Chroma SDK\bin;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Users\Insane\AppData\Local\Microsoft\WindowsApps; HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\Control Panel\Desktop\\Wallpaper -> S:\Documents\Rainmeter\Skins\SenSen Theme\Wallpaper 2560x1600.png DNS Servers: 82.163.142.182 - 82.163.143.180 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. MSCONFIG\Services: WsAppService => 2 MSCONFIG\Services: WsDrvInst => 2 HKLM\...\StartupApproved\Run: => "SecurityHealth" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run: => "AdobeGCInvoker-1.0" HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "Reflect UI" HKLM\...\StartupApproved\Run32: => "FoneLabAppService" HKLM\...\StartupApproved\Run32: => "vmware-tray.exe" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "Wraith Prism" HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud" HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\StartupApproved\StartupFolder: => "R79reHYMtOJgbn8Yc1jm.vbs" HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\StartupApproved\Run: => "Gyazo" HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\StartupApproved\Run: => "EpicGamesLauncher" HKU\S-1-5-21-2222582211-2325190247-1126929042-1001\...\StartupApproved\Run: => "Spotify" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{E6535DBD-5202-4F92-9E03-57B6048C78A2}] => (Allow) E:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{BB478833-36A5-4C6A-A843-ACC1D0F3C16E}] => (Allow) E:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{E6D06BA4-F64F-46C2-8676-A00E0BF0FC33}] => (Allow) E:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{425F0E50-6A95-4085-B338-45197F5CA34D}] => (Allow) E:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{0D419CF5-2271-4F8F-99F5-BA266E524483}] => (Allow) E:\Program Files\Vuze\Azureus.exe (Azureus Software, Inc. -> Azureus Software, Inc) FirewallRules: [{FF199D7B-EC6B-4C13-988D-7E9A7ED7A720}] => (Allow) E:\Program Files\Vuze\Azureus.exe (Azureus Software, Inc. -> Azureus Software, Inc) FirewallRules: [{C6158580-CEB0-4B3C-A680-F32553B66857}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Rust\Rust.exe No File FirewallRules: [{72ED494E-769A-406B-BE42-E23A547E3A4B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Rust\Rust.exe No File FirewallRules: [{606FDC4F-BA73-4607-A4B1-E863F5FC71B9}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe No File FirewallRules: [{AFDEC64C-707B-4218-B45E-171327435FAF}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe No File FirewallRules: [{BC82D6C9-EB7D-4188-9DE6-E6B7E239E3D1}] => (Allow) E:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{BF5C0CCE-EC0D-41E4-83A6-735DFCE97FA6}] => (Allow) E:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{2BD20FAA-D9F1-4010-910E-427F3C79DED6}] => (Allow) E:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{BD814CC5-E70A-42E1-B6D9-AAEE726DBF7D}] => (Allow) E:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{94D68FC5-35F3-4DBE-9B5A-C5C9F869E329}] => (Allow) E:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{8D389A3F-E54F-4160-9320-3AB99CF0ACC8}C:\users\insane\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\insane\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [UDP Query User{17EB1D72-BDFA-478D-9C03-0290440D7FE8}C:\users\insane\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\insane\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [TCP Query User{480562D4-0587-4A60-AC94-5C129C75B60E}E:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) E:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [UDP Query User{6CAEA44F-A475-417F-B81D-01E65FFE404E}E:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) E:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [TCP Query User{8B9D1D42-8260-494F-8B95-0DCA30638DC8}D:\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [UDP Query User{645B2941-0A36-45FA-851E-1D53A8421EFA}D:\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [{9C3F6C8C-594E-4440-A3E5-76536EAB502D}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe No File FirewallRules: [{48DF68F1-CE7A-4DE9-8EE3-F6592B5B0E97}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe No File FirewallRules: [{291A0A11-9271-458D-AE9E-560BCB64AA31}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe No File FirewallRules: [{297F6FA3-82D8-4A7A-85AB-4100324D27F1}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe No File FirewallRules: [{91658758-87F0-4803-A53D-4C04017C2F19}] => (Allow) D:\SteamGames\steamapps\common\Planum\Planum.exe () [File not signed] FirewallRules: [{F360C061-6E48-41B9-A57E-80404B1ABEEF}] => (Allow) D:\SteamGames\steamapps\common\Planum\Planum.exe () [File not signed] FirewallRules: [{CD81471F-392C-46A5-9614-3489EA5C0E5C}] => (Allow) D:\SteamGames\steamapps\common\Counter-Strike Global Offensive\csgo.exe No File FirewallRules: [{66D8C034-348F-40AB-A5B2-A69661766402}] => (Allow) D:\SteamGames\steamapps\common\Counter-Strike Global Offensive\csgo.exe No File FirewallRules: [TCP Query User{1E3F4FAC-5D7C-4DBE-9E4E-2B6FE27FCF52}D:\battle\overwatch\overwatch.exe] => (Allow) D:\battle\overwatch\overwatch.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment) FirewallRules: [UDP Query User{1D6C5AE8-3A7C-497C-9038-FDB8FE179CC5}D:\battle\overwatch\overwatch.exe] => (Allow) D:\battle\overwatch\overwatch.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment) FirewallRules: [TCP Query User{776FD7B9-392D-423A-B3C8-941CD8BC55CA}D:\battle\heroes of the storm\versions\base70616\heroesofthestorm_x64.exe] => (Allow) D:\battle\heroes of the storm\versions\base70616\heroesofthestorm_x64.exe No File FirewallRules: [UDP Query User{7BB28BAB-936B-451F-8907-CC73FF6593C1}D:\battle\heroes of the storm\versions\base70616\heroesofthestorm_x64.exe] => (Allow) D:\battle\heroes of the storm\versions\base70616\heroesofthestorm_x64.exe No File FirewallRules: [{30EBA10E-6227-4949-AFE4-262B5FFDF2B1}] => (Allow) D:\Ubisoft\Assassin's Creed Unity\ACU.exe (UBISOFT ENTERTAINMENT INC. -> ) FirewallRules: [{993EB727-385E-4E3D-A123-2A6F129A7CC6}] => (Allow) D:\Ubisoft\Assassin's Creed Unity\ACU.exe (UBISOFT ENTERTAINMENT INC. -> ) FirewallRules: [TCP Query User{1C9A5E25-AED7-4285-8E77-C5F3664D80D9}D:\games\blizzard\call of duty black ops 4\blackops4.exe] => (Allow) D:\games\blizzard\call of duty black ops 4\blackops4.exe (Activision Publishing Inc -> Activision Publishing, Inc.) FirewallRules: [UDP Query User{10DDA4C0-38B7-4239-88DA-129378C19695}D:\games\blizzard\call of duty black ops 4\blackops4.exe] => (Allow) D:\games\blizzard\call of duty black ops 4\blackops4.exe (Activision Publishing Inc -> Activision Publishing, Inc.) FirewallRules: [{94D79AAF-0E99-4504-8A14-57FB85C51D80}] => (Allow) D:\SteamGames\steamapps\common\Monster Hunter World\MonsterHunterWorld.exe (CAPCOM CO., LTD. -> CAPCOM CO., LTD.) FirewallRules: [{9B6590EC-1DC1-4F32-BDFE-E35C2885419C}] => (Allow) D:\SteamGames\steamapps\common\Monster Hunter World\MonsterHunterWorld.exe (CAPCOM CO., LTD. -> CAPCOM CO., LTD.) FirewallRules: [{7FA9746B-2925-491A-9C59-14385109A038}] => (Allow) D:\SteamGames\steamapps\common\Dead by Daylight\DeadByDaylight.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [{9BDDD6CF-F87E-4B57-98F9-EFC0EA6E831B}] => (Allow) D:\SteamGames\steamapps\common\Dead by Daylight\DeadByDaylight.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [{4B191F57-21BD-4539-B2F9-D5281F34D47F}] => (Allow) D:\SteamGames\steamapps\common\LEGO - The Hobbit\LEGOHobbit.exe (Travellers Tales (UK) Ltd -> Warner Bros. Interactive Entertainment) FirewallRules: [{C38B01F4-58FC-43A3-AE21-DD5CE7D171C8}] => (Allow) D:\SteamGames\steamapps\common\LEGO - The Hobbit\LEGOHobbit.exe (Travellers Tales (UK) Ltd -> Warner Bros. Interactive Entertainment) FirewallRules: [{A94BEFD4-F148-4C92-A1F2-453DC536BC48}] => (Allow) D:\SteamGames\steamapps\common\The Crew 2\TheCrew2.exe (UBISOFT ENTERTAINMENT INC. -> UBISoft) FirewallRules: [{65E9F9ED-4BE8-486C-889A-CAFA90758468}] => (Allow) D:\SteamGames\steamapps\common\The Crew 2\TheCrew2.exe (UBISOFT ENTERTAINMENT INC. -> UBISoft) FirewallRules: [{4822B3E6-C879-4B07-97D1-5483CDD9EBD5}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{A33E7A0E-7B31-40D4-8406-8F44179F3EB7}] => (Allow) E:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.) FirewallRules: [TCP Query User{DA799A2F-26AB-4F11-A75D-7F4F6D419F94}E:\program files\cisco packet tracer 7.1\bin\packettracer7.exe] => (Allow) E:\program files\cisco packet tracer 7.1\bin\packettracer7.exe No File FirewallRules: [UDP Query User{E8BC6242-874C-4BCC-9299-4D8864D372E0}E:\program files\cisco packet tracer 7.1\bin\packettracer7.exe] => (Allow) E:\program files\cisco packet tracer 7.1\bin\packettracer7.exe No File FirewallRules: [{B34114CA-2FDA-46C1-ACEE-C9AD3982FD8D}] => (Allow) D:\SteamGames\steamapps\common\Injustice2\Binaries\Retail\Injustice2.exe (WB Games, Inc.) [File not signed] FirewallRules: [{CF1072DF-063A-4D29-9148-78E3D052498B}] => (Allow) D:\SteamGames\steamapps\common\Injustice2\Binaries\Retail\Injustice2.exe (WB Games, Inc.) [File not signed] FirewallRules: [TCP Query User{90F74483-4CE6-4C79-B33A-BB8AC8AD2F35}S:\cinema4d\cinema 4d.exe] => (Allow) S:\cinema4d\cinema 4d.exe (MAXON Computer GmbH -> MAXON Computer GmbH) FirewallRules: [UDP Query User{670FC6EA-15D7-4DE3-BAEA-3931448D0972}S:\cinema4d\cinema 4d.exe] => (Allow) S:\cinema4d\cinema 4d.exe (MAXON Computer GmbH -> MAXON Computer GmbH) FirewallRules: [{0C8D0CFB-6544-4374-8478-8C7994F30651}] => (Allow) E:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{20A93C57-85DC-4CE2-A946-4A8DA78DD547}] => (Allow) E:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [TCP Query User{B0DB02A6-6094-421A-ABB2-61D64C5035CE}D:\games\minecraft\runtime\jre-x64\1.8.0_51\bin\javaw.exe] => (Allow) D:\games\minecraft\runtime\jre-x64\1.8.0_51\bin\javaw.exe No File FirewallRules: [UDP Query User{9F90BF94-9E94-4ED5-82D0-7B01FD0EE590}D:\games\minecraft\runtime\jre-x64\1.8.0_51\bin\javaw.exe] => (Allow) D:\games\minecraft\runtime\jre-x64\1.8.0_51\bin\javaw.exe No File FirewallRules: [{BF91D087-6F0D-4710-8F5D-224DF154DAF3}] => (Allow) D:\Games\Rockstar Games\Grand Theft Auto V\GTA5.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{86B4C6B5-4647-475E-9052-3AEAF655AB8E}] => (Allow) D:\Games\Rockstar Games\Grand Theft Auto V\GTA5.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{B57C4A5A-55E4-4844-A071-FA9BB2F92420}] => (Allow) D:\SteamGames\steamapps\common\TEKKEN 7\TEKKEN 7.exe () [File not signed] FirewallRules: [{D0A7507E-28B5-499C-9BF9-3004FEAAFE39}] => (Allow) D:\SteamGames\steamapps\common\TEKKEN 7\TEKKEN 7.exe () [File not signed] FirewallRules: [{A8F05A8A-AD4B-4637-988A-E59BFF0504AB}] => (Allow) D:\SteamGames\steamapps\common\The Forest\TheForest.exe () [File not signed] FirewallRules: [{B802E62B-9928-449B-8D4D-5DE7DF37D740}] => (Allow) D:\SteamGames\steamapps\common\The Forest\TheForest.exe () [File not signed] FirewallRules: [{2AA09209-791E-4F72-9256-E0A4D03B7A40}] => (Allow) D:\SteamGames\steamapps\common\The Forest\TheForestVR.exe () [File not signed] FirewallRules: [{0C2DDC53-6A3A-4908-B67E-8A28E877423E}] => (Allow) D:\SteamGames\steamapps\common\The Forest\TheForestVR.exe () [File not signed] FirewallRules: [TCP Query User{AE865812-6F59-4FD7-8943-1B915E45AE16}D:\steamgames\steamapps\common\tekken 7\tekkengame\binaries\win64\tekkengame-win64-shipping.exe] => (Allow) D:\steamgames\steamapps\common\tekken 7\tekkengame\binaries\win64\tekkengame-win64-shipping.exe (BANDAI NAMCO Entertainment Inc.) [File not signed] FirewallRules: [UDP Query User{0177E9A9-1553-41CA-B202-EB0709E25BB4}D:\steamgames\steamapps\common\tekken 7\tekkengame\binaries\win64\tekkengame-win64-shipping.exe] => (Allow) D:\steamgames\steamapps\common\tekken 7\tekkengame\binaries\win64\tekkengame-win64-shipping.exe (BANDAI NAMCO Entertainment Inc.) [File not signed] FirewallRules: [{17DB2535-20B6-434C-BE7E-20094588DDD8}] => (Allow) D:\SteamGames\steamapps\common\3DMark\3DMarkLauncher.exe (FUTUREMARK INC -> Futuremark) FirewallRules: [{4E273D87-89A1-4805-A820-41EF9FDCC512}] => (Allow) D:\SteamGames\steamapps\common\3DMark\3DMarkLauncher.exe (FUTUREMARK INC -> Futuremark) FirewallRules: [{381F115C-E1ED-4FF4-A17E-DE5D9FEA5EED}] => (Allow) U:\Program Files (x86)\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> ) FirewallRules: [{183A29DD-B29A-4C58-AAAF-2989687ABBAE}] => (Allow) U:\Program Files (x86)\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> ) FirewallRules: [{EE61ABD3-0077-49AA-BD6C-9ED0165219DA}] => (Allow) U:\Program Files (x86)\steamapps\common\Rust\Rust.exe (Facepunch Studios Ltd -> EasyAntiCheat Ltd) FirewallRules: [{8D42AA3A-6D6D-401D-BD02-13037824B200}] => (Allow) U:\Program Files (x86)\steamapps\common\Rust\Rust.exe (Facepunch Studios Ltd -> EasyAntiCheat Ltd) FirewallRules: [{3EEA9A1C-4F38-4898-8FC3-11F922715170}] => (Allow) U:\Program Files (x86)\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft) FirewallRules: [{DF34D1ED-2718-4773-9DCD-A48E47E75867}] => (Allow) U:\Program Files (x86)\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft) FirewallRules: [TCP Query User{808B9589-2651-4A96-BF5F-4FF581AFF4F9}C:\users\insane\appdata\local\popcorn-time\popcorn-time.exe] => (Allow) C:\users\insane\appdata\local\popcorn-time\popcorn-time.exe (The NWJS Community) [File not signed] FirewallRules: [UDP Query User{F46EF9DA-24BA-4A93-9A42-C523D3D71BAD}C:\users\insane\appdata\local\popcorn-time\popcorn-time.exe] => (Allow) C:\users\insane\appdata\local\popcorn-time\popcorn-time.exe (The NWJS Community) [File not signed] FirewallRules: [{EBA47FF9-51F0-4B7E-A0C3-2BC7321440DF}] => (Allow) U:\Program Files (x86)\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix_BE.exe (BattlEye Innovations e.K. -> BattlEye Innovations) FirewallRules: [{03D9A8DD-7E06-4F9E-AC26-93F41441D5C9}] => (Allow) U:\Program Files (x86)\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix_BE.exe (BattlEye Innovations e.K. -> BattlEye Innovations) FirewallRules: [{2145546D-153D-4BB6-AF51-1AB7429D394B}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Realm Royale\Binaries\Win64\RealmEAC.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [{D061A786-3E62-4618-BE40-2B11DDCF5DED}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Realm Royale\Binaries\Win64\RealmEAC.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [TCP Query User{54FEF003-48B9-4E75-A3D4-932033FB84FC}E:\program files (x86)\steam\steamapps\common\realm royale\binaries\win64\realm.exe] => (Allow) E:\program files (x86)\steam\steamapps\common\realm royale\binaries\win64\realm.exe (Hirez Studios, Inc.) [File not signed] FirewallRules: [UDP Query User{DB354DD5-C389-43F6-928D-4E7E5DC6CE9F}E:\program files (x86)\steam\steamapps\common\realm royale\binaries\win64\realm.exe] => (Allow) E:\program files (x86)\steam\steamapps\common\realm royale\binaries\win64\realm.exe (Hirez Studios, Inc.) [File not signed] FirewallRules: [{FAF62274-717F-453D-9AB9-0E6C5ECFDADF}] => (Allow) D:\SteamGames\steamapps\common\Hurtworld\Hurtworld.exe (EasyAntiCheat Ltd) [File not signed] FirewallRules: [{15783DEA-009F-4C65-9E15-22541CB93008}] => (Allow) D:\SteamGames\steamapps\common\Hurtworld\Hurtworld.exe (EasyAntiCheat Ltd) [File not signed] FirewallRules: [{FC73BBB8-D35A-4AF2-A938-ED6959777B33}] => (Allow) D:\Origin Games\AnthemDemo\AnthemDemo.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{99EF805E-28FE-42A9-9441-C1E8778C079B}] => (Allow) D:\Origin Games\AnthemDemo\AnthemDemo.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{66C367A6-83E5-4F6A-8ED4-2D2C3C2DAFF9}] => (Allow) E:\Program Files (x86)\VMWARE\vmware-authd.exe (VMware, Inc. -> VMware, Inc.) FirewallRules: [{0DCCAA05-AA99-47E8-AC1B-DA9780BD8C04}] => (Allow) E:\Program Files (x86)\VMWARE\vmware-authd.exe (VMware, Inc. -> VMware, Inc.) FirewallRules: [{21360BD1-621D-49FF-9C26-EC3CC11A33D9}] => (Allow) E:\Program Files (x86)\VMWARE\vmware-hostd.exe (VMware, Inc. -> ) FirewallRules: [{C44DC259-651B-4BC1-B95B-87B90DCE339E}] => (Allow) E:\Program Files (x86)\VMWARE\vmware-hostd.exe (VMware, Inc. -> ) FirewallRules: [TCP Query User{945FC884-8BEF-47A6-9DDE-DCC048C2062B}D:\steamgames\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) D:\steamgames\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe (Epic Games, Inc.) [File not signed] FirewallRules: [UDP Query User{61931356-01BC-4DB1-9BC4-2FD6140ADA37}D:\steamgames\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) D:\steamgames\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe (Epic Games, Inc.) [File not signed] FirewallRules: [{A8BA6138-C54D-4DD9-B089-E48BE6B09221}] => (Allow) U:\Program Files (x86)\steamapps\common\Deep Rock Galactic\FSD.exe (Epic Games, Inc.) [File not signed] FirewallRules: [{DCCEB91F-C8D8-4533-959E-E6EBD96E8E58}] => (Allow) U:\Program Files (x86)\steamapps\common\Deep Rock Galactic\FSD.exe (Epic Games, Inc.) [File not signed] FirewallRules: [{A4440A26-8C04-491F-BB87-E1087A1AC471}] => (Allow) U:\Program Files (x86)\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe (Bluehole, Inc. -> PUBG Corporation ) FirewallRules: [{7FCFA4F6-DF04-4391-8679-3204A038079F}] => (Allow) U:\Program Files (x86)\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe (Bluehole, Inc. -> PUBG Corporation ) FirewallRules: [{4B68C088-DEBC-406A-8F51-23F7BC4122BD}] => (Allow) U:\Ubisoft\Tom Clancy's The Division\TheDivision.exe (Ubisoft Entertainment Sweden AB -> Ubisoft) FirewallRules: [TCP Query User{82D05CC4-B3CC-498D-BD33-BFFB9736388C}U:\program files (x86)\steamapps\common\deep rock galactic\fsd\binaries\win64\fsd-win64-shipping.exe] => (Allow) U:\program files (x86)\steamapps\common\deep rock galactic\fsd\binaries\win64\fsd-win64-shipping.exe (Ghost Ship Games) [File not signed] FirewallRules: [UDP Query User{1922A70A-735A-491A-A97F-B06CCB90122B}U:\program files (x86)\steamapps\common\deep rock galactic\fsd\binaries\win64\fsd-win64-shipping.exe] => (Allow) U:\program files (x86)\steamapps\common\deep rock galactic\fsd\binaries\win64\fsd-win64-shipping.exe (Ghost Ship Games) [File not signed] FirewallRules: [TCP Query User{FBCD24AF-276F-43E1-A6E9-B92E74D7B145}U:\origin\apex\r5apex.exe] => (Allow) U:\origin\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment) FirewallRules: [UDP Query User{3342D132-EFE6-44AE-83BE-ABCC7CCC9AAC}U:\origin\apex\r5apex.exe] => (Allow) U:\origin\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment) FirewallRules: [{8B080269-C0A0-498A-992A-E05861F1A09A}] => (Allow) U:\Program Files (x86)\steamapps\common\Rustangelo\Rustangelo.exe (JaviteSoft) [File not signed] FirewallRules: [{7F645E07-F5A1-40B7-ACAF-C1DA6EEF0922}] => (Allow) U:\Program Files (x86)\steamapps\common\Rustangelo\Rustangelo.exe (JaviteSoft) [File not signed] FirewallRules: [TCP Query User{318DA07F-BD23-4580-B3C3-B8A0F3A4EC39}S:\downloads\aeroadmin.exe] => (Block) S:\downloads\aeroadmin.exe (AeroAdmin LLC -> AeroAdmin LLC) FirewallRules: [UDP Query User{7BD6BDE1-46A1-4677-A7FC-119506E082C0}S:\downloads\aeroadmin.exe] => (Block) S:\downloads\aeroadmin.exe (AeroAdmin LLC -> AeroAdmin LLC) FirewallRules: [{ABAF921B-ED14-4E31-BCCD-CC38F70B3751}] => (Allow) U:\Program Files (x86)\steamapps\common\Dying Light Bad Blood\BadBloodGameLauncher.exe (Techland Sp. z o.o. -> EasyAntiCheat Ltd) FirewallRules: [{298D7B38-EDB7-4924-B732-1BA27AB4FBCB}] => (Allow) U:\Program Files (x86)\steamapps\common\Dying Light Bad Blood\BadBloodGameLauncher.exe (Techland Sp. z o.o. -> EasyAntiCheat Ltd) FirewallRules: [TCP Query User{0682A38D-2AFB-45FB-9E9D-9762B9F72B8C}C:\program files (x86)\minecraft\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\bin\javaw.exe FirewallRules: [UDP Query User{2B2C12E4-3352-4B7F-B8E8-40092DEF6C0D}C:\program files (x86)\minecraft\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\bin\javaw.exe FirewallRules: [{CFE429A3-0BEE-460C-A852-BB5B5531C679}] => (Allow) U:\Origin\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [{B4C27021-8DBD-4FA6-9B54-F4CB4244D310}] => (Allow) U:\Origin\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [TCP Query User{31B9D9B1-F186-4ADB-BE41-570CDF8D4097}U:\program files (x86)\steamapps\common\dying light bad blood\badbloodgame.exe] => (Allow) U:\program files (x86)\steamapps\common\dying light bad blood\badbloodgame.exe (Techland Sp. z o.o. -> Techland) FirewallRules: [UDP Query User{3ADFE1D4-092A-441E-B275-7C6D9A4C6605}U:\program files (x86)\steamapps\common\dying light bad blood\badbloodgame.exe] => (Allow) U:\program files (x86)\steamapps\common\dying light bad blood\badbloodgame.exe (Techland Sp. z o.o. -> Techland) FirewallRules: [{13873CBF-6DC1-4D60-BE95-848D550361CF}] => (Allow) U:\Program Files (x86)\steamapps\common\Conan Exiles\ConanSandbox\Binaries\Win64\ConanSandbox_BE.exe (FUNCOM OSLO AS -> BattlEye Innovations) FirewallRules: [{C9FAE8A7-7561-4F76-B543-EE618B4C8178}] => (Allow) U:\Program Files (x86)\steamapps\common\Conan Exiles\ConanSandbox\Binaries\Win64\ConanSandbox_BE.exe (FUNCOM OSLO AS -> BattlEye Innovations) FirewallRules: [{423655A9-711C-498B-B014-B294ACBD8431}] => (Allow) U:\Program Files (x86)\steamapps\common\Conan Exiles\ConanSandbox\Binaries\Win64\ConanSandbox.exe (FUNCOM OSLO AS -> Funcom Oslo AS) FirewallRules: [{1C457C7A-46E1-40B6-B1D3-BD71A362A192}] => (Allow) U:\Program Files (x86)\steamapps\common\Conan Exiles\ConanSandbox\Binaries\Win64\ConanSandbox.exe (FUNCOM OSLO AS -> Funcom Oslo AS) FirewallRules: [{12A3CE98-3A85-40F1-8419-236047E72114}] => (Allow) U:\Origin\Anthem\AnthemTrial.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{5FFE73F1-B34E-4A95-89F1-38D614EC09E6}] => (Allow) U:\Origin\Anthem\AnthemTrial.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{831B3ED0-DC62-4138-A3A1-EB36DCD45833}] => (Allow) U:\Origin\Anthem\Anthem.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{FDDFDBD1-FACF-48AD-B706-512C12C7A133}] => (Allow) U:\Origin\Anthem\Anthem.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{74EA2EF7-9242-4CC8-8B67-B0AFB8868DEB}] => (Allow) E:\Program Files\Windows 10 Pro Permanent Activator Ultimate 2.2\Windows 10 Pro Permanent Activator Ultimate 2.2.exe No File FirewallRules: [{91846C96-6F92-43B2-B64E-67709BA689C6}] => (Allow) C:\Windows\system32\rundll32.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{597B053E-1E74-4DEC-96FF-66B8E9198869}] => (Allow) C:\Windows\SysWOW64\TCPSVCS.EXE (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{A2F77172-71E3-4A46-8C82-19805945DEBB}] => (Allow) C:\Program Files (x86)\Sony\PS4 Remote Play\RemotePlay.exe (Sony Interactive Entertainment Inc. -> Sony Interactive Entertainment Inc.) FirewallRules: [{F27682BE-803D-4EF1-963D-C67C23684432}] => (Allow) D:\SteamGames\steamapps\common\Hurtworld\experimental\Hurtworld.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [{8474D885-AF1D-4FEE-9485-E3E33C03E932}] => (Allow) D:\SteamGames\steamapps\common\Hurtworld\experimental\Hurtworld.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [{5B8EDAEC-FDB4-4000-A498-B8A0B22AC36D}] => (Allow) E:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) FirewallRules: [{3589B7BC-31BD-49A0-97F0-729DB2898DE4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{7DAFCA18-5F44-4BAC-A361-A05A9EB4B913}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{5DB5C89F-B08F-41FD-BFF3-EDF9BCFAE85D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{250794DA-4555-4BC8-AFA8-90686A8222A1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [TCP Query User{A797237B-F588-4E36-A9FE-5E4BC219B8B2}S:\cinema4d\cinema 4d teamrender client.exe] => (Block) S:\cinema4d\cinema 4d teamrender client.exe (MAXON Computer GmbH -> MAXON Computer GmbH) FirewallRules: [UDP Query User{9C33D497-F3B2-40CC-8CB9-D185F19A563E}S:\cinema4d\cinema 4d teamrender client.exe] => (Block) S:\cinema4d\cinema 4d teamrender client.exe (MAXON Computer GmbH -> MAXON Computer GmbH) FirewallRules: [{99A6065C-DF1F-4CA8-BFF0-0AB8653BF69B}] => (Allow) U:\Program Files (x86)\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{4173A600-C082-4951-A306-47283C8E93F8}] => (Allow) U:\Program Files (x86)\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [TCP Query User{837BFC64-8B1F-49F3-B1DE-99047514EEF5}U:\program files (x86)\steamapps\common\grand theft auto v\gta5.exe] => (Allow) U:\program files (x86)\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [UDP Query User{335BB567-44C5-4B67-9C93-9C902E6AA3E8}U:\program files (x86)\steamapps\common\grand theft auto v\gta5.exe] => (Allow) U:\program files (x86)\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{28F44EE7-797C-498C-B3F3-2D4D602C1268}] => (Allow) D:\SteamGames\steamapps\common\F13Game\EAC_Launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [{C476459C-412A-414E-9B99-ACF060A4DEF1}] => (Allow) D:\SteamGames\steamapps\common\F13Game\EAC_Launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [{2FED16BC-C2BE-4511-9BF0-769F63585323}] => (Allow) U:\Program Files (x86)\steamapps\common\Far Cry New Dawn\bin\FarCryNewDawn.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment) FirewallRules: [{DADD3D4A-7402-4034-ABCA-21568D0B9F91}] => (Allow) U:\Program Files (x86)\steamapps\common\Far Cry New Dawn\bin\FarCryNewDawn.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment) FirewallRules: [{2F8768D4-4A83-47A7-A09B-578AC0DFEBA7}] => (Allow) D:\SteamGames\steamapps\common\3DMark\bin\x86\3DMark.exe (FUTUREMARK INC -> ) FirewallRules: [{E607A4AF-15BD-486D-A8F9-44657F6B1EA2}] => (Allow) D:\SteamGames\steamapps\common\3DMark\bin\x86\3DMark.exe (FUTUREMARK INC -> ) FirewallRules: [{80362642-A2A0-4DD2-AB4F-218B06AA6213}] => (Allow) D:\SteamGames\steamapps\common\3DMark\bin\x64\3DMark.exe (FUTUREMARK INC -> ) FirewallRules: [{3A3BC7D8-7E2E-4F7B-92B8-233AAE32ACC9}] => (Allow) D:\SteamGames\steamapps\common\3DMark\bin\x64\3DMark.exe (FUTUREMARK INC -> ) FirewallRules: [{5EB130C1-F6B4-4A80-B644-BBE19F22AA96}] => (Allow) U:\Program Files (x86)\steamapps\common\DARK SOULS III\Game\DarkSoulsIII.exe (FromSoftware,Inc. -> BANDAI NAMCO Entertainment Inc.) FirewallRules: [{FE0C9E1A-B86C-40CA-8929-75ED8B7A4FEC}] => (Allow) U:\Program Files (x86)\steamapps\common\DARK SOULS III\Game\DarkSoulsIII.exe (FromSoftware,Inc. -> BANDAI NAMCO Entertainment Inc.) FirewallRules: [{5A58B24C-0505-4F0F-8AE5-D384A5251A34}] => (Allow) D:\SteamGames\steamapps\common\Deceit\bin\win_x64\Deceit.exe (Crytek GmbH) [File not signed] FirewallRules: [{E28FA939-A32E-4AAA-96B8-6C83E1A0B8A8}] => (Allow) D:\SteamGames\steamapps\common\Deceit\bin\win_x64\Deceit.exe (Crytek GmbH) [File not signed] FirewallRules: [TCP Query User{F82FAB92-E35D-49C4-AB9C-8546CDB2D154}C:\users\insane\appdata\local\fivem\fivem.app\cache\subprocess\fivem_gtaprocess.exe] => (Allow) C:\users\insane\appdata\local\fivem\fivem.app\cache\subprocess\fivem_gtaprocess.exe (cfx-collective) [File not signed] FirewallRules: [UDP Query User{368A7BA6-C308-4660-8CF6-835001A3A594}C:\users\insane\appdata\local\fivem\fivem.app\cache\subprocess\fivem_gtaprocess.exe] => (Allow) C:\users\insane\appdata\local\fivem\fivem.app\cache\subprocess\fivem_gtaprocess.exe (cfx-collective) [File not signed] ==================== Restore Points ========================= 21-03-2019 12:01:42 WINDOWS 24-03-2019 12:44:25 Windows Update ==================== Faulty Device Manager Devices ============= Name: Realtek PCIe GbE Family Controller #2 Description: Realtek PCIe GbE Family Controller Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Realtek Service: rt640x64 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (03/24/2019 12:44:25 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddCoreCsiFiles : RtlConvertNtFilePathToWin32Path() failed. System Error: 0xC0000039 (unresolvable). Error: (03/24/2019 12:43:02 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddCoreCsiFiles : RtlConvertNtFilePathToWin32Path() failed. System Error: 0xC0000039 (unresolvable). Error: (03/23/2019 11:18:46 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program GTAVLauncher.exe version 1.0.1604.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: d18 Start Time: 01d4e1c6206da716 Termination Time: 4294967295 Application Path: D:\Games\Rockstar Games\Grand Theft Auto V\GTAVLauncher.exe Report Id: b4b79b99-e042-4d70-bf64-c8f5cff6a751 Faulting package full name: Faulting package-relative application ID: Hang type: Cross-thread Error: (03/23/2019 08:03:10 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: ) Description: Event-ID 0 Error: (03/22/2019 08:03:10 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: ) Description: Event-ID 0 Error: (03/22/2019 03:21:04 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program mmc.exe version 10.0.17763.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 3620 Start Time: 01d4e0ba5b654b53 Termination Time: 6 Application Path: C:\Windows\System32\mmc.exe Report Id: f937ed2e-cd28-4b75-bedd-d6e28595b2e7 Faulting package full name: Faulting package-relative application ID: Hang type: Unknown Error: (03/22/2019 03:20:50 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program mmc.exe version 10.0.17763.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: a10 Start Time: 01d4e0b90e69037e Termination Time: 7 Application Path: C:\Windows\System32\mmc.exe Report Id: 51bd1576-a3dd-471a-a660-2a317e581c50 Faulting package full name: Faulting package-relative application ID: Hang type: Unknown Error: (03/22/2019 03:20:02 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program mmc.exe version 10.0.17763.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 3ce0 Start Time: 01d4e0b97abbe221 Termination Time: 8 Application Path: C:\Windows\System32\mmc.exe Report Id: 56cbdf44-1d9f-454d-bc7c-c8668213703f Faulting package full name: Faulting package-relative application ID: Hang type: Unknown System errors: ============= Error: (03/24/2019 01:17:25 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-B0HRTSQ) Description: The server {9E175B6D-F52A-11D8-B9A5-505054503030} did not register with DCOM within the required timeout. Error: (03/24/2019 01:15:25 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-B0HRTSQ) Description: The server {9E175B6D-F52A-11D8-B9A5-505054503030} did not register with DCOM within the required timeout. Error: (03/24/2019 01:13:25 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-B0HRTSQ) Description: The server {E48EDA45-43C6-48E0-9323-A7B2067D9CD5} did not register with DCOM within the required timeout. Error: (03/24/2019 01:11:25 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-B0HRTSQ) Description: The server {E48EDA45-43C6-48E0-9323-A7B2067D9CD5} did not register with DCOM within the required timeout. Error: (03/24/2019 01:09:25 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-B0HRTSQ) Description: The server {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} did not register with DCOM within the required timeout. Error: (03/24/2019 01:07:25 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-B0HRTSQ) Description: The server {E48EDA45-43C6-48E0-9323-A7B2067D9CD5} did not register with DCOM within the required timeout. Error: (03/24/2019 01:05:25 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-B0HRTSQ) Description: The server {B52D54BB-4818-4EB9-AA80-F9EACD371DF8} did not register with DCOM within the required timeout. Error: (03/24/2019 01:03:25 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {9E175B6D-F52A-11D8-B9A5-505054503030} did not register with DCOM within the required timeout. Windows Defender: =================================== Date: 2019-03-20 19:27:02.248 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {05D03F3D-7219-4056-A36D-7E72EEFE60C6} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-03-19 14:37:07.596 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {39856448-BCA5-4704-A611-E8700BC45F57} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-03-19 12:39:28.300 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {6526B76C-9B5D-4F2E-A986-909D22774A6F} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-03-17 22:22:54.884 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Ludicrouz.Z&threatid=2147722906&enterprise=0 Name: Trojan:Win32/Ludicrouz.Z ID: 2147722906 Severity: Severe Category: Trojan Path: file:_C:\ProgramData\{2DEC06E1-DDEE-847F-96C0-FC089627A559}\{2DEC06E1-DDEE-847F-96C0-FC089627A559}.tmp; file:_C:\ProgramData\{BD7BCDCA-16C5-14E8-BD0B-6B98BDEC32C9}\{BD7BCDCA-16C5-14E8-BD0B-6B98BDEC32C9}.tmp Detection Origin: Local machine Detection Type: FastPath Detection Source: System Process Name: Unknown Signature Version: AV: 1.289.1401.0, AS: 1.289.1401.0, NIS: 0.0.0.0 Engine Version: AM: 1.1.15700.9, NIS: 0.0.0.0 Date: 2019-03-12 21:12:37.086 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=TrojanSpy:Win32/SocStealer!rfn&threatid=2147724296&enterprise=0 Name: TrojanSpy:Win32/SocStealer!rfn ID: 2147724296 Severity: Severe Category: Trojan Monitoring Software Path: file:_C:\Users\Insane\AppData\Local\App\svchost.exe; process:_pid:11008,ProcessStart:131968945141853741; regkey:_HKCU@S-1-5-21-2222582211-2325190247-1126929042-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\App; runkey:_HKCU@S-1-5-21-2222582211-2325190247-1126929042-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\App Detection Origin: Local machine Detection Type: Concrete Detection Source: System Process Name: C:\Users\Insane\AppData\Local\App\svchost.exe Signature Version: AV: 1.289.999.0, AS: 1.289.999.0, NIS: 0.0.0.0 Engine Version: AM: 1.1.15700.9, NIS: 0.0.0.0 CodeIntegrity: =================================== Date: 2019-03-12 21:38:40.448 Description: Windows blocked file \Device\HarddiskVolume8\Windows\System32\scrobj.dll which has been disallowed for protected processes. Date: 2019-03-12 21:37:43.837 Description: Windows blocked file \Device\HarddiskVolume8\Windows\System32\scrobj.dll which has been disallowed for protected processes. Date: 2019-01-21 18:59:59.439 Description: Code Integrity determined that a process (\Device\HarddiskVolume8\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume7\Program Files\Bonjour\mdnsNSP.dll that did not meet the Windows signing level requirements. Date: 2019-01-21 18:59:59.438 Description: Code Integrity determined that a process (\Device\HarddiskVolume8\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume7\Program Files\Bonjour\mdnsNSP.dll that did not meet the Windows signing level requirements. Date: 2019-01-21 18:52:14.122 Description: Code Integrity determined that a process (\Device\HarddiskVolume8\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume7\Program Files\Bonjour\mdnsNSP.dll that did not meet the Windows signing level requirements. Date: 2019-01-21 18:52:14.122 Description: Code Integrity determined that a process (\Device\HarddiskVolume8\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume7\Program Files\Bonjour\mdnsNSP.dll that did not meet the Windows signing level requirements. Date: 2019-01-21 18:52:13.445 Description: Code Integrity determined that a process (\Device\HarddiskVolume8\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume7\Program Files\Bonjour\mdnsNSP.dll that did not meet the Windows signing level requirements. Date: 2019-01-21 18:52:13.444 Description: Code Integrity determined that a process (\Device\HarddiskVolume8\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume7\Program Files\Bonjour\mdnsNSP.dll that did not meet the Windows signing level requirements. ==================== Memory info =========================== Processor: AMD Ryzen 7 2700X Eight-Core Processor Percentage of memory in use: 38% Total physical RAM: 16316.66 MB Available physical RAM: 10080.35 MB Total Virtual: 23484.66 MB Available Virtual: 13931.88 MB ==================== Drives ================================ Drive c: (WINDOWS) (Fixed) (Total:476.94 GB) (Free:388.62 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: (GAMES) (Fixed) (Total:2794.39 GB) (Free:1554.95 GB) NTFS Drive e: (WINDOWS APPS) (Fixed) (Total:465.21 GB) (Free:370.96 GB) NTFS Drive s: (WINDOWS APPS 2) (Fixed) (Total:931.51 GB) (Free:857.43 GB) NTFS Drive u: (FAST GAMES) (Fixed) (Total:931.51 GB) (Free:338.31 GB) NTFS \\?\Volume{c3993348-77a7-4943-9e3f-37af949a9092}\ (Recovery) (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS \\?\Volume{2ea66bad-02c4-4aca-82a1-047984976280}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 7C1B9398) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Protective MBR) (Size: 2794.5 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 2 (Size: 465.8 GB) (Disk ID: BDE5C9A5) Partition: GPT. ======================================================== Disk: 3 (MBR Code: Windows 7/8/10) (Size: 476.9 GB) (Disk ID: 84C6F80B) Partition 1: (Active) - (Size=476.9 GB) - (Type=07 NTFS) ======================================================== Disk: 4 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 00000001) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================