Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-09-2017 01
- Ran by Loaf (19-09-2017 19:44:12)
- Running from E:\Downloads
- Windows 10 Pro Version 1703 (X64) (2017-08-27 06:44:56)
- Boot Mode: Normal
- ==========================================================
- ==================== Accounts: =============================
- Administrator (S-1-5-21-1624113848-1791311199-1234011438-500 - Administrator - Disabled)
- DefaultAccount (S-1-5-21-1624113848-1791311199-1234011438-503 - Limited - Disabled)
- Guest (S-1-5-21-1624113848-1791311199-1234011438-501 - Limited - Disabled)
- Loaf (S-1-5-21-1624113848-1791311199-1234011438-1001 - Administrator - Enabled) => C:\Users\loafb
- ==================== Security Center ========================
- (If an entry is included in the fixlist, it will be removed.)
- AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- ==================== Installed Programs ======================
- (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
- 7-Zip 17.00 beta (x64) (HKLM\...\7-Zip) (Version: 17.00 beta - Igor Pavlov)
- Adobe Flash Player 26 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 26.0.0.151 - Adobe Systems Incorporated)
- Audacity 2.1.3 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.3 - Audacity Team)
- Blizzard App (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
- Borderless Gaming (HKLM-x32\...\Borderless Gaming_is1) (Version: 9.4.9 - Andrew Sampson)
- Bulk Rename Utility 3.0.0.1 (64-bit) (HKLM\...\Bulk Rename Utility Installation_is1) (Version: - TGRMN Software)
- CCleaner (HKLM\...\CCleaner) (Version: 5.33 - Piriform)
- Classic Sticky Notes (HKLM\...\Classic Sticky Notes_is1) (Version: 1.0 - Winaero)
- Dead Rising 2 (HKLM\...\Steam App 45740) (Version: - Capcom Vancouver)
- Discord (HKU\S-1-5-21-1624113848-1791311199-1234011438-1001\...\Discord) (Version: 0.0.298 - Discord Inc.)
- Dolphin (HKLM-x32\...\Dolphin) (Version: 5.0 - Dolphin Team)
- EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
- Epson Software Updater (HKLM-x32\...\{B55DB65D-EF6E-4E04-89D5-B03603BF681B}) (Version: 4.4.5 - SEIKO EPSON CORPORATION)
- EPSON XP-235 Series Printer Uninstall (HKLM\...\EPSON XP-235 Series) (Version: - Seiko Epson Corporation)
- Everything 1.4.1.877 (x64) (HKLM\...\Everything) (Version: 1.4.1.877 (x64) - David Carpenter)
- foobar2000 v1.3.16 (HKLM-x32\...\foobar2000) (Version: 1.3.16 - Peter Pawlowski)
- Garry's Mod (HKLM\...\Steam App 4000) (Version: - Facepunch Studios)
- GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com)
- Google Chrome (HKLM\...\{4EC552DD-5454-3B12-A15F-D84ED8DD24D7}) (Version: 60.0.3112.113 - Google, Inc.)
- Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
- Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4624 - Intel Corporation)
- IrfanView 4.44 (32-bit) (HKLM-x32\...\IrfanView) (Version: 4.44 - Irfan Skiljan)
- Java 8 Update 144 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180144F0}) (Version: 8.0.1440.1 - Oracle Corporation)
- Java 8 Update 144 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180144F0}) (Version: 8.0.1440.1 - Oracle Corporation)
- JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
- KB4023057 (HKLM\...\{ED06689A-33B7-4D35-8F76-36A82CD03406}) (Version: 2.3.0.0 - Microsoft Corporation)
- KeePass Password Safe 2.36 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.36 - Dominik Reichl)
- laucher game 0.02 (HKLM-x32\...\laucher game 0.02) (Version: 0.02 - launcher)
- Left 4 Dead (HKLM\...\Steam App 500) (Version: - Valve)
- LibreOffice 5.4.0.3 (HKLM\...\{992C4FE4-C278-4B62-A8B1-6FACB8E62980}) (Version: 5.4.0.3 - The Document Foundation)
- Malwarebytes version 3.2.2.2029 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2029 - Malwarebytes)
- Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
- Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
- Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
- Minecraft 1.12 (HKLM-x32\...\Minecraft 1.12) (Version: 1.12 - Minecraft)
- Minecraft1.9 (HKLM-x32\...\Minecraft1.9) (Version: - )
- Mp3tag v2.84a (HKLM-x32\...\Mp3tag) (Version: 2.84a - Florian Heidenreich)
- MusicBee 3.0 (HKLM-x32\...\MusicBee) (Version: 3.0 - Steven Mayall)
- Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.5 - Notepad++ Team)
- NVIDIA 3D Vision Driver 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.53 - NVIDIA Corporation)
- NVIDIA GeForce Experience 3.9.0.61 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.9.0.61 - NVIDIA Corporation)
- NVIDIA Graphics Driver 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.53 - NVIDIA Corporation)
- NVIDIA HD Audio Driver 1.3.34.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.17 - NVIDIA Corporation)
- persistence Module 0.02 (HKLM-x32\...\persistence Module 0.02) (Version: 0.02 - Microsoft Security)
- Plex Media Player (HKLM\...\{E73E3D31-9801-4555-A9DE-D50BA523B7F0}) (Version: 1.3.5 - Plex) Hidden
- Plex Media Player (HKLM-x32\...\{03645912-aed8-475f-b4d0-68c1dbfd634b}) (Version: 1.3.5 - Plex)
- Plex Media Server (HKLM-x32\...\{7118FBC6-F81D-43B9-B30A-51945CC1A0C8}) (Version: 1.8.4249 - Plex, Inc.) Hidden
- Plex Media Server (HKLM-x32\...\{dd96de17-0520-49fc-ab44-44e1710f6c77}) (Version: 1.8.4.4249 - Plex, Inc.)
- Project64 1.6 (HKLM-x32\...\{9559F7CA-5E34-4237-A2D9-D856464AD727}) (Version: 1.6 - Project64)
- qBittorrent 3.3.16 (HKLM-x32\...\qBittorrent) (Version: 3.3.16 - The qBittorrent project)
- Reason Core Security (HKLM-x32\...\Reason Core Security) (Version: 2.3.0.3 - Reason Software Company Inc.)
- Slime Rancher (HKLM\...\Steam App 433340) (Version: - Monomi Park)
- Speccy (HKLM\...\Speccy) (Version: 1.31 - Piriform)
- Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
- Stopping Plex (HKLM-x32\...\{68B69B2F-7F58-41DC-AB5E-05E4E735AB0A}) (Version: 1.8.4249 - Plex, Inc.) Hidden
- SumatraPDF (HKLM\...\SumatraPDF) (Version: 3.1.2 - Krzysztof Kowalczyk)
- The Witcher 3: Wild Hunt (HKLM\...\Steam App 292030) (Version: - CD PROJEKT RED)
- VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN)
- Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
- WhatsApp (HKU\S-1-5-21-1624113848-1791311199-1234011438-1001\...\WhatsApp) (Version: 0.2.5863 - WhatsApp)
- WinDirStat 1.1.2 (HKU\S-1-5-21-1624113848-1791311199-1234011438-1001\...\WinDirStat) (Version: - )
- WinImage (HKLM-x32\...\WinImage) (Version: - )
- ==================== Custom CLSID (Whitelisted): ==========================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- CustomCLSID: HKU\S-1-5-21-1624113848-1791311199-1234011438-1001_Classes\CLSID\{3189f3c9-de26-4d34-8333-338d28fe8f98}\InprocServer32 -> C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
- CustomCLSID: HKU\S-1-5-21-1624113848-1791311199-1234011438-1001_Classes\CLSID\{5b234f25-87c4-414c-9c3c-f0f473d385b6}\InprocServer32 -> C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
- CustomCLSID: HKU\S-1-5-21-1624113848-1791311199-1234011438-1001_Classes\CLSID\{a54ea86c-8ce2-4273-a489-7fd787f32172}\InprocServer32 -> C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
- CustomCLSID: HKU\S-1-5-21-1624113848-1791311199-1234011438-1001_Classes\CLSID\{aae47c39-0787-4833-a810-7f2e25c498f8}\InprocServer32 -> C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
- CustomCLSID: HKU\S-1-5-21-1624113848-1791311199-1234011438-1001_Classes\CLSID\{b45a8cdc-1e6f-4df2-ad70-1ac359527245}\InprocServer32 -> C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
- ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2017-04-29] (Igor Pavlov)
- ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2017-08-15] ()
- ContextMenuHandlers1: [BRUMenuHandler] -> {5D924130-4CB1-11DB-B0DE-0800200C9A66} => C:\Program Files\Bulk Rename Utility\BRUhere64.dll [2016-02-04] (Bulk Rename Utility)
- ContextMenuHandlers1: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2017-08-26] (Florian Heidenreich)
- ContextMenuHandlers2: [BRUMenuHandler] -> {5D924130-4CB1-11DB-B0DE-0800200C9A66} => C:\Program Files\Bulk Rename Utility\BRUhere64.dll [2016-02-04] (Bulk Rename Utility)
- ContextMenuHandlers2: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2017-08-26] (Florian Heidenreich)
- ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)
- ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2017-04-29] (Igor Pavlov)
- ContextMenuHandlers4: [BRUMenuHandler] -> {5D924130-4CB1-11DB-B0DE-0800200C9A66} => C:\Program Files\Bulk Rename Utility\BRUhere64.dll [2016-02-04] (Bulk Rename Utility)
- ContextMenuHandlers4: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2017-08-26] (Florian Heidenreich)
- ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
- ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2017-03-17] (Intel Corporation)
- ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-05-01] (NVIDIA Corporation)
- ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2017-04-29] (Igor Pavlov)
- ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)
- ==================== Scheduled Tasks (Whitelisted) =============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- Task: {0232E04A-F692-4C33-A4AB-4EC07630A868} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-08-18] (NVIDIA Corporation)
- Task: {188F52F7-7E3F-4F3D-A391-4B869A650B11} - System32\Tasks\DisableLockScreen => reg.exe add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\SessionData /t REG_DWORD /v AllowLockScreen /d 0 /f
- Task: {3306C094-8505-4BE7-A655-2D15F5E0AC7A} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-08-18] (NVIDIA Corporation)
- Task: {4089FAC5-F938-4EED-8761-356AC19E215C} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-08-18] (NVIDIA Corporation)
- Task: {40A830C7-5DF6-4271-9647-8E1E012BCBFD} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-08-18] (NVIDIA Corporation)
- Task: {58D1E4AD-94BB-49F1-AD0F-4A9491BBA1F4} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-08-18] (NVIDIA Corporation)
- Task: {6E7BB374-804B-4496-8EDC-33052198652E} - System32\Tasks\EPSON XP-235 Series Update {EF1FF16C-591A-4A10-A313-D1BD4456B134} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPFE.EXE [2013-11-22] (SEIKO EPSON CORPORATION)
- Task: {8BCDE4A4-BD4C-469C-9A75-B28F1C999DEB} - System32\Tasks\BorderlessGaming => C:\Program Files (x86)\Borderless Gaming\BorderlessGaming.exe [2017-07-05] (Andrew Sampson)
- Task: {9867BDA8-4570-42C0-A30F-8212997D3884} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe
- Task: {A5B63C52-26B8-4082-BD83-58CE5C9BAC79} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-08-27] (Google Inc.)
- Task: {BB3B90A6-D8E6-4B88-8C78-4A7B2CC164EB} - System32\Tasks\R@1n-KMS\Windows64Professional => wmic [Argument = path SoftwareLicensingProduct where (ID="2de67392-b7a7-462a-b1ca-108dd189f588") call Activate]
- Task: {C10065F3-DAB0-46B4-84E4-A45571449F2E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-08-27] (Google Inc.)
- Task: {D8557B11-6A76-4C3E-8E04-6767EEEE248D} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-08-18] (NVIDIA Corporation)
- Task: {ECE3EF5E-8580-4D17-AA6D-CC328A1AC11B} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-08-18] (NVIDIA Corporation)
- Task: {EE53A473-7361-4446-9E31-126B75F3D75A} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-08-18] (NVIDIA Corporation)
- (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
- Task: C:\WINDOWS\Tasks\EPSON XP-235 Series Update {EF1FF16C-591A-4A10-A313-D1BD4456B134}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPFE.EXE:/EXE:{EF1FF16C-591A-4A10-A313-D1BD4456B134} /F:UpdateWORKGROUP\DESKTOP-3KVDNDS$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
- ==================== Shortcuts & WMI ========================
- (The entries could be listed to be restored or removed.)
- ==================== Loaded Modules (Whitelisted) ==============
- 2017-09-18 21:10 - 2017-06-07 02:42 - 002197608 _____ () C:\Program Files\Everything\Everything.exe
- 2017-08-27 00:29 - 2017-08-27 00:29 - 000026112 _____ () C:\Windows\KMS-R@1n.exe
- 2017-08-30 20:36 - 2017-08-18 05:32 - 001267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
- 2017-09-18 20:52 - 2017-09-18 20:53 - 000302360 _____ () C:\Program Files\Reason\Security\Protection\rscp\bin\rscp_svc.exe
- 2017-09-17 23:20 - 2017-08-24 11:27 - 002264528 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
- 2017-09-18 20:52 - 2017-09-18 20:53 - 000626968 _____ () C:\Program Files\Reason\Security\Protection\rscp\bin\rscp_bg.exe
- 2017-03-18 21:58 - 2017-03-18 21:58 - 000138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
- 2017-03-18 21:59 - 2017-03-19 03:30 - 001731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
- 2017-09-07 17:30 - 2017-09-07 17:30 - 015744000 _____ () C:\Program Files (x86)\qBittorrent\qbittorrent.exe
- 2017-08-29 17:23 - 2017-08-29 17:23 - 001528296 _____ () C:\Program Files (x86)\Blizzard App\Battle.net.9262\Battle.net Helper.exe
- 2017-08-27 08:17 - 2017-08-27 08:17 - 003139496 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11707.1001.23.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
- 2017-08-27 08:19 - 2017-08-27 08:19 - 010600960 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11707.1001.23.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll
- 2017-08-27 08:19 - 2017-08-27 08:19 - 002640896 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11707.1001.23.0_x64__8wekyb3d8bbwe\MS.Entertainment.Common.Mobile.dll
- 2017-08-27 17:32 - 2017-08-23 18:49 - 002259968 _____ () C:\Users\loafb\AppData\Local\WhatsApp\app-0.2.5863\ffmpeg.dll
- 2017-09-19 19:38 - 2017-09-19 19:38 - 000486400 _____ () \\?\C:\Users\loafb\AppData\Local\Temp\C827.tmp.node
- 2017-09-19 19:38 - 2017-09-19 19:38 - 000221184 _____ () \\?\C:\Users\loafb\AppData\Local\Temp\D22A.tmp.node
- 2017-08-27 17:32 - 2017-08-23 18:49 - 002917376 _____ () C:\Users\loafb\AppData\Local\WhatsApp\app-0.2.5863\libglesv2.dll
- 2017-08-27 17:32 - 2017-08-23 18:49 - 000095232 _____ () C:\Users\loafb\AppData\Local\WhatsApp\app-0.2.5863\libegl.dll
- 2017-09-19 19:38 - 2017-09-19 19:38 - 000486400 _____ () \\?\C:\Users\loafb\AppData\Local\Temp\D1BC.tmp.node
- 2017-08-27 00:41 - 2017-08-23 09:48 - 003824472 _____ () C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.113\libglesv2.dll
- 2017-08-27 00:41 - 2017-08-23 09:48 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.113\libegl.dll
- 2017-08-27 00:29 - 2017-08-27 00:29 - 000005120 _____ () C:\WINDOWS\KMS-R@1nHook.exe
- 2017-08-27 00:29 - 2017-08-27 00:29 - 000004096 _____ () C:\WINDOWS\KMS-R@1nHook.dll
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000083432 _____ () C:\Program Files (x86)\Plex\Plex Media Server\zlib.dll
- 2017-09-07 04:27 - 2017-09-07 04:27 - 000203240 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libidn.dll
- 2017-08-27 07:47 - 2017-08-04 22:19 - 000678176 _____ () C:\Program Files (x86)\Steam\SDL2.dll
- 2017-08-27 07:47 - 2017-09-07 05:51 - 002505504 _____ () C:\Program Files (x86)\Steam\video.dll
- 2017-08-27 07:47 - 2016-09-01 02:02 - 004969248 _____ () C:\Program Files (x86)\Steam\v8.dll
- 2017-08-27 07:47 - 2016-01-27 08:49 - 002549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
- 2017-08-27 07:47 - 2016-01-27 08:49 - 000491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
- 2017-08-27 07:47 - 2016-01-27 08:49 - 000332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
- 2017-08-27 07:47 - 2016-01-27 08:49 - 000442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
- 2017-08-27 07:47 - 2016-01-27 08:49 - 000485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
- 2017-08-27 07:47 - 2016-09-01 02:02 - 001563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
- 2017-08-27 07:47 - 2016-09-01 02:02 - 001195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
- 2017-08-27 07:47 - 2017-09-07 05:51 - 000885024 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
- 2017-08-27 07:47 - 2016-07-04 23:17 - 000266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
- 2017-09-07 04:27 - 2017-09-07 04:27 - 001083368 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libxml2.dll
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000115688 _____ () C:\Program Files (x86)\Plex\Plex Media Server\soci_core-vc80-3_0.dll
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000059880 _____ () C:\Program Files (x86)\Plex\Plex Media Server\soci_sqlite3-vc80-3_0.dll
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000772072 _____ () C:\Program Files (x86)\Plex\Plex Media Server\tag.dll
- 2017-09-07 04:27 - 2017-09-07 04:27 - 001741288 _____ () C:\Program Files (x86)\Plex\Plex Media Server\opencv_imgproc2411.dll
- 2017-09-07 04:27 - 2017-09-07 04:27 - 001962984 _____ () C:\Program Files (x86)\Plex\Plex Media Server\opencv_core2411.dll
- 2017-09-07 04:27 - 2017-09-07 04:27 - 000025576 _____ () C:\Program Files (x86)\Plex\Plex Media Server\lyric_lite.dll
- 2017-09-07 04:27 - 2017-09-07 04:27 - 001549104 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libstdc++-6.dll
- 2017-09-07 04:27 - 2017-09-07 04:27 - 000127136 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libgcc_s_dw2-1.dll
- 2017-08-29 23:08 - 2017-08-08 15:13 - 001893880 _____ () C:\Users\loafb\AppData\Local\Discord\app-0.0.298\ffmpeg.dll
- 2017-08-29 23:08 - 2017-08-29 23:08 - 001577976 _____ () \\?\C:\Users\loafb\AppData\Roaming\discord\0.0.298\modules\discord_toaster\discord_toaster.node
- 2017-08-29 23:37 - 2017-09-12 08:48 - 001403384 _____ () \\?\C:\Users\loafb\AppData\Roaming\discord\0.0.298\modules\discord_overlay\discord_overlay.node
- 2017-08-27 07:48 - 2017-07-17 23:50 - 073115424 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
- 2017-08-27 07:48 - 2017-05-17 02:54 - 000678176 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
- 2017-08-27 07:47 - 2015-09-25 00:52 - 000119208 _____ () C:\Program Files (x86)\Steam\winh264.dll
- 2017-08-29 23:08 - 2017-08-08 15:13 - 001938424 _____ () C:\Users\loafb\AppData\Local\Discord\app-0.0.298\libglesv2.dll
- 2017-08-29 23:08 - 2017-08-08 15:13 - 000095736 _____ () C:\Users\loafb\AppData\Local\Discord\app-0.0.298\libegl.dll
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000050152 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_socket.pyd
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000071656 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ssl.pyd
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000024552 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_hashlib.pyd
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000041448 _____ () C:\Program Files (x86)\Plex\Plex Media Server\Exts\simplejson\_speedups.pyd
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000930280 _____ () C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\etree.pyd
- 2017-09-07 04:27 - 2017-09-07 04:27 - 000074728 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libexslt.dll
- 2017-09-07 04:27 - 2017-09-07 04:27 - 000190952 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libxslt.dll
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000218088 _____ () C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\objectify.pyd
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000018920 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\select.pyd
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000095720 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ctypes.pyd
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000143336 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\pyexpat.pyd
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000694248 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\unicodedata.pyd
- 2017-08-30 20:36 - 2017-08-18 05:31 - 069807552 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll
- 2017-08-30 20:36 - 2017-08-18 05:32 - 001040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
- 2017-08-29 17:24 - 2017-08-29 17:24 - 055782888 _____ () C:\Program Files (x86)\Blizzard App\Battle.net.9262\libcef.dll
- 2017-08-29 17:24 - 2017-08-29 17:24 - 000540336 _____ () C:\Program Files (x86)\Blizzard App\Battle.net.9262\ortp.dll
- 2017-08-29 17:24 - 2017-08-29 17:24 - 000133632 _____ () C:\Program Files (x86)\Blizzard App\Battle.net.9262\libEGL.dll
- 2017-08-29 17:24 - 2017-08-29 17:24 - 003384832 _____ () C:\Program Files (x86)\Blizzard App\Battle.net.9262\libGLESv2.dll
- 2017-08-29 23:08 - 2017-08-31 20:58 - 009622008 _____ () \\?\C:\Users\loafb\AppData\Roaming\discord\0.0.298\modules\discord_voice\discord_voice.node
- 2017-08-29 23:08 - 2017-08-29 23:08 - 001440248 _____ () \\?\C:\Users\loafb\AppData\Roaming\discord\0.0.298\modules\discord_utils\discord_utils.node
- 2017-09-19 17:22 - 2017-09-19 17:22 - 000148992 _____ () \\?\C:\Users\loafb\AppData\Local\Temp\3081.tmp.node
- 2017-08-29 23:08 - 2017-08-29 23:08 - 002658296 _____ () \\?\C:\Users\loafb\AppData\Roaming\discord\0.0.298\modules\discord_rpc\discord_rpc.node
- 2017-08-29 23:10 - 2017-08-29 23:10 - 002673656 _____ () \\?\C:\Users\loafb\AppData\Roaming\discord\0.0.298\modules\discord_contact_import\discord_contact_import.node
- 2017-09-07 04:28 - 2017-09-07 04:28 - 000064488 _____ () C:\Program Files (x86)\Plex\Plex Media Server\TeVii.dll
- 2017-08-27 07:48 - 2017-07-17 23:50 - 001936672 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\swiftshader\libglesv2.dll
- 2017-08-27 07:48 - 2017-07-17 23:50 - 000113952 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\swiftshader\libegl.dll
- ==================== Alternate Data Streams (Whitelisted) =========
- (If an entry is included in the fixlist, only the ADS will be removed.)
- AlternateDataStreams: C:\Users\loafb\AppData\Local\Temp:$DATA [16]
- ==================== Safe Mode (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
- ==================== Association (Whitelisted) ===============
- (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
- ==================== Internet Explorer trusted/restricted ===============
- (If an entry is included in the fixlist, it will be removed from the registry.)
- ==================== Hosts content: ==========================
- (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
- 2015-10-30 08:24 - 2017-09-19 17:21 - 000002103 _____ C:\WINDOWS\system32\Drivers\etc\hosts
- 0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
- 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
- 0.0.0.0 media.opencandy.com
- 0.0.0.0 cdn.opencandy.com
- 0.0.0.0 tracking.opencandy.com
- 0.0.0.0 api.opencandy.com
- 0.0.0.0 api.recommendedsw.com
- 0.0.0.0 rp.yefeneri2.com
- 0.0.0.0 os.yefeneri2.com
- 0.0.0.0 os2.yefeneri2.com
- 0.0.0.0 installer.betterinstaller.com
- 0.0.0.0 installer.filebulldog.com
- 0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
- 0.0.0.0 inno.bisrv.com
- 0.0.0.0 nsis.bisrv.com
- 0.0.0.0 cdn.file2desktop.com
- 0.0.0.0 cdn.goateastcach.us
- 0.0.0.0 cdn.guttastatdk.us
- 0.0.0.0 cdn.inskinmedia.com
- 0.0.0.0 cdn.insta.oibundles2.com
- 0.0.0.0 cdn.insta.playbryte.com
- 0.0.0.0 cdn.llogetfastcach.us
- 0.0.0.0 cdn.montiera.com
- 0.0.0.0 cdn.msdwnld.com
- 0.0.0.0 cdn.mypcbackup.com
- 0.0.0.0 cdn.ppdownload.com
- 0.0.0.0 cdn.riceateastcach.us
- 0.0.0.0 cdn.shyapotato.us
- 0.0.0.0 cdn.solimba.com
- 0.0.0.0 cdn.tuto4pc.com
- ==================== Other Areas ============================
- (Currently there is no automatic fix for this section.)
- HKU\S-1-5-21-1624113848-1791311199-1234011438-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\loafb\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
- DNS Servers: 192.168.1.254
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
- Windows Firewall is enabled.
- ==================== MSCONFIG/TASK MANAGER disabled items ==
- HKU\S-1-5-21-1624113848-1791311199-1234011438-1001\...\StartupApproved\Run: => "GalaxyClient"
- ==================== FirewallRules (Whitelisted) ===============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- FirewallRules: [{41C2AA04-FCA1-4CA2-8A5D-5CBCBC1F2AC8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
- FirewallRules: [{B2172B22-20FB-407D-BD29-349BD0878BF6}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
- FirewallRules: [{7C6AD2F3-62D3-4B73-ADDA-4C47E435F7D5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- FirewallRules: [{684069C2-46F5-4A50-8326-0C3EA84EDCE7}] => (Allow) C:\Windows\KMS-R@1n.exe
- FirewallRules: [{C69B08DB-C453-499A-A55F-1D0112123479}] => (Allow) C:\Windows\KMS-R@1n.exe
- FirewallRules: [{A233EC9B-2DC5-4047-8094-7DCDD1ED030D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
- FirewallRules: [{2A7CD2B9-1431-4309-B9A1-298BB96549CA}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
- FirewallRules: [TCP Query User{F18956DB-44D0-4527-88E5-21615A4780BA}C:\program files\qbittorrent\qbittorrent.exe] => (Allow) C:\program files\qbittorrent\qbittorrent.exe
- FirewallRules: [UDP Query User{F31E6B73-0357-4515-BB57-002517FCB8FB}C:\program files\qbittorrent\qbittorrent.exe] => (Allow) C:\program files\qbittorrent\qbittorrent.exe
- FirewallRules: [{A1AA7F1F-CBD8-466A-8810-5F3FA674F68C}] => (Allow) C:\Program Files\Plex\Plex Media Player\PlexMediaPlayer.exe
- FirewallRules: [{E13EBFA9-6ED1-4A8C-BC7E-605601615F6A}] => (Allow) C:\Program Files\Plex\Plex Media Player\PMPHelper.exe
- FirewallRules: [TCP Query User{0608EC2C-A0BB-4886-A4D8-D75C301397BE}C:\program files (x86)\blizzard app\battle.net.9262\battle.net.exe] => (Allow) C:\program files (x86)\blizzard app\battle.net.9262\battle.net.exe
- FirewallRules: [UDP Query User{58157E2C-EDF6-4548-8569-AB486BD748A2}C:\program files (x86)\blizzard app\battle.net.9262\battle.net.exe] => (Allow) C:\program files (x86)\blizzard app\battle.net.9262\battle.net.exe
- FirewallRules: [{4BF1CDAA-E3CE-4C6C-88E7-F4C5E1E15106}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
- FirewallRules: [{405240B2-215E-43C0-9EFD-E99086C7644A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
- FirewallRules: [{9E9B14A1-640A-49AE-A523-5930DD5DBE52}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
- FirewallRules: [{A4E07308-D929-43B1-AF67-3D12A69BEA38}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
- FirewallRules: [{C7CC29A2-8A93-4535-94BD-704F7190F311}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
- FirewallRules: [{5D4FD049-A58D-49FD-8CDB-4DA94789759A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dead Rising 2\deadrising2.exe
- FirewallRules: [{9BFB68DB-7416-4159-89B9-9150BC16C34A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dead Rising 2\deadrising2.exe
- FirewallRules: [{BECD24DA-18C1-45E8-ABD0-98D6B510B386}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe
- FirewallRules: [{533B9D65-47C8-40A4-8D84-B3815E3C9344}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe
- FirewallRules: [TCP Query User{69D85777-EABA-4A60-833C-CBE14BA8537D}C:\program files (x86)\qbittorrent\qbittorrent.exe] => (Allow) C:\program files (x86)\qbittorrent\qbittorrent.exe
- FirewallRules: [UDP Query User{1BD575D8-D7C5-495B-B35B-C513F78B0F4B}C:\program files (x86)\qbittorrent\qbittorrent.exe] => (Allow) C:\program files (x86)\qbittorrent\qbittorrent.exe
- FirewallRules: [{920E28EE-0E74-4B15-836B-D2C561615E85}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
- FirewallRules: [{A6F08DCD-04ED-4BB4-BA97-8DEB73B0FE17}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
- FirewallRules: [{CBE6AD22-DFD8-48E4-B397-568A5F54B8CD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Slime Rancher\SlimeRancher.exe
- FirewallRules: [{2EAF58B4-502A-4DD5-A199-6246967B9E60}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Slime Rancher\SlimeRancher.exe
- FirewallRules: [{713EADD5-C01E-46A9-8287-DF6B5649224A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Witcher 3\bin\x64\witcher3.exe
- FirewallRules: [{7AADBE74-A630-4901-A7C5-01EF53E99E67}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Witcher 3\bin\x64\witcher3.exe
- FirewallRules: [{B6821F0C-AE05-4B39-966C-A7332FC89F1B}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
- FirewallRules: [{94F187CA-0363-46A2-83AA-6C408EE06EDB}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
- FirewallRules: [{DBB0B37D-EF4F-4424-8224-5D89135757A9}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe
- FirewallRules: [{B44FC198-A55B-471D-8C8B-7C5F81AA564C}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe
- FirewallRules: [TCP Query User{6D4651D4-5F1D-420C-A950-56B4E13EF483}D:\super mario 64 online\sm64o.exe] => (Allow) D:\super mario 64 online\sm64o.exe
- FirewallRules: [UDP Query User{576CF2FB-AFAF-4279-BBA8-A1EA3FD35F7C}D:\super mario 64 online\sm64o.exe] => (Allow) D:\super mario 64 online\sm64o.exe
- FirewallRules: [{39086079-CEFC-43D8-83CC-746BD6B307B1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\left 4 dead\left4dead.exe
- FirewallRules: [{E06D71AB-C492-4FB5-A9AB-757E8346CA36}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\left 4 dead\left4dead.exe
- FirewallRules: [TCP Query User{DA8443BB-C609-4805-B316-F76959418EE5}C:\program files\java\jre1.8.0_144\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_144\bin\javaw.exe
- FirewallRules: [UDP Query User{E7EB2D3A-47E6-4B88-9E26-D6F8C850868A}C:\program files\java\jre1.8.0_144\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_144\bin\javaw.exe
- FirewallRules: [{3BB73A8C-9F1F-4133-BDF0-D5391FE756D7}] => (Allow) F:\SteamLibrary\steamapps\common\Left 4 Dead 2\left4dead2.exe
- FirewallRules: [{9E037590-7A33-4522-A227-D558D84D0A4E}] => (Allow) F:\SteamLibrary\steamapps\common\Left 4 Dead 2\left4dead2.exe
- FirewallRules: [{EF56E385-0184-4A40-803E-E9D00EFB569C}] => (Allow) F:\SteamLibrary\steamapps\common\Half-Life\hl.exe
- FirewallRules: [{DE75B9DE-85D7-483B-99EC-A3645E81C88C}] => (Allow) F:\SteamLibrary\steamapps\common\Half-Life\hl.exe
- FirewallRules: [{5FC0AD74-3BE7-4033-A9CE-AFBC9C6D97D6}] => (Allow) F:\SteamLibrary\steamapps\common\Half-Life 2\hl2.exe
- FirewallRules: [{0FF77D3E-2935-44CE-967C-837893C60D4E}] => (Allow) F:\SteamLibrary\steamapps\common\Half-Life 2\hl2.exe
- FirewallRules: [{019F501B-53D6-4171-9467-8C54EC2B36D3}] => (Allow) F:\SteamLibrary\steamapps\common\Half-Life 2 Deathmatch\hl2.exe
- FirewallRules: [{9614EB6A-B233-473D-936E-49597A8C6DAB}] => (Allow) F:\SteamLibrary\steamapps\common\Half-Life 2 Deathmatch\hl2.exe
- FirewallRules: [{35174336-79DE-4271-9787-A4B265A0EC65}] => (Allow) F:\SteamLibrary\steamapps\common\Half-Life 1 Source Deathmatch\hl2.exe
- FirewallRules: [{DCE6E219-FADE-49ED-97C4-38095D47381E}] => (Allow) F:\SteamLibrary\steamapps\common\Half-Life 1 Source Deathmatch\hl2.exe
- FirewallRules: [{53E72EDC-354A-407B-B91B-96B1FDFCF2CC}] => (Allow) F:\SteamLibrary\steamapps\common\Portal\hl2.exe
- FirewallRules: [{32E4ABCF-E651-416B-9580-8C03059A081A}] => (Allow) F:\SteamLibrary\steamapps\common\Portal\hl2.exe
- ==================== Restore Points =========================
- 05-09-2017 14:19:46 Scheduled Checkpoint
- 11-09-2017 08:42:00 Plex Media Server
- 12-09-2017 12:39:05 Installed Project64 1.6
- 17-09-2017 09:46:23 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
- ==================== Faulty Device Manager Devices =============
- ==================== Event log errors: =========================
- Application errors:
- ==================
- Error: (09/19/2017 05:25:00 PM) (Source: SideBySide) (EventID: 78) (User: )
- Description: Activation context generation failed for "C:\Program Files (x86)\Audacity\audacity.exe".Error in manifest or policy file "" on line .
- A component version required by the application conflicts with another component version already active.
- Conflicting components are:.
- Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest.
- Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest.
- Error: (09/19/2017 05:23:33 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: BorderlessGaming.exe, version: 9.4.9.1328, time stamp: 0x595d36c1
- Faulting module name: KERNELBASE.dll, version: 10.0.15063.502, time stamp: 0xc3955624
- Exception code: 0xe0434352
- Fault offset: 0x000eb802
- Faulting process id: 0x7ec
- Faulting application start time: 0x01d331637092a776
- Faulting application path: C:\Program Files (x86)\Borderless Gaming\BorderlessGaming.exe
- Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
- Report Id: f986de87-61e9-4047-86f3-39088befef17
- Faulting package full name:
- Faulting package-relative application ID:
- Error: (09/19/2017 05:23:32 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
- Description: Application: BorderlessGaming.exe
- Framework Version: v4.0.30319
- Description: The process was terminated due to an unhandled exception.
- Exception Info: ProtoBuf.ProtoException
- at ProtoBuf.ProtoReader.CheckFullyConsumed()
- at ProtoBuf.Meta.TypeModel.Deserialize(System.IO.Stream, System.Object, System.Type, ProtoBuf.SerializationContext)
- at ProtoBuf.Serializer.Deserialize[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.IO.Stream)
- at BorderlessGaming.Logic.Windows.Security.LoadConfigFile()
- at BorderlessGaming.Logic.Models.Config.Load()
- at BorderlessGaming.Logic.System.Tools.Setup()
- at BorderlessGaming.Program.Main()
- Error: (09/18/2017 09:10:45 PM) (Source: SideBySide) (EventID: 78) (User: )
- Description: Activation context generation failed for "C:\Program Files (x86)\Audacity\audacity.exe".Error in manifest or policy file "" on line .
- A component version required by the application conflicts with another component version already active.
- Conflicting components are:.
- Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest.
- Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest.
- Error: (09/18/2017 08:59:10 PM) (Source: SideBySide) (EventID: 78) (User: )
- Description: Activation context generation failed for "C:\Program Files (x86)\Audacity\audacity.exe".Error in manifest or policy file "" on line .
- A component version required by the application conflicts with another component version already active.
- Conflicting components are:.
- Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest.
- Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest.
- Error: (09/18/2017 08:52:53 PM) (Source: SideBySide) (EventID: 78) (User: )
- Description: Activation context generation failed for "C:\Program Files (x86)\Audacity\audacity.exe".Error in manifest or policy file "" on line .
- A component version required by the application conflicts with another component version already active.
- Conflicting components are:.
- Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest.
- Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest.
- Error: (09/18/2017 08:31:44 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: mbam.exe, version: 3.0.0.1169, time stamp: 0x599723f1
- Faulting module name: Qt5Core.dll, version: 5.6.2.0, time stamp: 0x59a63e00
- Exception code: 0xc0000005
- Fault offset: 0x0018de83
- Faulting process id: 0x257c
- Faulting application start time: 0x01d330b4b69c7ce4
- Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
- Faulting module path: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
- Report Id: dd8c81ba-2bed-46c9-bc4e-0ebf2d862b54
- Faulting package full name:
- Faulting package-relative application ID:
- Error: (09/18/2017 08:30:47 PM) (Source: Perflib) (EventID: 1008) (User: )
- Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
- Error: (09/18/2017 07:54:53 PM) (Source: SideBySide) (EventID: 78) (User: )
- Description: Activation context generation failed for "C:\Program Files (x86)\Audacity\audacity.exe".Error in manifest or policy file "" on line .
- A component version required by the application conflicts with another component version already active.
- Conflicting components are:.
- Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest.
- Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest.
- Error: (09/17/2017 11:22:19 PM) (Source: SideBySide) (EventID: 78) (User: )
- Description: Activation context generation failed for "C:\Program Files (x86)\Audacity\audacity.exe".Error in manifest or policy file "" on line .
- A component version required by the application conflicts with another component version already active.
- Conflicting components are:.
- Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest.
- Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest.
- System errors:
- =============
- Error: (09/19/2017 05:21:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
- Description: The CldFlt service failed to start due to the following error:
- The request is not supported.
- Error: (09/19/2017 05:21:55 PM) (Source: EventLog) (EventID: 6008) (User: )
- Description: The previous system shutdown at 12:08:08 AM on 9/19/2017 was unexpected.
- Error: (09/19/2017 12:08:08 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
- Description: The CldFlt service failed to start due to the following error:
- The request is not supported.
- Error: (09/19/2017 12:07:58 AM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT AUTHORITY)
- Description: 32212256841279408
- Error: (09/19/2017 12:08:08 AM) (Source: EventLog) (EventID: 6008) (User: )
- Description: The previous system shutdown at 11:39:45 PM on 9/18/2017 was unexpected.
- Error: (09/18/2017 09:15:35 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
- Description: The KMS-R@1n service terminated unexpectedly. It has done this 1 time(s).
- Error: (09/18/2017 08:59:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
- Description: The CldFlt service failed to start due to the following error:
- The request is not supported.
- Error: (09/18/2017 07:51:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
- Description: The CldFlt service failed to start due to the following error:
- The request is not supported.
- Error: (09/18/2017 07:51:42 PM) (Source: EventLog) (EventID: 6008) (User: )
- Description: The previous system shutdown at 10:57:57 PM on 9/17/2017 was unexpected.
- Error: (09/18/2017 07:51:32 PM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT AUTHORITY)
- Description: 32212256841211280
- CodeIntegrity:
- ===================================
- Date: 2017-09-17 23:23:19.417
- Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
- Date: 2017-09-17 23:22:40.958
- Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
- Date: 2017-09-17 23:22:40.709
- Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
- Date: 2017-09-17 23:20:59.270
- Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
- Date: 2017-09-17 23:20:59.269
- Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
- Date: 2017-09-17 23:20:59.241
- Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
- Date: 2017-09-17 23:18:31.510
- Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
- Date: 2017-09-17 23:18:29.630
- Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
- Date: 2017-09-14 13:22:17.245
- Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
- Date: 2017-09-06 22:41:42.349
- Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
- ==================== Memory info ===========================
- Processor: Intel(R) Core(TM) i5-4670K CPU @ 3.40GHz
- Percentage of memory in use: 49%
- Total physical RAM: 8079.13 MB
- Available physical RAM: 4058.06 MB
- Total Virtual: 9359.13 MB
- Available Virtual: 4436.4 MB
- ==================== Drives ================================
- Drive c: () (Fixed) (Total:110.41 GB) (Free:10.74 GB) NTFS
- Drive d: (EMULATORS) (Fixed) (Total:931.51 GB) (Free:361.25 GB) NTFS
- Drive e: (MEDIA) (Fixed) (Total:5588.9 GB) (Free:4978.11 GB) NTFS
- Drive f: (PC GAMES) (Fixed) (Total:2794.39 GB) (Free:1772.68 GB) NTFS
- Drive g: (Gallagher External) (Fixed) (Total:1863.01 GB) (Free:751.55 GB) NTFS
- ==================== MBR & Partition Table ==================
- ========================================================
- Disk: 0 (Size: 111.8 GB) (Disk ID: 91138512)
- Partition: GPT.
- ========================================================
- Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A4B2E8ED)
- Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
- ========================================================
- Disk: 2 (MBR Code: Windows 7 or 8) (Size: 5589 GB) (Disk ID: 00000000)
- Partition: GPT.
- ========================================================
- Disk: 3 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 00000000)
- Partition: GPT.
- ========================================================
- Disk: 4 (Size: 1863 GB) (Disk ID: C4AFF0F7)
- Partition 1: (Active) - (Size=1863 GB) - (Type=07 NTFS)
- ==================== End of Addition.txt ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement