Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-07-2017
- Ran by Antec (04-07-2017 16:10:44)
- Running from C:\Users\Antec\Downloads
- Windows 10 Pro Version 1703 (X64) (2017-06-07 22:41:36)
- Boot Mode: Normal
- ==========================================================
- ==================== Accounts: =============================
- Administrator (S-1-5-21-2443440379-2010847049-395336280-500 - Administrator - Disabled)
- Antec (S-1-5-21-2443440379-2010847049-395336280-1001 - Administrator - Enabled) => C:\Users\Antec
- DefaultAccount (S-1-5-21-2443440379-2010847049-395336280-503 - Limited - Disabled)
- Guest (S-1-5-21-2443440379-2010847049-395336280-501 - Limited - Disabled)
- ==================== Security Center ========================
- (If an entry is included in the fixlist, it will be removed.)
- AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- ==================== Installed Programs ======================
- (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
- Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 382.05 - NVIDIA Corporation) Hidden
- Apple Application Support (32-bit) (HKLM-x32\...\{E92BB800-BCC5-4C25-8102-AC2C3B7C7C1E}) (Version: 5.5 - Apple Inc.)
- Apple Application Support (64-bit) (HKLM\...\{9C912B1E-06DD-43EF-BB2B-45CB2C88BAAE}) (Version: 5.5 - Apple Inc.)
- Apple Mobile Device Support (HKLM\...\{0A596141-97D5-45FA-9281-98DFAF48D579}) (Version: 10.3.2.3 - Apple Inc.)
- Apple Software Update (HKLM-x32\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.)
- BitTorrent (HKU\S-1-5-21-2443440379-2010847049-395336280-1001\...\BitTorrent) (Version: 7.10.0.43581 - BitTorrent Inc.)
- Blizzard App (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
- Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
- Borderlands 2 (HKLM\...\Steam App 49520) (Version: - Gearbox Software)
- CCleaner (HKLM\...\CCleaner) (Version: 5.31 - Piriform)
- Cities: Skylines (HKLM\...\Steam App 255710) (Version: - Colossal Order Ltd.)
- Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve)
- Dirty Bomb (HKLM\...\Steam App 333930) (Version: - Splash Damage®)
- Dota 2 (HKLM\...\Steam App 570) (Version: - Valve)
- Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
- Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
- H1Z1: King of the Kill (HKLM\...\Steam App 433850) (Version: - Daybreak Game Company)
- Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
- iTunes (HKLM\...\{F0C7385A-9D20-45F3-8101-05D383885180}) (Version: 12.6.1.25 - Apple Inc.)
- Java 8 Update 121 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
- KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version: - )
- LibreOffice 5.3.3.2 (HKLM\...\{DB76C19A-1E2A-4A8F-9AB7-3FC315EC57C7}) (Version: 5.3.3.2 - The Document Foundation)
- MapleStory (HKLM\...\Steam App 216150) (Version: - Nexon)
- Microsoft OneDrive (HKU\S-1-5-21-2443440379-2010847049-395336280-1001\...\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
- Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
- Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
- Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
- Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
- Mozilla Firefox 53.0.3 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 53.0.3 (x86 en-US)) (Version: 53.0.3 - Mozilla)
- Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0.3 - Mozilla)
- NETGEAR WNA3100 wireless USB 2.0 driver (HKLM-x32\...\{C2425F91-1F7B-4037-9A05-9F290184798D}) (Version: 2.2.0.2 - NETGEAR)
- Nexon Launcher (HKLM-x32\...\Nexon Nexon Launcher) (Version: 2.0.0 - Nexon)
- NVIDIA 3D Vision Driver 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 382.05 - NVIDIA Corporation)
- NVIDIA Graphics Driver 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 382.05 - NVIDIA Corporation)
- NVIDIA HD Audio Driver 1.3.34.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.26 - NVIDIA Corporation)
- NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
- NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
- Origin (HKLM-x32\...\Origin) (Version: 10.4.13.6637 - Electronic Arts, Inc.)
- Paladins (HKLM\...\Steam App 444090) (Version: - Hi-Rez Studios)
- Paws & Claws: Pet Vet (HKLM\...\Steam App 33720) (Version: - dtp – young entertainment Gmbh & Co. KG)
- PAYDAY 2 (HKLM\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.)
- PLAYERUNKNOWN'S BATTLEGROUNDS (HKLM\...\Steam App 578080) (Version: - Bluehole, Inc.)
- Raw Vengeance Launcher version 0.0.3 (HKLM-x32\...\{E610898A-20AB-4F81-96C0-184A754315D9}_is1) (Version: 0.0.3 - Raw Vengeance UG)
- Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
- TakeOwnershipEx (HKLM-x32\...\TakeOwnershipEx) (Version: 1.2.0.1 - hxxp://winaero.com)
- Team Fortress 2 (HKLM\...\Steam App 440) (Version: - Valve)
- UE4 Prerequisites (x86) (HKLM-x32\...\{6EAAE1C0-6000-45FA-B46D-D206144925BF}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden
- UE4 Prerequisites (x86) (HKLM-x32\...\{f1203e43-4ddb-4280-974e-73f14d793dbd}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden
- Universal Media Server (HKLM-x32\...\Universal Media Server) (Version: 7.0.0-b2-SNAPSHOT - Universal Media Server)
- VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN)
- Vulkan Run Time Libraries 1.0.42.1 (HKLM\...\VulkanRT1.0.42.1) (Version: 1.0.42.1 - LunarG, Inc.)
- Warframe (HKLM\...\Steam App 230410) (Version: - Digital Extremes)
- WinRAR 5.50 beta 3 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.3 - win.rar GmbH)
- ==================== Custom CLSID (Whitelisted): ==========================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- ContextMenuHandlers01: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-06-12] (Alexander Roshal)
- ContextMenuHandlers01: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
- ContextMenuHandlers05: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2017-05-01] (NVIDIA Corporation)
- ContextMenuHandlers06: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-06-12] (Alexander Roshal)
- ContextMenuHandlers06: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
- ==================== Scheduled Tasks (Whitelisted) =============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- Task: {3AA88DE3-9160-4A0E-897E-83C096DEA57F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-12] (Google Inc.)
- Task: {5D6DCA88-E823-4C3D-9515-8530F5BF0A40} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2015-12-01] (@ByELDI)
- Task: {A25E2E57-A965-430C-A148-FC095371FB70} - System32\Tasks\S-1-5-21-2443440379-2010847049-395336280-1001\DataSenseLiveTileTask => C:\Windows\System32\DataUsageLiveTileTask.exe [2017-03-18] (Microsoft Corporation)
- Task: {CED7623B-2F23-4D50-92E0-7EE45BB97819} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-06-13] (Piriform Ltd)
- Task: {EA7344D6-A9F4-4671-BE06-F441A8B50C40} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-12] (Google Inc.)
- (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
- ==================== Shortcuts & WMI ========================
- (The entries could be listed to be restored or removed.)
- ShortcutWithArgument: C:\Users\Antec\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1"
- ==================== Loaded Modules (Whitelisted) ==============
- 2017-05-09 00:44 - 2017-05-09 00:44 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
- 2017-05-09 00:44 - 2017-05-09 00:44 - 01354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
- 2017-06-07 18:11 - 2014-08-18 17:50 - 00316120 _____ () C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe
- 2017-03-18 13:58 - 2017-03-18 13:58 - 00138000 _____ () C:\Windows\SYSTEM32\inputhost.dll
- 2017-03-18 13:59 - 2017-03-18 19:30 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
- 2017-05-09 03:05 - 2017-05-09 03:05 - 00092472 _____ () C:\Program Files\iTunes\zlib1.dll
- 2017-05-09 03:05 - 2017-05-09 03:05 - 01354040 _____ () C:\Program Files\iTunes\libxml2.dll
- 2017-06-23 00:20 - 2017-06-23 00:25 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe
- 2017-06-23 00:20 - 2017-06-23 00:25 - 00203264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
- 2017-06-23 00:20 - 2017-06-23 00:27 - 43454464 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkyWrap.dll
- 2017-06-23 00:20 - 2017-06-23 00:25 - 02437120 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\skypert.dll
- 2017-06-12 17:53 - 2017-06-12 17:53 - 03139496 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11705.1001.21.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
- 2017-06-23 00:29 - 2017-06-23 00:46 - 00766464 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11705.1001.21.0_x64__8wekyb3d8bbwe\WinStore.Vui.dll
- 2017-06-23 00:29 - 2017-06-23 00:46 - 10628608 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11705.1001.21.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll
- 2017-06-23 00:29 - 2017-06-23 00:31 - 02640384 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11705.1001.21.0_x64__8wekyb3d8bbwe\MS.Entertainment.Common.Mobile.dll
- 2017-06-23 00:49 - 2017-06-23 00:50 - 01199816 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.41125.0_x64__8wekyb3d8bbwe\Office.UI.Xaml.Word.dll
- 2017-06-23 00:49 - 2017-06-23 00:50 - 13207232 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.41125.0_x64__8wekyb3d8bbwe\Office.UI.Xaml.Core.dll
- 2017-06-13 15:41 - 2017-06-13 15:41 - 04323840 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1706.1602.0_x64__8wekyb3d8bbwe\Calculator.exe
- 2017-06-12 17:55 - 2017-06-12 17:55 - 03500456 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1706.1602.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
- 2017-06-28 16:02 - 2017-06-22 20:21 - 03807064 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\libglesv2.dll
- 2017-06-28 16:02 - 2017-06-22 20:21 - 00100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\libegl.dll
- 2017-06-07 18:11 - 2015-02-26 20:19 - 00380928 _____ () C:\Program Files (x86)\NETGEAR\WNA3100\WifiLib.dll
- 2017-06-26 14:40 - 2017-06-26 21:46 - 02493440 _____ () C:\Program Files (x86)\Origin\libGLESv2.dll
- 2017-06-23 02:02 - 2017-05-16 18:54 - 00678176 _____ () C:\Program Files (x86)\Steam\SDL2.dll
- 2017-06-23 02:01 - 2017-06-07 22:42 - 02485536 _____ () C:\Program Files (x86)\Steam\video.dll
- 2017-06-23 02:01 - 2016-08-31 18:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll
- 2017-06-23 02:01 - 2016-01-27 00:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
- 2017-06-23 02:01 - 2016-01-27 00:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
- 2017-06-23 02:01 - 2016-01-27 00:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
- 2017-06-23 02:01 - 2016-01-27 00:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
- 2017-06-23 02:01 - 2016-01-27 00:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
- 2017-06-23 02:01 - 2016-08-31 18:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
- 2017-06-23 02:01 - 2016-08-31 18:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
- 2017-06-23 02:01 - 2017-06-07 22:42 - 00877856 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
- 2017-06-23 02:01 - 2016-07-04 15:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
- 2017-06-23 02:02 - 2017-05-16 18:54 - 00678176 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
- 2017-06-23 02:02 - 2017-05-08 12:45 - 69516064 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
- 2017-06-23 02:01 - 2017-06-07 22:42 - 00385312 _____ () C:\Program Files (x86)\Steam\steam.dll
- ==================== Alternate Data Streams (Whitelisted) =========
- (If an entry is included in the fixlist, only the ADS will be removed.)
- ==================== Safe Mode (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
- ==================== Association (Whitelisted) ===============
- (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
- ==================== Internet Explorer trusted/restricted ===============
- (If an entry is included in the fixlist, it will be removed from the registry.)
- ==================== Hosts content: ===============================
- (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
- 2017-03-18 14:03 - 2017-03-18 14:01 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts
- ==================== Other Areas ============================
- (Currently there is no automatic fix for this section.)
- HKU\S-1-5-21-2443440379-2010847049-395336280-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Antec\Desktop\skyline-buildings-new-york-skyscrapers.jpg
- DNS Servers: 192.168.1.1
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
- Windows Firewall is enabled.
- ==================== MSCONFIG/TASK MANAGER disabled items ==
- HKU\S-1-5-21-2443440379-2010847049-395336280-1001\...\StartupApproved\Run: => "EADM"
- ==================== FirewallRules (Whitelisted) ===============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- FirewallRules: [{96C6E4CB-AE45-452B-AF9E-770FB7354007}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- FirewallRules: [{D8C271C3-9990-4313-A83A-3BAC38C4D75F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- FirewallRules: [{70DA006B-9A81-43F0-9C78-EF3F365DE649}] => (Allow) C:\Users\Antec\AppData\Roaming\BitTorrent\BitTorrent.exe
- FirewallRules: [{C654FEAF-A2AA-480A-A6A3-76DCCF0A103F}] => (Allow) C:\Users\Antec\AppData\Roaming\BitTorrent\BitTorrent.exe
- FirewallRules: [{28DBD508-FDF8-4C46-AA60-A72CBA38E5B6}] => (Allow) C:\Users\Antec\AppData\Roaming\BitTorrent\BitTorrent.exe
- FirewallRules: [{C39AF40B-654A-41DE-BBED-7F965730D6CB}] => (Allow) C:\Users\Antec\AppData\Roaming\BitTorrent\BitTorrent.exe
- FirewallRules: [{4ABC72D8-B613-4295-B60C-7F262B59828E}] => (Allow) C:\Users\Antec\AppData\Roaming\BitTorrent\BitTorrent.exe
- FirewallRules: [{C63E4E0F-02ED-4793-B9B1-84D43E9A9BAC}] => (Allow) C:\Users\Antec\AppData\Roaming\BitTorrent\BitTorrent.exe
- FirewallRules: [{E30B8673-2657-482F-B661-66F81BE60A36}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
- FirewallRules: [{5FABC50B-89EB-4111-BC43-CCB28F62B1B0}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
- FirewallRules: [{21E0E94C-00D9-4402-AFF4-4964E1C30FD3}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
- FirewallRules: [{FA29C9F1-0D3C-44EA-BD24-32C3A166A100}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
- FirewallRules: [{98F4E74B-B7C2-4C73-9ED8-FE0FB5AEFE24}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
- FirewallRules: [{44838209-1CC7-48DD-99B6-1969078ABADA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
- FirewallRules: [{EF5335D9-5BFF-47D2-B990-14E33C5BCE9C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
- FirewallRules: [{BEDB6524-3E41-4EFE-B746-832FB7529E98}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
- FirewallRules: [{CFDC9205-2E4F-47CA-9A2F-5B8939883397}] => (Allow) C:\Program Files\iTunes\iTunes.exe
- FirewallRules: [TCP Query User{34107FEC-8EA9-460D-9A18-39CE3C276944}C:\program files\java\jre1.8.0_121\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_121\bin\javaw.exe
- FirewallRules: [UDP Query User{89BD00A2-B071-4680-811D-EA4547B9FF78}C:\program files\java\jre1.8.0_121\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_121\bin\javaw.exe
- FirewallRules: [TCP Query User{DB2DEEA8-69F2-4E1A-AEFE-390703637ECB}C:\users\antec\desktop\renegade line (portable)\rgline_template\binaries\win32\rgline_template-win32-shipping.exe] => (Allow) C:\users\antec\desktop\renegade line (portable)\rgline_template\binaries\win32\rgline_template-win32-shipping.exe
- FirewallRules: [UDP Query User{A2AF3E02-7C69-497C-9755-B4BF940F736A}C:\users\antec\desktop\renegade line (portable)\rgline_template\binaries\win32\rgline_template-win32-shipping.exe] => (Allow) C:\users\antec\desktop\renegade line (portable)\rgline_template\binaries\win32\rgline_template-win32-shipping.exe
- FirewallRules: [{AD6BCE0C-CBC4-4201-95A9-80A75AEEFA40}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\DirtyBombLauncher.exe
- FirewallRules: [{EE0D0ADD-FF30-428D-84DC-D3AFC0B31576}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\DirtyBombLauncher.exe
- FirewallRules: [TCP Query User{D32BCA26-E5C0-401A-ABBC-80AAA8637AA9}C:\program files (x86)\steam\steamapps\common\dirty bomb\binaries\win32\shootergame-win32-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dirty bomb\binaries\win32\shootergame-win32-shipping.exe
- FirewallRules: [UDP Query User{CE9DC2DC-5C51-450C-9C33-EFBF78412656}C:\program files (x86)\steam\steamapps\common\dirty bomb\binaries\win32\shootergame-win32-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dirty bomb\binaries\win32\shootergame-win32-shipping.exe
- FirewallRules: [TCP Query User{A64A4BBA-040D-474C-8F4A-859CFF4D1F66}C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe
- FirewallRules: [UDP Query User{E44B38C0-7BB4-4F40-89C2-1C95FB1FAFBE}C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe
- FirewallRules: [{4B4C72D1-16F5-4C3B-8599-3F8BCECAB013}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
- FirewallRules: [{68C8827E-C275-4982-8B3A-F214BBD1B3BC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
- FirewallRules: [TCP Query User{D54EE6A4-0A38-4A6B-91E8-EEB135CB649A}C:\program files (x86)\diablo iii\x64\diablo iii64.exe] => (Block) C:\program files (x86)\diablo iii\x64\diablo iii64.exe
- FirewallRules: [UDP Query User{5D816F9E-77E5-4A16-AF1D-397AD53C59B9}C:\program files (x86)\diablo iii\x64\diablo iii64.exe] => (Block) C:\program files (x86)\diablo iii\x64\diablo iii64.exe
- FirewallRules: [{FBA29214-E1B8-48DB-ACB3-19375F531C46}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
- FirewallRules: [{B763F7F5-901D-4036-BF6E-9DD3F5C8367E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
- FirewallRules: [{2AD76573-8732-4112-BE9C-822039898220}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
- FirewallRules: [{1F415355-9600-4455-BE71-0D319F61943D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
- FirewallRules: [{E971AFE6-50C6-42EB-BCA5-F0FFD7078700}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Team Fortress 2\hl2.exe
- FirewallRules: [{B7E4226A-772F-4C6C-8041-72CA3D7C1A41}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Team Fortress 2\hl2.exe
- FirewallRules: [{8E7F9490-0EDB-42D9-9865-01B6C4B70F6E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
- FirewallRules: [{B6FA6834-9FD4-4F9B-B7A1-A15113FBAEBA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
- FirewallRules: [TCP Query User{253E644E-4093-4F42-9F35-A11CC2C87706}C:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
- FirewallRules: [UDP Query User{BDEB0925-0693-4A07-A419-9D99B41F552E}C:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
- FirewallRules: [{147D0352-3C74-449D-8134-7995911D86F3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
- FirewallRules: [{50FE7880-C84F-42CA-B917-4D813F78DDCC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
- FirewallRules: [{B1FADAB3-A5C6-4448-9F58-78958863E50B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
- FirewallRules: [{D0924B0B-560A-4B7D-B567-B86D0913AECE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
- FirewallRules: [{2A37B1D9-C7E6-4492-9992-000D0707A6EB}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- FirewallRules: [{8512E836-1F5F-4F7C-91F1-83DEFD9FE2F2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MapleStory\nxsteam.exe
- FirewallRules: [{192F8F56-2312-4BB7-BD43-ACADFD2686A1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MapleStory\nxsteam.exe
- FirewallRules: [{EAF8802A-F191-4E15-A84E-92BA4CA47144}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe
- FirewallRules: [{96128A96-48BD-4124-A4BE-BF7CAEEBFE64}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe
- FirewallRules: [{3695CF11-5C53-486A-99DA-8AF2460A4698}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\Launcher.exe
- FirewallRules: [{133F3FE1-F996-4DA4-A2DA-7F7CF979479D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Warframe\Tools\Launcher.exe
- FirewallRules: [{EF51DEF8-86F4-4303-9735-95712928AD27}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
- FirewallRules: [{D2A0448A-BA39-4DC0-807C-40ADCF45065A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
- ==================== Restore Points =========================
- 03-07-2017 01:41:03 Removed League of Legends
- ==================== Faulty Device Manager Devices =============
- Name: Intel PCIC compatible PCMCIA controller
- Description: Intel PCIC compatible PCMCIA controller
- Class Guid: {4d36e977-e325-11ce-bfc1-08002be10318}
- Manufacturer: Intel
- Service: pcmcia
- Problem: : This device cannot start. (Code10)
- Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
- On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
- ==================== Event log errors: =========================
- Application errors:
- ==================
- Error: (07/04/2017 05:47:49 AM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: raw-vengeance-launcher.exe, version: 0.0.0.0, time stamp: 0x58deadd3
- Faulting module name: raw-vengeance-launcher.exe, version: 0.0.0.0, time stamp: 0x58deadd3
- Exception code: 0xc000041d
- Fault offset: 0x00469b61
- Faulting process id: 0x454
- Faulting application start time: 0x01d2f4c34f29b184
- Faulting application path: C:\Program Files (x86)\Raw Vengeance Launcher\raw-vengeance-launcher.exe
- Faulting module path: C:\Program Files (x86)\Raw Vengeance Launcher\raw-vengeance-launcher.exe
- Report Id: f18fc32e-6790-49ab-96dd-b7f8c90a9af3
- Faulting package full name:
- Faulting package-relative application ID:
- Error: (07/04/2017 05:47:43 AM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: raw-vengeance-launcher.exe, version: 0.0.0.0, time stamp: 0x58deadd3
- Faulting module name: raw-vengeance-launcher.exe, version: 0.0.0.0, time stamp: 0x58deadd3
- Exception code: 0xc0000005
- Fault offset: 0x00469b61
- Faulting process id: 0x454
- Faulting application start time: 0x01d2f4c34f29b184
- Faulting application path: C:\Program Files (x86)\Raw Vengeance Launcher\raw-vengeance-launcher.exe
- Faulting module path: C:\Program Files (x86)\Raw Vengeance Launcher\raw-vengeance-launcher.exe
- Report Id: a54ec63b-8a20-4a15-9c4c-c0fb6fe7c669
- Faulting package full name:
- Faulting package-relative application ID:
- Error: (07/03/2017 06:12:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
- Description: Task Scheduling Error: m->NextScheduledSPRetry 1516
- Error: (07/03/2017 06:12:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
- Description: Task Scheduling Error: m->NextScheduledEvent 1516
- Error: (07/03/2017 06:12:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
- Description: Task Scheduling Error: Continuously busy for more than a second
- Error: (07/02/2017 11:46:24 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-G17JNPH)
- Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.
- Error: (07/01/2017 07:46:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
- Description: Task Scheduling Error: m->NextScheduledSPRetry 1578
- Error: (07/01/2017 07:46:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
- Description: Task Scheduling Error: m->NextScheduledEvent 1578
- Error: (07/01/2017 07:46:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
- Description: Task Scheduling Error: Continuously busy for more than a second
- Error: (07/01/2017 06:08:40 PM) (Source: Bonjour Service) (EventID: 100) (User: )
- Description: Task Scheduling Error: m->NextScheduledSPRetry 2880250
- System errors:
- =============
- Error: (07/04/2017 03:43:04 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
- Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
- Error: (07/04/2017 03:43:04 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
- Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
- Error: (07/04/2017 03:43:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
- Description: The Service KMSELDI service failed to start due to the following error:
- The system cannot find the file specified.
- Error: (07/04/2017 03:42:59 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
- Description: WLAN Extensibility Module has failed to start.
- Module Path: C:\Windows\system32\Rtlihvs.dll
- Error Code: 126
- Error: (07/04/2017 03:42:59 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
- Description: The CldFlt service failed to start due to the following error:
- The request is not supported.
- Error: (07/04/2017 03:42:49 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
- Description: Performance power management features on Hyper-V logical processor 1 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.
- Error: (07/04/2017 03:42:49 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
- Description: Performance power management features on Hyper-V logical processor 7 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.
- Error: (07/04/2017 03:42:49 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
- Description: Performance power management features on Hyper-V logical processor 5 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.
- Error: (07/04/2017 03:42:49 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
- Description: Performance power management features on Hyper-V logical processor 3 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.
- Error: (07/04/2017 03:42:49 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
- Description: Performance power management features on Hyper-V logical processor 6 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.
- CodeIntegrity:
- ===================================
- Date: 2017-06-26 21:30:50.719
- Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
- Date: 2017-06-26 21:30:50.718
- Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
- Date: 2017-06-26 21:30:35.067
- Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
- Date: 2017-06-26 21:30:35.065
- Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
- Date: 2017-06-26 21:29:48.247
- Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
- Date: 2017-06-26 21:29:48.246
- Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
- Date: 2017-06-26 21:29:35.607
- Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
- Date: 2017-06-26 21:29:35.605
- Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
- Date: 2017-06-26 14:52:55.766
- Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
- Date: 2017-06-26 14:52:55.765
- Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
- ==================== Memory info ===========================
- Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz
- Percentage of memory in use: 46%
- Total physical RAM: 6135.18 MB
- Available physical RAM: 3311.46 MB
- Total Virtual: 8439.18 MB
- Available Virtual: 5472.59 MB
- ==================== Drives ================================
- Drive c: () (Fixed) (Total:232.79 GB) (Free:28.12 GB) NTFS
- ==================== MBR & Partition Table ==================
- ========================================================
- Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 58AC5A60)
- Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
- Partition 2: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS)
- ==================== End of Addition.txt ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement