Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Netio.sys error


  • Please log in to reply
13 replies to this topic

#1 PatL

PatL

  •  Avatar image
  • Members
  • 377 posts
  • OFFLINE
  •  
  • Local time:05:15 AM

Posted 12 November 2024 - 10:58 AM

I ran FRST and ran the flushdns ip commands with the EmptyTemp command now if I try and start my PC in normal mode it crashes mid load with a Netio.sys BSOD. I can log in to safe mode and have tried system restore which said it completed successfully but unfortunately did not resolve my issue. Help me Gary Wan Kenobi you're my only hope!

BC AdBot (Login to Remove)

 


#2 PatL

PatL
  • Topic Starter

  •  Avatar image
  • Members
  • 377 posts
  • OFFLINE
  •  
  • Local time:05:15 AM

Posted 12 November 2024 - 01:53 PM

Update I got FRST ran it in safe mode and chkdsk. Chkdsk will NOT run in normal boot it huts the Netio.sys error and blue screens, thoughts? here are the logs

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-11-2024
Ran by lechn (administrator) on DESKTOP-32DBH15 (Dell Inc. G5 5590) (12-11-2024 18:33:37)
Running from C:\Users\lechn\Downloads\FRST64.exe
Loaded Profiles: lechn
Platform: Microsoft Windows 11 Pro Version 23H2 22631.4391 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Safe Mode (minimal)

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> ) C:\Program Files\Malwarebytes\Anti-Malware\MBAMCrashHandler.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\System32\upfc.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\HelpPane.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_719a4f3eb3c3c65a\RtkAudUService64.exe [1588024 2022-08-11] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender Security App\bdagent.exe [1088224 2024-10-16] (Bitdefender SRL -> Bitdefender)
HKLM\...\Run: [0patch] => C:\Program Files (x86)\0patch\Agent\0patchTray.exe [557472 2022-11-11] (ACROS računalniški inženiring d.o.o. -> Acros Security)
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\LocalLow\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\LocalLow\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\LocalLow\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Temp*_*.zip\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\wz????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\Rar$EX*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\7zO????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\.ptmp??????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_PA*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\B1FreeArchiver-*-*-*-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\BNZ.???????????????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\$$_????\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\_AZTMP*_\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\ExpressZip-*-*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\PK????.tmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.tmp <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\?EXTMP??\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.msi <==== ATTENTION
HKLM Group Policy restriction on software: protected <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\SysWOW64\FxsTmp <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\SysWOW64\Com\dmp <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\System32\FxsTmp <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\debug\WIA <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\Registration\CRMLog <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\System32\spool\drivers\color <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\System32\Com\dmp <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\Tasks <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\tracing <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\System32\Tasks <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\Temp <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\System32\spool\PRINTERS <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\SysWOW64\Tasks <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE} <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\System32\Microsoft\Crypto\RSA\MachineKeys <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\System32\spool\SERVERS <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\System32\Tasks_Migrated <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\servicing\Packages <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\servicing\Sessions <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Temp\eM Client temporary files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Foxmail*\Temp-*\Attach\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Claws-mail\mimetmp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Mailspring\files\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\hiri\temp\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\*\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: C:\ProgramData\Microsoft\Windows\Start Menu\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\*\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\*\*\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\*\*\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: C:\Windows\Hard_Configurator\Tools <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group1\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group2\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group3\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\OneDrive\Desktop\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\OneDrive\Desktop\*\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\Desktop\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\Desktop\*\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\Public\Desktop\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\*\*.lnk\* <==== ATTENTION
HKLM Group Policy restriction on software: \\?\C:\Windows\system32 <==== ATTENTION
HKLM Group Policy restriction on software: *.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.tmp <==== ATTENTION
HKLM Group Policy restriction on software: *.msi <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\*\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: C:\ProgramData\Microsoft\Windows\Start Menu\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\*\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\*\*\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\*\*\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ProgramW6432Dir% <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)% <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group1\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group2\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group3\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Desktop%*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\OneDrive\Desktop\*\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\Desktop\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\Desktop\*\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\Public\Desktop\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\*\*.lnk <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\ProductAppDataPath% <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== ATTENTION
HKLM\...\Policies\Explorer: [HideRunAsVerb] 0
HKLM\...\Policies\Explorer: [EnforceShellExtensionSecurity] 0
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall: Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableSmartScreen] 1
HKLM\Software\Policies\...\system: [ShellSmartScreenLevel] Block
HKU\S-1-5-21-4002474698-1552430223-1960928661-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4412512 2024-11-05] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-4002474698-1552430223-1960928661-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [36844504 2024-11-07] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-4002474698-1552430223-1960928661-1001\...\Run: [electron.app.BlueStacks Services] => C:\Users\lechn\AppData\Local\Programs\bluestacks-services\BlueStacksServices.exe [162219656 2024-05-08] (Now.gg, INC -> now.gg, Inc.)
Startup: C:\Users\lechn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PatchMyPC.exe.lnk [2024-11-12]
ShortcutTarget: PatchMyPC.exe.lnk -> D:\Programs for new Install\PatchMyPC.exe (Patch My PC, LLC -> Patch My PC, LLC)
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy\User: Restriction - Edge <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {03ac212b-1fb6-4136-8562-2022e47a92b2} - no filepath. <==== ATTENTION
Task: {06948412-0410-4a72-afda-297dae8fe660} - no filepath. <==== ATTENTION
Task: {06c04537-6512-41fb-829c-47548eff5528} - no filepath. <==== ATTENTION
Task: {0f46bb58-07f7-4814-be7b-bb7eac4b1b6c} - no filepath. <==== ATTENTION
Task: {1aa86cb8-5422-4871-89ac-6bbb7ed3a479} - no filepath. <==== ATTENTION
Task: {3934a8b2-d696-41ec-bec5-a03faccab734} - no filepath. <==== ATTENTION
Task: {3be6ae32-3e01-4c24-b87a-2abcfd193e05} - no filepath. <==== ATTENTION
Task: {5a7d1e16-2e6d-4df3-a376-dd6664d2ff7a} - no filepath. <==== ATTENTION
Task: {5bf1727f-91c9-404e-b467-b2ac5d19da22} - no filepath. <==== ATTENTION
Task: {5f12a76e-efd6-4ec4-b4c6-da0fb182c107} - no filepath. <==== ATTENTION
Task: {5f17bc4b-ef24-43dc-9fb4-aa5818c1b836} - no filepath. <==== ATTENTION
Task: {5f64efc4-4850-4a44-beec-7d4eb8c3c84e} - no filepath. <==== ATTENTION
Task: {610ccab8-2395-43d3-bbed-30948580c284} - no filepath. <==== ATTENTION
Task: {63e7c3d3-77f6-47df-a1f8-4a92d705e178} - no filepath. <==== ATTENTION
Task: {873d01cf-2785-4d42-afeb-033f69b040e6} - no filepath. <==== ATTENTION
Task: {8927fdfd-4311-4d07-b837-2d655d5714d4} - no filepath. <==== ATTENTION
Task: {8f80fec1-5e76-4402-82e9-b2392da4518a} - no filepath. <==== ATTENTION
Task: {9423e1a2-7d2d-4673-9c9c-472d3a7a386b} - no filepath. <==== ATTENTION
Task: {9ea552a2-c92a-4a8f-aa24-200e9e24211a} - no filepath. <==== ATTENTION
Task: {9fa93143-6a13-49e7-846e-aca59f62311a} - no filepath. <==== ATTENTION
Task: {c73e1046-3183-460e-9d44-702bd55f5a24} - no filepath. <==== ATTENTION
Task: {c9610446-097d-48d1-8cec-b91b450c2fd5} - no filepath. <==== ATTENTION
Task: {cb8a6f99-1ab8-4f21-99d3-f00912d91c0c} - no filepath. <==== ATTENTION
Task: {e31ea6dc-6087-4e57-a1f3-4723741ab7ad} - no filepath. <==== ATTENTION
Task: {e7ae24b1-38a5-43e2-b6a4-ce7f3536161d} - no filepath. <==== ATTENTION
Task: {ea9be4fd-ae03-4690-9275-51c7bbc0973f} - no filepath. <==== ATTENTION
Task: {edd7ff7a-36be-4cf0-b02e-3ffb9c4196f9} - no filepath. <==== ATTENTION
Task: {fe1aaf6f-7fab-4528-a476-452b18fa68ea} - no filepath. <==== ATTENTION
Task: {A8A87EF1-035A-4205-9225-7A9F0BAF91E0} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\27.0.1.287\WatchDog.exe [1156912 2024-10-29] (Bitdefender SRL -> Bitdefender) -> C:\Program Files\Bitdefender Agent\27.0.1.287\repair
Task: {1FDB2453-83B0-4E70-9DF8-D05F35DBAC3A} - System32\Tasks\BlueStacksHelper_nxt => C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe [302968 2024-09-30] (Now.gg, INC -> BlueStack Systems, Inc.)
Task: {1A025443-B8DB-438F-8BBB-1F9095F3B402} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\FrameworkAgents\SupportAssistInstaller.exe [964936 2024-04-25] (Dell Technologies Inc. -> Dell Inc.) -> C:\Program Files\Dell\SupportAssistAgent\bin\AutoUpdate
Task: {DF9A6ED7-0ADF-4718-9778-D3A2A9424E50} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\VirtulizationBasedIsolation\Virtualization based Isolation master policy change => C:\Windows\system32\hvsievaluator.exe [194032 2024-10-22] (Microsoft Windows -> Microsoft Corporation)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {D1DAD8CA-A1D9-479C-80CB-9E6141CE7E59} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1EAA7DE5-4DED-41FB-8202-F925174D735A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4A89867F-2E70-46DE-8FE4-170026606CE8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {33EFBB53-0F2C-4A09-8904-A96B6869427B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {AFC7CF5B-9374-410B-8F47-95215E0F16AA} - System32\Tasks\NahimicTask32 => C:\Windows\System32\..\SysWOW64\NahimicSvc32.exe [837280 ] (A-Volute SAS -> Nahimic)
Task: {E481C78C-1727-4B3A-B0D0-E64CD0AF8775} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1277480 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {0A253F7A-1994-4D88-8763-DF1E21E0C3BF} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3347496 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {564E496E-B450-479B-92DE-445900D6CD53} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646696 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {C6C05742-7AC5-4AAB-ABD7-39F4D70790E4} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0C75CE5B-567C-418B-9EB8-8A54ED0DBD15} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0E57D172-290C-48E4-8DED-335F944E90E3} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B56134AC-4B80-4CA3-BC43-CA817FAA5F99} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F2DA4CC5-2C22-4F9B-AD79-5C6502A8E874} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {225A2F5B-4E91-4F94-A30D-8910E617248F} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{1c1d7d3d-adb3-4ca6-b8ad-17548cb48fb6}: [NameServer] 9.9.9.9,149.112.112.112
Tcpip\..\Interfaces\{3fa0d0f2-4744-4333-b551-0eca8a257f22}: [NameServer] 9.9.9.9,149.112.112.112
Tcpip\..\Interfaces\{3fa0d0f2-4744-4333-b551-0eca8a257f22}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{3fa0d0f2-4744-4333-b551-0eca8a257f22}: [DhcpDomain] hsd1.ca.comcast.net
Tcpip\..\Interfaces\{3fa0d0f2-4744-4333-b551-0eca8a257f22}\84F4D454D243246434: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{b3f66320-e06b-4b35-93fa-c71458013918}: [NameServer] 9.9.9.9,149.112.112.112
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\lechn\AppData\Local\Microsoft\Edge\User Data\Default [2024-11-12]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\lechn\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2024-10-22]
Edge Extension: (uBlock Origin) - C:\Users\lechn\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2024-11-08]
Edge Extension: (Bitdefender Anti-tracker) - C:\Users\lechn\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dbconhplchnbippmjabbcedokimacfjl [2024-10-29]
Edge Extension: (Google Docs Offline) - C:\Users\lechn\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-11-08]
Edge Extension: (Edge relevant text changes) - C:\Users\lechn\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-09-27]
Edge Extension: (Guardio Protection for Edge) - C:\Users\lechn\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nbnhplicmjembdbegdmlhnpddambfodp [2024-11-07]
Edge Extension: (uBlock Origin) - C:\Users\lechn\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\odfafepnkmbhccpbejgmiehpchacaeak [2024-11-06]
Edge HKLM-x32\...\Edge\Extension: [dbconhplchnbippmjabbcedokimacfjl]

FireFox:
========
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security App\bdtbext
FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender Security App\bdtbext [2024-10-23] [Legacy] [not signed]
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security App\bdtbext
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [khndhdhbebhaddchcgnalcjlaekbbeof]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 0patchService; C:\Program Files (x86)\0patch\Agent\0PatchServicex64.exe [507384 2022-11-11] (ACROS računalniški inženiring d.o.o. -> Acros Security)
S3 battlenet_helpersvc; C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe [3280000 2024-11-08] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
S2 BDAppSrv; C:\Program Files\Bitdefender\Bitdefender Security App\bdservicehost.exe [851640 2024-10-16] (Bitdefender SRL -> Bitdefender)
S2 BDAuxSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [851640 2024-10-23] (Bitdefender SRL -> Bitdefender)
S2 BDProtSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [851640 2024-10-23] (Bitdefender SRL -> Bitdefender)
S2 bdredline; C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe [2966176 2023-07-20] (Bitdefender SRL -> Bitdefender)
S2 bdredline_agent; C:\Program Files\Bitdefender Agent\redline\bdredline.exe [2577184 2023-07-20] (Bitdefender SRL -> Bitdefender)
S2 BDSafepaySrv; C:\Program Files\Bitdefender\Bitdefender Security App\Safepay\bdservicehost.exe [851640 2024-10-23] (Bitdefender SRL -> Bitdefender)
S3 dcpm-notify; C:\Program Files\Dell\CommandPowerManager\NotifyService.exe [329928 2024-07-29] (Dell Technologies Inc. -> Dell Inc.)
S2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [458128 2023-12-07] (Dell Technologies Inc. -> Dell Technologies Inc.)
S2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [159632 2023-12-07] (Dell Technologies Inc. -> Dell Technologies Inc.)
S2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [481680 2023-12-07] (Dell Technologies Inc. -> Dell Technologies Inc.)
S2 Dell SupportAssist Remediation; C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe [22232 2024-08-23] (Dell Technologies Inc. -> Dell INC.)
S3 Dell.CommandPowerManager.Service; C:\Windows\system32\dllhost.exe /Processid:{554564DE-BD10-44BA-810A-C52EA5A34B7F} [46416 2022-05-06] (Microsoft Windows -> Microsoft Corporation)
S2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [49880 2023-12-11] (Dell Inc -> )
S2 DellTechHub; C:\Program Files\Dell\TechHub\Dell.TechHub.exe [159664 2023-12-22] (Dell Technologies Inc. -> Dell)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [935344 2024-09-28] (EasyAntiCheat Oy -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2023-08-02] (Epic Games Inc. -> Epic Games, Inc.)
S2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [5899416 2024-10-03] (Sophos Ltd -> Sophos B.V.)
S3 LibreOfficeMaintenance; C:\Program Files\LibreOffice\program\update_service.exe [123320 2024-09-24] (The Document Foundation -> The Document Foundation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9433496 2024-11-11] (Malwarebytes Inc. -> Malwarebytes)
S2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe [1447680 2024-10-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 NahimicService; C:\Windows\system32\NahimicService.exe [1926840 2022-07-15] (A-Volute SAS -> Nahimic)
S2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvdmi.inf_amd64_a3eaecfbb94ad6bc\Display.NvContainer\NVDisplay.Container.exe [1275024 2024-10-16] (NVIDIA Corporation -> NVIDIA Corporation)
S2 PCManager Service Store; C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.14.10.0_x64__8wekyb3d8bbwe\PCManager\MSPCManagerService.exe [132640 2024-10-22] (Microsoft Corporation -> MSPCManagerService)
S2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [710576 2024-10-29] (Bitdefender SRL -> Bitdefender)
S2 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559368 2024-10-22] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [159048 2024-04-25] (Dell Technologies Inc. -> Dell Inc.)
S2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe [291224 2024-10-23] (Bitdefender SRL -> Bitdefender)
S2 VSSERV; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [851640 2024-10-23] (Bitdefender SRL -> Bitdefender)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe [3199672 2024-10-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe [141952 2024-10-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 MBVpnTunnelService; "C:\Program Files\Malwarebytes\Anti-Malware\tunnel\MBVpnTunnelService.exe" /service [X]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S1 0patchDriver; C:\Program Files (x86)\0patch\Agent\0patchDriver64.sys [153432 2022-11-11] (Microsoft Windows Hardware Compatibility Publisher -> )
S1 atc; C:\Windows\System32\DRIVERS\atc.sys [7505856 2024-09-03] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender S.R.L. Bucharest, ROMANIA)
S2 BdDci4; C:\Windows\system32\DRIVERS\bddci4.sys [933424 2024-07-17] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [24568 2023-05-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Bitdefender)
S3 bdprivmon; C:\Windows\system32\DRIVERS\bdprivmon.sys [49200 2023-08-08] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender SRL)
S3 bduefiscan; C:\Windows\system32\DRIVERS\bduefiscan.sys [42432 2024-07-01] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S2 BlueStacksDrv_nxt; C:\Program Files\BlueStacks_nxt\BstkDrv_nxt.sys [394176 2024-09-30] (Microsoft Windows Hardware Compatibility Publisher -> Bluestack System Inc.)
S3 DellInstrumentation; C:\Windows\System32\drivers\DellInstrumentation.sys [46640 2024-02-29] (Microsoft Windows Hardware Compatibility Publisher -> Dell)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [158640 2024-11-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R0 fse; C:\Windows\System32\drivers\fse.sys [218592 2024-10-22] (Microsoft Windows -> Microsoft Corporation)
S1 Gemma; C:\Windows\System32\DRIVERS\gemma.sys [1490896 2024-05-20] (Microsoft Windows Hardware Compatibility Publisher -> BitDefender S.R.L. Bucharest, ROMANIA)
S1 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [421528 2024-10-03] (Microsoft Windows Hardware Compatibility Publisher -> Sophos B.V.)
S2 Ignisv2; C:\Windows\system32\DRIVERS\ignisv2.sys [849968 2024-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
R0 mbamchameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [232024 2024-11-11] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [21480 2024-11-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMFarflt; C:\Windows\system32\DRIVERS\farflt11.sys [234168 2024-11-11] (Malwarebytes Inc. -> Malwarebytes)
S3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [80448 2024-11-11] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239568 2024-11-12] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [189776 2024-11-11] (Malwarebytes Inc. -> Malwarebytes)
S3 NvModuleTracker; C:\Windows\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys [47240 2024-04-03] (NVIDIA Corporation -> NVIDIA Corporation)
S3 rtcx21; C:\Windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_516e5c9b75c49dc2\rtcx21x64.sys [539648 2022-05-06] (Microsoft Windows -> Realtek)
U5 RTSUER; C:\Windows\System32\Drivers\RTSUER.sys [443480 2019-07-05] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S2 trufos; C:\Windows\System32\DRIVERS\trufos.sys [629184 2023-07-20] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S0 vlflt; C:\Windows\System32\DRIVERS\vlflt.sys [1403448 2024-07-01] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
S3 vmbusproxy; C:\Windows\system32\drivers\vmbusproxy.sys [94208 2024-10-01] (Microsoft Windows -> )
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [22104 2024-10-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\Windows\System32\drivers\wdcsam64.sys [25704 2020-09-10] (WDKTestCert user,132375440089837053 -> Western Digital Technologies, Inc.)
S0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [606624 2024-10-10] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105888 2024-10-10] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\Windows\System32\drivers\wireguard.sys [489368 2024-10-08] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2024-11-12 08:36 - 2024-11-12 08:37 - 000089785 _____ C:\Users\lechn\Downloads\Addition.txt
2024-11-12 08:35 - 2024-11-12 18:34 - 000147447 _____ C:\Users\lechn\Downloads\FRST.txt
2024-11-12 08:35 - 2024-11-12 18:28 - 002401280 _____ (Farbar) C:\Users\lechn\Downloads\FRST64.exe
2024-11-12 08:16 - 2024-11-12 08:16 - 000445176 _____ C:\Windows\system32\FNTCACHE.DAT
2024-11-12 07:58 - 2024-11-12 08:03 - 000000000 _____ C:\Recovery.txt
2024-11-12 07:40 - 2024-11-12 07:40 - 000000112 ___SH C:\bootTel.dat
2024-11-12 07:28 - 2024-11-12 07:28 - 000001036 _____ C:\Users\lechn\Downloads\Fixlog.txt
2024-11-12 07:26 - 2024-11-12 07:26 - 000002224 _____ C:\Users\lechn\OneDrive\Documents\Fixlog.txt
2024-11-12 07:25 - 2024-11-12 18:33 - 000000000 ____D C:\FRST
2024-11-12 07:20 - 2024-11-12 07:20 - 000003108 _____ C:\Windows\system32\Tasks\NahimicTask32
2024-11-12 07:20 - 2024-11-12 07:20 - 000003088 _____ C:\Windows\system32\Tasks\NahimicTask64
2024-11-11 13:49 - 2024-11-11 13:49 - 000000000 ____D C:\Users\lechn\Downloads\Bitdefender Safepay
2024-11-11 13:41 - 2024-11-11 13:41 - 000001473 _____ C:\Users\lechn\OneDrive\Desktop\A Plague Tale Requiem - Windows.lnk
2024-11-11 13:06 - 2024-11-11 13:06 - 000000268 _____ C:\Users\lechn\OneDrive\Documents\ESET Online Scanner.txt
2024-11-11 10:09 - 2024-11-11 10:09 - 000001282 _____ C:\Users\lechn\OneDrive\Desktop\ESET Online Scanner.lnk
2024-11-11 10:08 - 2024-11-12 08:03 - 000000000 ____D C:\Users\lechn\AppData\Local\ESET
2024-11-11 10:08 - 2024-11-11 10:09 - 000001382 _____ C:\Users\lechn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2024-11-11 09:40 - 2024-11-11 09:40 - 000000318 _____ C:\Windows\system32\httpproxy.json
2024-11-11 09:36 - 2024-11-11 09:36 - 000234168 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt11.sys
2024-11-11 09:36 - 2024-11-11 09:36 - 000189776 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2024-11-10 21:26 - 2024-11-10 21:26 - 003281747 _____ C:\Users\lechn\OneDrive\Documents\Sword of the Demon Hunter Volume 7.epub
2024-11-09 09:01 - 2024-11-09 09:01 - 000000000 ____D C:\Users\lechn\AppData\Local\WW
2024-11-07 09:20 - 2024-11-07 09:20 - 000000000 ____D C:\Users\lechn\AppData\LocalLow\Codename Entertainment
2024-11-05 21:36 - 2024-11-05 21:36 - 000000919 _____ C:\Users\lechn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tor Browser.lnk
2024-11-05 21:36 - 2024-11-05 21:36 - 000000853 _____ C:\Users\lechn\OneDrive\Desktop\Tor Browser.lnk
2024-11-05 21:36 - 2024-11-05 21:36 - 000000000 ____D C:\Users\lechn\OneDrive\Desktop\Tor Browser
2024-11-05 07:25 - 2024-11-12 08:41 - 000000000 ____D C:\Users\lechn\AppData\Local\Malwarebytes
2024-11-05 07:24 - 2024-11-05 07:24 - 000000000 ____D C:\Program Files\Malwarebytes
2024-11-05 04:36 - 2024-11-05 04:36 - 000000027 _____ C:\Windows\system32\ctc.json
2024-11-04 20:13 - 2023-08-09 03:49 - 001233584 _____ C:\Windows\RunBySmartscreen(x64).exe
2024-11-04 20:12 - 2024-11-04 20:12 - 000000798 _____ C:\Users\lechn\OneDrive\Desktop\WHH_Tools.lnk
2024-11-04 20:11 - 2024-11-04 20:12 - 000000000 ____D C:\Windows\Hard_Configurator
2024-11-04 19:16 - 2024-11-04 19:16 - 000036988 _____ C:\Users\lechn\OneDrive\Documents\Untitled 1.odt
2024-11-04 09:56 - 2024-11-11 01:13 - 000000000 ____D C:\Users\lechn\OneDrive\Documents\MYKIND~1
2024-11-03 19:31 - 2024-11-03 19:31 - 000000000 ____D C:\Program Files (x86)\Kalisto Entertainment
2024-11-03 19:31 - 2024-11-03 19:31 - 000000000 ____D C:\jeux
2024-11-03 19:30 - 1998-08-06 14:47 - 000304128 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe
2024-10-31 10:37 - 2024-10-31 10:39 - 000000000 ____D C:\GOG Games
2024-10-31 10:33 - 2022-09-30 04:24 - 000174112 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\ssudmdm.sys
2024-10-31 09:57 - 2024-10-31 09:57 - 000000223 _____ C:\Users\lechn\OneDrive\Desktop\Vampire Survivors.url
2024-10-31 09:57 - 2024-10-31 09:57 - 000000000 ____D C:\Users\lechn\AppData\Roaming\Vampire_Survivors_Data
2024-10-31 09:57 - 2024-10-31 09:57 - 000000000 ____D C:\Users\lechn\AppData\Roaming\Vampire_Survivors_1120064568
2024-10-31 09:57 - 2024-10-31 09:57 - 000000000 ____D C:\Users\lechn\AppData\Roaming\Vampire_Survivors
2024-10-31 09:57 - 2024-10-31 09:57 - 000000000 ____D C:\Users\lechn\AppData\LocalLow\poncle
2024-10-31 06:45 - 2024-10-31 06:45 - 000000000 ____D C:\Program Files (x86)\0patch
2024-10-29 12:22 - 2024-10-29 12:22 - 000000000 ____D C:\Windows\system32\elambkup
2024-10-29 12:22 - 2024-10-29 12:22 - 000000000 ____D C:\Users\lechn\AppData\Roaming\Bitdefender Security App
2024-10-29 12:22 - 2024-10-29 12:22 - 000000000 ____D C:\Users\lechn\AppData\Roaming\Bitdefender
2024-10-29 12:22 - 2024-10-29 12:22 - 000000000 ____D C:\Program Files\Bitdefender
2024-10-29 12:17 - 2024-11-06 08:07 - 000003846 _____ C:\Windows\system32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
2024-10-29 12:17 - 2024-10-29 12:28 - 000000000 ____D C:\Program Files\Common Files\Bitdefender
2024-10-29 12:15 - 2024-11-06 08:07 - 000000000 ____D C:\Program Files\Bitdefender Agent
2024-10-29 12:15 - 2024-10-29 12:15 - 000000000 ____D C:\Users\lechn\AppData\Local\Bitdefender
2024-10-29 12:00 - 2024-10-29 12:00 - 000000000 ____D C:\Program Files\qBittorrent
2024-10-27 11:20 - 2024-10-27 11:20 - 000000000 ____D C:\Users\lechn\EpuborAudible
2024-10-27 11:20 - 2024-10-27 11:20 - 000000000 ____D C:\Users\lechn\AppData\Roaming\.EpuborAudible
2024-10-27 08:46 - 2024-11-11 01:13 - 000000000 ____D C:\Users\lechn\AppData\Roaming\calibre
2024-10-27 08:17 - 2024-11-11 01:12 - 000000000 ____D C:\Users\lechn\Calibre Library 2
2024-10-25 11:57 - 2024-11-11 20:01 - 000000000 ____D C:\Users\lechn\AppData\Roaming\discord
2024-10-25 11:57 - 2024-11-11 19:52 - 000000000 ____D C:\Users\lechn\AppData\Local\Discord
2024-10-25 11:57 - 2024-11-05 14:06 - 000002253 _____ C:\Users\lechn\OneDrive\Desktop\Discord.lnk
2024-10-25 11:57 - 2024-10-25 11:57 - 000000000 ____D C:\Users\lechn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2024-10-25 11:57 - 2024-10-25 11:57 - 000000000 ____D C:\Users\lechn\AppData\Local\SquirrelTemp
2024-10-24 10:45 - 2024-10-24 10:50 - 000000000 ____D C:\Program Files\HitmanPro
2024-10-24 10:44 - 2024-10-24 10:50 - 014290472 ____H (Sophos B.V.) C:\Users\lechn\Downloads\HitmanPro_x64.exe
2024-10-24 10:26 - 2024-10-24 10:26 - 000003976 _____ C:\Windows\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-24 10:26 - 2024-10-24 10:26 - 000003940 _____ C:\Windows\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-24 10:26 - 2024-10-24 10:26 - 000000000 ____D C:\Users\lechn\ansel
2024-10-24 10:26 - 2024-06-11 12:19 - 002900520 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2024-10-24 10:26 - 2024-06-11 12:19 - 002231336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2024-10-24 10:26 - 2024-06-11 12:18 - 001296936 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll
2024-10-24 10:26 - 2024-06-11 11:50 - 000086568 _____ C:\Windows\system32\FvSDK_x64.dll
2024-10-24 10:26 - 2024-06-11 11:50 - 000075304 _____ C:\Windows\SysWOW64\FvSDK_x86.dll
2024-10-24 10:25 - 2024-10-24 10:25 - 000004308 _____ C:\Windows\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-24 10:25 - 2024-10-24 10:25 - 000003894 _____ C:\Windows\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-24 10:25 - 2024-10-24 10:25 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-24 10:25 - 2024-10-24 10:25 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-24 10:25 - 2024-10-24 10:25 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-24 10:25 - 2024-10-24 10:25 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-24 10:25 - 2024-10-24 10:25 - 000003654 _____ C:\Windows\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-10-24 10:25 - 2024-03-26 11:11 - 000180760 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2024-10-24 10:25 - 2024-03-26 11:11 - 000159768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2024-10-24 10:19 - 2024-03-26 11:11 - 000059928 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2024-10-24 10:19 - 2024-03-26 09:21 - 000060240 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2024-10-24 10:18 - 2024-10-16 00:00 - 002060648 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2024-10-24 10:18 - 2024-10-16 00:00 - 002060648 _____ C:\Windows\system32\vulkaninfo.exe
2024-10-24 10:18 - 2024-10-16 00:00 - 001600360 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2024-10-24 10:18 - 2024-10-16 00:00 - 001600360 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2024-10-24 10:18 - 2024-10-15 23:59 - 001452400 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2024-10-24 10:18 - 2024-10-15 23:59 - 001452400 _____ C:\Windows\system32\vulkan-1.dll
2024-10-24 10:18 - 2024-10-15 23:59 - 001301864 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2024-10-24 10:18 - 2024-10-15 23:59 - 001301864 _____ C:\Windows\SysWOW64\vulkan-1.dll
2024-10-24 10:18 - 2024-10-15 23:59 - 000477816 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2024-10-24 10:18 - 2024-10-15 23:59 - 000374944 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2024-10-24 10:18 - 2024-10-15 23:56 - 001554568 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2024-10-24 10:18 - 2024-10-15 23:56 - 001208952 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2024-10-24 10:18 - 2024-10-15 23:56 - 001114752 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2024-10-24 10:18 - 2024-10-15 23:56 - 000863904 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2024-10-24 10:18 - 2024-10-15 23:56 - 000670360 _____ (NVIDIA Corporation) C:\Windows\system32\nvofapi64.dll
2024-10-24 10:18 - 2024-10-15 23:56 - 000505488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvofapi.dll
2024-10-24 10:18 - 2024-10-15 23:55 - 025450104 _____ C:\Windows\system32\nvidia-pcc.exe
2024-10-24 10:18 - 2024-10-15 23:55 - 002185344 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2024-10-24 10:18 - 2024-10-15 23:55 - 001634944 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2024-10-24 10:18 - 2024-10-15 23:55 - 001042048 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2024-10-24 10:18 - 2024-10-15 23:55 - 000800888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2024-10-24 10:18 - 2024-10-15 23:55 - 000461944 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2024-10-24 10:18 - 2024-10-15 23:54 - 017736824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2024-10-24 10:18 - 2024-10-15 23:54 - 016811128 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2024-10-24 10:18 - 2024-10-15 23:54 - 006953120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2024-10-24 10:18 - 2024-10-15 23:54 - 005910168 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2024-10-24 10:18 - 2024-10-15 23:54 - 005435024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcudadebugger.dll
2024-10-24 10:18 - 2024-10-15 23:54 - 003807384 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2024-10-24 10:18 - 2024-10-15 23:54 - 000853112 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2024-10-24 10:18 - 2024-10-15 23:53 - 007159112 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2024-10-24 10:18 - 2024-10-15 23:53 - 006236256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2024-10-24 10:18 - 2024-10-15 11:04 - 000132701 _____ C:\Windows\system32\nvinfo.pb
2024-10-23 08:10 - 2024-11-05 08:52 - 000000000 ____D C:\Users\lechn\Ultimate
2024-10-23 08:10 - 2024-11-05 08:49 - 000000000 ____D C:\Users\lechn\AppData\Roaming\.Ultimate
2024-10-23 08:10 - 2024-11-05 08:46 - 000000000 ____D C:\Users\lechn\AppData\Roaming\.ecore_tmp
2024-10-23 08:10 - 2024-11-05 08:46 - 000000000 ____D C:\Users\lechn\.Epubor_Keys
2024-10-23 08:10 - 2024-11-04 09:55 - 000000000 ____D C:\Users\lechn\EpuborLog
2024-10-23 08:10 - 2024-10-23 08:10 - 000000000 ____D C:\Users\lechn\Favorite
2024-10-23 08:10 - 2024-10-23 08:10 - 000000000 ____D C:\Users\lechn\AppData\Roaming\Ultimate
2024-10-23 08:08 - 2024-10-27 11:19 - 000000000 ____D C:\Program Files\Epubor
2024-10-23 08:03 - 2024-11-04 09:56 - 000002318 _____ C:\Users\lechn\OneDrive\Desktop\Kindle.lnk
2024-10-23 08:03 - 2024-10-23 08:03 - 000000000 ____D C:\Users\lechn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon
2024-10-23 08:02 - 2024-10-23 08:20 - 000000000 ____D C:\Users\lechn\AppData\Local\Amazon
2024-10-22 15:41 - 2024-10-22 15:41 - 000000000 _____ C:\Windows\invcol.tmp
2024-10-22 14:10 - 2024-10-22 14:10 - 000026650 _____ C:\Windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-10-22 14:09 - 2024-10-22 14:09 - 000026650 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2024-10-22 14:03 - 2024-10-22 14:03 - 000007631 _____ C:\Users\lechn\AppData\Local\Resmon.ResmonCfg
2024-10-22 13:25 - 2024-10-22 14:28 - 000000186 _____ C:\Users\lechn\OneDrive\Desktop\Stranded Deep.url
2024-10-21 16:41 - 2022-09-30 04:23 - 000167440 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\ssudbus2.sys
2024-10-18 09:40 - 2024-11-11 14:05 - 003893825 _____ C:\Users\lechn\OneDrive\Documents\Sword of the Demon Hunter Volume 5.epub
2024-10-18 09:36 - 2024-11-11 14:05 - 003152595 _____ C:\Users\lechn\OneDrive\Documents\Sword of the Demon Hunter Volume 6.epub
2024-10-18 09:35 - 2024-11-11 14:05 - 002587912 _____ C:\Users\lechn\OneDrive\Documents\Sword of the Demon Hunter Volume 4.epub
2024-10-15 18:10 - 2024-10-15 18:10 - 000000000 ____D C:\Users\lechn\OneDrive\Documents\The Technomancer
2024-10-15 18:07 - 2024-10-15 18:07 - 000000222 _____ C:\Users\lechn\OneDrive\Desktop\The Technomancer.url
2024-10-15 18:04 - 2024-10-15 18:04 - 000000222 _____ C:\Users\lechn\OneDrive\Desktop\Mars War Logs.url
2024-10-15 18:02 - 2024-10-15 18:02 - 000000223 _____ C:\Users\lechn\OneDrive\Desktop\Beyond the Mountains.url
2024-10-15 11:30 - 2024-10-15 11:30 - 000001209 _____ C:\Users\lechn\OneDrive\Desktop\The Bard's Tale Trilogy.lnk
2024-10-15 11:11 - 2024-10-15 11:11 - 000000000 ____D C:\Users\lechn\AppData\Local\ProjectDinoCrisis
2024-10-14 08:03 - 2024-10-14 08:03 - 000000000 ____D C:\Games
2024-10-14 07:55 - 2024-10-14 08:06 - 000000000 ____D C:\Windows\Minidump

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2024-11-12 18:34 - 2024-10-12 11:34 - 002346974 _____ C:\Windows\ntbtlog.txt
2024-11-12 18:33 - 2024-09-27 17:20 - 000000000 ____D C:\Windows\system32\SleepStudy
2024-11-12 18:32 - 2024-10-12 11:43 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2024-11-12 18:32 - 2024-09-27 17:20 - 000012288 ___SH C:\DumpStack.log.tmp
2024-11-12 10:19 - 2022-05-06 21:17 - 000524288 _____ C:\Windows\system32\config\BBI
2024-11-12 10:18 - 2024-10-04 10:29 - 000000000 ____D C:\Users\lechn\AppData\Local\CrashDumps
2024-11-12 10:18 - 2024-09-28 09:53 - 000000000 ____D C:\Users\lechn\AppData\Roaming\Microsoft\MMC
2024-11-12 08:29 - 2024-09-27 10:47 - 000000000 ____D C:\Users\lechn\AppData\Local\D3DSCache
2024-11-12 08:26 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\SystemTemp
2024-11-12 08:22 - 2024-09-27 10:30 - 000850316 _____ C:\Windows\system32\PerfStringBackup.INI
2024-11-12 08:22 - 2022-05-06 21:22 - 000000000 ____D C:\Windows\INF
2024-11-12 08:16 - 2024-09-27 10:26 - 000000000 ____D C:\Users\lechn
2024-11-12 08:03 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\ServiceState
2024-11-12 08:02 - 2022-05-06 21:24 - 000000000 ___HD C:\Program Files\WindowsApps
2024-11-12 07:59 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\registration
2024-11-12 07:20 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\AppReadiness
2024-11-12 07:17 - 2024-09-30 13:55 - 000000000 ____D C:\Program Files (x86)\Diablo IV
2024-11-12 07:17 - 2024-09-30 13:53 - 000000000 ____D C:\Users\lechn\AppData\Local\Battle.net
2024-11-12 07:17 - 2024-09-27 11:06 - 000000000 ____D C:\Program Files (x86)\Steam
2024-11-12 07:16 - 2024-09-30 13:55 - 000000000 ____D C:\Program Files (x86)\StarCraft
2024-11-12 07:10 - 2024-09-27 10:43 - 000000000 __SHD C:\Users\lechn\IntelGraphicsProfiles
2024-11-11 14:05 - 2023-08-17 08:14 - 004794088 _____ C:\Users\lechn\OneDrive\Documents\Sword of the Demon Hunter Volume 3.epub
2024-11-11 14:05 - 2023-06-30 09:35 - 004212842 _____ C:\Users\lechn\OneDrive\Documents\Sword of the Demon Hunter Volume 2.epub
2024-11-11 14:05 - 2023-06-29 02:17 - 004918380 _____ C:\Users\lechn\OneDrive\Documents\Sword of the Demon Hunter Volume 1.epub
2024-11-11 13:41 - 2024-09-27 11:16 - 000000000 ____D C:\XboxGames
2024-11-11 13:41 - 2024-09-27 10:43 - 000000000 ____D C:\Users\lechn\AppData\Local\Packages
2024-11-11 10:12 - 2024-09-27 18:20 - 000000000 ____D C:\Windows\Panther
2024-11-11 10:01 - 2022-05-06 21:17 - 000000000 ____D C:\Windows\CbsTemp
2024-11-11 01:17 - 2024-09-27 11:09 - 000000000 ____D C:\Users\lechn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2024-11-11 01:11 - 2024-09-29 04:29 - 000000000 ____D C:\Users\lechn\AppData\Roaming\vlc
2024-11-10 07:44 - 2024-09-30 13:55 - 000000000 ____D C:\Program Files (x86)\Warcraft Orcs & Humans
2024-11-10 07:44 - 2024-09-30 13:55 - 000000000 ____D C:\Program Files (x86)\Warcraft II
2024-11-10 07:44 - 2024-09-30 13:55 - 000000000 ____D C:\Program Files (x86)\StarCraft II
2024-11-10 07:44 - 2024-09-30 13:55 - 000000000 ____D C:\Program Files (x86)\Diablo Immortal
2024-11-10 07:44 - 2024-09-30 13:55 - 000000000 ____D C:\Program Files (x86)\Diablo III
2024-11-10 07:44 - 2024-09-30 13:55 - 000000000 ____D C:\Program Files (x86)\Diablo II Resurrected
2024-11-10 07:44 - 2024-09-30 13:55 - 000000000 ____D C:\Program Files (x86)\Diablo
2024-11-10 07:44 - 2024-09-30 13:52 - 000000000 ____D C:\Program Files (x86)\Battle.net
2024-11-09 19:25 - 2024-09-28 08:34 - 000000000 ____D C:\Program Files\Calibre2
2024-11-09 19:20 - 2024-09-27 17:20 - 000003536 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-11-09 19:20 - 2024-09-27 17:20 - 000003412 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-11-09 09:01 - 2024-10-02 11:07 - 000000000 ____D C:\Users\lechn\AppData\Local\EpicGamesLauncher
2024-11-08 09:55 - 2024-10-01 14:55 - 000000715 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2024-11-07 13:08 - 2024-10-02 11:09 - 000000000 ____D C:\Users\lechn\AppData\Local\NVIDIA Corporation
2024-11-05 15:15 - 2022-05-06 21:17 - 000032768 _____ C:\Windows\system32\config\ELAM
2024-11-05 08:51 - 2024-09-28 08:35 - 000000000 ____D C:\Users\lechn\AppData\Local\calibre-cache
2024-11-05 07:25 - 2022-05-06 21:24 - 000000000 ___HD C:\Windows\ELAMBKUP
2024-11-05 07:21 - 2024-10-01 07:10 - 000037288 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\Drivers\PROCEXP152.SYS
2024-11-04 20:20 - 2024-09-27 17:22 - 000001535 _____ C:\Windows\system32\config\VSMIDK
2024-11-04 20:20 - 2024-09-27 17:20 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2024-11-04 20:20 - 2024-09-27 10:28 - 000000000 ____D C:\Intel
2024-11-02 08:38 - 2024-09-27 11:16 - 002872896 _____ (Microsoft Corporation) C:\Windows\system32\xgameruntime.dll
2024-11-02 08:38 - 2024-09-27 11:16 - 000775720 _____ (Microsoft Corporation) C:\Windows\system32\gameplatformservices.dll
2024-11-02 08:38 - 2024-09-27 11:16 - 000243240 _____ (Microsoft Corporation) C:\Windows\system32\gamelaunchhelper.dll
2024-11-02 08:38 - 2024-09-27 11:16 - 000243240 _____ (Microsoft Corporation) C:\Windows\system32\gameconfighelper.dll
2024-11-02 08:38 - 2024-09-27 11:16 - 000153152 _____ (Microsoft Corporation) C:\Windows\system32\gamingtcuihelpers.dll
2024-11-02 08:38 - 2024-09-27 11:16 - 000124456 _____ (Microsoft Corporation) C:\Windows\system32\xgamehelper.exe
2024-11-02 08:38 - 2024-09-27 11:16 - 000075304 _____ (Microsoft Corporation) C:\Windows\system32\xgamecontrol.exe
2024-10-31 12:43 - 2022-05-06 21:20 - 000520192 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000400896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000228352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dplayx.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000090112 _____ (Microsoft Corporation) C:\Windows\system32\dpnathlp.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnathlp.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpwsockx.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000049152 _____ (Microsoft Corporation) C:\Windows\system32\dpnsvr.exe
2024-10-31 12:43 - 2022-05-06 21:20 - 000032768 _____ (Microsoft Corporation) C:\Windows\system32\dpnlobby.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000032768 _____ (Microsoft Corporation) C:\Windows\system32\dpnhupnp.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000032768 _____ (Microsoft Corporation) C:\Windows\system32\dpnhpast.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000032768 _____ (Microsoft Corporation) C:\Windows\system32\dpnaddr.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpmodemx.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnsvr.exe
2024-10-31 12:43 - 2022-05-06 21:20 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dplaysvr.exe
2024-10-31 12:43 - 2022-05-06 21:20 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnhupnp.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnhpast.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnlobby.dll
2024-10-31 12:43 - 2022-05-06 21:20 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnaddr.dll
2024-10-31 09:38 - 2024-10-02 10:00 - 000000000 ____D C:\Users\lechn\AppData\Roaming\qBittorrent
2024-10-29 12:10 - 2024-09-28 14:12 - 000000000 ____D C:\Users\lechn\AppData\Local\VS Revo Group
2024-10-27 08:15 - 2024-09-28 08:36 - 000000000 ____D C:\Users\lechn\Calibre Library
2024-10-24 12:41 - 2024-09-27 10:46 - 000000000 ____D C:\Windows\system32\MRT
2024-10-24 10:26 - 2024-10-07 19:14 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2024-10-24 10:26 - 2024-09-27 11:09 - 000000000 ____D C:\Users\lechn\AppData\Local\NVIDIA
2024-10-24 10:26 - 2024-09-27 10:32 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2024-10-22 14:19 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\SysWOW64\setup
2024-10-22 14:19 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\SysWOW64\Dism
2024-10-22 14:19 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\SystemResources
2024-10-22 14:18 - 2024-10-01 14:53 - 000000000 ____D C:\Program Files\Hyper-V
2024-10-22 14:18 - 2022-05-06 23:39 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ___SD C:\Windows\system32\UNP
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ___RD C:\Windows\PrintDialog
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\system32\ShellExperiences
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\system32\Sgrm
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\system32\setup
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\system32\oobe
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\system32\HealthAttestationClient
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\system32\Dism
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\system32\appraiser
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\ShellExperiences
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\ShellComponents
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\DiagTrack
2024-10-22 14:18 - 2022-05-06 21:24 - 000000000 ____D C:\Windows\bcastdvr
2024-10-22 14:18 - 2022-05-06 21:17 - 000000000 ____D C:\Windows\servicing
2024-10-22 09:06 - 2024-09-27 10:43 - 000000000 ____D C:\Users\lechn\AppData\Local\ConnectedDevicesPlatform
2024-10-20 13:17 - 2024-10-03 14:43 - 000000000 ____D C:\Users\lechn\AppData\Local\BlueStacks X
2024-10-15 11:11 - 2024-09-27 17:15 - 000000000 ____D C:\Users\lechn\AppData\Local\UnrealEngine

==================== Files in the root of some directories ========

2024-10-01 20:00 - 2024-10-01 20:00 - 000003406 _____ () C:\Users\lechn\AppData\Local\444903052
2024-10-22 14:03 - 2024-10-22 14:03 - 000007631 _____ () C:\Users\lechn\AppData\Local\Resmon.ResmonCfg

==================== SigCheckExt =========================

2024-11-03 19:30 - 1998-08-06 14:47 - 000304128 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe
2024-11-12 08:35 - 2024-11-12 18:28 - 002401280 _____ (Farbar) C:\Users\lechn\Downloads\FRST64.exe

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)


==================== BCD ================================

==================== End of FRST.txt ========================

Attached Files


Edited by Oh My!, Yesterday, 09:25 AM.


#3 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 59,072 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:15 AM

Posted 13 November 2024 - 09:09 AM

Greetings and :welcome: back to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

===================================================

Ground Rules:
  • First, please keep in mind most of us at BleepingComputer volunteer our assistance for your benefit in your time of need. Please try to match our commitment to you with your patience toward us.
  • It is important to not run any tools or take any steps other than those I will provide for you.
  • Please perform all steps in the order they are listed. If things are not clear or you experience problems be sure to stop and let me know.
  • Please copy and paste all logs into your post unless otherwise requested.
  • When your computer is clean I will let you know, provide instructions to remove tools and reports, and offer you information about how you can combat future infections.
  • If you do not reply to your topic after 5 days I will assume it has been abandoned and I will close it.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.

Allow me some time to review the reports.
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#4 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 59,072 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:15 AM

Posted 13 November 2024 - 09:49 AM

Greetings Pat.
 

RunBySmartscreen(x64).exe
WHH_Tools.lnk
Hard_Configurator
0patch
(InstallShield Software Corporation) C:\Windows\IsUninst.exe
HKLM Group Policy restriction on software: protected <==== ATTENTION
HKLM\...\Policies\Explorer: [EnforceShellExtensionSecurity] 0
HKLM\Software\Policies\...\system: [ShellSmartScreenLevel] Block

What, if anything, can you tell me about these entries.
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#5 PatL

PatL
  • Topic Starter

  •  Avatar image
  • Members
  • 377 posts
  • OFFLINE
  •  
  • Local time:05:15 AM

Posted 13 November 2024 - 09:11 PM

Hey Gary,
 
RunbySmartScreen and WHH_Tools along hard configurator are parts of a series of programs to increase basic Windows Defender Security, I often employ them on a fresh install. 0Patch is a micropatching tool that helps with some zero days. No clue what IsUnist.exe is but before the crash I had checked it out and seemed clean of malware. The Group Policies were placed by Hard Configurator.
 
I tend to tinker with, semi sketchy games/programs which is why I have layered security in such a way. 
 
I have a license for Defender for Endpoint, Malware but on a whim decided to try other alternatives like ESET and then after that Bitdefender =. Eset found a Computrace.A in my UEFI but nothing else. bytes and HitmanPro.Alert, I usually set them up to all work in tandem according to Malwarebytes guidelines.
 
On a whim I ran this in FRST
 
cmd: netsh winsock reset catalog
cmd: netsh int ip reset C:\resettcpip.txt
cmd: Bitsadmin /Reset /Allusers
cmd: ipconfig /flushdns
Removeproxy:
 
Here is that Fixlog
 
Fix result of Farbar Recovery Scan Tool (x64) Version: 12-11-2024
Ran by lechn (12-11-2024 07:26:17) Run:1
Running from C:\Users\lechn\Downloads
Loaded Profiles: lechn
Boot Mode: Normal
==============================================

fixlist content:
*****************
cmd: netsh winsock reset catalog
cmd: netsh int ip reset C:\resettcpip.txt
cmd: Bitsadmin /Reset /Allusers
cmd: ipconfig /flushdns
Removeproxy:
*****************


========= netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.



========= End of CMD: =========


========= netsh int ip reset C:\resettcpip.txt =========

Resetting Compartment Forwarding, OK!
Resetting Compartment, OK!
Resetting Control Protocol, OK!
Resetting Echo Sequence Request, OK!
Resetting Global, OK!
Resetting Interface, OK!
Resetting Anycast Address, OK!
Resetting Multicast Address, OK!
Resetting Unicast Address, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting Potential, OK!
Resetting Prefix Policy, OK!
Resetting Proxy Neighbor, OK!
Resetting Route, OK!
Resetting Site Prefix, OK!
Resetting Subinterface, OK!
Resetting Wakeup Pattern, OK!
Resetting Resolve Neighbor, OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , failed.
Access is denied.

Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Restart the computer to complete this action.



========= End of CMD: =========


========= Bitsadmin /Reset /Allusers =========


BITSADMIN version 3.0
BITS administration utility.
© Copyright Microsoft Corp.

Unable to initialize COM - 0x8007007f
The specified procedure could not be found.

 



========= End of CMD: =========


========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.


========= End of CMD: =========


========= RemoveProxy: =========

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully


========= End of RemoveProxy: =========


==== End of Fixlog 07:26:23 ====

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-11-2024
Ran by lechn (12-11-2024 18:35:14)
Running from C:\Users\lechn\Downloads
Microsoft Windows 11 Pro Version 23H2 22631.4391 (X64) (2024-09-28 01:22:40)
Boot Mode: Safe Mode (minimal)
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-4002474698-1552430223-1960928661-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4002474698-1552430223-1960928661-503 - Limited - Disabled)
Guest (S-1-5-21-4002474698-1552430223-1960928661-501 - Limited - Disabled)
lechn (S-1-5-21-4002474698-1552430223-1960928661-1001 - Administrator - Enabled) => C:\Users\lechn
WDAGUtilityAccount (S-1-5-21-4002474698-1552430223-1960928661-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET Security (Enabled - Up to date) {DF8BEACB-94C9-218A-73AD-A78362A8C516}
AV: Bitdefender Antivirus (Enabled - Up to date) {0F59B032-EA77-E3A8-2382-74A4346E5522}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Firewall (Enabled) {E7B06BEE-DEA6-20D2-58F2-0EB69C7B826D}
FW: Bitdefender Firewall (Enabled) {37623117-A018-E2F0-08DD-DD91CABD1259}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

0patch Agent (HKLM-x32\...\{14417EF0-5440-40AB-90D9-D51AE4642929}) (Version: 22.11.11.10550 - 0patch)
Amazon Kindle (HKU\S-1-5-21-4002474698-1552430223-1960928661-1001\...\Amazon Kindle) (Version: 2.4.0.70904 - Amazon)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 27.0.1.287 - Bitdefender)
Bitdefender Internet Security (HKLM\...\Bitdefender) (Version: 27.0.42.214 - Bitdefender)
BlueStacks (HKLM\...\BlueStacks_nxt) (Version: 5.21.580.1019 - now.gg, Inc.)
BlueStacks Services (HKU\S-1-5-21-4002474698-1552430223-1960928661-1001\...\BlueStacksServices) (Version: 3.0.9 - now.gg, Inc.)
calibre 64bit (HKLM\...\{B7EE05BC-C7DC-4E56-AB79-063A58E9127F}) (Version: 7.21.0 - Kovid Goyal)
CDisplayEx 1.10.33 (HKLM\...\CDisplayEx_is1) (Version: - Progdigy Software S.A.R.L.)
Dell Power Manager Service (HKLM\...\{21390BC8-C4BF-49A2-A4AE-2BBD0DA79CCA}) (Version: 3.16.0 - Dell Inc.)
Dell SupportAssist (HKLM\...\{A1FC489C-7909-4E08-9685-6C77BA2053DE}) (Version: 4.0.3.61632 - Dell Inc.)
Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM\...\{39BF0E71-7A16-4A80-BBCE-FBDD2D1CC2D5}) (Version: 5.5.9.18923 - Dell Inc.) Hidden
Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM-x32\...\{f6a4df94-48f2-459a-8d40-16b1fbed13c5}) (Version: 5.5.9.18923 - Dell Inc.)
Dell SupportAssist Remediation (HKLM\...\{7DF32CAF-9F54-4DC3-9F7C-5B56C540C23C}) (Version: 5.5.12.0 - Dell Inc.) Hidden
Dell SupportAssist Remediation (HKLM-x32\...\{ae6c39ab-48ca-4912-bd28-370419db21e8}) (Version: 5.5.12.0 - Dell Inc.)
Diablo (HKLM-x32\...\Diablo) (Version: - Blizzard Entertainment)
Diablo II Resurrected (HKLM-x32\...\Diablo II Resurrected) (Version: - Blizzard Entertainment)
Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment)
Diablo Immortal (HKLM-x32\...\Diablo Immortal) (Version: - Blizzard Entertainment)
Diablo IV (HKLM-x32\...\Diablo IV) (Version: - Blizzard Entertainment)
Discord (HKU\S-1-5-21-4002474698-1552430223-1960928661-1001\...\Discord) (Version: 1.0.9003 - Discord Inc.)
Doom 3 Enhanced Edition (HKLM-x32\...\{20832903-C12C-41B6-A681-B328EDA4D10C}) (Version: 3.7.0 - lost_acs)
Dynamic Application Loader Host Interface Service (HKLM\...\{EE5AFC69-5911-4A47-B78C-6BFBA883AF15}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Epic Games Launcher (HKLM-x32\...\{B85FAA6E-A9AA-4655-9029-E1A4EDC05E1A}) (Version: 1.3.93.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Epic Online Services (HKLM-x32\...\{57A956AB-4BCC-45C6-9B40-957E4E125568}) (Version: 2.0.44.0 - Epic Games, Inc.)
Epubor Audible Converter (HKLM-x32\...\Epubor Audible Converter) (Version: 1.0.11.225 - epubor Inc.)
Epubor Ultimate (HKLM-x32\...\Epubor Ultimate) (Version: 3.0.16.286 - Epubor Inc.)
HitmanPro 3.8 (HKLM\...\HitmanPro38) (Version: 3.8.36.332 - SurfRight B.V.)
HitmanPro.Alert 3 (HKLM\...\HitmanPro.Alert) (Version: 3.8.26.983 - SurfRight B.V.)
Intel® Icls (HKLM\...\{E50319E3-A4FF-4642-A969-5C89B0A22E54}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1B254687-4D73-4347-94CB-B25EFF73B9E4}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2313.4.16.0 - Intel Corporation)
Intel® Management Engine Driver (HKLM\...\{DD82CAB8-FEBE-4B83-BD5C-F125839A0F70}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® ME WMI Provider (HKLM\...\{5DDCAB56-E374-431D-A70D-BEE3C9F787D1}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Software Installer (HKLM-x32\...\{bddd55ff-828e-4d3d-90dd-cdcc8076d5ba}) (Version: 22.200.2.1 - Intel Corporation) Hidden
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LibreOffice 24.8.2.1 (HKLM\...\{2B5B0425-12C7-4D48-ACA8-38CCA3082A81}) (Version: 24.8.2.1 - The Document Foundation)
Malwarebytes version 5.2.2.154 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.2.2.154 - Malwarebytes)
Microsoft .NET Host - 6.0.35 (x64) (HKLM\...\{C59601A1-771B-426B-A9F7-6CACCAC4DB4E}) (Version: 48.140.21458 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.35 (x64) (HKLM\...\{E91F8AC1-4917-455E-AACA-B40B193C7A62}) (Version: 48.140.21458 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.35 (x64) (HKLM\...\{C79F6EEC-3A2B-487D-A3B6-EDF4057B4E4B}) (Version: 48.140.21458 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 130.0.2849.80 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 130.0.2849.80 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.40.33816 (HKLM-x32\...\{77169412-f642-45e7-b533-0c6f48de12f9}) (Version: 14.40.33816.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.40.33816 (HKLM-x32\...\{4373d0b5-4457-4a80-bad9-029de8df097b}) (Version: 14.40.33816.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.40.33816 (HKLM\...\{5904914B-9FC8-44C2-AE48-5C7F30A603EC}) (Version: 14.40.33816 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.40.33816 (HKLM\...\{560D2DA4-096E-4868-B22A-DA6418FDE6FB}) (Version: 14.40.33816 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.40.33816 (HKLM-x32\...\{0DF1D9F9-6038-4641-AB6D-13DD654758A7}) (Version: 14.40.33816 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.40.33816 (HKLM-x32\...\{D7A66DA5-B103-45C1-A0A7-736C08E2F464}) (Version: 14.40.33816 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.35 (x64) (HKLM\...\{8AA69679-CCD6-42D9-BCDA-99BE386D57B7}) (Version: 48.140.21525 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.35 (x64) (HKLM-x32\...\{ed3bbfea-cc20-425e-b845-bc087d129675}) (Version: 6.0.35.34113 - Microsoft Corporation)
NVIDIA FrameView SDK 1.3.8513.32290073 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8513.32290073 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.28.0.417 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.28.0.417 - NVIDIA Corporation)
NVIDIA Graphics Driver 566.03 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 566.03 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.4.2.6 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.2.6 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
qBittorrent (HKLM-x32\...\qBittorrent) (Version: 5.0.1 - The qBittorrent project)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.18362.31252 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 10.31.828.2018 - Realtek)
StarCraft (HKLM-x32\...\StarCraft) (Version: - Blizzard Entertainment)
StarCraft II (HKLM-x32\...\StarCraft II) (Version: - Blizzard Entertainment)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
The Fifth Element (HKLM-x32\...\The Fifth Element) (Version: - )
The Suffering (HKLM-x32\...\1268478205_is1) (Version: 1.0.1 - GOG.com)
The Suffering: Ties That Bind (HKLM-x32\...\1578481504_is1) (Version: 1.0 - GOG.com)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.21 - VideoLAN)
Warcraft II Battle.net Edition (HKLM-x32\...\Warcraft II Battle.net Edition) (Version: - Blizzard Entertainment)
Warcraft Orcs & Humans (HKLM-x32\...\Warcraft Orcs & Humans) (Version: - Blizzard Entertainment)

Packages:
=========
A Plague Tale: Requiem - Windows -> C:\Program Files\WindowsApps\FocusHomeInteractiveSA.APlagueTaleRequiem-Windows_1.6.0.0_x64__4hny5m903y3g0 [2024-11-11] (Focus Home Interactive SA)
Alan Wake -> C:\Program Files\WindowsApps\Remedy.AlanWakePC_1.0.5.0_x86__a0f1gph4eb81p [2024-09-28] (Remedy)
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2024-11-12] (INTEL CORP) [Startup Task]
Battletoads -> C:\Program Files\WindowsApps\Microsoft.Frogspawn_1.4.2718.0_x64__8wekyb3d8bbwe [2024-09-28] (Microsoft Studios)
Bitdefender CL Contextual Menu -> C:\Program Files\Bitdefender\Bitdefender Security App [2024-11-12] (Bitdefender)
Bloodstained: Ritual of the Night -> C:\Program Files\WindowsApps\505GAMESS.P.A.BloodstainedRitualoftheNightPCGP_1.8.0.0_x64__tefn33qh9azfc [2024-10-22] (505 GAMES S.P.A.)
Control Expansion Pack 1 The Foundation -> C:\Program Files\WindowsApps\505GAMESS.P.A.4100916DF3B82_1.0.0.0_x64__tefn33qh9azfc [2024-09-29] (505 GAMES S.P.A.)
Control Expansion Pack 2 AWE -> C:\Program Files\WindowsApps\505GAMESS.P.A.2054521701B83_1.0.0.0_x64__tefn33qh9azfc [2024-09-29] (505 GAMES S.P.A.)
Control PCGP -> C:\Program Files\WindowsApps\505GAMESS.P.A.ControlPCGP_1.0.6.0_x64__tefn33qh9azfc [2024-09-29] (505 GAMES S.P.A.)
Dell Power Manager -> C:\Program Files\WindowsApps\DellInc.DellPowerManager_3.16.22.0_x64__htrsf667h5kn2 [2024-11-12] (Dell Inc)
Dell SupportAssist for Home PCs -> C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_4.0.16.0_x64__htrsf667h5kn2 [2024-11-12] (Dell Inc)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.25.920.0_x64__rz1tebttyb220 [2024-11-12] (Dolby Laboratories)
DOOM + DOOM II -> C:\Program Files\WindowsApps\BethesdaSoftworks.Osiris2.0_1.0.2584.0_x64__3275kfvn8vcwc [2024-10-04] (Bethesda Softworks)
Frostpunk 2: PC Edition -> C:\Program Files\WindowsApps\4063811bitstudios.Frostpunk2ConsoleEdition_1.41.3230.0_x64__gwy9gn5q9j1y6 [2024-10-31] (11 bit studios)
Gears of War: Ultimate Edition for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.DeltaPC_1.10.0.0_x64__8wekyb3d8bbwe [2024-11-12] (Microsoft Studios)
Halo: The Master Chief Collection -> C:\Program Files\WindowsApps\Microsoft.Chelan_1.3385.0.0_x64__8wekyb3d8bbwe [2024-09-28] (Microsoft Studios)
IrfanView64 -> C:\Program Files\WindowsApps\30067IrfanSkiljanIrfanVie.IrfanView64_4.6.7.0_x64__psgec73n2n7ne [2024-11-12] (Irfan Skiljan (IrfanView))
Lies of P -> C:\Program Files\WindowsApps\Neowiz.3616725F496B_1.5.0.0_x64__r4z3116tdh636 [2024-09-29] (Neowiz)
Lords of the Fallen -> C:\Program Files\WindowsApps\CIGamesS.A.LordsoftheFallen-PC_1.0.18.0_x64__9609msxhzdsvj [2024-11-04] (CI Games S.E.)
Microsoft.MicrosoftPCManager -> C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.14.10.0_x64__8wekyb3d8bbwe [2024-11-12] (Microsoft Corporation) [Startup Task]
NINJA GAIDEN 3: Razor's Edge -> C:\Program Files\WindowsApps\946B6A6E.NINJAGAIDEN3RazorsEdge_1.0.4.0_x64__dkffhzhmh6pmy [2024-09-28] (KOEI TECMO GAMES Co., Ltd.)
NINJA GAIDEN Σ -> C:\Program Files\WindowsApps\946B6A6E.NINJAGAIDENSIGMA_1.0.5.0_x64_NAEU_dkffhzhmh6pmy [2024-09-28] (KOEI TECMO GAMES Co., Ltd.)
NINJA GAIDEN Σ2 -> C:\Program Files\WindowsApps\946B6A6E.NINJAGAIDENSIGMA2_1.0.3.0_x64_NAEU_dkffhzhmh6pmy [2024-09-28] (KOEI TECMO GAMES Co., Ltd.)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.966.0_x64__56jybvy8sckqj [2024-11-12] (NVIDIA Corp.)
Old Mars -> C:\Program Files\WindowsApps\BethesdaSoftworks.PGPreorderContentwPkg_0.0.7.0_x64__3275kfvn8vcwc [2024-09-29] (Bethesda Softworks)
Pillars of Eternity -> C:\Program Files\WindowsApps\ParadoxInteractive.PillarsofEternity-MicrosoftStor_1.3.7.0_x64__zfnrdv2de78ny [2024-09-29] (Microsoft Studios)
Pillars of Eternity 2: Deadfire - PC -> C:\Program Files\WindowsApps\VersusEvil.PillarsofEternity2-PC_1.0.21.0_x64__xa16sj1v690xg [2024-09-29] (Versus Evil, LLC.)
Pillars of Eternity: Deadfire Pack -> C:\Program Files\WindowsApps\ParadoxInteractive.44059571801E4_1.0.0.0_x64__zfnrdv2de78ny [2024-09-29] (Paradox Interactive)
Pillars of Eternity: Royal Edition Upgrade Pack -> C:\Program Files\WindowsApps\ParadoxInteractive.PillarsofEternityRoyalEditionUp_1.0.0.0_x64__zfnrdv2de78ny [2024-09-29] (Paradox Interactive)
Pillars of Eternity: The White March Part I -> C:\Program Files\WindowsApps\ParadoxInteractive.1711547A16A34_1.0.1.0_x64__zfnrdv2de78ny [2024-09-29] (Paradox Interactive)
Pillars of Eternity: The White March Part II -> C:\Program Files\WindowsApps\ParadoxInteractive.6142042F97EAF_1.0.0.0_x64__zfnrdv2de78ny [2024-09-29] (Paradox Interactive)
Prey -> C:\Program Files\WindowsApps\BethesdaSoftworks.LiluDallas-Multipass_1.13.5.0_x64__3275kfvn8vcwc [2024-09-28] (Bethesda Softworks)
Quantum Break -> C:\Program Files\WindowsApps\Microsoft.QuantumBreak_2.5.0.0_x64__8wekyb3d8bbwe [2024-11-12] (Microsoft Studios)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.1.137.0_x64__dt26b99r8h8gj [2024-11-12] (Realtek Semiconductor Corp)
Remnant 2 -> C:\Program Files\WindowsApps\PerfectWorldEntertainment.GFREMP2_1.0.27.0_x64__jrajkyc4tsa6w [2024-11-05] (Arc Games Inc.)
RESIDENT EVIL 2 -> C:\Program Files\WindowsApps\F024294D.GAMEResidentEvil2biohazard2_1.2.0.0_x64_WW_8fty0by30jkny [2024-09-29] (株式会社 カプコン)
RESIDENT EVIL 3 -> C:\Program Files\WindowsApps\F024294D.1052923506B93_1.2.0.0_x64_WW_8fty0by30jkny [2024-09-29] (株式会社 カプコン)
S.T.A.L.K.E.R. 2: Heart of Chornobyl (Windows) -> C:\Program Files\WindowsApps\GSCGameWorld.S.T.A.L.K.E.R.2HeartofChernobyl_1.1.0.0_x64__6fr1t1rwfarwt [2024-10-01] (GSC Game World)
Scorn -> C:\Program Files\WindowsApps\KeplerInteractive.1439274AB3A46_1.2.2.0_x64__ymj30pw7xe604 [2024-09-28] (Kepler Interactive)
Starfield -> C:\Program Files\WindowsApps\BethesdaSoftworks.ProjectGold_1.14.70.0_x64__3275kfvn8vcwc [2024-09-30] (Bethesda Softworks)
Still Wakes the Deep -> C:\Program Files\WindowsApps\SecretMode.ProjectHabitat_1.3.2.0_x64__w0mtarpevwbkm [2024-09-28] (Secret Mode Limited)
Sysinternals Suite -> C:\Program Files\WindowsApps\Microsoft.SysinternalsSuite_2024.7.0.0_x64__8wekyb3d8bbwe [2024-11-12] (Microsoft Corporation)
The Bard's Tale Trilogy -> C:\Program Files\WindowsApps\Microsoft.TheBardsTaleTrilogy_1.0.4177.0_x64__8wekyb3d8bbwe [2024-10-15] (Microsoft Studios)
The Chess Lv.100 -> C:\Program Files\WindowsApps\6918E89D.THECHESSLV.100_2.9.0.0_x64__66n08swfvvka0 [2024-11-12] (UNBALANCE corp.)
Torment: Tides of Numenera -> C:\Program Files\WindowsApps\Microsoft.Torment_1.0.1.0_x64__8wekyb3d8bbwe [2024-09-29] (Microsoft Studios)
Windows Feature Experience Pack -> C:\Windows\SystemApps\LKG\MicrosoftWindows.LKG.DesktopSpotlight_cw5n1h2txyewy [2024-10-22] (Microsoft Windows)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [HitmanPro.Alert Shell Extension] -> {6FAC02B7-77D6-418B-AC11-962C65CDE8DD} => C:\Windows\system32\hmpshell.dll [2024-10-03] (Sophos BV -> Sophos B.V.)
ContextMenuHandlers1: [HitmanPro] -> {D7CF1AF8-E2AD-4DA4-ACE5-77F8A58AB71D} => C:\Program Files\HitmanPro\hmpshext.dll [2024-10-24] (Sophos BV -> Sophos B.V.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2024-11-05] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers4: [HitmanPro] -> {D7CF1AF8-E2AD-4DA4-ACE5-77F8A58AB71D} => C:\Program Files\HitmanPro\hmpshext.dll [2024-10-24] (Sophos BV -> Sophos B.V.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nvdmi.inf_amd64_a3eaecfbb94ad6bc\nvshext.dll [2024-10-15] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2024-11-05] (Malwarebytes Inc. -> Malwarebytes)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="1"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-4002474698-1552430223-1960928661-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2022-05-06 21:24 - 2024-10-07 17:13 - 000000779 _____ C:\Windows\system32\drivers\etc\hosts

2024-10-01 14:55 - 2024-11-08 09:55 - 000000715 _____ C:\Windows\system32\drivers\etc\hosts.ics
172.26.64.1 DESKTOP-32DBH15.mshome.net # 2029 11 3 7 17 55 45 767
11 0 3 14 17 14 430
172.24.192.1 DESKTOP-32DBH15.mshome.net # 2029 11 4 1 16 19 12 268
11 0 3 14 17 14 430
172.30.80.1 DESKTOP-32DBH15.mshome.net # 2029 10 0 28 22 10 44 944
4 11 0 3 14 17 14 430
172.17.144.1 DESKTOP-32DBH15.mshome.net # 2029 10 5 26 14 17 14 430

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4002474698-1552430223-1960928661-1001\Control Panel\Desktop\\Wallpaper -> D:\Pictures\war-cantmaster_low.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)

Network Binding:
=============

vms_vsf: Hyper-V Virtual Switch Extension Filter
ms_hvsifltr: Microsoft Defender Application Guard Filter Driver
vms_vsp: Hyper-V Virtual Switch Extension Protocol

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKU\S-1-5-21-4002474698-1552430223-1960928661-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-4002474698-1552430223-1960928661-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-4002474698-1552430223-1960928661-1001\...\StartupApproved\Run: => "electron.app.BlueStacks Services"
HKU\S-1-5-21-4002474698-1552430223-1960928661-1001\...\StartupApproved\Run: => "Discord"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{E9F787CA-D38F-4EE6-9338-C9D9078E08A6}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24244.507.3118.4732_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B06575B6-8217-4CAF-9100-B94CF156AF08}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24244.507.3118.4732_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E0838307-D0F6-4202-9C7B-83295A5EC149}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{8DDC9C7B-3807-4565-A735-7F537AFA844A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{54632671-1DC7-47B6-90D4-D3CCF4D9AEF5}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{357D701C-D9E0-4131-A86D-FEBCE6B388D4}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{667EE371-FA02-41F7-B9BE-882314921322}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BlackMythWukong\b1.exe (Game Science Interactive Technology Co., Ltd. -> Epic Games, Inc.)
FirewallRules: [{DECCBF7B-316E-4C46-B737-C005DB9E08BF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BlackMythWukong\b1.exe (Game Science Interactive Technology Co., Ltd. -> Epic Games, Inc.)
FirewallRules: [{B2C06872-1EDD-48FA-B9B8-60239EA93F38}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Baldurs Gate 3\Launcher\LariLauncher.exe (Larian Studios Games Ltd. -> LariLauncher)
FirewallRules: [{0F012AD7-AF0D-4BF5-B7BF-968006B4C038}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Baldurs Gate 3\Launcher\LariLauncher.exe (Larian Studios Games Ltd. -> LariLauncher)
FirewallRules: [{8C2C948D-69E1-421C-9D7B-C796C49971D2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\CastlevaniaLoS\bin\CastlevaniaLoSUE.exe (Mercury Steam Entertainment) [File not signed]
FirewallRules: [{A45EA136-E042-478A-B80D-52A6C5CB7991}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\CastlevaniaLoS\bin\CastlevaniaLoSUE.exe (Mercury Steam Entertainment) [File not signed]
FirewallRules: [{5958EB10-FFDD-4AD3-9F54-665CB2817042}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Castlevania Lords of Shadow - Mirror of Fate HD\CMOF.exe (Mercury Steam Entertainment S.L.) [File not signed]
FirewallRules: [{6886EEF7-0674-4A69-B8FB-6E8A6CDB7083}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Castlevania Lords of Shadow - Mirror of Fate HD\CMOF.exe (Mercury Steam Entertainment S.L.) [File not signed]
FirewallRules: [{A98CE28A-DEA9-433B-A2A8-3019EB9A9F59}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Castlevania Lords of Shadow 2\bin\CLOS2.exe (Mercury Steam Entertainment S.L.) [File not signed]
FirewallRules: [{F1AEB4F1-AEB5-4B08-80B5-2F7387730465}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Castlevania Lords of Shadow 2\bin\CLOS2.exe (Mercury Steam Entertainment S.L.) [File not signed]
FirewallRules: [{D28AC8BC-2A64-40E2-B8FE-21EDD14903CE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dead Space (2023)\Dead Space.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{19D64D87-6C36-4CDE-BD53-F48F2A96D558}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dead Space (2023)\Dead Space.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{7366E536-748E-4192-9F68-BCAD3B5EED9B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dead Space 2\deadspace2.exe (Electronic Arts Inc.) [File not signed]
FirewallRules: [{D875B280-2E23-44C3-9C46-0A4A1D0A74EC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dead Space 2\deadspace2.exe (Electronic Arts Inc.) [File not signed]
FirewallRules: [{04FE1B8C-965F-45D6-B5D1-730DA444735C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cyberpunk 2077\REDprelauncher.exe (CD PROJEKT S.A. -> CD Projekt RED)
FirewallRules: [{F6364974-ADFA-4E12-BD4F-2CD31703ABE6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cyberpunk 2077\REDprelauncher.exe (CD PROJEKT S.A. -> CD Projekt RED)
FirewallRules: [{E6346E85-6F34-4819-BA8B-4D035F706B81}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Doom 3\Doom3.exe (id Software) [File not signed]
FirewallRules: [{61E6865A-E055-4FC2-821D-BA3C93830075}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Doom 3\Doom3.exe (id Software) [File not signed]
FirewallRules: [{7729BCCB-C21B-43F5-AB33-1CF73290AA2E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dragon Age Ultimate Edition\DAOriginsLauncher.exe (BioWare -> BioWare)
FirewallRules: [{BE8F8C38-2518-4C83-A921-B4A895B0868F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dragon Age Ultimate Edition\DAOriginsLauncher.exe (BioWare -> BioWare)
FirewallRules: [{4964DE02-C089-4EB3-8647-716C3493D5A8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ryse Son of Rome\Bin64\Ryse.exe (Crytek GmbH) [File not signed]
FirewallRules: [{8CB063BA-3B8B-47A1-A0FF-D9A5B654CF62}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ryse Son of Rome\Bin64\Ryse.exe (Crytek GmbH) [File not signed]
FirewallRules: [{5602FF0F-82BD-489D-A5E6-E528749831D7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Pine Harbor\PineHarbor.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{F5E56C1D-A7F8-43C9-8723-2157C9609FC3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Pine Harbor\PineHarbor.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{D09089C7-6DB7-43BA-B4CA-705BCF97BD7A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FEAR Ultimate Shooter Edition\FEAR.exe (Monolith Productions, Inc.) [File not signed]
FirewallRules: [{B482A68B-6A68-494F-8B2F-288B0E6460F2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FEAR Ultimate Shooter Edition\FEAR.exe (Monolith Productions, Inc.) [File not signed]
FirewallRules: [{09B9AB5D-FBA2-42F6-959F-5B00998CB63B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FEAR Ultimate Shooter Edition\FEARXP\FEARXP.exe (Monolith Productions, Inc.) [File not signed]
FirewallRules: [{D9E8AFE0-FC3D-496E-980F-B3224C1C7656}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FEAR Ultimate Shooter Edition\FEARXP\FEARXP.exe (Monolith Productions, Inc.) [File not signed]
FirewallRules: [{B69D891D-513E-4D32-963B-0B4EB3595FAC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FEAR Ultimate Shooter Edition\FEARXP2\FEARXP2.exe (TimeGate Studios, Inc.) [File not signed]
FirewallRules: [{5C9FCF4E-BC64-4174-9B5B-F64443990481}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FEAR Ultimate Shooter Edition\FEARXP2\FEARXP2.exe (TimeGate Studios, Inc.) [File not signed]
FirewallRules: [{3F47E912-B53E-4B4C-8DCA-73585E231442}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FEAR2\FEAR2.exe (Monolith Productions, Inc. -> Monolith Productions, Inc.)
FirewallRules: [{F6C42094-F90F-4777-ACD0-4C70747D6661}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FEAR2\FEAR2.exe (Monolith Productions, Inc. -> Monolith Productions, Inc.)
FirewallRules: [{FA1DCE99-70FD-4B32-B759-B3108719B912}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\F.E.A.R. 3\F.E.A.R. 3.exe (Valve Corp. -> Day 1 Studios, LLC) [File not signed]
FirewallRules: [{163D7609-F642-47C7-AE63-D7CB12965A36}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\F.E.A.R. 3\F.E.A.R. 3.exe (Valve Corp. -> Day 1 Studios, LLC) [File not signed]
FirewallRules: [{F1AFFC6E-5587-4C03-90FB-BD4F68124C80}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Final Fantasy IV\FF4_Launcher.exe (SQUARE ENIX CO., LTD. -> SQUARE ENIX CO., LTD.)
FirewallRules: [{3F4EA0AE-9C38-4E65-8377-FFF5CE47AC82}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Final Fantasy IV\FF4_Launcher.exe (SQUARE ENIX CO., LTD. -> SQUARE ENIX CO., LTD.)
FirewallRules: [{5047D1EC-352E-4C16-8370-D1825DE33C16}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FINAL FANTASY VII\FF7_Launcher.exe (Square Enix Ltd. -> )
FirewallRules: [{1D0960F1-0902-4799-8CA6-69F042DEAA3C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FINAL FANTASY VII\FF7_Launcher.exe (Square Enix Ltd. -> )
FirewallRules: [{B7FED514-BE01-4A2C-BD20-D715E31E7247}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto 3\gta3.exe () [File not signed]
FirewallRules: [{7F389556-9C8C-403F-B335-FCCB91F78C6D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto 3\gta3.exe () [File not signed]
FirewallRules: [{6DE6206C-DD64-473D-B6B0-6D656564BD7F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GreedFall\GreedFall.exe (Focus Home Interactive S.A -> Spiders)
FirewallRules: [{A4DBFA0A-A3B7-4886-8EF5-26C8C7DF7BFD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GreedFall\GreedFall.exe (Focus Home Interactive S.A -> Spiders)
FirewallRules: [{A5883322-B0B9-40D8-B050-58558DA2DA0E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hellblade\HellbladeGame.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{4D5289ED-1692-472B-8028-3648A168BB32}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hellblade\HellbladeGame.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{F1B08285-1699-47A1-9397-5D6BCCFC7A4E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hellblade\HellbladeGame\Binaries\Win64\HellbladeGame-Win64-Shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{EBD8EA0B-48A7-4E3C-A553-AAA4C699BE46}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hellblade\HellbladeGame\Binaries\Win64\HellbladeGame-Win64-Shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{1F8628A3-AF9A-45F1-B1FF-979AEEB56A0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdoms of Amalur Re-Reckoning\koa.exe () [File not signed]
FirewallRules: [{1CA4936F-8040-4C23-850B-C26E5EF3202F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdoms of Amalur Re-Reckoning\koa.exe () [File not signed]
FirewallRules: [{2DF704A0-A7F2-4BF6-8B16-8C4525DC44C2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Prey 2006\prey.exe (Human Head Studios) [File not signed]
FirewallRules: [{E9A3136F-F6D3-42A6-B796-20B9BBDDA292}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Prey 2006\prey.exe (Human Head Studios) [File not signed]
FirewallRules: [{8C739995-9CA0-4755-9456-66D61ADD3D24}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Pathologic Classic HD\bin\Final\Game.exe () [File not signed]
FirewallRules: [{F76C79AD-9776-4268-80A6-6EE63AB95476}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Pathologic Classic HD\bin\Final\Game.exe () [File not signed]
FirewallRules: [{3F73DE87-D1F7-4A86-96A6-D6D221D89CFF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Layers of Fear\LayersOfFear.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{A413506A-8289-411E-8DC1-6BBBE6CD2A2C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Layers of Fear\LayersOfFear.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{ECFED208-15BA-462B-9E28-DB6EF1C80F39}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\HELLGATE_London\Hellgate.exe (Hanbitsoft, inc.) [File not signed]
FirewallRules: [{198FAC31-AAAE-48D0-BC16-D4435C1DE9A9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\HELLGATE_London\Hellgate.exe (Hanbitsoft, inc.) [File not signed]
FirewallRules: [{3298A889-A62A-4CDB-8FFA-7F4BAC2DC274}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hunted\BINARIES\WIN32\HUNTED.EXE (ZeniMax Media Inc.) [File not signed]
FirewallRules: [{962CFF46-7922-4536-94D2-48F221D6D009}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hunted\BINARIES\WIN32\HUNTED.EXE (ZeniMax Media Inc.) [File not signed]
FirewallRules: [{F9704A0B-722A-4D12-A094-7BB744E92CFC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Icewind Dale Enhanced Edition\icewind.exe (Overhaul Games™) [File not signed]
FirewallRules: [{505D7DE8-F255-40BF-B278-3588415294C2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Icewind Dale Enhanced Edition\icewind.exe (Overhaul Games™) [File not signed]
FirewallRules: [{9F8FECCB-48F9-4C84-9894-6F4DBE2CB8A9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades\x64\Hades.exe () [File not signed]
FirewallRules: [{ED4CAC92-854F-4FAB-BB9E-9D9F08E431FD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades\x64\Hades.exe () [File not signed]
FirewallRules: [{1A6365DC-042C-4E77-B946-6D0BBE6D555C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades\x64Vk\Hades.exe () [File not signed]
FirewallRules: [{B77187E2-9D6F-47AD-B8C2-4924713FCD20}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades\x64Vk\Hades.exe () [File not signed]
FirewallRules: [{F07ECD80-D08C-48BB-AAFD-0C065FC7CF00}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades\x86\Hades.exe () [File not signed]
FirewallRules: [{8FE602A0-7C0C-465C-BE60-61A41C883D72}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades\x86\Hades.exe () [File not signed]
FirewallRules: [{8F0BCCE9-D2E1-49C0-8D94-246D49BA2A1C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades II\Ship\Hades2.exe (Supergiant Games, LLC -> Supergiant Games, LLC)
FirewallRules: [{ACA6570F-6F01-45D5-8BEA-664A3346470F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades II\Ship\Hades2.exe (Supergiant Games, LLC -> Supergiant Games, LLC)
FirewallRules: [{A3817D2B-068C-4E7A-9FCB-27EDC9AE019E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Firewatch\Firewatch.exe () [File not signed]
FirewallRules: [{528753BF-895F-4030-A1A7-631EFA3BAF0F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Firewatch\Firewatch.exe () [File not signed]
FirewallRules: [{A6B8E271-D4DA-4D6D-BC51-EDD7A5390F5B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Advent Rising\System\Play Advent Rising.exe (Majesco Entertainment) [File not signed]
FirewallRules: [{4B8AEEBB-D6FE-4968-BE1B-ED1598832E01}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Advent Rising\System\Play Advent Rising.exe (Majesco Entertainment) [File not signed]
FirewallRules: [{EA6921F1-051D-4BC4-8694-25B6A4EAA527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Advent Rising\System\advent.exe () [File not signed]
FirewallRules: [{074A28FD-0C2B-4456-A0DE-8C96DA54ABCA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Advent Rising\System\advent.exe () [File not signed]
FirewallRules: [{4ADFD394-55AF-4D37-B1EF-A9ADDB6D0E06}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blood Omen 2 Legacy of Kain\bo2.exe () [File not signed]
FirewallRules: [{3361F419-F51E-416F-BF15-7D464D0B739A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blood Omen 2 Legacy of Kain\bo2.exe () [File not signed]
FirewallRules: [{F2D1E1EC-0940-4660-AA57-04555E22EE22}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\legacy_kain_defiance\defiance.exe (Eidos Inc.) [File not signed]
FirewallRules: [{5FCA46F7-CDE4-42F3-8F26-76E8AF8F4609}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\legacy_kain_defiance\defiance.exe (Eidos Inc.) [File not signed]
FirewallRules: [{8DFBFCAE-AC79-4C35-9B7B-D0F8D3BC4D23}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Legacy of Kain Soul Reaver\kain2.exe () [File not signed]
FirewallRules: [{E880F3A7-9F13-4275-A815-C1A10671C80C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Legacy of Kain Soul Reaver\kain2.exe () [File not signed]
FirewallRules: [{764218DC-A736-48E5-B5A7-2C030ACF75F9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Legacy of Kain Soul Reaver 2\sr2.exe () [File not signed]
FirewallRules: [{E82DB63C-0B5A-47E2-80B1-3E1FCDC6E2A2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Legacy of Kain Soul Reaver 2\sr2.exe () [File not signed]
FirewallRules: [{D619D2A9-C1DE-4DDA-B464-9B32B14F3490}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Imperium Galactica\DOSBOX\DOSBox.exe (DOSBox Team) [File not signed]
FirewallRules: [{CF13BBC8-60E2-4EFE-A39C-93E7AFA199DB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Imperium Galactica\DOSBOX\DOSBox.exe (DOSBox Team) [File not signed]
FirewallRules: [{297BB70D-04A8-4C69-9FB0-0759B5213051}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Imperium Galactica II\ig2.exe () [File not signed]
FirewallRules: [{A87DCD7C-0BCD-4FD2-BFA4-F1955DFBD610}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Imperium Galactica II\ig2.exe () [File not signed]
FirewallRules: [{9F4D19FF-A929-4626-9199-EC7B35EDD65D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Project P\Torment.exe (Overhaul Games™) [File not signed]
FirewallRules: [{1DC5DBD9-E3A3-42CE-ADF6-33AFDBF3D5D2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Project P\Torment.exe (Overhaul Games™) [File not signed]
FirewallRules: [{688FE12B-E45C-4427-B537-77BDC4F7328F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Baldurs Gate 3 Toolkit\Glasses.exe () [File not signed]
FirewallRules: [{663405E9-451C-4E0D-80E9-1FCDA18A9877}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Baldurs Gate 3 Toolkit\Glasses.exe () [File not signed]
FirewallRules: [{2089D676-0B65-446B-B6E8-CF55F5C612F6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Baldur's Gate II Enhanced Edition\Baldur.exe (Overhaul Games™) [File not signed]
FirewallRules: [{415C9F89-7474-4241-88B2-4148C70F298C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Baldur's Gate II Enhanced Edition\Baldur.exe (Overhaul Games™) [File not signed]
FirewallRules: [{663E2A6D-7FD5-4B4F-B56B-4E82C1B60211}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Aliens versus Predator Classic\Launcher\AvpGoldLauncher.exe () [File not signed]
FirewallRules: [{F4CFA4EA-B1C3-40E0-9D38-C6A7C5B3D75F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Aliens versus Predator Classic\Launcher\AvpGoldLauncher.exe () [File not signed]
FirewallRules: [{ED64E9BF-DFB2-4B50-8FE5-E4A1A4079158}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Alpha Protocol\APLauncher.exe (Obsidian Entertainment, Inc.) [File not signed]
FirewallRules: [{2FB121A1-812F-4AFB-AA8F-7380FC63731F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Alpha Protocol\APLauncher.exe (Obsidian Entertainment, Inc.) [File not signed]
FirewallRules: [{DC33357B-763B-41E8-8497-6D98E4BB9644}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ADOM\adom.exe () [File not signed]
FirewallRules: [{CA2A63A1-53CE-42FD-A99F-D60EF4101C11}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ADOM\adom.exe () [File not signed]
FirewallRules: [{C21EB2B9-F2EA-4880-B538-6A23C08D0BD5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Baldur's Gate Enhanced Edition\Baldur.exe (Overhaul Games™) [File not signed]
FirewallRules: [{FD3B5206-4094-4CEE-90E4-213040DD18C1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Baldur's Gate Enhanced Edition\Baldur.exe (Overhaul Games™) [File not signed]
FirewallRules: [{E88A61B8-53A2-412F-9866-3900EE37BE0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Aliens vs Predator\AvP_Launcher.exe (Sega Europe Limited -> Sega Europe Limited)
FirewallRules: [{02C9B36A-46E9-482B-989F-40A9007882F6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Aliens vs Predator\AvP_Launcher.exe (Sega Europe Limited -> Sega Europe Limited)
FirewallRules: [{11720BA2-ED7C-4B85-BC91-ED937240559C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Aliens vs Predator\AvP_DX11.exe (Valve Corp. -> Sega Europe Limited) [File not signed]
FirewallRules: [{E066697A-B421-40A9-84B6-71B10E765C3A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Aliens vs Predator\AvP_DX11.exe (Valve Corp. -> Sega Europe Limited) [File not signed]
FirewallRules: [{59F3DB9A-9A8E-4EAF-BEF6-C347BDE53A21}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Aliens vs Predator\AvP.exe (Valve Corp. -> Sega Europe Limited) [File not signed]
FirewallRules: [{EFA7DEDB-F192-4CF1-BEFD-41C5AD9B0EFC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Aliens vs Predator\AvP.exe (Valve Corp. -> Sega Europe Limited) [File not signed]
FirewallRules: [{FE3A6AE9-42C1-4112-869B-73B1FD92648D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crysis\Bin32\Crysis.exe (Crytek GmbH) [File not signed]
FirewallRules: [{49A14C41-7729-4428-B101-ADB5D59EA17A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crysis\Bin32\Crysis.exe (Crytek GmbH) [File not signed]
FirewallRules: [{AAC52578-BB49-4968-AE39-E01E0D1B7C26}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crysis\Bin64\Crysis.exe (GOG Limited -> Crytek GmbH)
FirewallRules: [{DB39CB76-3BA6-4C8C-8FB2-9224CFC03FDD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crysis\Bin64\Crysis.exe (GOG Limited -> Crytek GmbH)
FirewallRules: [{C64E3A4F-6339-4AA2-8639-4ECFFBC6FDE2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe (Bethesda Softworks -> Bethesda Softworks, Obsidian Entertainment)
FirewallRules: [{AD30A39F-2F67-4906-A1E1-BE471F8F25DD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe (Bethesda Softworks -> Bethesda Softworks, Obsidian Entertainment)
FirewallRules: [{731E85FC-7C39-44F9-860D-7B3A441BC493}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons & Dragons HD\ManaGame.exe () [File not signed]
FirewallRules: [{F83353D7-657A-4675-BDBB-D5A9C1C76D36}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons & Dragons HD\ManaGame.exe () [File not signed]
FirewallRules: [{9115BD5F-40AC-4DBA-AD35-B12972D86939}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry\Bin32\FarCry.exe (Crytek) [File not signed]
FirewallRules: [{A9B368E6-F03B-44C3-9866-F8C7A7EDCC27}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry\Bin32\FarCry.exe (Crytek) [File not signed]
FirewallRules: [{FAAE1DEA-46E5-4C2E-925E-C1AA80DAE6C4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry\Bin32\FarCryConfigurator.exe (Crytek) [File not signed]
FirewallRules: [{C6A88788-6680-4CB8-9813-217B8EA7DAA0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry\Bin32\FarCryConfigurator.exe (Crytek) [File not signed]
FirewallRules: [{5AC93FA8-EA63-478C-A733-8D85204E5FF7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Elder Scrolls Arena\DOSBox-0.74\DOSBox.exe (DOSBox Team) [File not signed]
FirewallRules: [{C9070440-9966-4DB5-87AE-D57EF994AB3A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Elder Scrolls Arena\DOSBox-0.74\DOSBox.exe (DOSBox Team) [File not signed]
FirewallRules: [{7670DADB-F9AE-4715-B09F-1E4B424CD7FD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Elder Scrolls Daggerfall\DOSBox-0.74\DOSBox.exe (DOSBox Team) [File not signed]
FirewallRules: [{B38BD0A7-0D64-4931-98CC-A1408E0F183D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Elder Scrolls Daggerfall\DOSBox-0.74\DOSBox.exe (DOSBox Team) [File not signed]
FirewallRules: [{0A45C24A-F787-42C7-A513-56FB001329F1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Morrowind\Morrowind Launcher.exe (Bethesda Softworks) [File not signed]
FirewallRules: [{85683B26-CD64-451F-AC2F-810023E28CE2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Morrowind\Morrowind Launcher.exe (Bethesda Softworks) [File not signed]
FirewallRules: [{3816DD34-2CE5-4F6A-B42D-1D5725651BBD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Oblivion\OblivionLauncher.exe (Bethesda Softworks) [File not signed]
FirewallRules: [{EC1FFA4E-AC03-42E4-B17E-81A274888AC6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Oblivion\OblivionLauncher.exe (Bethesda Softworks) [File not signed]
FirewallRules: [{5E21480B-F0D6-4B50-941D-5CABBC153DA4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe (Bethesda Softworks LLC -> Bethesda Softworks)
FirewallRules: [{7CDCDC93-F102-4298-8C7E-3533103C8A4D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe (Bethesda Softworks LLC -> Bethesda Softworks)
FirewallRules: [{11FEE19B-F01D-498C-9795-D58960F6751A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Divinity Original Sin 2\bin\SupportTool.exe (LariLauncher) [File not signed]
FirewallRules: [{385744C7-FFA5-49EA-9359-0584ED3AECB2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Divinity Original Sin 2\bin\SupportTool.exe (LariLauncher) [File not signed]
FirewallRules: [{9937C7B1-3B9E-4B09-BD2D-E993E2B6EF1C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Divinity Original Sin Enhanced Edition\Shipping\EoCApp.exe () [File not signed]
FirewallRules: [{62FF01FA-47CD-4BEA-8CF8-5BB1886D4794}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Divinity Original Sin Enhanced Edition\Shipping\EoCApp.exe () [File not signed]
FirewallRules: [{F42E379A-A6E5-41EE-8EA8-C900D17E76E0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\STALKER Shadow of Chernobyl\bin\XR_3DA.exe (GSC Game World -> )
FirewallRules: [{806E345C-F5EB-4CA3-AB84-7513FC725E77}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\STALKER Shadow of Chernobyl\bin\XR_3DA.exe (GSC Game World -> )
FirewallRules: [{34C0A45E-D111-4101-BA00-4EC894EE5596}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stalker Call of Pripyat\bin\xrEngine.exe (GSC Game World -> GSC Game World)
FirewallRules: [{6DFC1B9C-2E8D-4B07-B62F-C2CBE1AA75CF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stalker Call of Pripyat\bin\xrEngine.exe (GSC Game World -> GSC Game World)
FirewallRules: [{706FDE45-6670-41C8-B4C3-3A37DFECD4DC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\STALKER Clear Sky\bin\xrEngine.exe (GSC Game World -> )
FirewallRules: [{B5D74650-1E03-4DFF-85AE-FDCA6D075C54}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\STALKER Clear Sky\bin\xrEngine.exe (GSC Game World -> )
FirewallRules: [{0223FB12-FBB6-43BD-A87A-86ED75D3CF01}] => (Allow) C:\Program Files (x86)\BlueStacks X\BlueStacksWeb.exe (Now.gg, INC -> Bluestack Systems, Inc.)
FirewallRules: [{F729CF0A-7C73-42F1-BD7F-43630F0E1EF3}] => (Allow) C:\Program Files\BlueStacks_nxt\HD-Player.exe (Now.gg, INC -> BlueStack Systems)
FirewallRules: [{09FC1EE0-5A92-480B-92C1-71E4379DB65A}] => (Allow) C:\Program Files\BlueStacks_nxt\BlueStacksAppplayerWeb.exe (Now.gg, INC -> The Qt Company Ltd.)
FirewallRules: [{9B9F736C-A777-4450-B66F-01399108E95E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blade Runner Enhanced Edition\BladeRunnerRemastered.exe (Nightdive Studios) [File not signed]
FirewallRules: [{E57FE917-DED2-4A9B-8EA6-A69B8B83ED27}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blade Runner Enhanced Edition\BladeRunnerRemastered.exe (Nightdive Studios) [File not signed]
FirewallRules: [{FE63D86C-F7DE-4970-A70A-20215198EBDA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blade Runner Enhanced Edition\Classic\ScummVM\scummvm.exe (scummvm.org) [File not signed]
FirewallRules: [{43089D90-7119-4295-B74A-BF9834297DEA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blade Runner Enhanced Edition\Classic\ScummVM\scummvm.exe (scummvm.org) [File not signed]
FirewallRules: [{DDAA5E55-353B-41ED-8C47-2541E7DF8663}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Black Mesa\bms.exe () [File not signed]
FirewallRules: [{950D611F-EE4A-475D-AD1A-5665FBA515BD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Black Mesa\bms.exe () [File not signed]
FirewallRules: [{1D5EB40F-69D1-4BEA-9817-0AF6D42837A5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blade of Darkness\bin\bin\Blade.exe () [File not signed]
FirewallRules: [{1549656F-C0D0-4B6D-A61B-F8A2023AA00F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blade of Darkness\bin\bin\Blade.exe () [File not signed]
FirewallRules: [{7F969413-3844-4AD3-89AC-49346D4ADE18}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blade of Darkness\classic\Bin\Blade.exe (Rebel Act Studios) [File not signed]
FirewallRules: [{BAE3E95D-5F1C-427B-96E9-5650B0BB560C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blade of Darkness\classic\Bin\Blade.exe (Rebel Act Studios) [File not signed]
FirewallRules: [{C48C73F3-CC84-4323-BBEF-D75F2983413D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blade of Darkness\classic\Bin\nglide_config.exe (Zeus Software) [File not signed]
FirewallRules: [{E13CF6AE-DAF6-4216-ABA3-ACC3052DCB6E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blade of Darkness\classic\Bin\nglide_config.exe (Zeus Software) [File not signed]
FirewallRules: [{8E638A55-C883-4565-975B-EF0E22B46216}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\the witcher 2\Launcher.exe (CD Projekt RED) [File not signed]
FirewallRules: [{CEACB9DF-1646-49E7-B8CB-19B9A9905EEB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\the witcher 2\Launcher.exe (CD Projekt RED) [File not signed]
FirewallRules: [{9AB397F7-7622-4BF1-AAB7-AAD1ECE0E8BA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Witcher Enhanced Edition\System\witcher.exe (CD Projekt Red) [File not signed]
FirewallRules: [{5390449C-FE64-412D-8258-07DC42BCF994}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Witcher Enhanced Edition\System\witcher.exe (CD Projekt Red) [File not signed]
FirewallRules: [{9FFF261F-C355-4E25-AC3E-18F6F39862B5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Witcher Enhanced Edition\System\djinni!.exe (CD Projekt RED Sp. z o.o. -> CD Projekt Red)
FirewallRules: [{BDFF9FD6-29DB-4037-A8F8-05FA86479F69}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Witcher Enhanced Edition\System\djinni!.exe (CD Projekt RED Sp. z o.o. -> CD Projekt Red)
FirewallRules: [{4FA82E1C-2084-4E80-809B-76449D6B1A74}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Witcher Enhanced Edition\Digital Comic\DigitalComic.exe () [File not signed]
FirewallRules: [{E08AB8E4-1639-4A6F-810C-F92AF3E22D68}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Witcher Enhanced Edition\Digital Comic\DigitalComic.exe () [File not signed]
FirewallRules: [{E2BFDAB3-61FE-4407-8FB4-DD75A38709F8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\System Shock Remake\SystemShock.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{2BF04398-EA19-4A7F-B5AF-BD99C190C692}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\System Shock Remake\SystemShock.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{46BFDA56-AB1D-4C75-83BD-0DC8B26C122F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Knights of the Old Republic II\swkotor2.exe (Obsidian Entertainment, Inc.) [File not signed]
FirewallRules: [{2DF6551E-2C19-4416-B177-EC5BAE8C2E10}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Knights of the Old Republic II\swkotor2.exe (Obsidian Entertainment, Inc.) [File not signed]
FirewallRules: [{56FB58EE-6C1F-47B7-932D-4B66EED6D3C7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\swkotor\swkotor.exe (BioWare Corp.) [File not signed]
FirewallRules: [{3244F292-0152-4153-96BB-BB068CC628ED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\swkotor\swkotor.exe (BioWare Corp.) [File not signed]
FirewallRules: [{EB9A14BA-7E73-45FC-8951-A8AD50D64DD8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars Shadows of the Empire\Sdata\Shadows.exe () [File not signed]
FirewallRules: [{C11567B7-EFF8-4FFF-BCE9-EE2420868094}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars Shadows of the Empire\Sdata\Shadows.exe () [File not signed]
FirewallRules: [{F0CB11DD-147A-4AB0-AF70-3F6C33AF4A60}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars The Force Unleashed 2\SWTFU2.exe (LucasArts) [File not signed]
FirewallRules: [{97A5FAE6-BB10-46B0-80FB-4FF567B5253C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars The Force Unleashed 2\SWTFU2.exe (LucasArts) [File not signed]
FirewallRules: [{C3051F21-9520-4E6C-929A-E13CE43EF609}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars The Force Unleashed\SWTFU Launcher.exe (Aspyr Media, Inc. -> Lucas Arts, Inc.)
FirewallRules: [{7A7F179E-9C79-430C-8EFB-511DD3C3E1FA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars The Force Unleashed\SWTFU Launcher.exe (Aspyr Media, Inc. -> Lucas Arts, Inc.)
FirewallRules: [{67C7F5E9-8411-4E56-B731-07DCD49A2B0F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Jedi Outcast\GameData\jk2sp.exe () [File not signed]
FirewallRules: [{08FEA607-22C5-4B32-B39F-53D45A78D09B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Jedi Outcast\GameData\jk2sp.exe () [File not signed]
FirewallRules: [{AB2A2CC1-043A-4E41-8106-4F7B8D4BEA9E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Jedi Outcast\GameData\jk2mp.exe () [File not signed]
FirewallRules: [{6F2A9E9F-A782-4C83-8620-7CC67842A333}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Jedi Outcast\GameData\jk2mp.exe () [File not signed]
FirewallRules: [{6C89F47B-8249-4737-823E-222673041D2A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Jedi Knight Mysteries of the Sith\JediKnightM.EXE () [File not signed]
FirewallRules: [{30AAFB18-8308-4D50-A193-340F8FD5E82C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Jedi Knight Mysteries of the Sith\JediKnightM.EXE () [File not signed]
FirewallRules: [{15D397B5-5BE3-4223-B816-D859E477E8B3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars Jedi Knight\JediKnight.EXE () [File not signed]
FirewallRules: [{E06A3234-1874-4B7E-9887-C1ADC08BFEBD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars Jedi Knight\JediKnight.EXE () [File not signed]
FirewallRules: [{465727E7-E52F-4BAD-B50B-43250FD17096}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\STAR WARS Dark Forces Remaster\khonsu_Shipping_Steam_x64.exe (Nightdive Studios) [File not signed]
FirewallRules: [{AC6E7F7E-5FF0-49B7-9CD1-05390EE1AE1D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\STAR WARS Dark Forces Remaster\khonsu_Shipping_Steam_x64.exe (Nightdive Studios) [File not signed]
FirewallRules: [{994CFC8A-0BD4-465D-A357-FAEEFA05E125}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars Battlefront II Classic\GameData\BattlefrontII.exe () [File not signed]
FirewallRules: [{818B1709-721F-474A-9632-581372A70A31}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars Battlefront II Classic\GameData\BattlefrontII.exe () [File not signed]
FirewallRules: [{39148584-2351-46B9-9319-B3DDEB6E8C6E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Jedi Academy\GameData\jasp.exe (Activision Inc) [File not signed]
FirewallRules: [{6FC1444F-1AE1-4F18-A083-08F4C7195E32}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Jedi Academy\GameData\jasp.exe (Activision Inc) [File not signed]
FirewallRules: [{014D0F6D-4F68-4211-9346-9395E3EABB01}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Jedi Academy\GameData\jamp.exe (Activision Inc) [File not signed]
FirewallRules: [{E289C7D5-B504-47AE-B23C-21787774B89F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Jedi Academy\GameData\jamp.exe (Activision Inc) [File not signed]
FirewallRules: [{AF234ABD-220B-4CB2-8736-18EF89A06B13}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\IdleChampions\IdleDragons.exe () [File not signed]
FirewallRules: [{46BD2F5B-4077-4EE1-9ED7-61BC61D0EADF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\IdleChampions\IdleDragons.exe () [File not signed]
FirewallRules: [{337E24C8-493E-4397-A4E3-24588BBA3017}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Layers of Fear 2\LOF2.exe (BlooberTeam) [File not signed]
FirewallRules: [{3EB958FF-8002-4B9C-A8B3-C8CA1E0A05F8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Layers of Fear 2\LOF2.exe (BlooberTeam) [File not signed]
FirewallRules: [{B22FE2A0-78C7-4ECC-9DDD-03BA8667C080}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Silent Hill Homecoming\Bin\SilentHill.exe () [File not signed]
FirewallRules: [{C4011097-8BD6-4038-8CD5-2C479A0F6377}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Silent Hill Homecoming\Bin\SilentHill.exe () [File not signed]
FirewallRules: [{F2A5A9E7-AA30-4713-A0AF-5BF4AEA6D001}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Slender - The Arrival\SlenderTheArrival.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{12877E78-8682-4FB7-9A35-3C75DF5EE19E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Slender - The Arrival\SlenderTheArrival.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{354C1B02-FCCB-4F85-BB91-E0B6C6161F1C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SongOfHorror\SongOfHorror.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{C4E22161-BE28-4F7F-BA86-8A353660CAC0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SongOfHorror\SongOfHorror.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{638059B1-E0FD-432C-AC4E-ACCA6E1F0A04}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\skse_steam_boot.exe () [File not signed]
FirewallRules: [{173D4276-C25F-46AD-8A56-C4E8A135A725}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\skse_steam_boot.exe () [File not signed]
FirewallRules: [{4CF3C582-3390-420A-99B8-65FE99A42362}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars Empire at War\runme.exe (Disney Interactive Studios Inc -> )
FirewallRules: [{30C6DBBD-BA7D-494F-9155-7055E6756565}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars Empire at War\runme.exe (Disney Interactive Studios Inc -> )
FirewallRules: [{80113412-CEB7-410F-8D19-AB91C6E09897}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars Empire at War\runme2.exe (Disney Interactive Studios Inc -> )
FirewallRules: [{F0E41B69-3B4E-49FE-BE87-5324BF2DC7A0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Star Wars Empire at War\runme2.exe (Disney Interactive Studios Inc -> )
FirewallRules: [{5FD5196D-ED14-4936-B1F4-E7F46865562A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Picture in The House\ThePictureintheHouse.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{C1AA3CC6-FAC2-47D6-AF05-44008D72382D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Picture in The House\ThePictureintheHouse.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{BA97B50F-E3BE-4A3D-A4D0-9B0C3E949273}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Second Sight\secondsight.exe (Free Radical Design) [File not signed]
FirewallRules: [{41F387D8-8B50-4386-A364-E8987877CA87}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Second Sight\secondsight.exe (Free Radical Design) [File not signed]
FirewallRules: [{A28CFEE9-6699-46F2-A65F-8E57AAC5E174}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cry of Fear\CoFLaunchApp.exe (Team Psykskallar) [File not signed]
FirewallRules: [{B672AEEA-06B1-4686-9906-1C9B3670DE95}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cry of Fear\CoFLaunchApp.exe (Team Psykskallar) [File not signed]
FirewallRules: [{A62FBE00-B3C7-4AAD-BE07-3DC3358B1170}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cold Fear\coldfear_retail.exe (Ubisoft) [File not signed]
FirewallRules: [{0285BE00-1CFB-4A23-9D1D-0E5DE51ACE54}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cold Fear\coldfear_retail.exe (Ubisoft) [File not signed]
FirewallRules: [{AACDE89B-20F0-40CD-9D03-A401A550C4E1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Alien Isolation\AI.exe () [File not signed]
FirewallRules: [{6E98958A-CDCE-4F30-8E12-F274CDC85DEB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Alien Isolation\AI.exe () [File not signed]
FirewallRules: [{D061CF15-5BE4-4D0C-BBA9-E60C3ADA0BC7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FTL Faster Than Light\FTLGame.exe () [File not signed]
FirewallRules: [{55EDF160-19D4-43DC-A634-08DCFFAD7249}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FTL Faster Than Light\FTLGame.exe () [File not signed]
FirewallRules: [{00C5D459-E03C-4D1A-84D4-B7ABBD260437}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life\hl.exe (Valve Corp. -> Valve)
FirewallRules: [{7AAFB547-B277-43E5-B7E7-2109241C42E5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life\hl.exe (Valve Corp. -> Valve)
FirewallRules: [{1B5DC90D-26C2-4E04-81D5-C60E59BC467F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SILENT HILL 2\SHProto.exe (Konami) [File not signed]
FirewallRules: [{DE85C626-1510-4A43-B03D-792F359AE0BE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SILENT HILL 2\SHProto.exe (Konami) [File not signed]
FirewallRules: [{C296FC88-830C-4156-B3B0-7B22FC6C07AB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fears to Fathom - Ironbark Lookout\Fears to Fathom - Ironbark Lookout.exe () [File not signed]
FirewallRules: [{A73DBD60-546C-4919-ABA9-8AA5F35836F3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fears to Fathom - Ironbark Lookout\Fears to Fathom - Ironbark Lookout.exe () [File not signed]
FirewallRules: [{27125A3D-60F9-4E4B-9427-37E865E77D2E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life 2\hl2.exe (Valve Corp. -> )
FirewallRules: [{46D18335-317A-4314-8605-DB9F1C235EB1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life 2\hl2.exe (Valve Corp. -> )
FirewallRules: [{D25E4B95-6898-46EC-9505-1DCBA94C8070}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Lazaret\ShipHorror.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{ADBD1C74-65CA-4828-8E4F-9C284556D1B5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Lazaret\ShipHorror.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{8C0B0DDA-3D9B-43EE-87E7-145A206DBF04}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RealRTCW\launcher.x64.exe () [File not signed]
FirewallRules: [{B774303D-2E3F-46E9-A929-B8166515E1C6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RealRTCW\launcher.x64.exe () [File not signed]
FirewallRules: [{2F174B26-BE40-4DFA-BFE6-4F4C04B71EC5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RealRTCW\coop\RTCWCoop.x64.exe () [File not signed]
FirewallRules: [{33F86BB8-CBF9-45E0-8A21-CC21A13B4546}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RealRTCW\coop\RTCWCoop.x64.exe () [File not signed]
FirewallRules: [{7BF489EB-7327-4B2F-8973-5AFE62CA5328}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RealRTCW\mp\ioWolfMP.x86.exe () [File not signed]
FirewallRules: [{B9AD03F7-0157-47DC-83FC-7F55E95BFB52}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RealRTCW\mp\ioWolfMP.x86.exe () [File not signed]
FirewallRules: [{74CE93B3-B3E8-46F4-BB0D-A6B9B2BFE767}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Red Faction\RedFaction.exe (Volition, Inc.) [File not signed]
FirewallRules: [{5D2F1297-42AC-4189-A2FF-A84232D46151}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Red Faction\RedFaction.exe (Volition, Inc.) [File not signed]
FirewallRules: [{3EC78E60-F27B-423B-A32F-14BA8826F538}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Return to Castle Wolfenstein\WolfSP.exe () [File not signed]
FirewallRules: [{00F3E41E-2756-458B-884C-4F5BEAAF2B35}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Return to Castle Wolfenstein\WolfSP.exe () [File not signed]
FirewallRules: [{53974E8A-E816-4DF2-976C-F5CD7A84E901}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Return to Castle Wolfenstein\WolfMP.exe () [File not signed]
FirewallRules: [{70DA3454-78CE-4D16-AC0B-56746DB961AA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Return to Castle Wolfenstein\WolfMP.exe () [File not signed]
FirewallRules: [{304BDD43-AAAE-478D-BF18-D6021D722A6F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Project Crypt\Project_Crypt_GZ\project_crypt.exe () [File not signed]
FirewallRules: [{88E9D48A-78D3-4DB3-80FD-1F3EF7C760C7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Project Crypt\Project_Crypt_GZ\project_crypt.exe () [File not signed]
FirewallRules: [{FAC8808E-401A-4442-A93E-802300B43A6C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Beyond the Mountains\Beyond the Mountains.exe (SoftWeir Inc. -> SoftWeir Inc.)
FirewallRules: [{CA50CB8B-B941-4B56-998E-94057255CBAC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Beyond the Mountains\Beyond the Mountains.exe (SoftWeir Inc. -> SoftWeir Inc.)
FirewallRules: [{0D300594-E4FC-44E1-B7EE-286A7C33E219}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Beyond the Mountains\Redist001.exe (SoftWeir Inc. -> )
FirewallRules: [{97F5BFF2-C1DB-4038-9A40-C0633A493D94}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Beyond the Mountains\Redist001.exe (SoftWeir Inc. -> )
FirewallRules: [{04714C76-37BE-45BD-9F86-FDFE54FDA259}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mars War Logs\MarsWarLogs.exe (Focus Home Interactive -> Spiders)
FirewallRules: [{A121F487-35A4-4F06-8728-FC22DCAAA9BD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mars War Logs\MarsWarLogs.exe (Focus Home Interactive -> Spiders)
FirewallRules: [{782B63B4-C37D-41A6-8E81-E01842E20640}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Technomancer\TheTechnomancer.exe (Focus Home Interactive -> Spiders)
FirewallRules: [{24D3F57D-07C1-435C-B503-9CD88D375EC1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Technomancer\TheTechnomancer.exe (Focus Home Interactive -> Spiders)
FirewallRules: [{A4B2D42F-2F05-496D-943A-24DAFA3E5ED7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stranded Deep\Stranded_Deep_x64.exe () [File not signed]
FirewallRules: [{2DCA1FD7-98A0-4428-BF16-499FB8F6C294}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stranded Deep\Stranded_Deep_x64.exe () [File not signed]
FirewallRules: [{CE33AD11-9CD7-4B6C-AA08-49B097207446}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{EBD627B2-003D-47D9-8166-1873B8F7EEE0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{2F8F6C2A-BA71-4807-BE05-B41258E1716F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{5D4B63F8-7630-49AA-96C1-0565F1A0D3AD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{2EB3EE2D-F6F7-4BB9-A048-C9B2E0D8D86A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{27A449F3-C0AA-43C9-B421-B225EB746C84}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{E61478BB-10C5-42B7-B74D-2EDD24478278}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{FC1F3070-9767-4B4C-9AA6-A348B204C10F}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{43894597-D6E2-4F6B-84D1-57FDAF1E5589}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Vampire Survivors\VampireSurvivors.exe () [File not signed]
FirewallRules: [{D2359BD1-1B07-4B80-A340-D68C32309EB8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Vampire Survivors\VampireSurvivors.exe () [File not signed]
FirewallRules: [{0684AEC9-1D0D-4016-B434-55B47DDEAD97}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\130.0.2849.80\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Restore Points =========================

05-11-2024 13:22:12 Windows Update
12-11-2024 07:19:56 Windows Update

==================== Faulty Device Manager Devices ============
Name: Microsoft Hyper-V Virtual Machine Bus Provider
Description: Microsoft Hyper-V Virtual Machine Bus Provider
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vmbusr
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Realtek® Audio
Description: Realtek Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: IntcAzAudAddService
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Microsoft Hyper-V Virtualization Infrastructure Driver
Description: Microsoft Hyper-V Virtualization Infrastructure Driver
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: Vid
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Microsoft Hyper-V PCI Server
Description: Microsoft Hyper-V PCI Server
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vpcivsp
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Microsoft Hyper-V Virtual Disk Server
Description: Microsoft Hyper-V Virtual Disk Server
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: storvsp
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
Description: NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: NVIDIA
Service: nvvad_WaveExtensible
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Intel® Display Audio
Description: Intel® Display Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel® Corporation
Service: IntcDAud
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver


==================== Event log errors: ========================

Application errors:
==================
Error: (11/12/2024 10:18:21 AM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-32DBH15)
Description: Faulting application name: mmc.exe, version: 10.0.22621.4317, time stamp: 0x7393a548
Faulting module name: KERNELBASE.dll, version: 10.0.22621.4391, time stamp: 0x7433a115
Exception code: 0xe0434352
Fault offset: 0x000000000005fa4c
Faulting process id: 0x0x1044
Faulting application start time: 0x0x1db352f3b44349f
Faulting application path: C:\Windows\system32\mmc.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: 890b6c65-a0ff-4fc0-84b8-ca6f52ad492e
Faulting package full name:
Faulting package-relative application ID:

Error: (11/12/2024 10:18:21 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: mmc.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.OutOfMemoryException
at System.Drawing.Graphics.FromHwndInternal(IntPtr)
at System.Windows.Forms.SplitContainer.RepaintSplitterRect()
at System.Windows.Forms.SplitContainer.ResizeSplitContainer()
at System.Windows.Forms.SplitContainer.OnLayout(System.Windows.Forms.LayoutEventArgs)
at System.Windows.Forms.Control.PerformLayout(System.Windows.Forms.LayoutEventArgs)
at System.Windows.Forms.Control.OnResize(System.EventArgs)
at System.Windows.Forms.Control.OnSizeChanged(System.EventArgs)
at System.Windows.Forms.Control.UpdateBounds(Int32, Int32, Int32, Int32, Int32, Int32)
at System.Windows.Forms.Control.UpdateBounds()
at System.Windows.Forms.Control.WmWindowPosChanged(System.Windows.Forms.Message ByRef)
at System.Windows.Forms.Control.WndProc(System.Windows.Forms.Message ByRef)
at System.Windows.Forms.SplitContainer.WndProc(System.Windows.Forms.Message ByRef)
at System.Windows.Forms.NativeWindow.Callback(IntPtr, Int32, IntPtr, IntPtr)

Exception Info: System.Reflection.TargetInvocationException
at Microsoft.ManagementConsole.Internal.SnapInMessagePumpProxy.OnThreadException(System.Object, System.Threading.ThreadExceptionEventArgs)
at System.Windows.Forms.Application+ThreadContext.OnThreadException(System.Exception)
at System.Windows.Forms.Control.WndProcException(System.Exception)
at System.Windows.Forms.NativeWindow.Callback(IntPtr, Int32, IntPtr, IntPtr)

Error: (11/11/2024 02:49:32 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-32DBH15)
Description: Faulting application name: XboxPcTray.exe, version: 2411.1001.5.0, time stamp: 0x67243942
Faulting module name: ntdll.dll, version: 10.0.22621.4391, time stamp: 0x7b2ab261
Exception code: 0xc000000d
Fault offset: 0x00000000001266c0
Faulting process id: 0x0x615c
Faulting application start time: 0x0x1db347e6e33db58
Faulting application path: C:\Program Files\WindowsApps\Microsoft.GamingApp_2411.1001.5.0_x64__8wekyb3d8bbwe\XboxPcTray.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: a32d65ad-9cd0-4b4a-a869-e4815940435e
Faulting package full name: Microsoft.GamingApp_2411.1001.5.0_x64__8wekyb3d8bbwe
Faulting package-relative application ID: Microsoft.Xbox.App

Error: (11/11/2024 10:08:13 AM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-32DBH15)
Description: Faulting application name: ESETOnlineScanner.exe, version: 10.23.31.0, time stamp: 0x61e82da2
Faulting module name: WININET.dll, version: 11.0.22621.4391, time stamp: 0x5fbcc101
Exception code: 0xc0000005
Fault offset: 0x002a0a14
Faulting process id: 0x0x64d0
Faulting application start time: 0x0x1db3464a8ba92dd
Faulting application path: C:\Users\lechn\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe
Faulting module path: C:\Windows\SYSTEM32\WININET.dll
Report Id: b9a25049-ebc7-4d8a-a035-21b7b9ae8d1a
Faulting package full name:
Faulting package-relative application ID:

Error: (11/11/2024 09:37:56 AM) (Source: Application Hang) (EventID: 1002) (User: NT AUTHORITY)
Description: The program SystemSettings.exe version 10.0.22621.4391 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Error: (11/10/2024 11:09:01 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-32DBH15)
Description: Faulting application name: The Chess Lv.100.exe, version: 0.0.0.0, time stamp: 0x62fb2358
Faulting module name: edgehtml.dll, version: 11.0.22621.4391, time stamp: 0x917309c0
Exception code: 0xc00001ad
Fault offset: 0x00000000006030d4
Faulting process id: 0x0x5970
Faulting application start time: 0x0x1db33f4e247d980
Faulting application path: C:\Program Files\WindowsApps\6918E89D.THECHESSLV.100_2.9.0.0_x64__66n08swfvvka0\The Chess Lv.100.exe
Faulting module path: C:\Windows\SYSTEM32\edgehtml.dll
Report Id: 133bbf52-7d84-4c38-9833-b1d3701aa49b
Faulting package full name: 6918E89D.THECHESSLV.100_2.9.0.0_x64__66n08swfvvka0
Faulting package-relative application ID: App

Error: (11/10/2024 08:22:37 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-32DBH15)
Description: Faulting application name: The Chess Lv.100.exe, version: 0.0.0.0, time stamp: 0x62fb2358
Faulting module name: edgehtml.dll, version: 11.0.22621.4391, time stamp: 0x917309c0
Exception code: 0xc00001ad
Fault offset: 0x00000000006030d4
Faulting process id: 0x0x64fc
Faulting application start time: 0x0x1db33ea22262d86
Faulting application path: C:\Program Files\WindowsApps\6918E89D.THECHESSLV.100_2.9.0.0_x64__66n08swfvvka0\The Chess Lv.100.exe
Faulting module path: C:\Windows\SYSTEM32\edgehtml.dll
Report Id: d0bca0ab-52ca-4229-ab87-1a15b360c47d
Faulting package full name: 6918E89D.THECHESSLV.100_2.9.0.0_x64__66n08swfvvka0
Faulting package-relative application ID: App

Error: (11/08/2024 04:51:57 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-32DBH15)
Description: Faulting application name: firefox.exe, version: 128.4.0.65534, time stamp: 0x00000000
Faulting module name: xul.dll, version: 128.4.0.65534, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0000000000518cda
Faulting process id: 0x0x73dc
Faulting application start time: 0x0x1db324083c8d064
Faulting application path: C:\Users\lechn\OneDrive\Desktop\Tor Browser\Browser\firefox.exe
Faulting module path: C:\Users\lechn\OneDrive\Desktop\Tor Browser\Browser\xul.dll
Report Id: 5a110a5a-ca8c-4c51-8829-e5f80365b982
Faulting package full name:
Faulting package-relative application ID:


System errors:
=============
Error: (11/12/2024 06:36:09 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "1084" attempting to start the service EventSystem with arguments "Unavailable" in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Error: (11/12/2024 06:35:57 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "1084" attempting to start the service netprofm with arguments "Unavailable" in order to run the server:
{A47979D2-C419-11D9-A5B4-001185AD2B89}

Error: (11/12/2024 06:35:38 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-32DBH15)
Description: DCOM got error "1084" attempting to start the service BITS with arguments "Unavailable" in order to run the server:
{4991D34B-80A1-4291-83B6-3328366B9097}

Error: (11/12/2024 06:35:38 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-32DBH15)
Description: DCOM got error "1084" attempting to start the service BITS with arguments "Unavailable" in order to run the server:
{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}

Error: (11/12/2024 06:35:38 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-32DBH15)
Description: DCOM got error "1084" attempting to start the service BITS with arguments "Unavailable" in order to run the server:
{6D18AD12-BDE3-4393-B311-099C346E6DF9}

Error: (11/12/2024 06:35:38 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-32DBH15)
Description: DCOM got error "1084" attempting to start the service BITS with arguments "Unavailable" in order to run the server:
{03CA98D6-FF5D-49B8-ABC6-03DD84127020}

Error: (11/12/2024 06:35:38 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-32DBH15)
Description: DCOM got error "1084" attempting to start the service BITS with arguments "Unavailable" in order to run the server:
{659CDEA7-489E-11D9-A9CD-000D56965251}

Error: (11/12/2024 06:35:38 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-32DBH15)
Description: DCOM got error "1084" attempting to start the service BITS with arguments "Unavailable" in order to run the server:
{BB6DF56B-CACE-11DC-9992-0019B93A3A84}


Windows Defender:
================
Date: 2024-11-11 14:11:08
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2024-11-11 13:30:42
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2024-11-10 22:22:55
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2024-11-09 13:31:02
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2024-11-07 11:51:46
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Event[0]

Date: 2024-11-12 18:32:59
Description:
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

Date: 2024-11-12 10:17:46
Description:
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

Date: 2024-11-12 08:16:26
Description:
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

Date: 2024-11-12 07:42:06
Description:
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

Date: 2024-11-12 07:32:12
Description:
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

CodeIntegrity:
===============
Date: 2024-11-12 07:28:03
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Windows signing level requirements.

Date: 2024-11-12 07:21:16
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\bdamsi\dlls_267059357120000000\antimalware_provider64.dll that did not meet the Windows signing level requirements.

Date: 2024-11-12 07:21:16
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements.


==================== Memory info ===========================

BIOS: Dell Inc. 1.27.0 09/13/2023
Motherboard: Dell Inc. 0KW84T
Processor: Intel® Core™ i7-9750H CPU @ 2.60GHz
Percentage of memory in use: 8%
Total physical RAM: 32550.16 MB
Available physical RAM: 29695.19 MB
Total Virtual: 34598.16 MB
Available Virtual: 32130.62 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:3724.11 GB) (Free:921.06 GB) (Model: CT4000P3SSD8) NTFS
Drive d: (DATA) (Fixed) (Total:931.51 GB) (Free:9.46 GB) (Model: WDC WD10SPZX-75Z10T3) NTFS
Drive f: (ESD-USB) (Removable) (Total:28.89 GB) (Free:12.73 GB) FAT32

\\?\Volume{a960f1ca-bd39-4b5f-b0fc-edaea4fc36f2}\ () (Fixed) (Total:0.73 GB) (Free:0.1 GB) NTFS
\\?\Volume{e9dbf30b-8111-4257-3696-338296f0e77b}\ (DELLSUPPORT) (Fixed) (Total:1.06 GB) (Free:0.05 GB) NTFS
\\?\Volume{749af437-2e9e-43b1-80aa-79129cfc5481}\ () (Fixed) (Total:0.09 GB) (Free:0.04 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 8D22C964)

Partition: GPT.

==========================================================
Disk: 1 (Size: 3726 GB) (Disk ID: 6639429F)

Partition: GPT.

==========================================================
Disk: 2 (MBR Code: Windows 7/8/10) (Size: 28.9 GB) (Disk ID: 5C25A63E)
Partition 1: (Active) - (Size=28.9 GB) - (Type=FAT32)

==================== End of Addition.txt =======================
 
After running that is when the BSOD Netio.sys error occurred but tbh Corrupted m highly confused why a generic cleaning script would cause a BSOD.
 
In any even Safe Mode and Linux OSes work just fine so I'm a tad confused. Did resetting the Winsock break my Network adapter?
 
Is there any way to import the corrupted Netio.sys file to repair it to boot in Normal Mode, what should I do about the chkdsk? Should I reformat? or is it salvageable? Thank you very much for the help.

Edited by Oh My!, Yesterday, 09:25 AM.


#6 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 59,072 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:15 AM

Posted Yesterday, 09:46 AM

Greetings.

On a whim

This is never a good practice. Tinkering with your system and locking things down can have unintended consequences. Some of the programs you applied I have never heard of.

Please do this and let me know if you are able to boot into Normal Boot.

===================================================

Clean Boot

--------------------
  • Boot into Safe Mode
  • Press the Windows Key + R at the same time.
  • Type msconfig and press Enter
  • If you are prompted for an administrator password or for a confirmation, type the password, or provide confirmation
  • Click on the Startup tab
  • Click Open Task Manager
  • Note down each entry listed as Enabled then right click on the item and select Disable (you will need this list during subsequent steps)
  • Close the Task Manager windows and you should be back at the System Configuration window
  • Click the Services tab
  • Click to select the Hide All Microsoft Services check box
  • Click Disable All, and then click OK
  • Click Apply, then OK
  • When you are prompted, click Restart and boot into Normal Mode
  • Check your computer performance
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Results?

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#7 PatL

PatL
  • Topic Starter

  •  Avatar image
  • Members
  • 377 posts
  • OFFLINE
  •  
  • Local time:05:15 AM

Posted Yesterday, 11:31 AM

Hey Gary,

I tried the steps you lined out and there was no change, it still BSOD during boot into Normal Mode

#8 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 59,072 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:15 AM

Posted Yesterday, 01:59 PM

Thank you for trying.

Please do this.

===================================================

Reversing Clean Boot and Running FRST Fixlist in Safe Mode

--------------------
  • Boot into Safe Mode
  • Press the Windows Key + R at the same time.
  • Type msconfig and press Enter
  • If you are prompted for an administrator password or for a confirmation, type the password, or provide confirmation
  • Click the Services tab
  • Click to select the Hide All Microsoft Services check box
  • Click Enable All, and then click Apply
  • Click on the Startup tab
  • Click Open Task Manager
  • Using the list you previously created, for each entry now listed as Disable right click on the entry and select Enable
  • Close the Task Manager window
  • Click Start, type devmgmt.msc then hit Enter
  • Expand the Network Adapter section by clicking + sign
  • Right click on on the listed Network Adapter, select Uninstall, then OK - Do not select the option to Delete the driver software for this device
  • Close the Device Manager window
  • Click Start, type Notepad, then hit Enter
  • Copy and paste the below into the open Notepad document
cmd:sfc /scannow
Reboot:
  • Save the document as Fixlist.txt and save it in the same location as FRST64 (Desktop, Downloads folder, etc.) <<< Important
  • Right click on FRST and select Run as administrator
  • Click Fix and once completed allow your computer to attempt to boot into Normal Boot
  • The tool will create a log in the same location as FRST64 called Fixlog.txt
  • Copy and paste the contents of the report in your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Fixlog
  • Normal Boot work?

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#9 PatL

PatL
  • Topic Starter

  •  Avatar image
  • Members
  • 377 posts
  • OFFLINE
  •  
  • Local time:05:15 AM

Posted Yesterday, 02:43 PM

I did as you requested. Notepad wouldn't open so I just opened cmd prompt and ran sfc after Uninstalling the drivers. No success

#10 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 59,072 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:15 AM

Posted Yesterday, 03:06 PM

What were the results of the sfc scan?
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#11 PatL

PatL
  • Topic Starter

  •  Avatar image
  • Members
  • 377 posts
  • OFFLINE
  •  
  • Local time:05:15 AM

Posted Yesterday, 03:29 PM

The results were no integrity violations found

#12 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 59,072 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:15 AM

Posted Yesterday, 03:38 PM

Check the C:\Windows\Minidump folder. If there are minidump files zip the folder and attach it to your reply.


Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#13 PatL

PatL
  • Topic Starter

  •  Avatar image
  • Members
  • 377 posts
  • OFFLINE
  •  
  • Local time:05:15 AM

Posted Yesterday, 04:05 PM

There are no files in the folder.

#14 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 59,072 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:15 AM

Posted Yesterday, 09:59 PM

Download the SysnativeBSODCollectionApp v5.0.3 (Windows 10 and Windows 11) onto a USB device. Unzip the folder then copy and paste the folder onto the Desktop of the compromised computer while in Safe Mode. Right click on SysnativeFileCollectionApp.exe file and select Run as administrator. When completed a SysnativeFileCollectionApp.zip file will be created. Upload the file here.
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users