Specious Task Taking up system resources in task manager

Page 1 of 2 12 LastLast

  1. Posts : 8
    Windows 10 Pro
       #1

    Specious Task Taking up system resources in task manager


    In windows 10 Pro im trying to delete a file called dsovlwx.exe . I found of where the folder is located and i cant delete and its taking up to much system resources for no reason as i keep multitasking the ram usage of that process keeps increasing i think this could be some type of virus. When i open task manager its named Windowsprocess manager.I tried using file assassin to delete but i cant delete it what so ever.Specious Task Taking up system resources in task manager-specious-problem-my-ram.pngSpecious Task Taking up system resources in task manager-specious-task.pngSpecious Task Taking up system resources in task manager-cant-delete-file.png
    Attached Thumbnails Attached Thumbnails Specious Task Taking up system resources in task manager-dsovlwx.png  
      My Computer


  2. Posts : 5,299
    Windows 11 Pro 64-bit
       #2

    Scan with Farbar Recovery Scan Tool

    Please download Farbar Recovery Scan Tool x86 or Farbar Recovery Scan Tool x64 and save it to your Desktop.


    • Right-click on FRST icon and select Run as Administrator to start the tool.
    • When the tool opens click Yes to disclaimer.
    • Make sure that Addition option is checked.
    • Press Scan button and wait.
    • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.


    Please copy and paste their content into your next reply.
      My Computer


  3. Posts : 8
    Windows 10 Pro
    Thread Starter
       #3

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-11-2017 03
    Ran by Ryan Evan Ramos (administrator) on LITTLE-TAILS (14-11-2017 18:38:30)
    Running from C:\Users\Ryan Evan Ramos\Desktop
    Loaded Profiles: Ryan Evan Ramos (Available Profiles: Ryan Evan Ramos)
    Platform: Windows 10 Pro Version 1709 16299.15 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

    Code:
    ==================== Processes (Whitelisted) =================
    
    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
    
    (TOSHIBA CORPORATION) C:\Windows\System32\nisurwksvc.exe
    (Big Muscle) C:\AeroGlass\aerohost.exe
    (AMD) C:\Windows\System32\DriverStore\FileRepository\c0319547.inf_amd64_f15ceeed0afa1be7\atiesrxx.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Micro-Star Int'l Co., Ltd.) C:\Program Files\Gaming APP\GamingApp_Service.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\LightingService\1.00.01\LightingService.exe
    (RemoteMyApp sp. z o.o.) C:\Program Files (x86)\Remotr\RemotrService.exe
    (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    (DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
    (Micro-Star INT'L CO., LTD.) C:\Program Files\Gaming APP\GamingHotkey_Service.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
    (Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
    (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    (Micro-Star INT'L CO., LTD.) C:\Program Files\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe
    (Micro-Star INT'L CO., LTD.) C:\Program Files\Gaming APP\GamingHotkey.exe
    () C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
    () C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
    (Micro-Star INT'L CO., LTD.) C:\Program Files\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe
    (MSI) C:\Windows\SysWOW64\muachost.exe
    (AVAST Software) C:\Program Files (x86)\Avast Driver Updater\Avast Driver Updater.exe
    (Micro-Star Int'l Co., Ltd.) C:\Program Files\Gaming APP\MSI_LED.exe
    (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\VideoCardMonitorII.exe
    (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\EyeRest.exe
    (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\TriggerModeMonitor.exe
    () C:\Users\Ryan Evan Ramos\AppData\Local\wmrcaxe\wmrcaxe.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
    (RemoteMyApp sp. z o.o.) C:\Program Files (x86)\Remotr\RemotrServer.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
    (Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
    (Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
    (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
    (MSI) C:\Windows\SysWOW64\muachost.exe
    () C:\Program Files (x86)\NZXT\CAM\CAM_V3.exe
    (PUSH Entertainment) C:\Program Files\PUSH Entertainment\Watery Desktop 3D\pushwallpaper.exe
    () C:\Program Files\PUSH Entertainment\Watery Desktop 3D\pushhelper.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    () C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
    () C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe
    (AVAST Software) C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe
    (AVAST Software) C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
    (hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
    (Discord Inc.) C:\Users\Ryan Evan Ramos\AppData\Local\DiscordCanary\app-0.0.177\DiscordCanary.exe
    (Discord Inc.) C:\Users\Ryan Evan Ramos\AppData\Local\DiscordCanary\app-0.0.177\DiscordCanary.exe
    (Discord Inc.) C:\Users\Ryan Evan Ramos\AppData\Local\DiscordCanary\app-0.0.177\DiscordCanary.exe
    () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.487.0_x64__kzf8qxf38zg5c\SkypeHost.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    (Microsoft Corporation) C:\Windows\System32\SnippingTool.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    () C:\Users\Ryan Evan Ramos\AppData\Local\wmrcaxe\dsovlwx.exe
    () C:\Users\Ryan Evan Ramos\AppData\Local\wmrcaxe\dsovlwx.exe
    
    ==================== Registry (Whitelisted) ===========================
    
    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
    
    HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
    HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508240 2015-08-05] (Adobe Systems Incorporated)
    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9235944 2017-08-23] (Realtek Semiconductor)
    HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [253344 2017-11-13] (AVAST Software)
    HKLM-x32\...\Run: [Ext2 Volume Manager] => C:\Program Files\Ext2Fsd\Ext2Mgr.exe [1217176 2014-08-25] (Ext2Fsd Group (Ext2Fsd Project  ))
    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
    HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [408888 2015-06-07] (Power Software Ltd)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
    HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3102496 2017-10-30] (Valve Corporation)
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\Run: [PeerBlock] => C:\Program Files\PeerBlock\peerblock.exe [2513992 2014-01-14] (PeerBlock, LLC)
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\Run: [Tonido] => C:\Users\Ryan Evan Ramos\AppData\Roaming\Tonido\launcher.exe [165376 2014-11-09] (CodeLathe LLC)
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\Run: [Google Update] => C:\Users\Ryan Evan Ramos\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [601680 2017-11-13] (Google Inc.)
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\Run: [join.me.launcher] => C:\Users\Ryan Evan Ramos\AppData\Local\join.me.launcher\join.me.launcher.exe [176560 2015-10-27] (LogMeIn, Inc)
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\Run: [AirDroid 3] => C:\Program Files (x86)\AirDroid\AirDroid.exe [11456120 2017-10-25] (Sand Studio)
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\Run: [Clownfish] => C:\Program Files (x86)\Clownfish\Clownfish.exe [1359624 2015-11-02] (Bogdan Sharkov)
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\Run: [CloudDrive] => C:\Users\Ryan Evan Ramos\AppData\Roaming\TonidoDrive\TonidoDrive.exe [3618888 2014-11-09] (CodeLathe LLC)
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\Run: [XDM] => "C:\Users\Ryan Evan Ramos\AppData\Local\XDM\xdm.exe" -m
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\Run: [4233357] => "C:\Users\Ryan Evan Ramos\AppData\Roaming\ghlk2bdfxj4\r5lbl1aw5zw.exe" /VERYSILENT
    SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\WINDOWS\system32\CbFsMntNtf3.dll (EldoS Corporation)
    SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\WINDOWS\SysWow64\CbFsMntNtf3.dll (EldoS Corporation)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast Cleanup Premium.lnk [2017-11-14]
    ShortcutTarget: Avast Cleanup Premium.lnk -> C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe (AVAST Software)
    Startup: C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CAM.lnk [2017-10-09]
    ShortcutTarget: CAM.lnk -> C:\Program Files (x86)\NZXT\CAM\CAMLauncher.exe ()
    Startup: C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IMVU.lnk [2017-11-14]
    ShortcutTarget: IMVU.lnk -> C:\Users\Ryan Evan Ramos\AppData\Roaming\IMVUClient\IMVUQualityAgent.exe ()
    Startup: C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PUSH Wallpaper.lnk [2017-10-07]
    ShortcutTarget: PUSH Wallpaper.lnk -> C:\Program Files\PUSH Entertainment\Watery Desktop 3D\pushlivewallpaper.exe ()
    Startup: C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar80.lnk [2017-11-14]
    ShortcutTarget: Sidebar80.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
    GroupPolicy: Restriction <==== ATTENTION
    
    ==================== Internet (Whitelisted) ====================
    
    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
    
    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.42.129
    Tcpip\..\Interfaces\{18a35890-c9e0-4931-b075-0c0e6b4fb47f}: [DhcpNameServer] 192.168.42.129
    Tcpip\..\Interfaces\{2f932897-9e1d-40ad-b061-89eeeeee3295}: [DhcpNameServer] 192.168.137.1
    Tcpip\..\Interfaces\{b651bd41-79ae-4158-8ed6-4923a2f80ebe}: [DhcpNameServer] 207.69.188.186 207.69.188.187
    Tcpip\..\Interfaces\{c4b14dc9-6f84-4a5c-8841-0f074853cf31}: [DhcpNameServer] 10.0.0.1
    Tcpip\..\Interfaces\{de1cf3b5-7ac9-4b3b-a483-544b444528df}: [DhcpNameServer] 192.168.43.1
    Tcpip\..\Interfaces\{e77276ac-7916-4203-bac9-e2db09d7686c}: [DhcpNameServer] 172.16.11.254
    
    Internet Explorer:
    ==================
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
    SearchScopes: HKU\S-1-5-21-354301492-1375950521-280439656-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
    SearchScopes: HKU\S-1-5-21-354301492-1375950521-280439656-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
    BHO: No Name -> {27DD0F8B-3E0E-4ADC-A78A-66047E71ADC5} -> C:\Users\Ryan Evan Ramos\Documents\programs\OldNewExplorer\OldNewExplorer64.dll [2015-08-09] (StartIsBack: real start menu for Windows 8 and Windows 10)
    BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-11-07] (Microsoft Corporation)
    BHO: Virtual Storage Mount Notification -> {5FF49FE8-B332-4CB9-B102-FB6951629E55} -> C:\WINDOWS\system32\CbFsMntNtf3.dll [2011-09-19] (EldoS Corporation)
    BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-11-07] (Microsoft Corporation)
    BHO-x32: No Name -> {27DD0F8B-3E0E-4ADC-A78A-66047E71ADC5} -> C:\Users\Ryan Evan Ramos\Documents\programs\OldNewExplorer\OldNewExplorer32.dll [2015-08-09] (StartIsBack: real start menu for Windows 8 and Windows 10)
    BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-10-19] (Microsoft Corporation)
    BHO-x32: Virtual Storage Mount Notification -> {5FF49FE8-B332-4CB9-B102-FB6951629E55} -> C:\WINDOWS\SysWow64\CbFsMntNtf3.dll [2011-09-19] (EldoS Corporation)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-02-07] (Oracle Corporation)
    BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-11-07] (Microsoft Corporation)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-07] (Oracle Corporation)
    Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-11-07] (Microsoft Corporation)
    Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-11-07] (Microsoft Corporation)
    Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-11-07] (Microsoft Corporation)
    Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-11-07] (Microsoft Corporation)
    
    FireFox:
    ========
    FF DefaultProfile: mzg76i63.default-1507654953624
    FF ProfilePath: C:\Users\Ryan Evan Ramos\AppData\Roaming\Mozilla\Firefox\Profiles\mzg76i63.default-1507654953624 [2017-11-14]
    FF user.js: detected! => C:\Users\Ryan Evan Ramos\AppData\Roaming\Mozilla\Firefox\Profiles\mzg76i63.default-1507654953624\user.js [2016-03-23]
    FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\mzg76i63.default-1507654953624 -> Google
    FF Homepage: Mozilla\Firefox\Profiles\mzg76i63.default-1507654953624 -> hxxps://start.duckduckgo.com/
    FF NetworkProxy: Mozilla\Firefox\Profiles\mzg76i63.default-1507654953624 -> autoconfig_url", "data:text/javascript,function FindProxyForURL(url, host) {if ((url.indexOf("proxmate=us") != -1)) { return 'PROXY us03.sq.proxmate.me:8000; PROXY us06.sq.proxmate.me:8000; PROXY us02.sq.proxmate.me:8000; PROXY us13.sq.proxmate.me:8000; PROXY us11.sq.proxmate.me:8000; PROXY us12.sq.proxmate.me:8000; PROXY us07.sq.proxmate.me:8000; PROXY us05.sq.proxmate.me:8000; PROXY us08.sq.proxmate.me:8000; PROXY us14.sq.proxmate.me:8000; PROXY us10.sq.proxmate.me:8000; PROXY us01.sq.proxmate.me:8000; PROXY us09.sq.proxmate.me:8000' } else { return 'DIRECT'; }}"
    FF NetworkProxy: Mozilla\Firefox\Profiles\mzg76i63.default-1507654953624 -> type", 0
    FF Extension: (__MSG_extensionName__) - C:\Users\Ryan Evan Ramos\AppData\Roaming\Mozilla\Firefox\Profiles\mzg76i63.default-1507654953624\Extensions\app-menu@exe-boss.xpi [2017-11-14]
    FF Extension: (Flash Video Downloader) - C:\Users\Ryan Evan Ramos\AppData\Roaming\Mozilla\Firefox\Profiles\mzg76i63.default-1507654953624\Extensions\artur.dubovoy@gmail.com.xpi [2017-11-13]
    FF Extension: (Avast SafePrice) - C:\Users\Ryan Evan Ramos\AppData\Roaming\Mozilla\Firefox\Profiles\mzg76i63.default-1507654953624\Extensions\sp@avast.com.xpi [2017-11-13]
    FF Extension: (uBlock Origin) - C:\Users\Ryan Evan Ramos\AppData\Roaming\Mozilla\Firefox\Profiles\mzg76i63.default-1507654953624\Extensions\uBlock0@raymondhill.net.xpi [2017-11-08]
    FF Extension: (Avast Online Security) - C:\Users\Ryan Evan Ramos\AppData\Roaming\Mozilla\Firefox\Profiles\mzg76i63.default-1507654953624\Extensions\wrc@avast.com.xpi [2017-11-13]
    FF HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\Firefox\Extensions: [xdmff@xdman.sourceforge.net] - C:\Users\Ryan Evan Ramos\AppData\Local\XDM\xdmff => not found
    FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-10-25] ()
    FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-08-06] (Adobe Systems)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-10-25] ()
    FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1223183.dll [2015-12-21] (Adobe Systems, Inc.)
    FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-07] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-07] (Oracle Corporation)
    FF Plugin-x32: @Microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-10-19] (Microsoft Corporation)
    FF Plugin-x32: @Microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-10-19] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-08-10] (Adobe Systems Inc.)
    FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems)
    FF Plugin HKU\S-1-5-21-354301492-1375950521-280439656-1001: @nsroblox.roblox.com/launcher -> C:\Users\Ryan Evan Ramos\AppData\Local\Roblox\Versions\version-b7bf51c941dd400f\\NPRobloxProxy.dll [2012-12-31] ( ROBLOX Corporation)
    FF Plugin HKU\S-1-5-21-354301492-1375950521-280439656-1001: @nsroblox.roblox.com/launcher64 -> C:\Users\Ryan Evan Ramos\AppData\Local\Roblox\Versions\version-b7bf51c941dd400f\\NPRobloxProxy64.dll [2012-12-31] ( ROBLOX Corporation)
    FF Plugin HKU\S-1-5-21-354301492-1375950521-280439656-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Ryan Evan Ramos\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
    FF Plugin HKU\S-1-5-21-354301492-1375950521-280439656-1001: @talk.google.com/O1DPlugin -> C:\Users\Ryan Evan Ramos\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
    FF Plugin HKU\S-1-5-21-354301492-1375950521-280439656-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Ryan Evan Ramos\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
    FF Plugin HKU\S-1-5-21-354301492-1375950521-280439656-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Ryan Evan Ramos\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
    FF Plugin HKU\S-1-5-21-354301492-1375950521-280439656-1001: @Unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Ryan Evan Ramos\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-08] (Unity Technologies ApS)
    FF Plugin ProgramFiles/Appdata: C:\Users\Ryan Evan Ramos\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
    FF Plugin ProgramFiles/Appdata: C:\Users\Ryan Evan Ramos\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
    
    Chrome: 
    =======
    CHR Profile: C:\Users\Ryan Evan Ramos\AppData\Local\Google\Chrome\User Data\Default [2017-11-13]
    CHR Extension: (Slides) - C:\Users\Ryan Evan Ramos\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-11-12]
    CHR Extension: (Docs) - C:\Users\Ryan Evan Ramos\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-12]
    CHR Extension: (Google Drive) - C:\Users\Ryan Evan Ramos\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-04]
    CHR Extension: (YouTube) - C:\Users\Ryan Evan Ramos\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-27]
    CHR Extension: (Google Search) - C:\Users\Ryan Evan Ramos\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-04]
    CHR Extension: (Unlimited Hotspot Tethering) - C:\Users\Ryan Evan Ramos\AppData\Local\Google\Chrome\User Data\Default\Extensions\diddhabdhahhfajjfgepdlanilmdnogk [2015-12-27]
    CHR Extension: (Tails Theme) - C:\Users\Ryan Evan Ramos\AppData\Local\Google\Chrome\User Data\Default\Extensions\dloejodibckopjdcheeeifofgmkdoemm [2017-11-12]
    CHR Extension: (Sheets) - C:\Users\Ryan Evan Ramos\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-11-12]
    CHR Extension: (Google Docs Offline) - C:\Users\Ryan Evan Ramos\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-11-12]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Ryan Evan Ramos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-11-12]
    CHR Extension: (Gmail) - C:\Users\Ryan Evan Ramos\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-26]
    CHR Extension: (Chrome Media Router) - C:\Users\Ryan Evan Ramos\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-12]
    CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
    
    ==================== Services (Whitelisted) ====================
    
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
    
    S4 403452eb8042e065f60c58f400f5c873; C:\Program Files\403452eb8042e065f60c58f400f5c873\35a99b9cbd8ef82bb01aa75eee30d990.exe [943616 2017-11-11] () [File not signed] <==== ATTENTION
    R2 AMD External Events Utility; C:\WINDOWS\System32\DriverStore\FileRepository\c0319547.inf_amd64_f15ceeed0afa1be7\atiesrxx.exe [481808 2017-10-27] (AMD)
    R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7549928 2017-11-13] (AVAST Software)
    R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [281416 2017-11-13] (AVAST Software)
    R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [332368 2017-11-14] (AVAST Software)
    R2 BcmBtRSupport; C:\WINDOWS\system32\BtwRSupportService.exe [2278152 2017-09-16] (Broadcom Corporation.)
    R2 CleanupPSvc; C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe [4709728 2017-11-01] (AVAST Software)
    R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8063656 2017-10-31] (Microsoft Corporation)
    R2 GamingApp_Service; C:\Program Files\Gaming APP\GamingApp_Service.exe [47056 2017-07-13] (Micro-Star Int'l Co., Ltd.)
    R2 GamingHotkey_Service; C:\Program Files\Gaming APP\GamingHotkey_Service.exe [2019792 2016-10-13] (Micro-Star INT'L CO., LTD.)
    R2 LightingService; C:\Program Files (x86)\LightingService\1.00.01\LightingService.exe [723416 2017-05-23] (ASUSTek Computer Inc.)
    R2 MSI_ActiveX_Service; C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe [80824 2017-06-30] (Micro-Star INT'L CO., LTD.)
    R2 Remotr Service; C:\Program Files (x86)\Remotr\RemotrService.exe [207480 2017-02-27] (RemoteMyApp sp. z o.o.)
    S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-02-28] (Riverbed Technology, Inc.)
    S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4297920 2017-09-29] (Microsoft Corporation)
    R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [741640 2014-06-16] (DEVGURU Co., LTD.)
    R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10942704 2017-11-03] (TeamViewer GmbH)
    S4 txcoresrv; C:\Program Files (x86)\WiFi\txcoresrv.exe [168296 2016-03-10] (Tx-Network)
    S3 VsEtwService120; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-04] (Microsoft Corporation)
    S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
    S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)
    S2 CodeMeter.exe; C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [X]
    S2 MSI_SuperCharger; "C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe" [X]
    S3 scan; C:\Program Files\Immunet\tetra\scan.dll [X]
    
    ===================== Drivers (Whitelisted) ======================
    
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
    
    R1 6fdb8e3f7201037c9a9aabdcfe6da34d; C:\WINDOWS\system32\drivers\6fdb8e3f7201037c9a9aabdcfe6da34d.sys [68968 2017-11-11] (OWQ390) <==== ATTENTION
    R3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2013-01-28] (ASUSTek Computer Inc.)
    R3 amdgpio2; C:\WINDOWS\System32\drivers\amdgpio2.sys [43400 2017-03-01] (Advanced Micro Devices, Inc)
    R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [33120 2017-05-12] (Advanced Micro Devices, Inc)
    S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.)
    S3 amdkmcsp; C:\WINDOWS\system32\DRIVERS\amdkmcsp.sys [95080 2017-06-12] (Advanced Micro Devices, Inc. )
    R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0319547.inf_amd64_f15ceeed0afa1be7\atikmdag.sys [40030736 2017-10-27] (Advanced Micro Devices, Inc.)
    R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0319547.inf_amd64_f15ceeed0afa1be7\atikmpag.sys [545296 2017-10-27] (Advanced Micro Devices, Inc.)
    R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [62152 2014-10-27] (Advanced Micro Devices, Inc.)
    R1 amdpsp; C:\WINDOWS\system32\DRIVERS\amdpsp.sys [239976 2017-06-12] (Advanced Micro Devices, Inc. )
    R2 AMDRyzenMasterDriver1.0.0; C:\Program Files\AMD\RyzenMasterSDK\bin\AMDRyzenMasterDriver.sys [70312 2017-03-27] (Advanced Micro Devices)
    S3 AndNetDiag; C:\WINDOWS\system32\DRIVERS\lgandnetdiag64.sys [30720 2015-05-12] (LG Electronics Inc.)
    S3 ANDNetModem; C:\WINDOWS\system32\DRIVERS\lgandnetmodem64.sys [37376 2015-05-12] (LG Electronics Inc.)
    R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
    R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
    R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2013-01-14] ()
    R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [183584 2017-11-13] (AVAST Software)
    R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdrivera.sys [321032 2017-11-13] (AVAST Software s.r.o.)
    R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsha.sys [198968 2017-11-13] (AVAST Software s.r.o.)
    R0 aswblog; C:\WINDOWS\System32\drivers\aswbloga.sys [343288 2017-11-13] (AVAST Software s.r.o.)
    R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniva.sys [57728 2017-11-13] (AVAST Software s.r.o.)
    S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [47008 2017-11-13] (AVAST Software)
    R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [148288 2017-11-13] (AVAST Software)
    R1 aswNetSec; C:\WINDOWS\System32\drivers\aswNetSec.sys [570152 2017-11-14] (AVAST Software)
    R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110376 2017-11-13] (AVAST Software)
    R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [84416 2017-11-13] (AVAST Software)
    R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [1026232 2017-11-13] (AVAST Software)
    R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [455384 2017-11-13] (AVAST Software)
    R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [203976 2017-11-13] (AVAST Software)
    R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [364464 2017-11-13] (AVAST Software)
    R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [110088 2017-04-26] (Advanced Micro Devices)
    R3 bcbtums; C:\WINDOWS\system32\drivers\bcbtums.sys [199472 2017-09-16] (Broadcom Corporation.)
    R3 cbfs3; C:\WINDOWS\System32\drivers\cbfs3.sys [341904 2011-09-19] (EldoS Corporation)
    R3 cpuz143; C:\WINDOWS\temp\cpuz143\cpuz143_x64.sys [48960 2017-11-14] (CPUID)
    R3 DroidCam; C:\WINDOWS\system32\DRIVERS\droidcam.sys [33592 2015-10-26] (Dev47Apps)
    R3 DroidCamVideo; C:\WINDOWS\system32\DRIVERS\droidcamvideo.sys [230712 2015-10-26] (Windows (R) Win 7 DDK provider)
    R2 Ext2Fsd; C:\Windows\system32\Drivers\Ext2Fsd.sys [787576 2015-06-09] (Ext2Fsd Project  )
    R3 I2cHkBurn; C:\WINDOWS\system32\drivers\I2cHkBurn.sys [41760 2015-07-27] (FINTEK Corp.)
    S3 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [24824 2014-10-22] (ASUSTeK Computer Inc.)
    S3 Larmkanal; C:\WINDOWS\system32\DRIVERS\Larmkanal.sys [33144 2015-04-23] (Adoriasoft LLC)
    S3 ManyCam; C:\WINDOWS\system32\DRIVERS\mcvidrv.sys [49272 2014-12-28] (Visicom Media Inc.)
    R1 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [252232 2017-10-10] (Malwarebytes)
    S3 mcaudrv_simple; C:\WINDOWS\system32\drivers\mcaudrv_x64.sys [35960 2014-12-28] (Visicom Media Inc.)
    S3 monectdevices; C:\WINDOWS\System32\drivers\monectdevices.sys [15768 2013-12-03] ()
    S3 Neo_VPN; C:\WINDOWS\System32\drivers\Neo6_x64_VPN.sys [49424 2015-08-19] (SoftEther Corporation)
    R2 NPF; C:\WINDOWS\System32\drivers\npf.sys [36600 2013-02-28] (Riverbed Technology, Inc.)
    R3 NTIOLib_MBAPI; C:\Program Files\Gaming APP\Lib\NTIOLib_X64.sys [14288 2017-07-10] (MSI)
    S3 pbfilter; C:\Program Files\PeerBlock\pbfilter.sys [22600 2014-01-14] ()
    R3 Phosgene; C:\WINDOWS\system32\DRIVERS\Phosgene.sys [34136 2015-09-02] (Adoriasoft LLC)
    S3 ptun0901; C:\WINDOWS\system32\DRIVERS\ptun0901.sys [27136 2015-01-26] (The OpenVPN Project)
    S3 qcusbser; C:\WINDOWS\system32\DRIVERS\qcusbser.sys [254520 2017-03-15] (QUALCOMM Incorporated)
    R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [14024 2017-08-27] ()
    R1 SeLow; C:\WINDOWS\system32\DRIVERS\SeLow_x64.sys [48896 2015-07-16] (SoftEther Corporation)
    R3 SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [259584 2017-09-29] (Microsoft Corporation)
    S3 SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys [25608 2017-11-14] (SlimWare Utilities, Inc.)
    S3 tap-tb-0901; C:\WINDOWS\system32\DRIVERS\tap-tb-0901.sys [38656 2015-04-28] (The OpenVPN Project)
    S3 txwifinatwfp; C:\WINDOWS\System32\Drivers\txwifinatwfp64.sys [31496 2016-03-10] (TongXiang)
    U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
    R3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [23040 2017-09-29] (Microsoft Corporation)
    R1 VBoxNetAdp; C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [117768 2015-11-10] (Oracle Corporation)
    R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [194976 2015-11-10] (Oracle Corporation)
    R1 VBoxUSBMon; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [144656 2017-07-26] (BigNox Corporation)
    S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
    S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
    S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)
    R3 WinRing0_1_2_0; C:\Program Files (x86)\NZXT\CAM\CAM_V3.sys [14544 2017-11-14] (OpenLibSys.org)
    S3 wovad_micarray; C:\WINDOWS\system32\drivers\womic.sys [33072 2015-09-09] (Windows (R) Win 7 DDK provider)
    R1 YSDrv; C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [270608 2017-11-04] (BigNox Corporation)
    R3 udiskMgr; system32\drivers\ycfilp.sys [X]
    
    ==================== NetSvcs (Whitelisted) ===================
    
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
    
    
    ==================== One Month Created files and folders ========
    
    (If an entry is included in the fixlist, the file/folder will be moved.)
    
    2017-11-14 18:38 - 2017-11-14 18:39 - 000033425 _____ C:\Users\Ryan Evan Ramos\Desktop\FRST.txt
    2017-11-14 18:38 - 2017-11-14 18:38 - 000000000 ____D C:\FRST
    2017-11-14 18:37 - 2017-11-14 18:37 - 002392576 _____ (Farbar) C:\Users\Ryan Evan Ramos\Desktop\FRST64.exe
    2017-11-14 17:43 - 2017-11-14 17:44 - 003264606 _____ C:\Users\Ryan Evan Ramos\Downloads\gameguardian-8-2-1.apk
    2017-11-14 17:32 - 2017-11-14 17:32 - 000000000 ____D C:\ProgramData\SWCUTemp
    2017-11-14 17:18 - 2017-11-14 17:18 - 000140624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\psbeilor.sys
    2017-11-14 17:08 - 2017-11-14 17:08 - 000432688 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2017-11-14 16:51 - 2017-11-14 16:51 - 000346112 _____ C:\Users\Ryan Evan Ramos\Downloads\Unlocker x64 1.9.2.msi
    2017-11-14 16:51 - 2017-11-14 16:51 - 000001914 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unlocker.lnk
    2017-11-14 16:51 - 2017-11-14 16:51 - 000000000 ____D C:\Program Files\Unlocker
    2017-11-14 16:47 - 2017-11-14 16:47 - 000001124 _____ C:\Users\Public\Desktop\FileASSASSIN.lnk
    2017-11-14 16:46 - 2017-11-14 16:46 - 000167034 _____ C:\Users\Ryan Evan Ramos\Downloads\fileassassin-setup-1.06.exe
    2017-11-14 16:29 - 2017-11-14 16:59 - 090459905 _____ C:\Users\Ryan Evan Ramos\Downloads\Sonic Forces Speed Battle_v1.0.3_apkpure.com.apk
    2017-11-14 15:23 - 2017-11-14 15:23 - 000286274 _____ C:\Users\Ryan Evan Ramos\Downloads\custom_css_for_fx_v1.2.8.zip
    2017-11-14 15:07 - 2017-11-14 15:07 - 000001216 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
    2017-11-14 15:05 - 2017-11-14 15:05 - 000245816 _____ (Mozilla) C:\Users\Ryan Evan Ramos\Downloads\Firefox Installer.exe
    2017-11-14 13:22 - 2017-11-14 13:22 - 000000000 _____ C:\WINDOWS\SysWOW64\last.dump
    2017-11-14 12:57 - 2017-11-14 12:57 - 000004010 _____ C:\WINDOWS\System32\Tasks\Avast TUNEUP Update
    2017-11-14 12:57 - 2017-11-14 12:57 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Avast Tuneup
    2017-11-14 12:57 - 2017-11-14 12:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
    2017-11-14 12:57 - 2017-11-14 12:57 - 000000000 ____D C:\Program Files (x86)\AVAST Software
    2017-11-14 10:50 - 2017-11-14 17:22 - 000000528 _____ C:\WINDOWS\Tasks\Avast Driver Updater Startup.job
    2017-11-14 10:50 - 2017-11-14 10:50 - 000003046 _____ C:\WINDOWS\System32\Tasks\Avast Driver Updater Startup
    2017-11-14 10:49 - 2017-11-14 17:21 - 000025608 _____ (SlimWare Utilities, Inc.) C:\WINDOWS\system32\Drivers\SWDUMon.sys
    2017-11-14 10:49 - 2017-11-14 10:49 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\AVAST Software
    2017-11-14 10:49 - 2017-11-14 10:49 - 000000000 ____D C:\Users\Public\Documents\Downloaded Installers
    2017-11-14 10:49 - 2017-11-14 10:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Driver Updater
    2017-11-14 10:49 - 2017-11-14 10:49 - 000000000 ____D C:\Program Files (x86)\Avast Driver Updater
    2017-11-14 10:07 - 2017-11-14 10:07 - 000001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Premier.lnk
    2017-11-14 10:06 - 2017-11-14 10:05 - 000570152 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNetSec.sys
    2017-11-14 10:06 - 2017-11-13 19:39 - 000365168 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
    2017-11-14 08:36 - 2017-11-14 17:08 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
    2017-11-14 08:34 - 2017-11-14 17:18 - 000000000 ____D C:\WINDOWS\pss
    2017-11-14 08:22 - 2017-11-14 08:22 - 000000000 ___HD C:\Users\Public\Documents\AdobeGC
    2017-11-13 22:19 - 2017-11-13 22:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileASSASSIN
    2017-11-13 22:19 - 2017-11-13 22:19 - 000000000 ____D C:\Program Files (x86)\FileASSASSIN
    2017-11-13 19:56 - 2017-11-13 19:56 - 000000000 ___RD C:\Program Files (x86)\Skype
    2017-11-13 19:56 - 2017-11-13 19:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    2017-11-13 19:41 - 2017-11-14 10:07 - 000061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
    2017-11-13 19:41 - 2017-11-14 09:49 - 000061304 _____ () C:\WINDOWS\SMSS-PFRO8741.tmp
    2017-11-13 19:41 - 2017-11-14 09:24 - 000061304 _____ () C:\WINDOWS\SMSS-PFRO801c.tmp
    2017-11-13 19:41 - 2017-11-13 19:41 - 000061304 _____ () C:\WINDOWS\SMSS-PFRO8906.tmp
    2017-11-13 19:41 - 2017-11-13 19:41 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\AVAST Software
    2017-11-13 19:40 - 2017-11-14 10:20 - 000004268 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
    2017-11-13 19:40 - 2017-11-13 19:39 - 001026232 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
    2017-11-13 19:40 - 2017-11-13 19:39 - 000455384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
    2017-11-13 19:40 - 2017-11-13 19:39 - 000364464 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
    2017-11-13 19:40 - 2017-11-13 19:39 - 000343288 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys
    2017-11-13 19:40 - 2017-11-13 19:39 - 000321032 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
    2017-11-13 19:40 - 2017-11-13 19:39 - 000203976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
    2017-11-13 19:40 - 2017-11-13 19:39 - 000198968 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys
    2017-11-13 19:40 - 2017-11-13 19:39 - 000183584 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
    2017-11-13 19:40 - 2017-11-13 19:39 - 000148288 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
    2017-11-13 19:40 - 2017-11-13 19:39 - 000110376 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
    2017-11-13 19:40 - 2017-11-13 19:39 - 000084416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
    2017-11-13 19:40 - 2017-11-13 19:39 - 000057728 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys
    2017-11-13 19:40 - 2017-11-13 19:39 - 000047008 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
    2017-11-13 19:25 - 2017-11-13 19:25 - 000000000 ____D C:\Program Files\AVAST Software
    2017-11-13 19:24 - 2017-11-14 12:57 - 000000000 ____D C:\ProgramData\AVAST Software
    2017-11-13 19:24 - 2017-11-13 19:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
    2017-11-13 19:24 - 2017-11-13 19:24 - 000000000 ____D C:\Program Files\VS Revo Group
    2017-11-13 16:41 - 2017-11-13 17:21 - 000000000 ____D C:\Program Files (x86)\AnonymizerGadget
    2017-11-13 16:41 - 2017-11-13 16:41 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\AGData
    2017-11-13 16:34 - 2017-11-14 18:09 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\upsrgvc
    2017-11-13 16:33 - 2017-11-13 16:33 - 000072816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\etxktujq.sys
    2017-11-13 16:33 - 2017-11-13 16:33 - 000000103 _____ C:\WINDOWS\SysWOW64\del.bat
    2017-11-13 16:31 - 2017-11-13 17:08 - 000000000 ___HD C:\Program Files (x86)\~ProxyGate
    2017-11-13 16:30 - 2017-11-14 18:38 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\wmrcaxe
    2017-11-13 16:30 - 2017-11-14 17:19 - 002883072 _____ (TOSHIBA CORPORATION) C:\WINDOWS\system32\nisurwksvc.exe
    2017-11-13 16:30 - 2017-11-13 16:46 - 000000000 ____D C:\Program Files (x86)\s5
    2017-11-13 16:30 - 2017-11-13 16:33 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\rduvbn
    2017-11-13 16:30 - 2017-11-13 16:30 - 000000000 ____D C:\WINDOWS\SysWOW64\pwsnvcd
    2017-11-13 16:30 - 2017-11-13 16:30 - 000000000 ____D C:\WINDOWS\system32\pwsnvcd
    2017-11-13 16:30 - 2017-11-13 16:30 - 000000000 ____D C:\Program Files (x86)\Textify Company
    2017-11-13 16:29 - 2017-11-13 16:44 - 000000000 ____D C:\Program Files (x86)\ShutdownTime
    2017-11-13 16:29 - 2017-11-13 16:29 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\et
    2017-11-13 16:29 - 2017-11-13 16:29 - 000000000 ____D C:\ProgramData\1510608582
    2017-11-13 16:28 - 2017-11-14 16:41 - 000000000 ____D C:\Program Files\ALSF7IJK6Y
    2017-11-13 16:28 - 2017-11-13 17:03 - 000000000 ____D C:\WINDOWS\SysWOW64\SSL
    2017-11-13 16:28 - 2017-11-13 16:28 - 000031449 _____ C:\WINDOWS\f016e3968e92f2517ad9ac946c9a853b.ps1
    2017-11-13 16:28 - 2017-11-13 16:28 - 000003476 _____ C:\WINDOWS\System32\Tasks\f016e3968e92f2517ad9ac946c9a853b
    2017-11-13 16:28 - 2017-11-13 16:28 - 000003302 _____ C:\WINDOWS\System32\Tasks\403452eb8042e065f60c58f400f5c873
    2017-11-13 16:28 - 2017-11-13 16:28 - 000000000 ____D C:\Program Files\403452eb8042e065f60c58f400f5c873
    2017-11-12 21:24 - 2017-11-12 21:32 - 000000000 ____D C:\WINDOWS\System32\Tasks\MEGA
    2017-11-12 21:24 - 2017-11-12 21:24 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\Mega Limited
    2017-11-12 15:34 - 2017-11-12 15:34 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Citra
    2017-11-11 17:30 - 2017-11-11 17:30 - 001052672 _____ C:\WINDOWS\945c4342d4e8146e4c28a02c57def77e.exe
    2017-11-11 17:30 - 2017-11-11 17:30 - 000068968 _____ (OWQ390) C:\WINDOWS\system32\Drivers\6fdb8e3f7201037c9a9aabdcfe6da34d.sys
    2017-11-11 17:30 - 2017-11-11 17:30 - 000046466 _____ C:\WINDOWS\uninstaller.dat
    2017-11-07 15:11 - 2017-11-07 15:11 - 000000000 ____D C:\Users\Ryan Evan Ramos\Documents\4A Games
    2017-11-07 15:09 - 2017-11-07 15:09 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\4A Games
    2017-11-07 09:48 - 2017-11-07 09:48 - 000003170 _____ C:\WINDOWS\System32\Tasks\MSIGH_Host
    2017-11-07 09:48 - 2017-11-07 09:48 - 000003112 _____ C:\WINDOWS\System32\Tasks\MSIOSDx86_Host
    2017-11-07 09:48 - 2017-11-07 09:48 - 000003112 _____ C:\WINDOWS\System32\Tasks\MSIOSDx64_Host
    2017-11-07 09:46 - 2017-11-07 09:46 - 000000877 _____ C:\Users\Public\Desktop\MSI Gaming APP.lnk
    2017-11-07 09:45 - 2017-11-07 09:48 - 000000000 ____D C:\Program Files\Gaming APP
    2017-11-04 21:06 - 2017-11-14 18:07 - 000000000 ____D C:\Users\Ryan Evan Ramos\.BigNox
    2017-11-04 21:06 - 2017-11-04 21:06 - 000000000 ____D C:\Program Files (x86)\Bignox
    2017-11-03 14:33 - 2017-11-03 14:33 - 000000000 ____D C:\Users\Public\Documents\CAM
    2017-11-03 14:32 - 2017-11-03 14:32 - 000001095 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CAM.lnk
    2017-11-03 14:32 - 2017-11-03 14:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CAM
    2017-11-02 19:18 - 2017-11-02 19:18 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\LocalLow\AMD
    2017-11-02 19:03 - 2017-11-02 19:03 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Spore
    2017-11-02 14:47 - 2017-11-08 16:49 - 000001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 13.lnk
    2017-11-02 14:38 - 2017-11-02 14:38 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\LocalLow\Ookla
    2017-11-02 14:38 - 2017-11-02 14:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speedtest By Ookla
    2017-11-02 14:38 - 2017-11-02 14:38 - 000000000 ____D C:\Program Files (x86)\Speedtest
    2017-10-31 09:34 - 2017-10-31 09:34 - 000000000 ____D C:\Users\Ryan Evan Ramos\Documents\SEGA
    2017-10-30 20:36 - 2017-10-30 20:36 - 001193161 _____ C:\WINDOWS\unins000.exe
    2017-10-30 20:36 - 2017-10-30 20:36 - 000002845 _____ C:\WINDOWS\unins000.dat
    2017-10-30 20:36 - 2017-10-30 20:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xiph.Org
    2017-10-30 20:36 - 2017-10-30 20:36 - 000000000 ____D C:\Program Files (x86)\Phosgene
    2017-10-30 20:36 - 2015-09-02 06:28 - 000034136 _____ (Adoriasoft LLC) C:\WINDOWS\system32\Drivers\Phosgene.sys
    2017-10-30 20:35 - 2017-10-30 20:35 - 000000000 ____D C:\Program Files (x86)\Xiph.Org
    2017-10-30 20:33 - 2017-10-30 20:33 - 000000000 ____D C:\Program Files (x86)\directx
    2017-10-30 17:36 - 2017-10-30 17:36 - 000003160 _____ C:\WINDOWS\System32\Tasks\StartCN
    2017-10-30 17:36 - 2017-10-30 17:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
    2017-10-30 17:33 - 2017-10-30 17:33 - 000000000 ____D C:\Program Files\Common Files\ATI Technologies
    2017-10-30 17:25 - 2017-10-30 17:25 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\RadeonInstaller
    2017-10-30 16:29 - 2017-10-30 16:29 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\CrashRpt
    2017-10-30 16:23 - 2017-11-14 08:59 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
    2017-10-30 16:23 - 2017-10-30 16:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rigs of Rods 0.4.7.0
    2017-10-30 16:22 - 2017-10-30 16:22 - 000000000 ____D C:\Program Files (x86)\Rigs of Rods 0.4.7.0
    2017-10-30 12:54 - 2017-10-31 08:02 - 000000018 _____ C:\Users\Ryan Evan Ramos\.ruby-uuid
    2017-10-30 12:04 - 2017-10-30 12:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vanity Pack
    2017-10-30 12:01 - 2017-10-30 12:06 - 000000000 ____D C:\Program Files (x86)\Vanity Pack
    2017-10-29 17:35 - 2017-10-29 17:37 - 000000000 ____D C:\Users\Ryan Evan Ramos\Documents\RCT3
    2017-10-29 17:35 - 2017-10-29 17:35 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Atari
    2017-10-29 17:25 - 2017-10-29 17:26 - 000003238 _____ C:\WINDOWS\System32\Tasks\Aero Glass
    2017-10-29 16:31 - 2017-10-29 16:31 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\LocalLow\Refract
    2017-10-28 17:38 - 2017-10-28 17:38 - 000000000 ____D C:\Program Files (x86)\AGEIA Technologies
    2017-10-27 19:19 - 2017-10-27 19:19 - 000000000 ___HD C:\Users\Ryan Evan Ramos\MicrosoftEdgeBackups
    2017-10-27 17:30 - 2017-10-27 17:30 - 000000000 ____D C:\6ed2eab709c467c8b97cafcfe42f89
    2017-10-27 13:55 - 2017-10-27 13:55 - 001241616 _____ (AMD) C:\WINDOWS\system32\coinst_17.40.dll
    2017-10-27 13:55 - 2017-10-27 13:55 - 000168976 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
    2017-10-27 13:55 - 2017-10-27 13:55 - 000145936 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
    2017-10-27 13:55 - 2017-10-27 13:55 - 000120880 _____ C:\WINDOWS\system32\kapp_ci.sbin
    2017-10-27 13:55 - 2017-10-27 13:55 - 000034501 _____ C:\WINDOWS\system32\AMDKernelEvents.man
    2017-10-26 21:42 - 2017-10-26 21:42 - 000151592 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdihk64.dll
    2017-10-26 21:42 - 2017-10-26 21:42 - 000123752 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdihk32.dll
    2017-10-25 20:30 - 2017-10-26 17:18 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\PlaceholderTileLogoFolder
    2017-10-25 17:13 - 2017-10-25 17:13 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\StreamSurvival2
    2017-10-25 14:35 - 2017-11-13 17:21 - 000000000 ____D C:\WINDOWS\Minidump
    2017-10-25 11:25 - 2017-10-25 11:25 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DroidCam
    2017-10-25 11:25 - 2017-10-25 11:25 - 000000000 ____D C:\Program Files\DroidCam
    2017-10-25 10:38 - 2017-11-12 13:07 - 000032768 _____ C:\WINDOWS\nfm_cache.db-shm
    2017-10-25 10:38 - 2017-10-25 10:38 - 000012392 _____ C:\WINDOWS\nfm_cache.db-wal
    2017-10-25 10:38 - 2017-10-25 10:38 - 000004096 _____ C:\WINDOWS\nfm_cache.db
    2017-10-25 00:32 - 2017-11-06 17:56 - 000000000 ____D C:\Windows.old
    2017-10-24 21:28 - 2017-10-24 21:28 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
    2017-10-24 21:08 - 2017-10-24 21:08 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\PackageStaging
    2017-10-24 21:07 - 2017-10-24 21:07 - 000000020 ___SH C:\Users\Ryan Evan Ramos\ntuser.ini
    2017-10-24 21:01 - 2017-10-24 21:03 - 000007623 _____ C:\WINDOWS\diagwrn.xml
    2017-10-24 21:01 - 2017-10-24 21:03 - 000007623 _____ C:\WINDOWS\diagerr.xml
    2017-10-24 21:00 - 2017-11-14 17:28 - 000003354 _____ C:\WINDOWS\System32\Tasks\CAM
    2017-10-24 21:00 - 2017-11-14 17:19 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2017-10-24 21:00 - 2017-11-14 10:08 - 000003156 _____ C:\WINDOWS\System32\Tasks\MSIAfterburner
    2017-10-24 21:00 - 2017-11-14 10:07 - 000003140 _____ C:\WINDOWS\System32\Tasks\RTSS
    2017-10-24 21:00 - 2017-11-13 15:29 - 000003416 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
    2017-10-24 21:00 - 2017-11-13 15:29 - 000003292 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
    2017-10-24 21:00 - 2017-11-13 14:37 - 000003692 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-354301492-1375950521-280439656-1001UA
    2017-10-24 21:00 - 2017-11-13 14:37 - 000003424 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-354301492-1375950521-280439656-1001Core
    2017-10-24 21:00 - 2017-11-08 19:16 - 000003388 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-354301492-1375950521-280439656-1001
    2017-10-24 21:00 - 2017-10-25 16:34 - 000004386 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
    2017-10-24 21:00 - 2017-10-24 21:00 - 000003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
    2017-10-24 21:00 - 2017-10-24 21:00 - 000003094 _____ C:\WINDOWS\System32\Tasks\Java Platform SE Auto Updater
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002876 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-354301492-1375950521-280439656-1001
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002804 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-ryanevan4@hotmail.com
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002586 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002396 _____ C:\WINDOWS\System32\Tasks\Nahimic2UILauncherRun
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002388 _____ C:\WINDOWS\System32\Tasks\NahimicVRSvc64Run
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002384 _____ C:\WINDOWS\System32\Tasks\Nahimic2Svc64Run
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002380 _____ C:\WINDOWS\System32\Tasks\NahimicVRSvc32Run
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002376 _____ C:\WINDOWS\System32\Tasks\Nahimic2Svc32Run
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002366 _____ C:\WINDOWS\System32\Tasks\{E339F5C1-1CAA-4CFB-B2A1-DE60D516C4B4}
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002314 _____ C:\WINDOWS\System32\Tasks\{C7DA4B05-EC85-4E1F-844D-7E485B63C2C6}
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002240 _____ C:\WINDOWS\System32\Tasks\{A725609A-F2B5-4272-A808-0289609E5540}
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002240 _____ C:\WINDOWS\System32\Tasks\{7E1889A0-E2DC-4090-80D4-2CEC20069AF1}
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002182 _____ C:\WINDOWS\System32\Tasks\{AAF7AD4D-9A1A-452A-ACFA-C52785909272}
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002182 _____ C:\WINDOWS\System32\Tasks\{6235C2A1-08A9-43B6-B778-C00BC5A30EDA}
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002148 _____ C:\WINDOWS\System32\Tasks\MSISW_Host
    2017-10-24 21:00 - 2017-10-24 21:00 - 000002038 _____ C:\WINDOWS\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance
    2017-10-24 21:00 - 2017-10-24 21:00 - 000000000 ____D C:\WINDOWS\System32\Tasks\WPD
    2017-10-24 21:00 - 2017-10-24 21:00 - 000000000 ____D C:\WINDOWS\System32\Tasks\PCMeter
    2017-10-24 21:00 - 2017-10-24 21:00 - 000000000 ____D C:\WINDOWS\System32\Tasks\NCH Software
    2017-10-24 21:00 - 2017-10-24 21:00 - 000000000 ____D C:\WINDOWS\System32\Tasks\ASUS
    2017-10-24 20:47 - 2017-10-24 20:47 - 000000000 ____D C:\ProgramData\USOShared
    2017-10-24 20:44 - 2017-10-24 20:44 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2017-10-24 20:41 - 2017-10-26 17:21 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\Packages
    2017-10-24 20:40 - 2017-11-13 21:59 - 000000000 ____D C:\Users\Ryan Evan Ramos
    2017-10-24 20:39 - 2017-11-14 09:58 - 002061926 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2017-10-24 20:39 - 2017-09-29 08:41 - 002241024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2017-10-24 20:35 - 2017-11-13 17:10 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
    2017-10-24 20:21 - 2017-10-25 00:32 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
    2017-10-24 20:19 - 2017-10-24 20:21 - 000000000 ____D C:\WINDOWS\ServiceProfiles
    2017-10-24 20:13 - 2017-10-25 00:32 - 000000000 ____D C:\Program Files (x86)\MSBuild
    2017-10-24 20:13 - 2017-10-24 20:13 - 000000000 ____D C:\Program Files\Reference Assemblies
    2017-10-24 20:13 - 2017-10-24 20:13 - 000000000 ____D C:\Program Files\MSBuild
    2017-10-24 20:13 - 2017-10-24 20:13 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
    2017-10-24 20:11 - 2017-09-28 14:50 - 001166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
    2017-10-24 20:11 - 2017-09-28 14:50 - 000124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
    2017-10-24 20:11 - 2017-09-28 14:50 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
    2017-10-24 20:11 - 2017-09-22 17:19 - 000778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
    2017-10-24 20:11 - 2017-09-22 17:19 - 000103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2017-10-24 20:11 - 2017-09-22 17:19 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
    2017-10-24 20:01 - 2017-10-24 20:01 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
    2017-10-24 19:25 - 2017-11-14 13:22 - 000000000 ___DC C:\WINDOWS\Panther
    2017-10-24 18:43 - 2017-10-24 18:43 - 000000000 ___HD C:\$Windows.~WS
    2017-10-24 15:35 - 2017-10-24 19:25 - 000000000 ____D C:\ESD
    2017-10-24 15:18 - 2017-10-24 15:32 - 000000731 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10 Update Assistant.lnk
    2017-10-24 15:18 - 2017-10-24 15:18 - 000000000 ____D C:\Windows10Upgrade
    2017-10-24 12:50 - 2017-10-24 12:50 - 000000000 ____D C:\afa8836778f48d9c675faef2dd082594
    2017-10-24 12:29 - 2017-10-24 12:29 - 000000000 ____D C:\b7198c53b0febc6f84b46de0ad976b2d
    2017-10-24 12:22 - 2017-10-24 12:22 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\LocalLow\GoManga Interactive
    2017-10-23 13:41 - 2017-10-23 13:41 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\DevilInThePines
    2017-10-23 09:19 - 2017-10-23 09:19 - 000000000 ____D C:\Program Files (x86)\RailWorks
    2017-10-19 19:42 - 2017-11-03 14:32 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\NZXT
    2017-10-19 19:29 - 2017-11-14 09:07 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\DiscordCanary
    2017-10-18 13:20 - 2017-10-18 13:20 - 000000000 ____D C:\Users\Ryan Evan Ramos\Documents\REG
    2017-10-17 11:12 - 2017-10-17 11:12 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\VirtualDJ
    2017-10-17 11:11 - 2017-10-24 20:50 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
    2017-10-17 11:11 - 2017-10-23 13:33 - 000000000 ____D C:\Program Files (x86)\VirtualDJ
    2017-10-17 11:11 - 2017-10-19 15:28 - 000000000 ____D C:\Users\Ryan Evan Ramos\Documents\VirtualDJ
    2017-10-17 10:03 - 2017-10-17 11:37 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\Mixxx
    2017-10-15 16:27 - 2017-10-15 16:27 - 126925120 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
    
    ==================== One Month Modified files and folders ========
    
    (If an entry is included in the fixlist, the file/folder will be moved.)
    
    2017-11-14 18:36 - 2017-07-26 17:37 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\Nox
    2017-11-14 18:21 - 2017-07-13 18:14 - 000000000 ____D C:\ProgramData\Remotr
    2017-11-14 18:10 - 2015-06-30 12:39 - 000000000 ____D C:\Program Files (x86)\Steam
    2017-11-14 18:08 - 2015-11-04 06:37 - 000000000 ____D C:\Users\Ryan Evan Ramos\.android
    2017-11-14 18:07 - 2017-07-26 17:38 - 000000000 ____D C:\Users\Ryan Evan Ramos\vmlogs
    2017-11-14 17:36 - 2015-08-29 19:34 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\TSVNCache
    2017-11-14 17:23 - 2017-08-01 13:50 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\LocalLow\Mozilla
    2017-11-14 17:18 - 2017-09-29 03:45 - 025952256 _____ C:\WINDOWS\system32\config\HARDWARE
    2017-11-14 17:18 - 2017-09-29 03:45 - 000786432 _____ C:\WINDOWS\system32\config\BBI
    2017-11-14 17:08 - 2017-08-01 13:49 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2017-11-14 17:08 - 2015-06-30 09:09 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2017-11-14 17:07 - 2017-07-18 15:04 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
    2017-11-14 16:53 - 2015-08-02 13:03 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\stdplugs
    2017-11-14 16:53 - 2015-08-02 13:03 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\scripts
    2017-11-14 16:53 - 2015-08-02 13:03 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\MacroScripts
    2017-11-14 15:18 - 2015-06-30 09:09 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Mozilla
    2017-11-14 15:07 - 2015-06-30 09:09 - 000001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
    2017-11-14 13:46 - 2015-12-26 15:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
    2017-11-14 13:46 - 2015-12-26 15:50 - 000000000 ____D C:\Program Files\CPUID
    2017-11-14 13:38 - 2017-09-29 08:46 - 000000000 ___HD C:\Program Files\WindowsApps
    2017-11-14 13:38 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
    2017-11-14 13:38 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\AppReadiness
    2017-11-14 13:28 - 2017-10-10 16:10 - 000000000 ____D C:\Users\Ryan Evan Ramos\Downloads\Stardock
    2017-11-14 13:28 - 2017-10-03 13:30 - 000000000 ____D C:\Users\Ryan Evan Ramos\Downloads\Pac.Man.And.The.Ghostly.Adventures.2.PS3-iMARS
    2017-11-14 13:28 - 2017-09-18 12:31 - 000000000 ____D C:\Users\Ryan Evan Ramos\Downloads\mbid-ddb0eb4e-a0fa-4c4b-8f6f-0541363d4199
    2017-11-14 13:28 - 2017-08-22 14:59 - 000000000 ____D C:\Users\Ryan Evan Ramos\Downloads\BLUS31441_AUTO
    2017-11-14 13:28 - 2017-07-10 20:42 - 000000000 ____D C:\Users\Ryan Evan Ramos\Downloads\Tweaking.com - Repair WMI
    2017-11-14 13:28 - 2017-05-23 22:49 - 000000000 ____D C:\Users\Ryan Evan Ramos\Downloads\Trident Z RGB Control v1.00.22 BETA
    2017-11-14 13:28 - 2016-03-24 19:29 - 000000000 ____D C:\Users\Ryan Evan Ramos\Downloads\Turbo.FAST.S02.720p.NF.WebRip.x265-RnC
    2017-11-14 13:28 - 2016-03-23 10:36 - 000000000 ____D C:\Users\Ryan Evan Ramos\Downloads\Turbo FAST - Season 1, Episodes 01-13
    2017-11-14 13:28 - 2016-03-06 14:17 - 000000000 ____D C:\Users\Ryan Evan Ramos\Downloads\Xilisoft Video Converter Ultimate 7.8.8 Build 20150402 + Serial Key [DTW]
    2017-11-14 13:28 - 2016-02-16 20:38 - 000000000 ____D C:\Users\Ryan Evan Ramos\Downloads\Jean Jacques Perrey - Moog Indigo
    2017-11-14 13:28 - 2016-02-07 16:45 - 000000000 ____D C:\Users\Ryan Evan Ramos\Downloads\CAMP LAZLO[SEASONS 1-5][VERIFIED-VIDZ]
    2017-11-14 13:27 - 2016-04-12 15:36 - 000000000 ____D C:\AMD
    2017-11-14 13:22 - 2017-09-29 08:44 - 000000000 ____D C:\WINDOWS\INF
    2017-11-14 13:22 - 2015-12-13 21:32 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Skype
    2017-11-14 13:22 - 2015-11-04 15:35 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\TeamViewer
    2017-11-14 13:21 - 2015-10-21 16:00 - 000000000 ____D C:\Program Files (x86)\TeamViewer
    2017-11-14 13:20 - 2017-10-02 08:14 - 000000000 __SHD C:\found.002
    2017-11-14 13:20 - 2015-08-01 19:30 - 000000000 __SHD C:\found.001
    2017-11-14 13:05 - 2015-07-16 14:29 - 000000000 ____D C:\Program Files\SoftEther VPN Client
    2017-11-14 13:01 - 2017-08-23 15:21 - 000002718 _____ C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam ROM Manager.lnk
    2017-11-14 13:01 - 2017-08-21 13:34 - 000001434 _____ C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RPCS3.lnk
    2017-11-14 13:01 - 2017-08-01 19:06 - 000001478 _____ C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cemu.lnk
    2017-11-14 13:01 - 2015-11-01 19:55 - 000001348 _____ C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\join.me.lnk
    2017-11-14 13:01 - 2015-10-16 17:47 - 000001300 _____ C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HTTP File Server.lnk
    2017-11-14 13:01 - 2015-08-01 21:15 - 000001580 _____ C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DeSmuME_X432R_x64.lnk
    2017-11-14 13:01 - 2015-08-01 21:15 - 000001470 _____ C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crowbar.lnk
    2017-11-14 13:01 - 2015-08-01 20:49 - 000001624 _____ C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MikuMikuDance.lnk
    2017-11-14 13:01 - 2015-08-01 20:49 - 000001614 _____ C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PmxEditor.lnk
    2017-11-14 13:01 - 2015-07-30 01:16 - 000002560 _____ C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2017-11-14 12:59 - 2015-07-04 06:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Toontown Rewritten
    2017-11-14 12:58 - 2017-07-27 17:07 - 000000000 ____D C:\AeroGlass
    2017-11-14 10:07 - 2015-06-30 10:53 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
    2017-11-14 10:05 - 2016-01-12 10:28 - 000000000 ____D C:\Program Files (x86)\CodeMeter
    2017-11-14 09:49 - 2016-04-12 16:37 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
    2017-11-14 09:44 - 2015-08-08 20:11 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\MPC-BE
    2017-11-14 09:07 - 2017-07-27 17:31 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
    2017-11-14 09:07 - 2017-07-27 17:31 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\discordcanary
    2017-11-14 08:59 - 2016-04-12 16:39 - 000000000 ___HD C:\WINDOWS\msdownld.tmp
    2017-11-14 08:39 - 2017-10-10 13:41 - 000000000 ____D C:\ProgramData\Immunet
    2017-11-14 08:23 - 2015-06-30 15:43 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\Adobe
    2017-11-13 19:56 - 2015-06-30 08:43 - 000000000 ____D C:\ProgramData\Skype
    2017-11-13 17:26 - 2017-09-29 08:37 - 000000000 ____D C:\WINDOWS\CbsTemp
    2017-11-13 17:21 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\ModemLogs
    2017-11-13 17:21 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\LiveKernelReports
    2017-11-13 17:21 - 2015-06-30 19:50 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\LogMeIn Hamachi
    2017-11-13 16:46 - 2017-07-12 16:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
    2017-11-13 16:46 - 2017-07-12 16:58 - 000000000 ____D C:\Program Files (x86)\MSI
    2017-11-13 16:46 - 2017-07-10 16:50 - 000000000 ____D C:\MSI
    2017-11-13 16:38 - 2015-07-26 18:03 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2017-11-12 15:35 - 2017-08-08 10:35 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\citra
    2017-11-11 23:15 - 2015-07-01 20:34 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\ElevatedDiagnostics
    2017-11-10 17:38 - 2017-08-17 16:06 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\USB_HELPER
    2017-11-09 21:35 - 2017-08-23 15:21 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\steam-rom-manager
    2017-11-08 19:16 - 2015-07-01 10:51 - 000000000 __RDO C:\Users\Ryan Evan Ramos\OneDrive
    2017-11-07 19:19 - 2015-09-16 16:53 - 000000000 ____D C:\tmp
    2017-11-07 18:33 - 2015-06-30 09:46 - 000000000 ____D C:\Users\Ryan Evan Ramos\Documents\AirDroid
    2017-11-07 18:28 - 2015-07-18 11:13 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
    2017-11-07 09:39 - 2017-09-29 08:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2017-11-07 09:37 - 2015-10-21 15:25 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
    2017-11-05 17:45 - 2015-07-04 06:28 - 000000000 ____D C:\Program Files (x86)\Toontown Rewritten
    2017-11-04 21:06 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\Registration
    2017-11-04 19:30 - 2017-07-25 11:13 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Citra Development Team
    2017-11-04 19:24 - 2015-07-06 11:57 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Citra team
    2017-11-04 16:12 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\NDF
    2017-11-02 17:41 - 2015-10-26 12:32 - 000000034 _____ C:\ProgramData\droidcam-settings
    2017-10-30 20:31 - 2015-12-06 17:10 - 000000000 ____D C:\Program Files (x86)\ManyCam
    2017-10-30 17:33 - 2017-07-18 15:04 - 000000000 ____D C:\Program Files\AMD
    2017-10-30 17:32 - 2016-03-25 21:24 - 000000000 ____D C:\Program Files (x86)\VulkanRT
    2017-10-30 17:25 - 2017-09-18 13:34 - 000000060 _____ C:\ProgramData\SoftwareUpdateTemp.xml
    2017-10-30 17:12 - 2015-08-08 20:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-BE x64
    2017-10-30 17:12 - 2015-06-30 10:43 - 000000000 ____D C:\Program Files\MPC-BE x64
    2017-10-30 16:22 - 2015-06-30 09:45 - 000000000 ____D C:\Users\Ryan Evan Ramos\Documents\Rigs of Rods 0.4
    2017-10-30 13:55 - 2016-02-19 12:41 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\qBittorrent
    2017-10-29 17:53 - 2015-06-30 08:23 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\VirtualStore
    2017-10-28 17:38 - 2015-06-30 09:40 - 000000000 ____D C:\Users\Ryan Evan Ramos\Documents\My Games
    2017-10-27 13:55 - 2017-10-06 13:02 - 003471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap
    2017-10-27 13:55 - 2017-10-06 13:02 - 003437632 _____ C:\WINDOWS\system32\atiumd6a.cap
    2017-10-27 13:55 - 2017-10-06 13:02 - 000708112 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
    2017-10-27 13:55 - 2017-10-06 13:02 - 000556560 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Rapidfire64.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000480272 _____ C:\WINDOWS\system32\dgtrayicon.exe
    2017-10-27 13:55 - 2017-10-06 13:02 - 000470544 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\Rapidfire.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000467984 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000458768 _____ C:\WINDOWS\system32\GameManager64.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000414736 _____ C:\WINDOWS\system32\atieah64.exe
    2017-10-27 13:55 - 2017-10-06 13:02 - 000366608 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000352272 _____ C:\WINDOWS\system32\clinfo.exe
    2017-10-27 13:55 - 2017-10-06 13:02 - 000334864 _____ C:\WINDOWS\SysWOW64\atieah32.exe
    2017-10-27 13:55 - 2017-10-06 13:02 - 000277008 _____ C:\WINDOWS\system32\hsa-thunk64.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000242704 _____ C:\WINDOWS\SysWOW64\hsa-thunk.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000232464 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000203792 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000180240 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000159248 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000157712 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000151056 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000135696 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000133648 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000124944 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000122024 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000117264 _____ C:\WINDOWS\system32\atidxx64.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000102664 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000101904 _____ C:\WINDOWS\SysWOW64\atidxx32.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000045584 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\RapidFireServer64.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000042512 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\RapidFireServer.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000029712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
    2017-10-27 13:55 - 2017-10-06 13:02 - 000029712 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 013537296 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdvlk64.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 011100176 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdvlk32.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 002924560 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 002542608 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 001464336 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 001061392 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 001061392 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000875536 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000834320 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb
    2017-10-27 13:55 - 2017-10-06 13:01 - 000834320 _____ C:\WINDOWS\system32\atiapfxx.blb
    2017-10-27 13:55 - 2017-10-06 13:01 - 000704016 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000552976 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmcl64.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000548440 _____ C:\WINDOWS\system32\amdmiracast.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000445968 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000382992 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmcl32.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000361488 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000186416 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdhcp64.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000164552 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdhcp32.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000157864 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000149600 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000131304 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000122024 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000116216 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000114192 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000102664 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000099344 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000069648 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ati2erec.dll
    2017-10-27 13:55 - 2017-10-06 13:01 - 000000145 _____ C:\WINDOWS\SysWOW64\amd-vulkan32.json
    2017-10-27 13:55 - 2017-10-06 13:01 - 000000145 _____ C:\WINDOWS\system32\amd-vulkan64.json
    2017-10-25 17:13 - 2015-12-11 22:43 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\UnrealEngine
    2017-10-25 17:12 - 2015-07-30 00:18 - 000000000 ____D C:\ProgramData\Package Cache
    2017-10-25 17:01 - 2017-10-03 14:38 - 000000000 ____D C:\Users\Ryan Evan Ramos\Documents\American Truck Simulator
    2017-10-25 16:34 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
    2017-10-25 16:34 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\Macromed
    2017-10-25 12:44 - 2015-11-17 18:31 - 000000000 ____D C:\Program Files (x86)\AirDroid
    2017-10-25 11:24 - 2015-10-26 12:30 - 000000000 ____D C:\Program Files (x86)\DroidCam
    2017-10-25 10:40 - 2015-07-30 00:59 - 000000594 __RSH C:\ProgramData\ntuser.pol
    2017-10-25 10:14 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\appcompat
    2017-10-25 10:13 - 2017-09-29 08:46 - 000000000 ___RD C:\WINDOWS\PrintDialog
    2017-10-25 00:34 - 2017-09-29 08:46 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
    2017-10-25 00:33 - 2017-09-29 09:41 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
    2017-10-25 00:33 - 2017-09-29 09:41 - 000000000 ____D C:\WINDOWS\system32\WCN
    2017-10-25 00:33 - 2017-09-29 08:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
    2017-10-25 00:33 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
    2017-10-25 00:33 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
    2017-10-25 00:33 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\spool
    2017-10-25 00:33 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\oobe
    2017-10-25 00:33 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\InputMethod
    2017-10-25 00:33 - 2017-08-31 18:28 - 000000000 ___HD C:\WINDOWS\system32\WLANProfiles
    2017-10-25 00:33 - 2017-03-18 16:03 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
    2017-10-25 00:33 - 2015-12-05 19:25 - 000000000 ____D C:\WINDOWS\SysWOW64\Adobe
    2017-10-25 00:33 - 2015-11-26 22:34 - 000000000 ____D C:\WINDOWS\SysWOW64\1033
    2017-10-25 00:33 - 2015-11-26 22:34 - 000000000 ____D C:\WINDOWS\system32\1033
    2017-10-25 00:33 - 2015-11-06 20:49 - 000000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin
    2017-10-25 00:33 - 2015-06-30 20:35 - 000000000 ____D C:\WINDOWS\system32\appmgmt
    2017-10-25 00:33 - 2013-08-22 10:36 - 000000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
    2017-10-25 00:33 - 2013-08-22 10:36 - 000000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
    2017-10-25 00:32 - 2017-10-09 11:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G.SKILL
    2017-10-25 00:32 - 2017-09-29 08:49 - 000000000 ____D C:\WINDOWS\Setup
    2017-10-25 00:32 - 2017-09-29 08:46 - 000000000 __SHD C:\Program Files\Windows Sidebar
    2017-10-25 00:32 - 2017-09-29 08:46 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
    2017-10-25 00:32 - 2017-09-29 08:46 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
    2017-10-25 00:32 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
    2017-10-25 00:32 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\InputMethod
    2017-10-25 00:32 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\IME
    2017-10-25 00:32 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\Cursors
    2017-10-25 00:32 - 2017-09-29 08:46 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
    2017-10-25 00:32 - 2017-08-31 18:26 - 000000000 ____D C:\Program Files\Intel
    2017-10-25 00:32 - 2017-07-08 14:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Problem Report Wizard
    2017-10-25 00:32 - 2016-04-02 10:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
    2017-10-25 00:32 - 2016-03-07 18:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
    2017-10-25 00:32 - 2016-02-07 20:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2017-10-25 00:32 - 2016-02-07 19:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
    2017-10-25 00:32 - 2016-02-02 17:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crazybump
    2017-10-25 00:32 - 2016-01-18 18:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolphin
    2017-10-25 00:32 - 2016-01-18 13:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PPSSPP
    2017-10-25 00:32 - 2016-01-13 18:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\8GadgetPack
    2017-10-25 00:32 - 2016-01-11 15:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bus Driver
    2017-10-25 00:32 - 2016-01-06 15:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    2017-10-25 00:32 - 2016-01-02 13:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Midtown Madness 2 Vehicle Editor
    2017-10-25 00:32 - 2015-12-27 19:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinToUSB
    2017-10-25 00:32 - 2015-12-26 21:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Kombustor 3
    2017-10-25 00:32 - 2015-12-15 18:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
    2017-10-25 00:32 - 2015-12-14 21:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cygwin
    2017-10-25 00:32 - 2015-12-13 18:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LIGHTNING RETURNS FINAL FANTASY XIII
    2017-10-25 00:32 - 2015-11-27 21:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clownfish
    2017-10-25 00:32 - 2015-11-26 22:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2013
    2017-10-25 00:32 - 2015-11-17 18:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AirDroid
    2017-10-25 00:32 - 2015-10-31 22:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ComicRack
    2017-10-25 00:32 - 2015-10-30 04:07 - 000000000 ____D C:\WINDOWS\ShellNew
    2017-10-25 00:32 - 2015-10-24 11:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Open Rails
    2017-10-25 00:32 - 2015-10-21 15:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
    2017-10-25 00:32 - 2015-09-30 18:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoHotkey
    2017-10-25 00:32 - 2015-09-27 13:21 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
    2017-10-25 00:32 - 2015-09-25 21:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Chuzzle Deluxe
    2017-10-25 00:32 - 2015-08-29 18:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TortoiseSVN
    2017-10-25 00:32 - 2015-08-16 15:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix
    2017-10-25 00:32 - 2015-07-29 14:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\openBVE
    2017-10-25 00:32 - 2015-07-22 13:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeerBlock
    2017-10-25 00:32 - 2015-07-15 09:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vidalia Bridge Bundle
    2017-10-25 00:32 - 2015-07-14 13:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSX2
    2017-10-25 00:32 - 2015-07-12 14:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
    2017-10-25 00:32 - 2015-07-07 20:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
    2017-10-25 00:32 - 2015-07-05 10:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tonido
    2017-10-25 00:32 - 2015-07-02 19:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
    2017-10-25 00:32 - 2015-07-02 18:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoundWire Server
    2017-10-25 00:32 - 2015-07-01 18:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4
    2017-10-25 00:32 - 2015-06-30 20:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 3.1
    2017-10-25 00:32 - 2015-06-30 19:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flawless Widescreen
    2017-10-25 00:32 - 2015-06-30 19:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
    2017-10-25 00:32 - 2015-06-30 15:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
    2017-10-25 00:32 - 2015-06-30 14:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blasterball 2 Remix
    2017-10-25 00:32 - 2015-06-30 14:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
    2017-10-25 00:32 - 2015-06-30 10:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ext2Fsd
    2017-10-25 00:32 - 2013-08-22 10:36 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
    2017-10-24 21:08 - 2017-07-18 15:46 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\ConnectedDevicesPlatform
    2017-10-24 21:07 - 2015-07-30 02:21 - 000000000 ___RD C:\Users\Ryan Evan Ramos\3D Objects
    2017-10-24 21:07 - 2015-07-30 00:59 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\TileDataLayer
    2017-10-24 21:07 - 2015-06-30 08:31 - 000000000 __RHD C:\Users\Public\AccountPictures
    2017-10-24 21:05 - 2017-09-29 03:45 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
    2017-10-24 21:00 - 2015-07-30 00:45 - 000022840 _____ C:\WINDOWS\system32\emptyregdb.dat
    2017-10-24 20:50 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
    2017-10-24 20:50 - 2017-08-17 16:04 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WiiU_USB_Helper
    2017-10-24 20:50 - 2017-07-26 17:38 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Nox
    2017-10-24 20:50 - 2016-04-12 16:38 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
    2017-10-24 20:50 - 2016-02-02 17:22 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WiFi共享精灵
    2017-10-24 20:50 - 2016-01-06 15:10 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    2017-10-24 20:50 - 2015-12-28 11:06 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TonidoDrive
    2017-10-24 20:50 - 2015-12-10 17:57 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
    2017-10-24 20:50 - 2015-11-20 16:57 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kodi
    2017-10-24 20:50 - 2015-10-26 16:34 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU
    2017-10-24 20:50 - 2015-07-31 20:31 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mmv
    2017-10-24 20:50 - 2015-06-30 19:34 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xtreme Download Manager
    2017-10-24 20:50 - 2015-06-30 18:30 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z
    2017-10-24 20:50 - 2015-06-30 10:53 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
    2017-10-24 20:47 - 2017-09-29 08:46 - 000000000 ____D C:\ProgramData\USOPrivate
    2017-10-24 20:45 - 2017-09-29 08:46 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2017-10-24 20:42 - 2017-07-31 10:51 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AMD
    2017-10-24 20:39 - 2017-09-29 03:45 - 000000000 ____D C:\WINDOWS\system32\Sysprep
    2017-10-24 20:39 - 2017-07-18 15:07 - 000936124 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
    2017-10-24 20:38 - 2017-09-26 09:12 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
    2017-10-24 20:38 - 2017-09-26 09:12 - 000000000 ____D C:\WINDOWS\system32\RTCOM
    2017-10-24 20:38 - 2017-07-18 15:04 - 000000000 ____D C:\WINDOWS\system32\DAX3
    2017-10-24 20:38 - 2017-07-18 15:04 - 000000000 ____D C:\WINDOWS\system32\DAX2
    2017-10-24 20:38 - 2017-07-18 15:04 - 000000000 ____D C:\ProgramData\Audyssey Labs
    2017-10-24 20:28 - 2017-09-29 08:46 - 000000000 __RHD C:\Users\Public\Libraries
    2017-10-24 20:23 - 2017-09-29 09:41 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
    2017-10-24 20:23 - 2017-09-29 09:41 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
    2017-10-24 20:23 - 2017-09-29 09:41 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
    2017-10-24 20:23 - 2017-09-29 09:41 - 000000000 ____D C:\WINDOWS\system32\winrm
    2017-10-24 20:23 - 2017-09-29 09:41 - 000000000 ____D C:\WINDOWS\system32\slmgr
    2017-10-24 20:23 - 2017-09-29 09:41 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
    2017-10-24 20:23 - 2017-09-29 08:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
    2017-10-24 20:23 - 2017-09-29 08:46 - 000000000 ___SD C:\WINDOWS\system32\F12
    2017-10-24 20:23 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
    2017-10-24 20:23 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
    2017-10-24 20:23 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
    2017-10-24 20:23 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
    2017-10-24 20:23 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\MUI
    2017-10-24 20:23 - 2015-12-06 11:38 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
    2017-10-24 20:22 - 2017-09-29 08:46 - 000000000 ___SD C:\WINDOWS\system32\dsc
    2017-10-24 20:22 - 2017-09-29 08:46 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
    2017-10-24 20:22 - 2017-09-29 03:45 - 000000000 ____D C:\WINDOWS\system32\Dism
    2017-10-24 20:21 - 2017-10-07 08:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PUSH Entertainment
    2017-10-24 20:21 - 2017-09-29 09:41 - 000000000 ____D C:\WINDOWS\OCR
    2017-10-24 20:21 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\Help
    2017-10-24 20:21 - 2017-09-29 08:46 - 000000000 ____D C:\Program Files\Windows Photo Viewer
    2017-10-24 20:21 - 2017-09-29 08:46 - 000000000 ____D C:\Program Files\Common Files\system
    2017-10-24 20:21 - 2017-09-26 09:12 - 000000000 ____D C:\Program Files\Realtek
    2017-10-24 20:21 - 2017-08-31 18:27 - 000000000 ____D C:\Program Files (x86)\Intel
    2017-10-24 20:21 - 2016-03-25 21:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 1.0.3.1
    2017-10-24 20:21 - 2016-03-06 16:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xilisoft
    2017-10-24 20:21 - 2015-12-23 19:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CFS-Technologies
    2017-10-24 20:21 - 2015-11-11 18:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RSUPPORT
    2017-10-24 20:21 - 2015-10-23 17:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
    2017-10-24 20:21 - 2015-08-21 21:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rosetta Stone
    2017-10-24 20:21 - 2015-07-19 18:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nem's Tools
    2017-10-24 20:21 - 2015-07-08 13:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SEGA
    2017-10-24 20:21 - 2015-06-30 20:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BabelSoft
    2017-10-24 20:21 - 2015-06-30 18:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
    2017-10-24 20:21 - 2015-06-30 16:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\N3V Games
    2017-10-24 20:21 - 2015-06-30 09:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
    2017-10-24 20:13 - 2017-09-29 08:41 - 000422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
    2017-10-24 20:13 - 2017-09-29 08:41 - 000389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll
    2017-10-24 20:13 - 2017-09-29 08:41 - 000218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll
    2017-10-24 20:13 - 2017-09-29 08:41 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll
    2017-10-24 20:13 - 2017-09-29 08:41 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll
    2017-10-24 20:13 - 2017-09-29 08:41 - 000024576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll
    2017-10-24 20:13 - 2017-09-29 08:41 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe
    2017-10-24 20:13 - 2017-09-29 08:41 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe
    2017-10-24 20:13 - 2017-09-29 08:41 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll
    2017-10-24 20:13 - 2017-09-29 08:41 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll
    2017-10-24 20:13 - 2017-09-29 08:41 - 000005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll
    2017-10-24 20:13 - 2017-09-29 08:41 - 000005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll
    2017-10-24 20:12 - 2017-09-29 08:41 - 000464896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
    2017-10-24 20:12 - 2017-09-29 08:41 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
    2017-10-24 20:12 - 2017-09-29 08:41 - 000026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
    2017-10-24 20:12 - 2017-09-29 08:41 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
    2017-10-24 20:12 - 2017-09-29 08:41 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
    2017-10-24 20:12 - 2017-09-29 08:41 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
    2017-10-24 20:12 - 2017-09-29 08:41 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
    2017-10-24 08:03 - 2015-06-30 14:43 - 000000000 ____D C:\Games
    2017-10-19 19:29 - 2016-03-16 19:52 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\discord
    2017-10-19 19:29 - 2016-03-16 19:52 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Local\SquirrelTemp
    2017-10-19 18:39 - 2017-10-07 17:59 - 000000000 ____D C:\Program Files (x86)\WiFi
    2017-10-17 20:43 - 2016-03-27 12:01 - 000000000 ____D C:\Users\Ryan Evan Ramos\Documents\ManiaPlanet
    2017-10-17 20:02 - 2016-03-27 12:01 - 000000000 ____D C:\ProgramData\ManiaPlanet
    2017-10-17 10:53 - 2015-06-30 20:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ots Labs
    2017-10-16 21:39 - 2015-07-22 13:52 - 000000000 ____D C:\Program Files\PeerBlock
    2017-10-16 08:20 - 2015-07-18 06:03 - 000000000 ____D C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blender
    2017-10-15 16:33 - 2015-06-30 16:06 - 000000000 ____D C:\WINDOWS\system32\MRT
    2017-10-15 16:27 - 2015-06-30 16:06 - 126925120 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    
    ==================== Files in the root of some directories =======
    
    2015-03-26 06:48 - 2015-03-26 06:48 - 002174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
    2015-12-05 10:41 - 2015-12-06 07:49 - 000000624 _____ () C:\Users\Ryan Evan Ramos\AppData\Roaming\All CPU MeterV3_Settings.ini
    2015-10-28 15:27 - 2017-08-16 11:22 - 000000000 _____ () C:\Users\Ryan Evan Ramos\AppData\Roaming\FileIn.cns
    2015-10-28 15:27 - 2017-08-16 11:22 - 000000000 _____ () C:\Users\Ryan Evan Ramos\AppData\Roaming\FileOut.cns
    2015-08-21 16:05 - 2015-08-21 16:06 - 000003265 _____ () C:\Users\Ryan Evan Ramos\AppData\Roaming\glide_wrapper.zbag.ini
    2015-10-21 05:11 - 2015-10-21 05:11 - 000001096 _____ () C:\Users\Ryan Evan Ramos\AppData\Roaming\Network Meter_Settings.ini
    2015-10-21 05:11 - 2017-07-27 20:29 - 000000009 _____ () C:\Users\Ryan Evan Ramos\AppData\Roaming\Network Meter_Usage.ini
    2015-07-01 18:07 - 2017-07-27 19:06 - 000000897 _____ () C:\Users\Ryan Evan Ramos\AppData\Roaming\Network Monitor II_#0_Settings.ini
    2015-07-01 18:49 - 2017-07-27 19:06 - 000000141 _____ () C:\Users\Ryan Evan Ramos\AppData\Roaming\Network Monitor II_#0_Traffic.ini
    2016-01-13 19:46 - 2017-07-27 19:13 - 000002869 _____ () C:\Users\Ryan Evan Ramos\AppData\Roaming\System Monitor II_CPU0_Settings.ini
    2016-01-13 19:39 - 2016-01-23 12:21 - 000000122 _____ () C:\Users\Ryan Evan Ramos\AppData\Roaming\System Monitor II_UptimeRecord.ini
    2015-11-27 21:45 - 2015-11-27 21:45 - 000001167 _____ () C:\Users\Ryan Evan Ramos\AppData\Roaming\trace_FilterInstaller.1.txt
    2015-11-27 21:45 - 2015-11-28 21:53 - 000000905 _____ () C:\Users\Ryan Evan Ramos\AppData\Roaming\trace_FilterInstaller.txt
    2015-11-27 21:45 - 2015-11-28 21:53 - 000000000 _____ () C:\Users\Ryan Evan Ramos\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt
    2015-07-19 16:59 - 2015-07-19 16:59 - 000000000 ___SH () C:\Users\Ryan Evan Ramos\AppData\Local\LumaEmu
    2015-11-01 19:53 - 2015-11-01 19:53 - 000000239 _____ () C:\Users\Ryan Evan Ramos\AppData\Local\poetsch.bat
    2015-08-20 13:33 - 2015-08-20 13:33 - 000001608 _____ () C:\Users\Ryan Evan Ramos\AppData\Local\recently-used.xbel
    2017-07-28 21:04 - 2017-07-28 21:04 - 000007605 _____ () C:\Users\Ryan Evan Ramos\AppData\Local\Resmon.ResmonCfg
    2017-07-18 15:04 - 2017-07-18 15:04 - 000000000 _____ () C:\ProgramData\DP45977C.lfl
    2015-10-26 12:32 - 2017-11-02 17:41 - 000000034 _____ () C:\ProgramData\droidcam-settings
    2017-09-18 13:34 - 2017-10-30 17:25 - 000000060 _____ () C:\ProgramData\SoftwareUpdateTemp.xml
    
    Files to move or delete:
    ====================
    C:\Users\Ryan Evan Ramos\IP_Log_Data.js
    
    
    Some files in TEMP:
    ====================
    2017-11-13 16:44 - 2017-11-13 16:30 - 000067134 _____ () C:\Users\Ryan Evan Ramos\AppData\Local\Temp\Uninstall.exe
    
    ==================== Bamital & volsnap ======================
    
    (There is no automatic fix for files that do not pass verification.)
    
    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
    
    LastRegBack: 2017-11-11 23:14
    
    ==================== End of FRST.txt ============================
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-11-2017 03
    Ran by Ryan Evan Ramos (14-11-2017 18:39:42)
    Running from C:\Users\Ryan Evan Ramos\Desktop
    Windows 10 Pro Version 1709 16299.15 (X64) (2017-10-25 02:06:02)
    Boot Mode: Normal
    ==========================================================
    
    
    ==================== Accounts: =============================
    
    Administrator (S-1-5-21-354301492-1375950521-280439656-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-354301492-1375950521-280439656-503 - Limited - Disabled)
    Guest (S-1-5-21-354301492-1375950521-280439656-501 - Limited - Disabled)
    hybri (S-1-5-21-354301492-1375950521-280439656-1007 - Limited - Disabled)
    Ryan Evan Ramos (S-1-5-21-354301492-1375950521-280439656-1001 - Administrator - Enabled) => C:\Users\Ryan Evan Ramos
    WDAGUtilityAccount (S-1-5-21-354301492-1375950521-280439656-504 - Limited - Disabled)
    
    ==================== Security Center ========================
    
    (If an entry is included in the fixlist, it will be removed.)
    
    AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
    FW: Avast Antivirus (Enabled) {B693136B-F6EE-DD1C-A0EF-229B8B0B29C4}
    
    ==================== Installed Programs ======================
    
    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
    
    7-Zip 15.05 beta x64 (HKLM\...\7-Zip) (Version:  - )
    8GadgetPack (HKLM-x32\...\{D0BD6EC7-ADBC-4127-815A-77E2336873EA}) (Version: 17.0.0 - Helmut Buhler)
    Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.012.20098 - Adobe Systems Incorporated)
    Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.183 - Adobe Systems Incorporated)
    Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0.1 - Adobe Systems Incorporated)
    Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.3.183 - Adobe Systems, Inc.)
    Aero Glass for Win8.1 (HKLM\...\Aero Glass for Win8.1_is1) (Version: 1.2.5 - Big Muscle)
    Aero Glass for Win8.1+ (HKLM\...\{277BA0F1-D0BB-4D73-A2DF-6B60C91E1533}_is1) (Version: 1.5.6 - Big Muscle)
    AirDroid 3.5.1.1 (HKLM-x32\...\AirDroid) (Version: 3.5.1.1 - Sand Studio)
    AMD Ryzen Master (HKLM\...\{03213877-8001-4F2C-8917-26B127DE1540}) (Version: 1.0.1.0239 - Advanced Micro Devices, Inc.)
    AMD Ryzen Master SDK (HKLM\...\{8589864A-D0DC-4624-8F39-158E126F23DC}) (Version: 1.0.1.0239 - Advanced Micro Devices, Inc.)
    AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.)
    Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Audacity 2.1.1 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.1 - Audacity Team)
    Autodesk FBX Plug-in 2012.0 - 3ds Max 2012 64-bit (HKLM\...\Autodesk FBX Plug-in 2012.0 - 3ds Max 2012 64-bit) (Version:  - Autodesk)
    AutoHotkey 1.1.22.07 (HKLM\...\AutoHotkey) (Version: 1.1.22.07 - Lexikos)
    Avast Cleanup Premium (HKLM-x32\...\{075CC190-59EE-499F-828B-0B5C098C8C15}_is1) (Version: 17.2.3341.0 - AVAST Software)
    Avast Driver Updater (HKLM-x32\...\{06E0CADE-89B2-4EFD-B0AF-0DDCE4400E70}) (Version: 2.2.3 - AVAST Software) Hidden
    Avast Driver Updater (HKLM-x32\...\Avast Driver Updater) (Version: 2.2.3 - AVAST Software)
    Avast Premier (HKLM-x32\...\Avast Antivirus) (Version: 17.8.2318 - AVAST Software)
    AzureTools.Notifications.VwdExpress (HKLM-x32\...\{4C4FEB30-6A9F-402F-8E17-6C4C67AB3498}) (Version: 2.1.10731.1602 - Microsoft Corporation) Hidden
    Blasterball 2 Remix (HKLM-x32\...\{6236F514-B2B5-4432-95C0-201EB12BFE60}}_is1) (Version:  - WildTangent Games)
    Blur (HKLM-x32\...\Blur_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, ProZorg_tm)
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    Build Tools - amd64 (HKLM\...\{F74753A3-C93C-34F5-A199-993CAF602B7D}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
    Build Tools - x86 (HKLM-x32\...\{FB3A15FD-FC67-3A2F-892B-6890B0C56EA9}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
    Build Tools Language Resources - amd64 (HKLM\...\{05198C22-FFCE-374A-B190-9F18CC99DAEA}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
    Build Tools Language Resources - x86 (HKLM-x32\...\{9347889B-C22A-3905-901F-C05D8F73C929}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
    Bus Driver 1.5 (HKLM-x32\...\Bus Driver) (Version: 1.5 - )
    CAM (HKLM-x32\...\{6A4396B7-49C0-46D0-982D-247F5DB892EA}) (Version: 3.5.20 - NZXT)
    Catalyst Control Center Next Localization BR (HKLM\...\{D99BA8BB-CCA8-204C-1867-E904459A8B73}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization CHS (HKLM\...\{C1EB1702-1520-5BB2-9DED-5827FA12CB86}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization CHT (HKLM\...\{DB27CA77-C209-BFF6-700D-88E3FFAFE63D}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization CS (HKLM\...\{C0BE1CF5-F93D-2641-314B-85E2EB4A9256}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization DA (HKLM\...\{00953243-411E-294C-6B7B-1BEDB868EA39}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization DE (HKLM\...\{724A76E5-F967-25B3-C2CD-36BEBBB10A40}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization EL (HKLM\...\{EEEDD350-B86B-0FD7-CFF2-EF425C9443A7}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization ES (HKLM\...\{DAC228C5-C688-1F91-EEFA-EAA15002639F}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization FI (HKLM\...\{C70FDFA1-4B45-FDCD-708B-CC97C3D8033A}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization FR (HKLM\...\{C2CE1F6B-1866-DB80-2AD6-FD50E056821D}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization HU (HKLM\...\{F937AF00-B63F-E9F4-1B52-4C903E347FCD}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization IT (HKLM\...\{EBC36C18-E293-C3AC-9E8E-BA4BAC09346B}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization JA (HKLM\...\{A0C43CD7-AE8C-B0F3-4031-7565481DA451}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization KO (HKLM\...\{0CEFD072-4694-36C9-333E-C77BFBDC9DAB}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization NL (HKLM\...\{A4525810-2BB6-4989-0E35-6D78826561BB}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization NO (HKLM\...\{83D51B96-9433-356B-EB77-F26F4DB6B622}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization PL (HKLM\...\{DF47369F-DBEA-8AB1-B562-0A815ED0C454}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization RU (HKLM\...\{005A39B4-C104-C892-8E36-F00926DF37B2}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization SV (HKLM\...\{CF858C19-75B3-513C-188F-A87FEF8B4A01}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization TH (HKLM\...\{598E3EC4-B4A4-3CE3-ED42-26D8A29210B5}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization TR (HKLM\...\{BB3FA5E5-3652-4EDD-1229-0487E93EE950}) (Version: 2015.1204.1216.22046 - Advanced Micro Devices, Inc.) Hidden
    Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version:  - Cheat Engine)
    Chuzzle Deluxe (HKLM-x32\...\{79625024-363D-4653-BED2-82619B0D9F51}}_is1) (Version:  - PopCap Games)
    Citra (HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\{39f5eb59-8f46-4a77-9018-48781f452021}) (Version: 1.0.0 - Citra Team)
    Citra Edge (HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\citra) (Version: 0.1.463 - Citra Development Team)
    CloudDrive (HKLM-x32\...\TonidoDrive) (Version:  - )
    Clownfish for Skype (HKLM-x32\...\Clownfish) (Version:  - )
    ComicRack v0.9.177 (HKLM\...\ComicRack) (Version: v0.9.177 - cYo Soft)
    CPUID CPU-Z MSI 1.81 (HKLM\...\CPUID CPU-Z MSI_is1) (Version: 1.81 - CPUID, Inc.)
    Crazybump (remove only) (HKLM-x32\...\Crazybump) (Version:  - )
    Discord Canary (HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\DiscordCanary) (Version: 0.0.177 - Discord Inc.)
    Entity Framework Tools for Visual Studio 2013 (HKLM-x32\...\{08AEF86A-1956-4846-B906-B01350E96E30}) (Version: 12.0.20912.0 - Microsoft Corporation)
    Ext2Fsd 0.62 (HKLM\...\Ext2Fsd_is1) (Version: 0.62 - Matt Wu)
    FaceRig Virtual Video driver version 1.0.1.1000 (HKLM-x32\...\{7D6A1A0F-F57E-4C6B-9331-86CBC7D5C787}_is1) (Version: 1.0.1.1000 - Adoriasoft LLC)
    FFmpeg (Windows) for Audacity version 2.2.2 (HKLM-x32\...\{9C7E31E3-017F-434C-AC40-24431A354A1E}_is1) (Version: 2.2.2 - )
    FileASSASSIN (HKLM-x32\...\FileASSASSIN) (Version: 1.06 - Malwarebytes)
    Flawless Widescreen version 1.0.15 (HKLM-x32\...\{7348D82E-8C68-48FF-BA2D-8C97B5B4B3D8}_is1) (Version: 1.0.15 - Flawless Widescreen)
    Force Feedback Driver for XInput (HKLM\...\{FFB10368-5623-49AA-BD51-B321DB9625CE}) (Version: 6.1.7600.16385 - Masahiko Morii)
    G.SKILL (HKLM-x32\...\{7D0C0C2B-7660-4463-A29A-150C45CAA287}) (Version: 1.00.22 - G.SKILL International Enterprise)
    GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 61.0.3163.100 - Google Inc.)
    Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
    Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
    Hardlock Device Drivers (HKLM-x32\...\Hardlock Device Drivers) (Version:  - )
    IIS 8.0 Express (HKLM\...\{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}) (Version: 8.0.1557 - Microsoft Corporation)
    IIS Express Application Compatibility Database for x64 (HKLM\...\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb) (Version:  - )
    IIS Express Application Compatibility Database for x86 (HKLM\...\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb) (Version:  - )
    IMVU Avatar Chat Software (HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\IMVU Avatar chat client software BETA) (Version:  - )
    Intel® PROSet/Wireless Software (HKLM-x32\...\{440d014b-4444-4533-b96d-2910e1ca2bcf}) (Version: 16.7.0 - Intel Corporation)
    Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
    join.me (HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\JoinMe) (Version: 2.8.1.1469 - LogMeIn, Inc.)
    join.me.launcher (HKLM-x32\...\{910ECE43-4D0D-4FAB-BE1F-6992F0495624}) (Version: 1.0.624.0 - LogMeIn, Inc.) Hidden
    KB4023057 (HKLM\...\{F2D7A08E-6B70-4336-AC4F-C7F765068281}) (Version: 1.0.1.0 - Microsoft Corporation)
    Kodi (HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\Kodi) (Version:  - XBMC-Foundation)
    LG Mobile Driver (HKLM-x32\...\{3F490D0E-3131-438C-BCF9-7549CB88DF41}) (Version: 4.0.2 - LG Electronics)
    LIGHTNING RETURNS FINAL FANTASY XIII (HKLM-x32\...\LIGHTNING RETURNS FINAL FANTASY XIII_is1) (Version:  - )
    Media Preview (HKLM\...\{52AFC3E1-0FAA-4C05-88FF-373911EA68F5}) (Version: 1.4.3.429 - BabelSoft)
    Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
    Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
    Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
    Microsoft Help Viewer 2.1 (HKLM-x32\...\Microsoft Help Viewer 2.1) (Version: 2.1.21005 - Microsoft Corporation)
    Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.8625.2121 - Microsoft Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\OneDriveSetup.exe) (Version: 17.3.7076.1026 - Microsoft Corporation)
    Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{58FED865-4F13-408D-A5BF-996019C4B936}) (Version: 11.1.3000.0 - Microsoft Corporation)
    Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM-x32\...\{1B876496-B3A2-4D22-9B12-B608A3FD4B8B}) (Version: 11.1.2902.0 - Microsoft Corporation)
    Microsoft SQL Server 2012 Data-Tier App Framework  (x64) (HKLM\...\{A6BA243E-85A3-4635-A269-32949C98AC7F}) (Version: 11.1.2902.0 - Microsoft Corporation)
    Microsoft SQL Server 2012 Express LocalDB  (HKLM\...\{6C026A91-640F-4A23-8B68-05D589CC6F18}) (Version: 11.1.3000.0 - Microsoft Corporation)
    Microsoft SQL Server 2012 Management Objects  (HKLM-x32\...\{2F7DBBE6-8EBC-495C-9041-46A772F4E311}) (Version: 11.1.3000.0 - Microsoft Corporation)
    Microsoft SQL Server 2012 Management Objects  (x64) (HKLM\...\{43A5C316-9521-49C3-B9B6-FCE5E1005DF0}) (Version: 11.1.3000.0 - Microsoft Corporation)
    Microsoft SQL Server 2012 Native Client  (HKLM\...\{D411E9C9-CE62-4DBF-9D92-4CB22B750ED5}) (Version: 11.1.3000.0 - Microsoft Corporation)
    Microsoft SQL Server 2012 Transact-SQL ScriptDom  (HKLM\...\{54C5041B-0E91-4E92-8417-AAA12493C790}) (Version: 11.1.3000.0 - Microsoft Corporation)
    Microsoft SQL Server 2012 T-SQL Language Service  (HKLM-x32\...\{04DD7AF4-A6D3-4E30-9BB9-3B3670719234}) (Version: 11.1.3000.0 - Microsoft Corporation)
    Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
    Microsoft SQL Server Data Tools - enu (12.0.30919.1) (HKLM-x32\...\{0D7FCBFB-F478-4D32-901C-83F0BF5A3501}) (Version: 12.0.30919.1 - Microsoft Corporation)
    Microsoft SQL Server Data Tools Build Utilities - enu (12.0.30919.1) (HKLM-x32\...\{6781FF9B-E87D-4A03-9373-A55A288B83FA}) (Version: 12.0.30919.1 - Microsoft Corporation)
    Microsoft SQL Server System CLR Types (HKLM-x32\...\{A47FD1BF-A815-4A76-BE65-53A15BD5D25D}) (Version: 10.50.1600.1 - Microsoft Corporation)
    Microsoft SQL Server System CLR Types (x64) (HKLM\...\{4701DEDE-1888-49E0-BAE5-857875924CA2}) (Version: 10.50.1600.1 - Microsoft Corporation)
    Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{070C38AC-05CE-43DF-9A20-141332F6AB2B}) (Version: 11.1.3366.16 - Microsoft Corporation)
    Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\...\{05FF8209-C4F1-4C77-BC28-791653156D20}) (Version: 11.1.3366.16 - Microsoft Corporation)
    Microsoft Text-to-Speech Engine 4.0 (English) (HKLM-x32\...\MSTTS) (Version:  - )
    Microsoft Tool Web Package : EXCTRLST.EXE (HKLM-x32\...\{B0650E3D-FDCA-4908-B74B-0CC1731BDB93}) (Version: 1.00.0.1 - Microsoft Corporation)
    Microsoft Train Simulator (HKLM-x32\...\Train Simulator 1.0) (Version:  - )
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{86CE1746-9EFF-3C9C-8755-81EA8903AC34}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation)
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation)
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation)
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation)
    Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation)
    Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation)
    Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
    Microsoft Visual F# 2.0 Runtime (HKLM-x32\...\{85467CBC-7A39-33C9-8940-D72D9269B84F}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\{B0A5A6EE-F8BA-48B1-BB32-BAC17E96C2B4}) (Version: 2.0.50728 - Microsoft Corporation)
    Microsoft Visual Studio Express 2013 for Web - ENU (HKLM-x32\...\{3e544097-53d1-4252-98a6-93cc12a6d487}) (Version: 12.0.21005.13 - Microsoft Corporation)
    Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
    Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
    Midtown Madness 2 Vehicle Editor (HKLM-x32\...\ST6UNST #1) (Version:  - )
    Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
    MKVToolNix 8.6.0 (64bit) (HKLM-x32\...\MKVToolNix) (Version: 8.6.0 - Moritz Bunkus)
    Mozilla Firefox 57.0 (x64 en-US) (HKLM\...\Mozilla Firefox 57.0 (x64 en-US)) (Version: 57.0 - Mozilla)
    Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 57.0 - Mozilla)
    MPC-BE x64 1.5.1.2985 (HKLM\...\{FE09AF6D-78B2-4093-B012-FCDAF78693CE}_is1) (Version: 1.5.1.2985 - MPC-BE Team)
    MSI Afterburner 4.4.0 (HKLM-x32\...\Afterburner) (Version: 4.4.0 - MSI Co., LTD)
    MSI DragonEye (HKLM\...\{7116875E-F251-4C33-AB3F-37DE05B15595}_is1) (Version: 0.0.2.6 - MSI)
    MSI Gaming APP (HKLM-x32\...\{E0229316-E73B-484B-B9E0-45098AB38D8C}}_is1) (Version: 6.2.0.30 - MSI)
    MSI Kombustor 3.5.2.1 (64-bit) (HKLM\...\{9598DA62-2AE8-426D-9C86-BEA96AC6721E}_is1) (Version:  - MSI Co., LTD)
    Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.6 - Notepad++ Team)
    Nox APP Player (HKLM-x32\...\Nox) (Version: 5.2.1.0 - Duodian Technology Co. Ltd.)
    NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
    OBS Studio (HKLM-x32\...\OBS Studio) (Version: 0.13.4 - OBS Project)
    Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8625.2121 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8625.2121 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8625.2121 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.8326.2107 - Microsoft Corporation) Hidden
    OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
    openBVE (HKLM-x32\...\openBVE) (Version:  - )
    Oracle VM VirtualBox 5.0.10 (HKLM\...\{F6E922CF-068D-4AFC-8DBF-4636B84AF0A5}) (Version: 5.0.10 - Oracle Corporation)
    paint.net (HKLM\...\{DADC2AF6-DC9F-4BCF-BFCE-DCEC16EF507C}) (Version: 4.0.9 - dotPDN LLC)
    PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2-r5875) (Version:  - )
    PeerBlock 1.2 (r693) (HKLM\...\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.2.0.693 - PeerBlock, LLC)
    PowerISO (HKLM-x32\...\PowerISO) (Version: 6.3 - Power Software Ltd)
    Prerequisites for SSDT  (HKLM-x32\...\{35C1D9D6-87C0-46A3-B1B4-EDBCC063221C}) (Version: 11.1.3000.0 - Microsoft Corporation)
    Python 3.1.3 (HKLM-x32\...\{f719d8a6-46fc-4d71-94c6-ffd17a8c9f35}) (Version: 3.1.3150 - Python Software Foundation)
    qBittorrent 3.3.4 (HKLM-x32\...\qBittorrent) (Version: 3.3.4 - The qBittorrent project)
    QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8237 - Realtek Semiconductor Corp.)
    RealWorld Cursor Editor (HKLM-x32\...\{25A344BB-378D-4E51-9A39-780755012B2D}) (Version: 13.1.0 - RealWorld Graphics)
    Remotr version 1.3.1438 (HKLM-x32\...\Remotr_is1) (Version: 1.3.1438 - RemoteMyApp sp. z o.o.)
    Revo Uninstaller 2.0.4 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.4 - VS Revo Group, Ltd.)
    Rigs of Rods version 0.4.7.0 (HKLM-x32\...\{312BE7CD-13FB-4B37-8B25-C7011FC19C81}}_is1) (Version: 0.4.7.0 - rigsofrods.org)
    RivaTuner Statistics Server 7.0.0 (HKLM-x32\...\RTSS) (Version: 7.0.0 - Unwinder)
    ROBLOX Player for Ryan Evan Ramos (HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
    ROBLOX Studio for Ryan Evan Ramos (HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}) (Version:  - ROBLOX Corporation)
    Rosetta Stone Version 3 (HKLM-x32\...\{99011A6E-5200-11DE-BDB8-7ACD56D89593}) (Version: 3.4.5.0 - Rosetta Stone Ltd.)
    SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
    SearchAwesome (HKLM\...\403452eb8042e065f60c58f400f5c873) (Version: 13.14.1.73 (i1.0) - SearchAwesome) <==== ATTENTION
    Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.151 - Skype Technologies S.A.)
    SlimDX Runtime .NET 2.0 (January 2012) (HKLM-x32\...\{014A2868-BE56-4888-A16C-693989B8F153}) (Version: 2.0.13.43 - SlimDX Group)
    SoundWire Server version 2.1.2 (HKLM-x32\...\{E15658BC-7742-4397-999F-98B1BD11B784}_is1) (Version: 2.1.2 - GeorgieLabs)
    Speakonia (HKLM-x32\...\Speakonia_is1) (Version: 1.0.3.5 - CFS-Technologies)
    Speedtest by Ookla (HKLM\...\{4CB99888-11EE-4B49-BC91-447FF7FCD975}) (Version: 1.0.14.001 - Ookla)
    Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
    Steam ROM Manager 2.2.0-3 (only current user) (HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\ba4216a3-f688-5e5a-8b4c-b3693a0d7d6a) (Version: 2.2.0-3 - FrogTheFrog)
    swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
    Team Explorer for Microsoft Visual Studio 2013 (HKLM-x32\...\{C9E7751E-88ED-36CF-B610-71A1D262E906}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
    TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.0.3711 Beta - TeamViewer)
    TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version:  - TechPowerUp)
    Tonido 7.83.0.27601 (HKLM-x32\...\{E9355E4F-CA53-42EB-9392-2F288E3CD3F9}_is1) (Version:  - CodeLathe LLC)
    Toontown Rewritten (HKLM-x32\...\Toontown Rewritten) (Version: 00.00.00.00 - The TTR Team)
    TortoiseSVN 1.9.0.26652 (64 bit) (HKLM\...\{C35C94DD-E13F-4504-BB97-0CE2D9A0ED73}) (Version: 1.9.26652 - TortoiseSVN)
    Trainz Simulator 12 (HKLM-x32\...\Trainz Simulator 12_is1) (Version:  - )
    Unity Web Player (HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\UnityWebPlayer) (Version: 5.0.3f2 - Unity Technologies ApS)
    Unlocker (HKLM\...\{5993C960-4E90-4A00-A2F3-D0C4020A6992}) (Version: 1.9.2 - ajua Custom Installers)
    Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
    UpdateAssistant (HKLM-x32\...\{4E67FF7F-C24E-4279-9AB2-C26D57B53742}) (Version: 1.3.0.0 - Microsoft Corporation) Hidden
    UxStyle (HKLM\...\{86D24646-DAF6-4F5E-BCAD-CF7EF8E362E1}) (Version: 0.2.3.0 - The Within Network, LLC) Hidden
    UxStyle (HKLM-x32\...\{05560347-3a9b-4644-a8ed-8b64cc947189}) (Version: 0.2.3.0 - The Within Network, LLC)
    Vanity Pack version 2.0.0b10 (HKLM-x32\...\VanityPack_is1) (Version: 2.0.0b10 - )
    VirtualDJ 8 (HKLM-x32\...\{36A4C443-6C3A-4FF7-AFEC-7CC5F4E50E68}) (Version: 8.2.3936.0 - Atomix Productions)
    Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{6DA2B636-698A-3294-BF4A-B5E11B238CDD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
    Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
    Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
    Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
    Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
    Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{14866AAD-1F23-39AC-A62B-7091ED1ADE64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
    Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
    Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    VTFEdit 1.3.3 (HKLM\...\VTFEdit_is1) (Version:  - Neil Jedrzejewski & Ryan Gregg)
    Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1) (Version: 1.0.3.1 - LunarG, Inc.) Hidden
    Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1-8) (Version: 1.0.3.1 - LunarG, Inc.)
    Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.)
    Vulkan Run Time Libraries 1.0.51.0 (HKLM\...\VulkanRT1.0.51.0) (Version: 1.0.51.0 - LunarG, Inc.)
    Vulkan Run Time Libraries 1.0.54.0 (HKLM\...\VulkanRT1.0.54.0) (Version: 1.0.54.0 - LunarG, Inc.) Hidden
    Vulkan Run Time Libraries 1.0.54.0 (HKLM\...\VulkanRT1.0.54.0-3) (Version: 1.0.54.0 - LunarG, Inc.)
    Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
    Watery Desktop 3D Live Wallpaper and Screensaver (HKLM\...\Watery Desktop 3D_is1) (Version: 4.07 - PUSH Entertainment)
    WebM Project Directshow Filters (HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\webmdshow) (Version:  - )
    WiFi共享精灵 (HKLM-x32\...\WiFiShare) (Version: 4.2015.1225.001 - TXWL,Inc)
    Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22256 - Microsoft Corporation)
    Windows Driver Package - Broadcom Corporation (bcbtums) Bluetooth  (07/14/2015 12.0.1.658) (HKLM\...\BABE4E18F2E0DA329C1139E5584082BBE6F64E5F) (Version: 07/14/2015 12.0.1.658 - Broadcom Corporation)
    WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
    WinRAR 5.31 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.1 - win.rar GmbH)
    Wireshark 2.0.1 (64-bit) (HKLM-x32\...\Wireshark) (Version: 2.0.1 - The Wireshark developer community, hxxps://www.wireshark.org)
    Xilisoft Video Converter Ultimate (HKLM-x32\...\Xilisoft Video Converter Ultimate) (Version: 7.8.13.20160125 - Xilisoft)
    Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\...\Open Codecs) (Version: 0.85.17777 - Xiph.Org)
    
    ==================== Custom CLSID (Whitelisted): ==========================
    
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
    
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{083f5ae0-2b0a-11dd-bd0b-0800200c9a66}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{0B7AD8D3-094A-44DE-A348-83C6C3FA347C}\InprocServer32 -> C:\Users\Ryan Evan Ramos\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Clipboarder.gadget\Release\Clipboarder64.dll (Helmut Buhler)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{0E7BE950-4ACC-47CB-834B-41A8B96BBFF9}\InprocServer32 -> C:\Users\Ryan Evan Ramos\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Sidebar7.gadget\Release\Sidebar7.64.dll (Helmut Buhler)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{144DF3B2-2402-47AE-9583-5A045929A8D4}\InprocServer32 -> C:\Users\Ryan Evan Ramos\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{5b55a44a-d008-49aa-9234-86fb7709bc0a}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{89BB4535-5AE9-43a0-89C5-19B4697E5C5E}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{91A41FCC-BC02-42D8-A36E-0D27FF9BFFC8}\InprocServer32 -> C:\Users\Ryan Evan Ramos\AppData\Local\Google\Update\1.3.33.7\psuser_64.dll (Google Inc.)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{9cb364cc-1a94-4d91-9cc5-d298ca5f7583}\InprocServer32 -> C:\WINDOWS\system32\dfshim.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{A4FEF2CE-E494-419e-ABCC-B2E993FB6BC0}\InprocServer32 -> C:\Users\Ryan Evan Ramos\AppData\Local\Microsoft\Windows Sidebar\Gadgets\GlassyNetworkMonitor.gadget\Release\ProcessMonitor64.dll (TODO: <Firmenname>)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Ryan Evan Ramos\AppData\Local\Roblox\Versions\version-b7bf51c941dd400f\RobloxProxy64.dll (ROBLOX Corporation)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Ryan Evan Ramos\AppData\Local\Google\Update\1.3.33.7\psuser_64.dll (Google Inc.)
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll => No File
    CustomCLSID: HKU\S-1-5-21-354301492-1375950521-280439656-1001_Classes\CLSID\{FFB10360-5623-49AA-BD51-B321DB9625CE}\InprocServer32 -> C:\Program Files\Force Feedback Driver for XInput\x64\xiffd.dll (Masahiko Morii)
    ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Ryan Evan Ramos\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
    ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Ryan Evan Ramos\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
    ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Ryan Evan Ramos\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
    ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-13] (AVAST Software)
    ShellIconOverlayIdentifiers: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\WINDOWS\system32\CbFsMntNtf3.dll [2011-09-19] (EldoS Corporation)
    ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Ryan Evan Ramos\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
    ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Ryan Evan Ramos\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
    ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Ryan Evan Ramos\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
    ShellIconOverlayIdentifiers-x32: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers-x32: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers-x32: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers-x32: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers-x32: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers-x32: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers-x32: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers-x32: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers-x32: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
    ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\WINDOWS\system32\CbFsMntNtf3.dll [2011-09-19] (EldoS Corporation)
    ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-06-14] (Igor Pavlov)
    ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2015-04-15] ()
    ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-13] (AVAST Software)
    ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Ryan Evan Ramos\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
    ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2015-06-07] (Power Software Ltd)
    ContextMenuHandlers1: [TortoiseSVN] -> {30351349-7B7D-4FCC-81B4-1E394CA267EB} => C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll [2015-08-03] (hxxp://tortoisesvn.net)
    ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-01-03] (Alexander Roshal)
    ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-01-03] (Alexander Roshal)
    ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Ryan Evan Ramos\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
    ContextMenuHandlers2: [TortoiseSVN] -> {30351349-7B7D-4FCC-81B4-1E394CA267EB} => C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll [2015-08-03] (hxxp://tortoisesvn.net)
    ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-13] (AVAST Software)
    ContextMenuHandlers3-x32: [FAExt] -> {05672D66-9736-42F5-8BEB-FA1DD3CA51C4} => C:\Program Files (x86)\FileASSASSIN\FileASSASSINExt.dll [2007-03-30] (Malwarebytes)
    ContextMenuHandlers3-x32: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Ryan Evan Ramos\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
    ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-06-14] (Igor Pavlov)
    ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Ryan Evan Ramos\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
    ContextMenuHandlers4: [MPCBEShellExt] -> {A2CF4243-6525-4764-B3F5-2FCDE2F47989} => C:\Program Files\MPC-BE x64\MPCBEShellExt64.dll [2017-10-10] (MPC-BE Team)
    ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2015-06-07] (Power Software Ltd)
    ContextMenuHandlers4: [TortoiseSVN] -> {30351349-7B7D-4FCC-81B4-1E394CA267EB} => C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll [2015-08-03] (hxxp://tortoisesvn.net)
    ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2017-10-26] (Advanced Micro Devices, Inc.)
    ContextMenuHandlers5: [TortoiseSVN] -> {30351349-7B7D-4FCC-81B4-1E394CA267EB} => C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll [2015-08-03] (hxxp://tortoisesvn.net)
    ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-06-14] (Igor Pavlov)
    ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-13] (AVAST Software)
    ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2015-06-07] (Power Software Ltd)
    ContextMenuHandlers6: [TortoiseSVN] -> {30351349-7B7D-4FCC-81B4-1E394CA267EB} => C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll [2015-08-03] (hxxp://tortoisesvn.net)
    ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-01-03] (Alexander Roshal)
    ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-01-03] (Alexander Roshal)
    ContextMenuHandlers6_S-1-5-21-354301492-1375950521-280439656-1001: [InventorMenu] -> {6FDE7A70-351B-11d6-988B-0010B57A8BB7} =>  -> No File
    FolderExtensions: [] -> {27DD0F8B-3E0E-4ADC-A78A-66047E71ADC5} => C:\Users\Ryan Evan Ramos\Documents\programs\OldNewExplorer\OldNewExplorer64.dll [2015-08-09] (StartIsBack: real start menu for Windows 8 and Windows 10)
    
    ==================== Scheduled Tasks (Whitelisted) =============
    
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
    
    Task: {0061AD93-653F-4C91-AD08-B5196211FF63} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {07D20EEE-BC72-4130-958B-F9D0E66187E3} - System32\Tasks\Nahimic2Svc32Run => C:\Program Files\Nahimic\Nahimic2\UserInterface\Nahimic2Svc32.exe
    Task: {0936406B-62C2-4636-8633-8DAB1CF93E66} - System32\Tasks\MSIOSDx86_Host => C:\Program Files\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe [2017-08-15] (Micro-Star INT'L CO., LTD.)
    Task: {0A65195C-208E-4AF7-8B0A-FD91B1DB410D} - System32\Tasks\ASUS\ASUS AI Suite II Execute => C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
    Task: {1572F5D6-6FB6-4484-9B44-190B67E64E2C} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-01-29] (Oracle Corporation)
    Task: {2B54E91A-ECBC-4F69-8912-1BC73DE49570} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {2DFDFBF2-9D7B-4096-A9B3-45F6C1C163F9} - System32\Tasks\CAM => C:\Program Files (x86)\NZXT\CAM\CAM_V3.exe [2017-11-03] ()
    Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
    Task: {3722B1E1-C6BA-4BC9-8B0D-9E17C3B4F494} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {41681436-2193-4286-9672-4CDF2DC5FA66} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
    Task: {43216309-8B9C-413B-B3A2-BA9A4934BD2D} - System32\Tasks\{A725609A-F2B5-4272-A808-0289609E5540} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxp://ui.skype.com/ui/0/7.10.80.101/en/abandoninstall?page=tsProgressBar
    Task: {43B5773C-9903-4E4C-9467-DD5BFE8280B7} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-11-13] (AVAST Software)
    Task: {44155145-4AE9-4A4B-B9D1-247746396DC2} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-10-31] (Microsoft Corporation)
    Task: {4B179B16-E928-44A6-91E8-802C3D04E992} - System32\Tasks\f016e3968e92f2517ad9ac946c9a853b => powershell.exe -NoProfile -NoLogo -NonInteractive -ExecutionPolicy Bypass -File "C:\WINDOWS\f016e3968e92f2517ad9ac946c9a853b.ps1" <==== ATTENTION
    Task: {5392C411-CD15-4AB2-A11F-667F2572DBF6} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
    Task: {61BE05D5-8204-4648-ACDA-2F75869CBC05} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-11-07] (Microsoft Corporation)
    Task: {64D002AB-7504-4E15-AC61-DBD497FFCAAB} - System32\Tasks\{C7DA4B05-EC85-4E1F-844D-7E485B63C2C6} => C:\WINDOWS\system32\pcalua.exe -a "C:\Users\Ryan Evan Ramos\Downloads\mm2ve2.exe" -d "C:\Users\Ryan Evan Ramos\Downloads"
    Task: {654B31CC-44EA-49F4-BD33-C6FA84345668} - System32\Tasks\ASUS\ASUS DigiPowerControl Help => C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ Power Control\PowerControlHelp.exe
    Task: {69F9BED4-6636-44A8-A6A5-AF76009FE70B} - System32\Tasks\Nahimic2Svc64Run => C:\Program Files\Nahimic\Nahimic2\UserInterface\x64\Nahimic2Svc64.exe
    Task: {70988248-6857-46E6-B34A-B7E096F4B122} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
    Task: {74383E7F-1912-4716-B2C4-B9611EB666A8} - System32\Tasks\ASUS\Easy Update => C:\Program Files (x86)\ASUS\AI Suite II\EasyUpdate\EzUpdt.exe
    Task: {744F6F43-7048-4243-9378-A25257C947C3} - System32\Tasks\NahimicVRSvc64Run => C:\Program Files\Nahimic\Nahimic VR\Foundation\x64\NahimicVRSvc64.exe
    Task: {764020BD-EC6E-4FB3-ABDC-62135BB49076} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2017-10-26] (Advanced Micro Devices, Inc.)
    Task: {78503B89-6647-48C8-AE5E-1480713D9140} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    Task: {7B321EFF-3968-40CE-B537-C93CD8ADACCC} - System32\Tasks\Nahimic2UILauncherRun => C:\Program Files\Nahimic\Nahimic2\UserInterface\Nahimic2UILauncher.exe
    Task: {7BCCD407-4D96-45D2-A739-C00EC2676F45} - System32\Tasks\{AAF7AD4D-9A1A-452A-ACFA-C52785909272} => C:\WINDOWS\system32\pcalua.exe -a E:\AutoRun.exe -d E:\
    Task: {86830AA9-95EB-4C87-9BE0-172695B35C52} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    Task: {8CF5569A-CD13-49D3-9EDC-EE3649B6ACCA} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-354301492-1375950521-280439656-1001Core => C:\Users\Ryan Evan Ramos\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-21] (Google Inc.)
    Task: {8D8C1954-079C-4634-BEBB-FAEB9231E028} - System32\Tasks\{E339F5C1-1CAA-4CFB-B2A1-DE60D516C4B4} => C:\WINDOWS\system32\pcalua.exe -a "C:\Users\Ryan Evan Ramos\Desktop\MIDWAY ARCADE\Autoplay.exe" -d "C:\Users\Ryan Evan Ramos\Desktop\MIDWAY ARCADE"
    Task: {93DDF75F-7360-4349-A5C1-8B29923C964C} - System32\Tasks\Aero Glass => C:\AeroGlass\aerohost.exe [2017-09-10] (Big Muscle)
    Task: {99D48123-1F14-4640-BA22-526E8253133C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    Task: {9B877AE5-56C0-4813-B665-C4291EE02254} - System32\Tasks\ASUS\USB 3.0 Boost Service => C:\Program Files (x86)\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr.exe
    Task: {A0532433-0670-471A-9879-B4732F7F7DF0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {A226FF61-D75A-4B97-A3CB-8BC1493FC18D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-26] (Google Inc.)
    Task: {A2767268-4496-40BD-90D6-C25CE7B9AA77} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {A3632715-C2B9-4AF2-B7E0-9584B96D3498} - System32\Tasks\Avast TUNEUP Update => C:\Program Files (x86)\AVAST Software\Avast Cleanup\TUNEUpdate.exe [2017-11-01] (AVAST Software)
    Task: {A9A5D637-A705-4745-B830-81CC13454F13} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-10-02] ()
    Task: {A9B623BF-BA7A-4220-8114-906755F821BC} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: {AC02C2C6-5CB5-4AE9-91BC-89C02B5FF19F} - System32\Tasks\MSISW_Host => C:\WINDOWS\SysWOW64\muachost.exe [2015-08-18] (MSI)
    Task: {B5930934-8C0E-4E24-A2BD-7F07E4433A4D} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2017-10-31] ()
    Task: {B6556D05-E8B1-426A-9482-530E54267FA6} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-10-31] (Microsoft Corporation)
    Task: {BC68DFD9-8FE9-453B-8BE6-68C2A55F33B4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-354301492-1375950521-280439656-1001UA => C:\Users\Ryan Evan Ramos\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-21] (Google Inc.)
    Task: {BEB80A19-167D-4405-B51E-0681578C0F37} - System32\Tasks\403452eb8042e065f60c58f400f5c873 => sc start 403452eb8042e065f60c58f400f5c873 <==== ATTENTION
    Task: {C36F8C08-7173-45F1-AB29-58BAA20E5634} - System32\Tasks\{6235C2A1-08A9-43B6-B778-C00BC5A30EDA} => C:\WINDOWS\system32\pcalua.exe -a E:\AutoRun.exe -d E:\
    Task: {CCD21C12-0693-4DE1-9EB5-C5072721F178} - System32\Tasks\NahimicVRSvc32Run => C:\Program Files\Nahimic\Nahimic VR\Foundation\NahimicVRSvc32.exe
    Task: {D27842A1-37A7-48E4-92FD-B9D09DEB796E} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-10-02] ()
    Task: {D763F5E6-0DB1-4EAA-8035-4AE889408BD8} - System32\Tasks\{7E1889A0-E2DC-4090-80D4-2CEC20069AF1} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxp://ui.skype.com/ui/0/7.10.80.101/en/abandoninstall?page=tsProgressBar
    Task: {D80361EF-2ED3-439D-A7B6-8391832DA7AE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-26] (Google Inc.)
    Task: {E65EE6A3-9FE5-4EAC-AA4A-1740D41766D3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-11-07] (Microsoft Corporation)
    Task: {E9BB27F5-27A7-422B-AA30-A1934612481B} - System32\Tasks\RTSS => C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe [2017-10-31] ()
    Task: {EBA47ECE-9E40-4FCB-9C1C-E0F8DC462449} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)
    Task: {EE71C30D-0FFB-48AC-9809-97498F56A3EB} - System32\Tasks\PCMeter\Startup => C:\Users\Ryan Evan Ramos\Desktop\PCMeterV4\PCMeterV0.4.exe
    Task: {F1638FB1-12F3-46C5-BCC3-59D157C7542D} - System32\Tasks\Avast Driver Updater Startup => C:\Program Files (x86)\Avast Driver Updater\Avast Driver Updater.exe [2017-09-27] (AVAST Software)
    Task: {F1F90CB2-9FF5-4277-9D5C-99DE479CAAF2} - System32\Tasks\MSIOSDx64_Host => C:\Program Files\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe [2017-08-15] (Micro-Star INT'L CO., LTD.)
    Task: {F8A8E538-6416-445C-8377-71697F494852} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-ryanevan4@hotmail.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-08-05] (Adobe Systems Incorporated)
    Task: {FA11F16C-5E99-44D4-A8C3-D6DB0F916FBA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-25] (Adobe Systems Incorporated)
    Task: {FB560303-D933-4D30-B121-2EA1E43254B5} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {FDE3A745-556B-43BE-83E0-BD52A3966835} - System32\Tasks\MSIGH_Host => C:\Program Files\Gaming APP\GamingHotkey.exe [2017-06-23] (Micro-Star INT'L CO., LTD.)
    
    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
    
    Task: C:\WINDOWS\Tasks\Avast Driver Updater Startup.job => C:\Program Files (x86)\Avast Driver Updater\Avast Driver Updater.exe
    Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
    
    ==================== Shortcuts & WMI ========================
    
    (The entries could be listed to be restored or removed.)
    
    
    Shortcut: C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ\Online Help.lnk -> hxxp://www.virtualdj.com/wiki
    Shortcut: C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ\http://www.virtualdj.com.lnk -> hxxp://www.virtualdj.com
    
    ShortcutWithArgument: C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic
    
    ==================== Loaded Modules (Whitelisted) ==============
    
    2017-09-29 08:41 - 2017-09-29 08:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
    2014-11-09 06:37 - 2017-10-31 01:07 - 000444008 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks64.dll
    2017-10-31 04:05 - 2017-10-31 04:05 - 000722216 _____ () C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
    2017-10-31 01:07 - 2017-10-31 01:07 - 000252008 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
    2017-11-07 09:46 - 2016-06-14 16:35 - 000187392 _____ () C:\Program Files\Gaming APP\OSD\x64\D3D11FontDraw.dll
    2015-08-03 19:59 - 2015-08-03 19:59 - 000088576 _____ () C:\Program Files\TortoiseSVN\bin\libsasl.dll
    2016-03-15 03:25 - 2017-11-07 09:36 - 008931496 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
    2017-10-07 08:37 - 2016-11-24 04:11 - 000114176 _____ () C:\Program Files\PUSH Entertainment\Watery Desktop 3D\pushhelper.dll
    2017-09-29 08:42 - 2017-09-29 09:42 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
    2017-09-29 08:42 - 2017-09-29 09:42 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
    2017-06-05 04:34 - 2017-06-05 04:34 - 000015360 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.DLL
    2017-06-05 04:34 - 2017-06-05 04:34 - 002519040 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
    2017-11-03 10:45 - 2017-11-03 10:45 - 007430256 _____ () C:\Program Files (x86)\NZXT\CAM\CAM_V3.exe
    2017-10-07 08:37 - 2016-11-24 04:11 - 000088064 _____ () C:\Program Files\PUSH Entertainment\Watery Desktop 3D\pushhelper.exe
    2017-10-31 01:07 - 2017-10-31 01:07 - 000035432 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
    2017-10-31 01:07 - 2017-10-31 01:07 - 000061032 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe
    2017-11-11 19:21 - 2017-11-11 19:22 - 000087552 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.487.0_x64__kzf8qxf38zg5c\SkypeHost.exe
    2017-11-11 19:21 - 2017-11-11 19:22 - 000206336 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.487.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
    2017-11-11 19:21 - 2017-11-11 19:23 - 025461760 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.487.0_x64__kzf8qxf38zg5c\SkyWrap.dll
    2017-11-07 09:03 - 2017-11-07 09:24 - 002552832 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.487.0_x64__kzf8qxf38zg5c\skypert.dll
    2017-11-11 19:21 - 2017-11-11 19:21 - 000685056 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.487.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll
    2017-11-11 19:21 - 2017-11-11 19:22 - 000135680 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.487.0_x64__kzf8qxf38zg5c\SkypeHost.Proxies.dll
    2017-11-07 09:46 - 2016-06-14 16:35 - 000163328 _____ () C:\Program Files\Gaming APP\OSD\x86\D3D11FontDraw.dll
    2014-11-09 06:37 - 2017-10-31 01:07 - 000410728 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks.dll
    2017-10-29 15:00 - 2017-10-29 15:00 - 000056832 _____ () C:\Program Files (x86)\MSI Afterburner\RTFC.dll
    2017-10-29 15:01 - 2017-10-29 15:01 - 000357888 _____ () C:\Program Files (x86)\MSI Afterburner\RTUI.dll
    2017-10-29 15:01 - 2017-10-29 15:01 - 000565760 _____ () C:\Program Files (x86)\MSI Afterburner\RTHAL.dll
    2017-10-29 15:01 - 2017-10-29 15:01 - 000232448 _____ () C:\Program Files (x86)\MSI Afterburner\RTCore.dll
    2017-10-29 15:01 - 2017-10-29 15:01 - 000071680 _____ () C:\Program Files (x86)\MSI Afterburner\RTMUI.dll
    2017-10-10 13:52 - 2017-10-10 13:52 - 000353792 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTUI.dll
    2017-10-10 13:52 - 2017-10-10 13:52 - 000071680 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTMUI.dll
    2017-10-10 13:51 - 2017-10-10 13:51 - 000055808 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTFC.dll
    2017-11-07 09:45 - 2017-08-02 14:48 - 000237568 _____ () C:\Program Files\Gaming APP\LEDControl.dll
    2017-07-13 18:13 - 2017-02-27 19:52 - 000076408 _____ () C:\Program Files (x86)\Remotr\General.dll
    2017-07-13 18:13 - 2017-02-27 19:52 - 000057976 _____ () C:\Program Files (x86)\Remotr\Audio.dll
    2017-11-13 19:39 - 2017-11-13 19:39 - 000167096 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
    2017-11-13 19:39 - 2017-11-13 19:39 - 000059040 _____ () C:\Program Files\AVAST Software\Avast\module_lifetime.dll
    2017-11-13 19:39 - 2017-11-13 19:39 - 067109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
    2017-11-13 19:39 - 2017-11-13 19:39 - 000237808 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
    2017-11-13 19:39 - 2017-11-13 19:39 - 000244584 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
    2017-11-13 19:39 - 2017-11-13 19:39 - 000235816 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
    2017-10-18 17:31 - 2017-10-18 17:31 - 000282112 _____ () C:\Program Files (x86)\NZXT\CAM\GSyncLib.dll
    2017-10-24 14:34 - 2017-11-14 17:29 - 000078848 _____ () C:\Program Files (x86)\NZXT\CAM\AMDHelper.dll
    2017-11-14 12:57 - 2016-09-12 14:53 - 048936448 _____ () C:\Program Files (x86)\AVAST Software\Avast Cleanup\libcef.dll
    2017-11-14 09:06 - 2017-11-13 21:45 - 001718264 _____ () C:\Users\Ryan Evan Ramos\AppData\Local\DiscordCanary\app-0.0.177\ffmpeg.dll
    2017-11-14 09:07 - 2017-11-14 09:07 - 001604088 _____ () \\?\C:\Users\Ryan Evan Ramos\AppData\Roaming\discordcanary\0.0.177\modules\discord_toaster\discord_toaster.node
    2015-05-08 00:08 - 2015-05-08 00:08 - 000151552 _____ () C:\Program Files\DroidCam\lib\DroidCam.dll
    2015-05-08 00:08 - 2015-05-08 00:08 - 000081920 _____ () C:\Program Files\DroidCam\lib\DroidCamFilter.ax
    2015-05-08 00:14 - 2015-05-08 00:14 - 000086016 _____ () C:\Program Files\DroidCam\lib\DroidCamFilter240p.ax
    2017-11-14 09:06 - 2017-11-13 21:45 - 002533368 _____ () C:\Users\Ryan Evan Ramos\AppData\Local\DiscordCanary\app-0.0.177\libglesv2.dll
    2017-11-14 09:06 - 2017-11-13 21:45 - 000031736 _____ () C:\Users\Ryan Evan Ramos\AppData\Local\DiscordCanary\app-0.0.177\libegl.dll
    2017-11-14 09:07 - 2017-11-14 09:07 - 009748472 _____ () \\?\C:\Users\Ryan Evan Ramos\AppData\Roaming\discordcanary\0.0.177\modules\discord_voice\discord_voice.node
    2017-11-14 09:07 - 2017-11-14 09:07 - 001472504 _____ () \\?\C:\Users\Ryan Evan Ramos\AppData\Roaming\discordcanary\0.0.177\modules\discord_utils\discord_utils.node
    2017-11-14 09:07 - 2017-11-14 09:07 - 000509432 _____ () \\?\C:\Users\Ryan Evan Ramos\AppData\Roaming\discordcanary\0.0.177\modules\discord_erlpack\discord_erlpack.node
    2017-11-14 09:07 - 2017-11-14 09:07 - 002658296 _____ () \\?\C:\Users\Ryan Evan Ramos\AppData\Roaming\discordcanary\0.0.177\modules\discord_rpc\discord_rpc.node
    2017-11-14 09:08 - 2017-11-14 09:08 - 002693112 _____ () \\?\C:\Users\Ryan Evan Ramos\AppData\Roaming\discordcanary\0.0.177\modules\discord_contact_import\discord_contact_import.node
    2015-06-30 12:39 - 2017-09-09 14:25 - 000688416 _____ () C:\Program Files (x86)\Steam\SDL2.dll
    2015-06-30 12:39 - 2016-08-31 20:02 - 004969248 _____ () C:\Program Files (x86)\Steam\v8.dll
    2015-06-30 12:39 - 2017-10-30 22:22 - 002546976 _____ () C:\Program Files (x86)\Steam\video.dll
    2015-06-30 12:39 - 2016-08-31 20:02 - 001195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
    2015-06-30 12:39 - 2016-01-27 02:49 - 000442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
    2015-06-30 12:39 - 2016-08-31 20:02 - 001563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
    2015-06-30 12:39 - 2016-01-27 02:49 - 002549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
    2015-06-30 12:39 - 2016-01-27 02:49 - 000491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
    2015-06-30 12:39 - 2016-01-27 02:49 - 000332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
    2015-06-30 12:39 - 2016-01-27 02:49 - 000485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
    2015-06-30 12:39 - 2017-10-30 22:22 - 000901408 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
    2016-03-26 12:32 - 2016-07-04 17:17 - 000266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
    2017-07-18 10:35 - 2017-09-06 21:04 - 000678400 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
    2017-07-18 10:35 - 2017-08-16 17:28 - 073130272 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
    2015-06-30 12:39 - 2015-09-24 18:52 - 000119208 _____ () C:\Program Files (x86)\Steam\winh264.dll
    
    ==================== Alternate Data Streams (Whitelisted) =========
    
    (If an entry is included in the fixlist, only the ADS will be removed.)
    
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\etxktujq.sys:changelist [962]
    AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51 [94]
    AlternateDataStreams: C:\ProgramData\TEMP:6B50FDB5 [141]
    
    ==================== Safe Mode (Whitelisted) ===================
    
    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
    
    
    ==================== Association (Whitelisted) ===============
    
    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
    
    
    ==================== Internet Explorer trusted/restricted ===============
    
    (If an entry is included in the fixlist, it will be removed from the registry.)
    
    IE restricted site: HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\skype.com -> hxxps://apps.skype.com
    
    ==================== Hosts content: ==========================
    
    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
    
    2017-07-11 09:35 - 2017-11-13 16:29 - 000001255 _____ C:\WINDOWS\system32\Drivers\etc\hosts
    
    127.0.0.1 cpm.paneladmin.pro
    127.0.0.1 publisher.hmdiadmingate.xyz
    127.0.0.1 hmdicrewtracksystem.xyz
    127.0.0.1 linkmate.space
    127.0.0.1 space1.adminpressure.space
    127.0.0.1 trackpressure.website
    127.0.0.1 doctorlink.space
    127.0.0.1 plugpackdownload.net
    127.0.0.1 texttotalk.org
    127.0.0.1 gambling577.xyz
    127.0.0.1 htagdownload.space
    127.0.0.1 mybcnmonetize.com
    127.0.0.1 360devtraking.website
    127.0.0.1 dscdn.pw
    127.0.0.1 beautifllink.xyz
    
    ==================== Other Areas ============================
    
    (Currently there is no automatic fix for this section.)
    
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Ryan Evan Ramos\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
    DNS Servers: 192.168.42.129 - 10.0.0.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
    Windows Firewall is enabled.
    
    ==================== MSCONFIG/TASK MANAGER disabled items ==
    
    MSCONFIG\Services: 403452eb8042e065f60c58f400f5c873 => 2
    MSCONFIG\Services: AMD FUEL Service => 2
    MSCONFIG\Services: FlexNet Licensing Service 64 => 3
    MSCONFIG\Services: hasplms => 2
    MSCONFIG\Services: IEEtwCollectorService => 3
    MSCONFIG\Services: mi-raysat_3dsmax2016_64 => 3
    MSCONFIG\Services: mitsijm2016 => 2
    MSCONFIG\Services: MonectServerService => 2
    MSCONFIG\Services: txcoresrv => 2
    HKLM\...\StartupApproved\StartupFolder: => "SoftEther VPN Client Manager Startup.lnk"
    HKLM\...\StartupApproved\StartupFolder: => "Network Server.lnk"
    HKLM\...\StartupApproved\StartupFolder: => "Virtual Router Manager.lnk"
    HKLM\...\StartupApproved\StartupFolder: => "FAH.lnk"
    HKLM\...\StartupApproved\StartupFolder: => "Update Notifier.lnk"
    HKLM\...\StartupApproved\StartupFolder: => "WinZip Preloader.lnk"
    HKLM\...\StartupApproved\Run: => "SoftEther VPN Client UI Helper"
    HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
    HKLM\...\StartupApproved\Run: => "StartCN"
    HKLM\...\StartupApproved\Run: => "NahimicVRSvc64"
    HKLM\...\StartupApproved\Run: => "NahimicVRSvc32"
    HKLM\...\StartupApproved\Run32: => "ASUS AiChargerPlus Execute"
    HKLM\...\StartupApproved\Run32: => "StartCCC"
    HKLM\...\StartupApproved\Run32: => "APSDaemon"
    HKLM\...\StartupApproved\Run32: => "Ext2 Volume Manager"
    HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
    HKLM\...\StartupApproved\Run32: => "QuickTime Task"
    HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
    HKLM\...\StartupApproved\Run32: => "PWRISOVM.EXE"
    HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
    HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
    HKLM\...\StartupApproved\Run32: => "iTunesHelper"
    HKLM\...\StartupApproved\Run32: => "Raptr"
    HKLM\...\StartupApproved\Run32: => "MSIRegister"
    HKLM\...\StartupApproved\Run32: => "G.SKILL RIPJAWS KM780 RGB"
    HKLM\...\StartupApproved\Run32: => "G.SKILL RIPJAWS MX780"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\StartupFolder: => "IMVU.lnk"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\StartupFolder: => "Sidebar886.lnk"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\StartupFolder: => "CurseClientStartup.ccip"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "Skype"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "Steam"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "XDM"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "join.me.launcher"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "uTorrent"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "OneDrive"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "Tonido"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "CyberGhost"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "Google Update"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "iFunBox"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "autoRunTest"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "AirDroid 3"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "Clownfish"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "ManyCam"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "CloudDrive"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "Discord"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "DiscordCanary"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "4233357"
    HKU\S-1-5-21-354301492-1375950521-280439656-1001\...\StartupApproved\Run: => "VGYDUFDH60U2LQK"
    
    ==================== FirewallRules (Whitelisted) ===============
    
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
    
    FirewallRules: [{C15C1504-BE2A-40BE-A70C-F1E9271F5F93}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe
    FirewallRules: [{9ED14616-8113-44CA-8958-56201A18215B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe
    FirewallRules: [{2D672ACD-A811-4557-854A-AE5B95899ECC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Insane Decay of Mind\IDM.exe
    FirewallRules: [{FF0C609B-A7C0-41BA-B548-573F25C1E918}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Insane Decay of Mind\IDM.exe
    FirewallRules: [UDP Query User{FE15BDCA-0F3B-467F-9EFA-A2B408D693F6}C:\program files (x86)\steam\steamapps\common\devil in the pines\devilinthepines\binaries\win64\devilinthepines-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\devil in the pines\devilinthepines\binaries\win64\devilinthepines-win64-shipping.exe
    FirewallRules: [TCP Query User{66BD0B7A-FDC8-4270-9C44-4EB6CAB5AF8F}C:\program files (x86)\steam\steamapps\common\devil in the pines\devilinthepines\binaries\win64\devilinthepines-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\devil in the pines\devilinthepines\binaries\win64\devilinthepines-win64-shipping.exe
    FirewallRules: [{97B8EBFD-FC43-41AF-87C4-A27B502B4B6E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Devil in the Pines\DevilInThePines.exe
    FirewallRules: [{251AB012-C584-48CD-9106-E9196B181993}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Devil in the Pines\DevilInThePines.exe
    FirewallRules: [{8CC7EBB0-1566-4CFF-9E42-A15A34ED217F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blender\blender.exe
    FirewallRules: [{A6432F52-1183-463A-8E47-57829D0E5F24}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blender\blender.exe
    FirewallRules: [{A759D1CD-B38B-47C8-B4DE-984F67EE9C97}] => (Allow) LPort=2333
    FirewallRules: [{1C685AC0-07D5-41BF-9F54-83C520E8FFE3}] => (Allow) LPort=9143
    FirewallRules: [{A1712100-8CC2-4360-AC68-28E52421A920}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Pac-Man and the Ghostly Adventures\PACMAN.exe
    FirewallRules: [{6C24DE98-786A-4D24-BEDE-AEC42D4353A9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Pac-Man and the Ghostly Adventures\PACMAN.exe
    FirewallRules: [UDP Query User{F8930F89-6658-4E7A-AC74-057DF448FDF4}C:\users\ryan evan ramos\documents\programs\suntempel dx12 + metroid\windowsnoeditor\engine\binaries\win64\ue4game.exe] => (Allow) C:\users\ryan evan ramos\documents\programs\suntempel dx12 + metroid\windowsnoeditor\engine\binaries\win64\ue4game.exe
    FirewallRules: [TCP Query User{EEE950CF-6429-416A-A130-1F720A86C7BD}C:\users\ryan evan ramos\documents\programs\suntempel dx12 + metroid\windowsnoeditor\engine\binaries\win64\ue4game.exe] => (Allow) C:\users\ryan evan ramos\documents\programs\suntempel dx12 + metroid\windowsnoeditor\engine\binaries\win64\ue4game.exe
    FirewallRules: [{3C2086B9-3C45-4A4E-AEA7-0871F65206BD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    FirewallRules: [{331C802F-5683-441B-B06E-66BCB3216587}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
    FirewallRules: [{9D22E3A0-9CDE-4FD3-B349-077E58AD7F10}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
    FirewallRules: [{AD931FBC-C009-4698-8755-A2FAA6235E0A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Audiosurf\engine\QuestViewer.exe
    FirewallRules: [{C3E2002C-919F-4187-A008-F1C84E7B79F5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Audiosurf\engine\QuestViewer.exe
    FirewallRules: [{259EE60C-3D24-4ADC-92F0-B58C7C3A9524}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Audiosurf 2\Audiosurf2.exe
    FirewallRules: [{5F9CFEB0-C976-402C-9462-3D0D68949BCC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Audiosurf 2\Audiosurf2.exe
    FirewallRules: [{BC5BED40-A7FB-49F8-8190-8E3C4410D666}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ford Racing 3\fr3.exe
    FirewallRules: [{A099D4B4-8947-4BA0-B9A2-D1FF951A5767}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ford Racing 3\fr3.exe
    FirewallRules: [UDP Query User{107AC0AC-C4F6-4B42-A152-22D88A177CBE}D:\emulator games\wii u\wii u usb helper\wiiu_usb_helper.exe] => (Allow) D:\emulator games\wii u\wii u usb helper\wiiu_usb_helper.exe
    FirewallRules: [TCP Query User{0B08A88F-D7BA-4CA8-A50B-D56A57433993}D:\emulator games\wii u\wii u usb helper\wiiu_usb_helper.exe] => (Allow) D:\emulator games\wii u\wii u usb helper\wiiu_usb_helper.exe
    FirewallRules: [UDP Query User{0B469871-7626-46D4-8558-06D54596AFC2}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
    FirewallRules: [TCP Query User{9A121A1F-0FA0-4695-8B4A-5C0F7AE6C601}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
    FirewallRules: [UDP Query User{7641EEE5-77DD-404A-BBBF-82224558842F}C:\program files (x86)\airdroid\airdroid.exe] => (Allow) C:\program files (x86)\airdroid\airdroid.exe
    FirewallRules: [TCP Query User{640E100F-DC85-4A9B-B330-DB58E21423E4}C:\program files (x86)\airdroid\airdroid.exe] => (Allow) C:\program files (x86)\airdroid\airdroid.exe
    FirewallRules: [UDP Query User{3C10517E-36D5-427C-BB1A-4930B0D31FB0}C:\program files (x86)\r.g. mechanics\blur\blur.exe] => (Allow) C:\program files (x86)\r.g. mechanics\blur\blur.exe
    FirewallRules: [TCP Query User{DE89621A-3AD1-428B-AA41-2DCC3A9FFEA3}C:\program files (x86)\r.g. mechanics\blur\blur.exe] => (Allow) C:\program files (x86)\r.g. mechanics\blur\blur.exe
    FirewallRules: [UDP Query User{F20F3FFA-9D5F-454F-8E66-5EB120400083}C:\program files\my mobile\mymobiler\mexplorer.exe] => (Allow) C:\program files\my mobile\mymobiler\mexplorer.exe
    FirewallRules: [TCP Query User{A95F27B4-BB01-4F58-9BFA-032E7E8AF9F6}C:\program files\my mobile\mymobiler\mexplorer.exe] => (Allow) C:\program files\my mobile\mymobiler\mexplorer.exe
    FirewallRules: [UDP Query User{BB55720C-9B75-434D-9C5C-613653038D52}C:\program files\my mobile\mymobiler\mymobiler.exe] => (Allow) C:\program files\my mobile\mymobiler\mymobiler.exe
    FirewallRules: [TCP Query User{504BC965-C238-4524-9454-4A14CD2865FC}C:\program files\my mobile\mymobiler\mymobiler.exe] => (Allow) C:\program files\my mobile\mymobiler\mymobiler.exe
    FirewallRules: [{0E3D3488-EBF8-4D5D-8739-A2E543421A51}] => (Allow) C:\Program Files (x86)\My WIFI Router\My WIFI Router.exe
    FirewallRules: [{A3F0A176-2767-4072-AF7E-ABF77FC51E3E}] => (Allow) C:\Program Files (x86)\My WIFI Router\My WIFI Router.exe
    FirewallRules: [{25C63C81-D05E-4BDE-997C-6D62B9499CB3}] => (Allow) C:\Program Files (x86)\My WIFI Router\My WIFI Router.exe
    FirewallRules: [{EC5CD353-E0F3-44FB-A8EE-1B04CA4C379E}] => (Allow) C:\Program Files (x86)\My WIFI Router\My WIFI Router.exe
    FirewallRules: [{990F0921-92DD-4490-8DCE-6A4BB02625AB}] => (Allow) C:\Program Files (x86)\My WIFI Router\My WIFI Router.exe
    FirewallRules: [{93D0A754-6A4E-4B28-8038-7E19384F8DC8}] => (Allow) C:\Program Files (x86)\My WIFI Router\My WIFI Router.exe
    FirewallRules: [{784B0B65-1035-41D0-BC1F-1B1C20EED4F1}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{C19EE88E-9721-45DD-9B3D-80BD6EE161CC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [UDP Query User{047EF50F-79F8-4CDE-882D-24E93373D22E}C:\program files\comicrack\comicrack.exe] => (Allow) C:\program files\comicrack\comicrack.exe
    FirewallRules: [TCP Query User{15F48ED9-132F-45BD-B120-1AEEAAFD1C88}C:\program files\comicrack\comicrack.exe] => (Allow) C:\program files\comicrack\comicrack.exe
    FirewallRules: [UDP Query User{B6A1226D-3275-439F-B2DE-2E07E19CB1AD}C:\program files (x86)\open rails\runactivitylaa.exe] => (Allow) C:\program files (x86)\open rails\runactivitylaa.exe
    FirewallRules: [TCP Query User{0D1429BF-1C6D-4DD8-B233-04E3A8AA6D54}C:\program files (x86)\open rails\runactivitylaa.exe] => (Allow) C:\program files (x86)\open rails\runactivitylaa.exe
    FirewallRules: [{2E2DB3C3-7906-4D96-9CB6-A66E3B70949B}] => (Allow) LPort=1688
    FirewallRules: [UDP Query User{D06425CC-BFE0-4755-8EF9-4A39E9F1C72B}C:\games\railworks\railworks.exe] => (Block) C:\games\railworks\railworks.exe
    FirewallRules: [TCP Query User{38E94AEE-1B21-4A56-B9CC-904FCE758093}C:\games\railworks\railworks.exe] => (Block) C:\games\railworks\railworks.exe
    FirewallRules: [{914A4231-6824-40D2-B5E6-350F69357605}] => (Allow) LPort=8126
    FirewallRules: [{AF3CE170-CEB7-4D1E-9070-13F73AEB5484}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{BAD1F200-6473-48F4-A604-CAC846E7A5E3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{D6389073-37C5-40E5-BB01-C512440B8E18}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{6566ACD4-90F1-4CE8-BC36-C8C075EB383D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [UDP Query User{2D5BDA8B-6121-4E69-81CE-D74F2A1D5722}C:\users\ryan evan ramos\appdata\local\join.me\join.me.exe] => (Allow) C:\users\ryan evan ramos\appdata\local\join.me\join.me.exe
    FirewallRules: [TCP Query User{63FA1AFD-78B1-43A2-9526-F5C3B80D56E8}C:\users\ryan evan ramos\appdata\local\join.me\join.me.exe] => (Allow) C:\users\ryan evan ramos\appdata\local\join.me\join.me.exe
    FirewallRules: [{03CB0A00-313F-45B2-8328-DFE56E97B112}] => (Allow) C:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe
    FirewallRules: [{5A634378-06EB-4CFC-8AF6-1744A2C74321}] => (Allow) C:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe
    FirewallRules: [{A25D1E93-2D66-4B62-B5C6-CF2E083CE002}] => (Allow) C:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe
    FirewallRules: [{0C223A00-E8E9-49A3-A65E-62EFF393A8A3}] => (Allow) C:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe
    FirewallRules: [UDP Query User{92EE86F6-B125-451E-978D-9CD30A378E19}C:\users\ryan evan ramos\documents\programs\ppsspp\ppssppwindows64.exe] => (Allow) C:\users\ryan evan ramos\documents\programs\ppsspp\ppssppwindows64.exe
    FirewallRules: [TCP Query User{9CD96E09-91A4-45A8-BBCE-CF3A204B6ACC}C:\users\ryan evan ramos\documents\programs\ppsspp\ppssppwindows64.exe] => (Allow) C:\users\ryan evan ramos\documents\programs\ppsspp\ppssppwindows64.exe
    FirewallRules: [UDP Query User{35B04A81-D596-45D8-BAF1-922D34D61E19}C:\users\ryan evan ramos\documents\adhocserverproonline\adhocsever.exe] => (Allow) C:\users\ryan evan ramos\documents\adhocserverproonline\adhocsever.exe
    FirewallRules: [TCP Query User{04A443DC-1AAD-4A97-BF6A-DFD8F2378179}C:\users\ryan evan ramos\documents\adhocserverproonline\adhocsever.exe] => (Allow) C:\users\ryan evan ramos\documents\adhocserverproonline\adhocsever.exe
    FirewallRules: [UDP Query User{D3BB309F-1BB1-441D-B55E-31855C684AF0}C:\users\ryan evan ramos\appdata\roaming\tonido\tonido.exe] => (Allow) C:\users\ryan evan ramos\appdata\roaming\tonido\tonido.exe
    FirewallRules: [TCP Query User{809AF40E-185E-436A-A17E-D65B51F621D7}C:\users\ryan evan ramos\appdata\roaming\tonido\tonido.exe] => (Allow) C:\users\ryan evan ramos\appdata\roaming\tonido\tonido.exe
    FirewallRules: [TCP Query User{553855BC-86F3-43C1-860F-4F514EDF74E5}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
    FirewallRules: [UDP Query User{F61AD5FB-19A1-4EAC-840D-31034622D915}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
    FirewallRules: [{9B29DAAF-603E-45A0-8DE0-F3721594320F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{429EAE94-2DF5-42D9-85C8-925A533A6CF0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{BC29ED1E-1AA6-463C-9869-CA3AC6F488A9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [{2CA9E7B3-6EBE-4EB1-86E4-7B2A4994CA13}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [{9CDF5459-2FE3-4AFE-9D1A-AD1EF9024822}] => (Allow) E:\BioShock Infinite\Binaries\Win32\BioShockInfinite.exe
    FirewallRules: [{D3DF607E-4BAE-4066-8915-D9DC5F3C4E19}] => (Allow) E:\BioShock Infinite\Binaries\Win32\BioShockInfinite.exe
    FirewallRules: [TCP Query User{B9D2C9A5-CAD2-4410-8DE2-DB2BFA3A8168}C:\users\ryan evan ramos\documents\programs\hfs.exe] => (Allow) C:\users\ryan evan ramos\documents\programs\hfs.exe
    FirewallRules: [UDP Query User{66B58423-BCAC-491D-A831-953A037951B3}C:\users\ryan evan ramos\documents\programs\hfs.exe] => (Allow) C:\users\ryan evan ramos\documents\programs\hfs.exe
    FirewallRules: [TCP Query User{0D5FA934-AC9B-4D55-A6C8-783C97069012}C:\program files (x86)\soundwire server\soundwireserver.exe] => (Allow) C:\program files (x86)\soundwire server\soundwireserver.exe
    FirewallRules: [UDP Query User{26185A7D-7136-4459-8D44-13D19932948A}C:\program files (x86)\soundwire server\soundwireserver.exe] => (Allow) C:\program files (x86)\soundwire server\soundwireserver.exe
    FirewallRules: [{47E87C9B-A428-4ABA-AA7B-A4B14B6B642F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Team Fortress 2\hl2.exe
    FirewallRules: [{1D6A22CE-7727-403B-883D-B9778A621B81}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Team Fortress 2\hl2.exe
    FirewallRules: [{952D2987-AD29-4B04-9C37-5D52A0D8A0AF}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient.exe
    FirewallRules: [{8AC22BB3-0AB7-4176-847A-C67DB1B4B3E6}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
    FirewallRules: [{3E98DE0E-6354-4865-B527-DC373DF3DD93}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr.exe
    FirewallRules: [{90C3580E-2C0E-4C8E-987E-B8596BA2F07C}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd.exe
    FirewallRules: [{B6A58982-976A-4FCF-8DC6-7D3862774B3A}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe
    FirewallRules: [{6AB0B121-FCA0-4566-BD54-B648EB682052}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd_x64.exe
    FirewallRules: [TCP Query User{A0B1BCBA-2D60-4389-AA3D-1A0F6557F643}C:\program files (x86)\n3v games\ts12\bin\taddaemon.exe] => (Allow) C:\program files (x86)\n3v games\ts12\bin\taddaemon.exe
    FirewallRules: [UDP Query User{A4BF6955-5F93-48BC-9DFA-C5819E821356}C:\program files (x86)\n3v games\ts12\bin\taddaemon.exe] => (Allow) C:\program files (x86)\n3v games\ts12\bin\taddaemon.exe
    FirewallRules: [{239C4EA3-BEBE-4D39-B31B-6AB8D54CAC36}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Source SDK Base 2013 Multiplayer\hl2.exe
    FirewallRules: [{DE0C6E81-912D-495A-A68A-2CA84A595408}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Source SDK Base 2013 Multiplayer\hl2.exe
    FirewallRules: [TCP Query User{1AB91799-42E5-410D-AD5E-2D3D5223143E}C:\program files (x86)\steam\steamapps\common\garry's mod\garrysmod.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\garry's mod\garrysmod.exe
    FirewallRules: [UDP Query User{F74484CB-62BE-495F-8EAD-604B66A77E54}C:\program files (x86)\steam\steamapps\common\garry's mod\garrysmod.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\garry's mod\garrysmod.exe
    FirewallRules: [TCP Query User{DBCE9463-99ED-4447-9777-4C80060CBEB8}C:\program files (x86)\steam\steamapps\common\garry's mod\hl2.exe] => (Block) C:\program files (x86)\steam\steamapps\common\garry's mod\hl2.exe
    FirewallRules: [UDP Query User{F0586086-F8EB-4193-A319-B0170897CC67}C:\program files (x86)\steam\steamapps\common\garry's mod\hl2.exe] => (Block) C:\program files (x86)\steam\steamapps\common\garry's mod\hl2.exe
    FirewallRules: [TCP Query User{EC4D93B5-AFAD-4C75-84F3-A01750587F9D}C:\users\ryan evan ramos\appdata\local\roblox\versions\version-337f2aa823bb4833\robloxstudiobeta.exe] => (Allow) C:\users\ryan evan ramos\appdata\local\roblox\versions\version-337f2aa823bb4833\robloxstudiobeta.exe
    FirewallRules: [UDP Query User{33FB4550-D4B8-4614-AA52-E512932DB1A7}C:\users\ryan evan ramos\appdata\local\roblox\versions\version-337f2aa823bb4833\robloxstudiobeta.exe] => (Allow) C:\users\ryan evan ramos\appdata\local\roblox\versions\version-337f2aa823bb4833\robloxstudiobeta.exe
    FirewallRules: [TCP Query User{394B6168-9BB2-4E57-9545-CFA338C89591}C:\users\ryan evan ramos\documents\facerig\bin\facerig.exe] => (Allow) C:\users\ryan evan ramos\documents\facerig\bin\facerig.exe
    FirewallRules: [UDP Query User{616DA2C6-D2AB-4A6D-9E7A-8A6D0E1DB8F4}C:\users\ryan evan ramos\documents\facerig\bin\facerig.exe] => (Allow) C:\users\ryan evan ramos\documents\facerig\bin\facerig.exe
    FirewallRules: [{48C875F3-72A2-4E39-91CE-A93F9360F6D2}] => (Allow) LPort=7199
    FirewallRules: [TCP Query User{1AC75862-784C-4637-A63D-A371F4CE43E8}C:\users\ryan evan ramos\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe] => (Allow) C:\users\ryan evan ramos\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe
    FirewallRules: [UDP Query User{C2B38149-B608-460C-AE60-92F3E54B0867}C:\users\ryan evan ramos\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe] => (Allow) C:\users\ryan evan ramos\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe
    FirewallRules: [{3A0E0856-2997-4746-8261-D5FCF7991BF4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
    FirewallRules: [{B15358E9-5992-4643-AE7D-550BFB705F9B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
    FirewallRules: [TCP Query User{97E19A41-671F-4D88-AB72-D6A160244C00}C:\users\ryan evan ramos\documents\programs\midtown madness 2\midtown2.exe] => (Allow) C:\users\ryan evan ramos\documents\programs\midtown madness 2\midtown2.exe
    FirewallRules: [UDP Query User{C97251EB-AC69-43E7-9333-7862B3C3DEF8}C:\users\ryan evan ramos\documents\programs\midtown madness 2\midtown2.exe] => (Allow) C:\users\ryan evan ramos\documents\programs\midtown madness 2\midtown2.exe
    FirewallRules: [TCP Query User{17CA80EB-3409-4667-A129-115EE70D80B7}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe
    FirewallRules: [UDP Query User{B845BC98-A7E6-401D-A497-6D5A0AB922E2}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe
    FirewallRules: [{026F9139-94F8-437B-B349-5DFEA24FC36D}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
    FirewallRules: [{C8C3A33F-4FCC-4F24-95CC-10518670C8BB}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
    FirewallRules: [{C002F939-016F-4A50-9281-18396ADAD8F4}] => (Allow) C:\Program Files (x86)\WiFi\Wi-Fi.exe
    FirewallRules: [{67C16C9F-0165-4F2E-9A02-62247D2DADE9}] => (Allow) C:\Program Files (x86)\WiFi\TX_Httpd.exe
    FirewallRules: [TCP Query User{8F1A18F5-E2FF-4C8A-B583-6C9F6FF123B1}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
    FirewallRules: [UDP Query User{87391CDE-42A2-4295-8B6B-2C50E91D5D0D}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
    FirewallRules: [TCP Query User{2582C046-2471-4467-8BE5-3EF3C6E43E09}C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe
    FirewallRules: [UDP Query User{45A45C37-7B2F-4EED-9936-F7F2935548EA}C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_73\bin\javaw.exe
    FirewallRules: [TCP Query User{FF9D5CC3-615E-4029-ADD8-32D567C1A1DF}C:\users\ryan evan ramos\documents\programs\ppsspp\ppssppwindows.exe] => (Allow) C:\users\ryan evan ramos\documents\programs\ppsspp\ppssppwindows.exe
    FirewallRules: [UDP Query User{D39BD678-FFD1-48B5-A9F6-73E92695D859}C:\users\ryan evan ramos\documents\programs\ppsspp\ppssppwindows.exe] => (Allow) C:\users\ryan evan ramos\documents\programs\ppsspp\ppssppwindows.exe
    FirewallRules: [{971F54EC-D3EE-4B49-86E6-67040D52B35E}] => (Block) C:\users\ryan evan ramos\documents\programs\ppsspp\ppssppwindows.exe
    FirewallRules: [{C978A627-22B4-4214-A9A4-3984FC547571}] => (Block) C:\users\ryan evan ramos\documents\programs\ppsspp\ppssppwindows.exe
    FirewallRules: [{5D3D0301-DE8F-4D5C-BC15-B7507E90C5EA}] => (Allow) C:\Program Files (x86)\Crazybump\CrazyBump.exe
    FirewallRules: [{340DF170-9D50-4E34-9A4E-9B6EF5B7DC05}] => (Allow) C:\Program Files (x86)\Crazybump\CrazyBump.exe
    FirewallRules: [{8F215B66-7C61-4447-9EA9-764CC97EF440}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
    FirewallRules: [{B4A6F6ED-59E0-410D-B7D2-67B947C98A8C}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
    FirewallRules: [{3F10E0DD-EE31-40D8-B6EB-BA954057B9B0}] => (Allow) C:\Program Files (x86)\Crazybump\CrazyBump.exe
    FirewallRules: [{4E22B9ED-BA5A-4E1D-9881-C3BE43A8F688}] => (Allow) C:\Program Files (x86)\Crazybump\CrazyBump.exe
    FirewallRules: [TCP Query User{B36CD27F-F5EB-4FE7-8EA6-6B5E30A620AF}C:\program files (x86)\java\jre1.8.0_73\bin\jp2launcher.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_73\bin\jp2launcher.exe
    FirewallRules: [UDP Query User{6BBA0AAC-28A5-4939-9A86-7A212FB748A2}C:\program files (x86)\java\jre1.8.0_73\bin\jp2launcher.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_73\bin\jp2launcher.exe
    FirewallRules: [{34EEAA63-9524-45EA-9986-4E1DB83F4807}] => (Block) C:\Program Files (x86)\Xilisoft\Video Converter Ultimate\vc.exe
    FirewallRules: [{106AADB4-882C-4AD7-995D-88D7983210F3}] => (Block) C:\Program Files (x86)\Xilisoft\Video Converter Ultimate\vc.exe
    FirewallRules: [{C61D1CE1-C97C-4A1F-92F2-41B36BFCD0BE}] => (Block) C:\Program Files (x86)\Xilisoft\Video Converter Ultimate\vc.exe
    FirewallRules: [{468E2C73-760B-478B-90A7-7055193E2A5F}] => (Allow) C:\Program Files (x86)\Xilisoft\Video Converter Ultimate\vc.exe
    FirewallRules: [{DD0507FA-DFF8-45F6-8D6A-09AA1D2F688B}] => (Block) %ProgramFiles% (x86)\Xilisoft\Video Converter Ultimate\vcloader.exe
    FirewallRules: [{880FA378-F3BE-4401-99AB-ED3C45CC8AA4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ManiaPlanet_TMCanyon\ManiaPlanetLauncher.exe
    FirewallRules: [{15F73513-E4CC-4DCB-B856-B3726BEE5C14}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ManiaPlanet_TMCanyon\ManiaPlanetLauncher.exe
    FirewallRules: [{54981E54-4DED-4A0B-B47D-E49DA1997D27}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
    FirewallRules: [{196398E1-2A3B-49C1-A849-CE7BCD207B27}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
    FirewallRules: [{A1106B36-B3C0-4338-83D2-4CC4BD0E1581}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
    FirewallRules: [{C4ADF122-CC0B-4A95-8F73-ADECB5E626E6}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
    FirewallRules: [{54BE507F-F0F4-4B28-B08A-5F3ED040D4DD}] => (Allow) LPort=82
    FirewallRules: [{6A77A066-F152-4EB5-BAB9-01DCFBAAC795}] => (Allow) C:\Program Files (x86)\WiFi\Wi-Fi.exe
    FirewallRules: [{01E55C15-E22E-422E-90C7-DF4800A4BD83}] => (Allow) C:\Program Files (x86)\Remotr\RemotrServer.exe
    FirewallRules: [{4E40AE34-EB0A-4647-A6C3-AB741D0840DD}] => (Allow) C:\Program Files (x86)\Remotr\RemotrServer.exe
    FirewallRules: [{148B1180-6FC0-4A56-9770-30EDEC05A08D}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
    FirewallRules: [{835A7947-5FFD-4E92-9A74-95BB13B4945F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
    FirewallRules: [{71AF522F-E6D9-42B1-A653-760AFEDC150F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    FirewallRules: [{8862C617-330A-4C1D-9D84-C336FF56AA18}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    FirewallRules: [{1DB5266A-C443-4BD2-9725-66BA071E530E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Color Guardians\ColorGuardians.exe
    FirewallRules: [{C4F17341-B0F7-4D86-BF68-35F6B4B1DF90}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Color Guardians\ColorGuardians.exe
    FirewallRules: [TCP Query User{4EED1C07-A5EF-4869-A345-7A5D8999A0BA}C:\program files (x86)\steam\steamapps\common\maniaplanet_tmcanyon\maniaplanet.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\maniaplanet_tmcanyon\maniaplanet.exe
    FirewallRules: [UDP Query User{4F61F32C-4642-41F6-974D-F6AEEC7C9BFA}C:\program files (x86)\steam\steamapps\common\maniaplanet_tmcanyon\maniaplanet.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\maniaplanet_tmcanyon\maniaplanet.exe
    FirewallRules: [{331CF0C9-4700-4C0B-8A06-7D41582E8FA0}] => (Allow) %systemroot%\system32\alg.exe
    FirewallRules: [{16E543C7-7F23-41D8-A7C4-4D49C1B147C4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crash Drive 2\Crash Drive 2.exe
    FirewallRules: [{F281CB11-06E9-4133-B4E1-5A9D96ED1E85}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crash Drive 2\Crash Drive 2.exe
    FirewallRules: [{AD3E40CC-B040-4D42-800D-50F8F109AC03}] => (Allow) C:\Program Files\DroidCam\DroidCamApp.exe
    FirewallRules: [{1F7F82AC-E25B-4FFC-92F6-21A515180754}] => (Allow) C:\Program Files\DroidCam\DroidCamApp.exe
    FirewallRules: [{AD1C5883-1A14-4EEE-B20B-DCD7369C3F31}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe
    FirewallRules: [{DC4F8674-EDDE-4CBE-87FB-7B64F3A1B07F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\KillingFloor\System\KillingFloor.exe
    FirewallRules: [{43952F9C-776B-4895-AD6C-6E964FD77876}] => (Allow) F:\SteamLibrary\steamapps\common\Basement\WindowsNoEditor\StreamSurvival2.exe
    FirewallRules: [{4487E2CF-DE42-43FF-A468-5427CFD3B9C3}] => (Allow) F:\SteamLibrary\steamapps\common\Basement\WindowsNoEditor\StreamSurvival2.exe
    FirewallRules: [{01BB1E23-A514-4B73-BA3F-DC045E914511}] => (Allow) F:\SteamLibrary\steamapps\common\left 4 dead\left4dead.exe
    FirewallRules: [{B1AEA80F-1A8A-45BD-9B2B-65E71B1DAF2E}] => (Allow) F:\SteamLibrary\steamapps\common\left 4 dead\left4dead.exe
    FirewallRules: [{509C471E-83A0-475B-A61E-5D2A90C14BB6}] => (Allow) F:\SteamLibrary\steamapps\common\Left 4 Dead 2\left4dead2.exe
    FirewallRules: [{379C3D83-9A08-4F07-93AA-3D7501F9FAB8}] => (Allow) F:\SteamLibrary\steamapps\common\Left 4 Dead 2\left4dead2.exe
    FirewallRules: [{EC99AAFE-A116-4F11-B4F9-DC1C37C61348}] => (Allow) F:\SteamLibrary\steamapps\common\Outlast\OutlastLauncher.exe
    FirewallRules: [{9D45E0DB-891B-4F1D-A7DD-AD8C8F21F608}] => (Allow) F:\SteamLibrary\steamapps\common\Outlast\OutlastLauncher.exe
    FirewallRules: [{3874B249-FF80-496F-906A-687DBBE3ADD9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe
    FirewallRules: [{129F474C-B284-40D1-9EA4-50A720F53C5E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe
    FirewallRules: [TCP Query User{717E7A77-D5C4-4C8A-9949-B83735A7414B}F:\steamlibrary\steamapps\common\outlast\binaries\win64\olgame.exe] => (Allow) F:\steamlibrary\steamapps\common\outlast\binaries\win64\olgame.exe
    FirewallRules: [UDP Query User{B95A6681-0DD7-4E86-8EDA-CA9181F5114F}F:\steamlibrary\steamapps\common\outlast\binaries\win64\olgame.exe] => (Allow) F:\steamlibrary\steamapps\common\outlast\binaries\win64\olgame.exe
    FirewallRules: [{66366148-5239-492F-9C05-D454379A0616}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
    FirewallRules: [{4252445A-2685-4F22-A3DE-59829945EC48}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
    FirewallRules: [{68780526-43FE-42AA-B438-D72CADF3F00A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe
    FirewallRules: [{35E794D0-2634-4EE9-BE0E-CE3B7CFBDEF5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe
    FirewallRules: [{E5CC23C7-DE42-49C2-ADF2-F2560DB8C0EF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe
    FirewallRules: [{33C73754-17C0-4E82-BE53-492D5B9FB073}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe
    FirewallRules: [TCP Query User{7735C140-F920-443D-B48E-C07AF965A909}C:\program files (x86)\vanity pack\burnout(tm) paradise the ultimate box\burnoutparadise.exe] => (Allow) C:\program files (x86)\vanity pack\burnout(tm) paradise the ultimate box\burnoutparadise.exe
    FirewallRules: [UDP Query User{94ED06D9-D40F-447E-9930-17DC498932D8}C:\program files (x86)\vanity pack\burnout(tm) paradise the ultimate box\burnoutparadise.exe] => (Allow) C:\program files (x86)\vanity pack\burnout(tm) paradise the ultimate box\burnoutparadise.exe
    FirewallRules: [{772A6857-93FA-40A3-AAD4-A8139434B395}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Distance\Distance.exe
    FirewallRules: [{A4C1AA71-B291-4484-8A0B-38B0AAC65840}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Distance\Distance.exe
    FirewallRules: [{293B01D3-6115-4FEB-9EA8-8955C1F9AC6F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FaceRig\Bin\Launcher.exe
    FirewallRules: [{E237D586-011A-42DF-839F-0DAA05408253}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FaceRig\Bin\Launcher.exe
    FirewallRules: [{79BDB95F-5691-4319-84ED-2237F1481766}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FaceRig\Bin\FaceRig.exe
    FirewallRules: [{28B1BA47-0E92-4BBD-9B4D-2C4E58FD5330}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FaceRig\Bin\FaceRig.exe
    FirewallRules: [{7C8D609E-0959-4D61-BEB8-724FC525B091}] => (Allow) F:\SteamLibrary\steamapps\common\Sonic Adventure DX\AppLauncher.exe
    FirewallRules: [{A6FFA7F2-018B-4A5E-B101-8E2B2D3B9BDA}] => (Allow) F:\SteamLibrary\steamapps\common\Sonic Adventure DX\AppLauncher.exe
    FirewallRules: [{8F61508C-ECF2-4DFD-8EE9-7A5F6FC877E3}] => (Allow) F:\SteamLibrary\steamapps\common\Sonic Lost World\slw.exe
    FirewallRules: [{EA2FA59C-541A-4A8C-846F-8296117F762D}] => (Allow) F:\SteamLibrary\steamapps\common\Sonic Lost World\slw.exe
    FirewallRules: [{BE1874E4-812A-476B-9926-924EE0CFF743}] => (Allow) F:\SteamLibrary\steamapps\common\Sonic Generations\SonicGenerations.exe
    FirewallRules: [{FA83BA3A-2922-456E-8CB8-31197A83CAAF}] => (Allow) F:\SteamLibrary\steamapps\common\Sonic Generations\SonicGenerations.exe
    FirewallRules: [{2FBE5B89-103D-4CDE-8D51-531EFA34C5C6}] => (Allow) F:\SteamLibrary\steamapps\common\Sonic Generations\ConfigurationTool.exe
    FirewallRules: [{95D5D5D8-931F-4A3C-BBAC-62F77163A79D}] => (Allow) F:\SteamLibrary\steamapps\common\Sonic Generations\ConfigurationTool.exe
    FirewallRules: [{388B63DB-00C7-4100-9374-579B47344302}] => (Allow) F:\SteamLibrary\steamapps\common\Spore\SporeBin\SporeApp.exe
    FirewallRules: [{53CEE262-5D66-4341-96B1-878F8268C598}] => (Allow) F:\SteamLibrary\steamapps\common\Spore\SporeBin\SporeApp.exe
    FirewallRules: [{C6967E23-4EC8-44F9-9035-1B2B8CDC458A}] => (Allow) F:\SteamLibrary\steamapps\common\Spore\runme.exe
    FirewallRules: [{CA96AC12-4C74-4B07-941B-A613C44C846E}] => (Allow) F:\SteamLibrary\steamapps\common\Spore\runme.exe
    FirewallRules: [{910A3856-C9AF-4232-A90A-656916064B3E}] => (Allow) F:\SteamLibrary\steamapps\common\Spore\SporebinEP1\SporeApp.exe
    FirewallRules: [{FE865703-5FCC-4D93-8CD3-3D5A22F861C6}] => (Allow) F:\SteamLibrary\steamapps\common\Spore\SporebinEP1\SporeApp.exe
    FirewallRules: [{C5E80C71-D6D8-4FB0-86FA-6C7F4A89D2AC}] => (Allow) C:\Program Files (x86)\Nox\bin\Nox.exe
    FirewallRules: [{2D5C731C-74FC-4127-AA98-EB701D560F75}] => (Allow) C:\Program Files (x86)\Bignox\BigNoxVM\RT\NoxVMHandle.exe
    FirewallRules: [{1BE534F5-DA2B-4A82-AF58-A557BE01BDF7}] => (Allow) LPort=26789
    FirewallRules: [{6A349DF5-7687-454E-BC7D-19A6D43C7EE0}] => (Allow) F:\SteamLibrary\steamapps\common\Metro 2033 Redux\metro.exe
    FirewallRules: [{E1144B9A-C6AD-456F-9FBB-E3859CC671F7}] => (Allow) F:\SteamLibrary\steamapps\common\Metro 2033 Redux\metro.exe
    FirewallRules: [{F057D2A7-0995-45FD-AD29-914B23120702}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{35580A8C-565D-45F1-8D93-0013075E4222}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{17B04FCF-4F0D-47C1-BE32-930E3BAE7983}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [{36F89336-F9FE-4334-846C-C9D801F44F32}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [TCP Query User{AD3FAE5C-4E38-41C4-98BA-D174716E75B7}C:\users\ryan evan ramos\documents\programs\cemu_1.8.2\cemu.exe] => (Allow) C:\users\ryan evan ramos\documents\programs\cemu_1.8.2\cemu.exe
    FirewallRules: [UDP Query User{06AC0719-648C-4889-BEEA-3DD8398D4216}C:\users\ryan evan ramos\documents\programs\cemu_1.8.2\cemu.exe] => (Allow) C:\users\ryan evan ramos\documents\programs\cemu_1.8.2\cemu.exe
    FirewallRules: [{DAE2368B-A098-4812-8660-DE82FA12F070}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe
    FirewallRules: [{53C766FC-43F4-49CE-80EA-4BC9E72AB033}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe
    FirewallRules: [{D1B70483-DFA7-49C4-8E92-45990ED49591}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe
    FirewallRules: [{1655EC88-D427-43A4-B4D2-59A5DE3D9DF3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe
    FirewallRules: [{712505A3-B48A-4DB5-BC67-4015E9180CEB}] => (Allow) F:\SteamLibrary\steamapps\common\Metro Last Light Redux\metro.exe
    FirewallRules: [{DB9EB44E-5E60-42C4-90AE-42B9D3694245}] => (Allow) F:\SteamLibrary\steamapps\common\Metro Last Light Redux\metro.exe
    FirewallRules: [{37EA21DF-9822-49F6-AE17-21CEF2D51FB3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SonicForces\build\main\projects\exec\Sonic Forces.exe
    FirewallRules: [{5E4E4FCA-C973-48ED-80CD-B2EE141B16C4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SonicForces\build\main\projects\exec\Sonic Forces.exe
    FirewallRules: [{61C68798-6D33-4410-BB52-85CF9709B00F}] => (Allow) F:\SteamLibrary\steamapps\common\Basement\English\x64\WindowsNoEditor\StreamSurvival2.exe
    FirewallRules: [{0A8CBE23-00FF-421F-B06E-4710888719BA}] => (Allow) F:\SteamLibrary\steamapps\common\Basement\English\x64\WindowsNoEditor\StreamSurvival2.exe
    
    ==================== Restore Points =========================
    
    
    ==================== Faulty Device Manager Devices =============
    
    
    ==================== Event log errors: =========================
    
    Application errors:
    ==================
    Error: (11/14/2017 05:23:20 PM) (Source: Perflib) (EventID: 1008) (User: )
    Description: The Open Procedure for service "WmiApRpl" in DLL "C:\WINDOWS\system32\wbem\wmiaprpl.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
    
    Error: (11/14/2017 05:23:20 PM) (Source: PerfNet) (EventID: 2004) (User: )
    Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
    
    Error: (11/14/2017 05:23:20 PM) (Source: Perflib) (EventID: 1008) (User: )
    Description: The Open Procedure for service "Lsa" in DLL "C:\Windows\System32\Secur32.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
    
    Error: (11/14/2017 05:23:19 PM) (Source: Perflib) (EventID: 1008) (User: )
    Description: The Open Procedure for service "WmiApRpl" in DLL "C:\WINDOWS\system32\wbem\wmiaprpl.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
    
    Error: (11/14/2017 05:23:19 PM) (Source: PerfNet) (EventID: 2004) (User: )
    Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
    
    Error: (11/14/2017 05:23:19 PM) (Source: Perflib) (EventID: 1008) (User: )
    Description: The Open Procedure for service "Lsa" in DLL "C:\Windows\System32\Secur32.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
    
    Error: (11/14/2017 05:23:18 PM) (Source: Perflib) (EventID: 1008) (User: )
    Description: The Open Procedure for service "WmiApRpl" in DLL "C:\WINDOWS\system32\wbem\wmiaprpl.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
    
    Error: (11/14/2017 05:23:18 PM) (Source: PerfNet) (EventID: 2004) (User: )
    Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
    
    Error: (11/14/2017 05:23:17 PM) (Source: Perflib) (EventID: 1008) (User: )
    Description: The Open Procedure for service "Lsa" in DLL "C:\Windows\System32\Secur32.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
    
    Error: (11/14/2017 05:23:16 PM) (Source: Perflib) (EventID: 1008) (User: )
    Description: The Open Procedure for service "WmiApRpl" in DLL "C:\WINDOWS\system32\wbem\wmiaprpl.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
    
    
    System errors:
    =============
    Error: (11/14/2017 05:45:33 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk0\DR0.
    
    Error: (11/14/2017 05:45:33 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk0\DR0.
    
    Error: (11/14/2017 05:45:33 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk0\DR0.
    
    Error: (11/14/2017 05:45:33 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk0\DR0.
    
    Error: (11/14/2017 05:45:33 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk0\DR0.
    
    Error: (11/14/2017 05:45:33 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk0\DR0.
    
    Error: (11/14/2017 05:45:33 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk0\DR0.
    
    Error: (11/14/2017 05:45:33 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk0\DR0.
    
    Error: (11/14/2017 05:45:33 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk0\DR0.
    
    Error: (11/14/2017 05:45:33 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk0\DR0.
    
    
    CodeIntegrity:
    ===================================
      Date: 2017-11-13 17:32:38.292
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Users\Ryan Evan Ramos\Documents\programs\OldNewExplorer\OldNewExplorer64.dll that did not meet the Microsoft signing level requirements.
    
      Date: 2017-11-13 17:17:40.664
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Users\Ryan Evan Ramos\Documents\programs\OldNewExplorer\OldNewExplorer64.dll that did not meet the Microsoft signing level requirements.
    
      Date: 2017-11-13 17:16:34.051
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Users\Ryan Evan Ramos\Documents\programs\OldNewExplorer\OldNewExplorer64.dll that did not meet the Microsoft signing level requirements.
    
      Date: 2017-11-13 17:16:13.399
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Users\Ryan Evan Ramos\Documents\programs\OldNewExplorer\OldNewExplorer64.dll that did not meet the Microsoft signing level requirements.
    
      Date: 2017-11-13 17:07:55.052
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Users\Ryan Evan Ramos\Documents\programs\OldNewExplorer\OldNewExplorer64.dll that did not meet the Microsoft signing level requirements.
    
      Date: 2017-11-13 17:06:30.251
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Users\Ryan Evan Ramos\Documents\programs\OldNewExplorer\OldNewExplorer64.dll that did not meet the Microsoft signing level requirements.
    
      Date: 2017-11-13 17:06:10.237
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Users\Ryan Evan Ramos\Documents\programs\OldNewExplorer\OldNewExplorer64.dll that did not meet the Microsoft signing level requirements.
    
      Date: 2017-11-13 16:40:42.280
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Users\Ryan Evan Ramos\Desktop\Sonic Forces Trainer _6.exe that did not meet the Unchecked signing level requirements.
    
      Date: 2017-11-13 16:40:42.278
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Users\Ryan Evan Ramos\Desktop\Sonic Forces Trainer _6.exe that did not meet the Unchecked signing level requirements.
    
      Date: 2017-11-13 16:40:42.277
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Users\Ryan Evan Ramos\Desktop\Sonic Forces Trainer _6.exe that did not meet the Unchecked signing level requirements.
    
    
    ==================== Memory info =========================== 
    
    Processor: AMD Ryzen 7 1700 Eight-Core Processor 
    Percentage of memory in use: 27%
    Total physical RAM: 32717.52 MB
    Available physical RAM: 23611.54 MB
    Total Virtual: 37581.52 MB
    Available Virtual: 25684.09 MB
    
    ==================== Drives ================================
    
    Drive c: () (Fixed) (Total:930.56 GB) (Free:393.27 GB) NTFS
    Drive d: () (Fixed) (Total:298.09 GB) (Free:141.49 GB) NTFS
    Drive f: () (Fixed) (Total:110.99 GB) (Free:35.03 GB) NTFS
    
    ==================== MBR & Partition Table ==================
    
    ==================== End of Addition.txt ============================
    Last edited by Brink; 14 Nov 2017 at 18:45. Reason: code box
      My Computer


  4. Posts : 5,299
    Windows 11 Pro 64-bit
       #4

    I need you to post contents of the Addition.txt file. I see now you have post both files.
      My Computer


  5. Posts : 5,299
    Windows 11 Pro 64-bit
       #5

    Fix with Farbar Recovery Scan Tool

    This fix was created for this user for use on that particular machine.Running it on another one may cause damage and render the system unstable.

    Download attached fixlist.txt file and save it to the Desktop:

    Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


    • Right-click on FRST icon and select Run as Administrator to start the tool.
    • Press the Fix button just once and wait.
    • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
    • When finished FRST will generate a log on the Desktop, called Fixlog.txt.



    Please post it to your reply.
    Specious Task Taking up system resources in task manager Attached Files
      My Computer


  6. Posts : 5,299
    Windows 11 Pro 64-bit
       #6

    I also need you to install latest device drivers.

    System errors:
    =============
    Error: (11/14/2017 05:45:33 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk0\DR0.
    Backup your personal files and check SMART reported health of the HDD/SSD.

    Please download and run SeaTools for Windows.

    Before the installation begins you will be prompted to either Decline or Accept the terms of the installation, click on I Accept.

    Once the installation begins you will see an image similar to the one below.



    1. SeaTools for Windows will search for HDDs and SSDs on your computer.

    2. Detected Drives will list the HDDs and SSDs found. Place a check mark in the drive box you want to run the scan on. This should be the drive that has the operating system installed on it, this is usually C: drive.

    3. You will see Basic Tests toolbar above Detected Drives, move the mouse pointer over this to open the test options. Please click on Long Generic Test

    4. This will start the scan. When the scan is complete you will see the result under Test Status , please post the results in your topic.



    5. The test will indicate either Pass or Fail. Post the results of the scan in your topic.

    6. Click on Help, then click on View Log File. If the scan failed take a screen shot of the Log File and post it in your topic.
      My Computer


  7. Posts : 8
    Windows 10 Pro
    Thread Starter
       #7

    i also get this after running it Fix result of Farbar Recovery Scan Tool (x64) Version: 12-11-2017 03
    Ran by Ryan Evan Ramos (14-11-2017 22:17:30) Run:5
    Running from C:\Users\Ryan Evan Ramos\Desktop
    Loaded Profiles: Ryan Evan Ramos (Available Profiles: Ryan Evan Ramos)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************

    *****************


    ==== End of Fixlog 22:17:30 ====
      My Computer


  8. Posts : 8
    Windows 10 Pro
    Thread Starter
       #8

    reply to hard drive


    this is what i getSpecious Task Taking up system resources in task manager-fail.png
      My Computer


  9. Posts : 5,299
    Windows 11 Pro 64-bit
       #9

    Looks like you have Western Digital HDD use there HDD diagnostic software make sure to run extended test.


    Make sure fixlist.txt file and FRST are at same directory.
      My Computer


  10. Posts : 5,299
    Windows 11 Pro 64-bit
       #10

    Can you please download the attached Fixlist.txt file i have corrected mistake i have made.
    Specious Task Taking up system resources in task manager Attached Files
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 20:54.
Find Us




Windows 10 Forums