Malware Log Analysis

shared / trif55
content copied

content

Start:: SystemRestore: On CreateRestorePoint: CloseProcesses: CHR Notifications: Default -> hxxps://business.facebook.com; hxxps://linustechtips.com; hxxps://live.trading212.com; hxxps://mail.google.com; hxxps://meet.google.com; hxxps://my.pcloud.com; hxxps://re-captha-version-3-73.com; hxxps://trade.kraken.com; hxxps://www.instagram.com; hxxps://www.rcmoment.com; hxxps://www.tradingview.com CHR NewTab: Default -> Not-active:"chrome-extension://jpfpebmajhhopeonhlcgidhclcccjcik/newtab.html", Not-active:"chrome-extension://lgecddhfcfhlmllljooldkbbijdcnlpe/newtab.html", Not-active:"chrome-extension://cfmnkhhioonhiehehedmnjibmampjiab/newtab.html" Comment: Browser extension - Moment Homepage- #1 Personal Dashboard for Chrome C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgecddhfcfhlmllljooldkbbijdcnlpe 2026-08-21 21:49 - 2026-08-21 21:49 - 000000000 ____D C:\Users\chris\AppData\Local\Yandex BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_491\bin\ssv.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_491\bin\jp2ssv.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_491\bin\ssv.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_491\bin\jp2ssv.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation) PowerShell: Remove-MpPreference -ExclusionProcess "C:\Program Files\FreeFileSync\Bin\*" PowerShell: Remove-MpPreference -ExclusionProcess "C:\Program Files\FreeFileSync\Bin\FreeFileSync_*.exe" PowerShell: Remove-MpPreference -ExclusionProcess "C:\Program Files\FreeFileSync\FreeFileSync.exe" (C:\Program Files\TeamViewer\TeamViewer.exe ->) (TeamViewer Germany GmbH -> ) C:\Program Files\TeamViewer\crashpad_handler.exe HKU\S-1-5-21-769680110-549076602-1943842397-1001\...\Run: [MicrosoftEdgeAutoLaunch_0A1E394B2107F9944ED3CB9C6839BC54] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --win-session-start [5018440 2026-08-16] (Microsoft Corporation -> Microsoft Corporation) Comment: Browser extension - Chrome Remote Desktop C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai Comment: Browser extension - Violentmonkey C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\jinjaccalgkegednnccohejagnlnfdag CustomCLSID: HKU\S-1-5-21-769680110-549076602-1943842397-1001_Classes\CLSID\{3BC2EF70-3830-43FC-9009-029942FD2DCE}\InprocServer32 -> C:\Users\chris\AppData\Local\Google\Update\1.3.36.372\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-769680110-549076602-1943842397-1001_Classes\CLSID\{85D8EE2F-794F-41F0-BB03-49D56A23BEF4}\InprocServer32 -> C:\Users\chris\AppData\Local\Google\Update\1.3.36.372\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-769680110-549076602-1943842397-1001_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\chris\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20244.4\x64\Microsoft.Teams.AddinLoader.dll => No File CustomCLSID: HKU\S-1-5-21-769680110-549076602-1943842397-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> "C:\Users\chris\AppData\Local\Microsoft\Teams\current\Teams.exe" --toast => No File CustomCLSID: HKU\S-1-5-21-769680110-549076602-1943842397-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\chris\AppData\Local\Google\Update\1.3.36.372\psuser_64.dll => No File AlternateDataStreams: C:\WINDOWS\tracing:? [16] AlternateDataStreams: C:\ProgramData\DP45977C.lfl:677104FCAA [5138] AlternateDataStreams: C:\ProgramData\droidcam-client-options-v2:8329C6407A [5138] AlternateDataStreams: C:\ProgramData\droidcam-settings:3FFAD04353 [5138] AlternateDataStreams: C:\ProgramData\droidcam.log:ADD74D6E12 [5138] AlternateDataStreams: C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc:169D67954B [5138] AlternateDataStreams: C:\ProgramData\mntemp:8EAD8B3507 [5138] AlternateDataStreams: C:\ProgramData\SoftwareUpdateTemp.xml:62C63A1E49 [5138] AlternateDataStreams: C:\ProgramData\TEMP:3F30E778 [140] AlternateDataStreams: C:\ProgramData\TEMP:A9967A61 [139] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini:B1DA6C571C [5138] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk:B76C4E1157 [5138] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk:7661CCE9BF [5138] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk:8421170AC1 [5138] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro CC 2017.lnk:B37E45B570 [5138] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Arduino.lnk:34D926B811 [5138] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk:09A0A90EF3 [5138] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClearView.lnk:B69511AFB0 [5138] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClearView1.lnk:7FBCEC47AF [5138] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\deemix-gui.lnk:8A8BE14D52 [5138] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk:F9B57EE960 [5138] AlternateDataStreams: C:\Users\chris\Application Data:00e481b5e22dbe1f649fcddd505d3eb7 [394] AlternateDataStreams: C:\Users\chris\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394] AlternateDataStreams: C:\Users\Public\AppData:CSM [476] AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [2668] FirewallRules: [{77DC6E42-FE21-45A0-82A8-55DC55D51CF8}] => (Allow) H:\SteamLibrary\steamapps\common\For Honor\forhonor.exe => No File FirewallRules: [{4BF3B45B-81D4-4CA6-B18A-90B2C0F813EF}] => (Allow) H:\SteamLibrary\steamapps\common\For Honor\forhonor.exe => No File FirewallRules: [UDP Query User{185DB07F-7211-4D83-9C23-7DC2B4F107B3}H:\steamlibrary\steamapps\common\hell let loose\hll\binaries\win64\hll-win64-shipping.exe] => (Allow) H:\steamlibrary\steamapps\common\hell let loose\hll\binaries\win64\hll-win64-shipping.exe => No File FirewallRules: [TCP Query User{209DAFFD-EB5E-4C1D-83B8-93F9726AC81B}H:\steamlibrary\steamapps\common\hell let loose\hll\binaries\win64\hll-win64-shipping.exe] => (Allow) H:\steamlibrary\steamapps\common\hell let loose\hll\binaries\win64\hll-win64-shipping.exe => No File FirewallRules: [UDP Query User{6714D424-95B1-4592-91F5-9875C749C181}H:\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) H:\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [TCP Query User{5F02AFAA-8513-42E5-A33D-E19E61A54154}H:\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) H:\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [{908BB919-B225-437C-B293-62C13EBD7326}] => (Allow) H:\SteamLibrary\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe => No File FirewallRules: [{81F02779-4476-45E1-887F-017696AF8867}] => (Allow) H:\SteamLibrary\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe => No File FirewallRules: [{FBF4C861-3AF7-45A5-B5E7-1860FB2E2D63}] => (Allow) H:\SteamLibrary\steamapps\common\SpaceChem\SpaceChem.exe => No File FirewallRules: [{9A146CBA-C9BB-4DB6-95E8-24CCBAC3E54E}] => (Allow) H:\SteamLibrary\steamapps\common\SpaceChem\SpaceChem.exe => No File FirewallRules: [UDP Query User{BDD360C2-2615-4CE6-9BAA-39D589B4AC9C}C:\program files\mumble\murmur.exe] => (Allow) C:\program files\mumble\murmur.exe => No File FirewallRules: [TCP Query User{DED02900-0FDA-4D18-8E2B-06D15A780779}C:\program files\mumble\murmur.exe] => (Allow) C:\program files\mumble\murmur.exe => No File FirewallRules: [{65A8163D-8C2A-415F-B45E-521972998232}] => (Allow) H:\SteamLibrary\steamapps\common\KingdomComeDeliverance\Bin\Win64\KingdomCome.exe => No File FirewallRules: [{91AE1FFB-BABB-4687-9EA1-70F9E249C478}] => (Allow) H:\SteamLibrary\steamapps\common\KingdomComeDeliverance\Bin\Win64\KingdomCome.exe => No File FirewallRules: [UDP Query User{14C8D944-8CF6-4825-8394-BF9E35A23CB4}C:\program files\java\jre1.8.0_251\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_251\bin\java.exe => No File FirewallRules: [TCP Query User{1D8F1502-DAEF-4851-B97B-1932C9FB2062}C:\program files\java\jre1.8.0_251\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_251\bin\java.exe => No File FirewallRules: [UDP Query User{23A5E452-E3C4-4DF2-9149-D68FD997D4BD}D:\steam\steamapps\common\kards\kards\binaries\win64\kards-win64-shipping.exe] => (Allow) D:\steam\steamapps\common\kards\kards\binaries\win64\kards-win64-shipping.exe => No File FirewallRules: [TCP Query User{789BDB93-6ADC-4FF2-9706-69D5838BE81D}D:\steam\steamapps\common\kards\kards\binaries\win64\kards-win64-shipping.exe] => (Allow) D:\steam\steamapps\common\kards\kards\binaries\win64\kards-win64-shipping.exe => No File FirewallRules: [{D6B0E13F-6060-4539-AA59-A0C0E535D523}] => (Allow) D:\Steam\steamapps\common\Double Action\bin\hammer.exe => No File FirewallRules: [{B37AD3B4-E2BE-4408-8738-95F7CBBDABE3}] => (Allow) D:\Steam\steamapps\common\Double Action\bin\hammer.exe => No File FirewallRules: [{7E06C7FF-58BE-410A-8C9C-88396F69F134}] => (Allow) D:\BattleField3\Battlefield 3\bf3.exe => No File FirewallRules: [{B21B70F2-3D58-415A-8B56-04325A0B2010}] => (Allow) D:\BattleField3\Battlefield 3\bf3.exe => No File FirewallRules: [UDP Query User{6A8C8642-C66E-4AF9-877B-5EB7F3F494AC}D:\csgods\csgosl\server\srcds.exe] => (Allow) D:\csgods\csgosl\server\srcds.exe => No File FirewallRules: [TCP Query User{7A65297C-10A4-4067-9795-67A36F926DE4}D:\csgods\csgosl\server\srcds.exe] => (Allow) D:\csgods\csgosl\server\srcds.exe => No File FirewallRules: [{CBE44CB5-4E01-49F3-97A4-7598AA9E8BA6}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Source\hl2.exe => No File FirewallRules: [{9BE3437A-E950-476B-92A3-65F42DBD490C}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Source\hl2.exe => No File FirewallRules: [{AF15C050-7253-4067-91FC-B8E64AE4BF27}] => (Allow) C:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe => No File FirewallRules: [UDP Query User{35BF1AF9-9F1D-4696-924D-58498D78D24E}C:\program files\java\jre1.8.0_251\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_251\bin\javaw.exe => No File FirewallRules: [TCP Query User{5A8CC443-4396-4979-9AB9-905184931B28}C:\program files\java\jre1.8.0_251\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_251\bin\javaw.exe => No File FirewallRules: [UDP Query User{9BFB56CC-5B2A-49CB-B799-D49849721B0B}C:\program files (x86)\common files\oracle\java\javapath_target_306214437\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_306214437\java.exe => No File FirewallRules: [TCP Query User{AA2BCF20-2749-42FA-A871-2C1B8E4E2BF0}C:\program files (x86)\common files\oracle\java\javapath_target_306214437\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_306214437\java.exe => No File FirewallRules: [UDP Query User{CE049170-0845-4B99-B5DF-470A155FA576}C:\program files (x86)\common files\oracle\java\javapath_target_1916036171\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_1916036171\java.exe => No File FirewallRules: [TCP Query User{0DAB34B9-68C7-4820-BB05-58CACD19E12A}C:\program files (x86)\common files\oracle\java\javapath_target_1916036171\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_1916036171\java.exe => No File FirewallRules: [UDP Query User{CDA44D46-85CD-4595-BDF2-FF4FA00AE857}D:\steam\steamapps\common\post scriptum\postscriptum\binaries\win64\postscriptum.exe] => (Allow) D:\steam\steamapps\common\post scriptum\postscriptum\binaries\win64\postscriptum.exe => No File FirewallRules: [TCP Query User{345D5107-1966-41F2-B836-CCCD85D31D09}D:\steam\steamapps\common\post scriptum\postscriptum\binaries\win64\postscriptum.exe] => (Allow) D:\steam\steamapps\common\post scriptum\postscriptum\binaries\win64\postscriptum.exe => No File FirewallRules: [UDP Query User{6CC37696-7956-42FF-9807-7462C2982F4B}D:\csgods\srcds.exe] => (Allow) D:\csgods\srcds.exe => No File FirewallRules: [TCP Query User{DB554DAE-6C30-4703-8684-8AA576D1A48A}D:\csgods\srcds.exe] => (Allow) D:\csgods\srcds.exe => No File FirewallRules: [UDP Query User{C225A6EC-CD7D-4E11-AEF4-D527BC685761}D:\codmw\call of duty modern warfare\modernwarfare.exe] => (Allow) D:\codmw\call of duty modern warfare\modernwarfare.exe => No File FirewallRules: [TCP Query User{0910502B-42E5-4C94-8FD2-D8D7E491D6A5}D:\codmw\call of duty modern warfare\modernwarfare.exe] => (Allow) D:\codmw\call of duty modern warfare\modernwarfare.exe => No File FirewallRules: [UDP Query User{894082AE-C177-4C99-815A-65C5CDDDC626}C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe => No File FirewallRules: [TCP Query User{268BCD80-90C1-4F1C-BF9D-CC4AF5EEAD75}C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe => No File FirewallRules: [{C716C175-7B92-4AF6-A8B7-63E821BAC20E}] => (Block) C:\program files (x86)\world of warcraft\_retail_\utils\wowvoiceproxy.exe => No File FirewallRules: [{2BF39404-AD18-4405-B701-DD0C59C1ECAD}] => (Block) C:\program files (x86)\world of warcraft\_retail_\utils\wowvoiceproxy.exe => No File FirewallRules: [UDP Query User{0E49CA0D-3AEE-4FDD-B764-06BB1C310599}C:\program files (x86)\world of warcraft\_retail_\utils\wowvoiceproxy.exe] => (Allow) C:\program files (x86)\world of warcraft\_retail_\utils\wowvoiceproxy.exe => No File FirewallRules: [TCP Query User{39C5B4EA-5871-4E26-8074-4A3B1CFAC896}C:\program files (x86)\world of warcraft\_retail_\utils\wowvoiceproxy.exe] => (Allow) C:\program files (x86)\world of warcraft\_retail_\utils\wowvoiceproxy.exe => No File FirewallRules: [{AF42E7A0-C72B-4CB3-A612-90D737FE8060}] => (Block) H:\battlenet2\call of duty modern warfare beta\modernwarfare.exe => No File FirewallRules: [{22E8113B-73D7-4EF6-B5FB-2E71089427C3}] => (Block) H:\battlenet2\call of duty modern warfare beta\modernwarfare.exe => No File FirewallRules: [UDP Query User{C41D6790-222C-46A1-8FA5-50A5C910B63C}H:\battlenet2\call of duty modern warfare beta\modernwarfare.exe] => (Allow) H:\battlenet2\call of duty modern warfare beta\modernwarfare.exe => No File FirewallRules: [TCP Query User{69752A92-721F-43CA-BBFE-58D9ADDC9CED}H:\battlenet2\call of duty modern warfare beta\modernwarfare.exe] => (Allow) H:\battlenet2\call of duty modern warfare beta\modernwarfare.exe => No File FirewallRules: [{99325F46-276F-47E9-AD9F-77E92E882E33}] => (Block) C:\riot games\league of legends\game\league of legends.exe => No File FirewallRules: [{8CC252EF-4BD2-4513-8E13-2CEA2B6FB024}] => (Block) C:\riot games\league of legends\game\league of legends.exe => No File FirewallRules: [UDP Query User{ED183C8F-EFCB-4C9B-B6EA-E8F7891EE2BE}C:\riot games\league of legends\game\league of legends.exe] => (Allow) C:\riot games\league of legends\game\league of legends.exe => No File FirewallRules: [TCP Query User{DF5FBA93-2D24-4E27-8598-C529AE77237F}C:\riot games\league of legends\game\league of legends.exe] => (Allow) C:\riot games\league of legends\game\league of legends.exe => No File FirewallRules: [{8EE16ACF-68F7-40ED-966A-C7F11206C9FB}] => (Block) E:\dawn.of.war.iii.v4.0.0.16278\relicdow3.exe => No File FirewallRules: [{3956A0E7-07C0-4628-9B94-65CE579CEBFF}] => (Block) E:\dawn.of.war.iii.v4.0.0.16278\relicdow3.exe => No File FirewallRules: [UDP Query User{9E028A6E-BC2A-4A69-80B6-F508CC9FFEF9}E:\dawn.of.war.iii.v4.0.0.16278\relicdow3.exe] => (Allow) E:\dawn.of.war.iii.v4.0.0.16278\relicdow3.exe => No File FirewallRules: [TCP Query User{251A2211-9234-4DBD-A352-62F73FE7D811}E:\dawn.of.war.iii.v4.0.0.16278\relicdow3.exe] => (Allow) E:\dawn.of.war.iii.v4.0.0.16278\relicdow3.exe => No File FirewallRules: [{F4438797-8ADE-464F-B8DB-9109824F6309}] => (Block) D:\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe => No File FirewallRules: [{69B49A8F-62CC-46DD-8C62-85C20D995751}] => (Block) D:\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe => No File FirewallRules: [{1414227A-429D-4EA3-876B-D9753229A2AB}] => (Block) D:\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe => No File FirewallRules: [{0E2519FB-02DD-4DF3-8E30-BDB2661C3CB6}] => (Block) D:\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe => No File FirewallRules: [UDP Query User{7036C1DA-12CF-431A-9AA8-0DA691D3437A}D:\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) D:\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe => No File FirewallRules: [TCP Query User{2C1F9315-FBC5-4261-8304-C2E11B82D603}D:\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) D:\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe => No File FirewallRules: [UDP Query User{BE40F27A-7B54-4A57-BCCB-16713899473A}D:\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe] => (Allow) D:\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe => No File FirewallRules: [TCP Query User{52D37F11-1229-4DFE-AB0E-3940C12DF577}D:\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe] => (Allow) D:\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe => No File FirewallRules: [{9ED25B64-A168-4079-AEBE-5FCCA2D82287}] => (Block) E:\battle.net starcraft2\starcraft ii\versions\base65384\sc2_x64.exe => No File FirewallRules: [{6231EF9B-0BC6-461C-8679-E0B4965AB1AF}] => (Block) E:\battle.net starcraft2\starcraft ii\versions\base65384\sc2_x64.exe => No File FirewallRules: [UDP Query User{EEE197B8-30FB-4352-A09D-E43DC2C1F4E9}E:\battle.net starcraft2\starcraft ii\versions\base65384\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base65384\sc2_x64.exe => No File FirewallRules: [TCP Query User{2E43696A-9F58-4835-9919-B3333F752114}E:\battle.net starcraft2\starcraft ii\versions\base65384\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base65384\sc2_x64.exe => No File FirewallRules: [{6C7297C7-A72B-4129-8348-F0431FA755FC}] => (Block) E:\battle.net starcraft2\starcraft ii\versions\base65094\sc2_x64.exe => No File FirewallRules: [{3CA443DA-BA55-4542-B20C-71C01C23AD2C}] => (Block) E:\battle.net starcraft2\starcraft ii\versions\base65094\sc2_x64.exe => No File FirewallRules: [UDP Query User{5FF8758B-0228-4B72-878E-A0C47CC45227}E:\battle.net starcraft2\starcraft ii\versions\base65094\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base65094\sc2_x64.exe => No File FirewallRules: [TCP Query User{706E06DA-3808-4EB8-ABFE-984603E550F0}E:\battle.net starcraft2\starcraft ii\versions\base65094\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base65094\sc2_x64.exe => No File FirewallRules: [{8FC9ECAB-09BC-48A1-9ACE-3AFDBA0DC34E}] => (Block) D:\steam\steamapps\common\laser league\gameproject\binaries\win64\gameproject-win64-shipping.exe => No File FirewallRules: [{7BB1A93A-5A9E-41C8-A8EB-992475D1CD1B}] => (Block) D:\steam\steamapps\common\laser league\gameproject\binaries\win64\gameproject-win64-shipping.exe => No File FirewallRules: [UDP Query User{2D698992-7A6D-4271-8D3B-80799513D64C}D:\steam\steamapps\common\laser league\gameproject\binaries\win64\gameproject-win64-shipping.exe] => (Allow) D:\steam\steamapps\common\laser league\gameproject\binaries\win64\gameproject-win64-shipping.exe => No File FirewallRules: [TCP Query User{51A93A20-F9AA-4795-9BED-BEA542A943B8}D:\steam\steamapps\common\laser league\gameproject\binaries\win64\gameproject-win64-shipping.exe] => (Allow) D:\steam\steamapps\common\laser league\gameproject\binaries\win64\gameproject-win64-shipping.exe => No File FirewallRules: [{DB1FBC40-90D8-4A44-91E4-17940EE14E4A}] => (Block) E:\battle.net starcraft2\starcraft ii\versions\base64469\sc2_x64.exe => No File FirewallRules: [{B5251A31-0354-4236-9226-47CF2D51E5D5}] => (Block) E:\battle.net starcraft2\starcraft ii\versions\base64469\sc2_x64.exe => No File FirewallRules: [UDP Query User{5AD8CA2A-69B0-4587-B074-A64F1DD02E6C}E:\battle.net starcraft2\starcraft ii\versions\base64469\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base64469\sc2_x64.exe => No File FirewallRules: [TCP Query User{7E2E5B27-DF98-483F-99B1-B00BF7DBF80A}E:\battle.net starcraft2\starcraft ii\versions\base64469\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base64469\sc2_x64.exe => No File FirewallRules: [{551D5D7B-D027-4078-B69C-EF26D19301E4}] => (Block) E:\battle.net starcraft2\starcraft ii\versions\base63454\sc2_x64.exe => No File FirewallRules: [{75F1488F-2F3C-4982-8BA0-6DCC37F6A7B0}] => (Block) E:\battle.net starcraft2\starcraft ii\versions\base63454\sc2_x64.exe => No File FirewallRules: [UDP Query User{5EC2B42C-3D0A-481C-8150-6E762158E8B5}E:\battle.net starcraft2\starcraft ii\versions\base63454\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base63454\sc2_x64.exe => No File FirewallRules: [TCP Query User{1B05C641-94FE-41D3-84A3-1A1E9B0A4164}E:\battle.net starcraft2\starcraft ii\versions\base63454\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base63454\sc2_x64.exe => No File FirewallRules: [{F5A26DB2-DC42-4091-A117-89D165574068}] => (Block) E:\battle.net starcraft2\starcraft ii\versions\base62848\sc2_x64.exe => No File FirewallRules: [{B86182D3-9191-4A1B-BAD7-B29C4F615ABE}] => (Block) E:\battle.net starcraft2\starcraft ii\versions\base62848\sc2_x64.exe => No File FirewallRules: [UDP Query User{89257E64-9DA1-4C26-9B41-6273354DD285}E:\battle.net starcraft2\starcraft ii\versions\base62848\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base62848\sc2_x64.exe => No File FirewallRules: [TCP Query User{6D093C7B-5F1E-4333-889E-EE79C417A7D9}E:\battle.net starcraft2\starcraft ii\versions\base62848\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base62848\sc2_x64.exe => No File FirewallRules: [{3711CDB6-A6E6-4D8F-B78B-596EB09E779D}] => (Block) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File FirewallRules: [{2B615E82-1CC0-4FA1-A0AA-2E73F7A5B3CF}] => (Block) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File FirewallRules: [UDP Query User{5DF80186-4709-4E68-BCBB-A19AA4AD704A}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File FirewallRules: [TCP Query User{0D168A3C-484D-41C6-B070-4242ABCF02B6}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File FirewallRules: [{CB4C1BD0-0247-456F-91E8-A3072527B86B}] => (Allow) D:\Steam\steamapps\common\Verdun\1914-1918 Series.exe => No File FirewallRules: [{41B22DB9-A973-4451-A273-293A5B5E1AF2}] => (Allow) D:\Steam\steamapps\common\Verdun\1914-1918 Series.exe => No File FirewallRules: [{89E20ED5-972C-4942-BAD0-0B672D35E67E}] => (Block) C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe => No File FirewallRules: [{957B1483-44DD-469B-87E6-5A28C0C2DCAC}] => (Block) C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe => No File FirewallRules: [UDP Query User{C8F700F1-559B-44DA-8F94-E4A7EFBA07E1}C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe => No File FirewallRules: [TCP Query User{F8E5D76D-3E8F-4A80-A9F0-2B18932FDD26}C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe => No File FirewallRules: [{ADCAE1C6-4D68-48BA-B199-96B342AEA5A8}] => (Allow) D:\Steam\steamapps\common\Verdun\Verdun.exe => No File FirewallRules: [{2D713057-F444-4F67-AF6B-F3D2A4A21A31}] => (Allow) D:\Steam\steamapps\common\Verdun\Verdun.exe => No File FirewallRules: [{82DD7F3C-F29F-42F4-986C-D541B852C2D5}] => (Block) D:\steam\steamapps\common\elite dangerous\products\elite-dangerous-64\elitedangerous64.exe => No File FirewallRules: [{FF4CF0A8-3A13-4A22-9E70-CB522A889417}] => (Block) D:\steam\steamapps\common\elite dangerous\products\elite-dangerous-64\elitedangerous64.exe => No File FirewallRules: [UDP Query User{8D5E225F-15D6-434E-90B7-DE2D084C084E}D:\steam\steamapps\common\elite dangerous\products\elite-dangerous-64\elitedangerous64.exe] => (Allow) D:\steam\steamapps\common\elite dangerous\products\elite-dangerous-64\elitedangerous64.exe => No File FirewallRules: [TCP Query User{6FE94BD7-8A2B-4DD9-9BF6-F64FCBEE5229}D:\steam\steamapps\common\elite dangerous\products\elite-dangerous-64\elitedangerous64.exe] => (Allow) D:\steam\steamapps\common\elite dangerous\products\elite-dangerous-64\elitedangerous64.exe => No File FirewallRules: [UDP Query User{AA74BEE4-B506-4C40-AAFA-BC9EF0410423}E:\program files 2\thehunter call of the wild\thehuntercotw_f.exe] => (Block) E:\program files 2\thehunter call of the wild\thehuntercotw_f.exe => No File FirewallRules: [TCP Query User{3506CCFC-70EB-405A-85FE-E4F02788A714}E:\program files 2\thehunter call of the wild\thehuntercotw_f.exe] => (Block) E:\program files 2\thehunter call of the wild\thehuntercotw_f.exe => No File FirewallRules: [{43C819DC-2C3C-4B5B-BE5E-3C43EF7DE231}] => (Allow) D:\Steam\steamapps\common\Rust\Rust.exe => No File FirewallRules: [{A990FD77-4FE7-45A8-8997-4C1EF0B49225}] => (Allow) D:\Steam\steamapps\common\Rust\Rust.exe => No File FirewallRules: [{996B76FD-C5E1-4893-884A-4E288E5A954A}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe => No File FirewallRules: [{5655334B-46A8-4CBF-A272-B3AF78082B36}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe => No File FirewallRules: [UDP Query User{6C0513EB-97E7-4CAE-B51E-F853DF4D20FA}D:\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [TCP Query User{DEA1AD2D-771D-4BD4-A933-6D280FCDC107}D:\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [{F4CD125F-84D1-4DA8-8467-2B1ABEC2FED6}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File FirewallRules: [{5B235CD2-CCEA-4EC4-BF2F-81D19379529B}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File FirewallRules: [{AB07E50D-4407-4B4A-A791-3E3E953B9EA0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ArtOfWar\game\u1game.exe => No File FirewallRules: [{7048BB85-B156-48F8-8973-4BBF5FC2C446}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ArtOfWar\game\u1game.exe => No File FirewallRules: [{3279C583-A3C8-4B54-B0D2-C1D9920495A7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Scrap Mechanic\Release\ScrapMechanic.exe => No File FirewallRules: [{F51D5D87-C773-4D81-9EC4-179D8723BB01}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Scrap Mechanic\Release\ScrapMechanic.exe => No File FirewallRules: [{5EB1616F-B468-4CAA-A149-2A0B1BE0A7DA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Company of Heroes Relaunch\RelicCOH.exe => No File FirewallRules: [{BAC95496-0971-44E3-ABFE-295A8F88F184}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Company of Heroes Relaunch\RelicCOH.exe => No File FirewallRules: [{61CC8A71-AC10-465B-8587-5F4A3C2A8A30}] => (Block) C:\program files (x86)\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [{F77314B8-7140-4743-A165-1849E2CCB5BF}] => (Block) C:\program files (x86)\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [UDP Query User{DB070760-66EF-4731-871F-2EF57EE48164}C:\program files (x86)\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [TCP Query User{2BFE8823-B55B-4FE8-83D4-CB968BB68068}C:\program files (x86)\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [{06AEA3FD-7636-4CB3-880C-41BCC51859B5}] => (Block) C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [{57FA92BD-FD01-4956-B310-7D73805B4849}] => (Block) C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [UDP Query User{0CC96AE8-739F-4F08-A274-5EE6CA07A080}C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [TCP Query User{F99218E8-7901-45D5-9579-AD9AA9CA2D1C}C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [{D3536C8E-E70A-4EFE-99F6-1035F092E023}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe => No File FirewallRules: [{7B0FCA8D-5FAD-4E6D-A10A-4F57EE9102C4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe => No File FirewallRules: [{1BC62ECF-499B-4560-B23F-023AB0B19155}] => (Block) C:\users\chris\downloads\drlsimulator_1-1-0_win\simulator\drlsimulator.exe => No File FirewallRules: [{475CEA92-6DE6-4A57-A2B0-F1BE8F07E665}] => (Block) C:\users\chris\downloads\drlsimulator_1-1-0_win\simulator\drlsimulator.exe => No File FirewallRules: [UDP Query User{888DE240-B8FF-4876-BDFE-63969EA9D82E}C:\users\chris\downloads\drlsimulator_1-1-0_win\simulator\drlsimulator.exe] => (Allow) C:\users\chris\downloads\drlsimulator_1-1-0_win\simulator\drlsimulator.exe => No File FirewallRules: [TCP Query User{7D5B08AB-8D76-40EB-895F-348090F23C2D}C:\users\chris\downloads\drlsimulator_1-1-0_win\simulator\drlsimulator.exe] => (Allow) C:\users\chris\downloads\drlsimulator_1-1-0_win\simulator\drlsimulator.exe => No File FirewallRules: [{1A7AB9E3-ECD3-4A28-9FBC-615CA2767376}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Company of Heroes 2\RelicCoH2.exe => No File FirewallRules: [{8CBA182D-B840-480D-B85D-7B2700BBC6F3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Company of Heroes 2\RelicCoH2.exe => No File FirewallRules: [{EFE0A40C-28E8-489E-A1C6-946C591772A5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe => No File FirewallRules: [{EFC3199F-3030-49BC-8B63-7158754D04E8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe => No File FirewallRules: [{EF4F2F92-C652-445B-A7F6-A3CD651D4858}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Human Resource Machine\Human Resource Machine.exe => No File FirewallRules: [{10A42548-70DE-4680-A531-1BD41C4763F5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Human Resource Machine\Human Resource Machine.exe => No File FirewallRules: [{E211893C-14BE-4CE9-9C9F-8FD6A1527A25}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Super Hexagon\superhexagon.exe => No File FirewallRules: [{C8E7626B-D6F5-4EA1-9689-84AE08EE12BA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Super Hexagon\superhexagon.exe => No File FirewallRules: [{A9C04852-6723-4AAC-8E0C-B25F0DFA1B4C}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe => No File FirewallRules: [{547EC848-8360-4036-B108-B4677C2C56C4}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe => No File FirewallRules: [{E73659C6-C4BC-40EA-991D-2878F86EC863}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe => No File FirewallRules: [{D832F572-8B3A-4A61-A43D-AB2ED5AC5EB4}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe => No File FirewallRules: [{47A757F9-18D7-44F4-BD27-3C2FB74633D9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe => No File FirewallRules: [{8FA6B67C-1001-477F-A846-923B022716BF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe => No File FirewallRules: [{C852869A-7F5F-4CB4-A62D-468BE3640342}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Age2HD\Launcher.exe => No File FirewallRules: [{E1FAC177-AD93-427F-AFC2-DDAC7194F919}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Age2HD\Launcher.exe => No File FirewallRules: [{04A0FC66-1590-4741-B8C0-50220278444C}] => (Block) C:\users\chris\appdata\local\logmein client\lmiignition.exe => No File FirewallRules: [{F4220300-A1EF-4EC5-826E-6F6D62937BEC}] => (Block) C:\users\chris\appdata\local\logmein client\lmiignition.exe => No File FirewallRules: [UDP Query User{295BB580-B81C-4BEA-A97F-42EC95827AFF}C:\users\chris\appdata\local\logmein client\lmiignition.exe] => (Allow) C:\users\chris\appdata\local\logmein client\lmiignition.exe => No File FirewallRules: [TCP Query User{4E0E9044-21B7-4932-97D0-0A12439330A5}C:\users\chris\appdata\local\logmein client\lmiignition.exe] => (Allow) C:\users\chris\appdata\local\logmein client\lmiignition.exe => No File FirewallRules: [{72471370-D628-42FB-9F8E-F4F2C993EE91}] => (Block) C:\users\chris\appdata\local\temp\igne03.tmp\lmiignition.exe => No File FirewallRules: [{C04C61F7-DF9D-470E-92D8-3C3D81E2CEE9}] => (Block) C:\users\chris\appdata\local\temp\igne03.tmp\lmiignition.exe => No File FirewallRules: [UDP Query User{CC80D406-93C0-4D66-86D5-65AA02539FBA}C:\users\chris\appdata\local\temp\igne03.tmp\lmiignition.exe] => (Allow) C:\users\chris\appdata\local\temp\igne03.tmp\lmiignition.exe => No File FirewallRules: [TCP Query User{4A9F604E-C85F-4FAC-9566-56EC7071F08C}C:\users\chris\appdata\local\temp\igne03.tmp\lmiignition.exe] => (Allow) C:\users\chris\appdata\local\temp\igne03.tmp\lmiignition.exe => No File FirewallRules: [{D0C9BBFE-8162-474C-8D4B-B1192E627F6D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Istrolid\istrolid.exe => No File FirewallRules: [{17D4F2B8-928A-41CD-B746-1AA50B99DE26}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Istrolid\istrolid.exe => No File FirewallRules: [UDP Query User{71F34166-07E0-48AE-949C-E6F153FE3B17}C:\program files (x86)\steam\steamapps\common\artofwar\game\u1game.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\artofwar\game\u1game.exe => No File FirewallRules: [TCP Query User{E4252D00-D41E-4957-A381-B9DA4776B16F}C:\program files (x86)\steam\steamapps\common\artofwar\game\u1game.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\artofwar\game\u1game.exe => No File FirewallRules: [{EB37B5B8-FA3A-4196-9B58-DB827453CC1B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ArtOfWar\gslaunchershell.exe => No File FirewallRules: [{B8881C05-0D95-4CC4-89A8-A5FEE0E8B6E5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ArtOfWar\gslaunchershell.exe => No File FirewallRules: [{C3291BB4-7C20-45A4-B395-088D4E1E1FAB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Team Fortress 2\hl2.exe => No File FirewallRules: [{283EA7C5-063F-4E4B-A941-63750B649FFE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Team Fortress 2\hl2.exe => No File FirewallRules: [{A352D031-2F2F-49A1-894F-66E0B2A31C56}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe => No File FirewallRules: [{A7F10381-EC40-45FD-802A-A0AF11DBDE59}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe => No File FirewallRules: [{49B749F8-85B7-4AEA-A60E-05F36FBD5CDB}] => (Block) C:\program files (x86)\world_of_tanks\worldoftanks.exe => No File FirewallRules: [{B1FE41E9-8072-4538-8BE4-E6AEBE4D3CA2}] => (Block) C:\program files (x86)\world_of_tanks\worldoftanks.exe => No File FirewallRules: [UDP Query User{0F1D9A09-6B15-4FAF-9B99-27009ED2514A}C:\program files (x86)\world_of_tanks\worldoftanks.exe] => (Allow) C:\program files (x86)\world_of_tanks\worldoftanks.exe => No File FirewallRules: [TCP Query User{755BF8E5-3D41-4B52-9F44-9012BDE921F1}C:\program files (x86)\world_of_tanks\worldoftanks.exe] => (Allow) C:\program files (x86)\world_of_tanks\worldoftanks.exe => No File FirewallRules: [{09F26904-8BA0-49F1-92B6-47FE6DA338B8}] => (Block) C:\program files (x86)\world_of_tanks\wotlauncher.exe => No File FirewallRules: [{4B0F05DF-8930-49B0-AA0C-AF649815CE4D}] => (Block) C:\program files (x86)\world_of_tanks\wotlauncher.exe => No File FirewallRules: [UDP Query User{3597DD36-B505-4F73-9707-4B55C4158769}C:\program files (x86)\world_of_tanks\wotlauncher.exe] => (Allow) C:\program files (x86)\world_of_tanks\wotlauncher.exe => No File FirewallRules: [TCP Query User{A4FC6980-35F1-4DB9-867F-28EB9A049075}C:\program files (x86)\world_of_tanks\wotlauncher.exe] => (Allow) C:\program files (x86)\world_of_tanks\wotlauncher.exe => No File FirewallRules: [{2A989C57-4F1A-4449-A19D-5587DA205E2D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Rust\Rust.exe => No File FirewallRules: [{A4127850-2882-478F-8AA1-0099727F04A5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Rust\Rust.exe => No File FirewallRules: [{F4AA1FBC-AD26-49A5-8728-E10A18BB6065}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Verdun\Verdun.exe => No File FirewallRules: [{4BC4B1D1-9CC7-47D4-BD8C-4B6FC20423C3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Verdun\Verdun.exe => No File FirewallRules: [UDP Query User{76C6AEBC-41C3-4511-8CCE-AE4FB8719365}C:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe => No File FirewallRules: [TCP Query User{A24EAA6B-2ACC-4962-8788-9807BD90AA9D}C:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe => No File FirewallRules: [{10674973-3BAD-441E-865C-E1FC889C750A}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe => No File FirewallRules: [UDP Query User{EA77B0E0-9A97-465D-9AD9-E98A7AD151DD}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe => No File FirewallRules: [TCP Query User{E6B2263C-1448-4C17-91F6-CA2B3CEA03CF}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe => No File FirewallRules: [{ED825DCC-2AC3-4C06-9B63-790412937755}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File FirewallRules: [{E64DFA69-C727-450D-BCDB-03981F78F7A5}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File FirewallRules: [{9A3D465A-A55F-4B69-9C32-DCD0CEEEF913}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File FirewallRules: [{E3EE10C9-9853-48A0-BFA9-33D51CDB0D4C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File FirewallRules: [{B375546D-05F2-4A78-91A6-EFC5972FF8A1}] => (Allow) D:\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe => No File FirewallRules: [{3B8E6E34-51A7-46FF-AB97-49F241E046CB}] => (Allow) D:\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe => No File FirewallRules: [{69618827-6FF9-4E6A-9AF9-2F525F3028D0}] => (Allow) D:\Steam\steamapps\common\Call of Duty WWII Beta\s2_mp64_ship.exe => No File FirewallRules: [{DBB93469-BE43-4C29-8CC7-F45CD0D975DD}] => (Allow) D:\Steam\steamapps\common\Call of Duty WWII Beta\s2_mp64_ship.exe => No File FirewallRules: [{85081F5C-39D8-448E-A4CD-CBB072ABDA95}] => (Allow) C:\FastSteam\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe => No File FirewallRules: [{59882FF2-2F2B-4F4D-BEF9-35DBE2D0EF46}] => (Allow) C:\FastSteam\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe => No File FirewallRules: [TCP Query User{33E6D715-3851-4D90-A288-9CD5E7A09682}C:\faststeam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\faststeam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [UDP Query User{E6B743B0-BCA1-4E72-82B0-8087D6F23DD3}C:\faststeam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\faststeam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [{00F062AD-A71D-42BC-84F3-0EC16925B4D5}] => (Block) C:\faststeam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [{B1D5C701-1ECD-4E07-9139-F602703CE4DD}] => (Block) C:\faststeam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [TCP Query User{03A354BB-9BA1-49D8-99C9-219E4F5248AA}C:\program files (x86)\destiny 2\destiny2.exe] => (Allow) C:\program files (x86)\destiny 2\destiny2.exe => No File FirewallRules: [UDP Query User{37E65E96-3123-4B67-AC14-7651BCA5C7B6}C:\program files (x86)\destiny 2\destiny2.exe] => (Allow) C:\program files (x86)\destiny 2\destiny2.exe => No File FirewallRules: [{4D2E6786-6282-4910-B398-C23FFCCD024C}] => (Block) C:\program files (x86)\destiny 2\destiny2.exe => No File FirewallRules: [{8A916D7A-B4AA-4ECF-9716-F5B5FE417B64}] => (Block) C:\program files (x86)\destiny 2\destiny2.exe => No File FirewallRules: [TCP Query User{620FD3EC-E4E5-46B4-95A9-66C943DD2B95}C:\program files (x86)\battle.net\battle.net.9526\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.9526\battle.net.exe => No File FirewallRules: [UDP Query User{2A45F541-6B7F-4124-8CF1-85C05BC7CC36}C:\program files (x86)\battle.net\battle.net.9526\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.9526\battle.net.exe => No File FirewallRules: [{756E1789-3937-41D8-9681-908A15E65B0A}] => (Block) C:\program files (x86)\battle.net\battle.net.9526\battle.net.exe => No File FirewallRules: [{7076FBD9-1F0C-416A-9725-91609DAC6EC5}] => (Block) C:\program files (x86)\battle.net\battle.net.9526\battle.net.exe => No File FirewallRules: [{50BBD2D6-C444-4374-B996-E895F6B6AC61}] => (Allow) D:\Steam\steamapps\common\BlockNLoad\Win64\BlockNLoad.exe => No File FirewallRules: [{2124A350-B1FB-467A-BDC7-9A0734D2D7E7}] => (Allow) D:\Steam\steamapps\common\BlockNLoad\Win64\BlockNLoad.exe => No File FirewallRules: [{771759CA-6F31-4109-A1C5-A4D2027DF48D}] => (Allow) D:\Steam\steamapps\common\SmallWorld2\SW2Executable.app\Contents\Win32\SW2Executable.exe => No File FirewallRules: [{0F1955D3-EBCB-4B95-A20E-8403F7ED69A8}] => (Allow) D:\Steam\steamapps\common\SmallWorld2\SW2Executable.app\Contents\Win32\SW2Executable.exe => No File FirewallRules: [TCP Query User{314B7494-8312-4F7A-A68E-326EBDB1520D}D:\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [UDP Query User{8A468629-D59E-49C4-92B4-8FAF6C04962A}D:\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [{56553BD8-420A-4089-AEB3-8916950195C3}] => (Block) D:\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [{56BF00B9-080E-4AB7-8892-822C577DDF77}] => (Block) D:\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [TCP Query User{43E58D81-38D6-42A8-942F-C748CD25B86E}E:\grand theft auto v\gta5.exe] => (Block) E:\grand theft auto v\gta5.exe => No File FirewallRules: [UDP Query User{35DB97B3-05DC-4631-A8DD-D8E4DE5D622B}E:\grand theft auto v\gta5.exe] => (Block) E:\grand theft auto v\gta5.exe => No File FirewallRules: [{64348426-229A-483C-851F-D4A3008F6C62}] => (Block) E:\grand theft auto v\gta5.exe => No File FirewallRules: [{380B0EA6-555F-4F73-9DEE-A102E7645552}] => (Block) E:\grand theft auto v\gta5.exe => No File FirewallRules: [TCP Query User{47548C33-BB2D-43FE-B7A9-B489DA542CE3}E:\battle.net starcraft2\call of duty black ops 4\blackops4.exe] => (Allow) E:\battle.net starcraft2\call of duty black ops 4\blackops4.exe => No File FirewallRules: [UDP Query User{09CB4145-95B3-4865-B604-83F7207DBB3A}E:\battle.net starcraft2\call of duty black ops 4\blackops4.exe] => (Allow) E:\battle.net starcraft2\call of duty black ops 4\blackops4.exe => No File FirewallRules: [{48C41615-E11E-4676-AA90-5A2C2F823E88}] => (Block) E:\battle.net starcraft2\call of duty black ops 4\blackops4.exe => No File FirewallRules: [{AA3525AE-8070-4D1E-8026-21A1AB2D7CFD}] => (Block) E:\battle.net starcraft2\call of duty black ops 4\blackops4.exe => No File FirewallRules: [{82B9F67F-C71D-489E-BD38-DF3ECE55264E}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File FirewallRules: [{DB8F80F8-1CDD-489B-BC88-AB12D1430F30}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File FirewallRules: [{D7B9EF5F-E8FF-46AB-95AD-C4C83176A9D2}] => (Allow) C:\FastSteam\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe => No File FirewallRules: [{D7275D10-1917-4C76-8085-EDB0C2284342}] => (Allow) C:\FastSteam\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe => No File FirewallRules: [TCP Query User{9DAEF941-35B6-40E6-886B-5DC70FB39B35}C:\games\cncnet\tiberiandawn_online\cnc95.exe] => (Allow) C:\games\cncnet\tiberiandawn_online\cnc95.exe => No File FirewallRules: [UDP Query User{558A6A35-2454-4169-80CF-867C79169C68}C:\games\cncnet\tiberiandawn_online\cnc95.exe] => (Allow) C:\games\cncnet\tiberiandawn_online\cnc95.exe => No File FirewallRules: [{4D4A9440-39F4-45F5-A7B5-08E560062F17}] => (Block) C:\games\cncnet\tiberiandawn_online\cnc95.exe => No File FirewallRules: [{AADDB3C6-04AE-49E2-A8B1-C7A482F52206}] => (Block) C:\games\cncnet\tiberiandawn_online\cnc95.exe => No File FirewallRules: [TCP Query User{16A73DE4-301E-4E2F-B80E-54B0E3515AEB}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.170\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.170\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{AC248D29-0C79-4D4E-BE31-31F52F8EF198}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.170\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.170\deploy\leagueclient.exe => No File FirewallRules: [{BC5C09FB-7C01-4F53-8D4B-2DC66FEA0DCB}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.170\deploy\leagueclient.exe => No File FirewallRules: [{51C8B5B3-7813-426D-9DC5-E6DDE9BC86D6}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.170\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{E2CBECC8-0F98-49C3-8325-7AED0723BF14}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.171\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.171\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{B4FC1203-FCC1-44DC-BD00-0C865A75E20F}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.171\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.171\deploy\leagueclient.exe => No File FirewallRules: [{E9D67A30-A507-4A67-A8EA-E97043D9353C}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.171\deploy\leagueclient.exe => No File FirewallRules: [{5F83E984-AD73-4EE1-8441-3A006A1D4EF4}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.171\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{6B49E718-C60D-4E99-B05F-9FEF73CE057F}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.172\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.172\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{A53D7A4C-B6C2-4509-BA95-367A185760F0}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.172\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.172\deploy\leagueclient.exe => No File FirewallRules: [{DFE2BEEE-3693-4988-8B95-46DFDF3EC1D1}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.172\deploy\leagueclient.exe => No File FirewallRules: [{8D1636FC-97D9-4683-9442-667DEFD4B760}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.172\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{52F8C7E3-F2B0-4BE7-808F-E2F513465421}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.174\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.174\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{B965A9D2-638C-440F-BF55-15EECCA0E42D}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.174\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.174\deploy\leagueclient.exe => No File FirewallRules: [{72997DCF-B9C3-4747-8B01-A15D2A02C855}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.174\deploy\leagueclient.exe => No File FirewallRules: [{E5C0D99D-BBFA-43A7-BC5F-B800FDEDFE4B}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.174\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{43F7A608-7CDC-433C-B3BD-1E6F9E0D4F4E}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.175\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.175\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{E6EAD4E1-1BB7-4BFA-98D6-2F4C2E186065}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.175\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.175\deploy\leagueclient.exe => No File FirewallRules: [{5D505FCE-AB11-4C9B-83AF-8C5E3DD17A5B}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.175\deploy\leagueclient.exe => No File FirewallRules: [{6F36ECA9-3C3D-4614-AA33-FBDCD642B959}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.175\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{F28F43CD-DA61-44CA-ADCB-82E7BBFF815F}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.176\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.176\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{6DD91F8A-3E98-4C03-BCE6-E08152BC22AF}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.176\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.176\deploy\leagueclient.exe => No File FirewallRules: [{D38F3602-C149-4DF0-A506-744FDF69CF0E}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.176\deploy\leagueclient.exe => No File FirewallRules: [{2F65A196-2F06-483E-879A-ACAA5A8D25D6}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.176\deploy\leagueclient.exe => No File FirewallRules: [{6C68EEDF-865B-4061-9C7A-8C2C86BF19C2}] => (Block) C:\Program Files (x86)\RealFlight7\Launcher7.exe => No File FirewallRules: [TCP Query User{D35B0729-56D5-4F67-80BA-A06CA9744610}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.177\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.177\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{2605037A-A8C5-422F-9EA3-440F61A584CE}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.177\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.177\deploy\leagueclient.exe => No File FirewallRules: [{4E9F97E7-4169-40A0-8022-455728E83871}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.177\deploy\leagueclient.exe => No File FirewallRules: [{1597D6DF-3521-4FFD-BFA6-6E686612BF8D}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.177\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{E0595E94-4FB2-4C04-BD4E-0F56C92F60AC}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.178\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.178\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{15E6DE3B-8C74-4F33-843F-4FE5A1AF9660}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.178\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.178\deploy\leagueclient.exe => No File FirewallRules: [{239F03B2-99B3-48D7-A3E2-88C898A2935B}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.178\deploy\leagueclient.exe => No File FirewallRules: [{FF0A7A95-28ED-4735-A2A3-AA834B6C53FB}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.178\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{5CE298A4-F384-47DF-A3C4-4608D23A8454}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.179\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.179\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{FD422FA0-B935-456D-958D-7B07DB6BB041}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.179\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.179\deploy\leagueclient.exe => No File FirewallRules: [{7D870AA1-E496-4308-B252-DC27D5E24F16}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.179\deploy\leagueclient.exe => No File FirewallRules: [{181E2777-F585-478A-B633-5324395580C6}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.179\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{E48A071F-7F3C-4833-802C-EF3560D378F7}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.181\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.181\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{44C71A1F-92F5-46FA-8F32-BF95776B2F9D}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.181\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.181\deploy\leagueclient.exe => No File FirewallRules: [{347491C2-D573-41B6-815D-1A93F9E47423}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.181\deploy\leagueclient.exe => No File FirewallRules: [{EDB5039A-5ECF-4ABE-B9F7-A903FEDCDD8D}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.181\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{D36363D6-88CC-4FEE-A81A-B59F09B0D551}H:\battlenet2\call of duty black ops 4\blackops4.exe] => (Allow) H:\battlenet2\call of duty black ops 4\blackops4.exe => No File FirewallRules: [UDP Query User{201D6E04-0D2C-4606-A7E6-F4C9A090A278}H:\battlenet2\call of duty black ops 4\blackops4.exe] => (Allow) H:\battlenet2\call of duty black ops 4\blackops4.exe => No File FirewallRules: [{7C091377-E512-4534-B126-5280FFBCE386}] => (Block) H:\battlenet2\call of duty black ops 4\blackops4.exe => No File FirewallRules: [{E9B02F90-CF5D-4325-8CF9-0B110B5D8A93}] => (Block) H:\battlenet2\call of duty black ops 4\blackops4.exe => No File FirewallRules: [TCP Query User{0C1BD479-A64A-4971-BF9C-1340F8DF5759}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.182\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.182\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{F328FE04-2F29-46EA-A514-427FCF1AADA6}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.182\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.182\deploy\leagueclient.exe => No File FirewallRules: [{8E5F1A6B-18A0-4A42-B53A-E2BF9EA5B548}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.182\deploy\leagueclient.exe => No File FirewallRules: [{701280FE-B48F-427E-A99C-B79E454A6ABD}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.182\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{E868D2E0-6E9A-4820-AB2E-011018F72794}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.183\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.183\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{925C6DCD-1458-417F-970E-C7D3F9DFE31E}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.183\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.183\deploy\leagueclient.exe => No File FirewallRules: [{02806AFD-5BFF-4147-9C26-B9BBEB138A69}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.183\deploy\leagueclient.exe => No File FirewallRules: [{BE596EBF-AE7A-4A22-8F44-783635AB8A63}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.183\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{91E7B96B-3067-47CD-8C5E-94126CB3E5E1}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.184\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.184\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{7599665D-9BA1-475A-8340-3D162B19FEE7}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.184\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.184\deploy\leagueclient.exe => No File FirewallRules: [{93A844D9-A846-42FB-9CB1-760C3940D501}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.184\deploy\leagueclient.exe => No File FirewallRules: [{7640CE26-40C4-466A-9FB3-C2663BB3F03B}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.184\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{830D8439-F0C1-4B78-A3FC-E6EDEBBA4BD9}H:\originlibrary\apex\r5apex.exe] => (Allow) H:\originlibrary\apex\r5apex.exe => No File FirewallRules: [UDP Query User{5AB10C51-5E37-491A-8FC4-28CD4FB84CB0}H:\originlibrary\apex\r5apex.exe] => (Allow) H:\originlibrary\apex\r5apex.exe => No File FirewallRules: [TCP Query User{F59165E0-7229-4E0E-8A8B-934A67123897}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.185\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.185\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{DF8852B1-91F0-49A2-86E8-926B70736575}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.185\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.185\deploy\leagueclient.exe => No File FirewallRules: [{4760368E-B96F-4D2C-8838-9688A097F3B1}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.185\deploy\leagueclient.exe => No File FirewallRules: [{492230B0-2F79-4E00-82D5-29FCEB437C06}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.185\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{B6452F3F-9F41-486A-80DC-3C4CEDC64CA3}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.186\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.186\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{132AFD47-1503-4465-AD33-FE404AFFDDB0}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.186\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.186\deploy\leagueclient.exe => No File FirewallRules: [{9B50E59B-6619-4F9A-AC76-E7FEF177D74E}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.186\deploy\leagueclient.exe => No File FirewallRules: [{329973D3-7298-4705-9F23-5C24F8199FC0}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.186\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{25ACDC4A-BD58-4997-940A-1A1F6183A219}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.187\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.187\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{BCCE5B29-516B-418A-989A-B0FE5D1C2FE2}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.187\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.187\deploy\leagueclient.exe => No File FirewallRules: [{758DE3D3-EDB6-4C87-8080-84674AAE0348}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.187\deploy\leagueclient.exe => No File FirewallRules: [{7FC4FB3E-1C54-41D3-AA24-AFBD1EED4576}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.187\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{12272F77-FEC0-4B9F-9A1E-7656C44FC9E6}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.188\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.188\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{5F25A6F7-AA97-4CB7-A08C-0AB809666A42}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.188\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.188\deploy\leagueclient.exe => No File FirewallRules: [{368734ED-AC20-447A-9E19-F93746EE8F30}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.188\deploy\leagueclient.exe => No File FirewallRules: [{8CEFA0A6-66D5-4648-8C43-40201ECCD96A}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.188\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{77EA055F-AAE6-499D-9D38-0A0474596431}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.189\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.189\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{5516F991-61A8-414B-95B5-2F4599E04C1D}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.189\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.189\deploy\leagueclient.exe => No File FirewallRules: [{32917626-AF9A-410C-8BFE-39EB018F8436}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.189\deploy\leagueclient.exe => No File FirewallRules: [{B8C7160A-3087-4773-BBE3-0546EE13EB3A}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.189\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{05C2BE1F-D5F3-48DA-9B8E-01A9B3B21D22}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.190\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.190\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{6CA1A6BF-A962-4A47-A08E-2D21B2D6AEC7}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.190\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.190\deploy\leagueclient.exe => No File FirewallRules: [{AB51782E-81EC-4D62-9B1F-D08051D3AB76}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.190\deploy\leagueclient.exe => No File FirewallRules: [{73FA0B83-6090-4252-B83F-B11DB0996F77}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.190\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{91C72047-80A9-40BA-A7DE-5935D3BAE37C}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.191\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.191\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{7487245A-5729-40E8-A73D-D391F48F8C5F}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.191\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.191\deploy\leagueclient.exe => No File FirewallRules: [{E7520542-CCE8-4EC0-AEC6-232AA8307145}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.191\deploy\leagueclient.exe => No File FirewallRules: [{144AAFAB-DE3C-4703-864E-07A469F765FD}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.191\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{E96B4F34-81B0-4842-9B67-3976700A7900}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.192\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.192\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{111D8B00-964E-469F-A72E-18FDCA62CFF1}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.192\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.192\deploy\leagueclient.exe => No File FirewallRules: [{E10D3054-65B9-43CB-BE3C-EFBEB3A6F82F}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.192\deploy\leagueclient.exe => No File FirewallRules: [{436092E2-99CA-4730-BA02-CE3C689115C7}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.192\deploy\leagueclient.exe => No File FirewallRules: [{01E694B1-C961-4F48-B3E5-D80A85760561}] => (Allow) H:\SteamLibrary\steamapps\common\DCL - The Game (Early Demo)\DCGame.exe => No File FirewallRules: [{949640C2-FAA2-41D0-B128-B512BE5FD529}] => (Allow) H:\SteamLibrary\steamapps\common\DCL - The Game (Early Demo)\DCGame.exe => No File FirewallRules: [TCP Query User{C4AC865B-A7A7-4046-9DA8-79D1AB31D400}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.193\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.193\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{71E2D640-6FEC-4145-A17A-06EBC4B0B7F2}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.193\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.193\deploy\leagueclient.exe => No File FirewallRules: [{A7F9E6A5-AE6A-43EE-85AE-13C3DC568E61}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.193\deploy\leagueclient.exe => No File FirewallRules: [{BE123313-288F-4412-9458-2C47EDD7E596}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.193\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{1333A3AB-797F-4AF2-B48B-5B56AACB5E71}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.194\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.194\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{DF739153-7A8D-4196-B938-780BBAD71A21}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.194\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.194\deploy\leagueclient.exe => No File FirewallRules: [{C18E4194-76FF-479A-99E3-89FCE9E09ADD}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.194\deploy\leagueclient.exe => No File FirewallRules: [{C8DCC07C-6DDD-43AB-9E93-A5B6B5CDFAE8}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.194\deploy\leagueclient.exe => No File FirewallRules: [{7CB71D57-BBC1-42AC-A29B-612B7C56BB7C}] => (Allow) H:\OriginLibrary\SimCity\SimCity\SimCity.exe => No File FirewallRules: [{DD32703C-EA13-4578-9D1A-3209D9DD000D}] => (Allow) H:\OriginLibrary\SimCity\SimCity\SimCity.exe => No File FirewallRules: [TCP Query User{F463F124-D94D-4837-90E9-8F1FF6ABAAC3}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.195\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.195\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{CE810608-7118-43F9-ACA2-6159058B6A71}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.195\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.195\deploy\leagueclient.exe => No File FirewallRules: [{4CD41C91-613A-4AE9-A907-314B1690E1F1}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.195\deploy\leagueclient.exe => No File FirewallRules: [{92CF378A-20B2-4237-836B-B209C5ED36B9}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.195\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{86E14352-2F60-4890-88D1-C2DD09FCEA9F}C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe => No File FirewallRules: [UDP Query User{E1175A64-BF46-4052-B489-B2933B9E0FDB}C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe => No File FirewallRules: [{980D6898-22AD-4BC5-82BA-1CC62B666EE6}] => (Block) C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe => No File FirewallRules: [{3D76B9E2-6F30-4FF2-82E0-DAAD27143C99}] => (Block) C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe => No File FirewallRules: [TCP Query User{149D0F4D-4826-4C37-9C18-7F1BBDC28E77}H:\steamlibrary\steamapps\common\war thunder\win64\aces.exe] => (Allow) H:\steamlibrary\steamapps\common\war thunder\win64\aces.exe => No File FirewallRules: [UDP Query User{349D86AD-565C-4093-B154-AE57F58CE281}H:\steamlibrary\steamapps\common\war thunder\win64\aces.exe] => (Allow) H:\steamlibrary\steamapps\common\war thunder\win64\aces.exe => No File FirewallRules: [{B6F6A9A9-5A5B-47B6-B6FE-EE396C7100FB}] => (Block) H:\steamlibrary\steamapps\common\war thunder\win64\aces.exe => No File FirewallRules: [{720114EA-2BEE-4697-A38B-AE003DF42C92}] => (Block) H:\steamlibrary\steamapps\common\war thunder\win64\aces.exe => No File FirewallRules: [TCP Query User{079E0CA5-836A-4A5D-A696-6C79A9E6C993}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.196\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.196\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{FD50BCA6-E053-4275-87D3-EFC485720BE6}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.196\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.196\deploy\leagueclient.exe => No File FirewallRules: [{4B3E8421-ADAF-45E3-99BF-D9A5E3FA9C2C}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.196\deploy\leagueclient.exe => No File FirewallRules: [{A8CB256F-9AD4-4046-80FF-0FE39AC2BCC9}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.196\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{7724EF9C-BFCB-4F01-9F4F-8F2117EDF323}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.197\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.197\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{8CAE6EAF-2D6B-49F8-BA2F-A88FB061A7E5}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.197\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.197\deploy\leagueclient.exe => No File FirewallRules: [{BF0B9A9A-1B56-46FA-A63E-D515C10380DE}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.197\deploy\leagueclient.exe => No File FirewallRules: [{8B6BF072-07FE-4FA2-A1A7-132B75719163}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.197\deploy\leagueclient.exe => No File FirewallRules: [{B0613ADE-6632-455E-A90D-8F6DAB44B133}] => (Allow) C:\Program Files (x86)\Java\jre1.8.0_151\bin\java.exe => No File FirewallRules: [{E88A6AF8-B24C-4700-8B5A-AA7CE9EC7999}] => (Allow) C:\Program Files (x86)\Java\jre1.8.0_151\bin\java.exe => No File FirewallRules: [TCP Query User{50AB699C-9D62-409F-9CC9-EAEA6709F0BC}C:\program files (x86)\java\jre1.8.0_211\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_211\bin\java.exe => No File FirewallRules: [UDP Query User{24744C23-B09D-472A-BD0F-E6257902F654}C:\program files (x86)\java\jre1.8.0_211\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_211\bin\java.exe => No File FirewallRules: [TCP Query User{FBC547DF-D6A6-427C-9C88-990F2B547FA3}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.198\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.198\deploy\leagueclient.exe => No File FirewallRules: [UDP Query User{71692731-2411-45C9-9266-81BC52832BB8}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.198\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.198\deploy\leagueclient.exe => No File FirewallRules: [{14F5B4BD-5AC9-42D2-B14A-73AAF5A35818}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.198\deploy\leagueclient.exe => No File FirewallRules: [{7A05F76F-C738-4DDD-A2BC-DC3747BE9F00}] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.198\deploy\leagueclient.exe => No File FirewallRules: [TCP Query User{2D83B250-EAB9-48EF-B36D-9F57477865D4}C:\riot games\league of legends\leagueclient.exe] => (Allow) C:\riot games\league of legends\leagueclient.exe => No File FirewallRules: [UDP Query User{B0E69640-E72C-4BD7-B076-605A73428D3A}C:\riot games\league of legends\leagueclient.exe] => (Allow) C:\riot games\league of legends\leagueclient.exe => No File FirewallRules: [{554A67A0-7A46-4CCF-863A-269D0F115DE9}] => (Block) C:\riot games\league of legends\leagueclient.exe => No File FirewallRules: [{235DAC34-1F93-440D-BE7B-117A2DDF9CE0}] => (Block) C:\riot games\league of legends\leagueclient.exe => No File FirewallRules: [{1635AA9D-1220-4CE9-8B4D-8C0DD554EA16}] => (Allow) H:\SteamLibrary\steamapps\common\Stellaris\stellaris.exe => No File FirewallRules: [{664DE611-9869-4909-9548-3961918BD04B}] => (Allow) H:\SteamLibrary\steamapps\common\Stellaris\stellaris.exe => No File FirewallRules: [{67E0A0B4-F004-4A3E-832E-7044113AEDF4}] => (Allow) C:\Program Files (x86)\Java\jre1.8.0_211\bin\java.exe => No File FirewallRules: [{070E6478-79ED-41E9-8C53-F3FEAF351448}] => (Allow) C:\Program Files (x86)\Java\jre1.8.0_211\bin\java.exe => No File FirewallRules: [TCP Query User{61EBFAF6-8D1A-496B-8D02-225EB8B05B33}H:\steamlibrary\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe] => (Allow) H:\steamlibrary\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe => No File FirewallRules: [UDP Query User{56C0C8EF-B4E8-42A7-ACD7-F84B61ED211C}H:\steamlibrary\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe] => (Allow) H:\steamlibrary\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe => No File FirewallRules: [{00F7C2E6-1F57-4AEF-BA50-BE04E638DB49}] => (Allow) H:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client.exe => No File FirewallRules: [{D3EE5E80-9050-47E6-B7F2-2017EEFC8236}] => (Allow) H:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client.exe => No File FirewallRules: [{AB4BF25A-D941-4674-A9A2-7BBDAA83F526}] => (Allow) H:\SteamLibrary\steamapps\common\DOF\DOF.exe => No File FirewallRules: [{88BA4FDD-BAB1-473B-B678-DE49C6A7176A}] => (Allow) H:\SteamLibrary\steamapps\common\DOF\DOF.exe => No File FirewallRules: [TCP Query User{D4A9453C-E69F-492B-B0D3-A1DA3A8748CD}C:\users\chris\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\chris\appdata\local\microsoft\teams\current\teams.exe => No File FirewallRules: [UDP Query User{F03B866F-F631-43B1-830D-490527284707}C:\users\chris\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\chris\appdata\local\microsoft\teams\current\teams.exe => No File FirewallRules: [{1ACD4779-1550-42DA-B61E-641F47BA6E15}] => (Allow) H:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client_game.exe => No File FirewallRules: [{A46C4C5C-A28F-4BB0-9F78-7B1B60A63A4D}] => (Allow) H:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client_game.exe => No File FirewallRules: [TCP Query User{94E79E9A-C80C-4E24-AE6F-9DC3FEA93829}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe => No File FirewallRules: [UDP Query User{C7B51BA3-C764-4560-B818-3E46821C40B3}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe => No File FirewallRules: [TCP Query User{8125C627-E48B-4580-8130-B5833B8AF937}H:\steamlibrary\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe] => (Allow) N:\SteamLibrary\steamapps\common\Baldurs Gate 3\Launcher\LariLauncher.exe => No File FirewallRules: [UDP Query User{0E21FED5-21F7-4099-BF9B-F619F15DB46F}H:\steamlibrary\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe] => (Allow) N:\SteamLibrary\steamapps\common\Baldurs Gate 3\Launcher\LariLauncher.exe => No File FirewallRules: [TCP Query User{9015CFE2-B790-4369-91C9-FAB33B16EB84}E:\epicgames\rs2v\binaries\win64\risingstorm2.exe] => (Allow) E:\epicgames\rs2v\binaries\win64\risingstorm2.exe => No File FirewallRules: [UDP Query User{6AC0940C-144C-427C-B42E-DC0B8B0F8F84}E:\epicgames\rs2v\binaries\win64\risingstorm2.exe] => (Allow) E:\epicgames\rs2v\binaries\win64\risingstorm2.exe => No File FirewallRules: [{A90EBC5F-3098-4596-AB7E-6792DC685CE3}] => (Allow) H:\SteamLibrary\steamapps\common\Among Us\Among Us.exe => No File FirewallRules: [{74156678-089A-4907-B8E8-A085C87FD9B7}] => (Allow) H:\SteamLibrary\steamapps\common\Among Us\Among Us.exe => No File FirewallRules: [TCP Query User{0875455F-AF31-467E-A98F-0CE76C9FB999}C:\users\chris\appdata\local\programs\opera\71.0.3770.228\opera.exe] => (Allow) C:\users\chris\appdata\local\programs\opera\71.0.3770.228\opera.exe => No File FirewallRules: [UDP Query User{6E6741B9-F292-4141-A55F-2498C43D9928}C:\users\chris\appdata\local\programs\opera\71.0.3770.228\opera.exe] => (Allow) C:\users\chris\appdata\local\programs\opera\71.0.3770.228\opera.exe => No File FirewallRules: [TCP Query User{3C91B0B2-DF8F-453E-84BB-37840701957C}E:\epicgames\rs2v\binaries\win64\vngame.exe] => (Allow) E:\epicgames\rs2v\binaries\win64\vngame.exe => No File FirewallRules: [UDP Query User{AFD2EB38-1EEE-4298-A759-0DAD528CF0E8}E:\epicgames\rs2v\binaries\win64\vngame.exe] => (Allow) E:\epicgames\rs2v\binaries\win64\vngame.exe => No File FirewallRules: [TCP Query User{7C2742FB-5AB8-44EF-A973-4F565FA7036A}H:\steamlibrary\steamapps\common\planetside 2\planetside2_x64.exe] => (Allow) H:\steamlibrary\steamapps\common\planetside 2\planetside2_x64.exe => No File FirewallRules: [UDP Query User{21057A96-A495-4D8C-9E64-39DA45105631}H:\steamlibrary\steamapps\common\planetside 2\planetside2_x64.exe] => (Allow) H:\steamlibrary\steamapps\common\planetside 2\planetside2_x64.exe => No File FirewallRules: [TCP Query User{87A51007-065D-4C94-98CF-9EB5ED323689}H:\steamlibrary\steamapps\common\baldurs gate 3\bin\bg3.exe] => (Allow) N:\SteamLibrary\steamapps\common\Baldurs Gate 3\bin\bg3.exe => No File FirewallRules: [UDP Query User{EB3BE30D-74A1-4656-B986-78453544BD66}H:\steamlibrary\steamapps\common\baldurs gate 3\bin\bg3.exe] => (Allow) N:\SteamLibrary\steamapps\common\Baldurs Gate 3\bin\bg3.exe => No File FirewallRules: [TCP Query User{9F0B4873-F8D6-40DE-BBDF-BDA0FA8B7594}C:\program files\e2esoft\ivcam\ivcam.exe] => (Allow) C:\program files\e2esoft\ivcam\ivcam.exe => No File FirewallRules: [UDP Query User{17B9CAD2-D387-416A-9B87-4A35731BE6D9}C:\program files\e2esoft\ivcam\ivcam.exe] => (Allow) C:\program files\e2esoft\ivcam\ivcam.exe => No File FirewallRules: [TCP Query User{4BC8A74D-E147-4E67-9598-DB8CC55793BB}C:\program files (x86)\world_of_tanks\win64\worldoftanks.exe] => (Allow) C:\program files (x86)\world_of_tanks\win64\worldoftanks.exe => No File FirewallRules: [UDP Query User{4CA65633-B209-4196-A541-DF86BAD77F23}C:\program files (x86)\world_of_tanks\win64\worldoftanks.exe] => (Allow) C:\program files (x86)\world_of_tanks\win64\worldoftanks.exe => No File FirewallRules: [TCP Query User{48497DCA-1ADD-4509-B03D-9079483B0323}C:\program files\java\jre1.8.0_271\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_271\bin\javaw.exe => No File FirewallRules: [UDP Query User{75E4B069-444A-483C-9BC2-8FFAA43FB50C}C:\program files\java\jre1.8.0_271\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_271\bin\javaw.exe => No File FirewallRules: [{56DF91A6-ED4F-4656-8EB1-00D885D3E826}] => (Allow) H:\SteamLibrary\steamapps\common\Valheim\valheim.exe => No File FirewallRules: [{0765950F-1E2D-4249-AF63-C00D28F26EC0}] => (Allow) H:\SteamLibrary\steamapps\common\Valheim\valheim.exe => No File FirewallRules: [TCP Query User{58DF5EE0-B22E-48BD-8813-F931BDE2AF66}C:\program files\java\jre1.8.0_271\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_271\bin\java.exe => No File FirewallRules: [UDP Query User{364BD755-B441-44FB-AEC5-F975D08C686D}C:\program files\java\jre1.8.0_271\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_271\bin\java.exe => No File FirewallRules: [{31035EDF-E53C-48A0-871F-9BBC0424A215}] => (Allow) C:\Program Files\Java\jre1.8.0_271\bin\java.exe => No File FirewallRules: [{650A5B67-EA42-482F-870C-561A87148FEA}] => (Allow) C:\Program Files\Java\jre1.8.0_271\bin\java.exe => No File FirewallRules: [TCP Query User{DA19CE5D-1738-45FB-9BCA-2874AD0EB902}C:\program files (x86)\java\jre1.8.0_271\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_271\bin\javaw.exe => No File FirewallRules: [UDP Query User{647A6D37-2EB6-4E98-90AD-7C2943A19D18}C:\program files (x86)\java\jre1.8.0_271\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_271\bin\javaw.exe => No File FirewallRules: [TCP Query User{6D5D641A-4D0E-46E5-91F7-4D06F065FAD4}C:\program files (x86)\java\jre1.8.0_271\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_271\bin\java.exe => No File FirewallRules: [UDP Query User{164F60B0-00C8-417B-97AC-C7154F638858}C:\program files (x86)\java\jre1.8.0_271\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_271\bin\java.exe => No File FirewallRules: [TCP Query User{BB9A0B4F-9B5B-457F-AE07-D3E233E70168}C:\users\chris\appdata\local\chia-blockchain\app-1.1.2\resources\app.asar.unpacked\daemon\start_full_node.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.2\resources\app.asar.unpacked\daemon\start_full_node.exe => No File FirewallRules: [UDP Query User{880BEEFD-F7EA-45C6-A0FF-76407C0A1456}C:\users\chris\appdata\local\chia-blockchain\app-1.1.2\resources\app.asar.unpacked\daemon\start_full_node.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.2\resources\app.asar.unpacked\daemon\start_full_node.exe => No File FirewallRules: [TCP Query User{59E6DA55-6051-4785-8B95-1335B2AD0945}C:\users\chris\appdata\local\chia-blockchain\app-1.1.2\resources\app.asar.unpacked\daemon\start_farmer.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.2\resources\app.asar.unpacked\daemon\start_farmer.exe => No File FirewallRules: [UDP Query User{A0E03860-889A-43DE-8B8F-F8046EB85BDC}C:\users\chris\appdata\local\chia-blockchain\app-1.1.2\resources\app.asar.unpacked\daemon\start_farmer.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.2\resources\app.asar.unpacked\daemon\start_farmer.exe => No File FirewallRules: [TCP Query User{53F9AE68-694F-4484-8141-D91B235592BD}C:\users\chris\appdata\local\chia-blockchain\app-1.1.3\resources\app.asar.unpacked\daemon\start_farmer.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.3\resources\app.asar.unpacked\daemon\start_farmer.exe => No File FirewallRules: [UDP Query User{3F1179CA-8F2A-4FD4-BABF-E51E2B02843A}C:\users\chris\appdata\local\chia-blockchain\app-1.1.3\resources\app.asar.unpacked\daemon\start_farmer.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.3\resources\app.asar.unpacked\daemon\start_farmer.exe => No File FirewallRules: [TCP Query User{D6A07371-A51A-4A09-BD7C-68B08D607E6C}C:\users\chris\appdata\local\chia-blockchain\app-1.1.3\resources\app.asar.unpacked\daemon\start_full_node.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.3\resources\app.asar.unpacked\daemon\start_full_node.exe => No File FirewallRules: [UDP Query User{7D09FE69-264F-42FE-A2E0-A8A376E019E9}C:\users\chris\appdata\local\chia-blockchain\app-1.1.3\resources\app.asar.unpacked\daemon\start_full_node.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.3\resources\app.asar.unpacked\daemon\start_full_node.exe => No File FirewallRules: [TCP Query User{30835B6B-61B9-436A-A99A-CF6076AFBBB8}C:\users\chris\appdata\local\chia-blockchain\app-1.1.4\resources\app.asar.unpacked\daemon\start_farmer.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.4\resources\app.asar.unpacked\daemon\start_farmer.exe => No File FirewallRules: [UDP Query User{C5520A7C-65FB-4098-AE37-193371CF5DB2}C:\users\chris\appdata\local\chia-blockchain\app-1.1.4\resources\app.asar.unpacked\daemon\start_farmer.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.4\resources\app.asar.unpacked\daemon\start_farmer.exe => No File FirewallRules: [TCP Query User{53CC2978-7C50-4835-A34D-59A409F0AB31}C:\users\chris\appdata\local\chia-blockchain\app-1.1.4\resources\app.asar.unpacked\daemon\start_full_node.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.4\resources\app.asar.unpacked\daemon\start_full_node.exe => No File FirewallRules: [UDP Query User{B406CCF4-F26F-4927-B21E-2B60D2C14411}C:\users\chris\appdata\local\chia-blockchain\app-1.1.4\resources\app.asar.unpacked\daemon\start_full_node.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.4\resources\app.asar.unpacked\daemon\start_full_node.exe => No File FirewallRules: [TCP Query User{03F0085D-EB90-4CD2-986E-16A9C5E0EBFF}C:\users\chris\appdata\local\chia-blockchain\app-1.1.5\resources\app.asar.unpacked\daemon\start_farmer.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.5\resources\app.asar.unpacked\daemon\start_farmer.exe => No File FirewallRules: [UDP Query User{10476BE8-2F4B-4446-B376-AE6B708172D6}C:\users\chris\appdata\local\chia-blockchain\app-1.1.5\resources\app.asar.unpacked\daemon\start_farmer.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.5\resources\app.asar.unpacked\daemon\start_farmer.exe => No File FirewallRules: [TCP Query User{912839D1-28D7-4664-88FF-E75D3BAB68AA}C:\users\chris\appdata\local\chia-blockchain\app-1.1.5\resources\app.asar.unpacked\daemon\start_full_node.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.5\resources\app.asar.unpacked\daemon\start_full_node.exe => No File FirewallRules: [UDP Query User{E1F34EFD-FCBC-49E1-9901-CB20F32634D1}C:\users\chris\appdata\local\chia-blockchain\app-1.1.5\resources\app.asar.unpacked\daemon\start_full_node.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.5\resources\app.asar.unpacked\daemon\start_full_node.exe => No File FirewallRules: [TCP Query User{7F93B356-48B5-4DBC-8BE8-C62C9F1A9B97}C:\users\chris\appdata\local\chia-blockchain\app-1.1.6\resources\app.asar.unpacked\daemon\start_farmer.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.6\resources\app.asar.unpacked\daemon\start_farmer.exe => No File FirewallRules: [UDP Query User{BC9C58EE-04C3-48D0-98E7-687067088137}C:\users\chris\appdata\local\chia-blockchain\app-1.1.6\resources\app.asar.unpacked\daemon\start_farmer.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.6\resources\app.asar.unpacked\daemon\start_farmer.exe => No File FirewallRules: [TCP Query User{F2F73290-903E-4841-ABD1-2F91DFC9F38D}C:\users\chris\appdata\local\chia-blockchain\app-1.1.6\resources\app.asar.unpacked\daemon\start_full_node.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.6\resources\app.asar.unpacked\daemon\start_full_node.exe => No File FirewallRules: [UDP Query User{295A2A39-5640-4CCA-B713-2DB06DC30D83}C:\users\chris\appdata\local\chia-blockchain\app-1.1.6\resources\app.asar.unpacked\daemon\start_full_node.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.1.6\resources\app.asar.unpacked\daemon\start_full_node.exe => No File FirewallRules: [TCP Query User{2224B6E3-C459-4E00-BE22-9010A4DB9167}D:\steam\steamapps\common\knockoutcity\knockoutcity.exe] => (Allow) D:\steam\steamapps\common\knockoutcity\knockoutcity.exe => No File FirewallRules: [UDP Query User{5ADADFAF-6E7B-4696-AEAD-4B7BD323B37E}D:\steam\steamapps\common\knockoutcity\knockoutcity.exe] => (Allow) D:\steam\steamapps\common\knockoutcity\knockoutcity.exe => No File FirewallRules: [TCP Query User{907189FD-B640-43B6-922C-7C8D08D0903E}H:\steamlibrary\steamapps\common\conan exiles\conansandbox\binaries\win64\conansandbox.exe] => (Allow) H:\steamlibrary\steamapps\common\conan exiles\conansandbox\binaries\win64\conansandbox.exe => No File FirewallRules: [UDP Query User{3BABE9B4-8C5F-4BC1-9F02-91A38D66920B}H:\steamlibrary\steamapps\common\conan exiles\conansandbox\binaries\win64\conansandbox.exe] => (Allow) H:\steamlibrary\steamapps\common\conan exiles\conansandbox\binaries\win64\conansandbox.exe => No File FirewallRules: [{96466812-AB46-4A2C-A01B-D3D7E741DDCD}] => (Allow) H:\SteamLibrary\steamapps\common\No Man's Sky\Binaries\NMS.exe => No File FirewallRules: [{19A2E8CB-F3CF-4E4E-AA9B-82BCBEC20B87}] => (Allow) H:\SteamLibrary\steamapps\common\No Man's Sky\Binaries\NMS.exe => No File FirewallRules: [{7AA67F19-B9EC-465C-8087-10D1AD7D4F04}] => (Allow) H:\SteamLibrary\steamapps\common\WW1GameSeries\Verdun\Verdun.exe => No File FirewallRules: [{25C6869B-8EB4-46A0-B527-D4267A4B329D}] => (Allow) H:\SteamLibrary\steamapps\common\WW1GameSeries\Verdun\Verdun.exe => No File FirewallRules: [{36E709B2-FBEB-4AB2-BB4F-0434A4EB70A1}] => (Allow) D:\Steam\steamapps\common\Company of Heroes 3 - Pre-Alpha Preview\RelicAnvil.exe => No File FirewallRules: [{2BFB0174-59A2-4FD6-B67D-48CF68393180}] => (Allow) D:\Steam\steamapps\common\Company of Heroes 3 - Pre-Alpha Preview\RelicAnvil.exe => No File FirewallRules: [TCP Query User{97C52ECB-97A2-40E0-886C-B1A7EC803202}C:\users\chris\appdata\local\programs\opera\77.0.4054.277\opera.exe] => (Allow) C:\users\chris\appdata\local\programs\opera\77.0.4054.277\opera.exe => No File FirewallRules: [UDP Query User{C46BC292-1AF9-42B4-9E44-EC0A9010863C}C:\users\chris\appdata\local\programs\opera\77.0.4054.277\opera.exe] => (Allow) C:\users\chris\appdata\local\programs\opera\77.0.4054.277\opera.exe => No File FirewallRules: [{F5A1CEA1-7F0F-41D7-AD22-A8919910E2E6}] => (Allow) D:\Steam\steamapps\common\Splitgate\PortalWars\Binaries\Win64\PortalWars-Win64-Shipping.exe => No File FirewallRules: [{8DEE35D8-787E-4849-B72D-89D75E13DEB1}] => (Allow) D:\Steam\steamapps\common\Splitgate\PortalWars\Binaries\Win64\PortalWars-Win64-Shipping.exe => No File FirewallRules: [TCP Query User{277EFF5E-BEA4-4242-880B-A9F3F0F5F865}D:\steam\steamapps\common\age of empires iv beta\reliccardinal.exe] => (Allow) D:\steam\steamapps\common\age of empires iv beta\reliccardinal.exe => No File FirewallRules: [UDP Query User{6EB34DD8-0E88-41C7-B3E5-372915AED49A}D:\steam\steamapps\common\age of empires iv beta\reliccardinal.exe] => (Allow) D:\steam\steamapps\common\age of empires iv beta\reliccardinal.exe => No File FirewallRules: [TCP Query User{B962E0AE-AD85-4EF3-8D09-0B03C7284A9C}H:\steamlibrary\steamapps\common\battlefield 2042 open beta\bf.exe] => (Allow) H:\steamlibrary\steamapps\common\battlefield 2042 open beta\bf.exe => No File FirewallRules: [UDP Query User{0CDF0C44-66FE-4104-A0F3-8174318B91FE}H:\steamlibrary\steamapps\common\battlefield 2042 open beta\bf.exe] => (Allow) H:\steamlibrary\steamapps\common\battlefield 2042 open beta\bf.exe => No File FirewallRules: [{0A174CE9-AE50-4A0B-A580-378CDEB28022}] => (Allow) H:\SteamLibrary\steamapps\common\Battlefield 2042 Open Beta\BF2042_launcher.exe => No File FirewallRules: [{99F6939C-994E-4EB8-82C8-941915729913}] => (Allow) H:\SteamLibrary\steamapps\common\Battlefield 2042 Open Beta\BF2042_launcher.exe => No File FirewallRules: [TCP Query User{4820BAE1-65B9-4F15-B505-94325A8748B5}C:\program files\java\jre1.8.0_281\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_281\bin\javaw.exe => No File FirewallRules: [UDP Query User{59BF7B6B-13D0-4231-9704-920D548BC77C}C:\program files\java\jre1.8.0_281\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_281\bin\javaw.exe => No File FirewallRules: [TCP Query User{12D88737-90BE-4485-AA45-7204ED4A83AA}C:\program files\java\jre1.8.0_281\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_281\bin\java.exe => No File FirewallRules: [UDP Query User{46EF3DF0-C68D-47AE-B0E7-714E336F6709}C:\program files\java\jre1.8.0_281\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_281\bin\java.exe => No File FirewallRules: [TCP Query User{31975040-3DA7-4DAD-B6F3-4DAD25B662FF}C:\riot games\riot client\riotclientservices.exe] => (Allow) C:\riot games\riot client\riotclientservices.exe => No File FirewallRules: [UDP Query User{7268CDEC-6557-46B7-9278-1A6DB9352356}C:\riot games\riot client\riotclientservices.exe] => (Allow) C:\riot games\riot client\riotclientservices.exe => No File FirewallRules: [TCP Query User{9ECD27F3-DB19-4C4F-950A-EAEB7CF0225F}C:\program files\java\jre1.8.0_321\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_321\bin\javaw.exe => No File FirewallRules: [UDP Query User{13A6F9BC-6FB0-4CA4-A0D7-DC1976C1C3E8}C:\program files\java\jre1.8.0_321\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_321\bin\javaw.exe => No File FirewallRules: [TCP Query User{F3AA3CE2-5044-4FB4-B214-A029E9513545}C:\program files\java\jre1.8.0_321\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_321\bin\java.exe => No File FirewallRules: [UDP Query User{0B749EC8-46FE-47C2-92DA-EFF87A88740F}C:\program files\java\jre1.8.0_321\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_321\bin\java.exe => No File FirewallRules: [TCP Query User{582D7B45-D4A6-41D3-AE39-78F78D7C3DD1}L:\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) L:\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [UDP Query User{DAEE61EF-1E21-46A0-95C8-F90810951AF6}L:\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) L:\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [{D030343F-61DF-4182-9F4F-C20F3FDE37F1}] => (Allow) D:\Steam\steamapps\common\MultiVersus\start_protected_game.exe => No File FirewallRules: [{F6A24A49-D383-44E3-9DDB-BB8C370514E1}] => (Allow) D:\Steam\steamapps\common\MultiVersus\start_protected_game.exe => No File FirewallRules: [TCP Query User{2C779173-BE2E-4552-BDCD-048336AFFA06}N:\steamlibrary\steamapps\common\age of empires iv\reliccardinal.exe] => (Allow) N:\steamlibrary\steamapps\common\age of empires iv\reliccardinal.exe => No File FirewallRules: [UDP Query User{187186C0-CF2B-4360-862E-C0D20032BA6B}N:\steamlibrary\steamapps\common\age of empires iv\reliccardinal.exe] => (Allow) N:\steamlibrary\steamapps\common\age of empires iv\reliccardinal.exe => No File FirewallRules: [TCP Query User{297C7A11-3BE1-4751-958D-101CD3CF8A0F}N:\steamlibrary\steamapps\common\conan exiles\conansandbox\binaries\win64\conansandbox.exe] => (Allow) N:\steamlibrary\steamapps\common\conan exiles\conansandbox\binaries\win64\conansandbox.exe => No File FirewallRules: [UDP Query User{25382C7B-7730-4980-90CB-95EC490257E1}N:\steamlibrary\steamapps\common\conan exiles\conansandbox\binaries\win64\conansandbox.exe] => (Allow) N:\steamlibrary\steamapps\common\conan exiles\conansandbox\binaries\win64\conansandbox.exe => No File FirewallRules: [TCP Query User{8EE135D4-D1DC-4809-BF16-3148015C793E}C:\users\chris\appdata\local\chia-blockchain\app-1.5.1\resources\app.asar.unpacked\daemon\start_farmer.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.5.1\resources\app.asar.unpacked\daemon\start_farmer.exe => No File FirewallRules: [UDP Query User{BC5258E6-3641-4BBF-84D3-E9560A51EB03}C:\users\chris\appdata\local\chia-blockchain\app-1.5.1\resources\app.asar.unpacked\daemon\start_farmer.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.5.1\resources\app.asar.unpacked\daemon\start_farmer.exe => No File FirewallRules: [TCP Query User{BEDFEA87-248D-44D2-9FE8-23624E28D600}C:\users\chris\appdata\local\chia-blockchain\app-1.5.1\resources\app.asar.unpacked\daemon\start_full_node.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.5.1\resources\app.asar.unpacked\daemon\start_full_node.exe => No File FirewallRules: [UDP Query User{2FFA4A74-D450-455F-BD22-10219597C4A4}C:\users\chris\appdata\local\chia-blockchain\app-1.5.1\resources\app.asar.unpacked\daemon\start_full_node.exe] => (Allow) C:\users\chris\appdata\local\chia-blockchain\app-1.5.1\resources\app.asar.unpacked\daemon\start_full_node.exe => No File FirewallRules: [TCP Query User{3BE0FCA6-5BBC-434A-8CF2-7CD6579A4D61}E:\epicgames\gloomhaven\gh.exe] => (Allow) E:\epicgames\gloomhaven\gh.exe => No File FirewallRules: [UDP Query User{387F41AA-52BE-4D1F-8F58-7DC026C27662}E:\epicgames\gloomhaven\gh.exe] => (Allow) E:\epicgames\gloomhaven\gh.exe => No File FirewallRules: [TCP Query User{C453467F-0A7A-4607-AC2F-5104E57F0314}E:\epicgames\droneracingleaguesim\drl simulator.exe] => (Allow) E:\epicgames\droneracingleaguesim\drl simulator.exe => No File FirewallRules: [UDP Query User{0C5078DD-7832-4768-9F78-B8D4746211CE}E:\epicgames\droneracingleaguesim\drl simulator.exe] => (Allow) E:\epicgames\droneracingleaguesim\drl simulator.exe => No File FirewallRules: [TCP Query User{B7A1C06A-815D-42A0-86BC-9410E5CDE145}C:\users\chris\documents\minecraft - titan\.minecraft\runtime\java-runtime-gamma\windows\java-runtime-gamma\bin\javaw.exe] => (Allow) C:\users\chris\documents\minecraft - titan\.minecraft\runtime\java-runtime-gamma\windows\java-runtime-gamma\bin\javaw.exe => No File FirewallRules: [UDP Query User{CE7409D3-5062-49D7-90B4-87C1D422B8B9}C:\users\chris\documents\minecraft - titan\.minecraft\runtime\java-runtime-gamma\windows\java-runtime-gamma\bin\javaw.exe] => (Allow) C:\users\chris\documents\minecraft - titan\.minecraft\runtime\java-runtime-gamma\windows\java-runtime-gamma\bin\javaw.exe => No File FirewallRules: [{D644E615-EC6B-4AC3-81F2-0E97DD2857D1}] => (Allow) C:\Program Files\Java\jre1.8.0_321\bin\java.exe => No File FirewallRules: [{40602545-D1A7-4A43-9711-6D76AD7C43E6}] => (Allow) C:\Program Files\Java\jre1.8.0_321\bin\java.exe => No File FirewallRules: [{ACE72CE6-A83E-46BF-AE72-F575E003DADC}] => (Allow) D:\Steam\steamapps\common\3DMark\3DMarkLauncher.exe => No File FirewallRules: [{92F8BFF5-ACA9-41AC-999F-25C4955DBE5C}] => (Allow) D:\Steam\steamapps\common\3DMark\3DMarkLauncher.exe => No File FirewallRules: [{573166D3-4B78-495F-A189-25BE1E8BB8F4}] => (Allow) D:\Steam\steamapps\common\Company of Heroes 3\RelicCoH3.exe => No File FirewallRules: [{C9D4EA5C-25F6-40A6-940D-CFD3C78C1E89}] => (Allow) D:\Steam\steamapps\common\Company of Heroes 3\RelicCoH3.exe => No File FirewallRules: [{0D3D926E-166E-4A50-BB1A-D6384860CA76}] => (Allow) D:\Steam\steamapps\common\3DMark\bin\x64\3DMark.exe => No File FirewallRules: [{F7967C7E-22E8-4829-A132-09BB7333F8A4}] => (Allow) D:\Steam\steamapps\common\3DMark\bin\x64\3DMark.exe => No File FirewallRules: [TCP Query User{09178DB2-75A4-4804-88BA-92940C515F59}N:\steamlibrary\steamapps\common\divinity original sin 2\defed\bin\eocapp.exe] => (Allow) N:\steamlibrary\steamapps\common\divinity original sin 2\defed\bin\eocapp.exe => No File FirewallRules: [UDP Query User{944EE9F5-0A8E-4069-A8F3-28272F773671}N:\steamlibrary\steamapps\common\divinity original sin 2\defed\bin\eocapp.exe] => (Allow) N:\steamlibrary\steamapps\common\divinity original sin 2\defed\bin\eocapp.exe => No File FirewallRules: [TCP Query User{2F60B4C5-8D86-41FD-B3F2-30C83643A889}N:\steamlibrary\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe] => (Allow) N:\steamlibrary\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe => No File FirewallRules: [UDP Query User{073A204A-9E08-43BD-85A1-7DA745A9E3DC}N:\steamlibrary\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe] => (Allow) N:\steamlibrary\steamapps\common\baldurs gate 3\bin\bg3_dx11.exe => No File FirewallRules: [TCP Query User{ABE3EDB5-F66D-43DD-9418-BBBC5081CC25}N:\steamlibrary\steamapps\common\baldurs gate 3\bin\bg3.exe] => (Allow) N:\steamlibrary\steamapps\common\baldurs gate 3\bin\bg3.exe => No File FirewallRules: [UDP Query User{9642478C-1D55-4205-B945-D9D7F97CBA53}N:\steamlibrary\steamapps\common\baldurs gate 3\bin\bg3.exe] => (Allow) N:\steamlibrary\steamapps\common\baldurs gate 3\bin\bg3.exe => No File FirewallRules: [{006D3BA8-2707-4A6B-AFCF-964DCBB29275}] => (Allow) N:\SteamLibrary\steamapps\common\Baldurs Gate 3\bin\bg3_dx11.exe => No File FirewallRules: [{6722D382-E358-4B5C-96D5-7C6048537251}] => (Allow) N:\SteamLibrary\steamapps\common\Baldurs Gate 3\bin\bg3_dx11.exe => No File FirewallRules: [{17C00CD8-E240-4894-BF3C-E0742D20E479}] => (Allow) N:\SteamLibrary\steamapps\common\Baldurs Gate 3\Launcher\LariLauncher.exe => No File FirewallRules: [TCP Query User{62510D23-15D9-4F78-BA07-06095C3C7584}C:\program files\java\jre-1.8\bin\javaw.exe] => (Allow) C:\program files\java\jre-1.8\bin\javaw.exe => No File FirewallRules: [UDP Query User{98BEA7A5-A761-4714-A818-AABDFC11871F}C:\program files\java\jre-1.8\bin\javaw.exe] => (Allow) C:\program files\java\jre-1.8\bin\javaw.exe => No File FirewallRules: [TCP Query User{932F151F-F769-4A46-9A1C-F2672281B7D1}C:\program files\java\jre-1.8\bin\java.exe] => (Allow) C:\program files\java\jre-1.8\bin\java.exe => No File FirewallRules: [UDP Query User{23EEFBB6-A967-4D8E-8C82-A510EA367D28}C:\program files\java\jre-1.8\bin\java.exe] => (Allow) C:\program files\java\jre-1.8\bin\java.exe => No File FirewallRules: [TCP Query User{816CF960-2B3D-45AF-963C-350920FE219D}E:\epicgames\chivalry2\tbl\binaries\win64\chivalry2-win64-shipping.exe] => (Allow) E:\epicgames\chivalry2\tbl\binaries\win64\chivalry2-win64-shipping.exe => No File FirewallRules: [UDP Query User{DF71D233-9D21-4F00-9E3B-F3D827969CDD}E:\epicgames\chivalry2\tbl\binaries\win64\chivalry2-win64-shipping.exe] => (Allow) E:\epicgames\chivalry2\tbl\binaries\win64\chivalry2-win64-shipping.exe => No File FirewallRules: [{4712D7AD-2A9C-4D9A-A046-EC6A6B746A4C}] => (Allow) D:\Steam\steamapps\common\Farthest Frontier\Farthest Frontier.exe => No File FirewallRules: [{C65D781E-4D06-4887-A590-DF9A5CC550DA}] => (Allow) D:\Steam\steamapps\common\Farthest Frontier\Farthest Frontier.exe => No File FirewallRules: [TCP Query User{66007289-A673-4422-AEF4-3500CF1E7180}E:\epicgames\callofthewildtheangler\cotwtheangler_egs.exe] => (Allow) E:\epicgames\callofthewildtheangler\cotwtheangler_egs.exe => No File FirewallRules: [UDP Query User{27FD6B5A-F4C6-4E71-B826-8322011E086F}E:\epicgames\callofthewildtheangler\cotwtheangler_egs.exe] => (Allow) E:\epicgames\callofthewildtheangler\cotwtheangler_egs.exe => No File FirewallRules: [TCP Query User{07090385-7679-463D-937C-B9C2D25150E6}E:\battle.net starcraft2\starcraft ii\versions\base92028\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base92028\sc2_x64.exe => No File FirewallRules: [UDP Query User{8F50A713-70F7-4159-835D-A59EC92CDFB9}E:\battle.net starcraft2\starcraft ii\versions\base92028\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base92028\sc2_x64.exe => No File FirewallRules: [TCP Query User{8C4B2F9C-CEA6-4555-9F19-BD284972CA62}E:\battle.net starcraft2\starcraft ii\versions\base92174\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base92174\sc2_x64.exe => No File FirewallRules: [UDP Query User{EE1BFC68-E0A8-41D3-84B1-22C513F1B9F6}E:\battle.net starcraft2\starcraft ii\versions\base92174\sc2_x64.exe] => (Allow) E:\battle.net starcraft2\starcraft ii\versions\base92174\sc2_x64.exe => No File FirewallRules: [{AD2DB9E6-A38F-4B2A-B6B9-340E406D7D67}] => (Allow) E:\SteamLibrary\steamapps\common\FaaastPenguin\FaaastPenguinClient.exe => No File FirewallRules: [{201A1B20-5309-4BDE-946D-EDFABB442C9B}] => (Allow) E:\SteamLibrary\steamapps\common\FaaastPenguin\FaaastPenguinClient.exe => No File FirewallRules: [TCP Query User{5492DC32-FC07-4A82-8F22-DBD5650BCD86}M:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) M:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File FirewallRules: [UDP Query User{71802579-D089-4E59-96EA-DA0143E51B20}M:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) M:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File FirewallRules: [TCP Query User{C28BA8F1-1E1D-4082-B058-F973C3D9E32D}M:\wutheringwavesj3ofh\wuthering waves game\client\binaries\win64\client-win64-shipping.exe] => (Allow) M:\wutheringwavesj3ofh\wuthering waves game\client\binaries\win64\client-win64-shipping.exe => No File FirewallRules: [UDP Query User{7D1B0E8F-3EDA-45BE-BC6B-E92DF0B56FE7}M:\wutheringwavesj3ofh\wuthering waves game\client\binaries\win64\client-win64-shipping.exe] => (Allow) M:\wutheringwavesj3ofh\wuthering waves game\client\binaries\win64\client-win64-shipping.exe => No File FirewallRules: [TCP Query User{7B37CC32-1EF3-4587-B230-8A99CAEDCAA5}C:\program files\java\jre1.8.0_431\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_431\bin\javaw.exe => No File FirewallRules: [UDP Query User{8F1BB99A-2AB0-466A-A209-FB8F42B70E5C}C:\program files\java\jre1.8.0_431\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_431\bin\javaw.exe => No File FirewallRules: [TCP Query User{9698305D-256F-4EAA-9BA2-27EE7D8004C1}C:\program files\java\jre1.8.0_431\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_431\bin\java.exe => No File FirewallRules: [UDP Query User{895F56C4-0F99-4530-8DFD-AEF394A73B58}C:\program files\java\jre1.8.0_431\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_431\bin\java.exe => No File FirewallRules: [{5EBBD3FF-791A-403C-9DD8-1D65DE86AF4D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.138.3211.0_x64__kzf8qxf38zg5c\Skype\Skype.exe => No File FirewallRules: [{AA34DF4B-422A-459F-9FCE-0EFCF722E458}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.138.3211.0_x64__kzf8qxf38zg5c\Skype\Skype.exe => No File FirewallRules: [{59757E5F-7706-486A-8464-AB85BED0C016}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.138.3211.0_x64__kzf8qxf38zg5c\Skype\Skype.exe => No File FirewallRules: [{9AF56196-AB7E-4152-9FEA-2286FCCC666E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.138.3211.0_x64__kzf8qxf38zg5c\Skype\Skype.exe => No File FirewallRules: [TCP Query User{11150CFC-C319-41B2-8B14-546FA7E8427E}C:\program files\java\jre1.8.0_451\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_451\bin\javaw.exe => No File FirewallRules: [UDP Query User{67B6D31C-9D21-4F6F-B9A6-DFAE770C1FB3}C:\program files\java\jre1.8.0_451\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_451\bin\javaw.exe => No File FirewallRules: [TCP Query User{BA8C4284-0AA1-4508-A912-233E213AE656}C:\program files\java\jre1.8.0_451\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_451\bin\java.exe => No File FirewallRules: [UDP Query User{937876C6-10CC-416F-86DB-9A0E2552DE78}C:\program files\java\jre1.8.0_451\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_451\bin\java.exe => No File FirewallRules: [{530D2FE4-EFD8-476C-8627-5558EC254778}] => (Allow) M:\SteamLibrary\steamapps\common\Splitgate 2\PortalWars2\Binaries\Win64\PortalWars2Client-Win64-Shipping.exe => No File FirewallRules: [{A37A64C0-97F7-4979-9028-2E49AF58352A}] => (Allow) M:\SteamLibrary\steamapps\common\Splitgate 2\PortalWars2\Binaries\Win64\PortalWars2Client-Win64-Shipping.exe => No File FirewallRules: [{44C09F48-D12E-4384-BE04-BBD0F2298EE1}] => (Allow) N:\SteamLibrary\steamapps\common\SlayTheSpire\jre\bin\javaw.exe => No File FirewallRules: [{126944BB-D623-445B-9A04-224741CF3AD5}] => (Allow) N:\SteamLibrary\steamapps\common\SlayTheSpire\jre\bin\javaw.exe => No File FirewallRules: [TCP Query User{CC7BDF38-7646-4790-BE3E-2A388C8BD76B}N:\rockstar\red dead redemption 2\rdr2.exe] => (Allow) N:\rockstar\red dead redemption 2\rdr2.exe => No File FirewallRules: [UDP Query User{7B54C1E9-0D80-4806-B007-7263DCA0A4BB}N:\rockstar\red dead redemption 2\rdr2.exe] => (Allow) N:\rockstar\red dead redemption 2\rdr2.exe => No File FirewallRules: [{2C92770E-1D6A-4361-B78A-4C13D3B07205}] => (Allow) C:\Program Files (x86)\BlueStacks X\Cloud Game.exe => No File FirewallRules: [TCP Query User{BCD325F7-48D8-44F1-8141-544D8E08EE65}S:\steamlibrary\steamapps\common\arc raiders\pioneergame\binaries\win64\pioneergame-e.exe] => (Allow) S:\steamlibrary\steamapps\common\arc raiders\pioneergame\binaries\win64\pioneergame-e.exe => No File FirewallRules: [UDP Query User{3C96F983-F3CE-4379-988B-ED625A16C1AD}S:\steamlibrary\steamapps\common\arc raiders\pioneergame\binaries\win64\pioneergame-e.exe] => (Allow) S:\steamlibrary\steamapps\common\arc raiders\pioneergame\binaries\win64\pioneergame-e.exe => No File FirewallRules: [TCP Query User{BCFF46D3-D421-4780-8DB0-9E278322C8DF}S:\steamlibrary\steamapps\common\arc raiders\pioneergame\binaries\win64\pioneergame-d.exe] => (Allow) S:\steamlibrary\steamapps\common\arc raiders\pioneergame\binaries\win64\pioneergame-d.exe => No File FirewallRules: [UDP Query User{14E3646D-A095-4909-86FF-65831959ADF8}S:\steamlibrary\steamapps\common\arc raiders\pioneergame\binaries\win64\pioneergame-d.exe] => (Allow) S:\steamlibrary\steamapps\common\arc raiders\pioneergame\binaries\win64\pioneergame-d.exe => No File FirewallRules: [{87AF8375-B340-4879-8D1E-0F3C26AFEF5A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.37051.0_x64__8wekyb3d8bbwe\M365Copilot.exe => No File FirewallRules: [{A7293A45-9D16-47C8-8312-3B214E7A3C4B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.37051.0_x64__8wekyb3d8bbwe\M365Copilot.exe => No File FirewallRules: [{E2BE1872-B29F-45C6-82CB-E8317E18B514}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.37051.0_x64__8wekyb3d8bbwe\M365Copilot.exe => No File FirewallRules: [{DDA4FDD3-2C2A-4914-8439-545A44F75387}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.37051.0_x64__8wekyb3d8bbwe\M365Copilot.exe => No File FirewallRules: [{600C2429-07BC-49D5-9746-8462C24318F6}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.44041.0_x64__8wekyb3d8bbwe\M365Copilot.exe => No File FirewallRules: [{0B2EC4ED-FE45-4F3A-9B66-742D87D3B720}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.44041.0_x64__8wekyb3d8bbwe\M365Copilot.exe => No File FirewallRules: [{B0CECCDA-396A-4AB9-B7E0-119554C7CD37}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.44041.0_x64__8wekyb3d8bbwe\M365Copilot.exe => No File FirewallRules: [{94635F18-28E0-4533-BE97-683093E6A0BB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2607.44041.0_x64__8wekyb3d8bbwe\M365Copilot.exe => No File FirewallRules: [{C8F4C546-615D-44C9-8884-637C8C383EE8}] => (Allow) C:\Program Files (x86)\Overwolf\0.304.1.1\OverwolfBrowser.exe => No File FirewallRules: [{A3B791D3-9DCF-43CA-9DC1-42FC58AA1CAB}] => (Allow) C:\Program Files (x86)\Overwolf\0.304.1.1\OverwolfBrowser.exe => No File FirewallRules: [{77774A85-CB11-4E89-B888-377F08A76123}] => (Block) C:\Program Files (x86)\Overwolf\0.304.1.1\OverwolfBrowser.exe => No File FirewallRules: [{357EF561-7DA7-4020-B29F-F8505AA584BB}] => (Block) C:\Program Files (x86)\Overwolf\0.304.1.1\OverwolfBrowser.exe => No File FirewallRules: [{9F35105F-C694-4DA4-8F92-01F280EB6304}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2608.41021.0_x64__8wekyb3d8bbwe\M365Copilot.exe => No File FirewallRules: [{421463CE-590E-43BF-8317-011C1DFE1CFB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2608.41021.0_x64__8wekyb3d8bbwe\M365Copilot.exe => No File FirewallRules: [{07A7E39E-C3EA-47E4-8935-83A22B8A104F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2608.41021.0_x64__8wekyb3d8bbwe\M365Copilot.exe => No File FirewallRules: [{E931A8D4-AE87-47CC-9BF7-B6DC6933CAE3}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2608.41021.0_x64__8wekyb3d8bbwe\M365Copilot.exe => No File HKU\S-1-5-21-769680110-549076602-1943842397-1002\...\Run: [OneDrive] => "C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background (No File) HKU\S-1-5-21-769680110-549076602-1943842397-1002\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File) <==== ATTENTION HKU\S-1-5-21-769680110-549076602-1943842397-1002\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File) <==== ATTENTION HKU\S-1-5-21-769680110-549076602-1943842397-1002\...\RunOnce: [Uninstall 26.134.0713.0004] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.134.0713.0004" (No File) HKU\S-1-5-21-769680110-549076602-1943842397-1002\...\RunOnce: [Uninstall 26.134.0713.0007] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.134.0713.0007" (No File) HKU\S-1-5-21-769680110-549076602-1943842397-1005\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\gamers\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File) <==== ATTENTION HKU\S-1-5-21-769680110-549076602-1943842397-1005\...\RunOnce: [Uninstall 25.056.0324.0003] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\gamers\AppData\Local\Microsoft\OneDrive\25.056.0324.0003" (No File) HKU\S-1-5-21-769680110-549076602-1943842397-1005\...\RunOnce: [Uninstall 25.222.1112.0002] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\gamers\AppData\Local\Microsoft\OneDrive\25.222.1112.0002" (No File) HKU\S-1-5-21-769680110-549076602-1943842397-1005\...\RunOnce: [Uninstall 25.224.1116.0003] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\gamers\AppData\Local\Microsoft\OneDrive\25.224.1116.0003" (No File) HKU\S-1-5-21-769680110-549076602-1943842397-1005\...\RunOnce: [Uninstall 25.238.1204.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\gamers\AppData\Local\Microsoft\OneDrive\25.238.1204.0001" (No File) HKU\S-1-5-21-769680110-549076602-1943842397-1005\...\RunOnce: [Uninstall 26.002.0105.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\gamers\AppData\Local\Microsoft\OneDrive\26.002.0105.0001" (No File) HKU\S-1-5-21-769680110-549076602-1943842397-1005\...\RunOnce: [Uninstall 26.007.0112.0002] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\gamers\AppData\Local\Microsoft\OneDrive\26.007.0112.0002" (No File) HKU\S-1-5-21-769680110-549076602-1943842397-1005\...\RunOnce: [Uninstall 26.012.0119.0002] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\gamers\AppData\Local\Microsoft\OneDrive\26.012.0119.0002" (No File) HKU\S-1-5-21-769680110-549076602-1943842397-1005\...\RunOnce: [Uninstall 26.017.0126.0002] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\gamers\AppData\Local\Microsoft\OneDrive\26.017.0126.0002" (No File) HKU\S-1-5-21-769680110-549076602-1943842397-500\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Administrator\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File) <==== ATTENTION HKU\S-1-5-21-769680110-549076602-1943842397-500\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Administrator\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File) <==== ATTENTION Task: {225BA24B-EB6F-493B-8E6E-CF7317239C69} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION Task: {E98FE457-A0D9-4370-B665-51B5A4195C87} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe -mode=scheduled (No File) Task: {8DA681A3-27BC-41F6-AE33-678593015D4A} - System32\Tasks\AMDRyzenMasterSDKTask => "C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe" (No File) Task: {BC0F7AD5-B941-4140-8AF4-E48E481462D8} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File) S3 Rockstar Service; "V:\Rockstar\RockstarService.exe" (No File) R2 GigabyteUpdateService; %SystemRoot%\system32\GigabyteUpdateService.exe 2\C:\Windows\system32\ (No File) S2 AMDRyzenMasterDriverV17; \??\C:\Program Files\AMD\CNext\CNext\AMDRyzenMasterDriver.sys (No File) S3 EAAntiCheat; system32\drivers\eaanticheat.sys (No File) S3 semav6msr64; \??\C:\WINDOWS\system32\drivers\semav6msr64.sys (No File) HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ATTENTION GroupPolicy: Restriction ? <==== ATTENTION Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION Task: {03F6256B-7596-49FA-8D43-5BED3DE90123} - System32\Tasks\{5E9C47D5-C2A3-4B5B-9646-23F9F5362F1A} => E:\Program Files 2\Wizards of the Coast\MTGA\MTGALauncher\Updates\MTGAInstaller_1.0.94.exe -> /i "C:\Users\chris\AppData\Local\Temp\MTGAinstall\MTGAInstaller.msi" AI_SETUPEXEPATH="E:\Program Files 2\Wizards of the Coast\MTGA\MTGALauncher\Updates\MTGAInstaller_1.0.94.exe" SETUPEXEDIR="E:\Program Files 2\Wizards of the Coast\MTGA\MTGALauncher\Updates\" ADDLOCAL=MainFeature,MicrosoftVisualC ALL (the data entry has 848 more characters). <==== ATTENTION Task: {9895282D-5AC5-46E9-9101-68E616179C4B} - System32\Tasks\OneDrive Startup Task-S-1-5-21-769680110-549076602-1943842397-1002 => C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\OneDriveLauncher.exe /startInstances (Access Denied) <==== ATTENTION Task: C:\WINDOWS\Tasks\{5E9C47D5-C2A3-4B5B-9646-23F9F5362F1A}.job => E:\Program Files 2\Wizards of the Coast\MTGA\MTGALauncher\Updates\MTGAInstaller_1.0.94.exe}/i C:\Users\chris\AppData\Local\Temp\MTGAinstall\MTGAInstaller.msi AI_SETUPEXEPATH=E:\Program Files 2\Wizards of the Coast\MTGA\MTGALauncher\Updates\MTGAInstaller_1.0.94.exe SETUPEXEDIR=E:\Program Files 2\Wizards of the Coast\MTGA\MTGALauncher\Updates\ ADDLOCAL=MainFeature,MicrosoftVisualC ALLUSERS=1 PRIMARYFOLDER=APPDIR ROOTDRIVE=G:\ AI_PREREQFILES=C:\Users\chris\AppData\Roaming\Wizards of the Coast\MTGA Launcher\prerequisites\Visual C++ Redistributable for Visual Studio 2015-2019\VC_redist.x64.exe AI_PREREQDIRS=C:\Users\chris\AppData\Roaming\Wizards of the Coast\MTGA Launcher\prerequisites AI_MISSING_PREREQS=Visual C++ Redistributable for Visual Studio 2017 x64 AI_SETUPEXEPATH=E:\Program Files 2\Wizards of the Coast\MTGA\MTGALauncher\Updates\MTGAInstaller_1.0.94.exe SETUPEXEDIR=E:\Program Files 2\Wizards of the Coast\MTGA\MTGALauncher\Updates\ AI_INSTALL=1 BIPROCESSTIME=2020-12-30T16:04:14.5248722Z TARGETLOCKED=TRUE TARGETDIR=G:\ APPDIR=E:\Program Files 2\Wizards of the Coast\MTGA\ AI_SETUPEXEPATH_ORIGINAL=E:\Program Files 2\Wizards of the Coast\MTGA\MTGALauncher\Updates\MTGAInstaller_1.0.94.exe <==== ATTENTION R3 TermService; C:\Program Files\RDP Wrapper\rdpwrap.dll [116736 2024-08-09] (Stas'M Corp.) [File not signed] <==== ATTENTION (no ServiceDLL) S3 cpuz158; \??\C:\WINDOWS\temp\cpuz158\cpuz158_x64.sys [44576 2026-07-05] (Microsoft Windows Hardware Compatibility Publisher -> ) <==== ATTENTION File: C:\Users\chris\AppData\Local\MicroSIP\microsip.exe File: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.139.0720.0007\OneDriveLauncher.exe C:\Program Files\RDP Wrapper Comment: This snippet reverts SmartScreen settings to default StartRegedit: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer] "SmartScreenEnabled"="Warn" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter] "EnabledV9"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AppHost] "EnableWebContentEvaluation"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\AppHost] "EnableWebContentEvaluation"=dword:00000001 EndRegedit: Folder: C:\Program Files\Mumble File: C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\GraphicsCardEngine.exe HKU\S-1-5-21-769680110-549076602-1943842397-1002\...\RunOnce: [FlashPlayerUpdate] => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_465_Plugin.exe [1504312 2020-12-09] (Adobe Inc. -> Adobe) Task: {D3741A25-B50D-4A93-8C81-C729797F309E} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_465_Plugin.exe [1504312 2020-12-09] (Adobe Inc. -> Adobe) Task: {2160AF28-56CC-494C-91DD-A3C7A37BDFFF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-09] (Adobe Inc. -> Adobe) CMD: Type "C:\Users\chris\Documents\Chia\plot1.ps1" File: C:\Users\chris\Documents\MikroTik\Service\SnifferService.exe Avira Safe Shopping (HKLM-x32\...\{9158dccb-03a7-493c-b07e-f47b9784425c}) (Version: 1.0.65.2672 - Avira Operations Gmbh & Co. KG) Hidden AS: Avira Antivirus (Disabled - Up to date) {33CF8AA2-FA06-4AD4-98AB-332D53DD7FFB} 2026-08-21 21:39 - 2026-08-22 20:58 - 000000000 ____D C:\ProgramData\storage_analyzer_v3_0 2026-08-21 21:39 - 2026-08-21 21:39 - 000000000 ____D C:\Users\chris\AppData\Roaming\storage_analyzer_v3_0 2026-08-21 21:34 - 2026-08-21 21:34 - 854509047 _____ C:\Users\chris\Downloads\Archive_win_250765.zip.old Comment: Service / Driver Status (thanks to AdvancedSetup) Comment: 0 = Boot Comment: 1 = System Comment: 2 = Automatic Comment: 3 = Manual / Demand Comment: 4 = Disabled Comment: R = Running Comment: S = Stopped Comment: U = Unknown / unable to determine service state cleanly Comment: === rifteyy's default non-intrusive fixlist template === Comment: The following are done automatically with this fixlist: Comment: Hardens Windows Defender (for maximum efficiency DISABLE TAMPER PROTECTION) Comment: Checks and corrects the default Windows PATH environmental variable Comment: Checks for internet connection, valid DNS Comment: Checks for Windows RE status Comment: Checks and repairs WMI repository Comment: Checks Windows activation status Comment: Checks if TPM, Secure Boot are available and their status Comment: Restores original Windows services configuration Comment: Restores PowerShell execution policy Comment: Rebuilds performance counter library values Comment: Resynchronizes performance counter library values to WMI Comment: Enables file extensions Comment: Enables recovery environment Comment: Scans with HitmanPro from Sophos Comment: Scans and cleans with AdwCleaner from Malwarebytes Comment: Lists environment variables Comment: Lists Windows Defender properties, settings Comment: Lists drive info, identify possible damaged drives from Event Logs Comment: Lists Discord's "index.js" files that are often targeted by malware (to store and execute malicious code) Comment: Lists recent BSOD's Comment: Lists all installed applications, folder contents along with SHA256 for purposes of identifying installed app malware Comment: Lists 30 recent scheduled tasks Comment: Lists recent Run (Windows + R) executed commands, can identify ClickFix attacks Comment: Removes unwanted files (e.g. .exe, .com, .dll) from common folders (e.g. C:\ProgramData, AppData\Roaming) - these are not supposed to store any executable file types Comment: Removes generic filetypes associated with RenPyLoader from common folders Comment: Removes cache from Chrome, Firefox, Opera, Opera GX, Brave, Vivaldi, LibreWolf, Mullvad Browser, Zen and from Roblox, Fortnite, Discord, OBS Studio Comment: Removes policies Comment: Removes active BITS tasks Comment: Resets network Comment: Removes proxy servers Comment: Removes temporary files Comment: Repairs system files Comment: List environment variables StartPowerShell: $key = Get-Item -Path "HKCU:\Environment" -ErrorAction SilentlyContinue if ($key) { $path = "HKCU\Environment" foreach ($name in $key.GetValueNames()) { $value = $key.GetValue($name, $null, [Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames) "$path|$name=$value" } } $key = Get-Item -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Environment" -ErrorAction SilentlyContinue if ($key) { $path = "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment" foreach ($name in $key.GetValueNames()) { $value = $key.GetValue($name, $null, [Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames) "$path|$name=$value" } } Get-ChildItem Env: | Sort-Object Name | ForEach-Object { "SET|$($_.Name)=$($_.Value)" } Get-ChildItem Registry::HKEY_USERS | Where-Object { $_.PSChildName -match '^S-1-5-21-\d+-\d+-\d+-\d+$' } | ForEach-Object { $sid = $_.PSChildName $envPath = "Registry::HKEY_USERS\$sid\Environment" if (Test-Path $envPath) { $key = Get-Item -Path $envPath foreach ($name in $key.GetValueNames()) { $value = $key.GetValue($name, $null, [Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames) "HKEY_USERS\$sid\Environment|$name=$value" } } } EndPowerShell: StartPowerShell: # Checks default Windows PATH entries and repairs missing ones. $ErrorActionPreference = 'Continue' function Expand-PlainPath { param([string]$Entry) return [Environment]::ExpandEnvironmentVariables($Entry).TrimEnd('\') } # Templates expanded once to plain paths (C:\Windows\..., C:\Users\...) $systemDefaults = @( (Expand-PlainPath '%SystemRoot%\system32') (Expand-PlainPath '%SystemRoot%') (Expand-PlainPath '%SystemRoot%\System32\Wbem') (Expand-PlainPath '%SystemRoot%\System32\WindowsPowerShell\v1.0') (Expand-PlainPath '%SystemRoot%\System32\OpenSSH') ) $userDefaults = @( (Expand-PlainPath '%USERPROFILE%\AppData\Local\Microsoft\WindowsApps') ) function Get-NormalizedPathEntries { param([string]$Raw) if ([string]::IsNullOrWhiteSpace($Raw)) { return @() } return @( $Raw -split ';' | Where-Object { -not [string]::IsNullOrWhiteSpace($_) } | ForEach-Object { [Environment]::ExpandEnvironmentVariables($_.Trim().TrimEnd('\')).ToLowerInvariant() } ) } function Get-CombinedPathEntries { $machineRaw = [Environment]::GetEnvironmentVariable('Path', 'Machine') $userRaw = [Environment]::GetEnvironmentVariable('Path', 'User') return Get-NormalizedPathEntries -Raw ($machineRaw + ';' + $userRaw) } function Test-InPath { param( [string]$PlainPath, [string[]]$NormalizedEntries ) $key = $PlainPath.TrimEnd('\').ToLowerInvariant() return $NormalizedEntries -contains $key } function Add-ToPath { param( [string]$PlainPath, [ValidateSet('Machine', 'User')] [string]$Scope ) # always store plain path, never %VAR% form $toAdd = $PlainPath.TrimEnd('\') $current = [Environment]::GetEnvironmentVariable('Path', $Scope) if ([string]::IsNullOrWhiteSpace($current)) { [Environment]::SetEnvironmentVariable('Path', $toAdd, $Scope) return } $normalized = Get-NormalizedPathEntries -Raw $current $key = $toAdd.ToLowerInvariant() if ($normalized -contains $key) { return } $newPath = $current.TrimEnd(';') + ';' + $toAdd [Environment]::SetEnvironmentVariable('Path', $newPath, $Scope) } function Write-Result { param( [string]$Entry, [string]$Status ) $label = $Entry.PadRight(58) Write-Output ("{0} {1}" -f $label, $Status) } function Repair-AndVerify { param( [string]$PlainPath, [ValidateSet('Machine', 'User')] [string]$Scope ) if (-not (Test-Path -LiteralPath $PlainPath)) { Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (no folder, cannot repair)' return 'failed' } if ($Scope -eq 'Machine') { $isAdmin = ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()). IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator) if (-not $isAdmin) { Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (need Admin to repair)' return 'failed' } } try { Add-ToPath -PlainPath $PlainPath -Scope $Scope } catch { Write-Result -Entry $PlainPath -Status "ATTENTION !!! MISSING (repair failed: $_)" return 'failed' } # re-query PATH from registry and verify plain path is present $after = Get-CombinedPathEntries if (Test-InPath -PlainPath $PlainPath -NormalizedEntries $after) { Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING -> repaired (verified)' return 'repaired' } Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (repair ran, still missing after re-check)' return 'failed' } $combined = Get-CombinedPathEntries $hadMissing = $false $repairFailed = $false $repairedList = [System.Collections.Generic.List[string]]::new() Write-Output 'PATH CHECK' Write-Output ('-' * 72) foreach ($entry in $systemDefaults) { if (Test-InPath -PlainPath $entry -NormalizedEntries $combined) { Write-Result -Entry $entry -Status 'OK' continue } $hadMissing = $true $result = Repair-AndVerify -PlainPath $entry -Scope Machine if ($result -eq 'repaired') { [void]$repairedList.Add($entry) $combined = Get-CombinedPathEntries } else { $repairFailed = $true } } foreach ($entry in $userDefaults) { if (Test-InPath -PlainPath $entry -NormalizedEntries $combined) { Write-Result -Entry $entry -Status 'OK' continue } $hadMissing = $true $result = Repair-AndVerify -PlainPath $entry -Scope User if ($result -eq 'repaired') { [void]$repairedList.Add($entry) $combined = Get-CombinedPathEntries } else { $repairFailed = $true } } Write-Output ('-' * 72) if (-not $hadMissing) { Write-Output 'RESULT: all default PATH entries present' } elseif ($repairedList.Count -gt 0 -and -not $repairFailed) { Write-Output "RESULT: $($repairedList.Count) missing entry/entries repaired and verified - open a new terminal" } elseif ($repairedList.Count -gt 0 -and $repairFailed) { Write-Output "RESULT: $($repairedList.Count) verified, some still missing - open a new terminal / run as Admin" } else { Write-Output 'RESULT: missing entries not repaired (run as Admin for System PATH)' } if ($repairedList.Count -gt 0) { Write-Output '' Write-Output 'REPAIRED:' foreach ($item in $repairedList) { Write-Output " $item" } } if ($hadMissing -or $repairFailed) { exit 1 } exit 0 EndPowerShell: Comment: Verify Windows activation CMD: cscript c:\windows\system32\slmgr.vbs /xpr & cscript c:\windows\system32\slmgr.vbs /dlv Comment: Check TPM and Secure Boot status StartPowershell: [PSCustomObject]@{ "TPM Detected" = (Get-Tpm).TpmPresent; "TPM Enabled" = (Get-Tpm).TpmEnabled; "Secure Boot On" = (Confirm-SecureBootUEFI) } EndPowershell: StartPowerShell: # Check for internet connection $ErrorActionPreference = 'Continue' $dnsServers = @( '1.1.1.1' '8.8.8.8' ) $hosts = @( 'google.com' 'cloudflare.com' 'malwarebytes.com' ) function Write-Result { param( [string]$Label, [string]$Status ) Write-Output ("{0} {1}" -f $Label.PadRight(42), $Status) } function Test-DnsServer { param([string]$Server) $pingOk = $false try { $pingOk = Test-Connection -ComputerName $Server -Count 1 -Quiet -ErrorAction SilentlyContinue } catch { } $resolveOk = $false try { $result = Resolve-DnsName -Name 'google.com' -Server $Server -Type A -DnsOnly -ErrorAction Stop $ip = ($result | Where-Object { $_.IPAddress } | Select-Object -First 1).IPAddress if ($ip) { $resolveOk = $true } } catch { } # resolve is what matters; ping may be blocked if ($resolveOk) { return 'OK' } if ($pingOk) { return 'FAIL' } return 'FAIL' } function Test-HostReachable { param([string]$HostName) try { $dns = Resolve-DnsName -Name $HostName -Type A -ErrorAction Stop $resolvedIp = ($dns | Where-Object { $_.IPAddress } | Select-Object -First 1).IPAddress if (-not $resolvedIp) { return 'FAIL' } } catch { return 'FAIL' } try { $null = Invoke-WebRequest -Uri "https://$HostName" -UseBasicParsing -TimeoutSec 10 -MaximumRedirection 5 -ErrorAction Stop return 'OK' } catch { if ($_.Exception.Response) { return 'OK' } return 'FAIL' } } $failed = 0 Write-Output 'INTERNET CHECK' Write-Output ('-' * 72) Write-Output 'DNS SERVERS' foreach ($server in $dnsServers) { $status = Test-DnsServer -Server $server Write-Result -Label $server -Status $status if ($status -eq 'FAIL') { $failed++ } } Write-Output '' Write-Output 'HOSTS' foreach ($h in $hosts) { $status = Test-HostReachable -HostName $h Write-Result -Label $h -Status $status if ($status -eq 'FAIL') { $failed++ } } Write-Output ('-' * 72) if ($failed -eq 0) { Write-Output 'RESULT: all checks passed' exit 0 } Write-Output "RESULT: $failed check(s) failed" exit 1 EndPowerShell: StartPowershell: # Replace /scanonly with /clean if you also want to delete items -- however, this will activate a trial license on the system, I do not recommend it $hmpExe = "$env:TEMP\HitmanPro_x64.exe" $logFile = "$env:TEMP\HitmanPro_ScanLog.txt" Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing $proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 } Get-Content $logFile -Encoding Unicode EndPowershell: StartPowerShell: # Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console # Does not clean preinstalled objects, only PUP/Adware # If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument # If you would like to only scan with it, change the argument from /clean to /scan # NOTE: For the sake of users from Asia (primarily China), do not use the clean option. It will very likely remove a lot of their important software. New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden $logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt" Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile Get-Content $logFile -Encoding Unicode Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue EndPowerShell: Comment: List drive info, identify possible damaged drives (thanks to AdvancedSetup from Malwarebytes for parts of these) StartPowerShell: param( [int]$MaxEvents = 5000 ) $GPTTypeMap = @{ 'EBD0A0A2-B9E5-4433-87C0-68B6B72699C7' = 'Microsoft Basic Data' 'E3C9E316-0B5C-4DB8-817D-F92DF00215AE' = 'Microsoft Reserved (MSR)' 'DE94BBA4-06D1-4D40-A16A-BFD50179D6AC' = 'Windows Recovery Environment (WinRE)' 'C12A7328-F81F-11D2-BA4B-00A0C93EC93B' = 'EFI System Partition' '21686148-6449-6E6F-744E-656564454649' = 'BIOS Boot Partition' 'A19D880F-05FC-4D3B-A006-743F0F84911E' = 'OEM Partition' '5808C8AA-7E8F-42E0-85D2-E1E90434CFB3' = 'Cluster Metadata Partition' '48465300-0000-11AA-AA11-00306543ECAC' = 'Apple HFS/HFS+' '7C3457EF-0000-11AA-AA11-00306543ECAC' = 'Apple APFS' '0FC63DAF-8483-4772-8E79-3D69D8477DE4' = 'Linux Filesystem' '0657FD6D-A4AB-43C4-84E5-0933C84B4F4F' = 'Linux Swap' 'E6D6D379-F507-44C2-A23C-238F2A3DF928' = 'Linux LVM' } $MBRTypeMap = @{ '01'='FAT12';'04'='FAT16 <32M';'05'='Extended';'06'='FAT16';'07'='IFS/NTFS/exFAT/HPFS';'0B'='FAT32 CHS';'0C'='FAT32 LBA';'0E'='FAT16 LBA' '0F'='Extended LBA';'82'='Linux Swap';'83'='Linux Native';'8E'='Linux LVM';'A5'='FreeBSD';'A6'='OpenBSD';'A8'='Mac OS X';'AB'='Mac OS X Boot' 'AF'='Mac OS X HFS';'EE'='EFI GPT Protective';'EF'='EFI System Partition' } function Get-PartitionTypeInfo { param($Partition) $guid = $null if ($Partition.GptType) { $guid = ($Partition.GptType -replace '[{}]', '').ToUpper() } if ([string]::IsNullOrWhiteSpace($guid) -or $guid -eq '00000000-0000-0000-0000-000000000000') { $guid = switch ($Partition.Type) { "System" { "C12A7328-F81F-11D2-BA4B-00A0C93EC93B" } "Reserved" { "E3C9E316-0B5C-4DB8-817D-F92DF00215AE" } "Basic" { "EBD0A0A2-B9E5-4433-87C0-68B6B72699C7" } "Recovery" { "DE94BBA4-06D1-4D40-A16A-BFD50179D6AC" } default { $null } } } if ($guid) { $name = $GPTTypeMap[$guid] if ($name) { return "$name (GPT GUID: $($guid.ToLower()))" } else { return "Unknown/Custom (GPT GUID: $($guid.ToLower()))" } } if ($Partition.MbrType) { $code = ($Partition.MbrType.ToString() -replace '^0x', '').PadLeft(2, '0').ToUpper() $name = $MBRTypeMap[$code] if ($name) { return "$name (MBR code: 0x$code)" } else { return "Unknown/Custom (MBR code: $($Partition.MbrType))" } } return $Partition.Type } function Get-DrMapping { param([int]$MaxEvents) $map = @{} try { $events = Get-WinEvent -FilterHashtable @{ LogName = 'System'; ProviderName = 'disk' } -MaxEvents $MaxEvents -ErrorAction Stop } catch { return $map } foreach ($e in $events) { if ($e.Message -match 'Harddisk(\d+)\\DR(\d+)') { $n = [int]$Matches[1] $dr = [int]$Matches[2] if (-not $map.ContainsKey($n)) { $map[$n] = $dr } } } return $map } $drMap = Get-DrMapping -MaxEvents $MaxEvents $physicalDisks = Get-PhysicalDisk | Select-Object DeviceId, FriendlyName, SerialNumber, MediaType, @{N='SizeGB';E={[math]::Round($_.Size / 1GB,2)}} foreach ($pd in $physicalDisks) { $devId = [int]$pd.DeviceId $drSuffix = if ($drMap.ContainsKey($devId)) { "\DR$($drMap[$devId])" } else { '\DR? (no event seen yet)' } Write-Host "" Write-Host "<=== \Device\Harddisk$devId$drSuffix ($($pd.FriendlyName)) ===>" Write-Host " DeviceId: $devId | Serial: $($pd.SerialNumber) | Media: $($pd.MediaType) | Size: $($pd.SizeGB) GB" try { $partitions = Get-Partition -DiskNumber $devId -ErrorAction Stop if (-not $partitions) { Write-Host " (no partitions found)" continue } foreach ($part in $partitions) { $driveLetter = if ($part.DriveLetter) { "$($part.DriveLetter):" } else { 'no letter' } $sizeGB = [math]::Round($part.Size / 1GB, 2) $typeInfo = Get-PartitionTypeInfo -Partition $part Write-Host " [PARTITION $($part.PartitionNumber)] Drive: $driveLetter - $sizeGB GB - $typeInfo" } } catch { Write-Host " [ERROR] cannot read partitions for disk $devId" } } if ($drMap.Count -eq 0) { Write-Host "" Write-Host "Note: no \Device\HarddiskN\DRx entries found in the last $MaxEvents System log events. Increase -MaxEvents, or the DR number will only appear once Windows actually logs a disk event for that drive (e.g. a bad block warning)." } EndPowerShell: Comment: Verify that Discord does not have any injected code to intercept personal data. If anything is prompted here, it needs to be checked that it isn't malicious code. Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) } StartPowerShell: # Basic BSOD listings $ccKey = "HKLM:\SYSTEM\CurrentControlSet\Control\CrashControl" $cfg = Get-ItemProperty $ccKey -ErrorAction SilentlyContinue $dumpTypeMap = @{0='None';1='Complete';2='Kernel';3='Minidump';7='Automatic'} Write-Output "--- Configuration ---" Write-Output ("Dump Type: {0} ({1})" -f $cfg.CrashDumpEnabled, $dumpTypeMap[$cfg.CrashDumpEnabled]) Write-Output ("Full Dump Path: {0}" -f $(if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"})) Write-Output ("Minidump Folder: {0}" -f $(if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"})) Write-Output ("Auto Reboot: {0}" -f $(if($cfg.AutoReboot -eq 0){'Disabled'}else{'Enabled'})) Write-Output "--- Found Dump Files ---" $full = if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"} if (Test-Path $full) { Get-Item $full | Select Name,Length,LastWriteTime | Format-Table -AutoSize } $mini = if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"} if (Test-Path $mini) { Get-ChildItem $mini -Filter *.dmp | Select Name,Length,LastWriteTime | Format-Table -AutoSize } Write-Output "--- BugCheck Reasoning (recent events) ---" $map = @{ '0x0000000A'='IRQL_NOT_LESS_OR_EQUAL - faulty/outdated driver accessed memory at high IRQL' '0x0000001E'='KMODE_EXCEPTION_NOT_HANDLED - unhandled kernel exception, often driver/hardware' '0x0000002E'='DATA_BUS_ERROR - typically bad RAM or hardware fault' '0x0000003B'='SYSTEM_SERVICE_EXCEPTION - exception in a system service, often driver-related' '0x00000050'='PAGE_FAULT_IN_NONPAGED_AREA - bad RAM or faulty driver/antivirus' '0x0000007A'='KERNEL_DATA_INPAGE_ERROR - disk-related problem' '0x0000007B'='INACCESSIBLE_BOOT_DEVICE - system could not find/access the boot device' '0x0000007E'='SYSTEM_THREAD_EXCEPTION_NOT_HANDLED - almost always a faulty driver' '0x0000007F'='UNEXPECTED_KERNEL_MODE_TRAP - hardware issue (CPU/RAM/overclocking)' '0x0000009F'='DRIVER_POWER_STATE_FAILURE - driver failed to respond to a power state change' '0x000000C2'='BAD_POOL_CALLER - driver mishandling memory (pool corruption)' '0x000000D1'='DRIVER_IRQL_NOT_LESS_OR_EQUAL - typically a network or GPU driver' '0x000000EF'='CRITICAL_PROCESS_DIED - a critical system process died, often malware/system corruption' '0x00000116'='VIDEO_TDR_FAILURE - GPU driver failed to respond in time (timeout)' '0x00000124'='WHEA_UNCORRECTABLE_ERROR - hardware fault (CPU/RAM/PSU/overclocking)' '0x00000133'='DPC_WATCHDOG_VIOLATION - faulty driver or storage subsystem issue' '0x00000139'='KERNEL_SECURITY_CHECK_FAILURE - corrupted kernel structure, possibly malware' } $events = Get-WinEvent -FilterHashtable @{LogName='System';Id=1001} -MaxEvents 100 -ErrorAction SilentlyContinue | Where-Object { $_.ProviderName -match 'WER-SystemErrorReporting' } | Select-Object -First 5 if (-not $events) { Write-Output "No BugCheck events found in the log." } foreach ($ev in $events) { $code = if ($ev.Message -match 'bugcheck was:\s*(0x[0-9A-Fa-f]+)') { $matches[1] } else { $null } Write-Output ("Time: {0}" -f $ev.TimeCreated) Write-Output ("Code: {0}" -f $(if($code){$code}else{'not recognized'})) if ($code -and $map.ContainsKey($code.ToUpper())) { Write-Output ("Meaning: {0}" -f $map[$code.ToUpper()]) } elseif ($code) { Write-Output "Meaning: unknown code, look up at learn.microsoft.com/windows-hardware/drivers/debugger/bug-check-code-reference2" } Write-Output "" } EndPowerShell: StartPowerShell: # This snippet lists all installed apps and their folder contents along with SHA256 hashes. Useful for troubleshooting malware abusing installed app entry. param( [switch]$Recurse, [int]$MaxFilesPerApp = [int]::MaxValue ) $uninstallPaths = @( 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*', 'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*', 'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*' ) $script:msiInstaller = $null function Get-MsiInstallLocation { param([string]$ProductCode) if (-not $script:msiInstaller) { try { $script:msiInstaller = New-Object -ComObject WindowsInstaller.Installer } catch { return $null } } try { $loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallLocation') if ([string]::IsNullOrWhiteSpace($loc)) { $loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallSource') } if ([string]::IsNullOrWhiteSpace($loc)) { return $null } return $loc } catch { return $null } } function Get-CleanPath { param([string]$RawValue) if ([string]::IsNullOrWhiteSpace($RawValue)) { return $null } $s = $RawValue.Trim() if ($s.StartsWith('"')) { $endQuote = $s.IndexOf('"', 1) if ($endQuote -gt 0) { return $s.Substring(1, $endQuote - 1) } } if ($s -match '^(.*?\.exe)\b') { return $Matches[1] } return $s } function Format-FileSize { param([long]$Bytes) if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) } if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) } if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) } return "$Bytes B" } $script:PeExtensions = @('.exe', '.dll', '.sys', '.ocx', '.cpl', '.scr', '.drv', '.efi', '.msi', '.msp', '.msu') function Test-IsPeFile { param([string]$Extension) return $script:PeExtensions -contains $Extension.ToLower() } function Get-SignatureInfo { param([string]$Path, [string]$Extension) if (-not (Test-IsPeFile -Extension $Extension)) { return [PSCustomObject]@{ Signer = 'N/A (not PE)'; Status = 'NotApplicable'; Valid = $false } } $result = [PSCustomObject]@{ Signer = 'Unsigned'; Status = 'NotSigned'; Valid = $false } try { $sig = Get-AuthenticodeSignature -LiteralPath $Path -ErrorAction Stop $result.Status = $sig.Status.ToString() $result.Valid = ($sig.Status -eq 'Valid') if ($sig.SignerCertificate) { if ($sig.SignerCertificate.Subject -match 'CN=([^,]+)') { $result.Signer = $Matches[1].Trim('"') } else { $result.Signer = $sig.SignerCertificate.Subject } if (-not $result.Valid) { $result.Signer += " [INVALID: $($result.Status)]" } } elseif ($sig.Status -eq 'NotSigned') { $result.Signer = 'Unsigned' } else { $result.Signer = "Unknown [$($result.Status)]" } } catch { $result.Signer = 'Verification error' $result.Status = 'Error' $result.Valid = $false } return $result } $rawApps = Get-ItemProperty -Path $uninstallPaths -ErrorAction SilentlyContinue | Where-Object { $_.DisplayName -and $_.DisplayName.Trim() -ne '' } | Select-Object @{Name = 'Name'; Expression = { $_.DisplayName } }, @{Name = 'Version'; Expression = { $_.DisplayVersion } }, @{Name = 'Publisher'; Expression = { $_.Publisher } }, @{Name = 'InstallFolder'; Expression = { if ($_.InstallLocation -and $_.InstallLocation.Trim() -ne '') { $_.InstallLocation } elseif ($_.UninstallString -match 'MsiExec\.exe.*?(\{[0-9A-Fa-f\-]{36}\})') { $productCode = $Matches[1] $msiLoc = Get-MsiInstallLocation -ProductCode $productCode if ($msiLoc) { $msiLoc } else { "MSI: $productCode (location not found)" } } elseif ($_.UninstallString) { $_.UninstallString } else { 'N/A' } } } | Sort-Object Name -Unique foreach ($app in $rawApps) { $versionText = if ($app.Version) { $app.Version } else { '?' } $publisherText = if ($app.Publisher) { $app.Publisher } else { '?' } Write-Host "" Write-Host "<=== $($app.Name) [$versionText] ($publisherText) ===>" if ($app.InstallFolder -eq 'N/A' -or $app.InstallFolder -match '^MSI: .* \(location not found\)$') { Write-Host " Path: $($app.InstallFolder)" continue } $cleanPath = Get-CleanPath -RawValue $app.InstallFolder $exists = $false try { $exists = Test-Path -LiteralPath $cleanPath -ErrorAction Stop } catch [System.UnauthorizedAccessException] { Write-Host " Path: $cleanPath" Write-Host " [ACCESS DENIED]" continue } catch { Write-Host " Path: $cleanPath" Write-Host " [ERROR] cannot access" continue } if (-not $exists) { Write-Host " Path: $cleanPath" Write-Host " [NOT FOUND]" continue } $rootItem = Get-Item -LiteralPath $cleanPath -Force $created = $rootItem.CreationTime.ToString('dd/MM/yyyy HH:mm:ss') $modified = $rootItem.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss') if ($rootItem.PSIsContainer) { $subFolders = Get-ChildItem -LiteralPath $cleanPath -Directory -Force -ErrorAction SilentlyContinue $gciParams = @{ LiteralPath = $cleanPath; File = $true; Force = $true; ErrorAction = 'SilentlyContinue' } if ($Recurse) { $gciParams['Recurse'] = $true } $allFiles = Get-ChildItem @gciParams Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: $($allFiles.Count) | Folders: $($subFolders.Count)" foreach ($dir in $subFolders) { $dCreated = $dir.CreationTime.ToString('dd/MM/yyyy HH:mm:ss') $dModified = $dir.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss') $dFileCount = (Get-ChildItem -LiteralPath $dir.FullName -File -Force -ErrorAction SilentlyContinue).Count Write-Host (" [DIR] {0} - {1} - {2,10} - {3}" -f $dCreated, $dModified, "$dFileCount files", $dir.FullName) } } else { $allFiles = @($rootItem) Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: 1" } if ($allFiles.Count -eq 0) { continue } $shown = $allFiles | Select-Object -First $MaxFilesPerApp foreach ($f in $shown) { $hash = 'N/A' try { $hash = (Get-FileHash -LiteralPath $f.FullName -Algorithm SHA256 -ErrorAction Stop).Hash } catch { $hash = 'HASH-ERROR' } $size = Format-FileSize -Bytes $f.Length $fcreated = $f.CreationTime.ToString('dd/MM/yyyy HH:mm:ss') $fmod = $f.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss') $sigInfo = Get-SignatureInfo -Path $f.FullName -Extension $f.Extension Write-Host (" [{0}] {1} - {2} - {3,10} - Signer: {4} - {5}" -f $hash, $fcreated, $fmod, $size, $sigInfo.Signer, $f.FullName) } } EndPowerShell: Comment: List 30 recent scheduled tasks Powershell: Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo Comment: List recent Run (Windows + R) executed commands, useful for identifying ClickFix attacks Powershell: (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" } Comment: Remove unwanted files from common folders using native removal power of Farbar to include remove on reboot if needed. Please double check the user does not have any applications incorrectly installed in the directories listed below. C:\ProgramData\*.csproj C:\ProgramData\*.a3x C:\ProgramData\*.ahk C:\ProgramData\*.au3 C:\ProgramData\*.bat C:\ProgramData\*.cab C:\ProgramData\*.cmd C:\ProgramData\*.com C:\ProgramData\*.dll C:\ProgramData\*.exe C:\ProgramData\*.hta C:\ProgramData\*.jar C:\ProgramData\*.js C:\ProgramData\*.jse C:\ProgramData\*.lnk C:\ProgramData\*.pif C:\ProgramData\*.ps1 C:\ProgramData\*.py C:\ProgramData\*.pyc C:\ProgramData\*.pyd C:\ProgramData\*.scr C:\ProgramData\*.tmp C:\ProgramData\*.vbe C:\ProgramData\*.vbs C:\ProgramData\*.wsf C:\ProgramData\*.wsh C:\ProgramData\*.zip C:\ProgramData\*.rar C:\ProgramData\*.7z C:\Users\*\AppData\Roaming\*.csproj C:\Users\*\AppData\Roaming\*.au3 C:\Users\*\AppData\Roaming\*.bat C:\Users\*\AppData\Roaming\*.cab C:\Users\*\AppData\Roaming\*.cmd C:\Users\*\AppData\Roaming\*.com C:\Users\*\AppData\Roaming\*.dll C:\Users\*\AppData\Roaming\*.exe C:\Users\*\AppData\Roaming\*.hta C:\Users\*\AppData\Roaming\*.jar C:\Users\*\AppData\Roaming\*.js C:\Users\*\AppData\Roaming\*.jse C:\Users\*\AppData\Roaming\*.lnk C:\Users\*\AppData\Roaming\*.pif C:\Users\*\AppData\Roaming\*.ps1 C:\Users\*\AppData\Roaming\*.py C:\Users\*\AppData\Roaming\*.pyc C:\Users\*\AppData\Roaming\*.pyd C:\Users\*\AppData\Roaming\*.scr C:\Users\*\AppData\Roaming\*.tmp C:\Users\*\AppData\Roaming\*.vbe C:\Users\*\AppData\Roaming\*.vbs C:\Users\*\AppData\Roaming\*.wsf C:\Users\*\AppData\Roaming\*.wsh C:\Users\*\AppData\Roaming\*.zip C:\Users\*\AppData\Roaming\*.rar C:\Users\*\AppData\Roaming\*.7z C:\Users\CurrentUserName\AppData\Local\*.csproj C:\Users\CurrentUserName\AppData\Local\*.a3x C:\Users\CurrentUserName\AppData\Local\*.ahk C:\Users\CurrentUserName\AppData\Local\*.au3 C:\Users\CurrentUserName\AppData\Local\*.bat C:\Users\CurrentUserName\AppData\Local\*.cab C:\Users\CurrentUserName\AppData\Local\*.cmd C:\Users\CurrentUserName\AppData\Local\*.com C:\Users\CurrentUserName\AppData\Local\*.dll C:\Users\CurrentUserName\AppData\Local\*.exe C:\Users\CurrentUserName\AppData\Local\*.hta C:\Users\CurrentUserName\AppData\Local\*.jar C:\Users\CurrentUserName\AppData\Local\*.js C:\Users\CurrentUserName\AppData\Local\*.jse C:\Users\CurrentUserName\AppData\Local\*.lnk C:\Users\CurrentUserName\AppData\Local\*.pif C:\Users\CurrentUserName\AppData\Local\*.ps1 C:\Users\CurrentUserName\AppData\Local\*.py C:\Users\CurrentUserName\AppData\Local\*.pyc C:\Users\CurrentUserName\AppData\Local\*.pyd C:\Users\CurrentUserName\AppData\Local\*.scr C:\Users\CurrentUserName\AppData\Local\*.tmp C:\Users\CurrentUserName\AppData\Local\*.vbe C:\Users\CurrentUserName\AppData\Local\*.vbs C:\Users\CurrentUserName\AppData\Local\*.wsf C:\Users\CurrentUserName\AppData\Local\*.wsh C:\Users\CurrentUserName\AppData\Local\*.zip C:\Users\CurrentUserName\AppData\Local\*.rar C:\Users\CurrentUserName\AppData\Local\*.7z C:\Users\CurrentUserName\AppData\Roaming\*.csproj C:\Users\CurrentUserName\AppData\Roaming\*.a3x C:\Users\CurrentUserName\AppData\Roaming\*.ahk C:\Users\CurrentUserName\AppData\Roaming\*.au3 C:\Users\CurrentUserName\AppData\Roaming\*.bat C:\Users\CurrentUserName\AppData\Roaming\*.cab C:\Users\CurrentUserName\AppData\Roaming\*.cmd C:\Users\CurrentUserName\AppData\Roaming\*.com C:\Users\CurrentUserName\AppData\Roaming\*.dll C:\Users\CurrentUserName\AppData\Roaming\*.exe C:\Users\CurrentUserName\AppData\Roaming\*.hta C:\Users\CurrentUserName\AppData\Roaming\*.jar C:\Users\CurrentUserName\AppData\Roaming\*.js C:\Users\CurrentUserName\AppData\Roaming\*.jse C:\Users\CurrentUserName\AppData\Roaming\*.lnk C:\Users\CurrentUserName\AppData\Roaming\*.pif C:\Users\CurrentUserName\AppData\Roaming\*.ps1 C:\Users\CurrentUserName\AppData\Roaming\*.py C:\Users\CurrentUserName\AppData\Roaming\*.pyc C:\Users\CurrentUserName\AppData\Roaming\*.pyd C:\Users\CurrentUserName\AppData\Roaming\*.scr C:\Users\CurrentUserName\AppData\Roaming\*.tmp C:\Users\CurrentUserName\AppData\Roaming\*.vbe C:\Users\CurrentUserName\AppData\Roaming\*.vbs C:\Users\CurrentUserName\AppData\Roaming\*.wsf C:\Users\CurrentUserName\AppData\Roaming\*.wsh C:\Users\CurrentUserName\AppData\Roaming\*.zip C:\Users\CurrentUserName\AppData\Roaming\*.rar C:\Users\CurrentUserName\AppData\Roaming\*.7z Comment: RenPyLoader hollowed installed app generic removal C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cmd C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.props C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.targets C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.tmp C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.csproj C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.user C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cmd C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cache C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.config C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.bat C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cfg C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.props C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.targets C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.tmp C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.csproj C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.user C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cmd C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cache C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.config C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.bat C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cfg C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.props C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.targets C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.tmp C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.csproj C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.user C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cmd C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cache C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.config C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.bat C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cfg C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.props C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.targets C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.tmp C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.csproj C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.user C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cmd C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cache C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.config C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.bat C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cfg C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.props C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.targets C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.tmp C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.csproj C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.user C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cmd C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cache C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.config C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.bat C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cfg C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.props C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.targets C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.tmp C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.csproj C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.user C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cmd C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cache C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.config C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.bat C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cfg C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.props C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.targets C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.tmp C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.csproj C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cmd C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.user C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cache C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.config C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.bat C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cfg Comment: Remove cache C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\ C:\Users\CurrentUserName\AppData\Local\Roblox\UniversalApp\WebView2\EBWebView\Default\Cache\Cache_Data\ C:\Users\CurrentUserName\AppData\Local\FortniteGame\Saved\webcache\ C:\Users\CurrentUserName\AppData\Local\FortniteGame\Saved\webcache_4147\ C:\Users\CurrentUserName\AppData\Local\FortniteGame\Saved\webcache_4430\ C:\Users\CurrentUserName\AppData\Roaming\discord\Cache\Cache_Data\ C:\Users\CurrentUserName\AppData\Roaming\obs-studio\plugin_config\obs-browser\Cache\Cache_Data\ StartPowerShell: $ProfilesDirectory = (Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList').ProfilesDirectory $DisplayNames = @{ "chrome" = "Chrome" "firefox" = "Firefox" "opera" = "Opera" "operagx" = "Opera GX" "brave" = "Brave" "msedge" = "Edge" "vivaldi" = "Vivaldi" "librewolf" = "LibreWolf" "mullvad" = "Mullvad Browser" "zen" = "Zen" } $ProcessNameMap = @{ "operagx" = "opera" "mullvad" = "mullvadbrowser" } $trueCacheNames = @("Cache", "Code Cache", "DawnCache", "GPUCache", "GrShaderCache", "ShaderCache", "Shared Dictionary\cache") function Get-CacheDirs { param([string]$BrowserName, [string]$ProfilesDirectory) switch ($BrowserName) { "chrome" { $dir = "$ProfilesDirectory\*\AppData\Local\Google\Chrome\User Data" Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } } "firefox" { $dir = "$ProfilesDirectory\*\AppData\Local\Mozilla\Firefox\Profiles" Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' } } "opera" { $dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software" $r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } $dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software" $r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } $r1 + $r2 } "operagx" { $dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software\Opera GX Stable" $r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } $dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software\Opera GX Stable" $r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } $r1 + $r2 } "brave" { $dir = "$ProfilesDirectory\*\AppData\Local\BraveSoftware\Brave-Browser\User Data" Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } } "msedge" { $dir = "$ProfilesDirectory\*\AppData\Local\Microsoft\Edge\User Data" Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } } "vivaldi" { $dir = "$ProfilesDirectory\*\AppData\Local\Vivaldi\User Data" Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } } "librewolf" { $dir = "$ProfilesDirectory\*\AppData\Local\LibreWolf\Profiles" Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' } } "mullvad" { $dir = "$ProfilesDirectory\*\AppData\Local\Mullvad\MullvadBrowser\Profiles" Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' } } "zen" { $dir = "$ProfilesDirectory\*\AppData\Local\zen\Profiles" Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' } } } } function Format-Size { param([long]$Bytes) if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) } if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) } if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) } return "$Bytes B" } $BrowserKeys = @('chrome', 'firefox', 'opera', 'operagx', 'brave', 'msedge', 'vivaldi', 'librewolf', 'mullvad', 'zen') foreach ($key in $BrowserKeys) { $procName = if ($ProcessNameMap.ContainsKey($key)) { $ProcessNameMap[$key] } else { $key } Get-Process -Name $procName -ErrorAction SilentlyContinue | Stop-Process -Force -ErrorAction SilentlyContinue } Start-Sleep -Seconds 5 $grandBytes = 0L $grandFiles = 0 $anyFound = $false foreach ($key in $BrowserKeys) { $cacheDirs = Get-CacheDirs -BrowserName $key -ProfilesDirectory $ProfilesDirectory if (-not $cacheDirs -or $cacheDirs.Count -eq 0) { continue } $anyFound = $true $displayName = $DisplayNames[$key] $browserBytes = 0L $browserFiles = 0 foreach ($cacheDir in $cacheDirs) { if (-not (Test-Path $cacheDir)) { continue } $items = Get-ChildItem -Path $cacheDir -Force -Recurse -ErrorAction SilentlyContinue $files = $items | Where-Object { -not $_.PSIsContainer } $bytes = ($files | Measure-Object -Property Length -Sum).Sum if (-not $bytes) { $bytes = 0 } $browserFiles += $files.Count $browserBytes += $bytes Get-ChildItem -Path "$cacheDir\*" -Force -ErrorAction SilentlyContinue | Remove-Item -Force -Recurse -ErrorAction SilentlyContinue } $grandBytes += $browserBytes $grandFiles += $browserFiles Write-Host ("{0,-16} freed {1,10} ({2} files)" -f $displayName, (Format-Size $browserBytes), $browserFiles) } if (-not $anyFound) { Write-Host "No cache found for any installed browser." } Write-Host "" Write-Host ("Total freed: {0} ({1} files)" -f (Format-Size $grandBytes), $grandFiles) EndPowerShell: Comment: Windows Recovery Environment (Windows RE) status and enable CMD: reagentc.exe /info CMD: reagentc.exe /enable Comment: Disable hidden file extensions cmd: reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "HideFileExt" /t REG_DWORD /d 0 /f cmd: reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt" /v "CheckedValue" /t REG_DWORD /d 0 /f Comment: Verify WMI repository, repair & verify again CMD: winmgmt.exe /verifyrepository CMD: winmgmt.exe /salvagerepository CMD: winmgmt.exe /verifyrepository Comment: To rebuild the performance counter library values CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R" CMD: "%WINDIR%\SysWOW64\lodctr.exe /R" CMD: "C:\Windows\SYSTEM32\lodctr.exe /R" CMD: "C:\Windows\SysWOW64\lodctr.exe /R" Comment: Resync performance counter library values to WMI as well CMD: winmgmt.exe /resyncperf Comment: Force policy removal C:\Windows\System32\GroupPolicyUsers C:\Windows\System32\GroupPolicy CMD: gpupdate.exe /force Comment: Restores and hardens selected Microsoft Defender Antivirus preferences. Comment: Tamper Protection must be temporarily disabled before applying these settings. Comment: Thanks to AdvancedSetup from Malwarebytes DeleteValue: HKLM\SOFTWARE\Microsoft\Windows Defender|DisableAntiSpyware DeleteValue: HKLM\SOFTWARE\Microsoft\Windows Defender|DisableAntiVirus StartPowerShell: # Enable real-time and behavioral protection Set-MpPreference -DisableRealtimeMonitoring $false Set-MpPreference -DisableBehaviorMonitoring $false # Enable potentially unwanted application blocking Set-MpPreference -PUAProtection Enabled # Enable cloud-delivered protection and automatic safe-sample submission Set-MpPreference -MAPSReporting Advanced Set-MpPreference -SubmitSamplesConsent SendSafeSamples # Use Microsoft's recommended high cloud-blocking level Set-MpPreference -CloudBlockLevel High # Allow additional time for cloud analysis of suspicious files Set-MpPreference -CloudExtendedTimeout 30 # Block connections to known malicious or untrusted network destinations Set-MpPreference -EnableNetworkProtection Enabled # Enable Block at First Sight Set-MpPreference -DisableBlockAtFirstSeen $false # Enable archive, removable-drive, network-file, download, and script scanning Set-MpPreference -DisableArchiveScanning $false Set-MpPreference -DisableRemovableDriveScanning $false Set-MpPreference -DisableScanningNetworkFiles $false Set-MpPreference -DisableIOAVProtection $false Set-MpPreference -DisableScriptScanning $false # Check for current security intelligence before starting a scan Set-MpPreference -CheckForSignaturesBeforeRunningScan $true # Enable supported DNS attack inspection and sinkholing when available if ((Get-Command Set-MpPreference).Parameters.ContainsKey('EnableDnsSinkhole')) { Set-MpPreference -EnableDnsSinkhole $true } # Sets signature update interval to 12 hours (default 24 hours) Set-MpPreference -SignatureUpdateInterval 12 # Update Microsoft Defender security intelligence Update-MpSignature EndPowerShell: Comment: List Windows Defender properties, settings StartPowerShell: function Write-Section { param([string]$Title) Write-Host "" Write-Host "<=== $Title ===>" } Write-Section "Protection Status" Get-MpComputerStatus | Select-Object AMServiceEnabled, AntispywareEnabled, AntivirusEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, RealTimeProtectionEnabled, IsTamperProtected, NetworkProtectionStatus | Format-List Write-Section "Signature / Engine Versions" Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AntivirusSignatureVersion, AntispywareSignatureVersion | Format-List Write-Section "Preferences / Configuration" Get-MpPreference | Select-Object PUAProtection, MAPSReporting, SubmitSamplesConsent, CheckForSignaturesBeforeRunningScan, CloudBlockLevel, EnableNetworkProtection, DisableScriptScanning, DisableArchiveScanning, DisableRemovableDriveScanning, DisableScanningNetworkFiles, DisableScanningMappedNetworkDrivesForFullScan, DisableBlockAtFirstSeen, DisableHeuristics, DisableAutoExclusions | Format-List Write-Section "Threat Detections" $threats = Get-MpThreatDetection if ($threats) { $threats | Format-Table -AutoSize } else { Write-Host " (no threat detections found)" } EndPowerShell: Comment: Enable recovery environment CMD: bcdedit.exe /set {default} recoveryenabled yes Comment: Restore original Windows services configuration StartPowerShell: Set-Service -Name "Netlogon" -StartupType Manual Set-Service -Name "BITS" -StartupType Manual Set-Service -Name "Dhcp" -StartupType Automatic Set-Service -Name "EventLog" -StartupType Automatic Set-Service -Name "EventSystem" -StartupType Automatic Set-Service -Name "nsi" -StartupType Automatic Set-Service -Name "RasMan" -StartupType Manual Set-Service -Name "SDRSVC" -StartupType Manual Set-Service -Name "SstpSvc" -StartupType Manual Set-Service -Name "TrustedInstaller" -StartupType Manual Set-Service -Name "VSS" -StartupType Manual Set-Service -Name "Winmgmt" -StartupType Automatic Set-Service -Name "wuauserv" -StartupType Manual EndPowerShell: Comment: Reset the Windows Update download cache and update catalog database CMD: net.exe stop bits CMD: net.exe stop wuauserv CMD: net.exe stop cryptsvc CMD: net.exe stop msiserver CMD: rd /s /q "%SystemRoot%\SoftwareDistribution" CMD: rd /s /q "%SystemRoot%\System32\catroot2" CMD: net.exe start msiserver CMD: net.exe start cryptsvc CMD: net.exe start wuauserv CMD: net.exe start bits Comment: Enable automatic restart after a crash, enable automatic updates StartRegedit: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl] "AutoReboot"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU] "NoAutoUpdate"=- EndRegedit: Comment: Reset PowerShell execution policy Powershell: Set-ExecutionPolicy Unrestricted -Scope CurrentUser -Force Comment: Fully reset the Windows network stack, WinHTTP proxy settings, DNS cache, and BITS transfer queue. Comment: Thanks to AdvancedSetup from Malwarebytes StartBatch: ipconfig.exe /flushdns ipconfig.exe /release netsh.exe winsock reset catalog netsh.exe int ip reset netsh.exe winhttp reset proxy netsh.exe winhttp reset autoproxy netsh.exe winhttp reset tracing EndBatch: Comment: BITS reset Startbatch: @echo off net.exe stop BITS ipconfig.exe /flushdns ren "%programdata%\Microsoft\Network\Downloader\qmgr*.*" qmgr*.*.old net.exe start BITS Endbatch: cmd: bitsadmin.exe /reset /allusers Comment: Additional temp file removal C:\Windows\System32\config\systemprofile\AppData\Local\*.tmp C:\WINDOWS\system32\*.tmp C:\WINDOWS\syswow64\*.tmp C:\Users\CurrentUserName\AppData\Local\Temp\* C:\Windows\Temp\* C:\Windows\SystemTemp\* C:\Windows\Prefetch\* Comment: System repair commands CMD: SFC.exe /scannow CMD: DISM.exe /Online /Cleanup-image /Restorehealth Comment: Remove set proxy servers RemoveProxy: Comment: Remove temporary files via FRST EmptyTemp: End::