content copied
content
Start::
SystemRestore: On
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0 <==== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.exe [11264 2019-12-07] (Microsoft Corporation) [File not signed] <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
PowerShell: Remove-MpPreference -ExclusionPath "C:\Users\Aweso\AppData\Local\Temp"
PowerShell: Remove-MpPreference -ExclusionPath "C:\ProgramData"
PowerShell: Remove-MpPreference -ExclusionPath "C:\ProgramData\Windows\Microsoft"
PowerShell: Remove-MpPreference -ExclusionPath "C:\ProgramData\Microsoft\Windows"
HKU\S-1-5-21-918861487-1455304378-3185533227-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_69EE9C38E9ED55C930D07AE7B7F5D7AC"
HKU\S-1-5-21-918861487-1455304378-3185533227-1001\...\Run: [MicrosoftEdgeAutoLaunch_69EE9C38E9ED55C930D07AE7B7F5D7AC] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --win-session-start [5018440 2026-08-20] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_291\bin\ssv.dll [2021-05-24] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_291\bin\jp2ssv.dll [2021-05-24] (Oracle America, Inc. -> Oracle Corporation)
Comment: Browser extension - Ace Script
C:\Users\Aweso\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi
Comment: Browser extension - Browsec VPN - Free VPN for Edge
C:\Users\Aweso\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjnehcbecaggobjholekjijaaekbnlgj
FF HKU\S-1-5-21-918861487-1455304378-3185533227-1001\...\Firefox\Extensions: [[email protected]] - C:\Users\Aweso\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi
C:\Users\Aweso\AppData\Roaming\ACEStream
Comment: Browser extension - Gratis VPN for Chrome - VPN Proxy VeePN
C:\Users\Aweso\AppData\Local\Google\Chrome\User Data\Default\Extensions\majdfhpaihoncoakbjgbdhglocklcgno
CHR HKU\S-1-5-21-918861487-1455304378-3185533227-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo]
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
2021-05-31 22:01 - 2021-05-31 22:01 - 000000017 _____ () C:\Users\Aweso\AppData\Roaming\.cache3678791056.dat
CustomCLSID: HKU\S-1-5-21-918861487-1455304378-3185533227-1001_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> E:\Programfiler\Autodesk3DS\3ds Max 2022\Inventor Server\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-918861487-1455304378-3185533227-1001_Classes\CLSID\{23A5B06E-20BB-4E7E-A0AC-6982ED6A6041}\localserver32 -> C:\Program Files (x86)\Steam\steamapps\common\HD Poker\HD Poker.exe => No File
CustomCLSID: HKU\S-1-5-21-918861487-1455304378-3185533227-1001_Classes\CLSID\{4e6f7264-5650-4e00-0000-000000000000}\localserver32 -> "C:\Program Files\NordVPN\NordVPN.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-918861487-1455304378-3185533227-1001_Classes\CLSID\{89b2b650-c4dd-d68b-46e7-3176f1973c8b}\localserver32 -> "C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-918861487-1455304378-3185533227-1001_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> E:\Programfiler\Autodesk3DS\3ds Max 2022\Inventor Server\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-918861487-1455304378-3185533227-1001_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> E:\Programfiler\Autodesk3DS\3ds Max 2022\Inventor Server\Bin\TestServer.dll => No File
Shortcut: C:\Users\Aweso\Desktop\spill\MSFS.lnk -> C:\FSUIPC7\MSFS.bat (No File)
AlternateDataStreams: C:\ASUS:err [1672]
AlternateDataStreams: C:\WINDOWS\system32\9EarsSurroundSound.dll:97D88723C8 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc:169D67954B [3442]
AlternateDataStreams: C:\ProgramData\TEMP:A9967A61 [139]
AlternateDataStreams: C:\ProgramData\TEMP:F4C624DE [123]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk:09A0A90EF3 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk:BE32D07BC5 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uninstall Oculus.lnk:11F44C0E16 [3442]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [3246]
FirewallRules: [UDP Query User{19A8B6E5-1E6C-4D76-835A-C4D5CEBA174D}D:\program files x86\steamlibrary\steamapps\common\drugdealersimulator\drugdealersimulator\binaries\win64\drugdealersimulator-win64-shipping.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\drugdealersimulator\drugdealersimulator\binaries\win64\drugdealersimulator-win64-shipping.exe => No File
FirewallRules: [TCP Query User{E7846F16-F893-4552-B5D2-F230BF06190F}D:\program files x86\steamlibrary\steamapps\common\drugdealersimulator\drugdealersimulator\binaries\win64\drugdealersimulator-win64-shipping.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\drugdealersimulator\drugdealersimulator\binaries\win64\drugdealersimulator-win64-shipping.exe => No File
FirewallRules: [UDP Query User{14BD1197-4046-45F5-B91C-1AFAFCF29F41}C:\users\aweso\appdata\local\discord\app-1.0.9170\discord.exe] => (Allow) C:\users\aweso\appdata\local\discord\app-1.0.9170\discord.exe => No File
FirewallRules: [TCP Query User{7B10A615-3E9E-4F40-9527-1DA29A8B9D73}C:\users\aweso\appdata\local\discord\app-1.0.9170\discord.exe] => (Allow) C:\users\aweso\appdata\local\discord\app-1.0.9170\discord.exe => No File
FirewallRules: [UDP Query User{2E9F0296-46FE-469F-B0E4-C1A2E51C86AE}C:\users\aweso\appdata\local\faceit\app-2.0.26\faceit.exe] => (Allow) C:\users\aweso\appdata\local\faceit\app-2.0.26\faceit.exe => No File
FirewallRules: [TCP Query User{315FD14A-A1BD-420C-B98D-8D4059806069}C:\users\aweso\appdata\local\faceit\app-2.0.26\faceit.exe] => (Allow) C:\users\aweso\appdata\local\faceit\app-2.0.26\faceit.exe => No File
FirewallRules: [UDP Query User{0B14E76C-FA8F-45BC-A6E6-7C56390E92F2}C:\users\aweso\appdata\local\faceit\app-2.0.24\faceit.exe] => (Allow) C:\users\aweso\appdata\local\faceit\app-2.0.24\faceit.exe => No File
FirewallRules: [TCP Query User{6BC880F6-40D2-4CE0-9C8F-E6757ED5CEAC}C:\users\aweso\appdata\local\faceit\app-2.0.24\faceit.exe] => (Allow) C:\users\aweso\appdata\local\faceit\app-2.0.24\faceit.exe => No File
FirewallRules: [UDP Query User{A7CE78D6-7494-4088-8923-B6DE6B0F1402}D:\program files x86\steamlibrary\steamapps\common\tower unite\tower\binaries\win64\tower-win64-shipping.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\tower unite\tower\binaries\win64\tower-win64-shipping.exe => No File
FirewallRules: [TCP Query User{E1E47E0F-08AB-413A-A7F0-0ADBB5D71319}D:\program files x86\steamlibrary\steamapps\common\tower unite\tower\binaries\win64\tower-win64-shipping.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\tower unite\tower\binaries\win64\tower-win64-shipping.exe => No File
FirewallRules: [UDP Query User{3885F016-4405-420C-B6AE-CB0352EE18ED}C:\users\aweso\appdata\local\discord\app-1.0.9166\discord.exe] => (Allow) C:\users\aweso\appdata\local\discord\app-1.0.9166\discord.exe => No File
FirewallRules: [TCP Query User{FB4493A6-AE05-4448-999C-7D2572901DD0}C:\users\aweso\appdata\local\discord\app-1.0.9166\discord.exe] => (Allow) C:\users\aweso\appdata\local\discord\app-1.0.9166\discord.exe => No File
FirewallRules: [UDP Query User{8086168D-D0E9-4803-98DB-C51020E56B0D}C:\users\aweso\appdata\local\wemod\app-9.10.6\wemod.exe] => (Block) C:\users\aweso\appdata\local\wemod\app-9.10.6\wemod.exe => No File
FirewallRules: [TCP Query User{B6C10718-1DF5-454E-8842-FAE0620D1831}C:\users\aweso\appdata\local\wemod\app-9.10.6\wemod.exe] => (Block) C:\users\aweso\appdata\local\wemod\app-9.10.6\wemod.exe => No File
FirewallRules: [{EBF2A2ED-F403-407C-8B61-C674891D30FB}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\Spaceflight Simulator\Spaceflight Simulator Game\Spaceflight Simulator.exe => No File
FirewallRules: [{6F055696-A937-4963-9CA5-329745A65DF0}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\Spaceflight Simulator\Spaceflight Simulator Game\Spaceflight Simulator.exe => No File
FirewallRules: [UDP Query User{37C4D336-4011-4EAD-B830-678A0403DB59}F:\program files x86\steamlibrary\steamapps\common\beamng.drive\bin64\beamng.x64.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\beamng.drive\bin64\beamng.x64.exe => No File
FirewallRules: [TCP Query User{0126CCB3-78F1-4935-B160-0B96503531D8}F:\program files x86\steamlibrary\steamapps\common\beamng.drive\bin64\beamng.x64.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\beamng.drive\bin64\beamng.x64.exe => No File
FirewallRules: [UDP Query User{5D3E4873-B21E-48E3-91EF-D3B9375720D1}D:\program files x86\steamlibrary\steamapps\common\need for speed heat\needforspeedheat.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\need for speed heat\needforspeedheat.exe => No File
FirewallRules: [TCP Query User{BF16DDB5-ED4D-4CE4-B940-0B67BF4ADB5C}D:\program files x86\steamlibrary\steamapps\common\need for speed heat\needforspeedheat.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\need for speed heat\needforspeedheat.exe => No File
FirewallRules: [UDP Query User{27F1C3E5-A070-4DB3-B02D-56C279C7B36A}C:\users\aweso\appdata\local\discord\app-1.0.9156\discord.exe] => (Allow) C:\users\aweso\appdata\local\discord\app-1.0.9156\discord.exe => No File
FirewallRules: [TCP Query User{9C0158F7-A736-4B3A-9F1C-B7B3DA9D0FA1}C:\users\aweso\appdata\local\discord\app-1.0.9156\discord.exe] => (Allow) C:\users\aweso\appdata\local\discord\app-1.0.9156\discord.exe => No File
FirewallRules: [UDP Query User{D1240802-2263-4917-A1BC-9683E9F75BB2}D:\program files x86\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\program files x86\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File
FirewallRules: [TCP Query User{3717386E-EC6E-430E-A987-ADADF4ECFB48}D:\program files x86\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\program files x86\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File
FirewallRules: [UDP Query User{09A71BAF-0947-4146-BFA5-6B449B36A205}C:\users\aweso\appdata\local\discord\app-1.0.9149\discord.exe] => (Allow) C:\users\aweso\appdata\local\discord\app-1.0.9149\discord.exe => No File
FirewallRules: [TCP Query User{4BF5CB26-D6FC-47D0-92FD-62C78D2469A3}C:\users\aweso\appdata\local\discord\app-1.0.9149\discord.exe] => (Allow) C:\users\aweso\appdata\local\discord\app-1.0.9149\discord.exe => No File
FirewallRules: [UDP Query User{22914573-6C86-4E1F-9396-A905EF8138BB}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b3095_gtaprocess.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b3095_gtaprocess.exe => No File
FirewallRules: [TCP Query User{09711594-7276-48A0-B202-0A68373DB5B4}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b3095_gtaprocess.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b3095_gtaprocess.exe => No File
FirewallRules: [UDP Query User{F380EA06-B506-456C-928F-B16A788B89B9}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_steamchild.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_steamchild.exe => No File
FirewallRules: [TCP Query User{A779E2EC-7BF9-4E98-B865-4078D87FEB71}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_steamchild.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_steamchild.exe => No File
FirewallRules: [UDP Query User{DDB3A739-2E7B-4AF8-B245-BADFC26D68B8}C:\users\aweso\appdata\local\fivem\fivem.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.exe => No File
FirewallRules: [TCP Query User{6F79815B-EC1A-485E-A400-240C89597EEC}C:\users\aweso\appdata\local\fivem\fivem.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.exe => No File
FirewallRules: [{E68CA08C-C100-43BD-8023-959E01243AAD}] => (Allow) C:\Program Files\FenixSim A320\deps\GqlGateway\Fenix.GqlGateway.exe => No File
FirewallRules: [{09659B0D-D58E-46BF-86ED-B423E4C7EFF2}] => (Allow) C:\Program Files\FenixSim A320\deps\GqlGateway\Fenix.GqlGateway.exe => No File
FirewallRules: [{B55C13B1-D18A-4650-9B49-4F42000BA121}] => (Allow) C:\Program Files\FenixSim A320\deps\FenixSystem.exe => No File
FirewallRules: [{88632CF3-E3FE-4A3E-B2EB-17689F4CB47A}] => (Allow) C:\Program Files\FenixSim A320\deps\FenixSystem.exe => No File
FirewallRules: [{41C49779-0216-4710-9B36-7EC865F21DC9}] => (Allow) E:\Programfiler (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe => No File
FirewallRules: [{2EBFEC89-891D-4AD3-B7ED-ABD06A6F40A7}] => (Allow) E:\Programfiler (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe => No File
FirewallRules: [UDP Query User{B385BA70-02D8-459B-9404-3331284DC74B}C:\users\aweso\downloads\assettocorsaevoluzione_v1.2\assetto corsa evoluzione\assetto corsa evoluzione.exe] => (Allow) C:\users\aweso\downloads\assettocorsaevoluzione_v1.2\assetto corsa evoluzione\assetto corsa evoluzione.exe => No File
FirewallRules: [TCP Query User{9A7BD58B-23CF-4D38-AB64-B79B351D6786}C:\users\aweso\downloads\assettocorsaevoluzione_v1.2\assetto corsa evoluzione\assetto corsa evoluzione.exe] => (Allow) C:\users\aweso\downloads\assettocorsaevoluzione_v1.2\assetto corsa evoluzione\assetto corsa evoluzione.exe => No File
FirewallRules: [{42D17458-2CEA-4CC1-BC24-8924A5CEB989}] => (Allow) C:\Program Files (x86)\3uToolsV3\x86\extrastools\3uAirPlayer\airplayer_dlna\DlnaService.exe => No File
FirewallRules: [{74007584-30BE-43AC-9932-A087E54432C4}] => (Allow) C:\Program Files (x86)\3uToolsV3\x86\extrastools\3uAirPlayer\3uAirPlayer.exe => No File
FirewallRules: [UDP Query User{15087D6E-AB3B-479A-BA6B-DCABCA39F454}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File
FirewallRules: [TCP Query User{1688E1DE-B10F-4314-A157-91C95C6604F8}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File
FirewallRules: [UDP Query User{09524FE4-3689-4ED1-AF01-645F9932ECAE}C:\users\aweso\desktop\warno.v96938\warno\warno.exe] => (Allow) C:\users\aweso\desktop\warno.v96938\warno\warno.exe => No File
FirewallRules: [TCP Query User{BAEE104E-A41A-442F-90C6-DC2BA8EBB75A}C:\users\aweso\desktop\warno.v96938\warno\warno.exe] => (Allow) C:\users\aweso\desktop\warno.v96938\warno\warno.exe => No File
FirewallRules: [UDP Query User{21A5F9C3-A63A-40EB-9552-763F2A17CABD}D:\games\ride.4\ride 4\ride4\binaries\win64\ride4-win64-shipping.exe] => (Allow) D:\games\ride.4\ride 4\ride4\binaries\win64\ride4-win64-shipping.exe => No File
FirewallRules: [TCP Query User{3DBB1B15-8491-450C-AC7B-8D8F235EEDCB}D:\games\ride.4\ride 4\ride4\binaries\win64\ride4-win64-shipping.exe] => (Allow) D:\games\ride.4\ride 4\ride4\binaries\win64\ride4-win64-shipping.exe => No File
FirewallRules: [UDP Query User{5F0E69BA-7B99-4117-9C4A-F04F21B41CB2}F:\program files x86\steamlibrary\steamapps\common\brick rigs\brickrigs\binaries\win64\brickrigs-win64-shipping.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\brick rigs\brickrigs\binaries\win64\brickrigs-win64-shipping.exe => No File
FirewallRules: [TCP Query User{1AC5D2D1-E07B-457A-ABAB-F642B6C8BD8A}F:\program files x86\steamlibrary\steamapps\common\brick rigs\brickrigs\binaries\win64\brickrigs-win64-shipping.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\brick rigs\brickrigs\binaries\win64\brickrigs-win64-shipping.exe => No File
FirewallRules: [{D5CD2218-160D-436D-9234-F1C3FC74D425}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\Automation\UE427\AutomationGame\Binaries\Win64\AutomationGame-Win64-Shipping.exe => No File
FirewallRules: [{62952DA1-C304-4E96-A44E-692A623C8FE7}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\Automation\UE427\AutomationGame\Binaries\Win64\AutomationGame-Win64-Shipping.exe => No File
FirewallRules: [UDP Query User{4B6E71BA-29D3-45E0-ABAE-69CE53B9065E}C:\users\aweso\desktop\motor.town.behind.the.wheel.v0.6.19\motor.town.behind.the.wheel.v0.6.19\motortown\binaries\win64\motortown-win64-shipping.exe] => (Allow) C:\users\aweso\desktop\motor.town.behind.the.wheel.v0.6.19\motor.town.behind.the.wheel.v0.6.19\motortown\binaries\win64\motortown-win64-shipping.exe => No File
FirewallRules: [TCP Query User{61CD4781-BC2A-4833-8C2A-A4F10EE3DC40}C:\users\aweso\desktop\motor.town.behind.the.wheel.v0.6.19\motor.town.behind.the.wheel.v0.6.19\motortown\binaries\win64\motortown-win64-shipping.exe] => (Allow) C:\users\aweso\desktop\motor.town.behind.the.wheel.v0.6.19\motor.town.behind.the.wheel.v0.6.19\motortown\binaries\win64\motortown-win64-shipping.exe => No File
FirewallRules: [UDP Query User{6652B91D-E206-48CD-BF82-8883058E01AD}D:\games\contractors.vr\contractors.vr\contractorsvr\zomboy_p\binaries\win64\zomboy_p-win64-shipping.exe] => (Allow) D:\games\contractors.vr\contractors.vr\contractorsvr\zomboy_p\binaries\win64\zomboy_p-win64-shipping.exe => No File
FirewallRules: [TCP Query User{0BFC7B64-9270-47FB-8C4F-A07F59FD1212}D:\games\contractors.vr\contractors.vr\contractorsvr\zomboy_p\binaries\win64\zomboy_p-win64-shipping.exe] => (Allow) D:\games\contractors.vr\contractors.vr\contractorsvr\zomboy_p\binaries\win64\zomboy_p-win64-shipping.exe => No File
FirewallRules: [UDP Query User{2D1C1E15-CC51-4C50-A860-68C003386D6F}D:\games\contractors.vr\contractors.vr\contractorsvr\contractors.exe] => (Allow) D:\games\contractors.vr\contractors.vr\contractorsvr\contractors.exe => No File
FirewallRules: [TCP Query User{81AD90C7-595D-4765-BAD4-7BABD0A039F6}D:\games\contractors.vr\contractors.vr\contractorsvr\contractors.exe] => (Allow) D:\games\contractors.vr\contractors.vr\contractorsvr\contractors.exe => No File
FirewallRules: [UDP Query User{E926BA9A-ADE6-428C-98E9-A56D23E22B09}D:\games\hand.simulator.rendezvous\hand simulator rendezvous\hand simulator rendezvous.exe] => (Allow) D:\games\hand.simulator.rendezvous\hand simulator rendezvous\hand simulator rendezvous.exe => No File
FirewallRules: [TCP Query User{517880CF-92C1-4CC3-B29D-F12D6A96448C}D:\games\hand.simulator.rendezvous\hand simulator rendezvous\hand simulator rendezvous.exe] => (Allow) D:\games\hand.simulator.rendezvous\hand simulator rendezvous\hand simulator rendezvous.exe => No File
FirewallRules: [{25BEEBB8-D23F-4EDC-8F2F-8903DA55B3CD}] => (Allow) C:\Program Files\BlueStacks_nxt\BlueStacksAppplayerWeb.exe => No File
FirewallRules: [{B48802AE-F0FD-49E1-93F4-B423D98E9486}] => (Allow) C:\Program Files\BlueStacks_nxt\HD-Player.exe => No File
FirewallRules: [{F86DF744-647F-49D2-B842-7BB29F6E42CD}] => (Allow) C:\Program Files (x86)\BlueStacks X\Cloud Game.exe => No File
FirewallRules: [{17BD8072-BD1C-403A-AC78-B8EFE2D9DC39}] => (Allow) C:\Program Files (x86)\BlueStacks X\BlueStacksWeb.exe => No File
FirewallRules: [UDP Query User{5D6BD908-784E-44E6-999E-0EECB6388F9A}C:\users\aweso\appdata\local\discord\app-1.0.9011\discord.exe] => (Allow) C:\users\aweso\appdata\local\discord\app-1.0.9011\discord.exe => No File
FirewallRules: [TCP Query User{A5FB07AC-69FD-4A68-80DF-33414C3349AA}C:\users\aweso\appdata\local\discord\app-1.0.9011\discord.exe] => (Allow) C:\users\aweso\appdata\local\discord\app-1.0.9011\discord.exe => No File
FirewallRules: [{F0C5DA09-239B-4756-93C5-C7E71DD9D5CB}] => (Allow) F:\Program Files x86\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe => No File
FirewallRules: [{241921DE-5687-49B2-B88F-F59FC1E684DA}] => (Allow) F:\Program Files x86\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe => No File
FirewallRules: [{7777C277-C95C-4454-858A-1234A01A6278}] => (Allow) F:\Program Files x86\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe => No File
FirewallRules: [{84FF987C-4E09-4936-A462-DAEA250E377A}] => (Allow) F:\Program Files x86\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe => No File
FirewallRules: [UDP Query User{C8892FDE-D750-4DCD-B6A6-6A32C65F8F7A}F:\torrents\hogwarts legacy\phoenix\binaries\win64\hogwartslegacy.exe] => (Allow) F:\torrents\hogwarts legacy\phoenix\binaries\win64\hogwartslegacy.exe => No File
FirewallRules: [TCP Query User{50B8E841-30FE-4352-B325-1BF6F5FE26C1}F:\torrents\hogwarts legacy\phoenix\binaries\win64\hogwartslegacy.exe] => (Allow) F:\torrents\hogwarts legacy\phoenix\binaries\win64\hogwartslegacy.exe => No File
FirewallRules: [{B7916D68-DBC1-44EB-B61A-9D26064815D9}] => (Allow) C:\Program Files (x86)\Tacview\FSX2ACMI.exe => No File
FirewallRules: [{EDF47446-12D6-4146-9B89-013CBFD75129}] => (Allow) C:\Program Files (x86)\Tacview\FSX2ACMI.exe => No File
FirewallRules: [{E4D39CAB-8EDE-4A9C-B3D8-07863B7677DF}] => (Allow) C:\Program Files (x86)\Tacview\Tacview64.exe => No File
FirewallRules: [{B0FC185A-E8B7-4EFE-82D9-045BE3C3DF4E}] => (Allow) C:\Program Files (x86)\Tacview\Tacview64.exe => No File
FirewallRules: [UDP Query User{80087830-3A9C-4CAF-A9C6-B4BE304B2280}C:\users\aweso\desktop\trombone.champ.v1.0898\trombone.champ.v1.0898\trombonechamp.exe] => (Allow) C:\users\aweso\desktop\trombone.champ.v1.0898\trombone.champ.v1.0898\trombonechamp.exe => No File
FirewallRules: [TCP Query User{7B0301E8-E54C-4C42-92D8-95F39EE4EA7E}C:\users\aweso\desktop\trombone.champ.v1.0898\trombone.champ.v1.0898\trombonechamp.exe] => (Allow) C:\users\aweso\desktop\trombone.champ.v1.0898\trombone.champ.v1.0898\trombonechamp.exe => No File
FirewallRules: [UDP Query User{E7A7A7E3-F86A-4F9E-847A-BD2BE734753E}C:\program files (x86)\steam\steamapps\common\sandstorm\insurgency\binaries\win64\insurgencyclient-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\sandstorm\insurgency\binaries\win64\insurgencyclient-win64-shipping.exe => No File
FirewallRules: [TCP Query User{16EBCAD5-33FC-4C2E-99E5-F839BDD42E42}C:\program files (x86)\steam\steamapps\common\sandstorm\insurgency\binaries\win64\insurgencyclient-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\sandstorm\insurgency\binaries\win64\insurgencyclient-win64-shipping.exe => No File
FirewallRules: [{9C2D57A2-FD04-4515-957B-C351DC2920EA}] => (Allow) C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe => No File
FirewallRules: [UDP Query User{317471F9-F6CD-4763-BEA7-0A58DE46B06D}C:\users\aweso\desktop\assetto corsa evoluzione\assetto corsa evoluzione.exe] => (Allow) C:\users\aweso\desktop\assetto corsa evoluzione\assetto corsa evoluzione.exe => No File
FirewallRules: [TCP Query User{4BC3930F-A88C-447C-AFFB-A41A6B81C278}C:\users\aweso\desktop\assetto corsa evoluzione\assetto corsa evoluzione.exe] => (Allow) C:\users\aweso\desktop\assetto corsa evoluzione\assetto corsa evoluzione.exe => No File
FirewallRules: [UDP Query User{0284FBB1-D056-4818-A5CC-D9977A95FA83}C:\users\aweso\appdata\local\racelabapps\app-3.3.1\racelabapps.exe] => (Allow) C:\users\aweso\appdata\local\racelabapps\app-3.3.1\racelabapps.exe => No File
FirewallRules: [TCP Query User{09016D65-3742-4F89-8004-A3031AE7B6B4}C:\users\aweso\appdata\local\racelabapps\app-3.3.1\racelabapps.exe] => (Allow) C:\users\aweso\appdata\local\racelabapps\app-3.3.1\racelabapps.exe => No File
FirewallRules: [UDP Query User{6D620F0F-D019-4055-B260-F9F4C902A37B}C:\users\aweso\desktop\arduino\arduino ide.exe] => (Allow) C:\users\aweso\desktop\arduino\arduino ide.exe => No File
FirewallRules: [TCP Query User{5AC6AF4E-ECE0-4AE4-9998-82FE041A6EFA}C:\users\aweso\desktop\arduino\arduino ide.exe] => (Allow) C:\users\aweso\desktop\arduino\arduino ide.exe => No File
FirewallRules: [{739D88FF-8705-48FA-A528-D037E5C9D6D3}] => (Allow) F:\Program Files x86\SteamLibrary\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe => No File
FirewallRules: [{77E18B16-9C2F-4619-BC59-DE08BC00313D}] => (Allow) F:\Program Files x86\SteamLibrary\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe => No File
FirewallRules: [UDP Query User{DFE037C0-4F44-4B2A-8B9A-E152426D4DD8}D:\games\red.dead.redemption.2.ultimate.edition.rgl.rip-insaneramzes\red dead redemption 2\rdr2.exe] => (Allow) D:\games\red.dead.redemption.2.ultimate.edition.rgl.rip-insaneramzes\red dead redemption 2\rdr2.exe => No File
FirewallRules: [TCP Query User{06496687-0EF4-49AF-BF94-F5C17A9E6890}D:\games\red.dead.redemption.2.ultimate.edition.rgl.rip-insaneramzes\red dead redemption 2\rdr2.exe] => (Allow) D:\games\red.dead.redemption.2.ultimate.edition.rgl.rip-insaneramzes\red dead redemption 2\rdr2.exe => No File
FirewallRules: [UDP Query User{186FCB50-DA51-46AA-B5D7-E4D05D295AB1}D:\games\the long dark\tld.exe] => (Allow) D:\games\the long dark\tld.exe => No File
FirewallRules: [TCP Query User{DBA1D0A2-8676-4BFF-818B-523DF6F535F1}D:\games\the long dark\tld.exe] => (Allow) D:\games\the long dark\tld.exe => No File
FirewallRules: [UDP Query User{97FE1AED-DCE2-436A-8E5C-37ED20CFBABC}D:\games\rfactor2\bin64\rfactor2 mod mode.exe] => (Allow) D:\games\rfactor2\bin64\rfactor2 mod mode.exe => No File
FirewallRules: [TCP Query User{5567AF27-90BC-45AA-A2E6-DE31872B12B2}D:\games\rfactor2\bin64\rfactor2 mod mode.exe] => (Allow) D:\games\rfactor2\bin64\rfactor2 mod mode.exe => No File
FirewallRules: [UDP Query User{7DC0F161-497D-431B-BE1D-E90EFEED9B7E}D:\games\rfactor2\bin64\rfactor2.exe] => (Allow) D:\games\rfactor2\bin64\rfactor2.exe => No File
FirewallRules: [TCP Query User{9FD07923-37DD-43E0-89D9-B37838AD2160}D:\games\rfactor2\bin64\rfactor2.exe] => (Allow) D:\games\rfactor2\bin64\rfactor2.exe => No File
FirewallRules: [UDP Query User{799BF2D3-4F95-4A9E-A40D-B6015288451C}G:4\forzahorizon5.exe] => (Block) G:4\forzahorizon5.exe => No File
FirewallRules: [TCP Query User{8BE6205C-CEAC-43B9-9548-9BA41A4FB4B5}G:4\forzahorizon5.exe] => (Block) G:4\forzahorizon5.exe => No File
FirewallRules: [UDP Query User{A385D4CB-49E3-4F27-9762-B063F8CE0CAA}G:3\forzahorizon5.exe] => (Allow) G:3\forzahorizon5.exe => No File
FirewallRules: [TCP Query User{6BDCAECE-50FB-4D22-9A47-727279D7B906}G:3\forzahorizon5.exe] => (Allow) G:3\forzahorizon5.exe => No File
FirewallRules: [UDP Query User{2111FB8A-E441-4B67-A137-E435A9D22AD8}G:1\forzahorizon5.exe] => (Allow) G:1\forzahorizon5.exe => No File
FirewallRules: [TCP Query User{D4305C98-B55F-4540-8EE8-654185559A63}G:1\forzahorizon5.exe] => (Allow) G:1\forzahorizon5.exe => No File
FirewallRules: [UDP Query User{F657041F-278A-4968-88B3-64F9C1C44687}F:\program files x86\steamlibrary\steamapps\common\7 days to die\7daystodie.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\7 days to die\7daystodie.exe => No File
FirewallRules: [TCP Query User{1F5325E3-CAFA-4F16-BCB3-27C2EE020F52}F:\program files x86\steamlibrary\steamapps\common\7 days to die\7daystodie.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\7 days to die\7daystodie.exe => No File
FirewallRules: [{35B126F4-D65E-4465-972C-62A82C16C93D}] => (Allow) F:\Program Files x86\SteamLibrary\steamapps\common\TurnSignal\TurnSignal.exe => No File
FirewallRules: [{2C225386-00E2-4D40-8905-9916FF6B48B6}] => (Allow) F:\Program Files x86\SteamLibrary\steamapps\common\TurnSignal\TurnSignal.exe => No File
FirewallRules: [UDP Query User{1B9AA2A7-0E67-4F4F-A099-C4EF94A1F184}F:\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe] => (Allow) F:\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe => No File
FirewallRules: [TCP Query User{2121A1FF-65CB-4949-8A59-B9DA7EA9910B}F:\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe] => (Allow) F:\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe => No File
FirewallRules: [UDP Query User{5E402C7B-3D88-464D-803D-2A0355E36C25}C:\torrents\into.the.radius.vr.v16.10.2021\intotheradius\intotheradius\binaries\win64\intotheradius-win64-shipping.exe] => (Allow) C:\torrents\into.the.radius.vr.v16.10.2021\intotheradius\intotheradius\binaries\win64\intotheradius-win64-shipping.exe => No File
FirewallRules: [TCP Query User{7F5C0198-403B-4CE1-9C02-5037A2A36093}C:\torrents\into.the.radius.vr.v16.10.2021\intotheradius\intotheradius\binaries\win64\intotheradius-win64-shipping.exe] => (Allow) C:\torrents\into.the.radius.vr.v16.10.2021\intotheradius\intotheradius\binaries\win64\intotheradius-win64-shipping.exe => No File
FirewallRules: [UDP Query User{DF1244AF-15CD-47B2-93FE-531E1C837F14}C:\users\aweso\appdata\local\vortxengine\app-2.2.17\signal-x64\signalrgb.exe] => (Allow) C:\users\aweso\appdata\local\vortxengine\app-2.2.17\signal-x64\signalrgb.exe => No File
FirewallRules: [TCP Query User{C9C281E3-1192-482F-A855-0EF0E5FB7728}C:\users\aweso\appdata\local\vortxengine\app-2.2.17\signal-x64\signalrgb.exe] => (Allow) C:\users\aweso\appdata\local\vortxengine\app-2.2.17\signal-x64\signalrgb.exe => No File
FirewallRules: [UDP Query User{8C3CF489-6326-4899-86DA-E5B157B5476D}E:\programfiler (x86)\torrents\rfactor2\bin64\rfactor2.exe] => (Allow) E:\programfiler (x86)\torrents\rfactor2\bin64\rfactor2.exe => No File
FirewallRules: [TCP Query User{21E6D660-F239-42C8-A085-88C19E0325C3}E:\programfiler (x86)\torrents\rfactor2\bin64\rfactor2.exe] => (Allow) E:\programfiler (x86)\torrents\rfactor2\bin64\rfactor2.exe => No File
FirewallRules: [{36D50BEE-9BD2-471F-AB31-BED32C79CB9A}] => (Allow) E:\Programfiler (x86)\Steam\steamapps\common\raceroom racing experience\Game\RRRE.exe => No File
FirewallRules: [{962DACF2-A52A-4EBD-8602-109D65CAF289}] => (Allow) E:\Programfiler (x86)\Steam\steamapps\common\raceroom racing experience\Game\RRRE.exe => No File
FirewallRules: [{C9CD90A6-69A5-48BE-BC90-88578D02C169}] => (Allow) E:\Programfiler (x86)\Steam\steamapps\common\raceroom racing experience\Game\x64\RRRE64.exe => No File
FirewallRules: [{2806314A-0775-46C7-BA39-D7C5B694E255}] => (Allow) E:\Programfiler (x86)\Steam\steamapps\common\raceroom racing experience\Game\x64\RRRE64.exe => No File
FirewallRules: [{8DBF1716-CBAE-47D3-8EDA-6DCB64189885}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\TotallyAccurateBattlegrounds\TotallyAccurateBattlegrounds.exe => No File
FirewallRules: [{E706B542-4DCC-4201-B497-89D9FD6DC561}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\TotallyAccurateBattlegrounds\TotallyAccurateBattlegrounds.exe => No File
FirewallRules: [UDP Query User{9D5FCE1F-F7B4-4458-B19B-AB27B0FE3059}D:\program files x86\steamlibrary\steamapps\common\fifa 22\fifa22_trial.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\fifa 22\fifa22_trial.exe => No File
FirewallRules: [TCP Query User{CAAD1BA4-23AA-4665-958B-72F133B8E38B}D:\program files x86\steamlibrary\steamapps\common\fifa 22\fifa22_trial.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\fifa 22\fifa22_trial.exe => No File
FirewallRules: [UDP Query User{76F77B8A-3156-4252-9A20-5B3BB2B66646}F:\torrents\blade.and.sorcery.update.9\blade & sorcery\bladeandsorcery.exe] => (Allow) F:\torrents\blade.and.sorcery.update.9\blade & sorcery\bladeandsorcery.exe => No File
FirewallRules: [TCP Query User{0F42E6E3-1031-4724-A8BC-87BEC0404D6D}F:\torrents\blade.and.sorcery.update.9\blade & sorcery\bladeandsorcery.exe] => (Allow) F:\torrents\blade.and.sorcery.update.9\blade & sorcery\bladeandsorcery.exe => No File
FirewallRules: [UDP Query User{60C0DFF4-D0A0-403D-9F78-B54C10EFF9D2}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe => No File
FirewallRules: [TCP Query User{D9613A57-4D76-48FC-8D1E-A1A57B896646}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe => No File
FirewallRules: [{47672EA9-0EDD-49E5-B60D-3B21781D76A3}] => (Allow) F:\Program Files x86\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe => No File
FirewallRules: [{D5148CFC-4B86-4B72-B571-E407265DE552}] => (Allow) F:\Program Files x86\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe => No File
FirewallRules: [UDP Query User{FC33EB66-12B9-4378-95A0-3770E093E54A}D:\games\dcs world\bin\dcs.exe] => (Allow) D:\games\dcs world\bin\dcs.exe => No File
FirewallRules: [TCP Query User{F0C7CFE4-B546-44F2-9ACA-3BD368B46B2D}D:\games\dcs world\bin\dcs.exe] => (Allow) D:\games\dcs world\bin\dcs.exe => No File
FirewallRules: [UDP Query User{09E27E35-915D-4D7F-803A-E4831DEEB40C}C:\users\aweso\appdata\roaming\beammp launcher\beammp-launcher.exe] => (Allow) C:\users\aweso\appdata\roaming\beammp launcher\beammp-launcher.exe => No File
FirewallRules: [TCP Query User{39E0132A-73E8-49B2-B6A0-598DD01EF5B7}C:\users\aweso\appdata\roaming\beammp launcher\beammp-launcher.exe] => (Allow) C:\users\aweso\appdata\roaming\beammp launcher\beammp-launcher.exe => No File
FirewallRules: [UDP Query User{D4B9BEE6-03E4-4B53-9BB6-7E3E0751A93C}E:\programfiler (x86)\torrents\wrench.build.135\wrench.build.135\wrenchgame\binaries\win64\wrenchgame-win64-shipping.exe] => (Allow) E:\programfiler (x86)\torrents\wrench.build.135\wrench.build.135\wrenchgame\binaries\win64\wrenchgame-win64-shipping.exe => No File
FirewallRules: [TCP Query User{45ED2021-3162-464D-A10A-BC7598113E93}E:\programfiler (x86)\torrents\wrench.build.135\wrench.build.135\wrenchgame\binaries\win64\wrenchgame-win64-shipping.exe] => (Allow) E:\programfiler (x86)\torrents\wrench.build.135\wrench.build.135\wrenchgame\binaries\win64\wrenchgame-win64-shipping.exe => No File
FirewallRules: [{A29DF334-5702-4AA5-AAA1-6A605EEC41C2}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe => No File
FirewallRules: [{10E2E0A7-57FA-4992-B521-9DD4E3BBC2AB}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe => No File
FirewallRules: [{BDE2B8B9-01DD-49C9-B4E8-67A8C9A5B598}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe => No File
FirewallRules: [{BCC4393E-FBC9-4E91-806D-8526DF82F766}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe => No File
FirewallRules: [UDP Query User{1F0CA32D-761E-4059-916E-C71FA4527650}E:\programfiler (x86)\genshin impact\genshin impact game\genshinimpact.exe] => (Allow) E:\programfiler (x86)\genshin impact\genshin impact game\genshinimpact.exe => No File
FirewallRules: [TCP Query User{FCB73A12-BCB4-4861-B865-D2B52E2964FB}E:\programfiler (x86)\genshin impact\genshin impact game\genshinimpact.exe] => (Allow) E:\programfiler (x86)\genshin impact\genshin impact game\genshinimpact.exe => No File
FirewallRules: [UDP Query User{0C45D463-3E51-4EA3-A6B2-33C2720DF9AB}C:\users\aweso\appdata\local\vortxengine\app-2.2.11\signal-x64\signalrgb.exe] => (Allow) C:\users\aweso\appdata\local\vortxengine\app-2.2.11\signal-x64\signalrgb.exe => No File
FirewallRules: [TCP Query User{831585CB-797F-42F4-9747-530F048C0141}C:\users\aweso\appdata\local\vortxengine\app-2.2.11\signal-x64\signalrgb.exe] => (Allow) C:\users\aweso\appdata\local\vortxengine\app-2.2.11\signal-x64\signalrgb.exe => No File
FirewallRules: [UDP Query User{ECADDD99-9DBD-4EC3-ACDD-6BC0FCEA6A17}C:\program files\genshin impact\genshin impact game\genshinimpact.exe] => (Allow) C:\program files\genshin impact\genshin impact game\genshinimpact.exe => No File
FirewallRules: [TCP Query User{1C89D053-E99A-4486-85D9-F14DF0F0BBEB}C:\program files\genshin impact\genshin impact game\genshinimpact.exe] => (Allow) C:\program files\genshin impact\genshin impact game\genshinimpact.exe => No File
FirewallRules: [UDP Query User{F38006BC-3EC3-43A9-A52D-9FE63510AB43}F:\program files x86\steamlibrary\steamapps\common\war thunder\win64\aces.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\war thunder\win64\aces.exe => No File
FirewallRules: [TCP Query User{446E3C99-7C98-47D8-8A53-9D0875ED0E9C}F:\program files x86\steamlibrary\steamapps\common\war thunder\win64\aces.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\war thunder\win64\aces.exe => No File
FirewallRules: [UDP Query User{97636775-ABAB-4981-ABBD-DBFE11D08CD8}E:\nedlastninger\torrents\blade.and.sorcery.v9.3\blade & sorcery\bladeandsorcery.exe] => (Allow) E:\nedlastninger\torrents\blade.and.sorcery.v9.3\blade & sorcery\bladeandsorcery.exe => No File
FirewallRules: [TCP Query User{261835DB-A1CE-46A1-BEC3-D585199C3A65}E:\nedlastninger\torrents\blade.and.sorcery.v9.3\blade & sorcery\bladeandsorcery.exe] => (Allow) E:\nedlastninger\torrents\blade.and.sorcery.v9.3\blade & sorcery\bladeandsorcery.exe => No File
FirewallRules: [UDP Query User{FE1A8EC1-6E94-4A57-960A-D49BBA34F7FA}E:\programfiler (x86)\torrents\police.simulator.patrol.officers.build.7022258\police.simulator.patrol.officers.build.7022258\boston\binaries\win64\boston-win64-shipping.exe] => (Allow) E:\programfiler (x86)\torrents\police.simulator.patrol.officers.build.7022258\police.simulator.patrol.officers.build.7022258\boston\binaries\win64\boston-win64-shipping.exe => No File
FirewallRules: [TCP Query User{D2272BDC-448C-4DEA-8592-CF9FD8C1571D}E:\programfiler (x86)\torrents\police.simulator.patrol.officers.build.7022258\police.simulator.patrol.officers.build.7022258\boston\binaries\win64\boston-win64-shipping.exe] => (Allow) E:\programfiler (x86)\torrents\police.simulator.patrol.officers.build.7022258\police.simulator.patrol.officers.build.7022258\boston\binaries\win64\boston-win64-shipping.exe => No File
FirewallRules: [UDP Query User{694D13E7-C3BA-46EB-8207-48BBC8677C68}C:\riot games\riot client\riotclientservices.exe] => (Allow) C:\riot games\riot client\riotclientservices.exe => No File
FirewallRules: [TCP Query User{62E18D61-FA87-4BC4-940F-23807F77CF84}C:\riot games\riot client\riotclientservices.exe] => (Allow) C:\riot games\riot client\riotclientservices.exe => No File
FirewallRules: [UDP Query User{8CDC77B9-2C01-4540-86E2-4B7DB2FD5DA3}C:\users\aweso\downloads\blood.trail.v28.12.2020\blood trail\bloodtrail_419ai\binaries\win64\vrexppluginexample-win64-shipping.exe.unpacked.exe] => (Allow) C:\users\aweso\downloads\blood.trail.v28.12.2020\blood trail\bloodtrail_419ai\binaries\win64\vrexppluginexample-win64-shipping.exe.unpacked.exe => No File
FirewallRules: [TCP Query User{163CF95F-1E67-4B9A-A28B-3A34158D28EE}C:\users\aweso\downloads\blood.trail.v28.12.2020\blood trail\bloodtrail_419ai\binaries\win64\vrexppluginexample-win64-shipping.exe.unpacked.exe] => (Allow) C:\users\aweso\downloads\blood.trail.v28.12.2020\blood trail\bloodtrail_419ai\binaries\win64\vrexppluginexample-win64-shipping.exe.unpacked.exe => No File
FirewallRules: [UDP Query User{80A91B8B-6253-4EC6-B2CD-34CBCC921D7C}F:\nedlastninger\torrents\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe] => (Allow) F:\nedlastninger\torrents\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe => No File
FirewallRules: [TCP Query User{A23AE206-C9E8-491F-8E3F-60DE69712265}F:\nedlastninger\torrents\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe] => (Allow) F:\nedlastninger\torrents\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe => No File
FirewallRules: [UDP Query User{C11B227F-E0ED-4952-9E1E-4530FE6967B8}C:\program files (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe => No File
FirewallRules: [TCP Query User{2B9A674C-D81E-47DF-8F3F-410B0BC5C456}C:\program files (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe => No File
FirewallRules: [{F1D75621-4FD5-4AE8-B2EA-96E90BEC31EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\3DMark\bin\x64\3DMark.exe => No File
FirewallRules: [{5D82CE95-7B6E-4E91-8132-E64ED50A12C0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\3DMark\bin\x64\3DMark.exe => No File
FirewallRules: [{84330CFF-7658-4AFD-A6C6-A68B1129EDCB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\3DMark\bin\x86\3DMark.exe => No File
FirewallRules: [{3B99F034-6219-4C4A-824C-E03C61335E50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\3DMark\bin\x86\3DMark.exe => No File
FirewallRules: [UDP Query User{166BA30A-5139-48B1-9B08-6DCD18EB5541}F:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) F:\program files\rockstar games\grand theft auto v\gta5.exe => No File
FirewallRules: [TCP Query User{EE39A39E-365B-4EB5-82F7-2A8A95FAA132}F:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) F:\program files\rockstar games\grand theft auto v\gta5.exe => No File
FirewallRules: [{82FCFF5D-3EED-4552-B6EC-922FDFE47A89}] => (Block) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2372_gtaprocess.exe => No File
FirewallRules: [{D9210C8C-6920-4784-87C9-26B040D3C239}] => (Block) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2372_gtaprocess.exe => No File
FirewallRules: [UDP Query User{351CE473-2CE9-43B5-A370-BEE4A57F4176}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2372_gtaprocess.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2372_gtaprocess.exe => No File
FirewallRules: [TCP Query User{B144CDE9-3426-466A-9C0E-8A6BA1663F2D}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2372_gtaprocess.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2372_gtaprocess.exe => No File
FirewallRules: [UDP Query User{09F71029-9D4C-4F02-93EA-77DDF515F8C6}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2060_gtaprocess.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2060_gtaprocess.exe => No File
FirewallRules: [TCP Query User{634987E2-F2DF-410F-9DB7-91D9A1B26B53}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2060_gtaprocess.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2060_gtaprocess.exe => No File
FirewallRules: [UDP Query User{158C07B7-3664-4B4A-81A2-56360E531C5C}C:\users\aweso\desktop\stride.update.6\stride\binaries\win64\stride-win64-shipping.exe] => (Allow) C:\users\aweso\desktop\stride.update.6\stride\binaries\win64\stride-win64-shipping.exe => No File
FirewallRules: [TCP Query User{3B061BBB-4656-4ED4-88EF-051ECC275626}C:\users\aweso\desktop\stride.update.6\stride\binaries\win64\stride-win64-shipping.exe] => (Allow) C:\users\aweso\desktop\stride.update.6\stride\binaries\win64\stride-win64-shipping.exe => No File
FirewallRules: [UDP Query User{B041D78B-CE1E-47D7-877E-99C3522A76B3}C:\program files (x86)\steam\steamapps\common\fifa 21\fifa21_trial.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\fifa 21\fifa21_trial.exe => No File
FirewallRules: [TCP Query User{32B315F8-878F-4251-9782-6A5837D787FF}C:\program files (x86)\steam\steamapps\common\fifa 21\fifa21_trial.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\fifa 21\fifa21_trial.exe => No File
FirewallRules: [UDP Query User{3866AEC1-4F8F-4389-BD81-6E1FFF0733E1}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2189_gtaprocess.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2189_gtaprocess.exe => No File
FirewallRules: [TCP Query User{D368D8DC-A7E3-49EB-88ED-A66509D11942}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2189_gtaprocess.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2189_gtaprocess.exe => No File
FirewallRules: [UDP Query User{7278B36D-BCCF-4851-B603-7BB0FB08261B}C:\users\aweso\desktop\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe] => (Allow) C:\users\aweso\desktop\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe => No File
FirewallRules: [TCP Query User{AED13EFD-CE88-4564-AF01-210457DA18B0}C:\users\aweso\desktop\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe] => (Allow) C:\users\aweso\desktop\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe => No File
FirewallRules: [UDP Query User{954B6FD8-BB6E-4250-A9D0-D75C75401BE9}C:\program files (x86)\steam\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Block) C:\program files (x86)\steam\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe => No File
FirewallRules: [TCP Query User{92599B1C-2AE7-4C06-BC6D-65FD24EB6657}C:\program files (x86)\steam\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Block) C:\program files (x86)\steam\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe => No File
FirewallRules: [UDP Query User{32913256-0E04-4E5A-97FF-23CD50B46038}C:\program files\epic games\genshinimpact\genshin impact game\genshinimpact.exe] => (Allow) C:\program files\epic games\genshinimpact\genshin impact game\genshinimpact.exe => No File
FirewallRules: [TCP Query User{4B97688C-2A31-41A1-B3A3-8990AEC67A3C}C:\program files\epic games\genshinimpact\genshin impact game\genshinimpact.exe] => (Allow) C:\program files\epic games\genshinimpact\genshin impact game\genshinimpact.exe => No File
FirewallRules: [UDP Query User{73AACFEA-DBE2-415B-B896-0A1D9922D942}C:\users\aweso\desktop\pavlovvr.update.22\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Block) C:\users\aweso\desktop\pavlovvr.update.22\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe => No File
FirewallRules: [TCP Query User{2E7A062A-56FA-44A9-B8B8-76D735A0EDCE}C:\users\aweso\desktop\pavlovvr.update.22\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Block) C:\users\aweso\desktop\pavlovvr.update.22\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe => No File
FirewallRules: [UDP Query User{86C81082-3C2F-470B-B92D-D27A2D6E67B3}F:\program files x86\overwatch\_retail_\overwatch.exe] => (Allow) F:\program files x86\overwatch\_retail_\overwatch.exe => No File
FirewallRules: [TCP Query User{EB05AB66-0867-46F2-811C-E8C92110137C}F:\program files x86\overwatch\_retail_\overwatch.exe] => (Allow) F:\program files x86\overwatch\_retail_\overwatch.exe => No File
FirewallRules: [UDP Query User{08E9996A-5661-4DC4-A38C-A7C569F04D05}C:\users\aweso\desktop\spill\beat.saber.v1.14.0\beat.saber.v1.14.0\beat saber.exe] => (Allow) C:\users\aweso\desktop\spill\beat.saber.v1.14.0\beat.saber.v1.14.0\beat saber.exe => No File
FirewallRules: [TCP Query User{504CBBD9-4608-424C-A196-A3C6B58BC252}C:\users\aweso\desktop\spill\beat.saber.v1.14.0\beat.saber.v1.14.0\beat saber.exe] => (Allow) C:\users\aweso\desktop\spill\beat.saber.v1.14.0\beat.saber.v1.14.0\beat saber.exe => No File
FirewallRules: [UDP Query User{97ACE515-93BA-4CE0-B4A5-2DE7B2641B8D}F:\apper og spill\spill\beat.saber.v1.14.0\beat.saber.v1.14.0\beat saber.exe] => (Allow) F:\apper og spill\spill\beat.saber.v1.14.0\beat.saber.v1.14.0\beat saber.exe => No File
FirewallRules: [TCP Query User{FE179F55-3469-4FCC-BD05-5B3866AF5107}F:\apper og spill\spill\beat.saber.v1.14.0\beat.saber.v1.14.0\beat saber.exe] => (Allow) F:\apper og spill\spill\beat.saber.v1.14.0\beat.saber.v1.14.0\beat saber.exe => No File
FirewallRules: [{99898C00-93EC-41C2-96C3-BA256EE6408E}] => (Allow) C:\Program Files\Oculus\Software\Software\sharecare-you-by-sharecare\YOU_VR.exe => No File
FirewallRules: [{849378D3-0D34-47D6-ABC0-0F2AB8FEA9CB}] => (Allow) C:\Program Files\Oculus\Software\Software\sharecare-you-by-sharecare\YOU_VR.exe => No File
FirewallRules: [UDP Query User{CDFAB50D-4CDE-4077-8C0A-709560C5C902}F:\program files x86\steamlibrary\steamapps\common\the sims 4\game-cracked\bin_le\ts4.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\the sims 4\game-cracked\bin_le\ts4.exe => No File
FirewallRules: [TCP Query User{565EDEFA-CFED-4C76-B66C-77D7F5FF8AD7}F:\program files x86\steamlibrary\steamapps\common\the sims 4\game-cracked\bin_le\ts4.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\the sims 4\game-cracked\bin_le\ts4.exe => No File
FirewallRules: [UDP Query User{1596DB75-64B3-4DE1-BB5E-EDEC4F5B4BBD}F:\program files x86\steamlibrary\steamapps\common\the sims 4\game-cracked\bin\ts4_x64.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\the sims 4\game-cracked\bin\ts4_x64.exe => No File
FirewallRules: [TCP Query User{BAEC358D-8497-412D-8A7A-F83D98762732}F:\program files x86\steamlibrary\steamapps\common\the sims 4\game-cracked\bin\ts4_x64.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\the sims 4\game-cracked\bin\ts4_x64.exe => No File
FirewallRules: [UDP Query User{F77A290D-E602-4571-9D42-137BDB289AEC}C:\program files (x86)\steam\steamapps\common\bus simulator 18\bussimulator18\binaries\win64\bussimulator18-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\bus simulator 18\bussimulator18\binaries\win64\bussimulator18-win64-shipping.exe => No File
FirewallRules: [TCP Query User{9A7D0B81-FE8B-47F0-BF1D-79C732E5A06C}C:\program files (x86)\steam\steamapps\common\bus simulator 18\bussimulator18\binaries\win64\bussimulator18-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\bus simulator 18\bussimulator18\binaries\win64\bussimulator18-win64-shipping.exe => No File
FirewallRules: [UDP Query User{096DF490-521F-4C90-8716-81D1479E3ADA}C:\users\aweso\desktop\agfy-mx.bikes\mx bikes\mxbikes.exe] => (Allow) C:\users\aweso\desktop\agfy-mx.bikes\mx bikes\mxbikes.exe => No File
FirewallRules: [TCP Query User{B5AB3B03-7C82-4881-9A53-C8E1EF3E2533}C:\users\aweso\desktop\agfy-mx.bikes\mx bikes\mxbikes.exe] => (Allow) C:\users\aweso\desktop\agfy-mx.bikes\mx bikes\mxbikes.exe => No File
FirewallRules: [UDP Query User{C036F26A-4D64-4695-84AD-26FCFDF1E7FC}C:\program files (x86)\steam\steamapps\common\nvidia vr funhouse\engine\binaries\win64\ue4game-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\nvidia vr funhouse\engine\binaries\win64\ue4game-win64-shipping.exe => No File
FirewallRules: [TCP Query User{7783205E-3A7D-4C3F-8E9B-BD05297A0A26}C:\program files (x86)\steam\steamapps\common\nvidia vr funhouse\engine\binaries\win64\ue4game-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\nvidia vr funhouse\engine\binaries\win64\ue4game-win64-shipping.exe => No File
FirewallRules: [UDP Query User{8948A0B0-5095-4E20-9D64-4ACE663C6DE1}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_gtaprocess.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_gtaprocess.exe => No File
FirewallRules: [TCP Query User{C1DEF118-DE63-44CF-9EAA-14DCF2184F91}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_gtaprocess.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_gtaprocess.exe => No File
FirewallRules: [{503D3615-C636-47E5-B286-18115E3A2B90}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVR\bin\win32\vrstartup.exe => No File
FirewallRules: [{74988F68-FEA6-47A7-A1E1-72BD0464F0F1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVR\bin\win32\vrstartup.exe => No File
FirewallRules: [UDP Query User{5B8EEC8B-64CC-4141-9883-B173CF07A403}C:\users\aweso\desktop\spill\blade.and.sorcery.update.9\blade & sorcery\bladeandsorcery.exe] => (Block) C:\users\aweso\desktop\spill\blade.and.sorcery.update.9\blade & sorcery\bladeandsorcery.exe => No File
FirewallRules: [TCP Query User{EF71712A-FEB5-482A-B162-3917D288B553}C:\users\aweso\desktop\spill\blade.and.sorcery.update.9\blade & sorcery\bladeandsorcery.exe] => (Block) C:\users\aweso\desktop\spill\blade.and.sorcery.update.9\blade & sorcery\bladeandsorcery.exe => No File
FirewallRules: [UDP Query User{EE26935F-6512-4CC4-BF0D-B1245399D35F}C:\users\aweso\desktop\blade.and.sorcery.update.9\blade & sorcery\bladeandsorcery.exe] => (Allow) C:\users\aweso\desktop\blade.and.sorcery.update.9\blade & sorcery\bladeandsorcery.exe => No File
FirewallRules: [TCP Query User{121A87A3-E995-4E8D-ADBB-C34D7F99BE74}C:\users\aweso\desktop\blade.and.sorcery.update.9\blade & sorcery\bladeandsorcery.exe] => (Allow) C:\users\aweso\desktop\blade.and.sorcery.update.9\blade & sorcery\bladeandsorcery.exe => No File
FirewallRules: [{2C77F2B8-9F02-4023-A210-811C8F1DCF74}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{C82C30B1-77D9-42F3-BBBE-19CE6B8270B3}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [TCP Query User{48EDD5B7-D635-48C6-9863-3C01D2E9788C}E:\programfiler (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe] => (Allow) E:\programfiler (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe => No File
FirewallRules: [UDP Query User{2CED5358-F95E-4347-8353-B69FEF7F09A3}E:\programfiler (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe] => (Allow) E:\programfiler (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe => No File
FirewallRules: [TCP Query User{C1913F40-3FE3-4A69-B239-55C518FF9752}C:\users\aweso\appdata\local\vortxengine\app-2.2.18\signal-x64\signalrgb.exe] => (Allow) C:\users\aweso\appdata\local\vortxengine\app-2.2.18\signal-x64\signalrgb.exe => No File
FirewallRules: [UDP Query User{5EE4416A-513B-4D96-9661-A581EC609B2E}C:\users\aweso\appdata\local\vortxengine\app-2.2.18\signal-x64\signalrgb.exe] => (Allow) C:\users\aweso\appdata\local\vortxengine\app-2.2.18\signal-x64\signalrgb.exe => No File
FirewallRules: [TCP Query User{74B7C63B-EB2F-400F-AD81-7B707D5A967E}E:\programfiler (x86)\battle.net\overwatch\_retail_\overwatch.exe] => (Allow) E:\programfiler (x86)\battle.net\overwatch\_retail_\overwatch.exe => No File
FirewallRules: [UDP Query User{EC3FD7E3-9EF6-481F-A84C-6B0778216969}E:\programfiler (x86)\battle.net\overwatch\_retail_\overwatch.exe] => (Allow) E:\programfiler (x86)\battle.net\overwatch\_retail_\overwatch.exe => No File
FirewallRules: [TCP Query User{C41E0FA2-2BAE-4767-BB55-BA4F308578A2}D:\games\boneworks.v1.6\boneworks\boneworks.exe] => (Allow) D:\games\boneworks.v1.6\boneworks\boneworks.exe => No File
FirewallRules: [UDP Query User{6C0D07D8-9761-49C7-9031-CDBEA8D799B1}D:\games\boneworks.v1.6\boneworks\boneworks.exe] => (Allow) D:\games\boneworks.v1.6\boneworks\boneworks.exe => No File
FirewallRules: [TCP Query User{B2A53161-D617-43AE-B429-AAF041F55636}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2545_gtaprocess.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2545_gtaprocess.exe => No File
FirewallRules: [UDP Query User{BCD38BC9-596D-4FEF-8149-1189AC104FE4}C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2545_gtaprocess.exe] => (Allow) C:\users\aweso\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2545_gtaprocess.exe => No File
FirewallRules: [TCP Query User{929C7F14-E100-41A6-ACED-6EE0B7F4D636}D:\games\riot games\riot client\riotclientservices.exe] => (Allow) D:\games\riot games\riot client\riotclientservices.exe => No File
FirewallRules: [UDP Query User{E0260384-8156-4548-9D42-5AEFFCFAFF4F}D:\games\riot games\riot client\riotclientservices.exe] => (Allow) D:\games\riot games\riot client\riotclientservices.exe => No File
FirewallRules: [TCP Query User{2CD62FF8-6435-4013-B996-FD1310BC7F44}D:\games\assetto corsa competizione\ac2\binaries\win64\ac2-win64-shipping.exe] => (Allow) D:\games\assetto corsa competizione\ac2\binaries\win64\ac2-win64-shipping.exe => No File
FirewallRules: [UDP Query User{5B327F0D-41BE-4919-842E-EDA3951C1F85}D:\games\assetto corsa competizione\ac2\binaries\win64\ac2-win64-shipping.exe] => (Allow) D:\games\assetto corsa competizione\ac2\binaries\win64\ac2-win64-shipping.exe => No File
FirewallRules: [TCP Query User{6C57E026-C134-4B07-8D24-F3482B2682AF}F:\torrents\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe] => (Allow) F:\torrents\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe => No File
FirewallRules: [UDP Query User{A47B075D-F99D-4EA7-A01D-0CED28090789}F:\torrents\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe] => (Allow) F:\torrents\fuser.all.dlc\fuser\fuser\binaries\win64\fusereos-win64-shipping.exe => No File
FirewallRules: [TCP Query User{8F9AD4BC-C3D2-4297-8E9D-76552FA174CC}C:\program files\msfs2020 map enhancement\resources\extra\nginx\nginx.exe] => (Allow) C:\program files\msfs2020 map enhancement\resources\extra\nginx\nginx.exe => No File
FirewallRules: [UDP Query User{8D57E422-60DF-4A2F-8204-72C4181D53F3}C:\program files\msfs2020 map enhancement\resources\extra\nginx\nginx.exe] => (Allow) C:\program files\msfs2020 map enhancement\resources\extra\nginx\nginx.exe => No File
FirewallRules: [TCP Query User{62970840-6592-4A7D-80BD-EEE882DBB050}D:\program files x86\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe => No File
FirewallRules: [UDP Query User{AE8F3572-7CCF-4D6E-A00E-BD0F7EF60D2B}D:\program files x86\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe => No File
FirewallRules: [{E239E5C5-7EA8-409F-9E5F-1B7186D82469}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\PokerStars VR\PokerStarsVR.exe => No File
FirewallRules: [{521B4671-6367-44E0-ABF2-B9B240E9655C}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\PokerStars VR\PokerStarsVR.exe => No File
FirewallRules: [TCP Query User{866A32F0-D60F-476F-8E85-D6D77AEA692A}C:\users\aweso\appdata\local\programs\volanta\volanta.exe] => (Allow) C:\users\aweso\appdata\local\programs\volanta\volanta.exe => No File
FirewallRules: [UDP Query User{C2DC30A0-D7F9-4B06-B354-71A5B56C7990}C:\users\aweso\appdata\local\programs\volanta\volanta.exe] => (Allow) C:\users\aweso\appdata\local\programs\volanta\volanta.exe => No File
FirewallRules: [TCP Query User{0C95790A-6783-4DD5-8B99-415BDDA1C74F}C:\users\aweso\appdata\local\programs\sky4sim pad\sky4sim pad.exe] => (Allow) C:\users\aweso\appdata\local\programs\sky4sim pad\sky4sim pad.exe => No File
FirewallRules: [UDP Query User{ECD6FFB5-6D24-459E-B2C1-5AA792C93013}C:\users\aweso\appdata\local\programs\sky4sim pad\sky4sim pad.exe] => (Allow) C:\users\aweso\appdata\local\programs\sky4sim pad\sky4sim pad.exe => No File
FirewallRules: [TCP Query User{4EC3C281-51C7-4E98-96AA-EC9DD0D8392B}C:\users\aweso\appdata\local\temp\rar$exa7668.5631\msfs landing inspector v1_2.exe] => (Allow) C:\users\aweso\appdata\local\temp\rar$exa7668.5631\msfs landing inspector v1_2.exe => No File
FirewallRules: [UDP Query User{859084D9-FBEF-452B-B65C-788A1255E850}C:\users\aweso\appdata\local\temp\rar$exa7668.5631\msfs landing inspector v1_2.exe] => (Allow) C:\users\aweso\appdata\local\temp\rar$exa7668.5631\msfs landing inspector v1_2.exe => No File
FirewallRules: [TCP Query User{9914A11C-685F-4757-BD59-4038CA85149E}C:\users\aweso\desktop\tfdi design - pacx v1.2.13\pacx.exe] => (Allow) C:\users\aweso\desktop\tfdi design - pacx v1.2.13\pacx.exe => No File
FirewallRules: [UDP Query User{5A678998-3BB3-4F64-A9A6-27CC07E890A8}C:\users\aweso\desktop\tfdi design - pacx v1.2.13\pacx.exe] => (Allow) C:\users\aweso\desktop\tfdi design - pacx v1.2.13\pacx.exe => No File
FirewallRules: [TCP Query User{36F2AA2C-8A3F-4552-A4EE-DA15454A6660}C:\users\aweso\appdata\local\temp\rar$exa20260.37029\msfs landing inspector v1_2.exe] => (Allow) C:\users\aweso\appdata\local\temp\rar$exa20260.37029\msfs landing inspector v1_2.exe => No File
FirewallRules: [UDP Query User{CD861D92-EEEF-46F2-B524-BB6F04F0B02A}C:\users\aweso\appdata\local\temp\rar$exa20260.37029\msfs landing inspector v1_2.exe] => (Allow) C:\users\aweso\appdata\local\temp\rar$exa20260.37029\msfs landing inspector v1_2.exe => No File
FirewallRules: [TCP Query User{9D5792C6-CEF3-4ECF-8049-07FD43FF1545}C:\program files (x86)\steam\steamapps\common\steamvr\bin\win64\vrmonitor.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\steamvr\bin\win64\vrmonitor.exe => No File
FirewallRules: [UDP Query User{4C30F0A0-D267-4578-868A-EFC84CE2F700}C:\program files (x86)\steam\steamapps\common\steamvr\bin\win64\vrmonitor.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\steamvr\bin\win64\vrmonitor.exe => No File
FirewallRules: [TCP Query User{D62097F5-3CC8-4B37-8ADA-36DDD9572BC0}D:\games\eleven.table.tennis.vr\eleven.table.tennis.vr\pong_waves_vr.exe] => (Allow) D:\games\eleven.table.tennis.vr\eleven.table.tennis.vr\pong_waves_vr.exe => No File
FirewallRules: [UDP Query User{6133DF9D-B8FD-4DC1-97F7-F90FE2C08E09}D:\games\eleven.table.tennis.vr\eleven.table.tennis.vr\pong_waves_vr.exe] => (Allow) D:\games\eleven.table.tennis.vr\eleven.table.tennis.vr\pong_waves_vr.exe => No File
FirewallRules: [TCP Query User{8A71B83F-9F98-4C4B-943C-323EB4FC58DB}C:\users\aweso\desktop\eleven.table.tennis.vr\eleven table tennis vr [8041791]\pong_waves_vr.exe] => (Allow) C:\users\aweso\desktop\eleven.table.tennis.vr\eleven table tennis vr [8041791]\pong_waves_vr.exe => No File
FirewallRules: [UDP Query User{C7C99FDB-945C-49BD-9D17-9FB741F920CA}C:\users\aweso\desktop\eleven.table.tennis.vr\eleven table tennis vr [8041791]\pong_waves_vr.exe] => (Allow) C:\users\aweso\desktop\eleven.table.tennis.vr\eleven table tennis vr [8041791]\pong_waves_vr.exe => No File
FirewallRules: [TCP Query User{74F56B70-EB33-422C-826A-BFB2DA22F030}C:\program files (x86)\steam\steamapps\common\steamvr\bin\win64\vrdashboard.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\steamvr\bin\win64\vrdashboard.exe => No File
FirewallRules: [UDP Query User{F76D0675-25C7-4EC5-A10E-DF2D807CE0F3}C:\program files (x86)\steam\steamapps\common\steamvr\bin\win64\vrdashboard.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\steamvr\bin\win64\vrdashboard.exe => No File
FirewallRules: [TCP Query User{F2880A97-0D18-42F8-B98E-0B9BEEE92827}C:\users\aweso\desktop\eleven table tennis vr [8041791]\pong_waves_vr.exe] => (Allow) C:\users\aweso\desktop\eleven table tennis vr [8041791]\pong_waves_vr.exe => No File
FirewallRules: [UDP Query User{2A6F1931-693A-406F-B706-C9AC3BF2729B}C:\users\aweso\desktop\eleven table tennis vr [8041791]\pong_waves_vr.exe] => (Allow) C:\users\aweso\desktop\eleven table tennis vr [8041791]\pong_waves_vr.exe => No File
FirewallRules: [TCP Query User{7F704975-05B4-41E8-A233-507AF4013CBA}C:\users\aweso\appdata\local\temp\rar$exa8040.20328\eleven.table.tennis.vr\eleven table tennis vr [8041791]\pong_waves_vr.exe] => (Block) C:\users\aweso\appdata\local\temp\rar$exa8040.20328\eleven.table.tennis.vr\eleven table tennis vr [8041791]\pong_waves_vr.exe => No File
FirewallRules: [UDP Query User{C9C97F06-00ED-43DF-96BA-B5172977DA81}C:\users\aweso\appdata\local\temp\rar$exa8040.20328\eleven.table.tennis.vr\eleven table tennis vr [8041791]\pong_waves_vr.exe] => (Block) C:\users\aweso\appdata\local\temp\rar$exa8040.20328\eleven.table.tennis.vr\eleven table tennis vr [8041791]\pong_waves_vr.exe => No File
FirewallRules: [TCP Query User{6F70607C-72E9-4063-BE71-B7A65863AEE7}D:\games\mxbikes.exe] => (Allow) D:\games\mxbikes.exe => No File
FirewallRules: [UDP Query User{ECBA86DD-FF63-4016-90AA-179D8983E740}D:\games\mxbikes.exe] => (Allow) D:\games\mxbikes.exe => No File
FirewallRules: [TCP Query User{D41F8F23-C6C1-4572-8230-E395F53344BA}D:\program files x86\steamlibrary\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe => No File
FirewallRules: [UDP Query User{3B1627BB-C771-4CE0-894B-46849CCC8242}D:\program files x86\steamlibrary\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe => No File
FirewallRules: [TCP Query User{621920C3-A0DF-4673-89F4-54A1C361FAC8}D:\games\gpbikes.exe] => (Allow) D:\games\gpbikes.exe => No File
FirewallRules: [UDP Query User{04246289-5872-4CEC-B338-A6E25B01C582}D:\games\gpbikes.exe] => (Allow) D:\games\gpbikes.exe => No File
FirewallRules: [TCP Query User{A2BAE9CC-90EF-45D2-A4BD-B4F26A99FAC6}D:\games\mxbikes\mxbikes.exe] => (Allow) D:\games\mxbikes\mxbikes.exe => No File
FirewallRules: [UDP Query User{B3AC9B05-093D-47F1-886A-0AAEED89A801}D:\games\mxbikes\mxbikes.exe] => (Allow) D:\games\mxbikes\mxbikes.exe => No File
FirewallRules: [TCP Query User{AE540FA9-DF63-4581-A50C-0AAF148FB273}F:\program files x86\rockstar games\grand theft auto v\gta5.exe] => (Allow) F:\program files x86\rockstar games\grand theft auto v\gta5.exe => No File
FirewallRules: [UDP Query User{D9D1F5D8-3302-4D2F-B13F-3D28DD3ABF96}F:\program files x86\rockstar games\grand theft auto v\gta5.exe] => (Allow) F:\program files x86\rockstar games\grand theft auto v\gta5.exe => No File
FirewallRules: [TCP Query User{C8099F61-67A4-47B6-83C3-0FE11033EB89}C:\program files (x86)\steam\steamapps\common\red dead redemption 2\rdr2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\red dead redemption 2\rdr2.exe => No File
FirewallRules: [UDP Query User{1E0A2070-F7E3-43B7-9A41-99074B97A6DF}C:\program files (x86)\steam\steamapps\common\red dead redemption 2\rdr2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\red dead redemption 2\rdr2.exe => No File
FirewallRules: [TCP Query User{F71C4F91-7763-44B6-9A88-D7C1A4FA20D1}E:\nedlastninger\torrents\kayak.vr.mirage\kayak vr\kayak_vr\binaries\win64\kayak_vr-win64-shipping.exe] => (Allow) E:\nedlastninger\torrents\kayak.vr.mirage\kayak vr\kayak_vr\binaries\win64\kayak_vr-win64-shipping.exe => No File
FirewallRules: [UDP Query User{9E7E4A96-E593-4039-AA77-ECD606633A2C}E:\nedlastninger\torrents\kayak.vr.mirage\kayak vr\kayak_vr\binaries\win64\kayak_vr-win64-shipping.exe] => (Allow) E:\nedlastninger\torrents\kayak.vr.mirage\kayak vr\kayak_vr\binaries\win64\kayak_vr-win64-shipping.exe => No File
FirewallRules: [TCP Query User{BDAF68C9-EEAE-4498-8702-78EED74A6977}D:\games\being.a.dik.season.1.build.6706895\being.a.dik.season.1.build.6706895\being.a.dik.season.1.build.6706895\lib\windows-i686\beingadik.exe] => (Allow) D:\games\being.a.dik.season.1.build.6706895\being.a.dik.season.1.build.6706895\being.a.dik.season.1.build.6706895\lib\windows-i686\beingadik.exe => No File
FirewallRules: [UDP Query User{21B87E2E-D7FE-4BF0-82FE-D21C41577003}D:\games\being.a.dik.season.1.build.6706895\being.a.dik.season.1.build.6706895\being.a.dik.season.1.build.6706895\lib\windows-i686\beingadik.exe] => (Allow) D:\games\being.a.dik.season.1.build.6706895\being.a.dik.season.1.build.6706895\being.a.dik.season.1.build.6706895\lib\windows-i686\beingadik.exe => No File
FirewallRules: [TCP Query User{FB653CCB-9067-4F67-8DBB-9FFC8D46F9CD}D:\games\green.hell.vr.v1.0.7\green hell vr\ghvr.exe] => (Allow) D:\games\green.hell.vr.v1.0.7\green hell vr\ghvr.exe => No File
FirewallRules: [UDP Query User{3C9D2A18-9F25-4A67-9AF4-5D4217250FA7}D:\games\green.hell.vr.v1.0.7\green hell vr\ghvr.exe] => (Allow) D:\games\green.hell.vr.v1.0.7\green hell vr\ghvr.exe => No File
FirewallRules: [TCP Query User{A30383DD-2AFE-47D8-A0DF-3374A62FFEB8}C:\users\aweso\appdata\local\discord\app-1.0.9006\discord.exe] => (Block) C:\users\aweso\appdata\local\discord\app-1.0.9006\discord.exe => No File
FirewallRules: [UDP Query User{19650D96-D554-41B5-A0A9-A15531A8CBBD}C:\users\aweso\appdata\local\discord\app-1.0.9006\discord.exe] => (Block) C:\users\aweso\appdata\local\discord\app-1.0.9006\discord.exe => No File
FirewallRules: [TCP Query User{C7A8259B-8F60-48E7-BF8F-6B73C1FE825E}C:\users\aweso\downloads\vr.skater\vr skater\vrskater\binaries\win64\vrskater-win64-shipping.exe] => (Allow) C:\users\aweso\downloads\vr.skater\vr skater\vrskater\binaries\win64\vrskater-win64-shipping.exe => No File
FirewallRules: [UDP Query User{C17F7972-4FE0-4666-8A7C-6D210B21B6D7}C:\users\aweso\downloads\vr.skater\vr skater\vrskater\binaries\win64\vrskater-win64-shipping.exe] => (Allow) C:\users\aweso\downloads\vr.skater\vr skater\vrskater\binaries\win64\vrskater-win64-shipping.exe => No File
FirewallRules: [TCP Query User{E989CD0F-303C-44D5-8499-A4550D293E88}C:\users\aweso\downloads\bartender.vr.simulator\bartender vr simulator\bartendervr\binaries\win64\barman_grabbingnewplugin.exe] => (Allow) C:\users\aweso\downloads\bartender.vr.simulator\bartender vr simulator\bartendervr\binaries\win64\barman_grabbingnewplugin.exe => No File
FirewallRules: [UDP Query User{9BB4D4A6-C789-4629-BEFB-9A1530C7E54C}C:\users\aweso\downloads\bartender.vr.simulator\bartender vr simulator\bartendervr\binaries\win64\barman_grabbingnewplugin.exe] => (Allow) C:\users\aweso\downloads\bartender.vr.simulator\bartender vr simulator\bartendervr\binaries\win64\barman_grabbingnewplugin.exe => No File
FirewallRules: [TCP Query User{D072A502-45E2-4B1C-B068-3CD23F8E99A6}C:\users\aweso\desktop\all.in.one.sports.vr\all-in-one sports vr\allinonesports.exe] => (Allow) C:\users\aweso\desktop\all.in.one.sports.vr\all-in-one sports vr\allinonesports.exe => No File
FirewallRules: [UDP Query User{EDAA66E9-895A-42D7-AB64-1BF70D969905}C:\users\aweso\desktop\all.in.one.sports.vr\all-in-one sports vr\allinonesports.exe] => (Allow) C:\users\aweso\desktop\all.in.one.sports.vr\all-in-one sports vr\allinonesports.exe => No File
FirewallRules: [TCP Query User{A12B0706-3285-46C9-8F0B-7986AA8EABC5}C:\users\aweso\desktop\x-plane 11\x-plane.exe] => (Allow) C:\users\aweso\desktop\x-plane 11\x-plane.exe => No File
FirewallRules: [UDP Query User{FF03F6AB-2406-4365-A03C-F83959BD9AC6}C:\users\aweso\desktop\x-plane 11\x-plane.exe] => (Allow) C:\users\aweso\desktop\x-plane 11\x-plane.exe => No File
FirewallRules: [TCP Query User{97A01FA0-F24C-4260-B668-503997694CCF}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe => No File
FirewallRules: [UDP Query User{978F5445-1442-4BFB-9E30-FBD94D5ECBBF}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe => No File
FirewallRules: [{FC4E0200-53CF-459E-9266-0B08ACC026EC}] => (Allow) C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe => No File
FirewallRules: [{18E4942C-D7C7-4323-8BA8-8BBAABE25AEC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MX Bikes\mxbikes.exe => No File
FirewallRules: [{0196CA39-247A-4489-B25C-75A7EFBE7463}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MX Bikes\mxbikes.exe => No File
FirewallRules: [TCP Query User{33523E52-B49B-4D63-8FE4-46DE2F9A0729}C:\users\aweso\appdata\local\citra\canary-mingw\citra-qt.exe] => (Allow) C:\users\aweso\appdata\local\citra\canary-mingw\citra-qt.exe => No File
FirewallRules: [UDP Query User{5FD65EB9-DF2B-46A2-9162-AB20404FFE94}C:\users\aweso\appdata\local\citra\canary-mingw\citra-qt.exe] => (Allow) C:\users\aweso\appdata\local\citra\canary-mingw\citra-qt.exe => No File
FirewallRules: [TCP Query User{FFA1C63C-2835-417C-97A4-5569488E2461}C:\users\aweso\desktop\disney.dreamlight.valley.v1.0.5.88\disney.dreamlight.valley\ddv.exe] => (Allow) C:\users\aweso\desktop\disney.dreamlight.valley.v1.0.5.88\disney.dreamlight.valley\ddv.exe => No File
FirewallRules: [UDP Query User{170BBE0D-89B0-439B-B992-5973AFD23A1D}C:\users\aweso\desktop\disney.dreamlight.valley.v1.0.5.88\disney.dreamlight.valley\ddv.exe] => (Allow) C:\users\aweso\desktop\disney.dreamlight.valley.v1.0.5.88\disney.dreamlight.valley\ddv.exe => No File
FirewallRules: [TCP Query User{F6BB19E5-57F0-4284-8CA1-155635C15DFA}E:\programfiler (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) E:\programfiler (x86)\steam\steamapps\common\war thunder\win64\aces.exe => No File
FirewallRules: [UDP Query User{D59575F0-33F2-4B70-9A92-BCC9697988CA}E:\programfiler (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) E:\programfiler (x86)\steam\steamapps\common\war thunder\win64\aces.exe => No File
FirewallRules: [TCP Query User{4910516E-5191-4BC3-9F17-9D9199A0D88B}C:\users\aweso\desktop\bonelab\bonelab\bonelab_steam_windows64.exe] => (Allow) C:\users\aweso\desktop\bonelab\bonelab\bonelab_steam_windows64.exe => No File
FirewallRules: [UDP Query User{AC3B8BFA-42FD-4F26-9DE2-0E3AB49AAA75}C:\users\aweso\desktop\bonelab\bonelab\bonelab_steam_windows64.exe] => (Allow) C:\users\aweso\desktop\bonelab\bonelab\bonelab_steam_windows64.exe => No File
FirewallRules: [{B44A52BD-E41B-4DD8-9C99-1DB1CEA0CFE8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BeamNG.drive\BeamNG.drive.exe => No File
FirewallRules: [{8A9CC535-76B8-4F7D-B52F-1BEAE619EA5A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BeamNG.drive\BeamNG.drive.exe => No File
FirewallRules: [TCP Query User{82B7000F-3033-47C5-882F-4A4327EA179F}H:6\forzahorizon5.exe] => (Allow) H:6\forzahorizon5.exe => No File
FirewallRules: [UDP Query User{FEA88DEB-0549-4E28-A5FF-A508BE2D1B92}H:6\forzahorizon5.exe] => (Allow) H:6\forzahorizon5.exe => No File
FirewallRules: [TCP Query User{52A0173F-7B06-4E34-8B69-5EE7605107CE}H:5\forzahorizon5.exe] => (Allow) H:5\forzahorizon5.exe => No File
FirewallRules: [UDP Query User{08477B29-499C-42E1-A2F4-3EA9E8E8B822}H:5\forzahorizon5.exe] => (Allow) H:5\forzahorizon5.exe => No File
FirewallRules: [TCP Query User{FE74D2B9-39A6-40A2-9357-ADA4C1B8239F}D:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File
FirewallRules: [UDP Query User{A35C8D15-8B77-4166-8DAD-AEB01A200339}D:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe => No File
FirewallRules: [TCP Query User{99760B0B-5408-4207-87C8-8516D5EA5EDB}C:\program files\flashforge\flashprint 5\flashprint.exe] => (Allow) C:\program files\flashforge\flashprint 5\flashprint.exe => No File
FirewallRules: [UDP Query User{9A1B888E-CF95-4DA5-AD65-8CD9A51D8240}C:\program files\flashforge\flashprint 5\flashprint.exe] => (Allow) C:\program files\flashforge\flashprint 5\flashprint.exe => No File
FirewallRules: [TCP Query User{68847C3D-53DD-46EB-B404-E1EE5AF78497}C:\users\aweso\appdata\local\multiviewerforf1\app-1.9.8\multiviewer for f1.exe] => (Allow) C:\users\aweso\appdata\local\multiviewerforf1\app-1.9.8\multiviewer for f1.exe => No File
FirewallRules: [UDP Query User{D242778D-8FD3-4884-8809-C7520BE15F87}C:\users\aweso\appdata\local\multiviewerforf1\app-1.9.8\multiviewer for f1.exe] => (Allow) C:\users\aweso\appdata\local\multiviewerforf1\app-1.9.8\multiviewer for f1.exe => No File
FirewallRules: [TCP Query User{4577B090-072B-46DE-84DF-ADCEE0D59AE4}C:\users\aweso\appdata\local\multiviewerforf1\app-1.10.3\multiviewer for f1.exe] => (Allow) C:\users\aweso\appdata\local\multiviewerforf1\app-1.10.3\multiviewer for f1.exe => No File
FirewallRules: [UDP Query User{032C88D3-DE97-4421-A429-BA972E7DAAA5}C:\users\aweso\appdata\local\multiviewerforf1\app-1.10.3\multiviewer for f1.exe] => (Allow) C:\users\aweso\appdata\local\multiviewerforf1\app-1.10.3\multiviewer for f1.exe => No File
FirewallRules: [TCP Query User{57CFA746-D39A-4E51-A296-C7851D629C7F}H:9\forzahorizon5.exe] => (Allow) H:9\forzahorizon5.exe => No File
FirewallRules: [UDP Query User{FBF6A0DF-9838-4571-AE6D-97F5E8336C5F}H:9\forzahorizon5.exe] => (Allow) H:9\forzahorizon5.exe => No File
FirewallRules: [TCP Query User{8036A263-19B4-4589-93CD-07EB96BE0F1C}C:\users\aweso\appdata\local\multiviewerforf1\app-1.11.4\multiviewer for f1.exe] => (Allow) C:\users\aweso\appdata\local\multiviewerforf1\app-1.11.4\multiviewer for f1.exe => No File
FirewallRules: [UDP Query User{5D8FB0A8-E80F-4A84-975B-28193AC9EB52}C:\users\aweso\appdata\local\multiviewerforf1\app-1.11.4\multiviewer for f1.exe] => (Allow) C:\users\aweso\appdata\local\multiviewerforf1\app-1.11.4\multiviewer for f1.exe => No File
FirewallRules: [TCP Query User{C47E75A7-8655-4643-9D47-73709B48732A}D:\program files x86\steamlibrary\steamapps\common\vail\vail\binaries\win64\vail-win64-shipping.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\vail\vail\binaries\win64\vail-win64-shipping.exe => No File
FirewallRules: [UDP Query User{C535AA26-5268-4D6C-A299-AFC41632B349}D:\program files x86\steamlibrary\steamapps\common\vail\vail\binaries\win64\vail-win64-shipping.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\vail\vail\binaries\win64\vail-win64-shipping.exe => No File
FirewallRules: [TCP Query User{1C0FD1DB-4670-4A46-B9D0-419B6809357F}C:\program files\creality slicer 4.8.2\crealityslicer.exe] => (Allow) C:\program files\creality slicer 4.8.2\crealityslicer.exe => No File
FirewallRules: [UDP Query User{8F5C5F49-BED2-4CCB-B723-A9E6A6922C30}C:\program files\creality slicer 4.8.2\crealityslicer.exe] => (Allow) C:\program files\creality slicer 4.8.2\crealityslicer.exe => No File
FirewallRules: [TCP Query User{EB836F1A-5C4A-4474-8569-BCEFA066417B}F:\program files x86\steamlibrary\steamapps\common\tower unite\tower\binaries\win64\tower-win64-shipping.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\tower unite\tower\binaries\win64\tower-win64-shipping.exe => No File
FirewallRules: [UDP Query User{50E76EB5-FD2C-44D2-B3BA-336F0E781460}F:\program files x86\steamlibrary\steamapps\common\tower unite\tower\binaries\win64\tower-win64-shipping.exe] => (Allow) F:\program files x86\steamlibrary\steamapps\common\tower unite\tower\binaries\win64\tower-win64-shipping.exe => No File
FirewallRules: [TCP Query User{7662FED0-A734-4F12-AD5B-43EAD08692D9}H:7\forzahorizon5.exe] => (Allow) H:7\forzahorizon5.exe => No File
FirewallRules: [UDP Query User{CB48E091-E9DD-4546-9B20-CF4DA2DECA93}H:7\forzahorizon5.exe] => (Allow) H:7\forzahorizon5.exe => No File
FirewallRules: [{07D2B959-973B-47A3-899C-2DC9EB0D8919}] => (Allow) E:\program files\asus\aacambienthal\aacambientlighting.exe => No File
FirewallRules: [{CEBC28A3-FAA8-4FC8-BA45-01AB0BB6ACBA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Maestro\WindowsNoEditor\Maestro.exe => No File
FirewallRules: [{E09D0AA6-AD71-4014-986A-E48AA8DED14D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Maestro\WindowsNoEditor\Maestro.exe => No File
FirewallRules: [{A62FC742-CBD5-4624-8B76-48F81F36B1AC}] => (Allow) C:\Program Files\Oculus\Support\oculus-dash\dash\bin\OculusDash.exe => No File
FirewallRules: [{EEA199B5-9B42-48C3-BF19-CB968C072C5D}] => (Allow) C:\Program Files\Oculus\Support\oculus-dash\dash\bin\OculusDash.exe => No File
FirewallRules: [{E4108868-25BE-4413-958C-462F20CCFC87}] => (Allow) C:\Program Files\Oculus\Support\oculus-client\resources\bin\Casting\crashpad_mqdh_casting.exe => No File
FirewallRules: [{0C83C7CA-9F35-42E9-A15E-EBA14E1D7028}] => (Allow) C:\Program Files\Oculus\Support\oculus-client\resources\bin\Casting\crashpad_mqdh_casting.exe => No File
FirewallRules: [{4A9DBE82-B779-4B16-BE51-C8D2411D6A92}] => (Allow) C:\Program Files\Oculus\Support\oculus-client\OculusClient.exe => No File
FirewallRules: [{E9879507-EA2B-4522-BEA6-368B58635320}] => (Allow) C:\Program Files\Oculus\Support\oculus-client\OculusClient.exe => No File
FirewallRules: [{3A16E216-4080-4A81-9810-E154F65EFD80}] => (Allow) C:\Program Files\Oculus\Support\oculus-client\resources\bin\Casting\Casting.exe => No File
FirewallRules: [{519DFDD1-BE1F-4A65-AF95-34EE624598BE}] => (Allow) C:\Program Files\Oculus\Support\oculus-client\resources\bin\Casting\Casting.exe => No File
FirewallRules: [TCP Query User{E5E15705-C80B-4199-86AA-57348106345D}D:\program files x86\steamlibrary\steamapps\common\fcs\fcs\binaries\win64\fcs-win64-shipping.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\fcs\fcs\binaries\win64\fcs-win64-shipping.exe => No File
FirewallRules: [UDP Query User{93A01F5F-21AF-4486-9EA2-BCAC08F8CDD7}D:\program files x86\steamlibrary\steamapps\common\fcs\fcs\binaries\win64\fcs-win64-shipping.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\fcs\fcs\binaries\win64\fcs-win64-shipping.exe => No File
FirewallRules: [TCP Query User{D793FFFC-65D2-45CA-9CAD-FB80BE6DA6BC}D:\aweso\appdata\local\enlisted\launcher.exe] => (Allow) D:\aweso\appdata\local\enlisted\launcher.exe => No File
FirewallRules: [UDP Query User{FD1E1A9C-4274-4DB7-8665-92F7E058A3E0}D:\aweso\appdata\local\enlisted\launcher.exe] => (Allow) D:\aweso\appdata\local\enlisted\launcher.exe => No File
FirewallRules: [TCP Query User{1400217A-CC38-4D99-8BE1-234C212232FB}D:\aweso\appdata\local\enlisted\win64\enlisted.exe] => (Allow) D:\aweso\appdata\local\enlisted\win64\enlisted.exe => No File
FirewallRules: [UDP Query User{B2625575-EA84-4100-B071-1B69A5A9BA43}D:\aweso\appdata\local\enlisted\win64\enlisted.exe] => (Allow) D:\aweso\appdata\local\enlisted\win64\enlisted.exe => No File
FirewallRules: [TCP Query User{3E69E104-ED3B-496E-B436-BA86FEC2313F}C:\users\aweso\appdata\roaming\modrinthapp\meta\java_versions\zulu17.54.21-ca-jre17.0.13-win_x64\bin\javaw.exe] => (Allow) C:\users\aweso\appdata\roaming\modrinthapp\meta\java_versions\zulu17.54.21-ca-jre17.0.13-win_x64\bin\javaw.exe => No File
FirewallRules: [UDP Query User{E0DF9BE8-1F6B-4FEE-B8A0-BC7B7477E6C3}C:\users\aweso\appdata\roaming\modrinthapp\meta\java_versions\zulu17.54.21-ca-jre17.0.13-win_x64\bin\javaw.exe] => (Allow) C:\users\aweso\appdata\roaming\modrinthapp\meta\java_versions\zulu17.54.21-ca-jre17.0.13-win_x64\bin\javaw.exe => No File
FirewallRules: [TCP Query User{2B1E27D0-66AF-4A85-B464-DD008C2BBA15}D:\games\r.e.p.o\game\repo.exe] => (Block) D:\games\r.e.p.o\game\repo.exe => No File
FirewallRules: [UDP Query User{7707DBA9-CA32-4AD7-A0B1-DDA4B5E29B9F}D:\games\r.e.p.o\game\repo.exe] => (Block) D:\games\r.e.p.o\game\repo.exe => No File
FirewallRules: [{4108E41A-F76C-4436-80E2-F4BEE64813BE}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\Schedule I\Schedule I.exe => No File
FirewallRules: [{93FBA45E-D4DB-47DD-AEB7-56F7D9A18E72}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\Schedule I\Schedule I.exe => No File
FirewallRules: [TCP Query User{420E9DA1-C01C-413E-A672-D38290784F17}D:\games\wreckfest.2\wreckfest 2\wreckfest2.exe] => (Allow) D:\games\wreckfest.2\wreckfest 2\wreckfest2.exe => No File
FirewallRules: [UDP Query User{3C1DA444-A755-465C-8464-6AB54E7A60EE}D:\games\wreckfest.2\wreckfest 2\wreckfest2.exe] => (Allow) D:\games\wreckfest.2\wreckfest 2\wreckfest2.exe => No File
FirewallRules: [TCP Query User{A3CF1FE2-B6E3-40DC-B7EB-D067F5CE8AC4}D:\games\roadcraft.v1.5\roadcraft.v1.5\game\root\bin\pc\roadcraft - retail.exe] => (Allow) D:\games\roadcraft.v1.5\roadcraft.v1.5\game\root\bin\pc\roadcraft - retail.exe => No File
FirewallRules: [UDP Query User{A077CCEE-2953-4E64-8737-6615D7DC88B9}D:\games\roadcraft.v1.5\roadcraft.v1.5\game\root\bin\pc\roadcraft - retail.exe] => (Allow) D:\games\roadcraft.v1.5\roadcraft.v1.5\game\root\bin\pc\roadcraft - retail.exe => No File
FirewallRules: [TCP Query User{A2C936F4-9810-4A82-A6C0-EB243666AF63}E:\programfiler (x86)\steam\steamapps\common\tower unite\tower\binaries\win64\tower-win64-shipping.exe] => (Allow) E:\programfiler (x86)\steam\steamapps\common\tower unite\tower\binaries\win64\tower-win64-shipping.exe => No File
FirewallRules: [UDP Query User{831CAA75-471F-46E5-89B6-39D374503583}E:\programfiler (x86)\steam\steamapps\common\tower unite\tower\binaries\win64\tower-win64-shipping.exe] => (Allow) E:\programfiler (x86)\steam\steamapps\common\tower unite\tower\binaries\win64\tower-win64-shipping.exe => No File
FirewallRules: [TCP Query User{FBA011C0-FF5A-4973-A46A-5C8D1048E464}C:\users\aweso\appdata\roaming\.technic\runtimes\jre-legacy\bin\javaw.exe] => (Allow) C:\users\aweso\appdata\roaming\.technic\runtimes\jre-legacy\bin\javaw.exe => No File
FirewallRules: [UDP Query User{D1CC8B8D-6CCE-4AD7-8CBE-859BB3757E10}C:\users\aweso\appdata\roaming\.technic\runtimes\jre-legacy\bin\javaw.exe] => (Allow) C:\users\aweso\appdata\roaming\.technic\runtimes\jre-legacy\bin\javaw.exe => No File
FirewallRules: [TCP Query User{E3DB58B6-8C0B-465F-95A1-CB48A5C87486}C:\program files\eclipse adoptium\jdk-21.0.7.6-hotspot\bin\java.exe] => (Allow) C:\program files\eclipse adoptium\jdk-21.0.7.6-hotspot\bin\java.exe => No File
FirewallRules: [UDP Query User{2FB2124F-E4AF-4D12-8633-6FFCE040826F}C:\program files\eclipse adoptium\jdk-21.0.7.6-hotspot\bin\java.exe] => (Allow) C:\program files\eclipse adoptium\jdk-21.0.7.6-hotspot\bin\java.exe => No File
FirewallRules: [TCP Query User{856A9D0E-C470-4513-8793-570DB4BF4717}C:\users\aweso\downloads\mcdonalds newpos full suite\mcdonalds np6 2020 full suite\us-np6-full-suite\pedsim\pedsim.exe] => (Allow) C:\users\aweso\downloads\mcdonalds newpos full suite\mcdonalds np6 2020 full suite\us-np6-full-suite\pedsim\pedsim.exe => No File
FirewallRules: [UDP Query User{CBE020E0-9DB7-4247-B44A-09F245A76E6C}C:\users\aweso\downloads\mcdonalds newpos full suite\mcdonalds np6 2020 full suite\us-np6-full-suite\pedsim\pedsim.exe] => (Allow) C:\users\aweso\downloads\mcdonalds newpos full suite\mcdonalds np6 2020 full suite\us-np6-full-suite\pedsim\pedsim.exe => No File
FirewallRules: [{C7BA8B85-020A-476A-AE62-945299B09620}] => (Allow) E:\Programfiler (x86)\Steam\steamapps\common\VTOL VR\@Mod Loader\Mod Manager\Mod Manager.exe => No File
FirewallRules: [{0C6189AF-66FB-495E-9C30-D55C15E3E520}] => (Allow) E:\Programfiler (x86)\Steam\steamapps\common\VTOL VR\@Mod Loader\Mod Manager\Mod Manager.exe => No File
FirewallRules: [TCP Query User{F078AF75-426A-461D-B2C0-43D38FC3E5C2}E:\programfiler (x86)\steam\steamapps\common\vtol vr\@mod loader\steamqueries\steamqueries.exe] => (Allow) E:\programfiler (x86)\steam\steamapps\common\vtol vr\@mod loader\steamqueries\steamqueries.exe => No File
FirewallRules: [UDP Query User{4E948135-7CF8-4232-B4DF-8BC0F28EA492}E:\programfiler (x86)\steam\steamapps\common\vtol vr\@mod loader\steamqueries\steamqueries.exe] => (Allow) E:\programfiler (x86)\steam\steamapps\common\vtol vr\@mod loader\steamqueries\steamqueries.exe => No File
FirewallRules: [TCP Query User{784BD2B8-4C6F-45B9-A81D-21C4AF2535C1}C:\users\aweso\appdata\local\temp\e5872e15-7319-4bc0-b208-f0210be61c22_xteve_windows_amd64.zip.c22\xteve.exe] => (Allow) C:\users\aweso\appdata\local\temp\e5872e15-7319-4bc0-b208-f0210be61c22_xteve_windows_amd64.zip.c22\xteve.exe => No File
FirewallRules: [UDP Query User{3CB5894F-F4B0-410E-94C6-2B305C2F5250}C:\users\aweso\appdata\local\temp\e5872e15-7319-4bc0-b208-f0210be61c22_xteve_windows_amd64.zip.c22\xteve.exe] => (Allow) C:\users\aweso\appdata\local\temp\e5872e15-7319-4bc0-b208-f0210be61c22_xteve_windows_amd64.zip.c22\xteve.exe => No File
FirewallRules: [TCP Query User{86D3DBCD-D6E2-4047-9D61-7FEE21BAB0AC}D:\program files x86\steamlibrary\steamapps\common\skate\skate.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\skate\skate.exe => No File
FirewallRules: [UDP Query User{3C913248-6188-4342-8C0D-4814A87A4E50}D:\program files x86\steamlibrary\steamapps\common\skate\skate.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\skate\skate.exe => No File
FirewallRules: [{194039F1-8DE9-49F6-A048-AB78AF0EE1B0}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\Assetto Corsa Rally\acr\Binaries\Win64\acr.exe => No File
FirewallRules: [{FA423683-5373-4FC0-8CBD-4DD3F16C65AD}] => (Allow) D:\Program Files x86\SteamLibrary\Steamapps\common\Assetto Corsa Rally\acr\Binaries\Win64\acr.exe => No File
FirewallRules: [TCP Query User{3C163D50-B4E3-4DFE-A120-909B24AEB2ED}D:\program files x86\epic games\justdiealready\jdgame\binaries\win64\jdgame-win64-shipping.exe] => (Allow) D:\program files x86\epic games\justdiealready\jdgame\binaries\win64\jdgame-win64-shipping.exe => No File
FirewallRules: [UDP Query User{0069E7EE-F33A-47FC-9DAB-673440D5BB4C}D:\program files x86\epic games\justdiealready\jdgame\binaries\win64\jdgame-win64-shipping.exe] => (Allow) D:\program files x86\epic games\justdiealready\jdgame\binaries\win64\jdgame-win64-shipping.exe => No File
FirewallRules: [TCP Query User{7C1F4DD6-357C-40FA-BC00-6C221FD4694A}D:\program files x86\steamlibrary\steamapps\common\screw drivers\dedicated server\screw drivers server.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\screw drivers\dedicated server\screw drivers server.exe => No File
FirewallRules: [UDP Query User{999412A6-430C-4126-A53B-1FA332A0A59B}D:\program files x86\steamlibrary\steamapps\common\screw drivers\dedicated server\screw drivers server.exe] => (Allow) D:\program files x86\steamlibrary\steamapps\common\screw drivers\dedicated server\screw drivers server.exe => No File
FirewallRules: [TCP Query User{72D80020-11D9-49CC-8D80-2C7A86A64B9A}C:\programdata\ableton\live 12 trial\program\ableton live 12 trial.exe] => (Allow) C:\programdata\ableton\live 12 trial\program\ableton live 12 trial.exe => No File
FirewallRules: [UDP Query User{93ACA61D-B183-48D9-8ABA-62760EC5C3F2}C:\programdata\ableton\live 12 trial\program\ableton live 12 trial.exe] => (Allow) C:\programdata\ableton\live 12 trial\program\ableton live 12 trial.exe => No File
FirewallRules: [TCP Query User{E80DF076-2F82-411C-9976-A04B5816CF7C}D:\program files x86\steamlibrary\steamapps\common\meccha chameleon\chameleon\binaries\win64\penguinhotel-win64-shipping.exe] => (Block) D:\program files x86\steamlibrary\steamapps\common\meccha chameleon\chameleon\binaries\win64\penguinhotel-win64-shipping.exe => No File
FirewallRules: [UDP Query User{D9987D4D-7B83-468F-B7BB-AD1DC5705FCE}D:\program files x86\steamlibrary\steamapps\common\meccha chameleon\chameleon\binaries\win64\penguinhotel-win64-shipping.exe] => (Block) D:\program files x86\steamlibrary\steamapps\common\meccha chameleon\chameleon\binaries\win64\penguinhotel-win64-shipping.exe => No File
FirewallRules: [{35E039F5-A89F-405B-B9BB-BAD86DDD4738}] => (Allow) C:\Program Files (x86)\Overwolf\0.305.0.9\OverwolfBrowser.exe => No File
FirewallRules: [{9EAA1C6A-0EDA-4D33-927F-26949391B8EF}] => (Allow) C:\Program Files (x86)\Overwolf\0.305.0.9\OverwolfBrowser.exe => No File
FirewallRules: [{8C505046-F40A-4282-9B27-D5B19C271073}] => (Block) C:\Program Files (x86)\Overwolf\0.305.0.9\OverwolfBrowser.exe => No File
FirewallRules: [{7B11D8EF-03F8-4B79-B55D-41A89A883F97}] => (Block) C:\Program Files (x86)\Overwolf\0.305.0.9\OverwolfBrowser.exe => No File
HKLM\...\Run: [RtkAudUService] => "C:\WINDOWS\System32\RtkAudUService64.exe" -background (No File)
HKU\S-1-5-21-918861487-1455304378-3185533227-1001\...\Run: [NZXT.CAM] => C:\Program Files\NZXT CAM\NZXT CAM.exe --startup (No File)
HKU\S-1-5-21-918861487-1455304378-3185533227-1001\...\Run: [Navigraph Simlink] => D:\Program Files\Simlink\NavigraphSimlink.exe (No File)
HKU\S-1-5-21-918861487-1455304378-3185533227-1001\...\Run: [electron.app.Pi Network] => C:\Users\Aweso\AppData\Local\Programs\pi-network-desktop\Pi Network.exe (No File)
Task: {5ABBCE05-F0BA-49FB-811B-467CE15E7B85} - \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskWindowsLogins -> No File <==== ATTENTION
Task: {71AA8F6F-5AE3-4A86-919E-DB99F2930ACF} - \Microsoft\Windows\EDP\ScheduledDef -> No File <==== ATTENTION
Task: {7A5E84C0-D7BD-4421-AF30-2E3BA574B462} - \Microsoft\Windows\RegisterDeviceAccountChange\ProgramDataUpdate -> No File <==== ATTENTION
Task: {D698C1E3-2E79-4009-AEC1-FDD3A61180DF} - \Microsoft\Location\MicrosoftUpdaterMachineCore -> No File <==== ATTENTION
Task: {E6075C4D-4DFE-432A-8293-0B5C5E237124} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (No File)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
Task: {143E9296-1C61-4857-BE92-5CDC67D5C3B1} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (No File)
Task: {F8873CB8-8FD5-480D-AD85-ABF1A10DBD45} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {E3CC101D-B32F-4A44-9798-0913D6305050} - System32\Tasks\WindhawkRunUITask => C:\Program Files\Windhawk\windhawk.exe -run-ui-as-admin (No File)
Task: {BE8638B9-83EC-4A73-96F0-A04221727ABF} - System32\Tasks\WindhawkUpdateTask => C:\Program Files\Windhawk\windhawk.exe -check-for-updates (No File)
S3 Denuvo Anti-Cheat Update Service; "C:\Program Files\Denuvo Anti-Cheat\denuvo-anti-cheat-update-service.exe" (No File)
S3 Futuremark SystemInfo Service; "C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe" (No File)
S3 iPod Service; "C:\Program Files\iPod\bin\iPodService.exe" (No File)
S3 OVRLibraryService; "C:\Program Files\Oculus\Support\oculus-librarian\OVRLibraryService.exe" (No File)
S2 Windhawk; "C:\Program Files\Windhawk\windhawk.exe" -service (No File)
S3 Denuvo Anti-Cheat; \??\C:\Program Files\Denuvo Anti-Cheat\denuvo-anti-cheat.sys (No File)
S3 EAAntiCheat; system32\drivers\eaanticheat.sys (No File)
S4 NvModuleTracker; \SystemRoot\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys (No File)
S3 R0SteelSeriesSystemMonitor; \??\C:\Program Files\SteelSeries\GG\apps\engine\engineApps\system-stats\SteelSeriesSystemMonitor.sys (No File)
Folder: C:\ProgramData\Windows
Folder: C:\Users\Aweso\AppData\Local\Wand
Comment: This snippet reverts SmartScreen settings to default
StartRegedit:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer]
"SmartScreenEnabled"="Warn"
[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter]
"EnabledV9"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AppHost]
"EnableWebContentEvaluation"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\AppHost]
"EnableWebContentEvaluation"=dword:00000001
EndRegedit:
Comment: Service / Driver Status (thanks to AdvancedSetup)
Comment: 0 = Boot
Comment: 1 = System
Comment: 2 = Automatic
Comment: 3 = Manual / Demand
Comment: 4 = Disabled
Comment: R = Running
Comment: S = Stopped
Comment: U = Unknown / unable to determine service state cleanly
Comment: === rifteyy's default non-intrusive fixlist template ===
Comment: The following are done automatically with this fixlist:
Comment: Hardens Windows Defender (for maximum efficiency DISABLE TAMPER PROTECTION)
Comment: Checks and corrects the default Windows PATH environmental variable
Comment: Checks for internet connection, valid DNS
Comment: Checks for Windows RE status
Comment: Checks and repairs WMI repository
Comment: Checks Windows activation status
Comment: Checks if TPM, Secure Boot are available and their status
Comment: Restores original Windows services configuration
Comment: Restores PowerShell execution policy
Comment: Rebuilds performance counter library values
Comment: Resynchronizes performance counter library values to WMI
Comment: Enables file extensions
Comment: Enables recovery environment
Comment: Scans with HitmanPro from Sophos
Comment: Scans and cleans with AdwCleaner from Malwarebytes
Comment: Lists Windows Defender properties, settings
Comment: Lists drive info, identify possible damaged drives from Event Logs
Comment: Lists Discord's "index.js" files that are often targeted by malware (to store and execute malicious code)
Comment: Lists recent BSOD's
Comment: Lists all installed applications, folder contents along with SHA256 for purposes of identifying installed app malware
Comment: Lists 30 recent scheduled tasks
Comment: Lists recent Run (Windows + R) executed commands, can identify ClickFix attacks
Comment: Removes unwanted files (e.g. .exe, .com, .dll) from common folders (e.g. C:\ProgramData, AppData\Roaming) - these are not supposed to store any executable file types
Comment: Removes generic filetypes associated with RenPyLoader from common folders
Comment: Removes cache from Chrome, Firefox, Opera, Opera GX, Brave, Vivaldi, LibreWolf, Mullvad Browser, Zen and from Roblox, Fortnite, Discord, OBS Studio
Comment: Removes policies
Comment: Removes active BITS tasks
Comment: Resets network
Comment: Removes proxy servers
Comment: Removes temporary files
Comment: Repairs system files
StartPowerShell:
# Checks default Windows PATH entries and repairs missing ones.
$ErrorActionPreference = 'Continue'
function Expand-PlainPath {
param([string]$Entry)
return [Environment]::ExpandEnvironmentVariables($Entry).TrimEnd('\')
}
# Templates expanded once to plain paths (C:\Windows\..., C:\Users\...)
$systemDefaults = @(
(Expand-PlainPath '%SystemRoot%\system32')
(Expand-PlainPath '%SystemRoot%')
(Expand-PlainPath '%SystemRoot%\System32\Wbem')
(Expand-PlainPath '%SystemRoot%\System32\WindowsPowerShell\v1.0')
(Expand-PlainPath '%SystemRoot%\System32\OpenSSH')
)
$userDefaults = @(
(Expand-PlainPath '%USERPROFILE%\AppData\Local\Microsoft\WindowsApps')
)
function Get-NormalizedPathEntries {
param([string]$Raw)
if ([string]::IsNullOrWhiteSpace($Raw)) { return @() }
return @(
$Raw -split ';' |
Where-Object { -not [string]::IsNullOrWhiteSpace($_) } |
ForEach-Object {
[Environment]::ExpandEnvironmentVariables($_.Trim().TrimEnd('\')).ToLowerInvariant()
}
)
}
function Get-CombinedPathEntries {
$machineRaw = [Environment]::GetEnvironmentVariable('Path', 'Machine')
$userRaw = [Environment]::GetEnvironmentVariable('Path', 'User')
return Get-NormalizedPathEntries -Raw ($machineRaw + ';' + $userRaw)
}
function Test-InPath {
param(
[string]$PlainPath,
[string[]]$NormalizedEntries
)
$key = $PlainPath.TrimEnd('\').ToLowerInvariant()
return $NormalizedEntries -contains $key
}
function Add-ToPath {
param(
[string]$PlainPath,
[ValidateSet('Machine', 'User')]
[string]$Scope
)
# always store plain path, never %VAR% form
$toAdd = $PlainPath.TrimEnd('\')
$current = [Environment]::GetEnvironmentVariable('Path', $Scope)
if ([string]::IsNullOrWhiteSpace($current)) {
[Environment]::SetEnvironmentVariable('Path', $toAdd, $Scope)
return
}
$normalized = Get-NormalizedPathEntries -Raw $current
$key = $toAdd.ToLowerInvariant()
if ($normalized -contains $key) { return }
$newPath = $current.TrimEnd(';') + ';' + $toAdd
[Environment]::SetEnvironmentVariable('Path', $newPath, $Scope)
}
function Write-Result {
param(
[string]$Entry,
[string]$Status
)
$label = $Entry.PadRight(58)
Write-Output ("{0} {1}" -f $label, $Status)
}
function Repair-AndVerify {
param(
[string]$PlainPath,
[ValidateSet('Machine', 'User')]
[string]$Scope
)
if (-not (Test-Path -LiteralPath $PlainPath)) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (no folder, cannot repair)'
return 'failed'
}
if ($Scope -eq 'Machine') {
$isAdmin = ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).
IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)
if (-not $isAdmin) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (need Admin to repair)'
return 'failed'
}
}
try {
Add-ToPath -PlainPath $PlainPath -Scope $Scope
}
catch {
Write-Result -Entry $PlainPath -Status "ATTENTION !!! MISSING (repair failed: $_)"
return 'failed'
}
# re-query PATH from registry and verify plain path is present
$after = Get-CombinedPathEntries
if (Test-InPath -PlainPath $PlainPath -NormalizedEntries $after) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING -> repaired (verified)'
return 'repaired'
}
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (repair ran, still missing after re-check)'
return 'failed'
}
$combined = Get-CombinedPathEntries
$hadMissing = $false
$repairFailed = $false
$repairedList = [System.Collections.Generic.List[string]]::new()
Write-Output 'PATH CHECK'
Write-Output ('-' * 72)
foreach ($entry in $systemDefaults) {
if (Test-InPath -PlainPath $entry -NormalizedEntries $combined) {
Write-Result -Entry $entry -Status 'OK'
continue
}
$hadMissing = $true
$result = Repair-AndVerify -PlainPath $entry -Scope Machine
if ($result -eq 'repaired') {
[void]$repairedList.Add($entry)
$combined = Get-CombinedPathEntries
}
else {
$repairFailed = $true
}
}
foreach ($entry in $userDefaults) {
if (Test-InPath -PlainPath $entry -NormalizedEntries $combined) {
Write-Result -Entry $entry -Status 'OK'
continue
}
$hadMissing = $true
$result = Repair-AndVerify -PlainPath $entry -Scope User
if ($result -eq 'repaired') {
[void]$repairedList.Add($entry)
$combined = Get-CombinedPathEntries
}
else {
$repairFailed = $true
}
}
Write-Output ('-' * 72)
if (-not $hadMissing) {
Write-Output 'RESULT: all default PATH entries present'
}
elseif ($repairedList.Count -gt 0 -and -not $repairFailed) {
Write-Output "RESULT: $($repairedList.Count) missing entry/entries repaired and verified - open a new terminal"
}
elseif ($repairedList.Count -gt 0 -and $repairFailed) {
Write-Output "RESULT: $($repairedList.Count) verified, some still missing - open a new terminal / run as Admin"
}
else {
Write-Output 'RESULT: missing entries not repaired (run as Admin for System PATH)'
}
if ($repairedList.Count -gt 0) {
Write-Output ''
Write-Output 'REPAIRED:'
foreach ($item in $repairedList) {
Write-Output " $item"
}
}
if ($hadMissing -or $repairFailed) {
exit 1
}
exit 0
EndPowerShell:
Comment: Verify Windows activation
CMD: cscript c:\windows\system32\slmgr.vbs /xpr & cscript c:\windows\system32\slmgr.vbs /dlv
Comment: Check TPM and Secure Boot status
StartPowershell:
[PSCustomObject]@{ "TPM Detected" = (Get-Tpm).TpmPresent; "TPM Enabled" = (Get-Tpm).TpmEnabled; "Secure Boot On" = (Confirm-SecureBootUEFI) }
EndPowershell:
StartPowerShell:
# Check for internet connection
$ErrorActionPreference = 'Continue'
$dnsServers = @(
'1.1.1.1'
'8.8.8.8'
)
$hosts = @(
'google.com'
'cloudflare.com'
'malwarebytes.com'
)
function Write-Result {
param(
[string]$Label,
[string]$Status
)
Write-Output ("{0} {1}" -f $Label.PadRight(42), $Status)
}
function Test-DnsServer {
param([string]$Server)
$pingOk = $false
try {
$pingOk = Test-Connection -ComputerName $Server -Count 1 -Quiet -ErrorAction SilentlyContinue
}
catch { }
$resolveOk = $false
try {
$result = Resolve-DnsName -Name 'google.com' -Server $Server -Type A -DnsOnly -ErrorAction Stop
$ip = ($result | Where-Object { $_.IPAddress } | Select-Object -First 1).IPAddress
if ($ip) { $resolveOk = $true }
}
catch { }
# resolve is what matters; ping may be blocked
if ($resolveOk) { return 'OK' }
if ($pingOk) { return 'FAIL' }
return 'FAIL'
}
function Test-HostReachable {
param([string]$HostName)
try {
$dns = Resolve-DnsName -Name $HostName -Type A -ErrorAction Stop
$resolvedIp = ($dns | Where-Object { $_.IPAddress } | Select-Object -First 1).IPAddress
if (-not $resolvedIp) { return 'FAIL' }
}
catch {
return 'FAIL'
}
try {
$null = Invoke-WebRequest -Uri "https://$HostName" -UseBasicParsing -TimeoutSec 10 -MaximumRedirection 5 -ErrorAction Stop
return 'OK'
}
catch {
if ($_.Exception.Response) { return 'OK' }
return 'FAIL'
}
}
$failed = 0
Write-Output 'INTERNET CHECK'
Write-Output ('-' * 72)
Write-Output 'DNS SERVERS'
foreach ($server in $dnsServers) {
$status = Test-DnsServer -Server $server
Write-Result -Label $server -Status $status
if ($status -eq 'FAIL') { $failed++ }
}
Write-Output ''
Write-Output 'HOSTS'
foreach ($h in $hosts) {
$status = Test-HostReachable -HostName $h
Write-Result -Label $h -Status $status
if ($status -eq 'FAIL') { $failed++ }
}
Write-Output ('-' * 72)
if ($failed -eq 0) {
Write-Output 'RESULT: all checks passed'
exit 0
}
Write-Output "RESULT: $failed check(s) failed"
exit 1
EndPowerShell:
StartPowershell:
# Replace /scanonly with /clean if you also want to delete items -- however, this will activate a trial license on the system, I do not recommend it
$hmpExe = "$env:TEMP\HitmanPro_x64.exe"
$logFile = "$env:TEMP\HitmanPro_ScanLog.txt"
Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing
$proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru
if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 }
Get-Content $logFile -Encoding Unicode
EndPowershell:
StartPowerShell:
# Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console
# Does not clean preinstalled objects, only PUP/Adware
# If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument
# If you would like to only scan with it, change the argument from /clean to /scan
# NOTE: For the sake of users from Asia (primarily China), do not use the clean option. It will very likely remove a lot of their important software.
New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null
Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden
$logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile
Get-Content $logFile -Encoding Unicode
Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue
EndPowerShell:
Comment: List drive info, identify possible damaged drives (thanks to AdvancedSetup from Malwarebytes for parts of these)
StartPowerShell:
param(
[int]$MaxEvents = 5000
)
$GPTTypeMap = @{
'EBD0A0A2-B9E5-4433-87C0-68B6B72699C7' = 'Microsoft Basic Data'
'E3C9E316-0B5C-4DB8-817D-F92DF00215AE' = 'Microsoft Reserved (MSR)'
'DE94BBA4-06D1-4D40-A16A-BFD50179D6AC' = 'Windows Recovery Environment (WinRE)'
'C12A7328-F81F-11D2-BA4B-00A0C93EC93B' = 'EFI System Partition'
'21686148-6449-6E6F-744E-656564454649' = 'BIOS Boot Partition'
'A19D880F-05FC-4D3B-A006-743F0F84911E' = 'OEM Partition'
'5808C8AA-7E8F-42E0-85D2-E1E90434CFB3' = 'Cluster Metadata Partition'
'48465300-0000-11AA-AA11-00306543ECAC' = 'Apple HFS/HFS+'
'7C3457EF-0000-11AA-AA11-00306543ECAC' = 'Apple APFS'
'0FC63DAF-8483-4772-8E79-3D69D8477DE4' = 'Linux Filesystem'
'0657FD6D-A4AB-43C4-84E5-0933C84B4F4F' = 'Linux Swap'
'E6D6D379-F507-44C2-A23C-238F2A3DF928' = 'Linux LVM'
}
$MBRTypeMap = @{
'01'='FAT12';'04'='FAT16 <32M';'05'='Extended';'06'='FAT16';'07'='IFS/NTFS/exFAT/HPFS';'0B'='FAT32 CHS';'0C'='FAT32 LBA';'0E'='FAT16 LBA'
'0F'='Extended LBA';'82'='Linux Swap';'83'='Linux Native';'8E'='Linux LVM';'A5'='FreeBSD';'A6'='OpenBSD';'A8'='Mac OS X';'AB'='Mac OS X Boot'
'AF'='Mac OS X HFS';'EE'='EFI GPT Protective';'EF'='EFI System Partition'
}
function Get-PartitionTypeInfo {
param($Partition)
$guid = $null
if ($Partition.GptType) {
$guid = ($Partition.GptType -replace '[{}]', '').ToUpper()
}
if ([string]::IsNullOrWhiteSpace($guid) -or $guid -eq '00000000-0000-0000-0000-000000000000') {
$guid = switch ($Partition.Type) {
"System" { "C12A7328-F81F-11D2-BA4B-00A0C93EC93B" }
"Reserved" { "E3C9E316-0B5C-4DB8-817D-F92DF00215AE" }
"Basic" { "EBD0A0A2-B9E5-4433-87C0-68B6B72699C7" }
"Recovery" { "DE94BBA4-06D1-4D40-A16A-BFD50179D6AC" }
default { $null }
}
}
if ($guid) {
$name = $GPTTypeMap[$guid]
if ($name) { return "$name (GPT GUID: $($guid.ToLower()))" }
else { return "Unknown/Custom (GPT GUID: $($guid.ToLower()))" }
}
if ($Partition.MbrType) {
$code = ($Partition.MbrType.ToString() -replace '^0x', '').PadLeft(2, '0').ToUpper()
$name = $MBRTypeMap[$code]
if ($name) { return "$name (MBR code: 0x$code)" }
else { return "Unknown/Custom (MBR code: $($Partition.MbrType))" }
}
return $Partition.Type
}
function Get-DrMapping {
param([int]$MaxEvents)
$map = @{}
try {
$events = Get-WinEvent -FilterHashtable @{ LogName = 'System'; ProviderName = 'disk' } -MaxEvents $MaxEvents -ErrorAction Stop
} catch {
return $map
}
foreach ($e in $events) {
if ($e.Message -match 'Harddisk(\d+)\\DR(\d+)') {
$n = [int]$Matches[1]
$dr = [int]$Matches[2]
if (-not $map.ContainsKey($n)) { $map[$n] = $dr }
}
}
return $map
}
$drMap = Get-DrMapping -MaxEvents $MaxEvents
$physicalDisks = Get-PhysicalDisk | Select-Object DeviceId, FriendlyName, SerialNumber, MediaType, @{N='SizeGB';E={[math]::Round($_.Size / 1GB,2)}}
foreach ($pd in $physicalDisks) {
$devId = [int]$pd.DeviceId
$drSuffix = if ($drMap.ContainsKey($devId)) { "\DR$($drMap[$devId])" } else { '\DR? (no event seen yet)' }
Write-Host ""
Write-Host "<=== \Device\Harddisk$devId$drSuffix ($($pd.FriendlyName)) ===>"
Write-Host " DeviceId: $devId | Serial: $($pd.SerialNumber) | Media: $($pd.MediaType) | Size: $($pd.SizeGB) GB"
try {
$partitions = Get-Partition -DiskNumber $devId -ErrorAction Stop
if (-not $partitions) {
Write-Host " (no partitions found)"
continue
}
foreach ($part in $partitions) {
$driveLetter = if ($part.DriveLetter) { "$($part.DriveLetter):" } else { 'no letter' }
$sizeGB = [math]::Round($part.Size / 1GB, 2)
$typeInfo = Get-PartitionTypeInfo -Partition $part
Write-Host " [PARTITION $($part.PartitionNumber)] Drive: $driveLetter - $sizeGB GB - $typeInfo"
}
} catch {
Write-Host " [ERROR] cannot read partitions for disk $devId"
}
}
if ($drMap.Count -eq 0) {
Write-Host ""
Write-Host "Note: no \Device\HarddiskN\DRx entries found in the last $MaxEvents System log events. Increase -MaxEvents, or the DR number will only appear once Windows actually logs a disk event for that drive (e.g. a bad block warning)."
}
EndPowerShell:
Comment: Verify that Discord does not have any injected code to intercept personal data. If anything is prompted here, it needs to be checked that it isn't malicious code.
Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) }
StartPowerShell:
# Basic BSOD listings
$ccKey = "HKLM:\SYSTEM\CurrentControlSet\Control\CrashControl"
$cfg = Get-ItemProperty $ccKey -ErrorAction SilentlyContinue
$dumpTypeMap = @{0='None';1='Complete';2='Kernel';3='Minidump';7='Automatic'}
Write-Output "--- Configuration ---"
Write-Output ("Dump Type: {0} ({1})" -f $cfg.CrashDumpEnabled, $dumpTypeMap[$cfg.CrashDumpEnabled])
Write-Output ("Full Dump Path: {0}" -f $(if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}))
Write-Output ("Minidump Folder: {0}" -f $(if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}))
Write-Output ("Auto Reboot: {0}" -f $(if($cfg.AutoReboot -eq 0){'Disabled'}else{'Enabled'}))
Write-Output "--- Found Dump Files ---"
$full = if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}
if (Test-Path $full) { Get-Item $full | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
$mini = if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}
if (Test-Path $mini) { Get-ChildItem $mini -Filter *.dmp | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
Write-Output "--- BugCheck Reasoning (recent events) ---"
$map = @{
'0x0000000A'='IRQL_NOT_LESS_OR_EQUAL - faulty/outdated driver accessed memory at high IRQL'
'0x0000001E'='KMODE_EXCEPTION_NOT_HANDLED - unhandled kernel exception, often driver/hardware'
'0x0000002E'='DATA_BUS_ERROR - typically bad RAM or hardware fault'
'0x0000003B'='SYSTEM_SERVICE_EXCEPTION - exception in a system service, often driver-related'
'0x00000050'='PAGE_FAULT_IN_NONPAGED_AREA - bad RAM or faulty driver/antivirus'
'0x0000007A'='KERNEL_DATA_INPAGE_ERROR - disk-related problem'
'0x0000007B'='INACCESSIBLE_BOOT_DEVICE - system could not find/access the boot device'
'0x0000007E'='SYSTEM_THREAD_EXCEPTION_NOT_HANDLED - almost always a faulty driver'
'0x0000007F'='UNEXPECTED_KERNEL_MODE_TRAP - hardware issue (CPU/RAM/overclocking)'
'0x0000009F'='DRIVER_POWER_STATE_FAILURE - driver failed to respond to a power state change'
'0x000000C2'='BAD_POOL_CALLER - driver mishandling memory (pool corruption)'
'0x000000D1'='DRIVER_IRQL_NOT_LESS_OR_EQUAL - typically a network or GPU driver'
'0x000000EF'='CRITICAL_PROCESS_DIED - a critical system process died, often malware/system corruption'
'0x00000116'='VIDEO_TDR_FAILURE - GPU driver failed to respond in time (timeout)'
'0x00000124'='WHEA_UNCORRECTABLE_ERROR - hardware fault (CPU/RAM/PSU/overclocking)'
'0x00000133'='DPC_WATCHDOG_VIOLATION - faulty driver or storage subsystem issue'
'0x00000139'='KERNEL_SECURITY_CHECK_FAILURE - corrupted kernel structure, possibly malware'
}
$events = Get-WinEvent -FilterHashtable @{LogName='System';Id=1001} -MaxEvents 100 -ErrorAction SilentlyContinue |
Where-Object { $_.ProviderName -match 'WER-SystemErrorReporting' } | Select-Object -First 5
if (-not $events) { Write-Output "No BugCheck events found in the log." }
foreach ($ev in $events) {
$code = if ($ev.Message -match 'bugcheck was:\s*(0x[0-9A-Fa-f]+)') { $matches[1] } else { $null }
Write-Output ("Time: {0}" -f $ev.TimeCreated)
Write-Output ("Code: {0}" -f $(if($code){$code}else{'not recognized'}))
if ($code -and $map.ContainsKey($code.ToUpper())) {
Write-Output ("Meaning: {0}" -f $map[$code.ToUpper()])
} elseif ($code) {
Write-Output "Meaning: unknown code, look up at learn.microsoft.com/windows-hardware/drivers/debugger/bug-check-code-reference2"
}
Write-Output ""
}
EndPowerShell:
StartPowerShell:
# This snippet lists all installed apps and their folder contents along with SHA256 hashes. Useful for troubleshooting malware abusing installed app entry.
param(
[switch]$Recurse,
[int]$MaxFilesPerApp = [int]::MaxValue
)
$uninstallPaths = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
$script:msiInstaller = $null
function Get-MsiInstallLocation {
param([string]$ProductCode)
if (-not $script:msiInstaller) {
try { $script:msiInstaller = New-Object -ComObject WindowsInstaller.Installer } catch { return $null }
}
try {
$loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallLocation')
if ([string]::IsNullOrWhiteSpace($loc)) { $loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallSource') }
if ([string]::IsNullOrWhiteSpace($loc)) { return $null }
return $loc
} catch { return $null }
}
function Get-CleanPath {
param([string]$RawValue)
if ([string]::IsNullOrWhiteSpace($RawValue)) { return $null }
$s = $RawValue.Trim()
if ($s.StartsWith('"')) {
$endQuote = $s.IndexOf('"', 1)
if ($endQuote -gt 0) { return $s.Substring(1, $endQuote - 1) }
}
if ($s -match '^(.*?\.exe)\b') { return $Matches[1] }
return $s
}
function Format-FileSize {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$script:PeExtensions = @('.exe', '.dll', '.sys', '.ocx', '.cpl', '.scr', '.drv', '.efi', '.msi', '.msp', '.msu')
function Test-IsPeFile {
param([string]$Extension)
return $script:PeExtensions -contains $Extension.ToLower()
}
function Get-SignatureInfo {
param([string]$Path, [string]$Extension)
if (-not (Test-IsPeFile -Extension $Extension)) {
return [PSCustomObject]@{ Signer = 'N/A (not PE)'; Status = 'NotApplicable'; Valid = $false }
}
$result = [PSCustomObject]@{ Signer = 'Unsigned'; Status = 'NotSigned'; Valid = $false }
try {
$sig = Get-AuthenticodeSignature -LiteralPath $Path -ErrorAction Stop
$result.Status = $sig.Status.ToString()
$result.Valid = ($sig.Status -eq 'Valid')
if ($sig.SignerCertificate) {
if ($sig.SignerCertificate.Subject -match 'CN=([^,]+)') { $result.Signer = $Matches[1].Trim('"') }
else { $result.Signer = $sig.SignerCertificate.Subject }
if (-not $result.Valid) { $result.Signer += " [INVALID: $($result.Status)]" }
} elseif ($sig.Status -eq 'NotSigned') {
$result.Signer = 'Unsigned'
} else {
$result.Signer = "Unknown [$($result.Status)]"
}
} catch {
$result.Signer = 'Verification error'
$result.Status = 'Error'
$result.Valid = $false
}
return $result
}
$rawApps = Get-ItemProperty -Path $uninstallPaths -ErrorAction SilentlyContinue |
Where-Object { $_.DisplayName -and $_.DisplayName.Trim() -ne '' } |
Select-Object @{Name = 'Name'; Expression = { $_.DisplayName } },
@{Name = 'Version'; Expression = { $_.DisplayVersion } },
@{Name = 'Publisher'; Expression = { $_.Publisher } },
@{Name = 'InstallFolder'; Expression = {
if ($_.InstallLocation -and $_.InstallLocation.Trim() -ne '') { $_.InstallLocation }
elseif ($_.UninstallString -match 'MsiExec\.exe.*?(\{[0-9A-Fa-f\-]{36}\})') {
$productCode = $Matches[1]
$msiLoc = Get-MsiInstallLocation -ProductCode $productCode
if ($msiLoc) { $msiLoc } else { "MSI: $productCode (location not found)" }
}
elseif ($_.UninstallString) { $_.UninstallString }
else { 'N/A' }
} } |
Sort-Object Name -Unique
foreach ($app in $rawApps) {
$versionText = if ($app.Version) { $app.Version } else { '?' }
$publisherText = if ($app.Publisher) { $app.Publisher } else { '?' }
Write-Host ""
Write-Host "<=== $($app.Name) [$versionText] ($publisherText) ===>"
if ($app.InstallFolder -eq 'N/A' -or $app.InstallFolder -match '^MSI: .* \(location not found\)$') {
Write-Host " Path: $($app.InstallFolder)"
continue
}
$cleanPath = Get-CleanPath -RawValue $app.InstallFolder
$exists = $false
try {
$exists = Test-Path -LiteralPath $cleanPath -ErrorAction Stop
} catch [System.UnauthorizedAccessException] {
Write-Host " Path: $cleanPath"
Write-Host " [ACCESS DENIED]"
continue
} catch {
Write-Host " Path: $cleanPath"
Write-Host " [ERROR] cannot access"
continue
}
if (-not $exists) {
Write-Host " Path: $cleanPath"
Write-Host " [NOT FOUND]"
continue
}
$rootItem = Get-Item -LiteralPath $cleanPath -Force
$created = $rootItem.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$modified = $rootItem.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
if ($rootItem.PSIsContainer) {
$subFolders = Get-ChildItem -LiteralPath $cleanPath -Directory -Force -ErrorAction SilentlyContinue
$gciParams = @{ LiteralPath = $cleanPath; File = $true; Force = $true; ErrorAction = 'SilentlyContinue' }
if ($Recurse) { $gciParams['Recurse'] = $true }
$allFiles = Get-ChildItem @gciParams
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: $($allFiles.Count) | Folders: $($subFolders.Count)"
foreach ($dir in $subFolders) {
$dCreated = $dir.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$dModified = $dir.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$dFileCount = (Get-ChildItem -LiteralPath $dir.FullName -File -Force -ErrorAction SilentlyContinue).Count
Write-Host (" [DIR] {0} - {1} - {2,10} - {3}" -f $dCreated, $dModified, "$dFileCount files", $dir.FullName)
}
} else {
$allFiles = @($rootItem)
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: 1"
}
if ($allFiles.Count -eq 0) { continue }
$shown = $allFiles | Select-Object -First $MaxFilesPerApp
foreach ($f in $shown) {
$hash = 'N/A'
try { $hash = (Get-FileHash -LiteralPath $f.FullName -Algorithm SHA256 -ErrorAction Stop).Hash } catch { $hash = 'HASH-ERROR' }
$size = Format-FileSize -Bytes $f.Length
$fcreated = $f.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$fmod = $f.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$sigInfo = Get-SignatureInfo -Path $f.FullName -Extension $f.Extension
Write-Host (" [{0}] {1} - {2} - {3,10} - Signer: {4} - {5}" -f $hash, $fcreated, $fmod, $size, $sigInfo.Signer, $f.FullName)
}
}
EndPowerShell:
Comment: List 30 recent scheduled tasks
Powershell: Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo
Comment: List recent Run (Windows + R) executed commands, useful for identifying ClickFix attacks
Powershell: (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" }
Comment: Remove unwanted files from common folders using native removal power of Farbar to include remove on reboot if needed. Please double check the user does not have any applications incorrectly installed in the directories listed below.
C:\ProgramData\*.csproj
C:\ProgramData\*.a3x
C:\ProgramData\*.ahk
C:\ProgramData\*.au3
C:\ProgramData\*.bat
C:\ProgramData\*.cab
C:\ProgramData\*.cmd
C:\ProgramData\*.com
C:\ProgramData\*.dll
C:\ProgramData\*.exe
C:\ProgramData\*.hta
C:\ProgramData\*.jar
C:\ProgramData\*.js
C:\ProgramData\*.jse
C:\ProgramData\*.lnk
C:\ProgramData\*.pif
C:\ProgramData\*.ps1
C:\ProgramData\*.py
C:\ProgramData\*.pyc
C:\ProgramData\*.pyd
C:\ProgramData\*.scr
C:\ProgramData\*.tmp
C:\ProgramData\*.vbe
C:\ProgramData\*.vbs
C:\ProgramData\*.wsf
C:\ProgramData\*.wsh
C:\ProgramData\*.zip
C:\ProgramData\*.rar
C:\ProgramData\*.7z
C:\Users\*\AppData\Roaming\*.csproj
C:\Users\*\AppData\Roaming\*.au3
C:\Users\*\AppData\Roaming\*.bat
C:\Users\*\AppData\Roaming\*.cab
C:\Users\*\AppData\Roaming\*.cmd
C:\Users\*\AppData\Roaming\*.com
C:\Users\*\AppData\Roaming\*.dll
C:\Users\*\AppData\Roaming\*.exe
C:\Users\*\AppData\Roaming\*.hta
C:\Users\*\AppData\Roaming\*.jar
C:\Users\*\AppData\Roaming\*.js
C:\Users\*\AppData\Roaming\*.jse
C:\Users\*\AppData\Roaming\*.lnk
C:\Users\*\AppData\Roaming\*.pif
C:\Users\*\AppData\Roaming\*.ps1
C:\Users\*\AppData\Roaming\*.py
C:\Users\*\AppData\Roaming\*.pyc
C:\Users\*\AppData\Roaming\*.pyd
C:\Users\*\AppData\Roaming\*.scr
C:\Users\*\AppData\Roaming\*.tmp
C:\Users\*\AppData\Roaming\*.vbe
C:\Users\*\AppData\Roaming\*.vbs
C:\Users\*\AppData\Roaming\*.wsf
C:\Users\*\AppData\Roaming\*.wsh
C:\Users\*\AppData\Roaming\*.zip
C:\Users\*\AppData\Roaming\*.rar
C:\Users\*\AppData\Roaming\*.7z
C:\Users\CurrentUserName\AppData\Local\*.csproj
C:\Users\CurrentUserName\AppData\Local\*.a3x
C:\Users\CurrentUserName\AppData\Local\*.ahk
C:\Users\CurrentUserName\AppData\Local\*.au3
C:\Users\CurrentUserName\AppData\Local\*.bat
C:\Users\CurrentUserName\AppData\Local\*.cab
C:\Users\CurrentUserName\AppData\Local\*.cmd
C:\Users\CurrentUserName\AppData\Local\*.com
C:\Users\CurrentUserName\AppData\Local\*.dll
C:\Users\CurrentUserName\AppData\Local\*.exe
C:\Users\CurrentUserName\AppData\Local\*.hta
C:\Users\CurrentUserName\AppData\Local\*.jar
C:\Users\CurrentUserName\AppData\Local\*.js
C:\Users\CurrentUserName\AppData\Local\*.jse
C:\Users\CurrentUserName\AppData\Local\*.lnk
C:\Users\CurrentUserName\AppData\Local\*.pif
C:\Users\CurrentUserName\AppData\Local\*.ps1
C:\Users\CurrentUserName\AppData\Local\*.py
C:\Users\CurrentUserName\AppData\Local\*.pyc
C:\Users\CurrentUserName\AppData\Local\*.pyd
C:\Users\CurrentUserName\AppData\Local\*.scr
C:\Users\CurrentUserName\AppData\Local\*.tmp
C:\Users\CurrentUserName\AppData\Local\*.vbe
C:\Users\CurrentUserName\AppData\Local\*.vbs
C:\Users\CurrentUserName\AppData\Local\*.wsf
C:\Users\CurrentUserName\AppData\Local\*.wsh
C:\Users\CurrentUserName\AppData\Local\*.zip
C:\Users\CurrentUserName\AppData\Local\*.rar
C:\Users\CurrentUserName\AppData\Local\*.7z
C:\Users\CurrentUserName\AppData\Roaming\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\*.a3x
C:\Users\CurrentUserName\AppData\Roaming\*.ahk
C:\Users\CurrentUserName\AppData\Roaming\*.au3
C:\Users\CurrentUserName\AppData\Roaming\*.bat
C:\Users\CurrentUserName\AppData\Roaming\*.cab
C:\Users\CurrentUserName\AppData\Roaming\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\*.com
C:\Users\CurrentUserName\AppData\Roaming\*.dll
C:\Users\CurrentUserName\AppData\Roaming\*.exe
C:\Users\CurrentUserName\AppData\Roaming\*.hta
C:\Users\CurrentUserName\AppData\Roaming\*.jar
C:\Users\CurrentUserName\AppData\Roaming\*.js
C:\Users\CurrentUserName\AppData\Roaming\*.jse
C:\Users\CurrentUserName\AppData\Roaming\*.lnk
C:\Users\CurrentUserName\AppData\Roaming\*.pif
C:\Users\CurrentUserName\AppData\Roaming\*.ps1
C:\Users\CurrentUserName\AppData\Roaming\*.py
C:\Users\CurrentUserName\AppData\Roaming\*.pyc
C:\Users\CurrentUserName\AppData\Roaming\*.pyd
C:\Users\CurrentUserName\AppData\Roaming\*.scr
C:\Users\CurrentUserName\AppData\Roaming\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\*.vbe
C:\Users\CurrentUserName\AppData\Roaming\*.vbs
C:\Users\CurrentUserName\AppData\Roaming\*.wsf
C:\Users\CurrentUserName\AppData\Roaming\*.wsh
C:\Users\CurrentUserName\AppData\Roaming\*.zip
C:\Users\CurrentUserName\AppData\Roaming\*.rar
C:\Users\CurrentUserName\AppData\Roaming\*.7z
Comment: RenPyLoader hollowed installed app generic removal
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cmd
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.props
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.targets
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.tmp
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.csproj
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.user
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cmd
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cache
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.config
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.bat
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cfg
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cfg
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cfg
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cfg
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cfg
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.props
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.targets
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.user
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cache
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.config
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.bat
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cfg
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.props
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.targets
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.tmp
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.csproj
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cmd
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.user
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cache
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.config
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.bat
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cfg
Comment: Remove cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\
C:\Users\CurrentUserName\AppData\Local\Roblox\UniversalApp\WebView2\EBWebView\Default\Cache\Cache_Data\
C:\Users\CurrentUserName\AppData\Local\FortniteGame\Saved\webcache\
C:\Users\CurrentUserName\AppData\Local\FortniteGame\Saved\webcache_4147\
C:\Users\CurrentUserName\AppData\Local\FortniteGame\Saved\webcache_4430\
C:\Users\CurrentUserName\AppData\Roaming\discord\Cache\Cache_Data\
C:\Users\CurrentUserName\AppData\Roaming\obs-studio\plugin_config\obs-browser\Cache\Cache_Data\
StartPowerShell:
$ProfilesDirectory = (Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList').ProfilesDirectory
$DisplayNames = @{
"chrome" = "Chrome"
"firefox" = "Firefox"
"opera" = "Opera"
"operagx" = "Opera GX"
"brave" = "Brave"
"msedge" = "Edge"
"vivaldi" = "Vivaldi"
"librewolf" = "LibreWolf"
"mullvad" = "Mullvad Browser"
"zen" = "Zen"
}
$ProcessNameMap = @{
"operagx" = "opera"
"mullvad" = "mullvadbrowser"
}
$trueCacheNames = @("Cache", "Code Cache", "DawnCache", "GPUCache", "GrShaderCache", "ShaderCache", "Shared Dictionary\cache")
function Get-CacheDirs {
param([string]$BrowserName, [string]$ProfilesDirectory)
switch ($BrowserName) {
"chrome" {
$dir = "$ProfilesDirectory\*\AppData\Local\Google\Chrome\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"firefox" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mozilla\Firefox\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"opera" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"operagx" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software\Opera GX Stable"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software\Opera GX Stable"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"brave" {
$dir = "$ProfilesDirectory\*\AppData\Local\BraveSoftware\Brave-Browser\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"msedge" {
$dir = "$ProfilesDirectory\*\AppData\Local\Microsoft\Edge\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"vivaldi" {
$dir = "$ProfilesDirectory\*\AppData\Local\Vivaldi\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"librewolf" {
$dir = "$ProfilesDirectory\*\AppData\Local\LibreWolf\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"mullvad" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mullvad\MullvadBrowser\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"zen" {
$dir = "$ProfilesDirectory\*\AppData\Local\zen\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
}
}
function Format-Size {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$BrowserKeys = @('chrome', 'firefox', 'opera', 'operagx', 'brave', 'msedge', 'vivaldi', 'librewolf', 'mullvad', 'zen')
foreach ($key in $BrowserKeys) {
$procName = if ($ProcessNameMap.ContainsKey($key)) { $ProcessNameMap[$key] } else { $key }
Get-Process -Name $procName -ErrorAction SilentlyContinue | Stop-Process -Force -ErrorAction SilentlyContinue
}
Start-Sleep -Seconds 5
$grandBytes = 0L
$grandFiles = 0
$anyFound = $false
foreach ($key in $BrowserKeys) {
$cacheDirs = Get-CacheDirs -BrowserName $key -ProfilesDirectory $ProfilesDirectory
if (-not $cacheDirs -or $cacheDirs.Count -eq 0) { continue }
$anyFound = $true
$displayName = $DisplayNames[$key]
$browserBytes = 0L
$browserFiles = 0
foreach ($cacheDir in $cacheDirs) {
if (-not (Test-Path $cacheDir)) { continue }
$items = Get-ChildItem -Path $cacheDir -Force -Recurse -ErrorAction SilentlyContinue
$files = $items | Where-Object { -not $_.PSIsContainer }
$bytes = ($files | Measure-Object -Property Length -Sum).Sum
if (-not $bytes) { $bytes = 0 }
$browserFiles += $files.Count
$browserBytes += $bytes
Get-ChildItem -Path "$cacheDir\*" -Force -ErrorAction SilentlyContinue | Remove-Item -Force -Recurse -ErrorAction SilentlyContinue
}
$grandBytes += $browserBytes
$grandFiles += $browserFiles
Write-Host ("{0,-16} freed {1,10} ({2} files)" -f $displayName, (Format-Size $browserBytes), $browserFiles)
}
if (-not $anyFound) {
Write-Host "No cache found for any installed browser."
}
Write-Host ""
Write-Host ("Total freed: {0} ({1} files)" -f (Format-Size $grandBytes), $grandFiles)
EndPowerShell:
Comment: Windows Recovery Environment (Windows RE) status and enable
CMD: reagentc.exe /info
CMD: reagentc.exe /enable
Comment: Disable hidden file extensions
cmd: reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "HideFileExt" /t REG_DWORD /d 0 /f
cmd: reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt" /v "CheckedValue" /t REG_DWORD /d 0 /f
Comment: Verify WMI repository, repair & verify again
CMD: winmgmt.exe /verifyrepository
CMD: winmgmt.exe /salvagerepository
CMD: winmgmt.exe /verifyrepository
Comment: To rebuild the performance counter library values
CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R"
CMD: "%WINDIR%\SysWOW64\lodctr.exe /R"
CMD: "C:\Windows\SYSTEM32\lodctr.exe /R"
CMD: "C:\Windows\SysWOW64\lodctr.exe /R"
Comment: Resync performance counter library values to WMI as well
CMD: winmgmt.exe /resyncperf
Comment: Force policy removal
C:\Windows\System32\GroupPolicyUsers
C:\Windows\System32\GroupPolicy
CMD: gpupdate.exe /force
Comment: Restores and hardens selected Microsoft Defender Antivirus preferences.
Comment: Tamper Protection must be temporarily disabled before applying these settings.
Comment: Thanks to AdvancedSetup from Malwarebytes
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows Defender|DisableAntiSpyware
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows Defender|DisableAntiVirus
StartPowerShell:
# Enable real-time and behavioral protection
Set-MpPreference -DisableRealtimeMonitoring $false
Set-MpPreference -DisableBehaviorMonitoring $false
# Enable potentially unwanted application blocking
Set-MpPreference -PUAProtection Enabled
# Enable cloud-delivered protection and automatic safe-sample submission
Set-MpPreference -MAPSReporting Advanced
Set-MpPreference -SubmitSamplesConsent SendSafeSamples
# Use Microsoft's recommended high cloud-blocking level
Set-MpPreference -CloudBlockLevel High
# Allow additional time for cloud analysis of suspicious files
Set-MpPreference -CloudExtendedTimeout 30
# Block connections to known malicious or untrusted network destinations
Set-MpPreference -EnableNetworkProtection Enabled
# Enable Block at First Sight
Set-MpPreference -DisableBlockAtFirstSeen $false
# Enable archive, removable-drive, network-file, download, and script scanning
Set-MpPreference -DisableArchiveScanning $false
Set-MpPreference -DisableRemovableDriveScanning $false
Set-MpPreference -DisableScanningNetworkFiles $false
Set-MpPreference -DisableIOAVProtection $false
Set-MpPreference -DisableScriptScanning $false
# Check for current security intelligence before starting a scan
Set-MpPreference -CheckForSignaturesBeforeRunningScan $true
# Enable supported DNS attack inspection and sinkholing when available
if ((Get-Command Set-MpPreference).Parameters.ContainsKey('EnableDnsSinkhole')) {
Set-MpPreference -EnableDnsSinkhole $true
}
# Sets signature update interval to 12 hours (default 24 hours)
Set-MpPreference -SignatureUpdateInterval 12
# Update Microsoft Defender security intelligence
Update-MpSignature
EndPowerShell:
Comment: List Windows Defender properties, settings
StartPowerShell:
function Write-Section {
param([string]$Title)
Write-Host ""
Write-Host "<=== $Title ===>"
}
Write-Section "Protection Status"
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntispywareEnabled, AntivirusEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, RealTimeProtectionEnabled, IsTamperProtected, NetworkProtectionStatus | Format-List
Write-Section "Signature / Engine Versions"
Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AntivirusSignatureVersion, AntispywareSignatureVersion | Format-List
Write-Section "Preferences / Configuration"
Get-MpPreference | Select-Object PUAProtection, MAPSReporting, SubmitSamplesConsent, CheckForSignaturesBeforeRunningScan, CloudBlockLevel, EnableNetworkProtection, DisableScriptScanning, DisableArchiveScanning, DisableRemovableDriveScanning, DisableScanningNetworkFiles, DisableScanningMappedNetworkDrivesForFullScan, DisableBlockAtFirstSeen, DisableHeuristics, DisableAutoExclusions | Format-List
Write-Section "Threat Detections"
$threats = Get-MpThreatDetection
if ($threats) {
$threats | Format-Table -AutoSize
} else {
Write-Host " (no threat detections found)"
}
EndPowerShell:
Comment: Enable recovery environment
CMD: bcdedit.exe /set {default} recoveryenabled yes
Comment: Restore original Windows services configuration
StartPowerShell:
Set-Service -Name "Netlogon" -StartupType Manual
Set-Service -Name "BITS" -StartupType Manual
Set-Service -Name "Dhcp" -StartupType Automatic
Set-Service -Name "EventLog" -StartupType Automatic
Set-Service -Name "EventSystem" -StartupType Automatic
Set-Service -Name "nsi" -StartupType Automatic
Set-Service -Name "RasMan" -StartupType Manual
Set-Service -Name "SDRSVC" -StartupType Manual
Set-Service -Name "SstpSvc" -StartupType Manual
Set-Service -Name "TrustedInstaller" -StartupType Manual
Set-Service -Name "VSS" -StartupType Manual
Set-Service -Name "Winmgmt" -StartupType Automatic
Set-Service -Name "wuauserv" -StartupType Manual
EndPowerShell:
Comment: Reset the Windows Update download cache and update catalog database
CMD: net.exe stop bits
CMD: net.exe stop wuauserv
CMD: net.exe stop cryptsvc
CMD: net.exe stop msiserver
CMD: rd /s /q "%SystemRoot%\SoftwareDistribution"
CMD: rd /s /q "%SystemRoot%\System32\catroot2"
CMD: net.exe start msiserver
CMD: net.exe start cryptsvc
CMD: net.exe start wuauserv
CMD: net.exe start bits
Comment: Enable automatic restart after a restart, enable automatic updates
StartRegedit:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl]
"AutoReboot"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"NoAutoUpdate"=-
EndRegedit:
Comment: Reset PowerShell execution policy
Powershell: Set-ExecutionPolicy Unrestricted -Scope CurrentUser -Force
Comment: Fully reset the Windows network stack, WinHTTP proxy settings, DNS cache, and BITS transfer queue.
Comment: Thanks to AdvancedSetup from Malwarebytes
StartBatch:
ipconfig.exe /flushdns
ipconfig.exe /release
netsh.exe winsock reset catalog
netsh.exe int ip reset
netsh.exe winhttp reset proxy
netsh.exe winhttp reset autoproxy
netsh.exe winhttp reset tracing
EndBatch:
Comment: BITS reset
Startbatch:
@echo off
net.exe stop BITS
ipconfig.exe /flushdns
ren "%programdata%\Microsoft\Network\Downloader\qmgr*.*" qmgr*.*.old
net.exe start BITS
Endbatch:
cmd: bitsadmin.exe /reset /allusers
Comment: Additional temp file removal
C:\Windows\System32\config\systemprofile\AppData\Local\*.tmp
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
C:\Users\CurrentUserName\AppData\Local\Temp\*
C:\Windows\Temp\*
C:\Windows\SystemTemp\*
C:\Windows\Prefetch\*
Comment: System repair commands
CMD: SFC.exe /scannow
CMD: DISM.exe /Online /Cleanup-image /Restorehealth
CMD: DISM.exe /Online /Cleanup-Image /StartComponentCleanup /ResetBase
Comment: Remove set proxy servers
RemoveProxy:
Comment: Remove temporary files via FRST
EmptyTemp:
End::
Warning
Executing a Fixlist on the wrong system may permanently damage it. Continue only if this link was meant for you.
To view the content, acknowledge this warning.