Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-03-2020 Ran by [removed] (27-03-2020 10:28:27) Running from C:\Users\[removed]\Downloads Windows 10 Pro Version 1909 18363.752 (X64) (2019-09-30 02:56:25) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2825346925-3975081358-1914956935-500 - Administrator - Disabled) calam (S-1-5-21-2825346925-3975081358-1914956935-1003 - Limited - Disabled) DefaultAccount (S-1-5-21-2825346925-3975081358-1914956935-503 - Limited - Disabled) Guest (S-1-5-21-2825346925-3975081358-1914956935-501 - Limited - Disabled) misfi (S-1-5-21-2825346925-3975081358-1914956935-1002 - Administrator - Enabled) => C:\Users\misfi WDAGUtilityAccount (S-1-5-21-2825346925-3975081358-1914956935-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Avast Antivirus (Enabled) {B693136B-F6EE-DD1C-A0EF-229B8B0B29C4} FW: Avast Antivirus (Enabled) {D322394B-73F7-C65E-BBB0-3B81E063D6D4} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated) Apex Legends (HKLM-x32\...\{D7FBF176-382D-484E-863A-DFD1124A2A1C}) (Version: 1.0.3.1 - Electronic Arts, Inc.) AutoHotkey 1.1.32.00 (HKLM\...\AutoHotkey) (Version: 1.1.32.00 - Lexikos) Avast Premium Security (HKLM-x32\...\Avast Antivirus) (Version: 20.1.2397 - AVAST Software) Avast SecureLine VPN (HKLM\...\{2CD3C92F-EDC5-4B02-9B0A-9C1D37C58EF5}_is1) (Version: 5.5.515 - AVAST Software) CAM (HKLM-x32\...\{7929918C-B718-4DE8-9171-C885B0591BA7}) (Version: 3.7.8 - NZXT) Citrix Receiver 4.9 LTSR (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 14.9.4000.9 - Citrix Systems, Inc.) CORSAIR iCUE Software (HKLM-x32\...\{7D79914A-B70B-4915-94AB-C90DEE152FD0}) (Version: 3.21.88 - Corsair) Discord (HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\Discord) (Version: 0.0.306 - Discord Inc.) Epic Games Launcher (HKLM-x32\...\{DCE27B29-200D-491A-BBC5-98ECEFEC0843}) (Version: 1.1.257.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.149 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden Intel® PROSet/Wireless Software (HKLM-x32\...\{18ec79fd-8f83-4e12-bfa5-80c9872cc56b}) (Version: 20.40.0 - Intel Corporation) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Logitech G HUB (HKLM\...\{521c89be-637f-4274-a840-baaf7460c2b2}) (Version: - Logitech) Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes) Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.11929.20648 - Microsoft Corporation) Microsoft Office Professional Plus 2019 - en-us (HKLM\...\ProPlus2019Retail - en-us) (Version: 16.0.11929.20648 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\OneDriveSetup.exe) (Version: 19.232.1124.0010 - Microsoft Corporation) Microsoft Visio Professional 2019 - en-us (HKLM\...\VisioPro2019Retail - en-us) (Version: 16.0.11929.20648 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.24.28127 (HKLM-x32\...\{282975d8-55fe-4991-bbbb-06a72581ce58}) (Version: 14.24.28127.4 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.24.28127 (HKLM-x32\...\{e31cb1a4-76b5-46a5-a084-3fa419e82201}) (Version: 14.24.28127.4 - Microsoft Corporation) Mozilla Firefox 74.0 (x64 en-US) (HKLM\...\Mozilla Firefox 74.0 (x64 en-US)) (Version: 74.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.0.2 - Mozilla) MSI Afterburner 4.6.1 (HKLM-x32\...\Afterburner) (Version: 4.6.1 - MSI Co., LTD) NetLimiter 4 (HKLM\...\{4DFB0D0A-5023-484E-B3F6-78D5AFFCE477}) (Version: 4.0.59.0 - Locktime Software) Hidden NetLimiter 4 (HKLM-x32\...\NetLimiter 4 4.0.59.0) (Version: 4.0.59.0 - Locktime Software) NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.19 - NVIDIA Corporation) Hidden NVIDIA GeForce Experience 3.20.2.34 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.2.34 - NVIDIA Corporation) NVIDIA GeForce NOW 2.0.16.148 (HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GeforceNOW) (Version: 2.0.16.148 - NVIDIA Corporation) NVIDIA Graphics Driver 445.75 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 445.75 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.38.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.26 - NVIDIA Corporation) NVIDIA Install Application (HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer) (Version: 2.1002.338.0 - NVIDIA Corporation) Hidden NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation) NVIDIA USBC Driver 1.38.831.832 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC) (Version: 1.38.831.832 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.12130.20272 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.12130.20272 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.12130.20272 - Microsoft Corporation) Hidden Online Plug-in (HKLM-x32\...\{CC7B306B-BCB3-4E05-8D6E-40E6CDBD8FDB}) (Version: 14.9.4000.9 - Citrix Systems, Inc.) Hidden Origin (HKLM-x32\...\Origin) (Version: 10.5.66.38849 - Electronic Arts, Inc.) Self-service Plug-in (HKLM-x32\...\{63680662-0CFF-4C2B-A269-1CD4DD145430}) (Version: 4.9.4000.9 - Citrix Systems, Inc.) Hidden Skype Meetings App (HKLM-x32\...\{BC1D9E47-8927-4AA1-A891-7763BC2475B7}) (Version: 16.2.0.511 - Microsoft Corporation) Spotify (HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\Spotify) (Version: 1.1.28.721.g5b5ee660 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) ViGEm Bus Driver (HKLM\...\{4030BA52-E312-462E-B020-CCB5A2AC5497}) (Version: 1.16.116 - Nefarius Software Solutions e.U.) Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22866 - Microsoft Corporation) Packages: ========= DirectX -> C:\Program Files\WindowsApps\Microsoft.DirectXRuntime_9.29.952.0_x64__8wekyb3d8bbwe [2019-09-30] (Microsoft Corporation) DirectX -> C:\Program Files\WindowsApps\Microsoft.DirectXRuntime_9.29.952.0_x86__8wekyb3d8bbwe [2019-09-30] (Microsoft Corporation) Gaming Services -> C:\Program Files\WindowsApps\Microsoft.GamingServices_1.38.14001.0_x64__8wekyb3d8bbwe [2020-02-21] (Microsoft Corporation) Gears 5 -> C:\Program Files\WindowsApps\Microsoft.HalifaxBaseGame_1.1.166.0_x64__8wekyb3d8bbwe [2020-02-23] (Microsoft Studios) Halo: The Master Chief Collection -> C:\Program Files\WindowsApps\Microsoft.Chelan_1.1246.0.0_x64__8wekyb3d8bbwe [2019-12-06] (Microsoft Studios) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-08-26] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-08-26] (Microsoft Corporation) [MS Ad] MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.33.13253.0_x64__8wekyb3d8bbwe [2019-11-26] (Microsoft Corporation) [MS Ad] Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.1.137.0_x64__dt26b99r8h8gj [2019-11-02] (Realtek Semiconductor Corp) The Master Chief Collection: REACH -> C:\Program Files\WindowsApps\Microsoft.TheMasterChiefCollectionREACH_1.1.0.0_x64__8wekyb3d8bbwe [2019-12-06] (Microsoft Studios) Xbox One SmartGlass -> C:\Program Files\WindowsApps\Microsoft.XboxOneSmartGlass_2.2.1702.2004_x64__8wekyb3d8bbwe [2019-09-02] (Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2825346925-3975081358-1914956935-1002_Classes\CLSID\{3E3AD4BD-346A-460A-80E8-90699B75C00B}\InprocServer32 -> C:\Users\misfi\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\GatewayActiveX-x64.dll (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-25] (Avast Software s.r.o. -> AVAST Software) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => D:\Programs\7zip\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-25] (Avast Software s.r.o. -> AVAST Software) ContextMenuHandlers1: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => -> No File ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-25] (Avast Software s.r.o. -> AVAST Software) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-13] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => D:\Programs\7zip\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers4: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => -> No File ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2020-03-17] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => D:\Programs\7zip\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-25] (Avast Software s.r.o. -> AVAST Software) ContextMenuHandlers6: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => -> No File ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-13] (Malwarebytes Corporation -> Malwarebytes) ==================== Codecs (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Drivers32: [VIDC.RTV1] => C:\windows\system32\rtvcvfw64.dll [246272 2012-09-28] () [File not signed] HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [File not signed] ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2019-09-30 14:20 - 2019-09-30 14:20 - 000209408 _____ () [File not signed] C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\quazip.dll 2019-09-30 14:19 - 2019-09-30 14:19 - 000101376 _____ () [File not signed] C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\zlib.dll 2019-04-21 02:33 - 2019-04-21 02:33 - 000232448 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTCore.dll 2019-04-21 02:32 - 2019-04-21 02:32 - 000057344 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTFC.dll 2019-04-21 02:33 - 2019-04-21 02:33 - 000649216 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTHAL.dll 2019-04-21 02:32 - 2019-04-21 02:32 - 000074240 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTMUI.dll 2019-04-21 02:33 - 2019-04-21 02:33 - 000367104 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTUI.dll 2019-07-29 00:08 - 2019-07-29 00:08 - 001955328 _____ () [File not signed] C:\Program Files (x86)\NZXT\CAM\Launcher\ffmpeg.dll 2019-07-29 00:08 - 2019-07-29 00:08 - 000017920 _____ () [File not signed] C:\Program Files (x86)\NZXT\CAM\Launcher\libegl.dll 2019-07-29 00:08 - 2019-07-29 00:08 - 003687936 _____ () [File not signed] C:\Program Files (x86)\NZXT\CAM\Launcher\libglesv2.dll 2019-07-25 00:00 - 2020-03-27 10:10 - 001431552 _____ (CPUID) [File not signed] C:\Program Files (x86)\NZXT\CAM\DLLs\cpuidsdk.dll 2019-07-29 00:08 - 2019-07-29 00:08 - 017861632 _____ (Node.js) [File not signed] C:\Program Files (x86)\NZXT\CAM\Launcher\node.dll 2019-07-25 00:00 - 2019-07-25 00:00 - 001246208 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files (x86)\NZXT\CAM\x86\SQLite.Interop.dll 2019-08-23 18:33 - 2019-08-23 18:33 - 000090112 _____ (Silicon Laboratories, Inc.) [File not signed] C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\SiUSBXp.dll 2019-07-25 00:00 - 2019-07-25 00:00 - 000090112 _____ (Silicon Laboratories, Inc.) [File not signed] C:\Program Files (x86)\NZXT\CAM\DLLs\SiUSBXp.dll 2020-02-22 16:54 - 2020-03-16 14:05 - 001282048 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\LIBEAY32.dll 2020-02-22 16:54 - 2020-03-16 14:06 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\ssleay32.dll 2019-09-13 00:09 - 2018-09-05 22:32 - 002095104 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\AVAST Software\SecureLine VPN\libcrypto-1_1.dll 2019-09-23 20:12 - 2019-09-23 20:12 - 002508288 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\libcrypto-1_1.dll 2019-09-23 20:12 - 2019-09-23 20:12 - 000530432 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\libssl-1_1.dll 2020-02-22 16:54 - 2020-01-28 19:13 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll 2020-03-23 17:14 - 2020-01-28 19:13 - 005487104 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Core.dll 2020-03-23 17:14 - 2020-01-28 19:13 - 005841920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Gui.dll 2020-03-23 17:14 - 2020-01-28 19:13 - 001179136 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Network.dll 2020-03-23 17:14 - 2020-01-28 19:13 - 000146432 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebSockets.dll 2020-03-23 17:14 - 2020-01-28 19:13 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll 2020-03-23 17:14 - 2020-01-28 19:13 - 000184832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Xml.dll 2019-09-30 15:07 - 2019-09-30 15:07 - 005133432 _____ (The Qt Company Oy -> The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Qt5Core.dll ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\misfi\AppData\Local\Temp:$DATA​ [16] ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer trusted/restricted ========== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\sharepoint.com -> hxxps://kcassinelli-files.sharepoint.com IE trusted site: HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\webcompanion.com -> hxxp://webcompanion.com ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2018-09-15 01:31 - 2018-09-15 01:31 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\misfi\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\743581-free-ironman-wallpaper-hd-1920x1080-for-4k.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKLM\...\StartupApproved\Run32: => "TeamsMachineUninstallerLocalAppData" HKLM\...\StartupApproved\Run32: => "ConnectionCenter" HKLM\...\StartupApproved\Run32: => "Redirector" HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\StartupApproved\StartupFolder: => "[removed]" HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\StartupApproved\Run: => "NetLimiter" HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-2825346925-3975081358-1914956935-1002\...\StartupApproved\Run: => "EpicGamesLauncher" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [UDP Query User{D785292F-EF30-4631-8D31-3EF97B3E6215}C:\program files (x86)\lghub\lghub_agent.exe] => (Allow) C:\program files (x86)\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [TCP Query User{B981ABFF-78A3-4D0A-8223-07181337D469}C:\program files (x86)\lghub\lghub_agent.exe] => (Allow) C:\program files (x86)\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [UDP Query User{4E9627FF-98C4-488A-BB1A-C0E3153E8C5E}D:\programs\lghub\lghub_agent.exe] => (Allow) D:\programs\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [TCP Query User{9BAFA668-23DC-4F36-9C28-2E90922EF3AD}D:\programs\lghub\lghub_agent.exe] => (Allow) D:\programs\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [{83E3A617-42EE-4513-B325-3C20070A3B47}] => (Allow) D:\Programs\Steam Programs\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{4DFEE10C-0DE8-4F1E-8778-B07B90F5D203}] => (Allow) D:\Programs\Steam Programs\Steam.exe (Valve -> Valve Corporation) FirewallRules: [UDP Query User{A29F1971-6846-466F-9D35-EED305C1A780}C:\program files (x86)\nzxt\cam\cam.desktop.exe] => (Allow) C:\program files (x86)\nzxt\cam\cam.desktop.exe (NZXT, Inc. -> ) FirewallRules: [TCP Query User{FBD73D2F-219B-4B91-BD22-83E283060290}C:\program files (x86)\nzxt\cam\cam.desktop.exe] => (Allow) C:\program files (x86)\nzxt\cam\cam.desktop.exe (NZXT, Inc. -> ) FirewallRules: [{9AA7166F-D510-4C99-82EC-F5D8F925E8F6}] => (Block) C:\program files\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [{BDC3E73B-51BA-4012-937E-A83ED129E9E1}] => (Block) C:\program files\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [UDP Query User{B507A692-E0EE-48A9-9B82-BD9D050C2D0B}C:\program files\lghub\lghub_agent.exe] => (Allow) C:\program files\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [TCP Query User{AB4C631B-CA81-447F-A4DA-B6EDFADAB8C3}C:\program files\lghub\lghub_agent.exe] => (Allow) C:\program files\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.) FirewallRules: [UDP Query User{25D9EFD9-C271-46B5-8592-010D56222217}C:\program files (x86)\nzxt\cam\cam.desktop.exe] => (Allow) C:\program files (x86)\nzxt\cam\cam.desktop.exe (NZXT, Inc. -> ) FirewallRules: [TCP Query User{C67BCC2B-50EB-46A3-94DC-45FE8EA1CE0E}C:\program files (x86)\nzxt\cam\cam.desktop.exe] => (Allow) C:\program files (x86)\nzxt\cam\cam.desktop.exe (NZXT, Inc. -> ) FirewallRules: [{02C40CFA-81F3-42E5-A72B-CAFF920BD844}] => (Allow) LPort=9142 FirewallRules: [{9125D48B-5546-4354-8748-5B6803632B0E}] => (Allow) LPort=38518 FirewallRules: [{6C2F0FF4-C3F6-4EBC-A501-F3D43C9811A7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{E11393B4-F3F2-4E2D-B0B5-0FF1A9B9DCC0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{6EE2AC91-44CA-49F8-83A9-2E26B21AA056}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{40ED3791-1925-419F-8B88-A311CAF4766E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{06AE2988-6DE6-4B54-8928-A144AD31486A}] => (Allow) D:\Programs\Steam Programs\steamapps\common\Destiny 2\destiny2.exe (Bungie Inc. -> Bungie) FirewallRules: [{B6D3A41C-691F-427B-9BCA-C92AC9028979}] => (Allow) D:\Programs\Steam Programs\steamapps\common\Destiny 2\destiny2.exe (Bungie Inc. -> Bungie) FirewallRules: [{C9143C0D-19AB-4942-BFEB-2CE8D3893C16}] => (Allow) D:\Programs\Steam Programs\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{F10DBEB4-552C-4CF2-BCED-29AC0D4E4829}] => (Allow) D:\Programs\Steam Programs\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{2FEFC80B-ACCE-4682-9D8A-82F121DE7723}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{EEBA9B72-9E4B-4B1E-AD4B-B94E20BF2FDD}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{286352BB-37A4-4972-AF2F-0B916E28FFDB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{07522D8B-7621-479C-AE8D-5372C95F0D15}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{2EF4CFA8-3AFA-440E-A44C-7FD9126F1EC3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{78FA13AB-BA84-4F4D-9291-17565A484D3F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [TCP Query User{99BF9EB8-5D14-4456-A755-A036B9F60F25}C:\users\misfi\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\misfi\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [UDP Query User{B743C051-5A53-4B48-A1E2-B7CC1A1680EF}C:\users\misfi\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\misfi\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{87ED371C-B99C-4C11-8E62-6B1C3D348163}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel(R) Wireless Connectivity Solutions -> ) FirewallRules: [{EE704F78-9FB4-400C-B1A1-6D57C49FDDA9}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{0B3BF523-B2BD-4B27-A088-B1F79101C99C}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{DA4C011B-A0D8-4B26-947C-E56DBE7FA5E1}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{30F923BC-023D-4C1D-ADFD-A30C9C1C3506}] => (Allow) D:\Programs\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [{CF9CFF28-1B12-4109-AB5A-97C8DA347FC4}] => (Allow) D:\Programs\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [{ABACE310-C437-4839-8457-D81123D75A0F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{DE0F6B06-0FB7-4C49-A926-DA2E7A2B90B1}] => (Allow) D:\Programs\Steam Programs\steamapps\common\Shadow of the Tomb Raider\SOTTR.exe (Eidos Inc.) [File not signed] FirewallRules: [{9CF42387-F2F6-4EFF-9392-81C1FEF025D3}] => (Allow) D:\Programs\Steam Programs\steamapps\common\Shadow of the Tomb Raider\SOTTR.exe (Eidos Inc.) [File not signed] FirewallRules: [{5367ED37-F3DE-43CF-9EAB-A13AD654006F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe No File FirewallRules: [{0D4BFA1A-824B-4989-9BAB-3A239CDB3541}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe No File FirewallRules: [{29D532B8-D404-4849-A471-93899D1B9BDE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe No File FirewallRules: [{84F7BB7D-4D75-412D-8E7C-3E79C7D8130C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe No File FirewallRules: [{5D67F1B3-6418-402D-B447-1DC89A3C89D3}] => (Allow) C:\Users\misfi\AppData\Roaming\uTorrent\uTorrent.exe No File FirewallRules: [{2D2F36FA-B23F-43C1-B847-449C2FDBD4F7}] => (Allow) C:\Users\misfi\AppData\Roaming\uTorrent\uTorrent.exe No File FirewallRules: [{61AF5075-54C2-4094-A626-543C04B6E622}] => (Allow) D:\Programs\Steam Programs\steamapps\common\Warframe\Warframe.x64.exe (Digital Extremes Ltd. -> Digital Extremes) FirewallRules: [{EAE9C206-27A8-47C0-97A6-C993B61C933A}] => (Allow) D:\Programs\Steam Programs\steamapps\common\Warframe\Warframe.x64.exe (Digital Extremes Ltd. -> Digital Extremes) FirewallRules: [{B7D005EB-7E3C-4F6A-9A1A-97D079E1B926}] => (Allow) D:\Programs\Steam Programs\steamapps\common\Warframe\Tools\Launcher.exe (Digital Extremes Ltd. -> Digital Extremes) FirewallRules: [{35E2A2B6-A29B-474C-81AA-4FCD884513E7}] => (Allow) D:\Programs\Steam Programs\steamapps\common\Warframe\Tools\RemoteCrashSender.exe (Digital Extremes Ltd. -> ) FirewallRules: [{CC58D23A-71EA-41A7-A009-28A8BA2BCBDB}] => (Allow) D:\Programs\Steam Programs\steamapps\common\Warframe\Warframe.x64.exe (Digital Extremes Ltd. -> Digital Extremes) FirewallRules: [{120C8EBA-8675-4C8A-B474-3196C7FEF405}] => (Allow) D:\Programs\Steam Programs\steamapps\common\Warframe\Warframe.x64.exe (Digital Extremes Ltd. -> Digital Extremes) FirewallRules: [{6D3FAFCA-CCF5-4CF3-BBF9-EC67668F5645}] => (Allow) D:\Programs\Steam Programs\steamapps\common\Warframe\Tools\Launcher.exe (Digital Extremes Ltd. -> Digital Extremes) FirewallRules: [{ECD0078F-7F1D-44C8-9C14-6DDB54E35EE8}] => (Allow) D:\Programs\Steam Programs\steamapps\common\Warframe\Tools\RemoteCrashSender.exe (Digital Extremes Ltd. -> ) FirewallRules: [{EC54E1DE-FE0B-4623-A0F0-7B50B904363D}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe No File FirewallRules: [{D334B0B2-88FD-4072-8BF7-9323370104D7}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe No File FirewallRules: [{4D54A723-97EA-423D-9ED2-20555B3DD833}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe No File FirewallRules: [{43A5F0FE-149E-4CEC-BCD6-6AD31A02F659}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe No File FirewallRules: [{50E61C81-0999-44A9-B13C-8FB680B071F2}] => (Allow) C:\Program Files (x86)\Popcorn Time\nodejs\node.exe No File FirewallRules: [{361261F9-B853-462B-B68C-6DC61D669671}] => (Allow) C:\Program Files (x86)\Popcorn Time\nodejs\node.exe No File FirewallRules: [{340D436A-104B-42CC-AD28-AA871DDCEA27}] => (Allow) C:\Program Files (x86)\Popcorn Time\nodejs\node.exe No File FirewallRules: [{E3B39A13-E6A9-44EF-850F-F8086B43CE14}] => (Allow) C:\Program Files (x86)\Popcorn Time\nodejs\node.exe No File FirewallRules: [{A48D04C9-1769-476A-B0B3-C8089D1CFDCD}] => (Allow) D:\Programs\psnowlauncher.exe No File ==================== Restore Points ========================= 20-03-2020 09:16:15 Installed DirectX 25-03-2020 16:00:32 Windows Update 26-03-2020 16:38:23 Removed PlayStation™Now ==================== Faulty Device Manager Devices ============ Name: avast! SecureLine TAP Adapter v3 Description: avast! SecureLine TAP Adapter v3 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: TAP-Windows Provider V9 Service: aswTap Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ======================== Application errors: ================== Error: (03/27/2020 10:25:53 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (12700,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (03/27/2020 10:18:04 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (18500,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (03/26/2020 09:11:53 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (17668,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (03/26/2020 07:09:26 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (9152,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (03/26/2020 06:22:55 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (15848,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (03/26/2020 06:15:13 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (16996,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (03/26/2020 05:47:44 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (12796,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (03/26/2020 05:19:21 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (15592,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. System errors: ============= Error: (03/26/2020 07:08:16 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QVUMEON) Description: The server {D18705BE-FC2F-44C8-AEFF-1CD49AEA8FC1} did not register with DCOM within the required timeout. Error: (03/26/2020 07:06:16 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QVUMEON) Description: The server {D18705BE-FC2F-44C8-AEFF-1CD49AEA8FC1} did not register with DCOM within the required timeout. Error: (03/26/2020 04:37:49 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9MWPM2CQNLHN-Microsoft.GamingServices. Error: (03/26/2020 04:36:27 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16392) (User: NT AUTHORITY) Description: The BITS service failed to start. Error 2147500053. Error: (03/26/2020 12:39:35 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The IncognitoVPN Service service terminated unexpectedly. It has done this 1 time(s). Error: (03/25/2020 09:55:55 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout. Error: (03/25/2020 09:55:55 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout. Error: (03/25/2020 09:55:55 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout. Windows Defender: =================================== Date: 2020-02-28 09:15:16.020 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {71706BA6-6D73-4480-BBC0-F2214A919C3E} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2020-02-24 12:23:01.128 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {C937B5FF-D6F7-4B96-A296-ADDE6C270827} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2020-02-24 11:38:04.208 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {DEFD023B-6AF3-49B6-9AEB-4BD383CAF646} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2020-02-22 13:49:08.997 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {478EB891-8A64-4583-B0C4-26E0CACD1896} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2020-02-01 10:52:55.210 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {F118C5BE-4833-40DD-800C-545BA6D207EB} Scan Type: Antimalware Scan Parameters: Full Scan Date: 2020-03-26 16:46:55.767 Description: Windows Defender Antivirus has encountered an error trying to update security intelligence. New security intelligence Version: Previous security intelligence Version: 1.313.68.0 Update Source: Microsoft Update Server Security intelligence Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16900.4 Error code: 0x8024001e Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. CodeIntegrity: =================================== Date: 2020-03-26 21:33:12.580 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements. Date: 2020-03-26 21:33:12.566 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements. Date: 2020-03-26 21:33:12.553 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements. Date: 2020-03-26 21:33:12.540 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements. Date: 2020-03-26 21:33:12.526 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements. Date: 2020-03-26 21:33:12.512 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements. Date: 2020-03-26 21:33:12.500 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements. Date: 2020-03-26 21:33:12.486 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== BIOS: American Megatrends Inc. P4.00E 04/19/2019 Motherboard: ASRock Z390 Pro4 Processor: Intel(R) Core(TM) i7-9700K CPU @ 3.60GHz Percentage of memory in use: 18% Total physical RAM: 32684.63 MB Available physical RAM: 26504.72 MB Total Virtual: 37548.63 MB Available Virtual: 29886.09 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:231.61 GB) (Free:130.48 GB) NTFS Drive d: (Data) (Fixed) (Total:931.5 GB) (Free:412.75 GB) NTFS Drive f: (Partition) (Fixed) (Total:232.87 GB) (Free:232.48 GB) NTFS \\?\Volume{fa185e2d-1731-4f07-8545-fd97ba9cee9c}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS \\?\Volume{3a3b6193-c368-445c-982c-5e843565119d}\ (Windows RE tools) (Fixed) (Total:0.39 GB) (Free:0.38 GB) NTFS \\?\Volume{b8ccf6fc-583a-8247-4f6d-700df9418c7b}\ () (Fixed) (Total:24.78 GB) (Free:0 GB) NTFS \\?\Volume{a6a6d36b-772d-834c-4ad6-aae13186acf3}\ () (Fixed) (Total:73.48 GB) (Free:0 GB) NTFS \\?\Volume{a7537661-921f-ed59-a758-f2ff8a6db369}\ () (Fixed) (Total:0 GB) (Free:0 GB) NTFS \\?\Volume{e6488ed6-b49f-4577-ab8e-df3672fab826}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32 ==================== MBR & Partition Table ==================== Attempted reading MBR returned 0 bytes. Could not read MBR for disk 4. ==================== End of Addition.txt =======================