Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-04-2022 Ran by [removed] (23-04-2022 17:34:03) Running from C:\Users\[removed]\Desktop Microsoft Windows 10 Home Version 21H1 19043.1620 (X64) (2022-04-09 05:11:26) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) Administrator (S-1-5-21-1006872022-3032962147-1773234815-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1006872022-3032962147-1773234815-503 - Limited - Disabled) Eldritch (S-1-5-21-1006872022-3032962147-1773234815-1001 - Administrator - Enabled) => C:\Users\Eldritch Guest (S-1-5-21-1006872022-3032962147-1773234815-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-1006872022-3032962147-1773234815-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 21.07 (x64) (HKLM\...\7-Zip) (Version: 21.07 - Igor Pavlov) Energy Star (HKLM\...\{5CB22648-35F8-41BC-9C35-1E41FE6E12A5}) (Version: 1.1.1 - HP Inc.) HP 3D DriveGuard (HKLM-x32\...\{301F57A8-9CF2-4E0B-B742-26A80AF43CE6}) (Version: 6.0.44.1 - HP) HP Audio Switch (HKLM-x32\...\{BC852AA8-58F6-4F07-ACB1-7377E52CA4F3}) (Version: 1.0.150.0 - HP Inc.) HP Connection Optimizer (HKLM-x32\...\{6468C4A5-E47E-405F-B675-A70A70983EA6}) (Version: 2.0.9.0 - HP Inc.) HP CoolSense (HKLM-x32\...\{10F0BF3E-DBDB-422A-8C12-B4D46711D7C8}) (Version: 2.22.2 - HP Inc.) HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.) HP ePrint SW (HKLM-x32\...\{cdb5f70f-5107-4613-bf69-15de903b5b5d}) (Version: 5.5.22560 - HP Inc.) HP JumpStart Apps (HKLM-x32\...\HP JumpStart Apps) (Version: 7.0.32 - HP Inc.) HP JumpStart Bridge (HKLM-x32\...\{3FC961DB-BD36-4D8D-B276-0C456A2BB638}) (Version: 1.4.0.441 - HP Inc.) HP JumpStart Launch (HKLM-x32\...\{F213102E-FD30-4E22-AF73-4C682D65FFEE}) (Version: 1.4.441.0 - HP Inc.) HP Support Assistant (HKLM-x32\...\{4AAC4B07-77EF-4BCF-88DC-D24E4DE683E8}) (Version: 8.5.37.19 - HP Inc.) HP Support Solutions Framework (HKLM-x32\...\{FF81F9EB-61C1-48A4-8EE5-45C5D61BC0E0}) (Version: 12.19.53.13 - HP Inc.) HP System Event Utility (HKLM-x32\...\{4B0A7A8A-ECE5-4639-9A0D-C535F354313D}) (Version: 1.4.26 - HP Inc.) HP Wireless Button Driver (HKLM-x32\...\{2EC9AB64-3ACA-460D-B309-0A7052B0C8C0}) (Version: 1.1.21.1 - HP) Intel(R) Chipset Device Software (HKLM-x32\...\{17408817-d415-4768-a160-ae6d46d6bdb0}) (Version: 10.1.1.44 - Intel(R) Corporation) Hidden Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.3.10203.4295 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1043 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 22.20.16.4815 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.7.3.1019 - Intel Corporation) Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.715.0 - Intel Corporation) Hidden Intel(R) Trusted Connect Services Client (HKLM-x32\...\{2b32b7d0-4f9f-47c8-adb7-807e6cb2fb75}) (Version: 1.47.715.0 - Intel Corporation) Hidden Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000071-0190-1033-84C8-B8D95FA3C8C3}) (Version: 19.71.0 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{8060a69f-ee27-444b-b126-775f861232ea}) (Version: 20.0.2 - Intel Corporation) Java 8 Update 321 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180321F0}) (Version: 8.0.3210.7 - Oracle Corporation) K-Lite Mega Codec Pack 16.9.5 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 16.9.5 - KLCP) MCC Tool Chest PE (HKLM-x32\...\{822D45B5-B729-4511-8967-2714CE611B8D}) (Version: 0.00.0100 - MCCToolChest) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 100.0.1185.44 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.24.28127 (HKLM-x32\...\{282975d8-55fe-4991-bbbb-06a72581ce58}) (Version: 14.24.28127.4 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.24.28127 (HKLM-x32\...\{e31cb1a4-76b5-46a5-a084-3fa419e82201}) (Version: 14.24.28127.4 - Microsoft Corporation) Minecraft Launcher (HKLM-x32\...\{27B34E47-68AE-4802-822A-9F0C187AF84A}) (Version: 1.0.0.0 - Mojang) Minecraft: Education Edition (HKLM-x32\...\{4B83BB7B-FA66-4CEE-B8F6-92E03A2678E9}) (Version: 1.17.32.00 - Microsoft Studios) Hidden Minecraft: Education Edition (HKLM-x32\...\Minecraft: Education Edition 1.17.32.00) (Version: 1.17.32.00 - Microsoft Studios) Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox 99.0.1 (x64 en-US)) (Version: 99.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 99.0 - Mozilla) NetLimiter 4 (HKLM\...\{6B87DB1D-BC93-44BF-B156-9F3BA64CE86D}) (Version: 4.1.12.0 - Locktime Software) Hidden NetLimiter 4 (HKLM-x32\...\NetLimiter 4 4.1.12.0) (Version: 4.1.12.0 - Locktime Software) NVIDIA FrameView SDK 1.2.7321.30900954 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.2.7321.30900954 - NVIDIA Corporation) NVIDIA Graphics Driver 512.15 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 512.15 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.39.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.39.3 - NVIDIA Corporation) NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.370.162 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.19.627.2017 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8228 - Realtek Semiconductor Corp.) Synaptics ClickPad Driver (HKLM\...\SynTPDeinstKey) (Version: 19.5.10.75 - Synaptics Incorporated) VLC media player (HKLM\...\VLC media player) (Version: 3.0.16 - VideoLAN) Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Windows PC Health Check (HKLM\...\{B1E7D0FD-7CFE-4E0C-A5DA-0F676499DB91}) (Version: 3.2.2110.14001 - Microsoft Corporation) Wise Memory Optimizer 4.1.6 (HKLM\...\Wise Memory Optimizer_is1) (Version: 4.1.6 - WiseCleaner.com, Inc.) Packages: ========= Dropbox promotion -> C:\Program Files\WindowsApps\C27EB4BA.DropboxOEM_20.4.3.0_x64__xbfy0k16fey96 [2022-04-10] (Dropbox Inc.) HP JumpStart -> C:\Program Files\WindowsApps\AD2F1837.HPJumpStart_1.4.443.0_x86__v10z8vjag6ke6 [2022-04-09] (HP Inc.) Microsoft Access -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Access_16051.13426.20404.0_x86__8wekyb3d8bbwe [2022-04-09] (Microsoft Corporation) Microsoft Excel -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Excel_16051.13426.20404.0_x86__8wekyb3d8bbwe [2022-04-09] (Microsoft Corporation) Microsoft Office Desktop Apps -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.13426.20404.0_x86__8wekyb3d8bbwe [2022-04-09] (Microsoft Corporation) Microsoft Outlook -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.13426.20404.0_x86__8wekyb3d8bbwe [2022-04-09] (Microsoft Corporation) Microsoft PowerPoint -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.PowerPoint_16051.13426.20404.0_x86__8wekyb3d8bbwe [2022-04-09] (Microsoft Corporation) Microsoft Publisher -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Publisher_16051.13426.20404.0_x86__8wekyb3d8bbwe [2022-04-09] (Microsoft Corporation) Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.10142.0_x64__8wekyb3d8bbwe [2022-04-09] (Microsoft Studios) [MS Ad] Microsoft Word -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Word_16051.13426.20404.0_x86__8wekyb3d8bbwe [2022-04-09] (Microsoft Corporation) Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.98.1805.0_x64__mcm4njqhnhss8 [2022-04-10] (Netflix, Inc.) NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.962.0_x64__56jybvy8sckqj [2022-04-09] (NVIDIA Corp.) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1006872022-3032962147-1773234815-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Eldritch\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-1006872022-3032962147-1773234815-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Eldritch\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-1006872022-3032962147-1773234815-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Eldritch\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\amd64\FileSyncShell64.dll => No File ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed] ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed] ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki126951.inf_amd64_94804e3918169543\igfxDTCM.dll [2018-08-28] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvhmig.inf_amd64_715167e770b0a27c\nvshext.dll [2022-03-18] (Nvidia Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed] ==================== Codecs (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Drivers32: [VIDC.X264] => C:\windows\system32\x264vfw64.dll [3799552 2017-07-30] (x264vfw project) [File not signed] HKLM\...\Drivers32: [VIDC.HFYU] => C:\windows\system32\huffyuv.dll [55296 2005-01-22] () [File not signed] HKLM\...\Drivers32: [VIDC.LAGS] => C:\windows\system32\lagarith.dll [148992 2011-12-08] () [File not signed] HKLM\...\Drivers32: [VIDC.XVID] => C:\windows\system32\xvidvfw.dll [310784 2019-12-28] () [File not signed] HKLM\...\Drivers32: [msacm.ac3acm] => C:\windows\system32\ac3acm.acm [180736 2012-07-21] (fccHandler) [File not signed] HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\SysWOW64\x264vfw.dll [3850240 2017-07-30] (x264vfw project) [File not signed] HKLM\...\Drivers32: [VIDC.HFYU] => C:\Windows\SysWOW64\huffyuv.dll [39936 2004-05-19] (Disappearing Inc.) [File not signed] HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\SysWOW64\lagarith.dll [216064 2011-12-08] () [File not signed] HKLM\...\Drivers32: [VIDC.XVID] => C:\Windows\SysWOW64\xvidvfw.dll [284160 2019-12-28] () [File not signed] HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\SysWOW64\ac3acm.acm [122880 2012-07-21] (fccHandler) [File not signed] HKLM\...\Drivers32: [msacm.lameacm] => C:\Windows\SysWOW64\lameACM.acm [473088 2015-02-26] (hxxp://www.mp3dev.org/) [File not signed] HKLM\...\Drivers32: [VIDC.FFDS] => C:\Windows\SysWOW64\ff_vfw.dll [112128 2015-10-25] () [File not signed] ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2022-04-11 11:13 - 2022-04-11 11:13 - 000160768 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\BRIDGECommon\4e12ea4b2f7cb4f9a7240a1e99f31942\BRIDGECommon.ni.dll 2022-04-10 14:48 - 2022-04-10 14:48 - 000125440 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\BridgeExtension\2aa319e6981eb4e74b026e428c565105\BridgeExtension.ni.dll 2022-04-10 14:49 - 2022-04-10 14:49 - 000395264 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\CleanStartController\e0ee64a9410fcbbfa5405839ed775541\CleanStartController.ni.dll 2022-04-10 14:49 - 2022-04-10 14:49 - 000145920 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Registratio4eabc192#\dbc8609c9992952ae1d75e9c6c439088\RegistrationUtilities.ni.dll 2022-04-10 14:48 - 2022-04-10 14:48 - 000136192 _____ (HP Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\CommonPortable\0aaeb86bc829bc531877985eee056616\CommonPortable.ni.dll 2022-04-10 00:34 - 2021-12-26 22:00 - 000093696 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll 2022-04-10 14:47 - 2022-04-10 14:47 - 002306560 _____ (Newtonsoft) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Newtonsoft.Json\ac644a39262c8a347e2fa74944e77bc1\Newtonsoft.Json.ni.dll ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Eldritch\Application Data:2e7adecd915fad7ede6cff9c6c6e4e6e [394] AlternateDataStreams: C:\Users\Eldritch\AppData\Roaming:2e7adecd915fad7ede6cff9c6c6e4e6e [394] ==================== Safe Mode (Whitelisted) ================== ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE HKU\S-1-5-21-1006872022-3032962147-1773234815-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE HKU\S-1-5-21-1006872022-3032962147-1773234815-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2017-09-28] (HP Inc. -> HP Inc.) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2017-09-28] (HP Inc. -> HP Inc.) ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2017-09-29 21:46 - 2022-04-20 03:36 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\windows\system32;C:\windows;C:\windows\System32\Wbem;C:\windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\ HKU\S-1-5-21-1006872022-3032962147-1773234815-1001\Control Panel\Desktop\\Wallpaper -> C:\windows\web\wallpaper\HP Backgrounds\backgroundDefault.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{5668F1EC-0CA3-4DFC-A3D2-AC47A1EB035F}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel(R) Wireless Connectivity Solutions -> ) FirewallRules: [{CED12F8E-4D1B-4769-954F-1E640656A1E6}] => (Allow) C:\Elsword\data\x2.exe (KOG Co., Ltd. -> ) FirewallRules: [{1B630BB6-070F-46D9-AAB4-5F68D849700D}] => (Allow) C:\Elsword\data\x2.exe (KOG Co., Ltd. -> ) FirewallRules: [{FA163615-A0F0-4EE6-87D3-094649AF5B56}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{F5574039-CA2C-42AA-82F0-D71994D4FB2A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{12C110E4-3D14-47FC-961E-C6CA63EDD960}] => (Allow) C:\Program Files (x86)\Microsoft Studios\Minecraft Education Edition\Minecraft.Windows.exe (Microsoft Corporation -> ) FirewallRules: [TCP Query User{908BF4CA-417E-4570-91E8-ECF5C4AB4CDD}C:\program files\java\jre1.8.0_321\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_321\bin\java.exe FirewallRules: [UDP Query User{36C96049-E149-4BCB-B4CC-D42AF54E9AC2}C:\program files\java\jre1.8.0_321\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_321\bin\java.exe ==================== Restore Points ========================= 11-04-2022 12:20:17 Windows Update 17-04-2022 01:31:42 Windows Update 20-04-2022 03:47:40 Windows Update ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (04/23/2022 11:47:35 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: usoclient.exe, version: 10.0.19041.1503, time stamp: 0x96524c58 Faulting module name: ucrtbase.dll, version: 10.0.19041.789, time stamp: 0x2bd748bf Exception code: 0xc0000409 Fault offset: 0x000000000007286e Faulting process id: 0x100c Faulting application start time: 0x01d856c4de56a206 Faulting application path: C:\WINDOWS\System32\usoclient.exe Faulting module path: C:\WINDOWS\System32\ucrtbase.dll Report Id: fe314e1c-dc3f-45cb-8bc7-3e15a7b7f665 Faulting package full name: Faulting package-relative application ID: Error: (04/23/2022 05:11:54 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: usoclient.exe, version: 10.0.19041.1503, time stamp: 0x96524c58 Faulting module name: ucrtbase.dll, version: 10.0.19041.789, time stamp: 0x2bd748bf Exception code: 0xc0000409 Fault offset: 0x000000000007286e Faulting process id: 0x22e0 Faulting application start time: 0x01d8568d972075e7 Faulting application path: C:\WINDOWS\System32\usoclient.exe Faulting module path: C:\WINDOWS\System32\ucrtbase.dll Report Id: 1973f9d1-2a79-477f-a9c5-b6758ff22e2a Faulting package full name: Faulting package-relative application ID: Error: (04/22/2022 07:55:42 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: usoclient.exe, version: 10.0.19041.1503, time stamp: 0x96524c58 Faulting module name: ucrtbase.dll, version: 10.0.19041.789, time stamp: 0x2bd748bf Exception code: 0xc0000409 Fault offset: 0x000000000007286e Faulting process id: 0x1fc Faulting application start time: 0x01d8563fe40f8741 Faulting application path: C:\WINDOWS\System32\usoclient.exe Faulting module path: C:\WINDOWS\System32\ucrtbase.dll Report Id: ca2552c8-8f82-4798-835e-bdd0001fa713 Faulting package full name: Faulting package-relative application ID: Error: (04/22/2022 01:13:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: usoclient.exe, version: 10.0.19041.1503, time stamp: 0x96524c58 Faulting module name: ucrtbase.dll, version: 10.0.19041.789, time stamp: 0x2bd748bf Exception code: 0xc0000409 Fault offset: 0x000000000007286e Faulting process id: 0xcc4 Faulting application start time: 0x01d85607a3c473a5 Faulting application path: C:\WINDOWS\System32\usoclient.exe Faulting module path: C:\WINDOWS\System32\ucrtbase.dll Report Id: 8122998e-1d43-432b-aef4-89f530c08af1 Faulting package full name: Faulting package-relative application ID: Error: (04/21/2022 11:03:00 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: usoclient.exe, version: 10.0.19041.1503, time stamp: 0x96524c58 Faulting module name: ucrtbase.dll, version: 10.0.19041.789, time stamp: 0x2bd748bf Exception code: 0xc0000409 Fault offset: 0x000000000007286e Faulting process id: 0x13d4 Faulting application start time: 0x01d85590e484d4ee Faulting application path: C:\WINDOWS\System32\usoclient.exe Faulting module path: C:\WINDOWS\System32\ucrtbase.dll Report Id: 5c45b746-44f9-4bc3-b73e-53741d06c166 Faulting package full name: Faulting package-relative application ID: Error: (04/21/2022 04:52:32 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: usoclient.exe, version: 10.0.19041.1503, time stamp: 0x96524c58 Faulting module name: ucrtbase.dll, version: 10.0.19041.789, time stamp: 0x2bd748bf Exception code: 0xc0000409 Fault offset: 0x000000000007286e Faulting process id: 0x59c Faulting application start time: 0x01d8555d20700f09 Faulting application path: C:\WINDOWS\System32\usoclient.exe Faulting module path: C:\WINDOWS\System32\ucrtbase.dll Report Id: 230eb053-1503-4110-a9ae-45a5380fa8a3 Faulting package full name: Faulting package-relative application ID: Error: (04/21/2022 04:47:35 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: dwm.exe, version: 10.0.19041.746, time stamp: 0x6be51595 Faulting module name: KERNELBASE.dll, version: 10.0.19041.1566, time stamp: 0x0833f2d4 Exception code: 0xc00001ad Fault offset: 0x000000000010b362 Faulting process id: 0xd34 Faulting application start time: 0x01d8555c12e9c654 Faulting application path: C:\WINDOWS\system32\dwm.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report Id: c6ff4b6a-6be9-402b-97f3-d4b2905bbe28 Faulting package full name: Faulting package-relative application ID: Error: (04/21/2022 04:44:53 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: dwm.exe, version: 10.0.19041.746, time stamp: 0x6be51595 Faulting module name: KERNELBASE.dll, version: 10.0.19041.1566, time stamp: 0x0833f2d4 Exception code: 0xc00001ad Fault offset: 0x000000000010b362 Faulting process id: 0x1ba8 Faulting application start time: 0x01d8555b64681580 Faulting application path: C:\WINDOWS\system32\dwm.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report Id: 44c2200e-eac8-4af5-8d02-b2047c7e84b2 Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (04/23/2022 05:14:18 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-1O0LBCKU) Description: The server {5F7F3F7B-1177-4D4B-B1DB-BC6F671B8F25} did not register with DCOM within the required timeout. Error: (04/23/2022 05:14:18 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-1O0LBCKU) Description: The server {5F7F3F7B-1177-4D4B-B1DB-BC6F671B8F25} did not register with DCOM within the required timeout. Error: (04/21/2022 05:10:14 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80240016: Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.363.716.0). Error: (04/21/2022 04:51:22 PM) (Source: volmgr) (EventID: 46) (User: ) Description: Crash dump initialization failed! Error: (04/21/2022 04:39:57 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect. Error: (04/21/2022 11:04:38 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading Error: (04/21/2022 11:04:38 AM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\Eldritch\AppData\Local\Temp\ehdrv.sys Error: (04/21/2022 11:04:38 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading Windows Defender: ================ Date: 2022-04-23 07:28:36 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2022-04-21 07:39:01 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2022-04-21 05:34:59 Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=PUA:Win32/Presenoker&threatid=242420&enterprise=0 Name: PUA:Win32/Presenoker Severity: Low Category: Potentially Unwanted Software Path: file:_C:\Users\Eldritch\Downloads\Utilities\JDownloaderSetup.exe Detection Origin: Local machine Detection Type: Concrete Detection Source: Real-Time Protection Process Name: C:\Users\Eldritch\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe Security intelligence Version: AV: 1.363.704.0, AS: 1.363.704.0, NIS: 1.363.704.0 Engine Version: AM: 1.1.19100.5, NIS: 1.1.19100.5 Date: 2022-04-19 09:28:08 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2022-04-19 08:03:24 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Event[0]: Date: 2022-04-23 17:14:29 Description: Microsoft Defender Antivirus has encountered an error trying to update security intelligence. New security intelligence Version: Previous security intelligence Version: 1.363.802.0 Update Source: Microsoft Update Server Security intelligence Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.19100.5 Error code: 0x80240022 Error description: The program can't check for definition updates. Date: 2022-04-23 17:14:29 Description: Microsoft Defender Antivirus has encountered an error trying to update security intelligence. New security intelligence Version: Previous security intelligence Version: 1.363.802.0 Update Source: Microsoft Update Server Security intelligence Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.19100.5 Error code: 0x80240022 Error description: The program can't check for definition updates. Date: 2022-04-20 04:00:06 Description: Microsoft Defender Antivirus has encountered an error trying to update security intelligence. New security intelligence Version: Previous security intelligence Version: 1.363.629.0 Update Source: Microsoft Update Server Security intelligence Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.19100.5 Error code: 0x80070102 Error description: The wait operation timed out. Date: 2022-04-20 04:00:06 Description: Microsoft Defender Antivirus has encountered an error trying to update security intelligence. New security intelligence Version: Previous security intelligence Version: 1.363.629.0 Update Source: Microsoft Update Server Security intelligence Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.19100.5 Error code: 0x80070102 Error description: The wait operation timed out. CodeIntegrity: =============== Date: 2022-04-23 17:33:59 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\ki126951.inf_amd64_94804e3918169543\igd10iumd64.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== BIOS: Insyde F.38 05/24/2017 Motherboard: HP 8259 Processor: Intel(R) Core(TM) i7-7700HQ CPU @ 2.80GHz Percentage of memory in use: 47% Total physical RAM: 8077.22 MB Available physical RAM: 4222.13 MB Total Virtual: 24077.22 MB Available Virtual: 19220.17 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:917.46 GB) (Free:720.68 GB) NTFS Drive d: (RECOVERY) (Fixed) (Total:12.82 GB) (Free:1.55 GB) NTFS ==>[system with boot components (obtained from drive)] \\?\Volume{b9082327-8c3b-4f6d-b48d-f0ffba1463d2}\ () (Fixed) (Total:0.96 GB) (Free:0.4 GB) NTFS \\?\Volume{843d68c9-0eaa-4603-9b8a-056f2f57dc16}\ () (Fixed) (Total:0.25 GB) (Free:0.18 GB) FAT32 ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 27957957) Partition: GPT. ==================== End of Addition.txt =======================