Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

igdkmd64.sys (times 2) incompatible drivers prevent Memory Integrity from ON


  • This topic is locked This topic is locked
19 replies to this topic

#1 Delusionz

Delusionz

  •  Avatar image
  • Members
  • 195 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Texas
  • Local time:12:32 AM

Posted 14 February 2024 - 01:32 AM

Incompatible drivers:

 

Resolving incompatibilities with these drivers will enable you to turn on Memory Integrity

 

"igdkmd64.sys"

Intel Corporation

 

"igdkmd64.sys"

Intel Corporation

 

....... This system is fairly new to me and was only operating with Legacy BIOS and could not find a bootable drive if a UEFI mode, or UEFI with secure boot was attempted. This turns out to be because whoever upgraded the machine from Windows 8 or 8.1 to Windows 10, installed from Legacy mode, therefore when booting with UEFI the system found no device to boot, as the OS a MBR Legacy OS .... A few days ago I fixed the issue, and now I use UEFI bios and clean installed a new Windows 10 Pro O/S. 

 

My goal in accomplishing that was to be able to utilize at LEAST Secure Boot, Core Isolation/Memory Integrity to improve device security as best I could since my processor won't be going to Windows 11 and neither with my TPM 1.2. But hey, I'm happy with that!

 

I felt very vulnerable and am now much happier, I guess, but..... after my conversion, these 2 Intel instances are holding me back now and I don't know how to resolve it yet.

 

Then I began loading some of my favorite tools and Security Task Manager ranked 6 out of the top 7 security risks as Intel graphics type items (that we all know and use) .....and a little peek inside the Properties shows Expired Certificates on all 6 of them from 2018 and 2019. That's a little unacceptable to me that Intel's stuff is outdated...

 

I find this to be completely unacceptable coming from Intel as the elevated provider that they are, to be wearing outdated certificates LOL.....

 

and then it was only a short HOP from those 6 items ----  back over to my Intel drivers at Core Isolation where Memory Integrity seems to also think Intel needs to step up their game if they want to play with Windows........ LOL

 

incompatible drivers.....(which  i have assumed to be graphics related as well.... ? i haven't ran these down to fix them yet....

 

So who is responsible for updating the certificates for such items? Am I, the average Jane Windows user supposed to learn how to manage my own certificates? Or is someone else falling asleep at the wheel?

 

 

I find this to be completely unacceptable coming from Intel as the elevated provider that they are, to be wearing outdated certificates LOL..... and then it was only a short HOP from those 6 items back to my 



BC AdBot (Login to Remove)

 


#2 Porthos

Porthos

  •  Avatar image
  • Members
  • 1,093 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:32 AM

Posted 14 February 2024 - 02:41 AM

 

whoever upgraded the machine from Windows 8 or 8.1

Assuming the system came with 8 or 8.1 it is 10 years old. How long should a hardware manufacturer be required to update drivers?

 

I suggest you do a clean install of 10 with secure boot and UEFI intact. At least you would have that layer of security.

 

Don't forget 10's end of updates in Oct 2025.



#3 Pkshadow

Pkshadow

  •  Avatar image
  • BC Advisor
  • 12,972 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:On the Brow of the Hill, West Coast, Canada
  • Local time:10:32 PM

Posted 14 February 2024 - 03:06 AM

The 1st thing you do after installing Windows is install your Chipset Drivers and then SATA Drivers from your Motherboard Support Page or your Branded System Support Page.   If you have not done this please do so.

 

Is this what you call a Security Task Manager : https://pcmanager.microsoft.com/en-us if not we have no idea what your talking about.

 

You say 2 drivers but what you show is the same driver 2x's.

Where did you get the 2 drivers as you do not tell us.


" mosquitoes really wake up everyday and choose violence "   — dalia (@_dalia7)
www.cnn.com/2020/07/23/health/mosquitoes-attraction-humans-future-wellness-scn/index.html
 

I-7 ASUS ROG Rampage II Extreme  / ASUS TUF Gaming F17 / I-7 4770K ASUS ROG Maximus VI Extreme


#4 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:32 AM

Posted 14 February 2024 - 11:17 AM

Download and install Speccy - https://www.ccleaner.com/speccy

Run it, and then go to File and Publish Snapshot. Post the resulting link in your next reply

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#5 Delusionz

Delusionz
  • Topic Starter

  •  Avatar image
  • Members
  • 195 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Texas
  • Local time:12:32 AM

Posted 04 April 2024 - 12:48 PM

 

 

whoever upgraded the machine from Windows 8 or 8.1

Assuming the system came with 8 or 8.1 it is 10 years old. How long should a hardware manufacturer be required to update drivers?

 

I suggest you do a clean install of 10 with secure boot and UEFI intact. At least you would have that layer of security.

 

Don't forget 10's end of updates in Oct 2025.

 

 

I managed to get the BIOS issues fixed, with a clean install and it now works in UEFI mode with Secure Boot although I have a couple of bugs to work out still.

 

Dell OptiPlex 9020 SFF

Windows 10 Pro

Version 22H2 (OS Build 19045. 4170)

 

The driver that is preventing Memory Integrity happens to be a Microsoft Compatibility Publisher as the Digital Signer (with an expired Certificate) for my Intel® HD Graphics 4600 which Dell also provided an updated driver for to address security concerns, but Windows assigned the very same igdkmd64.sys driver for the newer Intel® HD Graphics for Windows, also with an expired Certificate. 

 

See next post for more info, if you want.

 



#6 Delusionz

Delusionz
  • Topic Starter

  •  Avatar image
  • Members
  • 195 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Texas
  • Local time:12:32 AM

Posted 04 April 2024 - 01:18 PM

The 1st thing you do after installing Windows is install your Chipset Drivers and then SATA Drivers from your Motherboard Support Page or your Branded System Support Page.   If you have not done this please do so.

 

Is this what you call a Security Task Manager : https://pcmanager.microsoft.com/en-us if not we have no idea what your talking about.

 

You say 2 drivers but what you show is the same driver 2x's.

Where did you get the 2 drivers as you do not tell us.

 

 

Greetings PKshadow! 

 

Yes, after my Clean Install, I did, as always, immediately go to Dell Support, and I even allowed the Support Assist app from Dell check for and Download and Install and the "necessary drivers" for me. The system ran pretty well for a little while and I had no reason to go looking for trouble in Event Viewer, or elsewhere. 

 

My granddaughter plays Roblox, and she absolutely loves The Sims 4, but when her laptop crashed, she had not been able to play, so I downloaded EA App and The Sims 4, but on my computer, the game was glitching. The screen was "tearing" and eventually I got around to double checking the specs and discovered that my Dedicated VRam was just a few MB short of their recommended requirements. That led me back to Dell to see if I could dedicate more as needed. While there, I saw that there was an updated driver for my graphics card.... and downloaded it. Her Sims 4 play was actually fixable within the game itself though, by just tweaking some of the options to High Performance.......

 

So then I moved back to my initial problem, which was to resolve the incompatible driver(s) for Memory Integrity, provided by Dell website. Windows, being ACPI Compliant, changes the Mfgr drivers at will, and mostly forces me to use their Windows Drivers ending in .sys and i have no choice about it.

 

I have also seen some forums mentioned completely deleting these and other drivers that were preventing them from turning on Memory Integrity, and their system continued to function just fine, but I'm not willing to delete drivers just yet.

 

As for Security Task Manager, that's not the one I use. This one is partnered somehow with Windows and i LOVE it!

 

Security Task Manager - Windows 11, 10, 7 process viewer (neuber.com)

 

After not finding a resolution to those drivers, I again did a Clean Install and wiped all my files, etc.... I now have so many errors in Event Viewer that I don't know where to start resolving them... From Critical, to Warnings, to Errors and mentions of corrupted camera files...... yet DISM and sfc show no corruption. So here I am back at Bleeping and hoping to have my old friend JStgRvr to do some FARBAR fixes and then some system cleanup.

 

My Speccy posted in the next post.

 

Good to see you :)

JSntgRvr

#7 Delusionz

Delusionz
  • Topic Starter

  •  Avatar image
  • Members
  • 195 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Texas
  • Local time:12:32 AM

Posted 04 April 2024 - 01:21 PM

Download and install Speccy - https://www.ccleaner.com/speccy

Run it, and then go to File and Publish Snapshot. Post the resulting link in your next reply

 

 

Sorry for the delay. Here is my Speccy

 

http://speccy.piriform.com/results/Ms2qKHtjnMROcMCqRARtMhO



#8 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:32 AM

Posted 04 April 2024 - 01:25 PM

Try these drivers

https://www.intel.com/content/www/us/en/download/18388/intel-graphics-driver-for-windows-10-15-40-4th-gen.html

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#9 Delusionz

Delusionz
  • Topic Starter

  •  Avatar image
  • Members
  • 195 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Texas
  • Local time:12:32 AM

Posted 04 April 2024 - 02:34 PM

No go.... 

 

 

 

Attached File  Screenshot 2024-04-04 143140.png   9.46KB   0 downloads



#10 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:32 AM

Posted 04 April 2024 - 02:50 PM

Can you provide your service tag number?

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#11 Delusionz

Delusionz
  • Topic Starter

  •  Avatar image
  • Members
  • 195 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Texas
  • Local time:12:32 AM

Posted 05 April 2024 - 09:13 AM

Service Tag: FM9BS52

 

Prior to my changes to UEFI and the Clean Install of Windows 10 Pro, I would have said that Event Viewer was mostly "nice" and that the events were minor and fixable, 

 

Today the events are definitely FAR more numerous and a lot of them are fixable, and some of them sound rather ominous, ranging from Errors and Warning to several Criticals.


Edited by Delusionz, 05 April 2024 - 10:33 AM.


#12 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:32 AM

Posted 05 April 2024 - 08:11 PM

https://www.dell.com/support/home/en-us/product-support/product/optiplex-9020-desktop/drivers

https://dl.dell.com/FOLDER05384356M/5/Intel-HD-4000-and-5000-Series-Graphics-Driver_4KV26_WIN_20.19.15.5063_A08_03.EXE

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#13 Delusionz

Delusionz
  • Topic Starter

  •  Avatar image
  • Members
  • 195 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Texas
  • Local time:12:32 AM

Posted 06 April 2024 - 08:13 AM

Been there, done that ..... 3 times. It uses the exact same driver as the Intel HD Graphics 4600 that was originally installed and its oem4. files


Edited by Delusionz, 06 April 2024 - 08:15 AM.


#14 Pkshadow

Pkshadow

  •  Avatar image
  • BC Advisor
  • 12,972 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:On the Brow of the Hill, West Coast, Canada
  • Local time:10:32 PM

Posted 06 April 2024 - 06:37 PM

Hi, Download Minitoolbox from the below link :
http://www.bleepingcomputer.com/download/minitoolbox/
  Run the tool and only select the following tick boxes.
    -List last 10 Event viewer errors
    -List installed programs
    -List devices
    -List users, partition and memory size
Now click "Go" and Copy/Paste and post the output text in your next reply


" mosquitoes really wake up everyday and choose violence "   — dalia (@_dalia7)
www.cnn.com/2020/07/23/health/mosquitoes-attraction-humans-future-wellness-scn/index.html
 

I-7 ASUS ROG Rampage II Extreme  / ASUS TUF Gaming F17 / I-7 4770K ASUS ROG Maximus VI Extreme


#15 Delusionz

Delusionz
  • Topic Starter

  •  Avatar image
  • Members
  • 195 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Texas
  • Local time:12:32 AM

Posted 08 April 2024 - 01:52 PM

MiniToolBox by Farbar  Version: 13-05-2022

Ran by nc2un (administrator) on 08-04-2024 at 13:48:30

Running from "C:\Users\nc2un\Downloads"

Microsoft Windows 10 Pro  (X64)

Model: OptiPlex 9020 Manufacturer: Dell Inc.

Boot Mode: Normal

***************************************************************************

 

========================= Event log errors: ===============================

 

Application errors:

==================

Error: (04/06/2024 03:22:40 AM) (Source: MsiInstaller) (EventID: 11920) (User: BLUEZ9020)

Description: Product: iTunes -- Error 1920. Service 'Apple Mobile Device' (Apple Mobile Device) failed to start.  Verify that you have sufficient privileges to start system services.

 

Error: (04/06/2024 03:21:51 AM) (Source: MsiInstaller) (EventID: 11920) (User: BLUEZ9020)

Description: Product: iTunes -- Error 1920. Service 'Apple Mobile Device' (Apple Mobile Device) failed to start.  Verify that you have sufficient privileges to start system services.

 

Error: (04/06/2024 03:18:38 AM) (Source: MsiInstaller) (EventID: 10005) (User: BLUEZ9020)

Description: Product: iTunes -- A later version of iTunes is already installed on this computer.

 

Error: (04/05/2024 11:51:18 AM) (Source: SideBySide) (EventID: 78) (User: )

Description: Activation context generation failed for "C:\Users\nc2un\Downloads\autoruns.exe".Error in manifest or policy file "" on line .

A component version required by the application conflicts with another component version already active.

Conflicting components are:.

Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db.manifest.

Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5.manifest.

 

Error: (04/05/2024 11:46:54 AM) (Source: SideBySide) (EventID: 78) (User: )

Description: Activation context generation failed for "C:\Users\nc2un\Downloads\autoruns.exe".Error in manifest or policy file "" on line .

A component version required by the application conflicts with another component version already active.

Conflicting components are:.

Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db.manifest.

Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5.manifest.

 

Error: (04/03/2024 04:49:18 AM) (Source: VSS) (EventID: 8194) (User: )

Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.

This is often caused by incorrect security settings in either the writer or requestor process.

Operation:

   Gathering Writer Data

Context:

   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}

   Writer Name: System Writer

   Writer Instance ID: {4c6c9ee0-0187-4538-908d-7c5dfbfb21b3}

 

Error: (04/03/2024 04:18:30 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: SupportAssistAgent.exe, version: 3.14.2.45116, time stamp: 0x64e81669

Faulting module name: coreclr.dll, version: 6.0.2824.12007, time stamp: 0x65d4fbd9

Exception code: 0xc0000005

Fault offset: 0x00000000000ab096

Faulting process id: 0x75c

Faulting application start time: 0x01da85a3aeed3033

Faulting application path: C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe

Faulting module path: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.28\coreclr.dll

Report Id: f5690f63-c38f-4fa6-8249-77177220b122

Faulting package full name: 

Faulting package-relative application ID:

 

Error: (04/03/2024 04:18:30 AM) (Source: .NET Runtime) (EventID: 1023) (User: )

Description: Application: SupportAssistAgent.exe

CoreCLR Version: 6.0.2824.12007

.NET Version: 6.0.28

Description: The process was terminated due to an internal error in the .NET Runtime at IP 00007FF92813B096 (00007FF928090000) with exit code 80131506.

 

Error: (04/03/2024 03:10:36 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: Dell.TechHub.Diagnostics.SubAgent.exe, version: 1.2.1.3372, time stamp: 0x63ed8286

Faulting module name: ucrtbase.dll, version: 10.0.19041.3636, time stamp: 0x81cf5d89

Exception code: 0xc0000409

Fault offset: 0x000000000007286e

Faulting process id: 0x20f8

Faulting application start time: 0x01da859e24add041

Faulting application path: C:\Program Files\Dell\DTP\DiagnosticsSubAgent\Dell.TechHub.Diagnostics.SubAgent.exe

Faulting module path: C:\WINDOWS\System32\ucrtbase.dll

Report Id: a609db45-bf43-4d89-be14-773d68681c62

Faulting package full name: 

Faulting package-relative application ID:

 

Error: (04/03/2024 01:36:46 AM) (Source: Application Hang) (EventID: 1002) (User: )

Description: The program PhoneExperienceHost.exe version 1.24022.87.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 320

Start Time: 01da858cba64cc1d

Termination Time: 4294967295

Application Path: C:\Program Files\WindowsApps\microsoft.yourphone_1.24022.87.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe

Report Id: 13137256-ca39-4c63-8208-9c8f847f528f

Faulting package full name: Microsoft.YourPhone_1.24022.87.0_x64__8wekyb3d8bbwe

Faulting package-relative application ID: App

Hang type: Quiesce

 

 

System errors:

=============

Error: (04/06/2024 07:06:13 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)

Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NBLGGGZM6WM-ROBLOXCORPORATION.ROBLOX.

 

Error: (04/06/2024 09:59:18 AM) (Source: DCOM) (EventID: 10010) (User: BLUEZ9020)

Description: Event-ID 10010

 

Error: (04/05/2024 11:02:43 PM) (Source: DCOM) (EventID: 10005) (User: BLUEZ9020)

Description: Event-ID 10005

 

Error: (04/05/2024 11:02:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The GameDVR and Broadcast User Service_ec4b45 service failed to start due to the following error: 

%%1053 = The service did not respond to the start or control request in a timely fashion.

 

Error: (04/05/2024 11:02:43 PM) (Source: Service Control Manager) (EventID: 7009) (User: )

Description: A timeout was reached (30000 milliseconds) while waiting for the GameDVR and Broadcast User Service_ec4b45 service to connect.

 

Error: (04/05/2024 11:02:42 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)

Description: Event-ID 10010

 

Error: (04/05/2024 10:34:55 PM) (Source: DCOM) (EventID: 10010) (User: BLUEZ9020)

Description: Event-ID 10010

 

Error: (04/05/2024 10:31:27 PM) (Source: DCOM) (EventID: 10010) (User: BLUEZ9020)

Description: Event-ID 10010

 

Error: (04/05/2024 10:30:56 PM) (Source: DCOM) (EventID: 10010) (User: BLUEZ9020)

Description: Event-ID 10010

 

Error: (04/05/2024 10:13:45 PM) (Source: DCOM) (EventID: 10010) (User: BLUEZ9020)

Description: Event-ID 10010

 

 

Windows Defender:

================

Date: 2024-04-07 12:43:16

Description: 

Microsoft Defender Antivirus scan has been stopped before completion.

Scan Type: Antimalware

Scan Parameters: Quick Scan

 

Date: 2024-04-06 08:31:42

Description: 

Microsoft Defender Antivirus scan has been stopped before completion.

Scan Type: Antimalware

Scan Parameters: Quick Scan

 

Date: 2024-04-05 11:49:41

Description: 

Microsoft Defender Antivirus has detected malware or other potentially unwanted software.

For more information please see the following:

https://go.microsoft.com/fwlink/?linkid=37020&name=PUABundler:Win32/DisplayDriverUninstaller&threatid=312040&enterprise=0

Name: PUABundler:Win32/DisplayDriverUninstaller

Severity: Low

Category: Potentially Unwanted Software

Path: file:_C:\Users\nc2un\Downloads\DDU-v17.0.6.6.zip; webfile:_C:\Users\nc2un\Downloads\DDU-v17.0.6.6.zip|https://download.bleepingcomputer.com/dl/34f2593a0bead9d6c93944035b8365dc/66101eb9/windows/utilities/driver-utilities/d/display-driver-uninstaller/DDU-v17.0.6.6.zip|pid:2624,ProcessStart:133568061128103712

Detection Origin: Internet

Detection Type: FastPath

Detection Source: Downloads and attachments

Process Name: C:\Windows\explorer.exe

Security intelligence Version: AV: 1.409.55.0, AS: 1.409.55.0, NIS: 1.409.55.0

Engine Version: AM: 1.1.24030.4, NIS: 1.1.24030.4

 

Date: 2024-04-05 10:55:14

Description: 

Microsoft Defender Antivirus has detected malware or other potentially unwanted software.

For more information please see the following:

https://go.microsoft.com/fwlink/?linkid=37020&name=PUABundler:Win32/DisplayDriverUninstaller&threatid=312040&enterprise=0

Name: PUABundler:Win32/DisplayDriverUninstaller

Severity: Low

Category: Potentially Unwanted Software

Path: file:_C:\Users\nc2un\Downloads\DDU-v17.0.6.6.zip; webfile:_C:\Users\nc2un\Downloads\DDU-v17.0.6.6.zip|https://download.bleepingcomputer.com/dl/34f2593a0bead9d6c93944035b8365dc/66101eb9/windows/utilities/driver-utilities/d/display-driver-uninstaller/DDU-v17.0.6.6.zip|pid:2624,ProcessStart:133568061128103712

Detection Origin: Internet

Detection Type: FastPath

Detection Source: Downloads and attachments

Process Name: Unknown

Security intelligence Version: AV: 1.409.55.0, AS: 1.409.55.0, NIS: 1.409.55.0

Engine Version: AM: 1.1.24030.4, NIS: 1.1.24030.4

 

Date: 2024-04-05 08:47:16

Description: 

Microsoft Defender Antivirus scan has been stopped before completion.

Scan Type: Antimalware

Scan Parameters: Quick Scan



CodeIntegrity Errors:

====================

Date: 2024-04-08 13:47:04

Description: 

Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

 

 

=========================== Installed Programs ============================

Apple Application Support (32-bit) (HKLM-x32\...\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.)

Apple Mobile Device Support (HKLM\...\{FA3D0F2D-BA1C-4462-B6B3-3048CFF464C7}) (Version: 17.0.0.28 - Apple Inc.)

Apple Software Update (HKLM-x32\...\{B292D163-23D2-4523-A699-1ABEC1875609}) (Version: 2.7.0.3 - Apple Inc.)

Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)

Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM\...\{0B884FA0-BBEE-4573-B696-426AA39ED913}) (Version: 5.5.7.18773 - Dell Inc.) Hidden

Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM-x32\...\{2600102a-dac2-4b2a-8257-df60c573fc29}) (Version: 5.5.7.18773 - Dell Inc.)

EA app (HKLM\...\{C2622085-ABD2-49E5-8AB9-D3D6A642C091}) (Version: 13.166.0.5679 - Electronic Arts) Hidden

EA app (HKLM-x32\...\{df861f89-e998-47ba-bfff-9354af4d3751}) (Version: 13.166.0.5679 - Electronic Arts)

GlassWire 2.1 (remove only) (HKLM-x32\...\GlassWire 2.1) (Version: 2.1.3167 - SecureMix LLC)

Google Chrome (HKLM-x32\...\Google Chrome) (Version: 123.0.6312.106 - Google LLC)

HWiNFO64 (HKLM\...\HWiNFO64_is1) (Version: 8.00 - Martin Malik, REALiX s.r.o.)

Intel® Chipset Device Software (HKLM-x32\...\{60c073df-e736-4210-9c3a-5fc2b651cef3}) (Version: 10.1.1.7 - Intel® Corporation) Hidden

Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1035 - Intel Corporation)

iTunes (HKLM\...\{7AE35063-BF3A-45AD-9F80-29777979DD15}) (Version: 12.13.1.3 - Apple Inc.)

Malwarebytes version 4.6.11.320 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.11.320 - Malwarebytes)

Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Overwolf (HKLM-x32\...\Overwolf) (Version: 0.243.1.1 - Overwolf Ltd.)

Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6086 - Realtek Semiconductor Corp.)

Revo Uninstaller Pro 5.2.6 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 5.2.6 - VS Revo Group, Ltd.)

Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)

The Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.105.345.1020 - Electronic Arts Inc.)

Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{B9A7A138-BFD5-4C73-A269-F78CCA28150E}) (Version: 8.94.0.0 - Microsoft Corporation)

 

Packages:

=========

HEVC Video Extensions -> C:\Program Files\WindowsApps\Microsoft.HEVCVideoExtensions_2.0.61933.0_x64__8wekyb3d8bbwe [2024-04-03] (Microsoft Corporation)

iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12131.3.2010.0_x64__nzyj5cx40ttqa [2024-04-06] (Apple Inc.) [Startup Task]

Microsoft Copilot -> C:\Program Files\WindowsApps\microsoft.windows.ai.copilot.provider_1.0.3.0_neutral__8wekyb3d8bbwe [2024-03-31] (ms-resource:PublisherDisplayName)

Microsoft Defender -> C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2403.21001.0_x64__8wekyb3d8bbwe [2024-04-03] (Microsoft Corporation) [Startup Task]

Prime Video for Windows -> C:\Program Files\WindowsApps\AmazonVideo.PrimeVideo_1.0.153.0_x64__pwbj9vvecjh7j [2024-03-29] (Amazon Development Centre (London) Ltd)

WindowsAppRuntime.1.1 -> C:\Program Files\WindowsApps\microsoft.windowsappruntime.1.1_1005.616.1651.0_x64__8wekyb3d8bbwe [2024-03-29] (Microsoft Corporation)

WindowsAppRuntime.1.1 -> C:\Program Files\WindowsApps\microsoft.windowsappruntime.1.1_1005.616.1651.0_x86__8wekyb3d8bbwe [2024-03-29] (Microsoft Corporation)

WindowsAppRuntime.1.3 -> C:\Program Files\WindowsApps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x64__8wekyb3d8bbwe [2024-03-29] (Microsoft Corporation)

WindowsAppRuntime.1.3 -> C:\Program Files\WindowsApps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe [2024-03-29] (Microsoft Corporation)

WindowsAppRuntime.1.4 -> C:\Program Files\WindowsApps\microsoft.windowsappruntime.1.4_4000.1136.2333.0_x64__8wekyb3d8bbwe [2024-03-29] (Microsoft Corporation)

WindowsAppRuntime.1.4 -> C:\Program Files\WindowsApps\microsoft.windowsappruntime.1.4_4000.1136.2333.0_x86__8wekyb3d8bbwe [2024-03-29] (Microsoft Corporation)

 

========================= Devices: ================================

 

 

========================= Memory info: ===================================

Percentage of memory in use: 31%

Total physical RAM: 16292.2 MB

Available physical RAM: 11079.19 MB

Total Virtual: 18596.2 MB

Available Virtual: 12463.16 MB

 

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:237.83 GB) (Free:98.24 GB) NTFS

 

========================= Users: ========================================

 

User accounts for \\BLUEZ9020

 

Administrator            DefaultAccount           Guest                    

Jade1                    keyer_z86jbid            nc2un                    

WDAGUtilityAccount       

 

 

**** End of log ****


Edited by hamluis, 08 April 2024 - 09:23 PM.





2 user(s) are reading this topic

0 members, 2 guests, 0 anonymous users