MiniToolBox by Farbar Version: 13-05-2022
Ran by John Salamone (administrator) on 28-02-2024 at 15:14:52
Running from "C:\Users\John Salamone\Desktop"
Microsoft Windows 11 Home (X64)
Model: 82KU Manufacturer: LENOVO
Boot Mode: Normal
***************************************************************************
========================= Flush DNS: ===================================
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========================= IE Proxy Settings: ==============================
Proxy is not enabled.
No Proxy Server is set.
"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= FF Proxy Settings: ==============================
"Reset FF Proxy Settings": Firefox Proxy settings were reset.
========================= Hosts content: =================================
========================= IP Configuration: ================================
Qualcomm Atheros QCA61x4A Wireless Network Adapter = Wi-Fi (Connected)
Realtek USB GbE Family Controller = Ethernet (Connected)
VirtualBox Host-Only Ethernet Adapter = Ethernet 3 (Connected)
ExpressVPN TAP Adapter = Ethernet 2 (Media disconnected)
ExpressVPN TUN Driver = Local Area Connection (Media disconnected)
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
reset
set global
set interface interface="Ethernet (Kernel Debugger)" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Bluetooth Network Connection" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Wi-Fi" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 9" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 10" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet 2" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet 3" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set subinterface interface=ult subinterface=ethernet_32774 mtu=1500
set subinterface interface=ult subinterface=iftype53_32768 mtu=1350
add address name="Ethernet 3" address=192.168.56.1 mask=255.255.255.0
popd
# End of IPv4 configuration
Windows IP Configuration
Host Name . . . . . . . . . . . . : JSS
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : fios-router.home
Unknown adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : ExpressVPN TUN Driver
Physical Address. . . . . . . . . :
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Ethernet adapter Ethernet:
Connection-specific DNS Suffix . : fios-router.home
Description . . . . . . . . . . . : Realtek USB GbE Family Controller
Physical Address. . . . . . . . . : 80-3F-5D-05-71-FA
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::4b4d:941c:2dbf:78e6%8(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.1.157(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Wednesday, February 28, 2024 12:50:03 PM
Lease Expires . . . . . . . . . . : Thursday, February 29, 2024 12:50:04 PM
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DHCPv6 IAID . . . . . . . . . . . : 142622557
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-2D-61-6B-CB-80-3F-5D-05-71-FA
DNS Servers . . . . . . . . . . . : 192.168.1.1
NetBIOS over Tcpip. . . . . . . . : Enabled
Connection-specific DNS Suffix Search List :
fios-router.home
Ethernet adapter Ethernet 2:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : ExpressVPN TAP Adapter
Physical Address. . . . . . . . . : 00-FF-15-00-69-40
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Ethernet adapter Ethernet 3:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : VirtualBox Host-Only Ethernet Adapter
Physical Address. . . . . . . . . : 0A-00-27-00-00-0A
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::4be0:e443:f251:f7c2%10(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.56.1(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DHCPv6 IAID . . . . . . . . . . . : 369754151
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-2D-61-6B-CB-80-3F-5D-05-71-FA
NetBIOS over Tcpip. . . . . . . . : Enabled
Wireless LAN adapter Local Area Connection* 9:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
Physical Address. . . . . . . . . : 76-4C-A1-9C-18-D1
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Wireless LAN adapter Local Area Connection* 10:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter #2
Physical Address. . . . . . . . . : 86-4C-A1-9C-18-D1
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Wireless LAN adapter Wi-Fi:
Connection-specific DNS Suffix . : fios-router.home
Description . . . . . . . . . . . : Qualcomm Atheros QCA61x4A Wireless Network Adapter
Physical Address. . . . . . . . . : 74-4C-A1-9C-18-D1
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::204:a949:d66a:12%20(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.1.247(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Wednesday, February 28, 2024 12:10:22 PM
Lease Expires . . . . . . . . . . : Thursday, February 29, 2024 2:52:08 PM
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DHCPv6 IAID . . . . . . . . . . . : 326388897
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-2D-61-6B-CB-80-3F-5D-05-71-FA
DNS Servers . . . . . . . . . . . : 192.168.1.1
NetBIOS over Tcpip. . . . . . . . : Enabled
Connection-specific DNS Suffix Search List :
fios-router.home
Server: Fios_Quantum_Gateway.fios-router.home
Address: 192.168.1.1
Name: google.com
Addresses: 2607:f8b0:4006:80e::200e
142.250.81.238
Ping request could not find host google.com. Please check the name and try again.
Server: Fios_Quantum_Gateway.fios-router.home
Address: 192.168.1.1
Name: yahoo.com
Addresses: 2001:4998:24:120d::1:0
2001:4998:124:1507::f000
2001:4998:124:1507::f001
2001:4998:44:3507::8001
2001:4998:44:3507::8000
2001:4998:24:120d::1:1
74.6.231.21
98.137.11.163
98.137.11.164
74.6.143.25
74.6.143.26
74.6.231.20
Ping request could not find host yahoo.com. Please check the name and try again.
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
21...........................ExpressVPN TUN Driver
8...80 3f 5d 05 71 fa ......Realtek USB GbE Family Controller
4...00 ff 15 00 69 40 ......ExpressVPN TAP Adapter
10...0a 00 27 00 00 0a ......VirtualBox Host-Only Ethernet Adapter
12...76 4c a1 9c 18 d1 ......Microsoft Wi-Fi Direct Virtual Adapter
16...86 4c a1 9c 18 d1 ......Microsoft Wi-Fi Direct Virtual Adapter #2
20...74 4c a1 9c 18 d1 ......Qualcomm Atheros QCA61x4A Wireless Network Adapter
1...........................Software Loopback Interface 1
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.247 35
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.157 25
127.0.0.0 255.0.0.0 On-link 127.0.0.1 331
127.0.0.1 255.255.255.255 On-link 127.0.0.1 331
127.255.255.255 255.255.255.255 On-link 127.0.0.1 331
192.168.1.0 255.255.255.0 On-link 192.168.1.247 291
192.168.1.0 255.255.255.0 On-link 192.168.1.157 281
192.168.1.157 255.255.255.255 On-link 192.168.1.157 281
192.168.1.247 255.255.255.255 On-link 192.168.1.247 291
192.168.1.255 255.255.255.255 On-link 192.168.1.247 291
192.168.1.255 255.255.255.255 On-link 192.168.1.157 281
192.168.56.0 255.255.255.0 On-link 192.168.56.1 281
192.168.56.1 255.255.255.255 On-link 192.168.56.1 281
192.168.56.255 255.255.255.255 On-link 192.168.56.1 281
224.0.0.0 240.0.0.0 On-link 127.0.0.1 331
224.0.0.0 240.0.0.0 On-link 192.168.56.1 281
224.0.0.0 240.0.0.0 On-link 192.168.1.247 291
224.0.0.0 240.0.0.0 On-link 192.168.1.157 281
255.255.255.255 255.255.255.255 On-link 127.0.0.1 331
255.255.255.255 255.255.255.255 On-link 192.168.56.1 281
255.255.255.255 255.255.255.255 On-link 192.168.1.247 291
255.255.255.255 255.255.255.255 On-link 192.168.1.157 281
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 331 ::1/128 On-link
10 281 fe80::/64 On-link
20 291 fe80::/64 On-link
8 281 fe80::/64 On-link
20 291 fe80::204:a949:d66a:12/128
On-link
8 281 fe80::4b4d:941c:2dbf:78e6/128
On-link
10 281 fe80::4be0:e443:f251:f7c2/128
On-link
1 331 ff00::/8 On-link
10 281 ff00::/8 On-link
20 291 ff00::/8 On-link
8 281 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================
Catalog5 01 C:\Windows\SysWOW64\napinsp.dll [68696] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\pnrpnsp.dll [71680] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [71680] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\winrnr.dll [45496] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\wshbth.dll [54272] (Microsoft Corporation)
Catalog5 07 C:\Windows\SysWOW64\nlansp_c.dll [82432] (Microsoft Corporation)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog9 12 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog9 13 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
Catalog9 14 C:\Windows\SysWOW64\mswsock.dll [321408] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\napinsp.dll [104712] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\pnrpnsp.dll [110592] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [110592] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\winrnr.dll [79896] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\wshbth.dll [86016] (Microsoft Corporation)
x64-Catalog5 07 C:\Windows\System32\nlansp_c.dll [135168] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog9 12 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog9 13 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
x64-Catalog9 14 C:\Windows\System32\mswsock.dll [439520] (Microsoft Corporation)
========================= Event log errors: ===============================
Application errors:
==================
Error: (02/28/2024 10:32:39 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (02/28/2024 10:32:39 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (02/27/2024 11:59:45 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (02/27/2024 11:59:45 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (02/27/2024 11:59:10 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x8007045b, A system shutdown is in progress.
.
Error: (02/27/2024 11:59:10 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]
Error: (02/27/2024 11:35:26 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (02/27/2024 11:35:26 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (02/27/2024 09:33:08 AM) (Source: Application Error) (EventID: 1000) (User: JSS)
Description: Faulting application name: MEmu-setup-abroad-sdk-mv.exe, version: 9.0.0.0, time stamp: 0x652375fd
Faulting module name: MEmu-setup-abroad-sdk-mv.exe, version: 9.0.0.0, time stamp: 0x652375fd
Exception code: 0xc000041d
Fault offset: 0x00177f8f
Faulting process id: 0x0xb70
Faulting application start time: 0x0x1da698995f324a0
Faulting application path: C:\Users\John Salamone\Desktop\MEmu-setup-abroad-sdk-mv.exe
Faulting module path: C:\Users\John Salamone\Desktop\MEmu-setup-abroad-sdk-mv.exe
Report Id: a85299ca-bd96-4082-8e09-7c491289483a
Faulting package full name:
Faulting package-relative application ID:
Error: (02/27/2024 09:33:05 AM) (Source: Application Error) (EventID: 1000) (User: JSS)
Description: Faulting application name: MEmu-setup-abroad-sdk-mv.exe, version: 9.0.0.0, time stamp: 0x652375fd
Faulting module name: MEmu-setup-abroad-sdk-mv.exe, version: 9.0.0.0, time stamp: 0x652375fd
Exception code: 0xc0000005
Fault offset: 0x00177f8f
Faulting process id: 0x0xb70
Faulting application start time: 0x0x1da698995f324a0
Faulting application path: C:\Users\John Salamone\Desktop\MEmu-setup-abroad-sdk-mv.exe
Faulting module path: C:\Users\John Salamone\Desktop\MEmu-setup-abroad-sdk-mv.exe
Report Id: 57b42529-2c07-43a7-82cf-3cd29c0093bb
Faulting package full name:
Faulting package-relative application ID:
System errors:
=============
Error: (02/28/2024 10:32:35 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The vlmcsd service failed to start due to the following error:
%%2 = The system cannot find the file specified.
Error: (02/27/2024 11:59:39 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The vlmcsd service failed to start due to the following error:
%%2 = The system cannot find the file specified.
Error: (02/27/2024 11:35:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The vlmcsd service failed to start due to the following error:
%%2 = The system cannot find the file specified.
Error: (02/27/2024 09:32:48 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The MEmuSVC service terminated unexpectedly. It has done this 1 time(s).
Error: (02/27/2024 08:14:25 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The vlmcsd service failed to start due to the following error:
%%2 = The system cannot find the file specified.
Error: (02/26/2024 09:35:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The vlmcsd service failed to start due to the following error:
%%2 = The system cannot find the file specified.
Error: (02/26/2024 08:41:58 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The vlmcsd service failed to start due to the following error:
%%2 = The system cannot find the file specified.
Error: (02/26/2024 08:41:53 PM) (Source: VBoxNetLwf) (EventID: 12) (User: )
Description: The driver detected an internal driver error on \Device\VBoxNetLwf.
Error: (02/26/2024 07:59:44 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The vlmcsd service failed to start due to the following error:
%%2 = The system cannot find the file specified.
Error: (02/26/2024 07:59:39 PM) (Source: VBoxNetLwf) (EventID: 12) (User: )
Description: The driver detected an internal driver error on \Device\VBoxNetLwf.
Windows Defender:
================
Date: 2024-02-27 17:09:37
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2024-02-24 21:38:12
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen
Severity: High
Category: Tool
Path: file:_C:\Users\John Salamone\Desktop\Macrium Reflect 8.1.7784 (x64) + Patch + WinRE\Macrium Reflect 8.1.7784 (x64) + Patch\Patch\Patch.zip
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Program Files\qBittorrent\qbittorrent.exe
Security intelligence Version: AV: 1.405.553.0, AS: 1.405.553.0, NIS: 1.405.553.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10
Date: 2024-02-23 16:13:41
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2024-02-22 17:47:40
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2024-02-22 16:30:52
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Event[0]
Date: 2024-02-20 08:45:58
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Current
Error Code: 0x80070003
Error description: The system cannot find the path specified.
Security intelligence Version: 0.0.0.0;0.0.0.0
Engine Version: 0.0.0.0
Date: 2024-02-16 13:27:42
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.321.69.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.17300.4
Error code: 0x80240016
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
CodeIntegrity Errors:
====================
Date: 2024-02-17 14:09:43
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.
=========================== Installed Programs ============================
7-Zip 24.01 (x64) (HKLM\...\7-Zip) (Version: 24.01 - Igor Pavlov)
Crack1 version 1.5 (HKLM-x32\...\Crack1_is1) (Version: 1.5 - )
Easy Photo Scan (HKLM-x32\...\{99364024-626C-4BE1-89C8-2F207023497B}) (Version: 1.00.0018 - Seiko Epson Corporation)
Epson Customer Research Participation (HKLM\...\{B26449A6-6007-4460-B4FE-C4776115BCEA}) (Version: 1.83.0000 - Seiko Epson Corporation)
Epson Event Manager (HKLM-x32\...\{E244A764-EDD0-46B0-8689-661F6B28D9E5}) (Version: 3.10.0069 - Seiko Epson Corporation)
Epson Printer Connection Checker (HKLM-x32\...\{DE32F90E-1A29-4D74-BCF1-E7DDB25D713A}) (Version: 3.4.0.0 - Seiko Epson Corporation)
Epson Scan 2 (HKLM-x32\...\Epson Scan 2) (Version: - Seiko Epson Corporation)
EPSON Scan OCR Component (HKLM-x32\...\{3615C893-F844-4A5B-B949-8409EAB62271}) (Version: 3.00.05 - Seiko Epson Corporation)
Epson Software Updater (HKLM-x32\...\{711E8536-AB71-4455-A6C4-357FDBBEBF91}) (Version: 4.6.7 - Seiko Epson Corporation)
EPSON XP-340 Series Printer Uninstall (HKLM\...\EPSON XP-340 Series) (Version: - Seiko Epson Corporation)
EpsonNet Print (HKLM\...\{96ED1D58-440C-4345-8FEE-C4781366C67F}) (Version: 3.1.4.0 - SEIKO EPSON Corporation)
ExpressVPN (HKLM-x32\...\{cc976def-e120-4c60-9a34-c81368881b37}) (Version: 12.73.0.10 - ExpressVPN)
ExpressVPN (HKLM-x32\...\{E5B9C3E5-889C-4F22-A959-F4B89A5D783B}) (Version: 12.73.0.10 - ExpressVPN) Hidden
Free Timer (HKLM-x32\...\{2AE4F065-5A3C-486D-81B4-161D4693303E}_is1) (Version: 5.2.0.0 - Comfort Software Group)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 122.0.6261.71 - Google LLC)
Hekasoft Backup & Restore 0.96 (HKLM\...\{PBR27112011-M1447-7KS6-C3E2-1X8374W715U4}_is1) (Version: 0.96 - Hekasoft)
Microsoft Office LTSC Professional Plus 2021 - en-us (HKLM\...\ProPlus2021Volume - en-us) (Version: 16.0.14332.20637 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox 123.0 (x64 en-US)) (Version: 123.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 115.7.0 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.14332.20637 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.14332.20637 - Microsoft Corporation) Hidden
Oracle VM VirtualBox 7.0.14 (HKLM\...\{8DDF4B7A-DE1A-4619-B426-959B44E40A87}) (Version: 7.0.14 - Oracle and/or its affiliates)
qBittorrent (HKLM-x32\...\qBittorrent) (Version: 4.6.3 - The qBittorrent project)
Revo Uninstaller 2.4.5 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.4.5 - VS Revo Group, Ltd.)
Solway's Task Scheduler 2.12 (HKLM-x32\...\Solway's Task Scheduler) (Version: 2.12 - Kevin Solway)
Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.4.0.19572 - Microsoft Corporation)
TeamViewer (HKLM\...\TeamViewer) (Version: 15.50.5 - TeamViewer)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN)
Packages:
=========
AMD Radeon Software -> C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.22.20073.0_x64__0a9344xs7nr4m [2024-02-24] (Advanced Micro Devices Inc.) [Startup Task]
Cortana -> C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
Dolby Audio -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAudio_3.30201.210.0_x64__rz1tebttyb220 [2024-02-24] (Dolby Laboratories)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_151.3.1092.0_x64__v10z8vjag6ke6 [2024-02-24] (HP Inc.)
Microsoft Emulator -> C:\Program Files\WindowsApps\Microsoft.MicrosoftEmulator_1.1.1081.0_x64__8wekyb3d8bbwe [2024-02-27] (Microsoft Corporation)
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.40.0_x64__8wekyb3d8bbwe [2024-02-24] (Microsoft Corp.)
Microsoft.WindowsAppRuntime.CBS -> C:\Windows\SystemApps\Microsoft.WindowsAppRuntime.CBS_8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
ms-resource://MicrosoftCorporationII.QuickAssist/resources/APP_WINDOW_NAME -> C:\Program Files\WindowsApps\MicrosoftCorporationII.QuickAssist_2.0.28.0_x64__8wekyb3d8bbwe [2024-02-24] (Microsoft Corp.)
ms-resource:AppStoreName -> C:\Program Files\WindowsApps\Microsoft.RawImageExtension_2.3.171.0_x64__8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
ms-resource:AppStoreName -> C:\Program Files\WindowsApps\Microsoft.Windows.DevHome_0.1100.416.0_x64__8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
ms-resource:AppxManifest_DisplayName -> C:\Windows\SystemApps\Microsoft.Windows.PrintQueueActionCenter_cw5n1h2txyewy [2024-02-24] (Microsoft Corporation)
ms-resource:Clipchamp/AppName -> C:\Program Files\WindowsApps\Clipchamp.Clipchamp_2.9.1.0_neutral__yxz26nhyzhsrt [2024-02-24] (Microsoft Corp.)
ms-resource:ProductPkgDisplayName -> C:\Windows\SystemApps\MicrosoftWindows.Client.Core_cw5n1h2txyewy [2024-02-24] (ms-resource:ProductPublisherDisplayName)
ms-resource:ProductPkgDisplayName -> C:\Windows\SystemApps\MicrosoftWindows.Client.FileExp_cw5n1h2txyewy [2024-02-24] (ms-resource:ProductPublisherDisplayName)
Outlook for Windows -> C:\Program Files\WindowsApps\Microsoft.OutlookForWindows_1.2024.111.100_x64__8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.44.302.0_x64__dt26b99r8h8gj [2024-02-24] (Realtek Semiconductor Corp)
Smart Microphone Settings -> C:\Program Files\WindowsApps\ElevocTechnologyCo.Ltd.SmartMicrophoneSettings_1.1.51.0_x64__ttaqwwhyt5s6t [2024-02-24] (Elevoc Technology Co., Ltd.)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.19.1262.0_x64__8wekyb3d8bbwe [2024-02-24] (Microsoft Studios) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.231.1205.0_x64__zpdnekdrzrea0 [2024-02-24] (Spotify AB) [Startup Task]
Windows® 10X Emulator Image 10.0.19578.0 (Preview) -> C:\Program Files\WindowsApps\Microsoft.Windows10XEmulatorImage10.0.19578.0Previ_1.0.1.0_x64__8wekyb3d8bbwe [2024-02-27] (Microsoft Corporation)
WindowsAppRuntime.1.1 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.1_1005.616.1651.0_x64__8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
WindowsAppRuntime.1.1 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.1_1005.616.1651.0_x86__8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
WindowsAppRuntime.1.2 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
WindowsAppRuntime.1.2 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.2_2000.802.31.0_x86__8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
WindowsAppRuntime.1.3 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.3_3000.934.1904.0_x64__8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
WindowsAppRuntime.1.3 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
WindowsAppRuntime.1.4 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.4_4000.1136.2333.0_x64__8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
WindowsAppRuntime.1.4 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.4_4000.1136.2333.0_x86__8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
WSATools -> C:\Program Files\WindowsApps\54406Simizfo.WSATools_1.0.3.0_x64__f0x555vvp18ze [2024-02-25] (Simone Franco)
========================= Devices: ================================
========================= Memory info: ===================================
Percentage of memory in use: 24%
Total physical RAM: 18293.74 MB
Available physical RAM: 13736.41 MB
Total Virtual: 19445.74 MB
Available Virtual: 13694.96 MB
========================= Partitions: =====================================
1 Drive c: () (Fixed) (Total:476.07 GB) (Free:281.96 GB) NTFS
========================= Users: ========================================
User accounts for \\JSS
Administrator DefaultAccount Guest
John Salamone WDAGUtilityAccount
========================= Minidump Files ==================================
No minidump file found
========================= Restore Points ==================================
24-02-2024 19:32:02 Scheduled Checkpoint
25-02-2024 03:31:24 Revo Uninstaller's restore point - AOMEI Backupper
25-02-2024 19:56:45 Windows Modules Installer
25-02-2024 20:09:50 Revo Uninstaller's restore point - Amazon Appstore
27-02-2024 02:14:52 Revo Uninstaller's restore point - BlueStacks X
27-02-2024 02:15:35 Revo Uninstaller's restore point - BlueStacks App Player
27-02-2024 02:16:09 Revo Uninstaller's restore point - BlueStacks Services
27-02-2024 02:22:30 Revo Uninstaller's restore point - BlueStacks X
27-02-2024 02:23:25 Revo Uninstaller's restore point - BlueStacks Services
27-02-2024 02:24:02 Revo Uninstaller's restore point - BlueStacks App Player
27-02-2024 02:34:23 Windows Modules Installer
27-02-2024 02:44:35 Revo Uninstaller's restore point - NoxPlayer
27-02-2024 03:16:57 Revo Uninstaller's restore point - BlueStacks 5
27-02-2024 03:17:37 Revo Uninstaller's restore point - BlueStacks X
27-02-2024 14:29:40 Revo Uninstaller's restore point - WebAdvisor by McAfee
27-02-2024 14:36:54 Revo Uninstaller's restore point - MEmu
27-02-2024 14:45:37 Revo Uninstaller's restore point - BlueStacks 5
27-02-2024 14:46:16 Revo Uninstaller's restore point - BlueStacks X
27-02-2024 15:45:12 Revo Uninstaller's restore point - BlueStacks App Player
27-02-2024 15:47:52 Revo Uninstaller's restore point - BlueStacks Services
27-02-2024 15:48:32 Revo Uninstaller's restore point - BlueStacks X
**** End of log ****
Do you need error messages from event viewer...etc? Problematic devices... none that i know of. I am the only user and : is the only partition.
If you need anything else plz let me know.
TIA