Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-11-2022
Ran by Connor (17-11-2022 18:27:27)
Running from F:\Downloads
Microsoft Windows 10 Home Version 22H2 19045.2251 (X64) (2022-11-17 07:55:59)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-4236781876-3171122071-1440949848-500 - Administrator - Disabled)
Connor (S-1-5-21-4236781876-3171122071-1440949848-1001 - Administrator - Enabled) => C:\Users\Connor
DefaultAccount (S-1-5-21-4236781876-3171122071-1440949848-503 - Limited - Disabled)
Guest (S-1-5-21-4236781876-3171122071-1440949848-501 - Limited - Disabled)
Turke (S-1-5-21-4236781876-3171122071-1440949848-1002 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-4236781876-3171122071-1440949848-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
CurseForge (HKU\S-1-5-21-4236781876-3171122071-1440949848-1001\...\Overwolf_cchhcaiapeikjbdbpfplgmpobbcdkdaphclbmkbj) (Version: 0.212.3.7035 - Overwolf app)
Discord (HKU\S-1-5-21-4236781876-3171122071-1440949848-1001\...\Discord) (Version: 1.0.9007 - Discord Inc.)
EasySmartConfigurationUtility (HKLM-x32\...\{2E6F915E-1948-49D0-B660-0F17C768E511}) (Version: 1.3.10.0 - TPLINK)
Epic Games Launcher (HKLM-x32\...\{20235E2B-1E9F-473D-A215-B2467F1F06E3}) (Version: 1.3.51.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Epic Online Services (HKLM-x32\...\{19695986-25CE-41AC-9C6F-54794653EDBA}) (Version: 2.0.36.0 - Epic Games, Inc.)
FileZilla 3.62.0 (HKU\S-1-5-21-4236781876-3171122071-1440949848-1001\...\FileZilla Client) (Version: 3.62.0 - Tim Kosse)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 107.0.5304.107 - Google LLC)
Gyazo 4.3.4.0 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.)
Java(TM) SE Development Kit 19.0.1 (64-bit) (HKLM\...\{E4838A94-3448-5F9E-B1FE-696C1DC1F772}) (Version: 19.0.1.0 - Oracle Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Logitech G HUB (HKLM\...\{521c89be-637f-4274-a840-baaf7460c2b2}) (Version: 2022.10.326382 - Logitech)
Microsoft .NET Host - 6.0.11 (x64) (HKLM\...\{B92B890A-04F2-4880-BA20-20D4364FB263}) (Version: 48.47.50420 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.11 (x64) (HKLM\...\{5E63E49B-C88C-46C5-855C-A7B07C11CDC8}) (Version: 48.47.50420 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.11 (x64) (HKLM\...\{C3DD1448-513A-4DB8-978D-6991562EA63D}) (Version: 48.47.50420 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 107.0.1418.42 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 107.0.1418.42 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4236781876-3171122071-1440949848-1001\...\OneDriveSetup.exe) (Version: 21.220.1024.0005 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.24.28127 (HKLM-x32\...\{e31cb1a4-76b5-46a5-a084-3fa419e82201}) (Version: 14.24.28127.4 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.34.31931 (HKLM-x32\...\{d4cecf3b-b68f-4995-8840-52ea0fab646e}) (Version: 14.34.31931.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.24.28127 (HKLM-x32\...\{EAC73207-74BD-4B13-AACF-8C0E751FA4E8}) (Version: 14.24.28127 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.24.28127 (HKLM-x32\...\{2E72FA1F-BADB-4337-B8AE-F7C17EC57D1D}) (Version: 14.24.28127 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.34.31931 (HKLM\...\{EAE242B1-0A26-485A-BFEB-0292EE9F03CB}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.34.31931 (HKLM\...\{CF4C347D-954E-4543-88D2-EC17F07F466F}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.11 (x64) (HKLM\...\{A39D4115-3A27-4245-AE92-3214B8B21932}) (Version: 48.47.50419 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.11 (x64) (HKLM-x32\...\{c4846f79-a633-4ae4-92a3-92fdbeb33da2}) (Version: 6.0.11.31823 - Microsoft Corporation)
MPC-HC 1.7.13 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.13 - MPC-HC Team)
Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 8.4.7 - Notepad++ Team)
NVIDIA FrameView SDK 1.3.8107.31782123 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8107.31782123 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.26.0.154 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.26.0.154 - NVIDIA Corporation)
NVIDIA Graphics Driver 526.98 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 526.98 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.39.16 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.39.16 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.208.1.2 - Overwolf Ltd.)
paint.net (HKLM\...\{E91052A0-E7C9-4462-B7B5-2C7279F7203B}) (Version: 4.3.12 - dotPDN LLC)
qBittorrent 4.4.5 (HKLM-x32\...\qBittorrent) (Version: 4.4.5 - The qBittorrent project)
TradeSkillMaster Application version 1.0 (HKLM-x32\...\{c44da794-b956-4d50-8733-346d56ae63c7}_is1) (Version: 1.0 - TradeSkillMaster)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.17.4 - VideoLAN)
Voicemeeter, The Virtual Mixing Console (HKLM-x32\...\VB:Voicemeeter {17359A74-1236-5467}) (Version: - VB-Audio Software)
Warcraft Logs Companion (HKU\S-1-5-21-4236781876-3171122071-1440949848-1001\...\Overwolf_ecboebafnpgnolnpgppohegbpjbhffiahodgijdp) (Version: 2.2.5 - Overwolf app)
WinRAR 6.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.11.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
Packages:
=========
EarTrumpet -> C:\Program Files\WindowsApps\40459File-New-Project.EarTrumpet_2.2.1.0_x86__1sdd7yawvg6ne [2022-11-17] (File-New-Project) [Startup Task]
Intel® Graphics Command Center -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3370.0_x64__8j3eq9eme6ctt [2022-11-17] (INTEL CORP) [Startup Task]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.10.7290.0_x64__8wekyb3d8bbwe [2022-11-17] (Microsoft Studios) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\nvidiacorp.nvidiacontrolpanel_8.1.963.0_x64__56jybvy8sckqj [2022-11-17] (NVIDIA Corp.)
One Calendar -> C:\Program Files\WindowsApps\64885BlueEdge.OneCalendar_2022.1021.1.0_x64__8kea50m9krsh2 [2022-11-17] (Code Spark)
Windows Package Manager Source (winget) -> C:\Program Files\WindowsApps\Microsoft.Winget.Source_2022.1117.1250.556_neutral__8wekyb3d8bbwe [2022-11-17] (Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-4236781876-3171122071-1440949848-1001_Classes\CLSID\{429b5ad2-84ad-69c7-183b-1ea42518b203}\localserver32 -> F:\Programs\HandBrake\HandBrake.exe (HandBrake Team) [File not signed]
CustomCLSID: HKU\S-1-5-21-4236781876-3171122071-1440949848-1001_Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre1.8.0_351\bin\jp2iexp.dll => No File
CustomCLSID: HKU\S-1-5-21-4236781876-3171122071-1440949848-1001_Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre1.8.0_351\bin\jp2iexp.dll => No File
CustomCLSID: HKU\S-1-5-21-4236781876-3171122071-1440949848-1001_Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre1.8.0_351\bin\jp2iexp.dll => No File
====Literally like 3.5 thousand lines of this message, the java one, I've been having a ton of issues downloading it, I guess it's related====
CustomCLSID: HKU\S-1-5-21-4236781876-3171122071-1440949848-1001_Classes\CLSID\{CAFEEFAC-0018-0000-FFFF-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre1.8.0_351\bin\jp2iexp.dll => No File
CustomCLSID: HKU\S-1-5-21-4236781876-3171122071-1440949848-1001_Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}\InprocServer32 -> C:\Program Files\Java\jre1.8.0_351\bin\jp2iexp.dll => No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => F:\Programs\Notepad++\NppShell_06.dll [2022-11-08] (Notepad++ -> )
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_009debfbd2e1619b\nvshext.dll [2022-11-15] (Nvidia Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2022-11-17 08:43 - 2022-11-17 08:43 - 104871424 _____ () [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\libcef.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 000112128 _____ () [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\libegl.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 006227456 _____ () [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\libglesv2.dll
2022-11-17 12:30 - 2022-11-17 12:29 - 000156160 _____ () [File not signed] C:\Program Files\LGHUB\resources\app.asar.unpacked\keytar.node
2022-11-17 08:43 - 2022-11-17 08:43 - 000810496 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\chrome_elf.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 000047104 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\audio\qtaudio_windows.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 000026112 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\imageformats\qgif.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 000027136 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\imageformats\qico.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 000243712 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\imageformats\qjpeg.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 000223744 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\imageformats\qmng.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 000020992 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\imageformats\qsvg.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 000332288 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\imageformats\qtiff.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 001140224 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\platforms\qwindows.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 004943360 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\Qt5Core.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 005022208 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\Qt5Gui.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 000626176 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\Qt5Multimedia.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 000877056 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\Qt5Network.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 002908672 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\Qt5Qml.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 003078656 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\Qt5Quick.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 000259072 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\Qt5Svg.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 004718080 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\Qt5Widgets.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 000439296 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\Qt5WinExtras.dll
2022-11-17 08:43 - 2022-11-17 08:43 - 000159232 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.13835\Qt5Xml.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_351\bin\ssv.dll => No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_351\bin\jp2ssv.dll => No File
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2019-12-07 09:14 - 2019-12-07 09:12 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files\dotnet\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common
HKU\S-1-5-21-4236781876-3171122071-1440949848-1001\Control Panel\Desktop\\Wallpaper -> D:\Pictures\Backgrounds\zClip\Finished PNG\81.2.png
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-4236781876-3171122071-1440949848-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-4236781876-3171122071-1440949848-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_13A61B3481C91B58676BDDFAAC1D15E5"
HKU\S-1-5-21-4236781876-3171122071-1440949848-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-4236781876-3171122071-1440949848-1001\...\StartupApproved\Run: => "Overwolf"
HKU\S-1-5-21-4236781876-3171122071-1440949848-1001\...\StartupApproved\Run: => "Discord"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{E3F82450-00C6-41AC-89C5-448613D33946}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\107.0.1418.42\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{933727B0-BB29-487E-BC36-3BD0D29ABC96}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{B8C4FA8A-B137-4089-B210-B6675BCDE2CA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{4BEDCAF5-E6C4-48D7-9AF1-7DE1F328FD27}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{ECF1604D-EF77-4D35-A4A4-39324678E7D7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{8DA00A26-F005-4E83-9C72-1DA5D75C90A5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{EDBF41E1-104B-4D73-8B5E-31179ED679B6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{FE279136-6DE1-4F20-AFBB-51C30A80DBA5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{29F44E73-F767-485E-829F-F646ADCA5389}] => (Allow) F:\Programs\overwolf\0.208.1.2\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{7E52011B-6F65-4CAF-88E6-2CA1768381BD}] => (Allow) F:\Programs\overwolf\0.208.1.2\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{94EF6430-5206-4B8B-9A2D-8555F69F5274}] => (Block) F:\Programs\overwolf\0.208.1.2\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{F7A06F8B-43F1-4861-AADF-FA0C1820595C}] => (Block) F:\Programs\overwolf\0.208.1.2\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{71DD1B5E-26F9-47CB-A9B7-AE9822CA6CB6}] => (Allow) F:\Programs\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{AFB2594D-4BA0-461C-9353-786EE6205480}] => (Allow) F:\Programs\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
==================== Restore Points =========================
17-11-2022 08:27:18 Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821
17-11-2022 08:27:24 Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.22.27821
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (11/17/2022 02:40:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: EpicGamesLauncher.exe, version: 14.3.2.0, time stamp: 0x63728f7b
Faulting module name: KERNELBASE.dll, version: 10.0.19041.2193, time stamp: 0x7f7062e1
Exception code: 0xc000041d
Fault offset: 0x000000000002cd29
Faulting process ID: 0x3794
Faulting application start time: 0x01d8fa7f829ea04c
Faulting application path: F:\Programs\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report ID: 54f2617b-c1f4-45d8-a44a-5a6de64e1a1f
Faulting package full name:
Faulting package-relative application ID:
Error: (11/17/2022 02:40:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: EpicGamesLauncher.exe, version: 14.3.2.0, time stamp: 0x63728f7b
Faulting module name: KERNELBASE.dll, version: 10.0.19041.2193, time stamp: 0x7f7062e1
Exception code: 0x00004000
Fault offset: 0x000000000002cd29
Faulting process ID: 0x3794
Faulting application start time: 0x01d8fa7f829ea04c
Faulting application path: F:\Programs\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report ID: c5e79957-a50d-4900-828e-8ef4a171a6b4
Faulting package full name:
Faulting package-relative application ID:
Error: (11/17/2022 02:35:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: dwm.exe, version: 10.0.19041.746, time stamp: 0x6be51595
Faulting module name: nvwgf2umx.dll, version: 31.0.15.2647, time stamp: 0x63583522
Exception code: 0xc0000005
Fault offset: 0x00000000002a1de6
Faulting process ID: 0x548
Faulting application start time: 0x01d8fa7f74b18f5d
Faulting application path: C:\WINDOWS\system32\dwm.exe
Faulting module path: C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_ade64cd54ec2f9ed\nvwgf2umx.dll
Report ID: 53c73cc2-d2b0-4f26-ad74-40b789a7e2cc
Faulting package full name:
Faulting package-relative application ID:
Error: (11/17/2022 12:19:43 PM) (Source: MsiInstaller) (EventID: 11722) (User: CONNOR-DESKTOP)
Description: Product: Java 8 Update 351 (64-bit) -- Error 1722. There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor. Action installexe, location: C:\Program Files\Java\jre1.8.0_351\installer.exe, command: /s INSTALLDIR="C:\Program Files\Java\jre1.8.0_351\\" INSTALL_SILENT=1 REPAIRMODE=0 ProductCode={26A24AE4-039D-4CA4-87B4-2F64180351F0}
Error: (11/17/2022 12:15:13 PM) (Source: MsiInstaller) (EventID: 11722) (User: CONNOR-DESKTOP)
Description: Product: Java 8 Update 351 (64-bit) -- Error 1722. There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor. Action installexe, location: C:\Program Files\Java\jre1.8.0_351\installer.exe, command: /s INSTALLDIR="C:\Program Files\Java\jre1.8.0_351\\" INSTALL_SILENT=1 REPAIRMODE=0 ProductCode={26A24AE4-039D-4CA4-87B4-2F64180351F0}
Error: (11/17/2022 10:01:57 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000002f0,SYSTEM\CurrentControlSet\Services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5},0,REG_BINARY,000000734637E200.72). hr = 0x80070005, Access is denied.
.
Operation:
Executing Asynchronous Operation
Context:
Current State: DoSnapshotSet
Error: (11/17/2022 10:01:57 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000002f0,SYSTEM\CurrentControlSet\Services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5},0,REG_BINARY,000000734637E200.72). hr = 0x80070005, Access is denied.
.
Operation:
Executing Asynchronous Operation
Context:
Current State: DoSnapshotSet
Error: (11/17/2022 10:01:57 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000002f0,SYSTEM\CurrentControlSet\Services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5},0,REG_BINARY,000000734637E200.72). hr = 0x80070005, Access is denied.
.
Operation:
Executing Asynchronous Operation
Context:
Current State: DoSnapshotSet
System errors:
=============
Error: (11/17/2022 02:35:12 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The NVIDIA LocalSystem Container service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 6000 milliseconds: Restart the service.
Error: (11/17/2022 02:35:12 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The NVIDIA LocalSystem Container service terminated with the following error:
A generic command executable returned a result that indicates failure.
Error: (11/17/2022 12:23:54 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The HitmanPro38CrusaderBoot service terminated with the following service-specific error:
The operation completed successfully.
Error: (11/17/2022 12:22:47 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Type with the following error:
Access is denied.
Error: (11/17/2022 12:20:47 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Type with the following error:
Access is denied.
Error: (11/17/2022 12:20:10 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200b: Update for Microsoft Defender Antivirus antimalware platform - KB4052623 (Version 4.18.2210.6).
Error: (11/17/2022 12:18:17 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Type with the following error:
Access is denied.
Error: (11/17/2022 12:18:17 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Type with the following error:
Access is denied.
Windows Defender:
================
Date: 2022-11-17 09:11:19
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: Trojan:Win32/Occamy.C38
Severity: Severe
Category: Trojan
Path: containerfile:_F:\Games\Crazy Machines 3\rld-crma3le.iso; file:_F:\Games\Crazy Machines 3\rld-crma3le.iso->\Crack\steam_api64.dll
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: User
Process Name: Unknown
Security intelligence Version: AV: 1.379.491.0, AS: 1.379.491.0, NIS: 1.379.491.0
Engine Version: AM: 1.1.19800.4, NIS: 1.1.19800.4
==================== Memory info ===========================
BIOS: American Megatrends Inc. A.60 01/30/2021
Motherboard: Micro-Star International Co., Ltd. MPG Z490 GAMING PLUS (MS-7C75)
Processor: Intel(R) Core(TM) i7-10700K CPU @ 3.80GHz
Percentage of memory in use: 60%
Total physical RAM: 16305.69 MB
Available physical RAM: 6414.17 MB
Total Virtual: 24931.47 MB
Available Virtual: 3259.98 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:232.29 GB) (Free:117.77 GB) (Model: Samsung SSD 970 EVO 250GB) NTFS
Drive d: (New Volume) (Fixed) (Total:931.5 GB) (Free:347.2 GB) (Model: WDC WD10EZEX-08WN4A0) NTFS
Drive e: (New Volume) (Fixed) (Total:2794.5 GB) (Free:727.25 GB) (Model: TOSHIBA HDWD130) NTFS
Drive f: (SSD 2) (Fixed) (Total:931.5 GB) (Free:275.33 GB) (Model: WDC WDS100T2B0C-00PXH0) NTFS
\\?\Volume{62adf89f-d184-4a71-9738-56be4931f768}\ () (Fixed) (Total:0.49 GB) (Free:0.05 GB) NTFS
\\?\Volume{7e8fbd3c-fad5-4075-8d09-9016376848ba}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 2794.5 GB) (Disk ID: 00000000)
Partition: GPT.
==========================================================
Disk: 1 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
==========================================================
Disk: 2 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
==========================================================
Disk: 3 (Protective MBR) (Size: 232.9 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt =======================