==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\USER\Desktop\Hawa - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\USER\Desktop\Stefano (Steve) - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default"
ShortcutWithArgument: C:\Users\USER\Desktop\Sword (Sword Geisha) - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Streaming Media Player.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=jggnklnmaecfofafepejcjcjkcohgcfb
ShortcutWithArgument: C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ubiquiti Device Discovery Tool.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=hmpigflbjeapnknladcfphgkemopofig
==================== Loaded Modules (Whitelisted) =============
2021-06-05 18:12 - 2019-12-19 15:04 - 000990720 _____ () [File not signed] C:\Program Files (x86)\vMix\filters\vMixVideo.ax
2021-06-10 17:39 - 2021-06-10 17:39 - 000114176 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\_ctypes.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000172544 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\_elementtree.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 002255872 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\_hashlib.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000032256 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\_multiprocessing.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000046080 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\_psutil_windows.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000047616 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\_socket.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 002824704 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\_ssl.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000026112 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\_yappi.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000080896 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\bz2.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000015872 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\common.time34.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000007680 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\hashobjs_ext.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000301568 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\PIL._imaging.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000168448 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\pyexpat.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 001084416 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\pysqlite2._sqlite.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000548864 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\pythoncom27.dll
2021-06-10 17:39 - 2021-06-10 17:39 - 000137728 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\pywintypes27.dll
2021-06-10 17:39 - 2021-06-10 17:39 - 000010752 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\select.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000020992 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\thumbnails_ext.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000689664 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\unicodedata.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000119808 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\usb_ext.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000128512 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\win32api.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000438784 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\win32com.shell.shell.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000011776 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\win32crypt.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000023040 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\win32event.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000149504 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\win32file.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000223232 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\win32gui.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000048128 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\win32inet.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000029696 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\win32pdh.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000027648 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\win32pipe.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000044032 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\win32process.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000020480 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\win32profile.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000136192 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\win32security.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000026624 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\win32ts.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000034304 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\windows.conditional.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000037888 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\windows.connectivity.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000071680 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\windows.device_monitor.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000103936 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\windows.volumes.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000019968 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\windows.winwrap.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 001325056 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\wx._controls_.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 001489408 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\wx._core_.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 001007104 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\wx._gdi_.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000103424 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\wx._html2.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 000916992 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\wx._misc_.pyd
2021-06-10 17:39 - 2021-06-10 17:39 - 001039872 _____ () [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\wx._windows_.pyd
2021-05-26 00:44 - 2020-01-30 12:36 - 000087040 _____ () [File not signed] C:\Windows\System32\custmon64.dll
2021-05-17 15:55 - 2021-05-17 15:55 - 005165568 _____ (Blackmagic Design) [File not signed] C:\Program Files\Blackmagic Design\Desktop Video\DeckLinkAPI64.dll
2021-06-10 17:39 - 2021-06-10 17:39 - 003043328 _____ (Python Software Foundation) [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\python27.dll
2021-06-10 17:39 - 2021-06-10 17:39 - 000202240 _____ (wxWidgets development team) [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\wxbase30u_net_vc90_x64.dll
2021-06-10 17:39 - 2021-06-10 17:39 - 002831872 _____ (wxWidgets development team) [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\wxbase30u_vc90_x64.dll
2021-06-10 17:39 - 2021-06-10 17:39 - 001654784 _____ (wxWidgets development team) [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\wxmsw30u_adv_vc90_x64.dll
2021-06-10 17:39 - 2021-06-10 17:39 - 006542336 _____ (wxWidgets development team) [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\wxmsw30u_core_vc90_x64.dll
2021-06-10 17:39 - 2021-06-10 17:39 - 000773632 _____ (wxWidgets development team) [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\wxmsw30u_html_vc90_x64.dll
2021-06-10 17:39 - 2021-06-10 17:39 - 000137216 _____ (wxWidgets development team) [File not signed] C:\Users\USER\AppData\Local\Temp\_MEI194122\wxmsw30u_webview_vc90_x64.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\avgSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\avgSP.sys => ""="Driver"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
HKU\S-1-5-21-2070248933-3621112216-831521933-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=ACTE
HKU\S-1-5-21-2070248933-3621112216-831521933-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.msn.com/?pc=ACTE
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2021-05-31] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-05-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-05-31] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-05-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-05-31] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-05-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-05-31] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-05-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-05-31] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2019-12-07 16:14 - 2019-12-07 16:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
2021-06-10 16:38 - 2021-06-10 16:38 - 000000435 _____ C:\Windows\system32\drivers\etc\hosts.ics
192.168.137.1 AcerSteve.mshome.net # 2026 6 2 9 9 38 35 989
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2070248933-3621112216-831521933-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\USER\Pictures\MA3wp.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn)
Windows Firewall is disabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{C4863744-FFC7-4D6C-91FA-DA20C9AE878D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{A329FA7B-E037-4E44-87C8-12BE5F1F54EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{BA8C4C9A-988A-48E2-B757-0CF968DEA743}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{1D4142F5-7F29-4D13-8599-4E8A296E5BBF}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{4B9999A2-41C5-4224-B03B-17D7D7429583}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{828CCD3C-D4AE-4990-96A5-B68E482B0582}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{E1D767E3-FD24-42A0-905D-2845A365DA7F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{074B2C66-1765-4DEE-AB3C-666DB49B91AA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{65E39FAA-88C4-4764-9311-0BB2F9EE3EDF}] => (Allow) C:\Program Files\MALightingTechnology\gma3_1.4.2\bin\app_system.exe (MA Lighting Technology GmbH -> MA Lighting Technology)
FirewallRules: [{04675841-DB61-4597-80CA-89E53079523A}] => (Allow) C:\Program Files\MALightingTechnology\gma3_1.4.2\bin\app_gma3.exe (MA Lighting Technology GmbH -> MA Lighting Technology)
FirewallRules: [{1E8C7505-7A9E-46F7-B3CC-70FBABFF4730}] => (Allow) LPort=9993
FirewallRules: [{B6D800D6-9D1D-4879-B5CF-46206091131F}] => (Allow) LPort=9993
FirewallRules: [{D6B78F20-A165-4525-9919-3BBFCF290FBD}] => (Allow) C:\ProgramData\ZeroTier\One\zerotier-one_x64.exe (ZeroTier, Inc. -> )
FirewallRules: [{92C6A74C-7F12-42F9-8062-5AD0D8B4C91C}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\Resolve.exe (Blackmagic Design Pty Ltd -> Blackmagic Design Pty. Ltd.)
FirewallRules: [{45DFEBF2-C492-4F91-B63F-1424B4A63523}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\bmdpaneld.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{DB1F1B60-9BA9-423A-93B2-D1F900385DE7}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\DaVinciPanelDaemon.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{2AA658DB-8EA4-494E-84DA-D7FE121AED4E}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\JLCooperPanelDaemon.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{697D8DAF-54D7-4D07-8CDA-54D6203A501C}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\EuphonixPanelDaemon.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{1EC4CE5C-DD91-4ED1-9601-8FB7522C8A3E}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\TangentPanelDaemon.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{F24FB58E-3C58-424C-AA3D-793473863EEA}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\fuscript.exe (Blackmagic Design Pty Ltd -> Blackmagic Design Pty. Ltd.)
FirewallRules: [{7E9E70B9-C71E-4616-9655-ACD1678E7FF2}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\DPDecoder.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [TCP Query User{4F29297A-03D1-466E-B2C8-2B425A683B2E}C:\program files (x86)\blackmagic design\blackmagic atem switchers\atem software control\atem software control.exe] => (Allow) C:\program files (x86)\blackmagic design\blackmagic atem switchers\atem software control\atem software control.exe () [File not signed]
FirewallRules: [UDP Query User{C47F00CD-9C0B-4B40-A0CC-F1FDF32FE1B3}C:\program files (x86)\blackmagic design\blackmagic atem switchers\atem software control\atem software control.exe] => (Allow) C:\program files (x86)\blackmagic design\blackmagic atem switchers\atem software control\atem software control.exe () [File not signed]
FirewallRules: [{4C5BF947-0076-4E88-A848-0C7BDCB0E40E}] => (Allow) LPort=3001
FirewallRules: [{B385835D-9F9D-4C42-9EA0-1E5803C03231}] => (Allow) LPort=4567
FirewallRules: [TCP Query User{9DE7DF3E-6B0C-4647-B003-7C2EEF049C46}C:\program files\arkaos mediamaster 5.3.1\mediamaster.exe] => (Allow) C:\program files\arkaos mediamaster 5.3.1\mediamaster.exe (ArKaos S.A. -> ArKaos S.A.)
FirewallRules: [UDP Query User{806804CF-AEF9-4EA9-8A40-2A52BA88F2EA}C:\program files\arkaos mediamaster 5.3.1\mediamaster.exe] => (Allow) C:\program files\arkaos mediamaster 5.3.1\mediamaster.exe (ArKaos S.A. -> ArKaos S.A.)
FirewallRules: [TCP Query User{63CB6DA3-073F-4B71-9F6E-7C5C7713370C}C:\program files\ma lighting technologies\grandma\grandma2 onpc 3.1.2.5\gma2onpc.exe] => (Allow) C:\program files\ma lighting technologies\grandma\grandma2 onpc 3.1.2.5\gma2onpc.exe (MA Lighting Technology GmbH -> )
FirewallRules: [UDP Query User{4CDC0D89-378C-4EF0-9351-9BEBC1674A44}C:\program files\ma lighting technologies\grandma\grandma2 onpc 3.1.2.5\gma2onpc.exe] => (Allow) C:\program files\ma lighting technologies\grandma\grandma2 onpc 3.1.2.5\gma2onpc.exe (MA Lighting Technology GmbH -> )
FirewallRules: [{E898F88E-61EE-4FDA-945F-85955468AC78}] => (Allow) C:\Program Files\Elgato\StreamDeck\StreamDeck.exe (Corsair Memory, Inc. -> Corsair Memory, Inc)
FirewallRules: [TCP Query User{CFCEDA88-ADAF-49FC-876E-B42734F878B2}C:\program files\companion\companion.exe] => (Allow) C:\program files\companion\companion.exe (Bitfocus AS) [File not signed]
FirewallRules: [UDP Query User{1D86DC22-D2FA-416C-914C-D1B19DC44002}C:\program files\companion\companion.exe] => (Allow) C:\program files\companion\companion.exe (Bitfocus AS) [File not signed]
FirewallRules: [TCP Query User{C17A0585-AD49-4E40-BAC1-4D9648D75162}C:\program files (x86)\blackmagic design\blackmagic atem switchers\atem setup\atem setup.exe] => (Allow) C:\program files (x86)\blackmagic design\blackmagic atem switchers\atem setup\atem setup.exe () [File not signed]
FirewallRules: [UDP Query User{4E7479C0-3E94-411E-9DAE-50CF712956C0}C:\program files (x86)\blackmagic design\blackmagic atem switchers\atem setup\atem setup.exe] => (Allow) C:\program files (x86)\blackmagic design\blackmagic atem switchers\atem setup\atem setup.exe () [File not signed]
FirewallRules: [TCP Query User{93440180-0765-4C43-AEBD-C26B3554CFED}C:\program files\ma lighting technologies\grandma\grandma2 onpc 3.8.0.0\gma2onpc.exe] => (Allow) C:\program files\ma lighting technologies\grandma\grandma2 onpc 3.8.0.0\gma2onpc.exe (MA Lighting Technology GmbH -> )
FirewallRules: [UDP Query User{DDCCE3C0-A59C-4C03-B3CE-67EC7AE38BC2}C:\program files\ma lighting technologies\grandma\grandma2 onpc 3.8.0.0\gma2onpc.exe] => (Allow) C:\program files\ma lighting technologies\grandma\grandma2 onpc 3.8.0.0\gma2onpc.exe (MA Lighting Technology GmbH -> )
FirewallRules: [TCP Query User{71F94433-3899-4A1E-962E-122A2123FC7C}C:\program files\ma lighting technologies\grandma\grandma2 onpc 3.9.60.4\gma2onpc.exe] => (Allow) C:\program files\ma lighting technologies\grandma\grandma2 onpc 3.9.60.4\gma2onpc.exe (MA Lighting Technology GmbH -> )
FirewallRules: [UDP Query User{A68DCF80-6C1F-4F9D-956B-188A88176C22}C:\program files\ma lighting technologies\grandma\grandma2 onpc 3.9.60.4\gma2onpc.exe] => (Allow) C:\program files\ma lighting technologies\grandma\grandma2 onpc 3.9.60.4\gma2onpc.exe (MA Lighting Technology GmbH -> )
FirewallRules: [{5A1D19B7-495C-4B2B-B228-1AD167667EBB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{9C916A1B-9487-48DF-A24B-D901637D9BF1}C:\program files (x86)\lj\the artnetominator\artnetominator.exe] => (Allow) C:\program files (x86)\lj\the artnetominator\artnetominator.exe (LJ) [File not signed]
FirewallRules: [UDP Query User{7EF10862-2B31-47A7-BBFF-302CD6543C96}C:\program files (x86)\lj\the artnetominator\artnetominator.exe] => (Allow) C:\program files (x86)\lj\the artnetominator\artnetominator.exe (LJ) [File not signed]
FirewallRules: [TCP Query User{4C0E3B31-E60B-42BA-BB2D-F99D983D1477}C:\users\user\desktop\pensuite.exe] => (Allow) C:\users\user\desktop\pensuite.exe () [File not signed]
FirewallRules: [UDP Query User{3827BF16-40ED-4736-A523-6ADE3ED5F644}C:\users\user\desktop\pensuite.exe] => (Allow) C:\users\user\desktop\pensuite.exe () [File not signed]
FirewallRules: [TCP Query User{4E7C85DE-9E5A-40EC-A878-037CEB3508EB}C:\program files (x86)\chamsys ltd\magicq pc\mqqt.exe] => (Allow) C:\program files (x86)\chamsys ltd\magicq pc\mqqt.exe => No File
FirewallRules: [UDP Query User{E783D260-FC8C-4ED2-8813-1E84F1121FFB}C:\program files (x86)\chamsys ltd\magicq pc\mqqt.exe] => (Allow) C:\program files (x86)\chamsys ltd\magicq pc\mqqt.exe => No File
FirewallRules: [{D3D29223-3490-4EFD-81F9-57E3EAC2350A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{4D21E81D-9BA6-463B-94E7-8AD22213342E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{9D181700-D80E-4F94-B154-33E1A440E703}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{EFF535E6-4347-431E-8B29-02C7F7F44E44}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [TCP Query User{531112A6-C9B5-478A-9C9E-B2FBC2CF1EFC}C:\program files\avolites\titan go\titan go.exe] => (Allow) C:\program files\avolites\titan go\titan go.exe => No File
FirewallRules: [UDP Query User{8D5D3D9F-E41B-4CF2-9C28-BA20379A24B5}C:\program files\avolites\titan go\titan go.exe] => (Allow) C:\program files\avolites\titan go\titan go.exe => No File
FirewallRules: [TCP Query User{828AD588-83CF-44F2-91A5-4CDF710567E1}C:\program files\avolites\titan simulator\titansimulator.exe] => (Allow) C:\program files\avolites\titan simulator\titansimulator.exe => No File
FirewallRules: [UDP Query User{5DBF0608-A5E3-4426-8309-0721D3FE5FBA}C:\program files\avolites\titan simulator\titansimulator.exe] => (Allow) C:\program files\avolites\titan simulator\titansimulator.exe => No File
FirewallRules: [TCP Query User{B35D54C5-1859-4009-90E7-0CEB968E4DBB}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{F330C502-8B7A-469E-A4A2-502DF981D89D}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{E6F248C7-185D-4FF7-9055-CEAEB6D9B276}C:\program files\epic games\ue_4.26\engine\binaries\win64\ue4editor.exe] => (Allow) C:\program files\epic games\ue_4.26\engine\binaries\win64\ue4editor.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{01472064-AA6E-4D9F-9387-A13CD6E4D369}C:\program files\epic games\ue_4.26\engine\binaries\win64\ue4editor.exe] => (Allow) C:\program files\epic games\ue_4.26\engine\binaries\win64\ue4editor.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{939A9ED8-59B5-458F-95A2-1DE59C1D2D0C}C:\program files\epic games\ue_5.0ea\engine\binaries\win64\unrealeditor.exe] => (Allow) C:\program files\epic games\ue_5.0ea\engine\binaries\win64\unrealeditor.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{642113AD-F365-4F43-8281-2D80CFAD8BA8}C:\program files\epic games\ue_5.0ea\engine\binaries\win64\unrealeditor.exe] => (Allow) C:\program files\epic games\ue_5.0ea\engine\binaries\win64\unrealeditor.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{7B62230B-DA05-471E-9065-AAB9318E08DA}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12113.17.53090.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{CD1C1DB0-625C-4603-B4E6-5F4C943DE13D}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12113.17.53090.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{22ED351F-9780-4EBC-BB81-8F44FAE613D5}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12113.17.53090.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8CCF8572-4C88-4FD0-875C-46E6B5E74B56}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12113.17.53090.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{A0EAEF1E-0C76-4773-ACCE-9E30C10D82B0}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12113.17.53090.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{9790D7E4-8A8D-4768-A670-FB9983949329}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12113.17.53090.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{51D3BFC6-6293-4724-ADA6-5636C48BB707}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12113.17.53090.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{EA51D2AD-C4EC-46CC-8641-4E8B8C3B06D8}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12113.17.53090.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [TCP Query User{B813B48C-28EC-4B8B-879D-784EA866233A}C:\program files (x86)\surfeasy vpn\client\surfeasyvpn.exe] => (Allow) C:\program files (x86)\surfeasy vpn\client\surfeasyvpn.exe (NortonLifeLock Inc. -> )
FirewallRules: [UDP Query User{E8030538-299E-4B9A-845B-8E6842F3379A}C:\program files (x86)\surfeasy vpn\client\surfeasyvpn.exe] => (Allow) C:\program files (x86)\surfeasy vpn\client\surfeasyvpn.exe (NortonLifeLock Inc. -> )
FirewallRules: [TCP Query User{A3FA7340-8D23-4047-9AE9-50F31786C585}C:\program files\adobe\adobe dreamweaver cc 2017\node\node.exe] => (Allow) C:\program files\adobe\adobe dreamweaver cc 2017\node\node.exe (Adobe Systems Incorporated -> Joyent, Inc)
FirewallRules: [UDP Query User{FEE5B962-3D9B-4B9A-964D-666774A3296E}C:\program files\adobe\adobe dreamweaver cc 2017\node\node.exe] => (Allow) C:\program files\adobe\adobe dreamweaver cc 2017\node\node.exe (Adobe Systems Incorporated -> Joyent, Inc)
FirewallRules: [{FC728423-EC51-452F-9B4E-94490E1C5E04}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [{D73EAE1E-2893-48FE-B197-4AC5208B6534}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{846AE1BC-2FC2-4444-BF9C-4A46EE4E507B}] => (Allow) C:\Program Files (x86)\vMix\vMix.exe (StudioCoast Pty Ltd -> StudioCoast Pty Ltd)
FirewallRules: [{22608AB2-B619-4FEB-997B-E9658B05151E}] => (Allow) C:\Program Files (x86)\vMix\vMix64.exe (StudioCoast Pty Ltd -> StudioCoast Pty Ltd)
FirewallRules: [{E4FA0130-FDFA-419E-BD0D-5D0463A87A51}] => (Allow) C:\Program Files (x86)\vMix\ndi\vMixNDIHelper.exe (StudioCoast Pty Ltd) [File not signed]
FirewallRules: [{024D3A79-15A2-4194-97C9-8FACAF1577A0}] => (Allow) C:\Program Files (x86)\vMix\vMixDesktopCapture.exe (StudioCoast Pty Ltd -> )
FirewallRules: [{17F2E0A6-BB88-4D68-B8C5-45DE5C8E1279}] => (Allow) C:\Program Files (x86)\vMix\ndi\x86\NDIRecord.exe (Newtek Inc -> )
FirewallRules: [{FF0EB9A5-EDE4-4B79-AFF5-A2B0D33412B1}] => (Allow) C:\Program Files (x86)\vMix\ndi\x64\NDIRecord.exe (Newtek Inc -> )
FirewallRules: [{A17AD332-F5D7-4E4B-87C2-E3C87B10418E}] => (Allow) C:\Program Files (x86)\vMix\NDINode.exe () [File not signed]
FirewallRules: [{94432C65-128C-4E4F-A0EE-45AF46CD540C}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\91.0.864.41\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{90DD8F4C-CCC8-4AAB-BC88-0AB6F0F1BDB8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{6E5DFCA8-944E-4581-A4EB-5A5525F4F6C1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{9A4186D7-F5CB-4EB1-91FC-5D222226FB76}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{CA105BE4-14AA-442E-9F89-D70D53A38279}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{5FB873EE-5AAA-4F49-8434-2D3B151F23DA}] => (Allow) C:\Program Files\MALightingTechnology\gma3_1.4.2\bin\app_system.exe (MA Lighting Technology GmbH -> MA Lighting Technology)
FirewallRules: [{78F1EF3B-82FC-46E4-A966-10E072C2C316}] => (Allow) C:\Program Files\MALightingTechnology\gma3_1.4.2\bin\app_gma3.exe (MA Lighting Technology GmbH -> MA Lighting Technology)
FirewallRules: [{616089A9-3E9C-4B6A-8916-4F16D8334483}] => (Allow) C:\ProgramData\ZeroTier\One\zerotier-one_x64.exe (ZeroTier, Inc. -> )
FirewallRules: [{C675E00D-EC9B-45F0-B6EA-C8654FC308D6}] => (Allow) C:\ProgramData\ZeroTier\One\zerotier-one_x64.exe (ZeroTier, Inc. -> )
==================== Restore Points =========================
02-06-2021 20:59:17 Scheduled Checkpoint
05-06-2021 16:31:40 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
09-06-2021 15:13:00 Windows Modules Installer
10-06-2021 16:21:22 Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.25.28508
10-06-2021 17:30:43 Removed Avolites Personality Builder
10-06-2021 17:31:58 Removed Avolites Titan 15.0
10-06-2021 17:33:05 Removed Avolites Usb Expert
10-06-2021 17:33:14 Installed Avolites Titan 15.0
10-06-2021 17:33:21 Removed Avolites Titan Mobile
10-06-2021 17:33:31 Removed Avolites Titan Simulator
10-06-2021 17:33:39 Removed Avolites Titan Go
10-06-2021 17:33:48 Removed Avolites Virtual Panel
10-06-2021 17:33:56 Removed Avolites WebAPI 15.0
10-06-2021 17:34:05 Removed Avolites CITP 15.0
10-06-2021 17:34:14 Removed Avolites ACN Gateway
10-06-2021 17:34:21 Removed Log Viewer Pro
10-06-2021 17:34:30 Installed Avolites Personality Builder
10-06-2021 17:34:37 Installed Titan HealthCheck
10-06-2021 17:34:46 Removed Authenticator
==================== Faulty Device Manager Devices ============
Name: Bluetooth Device (Personal Area Network)
Description: Bluetooth Device (Personal Area Network)
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: BthPan
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: ========================
Application errors:
==================
Error: (06/10/2021 05:11:06 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: ACERSTEVE)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
Error: (06/10/2021 05:10:13 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]
Error: (06/10/2021 04:59:48 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Local Hostname AcerSteve.local already in use; will try AcerSteve-2.local instead
Error: (06/10/2021 04:59:48 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister 4 AcerSteve.local. Addr 192.168.191.7
Error: (06/10/2021 04:59:48 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.191.7:5353 16 AcerSteve.local. AAAA FC93

062:A073:7029:3CB9:0000:0000:0001
Error: (06/10/2021 04:59:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Resetting to Probing: 16 AcerSteve.local. AAAA FE80:0000:0000:0000:41DE:83F2:596C:A350
Error: (06/10/2021 04:59:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.191.7:5353 16 AcerSteve.local. AAAA FC93

062:A073:7029:3CB9:0000:0000:0001
Error: (06/10/2021 04:59:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Resetting to Probing: 4 AcerSteve.local. Addr 192.168.191.7
System errors:
=============
Error: (06/10/2021 05:38:44 PM) (Source: DCOM) (EventID: 10010) (User: ACERSTEVE)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.
Error: (06/10/2021 05:38:43 PM) (Source: DCOM) (EventID: 10010) (User: ACERSTEVE)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.
Error: (06/10/2021 05:38:43 PM) (Source: DCOM) (EventID: 10010) (User: ACERSTEVE)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.
Error: (06/10/2021 05:38:43 PM) (Source: DCOM) (EventID: 10010) (User: ACERSTEVE)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.
Error: (06/10/2021 05:38:43 PM) (Source: DCOM) (EventID: 10010) (User: ACERSTEVE)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.
Error: (06/10/2021 05:38:43 PM) (Source: DCOM) (EventID: 10010) (User: ACERSTEVE)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.
Error: (06/10/2021 05:38:43 PM) (Source: DCOM) (EventID: 10010) (User: ACERSTEVE)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.
Error: (06/10/2021 05:38:43 PM) (Source: DCOM) (EventID: 10010) (User: ACERSTEVE)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.
Windows Defender:
================
Date: 2021-06-09 23:17:25
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2021-06-09 14:59:49
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: App:Utorrent_BundleInstaller
Severity: Low
Category: Potentially Unwanted Software
Path: file:_C:\Users\USER\AppData\Local\Temp\7zS460FEC70\Carrier.exe; file:_C:\Users\USER\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk; file:_C:\Users\USER\AppData\Roaming\uTorrent\uTorrent.exe; file:_C:\Users\USER\Desktop\µTorrent.lnk; regkey:_HKCU@S-1-5-21-2070248933-3621112216-831521933-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\uTorrent; regkey:_HKCU@S-1-5-21-2070248933-3621112216-831521933-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\uTorrent; runkey:_HKCU@S-1-5-21-2070248933-3621112216-831521933-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\uTorrent; uninstall:_HKCU@S-1-5-21-2070248933-3621112216-831521933-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\uTorrent
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Users\USER\Downloads\uTorrent.exe
Security intelligence Version: AV: 1.341.301.0, AS: 1.341.301.0, NIS: 1.341.301.0
Engine Version: AM: 1.1.18200.4, NIS: 1.1.18200.4
Date: 2021-06-08 17:20:36
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: Trojan:MSIL/AgentTesla.AUE!MTB
Severity: Severe
Category: Trojan
Path: containerfile:_C:\Program Files (x86)\Adobe\Adobe Photoshop 2021 Patch\AdobeOnlineActivator.exe; file:_C:\Program Files (x86)\Adobe\Adobe Photoshop 2021 Patch\AdobeOnlineActivator.exe->[MSILRES:costura.newtonsoft.json.dll]
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: System
Process Name: Unknown
Security intelligence Version: AV: 1.341.227.0, AS: 1.341.227.0, NIS: 1.341.227.0
Engine Version: AM: 1.1.18200.4, NIS: 1.1.18200.4
Date: 2021-06-08 14:18:48
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: Trojan:MSIL/AgentTesla.AUE!MTB
Severity: Severe
Category: Trojan
Path: containerfile:_C:\Program Files (x86)\Adobe\Adobe Photoshop 2021 Patch\AdobeOnlineActivator.exe; file:_C:\Program Files (x86)\Adobe\Adobe Photoshop 2021 Patch\AdobeOnlineActivator.exe->[MSILRES:costura.newtonsoft.json.dll]
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Program Files\AVG\Antivirus\avgToolsSvc.exe
Security intelligence Version: AV: 1.341.227.0, AS: 1.341.227.0, NIS: 1.341.227.0
Engine Version: AM: 1.1.18200.4, NIS: 1.1.18200.4
Date: 2021-06-08 02:39:13
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2021-06-09 19:32:36
Description:
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.
Date: 2021-06-04 19:55:47
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.341.8.0
Previous security intelligence Version: 1.339.1944.0
Update Source: User
Security intelligence Type: AntiSpyware
Update Type: Delta
Current Engine Version: 1.1.18200.4
Previous Engine Version: 1.1.18100.6
Error code: 0x80070666
Error description: Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel.
Date: 2021-06-04 19:55:47
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.341.8.0
Previous security intelligence Version: 1.339.1944.0
Update Source: User
Security intelligence Type: AntiVirus
Update Type: Delta
Current Engine Version: 1.1.18200.4
Previous Engine Version: 1.1.18100.6
Error code: 0x80070666
Error description: Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel.
Date: 2021-06-04 19:55:47
Description:
Microsoft Defender Antivirus has encountered an error trying to update the engine.
New Engine Version: 1.1.18200.4
Previous Engine Version: 1.1.18100.6
Error Code: 0x80070666
Error description: Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel.
Date: 2021-06-04 11:57:12
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.341.8.0
Previous security intelligence Version: 1.339.1944.0
Update Source: User
Security intelligence Type: AntiSpyware
Update Type: Delta
Current Engine Version: 1.1.18200.4
Previous Engine Version: 1.1.18100.6
Error code: 0x80070666
Error description: Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel.
CodeIntegrity:
===============
Date: 2021-06-10 17:53:40
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVG\Antivirus\aswhook.dll that did not meet the Microsoft signing level requirements.
Date: 2021-06-10 17:51:47
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\AVG\Antivirus\AVGSvc.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2021-06-10 17:49:47
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
==================== Memory info ===========================
BIOS: Insyde Corp. V1.07 08/27/2020
Motherboard: CML Stonic_CMS
Processor: Intel(R) Core(TM) i5-10300H CPU @ 2.50GHz
Percentage of memory in use: 63%
Total physical RAM: 16215.05 MB
Available physical RAM: 5953.29 MB
Total Virtual: 22359.05 MB
Available Virtual: 10202.38 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:475.83 GB) (Free:290.73 GB) NTFS
\\?\Volume{c29ed0c9-89ab-4192-9dd4-7e543b2f6a68}\ (Recovery) (Fixed) (Total:1 GB) (Free:0.47 GB) NTFS
\\?\Volume{17af0a60-6f05-4479-a1ae-f93371ade7b0}\ (ESP) (Fixed) (Total:0.09 GB) (Free:0.04 GB) FAT32
\\?\Volume{fff24c39-c45a-11eb-820e-dc41a962b23f}\ (Box) (Network) (Total:475.83 GB) (Free:290.73 GB) FAT32
==================== MBR & Partition Table ====================
==================== End of Addition.txt =======================