Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19.04.2024 01
Ran by cvkbodhi (05-05-2024 02:08:37)
Running from C:\Users\cory_\Desktop
Microsoft Windows 11 Home Version 23H2 22631.3527 (X64) (2024-04-28 23:13:21)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-2987512170-2648485282-3193886151-500 - Administrator - Disabled)
cvkbodhi (S-1-5-21-2987512170-2648485282-3193886151-1001 - Administrator - Enabled) => C:\Users\cory_
DefaultAccount (S-1-5-21-2987512170-2648485282-3193886151-503 - Limited - Disabled)
Guest (S-1-5-21-2987512170-2648485282-3193886151-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2987512170-2648485282-3193886151-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Antivirus (Enabled - Up to date) {18A975F9-A60C-37D8-E30B-4BEF31AD3411}
FW: AVG Antivirus (Enabled) {2092F4DC-EC63-3680-C854-E2DACF7E736A}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
1Password (HKU\S-1-5-21-2987512170-2648485282-3193886151-1001\...\1Password) (Version: 8.10.30 - AgileBits Inc.)
Aloha (HKU\S-1-5-21-2987512170-2648485282-3193886151-1001\...\Aloha Mobile Aloha) (Version: 1.5.0.0 - Aloha Mobile)
Assassin's Creed Origins (HKLM-x32\...\Uplay Install 3539) (Version: - Ubisoft)
AVG Driver Updater (HKLM\...\AVG Driver Updater) (Version: 23.4.4881.12032 - AVG)
AVG Internet Security (HKLM\...\AVG Antivirus) (Version: 24.4.9067.1725 - AVG)
AVG Secure Browser (HKU\S-1-5-21-2987512170-2648485282-3193886151-1001\...\AVG Secure Browser) (Version: 123.0.24828.123 - Gen Digital Inc.)
AVG Secure VPN (HKLM\...\AVG Secure VPN) (Version: 24.4.9914.11248 - AVG)
AVG TuneUp (HKLM\...\AVG TuneUp) (Version: 23.4.15807.8938 - AVG)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Burning Crusade Classic (HKLM-x32\...\Burning Crusade Classic) (Version: - Blizzard Entertainment)
Call of Duty (HKLM-x32\...\Call of Duty) (Version: - Blizzard Entertainment)
CurseForge 1.250.1-17753 (HKU\S-1-5-21-2987512170-2648485282-3193886151-1001\...\ca0e291c-abd4-5fc3-b6a0-3d4333eccbd7) (Version: 1.250.1-17753 - Overwolf)
Documentation Manager (HKLM\...\{51C5ED88-53DF-49F4-9855-0E9949AC7522}) (Version: 23.40.0.4 - Intel Corporation) Hidden
DownloadHelper CoApp (HKLM-x32\...\DownloadHelper CoApp) (Version: 2.0.19.0 - ACLAP)
EA app (HKLM\...\{C2622085-ABD2-49E5-8AB9-D3D6A642C091}) (Version: 13.180.0.5693 - Electronic Arts) Hidden
EA app (HKLM-x32\...\{d473ca0c-6e51-4386-a9d8-0458f243b271}) (Version: 13.180.0.5693 - Electronic Arts)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Intel® Software Installer (HKLM-x32\...\{778be45a-dd41-4bf6-8f9d-409a995d76b2}) (Version: 23.40.0.4 - Intel Corporation) Hidden
Lenovo Vantage Service (HKLM-x32\...\VantageSRV_is1) (Version: 4.0.75.0 - Lenovo Group Ltd.)
Lenovo Welcome (HKLM-x32\...\Lenovo Welcome) (Version: 3.3.2 - Lenovo Group Ltd.)
Malwarebytes version 5.1.3.110 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.1.3.110 - Malwarebytes)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.17425.20176 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 124.0.2478.80 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 124.0.2478.80 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2987512170-2648485282-3193886151-1001\...\OneDriveSetup.exe) (Version: 24.076.0414.0005 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.38.33135 (HKLM-x32\...\{46c3b171-c15c-4137-8e1d-67eeb2985b44}) (Version: 14.38.33135.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.38.33135 (HKLM-x32\...\{9C19C103-7DB1-44D1-A039-2C076A633A38}) (Version: 14.38.33135 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.38.33135 (HKLM-x32\...\{286DC39B-5FB7-4AFF-9DD4-22DB47664CD7}) (Version: 14.38.33135 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.17425.20146 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.17425.20176 - Microsoft Corporation) Hidden
Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment)
Plants vs Zombies Battle for Neighborville (HKLM-x32\...\{2071E3B5-A619-4F7E-B560-1769ABD91DCD}) (Version: 1.0.55.50001 - Electronic Arts)
Plex (HKLM-x32\...\Plex) (Version: 1.91.0 - Plex, Inc.)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9279.1 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 5.2.6 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 5.2.6 - VS Revo Group, Ltd.)
Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 145.1.10933 - Ubisoft)
Warcraft III (HKLM-x32\...\Warcraft III) (Version: - Blizzard Entertainment)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
World of Warcraft Classic Era (HKLM-x32\...\World of Warcraft Classic Era) (Version: - Blizzard Entertainment)
Packages:
=========
Apple Music -> C:\Program Files\WindowsApps\AppleInc.AppleMusicWin_1.1030.21762.0_x64__nzyj5cx40ttqa [2024-04-27] (Apple Inc.)
Apple TV -> C:\Program Files\WindowsApps\AppleInc.AppleTVWin_1.1030.21762.0_x64__nzyj5cx40ttqa [2024-04-28] (Apple Inc.)
AppleInc.AppleDevices -> C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1030.21762.0_x64__nzyj5cx40ttqa [2024-04-27] (Apple Inc.) [Startup Task]
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5435.0_x64__8j3eq9eme6ctt [2024-04-26] (INTEL CORP) [Startup Task]
DuckDuckGo -> C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.78.1.0_x64__ya2fgkz3nks94 [2024-05-02] (DuckDuckGo) [Startup Task]
DuckDuckGo VPN -> C:\Program Files\WindowsApps\DuckDuckGo.VPN_0.23.0.0_x64__ya2fgkz3nks94 [2024-04-28] (DuckDuckGo)
Instagram -> C:\Program Files\WindowsApps\Facebook.InstagramBeta_42.0.23.0_neutral__8xx8rvfyw5nnt [2024-04-28] (Instagram)
Lenovo Companion -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2403.25.0_x64__k1h2ywk1493x8 [2024-04-27] (LENOVO INC.)
Microsoft Defender -> C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2403.21002.0_x64__8wekyb3d8bbwe [2024-05-04] (Microsoft Corporation) [Startup Task]
Microsoft.WindowsAppRuntime.CBS -> C:\Windows\SystemApps\Microsoft.WindowsAppRuntime.CBS_8wekyb3d8bbwe [2024-04-28] (Microsoft Corporation)
MicrosoftWindows.Client.FileExp -> C:\Windows\SystemApps\MicrosoftWindows.Client.FileExp_cw5n1h2txyewy [2024-04-28] (Microsoft Windows)
MicrosoftWindows.Client.LKG -> C:\Windows\SystemApps\MicrosoftWindows.Client.LKG_cw5n1h2txyewy [2024-04-28] (Microsoft Windows)
Pinterest -> C:\Program Files\WindowsApps\1424566A.147190DF3DE79_1.1.1.0_neutral__5byw4zywtsh80 [2024-04-28] (Pinterest Inc.)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.1.137.0_x64__dt26b99r8h8gj [2024-04-26] (Realtek Semiconductor Corp)
Reddit -> C:\Program Files\WindowsApps\redditTV.Reddit_1.0.1.0_neutral__99kbdge22ed1a [2024-04-28] (Reddit Inc.)
Secure Folder, Files and Encrypt -> C:\Program Files\WindowsApps\15675MedhaChaitanya.FileLockEncrypt_3.75.63.0_x64__44hy61fym8r9t [2024-04-27] (MedhaChaitanya)
Sirius XM Radio Inc. -> C:\Program Files\WindowsApps\SiriusXM.SiriusXM_4.8.4.0_x64__rb1gq5s0htdrw [2024-04-28] (Sirius XM Radio Inc)
Speedtest by Ookla -> C:\Program Files\WindowsApps\Ookla.SpeedtestbyOokla_1.18.194.0_x64__43tkc6nmykmb6 [2024-04-28] (Ookla)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0 [2024-04-28] (Spotify AB) [Startup Task]
TikTok -> C:\Program Files\WindowsApps\BytedancePte.Ltd.TikTok_1.0.5.0_neutral__6yccndn6064se [2024-04-28] (Bytedance Pte. Ltd.)
Tumblr -> C:\Program Files\WindowsApps\22490Automattic.Tumblr_1.0.1.0_neutral__9h07f78gwnchp [2024-04-28] (Automattic, Inc.)
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.TWITTER_7.0.1.0_neutral__wgeqdkkx372wm [2024-04-28] (Twitter Inc.)
WindowsAppRuntime.1.2-preview1 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.2-preview1_2000.609.1413.0_x64__8wekyb3d8bbwe [2024-05-02] (Microsoft Corporation)
WindowsAppRuntime.1.2-preview1 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.2-preview1_2000.609.1413.0_x86__8wekyb3d8bbwe [2024-05-02] (Microsoft Corporation)
YouTube -> C:\Program Files\WindowsApps\www.youtube.com-54E21B02_1.0.0.0_neutral__pd8mbgmqs65xy [2024-05-04] (
www.youtube.com)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2987512170-2648485282-3193886151-1001_Classes\CLSID\{685174F1-6D52-4FE0-AFB8-28BE41DF11AB}\localserver32 -> C:\Users\cory_\AppData\Local\Aloha Mobile\Aloha\Application\1.5.0.0\notification_helper.exe (Aloha Mobile Ltd. -> Aloha Mobile)
CustomCLSID: HKU\S-1-5-21-2987512170-2648485282-3193886151-1001_Classes\CLSID\{A725D612-7D72-48B8-857A-4777781F415C}\localserver32 -> C:\Users\cory_\AppData\Local\AVG\Browser\Application\123.0.24828.123\notification_helper.exe (AVG Technologies USA, LLC -> Gen Digital Inc.)
CustomCLSID: HKU\S-1-5-21-2987512170-2648485282-3193886151-1001_Classes\CLSID\{B43D36BF-EC45-440E-8FDA-E8CDDA458D1C}\InprocServer32 -> C:\Users\cory_\AppData\Local\AVG\Browser\Update\1.8.1693.6\psuser_64.dll (AVG Technologies USA, LLC -> Gen Digital Inc.)
CustomCLSID: HKU\S-1-5-21-2987512170-2648485282-3193886151-1001_Classes\CLSID\{C9D22417-34EB-416B-BE82-31D5660097D6}\InprocServer32 -> C:\Users\cory_\AppData\Local\AVG\Browser\Update\1.8.1693.6\psuser_64.dll (AVG Technologies USA, LLC -> Gen Digital Inc.)
ShellIconOverlayIdentifiers: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2024-05-03] (AVG Technologies USA, LLC -> Gen Digital Inc.)
ShellIconOverlayIdentifiers-x32: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2024-05-03] (AVG Technologies USA, LLC -> Gen Digital Inc.)
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2024-05-03] (AVG Technologies USA, LLC -> Gen Digital Inc.)
ContextMenuHandlers3: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2024-05-03] (AVG Technologies USA, LLC -> Gen Digital Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2024-04-27] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2024-05-03] (AVG Technologies USA, LLC -> Gen Digital Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2024-04-27] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2022-04-04] (VS Revo Group Ltd. -> VS Revo Group)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\cory_\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\47ea3330b0f0d7a6\AVG Secure Browser.lnk -> C:\Users\cory_\AppData\Local\AVG\Browser\Application\AVGBrowser.exe (Gen Digital Inc.) -> --profile-directory=Default
ShortcutWithArgument: C:\Users\cory_\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\188f5ec9d11ded56\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) -> --profile-directory="Profile 1"
==================== Loaded Modules (Whitelisted) =============
2024-04-27 17:52 - 2024-04-27 17:53 - 165248000 _____ () [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\libcef.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000379392 _____ () [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\libegl.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 006679040 _____ () [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\libglesv2.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 004325888 _____ () [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\vk_swiftshader.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 001166336 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\chrome_elf.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000046080 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\audio\qtaudio_windows.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000030720 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\iconengines\qsvgicon.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000027136 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\imageformats\qgif.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000025600 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\imageformats\qico.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000353280 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\imageformats\qjpeg.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000021504 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\imageformats\qsvg.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000352256 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\imageformats\qtiff.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000423424 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\imageformats\qwebp.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 001239552 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\platforms\qwindows.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 005550592 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\Qt5Core.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 005812736 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\Qt5Gui.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000594944 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\Qt5Multimedia.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000915456 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\Qt5Network.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 003046400 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\Qt5Qml.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000362496 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\Qt5QmlModels.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 003650560 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\Qt5Quick.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000262144 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\Qt5Svg.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 004702208 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\Qt5Widgets.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000220160 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\Qt5WinExtras.dll
2024-04-27 17:52 - 2024-04-27 17:52 - 000165888 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.14792\Qt5Xml.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\avgSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\avgSP.sys => ""="Driver"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-05-02] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2022-05-07 01:24 - 2022-05-07 01:22 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2987512170-2648485282-3193886151-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\cory_\OneDrive\Pictures\Saved Pictures\Wallpapers\macOS-High-Sierra-Wallpaper-2880x1494-scaled.jpg
DNS Servers: 10.64.0.1 - 192.168.4.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-2987512170-2648485282-3193886151-1001\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-2987512170-2648485282-3193886151-1001\...\StartupApproved\Run: => "Discord"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{C9DF2DA0-35D1-4192-AD65-D3C293548DD1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{CB5F8481-55EA-491C-85D7-28E7D9785678}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{6ED886B7-6EE3-4180-BD0F-4B384263B4DD}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{7A6563C2-4EBB-4862-96AF-06854BD6AEEE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{61EC9851-15E2-4F0E-B45B-20DBD0C6B787}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{AA6EC424-CB85-413F-BED5-44C8231E4AE3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{D3C0B396-2AEF-417F-BF3B-946B3FC34A0F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{2910BC81-9052-405B-B7F6-70E504093009}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{CBA2D6DB-3663-4E04-9543-85713DD8BFBD}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{14EE5C99-A83E-495D-8806-74F5CF75445B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{FBF52E75-0F4B-4C0F-AAD2-A02F53366998}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALaunchHelper.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{3BBC71DE-2135-4C8A-B58B-005123B1BFBF}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{061D9325-B51D-4612-A17C-CA05B8B6FCDE}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{116979AE-8E98-44DF-BDFE-43B485EE29B8}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAGEP.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{C512E8EA-1891-4270-9A7C-BF1AD2CE5FCC}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAGEP.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{DCD4ED0C-5D9F-4EB4-9F9F-FB88C2FAC864}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{0AD161EE-3B43-4214-9304-40B2F3BCFBB0}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{D1E38FE4-B6C9-489A-93AF-6B43C86EBF45}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{E91903D9-7E11-424A-BEB4-D06D3420F92D}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{02AD0A10-86E1-4904-BC31-634DF9C7AC64}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{A1DCF859-3FD1-45A9-A869-8FEF42FA08CA}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{6C72543D-6C73-4DEF-8111-0B44506C1BBD}] => (Allow) C:\Program Files\WindowsApps\AppleInc.AppleTVWin_1.1030.21762.0_x64__nzyj5cx40ttqa\AppleTV.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{48305AC5-7D67-4FD0-AE34-81DFA27158B2}] => (Allow) C:\Program Files\WindowsApps\AppleInc.AppleTVWin_1.1030.21762.0_x64__nzyj5cx40ttqa\AppleTV.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{45F9CF8B-146F-4584-971A-80C8E612ACF2}] => (Allow) C:\Program Files\EA Games\PVZ Battle for Neighborville\EAAntiCheat.GameServiceLauncher.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{9E5CBCC3-43E6-49D6-BD99-A3F6167DB40A}] => (Allow) C:\Program Files\EA Games\PVZ Battle for Neighborville\EAAntiCheat.GameServiceLauncher.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{9CFCBA78-506A-4262-B3ED-610C3B4C8A55}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24060.3102.2733.5911_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D5DD904D-351F-4CEE-804A-6CFF9F9360E0}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24060.3102.2733.5911_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B43C7975-DEB0-4CDF-A66C-48AE6A9220F4}] => (Allow) C:\Program Files\AVG\Antivirus\AVGUI.exe (AVG Technologies USA, LLC -> Gen Digital Inc.)
FirewallRules: [{A1047370-463F-4ABC-8B36-B031E813FEE7}] => (Allow) C:\Program Files\AVG\Antivirus\AVGUI.exe (AVG Technologies USA, LLC -> Gen Digital Inc.)
FirewallRules: [{0756CF5D-D5EE-4FFD-BD2E-8572637829E1}] => (Allow) C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1030.21762.0_x64__nzyj5cx40ttqa\AppleMobileDeviceLauncher.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{235FA1F5-CCEA-472D-BAD0-6F84AD8A2B92}] => (Allow) C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1030.21762.0_x64__nzyj5cx40ttqa\AppleMobileDeviceLauncher.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{42E9EEFD-D827-4E2D-90AE-22DD03E37A62}] => (Allow) C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1030.21762.0_x64__nzyj5cx40ttqa\AMPDevicesAgent.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{C262BB8F-C009-48DB-97F7-7E221D47B39B}] => (Allow) C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1030.21762.0_x64__nzyj5cx40ttqa\AMPDevicesAgent.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{5C2786E4-AEAF-4CF8-8FDB-6A47C568EC19}] => (Allow) C:\Program Files\WindowsApps\AppleInc.AppleMusicWin_1.1030.21762.0_x64__nzyj5cx40ttqa\AppleMusic.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{2362AB56-26B2-4E41-AF18-94E5A26D72F8}] => (Allow) C:\Program Files\WindowsApps\AppleInc.AppleMusicWin_1.1030.21762.0_x64__nzyj5cx40ttqa\AppleMusic.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{C7160EEF-7E99-40BB-A819-3C9E93C09154}] => (Allow) C:\Program Files\WindowsApps\AppleInc.AppleMusicWin_1.1030.21762.0_x64__nzyj5cx40ttqa\AMPLibraryAgent.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{BB96C08F-5EAB-44BC-A376-DF9DF64B79A2}] => (Allow) C:\Program Files\WindowsApps\AppleInc.AppleMusicWin_1.1030.21762.0_x64__nzyj5cx40ttqa\AMPLibraryAgent.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{8CAF6D73-2D62-4D5B-9FF9-BE979A0EF878}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CF51217B-E2F1-4C28-8B1C-DD4EE0F387B6}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.78.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe (Duck Duck Go, Inc. -> Microsoft Corporation)
FirewallRules: [{902A264B-7D04-43ED-9E10-9F45424142D6}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.78.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe (Duck Duck Go, Inc. -> Microsoft Corporation)
FirewallRules: [{4C5D7E3B-CD6E-451F-9011-8A51B74D13CF}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\124.0.2478.80\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{216D51AF-C784-4A93-BF27-2DC14F569D13}] => (Allow) C:\Program Files\AVG\TuneUp\TuneupUI.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
FirewallRules: [{BE677AD9-AB2F-41F5-9F7F-3715FF307C47}] => (Allow) C:\Program Files\AVG\TuneUp\TuneupUI.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
FirewallRules: [{17919D91-DA31-40A8-BE16-5F95FCC8E5AF}] => (Allow) C:\Program Files\AVG\Driver Updater\DriverUpdUI.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
FirewallRules: [{B29DC623-6B6F-434A-AAB6-71E14F860182}] => (Allow) C:\Program Files\AVG\Driver Updater\DriverUpdUI.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
FirewallRules: [{4CAF8F02-004A-42C8-96DA-00B53F4CAA8D}] => (Allow) C:\Program Files\AVG\Secure VPN\Vpn.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
FirewallRules: [{41CE4D60-982E-4F7E-80CB-DBAA47762BF9}] => (Allow) C:\Program Files\AVG\Secure VPN\Vpn.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
==================== Restore Points =========================
04-05-2024 00:35:11 Revo Uninstaller Pro's restore point - Aloha
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (05/05/2024 01:59:55 AM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Faulting application name: svchost.exe_wuauserv, version: 10.0.22621.1, time stamp: 0x6dc5c2a5
Faulting module name: ntdll.dll, version: 10.0.22621.3527, time stamp: 0x92b2df34
Exception code: 0xc0000005
Fault offset: 0x0000000000026abf
Faulting process id: 0x0x4048
Faulting application start time: 0x0x1da9eb17352e79c
Faulting application path: C:\WINDOWS\system32\svchost.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 6892d6e9-28d8-4f96-8882-0c9a80c85d71
Faulting package full name:
Faulting package-relative application ID:
Error: (05/05/2024 01:58:51 AM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Faulting application name: svchost.exe_wuauserv, version: 10.0.22621.1, time stamp: 0x6dc5c2a5
Faulting module name: ntdll.dll, version: 10.0.22621.3527, time stamp: 0x92b2df34
Exception code: 0xc0000005
Fault offset: 0x0000000000026abf
Faulting process id: 0x0x44d0
Faulting application start time: 0x0x1da9eb14ae091bd
Faulting application path: C:\WINDOWS\system32\svchost.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 4400155d-6114-4b4d-9a42-6d88bff43e6c
Faulting package full name:
Faulting package-relative application ID:
Error: (05/05/2024 12:53:33 AM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Faulting application name: svchost.exe_wuauserv, version: 10.0.22621.1, time stamp: 0x6dc5c2a5
Faulting module name: ntdll.dll, version: 10.0.22621.3527, time stamp: 0x92b2df34
Exception code: 0xc0000005
Fault offset: 0x0000000000026abf
Faulting process id: 0x0x51b4
Faulting application start time: 0x0x1da9ea82def60fb
Faulting application path: C:\WINDOWS\system32\svchost.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: f1038677-5b0c-4fa1-aac8-e28381e147d9
Faulting package full name:
Faulting package-relative application ID:
Error: (05/04/2024 07:28:20 AM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Faulting application name: svchost.exe_wuauserv, version: 10.0.22621.1, time stamp: 0x6dc5c2a5
Faulting module name: ntdll.dll, version: 10.0.22621.3527, time stamp: 0x92b2df34
Exception code: 0xc0000005
Fault offset: 0x0000000000026abf
Faulting process id: 0x0x1f20
Faulting application start time: 0x0x1da9e162a1754a8
Faulting application path: C:\WINDOWS\system32\svchost.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 5d6aee8c-034a-4f77-aa06-6dd585abf53a
Faulting package full name:
Faulting package-relative application ID:
Error: (05/04/2024 06:26:24 AM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Faulting application name: svchost.exe_wuauserv, version: 10.0.22621.1, time stamp: 0x6dc5c2a5
Faulting module name: ntdll.dll, version: 10.0.22621.3527, time stamp: 0x92b2df34
Exception code: 0xc0000005
Fault offset: 0x0000000000026abf
Faulting process id: 0x0x4598
Faulting application start time: 0x0x1da9e0d82fe0ce3
Faulting application path: C:\WINDOWS\system32\svchost.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 5b3dbf23-3148-47fa-8d0f-88b8463de419
Faulting package full name:
Faulting package-relative application ID:
Error: (05/04/2024 02:56:27 AM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Faulting application name: svchost.exe_wuauserv, version: 10.0.22621.1, time stamp: 0x6dc5c2a5
Faulting module name: ntdll.dll, version: 10.0.22621.3527, time stamp: 0x92b2df34
Exception code: 0xc0000005
Fault offset: 0x0000000000026abf
Faulting process id: 0x0x3514
Faulting application start time: 0x0x1da9df02c3b2e99
Faulting application path: C:\WINDOWS\system32\svchost.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 0a4995f4-d053-4287-9c29-795972d99221
Faulting package full name:
Faulting package-relative application ID:
Error: (05/04/2024 02:22:17 AM) (Source: DuckDuckGo.VPN) (EventID: 0) (User: )
Description: Category: NetworkProtection.Grpc.ConnectionService
EventId: 0
SpanId: 58241ebd731e70ed
TraceId: 9635d510f8367ee8ae4baa073730daef
ParentId: 0000000000000000
ConnectionId: 0HN3BVUALNCDQ
RequestId: 0HN3BVUALNCDQ:00000003
RequestPath: /NetworkProtection.Grpc.Services.ConnectionService/GetLocations
Failed to retrieve vpn locations
Exception:
System.Net.Http.HttpRequestException: No such host is known. (controller.netp.duckduckgo.com:443)
---> System.Net.Sockets.SocketException (11001): No such host is known.
at System.Net.Sockets.Socket.AwaitableSocketAsyncEventArgs.ThrowException(SocketError error, CancellationToken cancellationToken)
at System.Net.Sockets.Socket.AwaitableSocketAsyncEventArgs.System.Threading.Tasks.Sources.IValueTaskSource.GetResult(Int16 token)
at System.Net.Sockets.Socket.<ConnectAsync>g__WaitForConnectWithCancellation|277_0(AwaitableSocketAsyncEventArgs saea, ValueTask connectTask, CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.ConnectToTcpHostAsync(String host, Int32 port, HttpRequestMessage initialRequest, Boolean async, CancellationToken cancellationToken)
--- End of inner exception stack trace ---
at System.Net.Http.HttpConnectionPool.ConnectToTcpHostAsync(String host, Int32 port, HttpRequestMessage initialRequest, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.ConnectAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.CreateHttp11ConnectionAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.AddHttp11ConnectionAsync(HttpRequestMessage request)
at System.Threading.Tasks.TaskCompletionSourceWithCancellation`1.WaitWithCancellationAsync(CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.GetHttp11ConnectionAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.SendWithVersionDetectionAndRetryAsync(HttpRequestMessage request, Boolean async, Boolean doRequestAuth, CancellationToken cancellationToken)
at System.Net.Http.DiagnosticsHandler.SendAsyncCore(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.RedirectHandler.SendAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at Microsoft.Extensions.Http.Logging.LoggingHttpMessageHandler.<SendAsync>g__Core|5_0(HttpRequestMessage request, CancellationToken cancellationToken)
at Microsoft.Extensions.Http.Logging.LoggingScopeHttpMessageHandler.<SendAsync>g__Core|5_0(HttpRequestMessage request, CancellationToken cancellationToken)
at System.Net.Http.HttpClient.<SendAsync>g__Core|83_0(HttpRequestMessage request, HttpCompletionOption completionOption, CancellationTokenSource cts, Boolean disposeCts, CancellationTokenSource pendingRequestsCts, CancellationToken originalCancellationToken)
at NetworkProtection.Backend.ApiClient.GetLocations(String authToken, CancellationToken cancellationToken) in C:\actions-runner\_work\windows-browser\windows-browser\NetworkProtection\NetworkProtection\Backend\ApiClient.cs:line 64
at DuckDuckGo.Windows.Extensions.TaskExtensions.RetryWhen[T](Func`2 taskFactory, UInt32 retryCount, Func`2 canRetry, Func`2 backOffStrategy, CancellationToken cancellationToken) in C:\actions-runner\_work\windows-browser\windows-browser\DuckDuckGo.Windows\Extensions\TaskExtensions.cs:line 0
at NetworkProtection.Grpc.ConnectionService.GetLocationsAsync(String authToken, CallContext context) in C:\actions-runner\_work\windows-browser\windows-browser\NetworkProtection\NetworkProtection\Grpc\ConnectionService.cs:line 77
Error: (05/04/2024 01:40:21 AM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Faulting application name: svchost.exe_wuauserv, version: 10.0.22621.1, time stamp: 0x6dc5c2a5
Faulting module name: ntdll.dll, version: 10.0.22621.3527, time stamp: 0x92b2df34
Exception code: 0xc0000005
Fault offset: 0x0000000000026abf
Faulting process id: 0x0x25f4
Faulting application start time: 0x0x1da9de58d1468bf
Faulting application path: C:\WINDOWS\system32\svchost.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 910ffa84-7f9f-4d8a-ac74-70a2d5fba148
Faulting package full name:
Faulting package-relative application ID:
System errors:
=============
Error: (05/05/2024 01:59:56 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Update service terminated unexpectedly. It has done this 5 time(s).
Error: (05/05/2024 01:58:52 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Update service terminated unexpectedly. It has done this 4 time(s).
Error: (05/05/2024 12:53:34 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Update service terminated unexpectedly. It has done this 3 time(s).
Error: (05/04/2024 11:24:37 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: )
Description: Miniport Microsoft Wi-Fi Direct Virtual Adapter #5, {16be7513-5637-4096-86db-a3b2f7c67c91}, had event 74
Error: (05/04/2024 07:28:23 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Update service terminated unexpectedly. It has done this 2 time(s).
Error: (05/04/2024 06:26:26 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
Error: (05/04/2024 06:25:34 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 4:26:57 AM on ‎5/‎4/‎2024 was unexpected.
Error: (05/04/2024 06:25:18 AM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT AUTHORITY)
Description: 3221225684A fatal error occurred processing the restoration data.
Windows Defender:
================
Date: 2024-05-02 15:47:31
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2024-05-02 14:38:54
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2024-05-02 13:04:45
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
CodeIntegrity:
===============
Date: 2024-05-05 02:06:06
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Windows signing level requirements.
==================== Memory info ===========================
BIOS: LENOVO O4HKT3BA 01/16/2023
Motherboard: LENOVO 370A
Processor: Intel(R) Core(TM) i5-10400 CPU @ 2.90GHz
Percentage of memory in use: 41%
Total physical RAM: 20232.07 MB
Available physical RAM: 11753.22 MB
Total Virtual: 23688.07 MB
Available Virtual: 14902.1 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:930.59 GB) (Free:398.88 GB) (Model: Samsung SSD 980 1TB) (Protected) NTFS
Drive d: (G930) (Fixed) (Total:931.5 GB) (Free:655.13 GB) (Model: ST1000DM003-1SB102) (Protected) NTFS
\\?\Volume{222fc970-fb27-47c7-b72f-978ad70a7d9f}\ () (Fixed) (Total:0.81 GB) (Free:0.08 GB) NTFS
\\?\Volume{a57434e5-24e2-4bf0-89b0-3352e2cbc097}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: DBB830C4)
Partition: GPT.
==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: 0C9E5D33)
Partition: GPT.
==================== End of Addition.txt =======================