whenever i connect to the internet the screen freezes and says blocked. i use a surface pro please any held will be appreciated. i tried blocking the application with windows defender but not much of a success.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-10-2023
Ran by Lawbitss (administrator) on DESKTOP-UAVRUKD (Microsoft Corporation Surface Pro) (22-10-2023 06:06:29)
Running from C:\Users\Lawbitss\Downloads\FRST64.exe
Loaded Profiles: Lawbitss
Platform: Microsoft Windows 10 Pro Version 20H2 19042.631 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <8>
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\64kb8682.inf_amd64_170ccd25b9699b84\IntelCpHDCPSvc.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\64kb8682.inf_amd64_170ccd25b9699b84\IntelCpHeciSvc.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SppExtComObj.Exe
(svchost.exe ->) (Skype Software Sarl -> ) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.77.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
(svchost.exe ->) (Skype Software Sarl -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.77.0_x64__kzf8qxf38zg5c\SkypeApp.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\66.0.3359.181\Installer\chrmstp.exe [2023-10-21] (Google Inc -> Google Inc.)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {D87E5EB4-ACC7-4506-9427-2E3908B505E6} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\Explorer.exe [4651032 2020-11-18] (Microsoft Windows -> Microsoft Corporation)
Task: {D1043206-1B00-42F0-A330-B512E1BC62FF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2023-10-21] (Google Inc -> Google Inc.)
Task: {AB607F1F-8610-4273-9221-E89D9CA131F3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2023-10-21] (Google Inc -> Google Inc.)
Task: {4624C1FE-1AAC-4D71-922B-0DB37E570544} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [5967976 2015-08-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {7AD49054-8A7B-42BC-9248-6AA3A564E85D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [5967976 2015-08-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {D981553F-D4D4-4019-BD2E-7F71475E7F06} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [418384 2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {176925E8-F45E-459E-8E64-093C313A7879} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [418384 2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {683067CE-DD30-4743-9BF7-2F39473681DC} - System32\Tasks\R@1n-KMS\Office365ProPlus => C:\Windows\System32\Wbem\wmic.exe [526848 2019-12-07] (Microsoft Windows -> Microsoft Corporation) -> path SoftwareLicensingProduct where (ID="d450596f-894d-49e0-966a-fd39ed4c4c64") call Activate
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.207.187
Tcpip\..\Interfaces\{efa46f2b-35fd-4701-b41e-21d03c34b087}: [DhcpNameServer] 192.168.207.187
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Lawbitss\AppData\Local\Microsoft\Edge\User Data\Default [2023-10-22]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.19 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2023-10-21] (Google Inc -> Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2023-10-21] (Google Inc -> Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default [2023-10-22]
CHR Extension: (Docs) - C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2023-10-22]
CHR Extension: (Google Drive) - C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2023-10-22]
CHR Extension: (YouTube) - C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2023-10-22]
CHR Extension: (Google Docs Offline) - C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-10-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-10-22]
CHR Extension: (Gmail) - C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2023-10-22]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2776664 2015-08-16] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5101992 2020-11-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-10-22 06:06 - 2023-10-22 06:07 - 000009269 _____ C:\Users\Lawbitss\Downloads\FRST.txt
2023-10-22 06:04 - 2023-10-22 06:06 - 000000000 ____D C:\FRST
2023-10-22 06:04 - 2023-10-22 06:04 - 002383360 _____ (Farbar) C:\Users\Lawbitss\Downloads\FRST64.exe
2023-10-22 06:03 - 2023-10-22 06:03 - 002084352 _____ (Farbar) C:\Users\Lawbitss\Downloads\FRST.exe
2023-10-22 05:42 - 2023-10-22 05:42 - 000003662 _____ C:\Windows\system32\Tasks\CreateExplorerShellUnelevatedTask
2023-10-22 05:42 - 2023-10-22 05:42 - 000001962 _____ C:\Users\Lawbitss\Desktop\kprm-20231022054207.txt
2023-10-22 05:42 - 2023-10-22 05:42 - 000000000 ____D C:\KPRM
2023-10-22 04:52 - 2023-10-22 04:52 - 000022932 ____N C:\Windows\SysWOW64\rpcnetp.exe
2023-10-22 04:52 - 2023-10-22 04:52 - 000022932 _____ C:\Windows\SysWOW64\rpcnetp.dll
2023-10-22 04:52 - 2023-10-22 04:52 - 000022932 _____ C:\Windows\system32\tik.exe
2023-10-21 19:42 - 2023-10-21 19:42 - 000000748 _____ C:\Users\Lawbitss\Desktop\Videos - Shortcut.lnk
2023-10-21 19:23 - 2023-10-21 19:23 - 000000000 ____D C:\Windows\system32\Tasks\Agent Activation Runtime
2023-10-21 18:58 - 2023-10-21 19:23 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\D3DSCache
2023-10-21 17:23 - 2023-10-21 16:25 - 000000000 ____D C:\Windows\Panther
2023-10-21 17:21 - 2023-10-21 19:23 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\vlc
2023-10-21 17:05 - 2023-10-21 17:05 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\UProof
2023-10-21 17:05 - 2023-10-21 17:05 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Proof
2023-10-21 17:04 - 2023-10-21 17:05 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Office
2023-10-21 17:04 - 2023-10-21 17:04 - 000003416 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2023-10-21 17:04 - 2023-10-21 17:04 - 000003292 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2023-10-21 17:04 - 2023-10-21 17:04 - 000002373 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-10-21 17:04 - 2023-10-21 17:04 - 000002332 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2023-10-21 17:04 - 2023-10-21 17:04 - 000000916 _____ C:\Users\Public\Desktop\VLC media player.lnk
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Word
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Document Building Blocks
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Bibliography
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\AddIns
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\Google
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\Program Files (x86)\Google
2023-10-21 17:03 - 2023-10-21 17:03 - 000002451 _____ C:\Users\Lawbitss\Desktop\Word 2016.lnk
2023-10-21 17:03 - 2023-10-21 17:03 - 000002450 _____ C:\Users\Lawbitss\Desktop\PowerPoint 2016.lnk
2023-10-21 17:03 - 2023-10-21 17:03 - 000002413 _____ C:\Users\Lawbitss\Desktop\Excel 2016.lnk
2023-10-21 17:03 - 2023-10-21 17:03 - 000000000 ____D C:\Program Files\VideoLAN
2023-10-21 17:02 - 2023-10-21 17:02 - 000003584 _____ C:\Windows\KMS-QADhook.dll
2023-10-21 17:02 - 2023-10-21 17:02 - 000000000 ____D C:\Windows\system32\Tasks\R@1n-KMS
2023-10-21 17:02 - 2023-10-21 17:02 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\PeerDistRepub
2023-10-21 17:02 - 2023-10-21 17:02 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\mpress
2023-10-21 17:00 - 2023-10-21 17:00 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2023-10-21 16:52 - 2023-10-21 16:52 - 000002492 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002456 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002414 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002413 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002407 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002401 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002393 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2023-10-21 16:50 - 2023-10-21 16:52 - 000000000 ____D C:\Program Files\Microsoft Office
2023-10-21 16:50 - 2023-10-21 16:50 - 000000000 ____D C:\Program Files\Microsoft Office 15
2023-10-21 16:49 - 2023-10-21 16:49 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\Comms
2023-10-21 16:40 - 2023-10-21 16:40 - 000000000 ____D C:\Users\Lawbitss\AppData\LocalLow\Intel
2023-10-21 16:39 - 2023-10-21 16:39 - 000000000 ____D C:\Windows\system32\Intel
2023-10-21 16:38 - 2023-10-21 16:47 - 000000000 ____D C:\ProgramData\Intel
2023-10-21 16:38 - 2023-10-21 16:38 - 000000000 ____D C:\Windows\LastGood.Tmp
2023-10-21 16:38 - 2023-10-21 16:38 - 000000000 ____D C:\Program Files\Intel
2023-10-21 16:38 - 2023-10-21 16:38 - 000000000 _____ C:\Windows\system32\GfxValDisplayLog.bin
2023-10-21 16:36 - 2023-10-21 16:36 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\MMC
2023-10-21 16:36 - 2023-10-21 16:36 - 000000000 ____D C:\Program Files\Reference Assemblies
2023-10-21 16:36 - 2023-10-21 16:36 - 000000000 ____D C:\Program Files\MSBuild
2023-10-21 16:36 - 2023-10-21 16:36 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2023-10-21 16:36 - 2023-10-21 16:36 - 000000000 ____D C:\Program Files (x86)\MSBuild
2023-10-21 16:35 - 2023-10-21 16:35 - 000003382 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4272348530-104420464-272258208-1001
2023-10-21 16:35 - 2023-10-21 16:35 - 000001074 _____ C:\Users\Lawbitss\Desktop\WinRAR.lnk
2023-10-21 16:35 - 2023-10-21 16:35 - 000000000 ___RD C:\Users\Lawbitss\OneDrive
2023-10-21 16:35 - 2023-10-21 16:35 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2023-10-21 16:35 - 2023-10-21 16:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2023-10-21 16:35 - 2023-10-21 16:35 - 000000000 ____D C:\Program Files (x86)\WinRAR
2023-10-21 16:32 - 2023-10-21 16:48 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\Packages
2023-10-21 16:32 - 2023-10-21 16:35 - 000002372 _____ C:\Users\Lawbitss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-10-21 16:32 - 2023-10-21 16:35 - 000000000 ____D C:\Users\Lawbitss
2023-10-21 16:32 - 2023-10-21 16:32 - 000000020 ___SH C:\Users\Lawbitss\ntuser.ini
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ___SD C:\Users\Lawbitss\AppData\Roaming\Microsoft\SystemCertificates
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ___SD C:\Users\Lawbitss\AppData\Roaming\Microsoft\Protect
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ___SD C:\Users\Lawbitss\AppData\Roaming\Microsoft\Crypto
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ___SD C:\Users\Lawbitss\AppData\Roaming\Microsoft\Credentials
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ___RD C:\Users\Lawbitss\3D Objects
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Windows
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Vault
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Spelling
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Network
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Adobe
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\VirtualStore
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\Publishers
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\ConnectedDevicesPlatform
2023-10-21 16:28 - 2023-10-21 16:28 - 000000000 ____D C:\Windows\CSC
2023-10-21 16:24 - 2023-10-21 16:24 - 000002850 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4272348530-104420464-272258208-500
2023-10-21 16:24 - 2023-10-21 16:24 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2023-10-21 16:23 - 2023-10-22 04:52 - 000034160 _____ C:\Windows\system32\wpbbin.exe
2023-10-21 02:56 - 2023-10-21 02:56 - 000000000 ___HD C:\$WinREAgent
2023-10-20 10:31 - 2023-10-20 10:31 - 044432408 _____ C:\Users\Lawbitss\Downloads\vlc-3.0.19-win64.exe
2023-10-20 10:20 - 2023-10-20 10:20 - 001373744 _____ (Google LLC) C:\Users\Lawbitss\Downloads\ChromeSetup.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-10-22 05:42 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-10-22 04:57 - 2020-11-19 00:54 - 000840838 _____ C:\Windows\system32\PerfStringBackup.INI
2023-10-22 04:57 - 2019-12-07 02:13 - 000000000 ____D C:\Windows\INF
2023-10-22 04:52 - 2023-03-25 17:20 - 000008192 ___SH C:\DumpStack.log.tmp
2023-10-22 04:52 - 2020-11-19 00:43 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2023-10-22 04:52 - 2019-12-07 02:14 - 000000000 ____D C:\Windows\ServiceState
2023-10-22 04:52 - 2019-12-07 02:03 - 000262144 _____ C:\Windows\system32\config\BBI
2023-10-22 04:51 - 2020-11-19 00:43 - 000000000 ____D C:\Windows\system32\SleepStudy
2023-10-21 19:26 - 2019-12-07 02:14 - 000000000 ____D C:\Windows\LiveKernelReports
2023-10-21 17:23 - 2019-12-07 02:14 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2023-10-21 17:20 - 2020-11-19 00:43 - 000435248 _____ C:\Windows\system32\FNTCACHE.DAT
2023-10-21 17:01 - 2019-12-07 02:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2023-10-21 17:01 - 2019-12-07 02:14 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2023-10-21 17:00 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2023-10-21 16:58 - 2019-12-07 02:14 - 000000000 ____D C:\Windows\AppReadiness
2023-10-21 16:48 - 2019-12-07 02:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-10-21 16:36 - 2019-12-07 02:03 - 000000000 ____D C:\Windows\CbsTemp
2023-10-21 16:33 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\USOPrivate
2023-10-21 16:32 - 2020-11-19 00:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2023-10-21 16:28 - 2019-12-07 02:51 - 000000000 ____D C:\Windows\system32\FxsTmp
2023-10-21 16:26 - 2020-11-19 00:46 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-10-21 16:26 - 2020-11-19 00:46 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2023-10-21 16:24 - 2020-11-19 00:46 - 000003406 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-10-21 16:24 - 2020-11-19 00:46 - 000003182 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-10-21 16:24 - 2019-12-07 02:14 - 000000000 ___RD C:\Windows\PrintDialog
2023-10-21 16:24 - 2019-12-07 02:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-10-2023
Ran by Lawbitss (22-10-2023 06:08:35)
Running from C:\Users\Lawbitss\Downloads
Microsoft Windows 10 Pro Version 20H2 19042.631 (X64) (2023-10-21 23:26:37)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-4272348530-104420464-272258208-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4272348530-104420464-272258208-503 - Limited - Disabled)
Guest (S-1-5-21-4272348530-104420464-272258208-501 - Limited - Disabled)
Lawbitss (S-1-5-21-4272348530-104420464-272258208-1001 - Administrator - Enabled) => C:\Users\Lawbitss
WDAGUtilityAccount (S-1-5-21-4272348530-104420464-272258208-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 66.0.3359.181 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 84.0.522.52 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.4266.1003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4272348530-104420464-272258208-1001\...\OneDriveSetup.exe) (Version: 19.043.0304.0013 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.4266.1003 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.4266.1003 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.4266.1003 - Microsoft Corporation) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 3.0.19 - VideoLAN)
WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version: - )
Packages:
=========
Cortana -> C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_1.1911.21713.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Corporation)
Mail and Calendar -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.8204.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Studios) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.25.20211.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Corporation) [MS Ad]
Skype -> C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.77.0_x64__kzf8qxf38zg5c [2019-12-07] (Skype)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2005-06-07] () [File not signed]
ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2005-06-07] () [File not signed]
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2005-06-07] () [File not signed]
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2019-12-07 02:14 - 2019-12-07 02:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4272348530-104420464-272258208-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.207.187
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{2AB06CB3-B524-499E-AA2A-5A28EB25D06D}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{64346849-97E3-45A8-8390-A35882A8E427}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{507DACFF-C760-4274-B66A-AB98622D0FDA}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1ECEF98B-034B-44C1-BA55-92E3831208F0}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AA733E6A-2817-4E1C-89C4-DE760E8B2AF0}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D157B4AB-E317-4D29-A598-51F4FEF6177D}] => (Allow) C:\Windows\KMS-R@1n.exe => No File
FirewallRules: [{A8859971-0D9D-474F-8341-555F169B9E8B}] => (Allow) C:\Windows\KMS-R@1n.exe => No File
FirewallRules: [{085CF7DB-CD22-4ED2-9B2E-2F4664FBBE71}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc -> Google Inc.)
FirewallRules: [{76FCAFF4-B587-4017-94DC-40EFBB56D363}] => (Block) %SystemRoot%\System32\rpcnetp.exe => No File
==================== Restore Points =========================
22-10-2023 05:42:16 KpRm
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (10/22/2023 05:42:20 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddWin32ServiceFiles: Unable to back up image of service rpcnetp since QueryServiceConfig API failed
System Error:
The system cannot find the file specified.
.
Error: (10/22/2023 04:59:58 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-UAVRUKD$ via https://ntc-keyid-1591d4b6eaf98d0104864b6903a48dd0026077d3.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(0ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (10/22/2023 04:53:13 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-UAVRUKD$ via https://ntc-keyid-1591d4b6eaf98d0104864b6903a48dd0026077d3.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(15ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (10/22/2023 04:53:11 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x80072EE7
Command-line arguments:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=613d217f-7f13-4268-9907-1662339531cd;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
Error: (10/22/2023 04:53:11 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Acquisition of End User License failed. hr=0x80072EE7
Sku Id=613d217f-7f13-4268-9907-1662339531cd
Error: (10/22/2023 04:53:11 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: License acquisition failure details.
hr=0x80072EE7
Error: (10/22/2023 04:52:20 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x8007045b, A system shutdown is in progress.
.
Error: (10/22/2023 04:52:20 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]
System errors:
=============
Error: (10/22/2023 05:00:08 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL POWER: The data area passed to a system call is too small. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 00 00 00
Error: (10/22/2023 04:59:58 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL TRANSMIT: Access is denied. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 a4 04 00
Error: (10/22/2023 04:59:58 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL TRANSMIT: Access is denied. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 a4 04 00
Error: (10/22/2023 04:59:58 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL TRANSMIT: The parameter is incorrect. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 ca 7f 68
Error: (10/22/2023 04:59:58 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL TRANSMIT: Access is denied. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 a4 04 00
Error: (10/22/2023 04:53:23 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL POWER: The data area passed to a system call is too small. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 00 00 00
Error: (10/22/2023 04:53:13 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL TRANSMIT: Access is denied. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 a4 04 00
Error: (10/22/2023 04:53:13 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL TRANSMIT: Access is denied. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 a4 04 00
Windows Defender:
================
Date: 2023-10-22 06:07:47
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...in32/AutoKMS&threatid=2147685180&enterprise=0
Name: HackTool:Win32/AutoKMS
Severity: High
Category: Tool
Path: file:_C:\Windows\KMS-QADhook.dll
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Users\Lawbitss\Downloads\FRST64.exe
Security intelligence Version: AV: 1.303.25.0, AS: 1.303.25.0, NIS: 1.303.25.0
Engine Version: AM: 1.1.16400.2, NIS: 1.1.16400.2
Date: 2023-10-21 17:21:15
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...toKMS.SA!MSR&threatid=2147741757&enterprise=0
Name: HackTool:Win32/AutoKMS.SA!MSR
Severity: High
Category: Tool
Path: file:_C:\Windows\KMS-R@1n.exe; process:_pid:4648,ProcessStart:133424076397329510; service:_KMS-R@1n
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\KMS-R@1n.exe
Security intelligence Version: AV: 1.303.25.0, AS: 1.303.25.0, NIS: 1.303.25.0
Engine Version: AM: 1.1.16400.2, NIS: 1.1.16400.2
Date: 2023-10-21 17:21:00
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...toKMS.SA!MSR&threatid=2147741757&enterprise=0
Name: HackTool:Win32/AutoKMS.SA!MSR
Severity: High
Category: Tool
Path: file:_C:\Windows\KMS-R@1n.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\System32\svchost.exe
Security intelligence Version: AV: 1.303.25.0, AS: 1.303.25.0, NIS: 1.303.25.0
Engine Version: AM: 1.1.16400.2, NIS: 1.1.16400.2
Date: 2023-10-21 17:05:17
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...MSIL/AutoKMS&threatid=2147711767&enterprise=0
Name: HackTool:MSIL/AutoKMS
Severity: High
Category: Tool
Path: file:_C:\Windows\KMS-R@1nhook.exe; imagefileexecoptions:_HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\OSppSvc.exe; imagefileexecoptions:_HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SppExtComObj.exe; imagefileexecoptions:_HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\OSppSvc.exe; imagefileexecoptions:_HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SppExtComObj.exe; regkey:_HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\OSppSvc.exe; regkey:_HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SppExtComObj.exe; regkey:_HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\OSppSvc.exe; regkey:_HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SppExtComObj.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\System32\svchost.exe
Security intelligence Version: AV: 1.303.25.0, AS: 1.303.25.0, NIS: 1.303.25.0
Engine Version: AM: 1.1.16400.2, NIS: 1.1.16400.2
Date: 2023-10-21 17:05:01
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...MSIL/AutoKMS&threatid=2147711767&enterprise=0
Name: HackTool:MSIL/AutoKMS
Severity: High
Category: Tool
Path: file:_C:\Windows\KMS-R@1nhook.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\System32\svchost.exe
Security intelligence Version: AV: 1.303.25.0, AS: 1.303.25.0, NIS: 1.303.25.0
Engine Version: AM: 1.1.16400.2, NIS: 1.1.16400.2
Event[0]:
Date: 2023-10-22 05:03:03
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.303.25.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16400.2
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2023-10-22 05:03:03
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.303.25.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiSpyware
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16400.2
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2023-10-22 05:03:03
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.303.25.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16400.2
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2023-10-22 05:03:03
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.303.25.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16400.2
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2023-10-22 05:03:03
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.303.25.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiSpyware
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16400.2
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
==================== Memory info ===========================
BIOS: Microsoft Corporation 238.167.768 05.07.2014
Motherboard: Microsoft Corporation Surface Pro
Processor: Intel(R) Core(TM) i5-7300U CPU @ 2.60GHz
Percentage of memory in use: 43%
Total physical RAM: 8108.95 MB
Available physical RAM: 4580.68 MB
Total Virtual: 10028.95 MB
Available Virtual: 6319.8 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:237.86 GB) (Free:208.45 GB) (Model: INTEL SSDPEBKF256G7) NTFS
\\?\Volume{d7940109-31e6-4c8a-9359-8d6863bad120}\ () (Fixed) (Total:0.5 GB) (Free:0.08 GB) NTFS
\\?\Volume{00561e41-b66e-4d06-bb80-26392ad91ca2}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 5A54E111)
Partition: GPT.
==================== End of Addition.txt =======================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-10-2023
Ran by Lawbitss (administrator) on DESKTOP-UAVRUKD (Microsoft Corporation Surface Pro) (22-10-2023 06:06:29)
Running from C:\Users\Lawbitss\Downloads\FRST64.exe
Loaded Profiles: Lawbitss
Platform: Microsoft Windows 10 Pro Version 20H2 19042.631 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <8>
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\64kb8682.inf_amd64_170ccd25b9699b84\IntelCpHDCPSvc.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\64kb8682.inf_amd64_170ccd25b9699b84\IntelCpHeciSvc.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SppExtComObj.Exe
(svchost.exe ->) (Skype Software Sarl -> ) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.77.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
(svchost.exe ->) (Skype Software Sarl -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.77.0_x64__kzf8qxf38zg5c\SkypeApp.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\66.0.3359.181\Installer\chrmstp.exe [2023-10-21] (Google Inc -> Google Inc.)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {D87E5EB4-ACC7-4506-9427-2E3908B505E6} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\Explorer.exe [4651032 2020-11-18] (Microsoft Windows -> Microsoft Corporation)
Task: {D1043206-1B00-42F0-A330-B512E1BC62FF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2023-10-21] (Google Inc -> Google Inc.)
Task: {AB607F1F-8610-4273-9221-E89D9CA131F3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2023-10-21] (Google Inc -> Google Inc.)
Task: {4624C1FE-1AAC-4D71-922B-0DB37E570544} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [5967976 2015-08-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {7AD49054-8A7B-42BC-9248-6AA3A564E85D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [5967976 2015-08-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {D981553F-D4D4-4019-BD2E-7F71475E7F06} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [418384 2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {176925E8-F45E-459E-8E64-093C313A7879} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [418384 2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {683067CE-DD30-4743-9BF7-2F39473681DC} - System32\Tasks\R@1n-KMS\Office365ProPlus => C:\Windows\System32\Wbem\wmic.exe [526848 2019-12-07] (Microsoft Windows -> Microsoft Corporation) -> path SoftwareLicensingProduct where (ID="d450596f-894d-49e0-966a-fd39ed4c4c64") call Activate
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.207.187
Tcpip\..\Interfaces\{efa46f2b-35fd-4701-b41e-21d03c34b087}: [DhcpNameServer] 192.168.207.187
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Lawbitss\AppData\Local\Microsoft\Edge\User Data\Default [2023-10-22]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.19 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2023-10-21] (Google Inc -> Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2023-10-21] (Google Inc -> Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default [2023-10-22]
CHR Extension: (Docs) - C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2023-10-22]
CHR Extension: (Google Drive) - C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2023-10-22]
CHR Extension: (YouTube) - C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2023-10-22]
CHR Extension: (Google Docs Offline) - C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-10-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-10-22]
CHR Extension: (Gmail) - C:\Users\Lawbitss\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2023-10-22]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2776664 2015-08-16] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5101992 2020-11-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-10-22 06:06 - 2023-10-22 06:07 - 000009269 _____ C:\Users\Lawbitss\Downloads\FRST.txt
2023-10-22 06:04 - 2023-10-22 06:06 - 000000000 ____D C:\FRST
2023-10-22 06:04 - 2023-10-22 06:04 - 002383360 _____ (Farbar) C:\Users\Lawbitss\Downloads\FRST64.exe
2023-10-22 06:03 - 2023-10-22 06:03 - 002084352 _____ (Farbar) C:\Users\Lawbitss\Downloads\FRST.exe
2023-10-22 05:42 - 2023-10-22 05:42 - 000003662 _____ C:\Windows\system32\Tasks\CreateExplorerShellUnelevatedTask
2023-10-22 05:42 - 2023-10-22 05:42 - 000001962 _____ C:\Users\Lawbitss\Desktop\kprm-20231022054207.txt
2023-10-22 05:42 - 2023-10-22 05:42 - 000000000 ____D C:\KPRM
2023-10-22 04:52 - 2023-10-22 04:52 - 000022932 ____N C:\Windows\SysWOW64\rpcnetp.exe
2023-10-22 04:52 - 2023-10-22 04:52 - 000022932 _____ C:\Windows\SysWOW64\rpcnetp.dll
2023-10-22 04:52 - 2023-10-22 04:52 - 000022932 _____ C:\Windows\system32\tik.exe
2023-10-21 19:42 - 2023-10-21 19:42 - 000000748 _____ C:\Users\Lawbitss\Desktop\Videos - Shortcut.lnk
2023-10-21 19:23 - 2023-10-21 19:23 - 000000000 ____D C:\Windows\system32\Tasks\Agent Activation Runtime
2023-10-21 18:58 - 2023-10-21 19:23 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\D3DSCache
2023-10-21 17:23 - 2023-10-21 16:25 - 000000000 ____D C:\Windows\Panther
2023-10-21 17:21 - 2023-10-21 19:23 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\vlc
2023-10-21 17:05 - 2023-10-21 17:05 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\UProof
2023-10-21 17:05 - 2023-10-21 17:05 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Proof
2023-10-21 17:04 - 2023-10-21 17:05 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Office
2023-10-21 17:04 - 2023-10-21 17:04 - 000003416 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2023-10-21 17:04 - 2023-10-21 17:04 - 000003292 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2023-10-21 17:04 - 2023-10-21 17:04 - 000002373 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-10-21 17:04 - 2023-10-21 17:04 - 000002332 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2023-10-21 17:04 - 2023-10-21 17:04 - 000000916 _____ C:\Users\Public\Desktop\VLC media player.lnk
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Word
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Document Building Blocks
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Bibliography
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\AddIns
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\Google
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2023-10-21 17:04 - 2023-10-21 17:04 - 000000000 ____D C:\Program Files (x86)\Google
2023-10-21 17:03 - 2023-10-21 17:03 - 000002451 _____ C:\Users\Lawbitss\Desktop\Word 2016.lnk
2023-10-21 17:03 - 2023-10-21 17:03 - 000002450 _____ C:\Users\Lawbitss\Desktop\PowerPoint 2016.lnk
2023-10-21 17:03 - 2023-10-21 17:03 - 000002413 _____ C:\Users\Lawbitss\Desktop\Excel 2016.lnk
2023-10-21 17:03 - 2023-10-21 17:03 - 000000000 ____D C:\Program Files\VideoLAN
2023-10-21 17:02 - 2023-10-21 17:02 - 000003584 _____ C:\Windows\KMS-QADhook.dll
2023-10-21 17:02 - 2023-10-21 17:02 - 000000000 ____D C:\Windows\system32\Tasks\R@1n-KMS
2023-10-21 17:02 - 2023-10-21 17:02 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\PeerDistRepub
2023-10-21 17:02 - 2023-10-21 17:02 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\mpress
2023-10-21 17:00 - 2023-10-21 17:00 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2023-10-21 16:52 - 2023-10-21 16:52 - 000002492 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002456 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002414 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002413 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002407 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002401 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000002393 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2023-10-21 16:52 - 2023-10-21 16:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2023-10-21 16:50 - 2023-10-21 16:52 - 000000000 ____D C:\Program Files\Microsoft Office
2023-10-21 16:50 - 2023-10-21 16:50 - 000000000 ____D C:\Program Files\Microsoft Office 15
2023-10-21 16:49 - 2023-10-21 16:49 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\Comms
2023-10-21 16:40 - 2023-10-21 16:40 - 000000000 ____D C:\Users\Lawbitss\AppData\LocalLow\Intel
2023-10-21 16:39 - 2023-10-21 16:39 - 000000000 ____D C:\Windows\system32\Intel
2023-10-21 16:38 - 2023-10-21 16:47 - 000000000 ____D C:\ProgramData\Intel
2023-10-21 16:38 - 2023-10-21 16:38 - 000000000 ____D C:\Windows\LastGood.Tmp
2023-10-21 16:38 - 2023-10-21 16:38 - 000000000 ____D C:\Program Files\Intel
2023-10-21 16:38 - 2023-10-21 16:38 - 000000000 _____ C:\Windows\system32\GfxValDisplayLog.bin
2023-10-21 16:36 - 2023-10-21 16:36 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\MMC
2023-10-21 16:36 - 2023-10-21 16:36 - 000000000 ____D C:\Program Files\Reference Assemblies
2023-10-21 16:36 - 2023-10-21 16:36 - 000000000 ____D C:\Program Files\MSBuild
2023-10-21 16:36 - 2023-10-21 16:36 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2023-10-21 16:36 - 2023-10-21 16:36 - 000000000 ____D C:\Program Files (x86)\MSBuild
2023-10-21 16:35 - 2023-10-21 16:35 - 000003382 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4272348530-104420464-272258208-1001
2023-10-21 16:35 - 2023-10-21 16:35 - 000001074 _____ C:\Users\Lawbitss\Desktop\WinRAR.lnk
2023-10-21 16:35 - 2023-10-21 16:35 - 000000000 ___RD C:\Users\Lawbitss\OneDrive
2023-10-21 16:35 - 2023-10-21 16:35 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2023-10-21 16:35 - 2023-10-21 16:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2023-10-21 16:35 - 2023-10-21 16:35 - 000000000 ____D C:\Program Files (x86)\WinRAR
2023-10-21 16:32 - 2023-10-21 16:48 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\Packages
2023-10-21 16:32 - 2023-10-21 16:35 - 000002372 _____ C:\Users\Lawbitss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-10-21 16:32 - 2023-10-21 16:35 - 000000000 ____D C:\Users\Lawbitss
2023-10-21 16:32 - 2023-10-21 16:32 - 000000020 ___SH C:\Users\Lawbitss\ntuser.ini
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ___SD C:\Users\Lawbitss\AppData\Roaming\Microsoft\SystemCertificates
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ___SD C:\Users\Lawbitss\AppData\Roaming\Microsoft\Protect
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ___SD C:\Users\Lawbitss\AppData\Roaming\Microsoft\Crypto
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ___SD C:\Users\Lawbitss\AppData\Roaming\Microsoft\Credentials
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ___RD C:\Users\Lawbitss\3D Objects
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Windows
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Vault
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Spelling
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Microsoft\Network
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Roaming\Adobe
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\VirtualStore
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\Publishers
2023-10-21 16:32 - 2023-10-21 16:32 - 000000000 ____D C:\Users\Lawbitss\AppData\Local\ConnectedDevicesPlatform
2023-10-21 16:28 - 2023-10-21 16:28 - 000000000 ____D C:\Windows\CSC
2023-10-21 16:24 - 2023-10-21 16:24 - 000002850 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4272348530-104420464-272258208-500
2023-10-21 16:24 - 2023-10-21 16:24 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2023-10-21 16:23 - 2023-10-22 04:52 - 000034160 _____ C:\Windows\system32\wpbbin.exe
2023-10-21 02:56 - 2023-10-21 02:56 - 000000000 ___HD C:\$WinREAgent
2023-10-20 10:31 - 2023-10-20 10:31 - 044432408 _____ C:\Users\Lawbitss\Downloads\vlc-3.0.19-win64.exe
2023-10-20 10:20 - 2023-10-20 10:20 - 001373744 _____ (Google LLC) C:\Users\Lawbitss\Downloads\ChromeSetup.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-10-22 05:42 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-10-22 04:57 - 2020-11-19 00:54 - 000840838 _____ C:\Windows\system32\PerfStringBackup.INI
2023-10-22 04:57 - 2019-12-07 02:13 - 000000000 ____D C:\Windows\INF
2023-10-22 04:52 - 2023-03-25 17:20 - 000008192 ___SH C:\DumpStack.log.tmp
2023-10-22 04:52 - 2020-11-19 00:43 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2023-10-22 04:52 - 2019-12-07 02:14 - 000000000 ____D C:\Windows\ServiceState
2023-10-22 04:52 - 2019-12-07 02:03 - 000262144 _____ C:\Windows\system32\config\BBI
2023-10-22 04:51 - 2020-11-19 00:43 - 000000000 ____D C:\Windows\system32\SleepStudy
2023-10-21 19:26 - 2019-12-07 02:14 - 000000000 ____D C:\Windows\LiveKernelReports
2023-10-21 17:23 - 2019-12-07 02:14 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2023-10-21 17:20 - 2020-11-19 00:43 - 000435248 _____ C:\Windows\system32\FNTCACHE.DAT
2023-10-21 17:01 - 2019-12-07 02:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2023-10-21 17:01 - 2019-12-07 02:14 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2023-10-21 17:00 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2023-10-21 16:58 - 2019-12-07 02:14 - 000000000 ____D C:\Windows\AppReadiness
2023-10-21 16:48 - 2019-12-07 02:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-10-21 16:36 - 2019-12-07 02:03 - 000000000 ____D C:\Windows\CbsTemp
2023-10-21 16:33 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\USOPrivate
2023-10-21 16:32 - 2020-11-19 00:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2023-10-21 16:28 - 2019-12-07 02:51 - 000000000 ____D C:\Windows\system32\FxsTmp
2023-10-21 16:26 - 2020-11-19 00:46 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-10-21 16:26 - 2020-11-19 00:46 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2023-10-21 16:24 - 2020-11-19 00:46 - 000003406 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-10-21 16:24 - 2020-11-19 00:46 - 000003182 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-10-21 16:24 - 2019-12-07 02:14 - 000000000 ___RD C:\Windows\PrintDialog
2023-10-21 16:24 - 2019-12-07 02:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-10-2023
Ran by Lawbitss (22-10-2023 06:08:35)
Running from C:\Users\Lawbitss\Downloads
Microsoft Windows 10 Pro Version 20H2 19042.631 (X64) (2023-10-21 23:26:37)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-4272348530-104420464-272258208-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4272348530-104420464-272258208-503 - Limited - Disabled)
Guest (S-1-5-21-4272348530-104420464-272258208-501 - Limited - Disabled)
Lawbitss (S-1-5-21-4272348530-104420464-272258208-1001 - Administrator - Enabled) => C:\Users\Lawbitss
WDAGUtilityAccount (S-1-5-21-4272348530-104420464-272258208-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 66.0.3359.181 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 84.0.522.52 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.4266.1003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4272348530-104420464-272258208-1001\...\OneDriveSetup.exe) (Version: 19.043.0304.0013 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.4266.1003 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.4266.1003 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.4266.1003 - Microsoft Corporation) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 3.0.19 - VideoLAN)
WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version: - )
Packages:
=========
Cortana -> C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_1.1911.21713.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Corporation)
Mail and Calendar -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.8204.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Studios) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.25.20211.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Corporation) [MS Ad]
Skype -> C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.77.0_x64__kzf8qxf38zg5c [2019-12-07] (Skype)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2005-06-07] () [File not signed]
ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2005-06-07] () [File not signed]
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2005-06-07] () [File not signed]
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-10-21] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2019-12-07 02:14 - 2019-12-07 02:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4272348530-104420464-272258208-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.207.187
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{2AB06CB3-B524-499E-AA2A-5A28EB25D06D}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{64346849-97E3-45A8-8390-A35882A8E427}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{507DACFF-C760-4274-B66A-AB98622D0FDA}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1ECEF98B-034B-44C1-BA55-92E3831208F0}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AA733E6A-2817-4E1C-89C4-DE760E8B2AF0}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D157B4AB-E317-4D29-A598-51F4FEF6177D}] => (Allow) C:\Windows\KMS-R@1n.exe => No File
FirewallRules: [{A8859971-0D9D-474F-8341-555F169B9E8B}] => (Allow) C:\Windows\KMS-R@1n.exe => No File
FirewallRules: [{085CF7DB-CD22-4ED2-9B2E-2F4664FBBE71}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc -> Google Inc.)
FirewallRules: [{76FCAFF4-B587-4017-94DC-40EFBB56D363}] => (Block) %SystemRoot%\System32\rpcnetp.exe => No File
==================== Restore Points =========================
22-10-2023 05:42:16 KpRm
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (10/22/2023 05:42:20 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddWin32ServiceFiles: Unable to back up image of service rpcnetp since QueryServiceConfig API failed
System Error:
The system cannot find the file specified.
.
Error: (10/22/2023 04:59:58 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-UAVRUKD$ via https://ntc-keyid-1591d4b6eaf98d0104864b6903a48dd0026077d3.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(0ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (10/22/2023 04:53:13 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-UAVRUKD$ via https://ntc-keyid-1591d4b6eaf98d0104864b6903a48dd0026077d3.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(15ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (10/22/2023 04:53:11 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x80072EE7
Command-line arguments:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=613d217f-7f13-4268-9907-1662339531cd;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
Error: (10/22/2023 04:53:11 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Acquisition of End User License failed. hr=0x80072EE7
Sku Id=613d217f-7f13-4268-9907-1662339531cd
Error: (10/22/2023 04:53:11 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: License acquisition failure details.
hr=0x80072EE7
Error: (10/22/2023 04:52:20 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x8007045b, A system shutdown is in progress.
.
Error: (10/22/2023 04:52:20 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]
System errors:
=============
Error: (10/22/2023 05:00:08 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL POWER: The data area passed to a system call is too small. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 00 00 00
Error: (10/22/2023 04:59:58 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL TRANSMIT: Access is denied. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 a4 04 00
Error: (10/22/2023 04:59:58 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL TRANSMIT: Access is denied. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 a4 04 00
Error: (10/22/2023 04:59:58 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL TRANSMIT: The parameter is incorrect. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 ca 7f 68
Error: (10/22/2023 04:59:58 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL TRANSMIT: Access is denied. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 a4 04 00
Error: (10/22/2023 04:53:23 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL POWER: The data area passed to a system call is too small. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 00 00 00
Error: (10/22/2023 04:53:13 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL TRANSMIT: Access is denied. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 a4 04 00
Error: (10/22/2023 04:53:13 AM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Microsoft UICC ISO Reader 0c44320e 1' rejected IOCTL TRANSMIT: Access is denied. If this error persists, your smart card or reader may not be functioning correctly.
Command Header: 00 a4 04 00
Windows Defender:
================
Date: 2023-10-22 06:07:47
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...in32/AutoKMS&threatid=2147685180&enterprise=0
Name: HackTool:Win32/AutoKMS
Severity: High
Category: Tool
Path: file:_C:\Windows\KMS-QADhook.dll
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Users\Lawbitss\Downloads\FRST64.exe
Security intelligence Version: AV: 1.303.25.0, AS: 1.303.25.0, NIS: 1.303.25.0
Engine Version: AM: 1.1.16400.2, NIS: 1.1.16400.2
Date: 2023-10-21 17:21:15
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...toKMS.SA!MSR&threatid=2147741757&enterprise=0
Name: HackTool:Win32/AutoKMS.SA!MSR
Severity: High
Category: Tool
Path: file:_C:\Windows\KMS-R@1n.exe; process:_pid:4648,ProcessStart:133424076397329510; service:_KMS-R@1n
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\KMS-R@1n.exe
Security intelligence Version: AV: 1.303.25.0, AS: 1.303.25.0, NIS: 1.303.25.0
Engine Version: AM: 1.1.16400.2, NIS: 1.1.16400.2
Date: 2023-10-21 17:21:00
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...toKMS.SA!MSR&threatid=2147741757&enterprise=0
Name: HackTool:Win32/AutoKMS.SA!MSR
Severity: High
Category: Tool
Path: file:_C:\Windows\KMS-R@1n.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\System32\svchost.exe
Security intelligence Version: AV: 1.303.25.0, AS: 1.303.25.0, NIS: 1.303.25.0
Engine Version: AM: 1.1.16400.2, NIS: 1.1.16400.2
Date: 2023-10-21 17:05:17
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...MSIL/AutoKMS&threatid=2147711767&enterprise=0
Name: HackTool:MSIL/AutoKMS
Severity: High
Category: Tool
Path: file:_C:\Windows\KMS-R@1nhook.exe; imagefileexecoptions:_HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\OSppSvc.exe; imagefileexecoptions:_HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SppExtComObj.exe; imagefileexecoptions:_HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\OSppSvc.exe; imagefileexecoptions:_HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SppExtComObj.exe; regkey:_HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\OSppSvc.exe; regkey:_HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SppExtComObj.exe; regkey:_HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\OSppSvc.exe; regkey:_HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SppExtComObj.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\System32\svchost.exe
Security intelligence Version: AV: 1.303.25.0, AS: 1.303.25.0, NIS: 1.303.25.0
Engine Version: AM: 1.1.16400.2, NIS: 1.1.16400.2
Date: 2023-10-21 17:05:01
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...MSIL/AutoKMS&threatid=2147711767&enterprise=0
Name: HackTool:MSIL/AutoKMS
Severity: High
Category: Tool
Path: file:_C:\Windows\KMS-R@1nhook.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\System32\svchost.exe
Security intelligence Version: AV: 1.303.25.0, AS: 1.303.25.0, NIS: 1.303.25.0
Engine Version: AM: 1.1.16400.2, NIS: 1.1.16400.2
Event[0]:
Date: 2023-10-22 05:03:03
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.303.25.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16400.2
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2023-10-22 05:03:03
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.303.25.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiSpyware
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16400.2
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2023-10-22 05:03:03
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.303.25.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16400.2
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2023-10-22 05:03:03
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.303.25.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16400.2
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2023-10-22 05:03:03
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.303.25.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiSpyware
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16400.2
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
==================== Memory info ===========================
BIOS: Microsoft Corporation 238.167.768 05.07.2014
Motherboard: Microsoft Corporation Surface Pro
Processor: Intel(R) Core(TM) i5-7300U CPU @ 2.60GHz
Percentage of memory in use: 43%
Total physical RAM: 8108.95 MB
Available physical RAM: 4580.68 MB
Total Virtual: 10028.95 MB
Available Virtual: 6319.8 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:237.86 GB) (Free:208.45 GB) (Model: INTEL SSDPEBKF256G7) NTFS
\\?\Volume{d7940109-31e6-4c8a-9359-8d6863bad120}\ () (Fixed) (Total:0.5 GB) (Free:0.08 GB) NTFS
\\?\Volume{00561e41-b66e-4d06-bb80-26392ad91ca2}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 5A54E111)
Partition: GPT.
==================== End of Addition.txt =======================