Computer froze up.

Started by ron350, April 20, 2024, 12:50:42 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

DR M

V_v, thanks for all the effort put on that! :)

I'll try to explain the procedure step by step, using images.

Ron, please follow the instructions very carefully.

1. Download FRST from the official source which is https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

2. You will be asked: What do you want to do with FRST.exe?
  Select Save as.

You cannot view this attachment.


3. Save it on to the Desktop. Make sure to save it as an application. See the image below.

You cannot view this attachment.


4. When you get the yellow triangle warning, click on the 3 horizontal dots and select Keep.

You cannot view this attachment.


5. Click on Show more and then select Keep anyway.

You cannot view this attachment.


Let the program to get downloaded. It will be placed on to the Desktop as an application file.

Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

ron350

 I have printed your instructions and atempted this several times with the same results.
This computer is opening this file as Notepad. Every place i send the file it has the Notepad icon in front of it.

 Theproblem is that the computer wants to know what to open this file with. I can open a full page of options to open this page with but i don't wnat to click on something that will wreck the computer.
 

 

 

 

The last picture is a page of options to open with.

DR M

QuoteTheproblem is that the computer wants to know what to open this file with.

Not agree. The problem is that the file is not completely downloaded. That's why the unconfirmed name.

Click on the Downloads icon as shown in my image below. Take a screenshot of what you see.

You cannot view this attachment.
Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

ron350

 this?

 

  DR M nothing on my computer looks like your pictures.

ron350

As you can see the FRST file has the notepad icon in front of it as soon as it loads.
This is before i click on any thing. I must have about a hundred of the notepad files on my computer by now.



DR M

You right clicked on it. Just left click on it.
Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

DR M

This is not a notepad icon, Ron. All you have to do is click on the Save as button, choose Desktop, follow the steps I provided in the images above, and wait for the file to download itself. Unconfirmed download refers to a partially downloaded item.
Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

ron350

 I fallow your instructions and it still ends upin Downloads or on the desltop as a Notepad file.

 Nothing i can do will keep it from showing up as a Notepad file.

 

DR M

Quote from: ron350 on April 22, 2024, 05:12:51 PMI fallow your instructions and it still ends upin Downloads or on the desltop as a Notepad file.

 Nothing i can do will keep it from showing up as a Notepad file.
 

This is because in your effort to open an unconfirmed download file you chose Notepad. But this is not an issue. The issue is that the file is not downloaded in your computer yet.

Check if you can download any other file. Try this one: url=https://www.bleepingcomputer.com/download/adwcleaner/

Can you download and save it on your Desktop?
Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

v_v

ron350 (and DR M),

Good afternoon all!  What a late night!!

Ron, thank you for the images.  You are almost there but you are not following my instructions exactly.  I will slightly disagree with my colleague DR M here, the file is downloaded.  We just have to get to it and rename it.

DR M - the browser IS saving the file but Windows Defender is renaming it and deleting the ".exe" suffix.  See my lengthy post from yesterday 04-21-24 at 05:54:58 PM explaining and verifying what is happening with Microsoft Edge and Windows Defender.



So Ron the image of your desktop shows the file as "Unconfirmed 680331" with a Notepad icon.  What this means is that there is a file IN YOUR DESKTOP FOLDER that has a similar name.  The icon on the desktop is simply a shortcut image, it IS NOT the file itself!  So we need to get to your DESKTOP FOLDER to find the file and then rename it to " FRST64.exe ".

From your images it appears that you did finally find "File Explorer".  In that image you see that you have highlighted under "Recent files (20)" an entry named "Unconfirmed 680331" with a Notepad icon.  This is the file that we need to look for.

Go back to that same image, to the immediate left of this highlighted file you should see a folder that says "Washing Machine".  Immediately above "Washing Machine" you will see "Saved Pictures", "DG 308 Maytag Dryer", etc.  Keep going up that same column and you will see "Pictures", "Documents", "Downloads", "Desktop":  this last item "DESKTOP" is what we want.  Click on Desktop.

Now, still in File Explorer, to the right you should see the "contents" of your DESKTOP FOLDER.  This may  show up as images (icons), or as a list, etc, depending on how you have set up File Explorer.  For more clarity what we will need is to change the VIEW of this right side.

Go to the top of File Explorer.  You should see four column listings:  "File" - "Home" - "Share" - "View".  Click on View.

The View banner or ribbon will now be visible.  Immediately under the word "View" you should see 8 "Layout" choices starting with "Extra large icons" and ending with "Details".  Click on "Details" so that it is highlighted.

Now move your cursor immediately to the right, leaving the 8 "Layout" group choices, then go past the "Current View" group choices, until you get to the "Show/Hide" group choices.  This group has 3 entries beginning with "Item check boxes".  Put a check in the check boxes next to "File name extensions" and "Hidden items".

By now the "contents" of your "Desktop Folder" should show a list of files with various details.  You might need to post an image of what you see at this point because I do not know how you have customized what details are showing in your content view.  But in your "contents" now you should be able to scan and look for a file with the name of "Unconfirmed 680331" or something very close to that.  If you find it this is the file we need to rename to "FRST64.exe".  So follow the previously posted renaming instructions if you find it.  If you do not find it post an image as to what your File Explorer window looks like at this point.

If you are able to rename it successfully, then simply double-click on it once it is renamed and follow my previous instructions to get it to run, and once it is running follow DR M's instructions.  At that point he will become your 'primary physician' and I will disappear!  (Smile)

----------

Okay, now I have seen both your last post and DR M's.  As I wrote above DR M is not correct about the download aspect of this matter.  Windows Defender is definitely blocking and renaming the "FRST64.exe" file which is what I have verified on my own computer.  So my instructions are to get around this.

v_v
Justice, Equity, and Meaningful, Productive, and Fulfilling Lives to All Earthlings

ron350

OK ADWCleaner is on the desktop and working.

I turned Malwarebytes off and attempted to download FRST the same way but still have a notepad file on the desktop that does nothing.

v_v

Justice, Equity, and Meaningful, Productive, and Fulfilling Lives to All Earthlings

ron350

V_V your instructions worked. YEAH

 Now the forum will not let me upload the FRST files.

v_v

ron350,

Good for you!  I was just about to write to say that the instructions were bad and would not work, and to revise them.  But if they worked then I guess that my fingers knew better than my mind did! (Smile)

(You can delete and disregard the PM that I sent to you, if you got it.)

As far as uploading the FRST files I will turn you over to DR M and/or Corrine or one of the other experts.  I am sure that they know some simple solution to the uploading problem.

My job is finished and I will disappear!  Good luck!!

v_v
Justice, Equity, and Meaningful, Productive, and Fulfilling Lives to All Earthlings

ron350

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19.04.2024 01
Ran by Ron (22-04-2024 14:01:26)
Running from C:\Users\Ron\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.4291 (X64) (2022-02-15 23:02:48)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-1533190171-1017924844-2528464932-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1533190171-1017924844-2528464932-503 - Limited - Disabled)
Guest (S-1-5-21-1533190171-1017924844-2528464932-501 - Limited - Disabled)
Ron (S-1-5-21-1533190171-1017924844-2528464932-1001 - Administrator - Enabled) => C:\Users\Ron
WDAGUtilityAccount (S-1-5-21-1533190171-1017924844-2528464932-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Malwarebytes (Disabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Malwarebytes version 4.6.12.323 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.12.323 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 124.0.2478.51 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 123.0.2420.97 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1533190171-1017924844-2528464932-1001\...\OneDriveSetup.exe) (Version: 24.070.0407.0003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6111 - Realtek Semiconductor Corp.)
Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{0746492E-47B6-4251-940C-44462DFD74BB}) (Version: 2.55.0.0 - Microsoft Corporation)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{B9A7A138-BFD5-4C73-A269-F78CCA28150E}) (Version: 8.94.0.0 - Microsoft Corporation)
UpdateAssistant (HKLM\...\{76A22428-2400-4521-96AF-7AC4A6174CA5}) (Version: 1.25.0.0 - Microsoft Corporation) Hidden
Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.19041.2183 - Microsoft Corporation)
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)

Packages:
=========

Disney+ -> C:\Program Files\WindowsApps\Disney.37853FC22B2CE_2024.3.211.0_neutral__6rarf9sa4v8jt [2024-04-20] (Disney)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2024-04-20] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2024-04-20] (Microsoft Corporation) [MS Ad]
Microsoft Copilot -> C:\Program Files\WindowsApps\Microsoft.Windows.Ai.Copilot.Provider_1.0.3.0_neutral__8wekyb3d8bbwe [2024-04-20] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2024-04-20] (Microsoft Corporation)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0 [2024-04-20] (Spotify AB) [Startup Task]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1533190171-1017924844-2528464932-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-03-03] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2018-02-26] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-03-03] (Malwarebytes Inc. -> Malwarebytes)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

HKU\S-1-5-21-1533190171-1017924844-2528464932-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mail.yahoo.com/b/?.src=ym&reason=myc

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2018-12-12 04:20 - 2018-12-12 04:18 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1533190171-1017924844-2528464932-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img2.jpg
DNS Servers: 209.18.47.61 - 209.18.47.62
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{E78010E5-E7FD-4689-BDF3-95484FCBCC98}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{31EAABA1-6B04-43D1-AE97-CEB7F41822D0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{FFE5B5A2-E897-4F59-8663-5F327C31AFBE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1C4A6B37-0012-4A9E-8D7C-2DF69FC74E8E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{B612F704-E1E6-45F4-B96A-0838B0819B45}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{873D14E3-B240-4161-B46F-3FE1E20928FA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{465BA9B6-3C40-4681-9516-616A941B141C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{9205F944-6ED6-4A3D-801A-4A4D6B230B53}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{D0EB38E8-B60B-48B4-8950-15C920098125}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{F278B8A2-0E2D-4F02-89C7-AE49F905B7A2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.235.663.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1C9A66AA-16C9-4239-89FD-60F8591A414C}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F090E1E4-A1AB-4D4C-9C7B-5F302FD802A9}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.117.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{BE6498E7-0378-4565-BA83-08B60CB1597A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.117.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{9D12B745-F465-4A31-B5A2-ACC5917B0B5E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.117.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{B79E3505-12FF-47ED-8C42-16635D4C473C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.117.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)

==================== Restore Points =========================

03-04-2024 19:12:16 Scheduled Checkpoint
09-04-2024 19:22:43 Windows Modules Installer
18-04-2024 18:31:36 Scheduled Checkpoint
19-04-2024 19:53:23 last
20-04-2024 16:38:48 Restore Operation
20-04-2024 17:40:32 4/20/24

==================== Faulty Device Manager Devices ============

Name: Unknown USB Device (Device Descriptor Request Failed)
Description: Unknown USB Device (Device Descriptor Request Failed)
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Standard USB Host Controller)
Service:
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation.


==================== Event log errors: ========================

Application errors:
==================
Error: (04/21/2024 08:53:51 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.19041.3636, time stamp: 0xe9186526
Faulting module name: KERNELBASE.dll, version: 10.0.19041.4291, time stamp: 0xa956ff71
Exception code: 0xc000027b
Fault offset: 0x000000000012dca2
Faulting process id: 0x8a4
Faulting application start time: 0x01da93f334300705
Faulting application path: C:\WINDOWS\system32\backgroundTaskHost.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: c99aa2fe-6624-4410-8145-f0a84d631f75
Faulting package full name: Microsoft.YourPhone_1.24032.123.0_x64__8wekyb3d8bbwe
Faulting package-relative application ID: App

Error: (04/20/2024 05:20:28 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (2932,R,98) SRUJet: Error -1811 (0xfffff8ed) occurred while opening logfile C:\WINDOWS\system32\SRU\SRU0D39B.log.

Error: (04/20/2024 04:55:29 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: An unspecified error occurred during System Restore: (Scheduled Checkpoint). Additional information: 0x80070005.

Error: (04/19/2024 07:09:15 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress..

Error: (04/19/2024 07:09:15 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.]

Error: (04/19/2024 07:09:14 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress..

Error: (04/19/2024 07:09:14 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.]

Error: (04/18/2024 08:52:14 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimizer couldn't complete retrim on Windows (C:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)


System errors:
=============
Error: (04/22/2024 01:04:47 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Security Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (04/22/2024 01:04:47 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) HD Graphics Control Panel Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (04/21/2024 10:51:40 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200b: 2024-01 Security Update for Windows 10 Version 22H2 for x64-based Systems (KB5034441).

Error: (04/21/2024 10:31:03 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200b: 2024-01 Security Update for Windows 10 Version 22H2 for x64-based Systems (KB5034441).

Error: (04/21/2024 10:21:40 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200b: 2024-01 Security Update for Windows 10 Version 22H2 for x64-based Systems (KB5034441).

Error: (04/20/2024 04:57:55 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Delivery Optimization service hung on starting.

Error: (04/20/2024 09:59:28 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-J4MTF94)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Error: (04/20/2024 09:59:28 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-J4MTF94)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.


Windows Defender:
================
Date: 2024-04-21 10:46:51
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2024-04-21 10:35:51
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2024-04-20 17:39:13
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2023-03-07 17:05:54
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2023-03-06 16:11:37
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
�Event[0]:

Date: 2024-04-20 17:09:02
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.389.793.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.20300.3
Error code: 0x80240022
Error description: The program can't check for definition updates.

Date: 2024-04-20 17:09:02
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.389.793.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.20300.3
Error code: 0x80240022
Error description: The program can't check for definition updates.

Date: 2024-04-20 16:40:32
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Current
Error Code: 0x80501102
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.
Security intelligence Version: 1.389.793.0;1.389.793.0
Engine Version: 1.1.20300.3

Date: 2024-04-20 11:37:57
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.389.793.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.20300.3
Error code: 0x80240017
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Date: 2024-04-20 11:34:32
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Current
Error Code: 0x80501102
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.
Security intelligence Version: 1.389.793.0;1.389.793.0
Engine Version: 1.1.20300.3

CodeIntegrity:
===============
Date: 2024-04-20 17:11:54
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\aepic.dll because the set of per-page image hashes could not be found on the system.

Date: 2024-03-12 08:32:51
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements.


==================== Memory info ===========================

BIOS: Dell Inc. A28 02/22/2018
Motherboard: Dell Inc. 0GY6Y8
Processor: Intel(R) Core(TM) i5-3570 CPU @ 3.40GHz
Percentage of memory in use: 30%
Total physical RAM: 16270.45 MB
Available physical RAM: 11361.8 MB
Total Virtual: 18702.45 MB
Available Virtual: 14224.39 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:1862.17 GB) (Free:1768.15 GB) (Model: Hitachi HUA722020ALA331) NTFS

\\?\Volume{219776b6-0000-0000-0000-100000000000}\ (System) (Fixed) (Total:0.34 GB) (Free:0.31 GB) NTFS
\\?\Volume{219776b6-0000-0000-0000-a0a0d1010000}\ () (Fixed) (Total:0.5 GB) (Free:0.08 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 1863 GB) (Disk ID: 219776B6)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1862.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=517 MB) - (Type=27)

==================== End of Addition.txt =======================