I've been having issues in particular when launching Elden Ring where when it gets half way past the loading screen, my computer shuts off, with no warnings beforehand. This all began when suddenly I would have random shutoffs when plugging in usb devices like my microphone or external hard drives into the front IO (this also happens when I use the ports on the motherboard). The case I have is the Deepcool Matrexx 55 Mesh in case that's what could be causing it. I have already given the computer to a local service center, but they proved to be of no help. I recently discovered Event Viewer, and upon further research found a particular repeating Critical Error:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331c3b3a-2005-44c2-ac5e-77220c37d6b4}" />
<EventID>41</EventID>
<Version>8</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000400000000002</Keywords>
<TimeCreated SystemTime="2022-07-09T14:59:05.9374076Z" />
<EventRecordID>8884</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>DESKTOP-EEHFES3</Computer>
<Security UserID="S-1-5-18" />
</System>
- <EventData>
<Data Name="BugcheckCode">0</Data>
<Data Name="BugcheckParameter1">0x0</Data>
<Data Name="BugcheckParameter2">0x0</Data>
<Data Name="BugcheckParameter3">0x0</Data>
<Data Name="BugcheckParameter4">0x0</Data>
<Data Name="SleepInProgress">0</Data>
<Data Name="PowerButtonTimestamp">0</Data>
<Data Name="BootAppStatus">0</Data>
<Data Name="Checkpoint">0</Data>
<Data Name="ConnectedStandbyInProgress">false</Data>
<Data Name="SystemSleepTransitionsToOn">0</Data>
<Data Name="CsEntryScenarioInstanceId">0</Data>
<Data Name="BugcheckInfoFromEFI">false</Data>
<Data Name="CheckpointStatus">0</Data>
<Data Name="CsEntryScenarioInstanceIdV2">0</Data>
<Data Name="LongPowerButtonPressDetected">false</Data>
</EventData>
</Event>
Below, I have listed the specs from Speccy
http://speccy.piriform.com/results/LoTDCaYHEj1FwrLNveGBKYU
I also saw people on a different forum wanting the following information:
MiniToolBox by Farbar Version: 13-05-2022
Ran by MetallicAlter (administrator) on 09-07-2022 at 21:34:23
Running from "C:\Users\MetallicAlter\AppData\Local\Temp\scoped_dir1216_358422418"
Microsoft Windows 10 Pro (X64)
Model: System Product Name Manufacturer: System manufacturer
Boot Mode: Normal
***
========================= Event log errors: ===============================
Application errors:
==================
Error: (07/09/2022 08:49:08 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (07/09/2022 08:48:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: atieclxx.exe, version: 6.14.11.1199, time stamp: 0x563a76a9
Faulting module name: atieclxx.exe, version: 6.14.11.1199, time stamp: 0x563a76a9
Exception code: 0xc0000005
Fault offset: 0x00000000000425c6
Faulting process id: 0x6e4
Faulting application start time: 0x01d893a472f201e4
Faulting application path: C:\WINDOWS\system32\atieclxx.exe
Faulting module path: C:\WINDOWS\system32\atieclxx.exe
Report Id: 8e5130fe-5da0-409f-b503-72f1a1f668b3
Faulting package full name:
Faulting package-relative application ID:
Error: (07/09/2022 08:29:19 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (07/09/2022 08:19:34 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (07/09/2022 07:31:51 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program javaw.exe version 8.0.51.16 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
Process ID: 1f8c
Start Time: 01d89392a07db530
Termination Time: 4
Application Path: C:\Users\MetallicAlter\AppData\Roaming\.minecraft\runtime\jre-legacy\windows\jre-legacy\bin\javaw.exe
Report Id: a53cf154-cf15-4592-9547-bd976ddd4edd
Faulting package full name:
Faulting package-relative application ID:
Hang type: Unknown
Error: (07/09/2022 05:54:45 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (07/09/2022 05:15:30 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (07/09/2022 05:02:31 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (07/09/2022 04:36:24 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007007B
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=2
Error: (07/09/2022 04:36:17 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007007B
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
System errors:
=============
Error: (07/09/2022 09:28:38 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error:
%%2153972227 = Unable to access a key.
Error: (07/09/2022 09:28:38 PM) (Source: PNRPSvc) (EventID: 102) (User: )
Description: Event-ID 102
Error: (07/09/2022 08:29:11 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:26:24 PM on 7/9/2022 was unexpected.
Error: (07/09/2022 08:19:24 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 7:54:35 PM on 7/9/2022 was unexpected.
Error: (07/09/2022 05:54:35 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 5:15:22 PM on 7/9/2022 was unexpected.
Error: (07/09/2022 05:15:22 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 5:02:22 PM on 7/9/2022 was unexpected.
Error: (07/09/2022 05:11:15 PM) (Source: nvlddmkm) (EventID: 14) (User: )
Description: Event-ID 14
Error: (07/09/2022 05:02:22 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 12:13:53 AM on 7/9/2022 was unexpected.
Error: (07/08/2022 08:13:53 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 6:07:30 AM on 7/8/2022 was unexpected.
Error: (07/07/2022 07:27:31 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 7:13:31 PM on 7/7/2022 was unexpected.
Windows Defender:
================
Date: 2022-06-10 17:17:11
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2022-06-02 14:52:26
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2022-05-25 21:36:20
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2022-05-19 02:58:48
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...:Win32/OfferCore&threatid=311999&enterprise=0
Name: PUADlManager:Win32/OfferCore
Severity: Low
Category: Potentially Unwanted Software
Path: containerfile:_C:\Users\MetallicAlter\Downloads\Hannahowo leaked mega - Linkvertise Downloader.zip; file:_C:\Users\MetallicAlter\Downloads\Hannahowo leaked mega - Linkvertise Downloader.zip->Hannahowo leaked mega - Linkvertise Downloader_RZN-mv1.exe; webfile:_C:\Users\MetallicAlter\Downloads\Hannahowo leaked mega - Linkvertise Downloader.zip|https://d1174705pgz8b8.cloudfront.net/installer/436213509051600/6616494|pid:13676,ProcessStart:132973829274694833
Detection Origin: Internet
Detection Type: Concrete
Detection Source: Downloads and attachments
Process Name: Unknown
Security intelligence Version: AV: 1.367.96.0, AS: 1.367.96.0, NIS: 1.367.96.0
Engine Version: AM: 1.1.19200.6, NIS: 1.1.19200.6
Date: 2022-05-19 02:57:22
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...:Win32/OfferCore&threatid=311999&enterprise=0
Name: PUADlManager:Win32/OfferCore
Severity: Low
Category: Potentially Unwanted Software
Path: containerfile:_C:\Users\MetallicAlter\Downloads\Hannahowo mega (1).zip; file:_C:\Users\MetallicAlter\Downloads\Hannahowo mega (1).zip->Hannahowo mega_5f3v-m1.exe; webfile:_C:\Users\MetallicAlter\Downloads\Hannahowo mega (1).zip|https://d1174705pgz8b8.cloudfront.net/installer/99548121086/5229686|pid:14712,ProcessStart:132973828414083306
Detection Origin: Internet
Detection Type: Concrete
Detection Source: Downloads and attachments
Process Name: Unknown
Security intelligence Version: AV: 1.367.96.0, AS: 1.367.96.0, NIS: 1.367.96.0
Engine Version: AM: 1.1.19200.6, NIS: 1.1.19200.6
=========================== Installed Programs ============================
BEACHED (HKLM\...\Steam App 1412190) (Version: - Gradient Studios)
Epic Games Launcher (HKLM-x32\...\{FAC47927-1A6A-4C6E-AD7D-E9756794A4BC}) (Version: 1.3.23.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Epic Online Services (HKLM-x32\...\{758842D2-1538-4008-A8E3-66F65A061C52}) (Version: 2.0.33.0 - Epic Games, Inc.)
Free Download Manager (HKLM\...\{0C1D4CF2-5575-4786-834C-B0FC977E9714}}_is1) (Version: 6.16.1.4558 - Softdeluxe)
Java 8 Update 333 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180333F0}) (Version: 8.0.3330.2 - Oracle Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation)
NVIDIA FrameView SDK 1.2.7521.31103277 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.2.7521.31103277 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.25.1.27 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.25.1.27 - NVIDIA Corporation)
NVIDIA Graphics Driver 516.59 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 516.59 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.39.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.39.3 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)
qBittorrent 4.4.2 (HKLM-x32\...\qBittorrent) (Version: 4.4.2 - The qBittorrent project)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7841 - Realtek Semiconductor Corp.)
Riot Vanguard (HKLM\...\Riot Vanguard) (Version: - Riot Games, Inc.)
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
WinRAR 6.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.11.0 - win.rar GmbH)
WO Mic Client (HKLM-x32\...\WOMic) (Version: - )
Packages:
=========
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.962.0_x64__56jybvy8sckqj [2022-07-07] (NVIDIA Corp.)
========================= Memory info: ===================================
Percentage of memory in use: 29%
Total physical RAM: 16294.27 MB
Available physical RAM: 11546.12 MB
Total Virtual: 22182.27 MB
Available Virtual: 15494.56 MB
========================= Partitions: =====================================
1 Drive c: () (Fixed) (Total:222.94 GB) (Free:96.76 GB) NTFS
2 Drive d: (Hard Drive) (Fixed) (Total:931.5 GB) (Free:306.13 GB) NTFS
========================= Users: ========================================
User accounts for \\DESKTOP-EEHFES3
Administrator DefaultAccount Guest
MetallicAlter WDAGUtilityAccount
** End of log **
I'm not particularly experienced in troubleshooting hardware errors like these, but I've tried my best to provide most of the necessary information. I've been running into this issue for about 2-3 months now and simply hoped the peeps over at the service center could somehow resolve it!
The .exe detected on Defender was not run, but i did unzip the .zip file after scanning it on Virustotal. Neither of those are still on the system.
Thanks so much to whoever reads through all this, all the help is appreciated!
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331c3b3a-2005-44c2-ac5e-77220c37d6b4}" />
<EventID>41</EventID>
<Version>8</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000400000000002</Keywords>
<TimeCreated SystemTime="2022-07-09T14:59:05.9374076Z" />
<EventRecordID>8884</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>DESKTOP-EEHFES3</Computer>
<Security UserID="S-1-5-18" />
</System>
- <EventData>
<Data Name="BugcheckCode">0</Data>
<Data Name="BugcheckParameter1">0x0</Data>
<Data Name="BugcheckParameter2">0x0</Data>
<Data Name="BugcheckParameter3">0x0</Data>
<Data Name="BugcheckParameter4">0x0</Data>
<Data Name="SleepInProgress">0</Data>
<Data Name="PowerButtonTimestamp">0</Data>
<Data Name="BootAppStatus">0</Data>
<Data Name="Checkpoint">0</Data>
<Data Name="ConnectedStandbyInProgress">false</Data>
<Data Name="SystemSleepTransitionsToOn">0</Data>
<Data Name="CsEntryScenarioInstanceId">0</Data>
<Data Name="BugcheckInfoFromEFI">false</Data>
<Data Name="CheckpointStatus">0</Data>
<Data Name="CsEntryScenarioInstanceIdV2">0</Data>
<Data Name="LongPowerButtonPressDetected">false</Data>
</EventData>
</Event>
Below, I have listed the specs from Speccy
http://speccy.piriform.com/results/LoTDCaYHEj1FwrLNveGBKYU
I also saw people on a different forum wanting the following information:
MiniToolBox by Farbar Version: 13-05-2022
Ran by MetallicAlter (administrator) on 09-07-2022 at 21:34:23
Running from "C:\Users\MetallicAlter\AppData\Local\Temp\scoped_dir1216_358422418"
Microsoft Windows 10 Pro (X64)
Model: System Product Name Manufacturer: System manufacturer
Boot Mode: Normal
***
========================= Event log errors: ===============================
Application errors:
==================
Error: (07/09/2022 08:49:08 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (07/09/2022 08:48:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: atieclxx.exe, version: 6.14.11.1199, time stamp: 0x563a76a9
Faulting module name: atieclxx.exe, version: 6.14.11.1199, time stamp: 0x563a76a9
Exception code: 0xc0000005
Fault offset: 0x00000000000425c6
Faulting process id: 0x6e4
Faulting application start time: 0x01d893a472f201e4
Faulting application path: C:\WINDOWS\system32\atieclxx.exe
Faulting module path: C:\WINDOWS\system32\atieclxx.exe
Report Id: 8e5130fe-5da0-409f-b503-72f1a1f668b3
Faulting package full name:
Faulting package-relative application ID:
Error: (07/09/2022 08:29:19 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (07/09/2022 08:19:34 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (07/09/2022 07:31:51 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program javaw.exe version 8.0.51.16 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
Process ID: 1f8c
Start Time: 01d89392a07db530
Termination Time: 4
Application Path: C:\Users\MetallicAlter\AppData\Roaming\.minecraft\runtime\jre-legacy\windows\jre-legacy\bin\javaw.exe
Report Id: a53cf154-cf15-4592-9547-bd976ddd4edd
Faulting package full name:
Faulting package-relative application ID:
Hang type: Unknown
Error: (07/09/2022 05:54:45 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (07/09/2022 05:15:30 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (07/09/2022 05:02:31 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Event-ID 86
Error: (07/09/2022 04:36:24 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007007B
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=2
Error: (07/09/2022 04:36:17 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007007B
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
System errors:
=============
Error: (07/09/2022 09:28:38 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error:
%%2153972227 = Unable to access a key.
Error: (07/09/2022 09:28:38 PM) (Source: PNRPSvc) (EventID: 102) (User: )
Description: Event-ID 102
Error: (07/09/2022 08:29:11 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:26:24 PM on 7/9/2022 was unexpected.
Error: (07/09/2022 08:19:24 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 7:54:35 PM on 7/9/2022 was unexpected.
Error: (07/09/2022 05:54:35 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 5:15:22 PM on 7/9/2022 was unexpected.
Error: (07/09/2022 05:15:22 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 5:02:22 PM on 7/9/2022 was unexpected.
Error: (07/09/2022 05:11:15 PM) (Source: nvlddmkm) (EventID: 14) (User: )
Description: Event-ID 14
Error: (07/09/2022 05:02:22 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 12:13:53 AM on 7/9/2022 was unexpected.
Error: (07/08/2022 08:13:53 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 6:07:30 AM on 7/8/2022 was unexpected.
Error: (07/07/2022 07:27:31 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 7:13:31 PM on 7/7/2022 was unexpected.
Windows Defender:
================
Date: 2022-06-10 17:17:11
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2022-06-02 14:52:26
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2022-05-25 21:36:20
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2022-05-19 02:58:48
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...:Win32/OfferCore&threatid=311999&enterprise=0
Name: PUADlManager:Win32/OfferCore
Severity: Low
Category: Potentially Unwanted Software
Path: containerfile:_C:\Users\MetallicAlter\Downloads\Hannahowo leaked mega - Linkvertise Downloader.zip; file:_C:\Users\MetallicAlter\Downloads\Hannahowo leaked mega - Linkvertise Downloader.zip->Hannahowo leaked mega - Linkvertise Downloader_RZN-mv1.exe; webfile:_C:\Users\MetallicAlter\Downloads\Hannahowo leaked mega - Linkvertise Downloader.zip|https://d1174705pgz8b8.cloudfront.net/installer/436213509051600/6616494|pid:13676,ProcessStart:132973829274694833
Detection Origin: Internet
Detection Type: Concrete
Detection Source: Downloads and attachments
Process Name: Unknown
Security intelligence Version: AV: 1.367.96.0, AS: 1.367.96.0, NIS: 1.367.96.0
Engine Version: AM: 1.1.19200.6, NIS: 1.1.19200.6
Date: 2022-05-19 02:57:22
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...:Win32/OfferCore&threatid=311999&enterprise=0
Name: PUADlManager:Win32/OfferCore
Severity: Low
Category: Potentially Unwanted Software
Path: containerfile:_C:\Users\MetallicAlter\Downloads\Hannahowo mega (1).zip; file:_C:\Users\MetallicAlter\Downloads\Hannahowo mega (1).zip->Hannahowo mega_5f3v-m1.exe; webfile:_C:\Users\MetallicAlter\Downloads\Hannahowo mega (1).zip|https://d1174705pgz8b8.cloudfront.net/installer/99548121086/5229686|pid:14712,ProcessStart:132973828414083306
Detection Origin: Internet
Detection Type: Concrete
Detection Source: Downloads and attachments
Process Name: Unknown
Security intelligence Version: AV: 1.367.96.0, AS: 1.367.96.0, NIS: 1.367.96.0
Engine Version: AM: 1.1.19200.6, NIS: 1.1.19200.6
=========================== Installed Programs ============================
BEACHED (HKLM\...\Steam App 1412190) (Version: - Gradient Studios)
Epic Games Launcher (HKLM-x32\...\{FAC47927-1A6A-4C6E-AD7D-E9756794A4BC}) (Version: 1.3.23.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Epic Online Services (HKLM-x32\...\{758842D2-1538-4008-A8E3-66F65A061C52}) (Version: 2.0.33.0 - Epic Games, Inc.)
Free Download Manager (HKLM\...\{0C1D4CF2-5575-4786-834C-B0FC977E9714}}_is1) (Version: 6.16.1.4558 - Softdeluxe)
Java 8 Update 333 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180333F0}) (Version: 8.0.3330.2 - Oracle Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation)
NVIDIA FrameView SDK 1.2.7521.31103277 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.2.7521.31103277 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.25.1.27 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.25.1.27 - NVIDIA Corporation)
NVIDIA Graphics Driver 516.59 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 516.59 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.39.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.39.3 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)
qBittorrent 4.4.2 (HKLM-x32\...\qBittorrent) (Version: 4.4.2 - The qBittorrent project)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7841 - Realtek Semiconductor Corp.)
Riot Vanguard (HKLM\...\Riot Vanguard) (Version: - Riot Games, Inc.)
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
WinRAR 6.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.11.0 - win.rar GmbH)
WO Mic Client (HKLM-x32\...\WOMic) (Version: - )
Packages:
=========
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.962.0_x64__56jybvy8sckqj [2022-07-07] (NVIDIA Corp.)
========================= Memory info: ===================================
Percentage of memory in use: 29%
Total physical RAM: 16294.27 MB
Available physical RAM: 11546.12 MB
Total Virtual: 22182.27 MB
Available Virtual: 15494.56 MB
========================= Partitions: =====================================
1 Drive c: () (Fixed) (Total:222.94 GB) (Free:96.76 GB) NTFS
2 Drive d: (Hard Drive) (Fixed) (Total:931.5 GB) (Free:306.13 GB) NTFS
========================= Users: ========================================
User accounts for \\DESKTOP-EEHFES3
Administrator DefaultAccount Guest
MetallicAlter WDAGUtilityAccount
** End of log **
I'm not particularly experienced in troubleshooting hardware errors like these, but I've tried my best to provide most of the necessary information. I've been running into this issue for about 2-3 months now and simply hoped the peeps over at the service center could somehow resolve it!
The .exe detected on Defender was not run, but i did unzip the .zip file after scanning it on Virustotal. Neither of those are still on the system.
Thanks so much to whoever reads through all this, all the help is appreciated!