Cultmethod
Member
- Aug 31, 2018
- 23
I built my workstation PC and it's been working flawlessly for about 2-3 years. Today I just got a BSOD (first one ever) while working in Photoshop CC:
I then ran sfc /scannow from an elevated command prompt and let it do its thing. It said it found corrupted files and told me to check the CBS.log file.
So I copied and opened the CBS.log file and scanned through to see if I could find anything. Here are the errors I could find:
While I am concerned about these errors, I am also concerned by some of the other entries in CBS.log. It looks like yesterday and earlier today some various "FoD packages" (according to the log) were installed and a lot of them seem related to remote management. I never use remote tools with my PC.
Ultimately I am concerned my PC is compromised and came here looking for some help. If anyone can possibly identify what's going on, that would be great.
Speccy link: http://speccy.piriform.com/results/QXnUMFE5UdP3tG1qFFO72i1
Code:
SYSTEM THREAD EXCEPTION NOT HANDLED
I then ran sfc /scannow from an elevated command prompt and let it do its thing. It said it found corrupted files and told me to check the CBS.log file.
So I copied and opened the CBS.log file and scanned through to see if I could find anything. Here are the errors I could find:
Code:
Warning: Overlap: Directory \??\C:\Program Files (x86)\ is owned twice or has its security set twice
Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}
New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}
2021-10-01 19:21:21, Info CSI 000001cd Warning: Overlap: Directory \??\C:\ProgramData\Microsoft\Windows\Start Menu\ is owned twice or has its security set twice
Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}
New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}
2021-10-01 19:21:21, Info CSI 000001ce Warning: Overlap: Directory \??\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ is owned twice or has its security set twice
Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}
New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}
2021-10-01 19:21:21, Info CSI 000001cf Warning: Overlap: Directory \??\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ is owned twice or has its security set twice
Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}
New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}
Code:
2021-10-01 19:21:12, Info CSI 00000195 Warning: Overlap: Directory \??\C:\WINDOWS\SysWOW64\drivers\en-US\ is owned twice or has its security set twice
Original owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch Host= amd64 Guest= x86, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}
New owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch Host= amd64 Guest= x86, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}
2021-10-01 19:21:12, Info CSI 00000196 Warning: Overlap: Directory \??\C:\WINDOWS\SysWOW64\wbem\en-US\ is owned twice or has its security set twice
Original owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch Host= amd64 Guest= x86, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}
New owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch Host= amd64 Guest= x86, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}
2021-10-01 19:21:12, Info CSI 00000197 Warning: Overlap: Directory \??\C:\WINDOWS\help\mui\0409\ is owned twice or has its security set twice
Original owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch Host= amd64 Guest= x86, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}
New owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch Host= amd64 Guest= x86, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}
Code:
2021-10-01 19:20:44, Info CSI 00000100 Warning: Overlap: Directory \??\C:\ProgramData\Microsoft\Windows\Start Menu\ is owned twice or has its security set twice
Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch amd64, nonSxS, pkt {l:8 b:31bf3856ad364e35}
New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch amd64, nonSxS, pkt {l:8 b:31bf3856ad364e35}
2021-10-01 19:20:44, Info CSI 00000101 Warning: Overlap: Directory \??\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ is owned twice or has its security set twice
Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch amd64, nonSxS, pkt {l:8 b:31bf3856ad364e35}
New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch amd64, nonSxS, pkt {l:8 b:31bf3856ad364e35}
2021-10-01 19:20:44, Info CSI 00000102 Warning: Overlap: Directory \??\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ is owned twice or has its security set twice
Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch amd64, nonSxS, pkt {l:8 b:31bf3856ad364e35}
New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch amd64, nonSxS, pkt {l:8 b:31bf3856ad364e35}
Code:
2021-10-01 19:20:17, Info CSI 0000007c Warning: Overlap: Directory \??\C:\WINDOWS\System32\drivers\en-US\ is owned twice or has its security set twice
Original owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch amd64, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}
New owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch amd64, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}
2021-10-01 19:20:17, Info CSI 0000007d Warning: Overlap: Directory \??\C:\WINDOWS\System32\wbem\en-US\ is owned twice or has its security set twice
Original owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch amd64, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}
New owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch amd64, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}
2021-10-01 19:20:17, Info CSI 0000007e Warning: Overlap: Directory \??\C:\WINDOWS\help\mui\0409\ is owned twice or has its security set twice
Original owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch amd64, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}
New owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch amd64, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}
While I am concerned about these errors, I am also concerned by some of the other entries in CBS.log. It looks like yesterday and earlier today some various "FoD packages" (according to the log) were installed and a lot of them seem related to remote management. I never use remote tools with my PC.
Ultimately I am concerned my PC is compromised and came here looking for some help. If anyone can possibly identify what's going on, that would be great.
Built it myselfSystem Manufacturer?
DesktopLaptop or Desktop?
Windows 10OS ? (Windows 10, 8.1, 8, 7, Vista)
x64x86 (32bit) or x64 (64bit)?
Windows 10What was original installed OS on system?
Full RetailIs the OS an OEM version (came pre-installed on system) or full retail version (YOU purchased it from retailer)?
About 2 yearsAge of system? (hardware)
Same as system.Age of OS installation?
No, and I'd really like to avoid that.Have you re-installed the OS?
Intel Core i9-9900KF
16GB PC4-17000 DDR4 SDRAM G-Skill F4-3600C16-16GTZRC in all four rows. (Total of 64GB)RAM (brand, EXACT model, what slots are you using?)
NVIDIA GeForce RTX 2080 TIVideo Card
Gigabyte Z390 AORUS ULTRAMotherBoard - (if NOT a laptop)
CORSAIR RMX Series, RM850xPower Supply - brand & wattage (if laptop, skip this one)
Not sure. I never manually enabled it.Is driver verifier enabled or disabled?
Just Windows security centerWhat security software are you using? (Firewall, antivirus, antimalware, antispyware, and so forth)
NoAre you using proxy, vpn, ipfilters or similar software?
NoAre you using Disk Image tools? (like daemon tools, alcohol 52% or 120%, virtual CloneDrive, roxio software)
I think I am very slightly overclocked. I did this when I first got the machine. Not using software, I did it via BIOS.Are you currently under/overclocking? Are there overclocking software installed on your system?
Speccy link: http://speccy.piriform.com/results/QXnUMFE5UdP3tG1qFFO72i1