Windows 11 [2021]

How to do that?

Btw svchost also got the same warning. But isn't svchost only can by used by windows itself?

svchost is used to host services. Most services are provided by Microsoft but there are also third party services. It's also possible a malware could install a fake service on the system although it's probably not common.
 
That is some feaky shit. I would take the drive out and scan it on a different system.
 
Screenshot 2025-02-10 094609.pngScreenshot 2025-02-10 094558.png
those are the screenshot with comaand line tab shown.
anything looks sus?

as for cmd, i cant find cmd running in task manager.
 
Try looking with Process Explorer or maybe try Autoruns
ps: finding cmd.exe in HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell is normal
 
uh... guys... help me make this made sense

1. tried to run windows defender offline but nothing happen after the full screen security prompt.
2. tried to run it thru powershell, shows error 0x8000000a (dunno how many zeroes)
3. tried to run thru cmd, it works! it reboots and start scanning.
4. back to normal windows, chkdsk found disk error on startup and told me to reboot.
5. reboot. checked windows defender scan log : 0 detected. checked the detection log, no longer detecting any issues...

screenshot. offline scan was done around that last warning. 1 hour later. still no detection.
Screenshot 2025-02-11 163628.png
 
uh... guys... help me make this made sense

1. tried to run windows defender offline but nothing happen after the full screen security prompt.
2. tried to run it thru powershell, shows error 0x8000000a (dunno how many zeroes)
3. tried to run thru cmd, it works! it reboots and start scanning.
4. back to normal windows, chkdsk found disk error on startup and told me to reboot.
5. reboot. checked windows defender scan log : 0 detected. checked the detection log, no longer detecting any issues...

screenshot. offline scan was done around that last warning. 1 hour later. still no detection.
View attachment 13110
is this still cmd.exe? did you see what the actual command line was?
 
is this still cmd.exe? did you see what the actual command line was?
yes still cmd.exe, svchost, etc... the same thing i posted previously. the command lines are also the same as the one before (no cmd.exe in task manager too).

anyway, the detection doesnt increase at all. here's the screenshot, many hours after that one.

Screenshot 2025-02-11 204205.png

so... issues fixed?

oh and i forgot to mention that i also got a windows update. it should be between 1 and 2 in my previous reply., but the update failed.
Screenshot 2025-02-11 204411.png
 
yes still cmd.exe, svchost, etc... the same thing i posted previously. the command lines are also the same as the one before (no cmd.exe in task manager too).

anyway, the detection doesnt increase at all. here's the screenshot, many hours after that one.

View attachment 13111

so... issues fixed?

oh and i forgot to mention that i also got a windows update. it should be between 1 and 2 in my previous reply., but the update failed.
View attachment 13112
try process monitor from sysinternals.com and try to have it log cmd.exe and match the times to see what trying to do
 
Back
Top