Windows 10: Strange Entry in Sigverif

Discus and support Strange Entry in Sigverif in Windows 10 Drivers and Hardware to solve the problem; So I have an Asus Hero VIII board, Win10 and my current Realtek audio driver is 6.0.1.8040. I found out at the ROG site that when installing these... Discussion in 'Windows 10 Drivers and Hardware' started by AirPower4ever, Feb 17, 2017.

  1. Strange Entry in Sigverif


    So I have an Asus Hero VIII board, Win10 and my current Realtek audio driver is 6.0.1.8040. I found out at the ROG site that when installing these driver that a file called atkex_cmd.exe gets deposited in the Realtek folder in the HDA area. this file causes a system entry of an error occurring when you look at the reliability screen. The answer is to just delete the file with no system instabilities.

    I have done this method for almost a year now and my system is runs fine. I got to just checking on my driver signatures using sigverif and this file is showing up. But when I check the exe location the file it is not there (of course because I deleted it right after installing these drivers every time I install them) so trying to figure out where this entry is coming from and is there a way to clear it out?

    :)
     
    AirPower4ever, Feb 17, 2017
    #1
  2. auggy Win User

    Windows 10 Code 52 Error

    It looks like the portcls.sys driver, a Windows audio related driver, may be the unsigned driver.

    Can you run the sigverif command to check for unsigned drivers:

    Start > type sigverif then click on "Sigverif Run command" > Start

    What drivers are "unsigned" ?

    After completion if you click "Advanced" > View Log you can save the log as a text file.
     
    auggy, Feb 17, 2017
    #2
  3. Strange Entry

    Anyone ever seen these entries? I just noticed them and the date happens to be the date my system crashed and had to be reinstalled.


    Strange Entry in Sigverif [​IMG]


    The first one has:

    HKEY_CLASSES_ROOT\SystemSettings\SettingId\SystemSettings_Update_PendingRestart\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Bluetooth_DeviceList\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Bluetooth_IsEnabled\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_DataSense_CellPlanUsageList\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_DataSense_ConfigureSetLimitButton\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_DataSense_ErrorLabelConfigureButton\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_DataSense_InterfaceUsageList\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_DataSense_PagePinHandler\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_DataSense_PieChart\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_PCSystem_GetDeviceID\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_PCSystem_GetDeviceName\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_PCSystem_GetDeviceSerialNumber\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_PCSystem_GetDeviceVersion\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Personalize_LockScreenBackgroundInfoText\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_CollectLogs\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_ConfigureMOMAgent\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_CortanaSettings\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_Developer_Mode\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_EngagementDetection\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_ExportRecoveryKey\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_ForceSurfaceHubAccountSyncStatus\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_GetDomainAdministratorGroup\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_GetMaintenanceWindowDuration\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_GetMaintenanceWindowStartTime\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_GetSurfaceHubAccountSyncStatus\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_GetSurfaceHubAccount\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_GetSurfaceHubName\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_MeetingInfo\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_OpenStore\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_PenUpdate\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_RequirePin\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_ResetDevice\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_RotatePassword\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_SessionTimeout\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_SetLocalAdministrator\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_SetMaintenanceWindow\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_SetSurfaceHubAccount\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_SetSurfaceHubName\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_Skype_FQDN\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_Skype_License_Link\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_WakeDisplayOnPresence\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_WirelessBeaconEnabled\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_SurfaceHub_WirelessOperatingChannel\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_Actions\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_ApplyChanges\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_AUModes\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_ChangeSettings\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_CheckForUpdates\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_FilterDefinition\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_History\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_ImportantList\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_InstallSelected\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_LastInstallTime\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_LastScanTime\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_MU_OptIn\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_OptionalList\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_PendingRestart\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_RecommendedList\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_RecommendedUpdates\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_SelectAll\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_UpdateDetails\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_Update_UpdateHistory\ : DllPath

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\Orchestrator\USOShared\StaticFilePathsToDump\ : C:\Data\ProgramData\USOShared\*

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\Orchestrator\USOShared\StaticFilePathsToDump\ : C:\Data\SystemData\ETW\StoreOperational*.etl

    Moved from: Windows / Windows 10 / Security & privacy
     
    EdwardBarcik, Feb 17, 2017
    #3
  4. Strange Entry in Sigverif

    So no one has seen this before?
     
    AirPower4ever, Feb 24, 2017
    #4
  5. Steve C Win User
    Right click that file to check its properties to see if it is genuine. You could also sent the file to virustotal to check. I have some AMD graphics driver files from the latest version which don't pass the sigverif check. You probably just have an unsigned driver.
     
    Steve C, Feb 24, 2017
    #5
  6. Thanks for the reply Steve C. I'll see if I can carve out some time today to try the latest driver. Currently the file has been deleted and is no longer on my computer yet this sigverif says it is still there at that location, That's why I was asking about this, but I see there is a newer version of the Realtek driver so I can download it, uninstall the old one, reinstall the new one and then grab the file and do as you mentioned.

    I'll let you know
     
    AirPower4ever, Apr 5, 2018
    #6
Thema:

Strange Entry in Sigverif

Loading...
  1. Strange Entry in Sigverif - Similar Threads - Strange Entry Sigverif

  2. What are these strange entries in regestry MountPoint2?

    in Windows 10 Network and Sharing
    What are these strange entries in regestry MountPoint2?: Microsoft Windows 10 Pro, Version: 10.0.19041 I have an NAS that just won't mount on the first try, but does successfully mount on the second try using:net use x: \\nuc4\share /user:nuc raspberry /y (Not the real password).But that's not why I am here. (I have a batch file...
  3. Strange registry entries

    in AntiVirus, Firewalls and System Security
    Strange registry entries: When searching the registry I came across the entries: The only languages I have installed are American and English. Are these entries installed by Microsoft or by malware?...
  4. strange entries in services

    in AntiVirus, Firewalls and System Security
    strange entries in services: [ATTACH] When I open services page I noticed there are some strange entries, as you can see from the screenshot there are some entries ended in 6dd8d3 like AarSvc_6dd8d3, BluetoothUserService_6dd8d3 and others. What are those ? are they virus ?...
  5. Strange Entries in Group Policy Editor

    in Windows 10 Ask Insider
    Strange Entries in Group Policy Editor: [ATTACH] Hi Guys, i was trying to trigger the 20h2 update in the group policy editor and saw this weird "Windows Security" entry, that doesnt seem normal. Anybody know whats up here? WIndows 10 Pro 10.0.18363...
  6. Strange entry in appwiz.cpl

    in Windows 10 Network and Sharing
    Strange entry in appwiz.cpl: I went into flag-key < appwiz.cpl to uninstall a different program, and I found this as one of the entries: [ATTACH]I have no idea what that is. It doesn't look like part of the Windows OS or something important. Should I uninstall this?...
  7. Strange email entries in contacts

    in Windows 10 Software and Apps
    Strange email entries in contacts: I'm having strange email entries in many of my contacts. Here is an example: Other email [necid: fq+cmm0sh6tjgrnqbnj0smqaacihmvdgaaaaabcjq8jn59bdgqwavbdlc5shaa50e0klskfkq/mla3xjopeaaaaaaq4aaa50e0klskfkq/mla3xjopeaaaaahncaabe=] This is in my daughters entry. I cannot edit...
  8. strange entry in Aministrative Events log

    in AntiVirus, Firewalls and System Security
    strange entry in Aministrative Events log: Was having trouble with W10 switching between desktop and tablet mode. Was so bad for a few days I could hardly use my computer. I looked through the windows logs to see if there were any unusual events. Found an item with a very unusual font that is difficult to read. I...
  9. Strange task scheduler entry

    in AntiVirus, Firewalls and System Security
    Strange task scheduler entry: Hello, I have a entry in my task scheduler under Microsoft>Windows>rempl> "shell" Primary shell invocation for sediment pack trigger everyday. Can anyone tell me what is this and what it does? For the record, I already scanned my computer with Malwarebytes anti-malware, found...
  10. Strange Log Entry

    in Windows 10 Support
    Strange Log Entry: Has anyone ever seen an entry to admin log file like this: The platform firmware has corrupted memory across the previous system power transition. Date and time: 1/11/2183 - 10:46:25 pm. How would someone even go about fixing this from reappearing since this is the third...