For quite some time ive been suspecting that ive been bootkitted. Suddenly I couldnt read my SMBIOS table, windows detected a hyper visor even when disabled with bcdedit. I could find traces of vpn connections getting established to MS ip addresses.
Some other explanations for what is going on ive also consider: 1. This happen when you kill defender 2. Its because i install xbox store and it is intended as an anticheat - by doing the attestion in another vm 3. This is done to make dtrace work somehow....
