#1. Detection Type: Concrete ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2021-09-15] (Adobe Inc. -> ) Description: Faulting application name: Windows Driver Installation Service.exe, version: 10.0.100.100, time stamp: 0x6174a237 2021-10-13 22:14 - 2021-10-07 19:32 - 001464976 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll Error description: The handle is invalid. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95d6d4ae-89c2-47b7-947d-0a2c92579474}" => removed successfully 2021-10-18 20:24 - 2021-10-18 20:24 - 000000000 ____D C:\Program Files\AMD (NortonLifeLock Inc. -> NortonLifeLock Inc.) C:\Users\Pepega\Downloads\NPE.exe 2021-10-02 23:04 - 2021-10-02 23:04 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} Resetting , OK! (NVIDIA Corporation -> NVIDIA) C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe 2021-10-07 17:52 - 2021-10-08 11:46 - 000000000 ____D C:\Program Files\Mozilla Firefox 2021-10-02 23:25 - 2021-10-02 23:26 - 000000000 ____D C:\Windows\SysWOW64\1031 WebOpen Hours: Monday Saturday, 8:00 a.m. 6:00 p.m. Login Register; Home; Contact Us Task: {10914230-EDDF-4324-BD6D-2A05C1496959} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-09-14] (NVIDIA Corporation -> NVIDIA Corporation) Error: (10/24/2021 06:01:46 PM) (Source: DCOM) (EventID: 10010) (User: Avalanche-14329) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{80442d75-04ca-4d81-8c53-a52f6d4b32b0}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{977e0d72-710d-4264-bfbf-105f17f81aa3}" => removed successfully Faulting package-relative application ID: HKU\S-1-5-21-326566074-3447909417-183555969-1001\\Run: [Windows Driver Installation Service] => C:\Windows\SysWOW64\Windows Driver Installation Service\Windows Driver Installation Service.exe 2021-10-02 22:51 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\system32\FxsTmp Faulting application start time: 0x01d7c8b23661392d Tcpip\..\Interfaces\{710b131b-0ffc-4c94-8d3e-1b075637d571}: [DhcpNameServer] 1.1.1.1 1.0.0.1 Description: The AORUS LCD Panel Service service terminated unexpectedly. 2021-10-04 11:39 - 2021-10-14 11:49 - 000058304 _____ (Intel Corporation ) C:\Windows\system32\Drivers\49306c4f52694e4557446c556347467a5a44673559566c4954584a44616c687152576c6a.sys 2021-10-24 20:41 - 2021-10-24 20:41 - 013884680 _____ (NortonLifeLock Inc.) C:\Users\Pepega\Downloads\NPE.exe Task: {134fdbcd-c972-40e5-a39b-91c169e4c9bf} - no filepath Resetting Route, OK! Faulting module path: C:\Windows\System32\KERNELBASE.dll "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{257fa8a3-d406-4d7e-99a9-c9e255f9f6f0}" => removed successfully 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\SysWOW64\1029 2021-10-18 20:24 - 2021-10-18 20:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Ryzen Master 2021-10-24 17:59 - 2021-10-24 18:15 - 000000000 ____D C:\Exotic 2.6 Update "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{e0ba60f1-d26f-4185-8bb0-04b05678ff5a}" => removed successfully Microsoft Update Health Tools (HKLM\\{8A6AB459-CB4B-4D09-8C1E-337FB59135C4}) (Version: 2.84.0.0 - Microsoft Corporation) Task: {C29DAE2E-7E30-4647-AAB2-EB669473462C} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe [66472 2021-10-02] (Microsoft Corporation -> Microsoft) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe Edge Profile: C:\Users\Pepega\AppData\Local\Microsoft\Edge\User Data\Default [2021-10-24] 2021-10-16 20:49 - 2021-10-16 20:49 - 000001142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder 2021.lnk 2021-10-24 12:15 - 2021-10-24 12:15 - 000000000 ____D C:\Program Files (x86)\Print driver host for applications R2 NahimicService; C:\Windows\system32\NahimicService.exe [1633288 2020-12-10] (A-Volute SAS -> Nahimic) When i clicked on properties, it said that its original name was 'Update.exe.' The NVIDIA LocalSystem Container service terminated unexpectedly. But again, it could be just a temporary solution, and the miner would re-appear again. Task: {1e6a4e2b-eca4-4162-8baf-5e2cbc56f0a8} - no filepath Running from C:\Users\Pepega\Downloads "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6c61cc2f-6bf1-4d13-9cc0-dd2cf2ba3087}" => removed successfully CustomCLSID: HKU\S-1-5-21-326566074-3447909417-183555969-1001_Classes\CLSID\{20894375-46AE-46E2-BAFD-CB38975CDCE6}\InprocServer32 -> C:\Users\Pepega\AppData\Local\Microsoft\OneDrive\21.170.0822.0002\amd64\FileSyncShell64.dll => No File Task: {8457ad0b-1c75-431d-a5ae-ee1aed76a239} - no filepath It is the time when you shutdown not Task: {7758a3fe-bd22-4403-acda-05ae12b2505a} - no filepath 2021-10-15 11:59 - 2021-10-15 11:59 - 000000128 _____ C:\Users\Pepega\AppData\Roaming\changzhi_leidianmac.data 2021-10-21 12:44 - 2021-10-21 12:44 - 000058304 _____ C:\Windows\system32\Drivers\49306c4f52694e4552323830615856545245354261476c4f516b4658556c5a5163446b33.sys 2021-10-24 20:41 - 2021-10-24 20:41 - 000000000 ____D C:\ProgramData\Norton The following corrective action will be taken in 3 milliseconds: Restart the service. 2021-10-04 18:19 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\ServiceState "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ab7dbf26-2e26-445a-a7dd-f60ac12f19a6}" => removed successfully Task: {4204c90d-5097-480b-ab90-0cff3c443b89} - no filepath 2021-10-08 16:58 - 2021-10-08 16:58 - 000058304 _____ C:\Windows\system32\Drivers\49306c4f52694d3363575a7151566834646c4a3252566836626a644955474a7463474a6f.sys 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\SysWOW64\1055 Task: {95d6d4ae-89c2-47b7-947d-0a2c92579474} - no filepath 2021-10-03 15:47 - 2021-10-18 20:25 - 000270480 _____ C:\Windows\system32\FNTCACHE.DAT ?\C:\Program Files\BlueStacks_nxt\BstkDrv_nxt.sys [X] 2021-10-02 23:49 - 2021-10-04 18:19 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 0.0.0.0 choice.microsoft.com Task: {519e0c96-0a46-4c15-840e-41ed3cda1aef} - no filepath 2021-10-16 20:42 - 2021-10-17 14:37 - 000000000 ___RD C:\Users\Pepega\Creative Cloud Files FirewallRules: [TCP Query User{3D3D13C6-EB42-4BF7-9989-E995CB143820}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.) Task: {481404b2-cd19-4388-9998-80f99056dcfd} - no filepath ==================== MSCONFIG/TASK MANAGER disabled items == The system cannot find the file specified. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{481404b2-cd19-4388-9998-80f99056dcfd}" => removed successfully S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8901968 2021-10-12] (BattlEye Innovations e.K. ================ Task: {560963e7-8fb3-45a5-b560-b69102dfab6a} - no filepath Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.10.9220.0_x64__8wekyb3d8bbwe [2021-10-12] (Microsoft Studios) [MS Ad] 2021-10-14 10:50 - 2021-10-14 17:35 - 000001229 ____H () C:\Users\Pepega\AppData\Local\d89b27a4d89b27a4d89b Python Launcher (HKLM-x32\\{B6EF11B6-0882-43B1-AA75-4D3BD32A144A}) (Version: 3.9.7427.0 - Python Software Foundation) 2021-10-24 20:37 - 2021-10-24 20:37 - 000000000 ____D C:\Users\Pepega\AppData\Local\D3DSCache Task: {0ffde93b-8785-42a8-8c6c-2672d544280d} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{519e0c96-0a46-4c15-840e-41ed3cda1aef}" => removed successfully 1. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{b2522ebf-6a65-406b-9bc7-1ce57d2a2c7c}" => removed successfully Task: {7ef13d49-f1cb-4454-af1c-a7a9e880a031} - no filepath SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp//www.bing.com/search?q={searchTerms}&FORM=IE8SRC (If an entry is included in the fixlist, it will be removed from the registry. 0.0.0.0 settings-sandbox.data.microsoft.com Task: {80442d75-04ca-4d81-8c53-a52f6d4b32b0} - no filepath HKU\S-1-5-21-326566074-3447909417-183555969-1001\\StartupApproved\Run: => "OneDrive" Task: {bab92bdb-173c-46a1-aad1-e84ad4e1371c} - no filepath (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3> (There is no automatic fix for files that do not pass verification.) \\?\Volume{66a9e99a-1cf4-4f5a-a085-9db2177d6629}\ (Recovery) (Fixed) (Total:0.52 GB) (Free:0.5 GB) NTFS Engine Version: AM: 1.1.18600.4, NIS: 1.1.18600.4 2021-10-18 19:33 - 2021-10-18 19:35 - 000000000 ____D C:\ProgramData\A-Volute Latest News: Apples first Rapid Security Response patch fails to install on iPhones, Featured Deal: Extended Deal: Get Microsoft Office 2021 on sale for just $39, Latest Buyer's Guide: Best VPNs to unblock WhatsApp calling in the UAE. Date: 2021-10-24 15:35:53.954 HKU\S-1-5-21-326566074-3447909417-183555969-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C} => removed successfully Task: {68703689-47bd-47ee-9cf2-e91abb43a182} - no filepath S4 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2109.6-0\MsMpEng.exe [128392 2021-10-24] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {16be7f3f-fa2f-44f1-b9e0-bb9be341d6ea} - no filepath HKLM-x32\\RunOnce: [SelLed] => C:\Program Files (x86)\GIGABYTE\RGBFusion\RunLed.exe [50096 2019-04-29] (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) 2021-10-02 22:50 - 2019-03-19 15:52 - 000000000 ____D C:\ProgramData\USOPrivate R1 vgk; C:\Program Files\Riot Vanguard\vgk.sys [8234256 2021-10-21] (Riot Games, Inc. -> Riot Games, Inc.) 10,510. Task: {8c4fdb45-99dd-42f3-8984-07e5f8dff7f4} - no filepath 2021-10-03 15:48 - 2021-10-03 15:48 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf Framework Version: v4.0.30319 Task: {78bdf1d8-0a82-4ea3-8ac6-e6a6e95fd874} - no filepath FirewallRules: [{4AE2A4DF-F2A8-4220-B0E2-D6204D68459E}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\95.0.1020.30\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{DB71EC80-788B-445B-9273-DF4E830413A2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) Detection Source: System 2021-10-01 15:07 - 2021-10-01 15:07 - 002045440 _____ (TODO: ) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\SMBCtrl.dll Resetting Compartment, OK! Task: {d2d2fbec-f7b4-41b4-9251-9cfdc41d781f} - no filepath not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7d4dac2b-fbf4-45de-adae-6a9396b9ca9c}" => removed successfully 2021-10-02 23:03 - 2021-09-14 14:39 - 000144240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll vs_CoreEditorFonts (HKLM-x32\\{E247EDC7-CB46-45AD-9F59-C5C339A006D9}) (Version: 17.0.31716 - Microsoft Corporation) Hidden 2021-10-03 18:36 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\system32\oobe Python 3.9.5 Tcl/Tk Support (64-bit) (HKLM\\{351016A7-AED4-4824-8D2E-2F9ED497CF77}) (Version: 3.9.5150.0 - Python Software Foundation) Hidden Python 3.9.5 Core Interpreter (64-bit symbols) (HKLM\\{7AE79937-D0A7-4D36-9965-5E91E22E5FFA}) (Version: 3.9.5150.0 - Python Software Foundation) Hidden HKU\S-1-5-21-326566074-3447909417-183555969-1001_Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1} => removed successfully The file will not be moved unless listed separately.) Description: The WinRing0_1_2_0 service failed to start due to the following error: And if the question was in general wich LCD Panel we mean. The Aorus Master 370 and 3080 have a LCD Panel on the site to show of GPU Stats and Gifs. THANK YOU! Microsoft Windows Desktop Runtime - 5.0.11 (x64) (HKLM-x32\\{59d2a8eb-a667-428d-a393-42df4da226a4}) (Version: 5.0.11.30524 - Microsoft Corporation) 2021-10-03 18:39 - 2021-10-07 12:21 - 000049533 _____ C:\Windows\diagerr.xml 2021-10-15 11:59 - 2021-10-15 11:59 - 000000068 _____ () C:\Users\Pepega\AppData\Roaming\changzhi_leidian.data WebKey Warranty Conditions. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{bc549475-73a3-47b9-8e8c-cce95c3b76c2}" => removed successfully 2021-10-24 14:37 - 2019-03-19 15:52 - 000000000 ____D C:\Program Files\Windows Defender Exception Info: System.Runtime.InteropServices.ExternalException "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11dec036-7e8b-4b5b-906d-51876287d3d1}" => removed successfully 0.0.0.0 watson.live.com (If an entry is included in the fixlist, it will be removed.) HKU\S-1-5-21-326566074-3447909417-183555969-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp//go.microsoft.com/fwlink/?LinkId=54896 =========== "C:\WINDOWS\system32\*.tmp" ========== 2021-10-21 09:11 - 2021-10-21 09:11 - 000058304 _____ C:\Windows\system32\Drivers\49306c4f52694e45546d63335a55524c4d56517854575651566c6c4d64334a474f565268.sys 2021-10-02 22:52 - 2021-10-23 10:08 - 000002421 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk FF Extension: (TubeBuddy) - C:\Users\Pepega\AppData\Roaming\Mozilla\Firefox\Profiles\q42kwfcc.default-release\Extensions\e389d8c2-5554-4ba2-a36e-ac7a57093130@gmail.com.xpi [2021-10-14] S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029472 2021-10-12] (Epic Games Inc. -> Epic Games, Inc.) 0.0.0.0 vortex-sandbox.data.microsoft.com C:\Users\Pepega\AppData\Local\Update.exe CMD: ipconfig /flushDNS HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Internet Explorer (Whitelisted) ========== C:\Windows\Temp\ASPNETSetup_00000.log => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ca0fb10b-e917-4aa5-9e3a-f6a019682f3f}" => removed successfully there is a folder in SysWOW64, which i presume to be related to the miner, called 'Windows driver installation service.' Task: {b7e27570-3f72-4ac2-b2ec-fd92b54c3a60} - no filepath Description: The AORUS LCD Panel Service service terminated unexpectedly. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{252c0390-ef87-47eb-805e-da800dd5671d}" => removed successfully VS Script Debugging Common (HKLM\\{9EC852BD-33D2-457C-99BB-ED3099B8176F}) (Version: 17.0.114.0 - Microsoft Corporation) Hidden 2021-10-02 23:01 - 2021-10-02 23:01 - 000000000 ____D C:\Users\Pepega\AppData\Local\cache Task: {ca0fb10b-e917-4aa5-9e3a-f6a019682f3f} - no filepath 2021-10-13 22:14 - 2021-10-07 19:28 - 001523328 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2021-10-02 22:59 - 2021-10-02 22:59 - 000000000 ____D C:\Program Files\WinRAR 2021-10-02 23:36 - 2021-10-24 17:28 - 000000000 ____D C:\Users\Pepega\AppData\Local\.IdentityService FF Extension: (vidIQ Vision for YouTube) - C:\Users\Pepega\AppData\Roaming\Mozilla\Firefox\Profiles\q42kwfcc.default-release\Extensions\firefox@vid.io.xpi [2021-10-23] 2021-10-02 23:26 - 2021-10-02 23:26 - 000000000 ____D C:\Users\Pepega\AppData\Local\Package Cache "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{90b432e7-5c87-425c-9dd5-33099e0e41c9}" => removed successfully 2021-10-13 22:14 - 2021-10-07 19:28 - 000676480 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll Inside that folder there is an executable called 'Windows driver installation service.' Security intelligence Version: AV: 1.351.958.0, AS: 1.351.958.0, NIS: 1.351.958.0 [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\GvIllumLib.dll 2021-10-02 23:25 - 2021-10-02 23:26 - 000000000 ____D C:\Windows\SysWOW64\1028 Task: {38c61830-b1df-4717-ae92-954fefd27747} - no filepath Task: {6c61cc2f-6bf1-4d13-9cc0-dd2cf2ba3087} - no filepath i scanned using norton power eraser, but it returned with no results. Adobe Creative Cloud (HKLM-x32\\Adobe Creative Cloud) (Version: 5.6.0.788 - Adobe Inc.) 2021-10-15 11:58 - 2021-10-15 11:58 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LDPlayer4 FirewallRules: [{E2EA9D77-F4B6-46E6-94CF-DAE772492424}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve Corp. -> ) Task: {378659c1-e595-42d5-9357-395cbc08c53b} - no filepath RGB Fusion (HKLM-x32\\{FFA8F1FA-3C2C-4A94-AC0B-0DF47272C25F}) (Version: 3.21.1001.1 - Gigabyte) Task: {134fdbcd-c972-40e5-a39b-91c169e4c9bf} - no filepath For more information please see the following:https://go.microsoft.com/fwlink/?linkid=37020&name=SettingsModifier:Win32/PossibleHostsFileHijack&threatid=14994&enterprise=0 2021-10-18 20:24 - 2021-10-18 20:24 - 000000000 ____D C:\ProgramData\AMD AutoUpdate In bios, its not showing up all of my SSDs, but at no point is it Task: {68912dca-04b7-43b9-b125-ab2888148ebb} - no filepath Engine Version: AM: 1.1.18600.4, NIS: 1.1.18600.4 Task: {e62b268c-ea0c-4217-bfa2-7bd1145ba5a0} - no filepath 2021-10-13 16:20 - 2021-10-13 16:38 - 000000254 _____ C:\Users\Pepega\AppData\LocalLow\rbxcsettings.rbx Task: {57f92185-4f7e-4549-bf72-8ded737637ee} - no filepath HKU\S-1-5-21-326566074-3447909417-183555969-1001_Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2} => removed successfully 2021-10-16 20:39 - 2021-10-16 20:41 - 000000000 ____D C:\ProgramData\Adobe 'Thing.bat' and 'Thing2.bat' are batch files that i wrote to try and kill 'Update.exe' and 'Windows Driver Installation Service.exe'. Python 3.9.5 Standard Library (64-bit) (HKLM\\{F4DC18F4-6323-4BE8-A322-38268831BC24}) (Version: 3.9.5150.0 - Python Software Foundation) Hidden "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78bdf1d8-0a82-4ea3-8ac6-e6a6e95fd874}" => removed successfully Task: {48ae682f-228f-4e67-8aa4-854778a3a6a2} - no filepath 2021-10-02 23:44 - 2021-10-24 12:19 - 000000000 ____D C:\Users\Pepega\AppData\Local\Battle.net FirewallRules: [{6044C6B5-9B61-4F44-874F-BF6511DBDB68}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) ==================== MBR & Partition Table ==================== (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) C:\Program Files (x86)\GIGABYTE\RGBFusion\RGBFusion.exe Epic Games Launcher (HKLM-x32\\{209F4B4B-3DF2-4825-9906-D4D6A80EC09E}) (Version: 1.3.0.0 - Epic Games, Inc.) 2021-10-02 23:03 - 2021-09-14 14:39 - 000043408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\NvModuleTracker.sys "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95bbc0e1-37d1-403e-badd-d7f7c4fc36d1}" => removed successfully Error: Unable to rebuild performance counter setting from system backup store, error code is 2 Default browser: FF Reason:0xC004F011 2021-10-05 09:55 - 2021-10-24 19:37 - 000000000 ____D C:\ProgramData\Mozilla 3>restart. 2021-10-15 11:58 - 2021-10-15 11:58 - 000000803 _____ C:\Users\Pepega\Desktop\LDPlayer4.lnk Task: {dfa6b7fe-8965-4d4f-9d9a-7abe5c5ee553} - no filepath Task: {44e64ec2-07de-480c-b391-0e70d56ee3de} - no filepath 2021-10-03 09:11 - 2021-10-03 09:12 - 000000000 ____D C:\Users\Pepega\Documents\Visual Studio 2022 2021-10-04 10:02 - 2021-10-04 10:02 - 000000000 ____D C:\Users\Pepega\AppData\Local\OO Software Task: {A8BA0F77-0928-4197-AD98-116E198D6501} - System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\RUXIMDisplay => C:\Program Files\ruxim\ruximics.exe [477512 2021-06-30] (Microsoft Windows -> Microsoft Corporation) 2021-10-03 09:12 - 2021-10-03 09:12 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\NuGet ClickOnce Bootstrapper Package for Microsoft .NET Framework (HKLM-x32\\{5A260D5A-95D3-4956-8E0A-E182CC4144ED}) (Version: 4.8.04162 - Microsoft Corporation) Hidden 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\system32\1045 "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{e2e2a07e-8ce9-45bf-94db-a91755d15155}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{e62b268c-ea0c-4217-bfa2-7bd1145ba5a0}" => removed successfully ==================== Safe Mode (Whitelisted) ================== Task: {a2a9bb80-76ce-4752-9e44-f43e01b26a35} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4596b534-45a4-4c4e-93a8-e4c01a69090e}" => removed successfully Faulting application path: D:\Cheetos\Woofing\Cinx Archieves\SinEx 4.2.0 [BETA]\SinEx 4.2.0 BETA Woofer [All Winver].exe "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{c68b5818-129c-4160-9e29-1a8feeb737d8}" => removed successfully icecap_collectionresourcesx64 (HKLM-x32\\{D7CA7EBC-6382-4CDB-BE73-9057ABE6DBA5}) (Version: 17.0.31709 - Microsoft Corporation) Hidden 2021-10-04 18:19 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\LiveKernelReports 2021-10-03 19:33 - 2021-10-03 19:34 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat 2021-10-02 23:20 - 2021-10-02 23:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2022 For more information please see the following:https://go.microsoft.com/fwlink/?linkid=37020&name=SettingsModifier:Win32/PossibleHostsFileHijack&threatid=14994&enterprise=0 SDK ARM Additions (HKLM-x32\\{FCF9D89E-6F79-64FB-B08D-B0E69FF54DEE}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{43f54ace-856e-4b50-9808-1588b79b7c18}" => removed successfully 0.0.0.0 vortex-win.data.microsoft.com 2021-10-02 22:51 - 2021-10-10 13:03 - 000003480 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA Task: {fc60ad33-5948-48d9-9f11-c6ca25373a9c} - no filepath Adobe Media Encoder 2021 (HKLM-x32\\AME_15_4_1) (Version: 15.4.1 - Adobe Inc.) Task: {6298650e-c3bc-47e3-a571-b4eea94ac419} - no filepath 0.0.0.0 vortex.data.microsoft.com The file will not be moved unless listed separately.) AMD_Chipset_Drivers (HKLM-x32\\{c370a4bd-5e86-489d-b1a5-54ceee532d20}) (Version: 2.15.07.2229 - Advanced Micro Devices, Inc.) Hidden 2021-10-07 17:59 - 2021-10-20 15:14 - 000000427 _____ C:\Users\Pepega\Desktop\Adjectives.txt Error: Unable to rebuild performance counter setting from system backup store, error code is 2 Resetting Anycast Address, OK! 2021-10-13 22:14 - 2021-10-07 19:32 - 000965336 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll Hey, i managed to get my computer built with a Ryzen 5 5600X and an NVIDIA GeForce Aorus Xtreme RTX 3080 - 10GB GDDR6X. FirewallRules: [{F7197523-B9AE-42F6-9BCD-3487235CDA82}] => (Allow) C:\Program Files\BlueStacks_nxt\HD-Player.exe => No File (If an entry is included in the fixlist, it will be removed from the registry. 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\SysWOW64\1049 Windows Defender: Resetting Multicast Address, OK! (If an entry is included in the fixlist, it will be removed.) The "AlternateShell" will be restored.) HKU\S-1-5-21-326566074-3447909417-183555969-1001\\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4267928 2021-10-14] (Valve -> Valve Corporation) Task: {4fb942bf-3d44-41ff-bc65-52cd12996f26} - no filepath 2021-10-18 19:32 - 2019-12-19 18:07 - 002877104 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll If registration is within 90 days of the purchase date and you are the S4 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [86264 2021-10-24] (Microsoft Windows -> Microsoft Corporation) 2021-10-02 23:34 - 2021-10-02 23:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits Task: {8a370bc5-d53d-4130-9a86-55745d7884c5} - no filepath Detection Type: Concrete Task: {a68a203b-7eaa-4914-a565-5ff9759ae2a4} - no filepath HKU\S-1-5-21-326566074-3447909417-183555969-1001\\Run: [Discord] => C:\Users\Pepega\AppData\Local\Discord\Update.exe [1512608 2021-09-22] (Discord Inc. -> GitHub) 2021-10-04 18:19 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\system32\MsDtc 2021-10-22 11:43 - 2021-10-22 12:31 - 000000000 ____D C:\Users\Pepega\AppData\Local\Riot Games "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{51f29cff-5f75-43a6-8c78-2970cd2f96ac}" => removed successfully Task: {f72e227f-a82a-46d0-b517-0dcc9c2c1947} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{d7495c49-8426-461c-8455-350522fba9cb}" => removed successfully Ethernet: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION Task: {f0e86eb7-a641-47fc-9528-df32545b183d} - no filepath Task: {b3eb79cd-689d-4158-bea3-8771c38a327c} - no filepath The file will not be moved unless listed separately.) Description: The rules engine failed to evaluate the rules. 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\system32\1033 Task: {6d29bb8b-f135-47e9-9ff9-392b06a68bf3} - no filepath 2021-09-29 10:31 - 2021-10-24 17:56 - 000000000 ____D C:\Users\Pepega (A-Volute SAS -> A-Volute) C:\Users\Pepega\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe 2021-10-02 23:03 - 2021-10-02 23:03 - 000000000 ____D C:\Windows\system32\lxss Task: {0c664c7f-7430-46ad-86a6-f5c0223c7fc4} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{d41d49ee-176e-4547-bd74-93495b181988}" => removed successfully Microsoft Edge WebView2 Runtime (HKLM-x32\\Microsoft EdgeWebView) (Version: 95.0.1020.30 - Microsoft Corporation) 0.0.0.0 telemetry.urs.microsoft.com 2021-10-02 22:55 - 2021-10-24 19:39 - 000000000 ____D C:\Users\Pepega\AppData\Local\ConnectedDevicesPlatform LDPlayer (HKLM-x32\\LDPlayer4) (Version: 4.0.66 - XUANZHI INTERNATIONAL CO., LIMITED) S3 SIVDriver; C:\Windows\system32\Drivers\SIVX64.sys [205552 2021-02-13] (RH Software Ltd -> Ray Hinchliffe) WinRT Intellisense Mobile - en-us (HKLM-x32\\{443FF51E-16C3-F23B-18FC-0D1D66024B0B}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1a105416-49db-4c94-a1d7-5a3597878e9a}" => removed successfully 2021-10-02 23:03 - 2021-09-14 14:39 - 000069856 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys FirewallRules: [{E1D43D4F-5765-4B23-A804-FDD364EFF570}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) at Miner.Clipboard+<>c__DisplayClass0_0.b__0() 'Thing.bat' and 'Thing2.bat' are batch files that i wrote to try and kill 'Update.exe' and 'Windows Driver Installation Service.exe' on startup, but as said in my post, the apps have a delayed start so my batch files are pretty much useless. Task: {82a0b077-3637-4350-9431-56dbbbb4d5c1} - no filepath 2021-10-24 20:41 - 2021-10-24 21:08 - 000000020 _____ C:\Windows\system32\Drivers\SMR540.dat Task: {4204c90d-5097-480b-ab90-0cff3c443b89} - no filepath 2021-10-15 11:58 - 2021-10-15 11:58 - 000000828 _____ C:\Users\Pepega\Desktop\LDMultiPlayer4.lnk ========= End of CMD: ========= Resetting , OK! Category: Settings Modifier Running from C:\Users\Pepega\Downloads Available Virtual: 28808.94 MB (If an entry is included in the fixlist, the registry item will be restored to default or removed. Task: {80442d75-04ca-4d81-8c53-a52f6d4b32b0} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{572eb39c-ac47-4eda-a21b-d776650fa302}" => removed successfully icecap_collectionresources (HKLM-x32\\{D71337CA-4452-43D2-9583-45670FF77185}) (Version: 17.0.31709 - Microsoft Corporation) Hidden Security intelligence Version: AV: 1.351.958.0, AS: 1.351.958.0, NIS: 1.351.958.0 2021-08-23 15:07 - 2021-08-23 15:07 - 000423936 _____ (TODO: ) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\GvLedLib.dll 2021-10-02 23:18 - 2021-10-02 23:18 - 000001429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio Installer.lnk WinRT Intellisense IoT - Other Languages (HKLM-x32\\{216D5F47-257D-6284-5849-B51037875EFA}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden 2021-10-04 18:28 - 2021-10-04 18:28 - 000103648 _____ C:\Windows\productkey.bat Microsoft System CLR Types for SQL Server 2019 (HKLM\\{5BC7E9EB-13E8-45DB-8A60-F2481FEB4595}) (Version: 15.0.2000.5 - Microsoft Corporation) Task: {23df4797-0507-44e3-9c41-f5d1be966072} - no filepath 2021-10-02 23:46 - 2021-10-24 14:30 - 000000000 ____D C:\Program Files (x86)\Steam Task: {8457ad0b-1c75-431d-a5ae-ee1aed76a239} - no filepath Python 3.9.5 pip Bootstrap (64-bit) (HKLM\\{7559EB6B-36F9-4AE8-8970-532E4DC0ECA3}) (Version: 3.9.5150.0 - Python Software Foundation) Hidden You currently have javascript disabled. Task: {0e056076-a1e1-4979-83ca-d3b97785e4bb} - no filepath 2021-10-02 23:04 - 2021-09-14 14:39 - 000067952 _____ C:\Windows\SysWOW64\FvSDK_x86.dll
Irish Phoenix Mythology,
Capricorn Woman In Love Behavior,
Articles T