2021-10-03 19:33 - 2021-10-03 19:34 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat Resetting , OK! Resetting Multicast Address, OK! 2021-10-18 13:16 - 2021-10-18 13:16 - 000000000 ____D C:\Users\Pepega\AppData\Local\ASP.NET ==================== Security Center ======================== R1 npcap; C:\Windows\system32\DRIVERS\npcap.sys [74744 2021-04-22] (Insecure.Com LLC -> Insecure.Com LLC.) 2021-10-07 17:59 - 2021-10-20 15:14 - 000000427 _____ C:\Users\Pepega\Desktop\Adjectives.txt Python Launcher (HKLM-x32\\{B6EF11B6-0882-43B1-AA75-4D3BD32A144A}) (Version: 3.9.7427.0 - Python Software Foundation) Name: SettingsModifier:Win32/PossibleHostsFileHijack (If an entry is included in the fixlist, the task (.job) file will be moved. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{bab92bdb-173c-46a1-aad1-e84ad4e1371c}" => removed successfully Virus, Trojan, Spyware, and Malware Removal Help, Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-10-2021, This is not recommended for shared computers, Apples first Rapid Security Response patch fails to install on iPhones, Extended Deal: Get Microsoft Office 2021 on sale for just $39, Best VPNs to unblock WhatsApp calling in the UAE, https://www.virustotal.com/gui/file/85aa1344d28fd7c6a911924040e5b3ae1278fb70444cd39d056bd270f147f61b, https://www.virustotal.com/gui/file/85aa1344d28fd7c6a911924040e5b3ae1278fb70444cd39d056bd270f147f61b/behavior/Microsoft%20Sysinternals, https://go.microsoft.com/fwlink/?linkid=37020&name=SettingsModifier:Win32/PossibleHostsFileHijack&threatid=14994&enterprise=0, Back to Virus, Trojan, Spyware, and Malware Removal Help. Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.30.30528 (HKLM-x32\\{97b4863e-6df5-4673-8f93-2a549b8a4a91}) (Version: 14.30.30528.0 - Microsoft Corporation) vs_devenvsharedmsi (HKLM-x32\\{50BACB43-F405-4D93-B102-DE47540F2A07}) (Version: 17.0.31703 - Microsoft Corporation) Hidden 2021-10-13 22:14 - 2021-10-07 19:32 - 001464976 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2021-10-15 11:59 - 2021-10-15 11:59 - 000000068 _____ () C:\Users\Pepega\AppData\Roaming\changzhi_leidian.data at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) 2021-10-21 09:11 - 2021-10-21 09:11 - 000058304 _____ C:\Windows\system32\Drivers\49306c4f52694e45546d63335a55524c4d56517854575651566c6c4d64334a474f565268.sys ENE_EHD_M2_HAL (HKLM-x32\\{54d3d2b5-db16-446d-b6dd-f4964b166b3b}) (Version: 1.0.8.13 - ENE TECHNOLOGY INC.) Hidden "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{29ad0c16-34a9-49f9-a1d8-81f44fff082d}" => removed successfully (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe 2021-10-02 23:22 - 2021-10-02 23:22 - 000000000 ____D C:\Program Files\Microsoft SQL Server 2021-10-02 23:04 - 2021-10-02 23:04 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} Task: {8457ad0b-1c75-431d-a5ae-ee1aed76a239} - no filepath Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.30.30528 (HKLM-x32\\{b8a0348b-0f62-46f7-b7a2-e3926f10955f}) (Version: 14.30.30528.0 - Microsoft Corporation) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{bc549475-73a3-47b9-8e8c-cce95c3b76c2}" => removed successfully 2021-10-03 15:03 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\system32\Sysprep ==================== Internet (Whitelisted) ==================== FF DefaultProfile: h4od9c6l.default Microsoft Defender Antivirus has detected malware or other potentially unwanted software. 2021-10-02 23:26 - 2021-10-02 23:26 - 000000000 ____D C:\Users\Pepega\AppData\Local\Package Cache CustomCLSID: HKU\S-1-5-21-326566074-3447909417-183555969-1001_Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\localserver32 -> "C:\Users\Pepega\AppData\Local\Microsoft\OneDrive\21.170.0822.0002\Microsoft.SharePoint.exe" => No File 2021-10-02 23:34 - 2021-10-02 23:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits Task: {dfa6b7fe-8965-4d4f-9d9a-7abe5c5ee553} - no filepath here are the virustotals for the 2 files:https://www.virustotal.com/gui/file/85aa1344d28fd7c6a911924040e5b3ae1278fb70444cd39d056bd270f147f61bhttps://www.virustotal.com/gui/file/85aa1344d28fd7c6a911924040e5b3ae1278fb70444cd39d056bd270f147f61b/behavior/Microsoft%20Sysinternals, FRST RESULTS: Task: {2a965443-ec13-4b75-abf9-394d697f739d} - no filepath 2021-10-22 11:43 - 2021-10-22 11:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games 2021-10-02 23:01 - 2021-10-02 23:01 - 000000000 ____D C:\Users\Pepega\AppData\Local\cache "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{d41d49ee-176e-4547-bd74-93495b181988}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{51006d50-cfd3-4b5a-af95-e596678bbea8}" => removed successfully 2021-10-15 11:55 - 2021-10-15 11:55 - 000000000 ____D C:\Users\Pepega\AppData\Local\BlueStacks "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{b30dbf6f-75b4-422c-82ed-f93cae0f7dec}" => removed successfully 2021-10-02 23:18 - 2021-10-02 23:18 - 000001429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio Installer.lnk Process Name: C:\Users\Pepega\AppData\Local\Discord\app-1.0.9003\Discord.exe there is a folder in SysWOW64, which i presume to be related to the miner, called 'Windows driver installation service.' Detection Type: Concrete 2021-10-03 15:47 - 2021-10-24 20:25 - 000000000 ____D C:\Windows\system32\SleepStudy Task: {65f6d357-0576-4835-8e37-d12ac62b76e0} - no filepath 2021-10-02 23:20 - 2021-10-02 23:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2022 (If an entry is included in the fixlist, it will be removed from the registry. For more information please see the following:https://go.microsoft.com/fwlink/?linkid=37020&name=SettingsModifier:Win32/PossibleHostsFileHijack&threatid=14994&enterprise=0 "C:\Users\Pepega\AppData\Local\Update.exe" => not found Task: {e0ba60f1-d26f-4185-8bb0-04b05678ff5a} - no filepath Task: {F30C20EC-C71A-406B-A23E-8B958ACE878E} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3339120 2021-09-14] (NVIDIA Corporation -> NVIDIA Corporation) 0.0.0.0 telemetry.microsoft.com 2021-10-02 22:51 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\system32\FxsTmp "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{960b6a6a-dc34-4565-96a7-4db5fb5b3ff9}" => removed successfully 0.0.0.0 sqm.telemetry.microsoft.com.nsatc.net Stage:GATHER_RULES_FROM_LICENSES vs_minshellsharedmsi (HKLM-x32\\{3113CCA8-60A5-476A-93E6-0992CE618C16}) (Version: 17.0.31709 - Microsoft Corporation) Hidden Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.10.9220.0_x64__8wekyb3d8bbwe [2021-10-12] (Microsoft Studios) [MS Ad] Task: {0ed742eb-771d-447f-a4e4-64c6fd2882f4} - no filepath HKLM\\StartupApproved\Run32: => "Adobe CCXProcess" 2021-10-02 23:00 - 2021-10-02 23:00 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\WinRAR Task: {d4928d07-631c-4754-af4f-3f5f19729138} - no filepath 2021-10-24 20:41 - 2021-10-24 20:41 - 000000000 ____D C:\Users\Pepega\AppData\Local\NPE 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\system32\1049 2021-10-24 21:15 - 2021-10-24 21:15 - 002310656 _____ (Farbar) C:\Users\Pepega\Downloads\FRST64.exe 2021-10-24 14:56 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\AppReadiness HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-326566074-3447909417-183555969-1001\\StartupApproved\Run: => "Steam" 2021-10-02 23:03 - 2021-09-14 14:39 - 000043408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\NvModuleTracker.sys at Miner.Clipboard+<>c__DisplayClass0_0.b__0() (If needed Hosts: directive could be included in the fixlist to reset Hosts.) =========== "C:\WINDOWS\syswow64\*.tmp" ========== RGB Fusion (HKLM-x32\\{FFA8F1FA-3C2C-4A94-AC0B-0DF47272C25F}) (Version: 3.21.1001.1 - Gigabyte) Task: {cefea723-c2e4-4ec0-b440-c45c5526fda8} - no filepath If you are successful, start the Dell Digital Delivery application again. HKLM\System\CurrentControlSet\Services\BlueStacksDrv_nxt => removed successfully Resetting Compartment, OK! 2021-10-24 09:40 - 2021-10-24 09:40 - 000000000 ____D C:\Users\Pepega\Documents\Call of Duty Modern Warfare Task: {51f29cff-5f75-43a6-8c78-2970cd2f96ac} - no filepath Detection Source: Real-Time Protection The file will not be moved.) Task: {fc60ad33-5948-48d9-9f11-c6ca25373a9c} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4fb942bf-3d44-41ff-bc65-52cd12996f26}" => removed successfully WebUpon reboot I was stuck at the aorus loading screen prior to booting into windows (I have a gigabyte x570 aorus elite). "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{e0ba60f1-d26f-4185-8bb0-04b05678ff5a}" => removed successfully Task: {6298650e-c3bc-47e3-a571-b4eea94ac419} - no filepath 0.0.0.0 telecommand.telemetry.microsoft.com.nsatc.net Faulting package-relative application ID: (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. AORUS LCD Panel Setting (HKLM-x32\\{82026686-454E-4233-83E3-4045BC3FB31C}_is1) (Version: 1.1.3.1 - GIGABYTE Technology Co.,Inc.) 2021-10-23 13:47 - 2021-10-23 13:47 - 000058304 _____ C:\Windows\system32\Drivers\49306c4f52694d3361456431565451784e3342326455786c5531673353475634636e566a.sys Task: {46ee8f94-e240-420c-a5e8-0660f5c5f9e1} - no filepath 2021-10-02 22:56 - 2021-10-24 19:38 - 000000000 ____D C:\ProgramData\NVIDIA HKLM\\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_df67044ddd98b524\RtkAudUService64.exe [1273712 2021-07-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{bfa657d3-0b7d-471a-89e3-f729ecb71365}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{134fdbcd-c972-40e5-a39b-91c169e4c9bf}" => removed successfully at System.Threading.ThreadHelper.ThreadStart() ==================== One month (created) (Whitelisted) ========= Task: {5ea271ce-e48a-4ade-9079-2a5bece10d83} - no filepath 2021-10-03 09:11 - 2021-10-03 09:11 - 000000000 ____D C:\Users\Pepega\AppData\Local\IdentityNexusIntegration Task: {38c61830-b1df-4717-ae92-954fefd27747} - no filepath 2021-10-15 11:58 - 2021-10-15 11:58 - 000000803 _____ C:\Users\Pepega\Desktop\LDPlayer4.lnk Startup: C:\Users\Pepega\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Thing.bat [2021-10-24] () [File not signed] "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mpcmdrun.exe" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{bd098352-5f63-4d2b-8e01-ba6a347a2975}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{098ef5b0-108d-4923-9d7d-021a97ef1fba}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{53b08e97-673e-4df6-ae10-9a73f6648a6c}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{f746fb73-bc4d-499e-882f-e5f30abe8a2f}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{560963e7-8fb3-45a5-b560-b69102dfab6a}" => removed successfully 2021-10-23 09:37 - 2021-10-23 09:37 - 000058304 _____ C:\Windows\system32\Drivers\49306c4f52694e45566e6c6b626a643359324534566b646c626d56724d32317156554e59.sys Check that it's latest OS build. Category: Settings Modifier "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{48ae682f-228f-4e67-8aa4-854778a3a6a2}" => removed successfully Startup: C:\Users\Pepega\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Thing2.bat [2021-10-24] () [File not signed] I have set the service to constantly restart as eventually when it fails to restart it crashes my entire PC. 2021-10-02 23:22 - 2021-10-02 23:26 - 000000000 ____D C:\Program Files (x86)\Windows Kits 2021-10-01 15:07 - 2021-10-01 15:07 - 002045440 _____ (TODO: ) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\SMBCtrl.dll "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{38c61830-b1df-4717-ae92-954fefd27747}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{dceb985f-25eb-484d-ae30-6da7f11e1091}" => removed successfully It has done this 1 time(s). The file will not be moved unless listed separately.) 2021-10-20 14:48 - 2021-10-20 14:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\AORUS 2021-10-24 13:01 - 2021-10-24 17:56 - 000000410 __RSH C:\ProgramData\ntuser.pol 2021-10-20 14:50 - 2021-10-20 14:50 - 000036352 ____N (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Windows\gdrv3.sys Task: {f99694c5-bf64-4109-a138-067cb4c7d2e7} - no filepath #1. CustomCLSID: HKU\S-1-5-21-326566074-3447909417-183555969-1001_Classes\CLSID\{80172dde-4e20-4df0-81a2-0a48553e80bb}\localserver32 -> C:\Users\Pepega\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe (A-Volute SAS -> A-Volute) ==================== End of FRST.txt ========================, Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-10-2021 WebA Customers may purchase an AORUS Extended Warranty at the time of registration for eligible product. 0.0.0.0 sqm.telemetry.microsoft.com start 2021-10-20 14:50 - 2021-10-20 14:50 - 000000000 ____D C:\Users\Pepega\Documents\temp Task: {a1c5790b-b106-45b9-9d9c-0442f6ab1b08} - no filepath 2021-10-02 23:24 - 2021-10-02 23:24 - 000000000 ____D C:\Users\Pepega\.dotnet Date: 2021-10-24 17:54:57.532 2021-10-02 22:55 - 2021-10-24 14:56 - 000000000 ____D C:\Users\Pepega\AppData\Local\Packages Description: The AORUS LCD Panel Service service terminated unexpectedly. 2021-10-02 23:07 - 2021-10-02 23:07 - 000000000 ____D C:\Users\Pepega\AppData\Local\tmp5qvbpq15.lck Description: Application: Windows Driver Installation Service.exe Description: S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8901968 2021-10-12] (BattlEye Innovations e.K. BlueStacksDrv_nxt => service removed successfully Python 3.9.5 pip Bootstrap (64-bit) (HKLM\\{7559EB6B-36F9-4AE8-8970-532E4DC0ECA3}) (Version: 3.9.5150.0 - Python Software Foundation) Hidden Task: {4bc5b754-7072-4f40-a1b7-dd43c20ebdf6} - no filepath Task: {964fea64-405c-411f-8d7c-f9b886d45580} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{d7495c49-8426-461c-8455-350522fba9cb}" => removed successfully at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) 2021-10-02 22:49 - 2021-10-24 14:30 - 000000000 ____D C:\Windows\minidump Task: {C6B4432E-BB97-4CBA-9DFC-158E3B8F51BE} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [680888 2021-10-07] (Mozilla Corporation -> Mozilla Foundation) VS Script Debugging Common (HKLM\\{9EC852BD-33D2-457C-99BB-ED3099B8176F}) (Version: 17.0.114.0 - Microsoft Corporation) Hidden Error: (10/24/2021 07:38:08 PM) (Source: Software Protection Platform Service) (EventID: 8211) (User: ) Python 3.9.5 Core Interpreter (64-bit symbols) (HKLM\\{7AE79937-D0A7-4D36-9965-5E91E22E5FFA}) (Version: 3.9.5150.0 - Python Software Foundation) Hidden 2021-10-07 17:52 - 2021-10-08 11:46 - 000000000 ____D C:\Program Files\Mozilla Firefox The following corrective action will be taken in 3 milliseconds: Restart the service. HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp//go.microsoft.com/fwlink/p/?LinkId=255141 Faulting application path: D:\Cheetos\Woofing\Cinx Archieves\SinEx 4.2.0 [BETA]\SinEx 4.2.0 BETA Woofer [All Winver].exe 2021-10-03 15:48 - 2021-10-24 19:36 - 000000006 ____H C:\Windows\Tasks\SA.DAT CustomCLSID: HKU\S-1-5-21-326566074-3447909417-183555969-1001_Classes\CLSID\{20894375-46AE-46E2-BAFD-CB38975CDCE6}\InprocServer32 -> C:\Users\Pepega\AppData\Local\Microsoft\OneDrive\21.170.0822.0002\amd64\FileSyncShell64.dll => No File FirewallRules: [{30A1031D-2A0F-4ED7-BB78-4C35329A0857}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) !go to the folder C:\Program Files (x86)\GIGABYTE\AORUS LCD Panel Setting\Updater\ right Task: {134fdbcd-c972-40e5-a39b-91c169e4c9bf} - no filepath 2021-10-05 09:55 - 2021-10-08 09:32 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk Process Name: C:\Users\Pepega\AppData\Local\Discord\app-1.0.9003\Discord.exe WinRT Intellisense PPI - en-us (HKLM-x32\\{15E29AFF-CB19-A20B-9A81-B0765A63115F}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden BIOS: American Megatrends International, LLC. Hey, i managed to get my computer built with a Ryzen 5 5600X and an NVIDIA GeForce Aorus Xtreme RTX 3080 - 10GB GDDR6X. Solution: Close the Dell Digital Delivery application, launch Internet Explorer and attempt to navigate to any website. 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\SysWOW64\1033 0.0.0.0 watson.telemetry.microsoft.com.nsatc.net "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{a1c5790b-b106-45b9-9d9c-0442f6ab1b08}" => removed successfully 2021-10-02 23:04 - 2021-10-02 23:04 - 000003976 _____ C:\Windows\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} Description: Faulting application name: SinEx 4.2.0 BETA Woofer [All Winver].exe, version: 0.0.0.0, time stamp: 0x616e2119 Task: {a4a7b095-aaa9-401c-a9d7-8abe8ea301af} - no filepath (If an entry is included in the fixlist, it will be removed.) HKU\S-1-5-21-326566074-3447909417-183555969-1001\\StartupApproved\Run: => "OneDrive" Loaded Profiles: Pepega 2021-10-12 19:18 - 2021-10-12 19:18 - 000000000 ____D C:\Program Files (x86)\Epic Games Feature: On Access "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{43f54ace-856e-4b50-9808-1588b79b7c18}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{378659c1-e595-42d5-9357-395cbc08c53b}" => removed successfully C:\Users\Pepega\NTUSER.pol => moved successfully 2021-10-20 14:48 - 2021-10-20 14:50 - 000000000 ____D C:\Program Files (x86)\GIGABYTE Task: {92ec50a0-247a-4611-885a-d70f21f03e46} - no filepath Fault offset: 0x000000000003a839 2021-10-24 13:24 - 2021-10-24 15:28 - 000000000 ____D C:\Users\Pepega\Desktop\resources 2021-10-13 22:14 - 2021-10-07 19:32 - 000965336 _____ C:\Windows\SysWOW64\vulkan-1.dll Resetting Site Prefix, OK! Task: {b7e27570-3f72-4ac2-b2ec-fd92b54c3a60} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{d2d2fbec-f7b4-41b4-9251-9cfdc41d781f}" => removed successfully 2021-10-22 22:53 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\system32\NDF 2021-10-16 20:37 - 2021-10-16 20:42 - 000000000 ____D C:\Users\Pepega\AppData\Local\Adobe 2021-10-18 13:16 - 2021-10-24 17:02 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\TcNo Account Switcher 2021-10-02 22:56 - 2021-10-07 19:25 - 007578032 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll Fault offset: 0x00000000000622d5 2021-10-05 09:55 - 2021-10-05 09:55 - 000000000 ____D C:\Users\Pepega\AppData\Local\Mozilla FirewallRules: [TCP Query User{3D3D13C6-EB42-4BF7-9989-E995CB143820}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.) Task: {b30dbf6f-75b4-422c-82ed-f93cae0f7dec} - no filepath 2021-10-13 22:14 - 2021-10-07 19:27 - 004938872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2021-10-04 09:35 - 2021-02-13 04:24 - 000205552 _____ (Ray Hinchliffe) C:\Windows\system32\Drivers\SIVX64.sys Resetting , OK! S4 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2109.6-0\MsMpEng.exe [128392 2021-10-24] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {098ef5b0-108d-4923-9d7d-021a97ef1fba} - no filepath Resetting Echo Sequence Request, OK! Task: {134fdbcd-c972-40e5-a39b-91c169e4c9bf} - no filepath 2021-10-24 13:05 - 2021-10-24 13:43 - 000000159 _____ C:\Users\Pepega\Desktop\thingstodelete.txt FirewallRules: [{E2EA9D77-F4B6-46E6-94CF-DAE772492424}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve Corp. -> ) VS JIT Debugger (HKLM\\{43F73608-5C94-436F-A1E6-E09ACE680391}) (Version: 17.0.114.0 - Microsoft Corporation) Hidden Adobe Creative Cloud (HKLM-x32\\Adobe Creative Cloud) (Version: 5.6.0.788 - Adobe Inc.) Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000) We are passionate about teaming up with gamers to fearlessly challenge the limits and win ultimate glory. (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3> Task: {977e0d72-710d-4264-bfbf-105f17f81aa3} - no filepath NVIDIA PhysX System Software 9.21.0713 (HKLM\\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation) 2021-10-24 21:15 - 2021-10-24 21:19 - 000000000 ____D C:\FRST "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{fae948d5-3779-41c7-9906-949a94f8fbda}" => removed successfully Task: {bab92bdb-173c-46a1-aad1-e84ad4e1371c} - no filepath The file will not be moved unless listed separately.) at System.Windows.Forms.Clipboard.ThrowIfFailed(Int32) 'Thing.bat' and 'Thing2.bat' are batch files that i wrote to try and kill 'Update.exe' and 'Windows Driver Installation Service.exe' on startup, but as said in my post, the apps have a delayed start so my batch files are pretty much useless. Error: Unable to rebuild performance counter setting from system backup store, error code is 2
Hospital Linen Attendant Job Description,
Articles T