Microsoft Defender Antivirus has detected malware or other potentially unwanted software. 2021-10-19 13:07 - 2021-10-19 13:07 - 000058304 _____ C:\Windows\system32\Drivers\49306c4f52694d335248524c513067795a6a467a6448704765585a4e516d68714f565a57.sys WebAORUS is a world leading brand in high-performance motherboards, graphic cards, laptops gaming hardware and systems. 2021-10-02 23:03 - 2021-09-14 14:39 - 000168304 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll HKLM\\StartupApproved\Run32: => "Adobe CCXProcess" Resetting Route, OK! "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{a68a203b-7eaa-4914-a565-5ff9759ae2a4}" => removed successfully 2021-10-02 23:21 - 2021-10-24 14:31 - 000000000 ____D C:\Program Files (x86)\MSBuild Computer shut off. Need help | TechPowerUp Forums 2021-10-21 12:44 - 2021-10-21 12:44 - 000058304 _____ C:\Windows\system32\Drivers\49306c4f52694e4552323830615856545245354261476c4f516b4658556c5a5163446b33.sys Security intelligence Version: AV: 1.351.958.0, AS: 1.351.958.0, NIS: 1.351.958.0 Microsoft Windows Desktop Runtime - 5.0.11 (x64) (HKLM-x32\\{59d2a8eb-a667-428d-a393-42df4da226a4}) (Version: 5.0.11.30524 - Microsoft Corporation) Task: {2a965443-ec13-4b75-abf9-394d697f739d} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{57f92185-4f7e-4549-bf72-8ded737637ee}" => removed successfully 2021-10-03 16:47 - 2021-10-07 11:42 - 000000000 ____D C:\Windows\Panther Python 3.9.5 Test Suite (64-bit symbols) (HKLM\\{F47D09A3-9226-47D6-A1E4-FDE02FAF24D0}) (Version: 3.9.5150.0 - Python Software Foundation) Hidden Task: {d41d49ee-176e-4547-bd74-93495b181988} - no filepath ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2021-09-15] (Adobe Inc. -> ) Description: Application: Update.exe 2021-10-02 22:55 - 2021-10-16 20:49 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\Adobe Task: {977e0d72-710d-4264-bfbf-105f17f81aa3} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{481404b2-cd19-4388-9998-80f99056dcfd}" => removed successfully RGB Fusion with Digital LEDs comes with 9 new patterns and various speed settings with more to come. Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Task: {977e0d72-710d-4264-bfbf-105f17f81aa3} - no filepath Resetting Control Protocol, OK! Path: file:_C:\Windows\System32\drivers\etc\hosts Task: {dfa6b7fe-8965-4d4f-9d9a-7abe5c5ee553} - no filepath Visual Studio Community 2022 Preview (HKLM-x32\\8cca2edf) (Version: 17.0.0 Preview 4.1 - Microsoft Corporation) Task: {68703689-47bd-47ee-9cf2-e91abb43a182} - no filepath Task: {bb2029d9-cbf0-4ee3-aa1b-fbafda7b399a} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95bbc0e1-37d1-403e-badd-d7f7c4fc36d1}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{55b76d6d-fbf6-450e-a24e-071e1db9f945}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8c4fdb45-99dd-42f3-8984-07e5f8dff7f4}" => removed successfully Faulting package-relative application ID: Description: ==================== NetSvcs (Whitelisted) =================== Task: {82a0b077-3637-4350-9431-56dbbbb4d5c1} - no filepath To see this start Windows and wait about 5 minutes. (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5292bbfbf575e2d2\Display.NvContainer\NVDisplay.Container.exe <2> however the RGB Fusion software is notoriously glitchy. 2021-10-02 23:18 - 2021-10-02 23:18 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\Visual Studio Setup 2021-10-03 15:48 - 2021-10-03 15:48 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2021-10-24 13:24 - 2021-10-19 08:02 - 000000000 ____D C:\Users\Pepega\Desktop\integrity_verification Task: {ab7dbf26-2e26-445a-a7dd-f60ac12f19a6} - no filepath 2021-10-03 13:32 - 2021-10-04 18:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Duty Modern Warfare "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{358ba298-e9a3-4572-a1cd-6ec4e7b85984}" => removed successfully CustomCLSID: HKU\S-1-5-21-326566074-3447909417-183555969-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-558F93368B4C} -> [Creative Cloud Files] => C:\Users\Pepega\Creative Cloud Files [2021-10-16 20:42] 2021-10-13 16:20 - 2021-10-13 16:20 - 000001245 _____ C:\Users\Pepega\Desktop\Roblox Studio.lnk FirewallRules: [{30A1031D-2A0F-4ED7-BB78-4C35329A0857}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) 0.0.0.0 vortex-bn2.metron.live.com.nsatc.net 2021-10-15 11:58 - 2021-10-15 11:58 - 000000000 ____D C:\Users\Pepega\Documents\XuanZhi Task: {7ef13d49-f1cb-4454-af1c-a7a9e880a031} - no filepath 2021-10-24 20:41 - 2021-10-24 20:41 - 000000000 ____D C:\ProgramData\Norton Resetting , OK! Task: {0D800AA5-1B39-4310-BE91-74EBCFD0DB76} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-09-14] (NVIDIA Corporation -> NVIDIA Corporation) Task: {29ad0c16-34a9-49f9-a1d8-81f44fff082d} - no filepath ============================================== AMD_Chipset_Drivers (HKLM-x32\\{c370a4bd-5e86-489d-b1a5-54ceee532d20}) (Version: 2.15.07.2229 - Advanced Micro Devices, Inc.) Hidden go to : C:\Program Files (x86)\GIGABYTE\AORUS LCD Panel Setting\Updater and run FWUpgrade.exe, you will see the progress and after completion, it will ask you to shutdown, click yes and the turn on the pc again. my os is win10 x64, 2004. goodluck. I have the 3090 and I do not see that folder. ==================== SigCheck ============================ 2021-10-09 19:30 - 2021-10-09 19:30 - 000058304 _____ C:\Windows\system32\Drivers\49306c4f52694e4555486333655846434e586f3256576c6e5a334e784f4535614e585674.sys HKU\S-1-5-21-326566074-3447909417-183555969-1001\\StartupApproved\Run: => "Steam" Resetting , OK! R2 NahimicService; C:\Windows\system32\NahimicService.exe [1633288 2020-12-10] (A-Volute SAS -> Nahimic) Date: 2021-10-24 15:35:53.954 Restart Windows and look at the time stamp on the event error message. ==================== Scheduled Tasks (Whitelisted) ============ "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{dfa6b7fe-8965-4d4f-9d9a-7abe5c5ee553}" => removed successfully Task: {6d29bb8b-f135-47e9-9ff9-392b06a68bf3} - no filepath Reason:0xC004F011 2021-10-18 20:26 - 2021-10-18 20:26 - 000000000 ____D C:\Users\Pepega\AppData\Local\ImageMagick Faulting module path: D:\Cheetos\Woofing\Cinx Archieves\SinEx 4.2.0 [BETA]\SinEx 4.2.0 BETA Woofer [All Winver].exe "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{e6857042-80d9-4422-85b4-1c5dc0aae451}" => removed successfully Tcpip\..\Interfaces\{0b906b63-14f9-4205-87bd-1b6b0fc3f4de}: [DhcpNameServer] 1.1.1.1 1.0.0.1 I just updated my BIOS on my gigabyte aorus elite x570. ==================== Security Center ======================== ==================== Files in the root of some directories ======== Description: The server Microsoft.Windows.Cortana_1.13.0.18362_neutral_neutral_cw5n1h2txyewy!CortanaUI did not register with DCOM within the required timeout. 2021-10-02 23:02 - 2021-10-02 23:02 - 000000000 ____D C:\Program Files (x86)\AMD Error: (10/24/2021 08:19:57 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) 2021-10-02 23:02 - 2021-10-18 19:32 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information Kits Configuration Installer (HKLM-x32\\{E75A9998-E979-760B-6AEB-49763F279EDD}) (Version: 10.1.19041.685 - Microsoft) Hidden WebAORUS Gaming Motherboards will support either 5v or 12v digital LED strips. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{23df4797-0507-44e3-9c41-f5d1be966072}" => removed successfully Task: {46ee8f94-e240-420c-a5e8-0660f5c5f9e1} - no filepath Task: {8c4fdb45-99dd-42f3-8984-07e5f8dff7f4} - no filepath 2021-10-02 23:44 - 2021-10-04 18:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net Task: {d9c6b67e-9dbb-4ba4-ad4b-5aecb6889d08} - no filepath The file will not be moved unless listed separately.) The file will not be moved unless listed separately.) Category: Settings Modifier HKU\S-1-5-21-326566074-3447909417-183555969-1001\SOFTWARE\Policies\Microsoft\Edge => removed successfully vs_SQLClickOnceBootstrappermsi (HKLM-x32\\{F16C13E8-83A4-47C8-8687-B9E1DDDFA80C}) (Version: 17.0.31703 - Microsoft Corporation) Hidden Faulting application path: C:\Windows\SysWOW64\Windows Driver Installation Service\Windows Driver Installation Service.exe Task: {F30C20EC-C71A-406B-A23E-8B958ACE878E} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3339120 2021-09-14] (NVIDIA Corporation -> NVIDIA Corporation) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <13> 2021-10-13 22:14 - 2021-10-07 19:28 - 001597584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll Description: The WinRing0_1_2_0 service failed to start due to the following error: "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4d4276f1-945c-486b-b48f-62cda9b73d18}" => removed successfully 2021-10-13 22:14 - 2021-10-07 19:32 - 001111256 _____ C:\Windows\system32\vulkan-1.dll "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{b7e27570-3f72-4ac2-b2ec-fd92b54c3a60}" => removed successfully 2021-10-24 21:16 - 2019-03-19 15:50 - 000000000 ____D C:\Windows\INF 2021-10-16 20:39 - 2021-10-16 20:41 - 000000000 ____D C:\ProgramData\Adobe 2021-10-04 10:02 - 2021-10-04 10:02 - 000000000 ____D C:\Users\Pepega\AppData\Local\OO Software The following corrective action will be taken in 10 milliseconds: Restart the service. (If an entry is included in the fixlist, the file/folder will be moved.) 2021-10-02 22:51 - 2021-10-02 22:51 - 000000000 ____D C:\Windows\CSC Faulting process id: 0x3860 Boot Mode: Normal Microsoft Windows 10 Pro Version 1909 18363.418 (X64) (1970-01-01 06:34:12) 2021-10-02 23:35 - 2021-10-02 23:35 - 000001738 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blend for Visual Studio 2022 Preview.lnk 2021-10-04 18:28 - 2021-10-04 18:28 - 000103648 _____ C:\Windows\productkey.bat Virus, Trojan, Spyware, and Malware Removal Help, Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-10-2021, This is not recommended for shared computers, Apples first Rapid Security Response patch fails to install on iPhones, Extended Deal: Get Microsoft Office 2021 on sale for just $39, Best VPNs to unblock WhatsApp calling in the UAE, https://www.virustotal.com/gui/file/85aa1344d28fd7c6a911924040e5b3ae1278fb70444cd39d056bd270f147f61b, https://www.virustotal.com/gui/file/85aa1344d28fd7c6a911924040e5b3ae1278fb70444cd39d056bd270f147f61b/behavior/Microsoft%20Sysinternals, https://go.microsoft.com/fwlink/?linkid=37020&name=SettingsModifier:Win32/PossibleHostsFileHijack&threatid=14994&enterprise=0, Back to Virus, Trojan, Spyware, and Malware Removal Help. 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\system32\1046 "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{257fa8a3-d406-4d7e-99a9-c9e255f9f6f0}" => removed successfully 2021-10-02 22:50 - 2019-03-19 15:52 - 000000000 ____D C:\ProgramData\USOPrivate Battle.net (HKLM-x32\\Battle.net) (Version: - Blizzard Entertainment) Percentage of memory in use: 19% 2021-10-24 20:37 - 2021-10-24 20:37 - 000000000 ____D C:\Users\Pepega\AppData\Local\D3DSCache HKLM-x32\\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [781552 2021-10-16] (Adobe Inc. -> Adobe Inc.) HKLM\\StartupApproved\Run: => "WindowsDefender" 2021-10-02 23:34 - 2021-10-02 23:34 - 000000000 ____D C:\Program Files\Application Verifier ========= End of CMD: ========= FirewallRules: [TCP Query User{CF0A0468-41A2-4CF4-BDA6-1586AE73104D}C:\windows\microsoft.net\framework64\v4.0.30319\vbc.exe] => (Allow) C:\windows\microsoft.net\framework64\v4.0.30319\vbc.exe (Microsoft Corporation -> Microsoft Corporation) Task: {4d4276f1-945c-486b-b48f-62cda9b73d18} - no filepath Process Name: C:\Users\Pepega\AppData\Local\Discord\app-1.0.9003\Discord.exe 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\system32\1036 Task: {8457ad0b-1c75-431d-a5ae-ee1aed76a239} - no filepath Task: {86c0c79f-566b-48c2-a517-d270146f5782} - no filepath CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R Startup: C:\Users\Pepega\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Thing2.bat [2021-10-24] () [File not signed] The following corrective action will be taken in 6000 milliseconds: Restart the service." Python 3.9.5 Test Suite (64-bit) (HKLM\\{605117B9-EE12-4498-A089-A63219191799}) (Version: 3.9.5150.0 - Python Software Foundation) Hidden 2021-10-02 23:25 - 2021-10-02 23:26 - 000000000 ____D C:\Windows\SysWOW64\1028 2021-10-02 23:03 - 2021-10-02 23:04 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2021-10-02 23:04 - 2021-10-02 23:04 - 000003940 _____ C:\Windows\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000) FirewallRules: [{E1D43D4F-5765-4B23-A804-FDD364EFF570}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) 2021-10-13 22:14 - 2021-10-07 19:32 - 000965336 _____ C:\Windows\SysWOW64\vulkan-1.dll 2021-10-24 14:31 - 2021-10-24 14:31 - 000000000 ____D C:\Program Files\MSBuild (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe Task: {d2d2fbec-f7b4-41b4-9251-9cfdc41d781f} - no filepath Windows IP Configuration Task: {5594E525-77BA-4ACC-96A7-90740DA56E19} - System32\Tasks\NahimicSvc32Run => C:\Windows\SysWOW64\NahimicSvc32.exe [823304 2020-12-10] (A-Volute SAS -> Nahimic) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2021-10-16] (Adobe Inc. -> Adobe Systems) Resetting , OK! FirewallRules: [{59D80DED-9B17-4C87-8B07-0F6E3D494323}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) vs_minshellsharedmsi (HKLM-x32\\{3113CCA8-60A5-476A-93E6-0992CE618C16}) (Version: 17.0.31709 - Microsoft Corporation) Hidden (If an entry is included in the fixlist, it will be removed from the registry. 2021-10-03 10:57 - 2021-10-03 10:57 - 000000000 ____D C:\Users\Pepega\ansel FirewallRules: [TCP Query User{3D3D13C6-EB42-4BF7-9989-E995CB143820}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.) Task: {E2F1A91A-7C7E-4500-92A5-65707C268116} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-09-14] (NVIDIA Corporation -> NVIDIA Corporation) Faulting module name: SinEx 4.2.0 BETA Woofer [All Winver].exe, version: 0.0.0.0, time stamp: 0x616e2119 2021-10-03 09:12 - 2021-10-03 09:12 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\NuGet Fusion 2.0 working for Aorus Xtreme 3080 working ==================== End of Addition.txt =======================. 0.0.0.0 telemetry.urs.microsoft.com 2021-10-18 19:32 - 2021-07-29 05:27 - 048046994 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT 2021-10-18 20:24 - 2021-10-18 20:24 - 000000000 ____D C:\ProgramData\AMD AutoUpdate ==================== FirewallRules (Whitelisted) ================ ==================== Event log errors: ======================== 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\SysWOW64\3082 Description: The AORUS LCD Panel Service service terminated unexpectedly. 2021-10-24 14:57 - 2021-10-24 14:57 - 000000000 ____D C:\Users\Pepega\AppData\Local\mbamtray "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8a370bc5-d53d-4130-9a86-55745d7884c5}" => removed successfully Task: {560963e7-8fb3-45a5-b560-b69102dfab6a} - no filepath vs_clickoncesigntoolmsi (HKLM-x32\\{B00D9AE3-D2B9-4C16-AF48-B3AF4B46E67A}) (Version: 17.0.31703 - Microsoft Corporation) Hidden Task: {b19f8042-93dc-47e1-87f7-7ad8cb0032d9} - no filepath Available physical RAM: 26345.08 MB 2021-10-12 19:18 - 2021-10-12 19:18 - 000000000 ____D C:\Program Files (x86)\Epic Games Task: {960b6a6a-dc34-4565-96a7-4db5fb5b3ff9} - no filepath 2021-10-02 22:51 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\system32\FxsTmp 2021-10-02 22:55 - 2021-10-24 19:39 - 000000000 ____D C:\Users\Pepega\AppData\Local\ConnectedDevicesPlatform Task: {964fea64-405c-411f-8d7c-f9b886d45580} - no filepath 2021-10-02 23:17 - 2021-10-02 23:18 - 000000000 ____D C:\Windows\SysWOW64\directx Error: (10/24/2021 07:38:08 PM) (Source: Software Protection Platform Service) (EventID: 8211) (User: ) Severity: Medium Task: {86c0c79f-566b-48c2-a517-d270146f5782} - no filepath 2021-10-07 12:11 - 2021-10-07 12:11 - 000000000 ____H C:\$WINRE_BACKUP_PARTITION.MARKER Task: {aadbbd5a-88ab-4f36-b6d5-c7eaaf6ddc1d} - no filepath Task: {b44de6b6-1303-474b-bd1f-0c3e771de5d9} - no filepath Task: {44e64ec2-07de-480c-b391-0e70d56ee3de} - no filepath Additional Data: 2021-10-18 20:24 - 2021-10-18 20:24 - 000003532 _____ C:\Windows\system32\Tasks\AMDAutoUpdate HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION 2021-10-24 20:41 - 2021-10-24 20:41 - 013884680 _____ (NortonLifeLock Inc.) C:\Users\Pepega\Downloads\NPE.exe 2021-10-15 11:40 - 2021-10-15 11:40 - 000003938 _____ C:\Windows\system32\Tasks\BlueStacksHelper_nxt IFEO\mpcmdrun.exe: [Debugger] C:\Windows\System32\systray.exe Please re-enable javascript to access full functionality. ==================== MBR & Partition Table ==================== Task: {358ba298-e9a3-4572-a1cd-6ec4e7b85984} - no filepath Faulting module path: C:\Windows\System32\KERNELBASE.dll 2021-10-13 22:14 - 2021-10-07 11:58 - 000085583 _____ C:\Windows\system32\nvinfo.pb "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{977e0d72-710d-4264-bfbf-105f17f81aa3}" => removed successfully ENE_X_AIC_HAL (HKLM-x32\\{ec10ac91-2e61-460a-b493-33f794a07682}) (Version: 1.0.4.0 - ENE TECHNOLOGY INC.) Hidden Click OK twice and restart the computer. PC stuck at aorus loading screen : r/buildapc - Reddit WinRT Intellisense Desktop - en-us (HKLM-x32\\{BCF7CA0F-E53C-2A4F-B128-A751EC9A1016}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp//www.bing.com/search?q={searchTerms}&FORM=IE8SRC It has done this 2 time(s). Task: {0AE34A62-50FD-43F2-9DC3-264E8205D137} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-09-14] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log iCue causing system to hang/crash. - Page 4 - iCUE =========== "C:\WINDOWS\syswow64\*.tmp" ========== Python 3.9.5 Documentation (64-bit) (HKLM\\{4EFE695B-F377-4CB0-90E3-6AEEE22DEFEB}) (Version: 3.9.5150.0 - Python Software Foundation) Hidden 0.0.0.0 oca.telemetry.microsoft.com.nsatc.net When i clicked on properties, it said that its original name was 'Update.exe.' (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe CreateRestorePoint: Steam (HKLM-x32\\Steam) (Version: 2.10.91.91 - Valve Corporation) Detection Type: Concrete vs_minshellmsires (HKLM-x32\\{6BEA577E-EB1B-47A4-A0EF-05D5FAC0861E}) (Version: 17.0.31709 - Microsoft Corporation) Hidden AORUS Resetting Interface, OK! 2021-10-09 21:21 - 2021-10-09 21:21 - 000058304 _____ (Intel Corporation ) C:\Windows\system32\Drivers\49306c4f52694d3265464132623078796254466e4e6d52774d324e545a315a7664556830.sys Task: {6ee54cdc-f0d4-4cad-be32-be99498e56b8} - no filepath It has done this 1 time(s). Task: {b3eb79cd-689d-4158-bea3-8771c38a327c} - no filepath Epic Online Services (HKLM-x32\\{32C68D93-D32F-4B01-8250-61642BFC22F8}) (Version: 2.0.28.0 - Epic Games, Inc.) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0e056076-a1e1-4979-83ca-d3b97785e4bb}" => removed successfully R1 npcap; C:\Windows\system32\DRIVERS\npcap.sys [74744 2021-04-22] (Insecure.Com LLC -> Insecure.Com LLC.) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4204c90d-5097-480b-ab90-0cff3c443b89}" => removed successfully 0.0.0.0 settings-sandbox.data.microsoft.com Startup: C:\Users\Pepega\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Thing.bat [2021-10-24] () [File not signed] Edge Profile: C:\Users\Pepega\AppData\Local\Microsoft\Edge\User Data\Default [2021-10-24] Task: {d4928d07-631c-4754-af4f-3f5f19729138} - no filepath Task: {646144d0-0d5f-463c-aedc-cbc190d10525} - no filepath 2021-10-02 23:03 - 2021-09-14 14:39 - 000067464 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys After you have restarted the application, it will correctly indicate that your software is up to date or retrieve and install Task: {8f7674a6-0b05-416d-8dc8-bba2f61cad8c} - no filepath Severity: Medium C:\Users\Pepega\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Thing2.bat => moved successfully