"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1e6a4e2b-eca4-4162-8baf-5e2cbc56f0a8}" => removed successfully Exception code: 0xe0434352 "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6c61cc2f-6bf1-4d13-9cc0-dd2cf2ba3087}" => removed successfully 2021-10-13 22:14 - 2021-10-07 19:28 - 001172608 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll End Category: Settings Modifier FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2021-10-16] (Adobe Inc. -> Adobe Systems) Date: 2021-10-24 15:35:27.734 Date: 2021-10-24 15:35:53.912 HKLM-x32\\RunOnce: [SelLed] => C:\Program Files (x86)\GIGABYTE\RGBFusion\RunLed.exe [50096 2019-04-29] (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) ^rinse and repeat. Error: (10/24/2021 07:38:08 PM) (Source: Software Protection Platform Service) (EventID: 8228) (User: ) 2021-10-02 23:01 - 2021-10-24 12:21 - 000000000 ____D C:\ProgramData\Package Cache Python 3.9.5 Documentation (64-bit) (HKLM\\{4EFE695B-F377-4CB0-90E3-6AEEE22DEFEB}) (Version: 3.9.5150.0 - Python Software Foundation) Hidden Event 7036 Source - service control manager The Windows Error Reporting Service service entered the running state. 2021-10-02 22:55 - 2021-10-24 14:56 - 000000000 ____D C:\Users\Pepega\AppData\Local\Packages Task: {0e056076-a1e1-4979-83ca-d3b97785e4bb} - no filepath CustomCLSID: HKU\S-1-5-21-326566074-3447909417-183555969-1001_Classes\CLSID\{2F81B25E-7507-4844-BFF2-77D2CC24CED4}\localserver32 -> C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Inc. -> Adobe Inc.) Python 3.9.5 Tcl/Tk Support (64-bit symbols) (HKLM\\{9F0D0DF1-B4D0-4760-A174-0CFF5C09D758}) (Version: 3.9.5150.0 - Python Software Foundation) Hidden 2021-10-02 23:44 - 2021-10-24 09:39 - 000000000 ____D C:\Users\Pepega\AppData\Local\Blizzard Entertainment Faulting module name: SinEx 4.2.0 BETA Woofer [All Winver].exe, version: 0.0.0.0, time stamp: 0x616e2119 FF Extension: (Decentraleyes) - C:\Users\Pepega\AppData\Roaming\Mozilla\Firefox\Profiles\q42kwfcc.default-release\Extensions\jid1-BoFifL9Vbdl2zQ@jetpack.xpi [2021-10-05] 2021-10-03 09:12 - 2021-10-03 09:12 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\NuGet "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ca0fb10b-e917-4aa5-9e3a-f6a019682f3f}" => removed successfully Date: 2021-10-24 17:54:57.532 2021-10-13 16:20 - 2021-10-13 16:21 - 000000000 ____D C:\Users\Pepega\AppData\Local\Roblox PC stuck at aorus loading screen : r/buildapc - Reddit 2021-10-02 23:46 - 2021-10-02 23:46 - 000000000 ____D C:\ProgramData\Blizzard Entertainment Task: {73931e1e-d4e0-4d8f-9b0c-c332b70c4204} - no filepath 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\SysWOW64\1040 "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{fc60ad33-5948-48d9-9f11-c6ca25373a9c}" => removed successfully Epic Online Services (HKLM-x32\\{32C68D93-D32F-4B01-8250-61642BFC22F8}) (Version: 2.0.28.0 - Epic Games, Inc.) WinRT Intellisense Desktop - en-us (HKLM-x32\\{BCF7CA0F-E53C-2A4F-B128-A751EC9A1016}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.46.1231.2020 - Realtek) at System.Windows.Forms.Clipboard.GetText(System.Windows.Forms.TextDataFormat) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" 2021-10-02 23:04 - 2021-10-02 23:04 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} Task: {4d4276f1-945c-486b-b48f-62cda9b73d18} - no filepath Process Name: C:\Users\Pepega\AppData\Local\Discord\app-1.0.9003\Discord.exe 0.0.0.0 watson.telemetry.microsoft.com.nsatc.net 2021-10-02 23:07 - 2021-10-24 21:18 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\discord Error: (10/24/2021 06:01:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Detection Origin: Local machine Task: {bfa657d3-0b7d-471a-89e3-f729ecb71365} - no filepath Task: {19e78c37-4706-4ee6-b14f-00a377e1761c} - no filepath (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SnippingTool.exe (CloudBees, Inc.) [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS LCD Panel Setting\MonitorService-exec.exe 2021-10-13 22:14 - 2021-10-07 19:27 - 002850432 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll Startup: C:\Users\Pepega\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Thing2.bat [2021-10-24] () [File not signed] 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\SysWOW64\1033 Task: {b3eb79cd-689d-4158-bea3-8771c38a327c} - no filepath SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp//www.bing.com/search?q={searchTerms}&FORM=IE8SRC Task: {634166c8-f3ba-4d37-96ef-8a18d9787a4e} - no filepath NVIDIA PhysX System Software 9.21.0713 (HKLM\\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation) here are the virustotals for the 2 files:https://www.virustotal.com/gui/file/85aa1344d28fd7c6a911924040e5b3ae1278fb70444cd39d056bd270f147f61bhttps://www.virustotal.com/gui/file/85aa1344d28fd7c6a911924040e5b3ae1278fb70444cd39d056bd270f147f61b/behavior/Microsoft%20Sysinternals, FRST RESULTS: Task: {90b432e7-5c87-425c-9dd5-33099e0e41c9} - no filepath It has done this 1 time(s). 2021-10-04 18:19 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\system32\MsDtc Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-10-22] (Microsoft Corporation) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68703689-47bd-47ee-9cf2-e91abb43a182}" => removed successfully ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2021-09-15] (Adobe Inc. -> ) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{51f29cff-5f75-43a6-8c78-2970cd2f96ac}" => removed successfully 2021-10-02 23:25 - 2021-10-02 23:26 - 000000000 ____D C:\Windows\system32\1042 Task: {d7495c49-8426-461c-8455-350522fba9cb} - no filepath (If an entry is included in the fixlist, the file/folder will be moved.) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{d4928d07-631c-4754-af4f-3f5f19729138}" => removed successfully Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Task: {b19f8042-93dc-47e1-87f7-7ad8cb0032d9} - no filepath Resetting Route, OK! 2021-10-13 22:14 - 2021-10-07 19:32 - 001111256 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal) Task: {44e64ec2-07de-480c-b391-0e70d56ee3de} - no filepath Task: {964fea64-405c-411f-8d7c-f9b886d45580} - no filepath Feature: On Access 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\system32\1033 2021-10-05 15:51 - 2021-10-05 16:12 - 000000094 _____ C:\Users\Pepega\Desktop\cod filters.txt not found Task: {66f5635a-5bb6-4432-8d29-d7d2f625b98a} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{a2a9bb80-76ce-4752-9e44-f43e01b26a35}" => removed successfully Task: {e62b268c-ea0c-4217-bfa2-7bd1145ba5a0} - no filepath 2021-10-02 23:03 - 2021-09-14 14:39 - 000069856 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys Task: {013418b8-2dc1-4fb4-9c18-21dcfcb620cb} - no filepath 2021-10-02 23:25 - 2021-10-02 23:26 - 000000000 ____D C:\Windows\SysWOW64\2052 Task: {e0ba60f1-d26f-4185-8bb0-04b05678ff5a} - no filepath !go to the folder C:\Program Files (x86)\GIGABYTE\AORUS LCD Panel Setting\Updater\ right 2021-10-02 23:49 - 2021-10-04 18:19 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{57f92185-4f7e-4549-bf72-8ded737637ee}" => removed successfully ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2021-09-15] (Adobe Inc. -> ) Task: {90b432e7-5c87-425c-9dd5-33099e0e41c9} - no filepath Dec 16, 2019. Task: {358ba298-e9a3-4572-a1cd-6ec4e7b85984} - no filepath Task: {414df2f8-cc7c-49b6-a90f-8e407ed62e02} - no filepath 2021-09-30 14:33 - 2021-09-30 14:33 - 001993216 _____ (GIGABYTE) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\AACPCIeSSD_Lib.dll [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\GVDisplay.dll It has done this 1 time(s). FF Extension: (Kurgzsekseta) - C:\Users\Pepega\AppData\Roaming\Mozilla\Firefox\Profiles\q42kwfcc.default-release\Extensions\{e8f3b919-d290-4270-b66f-29f3fdbb1986}.xpi [2021-10-05] go to : C:\Program Files (x86)\GIGABYTE\AORUS LCD Panel Setting\Updater and run FWUpgrade.exe, you will see the progress and after completion, Task: {ab7dbf26-2e26-445a-a7dd-f60ac12f19a6} - no filepath AMD Ryzen Master (HKLM\\AMD Ryzen Master) (Version: 2.8.0.1937 - Advanced Micro Devices, Inc.) 2021-10-13 22:14 - 2021-10-07 19:27 - 005703288 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll Windows Firewall is enabled. 2021-10-18 19:33 - 2021-10-18 19:33 - 000000000 ____D C:\Windows\system32\A-Volute 2021-10-13 22:14 - 2021-10-07 19:32 - 001874648 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe Task: {b086bb79-9ed7-4043-ab6c-148342fcf383} - no filepath Ethernet: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) 2021-10-02 23:34 - 2021-10-02 23:34 - 000000000 ____D C:\Program Files\Application Verifier Partition: GPT. Resetting , OK! "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{90b432e7-5c87-425c-9dd5-33099e0e41c9}" => removed successfully ***************** 2021-10-07 12:11 - 2021-10-07 12:11 - 000000000 ____H C:\$WINRE_BACKUP_PARTITION.MARKER 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\SysWOW64\1036 2021-10-03 16:47 - 2019-03-19 15:49 - 000028672 _____ C:\Windows\system32\config\BCD-Template (NVIDIA Corporation -> NVIDIA) C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\PresentMon_x64.exe <2> Task: {e21ec10f-b0f2-4d8c-ac9d-e74491370460} - no filepath 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\SysWOW64\1046 2021-10-02 23:00 - 2021-10-02 23:00 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\WinRAR service 0.0.0.0 redir.metaservices.microsoft.com "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6902881d-a9ea-4ce3-9977-eac42438e59f}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{257fa8a3-d406-4d7e-99a9-c9e255f9f6f0}" => removed successfully 2021-10-24 14:57 - 2021-10-24 14:57 - 000000000 ____D C:\Users\Pepega\AppData\Local\mbamtray If you were unable to navigate to a website, click Start, Control Panel, Network and Sharing Center, and select "Set up a new connection or network." 2021-10-02 23:46 - 2021-10-24 14:30 - 000000000 ____D C:\Program Files (x86)\Steam Task: {c4718da2-1857-4507-932c-28593e4e8294} - no filepath Task: {38c61830-b1df-4717-ae92-954fefd27747} - no filepath When i clicked on properties, it said that its original name was 'Update.exe.' "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4d4276f1-945c-486b-b48f-62cda9b73d18}" => removed successfully 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\system32\1046 ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal) 2021-10-02 23:44 - 2021-10-20 12:04 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\Battle.net "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{bb2029d9-cbf0-4ee3-aa1b-fbafda7b399a}" => removed successfully FirewallRules: [TCP Query User{3D3D13C6-EB42-4BF7-9989-E995CB143820}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.) 2021-10-02 23:02 - 2021-10-07 19:28 - 000792208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll Task: {df1c3fe3-3222-4a5e-b520-95a4768a5710} - no filepath Task: {19e78c37-4706-4ee6-b14f-00a377e1761c} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0e056076-a1e1-4979-83ca-d3b97785e4bb}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{e21ec10f-b0f2-4d8c-ac9d-e74491370460}" => removed successfully Tcpip\..\Interfaces\{0b906b63-14f9-4205-87bd-1b6b0fc3f4de}: [DhcpNameServer] 1.1.1.1 1.0.0.1 Reason:0xC004F011 2021-10-03 11:47 - 2021-10-04 18:19 - 000000000 ____D C:\Program Files\UNP The file will not be moved.) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82a0b077-3637-4350-9431-56dbbbb4d5c1}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9ab420ae-8543-428c-9838-410f79c8d585}" => removed successfully 2021-10-03 15:48 - 2021-10-24 14:37 - 000000000 ____D C:\Windows\system32\Drivers\wd GroupPolicy: Restriction ? ==================== Event log errors: ======================== Task: {6298650e-c3bc-47e3-a571-b4eea94ac419} - no filepath HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp//go.microsoft.com/fwlink/?LinkId=54896 2021-10-16 20:39 - 2021-10-16 20:39 - 000001382 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2021-10-15 11:40 - 2021-10-15 11:40 - 000000000 ____D C:\ProgramData\BlueStacks_nxt Task: {1539d558-2bfa-453d-a38e-aa8bbec05194} - no filepath FF DefaultProfile: h4od9c6l.default Edge DefaultProfile: Default vs_filehandler_amd64 (HKLM-x32\\{D4617896-04FC-45D7-8355-2BA21BBB314F}) (Version: 17.0.31709 - Microsoft Corporation) Hidden ========= End -> "C:\WINDOWS\system32\*.tmp" ======== Restore point was successfully created. CMD: ipconfig /flushDNS Dell Digital Delivery Services Crashes Task: {f99694c5-bf64-4109-a138-067cb4c7d2e7} - no filepath 2021-10-20 14:50 - 2021-10-20 14:50 - 000000000 ____D C:\Program Files\ENE Resetting Interface, OK! Path: file:_C:\Windows\System32\drivers\etc\hosts ENE_X_AIC_HAL (HKLM\\{CF703694-01C6-4062-B797-84DB215662BC}) (Version: 1.0.4.0 - ENE TECHNOLOGY INC.) Hidden HKU\S-1-5-21-326566074-3447909417-183555969-1001\\Run: [Windows Driver Installation Service] => C:\Windows\SysWOW64\Windows Driver Installation Service\Windows Driver Installation Service.exe Task: {a4a7b095-aaa9-401c-a9d7-8abe8ea301af} - no filepath 2021-10-24 14:58 - 2019-03-19 15:37 - 000032768 _____ C:\Windows\system32\config\ELAM Entity Framework 6.2.0 Tools for Visual Studio 2022 (HKLM-x32\\{3A21F37E-9707-4E7F-94EB-2937A1C931FA}) (Version: 6.2.0.0 - Microsoft Corporation) Hidden Close the Dell Digital Delivery application. Task: {134fdbcd-c972-40e5-a39b-91c169e4c9bf} - no filepath [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\GvIllumLib.dll 2021-10-01 15:07 - 2021-10-01 15:07 - 002045440 _____ (TODO: ) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\SMBCtrl.dll 2021-10-12 21:15 - 2021-10-24 19:39 - 000003658 _____ C:\Windows\system32\Tasks\CreateExplorerShellUnelevatedTask at System.Windows.Forms.Clipboard.GetDataObject(Int32, Int32) i scanned using norton power eraser, but it returned with no results. Check that it's latest OS build. 2021-10-03 18:05 - 2021-10-03 18:05 - 000000000 ____D C:\Users\Pepega\AppData\Local\Apple Computer "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{53b08e97-673e-4df6-ae10-9a73f6648a6c}" => removed successfully KeePassXC (HKLM\\{89472929-1ED2-410F-B9CC-974CEE93800E}) (Version: 2.6.6 - KeePassXC Team) 2021-10-02 22:55 - 2021-10-24 19:42 - 000049844 _____ C:\Windows\system32\PerfStringBackup.INI 2021-10-02 23:19 - 2021-10-02 23:19 - 000000000 ____D C:\Program Files\Microsoft Visual Studio Task: {4d4276f1-945c-486b-b48f-62cda9b73d18} - no filepath 2021-10-15 11:55 - 2021-10-15 11:55 - 000000000 ____D C:\Users\Pepega\AppData\Local\BlueStacksSetup Task: {4972aadd-d0db-4681-984f-17b847488bc9} - no filepath Restarting the service or rebooting the VM did not solved the problem. The system cannot find the path specified. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{a68a203b-7eaa-4914-a565-5ff9759ae2a4}" => removed successfully HKLM-x32\\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [781552 2021-10-16] (Adobe Inc. -> Adobe Inc.)