0.0.0.0 watson.microsoft.com HKLM\System\CurrentControlSet\Services\BlueStacksDrv_nxt => removed successfully HKU\S-1-5-21-326566074-3447909417-183555969-1001_Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2} => removed successfully 2021-10-02 22:56 - 2021-10-07 11:58 - 000125568 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{d7495c49-8426-461c-8455-350522fba9cb}" => removed successfully ClickOnce Bootstrapper Package for Microsoft .NET Framework (HKLM-x32\\{5A260D5A-95D3-4956-8E0A-E182CC4144ED}) (Version: 4.8.04162 - Microsoft Corporation) Hidden Partition: GPT. CloseProcesses: Virus, Trojan, Spyware, and Malware Removal Help, Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-10-2021, This is not recommended for shared computers, Apples first Rapid Security Response patch fails to install on iPhones, Extended Deal: Get Microsoft Office 2021 on sale for just $39, Best VPNs to unblock WhatsApp calling in the UAE, https://www.virustotal.com/gui/file/85aa1344d28fd7c6a911924040e5b3ae1278fb70444cd39d056bd270f147f61b, https://www.virustotal.com/gui/file/85aa1344d28fd7c6a911924040e5b3ae1278fb70444cd39d056bd270f147f61b/behavior/Microsoft%20Sysinternals, https://go.microsoft.com/fwlink/?linkid=37020&name=SettingsModifier:Win32/PossibleHostsFileHijack&threatid=14994&enterprise=0, Back to Virus, Trojan, Spyware, and Malware Removal Help. Category: Settings Modifier 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\SysWOW64\1046 2021-10-02 23:24 - 2021-10-02 23:24 - 000000000 ____D C:\Users\Pepega\.dotnet 2021-10-07 12:09 - 2019-12-07 22:09 - 000000000 ___HD C:\$WINDOWS.~BT Task: {e0ba60f1-d26f-4185-8bb0-04b05678ff5a} - no filepath ========= End -> "C:\WINDOWS\system32\*.tmp" ======== 2021-10-24 11:47 - 2021-10-24 11:47 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\Process Hacker 2 It has done this 1 time(s). Edge Profile: C:\Users\Pepega\AppData\Local\Microsoft\Edge\User Data\Default [2021-10-24] Error: (10/24/2021 07:38:08 PM) (Source: Software Protection Platform Service) (EventID: 8211) (User: ) Policies: C:\Users\Pepega\NTUSER.pol: Restriction <==== ATTENTION Python 3.9.5 Utility Scripts (64-bit) (HKLM\\{420E50F6-A8E8-4098-A321-7DF6B3C3BA82}) (Version: 3.9.5150.0 - Python Software Foundation) Hidden "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7ef13d49-f1cb-4454-af1c-a7a9e880a031}" => removed successfully Task: {A8BA0F77-0928-4197-AD98-116E198D6501} - System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\RUXIMDisplay => C:\Program Files\ruxim\ruximics.exe [477512 2021-06-30] (Microsoft Windows -> Microsoft Corporation) 2021-10-02 23:25 - 2021-10-02 23:26 - 000000000 ____D C:\Windows\SysWOW64\1031 Error: (10/24/2021 07:36:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) at System.Windows.Forms.Clipboard.ThrowIfFailed(Int32) FirewallRules: [{EF3E048A-7A4B-4F8B-8146-DAC25B77EE95}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) 2021-10-03 15:49 - 2021-10-03 15:49 - 000000000 _SHDL C:\Documents and Settings 2021-10-04 11:39 - 2021-10-14 11:49 - 000058304 _____ (Intel Corporation ) C:\Windows\system32\Drivers\49306c4f52694e4557446c556347467a5a44673559566c4954584a44616c687152576c6a.sys Task: {ca0fb10b-e917-4aa5-9e3a-f6a019682f3f} - no filepath 2021-10-18 20:24 - 2021-10-18 20:24 - 000000000 ____D C:\Program Files\AMD Task: {e6857042-80d9-4422-85b4-1c5dc0aae451} - no filepath 2021-10-21 09:11 - 2021-10-21 09:11 - 000058304 _____ C:\Windows\system32\Drivers\49306c4f52694e45546d63335a55524c4d56517854575651566c6c4d64334a474f565268.sys CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R ==================== NetSvcs (Whitelisted) =================== 2021-10-02 23:07 - 2021-10-02 23:07 - 000000000 ____D C:\Users\Pepega\AppData\Local\tmp5qvbpq15.lck C:\Windows\Temp\MpCopyAccelerator.log => moved successfully 2021-10-03 13:32 - 2021-10-04 18:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Duty Modern Warfare 2021-10-02 23:03 - 2021-09-14 14:39 - 000144240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2021-09-29 10:31 - 2021-10-24 17:56 - 000000000 ____D C:\Users\Pepega \\?\Volume{66a9e99a-1cf4-4f5a-a085-9db2177d6629}\ (Recovery) (Fixed) (Total:0.52 GB) (Free:0.5 GB) NTFS "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{86c0c79f-566b-48c2-a517-d270146f5782}" => removed successfully Resetting , OK! 2021-10-02 23:07 - 2021-10-02 23:07 - 000002232 _____ C:\Users\Pepega\Desktop\Discord.lnk ======= 2021-10-15 11:56 - 2021-10-15 11:56 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\lddownloader Faulting module name: KERNELBASE.dll, version: 10.0.18362.418, time stamp: 0xfba22159 VS Immersive Activate Helper (HKLM-x32\\{C0ACF658-B4DC-4CBB-B8F2-9E667D69919A}) (Version: 17.0.114.0 - Microsoft Corporation) Hidden [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\GVDisplay.dll 2021-10-02 23:25 - 2021-10-02 23:26 - 000000000 ____D C:\Windows\system32\1041 Faulting application start time: 0x01d7c8b2547f9944 2021-10-24 15:24 - 2019-03-19 15:37 - 000000000 ____D C:\Windows\CbsTemp ==================== Processes (Whitelisted) ================= "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4204c90d-5097-480b-ab90-0cff3c443b89}" => removed successfully 2021-10-02 23:34 - 2021-10-02 23:34 - 000000000 ____D C:\Program Files\Application Verifier 2021-10-22 11:43 - 2021-10-22 11:43 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Riot Games Stage:GATHER_RULES_FROM_LICENSES IntelliTraceProfilerProxy (HKLM-x32\\{C8891AD2-C223-45CD-A9BE-617A68923B61}) (Version: 15.0.21225.01 - Microsoft Corporation) Hidden 2021-10-15 11:57 - 2021-10-15 11:59 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\XuanZhi =========== "C:\Windows\Temp\*. Default browser: FF "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9ab420ae-8543-428c-9838-410f79c8d585}" => removed successfully ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2021-09-15] (Adobe Inc. -> ) HKLM\\StartupApproved\Run32: => "Adobe Creative Cloud" ==================== Services (Whitelisted) =================== HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp//go.microsoft.com/fwlink/?LinkId=54896 (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe Task: {7d4dac2b-fbf4-45de-adae-6a9396b9ca9c} - no filepath ***************** 2021-10-13 22:14 - 2021-10-07 19:32 - 001874648 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe Faulting module path: C:\Windows\System32\KERNELBASE.dll ==================== End of FRST.txt ========================, Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-10-2021 2021-10-04 18:19 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\system32\spool 2021-10-02 22:56 - 2021-10-04 09:59 - 000000000 ___RD C:\Users\Pepega\OneDrive vs_minshellsharedmsi (HKLM-x32\\{3113CCA8-60A5-476A-93E6-0992CE618C16}) (Version: 17.0.31709 - Microsoft Corporation) Hidden 2021-10-03 16:47 - 2019-03-19 15:49 - 000028672 _____ C:\Windows\system32\config\BCD-Template "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{46ee8f94-e240-420c-a5e8-0660f5c5f9e1}" => removed successfully Process Hacker 2.39 (r124) (HKLM\\Process_Hacker2_is1) (Version: 2.39.0.124 - wj32) 2021-10-14 10:50 - 2021-10-14 17:35 - 000001229 ____H C:\Users\Pepega\AppData\Local\d89b27a4d89b27a4d89b NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.961.0_x64__56jybvy8sckqj [2021-10-03] (NVIDIA Corp.) Task: {b30dbf6f-75b4-422c-82ed-f93cae0f7dec} - no filepath The system cannot find the file specified. Category: Settings Modifier Hosts: There are more than one entry in Hosts. (If an entry is included in the fixlist, the process will be closed. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{572eb39c-ac47-4eda-a21b-d776650fa302}" => removed successfully Task: {9ab420ae-8543-428c-9838-410f79c8d585} - no filepath 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\SysWOW64\1045 FirewallRules: [{7AD4F43C-4369-433E-B2EC-A10468B9A5B1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve Corp. -> ) PC stuck at Aorus loading screen. - Tom's Hardware Forum Detection Origin: Local machine (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe Windows Defender: "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{66f5635a-5bb6-4432-8d29-d7d2f625b98a}" => removed successfully 2021-10-02 23:03 - 2021-10-02 23:03 - 000000000 ____D C:\Windows\system32\lxss 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\system32\1045 FirewallRules: [{4AE2A4DF-F2A8-4220-B0E2-D6204D68459E}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\95.0.1020.30\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) 2021-10-12 19:18 - 2021-10-12 19:18 - 000000000 ____D C:\Users\Pepega\AppData\Local\Epic Games HKLM\\StartupApproved\Run: => "SecurityHealth" 2021-10-02 23:22 - 2021-10-02 23:26 - 000000000 ____D C:\Program Files (x86)\Windows Kits ========================================================== Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-10-22] (Microsoft Corporation) The NVIDIA LocalSystem Container service terminated unexpectedly. 2021-10-02 22:56 - 2021-10-24 15:34 - 000000000 ____D C:\ProgramData\NVIDIA Corporation HKU\S-1-5-21-326566074-3447909417-183555969-1001\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION Task: {51006d50-cfd3-4b5a-af95-e596678bbea8} - no filepath HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp//go.microsoft.com/fwlink/p/?LinkId=255141 "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2a965443-ec13-4b75-abf9-394d697f739d}" => removed successfully Dell Digital Delivery Services Crashes - Dell Community "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{d4928d07-631c-4754-af4f-3f5f19729138}" => removed successfully Task: {4fb942bf-3d44-41ff-bc65-52cd12996f26} - no filepath 2021-10-22 11:43 - 2021-10-22 11:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games S3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [10165360 2021-10-21] (Riot Games, Inc. -> Riot Games, Inc.) 2021-10-02 23:18 - 2021-10-02 23:18 - 000000000 ____D C:\ProgramData\Microsoft Visual Studio Error: Unable to rebuild performance counter setting from system backup store, error code is 2 CustomCLSID: HKU\S-1-5-21-326566074-3447909417-183555969-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Pepega\AppData\Local\Microsoft\OneDrive\21.170.0822.0002\amd64\FileSyncShell64.dll => No File 2021-10-18 13:16 - 2021-10-24 17:02 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\TcNo Account Switcher 2021-10-13 22:14 - 2021-10-07 19:32 - 001206416 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2021-10-02 23:01 - 2021-10-24 12:21 - 000000000 ____D C:\ProgramData\Package Cache Task: {519e0c96-0a46-4c15-840e-41ed3cda1aef} - no filepath (If an entry is included in the fixlist, it will be removed from the registry. Engine Version: AM: 1.1.18600.4, NIS: 1.1.18600.4 Task: {a1c5790b-b106-45b9-9d9c-0442f6ab1b08} - no filepath 2021-10-07 22:42 - 2021-10-21 13:34 - 000000044 _____ C:\Users\Pepega\Desktop\time.txt FF Extension: (NoScript) - C:\Users\Pepega\AppData\Roaming\Mozilla\Firefox\Profiles\q42kwfcc.default-release\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2021-10-05] "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{00f722c3-08dc-4b10-b10e-91a3004714f3}" => removed successfully ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5292bbfbf575e2d2\nvshext.dll [2021-10-07] (Nvidia Corporation -> NVIDIA Corporation) (NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe I assume this one is for the gpu mining as my gpu is also being used on 100%, but i am not able to see which app is using 100%, as the miner has a script where it immediately stops mining when process hacker or task manager is opened, the only way i was able to tell that the gpu was being used at 100% was because of an app that the gpu manufacturer has provided Microsoft Edge WebView2 Runtime (HKLM-x32\\Microsoft EdgeWebView) (Version: 95.0.1020.30 - Microsoft Corporation) Task: {55b76d6d-fbf6-450e-a24e-071e1db9f945} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{fc60ad33-5948-48d9-9f11-c6ca25373a9c}" => removed successfully 2021-10-13 22:14 - 2021-10-07 19:28 - 001597584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll Launcher Prerequisites (x64) (HKLM-x32\\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{19e78c37-4706-4ee6-b14f-00a377e1761c}" => removed successfully Windows SDK AddOn (HKLM-x32\\{E18618EC-D9DB-4BCE-B382-85ADA2CBB340}) (Version: 10.1.0.0 - Microsoft Corporation) Desktop PC Gaming Peripherals Premium Components Gaming Motherboards Premium Graphics Cards Gaming Laptops Windows Explorer Freezing, Screen Goes Black ClickOnce Bootstrapper Package for Microsoft .NET Framework 4.8 on Visual Studio 2017 (HKLM-x32\\{7556B2FA-6364-47EE-901D-12B23F78F382}) (Version: 4.8.04162 - Microsoft Corporation)
3 Bedroom House For Rent Hartford, Ct, Coretec Flooring Problems, Articles T
the aorus lcd panel service service terminated unexpectedly 2023