Python 3.9.5 (64-bit) (HKU\S-1-5-21-326566074-3447909417-183555969-1001\\{f3d4ed4c-f434-41ef-8469-ffadd80c4ccf}) (Version: 3.9.5150.0 - Python Software Foundation) Task: {9ab420ae-8543-428c-9838-410f79c8d585} - no filepath NVIDIA Graphics Driver 496.13 (HKLM\\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 496.13 - NVIDIA Corporation) Discord (HKU\S-1-5-21-326566074-3447909417-183555969-1001\\Discord) (Version: 1.0.9003 - Discord Inc.) 2021-10-15 11:40 - 2021-10-15 11:40 - 000003938 _____ C:\Windows\system32\Tasks\BlueStacksHelper_nxt "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ed48b1d9-cb70-4ae5-8deb-ce6ddd63422a}" => removed successfully 2021-10-07 12:09 - 2019-12-07 22:09 - 000000000 ___HD C:\$WINDOWS.~BT End Detection Source: Real-Time Protection Error: (10/24/2021 07:36:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) We are passionate about teaming up with gamers to fearlessly challenge the limits and win ultimate glory. 2021-10-13 22:14 - 2021-10-07 19:28 - 001597584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2021-10-03 15:48 - 2021-10-24 19:36 - 000000006 ____H C:\Windows\Tasks\SA.DAT Task: {977e0d72-710d-4264-bfbf-105f17f81aa3} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ca0fb10b-e917-4aa5-9e3a-f6a019682f3f}" => removed successfully HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp//go.microsoft.com/fwlink/?LinkId=54896 ==================== End of FRST.txt ========================, Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-10-2021 (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe HKLM\\StartupApproved\Run: => "SecurityHealth" 2021-10-03 10:44 - 2016-02-23 00:52 - 000111692 _____ C:\Users\Pepega\Documents\Burbank Big Condensed Black.ttf 2021-10-02 23:07 - 2021-10-24 21:18 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\discord FF Extension: (Decentraleyes) - C:\Users\Pepega\AppData\Roaming\Mozilla\Firefox\Profiles\q42kwfcc.default-release\Extensions\jid1-BoFifL9Vbdl2zQ@jetpack.xpi [2021-10-05] 2021-10-04 18:19 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\system32\MsDtc ==================== FirewallRules (Whitelisted) ================ "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mpcmdrun.exe" => not found HKLM\\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [3180256 2021-10-21] (Riot Games, Inc. -> Riot Games, Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2021-10-16] (Adobe Inc. -> Adobe Systems) 2021-10-03 09:11 - 2021-10-03 09:12 - 000000000 ____D C:\Users\Pepega\Documents\Visual Studio 2022 R3 gdrv3; C:\Windows\gdrv3.sys [36352 2021-10-20] (GIGA-BYTE Technology Co., Ltd. -> GIGA-BYTE TECHNOLOGY CO., LTD.) Task: {51006d50-cfd3-4b5a-af95-e596678bbea8} - no filepath ==================== Drives ================================ iCue causing system to hang/crash. - Page 4 - iCUE Task: {ed48b1d9-cb70-4ae5-8deb-ce6ddd63422a} - no filepath Task: {378659c1-e595-42d5-9357-395cbc08c53b} - no filepath "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{19e78c37-4706-4ee6-b14f-00a377e1761c}" => removed successfully 2021-10-02 23:44 - 2021-10-20 12:04 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\Battle.net at System.Windows.Forms.Clipboard.GetDataObject() 2021-10-04 18:19 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\system32\GroupPolicy 2021-10-24 20:41 - 2021-10-24 21:08 - 000119048 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SMR540.SYS Task: {53092fd3-455c-4d74-9110-8a5211ddb6c2} - no filepath Task: {f746fb73-bc4d-499e-882f-e5f30abe8a2f} - no filepath HKU\S-1-5-21-326566074-3447909417-183555969-1001\\StartupApproved\Run: => "Windows Driver Installation Service" Task: {e6857042-80d9-4422-85b4-1c5dc0aae451} - no filepath FF Extension: (TubeBuddy) - C:\Users\Pepega\AppData\Roaming\Mozilla\Firefox\Profiles\q42kwfcc.default-release\Extensions\e389d8c2-5554-4ba2-a36e-ac7a57093130@gmail.com.xpi [2021-10-14] 2021-10-02 23:01 - 2021-10-02 23:01 - 000000000 ____D C:\Users\Pepega\AppData\Local\setup Task: {414df2f8-cc7c-49b6-a90f-8e407ed62e02} - no filepath 2021-10-24 13:24 - 2021-10-24 13:24 - 000000000 ____D C:\Users\Pepega\Desktop\tron i scanned using norton power eraser, but it returned with no results. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{00f722c3-08dc-4b10-b10e-91a3004714f3}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{d9c6b67e-9dbb-4ba4-ad4b-5aecb6889d08}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{b7e27570-3f72-4ac2-b2ec-fd92b54c3a60}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4d4276f1-945c-486b-b48f-62cda9b73d18}" => removed successfully The Client License Service (ClipSVC) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{e6857042-80d9-4422-85b4-1c5dc0aae451}" => removed successfully ========= "%WINDIR%\SYSTEM32\lodctr.exe" /R ========= 2021-10-02 23:10 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\IME 2021-10-15 11:40 - 2021-10-15 11:40 - 000000000 ____D C:\ProgramData\BlueStacks_nxt ?\C:\Program Files\BlueStacks_nxt\BstkDrv_nxt.sys [X] 2021-10-24 14:56 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\AppReadiness 2021-10-18 20:24 - 2021-10-18 20:24 - 000000000 ____D C:\Program Files\AMD Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 25-10-2021 08:47:26)