Fix result of Farbar Recovery Scan Tool (x64) Version: 14-10-2020
Ran by Michal (17-10-2020 14:05:27) Run:1
Running from C:\Users\Michal\Desktop
Loaded Profiles: Michal
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
PowerShell: Enable-ComputerRestore -Drive "C:\"
HKU\S-1-5-21-3838665394-1485884192-1729339075-1001\...\Winlogon: [Shell] %comspec% <==== ATTENTION
HKU\S-1-5-21-3838665394-1485884192-1729339075-1001\...\Command Processor: @mode 20,5 & tasklist /FI "IMAGENAME eq SoundModule.exe" 2>NUL | find /I /N "SoundModule.exe">NUL && exit & if exist ( start /MIN "" & tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) else ( tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
Task: {17066C48-564A-4B1A-95FC-B0BEB03ADB44} - \Lenovo\ImController\TimeBasedEvents\31eec00a-96a3-4db9-87d6-eca9e7ef20ba -> No File <==== ATTENTION
Task: {18DCF431-8EAF-418F-B272-9309E3FF760C} - \Lenovo\ImController\Lenovo iM Controller Monitor -> No File <==== ATTENTION
Task: {240C7866-BB99-4F54-90BD-9252FE66855B} - \Lenovo\ImController\TimeBasedEvents\c5e48814-34ca-46aa-8bc4-647ed977827e -> No File <==== ATTENTION
Task: {25FDEC66-E71E-48EA-8666-F2A34B07507B} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> No File <==== ATTENTION
Task: {5694F966-7B51-4B2E-9295-C9A164065FC2} - System32\Tasks\LenovoUtility Task => C:\Windows\explorer.exe lenovo-utility://
Task: {3E75DFA2-59E9-4140-8704-15FF85C31259} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-08] (Google Inc -> Google Inc.)
Task: {5694F966-7B51-4B2E-9295-C9A164065FC2} - System32\Tasks\LenovoUtility Task => C:\Windows\explorer.exe lenovo-utility://
Task: {64FC6A1C-2449-4DB5-BE8B-9711A5EA2092} - \Lenovo\ImController\TimeBasedEvents\e381380a-727d-4464-91ff-b4ef58d2ece6 -> No File <==== ATTENTION
Task: {68E1E5D6-BDDD-4851-8311-43468C028AA8} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> No File <==== ATTENTION
Task: {F3EBEBFD-A048-4209-AACD-73C25DDBABFA} - \Lenovo\ImController\TimeBasedEvents\c0d09f3a-fb98-40b0-8d9f-d3af152038f5 -> No File <==== ATTENTION
FF NewTab: Mozilla\Firefox\Profiles\lmg1t01p.default -> hxxps://securesearch.org/homepage?hp=2&pId=BT170603&iDate=2020-10-04 12:41:51&bName=
S4 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [X]
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
HKU\S-1-5-21-3838665394-1485884192-1729339075-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://securesearch.org/homepage?hp=2&pId=BT170603&iDate=2020-10-04 12:41:51&bName=
SearchScopes: HKU\S-1-5-21-3838665394-1485884192-1729339075-1001 -> DefaultScope {EBD65539-52E0-4E9D-96FA-8CD5B08E67AD} URL =
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
FirewallRules: [{BA4F87B4-C6C0-4BBF-B8F7-E42EF3BB28E4}] => (Allow) C:\Users\Michal\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{E0FDB64B-C4EF-4E8B-9BE6-EFA1F85A9712}] => (Allow) C:\Users\Michal\AppData\Roaming\uTorrent\uTorrent.exe => No File
EmptyTemp:
End
*****************
Error: (0) Failed to create a restore point.
========= Enable-ComputerRestore -Drive "C:\" =========
========= End of Powershell: =========
"HKU\S-1-5-21-3838665394-1485884192-1729339075-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell" => removed successfully
"HKU\S-1-5-21-3838665394-1485884192-1729339075-1001\Software\Microsoft\Command Processor\\AutoRun" => removed successfully
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
HKLM\SOFTWARE\Policies\Google => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{17066C48-564A-4B1A-95FC-B0BEB03ADB44}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{17066C48-564A-4B1A-95FC-B0BEB03ADB44}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\31eec00a-96a3-4db9-87d6-eca9e7ef20ba" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{18DCF431-8EAF-418F-B272-9309E3FF760C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{18DCF431-8EAF-418F-B272-9309E3FF760C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Monitor" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{240C7866-BB99-4F54-90BD-9252FE66855B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{240C7866-BB99-4F54-90BD-9252FE66855B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\c5e48814-34ca-46aa-8bc4-647ed977827e" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{25FDEC66-E71E-48EA-8666-F2A34B07507B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25FDEC66-E71E-48EA-8666-F2A34B07507B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5694F966-7B51-4B2E-9295-C9A164065FC2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5694F966-7B51-4B2E-9295-C9A164065FC2}" => removed successfully
C:\WINDOWS\System32\Tasks\LenovoUtility Task => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LenovoUtility Task" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3E75DFA2-59E9-4140-8704-15FF85C31259}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E75DFA2-59E9-4140-8704-15FF85C31259}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5694F966-7B51-4B2E-9295-C9A164065FC2}" => not found
"C:\WINDOWS\System32\Tasks\LenovoUtility Task" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LenovoUtility Task" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{64FC6A1C-2449-4DB5-BE8B-9711A5EA2092}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{64FC6A1C-2449-4DB5-BE8B-9711A5EA2092}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\e381380a-727d-4464-91ff-b4ef58d2ece6" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{68E1E5D6-BDDD-4851-8311-43468C028AA8}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68E1E5D6-BDDD-4851-8311-43468C028AA8}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3EBEBFD-A048-4209-AACD-73C25DDBABFA}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3EBEBFD-A048-4209-AACD-73C25DDBABFA}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\c0d09f3a-fb98-40b0-8d9f-d3af152038f5" => removed successfully
"Firefox newtab" => removed successfully
HKLM\System\CurrentControlSet\Services\McAfee WebAdvisor => removed successfully
McAfee WebAdvisor => service removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKU\S-1-5-21-3838665394-1485884192-1729339075-1001\Software\Microsoft\Internet Explorer\Main\\"Start Page"="
http://go.microsoft.com/fwlink/?LinkId=69157" => value restored successfully
"HKU\S-1-5-21-3838665394-1485884192-1729339075-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\AdobeAAMUpdater-1.0" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BA4F87B4-C6C0-4BBF-B8F7-E42EF3BB28E4}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E0FDB64B-C4EF-4E8B-9BE6-EFA1F85A9712}" => removed successfully
=========== EmptyTemp: ==========
BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 18002273 B
Java, Flash, Steam htmlcache => 524 B
Windows/system/drivers => 737697 B
Edge => 57960 B
Chrome => 6992644 B
Firefox => 281712399 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 8878 B
NetworkService => 8878 B
Michal => 31602531 B
Marlenka => 31675914 B
RecycleBin => 0 B
EmptyTemp: => 363.6 MB temporary data Removed.
================================
The system needed a reboot.
==== End 1 Fixlog 14:05:45 ====