PaulTomasi
Posts: 24 +0
Fix result of Farbar Recovery Scan Tool (x64) Version: 06-06-2019
Ran by pault (07-06-2019 19:24:05) Run:2
Running from C:\Users\pault\Desktop
Loaded Profiles: pault (Available Profiles: pault & PAUL)
Boot Mode: Normal
==============================================
fixlist content:
*****************
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
URLSearchHook: [S-1-5-21-1882311373-1252287477-1295940213-1001] ATTENTION => Default URLSearchHook is missing
S4 BraveElevationService; "C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\71.0.58.21\elevation_service.exe" [X]
U4 npcap_wifi; no ImagePath
2018-08-23 02:41 - 2018-08-23 02:41 - 000195887 _____ () C:\Users\pault\DispDiag-20180823-024105-4760-16808.dat
2017-11-30 21:58 - 2017-11-30 21:58 - 000000351 _____ () C:\Program Files (x86)\BootAnalyzerInstaller.log
2018-08-17 18:50 - 2018-11-23 20:48 - 000000096 _____ () C:\Users\pault\AppData\Roaming\Camdata.ini
2018-08-17 18:50 - 2018-11-23 20:48 - 000000408 _____ () C:\Users\pault\AppData\Roaming\CamLayout.ini
2018-08-17 18:50 - 2018-11-23 20:48 - 000000408 _____ () C:\Users\pault\AppData\Roaming\CamShapes.ini
2018-08-05 19:50 - 2018-11-23 20:48 - 000004536 _____ () C:\Users\pault\AppData\Roaming\CamStudio.cfg
2018-08-05 10:00 - 2018-11-23 20:47 - 000000096 _____ () C:\Users\pault\AppData\Roaming\version2.xml
2018-03-21 04:06 - 2018-05-13 00:00 - 000003584 _____ () C:\Users\pault\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2019-05-31 14:53 - 2019-05-31 14:53 - 000000937 _____ () C:\Users\pault\AppData\Local\recently-used.xbel
2017-11-16 11:13 - 2017-11-16 11:13 - 000000017 _____ () C:\Users\pault\AppData\Local\resmon.resmoncfg
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [476]
FirewallRules: [MCX-In-TCP] => (Block) %SystemRoot%\ehome\ehshell.exe No File
FirewallRules: [MCX-In-UDP] => (Block) %SystemRoot%\ehome\ehshell.exe No File
FirewallRules: [TCP Query User{890A273F-B2EE-4E7E-9535-D4601EC8A573}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe No File
FirewallRules: [UDP Query User{17F6B1E2-62FD-4DC3-8E1B-40026CDCC595}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe No File
FirewallRules: [TCP Query User{C7D31D39-9CFB-4D09-B4F4-9D87D60E4A02}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File
FirewallRules: [UDP Query User{EE810FFF-251F-4CAF-9B51-68C48C90CE71}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File
*****************
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => could not remove, key could be protected
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
Could not restore Default URLSearchHook.
HKLM\System\CurrentControlSet\Services\BraveElevationService => removed successfully
BraveElevationService => service removed successfully
HKLM\System\CurrentControlSet\Services\npcap_wifi => removed successfully
npcap_wifi => service removed successfully
C:\Users\pault\DispDiag-20180823-024105-4760-16808.dat => moved successfully
C:\Program Files (x86)\BootAnalyzerInstaller.log => moved successfully
C:\Users\pault\AppData\Roaming\Camdata.ini => moved successfully
C:\Users\pault\AppData\Roaming\CamLayout.ini => moved successfully
C:\Users\pault\AppData\Roaming\CamShapes.ini => moved successfully
C:\Users\pault\AppData\Roaming\CamStudio.cfg => moved successfully
C:\Users\pault\AppData\Roaming\version2.xml => moved successfully
C:\Users\pault\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully
C:\Users\pault\AppData\Local\recently-used.xbel => moved successfully
C:\Users\pault\AppData\Local\resmon.resmoncfg => moved successfully
C:\Users\Public\Shared Files => ":VersionCache" ADS removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\MCX-In-TCP" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\MCX-In-UDP" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{890A273F-B2EE-4E7E-9535-D4601EC8A573}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{17F6B1E2-62FD-4DC3-8E1B-40026CDCC595}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{C7D31D39-9CFB-4D09-B4F4-9D87D60E4A02}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{EE810FFF-251F-4CAF-9B51-68C48C90CE71}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe" => removed successfully
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 07-06-2019 19:30:19)
Result of scheduled keys to remove after reboot:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
==== End of Fixlog 19:30:20 ====
Ran by pault (07-06-2019 19:24:05) Run:2
Running from C:\Users\pault\Desktop
Loaded Profiles: pault (Available Profiles: pault & PAUL)
Boot Mode: Normal
==============================================
fixlist content:
*****************
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
URLSearchHook: [S-1-5-21-1882311373-1252287477-1295940213-1001] ATTENTION => Default URLSearchHook is missing
S4 BraveElevationService; "C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\71.0.58.21\elevation_service.exe" [X]
U4 npcap_wifi; no ImagePath
2018-08-23 02:41 - 2018-08-23 02:41 - 000195887 _____ () C:\Users\pault\DispDiag-20180823-024105-4760-16808.dat
2017-11-30 21:58 - 2017-11-30 21:58 - 000000351 _____ () C:\Program Files (x86)\BootAnalyzerInstaller.log
2018-08-17 18:50 - 2018-11-23 20:48 - 000000096 _____ () C:\Users\pault\AppData\Roaming\Camdata.ini
2018-08-17 18:50 - 2018-11-23 20:48 - 000000408 _____ () C:\Users\pault\AppData\Roaming\CamLayout.ini
2018-08-17 18:50 - 2018-11-23 20:48 - 000000408 _____ () C:\Users\pault\AppData\Roaming\CamShapes.ini
2018-08-05 19:50 - 2018-11-23 20:48 - 000004536 _____ () C:\Users\pault\AppData\Roaming\CamStudio.cfg
2018-08-05 10:00 - 2018-11-23 20:47 - 000000096 _____ () C:\Users\pault\AppData\Roaming\version2.xml
2018-03-21 04:06 - 2018-05-13 00:00 - 000003584 _____ () C:\Users\pault\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2019-05-31 14:53 - 2019-05-31 14:53 - 000000937 _____ () C:\Users\pault\AppData\Local\recently-used.xbel
2017-11-16 11:13 - 2017-11-16 11:13 - 000000017 _____ () C:\Users\pault\AppData\Local\resmon.resmoncfg
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [476]
FirewallRules: [MCX-In-TCP] => (Block) %SystemRoot%\ehome\ehshell.exe No File
FirewallRules: [MCX-In-UDP] => (Block) %SystemRoot%\ehome\ehshell.exe No File
FirewallRules: [TCP Query User{890A273F-B2EE-4E7E-9535-D4601EC8A573}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe No File
FirewallRules: [UDP Query User{17F6B1E2-62FD-4DC3-8E1B-40026CDCC595}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe No File
FirewallRules: [TCP Query User{C7D31D39-9CFB-4D09-B4F4-9D87D60E4A02}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File
FirewallRules: [UDP Query User{EE810FFF-251F-4CAF-9B51-68C48C90CE71}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File
*****************
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => could not remove, key could be protected
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
Could not restore Default URLSearchHook.
HKLM\System\CurrentControlSet\Services\BraveElevationService => removed successfully
BraveElevationService => service removed successfully
HKLM\System\CurrentControlSet\Services\npcap_wifi => removed successfully
npcap_wifi => service removed successfully
C:\Users\pault\DispDiag-20180823-024105-4760-16808.dat => moved successfully
C:\Program Files (x86)\BootAnalyzerInstaller.log => moved successfully
C:\Users\pault\AppData\Roaming\Camdata.ini => moved successfully
C:\Users\pault\AppData\Roaming\CamLayout.ini => moved successfully
C:\Users\pault\AppData\Roaming\CamShapes.ini => moved successfully
C:\Users\pault\AppData\Roaming\CamStudio.cfg => moved successfully
C:\Users\pault\AppData\Roaming\version2.xml => moved successfully
C:\Users\pault\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully
C:\Users\pault\AppData\Local\recently-used.xbel => moved successfully
C:\Users\pault\AppData\Local\resmon.resmoncfg => moved successfully
C:\Users\Public\Shared Files => ":VersionCache" ADS removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\MCX-In-TCP" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\MCX-In-UDP" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{890A273F-B2EE-4E7E-9535-D4601EC8A573}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{17F6B1E2-62FD-4DC3-8E1B-40026CDCC595}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{C7D31D39-9CFB-4D09-B4F4-9D87D60E4A02}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{EE810FFF-251F-4CAF-9B51-68C48C90CE71}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe" => removed successfully
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 07-06-2019 19:30:19)
Result of scheduled keys to remove after reboot:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
==== End of Fixlog 19:30:20 ====