Fix result of Farbar Recovery Scan Tool (x64) Version: 19.02.2018 Ran by Clèm (20-02-2018 22:44:46) Run:1 Running from C:\Users\Clèm\Downloads Loaded Profiles: Clèm (Available Profiles: Clèm) Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: CloseProcesses: DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E08D6DD-46CA-47FC-A1E9-B28D86D989AF} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3E08D6DD-46CA-47FC-A1E9-B28D86D989AF} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{3E08D6DD-46CA-47FC-A1E9-B28D86D989AF} C:\Windows\System32\Tasks\{98D2AF2E-EB7C-4C51-88DE-F07F135BAA57} DeleteKey: HKLM\SOFTWARE\ByteFence DeleteKey: HKLM\SOFTWARE\WOW6432Node\ByteFence DeleteKey: HKCU\SOFTWARE\ByteFence DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{F44E24B3-3D2F-4510-B400-281E2D23AB43} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{043B23BB-228D-4261-969E-E76EFCBF73DA} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{72B9EE22-D406-4FF0-B47A-B33CABAB8B8F}C:\program files\avid\application manager\avidappmanhelper.exe DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{B6929DE4-8951-4560-B5F8-AEE99295F4D1}C:\program files\avid\application manager\avidappmanhelper.exe C:\Users\Clèm\AppData\Local\Google\Chrome\User Data\Default\File System\000 C:\Users\Clèm\AppData\Local\Google\Chrome\User Data\Default\File System\001 C:\Users\Clèm\AppData\Local\Google\Chrome\User Data\Default\File System\002 C:\Users\Clèm\AppData\Local\Google\Chrome\User Data\Default\File System\003 C:\Users\Clèm\AppData\Local\Google\Chrome\User Data\Default\File System\004 C:\Users\Cl??m\AppData\Local\Google\Chrome\User Data\Default\File System\005 DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASAPI32 DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASMANCS DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS C:\ProgramData\ByteFence DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceService_RASAPI32 DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceService_RASMANCS DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFence_RASAPI32 DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFence_RASMANCS C:\Users\Clèm\Desktop\Windows KMS Activator Ultimate 2018 4.0 S3 MBAMWebProtection; system32\DRIVERS\mwac.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] 2011-05-31 16:21 - 2011-05-31 16:21 - 000401408 _____ (Kingston Technology Inc) C:\Users\Clèm\AppData\Local\Temp\Kingston Format Utility.exe Task: {27861EBC-5230-4A1E-9384-86D5D53EA4AC} - \SystemMaintanceService -> No File Task: {DB2D2573-7AF2-4E0F-A2F7-009D5BBB91A6} - \OptimizerTask -> No File AlternateDataStreams: C:\Users\Clèm\Cookies:ISiEDbIXUXJSiUsiOsuF11 [2318] AlternateDataStreams: C:\Users\Clèm\Cookies:IYQaZqJmprDLiNRLAaAf7tX3p [2458] AlternateDataStreams: C:\Users\Clèm\Local Settings:kpruheKHZO8F5e5FOdw [2086] AlternateDataStreams: C:\Users\Clèm\AppData\Local:kpruheKHZO8F5e5FOdw [2086] AlternateDataStreams: C:\Users\Clèm\AppData\Local\Application Data:kpruheKHZO8F5e5FOdw [2086] EmptyTemp: ***************** Restore point was successfully created. Processes closed successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E08D6DD-46CA-47FC-A1E9-B28D86D989AF} => could not remove key. ErrorCode1: 0x00000002 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3E08D6DD-46CA-47FC-A1E9-B28D86D989AF} => could not remove key. ErrorCode1: 0x00000001 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{3E08D6DD-46CA-47FC-A1E9-B28D86D989AF} => could not remove key. ErrorCode1: 0x00000001 C:\Windows\System32\Tasks\{98D2AF2E-EB7C-4C51-88DE-F07F135BAA57} => moved successfully HKLM\SOFTWARE\ByteFence => key not found "HKLM\SOFTWARE\WOW6432Node\ByteFence" => removed successfully HKCU\SOFTWARE\ByteFence => key not found "HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32" => removed successfully HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} => key not found "HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32" => removed successfully HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} => key not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F44E24B3-3D2F-4510-B400-281E2D23AB43}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{043B23BB-228D-4261-969E-E76EFCBF73DA}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{72B9EE22-D406-4FF0-B47A-B33CABAB8B8F}C:\program files\avid\application manager\avidappmanhelper.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{B6929DE4-8951-4560-B5F8-AEE99295F4D1}C:\program files\avid\application manager\avidappmanhelper.exe" => removed successfully C:\Users\Clèm\AppData\Local\Google\Chrome\User Data\Default\File System\000 => moved successfully C:\Users\Clèm\AppData\Local\Google\Chrome\User Data\Default\File System\001 => moved successfully C:\Users\Clèm\AppData\Local\Google\Chrome\User Data\Default\File System\002 => moved successfully C:\Users\Clèm\AppData\Local\Google\Chrome\User Data\Default\File System\003 => moved successfully C:\Users\Clèm\AppData\Local\Google\Chrome\User Data\Default\File System\004 => moved successfully "C:\Users\Cl??m\AppData\Local\Google\Chrome\User Data\Default\File System\005" => not found "HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASAPI32" => removed successfully "HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASMANCS" => removed successfully "HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32" => removed successfully "HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS" => removed successfully "C:\ProgramData\ByteFence" => not found HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 => key not found HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} => key not found HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 => key not found "HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceService_RASAPI32" => not found "HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceService_RASMANCS" => not found "HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFence_RASAPI32" => not found "HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFence_RASMANCS" => not found "C:\Users\Clèm\Desktop\Windows KMS Activator Ultimate 2018 4.0" => not found "HKLM\System\CurrentControlSet\Services\MBAMWebProtection" => removed successfully MBAMWebProtection => service removed successfully "HKLM\System\CurrentControlSet\Services\VGPU" => removed successfully VGPU => service removed successfully C:\Users\Clèm\AppData\Local\Temp\Kingston Format Utility.exe => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{27861EBC-5230-4A1E-9384-86D5D53EA4AC} => could not remove key. ErrorCode1: 0x00000002 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{27861EBC-5230-4A1E-9384-86D5D53EA4AC} => could not remove key. ErrorCode1: 0x00000002 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SystemMaintanceService => could not remove key. ErrorCode1: 0x00000002 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DB2D2573-7AF2-4E0F-A2F7-009D5BBB91A6} => could not remove key. ErrorCode1: 0x00000002 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB2D2573-7AF2-4E0F-A2F7-009D5BBB91A6} => could not remove key. ErrorCode1: 0x00000002 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OptimizerTask => could not remove key. ErrorCode1: 0x00000002 C:\Users\Clèm\Cookies => ":ISiEDbIXUXJSiUsiOsuF11" ADS removed successfully C:\Users\Clèm\Cookies => ":IYQaZqJmprDLiNRLAaAf7tX3p" ADS removed successfully C:\Users\Clèm\Local Settings => ":kpruheKHZO8F5e5FOdw" ADS removed successfully "C:\Users\Clèm\AppData\Local" => ":kpruheKHZO8F5e5FOdw" ADS not found. "C:\Users\Clèm\AppData\Local\Application Data" => ":kpruheKHZO8F5e5FOdw" ADS not found. =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 38001958 B Java, Flash, Steam htmlcache => 43945957 B Windows/system/drivers => 8530133 B Edge => 0 B Chrome => 67805992 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 66356 B systemprofile32 => 66788 B LocalService => 66228 B NetworkService => 0 B Clèm => 541275060 B RecycleBin => 0 B EmptyTemp: => 675.3 MB temporary data Removed. ================================ Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 20-02-2018 22:48:15) Result of scheduled keys to remove after reboot: "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E08D6DD-46CA-47FC-A1E9-B28D86D989AF}" => removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3E08D6DD-46CA-47FC-A1E9-B28D86D989AF} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{3E08D6DD-46CA-47FC-A1E9-B28D86D989AF} => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{27861EBC-5230-4A1E-9384-86D5D53EA4AC}" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{27861EBC-5230-4A1E-9384-86D5D53EA4AC}" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SystemMaintanceService" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DB2D2573-7AF2-4E0F-A2F7-009D5BBB91A6}" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB2D2573-7AF2-4E0F-A2F7-009D5BBB91A6}" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OptimizerTask" => removed successfully ==== End of Fixlog 22:48:15 ====