Fix result of Farbar Recovery Scan Tool (x64) Version: 24.10.2018 Ran by owner (07-11-2018 13:05:03) Run:1 Running from C:\Users\owner\Desktop Loaded Profiles: owner (Available Profiles: owner) Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: CloseProcesses: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION GroupPolicy: Restriction ? <==== ATTENTION FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION CHR HKU\S-1-5-21-1112066077-4254746724-1257480092-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION R3 ALSysIO; C:\Users\owner\AppData\Local\Temp\ALSysIO64.sys [46384 2018-11-07] (Arthur Liberman) <==== ATTENTION FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\instaclick@leahscape.com.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\addressBarFontSizeBigger@papafresh.com.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{c71ff04d-f001-1fc1-1fc1-c71ff04df001}.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{477c4c36-24eb-11da-94d4-00e08161165f}.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\biscuit@nuko.org.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\undoclosedtabsbutton@supernova00.biz.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\ALone-live@ya.ru.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\addonsRecentUpdates@infocatcher.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\firegestures@xuldev.org.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\aboutconfigbutton@firefox.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\zoompage@DW-dev.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [not found] FF Extension: (No Name) - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [not found] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt => not found AlternateDataStreams: C:\ProgramData\TEMP:6DAA43DB [406] AlternateDataStreams: C:\ProgramData\TEMP:810B9F0D [136] Hosts: EmptyTemp: RemoveProxy: ***************** Error: (0) Failed to create a restore point. Processes closed successfully. HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully HKLM\SOFTWARE\Policies\Mozilla => removed successfully HKLM\SOFTWARE\Policies\Google => removed successfully HKU\S-1-5-21-1112066077-4254746724-1257480092-1001\SOFTWARE\Policies\Google => removed successfully ALSysIO => Unable to stop service. HKLM\System\CurrentControlSet\Services\ALSysIO => removed successfully ALSysIO => service removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\instaclick@leahscape.com.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\addressBarFontSizeBigger@papafresh.com.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{c71ff04d-f001-1fc1-1fc1-c71ff04df001}.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{477c4c36-24eb-11da-94d4-00e08161165f}.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\biscuit@nuko.org.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\undoclosedtabsbutton@supernova00.biz.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\ALone-live@ya.ru.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\addonsRecentUpdates@infocatcher.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\firegestures@xuldev.org.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\aboutconfigbutton@firefox.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\zoompage@DW-dev.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi => path removed successfully C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\3kg8bhol.New\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi => path removed successfully "HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{F003DA68-8256-4b37-A6C4-350FA04494DF}" => removed successfully C:\ProgramData\TEMP => ":6DAA43DB" ADS removed successfully C:\ProgramData\TEMP => ":810B9F0D" ADS removed successfully C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. ========= RemoveProxy: ========= HKU\S-1-5-21-1112066077-4254746724-1257480092-1001\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully "HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully "HKU\S-1-5-21-1112066077-4254746724-1257480092-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\S-1-5-21-1112066077-4254746724-1257480092-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully ========= End of RemoveProxy: ========= =========== EmptyTemp: ========== BITS transfer queue => 9461760 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 34223754 B Java, Flash, Steam htmlcache => 270578171 B Windows/system/drivers => 190140046 B Edge => 0 B Chrome => 0 B Firefox => 0 B Opera => 27376678 B Temp, IE cache, history, cookies, recent: Default => 6656 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 13810 B LocalService => 0 B NetworkService => 6656 B NetworkService => 0 B owner => 25812839 B DefaultAppPool => 0 B RecycleBin => 0 B EmptyTemp: => 531.8 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 13:07:12 ====