Fix result of Farbar Recovery Scan Tool (x64) Version: 01.01.2019 Ran by Berengere (04-01-2019 23:28:41) Run:1 Running from C:\Users\Berengere\Desktop Loaded Profiles: Berengere (Available Profiles: Berengere) Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: CloseProcesses: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION FirewallRules: [{655FD1DE-4E5C-4663-BEAE-CCC9F0C28C92}] => (Allow) C:\Users\Berengere\AppData\Roaming\BitTorrent\BitTorrent.exe No File FirewallRules: [{84253B7F-7142-4791-BD2F-7F6E2860D6AA}] => (Allow) C:\Users\Berengere\AppData\Roaming\BitTorrent\BitTorrent.exe No File FirewallRules: [{7996C8B5-8704-467B-98E7-0EDCA0CEC336}] => (Allow) C:\Users\Berengere\AppData\Local\Temp\7zS537C\HPDiagnosticCoreUI.exe No File FirewallRules: [{26694F81-B830-4B62-9646-0BDC5AB01E65}] => (Allow) C:\Users\Berengere\AppData\Local\Temp\7zS537C\HPDiagnosticCoreUI.exe No File FirewallRules: [{FFEEDE01-4E73-41FB-9CCB-3B30FB83A740}] => (Allow) C:\Users\Berengere\AppData\Local\Temp\7zS55C5\HPDiagnosticCoreUI.exe No File FirewallRules: [{6F37F181-A16F-4466-810F-82723625DC11}] => (Allow) C:\Users\Berengere\AppData\Local\Temp\7zS55C5\HPDiagnosticCoreUI.exe No File FirewallRules: [{07D02256-EE49-473A-B5FC-BC400B68D397}] => (Allow) C:\Users\Berengere\AppData\Local\Temp\7zS5648\HPDiagnosticCoreUI.exe No File FirewallRules: [{0BD30A5B-1C06-4A9B-87B8-FF3B1426EF62}] => (Allow) C:\Users\Berengere\AppData\Local\Temp\7zS5648\HPDiagnosticCoreUI.exe No File FirewallRules: [{F52F3B8A-3171-4F92-91B0-784A34830E8B}] => (Allow) C:\Users\Berengere\AppData\Local\Temp\7zS5359\HPDiagnosticCoreUI.exe No File FirewallRules: [{2406B423-296A-4D5A-AF7E-4D9F89ED3529}] => (Allow) C:\Users\Berengere\AppData\Local\Temp\7zS5359\HPDiagnosticCoreUI.exe No File FirewallRules: [{DE14ED8C-5CE3-44F2-BE09-62968EAEDEB3}] => (Allow) C:\Users\Berengere\AppData\Local\Temp\7zS4B4D\HPDiagnosticCoreUI.exe No File FirewallRules: [{9CDE51A3-1901-4E0B-A476-318F5A98173D}] => (Allow) C:\Users\Berengere\AppData\Local\Temp\7zS4B4D\HPDiagnosticCoreUI.exe No File FirewallRules: [{25F759DD-8080-4123-8BFB-8948DBC02A73}] => (Allow) C:\Users\Berengere\AppData\Local\Temp\7zS4C48\HPDiagnosticCoreUI.exe No File FirewallRules: [{1DACB567-610D-465C-9609-0F6D10C1384F}] => (Allow) C:\Users\Berengere\AppData\Local\Temp\7zS4C48\HPDiagnosticCoreUI.exe No File FF Extension: (No Name) - C:\Users\Berengere\AppData\Roaming\Mozilla\Firefox\Profiles\i3rcreje.default\Extensions\jid1-YcMV6ngYmQRA2w@jetpack.xpi [2018-12-10] ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File FirewallRules: [TCP Query User{9DC34E1F-AC0E-4F27-86FB-83333600F2F1}C:\program files\openshot video editor\launch.exe] => (Block) C:\program files\openshot video editor\launch.exe No File FirewallRules: [UDP Query User{1558B232-8BF6-4AB1-A70B-6665C41F09A1}C:\program files\openshot video editor\launch.exe] => (Block) C:\program files\openshot video editor\launch.exe No File S3 H2OFFT; \SystemRoot\System32\drivers\H2OFFT64.sys [X] EmptyTemp: ***************** Restore point was successfully created. Processes closed successfully. HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => could not remove, key could be protected "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{655FD1DE-4E5C-4663-BEAE-CCC9F0C28C92}" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{84253B7F-7142-4791-BD2F-7F6E2860D6AA}" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7996C8B5-8704-467B-98E7-0EDCA0CEC336}" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{26694F81-B830-4B62-9646-0BDC5AB01E65}" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FFEEDE01-4E73-41FB-9CCB-3B30FB83A740}" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6F37F181-A16F-4466-810F-82723625DC11}" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{07D02256-EE49-473A-B5FC-BC400B68D397}" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0BD30A5B-1C06-4A9B-87B8-FF3B1426EF62}" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F52F3B8A-3171-4F92-91B0-784A34830E8B}" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2406B423-296A-4D5A-AF7E-4D9F89ED3529}" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DE14ED8C-5CE3-44F2-BE09-62968EAEDEB3}" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9CDE51A3-1901-4E0B-A476-318F5A98173D}" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{25F759DD-8080-4123-8BFB-8948DBC02A73}" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1DACB567-610D-465C-9609-0F6D10C1384F}" => not found C:\Users\Berengere\AppData\Roaming\Mozilla\Firefox\Profiles\i3rcreje.default\Extensions\jid1-YcMV6ngYmQRA2w@jetpack.xpi => moved successfully HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{9DC34E1F-AC0E-4F27-86FB-83333600F2F1}C:\program files\openshot video editor\launch.exe" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{1558B232-8BF6-4AB1-A70B-6665C41F09A1}C:\program files\openshot video editor\launch.exe" => not found H2OFFT => service not found. =========== EmptyTemp: ========== BITS transfer queue => 9199616 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 20131770 B Java, Flash, Steam htmlcache => 1274 B Windows/system/drivers => 2839264 B Edge => 1181059 B Chrome => 13559537 B Firefox => 1097230566 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 47086 B LocalService => 0 B NetworkService => 5364 B NetworkService => 0 B Berengere => 95057296 B RecycleBin => 0 B EmptyTemp: => 1.2 GB temporary data Removed. ================================ Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 04-01-2019 23:33:24) Result of scheduled keys to remove after reboot: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => could not remove, key could be protected ==== End of Fixlog 23:33:25 ====