Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01 Ran by brennaman (2016-04-07 13:15:46) Run:1 Running from C:\Users\pbren_000\Downloads Loaded Profiles: brennaman (Available Profiles: brennaman) Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: Winsock: Catalog5 07 C:\ProgramData\System32\SafeGuard32.dll No File Winsock: Catalog5-x64 07 C:\ProgramData\System32\SafeGuard64.dll [3587000 2015-12-30] () S2 wbsvc; C:\Program Files\WebBar\wbsvc.exe [33792 2016-02-23] (Web Bar Media) [File not signed] 2016-03-12 20:47 - 2016-03-12 20:47 - 00000034 _____ C:\Users\Public\Documents\{DE764086-1C0A-4DD3-90BA-0B93BDD794BE} 2016-03-12 20:41 - 2016-04-05 20:18 - 00000000 ____D C:\Program Files\WebBar Task: {01070F9D-E5CE-4386-91F6-1952CE5AA2FB} - System32\Tasks\WebBarLaunchTask => C:\Program Files\WebBar\wbsvc.exe [2016-02-23] (Web Bar Media) <==== ATTENTION Task: {5F8D7336-CF79-4458-9F5B-22BA40B836AB} - System32\Tasks\WebBarUpdateTask => C:\Program Files\WebBar\wbsvc.exe [2016-02-23] (Web Bar Media) <==== ATTENTION Task: C:\WINDOWS\Tasks\System HealerPeriod.job => Task: C:\WINDOWS\Tasks\System HealerStartUp.job => C:\Program Files (x86)\SystemHealer\SystemHealer.exe AlternateDataStreams: C:\WINDOWS\SysWOW64\mswinsck32.ocx:rsrc [34] C:\ProgramData\System32\SafeGuard32.dll C:\ProgramData\System32\SafeGuard64.dll C:\Program Files (x86)\SystemHealer Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f RemoveProxy: CMD: netsh advfirewall reset CMD: netsh advfirewall set allprofiles state ON CMD: ipconfig /flushdns CMD: netsh winsock reset catalog CMD: netsh int ip reset c:\resetlog.txt CMD: ipconfig /release CMD: ipconfig /renew CMD: netsh int ipv4 reset CMD: netsh int ipv6 reset EmptyTemp: CMD: bitsadmin /reset /allusers ***************** Restore point was successfully created. "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007" => key removed successfully "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007" => key removed successfully wbsvc => service removed successfully C:\Users\Public\Documents\{DE764086-1C0A-4DD3-90BA-0B93BDD794BE} => moved successfully C:\Program Files\WebBar => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{01070F9D-E5CE-4386-91F6-1952CE5AA2FB}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{01070F9D-E5CE-4386-91F6-1952CE5AA2FB}" => key removed successfully C:\WINDOWS\System32\Tasks\WebBarLaunchTask => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WebBarLaunchTask" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5F8D7336-CF79-4458-9F5B-22BA40B836AB}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5F8D7336-CF79-4458-9F5B-22BA40B836AB}" => key removed successfully C:\WINDOWS\System32\Tasks\WebBarUpdateTask => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WebBarUpdateTask" => key removed successfully Task: C:\WINDOWS\Tasks\System HealerPeriod.job => => not found. C:\WINDOWS\Tasks\System HealerStartUp.job => moved successfully C:\WINDOWS\SysWOW64\mswinsck32.ocx => ":rsrc" ADS removed successfully. C:\ProgramData\System32\SafeGuard32.dll => moved successfully C:\ProgramData\System32\SafeGuard64.dll => moved successfully "C:\Program Files (x86)\SystemHealer" => not found. ========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f ========= The operation completed successfully. ========= End of Reg: ========= ========= RemoveProxy: ========= HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully HKU\S-1-5-21-3610044688-3067938498-1592336940-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\S-1-5-21-3610044688-3067938498-1592336940-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully ========= End of RemoveProxy: ========= ========= netsh advfirewall reset ========= Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003 Ok. ========= End of CMD: ========= ========= netsh advfirewall set allprofiles state ON ========= Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003 Ok. ========= End of CMD: ========= ========= ipconfig /flushdns ========= Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========= End of CMD: ========= ========= netsh winsock reset catalog ========= Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003 Sucessfully reset the Winsock Catalog. You must restart the computer in order to complete the reset. ========= End of CMD: ========= ========= netsh int ip reset c:\resetlog.txt ========= Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003 Resetting Global, OK! Resetting Interface, OK! Resetting Unicast Address, OK! Resetting Neighbor, OK! Resetting Path, OK! Resetting , failed. Access is denied. Resetting , OK! Restart the computer to complete this action. ========= End of CMD: ========= ========= ipconfig /release ========= Windows IP Configuration No operation can be performed on Ethernet while it has its media disconnected. No operation can be performed on Local Area Connection* 2 while it has its media disconnected. No operation can be performed on Bluetooth Network Connection while it has its media disconnected. Ethernet adapter Ethernet: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Wireless LAN adapter Local Area Connection* 2: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Wireless LAN adapter Wi-Fi: Connection-specific DNS Suffix . : IPv6 Address. . . . . . . . . . . : 2602:306:cffe:4530::1a IPv6 Address. . . . . . . . . . . : 2602:306:cffe:4530:7411:1789:eace:85f2 Temporary IPv6 Address. . . . . . : 2602:306:cffe:4530:5c0:4521:fc52:a89f Link-local IPv6 Address . . . . . : fe80::7411:1789:eace:85f2%10 Default Gateway . . . . . . . . . : fe80::ea33:81ff:fe6e:9140%10 Ethernet adapter Bluetooth Network Connection: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Tunnel adapter Teredo Tunneling Pseudo-Interface: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : ========= End of CMD: ========= ========= ipconfig /renew ========= Windows IP Configuration No operation can be performed on Ethernet while it has its media disconnected. No operation can be performed on Local Area Connection* 2 while it has its media disconnected. No operation can be performed on Bluetooth Network Connection while it has its media disconnected. Ethernet adapter Ethernet: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Wireless LAN adapter Local Area Connection* 2: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Wireless LAN adapter Wi-Fi: Connection-specific DNS Suffix . : attlocal.net IPv6 Address. . . . . . . . . . . : 2602:306:cffe:4530::1a IPv6 Address. . . . . . . . . . . : 2602:306:cffe:4530:7411:1789:eace:85f2 Temporary IPv6 Address. . . . . . : 2602:306:cffe:4530:5c0:4521:fc52:a89f Link-local IPv6 Address . . . . . : fe80::7411:1789:eace:85f2%10 IPv4 Address. . . . . . . . . . . : 192.168.1.194 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : fe80::ea33:81ff:fe6e:9140%10 192.168.1.254 Ethernet adapter Bluetooth Network Connection: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Tunnel adapter isatap.attlocal.net: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : attlocal.net Tunnel adapter Teredo Tunneling Pseudo-Interface: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : ========= End of CMD: ========= ========= netsh int ipv4 reset ========= Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003 Resetting Interface, OK! Resetting , failed. Access is denied. Restart the computer to complete this action. ========= End of CMD: ========= ========= netsh int ipv6 reset ========= Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003 Resetting Interface, OK! Resetting Neighbor, OK! Resetting Path, OK! Resetting , failed. Access is denied. Resetting , OK! Resetting , OK! Restart the computer to complete this action. ========= End of CMD: ========= ========= bitsadmin /reset /allusers ========= BITSADMIN version 3.0 [ 7.8.10586 ] BITS administration utility. (C) Copyright 2000-2006 Microsoft Corp. BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows. Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets. {6C0D5CD2-B278-492B-8D20-9476C079AFA7} canceled. {FAE8A569-0037-4216-8A1F-85123022BEEB} canceled. 2 out of 2 jobs canceled. ========= End of CMD: ========= EmptyTemp: => 1.1 GB temporary data Removed. The system needed a reboot. ==== End of Fixlog 13:17:32 ====