Fix result of Farbar Recovery Scan Tool (x64) Version: 11-11-2017 Ran by JohnDoe (11-11-2017 16:26:16) Run:2 Running from C:\Users\JohnDoe\Desktop Loaded Profiles: JohnDoe & DefaultAppPool (Available Profiles: JohnDoe & Visitor & DefaultAppPool) Boot Mode: Normal ============================================== fixlist content: ***************** HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-2118853541-1488753588-3094647493-1000\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.) HKU\S-1-5-21-2118853541-1488753588-3094647493-1000\...\Policies\Explorer: [] BootExecute: autocheck autochk * sdnclean64.exe GroupPolicy: Restriction <==== ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO-x32: No Name -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> No File FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> backup.ftp", "118.97.30.165" FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> backup.ftp_port", 80 FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> backup.socks", "118.97.30.165" FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> backup.socks_port", 80 FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> backup.ssl", "118.97.30.165" FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> backup.ssl_port", 80 FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> ftp", "140.0.237.238 " FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> ftp_port", 8080 FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> http", "140.0.237.238 " FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> http_port", 8080 FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> share_proxy_settings", true FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> socks", "140.0.237.238 " FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> socks_port", 8080 FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> ssl", "140.0.237.238 " FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> ssl_port", 8080 FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> type", 0 CHR Extension: (Click&Clean App) - C:\Users\JohnDoe\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2017-05-20] CHR Extension: (Facebook - Delete All Messages) - C:\Users\JohnDoe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hgiidlnejdlfoacoeleopkljhbckmlko [2017-10-29] CHR Extension: (Social Fixer for Facebook) - C:\Users\JohnDoe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb [2017-10-03] CHR Extension: (InstaG Downloader) - C:\Users\JohnDoe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jnkdcmgmnegofdddphijckfagibepdlb [2017-10-28] S4 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe" [X] R1 epp; C:\EEK\bin64\epp.sys [124552 2016-11-23] (Emsisoft Ltd) S3 Hamachi; C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [45680 2017-02-02] (LogMeIn Inc.) U3 idsvc; no ImagePath S3 VBAudioVACMME; \SystemRoot\system32\DRIVERS\vbaudio_cable64_win7.sys [X] S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X] U3 wpcsvc; no ImagePath C:\Program Files (x86)\Spybot - Search & Destroy 2 C:\ProgramData\Spybot - Search & Destroy CustomCLSID: HKU\S-1-5-21-2118853541-1488753588-3094647493-1000_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe /Automation => No File CustomCLSID: HKU\S-1-5-21-2118853541-1488753588-3094647493-1000_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe => No File CustomCLSID: HKU\S-1-5-21-2118853541-1488753588-3094647493-1000_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe /Automation => No File CustomCLSID: HKU\S-1-5-21-2118853541-1488753588-3094647493-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\en-US\acadficn.dll => No File Task: {043ABB39-7149-431C-A81F-172B310A7E73} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {085F6E7A-CABE-4D03-9AB3-09E55B9851C8} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {09221FF3-7AD7-43E6-9C8D-B9F821CEF5CA} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {0BFD8BCD-46B0-4EB2-B2D7-BAA9ABB9FAB1} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {10CFAE02-CE22-4E4C-A05C-54C4BE819A62} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {1B67756E-0F48-496B-BD07-C5067FA20EED} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {215932AA-6835-474A-BA4A-9185B7E70C4D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {2829A8E2-D3C5-4129-87E7-A61C3F0BCDF5} - System32\Tasks\Private Internet Access Startup => C:\Program Files\pia_manager\pia_manager.exe [2017-01-08] () Task: {2C1386B3-1B50-45CE-B67D-ABF510EF1268} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {390B6383-B0BA-4532-BB92-8A8CCD706D21} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {3CADE8BA-3376-4CC5-9129-DF20CEC9386A} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {3E83079D-5816-44DD-A1C5-035CBA2D8701} - System32\Tasks\{264AA82E-0D9F-491F-8F75-6AC88379EC64} => C:\Windows\system32\pcalua.exe -a C:\facetalk\vcredist_x86.exe -d C:\facetalk Task: {4824F5C2-CFF1-489B-9DD8-50867EF00A08} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {4DF66FDD-56D1-4CC0-82FD-C23A43BC9FD1} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe Task: {70BD27CD-43BC-4D7D-8CC0-A37C7DD5B5DE} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {7D8FACD2-560D-4F3F-849C-CE58FA6D8286} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {821FBBD1-F4F0-4D14-A496-C67DF82DDB40} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {82F255A8-9083-4D50-908F-6AE669801AAA} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe Task: {87FFBA8A-5C6C-40B3-8776-B7F4FFDBC42F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {88451E32-5273-48C4-84C3-5EC634EF6E74} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe Task: {8F42BC07-C2E6-4884-92D1-D62E0DCE1B98} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {8F4C3A2F-D807-437E-BAA4-10DF9721ED47} - \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync -> No File <==== ATTENTION Task: {9FF2A908-33EA-42DE-BFA0-940693DF7D25} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2118853541-1488753588-3094647493-1000Core => C:\Users\JohnDoe\AppData\Local\Google\Update\GoogleUpdate.exe Task: {A7B20046-C633-4354-A90C-5793CDC2F226} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {C66F61DB-B81C-4BBB-84E5-699CFC921128} - System32\Tasks\{0712CEE4-6F21-4497-83F5-42D74A7817AB} => C:\Windows\system32\pcalua.exe -a C:\Users\JohnDoe\Downloads\forge-1.8-11.14.1.1375-installer-win.exe -d C:\Users\JohnDoe\Downloads Task: {CCC7FE22-3409-4283-8E0D-C7015B12984F} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {D72F551A-6A6F-4425-8B05-DA317BC197FB} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {EAC73821-25D2-4693-83E1-F0CED2F7181F} - System32\Tasks\{62DE4789-40F7-454A-88EC-924C65C24006} => C:\Windows\system32\pcalua.exe -a C:\Users\JohnDoe\Desktop\oculus\Perception\Perception\bin\VireioDLLInstaller.exe -d C:\Users\JohnDoe\Desktop\oculus\Perception\Perception\bin Task: {043ABB39-7149-431C-A81F-172B310A7E73} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {085F6E7A-CABE-4D03-9AB3-09E55B9851C8} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {09221FF3-7AD7-43E6-9C8D-B9F821CEF5CA} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {0BFD8BCD-46B0-4EB2-B2D7-BAA9ABB9FAB1} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {10CFAE02-CE22-4E4C-A05C-54C4BE819A62} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {1B67756E-0F48-496B-BD07-C5067FA20EED} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {215932AA-6835-474A-BA4A-9185B7E70C4D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {2829A8E2-D3C5-4129-87E7-A61C3F0BCDF5} - System32\Tasks\Private Internet Access Startup => C:\Program Files\pia_manager\pia_manager.exe [2017-01-08] () Task: {2C1386B3-1B50-45CE-B67D-ABF510EF1268} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {390B6383-B0BA-4532-BB92-8A8CCD706D21} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {3CADE8BA-3376-4CC5-9129-DF20CEC9386A} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {3F6E048D-6404-433B-8F5F-CFF4D89BF89E} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => %windir%\system32\rundll32.exe generaltel.dll,RunTelemetryW Task: {4824F5C2-CFF1-489B-9DD8-50867EF00A08} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {4DF66FDD-56D1-4CC0-82FD-C23A43BC9FD1} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe Task: {70BD27CD-43BC-4D7D-8CC0-A37C7DD5B5DE} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {7D8FACD2-560D-4F3F-849C-CE58FA6D8286} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {821FBBD1-F4F0-4D14-A496-C67DF82DDB40} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {82F255A8-9083-4D50-908F-6AE669801AAA} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe Task: {87FFBA8A-5C6C-40B3-8776-B7F4FFDBC42F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {88451E32-5273-48C4-84C3-5EC634EF6E74} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe Task: {8F42BC07-C2E6-4884-92D1-D62E0DCE1B98} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {8F4C3A2F-D807-437E-BAA4-10DF9721ED47} - \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync -> No File <==== ATTENTION Task: {9FF2A908-33EA-42DE-BFA0-940693DF7D25} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2118853541-1488753588-3094647493-1000Core => C:\Users\JohnDoe\AppData\Local\Google\Update\GoogleUpdate.exe Task: {A7B20046-C633-4354-A90C-5793CDC2F226} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {C66F61DB-B81C-4BBB-84E5-699CFC921128} - System32\Tasks\{0712CEE4-6F21-4497-83F5-42D74A7817AB} => C:\Windows\system32\pcalua.exe -a C:\Users\JohnDoe\Downloads\forge-1.8-11.14.1.1375-installer-win.exe -d C:\Users\JohnDoe\Downloads Task: {CCC7FE22-3409-4283-8E0D-C7015B12984F} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {D72F551A-6A6F-4425-8B05-DA317BC197FB} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {EAC73821-25D2-4693-83E1-F0CED2F7181F} - System32\Tasks\{62DE4789-40F7-454A-88EC-924C65C24006} => C:\Windows\system32\pcalua.exe -a C:\Users\JohnDoe\Desktop\oculus\Perception\Perception\bin\VireioDLLInstaller.exe -d C:\Users\JohnDoe\Desktop\oculus\Perception\Perception\bin Task: {F8BEDA55-0D01-4DB6-8C7A-62977D00839B} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe C:\Program Files\pia_manager AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0] AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm [0] AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0] MSCONFIG\Services: !SASCORE => 2 MSCONFIG\Services: Hamachi2Svc => 2 MSCONFIG\Services: LMIGuardianSvc => 2 MSCONFIG\Services: SDScannerService => 2 MSCONFIG\Services: SDUpdateService => 2 MSCONFIG\Services: SDWSCService => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^JohnDoe^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk => C:\Windows\pss\MagicDisc.lnk.Startup MSCONFIG\startupreg: AVG-Secure-Search-Update_0214c => C:\Users\JohnDoe\AppData\Roaming\AVG 0214c Campaign\AVG-Secure-Search-Update-0214c.exe /PROMPT /mid=012d7d48095647d39ae281ac0f58262d-70393698b68259567fe90401a4c13bae881e40dd /CMPID=0214c MSCONFIG\startupreg: AVG-Secure-Search-Update_1113a => C:\Users\JohnDoe\AppData\Roaming\AVG 1113a Campaign\AVG-Secure-Search-Update-1113a.exe /PROMPT /mid=012d7d48095647d39ae281ac0f58262d-70393698b68259567fe90401a4c13bae881e40dd /CMPID=1113a MSCONFIG\startupreg: AVG_UI => "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" MSCONFIG\startupreg: Spybot-S&D Cleaning => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean MSCONFIG\startupreg: SpybotPostWindows10UpgradeReInstall => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe" MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKLM\...\StartupApproved\Run32: => "SDTray" HKU\S-1-5-21-2118853541-1488753588-3094647493-1000\...\StartupApproved\Run: => "SpybotPostWindows10UpgradeReInstall" CMD: for /F "tokens=*" %1 in ('wevtutil.exe el') DO wevtutil.exe cl "%1" Hosts: EMPTY TEMP: CMD: bitsadmin /Reset ***************** HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => key removed successfully HKU\S-1-5-21-2118853541-1488753588-3094647493-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SpybotPostWindows10UpgradeReInstall => value removed successfully HKU\S-1-5-21-2118853541-1488753588-3094647493-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => value removed successfully HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => value restored successfully C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully HKLM\SOFTWARE\Policies\Google => key removed successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Local Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Local Page => value restored successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} => key removed successfully HKLM\Software\Classes\CLSID\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} => key not found. HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B69F34DD-F0F9-42DC-9EDD-957187DA688D} => key removed successfully HKLM\Software\Wow6432Node\Classes\CLSID\{B69F34DD-F0F9-42DC-9EDD-957187DA688D} => key not found. Firefox Proxy settings were reset. FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> backup.ftp_port", 80 => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> backup.socks", "118.97.30.165" => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> backup.socks_port", 80 => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> backup.ssl", "118.97.30.165" => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> backup.ssl_port", 80 => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> ftp", "140.0.237.238 " => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> ftp_port", 8080 => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> http", "140.0.237.238 " => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> http_port", 8080 => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> share_proxy_settings", true => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> socks", "140.0.237.238 " => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> socks_port", 8080 => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> ssl", "140.0.237.238 " => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> ssl_port", 8080 => not found FF NetworkProxy: Mozilla\Firefox\Profiles\88xq2klu.default -> type", 0 => not found CHR Extension: (Click&Clean App) - C:\Users\JohnDoe\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2017-05-20] => Error: No automatic fix found for this entry. CHR Extension: (Facebook - Delete All Messages) - C:\Users\JohnDoe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hgiidlnejdlfoacoeleopkljhbckmlko [2017-10-29] => Error: No automatic fix found for this entry. CHR Extension: (Social Fixer for Facebook) - C:\Users\JohnDoe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb [2017-10-03] => Error: No automatic fix found for this entry. CHR Extension: (InstaG Downloader) - C:\Users\JohnDoe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jnkdcmgmnegofdddphijckfagibepdlb [2017-10-28] => Error: No automatic fix found for this entry. HKLM\System\CurrentControlSet\Services\LMIGuardianSvc => key removed successfully LMIGuardianSvc => service removed successfully epp => Unable to stop service. HKLM\System\CurrentControlSet\Services\epp => key removed successfully epp => service removed successfully HKLM\System\CurrentControlSet\Services\Hamachi => key removed successfully Hamachi => service removed successfully HKLM\System\CurrentControlSet\Services\idsvc => key removed successfully idsvc => service removed successfully HKLM\System\CurrentControlSet\Services\VBAudioVACMME => key removed successfully VBAudioVACMME => service removed successfully HKLM\System\CurrentControlSet\Services\wfpcapture => key removed successfully wfpcapture => service removed successfully HKLM\System\CurrentControlSet\Services\wpcsvc => key removed successfully wpcsvc => service removed successfully C:\Program Files (x86)\Spybot - Search & Destroy 2 => moved successfully C:\ProgramData\Spybot - Search & Destroy => moved successfully HKU\S-1-5-21-2118853541-1488753588-3094647493-1000_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6} => key removed successfully HKU\S-1-5-21-2118853541-1488753588-3094647493-1000_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98} => key removed successfully HKU\S-1-5-21-2118853541-1488753588-3094647493-1000_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D} => key removed successfully HKU\S-1-5-21-2118853541-1488753588-3094647493-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{043ABB39-7149-431C-A81F-172B310A7E73} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{043ABB39-7149-431C-A81F-172B310A7E73} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ConfigureInternetTimeService => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{085F6E7A-CABE-4D03-9AB3-09E55B9851C8} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{085F6E7A-CABE-4D03-9AB3-09E55B9851C8} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW1 => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{09221FF3-7AD7-43E6-9C8D-B9F821CEF5CA} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09221FF3-7AD7-43E6-9C8D-B9F821CEF5CA} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURActivate => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0BFD8BCD-46B0-4EB2-B2D7-BAA9ABB9FAB1} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0BFD8BCD-46B0-4EB2-B2D7-BAA9ABB9FAB1} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\InstallPlayReady => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{10CFAE02-CE22-4E4C-A05C-54C4BE819A62} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{10CFAE02-CE22-4E4C-A05C-54C4BE819A62} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ReindexSearchRoot => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1B67756E-0F48-496B-BD07-C5067FA20EED} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B67756E-0F48-496B-BD07-C5067FA20EED} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RegisterSearch => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{215932AA-6835-474A-BA4A-9185B7E70C4D} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{215932AA-6835-474A-BA4A-9185B7E70C4D} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscovery => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2829A8E2-D3C5-4129-87E7-A61C3F0BCDF5} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2829A8E2-D3C5-4129-87E7-A61C3F0BCDF5} => key removed successfully C:\WINDOWS\System32\Tasks\Private Internet Access Startup => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Private Internet Access Startup => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2C1386B3-1B50-45CE-B67D-ABF510EF1268} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2C1386B3-1B50-45CE-B67D-ABF510EF1268} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\mcupdate => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{390B6383-B0BA-4532-BB92-8A8CCD706D21} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{390B6383-B0BA-4532-BB92-8A8CCD706D21} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrRecoveryTask => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3CADE8BA-3376-4CC5-9129-DF20CEC9386A} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3CADE8BA-3376-4CC5-9129-DF20CEC9386A} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PeriodicScanRetry => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3E83079D-5816-44DD-A1C5-035CBA2D8701} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E83079D-5816-44DD-A1C5-035CBA2D8701} => key removed successfully C:\WINDOWS\System32\Tasks\{264AA82E-0D9F-491F-8F75-6AC88379EC64} => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{264AA82E-0D9F-491F-8F75-6AC88379EC64} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4824F5C2-CFF1-489B-9DD8-50867EF00A08} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4824F5C2-CFF1-489B-9DD8-50867EF00A08} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4DF66FDD-56D1-4CC0-82FD-C23A43BC9FD1} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4DF66FDD-56D1-4CC0-82FD-C23A43BC9FD1} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate_scheduled => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{70BD27CD-43BC-4D7D-8CC0-A37C7DD5B5DE} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70BD27CD-43BC-4D7D-8CC0-A37C7DD5B5DE} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ActivateWindowsSearch => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7D8FACD2-560D-4F3F-849C-CE58FA6D8286} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D8FACD2-560D-4F3F-849C-CE58FA6D8286} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrScheduleTask => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{821FBBD1-F4F0-4D14-A496-C67DF82DDB40} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{821FBBD1-F4F0-4D14-A496-C67DF82DDB40} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW2 => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{82F255A8-9083-4D50-908F-6AE669801AAA} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82F255A8-9083-4D50-908F-6AE669801AAA} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\UpdateRecordPath => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{87FFBA8A-5C6C-40B3-8776-B7F4FFDBC42F} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87FFBA8A-5C6C-40B3-8776-B7F4FFDBC42F} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RecordingRestart => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{88451E32-5273-48C4-84C3-5EC634EF6E74} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88451E32-5273-48C4-84C3-5EC634EF6E74} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\StartRecording => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\StartRecording => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8F42BC07-C2E6-4884-92D1-D62E0DCE1B98} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8F42BC07-C2E6-4884-92D1-D62E0DCE1B98} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8F4C3A2F-D807-437E-BAA4-10DF9721ED47} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8F4C3A2F-D807-437E-BAA4-10DF9721ED47} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\File Classification Infrastructure\Property Definition Sync => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9FF2A908-33EA-42DE-BFA0-940693DF7D25} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9FF2A908-33EA-42DE-BFA0-940693DF7D25} => key removed successfully C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2118853541-1488753588-3094647493-1000Core => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-2118853541-1488753588-3094647493-1000Core => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A7B20046-C633-4354-A90C-5793CDC2F226} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7B20046-C633-4354-A90C-5793CDC2F226} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ehDRMInit => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C66F61DB-B81C-4BBB-84E5-699CFC921128} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C66F61DB-B81C-4BBB-84E5-699CFC921128} => key removed successfully C:\WINDOWS\System32\Tasks\{0712CEE4-6F21-4497-83F5-42D74A7817AB} => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0712CEE4-6F21-4497-83F5-42D74A7817AB} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CCC7FE22-3409-4283-8E0D-C7015B12984F} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CCC7FE22-3409-4283-8E0D-C7015B12984F} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D72F551A-6A6F-4425-8B05-DA317BC197FB} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D72F551A-6A6F-4425-8B05-DA317BC197FB} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURDiscovery => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EAC73821-25D2-4693-83E1-F0CED2F7181F} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EAC73821-25D2-4693-83E1-F0CED2F7181F} => key removed successfully C:\WINDOWS\System32\Tasks\{62DE4789-40F7-454A-88EC-924C65C24006} => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{62DE4789-40F7-454A-88EC-924C65C24006} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{043ABB39-7149-431C-A81F-172B310A7E73} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ConfigureInternetTimeService => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{085F6E7A-CABE-4D03-9AB3-09E55B9851C8} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW1 => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09221FF3-7AD7-43E6-9C8D-B9F821CEF5CA} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURActivate => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0BFD8BCD-46B0-4EB2-B2D7-BAA9ABB9FAB1} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\InstallPlayReady => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{10CFAE02-CE22-4E4C-A05C-54C4BE819A62} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ReindexSearchRoot => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B67756E-0F48-496B-BD07-C5067FA20EED} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RegisterSearch => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{215932AA-6835-474A-BA4A-9185B7E70C4D} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscovery => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2829A8E2-D3C5-4129-87E7-A61C3F0BCDF5} => key not found. C:\WINDOWS\System32\Tasks\Private Internet Access Startup => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Private Internet Access Startup => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2C1386B3-1B50-45CE-B67D-ABF510EF1268} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\mcupdate => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{390B6383-B0BA-4532-BB92-8A8CCD706D21} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrRecoveryTask => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3CADE8BA-3376-4CC5-9129-DF20CEC9386A} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PeriodicScanRetry => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3F6E048D-6404-433B-8F5F-CFF4D89BF89E} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3F6E048D-6404-433B-8F5F-CFF4D89BF89E} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4824F5C2-CFF1-489B-9DD8-50867EF00A08} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4DF66FDD-56D1-4CC0-82FD-C23A43BC9FD1} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate_scheduled => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70BD27CD-43BC-4D7D-8CC0-A37C7DD5B5DE} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ActivateWindowsSearch => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D8FACD2-560D-4F3F-849C-CE58FA6D8286} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrScheduleTask => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{821FBBD1-F4F0-4D14-A496-C67DF82DDB40} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW2 => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82F255A8-9083-4D50-908F-6AE669801AAA} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\UpdateRecordPath => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87FFBA8A-5C6C-40B3-8776-B7F4FFDBC42F} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RecordingRestart => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88451E32-5273-48C4-84C3-5EC634EF6E74} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\StartRecording => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\StartRecording => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8F42BC07-C2E6-4884-92D1-D62E0DCE1B98} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8F4C3A2F-D807-437E-BAA4-10DF9721ED47} => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\File Classification Infrastructure\Property Definition Sync => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9FF2A908-33EA-42DE-BFA0-940693DF7D25} => key not found. C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2118853541-1488753588-3094647493-1000Core => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-2118853541-1488753588-3094647493-1000Core => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7B20046-C633-4354-A90C-5793CDC2F226} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ehDRMInit => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C66F61DB-B81C-4BBB-84E5-699CFC921128} => key not found. C:\WINDOWS\System32\Tasks\{0712CEE4-6F21-4497-83F5-42D74A7817AB} => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0712CEE4-6F21-4497-83F5-42D74A7817AB} => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CCC7FE22-3409-4283-8E0D-C7015B12984F} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D72F551A-6A6F-4425-8B05-DA317BC197FB} => key not found. C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURDiscovery => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EAC73821-25D2-4693-83E1-F0CED2F7181F} => key not found. C:\WINDOWS\System32\Tasks\{62DE4789-40F7-454A-88EC-924C65C24006} => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{62DE4789-40F7-454A-88EC-924C65C24006} => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F8BEDA55-0D01-4DB6-8C7A-62977D00839B} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8BEDA55-0D01-4DB6-8C7A-62977D00839B} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\DispatchRecoveryTasks => key removed successfully C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => moved successfully "C:\Program Files\pia_manager" folder move: Could not move "C:\Program Files\pia_manager" => Scheduled to move on reboot. C:\ProgramData\Reprise => ":wupeogjxlctlfudivq`qsp`28hfm" ADS removed successfully. C:\ProgramData\Reprise => ":wupeogjxldtlfudivq`qsp`26hfm" ADS removed successfully. C:\ProgramData\Reprise => ":wupeogjxldtlfudivq`qsp`27hfm" ADS removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\!SASCORE => key removed successfully HKLM\System\CurrentControlSet\Services\!SASCORE => key not found. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Hamachi2Svc => key removed successfully HKLM\System\CurrentControlSet\Services\Hamachi2Svc => key not found. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\LMIGuardianSvc => key removed successfully HKLM\System\CurrentControlSet\Services\LMIGuardianSvc => key not found. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\SDScannerService => key removed successfully HKLM\System\CurrentControlSet\Services\SDScannerService => key not found. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\SDUpdateService => key removed successfully HKLM\System\CurrentControlSet\Services\SDUpdateService => key not found. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\SDWSCService => key removed successfully HKLM\System\CurrentControlSet\Services\SDWSCService => key not found. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => key removed successfully C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup => moved successfully HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^JohnDoe^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk => key removed successfully C:\Windows\pss\MagicDisc.lnk.Startup => moved successfully HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AVG-Secure-Search-Update_0214c => key removed successfully HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AVG-Secure-Search-Update_1113a => key removed successfully HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AVG_UI => key removed successfully HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SDTray => key removed successfully HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spybot-S&D Cleaning => key removed successfully HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SpybotPostWindows10UpgradeReInstall => key removed successfully HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched => key removed successfully HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\LogMeIn Hamachi Ui => value removed successfully HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\LogMeIn Hamachi Ui => value not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\SDTray => value removed successfully HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SDTray => value not found. HKU\S-1-5-21-2118853541-1488753588-3094647493-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\SpybotPostWindows10UpgradeReInstall => value removed successfully HKU\S-1-5-21-2118853541-1488753588-3094647493-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SpybotPostWindows10UpgradeReInstall => value not found. ========= for /F "tokens=*" %1 in ('wevtutil.exe el') DO wevtutil.exe cl "%1" ========= Failed to clear log Microsoft-Windows-LiveId/Analytic. Access is denied. Failed to clear log Microsoft-Windows-LiveId/Operational. Access is denied. Failed to clear log Microsoft-Windows-USBVideo/Analytic. The instance name passed was not recognized as valid by a WMI data provider. ========= End of CMD: ========= C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. ========= bitsadmin /Reset ========= BITSADMIN version 3.0 [ 7.8.10240 ] BITS administration utility. (C) Copyright 2000-2006 Microsoft Corp. BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows. Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets. 0 out of 0 jobs canceled. ========= End of CMD: ========= =========== EmptyTemp: ========== BITS transfer queue => 32768 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 23171123 B Java, Flash, Steam htmlcache => 757291232 B Windows/system/drivers => 14410306 B Edge => 981667 B Chrome => 614584805 B Firefox => 130138005 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 1536 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 128 B LocalService => 2509272 B NetworkService => 0 B JohnDoe => 126911941 B Visitor => 10373772 B DefaultAppPool => 1536 B RecycleBin => 79373 B EmptyTemp: => 1.6 GB temporary data Removed. ================================ Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 11-11-2017 16:31:54) C:\Program Files\pia_manager => Is moved successfully ==== End of Fixlog 16:31:54 ====