Fix result of Farbar Recovery Scan Tool (x64) Version: 03-02-2021 Ran by Steve (03-02-2021 17:48:53) Run:3 Running from C:\Users\Steve\Documents\Desktop Loaded Profiles: Steve Boot Mode: Normal ============================================== fixlist content: ***************** C:\ProgramData\Malwarebytes' Anti-Malware (portable) [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0E2822AB-0447-4F28-AF4C-FFDB1E8595AE}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{226C1698-A075-4315-BB5D-9C164A96ACE7}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2446F405-83F0-460F-B837-F04540BB330C}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{332AFEBA-9341-4CEC-8EA6-DB155A99DF63}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{49F6AC60-2104-42C6-8F71-B3916D5AA732}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5709DEEB-F05E-4D5C-8DC4-3B0D924EE08F}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{59DBD1B8-A7BD-4322-998F-41B0D2516FA0}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{74630AE8-C170-4A8F-A90A-F42D63EFE1E8}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{783B187E-360F-419C-B6DA-592892764A01}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A23C190D-C714-42C7-BDBB-F4E1DE65AF27}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A82129F1-32E1-4D79-A39F-EBFEE53A70BF}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C731375E-3199-4C88-8326-9F81D3224DAD}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F5BCAC7E-75E7-4971-B3F3-B197A510F495}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FFB94DF8-FC15-411C-B443-E937085E2AC1}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\mbam.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\MBAMService.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\mbamtray.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Malwarebytes' Anti-Malware] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\MBAMService] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MbamElam] [-HKEY_USERS\.DEFAULT\Software\Malwarebytes] [-HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Office\14.0\Common\Security\Trusted Protocols\All Applications\malwarebytes:] [-HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Office\15.0\Common\Security\Trusted Protocols\All Applications\malwarebytes:] [-HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Office\16.0\Common\Security\Trusted Protocols\All Applications\malwarebytes:] [-HKEY_USERS\S-1-5-19\Software\Malwarebytes] [-HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Office\14.0\Common\Security\Trusted Protocols\All Applications\malwarebytes:] [-HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Office\15.0\Common\Security\Trusted Protocols\All Applications\malwarebytes:] [-HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Office\16.0\Common\Security\Trusted Protocols\All Applications\malwarebytes:] [-HKEY_USERS\S-1-5-20\Software\Malwarebytes] [-HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Office\14.0\Common\Security\Trusted Protocols\All Applications\malwarebytes:] [-HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Office\15.0\Common\Security\Trusted Protocols\All Applications\malwarebytes:] [-HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Office\16.0\Common\Security\Trusted Protocols\All Applications\malwarebytes:] [-HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Policies\Microsoft\Office\14.0\Common\Security\Trusted Protocols\All Applications\malwarebytes:] [-HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Policies\Microsoft\Office\15.0\Common\Security\Trusted Protocols\All Applications\malwarebytes:] [-HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Policies\Microsoft\Office\16.0\Common\Security\Trusted Protocols\All Applications\malwarebytes:] [-HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\Malwarebytes Anti-Malware] [-HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files (x86)\Malwarebytes Anti-Malware] DeleteValue:HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\7c61d98a_0| DeleteValue:HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\8d0525ca_0]| DeleteValue:HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\dcaa8608_0]| DeleteValue:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog\0462E881|AppFullPath ***************** C:\ProgramData\Malwarebytes' Anti-Malware (portable) => moved successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0E2822AB-0447-4F28-AF4C-FFDB1E8595AE} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{226C1698-A075-4315-BB5D-9C164A96ACE7} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2446F405-83F0-460F-B837-F04540BB330C} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{332AFEBA-9341-4CEC-8EA6-DB155A99DF63} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{49F6AC60-2104-42C6-8F71-B3916D5AA732} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5709DEEB-F05E-4D5C-8DC4-3B0D924EE08F} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{59DBD1B8-A7BD-4322-998F-41B0D2516FA0} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{74630AE8-C170-4A8F-A90A-F42D63EFE1E8} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{783B187E-360F-419C-B6DA-592892764A01} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A23C190D-C714-42C7-BDBB-F4E1DE65AF27} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A82129F1-32E1-4D79-A39F-EBFEE53A70BF} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C731375E-3199-4C88-8326-9F81D3224DAD} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F5BCAC7E-75E7-4971-B3F3-B197A510F495} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FFB94DF8-FC15-411C-B443-E937085E2AC1} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes => could not remove, key could be protected HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\mbam.exe => removed successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\MBAMService.exe => removed successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\mbamtray.exe => removed successfully HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Malwarebytes' Anti-Malware => removed successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\MBAMService => could not remove, key could be protected HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MbamElam => could not remove, key could be protected HKEY_USERS\.DEFAULT\Software\Malwarebytes => removed successfully HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Office\14.0\Common\Security\Trusted Protocols\All Applications\malwarebytes: => removed successfully HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Office\15.0\Common\Security\Trusted Protocols\All Applications\malwarebytes: => removed successfully HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Office\16.0\Common\Security\Trusted Protocols\All Applications\malwarebytes: => removed successfully HKEY_USERS\S-1-5-19\Software\Malwarebytes => removed successfully HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Office\14.0\Common\Security\Trusted Protocols\All Applications\malwarebytes: => removed successfully HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Office\15.0\Common\Security\Trusted Protocols\All Applications\malwarebytes: => removed successfully HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Office\16.0\Common\Security\Trusted Protocols\All Applications\malwarebytes: => removed successfully HKEY_USERS\S-1-5-20\Software\Malwarebytes => removed successfully HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Office\14.0\Common\Security\Trusted Protocols\All Applications\malwarebytes: => removed successfully HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Office\15.0\Common\Security\Trusted Protocols\All Applications\malwarebytes: => removed successfully HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Office\16.0\Common\Security\Trusted Protocols\All Applications\malwarebytes: => removed successfully HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Policies\Microsoft\Office\14.0\Common\Security\Trusted Protocols\All Applications\malwarebytes: => removed successfully HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Policies\Microsoft\Office\15.0\Common\Security\Trusted Protocols\All Applications\malwarebytes: => removed successfully HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Policies\Microsoft\Office\16.0\Common\Security\Trusted Protocols\All Applications\malwarebytes: => removed successfully HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\Malwarebytes Anti-Malware => removed successfully HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files (x86)\Malwarebytes Anti-Malware => removed successfully "HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\7c61d98a_0\\" => removed successfully "HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\8d0525ca_0\\" => removed successfully "HKEY_USERS\S-1-5-21-1097580972-3163717967-1959395198-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\dcaa8608_0\\" => removed successfully "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog\0462E881\\AppFullPath" => removed successfully Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 03-02-2021 17:51:02) Result of scheduled keys to remove after reboot: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0E2822AB-0447-4F28-AF4C-FFDB1E8595AE} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{226C1698-A075-4315-BB5D-9C164A96ACE7} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2446F405-83F0-460F-B837-F04540BB330C} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{332AFEBA-9341-4CEC-8EA6-DB155A99DF63} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{49F6AC60-2104-42C6-8F71-B3916D5AA732} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5709DEEB-F05E-4D5C-8DC4-3B0D924EE08F} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{59DBD1B8-A7BD-4322-998F-41B0D2516FA0} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{74630AE8-C170-4A8F-A90A-F42D63EFE1E8} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{783B187E-360F-419C-B6DA-592892764A01} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A23C190D-C714-42C7-BDBB-F4E1DE65AF27} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A82129F1-32E1-4D79-A39F-EBFEE53A70BF} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C731375E-3199-4C88-8326-9F81D3224DAD} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F5BCAC7E-75E7-4971-B3F3-B197A510F495} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FFB94DF8-FC15-411C-B443-E937085E2AC1} => could not remove. Access Denied. HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes => could not remove, key could be protected HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\MBAMService => could not remove, key could be protected HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MbamElam => could not remove, key could be protected ==== End of Fixlog 17:51:04 ====