Fix result of Farbar Recovery Scan Tool (x64) Version: 02-10-2021 Ran by JTug (02-10-2021 18:56:42) Run:1 Running from C:\Users\JTug\Desktop\comboF Loaded Profiles: JTug & Administrator Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: CloseProcesses: ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => -> No File ContextMenuHandlers1: [SHAREit.FileContextMenuExt] -> {430BD134-576D-4E75-87CD-0F5C6221A82B} => -> No File ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => -> No File ContextMenuHandlers4: [SHAREit.FileContextMenuExt] -> {430BD134-576D-4E75-87CD-0F5C6221A82B} => -> No File ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-223814551-1140071388-4042786358-1001 -> DefaultScope {58A62C29-8274-4A96-9D1A-261431BDBAEA} URL = SearchScopes: HKU\S-1-5-21-223814551-1140071388-4042786358-1001 -> {58A62C29-8274-4A96-9D1A-261431BDBAEA} URL = FirewallRules: [{B7C9703F-89BB-46A6-B572-1E81741F6338}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe => No File FirewallRules: [{B70742A6-3CA1-4246-8167-1B7D931296AD}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe => No File FirewallRules: [{AB73E184-BE4D-4643-8EA2-C91DD11F59FA}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoPlus.exe => No File FirewallRules: [{6095FCF1-45A4-45E2-896E-F78952F7B5EF}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe => No File FirewallRules: [{FD299C02-28F3-4529-8132-B2FE2F6B3490}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe => No File HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION S2 0161891631361214mcinstcleanup; C:\WINDOWS\TEMP\016189~1.EXE -cleanup -nolog [X] S2 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [X] S2 Lenovo System Agent Service; "C:\Program Files\Lenovo\iMController\SystemAgentService.exe" [X] S2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [X] S1 amsdk; \??\C:\WINDOWS\system32\drivers\amsdk.sys [X] 2021-10-02 15:22 - 2021-10-02 15:23 - 000153320 _____ C:\TDSSKiller.2.8.16.0_02.10.2021_15.22.43_log.txt 2021-10-02 15:22 - 2021-10-02 15:22 - 002237968 _____ (Kaspersky Lab ZAO) C:\Users\JTug\Downloads\tdsskiller.exe 2021-10-02 15:20 - 2021-10-02 15:21 - 005198336 _____ (AVAST Software) C:\Users\JTug\Downloads\aswMBR.exe 2021-10-02 10:54 - 2021-10-02 16:37 - 000000000 ____D C:\Users\JTug\AppData\Local\FSDART 2021-10-02 10:54 - 2021-10-02 12:42 - 000000000 ____D C:\ProgramData\F-Secure 2021-10-02 10:54 - 2021-10-02 10:54 - 000000000 ____D C:\Users\JTug\AppData\Local\F-Secure 2021-10-02 10:52 - 2021-10-02 10:52 - 012401864 _____ (F-Secure Corporation) C:\Users\JTug\Downloads\F-SecureOnlineScanner.exe 2021-10-02 10:50 - 2021-10-02 10:55 - 000000000 ____D C:\KVRT2020_Data 2021-10-02 10:49 - 2021-10-02 10:49 - 107072880 _____ (AO Kaspersky Lab) C:\Users\JTug\Downloads\KVRT.exe 2021-10-02 10:48 - 2021-10-02 10:48 - 003333936 _____ (Trend Micro Inc.) C:\Users\JTug\Downloads\HousecallLauncher64.exe 2021-10-02 10:48 - 2021-10-02 10:48 - 000000036 _____ C:\Users\JTug\AppData\Local\housecall.guid.cache 2021-10-02 10:34 - 2021-10-02 12:48 - 000910523 _____ C:\WINDOWS\ZAM.krnl.trace 2021-10-02 10:34 - 2021-10-02 10:34 - 000000000 ____D C:\Users\JTug\AppData\Local\Zemana 2021-10-02 10:33 - 2021-10-02 12:48 - 000000000 ____D C:\Users\JTug\AppData\Local\AMSDK 2021-10-02 10:00 - 2021-10-02 10:00 - 000000000 ____D C:\Program Files\Malwarebytes 2021-10-02 09:55 - 2021-10-02 17:32 - 000000000 ____D C:\Users\JTug\Desktop\comboF 2021-10-01 19:30 - 2021-10-01 19:30 - 000000000 ___HD C:\$AV_ASW 2021-10-01 19:26 - 2021-10-01 19:26 - 000000000 ____D C:\Users\JTug\AppData\Local\CEF 2021-10-01 19:10 - 2021-10-01 19:10 - 000000000 ____D C:\ProgramData\SProvide 2021-10-01 19:09 - 2021-10-02 16:37 - 000000000 ____D C:\ProgramData\Avast Software 2021-10-01 19:03 - 2021-10-01 19:03 - 000000108 _____ C:\Users\João 2021-10-01 19:00 - 2021-10-01 19:30 - 012134044 _____ C:\ProgramData\zohplghndapsm.tmp 2021-10-01 18:58 - 2021-10-01 18:58 - 000000000 ____D C:\ProgramData\Posse 2021-10-01 18:51 - 2021-10-01 18:51 - 000000000 ____D C:\Users\JTug\AppData\Roaming\calaba 2021-10-01 18:30 - 2021-10-01 18:44 - 000000000 ____D C:\ProgramData\Systemd 2021-10-01 18:30 - 2021-10-01 18:31 - 000000000 ____D C:\ProgramData\LKV6C095U2AXBTSQAKA51HXZH 2021-10-01 18:29 - 2021-10-01 18:29 - 000000000 ____D C:\Users\JTug\AppData\Local\Yandex 2021-10-01 18:28 - 2021-10-01 18:28 - 003265024 _____ C:\Users\JTug\AppData\Roaming\2323329.scr 2021-10-01 18:28 - 2021-10-01 18:28 - 002788864 _____ C:\Users\JTug\AppData\Roaming\2280703.scr 2021-10-01 18:28 - 2021-10-01 18:28 - 000216064 _____ (jfasdjk) C:\Users\JTug\AppData\Roaming\2366582.scr 2021-10-01 18:28 - 2021-10-01 18:28 - 000206848 _____ (jfasdjk) C:\Users\JTug\AppData\Roaming\4514659.scr 2021-10-01 18:28 - 2021-10-01 18:28 - 000068608 _____ (Hoting) C:\Users\JTug\AppData\Roaming\6999437.scr 2021-10-01 18:48 - 2017-05-31 10:48 - 000000000 ____D C:\AdwCleaner 2021-10-01 18:40 - 2018-11-06 16:01 - 000000000 ____D C:\Saft 2021-10-01 18:40 - 2018-06-13 08:09 - 000000000 ____D C:\Astor 2021-10-01 18:40 - 2017-06-19 14:35 - 000000000 ____D C:\SiLabs 2021-09-13 16:48 - 2015-06-18 19:56 - 000000000 ____D C:\Program Files\Common Files\McAfee 2021-09-12 00:19 - 2015-06-18 19:56 - 000000000 ____D C:\ProgramData\McAfee EmptyTemp: ***************** Restore point was successfully created. Processes closed successfully. HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\CLVDShellExt => removed successfully HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\SHAREit.FileContextMenuExt => removed successfully HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\CLVDShellExt => removed successfully HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\SHAREit.FileContextMenuExt => removed successfully HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully "HKU\S-1-5-21-223814551-1140071388-4042786358-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully HKU\S-1-5-21-223814551-1140071388-4042786358-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{58A62C29-8274-4A96-9D1A-261431BDBAEA} => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B7C9703F-89BB-46A6-B572-1E81741F6338}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B70742A6-3CA1-4246-8167-1B7D931296AD}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AB73E184-BE4D-4643-8EA2-C91DD11F59FA}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6095FCF1-45A4-45E2-896E-F78952F7B5EF}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FD299C02-28F3-4529-8132-B2FE2F6B3490}" => removed successfully HKLM\SOFTWARE\Policies\Mozilla => removed successfully HKLM\System\CurrentControlSet\Services\0161891631361214mcinstcleanup => removed successfully 0161891631361214mcinstcleanup => service removed successfully HKLM\System\CurrentControlSet\Services\CCSDK => removed successfully CCSDK => service removed successfully HKLM\System\CurrentControlSet\Services\Lenovo System Agent Service => removed successfully Lenovo System Agent Service => service removed successfully HKLM\System\CurrentControlSet\Services\LUService => removed successfully LUService => service removed successfully HKLM\System\CurrentControlSet\Services\amsdk => removed successfully amsdk => service removed successfully C:\TDSSKiller.2.8.16.0_02.10.2021_15.22.43_log.txt => moved successfully "C:\Users\JTug\Downloads\tdsskiller.exe" => not found "C:\Users\JTug\Downloads\aswMBR.exe" => not found "C:\Users\JTug\AppData\Local\FSDART" => not found C:\ProgramData\F-Secure => moved successfully "C:\Users\JTug\AppData\Local\F-Secure" => not found "C:\Users\JTug\Downloads\F-SecureOnlineScanner.exe" => not found C:\KVRT2020_Data => moved successfully "C:\Users\JTug\Downloads\KVRT.exe" => not found "C:\Users\JTug\Downloads\HousecallLauncher64.exe" => not found "C:\Users\JTug\AppData\Local\housecall.guid.cache" => not found C:\WINDOWS\ZAM.krnl.trace => moved successfully "C:\Users\JTug\AppData\Local\Zemana" => not found "C:\Users\JTug\AppData\Local\AMSDK" => not found C:\Program Files\Malwarebytes => moved successfully "C:\Users\JTug\Desktop\comboF" => not found C:\$AV_ASW => moved successfully "C:\Users\JTug\AppData\Local\CEF" => not found C:\ProgramData\SProvide => moved successfully C:\ProgramData\Avast Software => moved successfully C:\Users\João => moved successfully C:\ProgramData\zohplghndapsm.tmp => moved successfully C:\ProgramData\Posse => moved successfully "C:\Users\JTug\AppData\Roaming\calaba" => not found C:\ProgramData\Systemd => moved successfully C:\ProgramData\LKV6C095U2AXBTSQAKA51HXZH => moved successfully "C:\Users\JTug\AppData\Local\Yandex" => not found "C:\Users\JTug\AppData\Roaming\2323329.scr" => not found "C:\Users\JTug\AppData\Roaming\2280703.scr" => not found "C:\Users\JTug\AppData\Roaming\2366582.scr" => not found "C:\Users\JTug\AppData\Roaming\4514659.scr" => not found "C:\Users\JTug\AppData\Roaming\6999437.scr" => not found C:\AdwCleaner => moved successfully C:\Saft => moved successfully C:\Astor => moved successfully C:\SiLabs => moved successfully C:\Program Files\Common Files\McAfee => moved successfully C:\ProgramData\McAfee => moved successfully =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 13707793 B Java, Flash, Steam htmlcache => 343 B Windows/system/drivers => 391173 B Edge => 0 B Firefox => 12998852 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B systemprofile => 128 B systemprofile32 => 3716 B LocalService => 13988 B NetworkService => 13988 B JTug => 85066195 B Administrator => 632187964 B RecycleBin => 0 B EmptyTemp: => 717.9 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 18:58:30 ====