Fix result of Farbar Recovery Scan Tool (x64) Version: 23-10-2022 Ran by Wade (26-10-2022 10:10:16) Run:1 Running from C:\Users\Wade\OneDrive\Desktop Loaded Profiles: Wade Boot Mode: Normal ============================================== fixlist content: ***************** Start:: CreateRestorePoint: CloseProcesses: AS: Bitdefender Antispyware (Enabled - Up to date) {B5763A99-8435-6D40-83EB-2CA97758A9A5} SearchScopes: HKU\S-1-5-21-612249682-4202380856-1698065691-1001 -> DefaultScope {19DD036C-D3F6-4E92-AC6C-D795D806EB14} URL = SearchScopes: HKU\S-1-5-21-612249682-4202380856-1698065691-1001 -> {19DD036C-D3F6-4E92-AC6C-D795D806EB14} URL = FirewallRules: [{5BA8CB5E-4132-4080-B074-4B78E3C20397}] => (Allow) C:\Users\Wade\AppData\Roaming\Zoom\bin\airhost.exe => No File FirewallRules: [{848401B9-05EC-4783-93AB-BA4E6A8E71F0}] => (Allow) C:\Users\Wade\AppData\Roaming\Zoom\bin\Zoom.exe => No File HKLM\...\Run: [] => [X] HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-612249682-4202380856-1698065691-1001\...\Run: [] => [X] Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found] Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found] Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found] Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found] CHR DefaultSearchURL: Default -> hxxps://www.bing.com/search?q={searchTerms}&PC=U316&FORM=CHROMN CHR DefaultSearchKeyword: Default -> bing.com CHR DefaultNewTabURL: Default -> hxxps://www.bing.com/chrome/newtab CHR DefaultSuggestURL: Default -> hxxps://www.bing.com/osjson.aspx?query={searchTerms}&language={language}&PC=U316 R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [209088 2022-09-27] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [199312 2022-09-27] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [46704 2022-09-27] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R1 webshieldfilter; C:\WINDOWS\System32\drivers\webshieldfilter.sys [96264 2022-09-27] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) <==== ATTENTION 2022-10-15 10:18 - 2022-09-27 05:42 - 000209088 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 2022-10-15 10:18 - 2022-09-27 05:42 - 000199312 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 2022-10-15 10:18 - 2022-09-27 05:42 - 000046704 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys 2022-10-14 04:52 - 2022-10-14 04:52 - 000000000 ____D C:\ProgramData\TotalAV 2022-10-14 04:52 - 2022-10-14 04:52 - 000000000 ____D C:\ProgramData\SecuritySuite 2022-10-14 04:52 - 2022-09-27 05:42 - 000096264 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\webshieldfilter.sys EmptyTemp: End:: ***************** Restore point was successfully created. Processes closed successfully. "AS: Bitdefender Antispyware (Enabled - Up to date) {B5763A99-8435-6D40-83EB-2CA97758A9A5}" => removed successfully "HKU\S-1-5-21-612249682-4202380856-1698065691-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully HKU\S-1-5-21-612249682-4202380856-1698065691-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{19DD036C-D3F6-4E92-AC6C-D795D806EB14} => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5BA8CB5E-4132-4080-B074-4B78E3C20397}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{848401B9-05EC-4783-93AB-BA4E6A8E71F0}" => removed successfully "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully "HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully "HKU\S-1-5-21-612249682-4202380856-1698065691-1001\Software\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => removed successfully HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => removed successfully HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => removed successfully HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => removed successfully "Chrome DefaultSearchURL" => removed successfully "Chrome DefaultSearchKeyword" => removed successfully "Chrome DefaultNewTabURL" => removed successfully "Chrome DefaultSuggestURL" => removed successfully avgntflt => Unable to stop service. HKLM\System\CurrentControlSet\Services\avgntflt => removed successfully avgntflt => service removed successfully avipbb => Service stopped successfully. HKLM\System\CurrentControlSet\Services\avipbb => removed successfully avipbb => service removed successfully avkmgr => Unable to stop service. HKLM\System\CurrentControlSet\Services\avkmgr => removed successfully avkmgr => service removed successfully webshieldfilter => service not found. C:\WINDOWS\system32\Drivers\avgntflt.sys => moved successfully C:\WINDOWS\system32\Drivers\avipbb.sys => moved successfully C:\WINDOWS\system32\Drivers\avkmgr.sys => moved successfully "C:\ProgramData\TotalAV" => not found "C:\ProgramData\SecuritySuite" => not found "C:\WINDOWS\system32\Drivers\webshieldfilter.sys" => not found =========== EmptyTemp: ========== FlushDNS => completed BITS transfer queue => 0 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12859256 B Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B Windows/system/drivers => 342628677 B Edge => 1183132 B Chrome => 648809426 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 26872 B NetworkService => 1172790 B Wade => 3246689 B defaultuser1 => 3253857 B RecycleBin => 31865584 B EmptyTemp: => 996.6 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 10:12:04 ====