Fix result of Farbar Recovery Scan Tool (x64) Version: 08-05-2023 Ran by Maffu (08-05-2023 18:54:49) Run:1 Running from C:\Users\Maffu\Desktop Loaded Profiles: Maffu Boot Mode: Normal ============================================== fixlist content: ***************** Start:: CreateRestorePoint: CloseProcesses: CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{321F46A6-D8F8-4C44-ADD0-AF926E3606A9}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{3E888169-3C1E-43AA-BB32-87F6E985A44E}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{4279CFB2-D26D-4340-86E7-E7C7AF79F081}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{66C7C6A4-92CB-4203-944E-4A3F4323F497}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{77953D65-F265-485F-B67D-A34DE8045BFC}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{90489ADC-89AF-4E4D-9ED1-BB6B32C31E65}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{922D9A3B-8481-460C-9B73-5710AEB8423D}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{9324F009-C35E-4D14-9D20-0CE8A2A3E330}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{981637F7-4585-4D55-B365-A5C5B82F4CEB}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{C4B4627E-9496-4AD1-AC60-EFD2EB437A79}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{C8120E54-622E-4452-9974-87AC65D79CB6}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{CAEF3289-33A4-4931-AEC5-A610BEAA6AB0}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{D26F8E90-55B7-4753-9D33-F32FF52FF920}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{DEF990D9-9913-4AF0-9B4B-8D9F294F122E}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{DEFF582C-FF7C-4D00-8AE5-0E9EBC978C7F}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{F6764025-F2CA-4914-95BC-0F2F52FD9946}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File CustomCLSID: HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{FCF17890-E5E6-46CF-872C-75712AC0429B}\InprocServer32 -> C:\Users\Maffu\AppData\Local\VidyoConnect\VidyoNeoRDO64.dll => No File HKLM\...\.scr: SageThumbsImage.scr => "%1" /S <==== ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = DPF: HKLM {583C990C-2D38-410c-9A4A-0932D66A754F} hxxps://pulsesecure.net/dana-cached/sc/PulseSetupClient64.cab DPF: HKLM-x32 {8E375A63-C616-46F1-AC77-59DF78F3A826} hxxps://pulsesecure.net/dana-cached/sc/PulseSetupClient.cab Handler: AutorunsDisabled - {314111c7-a502-11d2-bbca-00c04f8ec294} - No File Handler: AutorunsDisabled - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - No File FirewallRules: [TCP Query User{DE3CB516-D806-462C-920E-3E8017277430}C:\users\maffu\appdata\local\vidyoconnect\vidyoconnect.exe] => (Allow) C:\users\maffu\appdata\local\vidyoconnect\vidyoconnect.exe => No File FirewallRules: [UDP Query User{BECAED13-B4C4-4F83-A13B-ECBAB0601FD9}C:\users\maffu\appdata\local\vidyoconnect\vidyoconnect.exe] => (Allow) C:\users\maffu\appdata\local\vidyoconnect\vidyoconnect.exe => No File FirewallRules: [{21A6A617-274E-416E-A997-6FBA654F9CE4}] => (Allow) E:\Games\Steamer\steamapps\common\Kerbal Space Program\KSP_x64.exe => No File FirewallRules: [{675589D1-FF6D-48BA-BB2F-AC069FFF2AD9}] => (Allow) E:\Games\Steamer\steamapps\common\Kerbal Space Program\KSP_x64.exe => No File FirewallRules: [{348BB91E-DDEA-428C-B2FD-570CEDEDE5A3}] => (Allow) E:\Games\Steamer\steamapps\common\Yakuza Like a Dragon\runtime\media\startup.exe => No File FirewallRules: [{1DF402D7-0E44-464F-8CB1-924685AC549B}] => (Allow) E:\Games\Steamer\steamapps\common\Yakuza Like a Dragon\runtime\media\startup.exe => No File FirewallRules: [TCP Query User{4F402EEF-26B2-49EA-9786-FD886488711B}D:\games\epic\pathfinderkingmaker\kingmaker.exe] => (Allow) D:\games\epic\pathfinderkingmaker\kingmaker.exe => No File FirewallRules: [UDP Query User{666A7E19-955F-4498-AAD1-9839728970F2}D:\games\epic\pathfinderkingmaker\kingmaker.exe] => (Allow) D:\games\epic\pathfinderkingmaker\kingmaker.exe => No File FirewallRules: [{6BE6A838-5075-4C9E-B7E3-AB9744B44944}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe => No File FirewallRules: [{05ABF53C-D11B-4019-B11D-F23A7452C819}] => (Allow) E:\Games\Steamer\steamapps\common\Dying Light\DevTools\DyingLightPlayer.exe => No File FirewallRules: [{A42CE8BE-82F1-461B-9FCA-3FD372B64DEA}] => (Allow) E:\Games\Steamer\steamapps\common\Dying Light\DevTools\DyingLightPlayer.exe => No File HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION HKLM\Software\...\Authentication\Credential Providers: [AutorunsDisabled] -> HKLM\Software\...\Authentication\Credential Provider Filters: [AutorunsDisabled] -> Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2022-11-06] Startup: C:\Users\Maffu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2022-10-08] HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION Task: {11F110E5-3636-434C-9BF1-77CA3817F448} - System32\Tasks\GoogleUpdateTaskMachineUA{94E9F92D-0F3C-4D4E-AE18-BC433213574A} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler (No File) Task: {BB99C98B-459A-40AA-934C-B320E321A31E} - System32\Tasks\GoogleUpdateTaskMachineCore{7A02C385-8D26-41D7-806B-BC90EB10767C} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c (No File) Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found] Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found] Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found] Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found] S4 DFWSIDService; C:\Program Files (x86)\Wondershare\Wondershare Dr.Fone\WsidService.exe [X] S4 ElevationService; C:\Program Files (x86)\Wondershare\Wondershare Dr.Fone\Addins\Backup\ElevationService.exe [X] S4 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S4 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] S4 WsDrvInst; C:\Program Files (x86)\Wondershare\Wondershare Dr.Fone\Addins\Repair\DriverInstall.exe [X] Hosts: EmptyTemp: End:: ***************** Restore point was successfully created. Processes closed successfully. HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{321F46A6-D8F8-4C44-ADD0-AF926E3606A9} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{3E888169-3C1E-43AA-BB32-87F6E985A44E} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{4279CFB2-D26D-4340-86E7-E7C7AF79F081} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{66C7C6A4-92CB-4203-944E-4A3F4323F497} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{77953D65-F265-485F-B67D-A34DE8045BFC} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{90489ADC-89AF-4E4D-9ED1-BB6B32C31E65} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{922D9A3B-8481-460C-9B73-5710AEB8423D} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{9324F009-C35E-4D14-9D20-0CE8A2A3E330} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{981637F7-4585-4D55-B365-A5C5B82F4CEB} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{C4B4627E-9496-4AD1-AC60-EFD2EB437A79} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{C8120E54-622E-4452-9974-87AC65D79CB6} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{CAEF3289-33A4-4931-AEC5-A610BEAA6AB0} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{D26F8E90-55B7-4753-9D33-F32FF52FF920} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{DEF990D9-9913-4AF0-9B4B-8D9F294F122E} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{DEFF582C-FF7C-4D00-8AE5-0E9EBC978C7F} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{F6764025-F2CA-4914-95BC-0F2F52FD9946} => removed successfully HKU\S-1-5-21-2763654447-502089044-3427749853-1001_Classes\CLSID\{FCF17890-E5E6-46CF-872C-75712AC0429B} => removed successfully HKLM\Software\Classes\.scr\\"Default"="scrfile" => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\"Local Page"="C:\Windows\System32\blank.htm" => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\"Local Page"="C:\Windows\SysWOW64\blank.htm" => value restored successfully HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{583C990C-2D38-410c-9A4A-0932D66A754F} => removed successfully HKLM\Software\Classes\CLSID\{583C990C-2D38-410c-9A4A-0932D66A754F} => removed successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{8E375A63-C616-46F1-AC77-59DF78F3A826} => removed successfully HKLM\Software\Wow6432Node\Classes\CLSID\{8E375A63-C616-46F1-AC77-59DF78F3A826} => removed successfully HKLM\Software\Classes\PROTOCOLS\Handler\AutorunsDisabled => removed successfully HKLM\Software\Classes\CLSID\{314111c7-a502-11d2-bbca-00c04f8ec294} => removed successfully HKLM\Software\Classes\PROTOCOLS\Handler\AutorunsDisabled => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{DE3CB516-D806-462C-920E-3E8017277430}C:\users\maffu\appdata\local\vidyoconnect\vidyoconnect.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{BECAED13-B4C4-4F83-A13B-ECBAB0601FD9}C:\users\maffu\appdata\local\vidyoconnect\vidyoconnect.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{21A6A617-274E-416E-A997-6FBA654F9CE4}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{675589D1-FF6D-48BA-BB2F-AC069FFF2AD9}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{348BB91E-DDEA-428C-B2FD-570CEDEDE5A3}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1DF402D7-0E44-464F-8CB1-924685AC549B}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{4F402EEF-26B2-49EA-9786-FD886488711B}D:\games\epic\pathfinderkingmaker\kingmaker.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{666A7E19-955F-4498-AAD1-9839728970F2}D:\games\epic\pathfinderkingmaker\kingmaker.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6BE6A838-5075-4C9E-B7E3-AB9744B44944}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{05ABF53C-D11B-4019-B11D-F23A7452C819}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A42CE8BE-82F1-461B-9FCA-3FD372B64DEA}" => removed successfully HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate => removed successfully HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\AutorunsDisabled => removed successfully HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters\AutorunsDisabled => removed successfully C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled => moved successfully C:\Users\Maffu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled => moved successfully HKLM\SOFTWARE\Policies\Mozilla => removed successfully HKLM\SOFTWARE\Policies\Google => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{11F110E5-3636-434C-9BF1-77CA3817F448}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11F110E5-3636-434C-9BF1-77CA3817F448}" => removed successfully C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA{94E9F92D-0F3C-4D4E-AE18-BC433213574A} => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA{94E9F92D-0F3C-4D4E-AE18-BC433213574A}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BB99C98B-459A-40AA-934C-B320E321A31E}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB99C98B-459A-40AA-934C-B320E321A31E}" => removed successfully C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore{7A02C385-8D26-41D7-806B-BC90EB10767C} => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore{7A02C385-8D26-41D7-806B-BC90EB10767C}" => removed successfully HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => removed successfully HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => removed successfully HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => removed successfully HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => removed successfully HKLM\System\CurrentControlSet\Services\DFWSIDService => removed successfully DFWSIDService => service removed successfully HKLM\System\CurrentControlSet\Services\ElevationService => removed successfully ElevationService => service removed successfully HKLM\System\CurrentControlSet\Services\gupdate => removed successfully gupdate => service removed successfully HKLM\System\CurrentControlSet\Services\gupdatem => removed successfully gupdatem => service removed successfully HKLM\System\CurrentControlSet\Services\WsDrvInst => removed successfully WsDrvInst => service removed successfully C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. =========== EmptyTemp: ========== FlushDNS => completed BITS transfer queue => 0 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 893071848 B Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 543385383 B Windows/system/drivers => 63859083 B Edge => 41772 B Chrome => 5410942203 B Brave => 355941 B Firefox => 378702731 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 2796790 B NetworkService => 2815592 B Maffu => 265272741 B RecycleBin => 14250776 B EmptyTemp: => 7.1 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 18:58:30 ====