Fix result of Farbar Recovery Scan Tool (x64) Version: 18-12-2023 Ran by HeatherSchmidt (20-12-2023 08:35:19) Run:2 Running from C:\Users\HeatherSchmidt\Downloads Loaded Profiles: stpau Boot Mode: Normal ============================================== fixlist content: ***************** Start:: CreateRestorePoint: CloseProcesses: HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION HKU\S-1-12-1-1721880173-1220933218-3369430184-3542225890\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\HeatherSchmidt\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File) HKU\S-1-12-1-1721880173-1220933218-3369430184-3542225890\...\RunOnce: [Uninstall 21.220.1024.0005\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\HeatherSchmidt\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\amd64" [0 2023-12-19] () <==== ATTENTION [zero byte File/Folder] HKU\S-1-12-1-1721880173-1220933218-3369430184-3542225890\...\RunOnce: [Uninstall 21.220.1024.0005] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\HeatherSchmidt\AppData\Local\Microsoft\OneDrive\21.220.1024.0005" [0 2023-12-19] () <==== ATTENTION [zero byte File/Folder] HKU\S-1-12-1-379402305-1282805949-553899156-2530637685\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ChadClough\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File) HKU\S-1-12-1-379402305-1282805949-553899156-2530637685\...\RunOnce: [Uninstall 23.226.1031.0003] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ChadClough\AppData\Local\Microsoft\OneDrive\23.226.1031.0003" [0 2023-12-15] () <==== ATTENTION [zero byte File/Folder] CMD: reg export "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList" C:\Profile.txt EmptyTemp: End:: ***************** Restore point was successfully created. Processes closed successfully. HKLM\SOFTWARE\Microsoft\Windows Defender\\DisableAntiSpyware => Error setting value. HKLM\SOFTWARE\Microsoft\Windows Defender\\DisableAntiVirus => Error setting value. "HKU\S-1-12-1-1721880173-1220933218-3369430184-3542225890\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Standalone Update Binary" => removed successfully "HKU\S-1-12-1-1721880173-1220933218-3369430184-3542225890\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall 21.220.1024.0005\amd64" => removed successfully "HKU\S-1-12-1-1721880173-1220933218-3369430184-3542225890\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall 21.220.1024.0005" => removed successfully "HKU\S-1-12-1-379402305-1282805949-553899156-2530637685\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Standalone Update Binary" => removed successfully "HKU\S-1-12-1-379402305-1282805949-553899156-2530637685\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall 23.226.1031.0003" => removed successfully ========= reg export "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList" C:\Profile.txt ========= The operation completed successfully. ========= End of CMD: ========= =========== EmptyTemp: ========== FlushDNS => completed BITS transfer queue => 0 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 11569902 B Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B Windows/system/drivers => 11221698 B Edge => 0 B Chrome => 58768062 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B HeatherSchmidt => 93543778 B JohnMilazzo => 93543778 B CollinMayer => 93543778 B LyleTimm => 93543778 B ChadClough => 178808228 B MiriamSchaewe => 178808228 B systemprofile => 178808228 B systemprofile32 => 178808228 B LocalService => 178823126 B NetworkService => 178824296 B stpau => 178824296 B RecycleBin => 0 B EmptyTemp: => 1.6 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 08:36:11 ====