JustPaste.it

Fixlog

Fix result of Farbar Recovery Scan Tool (x64) Version: 29-12-2022
Ran by Noname1 (03-01-2023 01:13:30) Run:1
Running from C:\Users\Noname1\Desktop
Loaded Profiles: Noname1
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe" (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SPDriverInstall.lnk [2022-06-06]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
Task: {2267433E-8501-4792-9322-96CFB85CDB33} - System32\Tasks\{2C678E6B-E144-4A71-81CA-495CA970DD2A} => C:\Windows\system32\pcalua.exe -a C:\Users\Noname1\Desktop\usb_format.exe -d C:\Users\Noname1\Desktop
AutoConfigURL: [{3F4E95A4-2440-4853-8148-2B2CD27588D2}] => hxxp://localhost:8446/sos.pac <==== ATTENTION
AutoConfigURL: [{425CB667-6E01-4006-8A0F-43951BE60412}] => hxxp://localhost:8446/sos.pac <==== ATTENTION
ProxyServer: [S-1-5-21-1844876104-4198425060-1534634173-1001] => 127.0.0.1:7890
RemoveProxy:
U0 Partizan; system32\drivers\Partizan.sys [X]
U3 SARPSvc; no ImagePath
cmd: del %temp%\*.* /f /s /q
cmd: rd /s /q %temp%
Hosts:
cmd: bitsadmin /reset /allusers
cmd: netsh winsock reset catalog
cmd: ipconfig /flushdns
EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsDefender" => removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SPDriverInstall.lnk => moved successfully
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
C:\ProgramData\NTUSER.pol => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2267433E-8501-4792-9322-96CFB85CDB33}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2267433E-8501-4792-9322-96CFB85CDB33}" => removed successfully
C:\Windows\System32\Tasks\{2C678E6B-E144-4A71-81CA-495CA970DD2A} => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2C678E6B-E144-4A71-81CA-495CA970DD2A}" => removed successfully
HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\ProxyMgr\{3F4E95A4-2440-4853-8148-2B2CD27588D2} => removed successfully
HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\ProxyMgr\{425CB667-6E01-4006-8A0F-43951BE60412} => removed successfully
"HKU\S-1-5-21-1844876104-4198425060-1534634173-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer" => removed successfully

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-1844876104-4198425060-1534634173-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-1844876104-4198425060-1534634173-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


========= End of RemoveProxy: =========

HKLM\System\CurrentControlSet\Services\Partizan => removed successfully
Partizan => service removed successfully
HKLM\System\CurrentControlSet\Services\SARPSvc => removed successfully
SARPSvc => service removed successfully

========= del %temp%\*.* /f /s /q =========

Deleted file - C:\Users\Noname1\AppData\Local\Temp\269c502f-c4c8-4da4-bb19-982299df162d.tmp
Deleted file - C:\Users\Noname1\AppData\Local\Temp\4a4660f0-744c-4074-b7eb-14dd3f5eaa7b.tmp
Deleted file - C:\Users\Noname1\AppData\Local\Temp\9945d696-6b19-4e97-a82d-11f4027627b1.tmp
Deleted file - C:\Users\Noname1\AppData\Local\Temp\assistant_installer_20230102222048.log
Deleted file - C:\Users\Noname1\AppData\Local\Temp\codeint5355
Deleted file - C:\Users\Noname1\AppData\Local\Temp\CUsersNoname1AppDataLocalProgramsOpera94.0.4606.38opera_autoupdate.download.lock
C:\Users\Noname1\AppData\Local\Temp\FXSAPIDebugLogFile.txt
Deleted file - C:\Users\Noname1\AppData\Local\Temp\PSExt.dbd
Deleted file - C:\Users\Noname1\AppData\Local\Temp\PSExt2.dbd
Deleted file - C:\Users\Noname1\AppData\Local\Temp\Setup Log 2023-01-03 #001.txt
Deleted file - C:\Users\Noname1\AppData\Local\Temp\sMarUpdateInfo.dbd
Deleted file - C:\Users\Noname1\AppData\Local\Temp\StartApps.txt
Deleted file - C:\Users\Noname1\AppData\Local\Temp\sUpdate.dbd
Deleted file - C:\Users\Noname1\AppData\Local\Temp\usoft.dbd
Deleted file - C:\Users\Noname1\AppData\Local\Temp\.opera\B1C290751286\opera_autoupdate.log
Deleted file - C:\Users\Noname1\AppData\Local\Temp\.opera\B1C290751286\Crash Reports\metadata
Deleted file - C:\Users\Noname1\AppData\Local\Temp\.opera\B1C290751286\Crash Reports\settings.dat

========= End of CMD: =========


========= rd /s /q %temp% =========

C:\Users\Noname1\AppData\Local\Temp\FXSAPIDebugLogFile.txt - The process cannot access the file because it is being used by another process.

========= End of CMD: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.7.9600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Unable to cancel {C39A2597-FC11-40C4-A7D5-FDD5CBDA8874}.
0 out of 1 jobs canceled.

========= End of CMD: =========


========= netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 47908376 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 6474 B
Edge => 0 B
Chrome => 778048171 B
Firefox => 16657737 B
Opera => 398649546 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 128 B
NetworkService => 1190 B
Noname1 => 1908285 B

RecycleBin => 0 B
EmptyTemp: => 1.2 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 01:14:53 ====