Fix result of Farbar Recovery Scan Tool (x64) Version: 13-12-2017 Ran by [removed] (13-12-2017 10:28:27) Run:1 Running from C:\Users\[removed]\Desktop [removed] Boot Mode: Normal ============================================== fixlist content: ***************** Code: Select all CreateRestorePoint: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\MountPoints2: {710d8cd7-502d-11e2-bf2d-806e6f6e6963} - "E:\WD SmartWare.exe" autoplay=true FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [No File] U1 aswbdisk; no ImagePath 2017-11-22 04:48 - 2017-12-10 22:10 - 000003260 _____ C:\Windows\System32\Tasks\{13A80A86-065B-441C-A635-6DAFE9158DE9} Task: {E7B8538C-BA16-4E60-8C77-9778584760FD} - System32\Tasks\{13A80A86-065B-441C-A635-6DAFE9158DE9} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\Revouninstaller.exe" -d "C:\Program Files (x86)\VS Revo Group\Revo Uninstaller" AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [62] VirusTotal: C:\Program Files (x86)\dsengine.cfg EmptyTemp: ***************** Code: Select all => Error: No automatic fix found for this entry. Restore point was successfully created. "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" => removed successfully "HKU\S-1-5-21-298761936-1198288888-1608458099-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{710d8cd7-502d-11e2-bf2d-806e6f6e6963}" => removed successfully HKLM\Software\Classes\CLSID\{710d8cd7-502d-11e2-bf2d-806e6f6e6963} => key not found "HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => removed successfully "HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => removed successfully "HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0" => removed successfully HKLM\System\CurrentControlSet\Services\aswbdisk => key could not remove, key could be protected C:\Windows\System32\Tasks\{13A80A86-065B-441C-A635-6DAFE9158DE9} => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E7B8538C-BA16-4E60-8C77-9778584760FD} => could not remove key. ErrorCode1: 0x00000002 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E7B8538C-BA16-4E60-8C77-9778584760FD}" => removed successfully C:\Windows\System32\Tasks\{13A80A86-065B-441C-A635-6DAFE9158DE9} => not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{13A80A86-065B-441C-A635-6DAFE9158DE9}" => removed successfully C:\ProgramData\TEMP => ":5C321E34" ADS removed successfully VirusTotal: C:\Program Files (x86)\dsengine.cfg => https://www.virustotal.com/file/5070d2735df03350d13086769e9b550452a0f3c104f71dfca944452251c3e099/analysis/1513160935/ =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10671133 B Java, Flash, Steam htmlcache => 0 B Windows/system/drivers => 15265792 B Edge => 0 B Chrome => 0 B Firefox => 45631891 B Opera => 0 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 100816 B systemprofile32 => 66228 B LocalService => 0 B NetworkService => 0 B Comet => 3103265 B Kiosk => 0 B Paul => 4670289 B RecycleBin => 546 B EmptyTemp: => 83.8 MB temporary data Removed. ================================ Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 13-12-2017 10:30:43) Result of scheduled keys to remove after reboot: HKLM\System\CurrentControlSet\Services\aswbdisk => key could not remove, key could be protected ==== End of Fixlog 10:30:43 ====