Fix result of Farbar Recovery Scan Tool (x64) Version: 17.03.2019 Ran by Artur Machnicki (14-04-2019 22:22:14) Run:5 Running from D:\Firefox Download Loaded Profiles: Artur Machnicki (Available Profiles: Artur Machnicki) Boot Mode: Normal ============================================== fixlist content: ***************** Task: {99C5EFF0-DF3B-4CDB-B641-B53C062CBAD5} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Security\Upgrade.exe (Symantec Corporation -> Symantec Corporation) Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"} FirewallRules: [TCP Query User{F4B59171-0422-4540-A021-78CFA0611B2B}D:\the long journey home\tljh\binaries\win64\tljh-win64-shipping.exe] => (Block) D:\the long journey home\tljh\binaries\win64\tljh-win64-shipping.exe No File FirewallRules: [UDP Query User{F2812ECA-0ED3-467B-9EB7-F7D339E1FA68}D:\the long journey home\tljh\binaries\win64\tljh-win64-shipping.exe] => (Block) D:\the long journey home\tljh\binaries\win64\tljh-win64-shipping.exe No File FirewallRules: [TCP Query User{6D38CB63-BD34-4B1B-B3B1-6FFE6BF3EA80}D:\fifa 17\fifa17.exe] => (Block) D:\fifa 17\fifa17.exe No File FirewallRules: [UDP Query User{2223FC7B-D83F-413B-9102-DB945ECB25EE}D:\fifa 17\fifa17.exe] => (Block) D:\fifa 17\fifa17.exe No File FirewallRules: [TCP Query User{8A91D75B-870A-4326-B174-101CCA5F8C0A}D:\battlefield 1\bf1.exe] => (Block) D:\battlefield 1\bf1.exe No File FirewallRules: [UDP Query User{86C21843-C2DF-4FF8-BDB9-90B5B7B66F92}D:\battlefield 1\bf1.exe] => (Block) D:\battlefield 1\bf1.exe No File FirewallRules: [TCP Query User{FCBE978C-B3D4-494A-A2F0-A40ED780A0EC}D:\doom\doomx64.exe] => (Block) D:\doom\doomx64.exe No File FirewallRules: [UDP Query User{C4DCCC99-7363-4E4F-941F-39BD89F4BBCD}D:\doom\doomx64.exe] => (Block) D:\doom\doomx64.exe No File FirewallRules: [TCP Query User{7BD58A7A-92CC-400F-B24A-C4D28426AD36}D:\vikings - wolves of midgard\vikings.exe] => (Block) D:\vikings - wolves of midgard\vikings.exe No File FirewallRules: [UDP Query User{88608FC6-0632-4F1A-A108-2C8E719B3143}D:\vikings - wolves of midgard\vikings.exe] => (Block) D:\vikings - wolves of midgard\vikings.exe No File FirewallRules: [TCP Query User{EB461CC7-FCD9-4FEF-9486-C4BB5C8330AD}D:\vikings wolves of midgard\vikings.exe] => (Block) D:\vikings wolves of midgard\vikings.exe No File FirewallRules: [TCP Query User{FBA8E737-FAE7-40C3-BE54-36372E66DB8F}D:\sword coast legends\swordcoast.exe] => (Block) D:\sword coast legends\swordcoast.exe No File FirewallRules: [UDP Query User{363A86E7-FAF1-41E0-B4C7-7D2F6FC89642}D:\sword coast legends\swordcoast.exe] => (Block) D:\sword coast legends\swordcoast.exe No File FirewallRules: [TCP Query User{0EEEC36B-8CFF-4B7F-AA27-BB7FADE17EB3}D:\fallout 4\fallout4.exe] => (Block) D:\fallout 4\fallout4.exe No File FirewallRules: [UDP Query User{F54C22F5-1263-44F1-AB45-61E147DE2883}D:\fallout 4\fallout4.exe] => (Block) D:\fallout 4\fallout4.exe No File HKLM\...\Run: [] => [X] HKU\S-1-5-21-3532491921-2668913716-1004277442-1000\...\Run: [] => [X] EmptyTemp: ***************** "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{99C5EFF0-DF3B-4CDB-B641-B53C062CBAD5}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{99C5EFF0-DF3B-4CDB-B641-B53C062CBAD5}" => removed successfully C:\Windows\System32\Tasks\Remediation\AntimalwareMigrationTask => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Remediation\AntimalwareMigrationTask" => removed successfully ========= wevtutil el | Foreach-Object {wevtutil cl "$_"} ========= ========= End of Powershell: ========= "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{F4B59171-0422-4540-A021-78CFA0611B2B}D:\the long journey home\tljh\binaries\win64\tljh-win64-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{F2812ECA-0ED3-467B-9EB7-F7D339E1FA68}D:\the long journey home\tljh\binaries\win64\tljh-win64-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{6D38CB63-BD34-4B1B-B3B1-6FFE6BF3EA80}D:\fifa 17\fifa17.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2223FC7B-D83F-413B-9102-DB945ECB25EE}D:\fifa 17\fifa17.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8A91D75B-870A-4326-B174-101CCA5F8C0A}D:\battlefield 1\bf1.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{86C21843-C2DF-4FF8-BDB9-90B5B7B66F92}D:\battlefield 1\bf1.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{FCBE978C-B3D4-494A-A2F0-A40ED780A0EC}D:\doom\doomx64.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{C4DCCC99-7363-4E4F-941F-39BD89F4BBCD}D:\doom\doomx64.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{7BD58A7A-92CC-400F-B24A-C4D28426AD36}D:\vikings - wolves of midgard\vikings.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{88608FC6-0632-4F1A-A108-2C8E719B3143}D:\vikings - wolves of midgard\vikings.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{EB461CC7-FCD9-4FEF-9486-C4BB5C8330AD}D:\vikings wolves of midgard\vikings.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{FBA8E737-FAE7-40C3-BE54-36372E66DB8F}D:\sword coast legends\swordcoast.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{363A86E7-FAF1-41E0-B4C7-7D2F6FC89642}D:\sword coast legends\swordcoast.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0EEEC36B-8CFF-4B7F-AA27-BB7FADE17EB3}D:\fallout 4\fallout4.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{F54C22F5-1263-44F1-AB45-61E147DE2883}D:\fallout 4\fallout4.exe" => removed successfully "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully "HKU\S-1-5-21-3532491921-2668913716-1004277442-1000\Software\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 68197786 B Java, Flash, Steam htmlcache => 3887 B Windows/system/drivers => 139509582 B Edge => 0 B Chrome => 0 B Firefox => 1097164860 B Opera => 0 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 128 B systemprofile32 => 128 B LocalService => 0 B NetworkService => 0 B Artur Machnicki => 299277564 B RecycleBin => 0 B EmptyTemp: => 1.5 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 22:22:33 ====