Fix result of Farbar Recovery Scan Tool (x64) Version: 16-02-2020
Ran by administrator (20-02-2020 21:55:42) Run:1
Running from C:\Users\user\Desktop
Loaded Profiles:user & MediaAdmin$ (Available Profiles: user & MediaAdmin$ & .NET v4.5 & .NET v4.5 Classic)
Boot Mode: Normal
==============================================
fixlist content:
*****************
cmd: sc config trustedinstaller start= auto
cmd: net start trustedinstaller
cmd: fsutil resource setautoreset true %SystemDrive%\
cmd: attrib -r -s -h %SystemRoot%\System32\Config\TxR\*
StartPowershell:
function Move-LockedFile
{
param($path, $destination)
$path = (Resolve-Path $path).Path
$destination = $executionContext.SessionState.Path.GetUnresolvedProviderPathFromPSPath($destination)
$MOVEFILE_DELAY_UNTIL_REBOOT = 0x00000004
$MOVEFILE_REPLACE_EXISTING = 1
$memberDefinition = @'
[DllImport("kernel32.dll", SetLastError=true, CharSet=CharSet.Auto)]
public static extern bool MoveFileEx(string lpExistingFileName, string lpNewFileName,
int dwFlags);
'@
$type = Add-Type -Name MoveFileUtils -MemberDefinition $memberDefinition -PassThru
$type::MoveFileEx($path, $destination, $MOVEFILE_DELAY_UNTIL_REBOOT + $MOVEFILE_REPLACE_EXISTING)
}
Get-ChildItem -path "$env:SystemRoot\system32\Config\TxR\." |
Foreach-Object {
write-output $_.fullname
Move-LockedFile -path $_.fullname "$env:SystemRoot\Temp\junk"
}
EndPowershell:
cmd: attrib -r -s -h %SystemRoot%\System32\SMI\Store\Machine\*
cmd: del /f /q %SystemRoot%\System32\SMI\Store\Machine\*.tm*
cmd: del /f /q %SystemRoot%\System32\SMI\Store\Machine\*.blf
cmd: del /f /q %SystemRoot%\System32\SMI\Store\Machine\*.regtrans-ms
EmptyTemp:
*****************
========= sc config trustedinstaller start= auto =========
[SC] ChangeServiceConfig SUCCESS
========= End of CMD: =========
========= net start trustedinstaller =========
The Windows Modules Installer service is starting.
The Windows Modules Installer service was started successfully.
========= End of CMD: =========
========= fsutil resource setautoreset true %SystemDrive%\ =========
The operation completed successfully.
========= End of CMD: =========
========= attrib -r -s -h %SystemRoot%\System32\Config\TxR\* =========
========= End of CMD: =========
========= Powershell: =========
C:\Windows\system32\Config\TxR\{c3213266-30b4-11e6-8101-806e6f6e6963}.TxR.0.regtrans-ms
True
C:\Windows\system32\Config\TxR\{c3213266-30b4-11e6-8101-806e6f6e6963}.TxR.1.regtrans-ms
True
C:\Windows\system32\Config\TxR\{c3213266-30b4-11e6-8101-806e6f6e6963}.TxR.2.regtrans-ms
True
C:\Windows\system32\Config\TxR\{c3213266-30b4-11e6-8101-806e6f6e6963}.TxR.3.regtrans-ms
True
C:\Windows\system32\Config\TxR\{c3213266-30b4-11e6-8101-806e6f6e6963}.TxR.blf
True
C:\Windows\system32\Config\TxR\{c3213267-30b4-11e6-8101-806e6f6e6963}.TM.blf
True
C:\Windows\system32\Config\TxR\{c3213267-30b4-11e6-8101-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms
True
C:\Windows\system32\Config\TxR\{c3213267-30b4-11e6-8101-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms
True
C:\Windows\system32\Config\TxR\{d044f62a-ae7e-11e3-80bf-b8ca3aeed8ca}.TxR.0.regtrans-ms
True
C:\Windows\system32\Config\TxR\{d044f62a-ae7e-11e3-80bf-b8ca3aeed8ca}.TxR.1.regtrans-ms
True
C:\Windows\system32\Config\TxR\{d044f62a-ae7e-11e3-80bf-b8ca3aeed8ca}.TxR.2.regtrans-ms
True
C:\Windows\system32\Config\TxR\{d044f62a-ae7e-11e3-80bf-b8ca3aeed8ca}.TxR.3.regtrans-ms
True
C:\Windows\system32\Config\TxR\{d044f62a-ae7e-11e3-80bf-b8ca3aeed8ca}.TxR.4.regtrans-ms
True
C:\Windows\system32\Config\TxR\{d044f62a-ae7e-11e3-80bf-b8ca3aeed8ca}.TxR.5.regtrans-ms
True
C:\Windows\system32\Config\TxR\{d044f62a-ae7e-11e3-80bf-b8ca3aeed8ca}.TxR.6.regtrans-ms
True
C:\Windows\system32\Config\TxR\{d044f62a-ae7e-11e3-80bf-b8ca3aeed8ca}.TxR.7.regtrans-ms
True
C:\Windows\system32\Config\TxR\{d044f62b-ae7e-11e3-80bf-b8ca3aeed8ca}.TMContainer00000000000000000001.regtrans-ms
True
C:\Windows\system32\Config\TxR\{d044f62b-ae7e-11e3-80bf-b8ca3aeed8ca}.TMContainer00000000000000000002.regtrans-ms
True
========= End of Powershell: =========
========= attrib -r -s -h %SystemRoot%\System32\SMI\Store\Machine\* =========
========= End of CMD: =========
========= del /f /q %SystemRoot%\System32\SMI\Store\Machine\*.tm* =========
========= End of CMD: =========
========= del /f /q %SystemRoot%\System32\SMI\Store\Machine\*.blf =========
Could Not Find C:\Windows\System32\SMI\Store\Machine\*.blf
========= End of CMD: =========
========= del /f /q %SystemRoot%\System32\SMI\Store\Machine\*.regtrans-ms =========
Could Not Find C:\Windows\System32\SMI\Store\Machine\*.regtrans-ms
========= End of CMD: =========
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 64740921 B
Java, Flash, Steam htmlcache => 379 B
Windows/system/drivers => 1218778403 B
Edge => 0 B
Chrome => 126248577 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 13747 B
systemprofile32 => 13747 B
LocalService => 8444103 B
NetworkService => 8477895 B
msds_adm => 10366221 B
MediaAdmin$ => 10366221 B
ea => 10366221 B
reception => 10366221 B
jj => 10366221 B
Administrator => 75818681 B
.NET v4.5 => 75818681 B
.NET v4.5 Classic => 75818681 B
RecycleBin => 37383898 B
EmptyTemp: => 1.6 GB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 21:56:54 ====