Fix result of Farbar Recovery Scan Tool (x64) Version: 17.03.2019
Ran by Jim (27-03-2019 09:09:59) Run:1
Running from C:\Users\Jim\Desktop
Loaded Profiles: Jim (Available Profiles: Jim & new & Guest)
Boot Mode: Normal
==============================================
fixlist content:
*
Start
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-1429559358-545836733-3232799662-1001\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-1429559358-545836733-3232799662-1001\...\Policies\system: [DisableChangePassword] 0
Startup: C:\Users\Sylvia\AppData\Roaming\Microsoft\Windows\Start Menu\Startup\lollipop.lnk
ShortcutTarget: lollipop.lnk -> C:\Users\Sylvia\AppData\Local\Lollipop\Lollipop.exe (No File)
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
webssearches
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Google{searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
webssearches
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
webssearches
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Google{searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
Google{searchTerms}
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
Google{searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
Google{searchTerms}
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File
S2 HP Health Check Service; "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe" [X]
S3 hpqwmiex; "C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe" [X]
Task: {D528F686-3FD6-43C9-9821-53D32E4202C8} - \EPUpdater No Task File
Task: {DD6F100D-5D23-4199-AA6E-F32D549BB673} - System32\Tasks\Freemium1ClickMaint => C:\Program Files (x86)\Freemium\System Utilities\1Click.exe
Task: {E19F18C6-D0D7-465F-A0F8-EAF14B7750EF} - \BrowserDefendert No Task File
Task: {EA08F72D-DC2D-4892-80C7-9B362A599135} - System32\Tasks\Start Registry Reviver => C:\Program Files (x86)\Reviversoft\Registry Reviver\RegistryReviver.exe
C:\Program Files (x86)\Iminent
C:\Users\Sylvia\AppData\Roaming\SupTab
C:\Users\Sylvia\AppData\Local\Tuguu_SL
C:\ProgramData\WPM
C:\Users\Sylvia\AppData\Roaming\VOPackage
C:\Users\Sylvia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
C:\Users\Sylvia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lollipop.lnk
C:\Users\Sylvia\AppData\Local\SearchProtect
C:\END
C:\Users\Sylvia\AppData\Local\Temp\BackupSetup.exe
C:\Users\Sylvia\AppData\Local\Temp\Quarantine.exe
End
*
"HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\EnableShellExecuteHooks" => not found
"HKU\S-1-5-21-1429559358-545836733-3232799662-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableLockWorkstation" => not found
"HKU\S-1-5-21-1429559358-545836733-3232799662-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableChangePassword" => not found
"Startup: C:\Users\Sylvia\AppData\Roaming\Microsoft\Windows\Start Menu\Startup\lollipop.lnk" => not found
"C:\Users\Sylvia\AppData\Local\Lollipop\Lollipop.exe" => not found
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
Google{searchTerms}" => not found
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
Google{searchTerms}" => not found
"\\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => not found
HKLM\Software\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => not found
"HKLM\Software\Classes\PROTOCOLS\Handler\ipp\0x00000001" => not found
HKLM\Software\Classes\CLSID\{E1D2BF42-A96B-11D1-9C6B-0000F875AC61} => not found
HP Health Check Service => service not found.
HKLM\System\CurrentControlSet\Services\hpqwmiex => removed successfully
hpqwmiex => service removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D528F686-3FD6-43C9-9821-53D32E4202C8}" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD6F100D-5D23-4199-AA6E-F32D549BB673}" => not found
"C:\Windows\System32\Tasks\Freemium1ClickMaint" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Freemium1ClickMaint" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E19F18C6-D0D7-465F-A0F8-EAF14B7750EF}" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA08F72D-DC2D-4892-80C7-9B362A599135}" => not found
"C:\Windows\System32\Tasks\Start Registry Reviver" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Start Registry Reviver" => not found
"C:\Program Files (x86)\Iminent" => not found
"C:\Users\Sylvia\AppData\Roaming\SupTab" => not found
"C:\Users\Sylvia\AppData\Local\Tuguu_SL" => not found
"C:\ProgramData\WPM" => not found
"C:\Users\Sylvia\AppData\Roaming\VOPackage" => not found
"C:\Users\Sylvia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage" => not found
"C:\Users\Sylvia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lollipop.lnk" => not found
"C:\Users\Sylvia\AppData\Local\SearchProtect" => not found
C:\END => moved successfully
"C:\Users\Sylvia\AppData\Local\Temp\BackupSetup.exe" => not found
"C:\Users\Sylvia\AppData\Local\Temp\Quarantine.exe" => not found
==== End of Fixlog 09:10:02 ====