Fix result of Farbar Recovery Scan Tool (x64) Version: 22.05.2024 01 Ran by Michal (28-05-2024 21:26:21) Run:1 Running from E:\Moje dokumenty\programy anty vir Loaded Profiles: Michal Boot Mode: Normal ============================================== fixlist content: ***************** START:: App Explorer (HKU\S-1-5-21-2729801542-2757189542-1995047959-1001\...\Host App Service) (Version: 0.273.4.677 - SweetLabs) <==== ATTENTION AlternateDataStreams: C:\Users\Michal\OneDrive\Desktop\28 alcohol order FCL.xlsx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Michal\OneDrive\Desktop\29 alcohol order FCL - zubr.xlsx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Michal\OneDrive\Desktop\advice.txt:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Michal\OneDrive\Desktop\Big Goals plan 1.xlsx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Michal\OneDrive\Desktop\Bring The Rocks.lnk:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Michal\OneDrive\Desktop\cashflow 2024.xlsx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Michal\OneDrive\Desktop\company meeting.txt:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Michal\OneDrive\Desktop\Sales Report 2024.xlsx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Michal\OneDrive\Desktop\Taiwan - Shortcut.lnk:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Michal\OneDrive\Desktop\work schedule April.xlsx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Michal\OneDrive\Desktop\work schedule May.xlsx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Michal\OneDrive\Desktop\µTorrent.lnk:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Michal\OneDrive\Documents\Custom Office Templates:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Michal\OneDrive\Documents\desktop (New).ini:com.dropbox.attrs [54] SearchScopes: HKU\S-1-5-21-2729801542-2757189542-1995047959-1001 -> DefaultScope {2B660B40-DECE-4211-9F0D-7F48364CE68B} URL = SearchScopes: HKU\S-1-5-21-2729801542-2757189542-1995047959-1001 -> {2B660B40-DECE-4211-9F0D-7F48364CE68B} URL = (svchost.exe ->) (SweetLabs Inc -> SweetLabs, Inc) C:\Users\Michal\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION Task: {86863ABE-63A9-4786-8FD4-793A2D854359} - System32\Tasks\App Explorer => C:\Users\Michal\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [7574560 2023-03-30] (SweetLabs Inc -> SweetLabs, Inc) <==== ATTENTION Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File) Task: {643C5F1F-970F-4502-AEED-6328D742F3EE} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => %systemroot%\system32\MusNotification.exe LogonUpdateResults (No File) Task: {B8FFC80E-7795-481C-A7EC-E5CBDA96008A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe Display (No File) Task: {FBD18413-4082-4638-BA3E-1CC0CC02EBCA} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC Reboot (No File) Task: {15614527-6C8D-4A07-B405-8E22C17EA2BB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery Reboot (No File) Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File) HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0: <==== ATTENTION (Restriction - Zones) CHR StartupUrls: Default -> "","hxxp://mysearch.avg.com?cid={38C9EF54-1B51-4F39-86C3-C9C0F7B8D7F5}&mid=b9a76e73b8be47d282abd16b059d98ef-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-01-27 19:13:00&v=17.3.1.91&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={38C9EF54-1B51-4F39-86C3-C9C0F7B8D7F5}&mid=b9a76e73b8be47d282abd16b059d98ef-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-07 08:17:37&v=17.3.1.204&pid=safeguard&sg=&sap=hp","|hxxp://mysearch.avg.com?cid={38C9EF54-1B51-4F39-86C3-C9C0F7B8D7F5}&mid=b9a76e73b8be47d282abd16b059d98ef-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-01-27 19:13:00&v=18.0.5.292&pid=safeguard&sg=&sap=hp|hxxp://mysearch.avg.com?cid={38C9EF54-1B51-4F39-86C3-C9C0F7B8D7F5}&mid=b9a76e73b8be47d282abd16b059d98ef-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-07 08:17:37&v=17.3.1.204&pid=safeguard&sg=&sap=hp","hxxp://www.sweet-page.com/?type=hp&ts=1422909478&from=cor&uid=WDCXWD10JPVX-22JC3T0_WD-WX51A84RA1Y2RA1Y2","hxxp://isearch.omiga-plus.com/?type=hp&ts=1418923397&from=cor&uid=HitachiXHTS547550A9E384_J2160051CVE2RDCVE2RDX","hxxp://do-search.com/?type=hp&ts=1432806674&z=daca7c61f0cadaeef45970eg7zdc1o2bee8qaq4mdo&from=cor&uid=HitachiXHTS547550A9E384_J2160051CVE2RDCVE2RDX" S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X] EmptyTemp: CreateRestorePoint: END:: ***************** App Explorer (HKU\S-1-5-21-2729801542-2757189542-1995047959-1001\...\Host App Service) (Version: 0.273.4.677 - SweetLabs) <==== ATTENTION => Error: No automatic fix found for this entry. C:\Users\Michal\OneDrive\Desktop\28 alcohol order FCL.xlsx => ":com.dropbox.attrs" ADS removed successfully C:\Users\Michal\OneDrive\Desktop\29 alcohol order FCL - zubr.xlsx => ":com.dropbox.attrs" ADS removed successfully C:\Users\Michal\OneDrive\Desktop\advice.txt => ":com.dropbox.attrs" ADS removed successfully C:\Users\Michal\OneDrive\Desktop\Big Goals plan 1.xlsx => ":com.dropbox.attrs" ADS removed successfully C:\Users\Michal\OneDrive\Desktop\Bring The Rocks.lnk => ":com.dropbox.attrs" ADS removed successfully C:\Users\Michal\OneDrive\Desktop\cashflow 2024.xlsx => ":com.dropbox.attrs" ADS removed successfully C:\Users\Michal\OneDrive\Desktop\company meeting.txt => ":com.dropbox.attrs" ADS removed successfully C:\Users\Michal\OneDrive\Desktop\Sales Report 2024.xlsx => ":com.dropbox.attrs" ADS removed successfully C:\Users\Michal\OneDrive\Desktop\Taiwan - Shortcut.lnk => ":com.dropbox.attrs" ADS removed successfully "C:\Users\Michal\OneDrive\Desktop\work schedule April.xlsx" => ":com.dropbox.attrs" ADS not found. C:\Users\Michal\OneDrive\Desktop\work schedule May.xlsx => ":com.dropbox.attrs" ADS removed successfully C:\Users\Michal\OneDrive\Desktop\µTorrent.lnk => ":com.dropbox.attrs" ADS removed successfully C:\Users\Michal\OneDrive\Documents\Custom Office Templates => ":com.dropbox.attrs" ADS removed successfully C:\Users\Michal\OneDrive\Documents\desktop (New).ini => ":com.dropbox.attrs" ADS could not remove. "HKU\S-1-5-21-2729801542-2757189542-1995047959-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully HKU\S-1-5-21-2729801542-2757189542-1995047959-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2B660B40-DECE-4211-9F0D-7F48364CE68B} => removed successfully [3340] C:\Users\Michal\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe => process closed successfully. HKLM\SOFTWARE\Policies\Mozilla => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{86863ABE-63A9-4786-8FD4-793A2D854359}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{86863ABE-63A9-4786-8FD4-793A2D854359}" => removed successfully C:\WINDOWS\System32\Tasks\App Explorer => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\App Explorer" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{643C5F1F-970F-4502-AEED-6328D742F3EE}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{643C5F1F-970F-4502-AEED-6328D742F3EE}" => removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B8FFC80E-7795-481C-A7EC-E5CBDA96008A}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B8FFC80E-7795-481C-A7EC-E5CBDA96008A}" => removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FBD18413-4082-4638-BA3E-1CC0CC02EBCA}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FBD18413-4082-4638-BA3E-1CC0CC02EBCA}" => removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_AC" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15614527-6C8D-4A07-B405-8E22C17EA2BB}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15614527-6C8D-4A07-B405-8E22C17EA2BB}" => removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" => removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 => removed successfully "Chrome StartupUrls" => removed successfully HKLM\System\CurrentControlSet\Services\WinSetupMon => removed successfully WinSetupMon => service removed successfully Restore point was successfully created. =========== EmptyTemp: ========== FlushDNS => completed BITS transfer queue => 0 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 819887864 B Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 14158 B Windows/system/drivers => 22332328 B Edge => 0 B Chrome => 2215754672 B Firefox => 11980092 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 100368 B NetworkService => 211674 B Michal => 338122558 B RecycleBin => 3598333471 B EmptyTemp: => 6.5 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 21:28:35 ====