Thank you
Fix result of Farbar Recovery Scan Tool (x64) Version: 08-08-2020
Ran by bailey (09-08-2020 00:29:28) Run:1
Running from C:\Users\baile\Desktop
Loaded Profiles: bailey
Boot Mode: Normal
==============================================
fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
VirusTotal: C:\Users\baile\AppData\Roaming\QTUpdate\QTConnect.exe;C:\Users\baile\AppData\Roaming\fix.ps1
Task: {1E649CDA-95E1-4B8C-B8E8-74E8382B8CFE} - \Lenovo\ImController\TimeBasedEvents\3578e401-7899-4505-bb7f-e2699d3bdc54 -> No File <==== ATTENTION
Task: {5F2A695C-4652-4E66-9D0F-F4622437989B} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> No File <==== ATTENTION
Task: {63861543-5211-4E66-8801-6EFD8591E965} - \Lenovo\ImController\Lenovo iM Controller Monitor -> No File <==== ATTENTION
Task: {6DC127F4-26AE-4CF1-8B85-4750BA3F33C6} - \Lenovo\ImController\TimeBasedEvents\d8f8e894-3373-4d40-8917-bafb04fe4bb4 -> No File <==== ATTENTION
Task: {7A3D0264-EDC8-4A0D-9047-006CB6A37F61} - \Lenovo\ImController\TimeBasedEvents\960dd729-c0eb-49c1-a0ce-ca278229e491 -> No File <==== ATTENTION
Task: {8FD88D6A-AA33-4048-8CF1-9258C185DABA} - \Lenovo\ImController\TimeBasedEvents\fcb69c11-3619-4a54-9840-18dbb3be06b4 -> No File <==== ATTENTION
Task: {DD27DF0B-4D9F-4AC3-997C-D0FE4E778AF9} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> No File <==== ATTENTION
SearchScopes: HKU\S-1-5-21-260720292-2504253849-2348319339-1001 -> DefaultScope {D4DBA3E0-BA8B-43C2-9BDB-2CD84DB0CF9F} URL =
SearchScopes: HKU\S-1-5-21-260720292-2504253849-2348319339-1001 -> {D4DBA3E0-BA8B-43C2-9BDB-2CD84DB0CF9F} URL =
Edge StartupUrls: Default -> "hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=88fptxqjxp1acegikmwv4003219¶m1=y6bdVFVIsvuYsgEClQfz8Gt8Oby4iBdjLq7%2Fysk4Phe5sV980wpeWqTlm5o9JII7iwwCvodvHVmpLIImL8j7rfbdJPlUwIIjqsZs2SjQQqCJvjS%2FQWY7KMbX%2FIbp9XkODOpZ1gnHRs3GPSypa6phnT6z2I1QoBwvRV%2FZDyyoVAPPPUsCDpVGq%2BpJ8sRZ0c7vOtazvH%2FdN4JThvEz%2B3sI%2BQIXutpSjLkz26%2BjMooTs0HZK%2FprPDR%2FVhBGYy41OTdWRLZ1nxtk9tzcE5AP%2Bso8ZX6rWFU6IgCN2KGbkqMOTzHtLQ6MgRDwf7aT8P66GsUbwrq9Mk7vfQzO8tvlB5sDEg%2F6d6juo%2F7hR5zLtsx3AxbWbHpmwcF7OSyZyPwkQyZejStlfM1yVRFc9JqPkXOpuA%3D%3D"
Edge DefaultSearchURL: Default -> hxxps://us.search.yahoo.com/yhs/search?hspart=omr&hsimp=yhs-001&type=88fptxqjxp1acegikmwv4003219¶m1=y6bdVFVIsvuYsgEClQfz8Gt8Oby4iBdjLq7%2Fysk4Phe5sV980wpeWqTlm5o9JII7iwwCvodvHVmpLIImL8j7ralwMtuqAWhvzt1IOFaMAcIduuJdmZe%2F3qriGNINMsteBhsX4nTzv8if0sWGgtKnQxNjXsYijXol39mTSjbOqmQGwZ8RMfbrUvnq3hKH3vWcRSN%2B8ABxFsECMCz1XKVrVkyOwJKfeoKhKMw1Dn%2BTEmoGtgVW9dehbKtCdtpIoWP65Tth5bGSfnw84vm8nTEqhL2MAGSYkftDJ33biJjzoaSymfHtnBhah2XVBZH0FSMcE5jGZazMhgjPIEhW7jcaUKM2GbXMpgi72MqAZ%2B0DebAzV3ojaKV5fpXCFED0kSwhv%2FnEWk6KNggrPCE5szjO2A%3D%3D&p={searchTerms}
Edge DefaultSearchKeyword: Default -> us.search.yahoo.com
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [No File]
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [No File]
Folder: C:\WINDOWS\branding
ExportKey: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TermService
S2 ImControllerService; %SystemRoot%\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [X]
Folder: c:\ProgramData\t3460
Folder: C:\Users\baile\AppData\Roaming\TeamViewer
CustomCLSID: HKU\S-1-5-21-260720292-2504253849-2348319339-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll => No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
FirewallRules: [{26019E5A-38C6-4D59-A5BE-8BDD267EDF6F}] => (Allow) C:\Users\baile\AppData\Local\Temp\7zS5E63\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{6B0D2048-307F-4244-AA4F-F2E848B56A09}] => (Allow) C:\Users\baile\AppData\Local\Temp\7zS5E63\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{9C38DD02-D1E5-42D1-B4AC-B5184FD1F6C9}] => (Allow) C:\Users\baile\AppData\Local\Temp\7zS39E4\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{0BA55689-C33A-4822-9E64-B3B2B16C88F7}] => (Allow) C:\Users\baile\AppData\Local\Temp\7zS39E4\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{C9296C30-660F-4D19-A23C-EA4864E409CA}] => (Allow) C:\Users\baile\AppData\Local\Temp\7zS427F\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{13017506-C2BE-42D1-A758-995EDCCF0D55}] => (Allow) C:\Users\baile\AppData\Local\Temp\7zS427F\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{2576A27D-0033-45B0-A059-CDC6B6633429}] => (Allow) C:\Users\baile\AppData\Local\Temp\7zS3C0D\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{61D876BE-D09D-4574-8C61-A846F591D4C7}] => (Allow) C:\Users\baile\AppData\Local\Temp\7zS3C0D\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{6CA07FE1-40F3-43F8-AC26-4C66B624A746}] => (Allow) C:\Users\baile\AppData\Local\Temp\7zS35F8\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{1EA577F8-A4B3-4D77-A21E-CE16F2BAC4F0}] => (Allow) C:\Users\baile\AppData\Local\Temp\7zS35F8\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{DB3CDFC4-2BF6-4663-8BC3-5E4D862A5642}] => (Allow) C:\Users\baile\AppData\Local\Temp\7zS501F\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{938EFB33-83CF-496D-95BC-EBEDF2230A57}] => (Allow) C:\Users\baile\AppData\Local\Temp\7zS501F\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{2DE0C751-C20B-41D9-ACE9-FA286B5FD124}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe => No File
FirewallRules: [{3966583E-9BD3-4AA7-ADEF-A8E228560145}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe => No File
*****************
Restore point was successfully created.
Processes closed successfully.
"VirusTotal: C:\Users\baile\AppData\Roaming\QTUpdate\QTConnect.exe" => not found
VirusTotal: C:\Users\baile\AppData\Roaming\fix.ps1 =>
https://www.virustotal.com/gui/file...48c74ab4201101a4ae2c9ec1703a5ab5f9-1596950984
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1E649CDA-95E1-4B8C-B8E8-74E8382B8CFE}" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\3578e401-7899-4505-bb7f-e2699d3bdc54" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5F2A695C-4652-4E66-9D0F-F4622437989B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5F2A695C-4652-4E66-9D0F-F4622437989B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{63861543-5211-4E66-8801-6EFD8591E965}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{63861543-5211-4E66-8801-6EFD8591E965}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Monitor" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DC127F4-26AE-4CF1-8B85-4750BA3F33C6}" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\d8f8e894-3373-4d40-8917-bafb04fe4bb4" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A3D0264-EDC8-4A0D-9047-006CB6A37F61}" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\960dd729-c0eb-49c1-a0ce-ca278229e491" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8FD88D6A-AA33-4048-8CF1-9258C185DABA}" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\fcb69c11-3619-4a54-9840-18dbb3be06b4" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DD27DF0B-4D9F-4AC3-997C-D0FE4E778AF9}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD27DF0B-4D9F-4AC3-997C-D0FE4E778AF9}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask" => removed successfully
"HKU\S-1-5-21-260720292-2504253849-2348319339-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKU\S-1-5-21-260720292-2504253849-2348319339-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D4DBA3E0-BA8B-43C2-9BDB-2CD84DB0CF9F} => removed successfully
"Edge StartupUrls" => removed successfully
"Edge DefaultSearchURL" => removed successfully
"Edge DefaultSearchKeyword" => removed successfully
HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect => removed successfully
HKLM\Software\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect => removed successfully
========================= Folder: C:\WINDOWS\branding ========================
2014-11-11 13:00 - 2014-11-11 13:00 - 000055808 ____A [14D089B8DB4132011FBB1DDF3CC6EB97] (important) C:\WINDOWS\branding\mediasrv.png
2014-11-11 13:00 - 2014-11-11 13:00 - 000152418 ____A [49DE4C621A5A22A3CCB9AB69BD1A5DAF] () C:\WINDOWS\branding\wupsvc.jpg
2014-11-11 13:00 - 2014-11-11 13:00 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\branding\Basebrd
2019-12-07 04:08 - 2019-12-07 04:08 - 001479368 ____A [CC0583AEB44859E5106FA3DBBD3AE983] (Microsoft Corporation) C:\WINDOWS\branding\Basebrd\basebrd.dll
2019-12-07 04:49 - 2020-06-17 17:29 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\branding\Basebrd\en-US
2020-06-17 17:26 - 2020-06-17 17:26 - 000008192 ____A [1B9E9972B86244F32D32F50DEDCAF937] (Microsoft Corporation) C:\WINDOWS\branding\Basebrd\en-US\basebrd.dll.mui
2014-11-11 13:00 - 2014-11-11 13:00 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\branding\shellbrd
2019-12-07 04:08 - 2019-12-07 04:08 - 000962048 ____A [167726ADF6B1BD73B6D2C09AFB96E853] (Microsoft Corporation) C:\WINDOWS\branding\shellbrd\shellbrd.dll
====== End of Folder: ======
================== ExportKey: ===================
[HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TermService]
"DependOnService"="RPCSS"
"Description"="@%SystemRoot%\System32\termsrv.dll,-267"
"DisplayName"="@%SystemRoot%\System32\termsrv.dll,-268"
"ErrorControl"="1"
"FailureActions"="80510100000000000000000003000000140000000100000060ea00000100000060ea00000000000060ea0000"
"ImagePath"="%SystemRoot%\System32\svchost.exe -k NetworkService"
"ObjectName"="NT Authority\NetworkService"
"RequiredPrivileges"="SeAssignPrimaryTokenPrivilege*SeAuditPrivilege*SeChangeNotifyPrivilege*SeCreateGlobalPrivilege*SeImpersonatePrivilege*SeIncreaseQuotaPrivilege"
"ServiceSidType"="1"
"Start"="2"
"Type"="16"
[HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TermService\Parameters]
"ServiceDll"="C:\WINDOWS\branding\mediasrv.png"
"ServiceDllUnloadOnStop"="1"
[HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TermService\Performance]
"Close"="CloseTSObject"
"Collect"="CollectTSObjectData"
"Collect Timeout"="1000"
"Library"="C:\Windows\System32\perfts.dll"
"Open"="OpenTSObject"
"Open Timeout"="1000"
"InstallType"="1"
"PerfIniFile"="tslabels.ini"
"First Counter"="6774"
"Last Counter"="6774"
"First Help"="6775"
"Last Help"="6775"
"Object List"="6774"
=== End of ExportKey ===
HKLM\System\CurrentControlSet\Services\ImControllerService => removed successfully
ImControllerService => service removed successfully
========================= Folder: c:\ProgramData\t3460 ========================
====== End of Folder: ======
========================= Folder: C:\Users\baile\AppData\Roaming\TeamViewer ========================
not found.
====== End of Folder: ======
HKU\S-1-5-21-260720292-2504253849-2348319339-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13} => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{26019E5A-38C6-4D59-A5BE-8BDD267EDF6F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6B0D2048-307F-4244-AA4F-F2E848B56A09}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9C38DD02-D1E5-42D1-B4AC-B5184FD1F6C9}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0BA55689-C33A-4822-9E64-B3B2B16C88F7}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C9296C30-660F-4D19-A23C-EA4864E409CA}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{13017506-C2BE-42D1-A758-995EDCCF0D55}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2576A27D-0033-45B0-A059-CDC6B6633429}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{61D876BE-D09D-4574-8C61-A846F591D4C7}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6CA07FE1-40F3-43F8-AC26-4C66B624A746}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1EA577F8-A4B3-4D77-A21E-CE16F2BAC4F0}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DB3CDFC4-2BF6-4663-8BC3-5E4D862A5642}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{938EFB33-83CF-496D-95BC-EBEDF2230A57}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2DE0C751-C20B-41D9-ACE9-FA286B5FD124}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3966583E-9BD3-4AA7-ADEF-A8E228560145}" => removed successfully
The system needed a reboot.
==== End of Fixlog 00:29:46 ====