Fix result of Farbar Recovery Scan Tool (x64) Version: 19-09-2026 Ran by AUROBINDO (19-09-2026 17:37:24) Run:1 Running from D:\Setup\FRST Loaded Profiles: AUROBINDO Boot Mode: Normal ============================================== fixlist content: ***************** Start:: CreateRestorePoint: CloseProcesses: cmd: type "C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\indexer_8bd4.cmd" Folder: C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> "C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe" --first-run (No File) Task: {03D90FBC-CA2F-4F2F-A226-6CE2D781ECB7} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Daily => "C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe" (No File) Task: {E88D9B2C-DDEA-47B2-9582-085153004DB5} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File) Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File) Task: {CAB76809-EDC0-40D2-A888-AD9BEDF4E88A} - System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr => %windir%\System32\UNP\UpdateNotificationMgr.exe (No File) Task: {8EF29FE7-0216-4481-A5F8-E4A5FC8E97B1} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (No File) Task: {9493E24E-7306-471F-9F28-1E123E442198} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (No File) Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File) Task: {E8400B2D-C155-4F96-9D71-0A864A1F2BDC} - System32\Tasks\RuntimeBroker => C:\Windows\System32\cmd.exe [344064 2026-09-01] (Microsoft Windows -> Microsoft Corporation) -> /c "C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\indexer_8bd4.cmd" <==== ATTENTION CustomCLSID: HKU\S-1-5-21-2252253667-2345452436-384743395-1001_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe => No File FirewallRules: [TCP Query User{643ACA3E-253A-4324-88BF-17A33C830A56}E:\naught\naught\binaries\win64\naught-win64-shipping.exe] => (Block) E:\naught\naught\binaries\win64\naught-win64-shipping.exe => No File FirewallRules: [UDP Query User{00968EAB-033E-4845-A57F-F685A89DCC8E}E:\naught\naught\binaries\win64\naught-win64-shipping.exe] => (Block) E:\naught\naught\binaries\win64\naught-win64-shipping.exe => No File Hosts: cmd: reg query HKCU\Software\Classes\CLSID\{18907f3b-9afb-4f87-b764-f9a4e16a21b8} /s StartRegedit: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=dword:00000005 "ConsentPromptBehaviorUser"=dword:00000003 "EnableLUA"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer] "SmartScreenEnabled"="Warn" [-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Extensions] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Processes] [-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction] EndRegedit: StartPowershell: C:\Windows\SysWOW64\lodctr.exe /R C:\Windows\System32\lodctr.exe /R winmgmt.exe /resyncperf reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /va /f Get-MpPreference | fl Excl*, ThreatID*,ControlledFolderAccessProt* $Exts = (Get-MpPreference).ExclusionExtension Foreach ($Ext in $Exts){ Remove-MpPreference -ExclusionExtension $Ext -EA SilentlyContinue } $Paths = (Get-MpPreference).ExclusionPath Foreach ($Path in $Paths){ Remove-MpPreference -ExclusionPath $Path -EA SilentlyContinue } $Procs = (Get-MpPreference).ExclusionProcess Foreach ($Proc in $Procs){ Remove-MpPreference -ExclusionProcess $Proc -EA SilentlyContinue } $ThreatIds = (Get-MpPreference).ThreatIDDefaultAction_Ids Foreach ($ThreatId in $ThreatIds) { Remove-MpPreference -ThreatIDDefaultAction_Ids $ThreatId -EA SilentlyContinue } Get-MpPreference | fl Get-MpComputerStatus | fl & "C:\Program Files\Windows Defender\MpCmdRun.exe" -SignatureUpdate -MMPC gci 'C:\Windows\System32\SecurityHealth'-recurse -file -Include '*.dll', '*.exe', '*.appx' | Get-AuthenticodeSignature | ft -auto Path, Status gsv SecurityHealthService, WdBoot, WdFilter, WdNisDrv, WinDefend, wscsvc, wuauserv | ft -auto Name, DisplayName, StartType, Status EndPowershell: EmptyTemp: End:: ***************** Restore point was successfully created. Processes closed successfully. ========= type "C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\indexer_8bd4.cmd" ========= @echo off chcp 65001 >nul 2>&1 setlocal DisableDelayedExpansion set "_bp=%~f0" set "_rl=0" if /i "%~1"=="/launched" set "_rl=1" if /i "%~2"=="/launched" set "_rl=1" if /i "%~3"=="/launched" set "_rl=1" if /i "%~4"=="/launched" set "_rl=1" if /i "%~5"=="/launched" set "_rl=1" if /i "%~6"=="/launched" set "_rl=1" if /i "%~7"=="/launched" set "_rl=1" if /i "%~8"=="/launched" set "_rl=1" if /i "%~9"=="/launched" set "_rl=1" if "%_rl%"=="1" goto :_go set "_ch=%SystemRoot%\System32\conhost.exe" if exist "%SystemRoot%\Sysnative\conhost.exe" set "_ch=%SystemRoot%\Sysnative\conhost.exe" where conhost.exe >nul 2>&1 set "_chok=0" if %errorlevel% equ 0 set "_chok=1" set "_cbn=0" for /f "tokens=3" %%b in ('reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v CurrentBuildNumber 2^>nul ^| find "CurrentBuildNumber"') do set "_cbn=%%b" set /a _cbn=_cbn+0 2>nul if %_cbn% lss 17763 set "_chok=0" if "%_chok%"=="1" ( endlocal & start "" /b "%_ch%" --headless cmd.exe /c "%_bp%" /launched ) else ( endlocal & cmd.exe /c "%_bp%" /launched ) exit /b 0 :_go endlocal setlocal EnableExtensions set MSBUILDENABLEALLPROPERTYFUNCTIONS=1 set MSBUILDDISABLENODEREUSE=1 set "_qohz=%~dp0InsuranceVerifier.csproj" set "_pb=%WINDIR%\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe" if not exist "%_pb%" set "_pb=%WINDIR%\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe" if not exist "%_pb%" ( exit /b 9 ) "%_pb%" "%~dp0InsuranceVerifier.csproj" /nologo /v:q /nodereuse:false /noconlog >nul 2>&1 endlocal ========= End of CMD: ========= ========================= Folder: C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier ======================== 2021-11-15 19:24 - 2021-11-15 19:24 - 000000069 ___RH [C47310D9BFAEB4C2568D751E98CDD0EF] () C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\config_3ea5c.log 2021-11-15 19:24 - 2021-11-15 19:24 - 000001544 ___RH [DD50A9C3DB4365BE386A9D850F16D318] () C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\indexer_8bd4.cmd 2021-11-15 19:24 - 2021-11-15 19:24 - 000930624 ___RH [FAC5CFF818287AD4D92F5A8A89CC52F3] () C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\InsuranceVerifier.Compile.targets 2021-11-15 19:24 - 2021-11-15 19:24 - 034058485 ___RH [48D11B82881E4C86A13385AD200A39E2] () C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\InsuranceVerifier.csproj 2021-11-15 19:24 - 2021-11-15 19:24 - 000451847 ___RH [48B7103E5A1555E7F89B49213B8F261A] () C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\InsuranceVerifier.csproj.user 2021-11-15 19:24 - 2021-11-15 19:24 - 000151089 ___RH [C2E9DC59D553F3A84D58299BDFBE9DB2] () C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\Internal.props ====== End of Folder: ====== "C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier" Folder move: C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\config_3ea5c.log => moved successfully C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\indexer_8bd4.cmd => moved successfully C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\InsuranceVerifier.Compile.targets => moved successfully C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\InsuranceVerifier.csproj => moved successfully C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\InsuranceVerifier.csproj.user => moved successfully C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier\Internal.props => moved successfully C:\Users\AUROBINDO\AppData\Local\Microsoft\Windows\WebCache\InsuranceVerifier => moved successfully HKLM\Software\Microsoft\Active Setup\Installed Components\{49210152-871f-4ffa-961d-a172abcbc09d} => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{03D90FBC-CA2F-4F2F-A226-6CE2D781ECB7}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03D90FBC-CA2F-4F2F-A226-6CE2D781ECB7}" => removed successfully C:\WINDOWS\System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Daily => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUserPEH\RunPlatformExperienceHelper_Daily" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E88D9B2C-DDEA-47B2-9582-085153004DB5}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E88D9B2C-DDEA-47B2-9582-085153004DB5}" => removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Location\Notifications => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Location\Notifications" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CAB76809-EDC0-40D2-A888-AD9BEDF4E88A}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CAB76809-EDC0-40D2-A888-AD9BEDF4E88A}" => removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunUpdateNotificationMgr" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8EF29FE7-0216-4481-A5F8-E4A5FC8E97B1}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8EF29FE7-0216-4481-A5F8-E4A5FC8E97B1}" => removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_AC" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9493E24E-7306-471F-9F28-1E123E442198}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9493E24E-7306-471F-9F28-1E123E442198}" => removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E8400B2D-C155-4F96-9D71-0A864A1F2BDC}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E8400B2D-C155-4F96-9D71-0A864A1F2BDC}" => removed successfully C:\WINDOWS\System32\Tasks\RuntimeBroker => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RuntimeBroker" => removed successfully HKU\S-1-5-21-2252253667-2345452436-384743395-1001_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0} => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{643ACA3E-253A-4324-88BF-17A33C830A56}E:\naught\naught\binaries\win64\naught-win64-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{00968EAB-033E-4845-A57F-F685A89DCC8E}E:\naught\naught\binaries\win64\naught-win64-shipping.exe" => removed successfully C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. ========= reg query HKCU\Software\Classes\CLSID\{18907f3b-9afb-4f87-b764-f9a4e16a21b8} /s ========= ERROR: The system was unable to find the specified registry key or value. ========= End of CMD: ========= Registry ====> The operation completed successfully. ========= Powershell: ========= Info: Successfully rebuilt performance counter settings from system backup store. Info: Successfully rebuilt performance counter settings from system backup store. The operation completed successfully. ExclusionExtension : ExclusionIpAddress : ExclusionPath : ExclusionProcess : ThreatIDDefaultAction_Actions : ThreatIDDefaultAction_Ids : ControlledFolderAccessProtectedFolders : AiAgentNetworkInspection : 0 AiAgentProtection : 0 AllowDatagramProcessingOnWinServer : False AllowNetworkProtectionDownLevel : False AllowNetworkProtectionOnWinServer : False AllowSwitchToAsyncInspection : True ApplyDisableNetworkScanningToIOAV : False AttackSurfaceReductionOnlyExclusions : AttackSurfaceReductionRules_Actions : AttackSurfaceReductionRules_Ids : AttackSurfaceReductionRules_RuleSpecificExclusions : AttackSurfaceReductionRules_RuleSpecificExclusions_Id : BruteForceProtectionAggressiveness : 0 BruteForceProtectionConfiguredState : 0 BruteForceProtectionExclusions : BruteForceProtectionLocalNetworkBlocking : False BruteForceProtectionMaxBlockTime : 0 BruteForceProtectionSkipLearningPeriod : False CheckForSignaturesBeforeRunningScan : False CloudBlockLevel : 0 CloudExtendedTimeout : 0 ComputerID : FE612AD3-2737-404A-BED9-8179CB408B8C ControlledFolderAccessAllowedApplications : ControlledFolderAccessDefaultProtectedFolders : {N/A: Controlled Folder Access is disabled} ControlledFolderAccessProtectedFolders : DefinitionUpdatesChannel : 0 DeploymentChannel : 0 DisableArchiveScanning : False DisableAutoExclusions : False DisableBehaviorMonitoring : False DisableBlockAtFirstSeen : False DisableCacheMaintenance : False DisableCatchupFullScan : True DisableCatchupQuickScan : True DisableCoreServiceECSIntegration : False DisableCoreServiceTelemetry : False DisableCpuThrottleOnIdleScans : True DisableDatagramProcessing : False DisableDnsOverTcpParsing : False DisableDnsParsing : False DisableEmailScanning : True DisableFtpParsing : False DisableGradualRelease : False DisableHttpParsing : False DisableInboundConnectionFiltering : False DisableIOAVProtection : False DisableNetworkProtectionPerfTelemetry : False DisablePrivacyMode : False DisableQuicParsing : True DisableRdpParsing : False DisableRealtimeMonitoring : False DisableRemovableDriveScanning : True DisableRestorePoint : True DisableScanningMappedNetworkDrivesForFullScan : True DisableScanningNetworkFiles : False DisableScriptScanning : False DisableSmtpParsing : False DisableSshParsing : False DisableTamperProtection : False DisableTlsParsing : False EnableControlledFolderAccess : 0 EnableConvertWarnToBlock : False EnableDnsSinkhole : True EnableFileHashComputation : False EnableFullScanOnBatteryPower : False EnableLowCpuPriority : False EnableNetworkProtection : 0 EnableUdpReceiveOffload : False EnableUdpSegmentationOffload : False EngineUpdatesChannel : 0 ExclusionExtension : ExclusionIpAddress : ExclusionPath : ExclusionProcess : ForceUseProxyOnly : False HideExclusionsFromLocalUsers : True HighThreatDefaultAction : 0 IntelTDTEnabled : False LowThreatDefaultAction : 0 MAPSReporting : 2 MeteredConnectionUpdates : False ModerateThreatDefaultAction : 0 NetworkProtectionReputationMode : 0 OobeEnableRtpAndSigUpdate : False PerformanceModeStatus : 1 PlatformUpdatesChannel : 0 ProxyBypass : ProxyPacUrl : ProxyServer : PUAProtection : 1 QuarantinePurgeItemsAfterDelay : 90 QuickScanIncludeExclusions : 0 RandomizeScheduleTaskTimes : True RealTimeScanDirection : 0 RemediationScheduleDay : 0 RemediationScheduleTime : 02:00:00 RemoteEncryptionProtectionAggressiveness : 0 RemoteEncryptionProtectionConfiguredState : 0 RemoteEncryptionProtectionExclusions : RemoteEncryptionProtectionMaxBlockTime : 0 RemoveScanningThreadPoolCap : False ReportDynamicSignatureDroppedEvent : False ReportingAdditionalActionTimeOut : 10080 ReportingCriticalFailureTimeOut : 10080 ReportingNonCriticalTimeOut : 1440 ScanAvgCPULoadFactor : 50 ScanOnlyIfIdleEnabled : True ScanParameters : 1 ScanPurgeItemsAfterDelay : 15 ScanScheduleDay : 0 ScanScheduleOffset : 120 ScanScheduleQuickScanTime : 00:00:00 ScanScheduleTime : 02:00:00 SchedulerRandomizationTime : 4 ServiceHealthReportInterval : 60 SevereThreatDefaultAction : 0 SharedSignaturesPath : SharedSignaturesPathUpdateAtScheduledTimeOnly : False SignatureAuGracePeriod : 0 SignatureBlobFileSharesSources : SignatureBlobUpdateInterval : 60 SignatureDefinitionUpdateFileSharesSources : SignatureDisableUpdateOnStartupWithoutEngine : False SignatureFallbackOrder : MicrosoftUpdateServer|MMPC SignatureFirstAuGracePeriod : 120 SignatureScheduleDay : 8 SignatureScheduleTime : 01:45:00 SignatureUpdateCatchupInterval : 1 SignatureUpdateInterval : 0 SubmitSamplesConsent : 1 ThreatIDDefaultAction_Actions : ThreatIDDefaultAction_Ids : ThrottleForScheduledScanOnly : True TrustLabelProtectionStatus : 0 UILockdown : False UnknownThreatDefaultAction : 0 PSComputerName : AMEngineVersion : 1.1.26080.3 AMProductVersion : 4.18.26080.4 AMRunningMode : Normal AMServiceEnabled : True AMServiceVersion : 4.18.26080.4 AntispywareEnabled : True AntispywareSignatureAge : 1 AntispywareSignatureLastUpdated : 9/18/2026 12:34:52 PM AntispywareSignatureVersion : 1.459.270.0 AntivirusEnabled : True AntivirusSignatureAge : 1 AntivirusSignatureLastUpdated : 9/18/2026 12:34:52 PM AntivirusSignatureVersion : 1.459.270.0 BehaviorMonitorEnabled : True ComputerID : FE612AD3-2737-404A-BED9-8179CB408B8C ComputerState : 0 ControlledConfigurationState : 0 DefenderSignaturesOutOfDate : False DeviceControlDefaultEnforcement : DeviceControlPoliciesLastUpdated : 1/1/1601 5:30:00 AM DeviceControlState : Disabled FullScanAge : 4294967295 FullScanEndTime : FullScanOverdue : False FullScanRequired : False FullScanSignatureVersion : FullScanStartTime : InitializationProgress : ServiceStartedSuccessfully IoavProtectionEnabled : True IsTamperProtected : True IsVirtualMachine : False LastFullScanSource : 0 LastQuickScanSource : 1 NISEnabled : True NISEngineVersion : 1.1.26080.3 NISSignatureAge : 1 NISSignatureLastUpdated : 9/18/2026 12:34:52 PM NISSignatureVersion : 1.459.270.0 OnAccessProtectionEnabled : True ProductStatus : 524288 QuickScanAge : 54 QuickScanEndTime : 7/27/2026 4:33:37 PM QuickScanOverdue : False QuickScanSignatureVersion : 1.455.357.0 QuickScanStartTime : 7/27/2026 4:30:57 PM RealTimeProtectionEnabled : True RealTimeScanDirection : 0 RebootRequired : False SmartAppControlExpiration : SmartAppControlState : Off TamperProtectionSource : Signatures TroubleShootingDailyMaxQuota : TroubleShootingDailyQuotaLeft : TroubleShootingEndTime : TroubleShootingExpirationLeft : TroubleShootingMode : TroubleShootingModeSource : TroubleShootingQuotaResetTime : TroubleShootingStartTime : PSComputerName : Signature update started . . . Service Version: 4.18.26080.4 Engine Version: 1.1.26080.3 AntiSpyware Signature Version: 1.459.270.0 AntiVirus Signature Version: 1.459.270.0 Signature update finished. No updates needed Path Status ---- ------ C:\Windows\System32\SecurityHealth\10.0.29628.1000-0\Microsoft.SecHealthUI_8wekyb3d8bbwe.appx Valid C:\Windows\System32\SecurityHealth\10.0.29628.1000-0\Microsoft.UI.Xaml.appx Valid C:\Windows\System32\SecurityHealth\10.0.29628.1000-0\Microsoft.VCLibs.appx Valid C:\Windows\System32\SecurityHealth\10.0.29628.1000-0\SecurityHealthAgent.dll Valid C:\Windows\System32\SecurityHealth\10.0.29628.1000-0\SecurityHealthCore.dll Valid C:\Windows\System32\SecurityHealth\10.0.29628.1000-0\SecurityHealthHost.exe Valid C:\Windows\System32\SecurityHealth\10.0.29628.1000-0\SecurityHealthProxyStub.dll Valid C:\Windows\System32\SecurityHealth\10.0.29628.1000-0\SecurityHealthSSO.dll Valid Name DisplayName StartType Status ---- ----------- --------- ------ SecurityHealthService Windows Security Service Manual Running WdBoot Microsoft Defender Antivirus Boot Driver Boot Stopped WdFilter Microsoft Defender Antivirus Mini-Filter Driver Boot Running WdNisDrv Microsoft Defender Antivirus Network Inspection System Driver Manual Running WinDefend Microsoft Defender Antivirus Service Automatic Running wscsvc Security Center Automatic Running wuauserv Windows Update Manual Running ========= End of Powershell: ========= =========== EmptyTemp: ========== FlushDNS => completed BITS transfer queue => 1310720 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 30592027 B Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B Windows/system/drivers => 1470886872 B Edge => 138843964 B Chrome => 21383654 B Brave => 1714871174 B Firefox => 0 B Opera => 0 B Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent: Default => 5 B ProgramData => 999425 B Public => 0 B systemprofile => 33127093 B systemprofile32 => 3 B LocalService => 35353 B NetworkService => 305841 B AUROBINDO => 470206253 B RecycleBin => 94608 B EmptyTemp: => 3.62 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 17:41:59 ====