Fix result of Farbar Recovery Scan Tool (x64) Version: 25-03-2026 Ran by ahmad (27-03-2026 01:06:57) Run:2 Running from C:\Users\ahmad\Downloads Loaded Profiles: ahmad & WsiAccount Boot Mode: Normal ============================================== fixlist content: ***************** Start:: CreateRestorePoint: CloseProcesses: D:\Dragonkin The Banished v1 2 64 53721-OFME HKU\S-1-5-21-481162469-4243654991-1736207878-1001\...\Run: [AMDNoiseSuppression] => "C:\WINDOWS\system32\AMD\ANR\AMDNoiseSuppression.exe" (No File) Task: {9B753AD3-F4FD-4801-9263-8B2689B1623E} - System32\Tasks\ASUS\Framework Service => C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe --delay (No File) Task: {93DC9CC4-FE27-4DC3-BBD3-298D4CA99F77} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (No File) Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File) Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File) Task: {9252F852-CD65-4FB2-BCA8-F045DC2D219D} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe /s (No File) 2023-05-16 00:40 - 2023-05-16 00:40 - 000005382 _____ () C:\Users\ahmad\AppData\Local\91114846003 2023-02-08 16:29 - 2023-02-08 16:29 - 000005414 _____ () C:\Users\ahmad\AppData\Local\93086452306 CustomCLSID: HKU\S-1-5-21-481162469-4243654991-1736207878-1001_Classes\CLSID\{21211829-c056-cb61-257b-8c61c4fbb5e5}\localserver32 -> "C:\Program Files\ASUS\Virtual Pet\Virtual Pet.exe" -ToastActivated => No File CustomCLSID: HKU\S-1-5-21-481162469-4243654991-1736207878-1001_Classes\CLSID\{28A80003-18FD-411D-B0A3-3C81F618E22B}\InprocServer32 -> C:\Users\ahmad\AppData\Local\Kingsoft\WPS Office\12.2.0.18607\office6\kwpsmenushellext64.dll => No File ContextMenuHandlers1_S-1-5-21-481162469-4243654991-1736207878-1001: [ kwpsshellext] -> {28A80003-18FD-411D-B0A3-3C81F618E22B} => C:\Users\ahmad\AppData\Local\Kingsoft\WPS Office\12.2.0.18607\office6\kwpsmenushellext64.dll -> No File ContextMenuHandlers4_S-1-5-21-481162469-4243654991-1736207878-1001: [ kwpsshellext] -> {28A80003-18FD-411D-B0A3-3C81F618E22B} => C:\Users\ahmad\AppData\Local\Kingsoft\WPS Office\12.2.0.18607\office6\kwpsmenushellext64.dll -> No File AlternateDataStreams: C:\ProgramData\mntemp:8EAD8B3507 [5146] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk:A1B76439FE [5146] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\draw.io.lnk:803345E73D [4290] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk:BE32D07BC5 [5146] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk:B96E9B8455 [4290] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk:C5112377E0 [5146] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk:60EC9648C0 [5146] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook (classic).lnk:BE800952D3 [5146] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk:1DC1525F34 [5146] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk:104946E0EA [5146] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk:7D9589121D [5146] AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [3516] HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION HKU\S-1-5-21-481162469-4243654991-1736207878-1001\Software\Classes\regfile: <==== ATTENTION HKU\S-1-5-21-481162469-4243654991-1736207878-1001\Software\Classes\.reg: => <==== ATTENTION HKU\S-1-5-21-481162469-4243654991-1736207878-1001\Software\Classes\.bat: => <==== ATTENTION HKU\S-1-5-21-481162469-4243654991-1736207878-1001\Software\Classes\.cmd: => <==== ATTENTION cmd: sfc /scannow cmd: DISM.exe /Online /Cleanup-image /Restorehealth cmd: netsh winsock reset catalog cmd: netsh int ip reset C:\resettcpip.txt cmd: Bitsadmin /Reset /Allusers cmd: ipconfig /flushdns Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg C:\Firewall.reg cmd: netsh advfirewall reset cmd: netsh advfirewall set allprofiles state ON RemoveProxy: EmptyTemp: End:: ***************** Restore point was successfully created. Processes closed successfully. "D:\Dragonkin The Banished v1 2 64 53721-OFME" Folder move: Could not move "D:\Dragonkin The Banished v1 2 64 53721-OFME" => Scheduled to move on reboot. "HKU\S-1-5-21-481162469-4243654991-1736207878-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AMDNoiseSuppression" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B753AD3-F4FD-4801-9263-8B2689B1623E}" => not found "C:\WINDOWS\System32\Tasks\ASUS\Framework Service" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS\Framework Service" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{93DC9CC4-FE27-4DC3-BBD3-298D4CA99F77}" => not found "C:\WINDOWS\System32\Tasks\ASUS\P508PowerAgent_sdk" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS\P508PowerAgent_sdk" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => not found "C:\WINDOWS\System32\Tasks\Microsoft\Windows\Location\Notifications" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Location\Notifications" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => not found "C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9252F852-CD65-4FB2-BCA8-F045DC2D219D}" => not found "C:\WINDOWS\System32\Tasks\MSIAfterburner" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MSIAfterburner" => not found "C:\Users\ahmad\AppData\Local\91114846003" => not found "C:\Users\ahmad\AppData\Local\93086452306" => not found HKU\S-1-5-21-481162469-4243654991-1736207878-1001_Classes\CLSID\{21211829-c056-cb61-257b-8c61c4fbb5e5} => not found HKU\S-1-5-21-481162469-4243654991-1736207878-1001_Classes\CLSID\{28A80003-18FD-411D-B0A3-3C81F618E22B} => not found HKU\S-1-5-21-481162469-4243654991-1736207878-1001\Software\Classes\*\ShellEx\ContextMenuHandlers\ kwpsshellext => not found HKU\S-1-5-21-481162469-4243654991-1736207878-1001\Software\Classes\Directory\ShellEx\ContextMenuHandlers\ kwpsshellext => not found "C:\ProgramData\mntemp" => ":8EAD8B3507" ADS not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk" => ":A1B76439FE" ADS not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\draw.io.lnk" => ":803345E73D" ADS not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk" => ":BE32D07BC5" ADS not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk" => ":B96E9B8455" ADS not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk" => ":C5112377E0" ADS not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk" => ":60EC9648C0" ADS not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook (classic).lnk" => ":BE800952D3" ADS not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk" => ":1DC1525F34" ADS not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk" => ":104946E0EA" ADS not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk" => ":7D9589121D" ADS not found. "C:\Users\Public\Shared Files" => ":VersionCache" ADS not found. HKLM\SOFTWARE\Policies\Google => not found HKLM\SOFTWARE\Policies\Microsoft\Edge => not found HKU\S-1-5-21-481162469-4243654991-1736207878-1001\Software\Classes\regfile => not found HKU\S-1-5-21-481162469-4243654991-1736207878-1001\Software\Classes\.reg => not found HKU\S-1-5-21-481162469-4243654991-1736207878-1001\Software\Classes\.bat => not found HKU\S-1-5-21-481162469-4243654991-1736207878-1001\Software\Classes\.cmd => not found ========= sfc /scannow ========= Beginning system scan. This process will take some time. Beginning verification phase of system scan. Verification 0% complete. Verification 1% complete. Verification 1% complete. Verification 2% complete. Verification 2% complete. Verification 3% complete. Verification 3% complete. Verification 4% complete. Verification 4% complete. Verification 5% complete. Verification 5% complete. Verification 6% complete. Verification 6% complete. Verification 7% complete. Verification 7% complete. Verification 8% complete. Verification 8% complete. Verification 9% complete. Verification 9% complete. Verification 10% complete. Verification 10% complete. Verification 11% complete. Verification 12% complete. Verification 12% complete. Verification 13% complete. Verification 13% complete. Verification 14% complete. Verification 14% complete. Verification 15% complete. Verification 15% complete. Verification 16% complete. Verification 16% complete. Verification 17% complete. Verification 17% complete. Verification 18% complete. Verification 18% complete. Verification 19% complete. Verification 19% complete. Verification 20% complete. Verification 20% complete. Verification 21% complete. Verification 21% complete. Verification 22% complete. Verification 23% complete. Verification 23% complete. Verification 24% complete. Verification 24% complete. Verification 25% complete. Verification 25% complete. Verification 26% complete. Verification 26% complete. Verification 27% complete. Verification 27% complete. Verification 28% complete. Verification 28% complete. Verification 29% complete. Verification 29% complete. Verification 30% complete. Verification 30% complete. Verification 31% complete. Verification 31% complete. Verification 32% complete. Verification 32% complete. Verification 33% complete. Verification 34% complete. Verification 34% complete. Verification 35% complete. Verification 35% complete. Verification 36% complete. Verification 36% complete. Verification 37% complete. Verification 37% complete. Verification 38% complete. Verification 38% complete. Verification 39% complete. Verification 39% complete. Verification 40% complete. Verification 40% complete. Verification 41% complete. Verification 41% complete. Verification 42% complete. Verification 42% complete. Verification 43% complete. Verification 43% complete. Verification 44% complete. Verification 45% complete. Verification 45% complete. Verification 46% complete. Verification 46% complete. Verification 47% complete. Verification 47% complete. Verification 48% complete. Verification 48% complete. Verification 49% complete. Verification 49% complete. Verification 50% complete. Verification 50% complete. Verification 51% complete. Verification 51% complete. Verification 52% complete. Verification 52% complete. Verification 53% complete. Verification 53% complete. Verification 54% complete. Verification 54% complete. Verification 55% complete. Verification 55% complete. Verification 56% complete. Verification 57% complete. Verification 57% complete. Verification 58% complete. Verification 58% complete. Verification 59% complete. Verification 59% complete. Verification 60% complete. Verification 60% complete. Verification 61% complete. Verification 61% complete. Verification 62% complete. Verification 62% complete. Verification 63% complete. Verification 63% complete. Verification 64% complete. Verification 64% complete. Verification 65% complete. Verification 65% complete. Verification 66% complete. Verification 66% complete. Verification 67% complete. Verification 68% complete. Verification 68% complete. Verification 69% complete. Verification 69% complete. Verification 70% complete. Verification 70% complete. Verification 71% complete. Verification 71% complete. Verification 72% complete. Verification 72% complete. Verification 73% complete. Verification 73% complete. Verification 74% complete. Verification 74% complete. Verification 75% complete. Verification 75% complete. Verification 76% complete. Verification 76% complete. Verification 77% complete. Verification 77% complete. Verification 78% complete. Verification 79% complete. Verification 79% complete. Verification 80% complete. Verification 80% complete. Verification 81% complete. Verification 81% complete. Verification 82% complete. Verification 82% complete. Verification 83% complete. Verification 83% complete. Verification 84% complete. Verification 84% complete. Verification 85% complete. Verification 85% complete. Verification 86% complete. Verification 86% complete. Verification 87% complete. Verification 87% complete. Verification 88% complete. Verification 88% complete. Verification 89% complete. Verification 90% complete. Verification 90% complete. Verification 91% complete. Verification 91% complete. Verification 92% complete. Verification 92% complete. Verification 93% complete. Verification 93% complete. Verification 94% complete. Verification 94% complete. Verification 95% complete. Verification 95% complete. Verification 96% complete. Verification 96% complete. Verification 97% complete. Verification 97% complete. Verification 98% complete. Verification 98% complete. Verification 99% complete. Verification 99% complete. Verification 100% complete. Windows Resource Protection did not find any integrity violations. ========= End of CMD: ========= ========= DISM.exe /Online /Cleanup-image /Restorehealth ========= Deployment Image Servicing and Management tool Version: 10.0.26100.5074 Image Version: 10.0.26200.8037 [== 3.8% ] [== 4.8% ] [=== 5.7% ] [=== 6.7% ] [==== 7.7% ] [===== 8.7% ] [===== 9.7% ] [====== 10.6% ] [====== 11.6% ] [======= 12.6% ] [======= 13.6% ] [======== 14.6% ] [========= 15.5% ] [========= 16.5% ] [========== 17.5% ] [========== 18.1% ] [========== 18.5% ] [=========== 19.5% ] [=========== 20.5% ] [============ 21.4% ] [============= 22.4% ] [============= 23.4% ] [============== 24.4% ] [============== 25.4% ] [=============== 26.3% ] [=============== 26.5% ] [=============== 26.5% ] [=============== 26.8% ] [================ 27.6% ] [================ 28.4% ] [================ 28.8% ] [================ 28.9% ] [================ 29.1% ] [================= 30.1% ] [================== 31.1% ] [================== 32.1% ] [================== 32.7% ] [=================== 33.4% ] [=================== 34.0% ] [=================== 34.3% ] [==================== 34.5% ] [==================== 34.9% ] [==================== 35.2% ] [==================== 35.9% ] [==================== 36.0% ] [===================== 36.6% ] [===================== 37.2% ] [===================== 37.6% ] [====================== 38.6% ] [====================== 38.9% ] [====================== 39.2% ] [======================= 39.7% ] [======================= 40.0% ] [======================= 40.2% ] [======================= 40.4% ] [======================= 41.2% ] [======================== 42.2% ] [======================== 42.6% ] [========================= 43.2% ] [========================= 44.2% ] [========================== 45.1% ] [========================== 46.1% ] [===========================47.1% ] [===========================48.1% ] [===========================49.1% ] [===========================50.0% ] [===========================51.0% ] [===========================52.0% ] [===========================53.0% ] [===========================53.3% ] [===========================53.3% ] [===========================53.4% ] [===========================53.6% ] [===========================53.6% ] [===========================53.8% ] [===========================53.8% ] [===========================53.9% ] [===========================54.0% ] [===========================54.0% ] [===========================54.0% ] [===========================54.1% ] [===========================54.1% ] [===========================54.2% ] [===========================54.2% ] [===========================54.3% ] [===========================54.3% ] [===========================54.3% ] [===========================54.5% ] [===========================54.6% ] [===========================54.6% ] [===========================54.7% ] [===========================54.7% ] [===========================54.7% ] [===========================54.8% ] [===========================54.8% ] [===========================54.8% ] [===========================54.8% ] [===========================54.8% ] [===========================54.9% ] [===========================54.9% ] [===========================54.9% ] [===========================55.0% ] [===========================55.1% ] [===========================55.1% ] [===========================55.2% ] [===========================55.3% ] [===========================55.3% ] [===========================55.5% ] [===========================55.5% ] [===========================55.6% ] [===========================55.7% ] [===========================55.8% ] [===========================55.9% ] [===========================55.9% ] [===========================56.0% ] [===========================56.0% ] [===========================56.0% ] [===========================56.5% ] [===========================57.4%= ] [===========================58.4%= ] [===========================59.2%== ] [===========================59.2%== ] [===========================59.2%== ] [===========================60.2%== ] [===========================62.3%==== ] [===========================77.4%============ ] [===========================84.9%================= ] [==========================100.0%==========================] The restore operation completed successfully. The operation completed successfully. ========= End of CMD: ========= ========= netsh winsock reset catalog ========= Sucessfully reset the Winsock Catalog. You must restart the computer in order to complete the reset. ========= End of CMD: ========= ========= netsh int ip reset C:\resettcpip.txt ========= Resetting Compartment Forwarding, OK! Resetting Compartment, OK! Resetting Control Protocol, OK! Resetting Echo Sequence Request, OK! Resetting Global, OK! Resetting Interface, OK! Resetting Anycast Address, OK! Resetting Multicast Address, OK! Resetting Unicast Address, OK! Resetting Neighbor, OK! Resetting Path, OK! Resetting Potential, OK! Resetting Prefix Policy, OK! Resetting Proxy Neighbor, OK! Resetting Route, OK! Resetting Site Prefix, OK! Resetting Subinterface, OK! Resetting Wakeup Pattern, OK! Resetting Resolve Neighbor, OK! Resetting , OK! Resetting , OK! Resetting , OK! Resetting , OK! Resetting , failed. Access is denied. Resetting , OK! Resetting , OK! Resetting , OK! Resetting , OK! Resetting , OK! Resetting , OK! Resetting , OK! Resetting , OK! Resetting , OK! Resetting , OK! Restart the computer to complete this action. ========= End of CMD: ========= ========= Bitsadmin /Reset /Allusers ========= BITSADMIN version 3.0 BITS administration utility. (C) Copyright Microsoft Corp. {884B8159-4961-4A86-9858-FFA1BE1848CB} canceled. {50394A40-CF67-4C7E-ACE0-8B27D4CFEFC5} canceled. {C135F781-4114-4425-828E-2FF07CFCDCBC} canceled. {077EBD10-3F2C-4C77-B54E-97211C18ABDC} canceled. 4 out of 4 jobs canceled. ========= End of CMD: ========= ========= ipconfig /flushdns ========= Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========= End of CMD: ========= ========= reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg ========= The operation completed successfully. ========= End of Reg: ========= C:\Firewall.reg => moved successfully ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= ========= netsh advfirewall set allprofiles state ON ========= Ok. ========= End of CMD: ========= ========= RemoveProxy: ========= "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully "HKU\S-1-5-21-481162469-4243654991-1736207878-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\S-1-5-21-481162469-4243654991-1736207878-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully "HKU\S-1-5-21-481162469-4243654991-1736207878-1031\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\S-1-5-21-481162469-4243654991-1736207878-1031\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully ========= End of RemoveProxy: ========= =========== EmptyTemp: ========== FlushDNS => completed BITS transfer queue => 0 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 121216096 B Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 864107860 B Windows/system/drivers => 390699860 B Edge => 1426628725 B Chrome => 56898960 B Firefox => 116774394 B Opera => 0 B Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B systemprofile => 1832 B systemprofile32 => 0 B LocalService => 20738 B NetworkService => 294388 B ahmad => 251706213 B defaultuser100000 => 9216 B WsiAccount => 0 B OracleServiceFREE => 0 B OracleOraDB23Home1TNSListener => 0 B OracleVssWriterFREE => 0 B RecycleBin => 0 B EmptyTemp: => 3 GB temporary data Removed. ================================ Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 27-03-2026 01:43:41) D:\Dragonkin The Banished v1 2 64 53721-OFME => Could not move ==== End of Fixlog 01:43:41 ====