Start:: CreateRestorePoint: CloseProcesses: CustomCLSID: HKU\S-1-5-21-1070632220-2695763294-3121136582-1001_Classes\CLSID\{4e6f7264-5650-4e00-0000-000000000000}\localserver32 -> "C:\Program Files\NordVPN\NordVPN.exe" -ToastActivated => No File ShellIconOverlayIdentifiers: [ .WorkspaceExt0] -> {C568C78A-652C-425B-8E6B-FFA73043302D} => -> No File ShellIconOverlayIdentifiers: [ .WorkspaceExt1] -> {2A6FE247-5DA3-4732-9626-77820518FD77} => -> No File ShellIconOverlayIdentifiers: [ .WorkspaceExt2] -> {FF895810-293B-464A-93F2-82D11E07EEC8} => -> No File AlternateDataStreams: C:\WINDOWS\tracing:? [16] AlternateDataStreams: C:\ProgramData\mntemp:8EAD8B3507 [3442] AlternateDataStreams: C:\ProgramData\system.conf:0F57F3FDE6 [3442] AlternateDataStreams: C:\ProgramData\system.conf:422D4106AB [3442] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk:075A04AA92 [3442] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2022.lnk:638138415C [3442] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk:BE32D07BC5 [3442] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publish or Perish 8.lnk:FE1FDDE9FE [3442] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zotero.lnk:3FAA705B12 [3442] AlternateDataStreams: C:\Users\Public\Documents\rsEngine.config.backup:AC0747FD1A [3442] AlternateDataStreams: C:\Users\Rifky Fauzan\Desktop\FRST64.exe:MBAM.Zone.Identifier [450] FirewallRules: [{5CF33C7C-9C4B-4D88-91F8-B9B0A32A15E9}] => (Allow) C:\Program Files\ASUS\ARMOURY CRATE Service\MobilePlugin\AutoConnectHelper.exe => No File FirewallRules: [UDP Query User{3F1AE855-F431-4393-8E46-C49729F4D476}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\2.50.00.10\webview2runtime\msedgewebview2.exe] => (Allow) C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\2.50.00.10\webview2runtime\msedgewebview2.exe => No File FirewallRules: [TCP Query User{54DB7925-A4EC-45F0-8632-A945A8B723D9}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\2.50.00.10\webview2runtime\msedgewebview2.exe] => (Allow) C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\2.50.00.10\webview2runtime\msedgewebview2.exe => No File FirewallRules: [UDP Query User{ECD5E675-829F-413D-B27D-12C933B05D4D}D:\game steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\game steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [TCP Query User{889B115C-E55E-4B50-9822-4BB7D30F1026}D:\game steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\game steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [UDP Query User{940F5700-1D2B-4589-8175-3AACD46FB157}C:\program files (x86)\folder baru\steam\steamapps\common\marvelrivals\marvelgame\marvel\binaries\win64\marvel-win64-shipping.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\marvelrivals\marvelgame\marvel\binaries\win64\marvel-win64-shipping.exe => No File FirewallRules: [TCP Query User{BD6E96E4-3217-43D5-99F2-3F8131DDD58D}C:\program files (x86)\folder baru\steam\steamapps\common\marvelrivals\marvelgame\marvel\binaries\win64\marvel-win64-shipping.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\marvelrivals\marvelgame\marvel\binaries\win64\marvel-win64-shipping.exe => No File FirewallRules: [UDP Query User{445BE85C-A77E-4391-BA35-EF7307F6F525}C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\ccmini\ccmini_new\ccmini.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\ccmini\ccmini_new\ccmini.exe => No File FirewallRules: [TCP Query User{4161C662-A62A-4EDE-97B1-790EB99A8005}C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\ccmini\ccmini_new\ccmini.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\ccmini\ccmini_new\ccmini.exe => No File FirewallRules: [{4340252b-18ee-4443-aac6-778ad3ab8082}] => (Allow) D:\LDPlayer\LDPlayer9\dnplayer.exe => No File FirewallRules: [UDP Query User{F708FF28-B402-412E-8EE3-919C17B487B0}D:\game xbox\world war z\content\wwzretail.exe] => (Allow) D:\game xbox\world war z\content\wwzretail.exe => No File FirewallRules: [TCP Query User{B5ECDF31-3AE5-4F07-AB40-AAE4317FFA04}D:\game xbox\world war z\content\wwzretail.exe] => (Allow) D:\game xbox\world war z\content\wwzretail.exe => No File FirewallRules: [UDP Query User{1146AD65-D285-4F24-85C5-60CFDEEEC157}D:\game bajakan\pico park\pico_park.exe] => (Allow) D:\game bajakan\pico park\pico_park.exe => No File FirewallRules: [TCP Query User{26119B60-B9DF-4B8B-B061-28A13D9FC32C}D:\game bajakan\pico park\pico_park.exe] => (Allow) D:\game bajakan\pico park\pico_park.exe => No File FirewallRules: [UDP Query User{4C0D1EFE-ECB2-470E-BB08-20647E333E2E}D:\game epic\redout2\redout2\binaries\win64\redout2-win64-shipping.exe] => (Allow) D:\game epic\redout2\redout2\binaries\win64\redout2-win64-shipping.exe => No File FirewallRules: [TCP Query User{990B1525-3467-4319-9723-7B1506B39F08}D:\game epic\redout2\redout2\binaries\win64\redout2-win64-shipping.exe] => (Allow) D:\game epic\redout2\redout2\binaries\win64\redout2-win64-shipping.exe => No File FirewallRules: [UDP Query User{C921B8B4-4356-4CCB-8D7B-355F2C1B480A}C:\users\rifky fauzan\appdata\local\discord\app-1.0.9147\discord.exe] => (Allow) C:\users\rifky fauzan\appdata\local\discord\app-1.0.9147\discord.exe => No File FirewallRules: [TCP Query User{C41EE502-8670-4561-9C53-44652E48BD67}C:\users\rifky fauzan\appdata\local\discord\app-1.0.9147\discord.exe] => (Allow) C:\users\rifky fauzan\appdata\local\discord\app-1.0.9147\discord.exe => No File FirewallRules: [UDP Query User{1FD0FB0B-21D5-4A55-B66F-DF1753779758}D:\wuthering waves\wuthering waves game\client\binaries\win64\client-win64-shipping.exe] => (Allow) D:\wuthering waves\wuthering waves game\client\binaries\win64\client-win64-shipping.exe => No File FirewallRules: [TCP Query User{39738E79-3815-4DF5-A7A6-DF2C78482272}D:\wuthering waves\wuthering waves game\client\binaries\win64\client-win64-shipping.exe] => (Allow) D:\wuthering waves\wuthering waves game\client\binaries\win64\client-win64-shipping.exe => No File FirewallRules: [UDP Query User{99B9877D-C885-438A-8893-B803A9D91117}D:\game bajakan\pummel party\pummelparty.exe] => (Allow) D:\game bajakan\pummel party\pummelparty.exe => No File FirewallRules: [TCP Query User{36AF805F-5FED-431F-9361-8EC964630665}D:\game bajakan\pummel party\pummelparty.exe] => (Allow) D:\game bajakan\pummel party\pummelparty.exe => No File FirewallRules: [{B5414662-D5A3-4954-B21C-E116DB2217AB}] => (Allow) C:\Program Files (x86)\360\Total Security\360TsLiveUpd.exe => No File FirewallRules: [{C21D619A-75EF-4BF8-87D3-6B2C9FDB9CDD}] => (Allow) C:\Program Files (x86)\360\Total Security\360TsLiveUpd.exe => No File FirewallRules: [{3D0645C8-15F1-49B0-9651-2594E26DF931}] => (Allow) C:\Users\Rifky Fauzan\AppData\Roaming\BitTorrent\BitTorrent.exe => No File FirewallRules: [{E71B8812-A841-4143-A80A-DD5B58B1B223}] => (Allow) C:\Users\Rifky Fauzan\AppData\Roaming\BitTorrent\BitTorrent.exe => No File FirewallRules: [UDP Query User{88197C24-CC8E-418F-A522-43E43D48183E}D:\game bajakan\ready or not\readyornot\binaries\win64\readyornot-win64-shipping.exe] => (Allow) D:\game bajakan\ready or not\readyornot\binaries\win64\readyornot-win64-shipping.exe => No File FirewallRules: [TCP Query User{410D2F41-FEF6-4B89-A64B-98FC7471774A}D:\game bajakan\ready or not\readyornot\binaries\win64\readyornot-win64-shipping.exe] => (Allow) D:\game bajakan\ready or not\readyornot\binaries\win64\readyornot-win64-shipping.exe => No File FirewallRules: [UDP Query User{626DC06D-4AAC-445A-82FC-B7F40315017F}D:\game epic\rocketleague\binaries\win64\rocketleague.exe] => (Allow) D:\game epic\rocketleague\binaries\win64\rocketleague.exe => No File FirewallRules: [TCP Query User{4D2A4A34-47E0-48E8-9E33-4EE988F21E26}D:\game epic\rocketleague\binaries\win64\rocketleague.exe] => (Allow) D:\game epic\rocketleague\binaries\win64\rocketleague.exe => No File FirewallRules: [UDP Query User{7E97962A-FB3C-4DB2-864D-87B74E111E80}D:\game steam\steamapps\common\need for speed heat\needforspeedheat.exe] => (Allow) D:\game steam\steamapps\common\need for speed heat\needforspeedheat.exe => No File FirewallRules: [TCP Query User{BB2E0DDD-C3E3-44B3-B664-FF3AC0CFDC63}D:\game steam\steamapps\common\need for speed heat\needforspeedheat.exe] => (Allow) D:\game steam\steamapps\common\need for speed heat\needforspeedheat.exe => No File FirewallRules: [UDP Query User{FE29DF77-8771-4331-8A22-BEB70E764B84}C:\users\rifky fauzan\appdata\local\programs\rave-desktop\rave.exe] => (Allow) C:\users\rifky fauzan\appdata\local\programs\rave-desktop\rave.exe => No File FirewallRules: [TCP Query User{BF4C7075-556A-4D64-99C8-33B829AADF81}C:\users\rifky fauzan\appdata\local\programs\rave-desktop\rave.exe] => (Allow) C:\users\rifky fauzan\appdata\local\programs\rave-desktop\rave.exe => No File FirewallRules: [UDP Query User{6FAAD2D4-37D1-413C-9FE5-3F2654BD45AC}D:\game steam\steamapps\common\kartrider drift\kartdrift\binaries\win64\kartdrift-win64-shipping.exe] => (Allow) D:\game steam\steamapps\common\kartrider drift\kartdrift\binaries\win64\kartdrift-win64-shipping.exe => No File FirewallRules: [TCP Query User{44E7FC2B-2F57-48B4-AAD8-B23F9BB521EC}D:\game steam\steamapps\common\kartrider drift\kartdrift\binaries\win64\kartdrift-win64-shipping.exe] => (Allow) D:\game steam\steamapps\common\kartrider drift\kartdrift\binaries\win64\kartdrift-win64-shipping.exe => No File FirewallRules: [{8D1AB8AB-102F-4B9D-8091-B79D8C8D15E6}] => (Allow) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_4fc38a913e0f2ea5\ASUSLinkRemote\AsusLinkRemoteAgent.exe => No File FirewallRules: [{C91839F8-8D29-4F1C-9EFF-AD5E55060390}] => (Allow) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_4fc38a913e0f2ea5\ASUSLinkRemote\AsusLinkRemoteAgent.exe => No File FirewallRules: [{94B62FEA-6C8B-4B2A-8F36-BF2EC591A365}] => (Allow) D:\game steam\steamapps\common\raceroom racing experience\Game\RRRE.exe => No File FirewallRules: [{776984E7-DE94-4ADB-ACBA-7ED9A4642898}] => (Allow) D:\game steam\steamapps\common\raceroom racing experience\Game\RRRE.exe => No File FirewallRules: [{2BE24D4F-809B-49B2-A759-9BF51C53105B}] => (Allow) D:\game steam\steamapps\common\raceroom racing experience\Game\x64\RRRE64.exe => No File FirewallRules: [{621D9A06-EBB6-486A-AA16-21AE26F297E2}] => (Allow) D:\game steam\steamapps\common\raceroom racing experience\Game\x64\RRRE64.exe => No File FirewallRules: [UDP Query User{BD34AC60-1749-43C2-B690-7C59FAFBAB14}D:\game steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe] => (Allow) D:\game steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe => No File FirewallRules: [TCP Query User{B8B0C420-6920-4196-84B1-E1020D1D4457}D:\game steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe] => (Allow) D:\game steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe => No File FirewallRules: [UDP Query User{87D98ED1-43DE-4580-8130-2B95BCB56F82}D:\game steam\steamapps\common\battlefield 2042\bf2042.exe] => (Allow) D:\game steam\steamapps\common\battlefield 2042\bf2042.exe => No File FirewallRules: [TCP Query User{EFA8158F-4A93-4C08-BF6B-CF9C722FFEC5}D:\game steam\steamapps\common\battlefield 2042\bf2042.exe] => (Allow) D:\game steam\steamapps\common\battlefield 2042\bf2042.exe => No File FirewallRules: [UDP Query User{8DEC17F0-3A48-454E-AC39-05F4709B86BB}C:\program files (x86)\overwatch\_retail_\overwatch.exe] => (Allow) C:\program files (x86)\overwatch\_retail_\overwatch.exe => No File FirewallRules: [TCP Query User{2E9B09AD-8FC2-4CFE-8A98-3C9F7B59CAF7}C:\program files (x86)\overwatch\_retail_\overwatch.exe] => (Allow) C:\program files (x86)\overwatch\_retail_\overwatch.exe => No File FirewallRules: [UDP Query User{345B0E6E-E1A8-44AD-9C39-AFEA3BAD41DE}C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\narakabladepoint.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\narakabladepoint.exe => No File FirewallRules: [TCP Query User{97E57F5A-15B3-47C5-B693-CD0AC4EBE56C}C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\narakabladepoint.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\narakabladepoint.exe => No File FirewallRules: [UDP Query User{0ED77822-E4B7-4ABE-8B36-FD0B9790F321}C:\program files (x86)\folder baru\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [TCP Query User{E6170B60-61F0-4864-AB72-1D1CB050D8F7}C:\program files (x86)\folder baru\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File FirewallRules: [UDP Query User{0C7F6D07-06B8-4F05-AFF9-B1BB19BBB6A5}C:\program files (x86)\folder baru\steam\steamapps\common\need for speed heat\needforspeedheat.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\need for speed heat\needforspeedheat.exe => No File FirewallRules: [TCP Query User{250D9F0B-445A-4902-8654-BD7E6F41E487}C:\program files (x86)\folder baru\steam\steamapps\common\need for speed heat\needforspeedheat.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\need for speed heat\needforspeedheat.exe => No File FirewallRules: [{1ECBA98F-43B7-4890-85C7-697DFCB09FE6}] => (Allow) C:\Program Files (x86)\Folder Baru\steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe => No File FirewallRules: [{52CCB2CB-C7D5-4547-9009-62F4FD0CBEBE}] => (Allow) C:\Program Files (x86)\Folder Baru\steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe => No File FirewallRules: [{6847C997-DCEF-4F31-97F7-5006D219F0FD}] => (Allow) C:\Program Files (x86)\Folder Baru\steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File FirewallRules: [{AD2BB4F5-0753-4045-BF7F-20AC9C271675}] => (Allow) C:\Program Files (x86)\Folder Baru\steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File FirewallRules: [{900047A5-CE77-4071-A0DF-557AD30496FC}] => (Allow) D:\steam\Steam.exe => No File FirewallRules: [{829F5EAB-D7F2-4796-A662-4A3A6F32598F}] => (Allow) D:\steam\Steam.exe => No File FirewallRules: [TCP Query User{B585681C-6783-4E4A-86A2-94ADF50CAF94}D:\game epic\worldwarz\en_us\client\bin\pc\wwzretailegs.exe] => (Allow) D:\game epic\worldwarz\en_us\client\bin\pc\wwzretailegs.exe => No File FirewallRules: [UDP Query User{F47817C2-4368-499A-B835-3A82D6EB5990}D:\game epic\worldwarz\en_us\client\bin\pc\wwzretailegs.exe] => (Allow) D:\game epic\worldwarz\en_us\client\bin\pc\wwzretailegs.exe => No File FirewallRules: [TCP Query User{C9929816-2B4D-46A4-B8A2-E6301C496E1F}D:\game steam\steamapps\common\fragpunk\fragpunk\binaries\win64\fragpunk.exe] => (Allow) D:\game steam\steamapps\common\fragpunk\fragpunk\binaries\win64\fragpunk.exe => No File FirewallRules: [UDP Query User{604B8C5F-33A4-4756-8F79-88DDF41542C8}D:\game steam\steamapps\common\fragpunk\fragpunk\binaries\win64\fragpunk.exe] => (Allow) D:\game steam\steamapps\common\fragpunk\fragpunk\binaries\win64\fragpunk.exe => No File FirewallRules: [TCP Query User{01A9F218-9FDC-45EB-8C31-C7D4142BE35F}D:\game bajakan\headbangers rhythm royale\headbangers.exe] => (Allow) D:\game bajakan\headbangers rhythm royale\headbangers.exe => No File FirewallRules: [UDP Query User{40F84DBA-074E-42F2-90C4-6E07A06B1B84}D:\game bajakan\headbangers rhythm royale\headbangers.exe] => (Allow) D:\game bajakan\headbangers rhythm royale\headbangers.exe => No File FirewallRules: [TCP Query User{52EBB557-329A-47B5-A50B-65B89FEE3918}D:\game bajakan\headbangers rhythm royale\unitycrashhandler64.exe] => (Allow) D:\game bajakan\headbangers rhythm royale\unitycrashhandler64.exe => No File FirewallRules: [UDP Query User{292983ED-A345-4207-973A-BD88BF8AF565}D:\game bajakan\headbangers rhythm royale\unitycrashhandler64.exe] => (Allow) D:\game bajakan\headbangers rhythm royale\unitycrashhandler64.exe => No File FirewallRules: [TCP Query User{00D44F79-0457-467D-BFF8-546CF6BC891F}C:\program files (x86)\folder baru\steam\steamapps\common\bloodstrike\engine\binaries\win64\bloodstrike.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\bloodstrike\engine\binaries\win64\bloodstrike.exe => No File FirewallRules: [UDP Query User{06316466-8B3A-4DAA-A14E-13B93241CE1B}C:\program files (x86)\folder baru\steam\steamapps\common\bloodstrike\engine\binaries\win64\bloodstrike.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\bloodstrike\engine\binaries\win64\bloodstrike.exe => No File FirewallRules: [TCP Query User{41F7DACC-8BAB-4338-9730-A8F819DDDEC9}D:\punishing gray raven\punishing gray raven game\pgr.exe] => (Allow) D:\punishing gray raven\punishing gray raven game\pgr.exe => No File FirewallRules: [UDP Query User{AD8B4EF1-8880-40EA-9EF1-087A5D338011}D:\punishing gray raven\punishing gray raven game\pgr.exe] => (Allow) D:\punishing gray raven\punishing gray raven game\pgr.exe => No File FirewallRules: [TCP Query User{87BB3253-A08D-4463-9014-353C13E905F2}D:\coaglobalgame\seria\binaries\win64\seria.exe] => (Allow) D:\coaglobalgame\seria\binaries\win64\seria.exe => No File FirewallRules: [UDP Query User{2EA04480-34E7-46CF-8297-36BD2DB4B423}D:\coaglobalgame\seria\binaries\win64\seria.exe] => (Allow) D:\coaglobalgame\seria\binaries\win64\seria.exe => No File FirewallRules: [TCP Query User{54555CA6-3F16-4A1B-9C49-A4E722F84AAB}D:\game bajakan\make way\make way.exe] => (Allow) D:\game bajakan\make way\make way.exe => No File FirewallRules: [UDP Query User{85702DDE-C4D0-43F8-B672-240AE3BC69B8}D:\game bajakan\make way\make way.exe] => (Allow) D:\game bajakan\make way\make way.exe => No File FirewallRules: [TCP Query User{D854AF06-0BDD-4048-8164-DF4DEA152CB2}D:\game bajakan\rematch\runtime\binaries\wingdk\runtimeclient-wingdk-shipping.exe] => (Allow) D:\game bajakan\rematch\runtime\binaries\wingdk\runtimeclient-wingdk-shipping.exe => No File FirewallRules: [UDP Query User{21ABFA1B-2E22-4D81-83E6-9E02B2935BB8}D:\game bajakan\rematch\runtime\binaries\wingdk\runtimeclient-wingdk-shipping.exe] => (Allow) D:\game bajakan\rematch\runtime\binaries\wingdk\runtimeclient-wingdk-shipping.exe => No File FirewallRules: [{4869E918-6FA2-4A49-BE54-AAD24B2ADDE8}] => (Allow) C:\Program Files\ASUS\ARMOURY CRATE Service\MobilePlugin\AutoConnectHelper.exe => No File FirewallRules: [{A4E5143E-3EA9-4FFD-89B1-6C6C01CD4C71}] => (Allow) C:\Program Files\ASUS\ARMOURY CRATE Service\MobilePlugin\AutoConnectHelper.exe => No File FirewallRules: [{CD1B492D-372F-4B75-9405-10B43C5B98A8}] => (Allow) C:\Users\Rifky Fauzan\AppData\Local\Temp\ACFL20250704071530\ACSetup\ACSetup.exe => No File FirewallRules: [{A043ECB3-7E33-4234-93D6-12060D5FEA77}] => (Allow) C:\Users\Rifky Fauzan\AppData\Local\Temp\ACFL20250704071530\ACSetup\ACSetup.exe => No File FirewallRules: [TCP Query User{61BCB877-975B-41E7-97FE-A0C1F9939C3C}D:\game bajakan\monsterhunterwilds\monsterhunterwilds.exe] => (Allow) D:\game bajakan\monsterhunterwilds\monsterhunterwilds.exe => No File FirewallRules: [UDP Query User{C5A9A206-A627-4FA1-80F8-74CB954510F2}D:\game bajakan\monsterhunterwilds\monsterhunterwilds.exe] => (Allow) D:\game bajakan\monsterhunterwilds\monsterhunterwilds.exe => No File FirewallRules: [TCP Query User{A46AF5AF-90E0-452F-A252-31B5E60FD40E}D:\game bajakan\cloudheim\protocat\binaries\win64\cloudheimsteam-win64-shipping.exe] => (Allow) D:\game bajakan\cloudheim\protocat\binaries\win64\cloudheimsteam-win64-shipping.exe => No File FirewallRules: [UDP Query User{2D293B4E-CA0F-44AD-8AC5-3552BABC0572}D:\game bajakan\cloudheim\protocat\binaries\win64\cloudheimsteam-win64-shipping.exe] => (Allow) D:\game bajakan\cloudheim\protocat\binaries\win64\cloudheimsteam-win64-shipping.exe => No File FirewallRules: [{E4C9F122-F9BB-4D3E-840B-72AE2F33C5F0}] => (Allow) C:\Program Files (x86)\Folder Baru\steam\steamapps\common\Apex Legends\start_protected_game.exe => No File FirewallRules: [{6DA2273C-A1AE-4949-B673-6A552FC7C2F9}] => (Allow) C:\Program Files (x86)\Folder Baru\steam\steamapps\common\Apex Legends\start_protected_game.exe => No File FirewallRules: [{87D3A10A-4045-4AC8-94FA-211AB58F003C}] => (Allow) C:\Users\Rifky Fauzan\AppData\Local\Temp\ACFL\ACSetup\ACSetup.exe => No File FirewallRules: [{E59191C0-6F08-44C6-BFA1-62C518DB942C}] => (Allow) C:\Users\Rifky Fauzan\AppData\Local\Temp\ACFL\ACSetup\ACSetup.exe => No File FirewallRules: [TCP Query User{8F959C4E-B10E-4A73-A705-C525FAF107D2}D:\game bajakan\vanguard\cardfight!! vanguard dear days 2\vgdd2.exe] => (Allow) D:\game bajakan\vanguard\cardfight!! vanguard dear days 2\vgdd2.exe => No File FirewallRules: [UDP Query User{55B9A6F3-7CC0-4885-B423-BC240195069F}D:\game bajakan\vanguard\cardfight!! vanguard dear days 2\vgdd2.exe] => (Allow) D:\game bajakan\vanguard\cardfight!! vanguard dear days 2\vgdd2.exe => No File HKU\S-1-5-21-1070632220-2695763294-3121136582-1001\...\Run: [Rave] => "C:\Users\Rifky Fauzan\AppData\Local\Programs\rave-desktop\Rave.exe" --hidden (No File) HKU\S-1-5-21-1070632220-2695763294-3121136582-1001\...\Run: [AF_uuid_514912] => 53c25f9f-58bd-43f4-9a9e-25e64cf2b839**e*\***************f**|***€GOCSPX-s (No File) HKU\S-1-5-21-1070632220-2695763294-3121136582-1001\...\Run: [AF_counter_514912] => 1 (No File) HKU\S-1-5-21-1070632220-2695763294-3121136582-1001\...\MountPoints2: {77135f4d-7826-11ed-a95d-505a65063c64} - "E:\setup.exe" Task: {58EF3C6E-D7B7-4A03-B443-6EF349D02164} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (No File) Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File) Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File) CHR HKU\S-1-5-21-1070632220-2695763294-3121136582-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dpadflhmiohjfhhaehelneimpllfbpcg] - C:\Users\Rifky Fauzan\AppData\Roam S3 ace-game-0; \SystemRoot\System32\drivers\ace-game-0.sys (No File) S3 NEProtect; \??\C:\Program Files (x86)\Folder Baru\steam\steamapps\common\BLOODSTRIKE\Engine\Binaries\Win64\NEProtect.sys (No File) 2026-07-02 23:29 - 2026-07-14 00:33 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\0b5e9b57a31dad4854415695873a1ad8f46a3c20b88e48efb7b2a96771e65bd9 2026-07-02 23:29 - 2026-07-02 23:29 - 000000026 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\29c0fc0f474cba4b579efb637113ed0a327d65af2258e235e2348ee72c8a7759 2026-07-14 08:48 - 2024-06-19 22:40 - 000042147 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\e8b8c38bc0813bee691394e17cde8da390a0e65ee924b2b3ea21d7e1bf2281f6 2026-07-14 08:44 - 2024-06-18 03:17 - 003270114 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\48175e76c0ff4e749e851f1f852c4355d6296fb912d5143b0a98400c90511d05 2026-07-14 06:46 - 2024-06-28 16:43 - 000059481 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\7e9486d5a9a71bdc94996a35dc80ce734de68bcbcaf557324f29a0d44251a630 2026-07-14 06:43 - 2024-06-18 07:31 - 001915645 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\cce47a310a2b6b5eb724cd7e159b5e69a9bfbcdfa607a503016b50e97460decd 2026-07-14 06:38 - 2025-09-19 13:27 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\7e681db666f22e0881505caef1f2069b31a0c71723fa40ef97b010913bbb0dd3 2026-07-14 06:31 - 2024-06-18 03:12 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\fbfe924ddb0464555ab0c1c3d6102a5c9c9a52b2b7c64e410edea756513d4ae4 2026-07-14 06:26 - 2024-08-26 17:03 - 000235270 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\3fde5216d2193240953c50de719ec957029f8d481810cb6be21e28129c17e0ea 2026-07-14 06:26 - 2024-08-26 17:03 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\7a30513e4032e80317004bfdff927d304a9f6e33d1d4d0a20426d318a1097f65 2026-07-14 06:26 - 2024-06-18 03:17 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\8d9f96ac0c81c4e109d1cbc5c849f4f0dcb5608abc0b55fd1734084a9d98342f 2026-07-14 06:15 - 2025-12-19 09:11 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\ca54b7cb4433a88da9612a9640d081082330ea768a5b2060c150e2d8a4731849 2026-07-14 06:14 - 2025-12-19 09:11 - 000966645 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\a7f7d656671c63f1edaa9ea613e376df328a91ef84a4438781013710fdc99068 2026-07-14 06:13 - 2025-12-19 09:11 - 000162556 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\c4beba2be83db5339b4f4173ce80666ec40750869f30c769de436300b3d875f2 2026-07-14 06:09 - 2025-07-28 08:26 - 000011216 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\e69ac24fe51cbd89a2862988dc23a8cd7e018583b57ce57bc0e8def010b5a5ce 2026-07-14 06:09 - 2024-06-18 03:11 - 000011216 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\538164be095319c9b35dd4523563bb2c05ff19c435a7794a0a56839bf802f3f6 2026-07-13 02:42 - 2025-11-16 19:28 - 000218675 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\4d056e1e29ec3c97750cf4a824471911c81bb102e8ed5157bea4ae3c18d81f05 2026-07-11 07:06 - 2024-07-18 20:12 - 000451745 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\062e0a2c15d8c229ab7c0bd25f71169a5cd5708c9dc7e4e8b31ff22ac7cc4411 2026-07-10 13:42 - 2024-08-08 16:02 - 000026882 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\8fadcb6a0d2bde06c5228769a5e71700102081a7191b21c706f6f4cb7c181b5d 2026-07-10 13:42 - 2024-08-08 16:02 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\a94f18ec458804c64b885271466f36a2681a2a7db80a5f9c50026cdf591b4211 2026-07-10 12:47 - 2025-06-06 03:06 - 000011216 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\ef7d34d7619787f6d1f2dc9f3da47c2417d0e4beef68371dd16fc8a4dfd83d59 2026-07-10 05:03 - 2025-06-06 03:06 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\62d829d95bb90bf102b4c2c6c78a555faf5a11242184bddc20a7039cd326e62c 2026-06-28 07:00 - 2025-11-16 19:28 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\a5afe75980b197a4f53b602b005671be082663031a53a86b6fd08117daac4704 2025-02-27 22:42 - 2025-02-27 22:42 - 000000024 _____ () C:\Users\Rifky Fauzan\AppData\Roaming\C23W6Vk43XTwu662.dat 2024-12-10 16:55 - 2024-12-10 16:55 - 000000048 ____R () C:\Users\Rifky Fauzan\AppData\Local\289997B9FC4FEEDE6DEF9AA33BCCA370 2025-05-11 17:44 - 2025-05-11 17:44 - 000000036 _____ () C:\Users\Rifky Fauzan\AppData\Local\4051BDD0000f042.pyo 2025-11-16 19:35 - 2025-11-16 19:35 - 000000048 ____R () C:\Users\Rifky Fauzan\AppData\Local\62548010F1356EF5554868D4EB2F2A25 2025-03-10 02:42 - 2025-03-10 02:42 - 000000048 ____R () C:\Users\Rifky Fauzan\AppData\Local\7288E29716A5FF2D4E06A4EAF635BD33 2026-05-31 23:59 - 2026-05-31 23:59 - 000000048 ____R () C:\Users\Rifky Fauzan\AppData\Local\AB94542F5FADE6F8B81D4B79C11311EF 2025-05-11 17:32 - 2025-05-11 17:32 - 000000048 ____R () C:\Users\Rifky Fauzan\AppData\Local\F1DD43B9BE218E8E2550DBF370E02D28 Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1653.5 - AVAST Software) Hidden 2026-07-14 06:13 - 2026-07-14 06:13 - 000114688 _____ () [File not signed] \\?\C:\Users\Rifky Fauzan\AppData\Local\Temp\35d1313a-5a14-4fb1-b411-7c9c5e596ab3.tmp.node HKU\S-1-5-21-1070632220-2695763294-3121136582-1001\...\Run: [MicrosoftEdgeAutoLaunch_908D2254D8BEE7E1651F33060FC32228] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4970824 2026-07-09] (Microsoft Corporation -> Microsoft Corporation) Task: {C51E5450-3A06-45C6-87C8-5A543AD57837} - System32\Tasks\BackgroundTask => C:\Windows\System32\cmd.exe [348160 2026-06-10] (Microsoft Windows -> Microsoft Corporation) -> /c "C:\Users\Rifky Fauzan\AppData\Local\Microsoft\Windows\WebCache\bootstrap_3b40.cmd" C:\Users\Rifky Fauzan\AppData\Local\Microsoft\Windows\WebCache CHR DefaultSuggestURL: Default -> hxxps://id.search.yahoo.com/sugg/gossip/gossip-id-partner?output=fxjson&appid=mca&source=yahoo_mcafee_searchassist&command={searchTerms} CHR DefaultSearchURL: Default -> hxxps://id.search.yahoo.com/search?fr=mcafee&type=E210ID885G0&p={searchTerms} Edge HKLM-x32\...\Edge\Extension: [fdhgeoginicibhagdmblfikbgbkahibd] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] 2026-07-14 04:00 - 2026-07-14 04:00 - 000003524 _____ C:\WINDOWS\system32\Tasks\BackgroundTask 2026-07-14 06:15 - 2024-06-18 07:31 - 000002650 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\2ed50ab3386a4fc9cf53DcJHrrHSgvFpsYxqb6g97uaQTd2kE31rPUeDZTeDsjVq 2026-07-14 00:33 - 2024-11-29 01:41 - 000000000 ____D C:\temp 2026-07-11 07:33 - 2024-07-18 20:12 - 000000466 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\d57efd2e9415e4a6500c4c130c77805d6dd5c319eWJh8J6Mx9DrGXKEv3ojKmqw8Cv9pscK StartPowershell: # Replace /scanonly with /clean if you also want to delete items -- however, this will activate a trial license on the system, I do not recommend it $hmpExe = "$env:TEMP\HitmanPro_x64.exe" $logFile = "$env:TEMP\HitmanPro_ScanLog.txt" Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing $proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 } Get-Content $logFile -Encoding Unicode EndPowershell: StartPowerShell: # Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console # Does not clean preinstalled objects, only PUP/Adware # If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument # If you would like to only scan with it, change the argument from /clean to /scan # NOTE: For the sake of users from Asia (primarily China), do not use the clean option. It will very likely remove a lot of their important software. New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden $logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt" Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile Get-Content $logFile -Encoding Unicode Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue EndPowerShell: Comment: List Windows Defender properties, settings StartPowerShell: function Write-Section { param([string]$Title) Write-Host "" Write-Host "<=== $Title ===>" } Write-Section "Protection Status" Get-MpComputerStatus | Select-Object AMServiceEnabled, AntispywareEnabled, AntivirusEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, RealTimeProtectionEnabled, IsTamperProtected, NetworkProtectionStatus | Format-List Write-Section "Signature / Engine Versions" Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AntivirusSignatureVersion, AntispywareSignatureVersion | Format-List Write-Section "Preferences / Configuration" Get-MpPreference | Select-Object PUAProtection, MAPSReporting, SubmitSamplesConsent, CheckForSignaturesBeforeRunningScan, CloudBlockLevel, EnableNetworkProtection, DisableScriptScanning, DisableArchiveScanning, DisableRemovableDriveScanning, DisableScanningNetworkFiles, DisableScanningMappedNetworkDrivesForFullScan, DisableBlockAtFirstSeen, DisableHeuristics, DisableAutoExclusions | Format-List Write-Section "Threat Detections" $threats = Get-MpThreatDetection if ($threats) { $threats | Format-Table -AutoSize } else { Write-Host " (no threat detections found)" } EndPowerShell: Comment: List drive info, identify possible damaged drives (thanks to AdvancedSetup from Malwarebytes for parts of these) StartPowerShell: param( [int]$MaxEvents = 2000 ) $GPTTypeMap = @{ 'EBD0A0A2-B9E5-4433-87C0-68B6B72699C7' = 'Microsoft Basic Data' 'E3C9E316-0B5C-4DB8-817D-F92DF00215AE' = 'Microsoft Reserved (MSR)' 'DE94BBA4-06D1-4D40-A16A-BFD50179D6AC' = 'Windows Recovery Environment (WinRE)' 'C12A7328-F81F-11D2-BA4B-00A0C93EC93B' = 'EFI System Partition' '21686148-6449-6E6F-744E-656564454649' = 'BIOS Boot Partition' 'A19D880F-05FC-4D3B-A006-743F0F84911E' = 'OEM Partition' '5808C8AA-7E8F-42E0-85D2-E1E90434CFB3' = 'Cluster Metadata Partition' '48465300-0000-11AA-AA11-00306543ECAC' = 'Apple HFS/HFS+' '7C3457EF-0000-11AA-AA11-00306543ECAC' = 'Apple APFS' '0FC63DAF-8483-4772-8E79-3D69D8477DE4' = 'Linux Filesystem' '0657FD6D-A4AB-43C4-84E5-0933C84B4F4F' = 'Linux Swap' 'E6D6D379-F507-44C2-A23C-238F2A3DF928' = 'Linux LVM' } $MBRTypeMap = @{ '01'='FAT12';'04'='FAT16 <32M';'05'='Extended';'06'='FAT16';'07'='IFS/NTFS/exFAT/HPFS';'0B'='FAT32 CHS';'0C'='FAT32 LBA';'0E'='FAT16 LBA' '0F'='Extended LBA';'82'='Linux Swap';'83'='Linux Native';'8E'='Linux LVM';'A5'='FreeBSD';'A6'='OpenBSD';'A8'='Mac OS X';'AB'='Mac OS X Boot' 'AF'='Mac OS X HFS';'EE'='EFI GPT Protective';'EF'='EFI System Partition' } function Get-PartitionTypeInfo { param($Partition) $guid = $null if ($Partition.GptType) { $guid = ($Partition.GptType -replace '[{}]', '').ToUpper() } if ([string]::IsNullOrWhiteSpace($guid) -or $guid -eq '00000000-0000-0000-0000-000000000000') { $guid = switch ($Partition.Type) { "System" { "C12A7328-F81F-11D2-BA4B-00A0C93EC93B" } "Reserved" { "E3C9E316-0B5C-4DB8-817D-F92DF00215AE" } "Basic" { "EBD0A0A2-B9E5-4433-87C0-68B6B72699C7" } "Recovery" { "DE94BBA4-06D1-4D40-A16A-BFD50179D6AC" } default { $null } } } if ($guid) { $name = $GPTTypeMap[$guid] if ($name) { return "$name (GPT GUID: $($guid.ToLower()))" } else { return "Unknown/Custom (GPT GUID: $($guid.ToLower()))" } } if ($Partition.MbrType) { $code = ($Partition.MbrType.ToString() -replace '^0x', '').PadLeft(2, '0').ToUpper() $name = $MBRTypeMap[$code] if ($name) { return "$name (MBR code: 0x$code)" } else { return "Unknown/Custom (MBR code: $($Partition.MbrType))" } } return $Partition.Type } function Get-DrMapping { param([int]$MaxEvents) $map = @{} try { $events = Get-WinEvent -FilterHashtable @{ LogName = 'System'; ProviderName = 'disk' } -MaxEvents $MaxEvents -ErrorAction Stop } catch { return $map } foreach ($e in $events) { if ($e.Message -match 'Harddisk(\d+)\\DR(\d+)') { $n = [int]$Matches[1] $dr = [int]$Matches[2] if (-not $map.ContainsKey($n)) { $map[$n] = $dr } } } return $map } $drMap = Get-DrMapping -MaxEvents $MaxEvents $physicalDisks = Get-PhysicalDisk | Select-Object DeviceId, FriendlyName, SerialNumber, MediaType, @{N='SizeGB';E={[math]::Round($_.Size / 1GB,2)}} foreach ($pd in $physicalDisks) { $devId = [int]$pd.DeviceId $drSuffix = if ($drMap.ContainsKey($devId)) { "\DR$($drMap[$devId])" } else { '\DR? (no event seen yet)' } Write-Host "" Write-Host "<=== \Device\Harddisk$devId$drSuffix ($($pd.FriendlyName)) ===>" Write-Host " DeviceId: $devId | Serial: $($pd.SerialNumber) | Media: $($pd.MediaType) | Size: $($pd.SizeGB) GB" try { $partitions = Get-Partition -DiskNumber $devId -ErrorAction Stop if (-not $partitions) { Write-Host " (no partitions found)" continue } foreach ($part in $partitions) { $driveLetter = if ($part.DriveLetter) { "$($part.DriveLetter):" } else { 'no letter' } $sizeGB = [math]::Round($part.Size / 1GB, 2) $typeInfo = Get-PartitionTypeInfo -Partition $part Write-Host " [PARTITION $($part.PartitionNumber)] Drive: $driveLetter - $sizeGB GB - $typeInfo" } } catch { Write-Host " [ERROR] cannot read partitions for disk $devId" } } if ($drMap.Count -eq 0) { Write-Host "" Write-Host "Note: no \Device\HarddiskN\DRx entries found in the last $MaxEvents System log events. Increase -MaxEvents, or the DR number will only appear once Windows actually logs a disk event for that drive (e.g. a bad block warning)." } EndPowerShell: Comment: Verify that Discord does not have any injected code to intercept personal data. If anything is prompted here, it needs to be checked that it isn't malicious code. Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) } StartPowerShell: # Basic BSOD listings $ccKey = "HKLM:\SYSTEM\CurrentControlSet\Control\CrashControl" $cfg = Get-ItemProperty $ccKey -ErrorAction SilentlyContinue $dumpTypeMap = @{0='None';1='Complete';2='Kernel';3='Minidump';7='Automatic'} Write-Output "--- Configuration ---" Write-Output ("Dump Type: {0} ({1})" -f $cfg.CrashDumpEnabled, $dumpTypeMap[$cfg.CrashDumpEnabled]) Write-Output ("Full Dump Path: {0}" -f $(if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"})) Write-Output ("Minidump Folder: {0}" -f $(if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"})) Write-Output ("Auto Reboot: {0}" -f $(if($cfg.AutoReboot -eq 0){'Disabled'}else{'Enabled'})) Write-Output "--- Found Dump Files ---" $full = if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"} if (Test-Path $full) { Get-Item $full | Select Name,Length,LastWriteTime | Format-Table -AutoSize } $mini = if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"} if (Test-Path $mini) { Get-ChildItem $mini -Filter *.dmp | Select Name,Length,LastWriteTime | Format-Table -AutoSize } Write-Output "--- BugCheck Reasoning (recent events) ---" $map = @{ '0x0000000A'='IRQL_NOT_LESS_OR_EQUAL - faulty/outdated driver accessed memory at high IRQL' '0x0000001E'='KMODE_EXCEPTION_NOT_HANDLED - unhandled kernel exception, often driver/hardware' '0x0000002E'='DATA_BUS_ERROR - typically bad RAM or hardware fault' '0x0000003B'='SYSTEM_SERVICE_EXCEPTION - exception in a system service, often driver-related' '0x00000050'='PAGE_FAULT_IN_NONPAGED_AREA - bad RAM or faulty driver/antivirus' '0x0000007A'='KERNEL_DATA_INPAGE_ERROR - disk-related problem' '0x0000007B'='INACCESSIBLE_BOOT_DEVICE - system could not find/access the boot device' '0x0000007E'='SYSTEM_THREAD_EXCEPTION_NOT_HANDLED - almost always a faulty driver' '0x0000007F'='UNEXPECTED_KERNEL_MODE_TRAP - hardware issue (CPU/RAM/overclocking)' '0x0000009F'='DRIVER_POWER_STATE_FAILURE - driver failed to respond to a power state change' '0x000000C2'='BAD_POOL_CALLER - driver mishandling memory (pool corruption)' '0x000000D1'='DRIVER_IRQL_NOT_LESS_OR_EQUAL - typically a network or GPU driver' '0x000000EF'='CRITICAL_PROCESS_DIED - a critical system process died, often malware/system corruption' '0x00000116'='VIDEO_TDR_FAILURE - GPU driver failed to respond in time (timeout)' '0x00000124'='WHEA_UNCORRECTABLE_ERROR - hardware fault (CPU/RAM/PSU/overclocking)' '0x00000133'='DPC_WATCHDOG_VIOLATION - faulty driver or storage subsystem issue' '0x00000139'='KERNEL_SECURITY_CHECK_FAILURE - corrupted kernel structure, possibly malware' } $events = Get-WinEvent -FilterHashtable @{LogName='System';Id=1001} -MaxEvents 100 -ErrorAction SilentlyContinue | Where-Object { $_.ProviderName -match 'WER-SystemErrorReporting' } | Select-Object -First 5 if (-not $events) { Write-Output "No BugCheck events found in the log." } foreach ($ev in $events) { $code = if ($ev.Message -match 'bugcheck was:\s*(0x[0-9A-Fa-f]+)') { $matches[1] } else { $null } Write-Output ("Time: {0}" -f $ev.TimeCreated) Write-Output ("Code: {0}" -f $(if($code){$code}else{'not recognized'})) if ($code -and $map.ContainsKey($code.ToUpper())) { Write-Output ("Meaning: {0}" -f $map[$code.ToUpper()]) } elseif ($code) { Write-Output "Meaning: unknown code, look up at learn.microsoft.com/windows-hardware/drivers/debugger/bug-check-code-reference2" } Write-Output "" } EndPowerShell: StartPowerShell: # This snippet lists all installed apps and their folder contents along with SHA256 hashes. Useful for troubleshooting malware abusing installed app entry. param( [switch]$Recurse, [int]$MaxFilesPerApp = [int]::MaxValue ) $uninstallPaths = @( 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*', 'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*', 'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*' ) $script:msiInstaller = $null function Get-MsiInstallLocation { param([string]$ProductCode) if (-not $script:msiInstaller) { try { $script:msiInstaller = New-Object -ComObject WindowsInstaller.Installer } catch { return $null } } try { $loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallLocation') if ([string]::IsNullOrWhiteSpace($loc)) { $loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallSource') } if ([string]::IsNullOrWhiteSpace($loc)) { return $null } return $loc } catch { return $null } } function Get-CleanPath { param([string]$RawValue) if ([string]::IsNullOrWhiteSpace($RawValue)) { return $null } $s = $RawValue.Trim() if ($s.StartsWith('"')) { $endQuote = $s.IndexOf('"', 1) if ($endQuote -gt 0) { return $s.Substring(1, $endQuote - 1) } } if ($s -match '^(.*?\.exe)\b') { return $Matches[1] } return $s } function Format-FileSize { param([long]$Bytes) if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) } if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) } if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) } return "$Bytes B" } $script:PeExtensions = @('.exe', '.dll', '.sys', '.ocx', '.cpl', '.scr', '.drv', '.efi', '.msi', '.msp', '.msu') function Test-IsPeFile { param([string]$Extension) return $script:PeExtensions -contains $Extension.ToLower() } function Get-SignatureInfo { param([string]$Path, [string]$Extension) if (-not (Test-IsPeFile -Extension $Extension)) { return [PSCustomObject]@{ Signer = 'N/A (not PE)'; Status = 'NotApplicable'; Valid = $false } } $result = [PSCustomObject]@{ Signer = 'Unsigned'; Status = 'NotSigned'; Valid = $false } try { $sig = Get-AuthenticodeSignature -LiteralPath $Path -ErrorAction Stop $result.Status = $sig.Status.ToString() $result.Valid = ($sig.Status -eq 'Valid') if ($sig.SignerCertificate) { if ($sig.SignerCertificate.Subject -match 'CN=([^,]+)') { $result.Signer = $Matches[1].Trim('"') } else { $result.Signer = $sig.SignerCertificate.Subject } if (-not $result.Valid) { $result.Signer += " [INVALID: $($result.Status)]" } } elseif ($sig.Status -eq 'NotSigned') { $result.Signer = 'Unsigned' } else { $result.Signer = "Unknown [$($result.Status)]" } } catch { $result.Signer = 'Verification error' $result.Status = 'Error' $result.Valid = $false } return $result } $rawApps = Get-ItemProperty -Path $uninstallPaths -ErrorAction SilentlyContinue | Where-Object { $_.DisplayName -and $_.DisplayName.Trim() -ne '' } | Select-Object @{Name = 'Name'; Expression = { $_.DisplayName } }, @{Name = 'Version'; Expression = { $_.DisplayVersion } }, @{Name = 'Publisher'; Expression = { $_.Publisher } }, @{Name = 'InstallFolder'; Expression = { if ($_.InstallLocation -and $_.InstallLocation.Trim() -ne '') { $_.InstallLocation } elseif ($_.UninstallString -match 'MsiExec\.exe.*?(\{[0-9A-Fa-f\-]{36}\})') { $productCode = $Matches[1] $msiLoc = Get-MsiInstallLocation -ProductCode $productCode if ($msiLoc) { $msiLoc } else { "MSI: $productCode (location not found)" } } elseif ($_.UninstallString) { $_.UninstallString } else { 'N/A' } } } | Sort-Object Name -Unique foreach ($app in $rawApps) { $versionText = if ($app.Version) { $app.Version } else { '?' } $publisherText = if ($app.Publisher) { $app.Publisher } else { '?' } Write-Host "" Write-Host "<=== $($app.Name) [$versionText] ($publisherText) ===>" if ($app.InstallFolder -eq 'N/A' -or $app.InstallFolder -match '^MSI: .* \(location not found\)$') { Write-Host " Path: $($app.InstallFolder)" continue } $cleanPath = Get-CleanPath -RawValue $app.InstallFolder $exists = $false try { $exists = Test-Path -LiteralPath $cleanPath -ErrorAction Stop } catch [System.UnauthorizedAccessException] { Write-Host " Path: $cleanPath" Write-Host " [ACCESS DENIED]" continue } catch { Write-Host " Path: $cleanPath" Write-Host " [ERROR] cannot access" continue } if (-not $exists) { Write-Host " Path: $cleanPath" Write-Host " [NOT FOUND]" continue } $rootItem = Get-Item -LiteralPath $cleanPath -Force $created = $rootItem.CreationTime.ToString('dd/MM/yyyy HH:mm:ss') $modified = $rootItem.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss') if ($rootItem.PSIsContainer) { $subFolders = Get-ChildItem -LiteralPath $cleanPath -Directory -Force -ErrorAction SilentlyContinue $gciParams = @{ LiteralPath = $cleanPath; File = $true; Force = $true; ErrorAction = 'SilentlyContinue' } if ($Recurse) { $gciParams['Recurse'] = $true } $allFiles = Get-ChildItem @gciParams Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: $($allFiles.Count) | Folders: $($subFolders.Count)" foreach ($dir in $subFolders) { $dCreated = $dir.CreationTime.ToString('dd/MM/yyyy HH:mm:ss') $dModified = $dir.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss') $dFileCount = (Get-ChildItem -LiteralPath $dir.FullName -File -Force -ErrorAction SilentlyContinue).Count Write-Host (" [DIR] {0} - {1} - {2,10} - {3}" -f $dCreated, $dModified, "$dFileCount files", $dir.FullName) } } else { $allFiles = @($rootItem) Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: 1" } if ($allFiles.Count -eq 0) { continue } $shown = $allFiles | Select-Object -First $MaxFilesPerApp foreach ($f in $shown) { $hash = 'N/A' try { $hash = (Get-FileHash -LiteralPath $f.FullName -Algorithm SHA256 -ErrorAction Stop).Hash } catch { $hash = 'HASH-ERROR' } $size = Format-FileSize -Bytes $f.Length $fcreated = $f.CreationTime.ToString('dd/MM/yyyy HH:mm:ss') $fmod = $f.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss') $sigInfo = Get-SignatureInfo -Path $f.FullName -Extension $f.Extension Write-Host (" [{0}] {1} - {2} - {3,10} - Signer: {4} - {5}" -f $hash, $fcreated, $fmod, $size, $sigInfo.Signer, $f.FullName) } } EndPowerShell: Comment: List 30 recent scheduled tasks (you know, just for the sake of it) Powershell: Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo Comment: List recent Run (Windows + R) executed commands, useful for identifying ClickFix attacks Powershell: (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" } Comment: Remove unwanted files from common folders using native removal power of Farbar to include remove on reboot if needed. Please double check the user does not have any applications incorrectly installed in the directories listed below. C:\ProgramData\*.csproj C:\ProgramData\*.a3x C:\ProgramData\*.ahk C:\ProgramData\*.au3 C:\ProgramData\*.bat C:\ProgramData\*.cab C:\ProgramData\*.cmd C:\ProgramData\*.com C:\ProgramData\*.dll C:\ProgramData\*.exe C:\ProgramData\*.hta C:\ProgramData\*.jar C:\ProgramData\*.js C:\ProgramData\*.jse C:\ProgramData\*.lnk C:\ProgramData\*.pif C:\ProgramData\*.ps1 C:\ProgramData\*.py C:\ProgramData\*.pyc C:\ProgramData\*.pyd C:\ProgramData\*.scr C:\ProgramData\*.tmp C:\ProgramData\*.vbe C:\ProgramData\*.vbs C:\ProgramData\*.wsf C:\ProgramData\*.wsh C:\ProgramData\*.zip C:\ProgramData\*.rar C:\ProgramData\*.7z C:\Users\*\AppData\Roaming\*.csproj C:\Users\*\AppData\Roaming\*.au3 C:\Users\*\AppData\Roaming\*.bat C:\Users\*\AppData\Roaming\*.cab C:\Users\*\AppData\Roaming\*.cmd C:\Users\*\AppData\Roaming\*.com C:\Users\*\AppData\Roaming\*.dll C:\Users\*\AppData\Roaming\*.exe C:\Users\*\AppData\Roaming\*.hta C:\Users\*\AppData\Roaming\*.jar C:\Users\*\AppData\Roaming\*.js C:\Users\*\AppData\Roaming\*.jse C:\Users\*\AppData\Roaming\*.lnk C:\Users\*\AppData\Roaming\*.pif C:\Users\*\AppData\Roaming\*.ps1 C:\Users\*\AppData\Roaming\*.py C:\Users\*\AppData\Roaming\*.pyc C:\Users\*\AppData\Roaming\*.pyd C:\Users\*\AppData\Roaming\*.scr C:\Users\*\AppData\Roaming\*.tmp C:\Users\*\AppData\Roaming\*.vbe C:\Users\*\AppData\Roaming\*.vbs C:\Users\*\AppData\Roaming\*.wsf C:\Users\*\AppData\Roaming\*.wsh C:\Users\*\AppData\Roaming\*.zip C:\Users\*\AppData\Roaming\*.rar C:\Users\*\AppData\Roaming\*.7z C:\Users\CurrentUserName\AppData\Local\*.csproj C:\Users\CurrentUserName\AppData\Local\*.a3x C:\Users\CurrentUserName\AppData\Local\*.ahk C:\Users\CurrentUserName\AppData\Local\*.au3 C:\Users\CurrentUserName\AppData\Local\*.bat C:\Users\CurrentUserName\AppData\Local\*.cab C:\Users\CurrentUserName\AppData\Local\*.cmd C:\Users\CurrentUserName\AppData\Local\*.com C:\Users\CurrentUserName\AppData\Local\*.dll C:\Users\CurrentUserName\AppData\Local\*.exe C:\Users\CurrentUserName\AppData\Local\*.hta C:\Users\CurrentUserName\AppData\Local\*.jar C:\Users\CurrentUserName\AppData\Local\*.js C:\Users\CurrentUserName\AppData\Local\*.jse C:\Users\CurrentUserName\AppData\Local\*.lnk C:\Users\CurrentUserName\AppData\Local\*.pif C:\Users\CurrentUserName\AppData\Local\*.ps1 C:\Users\CurrentUserName\AppData\Local\*.py C:\Users\CurrentUserName\AppData\Local\*.pyc C:\Users\CurrentUserName\AppData\Local\*.pyd C:\Users\CurrentUserName\AppData\Local\*.scr C:\Users\CurrentUserName\AppData\Local\*.tmp C:\Users\CurrentUserName\AppData\Local\*.vbe C:\Users\CurrentUserName\AppData\Local\*.vbs C:\Users\CurrentUserName\AppData\Local\*.wsf C:\Users\CurrentUserName\AppData\Local\*.wsh C:\Users\CurrentUserName\AppData\Local\*.zip C:\Users\CurrentUserName\AppData\Local\*.rar C:\Users\CurrentUserName\AppData\Local\*.7z C:\Users\CurrentUserName\AppData\Roaming\*.csproj C:\Users\CurrentUserName\AppData\Roaming\*.a3x C:\Users\CurrentUserName\AppData\Roaming\*.ahk C:\Users\CurrentUserName\AppData\Roaming\*.au3 C:\Users\CurrentUserName\AppData\Roaming\*.bat C:\Users\CurrentUserName\AppData\Roaming\*.cab C:\Users\CurrentUserName\AppData\Roaming\*.cmd C:\Users\CurrentUserName\AppData\Roaming\*.com C:\Users\CurrentUserName\AppData\Roaming\*.dll C:\Users\CurrentUserName\AppData\Roaming\*.exe C:\Users\CurrentUserName\AppData\Roaming\*.hta C:\Users\CurrentUserName\AppData\Roaming\*.jar C:\Users\CurrentUserName\AppData\Roaming\*.js C:\Users\CurrentUserName\AppData\Roaming\*.jse C:\Users\CurrentUserName\AppData\Roaming\*.lnk C:\Users\CurrentUserName\AppData\Roaming\*.pif C:\Users\CurrentUserName\AppData\Roaming\*.ps1 C:\Users\CurrentUserName\AppData\Roaming\*.py C:\Users\CurrentUserName\AppData\Roaming\*.pyc C:\Users\CurrentUserName\AppData\Roaming\*.pyd C:\Users\CurrentUserName\AppData\Roaming\*.scr C:\Users\CurrentUserName\AppData\Roaming\*.tmp C:\Users\CurrentUserName\AppData\Roaming\*.vbe C:\Users\CurrentUserName\AppData\Roaming\*.vbs C:\Users\CurrentUserName\AppData\Roaming\*.wsf C:\Users\CurrentUserName\AppData\Roaming\*.wsh C:\Users\CurrentUserName\AppData\Roaming\*.zip C:\Users\CurrentUserName\AppData\Roaming\*.rar C:\Users\CurrentUserName\AppData\Roaming\*.7z Comment: Remove browser cache StartPowerShell: $ProfilesDirectory = (Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList').ProfilesDirectory $DisplayNames = @{ "chrome" = "Chrome" "firefox" = "Firefox" "opera" = "Opera" "operagx" = "Opera GX" "brave" = "Brave" "msedge" = "Edge" "vivaldi" = "Vivaldi" "librewolf" = "LibreWolf" "mullvad" = "Mullvad Browser" "zen" = "Zen" } $ProcessNameMap = @{ "operagx" = "opera" "mullvad" = "mullvadbrowser" } $trueCacheNames = @("Cache", "Code Cache", "DawnCache", "GPUCache", "GrShaderCache", "ShaderCache", "Shared Dictionary\cache") function Get-CacheDirs { param([string]$BrowserName, [string]$ProfilesDirectory) switch ($BrowserName) { "chrome" { $dir = "$ProfilesDirectory\*\AppData\Local\Google\Chrome\User Data" Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } } "firefox" { $dir = "$ProfilesDirectory\*\AppData\Local\Mozilla\Firefox\Profiles" Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' } } "opera" { $dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software" $r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } $dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software" $r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } $r1 + $r2 } "operagx" { $dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software\Opera GX Stable" $r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } $dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software\Opera GX Stable" $r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } $r1 + $r2 } "brave" { $dir = "$ProfilesDirectory\*\AppData\Local\BraveSoftware\Brave-Browser\User Data" Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } } "msedge" { $dir = "$ProfilesDirectory\*\AppData\Local\Microsoft\Edge\User Data" Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } } "vivaldi" { $dir = "$ProfilesDirectory\*\AppData\Local\Vivaldi\User Data" Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } } "librewolf" { $dir = "$ProfilesDirectory\*\AppData\Local\LibreWolf\Profiles" Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' } } "mullvad" { $dir = "$ProfilesDirectory\*\AppData\Local\Mullvad\MullvadBrowser\Profiles" Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' } } "zen" { $dir = "$ProfilesDirectory\*\AppData\Local\zen\Profiles" Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' } } } } function Format-Size { param([long]$Bytes) if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) } if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) } if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) } return "$Bytes B" } $BrowserKeys = @('chrome', 'firefox', 'opera', 'operagx', 'brave', 'msedge', 'vivaldi', 'librewolf', 'mullvad', 'zen') foreach ($key in $BrowserKeys) { $procName = if ($ProcessNameMap.ContainsKey($key)) { $ProcessNameMap[$key] } else { $key } Get-Process -Name $procName -ErrorAction SilentlyContinue | Stop-Process -Force -ErrorAction SilentlyContinue } Start-Sleep -Seconds 5 $grandBytes = 0L $grandFiles = 0 $anyFound = $false foreach ($key in $BrowserKeys) { $cacheDirs = Get-CacheDirs -BrowserName $key -ProfilesDirectory $ProfilesDirectory if (-not $cacheDirs -or $cacheDirs.Count -eq 0) { continue } $anyFound = $true $displayName = $DisplayNames[$key] $browserBytes = 0L $browserFiles = 0 foreach ($cacheDir in $cacheDirs) { if (-not (Test-Path $cacheDir)) { continue } $items = Get-ChildItem -Path $cacheDir -Force -Recurse -ErrorAction SilentlyContinue $files = $items | Where-Object { -not $_.PSIsContainer } $bytes = ($files | Measure-Object -Property Length -Sum).Sum if (-not $bytes) { $bytes = 0 } $browserFiles += $files.Count $browserBytes += $bytes Get-ChildItem -Path "$cacheDir\*" -Force -ErrorAction SilentlyContinue | Remove-Item -Force -Recurse -ErrorAction SilentlyContinue } $grandBytes += $browserBytes $grandFiles += $browserFiles Write-Host ("{0,-16} freed {1,10} ({2} files)" -f $displayName, (Format-Size $browserBytes), $browserFiles) } if (-not $anyFound) { Write-Host "No cache found for any installed browser." } Write-Host "" Write-Host ("Total freed: {0} ({1} files)" -f (Format-Size $grandBytes), $grandFiles) EndPowerShell: Comment: Verify WMI repository, repair & verify again CMD: winmgmt.exe /verifyrepository CMD: winmgmt.exe /salvagerepository CMD: winmgmt.exe /verifyrepository Comment: To rebuild the performance counter library values CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R" CMD: "%WINDIR%\SysWOW64\lodctr.exe /R" CMD: "C:\Windows\SYSTEM32\lodctr.exe /R" CMD: "C:\Windows\SysWOW64\lodctr.exe /R" Comment: Resync performance counter library values to WMI as well CMD: winmgmt.exe /resyncperf Comment: Force policy removal C:\Windows\System32\GroupPolicyUsers C:\Windows\System32\GroupPolicy CMD: gpupdate.exe /force Comment: Reset PowerShell execution policy Powershell: Set-ExecutionPolicy Unrestricted -Scope CurrentUser -Force Comment: BITS reset Startbatch: @echo off net.exe stop BITS ipconfig.exe /flushdns ren "%programdata%\Microsoft\Network\Downloader\qmgr*.*" qmgr*.*.old net.exe start BITS Endbatch: cmd: bitsadmin.exe /reset /allusers Comment: Network reset commands CMD: netsh.exe int ip reset CMD: netsh.exe int ipv6 reset CMD: ipconfig.exe /flushDNS CMD: netsh.exe winsock reset catalog Comment: Additional temp file removal C:\Windows\System32\config\systemprofile\AppData\Local\*.tmp C:\WINDOWS\system32\*.tmp C:\WINDOWS\syswow64\*.tmp C:\Users\CurrentUserName\AppData\Local\Temp\* C:\Windows\Temp\* C:\Windows\SystemTemp\* C:\Windows\Prefetch\* Comment: System repair commands CMD: SFC.exe /scannow CMD: DISM.exe /Online /Cleanup-image /Restorehealth EmptyTemp: End::