content copied
content
Start::
SystemRestore: On
CreateRestorePoint:
CloseProcesses:
Folder: C:\Users\bsobh\AppData\Roaming\Troplo
File: C:\WINDOWS\unins001.exe
File: C:\WINDOWS\unins001.dat
HKU\S-1-5-21-2113188910-3818819163-733913382-1002\Software\Classes\exefile: <==== ATTENTION
HKU\S-1-5-21-2113188910-3818819163-733913382-1002\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKU\S-1-5-21-2113188910-3818819163-733913382-1002\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_F508CA0AFC94EC8AC8F225861BD7713E"
HKU\S-1-5-21-2113188910-3818819163-733913382-1002\...\Run: [MicrosoftEdgeAutoLaunch_F508CA0AFC94EC8AC8F225861BD7713E] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5024072 2026-07-31] (Microsoft Corporation -> Microsoft Corporation)
R3 HWiNFO_204; \??\C:\Users\bsobh\AppData\Local\Temp\HWiNFO_x64_204.sys [58024 2026-08-25] (Microsoft Windows Hardware Compatibility Publisher -> ) <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-2113188910-3818819163-733913382-1002_Classes\CLSID\{8398410F-DEAA-4189-872B-845988323C62}\localserver32 -> C:\Users\bsobh\AppData\Local\Discord\app-1.0.9250\Discord.exe => No File
ContextMenuHandlers1: [TeraCopy] -> {2386CB87-96FF-473D-A009-957E3BFE6F88} => -> No File
ContextMenuHandlers2: [TeraCopy] -> {2386CB87-96FF-473D-A009-957E3BFE6F88} => -> No File
ContextMenuHandlers4: [TeraCopy] -> {2386CB87-96FF-473D-A009-957E3BFE6F88} => -> No File
ContextMenuHandlers6: [TeraCopy] -> {2386CB87-96FF-473D-A009-957E3BFE6F88} => -> No File
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [6990]
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {08BF9DBD-BA1A-4346-93FF-8C18D96DA6CE} - System32\Tasks\MiniToolPartitionWizard => C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe /fromtask (No File)
S3 LGDDCDevice; \??\C:\WINDOWS\SysWOW64\LGI2CDriver.sys (No File)
S3 LGII2CDevice; \??\C:\WINDOWS\SysWOW64\LGPII2CDriver.sys (No File)
2026-02-09 17:18 - 2026-02-09 17:18 - 000000048 ____R () C:\Users\bsobh\AppData\Local\0119AC2FC90D95AC063B177717B7B3B6
2025-02-26 22:50 - 2025-02-26 22:50 - 000000048 ____R () C:\Users\bsobh\AppData\Local\0742DC28DA316097BD4D813F2D4096FC
HKU\S-1-5-21-2113188910-3818819163-733913382-1002\Software\Classes\exefile: <==== ATTENTION
HKU\S-1-5-21-2113188910-3818819163-733913382-1002\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) }
StartPowerShell:
# Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console
# Does not clean preinstalled objects, only PUP/Adware
# If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument
# If you would like to only scan with it, change the argument from /clean to /scan
# NOTE: For the sake of users from Asia (primarily China), do not use the clean option. It will very likely remove a lot of their important software.
New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null
Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden
$logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile
Get-Content $logFile -Encoding Unicode
Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue
EndPowerShell:
StartPowershell:
$hmpExe = "$env:TEMP\HitmanPro_x64.exe"
$logFile = "$env:TEMP\HitmanPro_ScanLog.txt"
Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing
$proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru
if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 }
Get-Content $logFile -Encoding Unicode
EndPowershell:
Comment: RenPyLoader hollowed installed app generic removal
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.bat
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.props
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.targets
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.user
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cache
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.config
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.bat
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.props
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.targets
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.tmp
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.csproj
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cmd
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.user
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cache
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.config
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.bat
Comment: Remove unwanted files from common folders using native removal power of Farbar to include remove on reboot if needed. Please double check the user does not have any applications incorrectly installed in the directories listed below.ยจ
C:\ProgramData\*.csproj
C:\ProgramData\*.a3x
C:\ProgramData\*.ahk
C:\ProgramData\*.au3
C:\ProgramData\*.bat
C:\ProgramData\*.cab
C:\ProgramData\*.cmd
C:\ProgramData\*.com
C:\ProgramData\*.dll
C:\ProgramData\*.exe
C:\ProgramData\*.hta
C:\ProgramData\*.jar
C:\ProgramData\*.js
C:\ProgramData\*.jse
C:\ProgramData\*.lnk
C:\ProgramData\*.pif
C:\ProgramData\*.ps1
C:\ProgramData\*.py
C:\ProgramData\*.pyc
C:\ProgramData\*.pyd
C:\ProgramData\*.scr
C:\ProgramData\*.tmp
C:\ProgramData\*.vbe
C:\ProgramData\*.vbs
C:\ProgramData\*.wsf
C:\ProgramData\*.wsh
C:\ProgramData\*.zip
C:\ProgramData\*.rar
C:\ProgramData\*.7z
C:\Users\*\AppData\Roaming\*.csproj
C:\Users\*\AppData\Roaming\*.au3
C:\Users\*\AppData\Roaming\*.bat
C:\Users\*\AppData\Roaming\*.cab
C:\Users\*\AppData\Roaming\*.cmd
C:\Users\*\AppData\Roaming\*.com
C:\Users\*\AppData\Roaming\*.dll
C:\Users\*\AppData\Roaming\*.exe
C:\Users\*\AppData\Roaming\*.hta
C:\Users\*\AppData\Roaming\*.jar
C:\Users\*\AppData\Roaming\*.js
C:\Users\*\AppData\Roaming\*.jse
C:\Users\*\AppData\Roaming\*.lnk
C:\Users\*\AppData\Roaming\*.pif
C:\Users\*\AppData\Roaming\*.ps1
C:\Users\*\AppData\Roaming\*.py
C:\Users\*\AppData\Roaming\*.pyc
C:\Users\*\AppData\Roaming\*.pyd
C:\Users\*\AppData\Roaming\*.scr
C:\Users\*\AppData\Roaming\*.tmp
C:\Users\*\AppData\Roaming\*.vbe
C:\Users\*\AppData\Roaming\*.vbs
C:\Users\*\AppData\Roaming\*.wsf
C:\Users\*\AppData\Roaming\*.wsh
C:\Users\*\AppData\Roaming\*.zip
C:\Users\*\AppData\Roaming\*.rar
C:\Users\*\AppData\Roaming\*.7z
C:\Users\CurrentUserName\AppData\Local\*.csproj
C:\Users\CurrentUserName\AppData\Local\*.a3x
C:\Users\CurrentUserName\AppData\Local\*.ahk
C:\Users\CurrentUserName\AppData\Local\*.au3
C:\Users\CurrentUserName\AppData\Local\*.bat
C:\Users\CurrentUserName\AppData\Local\*.cab
C:\Users\CurrentUserName\AppData\Local\*.cmd
C:\Users\CurrentUserName\AppData\Local\*.com
C:\Users\CurrentUserName\AppData\Local\*.dll
C:\Users\CurrentUserName\AppData\Local\*.exe
C:\Users\CurrentUserName\AppData\Local\*.hta
C:\Users\CurrentUserName\AppData\Local\*.jar
C:\Users\CurrentUserName\AppData\Local\*.js
C:\Users\CurrentUserName\AppData\Local\*.jse
C:\Users\CurrentUserName\AppData\Local\*.lnk
C:\Users\CurrentUserName\AppData\Local\*.pif
C:\Users\CurrentUserName\AppData\Local\*.ps1
C:\Users\CurrentUserName\AppData\Local\*.py
C:\Users\CurrentUserName\AppData\Local\*.pyc
C:\Users\CurrentUserName\AppData\Local\*.pyd
C:\Users\CurrentUserName\AppData\Local\*.scr
C:\Users\CurrentUserName\AppData\Local\*.tmp
C:\Users\CurrentUserName\AppData\Local\*.vbe
C:\Users\CurrentUserName\AppData\Local\*.vbs
C:\Users\CurrentUserName\AppData\Local\*.wsf
C:\Users\CurrentUserName\AppData\Local\*.wsh
C:\Users\CurrentUserName\AppData\Local\*.zip
C:\Users\CurrentUserName\AppData\Local\*.rar
C:\Users\CurrentUserName\AppData\Local\*.7z
C:\Users\CurrentUserName\AppData\Roaming\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\*.a3x
C:\Users\CurrentUserName\AppData\Roaming\*.ahk
C:\Users\CurrentUserName\AppData\Roaming\*.au3
C:\Users\CurrentUserName\AppData\Roaming\*.bat
C:\Users\CurrentUserName\AppData\Roaming\*.cab
C:\Users\CurrentUserName\AppData\Roaming\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\*.com
C:\Users\CurrentUserName\AppData\Roaming\*.dll
C:\Users\CurrentUserName\AppData\Roaming\*.exe
C:\Users\CurrentUserName\AppData\Roaming\*.hta
C:\Users\CurrentUserName\AppData\Roaming\*.jar
C:\Users\CurrentUserName\AppData\Roaming\*.js
C:\Users\CurrentUserName\AppData\Roaming\*.jse
C:\Users\CurrentUserName\AppData\Roaming\*.lnk
C:\Users\CurrentUserName\AppData\Roaming\*.pif
C:\Users\CurrentUserName\AppData\Roaming\*.ps1
C:\Users\CurrentUserName\AppData\Roaming\*.py
C:\Users\CurrentUserName\AppData\Roaming\*.pyc
C:\Users\CurrentUserName\AppData\Roaming\*.pyd
C:\Users\CurrentUserName\AppData\Roaming\*.scr
C:\Users\CurrentUserName\AppData\Roaming\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\*.vbe
C:\Users\CurrentUserName\AppData\Roaming\*.vbs
C:\Users\CurrentUserName\AppData\Roaming\*.wsf
C:\Users\CurrentUserName\AppData\Roaming\*.wsh
C:\Users\CurrentUserName\AppData\Roaming\*.zip
C:\Users\CurrentUserName\AppData\Roaming\*.rar
C:\Users\CurrentUserName\AppData\Roaming\*.7z
C:\Users\CurrentUserName\AppData\Local\Temp\*
C:\Windows\Temp\*
C:\Windows\SystemTemp\*
CMD: cscript c:\windows\system32\slmgr.vbs /xpr & cscript c:\windows\system32\slmgr.vbs /dlv
CMD: netsh int ip reset
CMD: netsh int ipv6 reset
CMD: ipconfig /flushDNS
CMD: netsh winhttp reset proxy
CMD: netsh winsock reset catalog
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: bitsadmin /reset /allusers
CMD: Winmgmt /salvagerepository
CMD: winmgmt /resyncperf
CMD: DISM.exe /Online /Cleanup-image /Restorehealth
CMD: sfc /scannow
RemoveProxy:
EmptyTemp:
End::
Warning
Executing a Fixlist on the wrong system may permanently damage it. Continue only if this link was meant for you.
To view the content, acknowledge this warning.