content copied
content
Start::
CreateRestorePoint:
CloseProcesses:
Folder: C:\ProgramData\PackerCrashCanary
Folder: C:\Users\Canvas\AppData\Local\SystemSettingsBackup
Folder: C:\Users\Canvas\.local
Folder: C:\Users\Canvas\AppData\Roaming\Smart Launcher
Folder: C:\Users\Canvas\AppData\Local\Smart Launcher SRL
File: D:\Firefox\default-browser-agent.exe
File: E:\GOG Galaxy\plugins\GalaxyPluginEpic\multidict\_multidict.cp313-win_amd64.pyd
C:\Users\Canvas\AppData\Local\SystemSettingsBackup
C:\Users\Canvas\AppData\Roaming\Smart Launcher
C:\Users\Canvas\AppData\Local\Smart Launcher SRL
HKU\S-1-5-21-3186362531-4182011304-2197262190-1001\Software\Classes\regfile: <==== ATTENTION
HKU\S-1-5-21-3186362531-4182011304-2197262190-1001\Software\Classes\.reg: => <==== ATTENTION
HKU\S-1-5-21-3186362531-4182011304-2197262190-1001\Software\Classes\.bat: => <==== ATTENTION
HKU\S-1-5-21-3186362531-4182011304-2197262190-1001\Software\Classes\.cmd: => <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
HKU\S-1-5-21-3186362531-4182011304-2197262190-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_B60D8644264E4F1A29E342FEA5E309F1"
HKU\S-1-5-21-3186362531-4182011304-2197262190-1001\...\Run: [MicrosoftEdgeAutoLaunch_B60D8644264E4F1A29E342FEA5E309F1] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5018440 2026-08-20] (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3186362531-4182011304-2197262190-1001_Classes\CLSID\{23B3E3D8-C162-4A8B-AB0C-0905DCB1DF19}\InprocServer32 -> C:\Users\Canvas\AppData\Local\Packages\Microsoft.PowerAutomateDesktop_8wekyb3d8bbwe\TempState\RDP\DVCPlugin\x64\Microsoft.Flow.RPA.Desktop.UIAutomation.RDP.DVC.Plugin.dll => No File
FirewallRules: [{5790718D-5011-432C-A17B-FE01F500B1AB}] => (Allow) C:\Users\Canvas\AppData\Local\Temp\ACFL20260107135025\ACSetup\ACSetup.exe => No File
FirewallRules: [{DA8C1826-09A4-44C2-9727-F4A5C2AA87CE}] => (Allow) C:\Users\Canvas\AppData\Local\Temp\ACFL20260107135025\ACSetup\ACSetup.exe => No File
FirewallRules: [TCP Query User{FD7CA6DE-B09F-4A8C-B46B-D35777ABF110}C:\users\canvas\appdata\local\discord\app-1.0.9236\discord.exe] => (Allow) C:\users\canvas\appdata\local\discord\app-1.0.9236\discord.exe => No File
FirewallRules: [UDP Query User{7B79F5D8-79A6-465D-BC1D-03A5835F9CC8}C:\users\canvas\appdata\local\discord\app-1.0.9236\discord.exe] => (Allow) C:\users\canvas\appdata\local\discord\app-1.0.9236\discord.exe => No File
FirewallRules: [TCP Query User{D0487672-1E9E-439C-B3BE-F8733BFA77AC}E:\steam library\steamapps\common\backrooms_escape_together\bet\binaries\win64\betgamesteam-win64-shipping.exe] => (Allow) E:\steam library\steamapps\common\backrooms_escape_together\bet\binaries\win64\betgamesteam-win64-shipping.exe => No File
FirewallRules: [UDP Query User{ED17D95C-2B04-4E64-8C18-C26B3C284760}E:\steam library\steamapps\common\backrooms_escape_together\bet\binaries\win64\betgamesteam-win64-shipping.exe] => (Allow) E:\steam library\steamapps\common\backrooms_escape_together\bet\binaries\win64\betgamesteam-win64-shipping.exe => No File
FirewallRules: [{FD738C09-2C4C-4DAC-842E-7537833F8323}] => (Allow) E:\Steam Library\steamapps\common\Restory Demo\Restory.exe => No File
FirewallRules: [{C1FBF637-B925-4041-A139-B0F6379A6109}] => (Allow) E:\Steam Library\steamapps\common\Restory Demo\Restory.exe => No File
FirewallRules: [{0DE37EFD-D646-42D9-8E67-D4941D97E9AD}] => (Allow) C:\Users\Canvas\AppData\Local\Temp\ACFL\ACSetup\ACSetup.exe => No File
FirewallRules: [{FB3F51D8-FC60-4D26-8210-79F7E495AA65}] => (Allow) C:\Users\Canvas\AppData\Local\Temp\ACFL\ACSetup\ACSetup.exe => No File
HKU\S-1-5-21-3186362531-4182011304-2197262190-1001\...\Run: [GalaxyClient] => [X]
HKU\S-1-5-21-3186362531-4182011304-2197262190-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Canvas\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File) <==== ATTENTION
Task: {49C62B52-B77C-4A3B-8F9B-B71488358CC8} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (No File)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {0BB36A32-0D9E-4297-AFD7-6BD7B5DB4C9B} - System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr => %windir%\System32\UNP\UpdateNotificationMgr.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
S3 cpuz159; \??\C:\WINDOWS\temp\cpuz159\cpuz159_x64.sys (No File) <==== ATTENTION
Comment: AdwCleaner scan + clean
StartPowerShell:
New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null
Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden
$logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile
Get-Content $logFile -Encoding Unicode
Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue
EndPowerShell:
Comment: HitmanPro scan
StartPowershell:
$hmpExe = "$env:TEMP\HitmanPro_x64.exe"
$logFile = "$env:TEMP\HitmanPro_ScanLog.txt"
Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing
$proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru
if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 }
Get-Content $logFile -Encoding Unicode
EndPowershell:
Comment: Verify that Discord does not have any injected code to intercept personal data. If anything is prompted here, it needs to be checked that it isn't malicious code.
Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) }
Comment: Verify Windows activation
CMD: cscript c:\windows\system32\slmgr.vbs /xpr & cscript c:\windows\system32\slmgr.vbs /dlv
Comment: Check TPM and Secure Boot status
StartPowershell:
[PSCustomObject]@{ "TPM Detected" = (Get-Tpm).TpmPresent; "TPM Enabled" = (Get-Tpm).TpmEnabled; "Secure Boot On" = (Confirm-SecureBootUEFI) }
EndPowershell:
Comment: Force policy removal
C:\Windows\System32\GroupPolicyUsers
C:\Windows\System32\GroupPolicy
Comment: Network reset commands
CMD: netsh int ip reset
CMD: netsh int ipv6 reset
CMD: ipconfig /flushDNS
CMD: netsh winsock reset catalog
Comment: Remove unwanted files from common folders using native removal power of Farbar to include remove on reboot if needed. Please double check the user does not have any applications incorrectly installed in the directories listed below.
C:\ProgramData\*.csproj
C:\ProgramData\*.a3x
C:\ProgramData\*.ahk
C:\ProgramData\*.au3
C:\ProgramData\*.bat
C:\ProgramData\*.cab
C:\ProgramData\*.cmd
C:\ProgramData\*.com
C:\ProgramData\*.dll
C:\ProgramData\*.exe
C:\ProgramData\*.hta
C:\ProgramData\*.jar
C:\ProgramData\*.js
C:\ProgramData\*.jse
C:\ProgramData\*.lnk
C:\ProgramData\*.pif
C:\ProgramData\*.ps1
C:\ProgramData\*.py
C:\ProgramData\*.pyc
C:\ProgramData\*.pyd
C:\ProgramData\*.scr
C:\ProgramData\*.tmp
C:\ProgramData\*.vbe
C:\ProgramData\*.vbs
C:\ProgramData\*.wsf
C:\ProgramData\*.wsh
C:\ProgramData\*.zip
C:\ProgramData\*.rar
C:\ProgramData\*.7z
C:\Users\*\AppData\Roaming\*.csproj
C:\Users\*\AppData\Roaming\*.au3
C:\Users\*\AppData\Roaming\*.bat
C:\Users\*\AppData\Roaming\*.cab
C:\Users\*\AppData\Roaming\*.cmd
C:\Users\*\AppData\Roaming\*.com
C:\Users\*\AppData\Roaming\*.dll
C:\Users\*\AppData\Roaming\*.exe
C:\Users\*\AppData\Roaming\*.hta
C:\Users\*\AppData\Roaming\*.jar
C:\Users\*\AppData\Roaming\*.js
C:\Users\*\AppData\Roaming\*.jse
C:\Users\*\AppData\Roaming\*.lnk
C:\Users\*\AppData\Roaming\*.pif
C:\Users\*\AppData\Roaming\*.ps1
C:\Users\*\AppData\Roaming\*.py
C:\Users\*\AppData\Roaming\*.pyc
C:\Users\*\AppData\Roaming\*.pyd
C:\Users\*\AppData\Roaming\*.scr
C:\Users\*\AppData\Roaming\*.tmp
C:\Users\*\AppData\Roaming\*.vbe
C:\Users\*\AppData\Roaming\*.vbs
C:\Users\*\AppData\Roaming\*.wsf
C:\Users\*\AppData\Roaming\*.wsh
C:\Users\*\AppData\Roaming\*.zip
C:\Users\*\AppData\Roaming\*.rar
C:\Users\*\AppData\Roaming\*.7z
C:\Users\CurrentUserName\AppData\Local\*.csproj
C:\Users\CurrentUserName\AppData\Local\*.a3x
C:\Users\CurrentUserName\AppData\Local\*.ahk
C:\Users\CurrentUserName\AppData\Local\*.au3
C:\Users\CurrentUserName\AppData\Local\*.bat
C:\Users\CurrentUserName\AppData\Local\*.cab
C:\Users\CurrentUserName\AppData\Local\*.cmd
C:\Users\CurrentUserName\AppData\Local\*.com
C:\Users\CurrentUserName\AppData\Local\*.dll
C:\Users\CurrentUserName\AppData\Local\*.exe
C:\Users\CurrentUserName\AppData\Local\*.hta
C:\Users\CurrentUserName\AppData\Local\*.jar
C:\Users\CurrentUserName\AppData\Local\*.js
C:\Users\CurrentUserName\AppData\Local\*.jse
C:\Users\CurrentUserName\AppData\Local\*.lnk
C:\Users\CurrentUserName\AppData\Local\*.pif
C:\Users\CurrentUserName\AppData\Local\*.ps1
C:\Users\CurrentUserName\AppData\Local\*.py
C:\Users\CurrentUserName\AppData\Local\*.pyc
C:\Users\CurrentUserName\AppData\Local\*.pyd
C:\Users\CurrentUserName\AppData\Local\*.scr
C:\Users\CurrentUserName\AppData\Local\*.tmp
C:\Users\CurrentUserName\AppData\Local\*.vbe
C:\Users\CurrentUserName\AppData\Local\*.vbs
C:\Users\CurrentUserName\AppData\Local\*.wsf
C:\Users\CurrentUserName\AppData\Local\*.wsh
C:\Users\CurrentUserName\AppData\Local\*.zip
C:\Users\CurrentUserName\AppData\Local\*.rar
C:\Users\CurrentUserName\AppData\Local\*.7z
C:\Users\CurrentUserName\AppData\Roaming\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\*.a3x
C:\Users\CurrentUserName\AppData\Roaming\*.ahk
C:\Users\CurrentUserName\AppData\Roaming\*.au3
C:\Users\CurrentUserName\AppData\Roaming\*.bat
C:\Users\CurrentUserName\AppData\Roaming\*.cab
C:\Users\CurrentUserName\AppData\Roaming\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\*.com
C:\Users\CurrentUserName\AppData\Roaming\*.dll
C:\Users\CurrentUserName\AppData\Roaming\*.exe
C:\Users\CurrentUserName\AppData\Roaming\*.hta
C:\Users\CurrentUserName\AppData\Roaming\*.jar
C:\Users\CurrentUserName\AppData\Roaming\*.js
C:\Users\CurrentUserName\AppData\Roaming\*.jse
C:\Users\CurrentUserName\AppData\Roaming\*.lnk
C:\Users\CurrentUserName\AppData\Roaming\*.pif
C:\Users\CurrentUserName\AppData\Roaming\*.ps1
C:\Users\CurrentUserName\AppData\Roaming\*.py
C:\Users\CurrentUserName\AppData\Roaming\*.pyc
C:\Users\CurrentUserName\AppData\Roaming\*.pyd
C:\Users\CurrentUserName\AppData\Roaming\*.scr
C:\Users\CurrentUserName\AppData\Roaming\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\*.vbe
C:\Users\CurrentUserName\AppData\Roaming\*.vbs
C:\Users\CurrentUserName\AppData\Roaming\*.wsf
C:\Users\CurrentUserName\AppData\Roaming\*.wsh
C:\Users\CurrentUserName\AppData\Roaming\*.zip
C:\Users\CurrentUserName\AppData\Roaming\*.rar
C:\Users\CurrentUserName\AppData\Roaming\*.7z
Comment: Additional temp file removal
C:\Windows\System32\config\systemprofile\AppData\Local\*.tmp
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
C:\Users\CurrentUserName\AppData\Local\Temp\*
C:\Windows\Temp\*
C:\Windows\SystemTemp\*
EmptyTemp:
End::
Warning
Executing a Fixlist on the wrong system may permanently damage it. Continue only if this link was meant for you.
To view the content, acknowledge this warning.