content copied
content
Start::
CreateRestorePoint:
CloseProcesses:
PowerShell: Remove-MpPreference -ExclusionPath "V:\Games\Riot Games"
PowerShell: Remove-MpPreference -ExclusionPath "C:\Users\NgKho\AppData\Local\JetBrains\PyCharmCE2024.1"
PowerShell: Remove-MpPreference -ExclusionPath "V:\SIM UoW\CSCI323\GA\Project\pythonProject"
2026-07-16 23:11 - 2026-07-16 23:11 - 000000000 ____D C:\Users\NgKho\AppData\Roaming\RenPy
CustomCLSID: HKU\S-1-5-21-2806995396-159071790-1316216123-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll -> No File
AlternateDataStreams: C:\WINDOWS\tracing:? [16]
AlternateDataStreams: C:\ProgramData\DP45977C.lfl:677104FCAA [7706]
AlternateDataStreams: C:\ProgramData\mntemp:8EAD8B3507 [7706]
AlternateDataStreams: C:\ProgramData\rtpeskt:1F3D48CBE8 [7706]
AlternateDataStreams: C:\ProgramData\sldh.dat:136096DD5B [7706]
AlternateDataStreams: C:\ProgramData\sldh.dat:F3D162C601 [7706]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk:A1B76439FE [7706]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk:1069064143 [7706]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk:9185529B88 [7706]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk:BE32D07BC5 [7706]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk:B96E9B8455 [7706]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk:980850BA8A [7706]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mpv.lnk:C7C2D1BECF [7706]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mullvad VPN.lnk:EB872D984C [7706]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++.lnk:159ADC9AA1 [7706]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk:60EC9648C0 [7706]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook (classic).lnk:5465085A2F [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook (classic).lnk:BE800952D3 [7706]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk:F20EF51E1F [3442]
AlternateDataStreams: C:\Users\NgKho\Application Data:86dabf594e68b7fb8ac56037576b6591 [394]
AlternateDataStreams: C:\Users\NgKho\AppData\Roaming:86dabf594e68b7fb8ac56037576b6591 [394]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [10024]
FirewallRules: [UDP Query User{62798C89-761F-4F31-9A09-6162F12AFB42}D:\program files\netease\mumuplayer\nx_device\12.0\shell\mumunxdevice.exe] => (Allow) D:\program files\netease\mumuplayer\nx_device\12.0\shell\mumunxdevice.exe => No File
FirewallRules: [TCP Query User{7E7F8BC7-52F0-4BBE-A1DC-BC9450A8A534}D:\program files\netease\mumuplayer\nx_device\12.0\shell\mumunxdevice.exe] => (Allow) D:\program files\netease\mumuplayer\nx_device\12.0\shell\mumunxdevice.exe => No File
FirewallRules: [{BA0F92D6-51E6-4330-B8A6-770E59DC48A2}] => (Allow) D:\Program Files\Netease\MuMuPlayer\nx_main\MuMuNxMain.exe => No File
FirewallRules: [{754F8D67-C972-4C55-BD54-3E8FEEF84A79}] => (Allow) C:\Program Files\MuMuVMMVbox\Hypervisor\MuMuVMMHeadless.exe => No File
FirewallRules: [{61D5A1AC-FCF5-44A9-B74E-FECF604F4BF8}] => (Allow) C:\Program Files\MuMuVMMVbox\Hypervisor\MuMuVMMSVC.exe => No File
FirewallRules: [{DA19F662-C90A-4C6B-B20E-3406543E7731}] => (Block) D:\downloaded games\[230330] [poison] sex-loving family\ntrkazoku.exe => No File
FirewallRules: [{587982E1-713B-48CB-AA23-A573A36B32E0}] => (Block) D:\downloaded games\[230330] [poison] sex-loving family\ntrkazoku.exe => No File
FirewallRules: [UDP Query User{C5979DEC-C0D7-47FD-8B97-A87547502328}D:\downloaded games\[230330] [poison] sex-loving family\ntrkazoku.exe] => (Allow) D:\downloaded games\[230330] [poison] sex-loving family\ntrkazoku.exe => No File
FirewallRules: [TCP Query User{A6B216E8-8B76-4E3F-B36D-1F8B6F9D0A6E}D:\downloaded games\[230330] [poison] sex-loving family\ntrkazoku.exe] => (Allow) D:\downloaded games\[230330] [poison] sex-loving family\ntrkazoku.exe => No File
FirewallRules: [UDP Query User{4337FE0D-EC9E-4B50-AFD2-6FD1F5313AB8}D:\games\coaglobal\coaglobalgame\seria\binaries\win64\seria.exe] => (Allow) D:\games\coaglobal\coaglobalgame\seria\binaries\win64\seria.exe => No File
FirewallRules: [TCP Query User{27C3D526-25A6-40CB-A5B5-A43CF106464A}D:\games\coaglobal\coaglobalgame\seria\binaries\win64\seria.exe] => (Allow) D:\games\coaglobal\coaglobalgame\seria\binaries\win64\seria.exe => No File
FirewallRules: [{ED8EFB63-F86A-453F-98C5-75207771FA88}] => (Allow) D:\SteamLibrary\steamapps\common\Split Fiction\Split\Binaries\Win64\SplitFiction.exe => No File
FirewallRules: [{8496325E-2A77-41D8-81C3-4259A441BA6B}] => (Allow) D:\SteamLibrary\steamapps\common\Split Fiction\Split\Binaries\Win64\SplitFiction.exe => No File
FirewallRules: [UDP Query User{2EA4464D-3B74-4D6B-A252-3601DB275731}D:\games\split fiction\split\binaries\win64\splitfiction.exe] => (Block) D:\games\split fiction\split\binaries\win64\splitfiction.exe => No File
FirewallRules: [TCP Query User{ED75314D-E698-486E-AB5C-4F3C5C74661F}D:\games\split fiction\split\binaries\win64\splitfiction.exe] => (Block) D:\games\split fiction\split\binaries\win64\splitfiction.exe => No File
FirewallRules: [UDP Query User{14019DAE-2376-46E7-BCA3-B9EECF6CE204}D:\games\metaphor - refantazio\metaphor.exe] => (Allow) D:\games\metaphor - refantazio\metaphor.exe => No File
FirewallRules: [TCP Query User{D55340A9-304E-424C-8C5C-F64DE4979190}D:\games\metaphor - refantazio\metaphor.exe] => (Allow) D:\games\metaphor - refantazio\metaphor.exe => No File
FirewallRules: [UDP Query User{E185D89D-2A99-44F8-8211-8B02452FD494}D:\games\worldwarz\en_us\client\bin\pc\wwzretailegs.exe] => (Allow) D:\games\worldwarz\en_us\client\bin\pc\wwzretailegs.exe => No File
FirewallRules: [TCP Query User{491AFC0F-440F-427E-8F91-2B1834458F80}D:\games\worldwarz\en_us\client\bin\pc\wwzretailegs.exe] => (Allow) D:\games\worldwarz\en_us\client\bin\pc\wwzretailegs.exe => No File
FirewallRules: [UDP Query User{DBD736D1-9ADB-4E63-B6A6-F4B677026A82}V:\steam\steamapps\common\marvelrivals\marvelgame\marvel\binaries\win64\marvel-win64-shipping.exe] => (Allow) V:\steam\steamapps\common\marvelrivals\marvelgame\marvel\binaries\win64\marvel-win64-shipping.exe => No File
FirewallRules: [TCP Query User{4FF25DB8-64C7-4C68-8DD0-881CED6ED631}V:\steam\steamapps\common\marvelrivals\marvelgame\marvel\binaries\win64\marvel-win64-shipping.exe] => (Allow) V:\steam\steamapps\common\marvelrivals\marvelgame\marvel\binaries\win64\marvel-win64-shipping.exe => No File
FirewallRules: [UDP Query User{7B3D3708-EE3C-4E43-804C-80FB90187F9D}C:\users\ngkho\appdata\local\discord\app-1.0.9161\discord.exe] => (Allow) C:\users\ngkho\appdata\local\discord\app-1.0.9161\discord.exe => No File
FirewallRules: [TCP Query User{92729AE1-A347-49CA-A5C7-C415790F39E4}C:\users\ngkho\appdata\local\discord\app-1.0.9161\discord.exe] => (Allow) C:\users\ngkho\appdata\local\discord\app-1.0.9161\discord.exe => No File
FirewallRules: [UDP Query User{E3348E67-58EF-4D9C-9FFA-375F05F945D2}V:\games\palworld 2.2\pal\binaries\win64\palworld-win64-shipping.exe] => (Allow) V:\games\palworld 2.2\pal\binaries\win64\palworld-win64-shipping.exe => No File
FirewallRules: [TCP Query User{E184ED52-897E-4AC9-883D-2C0002990714}V:\games\palworld 2.2\pal\binaries\win64\palworld-win64-shipping.exe] => (Allow) V:\games\palworld 2.2\pal\binaries\win64\palworld-win64-shipping.exe => No File
FirewallRules: [UDP Query User{ACF8796D-7634-460B-ACC2-A9F4B2CFB79E}V:\games\palworld 2.1\pal\binaries\win64\palworld-win64-shipping.exe] => (Allow) V:\games\palworld 2.1\pal\binaries\win64\palworld-win64-shipping.exe => No File
FirewallRules: [TCP Query User{C51B0A5F-6328-4B8F-A815-0DA343BCDD99}V:\games\palworld 2.1\pal\binaries\win64\palworld-win64-shipping.exe] => (Allow) V:\games\palworld 2.1\pal\binaries\win64\palworld-win64-shipping.exe => No File
FirewallRules: [UDP Query User{F723B5EC-0B35-470D-A343-358F59432059}V:\games\palworld\pal\binaries\win64\palworld-win64-shipping.exe] => (Allow) V:\games\palworld\pal\binaries\win64\palworld-win64-shipping.exe => No File
FirewallRules: [TCP Query User{850A35FA-1A57-4C92-8FE5-E43E37971B53}V:\games\palworld\pal\binaries\win64\palworld-win64-shipping.exe] => (Allow) V:\games\palworld\pal\binaries\win64\palworld-win64-shipping.exe => No File
FirewallRules: [UDP Query User{8BBF64C2-CDBB-4659-B34E-40F4764328E8}V:\games\palworld\pal\binaries\win64\palserver-win64-test-cmd.exe] => (Allow) V:\games\palworld\pal\binaries\win64\palserver-win64-test-cmd.exe => No File
FirewallRules: [TCP Query User{06F28F7F-02A4-4D6C-9585-9252A6E8D04F}V:\games\palworld\pal\binaries\win64\palserver-win64-test-cmd.exe] => (Allow) V:\games\palworld\pal\binaries\win64\palserver-win64-test-cmd.exe => No File
FirewallRules: [UDP Query User{B664040D-89A7-4372-BFC1-377C698B47A8}V:\games\palworld\palworld\pal\binaries\win64\palserver-win64-test-cmd.exe] => (Allow) V:\games\palworld\palworld\pal\binaries\win64\palserver-win64-test-cmd.exe => No File
FirewallRules: [TCP Query User{A8EAC51C-8912-4E16-BDE7-F62684A100BF}V:\games\palworld\palworld\pal\binaries\win64\palserver-win64-test-cmd.exe] => (Allow) V:\games\palworld\palworld\pal\binaries\win64\palserver-win64-test-cmd.exe => No File
FirewallRules: [UDP Query User{334988C3-AC36-4307-9C43-F2B7B402A859}V:\games\palworld\palworld\pal\binaries\win64\palworld-win64-shipping.exe] => (Allow) V:\games\palworld\palworld\pal\binaries\win64\palworld-win64-shipping.exe => No File
FirewallRules: [TCP Query User{EBC0F322-7B20-4A7C-852B-9EE29CFD8609}V:\games\palworld\palworld\pal\binaries\win64\palworld-win64-shipping.exe] => (Allow) V:\games\palworld\palworld\pal\binaries\win64\palworld-win64-shipping.exe => No File
FirewallRules: [UDP Query User{45C35A6F-D40D-48A6-B412-3B896897330C}V:\steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe] => (Allow) V:\steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe => No File
FirewallRules: [TCP Query User{5DA97BB7-9825-48BC-A39A-C65A6F941906}V:\steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe] => (Allow) V:\steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe => No File
FirewallRules: [UDP Query User{365B9AEC-290C-4282-A7EA-F32D4AA8B65D}C:\users\ngkho\appdata\local\programs\microsoft vs code\code.exe] => (Allow) C:\users\ngkho\appdata\local\programs\microsoft vs code\code.exe => No File
FirewallRules: [TCP Query User{10E44B0F-9842-4BD5-9057-7A6AC22BEC2F}C:\users\ngkho\appdata\local\programs\microsoft vs code\code.exe] => (Allow) C:\users\ngkho\appdata\local\programs\microsoft vs code\code.exe => No File
FirewallRules: [UDP Query User{A264E272-D40C-47E7-8469-C350CC8F508F}V:\games\remnant ii\remnant2\binaries\win64\remnant2-win64-shipping.exe] => (Allow) V:\games\remnant ii\remnant2\binaries\win64\remnant2-win64-shipping.exe => No File
FirewallRules: [TCP Query User{B803E691-64A9-4927-9C86-FBF9183158E6}V:\games\remnant ii\remnant2\binaries\win64\remnant2-win64-shipping.exe] => (Allow) V:\games\remnant ii\remnant2\binaries\win64\remnant2-win64-shipping.exe => No File
FirewallRules: [UDP Query User{56DF0A5C-332A-45A4-BAE3-760811B98567}C:\steamlibrary\steamapps\common\realm royale\binaries\win64\realm.exe] => (Allow) C:\steamlibrary\steamapps\common\realm royale\binaries\win64\realm.exe => No File
FirewallRules: [TCP Query User{983EB174-2C89-48B5-B1FC-55836E0489EE}C:\steamlibrary\steamapps\common\realm royale\binaries\win64\realm.exe] => (Allow) C:\steamlibrary\steamapps\common\realm royale\binaries\win64\realm.exe => No File
FirewallRules: [UDP Query User{0703EDF2-C0D2-4EBE-8785-6DCB7419D3C0}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe => No File
FirewallRules: [TCP Query User{25EB4625-2CC1-4727-BA46-15C4406D1CF0}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe => No File
FirewallRules: [UDP Query User{57D32E7B-03E9-4AC1-AD06-B23524F99B8E}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe => No File
FirewallRules: [TCP Query User{124DCA24-F126-4CAE-B91A-042C076420F5}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe => No File
FirewallRules: [UDP Query User{D6431FDC-6DE2-4909-8628-1639DA2B660D}V:\xampp\mysql\bin\mysqld.exe] => (Allow) V:\xampp\mysql\bin\mysqld.exe => No File
FirewallRules: [TCP Query User{C9850358-6D06-449D-9C4D-20BF06ADDBFB}V:\xampp\mysql\bin\mysqld.exe] => (Allow) V:\xampp\mysql\bin\mysqld.exe => No File
FirewallRules: [UDP Query User{DBD76946-23C3-40C3-A928-B0836C3CFCE0}V:\xampp\apache\bin\httpd.exe] => (Allow) V:\xampp\apache\bin\httpd.exe => No File
FirewallRules: [TCP Query User{C6C2C8B7-46F0-42B0-A18C-7C2BA7472AEF}V:\xampp\apache\bin\httpd.exe] => (Allow) V:\xampp\apache\bin\httpd.exe => No File
FirewallRules: [UDP Query User{D3604F84-63BE-414B-BF9B-E46E3D798404}V:\games\destiny2\destiny2.exe] => (Allow) V:\games\destiny2\destiny2.exe => No File
FirewallRules: [TCP Query User{B8845FE3-E916-4813-8210-C35C39B83AD3}V:\games\destiny2\destiny2.exe] => (Allow) V:\games\destiny2\destiny2.exe => No File
FirewallRules: [{F08816C4-C0D5-4BF1-B1E7-3A036527140C}] => (Allow) V:\Mumu\emulator\nemu\EmulatorShell\NemuPlayer.exe => No File
FirewallRules: [UDP Query User{A7D06BFF-FE85-4291-B93F-A117415629FD}V:\steam\steamapps\common\destiny 2\destiny2.exe] => (Allow) V:\steam\steamapps\common\destiny 2\destiny2.exe => No File
FirewallRules: [TCP Query User{BE27E27F-5E47-4509-A429-198E5C366BCD}V:\steam\steamapps\common\destiny 2\destiny2.exe] => (Allow) V:\steam\steamapps\common\destiny 2\destiny2.exe => No File
FirewallRules: [UDP Query User{01AB4A0A-F144-451D-A4F8-45FB74C785C7}V:\games\terraria\terrariaserver.exe] => (Allow) V:\games\terraria\terrariaserver.exe => No File
FirewallRules: [TCP Query User{26A7E17C-3BDC-4A5B-A481-944262CCF0D8}V:\games\terraria\terrariaserver.exe] => (Allow) V:\games\terraria\terrariaserver.exe => No File
FirewallRules: [UDP Query User{A9C25C42-C247-46FA-883A-A8BFEB0195C5}V:\games\borderlands3\oakgame\binaries\win64\borderlands3.exe] => (Allow) V:\games\borderlands3\oakgame\binaries\win64\borderlands3.exe => No File
FirewallRules: [TCP Query User{66F4608F-3EA2-494D-921A-65D71343A95B}V:\games\borderlands3\oakgame\binaries\win64\borderlands3.exe] => (Allow) V:\games\borderlands3\oakgame\binaries\win64\borderlands3.exe => No File
FirewallRules: [{F6358D3B-7B50-4CA7-BD40-B7E6C5E8E8CB}] => (Allow) V:\Mumu\emulator\nemu\EmulatorShell\NemuPlayer.exe => No File
FirewallRules: [UDP Query User{913DA90B-EDD3-41DD-A3E1-2D8DE2C0DC74}V:\games\trine 4 - the nightmare prince\trine4.exe] => (Allow) V:\games\trine 4 - the nightmare prince\trine4.exe => No File
FirewallRules: [TCP Query User{6C43892F-2DA6-4713-A033-C19C96BE974A}V:\games\trine 4 - the nightmare prince\trine4.exe] => (Allow) V:\games\trine 4 - the nightmare prince\trine4.exe => No File
FirewallRules: [{a21dda09-ac1f-4a39-b9f3-7b311aa95873}] => (Allow) C:\Program Files\ldplayerbox\LdVBoxHeadless.exe => No File
FirewallRules: [{64055441-364C-474E-B16F-C2594FB77184}] => (Allow) C:\Program Files\MuMu9\emulator\nemu9\EmulatorShell\NemuPlayer.exe => No File
FirewallRules: [{4C8B6B25-B177-4986-8F85-B28A1F963CB1}] => (Allow) C:\Program Files\MuMu9\emulator\nemu9\EmulatorShell\NemuPlayer.exe => No File
FirewallRules: [{C5558B6E-3118-4EF6-A433-3820316F3DF5}] => (Block) V:\games\genshin impact\genshin impact game\genshinimpact.exe => No File
FirewallRules: [{D884D72C-82E6-422F-8979-1A7E1249921E}] => (Block) V:\games\genshin impact\genshin impact game\genshinimpact.exe => No File
FirewallRules: [UDP Query User{70A8E70D-C234-40CA-B61E-7506D40F08DF}V:\games\genshin impact\genshin impact game\genshinimpact.exe] => (Allow) V:\games\genshin impact\genshin impact game\genshinimpact.exe => No File
FirewallRules: [TCP Query User{F531C1DB-2DAC-483D-9ED4-51BA07A69C71}V:\games\genshin impact\genshin impact game\genshinimpact.exe] => (Allow) V:\games\genshin impact\genshin impact game\genshinimpact.exe => No File
FirewallRules: [{4DDDC1BD-06B6-4D9C-83B5-A24314C27DEF}] => (Allow) V:\garena\games\32771\riot client\riotclientservices.exe => No File
FirewallRules: [{76C24B0C-8BDF-4828-A5F0-CB7279BE8529}] => (Allow) V:\garena\games\32771\riot client\riotclientservices.exe => No File
FirewallRules: [UDP Query User{E63FB3AA-DA62-4BBF-9655-3DDCC1870704}V:\garena\games\32771\riot client\riotclientservices.exe] => (Allow) V:\garena\games\32771\riot client\riotclientservices.exe => No File
FirewallRules: [TCP Query User{3AFC57FB-0DCF-4041-BEB3-4A427E893719}V:\garena\games\32771\riot client\riotclientservices.exe] => (Allow) V:\garena\games\32771\riot client\riotclientservices.exe => No File
FirewallRules: [UDP Query User{A38499FB-2EDA-423E-828F-1CA7A5D6D75A}V:\games\overcooked2\overcooked2.exe] => (Allow) V:\games\overcooked2\overcooked2.exe => No File
FirewallRules: [TCP Query User{722AA973-C6B7-4A28-8595-0EB0A95A92E6}V:\games\overcooked2\overcooked2.exe] => (Allow) V:\games\overcooked2\overcooked2.exe => No File
FirewallRules: [{D966F4CD-FC1A-4D8C-942C-B92E763450EA}] => (Block) C:\program files\ldplayerbox\ldvboxheadless.exe => No File
FirewallRules: [{257F3E72-9F36-4204-ABD8-C807532A334E}] => (Block) C:\program files\ldplayerbox\ldvboxheadless.exe => No File
FirewallRules: [UDP Query User{D7B46E2F-4AEE-4A02-91A0-4A5AD895CE3C}C:\program files\ldplayerbox\ldvboxheadless.exe] => (Allow) C:\program files\ldplayerbox\ldvboxheadless.exe => No File
FirewallRules: [TCP Query User{6C1B88DF-7212-4976-AD09-3197C4C50E3F}C:\program files\ldplayerbox\ldvboxheadless.exe] => (Allow) C:\program files\ldplayerbox\ldvboxheadless.exe => No File
FirewallRules: [UDP Query User{B895C02F-AB99-478D-B44C-9708E6C8E49F}V:\games\gamez bdo\bin64\blackdesert64.bin] => (Block) V:\games\gamez bdo\bin64\blackdesert64.bin => No File
FirewallRules: [TCP Query User{80F9DDDB-20B5-46D6-86CA-D76854D67799}V:\games\gamez bdo\bin64\blackdesert64.bin] => (Block) V:\games\gamez bdo\bin64\blackdesert64.bin => No File
FirewallRules: [{8944DA1C-D738-4C0E-B224-9391AEE133C4}] => (Block) V:\games\it takes two\nuts\binaries\win64\ittakestwo.exe => No File
FirewallRules: [{078B1A1A-7984-4169-932F-EA7621D49583}] => (Block) V:\games\it takes two\nuts\binaries\win64\ittakestwo.exe => No File
FirewallRules: [UDP Query User{F77271B4-2E69-4ADE-B48B-516E0B45D8C5}V:\games\it takes two\nuts\binaries\win64\ittakestwo.exe] => (Allow) V:\games\it takes two\nuts\binaries\win64\ittakestwo.exe => No File
FirewallRules: [TCP Query User{194DF0D1-52E2-43B4-9DCD-DA1BA1CFB8BC}V:\games\it takes two\nuts\binaries\win64\ittakestwo.exe] => (Allow) V:\games\it takes two\nuts\binaries\win64\ittakestwo.exe => No File
FirewallRules: [{1D34B4AB-3EF3-4086-B192-6E43C148127A}] => (Block) V:\games\it takes two\nodvd\steamfix\nuts\binaries\win64\ittakestwo.exe => No File
FirewallRules: [{D03BCD58-AA34-46A7-9BC2-1B397E18CE1B}] => (Block) V:\games\it takes two\nodvd\steamfix\nuts\binaries\win64\ittakestwo.exe => No File
FirewallRules: [UDP Query User{647DE512-DA39-4EE5-AC43-459BAE3CACB0}V:\games\it takes two\nodvd\steamfix\nuts\binaries\win64\ittakestwo.exe] => (Allow) V:\games\it takes two\nodvd\steamfix\nuts\binaries\win64\ittakestwo.exe => No File
FirewallRules: [TCP Query User{EDD4B50A-BD1D-4545-A5A4-234B06E5918B}V:\games\it takes two\nodvd\steamfix\nuts\binaries\win64\ittakestwo.exe] => (Allow) V:\games\it takes two\nodvd\steamfix\nuts\binaries\win64\ittakestwo.exe => No File
FirewallRules: [{868F1D41-A5F2-42E7-BA43-BCF9D2E58F5C}] => (Allow) V:\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File
FirewallRules: [{9FE37991-CDBC-4A63-9237-4CF2B7FD4BB1}] => (Allow) V:\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File
FirewallRules: [{92D36581-27D9-4854-9B0F-D4045C80BE9C}] => (Allow) V:\Garena\Garena\2.0.1909.2618\gxxsvc.exe => No File
FirewallRules: [TCP Query User{91C0C09F-3DD9-4DDD-A2BC-095B763CD703}V:\garena\games\32771\game\league of legends.exe] => (Allow) V:\garena\games\32771\game\league of legends.exe => No File
FirewallRules: [UDP Query User{45F2E297-30E9-465A-8D00-F3A9C01B2C54}V:\garena\games\32771\game\league of legends.exe] => (Allow) V:\garena\games\32771\game\league of legends.exe => No File
FirewallRules: [{904B273A-84DF-4D17-BB83-9DFC5794B691}] => (Allow) C:\Program Files (x86)\Gigabyte\CloudStation\HomeCloud\HCLOUD.exe => No File
FirewallRules: [{9E9A0A1D-96D1-483D-990F-7A97A35E51B7}] => (Allow) C:\Program Files (x86)\Gigabyte\CloudStation\RemoteOC\ubssrv_oc_only.exe => No File
FirewallRules: [{1A49134D-2307-478F-A23E-DA65B3B377F1}] => (Allow) C:\Program Files (x86)\Gigabyte\CloudStation\RemoteControl\grckm.exe => No File
FirewallRules: [TCP Query User{12763F95-780C-47EE-90C1-192C79DE7A26}V:\steam\steamapps\common\kurtzpel\thechase\binaries\win64\thechase-win64-shipping.exe] => (Allow) V:\steam\steamapps\common\kurtzpel\thechase\binaries\win64\thechase-win64-shipping.exe => No File
FirewallRules: [UDP Query User{E8DF2D3B-721A-4536-BE9E-F289C4E5D5E1}V:\steam\steamapps\common\kurtzpel\thechase\binaries\win64\thechase-win64-shipping.exe] => (Allow) V:\steam\steamapps\common\kurtzpel\thechase\binaries\win64\thechase-win64-shipping.exe => No File
FirewallRules: [{95A85CB4-E2BA-4D34-B681-8726839BC4AA}] => (Allow) V:\Steam\steamapps\common\Realm Royale\Binaries\Win64\RealmEAC.exe => No File
FirewallRules: [{5523D602-4C3B-40D4-A0D9-1C9674A66E92}] => (Allow) V:\Steam\steamapps\common\Realm Royale\Binaries\Win64\RealmEAC.exe => No File
FirewallRules: [TCP Query User{E3E6E783-AE4E-4F95-A035-840EC03AA411}V:\steam\steamapps\common\realm royale\binaries\win64\realm.exe] => (Allow) V:\steam\steamapps\common\realm royale\binaries\win64\realm.exe => No File
FirewallRules: [UDP Query User{C7D2959F-0A84-41EB-8D4C-E21A5B134B42}V:\steam\steamapps\common\realm royale\binaries\win64\realm.exe] => (Allow) V:\steam\steamapps\common\realm royale\binaries\win64\realm.exe => No File
FirewallRules: [{96F270F5-8EA3-4C65-ADC5-6BFBF08C088F}] => (Allow) V:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{17BF507C-137F-4A80-8DD2-E246B759A4F6}] => (Allow) V:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [TCP Query User{220F6F8C-2689-4755-89FA-2934A062A264}C:\users\ngkho\desktop\gamezbd launcher\gamezbdo.exe] => (Allow) C:\users\ngkho\desktop\gamezbd launcher\gamezbdo.exe => No File
FirewallRules: [UDP Query User{E0A858DF-DAE6-46C0-BA24-8A214CBA7370}C:\users\ngkho\desktop\gamezbd launcher\gamezbdo.exe] => (Allow) C:\users\ngkho\desktop\gamezbd launcher\gamezbdo.exe => No File
FirewallRules: [TCP Query User{960D1247-4AF8-4EDF-AB14-134BA925C0DD}C:\users\ngkho\appdata\local\programs\opera\67.0.3575.97\opera.exe] => (Allow) C:\users\ngkho\appdata\local\programs\opera\67.0.3575.97\opera.exe => No File
FirewallRules: [UDP Query User{B7B10113-ECE6-4F70-A1BB-E103C4020793}C:\users\ngkho\appdata\local\programs\opera\67.0.3575.97\opera.exe] => (Allow) C:\users\ngkho\appdata\local\programs\opera\67.0.3575.97\opera.exe => No File
FirewallRules: [TCP Query User{31D2335F-89EF-4B52-A130-A02282A71400}V:\games\remnant - from the ashes\remnant\binaries\win64\remnant-win64-shipping.exe] => (Allow) V:\games\remnant - from the ashes\remnant\binaries\win64\remnant-win64-shipping.exe => No File
FirewallRules: [UDP Query User{D5593BA0-07B8-4290-B653-57B06DEF048B}V:\games\remnant - from the ashes\remnant\binaries\win64\remnant-win64-shipping.exe] => (Allow) V:\games\remnant - from the ashes\remnant\binaries\win64\remnant-win64-shipping.exe => No File
FirewallRules: [{16EB8816-2F20-4FA7-AD1C-8C0CF7649892}] => (Block) V:\games\remnant - from the ashes\remnant\binaries\win64\remnant-win64-shipping.exe => No File
FirewallRules: [{D4D58954-A564-4BAD-99ED-FEEEBFECFCCC}] => (Block) V:\games\remnant - from the ashes\remnant\binaries\win64\remnant-win64-shipping.exe => No File
FirewallRules: [TCP Query User{636A200F-766B-444C-B43A-AA32993AF7F8}C:\program files (x86)\call of duty modern warfare\modernwarfare.exe] => (Allow) C:\program files (x86)\call of duty modern warfare\modernwarfare.exe => No File
FirewallRules: [UDP Query User{F9DF32D0-DBF8-432E-9D12-C95B8C27B56D}C:\program files (x86)\call of duty modern warfare\modernwarfare.exe] => (Allow) C:\program files (x86)\call of duty modern warfare\modernwarfare.exe => No File
FirewallRules: [TCP Query User{1BEDBEE5-BE70-49A7-B36C-8FB193BD8770}V:\games\pearl abyss\black desert\bin64\blackdesert64.exe] => (Block) V:\games\pearl abyss\black desert\bin64\blackdesert64.exe => No File
FirewallRules: [UDP Query User{CF480377-7FDD-48FF-B1CA-4DBC9CABBFFC}V:\games\pearl abyss\black desert\bin64\blackdesert64.exe] => (Block) V:\games\pearl abyss\black desert\bin64\blackdesert64.exe => No File
FirewallRules: [TCP Query User{7735ACB1-DDC2-42A6-BCB3-9DFA6B4D3AF2}V:\games\gamez bdo\gamezbdo.exe] => (Allow) V:\games\gamez bdo\gamezbdo.exe => No File
FirewallRules: [UDP Query User{C6FEE2F5-3F3E-4144-B80E-59846FE7956B}V:\games\gamez bdo\gamezbdo.exe] => (Allow) V:\games\gamez bdo\gamezbdo.exe => No File
FirewallRules: [{6DF1E736-239E-408C-91EE-7BB358E68EBE}] => (Block) V:\games\gamez bdo\gamezbdo.exe => No File
FirewallRules: [{6D60FC96-B4AF-48B4-9095-7B10F02A9B17}] => (Block) V:\games\gamez bdo\gamezbdo.exe => No File
FirewallRules: [TCP Query User{6A9D967E-C8F6-403D-89AD-8A2C0B47608E}V:\games\risk of rain 2\risk of rain 2.exe] => (Allow) V:\games\risk of rain 2\risk of rain 2.exe => No File
FirewallRules: [UDP Query User{E4525760-054F-4A7F-8756-D8BE1497D872}V:\games\risk of rain 2\risk of rain 2.exe] => (Allow) V:\games\risk of rain 2\risk of rain 2.exe => No File
FirewallRules: [{64643E20-0C37-45A8-B22B-F70DAA1185BB}] => (Allow) V:\Epic Games\Warframe\Downloaded\Tools\Launcher.exe => No File
FirewallRules: [{53A3C9B2-7B99-4599-AF37-0AA38B1B8829}] => (Allow) V:\Epic Games\Warframe\Downloaded\Warframe.x64.exe => No File
FirewallRules: [{8BC0C0AC-A31F-432F-9032-35D2388A3D27}] => (Allow) V:\Epic Games\Warframe\Downloaded\Warframe.x64.exe => No File
FirewallRules: [{0B1031D7-5DAA-49DC-8814-77DDC980F057}] => (Allow) V:\Epic Games\Warframe\Downloaded\Tools\RemoteCrashSender.exe => No File
FirewallRules: [{2E479BD3-D5EA-4D68-AA5A-6634BD32DF8F}] => (Allow) V:\Epic Games\Warframe\Downloaded\Tools\Launcher.exe => No File
FirewallRules: [{D7E8E93F-9954-4C21-A2CD-46F726790C47}] => (Allow) V:\Epic Games\Warframe\Downloaded\Warframe.x64.exe => No File
FirewallRules: [{46EF5CEE-6EBC-4829-A125-BADE6F4875DA}] => (Allow) V:\Epic Games\Warframe\Downloaded\Warframe.x64.exe => No File
FirewallRules: [{03B93F59-13F3-408A-9CEF-99201BB3A4E2}] => (Allow) V:\Epic Games\Warframe\Downloaded\Tools\RemoteCrashSender.exe => No File
FirewallRules: [TCP Query User{72DE518B-DBD6-4F9E-A229-F6C6B044756A}V:\games\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Allow) V:\games\cyberpunk 2077\bin\x64\cyberpunk2077.exe => No File
FirewallRules: [UDP Query User{A4A136A7-4B6B-4543-96BB-7CBC53C1D835}V:\games\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Allow) V:\games\cyberpunk 2077\bin\x64\cyberpunk2077.exe => No File
FirewallRules: [{63DF5B62-C8B5-4F1F-8DB9-A5FC906DF3C0}] => (Block) V:\games\cyberpunk 2077\bin\x64\cyberpunk2077.exe => No File
FirewallRules: [{FB0A10F5-0356-4740-BC65-0C7C93871D3F}] => (Block) V:\games\cyberpunk 2077\bin\x64\cyberpunk2077.exe => No File
FirewallRules: [TCP Query User{B2F66A55-82BE-4476-B1B8-C96B8987C498}V:\games\left 4 dead 2\left4dead2.exe] => (Allow) V:\games\left 4 dead 2\left4dead2.exe => No File
FirewallRules: [UDP Query User{B7006CF7-FC23-4ECE-9A13-A655E6BC50B6}V:\games\left 4 dead 2\left4dead2.exe] => (Allow) V:\games\left 4 dead 2\left4dead2.exe => No File
FirewallRules: [{CAB33524-0713-40E5-B400-9670CAE11A05}] => (Block) V:\games\left 4 dead 2\left4dead2.exe => No File
FirewallRules: [{6EC6E161-3664-4B5D-9296-04BFA777DCAC}] => (Block) V:\games\left 4 dead 2\left4dead2.exe => No File
HKU\S-1-5-21-2806995396-159071790-1316216123-1001\...\MountPoints2: {3d8fa81d-adc4-11f0-a5ff-709cd14fa1bd} - "E:\setup.exe"
Task: {31414B0D-F2F1-48E7-BEE3-B4F13266D3B0} - System32\Tasks\Microsoft\Windows\Clip\ClipESU => %SystemRoot%\system32\clipesu.exe (No File)
Task: {267CFD00-B070-4432-89E5-496AB76C31D5} - System32\Tasks\Microsoft\Windows\Clip\ClipESUConsumer => %SystemRoot%\system32\ClipESUConsumer.exe -evaluateEligibility (No File)
Task: {AB27CB38-8552-459C-B276-D2A146589862} - System32\Tasks\Microsoft\Windows\Clip\ClipEsuConsumerProcessPreOrder => %SystemRoot%\system32\ClipESUConsumer.exe -postProcessPreOrder (No File)
Task: {9323867C-B53A-4039-A008-7227CAE04417} - System32\Tasks\Microsoft\Windows\Clip\ClipEsuConsumerProcessRefund => %SystemRoot%\system32\ClipESUConsumer.exe -processRefund (No File)
Task: {DC8A6891-DB6D-4DEE-B62C-EBEFC9ECE4F4} - System32\Tasks\Microsoft\Windows\Clip\EnableClipESU => %SystemRoot%\system32\clipesu.exe -e (No File)
Task: {E88D9B2C-DDEA-47B2-9582-085153004DB5} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
Task: {CAB76809-EDC0-40D2-A888-AD9BEDF4E88A} - System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr => %windir%\System32\UNP\UpdateNotificationMgr.exe (No File)
Task: {9B8A7CD5-15AA-4B64-8011-9D7A5CCA8366} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe LogonDisplay (No File)
Task: {9B22233F-35E6-4087-9D00-A7F558474D9F} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC Reboot (No File)
Task: {3413DC7E-6E42-4ECE-A912-35E321852335} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery Reboot (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {536E4B58-8B7A-403B-8F70-9220C5A62EE4} - System32\Tasks\S-1-5-21-2806995396-159071790-1316216123-1001\DataSenseLiveTileTask => %SystemRoot%\System32\DataUsageLiveTileTask.exe (No File)
S3 BlackCat1; \??\C:\ProgramData\Nexon\NGS\BlackCat1.sys (No File)
S3 HWiNFO_150; \??\C:\Users\NgKho\AppData\Local\Temp\HWiNFO64A_150.SYS (No File) <==== ATTENTION
S3 HWiNFO_206; \??\C:\Users\NgKho\AppData\Local\Temp\HWiNFO_x64_206.sys (No File) <==== ATTENTION
S3 WinRing0_1_2_0; \??\C:\Users\NgKho\Desktop\openhardwaremonitor-v0.9.6\OpenHardwareMonitor\OpenHardwareMonitorLib.sys (No File)
2025-11-15 06:09 - 2025-11-15 06:09 - 000000048 ____R () C:\Users\NgKho\AppData\Local\47C775A3FE68A525E8B1D40D67CA11AA
2026-05-30 17:01 - 2026-05-30 17:01 - 000000048 ____R () C:\Users\NgKho\AppData\Local\AB94542F5FADE6F8B81D4B79C11311EF
2024-12-11 15:39 - 2024-12-11 15:39 - 000000048 ____R () C:\Users\NgKho\AppData\Local\EAA2DE278028D0939D0668501C6C404A
StartPowerShell:
# This snippet re-enables Windows Defender and applies optimized settings to ensure high protection against malware
# Enable real-time protection
Set-MpPreference -DisableRealtimeMonitoring $false
# Enable behavioural protection
Set-MpPreference -DisableBehaviorMonitoring $false
# Enable PUP detection
Set-MpPreference -PUAProtection Enabled
# Enable cloud protection to level 4 - aggressively block unknowns and apply additional protection measures, alternatively use 2 for lower protection or 0 for default
Set-MpPreference -CloudBlockLevel 4
# Send advanced information about malicious/unwanted software present on your device
Set-MpPreference -MAPSReporting 2
# Send safe samples automatically to Microsoft
Set-MpPreference -SubmitSamplesConsent 1
# Enables inspection of HTTP traffic to detect malicious websites
Set-MpPreference -EnableNetworkProtection Enabled
# Enables block at first seen
Set-MpPreference -DisableBlockAtFirstSeen $false
# Allows scanning of archive files, such as .zip and .cab files for malware/PUP
Set-MpPreference -DisableArchiveScanning $false
# Enables automatic scanning of USB & removal drives
Set-MpPreference -DisableRemovableDriveScanning $false
# Enables scanning of network files
Set-MpPreference -DisableScanningNetworkFiles $false
# Forces signature check before running a scan
Set-MpPreference -CheckForSignaturesBeforeRunningScan $true
# Extends cloud check timer from default 10 to 30 seconds
Set-MpPreference -CloudExtendedTimeout 30
# Enables automatic scanning of all downloaded files and attachments
Set-MpPreference -DisableIOAVProtection $false
# Enables script detection
Set-MpPreference -DisableScriptScanning $false
# Disables automatic exclusions from scanning
Set-MpPreference -DisableAutoExclusions 1
# Enables scanning of mapped network drives
Set-MpPreference -DisableScanningMappedNetworkDrivesForFullScan 0
# Enables scanning of email files
Set-MpPreference -DisableEmailScanning 0
# Enables blocking of malicious domains and IP's on DNS level
Set-MpPreference -EnableDnsSinkhole $true
# Enables signature updates every 12 hours
Set-MpPreference -SignatureUpdateInterval 12
# Enables automatic quarantine for threats labelled as high and severe
Set-MpPreference -HighThreatDefaultAction Quarantine
Set-MpPreference -SevereThreatDefaultAction Quarantine
# Updates signatures
Update-MpSignature
EndPowerShell:
StartPowershell:
# Replace /scanonly with /clean if you also want to delete items -- however, this will activate a trial license on the system, I do not recommend it
$hmpExe = "$env:TEMP\HitmanPro_x64.exe"
$logFile = "$env:TEMP\HitmanPro_ScanLog.txt"
Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing
$proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru
if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 }
Get-Content $logFile -Encoding Unicode
EndPowershell:
StartPowerShell:
# Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console
# Does not clean preinstalled objects, only PUP/Adware
# If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument
# If you would like to only scan with it, change the argument from /clean to /scan
# NOTE: For the sake of users from Asia (primarily China), do not use the clean option. It will very likely remove a lot of their important software.
New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null
Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden
$logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile
Get-Content $logFile -Encoding Unicode
Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue
EndPowerShell:
Comment: List Windows Defender properties, settings
StartPowerShell:
function Write-Section {
param([string]$Title)
Write-Host ""
Write-Host "<=== $Title ===>"
}
Write-Section "Protection Status"
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntispywareEnabled, AntivirusEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, RealTimeProtectionEnabled, IsTamperProtected, NetworkProtectionStatus | Format-List
Write-Section "Signature / Engine Versions"
Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AntivirusSignatureVersion, AntispywareSignatureVersion | Format-List
Write-Section "Preferences / Configuration"
Get-MpPreference | Select-Object PUAProtection, MAPSReporting, SubmitSamplesConsent, CheckForSignaturesBeforeRunningScan, CloudBlockLevel, EnableNetworkProtection, DisableScriptScanning, DisableArchiveScanning, DisableRemovableDriveScanning, DisableScanningNetworkFiles, DisableScanningMappedNetworkDrivesForFullScan, DisableBlockAtFirstSeen, DisableHeuristics, DisableAutoExclusions | Format-List
Write-Section "Threat Detections"
$threats = Get-MpThreatDetection
if ($threats) {
$threats | Format-Table -AutoSize
} else {
Write-Host " (no threat detections found)"
}
EndPowerShell:
Comment: List drive info, identify possible damaged drives (thanks to AdvancedSetup from Malwarebytes for parts of these)
StartPowerShell:
param(
[int]$MaxEvents = 2000
)
$GPTTypeMap = @{
'EBD0A0A2-B9E5-4433-87C0-68B6B72699C7' = 'Microsoft Basic Data'
'E3C9E316-0B5C-4DB8-817D-F92DF00215AE' = 'Microsoft Reserved (MSR)'
'DE94BBA4-06D1-4D40-A16A-BFD50179D6AC' = 'Windows Recovery Environment (WinRE)'
'C12A7328-F81F-11D2-BA4B-00A0C93EC93B' = 'EFI System Partition'
'21686148-6449-6E6F-744E-656564454649' = 'BIOS Boot Partition'
'A19D880F-05FC-4D3B-A006-743F0F84911E' = 'OEM Partition'
'5808C8AA-7E8F-42E0-85D2-E1E90434CFB3' = 'Cluster Metadata Partition'
'48465300-0000-11AA-AA11-00306543ECAC' = 'Apple HFS/HFS+'
'7C3457EF-0000-11AA-AA11-00306543ECAC' = 'Apple APFS'
'0FC63DAF-8483-4772-8E79-3D69D8477DE4' = 'Linux Filesystem'
'0657FD6D-A4AB-43C4-84E5-0933C84B4F4F' = 'Linux Swap'
'E6D6D379-F507-44C2-A23C-238F2A3DF928' = 'Linux LVM'
}
$MBRTypeMap = @{
'01'='FAT12';'04'='FAT16 <32M';'05'='Extended';'06'='FAT16';'07'='IFS/NTFS/exFAT/HPFS';'0B'='FAT32 CHS';'0C'='FAT32 LBA';'0E'='FAT16 LBA'
'0F'='Extended LBA';'82'='Linux Swap';'83'='Linux Native';'8E'='Linux LVM';'A5'='FreeBSD';'A6'='OpenBSD';'A8'='Mac OS X';'AB'='Mac OS X Boot'
'AF'='Mac OS X HFS';'EE'='EFI GPT Protective';'EF'='EFI System Partition'
}
function Get-PartitionTypeInfo {
param($Partition)
$guid = $null
if ($Partition.GptType) {
$guid = ($Partition.GptType -replace '[{}]', '').ToUpper()
}
if ([string]::IsNullOrWhiteSpace($guid) -or $guid -eq '00000000-0000-0000-0000-000000000000') {
$guid = switch ($Partition.Type) {
"System" { "C12A7328-F81F-11D2-BA4B-00A0C93EC93B" }
"Reserved" { "E3C9E316-0B5C-4DB8-817D-F92DF00215AE" }
"Basic" { "EBD0A0A2-B9E5-4433-87C0-68B6B72699C7" }
"Recovery" { "DE94BBA4-06D1-4D40-A16A-BFD50179D6AC" }
default { $null }
}
}
if ($guid) {
$name = $GPTTypeMap[$guid]
if ($name) { return "$name (GPT GUID: $($guid.ToLower()))" }
else { return "Unknown/Custom (GPT GUID: $($guid.ToLower()))" }
}
if ($Partition.MbrType) {
$code = ($Partition.MbrType.ToString() -replace '^0x', '').PadLeft(2, '0').ToUpper()
$name = $MBRTypeMap[$code]
if ($name) { return "$name (MBR code: 0x$code)" }
else { return "Unknown/Custom (MBR code: $($Partition.MbrType))" }
}
return $Partition.Type
}
function Get-DrMapping {
param([int]$MaxEvents)
$map = @{}
try {
$events = Get-WinEvent -FilterHashtable @{ LogName = 'System'; ProviderName = 'disk' } -MaxEvents $MaxEvents -ErrorAction Stop
} catch {
return $map
}
foreach ($e in $events) {
if ($e.Message -match 'Harddisk(\d+)\\DR(\d+)') {
$n = [int]$Matches[1]
$dr = [int]$Matches[2]
if (-not $map.ContainsKey($n)) { $map[$n] = $dr }
}
}
return $map
}
$drMap = Get-DrMapping -MaxEvents $MaxEvents
$physicalDisks = Get-PhysicalDisk | Select-Object DeviceId, FriendlyName, SerialNumber, MediaType, @{N='SizeGB';E={[math]::Round($_.Size / 1GB,2)}}
foreach ($pd in $physicalDisks) {
$devId = [int]$pd.DeviceId
$drSuffix = if ($drMap.ContainsKey($devId)) { "\DR$($drMap[$devId])" } else { '\DR? (no event seen yet)' }
Write-Host ""
Write-Host "<=== \Device\Harddisk$devId$drSuffix ($($pd.FriendlyName)) ===>"
Write-Host " DeviceId: $devId | Serial: $($pd.SerialNumber) | Media: $($pd.MediaType) | Size: $($pd.SizeGB) GB"
try {
$partitions = Get-Partition -DiskNumber $devId -ErrorAction Stop
if (-not $partitions) {
Write-Host " (no partitions found)"
continue
}
foreach ($part in $partitions) {
$driveLetter = if ($part.DriveLetter) { "$($part.DriveLetter):" } else { 'no letter' }
$sizeGB = [math]::Round($part.Size / 1GB, 2)
$typeInfo = Get-PartitionTypeInfo -Partition $part
Write-Host " [PARTITION $($part.PartitionNumber)] Drive: $driveLetter - $sizeGB GB - $typeInfo"
}
} catch {
Write-Host " [ERROR] cannot read partitions for disk $devId"
}
}
if ($drMap.Count -eq 0) {
Write-Host ""
Write-Host "Note: no \Device\HarddiskN\DRx entries found in the last $MaxEvents System log events. Increase -MaxEvents, or the DR number will only appear once Windows actually logs a disk event for that drive (e.g. a bad block warning)."
}
EndPowerShell:
Comment: Verify that Discord does not have any injected code to intercept personal data. If anything is prompted here, it needs to be checked that it isn't malicious code.
Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) }
StartPowerShell:
# Basic BSOD listings
$ccKey = "HKLM:\SYSTEM\CurrentControlSet\Control\CrashControl"
$cfg = Get-ItemProperty $ccKey -ErrorAction SilentlyContinue
$dumpTypeMap = @{0='None';1='Complete';2='Kernel';3='Minidump';7='Automatic'}
Write-Output "--- Configuration ---"
Write-Output ("Dump Type: {0} ({1})" -f $cfg.CrashDumpEnabled, $dumpTypeMap[$cfg.CrashDumpEnabled])
Write-Output ("Full Dump Path: {0}" -f $(if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}))
Write-Output ("Minidump Folder: {0}" -f $(if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}))
Write-Output ("Auto Reboot: {0}" -f $(if($cfg.AutoReboot -eq 0){'Disabled'}else{'Enabled'}))
Write-Output "--- Found Dump Files ---"
$full = if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}
if (Test-Path $full) { Get-Item $full | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
$mini = if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}
if (Test-Path $mini) { Get-ChildItem $mini -Filter *.dmp | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
Write-Output "--- BugCheck Reasoning (recent events) ---"
$map = @{
'0x0000000A'='IRQL_NOT_LESS_OR_EQUAL - faulty/outdated driver accessed memory at high IRQL'
'0x0000001E'='KMODE_EXCEPTION_NOT_HANDLED - unhandled kernel exception, often driver/hardware'
'0x0000002E'='DATA_BUS_ERROR - typically bad RAM or hardware fault'
'0x0000003B'='SYSTEM_SERVICE_EXCEPTION - exception in a system service, often driver-related'
'0x00000050'='PAGE_FAULT_IN_NONPAGED_AREA - bad RAM or faulty driver/antivirus'
'0x0000007A'='KERNEL_DATA_INPAGE_ERROR - disk-related problem'
'0x0000007B'='INACCESSIBLE_BOOT_DEVICE - system could not find/access the boot device'
'0x0000007E'='SYSTEM_THREAD_EXCEPTION_NOT_HANDLED - almost always a faulty driver'
'0x0000007F'='UNEXPECTED_KERNEL_MODE_TRAP - hardware issue (CPU/RAM/overclocking)'
'0x0000009F'='DRIVER_POWER_STATE_FAILURE - driver failed to respond to a power state change'
'0x000000C2'='BAD_POOL_CALLER - driver mishandling memory (pool corruption)'
'0x000000D1'='DRIVER_IRQL_NOT_LESS_OR_EQUAL - typically a network or GPU driver'
'0x000000EF'='CRITICAL_PROCESS_DIED - a critical system process died, often malware/system corruption'
'0x00000116'='VIDEO_TDR_FAILURE - GPU driver failed to respond in time (timeout)'
'0x00000124'='WHEA_UNCORRECTABLE_ERROR - hardware fault (CPU/RAM/PSU/overclocking)'
'0x00000133'='DPC_WATCHDOG_VIOLATION - faulty driver or storage subsystem issue'
'0x00000139'='KERNEL_SECURITY_CHECK_FAILURE - corrupted kernel structure, possibly malware'
}
$events = Get-WinEvent -FilterHashtable @{LogName='System';Id=1001} -MaxEvents 100 -ErrorAction SilentlyContinue |
Where-Object { $_.ProviderName -match 'WER-SystemErrorReporting' } | Select-Object -First 5
if (-not $events) { Write-Output "No BugCheck events found in the log." }
foreach ($ev in $events) {
$code = if ($ev.Message -match 'bugcheck was:\s*(0x[0-9A-Fa-f]+)') { $matches[1] } else { $null }
Write-Output ("Time: {0}" -f $ev.TimeCreated)
Write-Output ("Code: {0}" -f $(if($code){$code}else{'not recognized'}))
if ($code -and $map.ContainsKey($code.ToUpper())) {
Write-Output ("Meaning: {0}" -f $map[$code.ToUpper()])
} elseif ($code) {
Write-Output "Meaning: unknown code, look up at learn.microsoft.com/windows-hardware/drivers/debugger/bug-check-code-reference2"
}
Write-Output ""
}
EndPowerShell:
StartPowerShell:
# This snippet lists all installed apps and their folder contents along with SHA256 hashes. Useful for troubleshooting malware abusing installed app entry.
param(
[switch]$Recurse,
[int]$MaxFilesPerApp = [int]::MaxValue
)
$uninstallPaths = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
$script:msiInstaller = $null
function Get-MsiInstallLocation {
param([string]$ProductCode)
if (-not $script:msiInstaller) {
try { $script:msiInstaller = New-Object -ComObject WindowsInstaller.Installer } catch { return $null }
}
try {
$loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallLocation')
if ([string]::IsNullOrWhiteSpace($loc)) { $loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallSource') }
if ([string]::IsNullOrWhiteSpace($loc)) { return $null }
return $loc
} catch { return $null }
}
function Get-CleanPath {
param([string]$RawValue)
if ([string]::IsNullOrWhiteSpace($RawValue)) { return $null }
$s = $RawValue.Trim()
if ($s.StartsWith('"')) {
$endQuote = $s.IndexOf('"', 1)
if ($endQuote -gt 0) { return $s.Substring(1, $endQuote - 1) }
}
if ($s -match '^(.*?\.exe)\b') { return $Matches[1] }
return $s
}
function Format-FileSize {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$script:PeExtensions = @('.exe', '.dll', '.sys', '.ocx', '.cpl', '.scr', '.drv', '.efi', '.msi', '.msp', '.msu')
function Test-IsPeFile {
param([string]$Extension)
return $script:PeExtensions -contains $Extension.ToLower()
}
function Get-SignatureInfo {
param([string]$Path, [string]$Extension)
if (-not (Test-IsPeFile -Extension $Extension)) {
return [PSCustomObject]@{ Signer = 'N/A (not PE)'; Status = 'NotApplicable'; Valid = $false }
}
$result = [PSCustomObject]@{ Signer = 'Unsigned'; Status = 'NotSigned'; Valid = $false }
try {
$sig = Get-AuthenticodeSignature -LiteralPath $Path -ErrorAction Stop
$result.Status = $sig.Status.ToString()
$result.Valid = ($sig.Status -eq 'Valid')
if ($sig.SignerCertificate) {
if ($sig.SignerCertificate.Subject -match 'CN=([^,]+)') { $result.Signer = $Matches[1].Trim('"') }
else { $result.Signer = $sig.SignerCertificate.Subject }
if (-not $result.Valid) { $result.Signer += " [INVALID: $($result.Status)]" }
} elseif ($sig.Status -eq 'NotSigned') {
$result.Signer = 'Unsigned'
} else {
$result.Signer = "Unknown [$($result.Status)]"
}
} catch {
$result.Signer = 'Verification error'
$result.Status = 'Error'
$result.Valid = $false
}
return $result
}
$rawApps = Get-ItemProperty -Path $uninstallPaths -ErrorAction SilentlyContinue |
Where-Object { $_.DisplayName -and $_.DisplayName.Trim() -ne '' } |
Select-Object @{Name = 'Name'; Expression = { $_.DisplayName } },
@{Name = 'Version'; Expression = { $_.DisplayVersion } },
@{Name = 'Publisher'; Expression = { $_.Publisher } },
@{Name = 'InstallFolder'; Expression = {
if ($_.InstallLocation -and $_.InstallLocation.Trim() -ne '') { $_.InstallLocation }
elseif ($_.UninstallString -match 'MsiExec\.exe.*?(\{[0-9A-Fa-f\-]{36}\})') {
$productCode = $Matches[1]
$msiLoc = Get-MsiInstallLocation -ProductCode $productCode
if ($msiLoc) { $msiLoc } else { "MSI: $productCode (location not found)" }
}
elseif ($_.UninstallString) { $_.UninstallString }
else { 'N/A' }
} } |
Sort-Object Name -Unique
foreach ($app in $rawApps) {
$versionText = if ($app.Version) { $app.Version } else { '?' }
$publisherText = if ($app.Publisher) { $app.Publisher } else { '?' }
Write-Host ""
Write-Host "<=== $($app.Name) [$versionText] ($publisherText) ===>"
if ($app.InstallFolder -eq 'N/A' -or $app.InstallFolder -match '^MSI: .* \(location not found\)$') {
Write-Host " Path: $($app.InstallFolder)"
continue
}
$cleanPath = Get-CleanPath -RawValue $app.InstallFolder
$exists = $false
try {
$exists = Test-Path -LiteralPath $cleanPath -ErrorAction Stop
} catch [System.UnauthorizedAccessException] {
Write-Host " Path: $cleanPath"
Write-Host " [ACCESS DENIED]"
continue
} catch {
Write-Host " Path: $cleanPath"
Write-Host " [ERROR] cannot access"
continue
}
if (-not $exists) {
Write-Host " Path: $cleanPath"
Write-Host " [NOT FOUND]"
continue
}
$rootItem = Get-Item -LiteralPath $cleanPath -Force
$created = $rootItem.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$modified = $rootItem.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
if ($rootItem.PSIsContainer) {
$subFolders = Get-ChildItem -LiteralPath $cleanPath -Directory -Force -ErrorAction SilentlyContinue
$gciParams = @{ LiteralPath = $cleanPath; File = $true; Force = $true; ErrorAction = 'SilentlyContinue' }
if ($Recurse) { $gciParams['Recurse'] = $true }
$allFiles = Get-ChildItem @gciParams
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: $($allFiles.Count) | Folders: $($subFolders.Count)"
foreach ($dir in $subFolders) {
$dCreated = $dir.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$dModified = $dir.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$dFileCount = (Get-ChildItem -LiteralPath $dir.FullName -File -Force -ErrorAction SilentlyContinue).Count
Write-Host (" [DIR] {0} - {1} - {2,10} - {3}" -f $dCreated, $dModified, "$dFileCount files", $dir.FullName)
}
} else {
$allFiles = @($rootItem)
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: 1"
}
if ($allFiles.Count -eq 0) { continue }
$shown = $allFiles | Select-Object -First $MaxFilesPerApp
foreach ($f in $shown) {
$hash = 'N/A'
try { $hash = (Get-FileHash -LiteralPath $f.FullName -Algorithm SHA256 -ErrorAction Stop).Hash } catch { $hash = 'HASH-ERROR' }
$size = Format-FileSize -Bytes $f.Length
$fcreated = $f.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$fmod = $f.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$sigInfo = Get-SignatureInfo -Path $f.FullName -Extension $f.Extension
Write-Host (" [{0}] {1} - {2} - {3,10} - Signer: {4} - {5}" -f $hash, $fcreated, $fmod, $size, $sigInfo.Signer, $f.FullName)
}
}
EndPowerShell:
Comment: List 30 recent scheduled tasks (you know, just for the sake of it)
Powershell: Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo
Comment: List recent Run (Windows + R) executed commands, useful for identifying ClickFix attacks
Powershell: (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" }
Comment: Remove unwanted files from common folders using native removal power of Farbar to include remove on reboot if needed. Please double check the user does not have any applications incorrectly installed in the directories listed below.
C:\ProgramData\*.csproj
C:\ProgramData\*.a3x
C:\ProgramData\*.ahk
C:\ProgramData\*.au3
C:\ProgramData\*.bat
C:\ProgramData\*.cab
C:\ProgramData\*.cmd
C:\ProgramData\*.com
C:\ProgramData\*.dll
C:\ProgramData\*.exe
C:\ProgramData\*.hta
C:\ProgramData\*.jar
C:\ProgramData\*.js
C:\ProgramData\*.jse
C:\ProgramData\*.lnk
C:\ProgramData\*.pif
C:\ProgramData\*.ps1
C:\ProgramData\*.py
C:\ProgramData\*.pyc
C:\ProgramData\*.pyd
C:\ProgramData\*.scr
C:\ProgramData\*.tmp
C:\ProgramData\*.vbe
C:\ProgramData\*.vbs
C:\ProgramData\*.wsf
C:\ProgramData\*.wsh
C:\ProgramData\*.zip
C:\ProgramData\*.rar
C:\ProgramData\*.7z
C:\Users\*\AppData\Roaming\*.csproj
C:\Users\*\AppData\Roaming\*.au3
C:\Users\*\AppData\Roaming\*.bat
C:\Users\*\AppData\Roaming\*.cab
C:\Users\*\AppData\Roaming\*.cmd
C:\Users\*\AppData\Roaming\*.com
C:\Users\*\AppData\Roaming\*.dll
C:\Users\*\AppData\Roaming\*.exe
C:\Users\*\AppData\Roaming\*.hta
C:\Users\*\AppData\Roaming\*.jar
C:\Users\*\AppData\Roaming\*.js
C:\Users\*\AppData\Roaming\*.jse
C:\Users\*\AppData\Roaming\*.lnk
C:\Users\*\AppData\Roaming\*.pif
C:\Users\*\AppData\Roaming\*.ps1
C:\Users\*\AppData\Roaming\*.py
C:\Users\*\AppData\Roaming\*.pyc
C:\Users\*\AppData\Roaming\*.pyd
C:\Users\*\AppData\Roaming\*.scr
C:\Users\*\AppData\Roaming\*.tmp
C:\Users\*\AppData\Roaming\*.vbe
C:\Users\*\AppData\Roaming\*.vbs
C:\Users\*\AppData\Roaming\*.wsf
C:\Users\*\AppData\Roaming\*.wsh
C:\Users\*\AppData\Roaming\*.zip
C:\Users\*\AppData\Roaming\*.rar
C:\Users\*\AppData\Roaming\*.7z
C:\Users\CurrentUserName\AppData\Local\*.csproj
C:\Users\CurrentUserName\AppData\Local\*.a3x
C:\Users\CurrentUserName\AppData\Local\*.ahk
C:\Users\CurrentUserName\AppData\Local\*.au3
C:\Users\CurrentUserName\AppData\Local\*.bat
C:\Users\CurrentUserName\AppData\Local\*.cab
C:\Users\CurrentUserName\AppData\Local\*.cmd
C:\Users\CurrentUserName\AppData\Local\*.com
C:\Users\CurrentUserName\AppData\Local\*.dll
C:\Users\CurrentUserName\AppData\Local\*.exe
C:\Users\CurrentUserName\AppData\Local\*.hta
C:\Users\CurrentUserName\AppData\Local\*.jar
C:\Users\CurrentUserName\AppData\Local\*.js
C:\Users\CurrentUserName\AppData\Local\*.jse
C:\Users\CurrentUserName\AppData\Local\*.lnk
C:\Users\CurrentUserName\AppData\Local\*.pif
C:\Users\CurrentUserName\AppData\Local\*.ps1
C:\Users\CurrentUserName\AppData\Local\*.py
C:\Users\CurrentUserName\AppData\Local\*.pyc
C:\Users\CurrentUserName\AppData\Local\*.pyd
C:\Users\CurrentUserName\AppData\Local\*.scr
C:\Users\CurrentUserName\AppData\Local\*.tmp
C:\Users\CurrentUserName\AppData\Local\*.vbe
C:\Users\CurrentUserName\AppData\Local\*.vbs
C:\Users\CurrentUserName\AppData\Local\*.wsf
C:\Users\CurrentUserName\AppData\Local\*.wsh
C:\Users\CurrentUserName\AppData\Local\*.zip
C:\Users\CurrentUserName\AppData\Local\*.rar
C:\Users\CurrentUserName\AppData\Local\*.7z
C:\Users\CurrentUserName\AppData\Roaming\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\*.a3x
C:\Users\CurrentUserName\AppData\Roaming\*.ahk
C:\Users\CurrentUserName\AppData\Roaming\*.au3
C:\Users\CurrentUserName\AppData\Roaming\*.bat
C:\Users\CurrentUserName\AppData\Roaming\*.cab
C:\Users\CurrentUserName\AppData\Roaming\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\*.com
C:\Users\CurrentUserName\AppData\Roaming\*.dll
C:\Users\CurrentUserName\AppData\Roaming\*.exe
C:\Users\CurrentUserName\AppData\Roaming\*.hta
C:\Users\CurrentUserName\AppData\Roaming\*.jar
C:\Users\CurrentUserName\AppData\Roaming\*.js
C:\Users\CurrentUserName\AppData\Roaming\*.jse
C:\Users\CurrentUserName\AppData\Roaming\*.lnk
C:\Users\CurrentUserName\AppData\Roaming\*.pif
C:\Users\CurrentUserName\AppData\Roaming\*.ps1
C:\Users\CurrentUserName\AppData\Roaming\*.py
C:\Users\CurrentUserName\AppData\Roaming\*.pyc
C:\Users\CurrentUserName\AppData\Roaming\*.pyd
C:\Users\CurrentUserName\AppData\Roaming\*.scr
C:\Users\CurrentUserName\AppData\Roaming\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\*.vbe
C:\Users\CurrentUserName\AppData\Roaming\*.vbs
C:\Users\CurrentUserName\AppData\Roaming\*.wsf
C:\Users\CurrentUserName\AppData\Roaming\*.wsh
C:\Users\CurrentUserName\AppData\Roaming\*.zip
C:\Users\CurrentUserName\AppData\Roaming\*.rar
C:\Users\CurrentUserName\AppData\Roaming\*.7z
Comment: Remove browser cache
StartPowerShell:
$ProfilesDirectory = (Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList').ProfilesDirectory
$DisplayNames = @{
"chrome" = "Chrome"
"firefox" = "Firefox"
"opera" = "Opera"
"operagx" = "Opera GX"
"brave" = "Brave"
"msedge" = "Edge"
"vivaldi" = "Vivaldi"
"librewolf" = "LibreWolf"
"mullvad" = "Mullvad Browser"
"zen" = "Zen"
}
$ProcessNameMap = @{
"operagx" = "opera"
"mullvad" = "mullvadbrowser"
}
$trueCacheNames = @("Cache", "Code Cache", "DawnCache", "GPUCache", "GrShaderCache", "ShaderCache", "Shared Dictionary\cache")
function Get-CacheDirs {
param([string]$BrowserName, [string]$ProfilesDirectory)
switch ($BrowserName) {
"chrome" {
$dir = "$ProfilesDirectory\*\AppData\Local\Google\Chrome\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"firefox" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mozilla\Firefox\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"opera" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"operagx" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software\Opera GX Stable"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software\Opera GX Stable"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"brave" {
$dir = "$ProfilesDirectory\*\AppData\Local\BraveSoftware\Brave-Browser\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"msedge" {
$dir = "$ProfilesDirectory\*\AppData\Local\Microsoft\Edge\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"vivaldi" {
$dir = "$ProfilesDirectory\*\AppData\Local\Vivaldi\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"librewolf" {
$dir = "$ProfilesDirectory\*\AppData\Local\LibreWolf\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"mullvad" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mullvad\MullvadBrowser\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"zen" {
$dir = "$ProfilesDirectory\*\AppData\Local\zen\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
}
}
function Format-Size {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$BrowserKeys = @('chrome', 'firefox', 'opera', 'operagx', 'brave', 'msedge', 'vivaldi', 'librewolf', 'mullvad', 'zen')
foreach ($key in $BrowserKeys) {
$procName = if ($ProcessNameMap.ContainsKey($key)) { $ProcessNameMap[$key] } else { $key }
Get-Process -Name $procName -ErrorAction SilentlyContinue | Stop-Process -Force -ErrorAction SilentlyContinue
}
Start-Sleep -Seconds 5
$grandBytes = 0L
$grandFiles = 0
$anyFound = $false
foreach ($key in $BrowserKeys) {
$cacheDirs = Get-CacheDirs -BrowserName $key -ProfilesDirectory $ProfilesDirectory
if (-not $cacheDirs -or $cacheDirs.Count -eq 0) { continue }
$anyFound = $true
$displayName = $DisplayNames[$key]
$browserBytes = 0L
$browserFiles = 0
foreach ($cacheDir in $cacheDirs) {
if (-not (Test-Path $cacheDir)) { continue }
$items = Get-ChildItem -Path $cacheDir -Force -Recurse -ErrorAction SilentlyContinue
$files = $items | Where-Object { -not $_.PSIsContainer }
$bytes = ($files | Measure-Object -Property Length -Sum).Sum
if (-not $bytes) { $bytes = 0 }
$browserFiles += $files.Count
$browserBytes += $bytes
Get-ChildItem -Path "$cacheDir\*" -Force -ErrorAction SilentlyContinue | Remove-Item -Force -Recurse -ErrorAction SilentlyContinue
}
$grandBytes += $browserBytes
$grandFiles += $browserFiles
Write-Host ("{0,-16} freed {1,10} ({2} files)" -f $displayName, (Format-Size $browserBytes), $browserFiles)
}
if (-not $anyFound) {
Write-Host "No cache found for any installed browser."
}
Write-Host ""
Write-Host ("Total freed: {0} ({1} files)" -f (Format-Size $grandBytes), $grandFiles)
EndPowerShell:
Comment: Verify WMI repository, repair & verify again
CMD: winmgmt.exe /verifyrepository
CMD: winmgmt.exe /salvagerepository
CMD: winmgmt.exe /verifyrepository
Comment: To rebuild the performance counter library values
CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R"
CMD: "%WINDIR%\SysWOW64\lodctr.exe /R"
CMD: "C:\Windows\SYSTEM32\lodctr.exe /R"
CMD: "C:\Windows\SysWOW64\lodctr.exe /R"
Comment: Resync performance counter library values to WMI as well
CMD: winmgmt.exe /resyncperf
Comment: Force policy removal
C:\Windows\System32\GroupPolicyUsers
C:\Windows\System32\GroupPolicy
CMD: gpupdate.exe /force
Comment: Reset PowerShell execution policy
Powershell: Set-ExecutionPolicy Unrestricted -Scope CurrentUser -Force
Comment: BITS reset
Startbatch:
@echo off
net.exe stop BITS
ipconfig.exe /flushdns
ren "%programdata%\Microsoft\Network\Downloader\qmgr*.*" qmgr*.*.old
net.exe start BITS
Endbatch:
cmd: bitsadmin.exe /reset /allusers
Comment: Network reset commands
CMD: netsh.exe int ip reset
CMD: netsh.exe int ipv6 reset
CMD: ipconfig.exe /flushDNS
CMD: netsh.exe winsock reset catalog
Comment: Additional temp file removal
C:\Windows\System32\config\systemprofile\AppData\Local\*.tmp
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
C:\Users\CurrentUserName\AppData\Local\Temp\*
C:\Windows\Temp\*
C:\Windows\SystemTemp\*
C:\Windows\Prefetch\*
Comment: System repair commands
CMD: SFC.exe /scannow
CMD: DISM.exe /Online /Cleanup-image /Restorehealth
EmptyTemp:
End::
Warning
Executing a Fixlist on the wrong system may permanently damage it. Continue only if this link was meant for you.
To view the content, acknowledge this warning.