content copied
content
Start::
SystemRestore: On
CreateRestorePoint:
CloseProcesses:
File: C:\Windows\system32\Tasks\MSFTVpn_64
Folder: C:\Users\NL\AppData\Local\Intel
Folder: C:\Users\NL\AppData\Roaming\WPersistent
Folder: C:\Users\NL\AppData\Local\Nahimic
2026-09-04 01:40 - 2026-09-04 01:40 - 000000000 ____D C:\Users\NL\AppData\Roaming\WPersistent
2026-09-02 15:17 - 2026-09-02 15:17 - 000003092 _____ C:\Windows\system32\Tasks\MSFTVpn_64
2026-09-02 15:16 - 2026-09-02 15:16 - 000000000 ____D C:\Users\nikke\AppData\Local\VIA
C:\ProgramData\HubPrompt_v8_dev\
Task: {D9174720-EB40-4724-84E8-AAE53FCD8AD7} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\Users\nikke\Downloads\msert.exe [224655776 2026-09-02] (Microsoft Corporation -> Microsoft Corporation) -> C:\Users\nikke\Downloads\/EHB /HeartbeatFailure "SubmitHeartbeatReportData" /HeartbeatError "0x80072ee7"
HKU\S-1-5-21-1919299351-3891365052-503580553-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_5C997B8C0506F5E55843F617008879EB"
HKU\S-1-5-21-1919299351-3891365052-503580553-1001\...\Run: [MicrosoftEdgeAutoLaunch_5C997B8C0506F5E55843F617008879EB] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5365576 2026-09-04] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1919299351-3891365052-503580553-1002\...\Run: [MicrosoftEdgeAutoLaunch_255C7475D0650B8255FB85EC5B48518D] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5365576 2026-09-04] (Microsoft Corporation -> Microsoft Corporation)
AlternateDataStreams: C:\Users\nikke\Desktop\SecurityCheck.exe:MBAM.Zone.Identifier [164]
AlternateDataStreams: C:\Users\nikke\Downloads\EmsisoftAntiMalwareWebSetup_393032cb-62ac-4f2b-993b-ccca7f07fd7e.exe:MBAM.Zone.Identifier [346]
AlternateDataStreams: C:\Users\nikke\Downloads\esetonlinescanner.exe:MBAM.Zone.Identifier [356]
AlternateDataStreams: C:\Users\nikke\Downloads\FRST64.exe:MBAM.Zone.Identifier [450]
AlternateDataStreams: C:\Users\nikke\Downloads\KVRT.exe:MBAM.Zone.Identifier [378]
AlternateDataStreams: C:\Users\nikke\Downloads\mb-support-1.9.17.1158.exe:MBAM.Zone.Identifier [390]
AlternateDataStreams: C:\Users\nikke\Downloads\msert.exe:MBAM.Zone.Identifier [402]
HKU\S-1-5-21-1919299351-3891365052-503580553-1001\...\Run: [GalaxyClient] => [X]
HKU\S-1-5-21-1919299351-3891365052-503580553-1002\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\NL\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File) <==== ATTENTION
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {3409E69F-7EFF-4F5E-AC83-8B667A936116} - System32\Tasks\MSFTVpn_64 => C:\ProgramData\HubPrompt_v8_dev\Synch-Iron.exe (No File)
S2 Skyve.Service; "D:\Skyve CS-II\Skyve.Service.exe" (No File)
S3 HWiNFO_215; \??\C:\Users\nikke\AppData\Local\Temp\HWiNFO_x64_215.sys (No File) <==== ATTENTION
S3 PRI-Driver; \??\C:\Windows\System32\drivers\PRI-Driver.sys (No File)
2026-09-08 10:52 - 2026-09-08 11:33 - 000086125 _____ C:\Users\NL\AppData\LocalLow\f6c07a119bcc793ef10ecb8f2cc1624d6dd7ea2d05934c2d27b2ad9585db62e1
2026-09-08 10:52 - 2026-09-08 10:57 - 000000130 _____ C:\Users\NL\AppData\LocalLow\4c4dbb116a6549df53c630444745f2035f0b70432bc24de0f282fe5b9b32bd4b
2026-09-04 01:41 - 2026-09-04 01:41 - 000008133 _____ C:\Users\NL\AppData\LocalLow\cdabba53f33c66486adb735a326848f6cd7d5823deabb9741425e0a3f60f46eb
2026-09-04 01:41 - 2026-09-04 01:41 - 000005895 _____ C:\Users\NL\AppData\LocalLow\afe1d7afbacb9b5afdc2d0937fb9cb8b3b4479eeea0dc2cbb6b974f7916ddb10
2026-09-04 01:41 - 2026-09-04 01:41 - 000002264 _____ C:\Users\NL\AppData\LocalLow\f6eb7a6a1845f1d1440a994d4e34c1e11780045443c604c5be66c5d14c448383
2026-09-04 01:41 - 2026-09-04 01:41 - 000000026 _____ C:\Users\NL\AppData\LocalLow\eb4180b566259c4c4151d8ed10e3afc287d78be326e06067b72f2537b238d9e9
2026-09-04 01:41 - 2026-09-04 01:41 - 000000026 _____ C:\Users\NL\AppData\LocalLow\af73d6bec050e7258d4fd30d1ee1360a05d1901b1c12de40a72b0d1954fef96a
2026-09-04 01:40 - 2026-09-04 01:40 - 000005886 _____ C:\Users\NL\AppData\LocalLow\c1e9bce9022d87481c201dd464bd95c766ca980373625bc6377ec1f2492ec3dc
2026-09-04 01:40 - 2026-09-04 01:40 - 000005881 _____ C:\Users\NL\AppData\LocalLow\c4ee1094e5ef4f90f2f67d2afb3e8c2f6eff6b7380a00ad50355dbe9124d29cc
2026-09-04 01:40 - 2026-09-04 01:40 - 000002264 _____ C:\Users\NL\AppData\LocalLow\59958be863605b09433250d3a96eb521c732218c09e5c8a1f0ead189c2ebae94
2026-09-04 01:40 - 2026-09-04 01:40 - 000000026 _____ C:\Users\NL\AppData\LocalLow\f06f7457558ed8f9eeec1e72747147b4a67561eb44d609da6a043850a1e69539
2026-09-04 01:40 - 2026-09-04 01:40 - 000000026 _____ C:\Users\NL\AppData\LocalLow\e9943804e2f13bd11bbc9f09e9daa618bf6ba9e3f4a3b68b86d68ae8d1c209c4
2026-08-29 17:30 - 2026-08-29 17:30 - 000000026 _____ C:\Users\nikke\AppData\LocalLow\3aa6b955fe130aa71b2dabd2291c0e02325ae93b43764bcc2a7ad55ec2d322bc
2026-08-29 17:30 - 2026-08-29 17:30 - 000000026 _____ C:\Users\nikke\AppData\LocalLow\3113ef3a94ef983f0a0c88b3f235dbaf34ad673e20040ddd69c76390fbeaa8cc
2026-09-08 10:35 - 2025-10-04 18:36 - 000000130 _____ C:\Users\nikke\AppData\LocalLow\85672950867d48fbbc081773a7d2ed76a657e281393f4d3f49d484df517d5c5a
2026-09-08 10:02 - 2025-11-01 15:42 - 000082587 _____ C:\Users\nikke\AppData\LocalLow\f6c07a119bcc793ef10ecb8f2cc1624d6dd7ea2d05934c2d27b2ad9585db62e1
2026-09-08 10:02 - 2025-11-01 15:42 - 000000130 _____ C:\Users\nikke\AppData\LocalLow\4c4dbb116a6549df53c630444745f2035f0b70432bc24de0f282fe5b9b32bd4b
2026-09-08 09:54 - 2026-03-17 15:37 - 000000130 _____ C:\Users\nikke\AppData\LocalLow\9e4e0a44b8ef53860d8299bd9acb1798ae4462166f54dc25a92a4f1841ed1786
2026-09-08 09:53 - 2025-10-07 11:39 - 000014092 _____ C:\Users\nikke\AppData\LocalLow\084aefeb8f72bc76d594bd09006b1d71ec24fbbfa72b6c9a04ac6b5229de379d
2026-09-08 09:53 - 2025-10-07 11:39 - 000000130 _____ C:\Users\nikke\AppData\LocalLow\a4e7000bd843d33bfa61544e63ec6978d950e527e72b1d7a20a15c0f0e8ba4b2
2026-09-07 16:29 - 2025-10-04 22:22 - 000002264 _____ C:\Users\nikke\AppData\LocalLow\777d30791be2d3bc0e705ed97ff1a31a920027bc988bffb65c8b7b4e94f6de6f
2026-09-07 16:02 - 2026-01-12 16:30 - 000053000 _____ C:\Users\nikke\AppData\LocalLow\d8fe0ac5e3478ddfb44903d0fd978cda588bcc033e853fd7749958792f3521f1
2026-09-07 14:21 - 2025-10-04 16:52 - 000000130 _____ C:\Users\nikke\AppData\LocalLow\e9943804e2f13bd11bbc9f09e9daa618bf6ba9e3f4a3b68b86d68ae8d1c209c4
2026-09-07 14:21 - 2025-10-04 15:10 - 000000130 _____ C:\Users\nikke\AppData\LocalLow\eb4180b566259c4c4151d8ed10e3afc287d78be326e06067b72f2537b238d9e9
2026-09-06 21:07 - 2025-10-21 23:50 - 000000130 _____ C:\Users\nikke\AppData\LocalLow\30a085bcaa17b5e7d810964f3df7957c063e61b540b792207984ce4ef0dd6792
2026-09-06 12:58 - 2025-10-16 16:43 - 000002264 _____ C:\Users\nikke\AppData\LocalLow\f6eb7a6a1845f1d1440a994d4e34c1e11780045443c604c5be66c5d14c448383
2026-09-06 12:34 - 2025-10-07 12:27 - 000541703 _____ C:\Users\nikke\AppData\LocalLow\950fe9697c0179fa650b224e88d025b2da72b67bd25e6d238b3aa7c5239b7e5e
2026-09-06 12:32 - 2025-10-07 12:27 - 000000298 _____ C:\Users\nikke\AppData\LocalLow\4b6d3651ff7eee383e325aa2bca63560464e8b8b49f6a3eec23d512f868b8082
2026-09-06 11:05 - 2025-10-04 18:25 - 000005888 _____ C:\Users\nikke\AppData\LocalLow\52d2d409878d2bb09e94b8b1bf958dccb4fe9bdc9a59e5bcce42b1ea7ab5281e
2026-09-06 11:05 - 2025-10-04 18:25 - 000000026 _____ C:\Users\nikke\AppData\LocalLow\c3d0bc0bb138cca37dc90ef32a55c640dc5b59ce21088b7df9e60974c0b2800d
2026-09-04 23:43 - 2025-10-04 21:55 - 000000130 _____ C:\Users\nikke\AppData\LocalLow\73b744cda150126a967fb4386c87d2172628aa829d81a22b29a36c31ff42d8a4
2026-09-04 23:26 - 2025-10-04 21:55 - 000012896 _____ C:\Users\nikke\AppData\LocalLow\303fad4049058202f8a78193a3c39aa2befd7891a705eb736ca9fa233d43e18f
2026-09-04 10:21 - 2025-10-06 02:30 - 000002264 _____ C:\Users\nikke\AppData\LocalLow\59958be863605b09433250d3a96eb521c732218c09e5c8a1f0ead189c2ebae94
2026-09-04 01:57 - 2025-10-08 18:48 - 000002264 _____ C:\Users\nikke\AppData\LocalLow\cd407d31fa09227309ec297088632930c312aad144e1682ca717271d9754ebe4
2026-09-03 21:15 - 2026-03-17 15:37 - 000002985 _____ C:\Users\nikke\AppData\LocalLow\901a77d696ca9eb47a91e9709c36021c1ba6b2a2d5eede594776e7a653a3f105
2026-09-03 19:49 - 2026-03-17 15:39 - 000002264 _____ C:\Users\nikke\AppData\LocalLow\53c4ce8b3f235f0cc60f5763fc2af4a885de6fe1c1e6627d5544e62a3ec2d64a
2026-09-03 13:14 - 2025-10-04 18:38 - 000002264 _____ C:\Users\nikke\AppData\LocalLow\58fabf7a002278483a9ad7c65882c4d633a25029ef7872677a483a5e33e9804d
2026-09-03 13:13 - 2025-10-04 15:10 - 000008125 _____ C:\Users\nikke\AppData\LocalLow\cdabba53f33c66486adb735a326848f6cd7d5823deabb9741425e0a3f60f46eb
2026-09-03 13:13 - 2025-10-04 15:10 - 000000026 _____ C:\Users\nikke\AppData\LocalLow\af73d6bec050e7258d4fd30d1ee1360a05d1901b1c12de40a72b0d1954fef96a
2026-09-03 13:12 - 2025-10-21 23:50 - 000005874 _____ C:\Users\nikke\AppData\LocalLow\cd30d884c80c89ee937ebb8511b3b5caab3cf7b9a54e37c28fd27723c6769483
2026-09-03 13:12 - 2025-10-04 18:36 - 000000026 _____ C:\Users\nikke\AppData\LocalLow\1d9aabf8780473a6442b1b33b86d6c2ddcd9c9097ce03e4c60aa5185961359e0
2026-09-03 13:12 - 2025-10-04 15:10 - 000005887 _____ C:\Users\nikke\AppData\LocalLow\afe1d7afbacb9b5afdc2d0937fb9cb8b3b4479eeea0dc2cbb6b974f7916ddb10
2026-09-03 13:11 - 2026-02-21 14:44 - 000005888 _____ C:\Users\nikke\AppData\LocalLow\c1e9bce9022d87481c201dd464bd95c766ca980373625bc6377ec1f2492ec3dc
2026-09-03 13:11 - 2026-02-21 14:44 - 000000026 _____ C:\Users\nikke\AppData\LocalLow\f06f7457558ed8f9eeec1e72747147b4a67561eb44d609da6a043850a1e69539
2026-09-03 13:11 - 2025-10-04 16:52 - 000005898 _____ C:\Users\nikke\AppData\LocalLow\c4ee1094e5ef4f90f2f67d2afb3e8c2f6eff6b7380a00ad50355dbe9124d29cc
2026-08-29 17:56 - 2026-07-24 18:44 - 000000130 _____ C:\Users\nikke\AppData\LocalLow\9c5f9afd16d1a7a4a31cab9b4985da755e413d992a8b0f9f345b529021dc9496
2026-08-29 17:21 - 2025-10-04 18:26 - 000092154 _____ C:\Users\nikke\AppData\LocalLow\84bd48c35c5516820bd97b055f9f31a9d66a2c28d2eec9af51de86bf066ab8d9
2026-08-14 12:44 - 2025-11-22 19:19 - 000000298 _____ C:\Users\nikke\AppData\LocalLow\62f9009974d8fe5a2c5b3ce728226dd27fcd6fa32952edccddcead82abaa7fea
2026-08-14 12:41 - 2025-11-22 19:19 - 000127207 _____ C:\Users\nikke\AppData\LocalLow\5eea564bf089f170cba12b7b0944c4fc79cf3ea963d83591aa95ec8879d4b8de
PowerShell: (New-Object -ComObject WScript.Shell).CreateShortcut("C:\Users\NL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nahimic Companion.lnk") | Select-Object TargetPath, Arguments | Format-List
Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) }
StartPowerShell:
# Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console
# Does not clean preinstalled objects, only PUP/Adware
# If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument
# If you would like to only scan with it, change the argument from /clean to /scan
# NOTE: For the sake of users from Asia (primarily China), do not use the clean option. It will very likely remove a lot of their important software.
New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null
Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden
$logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile
Get-Content $logFile -Encoding Unicode
Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue
EndPowerShell:
StartPowershell:
$hmpExe = "$env:TEMP\HitmanPro_x64.exe"
$logFile = "$env:TEMP\HitmanPro_ScanLog.txt"
Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing
$proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru
if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 }
Get-Content $logFile -Encoding Unicode
EndPowershell:
Comment: RenPyLoader hollowed installed app generic removal
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.bat
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.props
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.targets
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.user
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cache
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.config
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.bat
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.props
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.targets
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.tmp
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.csproj
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cmd
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.user
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cache
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.config
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.bat
Comment: Remove unwanted files from common folders using native removal power of Farbar to include remove on reboot if needed. Please double check the user does not have any applications incorrectly installed in the directories listed below.ยจ
C:\ProgramData\*.csproj
C:\ProgramData\*.a3x
C:\ProgramData\*.ahk
C:\ProgramData\*.au3
C:\ProgramData\*.bat
C:\ProgramData\*.cab
C:\ProgramData\*.cmd
C:\ProgramData\*.com
C:\ProgramData\*.dll
C:\ProgramData\*.exe
C:\ProgramData\*.hta
C:\ProgramData\*.jar
C:\ProgramData\*.js
C:\ProgramData\*.jse
C:\ProgramData\*.lnk
C:\ProgramData\*.pif
C:\ProgramData\*.ps1
C:\ProgramData\*.py
C:\ProgramData\*.pyc
C:\ProgramData\*.pyd
C:\ProgramData\*.scr
C:\ProgramData\*.tmp
C:\ProgramData\*.vbe
C:\ProgramData\*.vbs
C:\ProgramData\*.wsf
C:\ProgramData\*.wsh
C:\ProgramData\*.zip
C:\ProgramData\*.rar
C:\ProgramData\*.7z
C:\Users\*\AppData\Roaming\*.csproj
C:\Users\*\AppData\Roaming\*.au3
C:\Users\*\AppData\Roaming\*.bat
C:\Users\*\AppData\Roaming\*.cab
C:\Users\*\AppData\Roaming\*.cmd
C:\Users\*\AppData\Roaming\*.com
C:\Users\*\AppData\Roaming\*.dll
C:\Users\*\AppData\Roaming\*.exe
C:\Users\*\AppData\Roaming\*.hta
C:\Users\*\AppData\Roaming\*.jar
C:\Users\*\AppData\Roaming\*.js
C:\Users\*\AppData\Roaming\*.jse
C:\Users\*\AppData\Roaming\*.lnk
C:\Users\*\AppData\Roaming\*.pif
C:\Users\*\AppData\Roaming\*.ps1
C:\Users\*\AppData\Roaming\*.py
C:\Users\*\AppData\Roaming\*.pyc
C:\Users\*\AppData\Roaming\*.pyd
C:\Users\*\AppData\Roaming\*.scr
C:\Users\*\AppData\Roaming\*.tmp
C:\Users\*\AppData\Roaming\*.vbe
C:\Users\*\AppData\Roaming\*.vbs
C:\Users\*\AppData\Roaming\*.wsf
C:\Users\*\AppData\Roaming\*.wsh
C:\Users\*\AppData\Roaming\*.zip
C:\Users\*\AppData\Roaming\*.rar
C:\Users\*\AppData\Roaming\*.7z
C:\Users\CurrentUserName\AppData\Local\*.csproj
C:\Users\CurrentUserName\AppData\Local\*.a3x
C:\Users\CurrentUserName\AppData\Local\*.ahk
C:\Users\CurrentUserName\AppData\Local\*.au3
C:\Users\CurrentUserName\AppData\Local\*.bat
C:\Users\CurrentUserName\AppData\Local\*.cab
C:\Users\CurrentUserName\AppData\Local\*.cmd
C:\Users\CurrentUserName\AppData\Local\*.com
C:\Users\CurrentUserName\AppData\Local\*.dll
C:\Users\CurrentUserName\AppData\Local\*.exe
C:\Users\CurrentUserName\AppData\Local\*.hta
C:\Users\CurrentUserName\AppData\Local\*.jar
C:\Users\CurrentUserName\AppData\Local\*.js
C:\Users\CurrentUserName\AppData\Local\*.jse
C:\Users\CurrentUserName\AppData\Local\*.lnk
C:\Users\CurrentUserName\AppData\Local\*.pif
C:\Users\CurrentUserName\AppData\Local\*.ps1
C:\Users\CurrentUserName\AppData\Local\*.py
C:\Users\CurrentUserName\AppData\Local\*.pyc
C:\Users\CurrentUserName\AppData\Local\*.pyd
C:\Users\CurrentUserName\AppData\Local\*.scr
C:\Users\CurrentUserName\AppData\Local\*.tmp
C:\Users\CurrentUserName\AppData\Local\*.vbe
C:\Users\CurrentUserName\AppData\Local\*.vbs
C:\Users\CurrentUserName\AppData\Local\*.wsf
C:\Users\CurrentUserName\AppData\Local\*.wsh
C:\Users\CurrentUserName\AppData\Local\*.zip
C:\Users\CurrentUserName\AppData\Local\*.rar
C:\Users\CurrentUserName\AppData\Local\*.7z
C:\Users\CurrentUserName\AppData\Roaming\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\*.a3x
C:\Users\CurrentUserName\AppData\Roaming\*.ahk
C:\Users\CurrentUserName\AppData\Roaming\*.au3
C:\Users\CurrentUserName\AppData\Roaming\*.bat
C:\Users\CurrentUserName\AppData\Roaming\*.cab
C:\Users\CurrentUserName\AppData\Roaming\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\*.com
C:\Users\CurrentUserName\AppData\Roaming\*.dll
C:\Users\CurrentUserName\AppData\Roaming\*.exe
C:\Users\CurrentUserName\AppData\Roaming\*.hta
C:\Users\CurrentUserName\AppData\Roaming\*.jar
C:\Users\CurrentUserName\AppData\Roaming\*.js
C:\Users\CurrentUserName\AppData\Roaming\*.jse
C:\Users\CurrentUserName\AppData\Roaming\*.lnk
C:\Users\CurrentUserName\AppData\Roaming\*.pif
C:\Users\CurrentUserName\AppData\Roaming\*.ps1
C:\Users\CurrentUserName\AppData\Roaming\*.py
C:\Users\CurrentUserName\AppData\Roaming\*.pyc
C:\Users\CurrentUserName\AppData\Roaming\*.pyd
C:\Users\CurrentUserName\AppData\Roaming\*.scr
C:\Users\CurrentUserName\AppData\Roaming\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\*.vbe
C:\Users\CurrentUserName\AppData\Roaming\*.vbs
C:\Users\CurrentUserName\AppData\Roaming\*.wsf
C:\Users\CurrentUserName\AppData\Roaming\*.wsh
C:\Users\CurrentUserName\AppData\Roaming\*.zip
C:\Users\CurrentUserName\AppData\Roaming\*.rar
C:\Users\CurrentUserName\AppData\Roaming\*.7z
C:\Users\CurrentUserName\AppData\Local\Temp\*
C:\Windows\Temp\*
C:\Windows\SystemTemp\*
CMD: cscript c:\windows\system32\slmgr.vbs /xpr & cscript c:\windows\system32\slmgr.vbs /dlv
CMD: netsh int ip reset
CMD: netsh int ipv6 reset
CMD: ipconfig /flushDNS
CMD: netsh winhttp reset proxy
CMD: netsh winsock reset catalog
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: bitsadmin /reset /allusers
CMD: Winmgmt /salvagerepository
CMD: winmgmt /resyncperf
CMD: DISM.exe /Online /Cleanup-image /Restorehealth
CMD: sfc /scannow
RemoveProxy:
EmptyTemp:
End::
Warning
Executing a Fixlist on the wrong system may permanently damage it. Continue only if this link was meant for you.
To view the content, acknowledge this warning.