content copied
content
Start::
SystemRestore: On
CreateRestorePoint:
CloseProcesses:
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_311\bin\ssv.dll [2021-10-23] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_311\bin\jp2ssv.dll [2021-10-23] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_441\bin\ssv.dll => No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_441\bin\jp2ssv.dll => No File
IE trusted site: HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\webcompanion.com -> hxxp://webcompanion.com
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\StartupApproved\Run: => "Web Companion"
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_C46CFC0629905CC775E70B50EA8A519C"
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\Run: [MicrosoftEdgeAutoLaunch_C46CFC0629905CC775E70B50EA8A519C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --win-session-start [5365576 2026-08-27] (Microsoft Corporation -> Microsoft Corporation)
Comment: Browser extension - Volume Booster
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejkiikneibegknkgimmihdpcbcedgmpo
Comment: Browser extension - Violentmonkey
C:\Users\User\Downloads\Violentmonkey-webext-v2.31.0
Comment: Browser extension - Volume Booster
C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ejkiikneibegknkgimmihdpcbcedgmpo
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
CHR HKLM-x32\...\Chrome\Extension: [mfhcmdonhekjhfbjmeacdjbhlfgpjabp]
Comment: Browser extension - Resource Override
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkoacgokdfckfpndoffpifphamojphii
Comment: Browser extension - Resource Override
C:\Users\User\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\pkoacgokdfckfpndoffpifphamojphii
Comment: Browser extension - Adblock for Youtube™
C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cmedhionkhpnakcndndgjdbohmhepckk
Comment: Browser extension - Adblock for Youtube™
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk
Comment: Browser extension - Torrent Scanner
C:\Users\User\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb
Comment: Browser extension - Stream Cleaner
C:\Users\User\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\lehcglgkjkamolcflammloedahjocbbg
Comment: Browser extension - Web Safety
C:\Users\User\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp
2026-08-31 02:28 - 2026-08-31 02:28 - 000000000 ____D C:\Users\User\AppData\Roaming\basebridge_win32
2026-08-31 02:28 - 2026-08-31 02:28 - 000000000 ____D C:\Users\User\AppData\Local\Yandex
2026-08-31 02:27 - 2026-09-02 04:29 - 000000000 ____D C:\ProgramData\InProcSvr32
2026-09-02 04:30 - 2021-07-06 23:55 - 000000000 ____D C:\Users\User\AppData\Roaming\Lavasoft
2026-09-02 04:30 - 2021-07-06 23:54 - 000000000 ____D C:\ProgramData\Lavasoft
C:\Flashpoint\Data\Games\2ecf56d6-c5e4-a801-bc7f-60374ba1a051-1703195084180.zip
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\StartupApproved\Run: => "BuilderBeta"
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{03B29243-35DA-4858-920E-B70A007DF5AA}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.217.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{0982FB18-B2DC-43DF-9DA3-A54C41F699EA}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.233.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{09F84D84-51E6-4978-8151-D4EC42C08A35}\localserver32 -> C:\Users\User\AppData\Local\DiscordCanary\app-1.0.1021\DiscordCanary.exe => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{1108FD1C-492F-4251-B9DB-77F0274267B2}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.187.37\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{1A6B3BB8-4423-46A3-8848-CA56F15EDB9C}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.255.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{1C67DF85-7959-43C0-92F8-2CAD0314C31C}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.201.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{22D49062-B8D3-4DD5-B9C2-A044EA04D5CD}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.223.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{2ABD6384-2E18-40E8-8439-F06D21E0B03D}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.43\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{2B49DB21-41C5-44C0-8358-CA4C76205AE1}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.209.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{2E1C6470-986B-46B5-B238-4B0AA6D46629}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.257.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{2EF7E390-2F7C-4F9A-9B7D-4A87B56B711D}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.173.51\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{2F2D16C4-81C2-4DF6-AD4E-E6FB18F48503}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.249.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{2FDB3305-19B8-4FE2-972B-ED5E97CBBD6E}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.39\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{38971E90-14FD-44F6-AA45-1447B653F873}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.173.45\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{41B09861-5409-4D44-8CA4-D49FBFAA2E6F}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.49\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{448DD314-7FBB-429C-9DAA-C05A00D235A8}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.215.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{4FFB4BD8-A109-4F25-A4DB-313678B19417}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.31\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{5247F326-2FF0-4920-998E-12AA35F0883C}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.213.7\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{5A96AC40-172E-45CB-823C-1BC933E771EC}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.251.23\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{5E9DEE2B-5F44-4C87-84B8-D2E7B11D7017}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.229.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{5FC44EBC-3A1F-4FBB-85E5-34405788C8D7}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.187.41\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{608D599A-DCA6-4A7C-BED7-AFCD8465345A}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.175.29\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{64C6EFB9-8F79-4106-B975-067448DC768F}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.177.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{674CB023-C9D4-4286-B1FF-A1FF76AD4B27}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.227.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{682D84E1-25A0-4741-9EA9-E57BA894B8C3}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.251.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{6A012BDE-3690-4747-9C3E-5E4FC354304A}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.241.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{6A49690B-7DB6-424B-81CE-F51078F2A58D}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.203.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{6DD6748E-7DAE-47EF-B4D5-03AA1B06D697}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.187.39\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{72726D01-426C-4B35-8266-B4496CAA889E}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.183.29\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{78C1ADF4-6DAE-4164-AEFA-4E3EAD9E750A}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.19\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{79F05C14-E714-4C12-9924-93C812894CB0}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.57\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{7C9A348D-C321-47AC-904F-150312A5430F}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.175.27\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{7EE9863F-34ED-427C-B03E-3853C66D5CBE}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.259.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{7EFB4924-4B93-4C43-9832-9C3D05E85214}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.59\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{83F21C4B-8643-4A08-A29A-822AFD835037}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.193.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{8DC94452-5748-435A-B24F-B0F57718821E}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.225.7\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{9C391760-8CB8-4F1E-AB7D-0C9915EFB004}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.211.7\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{A087E49F-1F8E-4603-A200-55537B737421}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.25\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{A78355B5-2A4D-486B-B97A-43448FC8C34D}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.207.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{ABF66F82-B04C-4FE4-8272-661539463FE1}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.171.37\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{AE1542A7-3989-481B-93A9-1500C5F56B14}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.185.27\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{B12A60CF-E572-4314-8F54-4E96C6660780}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.237.7\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{B258532D-3529-4BEB-BF38-F08F98B3968C}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{B29F5F83-90DF-479A-BDE7-8A9F4412E394}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.171.39\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{B314A279-F12F-4B54-A0AC-148FA68207CF}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.241.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{BB04C6F8-598E-4733-ABB4-07489C863436}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.205.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{BC4C72EF-3055-4A6D-86E1-AE4D24DB63CA}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.35\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{BCF99248-58CE-4562-B227-14D1E171B49D}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.221.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{c0f42af5-855f-f8f2-3cc9-c23f54cf00ec}\localserver32 -> "C:\Program Files\Nefarius Software Solutions\Nefarius VirtualPad Driver Runtime\NefariusVirtualPadDriverNotifications.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{C88B3957-621C-415B-8EE5-B688FC7EF924}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.61\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{CAE1760A-CB07-481B-8F9A-BC65510AF5D5}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.185.21\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> "C:\Users\User\AppData\Local\Microsoft\Teams\current\Teams.exe" --toast => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{D2188EEC-2B0F-488C-8ECA-5285E8ECD87D}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.69\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{D610770A-6AE5-45D7-8ECD-4D130A66EF51}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.251.21\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{D6EDECA7-CB7A-485F-A3FF-FCA4DFEC563C}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.263.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{D8599F80-3D26-46D2-8CF1-0AD21B0ECF31}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.65\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{DAA7499A-B3AC-4419-A89B-124318504051}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.185.29\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{E3D57E77-FE71-4D06-BD34-D48820074909}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.181.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{E76F97B1-1AE9-497C-9FA4-F57BBABAD54A}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.185.17\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{E8791438-3525-48BF-A600-C577AD1674C2}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.173.49\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{ECCE2756-C45D-4E13-BC2D-EC9F138997E6}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.199.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{F1658933-2997-4DDB-869C-061D53A9718E}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.21\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{F1CBF5EB-347F-4E4C-90AC-E43339FC34EC}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.173.55\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{F46A78BD-06FC-442C-88DF-0500F08F2379}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183178878-1416291722-3982040413-1001_Classes\CLSID\{F583F9E9-8B95-4D88-BC72-AE190E9B71F9}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\EdgeUpdate\1.3.239.19\psuser_64.dll => No File
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [10284]
AlternateDataStreams: C:\Users\User\Application Data:.grab_device_id [32]
AlternateDataStreams: C:\Users\User\Downloads\FRST64.exe:MBAM.Zone.Identifier [225]
AlternateDataStreams: C:\Users\User\Downloads\kaspersky4win202121.26.4.406ru_47020.exe:MBAM.Zone.Identifier [232]
AlternateDataStreams: C:\Users\User\AppData\Roaming:.grab_device_id [32]
AlternateDataStreams: C:\Users\User\AppData\Local\Microsoft:ISBD [32]
HKLM\...\Run: [] => [X]
HKLM\...\Run: [RZSurroundHelper] => C:\Windows\system32\RZSurroundHelper.exe (No File)
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\Run: [GalaxyClient] => [X]
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\Run: [WindowsBootManager] => C:\Users\User\AppData\Local\Microsoft\Windows\0\WindowsBootManager.exe (No File)
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\Run: [KeePassXC] => "C:\Program Files\KeePassXC\KeePassXC.exe" (No File)
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\Run: [LGHUB] => "C:\Program Files\LGHUB\system_tray\lghub_system_tray.exe" --minimized (No File)
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\Run: [com.todesktop.25020447d4kq915] => C:\Users\User\AppData\Local\Programs\Perplexity\Perplexity.exe (No File)
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\Run: [DiscordCanary] => "C:\Users\User\AppData\Local\DiscordCanary\Update.exe" --processStart DiscordCanary.exe (No File)
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\Run: [BuilderBeta] => C:\ProgramData\InProcSvr32\BuilderBeta.exe (No File) <==== ATTENTION
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\MountPoints2: {7fce3ca3-2a44-11eb-ba72-dc1ba1a08665} - "D:\DVDSetup.exe"
HKU\S-1-5-21-183178878-1416291722-3982040413-1001\...\MountPoints2: {ea5557c6-ea39-11ee-bb0e-dc1ba1a08669} - "E:\LaunchU3.exe"
HKU\S-1-5-18\...\Run: [Bomgar_Cleanup_ZD17188122744] => cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-0x6208739b" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD17188122744 /f (No File) <==== ATTENTION
Task: {8C9D294A-AF66-4F54-924D-57655B3518F3} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-183178878-1416291722-3982040413-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File)
FF Plugin-x32: @java.com/DTPlugin,version=11.441.2 -> C:\Program Files (x86)\Java\jre1.8.0_441\bin\dtplugin\npDeployJava1.dll [No File]
FF Plugin-x32: @java.com/JavaPlugin,version=11.441.2 -> C:\Program Files (x86)\Java\jre1.8.0_441\bin\plugin2\npjp2.dll [No File]
S3 klvssbridge64_21.26; "C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.26\x64\vssbridge64.exe" (No File)
S3 EAAntiCheat; system32\drivers\eaanticheat.sys (No File)
R4 klbackupdisk.K4W-21-26; \SystemRoot\system32\DRIVERS\K4W-21-26\klbackupdisk.sys (No File)
R4 klbackupflt.K4W-21-26; system32\DRIVERS\K4W-21-26\klbackupflt.sys (No File)
R4 klflt.K4W-21-26; \SystemRoot\system32\DRIVERS\K4W-21-26\klflt.sys (No File)
R4 KLIF.K4W-21-26; system32\DRIVERS\K4W-21-26\klif.sys (No File)
R4 klmouflt.K4W-21-26; \SystemRoot\system32\DRIVERS\K4W-21-26\klmouflt.sys (No File)
S3 ThrottleStop; \??\C:\Users\User\AppData\Local\Temp\ThrottleStop.sys (No File) <==== ATTENTION
PowerShell: (New-Object -ComObject WScript.Shell).CreateShortcut("C:\Users\User\Desktop\Microsoft Edge.lnk") | Select-Object TargetPath, Arguments | Format-List
File: C:\Users\User\zandronum.exe
Comment: === rifteyy's default non-intrusive fixlist template ===
Comment: The following are done automatically with this fixlist:
Comment: Hardens Windows Defender (for maximum efficiency DISABLE TAMPER PROTECTION)
Comment: Checks and corrects the default Windows PATH environmental variable
Comment: Checks for internet connection, valid DNS
Comment: Checks for Windows RE status
Comment: Checks and repairs WMI repository
Comment: Checks Windows activation status
Comment: Checks if TPM, Secure Boot are available and their status
Comment: Restores original Windows services configuration
Comment: Restores PowerShell execution policy
Comment: Rebuilds performance counter library values
Comment: Resynchronizes performance counter library values to WMI
Comment: Enables file extensions
Comment: Enables recovery environment
Comment: Scans with HitmanPro from Sophos
Comment: Scans and cleans with AdwCleaner from Malwarebytes
Comment: Lists Windows Defender properties, settings
Comment: Lists drive info, identify possible damaged drives from Event Logs
Comment: Lists Discord's "index.js" files that are often targeted by malware (to store and execute malicious code)
Comment: Lists recent BSOD's
Comment: Lists all installed applications, folder contents along with SHA256 for purposes of identifying installed app malware
Comment: Lists 30 recent scheduled tasks
Comment: Lists recent Run (Windows + R) executed commands, can identify ClickFix attacks
Comment: Removes unwanted files (e.g. .exe, .com, .dll) from common folders (e.g. C:\ProgramData, AppData\Roaming) - these are not supposed to store any executable file types
Comment: Removes generic filetypes associated with RenPyLoader from common folders
Comment: Removes cache from Chrome, Firefox, Opera, Opera GX, Brave, Vivaldi, LibreWolf, Mullvad Browser, Zen and from Roblox, Fortnite, Discord, OBS Studio
Comment: Removes policies
Comment: Removes active BITS tasks
Comment: Resets network
Comment: Removes proxy servers
Comment: Removes temporary files
Comment: Repairs system files
StartPowerShell:
# Checks default Windows PATH entries and repairs missing ones.
$ErrorActionPreference = 'Continue'
function Expand-PlainPath {
param([string]$Entry)
return [Environment]::ExpandEnvironmentVariables($Entry).TrimEnd('\')
}
# Templates expanded once to plain paths (C:\Windows\..., C:\Users\...)
$systemDefaults = @(
(Expand-PlainPath '%SystemRoot%\system32')
(Expand-PlainPath '%SystemRoot%')
(Expand-PlainPath '%SystemRoot%\System32\Wbem')
(Expand-PlainPath '%SystemRoot%\System32\WindowsPowerShell\v1.0')
(Expand-PlainPath '%SystemRoot%\System32\OpenSSH')
)
$userDefaults = @(
(Expand-PlainPath '%USERPROFILE%\AppData\Local\Microsoft\WindowsApps')
)
function Get-NormalizedPathEntries {
param([string]$Raw)
if ([string]::IsNullOrWhiteSpace($Raw)) { return @() }
return @(
$Raw -split ';' |
Where-Object { -not [string]::IsNullOrWhiteSpace($_) } |
ForEach-Object {
[Environment]::ExpandEnvironmentVariables($_.Trim().TrimEnd('\')).ToLowerInvariant()
}
)
}
function Get-CombinedPathEntries {
$machineRaw = [Environment]::GetEnvironmentVariable('Path', 'Machine')
$userRaw = [Environment]::GetEnvironmentVariable('Path', 'User')
return Get-NormalizedPathEntries -Raw ($machineRaw + ';' + $userRaw)
}
function Test-InPath {
param(
[string]$PlainPath,
[string[]]$NormalizedEntries
)
$key = $PlainPath.TrimEnd('\').ToLowerInvariant()
return $NormalizedEntries -contains $key
}
function Add-ToPath {
param(
[string]$PlainPath,
[ValidateSet('Machine', 'User')]
[string]$Scope
)
# always store plain path, never %VAR% form
$toAdd = $PlainPath.TrimEnd('\')
$current = [Environment]::GetEnvironmentVariable('Path', $Scope)
if ([string]::IsNullOrWhiteSpace($current)) {
[Environment]::SetEnvironmentVariable('Path', $toAdd, $Scope)
return
}
$normalized = Get-NormalizedPathEntries -Raw $current
$key = $toAdd.ToLowerInvariant()
if ($normalized -contains $key) { return }
$newPath = $current.TrimEnd(';') + ';' + $toAdd
[Environment]::SetEnvironmentVariable('Path', $newPath, $Scope)
}
function Write-Result {
param(
[string]$Entry,
[string]$Status
)
$label = $Entry.PadRight(58)
Write-Output ("{0} {1}" -f $label, $Status)
}
function Repair-AndVerify {
param(
[string]$PlainPath,
[ValidateSet('Machine', 'User')]
[string]$Scope
)
if (-not (Test-Path -LiteralPath $PlainPath)) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (no folder, cannot repair)'
return 'failed'
}
if ($Scope -eq 'Machine') {
$isAdmin = ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).
IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)
if (-not $isAdmin) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (need Admin to repair)'
return 'failed'
}
}
try {
Add-ToPath -PlainPath $PlainPath -Scope $Scope
}
catch {
Write-Result -Entry $PlainPath -Status "ATTENTION !!! MISSING (repair failed: $_)"
return 'failed'
}
# re-query PATH from registry and verify plain path is present
$after = Get-CombinedPathEntries
if (Test-InPath -PlainPath $PlainPath -NormalizedEntries $after) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING -> repaired (verified)'
return 'repaired'
}
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (repair ran, still missing after re-check)'
return 'failed'
}
$combined = Get-CombinedPathEntries
$hadMissing = $false
$repairFailed = $false
$repairedList = [System.Collections.Generic.List[string]]::new()
Write-Output 'PATH CHECK'
Write-Output ('-' * 72)
foreach ($entry in $systemDefaults) {
if (Test-InPath -PlainPath $entry -NormalizedEntries $combined) {
Write-Result -Entry $entry -Status 'OK'
continue
}
$hadMissing = $true
$result = Repair-AndVerify -PlainPath $entry -Scope Machine
if ($result -eq 'repaired') {
[void]$repairedList.Add($entry)
$combined = Get-CombinedPathEntries
}
else {
$repairFailed = $true
}
}
foreach ($entry in $userDefaults) {
if (Test-InPath -PlainPath $entry -NormalizedEntries $combined) {
Write-Result -Entry $entry -Status 'OK'
continue
}
$hadMissing = $true
$result = Repair-AndVerify -PlainPath $entry -Scope User
if ($result -eq 'repaired') {
[void]$repairedList.Add($entry)
$combined = Get-CombinedPathEntries
}
else {
$repairFailed = $true
}
}
Write-Output ('-' * 72)
if (-not $hadMissing) {
Write-Output 'RESULT: all default PATH entries present'
}
elseif ($repairedList.Count -gt 0 -and -not $repairFailed) {
Write-Output "RESULT: $($repairedList.Count) missing entry/entries repaired and verified - open a new terminal"
}
elseif ($repairedList.Count -gt 0 -and $repairFailed) {
Write-Output "RESULT: $($repairedList.Count) verified, some still missing - open a new terminal / run as Admin"
}
else {
Write-Output 'RESULT: missing entries not repaired (run as Admin for System PATH)'
}
if ($repairedList.Count -gt 0) {
Write-Output ''
Write-Output 'REPAIRED:'
foreach ($item in $repairedList) {
Write-Output " $item"
}
}
if ($hadMissing -or $repairFailed) {
exit 1
}
exit 0
EndPowerShell:
Comment: Verify Windows activation
CMD: cscript c:\windows\system32\slmgr.vbs /xpr & cscript c:\windows\system32\slmgr.vbs /dlv
Comment: Check TPM and Secure Boot status
StartPowershell:
[PSCustomObject]@{ "TPM Detected" = (Get-Tpm).TpmPresent; "TPM Enabled" = (Get-Tpm).TpmEnabled; "Secure Boot On" = (Confirm-SecureBootUEFI) }
EndPowershell:
StartPowerShell:
# Check for internet connection
$ErrorActionPreference = 'Continue'
$dnsServers = @(
'1.1.1.1'
'8.8.8.8'
)
$hosts = @(
'google.com'
'cloudflare.com'
'malwarebytes.com'
)
function Write-Result {
param(
[string]$Label,
[string]$Status
)
Write-Output ("{0} {1}" -f $Label.PadRight(42), $Status)
}
function Test-DnsServer {
param([string]$Server)
$pingOk = $false
try {
$pingOk = Test-Connection -ComputerName $Server -Count 1 -Quiet -ErrorAction SilentlyContinue
}
catch { }
$resolveOk = $false
try {
$result = Resolve-DnsName -Name 'google.com' -Server $Server -Type A -DnsOnly -ErrorAction Stop
$ip = ($result | Where-Object { $_.IPAddress } | Select-Object -First 1).IPAddress
if ($ip) { $resolveOk = $true }
}
catch { }
# resolve is what matters; ping may be blocked
if ($resolveOk) { return 'OK' }
if ($pingOk) { return 'FAIL' }
return 'FAIL'
}
function Test-HostReachable {
param([string]$HostName)
try {
$dns = Resolve-DnsName -Name $HostName -Type A -ErrorAction Stop
$resolvedIp = ($dns | Where-Object { $_.IPAddress } | Select-Object -First 1).IPAddress
if (-not $resolvedIp) { return 'FAIL' }
}
catch {
return 'FAIL'
}
try {
$null = Invoke-WebRequest -Uri "https://$HostName" -UseBasicParsing -TimeoutSec 10 -MaximumRedirection 5 -ErrorAction Stop
return 'OK'
}
catch {
if ($_.Exception.Response) { return 'OK' }
return 'FAIL'
}
}
$failed = 0
Write-Output 'INTERNET CHECK'
Write-Output ('-' * 72)
Write-Output 'DNS SERVERS'
foreach ($server in $dnsServers) {
$status = Test-DnsServer -Server $server
Write-Result -Label $server -Status $status
if ($status -eq 'FAIL') { $failed++ }
}
Write-Output ''
Write-Output 'HOSTS'
foreach ($h in $hosts) {
$status = Test-HostReachable -HostName $h
Write-Result -Label $h -Status $status
if ($status -eq 'FAIL') { $failed++ }
}
Write-Output ('-' * 72)
if ($failed -eq 0) {
Write-Output 'RESULT: all checks passed'
exit 0
}
Write-Output "RESULT: $failed check(s) failed"
exit 1
EndPowerShell:
StartPowershell:
# Replace /scanonly with /clean if you also want to delete items -- however, this will activate a trial license on the system, I do not recommend it
$hmpExe = "$env:TEMP\HitmanPro_x64.exe"
$logFile = "$env:TEMP\HitmanPro_ScanLog.txt"
Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing
$proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru
if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 }
Get-Content $logFile -Encoding Unicode
EndPowershell:
StartPowerShell:
# Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console
# Does not clean preinstalled objects, only PUP/Adware
# If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument
# If you would like to only scan with it, change the argument from /clean to /scan
# NOTE: For the sake of users from Asia (primarily China), do not use the clean option. It will very likely remove a lot of their important software.
New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null
Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden
$logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile
Get-Content $logFile -Encoding Unicode
Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue
EndPowerShell:
Comment: List drive info, identify possible damaged drives (thanks to AdvancedSetup from Malwarebytes for parts of these)
StartPowerShell:
param(
[int]$MaxEvents = 5000
)
$GPTTypeMap = @{
'EBD0A0A2-B9E5-4433-87C0-68B6B72699C7' = 'Microsoft Basic Data'
'E3C9E316-0B5C-4DB8-817D-F92DF00215AE' = 'Microsoft Reserved (MSR)'
'DE94BBA4-06D1-4D40-A16A-BFD50179D6AC' = 'Windows Recovery Environment (WinRE)'
'C12A7328-F81F-11D2-BA4B-00A0C93EC93B' = 'EFI System Partition'
'21686148-6449-6E6F-744E-656564454649' = 'BIOS Boot Partition'
'A19D880F-05FC-4D3B-A006-743F0F84911E' = 'OEM Partition'
'5808C8AA-7E8F-42E0-85D2-E1E90434CFB3' = 'Cluster Metadata Partition'
'48465300-0000-11AA-AA11-00306543ECAC' = 'Apple HFS/HFS+'
'7C3457EF-0000-11AA-AA11-00306543ECAC' = 'Apple APFS'
'0FC63DAF-8483-4772-8E79-3D69D8477DE4' = 'Linux Filesystem'
'0657FD6D-A4AB-43C4-84E5-0933C84B4F4F' = 'Linux Swap'
'E6D6D379-F507-44C2-A23C-238F2A3DF928' = 'Linux LVM'
}
$MBRTypeMap = @{
'01'='FAT12';'04'='FAT16 <32M';'05'='Extended';'06'='FAT16';'07'='IFS/NTFS/exFAT/HPFS';'0B'='FAT32 CHS';'0C'='FAT32 LBA';'0E'='FAT16 LBA'
'0F'='Extended LBA';'82'='Linux Swap';'83'='Linux Native';'8E'='Linux LVM';'A5'='FreeBSD';'A6'='OpenBSD';'A8'='Mac OS X';'AB'='Mac OS X Boot'
'AF'='Mac OS X HFS';'EE'='EFI GPT Protective';'EF'='EFI System Partition'
}
function Get-PartitionTypeInfo {
param($Partition)
$guid = $null
if ($Partition.GptType) {
$guid = ($Partition.GptType -replace '[{}]', '').ToUpper()
}
if ([string]::IsNullOrWhiteSpace($guid) -or $guid -eq '00000000-0000-0000-0000-000000000000') {
$guid = switch ($Partition.Type) {
"System" { "C12A7328-F81F-11D2-BA4B-00A0C93EC93B" }
"Reserved" { "E3C9E316-0B5C-4DB8-817D-F92DF00215AE" }
"Basic" { "EBD0A0A2-B9E5-4433-87C0-68B6B72699C7" }
"Recovery" { "DE94BBA4-06D1-4D40-A16A-BFD50179D6AC" }
default { $null }
}
}
if ($guid) {
$name = $GPTTypeMap[$guid]
if ($name) { return "$name (GPT GUID: $($guid.ToLower()))" }
else { return "Unknown/Custom (GPT GUID: $($guid.ToLower()))" }
}
if ($Partition.MbrType) {
$code = ($Partition.MbrType.ToString() -replace '^0x', '').PadLeft(2, '0').ToUpper()
$name = $MBRTypeMap[$code]
if ($name) { return "$name (MBR code: 0x$code)" }
else { return "Unknown/Custom (MBR code: $($Partition.MbrType))" }
}
return $Partition.Type
}
function Get-DrMapping {
param([int]$MaxEvents)
$map = @{}
try {
$events = Get-WinEvent -FilterHashtable @{ LogName = 'System'; ProviderName = 'disk' } -MaxEvents $MaxEvents -ErrorAction Stop
} catch {
return $map
}
foreach ($e in $events) {
if ($e.Message -match 'Harddisk(\d+)\\DR(\d+)') {
$n = [int]$Matches[1]
$dr = [int]$Matches[2]
if (-not $map.ContainsKey($n)) { $map[$n] = $dr }
}
}
return $map
}
$drMap = Get-DrMapping -MaxEvents $MaxEvents
$physicalDisks = Get-PhysicalDisk | Select-Object DeviceId, FriendlyName, SerialNumber, MediaType, @{N='SizeGB';E={[math]::Round($_.Size / 1GB,2)}}
foreach ($pd in $physicalDisks) {
$devId = [int]$pd.DeviceId
$drSuffix = if ($drMap.ContainsKey($devId)) { "\DR$($drMap[$devId])" } else { '\DR? (no event seen yet)' }
Write-Host ""
Write-Host "<=== \Device\Harddisk$devId$drSuffix ($($pd.FriendlyName)) ===>"
Write-Host " DeviceId: $devId | Serial: $($pd.SerialNumber) | Media: $($pd.MediaType) | Size: $($pd.SizeGB) GB"
try {
$partitions = Get-Partition -DiskNumber $devId -ErrorAction Stop
if (-not $partitions) {
Write-Host " (no partitions found)"
continue
}
foreach ($part in $partitions) {
$driveLetter = if ($part.DriveLetter) { "$($part.DriveLetter):" } else { 'no letter' }
$sizeGB = [math]::Round($part.Size / 1GB, 2)
$typeInfo = Get-PartitionTypeInfo -Partition $part
Write-Host " [PARTITION $($part.PartitionNumber)] Drive: $driveLetter - $sizeGB GB - $typeInfo"
}
} catch {
Write-Host " [ERROR] cannot read partitions for disk $devId"
}
}
if ($drMap.Count -eq 0) {
Write-Host ""
Write-Host "Note: no \Device\HarddiskN\DRx entries found in the last $MaxEvents System log events. Increase -MaxEvents, or the DR number will only appear once Windows actually logs a disk event for that drive (e.g. a bad block warning)."
}
EndPowerShell:
Comment: Verify that Discord does not have any injected code to intercept personal data. If anything is prompted here, it needs to be checked that it isn't malicious code.
Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) }
StartPowerShell:
# Basic BSOD listings
$ccKey = "HKLM:\SYSTEM\CurrentControlSet\Control\CrashControl"
$cfg = Get-ItemProperty $ccKey -ErrorAction SilentlyContinue
$dumpTypeMap = @{0='None';1='Complete';2='Kernel';3='Minidump';7='Automatic'}
Write-Output "--- Configuration ---"
Write-Output ("Dump Type: {0} ({1})" -f $cfg.CrashDumpEnabled, $dumpTypeMap[$cfg.CrashDumpEnabled])
Write-Output ("Full Dump Path: {0}" -f $(if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}))
Write-Output ("Minidump Folder: {0}" -f $(if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}))
Write-Output ("Auto Reboot: {0}" -f $(if($cfg.AutoReboot -eq 0){'Disabled'}else{'Enabled'}))
Write-Output "--- Found Dump Files ---"
$full = if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}
if (Test-Path $full) { Get-Item $full | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
$mini = if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}
if (Test-Path $mini) { Get-ChildItem $mini -Filter *.dmp | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
Write-Output "--- BugCheck Reasoning (recent events) ---"
$map = @{
'0x0000000A'='IRQL_NOT_LESS_OR_EQUAL - faulty/outdated driver accessed memory at high IRQL'
'0x0000001E'='KMODE_EXCEPTION_NOT_HANDLED - unhandled kernel exception, often driver/hardware'
'0x0000002E'='DATA_BUS_ERROR - typically bad RAM or hardware fault'
'0x0000003B'='SYSTEM_SERVICE_EXCEPTION - exception in a system service, often driver-related'
'0x00000050'='PAGE_FAULT_IN_NONPAGED_AREA - bad RAM or faulty driver/antivirus'
'0x0000007A'='KERNEL_DATA_INPAGE_ERROR - disk-related problem'
'0x0000007B'='INACCESSIBLE_BOOT_DEVICE - system could not find/access the boot device'
'0x0000007E'='SYSTEM_THREAD_EXCEPTION_NOT_HANDLED - almost always a faulty driver'
'0x0000007F'='UNEXPECTED_KERNEL_MODE_TRAP - hardware issue (CPU/RAM/overclocking)'
'0x0000009F'='DRIVER_POWER_STATE_FAILURE - driver failed to respond to a power state change'
'0x000000C2'='BAD_POOL_CALLER - driver mishandling memory (pool corruption)'
'0x000000D1'='DRIVER_IRQL_NOT_LESS_OR_EQUAL - typically a network or GPU driver'
'0x000000EF'='CRITICAL_PROCESS_DIED - a critical system process died, often malware/system corruption'
'0x00000116'='VIDEO_TDR_FAILURE - GPU driver failed to respond in time (timeout)'
'0x00000124'='WHEA_UNCORRECTABLE_ERROR - hardware fault (CPU/RAM/PSU/overclocking)'
'0x00000133'='DPC_WATCHDOG_VIOLATION - faulty driver or storage subsystem issue'
'0x00000139'='KERNEL_SECURITY_CHECK_FAILURE - corrupted kernel structure, possibly malware'
}
$events = Get-WinEvent -FilterHashtable @{LogName='System';Id=1001} -MaxEvents 100 -ErrorAction SilentlyContinue |
Where-Object { $_.ProviderName -match 'WER-SystemErrorReporting' } | Select-Object -First 5
if (-not $events) { Write-Output "No BugCheck events found in the log." }
foreach ($ev in $events) {
$code = if ($ev.Message -match 'bugcheck was:\s*(0x[0-9A-Fa-f]+)') { $matches[1] } else { $null }
Write-Output ("Time: {0}" -f $ev.TimeCreated)
Write-Output ("Code: {0}" -f $(if($code){$code}else{'not recognized'}))
if ($code -and $map.ContainsKey($code.ToUpper())) {
Write-Output ("Meaning: {0}" -f $map[$code.ToUpper()])
} elseif ($code) {
Write-Output "Meaning: unknown code, look up at learn.microsoft.com/windows-hardware/drivers/debugger/bug-check-code-reference2"
}
Write-Output ""
}
EndPowerShell:
StartPowerShell:
# This snippet lists all installed apps and their folder contents along with SHA256 hashes. Useful for troubleshooting malware abusing installed app entry.
param(
[switch]$Recurse,
[int]$MaxFilesPerApp = [int]::MaxValue
)
$uninstallPaths = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
$script:msiInstaller = $null
function Get-MsiInstallLocation {
param([string]$ProductCode)
if (-not $script:msiInstaller) {
try { $script:msiInstaller = New-Object -ComObject WindowsInstaller.Installer } catch { return $null }
}
try {
$loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallLocation')
if ([string]::IsNullOrWhiteSpace($loc)) { $loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallSource') }
if ([string]::IsNullOrWhiteSpace($loc)) { return $null }
return $loc
} catch { return $null }
}
function Get-CleanPath {
param([string]$RawValue)
if ([string]::IsNullOrWhiteSpace($RawValue)) { return $null }
$s = $RawValue.Trim()
if ($s.StartsWith('"')) {
$endQuote = $s.IndexOf('"', 1)
if ($endQuote -gt 0) { return $s.Substring(1, $endQuote - 1) }
}
if ($s -match '^(.*?\.exe)\b') { return $Matches[1] }
return $s
}
function Format-FileSize {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$script:PeExtensions = @('.exe', '.dll', '.sys', '.ocx', '.cpl', '.scr', '.drv', '.efi', '.msi', '.msp', '.msu')
function Test-IsPeFile {
param([string]$Extension)
return $script:PeExtensions -contains $Extension.ToLower()
}
function Get-SignatureInfo {
param([string]$Path, [string]$Extension)
if (-not (Test-IsPeFile -Extension $Extension)) {
return [PSCustomObject]@{ Signer = 'N/A (not PE)'; Status = 'NotApplicable'; Valid = $false }
}
$result = [PSCustomObject]@{ Signer = 'Unsigned'; Status = 'NotSigned'; Valid = $false }
try {
$sig = Get-AuthenticodeSignature -LiteralPath $Path -ErrorAction Stop
$result.Status = $sig.Status.ToString()
$result.Valid = ($sig.Status -eq 'Valid')
if ($sig.SignerCertificate) {
if ($sig.SignerCertificate.Subject -match 'CN=([^,]+)') { $result.Signer = $Matches[1].Trim('"') }
else { $result.Signer = $sig.SignerCertificate.Subject }
if (-not $result.Valid) { $result.Signer += " [INVALID: $($result.Status)]" }
} elseif ($sig.Status -eq 'NotSigned') {
$result.Signer = 'Unsigned'
} else {
$result.Signer = "Unknown [$($result.Status)]"
}
} catch {
$result.Signer = 'Verification error'
$result.Status = 'Error'
$result.Valid = $false
}
return $result
}
$rawApps = Get-ItemProperty -Path $uninstallPaths -ErrorAction SilentlyContinue |
Where-Object { $_.DisplayName -and $_.DisplayName.Trim() -ne '' } |
Select-Object @{Name = 'Name'; Expression = { $_.DisplayName } },
@{Name = 'Version'; Expression = { $_.DisplayVersion } },
@{Name = 'Publisher'; Expression = { $_.Publisher } },
@{Name = 'InstallFolder'; Expression = {
if ($_.InstallLocation -and $_.InstallLocation.Trim() -ne '') { $_.InstallLocation }
elseif ($_.UninstallString -match 'MsiExec\.exe.*?(\{[0-9A-Fa-f\-]{36}\})') {
$productCode = $Matches[1]
$msiLoc = Get-MsiInstallLocation -ProductCode $productCode
if ($msiLoc) { $msiLoc } else { "MSI: $productCode (location not found)" }
}
elseif ($_.UninstallString) { $_.UninstallString }
else { 'N/A' }
} } |
Sort-Object Name -Unique
foreach ($app in $rawApps) {
$versionText = if ($app.Version) { $app.Version } else { '?' }
$publisherText = if ($app.Publisher) { $app.Publisher } else { '?' }
Write-Host ""
Write-Host "<=== $($app.Name) [$versionText] ($publisherText) ===>"
if ($app.InstallFolder -eq 'N/A' -or $app.InstallFolder -match '^MSI: .* \(location not found\)$') {
Write-Host " Path: $($app.InstallFolder)"
continue
}
$cleanPath = Get-CleanPath -RawValue $app.InstallFolder
$exists = $false
try {
$exists = Test-Path -LiteralPath $cleanPath -ErrorAction Stop
} catch [System.UnauthorizedAccessException] {
Write-Host " Path: $cleanPath"
Write-Host " [ACCESS DENIED]"
continue
} catch {
Write-Host " Path: $cleanPath"
Write-Host " [ERROR] cannot access"
continue
}
if (-not $exists) {
Write-Host " Path: $cleanPath"
Write-Host " [NOT FOUND]"
continue
}
$rootItem = Get-Item -LiteralPath $cleanPath -Force
$created = $rootItem.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$modified = $rootItem.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
if ($rootItem.PSIsContainer) {
$subFolders = Get-ChildItem -LiteralPath $cleanPath -Directory -Force -ErrorAction SilentlyContinue
$gciParams = @{ LiteralPath = $cleanPath; File = $true; Force = $true; ErrorAction = 'SilentlyContinue' }
if ($Recurse) { $gciParams['Recurse'] = $true }
$allFiles = Get-ChildItem @gciParams
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: $($allFiles.Count) | Folders: $($subFolders.Count)"
foreach ($dir in $subFolders) {
$dCreated = $dir.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$dModified = $dir.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$dFileCount = (Get-ChildItem -LiteralPath $dir.FullName -File -Force -ErrorAction SilentlyContinue).Count
Write-Host (" [DIR] {0} - {1} - {2,10} - {3}" -f $dCreated, $dModified, "$dFileCount files", $dir.FullName)
}
} else {
$allFiles = @($rootItem)
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: 1"
}
if ($allFiles.Count -eq 0) { continue }
$shown = $allFiles | Select-Object -First $MaxFilesPerApp
foreach ($f in $shown) {
$hash = 'N/A'
try { $hash = (Get-FileHash -LiteralPath $f.FullName -Algorithm SHA256 -ErrorAction Stop).Hash } catch { $hash = 'HASH-ERROR' }
$size = Format-FileSize -Bytes $f.Length
$fcreated = $f.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$fmod = $f.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$sigInfo = Get-SignatureInfo -Path $f.FullName -Extension $f.Extension
Write-Host (" [{0}] {1} - {2} - {3,10} - Signer: {4} - {5}" -f $hash, $fcreated, $fmod, $size, $sigInfo.Signer, $f.FullName)
}
}
EndPowerShell:
Comment: List 30 recent scheduled tasks
Powershell: Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo
Comment: List recent Run (Windows + R) executed commands, useful for identifying ClickFix attacks
Powershell: (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" }
Comment: RenPyLoader hollowed installed app generic removal
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cmd
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.props
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.targets
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.tmp
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.csproj
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.user
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cmd
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cache
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.config
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.bat
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cfg
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cfg
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cfg
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cfg
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cfg
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.props
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.targets
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.user
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cache
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.config
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.bat
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cfg
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.props
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.targets
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.tmp
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.csproj
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cmd
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.user
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cache
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.config
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.bat
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cfg
Comment: Remove cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\
C:\Users\CurrentUserName\AppData\Local\Roblox\UniversalApp\WebView2\EBWebView\Default\Cache\Cache_Data\
C:\Users\CurrentUserName\AppData\Local\FortniteGame\Saved\webcache\
C:\Users\CurrentUserName\AppData\Local\FortniteGame\Saved\webcache_4147\
C:\Users\CurrentUserName\AppData\Local\FortniteGame\Saved\webcache_4430\
C:\Users\CurrentUserName\AppData\Roaming\discord\Cache\Cache_Data\
C:\Users\CurrentUserName\AppData\Roaming\obs-studio\plugin_config\obs-browser\Cache\Cache_Data\
StartPowerShell:
$ProfilesDirectory = (Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList').ProfilesDirectory
$DisplayNames = @{
"chrome" = "Chrome"
"firefox" = "Firefox"
"opera" = "Opera"
"operagx" = "Opera GX"
"brave" = "Brave"
"msedge" = "Edge"
"vivaldi" = "Vivaldi"
"librewolf" = "LibreWolf"
"mullvad" = "Mullvad Browser"
"zen" = "Zen"
}
$ProcessNameMap = @{
"operagx" = "opera"
"mullvad" = "mullvadbrowser"
}
$trueCacheNames = @("Cache", "Code Cache", "DawnCache", "GPUCache", "GrShaderCache", "ShaderCache", "Shared Dictionary\cache")
function Get-CacheDirs {
param([string]$BrowserName, [string]$ProfilesDirectory)
switch ($BrowserName) {
"chrome" {
$dir = "$ProfilesDirectory\*\AppData\Local\Google\Chrome\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"firefox" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mozilla\Firefox\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"opera" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"operagx" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software\Opera GX Stable"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software\Opera GX Stable"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"brave" {
$dir = "$ProfilesDirectory\*\AppData\Local\BraveSoftware\Brave-Browser\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"msedge" {
$dir = "$ProfilesDirectory\*\AppData\Local\Microsoft\Edge\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"vivaldi" {
$dir = "$ProfilesDirectory\*\AppData\Local\Vivaldi\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"librewolf" {
$dir = "$ProfilesDirectory\*\AppData\Local\LibreWolf\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"mullvad" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mullvad\MullvadBrowser\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"zen" {
$dir = "$ProfilesDirectory\*\AppData\Local\zen\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
}
}
function Format-Size {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$BrowserKeys = @('chrome', 'firefox', 'opera', 'operagx', 'brave', 'msedge', 'vivaldi', 'librewolf', 'mullvad', 'zen')
foreach ($key in $BrowserKeys) {
$procName = if ($ProcessNameMap.ContainsKey($key)) { $ProcessNameMap[$key] } else { $key }
Get-Process -Name $procName -ErrorAction SilentlyContinue | Stop-Process -Force -ErrorAction SilentlyContinue
}
Start-Sleep -Seconds 5
$grandBytes = 0L
$grandFiles = 0
$anyFound = $false
foreach ($key in $BrowserKeys) {
$cacheDirs = Get-CacheDirs -BrowserName $key -ProfilesDirectory $ProfilesDirectory
if (-not $cacheDirs -or $cacheDirs.Count -eq 0) { continue }
$anyFound = $true
$displayName = $DisplayNames[$key]
$browserBytes = 0L
$browserFiles = 0
foreach ($cacheDir in $cacheDirs) {
if (-not (Test-Path $cacheDir)) { continue }
$items = Get-ChildItem -Path $cacheDir -Force -Recurse -ErrorAction SilentlyContinue
$files = $items | Where-Object { -not $_.PSIsContainer }
$bytes = ($files | Measure-Object -Property Length -Sum).Sum
if (-not $bytes) { $bytes = 0 }
$browserFiles += $files.Count
$browserBytes += $bytes
Get-ChildItem -Path "$cacheDir\*" -Force -ErrorAction SilentlyContinue | Remove-Item -Force -Recurse -ErrorAction SilentlyContinue
}
$grandBytes += $browserBytes
$grandFiles += $browserFiles
Write-Host ("{0,-16} freed {1,10} ({2} files)" -f $displayName, (Format-Size $browserBytes), $browserFiles)
}
if (-not $anyFound) {
Write-Host "No cache found for any installed browser."
}
Write-Host ""
Write-Host ("Total freed: {0} ({1} files)" -f (Format-Size $grandBytes), $grandFiles)
EndPowerShell:
Comment: Windows Recovery Environment (Windows RE) status and enable
CMD: reagentc.exe /info
CMD: reagentc.exe /enable
Comment: Disable hidden file extensions
cmd: reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "HideFileExt" /t REG_DWORD /d 0 /f
cmd: reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt" /v "CheckedValue" /t REG_DWORD /d 0 /f
Comment: Verify WMI repository, repair & verify again
CMD: winmgmt.exe /verifyrepository
CMD: winmgmt.exe /salvagerepository
CMD: winmgmt.exe /verifyrepository
Comment: To rebuild the performance counter library values
CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R"
CMD: "%WINDIR%\SysWOW64\lodctr.exe /R"
CMD: "C:\Windows\SYSTEM32\lodctr.exe /R"
CMD: "C:\Windows\SysWOW64\lodctr.exe /R"
Comment: Resync performance counter library values to WMI as well
CMD: winmgmt.exe /resyncperf
Comment: Force policy removal
C:\Windows\System32\GroupPolicyUsers
C:\Windows\System32\GroupPolicy
CMD: gpupdate.exe /force
Comment: Restores and hardens selected Microsoft Defender Antivirus preferences.
Comment: Tamper Protection must be temporarily disabled before applying these settings.
Comment: Thanks to AdvancedSetup from Malwarebytes
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows Defender|DisableAntiSpyware
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows Defender|DisableAntiVirus
StartPowerShell:
# Enable real-time and behavioral protection
Set-MpPreference -DisableRealtimeMonitoring $false
Set-MpPreference -DisableBehaviorMonitoring $false
# Enable potentially unwanted application blocking
Set-MpPreference -PUAProtection Enabled
# Enable cloud-delivered protection and automatic safe-sample submission
Set-MpPreference -MAPSReporting Advanced
Set-MpPreference -SubmitSamplesConsent SendSafeSamples
# Use Microsoft's recommended high cloud-blocking level
Set-MpPreference -CloudBlockLevel High
# Allow additional time for cloud analysis of suspicious files
Set-MpPreference -CloudExtendedTimeout 30
# Block connections to known malicious or untrusted network destinations
Set-MpPreference -EnableNetworkProtection Enabled
# Enable Block at First Sight
Set-MpPreference -DisableBlockAtFirstSeen $false
# Enable archive, removable-drive, network-file, download, and script scanning
Set-MpPreference -DisableArchiveScanning $false
Set-MpPreference -DisableRemovableDriveScanning $false
Set-MpPreference -DisableScanningNetworkFiles $false
Set-MpPreference -DisableIOAVProtection $false
Set-MpPreference -DisableScriptScanning $false
# Check for current security intelligence before starting a scan
Set-MpPreference -CheckForSignaturesBeforeRunningScan $true
# Enable supported DNS attack inspection and sinkholing when available
if ((Get-Command Set-MpPreference).Parameters.ContainsKey('EnableDnsSinkhole')) {
Set-MpPreference -EnableDnsSinkhole $true
}
# Sets signature update interval to 12 hours (default 24 hours)
Set-MpPreference -SignatureUpdateInterval 12
# Update Microsoft Defender security intelligence
Update-MpSignature
EndPowerShell:
Comment: List Windows Defender properties, settings
StartPowerShell:
function Write-Section {
param([string]$Title)
Write-Host ""
Write-Host "<=== $Title ===>"
}
Write-Section "Protection Status"
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntispywareEnabled, AntivirusEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, RealTimeProtectionEnabled, IsTamperProtected, NetworkProtectionStatus | Format-List
Write-Section "Signature / Engine Versions"
Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AntivirusSignatureVersion, AntispywareSignatureVersion | Format-List
Write-Section "Preferences / Configuration"
Get-MpPreference | Select-Object PUAProtection, MAPSReporting, SubmitSamplesConsent, CheckForSignaturesBeforeRunningScan, CloudBlockLevel, EnableNetworkProtection, DisableScriptScanning, DisableArchiveScanning, DisableRemovableDriveScanning, DisableScanningNetworkFiles, DisableScanningMappedNetworkDrivesForFullScan, DisableBlockAtFirstSeen, DisableHeuristics, DisableAutoExclusions | Format-List
Write-Section "Threat Detections"
$threats = Get-MpThreatDetection
if ($threats) {
$threats | Format-Table -AutoSize
} else {
Write-Host " (no threat detections found)"
}
EndPowerShell:
Comment: Enable recovery environment
CMD: bcdedit.exe /set {default} recoveryenabled yes
Comment: Restore original Windows services configuration
StartPowerShell:
Set-Service -Name "Netlogon" -StartupType Manual
Set-Service -Name "BITS" -StartupType Manual
Set-Service -Name "Dhcp" -StartupType Automatic
Set-Service -Name "EventLog" -StartupType Automatic
Set-Service -Name "EventSystem" -StartupType Automatic
Set-Service -Name "nsi" -StartupType Automatic
Set-Service -Name "RasMan" -StartupType Manual
Set-Service -Name "SDRSVC" -StartupType Manual
Set-Service -Name "SstpSvc" -StartupType Manual
Set-Service -Name "TrustedInstaller" -StartupType Manual
Set-Service -Name "VSS" -StartupType Manual
Set-Service -Name "Winmgmt" -StartupType Automatic
Set-Service -Name "wuauserv" -StartupType Manual
EndPowerShell:
Comment: Reset the Windows Update download cache and update catalog database
CMD: net.exe stop bits
CMD: net.exe stop wuauserv
CMD: net.exe stop cryptsvc
CMD: net.exe stop msiserver
CMD: rd /s /q "%SystemRoot%\SoftwareDistribution"
CMD: rd /s /q "%SystemRoot%\System32\catroot2"
CMD: net.exe start msiserver
CMD: net.exe start cryptsvc
CMD: net.exe start wuauserv
CMD: net.exe start bits
Comment: Enable automatic restart after a restart, enable automatic updates
StartRegedit:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl]
"AutoReboot"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"NoAutoUpdate"=-
EndRegedit:
Comment: Reset PowerShell execution policy
Powershell: Set-ExecutionPolicy Unrestricted -Scope CurrentUser -Force
Comment: Fully reset the Windows network stack, WinHTTP proxy settings, DNS cache, and BITS transfer queue.
Comment: Thanks to AdvancedSetup from Malwarebytes
StartBatch:
ipconfig.exe /flushdns
ipconfig.exe /release
netsh.exe winsock reset catalog
netsh.exe int ip reset
netsh.exe winhttp reset proxy
netsh.exe winhttp reset autoproxy
netsh.exe winhttp reset tracing
EndBatch:
Comment: BITS reset
Startbatch:
@echo off
net.exe stop BITS
ipconfig.exe /flushdns
ren "%programdata%\Microsoft\Network\Downloader\qmgr*.*" qmgr*.*.old
net.exe start BITS
Endbatch:
cmd: bitsadmin.exe /reset /allusers
Comment: Additional temp file removal
C:\Windows\System32\config\systemprofile\AppData\Local\*.tmp
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
C:\Users\CurrentUserName\AppData\Local\Temp\*
C:\Windows\Temp\*
C:\Windows\SystemTemp\*
C:\Windows\Prefetch\*
Comment: System repair commands
CMD: SFC.exe /scannow
CMD: DISM.exe /Online /Cleanup-image /Restorehealth
CMD: DISM.exe /Online /Cleanup-Image /StartComponentCleanup /ResetBase
Comment: Remove set proxy servers
RemoveProxy:
Comment: Remove temporary files via FRST
EmptyTemp:
End::
Warning
Executing a Fixlist on the wrong system may permanently damage it. Continue only if this link was meant for you.
To view the content, acknowledge this warning.