content copied
content
Start
CreateRestorePoint:
CloseProcesses:
Reg: reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces" /s
2026-08-22 08:44 - 2025-07-01 17:01 - 000003408 _____ C:\WINDOWS\system32\Tasks\MAkF7mCn3tPqp662daybvERzwsKQYqnzM8
2025-07-05 22:31 - 2025-07-05 22:31 - 000000048 ____R () C:\Users\prawa\AppData\Local\F19eWJh8J6Mx9DrGXKEv3ojKmqw8Cv9pscK
Tcpip\..\Interfaces\{80bb6a33-6df0-4e1f-8c3c-35d983ffa4a1}\A719eWJh8J6Mx9DrGXKEv3ojKmqw8Cv9pscK: [DhcpNameServer] 10.97.52.208
Folder: C:\Users\prawa\AppData\Local\Renesas
Folder: C:\Users\prawa\AppData\LocalLow\DefaultCompany
Folder: C:\Users\prawa\AppData\Local\ANTONBLAST
Folder: C:\Users\prawa\AppData\Local\SW64
Folder: C:\Users\prawa\AppData\Roaming\Microsoft\Protect
2026-08-24 12:11 - 2026-08-24 12:11 - 000000000 ____D C:\Users\prawa\AppData\Local\Renesas
2026-08-22 18:04 - 2026-08-24 12:09 - 000000000 ____D C:\Users\prawa\AppData\Roaming\RenPy
C:\USERS\PRAWA\APPDATA\ROAMING\MICROSOFT\PROTECT\NEWTONSOFTJSON
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
C:\Users\prawa\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\jlgkpaicikihijadgifklkbpdajbkhjo
2026-08-19 13:22 - 2026-08-19 13:22 - 000000000 ____D C:\Users\prawa\AppData\Local\OB
2026-08-19 13:20 - 2026-08-19 13:22 - 000000000 ____D C:\Program Files (x86)\OB
HKU\S-1-5-21-3462901007-694797416-3828339284-1000\...\Run: [RiotClient] => D:\Riot Games\Riot Client\RiotClientServices.exe --launch-background-mode (No File)
HKU\S-1-5-21-3462901007-694797416-3828339284-1000\...\MountPoints2: {061dfac8-193a-11f1-8c89-4cb04a755417} - "F:\setup.exe"
HKU\S-1-5-21-3462901007-694797416-3828339284-1000\...\MountPoints2: {48103532-55ba-11f1-8ce5-4cb04a755417} - "G:\setup.exe"
HKU\S-1-5-21-3462901007-694797416-3828339284-1000\...\MountPoints2: {8ec5c61c-5698-11f0-8b60-4cb04a755417} - "F:\setup.exe"
HKU\S-1-5-21-3462901007-694797416-3828339284-1000\...\MountPoints2: {f6d06c46-51c9-11f1-8cdf-4cb04a755417} - "E:\CMADownloader.exe"
HKU\S-1-5-18\...\Run: [RazerAppEngine] => "C:\Program Files\Razer\RazerAppEngine\RazerAppEngine.exe" --url-params=apps=synapse --launch-force-hidden=synapse (No File)
Task: {DB668D98-BC5A-4F33-A171-5CEF14BE70B5} - System32\Tasks\Microsoft\Windows\Clip\ClipESU => %SystemRoot%\system32\clipesu.exe (No File)
Task: {ED1E2ED7-60CA-4CC1-9018-2D972F7F19FD} - System32\Tasks\Microsoft\Windows\Clip\ClipESUConsumer => %SystemRoot%\system32\ClipESUConsumer.exe -evaluateEligibility (No File)
Task: {42B43579-001A-4739-8186-0CCC74251143} - System32\Tasks\Microsoft\Windows\Clip\ClipEsuConsumerProcessPreOrder => %SystemRoot%\system32\ClipESUConsumer.exe -postProcessPreOrder (No File)
Task: {44F11359-544D-4C5D-9D9F-CED7E5D3979D} - System32\Tasks\Microsoft\Windows\Clip\ClipEsuConsumerProcessRefund => %SystemRoot%\system32\ClipESUConsumer.exe -processRefund (No File)
Task: {E88D9B2C-DDEA-47B2-9582-085153004DB5} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
Task: {AA6B9E2E-01C1-4997-9DCC-10EF15D88281} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (No File)
Task: {F270570A-065E-4AB5-A43D-D1DEB311BEED} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {11BE3C73-806E-46D2-ACA5-FF7E6956B03D} - System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler => "%ProgramFiles%\RUXIM\PLUGscheduler.exe" (No File)
S2 AdskNLM; "C:\Program Files (x86)\Common Files\Autodesk Shared\Network License Manager\lmgrd.exe" (No File)
S2 onebupdate; C:\Program Files (x86)\OB\OneBUpdate\OneBUpdateService.exe -service (No File) <==== ATTENTION
U2 DriverUpdSvc.exe; no ImagePath
U2 TuneupSvc.exe; no ImagePath
CustomCLSID: HKU\S-1-5-21-3462901007-694797416-3828339284-1000_Classes\CLSID\{50726f74-6f6e-2e56-504e-000000000000}\localserver32 -> "C:\Program Files\Proton\VPN\v5.1.6\ProtonVPN.Client.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-3462901007-694797416-3828339284-1000_Classes\CLSID\{607BBE5B-A4EE-47EB-88C9-75FE5F12EAC7}\localserver32 -> D:\autodesk\AutoCAD 2026\acad.exe /Automation => No File
CustomCLSID: HKU\S-1-5-21-3462901007-694797416-3828339284-1000_Classes\CLSID\{832ef2bc-a9fa-4bc1-8ec8-e9ac60c64bf5}\InprocServer32 -> C:\Program Files\LibreWolf\notificationserver.dll => No File
CustomCLSID: HKU\S-1-5-21-3462901007-694797416-3828339284-1000_Classes\CLSID\{C5279B1A-0D02-4307-B436-1462D128C900}\localserver32 -> C:\Users\prawa\AppData\Local\Wand\app-12.32.0\Wand.exe => No File
CustomCLSID: HKU\S-1-5-21-3462901007-694797416-3828339284-1000_Classes\CLSID\{C8057BBA-5B80-4759-AB0E-7E877A876110}\localserver32 -> C:\Program Files\Autodesk\AdODIS\V1\Setup\ui-launcher\AdskAccessUIHost.exe => No File
AlternateDataStreams: C:\Users\prawa\OneDrive\Рабочий стол\mb-support-1.9.17.1158.exe:MBAM.Zone.Identifier [132]
FirewallRules: [UDP Query User{993675D6-C53B-4BDA-8CB9-D77F3E7E8117}D:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) D:\riot games\riot client\riotclientelectron\riot client.exe => No File
FirewallRules: [TCP Query User{E665AF1E-84E5-478B-8DA0-73B99EFD5DD8}D:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) D:\riot games\riot client\riotclientelectron\riot client.exe => No File
FirewallRules: [{EBC43011-755B-4E90-B9A3-46A1EA7CCFD4}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [{B7DFB8FF-D51C-4652-8067-451E50A42B1A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [TCP Query User{D380622B-5810-4324-B003-CA11C53642E8}D:\qbit\v rising\v rising 30.04.25\v rising\vrising.exe] => (Allow) D:\qbit\v rising\v rising 30.04.25\v rising\vrising.exe => No File
FirewallRules: [UDP Query User{5A7DEAD6-D1C9-4DD7-9655-91FA35C7111A}D:\qbit\v rising\v rising 30.04.25\v rising\vrising.exe] => (Allow) D:\qbit\v rising\v rising 30.04.25\v rising\vrising.exe => No File
FirewallRules: [TCP Query User{34C0C349-F0BB-42FB-97C3-73A778BD1AE5}D:\qbit\v rising\v rising 30.04.25\v rising\vrising_server\vrisingserver.exe] => (Allow) D:\qbit\v rising\v rising 30.04.25\v rising\vrising_server\vrisingserver.exe => No File
FirewallRules: [UDP Query User{5DC060E8-D550-42DF-BE91-4406CC6725D9}D:\qbit\v rising\v rising 30.04.25\v rising\vrising_server\vrisingserver.exe] => (Allow) D:\qbit\v rising\v rising 30.04.25\v rising\vrising_server\vrisingserver.exe => No File
FirewallRules: [{DD8FB3A2-22FD-4408-8976-0EC813EEC433}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{D28F3CBA-111A-4F7E-A85B-7D4806129B35}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [TCP Query User{9DA61520-9D38-4118-A9E5-60F122D6C665}D:\games\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe] => (Allow) D:\games\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe => No File
FirewallRules: [UDP Query User{5D1A46B9-DD95-4759-B70B-108CA0A6E34E}D:\games\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe] => (Allow) D:\games\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe => No File
FirewallRules: [TCP Query User{11D4B16C-EA6D-48CE-9AFA-013EBC1B6DF9}D:\divinity - original sin 2\defed\bin\eocapp.exe] => (Allow) D:\divinity - original sin 2\defed\bin\eocapp.exe => No File
FirewallRules: [UDP Query User{4E94E246-F81D-4FAA-BAA5-16B5D329DE9A}D:\divinity - original sin 2\defed\bin\eocapp.exe] => (Allow) D:\divinity - original sin 2\defed\bin\eocapp.exe => No File
FirewallRules: [TCP Query User{1B0497B4-8AB0-4030-B7B4-FE40F014765B}D:\games\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Block) D:\games\cyberpunk 2077\bin\x64\cyberpunk2077.exe => No File
FirewallRules: [UDP Query User{060B5D19-ED1F-4309-BFB2-AADEC1FED332}D:\games\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Block) D:\games\cyberpunk 2077\bin\x64\cyberpunk2077.exe => No File
FirewallRules: [TCP Query User{CAAEB6D9-7032-4DD4-8D88-5C0DFF72935F}D:\doomthedarkages\doomthedarkages.exe] => (Allow) D:\doomthedarkages\doomthedarkages.exe => No File
FirewallRules: [UDP Query User{133286D6-0B60-40C2-89C7-3734B8D167EE}D:\doomthedarkages\doomthedarkages.exe] => (Allow) D:\doomthedarkages\doomthedarkages.exe => No File
FirewallRules: [TCP Query User{17FE3972-F6EF-4AD3-9819-9A10199F981D}D:\blackmythwukong\b1\binaries\win64\b1-win64-shipping.exe] => (Allow) D:\blackmythwukong\b1\binaries\win64\b1-win64-shipping.exe => No File
FirewallRules: [UDP Query User{BBD48E57-104B-4C01-A05F-C5BD5C4BC7BD}D:\blackmythwukong\b1\binaries\win64\b1-win64-shipping.exe] => (Allow) D:\blackmythwukong\b1\binaries\win64\b1-win64-shipping.exe => No File
FirewallRules: [TCP Query User{E7E9C3F7-C84A-474F-98C9-EA3BC02EDD19}C:\users\prawa\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\prawa\appdata\roaming\zoom\bin\zoom.exe => No File
FirewallRules: [UDP Query User{B84FEC8C-0D8E-426E-B74F-F5EB4956AE25}C:\users\prawa\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\prawa\appdata\roaming\zoom\bin\zoom.exe => No File
FirewallRules: [TCP Query User{898589A1-6C3A-47C3-B0F0-C65EDE2642B3}D:\hi-fi rush\hibiki\binaries\win64\hi-fi-rush.exe] => (Allow) D:\hi-fi rush\hibiki\binaries\win64\hi-fi-rush.exe => No File
FirewallRules: [UDP Query User{811BBC0A-3993-4CF3-BFE2-EA7475EC4418}D:\hi-fi rush\hibiki\binaries\win64\hi-fi-rush.exe] => (Allow) D:\hi-fi rush\hibiki\binaries\win64\hi-fi-rush.exe => No File
FirewallRules: [TCP Query User{28C1A51D-B3AB-48A7-A2E3-A70A4B59CB38}D:\shinobi_aov\shinobi_aov.exe] => (Allow) D:\shinobi_aov\shinobi_aov.exe => No File
FirewallRules: [UDP Query User{060598A7-08AB-4C01-84A8-77310C9309C8}D:\shinobi_aov\shinobi_aov.exe] => (Allow) D:\shinobi_aov\shinobi_aov.exe => No File
FirewallRules: [TCP Query User{4805ACAD-BB24-4DF1-B6B7-B2565A00C035}D:\the first berserker khazan\bbq\binaries\win64\bbq-win64-shipping.exe] => (Allow) D:\the first berserker khazan\bbq\binaries\win64\bbq-win64-shipping.exe => No File
FirewallRules: [UDP Query User{1AF3FD16-8B98-411C-B1B0-04AF1703042A}D:\the first berserker khazan\bbq\binaries\win64\bbq-win64-shipping.exe] => (Allow) D:\the first berserker khazan\bbq\binaries\win64\bbq-win64-shipping.exe => No File
FirewallRules: [TCP Query User{7BF23336-C449-4B44-8165-567143895188}D:\sonic_x_shadow_generations\sonic_x_shadow_generations.exe] => (Allow) D:\sonic_x_shadow_generations\sonic_x_shadow_generations.exe => No File
FirewallRules: [UDP Query User{762BBA32-EFD5-4AF4-A2A7-4DAB3DF2DF12}D:\sonic_x_shadow_generations\sonic_x_shadow_generations.exe] => (Allow) D:\sonic_x_shadow_generations\sonic_x_shadow_generations.exe => No File
FirewallRules: [TCP Query User{466E1083-3894-4B2C-A93F-617A869995C2}D:\sonicfrontiers\sonicfrontiers.exe] => (Allow) D:\sonicfrontiers\sonicfrontiers.exe => No File
FirewallRules: [UDP Query User{01F72993-918B-4A1B-AD76-BB30777B0014}D:\sonicfrontiers\sonicfrontiers.exe] => (Allow) D:\sonicfrontiers\sonicfrontiers.exe => No File
FirewallRules: [TCP Query User{B282D973-72C5-4BF7-BA4F-660CA478D068}D:\sonicfrontiers\sonicfrontiersartandmusic.exe] => (Allow) D:\sonicfrontiers\sonicfrontiersartandmusic.exe => No File
FirewallRules: [UDP Query User{F05F6D03-006A-4342-84DF-E40D955213FF}D:\sonicfrontiers\sonicfrontiersartandmusic.exe] => (Allow) D:\sonicfrontiers\sonicfrontiersartandmusic.exe => No File
FirewallRules: [TCP Query User{F56C5D4D-D923-47C5-991E-B8AEE83FC780}D:\qbit\inzoi-insaneramzes\blueclient\binaries\win64\inzoi-win64-shipping.exe] => (Allow) D:\qbit\inzoi-insaneramzes\blueclient\binaries\win64\inzoi-win64-shipping.exe => No File
FirewallRules: [UDP Query User{796D4A17-0338-4A96-982B-60EF70F2B2A9}D:\qbit\inzoi-insaneramzes\blueclient\binaries\win64\inzoi-win64-shipping.exe] => (Allow) D:\qbit\inzoi-insaneramzes\blueclient\binaries\win64\inzoi-win64-shipping.exe => No File
FirewallRules: [TCP Query User{69D0F12E-2159-4615-859E-3AADB2DE2B52}D:\sonic superstars\sonicsuperstars.exe] => (Allow) D:\sonic superstars\sonicsuperstars.exe => No File
FirewallRules: [UDP Query User{801B3C19-0D15-4879-8947-7E4C41C4E7D7}D:\sonic superstars\sonicsuperstars.exe] => (Allow) D:\sonic superstars\sonicsuperstars.exe => No File
FirewallRules: [TCP Query User{A93C1EB5-7892-4C42-9EC6-8B7D540B7E67}D:\soniccolorsultimate\exec\soniccolorsultimate.exe] => (Allow) D:\soniccolorsultimate\exec\soniccolorsultimate.exe => No File
FirewallRules: [UDP Query User{E42AC169-94DA-4171-86C1-EF06A8BC0A79}D:\soniccolorsultimate\exec\soniccolorsultimate.exe] => (Allow) D:\soniccolorsultimate\exec\soniccolorsultimate.exe => No File
FirewallRules: [{507BB9F4-E055-4F15-BBD3-8AB00546E7EA}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe => No File
FirewallRules: [{BDCDCE7D-571E-4F40-B73A-9C8DAEDB7E13}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe => No File
FirewallRules: [TCP Query User{308298B5-3B3A-417F-BA7B-B3955C12E3F6}D:\qbit\zeroranger\zeroranger.exe] => (Allow) D:\qbit\zeroranger\zeroranger.exe => No File
FirewallRules: [UDP Query User{EDAB53E7-E784-430A-A8A0-00B0B83BAEDB}D:\qbit\zeroranger\zeroranger.exe] => (Allow) D:\qbit\zeroranger\zeroranger.exe => No File
FirewallRules: [TCP Query User{C801BDDB-7B44-4D93-B4D5-FFF42DE3D687}D:\qbit\portal\portal\hl2.exe] => (Allow) D:\qbit\portal\portal\hl2.exe => No File
FirewallRules: [UDP Query User{BC8201F9-56CC-4A29-B5E3-687604764178}D:\qbit\portal\portal\hl2.exe] => (Allow) D:\qbit\portal\portal\hl2.exe => No File
FirewallRules: [TCP Query User{74E583EA-89E8-4E63-A7C0-D05458F62320}D:\games\portal + portal prelude\hl2.exe] => (Allow) D:\games\portal + portal prelude\hl2.exe => No File
FirewallRules: [UDP Query User{77A50393-02A2-4FAA-B700-5698A02B57A1}D:\games\portal + portal prelude\hl2.exe] => (Allow) D:\games\portal + portal prelude\hl2.exe => No File
FirewallRules: [TCP Query User{E14A0464-B87C-47C4-8928-74C3A03B89C0}D:\qbit\buckshot roulette\buckshot roulette.exe] => (Allow) D:\qbit\buckshot roulette\buckshot roulette.exe => No File
FirewallRules: [UDP Query User{402AD75A-344B-4BCC-A897-5C392D4776A9}D:\qbit\buckshot roulette\buckshot roulette.exe] => (Allow) D:\qbit\buckshot roulette\buckshot roulette.exe => No File
FirewallRules: [TCP Query User{1B5E162E-64A3-485A-B247-9A1904C15374}D:\qbit\who's lila\who's lila 20.07.22\who's lila\whoslila.exe] => (Allow) D:\qbit\who's lila\who's lila 20.07.22\who's lila\whoslila.exe => No File
FirewallRules: [UDP Query User{B06B97D0-02C7-484A-9481-EE56D4F5520A}D:\qbit\who's lila\who's lila 20.07.22\who's lila\whoslila.exe] => (Allow) D:\qbit\who's lila\who's lila 20.07.22\who's lila\whoslila.exe => No File
FirewallRules: [TCP Query User{B72D8378-A31C-4148-B67A-CA75D0B04890}D:\steam\steamapps\common\tom clancy's rainbow six siege\rainbowsix.exe] => (Allow) D:\steam\steamapps\common\tom clancy's rainbow six siege\rainbowsix.exe => No File
FirewallRules: [UDP Query User{B3CAB445-5B15-4E19-8C32-6D3CF0A10848}D:\steam\steamapps\common\tom clancy's rainbow six siege\rainbowsix.exe] => (Allow) D:\steam\steamapps\common\tom clancy's rainbow six siege\rainbowsix.exe => No File
FirewallRules: [TCP Query User{435CDDFE-2268-482D-B8C1-C214034768FB}C:\users\prawa\appdata\local\ubisoft\r6siege\rainbowsix.exe] => (Allow) C:\users\prawa\appdata\local\ubisoft\r6siege\rainbowsix.exe => No File
FirewallRules: [UDP Query User{8146E6D2-94A2-46D3-8E6A-4777F8CB4921}C:\users\prawa\appdata\local\ubisoft\r6siege\rainbowsix.exe] => (Allow) C:\users\prawa\appdata\local\ubisoft\r6siege\rainbowsix.exe => No File
FirewallRules: [TCP Query User{BA409F7A-CBE3-4558-ABDD-30E2897DA06F}D:\sonic_x_shadow_generations\sonic_generations.exe] => (Allow) D:\sonic_x_shadow_generations\sonic_generations.exe => No File
FirewallRules: [UDP Query User{E03F19EE-293A-433E-9F99-3A1E7324BB1A}D:\sonic_x_shadow_generations\sonic_generations.exe] => (Allow) D:\sonic_x_shadow_generations\sonic_generations.exe => No File
FirewallRules: [TCP Query User{B9B7DA56-1AE1-4A4E-BA97-20BB8B6E04B1}D:\qbit\ship of fools\ship of fools\shipoffools.exe] => (Allow) D:\qbit\ship of fools\ship of fools\shipoffools.exe => No File
FirewallRules: [UDP Query User{5E6A38A3-81A4-4F0A-90F9-DF459883E0DC}D:\qbit\ship of fools\ship of fools\shipoffools.exe] => (Allow) D:\qbit\ship of fools\ship of fools\shipoffools.exe => No File
FirewallRules: [TCP Query User{CA753B49-F2DA-46E8-ABB2-D8756D660C42}D:\qbit\sun haven\sun haven 26.03.25\sun haven\sun haven.exe] => (Allow) D:\qbit\sun haven\sun haven 26.03.25\sun haven\sun haven.exe => No File
FirewallRules: [UDP Query User{F709FD39-4F60-4EBF-B34E-8AB74980B7E0}D:\qbit\sun haven\sun haven 26.03.25\sun haven\sun haven.exe] => (Allow) D:\qbit\sun haven\sun haven 26.03.25\sun haven\sun haven.exe => No File
FirewallRules: [TCP Query User{7464D477-D015-4044-9B58-B6662D0E5B02}D:\qbittorrent\sun haven\sun haven 26.03.25\sun haven\sun haven.exe] => (Allow) D:\qbittorrent\sun haven\sun haven 26.03.25\sun haven\sun haven.exe => No File
FirewallRules: [UDP Query User{4F3B9897-879B-4081-AD8A-463FAC398476}D:\qbittorrent\sun haven\sun haven 26.03.25\sun haven\sun haven.exe] => (Allow) D:\qbittorrent\sun haven\sun haven 26.03.25\sun haven\sun haven.exe => No File
FirewallRules: [TCP Query User{D4D4D550-E0AC-4830-8E37-AA391419AADA}D:\resident evil requiem biohazard requiem\re9.exe] => (Allow) D:\resident evil requiem biohazard requiem\re9.exe => No File
FirewallRules: [UDP Query User{F52152BE-2AA4-4B45-A242-B97468ED5494}D:\resident evil requiem biohazard requiem\re9.exe] => (Allow) D:\resident evil requiem biohazard requiem\re9.exe => No File
FirewallRules: [TCP Query User{9FD4D97B-73FA-442A-8195-4B315037D468}D:\qbit\sun.haven.v3.0.2b.rexagames.com\sun haven.exe] => (Block) D:\qbit\sun.haven.v3.0.2b.rexagames.com\sun haven.exe => No File
FirewallRules: [UDP Query User{7E16951B-00AE-4A22-B2DE-BDF62DCB3DCE}D:\qbit\sun.haven.v3.0.2b.rexagames.com\sun haven.exe] => (Block) D:\qbit\sun.haven.v3.0.2b.rexagames.com\sun haven.exe => No File
FirewallRules: [TCP Query User{51AB38A6-DB6C-40AB-B3E3-F13A77389A61}C:\users\prawa\appdata\local\temp\3bdrhzmjwak9tzjygpmriecffim\s4mp launcher.exe] => (Allow) C:\users\prawa\appdata\local\temp\3bdrhzmjwak9tzjygpmriecffim\s4mp launcher.exe => No File
FirewallRules: [UDP Query User{414591DC-45CA-42BB-8576-12EEC30D55EB}C:\users\prawa\appdata\local\temp\3bdrhzmjwak9tzjygpmriecffim\s4mp launcher.exe] => (Allow) C:\users\prawa\appdata\local\temp\3bdrhzmjwak9tzjygpmriecffim\s4mp launcher.exe => No File
FirewallRules: [TCP Query User{B605CDBD-FF40-4E71-B2B8-4D050A0A492A}D:\qbit\[dl] don't starve together [p] [eng+2] (2016, adventure) (647923) [portable]\don't starve together\bin64\dontstarve_steam_x64.exe] => (Allow) D:\qbit\[dl] don't starve together [p] [eng+2] (2016, adventure) (647923) [portable]\don't starve together\bin64\dontstarve_steam_x64.exe => No File
FirewallRules: [UDP Query User{CD60FE2F-1EAC-4CF5-913D-65FA47BF89AD}D:\qbit\[dl] don't starve together [p] [eng+2] (2016, adventure) (647923) [portable]\don't starve together\bin64\dontstarve_steam_x64.exe] => (Allow) D:\qbit\[dl] don't starve together [p] [eng+2] (2016, adventure) (647923) [portable]\don't starve together\bin64\dontstarve_steam_x64.exe => No File
FirewallRules: [TCP Query User{51B977D1-384C-4169-B755-C030F10ECE2A}D:\qbit\[dl] don't starve together [p] [eng+2] (2016, adventure) (647923) [portable]\don't starve together\bin64\dontstarve_dedicated_server_nullrenderer_x64.exe] => (Allow) D:\qbit\[dl] don't starve together [p] [eng+2] (2016, adventure) (647923) [portable]\don't starve together\bin64\dontstarve_dedicated_server_nullrenderer_x64.exe => No File
FirewallRules: [UDP Query User{2FE95692-E789-45FB-BD7E-C52BBE416B09}D:\qbit\[dl] don't starve together [p] [eng+2] (2016, adventure) (647923) [portable]\don't starve together\bin64\dontstarve_dedicated_server_nullrenderer_x64.exe] => (Allow) D:\qbit\[dl] don't starve together [p] [eng+2] (2016, adventure) (647923) [portable]\don't starve together\bin64\dontstarve_dedicated_server_nullrenderer_x64.exe => No File
FirewallRules: [TCP Query User{92662BE4-2F55-43C4-A5EE-5C2A58C1BE51}D:\games\titanfall 2\titanfall2.exe] => (Allow) D:\games\titanfall 2\titanfall2.exe => No File
FirewallRules: [UDP Query User{4A3610B1-C4A5-4FB4-AA2C-C8427887E0C5}D:\games\titanfall 2\titanfall2.exe] => (Allow) D:\games\titanfall 2\titanfall2.exe => No File
FirewallRules: [TCP Query User{3BD39058-FBBF-4393-BABE-A7E3CA521CE4}D:\cursor\cursor.exe] => (Allow) D:\cursor\cursor.exe => No File
FirewallRules: [UDP Query User{CA948FCC-29D2-4B65-9D7F-B81AB2496509}D:\cursor\cursor.exe] => (Allow) D:\cursor\cursor.exe => No File
FirewallRules: [{6495F5FA-ABCC-416A-84BE-0B77710200FC}] => (Allow) D:\Games\MiniTool ShadowMaker\AgentService.exe => No File
FirewallRules: [{E4080483-F415-46A9-82CE-0547973298ED}] => (Allow) D:\Games\MiniTool ShadowMaker\AgentService.exe => No File
FirewallRules: [{260E7C97-0CF2-415A-87B6-31D37F56CDC7}] => (Allow) C:\Users\prawa\AppData\Local\Programs\Opera GX\opera.exe => No File
FirewallRules: [TCP Query User{EDEBF65E-9515-410F-91B0-7BA59581DE27}D:\qbit\sonic colors ultimate\sonic colors ultimate\exec\soniccolorsultimate.exe] => (Allow) D:\qbit\sonic colors ultimate\sonic colors ultimate\exec\soniccolorsultimate.exe => No File
FirewallRules: [UDP Query User{A901C67F-A3C4-438A-BC94-BFB48006CC18}D:\qbit\sonic colors ultimate\sonic colors ultimate\exec\soniccolorsultimate.exe] => (Allow) D:\qbit\sonic colors ultimate\sonic colors ultimate\exec\soniccolorsultimate.exe => No File
FirewallRules: [TCP Query User{22A71C45-AF67-4AD1-A8AF-5CBEFE617AEF}D:\qbit\virtua fighter 5 r.e.v.o\virtua.fighter.5.r.e.v.o.build.04022025-ofme\virtua fighter 5 r.e.v.o\vfrevo.exe] => (Allow) D:\qbit\virtua fighter 5 r.e.v.o\virtua.fighter.5.r.e.v.o.build.04022025-ofme\virtua fighter 5 r.e.v.o\vfrevo.exe => No File
FirewallRules: [UDP Query User{DEBEAC06-020C-494B-BA9E-6362D52AB1CF}D:\qbit\virtua fighter 5 r.e.v.o\virtua.fighter.5.r.e.v.o.build.04022025-ofme\virtua fighter 5 r.e.v.o\vfrevo.exe] => (Allow) D:\qbit\virtua fighter 5 r.e.v.o\virtua.fighter.5.r.e.v.o.build.04022025-ofme\virtua fighter 5 r.e.v.o\vfrevo.exe => No File
FirewallRules: [TCP Query User{485BB4FF-E665-4DF2-8090-4312D402C9D0}C:\program files\docker\docker\resources\com.docker.backend.exe] => (Allow) C:\program files\docker\docker\resources\com.docker.backend.exe => No File
FirewallRules: [UDP Query User{CCE85C52-243B-48E9-AA2A-10158566B1A9}C:\program files\docker\docker\resources\com.docker.backend.exe] => (Allow) C:\program files\docker\docker\resources\com.docker.backend.exe => No File
FirewallRules: [TCP Query User{F42CD2AC-1659-460B-8548-392B73E05EBF}C:\users\prawa\appdata\local\discord\app-1.0.9245\discord.exe] => (Allow) C:\users\prawa\appdata\local\discord\app-1.0.9245\discord.exe => No File
FirewallRules: [UDP Query User{35D72F53-B6A7-498E-B1E5-EDCFE0718F52}C:\users\prawa\appdata\local\discord\app-1.0.9245\discord.exe] => (Allow) C:\users\prawa\appdata\local\discord\app-1.0.9245\discord.exe => No File
FirewallRules: [TCP Query User{BA9BA902-26BB-4111-80CD-F561B8F49825}C:\program files (x86)\nvidia corporation\nsight visual studio edition 2025.3\monitor\common\nsight.monitor.exe] => (Allow) C:\program files (x86)\nvidia corporation\nsight visual studio edition 2025.3\monitor\common\nsight.monitor.exe => No File
FirewallRules: [UDP Query User{B38C82EA-874B-42B4-BD8E-C1B88C21928B}C:\program files (x86)\nvidia corporation\nsight visual studio edition 2025.3\monitor\common\nsight.monitor.exe] => (Allow) C:\program files (x86)\nvidia corporation\nsight visual studio edition 2025.3\monitor\common\nsight.monitor.exe => No File
FirewallRules: [{DB40D7E8-9E1F-4CE8-90D6-B8952495540D}] => (Allow) D:\BlueStacks X\BlueStacksWeb.exe => No File
FirewallRules: [{870618D9-A7CD-410D-BBCE-344EB3FEB39A}] => (Allow) D:\BlueStacks X\Cloud Game.exe => No File
FirewallRules: [{79FA4EB2-9255-4168-8EA4-8037C8E33224}] => (Allow) C:\Program Files\BlueStacks_nxt\HD-Player.exe => No File
FirewallRules: [{F9B86EEE-E698-47E5-B0F1-32F49D05EE07}] => (Allow) C:\Program Files\BlueStacks_nxt\BlueStacksAppplayerWeb.exe => No File
FirewallRules: [{7402B3EF-7438-4C93-9FB8-ED93FB25DF1C}] => (Allow) C:\Program Files\BlueStacks_nxt\BlueStacksAIRun.exe => No File
FirewallRules: [TCP Query User{3D47943B-C0DC-438A-9A62-27CAAE25A26E}C:\platform-tools\adb.exe] => (Allow) C:\platform-tools\adb.exe => No File
FirewallRules: [UDP Query User{A801C6F4-416C-4AAC-A26B-87E951E0BE79}C:\platform-tools\adb.exe] => (Allow) C:\platform-tools\adb.exe => No File
FirewallRules: [TCP Query User{5A48DFE1-1895-4689-92C8-4F3B96B69F97}C:\android-sdk\platform-tools\adb.exe] => (Allow) C:\android-sdk\platform-tools\adb.exe => No File
FirewallRules: [UDP Query User{F246F0B6-C051-43D3-8AF2-563CA0786538}C:\android-sdk\platform-tools\adb.exe] => (Allow) C:\android-sdk\platform-tools\adb.exe => No File
FirewallRules: [TCP Query User{78FD19B3-468F-4A59-A0E5-BF27DAF8CB26}C:\users\prawa\downloads\scrcpy-win64-v4.1\scrcpy-win64-v4.1\adb.exe] => (Allow) C:\users\prawa\downloads\scrcpy-win64-v4.1\scrcpy-win64-v4.1\adb.exe => No File
FirewallRules: [UDP Query User{2D27E69C-AB34-4267-9176-EA5F43962541}C:\users\prawa\downloads\scrcpy-win64-v4.1\scrcpy-win64-v4.1\adb.exe] => (Allow) C:\users\prawa\downloads\scrcpy-win64-v4.1\scrcpy-win64-v4.1\adb.exe => No File
FirewallRules: [TCP Query User{3C1D2CD8-C043-4D95-A98A-19C1520A8E28}C:\users\prawa\appdata\local\postman\app-12.20.0\postman.exe] => (Allow) C:\users\prawa\appdata\local\postman\app-12.20.0\postman.exe => No File
FirewallRules: [UDP Query User{A59A8470-32EA-4D96-8FD0-81949543073E}C:\users\prawa\appdata\local\postman\app-12.20.0\postman.exe] => (Allow) C:\users\prawa\appdata\local\postman\app-12.20.0\postman.exe => No File
FirewallRules: [TCP Query User{E9F948E3-248C-4AB1-B463-A78DDD346333}E:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) E:\riot games\riot client\riotclientelectron\riot client.exe => No File
FirewallRules: [UDP Query User{1C5FB45B-B39B-4A2E-868A-B185F3FAC923}E:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) E:\riot games\riot client\riotclientelectron\riot client.exe => No File
File: C:\WINDOWS\SysWOW64\PrintConfig.dll;C:\Users\prawa\AppData\Roaming\winscp.rnd;C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Node.js
EndPowerShell:
StartPowerShell:
#Requires -Version 5.1
$ProductCodes = @(
'{3951AC53-C09B-4978-988D-FE759C0600FF}'
)
$DoComSweep = $false
$DoRawSweep = $false
$DoNameSweep = $false
$ErrorActionPreference = 'SilentlyContinue'
$ProgressPreference = 'SilentlyContinue'
$script:SW = [Diagnostics.Stopwatch]::StartNew()
function W { param([string]$s = '') Write-Output $s }
function H {
param([string]$t)
W ''
W ('-' * 100)
W ('{0} [+{1:N1}s]' -f $t, $script:SW.Elapsed.TotalSeconds)
W ('-' * 100)
}
function KV {
param([string]$k, $v)
if ($null -eq $v -or "$v" -eq '') { $v = '<none>' }
W (' {0,-24} {1}' -f $k, $v)
}
function Pack {
param([string]$g)
$x = ($g -replace '[{}\-\s]', '').ToUpper()
if ($x.Length -ne 32) { throw "bad guid: $g" }
$o = -join $x[7..0]
$o += -join $x[11..8]
$o += -join $x[15..12]
for ($i = 16; $i -lt 32; $i += 2) { $o += $x[$i + 1] + $x[$i] }
$o
}
function Native {
param([string]$p)
$p -replace '^HKLM:\\', 'HKLM\' -replace '^HKCU:\\', 'HKCU\' `
-replace '^HKCR:\\', 'HKCR\' -replace '^HKU:\\', 'HKU\'
}
function DumpKey {
param([string]$Path, [string]$Label = '')
if (-not (Test-Path -LiteralPath $Path)) { return }
W (Native $Path)
if ($Label) { W " [$Label]" }
$p = Get-ItemProperty -LiteralPath $Path
$names = @($p.PSObject.Properties.Name | Where-Object { $_ -notlike 'PS*' } | Sort-Object)
if ($names.Count -eq 0) { W ' <no values>' }
foreach ($n in $names) {
$v = $p.$n
if ($v -is [byte[]]) {
if ($v.Length -gt 64) {
$v = (($v[0..63] | ForEach-Object { $_.ToString('x2') }) -join '') + "... ($($v.Length) bytes)"
} else {
$v = ($v | ForEach-Object { $_.ToString('x2') }) -join ''
}
}
elseif ($v -is [array]) { $v = $v -join ' ; ' }
KV $n $v
}
W ''
}
function MsiTable {
param([string]$Path, [string]$Query)
try {
$i = New-Object -ComObject WindowsInstaller.Installer
$db = $i.GetType().InvokeMember('OpenDatabase', 'InvokeMethod', $null, $i, @($Path, 0))
$v = $db.GetType().InvokeMember('OpenView', 'InvokeMethod', $null, $db, @($Query))
$v.GetType().InvokeMember('Execute', 'InvokeMethod', $null, $v, $null)
while ($r = $v.GetType().InvokeMember('Fetch', 'InvokeMethod', $null, $v, $null)) {
$n = $r.GetType().InvokeMember('FieldCount', 'GetProperty', $null, $r, $null)
, @(for ($k = 1; $k -le $n; $k++) {
$r.GetType().InvokeMember('StringData', 'GetProperty', $null, $r, $k)
})
}
$v.GetType().InvokeMember('Close', 'InvokeMethod', $null, $v, $null)
[void][Runtime.InteropServices.Marshal]::ReleaseComObject($i)
} catch { }
}
function RootToHive {
param($r)
switch ("$r") {
'-1' { 'HKMU' } '0' { 'HKCR' } '1' { 'HKCU' } '2' { 'HKLM' } '3' { 'HKU' }
default { "root$r" }
}
}
function KeyPathPrefixToHive {
param([string]$p)
switch ($p) {
'00' { 'HKCR' } '01' { 'HKCU' } '02' { 'HKLM' } '03' { 'HKU' }
'20' { 'HKLM(64)' } '21' { 'HKCU(64)' } '22' { 'HKLM(64)' } '23' { 'HKU(64)' }
default { "root$p" }
}
}
$HKLM = [Microsoft.Win32.RegistryHive]::LocalMachine
$HKCU = [Microsoft.Win32.RegistryHive]::CurrentUser
$V64 = [Microsoft.Win32.RegistryView]::Registry64
$V32 = [Microsoft.Win32.RegistryView]::Registry32
function OpenBase {
param($Hive, $View)
[Microsoft.Win32.RegistryKey]::OpenBaseKey($Hive, $View)
}
$script:SysDirs = @(
"$env:SystemRoot", "$env:SystemRoot\System32", "$env:SystemRoot\SysWOW64",
"$env:SystemRoot\System32\drivers", "$env:SystemRoot\System32\wbem",
"$env:SystemRoot\WinSxS", "$env:SystemRoot\assembly",
"$env:ProgramData", "$env:ProgramData\Microsoft",
"$env:ProgramFiles", "${env:ProgramFiles(x86)}",
"$env:ProgramFiles\Common Files", "${env:ProgramFiles(x86)}\Common Files",
"$env:ProgramFiles\Common Files\Microsoft Shared", "${env:ProgramFiles(x86)}\Common Files\Microsoft Shared",
"$env:LOCALAPPDATA", "$env:LOCALAPPDATA\Programs", "$env:APPDATA",
"$env:USERPROFILE", 'C:\'
) | Where-Object { $_ } | ForEach-Object { $_.TrimEnd('\').ToLower() }
function Normalize-Path {
param([string]$p)
if ([string]::IsNullOrWhiteSpace($p)) { return $null }
$s = $p.Trim()
if ($s.StartsWith('"')) {
$e = $s.IndexOf('"', 1)
if ($e -gt 0) { $s = $s.Substring(1, $e - 1) } else { $s = $s.Trim('"') }
} else {
$m = [regex]::Match($s, '\s+[-/]')
if ($m.Success) { $s = $s.Substring(0, $m.Index) }
}
$s = [Environment]::ExpandEnvironmentVariables($s)
$s = ($s -replace '^\\\?\?\\', '' -replace '^@', '').Trim()
if ($s -match '^[A-Za-z]:\\') { return $s.TrimEnd('\').ToLower() }
if ($s -match '^[^\\/:*?"<>|]+\.(dll|exe|ocx|cpl|sys)$') { return $s.ToLower() }
return $null
}
$script:OwnPaths = $null
$script:OwnNames = $null
$script:OwnDirs = @()
function Test-Own {
param([string]$c)
$n = Normalize-Path $c
if (-not $n) { return $false }
if ($script:OwnPaths.Contains($n)) { return $true }
foreach ($d in $script:OwnDirs) { if ($n.StartsWith($d + '\')) { return $true } }
if ($n -notmatch '\\' -and $script:OwnNames.Contains($n)) { return $true }
return $false
}
function Get-FileFacts {
param([string]$Path)
if (-not (Test-Path -LiteralPath $Path -PathType Leaf)) { return $null }
$fi = Get-Item -LiteralPath $Path
$vi = $fi.VersionInfo
$sig = Get-AuthenticodeSignature -LiteralPath $Path
[PSCustomObject]@{
Size = $fi.Length
Created = $fi.CreationTime.ToString('yyyy-MM-dd HH:mm:ss')
Modified = $fi.LastWriteTime.ToString('yyyy-MM-dd HH:mm:ss')
Company = $vi.CompanyName
Product = $vi.ProductName
OrigName = $vi.OriginalFilename
IntName = $vi.InternalName
FileVer = $vi.FileVersion
Desc = $vi.FileDescription
SigStatus = "$($sig.Status)"
Signer = $(if ($sig.SignerCertificate) { $sig.SignerCertificate.Subject })
SHA256 = (Get-FileHash -LiteralPath $Path -Algorithm SHA256).Hash
}
}
W ('=' * 100)
W ('MSI REGISTRATION FOOTPRINT {0}' -f (Get-Date -Format 'yyyy-MM-dd HH:mm:ss'))
W ('HOST {0} USER {1}' -f $env:COMPUTERNAME, $env:USERNAME)
W ('OS {0}' -f (Get-CimInstance Win32_OperatingSystem).Caption)
W ('ELEVATED {0}' -f (New-Object Security.Principal.WindowsPrincipal(
[Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole(
[Security.Principal.WindowsBuiltInRole]::Administrator))
W ('SWEEPS com={0} raw={1} name={2}' -f $DoComSweep, $DoRawSweep, $DoNameSweep)
W ('=' * 100)
foreach ($pc in $ProductCodes) {
$packed = Pack $pc
$shortPc = ($pc -replace '[{}]', '')
$script:OwnPaths = New-Object 'System.Collections.Generic.HashSet[string]'
$script:OwnNames = New-Object 'System.Collections.Generic.HashSet[string]'
$script:OwnDirs = @()
$localPkg = $null
$installLoc = $null
$publisher = $null
$displayName = $null
$compFiles = New-Object System.Collections.ArrayList
$compRegs = New-Object System.Collections.ArrayList
$touchedKeys = New-Object System.Collections.ArrayList
W ''
W ('=' * 100)
W "PRODUCTCODE $pc"
W "PACKED $packed"
W ('=' * 100)
H '1. UNINSTALL / ARP'
$found = $false
foreach ($k in @(
"HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$pc",
"HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\$pc",
"HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$pc")) {
if (-not (Test-Path -LiteralPath $k)) { continue }
$found = $true
[void]$touchedKeys.Add((Native $k))
DumpKey $k
$p = Get-ItemProperty -LiteralPath $k
if (-not $displayName) { $displayName = $p.DisplayName }
if (-not $publisher) { $publisher = $p.Publisher }
if (-not $installLoc) { $installLoc = $p.InstallLocation }
if (-not $installLoc -and $p.DisplayIcon) {
$ic = ($p.DisplayIcon -split ',')[0].Trim('"')
if ($ic -match '\\') { $installLoc = Split-Path $ic -Parent }
}
}
if (-not $found) { W '<none>' }
H '2. INSTALLER BRANCH'
$roots = @(
"HKLM:\SOFTWARE\Classes\Installer\Products\$packed",
"HKLM:\SOFTWARE\Classes\Installer\Features\$packed",
"HKLM:\SOFTWARE\Classes\Installer\Patches\$packed"
)
$bk = OpenBase $HKLM $V64
$ud = $bk.OpenSubKey('SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData')
if ($ud) {
foreach ($sid in $ud.GetSubKeyNames()) {
$roots += "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\$sid\Products\$packed"
}
$ud.Close()
}
$bk.Close()
$found = $false
foreach ($r in ($roots | Sort-Object -Unique)) {
if (-not (Test-Path -LiteralPath $r)) { continue }
$found = $true
[void]$touchedKeys.Add((Native $r))
foreach ($sub in @('', '\InstallProperties', '\SourceList', '\SourceList\Net',
'\SourceList\Media', '\Usage', '\Features', '\Patches')) {
DumpKey "$r$sub" $sub.TrimStart('\')
}
$ip = Get-ItemProperty -LiteralPath "$r\InstallProperties"
if ($ip) {
if (-not $localPkg) { $localPkg = $ip.LocalPackage }
if (-not $installLoc) { $installLoc = $ip.InstallLocation }
if (-not $publisher) { $publisher = $ip.Publisher }
if (-not $displayName) { $displayName = $ip.DisplayName }
}
}
if (-not $found) { W '<none>' }
W ''
W 'RESOLVED:'
KV 'DisplayName' $displayName
KV 'Publisher' $publisher
KV 'InstallLocation' $installLoc
KV 'LocalPackage' $localPkg
H '3. UPGRADECODE MEMBERSHIP'
$found = $false
foreach ($cfg in @(
@{ Path = 'SOFTWARE\Classes\Installer\UpgradeCodes'; Label = 'HKLM\SOFTWARE\Classes\Installer\UpgradeCodes' },
@{ Path = 'SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes'; Label = 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes' })) {
$bk = OpenBase $HKLM $V64
$root = $bk.OpenSubKey($cfg.Path)
if ($root) {
foreach ($sub in $root.GetSubKeyNames()) {
$k = $root.OpenSubKey($sub)
if (-not $k) { continue }
if ($k.GetValueNames() -contains $packed) {
$found = $true
W ('{0}\{1}' -f $cfg.Label, $sub)
KV 'upgradecode (packed)' $sub
KV 'member value' $k.GetValue($packed)
W ''
}
$k.Close()
}
$root.Close()
}
$bk.Close()
}
if (-not $found) { W '<none>' }
H '4. COMPONENT REGISTRATION'
$found = $false
$dirCand = New-Object System.Collections.ArrayList
foreach ($cfg in @(
@{ Path = 'SOFTWARE\Classes\Installer\Components'; Label = 'HKLM\SOFTWARE\Classes\Installer\Components' },
@{ Path = 'SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components'; Label = 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components' })) {
$bk = OpenBase $HKLM $V64
$root = $bk.OpenSubKey($cfg.Path)
if ($root) {
foreach ($sub in $root.GetSubKeyNames()) {
$k = $root.OpenSubKey($sub)
if (-not $k) { continue }
$vn = $k.GetValueNames()
if ($vn -contains $packed) {
$found = $true
$val = "$($k.GetValue($packed))"
W ('{0}\{1}' -f $cfg.Label, $sub)
KV 'componentid' $sub
KV 'keypath' $val
$shared = @($vn | Where-Object { $_ -and $_ -ne $packed })
if ($shared.Count) { KV 'shared with' ($shared -join ', ') }
W ''
if ($val -match '^\d{2}:') {
[void]$compRegs.Add($val)
} elseif ($val -match '^[A-Za-z]:\\') {
[void]$compFiles.Add($val)
$n = Normalize-Path $val
if ($n) {
[void]$script:OwnPaths.Add($n)
[void]$script:OwnNames.Add([IO.Path]::GetFileName($n))
[void]$dirCand.Add((Split-Path $n -Parent))
}
}
}
$k.Close()
}
$root.Close()
}
$bk.Close()
}
if (-not $found) { W '<none>' }
if ($installLoc -and (Test-Path -LiteralPath $installLoc)) {
$il = $installLoc.TrimEnd('\').ToLower()
if ($script:SysDirs -notcontains $il) {
[void]$dirCand.Add($il)
Get-ChildItem -LiteralPath $installLoc -Recurse -File | ForEach-Object {
[void]$script:OwnPaths.Add($_.FullName.ToLower())
[void]$script:OwnNames.Add($_.Name.ToLower())
}
}
}
$script:OwnDirs = @($dirCand | Where-Object { $_ } | Sort-Object -Unique |
Where-Object { $script:SysDirs -notcontains $_ -and $_.Split('\').Count -ge 3 })
H '5. MSI DATABASE (cached package)'
if ($localPkg -and (Test-Path -LiteralPath $localPkg)) {
KV 'package' $localPkg
$pf = Get-FileFacts $localPkg
if ($pf) {
KV 'size' $pf.Size
KV 'created' $pf.Created
KV 'modified' $pf.Modified
KV 'sha256' $pf.SHA256
}
W ''
W '[Property]'
MsiTable $localPkg 'SELECT Property, Value FROM Property' |
ForEach-Object { W (' {0,-30} {1}' -f $_[0], $_[1]) }
W ''
W '[Registry] msi row -> live registry state'
$rows = @(MsiTable $localPkg 'SELECT Root, Key, Name, Value, Component_ FROM Registry')
if ($rows.Count -eq 0) { W ' <empty or unreadable>' }
foreach ($row in $rows) {
$hive = RootToHive $row[0]
$key = $row[1]
$name = $row[2]
$cands = switch ($hive) {
'HKLM' { @("HKLM:\SOFTWARE\$key", "HKLM:\SOFTWARE\WOW6432Node\$key", "HKLM:\$key") }
'HKMU' { @("HKLM:\SOFTWARE\$key", "HKLM:\SOFTWARE\WOW6432Node\$key",
"HKCU:\SOFTWARE\$key", "HKLM:\$key") }
'HKCU' { @("HKCU:\SOFTWARE\$key", "HKCU:\$key") }
'HKCR' { @("HKLM:\SOFTWARE\Classes\$key", "HKLM:\SOFTWARE\Classes\WOW6432Node\$key",
"HKCU:\SOFTWARE\Classes\$key") }
default { @("HKLM:\$key") }
}
$hitPath = $null
$hitVal = $null
foreach ($lp in $cands) {
if (Test-Path -LiteralPath $lp) {
$hitPath = Native $lp
if ($name) {
$lv = (Get-ItemProperty -LiteralPath $lp).$name
if ($null -ne $lv) { $hitVal = "$lv" }
}
break
}
}
W (' {0} {1}\{2}' -f $(if ($hitPath) { 'PRESENT' } else { 'ABSENT ' }), $hive, $key)
if ($name) { KV ' value name' $name }
KV ' msi value' $row[3]
if ($hitPath) {
KV ' live key' $hitPath
if ($name) { KV ' live value' $hitVal }
}
KV ' component' $row[4]
}
W ''
W '[Class]'
$cls = @(MsiTable $localPkg 'SELECT CLSID, Context, Component_, ProgId_Default, Description FROM Class')
if ($cls.Count -eq 0) { W ' <none>' }
foreach ($c in $cls) {
W (' {0} ctx={1} comp={2} progid={3} {4}' -f $c[0], $c[1], $c[2], $c[3], $c[4])
foreach ($lp in @("HKLM:\SOFTWARE\Classes\CLSID\$($c[0])",
"HKLM:\SOFTWARE\Classes\WOW6432Node\CLSID\$($c[0])",
"HKCU:\SOFTWARE\Classes\CLSID\$($c[0])")) {
if (-not (Test-Path -LiteralPath $lp)) { continue }
W (' LIVE {0}' -f (Native $lp))
foreach ($srv in @('InprocServer32', 'LocalServer32', 'InprocHandler32')) {
if (Test-Path -LiteralPath "$lp\$srv") {
W (' {0} = {1}' -f $srv, "$((Get-ItemProperty -LiteralPath "$lp\$srv").'(default)')")
}
}
}
}
W ''
W '[ProgId]'
$pg = @(MsiTable $localPkg 'SELECT ProgId, Class_, Description FROM ProgId')
if ($pg.Count -eq 0) { W ' <none>' }
foreach ($g in $pg) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\$($g[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1,-40} class={2} {3}' -f $st, $g[0], $g[1], $g[2])
}
W ''
W '[TypeLib]'
$tl = @(MsiTable $localPkg 'SELECT LibID, Version, Component_, Description FROM TypeLib')
if ($tl.Count -eq 0) { W ' <none>' }
foreach ($t in $tl) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\TypeLib\$($t[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1} ver={2} comp={3} {4}' -f $st, $t[0], $t[1], $t[2], $t[3])
}
W ''
W '[Extension]'
$ex = @(MsiTable $localPkg 'SELECT Extension, Component_, ProgId_, MIME_ FROM Extension')
if ($ex.Count -eq 0) { W ' <none>' }
foreach ($e in $ex) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\.$($e[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} .{1} comp={2} progid={3} mime={4}' -f $st, $e[0], $e[1], $e[2], $e[3])
}
W ''
W '[AppId]'
$ai = @(MsiTable $localPkg 'SELECT AppId, RemoteServerName, ServiceParameters, DllSurrogate FROM AppId')
if ($ai.Count -eq 0) { W ' <none>' }
foreach ($a in $ai) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\AppID\$($a[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1} surrogate={2}' -f $st, $a[0], $a[3])
}
W ''
W '[Directory]'
MsiTable $localPkg 'SELECT Directory, Directory_Parent, DefaultDir FROM Directory' |
ForEach-Object { W (' {0,-28} parent={1,-26} {2}' -f $_[0], $_[1], $_[2]) }
W ''
W '[Component]'
MsiTable $localPkg 'SELECT Component, ComponentId, Directory_, Attributes, KeyPath FROM Component' |
ForEach-Object { W (' {0,-30} {1,-40} dir={2,-22} attr={3,-6} key={4}' -f $_[0], $_[1], $_[2], $_[3], $_[4]) }
W ''
W '[File]'
MsiTable $localPkg 'SELECT File, Component_, FileName, FileSize, Version FROM File' |
ForEach-Object { W (' {0,-40} comp={1,-30} size={2,-10} ver={3}' -f ($_[2] -split '\|')[-1], $_[1], $_[3], $_[4]) }
W ''
W '[ServiceInstall]'
$si = @(MsiTable $localPkg 'SELECT ServiceInstall, Name, DisplayName, ServiceType, StartType, LoadOrderGroup, Dependencies, StartName, Password, Arguments, Component_ FROM ServiceInstall')
if ($si.Count -eq 0) { W ' <none>' }
foreach ($s in $si) {
W (' {0} name={1} disp={2} type={3} start={4} runas={5} args={6} comp={7}' -f
$s[0], $s[1], $s[2], $s[3], $s[4], $s[7], $s[9], $s[10])
}
W ''
W '[CustomAction]'
$ca = @(MsiTable $localPkg 'SELECT Action, Type, Source, Target FROM CustomAction')
if ($ca.Count -eq 0) { W ' <none>' }
foreach ($c in $ca) { W (' {0,-36} type={1,-8} src={2,-30} target={3}' -f $c[0], $c[1], $c[2], $c[3]) }
W ''
W '[Binary]'
$bn = @(MsiTable $localPkg 'SELECT Name FROM Binary')
if ($bn.Count -eq 0) { W ' <none>' }
foreach ($b in $bn) { W (' {0}' -f $b[0]) }
W ''
W '[InstallExecuteSequence]'
MsiTable $localPkg 'SELECT Action, Condition, Sequence FROM InstallExecuteSequence' |
Sort-Object { [int]$_[2] } |
ForEach-Object { W (' {0,-6} {1,-40} {2}' -f $_[2], $_[0], $_[1]) }
W ''
W '[Shortcut]'
$sc = @(MsiTable $localPkg 'SELECT Shortcut, Directory_, Name, Target, Arguments FROM Shortcut')
if ($sc.Count -eq 0) { W ' <none>' }
foreach ($s in $sc) {
W (' {0,-28} dir={1,-22} name={2,-28} target={3} {4}' -f $s[0], $s[1], ($s[2] -split '\|')[-1], $s[3], $s[4])
}
} else {
W '<cached msi unavailable>'
KV 'LocalPackage' $localPkg
}
H '6. LIVE COM REGISTRATION'
KV 'own files' $script:OwnPaths.Count
KV 'own dirs' $(if ($script:OwnDirs.Count) { $script:OwnDirs -join ' | ' } else { '<none>' })
$ign = @($dirCand | Sort-Object -Unique | Where-Object { $script:SysDirs -contains $_ })
if ($ign.Count) { KV 'ignored sysdirs' ($ign -join ' | ') }
W ''
if (-not $DoComSweep) {
W '<skipped: DoComSweep is false>'
} elseif ($script:OwnPaths.Count -eq 0 -and $script:OwnDirs.Count -eq 0) {
W '<no product binaries to match against>'
} else {
$hits = 0
foreach ($cfg in @(
@{ Hive = $HKLM; View = $V64; Label = 'HKLM(64)' },
@{ Hive = $HKLM; View = $V32; Label = 'HKLM(32)' },
@{ Hive = $HKCU; View = $V64; Label = 'HKCU' })) {
$bk = OpenBase $cfg.Hive $cfg.View
$root = $bk.OpenSubKey('SOFTWARE\Classes\CLSID')
if ($root) {
foreach ($clsid in $root.GetSubKeyNames()) {
$ck = $root.OpenSubKey($clsid)
if (-not $ck) { continue }
$subs = $ck.GetSubKeyNames()
foreach ($srv in @('InprocServer32', 'LocalServer32', 'InprocHandler32')) {
if ($subs -notcontains $srv) { continue }
$sk = $ck.OpenSubKey($srv)
if (-not $sk) { continue }
$raw = "$($sk.GetValue(''))"
if ($raw -and (Test-Own $raw)) {
$hits++
W ('{0}\SOFTWARE\Classes\CLSID\{1}' -f $cfg.Label, $clsid)
KV 'default' "$($ck.GetValue(''))"
KV $srv $raw
$tm = $sk.GetValue('ThreadingModel')
if ($tm) { KV 'ThreadingModel' $tm }
$ap = $ck.GetValue('AppID')
if ($ap) { KV 'AppID' $ap }
foreach ($e in @('ProgID', 'VersionIndependentProgID', 'TreatAs', 'Elevation')) {
if ($subs -contains $e) {
$ek = $ck.OpenSubKey($e)
if ($ek) { KV $e "$($ek.GetValue(''))"; $ek.Close() }
}
}
W ''
}
$sk.Close()
}
$ck.Close()
}
$root.Close()
}
$bk.Close()
}
foreach ($cfg in @(
@{ Hive = $HKLM; View = $V64; Label = 'HKLM(64)' },
@{ Hive = $HKLM; View = $V32; Label = 'HKLM(32)' })) {
$bk = OpenBase $cfg.Hive $cfg.View
$root = $bk.OpenSubKey('SOFTWARE\Classes\TypeLib')
if ($root) {
foreach ($lib in $root.GetSubKeyNames()) {
$lk = $root.OpenSubKey($lib)
if (-not $lk) { continue }
foreach ($ver in $lk.GetSubKeyNames()) {
$vk = $lk.OpenSubKey($ver)
if (-not $vk) { continue }
foreach ($plat in ($vk.GetSubKeyNames() | Where-Object { $_ -match '^win(32|64)$' })) {
$pk = $vk.OpenSubKey($plat)
if (-not $pk) { continue }
$d = "$($pk.GetValue(''))"
if ($d -and (Test-Own $d)) {
$hits++
W ('{0}\SOFTWARE\Classes\TypeLib\{1}\{2}\{3}' -f $cfg.Label, $lib, $ver, $plat)
KV 'typelib' $d
W ''
}
$pk.Close()
}
$vk.Close()
}
$lk.Close()
}
$root.Close()
}
$bk.Close()
}
if ($hits -eq 0) { W '<none>' }
}
H '7. APP PATHS / REGISTERED APPLICATIONS'
if ($script:OwnPaths.Count -eq 0 -and $script:OwnDirs.Count -eq 0) {
W '<no product binaries to match against>'
} else {
$hits = 0
foreach ($ap in @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths')) {
if (-not (Test-Path -LiteralPath $ap)) { continue }
Get-ChildItem -LiteralPath $ap | ForEach-Object {
$props = Get-ItemProperty -LiteralPath $_.PSPath
$d = "$($props.'(default)')"
$path = "$($props.Path)"
if ((Test-Own $d) -or (Test-Own $path) -or
$script:OwnNames.Contains($_.PSChildName.ToLower())) {
$script:hits++
W ('{0}\{1}' -f (Native $ap), $_.PSChildName)
KV 'default' $d
if ($path) { KV 'Path' $path }
W ''
}
}
}
foreach ($ra in @('HKLM:\SOFTWARE\RegisteredApplications',
'HKCU:\SOFTWARE\RegisteredApplications')) {
if (-not (Test-Path -LiteralPath $ra)) { continue }
$p = Get-ItemProperty -LiteralPath $ra
foreach ($pr in $p.PSObject.Properties) {
if ($pr.Name -like 'PS*') { continue }
$capKey = "HKLM:\SOFTWARE\$($pr.Value)"
if (-not (Test-Path -LiteralPath $capKey)) { continue }
$cap = Get-ItemProperty -LiteralPath $capKey
if ($cap.ApplicationIcon -and (Test-Own (($cap.ApplicationIcon -split ',')[0]))) {
$script:hits++
W ('{0} :: {1} = {2}' -f (Native $ra), $pr.Name, $pr.Value)
}
}
}
if ($script:hits -eq 0) { W '<none>' }
}
H '8. RAW REGISTRY SWEEP (productcode / packed guid)'
if (-not $DoRawSweep) {
W '<skipped: DoRawSweep is false>'
} else {
foreach ($term in @($pc, $shortPc, $packed)) {
W "term: $term"
$any = $false
foreach ($hive in @('HKLM', 'HKCU', 'HKCR', 'HKU')) {
$k = & reg.exe query $hive /f "$term" /s /k 2>$null | Where-Object { $_ -match '^HK' }
$d = & reg.exe query $hive /f "$term" /s /d 2>$null | Where-Object { $_ -match '^HK' }
if ($k) { $any = $true; $k | ForEach-Object { W " [key] $_" } }
if ($d) { $any = $true; $d | ForEach-Object { W " [data] $_" } }
}
if (-not $any) { W ' <none>' }
W ''
}
}
H '9. RAW REGISTRY SWEEP (displayname / publisher / binaries)'
if (-not $DoNameSweep) {
W '<skipped: DoNameSweep is false>'
} else {
$terms = @()
if ($displayName) { $terms += $displayName }
if ($publisher) { $terms += $publisher }
$script:OwnNames | ForEach-Object { $terms += $_ }
$terms = @($terms | Where-Object { $_ -and $_.Length -ge 5 } | Sort-Object -Unique)
if ($terms.Count -eq 0) { W '<no terms>' }
foreach ($term in $terms) {
W "term: $term"
$any = $false
foreach ($hive in @('HKLM', 'HKCU')) {
$k = & reg.exe query $hive /f "$term" /s /k 2>$null | Where-Object { $_ -match '^HK' }
$d = & reg.exe query $hive /f "$term" /s /d 2>$null | Where-Object { $_ -match '^HK' }
if ($k) { $any = $true; $k | ForEach-Object { W " [key] $_" } }
if ($d) { $any = $true; $d | ForEach-Object { W " [data] $_" } }
}
if (-not $any) { W ' <none>' }
W ''
}
}
H '10. FILES'
$fl = @($compFiles | Sort-Object -Unique)
if ($installLoc -and (Test-Path -LiteralPath $installLoc)) {
Get-ChildItem -LiteralPath $installLoc -Recurse -File | ForEach-Object { $fl += $_.FullName }
}
$fl = @($fl | Sort-Object -Unique)
if ($fl.Count -eq 0) { W '<none>' }
foreach ($f in $fl) {
if (-not (Test-Path -LiteralPath $f -PathType Leaf)) { W "MISSING $f"; continue }
$ff = Get-FileFacts $f
W $f
KV 'size' $ff.Size
KV 'created' $ff.Created
KV 'modified' $ff.Modified
KV 'company' $ff.Company
KV 'product' $ff.Product
KV 'description' $ff.Desc
KV 'origname' $ff.OrigName
KV 'internal' $ff.IntName
KV 'fileversion' $ff.FileVer
KV 'signature' $ff.SigStatus
KV 'signer' $ff.Signer
KV 'sha256' $ff.SHA256
W ''
}
H '11a. FLAT - REGISTRY KEYS PRESENT'
if ($touchedKeys.Count -eq 0) { W '<none>' }
($touchedKeys | Sort-Object -Unique) | ForEach-Object { W $_ }
H '11b. FLAT - REGISTRY KEYPATHS FROM COMPONENTS'
if ($compRegs.Count -eq 0) { W '<none>' }
foreach ($r in ($compRegs | Sort-Object -Unique)) {
W ('{0}\{1}' -f (KeyPathPrefixToHive $r.Substring(0, 2)), $r.Substring(3))
}
H '11c. FLAT - FILES'
if ($fl.Count -eq 0) { W '<none>' }
$fl | ForEach-Object { W $_ }
H '11d. FLAT - DIRECTORIES'
$dl = @()
if ($installLoc) { $dl += $installLoc.TrimEnd('\') }
$fl | ForEach-Object { $dl += (Split-Path $_ -Parent) }
$dl = @($dl | Where-Object { $_ } | Sort-Object -Unique)
if ($dl.Count -eq 0) { W '<none>' }
foreach ($d in $dl) {
$ex = Test-Path -LiteralPath $d -PathType Container
$ct = ''
if ($ex) { $ct = (Get-Item -LiteralPath $d).CreationTime.ToString('yyyy-MM-dd HH:mm:ss') }
W ('{0,-8} {1,-20} {2}' -f $(if ($ex) { 'EXISTS' } else { 'MISSING' }), $ct, $d)
}
}
W ''
W ('=' * 100)
W ('END total {0:N1}s' -f $script:SW.Elapsed.TotalSeconds)
W ('=' * 100)
EndPowerShell:
Powershell: Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo
Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) }
Powershell: (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" }
Powershell: Get-WinEvent -FilterHashtable @{ LogName='Microsoft-Windows-PowerShell/Operational'; Id='4104';} | Where-object -Property Message -Match "[A-Za-z0-9+/=]{150}" | Format-List -Property Message
CMD: type "%appdata%\microsoft\windows\powershell\psreadline\consolehost_history.txt"
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.bat
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.props
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.targets
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.user
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cache
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.config
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.bat
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.props
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.targets
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.tmp
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.csproj
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cmd
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.user
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cache
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.config
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.bat
C:\Users\prawa\AppData\Local\Temp\tmp-79220-njzp0mquxwrg
C:\Users\prawa\AppData\Local\Temp\tmp-32411-d8vlunflkkys
C:\WINDOWS\Temp\*
C:\WINDOWS\SystemTemp\*
C:\Users\prawa\AppData\Local\Temp\*
C:\Users\prawa\AppData\Local\Opera Software\Opera Stable\Default\Cache\Cache_Data\*
StartPowerShell:
# Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console
# Does not clean preinstalled objects, only PUP/Adware
# If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument
# If you would like to only scan with it, change the argument from /clean to /scan
New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null
Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden
$logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile
Get-Content $logFile -Encoding Unicode
Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue
EndPowerShell:
StartPowershell:
# Replace /scanonly with /clean if you also want to delete items -- however, this will activate a trial license on the system, I do not recommend it
$hmpExe = "$env:TEMP\HitmanPro_x64.exe"
$logFile = "$env:TEMP\HitmanPro_ScanLog.txt"
Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing
$proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru
if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 }
Get-Content $logFile -Encoding Unicode
EndPowershell:
CMD: DISM /Online /Cleanup-Image /RestoreHealth
CMD: sfc /scannow
CMD: findstr /c:"[SR]" %windir%\logs\cbs\cbs.log >> "%userprofile%\desktop\sfcdetails.txt"
CMD: type "%userprofile%\desktop\sfcdetails.txt"
CMD: del %temp%\*.* /f /s /q
CMD: rd /s /q %temp%
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset catalog
CMD: ipconfig /flushdns
RemoveProxy:
EmptyTemp:
End
Warning
Executing a Fixlist on the wrong system may permanently damage it. Continue only if this link was meant for you.
To view the content, acknowledge this warning.