content copied
content
Start::
CreateRestorePoint:
CloseProcesses:
CustomCLSID: HKU\S-1-5-21-1070632220-2695763294-3121136582-1001_Classes\CLSID\{4e6f7264-5650-4e00-0000-000000000000}\localserver32 -> "C:\Program Files\NordVPN\NordVPN.exe" -ToastActivated => No File
ShellIconOverlayIdentifiers: [ .WorkspaceExt0] -> {C568C78A-652C-425B-8E6B-FFA73043302D} => -> No File
ShellIconOverlayIdentifiers: [ .WorkspaceExt1] -> {2A6FE247-5DA3-4732-9626-77820518FD77} => -> No File
ShellIconOverlayIdentifiers: [ .WorkspaceExt2] -> {FF895810-293B-464A-93F2-82D11E07EEC8} => -> No File
AlternateDataStreams: C:\WINDOWS\tracing:? [16]
AlternateDataStreams: C:\ProgramData\mntemp:8EAD8B3507 [3442]
AlternateDataStreams: C:\ProgramData\system.conf:0F57F3FDE6 [3442]
AlternateDataStreams: C:\ProgramData\system.conf:422D4106AB [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk:075A04AA92 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2022.lnk:638138415C [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk:BE32D07BC5 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publish or Perish 8.lnk:FE1FDDE9FE [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zotero.lnk:3FAA705B12 [3442]
AlternateDataStreams: C:\Users\Public\Documents\rsEngine.config.backup:AC0747FD1A [3442]
AlternateDataStreams: C:\Users\Rifky Fauzan\Desktop\FRST64.exe:MBAM.Zone.Identifier [450]
FirewallRules: [{5CF33C7C-9C4B-4D88-91F8-B9B0A32A15E9}] => (Allow) C:\Program Files\ASUS\ARMOURY CRATE Service\MobilePlugin\AutoConnectHelper.exe => No File
FirewallRules: [UDP Query User{3F1AE855-F431-4393-8E46-C49729F4D476}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\2.50.00.10\webview2runtime\msedgewebview2.exe] => (Allow) C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\2.50.00.10\webview2runtime\msedgewebview2.exe => No File
FirewallRules: [TCP Query User{54DB7925-A4EC-45F0-8632-A945A8B723D9}C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\2.50.00.10\webview2runtime\msedgewebview2.exe] => (Allow) C:\programdata\sony interactive entertainment inc\pspc_sdk\s22\2.50.00.10\webview2runtime\msedgewebview2.exe => No File
FirewallRules: [UDP Query User{ECD5E675-829F-413D-B27D-12C933B05D4D}D:\game steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\game steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File
FirewallRules: [TCP Query User{889B115C-E55E-4B50-9822-4BB7D30F1026}D:\game steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\game steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File
FirewallRules: [UDP Query User{940F5700-1D2B-4589-8175-3AACD46FB157}C:\program files (x86)\folder baru\steam\steamapps\common\marvelrivals\marvelgame\marvel\binaries\win64\marvel-win64-shipping.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\marvelrivals\marvelgame\marvel\binaries\win64\marvel-win64-shipping.exe => No File
FirewallRules: [TCP Query User{BD6E96E4-3217-43D5-99F2-3F8131DDD58D}C:\program files (x86)\folder baru\steam\steamapps\common\marvelrivals\marvelgame\marvel\binaries\win64\marvel-win64-shipping.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\marvelrivals\marvelgame\marvel\binaries\win64\marvel-win64-shipping.exe => No File
FirewallRules: [UDP Query User{445BE85C-A77E-4391-BA35-EF7307F6F525}C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\ccmini\ccmini_new\ccmini.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\ccmini\ccmini_new\ccmini.exe => No File
FirewallRules: [TCP Query User{4161C662-A62A-4EDE-97B1-790EB99A8005}C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\ccmini\ccmini_new\ccmini.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\ccmini\ccmini_new\ccmini.exe => No File
FirewallRules: [{4340252b-18ee-4443-aac6-778ad3ab8082}] => (Allow) D:\LDPlayer\LDPlayer9\dnplayer.exe => No File
FirewallRules: [UDP Query User{F708FF28-B402-412E-8EE3-919C17B487B0}D:\game xbox\world war z\content\wwzretail.exe] => (Allow) D:\game xbox\world war z\content\wwzretail.exe => No File
FirewallRules: [TCP Query User{B5ECDF31-3AE5-4F07-AB40-AAE4317FFA04}D:\game xbox\world war z\content\wwzretail.exe] => (Allow) D:\game xbox\world war z\content\wwzretail.exe => No File
FirewallRules: [UDP Query User{1146AD65-D285-4F24-85C5-60CFDEEEC157}D:\game bajakan\pico park\pico_park.exe] => (Allow) D:\game bajakan\pico park\pico_park.exe => No File
FirewallRules: [TCP Query User{26119B60-B9DF-4B8B-B061-28A13D9FC32C}D:\game bajakan\pico park\pico_park.exe] => (Allow) D:\game bajakan\pico park\pico_park.exe => No File
FirewallRules: [UDP Query User{4C0D1EFE-ECB2-470E-BB08-20647E333E2E}D:\game epic\redout2\redout2\binaries\win64\redout2-win64-shipping.exe] => (Allow) D:\game epic\redout2\redout2\binaries\win64\redout2-win64-shipping.exe => No File
FirewallRules: [TCP Query User{990B1525-3467-4319-9723-7B1506B39F08}D:\game epic\redout2\redout2\binaries\win64\redout2-win64-shipping.exe] => (Allow) D:\game epic\redout2\redout2\binaries\win64\redout2-win64-shipping.exe => No File
FirewallRules: [UDP Query User{C921B8B4-4356-4CCB-8D7B-355F2C1B480A}C:\users\rifky fauzan\appdata\local\discord\app-1.0.9147\discord.exe] => (Allow) C:\users\rifky fauzan\appdata\local\discord\app-1.0.9147\discord.exe => No File
FirewallRules: [TCP Query User{C41EE502-8670-4561-9C53-44652E48BD67}C:\users\rifky fauzan\appdata\local\discord\app-1.0.9147\discord.exe] => (Allow) C:\users\rifky fauzan\appdata\local\discord\app-1.0.9147\discord.exe => No File
FirewallRules: [UDP Query User{1FD0FB0B-21D5-4A55-B66F-DF1753779758}D:\wuthering waves\wuthering waves game\client\binaries\win64\client-win64-shipping.exe] => (Allow) D:\wuthering waves\wuthering waves game\client\binaries\win64\client-win64-shipping.exe => No File
FirewallRules: [TCP Query User{39738E79-3815-4DF5-A7A6-DF2C78482272}D:\wuthering waves\wuthering waves game\client\binaries\win64\client-win64-shipping.exe] => (Allow) D:\wuthering waves\wuthering waves game\client\binaries\win64\client-win64-shipping.exe => No File
FirewallRules: [UDP Query User{99B9877D-C885-438A-8893-B803A9D91117}D:\game bajakan\pummel party\pummelparty.exe] => (Allow) D:\game bajakan\pummel party\pummelparty.exe => No File
FirewallRules: [TCP Query User{36AF805F-5FED-431F-9361-8EC964630665}D:\game bajakan\pummel party\pummelparty.exe] => (Allow) D:\game bajakan\pummel party\pummelparty.exe => No File
FirewallRules: [{B5414662-D5A3-4954-B21C-E116DB2217AB}] => (Allow) C:\Program Files (x86)\360\Total Security\360TsLiveUpd.exe => No File
FirewallRules: [{C21D619A-75EF-4BF8-87D3-6B2C9FDB9CDD}] => (Allow) C:\Program Files (x86)\360\Total Security\360TsLiveUpd.exe => No File
FirewallRules: [{3D0645C8-15F1-49B0-9651-2594E26DF931}] => (Allow) C:\Users\Rifky Fauzan\AppData\Roaming\BitTorrent\BitTorrent.exe => No File
FirewallRules: [{E71B8812-A841-4143-A80A-DD5B58B1B223}] => (Allow) C:\Users\Rifky Fauzan\AppData\Roaming\BitTorrent\BitTorrent.exe => No File
FirewallRules: [UDP Query User{88197C24-CC8E-418F-A522-43E43D48183E}D:\game bajakan\ready or not\readyornot\binaries\win64\readyornot-win64-shipping.exe] => (Allow) D:\game bajakan\ready or not\readyornot\binaries\win64\readyornot-win64-shipping.exe => No File
FirewallRules: [TCP Query User{410D2F41-FEF6-4B89-A64B-98FC7471774A}D:\game bajakan\ready or not\readyornot\binaries\win64\readyornot-win64-shipping.exe] => (Allow) D:\game bajakan\ready or not\readyornot\binaries\win64\readyornot-win64-shipping.exe => No File
FirewallRules: [UDP Query User{626DC06D-4AAC-445A-82FC-B7F40315017F}D:\game epic\rocketleague\binaries\win64\rocketleague.exe] => (Allow) D:\game epic\rocketleague\binaries\win64\rocketleague.exe => No File
FirewallRules: [TCP Query User{4D2A4A34-47E0-48E8-9E33-4EE988F21E26}D:\game epic\rocketleague\binaries\win64\rocketleague.exe] => (Allow) D:\game epic\rocketleague\binaries\win64\rocketleague.exe => No File
FirewallRules: [UDP Query User{7E97962A-FB3C-4DB2-864D-87B74E111E80}D:\game steam\steamapps\common\need for speed heat\needforspeedheat.exe] => (Allow) D:\game steam\steamapps\common\need for speed heat\needforspeedheat.exe => No File
FirewallRules: [TCP Query User{BB2E0DDD-C3E3-44B3-B664-FF3AC0CFDC63}D:\game steam\steamapps\common\need for speed heat\needforspeedheat.exe] => (Allow) D:\game steam\steamapps\common\need for speed heat\needforspeedheat.exe => No File
FirewallRules: [UDP Query User{FE29DF77-8771-4331-8A22-BEB70E764B84}C:\users\rifky fauzan\appdata\local\programs\rave-desktop\rave.exe] => (Allow) C:\users\rifky fauzan\appdata\local\programs\rave-desktop\rave.exe => No File
FirewallRules: [TCP Query User{BF4C7075-556A-4D64-99C8-33B829AADF81}C:\users\rifky fauzan\appdata\local\programs\rave-desktop\rave.exe] => (Allow) C:\users\rifky fauzan\appdata\local\programs\rave-desktop\rave.exe => No File
FirewallRules: [UDP Query User{6FAAD2D4-37D1-413C-9FE5-3F2654BD45AC}D:\game steam\steamapps\common\kartrider drift\kartdrift\binaries\win64\kartdrift-win64-shipping.exe] => (Allow) D:\game steam\steamapps\common\kartrider drift\kartdrift\binaries\win64\kartdrift-win64-shipping.exe => No File
FirewallRules: [TCP Query User{44E7FC2B-2F57-48B4-AAD8-B23F9BB521EC}D:\game steam\steamapps\common\kartrider drift\kartdrift\binaries\win64\kartdrift-win64-shipping.exe] => (Allow) D:\game steam\steamapps\common\kartrider drift\kartdrift\binaries\win64\kartdrift-win64-shipping.exe => No File
FirewallRules: [{8D1AB8AB-102F-4B9D-8091-B79D8C8D15E6}] => (Allow) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_4fc38a913e0f2ea5\ASUSLinkRemote\AsusLinkRemoteAgent.exe => No File
FirewallRules: [{C91839F8-8D29-4F1C-9EFF-AD5E55060390}] => (Allow) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_4fc38a913e0f2ea5\ASUSLinkRemote\AsusLinkRemoteAgent.exe => No File
FirewallRules: [{94B62FEA-6C8B-4B2A-8F36-BF2EC591A365}] => (Allow) D:\game steam\steamapps\common\raceroom racing experience\Game\RRRE.exe => No File
FirewallRules: [{776984E7-DE94-4ADB-ACBA-7ED9A4642898}] => (Allow) D:\game steam\steamapps\common\raceroom racing experience\Game\RRRE.exe => No File
FirewallRules: [{2BE24D4F-809B-49B2-A759-9BF51C53105B}] => (Allow) D:\game steam\steamapps\common\raceroom racing experience\Game\x64\RRRE64.exe => No File
FirewallRules: [{621D9A06-EBB6-486A-AA16-21AE26F297E2}] => (Allow) D:\game steam\steamapps\common\raceroom racing experience\Game\x64\RRRE64.exe => No File
FirewallRules: [UDP Query User{BD34AC60-1749-43C2-B690-7C59FAFBAB14}D:\game steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe] => (Allow) D:\game steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe => No File
FirewallRules: [TCP Query User{B8B0C420-6920-4196-84B1-E1020D1D4457}D:\game steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe] => (Allow) D:\game steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe => No File
FirewallRules: [UDP Query User{87D98ED1-43DE-4580-8130-2B95BCB56F82}D:\game steam\steamapps\common\battlefield 2042\bf2042.exe] => (Allow) D:\game steam\steamapps\common\battlefield 2042\bf2042.exe => No File
FirewallRules: [TCP Query User{EFA8158F-4A93-4C08-BF6B-CF9C722FFEC5}D:\game steam\steamapps\common\battlefield 2042\bf2042.exe] => (Allow) D:\game steam\steamapps\common\battlefield 2042\bf2042.exe => No File
FirewallRules: [UDP Query User{8DEC17F0-3A48-454E-AC39-05F4709B86BB}C:\program files (x86)\overwatch\_retail_\overwatch.exe] => (Allow) C:\program files (x86)\overwatch\_retail_\overwatch.exe => No File
FirewallRules: [TCP Query User{2E9B09AD-8FC2-4CFE-8A98-3C9F7B59CAF7}C:\program files (x86)\overwatch\_retail_\overwatch.exe] => (Allow) C:\program files (x86)\overwatch\_retail_\overwatch.exe => No File
FirewallRules: [UDP Query User{345B0E6E-E1A8-44AD-9C39-AFEA3BAD41DE}C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\narakabladepoint.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\narakabladepoint.exe => No File
FirewallRules: [TCP Query User{97E57F5A-15B3-47C5-B693-CD0AC4EBE56C}C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\narakabladepoint.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\naraka bladepoint\narakabladepoint.exe => No File
FirewallRules: [UDP Query User{0ED77822-E4B7-4ABE-8B36-FD0B9790F321}C:\program files (x86)\folder baru\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File
FirewallRules: [TCP Query User{E6170B60-61F0-4864-AB72-1D1CB050D8F7}C:\program files (x86)\folder baru\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe => No File
FirewallRules: [UDP Query User{0C7F6D07-06B8-4F05-AFF9-B1BB19BBB6A5}C:\program files (x86)\folder baru\steam\steamapps\common\need for speed heat\needforspeedheat.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\need for speed heat\needforspeedheat.exe => No File
FirewallRules: [TCP Query User{250D9F0B-445A-4902-8654-BD7E6F41E487}C:\program files (x86)\folder baru\steam\steamapps\common\need for speed heat\needforspeedheat.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\need for speed heat\needforspeedheat.exe => No File
FirewallRules: [{1ECBA98F-43B7-4890-85C7-697DFCB09FE6}] => (Allow) C:\Program Files (x86)\Folder Baru\steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe => No File
FirewallRules: [{52CCB2CB-C7D5-4547-9009-62F4FD0CBEBE}] => (Allow) C:\Program Files (x86)\Folder Baru\steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe => No File
FirewallRules: [{6847C997-DCEF-4F31-97F7-5006D219F0FD}] => (Allow) C:\Program Files (x86)\Folder Baru\steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{AD2BB4F5-0753-4045-BF7F-20AC9C271675}] => (Allow) C:\Program Files (x86)\Folder Baru\steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{900047A5-CE77-4071-A0DF-557AD30496FC}] => (Allow) D:\steam\Steam.exe => No File
FirewallRules: [{829F5EAB-D7F2-4796-A662-4A3A6F32598F}] => (Allow) D:\steam\Steam.exe => No File
FirewallRules: [TCP Query User{B585681C-6783-4E4A-86A2-94ADF50CAF94}D:\game epic\worldwarz\en_us\client\bin\pc\wwzretailegs.exe] => (Allow) D:\game epic\worldwarz\en_us\client\bin\pc\wwzretailegs.exe => No File
FirewallRules: [UDP Query User{F47817C2-4368-499A-B835-3A82D6EB5990}D:\game epic\worldwarz\en_us\client\bin\pc\wwzretailegs.exe] => (Allow) D:\game epic\worldwarz\en_us\client\bin\pc\wwzretailegs.exe => No File
FirewallRules: [TCP Query User{C9929816-2B4D-46A4-B8A2-E6301C496E1F}D:\game steam\steamapps\common\fragpunk\fragpunk\binaries\win64\fragpunk.exe] => (Allow) D:\game steam\steamapps\common\fragpunk\fragpunk\binaries\win64\fragpunk.exe => No File
FirewallRules: [UDP Query User{604B8C5F-33A4-4756-8F79-88DDF41542C8}D:\game steam\steamapps\common\fragpunk\fragpunk\binaries\win64\fragpunk.exe] => (Allow) D:\game steam\steamapps\common\fragpunk\fragpunk\binaries\win64\fragpunk.exe => No File
FirewallRules: [TCP Query User{01A9F218-9FDC-45EB-8C31-C7D4142BE35F}D:\game bajakan\headbangers rhythm royale\headbangers.exe] => (Allow) D:\game bajakan\headbangers rhythm royale\headbangers.exe => No File
FirewallRules: [UDP Query User{40F84DBA-074E-42F2-90C4-6E07A06B1B84}D:\game bajakan\headbangers rhythm royale\headbangers.exe] => (Allow) D:\game bajakan\headbangers rhythm royale\headbangers.exe => No File
FirewallRules: [TCP Query User{52EBB557-329A-47B5-A50B-65B89FEE3918}D:\game bajakan\headbangers rhythm royale\unitycrashhandler64.exe] => (Allow) D:\game bajakan\headbangers rhythm royale\unitycrashhandler64.exe => No File
FirewallRules: [UDP Query User{292983ED-A345-4207-973A-BD88BF8AF565}D:\game bajakan\headbangers rhythm royale\unitycrashhandler64.exe] => (Allow) D:\game bajakan\headbangers rhythm royale\unitycrashhandler64.exe => No File
FirewallRules: [TCP Query User{00D44F79-0457-467D-BFF8-546CF6BC891F}C:\program files (x86)\folder baru\steam\steamapps\common\bloodstrike\engine\binaries\win64\bloodstrike.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\bloodstrike\engine\binaries\win64\bloodstrike.exe => No File
FirewallRules: [UDP Query User{06316466-8B3A-4DAA-A14E-13B93241CE1B}C:\program files (x86)\folder baru\steam\steamapps\common\bloodstrike\engine\binaries\win64\bloodstrike.exe] => (Allow) C:\program files (x86)\folder baru\steam\steamapps\common\bloodstrike\engine\binaries\win64\bloodstrike.exe => No File
FirewallRules: [TCP Query User{41F7DACC-8BAB-4338-9730-A8F819DDDEC9}D:\punishing gray raven\punishing gray raven game\pgr.exe] => (Allow) D:\punishing gray raven\punishing gray raven game\pgr.exe => No File
FirewallRules: [UDP Query User{AD8B4EF1-8880-40EA-9EF1-087A5D338011}D:\punishing gray raven\punishing gray raven game\pgr.exe] => (Allow) D:\punishing gray raven\punishing gray raven game\pgr.exe => No File
FirewallRules: [TCP Query User{87BB3253-A08D-4463-9014-353C13E905F2}D:\coaglobalgame\seria\binaries\win64\seria.exe] => (Allow) D:\coaglobalgame\seria\binaries\win64\seria.exe => No File
FirewallRules: [UDP Query User{2EA04480-34E7-46CF-8297-36BD2DB4B423}D:\coaglobalgame\seria\binaries\win64\seria.exe] => (Allow) D:\coaglobalgame\seria\binaries\win64\seria.exe => No File
FirewallRules: [TCP Query User{54555CA6-3F16-4A1B-9C49-A4E722F84AAB}D:\game bajakan\make way\make way.exe] => (Allow) D:\game bajakan\make way\make way.exe => No File
FirewallRules: [UDP Query User{85702DDE-C4D0-43F8-B672-240AE3BC69B8}D:\game bajakan\make way\make way.exe] => (Allow) D:\game bajakan\make way\make way.exe => No File
FirewallRules: [TCP Query User{D854AF06-0BDD-4048-8164-DF4DEA152CB2}D:\game bajakan\rematch\runtime\binaries\wingdk\runtimeclient-wingdk-shipping.exe] => (Allow) D:\game bajakan\rematch\runtime\binaries\wingdk\runtimeclient-wingdk-shipping.exe => No File
FirewallRules: [UDP Query User{21ABFA1B-2E22-4D81-83E6-9E02B2935BB8}D:\game bajakan\rematch\runtime\binaries\wingdk\runtimeclient-wingdk-shipping.exe] => (Allow) D:\game bajakan\rematch\runtime\binaries\wingdk\runtimeclient-wingdk-shipping.exe => No File
FirewallRules: [{4869E918-6FA2-4A49-BE54-AAD24B2ADDE8}] => (Allow) C:\Program Files\ASUS\ARMOURY CRATE Service\MobilePlugin\AutoConnectHelper.exe => No File
FirewallRules: [{A4E5143E-3EA9-4FFD-89B1-6C6C01CD4C71}] => (Allow) C:\Program Files\ASUS\ARMOURY CRATE Service\MobilePlugin\AutoConnectHelper.exe => No File
FirewallRules: [{CD1B492D-372F-4B75-9405-10B43C5B98A8}] => (Allow) C:\Users\Rifky Fauzan\AppData\Local\Temp\ACFL20250704071530\ACSetup\ACSetup.exe => No File
FirewallRules: [{A043ECB3-7E33-4234-93D6-12060D5FEA77}] => (Allow) C:\Users\Rifky Fauzan\AppData\Local\Temp\ACFL20250704071530\ACSetup\ACSetup.exe => No File
FirewallRules: [TCP Query User{61BCB877-975B-41E7-97FE-A0C1F9939C3C}D:\game bajakan\monsterhunterwilds\monsterhunterwilds.exe] => (Allow) D:\game bajakan\monsterhunterwilds\monsterhunterwilds.exe => No File
FirewallRules: [UDP Query User{C5A9A206-A627-4FA1-80F8-74CB954510F2}D:\game bajakan\monsterhunterwilds\monsterhunterwilds.exe] => (Allow) D:\game bajakan\monsterhunterwilds\monsterhunterwilds.exe => No File
FirewallRules: [TCP Query User{A46AF5AF-90E0-452F-A252-31B5E60FD40E}D:\game bajakan\cloudheim\protocat\binaries\win64\cloudheimsteam-win64-shipping.exe] => (Allow) D:\game bajakan\cloudheim\protocat\binaries\win64\cloudheimsteam-win64-shipping.exe => No File
FirewallRules: [UDP Query User{2D293B4E-CA0F-44AD-8AC5-3552BABC0572}D:\game bajakan\cloudheim\protocat\binaries\win64\cloudheimsteam-win64-shipping.exe] => (Allow) D:\game bajakan\cloudheim\protocat\binaries\win64\cloudheimsteam-win64-shipping.exe => No File
FirewallRules: [{E4C9F122-F9BB-4D3E-840B-72AE2F33C5F0}] => (Allow) C:\Program Files (x86)\Folder Baru\steam\steamapps\common\Apex Legends\start_protected_game.exe => No File
FirewallRules: [{6DA2273C-A1AE-4949-B673-6A552FC7C2F9}] => (Allow) C:\Program Files (x86)\Folder Baru\steam\steamapps\common\Apex Legends\start_protected_game.exe => No File
FirewallRules: [{87D3A10A-4045-4AC8-94FA-211AB58F003C}] => (Allow) C:\Users\Rifky Fauzan\AppData\Local\Temp\ACFL\ACSetup\ACSetup.exe => No File
FirewallRules: [{E59191C0-6F08-44C6-BFA1-62C518DB942C}] => (Allow) C:\Users\Rifky Fauzan\AppData\Local\Temp\ACFL\ACSetup\ACSetup.exe => No File
FirewallRules: [TCP Query User{8F959C4E-B10E-4A73-A705-C525FAF107D2}D:\game bajakan\vanguard\cardfight!! vanguard dear days 2\vgdd2.exe] => (Allow) D:\game bajakan\vanguard\cardfight!! vanguard dear days 2\vgdd2.exe => No File
FirewallRules: [UDP Query User{55B9A6F3-7CC0-4885-B423-BC240195069F}D:\game bajakan\vanguard\cardfight!! vanguard dear days 2\vgdd2.exe] => (Allow) D:\game bajakan\vanguard\cardfight!! vanguard dear days 2\vgdd2.exe => No File
HKU\S-1-5-21-1070632220-2695763294-3121136582-1001\...\Run: [Rave] => "C:\Users\Rifky Fauzan\AppData\Local\Programs\rave-desktop\Rave.exe" --hidden (No File)
HKU\S-1-5-21-1070632220-2695763294-3121136582-1001\...\Run: [AF_uuid_514912] => 53c25f9f-58bd-43f4-9a9e-25e64cf2b839**e*\***************f**|***€GOCSPX-s (No File)
HKU\S-1-5-21-1070632220-2695763294-3121136582-1001\...\Run: [AF_counter_514912] => 1 (No File)
HKU\S-1-5-21-1070632220-2695763294-3121136582-1001\...\MountPoints2: {77135f4d-7826-11ed-a95d-505a65063c64} - "E:\setup.exe"
Task: {58EF3C6E-D7B7-4A03-B443-6EF349D02164} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (No File)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
CHR HKU\S-1-5-21-1070632220-2695763294-3121136582-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dpadflhmiohjfhhaehelneimpllfbpcg] - C:\Users\Rifky Fauzan\AppData\Roam <not found>
S3 ace-game-0; \SystemRoot\System32\drivers\ace-game-0.sys (No File)
S3 NEProtect; \??\C:\Program Files (x86)\Folder Baru\steam\steamapps\common\BLOODSTRIKE\Engine\Binaries\Win64\NEProtect.sys (No File)
2026-07-02 23:29 - 2026-07-14 00:33 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\0b5e9b57a31dad4854415695873a1ad8f46a3c20b88e48efb7b2a96771e65bd9
2026-07-02 23:29 - 2026-07-02 23:29 - 000000026 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\29c0fc0f474cba4b579efb637113ed0a327d65af2258e235e2348ee72c8a7759
2026-07-14 08:48 - 2024-06-19 22:40 - 000042147 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\e8b8c38bc0813bee691394e17cde8da390a0e65ee924b2b3ea21d7e1bf2281f6
2026-07-14 08:44 - 2024-06-18 03:17 - 003270114 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\48175e76c0ff4e749e851f1f852c4355d6296fb912d5143b0a98400c90511d05
2026-07-14 06:46 - 2024-06-28 16:43 - 000059481 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\7e9486d5a9a71bdc94996a35dc80ce734de68bcbcaf557324f29a0d44251a630
2026-07-14 06:43 - 2024-06-18 07:31 - 001915645 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\cce47a310a2b6b5eb724cd7e159b5e69a9bfbcdfa607a503016b50e97460decd
2026-07-14 06:38 - 2025-09-19 13:27 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\7e681db666f22e0881505caef1f2069b31a0c71723fa40ef97b010913bbb0dd3
2026-07-14 06:31 - 2024-06-18 03:12 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\fbfe924ddb0464555ab0c1c3d6102a5c9c9a52b2b7c64e410edea756513d4ae4
2026-07-14 06:26 - 2024-08-26 17:03 - 000235270 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\3fde5216d2193240953c50de719ec957029f8d481810cb6be21e28129c17e0ea
2026-07-14 06:26 - 2024-08-26 17:03 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\7a30513e4032e80317004bfdff927d304a9f6e33d1d4d0a20426d318a1097f65
2026-07-14 06:26 - 2024-06-18 03:17 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\8d9f96ac0c81c4e109d1cbc5c849f4f0dcb5608abc0b55fd1734084a9d98342f
2026-07-14 06:15 - 2025-12-19 09:11 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\ca54b7cb4433a88da9612a9640d081082330ea768a5b2060c150e2d8a4731849
2026-07-14 06:14 - 2025-12-19 09:11 - 000966645 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\a7f7d656671c63f1edaa9ea613e376df328a91ef84a4438781013710fdc99068
2026-07-14 06:13 - 2025-12-19 09:11 - 000162556 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\c4beba2be83db5339b4f4173ce80666ec40750869f30c769de436300b3d875f2
2026-07-14 06:09 - 2025-07-28 08:26 - 000011216 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\e69ac24fe51cbd89a2862988dc23a8cd7e018583b57ce57bc0e8def010b5a5ce
2026-07-14 06:09 - 2024-06-18 03:11 - 000011216 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\538164be095319c9b35dd4523563bb2c05ff19c435a7794a0a56839bf802f3f6
2026-07-13 02:42 - 2025-11-16 19:28 - 000218675 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\4d056e1e29ec3c97750cf4a824471911c81bb102e8ed5157bea4ae3c18d81f05
2026-07-11 07:06 - 2024-07-18 20:12 - 000451745 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\062e0a2c15d8c229ab7c0bd25f71169a5cd5708c9dc7e4e8b31ff22ac7cc4411
2026-07-10 13:42 - 2024-08-08 16:02 - 000026882 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\8fadcb6a0d2bde06c5228769a5e71700102081a7191b21c706f6f4cb7c181b5d
2026-07-10 13:42 - 2024-08-08 16:02 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\a94f18ec458804c64b885271466f36a2681a2a7db80a5f9c50026cdf591b4211
2026-07-10 12:47 - 2025-06-06 03:06 - 000011216 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\ef7d34d7619787f6d1f2dc9f3da47c2417d0e4beef68371dd16fc8a4dfd83d59
2026-07-10 05:03 - 2025-06-06 03:06 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\62d829d95bb90bf102b4c2c6c78a555faf5a11242184bddc20a7039cd326e62c
2026-06-28 07:00 - 2025-11-16 19:28 - 000000130 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\a5afe75980b197a4f53b602b005671be082663031a53a86b6fd08117daac4704
2025-02-27 22:42 - 2025-02-27 22:42 - 000000024 _____ () C:\Users\Rifky Fauzan\AppData\Roaming\C23W6Vk43XTwu662.dat
2024-12-10 16:55 - 2024-12-10 16:55 - 000000048 ____R () C:\Users\Rifky Fauzan\AppData\Local\289997B9FC4FEEDE6DEF9AA33BCCA370
2025-05-11 17:44 - 2025-05-11 17:44 - 000000036 _____ () C:\Users\Rifky Fauzan\AppData\Local\4051BDD0000f042.pyo
2025-11-16 19:35 - 2025-11-16 19:35 - 000000048 ____R () C:\Users\Rifky Fauzan\AppData\Local\62548010F1356EF5554868D4EB2F2A25
2025-03-10 02:42 - 2025-03-10 02:42 - 000000048 ____R () C:\Users\Rifky Fauzan\AppData\Local\7288E29716A5FF2D4E06A4EAF635BD33
2026-05-31 23:59 - 2026-05-31 23:59 - 000000048 ____R () C:\Users\Rifky Fauzan\AppData\Local\AB94542F5FADE6F8B81D4B79C11311EF
2025-05-11 17:32 - 2025-05-11 17:32 - 000000048 ____R () C:\Users\Rifky Fauzan\AppData\Local\F1DD43B9BE218E8E2550DBF370E02D28
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1653.5 - AVAST Software) Hidden
2026-07-14 06:13 - 2026-07-14 06:13 - 000114688 _____ () [File not signed] \\?\C:\Users\Rifky Fauzan\AppData\Local\Temp\35d1313a-5a14-4fb1-b411-7c9c5e596ab3.tmp.node
HKU\S-1-5-21-1070632220-2695763294-3121136582-1001\...\Run: [MicrosoftEdgeAutoLaunch_908D2254D8BEE7E1651F33060FC32228] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4970824 2026-07-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {C51E5450-3A06-45C6-87C8-5A543AD57837} - System32\Tasks\BackgroundTask => C:\Windows\System32\cmd.exe [348160 2026-06-10] (Microsoft Windows -> Microsoft Corporation) -> /c "C:\Users\Rifky Fauzan\AppData\Local\Microsoft\Windows\WebCache\bootstrap_3b40.cmd"
C:\Users\Rifky Fauzan\AppData\Local\Microsoft\Windows\WebCache
CHR DefaultSuggestURL: Default -> hxxps://id.search.yahoo.com/sugg/gossip/gossip-id-partner?output=fxjson&appid=mca&source=yahoo_mcafee_searchassist&command={searchTerms}
CHR DefaultSearchURL: Default -> hxxps://id.search.yahoo.com/search?fr=mcafee&type=E210ID885G0&p={searchTerms}
Edge HKLM-x32\...\Edge\Extension: [fdhgeoginicibhagdmblfikbgbkahibd]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
2026-07-14 04:00 - 2026-07-14 04:00 - 000003524 _____ C:\WINDOWS\system32\Tasks\BackgroundTask
2026-07-14 06:15 - 2024-06-18 07:31 - 000002650 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\2ed50ab3386a4fc9cf53DcJHrrHSgvFpsYxqb6g97uaQTd2kE31rPUeDZTeDsjVq
2026-07-14 00:33 - 2024-11-29 01:41 - 000000000 ____D C:\temp
2026-07-11 07:33 - 2024-07-18 20:12 - 000000466 _____ C:\Users\Rifky Fauzan\AppData\LocalLow\d57efd2e9415e4a6500c4c130c77805d6dd5c319eWJh8J6Mx9DrGXKEv3ojKmqw8Cv9pscK
StartPowershell:
# Replace /scanonly with /clean if you also want to delete items -- however, this will activate a trial license on the system, I do not recommend it
$hmpExe = "$env:TEMP\HitmanPro_x64.exe"
$logFile = "$env:TEMP\HitmanPro_ScanLog.txt"
Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing
$proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru
if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 }
Get-Content $logFile -Encoding Unicode
EndPowershell:
StartPowerShell:
# Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console
# Does not clean preinstalled objects, only PUP/Adware
# If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument
# If you would like to only scan with it, change the argument from /clean to /scan
# NOTE: For the sake of users from Asia (primarily China), do not use the clean option. It will very likely remove a lot of their important software.
New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null
Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden
$logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile
Get-Content $logFile -Encoding Unicode
Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue
EndPowerShell:
Comment: List Windows Defender properties, settings
StartPowerShell:
function Write-Section {
param([string]$Title)
Write-Host ""
Write-Host "<=== $Title ===>"
}
Write-Section "Protection Status"
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntispywareEnabled, AntivirusEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, RealTimeProtectionEnabled, IsTamperProtected, NetworkProtectionStatus | Format-List
Write-Section "Signature / Engine Versions"
Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AntivirusSignatureVersion, AntispywareSignatureVersion | Format-List
Write-Section "Preferences / Configuration"
Get-MpPreference | Select-Object PUAProtection, MAPSReporting, SubmitSamplesConsent, CheckForSignaturesBeforeRunningScan, CloudBlockLevel, EnableNetworkProtection, DisableScriptScanning, DisableArchiveScanning, DisableRemovableDriveScanning, DisableScanningNetworkFiles, DisableScanningMappedNetworkDrivesForFullScan, DisableBlockAtFirstSeen, DisableHeuristics, DisableAutoExclusions | Format-List
Write-Section "Threat Detections"
$threats = Get-MpThreatDetection
if ($threats) {
$threats | Format-Table -AutoSize
} else {
Write-Host " (no threat detections found)"
}
EndPowerShell:
Comment: List drive info, identify possible damaged drives (thanks to AdvancedSetup from Malwarebytes for parts of these)
StartPowerShell:
param(
[int]$MaxEvents = 2000
)
$GPTTypeMap = @{
'EBD0A0A2-B9E5-4433-87C0-68B6B72699C7' = 'Microsoft Basic Data'
'E3C9E316-0B5C-4DB8-817D-F92DF00215AE' = 'Microsoft Reserved (MSR)'
'DE94BBA4-06D1-4D40-A16A-BFD50179D6AC' = 'Windows Recovery Environment (WinRE)'
'C12A7328-F81F-11D2-BA4B-00A0C93EC93B' = 'EFI System Partition'
'21686148-6449-6E6F-744E-656564454649' = 'BIOS Boot Partition'
'A19D880F-05FC-4D3B-A006-743F0F84911E' = 'OEM Partition'
'5808C8AA-7E8F-42E0-85D2-E1E90434CFB3' = 'Cluster Metadata Partition'
'48465300-0000-11AA-AA11-00306543ECAC' = 'Apple HFS/HFS+'
'7C3457EF-0000-11AA-AA11-00306543ECAC' = 'Apple APFS'
'0FC63DAF-8483-4772-8E79-3D69D8477DE4' = 'Linux Filesystem'
'0657FD6D-A4AB-43C4-84E5-0933C84B4F4F' = 'Linux Swap'
'E6D6D379-F507-44C2-A23C-238F2A3DF928' = 'Linux LVM'
}
$MBRTypeMap = @{
'01'='FAT12';'04'='FAT16 <32M';'05'='Extended';'06'='FAT16';'07'='IFS/NTFS/exFAT/HPFS';'0B'='FAT32 CHS';'0C'='FAT32 LBA';'0E'='FAT16 LBA'
'0F'='Extended LBA';'82'='Linux Swap';'83'='Linux Native';'8E'='Linux LVM';'A5'='FreeBSD';'A6'='OpenBSD';'A8'='Mac OS X';'AB'='Mac OS X Boot'
'AF'='Mac OS X HFS';'EE'='EFI GPT Protective';'EF'='EFI System Partition'
}
function Get-PartitionTypeInfo {
param($Partition)
$guid = $null
if ($Partition.GptType) {
$guid = ($Partition.GptType -replace '[{}]', '').ToUpper()
}
if ([string]::IsNullOrWhiteSpace($guid) -or $guid -eq '00000000-0000-0000-0000-000000000000') {
$guid = switch ($Partition.Type) {
"System" { "C12A7328-F81F-11D2-BA4B-00A0C93EC93B" }
"Reserved" { "E3C9E316-0B5C-4DB8-817D-F92DF00215AE" }
"Basic" { "EBD0A0A2-B9E5-4433-87C0-68B6B72699C7" }
"Recovery" { "DE94BBA4-06D1-4D40-A16A-BFD50179D6AC" }
default { $null }
}
}
if ($guid) {
$name = $GPTTypeMap[$guid]
if ($name) { return "$name (GPT GUID: $($guid.ToLower()))" }
else { return "Unknown/Custom (GPT GUID: $($guid.ToLower()))" }
}
if ($Partition.MbrType) {
$code = ($Partition.MbrType.ToString() -replace '^0x', '').PadLeft(2, '0').ToUpper()
$name = $MBRTypeMap[$code]
if ($name) { return "$name (MBR code: 0x$code)" }
else { return "Unknown/Custom (MBR code: $($Partition.MbrType))" }
}
return $Partition.Type
}
function Get-DrMapping {
param([int]$MaxEvents)
$map = @{}
try {
$events = Get-WinEvent -FilterHashtable @{ LogName = 'System'; ProviderName = 'disk' } -MaxEvents $MaxEvents -ErrorAction Stop
} catch {
return $map
}
foreach ($e in $events) {
if ($e.Message -match 'Harddisk(\d+)\\DR(\d+)') {
$n = [int]$Matches[1]
$dr = [int]$Matches[2]
if (-not $map.ContainsKey($n)) { $map[$n] = $dr }
}
}
return $map
}
$drMap = Get-DrMapping -MaxEvents $MaxEvents
$physicalDisks = Get-PhysicalDisk | Select-Object DeviceId, FriendlyName, SerialNumber, MediaType, @{N='SizeGB';E={[math]::Round($_.Size / 1GB,2)}}
foreach ($pd in $physicalDisks) {
$devId = [int]$pd.DeviceId
$drSuffix = if ($drMap.ContainsKey($devId)) { "\DR$($drMap[$devId])" } else { '\DR? (no event seen yet)' }
Write-Host ""
Write-Host "<=== \Device\Harddisk$devId$drSuffix ($($pd.FriendlyName)) ===>"
Write-Host " DeviceId: $devId | Serial: $($pd.SerialNumber) | Media: $($pd.MediaType) | Size: $($pd.SizeGB) GB"
try {
$partitions = Get-Partition -DiskNumber $devId -ErrorAction Stop
if (-not $partitions) {
Write-Host " (no partitions found)"
continue
}
foreach ($part in $partitions) {
$driveLetter = if ($part.DriveLetter) { "$($part.DriveLetter):" } else { 'no letter' }
$sizeGB = [math]::Round($part.Size / 1GB, 2)
$typeInfo = Get-PartitionTypeInfo -Partition $part
Write-Host " [PARTITION $($part.PartitionNumber)] Drive: $driveLetter - $sizeGB GB - $typeInfo"
}
} catch {
Write-Host " [ERROR] cannot read partitions for disk $devId"
}
}
if ($drMap.Count -eq 0) {
Write-Host ""
Write-Host "Note: no \Device\HarddiskN\DRx entries found in the last $MaxEvents System log events. Increase -MaxEvents, or the DR number will only appear once Windows actually logs a disk event for that drive (e.g. a bad block warning)."
}
EndPowerShell:
Comment: Verify that Discord does not have any injected code to intercept personal data. If anything is prompted here, it needs to be checked that it isn't malicious code.
Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) }
StartPowerShell:
# Basic BSOD listings
$ccKey = "HKLM:\SYSTEM\CurrentControlSet\Control\CrashControl"
$cfg = Get-ItemProperty $ccKey -ErrorAction SilentlyContinue
$dumpTypeMap = @{0='None';1='Complete';2='Kernel';3='Minidump';7='Automatic'}
Write-Output "--- Configuration ---"
Write-Output ("Dump Type: {0} ({1})" -f $cfg.CrashDumpEnabled, $dumpTypeMap[$cfg.CrashDumpEnabled])
Write-Output ("Full Dump Path: {0}" -f $(if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}))
Write-Output ("Minidump Folder: {0}" -f $(if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}))
Write-Output ("Auto Reboot: {0}" -f $(if($cfg.AutoReboot -eq 0){'Disabled'}else{'Enabled'}))
Write-Output "--- Found Dump Files ---"
$full = if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}
if (Test-Path $full) { Get-Item $full | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
$mini = if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}
if (Test-Path $mini) { Get-ChildItem $mini -Filter *.dmp | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
Write-Output "--- BugCheck Reasoning (recent events) ---"
$map = @{
'0x0000000A'='IRQL_NOT_LESS_OR_EQUAL - faulty/outdated driver accessed memory at high IRQL'
'0x0000001E'='KMODE_EXCEPTION_NOT_HANDLED - unhandled kernel exception, often driver/hardware'
'0x0000002E'='DATA_BUS_ERROR - typically bad RAM or hardware fault'
'0x0000003B'='SYSTEM_SERVICE_EXCEPTION - exception in a system service, often driver-related'
'0x00000050'='PAGE_FAULT_IN_NONPAGED_AREA - bad RAM or faulty driver/antivirus'
'0x0000007A'='KERNEL_DATA_INPAGE_ERROR - disk-related problem'
'0x0000007B'='INACCESSIBLE_BOOT_DEVICE - system could not find/access the boot device'
'0x0000007E'='SYSTEM_THREAD_EXCEPTION_NOT_HANDLED - almost always a faulty driver'
'0x0000007F'='UNEXPECTED_KERNEL_MODE_TRAP - hardware issue (CPU/RAM/overclocking)'
'0x0000009F'='DRIVER_POWER_STATE_FAILURE - driver failed to respond to a power state change'
'0x000000C2'='BAD_POOL_CALLER - driver mishandling memory (pool corruption)'
'0x000000D1'='DRIVER_IRQL_NOT_LESS_OR_EQUAL - typically a network or GPU driver'
'0x000000EF'='CRITICAL_PROCESS_DIED - a critical system process died, often malware/system corruption'
'0x00000116'='VIDEO_TDR_FAILURE - GPU driver failed to respond in time (timeout)'
'0x00000124'='WHEA_UNCORRECTABLE_ERROR - hardware fault (CPU/RAM/PSU/overclocking)'
'0x00000133'='DPC_WATCHDOG_VIOLATION - faulty driver or storage subsystem issue'
'0x00000139'='KERNEL_SECURITY_CHECK_FAILURE - corrupted kernel structure, possibly malware'
}
$events = Get-WinEvent -FilterHashtable @{LogName='System';Id=1001} -MaxEvents 100 -ErrorAction SilentlyContinue |
Where-Object { $_.ProviderName -match 'WER-SystemErrorReporting' } | Select-Object -First 5
if (-not $events) { Write-Output "No BugCheck events found in the log." }
foreach ($ev in $events) {
$code = if ($ev.Message -match 'bugcheck was:\s*(0x[0-9A-Fa-f]+)') { $matches[1] } else { $null }
Write-Output ("Time: {0}" -f $ev.TimeCreated)
Write-Output ("Code: {0}" -f $(if($code){$code}else{'not recognized'}))
if ($code -and $map.ContainsKey($code.ToUpper())) {
Write-Output ("Meaning: {0}" -f $map[$code.ToUpper()])
} elseif ($code) {
Write-Output "Meaning: unknown code, look up at learn.microsoft.com/windows-hardware/drivers/debugger/bug-check-code-reference2"
}
Write-Output ""
}
EndPowerShell:
StartPowerShell:
# This snippet lists all installed apps and their folder contents along with SHA256 hashes. Useful for troubleshooting malware abusing installed app entry.
param(
[switch]$Recurse,
[int]$MaxFilesPerApp = [int]::MaxValue
)
$uninstallPaths = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
$script:msiInstaller = $null
function Get-MsiInstallLocation {
param([string]$ProductCode)
if (-not $script:msiInstaller) {
try { $script:msiInstaller = New-Object -ComObject WindowsInstaller.Installer } catch { return $null }
}
try {
$loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallLocation')
if ([string]::IsNullOrWhiteSpace($loc)) { $loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallSource') }
if ([string]::IsNullOrWhiteSpace($loc)) { return $null }
return $loc
} catch { return $null }
}
function Get-CleanPath {
param([string]$RawValue)
if ([string]::IsNullOrWhiteSpace($RawValue)) { return $null }
$s = $RawValue.Trim()
if ($s.StartsWith('"')) {
$endQuote = $s.IndexOf('"', 1)
if ($endQuote -gt 0) { return $s.Substring(1, $endQuote - 1) }
}
if ($s -match '^(.*?\.exe)\b') { return $Matches[1] }
return $s
}
function Format-FileSize {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$script:PeExtensions = @('.exe', '.dll', '.sys', '.ocx', '.cpl', '.scr', '.drv', '.efi', '.msi', '.msp', '.msu')
function Test-IsPeFile {
param([string]$Extension)
return $script:PeExtensions -contains $Extension.ToLower()
}
function Get-SignatureInfo {
param([string]$Path, [string]$Extension)
if (-not (Test-IsPeFile -Extension $Extension)) {
return [PSCustomObject]@{ Signer = 'N/A (not PE)'; Status = 'NotApplicable'; Valid = $false }
}
$result = [PSCustomObject]@{ Signer = 'Unsigned'; Status = 'NotSigned'; Valid = $false }
try {
$sig = Get-AuthenticodeSignature -LiteralPath $Path -ErrorAction Stop
$result.Status = $sig.Status.ToString()
$result.Valid = ($sig.Status -eq 'Valid')
if ($sig.SignerCertificate) {
if ($sig.SignerCertificate.Subject -match 'CN=([^,]+)') { $result.Signer = $Matches[1].Trim('"') }
else { $result.Signer = $sig.SignerCertificate.Subject }
if (-not $result.Valid) { $result.Signer += " [INVALID: $($result.Status)]" }
} elseif ($sig.Status -eq 'NotSigned') {
$result.Signer = 'Unsigned'
} else {
$result.Signer = "Unknown [$($result.Status)]"
}
} catch {
$result.Signer = 'Verification error'
$result.Status = 'Error'
$result.Valid = $false
}
return $result
}
$rawApps = Get-ItemProperty -Path $uninstallPaths -ErrorAction SilentlyContinue |
Where-Object { $_.DisplayName -and $_.DisplayName.Trim() -ne '' } |
Select-Object @{Name = 'Name'; Expression = { $_.DisplayName } },
@{Name = 'Version'; Expression = { $_.DisplayVersion } },
@{Name = 'Publisher'; Expression = { $_.Publisher } },
@{Name = 'InstallFolder'; Expression = {
if ($_.InstallLocation -and $_.InstallLocation.Trim() -ne '') { $_.InstallLocation }
elseif ($_.UninstallString -match 'MsiExec\.exe.*?(\{[0-9A-Fa-f\-]{36}\})') {
$productCode = $Matches[1]
$msiLoc = Get-MsiInstallLocation -ProductCode $productCode
if ($msiLoc) { $msiLoc } else { "MSI: $productCode (location not found)" }
}
elseif ($_.UninstallString) { $_.UninstallString }
else { 'N/A' }
} } |
Sort-Object Name -Unique
foreach ($app in $rawApps) {
$versionText = if ($app.Version) { $app.Version } else { '?' }
$publisherText = if ($app.Publisher) { $app.Publisher } else { '?' }
Write-Host ""
Write-Host "<=== $($app.Name) [$versionText] ($publisherText) ===>"
if ($app.InstallFolder -eq 'N/A' -or $app.InstallFolder -match '^MSI: .* \(location not found\)$') {
Write-Host " Path: $($app.InstallFolder)"
continue
}
$cleanPath = Get-CleanPath -RawValue $app.InstallFolder
$exists = $false
try {
$exists = Test-Path -LiteralPath $cleanPath -ErrorAction Stop
} catch [System.UnauthorizedAccessException] {
Write-Host " Path: $cleanPath"
Write-Host " [ACCESS DENIED]"
continue
} catch {
Write-Host " Path: $cleanPath"
Write-Host " [ERROR] cannot access"
continue
}
if (-not $exists) {
Write-Host " Path: $cleanPath"
Write-Host " [NOT FOUND]"
continue
}
$rootItem = Get-Item -LiteralPath $cleanPath -Force
$created = $rootItem.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$modified = $rootItem.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
if ($rootItem.PSIsContainer) {
$subFolders = Get-ChildItem -LiteralPath $cleanPath -Directory -Force -ErrorAction SilentlyContinue
$gciParams = @{ LiteralPath = $cleanPath; File = $true; Force = $true; ErrorAction = 'SilentlyContinue' }
if ($Recurse) { $gciParams['Recurse'] = $true }
$allFiles = Get-ChildItem @gciParams
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: $($allFiles.Count) | Folders: $($subFolders.Count)"
foreach ($dir in $subFolders) {
$dCreated = $dir.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$dModified = $dir.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$dFileCount = (Get-ChildItem -LiteralPath $dir.FullName -File -Force -ErrorAction SilentlyContinue).Count
Write-Host (" [DIR] {0} - {1} - {2,10} - {3}" -f $dCreated, $dModified, "$dFileCount files", $dir.FullName)
}
} else {
$allFiles = @($rootItem)
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: 1"
}
if ($allFiles.Count -eq 0) { continue }
$shown = $allFiles | Select-Object -First $MaxFilesPerApp
foreach ($f in $shown) {
$hash = 'N/A'
try { $hash = (Get-FileHash -LiteralPath $f.FullName -Algorithm SHA256 -ErrorAction Stop).Hash } catch { $hash = 'HASH-ERROR' }
$size = Format-FileSize -Bytes $f.Length
$fcreated = $f.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$fmod = $f.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$sigInfo = Get-SignatureInfo -Path $f.FullName -Extension $f.Extension
Write-Host (" [{0}] {1} - {2} - {3,10} - Signer: {4} - {5}" -f $hash, $fcreated, $fmod, $size, $sigInfo.Signer, $f.FullName)
}
}
EndPowerShell:
Comment: List 30 recent scheduled tasks (you know, just for the sake of it)
Powershell: Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo
Comment: List recent Run (Windows + R) executed commands, useful for identifying ClickFix attacks
Powershell: (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" }
Comment: Remove unwanted files from common folders using native removal power of Farbar to include remove on reboot if needed. Please double check the user does not have any applications incorrectly installed in the directories listed below.
C:\ProgramData\*.csproj
C:\ProgramData\*.a3x
C:\ProgramData\*.ahk
C:\ProgramData\*.au3
C:\ProgramData\*.bat
C:\ProgramData\*.cab
C:\ProgramData\*.cmd
C:\ProgramData\*.com
C:\ProgramData\*.dll
C:\ProgramData\*.exe
C:\ProgramData\*.hta
C:\ProgramData\*.jar
C:\ProgramData\*.js
C:\ProgramData\*.jse
C:\ProgramData\*.lnk
C:\ProgramData\*.pif
C:\ProgramData\*.ps1
C:\ProgramData\*.py
C:\ProgramData\*.pyc
C:\ProgramData\*.pyd
C:\ProgramData\*.scr
C:\ProgramData\*.tmp
C:\ProgramData\*.vbe
C:\ProgramData\*.vbs
C:\ProgramData\*.wsf
C:\ProgramData\*.wsh
C:\ProgramData\*.zip
C:\ProgramData\*.rar
C:\ProgramData\*.7z
C:\Users\*\AppData\Roaming\*.csproj
C:\Users\*\AppData\Roaming\*.au3
C:\Users\*\AppData\Roaming\*.bat
C:\Users\*\AppData\Roaming\*.cab
C:\Users\*\AppData\Roaming\*.cmd
C:\Users\*\AppData\Roaming\*.com
C:\Users\*\AppData\Roaming\*.dll
C:\Users\*\AppData\Roaming\*.exe
C:\Users\*\AppData\Roaming\*.hta
C:\Users\*\AppData\Roaming\*.jar
C:\Users\*\AppData\Roaming\*.js
C:\Users\*\AppData\Roaming\*.jse
C:\Users\*\AppData\Roaming\*.lnk
C:\Users\*\AppData\Roaming\*.pif
C:\Users\*\AppData\Roaming\*.ps1
C:\Users\*\AppData\Roaming\*.py
C:\Users\*\AppData\Roaming\*.pyc
C:\Users\*\AppData\Roaming\*.pyd
C:\Users\*\AppData\Roaming\*.scr
C:\Users\*\AppData\Roaming\*.tmp
C:\Users\*\AppData\Roaming\*.vbe
C:\Users\*\AppData\Roaming\*.vbs
C:\Users\*\AppData\Roaming\*.wsf
C:\Users\*\AppData\Roaming\*.wsh
C:\Users\*\AppData\Roaming\*.zip
C:\Users\*\AppData\Roaming\*.rar
C:\Users\*\AppData\Roaming\*.7z
C:\Users\CurrentUserName\AppData\Local\*.csproj
C:\Users\CurrentUserName\AppData\Local\*.a3x
C:\Users\CurrentUserName\AppData\Local\*.ahk
C:\Users\CurrentUserName\AppData\Local\*.au3
C:\Users\CurrentUserName\AppData\Local\*.bat
C:\Users\CurrentUserName\AppData\Local\*.cab
C:\Users\CurrentUserName\AppData\Local\*.cmd
C:\Users\CurrentUserName\AppData\Local\*.com
C:\Users\CurrentUserName\AppData\Local\*.dll
C:\Users\CurrentUserName\AppData\Local\*.exe
C:\Users\CurrentUserName\AppData\Local\*.hta
C:\Users\CurrentUserName\AppData\Local\*.jar
C:\Users\CurrentUserName\AppData\Local\*.js
C:\Users\CurrentUserName\AppData\Local\*.jse
C:\Users\CurrentUserName\AppData\Local\*.lnk
C:\Users\CurrentUserName\AppData\Local\*.pif
C:\Users\CurrentUserName\AppData\Local\*.ps1
C:\Users\CurrentUserName\AppData\Local\*.py
C:\Users\CurrentUserName\AppData\Local\*.pyc
C:\Users\CurrentUserName\AppData\Local\*.pyd
C:\Users\CurrentUserName\AppData\Local\*.scr
C:\Users\CurrentUserName\AppData\Local\*.tmp
C:\Users\CurrentUserName\AppData\Local\*.vbe
C:\Users\CurrentUserName\AppData\Local\*.vbs
C:\Users\CurrentUserName\AppData\Local\*.wsf
C:\Users\CurrentUserName\AppData\Local\*.wsh
C:\Users\CurrentUserName\AppData\Local\*.zip
C:\Users\CurrentUserName\AppData\Local\*.rar
C:\Users\CurrentUserName\AppData\Local\*.7z
C:\Users\CurrentUserName\AppData\Roaming\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\*.a3x
C:\Users\CurrentUserName\AppData\Roaming\*.ahk
C:\Users\CurrentUserName\AppData\Roaming\*.au3
C:\Users\CurrentUserName\AppData\Roaming\*.bat
C:\Users\CurrentUserName\AppData\Roaming\*.cab
C:\Users\CurrentUserName\AppData\Roaming\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\*.com
C:\Users\CurrentUserName\AppData\Roaming\*.dll
C:\Users\CurrentUserName\AppData\Roaming\*.exe
C:\Users\CurrentUserName\AppData\Roaming\*.hta
C:\Users\CurrentUserName\AppData\Roaming\*.jar
C:\Users\CurrentUserName\AppData\Roaming\*.js
C:\Users\CurrentUserName\AppData\Roaming\*.jse
C:\Users\CurrentUserName\AppData\Roaming\*.lnk
C:\Users\CurrentUserName\AppData\Roaming\*.pif
C:\Users\CurrentUserName\AppData\Roaming\*.ps1
C:\Users\CurrentUserName\AppData\Roaming\*.py
C:\Users\CurrentUserName\AppData\Roaming\*.pyc
C:\Users\CurrentUserName\AppData\Roaming\*.pyd
C:\Users\CurrentUserName\AppData\Roaming\*.scr
C:\Users\CurrentUserName\AppData\Roaming\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\*.vbe
C:\Users\CurrentUserName\AppData\Roaming\*.vbs
C:\Users\CurrentUserName\AppData\Roaming\*.wsf
C:\Users\CurrentUserName\AppData\Roaming\*.wsh
C:\Users\CurrentUserName\AppData\Roaming\*.zip
C:\Users\CurrentUserName\AppData\Roaming\*.rar
C:\Users\CurrentUserName\AppData\Roaming\*.7z
Comment: Remove browser cache
StartPowerShell:
$ProfilesDirectory = (Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList').ProfilesDirectory
$DisplayNames = @{
"chrome" = "Chrome"
"firefox" = "Firefox"
"opera" = "Opera"
"operagx" = "Opera GX"
"brave" = "Brave"
"msedge" = "Edge"
"vivaldi" = "Vivaldi"
"librewolf" = "LibreWolf"
"mullvad" = "Mullvad Browser"
"zen" = "Zen"
}
$ProcessNameMap = @{
"operagx" = "opera"
"mullvad" = "mullvadbrowser"
}
$trueCacheNames = @("Cache", "Code Cache", "DawnCache", "GPUCache", "GrShaderCache", "ShaderCache", "Shared Dictionary\cache")
function Get-CacheDirs {
param([string]$BrowserName, [string]$ProfilesDirectory)
switch ($BrowserName) {
"chrome" {
$dir = "$ProfilesDirectory\*\AppData\Local\Google\Chrome\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"firefox" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mozilla\Firefox\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"opera" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"operagx" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software\Opera GX Stable"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software\Opera GX Stable"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"brave" {
$dir = "$ProfilesDirectory\*\AppData\Local\BraveSoftware\Brave-Browser\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"msedge" {
$dir = "$ProfilesDirectory\*\AppData\Local\Microsoft\Edge\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"vivaldi" {
$dir = "$ProfilesDirectory\*\AppData\Local\Vivaldi\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"librewolf" {
$dir = "$ProfilesDirectory\*\AppData\Local\LibreWolf\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"mullvad" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mullvad\MullvadBrowser\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"zen" {
$dir = "$ProfilesDirectory\*\AppData\Local\zen\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
}
}
function Format-Size {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$BrowserKeys = @('chrome', 'firefox', 'opera', 'operagx', 'brave', 'msedge', 'vivaldi', 'librewolf', 'mullvad', 'zen')
foreach ($key in $BrowserKeys) {
$procName = if ($ProcessNameMap.ContainsKey($key)) { $ProcessNameMap[$key] } else { $key }
Get-Process -Name $procName -ErrorAction SilentlyContinue | Stop-Process -Force -ErrorAction SilentlyContinue
}
Start-Sleep -Seconds 5
$grandBytes = 0L
$grandFiles = 0
$anyFound = $false
foreach ($key in $BrowserKeys) {
$cacheDirs = Get-CacheDirs -BrowserName $key -ProfilesDirectory $ProfilesDirectory
if (-not $cacheDirs -or $cacheDirs.Count -eq 0) { continue }
$anyFound = $true
$displayName = $DisplayNames[$key]
$browserBytes = 0L
$browserFiles = 0
foreach ($cacheDir in $cacheDirs) {
if (-not (Test-Path $cacheDir)) { continue }
$items = Get-ChildItem -Path $cacheDir -Force -Recurse -ErrorAction SilentlyContinue
$files = $items | Where-Object { -not $_.PSIsContainer }
$bytes = ($files | Measure-Object -Property Length -Sum).Sum
if (-not $bytes) { $bytes = 0 }
$browserFiles += $files.Count
$browserBytes += $bytes
Get-ChildItem -Path "$cacheDir\*" -Force -ErrorAction SilentlyContinue | Remove-Item -Force -Recurse -ErrorAction SilentlyContinue
}
$grandBytes += $browserBytes
$grandFiles += $browserFiles
Write-Host ("{0,-16} freed {1,10} ({2} files)" -f $displayName, (Format-Size $browserBytes), $browserFiles)
}
if (-not $anyFound) {
Write-Host "No cache found for any installed browser."
}
Write-Host ""
Write-Host ("Total freed: {0} ({1} files)" -f (Format-Size $grandBytes), $grandFiles)
EndPowerShell:
Comment: Verify WMI repository, repair & verify again
CMD: winmgmt.exe /verifyrepository
CMD: winmgmt.exe /salvagerepository
CMD: winmgmt.exe /verifyrepository
Comment: To rebuild the performance counter library values
CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R"
CMD: "%WINDIR%\SysWOW64\lodctr.exe /R"
CMD: "C:\Windows\SYSTEM32\lodctr.exe /R"
CMD: "C:\Windows\SysWOW64\lodctr.exe /R"
Comment: Resync performance counter library values to WMI as well
CMD: winmgmt.exe /resyncperf
Comment: Force policy removal
C:\Windows\System32\GroupPolicyUsers
C:\Windows\System32\GroupPolicy
CMD: gpupdate.exe /force
Comment: Reset PowerShell execution policy
Powershell: Set-ExecutionPolicy Unrestricted -Scope CurrentUser -Force
Comment: BITS reset
Startbatch:
@echo off
net.exe stop BITS
ipconfig.exe /flushdns
ren "%programdata%\Microsoft\Network\Downloader\qmgr*.*" qmgr*.*.old
net.exe start BITS
Endbatch:
cmd: bitsadmin.exe /reset /allusers
Comment: Network reset commands
CMD: netsh.exe int ip reset
CMD: netsh.exe int ipv6 reset
CMD: ipconfig.exe /flushDNS
CMD: netsh.exe winsock reset catalog
Comment: Additional temp file removal
C:\Windows\System32\config\systemprofile\AppData\Local\*.tmp
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
C:\Users\CurrentUserName\AppData\Local\Temp\*
C:\Windows\Temp\*
C:\Windows\SystemTemp\*
C:\Windows\Prefetch\*
Comment: System repair commands
CMD: SFC.exe /scannow
CMD: DISM.exe /Online /Cleanup-image /Restorehealth
EmptyTemp:
End::
Warning
Executing a Fixlist on the wrong system may permanently damage it. Continue only if this link was meant for you.
To view the content, acknowledge this warning.