Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- String Dumper - Based off strings2 (adds string decryption, regex to match only pertinent strings.)
- Starting in 10 ms.
- Started...
- !This program cannot be run in DOS mode.
- $
- !This program cannot be run in DOS mode.
- $
- CorExitProcess
- !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
- runtime error
- DOMAIN error
- R6034
- An application has made an attempt to load the C runtime library incorrectly.
- Please contact the application's support team for more information.
- R6033
- - Attempt to use MSIL code from this assembly during native code initialization
- This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- R6032
- - not enough space for locale information
- R6031
- - Attempt to initialize the CRT more than once.
- This indicates a bug in your application.
- R6030
- - CRT not initialized
- R6028
- - unable to initialize heap
- R6027
- - not enough space for lowio initialization
- R6026
- - not enough space for stdio initialization
- R6025
- - pure virtual function call
- R6024
- - not enough space for _onexit/atexit table
- R6019
- - unable to open console device
- R6018
- - unexpected heap error
- R6017
- - unexpected multithread lock error
- R6016
- - not enough space for thread data
- This application has requested the Runtime to terminate it in an unusual way.
- Please contact the application's support team for more information.
- R6009
- - not enough space for environment
- R6008
- - not enough space for arguments
- R6002
- - floating point support not loaded
- Microsoft Visual C++ Runtime Library
- <program name unknown>
- Runtime Error!
- Program:
- ((((( H
- h(((( H
- H
- !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
- !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
- dddd, MMMM dd, yyyy
- GetProcessWindowStation
- GetUserObjectInformationA
- GetLastActivePopup
- GetActiveWindow
- SunMonTueWedThuFriSat
- JanFebMarAprMayJunJulAugSepOctNovDec
- GetCurrentThreadId
- GetCommandLineA
- TerminateProcess
- GetCurrentProcess
- UnhandledExceptionFilter
- SetUnhandledExceptionFilter
- IsDebuggerPresent
- GetModuleHandleW
- GetProcAddress
- InterlockedIncrement
- InterlockedDecrement
- SetHandleCount
- GetStartupInfoA
- DeleteCriticalSection
- GetModuleFileNameA
- FreeEnvironmentStringsA
- GetEnvironmentStrings
- FreeEnvironmentStringsW
- WideCharToMultiByte
- GetEnvironmentStringsW
- QueryPerformanceCounter
- GetCurrentProcessId
- GetSystemTimeAsFileTime
- LeaveCriticalSection
- EnterCriticalSection
- IsValidCodePage
- InitializeCriticalSectionAndSpinCount
- GetLocaleInfoA
- GetStringTypeA
- MultiByteToWideChar
- GetStringTypeW
- NativeEncoderx86.dll
- getEngineVersion
- abcdefghijklmnopqrstuvwxyz
- ABCDEFGHIJKLMNOPQRSTUVWXYZ
- abcdefghijklmnopqrstuvwxyz
- ABCDEFGHIJKLMNOPQRSTUVWXYZ
- 3/343:3@3V3]3k3q3|3
- 8"8(8/858=8D8I8Q8Z8f8k8p8v8z8
- 9'949?9Q9d9o9u9{9
- 11181<1@1D1H1L1P1T1
- 2!2<2C2H2L2P2q2
- :
- :":):3:;:H:O:
- 11181<1@1D1H1L1P1T1
- 2!2<2C2H2L2P2q2
- 2(282\2h2l2p2t2x2
- 9$9,949<9D9L9T9\9d9l9t9|9
- : :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
- !This program cannot be run in DOS mode.
- $
- D$X9D$,}$HcL$,H
- @USVWATAUAVAWH
- eHA_A^A]A\_^[]
- CorExitProcess
- !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
- runtime error
- DOMAIN error
- R6034
- An application has made an attempt to load the C runtime library incorrectly.
- Please contact the application's support team for more information.
- R6033
- - Attempt to use MSIL code from this assembly during native code initialization
- This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- R6032
- - not enough space for locale information
- R6031
- - Attempt to initialize the CRT more than once.
- This indicates a bug in your application.
- R6030
- - CRT not initialized
- R6028
- - unable to initialize heap
- R6027
- - not enough space for lowio initialization
- R6026
- - not enough space for stdio initialization
- R6025
- - pure virtual function call
- R6024
- - not enough space for _onexit/atexit table
- R6019
- - unable to open console device
- R6018
- - unexpected heap error
- R6017
- - unexpected multithread lock error
- R6016
- - not enough space for thread data
- This application has requested the Runtime to terminate it in an unusual way.
- Please contact the application's support team for more information.
- R6009
- - not enough space for environment
- R6008
- - not enough space for arguments
- R6002
- - floating point support not loaded
- Microsoft Visual C++ Runtime Library
- <program name unknown>
- Runtime Error!
- Program:
- ((((( H
- h(((( H
- H
- !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
- !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
- dddd, MMMM dd, yyyy
- GetProcessWindowStation
- GetUserObjectInformationA
- GetLastActivePopup
- GetActiveWindow
- SunMonTueWedThuFriSat
- JanFebMarAprMayJunJulAugSepOctNovDec
- GetCurrentThreadId
- GetCommandLineA
- GetModuleHandleW
- GetProcAddress
- SetHandleCount
- GetStartupInfoA
- DeleteCriticalSection
- GetModuleFileNameA
- FreeEnvironmentStringsA
- GetEnvironmentStrings
- FreeEnvironmentStringsW
- WideCharToMultiByte
- GetEnvironmentStringsW
- HeapSetInformation
- QueryPerformanceCounter
- GetCurrentProcessId
- GetSystemTimeAsFileTime
- LeaveCriticalSection
- EnterCriticalSection
- IsValidCodePage
- TerminateProcess
- GetCurrentProcess
- UnhandledExceptionFilter
- SetUnhandledExceptionFilter
- IsDebuggerPresent
- RtlVirtualUnwind
- RtlLookupFunctionEntry
- RtlCaptureContext
- InitializeCriticalSectionAndSpinCount
- GetLocaleInfoA
- GetStringTypeA
- MultiByteToWideChar
- GetStringTypeW
- NativeEncoderx64.dll
- getEngineVersion
- abcdefghijklmnopqrstuvwxyz
- ABCDEFGHIJKLMNOPQRSTUVWXYZ
- abcdefghijklmnopqrstuvwxyz
- ABCDEFGHIJKLMNOPQRSTUVWXYZ
- !This program cannot be run in DOS mode.
- $
- KeyValuePair`2
- IL_Emulator_Dynamic
- System.Collections.Generic
- RijndaelManaged
- CreateInstance
- extractResource
- byteArrayResource
- CryptoStreamMode
- GetEnvironmentVariable
- SetEnvironmentVariable
- get_MethodHandle
- RuntimeMethodHandle
- GetModuleHandle
- RuntimeTypeHandle
- GetTypeFromHandle
- get_ManifestModule
- get_DeclaringType
- get_ReturnType
- get_MemberType
- get_ParameterType
- get_ProcessorArchitecture
- MulticastDelegate
- WhereAlternate
- DebuggableAttribute
- ComVisibleAttribute
- AssemblyTitleAttribute
- AssemblyTrademarkAttribute
- AssemblyFileVersionAttribute
- ObfuscationAttribute
- AssemblyConfigurationAttribute
- AssemblyDescriptionAttribute
- CompilationRelaxationsAttribute
- AssemblyProductAttribute
- AssemblyCopyrightAttribute
- AssemblyCompanyAttribute
- RuntimeCompatibilityAttribute
- System.Threading
- ConversionBack
- BeginCatchBlock
- FlushFinalBlock
- EndExceptionBlock
- BeginExceptionBlock
- BeginFinallyBlock
- System.ComponentModel
- GetManifestResourceStream
- get_BaseStream
- SymmetricAlgorithm
- ICryptoTransform
- System.Reflection
- Win32Exception
- DllNotFoundException
- ArgumentNullException
- LocalVariableInfo
- ConstructorInfo
- byteArrayGrabber
- processExceptionHandler
- checkAndSetExceptionHandler
- get_ReturnParameter
- GetDelegateForFunctionPointer
- GetFunctionPointer
- InlineI8Emitter
- ShortInlineIEmitter
- ShortInlineREmitter
- InlineFieldEmitter
- InlineMethodEmitter
- InlineNoneEmitter
- InlineTypeEmitter
- InlineStringEmitter
- InlineSwitchEmitter
- InlineTokEmitter
- InlineVarEmitter
- ShortInlineBrTargetEmitter
- GetILGenerator
- GetConstructor
- CreateDecryptor
- System.Diagnostics
- System.Runtime.InteropServices
- System.Runtime.CompilerServices
- oneByteOpCodes
- twoByteOpCodes
- DebuggingModes
- get_LocalVariables
- GetManifestResourceNames
- _allExceptionHandlerses
- ExtractEmbeddedDlls
- System.Collections
- VMExample.Instructions
- fixAndSortExceptionHandlers
- EmbeddedDllClass
- ExceptionHandlerClass
- FixedExceptionHandlersClass
- GetProcAddress
- lpflOldProtect
- VirtualProtect
- System.Reflection.Emit
- GetILAsByteArray
- System.Security.Cryptography
- GetExecutingAssembly
- _allLabelsDictionary
- CreateDirectory
- IsDebuggerPresent
- Operand Type Unknown
- Check resolvedMethodBase Type
- Please call ExtractEmbeddedDlls before LoadDll
- Unable to load library:
- WrapNonExceptionThrows
- $520b7746-86a7-4021-87b4-507236a14cae
- virtualizationT
- C:\Users\buett\Desktop\VM\Runtime\obj\Debug\Runtime.pdb
- VS_VERSION_INFO
- StringFileInfo
- FileDescription
- LegalCopyright
- LegalTrademarks
- OriginalFilename
- ProductVersion
- Assembly Version
- !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
- #$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
- b!b+b2b;bDbObYbsbyb
- c"c-c6c=cFcUchctc
- e*e;eCeKeTe_eoewe
- System.Reflection
- GetExecutingAssembly
- get_BaseStream
- System.Security.Cryptography
- BadImageFormatException
- ManualResetEvent
- System.Threading
- EventWaitHandle
- set_IsBackground
- System.Diagnostics
- GetCurrentProcess
- get_ProcessName
- ProcessStartInfo
- set_CreateNoWindow
- set_UseShellExecute
- CreateDirectory
- get_MainWindowTitle
- Microsoft.Win32
- get_IsAttached
- GCCollectionMode
- set_ForegroundColor
- System.Drawing
- Colorful.Console
- SetCursorPosition
- GetDirectories
- set_RedirectStandardInput
- get_StandardInput
- set_RedirectStandardOutput
- System.Management
- ManagementObjectSearcher
- ManagementObjectCollection
- ManagementObjectEnumerator
- ManagementBaseObject
- set_RedirectStandardError
- get_StandardOutput
- get_StandardError
- RegistryValueKind
- ToUpperInvariant
- GetProcessesByName
- ManagementObject
- ObjectGetOptions
- GetMethodParameters
- InvokeMethodOptions
- Rfc2898DeriveBytes
- RijndaelManaged
- SymmetricAlgorithm
- CreateEncryptor
- ICryptoTransform
- CryptoStreamMode
- FlushFinalBlock
- ToBase64String
- FromBase64String
- CreateDecryptor
- GetSubKeyNames
- GetCallingAssembly
- GetManifestResourceStream
- DeleteSubKeyTree
- NetworkInterface
- System.Net.NetworkInformation
- GetAllNetworkInterfaces
- ManagementClass
- get_OperationalStatus
- OperationalStatus
- GetPhysicalAddress
- PhysicalAddress
- get_BasePriority
- FromMilliseconds
- System.ServiceProcess
- ServiceController
- ServiceControllerStatus
- WindowsIdentity
- System.Security.Principal
- WindowsPrincipal
- WindowsBuiltInRole
- WaitForPendingFinalizers
- OperatingSystem
- set_WindowStyle
- ProcessWindowStyle
- ToLowerInvariant
- RuntimeFieldHandle
- NtSetInformationProcess
- Nemesis_Recode
- SetProcessWorkingSetSize
- VirtualProtect
- GetModuleHandle
- GetProcAddress
- GetFileAttributes
- MulticastDelegate
- CompilationRelaxationsAttribute
- System.Runtime.CompilerServices
- RuntimeCompatibilityAttribute
- DebuggableAttribute
- DebuggingModes
- AssemblyTitleAttribute
- AssemblyDescriptionAttribute
- AssemblyConfigurationAttribute
- AssemblyCompanyAttribute
- AssemblyProductAttribute
- AssemblyCopyrightAttribute
- AssemblyTrademarkAttribute
- ComVisibleAttribute
- System.Runtime.InteropServices
- AssemblyFileVersionAttribute
- TargetFrameworkAttribute
- System.Runtime.Versioning
- CompilerGeneratedAttribute
- DebuggerBrowsableAttribute
- DebuggerBrowsableState
- System.Reflection.Emit
- GetFieldFromHandle
- get_MetadataToken
- ResolveSignature
- GetOptionalCustomModifiers
- GetCustomAttributes
- CreateDelegate
- get_DeclaringType
- get_ParameterType
- get_ReturnType
- get_IsInterface
- GetDynamicILInfo
- SetLocalSignature
- get_IsConstructor
- get_TypeHandle
- RuntimeTypeHandle
- get_MethodHandle
- RuntimeMethodHandle
- System.Collections.Generic
- FirstOrDefault
- InvalidOperationException
- EnterDebugMode
- GetPropertyValue
- ResolveAssembly
- ResolveEventArgs
- ConversionBack
- get_CurrentDomain
- ResolveEventHandler
- add_AssemblyResolve
- FolderChangesView
- simpleassembly
- Progress Telerik Fiddler Web Debugger
- ImmunityDebugger
- SimpleAssemblyExplorer
- Simple Assembly Explorer
- awfawgawgawgha
- awfawgfawawgawgawhw
- awgawgawwhaedawd
- opauhwfpoauwhgfpauoiwhg
- /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO
- Detected! && TIMEOUT 10"
- C:\ProgramData\Pizza
- C:\ProgramData\Pizza\
- Software\Microsoft\Windows\CurrentVersion\Internet Settings
- C:\WINDOWS\System32\Drivers\Etc\hosts
- C:\ProgramData\Karma
- C:\ProgramData\Karma\DisableProxy.txt
- /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO Proxy Enabled While Running Software! && TIMEOUT 10"
- pizzaxyz.bplaced.net
- grab.bplaced.net
- cdn.discordapp.com
- FiddlerCore4.dll
- Titanium.Web.Proxy.dll
- /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO Fidler DLL Detected While Running Software! && TIMEOUT 10"
- /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO Debugger atached! && TIMEOUT 10"
- Karma Spoofer |
- K |
- A |
- R |
- M |
- A |
- * |
- K |
- A |
- R |
- M |
- A |
- K |
- R |
- M |
- K |
- A |
- R |
- M |
- A |
- * |
- EpicGamesLauncher
- FortniteClient-Win64-Shipping
- C:\Windows\System32\config
- C:\Windows\Temp
- cmd /C "REG ADD HKLM\SYSTEM\HardwareConfig /v LastConfig /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v HwProfileGuid /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v GUID /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOwner /t REG_SZ /d %%random%%%%random%%%%random%% /f"
- cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOrganization /t REG_SZ /d %%random%%%%random%%%%random%% /f"
- cmd /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography" /v MachineGuid /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v BuildGUID /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}\Configuration\Variables\BusDeviceDesc" /v PropertyGuid /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\DeviceDesc" /v PropertyGuid /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation" /v ComputerHardwareId /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_SZ /d %%random%% /f"
- cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v ProductId /t REG_SZ /d %%random%%-%%random%%-%%random%%-%%random%% /f"
- cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOrganization /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD HKLM\System\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD HKLM\System\CurrentControlSet\Control\WMI\Security /v 671a8285-4edb-4cae-99fe-69a15c48c0bc /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion" "WindowsUpdate /v SusClientId /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f
- cmd /C "REG DELETE HKLM\Hardware\Description\System\BIOS /v BIOSVendor /f"
- cmd /C "REG DELETE HKLM\Hardware\Description\System\BIOS /v BIOSReleaseDate /f"
- cmd /C "REG DELETE HKLM\Hardware\Description\System\BIOS /v SystemManufacturer /f"
- cmd /C "REG DELETE HKLM\Hardware\Description\System\BIOS /v SystemProductName /f"
- cmd /C "REG DELETE HKLM\Hardware\Description\System\CentralProcessor\0 /v ProcessorNameString /f"
- cmd /C "REG DELETE HKLM\SYSTEM\HardwareConfig /f"
- cmd /C "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\Profile\Profile /v Guid /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
- cmd /C net stop FACEIT
- cmd /C net stop ESEADriver2
- cmd /C net stop BEDaisy
- cmd /C net stop EasyAntiCheat
- cmd /C "taskkill /f /im EpicGamesLauncher.exe >nul 2>&1"
- cmd /C "taskkill /f /im FortniteClient-Win64-Shipping_EAC.exe >nul 2>&1"
- cmd /C "taskkill /f /im FortniteClient-Win64-Shipping.exe >nul 2>&1"
- cmd /C "taskkill /f /im FortniteClient-Win64-Shipping_BE.exe >nul 2>&1"
- cmd /C "taskkill /f /im FortniteLauncher.exe >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\UnrealEngine\*.*" >nul 2>&1"
- cmd /C "rmdir /s /q "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame" "
- cmd /C "del /s /f /a:h /a:a /q "%%systemdrive%%\Users\%%username%%\AppData\Local\UnrealEngine\* .*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\Logs\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\Config\WindowsClient\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\LMS\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\Cloud\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Recovery\ntuser.sys\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\Public\Libraries\collection.dat\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Feeds\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\History\History.IE5\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Speech Graphics\Carnival\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\WER\Temp\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\*.*" >nul 2>&1"
- cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\UnrealEngine\*.*"
- cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\Logs\*.*"
- cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\*.*"
- cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\*.*"
- cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\Config\WindowsClient\*.*"
- cmd /C "del /f /s /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\*.*"
- cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\LMS\*.*"
- cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\Cloud\*.*"
- cmd /C "del /f /s /q "C:\Recovery\ntuser.sys\*.*"
- cmd /C "del /f /s /q "C:\Users\Public\Libraries\collection.dat\*.*"
- cmd /C "del /f /s /q "C:\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat\*.*"
- cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\WebCache\*.*"
- cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Feeds\*.*""
- cmd /C "del /f /s /q "C:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache\*.*"
- cmd /C "del /f /s /q "C:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules\*.*"
- cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\History\History.IE5\*.*"
- cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\Speech Graphics\Carnival\*.*"
- cmd /C "del /f /s /q "C:\ProgramData\Microsoft\Windows\WER\Temp\*.*"
- cmd /C "del /f /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5\*.*"
- cmd /C "del /f /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies\*.*"
- cmd /C "del /f /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\*.*"cmd /C "del /f /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\*.*"
- cmd /C "del /s /f /q C:\Windows\Public\Libraries\*.*"
- cmd /C "del /s /f /q C:\Windows\Prefetch\*.*"
- cmd /C "del /f /s /q C:\Intel\*.*""
- cmd /C "del /f /s /q C:\desktop.ini\*.*""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\UnrealEngine""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\Logs""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\LMS""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\Cloud""
- cmd /C "rmdir /s /q "C:\Recovery\ntuser.sys""
- cmd /C "rmdir /s /q "C:\Users\Public\Libraries\collection.dat""
- cmd /C "rmdir /s /q "C:\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Feeds""
- cmd /C "rmdir /s /q "C:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache""
- cmd /C "rmdir /s /q "C:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\History\History.IE5""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Speech Graphics\Carnival""
- cmd /C "rmdir /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5""
- cmd /C "rmdir /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies""
- cmd /C "rmdir /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData""
- cmd /C "rmdir /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content""
- cmd /C "rmdir /s /q "C:\Windows\Public\Libraries""
- cmd /C "rmdir /s /q "C:\Intel""
- cmd /C "rmdir /s /q "C:\desktop.ini""
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.jfm\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\INetCache\IE\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\Videos\Captures\desktop.ini\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\INetHistory\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Internet Explorer\CacheStorage\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Program Files (x86)\AMD\CNext\CCCSlim\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\NVIDIA Corporation\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\XboxLive\NSALCache\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\PlaceholderTileLogoFolder\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\LocalLow\Microsoft\CryptnetUrlCache\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\WebCache\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Themes\CachedFiles\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\Prefetch\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\LMS\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Diagnosis\EventStore.db-wal\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\perfc009.dat\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\perfh009.dat\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\PerfStringBackup.TMP\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\PerfStringBackup.INI\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\ntuser.dat.LOG2\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\wbem\Performance\WmiApRpl.ini\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\TEMP\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SoftwareDistribution\DataStore\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\WDI\LogFiles\StartupInfo\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SysWOW64\Gms.log\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\spp\store\2.0\cache\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\USOShared\Logs\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\WER\ERC\*.*"
- cmd /C "del /s /q /f /a ".\desktop.ini""
- cmd /C "del /s /ah desktop.ini."
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync\remotemetastore\v1\edb.log\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync\metastore\edb.log\*.*"cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Comms\Unistore\data\3\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Comms\Unistore\data\temp\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AppData\User\Default\Indexed DB\edb.log\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\b05132b02959bc64.automaticDestinations-ms\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\EasyAntiCheat\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTGraphicsPerfMonitorSession.etl\*.*"
- cmd /C "del /f /s /q "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame\*.*""
- cmd /C "rmdir /s /q "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame""
- cmd /C "RD /S /Q "%%localappdata%%\FortniteGame""
- cmd /C "RD /S /Q "%%localappdata%%\EpicGamesLauncher""
- cmd /C "RD /S /Q "%%localappdata%%\UnrealEngine""
- cmd /C "RD /S /Q "%%localappdata%%\UnrealEngineLauncher""
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\Recovery\Active\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!002\MicrosoftEdge\User\Default\AppCache\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Recent\Autom\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\rescache\_merged\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\ntuser.dat.LOG1\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\ntuser.dat.LOG2\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\OneDrive\settings\Personal\logUploaderSettings_temp.ini\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\OneDrive\settings\Personal\logUploaderSettings.ini\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\sru\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\OneDrive\logs\Common\DeviceHealthSummaryConfiguration.ini\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\Logs\MoSetup\UpdateAgent.log\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SoftwareDistribution\PostRebootEventCache.V2\{323558A6-0300-4C3E-97A0-EDEDFEB96B00}.bin\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync\metastore\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTGraphicsPerfMonitorSession.etl\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\NVIDIA Corporation\GfeSDK\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SoftwareDistribution\DataStore\Logs\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\Logs\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Comms\Unistore\data\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Comms\UnistoreDB\USS.jtx\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Feeds\*.*" >nul 2>&1\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGameOverlay_1.42.4001.0_x64__8wekyb3d8bbwe\ActivationStore.dat\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\DiagOutputDir\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\WebCache\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\ServiceState\EventLog\Data\lastalive0.dat\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\INetCache\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\WindowsUpdate.log\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SoftwareDistribution\DataStore\DataStore.edb\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log\*.*" >nul 2>&1"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\Safety\edge\remote\*.*" >nul 2>&1"cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SoftwareDistribution\DataStore\Logs\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\config\DEFAULT.LOG2\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\config\SYSTEM.LOG2\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\appcompat\appraiser\AltData\Appraiser_Data.ini\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\Logs\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\System Volume Information\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\dosvcState.dat.LOG1\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\appcompat\Programs\Amcache.hve.LOG1\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\ClipSVC\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\CloudStore\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePacken-GB_17763.9.22.0_neutral__8wekyb3d8bbwe\Windows\System32\driverstore\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\Logs\CBS\CBS.log\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\History\History.IE5\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\OneDrive\logs\Common\DeviceHealthSummaryConfiguration.ini\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\Logs\MoSetup\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Program Files (x86)\Common Files\BattlEye\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\AMD\DxCache\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\NVIDIA Corporation\GfeSDK\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\INetCookies\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\LogFiles\WMI\LwtNetLog.etl\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\ntuser.dat.LOG1\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\Notepad++\backup\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\temp\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\INF\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\WER\Temp\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\Shared Files\*.*"
- cmd /C "rmdir /s /q "C:\ProgramData\Microsoft\Windows\WER\Temp""
- cmd /C "rmdir /s /q "C:\Windows\temp""
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\OneDrive\logs\*.*"
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\TempState""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Roaming\EasyAntiCheat""
- cmd /C "del /s /f /a:h /a:a /q "C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys\*.*"
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations""
- cmd /C "rmdir /s /q "C:\Program Files (x86)\Common Files\BattlEye""
- cmd /C "del /s /f /a:h /a:a /q "C:\desktop.ini\*.*"
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\CloudStore""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\Config\WindowsClient""
- cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\regid.1991-06.com.microsoft\*.*"
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\WebCache""
- cmd /C "rmdir /s /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir""
- cmd /C "rmdir /s /q "C:\Windows\System32\LogFiles""
- cmd /C "rmdir /s /q "C:\Windows\Logs""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\OneDrive\logs""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\Explorer""
- cmd /C "rmdir /s /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\Shared Files""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Themes\CachedFiles""
- cmd /C "rmdir /s /q "C:\ProgramData\Microsoft\Wlansvc\Profiles\Interfaces""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\XboxLive""
- cmd /C "rmdir /s /q "C:\ProgramData\Microsoft\Windows\DeviceMetadataCache""
- cmd /C "rmdir /s /q "C:\Windows\ServiceState\EventLog""
- cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal\*.*"
- cmd /C "rmdir /s /q "C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.30.20002.0_neutral_split.scale-150_8wekyb3d8bbwe\Assets""
- cmd /C "rmdir /s /q "C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.30.20002.0_x64__8wekyb3d8bbwe\AppxMetadata""
- cmd /C "rmdir /s /q "C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.30.20002.0_x64__8wekyb3d8bbwe\Source""
- cmd /C "rmdir /s /q "C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.30.20002.0_x64__8wekyb3d8bbwe\Spotify""
- cmd /C "rmdir /s /q "C:\ProgramData\Microsoft\Windows\ClipSVC""
- cmd /C "rmdir /s /q "C:\Program Files\WindowsApps\Deleted""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache""cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync\metastore""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\LocalLow\Microsoft\CryptnetUrlCache""
- cmd /C "rmdir /s /q "C:\Windows\Prefetch""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings""
- cmd /C "rmdir /s /q "C:\Windows\SoftwareDistribution\PostRebootEventCache.V2""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\MicrosoftEdge\SharedCacheContainers""
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\Public\Libraries\collection.dat\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Feeds\*.*"
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Recent""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\History""
- cmd /C "rmdir /s /q "C:\Windows\AppReadiness""
- cmd /C "rmdir /s /q "C:\Windows\System32\WDI""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame""
- cmd /C "rmdir /s /q "C:\Windows\SoftwareDistribution\DataStore\Logs""
- cmd /C "rmdir /s /q "C:\Windows\INF""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\INetCache""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync\remotemetastore""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\Explorer\ThumbCacheToDelete""
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Comms\UnistoreDB\USS.jtx""
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\config\BBI.LOG2\*.*"
- cmd /C "rmdir /s /q "C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive""
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\appcompat\Programs\Amcache.hve\*.*"
- cmd /C "rmdir /s /q "C:\Windows\System32\spp\store\2.0\cache""
- cmd /C "rmdir /s /q "C:\Windows\TEMP""
- cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe\ActivationStore.dat\*.*"
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\LocalCache""
- cmd /C "rmdir /s /q "C:\Windows\System32\winevt\Logs""
- cmd /C "rmdir /s /q "C:\Windows\SoftwareDistribution\SLS""
- cmd /C "rmdir /s /q "C:\Windows\SoftwareDistribution\DataStore""
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\dosvcState.dat.LOG2\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-ClassPnP%%4Operational.evtx\*.*"
- cmd /C "rmdir /s /q "C:\Recovery""
- cmd /C "rmdir /s /q "C:\MSOCache""
- cmd /C "rmdir /s /q "D:\Recovery""
- cmd /C "del /s /f /a:h /a:a /q "D:\Users\Public\Libraries\collection.dat\*.*" >nul 2>&1"
- cmd /C "rmdir /s /q "D:\MSOCache""
- cmd /C "del /f /s /q D:\desktop.ini\*.*""
- cmd /C "rmdir /s /q "E:\Recovery""
- cmd /C "del /s /f /a:h /a:a /q "E:\Users\Public\Libraries\collection.dat\*.*" >nul 2>&1"
- cmd /C "rmdir /s /q "E:\MSOCache""
- cmd /C "del /f /s /q E:\desktop.ini\*.*""
- cmd /C "rmdir /s /q "F:\Recovery""
- cmd /C "del /s /f /a:h /a:a /q "F:\Users\Public\Libraries\collection.dat\*.*" >nul 2>&1"
- cmd /C "rmdir /s /q "F:\MSOCache""
- cmd /C "del /f /s /q F:\desktop.ini\*.*""
- cmd /C "rd /q /s C:\$Recycle.Bin"
- cmd /C "rd /q /s d:\$Recycle.Bin"
- cmd /C "rd /q /s e:\$Recycle.Bin"
- cmd /C "rd /q /s f:\$Recycle.Bin"
- cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography" /v MachineGuid /t REG_SZ /d %%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex1%%-%%Hex10%% /f>nul 2>&1"
- cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v BuildGUID /t REG_SZ /d %%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex1%%-%%Hex10%% /f>nul 2>&1"
- cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}\Configuration\Variables\BusDeviceDesc" /v PropertyGuid /t REG_SZ /d {%%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex1%%-%%Hex10%%} /f>nul 2>&1"
- cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\DeviceDesc" /v PropertyGuid /t REG_SZ /d {%%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex1%%-%%Hex10%%} /f>nul 2>&1"
- cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\Driver" /v PropertyGuid /t REG_SZ /d {%%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex1%%-%%Hex10%%} /f>nul 2>&1W"
- cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation" /v ComputerHardwareId /t REG_SZ /d {%%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex1%%-%%Hex10%%} /f>nul 2>&1"
- cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d %%Hex1%%-%%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex10%% /f"
- cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d %%Hex1%%-%%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex10%% /f"
- cmd /C "REG ADD HKLM\System\CurrentControlSet\Control\WMI\Security /v 671a8285-4edb-4cae-99fe-69a15c48c0bc /t REG_SZ /d %%random%% /f"
- cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion" "WindowsUpdate /v SusClientId /t REG_SZ /d {C-H-E-A-T-L-O-V-E-R-Z-%%random%%%%random%%-%%random%%} /f"
- cmd /C "reg delete "HKEY_CLASSES_ROOT\com.epicgames.launcher" /f"
- cmd /C "reg delete "HKEY_CURRENT_USER\SOFTWARE\Epic Games" /f"
- cmd /C "reg delete "HKEY_CURRENT_USER\SOFTWARE\EpicGames" /f"
- cmd /C "reg delete "HKEY_CURRENT_USER\Software\Classes\Installer\Dependencies" /v MSICache /f"
- cmd /C "reg delete "HKEY_CURRENT_USER\Software\Classes\com.epicgames.launcher" /f"
- cmd /C "reg delete "HKEY_CURRENT_USER\Software\Epic Games" /f"
- cmd /C "reg delete "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine" /f"
- cmd /C "reg delete "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Hardware Survey" /f"
- cmd /C "reg delete "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Identifiers" /f"
- cmd /C "reg delete "HKEY_CURRENT_USER\Software\Microsoft\Direct3D" /v WHQLClass /f"
- cmd /C "reg delete "HKEY_CURRENT_USER\Software\WOW6432Node\Epic Games" /f"
- cmd /C "reg delete "HKEY_LOCAL_MACHINE\Hardware\Description\System\CentralProcessor\0" /v ProcessorNameString /f"
- cmd /C "reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\com.epicgames.launcher" /f"
- cmd /C "reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Epic Games" /f"
- cmd /C "reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\EpicGames" /f"
- cmd /C "reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Epic Games" /f"
- cmd /C "reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\EpicGames" /f"
- cmd /C "reg delete "HKEY_LOCAL_MACHINE\SYSTEM\HardwareConfig" /f"
- cmd /C "reg delete "HKEY_LOCAL_MACHINE\Software\Epic Games" /f"
- cmd /C "reg delete "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control" /v SystemStartOptions /f"
- cmd /C "reg delete "HKEY_USERS\S-1-5-21-2097722829-2509645790-3642206209-1001\Software\Epic Games" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5e4eddc4_0\: "{2}.\\?\hdaudio#func_01&ven_10ec&dev_0290&subsys_103c80df&rev_1000#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\singlelineouttopo/00010001|\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe%%b{00000000-0000-0000-0000-000000000000}"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Program Files\Windows NT\Accessories\WORDPAD.EXE,-190: "Rich Text Document"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Windows\system32\zipfldr.dll,-10195: "Compressed (zipped) Folder"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Program Files\Common Files\system\wab32res.dll,-10203: "Contact"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Windows\System32\ieframe.dll,-5723: "The Internet"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Program Files (x86)\Common Files\Microsoft Shared\MSEnv\1033\\VSLauncherUI.dll,-1002: "Open in &Visual Studio"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\Microsoft.XboxGameOverlay_8wekyb3d8bbwe!App" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\FortniteClient-Win64-Shipping.exe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\Package\181" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\Package\181\93" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\PackageAndPackageRelativeApplicationId\181^App" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\PackageAndPackageRelativeApplicationId\181^App\93" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ac" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ad" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplication\3^93" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplication\3^93\ac" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplication\4^93" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplication\4^93\ad" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFamily\4e\180" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFamily\4e\181" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFamily\4e\182" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe\182" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\180" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\181" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a80" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a81" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a82" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a83" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a84" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\User\3\1a80" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\User\3\1a81" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\User\3\1a82" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\User\4\1a83" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\User\4\1a84" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\3^180" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\3^180\1a80" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\3^181" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\3^181\1a81" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\3^182" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\3^182\1a82" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\4^180" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\4^180\1a83" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\4^181" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\4^181\1a84" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x86__8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x86__8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\Security" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\Security" /f"
- cmd /C "reg delete "HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher" /f"
- cmd /C "reg delete "HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates" /f"
- cmd /C "reg delete "HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs" /f"
- cmd /C "reg delete "HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs" /f"
- cmd /C "reg delete "HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher" /f"
- cmd /C "reg delete "HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates" /f"
- cmd /C "reg delete "HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs" /f"
- cmd /C "reg delete "HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5e4eddc4_0" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5e4eddc4_0\{219ED5A0-9CBF-4F3A-B927-37C9E5C5F14F}" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\0" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000205B6" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000403D6" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000405DE" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000060286" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000009042E" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000A03B4" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000A0430" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000B0532" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000B05D6" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000C0430" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000C0586" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000E03D2" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000E0406" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000100430" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001103EE" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000011041E" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000012047E" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001303EE" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001304F2" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000014041E" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001703E6" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000170440" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001704FC" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499\87f345c2" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572\DefaultIcon" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572\shell" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572\shell\open" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572\shell\open\command" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Parents\fd13f746e7d2d69760b017363f621255c9b49ac8" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499\87f345c2" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572\DefaultIcon" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572\shell" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572\shell\open" /f"cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572\shell\open\command" /f"
- cmd /C "reg delete "HKU\S-1-5-18\Software\Microsoft\SystemCertificates\TrustedPublisher" /f"
- cmd /C "reg delete "HKU\S-1-5-18\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates" /f"
- cmd /C "reg delete "HKU\S-1-5-18\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs" /f"
- cmd /C "reg delete "HKU\S-1-5-18\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs" /f"
- cmd /C "reg delete "HKU\S-1-5-18\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher" /f"
- cmd /C "reg delete "HKU\S-1-5-18\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates" /f"
- cmd /C "reg delete "HKU\S-1-5-18\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs" /f"
- cmd /C "reg delete "HKU\S-1-5-18\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Extensions\ProgIDs\AppXm8fs0gj5h36ynw4kq0x3gqnz6ecr1kvy\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe: (NULL!)" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\FortniteClient-Win64-Shipping.exe\LastDetectionTime: F9 8F FD B6 8D 13 D5 01" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\AppPackageType: 0x00000000" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\PackageSid: "S-1-15-2-1823635404-1364722122-2170562666-1762391777-2399050872-3465541734-3732476201"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\EnterpriseID: 0x00000000" /f"
- cmd /C "reg delete " 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\ApplicationFlags: 0x00000000" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\Origins\kz2LMQg4+pNfXggv65DcWFQ9SiekWR4B4WMWT+pcqbU: 0x00000002" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\Origins\4JSyFFDDKUMXDyK2USgAjbiksFnqOb3f8RPZBPSpEfU: 0x00000002" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\Origins\62bDlCzxB/xxIWLkQdDRYcAqhmZhNOMUtjhRkAgTvkQ: 0x00000002" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\Package: 0x00000181" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\Index: 0x00000000" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\Flags: 0x00000000" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\PackageRelativeApplicationId: "App"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\ApplicationUserModelId: "Microsoft.XboxGameOverlay_8wekyb3d8bbwe!App"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\Executable: "GameBar.exe"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\Entrypoint: "GameBar.App"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\StartPage: (NULL!)" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\_IndexKeys: 50 61 63 6B 61 67 65 5C 31 38 31 5C 39 33 00 50 61 63 6B 61 67 65 41 6E 64 50 61 63 6B 61 67 65 52 65 6C 61 74 69 76 65 41 70 70 6C 69 63 61 74 69 6F 6E 49 64 5C 31 38 31 5E 41 70 70 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ac\Application: 0x00000093" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ac\User: 0x00000003" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ac\ApplicationUserModelId: "Microsoft.XboxGameOverlay_8wekyb3d8bbwe!App"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ac\_IndexKeys: 55 73 65 72 41 6E 64 41 70 70 6C 69 63 61 74 69 6F 6E 5C 33 5E 39 33 00 55 73 65 72 41 6E 64 41 70 70 6C 69 63 61 74 69 6F 6E 55 73 65 72 4D 6F 64 65 6C 49 64 5C 33 5E 4D 69 63 72 6F 73 6F 66 74 2E 58 62 6F 78 47 61 6D 65 4F 76 65 72 6C 61 79 5F 38 77 65 6B 79 62 33 64 38 62 62 77 65 21 41 70 70 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ad\Application: 0x00000093" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ad\User: 0x00000004" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ad\ApplicationUserModelId: "Microsoft.XboxGameOverlay_8wekyb3d8bbwe!App"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ad\_IndexKeys: 55 73 65 72 41 6E 64 41 70 70 6C 69 63 61 74 69 6F 6E 5C 34 5E 39 33 00 55 73 65 72 41 6E 64 41 70 70 6C 69 63 61 74 69 6F 6E 55 73 65 72 4D 6F 64 65 6C 49 64 5C 34 5E 4D 69 63 72 6F 73 6F 66 74 2E 58 62 6F 78 47 61 6D 65 4F 76 65 72 6C 61 79 5F 38 77 65 6B 79 62 33 64 38 62 62 77 65 21 41 70 70 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\PackageFullName: "Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\PackageFamily: 0x0000004E" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\PackageType: 0x00000008" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\Flags: 0x00000000" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\PackageOrigin: 0x00000003" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\Volume: 0x00000001" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\InstalledLocation: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\_IndexKeys: 50 61 63 6B 61 67 65 46 61 6D 69 6C 79 5C 34 65 5C 31 38 30 00 50 61 63 6B 61 67 65 46 75 6C 6C 4E 61 6D 65 5C 4D 69 63 72 6F 73 6F 66 74 2E 58 62 6F 78 47 61 6D 65 4F 76 65 72 6C 61 79 5F 31 2E 34 31 2E 32 34 30 30 31 2E 30 5F 6E 65 75 74 72 61 6C 5F 7E 5F 38 77 65 6B 79 62 33 64 38 62 62 77 65 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\PackageFullName: "Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\PackageFamily: 0x0000004E" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\PackageType: 0x00000001" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\Flags: 0x00000000" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\PackageOrigin: 0x00000003" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\Volume: 0x00000001" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\InstalledLocation: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\_IndexKeys: 50 61 63 6B 61 67 65 46 61 6D 69 6C 79 5C 34 65 5C 31 38 31 00 50 61 63 6B 61 67 65 46 75 6C 6C 4E 61 6D 65 5C 4D 69 63 72 6F 73 6F 66 74 2E 58 62 6F 78 47 61 6D 65 4F 76 65 72 6C 61 79 5F 31 2E 34 31 2E 32 34 30 30 31 2E 30 5F 78 36 34 5F 5F 38 77 65 6B 79 62 33 64 38 62 62 77 65 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\PackageFullName: "Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\PackageFamily: 0x0000004E" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\PackageType: 0x00000004" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\Flags: 0x00000000" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\PackageOrigin: 0x00000003" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\Volume: 0x00000001" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\InstalledLocation: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\_IndexKeys: 50 61 63 6B 61 67 65 46 61 6D 69 6C 79 5C 34 65 5C 31 38 32 00 50 61 63 6B 61 67 65 46 75 6C 6C 4E 61 6D 65 5C 4D 69 63 72 6F 73 6F 66 74 2E 58 62 6F 78 47 61 6D 65 4F 76 65 72 6C 61 79 5F 31 2E 34 31 2E 32 34 30 30 31 2E 30 5F 6E 65 75 74 72 61 6C 5F 73 70 6C 69 74 2E 73 63 61 6C 65 2D 31 30 30 5F 38 77 65 6B 79 62 33 64 38 62 62 77 65 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a80\Package: 0x00000180" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a80\User: 0x00000003" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a80\_IndexKeys: 55 73 65 72 5C 33 5C 31 61 38 30 00 55 73 65 72 41 6E 64 50 61 63 6B 61 67 65 5C 33 5E 31 38 30 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a81\Package: 0x00000181" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a81\User: 0x00000003" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a81\_IndexKeys: 55 73 65 72 5C 33 5C 31 61 38 31 00 55 73 65 72 41 6E 64 50 61 63 6B 61 67 65 5C 33 5E 31 38 31 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a82\Package: 0x00000182" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a82\User: 0x00000003" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a82\_IndexKeys: 55 73 65 72 5C 33 5C 31 61 38 32 00 55 73 65 72 41 6E 64 50 61 63 6B 61 67 65 5C 33 5E 31 38 32 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a83\Package: 0x00000180" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a83\User: 0x00000004" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a83\_IndexKeys: 55 73 65 72 5C 34 5C 31 61 38 33 00 55 73 65 72 41 6E 64 50 61 63 6B 61 67 65 5C 34 5E 31 38 30 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a84\Package: 0x00000181" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a84\User: 0x00000004" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a84\_IndexKeys: 55 73 65 72 5C 34 5C 31 61 38 34 00 55 73 65 72 41 6E 64 50 61 63 6B 61 67 65 5C 34 5E 31 38 31 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\AppxMetadata\AppxBundleManifest.xml"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\AppxManifest.xml"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x86__8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.27323.0_x86__8wekyb3d8bbwe\AppxManifest.xml"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\AppxMetadata\AppxBundleManifest.xml"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\LastReturnValue: 0x00000000" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\NumberOfAttempts: 0x00000001" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\AppxManifest.xml"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x86__8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.27323.0_x86__8wekyb3d8bbwe\AppxManifest.xml"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\VolatileNotifications\41C64E6DA3D39855: 01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00 14 00 00 00 02 00 1C 00 01 00 00 00 00 00 14 00 03 00 00 00 01 01 00 00 00 00 00 05 0B 00 00 00 04 00 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\VolatileNotifications\41C64E6DA3CF4055: 01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00 14 00 00 00 02 00 1C 00 01 00 00 00 00 00 14 00 03 00 00 00 01 01 00 00 00 00 00 05 0B 00 00 00 04 00 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\Google\Update\UsageStats\Daily\Counts\cup_ecdsa_http_failure: 01 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\AppPackageType: 0x00000000" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\PackageSid: "S-1-15-2-1823635404-1364722122-2170562666-1762391777-2399050872-3465541734-3732476201"" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\EnterpriseID: 0x00000000" /f"
- cmd /C "reg delete " 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\ApplicationFlags: 0x00000000" /f"
- cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\GamesInstalled: "217;"" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862software: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 43 61 63 68 65 5C 35 63 38 63 62 62 36 61 61 37 65 61 31 34 32 34 2E 64 61 74 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862user_sid: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 55 73 65 72 2E 64 61 74 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862user_classes: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 55 73 65 72 43 6C 61 73 73 65 73 2E 64 61 74 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Control\hivelist\\REGISTRY\WC\Siloe6b4a779-bfe1-62d8-47ac-fa19e9becbbecom: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 43 61 63 68 65 5C 35 63 38 63 62 62 36 61 61 37 65 61 31 34 32 34 5F 43 4F 4D 31 35 2E 64 61 74 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862com: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 43 61 63 68 65 5C 35 63 38 63 62 62 36 61 61 37 65 61 31 34 32 34 2E 64 61 74 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-2532382528-581214834-2534474248-1001\\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping_EAC.exe: B1 8A B0 E9 8D 13 D5 01 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-2532382528-581214834-2534474248-1001\\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\EasyAntiCheat\EasyAntiCheat_Setup.exe: 73 D5 4B 11 8D 13 D5 01 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-2532382528-581214834-2534474248-1001\\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe: E7 CB 84 E9 8D 13 D5 01 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\Type: 0x00000010" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\Start: 0x00000003" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\ErrorControl: 0x00000001" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\ImagePath: ""C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe""" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\DisplayName: "EasyAntiCheat"" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\WOW64: 0x0000014C" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\ObjectName: "LocalSystem"" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\Description: "Provides integrated security and services for online multiplayer games."" /f"
- cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\Security\Security: 01 00 14 80 A0 00 00 00 AC 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 70 00 05 00 00 00 00 00 14 00 30 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 04 00 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 06 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862software: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 43 61 63 68 65 5C 35 63 38 63 62 62 36 61 61 37 65 61 31 34 32 34 2E 64 61 74 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862user_sid: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 55 73 65 72 2E 64 61 74 00 00" /f"cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862user_classes: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 55 73 65 72 43 6C 61 73 73 65 73 2E 64 61 74 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Control\hivelist\\REGISTRY\WC\Siloe6b4a779-bfe1-62d8-47ac-fa19e9becbbecom: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 43 61 63 68 65 5C 35 63 38 63 62 62 36 61 61 37 65 61 31 34 32 34 5F 43 4F 4D 31 35 2E 64 61 74 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862com: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 43 61 63 68 65 5C 35 63 38 63 62 62 36 61 61 37 65 61 31 34 32 34 2E 64 61 74 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-2532382528-581214834-2534474248-1001\\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-2532382528-581214834-2534474248-1001\\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\EasyAntiCheat\EasyAntiCheat_Setup.exe: 73 D5 4B 11 8D 13 D5 01 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-2532382528-581214834-2534474248-1001\\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe: E7 CB 84 E9 8D 13 D5 01 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\Type: 0x00000010" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\Start: 0x00000003" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\ErrorControl: 0x00000001" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\ImagePath: ""C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe""" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\DisplayName: "EasyAntiCheat"" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\WOW64: 0x0000014C" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\ObjectName: "LocalSystem"" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\Description: "Provides integrated security and services for online multiplayer games."" /f"
- cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\Security\Security: 01 00 14 80 A0 00 00 00 AC 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 70 00 05 00 00 00 00 00 14 00 30 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 04 00 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 06 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5e4eddc4_0\{219ED5A0-9CBF-4F3A-B927-37C9E5C5F14F}\3: 04 00 00 00 00 00 00 00 00 00 80 3F 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5e4eddc4_0\{219ED5A0-9CBF-4F3A-B927-37C9E5C5F14F}\4: 04 20 00 00 00 00 00 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 3F 00 00 80 3F" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5e4eddc4_0\{219ED5A0-9CBF-4F3A-B927-37C9E5C5F14F}\5: 0B 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "70 00 74 00 69 00 70 00 73 00 2D 00 54 00 69 00 74 00 6C 00 65 00 49 00 64 00 3D 00 31 00 38 00 32 00 30 00 32 00 35 00 30 00 37 00 38 00 38 00 26 00 50 00 72 00 6F 00 63 00 65 00 73 00 73 00 49 00 64 00 3D 00 36 00 31 00 39 00 36 00 26 00 57 00 69 00 6E 00 64 00 6F 00 77 00 49 00 64 00 3D 00 32 00 36 00 33 00 31 00 32 00 36 00 2E 00 6C 00 6E 00 6B 00 00 00 62 00 00 00" /f"
- cmd /C "reg delete " 9E EB AC 0C 00 00 00 50 00 00 00 A6 6A 63 28 3D 95 D2 11 B5 D6 00 C0 4F D9 18 D0 0B 00 00 00 78 00 00 00 30 F1 25 B7 EF 47 1A 10 A5 F1 02 60 8C 9E EB AC 0E 00 00 00 78 00 00 00 2F 00 00 00 1E 00 00 00 00 47 00 72 00 6F 00 75 00 70 00 42 00 79 00 4B 00 65 00 79 00 3A 00 50 00 49 00 44 00 00 00 13 00 00 00 00 00 00 00 1F 00 00 00 0E 00 00 00 00 46 00 46 00 6C 00 61 00 67 00 73 00 00 00 13 00 00 00 11 00 20 01 31 00 00 00 20 00 00 00 00 4C 00 6F 00 67 00 69 00 63 00 61 00 6C 00 56 00 69 00 65 00 77 00 4D 00 6F 00 64 00 65 00 00 00 13 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Rcvp Tnzrf\Sbegavgr\SbegavgrTnzr\Ovanevrf\Jva64\SbegavgrPyvrag-Jva64-Fuvccvat_RNP.rkr: 01 00 00 00 00 00 00 00 02 00 00 00 FB 2C 00 00 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF FF FF FF FF 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Rcvp Tnzrf\Sbegavgr\SbegavgrTnzr\Ovanevrf\Jva64\RnflNagvPurng\RnflNagvPurng_Frghc.rkr: 01 00 00 00 00 00 00 00 01 00 00 00 35 0C 00 00 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF FF FF FF FF 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Rcvp Tnzrf\Sbegavgr\SbegavgrTnzr\Ovanevrf\Jva64\SbegavgrPyvrag-Jva64-Fuvccvat.rkr: 01 00 00 00 00 00 00 00 04 00 00 00 AF B4 02 00 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF FF FF FF FF 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000020552\CloakType: 04 00 00 00 30 30 54 43 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000703C4\CloakType: 04 00 00 00 30 30 54 43 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000205B6\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000403D6\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000405DE\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000060286\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000009042E\VirtualDesktop: 10 00 00 00 30 30 44 56 8A 14 1B 02 6F DF F6 46 96 A2 BA 8C 49 3E 6C EE" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000009042E\CloakType: 04 00 00 00 30 30 54 43 02 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000A03B4\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000A0430\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000B0532\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000B05D6\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000C0430\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000C0586\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000E03D2\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000E0406\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000100430\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000100430\CloakType: 04 00 00 00 30 30 54 43 02 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001103EE\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000011041E\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000012047E\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001303EE\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001304F2\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000014041E\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001703E6\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000170440\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001704FC\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\VirtualDesktops\CurrentVirtualDesktop: B5 05 CB 90 C0 9D AF 44 93 6E 8E 33 22 0E 1E 9A" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU\MRUListEx: 00 00 00 00 FF FF FF FF" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU\0: 14 00 1F 78 40 F0 5F 64 81 50 1B 10 9F 08 00 AA 00 2F 95 4E 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Search\JumplistData\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe!App: 6F 70 0D 53 8D 13 D5 01" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.44.40.1000_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe: 53 41 43 50 01 00 00 00 00 00 00 00 07 00 00 00 28 00 00 00 00 EA 08 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 0A 73 20 00 00 67 07 7C BA C5 4C D4 01 00 00 00 00 00 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\EasyAntiCheat\EasyAntiCheat_Setup.exe: 53 41 43 50 01 00 00 00 00 00 00 00 07 00 00 00 28 00 00 00 70 42 0C 00 0E EB 0C 00 01 00 00 00 00 00 00 00 00 00 03 06 00 01 00 00 67 07 7C BA C5 4C D4 01 00 00 00 00 00 00 00 00 02 00 00 00 28 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 83 0C 00 00 00 00 00 00 01 00 00 00 01 00 00 00" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499\87f345c2\LanguageList: 5F 65 6E 2D 55 53 5F 73 74 61 6E 64 61 72 64 5F 31 32 35 5F 55 53 5F 4C 54 52 5F 6C 69 67 68 74 5F 44 65 73 6B 74 6F 70" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499\87f345c2\{Microsoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.XboxGamingOverlay/resources/GameBar}: "Game bar"" /f"cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Program Files\Common Files\System\wab32res.dll,-4602: "Contact file"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Program Files (x86)\Common Files\Microsoft Shared\MSEnv\1033\\VSLauncherUI.dll,-1002: "Open in &Visual Studio"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\windows.storage.dll,-21826: "Captures"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572\DefaultIcon\: "C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572\shell\open\command\: "C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe"" /f"cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\Type: 0x00000001" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\Revision: 0x00000749" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\Flags: 0x00000011" /f"
- cmd /C "reg delete " C9 73 F7" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\GameDVR_GameGUID: "284ea1b3-f5e7-4133-b521-74a8d9ae997e"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\TitleId: "1820250788"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\MatchedExeFullPath: 43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73 5C 45 70 69 63 20 47 61 6D 65 73 5C 46 6F 72 74 6E 69 74 65 5C 46 6F 72 74 6E 69 74 65 47 61 6D 65 5C 42 69 6E 61 72 69 65 73 5C 57 69 6E 36 34 5C 46 6F 72 74 6E 69 74 65 43 6C 69 65 6E 74 2D 57 69 6E 36 34 2D 53 68 69 70 70 69 6E 67 2E 65 78 65" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\LastAccessed: 50 3B 6E 52 8D 13 D5 01" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Parents\fd13f746e7d2d69760b017363f621255c9b49ac8\Children: "03ce6902-ff58-41de-ab92-36fcaf27a580"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499\87f345c2\LanguageList: 5F 65 6E 2D 55 53 5F 73 74 61 6E 64 61 72 64 5F 31 32 35 5F 55 53 5F 4C 54 52 5F 6C 69 67 68 74 5F 44 65 73 6B 74 6F 70" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499\87f345c2\{Microsoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.XboxGamingOverlay/resources/GameBar}: "Game bar"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Program Files\Common Files\System\wab32res.dll,-4602: "Contact file"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MuiCache\ab\52C64B7E\windows.storage.dll,-21826: "Captures"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572\DefaultIcon\: "C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe"" /f"
- cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572\shell\open\command\: "C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe"" /f"
- cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Temp""
- cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\Temp\*.*"
- cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Temp\*.*" >nul 2>&1"
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName /v ComputerName /t REG_SZ /d r%random% /f >nul 2>&1
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName /v ComputerName /t REG_SZ /d r%random% /f >nul 2>&1
- REG ADD HKLM\SYSTEM\HardwareConfig /v LastConfig /t REG_SZ /d {be%random%} /f >nul 2>&1
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v HwProfileGuid /t REG_SZ /d {fefefee%random%-%random%-%random%-%random%} /f >nul 2>&1
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v GUID /t REG_SZ /d {fefefe%random%-%random%-%random%-%random%} /f >nul 2>&1
- REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d r%random% /f >nul 2>&1
- REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOwner /t REG_SZ /d r%random% /f >nul 2>&1
- REG ADD HKL\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOrganization /t REG_SZ /d r%random% /f >nul 2>&1
- REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d r%random%-%random%-%random%-%random% /f >nul 2>&1
- REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d hello%random%-%random%-%random%-%random% /f >nul 2>&1
- REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v ProductId /t REG_SZ /d %random%-%random%-%random%-%random% /f >nul 2>&1
- REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_SZ /d %random% /f >nul 2>&1
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {randomd%random%-%random%-%random%-%random%} /f >nul 2>&1
- REG ADD HKLM\SYSTEM\HardwareConfig /v LastConfig /t REG_SZ /d {BE%random%} /f >nul 2>&1
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v HwProfileGuid /t REG_SZ /d {%random%-%random%-%random%-%random%} /f >nul 2>&1
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v GUID /t REG_SZ /d {%random%-%random%-%random%-%random%} /f >nul 2>&1
- REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d %random% /f >nul 2>&1
- REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOwner /t REG_SZ /d %random% /f >nul 2>&1
- REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOrganization /t REG_SZ /d %random% /f >nul 2>&1
- REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d %random%-%random%-%random%-%random% /f >nul 2>&1
- REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d %random%-%random%-%random%-%random% /f >nul 2>&1
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {%random%-%random%-%random%-%random%} /f >nul 2>&1
- reg delete "HKEY_CURRENT_USER\Software\Epic Games" /f >nul 2>&1
- reg delete "HKEY_CURRENT_USER\Software\WOW6432Node\Epic Games" /f >nul 2>&1
- reg delete "HKEY_CURRENT_USER\Software\Classes\com.epicgames.launcher" /f >nul 2>&1
- reg delete "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Identifiers" /f >nul 2>&1
- reg delete "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Hardware Survey" /f >nul 2>&1
- reg delete "HKEY_CLASSES_ROOT\com.epicgames.launcher" /f >nul 2>&1
- del /s /f /a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\UnrealEngine\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Logs\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Config\WindowsClient\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\LMS\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Cloud\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Recovery\ntuser.sys\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Users\Public\Libraries\collection.dat\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Feeds\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\Rules\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\History\History.IE5\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\Speech Graphics\Carnival\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\ProgramData\Microsoft\Windows\WER\Temp\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\*.*" >nul 2>&1
- del / s / f / a:h / a:a / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\*.*" >nul 2>&1
- del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\UnrealEngine\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Logs\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Config\WindowsClient\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\LMS\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Cloud\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Recovery\ntuser.sys\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Users\Public\Libraries\collection.dat\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Feeds\*.*" >nul 2>&1
- del / f / s / q "%systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache\*.*>nul 2>&1
- del / f / s / q "%systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\Rules\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\History\History.IE5\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\Speech Graphics\Carnival\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\ProgramData\Microsoft\Windows\WER\Temp\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\*.* >nul 2>&1
- del / f / s / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\*.* >nul 2>&1
- del / s / f / q % systemdrive %\Windows\Public\Libraries\*.* > nul 2 > &1
- del / s / f / q % systemdrive %\Windows\Prefetch\*.* > nul 2 > &1
- del / f / s / q % systemdrive %\Intel\*.*" >nul 2>&1
- rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\UnrealEngine" >nul 2>&1
- rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\EpicGamesLauncher\Saved\Logs" >nul 2>&1
- rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage" >nul 2>&1
- rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache" >nul 2>&1
- rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\FortniteGame\Saved\Config\WindowsClient" >nul 2>&1
- rmdir / s / q % systemdrive %\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir" >nul 2>&1
- rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\FortniteGame\Saved\LMS" >nul 2>&1
- rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\FortniteGame\Saved\Cloud" >nul 2>&1
- rmdir / s / q % systemdrive %\Recovery\ntuser.sys" >nul 2>&1
- rmdir / s / q % systemdrive %\Users\Public\Libraries\collection.dat" >nul 2>&1
- rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\Microsoft\Windows\WebCache" >nul 2>&1
- rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Feeds" >nul 2>&1
- rmdir /s /q %systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache" >nul 2>&1
- rmdir /s /q %systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\Rules" >nul 2>&1
- rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\History\History.IE5" >nul 2>&1
- rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Speech Graphics\Carnival" >nul 2>&1
- rmdir /s /q %systemdrive%\ProgramData\Microsoft\Windows\WER\Temp" >nul 2>&1
- rmdir /s /q %systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5" >nul 2>&1
- rmdir /s /q %systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies" >nul 2>&1
- rmdir /s /q %systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData" >nul 2>&1
- rmdir /s /q %systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content" >nul 2>&1
- rmdir /s /q %systemdrive%\Windows\Public\Libraries" >nul 2>&1
- rmdir /s /q %systemdrive%\Windows\Prefetch" >nul 2>&1
- rmdir /s /q %systemdrive%\Intel" >nul 2>&1
- del /f /s /q %systemdrive%\*.tmp
- del /f /s /q %systemdrive%\*._mp
- del /f /s /q %systemdrive%\*.gid
- del /f /s /q %systemdrive%\*.chk
- del /f /s /q %systemdrive%\*.old
- del /f /s /q %windir%\*.bak
- C:\Windows\System32\eac_usermode_21537346703536.dll
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive
- C:\Windows\appcompact\Programs\Amcache.hve
- C:\Windows\System32\LogFiles\WMI\EtwRTGraphicsPerfMonitorSession.etl
- C:\Windows\System\config\BBI.LOG2
- \AppData\Local\UnrealEngine
- \AppData\Local\UnrealEngineLauncher
- \AppData\Local\EpicGamesLauncher
- \AppData\Local\FortniteGame
- \AppData\Local\NVIDIA Corporation
- \AppData\Local\Speech Graphics
- \AppData\Local\Packages
- \AppData\Local\AMD\DxCache
- \AppData\Local\Microsoft\Windows\WebCache\V01.chk
- \AppData\Local\Microsoft\Windows\INetCache
- \AppData\Roaming\Microsoft\Windows\Recent
- \AppData\Local\Microsoft\Windows\Notifications
- \AppData\Local\Microsoft\Windows\ActionCenterCache
- \AppData\Roaming\EasyAntiCheat
- \AppData\Roaming\Microsoft\Windows\CloudStore
- \AppData\Local\Microsoft\Feeds
- C:\Program Files\Epic Games\Fortnite.lysEB
- C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir
- C:\Program Files\Epic Games\Fortnite\EAAC0DED42EADD813C76C2B26C315591
- C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe.local
- C:\ProgramData\Epic\EpicGamesLauncher\Data\EMS\current
- C:\ProgramData\Epic\UnrealEngineLauncher\LauncherInstalled.dat
- \AppData\Local\FortniteGame\Saved\LMS\Manifest.sav
- \AppData\Local\Local\Temp\1CF4.tmp
- \AppData\Local\Local\Temp\1CF4.tmp\1CF5.bat
- C:Windows\System32\spp\store\2.0\data.dat
- \AppData\Local\Microsoft\Windows\INetCache\
- C:\Users\Public
- \AppData\Local\Microsoft\OneDrive\settings\Personal\logUploaderSettings_temp.ini
- \AppData\Local\Microsoft\OneDrive\settings\Personal\logUploaderSettings.ini
- C:\desktop.ini
- C:\ProgramData\Microsoft\Diagnosis\parse.dat
- \ntuser.dat.LOG2
- \ntuser.dat.LOG1
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat.LOG2
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\qwavecache.dat
- C:\Windows\System32\wbem\Performance\WmiApRpl.ini
- C:\Windows\System32\PerfStringBackup.TMP
- C:\Windows\System32\PerfStringBackup.INI
- C:\Windows\System32\wbem\Repository\OBJECTS.DATA
- C:\Windows\System32\wbem\Repository\INDEX.BTR
- C:\Windows\System32\wbem\Repository\MAPPING2.MAP
- C:\Windows\Prefetch
- C:\Windows\temp\MpCmdRun.log
- C:\Windows\System32\sru
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC
- \AppData\Local\Microsoft\Windows\History\History.IE5
- C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache
- C:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache
- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache
- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies
- \AppData\Local\Microsoft\Windows\SettingSync\remotemetastore
- \AppData\Local\Microsoft\Windows\SettingSync\metastore
- C:\Windows\INF
- C:\Windows\Logs\CBS
- C:\Windows\Logs
- C:\Windows\SoftwareDistribution\DataStore\Logs
- D:\Windows\System32\eac_usermode_21537346703536.dll
- D:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive
- D:\Windows\appcompact\Programs\Amcache.hve
- D:\Windows\System32\LogFiles\WMI\EtwRTGraphicsPerfMonitorSession.etl
- D:\Windows\System\config\BBI.LOG2
- D:\Program Files\Epic Games\Fortnite.lysEB
- D:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir
- D:\Program Files\Epic Games\Fortnite\EAAC0DED42EADD813C76C2B26C315591
- D:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe.local
- D:\ProgramData\Epic\EpicGamesLauncher\Data\EMS\current
- D:\ProgramData\Epic\UnrealEngineLauncher\LauncherInstalled.dat
- \AppData\Local\Origin
- D:\Users\Public
- \AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF244a582.TMP
- D:\Windows\temp\w1053
- D:\Windows\temp\MpCmdRun.log
- D:\Windows\Prefetch
- E:\Windows\System32\eac_usermode_21537346703536.dll
- E:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive
- E:\Windows\appcompact\Programs\Amcache.hve
- E:\Windows\System32\LogFiles\WMI\EtwRTGraphicsPerfMonitorSession.etl
- E:\Windows\System\config\BBI.LOG2
- E:\Program Files\Epic Games\Fortnite.lysEB
- E:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir
- E:\Program Files\Epic Games\Fortnite\EAAC0DED42EADD813C76C2B26C315591
- E:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe.local
- E:\ProgramData\Epic\EpicGamesLauncher\Data\EMS\current
- E:\ProgramData\Epic\UnrealEngineLauncher\LauncherInstalled.dat
- \AppData\Local\Google\Chrome\User Data\Default\Network Persistent State~RF245551b.TMP
- \AppData\Local\Google\Chrome\User Data\Default\Cache\f_00902d
- \AppData\Local\Google\Chrome\User Data\Default\Cache\f_00902c
- \AppData\Local\Google\Chrome\User Data\Default\Cache\f_00902a
- \AppData\Local\Google\Chrome\User Data\Default\Cache\f_00902b
- \AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF24436e9.TMP
- \AppData\Local\Google\Chrome\User Data\Default\Network Persistent State~RF24465f8.TMP
- \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009023
- \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009022
- \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009024
- \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009025
- \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009026
- \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009027
- \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009028
- \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009029
- E:\Users\Public
- E:\Windows\temp\w1053
- E:\Windows\temp\MpCmdRun.log
- E:\Windows\Prefetch
- F:\Windows\System32\eac_usermode_21537346703536.dll
- F:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive
- F:\Windows\appcompact\Programs\Amcache.hve
- F:\Windows\System32\LogFiles\WMI\EtwRTGraphicsPerfMonitorSession.etl
- F:\Windows\System\config\BBI.LOG2
- F:\Program Files\Epic Games\Fortnite.lysEB
- F:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir
- F:\Program Files\Epic Games\Fortnite\EAAC0DED42EADD813C76C2B26C315591
- F:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe.local
- F:\ProgramData\Epic\EpicGamesLauncher\Data\EMS\current
- F:\ProgramData\Epic\UnrealEngineLauncher\LauncherInstalled.dat
- F:\Users\Public
- F:\Windows\temp\w1053
- F:\Windows\temp\MpCmdRun.log
- F:\Windows\Prefetch
- D:\Windows\System32\sru
- E:\Windows\System32\sru
- F:\Windows\System32\sru
- C\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache
- C\ProgramData\Microsoft\DataMart\PaidWiFi\Rules
- C\Windows\System32\sru
- C\Users\Public\desktop.ini
- C\Windows\Logs\WindowsUpdate
- C\Windows\WindowsUpdate.log
- C\Windows\SoftwareDistribution\DataStore
- C\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache
- \AppData\Local\Microsoft\Windows\WebCache
- \AppData\Local\Speech Graphics\Carnival
- C\ProgramData\USOPrivate\UpdateStore
- C\ProgramData\USOShared\Logs
- C\Windows\System32\config\DEFAULT.LOG1
- C\Windows\System32\config\BBI.LOG2
- C\Windows\System32\SleepStudy
- C\Windows\System32\LogFiles\WMI\RtBackup
- C\Windows\System32\spp\store\2.0\cache\cache.dat
- C\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
- C\Windows\System32\wbem\Repository\OBJECTS.DATA
- C\Windows\System32\wbem\Repository\INDEX.BTR
- C\Windows\System32\wbem\Repository\MAPPING3.MAP
- C\Windows\System32\winevt\Logs
- C\Windows\System32\LogFiles\WMI\Wifi.etl
- C\Windows\INF\netrasa.PNF
- C\Recovery\ntuser.sys
- C\MSOCache{71230000-00E2-0000-1000-00000000}\Setup.dat
- C\Users\Public\Libraries\collection.dat
- C\Windows\1234.exe
- C:\Windows\System32\spp\store\2.0\cache\cache.dat
- \AppData\LocalLow\AMD
- C:\Shared Files
- C:\Recovery\ntuser.sys
- \AppData\Local\Temp
- C:\Windows\appcompat\Programs\Amcache.hve
- C:\$RECYCLE.BIN
- D:\Recovery\ntuser.sys
- D:\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat
- D:\desktop.ini:CachedTiles
- \AppData\Local\CEF
- \AppData\Local\Comms
- \AppData\Local\ConnectedDevicesPlatform
- \AppData\Local\BattlEye
- \AppData\Local\CrashDumps
- \AppData\Local\CrashReportClient
- \AppData\Local\D3DSCache
- \AppData\Local\DBG
- \AppData\Local\Programs\Common
- \AppData\Local\PlaceholderTileLogoFolder
- \AppData\Local\VirtualStore
- C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\CMS
- C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\DMS
- C:\Program Files\rempl\Logs
- C:\ProgramData\Microsoft\Diagnosis
- C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings
- C:\ProgramData\Microsoft\Windows\AppRepository
- C:\ProgramData\Microsoft\Windows\WER\Temp
- C:\ProgramData\USOShared\Logs
- C:\ProgramData\USOPrivate\UpdateStore
- C:\System Volume Information
- \AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2
- \AppData\Local\NVIDIA Corporation\GfeSDK
- \AppData\Roaming\Microsoft\Windows\Themes\CachedFiles
- \AppData\Roaming\Microsoft\Windows\Themes\slideshow.ini
- C:\Users\Public\Libraries
- C:\Users\Public\desktop.ini
- C:\Windows\DeliveryOptimization
- C:\Windows\Logs\WindowsUpdate
- C:\Windows\ServiceProfiles\LocalService\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content
- C:\Windows\ServiceProfiles\LocalService\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp
- C:\Windows\System32\LogFiles\WMI\RtBackup
- C:\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
- C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting
- C:\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start
- C:\Windows\System32\winevt\Logs
- C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\LMS\Manifest.sav
- C:\Windows\System32\drivers\storage.cache
- \AppData\Local\Publishers
- \AppData\Local\NVIDIA Corporation\GfeSDK\FortniteClient-Win64-Shipping_8060.log
- C:\Windows\SoftwareDistribution\ReportingEvents.log
- C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTGraphic
- PerfMonitorSession.etl
- \AppData\Local\Microsoft\Windows\INetCache\IE
- C:\Windows\INF\netrasa.PNF
- C:\MSOCache{71230000-00E2-0000-1000-00000000}\Setup.dat
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache
- C:\ProgramData\Microsoft\DataMart\PaidWiFi
- C:\Windows\System32\SleepStudy
- C:\Windows\System32\wbem\Repository\MAPPING3.MAP
- C:\Windows\System32\perfc009.dat
- C:\Windows\System32\perfh009.dat
- \AppData\Local\Microsoft\OneDrive\settings
- C:\Windows\SoftwareDistribution\DataStore
- C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys
- \AppData\Local\EpicGamesLauncher\Intermediate\Config\CoalescedSourceConfigs\Engine.ini
- C:\PerfLogs\collections.dat
- \AppData\Local\FortniteGame\Saved\Config\CrashReportClient
- \AppData\Local\IconCache.db
- \AppData\Local\updater.log
- \AppData\Local\Microsoft\Windows\AppCache
- \AppData\Local\Microsoft\Windows\INetCache\IE\container.dat
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive
- C:\ProgramData\Origin\Logs
- C:\Windows\System32\config\DEFAULT.LOG1
- C:\Windows\System32\config\SYSTEM.LOG2
- C:\Windows\WinSxS\ManifestCache
- C:\Windows\appcompat\Programs\Amcache.hve.LOG2
- C:\Windows\appcompat\appraiser\AltData
- \AppData\Local\Microsoft\Feeds Cache
- C:\desktop.ini:CachedTiles
- \AppData\Local\Local Settings\Temporary Internet Files
- C:\Program Files (x86)\TeamViewer\Connections_incoming.txt
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy
- \AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
- C:\Windows\1234.exe
- C:\Windows\System32\LogFiles\WMI\Wifi.etl
- C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{1c3790dc-b8ad-11e8-aa21-e41d2d101530}.TxR.2.regtrans-ms
- C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{1c3790dc-b8ad-11e8-aa21-e41d2d101530}.TxR.blf
- C:\Windows\System32\config\BBI.LOG2
- C:\Windows\System32\config\COMPONENTS{1c379064-b8ad-11e8-aa21-e41d2d101530}.TMContainer00000000000000000001.regtrans-ms
- C:\Windows\System32\config\COMPONENTS{1c379064-b8ad-11e8-aa21-e41d2d101530}.TMContainer00000000000000000002.regtrans-ms
- C:\Windows\System32\drivers\etc\protocol
- \AppData\Local\FortniteGame\Saved\Config
- C:\Windows\INF\WmiApRpl
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\INetCache
- \AppData\Roaming\Logs
- C:\ProgramData\NVIDIA Corporation\NV_Cache\92e0b06784280dec34f87311d172295b_fce8395c8fd8a98b_be4cb461d6f8ddbc_0_6__1.bin
- \AppData\Local\FortniteGame\Saved\Demos
- \AppData\Local\Microsoft\VSApplicationInsights
- C:\Windows\System32\config\DEFAULT.LOG2
- C:\Windows\System32\config\SYSTEM.LOG1
- C:\ProgramData\Microsoft\Diagnosis\EventStore.db-wal
- C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.A-MSTelDefault.json.new
- C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.A-MSTelDefault.json
- C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.SIUF.xml
- C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.SIUF.xml.new
- C:\Windows\System32\config\BBI.LOG1
- \AppData\Local\NVIDIA Corporation\GfeSDK\FortniteClient-Win64-Shipping_5880.log
- \AppData\Local\EpicGamesLauncher\Saved\Logs
- \AppData\Local\EpicGamesLauncher\Saved\webcache
- C:\ProgramData\NVIDIA Corporation\Drs
- \AppData\Local\EpicGamesLauncher\Saved\Config\Windows\GameUserSettings.ini
- C:\ProgramData\NVIDIA
- C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1
- C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2
- C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp
- C:\Windows\ServiceProfiles\LocalService\AppData\LocalLow\Microsoft\CryptnetUrlCache
- \AppData\LocalLow\Microsoft\CryptnetUrlCache
- C:\ProgramData\NVIDIA Corporation\NV_Cache
- \AppData\Local\Nvidia
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft
- C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{1c3790dc-b8ad-11e8-aa21-e41d2d101530}.TxR.0.regtrans-ms
- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History
- C:\Program Files\Epic Games\Fortnite\.lysEB\Install\$resumeData
- C:\Windows\INF\WmiApRpl\WmiApRpl.ini
- C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{1c3790dc-b8ad-11e8-aa21-e41d2d101530}.TxR.1.regtrans-ms
- C:\Windows\System32\DriverStore\en-US
- C:\Windows\system32\dllcache
- C:\Windows\System32\wbem\Repository
- C:\Windows\System32\config\systemprofile\AppData\Local\temp
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\TempState
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\AppCache
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\Windows
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Temp
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData
- \AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
- \AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
- C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3\Win64\d3dcompiler_43.dll
- C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3\Win64\d3dcompiler_47.dll
- C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3\Win64\libcef.dll
- C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3\Win64\libEGL.dll
- C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3\Win64\libGLESv2.dll
- C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3\Win64
- C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3
- C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\NVIDIA
- C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\Ogg\Win64\VS2015\libogg_64.dll
- C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\Ogg\Win64\VS2015
- C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\PhysX3\Win64\VS2015\ApexFramework_x64.dll
- \AppData\Local\Microsoft\OneDrive\logs
- \AppData\Local\Microsoft\OneDrive\logs\Personal
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Logs
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\ConnectedDevicesPlatform
- C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\RSA
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\CLR_v2.0\UsageLogs
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\INetCache
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\INetCookies
- C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\Shared Files
- C:\Program Files (x86)\Epic Games\Launcher\VaultCache
- C:\Program Files (x86)\Epic Games\Launcher\Engine\Programs\CrashReportClient\Config\DefaultEngine.ini
- \AppData\Local\Microsoft\Windows\Caches
- \AppData\Local\Microsoft\Internet Explorer\CacheStorage
- C:\ProgramData\Package Cache
- C:\ProgramData\Microsoft\Windows\Caches
- C:\Windows\System32\spp\store\2.0\cache
- C:\Program Files (x86)\Microsoft.NET\Multi-Targeting Pack\v4.5.1\SetupCache
- C:\Program Files (x86)\Microsoft.NET\Multi-Targeting Pack\v4.5.2\SetupCache
- C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Cache
- C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection
- C:\ProgramData\Microsoft\Windows Defender\Definition Updates
- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CC288659-A1DB-4AEC-BAB2-6DBB6A99ABE8}
- C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\{CC288659-A1DB-4AEC-BAB2-6DBB6A99ABE8}
- C:\Windows\System32\WDI
- C:\Windows\System32\WDI\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{1b3f1407-39d0-4a4f-a547-cd4c65d17116}
- C:\Windows\System32\WDI\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{ed1e579f-1b61-4367-9430-f55c00c26870}
- C:\Windows\SoftwareDistribution\Download\Install
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-PriResources-Deployment%4Operational.evtx
- C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.002
- C:\Windows\System32\wbem\Repository\MAPPING1.MAP
- C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan
- C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Backup Scan
- C:\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache
- C:\Windows\System32\drivers\mbamswissarmy.sys
- C:\Windows\System32\catroot2\dberr.txt
- C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\MBAMSwissArmy.cat
- C:\Windows\ServiceState\EventLog\Data\lastalive0.dat
- C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\dosvcState.dat.LOG1
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Intel\DPTF\dptf.dv
- C:\Windows\security\logs
- C:\Windows\security\logs\scecomp.log
- C:\Windows\Logs\CBS\CBS.log
- C:\Windows\Logs\NetSetup\service.0.etl
- C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20190526.072128.021.3.etl
- C:\Windows\bootstat.dat
- \AppData\Roaming\Microsoft\Windows\Recent\The Internet.lnk
- \AppData\Roaming\Microsoft\Windows\AccountPictures\8495ae10deeaf929.accountpicture-ms
- \AppData\Local\ProtonVPN\ProtonVPN.exe_Url_5k5woeau2v3gmtlay4mjwsftlqxjnn2p\1.8.1.0\user.config
- \AppData\Local\ProtonVPN\Logs
- \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat.LOG1
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\FB0D848F74F70BB2EAA93746D24D9749
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
- \AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\signals\collection\WIFI\{a70e087b-499b-4632-ad5d-4b1c6d71e648}
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Graph\Login.ttl
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Graph\49ccf8c88be99e2b\Me\00000000.ttl
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\VaStartMenu_01.0409.digest.bin.tmp
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\VaStartMenuGames_01.0409.digest.bin.tmp
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest_01.0409.digest.bin.tmp
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest2_01.0409.digest.bin.tmp
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat.LOG1
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\SkypeRT\persistent.conf
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\DiagOutputDir\SkypeApp0.txt
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\CS_localstate\CS_shared.conf
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\AsyncStorage\saveUlLog.data
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\AsyncStorage\FirstTimeSignIn.data
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\AsyncStorage\ecsDefaultConfig.data
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\TokenBroker\Cache\0c55efda7496e58ee00d3d8c9b78994f9ee0359c.tbres
- \AppData\Local\Microsoft\Windows\UPPS\UPPS.bin
- \AppData\Local\Microsoft\Windows\SettingSync\remotemetastore\v1
- \AppData\Local\Microsoft\Windows\Explorer\NotifyIcon\Microsoft.Explorer.Notification.{856ABD34-82E0-98F4-3351-225E04F0D828}.png
- \AppData\Local\Microsoft\Credentials\5003A98EAE20BC3E53D43ADBDDEDBA4E
- \AppData\Local\EpicGamesLauncher\Saved\webcache\Visited Links
- \AppData\Local\EpicGamesLauncher\Saved\Logs\EpicGamesLauncher.log
- \AppData\Local\EpicGamesLauncher\Saved\Logs\cef3.log
- \AppData\Local\ConnectedDevicesPlatform\49ccf8c88be99e2b\ActivitiesCache.db-wal
- \AppData\Local\ConnectedDevicesPlatform\49ccf8c88be99e2b\ActivitiesCache.db
- C:\Users\All Users\USOPrivate\UpdateStore\updatestore51b519d5-b6f5-4333-8df6-e74d7c9aead4.xml
- C:\Users\All Users\Synaptics\ValidityService.log
- C:\Users\All Users\ProtonVPN\Logs\service.txt
- C:\Users\All Users\Microsoft\Windows Defender\Support\MPLog-20190520-222511.log
- C:\Users\All Users\Microsoft\Windows Defender\Scans
- C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Backup
- C:\Users\All Users\Microsoft\Windows\AppRepository
- C:\Users\All Users\Microsoft\SmsRouter\MessageStore
- C:\Users\All Users\Microsoft\Search\Data\Applications\Windows
- C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\edbtmp.jtx
- C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\edb.jtx
- C:\Users\All Users\Microsoft\Network\Downloader
- C:\Users\All Users\Microsoft\Diagnosis
- C:\Users\All Users\Malwarebytes
- C:\Users\All Users\Malwarebytes\MBAMService
- C:\Users\All Users\Malwarebytes\MBAMService\config
- C:\ProgramData\USOPrivate\UpdateStore\updatestore51b519d5-b6f5-4333-8df6-e74d7c9aead4.xml
- C:\ProgramData\Microsoft\Windows Defender\Support
- C:\ProgramData\Microsoft\Windows Defender\Scans
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows
- C:\Program Files\Malwarebytes
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-Containers-Wcnfs%4Operational.evtx
- C:\Windows\System32\WDI\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{ed1e579f-1b61-4367-9430-f55c00c26870}\snapshot.etl
- C:\Windows\System32\WDI\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{1b3f1407-39d0-4a4f-a547-cd4c65d17116}\snapshot.etl
- c:\Windows\SoftwareDistribution\DataStore\Logs,,,
- C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20190526.072128.021.4.etl
- C:\Windows\Logs\waasmedic\waasmedic.20190526_063337_646.etl
- C:\Windows\Logs\waasmedic
- C:\Users\Public\ASR.dat
- \js_logs\2019-05-26-10.txt
- \AppData\Roaming\EasyAntiCheat\gamelauncher.log
- \AppData\Roaming\EasyAntiCheat\217
- \AppData\Local\FortniteGame\Saved\Logs
- \AppData\Local\FortniteGame\Saved\Logs\FortniteGame.log
- \AppData\Local\FortniteGame\Saved\Config\WindowsClient
- \AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\LocalState
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache\MetaData
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache\Content
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\INetCache
- \AppData\Local\Microsoft\Windows\ActionCenterCache\microsoft-explorer-notification--856abd34-82e0-98f4-3351-225e04f0d828-_489_0.png
- \AppData\Local\Microsoft\TokenBroker\Cache
- \AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage
- \AppData\Local\EpicGamesLauncher\Saved\webcache\Cache
- C:\Users\All Users\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424_COM15.dat.LOG2
- C:\Users\All Users\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424_COM15.dat.LOG1
- C:\Users\All Users\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424_COM15.dat
- C:\Users\All Users\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424.dat
- C:\Users\All Users\Microsoft\Windows Defender\Definition Updates
- C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\edb00194.jtx
- C:\ProgramData\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424_COM15.dat.LOG2
- C:\ProgramData\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424_COM15.dat.LOG1
- C:\ProgramData\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424.dat
- C:\ProgramData\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache
- \AppData\Local\Microsoft\OneDrive\logs\Common
- C:\ProgramData\Microsoft\Network\Downloader
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\CacheStorage
- C:\Windows\appcompat\Programs\Amcache.hve.LOG1
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-Storport%4Operational.evtx
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-Storport%4Health.evtx
- C:\Windows\ServiceProfiles\NetworkService\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
- C:\Windows\System32\eac_usermode_21654663664752.dll
- C:\Windows\System32\spp\store\2.0\data.dat
- C:\Program Files\Epic Games\Fortnite1\FortniteGame\PersistentDownloadDir\EMS
- \AppData\Local\Microsoft\Windows\WER\ERC\statecache.lock
- C:\Program Files\Epic Games\Fortnite1\FortniteGame\PersistentDownloadDir\CMS
- C:\Program Files (x86)\EasyAntiCheat
- C:\ProgramData\Microsoft\Diagnosis\EventStore.db
- C:\ProgramData\Microsoft\Network\Downloader\edb.chk
- C:\ProgramData\Microsoft\SmsRouter\MessageStore
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\TokenBroker\Cache
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\AsyncStorage
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\Internet Explorer
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Graph
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\signals\collection\WIFI
- \AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState
- C:\Windows\System32\catroot2
- C:\Users\All Users\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache
- C:\Users\All Users\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c
- C:\MSOCache\{71230000-00E2-0000-1000-00000000}
- C:\Users\caspue\AppData\Local\Speech Graphics\Carnival
- C:\windows\system32\dllcache
- C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\Tips
- C:\ProgramData\Microsoft\Diagnosis\ScenariosSqlStore
- \AppData\Local\Comms\UnistoreDB\USS.jtx
- \AppData\Local\FortniteGame\Saved\LMS
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat.LOG1
- \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\AC\INetCache
- \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\AC\INetCookies
- \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\AC\INetHistory
- \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\AC\Temp
- \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\LocalCache
- \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\TempState
- \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\roaming.lock
- \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
- \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\AC\INetCache
- \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\AC\INetCookies
- \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\AC\INetHistory
- \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\AC\Temp
- \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
- \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\roaming.lock
- \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\TempState
- \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\LocalCache
- C:\Program Files\WindowsApps\Microsoft.StorePurchaseApp_11811.1001.18.0_neutral_split.language-de_8wekyb3d8bbwe
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.MicrosoftStickyNotes_3.6.73.0_x64__8wekyb3d8bbwe\ActivationStore.dat.LOG1
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.MicrosoftStickyNotes_3.6.73.0_x64__8wekyb3d8bbwe\ActivationStore.dat.LOG2
- C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\migration.dat.LOG1
- C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\migration.dat.LOG2
- C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\dosvcState.dat.LOG2
- \AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\AC\INetCache
- \AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\AC\INetCookies
- \AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\AC\INetHistory
- \AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\AC\Temp
- \AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\TempState
- \AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\LocalCache
- C:\Windows\System32\winevt\Logs\Application.evtx
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\INetCache
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\INetCookies
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\INetHistory
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AppData
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalCache
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\TempState
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\INetCache
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\INetCookies
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\INetHistory
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\Temp
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\Temp\NVIDIA Corporation
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\Temp\NVIDIA Corporation\NV_Cache
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalCache
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState
- \AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\AC
- \AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\AC\Temp
- \AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\AC\Temp\NVIDIA Corporation
- \AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\AC\Temp\NVIDIA Corporation\NV_Cache
- \AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG1
- \AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG2
- \AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG1
- \AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG2
- \AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState
- \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\INetCookies
- \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\INetCache
- \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\INetHistory
- \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\TempState
- \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\settings.dat.LOG1
- \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\settings.dat.LOG2
- \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\LocalCache
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\Local
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\Local\Microsoft
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\Local\Microsoft\Windows
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\Local\Microsoft\Windows\Caches
- \AppData\Local\Packages\AD2F1837.HPPrinterControl_v10z8vjag6ke6\AC\INetCache
- \AppData\Local\Packages\AD2F1837.HPPrinterControl_v10z8vjag6ke6\AC\INetCookies
- \AppData\Local\Packages\AD2F1837.HPPrinterControl_v10z8vjag6ke6\AC\INetHistory
- \AppData\Local\Packages\AD2F1837.HPPrinterControl_v10z8vjag6ke6\AC\Temp
- \AppData\LocalLow\Microsoft\CryptnetUrlCache\Content
- \AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
- C:\Windows\System32\spp\store\2.0
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19051.545.0_x64__8wekyb3d8bbwe
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\roaming.lock
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat.LOG1
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat.LOG2
- C:\ProgramData\Epic\EpicGamesLauncher\Data\EMS
- C:\ProgramData\Epic\UnrealEngineLauncher
- C:\ProgramData\NVIDIA Corporation
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-Storport%4Health.evtx
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-Storport%4Operational.evtx
- \AppData\Local\Microsoft\Windows\IECompatCache
- \AppData\Local\Microsoft\Windows\IECompatUaCache
- \AppData\Local\Microsoft\Windows\INetCookies
- \AppData\Local\Microsoft\Windows\INetCookies\Low
- \AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
- \AppData\Local\Spotify\Browser\GPUCache
- C:\Windows\System32\wbem\Logs\wmiprov.log
- C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTTerminal-Services-LSM-ApplicationLag-9032.etl
- C:\Program Files (x86)\Common Files\BattlEye
- C:\Windows\System32\config\SOFTWARE.LOG1
- C:\Windows\WindowsUpdate.log
- \AppData\Local\Packages\InputApp_cw5n1h2txyewy\AC
- \AppData\Local\Packages\InputApp_cw5n1h2txyewy\AC\Temp
- \AppData\Local\Packages\InputApp_cw5n1h2txyewy\AC\Temp\NVIDIA Corporation
- \AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\AC\Temp\NVIDIA Corporation
- \AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\AC\Temp
- \AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\AC
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData
- \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\Temp\NVIDIA Corporation
- \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\Temp\NVIDIA Corporation\NV_Cache
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\TempState\Traces
- C:\Windows\System32\wbem\Performance
- C:\Windows\AppReadiness
- C:\ProgramData\regid.1991-06.com.microsoft
- \AppData\Local\Microsoft\Internet Explorer\Indexed DB
- C:\Windows\ServiceProfiles\LocalService\ntuser.dat.log1
- C:\Windows\ServiceProfiles\LocalService\ntuser.dat.log2
- \AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC
- \AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\Temp
- \AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\INetHistory
- \AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\INetCookies
- \AppData\Local\Temp\NVIDIA Corporation\NV_Cache
- \AppData\Local\Microsoft\Windows\History
- C:\Windows\Public\Libraries
- C:\Users\Public\Libraries\collection.dat
- C:\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat
- C:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.jfm
- \AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
- C:\Windows\System32\WDI\LogFiles\StartupInfo
- C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs
- C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State
- C:\Windows\SysWOW64\Gms.log
- \AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous
- \AppData\Local\Microsoft\Windows\WER\ERC
- \AppData\Local\Comms\Unistore\data
- \AppData\Local\Comms\Unistore\data\temp
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AppData\User\Default\Indexed DB\edb.log
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AppData\User\Default\Indexed DB
- \AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb
- C:\Windows\appcompat\Programs\Install
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\Recovery\Active
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!002\MicrosoftEdge\User\Default\AppCache
- \AppData\Roaming\Microsoft\Windows\Recent\Autom
- C:\Windows\rescache\_merged
- \AppData\Local\Microsoft\OneDrive\settings\Personal
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive\AuthStateCache.dat
- C:\Windows\Logs\MoSetup\UpdateAgent.log
- C:\Windows\SoftwareDistribution\PostRebootEventCache.V2\{323558A6-0300-4C3E-97A0-EDEDFEB96B00}.bin
- C:\Windows\SoftwareDistribution\PostRebootEventCache.V2
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
- \AppData\Local\Comms\UnistoreDB
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGameOverlay_1.42.4001.0_x64__8wekyb3d8bbwe\ActivationStore.dat
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\DiagOutputDir
- systemdrive%\Users\
- \AppData\Local\Microsoft\Windows\Safety\edge\remote
- C:\Windows\SoftwareDistribution\DataStore\DataStore.edb
- C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log
- \AppData\Local\Microsoft\VisualStudio\16.0_76be8573\privateregistry.bin.LOG2
- \AppData\Local\Microsoft\VisualStudio\16.0_76be8573\privateregistry.bin.LOG1
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\IndexedDB.jfm
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe\ActivationStore.dat
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\Assets
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\StagedAssets
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\INetCache\ARDTOTYX
- C:\Program Files (x86)\Google\CrashReports
- \AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\LocalState\DiagOutputDir
- \AppData\Local\Comms\UnistoreDB\store.jfm
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Wallet_2.2.18179.0_x64__8wekyb3d8bbwe\ActivationStore.dat
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\TargetedContentCache
- C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd-wal
- C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd
- \AppData\Local\Temp\VSRemoteControl
- \AppData\Local\Temp\VSFeedbackIntelliCodeLogs
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Temp
- C:\ProgramData\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db
- C:\ProgramData\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db-wal
- C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\XSettings.Sav
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-Fault-Tolerant-Heap%4Operational.evtx
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings\settings.dat.LOG1
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings\settings.dat.LOG2
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGameOverlay_1.42.4001.0_x64__8wekyb3d8bbwe
- C:\Windows\SoftwareDistribution\Download
- C:\ProgramData\Audyssey Labs
- C:\ProgramData\Intel\ShaderCache
- C:\ProgramData\Intel\ShaderCache\FortniteClient-Win64-Shipping_1
- C:\ProgramData\Intel\ShaderCache\EpicGamesLauncher_1
- C:\ProgramData\Microsoft\Provisioning\AssetCache
- C:\ProgramData\Microsoft\Search\Data\Temp
- C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrccache
- C:\ProgramData\Microsoft\Windows\DeviceMetadataCache
- C:\ProgramData\Microsoft\Windows\wfp
- C:\ProgramData\NVIDIA Corporation\umdlogs
- C:\ProgramData\Package Cache\{64ff2cb0-807c-4ee9-87ef-ec1b2ede0daf}
- C:\Users\Public\Desktop
- C:\Users\Public\AccountPictures
- \AppData\LocalLow\Temp
- \AppData\Local\Intel
- \AppData\Local\AMD
- \AppData\Local\History
- \AppData\Local\MicrosoftEdge\SharedCacheContainers
- \AppData\Local\MicrosoftEdge\User\Default
- \AppData\Local\OneDrive\cache
- \AppData\Local\OneDrive\cache\qmlcache
- \AppData\Local\SquirrelTemp
- \AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs
- \AppData\Local\Microsoft\CLR_v4.0\UsageLogs
- \AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs
- \AppData\Local\Microsoft\Internet Explorer\DOMStore
- \AppData\Local\Microsoft\Media Player\Transcoded Files Cache
- \AppData\Local\Microsoft\Vault
- \AppData\Local\Microsoft\VisualStudio\16.0_b35fdcc8\PackageCache
- \AppData\Local\Microsoft\VisualStudio\16.0_b35fdcc8\TextMateCache
- \AppData\Local\Microsoft\Windows\IEDownloadHistory
- \AppData\Local\Microsoft\Windows\PPBCompatCache
- \AppData\Local\Microsoft\Windows\PPBCompatUaCache
- \AppData\Local\Microsoft\Windows\PRICache
- \AppData\Local\Microsoft\Windows\WER
- \AppData\Roaming\Adobe\Flash Player\AssetCache
- \AppData\Roaming\Adobe\Flash Player\NativeCache
- \AppData\Roaming\Microsoft\Vault
- \AppData\Roaming\NVIDIA\ComputeCache
- \AppData\Roaming\Visual Studio Setup\Cache
- \AppData\Roaming\Visual Studio Setup\GPUCache
- \AppData\Roaming\vs_installershell\logs
- \AppData\Roaming\Microsoft\Spelling\en-US
- \AppData\Roaming\Microsoft\Spelling\en-UK
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings\settings.dat
- \AppData\Local\Origin\Origin\QtWebEngine\Default\Service Worker\ScriptCache
- \AppData\Local\Microsoft\PenWorkspace
- \AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
- \AppData\Local\Origin\Web Cache
- C:\Windows\System32\winevt\Logs\Security.evtx
- C:\ProgramData\Origin\AchievementCache
- C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json.new
- C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\TELEMETRY.ASM-WINDOWSSQ.json.new
- C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.ASM-WindowsDefault.json.new
- C:\ProgramData\Microsoft\Windows\LfSvc\Geofence\S-1-5-18_NonPackagedApp\Geofence.dat
- C:\ProgramData\Microsoft\Windows\LfSvc\Geofence\S-1-5-18_NonPackagedApp
- C:\Windows\System32\LogFiles\WMI
- C:\ProgramData\Intel
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\1033
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Caches
- C:\Windows\System32\config\systemprofile\AppData\Local\D3DSCache\f9156d1136660b11\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.lock
- :\ProgramData\Intel\ShaderCache\taskhostw_1
- C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTdfa2c640-651d-488d-a479-2fd7a7ca6e29.etl
- C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20190621.222200.334.1.etl
- C:\Windows\SoftwareDistribution\DataStore\DataStore.jfm
- C:\Windows\INF\WmiApRpl\0009
- :\Windows\System32\wbem\Performance
- C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTTerminal-Services-LSM-ApplicationLag-9452.etl
- \Saved Games\Respawn\Apex
- \AppData\Roaming\CSM
- C:\Windows\System32\SMI\Store\Machine
- C:\ProgramData\Epic\EpicGamesLauncher\Data\EMS\stage
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
- C:\ProgramData\Microsoft\XboxLive\NSALCache
- C:\Program Files (x86)\AMD\CNext\CCCSlim
- \Videos\Captures\desktop.ini
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe
- \AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe
- \AppData\Local\Microsoft\Windows\SettingSync
- \AppData\Local\Comms\Unistore
- \AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-wal
- \AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db
- C:\Users\Public\Shared Files
- C:\Users\Public\Shared Files.sys
- C:\Windows\System32\config\systemprofile\AppData\Local\D3DSCache
- C:\Windows\System32\config\systemprofile\AppData\Local\Packages\microsoft.windows.fontdrvhost\AC
- C:\Windows\SoftwareDistribution
- C:\Windows\SoftwareDistribution\SLS
- C:\Windows\Logs\SIH
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\ReactNativeBundle.bin
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\dtlscert.der
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\dtlskey.der
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\SkypeRT\persistent.tmp
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\slimcore-aria-cache.data-shm
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\slimcore-aria-cache.data-wal
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\slimcore-aria-cache.data-journal
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\CS_localstate
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\shared.xml
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\shared.lck
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\INetCache\container.dat
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\INetCookies\ESE\container.dat
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\TempState\VimTemp
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\TempState
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalCache\RNManualFileCache
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb0003A.jtx
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbtmp.jtx
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache
- C:\ProgramData\Microsoft\Windows\wfp\currentState.xml
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.MicrosoftEdge_44.17763.1.0_neutral__8wekyb3d8bbwe
- C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\microsoft.system.package.metadata\Autogen
- C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\microsoft.system.package.metadata\Autogen\JSByteCodeCache_64
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.Cortana_1.11.5.17763_neutral_neutral_cw5n1h2txyewy
- \AppData\Local\Microsoft\Windows\History\History.IE5\container.dat
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb0001C.jtx
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat.LOG2
- \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Temp\NVIDIA Corporation
- \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat.LOG1
- \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat.LOG2
- \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat.LOG2
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsAlarms_10.1903.1006.0_x64__8wekyb3d8bbwe
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsAlarms_10.1903.1006.0_neutral_split.scale-100_8wekyb3d8bbwe
- \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AC\Temp
- \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AC\INetCache
- \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AC\INetHistory
- \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AC\INetCookies
- \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\LocalCache
- \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings
- \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\TempState
- C:\Program Files\WindowsApps\Microsoft.WindowsAlarms_10.1903.1006.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_neutral_split.language-de_8wekyb3d8bbwe
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_neutral_split.scale-100_8wekyb3d8bbwe
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_x64__8wekyb3d8bbwe
- \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\Temp
- \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\INetCache
- \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\INetHistory
- \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\INetCookies
- \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\LocalCache
- \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\TempState
- C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19061.410.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings
- \AppData\Local\Packages\InputApp_cw5n1h2txyewy\AC\INetCache
- \AppData\Local\Packages\InputApp_cw5n1h2txyewy\AC\INetHistory
- \AppData\Local\Packages\InputApp_cw5n1h2txyewy\AC\INetCookies
- \AppData\Local\Packages\InputApp_cw5n1h2txyewy\LocalCache
- \AppData\Local\Packages\InputApp_cw5n1h2txyewy\TempState
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c
- C:\ProgramData\Microsoft\Network
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsStore_11905.1001.4.0_neutral_split.scale-100_8wekyb3d8bbwe
- C:\Windows\TEMP\NVIDIA Corporation
- C:\Program Files\UNP\UpdateNotificationMgr
- C:\Program Files\UNP\Logs
- \AppData\Local\Microsoft\Windows\Safety\edge\local\local\cache
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC
- \AppData\Local\Microsoft\VisualStudio\Packages\_Channels
- \AppData\Local\Microsoft\VisualStudio\Packages\_Instances
- C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe
- \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC
- C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator
- C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal
- C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\microsoft.system.package.metadata
- \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\TempState
- \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings
- \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\LocalState
- C:\Program Files\WindowsApps\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata
- C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd-shm
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\TokenBroker\Cache
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\BackgroundTransferApi
- C:\Windows\appcompat\Programs
- \AppData\Local\Microsoft\Windows\Explorer\ThumbCacheToDelete
- \AppData\Local\FortniteGame\Saved\Cloud
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\InstallAgent\Checkpoints
- \AppData\Roaming\Microsoft\Spelling
- C:\Windows\System32\eac_usermode_11511826802397.dll
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC
- \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\OneSettingsResponseCache
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\DeviceSearchCache
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\AppIconCache
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\AppIconCache\100
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState
- \AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
- C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.bk
- C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\InstallAgent
- C:\ProgramData\Microsoft\Windows\WER
- \AppData\Local\Microsoft\Windows\INetCache\Content.IE5
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects
- \AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\roaming.lock
- C:\Windows\TEMP\NVIDIA Corporation\NV_Cache
- C:\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows
- C:\Windows\System32\eac_usermode_9472654871434.dll
- \AppData\Local\Microsoft\Windows\UsrClass.dat
- C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm
- C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.DIAGNOSTICS.xml.temp
- C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.DIAGNOSTICS.xml
- C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.DIAGNOSTICS.xml.new
- \AppData\Local\Microsoft\CLR_v2.0\UsageLogs
- C:\ProgramData\USOShared\Logs\NotificationUxBroker_Temp.1.etl
- \AppData\Local\Microsoft\Windows\Ringtones
- \AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
- C:\Windows\WindowsUpData.dll
- C:\Windows\WindowsUpData.sys
- C:\ProgramData\Origin
- C:\ProgramData\Origin\CatalogCache
- C:\ProgramData\Origin\CustomBoxartCache
- C:\ProgramData\Origin\DownloadCache
- C:\ProgramData\Origin\EntitlementCache
- C:\ProgramData\Origin\IGOCache
- C:\ProgramData\Origin\NonOriginContentCache
- C:\ProgramData\Origin\SelfUpdate
- C:\ProgramData\Origin\Subscription
- C:\ProgramData\Origin\Telemetry
- E:\ProgramData\Origin
- E:\ProgramData\Origin\AchievementCache
- E:\ProgramData\Origin\CatalogCache
- E:\ProgramData\Origin\CustomBoxartCache
- E:\ProgramData\Origin\DownloadCache
- E:\ProgramData\Origin\EntitlementCache
- E:\ProgramData\Origin\IGOCache
- E:\ProgramData\Origin\Logs
- E:\ProgramData\Origin\NonOriginContentCache
- E:\ProgramData\Origin\SelfUpdate
- E:\ProgramData\Origin\Subscription
- E:\ProgramData\Origin\Telemetry
- D:\ProgramData\Origin
- D:\ProgramData\Origin\AchievementCache
- D:\ProgramData\Origin\CatalogCache
- D:\ProgramData\Origin\CustomBoxartCache
- D:\ProgramData\Origin\DownloadCache
- D:\ProgramData\Origin\EntitlementCache
- D:\ProgramData\Origin\IGOCache
- D:\ProgramData\Origin\Logs
- D:\ProgramData\Origin\NonOriginContentCache
- D:\ProgramData\Origin\SelfUpdate
- D:\ProgramData\Origin\Subscription
- D:\ProgramData\Origin\Telemetry
- \AppData\Roaming\Origin
- C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePacken-GB_17763.9.22.0_neutral__8wekyb3d8bbwe\Windows\System32\driverstore
- C:\ProgramData\Microsoft\Windows\ClipSVC
- C:\Windows\appcompat\appraiser\AltData\Appraiser_Data.ini
- C:\Windows\Logs\MoSetup
- \AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState
- C:\Windows\System32\spp\store
- C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization
- C:\Windows\System32\WDI\LogFiles
- C:\Program Files (x86)\AMD
- C:\Program Files (x86)\AMD\CNext
- \AppData\Local\Microsoft\Internet Explorer
- \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy
- C:\Users\DefaultAppPool
- C:\Users\All Users\NVIDIA Corporation
- C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.CloudExperienceHost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy
- C:\Users\All Users\Intel
- C:\Windows\System32\LogFiles\WMI\LwtNetLog.etl
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.CloudExperienceHost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy
- C:\Users\All Users\Microsoft\Windows\WER
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGamingOverlay_3.30.20002.0_x64__8wekyb3d8bbwe
- C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGamingOverlay_3.30.20002.0_x64__8wekyb3d8bbwe
- \AppData\Local\ElevatedDiagnostics
- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5
- C:\ProgramData\Microsoft\XboxLive
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AppData
- C:\Windows\rescache
- C:\Windows\ServiceState\EventLog
- \AppData\Local\Microsoft\Windows\Safety
- C:\Windows\appcompat\appraiser
- \AppData\Local\temp\Origin
- C:\ProgramData\Microsoft\Windows\ClipSvc
- C:\Users\All Users\Microsoft\Windows\AppRepository\1e219871-2a28-4d27-b3c8-3412c40a9d4b_S-1-5-21-3790113146-3068863390-284532636-1001_24.rslc
- C:\Users\All Users\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal
- C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_neutral_split.language-de_8wekyb3d8bbwe
- C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_neutral_split.scale-100_8wekyb3d8bbwe
- C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_x64__8wekyb3d8bbwe
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_x64__8wekyb3d8bbwe\ActivationStore.dat
- C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_x64__8wekyb3d8bbwe\ActivationStore.dat
- C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19061.410.0_x64__8wekyb3d8bbwe
- \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe
- C:\Users\All Users\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm
- C:\Users\All Users\Epic\UnrealEngineLauncher
- C:\Users\All Users\Microsoft\Diagnosis\parse.dat
- C:\Users\All Users\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db-wal
- C:\Users\All Users\Microsoft\Diagnosis\DownloadedScenarios
- C:\Users\All Users\Microsoft\Diagnosis\DownloadedSettings
- C:\Users\All Users\Epic\EpicGamesLauncher\Data\EMS
- \IntelGraphicsProfiles
- \MicrosoftEdgeBackups
- \Documents\desktop.ini
- \Picture\desktop.ini
- \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe
- \AppData\Roaming\Notepad++\backup
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex
- C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex
- C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore
- C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap
- C:\ProgramData\Microsoft\Search\Data
- C:\Users\All Users\Microsoft\Search\Data
- C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Config
- C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects
- \AppData\Local\Microsoft\Internet Explorer\EmieSiteList
- \AppData\Local\Microsoft\OneDrive\StandaloneUpdater
- C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.CloudExperienceHost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.CloudExperienceHost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat
- C:\Users\All Users\Microsoft\Diagnosis\EventStore.db-wal
- C:\Windows\TEMP\UDD6086.tmp
- \AppData\Local\Microsoft\Internet Explorer\EmieUserList
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jcp
- C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\edb.jcp
- \AppData\Local\NVIDIA Corporation\GfeSDK\FortniteClient-Win64-Shipping_10864.log
- C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00025.jtx
- C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\edb00025.jtx
- \AppData\Local\Microsoft\Windows\INetCookies\ESE
- \AppData\Local\Intel\CUIPromotions
- \AppData\Local\Microsoft\Credentials
- C:\Users\All Users\Microsoft\Windows\ClipSvc\tokens.dat
- C:\Users\All Users\Microsoft\Windows\ClipSvc
- C:\ProgramData\Microsoft\Windows\ClipSvc\tokens.dat.bak
- C:\Users\All Users\Intel\ShaderCache
- C:\ProgramData\Microsoft\Windows\ClipSvc\tokens.dat
- C:\Users\All Users\Microsoft\Windows\ClipSvc\tokens.dat.bak
- C:\Program Files\Epic Games\Fortnite\FortniteGame\Content\Movies
- \AppData\Local\Microsoft\OneDrive
- C:\Users\All Users\NVIDIA
- C:\Users\Default
- C:\Users\All Users\Microsoft\SmsRouter
- \AppData\Local\Microsoft\Windows\DeliveryOptimization
- C:\ProgramData\Microsoft\Windows\ClipSVC\tokens.dat
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Credentials
- C:\Windows\CbsTemp
- C:\Windows\servicing\Sessions
- C:\Windows\WinSxS\Temp
- C:\ProgramData\Electronic Arts
- \.QtWebEngineProcess
- \Saved Games\Respawn\Apex\
- \Documents\apex_crash.txt
- C:\Program Files\Common Files\EAInstaller
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Origin
- C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Origin
- C:\Program Files (x86)\Origin\debug.log
- C:\Program Files (x86)\Origin\EACore.ini
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Credentials
- C:\Windows\ServiceState\EventLog\Data\lastalive1.dat
- \AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Update.exe.log
- C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\CMS\CacheAccess.json
- C:\Windows\System32\sru\SRU.chk
- C:\Users\All Users\NVIDIA Corporation\nvstapisvr\nvstapisvr.log
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\IndexedDB.edb
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\edb.chk
- \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\edb.log
- C:\Users\All Users\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd
- C:\Users\All Users\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd-wal
- C:\Windows\SoftwareDistribution\DataStore\Logs\edb.chk
- \AppData\Local\EpicGamesLauncher\Saved\Data
- C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache
- C:\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate
- C:\Windows\System32\Tasks\Microsoft\Windows\CloudExperienceHost
- C:\Windows\System32\Tasks\Microsoft\Windows
- C:\Windows\System32\Tasks\Microsoft\XblGameSave
- C:\Users\All Users\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd-shm
- C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGamingOverlay_3.32.20003.0_x64__8wekyb3d8bbwe\ActivationStore.dat
- C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGamingOverlay_3.32.20003.0_x64__8wekyb3d8bbwe\ActivationStore.dat
- C:\Users\All Users\USOShared
- C:\ProgramData\USOShared
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx
- C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\AC Power Download
- C:\Windows\SoftwareDistribution\DataStore\
- C:\Users\All Users\USOPrivate\UpdateStore
- C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Notifications
- sc delete prox
- \AppData\Local\Temp\tem7AD6.tmp
- \AppData\Local\Temp\tem7AD8.tmp
- \AppData\Local\Temp\tem6AD8.tmp
- \AppData\Local\Temp\tem1AD8.tmp
- \AppData\Local\Temp\tem5AD8.tmp
- \AppData\Local\Temp\tem7gD8.tmp
- \AppData\Local\Temp\tem7AgD8.tmp
- sc create prox binpath= C:\Users\
- \AppData\Local\Temp\tem7AD6.tmp type= kernel
- \AppData\Local\Temp\temposid.tmp
- \AppData\Local\Temptemp\tem7aD8.tmp
- \AppData\Local\Temp\temp\tem7ADz.tmp
- SELECT * FROM Win32_DiskDrive
- Error: 105 (Contact I LOVE PIZZA#6740)
- Error: 123 (Contact I LOVE PIZZA#6740)
- ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789
- MSI A320M PRO - E
- Asus Prime A320M-C R2.0
- Gigabyte GA - A320M - H
- ASRock Z390 Phantom Gaming SLI
- Asus ROG Rampage VI Extreme Omega
- Asus Prime H310I - Plus R2.0
- Asus ROG Zenith Extreme Alpha X399
- MSI MEG X299 Creation
- ASRock AB350M - HDV R3.0
- MSI B450M Pro-VDH V2
- MSI B450M Bazooka V2
- Asus Prime B450M - A / CSM
- Asus Prime H310I - Plus R2.0 / CSM
- Gigabyte GA-AB350M-DS3H V2 (rev. 1.1)
- Gigabyte B360 M AORUS PRO
- Gigabyte X299-WU8
- MSI MAG Z390M Mortar
- HARDWARE\DESCRIPTION\System\BIOS
- BaseBoardProduct
- BaseBoardVersion
- BaseBoardManufacturer
- SystemManufacturer
- BIOSReleaseDate
- SystemProductName
- American Megatrends Inc.
- Phoenix Technologies, Ltd
- Award Software, Inc.
- Intel Corporation
- Sun Microsystems
- SYSTEM\HardwareConfig\Current
- SYSTEM\CurrentControlSet\Control\SystemInformation
- ComputerHardwareId
- ABCDEFGHIJKLMNOPQRSTUVWXYZ
- abcdefghijklmnopqrstuvwxyz0123456789
- Software\Epic Games\Unreal Engine\Identifiers
- HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\0
- HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\1
- Software\Microsoft\Feeds
- BackgroundSync
- Software\Microsoft\IdentityCRL\ExtendedProperties
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\Connected
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\Disconnected
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\EmailImage
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\FaxImage
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\PrintImage
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\ScanButton
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\STIproxyEvent
- HKEY_LOCAL_MACHINE\Software\Microsoft\IdentityCRL\ExtendedProperties
- HKEY_CURRENT_USER\Software\Microsoft\Feeds
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\0
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\1
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\BIOS
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\IDConfigDB\Hardware Profiles\0001
- HKEY_LOCAL_MACHINE\SYSTEM\HardwareConfig\{b30417c0-53bd-11e5-8727-305a3ae502fe}
- HKEY_LOCAL_MACHINE\SYSTEM\HardwareConfig
- HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\DMR
- HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\General
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware Profiles\0001
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation
- ComputerHardwareIds
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e965-e325-11ce-bfc1-08002be10318}\Configuration\Variables\BusDeviceDesc
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\DeviceDesc
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\Driver
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WMI\Autologger\AppModel
- HKEY_LOCAL_MACHINE\SYSTEM\SYSTEM\HardwareConfig
- /c wmic useraccount where caption='
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Tcpip\Parameters
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
- RegisteredOwner
- RegisteredOrganization
- Virtual Machine
- ipconfig /release
- ipconfig /renew
- ipconfig /flushdns
- netsh advfirewall reset
- netsh int ipv6 reset
- netsh winsock reset
- netsh int ip reset
- Select * from Win32_ComputerSystem
- microsoft corporation
- C:\Program Files\DBG
- Anti Debug Detected:
- C:\Program Files\DBG\
- Win32_Process.Handle='
- HP Intel Core i3 - 6100
- IBM Intel Xeon E5620
- Lenovo Intel Xeon Silver 4114
- AMD Athlon 220GE Boxed
- AMD Athlon 240GE Boxed
- Intel Xeon E-2186G Tray
- Dell Intel Xeon Gold 5120
- AMD A8 - 7680 Boxed
- AMD Ryzen 7 2700 Wraith MAX Boxed
- AMD Ryzen 5 2600X Wraith Max Boxed
- AMD Ryzen 3 2300X Tray
- HARDWARE\DESCRIPTION\System\CentralProcessor\0
- ProcessorNameString
- SOFTWARE\Microsoft\Windows NT\CurrentVersion
- 17763.1.amd64fre.rs5_release.180914-
- 17763.rs5_release.180914-
- CurrentVersion
- CurrentBuildNumber
- HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 0\Target Id 0\Logical Unit Id 0
- HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 1\Target Id 0\Logical Unit Id 0
- SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate
- SOFTWARE\Microsoft\Internet Explorer\Registration
- HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 0\Target Id 2\Logical Unit Id 0
- SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName
- SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName
- SOFTWARE\Microsoft\Cryptography
- SYSTEM\ControlSet001\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}\Configuration\Variables\BusDeviceDesc
- SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\DeviceDesc
- SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\Driver
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName /v ComputerName /t REG_SZ /d PizzaXYZ-%random% /f
- Software\WOW6432Node
- Electronic Arts
- Software\Classes
- com.epicgames.launcher
- SOFTWARE\Classes
- SOFTWARE\WOW6432Node
- SOFTWARE\NVIDIA Corporation\Installer2
- HardwareConfig
- Software\Classes\Installer\Dependencies
- Software\Classes\Installer\Dependecies
- Software\Microsoft\Direct3D
- System\CurrentControlSet\Control
- SystemStartOptions
- SOFTWARE\Microsoft\RADAR\HeapLeakDetection
- DiagnosedApplications
- SYSTEM\ControlSet001\Services
- SYSTEM\ControlSet001\Services\EasyAntiCheat
- SYSTEM\CurrentControlSet\Services
- .DEFAULT\Software\Microsoft\SystemCertificates
- TrustedPublisher
- .DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher
- .DEFAULT\Software\Policies\Microsoft\SystemCertificates
- .DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher
- S-1-5-18\Software\Microsoft\SystemCertificates
- S-1-5-18\Software\Microsoft\SystemCertificates\TrustedPublisher
- S-1-5-18\Software\Policies\Microsoft\SystemCertificates
- SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications
- FortniteClient-Win64-Shipping.exe
- SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel
- SYSTEM\ControlSet001\Control
- Origin Client Service
- Origin Web Helper Service
- SOFTWARE\Classes\Applications
- SOFTWARE\Respawn
- SOFTWARE\WOW6432Node\Respawn
- SYSTEM\Setup\FirstBoot\Services
- SYSTEM\ControlSet001
- Hardware Profiles
- SYSTEM\CurrentControlSet\Software\Classes\Local Settings
- Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache
- DefaultAccount
- SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Deployment\Package
- SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Catalogs
- SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
- Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
- Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
- Software\Microsoft\Windows\CurrentVersion\Search\JumplistData
- SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\AppIso\FirewallRules
- \System\GameConfigStore
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName /v ComputerName /t REG_SZ /d I LOVE PIZZA-%random% /f
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName /v ComputerName /t REG_SZ /d I LOVE PIZZA-%random% /f
- REG ADD HKLM\SYSTEM\HardwareConfig /v LastConfig /t REG_SZ /d {I LOVE PIZZA-%random%} /f
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v HwProfileGuid /t REG_SZ /d {I LOVE PIZZA-%random%-%random%-%random%-%random%} /f
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v GUID /t REG_SZ /d {I LOVE PIZZA-%random%-%random%-%random%-%random%} /f
- REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d I LOVE PIZZA-%random% /f
- REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOwner /t REG_SZ /d I LOVE PIZZA-%random% /f
- REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOrganization /t REG_SZ /d I LOVE PIZZA-%random% /f
- REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d %random%-%random%-%random%-%random% /f
- REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d %random%-%random%-%random%-%random% /f
- REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v ProductId /t REG_SZ /d %random%-%random%-%random%-%random% /f
- REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_SZ /d %random% /f
- REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {%random%-%random%-%random%-%random%} /f
- REG ADD HKLM\HARDWARE\DESCRIPTION\System\BIOS /v SystemSKU /t REG_SZ /d I LOVE PIZZA-%random%-%random% /f
- REG ADD HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\1 /v ProcessorNameString /t REG_SZ /d %random%-%random% /f
- REG ADD HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\2 /v ProcessorNameString /t REG_SZ /d %random%-%random% /f
- REG ADD HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\3 /v ProcessorNameString /t REG_SZ /d %random%-%random% /f
- REG ADD HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0 /v ProcessorNameString /t REG_SZ /d %random%-%random% /f
- REG ADD "HKEY_CURRENT_USER\Software\Epic Games"
- REG ADD "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine"
- REG ADD "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Identifiers"
- reg delete "HKEY_LOCAL_MACHINE\Software\Epic Games" / f
- reg delete "HKEY_CURRENT_USER\Software\Epic Games" /f
- REG ADD "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Identifiers" /v AccountId /t REG_SZ /d %random%-%random%-%random%-%random% /f
- REG ADD "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Identifiers" /v Machineid /t REG_SZ /d %random%-%random%-%random%-%random% /f
- REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0000" /v NetCfgInstanceId /t REG_SZ /d {%random%-%random%-%random%-%random%} /f
- REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0000" /v MatchingDeviceId /t REG_SZ /d {%random%-%random%-%random%-%random%} /f
- http://clients3.google.com/generate_204
- UrMomIsfuckingGay
- @1B2c3D4e5F6g7H8
- \Documents\My Games
- \AppData\Local\BattlEye\r6s
- \Pictures\Uplay
- \AppData\Local\Ubisoft Game Launcher
- C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\logs
- C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\cache
- C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\crashes
- SOFTWARE\Microsoft\Windows NT\CurrentVersion\DefaultProductKey
- Software\Microsoft
- war nicht im zul
- ssigen Bereich! (BitNumber = (min)0 - (max)7)
- Win32_NetworkAdapterConfiguration
- SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\
- NetworkAddress
- backgroundTaskHost
- NVDisplay.Container
- ShellExperienceHost
- obs-ffmpeg-mux
- OBS Studio (64bit)
- Failed to grab WMI data
- C:\Windows\System32\config\DRIVERS.
- Your drivers File is corrupted
- Your Subscribtion expires on
- [1] Spoof BE (Diskdrive/ Bios/ Baseboard/ UUID)
- [2] Spoof EAC (Diskdrive/ Bios/ Baseboard/ UUID)
- [3] Unspoof Baseboard/ BIOS (Only, when used EAC Spoof)
- [4] Leight Cleaner for r6s
- [4] Spoof Network
- [5] Clean Files/ Registry
- sc stop winmgmt
- C:\Windows\System32\wbem\repository
- sc start winmgmt
- wmic diskdrive get serialnumber
- Spoofing Baseboard/ BIOS/ UUID...
- BaseBoard and Bios might need some minutes
- wmic path win32_networkadapter where PhysicalAdapter=True call disable
- wmic path win32_networkadapter where PhysicalAdapter=True call enable
- SELECT * FROM Win32_NetworkAdapter
- Spoofing Mac...
- SETLOCAL ENABLEDELAYEDEXPANSION
- SETLOCAL ENABLEEXTENSIONS
- FOR /F "tokens=1" %%a IN ('wmic nic where physicaladapter^=true get deviceid ^| findstr [0-9]') DO (
- CALL :MAC
- FOR %%b IN (0 00 000) DO (
- REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\%%b%%a >NUL 2>NUL && REG ADD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\%%b%%a /v NetworkAddress /t REG_SZ /d !MAC! /f >NUL 2>NUL
- )
- )
- FOR /F "tokens=1" %%a IN ('wmic nic where physicaladapter^=true get deviceid ^| findstr [0-9]') DO (
- FOR %%b IN (0 00 000) DO (
- REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\%%b%%a >NUL 2>NUL && REG ADD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\%%b%%a /v PnPCapabilities /t REG_DWORD /d 24 /f >NUL 2>NUL
- )
- )
- FOR /F "tokens=2 delims=, skip=2" %%a IN ('"wmic nic where (netconnectionid like '%%') get netconnectionid,netconnectionstatus /format:csv"') DO (
- netsh interface set interface name="%%a" disable >NUL 2>NUL
- netsh interface set interface name="%%a" enable >NUL 2>NUL
- )
- GOTO :EOF
- :MAC
- SET COUNT=0
- SET GEN=ABCDEF0123456789
- SET GEN2=26AE
- SET MAC=
- :MACLOOP
- SET /a COUNT+=1
- SET RND=%random%
- ::%%n,
- SET /A RND=RND%%16
- SET RNDGEN=!GEN:~%RND%,1!
- SET /A RND2=RND%%4
- SET RNDGEN2=!GEN2:~%RND2%,1!
- IF "!COUNT!" EQU "2" (SET MAC=!MAC!!RNDGEN2!) ELSE (SET MAC=!MAC!!RNDGEN!)
- IF !COUNT! LEQ 11 GOTO MACLOOP
- C:\Program Files\Windows Photo Viewer\mac.bat
- Cleaning System...
- Error: 111 (Contact I LOVE PIZZA#6740)
- Error: 111111 (Contact I LOVE PIZZA#6740)
- Cleaning Registry...
- Error: 112 (Contact I LOVE PIZZA#6740)
- SELECT * FROM Win32_BaseBoard
- SELECT * FROM Win32_ComputerSystemProduct
- SELECT * FROM Win32_Processor
- \AppData\Roaming\Microsoft\BaseBoard.dll
- \AppData\Roaming\Microsoft\UUID.dll
- \AppData\Roaming\Microsoft\Processor.dll
- SELECT * FROM Win32_BIOS
- C:\Windows\AMIDEWINx64.exe
- [+] Failed to download a File
- C:\Windows\amifldrv64.sys
- C:\Windows\AMIDEWINx64.exe /SS
- C:\Windows\AMIDEWINx64.exe /SU
- C:\Windows\AMIDEWINx64.exe /BS
- C:\Windows\AMIDEWINx64.exe /BSH
- C:\Windows\AMIDEWINx64.exe /PSN
- C:\Windows\Speech\EcXm42Tkyp.sys
- ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789abcdefghijklmopqrstuvwxyz
- C:\Windows\AMIDEWINx64.exe /SU auto
- C:\Windows\AMIDEWINx64.exe /CS
- C:\Windows\AMIDEWINx64.exe /CSH
- C:\devcon.exe /r remove =net
- C:\devcon.exe rescan
- && TIMEOUT 10"
- C:\Program Files\WindowsApps
- C:\Program Files (x86)\Progress\JustDecompile
- C:\Windows\servicing\LCU
- /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO Sanboxie, VM Or Emulation Detected! && TIMEOUT 10"
- SELECT * FROM Win32_VideoController
- /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO Run as Admin! && TIMEOUT 10"
- C:\Windows\explorer.exe
- vp5wsKKVVUdZoqyQs80hPApD3keP9BV1MQ1O1DPUJgvTK
- [+] Main Menu:
- Do you want to remove auto login? [Y][N]
- Newtonsoft.Json.dll
- 4df6c8781e70c3a4912b5be796e6d337
- TrinitySeal.dll
- 0ac32b36f97427f59bd8e179c2594d95
- /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO File Tampering Detected! && TIMEOUT 10"
- WrapNonExceptionThrows
- Nemesis-76523
- Nemesis-76523 2019
- $9af2bc0b-b116-4e19-9cf2-8ed7463c2ecb
- .NETFramework,Version=v4.7.2
- FrameworkDisplayName
- .NET Framework 4.7.2
- VS_VERSION_INFO
- StringFileInfo
- FileDescription
- LegalCopyright
- Nemesis-76523 2019
- LegalTrademarks
- OriginalFilename
- ProductVersion
- Assembly Version
- <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
- <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
- <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
- <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
- <security>
- <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
- <requestedExecutionLevel level="asInvoker" uiAccess="false"/>
- </requestedPrivileges>
- </security>
- </trustInfo>
- </assembly>
- --------------------------------------------------
- Finished in 3.25834 seconds.
- --------------------
- Files
- --------------------
- 9d123.sys : https://cdn.discordapp.com/attachments/619316777326870530/619323747052027964/9d123.sys
- Dibbu.sys : https://cdn.discordapp.com/attachments/619316777326870530/619323878052724736/Dibbu.sys
- Cheat.dll : https://cdn.discordapp.com/attachments/619316777326870530/619324185969295380/cheat_1.dll
- Rand.sys : https://cdn.discordapp.com/attachments/619316777326870530/619324317531897886/Rand.sys
- Mappi.exe : https://cdn.discordapp.com/attachments/619316777326870530/619343977199566858/Mappi.exe
- Epic.dll : https://cdn.discordapp.com/attachments/619316777326870530/619344123710930954/Epic_1.dll
- Mac.exe : https://cdn.discordapp.com/attachments/619316777326870530/619344274705874945/Mac_1.exe
- Adapt.exe : https://cdn.discordapp.com/attachments/619316777326870530/619344345987940352/Adapt.exe
- WMI.bat : https://cdn.discordapp.com/attachments/619316777326870530/619344432369762324/WMI_1.bat
- -------
- Usage
- -------
- I dont know how those are used, but most of them are public so you can find "docs" on it
Add Comment
Please, Sign In to add comment