ZernaxLeDozo

Karma Spoofer String Dump, files at the bottom, usage too

Sep 13th, 2019
126
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 210.27 KB | None | 0 0
  1.  
  2. String Dumper - Based off strings2 (adds string decryption, regex to match only pertinent strings.)
  3.  
  4. Starting in 10 ms.
  5. Started...
  6.  
  7. !This program cannot be run in DOS mode.
  8. $
  9. !This program cannot be run in DOS mode.
  10. $
  11. CorExitProcess
  12. !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
  13. runtime error
  14. DOMAIN error
  15.  
  16. R6034
  17. An application has made an attempt to load the C runtime library incorrectly.
  18. Please contact the application's support team for more information.
  19.  
  20. R6033
  21. - Attempt to use MSIL code from this assembly during native code initialization
  22. This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
  23.  
  24. R6032
  25. - not enough space for locale information
  26.  
  27. R6031
  28. - Attempt to initialize the CRT more than once.
  29. This indicates a bug in your application.
  30.  
  31. R6030
  32. - CRT not initialized
  33.  
  34. R6028
  35. - unable to initialize heap
  36.  
  37. R6027
  38. - not enough space for lowio initialization
  39.  
  40. R6026
  41. - not enough space for stdio initialization
  42.  
  43. R6025
  44. - pure virtual function call
  45.  
  46. R6024
  47. - not enough space for _onexit/atexit table
  48.  
  49. R6019
  50. - unable to open console device
  51.  
  52. R6018
  53. - unexpected heap error
  54.  
  55. R6017
  56. - unexpected multithread lock error
  57.  
  58. R6016
  59. - not enough space for thread data
  60.  
  61.  
  62. This application has requested the Runtime to terminate it in an unusual way.
  63. Please contact the application's support team for more information.
  64.  
  65. R6009
  66. - not enough space for environment
  67.  
  68. R6008
  69. - not enough space for arguments
  70.  
  71. R6002
  72. - floating point support not loaded
  73.  
  74. Microsoft Visual C++ Runtime Library
  75. <program name unknown>
  76. Runtime Error!
  77.  
  78. Program:
  79. ((((( H
  80. h(((( H
  81. H
  82. !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
  83. !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
  84. dddd, MMMM dd, yyyy
  85. GetProcessWindowStation
  86. GetUserObjectInformationA
  87. GetLastActivePopup
  88. GetActiveWindow
  89. SunMonTueWedThuFriSat
  90. JanFebMarAprMayJunJulAugSepOctNovDec
  91. GetCurrentThreadId
  92. GetCommandLineA
  93. TerminateProcess
  94. GetCurrentProcess
  95. UnhandledExceptionFilter
  96. SetUnhandledExceptionFilter
  97. IsDebuggerPresent
  98. GetModuleHandleW
  99. GetProcAddress
  100. InterlockedIncrement
  101. InterlockedDecrement
  102. SetHandleCount
  103. GetStartupInfoA
  104. DeleteCriticalSection
  105. GetModuleFileNameA
  106. FreeEnvironmentStringsA
  107. GetEnvironmentStrings
  108. FreeEnvironmentStringsW
  109. WideCharToMultiByte
  110. GetEnvironmentStringsW
  111. QueryPerformanceCounter
  112. GetCurrentProcessId
  113. GetSystemTimeAsFileTime
  114. LeaveCriticalSection
  115. EnterCriticalSection
  116. IsValidCodePage
  117. InitializeCriticalSectionAndSpinCount
  118. GetLocaleInfoA
  119. GetStringTypeA
  120. MultiByteToWideChar
  121. GetStringTypeW
  122. NativeEncoderx86.dll
  123. getEngineVersion
  124.  
  125. abcdefghijklmnopqrstuvwxyz
  126. ABCDEFGHIJKLMNOPQRSTUVWXYZ
  127.  
  128. abcdefghijklmnopqrstuvwxyz
  129. ABCDEFGHIJKLMNOPQRSTUVWXYZ
  130. 3/343:3@3V3]3k3q3|3
  131. 8"8(8/858=8D8I8Q8Z8f8k8p8v8z8
  132. 9'949?9Q9d9o9u9{9
  133. 11181<1@1D1H1L1P1T1
  134. 2!2<2C2H2L2P2q2
  135. :
  136. :":):3:;:H:O:
  137. 11181<1@1D1H1L1P1T1
  138. 2!2<2C2H2L2P2q2
  139. 2(282\2h2l2p2t2x2
  140. 9$9,949<9D9L9T9\9d9l9t9|9
  141. : :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
  142. !This program cannot be run in DOS mode.
  143. $
  144. D$X9D$,}$HcL$,H
  145. @USVWATAUAVAWH
  146. eHA_A^A]A\_^[]
  147. CorExitProcess
  148. !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
  149. runtime error
  150. DOMAIN error
  151.  
  152. R6034
  153. An application has made an attempt to load the C runtime library incorrectly.
  154. Please contact the application's support team for more information.
  155.  
  156. R6033
  157. - Attempt to use MSIL code from this assembly during native code initialization
  158. This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
  159.  
  160. R6032
  161. - not enough space for locale information
  162.  
  163. R6031
  164. - Attempt to initialize the CRT more than once.
  165. This indicates a bug in your application.
  166.  
  167. R6030
  168. - CRT not initialized
  169.  
  170. R6028
  171. - unable to initialize heap
  172.  
  173. R6027
  174. - not enough space for lowio initialization
  175.  
  176. R6026
  177. - not enough space for stdio initialization
  178.  
  179. R6025
  180. - pure virtual function call
  181.  
  182. R6024
  183. - not enough space for _onexit/atexit table
  184.  
  185. R6019
  186. - unable to open console device
  187.  
  188. R6018
  189. - unexpected heap error
  190.  
  191. R6017
  192. - unexpected multithread lock error
  193.  
  194. R6016
  195. - not enough space for thread data
  196.  
  197.  
  198. This application has requested the Runtime to terminate it in an unusual way.
  199. Please contact the application's support team for more information.
  200.  
  201. R6009
  202. - not enough space for environment
  203.  
  204. R6008
  205. - not enough space for arguments
  206.  
  207. R6002
  208. - floating point support not loaded
  209.  
  210. Microsoft Visual C++ Runtime Library
  211. <program name unknown>
  212. Runtime Error!
  213.  
  214. Program:
  215. ((((( H
  216. h(((( H
  217. H
  218. !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
  219. !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
  220. dddd, MMMM dd, yyyy
  221. GetProcessWindowStation
  222. GetUserObjectInformationA
  223. GetLastActivePopup
  224. GetActiveWindow
  225. SunMonTueWedThuFriSat
  226. JanFebMarAprMayJunJulAugSepOctNovDec
  227. GetCurrentThreadId
  228. GetCommandLineA
  229. GetModuleHandleW
  230. GetProcAddress
  231. SetHandleCount
  232. GetStartupInfoA
  233. DeleteCriticalSection
  234. GetModuleFileNameA
  235. FreeEnvironmentStringsA
  236. GetEnvironmentStrings
  237. FreeEnvironmentStringsW
  238. WideCharToMultiByte
  239. GetEnvironmentStringsW
  240. HeapSetInformation
  241. QueryPerformanceCounter
  242. GetCurrentProcessId
  243. GetSystemTimeAsFileTime
  244. LeaveCriticalSection
  245. EnterCriticalSection
  246. IsValidCodePage
  247. TerminateProcess
  248. GetCurrentProcess
  249. UnhandledExceptionFilter
  250. SetUnhandledExceptionFilter
  251. IsDebuggerPresent
  252. RtlVirtualUnwind
  253. RtlLookupFunctionEntry
  254. RtlCaptureContext
  255. InitializeCriticalSectionAndSpinCount
  256. GetLocaleInfoA
  257. GetStringTypeA
  258. MultiByteToWideChar
  259. GetStringTypeW
  260. NativeEncoderx64.dll
  261. getEngineVersion
  262.  
  263. abcdefghijklmnopqrstuvwxyz
  264. ABCDEFGHIJKLMNOPQRSTUVWXYZ
  265.  
  266. abcdefghijklmnopqrstuvwxyz
  267. ABCDEFGHIJKLMNOPQRSTUVWXYZ
  268. !This program cannot be run in DOS mode.
  269. $
  270. KeyValuePair`2
  271. IL_Emulator_Dynamic
  272. System.Collections.Generic
  273. RijndaelManaged
  274. CreateInstance
  275. extractResource
  276. byteArrayResource
  277. CryptoStreamMode
  278. GetEnvironmentVariable
  279. SetEnvironmentVariable
  280. get_MethodHandle
  281. RuntimeMethodHandle
  282. GetModuleHandle
  283. RuntimeTypeHandle
  284. GetTypeFromHandle
  285. get_ManifestModule
  286. get_DeclaringType
  287. get_ReturnType
  288. get_MemberType
  289. get_ParameterType
  290. get_ProcessorArchitecture
  291. MulticastDelegate
  292. WhereAlternate
  293. DebuggableAttribute
  294. ComVisibleAttribute
  295. AssemblyTitleAttribute
  296. AssemblyTrademarkAttribute
  297. AssemblyFileVersionAttribute
  298. ObfuscationAttribute
  299. AssemblyConfigurationAttribute
  300. AssemblyDescriptionAttribute
  301. CompilationRelaxationsAttribute
  302. AssemblyProductAttribute
  303. AssemblyCopyrightAttribute
  304. AssemblyCompanyAttribute
  305. RuntimeCompatibilityAttribute
  306. System.Threading
  307. ConversionBack
  308. BeginCatchBlock
  309. FlushFinalBlock
  310. EndExceptionBlock
  311. BeginExceptionBlock
  312. BeginFinallyBlock
  313. System.ComponentModel
  314. GetManifestResourceStream
  315. get_BaseStream
  316. SymmetricAlgorithm
  317. ICryptoTransform
  318. System.Reflection
  319. Win32Exception
  320. DllNotFoundException
  321. ArgumentNullException
  322. LocalVariableInfo
  323. ConstructorInfo
  324. byteArrayGrabber
  325. processExceptionHandler
  326. checkAndSetExceptionHandler
  327. get_ReturnParameter
  328. GetDelegateForFunctionPointer
  329. GetFunctionPointer
  330. InlineI8Emitter
  331. ShortInlineIEmitter
  332. ShortInlineREmitter
  333. InlineFieldEmitter
  334. InlineMethodEmitter
  335. InlineNoneEmitter
  336. InlineTypeEmitter
  337. InlineStringEmitter
  338. InlineSwitchEmitter
  339. InlineTokEmitter
  340. InlineVarEmitter
  341. ShortInlineBrTargetEmitter
  342. GetILGenerator
  343. GetConstructor
  344. CreateDecryptor
  345. System.Diagnostics
  346. System.Runtime.InteropServices
  347. System.Runtime.CompilerServices
  348. oneByteOpCodes
  349. twoByteOpCodes
  350. DebuggingModes
  351. get_LocalVariables
  352. GetManifestResourceNames
  353. _allExceptionHandlerses
  354. ExtractEmbeddedDlls
  355. System.Collections
  356. VMExample.Instructions
  357. fixAndSortExceptionHandlers
  358. EmbeddedDllClass
  359. ExceptionHandlerClass
  360. FixedExceptionHandlersClass
  361. GetProcAddress
  362. lpflOldProtect
  363. VirtualProtect
  364. System.Reflection.Emit
  365. GetILAsByteArray
  366. System.Security.Cryptography
  367. GetExecutingAssembly
  368. _allLabelsDictionary
  369. CreateDirectory
  370. IsDebuggerPresent
  371. Operand Type Unknown
  372. Check resolvedMethodBase Type
  373. Please call ExtractEmbeddedDlls before LoadDll
  374. Unable to load library:
  375. WrapNonExceptionThrows
  376. $520b7746-86a7-4021-87b4-507236a14cae
  377. virtualizationT
  378. C:\Users\buett\Desktop\VM\Runtime\obj\Debug\Runtime.pdb
  379. VS_VERSION_INFO
  380. StringFileInfo
  381. FileDescription
  382. LegalCopyright
  383. LegalTrademarks
  384. OriginalFilename
  385. ProductVersion
  386. Assembly Version
  387. !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
  388. #$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
  389. b!b+b2b;bDbObYbsbyb
  390. c"c-c6c=cFcUchctc
  391. e*e;eCeKeTe_eoewe
  392. System.Reflection
  393. GetExecutingAssembly
  394. get_BaseStream
  395. System.Security.Cryptography
  396. BadImageFormatException
  397. ManualResetEvent
  398. System.Threading
  399. EventWaitHandle
  400. set_IsBackground
  401. System.Diagnostics
  402. GetCurrentProcess
  403. get_ProcessName
  404. ProcessStartInfo
  405. set_CreateNoWindow
  406. set_UseShellExecute
  407. CreateDirectory
  408. get_MainWindowTitle
  409. Microsoft.Win32
  410. get_IsAttached
  411. GCCollectionMode
  412. set_ForegroundColor
  413. System.Drawing
  414. Colorful.Console
  415. SetCursorPosition
  416. GetDirectories
  417. set_RedirectStandardInput
  418. get_StandardInput
  419. set_RedirectStandardOutput
  420. System.Management
  421. ManagementObjectSearcher
  422. ManagementObjectCollection
  423. ManagementObjectEnumerator
  424. ManagementBaseObject
  425. set_RedirectStandardError
  426. get_StandardOutput
  427. get_StandardError
  428. RegistryValueKind
  429. ToUpperInvariant
  430. GetProcessesByName
  431. ManagementObject
  432. ObjectGetOptions
  433. GetMethodParameters
  434. InvokeMethodOptions
  435. Rfc2898DeriveBytes
  436. RijndaelManaged
  437. SymmetricAlgorithm
  438. CreateEncryptor
  439. ICryptoTransform
  440. CryptoStreamMode
  441. FlushFinalBlock
  442. ToBase64String
  443. FromBase64String
  444. CreateDecryptor
  445. GetSubKeyNames
  446. GetCallingAssembly
  447. GetManifestResourceStream
  448. DeleteSubKeyTree
  449. NetworkInterface
  450. System.Net.NetworkInformation
  451. GetAllNetworkInterfaces
  452. ManagementClass
  453. get_OperationalStatus
  454. OperationalStatus
  455. GetPhysicalAddress
  456. PhysicalAddress
  457. get_BasePriority
  458. FromMilliseconds
  459. System.ServiceProcess
  460. ServiceController
  461. ServiceControllerStatus
  462. WindowsIdentity
  463. System.Security.Principal
  464. WindowsPrincipal
  465. WindowsBuiltInRole
  466. WaitForPendingFinalizers
  467. OperatingSystem
  468. set_WindowStyle
  469. ProcessWindowStyle
  470. ToLowerInvariant
  471. RuntimeFieldHandle
  472. NtSetInformationProcess
  473. Nemesis_Recode
  474. SetProcessWorkingSetSize
  475. VirtualProtect
  476. GetModuleHandle
  477. GetProcAddress
  478. GetFileAttributes
  479. MulticastDelegate
  480. CompilationRelaxationsAttribute
  481. System.Runtime.CompilerServices
  482. RuntimeCompatibilityAttribute
  483. DebuggableAttribute
  484. DebuggingModes
  485. AssemblyTitleAttribute
  486. AssemblyDescriptionAttribute
  487. AssemblyConfigurationAttribute
  488. AssemblyCompanyAttribute
  489. AssemblyProductAttribute
  490. AssemblyCopyrightAttribute
  491. AssemblyTrademarkAttribute
  492. ComVisibleAttribute
  493. System.Runtime.InteropServices
  494. AssemblyFileVersionAttribute
  495. TargetFrameworkAttribute
  496. System.Runtime.Versioning
  497. CompilerGeneratedAttribute
  498. DebuggerBrowsableAttribute
  499. DebuggerBrowsableState
  500. System.Reflection.Emit
  501. GetFieldFromHandle
  502. get_MetadataToken
  503. ResolveSignature
  504. GetOptionalCustomModifiers
  505. GetCustomAttributes
  506. CreateDelegate
  507. get_DeclaringType
  508. get_ParameterType
  509. get_ReturnType
  510. get_IsInterface
  511. GetDynamicILInfo
  512. SetLocalSignature
  513. get_IsConstructor
  514. get_TypeHandle
  515. RuntimeTypeHandle
  516. get_MethodHandle
  517. RuntimeMethodHandle
  518. System.Collections.Generic
  519. FirstOrDefault
  520. InvalidOperationException
  521. EnterDebugMode
  522. GetPropertyValue
  523. ResolveAssembly
  524. ResolveEventArgs
  525. ConversionBack
  526. get_CurrentDomain
  527. ResolveEventHandler
  528. add_AssemblyResolve
  529. FolderChangesView
  530. simpleassembly
  531. Progress Telerik Fiddler Web Debugger
  532. ImmunityDebugger
  533. SimpleAssemblyExplorer
  534. Simple Assembly Explorer
  535. awfawgawgawgha
  536. awfawgfawawgawgawhw
  537. awgawgawwhaedawd
  538. opauhwfpoauwhgfpauoiwhg
  539. /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO
  540. Detected! && TIMEOUT 10"
  541. C:\ProgramData\Pizza
  542. C:\ProgramData\Pizza\
  543. Software\Microsoft\Windows\CurrentVersion\Internet Settings
  544. C:\WINDOWS\System32\Drivers\Etc\hosts
  545. C:\ProgramData\Karma
  546. C:\ProgramData\Karma\DisableProxy.txt
  547. /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO Proxy Enabled While Running Software! && TIMEOUT 10"
  548. pizzaxyz.bplaced.net
  549. grab.bplaced.net
  550. cdn.discordapp.com
  551. FiddlerCore4.dll
  552. Titanium.Web.Proxy.dll
  553. /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO Fidler DLL Detected While Running Software! && TIMEOUT 10"
  554. /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO Debugger atached! && TIMEOUT 10"
  555. Karma Spoofer |
  556. K |
  557. A |
  558. R |
  559. M |
  560. A |
  561. * |
  562. K |
  563. A |
  564. R |
  565. M |
  566. A |
  567. K |
  568. R |
  569. M |
  570. K |
  571. A |
  572. R |
  573. M |
  574. A |
  575. * |
  576. EpicGamesLauncher
  577. FortniteClient-Win64-Shipping
  578. C:\Windows\System32\config
  579. C:\Windows\Temp
  580. cmd /C "REG ADD HKLM\SYSTEM\HardwareConfig /v LastConfig /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  581. cmd /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v HwProfileGuid /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  582. cmd /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v GUID /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  583. cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  584. cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOwner /t REG_SZ /d %%random%%%%random%%%%random%% /f"
  585. cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOrganization /t REG_SZ /d %%random%%%%random%%%%random%% /f"
  586. cmd /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  587. cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography" /v MachineGuid /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  588. cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v BuildGUID /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  589. cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}\Configuration\Variables\BusDeviceDesc" /v PropertyGuid /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  590. cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\DeviceDesc" /v PropertyGuid /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  591. cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation" /v ComputerHardwareId /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  592. cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  593. cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  594. cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_SZ /d %%random%% /f"
  595. cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v ProductId /t REG_SZ /d %%random%%-%%random%%-%%random%%-%%random%% /f"
  596. cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOrganization /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  597. cmd /C "REG ADD HKLM\System\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  598. cmd /C "REG ADD HKLM\System\CurrentControlSet\Control\WMI\Security /v 671a8285-4edb-4cae-99fe-69a15c48c0bc /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  599. cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion" "WindowsUpdate /v SusClientId /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f
  600. cmd /C "REG DELETE HKLM\Hardware\Description\System\BIOS /v BIOSVendor /f"
  601. cmd /C "REG DELETE HKLM\Hardware\Description\System\BIOS /v BIOSReleaseDate /f"
  602. cmd /C "REG DELETE HKLM\Hardware\Description\System\BIOS /v SystemManufacturer /f"
  603. cmd /C "REG DELETE HKLM\Hardware\Description\System\BIOS /v SystemProductName /f"
  604. cmd /C "REG DELETE HKLM\Hardware\Description\System\CentralProcessor\0 /v ProcessorNameString /f"
  605. cmd /C "REG DELETE HKLM\SYSTEM\HardwareConfig /f"
  606. cmd /C "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\Profile\Profile /v Guid /t REG_SZ /d {%08x-%04x-%04x-%04x-%04x%08x} /f"
  607. cmd /C net stop FACEIT
  608. cmd /C net stop ESEADriver2
  609. cmd /C net stop BEDaisy
  610. cmd /C net stop EasyAntiCheat
  611. cmd /C "taskkill /f /im EpicGamesLauncher.exe >nul 2>&1"
  612. cmd /C "taskkill /f /im FortniteClient-Win64-Shipping_EAC.exe >nul 2>&1"
  613. cmd /C "taskkill /f /im FortniteClient-Win64-Shipping.exe >nul 2>&1"
  614. cmd /C "taskkill /f /im FortniteClient-Win64-Shipping_BE.exe >nul 2>&1"
  615. cmd /C "taskkill /f /im FortniteLauncher.exe >nul 2>&1"
  616. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\UnrealEngine\*.*" >nul 2>&1"
  617. cmd /C "rmdir /s /q "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame" "
  618. cmd /C "del /s /f /a:h /a:a /q "%%systemdrive%%\Users\%%username%%\AppData\Local\UnrealEngine\* .*" >nul 2>&1"
  619. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\Logs\*.*" >nul 2>&1"
  620. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\*.*" >nul 2>&1"
  621. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\*.*" >nul 2>&1"
  622. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\Config\WindowsClient\*.*" >nul 2>&1"
  623. cmd /C "del /s /f /a:h /a:a /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\*.*" >nul 2>&1"
  624. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\LMS\*.*" >nul 2>&1"
  625. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\Cloud\*.*" >nul 2>&1"
  626. cmd /C "del /s /f /a:h /a:a /q "C:\Recovery\ntuser.sys\*.*" >nul 2>&1"
  627. cmd /C "del /s /f /a:h /a:a /q "C:\Users\Public\Libraries\collection.dat\*.*" >nul 2>&1"
  628. cmd /C "del /s /f /a:h /a:a /q "C:\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat\*.*" >nul 2>&1"
  629. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Feeds\*.*" >nul 2>&1"
  630. cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache\*.*" >nul 2>&1"
  631. cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules\*.*" >nul 2>&1"
  632. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\History\History.IE5\*.*" >nul 2>&1"
  633. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Speech Graphics\Carnival\*.*" >nul 2>&1"
  634. cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\WER\Temp\*.*" >nul 2>&1"
  635. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5\*.*" >nul 2>&1"
  636. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies\*.*" >nul 2>&1"
  637. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\*.*" >nul 2>&1"
  638. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\*.*" >nul 2>&1"
  639. cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\UnrealEngine\*.*"
  640. cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\Logs\*.*"
  641. cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\*.*"
  642. cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\*.*"
  643. cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\Config\WindowsClient\*.*"
  644. cmd /C "del /f /s /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\*.*"
  645. cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\LMS\*.*"
  646. cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\Cloud\*.*"
  647. cmd /C "del /f /s /q "C:\Recovery\ntuser.sys\*.*"
  648. cmd /C "del /f /s /q "C:\Users\Public\Libraries\collection.dat\*.*"
  649. cmd /C "del /f /s /q "C:\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat\*.*"
  650. cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\WebCache\*.*"
  651. cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Feeds\*.*""
  652. cmd /C "del /f /s /q "C:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache\*.*"
  653. cmd /C "del /f /s /q "C:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules\*.*"
  654. cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\History\History.IE5\*.*"
  655. cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\Speech Graphics\Carnival\*.*"
  656. cmd /C "del /f /s /q "C:\ProgramData\Microsoft\Windows\WER\Temp\*.*"
  657. cmd /C "del /f /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5\*.*"
  658. cmd /C "del /f /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies\*.*"
  659. cmd /C "del /f /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\*.*"cmd /C "del /f /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\*.*"
  660. cmd /C "del /s /f /q C:\Windows\Public\Libraries\*.*"
  661. cmd /C "del /s /f /q C:\Windows\Prefetch\*.*"
  662. cmd /C "del /f /s /q C:\Intel\*.*""
  663. cmd /C "del /f /s /q C:\desktop.ini\*.*""
  664. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\UnrealEngine""
  665. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\Logs""
  666. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage""
  667. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\LMS""
  668. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\Cloud""
  669. cmd /C "rmdir /s /q "C:\Recovery\ntuser.sys""
  670. cmd /C "rmdir /s /q "C:\Users\Public\Libraries\collection.dat""
  671. cmd /C "rmdir /s /q "C:\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat""
  672. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Feeds""
  673. cmd /C "rmdir /s /q "C:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache""
  674. cmd /C "rmdir /s /q "C:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules""
  675. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\History\History.IE5""
  676. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Speech Graphics\Carnival""
  677. cmd /C "rmdir /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5""
  678. cmd /C "rmdir /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies""
  679. cmd /C "rmdir /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData""
  680. cmd /C "rmdir /s /q "C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content""
  681. cmd /C "rmdir /s /q "C:\Windows\Public\Libraries""
  682. cmd /C "rmdir /s /q "C:\Intel""
  683. cmd /C "rmdir /s /q "C:\desktop.ini""
  684. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.*"
  685. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat\*.*"
  686. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.jfm\*.*"
  687. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\*.*"
  688. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\INetCache\IE\*.*"
  689. cmd /C "del /s /f /a:h /a:a /q "C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys\*.*"
  690. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\Videos\Captures\desktop.ini\*.*"
  691. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\*.*"
  692. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\INetHistory\*.*"
  693. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat\*.*"
  694. cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx\*.*"
  695. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Internet Explorer\CacheStorage\*.*"
  696. cmd /C "del /s /f /a:h /a:a /q "C:\Program Files (x86)\AMD\CNext\CCCSlim\*.*"
  697. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\NVIDIA Corporation\*.*"
  698. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\*.*"
  699. cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\XboxLive\NSALCache\*.*"
  700. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\PlaceholderTileLogoFolder\*.*"
  701. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\LocalLow\Microsoft\CryptnetUrlCache\*.*"
  702. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\WebCache\*.*"
  703. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Themes\CachedFiles\*.*"
  704. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\*.*"
  705. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\Prefetch\*.*"
  706. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\LMS\*.*"
  707. cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Diagnosis\EventStore.db-wal\*.*"
  708. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\perfc009.dat\*.*"
  709. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\perfh009.dat\*.*"
  710. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\PerfStringBackup.TMP\*.*"
  711. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\PerfStringBackup.INI\*.*"
  712. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\ntuser.dat.LOG2\*.*"
  713. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\wbem\Performance\WmiApRpl.ini\*.*"
  714. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\TEMP\*.*"
  715. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SoftwareDistribution\DataStore\*.*"
  716. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\WDI\LogFiles\StartupInfo\*.*"
  717. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs\*.*"
  718. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\*.*"
  719. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SysWOW64\Gms.log\*.*"
  720. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\spp\store\2.0\cache\*.*"
  721. cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\USOShared\Logs\*.*"
  722. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\*.*"
  723. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\WER\ERC\*.*"
  724. cmd /C "del /s /q /f /a ".\desktop.ini""
  725. cmd /C "del /s /ah desktop.ini."
  726. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync\remotemetastore\v1\edb.log\*.*"
  727. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync\metastore\edb.log\*.*"cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Comms\Unistore\data\3\*.*"
  728. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Comms\Unistore\data\temp\*.*"
  729. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AppData\User\Default\Indexed DB\edb.log\*.*"
  730. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb\*.*"
  731. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\b05132b02959bc64.automaticDestinations-ms\*.*"
  732. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\EasyAntiCheat\*.*"
  733. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTGraphicsPerfMonitorSession.etl\*.*"
  734. cmd /C "del /f /s /q "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame\*.*""
  735. cmd /C "rmdir /s /q "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\FortniteGame""
  736. cmd /C "RD /S /Q "%%localappdata%%\FortniteGame""
  737. cmd /C "RD /S /Q "%%localappdata%%\EpicGamesLauncher""
  738. cmd /C "RD /S /Q "%%localappdata%%\UnrealEngine""
  739. cmd /C "RD /S /Q "%%localappdata%%\UnrealEngineLauncher""
  740. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\Recovery\Active\*.*" >nul 2>&1"
  741. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!002\MicrosoftEdge\User\Default\AppCache\*.*" >nul 2>&1"
  742. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Recent\Autom\*.*" >nul 2>&1"
  743. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\rescache\_merged\*.*" >nul 2>&1"
  744. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\ntuser.dat.LOG1\*.*" >nul 2>&1"
  745. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\ntuser.dat.LOG2\*.*" >nul 2>&1"
  746. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\OneDrive\settings\Personal\logUploaderSettings_temp.ini\*.*" >nul 2>&1"
  747. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\OneDrive\settings\Personal\logUploaderSettings.ini\*.*" >nul 2>&1"
  748. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\sru\*.*" >nul 2>&1"
  749. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\OneDrive\logs\Common\DeviceHealthSummaryConfiguration.ini\*.*" >nul 2>&1"
  750. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\Logs\MoSetup\UpdateAgent.log\*.*" >nul 2>&1"
  751. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SoftwareDistribution\PostRebootEventCache.V2\{323558A6-0300-4C3E-97A0-EDEDFEB96B00}.bin\*.*" >nul 2>&1"
  752. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync\metastore\*.*" >nul 2>&1"
  753. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTGraphicsPerfMonitorSession.etl\*.*" >nul 2>&1"
  754. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\NVIDIA Corporation\GfeSDK\*.*" >nul 2>&1"
  755. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SoftwareDistribution\DataStore\Logs\*.*" >nul 2>&1"
  756. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\Logs\*.*" >nul 2>&1"
  757. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Comms\Unistore\data\*.*" >nul 2>&1"
  758. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Comms\UnistoreDB\USS.jtx\*.*" >nul 2>&1"
  759. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Feeds\*.*" >nul 2>&1\*.*" >nul 2>&1"
  760. cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGameOverlay_1.42.4001.0_x64__8wekyb3d8bbwe\ActivationStore.dat\*.*" >nul 2>&1"
  761. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\DiagOutputDir\*.*" >nul 2>&1"
  762. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\WebCache\*.*" >nul 2>&1"
  763. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\ServiceState\EventLog\Data\lastalive0.dat\*.*" >nul 2>&1"
  764. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2\*.*" >nul 2>&1"
  765. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1\*.*" >nul 2>&1"
  766. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\INetCache\*.*" >nul 2>&1"
  767. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\WindowsUpdate.log\*.*" >nul 2>&1"
  768. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SoftwareDistribution\DataStore\DataStore.edb\*.*" >nul 2>&1"
  769. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log\*.*" >nul 2>&1"
  770. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\Safety\edge\remote\*.*" >nul 2>&1"cmd /C "del /s /f /a:h /a:a /q "C:\Windows\SoftwareDistribution\DataStore\Logs\*.*"
  771. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\config\DEFAULT.LOG2\*.*"
  772. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\config\SYSTEM.LOG2\*.*"
  773. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\appcompat\appraiser\AltData\Appraiser_Data.ini\*.*"
  774. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\Logs\*.*"
  775. cmd /C "del /s /f /a:h /a:a /q "C:\System Volume Information\*.*"
  776. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\dosvcState.dat.LOG1\*.*"
  777. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\appcompat\Programs\Amcache.hve.LOG1\*.*"
  778. cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\ClipSVC\*.*"
  779. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\CloudStore\*.*"
  780. cmd /C "del /s /f /a:h /a:a /q "C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePacken-GB_17763.9.22.0_neutral__8wekyb3d8bbwe\Windows\System32\driverstore\*.*"
  781. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\Logs\CBS\CBS.log\*.*"
  782. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\History\History.IE5\*.*"
  783. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\OneDrive\logs\Common\DeviceHealthSummaryConfiguration.ini\*.*"
  784. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\Logs\MoSetup\*.*"
  785. cmd /C "del /s /f /a:h /a:a /q "C:\Program Files (x86)\Common Files\BattlEye\*.*"
  786. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\AMD\DxCache\*.*"
  787. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\NVIDIA Corporation\GfeSDK\*.*"
  788. cmd /C "del /s /f /a:h /a:a /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\*.*"
  789. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\INetCookies\*.*"
  790. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1\*.*"
  791. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\LogFiles\WMI\LwtNetLog.etl\*.*"
  792. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\ntuser.dat.LOG1\*.*"
  793. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\Notepad++\backup\*.*"
  794. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\temp\*.*"
  795. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\INF\*.*"
  796. cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\WER\Temp\*.*"
  797. cmd /C "del /s /f /a:h /a:a /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\Shared Files\*.*"
  798. cmd /C "rmdir /s /q "C:\ProgramData\Microsoft\Windows\WER\Temp""
  799. cmd /C "rmdir /s /q "C:\Windows\temp""
  800. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\*.*"
  801. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\*.*"
  802. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\*.*"
  803. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\*.*"
  804. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\OneDrive\logs\*.*"
  805. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\TempState""
  806. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Roaming\EasyAntiCheat""
  807. cmd /C "del /s /f /a:h /a:a /q "C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys\*.*"
  808. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache""
  809. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations""
  810. cmd /C "rmdir /s /q "C:\Program Files (x86)\Common Files\BattlEye""
  811. cmd /C "del /s /f /a:h /a:a /q "C:\desktop.ini\*.*"
  812. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\CloudStore""
  813. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame\Saved\Config\WindowsClient""
  814. cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\regid.1991-06.com.microsoft\*.*"
  815. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\WebCache""
  816. cmd /C "rmdir /s /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir""
  817. cmd /C "rmdir /s /q "C:\Windows\System32\LogFiles""
  818. cmd /C "rmdir /s /q "C:\Windows\Logs""
  819. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\OneDrive\logs""
  820. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\EpicGamesLauncher""
  821. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\Explorer""
  822. cmd /C "rmdir /s /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\Shared Files""
  823. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Themes\CachedFiles""
  824. cmd /C "rmdir /s /q "C:\ProgramData\Microsoft\Wlansvc\Profiles\Interfaces""
  825. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\XboxLive""
  826. cmd /C "rmdir /s /q "C:\ProgramData\Microsoft\Windows\DeviceMetadataCache""
  827. cmd /C "rmdir /s /q "C:\Windows\ServiceState\EventLog""
  828. cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal\*.*"
  829. cmd /C "rmdir /s /q "C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.30.20002.0_neutral_split.scale-150_8wekyb3d8bbwe\Assets""
  830. cmd /C "rmdir /s /q "C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.30.20002.0_x64__8wekyb3d8bbwe\AppxMetadata""
  831. cmd /C "rmdir /s /q "C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.30.20002.0_x64__8wekyb3d8bbwe\Source""
  832. cmd /C "rmdir /s /q "C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.30.20002.0_x64__8wekyb3d8bbwe\Spotify""
  833. cmd /C "rmdir /s /q "C:\ProgramData\Microsoft\Windows\ClipSVC""
  834. cmd /C "rmdir /s /q "C:\Program Files\WindowsApps\Deleted""
  835. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC""
  836. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache""cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState""
  837. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync\metastore""
  838. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\LocalLow\Microsoft\CryptnetUrlCache""
  839. cmd /C "rmdir /s /q "C:\Windows\Prefetch""
  840. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings""
  841. cmd /C "rmdir /s /q "C:\Windows\SoftwareDistribution\PostRebootEventCache.V2""
  842. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC""
  843. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\MicrosoftEdge\SharedCacheContainers""
  844. cmd /C "del /s /f /a:h /a:a /q "C:\Users\Public\Libraries\collection.dat\*.*"
  845. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Feeds\*.*"
  846. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Roaming\Microsoft\Windows\Recent""
  847. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\History""
  848. cmd /C "rmdir /s /q "C:\Windows\AppReadiness""
  849. cmd /C "rmdir /s /q "C:\Windows\System32\WDI""
  850. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\FortniteGame""
  851. cmd /C "rmdir /s /q "C:\Windows\SoftwareDistribution\DataStore\Logs""
  852. cmd /C "rmdir /s /q "C:\Windows\INF""
  853. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\INetCache""
  854. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync\remotemetastore""
  855. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\SettingSync""
  856. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Microsoft\Windows\Explorer\ThumbCacheToDelete""
  857. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Comms\UnistoreDB\USS.jtx""
  858. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\config\BBI.LOG2\*.*"
  859. cmd /C "rmdir /s /q "C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive""
  860. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\appcompat\Programs\Amcache.hve\*.*"
  861. cmd /C "rmdir /s /q "C:\Windows\System32\spp\store\2.0\cache""
  862. cmd /C "rmdir /s /q "C:\Windows\TEMP""
  863. cmd /C "del /s /f /a:h /a:a /q "C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe\ActivationStore.dat\*.*"
  864. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\LocalCache""
  865. cmd /C "rmdir /s /q "C:\Windows\System32\winevt\Logs""
  866. cmd /C "rmdir /s /q "C:\Windows\SoftwareDistribution\SLS""
  867. cmd /C "rmdir /s /q "C:\Windows\SoftwareDistribution\DataStore""
  868. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat\*.*"
  869. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\dosvcState.dat.LOG2\*.*"
  870. cmd /C "del /s /f /a:h /a:a /q "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-ClassPnP%%4Operational.evtx\*.*"
  871. cmd /C "rmdir /s /q "C:\Recovery""
  872. cmd /C "rmdir /s /q "C:\MSOCache""
  873. cmd /C "rmdir /s /q "D:\Recovery""
  874. cmd /C "del /s /f /a:h /a:a /q "D:\Users\Public\Libraries\collection.dat\*.*" >nul 2>&1"
  875. cmd /C "rmdir /s /q "D:\MSOCache""
  876. cmd /C "del /f /s /q D:\desktop.ini\*.*""
  877. cmd /C "rmdir /s /q "E:\Recovery""
  878. cmd /C "del /s /f /a:h /a:a /q "E:\Users\Public\Libraries\collection.dat\*.*" >nul 2>&1"
  879. cmd /C "rmdir /s /q "E:\MSOCache""
  880. cmd /C "del /f /s /q E:\desktop.ini\*.*""
  881. cmd /C "rmdir /s /q "F:\Recovery""
  882. cmd /C "del /s /f /a:h /a:a /q "F:\Users\Public\Libraries\collection.dat\*.*" >nul 2>&1"
  883. cmd /C "rmdir /s /q "F:\MSOCache""
  884. cmd /C "del /f /s /q F:\desktop.ini\*.*""
  885. cmd /C "rd /q /s C:\$Recycle.Bin"
  886. cmd /C "rd /q /s d:\$Recycle.Bin"
  887. cmd /C "rd /q /s e:\$Recycle.Bin"
  888. cmd /C "rd /q /s f:\$Recycle.Bin"
  889. cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography" /v MachineGuid /t REG_SZ /d %%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex1%%-%%Hex10%% /f>nul 2>&1"
  890. cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v BuildGUID /t REG_SZ /d %%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex1%%-%%Hex10%% /f>nul 2>&1"
  891. cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}\Configuration\Variables\BusDeviceDesc" /v PropertyGuid /t REG_SZ /d {%%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex1%%-%%Hex10%%} /f>nul 2>&1"
  892. cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\DeviceDesc" /v PropertyGuid /t REG_SZ /d {%%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex1%%-%%Hex10%%} /f>nul 2>&1"
  893. cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\Driver" /v PropertyGuid /t REG_SZ /d {%%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex1%%-%%Hex10%%} /f>nul 2>&1W"
  894. cmd /C "REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation" /v ComputerHardwareId /t REG_SZ /d {%%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex1%%-%%Hex10%%} /f>nul 2>&1"
  895. cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d %%Hex1%%-%%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex10%% /f"
  896. cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d %%Hex1%%-%%Hex8%%-%%Hex1%%-%%Hex0%%-%%Hex10%% /f"
  897. cmd /C "REG ADD HKLM\System\CurrentControlSet\Control\WMI\Security /v 671a8285-4edb-4cae-99fe-69a15c48c0bc /t REG_SZ /d %%random%% /f"
  898. cmd /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion" "WindowsUpdate /v SusClientId /t REG_SZ /d {C-H-E-A-T-L-O-V-E-R-Z-%%random%%%%random%%-%%random%%} /f"
  899. cmd /C "reg delete "HKEY_CLASSES_ROOT\com.epicgames.launcher" /f"
  900. cmd /C "reg delete "HKEY_CURRENT_USER\SOFTWARE\Epic Games" /f"
  901. cmd /C "reg delete "HKEY_CURRENT_USER\SOFTWARE\EpicGames" /f"
  902. cmd /C "reg delete "HKEY_CURRENT_USER\Software\Classes\Installer\Dependencies" /v MSICache /f"
  903. cmd /C "reg delete "HKEY_CURRENT_USER\Software\Classes\com.epicgames.launcher" /f"
  904. cmd /C "reg delete "HKEY_CURRENT_USER\Software\Epic Games" /f"
  905. cmd /C "reg delete "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine" /f"
  906. cmd /C "reg delete "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Hardware Survey" /f"
  907. cmd /C "reg delete "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Identifiers" /f"
  908. cmd /C "reg delete "HKEY_CURRENT_USER\Software\Microsoft\Direct3D" /v WHQLClass /f"
  909. cmd /C "reg delete "HKEY_CURRENT_USER\Software\WOW6432Node\Epic Games" /f"
  910. cmd /C "reg delete "HKEY_LOCAL_MACHINE\Hardware\Description\System\CentralProcessor\0" /v ProcessorNameString /f"
  911. cmd /C "reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\com.epicgames.launcher" /f"
  912. cmd /C "reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Epic Games" /f"
  913. cmd /C "reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\EpicGames" /f"
  914. cmd /C "reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Epic Games" /f"
  915. cmd /C "reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\EpicGames" /f"
  916. cmd /C "reg delete "HKEY_LOCAL_MACHINE\SYSTEM\HardwareConfig" /f"
  917. cmd /C "reg delete "HKEY_LOCAL_MACHINE\Software\Epic Games" /f"
  918. cmd /C "reg delete "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control" /v SystemStartOptions /f"
  919. cmd /C "reg delete "HKEY_USERS\S-1-5-21-2097722829-2509645790-3642206209-1001\Software\Epic Games" /f"
  920. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5e4eddc4_0\: "{2}.\\?\hdaudio#func_01&ven_10ec&dev_0290&subsys_103c80df&rev_1000#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\singlelineouttopo/00010001|\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe%%b{00000000-0000-0000-0000-000000000000}"" /f"
  921. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Program Files\Windows NT\Accessories\WORDPAD.EXE,-190: "Rich Text Document"" /f"
  922. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Windows\system32\zipfldr.dll,-10195: "Compressed (zipped) Folder"" /f"
  923. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Program Files\Common Files\system\wab32res.dll,-10203: "Contact"" /f"
  924. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Windows\System32\ieframe.dll,-5723: "The Internet"" /f"
  925. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Program Files (x86)\Common Files\Microsoft Shared\MSEnv\1033\\VSLauncherUI.dll,-1002: "Open in &Visual Studio"" /f"
  926. cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe" /f"
  927. cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe" /f"
  928. cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe" /f"
  929. cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\Microsoft.XboxGameOverlay_8wekyb3d8bbwe!App" /f"
  930. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\FortniteClient-Win64-Shipping.exe" /f"
  931. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe" /f"
  932. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93" /f"
  933. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\Package\181" /f"
  934. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\Package\181\93" /f"
  935. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\PackageAndPackageRelativeApplicationId\181^App" /f"
  936. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\PackageAndPackageRelativeApplicationId\181^App\93" /f"
  937. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ac" /f"
  938. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ad" /f"
  939. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplication\3^93" /f"
  940. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplication\3^93\ac" /f"
  941. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplication\4^93" /f"
  942. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplication\4^93\ad" /f"
  943. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180" /f"
  944. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181" /f"
  945. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182" /f"
  946. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFamily\4e\180" /f"
  947. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFamily\4e\181" /f"
  948. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFamily\4e\182" /f"
  949. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe" /f"
  950. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe\182" /f"
  951. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe" /f"
  952. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\180" /f"
  953. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe" /f"
  954. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\181" /f"
  955. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a80" /f"
  956. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a81" /f"
  957. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a82" /f"
  958. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a83" /f"
  959. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a84" /f"
  960. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\User\3\1a80" /f"
  961. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\User\3\1a81" /f"
  962. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\User\3\1a82" /f"
  963. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\User\4\1a83" /f"
  964. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\User\4\1a84" /f"
  965. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\3^180" /f"
  966. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\3^180\1a80" /f"
  967. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\3^181" /f"
  968. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\3^181\1a81" /f"
  969. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\3^182" /f"
  970. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\3^182\1a82" /f"
  971. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\4^180" /f"
  972. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\4^180\1a83" /f"
  973. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\4^181" /f"
  974. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Index\UserAndPackage\4^181\1a84" /f"
  975. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe" /f"
  976. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe" /f"
  977. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x86__8wekyb3d8bbwe" /f"
  978. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe" /f"
  979. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe" /f"
  980. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x86__8wekyb3d8bbwe" /f"
  981. cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe" /f"
  982. cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat" /f"
  983. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat" /f"
  984. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\Security" /f"
  985. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat" /f"
  986. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\Security" /f"
  987. cmd /C "reg delete "HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher" /f"
  988. cmd /C "reg delete "HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates" /f"
  989. cmd /C "reg delete "HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs" /f"
  990. cmd /C "reg delete "HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs" /f"
  991. cmd /C "reg delete "HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher" /f"
  992. cmd /C "reg delete "HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates" /f"
  993. cmd /C "reg delete "HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs" /f"
  994. cmd /C "reg delete "HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs" /f"
  995. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5e4eddc4_0" /f"
  996. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5e4eddc4_0\{219ED5A0-9CBF-4F3A-B927-37C9E5C5F14F}" /f"
  997. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\0" /f"
  998. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000205B6" /f"
  999. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000403D6" /f"
  1000. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000405DE" /f"
  1001. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000060286" /f"
  1002. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000009042E" /f"
  1003. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000A03B4" /f"
  1004. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000A0430" /f"
  1005. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000B0532" /f"
  1006. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000B05D6" /f"
  1007. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000C0430" /f"
  1008. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000C0586" /f"
  1009. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000E03D2" /f"
  1010. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000E0406" /f"
  1011. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000100430" /f"
  1012. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001103EE" /f"
  1013. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000011041E" /f"
  1014. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000012047E" /f"
  1015. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001303EE" /f"
  1016. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001304F2" /f"
  1017. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000014041E" /f"
  1018. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001703E6" /f"
  1019. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000170440" /f"
  1020. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001704FC" /f"
  1021. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU" /f"
  1022. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri" /f"
  1023. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499" /f"
  1024. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499\87f345c2" /f"
  1025. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572" /f"
  1026. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572\DefaultIcon" /f"
  1027. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572\shell" /f"
  1028. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572\shell\open" /f"
  1029. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572\shell\open\command" /f"
  1030. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580" /f"
  1031. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Parents\fd13f746e7d2d69760b017363f621255c9b49ac8" /f"
  1032. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri" /f"
  1033. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499" /f"
  1034. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499\87f345c2" /f"
  1035. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572" /f"
  1036. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572\DefaultIcon" /f"
  1037. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572\shell" /f"
  1038. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572\shell\open" /f"cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572\shell\open\command" /f"
  1039. cmd /C "reg delete "HKU\S-1-5-18\Software\Microsoft\SystemCertificates\TrustedPublisher" /f"
  1040. cmd /C "reg delete "HKU\S-1-5-18\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates" /f"
  1041. cmd /C "reg delete "HKU\S-1-5-18\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs" /f"
  1042. cmd /C "reg delete "HKU\S-1-5-18\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs" /f"
  1043. cmd /C "reg delete "HKU\S-1-5-18\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher" /f"
  1044. cmd /C "reg delete "HKU\S-1-5-18\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates" /f"
  1045. cmd /C "reg delete "HKU\S-1-5-18\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs" /f"
  1046. cmd /C "reg delete "HKU\S-1-5-18\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs" /f"
  1047. cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Extensions\ProgIDs\AppXm8fs0gj5h36ynw4kq0x3gqnz6ecr1kvy\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe: (NULL!)" /f"
  1048. cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe"" /f"
  1049. cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe"" /f"
  1050. cmd /C "reg delete "HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe"" /f"
  1051. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\FortniteClient-Win64-Shipping.exe\LastDetectionTime: F9 8F FD B6 8D 13 D5 01" /f"
  1052. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\AppPackageType: 0x00000000" /f"
  1053. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\PackageSid: "S-1-15-2-1823635404-1364722122-2170562666-1762391777-2399050872-3465541734-3732476201"" /f"
  1054. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\EnterpriseID: 0x00000000" /f"
  1055. cmd /C "reg delete " 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1056. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\ApplicationFlags: 0x00000000" /f"
  1057. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\Origins\kz2LMQg4+pNfXggv65DcWFQ9SiekWR4B4WMWT+pcqbU: 0x00000002" /f"
  1058. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\Origins\4JSyFFDDKUMXDyK2USgAjbiksFnqOb3f8RPZBPSpEfU: 0x00000002" /f"
  1059. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\Origins\62bDlCzxB/xxIWLkQdDRYcAqhmZhNOMUtjhRkAgTvkQ: 0x00000002" /f"
  1060. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\Package: 0x00000181" /f"
  1061. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\Index: 0x00000000" /f"
  1062. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\Flags: 0x00000000" /f"
  1063. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\PackageRelativeApplicationId: "App"" /f"
  1064. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\ApplicationUserModelId: "Microsoft.XboxGameOverlay_8wekyb3d8bbwe!App"" /f"
  1065. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\Executable: "GameBar.exe"" /f"
  1066. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\Entrypoint: "GameBar.App"" /f"
  1067. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\StartPage: (NULL!)" /f"
  1068. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\93\_IndexKeys: 50 61 63 6B 61 67 65 5C 31 38 31 5C 39 33 00 50 61 63 6B 61 67 65 41 6E 64 50 61 63 6B 61 67 65 52 65 6C 61 74 69 76 65 41 70 70 6C 69 63 61 74 69 6F 6E 49 64 5C 31 38 31 5E 41 70 70 00 00" /f"
  1069. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ac\Application: 0x00000093" /f"
  1070. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ac\User: 0x00000003" /f"
  1071. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ac\ApplicationUserModelId: "Microsoft.XboxGameOverlay_8wekyb3d8bbwe!App"" /f"
  1072. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ac\_IndexKeys: 55 73 65 72 41 6E 64 41 70 70 6C 69 63 61 74 69 6F 6E 5C 33 5E 39 33 00 55 73 65 72 41 6E 64 41 70 70 6C 69 63 61 74 69 6F 6E 55 73 65 72 4D 6F 64 65 6C 49 64 5C 33 5E 4D 69 63 72 6F 73 6F 66 74 2E 58 62 6F 78 47 61 6D 65 4F 76 65 72 6C 61 79 5F 38 77 65 6B 79 62 33 64 38 62 62 77 65 21 41 70 70 00 00" /f"
  1073. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ad\Application: 0x00000093" /f"
  1074. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ad\User: 0x00000004" /f"
  1075. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ad\ApplicationUserModelId: "Microsoft.XboxGameOverlay_8wekyb3d8bbwe!App"" /f"
  1076. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\ad\_IndexKeys: 55 73 65 72 41 6E 64 41 70 70 6C 69 63 61 74 69 6F 6E 5C 34 5E 39 33 00 55 73 65 72 41 6E 64 41 70 70 6C 69 63 61 74 69 6F 6E 55 73 65 72 4D 6F 64 65 6C 49 64 5C 34 5E 4D 69 63 72 6F 73 6F 66 74 2E 58 62 6F 78 47 61 6D 65 4F 76 65 72 6C 61 79 5F 38 77 65 6B 79 62 33 64 38 62 62 77 65 21 41 70 70 00 00" /f"
  1077. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\PackageFullName: "Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe"" /f"
  1078. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\PackageFamily: 0x0000004E" /f"
  1079. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\PackageType: 0x00000008" /f"
  1080. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\Flags: 0x00000000" /f"
  1081. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\PackageOrigin: 0x00000003" /f"
  1082. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\Volume: 0x00000001" /f"
  1083. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\InstalledLocation: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe"" /f"
  1084. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\180\_IndexKeys: 50 61 63 6B 61 67 65 46 61 6D 69 6C 79 5C 34 65 5C 31 38 30 00 50 61 63 6B 61 67 65 46 75 6C 6C 4E 61 6D 65 5C 4D 69 63 72 6F 73 6F 66 74 2E 58 62 6F 78 47 61 6D 65 4F 76 65 72 6C 61 79 5F 31 2E 34 31 2E 32 34 30 30 31 2E 30 5F 6E 65 75 74 72 61 6C 5F 7E 5F 38 77 65 6B 79 62 33 64 38 62 62 77 65 00 00" /f"
  1085. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\PackageFullName: "Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe"" /f"
  1086. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\PackageFamily: 0x0000004E" /f"
  1087. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\PackageType: 0x00000001" /f"
  1088. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\Flags: 0x00000000" /f"
  1089. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\PackageOrigin: 0x00000003" /f"
  1090. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\Volume: 0x00000001" /f"
  1091. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\InstalledLocation: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe"" /f"
  1092. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\181\_IndexKeys: 50 61 63 6B 61 67 65 46 61 6D 69 6C 79 5C 34 65 5C 31 38 31 00 50 61 63 6B 61 67 65 46 75 6C 6C 4E 61 6D 65 5C 4D 69 63 72 6F 73 6F 66 74 2E 58 62 6F 78 47 61 6D 65 4F 76 65 72 6C 61 79 5F 31 2E 34 31 2E 32 34 30 30 31 2E 30 5F 78 36 34 5F 5F 38 77 65 6B 79 62 33 64 38 62 62 77 65 00 00" /f"
  1093. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\PackageFullName: "Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe"" /f"
  1094. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\PackageFamily: 0x0000004E" /f"
  1095. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\PackageType: 0x00000004" /f"
  1096. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\Flags: 0x00000000" /f"
  1097. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\PackageOrigin: 0x00000003" /f"
  1098. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\Volume: 0x00000001" /f"
  1099. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\InstalledLocation: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_split.scale-100_8wekyb3d8bbwe"" /f"
  1100. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\182\_IndexKeys: 50 61 63 6B 61 67 65 46 61 6D 69 6C 79 5C 34 65 5C 31 38 32 00 50 61 63 6B 61 67 65 46 75 6C 6C 4E 61 6D 65 5C 4D 69 63 72 6F 73 6F 66 74 2E 58 62 6F 78 47 61 6D 65 4F 76 65 72 6C 61 79 5F 31 2E 34 31 2E 32 34 30 30 31 2E 30 5F 6E 65 75 74 72 61 6C 5F 73 70 6C 69 74 2E 73 63 61 6C 65 2D 31 30 30 5F 38 77 65 6B 79 62 33 64 38 62 62 77 65 00 00" /f"
  1101. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a80\Package: 0x00000180" /f"
  1102. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a80\User: 0x00000003" /f"
  1103. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a80\_IndexKeys: 55 73 65 72 5C 33 5C 31 61 38 30 00 55 73 65 72 41 6E 64 50 61 63 6B 61 67 65 5C 33 5E 31 38 30 00 00" /f"
  1104. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a81\Package: 0x00000181" /f"
  1105. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a81\User: 0x00000003" /f"
  1106. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a81\_IndexKeys: 55 73 65 72 5C 33 5C 31 61 38 31 00 55 73 65 72 41 6E 64 50 61 63 6B 61 67 65 5C 33 5E 31 38 31 00 00" /f"
  1107. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a82\Package: 0x00000182" /f"
  1108. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a82\User: 0x00000003" /f"
  1109. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a82\_IndexKeys: 55 73 65 72 5C 33 5C 31 61 38 32 00 55 73 65 72 41 6E 64 50 61 63 6B 61 67 65 5C 33 5E 31 38 32 00 00" /f"
  1110. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a83\Package: 0x00000180" /f"
  1111. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a83\User: 0x00000004" /f"
  1112. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a83\_IndexKeys: 55 73 65 72 5C 34 5C 31 61 38 33 00 55 73 65 72 41 6E 64 50 61 63 6B 61 67 65 5C 34 5E 31 38 30 00 00" /f"
  1113. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a84\Package: 0x00000181" /f"
  1114. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a84\User: 0x00000004" /f"
  1115. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageUser\Data\1a84\_IndexKeys: 55 73 65 72 5C 34 5C 31 61 38 34 00 55 73 65 72 41 6E 64 50 61 63 6B 61 67 65 5C 34 5E 31 38 31 00 00" /f"
  1116. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\AppxMetadata\AppxBundleManifest.xml"" /f"
  1117. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\AppxManifest.xml"" /f"
  1118. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x86__8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.27323.0_x86__8wekyb3d8bbwe\AppxManifest.xml"" /f"
  1119. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\AppxMetadata\AppxBundleManifest.xml"" /f"
  1120. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\LastReturnValue: 0x00000000" /f"
  1121. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\NumberOfAttempts: 0x00000001" /f"
  1122. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\AppxManifest.xml"" /f"
  1123. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-2532382528-581214834-2534474248-1001\Microsoft.XboxGameOverlay_1.41.24001.0_neutral_~_8wekyb3d8bbwe\Microsoft.VCLibs.140.00_14.0.27323.0_x86__8wekyb3d8bbwe\Path: "C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.27323.0_x86__8wekyb3d8bbwe\AppxManifest.xml"" /f"
  1124. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\VolatileNotifications\41C64E6DA3D39855: 01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00 14 00 00 00 02 00 1C 00 01 00 00 00 00 00 14 00 03 00 00 00 01 01 00 00 00 00 00 05 0B 00 00 00 04 00 00 00" /f"
  1125. cmd /C "reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\VolatileNotifications\41C64E6DA3CF4055: 01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00 14 00 00 00 02 00 1C 00 01 00 00 00 00 00 14 00 03 00 00 00 01 01 00 00 00 00 00 05 0B 00 00 00 04 00 00 00" /f"
  1126. cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\Google\Update\UsageStats\Daily\Counts\cup_ecdsa_http_failure: 01 00 00 00 00 00 00 00" /f"
  1127. cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\AppPackageType: 0x00000000" /f"
  1128. cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\PackageSid: "S-1-15-2-1823635404-1364722122-2170562666-1762391777-2399050872-3465541734-3732476201"" /f"
  1129. cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\EnterpriseID: 0x00000000" /f"
  1130. cmd /C "reg delete " 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1131. cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\Microsoft.XboxGameOverlay_1.41.24001.0_x64__8wekyb3d8bbwe\ApplicationFlags: 0x00000000" /f"
  1132. cmd /C "reg delete "HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\GamesInstalled: "217;"" /f"
  1133. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862software: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 43 61 63 68 65 5C 35 63 38 63 62 62 36 61 61 37 65 61 31 34 32 34 2E 64 61 74 00 00" /f"
  1134. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862user_sid: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 55 73 65 72 2E 64 61 74 00 00" /f"
  1135. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862user_classes: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 55 73 65 72 43 6C 61 73 73 65 73 2E 64 61 74 00 00" /f"
  1136. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Control\hivelist\\REGISTRY\WC\Siloe6b4a779-bfe1-62d8-47ac-fa19e9becbbecom: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 43 61 63 68 65 5C 35 63 38 63 62 62 36 61 61 37 65 61 31 34 32 34 5F 43 4F 4D 31 35 2E 64 61 74 00 00" /f"
  1137. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862com: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 43 61 63 68 65 5C 35 63 38 63 62 62 36 61 61 37 65 61 31 34 32 34 2E 64 61 74 00 00" /f"
  1138. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-2532382528-581214834-2534474248-1001\\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping_EAC.exe: B1 8A B0 E9 8D 13 D5 01 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00" /f"
  1139. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-2532382528-581214834-2534474248-1001\\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\EasyAntiCheat\EasyAntiCheat_Setup.exe: 73 D5 4B 11 8D 13 D5 01 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00" /f"
  1140. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-2532382528-581214834-2534474248-1001\\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe: E7 CB 84 E9 8D 13 D5 01 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00" /f"
  1141. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\Type: 0x00000010" /f"
  1142. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\Start: 0x00000003" /f"
  1143. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\ErrorControl: 0x00000001" /f"
  1144. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\ImagePath: ""C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe""" /f"
  1145. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\DisplayName: "EasyAntiCheat"" /f"
  1146. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\WOW64: 0x0000014C" /f"
  1147. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\ObjectName: "LocalSystem"" /f"
  1148. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\Description: "Provides integrated security and services for online multiplayer games."" /f"
  1149. cmd /C "reg delete "HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat\Security\Security: 01 00 14 80 A0 00 00 00 AC 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 70 00 05 00 00 00 00 00 14 00 30 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 04 00 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 06 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00" /f"
  1150. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862software: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 43 61 63 68 65 5C 35 63 38 63 62 62 36 61 61 37 65 61 31 34 32 34 2E 64 61 74 00 00" /f"
  1151. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862user_sid: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 55 73 65 72 2E 64 61 74 00 00" /f"cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862user_classes: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 55 73 65 72 43 6C 61 73 73 65 73 2E 64 61 74 00 00" /f"
  1152. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Control\hivelist\\REGISTRY\WC\Siloe6b4a779-bfe1-62d8-47ac-fa19e9becbbecom: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 43 61 63 68 65 5C 35 63 38 63 62 62 36 61 61 37 65 61 31 34 32 34 5F 43 4F 4D 31 35 2E 64 61 74 00 00" /f"
  1153. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Control\hivelist\\REGISTRY\WC\Silo19faac47-bee9-becb-79a7-b4e6e1bfd862com: 5C 44 65 76 69 63 65 5C 48 61 72 64 64 69 73 6B 56 6F 6C 75 6D 65 33 5C 50 72 6F 67 72 61 6D 44 61 74 61 5C 50 61 63 6B 61 67 65 73 5C 4D 69 63 72 6F 73 6F 66 74 2E 53 6B 79 70 65 41 70 70 5F 6B 7A 66 38 71 78 66 33 38 7A 67 35 63 5C 53 2D 31 2D 35 2D 32 31 2D 32 35 33 32 33 38 32 35 32 38 2D 35 38 31 32 31 34 38 33 34 2D 32 35 33 34 34 37 34 32 34 38 2D 31 30 30 31 5C 53 79 73 74 65 6D 41 70 70 44 61 74 61 5C 48 65 6C 69 75 6D 5C 43 61 63 68 65 5C 35 63 38 63 62 62 36 61 61 37 65 61 31 34 32 34 2E 64 61 74 00 00" /f"
  1154. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-2532382528-581214834-2534474248-1001\\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\
  1155. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-2532382528-581214834-2534474248-1001\\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\EasyAntiCheat\EasyAntiCheat_Setup.exe: 73 D5 4B 11 8D 13 D5 01 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00" /f"
  1156. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-2532382528-581214834-2534474248-1001\\Device\HarddiskVolume3\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe: E7 CB 84 E9 8D 13 D5 01 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00" /f"
  1157. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\Type: 0x00000010" /f"
  1158. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\Start: 0x00000003" /f"
  1159. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\ErrorControl: 0x00000001" /f"
  1160. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\ImagePath: ""C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe""" /f"
  1161. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\DisplayName: "EasyAntiCheat"" /f"
  1162. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\WOW64: 0x0000014C" /f"
  1163. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\ObjectName: "LocalSystem"" /f"
  1164. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\Description: "Provides integrated security and services for online multiplayer games."" /f"
  1165. cmd /C "reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EasyAntiCheat\Security\Security: 01 00 14 80 A0 00 00 00 AC 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 70 00 05 00 00 00 00 00 14 00 30 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 04 00 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 06 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00" /f"
  1166. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5e4eddc4_0\{219ED5A0-9CBF-4F3A-B927-37C9E5C5F14F}\3: 04 00 00 00 00 00 00 00 00 00 80 3F 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1167. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5e4eddc4_0\{219ED5A0-9CBF-4F3A-B927-37C9E5C5F14F}\4: 04 20 00 00 00 00 00 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 3F 00 00 80 3F" /f"
  1168. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5e4eddc4_0\{219ED5A0-9CBF-4F3A-B927-37C9E5C5F14F}\5: 0B 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1169. cmd /C "reg delete "70 00 74 00 69 00 70 00 73 00 2D 00 54 00 69 00 74 00 6C 00 65 00 49 00 64 00 3D 00 31 00 38 00 32 00 30 00 32 00 35 00 30 00 37 00 38 00 38 00 26 00 50 00 72 00 6F 00 63 00 65 00 73 00 73 00 49 00 64 00 3D 00 36 00 31 00 39 00 36 00 26 00 57 00 69 00 6E 00 64 00 6F 00 77 00 49 00 64 00 3D 00 32 00 36 00 33 00 31 00 32 00 36 00 2E 00 6C 00 6E 00 6B 00 00 00 62 00 00 00" /f"
  1170. cmd /C "reg delete " 9E EB AC 0C 00 00 00 50 00 00 00 A6 6A 63 28 3D 95 D2 11 B5 D6 00 C0 4F D9 18 D0 0B 00 00 00 78 00 00 00 30 F1 25 B7 EF 47 1A 10 A5 F1 02 60 8C 9E EB AC 0E 00 00 00 78 00 00 00 2F 00 00 00 1E 00 00 00 00 47 00 72 00 6F 00 75 00 70 00 42 00 79 00 4B 00 65 00 79 00 3A 00 50 00 49 00 44 00 00 00 13 00 00 00 00 00 00 00 1F 00 00 00 0E 00 00 00 00 46 00 46 00 6C 00 61 00 67 00 73 00 00 00 13 00 00 00 11 00 20 01 31 00 00 00 20 00 00 00 00 4C 00 6F 00 67 00 69 00 63 00 61 00 6C 00 56 00 69 00 65 00 77 00 4D 00 6F 00 64 00 65 00 00 00 13 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00" /f"
  1171. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Rcvp Tnzrf\Sbegavgr\SbegavgrTnzr\Ovanevrf\Jva64\SbegavgrPyvrag-Jva64-Fuvccvat_RNP.rkr: 01 00 00 00 00 00 00 00 02 00 00 00 FB 2C 00 00 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF FF FF FF FF 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1172. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Rcvp Tnzrf\Sbegavgr\SbegavgrTnzr\Ovanevrf\Jva64\RnflNagvPurng\RnflNagvPurng_Frghc.rkr: 01 00 00 00 00 00 00 00 01 00 00 00 35 0C 00 00 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF FF FF FF FF 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1173. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Rcvp Tnzrf\Sbegavgr\SbegavgrTnzr\Ovanevrf\Jva64\SbegavgrPyvrag-Jva64-Fuvccvat.rkr: 01 00 00 00 00 00 00 00 04 00 00 00 AF B4 02 00 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF 00 00 80 BF FF FF FF FF 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1174. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000020552\CloakType: 04 00 00 00 30 30 54 43 00 00 00 00" /f"
  1175. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000703C4\CloakType: 04 00 00 00 30 30 54 43 00 00 00 00" /f"
  1176. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000205B6\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1177. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000403D6\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1178. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000405DE\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1179. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000060286\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1180. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000009042E\VirtualDesktop: 10 00 00 00 30 30 44 56 8A 14 1B 02 6F DF F6 46 96 A2 BA 8C 49 3E 6C EE" /f"
  1181. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000009042E\CloakType: 04 00 00 00 30 30 54 43 02 00 00 00" /f"
  1182. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000A03B4\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1183. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000A0430\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1184. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000B0532\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1185. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000B05D6\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1186. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000C0430\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1187. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000C0586\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1188. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000E03D2\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1189. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000E0406\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1190. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000100430\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1191. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000100430\CloakType: 04 00 00 00 30 30 54 43 02 00 00 00" /f"
  1192. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001103EE\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1193. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000011041E\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1194. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000012047E\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1195. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001303EE\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1196. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001304F2\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1197. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000014041E\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1198. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001703E6\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1199. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000170440\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1200. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001704FC\VirtualDesktop: 10 00 00 00 30 30 44 56 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00" /f"
  1201. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\VirtualDesktops\CurrentVirtualDesktop: B5 05 CB 90 C0 9D AF 44 93 6E 8E 33 22 0E 1E 9A" /f"
  1202. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU\MRUListEx: 00 00 00 00 FF FF FF FF" /f"
  1203. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU\0: 14 00 1F 78 40 F0 5F 64 81 50 1B 10 9F 08 00 AA 00 2F 95 4E 00 00" /f"
  1204. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows\CurrentVersion\Search\JumplistData\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe!App: 6F 70 0D 53 8D 13 D5 01" /f"
  1205. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.44.40.1000_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe: 53 41 43 50 01 00 00 00 00 00 00 00 07 00 00 00 28 00 00 00 00 EA 08 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 0A 73 20 00 00 67 07 7C BA C5 4C D4 01 00 00 00 00 00 00 00 00" /f"
  1206. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\EasyAntiCheat\EasyAntiCheat_Setup.exe: 53 41 43 50 01 00 00 00 00 00 00 00 07 00 00 00 28 00 00 00 70 42 0C 00 0E EB 0C 00 01 00 00 00 00 00 00 00 00 00 03 06 00 01 00 00 67 07 7C BA C5 4C D4 01 00 00 00 00 00 00 00 00 02 00 00 00 28 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 83 0C 00 00 00 00 00 00 01 00 00 00 01 00 00 00" /f"
  1207. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499\87f345c2\LanguageList: 5F 65 6E 2D 55 53 5F 73 74 61 6E 64 61 72 64 5F 31 32 35 5F 55 53 5F 4C 54 52 5F 6C 69 67 68 74 5F 44 65 73 6B 74 6F 70" /f"
  1208. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499\87f345c2\{Microsoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.XboxGamingOverlay/resources/GameBar}: "Game bar"" /f"cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Program Files\Common Files\System\wab32res.dll,-4602: "Contact file"" /f"
  1209. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Program Files (x86)\Common Files\Microsoft Shared\MSEnv\1033\\VSLauncherUI.dll,-1002: "Open in &Visual Studio"" /f"
  1210. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\Local Settings\MuiCache\ab\52C64B7E\windows.storage.dll,-21826: "Captures"" /f"
  1211. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572\DefaultIcon\: "C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe"" /f"
  1212. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\Software\Classes\discord-432980957394370572\shell\open\command\: "C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe"" /f"cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\Type: 0x00000001" /f"
  1213. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\Revision: 0x00000749" /f"
  1214. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\Flags: 0x00000011" /f"
  1215. cmd /C "reg delete " C9 73 F7" /f"
  1216. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\GameDVR_GameGUID: "284ea1b3-f5e7-4133-b521-74a8d9ae997e"" /f"
  1217. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\TitleId: "1820250788"" /f"
  1218. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\MatchedExeFullPath: 43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73 5C 45 70 69 63 20 47 61 6D 65 73 5C 46 6F 72 74 6E 69 74 65 5C 46 6F 72 74 6E 69 74 65 47 61 6D 65 5C 42 69 6E 61 72 69 65 73 5C 57 69 6E 36 34 5C 46 6F 72 74 6E 69 74 65 43 6C 69 65 6E 74 2D 57 69 6E 36 34 2D 53 68 69 70 70 69 6E 67 2E 65 78 65" /f"
  1219. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Children\03ce6902-ff58-41de-ab92-36fcaf27a580\LastAccessed: 50 3B 6E 52 8D 13 D5 01" /f"
  1220. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001\System\GameConfigStore\Parents\fd13f746e7d2d69760b017363f621255c9b49ac8\Children: "03ce6902-ff58-41de-ab92-36fcaf27a580"" /f"
  1221. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499\87f345c2\LanguageList: 5F 65 6E 2D 55 53 5F 73 74 61 6E 64 61 72 64 5F 31 32 35 5F 55 53 5F 4C 54 52 5F 6C 69 67 68 74 5F 44 65 73 6B 74 6F 70" /f"
  1222. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MrtCache\C:%%5CProgram Files%%5CWindowsApps%%5CMicrosoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe%%5Cmicrosoft.system.package.metadata%%5CS-1-5-21-2532382528-581214834-2534474248-1001-MergedResources-2.pri\1d50f44cf1a0499\87f345c2\{Microsoft.XboxGamingOverlay_2.26.28001.0_x64__8wekyb3d8bbwe?ms-resource://Microsoft.XboxGamingOverlay/resources/GameBar}: "Game bar"" /f"
  1223. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MuiCache\ab\52C64B7E\C:\Program Files\Common Files\System\wab32res.dll,-4602: "Contact file"" /f"
  1224. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\Local Settings\MuiCache\ab\52C64B7E\windows.storage.dll,-21826: "Captures"" /f"
  1225. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572\DefaultIcon\: "C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe"" /f"
  1226. cmd /C "reg delete "HKU\S-1-5-21-2532382528-581214834-2534474248-1001_Classes\discord-432980957394370572\shell\open\command\: "C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe"" /f"
  1227. cmd /C "rmdir /s /q "C:\Users\%%username%%\AppData\Local\Temp""
  1228. cmd /C "del /f /s /q "C:\Users\%%username%%\AppData\Local\Temp\*.*"
  1229. cmd /C "del /s /f /a:h /a:a /q "C:\Users\%%username%%\AppData\Local\Temp\*.*" >nul 2>&1"
  1230. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName /v ComputerName /t REG_SZ /d r%random% /f >nul 2>&1
  1231. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName /v ComputerName /t REG_SZ /d r%random% /f >nul 2>&1
  1232. REG ADD HKLM\SYSTEM\HardwareConfig /v LastConfig /t REG_SZ /d {be%random%} /f >nul 2>&1
  1233. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v HwProfileGuid /t REG_SZ /d {fefefee%random%-%random%-%random%-%random%} /f >nul 2>&1
  1234. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v GUID /t REG_SZ /d {fefefe%random%-%random%-%random%-%random%} /f >nul 2>&1
  1235. REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d r%random% /f >nul 2>&1
  1236. REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOwner /t REG_SZ /d r%random% /f >nul 2>&1
  1237. REG ADD HKL\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOrganization /t REG_SZ /d r%random% /f >nul 2>&1
  1238. REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d r%random%-%random%-%random%-%random% /f >nul 2>&1
  1239. REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d hello%random%-%random%-%random%-%random% /f >nul 2>&1
  1240. REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v ProductId /t REG_SZ /d %random%-%random%-%random%-%random% /f >nul 2>&1
  1241. REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_SZ /d %random% /f >nul 2>&1
  1242. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {randomd%random%-%random%-%random%-%random%} /f >nul 2>&1
  1243. REG ADD HKLM\SYSTEM\HardwareConfig /v LastConfig /t REG_SZ /d {BE%random%} /f >nul 2>&1
  1244. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v HwProfileGuid /t REG_SZ /d {%random%-%random%-%random%-%random%} /f >nul 2>&1
  1245. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v GUID /t REG_SZ /d {%random%-%random%-%random%-%random%} /f >nul 2>&1
  1246. REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d %random% /f >nul 2>&1
  1247. REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOwner /t REG_SZ /d %random% /f >nul 2>&1
  1248. REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOrganization /t REG_SZ /d %random% /f >nul 2>&1
  1249. REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d %random%-%random%-%random%-%random% /f >nul 2>&1
  1250. REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d %random%-%random%-%random%-%random% /f >nul 2>&1
  1251. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {%random%-%random%-%random%-%random%} /f >nul 2>&1
  1252. reg delete "HKEY_CURRENT_USER\Software\Epic Games" /f >nul 2>&1
  1253. reg delete "HKEY_CURRENT_USER\Software\WOW6432Node\Epic Games" /f >nul 2>&1
  1254. reg delete "HKEY_CURRENT_USER\Software\Classes\com.epicgames.launcher" /f >nul 2>&1
  1255. reg delete "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Identifiers" /f >nul 2>&1
  1256. reg delete "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Hardware Survey" /f >nul 2>&1
  1257. reg delete "HKEY_CLASSES_ROOT\com.epicgames.launcher" /f >nul 2>&1
  1258. del /s /f /a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\UnrealEngine\*.*" >nul 2>&1
  1259. del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Logs\*.*" >nul 2>&1
  1260. del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\*.*" >nul 2>&1
  1261. del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\*.*" >nul 2>&1
  1262. del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Config\WindowsClient\*.*" >nul 2>&1
  1263. del / s / f / a:h / a:a / q "%systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\*.*" >nul 2>&1
  1264. del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\LMS\*.*" >nul 2>&1
  1265. del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Cloud\*.*" >nul 2>&1
  1266. del / s / f / a:h / a:a / q "%systemdrive%\Recovery\ntuser.sys\*.*" >nul 2>&1
  1267. del / s / f / a:h / a:a / q "%systemdrive%\Users\Public\Libraries\collection.dat\*.*" >nul 2>&1
  1268. del / s / f / a:h / a:a / q "%systemdrive%\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat\*.*" >nul 2>&1
  1269. del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*" >nul 2>&1
  1270. del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Feeds\*.*" >nul 2>&1
  1271. del / s / f / a:h / a:a / q "%systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache\*.*" >nul 2>&1
  1272. del / s / f / a:h / a:a / q "%systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\Rules\*.*" >nul 2>&1
  1273. del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\History\History.IE5\*.*" >nul 2>&1
  1274. del / s / f / a:h / a:a / q "%systemdrive%\Users\%username%\AppData\Local\Speech Graphics\Carnival\*.*" >nul 2>&1
  1275. del / s / f / a:h / a:a / q "%systemdrive%\ProgramData\Microsoft\Windows\WER\Temp\*.*" >nul 2>&1
  1276. del / s / f / a:h / a:a / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5\*.*" >nul 2>&1
  1277. del / s / f / a:h / a:a / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies\*.*" >nul 2>&1
  1278. del / s / f / a:h / a:a / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\*.*" >nul 2>&1
  1279. del / s / f / a:h / a:a / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\*.*" >nul 2>&1
  1280. del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\UnrealEngine\*.* >nul 2>&1
  1281. del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Logs\*.* >nul 2>&1
  1282. del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\*.* >nul 2>&1
  1283. del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\*.* >nul 2>&1
  1284. del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Config\WindowsClient\*.* >nul 2>&1
  1285. del / f / s / q "%systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\*.* >nul 2>&1
  1286. del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\LMS\*.* >nul 2>&1
  1287. del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Cloud\*.* >nul 2>&1
  1288. del / f / s / q "%systemdrive%\Recovery\ntuser.sys\*.* >nul 2>&1
  1289. del / f / s / q "%systemdrive%\Users\Public\Libraries\collection.dat\*.* >nul 2>&1
  1290. del / f / s / q "%systemdrive%\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat\*.* >nul 2>&1
  1291. del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.* >nul 2>&1
  1292. del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Feeds\*.*" >nul 2>&1
  1293. del / f / s / q "%systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache\*.*>nul 2>&1
  1294. del / f / s / q "%systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\Rules\*.* >nul 2>&1
  1295. del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\History\History.IE5\*.* >nul 2>&1
  1296. del / f / s / q "%systemdrive%\Users\%username%\AppData\Local\Speech Graphics\Carnival\*.* >nul 2>&1
  1297. del / f / s / q "%systemdrive%\ProgramData\Microsoft\Windows\WER\Temp\*.* >nul 2>&1
  1298. del / f / s / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5\*.* >nul 2>&1
  1299. del / f / s / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies\*.* >nul 2>&1
  1300. del / f / s / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\*.* >nul 2>&1
  1301. del / f / s / q "%systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\*.* >nul 2>&1
  1302. del / s / f / q % systemdrive %\Windows\Public\Libraries\*.* > nul 2 > &1
  1303. del / s / f / q % systemdrive %\Windows\Prefetch\*.* > nul 2 > &1
  1304. del / f / s / q % systemdrive %\Intel\*.*" >nul 2>&1
  1305. rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\UnrealEngine" >nul 2>&1
  1306. rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\EpicGamesLauncher\Saved\Logs" >nul 2>&1
  1307. rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage" >nul 2>&1
  1308. rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache" >nul 2>&1
  1309. rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\FortniteGame\Saved\Config\WindowsClient" >nul 2>&1
  1310. rmdir / s / q % systemdrive %\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir" >nul 2>&1
  1311. rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\FortniteGame\Saved\LMS" >nul 2>&1
  1312. rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\FortniteGame\Saved\Cloud" >nul 2>&1
  1313. rmdir / s / q % systemdrive %\Recovery\ntuser.sys" >nul 2>&1
  1314. rmdir / s / q % systemdrive %\Users\Public\Libraries\collection.dat" >nul 2>&1
  1315. rmdir / s / q % systemdrive %\Users\% username %\AppData\Local\Microsoft\Windows\WebCache" >nul 2>&1
  1316. rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Feeds" >nul 2>&1
  1317. rmdir /s /q %systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache" >nul 2>&1
  1318. rmdir /s /q %systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\Rules" >nul 2>&1
  1319. rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\History\History.IE5" >nul 2>&1
  1320. rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Speech Graphics\Carnival" >nul 2>&1
  1321. rmdir /s /q %systemdrive%\ProgramData\Microsoft\Windows\WER\Temp" >nul 2>&1
  1322. rmdir /s /q %systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5" >nul 2>&1
  1323. rmdir /s /q %systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies" >nul 2>&1
  1324. rmdir /s /q %systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData" >nul 2>&1
  1325. rmdir /s /q %systemdrive%\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content" >nul 2>&1
  1326. rmdir /s /q %systemdrive%\Windows\Public\Libraries" >nul 2>&1
  1327. rmdir /s /q %systemdrive%\Windows\Prefetch" >nul 2>&1
  1328. rmdir /s /q %systemdrive%\Intel" >nul 2>&1
  1329. del /f /s /q %systemdrive%\*.tmp
  1330. del /f /s /q %systemdrive%\*._mp
  1331. del /f /s /q %systemdrive%\*.gid
  1332. del /f /s /q %systemdrive%\*.chk
  1333. del /f /s /q %systemdrive%\*.old
  1334. del /f /s /q %windir%\*.bak
  1335. C:\Windows\System32\eac_usermode_21537346703536.dll
  1336. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive
  1337. C:\Windows\appcompact\Programs\Amcache.hve
  1338. C:\Windows\System32\LogFiles\WMI\EtwRTGraphicsPerfMonitorSession.etl
  1339. C:\Windows\System\config\BBI.LOG2
  1340. \AppData\Local\UnrealEngine
  1341. \AppData\Local\UnrealEngineLauncher
  1342. \AppData\Local\EpicGamesLauncher
  1343. \AppData\Local\FortniteGame
  1344. \AppData\Local\NVIDIA Corporation
  1345. \AppData\Local\Speech Graphics
  1346. \AppData\Local\Packages
  1347. \AppData\Local\AMD\DxCache
  1348. \AppData\Local\Microsoft\Windows\WebCache\V01.chk
  1349. \AppData\Local\Microsoft\Windows\INetCache
  1350. \AppData\Roaming\Microsoft\Windows\Recent
  1351. \AppData\Local\Microsoft\Windows\Notifications
  1352. \AppData\Local\Microsoft\Windows\ActionCenterCache
  1353. \AppData\Roaming\EasyAntiCheat
  1354. \AppData\Roaming\Microsoft\Windows\CloudStore
  1355. \AppData\Local\Microsoft\Feeds
  1356. C:\Program Files\Epic Games\Fortnite.lysEB
  1357. C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir
  1358. C:\Program Files\Epic Games\Fortnite\EAAC0DED42EADD813C76C2B26C315591
  1359. C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe.local
  1360. C:\ProgramData\Epic\EpicGamesLauncher\Data\EMS\current
  1361. C:\ProgramData\Epic\UnrealEngineLauncher\LauncherInstalled.dat
  1362. \AppData\Local\FortniteGame\Saved\LMS\Manifest.sav
  1363. \AppData\Local\Local\Temp\1CF4.tmp
  1364. \AppData\Local\Local\Temp\1CF4.tmp\1CF5.bat
  1365. C:Windows\System32\spp\store\2.0\data.dat
  1366. \AppData\Local\Microsoft\Windows\INetCache\
  1367. C:\Users\Public
  1368. \AppData\Local\Microsoft\OneDrive\settings\Personal\logUploaderSettings_temp.ini
  1369. \AppData\Local\Microsoft\OneDrive\settings\Personal\logUploaderSettings.ini
  1370. C:\desktop.ini
  1371. C:\ProgramData\Microsoft\Diagnosis\parse.dat
  1372. \ntuser.dat.LOG2
  1373. \ntuser.dat.LOG1
  1374. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat.LOG2
  1375. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\qwavecache.dat
  1376. C:\Windows\System32\wbem\Performance\WmiApRpl.ini
  1377. C:\Windows\System32\PerfStringBackup.TMP
  1378. C:\Windows\System32\PerfStringBackup.INI
  1379. C:\Windows\System32\wbem\Repository\OBJECTS.DATA
  1380. C:\Windows\System32\wbem\Repository\INDEX.BTR
  1381. C:\Windows\System32\wbem\Repository\MAPPING2.MAP
  1382. C:\Windows\Prefetch
  1383. C:\Windows\temp\MpCmdRun.log
  1384. C:\Windows\System32\sru
  1385. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC
  1386. \AppData\Local\Microsoft\Windows\History\History.IE5
  1387. C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache
  1388. C:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache
  1389. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache
  1390. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies
  1391. \AppData\Local\Microsoft\Windows\SettingSync\remotemetastore
  1392. \AppData\Local\Microsoft\Windows\SettingSync\metastore
  1393. C:\Windows\INF
  1394. C:\Windows\Logs\CBS
  1395. C:\Windows\Logs
  1396. C:\Windows\SoftwareDistribution\DataStore\Logs
  1397. D:\Windows\System32\eac_usermode_21537346703536.dll
  1398. D:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive
  1399. D:\Windows\appcompact\Programs\Amcache.hve
  1400. D:\Windows\System32\LogFiles\WMI\EtwRTGraphicsPerfMonitorSession.etl
  1401. D:\Windows\System\config\BBI.LOG2
  1402. D:\Program Files\Epic Games\Fortnite.lysEB
  1403. D:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir
  1404. D:\Program Files\Epic Games\Fortnite\EAAC0DED42EADD813C76C2B26C315591
  1405. D:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe.local
  1406. D:\ProgramData\Epic\EpicGamesLauncher\Data\EMS\current
  1407. D:\ProgramData\Epic\UnrealEngineLauncher\LauncherInstalled.dat
  1408. \AppData\Local\Origin
  1409. D:\Users\Public
  1410. \AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF244a582.TMP
  1411. D:\Windows\temp\w1053
  1412. D:\Windows\temp\MpCmdRun.log
  1413. D:\Windows\Prefetch
  1414. E:\Windows\System32\eac_usermode_21537346703536.dll
  1415. E:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive
  1416. E:\Windows\appcompact\Programs\Amcache.hve
  1417. E:\Windows\System32\LogFiles\WMI\EtwRTGraphicsPerfMonitorSession.etl
  1418. E:\Windows\System\config\BBI.LOG2
  1419. E:\Program Files\Epic Games\Fortnite.lysEB
  1420. E:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir
  1421. E:\Program Files\Epic Games\Fortnite\EAAC0DED42EADD813C76C2B26C315591
  1422. E:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe.local
  1423. E:\ProgramData\Epic\EpicGamesLauncher\Data\EMS\current
  1424. E:\ProgramData\Epic\UnrealEngineLauncher\LauncherInstalled.dat
  1425. \AppData\Local\Google\Chrome\User Data\Default\Network Persistent State~RF245551b.TMP
  1426. \AppData\Local\Google\Chrome\User Data\Default\Cache\f_00902d
  1427. \AppData\Local\Google\Chrome\User Data\Default\Cache\f_00902c
  1428. \AppData\Local\Google\Chrome\User Data\Default\Cache\f_00902a
  1429. \AppData\Local\Google\Chrome\User Data\Default\Cache\f_00902b
  1430. \AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF24436e9.TMP
  1431. \AppData\Local\Google\Chrome\User Data\Default\Network Persistent State~RF24465f8.TMP
  1432. \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009023
  1433. \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009022
  1434. \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009024
  1435. \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009025
  1436. \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009026
  1437. \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009027
  1438. \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009028
  1439. \AppData\Local\Google\Chrome\User Data\Default\Cache\f_009029
  1440. E:\Users\Public
  1441. E:\Windows\temp\w1053
  1442. E:\Windows\temp\MpCmdRun.log
  1443. E:\Windows\Prefetch
  1444. F:\Windows\System32\eac_usermode_21537346703536.dll
  1445. F:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive
  1446. F:\Windows\appcompact\Programs\Amcache.hve
  1447. F:\Windows\System32\LogFiles\WMI\EtwRTGraphicsPerfMonitorSession.etl
  1448. F:\Windows\System\config\BBI.LOG2
  1449. F:\Program Files\Epic Games\Fortnite.lysEB
  1450. F:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir
  1451. F:\Program Files\Epic Games\Fortnite\EAAC0DED42EADD813C76C2B26C315591
  1452. F:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe.local
  1453. F:\ProgramData\Epic\EpicGamesLauncher\Data\EMS\current
  1454. F:\ProgramData\Epic\UnrealEngineLauncher\LauncherInstalled.dat
  1455. F:\Users\Public
  1456. F:\Windows\temp\w1053
  1457. F:\Windows\temp\MpCmdRun.log
  1458. F:\Windows\Prefetch
  1459. D:\Windows\System32\sru
  1460. E:\Windows\System32\sru
  1461. F:\Windows\System32\sru
  1462. C\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache
  1463. C\ProgramData\Microsoft\DataMart\PaidWiFi\Rules
  1464. C\Windows\System32\sru
  1465. C\Users\Public\desktop.ini
  1466. C\Windows\Logs\WindowsUpdate
  1467. C\Windows\WindowsUpdate.log
  1468. C\Windows\SoftwareDistribution\DataStore
  1469. C\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache
  1470. \AppData\Local\Microsoft\Windows\WebCache
  1471. \AppData\Local\Speech Graphics\Carnival
  1472. C\ProgramData\USOPrivate\UpdateStore
  1473. C\ProgramData\USOShared\Logs
  1474. C\Windows\System32\config\DEFAULT.LOG1
  1475. C\Windows\System32\config\BBI.LOG2
  1476. C\Windows\System32\SleepStudy
  1477. C\Windows\System32\LogFiles\WMI\RtBackup
  1478. C\Windows\System32\spp\store\2.0\cache\cache.dat
  1479. C\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
  1480. C\Windows\System32\wbem\Repository\OBJECTS.DATA
  1481. C\Windows\System32\wbem\Repository\INDEX.BTR
  1482. C\Windows\System32\wbem\Repository\MAPPING3.MAP
  1483. C\Windows\System32\winevt\Logs
  1484. C\Windows\System32\LogFiles\WMI\Wifi.etl
  1485. C\Windows\INF\netrasa.PNF
  1486. C\Recovery\ntuser.sys
  1487. C\MSOCache{71230000-00E2-0000-1000-00000000}\Setup.dat
  1488. C\Users\Public\Libraries\collection.dat
  1489. C\Windows\1234.exe
  1490. C:\Windows\System32\spp\store\2.0\cache\cache.dat
  1491. \AppData\LocalLow\AMD
  1492. C:\Shared Files
  1493. C:\Recovery\ntuser.sys
  1494. \AppData\Local\Temp
  1495. C:\Windows\appcompat\Programs\Amcache.hve
  1496. C:\$RECYCLE.BIN
  1497. D:\Recovery\ntuser.sys
  1498. D:\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat
  1499. D:\desktop.ini:CachedTiles
  1500. \AppData\Local\CEF
  1501. \AppData\Local\Comms
  1502. \AppData\Local\ConnectedDevicesPlatform
  1503. \AppData\Local\BattlEye
  1504. \AppData\Local\CrashDumps
  1505. \AppData\Local\CrashReportClient
  1506. \AppData\Local\D3DSCache
  1507. \AppData\Local\DBG
  1508. \AppData\Local\Programs\Common
  1509. \AppData\Local\PlaceholderTileLogoFolder
  1510. \AppData\Local\VirtualStore
  1511. C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\CMS
  1512. C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\DMS
  1513. C:\Program Files\rempl\Logs
  1514. C:\ProgramData\Microsoft\Diagnosis
  1515. C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings
  1516. C:\ProgramData\Microsoft\Windows\AppRepository
  1517. C:\ProgramData\Microsoft\Windows\WER\Temp
  1518. C:\ProgramData\USOShared\Logs
  1519. C:\ProgramData\USOPrivate\UpdateStore
  1520. C:\System Volume Information
  1521. \AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2
  1522. \AppData\Local\NVIDIA Corporation\GfeSDK
  1523. \AppData\Roaming\Microsoft\Windows\Themes\CachedFiles
  1524. \AppData\Roaming\Microsoft\Windows\Themes\slideshow.ini
  1525. C:\Users\Public\Libraries
  1526. C:\Users\Public\desktop.ini
  1527. C:\Windows\DeliveryOptimization
  1528. C:\Windows\Logs\WindowsUpdate
  1529. C:\Windows\ServiceProfiles\LocalService\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content
  1530. C:\Windows\ServiceProfiles\LocalService\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
  1531. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp
  1532. C:\Windows\System32\LogFiles\WMI\RtBackup
  1533. C:\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
  1534. C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting
  1535. C:\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start
  1536. C:\Windows\System32\winevt\Logs
  1537. C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\LMS\Manifest.sav
  1538. C:\Windows\System32\drivers\storage.cache
  1539. \AppData\Local\Publishers
  1540. \AppData\Local\NVIDIA Corporation\GfeSDK\FortniteClient-Win64-Shipping_8060.log
  1541. C:\Windows\SoftwareDistribution\ReportingEvents.log
  1542. C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTGraphic
  1543. PerfMonitorSession.etl
  1544. \AppData\Local\Microsoft\Windows\INetCache\IE
  1545. C:\Windows\INF\netrasa.PNF
  1546. C:\MSOCache{71230000-00E2-0000-1000-00000000}\Setup.dat
  1547. C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache
  1548. C:\ProgramData\Microsoft\DataMart\PaidWiFi
  1549. C:\Windows\System32\SleepStudy
  1550. C:\Windows\System32\wbem\Repository\MAPPING3.MAP
  1551. C:\Windows\System32\perfc009.dat
  1552. C:\Windows\System32\perfh009.dat
  1553. \AppData\Local\Microsoft\OneDrive\settings
  1554. C:\Windows\SoftwareDistribution\DataStore
  1555. C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys
  1556. \AppData\Local\EpicGamesLauncher\Intermediate\Config\CoalescedSourceConfigs\Engine.ini
  1557. C:\PerfLogs\collections.dat
  1558. \AppData\Local\FortniteGame\Saved\Config\CrashReportClient
  1559. \AppData\Local\IconCache.db
  1560. \AppData\Local\updater.log
  1561. \AppData\Local\Microsoft\Windows\AppCache
  1562. \AppData\Local\Microsoft\Windows\INetCache\IE\container.dat
  1563. C:\ProgramData\Microsoft\Windows\WER\ReportArchive
  1564. C:\ProgramData\Origin\Logs
  1565. C:\Windows\System32\config\DEFAULT.LOG1
  1566. C:\Windows\System32\config\SYSTEM.LOG2
  1567. C:\Windows\WinSxS\ManifestCache
  1568. C:\Windows\appcompat\Programs\Amcache.hve.LOG2
  1569. C:\Windows\appcompat\appraiser\AltData
  1570. \AppData\Local\Microsoft\Feeds Cache
  1571. C:\desktop.ini:CachedTiles
  1572. \AppData\Local\Local Settings\Temporary Internet Files
  1573. C:\Program Files (x86)\TeamViewer\Connections_incoming.txt
  1574. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy
  1575. \AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe
  1576. C:\Windows\1234.exe
  1577. C:\Windows\System32\LogFiles\WMI\Wifi.etl
  1578. C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{1c3790dc-b8ad-11e8-aa21-e41d2d101530}.TxR.2.regtrans-ms
  1579. C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{1c3790dc-b8ad-11e8-aa21-e41d2d101530}.TxR.blf
  1580. C:\Windows\System32\config\BBI.LOG2
  1581. C:\Windows\System32\config\COMPONENTS{1c379064-b8ad-11e8-aa21-e41d2d101530}.TMContainer00000000000000000001.regtrans-ms
  1582. C:\Windows\System32\config\COMPONENTS{1c379064-b8ad-11e8-aa21-e41d2d101530}.TMContainer00000000000000000002.regtrans-ms
  1583. C:\Windows\System32\drivers\etc\protocol
  1584. \AppData\Local\FortniteGame\Saved\Config
  1585. C:\Windows\INF\WmiApRpl
  1586. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\INetCache
  1587. \AppData\Roaming\Logs
  1588. C:\ProgramData\NVIDIA Corporation\NV_Cache\92e0b06784280dec34f87311d172295b_fce8395c8fd8a98b_be4cb461d6f8ddbc_0_6__1.bin
  1589. \AppData\Local\FortniteGame\Saved\Demos
  1590. \AppData\Local\Microsoft\VSApplicationInsights
  1591. C:\Windows\System32\config\DEFAULT.LOG2
  1592. C:\Windows\System32\config\SYSTEM.LOG1
  1593. C:\ProgramData\Microsoft\Diagnosis\EventStore.db-wal
  1594. C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.A-MSTelDefault.json.new
  1595. C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.A-MSTelDefault.json
  1596. C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.SIUF.xml
  1597. C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.SIUF.xml.new
  1598. C:\Windows\System32\config\BBI.LOG1
  1599. \AppData\Local\NVIDIA Corporation\GfeSDK\FortniteClient-Win64-Shipping_5880.log
  1600. \AppData\Local\EpicGamesLauncher\Saved\Logs
  1601. \AppData\Local\EpicGamesLauncher\Saved\webcache
  1602. C:\ProgramData\NVIDIA Corporation\Drs
  1603. \AppData\Local\EpicGamesLauncher\Saved\Config\Windows\GameUserSettings.ini
  1604. C:\ProgramData\NVIDIA
  1605. C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1
  1606. C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2
  1607. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp
  1608. C:\Windows\ServiceProfiles\LocalService\AppData\LocalLow\Microsoft\CryptnetUrlCache
  1609. \AppData\LocalLow\Microsoft\CryptnetUrlCache
  1610. C:\ProgramData\NVIDIA Corporation\NV_Cache
  1611. \AppData\Local\Nvidia
  1612. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft
  1613. C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{1c3790dc-b8ad-11e8-aa21-e41d2d101530}.TxR.0.regtrans-ms
  1614. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History
  1615. C:\Program Files\Epic Games\Fortnite\.lysEB\Install\$resumeData
  1616. C:\Windows\INF\WmiApRpl\WmiApRpl.ini
  1617. C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{1c3790dc-b8ad-11e8-aa21-e41d2d101530}.TxR.1.regtrans-ms
  1618. C:\Windows\System32\DriverStore\en-US
  1619. C:\Windows\system32\dllcache
  1620. C:\Windows\System32\wbem\Repository
  1621. C:\Windows\System32\config\systemprofile\AppData\Local\temp
  1622. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache
  1623. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft
  1624. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\TempState
  1625. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\AppCache
  1626. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore
  1627. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\Windows
  1628. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Temp
  1629. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData
  1630. \AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
  1631. \AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
  1632. C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3\Win64\d3dcompiler_43.dll
  1633. C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3\Win64\d3dcompiler_47.dll
  1634. C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3\Win64\libcef.dll
  1635. C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3\Win64\libEGL.dll
  1636. C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3\Win64\libGLESv2.dll
  1637. C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3\Win64
  1638. C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\CEF3
  1639. C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\NVIDIA
  1640. C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\Ogg\Win64\VS2015\libogg_64.dll
  1641. C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\Ogg\Win64\VS2015
  1642. C:\Program Files\Epic Games\Fortnite\.lysEB\Install\Engine\Binaries\ThirdParty\PhysX3\Win64\VS2015\ApexFramework_x64.dll
  1643. \AppData\Local\Microsoft\OneDrive\logs
  1644. \AppData\Local\Microsoft\OneDrive\logs\Personal
  1645. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Logs
  1646. C:\Windows\ServiceProfiles\LocalService\AppData\Local\ConnectedDevicesPlatform
  1647. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\RSA
  1648. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons
  1649. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\CLR_v2.0\UsageLogs
  1650. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\INetCache
  1651. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\INetCookies
  1652. C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\Shared Files
  1653. C:\Program Files (x86)\Epic Games\Launcher\VaultCache
  1654. C:\Program Files (x86)\Epic Games\Launcher\Engine\Programs\CrashReportClient\Config\DefaultEngine.ini
  1655. \AppData\Local\Microsoft\Windows\Caches
  1656. \AppData\Local\Microsoft\Internet Explorer\CacheStorage
  1657. C:\ProgramData\Package Cache
  1658. C:\ProgramData\Microsoft\Windows\Caches
  1659. C:\Windows\System32\spp\store\2.0\cache
  1660. C:\Program Files (x86)\Microsoft.NET\Multi-Targeting Pack\v4.5.1\SetupCache
  1661. C:\Program Files (x86)\Microsoft.NET\Multi-Targeting Pack\v4.5.2\SetupCache
  1662. C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Cache
  1663. C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection
  1664. C:\ProgramData\Microsoft\Windows Defender\Definition Updates
  1665. C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CC288659-A1DB-4AEC-BAB2-6DBB6A99ABE8}
  1666. C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\{CC288659-A1DB-4AEC-BAB2-6DBB6A99ABE8}
  1667. C:\Windows\System32\WDI
  1668. C:\Windows\System32\WDI\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{1b3f1407-39d0-4a4f-a547-cd4c65d17116}
  1669. C:\Windows\System32\WDI\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{ed1e579f-1b61-4367-9430-f55c00c26870}
  1670. C:\Windows\SoftwareDistribution\Download\Install
  1671. C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx
  1672. C:\Windows\System32\winevt\Logs\Microsoft-Windows-PriResources-Deployment%4Operational.evtx
  1673. C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.002
  1674. C:\Windows\System32\wbem\Repository\MAPPING1.MAP
  1675. C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan
  1676. C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Backup Scan
  1677. C:\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache
  1678. C:\Windows\System32\drivers\mbamswissarmy.sys
  1679. C:\Windows\System32\catroot2\dberr.txt
  1680. C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\MBAMSwissArmy.cat
  1681. C:\Windows\ServiceState\EventLog\Data\lastalive0.dat
  1682. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\dosvcState.dat.LOG1
  1683. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Intel\DPTF\dptf.dv
  1684. C:\Windows\security\logs
  1685. C:\Windows\security\logs\scecomp.log
  1686. C:\Windows\Logs\CBS\CBS.log
  1687. C:\Windows\Logs\NetSetup\service.0.etl
  1688. C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20190526.072128.021.3.etl
  1689. C:\Windows\bootstat.dat
  1690. \AppData\Roaming\Microsoft\Windows\Recent\The Internet.lnk
  1691. \AppData\Roaming\Microsoft\Windows\AccountPictures\8495ae10deeaf929.accountpicture-ms
  1692. \AppData\Local\ProtonVPN\ProtonVPN.exe_Url_5k5woeau2v3gmtlay4mjwsftlqxjnn2p\1.8.1.0\user.config
  1693. \AppData\Local\ProtonVPN\Logs
  1694. \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat.LOG1
  1695. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache
  1696. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData
  1697. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\FB0D848F74F70BB2EAA93746D24D9749
  1698. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
  1699. \AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd
  1700. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\signals\collection\WIFI\{a70e087b-499b-4632-ad5d-4b1c6d71e648}
  1701. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Graph\Login.ttl
  1702. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Graph\49ccf8c88be99e2b\Me\00000000.ttl
  1703. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\VaStartMenu_01.0409.digest.bin.tmp
  1704. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\VaStartMenuGames_01.0409.digest.bin.tmp
  1705. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest_01.0409.digest.bin.tmp
  1706. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest2_01.0409.digest.bin.tmp
  1707. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB
  1708. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat.LOG1
  1709. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\SkypeRT\persistent.conf
  1710. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\DiagOutputDir\SkypeApp0.txt
  1711. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\CS_localstate\CS_shared.conf
  1712. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\AsyncStorage\saveUlLog.data
  1713. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\AsyncStorage\FirstTimeSignIn.data
  1714. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\AsyncStorage\ecsDefaultConfig.data
  1715. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\TokenBroker\Cache\0c55efda7496e58ee00d3d8c9b78994f9ee0359c.tbres
  1716. \AppData\Local\Microsoft\Windows\UPPS\UPPS.bin
  1717. \AppData\Local\Microsoft\Windows\SettingSync\remotemetastore\v1
  1718. \AppData\Local\Microsoft\Windows\Explorer\NotifyIcon\Microsoft.Explorer.Notification.{856ABD34-82E0-98F4-3351-225E04F0D828}.png
  1719. \AppData\Local\Microsoft\Credentials\5003A98EAE20BC3E53D43ADBDDEDBA4E
  1720. \AppData\Local\EpicGamesLauncher\Saved\webcache\Visited Links
  1721. \AppData\Local\EpicGamesLauncher\Saved\Logs\EpicGamesLauncher.log
  1722. \AppData\Local\EpicGamesLauncher\Saved\Logs\cef3.log
  1723. \AppData\Local\ConnectedDevicesPlatform\49ccf8c88be99e2b\ActivitiesCache.db-wal
  1724. \AppData\Local\ConnectedDevicesPlatform\49ccf8c88be99e2b\ActivitiesCache.db
  1725. C:\Users\All Users\USOPrivate\UpdateStore\updatestore51b519d5-b6f5-4333-8df6-e74d7c9aead4.xml
  1726. C:\Users\All Users\Synaptics\ValidityService.log
  1727. C:\Users\All Users\ProtonVPN\Logs\service.txt
  1728. C:\Users\All Users\Microsoft\Windows Defender\Support\MPLog-20190520-222511.log
  1729. C:\Users\All Users\Microsoft\Windows Defender\Scans
  1730. C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Backup
  1731. C:\Users\All Users\Microsoft\Windows\AppRepository
  1732. C:\Users\All Users\Microsoft\SmsRouter\MessageStore
  1733. C:\Users\All Users\Microsoft\Search\Data\Applications\Windows
  1734. C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\edbtmp.jtx
  1735. C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\edb.jtx
  1736. C:\Users\All Users\Microsoft\Network\Downloader
  1737. C:\Users\All Users\Microsoft\Diagnosis
  1738. C:\Users\All Users\Malwarebytes
  1739. C:\Users\All Users\Malwarebytes\MBAMService
  1740. C:\Users\All Users\Malwarebytes\MBAMService\config
  1741. C:\ProgramData\USOPrivate\UpdateStore\updatestore51b519d5-b6f5-4333-8df6-e74d7c9aead4.xml
  1742. C:\ProgramData\Microsoft\Windows Defender\Support
  1743. C:\ProgramData\Microsoft\Windows Defender\Scans
  1744. C:\ProgramData\Microsoft\Search\Data\Applications\Windows
  1745. C:\Program Files\Malwarebytes
  1746. C:\Windows\System32\winevt\Logs\Microsoft-Windows-Containers-Wcnfs%4Operational.evtx
  1747. C:\Windows\System32\WDI\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{ed1e579f-1b61-4367-9430-f55c00c26870}\snapshot.etl
  1748. C:\Windows\System32\WDI\{533a67eb-9fb5-473d-b884-958cf4b9c4a3}\{1b3f1407-39d0-4a4f-a547-cd4c65d17116}\snapshot.etl
  1749. c:\Windows\SoftwareDistribution\DataStore\Logs,,,
  1750. C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20190526.072128.021.4.etl
  1751. C:\Windows\Logs\waasmedic\waasmedic.20190526_063337_646.etl
  1752. C:\Windows\Logs\waasmedic
  1753. C:\Users\Public\ASR.dat
  1754. \js_logs\2019-05-26-10.txt
  1755. \AppData\Roaming\EasyAntiCheat\gamelauncher.log
  1756. \AppData\Roaming\EasyAntiCheat\217
  1757. \AppData\Local\FortniteGame\Saved\Logs
  1758. \AppData\Local\FortniteGame\Saved\Logs\FortniteGame.log
  1759. \AppData\Local\FortniteGame\Saved\Config\WindowsClient
  1760. \AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\LocalState
  1761. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState
  1762. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache
  1763. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache\MetaData
  1764. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache\Content
  1765. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\INetCache
  1766. \AppData\Local\Microsoft\Windows\ActionCenterCache\microsoft-explorer-notification--856abd34-82e0-98f4-3351-225e04f0d828-_489_0.png
  1767. \AppData\Local\Microsoft\TokenBroker\Cache
  1768. \AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage
  1769. \AppData\Local\EpicGamesLauncher\Saved\webcache\Cache
  1770. C:\Users\All Users\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424_COM15.dat.LOG2
  1771. C:\Users\All Users\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424_COM15.dat.LOG1
  1772. C:\Users\All Users\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424_COM15.dat
  1773. C:\Users\All Users\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424.dat
  1774. C:\Users\All Users\Microsoft\Windows Defender\Definition Updates
  1775. C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\edb00194.jtx
  1776. C:\ProgramData\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424_COM15.dat.LOG2
  1777. C:\ProgramData\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424_COM15.dat.LOG1
  1778. C:\ProgramData\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache\5c8cbb6aa7ea1424.dat
  1779. C:\ProgramData\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache
  1780. \AppData\Local\Microsoft\OneDrive\logs\Common
  1781. C:\ProgramData\Microsoft\Network\Downloader
  1782. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\CacheStorage
  1783. C:\Windows\appcompat\Programs\Amcache.hve.LOG1
  1784. C:\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-Storport%4Operational.evtx
  1785. C:\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-Storport%4Health.evtx
  1786. C:\Windows\ServiceProfiles\NetworkService\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
  1787. C:\Windows\System32\eac_usermode_21654663664752.dll
  1788. C:\Windows\System32\spp\store\2.0\data.dat
  1789. C:\Program Files\Epic Games\Fortnite1\FortniteGame\PersistentDownloadDir\EMS
  1790. \AppData\Local\Microsoft\Windows\WER\ERC\statecache.lock
  1791. C:\Program Files\Epic Games\Fortnite1\FortniteGame\PersistentDownloadDir\CMS
  1792. C:\Program Files (x86)\EasyAntiCheat
  1793. C:\ProgramData\Microsoft\Diagnosis\EventStore.db
  1794. C:\ProgramData\Microsoft\Network\Downloader\edb.chk
  1795. C:\ProgramData\Microsoft\SmsRouter\MessageStore
  1796. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\TokenBroker\Cache
  1797. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\AsyncStorage
  1798. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\Internet Explorer
  1799. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars
  1800. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Graph
  1801. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\signals\collection\WIFI
  1802. \AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState
  1803. C:\Windows\System32\catroot2
  1804. C:\Users\All Users\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\S-1-5-21-2532382528-581214834-2534474248-1001\SystemAppData\Helium\Cache
  1805. C:\Users\All Users\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c
  1806. C:\MSOCache\{71230000-00E2-0000-1000-00000000}
  1807. C:\Users\caspue\AppData\Local\Speech Graphics\Carnival
  1808. C:\windows\system32\dllcache
  1809. C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios
  1810. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\Tips
  1811. C:\ProgramData\Microsoft\Diagnosis\ScenariosSqlStore
  1812. \AppData\Local\Comms\UnistoreDB\USS.jtx
  1813. \AppData\Local\FortniteGame\Saved\LMS
  1814. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat.LOG1
  1815. \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\AC\INetCache
  1816. \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\AC\INetCookies
  1817. \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\AC\INetHistory
  1818. \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\AC\Temp
  1819. \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\LocalCache
  1820. \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\TempState
  1821. \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\roaming.lock
  1822. \AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
  1823. \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\AC\INetCache
  1824. \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\AC\INetCookies
  1825. \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\AC\INetHistory
  1826. \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\AC\Temp
  1827. \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
  1828. \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\roaming.lock
  1829. \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\TempState
  1830. \AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\LocalCache
  1831. C:\Program Files\WindowsApps\Microsoft.StorePurchaseApp_11811.1001.18.0_neutral_split.language-de_8wekyb3d8bbwe
  1832. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.MicrosoftStickyNotes_3.6.73.0_x64__8wekyb3d8bbwe\ActivationStore.dat.LOG1
  1833. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.MicrosoftStickyNotes_3.6.73.0_x64__8wekyb3d8bbwe\ActivationStore.dat.LOG2
  1834. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\migration.dat.LOG1
  1835. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\migration.dat.LOG2
  1836. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\dosvcState.dat.LOG2
  1837. \AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\AC\INetCache
  1838. \AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\AC\INetCookies
  1839. \AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\AC\INetHistory
  1840. \AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\AC\Temp
  1841. \AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\TempState
  1842. \AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\LocalCache
  1843. C:\Windows\System32\winevt\Logs\Application.evtx
  1844. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\INetCache
  1845. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\INetCookies
  1846. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\INetHistory
  1847. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache
  1848. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content
  1849. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData
  1850. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AppData
  1851. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalCache
  1852. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState
  1853. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\TempState
  1854. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC
  1855. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\INetCache
  1856. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\INetCookies
  1857. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\INetHistory
  1858. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\Temp
  1859. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\Temp\NVIDIA Corporation
  1860. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\Temp\NVIDIA Corporation\NV_Cache
  1861. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalCache
  1862. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState
  1863. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState
  1864. \AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\AC
  1865. \AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\AC\Temp
  1866. \AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\AC\Temp\NVIDIA Corporation
  1867. \AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\AC\Temp\NVIDIA Corporation\NV_Cache
  1868. \AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG1
  1869. \AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG2
  1870. \AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG1
  1871. \AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG2
  1872. \AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState
  1873. \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\INetCookies
  1874. \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\INetCache
  1875. \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\INetHistory
  1876. \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\TempState
  1877. \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\settings.dat.LOG1
  1878. \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\settings.dat.LOG2
  1879. \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\LocalCache
  1880. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache
  1881. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\Local
  1882. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\Local\Microsoft
  1883. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\Local\Microsoft\Windows
  1884. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\Local\Microsoft\Windows\Caches
  1885. \AppData\Local\Packages\AD2F1837.HPPrinterControl_v10z8vjag6ke6\AC\INetCache
  1886. \AppData\Local\Packages\AD2F1837.HPPrinterControl_v10z8vjag6ke6\AC\INetCookies
  1887. \AppData\Local\Packages\AD2F1837.HPPrinterControl_v10z8vjag6ke6\AC\INetHistory
  1888. \AppData\Local\Packages\AD2F1837.HPPrinterControl_v10z8vjag6ke6\AC\Temp
  1889. \AppData\LocalLow\Microsoft\CryptnetUrlCache\Content
  1890. \AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
  1891. C:\Windows\System32\spp\store\2.0
  1892. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19051.545.0_x64__8wekyb3d8bbwe
  1893. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\roaming.lock
  1894. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat.LOG1
  1895. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat.LOG2
  1896. C:\ProgramData\Epic\EpicGamesLauncher\Data\EMS
  1897. C:\ProgramData\Epic\UnrealEngineLauncher
  1898. C:\ProgramData\NVIDIA Corporation
  1899. C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx
  1900. C:\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-Storport%4Health.evtx
  1901. C:\Windows\System32\winevt\Logs\Microsoft-Windows-Storage-Storport%4Operational.evtx
  1902. \AppData\Local\Microsoft\Windows\IECompatCache
  1903. \AppData\Local\Microsoft\Windows\IECompatUaCache
  1904. \AppData\Local\Microsoft\Windows\INetCookies
  1905. \AppData\Local\Microsoft\Windows\INetCookies\Low
  1906. \AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
  1907. \AppData\Local\Spotify\Browser\GPUCache
  1908. C:\Windows\System32\wbem\Logs\wmiprov.log
  1909. C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTTerminal-Services-LSM-ApplicationLag-9032.etl
  1910. C:\Program Files (x86)\Common Files\BattlEye
  1911. C:\Windows\System32\config\SOFTWARE.LOG1
  1912. C:\Windows\WindowsUpdate.log
  1913. \AppData\Local\Packages\InputApp_cw5n1h2txyewy\AC
  1914. \AppData\Local\Packages\InputApp_cw5n1h2txyewy\AC\Temp
  1915. \AppData\Local\Packages\InputApp_cw5n1h2txyewy\AC\Temp\NVIDIA Corporation
  1916. \AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\AC\Temp\NVIDIA Corporation
  1917. \AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\AC\Temp
  1918. \AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\AC
  1919. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content
  1920. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData
  1921. \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\Temp\NVIDIA Corporation
  1922. \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\Temp\NVIDIA Corporation\NV_Cache
  1923. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\TempState\Traces
  1924. C:\Windows\System32\wbem\Performance
  1925. C:\Windows\AppReadiness
  1926. C:\ProgramData\regid.1991-06.com.microsoft
  1927. \AppData\Local\Microsoft\Internet Explorer\Indexed DB
  1928. C:\Windows\ServiceProfiles\LocalService\ntuser.dat.log1
  1929. C:\Windows\ServiceProfiles\LocalService\ntuser.dat.log2
  1930. \AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC
  1931. \AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\Temp
  1932. \AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\INetHistory
  1933. \AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\INetCookies
  1934. \AppData\Local\Temp\NVIDIA Corporation\NV_Cache
  1935. \AppData\Local\Microsoft\Windows\History
  1936. C:\Windows\Public\Libraries
  1937. C:\Users\Public\Libraries\collection.dat
  1938. C:\MSOCache\{71230000-00E2-0000-1000-00000000}\Setup.dat
  1939. C:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules
  1940. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.jfm
  1941. \AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
  1942. C:\Windows\System32\WDI\LogFiles\StartupInfo
  1943. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs
  1944. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State
  1945. C:\Windows\SysWOW64\Gms.log
  1946. \AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous
  1947. \AppData\Local\Microsoft\Windows\WER\ERC
  1948. \AppData\Local\Comms\Unistore\data
  1949. \AppData\Local\Comms\Unistore\data\temp
  1950. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AppData\User\Default\Indexed DB\edb.log
  1951. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AppData\User\Default\Indexed DB
  1952. \AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb
  1953. C:\Windows\appcompat\Programs\Install
  1954. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\Recovery\Active
  1955. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!002\MicrosoftEdge\User\Default\AppCache
  1956. \AppData\Roaming\Microsoft\Windows\Recent\Autom
  1957. C:\Windows\rescache\_merged
  1958. \AppData\Local\Microsoft\OneDrive\settings\Personal
  1959. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache
  1960. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive\AuthStateCache.dat
  1961. C:\Windows\Logs\MoSetup\UpdateAgent.log
  1962. C:\Windows\SoftwareDistribution\PostRebootEventCache.V2\{323558A6-0300-4C3E-97A0-EDEDFEB96B00}.bin
  1963. C:\Windows\SoftwareDistribution\PostRebootEventCache.V2
  1964. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
  1965. \AppData\Local\Comms\UnistoreDB
  1966. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGameOverlay_1.42.4001.0_x64__8wekyb3d8bbwe\ActivationStore.dat
  1967. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\DiagOutputDir
  1968. systemdrive%\Users\
  1969. \AppData\Local\Microsoft\Windows\Safety\edge\remote
  1970. C:\Windows\SoftwareDistribution\DataStore\DataStore.edb
  1971. C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log
  1972. \AppData\Local\Microsoft\VisualStudio\16.0_76be8573\privateregistry.bin.LOG2
  1973. \AppData\Local\Microsoft\VisualStudio\16.0_76be8573\privateregistry.bin.LOG1
  1974. C:\Windows\System32\winevt\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx
  1975. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\IndexedDB.jfm
  1976. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe\ActivationStore.dat
  1977. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\Assets
  1978. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi
  1979. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\StagedAssets
  1980. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\INetCache\ARDTOTYX
  1981. C:\Program Files (x86)\Google\CrashReports
  1982. \AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\LocalState\DiagOutputDir
  1983. \AppData\Local\Comms\UnistoreDB\store.jfm
  1984. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Wallet_2.2.18179.0_x64__8wekyb3d8bbwe\ActivationStore.dat
  1985. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\TargetedContentCache
  1986. C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd-wal
  1987. C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd
  1988. \AppData\Local\Temp\VSRemoteControl
  1989. \AppData\Local\Temp\VSFeedbackIntelliCodeLogs
  1990. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Temp
  1991. C:\ProgramData\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db
  1992. C:\ProgramData\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db-wal
  1993. C:\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\XSettings.Sav
  1994. C:\Windows\System32\winevt\Logs\Microsoft-Windows-Fault-Tolerant-Heap%4Operational.evtx
  1995. C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs
  1996. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings
  1997. C:\ProgramData\Microsoft\Windows\WER\ReportQueue
  1998. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings
  1999. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings\settings.dat.LOG1
  2000. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings\settings.dat.LOG2
  2001. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGameOverlay_1.42.4001.0_x64__8wekyb3d8bbwe
  2002. C:\Windows\SoftwareDistribution\Download
  2003. C:\ProgramData\Audyssey Labs
  2004. C:\ProgramData\Intel\ShaderCache
  2005. C:\ProgramData\Intel\ShaderCache\FortniteClient-Win64-Shipping_1
  2006. C:\ProgramData\Intel\ShaderCache\EpicGamesLauncher_1
  2007. C:\ProgramData\Microsoft\Provisioning\AssetCache
  2008. C:\ProgramData\Microsoft\Search\Data\Temp
  2009. C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrccache
  2010. C:\ProgramData\Microsoft\Windows\DeviceMetadataCache
  2011. C:\ProgramData\Microsoft\Windows\wfp
  2012. C:\ProgramData\NVIDIA Corporation\umdlogs
  2013. C:\ProgramData\Package Cache\{64ff2cb0-807c-4ee9-87ef-ec1b2ede0daf}
  2014. C:\Users\Public\Desktop
  2015. C:\Users\Public\AccountPictures
  2016. \AppData\LocalLow\Temp
  2017. \AppData\Local\Intel
  2018. \AppData\Local\AMD
  2019. \AppData\Local\History
  2020. \AppData\Local\MicrosoftEdge\SharedCacheContainers
  2021. \AppData\Local\MicrosoftEdge\User\Default
  2022. \AppData\Local\OneDrive\cache
  2023. \AppData\Local\OneDrive\cache\qmlcache
  2024. \AppData\Local\SquirrelTemp
  2025. \AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs
  2026. \AppData\Local\Microsoft\CLR_v4.0\UsageLogs
  2027. \AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs
  2028. \AppData\Local\Microsoft\Internet Explorer\DOMStore
  2029. \AppData\Local\Microsoft\Media Player\Transcoded Files Cache
  2030. \AppData\Local\Microsoft\Vault
  2031. \AppData\Local\Microsoft\VisualStudio\16.0_b35fdcc8\PackageCache
  2032. \AppData\Local\Microsoft\VisualStudio\16.0_b35fdcc8\TextMateCache
  2033. \AppData\Local\Microsoft\Windows\IEDownloadHistory
  2034. \AppData\Local\Microsoft\Windows\PPBCompatCache
  2035. \AppData\Local\Microsoft\Windows\PPBCompatUaCache
  2036. \AppData\Local\Microsoft\Windows\PRICache
  2037. \AppData\Local\Microsoft\Windows\WER
  2038. \AppData\Roaming\Adobe\Flash Player\AssetCache
  2039. \AppData\Roaming\Adobe\Flash Player\NativeCache
  2040. \AppData\Roaming\Microsoft\Vault
  2041. \AppData\Roaming\NVIDIA\ComputeCache
  2042. \AppData\Roaming\Visual Studio Setup\Cache
  2043. \AppData\Roaming\Visual Studio Setup\GPUCache
  2044. \AppData\Roaming\vs_installershell\logs
  2045. \AppData\Roaming\Microsoft\Spelling\en-US
  2046. \AppData\Roaming\Microsoft\Spelling\en-UK
  2047. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings\settings.dat
  2048. \AppData\Local\Origin\Origin\QtWebEngine\Default\Service Worker\ScriptCache
  2049. \AppData\Local\Microsoft\PenWorkspace
  2050. \AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
  2051. \AppData\Local\Origin\Web Cache
  2052. C:\Windows\System32\winevt\Logs\Security.evtx
  2053. C:\ProgramData\Origin\AchievementCache
  2054. C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json.new
  2055. C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\TELEMETRY.ASM-WINDOWSSQ.json.new
  2056. C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.ASM-WindowsDefault.json.new
  2057. C:\ProgramData\Microsoft\Windows\LfSvc\Geofence\S-1-5-18_NonPackagedApp\Geofence.dat
  2058. C:\ProgramData\Microsoft\Windows\LfSvc\Geofence\S-1-5-18_NonPackagedApp
  2059. C:\Windows\System32\LogFiles\WMI
  2060. C:\ProgramData\Intel
  2061. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\1033
  2062. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Caches
  2063. C:\Windows\System32\config\systemprofile\AppData\Local\D3DSCache\f9156d1136660b11\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.lock
  2064. :\ProgramData\Intel\ShaderCache\taskhostw_1
  2065. C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTdfa2c640-651d-488d-a479-2fd7a7ca6e29.etl
  2066. C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20190621.222200.334.1.etl
  2067. C:\Windows\SoftwareDistribution\DataStore\DataStore.jfm
  2068. C:\Windows\INF\WmiApRpl\0009
  2069. :\Windows\System32\wbem\Performance
  2070. C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTTerminal-Services-LSM-ApplicationLag-9452.etl
  2071. \Saved Games\Respawn\Apex
  2072. \AppData\Roaming\CSM
  2073. C:\Windows\System32\SMI\Store\Machine
  2074. C:\ProgramData\Epic\EpicGamesLauncher\Data\EMS\stage
  2075. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c
  2076. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
  2077. C:\ProgramData\Microsoft\XboxLive\NSALCache
  2078. C:\Program Files (x86)\AMD\CNext\CCCSlim
  2079. \Videos\Captures\desktop.ini
  2080. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe
  2081. \AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe
  2082. \AppData\Local\Microsoft\Windows\SettingSync
  2083. \AppData\Local\Comms\Unistore
  2084. \AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-wal
  2085. \AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db
  2086. C:\Users\Public\Shared Files
  2087. C:\Users\Public\Shared Files.sys
  2088. C:\Windows\System32\config\systemprofile\AppData\Local\D3DSCache
  2089. C:\Windows\System32\config\systemprofile\AppData\Local\Packages\microsoft.windows.fontdrvhost\AC
  2090. C:\Windows\SoftwareDistribution
  2091. C:\Windows\SoftwareDistribution\SLS
  2092. C:\Windows\Logs\SIH
  2093. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\ReactNativeBundle.bin
  2094. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\dtlscert.der
  2095. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\dtlskey.der
  2096. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\SkypeRT\persistent.tmp
  2097. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\slimcore-aria-cache.data-shm
  2098. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\slimcore-aria-cache.data-wal
  2099. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\slimcore-aria-cache.data-journal
  2100. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC
  2101. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft
  2102. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\CS_localstate
  2103. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\shared.xml
  2104. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\shared.lck
  2105. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\INetCache\container.dat
  2106. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\INetCookies\ESE\container.dat
  2107. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\TempState\VimTemp
  2108. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\TempState
  2109. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalCache\RNManualFileCache
  2110. C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb0003A.jtx
  2111. C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbtmp.jtx
  2112. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History
  2113. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies
  2114. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5
  2115. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5
  2116. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache
  2117. C:\ProgramData\Microsoft\Windows\wfp\currentState.xml
  2118. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.MicrosoftEdge_44.17763.1.0_neutral__8wekyb3d8bbwe
  2119. C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\microsoft.system.package.metadata\Autogen
  2120. C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\microsoft.system.package.metadata\Autogen\JSByteCodeCache_64
  2121. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.Cortana_1.11.5.17763_neutral_neutral_cw5n1h2txyewy
  2122. \AppData\Local\Microsoft\Windows\History\History.IE5\container.dat
  2123. C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx
  2124. C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb0001C.jtx
  2125. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat.LOG2
  2126. \AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Temp\NVIDIA Corporation
  2127. \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat.LOG1
  2128. \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat.LOG2
  2129. \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat.LOG2
  2130. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsAlarms_10.1903.1006.0_x64__8wekyb3d8bbwe
  2131. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsAlarms_10.1903.1006.0_neutral_split.scale-100_8wekyb3d8bbwe
  2132. \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AC\Temp
  2133. \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AC\INetCache
  2134. \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AC\INetHistory
  2135. \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AC\INetCookies
  2136. \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\LocalCache
  2137. \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings
  2138. \AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\TempState
  2139. C:\Program Files\WindowsApps\Microsoft.WindowsAlarms_10.1903.1006.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata
  2140. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_neutral_split.language-de_8wekyb3d8bbwe
  2141. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_neutral_split.scale-100_8wekyb3d8bbwe
  2142. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_x64__8wekyb3d8bbwe
  2143. \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\Temp
  2144. \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\INetCache
  2145. \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\INetHistory
  2146. \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\INetCookies
  2147. \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\LocalCache
  2148. \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\TempState
  2149. C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19061.410.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata
  2150. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings
  2151. \AppData\Local\Packages\InputApp_cw5n1h2txyewy\AC\INetCache
  2152. \AppData\Local\Packages\InputApp_cw5n1h2txyewy\AC\INetHistory
  2153. \AppData\Local\Packages\InputApp_cw5n1h2txyewy\AC\INetCookies
  2154. \AppData\Local\Packages\InputApp_cw5n1h2txyewy\LocalCache
  2155. \AppData\Local\Packages\InputApp_cw5n1h2txyewy\TempState
  2156. C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx
  2157. C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx
  2158. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c
  2159. C:\ProgramData\Microsoft\Network
  2160. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsStore_11905.1001.4.0_neutral_split.scale-100_8wekyb3d8bbwe
  2161. C:\Windows\TEMP\NVIDIA Corporation
  2162. C:\Program Files\UNP\UpdateNotificationMgr
  2163. C:\Program Files\UNP\Logs
  2164. \AppData\Local\Microsoft\Windows\Safety\edge\local\local\cache
  2165. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC
  2166. \AppData\Local\Microsoft\VisualStudio\Packages\_Channels
  2167. \AppData\Local\Microsoft\VisualStudio\Packages\_Instances
  2168. C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd
  2169. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe
  2170. \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC
  2171. C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator
  2172. C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal
  2173. C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\microsoft.system.package.metadata
  2174. \AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\TempState
  2175. \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings
  2176. \AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\LocalState
  2177. C:\Program Files\WindowsApps\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata
  2178. C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd-shm
  2179. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\TokenBroker\Cache
  2180. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\BackgroundTransferApi
  2181. C:\Windows\appcompat\Programs
  2182. \AppData\Local\Microsoft\Windows\Explorer\ThumbCacheToDelete
  2183. \AppData\Local\FortniteGame\Saved\Cloud
  2184. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\InstallAgent\Checkpoints
  2185. \AppData\Roaming\Microsoft\Spelling
  2186. C:\Windows\System32\eac_usermode_11511826802397.dll
  2187. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC
  2188. \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC
  2189. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\OneSettingsResponseCache
  2190. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\DeviceSearchCache
  2191. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\AppIconCache
  2192. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\AppIconCache\100
  2193. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState
  2194. \AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
  2195. C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.bk
  2196. C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json
  2197. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\InstallAgent
  2198. C:\ProgramData\Microsoft\Windows\WER
  2199. \AppData\Local\Microsoft\Windows\INetCache\Content.IE5
  2200. C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore
  2201. C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap
  2202. C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex
  2203. C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects
  2204. \AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
  2205. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\roaming.lock
  2206. C:\Windows\TEMP\NVIDIA Corporation\NV_Cache
  2207. C:\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings
  2208. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows
  2209. C:\Windows\System32\eac_usermode_9472654871434.dll
  2210. \AppData\Local\Microsoft\Windows\UsrClass.dat
  2211. C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm
  2212. C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.DIAGNOSTICS.xml.temp
  2213. C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.DIAGNOSTICS.xml
  2214. C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\WINDOWS.DIAGNOSTICS.xml.new
  2215. \AppData\Local\Microsoft\CLR_v2.0\UsageLogs
  2216. C:\ProgramData\USOShared\Logs\NotificationUxBroker_Temp.1.etl
  2217. \AppData\Local\Microsoft\Windows\Ringtones
  2218. \AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
  2219. C:\Windows\WindowsUpData.dll
  2220. C:\Windows\WindowsUpData.sys
  2221. C:\ProgramData\Origin
  2222. C:\ProgramData\Origin\CatalogCache
  2223. C:\ProgramData\Origin\CustomBoxartCache
  2224. C:\ProgramData\Origin\DownloadCache
  2225. C:\ProgramData\Origin\EntitlementCache
  2226. C:\ProgramData\Origin\IGOCache
  2227. C:\ProgramData\Origin\NonOriginContentCache
  2228. C:\ProgramData\Origin\SelfUpdate
  2229. C:\ProgramData\Origin\Subscription
  2230. C:\ProgramData\Origin\Telemetry
  2231. E:\ProgramData\Origin
  2232. E:\ProgramData\Origin\AchievementCache
  2233. E:\ProgramData\Origin\CatalogCache
  2234. E:\ProgramData\Origin\CustomBoxartCache
  2235. E:\ProgramData\Origin\DownloadCache
  2236. E:\ProgramData\Origin\EntitlementCache
  2237. E:\ProgramData\Origin\IGOCache
  2238. E:\ProgramData\Origin\Logs
  2239. E:\ProgramData\Origin\NonOriginContentCache
  2240. E:\ProgramData\Origin\SelfUpdate
  2241. E:\ProgramData\Origin\Subscription
  2242. E:\ProgramData\Origin\Telemetry
  2243. D:\ProgramData\Origin
  2244. D:\ProgramData\Origin\AchievementCache
  2245. D:\ProgramData\Origin\CatalogCache
  2246. D:\ProgramData\Origin\CustomBoxartCache
  2247. D:\ProgramData\Origin\DownloadCache
  2248. D:\ProgramData\Origin\EntitlementCache
  2249. D:\ProgramData\Origin\IGOCache
  2250. D:\ProgramData\Origin\Logs
  2251. D:\ProgramData\Origin\NonOriginContentCache
  2252. D:\ProgramData\Origin\SelfUpdate
  2253. D:\ProgramData\Origin\Subscription
  2254. D:\ProgramData\Origin\Telemetry
  2255. \AppData\Roaming\Origin
  2256. C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePacken-GB_17763.9.22.0_neutral__8wekyb3d8bbwe\Windows\System32\driverstore
  2257. C:\ProgramData\Microsoft\Windows\ClipSVC
  2258. C:\Windows\appcompat\appraiser\AltData\Appraiser_Data.ini
  2259. C:\Windows\Logs\MoSetup
  2260. \AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState
  2261. C:\Windows\System32\spp\store
  2262. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization
  2263. C:\Windows\System32\WDI\LogFiles
  2264. C:\Program Files (x86)\AMD
  2265. C:\Program Files (x86)\AMD\CNext
  2266. \AppData\Local\Microsoft\Internet Explorer
  2267. \AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy
  2268. C:\Users\DefaultAppPool
  2269. C:\Users\All Users\NVIDIA Corporation
  2270. C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.CloudExperienceHost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy
  2271. C:\Users\All Users\Intel
  2272. C:\Windows\System32\LogFiles\WMI\LwtNetLog.etl
  2273. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.CloudExperienceHost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy
  2274. C:\Users\All Users\Microsoft\Windows\WER
  2275. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGamingOverlay_3.30.20002.0_x64__8wekyb3d8bbwe
  2276. C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGamingOverlay_3.30.20002.0_x64__8wekyb3d8bbwe
  2277. \AppData\Local\ElevatedDiagnostics
  2278. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5
  2279. C:\ProgramData\Microsoft\XboxLive
  2280. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AppData
  2281. C:\Windows\rescache
  2282. C:\Windows\ServiceState\EventLog
  2283. \AppData\Local\Microsoft\Windows\Safety
  2284. C:\Windows\appcompat\appraiser
  2285. \AppData\Local\temp\Origin
  2286. C:\ProgramData\Microsoft\Windows\ClipSvc
  2287. C:\Users\All Users\Microsoft\Windows\AppRepository\1e219871-2a28-4d27-b3c8-3412c40a9d4b_S-1-5-21-3790113146-3068863390-284532636-1001_24.rslc
  2288. C:\Users\All Users\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal
  2289. C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_neutral_split.language-de_8wekyb3d8bbwe
  2290. C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_neutral_split.scale-100_8wekyb3d8bbwe
  2291. C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_x64__8wekyb3d8bbwe
  2292. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_x64__8wekyb3d8bbwe\ActivationStore.dat
  2293. C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.YourPhone_1.19061.410.0_x64__8wekyb3d8bbwe\ActivationStore.dat
  2294. C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19061.410.0_x64__8wekyb3d8bbwe
  2295. \AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe
  2296. C:\Users\All Users\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm
  2297. C:\Users\All Users\Epic\UnrealEngineLauncher
  2298. C:\Users\All Users\Microsoft\Diagnosis\parse.dat
  2299. C:\Users\All Users\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db-wal
  2300. C:\Users\All Users\Microsoft\Diagnosis\DownloadedScenarios
  2301. C:\Users\All Users\Microsoft\Diagnosis\DownloadedSettings
  2302. C:\Users\All Users\Epic\EpicGamesLauncher\Data\EMS
  2303. \IntelGraphicsProfiles
  2304. \MicrosoftEdgeBackups
  2305. \Documents\desktop.ini
  2306. \Picture\desktop.ini
  2307. \AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe
  2308. \AppData\Roaming\Notepad++\backup
  2309. C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex
  2310. C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex
  2311. C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore
  2312. C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap
  2313. C:\ProgramData\Microsoft\Search\Data
  2314. C:\Users\All Users\Microsoft\Search\Data
  2315. C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Config
  2316. C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects
  2317. \AppData\Local\Microsoft\Internet Explorer\EmieSiteList
  2318. \AppData\Local\Microsoft\OneDrive\StandaloneUpdater
  2319. C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.CloudExperienceHost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat
  2320. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.CloudExperienceHost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat
  2321. C:\Users\All Users\Microsoft\Diagnosis\EventStore.db-wal
  2322. C:\Windows\TEMP\UDD6086.tmp
  2323. \AppData\Local\Microsoft\Internet Explorer\EmieUserList
  2324. C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jcp
  2325. C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\edb.jcp
  2326. \AppData\Local\NVIDIA Corporation\GfeSDK\FortniteClient-Win64-Shipping_10864.log
  2327. C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00025.jtx
  2328. C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\edb00025.jtx
  2329. \AppData\Local\Microsoft\Windows\INetCookies\ESE
  2330. \AppData\Local\Intel\CUIPromotions
  2331. \AppData\Local\Microsoft\Credentials
  2332. C:\Users\All Users\Microsoft\Windows\ClipSvc\tokens.dat
  2333. C:\Users\All Users\Microsoft\Windows\ClipSvc
  2334. C:\ProgramData\Microsoft\Windows\ClipSvc\tokens.dat.bak
  2335. C:\Users\All Users\Intel\ShaderCache
  2336. C:\ProgramData\Microsoft\Windows\ClipSvc\tokens.dat
  2337. C:\Users\All Users\Microsoft\Windows\ClipSvc\tokens.dat.bak
  2338. C:\Program Files\Epic Games\Fortnite\FortniteGame\Content\Movies
  2339. \AppData\Local\Microsoft\OneDrive
  2340. C:\Users\All Users\NVIDIA
  2341. C:\Users\Default
  2342. C:\Users\All Users\Microsoft\SmsRouter
  2343. \AppData\Local\Microsoft\Windows\DeliveryOptimization
  2344. C:\ProgramData\Microsoft\Windows\ClipSVC\tokens.dat
  2345. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Credentials
  2346. C:\Windows\CbsTemp
  2347. C:\Windows\servicing\Sessions
  2348. C:\Windows\WinSxS\Temp
  2349. C:\ProgramData\Electronic Arts
  2350. \.QtWebEngineProcess
  2351. \Saved Games\Respawn\Apex\
  2352. \Documents\apex_crash.txt
  2353. C:\Program Files\Common Files\EAInstaller
  2354. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Origin
  2355. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Origin
  2356. C:\Program Files (x86)\Origin\debug.log
  2357. C:\Program Files (x86)\Origin\EACore.ini
  2358. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Credentials
  2359. C:\Windows\ServiceState\EventLog\Data\lastalive1.dat
  2360. \AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Update.exe.log
  2361. C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\CMS\CacheAccess.json
  2362. C:\Windows\System32\sru\SRU.chk
  2363. C:\Users\All Users\NVIDIA Corporation\nvstapisvr\nvstapisvr.log
  2364. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\IndexedDB.edb
  2365. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\edb.chk
  2366. \AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\edb.log
  2367. C:\Users\All Users\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd
  2368. C:\Users\All Users\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd-wal
  2369. C:\Windows\SoftwareDistribution\DataStore\Logs\edb.chk
  2370. \AppData\Local\EpicGamesLauncher\Saved\Data
  2371. C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache
  2372. C:\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate
  2373. C:\Windows\System32\Tasks\Microsoft\Windows\CloudExperienceHost
  2374. C:\Windows\System32\Tasks\Microsoft\Windows
  2375. C:\Windows\System32\Tasks\Microsoft\XblGameSave
  2376. C:\Users\All Users\Microsoft\Windows\AppRepository\StateRepository-Deployment.srd-shm
  2377. C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGamingOverlay_3.32.20003.0_x64__8wekyb3d8bbwe\ActivationStore.dat
  2378. C:\Users\All Users\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGamingOverlay_3.32.20003.0_x64__8wekyb3d8bbwe\ActivationStore.dat
  2379. C:\Users\All Users\USOShared
  2380. C:\ProgramData\USOShared
  2381. C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx
  2382. C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\AC Power Download
  2383. C:\Windows\SoftwareDistribution\DataStore\
  2384. C:\Users\All Users\USOPrivate\UpdateStore
  2385. C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Notifications
  2386. sc delete prox
  2387. \AppData\Local\Temp\tem7AD6.tmp
  2388. \AppData\Local\Temp\tem7AD8.tmp
  2389. \AppData\Local\Temp\tem6AD8.tmp
  2390. \AppData\Local\Temp\tem1AD8.tmp
  2391. \AppData\Local\Temp\tem5AD8.tmp
  2392. \AppData\Local\Temp\tem7gD8.tmp
  2393. \AppData\Local\Temp\tem7AgD8.tmp
  2394. sc create prox binpath= C:\Users\
  2395. \AppData\Local\Temp\tem7AD6.tmp type= kernel
  2396. \AppData\Local\Temp\temposid.tmp
  2397. \AppData\Local\Temptemp\tem7aD8.tmp
  2398. \AppData\Local\Temp\temp\tem7ADz.tmp
  2399. SELECT * FROM Win32_DiskDrive
  2400. Error: 105 (Contact I LOVE PIZZA#6740)
  2401. Error: 123 (Contact I LOVE PIZZA#6740)
  2402. ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789
  2403. MSI A320M PRO - E
  2404. Asus Prime A320M-C R2.0
  2405. Gigabyte GA - A320M - H
  2406. ASRock Z390 Phantom Gaming SLI
  2407. Asus ROG Rampage VI Extreme Omega
  2408. Asus Prime H310I - Plus R2.0
  2409. Asus ROG Zenith Extreme Alpha X399
  2410. MSI MEG X299 Creation
  2411. ASRock AB350M - HDV R3.0
  2412. MSI B450M Pro-VDH V2
  2413. MSI B450M Bazooka V2
  2414. Asus Prime B450M - A / CSM
  2415. Asus Prime H310I - Plus R2.0 / CSM
  2416. Gigabyte GA-AB350M-DS3H V2 (rev. 1.1)
  2417. Gigabyte B360 M AORUS PRO
  2418. Gigabyte X299-WU8
  2419. MSI MAG Z390M Mortar
  2420. HARDWARE\DESCRIPTION\System\BIOS
  2421. BaseBoardProduct
  2422. BaseBoardVersion
  2423. BaseBoardManufacturer
  2424. SystemManufacturer
  2425. BIOSReleaseDate
  2426. SystemProductName
  2427. American Megatrends Inc.
  2428. Phoenix Technologies, Ltd
  2429. Award Software, Inc.
  2430. Intel Corporation
  2431. Sun Microsystems
  2432. SYSTEM\HardwareConfig\Current
  2433. SYSTEM\CurrentControlSet\Control\SystemInformation
  2434. ComputerHardwareId
  2435. ABCDEFGHIJKLMNOPQRSTUVWXYZ
  2436. abcdefghijklmnopqrstuvwxyz0123456789
  2437. Software\Epic Games\Unreal Engine\Identifiers
  2438. HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\0
  2439. HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\1
  2440. Software\Microsoft\Feeds
  2441. BackgroundSync
  2442. Software\Microsoft\IdentityCRL\ExtendedProperties
  2443. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\Connected
  2444. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\Disconnected
  2445. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\EmailImage
  2446. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\FaxImage
  2447. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\PrintImage
  2448. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\ScanButton
  2449. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Events\STIproxyEvent
  2450. HKEY_LOCAL_MACHINE\Software\Microsoft\IdentityCRL\ExtendedProperties
  2451. HKEY_CURRENT_USER\Software\Microsoft\Feeds
  2452. HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\0
  2453. HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\1
  2454. HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\BIOS
  2455. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography
  2456. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\IDConfigDB\Hardware Profiles\0001
  2457. HKEY_LOCAL_MACHINE\SYSTEM\HardwareConfig\{b30417c0-53bd-11e5-8727-305a3ae502fe}
  2458. HKEY_LOCAL_MACHINE\SYSTEM\HardwareConfig
  2459. HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\DMR
  2460. HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\General
  2461. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient
  2462. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware Profiles\0001
  2463. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware
  2464. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion
  2465. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation
  2466. ComputerHardwareIds
  2467. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e965-e325-11ce-bfc1-08002be10318}\Configuration\Variables\BusDeviceDesc
  2468. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\DeviceDesc
  2469. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\Driver
  2470. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WMI\Autologger\AppModel
  2471. HKEY_LOCAL_MACHINE\SYSTEM\SYSTEM\HardwareConfig
  2472. /c wmic useraccount where caption='
  2473. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName
  2474. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName
  2475. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Tcpip\Parameters
  2476. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
  2477. RegisteredOwner
  2478. RegisteredOrganization
  2479. Virtual Machine
  2480. ipconfig /release
  2481. ipconfig /renew
  2482. ipconfig /flushdns
  2483. netsh advfirewall reset
  2484. netsh int ipv6 reset
  2485. netsh winsock reset
  2486. netsh int ip reset
  2487. Select * from Win32_ComputerSystem
  2488. microsoft corporation
  2489. C:\Program Files\DBG
  2490. Anti Debug Detected:
  2491. C:\Program Files\DBG\
  2492. Win32_Process.Handle='
  2493. HP Intel Core i3 - 6100
  2494. IBM Intel Xeon E5620
  2495. Lenovo Intel Xeon Silver 4114
  2496. AMD Athlon 220GE Boxed
  2497. AMD Athlon 240GE Boxed
  2498. Intel Xeon E-2186G Tray
  2499. Dell Intel Xeon Gold 5120
  2500. AMD A8 - 7680 Boxed
  2501. AMD Ryzen 7 2700 Wraith MAX Boxed
  2502. AMD Ryzen 5 2600X Wraith Max Boxed
  2503. AMD Ryzen 3 2300X Tray
  2504. HARDWARE\DESCRIPTION\System\CentralProcessor\0
  2505. ProcessorNameString
  2506. SOFTWARE\Microsoft\Windows NT\CurrentVersion
  2507. 17763.1.amd64fre.rs5_release.180914-
  2508. 17763.rs5_release.180914-
  2509. CurrentVersion
  2510. CurrentBuildNumber
  2511. HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 0\Target Id 0\Logical Unit Id 0
  2512. HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 1\Target Id 0\Logical Unit Id 0
  2513. SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate
  2514. SOFTWARE\Microsoft\Internet Explorer\Registration
  2515. HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 0\Target Id 2\Logical Unit Id 0
  2516. SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName
  2517. SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName
  2518. SOFTWARE\Microsoft\Cryptography
  2519. SYSTEM\ControlSet001\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}\Configuration\Variables\BusDeviceDesc
  2520. SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\DeviceDesc
  2521. SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\Configuration\Variables\Driver
  2522. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName /v ComputerName /t REG_SZ /d PizzaXYZ-%random% /f
  2523. Software\WOW6432Node
  2524. Electronic Arts
  2525. Software\Classes
  2526. com.epicgames.launcher
  2527. SOFTWARE\Classes
  2528. SOFTWARE\WOW6432Node
  2529. SOFTWARE\NVIDIA Corporation\Installer2
  2530. HardwareConfig
  2531. Software\Classes\Installer\Dependencies
  2532. Software\Classes\Installer\Dependecies
  2533. Software\Microsoft\Direct3D
  2534. System\CurrentControlSet\Control
  2535. SystemStartOptions
  2536. SOFTWARE\Microsoft\RADAR\HeapLeakDetection
  2537. DiagnosedApplications
  2538. SYSTEM\ControlSet001\Services
  2539. SYSTEM\ControlSet001\Services\EasyAntiCheat
  2540. SYSTEM\CurrentControlSet\Services
  2541. .DEFAULT\Software\Microsoft\SystemCertificates
  2542. TrustedPublisher
  2543. .DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher
  2544. .DEFAULT\Software\Policies\Microsoft\SystemCertificates
  2545. .DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher
  2546. S-1-5-18\Software\Microsoft\SystemCertificates
  2547. S-1-5-18\Software\Microsoft\SystemCertificates\TrustedPublisher
  2548. S-1-5-18\Software\Policies\Microsoft\SystemCertificates
  2549. SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications
  2550. FortniteClient-Win64-Shipping.exe
  2551. SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel
  2552. SYSTEM\ControlSet001\Control
  2553. Origin Client Service
  2554. Origin Web Helper Service
  2555. SOFTWARE\Classes\Applications
  2556. SOFTWARE\Respawn
  2557. SOFTWARE\WOW6432Node\Respawn
  2558. SYSTEM\Setup\FirstBoot\Services
  2559. SYSTEM\ControlSet001
  2560. Hardware Profiles
  2561. SYSTEM\CurrentControlSet\Software\Classes\Local Settings
  2562. Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache
  2563. DefaultAccount
  2564. SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Deployment\Package
  2565. SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Catalogs
  2566. SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
  2567. Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
  2568. Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
  2569. Software\Microsoft\Windows\CurrentVersion\Search\JumplistData
  2570. SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\AppIso\FirewallRules
  2571. \System\GameConfigStore
  2572. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName /v ComputerName /t REG_SZ /d I LOVE PIZZA-%random% /f
  2573. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName /v ComputerName /t REG_SZ /d I LOVE PIZZA-%random% /f
  2574. REG ADD HKLM\SYSTEM\HardwareConfig /v LastConfig /t REG_SZ /d {I LOVE PIZZA-%random%} /f
  2575. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v HwProfileGuid /t REG_SZ /d {I LOVE PIZZA-%random%-%random%-%random%-%random%} /f
  2576. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v GUID /t REG_SZ /d {I LOVE PIZZA-%random%-%random%-%random%-%random%} /f
  2577. REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d I LOVE PIZZA-%random% /f
  2578. REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOwner /t REG_SZ /d I LOVE PIZZA-%random% /f
  2579. REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOrganization /t REG_SZ /d I LOVE PIZZA-%random% /f
  2580. REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d %random%-%random%-%random%-%random% /f
  2581. REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d %random%-%random%-%random%-%random% /f
  2582. REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v ProductId /t REG_SZ /d %random%-%random%-%random%-%random% /f
  2583. REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_SZ /d %random% /f
  2584. REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {%random%-%random%-%random%-%random%} /f
  2585. REG ADD HKLM\HARDWARE\DESCRIPTION\System\BIOS /v SystemSKU /t REG_SZ /d I LOVE PIZZA-%random%-%random% /f
  2586. REG ADD HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\1 /v ProcessorNameString /t REG_SZ /d %random%-%random% /f
  2587. REG ADD HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\2 /v ProcessorNameString /t REG_SZ /d %random%-%random% /f
  2588. REG ADD HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\3 /v ProcessorNameString /t REG_SZ /d %random%-%random% /f
  2589. REG ADD HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0 /v ProcessorNameString /t REG_SZ /d %random%-%random% /f
  2590. REG ADD "HKEY_CURRENT_USER\Software\Epic Games"
  2591. REG ADD "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine"
  2592. REG ADD "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Identifiers"
  2593. reg delete "HKEY_LOCAL_MACHINE\Software\Epic Games" / f
  2594. reg delete "HKEY_CURRENT_USER\Software\Epic Games" /f
  2595. REG ADD "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Identifiers" /v AccountId /t REG_SZ /d %random%-%random%-%random%-%random% /f
  2596. REG ADD "HKEY_CURRENT_USER\Software\Epic Games\Unreal Engine\Identifiers" /v Machineid /t REG_SZ /d %random%-%random%-%random%-%random% /f
  2597. REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0000" /v NetCfgInstanceId /t REG_SZ /d {%random%-%random%-%random%-%random%} /f
  2598. REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0000" /v MatchingDeviceId /t REG_SZ /d {%random%-%random%-%random%-%random%} /f
  2599. http://clients3.google.com/generate_204
  2600. UrMomIsfuckingGay
  2601. @1B2c3D4e5F6g7H8
  2602. \Documents\My Games
  2603. \AppData\Local\BattlEye\r6s
  2604. \Pictures\Uplay
  2605. \AppData\Local\Ubisoft Game Launcher
  2606. C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\logs
  2607. C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\cache
  2608. C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\crashes
  2609. SOFTWARE\Microsoft\Windows NT\CurrentVersion\DefaultProductKey
  2610. Software\Microsoft
  2611. war nicht im zul
  2612. ssigen Bereich! (BitNumber = (min)0 - (max)7)
  2613. Win32_NetworkAdapterConfiguration
  2614. SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\
  2615. NetworkAddress
  2616. backgroundTaskHost
  2617. NVDisplay.Container
  2618. ShellExperienceHost
  2619. obs-ffmpeg-mux
  2620. OBS Studio (64bit)
  2621. Failed to grab WMI data
  2622. C:\Windows\System32\config\DRIVERS.
  2623. Your drivers File is corrupted
  2624. Your Subscribtion expires on
  2625. [1] Spoof BE (Diskdrive/ Bios/ Baseboard/ UUID)
  2626. [2] Spoof EAC (Diskdrive/ Bios/ Baseboard/ UUID)
  2627. [3] Unspoof Baseboard/ BIOS (Only, when used EAC Spoof)
  2628. [4] Leight Cleaner for r6s
  2629. [4] Spoof Network
  2630. [5] Clean Files/ Registry
  2631. sc stop winmgmt
  2632. C:\Windows\System32\wbem\repository
  2633. sc start winmgmt
  2634. wmic diskdrive get serialnumber
  2635. Spoofing Baseboard/ BIOS/ UUID...
  2636. BaseBoard and Bios might need some minutes
  2637. wmic path win32_networkadapter where PhysicalAdapter=True call disable
  2638. wmic path win32_networkadapter where PhysicalAdapter=True call enable
  2639. SELECT * FROM Win32_NetworkAdapter
  2640. Spoofing Mac...
  2641. SETLOCAL ENABLEDELAYEDEXPANSION
  2642. SETLOCAL ENABLEEXTENSIONS
  2643. FOR /F "tokens=1" %%a IN ('wmic nic where physicaladapter^=true get deviceid ^| findstr [0-9]') DO (
  2644. CALL :MAC
  2645. FOR %%b IN (0 00 000) DO (
  2646. REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\%%b%%a >NUL 2>NUL && REG ADD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\%%b%%a /v NetworkAddress /t REG_SZ /d !MAC! /f >NUL 2>NUL
  2647. )
  2648. )
  2649. FOR /F "tokens=1" %%a IN ('wmic nic where physicaladapter^=true get deviceid ^| findstr [0-9]') DO (
  2650. FOR %%b IN (0 00 000) DO (
  2651. REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\%%b%%a >NUL 2>NUL && REG ADD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\%%b%%a /v PnPCapabilities /t REG_DWORD /d 24 /f >NUL 2>NUL
  2652. )
  2653. )
  2654. FOR /F "tokens=2 delims=, skip=2" %%a IN ('"wmic nic where (netconnectionid like '%%') get netconnectionid,netconnectionstatus /format:csv"') DO (
  2655. netsh interface set interface name="%%a" disable >NUL 2>NUL
  2656. netsh interface set interface name="%%a" enable >NUL 2>NUL
  2657. )
  2658. GOTO :EOF
  2659. :MAC
  2660. SET COUNT=0
  2661. SET GEN=ABCDEF0123456789
  2662. SET GEN2=26AE
  2663. SET MAC=
  2664. :MACLOOP
  2665. SET /a COUNT+=1
  2666. SET RND=%random%
  2667. ::%%n,
  2668. SET /A RND=RND%%16
  2669. SET RNDGEN=!GEN:~%RND%,1!
  2670. SET /A RND2=RND%%4
  2671. SET RNDGEN2=!GEN2:~%RND2%,1!
  2672. IF "!COUNT!" EQU "2" (SET MAC=!MAC!!RNDGEN2!) ELSE (SET MAC=!MAC!!RNDGEN!)
  2673. IF !COUNT! LEQ 11 GOTO MACLOOP
  2674.  
  2675. C:\Program Files\Windows Photo Viewer\mac.bat
  2676. Cleaning System...
  2677. Error: 111 (Contact I LOVE PIZZA#6740)
  2678. Error: 111111 (Contact I LOVE PIZZA#6740)
  2679. Cleaning Registry...
  2680. Error: 112 (Contact I LOVE PIZZA#6740)
  2681. SELECT * FROM Win32_BaseBoard
  2682. SELECT * FROM Win32_ComputerSystemProduct
  2683. SELECT * FROM Win32_Processor
  2684. \AppData\Roaming\Microsoft\BaseBoard.dll
  2685. \AppData\Roaming\Microsoft\UUID.dll
  2686. \AppData\Roaming\Microsoft\Processor.dll
  2687. SELECT * FROM Win32_BIOS
  2688. C:\Windows\AMIDEWINx64.exe
  2689. [+] Failed to download a File
  2690. C:\Windows\amifldrv64.sys
  2691. C:\Windows\AMIDEWINx64.exe /SS
  2692. C:\Windows\AMIDEWINx64.exe /SU
  2693. C:\Windows\AMIDEWINx64.exe /BS
  2694. C:\Windows\AMIDEWINx64.exe /BSH
  2695. C:\Windows\AMIDEWINx64.exe /PSN
  2696. C:\Windows\Speech\EcXm42Tkyp.sys
  2697. ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789abcdefghijklmopqrstuvwxyz
  2698. C:\Windows\AMIDEWINx64.exe /SU auto
  2699. C:\Windows\AMIDEWINx64.exe /CS
  2700. C:\Windows\AMIDEWINx64.exe /CSH
  2701. C:\devcon.exe /r remove =net
  2702. C:\devcon.exe rescan
  2703. && TIMEOUT 10"
  2704. C:\Program Files\WindowsApps
  2705. C:\Program Files (x86)\Progress\JustDecompile
  2706. C:\Windows\servicing\LCU
  2707. /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO Sanboxie, VM Or Emulation Detected! && TIMEOUT 10"
  2708. SELECT * FROM Win32_VideoController
  2709. /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO Run as Admin! && TIMEOUT 10"
  2710. C:\Windows\explorer.exe
  2711. vp5wsKKVVUdZoqyQs80hPApD3keP9BV1MQ1O1DPUJgvTK
  2712. [+] Main Menu:
  2713.  
  2714. Do you want to remove auto login? [Y][N]
  2715. Newtonsoft.Json.dll
  2716. 4df6c8781e70c3a4912b5be796e6d337
  2717. TrinitySeal.dll
  2718. 0ac32b36f97427f59bd8e179c2594d95
  2719. /c START CMD /C "COLOR C && TITLE Pizza Protection && ECHO File Tampering Detected! && TIMEOUT 10"
  2720. WrapNonExceptionThrows
  2721. Nemesis-76523
  2722. Nemesis-76523 2019
  2723. $9af2bc0b-b116-4e19-9cf2-8ed7463c2ecb
  2724. .NETFramework,Version=v4.7.2
  2725. FrameworkDisplayName
  2726. .NET Framework 4.7.2
  2727. VS_VERSION_INFO
  2728. StringFileInfo
  2729. FileDescription
  2730. LegalCopyright
  2731. Nemesis-76523 2019
  2732. LegalTrademarks
  2733. OriginalFilename
  2734. ProductVersion
  2735. Assembly Version
  2736. <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
  2737.  
  2738. <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
  2739. <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
  2740. <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
  2741. <security>
  2742. <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
  2743. <requestedExecutionLevel level="asInvoker" uiAccess="false"/>
  2744. </requestedPrivileges>
  2745. </security>
  2746. </trustInfo>
  2747. </assembly>
  2748.  
  2749. --------------------------------------------------
  2750. Finished in 3.25834 seconds.
  2751.  
  2752. --------------------
  2753. Files
  2754. --------------------
  2755. 9d123.sys : https://cdn.discordapp.com/attachments/619316777326870530/619323747052027964/9d123.sys
  2756. Dibbu.sys : https://cdn.discordapp.com/attachments/619316777326870530/619323878052724736/Dibbu.sys
  2757. Cheat.dll : https://cdn.discordapp.com/attachments/619316777326870530/619324185969295380/cheat_1.dll
  2758. Rand.sys : https://cdn.discordapp.com/attachments/619316777326870530/619324317531897886/Rand.sys
  2759. Mappi.exe : https://cdn.discordapp.com/attachments/619316777326870530/619343977199566858/Mappi.exe
  2760. Epic.dll : https://cdn.discordapp.com/attachments/619316777326870530/619344123710930954/Epic_1.dll
  2761. Mac.exe : https://cdn.discordapp.com/attachments/619316777326870530/619344274705874945/Mac_1.exe
  2762. Adapt.exe : https://cdn.discordapp.com/attachments/619316777326870530/619344345987940352/Adapt.exe
  2763. WMI.bat : https://cdn.discordapp.com/attachments/619316777326870530/619344432369762324/WMI_1.bat
  2764.  
  2765. -------
  2766. Usage
  2767. -------
  2768. I dont know how those are used, but most of them are public so you can find "docs" on it
Add Comment
Please, Sign In to add comment