content copied
content
Start::
SystemRestore: On
CreateRestorePoint:
CloseProcesses:
C:\Users\kumar\AppData\Local\Qualcomm
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-3052480637-688437526-2025535754-1001_Classes\CLSID\{c3d69995-0472-1abf-3763-f2b143b5fb29}\localserver32 -> "C:\ProgramData\Samsung\SamsungMultiControl\Package\SamsungMultiControlHelper.exe" -ToastActivated => No File
AlternateDataStreams: C:\Users\kumar\Downloads\FRST64.exe:MBAM.Zone.Identifier [450]
FirewallRules: [{65EB5809-4637-409D-A9F0-9A34824FAFC6}] => (Allow) D:\Apps\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{7BCAFF22-6673-4FEA-B780-983318A1A9C5}] => (Allow) D:\Apps\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{953CB6E2-B565-44C8-9748-4E94D7269FF0}] => (Allow) C:\ProgramData\Samsung\SamsungMultiControl\Package\SamsungMultiControl.exe => No File
FirewallRules: [{5E138161-019D-4581-B9D6-108D32EF3F22}] => (Allow) D:\Apps\Steam\steamapps\common\Break a Leg\BreakaLeg\BreakALeg.exe => No File
FirewallRules: [{73AA9B83-33CF-4F86-A43F-C21691DCB065}] => (Allow) D:\Apps\Steam\steamapps\common\Break a Leg\BreakaLeg\BreakALeg.exe => No File
FirewallRules: [{A392576B-5C24-4628-B39B-81000DA05EC1}] => (Allow) D:\Apps\Steam\steamapps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe => No File
FirewallRules: [{90A33697-0882-4B13-91E4-74091D0DD8B5}] => (Allow) D:\Apps\Steam\steamapps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe => No File
FirewallRules: [{9B68FDBC-7CC6-4BA7-B622-A1CC5C244C4F}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\ElementsPanelDaemon.exe => No File
FirewallRules: [{B0CF8F1B-CE50-4F66-982B-73F716969683}] => (Allow) C:\Program Files (x86)\BlueStacks X\BlueStacksWeb.exe => No File
FirewallRules: [{59E2CBBA-89F9-47B0-A04B-128EB9D38FC1}] => (Allow) C:\Program Files (x86)\BlueStacks X\Cloud Game.exe => No File
FirewallRules: [{DF74E324-48E4-4398-92DA-D836310E0D59}] => (Allow) C:\Program Files\BlueStacks_nxt\HD-Player.exe => No File
FirewallRules: [{41F4CD11-04AC-4745-B4FD-492D71E721A0}] => (Allow) C:\Program Files\BlueStacks_nxt\BlueStacksAppplayerWeb.exe => No File
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {8E8EE474-BA61-4250-B175-F39D37EBEC07} - System32\Tasks\Microsoft\Windows\PI\SecureBootEncodeUEFI => %WINDIR%\system32\SecureBootEncodeUEFI.exe (No File)
Task: {0BB36A32-0D9E-4297-AFD7-6BD7B5DB4C9B} - System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr => %windir%\System32\UNP\UpdateNotificationMgr.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
S2 ET05A1EvtSvc; %SystemRoot%\System32\Rundll32.exe C:\WINDOWS\System32\drivers\UMDF\EgisTouchFPEventLog05A1.dll,Rundll32EntryPointW (No File)
S2 SmartThingsService; "C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SmartThingsWindows_1.22521.0.0_x64__3c1yjt4zspk6g\SmartThingsService\SmartThingsService.exe" (No File)
2026-07-26 14:29 - 2026-07-27 23:48 - 000095884 _____ C:\Users\kumar\AppData\LocalLow\5d9719002be2068ce9885bb8d170b43a7bd72defaae1a7b95f1b3692c69c3119
2026-07-26 14:29 - 2026-07-26 14:29 - 000000026 _____ C:\Users\kumar\AppData\LocalLow\219e8b429a2e9a10bc2bb8ff2606bd6e99899b3a7b05345aedf13291e924313c
2026-07-25 15:52 - 2026-07-25 15:52 - 000017730 _____ C:\Users\kumar\AppData\LocalLow\5a3bd1862597d79bc4069c21497197250295c1c879009ee9210c98384f06eaa1
2026-07-25 15:52 - 2026-07-25 15:52 - 000000026 _____ C:\Users\kumar\AppData\LocalLow\33c19af634bd05f68ca3e11de70fa9347050eb01b3671331e4148f646481fe66
2026-07-23 11:53 - 2026-07-23 11:53 - 000290557 _____ C:\Users\kumar\AppData\LocalLow\cf512c707d81988f5e68ece8aceab6094711c2db35cc2517223a5becfd8d224b
2026-07-23 11:53 - 2026-07-23 11:53 - 000000026 _____ C:\Users\kumar\AppData\LocalLow\67b8c0f30ace3eafb827a1cad29dfad12466140d24d3c2f9291fbe84545dfd8f
2026-07-06 20:28 - 2026-07-06 20:28 - 000002264 _____ C:\Users\kumar\AppData\LocalLow\6657b3f5cb146fc70a05895703e58150a7f409b6d800de8e220b9a2ed6577a6d
2026-07-06 20:26 - 2026-07-06 20:32 - 000333987 _____ C:\Users\kumar\AppData\LocalLow\1bf4897ea7c351f2b05c15541ac1a0169af9a34ddaff18b74531afdb4f28ab47
2026-07-06 20:26 - 2026-07-06 20:26 - 000000026 _____ C:\Users\kumar\AppData\LocalLow\97efb0a2e8fb891ad4a1ff234a5278106ced58c0e4e9ab91d4ddeb400601787e
2026-07-26 14:58 - 2026-02-27 20:53 - 000093794 _____ C:\Users\kumar\AppData\LocalLow\71f0008ccd3814e684738b999a1498aae61d2024c7f118fc128d713b0948ea49
2026-07-26 13:00 - 2026-03-01 12:26 - 000000026 _____ C:\Users\kumar\AppData\LocalLow\e79aa2138b5746240cbf112e771d7348226fcc9090021808250fc443db9e6c1c
2026-06-29 00:44 - 2026-02-27 20:53 - 000153114 _____ C:\Users\kumar\AppData\LocalLow\7bfdd2079cc83f1cc34980a8e67011f48337a3ba8e95b3828e5e510423950d1a
2026-06-29 00:10 - 2026-02-27 20:53 - 000004502 _____ C:\Users\kumar\AppData\LocalLow\1a20e1f2636d0a427698b0ccd59bda74ffd92d821e5682a5b71cc23d0940850e
2026-06-28 18:18 - 2026-02-27 20:56 - 000095042 _____ C:\Users\kumar\AppData\LocalLow\65ab9bb7909ee7e36547098d6082ee1f4794b1921b1224fc26aa264b0f932812
StartPowerShell:
#Requires -Version 5.1
$ProductCodes = @(
'{2806F34E-16BA-41BC-AA3C-5134B3D49A9D}'
)
$DoComSweep = $false
$DoRawSweep = $false
$DoNameSweep = $false
$ErrorActionPreference = 'SilentlyContinue'
$ProgressPreference = 'SilentlyContinue'
$script:SW = [Diagnostics.Stopwatch]::StartNew()
function W { param([string]$s = '') Write-Output $s }
function H {
param([string]$t)
W ''
W ('-' * 100)
W ('{0} [+{1:N1}s]' -f $t, $script:SW.Elapsed.TotalSeconds)
W ('-' * 100)
}
function KV {
param([string]$k, $v)
if ($null -eq $v -or "$v" -eq '') { $v = '<none>' }
W (' {0,-24} {1}' -f $k, $v)
}
function Pack {
param([string]$g)
$x = ($g -replace '[{}\-\s]', '').ToUpper()
if ($x.Length -ne 32) { throw "bad guid: $g" }
$o = -join $x[7..0]
$o += -join $x[11..8]
$o += -join $x[15..12]
for ($i = 16; $i -lt 32; $i += 2) { $o += $x[$i + 1] + $x[$i] }
$o
}
function Native {
param([string]$p)
$p -replace '^HKLM:\\', 'HKLM\' -replace '^HKCU:\\', 'HKCU\' `
-replace '^HKCR:\\', 'HKCR\' -replace '^HKU:\\', 'HKU\'
}
function DumpKey {
param([string]$Path, [string]$Label = '')
if (-not (Test-Path -LiteralPath $Path)) { return }
W (Native $Path)
if ($Label) { W " [$Label]" }
$p = Get-ItemProperty -LiteralPath $Path
$names = @($p.PSObject.Properties.Name | Where-Object { $_ -notlike 'PS*' } | Sort-Object)
if ($names.Count -eq 0) { W ' <no values>' }
foreach ($n in $names) {
$v = $p.$n
if ($v -is [byte[]]) {
if ($v.Length -gt 64) {
$v = (($v[0..63] | ForEach-Object { $_.ToString('x2') }) -join '') + "... ($($v.Length) bytes)"
} else {
$v = ($v | ForEach-Object { $_.ToString('x2') }) -join ''
}
}
elseif ($v -is [array]) { $v = $v -join ' ; ' }
KV $n $v
}
W ''
}
function MsiTable {
param([string]$Path, [string]$Query)
try {
$i = New-Object -ComObject WindowsInstaller.Installer
$db = $i.GetType().InvokeMember('OpenDatabase', 'InvokeMethod', $null, $i, @($Path, 0))
$v = $db.GetType().InvokeMember('OpenView', 'InvokeMethod', $null, $db, @($Query))
$v.GetType().InvokeMember('Execute', 'InvokeMethod', $null, $v, $null)
while ($r = $v.GetType().InvokeMember('Fetch', 'InvokeMethod', $null, $v, $null)) {
$n = $r.GetType().InvokeMember('FieldCount', 'GetProperty', $null, $r, $null)
, @(for ($k = 1; $k -le $n; $k++) {
$r.GetType().InvokeMember('StringData', 'GetProperty', $null, $r, $k)
})
}
$v.GetType().InvokeMember('Close', 'InvokeMethod', $null, $v, $null)
[void][Runtime.InteropServices.Marshal]::ReleaseComObject($i)
} catch { }
}
function RootToHive {
param($r)
switch ("$r") {
'-1' { 'HKMU' } '0' { 'HKCR' } '1' { 'HKCU' } '2' { 'HKLM' } '3' { 'HKU' }
default { "root$r" }
}
}
function KeyPathPrefixToHive {
param([string]$p)
switch ($p) {
'00' { 'HKCR' } '01' { 'HKCU' } '02' { 'HKLM' } '03' { 'HKU' }
'20' { 'HKLM(64)' } '21' { 'HKCU(64)' } '22' { 'HKLM(64)' } '23' { 'HKU(64)' }
default { "root$p" }
}
}
$HKLM = [Microsoft.Win32.RegistryHive]::LocalMachine
$HKCU = [Microsoft.Win32.RegistryHive]::CurrentUser
$V64 = [Microsoft.Win32.RegistryView]::Registry64
$V32 = [Microsoft.Win32.RegistryView]::Registry32
function OpenBase {
param($Hive, $View)
[Microsoft.Win32.RegistryKey]::OpenBaseKey($Hive, $View)
}
$script:SysDirs = @(
"$env:SystemRoot", "$env:SystemRoot\System32", "$env:SystemRoot\SysWOW64",
"$env:SystemRoot\System32\drivers", "$env:SystemRoot\System32\wbem",
"$env:SystemRoot\WinSxS", "$env:SystemRoot\assembly",
"$env:ProgramData", "$env:ProgramData\Microsoft",
"$env:ProgramFiles", "${env:ProgramFiles(x86)}",
"$env:ProgramFiles\Common Files", "${env:ProgramFiles(x86)}\Common Files",
"$env:ProgramFiles\Common Files\Microsoft Shared", "${env:ProgramFiles(x86)}\Common Files\Microsoft Shared",
"$env:LOCALAPPDATA", "$env:LOCALAPPDATA\Programs", "$env:APPDATA",
"$env:USERPROFILE", 'C:\'
) | Where-Object { $_ } | ForEach-Object { $_.TrimEnd('\').ToLower() }
function Normalize-Path {
param([string]$p)
if ([string]::IsNullOrWhiteSpace($p)) { return $null }
$s = $p.Trim()
if ($s.StartsWith('"')) {
$e = $s.IndexOf('"', 1)
if ($e -gt 0) { $s = $s.Substring(1, $e - 1) } else { $s = $s.Trim('"') }
} else {
$m = [regex]::Match($s, '\s+[-/]')
if ($m.Success) { $s = $s.Substring(0, $m.Index) }
}
$s = [Environment]::ExpandEnvironmentVariables($s)
$s = ($s -replace '^\\\?\?\\', '' -replace '^@', '').Trim()
if ($s -match '^[A-Za-z]:\\') { return $s.TrimEnd('\').ToLower() }
if ($s -match '^[^\\/:*?"<>|]+\.(dll|exe|ocx|cpl|sys)$') { return $s.ToLower() }
return $null
}
$script:OwnPaths = $null
$script:OwnNames = $null
$script:OwnDirs = @()
function Test-Own {
param([string]$c)
$n = Normalize-Path $c
if (-not $n) { return $false }
if ($script:OwnPaths.Contains($n)) { return $true }
foreach ($d in $script:OwnDirs) { if ($n.StartsWith($d + '\')) { return $true } }
if ($n -notmatch '\\' -and $script:OwnNames.Contains($n)) { return $true }
return $false
}
function Get-FileFacts {
param([string]$Path)
if (-not (Test-Path -LiteralPath $Path -PathType Leaf)) { return $null }
$fi = Get-Item -LiteralPath $Path
$vi = $fi.VersionInfo
$sig = Get-AuthenticodeSignature -LiteralPath $Path
[PSCustomObject]@{
Size = $fi.Length
Created = $fi.CreationTime.ToString('yyyy-MM-dd HH:mm:ss')
Modified = $fi.LastWriteTime.ToString('yyyy-MM-dd HH:mm:ss')
Company = $vi.CompanyName
Product = $vi.ProductName
OrigName = $vi.OriginalFilename
IntName = $vi.InternalName
FileVer = $vi.FileVersion
Desc = $vi.FileDescription
SigStatus = "$($sig.Status)"
Signer = $(if ($sig.SignerCertificate) { $sig.SignerCertificate.Subject })
SHA256 = (Get-FileHash -LiteralPath $Path -Algorithm SHA256).Hash
}
}
W ('=' * 100)
W ('MSI REGISTRATION FOOTPRINT {0}' -f (Get-Date -Format 'yyyy-MM-dd HH:mm:ss'))
W ('HOST {0} USER {1}' -f $env:COMPUTERNAME, $env:USERNAME)
W ('OS {0}' -f (Get-CimInstance Win32_OperatingSystem).Caption)
W ('ELEVATED {0}' -f (New-Object Security.Principal.WindowsPrincipal(
[Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole(
[Security.Principal.WindowsBuiltInRole]::Administrator))
W ('SWEEPS com={0} raw={1} name={2}' -f $DoComSweep, $DoRawSweep, $DoNameSweep)
W ('=' * 100)
foreach ($pc in $ProductCodes) {
$packed = Pack $pc
$shortPc = ($pc -replace '[{}]', '')
$script:OwnPaths = New-Object 'System.Collections.Generic.HashSet[string]'
$script:OwnNames = New-Object 'System.Collections.Generic.HashSet[string]'
$script:OwnDirs = @()
$localPkg = $null
$installLoc = $null
$publisher = $null
$displayName = $null
$compFiles = New-Object System.Collections.ArrayList
$compRegs = New-Object System.Collections.ArrayList
$touchedKeys = New-Object System.Collections.ArrayList
W ''
W ('=' * 100)
W "PRODUCTCODE $pc"
W "PACKED $packed"
W ('=' * 100)
H '1. UNINSTALL / ARP'
$found = $false
foreach ($k in @(
"HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$pc",
"HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\$pc",
"HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$pc")) {
if (-not (Test-Path -LiteralPath $k)) { continue }
$found = $true
[void]$touchedKeys.Add((Native $k))
DumpKey $k
$p = Get-ItemProperty -LiteralPath $k
if (-not $displayName) { $displayName = $p.DisplayName }
if (-not $publisher) { $publisher = $p.Publisher }
if (-not $installLoc) { $installLoc = $p.InstallLocation }
if (-not $installLoc -and $p.DisplayIcon) {
$ic = ($p.DisplayIcon -split ',')[0].Trim('"')
if ($ic -match '\\') { $installLoc = Split-Path $ic -Parent }
}
}
if (-not $found) { W '<none>' }
H '2. INSTALLER BRANCH'
$roots = @(
"HKLM:\SOFTWARE\Classes\Installer\Products\$packed",
"HKLM:\SOFTWARE\Classes\Installer\Features\$packed",
"HKLM:\SOFTWARE\Classes\Installer\Patches\$packed"
)
$bk = OpenBase $HKLM $V64
$ud = $bk.OpenSubKey('SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData')
if ($ud) {
foreach ($sid in $ud.GetSubKeyNames()) {
$roots += "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\$sid\Products\$packed"
}
$ud.Close()
}
$bk.Close()
$found = $false
foreach ($r in ($roots | Sort-Object -Unique)) {
if (-not (Test-Path -LiteralPath $r)) { continue }
$found = $true
[void]$touchedKeys.Add((Native $r))
foreach ($sub in @('', '\InstallProperties', '\SourceList', '\SourceList\Net',
'\SourceList\Media', '\Usage', '\Features', '\Patches')) {
DumpKey "$r$sub" $sub.TrimStart('\')
}
$ip = Get-ItemProperty -LiteralPath "$r\InstallProperties"
if ($ip) {
if (-not $localPkg) { $localPkg = $ip.LocalPackage }
if (-not $installLoc) { $installLoc = $ip.InstallLocation }
if (-not $publisher) { $publisher = $ip.Publisher }
if (-not $displayName) { $displayName = $ip.DisplayName }
}
}
if (-not $found) { W '<none>' }
W ''
W 'RESOLVED:'
KV 'DisplayName' $displayName
KV 'Publisher' $publisher
KV 'InstallLocation' $installLoc
KV 'LocalPackage' $localPkg
H '3. UPGRADECODE MEMBERSHIP'
$found = $false
foreach ($cfg in @(
@{ Path = 'SOFTWARE\Classes\Installer\UpgradeCodes'; Label = 'HKLM\SOFTWARE\Classes\Installer\UpgradeCodes' },
@{ Path = 'SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes'; Label = 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes' })) {
$bk = OpenBase $HKLM $V64
$root = $bk.OpenSubKey($cfg.Path)
if ($root) {
foreach ($sub in $root.GetSubKeyNames()) {
$k = $root.OpenSubKey($sub)
if (-not $k) { continue }
if ($k.GetValueNames() -contains $packed) {
$found = $true
W ('{0}\{1}' -f $cfg.Label, $sub)
KV 'upgradecode (packed)' $sub
KV 'member value' $k.GetValue($packed)
W ''
}
$k.Close()
}
$root.Close()
}
$bk.Close()
}
if (-not $found) { W '<none>' }
H '4. COMPONENT REGISTRATION'
$found = $false
$dirCand = New-Object System.Collections.ArrayList
foreach ($cfg in @(
@{ Path = 'SOFTWARE\Classes\Installer\Components'; Label = 'HKLM\SOFTWARE\Classes\Installer\Components' },
@{ Path = 'SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components'; Label = 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components' })) {
$bk = OpenBase $HKLM $V64
$root = $bk.OpenSubKey($cfg.Path)
if ($root) {
foreach ($sub in $root.GetSubKeyNames()) {
$k = $root.OpenSubKey($sub)
if (-not $k) { continue }
$vn = $k.GetValueNames()
if ($vn -contains $packed) {
$found = $true
$val = "$($k.GetValue($packed))"
W ('{0}\{1}' -f $cfg.Label, $sub)
KV 'componentid' $sub
KV 'keypath' $val
$shared = @($vn | Where-Object { $_ -and $_ -ne $packed })
if ($shared.Count) { KV 'shared with' ($shared -join ', ') }
W ''
if ($val -match '^\d{2}:') {
[void]$compRegs.Add($val)
} elseif ($val -match '^[A-Za-z]:\\') {
[void]$compFiles.Add($val)
$n = Normalize-Path $val
if ($n) {
[void]$script:OwnPaths.Add($n)
[void]$script:OwnNames.Add([IO.Path]::GetFileName($n))
[void]$dirCand.Add((Split-Path $n -Parent))
}
}
}
$k.Close()
}
$root.Close()
}
$bk.Close()
}
if (-not $found) { W '<none>' }
if ($installLoc -and (Test-Path -LiteralPath $installLoc)) {
$il = $installLoc.TrimEnd('\').ToLower()
if ($script:SysDirs -notcontains $il) {
[void]$dirCand.Add($il)
Get-ChildItem -LiteralPath $installLoc -Recurse -File | ForEach-Object {
[void]$script:OwnPaths.Add($_.FullName.ToLower())
[void]$script:OwnNames.Add($_.Name.ToLower())
}
}
}
$script:OwnDirs = @($dirCand | Where-Object { $_ } | Sort-Object -Unique |
Where-Object { $script:SysDirs -notcontains $_ -and $_.Split('\').Count -ge 3 })
H '5. MSI DATABASE (cached package)'
if ($localPkg -and (Test-Path -LiteralPath $localPkg)) {
KV 'package' $localPkg
$pf = Get-FileFacts $localPkg
if ($pf) {
KV 'size' $pf.Size
KV 'created' $pf.Created
KV 'modified' $pf.Modified
KV 'sha256' $pf.SHA256
}
W ''
W '[Property]'
MsiTable $localPkg 'SELECT Property, Value FROM Property' |
ForEach-Object { W (' {0,-30} {1}' -f $_[0], $_[1]) }
W ''
W '[Registry] msi row -> live registry state'
$rows = @(MsiTable $localPkg 'SELECT Root, Key, Name, Value, Component_ FROM Registry')
if ($rows.Count -eq 0) { W ' <empty or unreadable>' }
foreach ($row in $rows) {
$hive = RootToHive $row[0]
$key = $row[1]
$name = $row[2]
$cands = switch ($hive) {
'HKLM' { @("HKLM:\SOFTWARE\$key", "HKLM:\SOFTWARE\WOW6432Node\$key", "HKLM:\$key") }
'HKMU' { @("HKLM:\SOFTWARE\$key", "HKLM:\SOFTWARE\WOW6432Node\$key",
"HKCU:\SOFTWARE\$key", "HKLM:\$key") }
'HKCU' { @("HKCU:\SOFTWARE\$key", "HKCU:\$key") }
'HKCR' { @("HKLM:\SOFTWARE\Classes\$key", "HKLM:\SOFTWARE\Classes\WOW6432Node\$key",
"HKCU:\SOFTWARE\Classes\$key") }
default { @("HKLM:\$key") }
}
$hitPath = $null
$hitVal = $null
foreach ($lp in $cands) {
if (Test-Path -LiteralPath $lp) {
$hitPath = Native $lp
if ($name) {
$lv = (Get-ItemProperty -LiteralPath $lp).$name
if ($null -ne $lv) { $hitVal = "$lv" }
}
break
}
}
W (' {0} {1}\{2}' -f $(if ($hitPath) { 'PRESENT' } else { 'ABSENT ' }), $hive, $key)
if ($name) { KV ' value name' $name }
KV ' msi value' $row[3]
if ($hitPath) {
KV ' live key' $hitPath
if ($name) { KV ' live value' $hitVal }
}
KV ' component' $row[4]
}
W ''
W '[Class]'
$cls = @(MsiTable $localPkg 'SELECT CLSID, Context, Component_, ProgId_Default, Description FROM Class')
if ($cls.Count -eq 0) { W ' <none>' }
foreach ($c in $cls) {
W (' {0} ctx={1} comp={2} progid={3} {4}' -f $c[0], $c[1], $c[2], $c[3], $c[4])
foreach ($lp in @("HKLM:\SOFTWARE\Classes\CLSID\$($c[0])",
"HKLM:\SOFTWARE\Classes\WOW6432Node\CLSID\$($c[0])",
"HKCU:\SOFTWARE\Classes\CLSID\$($c[0])")) {
if (-not (Test-Path -LiteralPath $lp)) { continue }
W (' LIVE {0}' -f (Native $lp))
foreach ($srv in @('InprocServer32', 'LocalServer32', 'InprocHandler32')) {
if (Test-Path -LiteralPath "$lp\$srv") {
W (' {0} = {1}' -f $srv, "$((Get-ItemProperty -LiteralPath "$lp\$srv").'(default)')")
}
}
}
}
W ''
W '[ProgId]'
$pg = @(MsiTable $localPkg 'SELECT ProgId, Class_, Description FROM ProgId')
if ($pg.Count -eq 0) { W ' <none>' }
foreach ($g in $pg) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\$($g[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1,-40} class={2} {3}' -f $st, $g[0], $g[1], $g[2])
}
W ''
W '[TypeLib]'
$tl = @(MsiTable $localPkg 'SELECT LibID, Version, Component_, Description FROM TypeLib')
if ($tl.Count -eq 0) { W ' <none>' }
foreach ($t in $tl) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\TypeLib\$($t[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1} ver={2} comp={3} {4}' -f $st, $t[0], $t[1], $t[2], $t[3])
}
W ''
W '[Extension]'
$ex = @(MsiTable $localPkg 'SELECT Extension, Component_, ProgId_, MIME_ FROM Extension')
if ($ex.Count -eq 0) { W ' <none>' }
foreach ($e in $ex) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\.$($e[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} .{1} comp={2} progid={3} mime={4}' -f $st, $e[0], $e[1], $e[2], $e[3])
}
W ''
W '[AppId]'
$ai = @(MsiTable $localPkg 'SELECT AppId, RemoteServerName, ServiceParameters, DllSurrogate FROM AppId')
if ($ai.Count -eq 0) { W ' <none>' }
foreach ($a in $ai) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\AppID\$($a[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1} surrogate={2}' -f $st, $a[0], $a[3])
}
W ''
W '[Directory]'
MsiTable $localPkg 'SELECT Directory, Directory_Parent, DefaultDir FROM Directory' |
ForEach-Object { W (' {0,-28} parent={1,-26} {2}' -f $_[0], $_[1], $_[2]) }
W ''
W '[Component]'
MsiTable $localPkg 'SELECT Component, ComponentId, Directory_, Attributes, KeyPath FROM Component' |
ForEach-Object { W (' {0,-30} {1,-40} dir={2,-22} attr={3,-6} key={4}' -f $_[0], $_[1], $_[2], $_[3], $_[4]) }
W ''
W '[File]'
MsiTable $localPkg 'SELECT File, Component_, FileName, FileSize, Version FROM File' |
ForEach-Object { W (' {0,-40} comp={1,-30} size={2,-10} ver={3}' -f ($_[2] -split '\|')[-1], $_[1], $_[3], $_[4]) }
W ''
W '[ServiceInstall]'
$si = @(MsiTable $localPkg 'SELECT ServiceInstall, Name, DisplayName, ServiceType, StartType, LoadOrderGroup, Dependencies, StartName, Password, Arguments, Component_ FROM ServiceInstall')
if ($si.Count -eq 0) { W ' <none>' }
foreach ($s in $si) {
W (' {0} name={1} disp={2} type={3} start={4} runas={5} args={6} comp={7}' -f
$s[0], $s[1], $s[2], $s[3], $s[4], $s[7], $s[9], $s[10])
}
W ''
W '[CustomAction]'
$ca = @(MsiTable $localPkg 'SELECT Action, Type, Source, Target FROM CustomAction')
if ($ca.Count -eq 0) { W ' <none>' }
foreach ($c in $ca) { W (' {0,-36} type={1,-8} src={2,-30} target={3}' -f $c[0], $c[1], $c[2], $c[3]) }
W ''
W '[Binary]'
$bn = @(MsiTable $localPkg 'SELECT Name FROM Binary')
if ($bn.Count -eq 0) { W ' <none>' }
foreach ($b in $bn) { W (' {0}' -f $b[0]) }
W ''
W '[InstallExecuteSequence]'
MsiTable $localPkg 'SELECT Action, Condition, Sequence FROM InstallExecuteSequence' |
Sort-Object { [int]$_[2] } |
ForEach-Object { W (' {0,-6} {1,-40} {2}' -f $_[2], $_[0], $_[1]) }
W ''
W '[Shortcut]'
$sc = @(MsiTable $localPkg 'SELECT Shortcut, Directory_, Name, Target, Arguments FROM Shortcut')
if ($sc.Count -eq 0) { W ' <none>' }
foreach ($s in $sc) {
W (' {0,-28} dir={1,-22} name={2,-28} target={3} {4}' -f $s[0], $s[1], ($s[2] -split '\|')[-1], $s[3], $s[4])
}
} else {
W '<cached msi unavailable>'
KV 'LocalPackage' $localPkg
}
H '6. LIVE COM REGISTRATION'
KV 'own files' $script:OwnPaths.Count
KV 'own dirs' $(if ($script:OwnDirs.Count) { $script:OwnDirs -join ' | ' } else { '<none>' })
$ign = @($dirCand | Sort-Object -Unique | Where-Object { $script:SysDirs -contains $_ })
if ($ign.Count) { KV 'ignored sysdirs' ($ign -join ' | ') }
W ''
if (-not $DoComSweep) {
W '<skipped: DoComSweep is false>'
} elseif ($script:OwnPaths.Count -eq 0 -and $script:OwnDirs.Count -eq 0) {
W '<no product binaries to match against>'
} else {
$hits = 0
foreach ($cfg in @(
@{ Hive = $HKLM; View = $V64; Label = 'HKLM(64)' },
@{ Hive = $HKLM; View = $V32; Label = 'HKLM(32)' },
@{ Hive = $HKCU; View = $V64; Label = 'HKCU' })) {
$bk = OpenBase $cfg.Hive $cfg.View
$root = $bk.OpenSubKey('SOFTWARE\Classes\CLSID')
if ($root) {
foreach ($clsid in $root.GetSubKeyNames()) {
$ck = $root.OpenSubKey($clsid)
if (-not $ck) { continue }
$subs = $ck.GetSubKeyNames()
foreach ($srv in @('InprocServer32', 'LocalServer32', 'InprocHandler32')) {
if ($subs -notcontains $srv) { continue }
$sk = $ck.OpenSubKey($srv)
if (-not $sk) { continue }
$raw = "$($sk.GetValue(''))"
if ($raw -and (Test-Own $raw)) {
$hits++
W ('{0}\SOFTWARE\Classes\CLSID\{1}' -f $cfg.Label, $clsid)
KV 'default' "$($ck.GetValue(''))"
KV $srv $raw
$tm = $sk.GetValue('ThreadingModel')
if ($tm) { KV 'ThreadingModel' $tm }
$ap = $ck.GetValue('AppID')
if ($ap) { KV 'AppID' $ap }
foreach ($e in @('ProgID', 'VersionIndependentProgID', 'TreatAs', 'Elevation')) {
if ($subs -contains $e) {
$ek = $ck.OpenSubKey($e)
if ($ek) { KV $e "$($ek.GetValue(''))"; $ek.Close() }
}
}
W ''
}
$sk.Close()
}
$ck.Close()
}
$root.Close()
}
$bk.Close()
}
foreach ($cfg in @(
@{ Hive = $HKLM; View = $V64; Label = 'HKLM(64)' },
@{ Hive = $HKLM; View = $V32; Label = 'HKLM(32)' })) {
$bk = OpenBase $cfg.Hive $cfg.View
$root = $bk.OpenSubKey('SOFTWARE\Classes\TypeLib')
if ($root) {
foreach ($lib in $root.GetSubKeyNames()) {
$lk = $root.OpenSubKey($lib)
if (-not $lk) { continue }
foreach ($ver in $lk.GetSubKeyNames()) {
$vk = $lk.OpenSubKey($ver)
if (-not $vk) { continue }
foreach ($plat in ($vk.GetSubKeyNames() | Where-Object { $_ -match '^win(32|64)$' })) {
$pk = $vk.OpenSubKey($plat)
if (-not $pk) { continue }
$d = "$($pk.GetValue(''))"
if ($d -and (Test-Own $d)) {
$hits++
W ('{0}\SOFTWARE\Classes\TypeLib\{1}\{2}\{3}' -f $cfg.Label, $lib, $ver, $plat)
KV 'typelib' $d
W ''
}
$pk.Close()
}
$vk.Close()
}
$lk.Close()
}
$root.Close()
}
$bk.Close()
}
if ($hits -eq 0) { W '<none>' }
}
H '7. APP PATHS / REGISTERED APPLICATIONS'
if ($script:OwnPaths.Count -eq 0 -and $script:OwnDirs.Count -eq 0) {
W '<no product binaries to match against>'
} else {
$hits = 0
foreach ($ap in @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths')) {
if (-not (Test-Path -LiteralPath $ap)) { continue }
Get-ChildItem -LiteralPath $ap | ForEach-Object {
$props = Get-ItemProperty -LiteralPath $_.PSPath
$d = "$($props.'(default)')"
$path = "$($props.Path)"
if ((Test-Own $d) -or (Test-Own $path) -or
$script:OwnNames.Contains($_.PSChildName.ToLower())) {
$script:hits++
W ('{0}\{1}' -f (Native $ap), $_.PSChildName)
KV 'default' $d
if ($path) { KV 'Path' $path }
W ''
}
}
}
foreach ($ra in @('HKLM:\SOFTWARE\RegisteredApplications',
'HKCU:\SOFTWARE\RegisteredApplications')) {
if (-not (Test-Path -LiteralPath $ra)) { continue }
$p = Get-ItemProperty -LiteralPath $ra
foreach ($pr in $p.PSObject.Properties) {
if ($pr.Name -like 'PS*') { continue }
$capKey = "HKLM:\SOFTWARE\$($pr.Value)"
if (-not (Test-Path -LiteralPath $capKey)) { continue }
$cap = Get-ItemProperty -LiteralPath $capKey
if ($cap.ApplicationIcon -and (Test-Own (($cap.ApplicationIcon -split ',')[0]))) {
$script:hits++
W ('{0} :: {1} = {2}' -f (Native $ra), $pr.Name, $pr.Value)
}
}
}
if ($script:hits -eq 0) { W '<none>' }
}
H '8. RAW REGISTRY SWEEP (productcode / packed guid)'
if (-not $DoRawSweep) {
W '<skipped: DoRawSweep is false>'
} else {
foreach ($term in @($pc, $shortPc, $packed)) {
W "term: $term"
$any = $false
foreach ($hive in @('HKLM', 'HKCU', 'HKCR', 'HKU')) {
$k = & reg.exe query $hive /f "$term" /s /k 2>$null | Where-Object { $_ -match '^HK' }
$d = & reg.exe query $hive /f "$term" /s /d 2>$null | Where-Object { $_ -match '^HK' }
if ($k) { $any = $true; $k | ForEach-Object { W " [key] $_" } }
if ($d) { $any = $true; $d | ForEach-Object { W " [data] $_" } }
}
if (-not $any) { W ' <none>' }
W ''
}
}
H '9. RAW REGISTRY SWEEP (displayname / publisher / binaries)'
if (-not $DoNameSweep) {
W '<skipped: DoNameSweep is false>'
} else {
$terms = @()
if ($displayName) { $terms += $displayName }
if ($publisher) { $terms += $publisher }
$script:OwnNames | ForEach-Object { $terms += $_ }
$terms = @($terms | Where-Object { $_ -and $_.Length -ge 5 } | Sort-Object -Unique)
if ($terms.Count -eq 0) { W '<no terms>' }
foreach ($term in $terms) {
W "term: $term"
$any = $false
foreach ($hive in @('HKLM', 'HKCU')) {
$k = & reg.exe query $hive /f "$term" /s /k 2>$null | Where-Object { $_ -match '^HK' }
$d = & reg.exe query $hive /f "$term" /s /d 2>$null | Where-Object { $_ -match '^HK' }
if ($k) { $any = $true; $k | ForEach-Object { W " [key] $_" } }
if ($d) { $any = $true; $d | ForEach-Object { W " [data] $_" } }
}
if (-not $any) { W ' <none>' }
W ''
}
}
H '10. FILES'
$fl = @($compFiles | Sort-Object -Unique)
if ($installLoc -and (Test-Path -LiteralPath $installLoc)) {
Get-ChildItem -LiteralPath $installLoc -Recurse -File | ForEach-Object { $fl += $_.FullName }
}
$fl = @($fl | Sort-Object -Unique)
if ($fl.Count -eq 0) { W '<none>' }
foreach ($f in $fl) {
if (-not (Test-Path -LiteralPath $f -PathType Leaf)) { W "MISSING $f"; continue }
$ff = Get-FileFacts $f
W $f
KV 'size' $ff.Size
KV 'created' $ff.Created
KV 'modified' $ff.Modified
KV 'company' $ff.Company
KV 'product' $ff.Product
KV 'description' $ff.Desc
KV 'origname' $ff.OrigName
KV 'internal' $ff.IntName
KV 'fileversion' $ff.FileVer
KV 'signature' $ff.SigStatus
KV 'signer' $ff.Signer
KV 'sha256' $ff.SHA256
W ''
}
H '11a. FLAT - REGISTRY KEYS PRESENT'
if ($touchedKeys.Count -eq 0) { W '<none>' }
($touchedKeys | Sort-Object -Unique) | ForEach-Object { W $_ }
H '11b. FLAT - REGISTRY KEYPATHS FROM COMPONENTS'
if ($compRegs.Count -eq 0) { W '<none>' }
foreach ($r in ($compRegs | Sort-Object -Unique)) {
W ('{0}\{1}' -f (KeyPathPrefixToHive $r.Substring(0, 2)), $r.Substring(3))
}
H '11c. FLAT - FILES'
if ($fl.Count -eq 0) { W '<none>' }
$fl | ForEach-Object { W $_ }
H '11d. FLAT - DIRECTORIES'
$dl = @()
if ($installLoc) { $dl += $installLoc.TrimEnd('\') }
$fl | ForEach-Object { $dl += (Split-Path $_ -Parent) }
$dl = @($dl | Where-Object { $_ } | Sort-Object -Unique)
if ($dl.Count -eq 0) { W '<none>' }
foreach ($d in $dl) {
$ex = Test-Path -LiteralPath $d -PathType Container
$ct = ''
if ($ex) { $ct = (Get-Item -LiteralPath $d).CreationTime.ToString('yyyy-MM-dd HH:mm:ss') }
W ('{0,-8} {1,-20} {2}' -f $(if ($ex) { 'EXISTS' } else { 'MISSING' }), $ct, $d)
}
}
W ''
W ('=' * 100)
W ('END total {0:N1}s' -f $script:SW.Elapsed.TotalSeconds)
W ('=' * 100)
EndPowerShell:
StartPowerShell:
# Checks default Windows PATH entries and repairs missing ones.
$ErrorActionPreference = 'Continue'
function Expand-PlainPath {
param([string]$Entry)
return [Environment]::ExpandEnvironmentVariables($Entry).TrimEnd('\')
}
# Templates expanded once to plain paths (C:\Windows\..., C:\Users\...)
$systemDefaults = @(
(Expand-PlainPath '%SystemRoot%\system32')
(Expand-PlainPath '%SystemRoot%')
(Expand-PlainPath '%SystemRoot%\System32\Wbem')
(Expand-PlainPath '%SystemRoot%\System32\WindowsPowerShell\v1.0')
(Expand-PlainPath '%SystemRoot%\System32\OpenSSH')
)
$userDefaults = @(
(Expand-PlainPath '%USERPROFILE%\AppData\Local\Microsoft\WindowsApps')
)
function Get-NormalizedPathEntries {
param([string]$Raw)
if ([string]::IsNullOrWhiteSpace($Raw)) { return @() }
return @(
$Raw -split ';' |
Where-Object { -not [string]::IsNullOrWhiteSpace($_) } |
ForEach-Object {
[Environment]::ExpandEnvironmentVariables($_.Trim().TrimEnd('\')).ToLowerInvariant()
}
)
}
function Get-CombinedPathEntries {
$machineRaw = [Environment]::GetEnvironmentVariable('Path', 'Machine')
$userRaw = [Environment]::GetEnvironmentVariable('Path', 'User')
return Get-NormalizedPathEntries -Raw ($machineRaw + ';' + $userRaw)
}
function Test-InPath {
param(
[string]$PlainPath,
[string[]]$NormalizedEntries
)
$key = $PlainPath.TrimEnd('\').ToLowerInvariant()
return $NormalizedEntries -contains $key
}
function Add-ToPath {
param(
[string]$PlainPath,
[ValidateSet('Machine', 'User')]
[string]$Scope
)
# always store plain path, never %VAR% form
$toAdd = $PlainPath.TrimEnd('\')
$current = [Environment]::GetEnvironmentVariable('Path', $Scope)
if ([string]::IsNullOrWhiteSpace($current)) {
[Environment]::SetEnvironmentVariable('Path', $toAdd, $Scope)
return
}
$normalized = Get-NormalizedPathEntries -Raw $current
$key = $toAdd.ToLowerInvariant()
if ($normalized -contains $key) { return }
$newPath = $current.TrimEnd(';') + ';' + $toAdd
[Environment]::SetEnvironmentVariable('Path', $newPath, $Scope)
}
function Write-Result {
param(
[string]$Entry,
[string]$Status
)
$label = $Entry.PadRight(58)
Write-Output ("{0} {1}" -f $label, $Status)
}
function Repair-AndVerify {
param(
[string]$PlainPath,
[ValidateSet('Machine', 'User')]
[string]$Scope
)
if (-not (Test-Path -LiteralPath $PlainPath)) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (no folder, cannot repair)'
return 'failed'
}
if ($Scope -eq 'Machine') {
$isAdmin = ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).
IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)
if (-not $isAdmin) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (need Admin to repair)'
return 'failed'
}
}
try {
Add-ToPath -PlainPath $PlainPath -Scope $Scope
}
catch {
Write-Result -Entry $PlainPath -Status "ATTENTION !!! MISSING (repair failed: $_)"
return 'failed'
}
# re-query PATH from registry and verify plain path is present
$after = Get-CombinedPathEntries
if (Test-InPath -PlainPath $PlainPath -NormalizedEntries $after) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING -> repaired (verified)'
return 'repaired'
}
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (repair ran, still missing after re-check)'
return 'failed'
}
$combined = Get-CombinedPathEntries
$hadMissing = $false
$repairFailed = $false
$repairedList = [System.Collections.Generic.List[string]]::new()
Write-Output 'PATH CHECK'
Write-Output ('-' * 72)
foreach ($entry in $systemDefaults) {
if (Test-InPath -PlainPath $entry -NormalizedEntries $combined) {
Write-Result -Entry $entry -Status 'OK'
continue
}
$hadMissing = $true
$result = Repair-AndVerify -PlainPath $entry -Scope Machine
if ($result -eq 'repaired') {
[void]$repairedList.Add($entry)
$combined = Get-CombinedPathEntries
}
else {
$repairFailed = $true
}
}
foreach ($entry in $userDefaults) {
if (Test-InPath -PlainPath $entry -NormalizedEntries $combined) {
Write-Result -Entry $entry -Status 'OK'
continue
}
$hadMissing = $true
$result = Repair-AndVerify -PlainPath $entry -Scope User
if ($result -eq 'repaired') {
[void]$repairedList.Add($entry)
$combined = Get-CombinedPathEntries
}
else {
$repairFailed = $true
}
}
Write-Output ('-' * 72)
if (-not $hadMissing) {
Write-Output 'RESULT: all default PATH entries present'
}
elseif ($repairedList.Count -gt 0 -and -not $repairFailed) {
Write-Output "RESULT: $($repairedList.Count) missing entry/entries repaired and verified - open a new terminal"
}
elseif ($repairedList.Count -gt 0 -and $repairFailed) {
Write-Output "RESULT: $($repairedList.Count) verified, some still missing - open a new terminal / run as Admin"
}
else {
Write-Output 'RESULT: missing entries not repaired (run as Admin for System PATH)'
}
if ($repairedList.Count -gt 0) {
Write-Output ''
Write-Output 'REPAIRED:'
foreach ($item in $repairedList) {
Write-Output " $item"
}
}
if ($hadMissing -or $repairFailed) {
exit 1
}
exit 0
EndPowerShell:
StartPowerShell:
# Check for internet connection
$ErrorActionPreference = 'Continue'
$dnsServers = @(
'1.1.1.1'
'8.8.8.8'
)
$hosts = @(
'google.com'
'cloudflare.com'
'malwarebytes.com'
)
function Write-Result {
param(
[string]$Label,
[string]$Status
)
Write-Output ("{0} {1}" -f $Label.PadRight(42), $Status)
}
function Test-DnsServer {
param([string]$Server)
$pingOk = $false
try {
$pingOk = Test-Connection -ComputerName $Server -Count 1 -Quiet -ErrorAction SilentlyContinue
}
catch { }
$resolveOk = $false
try {
$result = Resolve-DnsName -Name 'google.com' -Server $Server -Type A -DnsOnly -ErrorAction Stop
$ip = ($result | Where-Object { $_.IPAddress } | Select-Object -First 1).IPAddress
if ($ip) { $resolveOk = $true }
}
catch { }
# resolve is what matters; ping may be blocked
if ($resolveOk) { return 'OK' }
if ($pingOk) { return 'FAIL' }
return 'FAIL'
}
function Test-HostReachable {
param([string]$HostName)
try {
$dns = Resolve-DnsName -Name $HostName -Type A -ErrorAction Stop
$resolvedIp = ($dns | Where-Object { $_.IPAddress } | Select-Object -First 1).IPAddress
if (-not $resolvedIp) { return 'FAIL' }
}
catch {
return 'FAIL'
}
try {
$null = Invoke-WebRequest -Uri "https://$HostName" -UseBasicParsing -TimeoutSec 10 -MaximumRedirection 5 -ErrorAction Stop
return 'OK'
}
catch {
if ($_.Exception.Response) { return 'OK' }
return 'FAIL'
}
}
$failed = 0
Write-Output 'INTERNET CHECK'
Write-Output ('-' * 72)
Write-Output 'DNS SERVERS'
foreach ($server in $dnsServers) {
$status = Test-DnsServer -Server $server
Write-Result -Label $server -Status $status
if ($status -eq 'FAIL') { $failed++ }
}
Write-Output ''
Write-Output 'HOSTS'
foreach ($h in $hosts) {
$status = Test-HostReachable -HostName $h
Write-Result -Label $h -Status $status
if ($status -eq 'FAIL') { $failed++ }
}
Write-Output ('-' * 72)
if ($failed -eq 0) {
Write-Output 'RESULT: all checks passed'
exit 0
}
Write-Output "RESULT: $failed check(s) failed"
exit 1
EndPowerShell:
StartPowershell:
# Replace /scanonly with /clean if you also want to delete items -- however, this will activate a trial license on the system, I do not recommend it
$hmpExe = "$env:TEMP\HitmanPro_x64.exe"
$logFile = "$env:TEMP\HitmanPro_ScanLog.txt"
Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing
$proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru
if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 }
Get-Content $logFile -Encoding Unicode
EndPowershell:
StartPowerShell:
# Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console
# Does not clean preinstalled objects, only PUP/Adware
# If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument
# If you would like to only scan with it, change the argument from /clean to /scan
# NOTE: For the sake of users from Asia (primarily China), do not use the clean option. It will very likely remove a lot of their important software.
New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null
Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden
$logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile
Get-Content $logFile -Encoding Unicode
Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue
EndPowerShell:
Comment: List Windows Defender properties, settings
StartPowerShell:
function Write-Section {
param([string]$Title)
Write-Host ""
Write-Host "<=== $Title ===>"
}
Write-Section "Protection Status"
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntispywareEnabled, AntivirusEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, RealTimeProtectionEnabled, IsTamperProtected, NetworkProtectionStatus | Format-List
Write-Section "Signature / Engine Versions"
Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AntivirusSignatureVersion, AntispywareSignatureVersion | Format-List
Write-Section "Preferences / Configuration"
Get-MpPreference | Select-Object PUAProtection, MAPSReporting, SubmitSamplesConsent, CheckForSignaturesBeforeRunningScan, CloudBlockLevel, EnableNetworkProtection, DisableScriptScanning, DisableArchiveScanning, DisableRemovableDriveScanning, DisableScanningNetworkFiles, DisableScanningMappedNetworkDrivesForFullScan, DisableBlockAtFirstSeen, DisableHeuristics, DisableAutoExclusions | Format-List
Write-Section "Threat Detections"
$threats = Get-MpThreatDetection
if ($threats) {
$threats | Format-Table -AutoSize
} else {
Write-Host " (no threat detections found)"
}
EndPowerShell:
Comment: List drive info, identify possible damaged drives (thanks to AdvancedSetup from Malwarebytes for parts of these)
StartPowerShell:
param(
[int]$MaxEvents = 2000
)
$GPTTypeMap = @{
'EBD0A0A2-B9E5-4433-87C0-68B6B72699C7' = 'Microsoft Basic Data'
'E3C9E316-0B5C-4DB8-817D-F92DF00215AE' = 'Microsoft Reserved (MSR)'
'DE94BBA4-06D1-4D40-A16A-BFD50179D6AC' = 'Windows Recovery Environment (WinRE)'
'C12A7328-F81F-11D2-BA4B-00A0C93EC93B' = 'EFI System Partition'
'21686148-6449-6E6F-744E-656564454649' = 'BIOS Boot Partition'
'A19D880F-05FC-4D3B-A006-743F0F84911E' = 'OEM Partition'
'5808C8AA-7E8F-42E0-85D2-E1E90434CFB3' = 'Cluster Metadata Partition'
'48465300-0000-11AA-AA11-00306543ECAC' = 'Apple HFS/HFS+'
'7C3457EF-0000-11AA-AA11-00306543ECAC' = 'Apple APFS'
'0FC63DAF-8483-4772-8E79-3D69D8477DE4' = 'Linux Filesystem'
'0657FD6D-A4AB-43C4-84E5-0933C84B4F4F' = 'Linux Swap'
'E6D6D379-F507-44C2-A23C-238F2A3DF928' = 'Linux LVM'
}
$MBRTypeMap = @{
'01'='FAT12';'04'='FAT16 <32M';'05'='Extended';'06'='FAT16';'07'='IFS/NTFS/exFAT/HPFS';'0B'='FAT32 CHS';'0C'='FAT32 LBA';'0E'='FAT16 LBA'
'0F'='Extended LBA';'82'='Linux Swap';'83'='Linux Native';'8E'='Linux LVM';'A5'='FreeBSD';'A6'='OpenBSD';'A8'='Mac OS X';'AB'='Mac OS X Boot'
'AF'='Mac OS X HFS';'EE'='EFI GPT Protective';'EF'='EFI System Partition'
}
function Get-PartitionTypeInfo {
param($Partition)
$guid = $null
if ($Partition.GptType) {
$guid = ($Partition.GptType -replace '[{}]', '').ToUpper()
}
if ([string]::IsNullOrWhiteSpace($guid) -or $guid -eq '00000000-0000-0000-0000-000000000000') {
$guid = switch ($Partition.Type) {
"System" { "C12A7328-F81F-11D2-BA4B-00A0C93EC93B" }
"Reserved" { "E3C9E316-0B5C-4DB8-817D-F92DF00215AE" }
"Basic" { "EBD0A0A2-B9E5-4433-87C0-68B6B72699C7" }
"Recovery" { "DE94BBA4-06D1-4D40-A16A-BFD50179D6AC" }
default { $null }
}
}
if ($guid) {
$name = $GPTTypeMap[$guid]
if ($name) { return "$name (GPT GUID: $($guid.ToLower()))" }
else { return "Unknown/Custom (GPT GUID: $($guid.ToLower()))" }
}
if ($Partition.MbrType) {
$code = ($Partition.MbrType.ToString() -replace '^0x', '').PadLeft(2, '0').ToUpper()
$name = $MBRTypeMap[$code]
if ($name) { return "$name (MBR code: 0x$code)" }
else { return "Unknown/Custom (MBR code: $($Partition.MbrType))" }
}
return $Partition.Type
}
function Get-DrMapping {
param([int]$MaxEvents)
$map = @{}
try {
$events = Get-WinEvent -FilterHashtable @{ LogName = 'System'; ProviderName = 'disk' } -MaxEvents $MaxEvents -ErrorAction Stop
} catch {
return $map
}
foreach ($e in $events) {
if ($e.Message -match 'Harddisk(\d+)\\DR(\d+)') {
$n = [int]$Matches[1]
$dr = [int]$Matches[2]
if (-not $map.ContainsKey($n)) { $map[$n] = $dr }
}
}
return $map
}
$drMap = Get-DrMapping -MaxEvents $MaxEvents
$physicalDisks = Get-PhysicalDisk | Select-Object DeviceId, FriendlyName, SerialNumber, MediaType, @{N='SizeGB';E={[math]::Round($_.Size / 1GB,2)}}
foreach ($pd in $physicalDisks) {
$devId = [int]$pd.DeviceId
$drSuffix = if ($drMap.ContainsKey($devId)) { "\DR$($drMap[$devId])" } else { '\DR? (no event seen yet)' }
Write-Host ""
Write-Host "<=== \Device\Harddisk$devId$drSuffix ($($pd.FriendlyName)) ===>"
Write-Host " DeviceId: $devId | Serial: $($pd.SerialNumber) | Media: $($pd.MediaType) | Size: $($pd.SizeGB) GB"
try {
$partitions = Get-Partition -DiskNumber $devId -ErrorAction Stop
if (-not $partitions) {
Write-Host " (no partitions found)"
continue
}
foreach ($part in $partitions) {
$driveLetter = if ($part.DriveLetter) { "$($part.DriveLetter):" } else { 'no letter' }
$sizeGB = [math]::Round($part.Size / 1GB, 2)
$typeInfo = Get-PartitionTypeInfo -Partition $part
Write-Host " [PARTITION $($part.PartitionNumber)] Drive: $driveLetter - $sizeGB GB - $typeInfo"
}
} catch {
Write-Host " [ERROR] cannot read partitions for disk $devId"
}
}
if ($drMap.Count -eq 0) {
Write-Host ""
Write-Host "Note: no \Device\HarddiskN\DRx entries found in the last $MaxEvents System log events. Increase -MaxEvents, or the DR number will only appear once Windows actually logs a disk event for that drive (e.g. a bad block warning)."
}
EndPowerShell:
Comment: Verify that Discord does not have any injected code to intercept personal data. If anything is prompted here, it needs to be checked that it isn't malicious code.
Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) }
StartPowerShell:
# Basic BSOD listings
$ccKey = "HKLM:\SYSTEM\CurrentControlSet\Control\CrashControl"
$cfg = Get-ItemProperty $ccKey -ErrorAction SilentlyContinue
$dumpTypeMap = @{0='None';1='Complete';2='Kernel';3='Minidump';7='Automatic'}
Write-Output "--- Configuration ---"
Write-Output ("Dump Type: {0} ({1})" -f $cfg.CrashDumpEnabled, $dumpTypeMap[$cfg.CrashDumpEnabled])
Write-Output ("Full Dump Path: {0}" -f $(if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}))
Write-Output ("Minidump Folder: {0}" -f $(if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}))
Write-Output ("Auto Reboot: {0}" -f $(if($cfg.AutoReboot -eq 0){'Disabled'}else{'Enabled'}))
Write-Output "--- Found Dump Files ---"
$full = if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}
if (Test-Path $full) { Get-Item $full | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
$mini = if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}
if (Test-Path $mini) { Get-ChildItem $mini -Filter *.dmp | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
Write-Output "--- BugCheck Reasoning (recent events) ---"
$map = @{
'0x0000000A'='IRQL_NOT_LESS_OR_EQUAL - faulty/outdated driver accessed memory at high IRQL'
'0x0000001E'='KMODE_EXCEPTION_NOT_HANDLED - unhandled kernel exception, often driver/hardware'
'0x0000002E'='DATA_BUS_ERROR - typically bad RAM or hardware fault'
'0x0000003B'='SYSTEM_SERVICE_EXCEPTION - exception in a system service, often driver-related'
'0x00000050'='PAGE_FAULT_IN_NONPAGED_AREA - bad RAM or faulty driver/antivirus'
'0x0000007A'='KERNEL_DATA_INPAGE_ERROR - disk-related problem'
'0x0000007B'='INACCESSIBLE_BOOT_DEVICE - system could not find/access the boot device'
'0x0000007E'='SYSTEM_THREAD_EXCEPTION_NOT_HANDLED - almost always a faulty driver'
'0x0000007F'='UNEXPECTED_KERNEL_MODE_TRAP - hardware issue (CPU/RAM/overclocking)'
'0x0000009F'='DRIVER_POWER_STATE_FAILURE - driver failed to respond to a power state change'
'0x000000C2'='BAD_POOL_CALLER - driver mishandling memory (pool corruption)'
'0x000000D1'='DRIVER_IRQL_NOT_LESS_OR_EQUAL - typically a network or GPU driver'
'0x000000EF'='CRITICAL_PROCESS_DIED - a critical system process died, often malware/system corruption'
'0x00000116'='VIDEO_TDR_FAILURE - GPU driver failed to respond in time (timeout)'
'0x00000124'='WHEA_UNCORRECTABLE_ERROR - hardware fault (CPU/RAM/PSU/overclocking)'
'0x00000133'='DPC_WATCHDOG_VIOLATION - faulty driver or storage subsystem issue'
'0x00000139'='KERNEL_SECURITY_CHECK_FAILURE - corrupted kernel structure, possibly malware'
}
$events = Get-WinEvent -FilterHashtable @{LogName='System';Id=1001} -MaxEvents 100 -ErrorAction SilentlyContinue |
Where-Object { $_.ProviderName -match 'WER-SystemErrorReporting' } | Select-Object -First 5
if (-not $events) { Write-Output "No BugCheck events found in the log." }
foreach ($ev in $events) {
$code = if ($ev.Message -match 'bugcheck was:\s*(0x[0-9A-Fa-f]+)') { $matches[1] } else { $null }
Write-Output ("Time: {0}" -f $ev.TimeCreated)
Write-Output ("Code: {0}" -f $(if($code){$code}else{'not recognized'}))
if ($code -and $map.ContainsKey($code.ToUpper())) {
Write-Output ("Meaning: {0}" -f $map[$code.ToUpper()])
} elseif ($code) {
Write-Output "Meaning: unknown code, look up at learn.microsoft.com/windows-hardware/drivers/debugger/bug-check-code-reference2"
}
Write-Output ""
}
EndPowerShell:
StartPowerShell:
# This snippet lists all installed apps and their folder contents along with SHA256 hashes. Useful for troubleshooting malware abusing installed app entry.
param(
[switch]$Recurse,
[int]$MaxFilesPerApp = [int]::MaxValue
)
$uninstallPaths = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
$script:msiInstaller = $null
function Get-MsiInstallLocation {
param([string]$ProductCode)
if (-not $script:msiInstaller) {
try { $script:msiInstaller = New-Object -ComObject WindowsInstaller.Installer } catch { return $null }
}
try {
$loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallLocation')
if ([string]::IsNullOrWhiteSpace($loc)) { $loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallSource') }
if ([string]::IsNullOrWhiteSpace($loc)) { return $null }
return $loc
} catch { return $null }
}
function Get-CleanPath {
param([string]$RawValue)
if ([string]::IsNullOrWhiteSpace($RawValue)) { return $null }
$s = $RawValue.Trim()
if ($s.StartsWith('"')) {
$endQuote = $s.IndexOf('"', 1)
if ($endQuote -gt 0) { return $s.Substring(1, $endQuote - 1) }
}
if ($s -match '^(.*?\.exe)\b') { return $Matches[1] }
return $s
}
function Format-FileSize {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$script:PeExtensions = @('.exe', '.dll', '.sys', '.ocx', '.cpl', '.scr', '.drv', '.efi', '.msi', '.msp', '.msu')
function Test-IsPeFile {
param([string]$Extension)
return $script:PeExtensions -contains $Extension.ToLower()
}
function Get-SignatureInfo {
param([string]$Path, [string]$Extension)
if (-not (Test-IsPeFile -Extension $Extension)) {
return [PSCustomObject]@{ Signer = 'N/A (not PE)'; Status = 'NotApplicable'; Valid = $false }
}
$result = [PSCustomObject]@{ Signer = 'Unsigned'; Status = 'NotSigned'; Valid = $false }
try {
$sig = Get-AuthenticodeSignature -LiteralPath $Path -ErrorAction Stop
$result.Status = $sig.Status.ToString()
$result.Valid = ($sig.Status -eq 'Valid')
if ($sig.SignerCertificate) {
if ($sig.SignerCertificate.Subject -match 'CN=([^,]+)') { $result.Signer = $Matches[1].Trim('"') }
else { $result.Signer = $sig.SignerCertificate.Subject }
if (-not $result.Valid) { $result.Signer += " [INVALID: $($result.Status)]" }
} elseif ($sig.Status -eq 'NotSigned') {
$result.Signer = 'Unsigned'
} else {
$result.Signer = "Unknown [$($result.Status)]"
}
} catch {
$result.Signer = 'Verification error'
$result.Status = 'Error'
$result.Valid = $false
}
return $result
}
$rawApps = Get-ItemProperty -Path $uninstallPaths -ErrorAction SilentlyContinue |
Where-Object { $_.DisplayName -and $_.DisplayName.Trim() -ne '' } |
Select-Object @{Name = 'Name'; Expression = { $_.DisplayName } },
@{Name = 'Version'; Expression = { $_.DisplayVersion } },
@{Name = 'Publisher'; Expression = { $_.Publisher } },
@{Name = 'InstallFolder'; Expression = {
if ($_.InstallLocation -and $_.InstallLocation.Trim() -ne '') { $_.InstallLocation }
elseif ($_.UninstallString -match 'MsiExec\.exe.*?(\{[0-9A-Fa-f\-]{36}\})') {
$productCode = $Matches[1]
$msiLoc = Get-MsiInstallLocation -ProductCode $productCode
if ($msiLoc) { $msiLoc } else { "MSI: $productCode (location not found)" }
}
elseif ($_.UninstallString) { $_.UninstallString }
else { 'N/A' }
} } |
Sort-Object Name -Unique
foreach ($app in $rawApps) {
$versionText = if ($app.Version) { $app.Version } else { '?' }
$publisherText = if ($app.Publisher) { $app.Publisher } else { '?' }
Write-Host ""
Write-Host "<=== $($app.Name) [$versionText] ($publisherText) ===>"
if ($app.InstallFolder -eq 'N/A' -or $app.InstallFolder -match '^MSI: .* \(location not found\)$') {
Write-Host " Path: $($app.InstallFolder)"
continue
}
$cleanPath = Get-CleanPath -RawValue $app.InstallFolder
$exists = $false
try {
$exists = Test-Path -LiteralPath $cleanPath -ErrorAction Stop
} catch [System.UnauthorizedAccessException] {
Write-Host " Path: $cleanPath"
Write-Host " [ACCESS DENIED]"
continue
} catch {
Write-Host " Path: $cleanPath"
Write-Host " [ERROR] cannot access"
continue
}
if (-not $exists) {
Write-Host " Path: $cleanPath"
Write-Host " [NOT FOUND]"
continue
}
$rootItem = Get-Item -LiteralPath $cleanPath -Force
$created = $rootItem.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$modified = $rootItem.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
if ($rootItem.PSIsContainer) {
$subFolders = Get-ChildItem -LiteralPath $cleanPath -Directory -Force -ErrorAction SilentlyContinue
$gciParams = @{ LiteralPath = $cleanPath; File = $true; Force = $true; ErrorAction = 'SilentlyContinue' }
if ($Recurse) { $gciParams['Recurse'] = $true }
$allFiles = Get-ChildItem @gciParams
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: $($allFiles.Count) | Folders: $($subFolders.Count)"
foreach ($dir in $subFolders) {
$dCreated = $dir.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$dModified = $dir.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$dFileCount = (Get-ChildItem -LiteralPath $dir.FullName -File -Force -ErrorAction SilentlyContinue).Count
Write-Host (" [DIR] {0} - {1} - {2,10} - {3}" -f $dCreated, $dModified, "$dFileCount files", $dir.FullName)
}
} else {
$allFiles = @($rootItem)
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: 1"
}
if ($allFiles.Count -eq 0) { continue }
$shown = $allFiles | Select-Object -First $MaxFilesPerApp
foreach ($f in $shown) {
$hash = 'N/A'
try { $hash = (Get-FileHash -LiteralPath $f.FullName -Algorithm SHA256 -ErrorAction Stop).Hash } catch { $hash = 'HASH-ERROR' }
$size = Format-FileSize -Bytes $f.Length
$fcreated = $f.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$fmod = $f.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$sigInfo = Get-SignatureInfo -Path $f.FullName -Extension $f.Extension
Write-Host (" [{0}] {1} - {2} - {3,10} - Signer: {4} - {5}" -f $hash, $fcreated, $fmod, $size, $sigInfo.Signer, $f.FullName)
}
}
EndPowerShell:
Comment: List 30 recent scheduled tasks (you know, just for the sake of it)
Powershell: Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo
Comment: List recent Run (Windows + R) executed commands, useful for identifying ClickFix attacks
Powershell: (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" }
Comment: Remove browser cache
StartPowerShell:
$ProfilesDirectory = (Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList').ProfilesDirectory
$DisplayNames = @{
"chrome" = "Chrome"
"firefox" = "Firefox"
"opera" = "Opera"
"operagx" = "Opera GX"
"brave" = "Brave"
"msedge" = "Edge"
"vivaldi" = "Vivaldi"
"librewolf" = "LibreWolf"
"mullvad" = "Mullvad Browser"
"zen" = "Zen"
}
$ProcessNameMap = @{
"operagx" = "opera"
"mullvad" = "mullvadbrowser"
}
$trueCacheNames = @("Cache", "Code Cache", "DawnCache", "GPUCache", "GrShaderCache", "ShaderCache", "Shared Dictionary\cache")
function Get-CacheDirs {
param([string]$BrowserName, [string]$ProfilesDirectory)
switch ($BrowserName) {
"chrome" {
$dir = "$ProfilesDirectory\*\AppData\Local\Google\Chrome\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"firefox" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mozilla\Firefox\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"opera" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"operagx" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software\Opera GX Stable"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software\Opera GX Stable"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"brave" {
$dir = "$ProfilesDirectory\*\AppData\Local\BraveSoftware\Brave-Browser\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"msedge" {
$dir = "$ProfilesDirectory\*\AppData\Local\Microsoft\Edge\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"vivaldi" {
$dir = "$ProfilesDirectory\*\AppData\Local\Vivaldi\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"librewolf" {
$dir = "$ProfilesDirectory\*\AppData\Local\LibreWolf\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"mullvad" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mullvad\MullvadBrowser\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"zen" {
$dir = "$ProfilesDirectory\*\AppData\Local\zen\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
}
}
function Format-Size {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$BrowserKeys = @('chrome', 'firefox', 'opera', 'operagx', 'brave', 'msedge', 'vivaldi', 'librewolf', 'mullvad', 'zen')
foreach ($key in $BrowserKeys) {
$procName = if ($ProcessNameMap.ContainsKey($key)) { $ProcessNameMap[$key] } else { $key }
Get-Process -Name $procName -ErrorAction SilentlyContinue | Stop-Process -Force -ErrorAction SilentlyContinue
}
Start-Sleep -Seconds 5
$grandBytes = 0L
$grandFiles = 0
$anyFound = $false
foreach ($key in $BrowserKeys) {
$cacheDirs = Get-CacheDirs -BrowserName $key -ProfilesDirectory $ProfilesDirectory
if (-not $cacheDirs -or $cacheDirs.Count -eq 0) { continue }
$anyFound = $true
$displayName = $DisplayNames[$key]
$browserBytes = 0L
$browserFiles = 0
foreach ($cacheDir in $cacheDirs) {
if (-not (Test-Path $cacheDir)) { continue }
$items = Get-ChildItem -Path $cacheDir -Force -Recurse -ErrorAction SilentlyContinue
$files = $items | Where-Object { -not $_.PSIsContainer }
$bytes = ($files | Measure-Object -Property Length -Sum).Sum
if (-not $bytes) { $bytes = 0 }
$browserFiles += $files.Count
$browserBytes += $bytes
Get-ChildItem -Path "$cacheDir\*" -Force -ErrorAction SilentlyContinue | Remove-Item -Force -Recurse -ErrorAction SilentlyContinue
}
$grandBytes += $browserBytes
$grandFiles += $browserFiles
Write-Host ("{0,-16} freed {1,10} ({2} files)" -f $displayName, (Format-Size $browserBytes), $browserFiles)
}
if (-not $anyFound) {
Write-Host "No cache found for any installed browser."
}
Write-Host ""
Write-Host ("Total freed: {0} ({1} files)" -f (Format-Size $grandBytes), $grandFiles)
EndPowerShell:
Comment: Verify WMI repository, repair & verify again
CMD: winmgmt.exe /verifyrepository
CMD: winmgmt.exe /salvagerepository
CMD: winmgmt.exe /verifyrepository
Comment: To rebuild the performance counter library values
CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R"
CMD: "%WINDIR%\SysWOW64\lodctr.exe /R"
CMD: "C:\Windows\SYSTEM32\lodctr.exe /R"
CMD: "C:\Windows\SysWOW64\lodctr.exe /R"
Comment: Resync performance counter library values to WMI as well
CMD: winmgmt.exe /resyncperf
Comment: Force policy removal
C:\Windows\System32\GroupPolicyUsers
C:\Windows\System32\GroupPolicy
CMD: gpupdate.exe /force
Comment: Reset PowerShell execution policy
Powershell: Set-ExecutionPolicy Unrestricted -Scope CurrentUser -Force
Comment: BITS reset
Startbatch:
@echo off
net.exe stop BITS
ipconfig.exe /flushdns
ren "%programdata%\Microsoft\Network\Downloader\qmgr*.*" qmgr*.*.old
net.exe start BITS
Endbatch:
cmd: bitsadmin.exe /reset /allusers
Comment: Network reset commands
CMD: ipconfig.exe /release
CMD: ipconfig.exe /release6
CMD: netsh.exe winhttp reset proxy
CMD: netsh.exe int ip reset
CMD: netsh.exe int ipv6 reset
CMD: netsh.exe int tcp reset
CMD: netsh.exe winsock reset
CMD: netsh.exe branchcache reset
CMD: ipconfig.exe /flushDNS
CMD: arp.exe -d *
CMD: nbtstat.exe -R
CMD: route.exe -f
CMD: ipconfig.exe /renew
CMD: nbtstat.exe -RR
CMD: ipconfig.exe /registerdns
CMD: ipconfig.exe /all
Comment: Additional temp file removal
C:\Windows\System32\config\systemprofile\AppData\Local\*.tmp
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
C:\Users\CurrentUserName\AppData\Local\Temp\*
C:\Windows\Temp\*
C:\Windows\SystemTemp\*
C:\Windows\Prefetch\*
Comment: System repair commands
CMD: DISM.exe /Online /Cleanup-Image /RestoreHealth
CMD: SFC /ScanNow
CMD: DISM.exe /Online /Cleanup-Image /StartComponentCleanup /ResetBase
Comment: Remove set proxy servers
RemoveProxy:
Comment: Remove temporary files via FRST
EmptyTemp:
Warning
Executing a Fixlist on the wrong system may permanently damage it. Continue only if this link was meant for you.
To view the content, acknowledge this warning.