content copied
content
Start::
SystemRestore: On
CreateRestorePoint:
CloseProcesses:
2026-07-25 11:49 - 2026-07-25 11:49 - 000000000 ____D C:\Users\gabri\AppData\Local\Qualcomm
2026-07-25 11:41 - 2025-10-03 05:24 - 000000000 ____D C:\Users\gabri\AppData\Roaming\RenPy
PowerShell: Remove-MpPreference -ExclusionPath "C:\Users\gabri\Desktop\Escritorio\Silent Hill F"
PowerShell: Remove-MpPreference -ExclusionPath "C:\Users\gabri\Desktop\Escritorio\Silent Hill F\SILENT HILL f\SHf.exe"
HKU\S-1-5-21-1709695016-1157341809-3477375620-1001\...\Run: [btweb] => "C:\Users\gabri\AppData\Roaming\BitTorrent Web\btweb.exe" /MINIMIZED (No File)
HKU\S-1-5-21-1709695016-1157341809-3477375620-1001\...\Run: [utweb] => "C:\Users\gabri\AppData\Roaming\uTorrent Web\utweb.exe" /MINIMIZED (No File)
HKU\S-1-5-21-1709695016-1157341809-3477375620-1001\...\Run: [RobloxPlayerBeta] => "C:\Users\gabri\AppData\Local\Roblox\Versions\version-90f2fddd3b244ff6\RobloxPlayerBeta.exe" --launch-to-tray (No File)
Task: {88525D88-BA77-4C67-B6ED-6ED3A6C19ABF} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
S2 GBTECService; C:\Program Files (x86)\GIGABYTE\GBTECService\OLEDDisplayService.exe (No File)
S2 Power_a17007; "C:\Program Files\Cold Turkey\ServiceHub.Power.exe" (No File)
S0 WinSetupMon; system32\DRIVERS\WinSetupMon.sys (No File)
2026-03-17 23:48 - 2026-03-17 23:48 - 000000048 ____R () C:\Users\gabri\AppData\Local\0119AC2FC90D95AC063B177717B7B3B6
AlternateDataStreams: C:\Users\gabri\Desktop\Escritorio\FRSTEnglish.exe:MBAM.Zone.Identifier [450]
FirewallRules: [{5C64651E-C72D-4A3D-991F-6E7FD7322B7A}] => (Allow) C:\Program Files\GIGABYTE\Control Center\GCC.exe => No File
FirewallRules: [{4D6B7DE5-025D-4A8F-B151-47BE0F9A7424}] => (Allow) C:\Program Files\GIGABYTE\Control Center\GCC.exe => No File
FirewallRules: [{119788BD-167A-4350-A8B0-F8B38864E485}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{B732C922-9A9B-45F0-AE1E-B89D61BFE241}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [TCP Query User{7BC7AA17-6C78-4BF5-A858-29D5995CAB91}C:\program files (x86)\steam\steamapps\common\palworld\pal\binaries\win64\palworld-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\palworld\pal\binaries\win64\palworld-win64-shipping.exe => No File
FirewallRules: [UDP Query User{D40CD6BE-D6CB-46FF-A501-54ECEE0538CB}C:\program files (x86)\steam\steamapps\common\palworld\pal\binaries\win64\palworld-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\palworld\pal\binaries\win64\palworld-win64-shipping.exe => No File
FirewallRules: [TCP Query User{C76C5377-F2EC-4D31-8191-D21ECFACDF77}C:\users\gabri\appdata\local\discord\app-1.0.9218\discord.exe] => (Allow) C:\users\gabri\appdata\local\discord\app-1.0.9218\discord.exe => No File
FirewallRules: [UDP Query User{5C4424ED-84AE-4AD0-84CE-503DDC46FD56}C:\users\gabri\appdata\local\discord\app-1.0.9218\discord.exe] => (Allow) C:\users\gabri\appdata\local\discord\app-1.0.9218\discord.exe => No File
FirewallRules: [{622BBE7C-E28C-4E89-8875-1F47E885F2AC}] => (Allow) C:\Users\gabri\AppData\Roaming\Hytale\install\pre-release\package\game\latest\Client\HytaleClient.exe => No File
FirewallRules: [{71D2FC66-CAAC-4A83-8685-F8E0FA6F279B}] => (Allow) C:\Users\gabri\AppData\Roaming\Hytale\install\pre-release\package\game\latest\Client\HytaleClient.exe => No File
FirewallRules: [{142FD88D-762C-40AB-A257-6F77FC34807E}] => (Allow) C:\Users\gabri\AppData\Roaming\Hytale\install\pre-release\package\jre\latest\bin\java.exe => No File
FirewallRules: [{493ACE5E-8730-46B2-8123-C6BF276347FD}] => (Allow) C:\Users\gabri\AppData\Roaming\Hytale\install\pre-release\package\jre\latest\bin\java.exe => No File
FirewallRules: [TCP Query User{3F0120DF-74E0-4DB7-AAE0-226AAB0447D3}C:\users\gabri\appdata\local\discord\app-1.0.9225\discord.exe] => (Allow) C:\users\gabri\appdata\local\discord\app-1.0.9225\discord.exe => No File
FirewallRules: [UDP Query User{9EE3594D-AD4D-4B29-A8AC-877E52A35B16}C:\users\gabri\appdata\local\discord\app-1.0.9225\discord.exe] => (Allow) C:\users\gabri\appdata\local\discord\app-1.0.9225\discord.exe => No File
FirewallRules: [TCP Query User{A426D76C-7F2A-4CD3-BA10-F77DDFE2675E}C:\users\gabri\desktop\escritorio\dfm\asdfa.exe] => (Allow) C:\users\gabri\desktop\escritorio\dfm\asdfa.exe => No File
FirewallRules: [UDP Query User{814BA306-1E15-46F6-9742-9FD906EA8D91}C:\users\gabri\desktop\escritorio\dfm\asdfa.exe] => (Allow) C:\users\gabri\desktop\escritorio\dfm\asdfa.exe => No File
FirewallRules: [TCP Query User{8CE68A0A-13F8-4D38-B5D9-2047D1A0C711}D:\thief simulator\thief simulator\thief.exe] => (Allow) D:\thief simulator\thief simulator\thief.exe => No File
FirewallRules: [UDP Query User{F0BF9BD4-1658-4D2C-B847-4B59B29849D2}D:\thief simulator\thief simulator\thief.exe] => (Allow) D:\thief simulator\thief simulator\thief.exe => No File
FirewallRules: [TCP Query User{814DF51E-59DF-46EE-A8D4-ABC534359CD0}C:\users\gabri\desktop\escritorio\quake iii arena\ioquake3.x86_64.exe] => (Allow) C:\users\gabri\desktop\escritorio\quake iii arena\ioquake3.x86_64.exe => No File
FirewallRules: [UDP Query User{02DE9945-C1ED-406B-942C-98F2E728C40D}C:\users\gabri\desktop\escritorio\quake iii arena\ioquake3.x86_64.exe] => (Allow) C:\users\gabri\desktop\escritorio\quake iii arena\ioquake3.x86_64.exe => No File
FirewallRules: [TCP Query User{077F0D57-3767-442E-9A9E-CA05E6C84213}C:\users\gabri\desktop\escritorio\quake iii arena\ioq3ded.x86.exe] => (Allow) C:\users\gabri\desktop\escritorio\quake iii arena\ioq3ded.x86.exe => No File
FirewallRules: [UDP Query User{96EFE715-678B-4F32-A1F5-60FA7CF31952}C:\users\gabri\desktop\escritorio\quake iii arena\ioq3ded.x86.exe] => (Allow) C:\users\gabri\desktop\escritorio\quake iii arena\ioq3ded.x86.exe => No File
FirewallRules: [TCP Query User{0A4E8053-1FF6-4631-9AF5-97A045FC6426}C:\users\gabri\desktop\escritorio\quake iii arena\ioquake3.x86.exe] => (Allow) C:\users\gabri\desktop\escritorio\quake iii arena\ioquake3.x86.exe => No File
FirewallRules: [UDP Query User{5E1252DC-A86F-457B-96A9-7F46E6B143FD}C:\users\gabri\desktop\escritorio\quake iii arena\ioquake3.x86.exe] => (Allow) C:\users\gabri\desktop\escritorio\quake iii arena\ioquake3.x86.exe => No File
FirewallRules: [TCP Query User{67A4F8A8-F392-4530-BF01-10E16C08005F}C:\users\gabri\desktop\escritorio\quake iii arena\ioq3ded.x86_64.exe] => (Allow) C:\users\gabri\desktop\escritorio\quake iii arena\ioq3ded.x86_64.exe => No File
FirewallRules: [UDP Query User{FE674A65-592F-418B-BC74-D18ABEFADE90}C:\users\gabri\desktop\escritorio\quake iii arena\ioq3ded.x86_64.exe] => (Allow) C:\users\gabri\desktop\escritorio\quake iii arena\ioq3ded.x86_64.exe => No File
FirewallRules: [TCP Query User{E04DA8BC-8D18-4C90-AE8A-5155A53474A5}C:\users\gabri\appdata\local\discord\app-1.0.9238\discord.exe] => (Allow) C:\users\gabri\appdata\local\discord\app-1.0.9238\discord.exe => No File
FirewallRules: [UDP Query User{955239A8-FBF1-4667-BC6B-4E5C20DDEB30}C:\users\gabri\appdata\local\discord\app-1.0.9238\discord.exe] => (Allow) C:\users\gabri\appdata\local\discord\app-1.0.9238\discord.exe => No File
FirewallRules: [TCP Query User{55DDC800-9D02-459E-9144-8E8E43C72E81}C:\users\gabri\appdata\local\discord\app-1.0.9239\discord.exe] => (Allow) C:\users\gabri\appdata\local\discord\app-1.0.9239\discord.exe => No File
FirewallRules: [UDP Query User{A1F389FA-B4D6-4772-A976-0444E39F77CE}C:\users\gabri\appdata\local\discord\app-1.0.9239\discord.exe] => (Allow) C:\users\gabri\appdata\local\discord\app-1.0.9239\discord.exe => No File
FirewallRules: [TCP Query User{4F4EF101-0AB0-441F-89E1-D4FD48ECE441}C:\users\gabri\appdata\local\discord\app-1.0.9242\discord.exe] => (Allow) C:\users\gabri\appdata\local\discord\app-1.0.9242\discord.exe => No File
FirewallRules: [UDP Query User{5731ED3A-C27D-4464-B2B7-19B5C99B5BDA}C:\users\gabri\appdata\local\discord\app-1.0.9242\discord.exe] => (Allow) C:\users\gabri\appdata\local\discord\app-1.0.9242\discord.exe => No File
FirewallRules: [{8BF28E59-DC58-4CC4-A6A6-C08613773C1E}] => (Allow) C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe => No File
FirewallRules: [{68144F16-4322-4D44-BBC0-E77F4B7651A7}] => (Allow) C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe => No File
FirewallRules: [{597507D7-18D6-41C5-9B5A-747A2329C31E}] => (Allow) C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe => No File
FirewallRules: [{8E538E29-D59F-49F4-9FD7-2A959F3B5709}] => (Allow) C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe => No File
FirewallRules: [{A60F5DC0-3CC2-4459-8AC6-F6C6D79B127D}] => (Allow) C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe => No File
FirewallRules: [{088CB059-19E8-4A0B-B9A5-DFB5503FADCF}] => (Allow) C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe => No File
FirewallRules: [{DF83E41C-ACDC-40C4-BA61-BF313B2039EC}] => (Allow) C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe => No File
FirewallRules: [{5C128F3B-F322-445D-9AD0-6E5B52CB8218}] => (Allow) C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe => No File
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {4bd716da-5cfc-46af-8aeb-888a87ef3df0} - no filepath. <==== ATTENTION
File: c:\app\gabri\product\21c\dbhomexe\bin\ORACLE.EXE
File: C:\Users\gabri\AppData\Local\Qualcomm\Wireless Toolkit\prefetch_ad37.exe
2026-07-25 19:48 - 2026-07-25 19:48 - 002449408 _____ (Farbar) C:\Users\gabri\Downloads\Unconfirmed 456281.crdownload
2026-07-21 15:36 - 2025-09-22 09:03 - 000003484 _____ C:\WINDOWS\system32\Tasks\MAkF7mCn3tPqp662daybvERzwsKQYqnzM8{26EB8506-9B9D-496C-9BF4-9A8617CE513A}
HKU\S-1-5-21-1709695016-1157341809-3477375620-1001\...\Run: [MicrosoftEdgeAutoLaunch_E366E5E6AF98057EB6410578BC1FD47F] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4970824 2026-07-24] (Microsoft Corporation -> Microsoft Corporation)
StartPowerShell:
#Requires -Version 5.1
$ProductCodes = @(
'{2806F34E-16BA-41BC-AA3C-5134B3D49A9D}'
)
$DoComSweep = $false
$DoRawSweep = $false
$DoNameSweep = $false
$ErrorActionPreference = 'SilentlyContinue'
$ProgressPreference = 'SilentlyContinue'
$script:SW = [Diagnostics.Stopwatch]::StartNew()
function W { param([string]$s = '') Write-Output $s }
function H {
param([string]$t)
W ''
W ('-' * 100)
W ('{0} [+{1:N1}s]' -f $t, $script:SW.Elapsed.TotalSeconds)
W ('-' * 100)
}
function KV {
param([string]$k, $v)
if ($null -eq $v -or "$v" -eq '') { $v = '<none>' }
W (' {0,-24} {1}' -f $k, $v)
}
function Pack {
param([string]$g)
$x = ($g -replace '[{}\-\s]', '').ToUpper()
if ($x.Length -ne 32) { throw "bad guid: $g" }
$o = -join $x[7..0]
$o += -join $x[11..8]
$o += -join $x[15..12]
for ($i = 16; $i -lt 32; $i += 2) { $o += $x[$i + 1] + $x[$i] }
$o
}
function Native {
param([string]$p)
$p -replace '^HKLM:\\', 'HKLM\' -replace '^HKCU:\\', 'HKCU\' `
-replace '^HKCR:\\', 'HKCR\' -replace '^HKU:\\', 'HKU\'
}
function DumpKey {
param([string]$Path, [string]$Label = '')
if (-not (Test-Path -LiteralPath $Path)) { return }
W (Native $Path)
if ($Label) { W " [$Label]" }
$p = Get-ItemProperty -LiteralPath $Path
$names = @($p.PSObject.Properties.Name | Where-Object { $_ -notlike 'PS*' } | Sort-Object)
if ($names.Count -eq 0) { W ' <no values>' }
foreach ($n in $names) {
$v = $p.$n
if ($v -is [byte[]]) {
if ($v.Length -gt 64) {
$v = (($v[0..63] | ForEach-Object { $_.ToString('x2') }) -join '') + "... ($($v.Length) bytes)"
} else {
$v = ($v | ForEach-Object { $_.ToString('x2') }) -join ''
}
}
elseif ($v -is [array]) { $v = $v -join ' ; ' }
KV $n $v
}
W ''
}
function MsiTable {
param([string]$Path, [string]$Query)
try {
$i = New-Object -ComObject WindowsInstaller.Installer
$db = $i.GetType().InvokeMember('OpenDatabase', 'InvokeMethod', $null, $i, @($Path, 0))
$v = $db.GetType().InvokeMember('OpenView', 'InvokeMethod', $null, $db, @($Query))
$v.GetType().InvokeMember('Execute', 'InvokeMethod', $null, $v, $null)
while ($r = $v.GetType().InvokeMember('Fetch', 'InvokeMethod', $null, $v, $null)) {
$n = $r.GetType().InvokeMember('FieldCount', 'GetProperty', $null, $r, $null)
, @(for ($k = 1; $k -le $n; $k++) {
$r.GetType().InvokeMember('StringData', 'GetProperty', $null, $r, $k)
})
}
$v.GetType().InvokeMember('Close', 'InvokeMethod', $null, $v, $null)
[void][Runtime.InteropServices.Marshal]::ReleaseComObject($i)
} catch { }
}
function RootToHive {
param($r)
switch ("$r") {
'-1' { 'HKMU' } '0' { 'HKCR' } '1' { 'HKCU' } '2' { 'HKLM' } '3' { 'HKU' }
default { "root$r" }
}
}
function KeyPathPrefixToHive {
param([string]$p)
switch ($p) {
'00' { 'HKCR' } '01' { 'HKCU' } '02' { 'HKLM' } '03' { 'HKU' }
'20' { 'HKLM(64)' } '21' { 'HKCU(64)' } '22' { 'HKLM(64)' } '23' { 'HKU(64)' }
default { "root$p" }
}
}
$HKLM = [Microsoft.Win32.RegistryHive]::LocalMachine
$HKCU = [Microsoft.Win32.RegistryHive]::CurrentUser
$V64 = [Microsoft.Win32.RegistryView]::Registry64
$V32 = [Microsoft.Win32.RegistryView]::Registry32
function OpenBase {
param($Hive, $View)
[Microsoft.Win32.RegistryKey]::OpenBaseKey($Hive, $View)
}
$script:SysDirs = @(
"$env:SystemRoot", "$env:SystemRoot\System32", "$env:SystemRoot\SysWOW64",
"$env:SystemRoot\System32\drivers", "$env:SystemRoot\System32\wbem",
"$env:SystemRoot\WinSxS", "$env:SystemRoot\assembly",
"$env:ProgramData", "$env:ProgramData\Microsoft",
"$env:ProgramFiles", "${env:ProgramFiles(x86)}",
"$env:ProgramFiles\Common Files", "${env:ProgramFiles(x86)}\Common Files",
"$env:ProgramFiles\Common Files\Microsoft Shared", "${env:ProgramFiles(x86)}\Common Files\Microsoft Shared",
"$env:LOCALAPPDATA", "$env:LOCALAPPDATA\Programs", "$env:APPDATA",
"$env:USERPROFILE", 'C:\'
) | Where-Object { $_ } | ForEach-Object { $_.TrimEnd('\').ToLower() }
function Normalize-Path {
param([string]$p)
if ([string]::IsNullOrWhiteSpace($p)) { return $null }
$s = $p.Trim()
if ($s.StartsWith('"')) {
$e = $s.IndexOf('"', 1)
if ($e -gt 0) { $s = $s.Substring(1, $e - 1) } else { $s = $s.Trim('"') }
} else {
$m = [regex]::Match($s, '\s+[-/]')
if ($m.Success) { $s = $s.Substring(0, $m.Index) }
}
$s = [Environment]::ExpandEnvironmentVariables($s)
$s = ($s -replace '^\\\?\?\\', '' -replace '^@', '').Trim()
if ($s -match '^[A-Za-z]:\\') { return $s.TrimEnd('\').ToLower() }
if ($s -match '^[^\\/:*?"<>|]+\.(dll|exe|ocx|cpl|sys)$') { return $s.ToLower() }
return $null
}
$script:OwnPaths = $null
$script:OwnNames = $null
$script:OwnDirs = @()
function Test-Own {
param([string]$c)
$n = Normalize-Path $c
if (-not $n) { return $false }
if ($script:OwnPaths.Contains($n)) { return $true }
foreach ($d in $script:OwnDirs) { if ($n.StartsWith($d + '\')) { return $true } }
if ($n -notmatch '\\' -and $script:OwnNames.Contains($n)) { return $true }
return $false
}
function Get-FileFacts {
param([string]$Path)
if (-not (Test-Path -LiteralPath $Path -PathType Leaf)) { return $null }
$fi = Get-Item -LiteralPath $Path
$vi = $fi.VersionInfo
$sig = Get-AuthenticodeSignature -LiteralPath $Path
[PSCustomObject]@{
Size = $fi.Length
Created = $fi.CreationTime.ToString('yyyy-MM-dd HH:mm:ss')
Modified = $fi.LastWriteTime.ToString('yyyy-MM-dd HH:mm:ss')
Company = $vi.CompanyName
Product = $vi.ProductName
OrigName = $vi.OriginalFilename
IntName = $vi.InternalName
FileVer = $vi.FileVersion
Desc = $vi.FileDescription
SigStatus = "$($sig.Status)"
Signer = $(if ($sig.SignerCertificate) { $sig.SignerCertificate.Subject })
SHA256 = (Get-FileHash -LiteralPath $Path -Algorithm SHA256).Hash
}
}
W ('=' * 100)
W ('MSI REGISTRATION FOOTPRINT {0}' -f (Get-Date -Format 'yyyy-MM-dd HH:mm:ss'))
W ('HOST {0} USER {1}' -f $env:COMPUTERNAME, $env:USERNAME)
W ('OS {0}' -f (Get-CimInstance Win32_OperatingSystem).Caption)
W ('ELEVATED {0}' -f (New-Object Security.Principal.WindowsPrincipal(
[Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole(
[Security.Principal.WindowsBuiltInRole]::Administrator))
W ('SWEEPS com={0} raw={1} name={2}' -f $DoComSweep, $DoRawSweep, $DoNameSweep)
W ('=' * 100)
foreach ($pc in $ProductCodes) {
$packed = Pack $pc
$shortPc = ($pc -replace '[{}]', '')
$script:OwnPaths = New-Object 'System.Collections.Generic.HashSet[string]'
$script:OwnNames = New-Object 'System.Collections.Generic.HashSet[string]'
$script:OwnDirs = @()
$localPkg = $null
$installLoc = $null
$publisher = $null
$displayName = $null
$compFiles = New-Object System.Collections.ArrayList
$compRegs = New-Object System.Collections.ArrayList
$touchedKeys = New-Object System.Collections.ArrayList
W ''
W ('=' * 100)
W "PRODUCTCODE $pc"
W "PACKED $packed"
W ('=' * 100)
H '1. UNINSTALL / ARP'
$found = $false
foreach ($k in @(
"HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$pc",
"HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\$pc",
"HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$pc")) {
if (-not (Test-Path -LiteralPath $k)) { continue }
$found = $true
[void]$touchedKeys.Add((Native $k))
DumpKey $k
$p = Get-ItemProperty -LiteralPath $k
if (-not $displayName) { $displayName = $p.DisplayName }
if (-not $publisher) { $publisher = $p.Publisher }
if (-not $installLoc) { $installLoc = $p.InstallLocation }
if (-not $installLoc -and $p.DisplayIcon) {
$ic = ($p.DisplayIcon -split ',')[0].Trim('"')
if ($ic -match '\\') { $installLoc = Split-Path $ic -Parent }
}
}
if (-not $found) { W '<none>' }
H '2. INSTALLER BRANCH'
$roots = @(
"HKLM:\SOFTWARE\Classes\Installer\Products\$packed",
"HKLM:\SOFTWARE\Classes\Installer\Features\$packed",
"HKLM:\SOFTWARE\Classes\Installer\Patches\$packed"
)
$bk = OpenBase $HKLM $V64
$ud = $bk.OpenSubKey('SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData')
if ($ud) {
foreach ($sid in $ud.GetSubKeyNames()) {
$roots += "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\$sid\Products\$packed"
}
$ud.Close()
}
$bk.Close()
$found = $false
foreach ($r in ($roots | Sort-Object -Unique)) {
if (-not (Test-Path -LiteralPath $r)) { continue }
$found = $true
[void]$touchedKeys.Add((Native $r))
foreach ($sub in @('', '\InstallProperties', '\SourceList', '\SourceList\Net',
'\SourceList\Media', '\Usage', '\Features', '\Patches')) {
DumpKey "$r$sub" $sub.TrimStart('\')
}
$ip = Get-ItemProperty -LiteralPath "$r\InstallProperties"
if ($ip) {
if (-not $localPkg) { $localPkg = $ip.LocalPackage }
if (-not $installLoc) { $installLoc = $ip.InstallLocation }
if (-not $publisher) { $publisher = $ip.Publisher }
if (-not $displayName) { $displayName = $ip.DisplayName }
}
}
if (-not $found) { W '<none>' }
W ''
W 'RESOLVED:'
KV 'DisplayName' $displayName
KV 'Publisher' $publisher
KV 'InstallLocation' $installLoc
KV 'LocalPackage' $localPkg
H '3. UPGRADECODE MEMBERSHIP'
$found = $false
foreach ($cfg in @(
@{ Path = 'SOFTWARE\Classes\Installer\UpgradeCodes'; Label = 'HKLM\SOFTWARE\Classes\Installer\UpgradeCodes' },
@{ Path = 'SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes'; Label = 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes' })) {
$bk = OpenBase $HKLM $V64
$root = $bk.OpenSubKey($cfg.Path)
if ($root) {
foreach ($sub in $root.GetSubKeyNames()) {
$k = $root.OpenSubKey($sub)
if (-not $k) { continue }
if ($k.GetValueNames() -contains $packed) {
$found = $true
W ('{0}\{1}' -f $cfg.Label, $sub)
KV 'upgradecode (packed)' $sub
KV 'member value' $k.GetValue($packed)
W ''
}
$k.Close()
}
$root.Close()
}
$bk.Close()
}
if (-not $found) { W '<none>' }
H '4. COMPONENT REGISTRATION'
$found = $false
$dirCand = New-Object System.Collections.ArrayList
foreach ($cfg in @(
@{ Path = 'SOFTWARE\Classes\Installer\Components'; Label = 'HKLM\SOFTWARE\Classes\Installer\Components' },
@{ Path = 'SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components'; Label = 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components' })) {
$bk = OpenBase $HKLM $V64
$root = $bk.OpenSubKey($cfg.Path)
if ($root) {
foreach ($sub in $root.GetSubKeyNames()) {
$k = $root.OpenSubKey($sub)
if (-not $k) { continue }
$vn = $k.GetValueNames()
if ($vn -contains $packed) {
$found = $true
$val = "$($k.GetValue($packed))"
W ('{0}\{1}' -f $cfg.Label, $sub)
KV 'componentid' $sub
KV 'keypath' $val
$shared = @($vn | Where-Object { $_ -and $_ -ne $packed })
if ($shared.Count) { KV 'shared with' ($shared -join ', ') }
W ''
if ($val -match '^\d{2}:') {
[void]$compRegs.Add($val)
} elseif ($val -match '^[A-Za-z]:\\') {
[void]$compFiles.Add($val)
$n = Normalize-Path $val
if ($n) {
[void]$script:OwnPaths.Add($n)
[void]$script:OwnNames.Add([IO.Path]::GetFileName($n))
[void]$dirCand.Add((Split-Path $n -Parent))
}
}
}
$k.Close()
}
$root.Close()
}
$bk.Close()
}
if (-not $found) { W '<none>' }
if ($installLoc -and (Test-Path -LiteralPath $installLoc)) {
$il = $installLoc.TrimEnd('\').ToLower()
if ($script:SysDirs -notcontains $il) {
[void]$dirCand.Add($il)
Get-ChildItem -LiteralPath $installLoc -Recurse -File | ForEach-Object {
[void]$script:OwnPaths.Add($_.FullName.ToLower())
[void]$script:OwnNames.Add($_.Name.ToLower())
}
}
}
$script:OwnDirs = @($dirCand | Where-Object { $_ } | Sort-Object -Unique |
Where-Object { $script:SysDirs -notcontains $_ -and $_.Split('\').Count -ge 3 })
H '5. MSI DATABASE (cached package)'
if ($localPkg -and (Test-Path -LiteralPath $localPkg)) {
KV 'package' $localPkg
$pf = Get-FileFacts $localPkg
if ($pf) {
KV 'size' $pf.Size
KV 'created' $pf.Created
KV 'modified' $pf.Modified
KV 'sha256' $pf.SHA256
}
W ''
W '[Property]'
MsiTable $localPkg 'SELECT Property, Value FROM Property' |
ForEach-Object { W (' {0,-30} {1}' -f $_[0], $_[1]) }
W ''
W '[Registry] msi row -> live registry state'
$rows = @(MsiTable $localPkg 'SELECT Root, Key, Name, Value, Component_ FROM Registry')
if ($rows.Count -eq 0) { W ' <empty or unreadable>' }
foreach ($row in $rows) {
$hive = RootToHive $row[0]
$key = $row[1]
$name = $row[2]
$cands = switch ($hive) {
'HKLM' { @("HKLM:\SOFTWARE\$key", "HKLM:\SOFTWARE\WOW6432Node\$key", "HKLM:\$key") }
'HKMU' { @("HKLM:\SOFTWARE\$key", "HKLM:\SOFTWARE\WOW6432Node\$key",
"HKCU:\SOFTWARE\$key", "HKLM:\$key") }
'HKCU' { @("HKCU:\SOFTWARE\$key", "HKCU:\$key") }
'HKCR' { @("HKLM:\SOFTWARE\Classes\$key", "HKLM:\SOFTWARE\Classes\WOW6432Node\$key",
"HKCU:\SOFTWARE\Classes\$key") }
default { @("HKLM:\$key") }
}
$hitPath = $null
$hitVal = $null
foreach ($lp in $cands) {
if (Test-Path -LiteralPath $lp) {
$hitPath = Native $lp
if ($name) {
$lv = (Get-ItemProperty -LiteralPath $lp).$name
if ($null -ne $lv) { $hitVal = "$lv" }
}
break
}
}
W (' {0} {1}\{2}' -f $(if ($hitPath) { 'PRESENT' } else { 'ABSENT ' }), $hive, $key)
if ($name) { KV ' value name' $name }
KV ' msi value' $row[3]
if ($hitPath) {
KV ' live key' $hitPath
if ($name) { KV ' live value' $hitVal }
}
KV ' component' $row[4]
}
W ''
W '[Class]'
$cls = @(MsiTable $localPkg 'SELECT CLSID, Context, Component_, ProgId_Default, Description FROM Class')
if ($cls.Count -eq 0) { W ' <none>' }
foreach ($c in $cls) {
W (' {0} ctx={1} comp={2} progid={3} {4}' -f $c[0], $c[1], $c[2], $c[3], $c[4])
foreach ($lp in @("HKLM:\SOFTWARE\Classes\CLSID\$($c[0])",
"HKLM:\SOFTWARE\Classes\WOW6432Node\CLSID\$($c[0])",
"HKCU:\SOFTWARE\Classes\CLSID\$($c[0])")) {
if (-not (Test-Path -LiteralPath $lp)) { continue }
W (' LIVE {0}' -f (Native $lp))
foreach ($srv in @('InprocServer32', 'LocalServer32', 'InprocHandler32')) {
if (Test-Path -LiteralPath "$lp\$srv") {
W (' {0} = {1}' -f $srv, "$((Get-ItemProperty -LiteralPath "$lp\$srv").'(default)')")
}
}
}
}
W ''
W '[ProgId]'
$pg = @(MsiTable $localPkg 'SELECT ProgId, Class_, Description FROM ProgId')
if ($pg.Count -eq 0) { W ' <none>' }
foreach ($g in $pg) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\$($g[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1,-40} class={2} {3}' -f $st, $g[0], $g[1], $g[2])
}
W ''
W '[TypeLib]'
$tl = @(MsiTable $localPkg 'SELECT LibID, Version, Component_, Description FROM TypeLib')
if ($tl.Count -eq 0) { W ' <none>' }
foreach ($t in $tl) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\TypeLib\$($t[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1} ver={2} comp={3} {4}' -f $st, $t[0], $t[1], $t[2], $t[3])
}
W ''
W '[Extension]'
$ex = @(MsiTable $localPkg 'SELECT Extension, Component_, ProgId_, MIME_ FROM Extension')
if ($ex.Count -eq 0) { W ' <none>' }
foreach ($e in $ex) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\.$($e[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} .{1} comp={2} progid={3} mime={4}' -f $st, $e[0], $e[1], $e[2], $e[3])
}
W ''
W '[AppId]'
$ai = @(MsiTable $localPkg 'SELECT AppId, RemoteServerName, ServiceParameters, DllSurrogate FROM AppId')
if ($ai.Count -eq 0) { W ' <none>' }
foreach ($a in $ai) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\AppID\$($a[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1} surrogate={2}' -f $st, $a[0], $a[3])
}
W ''
W '[Directory]'
MsiTable $localPkg 'SELECT Directory, Directory_Parent, DefaultDir FROM Directory' |
ForEach-Object { W (' {0,-28} parent={1,-26} {2}' -f $_[0], $_[1], $_[2]) }
W ''
W '[Component]'
MsiTable $localPkg 'SELECT Component, ComponentId, Directory_, Attributes, KeyPath FROM Component' |
ForEach-Object { W (' {0,-30} {1,-40} dir={2,-22} attr={3,-6} key={4}' -f $_[0], $_[1], $_[2], $_[3], $_[4]) }
W ''
W '[File]'
MsiTable $localPkg 'SELECT File, Component_, FileName, FileSize, Version FROM File' |
ForEach-Object { W (' {0,-40} comp={1,-30} size={2,-10} ver={3}' -f ($_[2] -split '\|')[-1], $_[1], $_[3], $_[4]) }
W ''
W '[ServiceInstall]'
$si = @(MsiTable $localPkg 'SELECT ServiceInstall, Name, DisplayName, ServiceType, StartType, LoadOrderGroup, Dependencies, StartName, Password, Arguments, Component_ FROM ServiceInstall')
if ($si.Count -eq 0) { W ' <none>' }
foreach ($s in $si) {
W (' {0} name={1} disp={2} type={3} start={4} runas={5} args={6} comp={7}' -f
$s[0], $s[1], $s[2], $s[3], $s[4], $s[7], $s[9], $s[10])
}
W ''
W '[CustomAction]'
$ca = @(MsiTable $localPkg 'SELECT Action, Type, Source, Target FROM CustomAction')
if ($ca.Count -eq 0) { W ' <none>' }
foreach ($c in $ca) { W (' {0,-36} type={1,-8} src={2,-30} target={3}' -f $c[0], $c[1], $c[2], $c[3]) }
W ''
W '[Binary]'
$bn = @(MsiTable $localPkg 'SELECT Name FROM Binary')
if ($bn.Count -eq 0) { W ' <none>' }
foreach ($b in $bn) { W (' {0}' -f $b[0]) }
W ''
W '[InstallExecuteSequence]'
MsiTable $localPkg 'SELECT Action, Condition, Sequence FROM InstallExecuteSequence' |
Sort-Object { [int]$_[2] } |
ForEach-Object { W (' {0,-6} {1,-40} {2}' -f $_[2], $_[0], $_[1]) }
W ''
W '[Shortcut]'
$sc = @(MsiTable $localPkg 'SELECT Shortcut, Directory_, Name, Target, Arguments FROM Shortcut')
if ($sc.Count -eq 0) { W ' <none>' }
foreach ($s in $sc) {
W (' {0,-28} dir={1,-22} name={2,-28} target={3} {4}' -f $s[0], $s[1], ($s[2] -split '\|')[-1], $s[3], $s[4])
}
} else {
W '<cached msi unavailable>'
KV 'LocalPackage' $localPkg
}
H '6. LIVE COM REGISTRATION'
KV 'own files' $script:OwnPaths.Count
KV 'own dirs' $(if ($script:OwnDirs.Count) { $script:OwnDirs -join ' | ' } else { '<none>' })
$ign = @($dirCand | Sort-Object -Unique | Where-Object { $script:SysDirs -contains $_ })
if ($ign.Count) { KV 'ignored sysdirs' ($ign -join ' | ') }
W ''
if (-not $DoComSweep) {
W '<skipped: DoComSweep is false>'
} elseif ($script:OwnPaths.Count -eq 0 -and $script:OwnDirs.Count -eq 0) {
W '<no product binaries to match against>'
} else {
$hits = 0
foreach ($cfg in @(
@{ Hive = $HKLM; View = $V64; Label = 'HKLM(64)' },
@{ Hive = $HKLM; View = $V32; Label = 'HKLM(32)' },
@{ Hive = $HKCU; View = $V64; Label = 'HKCU' })) {
$bk = OpenBase $cfg.Hive $cfg.View
$root = $bk.OpenSubKey('SOFTWARE\Classes\CLSID')
if ($root) {
foreach ($clsid in $root.GetSubKeyNames()) {
$ck = $root.OpenSubKey($clsid)
if (-not $ck) { continue }
$subs = $ck.GetSubKeyNames()
foreach ($srv in @('InprocServer32', 'LocalServer32', 'InprocHandler32')) {
if ($subs -notcontains $srv) { continue }
$sk = $ck.OpenSubKey($srv)
if (-not $sk) { continue }
$raw = "$($sk.GetValue(''))"
if ($raw -and (Test-Own $raw)) {
$hits++
W ('{0}\SOFTWARE\Classes\CLSID\{1}' -f $cfg.Label, $clsid)
KV 'default' "$($ck.GetValue(''))"
KV $srv $raw
$tm = $sk.GetValue('ThreadingModel')
if ($tm) { KV 'ThreadingModel' $tm }
$ap = $ck.GetValue('AppID')
if ($ap) { KV 'AppID' $ap }
foreach ($e in @('ProgID', 'VersionIndependentProgID', 'TreatAs', 'Elevation')) {
if ($subs -contains $e) {
$ek = $ck.OpenSubKey($e)
if ($ek) { KV $e "$($ek.GetValue(''))"; $ek.Close() }
}
}
W ''
}
$sk.Close()
}
$ck.Close()
}
$root.Close()
}
$bk.Close()
}
foreach ($cfg in @(
@{ Hive = $HKLM; View = $V64; Label = 'HKLM(64)' },
@{ Hive = $HKLM; View = $V32; Label = 'HKLM(32)' })) {
$bk = OpenBase $cfg.Hive $cfg.View
$root = $bk.OpenSubKey('SOFTWARE\Classes\TypeLib')
if ($root) {
foreach ($lib in $root.GetSubKeyNames()) {
$lk = $root.OpenSubKey($lib)
if (-not $lk) { continue }
foreach ($ver in $lk.GetSubKeyNames()) {
$vk = $lk.OpenSubKey($ver)
if (-not $vk) { continue }
foreach ($plat in ($vk.GetSubKeyNames() | Where-Object { $_ -match '^win(32|64)$' })) {
$pk = $vk.OpenSubKey($plat)
if (-not $pk) { continue }
$d = "$($pk.GetValue(''))"
if ($d -and (Test-Own $d)) {
$hits++
W ('{0}\SOFTWARE\Classes\TypeLib\{1}\{2}\{3}' -f $cfg.Label, $lib, $ver, $plat)
KV 'typelib' $d
W ''
}
$pk.Close()
}
$vk.Close()
}
$lk.Close()
}
$root.Close()
}
$bk.Close()
}
if ($hits -eq 0) { W '<none>' }
}
H '7. APP PATHS / REGISTERED APPLICATIONS'
if ($script:OwnPaths.Count -eq 0 -and $script:OwnDirs.Count -eq 0) {
W '<no product binaries to match against>'
} else {
$hits = 0
foreach ($ap in @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths')) {
if (-not (Test-Path -LiteralPath $ap)) { continue }
Get-ChildItem -LiteralPath $ap | ForEach-Object {
$props = Get-ItemProperty -LiteralPath $_.PSPath
$d = "$($props.'(default)')"
$path = "$($props.Path)"
if ((Test-Own $d) -or (Test-Own $path) -or
$script:OwnNames.Contains($_.PSChildName.ToLower())) {
$script:hits++
W ('{0}\{1}' -f (Native $ap), $_.PSChildName)
KV 'default' $d
if ($path) { KV 'Path' $path }
W ''
}
}
}
foreach ($ra in @('HKLM:\SOFTWARE\RegisteredApplications',
'HKCU:\SOFTWARE\RegisteredApplications')) {
if (-not (Test-Path -LiteralPath $ra)) { continue }
$p = Get-ItemProperty -LiteralPath $ra
foreach ($pr in $p.PSObject.Properties) {
if ($pr.Name -like 'PS*') { continue }
$capKey = "HKLM:\SOFTWARE\$($pr.Value)"
if (-not (Test-Path -LiteralPath $capKey)) { continue }
$cap = Get-ItemProperty -LiteralPath $capKey
if ($cap.ApplicationIcon -and (Test-Own (($cap.ApplicationIcon -split ',')[0]))) {
$script:hits++
W ('{0} :: {1} = {2}' -f (Native $ra), $pr.Name, $pr.Value)
}
}
}
if ($script:hits -eq 0) { W '<none>' }
}
H '8. RAW REGISTRY SWEEP (productcode / packed guid)'
if (-not $DoRawSweep) {
W '<skipped: DoRawSweep is false>'
} else {
foreach ($term in @($pc, $shortPc, $packed)) {
W "term: $term"
$any = $false
foreach ($hive in @('HKLM', 'HKCU', 'HKCR', 'HKU')) {
$k = & reg.exe query $hive /f "$term" /s /k 2>$null | Where-Object { $_ -match '^HK' }
$d = & reg.exe query $hive /f "$term" /s /d 2>$null | Where-Object { $_ -match '^HK' }
if ($k) { $any = $true; $k | ForEach-Object { W " [key] $_" } }
if ($d) { $any = $true; $d | ForEach-Object { W " [data] $_" } }
}
if (-not $any) { W ' <none>' }
W ''
}
}
H '9. RAW REGISTRY SWEEP (displayname / publisher / binaries)'
if (-not $DoNameSweep) {
W '<skipped: DoNameSweep is false>'
} else {
$terms = @()
if ($displayName) { $terms += $displayName }
if ($publisher) { $terms += $publisher }
$script:OwnNames | ForEach-Object { $terms += $_ }
$terms = @($terms | Where-Object { $_ -and $_.Length -ge 5 } | Sort-Object -Unique)
if ($terms.Count -eq 0) { W '<no terms>' }
foreach ($term in $terms) {
W "term: $term"
$any = $false
foreach ($hive in @('HKLM', 'HKCU')) {
$k = & reg.exe query $hive /f "$term" /s /k 2>$null | Where-Object { $_ -match '^HK' }
$d = & reg.exe query $hive /f "$term" /s /d 2>$null | Where-Object { $_ -match '^HK' }
if ($k) { $any = $true; $k | ForEach-Object { W " [key] $_" } }
if ($d) { $any = $true; $d | ForEach-Object { W " [data] $_" } }
}
if (-not $any) { W ' <none>' }
W ''
}
}
H '10. FILES'
$fl = @($compFiles | Sort-Object -Unique)
if ($installLoc -and (Test-Path -LiteralPath $installLoc)) {
Get-ChildItem -LiteralPath $installLoc -Recurse -File | ForEach-Object { $fl += $_.FullName }
}
$fl = @($fl | Sort-Object -Unique)
if ($fl.Count -eq 0) { W '<none>' }
foreach ($f in $fl) {
if (-not (Test-Path -LiteralPath $f -PathType Leaf)) { W "MISSING $f"; continue }
$ff = Get-FileFacts $f
W $f
KV 'size' $ff.Size
KV 'created' $ff.Created
KV 'modified' $ff.Modified
KV 'company' $ff.Company
KV 'product' $ff.Product
KV 'description' $ff.Desc
KV 'origname' $ff.OrigName
KV 'internal' $ff.IntName
KV 'fileversion' $ff.FileVer
KV 'signature' $ff.SigStatus
KV 'signer' $ff.Signer
KV 'sha256' $ff.SHA256
W ''
}
H '11a. FLAT - REGISTRY KEYS PRESENT'
if ($touchedKeys.Count -eq 0) { W '<none>' }
($touchedKeys | Sort-Object -Unique) | ForEach-Object { W $_ }
H '11b. FLAT - REGISTRY KEYPATHS FROM COMPONENTS'
if ($compRegs.Count -eq 0) { W '<none>' }
foreach ($r in ($compRegs | Sort-Object -Unique)) {
W ('{0}\{1}' -f (KeyPathPrefixToHive $r.Substring(0, 2)), $r.Substring(3))
}
H '11c. FLAT - FILES'
if ($fl.Count -eq 0) { W '<none>' }
$fl | ForEach-Object { W $_ }
H '11d. FLAT - DIRECTORIES'
$dl = @()
if ($installLoc) { $dl += $installLoc.TrimEnd('\') }
$fl | ForEach-Object { $dl += (Split-Path $_ -Parent) }
$dl = @($dl | Where-Object { $_ } | Sort-Object -Unique)
if ($dl.Count -eq 0) { W '<none>' }
foreach ($d in $dl) {
$ex = Test-Path -LiteralPath $d -PathType Container
$ct = ''
if ($ex) { $ct = (Get-Item -LiteralPath $d).CreationTime.ToString('yyyy-MM-dd HH:mm:ss') }
W ('{0,-8} {1,-20} {2}' -f $(if ($ex) { 'EXISTS' } else { 'MISSING' }), $ct, $d)
}
}
W ''
W ('=' * 100)
W ('END total {0:N1}s' -f $script:SW.Elapsed.TotalSeconds)
W ('=' * 100)
EndPowerShell:
Comment: rifteyy's default fixlist template
Comment: The following are done automatically with this fixlist:
Comment: Checks and corrects the default Windows PATH environmental variable
Comment: Checks for internet connection, valid DNS
Comment: Checks for Windows RE status
Comment: Checks and repairs WMI repository
Comment: Restores original Windows services configuration
Comment: Restores PowerShell execution policy
Comment: Rebuilds performance counter library values
Comment: Resynchronizes performance counter library values to WMI
Comment: Enables file extensions
Comment: Enables recovery environment
Comment: Scans with HitmanPro from Sophos
Comment: Scans and cleans with AdwCleaner from Malwarebytes
Comment: Lists Windows Defender properties, settings
Comment: Lists drive info, identify possible damaged drives from Event Logs
Comment: Lists Discord's "index.js" files that are often targeted by malware (to store and execute malicious code)
Comment: Lists recent BSOD's
Comment: Lists all installed applications, folder contents along with SHA256 for purposes of identifying installed app malware
Comment: Lists 30 recent scheduled tasks
Comment: Lists recent Run (Windows + R) executed commands, can identify ClickFix attacks
Comment: Removes unwanted files (e.g. .exe, .com, .dll) from common folders (e.g. C:\ProgramData, AppData\Roaming) - these are not supposed to store any executable file types
Comment: Removes browser cache from Chrome, Firefox, Opera, Opera GX, Brave, Vivaldi, LibreWolf, Mullvad Browser, Zen
Comment: Removes policies
Comment: Removes active BITS tasks
Comment: Resets network
Comment: Removes proxy servers
Comment: Removes temporary files
Comment: Repairs system files
StartPowerShell:
# Checks default Windows PATH entries and repairs missing ones.
$ErrorActionPreference = 'Continue'
function Expand-PlainPath {
param([string]$Entry)
return [Environment]::ExpandEnvironmentVariables($Entry).TrimEnd('\')
}
# Templates expanded once to plain paths (C:\Windows\..., C:\Users\...)
$systemDefaults = @(
(Expand-PlainPath '%SystemRoot%\system32')
(Expand-PlainPath '%SystemRoot%')
(Expand-PlainPath '%SystemRoot%\System32\Wbem')
(Expand-PlainPath '%SystemRoot%\System32\WindowsPowerShell\v1.0')
(Expand-PlainPath '%SystemRoot%\System32\OpenSSH')
)
$userDefaults = @(
(Expand-PlainPath '%USERPROFILE%\AppData\Local\Microsoft\WindowsApps')
)
function Get-NormalizedPathEntries {
param([string]$Raw)
if ([string]::IsNullOrWhiteSpace($Raw)) { return @() }
return @(
$Raw -split ';' |
Where-Object { -not [string]::IsNullOrWhiteSpace($_) } |
ForEach-Object {
[Environment]::ExpandEnvironmentVariables($_.Trim().TrimEnd('\')).ToLowerInvariant()
}
)
}
function Get-CombinedPathEntries {
$machineRaw = [Environment]::GetEnvironmentVariable('Path', 'Machine')
$userRaw = [Environment]::GetEnvironmentVariable('Path', 'User')
return Get-NormalizedPathEntries -Raw ($machineRaw + ';' + $userRaw)
}
function Test-InPath {
param(
[string]$PlainPath,
[string[]]$NormalizedEntries
)
$key = $PlainPath.TrimEnd('\').ToLowerInvariant()
return $NormalizedEntries -contains $key
}
function Add-ToPath {
param(
[string]$PlainPath,
[ValidateSet('Machine', 'User')]
[string]$Scope
)
# always store plain path, never %VAR% form
$toAdd = $PlainPath.TrimEnd('\')
$current = [Environment]::GetEnvironmentVariable('Path', $Scope)
if ([string]::IsNullOrWhiteSpace($current)) {
[Environment]::SetEnvironmentVariable('Path', $toAdd, $Scope)
return
}
$normalized = Get-NormalizedPathEntries -Raw $current
$key = $toAdd.ToLowerInvariant()
if ($normalized -contains $key) { return }
$newPath = $current.TrimEnd(';') + ';' + $toAdd
[Environment]::SetEnvironmentVariable('Path', $newPath, $Scope)
}
function Write-Result {
param(
[string]$Entry,
[string]$Status
)
$label = $Entry.PadRight(58)
Write-Output ("{0} {1}" -f $label, $Status)
}
function Repair-AndVerify {
param(
[string]$PlainPath,
[ValidateSet('Machine', 'User')]
[string]$Scope
)
if (-not (Test-Path -LiteralPath $PlainPath)) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (no folder, cannot repair)'
return 'failed'
}
if ($Scope -eq 'Machine') {
$isAdmin = ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).
IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)
if (-not $isAdmin) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (need Admin to repair)'
return 'failed'
}
}
try {
Add-ToPath -PlainPath $PlainPath -Scope $Scope
}
catch {
Write-Result -Entry $PlainPath -Status "ATTENTION !!! MISSING (repair failed: $_)"
return 'failed'
}
# re-query PATH from registry and verify plain path is present
$after = Get-CombinedPathEntries
if (Test-InPath -PlainPath $PlainPath -NormalizedEntries $after) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING -> repaired (verified)'
return 'repaired'
}
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (repair ran, still missing after re-check)'
return 'failed'
}
$combined = Get-CombinedPathEntries
$hadMissing = $false
$repairFailed = $false
$repairedList = [System.Collections.Generic.List[string]]::new()
Write-Output 'PATH CHECK'
Write-Output ('-' * 72)
foreach ($entry in $systemDefaults) {
if (Test-InPath -PlainPath $entry -NormalizedEntries $combined) {
Write-Result -Entry $entry -Status 'OK'
continue
}
$hadMissing = $true
$result = Repair-AndVerify -PlainPath $entry -Scope Machine
if ($result -eq 'repaired') {
[void]$repairedList.Add($entry)
$combined = Get-CombinedPathEntries
}
else {
$repairFailed = $true
}
}
foreach ($entry in $userDefaults) {
if (Test-InPath -PlainPath $entry -NormalizedEntries $combined) {
Write-Result -Entry $entry -Status 'OK'
continue
}
$hadMissing = $true
$result = Repair-AndVerify -PlainPath $entry -Scope User
if ($result -eq 'repaired') {
[void]$repairedList.Add($entry)
$combined = Get-CombinedPathEntries
}
else {
$repairFailed = $true
}
}
Write-Output ('-' * 72)
if (-not $hadMissing) {
Write-Output 'RESULT: all default PATH entries present'
}
elseif ($repairedList.Count -gt 0 -and -not $repairFailed) {
Write-Output "RESULT: $($repairedList.Count) missing entry/entries repaired and verified - open a new terminal"
}
elseif ($repairedList.Count -gt 0 -and $repairFailed) {
Write-Output "RESULT: $($repairedList.Count) verified, some still missing - open a new terminal / run as Admin"
}
else {
Write-Output 'RESULT: missing entries not repaired (run as Admin for System PATH)'
}
if ($repairedList.Count -gt 0) {
Write-Output ''
Write-Output 'REPAIRED:'
foreach ($item in $repairedList) {
Write-Output " $item"
}
}
if ($hadMissing -or $repairFailed) {
exit 1
}
exit 0
EndPowerShell:
StartPowerShell:
# Check for internet connection
$ErrorActionPreference = 'Continue'
$dnsServers = @(
'1.1.1.1'
'8.8.8.8'
)
$hosts = @(
'google.com'
'cloudflare.com'
'malwarebytes.com'
)
function Write-Result {
param(
[string]$Label,
[string]$Status
)
Write-Output ("{0} {1}" -f $Label.PadRight(42), $Status)
}
function Test-DnsServer {
param([string]$Server)
$pingOk = $false
try {
$pingOk = Test-Connection -ComputerName $Server -Count 1 -Quiet -ErrorAction SilentlyContinue
}
catch { }
$resolveOk = $false
try {
$result = Resolve-DnsName -Name 'google.com' -Server $Server -Type A -DnsOnly -ErrorAction Stop
$ip = ($result | Where-Object { $_.IPAddress } | Select-Object -First 1).IPAddress
if ($ip) { $resolveOk = $true }
}
catch { }
# resolve is what matters; ping may be blocked
if ($resolveOk) { return 'OK' }
if ($pingOk) { return 'FAIL' }
return 'FAIL'
}
function Test-HostReachable {
param([string]$HostName)
try {
$dns = Resolve-DnsName -Name $HostName -Type A -ErrorAction Stop
$resolvedIp = ($dns | Where-Object { $_.IPAddress } | Select-Object -First 1).IPAddress
if (-not $resolvedIp) { return 'FAIL' }
}
catch {
return 'FAIL'
}
try {
$null = Invoke-WebRequest -Uri "https://$HostName" -UseBasicParsing -TimeoutSec 10 -MaximumRedirection 5 -ErrorAction Stop
return 'OK'
}
catch {
if ($_.Exception.Response) { return 'OK' }
return 'FAIL'
}
}
$failed = 0
Write-Output 'INTERNET CHECK'
Write-Output ('-' * 72)
Write-Output 'DNS SERVERS'
foreach ($server in $dnsServers) {
$status = Test-DnsServer -Server $server
Write-Result -Label $server -Status $status
if ($status -eq 'FAIL') { $failed++ }
}
Write-Output ''
Write-Output 'HOSTS'
foreach ($h in $hosts) {
$status = Test-HostReachable -HostName $h
Write-Result -Label $h -Status $status
if ($status -eq 'FAIL') { $failed++ }
}
Write-Output ('-' * 72)
if ($failed -eq 0) {
Write-Output 'RESULT: all checks passed'
exit 0
}
Write-Output "RESULT: $failed check(s) failed"
exit 1
EndPowerShell:
StartPowershell:
# Replace /scanonly with /clean if you also want to delete items -- however, this will activate a trial license on the system, I do not recommend it
$hmpExe = "$env:TEMP\HitmanPro_x64.exe"
$logFile = "$env:TEMP\HitmanPro_ScanLog.txt"
Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing
$proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru
if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 }
Get-Content $logFile -Encoding Unicode
EndPowershell:
StartPowerShell:
# Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console
# Does not clean preinstalled objects, only PUP/Adware
# If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument
# If you would like to only scan with it, change the argument from /clean to /scan
# NOTE: For the sake of users from Asia (primarily China), do not use the clean option. It will very likely remove a lot of their important software.
New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null
Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden
$logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile
Get-Content $logFile -Encoding Unicode
Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue
EndPowerShell:
Comment: List Windows Defender properties, settings
StartPowerShell:
function Write-Section {
param([string]$Title)
Write-Host ""
Write-Host "<=== $Title ===>"
}
Write-Section "Protection Status"
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntispywareEnabled, AntivirusEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, RealTimeProtectionEnabled, IsTamperProtected, NetworkProtectionStatus | Format-List
Write-Section "Signature / Engine Versions"
Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AntivirusSignatureVersion, AntispywareSignatureVersion | Format-List
Write-Section "Preferences / Configuration"
Get-MpPreference | Select-Object PUAProtection, MAPSReporting, SubmitSamplesConsent, CheckForSignaturesBeforeRunningScan, CloudBlockLevel, EnableNetworkProtection, DisableScriptScanning, DisableArchiveScanning, DisableRemovableDriveScanning, DisableScanningNetworkFiles, DisableScanningMappedNetworkDrivesForFullScan, DisableBlockAtFirstSeen, DisableHeuristics, DisableAutoExclusions | Format-List
Write-Section "Threat Detections"
$threats = Get-MpThreatDetection
if ($threats) {
$threats | Format-Table -AutoSize
} else {
Write-Host " (no threat detections found)"
}
EndPowerShell:
Comment: List drive info, identify possible damaged drives (thanks to AdvancedSetup from Malwarebytes for parts of these)
StartPowerShell:
param(
[int]$MaxEvents = 5000
)
$GPTTypeMap = @{
'EBD0A0A2-B9E5-4433-87C0-68B6B72699C7' = 'Microsoft Basic Data'
'E3C9E316-0B5C-4DB8-817D-F92DF00215AE' = 'Microsoft Reserved (MSR)'
'DE94BBA4-06D1-4D40-A16A-BFD50179D6AC' = 'Windows Recovery Environment (WinRE)'
'C12A7328-F81F-11D2-BA4B-00A0C93EC93B' = 'EFI System Partition'
'21686148-6449-6E6F-744E-656564454649' = 'BIOS Boot Partition'
'A19D880F-05FC-4D3B-A006-743F0F84911E' = 'OEM Partition'
'5808C8AA-7E8F-42E0-85D2-E1E90434CFB3' = 'Cluster Metadata Partition'
'48465300-0000-11AA-AA11-00306543ECAC' = 'Apple HFS/HFS+'
'7C3457EF-0000-11AA-AA11-00306543ECAC' = 'Apple APFS'
'0FC63DAF-8483-4772-8E79-3D69D8477DE4' = 'Linux Filesystem'
'0657FD6D-A4AB-43C4-84E5-0933C84B4F4F' = 'Linux Swap'
'E6D6D379-F507-44C2-A23C-238F2A3DF928' = 'Linux LVM'
}
$MBRTypeMap = @{
'01'='FAT12';'04'='FAT16 <32M';'05'='Extended';'06'='FAT16';'07'='IFS/NTFS/exFAT/HPFS';'0B'='FAT32 CHS';'0C'='FAT32 LBA';'0E'='FAT16 LBA'
'0F'='Extended LBA';'82'='Linux Swap';'83'='Linux Native';'8E'='Linux LVM';'A5'='FreeBSD';'A6'='OpenBSD';'A8'='Mac OS X';'AB'='Mac OS X Boot'
'AF'='Mac OS X HFS';'EE'='EFI GPT Protective';'EF'='EFI System Partition'
}
function Get-PartitionTypeInfo {
param($Partition)
$guid = $null
if ($Partition.GptType) {
$guid = ($Partition.GptType -replace '[{}]', '').ToUpper()
}
if ([string]::IsNullOrWhiteSpace($guid) -or $guid -eq '00000000-0000-0000-0000-000000000000') {
$guid = switch ($Partition.Type) {
"System" { "C12A7328-F81F-11D2-BA4B-00A0C93EC93B" }
"Reserved" { "E3C9E316-0B5C-4DB8-817D-F92DF00215AE" }
"Basic" { "EBD0A0A2-B9E5-4433-87C0-68B6B72699C7" }
"Recovery" { "DE94BBA4-06D1-4D40-A16A-BFD50179D6AC" }
default { $null }
}
}
if ($guid) {
$name = $GPTTypeMap[$guid]
if ($name) { return "$name (GPT GUID: $($guid.ToLower()))" }
else { return "Unknown/Custom (GPT GUID: $($guid.ToLower()))" }
}
if ($Partition.MbrType) {
$code = ($Partition.MbrType.ToString() -replace '^0x', '').PadLeft(2, '0').ToUpper()
$name = $MBRTypeMap[$code]
if ($name) { return "$name (MBR code: 0x$code)" }
else { return "Unknown/Custom (MBR code: $($Partition.MbrType))" }
}
return $Partition.Type
}
function Get-DrMapping {
param([int]$MaxEvents)
$map = @{}
try {
$events = Get-WinEvent -FilterHashtable @{ LogName = 'System'; ProviderName = 'disk' } -MaxEvents $MaxEvents -ErrorAction Stop
} catch {
return $map
}
foreach ($e in $events) {
if ($e.Message -match 'Harddisk(\d+)\\DR(\d+)') {
$n = [int]$Matches[1]
$dr = [int]$Matches[2]
if (-not $map.ContainsKey($n)) { $map[$n] = $dr }
}
}
return $map
}
$drMap = Get-DrMapping -MaxEvents $MaxEvents
$physicalDisks = Get-PhysicalDisk | Select-Object DeviceId, FriendlyName, SerialNumber, MediaType, @{N='SizeGB';E={[math]::Round($_.Size / 1GB,2)}}
foreach ($pd in $physicalDisks) {
$devId = [int]$pd.DeviceId
$drSuffix = if ($drMap.ContainsKey($devId)) { "\DR$($drMap[$devId])" } else { '\DR? (no event seen yet)' }
Write-Host ""
Write-Host "<=== \Device\Harddisk$devId$drSuffix ($($pd.FriendlyName)) ===>"
Write-Host " DeviceId: $devId | Serial: $($pd.SerialNumber) | Media: $($pd.MediaType) | Size: $($pd.SizeGB) GB"
try {
$partitions = Get-Partition -DiskNumber $devId -ErrorAction Stop
if (-not $partitions) {
Write-Host " (no partitions found)"
continue
}
foreach ($part in $partitions) {
$driveLetter = if ($part.DriveLetter) { "$($part.DriveLetter):" } else { 'no letter' }
$sizeGB = [math]::Round($part.Size / 1GB, 2)
$typeInfo = Get-PartitionTypeInfo -Partition $part
Write-Host " [PARTITION $($part.PartitionNumber)] Drive: $driveLetter - $sizeGB GB - $typeInfo"
}
} catch {
Write-Host " [ERROR] cannot read partitions for disk $devId"
}
}
if ($drMap.Count -eq 0) {
Write-Host ""
Write-Host "Note: no \Device\HarddiskN\DRx entries found in the last $MaxEvents System log events. Increase -MaxEvents, or the DR number will only appear once Windows actually logs a disk event for that drive (e.g. a bad block warning)."
}
EndPowerShell:
Comment: Verify that Discord does not have any injected code to intercept personal data. If anything is prompted here, it needs to be checked that it isn't malicious code.
Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) }
StartPowerShell:
# Basic BSOD listings
$ccKey = "HKLM:\SYSTEM\CurrentControlSet\Control\CrashControl"
$cfg = Get-ItemProperty $ccKey -ErrorAction SilentlyContinue
$dumpTypeMap = @{0='None';1='Complete';2='Kernel';3='Minidump';7='Automatic'}
Write-Output "--- Configuration ---"
Write-Output ("Dump Type: {0} ({1})" -f $cfg.CrashDumpEnabled, $dumpTypeMap[$cfg.CrashDumpEnabled])
Write-Output ("Full Dump Path: {0}" -f $(if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}))
Write-Output ("Minidump Folder: {0}" -f $(if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}))
Write-Output ("Auto Reboot: {0}" -f $(if($cfg.AutoReboot -eq 0){'Disabled'}else{'Enabled'}))
Write-Output "--- Found Dump Files ---"
$full = if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}
if (Test-Path $full) { Get-Item $full | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
$mini = if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}
if (Test-Path $mini) { Get-ChildItem $mini -Filter *.dmp | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
Write-Output "--- BugCheck Reasoning (recent events) ---"
$map = @{
'0x0000000A'='IRQL_NOT_LESS_OR_EQUAL - faulty/outdated driver accessed memory at high IRQL'
'0x0000001E'='KMODE_EXCEPTION_NOT_HANDLED - unhandled kernel exception, often driver/hardware'
'0x0000002E'='DATA_BUS_ERROR - typically bad RAM or hardware fault'
'0x0000003B'='SYSTEM_SERVICE_EXCEPTION - exception in a system service, often driver-related'
'0x00000050'='PAGE_FAULT_IN_NONPAGED_AREA - bad RAM or faulty driver/antivirus'
'0x0000007A'='KERNEL_DATA_INPAGE_ERROR - disk-related problem'
'0x0000007B'='INACCESSIBLE_BOOT_DEVICE - system could not find/access the boot device'
'0x0000007E'='SYSTEM_THREAD_EXCEPTION_NOT_HANDLED - almost always a faulty driver'
'0x0000007F'='UNEXPECTED_KERNEL_MODE_TRAP - hardware issue (CPU/RAM/overclocking)'
'0x0000009F'='DRIVER_POWER_STATE_FAILURE - driver failed to respond to a power state change'
'0x000000C2'='BAD_POOL_CALLER - driver mishandling memory (pool corruption)'
'0x000000D1'='DRIVER_IRQL_NOT_LESS_OR_EQUAL - typically a network or GPU driver'
'0x000000EF'='CRITICAL_PROCESS_DIED - a critical system process died, often malware/system corruption'
'0x00000116'='VIDEO_TDR_FAILURE - GPU driver failed to respond in time (timeout)'
'0x00000124'='WHEA_UNCORRECTABLE_ERROR - hardware fault (CPU/RAM/PSU/overclocking)'
'0x00000133'='DPC_WATCHDOG_VIOLATION - faulty driver or storage subsystem issue'
'0x00000139'='KERNEL_SECURITY_CHECK_FAILURE - corrupted kernel structure, possibly malware'
}
$events = Get-WinEvent -FilterHashtable @{LogName='System';Id=1001} -MaxEvents 100 -ErrorAction SilentlyContinue |
Where-Object { $_.ProviderName -match 'WER-SystemErrorReporting' } | Select-Object -First 5
if (-not $events) { Write-Output "No BugCheck events found in the log." }
foreach ($ev in $events) {
$code = if ($ev.Message -match 'bugcheck was:\s*(0x[0-9A-Fa-f]+)') { $matches[1] } else { $null }
Write-Output ("Time: {0}" -f $ev.TimeCreated)
Write-Output ("Code: {0}" -f $(if($code){$code}else{'not recognized'}))
if ($code -and $map.ContainsKey($code.ToUpper())) {
Write-Output ("Meaning: {0}" -f $map[$code.ToUpper()])
} elseif ($code) {
Write-Output "Meaning: unknown code, look up at learn.microsoft.com/windows-hardware/drivers/debugger/bug-check-code-reference2"
}
Write-Output ""
}
EndPowerShell:
StartPowerShell:
# This snippet lists all installed apps and their folder contents along with SHA256 hashes. Useful for troubleshooting malware abusing installed app entry.
param(
[switch]$Recurse,
[int]$MaxFilesPerApp = [int]::MaxValue
)
$uninstallPaths = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
$script:msiInstaller = $null
function Get-MsiInstallLocation {
param([string]$ProductCode)
if (-not $script:msiInstaller) {
try { $script:msiInstaller = New-Object -ComObject WindowsInstaller.Installer } catch { return $null }
}
try {
$loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallLocation')
if ([string]::IsNullOrWhiteSpace($loc)) { $loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallSource') }
if ([string]::IsNullOrWhiteSpace($loc)) { return $null }
return $loc
} catch { return $null }
}
function Get-CleanPath {
param([string]$RawValue)
if ([string]::IsNullOrWhiteSpace($RawValue)) { return $null }
$s = $RawValue.Trim()
if ($s.StartsWith('"')) {
$endQuote = $s.IndexOf('"', 1)
if ($endQuote -gt 0) { return $s.Substring(1, $endQuote - 1) }
}
if ($s -match '^(.*?\.exe)\b') { return $Matches[1] }
return $s
}
function Format-FileSize {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$script:PeExtensions = @('.exe', '.dll', '.sys', '.ocx', '.cpl', '.scr', '.drv', '.efi', '.msi', '.msp', '.msu')
function Test-IsPeFile {
param([string]$Extension)
return $script:PeExtensions -contains $Extension.ToLower()
}
function Get-SignatureInfo {
param([string]$Path, [string]$Extension)
if (-not (Test-IsPeFile -Extension $Extension)) {
return [PSCustomObject]@{ Signer = 'N/A (not PE)'; Status = 'NotApplicable'; Valid = $false }
}
$result = [PSCustomObject]@{ Signer = 'Unsigned'; Status = 'NotSigned'; Valid = $false }
try {
$sig = Get-AuthenticodeSignature -LiteralPath $Path -ErrorAction Stop
$result.Status = $sig.Status.ToString()
$result.Valid = ($sig.Status -eq 'Valid')
if ($sig.SignerCertificate) {
if ($sig.SignerCertificate.Subject -match 'CN=([^,]+)') { $result.Signer = $Matches[1].Trim('"') }
else { $result.Signer = $sig.SignerCertificate.Subject }
if (-not $result.Valid) { $result.Signer += " [INVALID: $($result.Status)]" }
} elseif ($sig.Status -eq 'NotSigned') {
$result.Signer = 'Unsigned'
} else {
$result.Signer = "Unknown [$($result.Status)]"
}
} catch {
$result.Signer = 'Verification error'
$result.Status = 'Error'
$result.Valid = $false
}
return $result
}
$rawApps = Get-ItemProperty -Path $uninstallPaths -ErrorAction SilentlyContinue |
Where-Object { $_.DisplayName -and $_.DisplayName.Trim() -ne '' } |
Select-Object @{Name = 'Name'; Expression = { $_.DisplayName } },
@{Name = 'Version'; Expression = { $_.DisplayVersion } },
@{Name = 'Publisher'; Expression = { $_.Publisher } },
@{Name = 'InstallFolder'; Expression = {
if ($_.InstallLocation -and $_.InstallLocation.Trim() -ne '') { $_.InstallLocation }
elseif ($_.UninstallString -match 'MsiExec\.exe.*?(\{[0-9A-Fa-f\-]{36}\})') {
$productCode = $Matches[1]
$msiLoc = Get-MsiInstallLocation -ProductCode $productCode
if ($msiLoc) { $msiLoc } else { "MSI: $productCode (location not found)" }
}
elseif ($_.UninstallString) { $_.UninstallString }
else { 'N/A' }
} } |
Sort-Object Name -Unique
foreach ($app in $rawApps) {
$versionText = if ($app.Version) { $app.Version } else { '?' }
$publisherText = if ($app.Publisher) { $app.Publisher } else { '?' }
Write-Host ""
Write-Host "<=== $($app.Name) [$versionText] ($publisherText) ===>"
if ($app.InstallFolder -eq 'N/A' -or $app.InstallFolder -match '^MSI: .* \(location not found\)$') {
Write-Host " Path: $($app.InstallFolder)"
continue
}
$cleanPath = Get-CleanPath -RawValue $app.InstallFolder
$exists = $false
try {
$exists = Test-Path -LiteralPath $cleanPath -ErrorAction Stop
} catch [System.UnauthorizedAccessException] {
Write-Host " Path: $cleanPath"
Write-Host " [ACCESS DENIED]"
continue
} catch {
Write-Host " Path: $cleanPath"
Write-Host " [ERROR] cannot access"
continue
}
if (-not $exists) {
Write-Host " Path: $cleanPath"
Write-Host " [NOT FOUND]"
continue
}
$rootItem = Get-Item -LiteralPath $cleanPath -Force
$created = $rootItem.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$modified = $rootItem.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
if ($rootItem.PSIsContainer) {
$subFolders = Get-ChildItem -LiteralPath $cleanPath -Directory -Force -ErrorAction SilentlyContinue
$gciParams = @{ LiteralPath = $cleanPath; File = $true; Force = $true; ErrorAction = 'SilentlyContinue' }
if ($Recurse) { $gciParams['Recurse'] = $true }
$allFiles = Get-ChildItem @gciParams
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: $($allFiles.Count) | Folders: $($subFolders.Count)"
foreach ($dir in $subFolders) {
$dCreated = $dir.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$dModified = $dir.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$dFileCount = (Get-ChildItem -LiteralPath $dir.FullName -File -Force -ErrorAction SilentlyContinue).Count
Write-Host (" [DIR] {0} - {1} - {2,10} - {3}" -f $dCreated, $dModified, "$dFileCount files", $dir.FullName)
}
} else {
$allFiles = @($rootItem)
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: 1"
}
if ($allFiles.Count -eq 0) { continue }
$shown = $allFiles | Select-Object -First $MaxFilesPerApp
foreach ($f in $shown) {
$hash = 'N/A'
try { $hash = (Get-FileHash -LiteralPath $f.FullName -Algorithm SHA256 -ErrorAction Stop).Hash } catch { $hash = 'HASH-ERROR' }
$size = Format-FileSize -Bytes $f.Length
$fcreated = $f.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$fmod = $f.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$sigInfo = Get-SignatureInfo -Path $f.FullName -Extension $f.Extension
Write-Host (" [{0}] {1} - {2} - {3,10} - Signer: {4} - {5}" -f $hash, $fcreated, $fmod, $size, $sigInfo.Signer, $f.FullName)
}
}
EndPowerShell:
Comment: List 30 recent scheduled tasks
Powershell: Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo
Comment: List recent Run (Windows + R) executed commands, useful for identifying ClickFix attacks
Powershell: (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" }
Comment: Remove unwanted files from common folders using native removal power of Farbar to include remove on reboot if needed. Please double check the user does not have any applications incorrectly installed in the directories listed below.
C:\ProgramData\*.csproj
C:\ProgramData\*.a3x
C:\ProgramData\*.ahk
C:\ProgramData\*.au3
C:\ProgramData\*.bat
C:\ProgramData\*.cab
C:\ProgramData\*.cmd
C:\ProgramData\*.com
C:\ProgramData\*.dll
C:\ProgramData\*.exe
C:\ProgramData\*.hta
C:\ProgramData\*.jar
C:\ProgramData\*.js
C:\ProgramData\*.jse
C:\ProgramData\*.lnk
C:\ProgramData\*.pif
C:\ProgramData\*.ps1
C:\ProgramData\*.py
C:\ProgramData\*.pyc
C:\ProgramData\*.pyd
C:\ProgramData\*.scr
C:\ProgramData\*.tmp
C:\ProgramData\*.vbe
C:\ProgramData\*.vbs
C:\ProgramData\*.wsf
C:\ProgramData\*.wsh
C:\ProgramData\*.zip
C:\ProgramData\*.rar
C:\ProgramData\*.7z
C:\Users\*\AppData\Roaming\*.csproj
C:\Users\*\AppData\Roaming\*.au3
C:\Users\*\AppData\Roaming\*.bat
C:\Users\*\AppData\Roaming\*.cab
C:\Users\*\AppData\Roaming\*.cmd
C:\Users\*\AppData\Roaming\*.com
C:\Users\*\AppData\Roaming\*.dll
C:\Users\*\AppData\Roaming\*.exe
C:\Users\*\AppData\Roaming\*.hta
C:\Users\*\AppData\Roaming\*.jar
C:\Users\*\AppData\Roaming\*.js
C:\Users\*\AppData\Roaming\*.jse
C:\Users\*\AppData\Roaming\*.lnk
C:\Users\*\AppData\Roaming\*.pif
C:\Users\*\AppData\Roaming\*.ps1
C:\Users\*\AppData\Roaming\*.py
C:\Users\*\AppData\Roaming\*.pyc
C:\Users\*\AppData\Roaming\*.pyd
C:\Users\*\AppData\Roaming\*.scr
C:\Users\*\AppData\Roaming\*.tmp
C:\Users\*\AppData\Roaming\*.vbe
C:\Users\*\AppData\Roaming\*.vbs
C:\Users\*\AppData\Roaming\*.wsf
C:\Users\*\AppData\Roaming\*.wsh
C:\Users\*\AppData\Roaming\*.zip
C:\Users\*\AppData\Roaming\*.rar
C:\Users\*\AppData\Roaming\*.7z
C:\Users\CurrentUserName\AppData\Local\*.csproj
C:\Users\CurrentUserName\AppData\Local\*.a3x
C:\Users\CurrentUserName\AppData\Local\*.ahk
C:\Users\CurrentUserName\AppData\Local\*.au3
C:\Users\CurrentUserName\AppData\Local\*.bat
C:\Users\CurrentUserName\AppData\Local\*.cab
C:\Users\CurrentUserName\AppData\Local\*.cmd
C:\Users\CurrentUserName\AppData\Local\*.com
C:\Users\CurrentUserName\AppData\Local\*.dll
C:\Users\CurrentUserName\AppData\Local\*.exe
C:\Users\CurrentUserName\AppData\Local\*.hta
C:\Users\CurrentUserName\AppData\Local\*.jar
C:\Users\CurrentUserName\AppData\Local\*.js
C:\Users\CurrentUserName\AppData\Local\*.jse
C:\Users\CurrentUserName\AppData\Local\*.lnk
C:\Users\CurrentUserName\AppData\Local\*.pif
C:\Users\CurrentUserName\AppData\Local\*.ps1
C:\Users\CurrentUserName\AppData\Local\*.py
C:\Users\CurrentUserName\AppData\Local\*.pyc
C:\Users\CurrentUserName\AppData\Local\*.pyd
C:\Users\CurrentUserName\AppData\Local\*.scr
C:\Users\CurrentUserName\AppData\Local\*.tmp
C:\Users\CurrentUserName\AppData\Local\*.vbe
C:\Users\CurrentUserName\AppData\Local\*.vbs
C:\Users\CurrentUserName\AppData\Local\*.wsf
C:\Users\CurrentUserName\AppData\Local\*.wsh
C:\Users\CurrentUserName\AppData\Local\*.zip
C:\Users\CurrentUserName\AppData\Local\*.rar
C:\Users\CurrentUserName\AppData\Local\*.7z
C:\Users\CurrentUserName\AppData\Roaming\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\*.a3x
C:\Users\CurrentUserName\AppData\Roaming\*.ahk
C:\Users\CurrentUserName\AppData\Roaming\*.au3
C:\Users\CurrentUserName\AppData\Roaming\*.bat
C:\Users\CurrentUserName\AppData\Roaming\*.cab
C:\Users\CurrentUserName\AppData\Roaming\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\*.com
C:\Users\CurrentUserName\AppData\Roaming\*.dll
C:\Users\CurrentUserName\AppData\Roaming\*.exe
C:\Users\CurrentUserName\AppData\Roaming\*.hta
C:\Users\CurrentUserName\AppData\Roaming\*.jar
C:\Users\CurrentUserName\AppData\Roaming\*.js
C:\Users\CurrentUserName\AppData\Roaming\*.jse
C:\Users\CurrentUserName\AppData\Roaming\*.lnk
C:\Users\CurrentUserName\AppData\Roaming\*.pif
C:\Users\CurrentUserName\AppData\Roaming\*.ps1
C:\Users\CurrentUserName\AppData\Roaming\*.py
C:\Users\CurrentUserName\AppData\Roaming\*.pyc
C:\Users\CurrentUserName\AppData\Roaming\*.pyd
C:\Users\CurrentUserName\AppData\Roaming\*.scr
C:\Users\CurrentUserName\AppData\Roaming\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\*.vbe
C:\Users\CurrentUserName\AppData\Roaming\*.vbs
C:\Users\CurrentUserName\AppData\Roaming\*.wsf
C:\Users\CurrentUserName\AppData\Roaming\*.wsh
C:\Users\CurrentUserName\AppData\Roaming\*.zip
C:\Users\CurrentUserName\AppData\Roaming\*.rar
C:\Users\CurrentUserName\AppData\Roaming\*.7z
Comment: Remove browser cache
StartPowerShell:
$ProfilesDirectory = (Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList').ProfilesDirectory
$DisplayNames = @{
"chrome" = "Chrome"
"firefox" = "Firefox"
"opera" = "Opera"
"operagx" = "Opera GX"
"brave" = "Brave"
"msedge" = "Edge"
"vivaldi" = "Vivaldi"
"librewolf" = "LibreWolf"
"mullvad" = "Mullvad Browser"
"zen" = "Zen"
}
$ProcessNameMap = @{
"operagx" = "opera"
"mullvad" = "mullvadbrowser"
}
$trueCacheNames = @("Cache", "Code Cache", "DawnCache", "GPUCache", "GrShaderCache", "ShaderCache", "Shared Dictionary\cache")
function Get-CacheDirs {
param([string]$BrowserName, [string]$ProfilesDirectory)
switch ($BrowserName) {
"chrome" {
$dir = "$ProfilesDirectory\*\AppData\Local\Google\Chrome\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"firefox" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mozilla\Firefox\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"opera" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"operagx" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software\Opera GX Stable"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software\Opera GX Stable"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"brave" {
$dir = "$ProfilesDirectory\*\AppData\Local\BraveSoftware\Brave-Browser\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"msedge" {
$dir = "$ProfilesDirectory\*\AppData\Local\Microsoft\Edge\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"vivaldi" {
$dir = "$ProfilesDirectory\*\AppData\Local\Vivaldi\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"librewolf" {
$dir = "$ProfilesDirectory\*\AppData\Local\LibreWolf\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"mullvad" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mullvad\MullvadBrowser\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"zen" {
$dir = "$ProfilesDirectory\*\AppData\Local\zen\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
}
}
function Format-Size {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$BrowserKeys = @('chrome', 'firefox', 'opera', 'operagx', 'brave', 'msedge', 'vivaldi', 'librewolf', 'mullvad', 'zen')
foreach ($key in $BrowserKeys) {
$procName = if ($ProcessNameMap.ContainsKey($key)) { $ProcessNameMap[$key] } else { $key }
Get-Process -Name $procName -ErrorAction SilentlyContinue | Stop-Process -Force -ErrorAction SilentlyContinue
}
Start-Sleep -Seconds 5
$grandBytes = 0L
$grandFiles = 0
$anyFound = $false
foreach ($key in $BrowserKeys) {
$cacheDirs = Get-CacheDirs -BrowserName $key -ProfilesDirectory $ProfilesDirectory
if (-not $cacheDirs -or $cacheDirs.Count -eq 0) { continue }
$anyFound = $true
$displayName = $DisplayNames[$key]
$browserBytes = 0L
$browserFiles = 0
foreach ($cacheDir in $cacheDirs) {
if (-not (Test-Path $cacheDir)) { continue }
$items = Get-ChildItem -Path $cacheDir -Force -Recurse -ErrorAction SilentlyContinue
$files = $items | Where-Object { -not $_.PSIsContainer }
$bytes = ($files | Measure-Object -Property Length -Sum).Sum
if (-not $bytes) { $bytes = 0 }
$browserFiles += $files.Count
$browserBytes += $bytes
Get-ChildItem -Path "$cacheDir\*" -Force -ErrorAction SilentlyContinue | Remove-Item -Force -Recurse -ErrorAction SilentlyContinue
}
$grandBytes += $browserBytes
$grandFiles += $browserFiles
Write-Host ("{0,-16} freed {1,10} ({2} files)" -f $displayName, (Format-Size $browserBytes), $browserFiles)
}
if (-not $anyFound) {
Write-Host "No cache found for any installed browser."
}
Write-Host ""
Write-Host ("Total freed: {0} ({1} files)" -f (Format-Size $grandBytes), $grandFiles)
EndPowerShell:
Comment: Windows Recovery Environment (Windows RE) status
CMD: reagentc.exe /info
Comment: Disable hidden file extensions
cmd: reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "HideFileExt" /t REG_DWORD /d 0 /f
cmd: reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt" /v "CheckedValue" /t REG_DWORD /d 0 /f
Comment: Verify WMI repository, repair & verify again
CMD: winmgmt.exe /verifyrepository
CMD: winmgmt.exe /salvagerepository
CMD: winmgmt.exe /verifyrepository
Comment: To rebuild the performance counter library values
CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R"
CMD: "%WINDIR%\SysWOW64\lodctr.exe /R"
CMD: "C:\Windows\SYSTEM32\lodctr.exe /R"
CMD: "C:\Windows\SysWOW64\lodctr.exe /R"
Comment: Resync performance counter library values to WMI as well
CMD: winmgmt.exe /resyncperf
Comment: Force policy removal
C:\Windows\System32\GroupPolicyUsers
C:\Windows\System32\GroupPolicy
CMD: gpupdate.exe /force
Comment: Enable recovery environment
CMD: bcdedit.exe /set {default} recoveryenabled yes
Comment: Restore original Windows services configuration
StartPowerShell:
Set-Service -Name "Netlogon" -StartupType Manual
Set-Service -Name "BITS" -StartupType Manual
Set-Service -Name "Dhcp" -StartupType Automatic
Set-Service -Name "EventLog" -StartupType Automatic
Set-Service -Name "EventSystem" -StartupType Automatic
Set-Service -Name "nsi" -StartupType Automatic
Set-Service -Name "RasMan" -StartupType Manual
Set-Service -Name "SDRSVC" -StartupType Manual
Set-Service -Name "SstpSvc" -StartupType Manual
Set-Service -Name "TrustedInstaller" -StartupType Manual
Set-Service -Name "VSS" -StartupType Manual
Set-Service -Name "Winmgmt" -StartupType Automatic
Set-Service -Name "wuauserv" -StartupType Manual
EndPowerShell:
Comment: Reset PowerShell execution policy
Powershell: Set-ExecutionPolicy Unrestricted -Scope CurrentUser -Force
Comment: BITS reset
Startbatch:
@echo off
net.exe stop BITS
ipconfig.exe /flushdns
ren "%programdata%\Microsoft\Network\Downloader\qmgr*.*" qmgr*.*.old
net.exe start BITS
Endbatch:
cmd: bitsadmin.exe /reset /allusers
Comment: Network reset commands
CMD: ipconfig.exe /release
CMD: ipconfig.exe /release6
CMD: netsh.exe winhttp reset proxy
CMD: netsh.exe int ip reset
CMD: netsh.exe int ipv6 reset
CMD: netsh.exe int tcp reset
CMD: netsh.exe winsock reset
CMD: netsh.exe branchcache reset
CMD: ipconfig.exe /flushDNS
CMD: arp.exe -d *
CMD: nbtstat.exe -R
CMD: route.exe -f
CMD: ipconfig.exe /renew
CMD: nbtstat.exe -RR
CMD: ipconfig.exe /registerdns
CMD: ipconfig.exe /all
Comment: Additional temp file removal
C:\Windows\System32\config\systemprofile\AppData\Local\*.tmp
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
C:\Users\CurrentUserName\AppData\Local\Temp\*
C:\Windows\Temp\*
C:\Windows\SystemTemp\*
C:\Windows\Prefetch\*
Comment: System repair commands
CMD: SFC.exe /scannow
CMD: DISM.exe /Online /Cleanup-image /Restorehealth
Comment: Remove set proxy servers
RemoveProxy:
Comment: Remove temporary files via FRST
EmptyTemp:
End::
Warning
Executing a Fixlist on the wrong system may permanently damage it. Continue only if this link was meant for you.
To view the content, acknowledge this warning.