content copied
content
Start::
CloseProcesses:
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{490DAA44-7D30-428D-B437-32398D6890D5}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2976900799-3423729617-4255589462-1003\Products\44AAD09403D7D8244B732393D886095D
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\6999EC0E4108D4641A7C1BC37D80ECE0
Unlock: C:\WINDOWS\Installer\57ab4578.msi
StartPowerShell:
# This snippet uses Sysinternals Sigcheck to upload file on VirusTotal.
# Change the line containing the string "INSERTFILEPATHHERE" to the desired filepath
# ---
# It displays the following: entropy, file hashes, catalog name & signing chain, VirusTotal scan results and link to it.
# It is also able to traverse symbolic links and directory junctions.
# ---
# NOTE: If the file is not known prior, it gets uploaded to VirusTotal and the result will be available in a few minutes.
# You can search up the report by visiting the URL "https://www.virustotal.com/gui/file/<SHA256>"
$TempDir = [System.IO.Path]::GetTempPath()
$ZipPath = Join-Path $TempDir "SigcheckFRST.zip"
$ExtractPath = Join-Path $TempDir "SigcheckFRST"
Invoke-WebRequest -Uri "https://download.sysinternals.com/files/Sigcheck.zip" -OutFile $ZipPath -UseBasicParsing
if (Test-Path $ExtractPath) { Remove-Item $ExtractPath -Recurse -Force }
Expand-Archive -Path $ZipPath -DestinationPath $ExtractPath -Force
$SigcheckExe = Join-Path $ExtractPath "sigcheck.exe"
if (Test-Path $SigcheckExe) {
$psi = New-Object System.Diagnostics.ProcessStartInfo
$psi.FileName = $SigcheckExe
$psi.Arguments = '-accepteula -a -h -i -m -l -vt -vs -nobanner "C:\WINDOWS\Installer\57ab4578.msi"'
$psi.RedirectStandardOutput = $true
$psi.StandardOutputEncoding = [System.Text.Encoding]::Unicode
$psi.UseShellExecute = $false
$psi.CreateNoWindow = $true
$p = [System.Diagnostics.Process]::Start($psi)
$output = $p.StandardOutput.ReadToEnd()
$p.WaitForExit()
Write-Output $output
} else {
Write-Host "Error: Sigcheck does not exist"
}
Remove-Item $ZipPath -Force
EndPowerShell:
C:\WINDOWS\Installer\57ab4578.msi
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6A59175F-21C3-4E1A-9945-8F7459BF70E8}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2976900799-3423729617-4255589462-1003\Products\F57195A63C12A1E49954F84795FB078E
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\1F306914E5BB2DD4A868E1A8D8EB0EAD
Unlock: C:\WINDOWS\Installer\57ab456f.msi
C:\WINDOWS\Installer\57ab456f.msi
FirewallRules: [UDP Query User{DCF7C8BF-F603-4559-8808-49425D3A0E26}D:\games\nah\dddd\the arrogant kaiju princess and the detective servant v1.06\the detective servant.exe] => (Block) D:\games\nah\dddd\the arrogant kaiju princess and the detective servant v1.06\the detective servant.exe => No File
FirewallRules: [TCP Query User{8CBE0AF1-BB4D-45ED-AA60-FEAE52ADC940}D:\games\nah\dddd\the arrogant kaiju princess and the detective servant v1.06\the detective servant.exe] => (Block) D:\games\nah\dddd\the arrogant kaiju princess and the detective servant v1.06\the detective servant.exe => No File
FirewallRules: [{01C1FC11-3D42-4607-BC55-29A65F42CB5B}] => (Allow) C:\Users\yxy20\AppData\Roaming\Tencent\TIM\STemp\SetupEx0\QQSetupEx.exe => No File
FirewallRules: [TCP Query User{25A81A00-C7DE-451F-A9CD-9029D1A373AF}E:\games\othergames\transformers - war for cybertron\binaries\twfc.exe] => (Allow) E:\games\othergames\transformers - war for cybertron\binaries\twfc.exe => No File
FirewallRules: [UDP Query User{272B1504-3191-4917-99B0-20770EDFC72A}E:\games\othergames\transformers - war for cybertron\binaries\twfc.exe] => (Allow) E:\games\othergames\transformers - war for cybertron\binaries\twfc.exe => No File
FirewallRules: [TCP Query User{8AA0FF7E-7BEB-4870-BF67-A8AC8F57C84A}E:\games\nahh\dzone\hs2\[utility] kkmanager\standaloneupdater.exe] => (Allow) E:\games\nahh\dzone\hs2\[utility] kkmanager\standaloneupdater.exe => No File
FirewallRules: [UDP Query User{EDB1CE9D-F50E-4C76-8D9F-89CC4CBD837D}E:\games\nahh\dzone\hs2\[utility] kkmanager\standaloneupdater.exe] => (Allow) E:\games\nahh\dzone\hs2\[utility] kkmanager\standaloneupdater.exe => No File
FirewallRules: [TCP Query User{EB17BE39-AF36-42D2-83B3-4D6D62372F1B}C:\program files (x86)\java\jdk-1.8\bin\java.exe] => (Allow) C:\program files (x86)\java\jdk-1.8\bin\java.exe => No File
FirewallRules: [UDP Query User{CF09158C-F41D-4769-9420-AC22DD5BD14C}C:\program files (x86)\java\jdk-1.8\bin\java.exe] => (Allow) C:\program files (x86)\java\jdk-1.8\bin\java.exe => No File
FirewallRules: [TCP Query User{8E274EEA-185D-4648-971E-089A6F464DAA}D:\ide\anaconda\python.exe] => (Allow) D:\ide\anaconda\python.exe => No File
FirewallRules: [UDP Query User{82F9E126-D326-4962-A8B2-467D4BD1269F}D:\ide\anaconda\python.exe] => (Allow) D:\ide\anaconda\python.exe => No File
HKLM-x32\...\RunOnce: [InnoSetupRegFile.0000000001] => "C:\WINDOWS\is-TD8IA.exe" /REG /REGSVRMODE (No File)
Task: {ADC8825B-E373-4C47-A2D9-AAA64E7F69B7} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\yxy20\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe LOGON (No File)
Task: {91B719E7-D8BC-44C3-9683-EEBA4511F603} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\yxy20\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe SCHED (No File)
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin: @videolan.org/vlc,version=3.0.23 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [No File]
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
EmptyTemp:
End::
Warning
Executing a Fixlist on the wrong system may permanently damage it. Continue only if this link was meant for you.
To view the content, acknowledge this warning.