content copied
content
Start::
CreateRestorePoint:
CloseProcesses:
C:\Users\yxy20\AppData\Roaming\8e9279a59036
2026-10-05 02:11 - 2026-10-05 02:11 - 000000000 ____D C:\Users\yxy20\AppData\Local\TP-Link
2026-10-05 02:11 - 2026-10-05 02:11 - 000000000 ____D C:\Users\yxy20\AppData\Local\Marvell
2026-10-05 02:09 - 2026-10-05 02:09 - 000000000 ____D C:\Users\Public\.ff_tmp
HKU\S-1-5-21-2976900799-3423729617-4255589462-1003\...\Run: [MicrosoftEdgeAutoLaunch_5A37281B10BDC32883CF242B3D570F80] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5403976 2026-10-01] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2976900799-3423729617-4255589462-1003\Environment\\UserInitMprLogonScript: -> C:\Users\yxy20\AppData\Roaming\8e9279a59036\AutoIt3.exe [2026-10-04] (AUTOIT CONSULTING LTD -> AutoIt Team)
2026-10-05 02:11 - 2026-10-05 02:11 - 000000000 ____D C:\Users\yxy20\AppData\Local\Yandex
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_503\bin\ssv.dll [2026-07-23] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_503\bin\jp2ssv.dll [2026-07-23] (Oracle America, Inc. -> Oracle Corporation)
PowerShell: Remove-MpPreference -ExclusionPath "C:\Program Files\JetBrains\Rider\r2r"
PowerShell: Remove-MpPreference -ExclusionPath "C:\Users\yxy20\.nuget"
PowerShell: Remove-MpPreference -ExclusionPath "C:\Users\yxy20\AppData\Local\JetBrains\Rider2024.1"
PowerShell: Remove-MpPreference -ExclusionPath "D:\Games\gamedev\Unreal\project_storage\fpstest"
PowerShell: Remove-MpPreference -ExclusionPath "C:\Users\yxy20\AppData\Local\JetBrains\IntelliJIdea2024.3"
PowerShell: Remove-MpPreference -ExclusionPath "D:\Graduate\personal_proj\task-management-app"
PowerShell: Remove-MpPreference -ExclusionPath "D:\Graduate\personal_proj\task-management-backend\task-management-app"
PowerShell: Remove-MpPreference -ExclusionPath "D:\Graduate\personal_proj\task-management-app-teacher-mode-class-7-k8s"
PowerShell: Remove-MpPreference -ExclusionPath "D:\internship_stablecoin\test_project"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\sl\w2\3A V9ServletDemo"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\sl\w3\3B MavenSpringDemo"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\assg\w3\spring_project"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\assg\w3\d4\d4_project"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\sl\w3\SpringDataAccessDemo"
PowerShell: Remove-MpPreference -ExclusionPath "C:\Users\yxy20\AppData\Local\JetBrains\IntelliJIdea2025.3"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\assg\w3\d5mvc\spring_project"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\assg\w3\d5mvc\d5_project"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\sl\w4\4A HibernateIntroDemo"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\sl\w4\SpringSecurityDemo"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\sl\w4\AOP\SpringAOP"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\project\shopping_proj\hibernate-project-demo"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\project\shopping_proj\shopping-project"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\project\shopping_proj\shopping-project - Copy"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\project\shopping_proj\authentication-server"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\sl\w6\d4\Java-FS-Angular-1-main"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\sl\w6\d5\Java-FS-Angular-2-main"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\sl\w7\spring-data-demo"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\project\final_repos\auth-service"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\project\final_repos\eureka-server"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\project\final_repos\application-service"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\project\final_repos\api-gateway"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\project\final_repos\email-service"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\project\final_repos\frontend"
PowerShell: Remove-MpPreference -ExclusionPath "D:\work\project\final_repos\postman_collections"
HKU\S-1-5-21-2976900799-3423729617-4255589462-1003\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_5A37281B10BDC32883CF242B3D570F80"
HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\122.0.1.0\GoogleDriveFS.exe --startup_mode (No File)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\122.0.1.0\GoogleDriveFS.exe --startup_mode (No File)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\122.0.1.0\GoogleDriveFS.exe --startup_mode (No File)
Task: {E42AF5CF-1436-4AFC-ACA1-09DBD5F601EE} - System32\Tasks\ASUS\Aura Wallpaper Service => C:\Program Files\ASUS\Aura Wallpaper Service\Aura Wallpaper Service.exe (No File)
Task: {ADC6B01B-D438-44C4-9579-539BD46DD3E5} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (No File)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
2026-10-03 12:50 - 2025-09-16 02:23 - 000000130 _____ C:\Users\yxy20\AppData\LocalLow\b163e9a4f0592f0cf5d77e1865f44228d397334030e246aa162719fd6c655a78
2026-10-01 15:16 - 2025-09-16 03:38 - 000000130 _____ C:\Users\yxy20\AppData\LocalLow\04fc87343414e72d2e910aaad0f95c3311d88b4ef66f3c8fa325eb4be243f026
2026-09-20 10:03 - 2025-09-16 02:23 - 000000130 _____ C:\Users\yxy20\AppData\LocalLow\330192cf758fa65b9ebffff54ffb84507d6779bedd16d160c6af18f4bb31aa8f
2026-09-09 11:03 - 2025-09-19 02:48 - 000000130 _____ C:\Users\yxy20\AppData\LocalLow\cb9bcbe24cb52282c1aec7f8313bdd1943b1d304515495bb1a09780b81f970bd
2026-09-08 12:34 - 2025-09-16 23:14 - 002130456 _____ C:\Users\yxy20\AppData\LocalLow\36c67e3c3cfb29b57475f598676af9ede6b85efe6caecbe3ec8da07bf48ee69f
2026-09-08 12:33 - 2025-09-19 00:09 - 000000130 _____ C:\Users\yxy20\AppData\LocalLow\37837fd8114198da5e10bde81e4a44a416f7e1a6fdfc92608b55e85fc6caad61
2026-09-08 11:22 - 2025-10-08 04:43 - 000000130 _____ C:\Users\yxy20\AppData\LocalLow\d6e5cd5405014efa1b419324067ac2d78badda0f5ed9d157328f6872794ef31f
2026-09-07 13:27 - 2025-10-24 06:14 - 000000130 _____ C:\Users\yxy20\AppData\LocalLow\9afc721912d2ce218ffce110563cf3bf9fe6f73c7b2d45c39dbe8d0977f90810
2026-09-06 21:00 - 2025-09-16 23:14 - 000000634 _____ C:\Users\yxy20\AppData\LocalLow\0a5c6414178e93379f4c25c718b537e896a44440a58c97a6622be538499b7a30
CustomCLSID: HKU\S-1-5-21-2976900799-3423729617-4255589462-1003_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\yxy20\AppData\Local\GoToMeeting\19950\G2MOutlookAddin64.dll => No File
ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => -> No File
ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => -> No File
ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => -> No File
AlternateDataStreams: C:\Users\yxy20\Downloads\mb-support-1.9.17.1158.exe:MBAM.Zone.Identifier [390]
AlternateDataStreams: C:\Users\yxy20\Downloads\weasel-0.15.0.0-installer.exe:MBAM.Zone.Identifier [631]
AlternateDataStreams: C:\Users\yxy20\AppData\Local\Temp:$DATA [16]
FirewallRules: [{2AED5858-BD94-42F3-A30C-858D5625EF67}] => (Allow) C:\Program Files\ASUS\ARMOURY CRATE Service\MobilePlugin\AutoConnectHelper.exe => No File
FirewallRules: [UDP Query User{B9B5AEFF-5171-4345-95E8-230DA8F1EF01}D:\graduate\tamu\csce735\hw4\hw4-735\mpi_hello_world.exe] => (Allow) D:\graduate\tamu\csce735\hw4\hw4-735\mpi_hello_world.exe => No File
FirewallRules: [TCP Query User{82D61A09-832E-46CA-8BA7-621E93569592}D:\graduate\tamu\csce735\hw4\hw4-735\mpi_hello_world.exe] => (Allow) D:\graduate\tamu\csce735\hw4\hw4-735\mpi_hello_world.exe => No File
FirewallRules: [UDP Query User{7E71F51A-F575-47EC-A0D9-56083FE222BC}C:\users\yxy20\.vscode\extensions\redhat.java-1.36.0-win32-x64\jre\17.0.13-win32-x86_64\bin\java.exe] => (Block) C:\users\yxy20\.vscode\extensions\redhat.java-1.36.0-win32-x64\jre\17.0.13-win32-x86_64\bin\java.exe => No File
FirewallRules: [TCP Query User{8DB17CFA-1A77-4EAD-B716-EF24F017CBA1}C:\users\yxy20\.vscode\extensions\redhat.java-1.36.0-win32-x64\jre\17.0.13-win32-x86_64\bin\java.exe] => (Block) C:\users\yxy20\.vscode\extensions\redhat.java-1.36.0-win32-x64\jre\17.0.13-win32-x86_64\bin\java.exe => No File
FirewallRules: [UDP Query User{B22F6C4B-7DDF-41F7-819B-20950577482B}D:\games\steam\steamapps\common\payday3\payday3\binaries\win64\payday3client-win64-shipping.exe] => (Allow) D:\games\steam\steamapps\common\payday3\payday3\binaries\win64\payday3client-win64-shipping.exe => No File
FirewallRules: [TCP Query User{E8D06043-00AA-452C-A23D-70BBDF4923D7}D:\games\steam\steamapps\common\payday3\payday3\binaries\win64\payday3client-win64-shipping.exe] => (Allow) D:\games\steam\steamapps\common\payday3\payday3\binaries\win64\payday3client-win64-shipping.exe => No File
FirewallRules: [{2D0A45FD-2E9A-4B9A-9BA6-F719E2C01B32}] => (Allow) D:\Games\steam\steamapps\common\ARMORED CORE VI FIRES OF RUBICON\Game\start_protected_game.exe => No File
FirewallRules: [{AADA446F-5C0F-4462-9604-441D9847CD5C}] => (Allow) D:\Games\steam\steamapps\common\ARMORED CORE VI FIRES OF RUBICON\Game\start_protected_game.exe => No File
FirewallRules: [UDP Query User{A5D78B8C-D9CD-49A9-A4D3-B3435CBCBFF6}C:\users\yxy20\.vscode\extensions\redhat.java-1.35.1-win32-x64\jre\17.0.12-win32-x86_64\bin\java.exe] => (Allow) C:\users\yxy20\.vscode\extensions\redhat.java-1.35.1-win32-x64\jre\17.0.12-win32-x86_64\bin\java.exe => No File
FirewallRules: [TCP Query User{95E58326-EEEC-4750-9B02-0E7E6A23797C}C:\users\yxy20\.vscode\extensions\redhat.java-1.35.1-win32-x64\jre\17.0.12-win32-x86_64\bin\java.exe] => (Allow) C:\users\yxy20\.vscode\extensions\redhat.java-1.35.1-win32-x64\jre\17.0.12-win32-x86_64\bin\java.exe => No File
FirewallRules: [UDP Query User{008FF7EA-8393-44D2-93ED-47369F6A75C8}D:\video_related\davinci_resolve\resolve.exe] => (Allow) D:\video_related\davinci_resolve\resolve.exe => No File
FirewallRules: [TCP Query User{FCB122F3-715A-4741-ABFA-A70E35847426}D:\video_related\davinci_resolve\resolve.exe] => (Allow) D:\video_related\davinci_resolve\resolve.exe => No File
FirewallRules: [UDP Query User{150DC21A-9120-4661-BC72-8419C956D215}C:\users\yxy20\.vscode\extensions\redhat.java-1.34.0-win32-x64\jre\17.0.12-win32-x86_64\bin\java.exe] => (Allow) C:\users\yxy20\.vscode\extensions\redhat.java-1.34.0-win32-x64\jre\17.0.12-win32-x86_64\bin\java.exe => No File
FirewallRules: [TCP Query User{7F031BA7-FA66-435F-A080-318EFE19810B}C:\users\yxy20\.vscode\extensions\redhat.java-1.34.0-win32-x64\jre\17.0.12-win32-x86_64\bin\java.exe] => (Allow) C:\users\yxy20\.vscode\extensions\redhat.java-1.34.0-win32-x64\jre\17.0.12-win32-x86_64\bin\java.exe => No File
FirewallRules: [UDP Query User{B8A40998-A8AF-4F6A-9C0D-437DC095F7FF}D:\games\steam\steamapps\common\space marine 2\client_pc\root\bin\pc\warhammer 40000 space marine 2 - retail.exe] => (Allow) D:\games\steam\steamapps\common\space marine 2\client_pc\root\bin\pc\warhammer 40000 space marine 2 - retail.exe => No File
FirewallRules: [TCP Query User{912BBBD0-B033-4DDF-9FEF-783D678D9B41}D:\games\steam\steamapps\common\space marine 2\client_pc\root\bin\pc\warhammer 40000 space marine 2 - retail.exe] => (Allow) D:\games\steam\steamapps\common\space marine 2\client_pc\root\bin\pc\warhammer 40000 space marine 2 - retail.exe => No File
FirewallRules: [{6662811E-4BE9-44F6-8F9C-FF8584B5D9BC}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\135\bugreport_xf.exe => No File
FirewallRules: [{1463443B-C14D-4977-9CC6-EA34AE08E6ED}] => (Allow) D:\Program_Files\Tencent\Tim\Bin\maUpdat.exe => No File
FirewallRules: [{F66927D4-C232-4FA0-832C-E068F7CBC172}] => (Allow) D:\Program_Files\Tencent\Tim\Bin\maLauncher.exe => No File
FirewallRules: [{A9160589-AA77-4832-BF5A-DCFE5FACE5E3}] => (Allow) D:\Program_Files\Tencent\Tim\Bin\SetupEx\SetupEx.exe => No File
FirewallRules: [{39128246-A1FB-4BDC-8C1B-1C3ADC2B26E1}] => (Allow) D:\Program_Files\Tencent\Tim\Bin\txupd.exe => No File
FirewallRules: [{E2C12834-057C-44B4-9C2F-32488FECC05E}] => (Allow) D:\Program_Files\Tencent\Tim\Bin\auclt.exe => No File
FirewallRules: [{F0263799-2696-410D-8D23-3BAFD950D814}] => (Allow) D:\Program_Files\Tencent\Tim\Bin\QQ.exe => No File
FirewallRules: [{6EC57530-2547-4080-9BA5-AAC61E5B2CA2}] => (Allow) D:\Games\steam\steamapps\common\HatinTime\Binaries\ModManager.exe => No File
FirewallRules: [{46DBFCED-2588-4FD6-94F2-6AEC4418C73C}] => (Allow) D:\Games\steam\steamapps\common\HatinTime\Binaries\ModManager.exe => No File
FirewallRules: [UDP Query User{CD6F2F94-FF2C-48D3-A6AF-D57E154B38D3}D:\tools\burner\baidunetdisk\baidunetdiskrender.exe] => (Allow) D:\tools\burner\baidunetdisk\baidunetdiskrender.exe => No File
FirewallRules: [TCP Query User{469939E5-438F-4495-BD18-64B6233736D0}D:\tools\burner\baidunetdisk\baidunetdiskrender.exe] => (Allow) D:\tools\burner\baidunetdisk\baidunetdiskrender.exe => No File
FirewallRules: [UDP Query User{148B53F0-CEDC-4A97-942F-BE6DCDEE03B4}D:\tools\burner\baidunetdisk\baidunetdiskhost.exe] => (Allow) D:\tools\burner\baidunetdisk\baidunetdiskhost.exe => No File
FirewallRules: [TCP Query User{B1FED31C-7289-481E-9AD1-2518F70D287B}D:\tools\burner\baidunetdisk\baidunetdiskhost.exe] => (Allow) D:\tools\burner\baidunetdisk\baidunetdiskhost.exe => No File
FirewallRules: [UDP Query User{0DAE0819-B0DD-4360-B614-3C6B8A2E6E22}D:\games\gamedev\unreal\ue_5.3\engine\binaries\win64\unrealeditor.exe] => (Allow) D:\games\gamedev\unreal\ue_5.3\engine\binaries\win64\unrealeditor.exe => No File
FirewallRules: [TCP Query User{38AA0F47-A441-4BB9-88AA-2E9C113CDE93}D:\games\gamedev\unreal\ue_5.3\engine\binaries\win64\unrealeditor.exe] => (Allow) D:\games\gamedev\unreal\ue_5.3\engine\binaries\win64\unrealeditor.exe => No File
FirewallRules: [UDP Query User{A980ED22-12D0-4845-979E-A927803D12B9}D:\games\othergames\itchio_games\windows\topdown\binaries\win64\topdown.exe] => (Block) D:\games\othergames\itchio_games\windows\topdown\binaries\win64\topdown.exe => No File
FirewallRules: [TCP Query User{B81D68B1-0BEB-4FEC-87B9-804BC95FBBC0}D:\games\othergames\itchio_games\windows\topdown\binaries\win64\topdown.exe] => (Block) D:\games\othergames\itchio_games\windows\topdown\binaries\win64\topdown.exe => No File
FirewallRules: [UDP Query User{E139272E-ECEB-4887-994D-96A4C9E8F408}C:\program files\jetbrains\clion 2024.1.1\bin\clion64.exe] => (Allow) C:\program files\jetbrains\clion 2024.1.1\bin\clion64.exe => No File
FirewallRules: [TCP Query User{F7BE3928-8781-4509-B646-208C15EE1E67}C:\program files\jetbrains\clion 2024.1.1\bin\clion64.exe] => (Allow) C:\program files\jetbrains\clion 2024.1.1\bin\clion64.exe => No File
FirewallRules: [UDP Query User{B89D5F4A-615A-44C6-9B74-5932EFF8570C}D:\games\nah\dddd\peeping dorm manager\peeping dorm manager\peeping dorm manager.exe] => (Block) D:\games\nah\dddd\peeping dorm manager\peeping dorm manager\peeping dorm manager.exe => No File
FirewallRules: [TCP Query User{3A94C7BC-09B2-4F06-97AC-C8082E5EF962}D:\games\nah\dddd\peeping dorm manager\peeping dorm manager\peeping dorm manager.exe] => (Block) D:\games\nah\dddd\peeping dorm manager\peeping dorm manager\peeping dorm manager.exe => No File
FirewallRules: [UDP Query User{2A833355-1DC2-4296-883A-C1C1867E10C3}D:\games\steam\steamapps\common\halo infinite\game\haloinfinite.exe] => (Allow) D:\games\steam\steamapps\common\halo infinite\game\haloinfinite.exe => No File
FirewallRules: [TCP Query User{BAF543DD-C4F8-4A0C-B306-BAB3D12FA437}D:\games\steam\steamapps\common\halo infinite\game\haloinfinite.exe] => (Allow) D:\games\steam\steamapps\common\halo infinite\game\haloinfinite.exe => No File
FirewallRules: [UDP Query User{DB9140D2-4332-48E5-92FD-22BB5FCB558D}C:\program files\blackmagic design\davinci resolve\resolve.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\resolve.exe => No File
FirewallRules: [TCP Query User{EE6A0D8E-88B4-4C43-AA8A-FD9DD92E0F9D}C:\program files\blackmagic design\davinci resolve\resolve.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\resolve.exe => No File
FirewallRules: [{6CD8EDE0-4244-41A0-A2BB-34CDDA9D9DF1}] => (Allow) D:\Games\steam\steamapps\common\DARK SOULS III\Game\DarkSoulsIII.exe => No File
FirewallRules: [{499C1361-8E32-4E76-B84A-D0D4BD5ABCDF}] => (Allow) D:\Games\steam\steamapps\common\DARK SOULS III\Game\DarkSoulsIII.exe => No File
FirewallRules: [UDP Query User{E3B5A15D-D1C8-4D5B-8562-DFD1977C2456}D:\games\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe] => (Allow) D:\games\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe => No File
FirewallRules: [TCP Query User{D48FB421-0230-47E6-9115-0B163283F680}D:\games\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe] => (Allow) D:\games\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe => No File
FirewallRules: [UDP Query User{AB9EB09C-F582-49E3-A4F4-2416BBE77092}D:\games\othergames\transformers-war-for-cybertron\transformers war for cybertron\steamapps\common\transformers war for cybertron\binaries\twfc.exe] => (Allow) D:\games\othergames\transformers-war-for-cybertron\transformers war for cybertron\steamapps\common\transformers war for cybertron\binaries\twfc.exe => No File
FirewallRules: [TCP Query User{3C3963E6-F821-4502-9632-273B0D8CD718}D:\games\othergames\transformers-war-for-cybertron\transformers war for cybertron\steamapps\common\transformers war for cybertron\binaries\twfc.exe] => (Allow) D:\games\othergames\transformers-war-for-cybertron\transformers war for cybertron\steamapps\common\transformers war for cybertron\binaries\twfc.exe => No File
FirewallRules: [UDP Query User{94BA0172-C7BD-4FA4-B77C-CCBF6A52E838}C:\users\yxy20\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\yxy20\appdata\roaming\utorrent\utorrent.exe => No File
FirewallRules: [TCP Query User{69CADA8D-621C-490B-BE6B-F5AFDD73E091}C:\users\yxy20\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\yxy20\appdata\roaming\utorrent\utorrent.exe => No File
FirewallRules: [{7C010F88-DB72-403D-B688-4765E1297BDB}] => (Allow) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_4fc38a913e0f2ea5\ASUSLinkRemote\AsusLinkRemoteAgent.exe => No File
FirewallRules: [{4041DCD7-DA03-49CE-9042-84E23D58B271}] => (Allow) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_4fc38a913e0f2ea5\ASUSLinkRemote\AsusLinkRemoteAgent.exe => No File
FirewallRules: [{977AE013-6BA2-4708-92EF-3AF701CD1EEA}] => (Allow) D:\Games\steam\steamapps\common\Quickie A Love Hotel Story\Quickie A Love Hotel Story\Quickie A Love Hotel Story.exe => No File
FirewallRules: [{3DFFFF69-3BEB-4CC3-BD2E-F56A062DEFDF}] => (Allow) D:\Games\steam\steamapps\common\Quickie A Love Hotel Story\Quickie A Love Hotel Story\Quickie A Love Hotel Story.exe => No File
FirewallRules: [{899F640E-B66E-4EDD-A05E-35C33464ABA1}] => (Allow) C:\Users\yxy20\AppData\Local\Temp\ACFL\ACSetup\ACSetup.exe => No File
FirewallRules: [{CCE4CCF6-6F5A-4D66-886F-04A355586D1F}] => (Allow) C:\Users\yxy20\AppData\Local\Temp\ACFL\ACSetup\ACSetup.exe => No File
FirewallRules: [{42595B8A-E01E-46F2-93C2-D28A891A3CD6}] => (Allow) D:\MessengerApps\wechat\WeChatPlayer.exe => No File
FirewallRules: [{1D3E4E31-4205-4C65-8FDC-B42E76177B5D}] => (Allow) D:\MessengerApps\wechat\WeChatBrowser.exe => No File
FirewallRules: [{4FA2CE1E-6FA1-4C45-A9B5-37FE51F24D63}] => (Allow) D:\MessengerApps\wechat\WeChat.exe => No File
FirewallRules: [{F3EF2A03-697B-419D-9658-A5262DFA7F20}] => (Allow) D:\Games\steam\steamapps\common\HatinTime\Binaries\Win64\HatinTimeGame.exe => No File
FirewallRules: [{7B104BCB-FE12-4163-A776-1799F7FBFD2B}] => (Allow) D:\Games\steam\steamapps\common\HatinTime\Binaries\Win64\HatinTimeGame.exe => No File
FirewallRules: [{5CD3750D-9828-493F-997F-163B54E77A0E}] => (Allow) D:\Games\steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{9BC99545-99D3-4767-A9AD-8912B721A39C}] => (Allow) D:\Games\steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{A182D7D3-A35B-4EAD-BE33-9E53BE407D43}] => (Allow) D:\Games\steam\steamapps\common\MiSide\MiSideFull.exe => No File
FirewallRules: [{307730AC-C630-459F-B0C0-66A615E12528}] => (Allow) D:\Games\steam\steamapps\common\MiSide\MiSideFull.exe => No File
FirewallRules: [{274570E4-6078-4B29-A408-5A99C14BD79E}] => (Allow) D:\Games\steam\steamapps\common\Warhammer 40,000 Space Marine\SpaceMarine.exe => No File
FirewallRules: [{C6FF39FD-78CC-4F47-AAD0-0603D0A82F61}] => (Allow) D:\Games\steam\steamapps\common\Warhammer 40,000 Space Marine\SpaceMarine.exe => No File
FirewallRules: [{F51DEEFB-9869-4160-9F7D-F43D279FB66B}] => (Allow) D:\Games\steam\steamapps\common\Swelter\hl2.exe => No File
FirewallRules: [{0B872BBE-BF88-4EC0-82DD-0EABE6BF1332}] => (Allow) D:\Games\steam\steamapps\common\Swelter\hl2.exe => No File
FirewallRules: [TCP Query User{7D124AC9-6390-4790-ACF7-290FA37D22FF}C:\users\yxy20\appdata\roaming\tencent\wechat\xplugin\plugins\radiumwmpf\11581\extracted\runtime\wechatappex.exe] => (Allow) C:\users\yxy20\appdata\roaming\tencent\wechat\xplugin\plugins\radiumwmpf\11581\extracted\runtime\wechatappex.exe => No File
FirewallRules: [UDP Query User{3528516C-1822-4D7C-811D-D2A62A66A737}C:\users\yxy20\appdata\roaming\tencent\wechat\xplugin\plugins\radiumwmpf\11581\extracted\runtime\wechatappex.exe] => (Allow) C:\users\yxy20\appdata\roaming\tencent\wechat\xplugin\plugins\radiumwmpf\11581\extracted\runtime\wechatappex.exe => No File
FirewallRules: [{EAC2BB58-93D5-4A83-955F-42060710DA9D}] => (Allow) D:\Games\steam\steamapps\common\Slave Zero X\slavex.exe => No File
FirewallRules: [{0FBFEBD4-F140-4EE0-ADC6-674B518D8A4F}] => (Allow) D:\Games\steam\steamapps\common\Slave Zero X\slavex.exe => No File
FirewallRules: [{DB7FF5E7-5D14-46B3-A0C0-EAA337451B49}] => (Allow) D:\Games\steam\steamapps\common\Boltgun\Warhammer 40,000 Boltgun.exe => No File
FirewallRules: [{A77685C7-C81D-415A-B0B9-9AFEC70C45A9}] => (Allow) D:\Games\steam\steamapps\common\Boltgun\Warhammer 40,000 Boltgun.exe => No File
FirewallRules: [{8F80C467-1209-4B52-B246-2E727EFE9774}] => (Allow) E:\video_related\DavinciResolve\ElementsPanelDaemon.exe => No File
FirewallRules: [TCP Query User{A3F76A06-0928-437D-8A73-35542890C67B}C:\users\yxy20\.vscode\extensions\redhat.java-1.39.0-win32-x64\jre\21.0.5-win32-x86_64\bin\java.exe] => (Allow) C:\users\yxy20\.vscode\extensions\redhat.java-1.39.0-win32-x64\jre\21.0.5-win32-x86_64\bin\java.exe => No File
FirewallRules: [UDP Query User{2A6671A9-C757-44E7-8A76-AAD67203645B}C:\users\yxy20\.vscode\extensions\redhat.java-1.39.0-win32-x64\jre\21.0.5-win32-x86_64\bin\java.exe] => (Allow) C:\users\yxy20\.vscode\extensions\redhat.java-1.39.0-win32-x64\jre\21.0.5-win32-x86_64\bin\java.exe => No File
FirewallRules: [TCP Query User{A2F7CAD9-3ACF-4F21-950A-949FB47F23BA}D:\ide\intellij\intellij idea 2024.3.2.2\bin\idea64.exe] => (Allow) D:\ide\intellij\intellij idea 2024.3.2.2\bin\idea64.exe => No File
FirewallRules: [UDP Query User{1E911DE1-0296-4B13-92A5-26B77E8A86A7}D:\ide\intellij\intellij idea 2024.3.2.2\bin\idea64.exe] => (Allow) D:\ide\intellij\intellij idea 2024.3.2.2\bin\idea64.exe => No File
FirewallRules: [{D771A713-6149-4905-97CB-825147B9DE80}] => (Allow) C:\Program Files\ASUS\ARMOURY CRATE Service\MobilePlugin\AutoConnectHelper.exe => No File
FirewallRules: [{AC270235-F442-4537-8D08-AB71D487B1BA}] => (Allow) C:\Program Files\ASUS\ARMOURY CRATE Service\MobilePlugin\AutoConnectHelper.exe => No File
FirewallRules: [TCP Query User{D3894B62-E216-466F-859A-19A8B1605547}C:\users\yxy20\.vscode\extensions\redhat.java-1.40.0-win32-x64\jre\21.0.6-win32-x86_64\bin\java.exe] => (Allow) C:\users\yxy20\.vscode\extensions\redhat.java-1.40.0-win32-x64\jre\21.0.6-win32-x86_64\bin\java.exe => No File
FirewallRules: [UDP Query User{660DEA79-3EB6-4C6B-AA80-450563B9829D}C:\users\yxy20\.vscode\extensions\redhat.java-1.40.0-win32-x64\jre\21.0.6-win32-x86_64\bin\java.exe] => (Allow) C:\users\yxy20\.vscode\extensions\redhat.java-1.40.0-win32-x64\jre\21.0.6-win32-x86_64\bin\java.exe => No File
FirewallRules: [TCP Query User{AE157E5E-99CD-44F8-8232-7AF2B124C9F2}D:\games\steam\steamapps\common\metal bringer demo\metalbringer\binaries\win64\metalbringer-win64-shipping.exe] => (Allow) D:\games\steam\steamapps\common\metal bringer demo\metalbringer\binaries\win64\metalbringer-win64-shipping.exe => No File
FirewallRules: [UDP Query User{5128D257-CC7B-42AE-99DA-F6677ED97E86}D:\games\steam\steamapps\common\metal bringer demo\metalbringer\binaries\win64\metalbringer-win64-shipping.exe] => (Allow) D:\games\steam\steamapps\common\metal bringer demo\metalbringer\binaries\win64\metalbringer-win64-shipping.exe => No File
FirewallRules: [TCP Query User{C109D370-CF67-4EDA-98C5-525769E1B9CC}C:\users\yxy20\appdata\roaming\tencent\wechat\xplugin\plugins\radiumwmpf\13487\extracted\runtime\wechatappex.exe] => (Block) C:\users\yxy20\appdata\roaming\tencent\wechat\xplugin\plugins\radiumwmpf\13487\extracted\runtime\wechatappex.exe => No File
FirewallRules: [UDP Query User{B49497EC-DF78-4876-A55F-5C4821160562}C:\users\yxy20\appdata\roaming\tencent\wechat\xplugin\plugins\radiumwmpf\13487\extracted\runtime\wechatappex.exe] => (Block) C:\users\yxy20\appdata\roaming\tencent\wechat\xplugin\plugins\radiumwmpf\13487\extracted\runtime\wechatappex.exe => No File
FirewallRules: [{C4ECB646-F6F2-4A96-AD14-EF7B065742D4}] => (Allow) E:\Games\steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe => No File
FirewallRules: [{5453012B-B8C1-4ACB-8312-B592B8B59D2A}] => (Allow) E:\Games\steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe => No File
FirewallRules: [{422908FB-3CAB-46BE-8F4C-FCB9C2E984A8}] => (Allow) E:\Games\steam\steamapps\common\ARMORED CORE VI FIRES OF RUBICON\Game\start_protected_game.exe => No File
FirewallRules: [{4CC8B05F-6266-44C4-B58F-22C3D6ACF199}] => (Allow) E:\Games\steam\steamapps\common\ARMORED CORE VI FIRES OF RUBICON\Game\start_protected_game.exe => No File
FirewallRules: [TCP Query User{8BC3FD92-6854-43CF-97FD-0CEB67EF2F53}E:\games\steam\steamapps\common\subverse\subverse\binaries\win64\subverse-win64-shipping.exe] => (Allow) E:\games\steam\steamapps\common\subverse\subverse\binaries\win64\subverse-win64-shipping.exe => No File
FirewallRules: [UDP Query User{B1BF54A4-DDD6-4006-A1CC-2915D84845A4}E:\games\steam\steamapps\common\subverse\subverse\binaries\win64\subverse-win64-shipping.exe] => (Allow) E:\games\steam\steamapps\common\subverse\subverse\binaries\win64\subverse-win64-shipping.exe => No File
FirewallRules: [TCP Query User{F5CB9AFE-C4E9-4A8C-8F97-ED6E46FAFC68}C:\users\yxy20\appdata\roaming\tencent\wechat\xplugin\plugins\radiumwmpf\13639\extracted\runtime\wechatappex.exe] => (Allow) C:\users\yxy20\appdata\roaming\tencent\wechat\xplugin\plugins\radiumwmpf\13639\extracted\runtime\wechatappex.exe => No File
FirewallRules: [UDP Query User{63AD488E-9E62-4A43-9EAA-776B83EC320D}C:\users\yxy20\appdata\roaming\tencent\wechat\xplugin\plugins\radiumwmpf\13639\extracted\runtime\wechatappex.exe] => (Allow) C:\users\yxy20\appdata\roaming\tencent\wechat\xplugin\plugins\radiumwmpf\13639\extracted\runtime\wechatappex.exe => No File
FirewallRules: [{5FDDD33F-5CEA-455C-9DDE-0C91D425C24B}] => (Allow) E:\Games\steam\steamapps\common\Splitgate 2\PortalWars2\Binaries\Win64\PortalWars2Client-Win64-Shipping.exe => No File
FirewallRules: [{A6783CB2-FD1B-43D7-BE40-E7C2F050CC42}] => (Allow) E:\Games\steam\steamapps\common\Splitgate 2\PortalWars2\Binaries\Win64\PortalWars2Client-Win64-Shipping.exe => No File
FirewallRules: [TCP Query User{C869DF19-2204-49F2-BDD9-95A6B478C6D0}E:\games\steam\steamapps\common\halo infinite\game\haloinfinite.exe] => (Allow) E:\games\steam\steamapps\common\halo infinite\game\haloinfinite.exe => No File
FirewallRules: [UDP Query User{E0B18D68-CFD7-40B2-8317-77241301C074}E:\games\steam\steamapps\common\halo infinite\game\haloinfinite.exe] => (Allow) E:\games\steam\steamapps\common\halo infinite\game\haloinfinite.exe => No File
FirewallRules: [TCP Query User{C03479E9-8C4D-41AB-9E26-5B2B82EFAB89}E:\games\steam\steamapps\common\battletech\battletech.exe] => (Allow) E:\games\steam\steamapps\common\battletech\battletech.exe => No File
FirewallRules: [UDP Query User{0F98FEDE-971F-4BAD-97B6-AB67CA35C9EB}E:\games\steam\steamapps\common\battletech\battletech.exe] => (Allow) E:\games\steam\steamapps\common\battletech\battletech.exe => No File
FirewallRules: [{31BD3A64-F702-4D14-B6D6-5A834C97BD1D}] => (Allow) E:\Games\steam\steamapps\common\Warframe\Tools\Launcher.exe => No File
FirewallRules: [{10FFFCD8-50F9-454B-8CC5-6AAE8DAC794E}] => (Allow) E:\Games\steam\steamapps\common\Warframe\Warframe.x64.exe => No File
FirewallRules: [{F2D19405-2431-45FF-8247-C98E86E4D5D2}] => (Allow) E:\Games\steam\steamapps\common\Warframe\Warframe.x64.exe => No File
FirewallRules: [{73A482D4-0456-40F2-A29A-D594FE082C5A}] => (Allow) E:\Games\steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe => No File
FirewallRules: [{EAA8EEBD-E442-4B4F-A094-5F8572087F1E}] => (Allow) E:\Games\steam\steamapps\common\Warframe\Tools\Launcher.exe => No File
FirewallRules: [{A8CC1C16-3D27-4723-B47C-AD3756348DA8}] => (Allow) E:\Games\steam\steamapps\common\Warframe\Warframe.x64.exe => No File
FirewallRules: [{C6B95FD5-FF25-4F74-83A6-22E2911D5A52}] => (Allow) E:\Games\steam\steamapps\common\Warframe\Warframe.x64.exe => No File
FirewallRules: [{08C925D2-FBF4-4BC5-AB9B-DDC3C77876CD}] => (Allow) E:\Games\steam\steamapps\common\Warframe\Tools\RemoteCrashSender.exe => No File
FirewallRules: [{F72F7B2F-9CD7-4F9C-95CC-836D03C7BD38}] => (Allow) D:\MessengerApps\tim\Bin\QQ.exe => No File
FirewallRules: [{C542F419-3D83-4675-A89D-DC3736972C3E}] => (Allow) D:\MessengerApps\tim\Bin\txupd.exe => No File
FirewallRules: [{A8AD0F38-B500-4CA9-B5A5-7E97CBB198D8}] => (Allow) D:\MessengerApps\tim\Bin\SetupEx\SetupEx.exe => No File
FirewallRules: [{396E89FE-B306-4F5F-8E4E-CC69B0C9132B}] => (Allow) D:\MessengerApps\tim\Bin\maLauncher.exe => No File
FirewallRules: [{67731BCB-1B8F-4E07-BB6C-9A3CB87038E8}] => (Allow) D:\MessengerApps\tim\Bin\maUpdat.exe => No File
FirewallRules: [{AAAA5FB2-EAC8-4F97-BC81-1BDF8C8D9726}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\135\bugreport_xf.exe => No File
FirewallRules: [{C6E2C8EF-7A72-497B-BF1C-151092ADEE43}] => (Allow) D:\Games\steam\steamapps\common\DarkSwarm Closed Alpha\DarkSwarm\Binaries\Win64\DarkSwarm-Win64-DebugGame.exe => No File
FirewallRules: [{C27D5355-8A03-4F87-9E98-C2A412309423}] => (Allow) D:\Games\steam\steamapps\common\DarkSwarm Closed Alpha\DarkSwarm\Binaries\Win64\DarkSwarm-Win64-DebugGame.exe => No File
FirewallRules: [TCP Query User{3875FF97-CAE8-4193-8EC1-58A06036EA10}C:\users\yxy20\appdata\local\postman\app-11.65.4\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-11.65.4\postman.exe => No File
FirewallRules: [UDP Query User{85A2047C-174D-43FA-B842-CC7CCE2EC8D0}C:\users\yxy20\appdata\local\postman\app-11.65.4\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-11.65.4\postman.exe => No File
FirewallRules: [TCP Query User{EB24196B-C798-4F3F-A97C-E1B8489788E5}E:\games\nahh\cccccc\romanticescapades-2.0.2\re.exe] => (Block) E:\games\nahh\cccccc\romanticescapades-2.0.2\re.exe => No File
FirewallRules: [UDP Query User{54E740F6-C959-41C9-A8C0-725EC1F37C35}E:\games\nahh\cccccc\romanticescapades-2.0.2\re.exe] => (Block) E:\games\nahh\cccccc\romanticescapades-2.0.2\re.exe => No File
FirewallRules: [TCP Query User{6A888878-3627-4A2E-955F-3B7033E11C32}E:\games\steam\steamapps\common\space hulk deathwing - enhanced edition\spacehulkgame\binaries\win64\spacehulkgame-win64-shipping.exe] => (Allow) E:\games\steam\steamapps\common\space hulk deathwing - enhanced edition\spacehulkgame\binaries\win64\spacehulkgame-win64-shipping.exe => No File
FirewallRules: [UDP Query User{B35FB550-AB6B-4C19-87DC-6CB64F470D19}E:\games\steam\steamapps\common\space hulk deathwing - enhanced edition\spacehulkgame\binaries\win64\spacehulkgame-win64-shipping.exe] => (Allow) E:\games\steam\steamapps\common\space hulk deathwing - enhanced edition\spacehulkgame\binaries\win64\spacehulkgame-win64-shipping.exe => No File
FirewallRules: [TCP Query User{90557C27-FB83-4B0D-8AE5-1D0DDE0442AA}E:\games\steam\steamapps\common\deadzone rogue\valhalla\binaries\win64\deadzonesteam-win64-shipping.exe] => (Allow) E:\games\steam\steamapps\common\deadzone rogue\valhalla\binaries\win64\deadzonesteam-win64-shipping.exe => No File
FirewallRules: [UDP Query User{399C104A-7C98-46D3-BF37-83504F860F63}E:\games\steam\steamapps\common\deadzone rogue\valhalla\binaries\win64\deadzonesteam-win64-shipping.exe] => (Allow) E:\games\steam\steamapps\common\deadzone rogue\valhalla\binaries\win64\deadzonesteam-win64-shipping.exe => No File
FirewallRules: [TCP Query User{63AF7637-5BC8-4397-B299-01C5185EC777}C:\users\yxy20\appdata\local\discord\app-1.0.9219\discord.exe] => (Allow) C:\users\yxy20\appdata\local\discord\app-1.0.9219\discord.exe => No File
FirewallRules: [UDP Query User{12674AB8-8B92-44A1-977A-29AF7F0EEA3D}C:\users\yxy20\appdata\local\discord\app-1.0.9219\discord.exe] => (Allow) C:\users\yxy20\appdata\local\discord\app-1.0.9219\discord.exe => No File
FirewallRules: [TCP Query User{DB808A83-61E1-4CBF-8025-BDD3EEBA47F5}E:\games\steam\steamapps\common\painkiller\painkiller\binaries\win64\painkiller-win64-shipping.exe] => (Allow) E:\games\steam\steamapps\common\painkiller\painkiller\binaries\win64\painkiller-win64-shipping.exe => No File
FirewallRules: [UDP Query User{340D6FB5-B6FE-4365-9382-2C4DCCDCD302}E:\games\steam\steamapps\common\painkiller\painkiller\binaries\win64\painkiller-win64-shipping.exe] => (Allow) E:\games\steam\steamapps\common\painkiller\painkiller\binaries\win64\painkiller-win64-shipping.exe => No File
FirewallRules: [TCP Query User{3FA96881-1AD7-4C1B-8FEF-021E659AFA37}C:\users\yxy20\appdata\local\discord\app-1.0.9222\discord.exe] => (Allow) C:\users\yxy20\appdata\local\discord\app-1.0.9222\discord.exe => No File
FirewallRules: [UDP Query User{F5A930BF-15B4-4FC8-ACA0-B14E0B5EE39F}C:\users\yxy20\appdata\local\discord\app-1.0.9222\discord.exe] => (Allow) C:\users\yxy20\appdata\local\discord\app-1.0.9222\discord.exe => No File
FirewallRules: [TCP Query User{EC6DBD8A-BA23-4141-BF79-9BE6A76242FA}C:\users\yxy20\appdata\local\postman\app-11.67.0\postman.exe] => (Block) C:\users\yxy20\appdata\local\postman\app-11.67.0\postman.exe => No File
FirewallRules: [UDP Query User{4A85B70C-6225-447A-8C6E-198B137981C9}C:\users\yxy20\appdata\local\postman\app-11.67.0\postman.exe] => (Block) C:\users\yxy20\appdata\local\postman\app-11.67.0\postman.exe => No File
FirewallRules: [TCP Query User{42E9977A-C7A5-487E-A46D-78B4CBB2C245}C:\users\yxy20\appdata\local\postman\app-11.83.2\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-11.83.2\postman.exe => No File
FirewallRules: [UDP Query User{359F3A1B-A438-49B0-A0A7-D2709A40FC79}C:\users\yxy20\appdata\local\postman\app-11.83.2\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-11.83.2\postman.exe => No File
FirewallRules: [TCP Query User{63D5A518-F93A-458F-89C4-637C2F03AE08}E:\games\nahh\cccccc\hypnosis card 2 happy life v1.0\hypnosis card 2 happy life.exe] => (Block) E:\games\nahh\cccccc\hypnosis card 2 happy life v1.0\hypnosis card 2 happy life.exe => No File
FirewallRules: [UDP Query User{04444D93-9B8F-4C59-9EE1-4C6F5B24CEA4}E:\games\nahh\cccccc\hypnosis card 2 happy life v1.0\hypnosis card 2 happy life.exe] => (Block) E:\games\nahh\cccccc\hypnosis card 2 happy life v1.0\hypnosis card 2 happy life.exe => No File
FirewallRules: [TCP Query User{36CD0078-D4D5-4F9E-B544-EC0C11F53B8F}C:\users\yxy20\appdata\local\postman\app-11.85.1\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-11.85.1\postman.exe => No File
FirewallRules: [UDP Query User{EF1930DB-A1F2-48E4-888F-1D7DC75B810E}C:\users\yxy20\appdata\local\postman\app-11.85.1\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-11.85.1\postman.exe => No File
FirewallRules: [TCP Query User{F7C114B8-F623-46E5-8EE0-6ACD651E88C0}C:\users\yxy20\appdata\local\postman\app-11.86.1\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-11.86.1\postman.exe => No File
FirewallRules: [UDP Query User{C72A4FE2-CF79-4420-A212-0FE26A670B8B}C:\users\yxy20\appdata\local\postman\app-11.86.1\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-11.86.1\postman.exe => No File
FirewallRules: [TCP Query User{50331AE9-E418-46D2-8B91-A534ABF03368}C:\users\yxy20\appdata\local\postman\app-12.0.4\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-12.0.4\postman.exe => No File
FirewallRules: [UDP Query User{45280CCA-4B46-4E0B-A372-C572CD9039C5}C:\users\yxy20\appdata\local\postman\app-12.0.4\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-12.0.4\postman.exe => No File
FirewallRules: [TCP Query User{FF677C70-8298-4B60-A1C1-456E8A81DB97}C:\users\yxy20\appdata\local\postman\app-12.0.5\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-12.0.5\postman.exe => No File
FirewallRules: [UDP Query User{8B9C1C88-1FBB-4581-9EB4-FA2B6D131342}C:\users\yxy20\appdata\local\postman\app-12.0.5\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-12.0.5\postman.exe => No File
FirewallRules: [TCP Query User{5BC33B7F-5338-4257-B464-2EEE8742DBF5}C:\users\yxy20\appdata\local\postman\app-12.2.0\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-12.2.0\postman.exe => No File
FirewallRules: [UDP Query User{C763325D-DB89-4689-B609-F07A4929EC98}C:\users\yxy20\appdata\local\postman\app-12.2.0\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-12.2.0\postman.exe => No File
FirewallRules: [TCP Query User{79097618-9B03-4DF8-B101-1131838911DD}C:\users\yxy20\appdata\local\postman\app-12.2.3\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-12.2.3\postman.exe => No File
FirewallRules: [UDP Query User{FF21E26C-7978-4045-86D3-523E0C6F1FCC}C:\users\yxy20\appdata\local\postman\app-12.2.3\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-12.2.3\postman.exe => No File
FirewallRules: [TCP Query User{45E59B9D-4AD1-43C5-B642-DB9FBE486A1E}C:\users\yxy20\appdata\local\postman\app-12.3.0\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-12.3.0\postman.exe => No File
FirewallRules: [UDP Query User{5C32A3C1-8B67-4A2B-BB9D-4A5A46F7568D}C:\users\yxy20\appdata\local\postman\app-12.3.0\postman.exe] => (Allow) C:\users\yxy20\appdata\local\postman\app-12.3.0\postman.exe => No File
FirewallRules: [TCP Query User{EB349618-77F5-4059-B121-A61E7A7EF078}E:\games\steam\steamapps\common\projectzomboid\jre64\bin\java.exe] => (Allow) E:\games\steam\steamapps\common\projectzomboid\jre64\bin\java.exe => No File
FirewallRules: [UDP Query User{B267827F-195A-43E4-B64A-AA9DD46A653D}E:\games\steam\steamapps\common\projectzomboid\jre64\bin\java.exe] => (Allow) E:\games\steam\steamapps\common\projectzomboid\jre64\bin\java.exe => No File
FirewallRules: [TCP Query User{9C18CAC6-B559-4F29-A390-5832B73C4579}C:\users\yxy20\appdata\local\discord\app-1.0.9233\discord.exe] => (Allow) C:\users\yxy20\appdata\local\discord\app-1.0.9233\discord.exe => No File
FirewallRules: [UDP Query User{3F1E283B-32A3-454E-975E-F2F3DD12FE5A}C:\users\yxy20\appdata\local\discord\app-1.0.9233\discord.exe] => (Allow) C:\users\yxy20\appdata\local\discord\app-1.0.9233\discord.exe => No File
FirewallRules: [{4B2CFA45-862E-434D-84FC-7BE27D3EC46B}] => (Allow) E:\Games\steam\steamapps\common\Dark Souls II Scholar of the First Sin\Game\DarkSoulsII.exe => No File
FirewallRules: [{906C908C-9E10-4F7D-9E3A-CF112D085094}] => (Allow) E:\Games\steam\steamapps\common\Dark Souls II Scholar of the First Sin\Game\DarkSoulsII.exe => No File
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
File: C:\Users\yxy20\AppData\Local\Temp\WinMemoryCleaner.exe.3.0.8.0.new
File: C:\Program Files (x86)\Rime\weasel-0.17.4\WeaselServer.exe
File: C:\Program Files\JetBrains\ETW Host\16\Updater\EtwHostServiceUpdater.exe
File: C:\WINDOWS\System32\wpninprc.dll
StartPowerShell:
#Requires -Version 5.1
$ProductCodes = @(
'{490DAA44-7D30-428D-B437-32398D6890D5}'
)
$DoComSweep = $false
$DoRawSweep = $false
$DoNameSweep = $false
$ErrorActionPreference = 'SilentlyContinue'
$ProgressPreference = 'SilentlyContinue'
$script:SW = [Diagnostics.Stopwatch]::StartNew()
function W { param([string]$s = '') Write-Output $s }
function H {
param([string]$t)
W ''
W ('-' * 100)
W ('{0} [+{1:N1}s]' -f $t, $script:SW.Elapsed.TotalSeconds)
W ('-' * 100)
}
function KV {
param([string]$k, $v)
if ($null -eq $v -or "$v" -eq '') { $v = '<none>' }
W (' {0,-24} {1}' -f $k, $v)
}
function Pack {
param([string]$g)
$x = ($g -replace '[{}\-\s]', '').ToUpper()
if ($x.Length -ne 32) { throw "bad guid: $g" }
$o = -join $x[7..0]
$o += -join $x[11..8]
$o += -join $x[15..12]
for ($i = 16; $i -lt 32; $i += 2) { $o += $x[$i + 1] + $x[$i] }
$o
}
function Native {
param([string]$p)
$p -replace '^HKLM:\\', 'HKLM\' -replace '^HKCU:\\', 'HKCU\' `
-replace '^HKCR:\\', 'HKCR\' -replace '^HKU:\\', 'HKU\'
}
function DumpKey {
param([string]$Path, [string]$Label = '')
if (-not (Test-Path -LiteralPath $Path)) { return }
W (Native $Path)
if ($Label) { W " [$Label]" }
$p = Get-ItemProperty -LiteralPath $Path
$names = @($p.PSObject.Properties.Name | Where-Object { $_ -notlike 'PS*' } | Sort-Object)
if ($names.Count -eq 0) { W ' <no values>' }
foreach ($n in $names) {
$v = $p.$n
if ($v -is [byte[]]) {
if ($v.Length -gt 64) {
$v = (($v[0..63] | ForEach-Object { $_.ToString('x2') }) -join '') + "... ($($v.Length) bytes)"
} else {
$v = ($v | ForEach-Object { $_.ToString('x2') }) -join ''
}
}
elseif ($v -is [array]) { $v = $v -join ' ; ' }
KV $n $v
}
W ''
}
function MsiTable {
param([string]$Path, [string]$Query)
try {
$i = New-Object -ComObject WindowsInstaller.Installer
$db = $i.GetType().InvokeMember('OpenDatabase', 'InvokeMethod', $null, $i, @($Path, 0))
$v = $db.GetType().InvokeMember('OpenView', 'InvokeMethod', $null, $db, @($Query))
$v.GetType().InvokeMember('Execute', 'InvokeMethod', $null, $v, $null)
while ($r = $v.GetType().InvokeMember('Fetch', 'InvokeMethod', $null, $v, $null)) {
$n = $r.GetType().InvokeMember('FieldCount', 'GetProperty', $null, $r, $null)
, @(for ($k = 1; $k -le $n; $k++) {
$r.GetType().InvokeMember('StringData', 'GetProperty', $null, $r, $k)
})
}
$v.GetType().InvokeMember('Close', 'InvokeMethod', $null, $v, $null)
[void][Runtime.InteropServices.Marshal]::ReleaseComObject($i)
} catch { }
}
function RootToHive {
param($r)
switch ("$r") {
'-1' { 'HKMU' } '0' { 'HKCR' } '1' { 'HKCU' } '2' { 'HKLM' } '3' { 'HKU' }
default { "root$r" }
}
}
function KeyPathPrefixToHive {
param([string]$p)
switch ($p) {
'00' { 'HKCR' } '01' { 'HKCU' } '02' { 'HKLM' } '03' { 'HKU' }
'20' { 'HKLM(64)' } '21' { 'HKCU(64)' } '22' { 'HKLM(64)' } '23' { 'HKU(64)' }
default { "root$p" }
}
}
$HKLM = [Microsoft.Win32.RegistryHive]::LocalMachine
$HKCU = [Microsoft.Win32.RegistryHive]::CurrentUser
$V64 = [Microsoft.Win32.RegistryView]::Registry64
$V32 = [Microsoft.Win32.RegistryView]::Registry32
function OpenBase {
param($Hive, $View)
[Microsoft.Win32.RegistryKey]::OpenBaseKey($Hive, $View)
}
$script:SysDirs = @(
"$env:SystemRoot", "$env:SystemRoot\System32", "$env:SystemRoot\SysWOW64",
"$env:SystemRoot\System32\drivers", "$env:SystemRoot\System32\wbem",
"$env:SystemRoot\WinSxS", "$env:SystemRoot\assembly",
"$env:ProgramData", "$env:ProgramData\Microsoft",
"$env:ProgramFiles", "${env:ProgramFiles(x86)}",
"$env:ProgramFiles\Common Files", "${env:ProgramFiles(x86)}\Common Files",
"$env:ProgramFiles\Common Files\Microsoft Shared", "${env:ProgramFiles(x86)}\Common Files\Microsoft Shared",
"$env:LOCALAPPDATA", "$env:LOCALAPPDATA\Programs", "$env:APPDATA",
"$env:USERPROFILE", 'C:\'
) | Where-Object { $_ } | ForEach-Object { $_.TrimEnd('\').ToLower() }
function Normalize-Path {
param([string]$p)
if ([string]::IsNullOrWhiteSpace($p)) { return $null }
$s = $p.Trim()
if ($s.StartsWith('"')) {
$e = $s.IndexOf('"', 1)
if ($e -gt 0) { $s = $s.Substring(1, $e - 1) } else { $s = $s.Trim('"') }
} else {
$m = [regex]::Match($s, '\s+[-/]')
if ($m.Success) { $s = $s.Substring(0, $m.Index) }
}
$s = [Environment]::ExpandEnvironmentVariables($s)
$s = ($s -replace '^\\\?\?\\', '' -replace '^@', '').Trim()
if ($s -match '^[A-Za-z]:\\') { return $s.TrimEnd('\').ToLower() }
if ($s -match '^[^\\/:*?"<>|]+\.(dll|exe|ocx|cpl|sys)$') { return $s.ToLower() }
return $null
}
$script:OwnPaths = $null
$script:OwnNames = $null
$script:OwnDirs = @()
function Test-Own {
param([string]$c)
$n = Normalize-Path $c
if (-not $n) { return $false }
if ($script:OwnPaths.Contains($n)) { return $true }
foreach ($d in $script:OwnDirs) { if ($n.StartsWith($d + '\')) { return $true } }
if ($n -notmatch '\\' -and $script:OwnNames.Contains($n)) { return $true }
return $false
}
function Get-FileFacts {
param([string]$Path)
if (-not (Test-Path -LiteralPath $Path -PathType Leaf)) { return $null }
$fi = Get-Item -LiteralPath $Path
$vi = $fi.VersionInfo
$sig = Get-AuthenticodeSignature -LiteralPath $Path
[PSCustomObject]@{
Size = $fi.Length
Created = $fi.CreationTime.ToString('yyyy-MM-dd HH:mm:ss')
Modified = $fi.LastWriteTime.ToString('yyyy-MM-dd HH:mm:ss')
Company = $vi.CompanyName
Product = $vi.ProductName
OrigName = $vi.OriginalFilename
IntName = $vi.InternalName
FileVer = $vi.FileVersion
Desc = $vi.FileDescription
SigStatus = "$($sig.Status)"
Signer = $(if ($sig.SignerCertificate) { $sig.SignerCertificate.Subject })
SHA256 = (Get-FileHash -LiteralPath $Path -Algorithm SHA256).Hash
}
}
W ('=' * 100)
W ('MSI REGISTRATION FOOTPRINT {0}' -f (Get-Date -Format 'yyyy-MM-dd HH:mm:ss'))
W ('HOST {0} USER {1}' -f $env:COMPUTERNAME, $env:USERNAME)
W ('OS {0}' -f (Get-CimInstance Win32_OperatingSystem).Caption)
W ('ELEVATED {0}' -f (New-Object Security.Principal.WindowsPrincipal(
[Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole(
[Security.Principal.WindowsBuiltInRole]::Administrator))
W ('SWEEPS com={0} raw={1} name={2}' -f $DoComSweep, $DoRawSweep, $DoNameSweep)
W ('=' * 100)
foreach ($pc in $ProductCodes) {
$packed = Pack $pc
$shortPc = ($pc -replace '[{}]', '')
$script:OwnPaths = New-Object 'System.Collections.Generic.HashSet[string]'
$script:OwnNames = New-Object 'System.Collections.Generic.HashSet[string]'
$script:OwnDirs = @()
$localPkg = $null
$installLoc = $null
$publisher = $null
$displayName = $null
$compFiles = New-Object System.Collections.ArrayList
$compRegs = New-Object System.Collections.ArrayList
$touchedKeys = New-Object System.Collections.ArrayList
W ''
W ('=' * 100)
W "PRODUCTCODE $pc"
W "PACKED $packed"
W ('=' * 100)
H '1. UNINSTALL / ARP'
$found = $false
foreach ($k in @(
"HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$pc",
"HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\$pc",
"HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$pc")) {
if (-not (Test-Path -LiteralPath $k)) { continue }
$found = $true
[void]$touchedKeys.Add((Native $k))
DumpKey $k
$p = Get-ItemProperty -LiteralPath $k
if (-not $displayName) { $displayName = $p.DisplayName }
if (-not $publisher) { $publisher = $p.Publisher }
if (-not $installLoc) { $installLoc = $p.InstallLocation }
if (-not $installLoc -and $p.DisplayIcon) {
$ic = ($p.DisplayIcon -split ',')[0].Trim('"')
if ($ic -match '\\') { $installLoc = Split-Path $ic -Parent }
}
}
if (-not $found) { W '<none>' }
H '2. INSTALLER BRANCH'
$roots = @(
"HKLM:\SOFTWARE\Classes\Installer\Products\$packed",
"HKLM:\SOFTWARE\Classes\Installer\Features\$packed",
"HKLM:\SOFTWARE\Classes\Installer\Patches\$packed"
)
$bk = OpenBase $HKLM $V64
$ud = $bk.OpenSubKey('SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData')
if ($ud) {
foreach ($sid in $ud.GetSubKeyNames()) {
$roots += "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\$sid\Products\$packed"
}
$ud.Close()
}
$bk.Close()
$found = $false
foreach ($r in ($roots | Sort-Object -Unique)) {
if (-not (Test-Path -LiteralPath $r)) { continue }
$found = $true
[void]$touchedKeys.Add((Native $r))
foreach ($sub in @('', '\InstallProperties', '\SourceList', '\SourceList\Net',
'\SourceList\Media', '\Usage', '\Features', '\Patches')) {
DumpKey "$r$sub" $sub.TrimStart('\')
}
$ip = Get-ItemProperty -LiteralPath "$r\InstallProperties"
if ($ip) {
if (-not $localPkg) { $localPkg = $ip.LocalPackage }
if (-not $installLoc) { $installLoc = $ip.InstallLocation }
if (-not $publisher) { $publisher = $ip.Publisher }
if (-not $displayName) { $displayName = $ip.DisplayName }
}
}
if (-not $found) { W '<none>' }
W ''
W 'RESOLVED:'
KV 'DisplayName' $displayName
KV 'Publisher' $publisher
KV 'InstallLocation' $installLoc
KV 'LocalPackage' $localPkg
H '3. UPGRADECODE MEMBERSHIP'
$found = $false
foreach ($cfg in @(
@{ Path = 'SOFTWARE\Classes\Installer\UpgradeCodes'; Label = 'HKLM\SOFTWARE\Classes\Installer\UpgradeCodes' },
@{ Path = 'SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes'; Label = 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes' })) {
$bk = OpenBase $HKLM $V64
$root = $bk.OpenSubKey($cfg.Path)
if ($root) {
foreach ($sub in $root.GetSubKeyNames()) {
$k = $root.OpenSubKey($sub)
if (-not $k) { continue }
if ($k.GetValueNames() -contains $packed) {
$found = $true
W ('{0}\{1}' -f $cfg.Label, $sub)
KV 'upgradecode (packed)' $sub
KV 'member value' $k.GetValue($packed)
W ''
}
$k.Close()
}
$root.Close()
}
$bk.Close()
}
if (-not $found) { W '<none>' }
H '4. COMPONENT REGISTRATION'
$found = $false
$dirCand = New-Object System.Collections.ArrayList
foreach ($cfg in @(
@{ Path = 'SOFTWARE\Classes\Installer\Components'; Label = 'HKLM\SOFTWARE\Classes\Installer\Components' },
@{ Path = 'SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components'; Label = 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components' })) {
$bk = OpenBase $HKLM $V64
$root = $bk.OpenSubKey($cfg.Path)
if ($root) {
foreach ($sub in $root.GetSubKeyNames()) {
$k = $root.OpenSubKey($sub)
if (-not $k) { continue }
$vn = $k.GetValueNames()
if ($vn -contains $packed) {
$found = $true
$val = "$($k.GetValue($packed))"
W ('{0}\{1}' -f $cfg.Label, $sub)
KV 'componentid' $sub
KV 'keypath' $val
$shared = @($vn | Where-Object { $_ -and $_ -ne $packed })
if ($shared.Count) { KV 'shared with' ($shared -join ', ') }
W ''
if ($val -match '^\d{2}:') {
[void]$compRegs.Add($val)
} elseif ($val -match '^[A-Za-z]:\\') {
[void]$compFiles.Add($val)
$n = Normalize-Path $val
if ($n) {
[void]$script:OwnPaths.Add($n)
[void]$script:OwnNames.Add([IO.Path]::GetFileName($n))
[void]$dirCand.Add((Split-Path $n -Parent))
}
}
}
$k.Close()
}
$root.Close()
}
$bk.Close()
}
if (-not $found) { W '<none>' }
if ($installLoc -and (Test-Path -LiteralPath $installLoc)) {
$il = $installLoc.TrimEnd('\').ToLower()
if ($script:SysDirs -notcontains $il) {
[void]$dirCand.Add($il)
Get-ChildItem -LiteralPath $installLoc -Recurse -File | ForEach-Object {
[void]$script:OwnPaths.Add($_.FullName.ToLower())
[void]$script:OwnNames.Add($_.Name.ToLower())
}
}
}
$script:OwnDirs = @($dirCand | Where-Object { $_ } | Sort-Object -Unique |
Where-Object { $script:SysDirs -notcontains $_ -and $_.Split('\').Count -ge 3 })
H '5. MSI DATABASE (cached package)'
if ($localPkg -and (Test-Path -LiteralPath $localPkg)) {
KV 'package' $localPkg
$pf = Get-FileFacts $localPkg
if ($pf) {
KV 'size' $pf.Size
KV 'created' $pf.Created
KV 'modified' $pf.Modified
KV 'sha256' $pf.SHA256
}
W ''
W '[Property]'
MsiTable $localPkg 'SELECT Property, Value FROM Property' |
ForEach-Object { W (' {0,-30} {1}' -f $_[0], $_[1]) }
W ''
W '[Registry] msi row -> live registry state'
$rows = @(MsiTable $localPkg 'SELECT Root, Key, Name, Value, Component_ FROM Registry')
if ($rows.Count -eq 0) { W ' <empty or unreadable>' }
foreach ($row in $rows) {
$hive = RootToHive $row[0]
$key = $row[1]
$name = $row[2]
$cands = switch ($hive) {
'HKLM' { @("HKLM:\SOFTWARE\$key", "HKLM:\SOFTWARE\WOW6432Node\$key", "HKLM:\$key") }
'HKMU' { @("HKLM:\SOFTWARE\$key", "HKLM:\SOFTWARE\WOW6432Node\$key",
"HKCU:\SOFTWARE\$key", "HKLM:\$key") }
'HKCU' { @("HKCU:\SOFTWARE\$key", "HKCU:\$key") }
'HKCR' { @("HKLM:\SOFTWARE\Classes\$key", "HKLM:\SOFTWARE\Classes\WOW6432Node\$key",
"HKCU:\SOFTWARE\Classes\$key") }
default { @("HKLM:\$key") }
}
$hitPath = $null
$hitVal = $null
foreach ($lp in $cands) {
if (Test-Path -LiteralPath $lp) {
$hitPath = Native $lp
if ($name) {
$lv = (Get-ItemProperty -LiteralPath $lp).$name
if ($null -ne $lv) { $hitVal = "$lv" }
}
break
}
}
W (' {0} {1}\{2}' -f $(if ($hitPath) { 'PRESENT' } else { 'ABSENT ' }), $hive, $key)
if ($name) { KV ' value name' $name }
KV ' msi value' $row[3]
if ($hitPath) {
KV ' live key' $hitPath
if ($name) { KV ' live value' $hitVal }
}
KV ' component' $row[4]
}
W ''
W '[Class]'
$cls = @(MsiTable $localPkg 'SELECT CLSID, Context, Component_, ProgId_Default, Description FROM Class')
if ($cls.Count -eq 0) { W ' <none>' }
foreach ($c in $cls) {
W (' {0} ctx={1} comp={2} progid={3} {4}' -f $c[0], $c[1], $c[2], $c[3], $c[4])
foreach ($lp in @("HKLM:\SOFTWARE\Classes\CLSID\$($c[0])",
"HKLM:\SOFTWARE\Classes\WOW6432Node\CLSID\$($c[0])",
"HKCU:\SOFTWARE\Classes\CLSID\$($c[0])")) {
if (-not (Test-Path -LiteralPath $lp)) { continue }
W (' LIVE {0}' -f (Native $lp))
foreach ($srv in @('InprocServer32', 'LocalServer32', 'InprocHandler32')) {
if (Test-Path -LiteralPath "$lp\$srv") {
W (' {0} = {1}' -f $srv, "$((Get-ItemProperty -LiteralPath "$lp\$srv").'(default)')")
}
}
}
}
W ''
W '[ProgId]'
$pg = @(MsiTable $localPkg 'SELECT ProgId, Class_, Description FROM ProgId')
if ($pg.Count -eq 0) { W ' <none>' }
foreach ($g in $pg) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\$($g[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1,-40} class={2} {3}' -f $st, $g[0], $g[1], $g[2])
}
W ''
W '[TypeLib]'
$tl = @(MsiTable $localPkg 'SELECT LibID, Version, Component_, Description FROM TypeLib')
if ($tl.Count -eq 0) { W ' <none>' }
foreach ($t in $tl) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\TypeLib\$($t[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1} ver={2} comp={3} {4}' -f $st, $t[0], $t[1], $t[2], $t[3])
}
W ''
W '[Extension]'
$ex = @(MsiTable $localPkg 'SELECT Extension, Component_, ProgId_, MIME_ FROM Extension')
if ($ex.Count -eq 0) { W ' <none>' }
foreach ($e in $ex) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\.$($e[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} .{1} comp={2} progid={3} mime={4}' -f $st, $e[0], $e[1], $e[2], $e[3])
}
W ''
W '[AppId]'
$ai = @(MsiTable $localPkg 'SELECT AppId, RemoteServerName, ServiceParameters, DllSurrogate FROM AppId')
if ($ai.Count -eq 0) { W ' <none>' }
foreach ($a in $ai) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\AppID\$($a[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1} surrogate={2}' -f $st, $a[0], $a[3])
}
W ''
W '[Directory]'
MsiTable $localPkg 'SELECT Directory, Directory_Parent, DefaultDir FROM Directory' |
ForEach-Object { W (' {0,-28} parent={1,-26} {2}' -f $_[0], $_[1], $_[2]) }
W ''
W '[Component]'
MsiTable $localPkg 'SELECT Component, ComponentId, Directory_, Attributes, KeyPath FROM Component' |
ForEach-Object { W (' {0,-30} {1,-40} dir={2,-22} attr={3,-6} key={4}' -f $_[0], $_[1], $_[2], $_[3], $_[4]) }
W ''
W '[File]'
MsiTable $localPkg 'SELECT File, Component_, FileName, FileSize, Version FROM File' |
ForEach-Object { W (' {0,-40} comp={1,-30} size={2,-10} ver={3}' -f ($_[2] -split '\|')[-1], $_[1], $_[3], $_[4]) }
W ''
W '[ServiceInstall]'
$si = @(MsiTable $localPkg 'SELECT ServiceInstall, Name, DisplayName, ServiceType, StartType, LoadOrderGroup, Dependencies, StartName, Password, Arguments, Component_ FROM ServiceInstall')
if ($si.Count -eq 0) { W ' <none>' }
foreach ($s in $si) {
W (' {0} name={1} disp={2} type={3} start={4} runas={5} args={6} comp={7}' -f
$s[0], $s[1], $s[2], $s[3], $s[4], $s[7], $s[9], $s[10])
}
W ''
W '[CustomAction]'
$ca = @(MsiTable $localPkg 'SELECT Action, Type, Source, Target FROM CustomAction')
if ($ca.Count -eq 0) { W ' <none>' }
foreach ($c in $ca) { W (' {0,-36} type={1,-8} src={2,-30} target={3}' -f $c[0], $c[1], $c[2], $c[3]) }
W ''
W '[Binary]'
$bn = @(MsiTable $localPkg 'SELECT Name FROM Binary')
if ($bn.Count -eq 0) { W ' <none>' }
foreach ($b in $bn) { W (' {0}' -f $b[0]) }
W ''
W '[InstallExecuteSequence]'
MsiTable $localPkg 'SELECT Action, Condition, Sequence FROM InstallExecuteSequence' |
Sort-Object { [int]$_[2] } |
ForEach-Object { W (' {0,-6} {1,-40} {2}' -f $_[2], $_[0], $_[1]) }
W ''
W '[Shortcut]'
$sc = @(MsiTable $localPkg 'SELECT Shortcut, Directory_, Name, Target, Arguments FROM Shortcut')
if ($sc.Count -eq 0) { W ' <none>' }
foreach ($s in $sc) {
W (' {0,-28} dir={1,-22} name={2,-28} target={3} {4}' -f $s[0], $s[1], ($s[2] -split '\|')[-1], $s[3], $s[4])
}
} else {
W '<cached msi unavailable>'
KV 'LocalPackage' $localPkg
}
H '6. LIVE COM REGISTRATION'
KV 'own files' $script:OwnPaths.Count
KV 'own dirs' $(if ($script:OwnDirs.Count) { $script:OwnDirs -join ' | ' } else { '<none>' })
$ign = @($dirCand | Sort-Object -Unique | Where-Object { $script:SysDirs -contains $_ })
if ($ign.Count) { KV 'ignored sysdirs' ($ign -join ' | ') }
W ''
if (-not $DoComSweep) {
W '<skipped: DoComSweep is false>'
} elseif ($script:OwnPaths.Count -eq 0 -and $script:OwnDirs.Count -eq 0) {
W '<no product binaries to match against>'
} else {
$hits = 0
foreach ($cfg in @(
@{ Hive = $HKLM; View = $V64; Label = 'HKLM(64)' },
@{ Hive = $HKLM; View = $V32; Label = 'HKLM(32)' },
@{ Hive = $HKCU; View = $V64; Label = 'HKCU' })) {
$bk = OpenBase $cfg.Hive $cfg.View
$root = $bk.OpenSubKey('SOFTWARE\Classes\CLSID')
if ($root) {
foreach ($clsid in $root.GetSubKeyNames()) {
$ck = $root.OpenSubKey($clsid)
if (-not $ck) { continue }
$subs = $ck.GetSubKeyNames()
foreach ($srv in @('InprocServer32', 'LocalServer32', 'InprocHandler32')) {
if ($subs -notcontains $srv) { continue }
$sk = $ck.OpenSubKey($srv)
if (-not $sk) { continue }
$raw = "$($sk.GetValue(''))"
if ($raw -and (Test-Own $raw)) {
$hits++
W ('{0}\SOFTWARE\Classes\CLSID\{1}' -f $cfg.Label, $clsid)
KV 'default' "$($ck.GetValue(''))"
KV $srv $raw
$tm = $sk.GetValue('ThreadingModel')
if ($tm) { KV 'ThreadingModel' $tm }
$ap = $ck.GetValue('AppID')
if ($ap) { KV 'AppID' $ap }
foreach ($e in @('ProgID', 'VersionIndependentProgID', 'TreatAs', 'Elevation')) {
if ($subs -contains $e) {
$ek = $ck.OpenSubKey($e)
if ($ek) { KV $e "$($ek.GetValue(''))"; $ek.Close() }
}
}
W ''
}
$sk.Close()
}
$ck.Close()
}
$root.Close()
}
$bk.Close()
}
foreach ($cfg in @(
@{ Hive = $HKLM; View = $V64; Label = 'HKLM(64)' },
@{ Hive = $HKLM; View = $V32; Label = 'HKLM(32)' })) {
$bk = OpenBase $cfg.Hive $cfg.View
$root = $bk.OpenSubKey('SOFTWARE\Classes\TypeLib')
if ($root) {
foreach ($lib in $root.GetSubKeyNames()) {
$lk = $root.OpenSubKey($lib)
if (-not $lk) { continue }
foreach ($ver in $lk.GetSubKeyNames()) {
$vk = $lk.OpenSubKey($ver)
if (-not $vk) { continue }
foreach ($plat in ($vk.GetSubKeyNames() | Where-Object { $_ -match '^win(32|64)$' })) {
$pk = $vk.OpenSubKey($plat)
if (-not $pk) { continue }
$d = "$($pk.GetValue(''))"
if ($d -and (Test-Own $d)) {
$hits++
W ('{0}\SOFTWARE\Classes\TypeLib\{1}\{2}\{3}' -f $cfg.Label, $lib, $ver, $plat)
KV 'typelib' $d
W ''
}
$pk.Close()
}
$vk.Close()
}
$lk.Close()
}
$root.Close()
}
$bk.Close()
}
if ($hits -eq 0) { W '<none>' }
}
H '7. APP PATHS / REGISTERED APPLICATIONS'
if ($script:OwnPaths.Count -eq 0 -and $script:OwnDirs.Count -eq 0) {
W '<no product binaries to match against>'
} else {
$hits = 0
foreach ($ap in @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths')) {
if (-not (Test-Path -LiteralPath $ap)) { continue }
Get-ChildItem -LiteralPath $ap | ForEach-Object {
$props = Get-ItemProperty -LiteralPath $_.PSPath
$d = "$($props.'(default)')"
$path = "$($props.Path)"
if ((Test-Own $d) -or (Test-Own $path) -or
$script:OwnNames.Contains($_.PSChildName.ToLower())) {
$script:hits++
W ('{0}\{1}' -f (Native $ap), $_.PSChildName)
KV 'default' $d
if ($path) { KV 'Path' $path }
W ''
}
}
}
foreach ($ra in @('HKLM:\SOFTWARE\RegisteredApplications',
'HKCU:\SOFTWARE\RegisteredApplications')) {
if (-not (Test-Path -LiteralPath $ra)) { continue }
$p = Get-ItemProperty -LiteralPath $ra
foreach ($pr in $p.PSObject.Properties) {
if ($pr.Name -like 'PS*') { continue }
$capKey = "HKLM:\SOFTWARE\$($pr.Value)"
if (-not (Test-Path -LiteralPath $capKey)) { continue }
$cap = Get-ItemProperty -LiteralPath $capKey
if ($cap.ApplicationIcon -and (Test-Own (($cap.ApplicationIcon -split ',')[0]))) {
$script:hits++
W ('{0} :: {1} = {2}' -f (Native $ra), $pr.Name, $pr.Value)
}
}
}
if ($script:hits -eq 0) { W '<none>' }
}
H '8. RAW REGISTRY SWEEP (productcode / packed guid)'
if (-not $DoRawSweep) {
W '<skipped: DoRawSweep is false>'
} else {
foreach ($term in @($pc, $shortPc, $packed)) {
W "term: $term"
$any = $false
foreach ($hive in @('HKLM', 'HKCU', 'HKCR', 'HKU')) {
$k = & reg.exe query $hive /f "$term" /s /k 2>$null | Where-Object { $_ -match '^HK' }
$d = & reg.exe query $hive /f "$term" /s /d 2>$null | Where-Object { $_ -match '^HK' }
if ($k) { $any = $true; $k | ForEach-Object { W " [key] $_" } }
if ($d) { $any = $true; $d | ForEach-Object { W " [data] $_" } }
}
if (-not $any) { W ' <none>' }
W ''
}
}
H '9. RAW REGISTRY SWEEP (displayname / publisher / binaries)'
if (-not $DoNameSweep) {
W '<skipped: DoNameSweep is false>'
} else {
$terms = @()
if ($displayName) { $terms += $displayName }
if ($publisher) { $terms += $publisher }
$script:OwnNames | ForEach-Object { $terms += $_ }
$terms = @($terms | Where-Object { $_ -and $_.Length -ge 5 } | Sort-Object -Unique)
if ($terms.Count -eq 0) { W '<no terms>' }
foreach ($term in $terms) {
W "term: $term"
$any = $false
foreach ($hive in @('HKLM', 'HKCU')) {
$k = & reg.exe query $hive /f "$term" /s /k 2>$null | Where-Object { $_ -match '^HK' }
$d = & reg.exe query $hive /f "$term" /s /d 2>$null | Where-Object { $_ -match '^HK' }
if ($k) { $any = $true; $k | ForEach-Object { W " [key] $_" } }
if ($d) { $any = $true; $d | ForEach-Object { W " [data] $_" } }
}
if (-not $any) { W ' <none>' }
W ''
}
}
H '10. FILES'
$fl = @($compFiles | Sort-Object -Unique)
if ($installLoc -and (Test-Path -LiteralPath $installLoc)) {
Get-ChildItem -LiteralPath $installLoc -Recurse -File | ForEach-Object { $fl += $_.FullName }
}
$fl = @($fl | Sort-Object -Unique)
if ($fl.Count -eq 0) { W '<none>' }
foreach ($f in $fl) {
if (-not (Test-Path -LiteralPath $f -PathType Leaf)) { W "MISSING $f"; continue }
$ff = Get-FileFacts $f
W $f
KV 'size' $ff.Size
KV 'created' $ff.Created
KV 'modified' $ff.Modified
KV 'company' $ff.Company
KV 'product' $ff.Product
KV 'description' $ff.Desc
KV 'origname' $ff.OrigName
KV 'internal' $ff.IntName
KV 'fileversion' $ff.FileVer
KV 'signature' $ff.SigStatus
KV 'signer' $ff.Signer
KV 'sha256' $ff.SHA256
W ''
}
H '11a. FLAT - REGISTRY KEYS PRESENT'
if ($touchedKeys.Count -eq 0) { W '<none>' }
($touchedKeys | Sort-Object -Unique) | ForEach-Object { W $_ }
H '11b. FLAT - REGISTRY KEYPATHS FROM COMPONENTS'
if ($compRegs.Count -eq 0) { W '<none>' }
foreach ($r in ($compRegs | Sort-Object -Unique)) {
W ('{0}\{1}' -f (KeyPathPrefixToHive $r.Substring(0, 2)), $r.Substring(3))
}
H '11c. FLAT - FILES'
if ($fl.Count -eq 0) { W '<none>' }
$fl | ForEach-Object { W $_ }
H '11d. FLAT - DIRECTORIES'
$dl = @()
if ($installLoc) { $dl += $installLoc.TrimEnd('\') }
$fl | ForEach-Object { $dl += (Split-Path $_ -Parent) }
$dl = @($dl | Where-Object { $_ } | Sort-Object -Unique)
if ($dl.Count -eq 0) { W '<none>' }
foreach ($d in $dl) {
$ex = Test-Path -LiteralPath $d -PathType Container
$ct = ''
if ($ex) { $ct = (Get-Item -LiteralPath $d).CreationTime.ToString('yyyy-MM-dd HH:mm:ss') }
W ('{0,-8} {1,-20} {2}' -f $(if ($ex) { 'EXISTS' } else { 'MISSING' }), $ct, $d)
}
}
W ''
W ('=' * 100)
W ('END total {0:N1}s' -f $script:SW.Elapsed.TotalSeconds)
W ('=' * 100)
EndPowerShell:
StartPowerShell:
#Requires -Version 5.1
$ProductCodes = @(
'{6A59175F-21C3-4E1A-9945-8F7459BF70E8}'
)
$DoComSweep = $false
$DoRawSweep = $false
$DoNameSweep = $false
$ErrorActionPreference = 'SilentlyContinue'
$ProgressPreference = 'SilentlyContinue'
$script:SW = [Diagnostics.Stopwatch]::StartNew()
function W { param([string]$s = '') Write-Output $s }
function H {
param([string]$t)
W ''
W ('-' * 100)
W ('{0} [+{1:N1}s]' -f $t, $script:SW.Elapsed.TotalSeconds)
W ('-' * 100)
}
function KV {
param([string]$k, $v)
if ($null -eq $v -or "$v" -eq '') { $v = '<none>' }
W (' {0,-24} {1}' -f $k, $v)
}
function Pack {
param([string]$g)
$x = ($g -replace '[{}\-\s]', '').ToUpper()
if ($x.Length -ne 32) { throw "bad guid: $g" }
$o = -join $x[7..0]
$o += -join $x[11..8]
$o += -join $x[15..12]
for ($i = 16; $i -lt 32; $i += 2) { $o += $x[$i + 1] + $x[$i] }
$o
}
function Native {
param([string]$p)
$p -replace '^HKLM:\\', 'HKLM\' -replace '^HKCU:\\', 'HKCU\' `
-replace '^HKCR:\\', 'HKCR\' -replace '^HKU:\\', 'HKU\'
}
function DumpKey {
param([string]$Path, [string]$Label = '')
if (-not (Test-Path -LiteralPath $Path)) { return }
W (Native $Path)
if ($Label) { W " [$Label]" }
$p = Get-ItemProperty -LiteralPath $Path
$names = @($p.PSObject.Properties.Name | Where-Object { $_ -notlike 'PS*' } | Sort-Object)
if ($names.Count -eq 0) { W ' <no values>' }
foreach ($n in $names) {
$v = $p.$n
if ($v -is [byte[]]) {
if ($v.Length -gt 64) {
$v = (($v[0..63] | ForEach-Object { $_.ToString('x2') }) -join '') + "... ($($v.Length) bytes)"
} else {
$v = ($v | ForEach-Object { $_.ToString('x2') }) -join ''
}
}
elseif ($v -is [array]) { $v = $v -join ' ; ' }
KV $n $v
}
W ''
}
function MsiTable {
param([string]$Path, [string]$Query)
try {
$i = New-Object -ComObject WindowsInstaller.Installer
$db = $i.GetType().InvokeMember('OpenDatabase', 'InvokeMethod', $null, $i, @($Path, 0))
$v = $db.GetType().InvokeMember('OpenView', 'InvokeMethod', $null, $db, @($Query))
$v.GetType().InvokeMember('Execute', 'InvokeMethod', $null, $v, $null)
while ($r = $v.GetType().InvokeMember('Fetch', 'InvokeMethod', $null, $v, $null)) {
$n = $r.GetType().InvokeMember('FieldCount', 'GetProperty', $null, $r, $null)
, @(for ($k = 1; $k -le $n; $k++) {
$r.GetType().InvokeMember('StringData', 'GetProperty', $null, $r, $k)
})
}
$v.GetType().InvokeMember('Close', 'InvokeMethod', $null, $v, $null)
[void][Runtime.InteropServices.Marshal]::ReleaseComObject($i)
} catch { }
}
function RootToHive {
param($r)
switch ("$r") {
'-1' { 'HKMU' } '0' { 'HKCR' } '1' { 'HKCU' } '2' { 'HKLM' } '3' { 'HKU' }
default { "root$r" }
}
}
function KeyPathPrefixToHive {
param([string]$p)
switch ($p) {
'00' { 'HKCR' } '01' { 'HKCU' } '02' { 'HKLM' } '03' { 'HKU' }
'20' { 'HKLM(64)' } '21' { 'HKCU(64)' } '22' { 'HKLM(64)' } '23' { 'HKU(64)' }
default { "root$p" }
}
}
$HKLM = [Microsoft.Win32.RegistryHive]::LocalMachine
$HKCU = [Microsoft.Win32.RegistryHive]::CurrentUser
$V64 = [Microsoft.Win32.RegistryView]::Registry64
$V32 = [Microsoft.Win32.RegistryView]::Registry32
function OpenBase {
param($Hive, $View)
[Microsoft.Win32.RegistryKey]::OpenBaseKey($Hive, $View)
}
$script:SysDirs = @(
"$env:SystemRoot", "$env:SystemRoot\System32", "$env:SystemRoot\SysWOW64",
"$env:SystemRoot\System32\drivers", "$env:SystemRoot\System32\wbem",
"$env:SystemRoot\WinSxS", "$env:SystemRoot\assembly",
"$env:ProgramData", "$env:ProgramData\Microsoft",
"$env:ProgramFiles", "${env:ProgramFiles(x86)}",
"$env:ProgramFiles\Common Files", "${env:ProgramFiles(x86)}\Common Files",
"$env:ProgramFiles\Common Files\Microsoft Shared", "${env:ProgramFiles(x86)}\Common Files\Microsoft Shared",
"$env:LOCALAPPDATA", "$env:LOCALAPPDATA\Programs", "$env:APPDATA",
"$env:USERPROFILE", 'C:\'
) | Where-Object { $_ } | ForEach-Object { $_.TrimEnd('\').ToLower() }
function Normalize-Path {
param([string]$p)
if ([string]::IsNullOrWhiteSpace($p)) { return $null }
$s = $p.Trim()
if ($s.StartsWith('"')) {
$e = $s.IndexOf('"', 1)
if ($e -gt 0) { $s = $s.Substring(1, $e - 1) } else { $s = $s.Trim('"') }
} else {
$m = [regex]::Match($s, '\s+[-/]')
if ($m.Success) { $s = $s.Substring(0, $m.Index) }
}
$s = [Environment]::ExpandEnvironmentVariables($s)
$s = ($s -replace '^\\\?\?\\', '' -replace '^@', '').Trim()
if ($s -match '^[A-Za-z]:\\') { return $s.TrimEnd('\').ToLower() }
if ($s -match '^[^\\/:*?"<>|]+\.(dll|exe|ocx|cpl|sys)$') { return $s.ToLower() }
return $null
}
$script:OwnPaths = $null
$script:OwnNames = $null
$script:OwnDirs = @()
function Test-Own {
param([string]$c)
$n = Normalize-Path $c
if (-not $n) { return $false }
if ($script:OwnPaths.Contains($n)) { return $true }
foreach ($d in $script:OwnDirs) { if ($n.StartsWith($d + '\')) { return $true } }
if ($n -notmatch '\\' -and $script:OwnNames.Contains($n)) { return $true }
return $false
}
function Get-FileFacts {
param([string]$Path)
if (-not (Test-Path -LiteralPath $Path -PathType Leaf)) { return $null }
$fi = Get-Item -LiteralPath $Path
$vi = $fi.VersionInfo
$sig = Get-AuthenticodeSignature -LiteralPath $Path
[PSCustomObject]@{
Size = $fi.Length
Created = $fi.CreationTime.ToString('yyyy-MM-dd HH:mm:ss')
Modified = $fi.LastWriteTime.ToString('yyyy-MM-dd HH:mm:ss')
Company = $vi.CompanyName
Product = $vi.ProductName
OrigName = $vi.OriginalFilename
IntName = $vi.InternalName
FileVer = $vi.FileVersion
Desc = $vi.FileDescription
SigStatus = "$($sig.Status)"
Signer = $(if ($sig.SignerCertificate) { $sig.SignerCertificate.Subject })
SHA256 = (Get-FileHash -LiteralPath $Path -Algorithm SHA256).Hash
}
}
W ('=' * 100)
W ('MSI REGISTRATION FOOTPRINT {0}' -f (Get-Date -Format 'yyyy-MM-dd HH:mm:ss'))
W ('HOST {0} USER {1}' -f $env:COMPUTERNAME, $env:USERNAME)
W ('OS {0}' -f (Get-CimInstance Win32_OperatingSystem).Caption)
W ('ELEVATED {0}' -f (New-Object Security.Principal.WindowsPrincipal(
[Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole(
[Security.Principal.WindowsBuiltInRole]::Administrator))
W ('SWEEPS com={0} raw={1} name={2}' -f $DoComSweep, $DoRawSweep, $DoNameSweep)
W ('=' * 100)
foreach ($pc in $ProductCodes) {
$packed = Pack $pc
$shortPc = ($pc -replace '[{}]', '')
$script:OwnPaths = New-Object 'System.Collections.Generic.HashSet[string]'
$script:OwnNames = New-Object 'System.Collections.Generic.HashSet[string]'
$script:OwnDirs = @()
$localPkg = $null
$installLoc = $null
$publisher = $null
$displayName = $null
$compFiles = New-Object System.Collections.ArrayList
$compRegs = New-Object System.Collections.ArrayList
$touchedKeys = New-Object System.Collections.ArrayList
W ''
W ('=' * 100)
W "PRODUCTCODE $pc"
W "PACKED $packed"
W ('=' * 100)
H '1. UNINSTALL / ARP'
$found = $false
foreach ($k in @(
"HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$pc",
"HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\$pc",
"HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$pc")) {
if (-not (Test-Path -LiteralPath $k)) { continue }
$found = $true
[void]$touchedKeys.Add((Native $k))
DumpKey $k
$p = Get-ItemProperty -LiteralPath $k
if (-not $displayName) { $displayName = $p.DisplayName }
if (-not $publisher) { $publisher = $p.Publisher }
if (-not $installLoc) { $installLoc = $p.InstallLocation }
if (-not $installLoc -and $p.DisplayIcon) {
$ic = ($p.DisplayIcon -split ',')[0].Trim('"')
if ($ic -match '\\') { $installLoc = Split-Path $ic -Parent }
}
}
if (-not $found) { W '<none>' }
H '2. INSTALLER BRANCH'
$roots = @(
"HKLM:\SOFTWARE\Classes\Installer\Products\$packed",
"HKLM:\SOFTWARE\Classes\Installer\Features\$packed",
"HKLM:\SOFTWARE\Classes\Installer\Patches\$packed"
)
$bk = OpenBase $HKLM $V64
$ud = $bk.OpenSubKey('SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData')
if ($ud) {
foreach ($sid in $ud.GetSubKeyNames()) {
$roots += "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\$sid\Products\$packed"
}
$ud.Close()
}
$bk.Close()
$found = $false
foreach ($r in ($roots | Sort-Object -Unique)) {
if (-not (Test-Path -LiteralPath $r)) { continue }
$found = $true
[void]$touchedKeys.Add((Native $r))
foreach ($sub in @('', '\InstallProperties', '\SourceList', '\SourceList\Net',
'\SourceList\Media', '\Usage', '\Features', '\Patches')) {
DumpKey "$r$sub" $sub.TrimStart('\')
}
$ip = Get-ItemProperty -LiteralPath "$r\InstallProperties"
if ($ip) {
if (-not $localPkg) { $localPkg = $ip.LocalPackage }
if (-not $installLoc) { $installLoc = $ip.InstallLocation }
if (-not $publisher) { $publisher = $ip.Publisher }
if (-not $displayName) { $displayName = $ip.DisplayName }
}
}
if (-not $found) { W '<none>' }
W ''
W 'RESOLVED:'
KV 'DisplayName' $displayName
KV 'Publisher' $publisher
KV 'InstallLocation' $installLoc
KV 'LocalPackage' $localPkg
H '3. UPGRADECODE MEMBERSHIP'
$found = $false
foreach ($cfg in @(
@{ Path = 'SOFTWARE\Classes\Installer\UpgradeCodes'; Label = 'HKLM\SOFTWARE\Classes\Installer\UpgradeCodes' },
@{ Path = 'SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes'; Label = 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes' })) {
$bk = OpenBase $HKLM $V64
$root = $bk.OpenSubKey($cfg.Path)
if ($root) {
foreach ($sub in $root.GetSubKeyNames()) {
$k = $root.OpenSubKey($sub)
if (-not $k) { continue }
if ($k.GetValueNames() -contains $packed) {
$found = $true
W ('{0}\{1}' -f $cfg.Label, $sub)
KV 'upgradecode (packed)' $sub
KV 'member value' $k.GetValue($packed)
W ''
}
$k.Close()
}
$root.Close()
}
$bk.Close()
}
if (-not $found) { W '<none>' }
H '4. COMPONENT REGISTRATION'
$found = $false
$dirCand = New-Object System.Collections.ArrayList
foreach ($cfg in @(
@{ Path = 'SOFTWARE\Classes\Installer\Components'; Label = 'HKLM\SOFTWARE\Classes\Installer\Components' },
@{ Path = 'SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components'; Label = 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components' })) {
$bk = OpenBase $HKLM $V64
$root = $bk.OpenSubKey($cfg.Path)
if ($root) {
foreach ($sub in $root.GetSubKeyNames()) {
$k = $root.OpenSubKey($sub)
if (-not $k) { continue }
$vn = $k.GetValueNames()
if ($vn -contains $packed) {
$found = $true
$val = "$($k.GetValue($packed))"
W ('{0}\{1}' -f $cfg.Label, $sub)
KV 'componentid' $sub
KV 'keypath' $val
$shared = @($vn | Where-Object { $_ -and $_ -ne $packed })
if ($shared.Count) { KV 'shared with' ($shared -join ', ') }
W ''
if ($val -match '^\d{2}:') {
[void]$compRegs.Add($val)
} elseif ($val -match '^[A-Za-z]:\\') {
[void]$compFiles.Add($val)
$n = Normalize-Path $val
if ($n) {
[void]$script:OwnPaths.Add($n)
[void]$script:OwnNames.Add([IO.Path]::GetFileName($n))
[void]$dirCand.Add((Split-Path $n -Parent))
}
}
}
$k.Close()
}
$root.Close()
}
$bk.Close()
}
if (-not $found) { W '<none>' }
if ($installLoc -and (Test-Path -LiteralPath $installLoc)) {
$il = $installLoc.TrimEnd('\').ToLower()
if ($script:SysDirs -notcontains $il) {
[void]$dirCand.Add($il)
Get-ChildItem -LiteralPath $installLoc -Recurse -File | ForEach-Object {
[void]$script:OwnPaths.Add($_.FullName.ToLower())
[void]$script:OwnNames.Add($_.Name.ToLower())
}
}
}
$script:OwnDirs = @($dirCand | Where-Object { $_ } | Sort-Object -Unique |
Where-Object { $script:SysDirs -notcontains $_ -and $_.Split('\').Count -ge 3 })
H '5. MSI DATABASE (cached package)'
if ($localPkg -and (Test-Path -LiteralPath $localPkg)) {
KV 'package' $localPkg
$pf = Get-FileFacts $localPkg
if ($pf) {
KV 'size' $pf.Size
KV 'created' $pf.Created
KV 'modified' $pf.Modified
KV 'sha256' $pf.SHA256
}
W ''
W '[Property]'
MsiTable $localPkg 'SELECT Property, Value FROM Property' |
ForEach-Object { W (' {0,-30} {1}' -f $_[0], $_[1]) }
W ''
W '[Registry] msi row -> live registry state'
$rows = @(MsiTable $localPkg 'SELECT Root, Key, Name, Value, Component_ FROM Registry')
if ($rows.Count -eq 0) { W ' <empty or unreadable>' }
foreach ($row in $rows) {
$hive = RootToHive $row[0]
$key = $row[1]
$name = $row[2]
$cands = switch ($hive) {
'HKLM' { @("HKLM:\SOFTWARE\$key", "HKLM:\SOFTWARE\WOW6432Node\$key", "HKLM:\$key") }
'HKMU' { @("HKLM:\SOFTWARE\$key", "HKLM:\SOFTWARE\WOW6432Node\$key",
"HKCU:\SOFTWARE\$key", "HKLM:\$key") }
'HKCU' { @("HKCU:\SOFTWARE\$key", "HKCU:\$key") }
'HKCR' { @("HKLM:\SOFTWARE\Classes\$key", "HKLM:\SOFTWARE\Classes\WOW6432Node\$key",
"HKCU:\SOFTWARE\Classes\$key") }
default { @("HKLM:\$key") }
}
$hitPath = $null
$hitVal = $null
foreach ($lp in $cands) {
if (Test-Path -LiteralPath $lp) {
$hitPath = Native $lp
if ($name) {
$lv = (Get-ItemProperty -LiteralPath $lp).$name
if ($null -ne $lv) { $hitVal = "$lv" }
}
break
}
}
W (' {0} {1}\{2}' -f $(if ($hitPath) { 'PRESENT' } else { 'ABSENT ' }), $hive, $key)
if ($name) { KV ' value name' $name }
KV ' msi value' $row[3]
if ($hitPath) {
KV ' live key' $hitPath
if ($name) { KV ' live value' $hitVal }
}
KV ' component' $row[4]
}
W ''
W '[Class]'
$cls = @(MsiTable $localPkg 'SELECT CLSID, Context, Component_, ProgId_Default, Description FROM Class')
if ($cls.Count -eq 0) { W ' <none>' }
foreach ($c in $cls) {
W (' {0} ctx={1} comp={2} progid={3} {4}' -f $c[0], $c[1], $c[2], $c[3], $c[4])
foreach ($lp in @("HKLM:\SOFTWARE\Classes\CLSID\$($c[0])",
"HKLM:\SOFTWARE\Classes\WOW6432Node\CLSID\$($c[0])",
"HKCU:\SOFTWARE\Classes\CLSID\$($c[0])")) {
if (-not (Test-Path -LiteralPath $lp)) { continue }
W (' LIVE {0}' -f (Native $lp))
foreach ($srv in @('InprocServer32', 'LocalServer32', 'InprocHandler32')) {
if (Test-Path -LiteralPath "$lp\$srv") {
W (' {0} = {1}' -f $srv, "$((Get-ItemProperty -LiteralPath "$lp\$srv").'(default)')")
}
}
}
}
W ''
W '[ProgId]'
$pg = @(MsiTable $localPkg 'SELECT ProgId, Class_, Description FROM ProgId')
if ($pg.Count -eq 0) { W ' <none>' }
foreach ($g in $pg) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\$($g[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1,-40} class={2} {3}' -f $st, $g[0], $g[1], $g[2])
}
W ''
W '[TypeLib]'
$tl = @(MsiTable $localPkg 'SELECT LibID, Version, Component_, Description FROM TypeLib')
if ($tl.Count -eq 0) { W ' <none>' }
foreach ($t in $tl) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\TypeLib\$($t[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1} ver={2} comp={3} {4}' -f $st, $t[0], $t[1], $t[2], $t[3])
}
W ''
W '[Extension]'
$ex = @(MsiTable $localPkg 'SELECT Extension, Component_, ProgId_, MIME_ FROM Extension')
if ($ex.Count -eq 0) { W ' <none>' }
foreach ($e in $ex) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\.$($e[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} .{1} comp={2} progid={3} mime={4}' -f $st, $e[0], $e[1], $e[2], $e[3])
}
W ''
W '[AppId]'
$ai = @(MsiTable $localPkg 'SELECT AppId, RemoteServerName, ServiceParameters, DllSurrogate FROM AppId')
if ($ai.Count -eq 0) { W ' <none>' }
foreach ($a in $ai) {
$st = if (Test-Path -LiteralPath "HKLM:\SOFTWARE\Classes\AppID\$($a[0])") { 'PRESENT' } else { 'ABSENT ' }
W (' {0} {1} surrogate={2}' -f $st, $a[0], $a[3])
}
W ''
W '[Directory]'
MsiTable $localPkg 'SELECT Directory, Directory_Parent, DefaultDir FROM Directory' |
ForEach-Object { W (' {0,-28} parent={1,-26} {2}' -f $_[0], $_[1], $_[2]) }
W ''
W '[Component]'
MsiTable $localPkg 'SELECT Component, ComponentId, Directory_, Attributes, KeyPath FROM Component' |
ForEach-Object { W (' {0,-30} {1,-40} dir={2,-22} attr={3,-6} key={4}' -f $_[0], $_[1], $_[2], $_[3], $_[4]) }
W ''
W '[File]'
MsiTable $localPkg 'SELECT File, Component_, FileName, FileSize, Version FROM File' |
ForEach-Object { W (' {0,-40} comp={1,-30} size={2,-10} ver={3}' -f ($_[2] -split '\|')[-1], $_[1], $_[3], $_[4]) }
W ''
W '[ServiceInstall]'
$si = @(MsiTable $localPkg 'SELECT ServiceInstall, Name, DisplayName, ServiceType, StartType, LoadOrderGroup, Dependencies, StartName, Password, Arguments, Component_ FROM ServiceInstall')
if ($si.Count -eq 0) { W ' <none>' }
foreach ($s in $si) {
W (' {0} name={1} disp={2} type={3} start={4} runas={5} args={6} comp={7}' -f
$s[0], $s[1], $s[2], $s[3], $s[4], $s[7], $s[9], $s[10])
}
W ''
W '[CustomAction]'
$ca = @(MsiTable $localPkg 'SELECT Action, Type, Source, Target FROM CustomAction')
if ($ca.Count -eq 0) { W ' <none>' }
foreach ($c in $ca) { W (' {0,-36} type={1,-8} src={2,-30} target={3}' -f $c[0], $c[1], $c[2], $c[3]) }
W ''
W '[Binary]'
$bn = @(MsiTable $localPkg 'SELECT Name FROM Binary')
if ($bn.Count -eq 0) { W ' <none>' }
foreach ($b in $bn) { W (' {0}' -f $b[0]) }
W ''
W '[InstallExecuteSequence]'
MsiTable $localPkg 'SELECT Action, Condition, Sequence FROM InstallExecuteSequence' |
Sort-Object { [int]$_[2] } |
ForEach-Object { W (' {0,-6} {1,-40} {2}' -f $_[2], $_[0], $_[1]) }
W ''
W '[Shortcut]'
$sc = @(MsiTable $localPkg 'SELECT Shortcut, Directory_, Name, Target, Arguments FROM Shortcut')
if ($sc.Count -eq 0) { W ' <none>' }
foreach ($s in $sc) {
W (' {0,-28} dir={1,-22} name={2,-28} target={3} {4}' -f $s[0], $s[1], ($s[2] -split '\|')[-1], $s[3], $s[4])
}
} else {
W '<cached msi unavailable>'
KV 'LocalPackage' $localPkg
}
H '6. LIVE COM REGISTRATION'
KV 'own files' $script:OwnPaths.Count
KV 'own dirs' $(if ($script:OwnDirs.Count) { $script:OwnDirs -join ' | ' } else { '<none>' })
$ign = @($dirCand | Sort-Object -Unique | Where-Object { $script:SysDirs -contains $_ })
if ($ign.Count) { KV 'ignored sysdirs' ($ign -join ' | ') }
W ''
if (-not $DoComSweep) {
W '<skipped: DoComSweep is false>'
} elseif ($script:OwnPaths.Count -eq 0 -and $script:OwnDirs.Count -eq 0) {
W '<no product binaries to match against>'
} else {
$hits = 0
foreach ($cfg in @(
@{ Hive = $HKLM; View = $V64; Label = 'HKLM(64)' },
@{ Hive = $HKLM; View = $V32; Label = 'HKLM(32)' },
@{ Hive = $HKCU; View = $V64; Label = 'HKCU' })) {
$bk = OpenBase $cfg.Hive $cfg.View
$root = $bk.OpenSubKey('SOFTWARE\Classes\CLSID')
if ($root) {
foreach ($clsid in $root.GetSubKeyNames()) {
$ck = $root.OpenSubKey($clsid)
if (-not $ck) { continue }
$subs = $ck.GetSubKeyNames()
foreach ($srv in @('InprocServer32', 'LocalServer32', 'InprocHandler32')) {
if ($subs -notcontains $srv) { continue }
$sk = $ck.OpenSubKey($srv)
if (-not $sk) { continue }
$raw = "$($sk.GetValue(''))"
if ($raw -and (Test-Own $raw)) {
$hits++
W ('{0}\SOFTWARE\Classes\CLSID\{1}' -f $cfg.Label, $clsid)
KV 'default' "$($ck.GetValue(''))"
KV $srv $raw
$tm = $sk.GetValue('ThreadingModel')
if ($tm) { KV 'ThreadingModel' $tm }
$ap = $ck.GetValue('AppID')
if ($ap) { KV 'AppID' $ap }
foreach ($e in @('ProgID', 'VersionIndependentProgID', 'TreatAs', 'Elevation')) {
if ($subs -contains $e) {
$ek = $ck.OpenSubKey($e)
if ($ek) { KV $e "$($ek.GetValue(''))"; $ek.Close() }
}
}
W ''
}
$sk.Close()
}
$ck.Close()
}
$root.Close()
}
$bk.Close()
}
foreach ($cfg in @(
@{ Hive = $HKLM; View = $V64; Label = 'HKLM(64)' },
@{ Hive = $HKLM; View = $V32; Label = 'HKLM(32)' })) {
$bk = OpenBase $cfg.Hive $cfg.View
$root = $bk.OpenSubKey('SOFTWARE\Classes\TypeLib')
if ($root) {
foreach ($lib in $root.GetSubKeyNames()) {
$lk = $root.OpenSubKey($lib)
if (-not $lk) { continue }
foreach ($ver in $lk.GetSubKeyNames()) {
$vk = $lk.OpenSubKey($ver)
if (-not $vk) { continue }
foreach ($plat in ($vk.GetSubKeyNames() | Where-Object { $_ -match '^win(32|64)$' })) {
$pk = $vk.OpenSubKey($plat)
if (-not $pk) { continue }
$d = "$($pk.GetValue(''))"
if ($d -and (Test-Own $d)) {
$hits++
W ('{0}\SOFTWARE\Classes\TypeLib\{1}\{2}\{3}' -f $cfg.Label, $lib, $ver, $plat)
KV 'typelib' $d
W ''
}
$pk.Close()
}
$vk.Close()
}
$lk.Close()
}
$root.Close()
}
$bk.Close()
}
if ($hits -eq 0) { W '<none>' }
}
H '7. APP PATHS / REGISTERED APPLICATIONS'
if ($script:OwnPaths.Count -eq 0 -and $script:OwnDirs.Count -eq 0) {
W '<no product binaries to match against>'
} else {
$hits = 0
foreach ($ap in @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths')) {
if (-not (Test-Path -LiteralPath $ap)) { continue }
Get-ChildItem -LiteralPath $ap | ForEach-Object {
$props = Get-ItemProperty -LiteralPath $_.PSPath
$d = "$($props.'(default)')"
$path = "$($props.Path)"
if ((Test-Own $d) -or (Test-Own $path) -or
$script:OwnNames.Contains($_.PSChildName.ToLower())) {
$script:hits++
W ('{0}\{1}' -f (Native $ap), $_.PSChildName)
KV 'default' $d
if ($path) { KV 'Path' $path }
W ''
}
}
}
foreach ($ra in @('HKLM:\SOFTWARE\RegisteredApplications',
'HKCU:\SOFTWARE\RegisteredApplications')) {
if (-not (Test-Path -LiteralPath $ra)) { continue }
$p = Get-ItemProperty -LiteralPath $ra
foreach ($pr in $p.PSObject.Properties) {
if ($pr.Name -like 'PS*') { continue }
$capKey = "HKLM:\SOFTWARE\$($pr.Value)"
if (-not (Test-Path -LiteralPath $capKey)) { continue }
$cap = Get-ItemProperty -LiteralPath $capKey
if ($cap.ApplicationIcon -and (Test-Own (($cap.ApplicationIcon -split ',')[0]))) {
$script:hits++
W ('{0} :: {1} = {2}' -f (Native $ra), $pr.Name, $pr.Value)
}
}
}
if ($script:hits -eq 0) { W '<none>' }
}
H '8. RAW REGISTRY SWEEP (productcode / packed guid)'
if (-not $DoRawSweep) {
W '<skipped: DoRawSweep is false>'
} else {
foreach ($term in @($pc, $shortPc, $packed)) {
W "term: $term"
$any = $false
foreach ($hive in @('HKLM', 'HKCU', 'HKCR', 'HKU')) {
$k = & reg.exe query $hive /f "$term" /s /k 2>$null | Where-Object { $_ -match '^HK' }
$d = & reg.exe query $hive /f "$term" /s /d 2>$null | Where-Object { $_ -match '^HK' }
if ($k) { $any = $true; $k | ForEach-Object { W " [key] $_" } }
if ($d) { $any = $true; $d | ForEach-Object { W " [data] $_" } }
}
if (-not $any) { W ' <none>' }
W ''
}
}
H '9. RAW REGISTRY SWEEP (displayname / publisher / binaries)'
if (-not $DoNameSweep) {
W '<skipped: DoNameSweep is false>'
} else {
$terms = @()
if ($displayName) { $terms += $displayName }
if ($publisher) { $terms += $publisher }
$script:OwnNames | ForEach-Object { $terms += $_ }
$terms = @($terms | Where-Object { $_ -and $_.Length -ge 5 } | Sort-Object -Unique)
if ($terms.Count -eq 0) { W '<no terms>' }
foreach ($term in $terms) {
W "term: $term"
$any = $false
foreach ($hive in @('HKLM', 'HKCU')) {
$k = & reg.exe query $hive /f "$term" /s /k 2>$null | Where-Object { $_ -match '^HK' }
$d = & reg.exe query $hive /f "$term" /s /d 2>$null | Where-Object { $_ -match '^HK' }
if ($k) { $any = $true; $k | ForEach-Object { W " [key] $_" } }
if ($d) { $any = $true; $d | ForEach-Object { W " [data] $_" } }
}
if (-not $any) { W ' <none>' }
W ''
}
}
H '10. FILES'
$fl = @($compFiles | Sort-Object -Unique)
if ($installLoc -and (Test-Path -LiteralPath $installLoc)) {
Get-ChildItem -LiteralPath $installLoc -Recurse -File | ForEach-Object { $fl += $_.FullName }
}
$fl = @($fl | Sort-Object -Unique)
if ($fl.Count -eq 0) { W '<none>' }
foreach ($f in $fl) {
if (-not (Test-Path -LiteralPath $f -PathType Leaf)) { W "MISSING $f"; continue }
$ff = Get-FileFacts $f
W $f
KV 'size' $ff.Size
KV 'created' $ff.Created
KV 'modified' $ff.Modified
KV 'company' $ff.Company
KV 'product' $ff.Product
KV 'description' $ff.Desc
KV 'origname' $ff.OrigName
KV 'internal' $ff.IntName
KV 'fileversion' $ff.FileVer
KV 'signature' $ff.SigStatus
KV 'signer' $ff.Signer
KV 'sha256' $ff.SHA256
W ''
}
H '11a. FLAT - REGISTRY KEYS PRESENT'
if ($touchedKeys.Count -eq 0) { W '<none>' }
($touchedKeys | Sort-Object -Unique) | ForEach-Object { W $_ }
H '11b. FLAT - REGISTRY KEYPATHS FROM COMPONENTS'
if ($compRegs.Count -eq 0) { W '<none>' }
foreach ($r in ($compRegs | Sort-Object -Unique)) {
W ('{0}\{1}' -f (KeyPathPrefixToHive $r.Substring(0, 2)), $r.Substring(3))
}
H '11c. FLAT - FILES'
if ($fl.Count -eq 0) { W '<none>' }
$fl | ForEach-Object { W $_ }
H '11d. FLAT - DIRECTORIES'
$dl = @()
if ($installLoc) { $dl += $installLoc.TrimEnd('\') }
$fl | ForEach-Object { $dl += (Split-Path $_ -Parent) }
$dl = @($dl | Where-Object { $_ } | Sort-Object -Unique)
if ($dl.Count -eq 0) { W '<none>' }
foreach ($d in $dl) {
$ex = Test-Path -LiteralPath $d -PathType Container
$ct = ''
if ($ex) { $ct = (Get-Item -LiteralPath $d).CreationTime.ToString('yyyy-MM-dd HH:mm:ss') }
W ('{0,-8} {1,-20} {2}' -f $(if ($ex) { 'EXISTS' } else { 'MISSING' }), $ct, $d)
}
}
W ''
W ('=' * 100)
W ('END total {0:N1}s' -f $script:SW.Elapsed.TotalSeconds)
W ('=' * 100)
EndPowerShell:
Comment: Service / Driver Status (thanks to AdvancedSetup)
Comment: 0 = Boot
Comment: 1 = System
Comment: 2 = Automatic
Comment: 3 = Manual / Demand
Comment: 4 = Disabled
Comment: R = Running
Comment: S = Stopped
Comment: U = Unknown / unable to determine service state cleanly
Comment: === rifteyy's default non-intrusive fixlist template ===
Comment: The following are done automatically with this fixlist:
Comment: Hardens Windows Defender (for maximum efficiency DISABLE TAMPER PROTECTION)
Comment: Checks and corrects the default Windows PATH environmental variable
Comment: Checks for internet connection, valid DNS
Comment: Checks for Windows RE status
Comment: Checks and repairs WMI repository
Comment: Checks Windows activation status
Comment: Checks if TPM, Secure Boot are available and their status
Comment: Checks Bitlocker status
Comment: Checks for chkdsk logs from the past 90 days
Comment: Runs chkdsk to repair and check integrity of systemdrive
Comment: Restores original Windows services configuration
Comment: Restores PowerShell execution policy
Comment: Rebuilds performance counter library values
Comment: Resynchronizes performance counter library values to WMI
Comment: Enables file extensions
Comment: Enables recovery environment
Comment: Enables all firewall profiles
Comment: Scans with HitmanPro from Sophos
Comment: Scans and cleans with AdwCleaner from Malwarebytes
Comment: Lists environment variables
Comment: Lists Windows Defender properties, settings
Comment: Lists drive info, identify possible damaged drives from Event Logs
Comment: Lists Discord's "index.js" files that are often targeted by malware (to store and execute malicious code)
Comment: Lists recent BSOD's
Comment: Lists all installed applications, folder contents along with SHA256 for purposes of identifying installed app malware
Comment: Lists 30 recent scheduled tasks
Comment: Lists recent Run (Windows + R) executed commands, can identify ClickFix attacks
Comment: Removes unwanted files (e.g. .exe, .com, .dll) from common folders (e.g. C:\ProgramData, AppData\Roaming) - these are not supposed to store any executable file types
Comment: Removes generic filetypes associated with RenPyLoader from common folders
Comment: Removes cache from Chrome, Firefox, Opera, Opera GX, Brave, Vivaldi, LibreWolf, Mullvad Browser, Zen and from Roblox, Fortnite, Discord, OBS Studio
Comment: Removes policies
Comment: Removes active BITS tasks
Comment: Resets network
Comment: Resets icon cache
Comment: Removes proxy servers
Comment: Removes temporary files
Comment: Repairs system files
Comment: Schedule chkdsk run for next restart
StartBatch:
echo Y | C:\Windows\System32\chkdsk.exe C: /F
EndBatch:
Comment: List environment variables
StartPowerShell:
$key = Get-Item -Path "HKCU:\Environment" -ErrorAction SilentlyContinue
if ($key) {
$path = "HKCU\Environment"
foreach ($name in $key.GetValueNames()) {
$value = $key.GetValue($name, $null, [Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames)
"$path|$name=$value"
}
}
$key = Get-Item -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Environment" -ErrorAction SilentlyContinue
if ($key) {
$path = "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment"
foreach ($name in $key.GetValueNames()) {
$value = $key.GetValue($name, $null, [Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames)
"$path|$name=$value"
}
}
Get-ChildItem Env: | Sort-Object Name | ForEach-Object {
"SET|$($_.Name)=$($_.Value)"
}
Get-ChildItem Registry::HKEY_USERS | Where-Object {
$_.PSChildName -match '^S-1-5-21-\d+-\d+-\d+-\d+$'
} | ForEach-Object {
$sid = $_.PSChildName
$envPath = "Registry::HKEY_USERS\$sid\Environment"
if (Test-Path $envPath) {
$key = Get-Item -Path $envPath
foreach ($name in $key.GetValueNames()) {
$value = $key.GetValue($name, $null, [Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames)
"HKEY_USERS\$sid\Environment|$name=$value"
}
}
}
EndPowerShell:
StartPowerShell:
# Checks default Windows PATH entries and repairs missing ones.
$ErrorActionPreference = 'Continue'
function Expand-PlainPath {
param([string]$Entry)
return [Environment]::ExpandEnvironmentVariables($Entry).TrimEnd('\')
}
# Templates expanded once to plain paths (C:\Windows\..., C:\Users\...)
$systemDefaults = @(
(Expand-PlainPath '%SystemRoot%\system32')
(Expand-PlainPath '%SystemRoot%')
(Expand-PlainPath '%SystemRoot%\System32\Wbem')
(Expand-PlainPath '%SystemRoot%\System32\WindowsPowerShell\v1.0')
(Expand-PlainPath '%SystemRoot%\System32\OpenSSH')
)
$userDefaults = @(
(Expand-PlainPath '%USERPROFILE%\AppData\Local\Microsoft\WindowsApps')
)
function Get-NormalizedPathEntries {
param([string]$Raw)
if ([string]::IsNullOrWhiteSpace($Raw)) { return @() }
return @(
$Raw -split ';' |
Where-Object { -not [string]::IsNullOrWhiteSpace($_) } |
ForEach-Object {
[Environment]::ExpandEnvironmentVariables($_.Trim().TrimEnd('\')).ToLowerInvariant()
}
)
}
function Get-CombinedPathEntries {
$machineRaw = [Environment]::GetEnvironmentVariable('Path', 'Machine')
$userRaw = [Environment]::GetEnvironmentVariable('Path', 'User')
return Get-NormalizedPathEntries -Raw ($machineRaw + ';' + $userRaw)
}
function Test-InPath {
param(
[string]$PlainPath,
[string[]]$NormalizedEntries
)
$key = $PlainPath.TrimEnd('\').ToLowerInvariant()
return $NormalizedEntries -contains $key
}
function Add-ToPath {
param(
[string]$PlainPath,
[ValidateSet('Machine', 'User')]
[string]$Scope
)
# always store plain path, never %VAR% form
$toAdd = $PlainPath.TrimEnd('\')
$current = [Environment]::GetEnvironmentVariable('Path', $Scope)
if ([string]::IsNullOrWhiteSpace($current)) {
[Environment]::SetEnvironmentVariable('Path', $toAdd, $Scope)
return
}
$normalized = Get-NormalizedPathEntries -Raw $current
$key = $toAdd.ToLowerInvariant()
if ($normalized -contains $key) { return }
$newPath = $current.TrimEnd(';') + ';' + $toAdd
[Environment]::SetEnvironmentVariable('Path', $newPath, $Scope)
}
function Write-Result {
param(
[string]$Entry,
[string]$Status
)
$label = $Entry.PadRight(58)
Write-Output ("{0} {1}" -f $label, $Status)
}
function Repair-AndVerify {
param(
[string]$PlainPath,
[ValidateSet('Machine', 'User')]
[string]$Scope
)
if (-not (Test-Path -LiteralPath $PlainPath)) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (no folder, cannot repair)'
return 'failed'
}
if ($Scope -eq 'Machine') {
$isAdmin = ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).
IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)
if (-not $isAdmin) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (need Admin to repair)'
return 'failed'
}
}
try {
Add-ToPath -PlainPath $PlainPath -Scope $Scope
}
catch {
Write-Result -Entry $PlainPath -Status "ATTENTION !!! MISSING (repair failed: $_)"
return 'failed'
}
# re-query PATH from registry and verify plain path is present
$after = Get-CombinedPathEntries
if (Test-InPath -PlainPath $PlainPath -NormalizedEntries $after) {
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING -> repaired (verified)'
return 'repaired'
}
Write-Result -Entry $PlainPath -Status 'ATTENTION !!! MISSING (repair ran, still missing after re-check)'
return 'failed'
}
$combined = Get-CombinedPathEntries
$hadMissing = $false
$repairFailed = $false
$repairedList = [System.Collections.Generic.List[string]]::new()
Write-Output 'PATH CHECK'
Write-Output ('-' * 72)
foreach ($entry in $systemDefaults) {
if (Test-InPath -PlainPath $entry -NormalizedEntries $combined) {
Write-Result -Entry $entry -Status 'OK'
continue
}
$hadMissing = $true
$result = Repair-AndVerify -PlainPath $entry -Scope Machine
if ($result -eq 'repaired') {
[void]$repairedList.Add($entry)
$combined = Get-CombinedPathEntries
}
else {
$repairFailed = $true
}
}
foreach ($entry in $userDefaults) {
if (Test-InPath -PlainPath $entry -NormalizedEntries $combined) {
Write-Result -Entry $entry -Status 'OK'
continue
}
$hadMissing = $true
$result = Repair-AndVerify -PlainPath $entry -Scope User
if ($result -eq 'repaired') {
[void]$repairedList.Add($entry)
$combined = Get-CombinedPathEntries
}
else {
$repairFailed = $true
}
}
Write-Output ('-' * 72)
if (-not $hadMissing) {
Write-Output 'RESULT: all default PATH entries present'
}
elseif ($repairedList.Count -gt 0 -and -not $repairFailed) {
Write-Output "RESULT: $($repairedList.Count) missing entry/entries repaired and verified - open a new terminal"
}
elseif ($repairedList.Count -gt 0 -and $repairFailed) {
Write-Output "RESULT: $($repairedList.Count) verified, some still missing - open a new terminal / run as Admin"
}
else {
Write-Output 'RESULT: missing entries not repaired (run as Admin for System PATH)'
}
if ($repairedList.Count -gt 0) {
Write-Output ''
Write-Output 'REPAIRED:'
foreach ($item in $repairedList) {
Write-Output " $item"
}
}
if ($hadMissing -or $repairFailed) {
exit 1
}
exit 0
EndPowerShell:
Comment: Windows activation status
StartPowerShell:
$windowsAppId = "55c92734-d682-4d71-983e-d6ec3f16059f"
function Get-LicenseStatusText {
param([uint32]$LicenseStatus)
switch ($LicenseStatus) {
0 { "Unlicensed" }
1 { "Activated" }
2 { "OOB Grace" }
3 { "OOT Grace" }
4 { "Non-genuine grace" }
5 { "Notification" }
6 { "Extended grace" }
default { "Unknown ($LicenseStatus)" }
}
}
# BackupProductKeyDefault is commonly a generic key; still useful for reporting consistency.
$bk = (Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform" `
-Name BackupProductKeyDefault -ErrorAction SilentlyContinue).BackupProductKeyDefault
# Pick the best Windows licensing row (activated wins first, then highest status)
$win = Get-CimInstance -ClassName SoftwareLicensingProduct |
Where-Object {
$_.ApplicationID -eq $windowsAppId -and
$_.PartialProductKey -and
($_.LicenseIsAddon -ne $true)
} |
Sort-Object -Property @{Expression = { $_.LicenseStatus -eq 1 }; Descending = $true }, LicenseStatus -Descending |
Select-Object -First 1
if (-not $win) {
Write-Output "No Windows licensing row found (SoftwareLicensingProduct)."
return
}
$desc = [string]$win.Description
# Detect channel/type from Description
$isKms = $desc -match "VOLUME_KMSCLIENT"
$isMak = $desc -match "VOLUME_MAK"
$isVolume = $desc -match "VOLUME_"
# Estimate expiration for KMS/volume using GracePeriodRemaining (minutes). Best-effort.
$expiresEstimate = $null
if ($win.GracePeriodRemaining -gt 0) {
$expiresEstimate = (Get-Date).AddMinutes([int]$win.GracePeriodRemaining)
}
# Base report (always shown)
$out = [ordered]@{
Name = $win.Name
Description = $win.Description
ActivationStatus = (Get-LicenseStatusText $win.LicenseStatus)
LicenseStatus = $win.LicenseStatus
PartialProductKey = $win.PartialProductKey
BackupProductKeyDefault = $bk
"Xpr Summary" = "" # slmgr /xpr-like friendly summary
}
# slmgr /xpr-like summary (no VBScript)
if ($win.LicenseStatus -ne 1) {
$out["Xpr Summary"] = "Not activated"
}
elseif ($isKms -and $win.GracePeriodRemaining -gt 0 -and $expiresEstimate) {
$out["Xpr Summary"] = "Activated (KMS), expires about: " + $expiresEstimate.ToString("yyyy-MM-dd HH:mm:ss")
}
else {
$out["Xpr Summary"] = "The machine is permanently activated."
}
# Only show grace/expiry fields for volume clients (KMS/MAK)
if ($isVolume) {
$out["GracePeriodRemainingMin"] = $win.GracePeriodRemaining
$out["ExpiresEstimateLocal"] = if ($expiresEstimate) { $expiresEstimate.ToString("yyyy-MM-dd HH:mm:ss") } else { "" }
if ($isKms) { $out["VolumeType"] = "KMS Client" }
elseif ($isMak) { $out["VolumeType"] = "MAK" }
else { $out["VolumeType"] = "Volume" }
}
# Only show KMS server/interval fields for KMS clients
if ($isKms) {
$svc = Get-CimInstance -ClassName SoftwareLicensingService
$out["KmsConfiguredHost"] = $svc.KeyManagementServiceMachine
$out["KmsConfiguredPort"] = $svc.KeyManagementServicePort
$out["KmsDiscoveredHost"] = $svc.DiscoveredKeyManagementServiceMachineName
$out["KmsDiscoveredPort"] = $svc.DiscoveredKeyManagementServiceMachinePort
$out["VLRenewalIntervalMin"] = $svc.VLRenewalInterval
$out["VLActivationIntervalMin"] = $svc.VLActivationInterval
}
[pscustomobject]$out | Format-List
EndPowerShell:
Comment: Check TPM and Secure Boot status
StartPowershell:
[PSCustomObject]@{ "TPM Detected" = (Get-Tpm).TpmPresent; "TPM Enabled" = (Get-Tpm).TpmEnabled; "Secure Boot On" = (Confirm-SecureBootUEFI) }
EndPowershell:
Comment: List chkdsk logs from the past 90 days
StartPowerShell:
$rangeStart = (Get-Date).AddDays(-90)
$rangeEnd = Get-Date
try {
$latestEvent = Get-WinEvent -FilterHashtable @{ LogName = 'Application'; ID = 1001; StartTime = $rangeStart } -ErrorAction Stop |
Where-Object { $_.ProviderName -match '(?i)wininit|chkdsk' } |
Sort-Object TimeCreated -Descending |
Select-Object -First 1
if (-not $latestEvent) {
Write-Output ("No disk check logs found in Application log for last 90 days ({0} to {1})." -f $rangeStart.ToString("yyyy-MM-dd"), $rangeEnd.ToString("yyyy-MM-dd"))
return
}
$lines = $latestEvent.Message -split '\r?\n'
$summaryLines = $lines |
Where-Object { $_ -match '(?i)found no problems|has been scheduled|made corrections|no further action' } |
ForEach-Object { $_.Trim() }
if (-not $summaryLines) { $summaryLines = $lines | Where-Object { $_.Trim() } | Select-Object -First 1 }
Write-Output ("{0} | {1}" -f $latestEvent.TimeCreated, ($summaryLines -join ' '))
}
catch {
Write-Output "Error retrieving disk check logs: $_"
}
EndPowerShell:
Comment: Bitlocker status
Powershell: manage-bde -status c:
StartPowerShell:
# Check for internet connection
$ErrorActionPreference = 'Continue'
$dnsServers = @(
'1.1.1.1'
'8.8.8.8'
)
$hosts = @(
'google.com'
'cloudflare.com'
'malwarebytes.com'
)
function Write-Result {
param(
[string]$Label,
[string]$Status
)
Write-Output ("{0} {1}" -f $Label.PadRight(42), $Status)
}
function Test-DnsServer {
param([string]$Server)
$pingOk = $false
try {
$pingOk = Test-Connection -ComputerName $Server -Count 1 -Quiet -ErrorAction SilentlyContinue
}
catch { }
$resolveOk = $false
try {
$result = Resolve-DnsName -Name 'google.com' -Server $Server -Type A -DnsOnly -ErrorAction Stop
$ip = ($result | Where-Object { $_.IPAddress } | Select-Object -First 1).IPAddress
if ($ip) { $resolveOk = $true }
}
catch { }
# resolve is what matters; ping may be blocked
if ($resolveOk) { return 'OK' }
if ($pingOk) { return 'FAIL' }
return 'FAIL'
}
function Test-HostReachable {
param([string]$HostName)
try {
$dns = Resolve-DnsName -Name $HostName -Type A -ErrorAction Stop
$resolvedIp = ($dns | Where-Object { $_.IPAddress } | Select-Object -First 1).IPAddress
if (-not $resolvedIp) { return 'FAIL' }
}
catch {
return 'FAIL'
}
try {
$null = Invoke-WebRequest -Uri "https://$HostName" -UseBasicParsing -TimeoutSec 10 -MaximumRedirection 5 -ErrorAction Stop
return 'OK'
}
catch {
if ($_.Exception.Response) { return 'OK' }
return 'FAIL'
}
}
$failed = 0
Write-Output 'INTERNET CHECK'
Write-Output ('-' * 72)
Write-Output 'DNS SERVERS'
foreach ($server in $dnsServers) {
$status = Test-DnsServer -Server $server
Write-Result -Label $server -Status $status
if ($status -eq 'FAIL') { $failed++ }
}
Write-Output ''
Write-Output 'HOSTS'
foreach ($h in $hosts) {
$status = Test-HostReachable -HostName $h
Write-Result -Label $h -Status $status
if ($status -eq 'FAIL') { $failed++ }
}
Write-Output ('-' * 72)
if ($failed -eq 0) {
Write-Output 'RESULT: all checks passed'
exit 0
}
Write-Output "RESULT: $failed check(s) failed"
exit 1
EndPowerShell:
StartPowershell:
# Replace /scanonly with /clean if you also want to delete items -- however, this will activate a trial license on the system, I do not recommend it
$hmpExe = "$env:TEMP\HitmanPro_x64.exe"
$logFile = "$env:TEMP\HitmanPro_ScanLog.txt"
Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing
$proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru
if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 }
Get-Content $logFile -Encoding Unicode
EndPowershell:
StartPowerShell:
# Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console
# Does not clean preinstalled objects, only PUP/Adware
# If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument
# If you would like to only scan with it, change the argument from /clean to /scan
# NOTE: For the sake of users from Asia (primarily China), do not use the clean option. It will very likely remove a lot of their important software.
New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null
Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden
$logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt"
Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /scan" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile
Get-Content $logFile -Encoding Unicode
Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue
EndPowerShell:
Comment: List drive info, identify possible damaged drives (thanks to AdvancedSetup from Malwarebytes for parts of these)
StartPowerShell:
param(
[int]$MaxEvents = 5000
)
$GPTTypeMap = @{
'EBD0A0A2-B9E5-4433-87C0-68B6B72699C7' = 'Microsoft Basic Data'
'E3C9E316-0B5C-4DB8-817D-F92DF00215AE' = 'Microsoft Reserved (MSR)'
'DE94BBA4-06D1-4D40-A16A-BFD50179D6AC' = 'Windows Recovery Environment (WinRE)'
'C12A7328-F81F-11D2-BA4B-00A0C93EC93B' = 'EFI System Partition'
'21686148-6449-6E6F-744E-656564454649' = 'BIOS Boot Partition'
'A19D880F-05FC-4D3B-A006-743F0F84911E' = 'OEM Partition'
'5808C8AA-7E8F-42E0-85D2-E1E90434CFB3' = 'Cluster Metadata Partition'
'48465300-0000-11AA-AA11-00306543ECAC' = 'Apple HFS/HFS+'
'7C3457EF-0000-11AA-AA11-00306543ECAC' = 'Apple APFS'
'0FC63DAF-8483-4772-8E79-3D69D8477DE4' = 'Linux Filesystem'
'0657FD6D-A4AB-43C4-84E5-0933C84B4F4F' = 'Linux Swap'
'E6D6D379-F507-44C2-A23C-238F2A3DF928' = 'Linux LVM'
}
$MBRTypeMap = @{
'01'='FAT12';'04'='FAT16 <32M';'05'='Extended';'06'='FAT16';'07'='IFS/NTFS/exFAT/HPFS';'0B'='FAT32 CHS';'0C'='FAT32 LBA';'0E'='FAT16 LBA'
'0F'='Extended LBA';'82'='Linux Swap';'83'='Linux Native';'8E'='Linux LVM';'A5'='FreeBSD';'A6'='OpenBSD';'A8'='Mac OS X';'AB'='Mac OS X Boot'
'AF'='Mac OS X HFS';'EE'='EFI GPT Protective';'EF'='EFI System Partition'
}
function Get-PartitionTypeInfo {
param($Partition)
$guid = $null
if ($Partition.GptType) {
$guid = ($Partition.GptType -replace '[{}]', '').ToUpper()
}
if ([string]::IsNullOrWhiteSpace($guid) -or $guid -eq '00000000-0000-0000-0000-000000000000') {
$guid = switch ($Partition.Type) {
"System" { "C12A7328-F81F-11D2-BA4B-00A0C93EC93B" }
"Reserved" { "E3C9E316-0B5C-4DB8-817D-F92DF00215AE" }
"Basic" { "EBD0A0A2-B9E5-4433-87C0-68B6B72699C7" }
"Recovery" { "DE94BBA4-06D1-4D40-A16A-BFD50179D6AC" }
default { $null }
}
}
if ($guid) {
$name = $GPTTypeMap[$guid]
if ($name) { return "$name (GPT GUID: $($guid.ToLower()))" }
else { return "Unknown/Custom (GPT GUID: $($guid.ToLower()))" }
}
if ($Partition.MbrType) {
$code = ($Partition.MbrType.ToString() -replace '^0x', '').PadLeft(2, '0').ToUpper()
$name = $MBRTypeMap[$code]
if ($name) { return "$name (MBR code: 0x$code)" }
else { return "Unknown/Custom (MBR code: $($Partition.MbrType))" }
}
return $Partition.Type
}
function Get-DrMapping {
param([int]$MaxEvents)
$map = @{}
try {
$events = Get-WinEvent -FilterHashtable @{ LogName = 'System'; ProviderName = 'disk' } -MaxEvents $MaxEvents -ErrorAction Stop
} catch {
return $map
}
foreach ($e in $events) {
if ($e.Message -match 'Harddisk(\d+)\\DR(\d+)') {
$n = [int]$Matches[1]
$dr = [int]$Matches[2]
if (-not $map.ContainsKey($n)) { $map[$n] = $dr }
}
}
return $map
}
$drMap = Get-DrMapping -MaxEvents $MaxEvents
$physicalDisks = Get-PhysicalDisk | Select-Object DeviceId, FriendlyName, SerialNumber, MediaType, @{N='SizeGB';E={[math]::Round($_.Size / 1GB,2)}}
foreach ($pd in $physicalDisks) {
$devId = [int]$pd.DeviceId
$drSuffix = if ($drMap.ContainsKey($devId)) { "\DR$($drMap[$devId])" } else { '\DR? (no event seen yet)' }
Write-Host ""
Write-Host "<=== \Device\Harddisk$devId$drSuffix ($($pd.FriendlyName)) ===>"
Write-Host " DeviceId: $devId | Serial: $($pd.SerialNumber) | Media: $($pd.MediaType) | Size: $($pd.SizeGB) GB"
try {
$partitions = Get-Partition -DiskNumber $devId -ErrorAction Stop
if (-not $partitions) {
Write-Host " (no partitions found)"
continue
}
foreach ($part in $partitions) {
$driveLetter = if ($part.DriveLetter) { "$($part.DriveLetter):" } else { 'no letter' }
$sizeGB = [math]::Round($part.Size / 1GB, 2)
$typeInfo = Get-PartitionTypeInfo -Partition $part
Write-Host " [PARTITION $($part.PartitionNumber)] Drive: $driveLetter - $sizeGB GB - $typeInfo"
}
} catch {
Write-Host " [ERROR] cannot read partitions for disk $devId"
}
}
if ($drMap.Count -eq 0) {
Write-Host ""
Write-Host "Note: no \Device\HarddiskN\DRx entries found in the last $MaxEvents System log events. Increase -MaxEvents, or the DR number will only appear once Windows actually logs a disk event for that drive (e.g. a bad block warning)."
}
EndPowerShell:
Comment: Verify that Discord does not have any injected code to intercept personal data. If anything is prompted here, it needs to be checked that it isn't malicious code.
Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) }
StartPowerShell:
# Basic BSOD listings
$ccKey = "HKLM:\SYSTEM\CurrentControlSet\Control\CrashControl"
$cfg = Get-ItemProperty $ccKey -ErrorAction SilentlyContinue
$dumpTypeMap = @{0='None';1='Complete';2='Kernel';3='Minidump';7='Automatic'}
Write-Output "--- Configuration ---"
Write-Output ("Dump Type: {0} ({1})" -f $cfg.CrashDumpEnabled, $dumpTypeMap[$cfg.CrashDumpEnabled])
Write-Output ("Full Dump Path: {0}" -f $(if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}))
Write-Output ("Minidump Folder: {0}" -f $(if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}))
Write-Output ("Auto Reboot: {0}" -f $(if($cfg.AutoReboot -eq 0){'Disabled'}else{'Enabled'}))
Write-Output "--- Found Dump Files ---"
$full = if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"}
if (Test-Path $full) { Get-Item $full | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
$mini = if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"}
if (Test-Path $mini) { Get-ChildItem $mini -Filter *.dmp | Select Name,Length,LastWriteTime | Format-Table -AutoSize }
Write-Output "--- BugCheck Reasoning (recent events) ---"
$map = @{
'0x0000000A'='IRQL_NOT_LESS_OR_EQUAL - faulty/outdated driver accessed memory at high IRQL'
'0x0000001E'='KMODE_EXCEPTION_NOT_HANDLED - unhandled kernel exception, often driver/hardware'
'0x0000002E'='DATA_BUS_ERROR - typically bad RAM or hardware fault'
'0x0000003B'='SYSTEM_SERVICE_EXCEPTION - exception in a system service, often driver-related'
'0x00000050'='PAGE_FAULT_IN_NONPAGED_AREA - bad RAM or faulty driver/antivirus'
'0x0000007A'='KERNEL_DATA_INPAGE_ERROR - disk-related problem'
'0x0000007B'='INACCESSIBLE_BOOT_DEVICE - system could not find/access the boot device'
'0x0000007E'='SYSTEM_THREAD_EXCEPTION_NOT_HANDLED - almost always a faulty driver'
'0x0000007F'='UNEXPECTED_KERNEL_MODE_TRAP - hardware issue (CPU/RAM/overclocking)'
'0x0000009F'='DRIVER_POWER_STATE_FAILURE - driver failed to respond to a power state change'
'0x000000C2'='BAD_POOL_CALLER - driver mishandling memory (pool corruption)'
'0x000000D1'='DRIVER_IRQL_NOT_LESS_OR_EQUAL - typically a network or GPU driver'
'0x000000EF'='CRITICAL_PROCESS_DIED - a critical system process died, often malware/system corruption'
'0x00000116'='VIDEO_TDR_FAILURE - GPU driver failed to respond in time (timeout)'
'0x00000124'='WHEA_UNCORRECTABLE_ERROR - hardware fault (CPU/RAM/PSU/overclocking)'
'0x00000133'='DPC_WATCHDOG_VIOLATION - faulty driver or storage subsystem issue'
'0x00000139'='KERNEL_SECURITY_CHECK_FAILURE - corrupted kernel structure, possibly malware'
}
$events = Get-WinEvent -FilterHashtable @{LogName='System';Id=1001} -MaxEvents 100 -ErrorAction SilentlyContinue |
Where-Object { $_.ProviderName -match 'WER-SystemErrorReporting' } | Select-Object -First 5
if (-not $events) { Write-Output "No BugCheck events found in the log." }
foreach ($ev in $events) {
$code = if ($ev.Message -match 'bugcheck was:\s*(0x[0-9A-Fa-f]+)') { $matches[1] } else { $null }
Write-Output ("Time: {0}" -f $ev.TimeCreated)
Write-Output ("Code: {0}" -f $(if($code){$code}else{'not recognized'}))
if ($code -and $map.ContainsKey($code.ToUpper())) {
Write-Output ("Meaning: {0}" -f $map[$code.ToUpper()])
} elseif ($code) {
Write-Output "Meaning: unknown code, look up at learn.microsoft.com/windows-hardware/drivers/debugger/bug-check-code-reference2"
}
Write-Output ""
}
EndPowerShell:
Comment: List recent Run (Windows + R) executed commands, useful for identifying ClickFix attacks
Powershell: (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" }
Comment: Lists all installed apps and their folder contents along with SHA256 hashes. Useful for troubleshooting malware abusing installed app entry
StartPowerShell:
param(
[switch]$Recurse,
[int]$MaxFilesPerApp = [int]::MaxValue
)
$uninstallPaths = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
$script:msiInstaller = $null
function Get-MsiInstallLocation {
param([string]$ProductCode)
if (-not $script:msiInstaller) {
try { $script:msiInstaller = New-Object -ComObject WindowsInstaller.Installer } catch { return $null }
}
try {
$loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallLocation')
if ([string]::IsNullOrWhiteSpace($loc)) { $loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallSource') }
if ([string]::IsNullOrWhiteSpace($loc)) { return $null }
return $loc
} catch { return $null }
}
function Get-CleanPath {
param([string]$RawValue)
if ([string]::IsNullOrWhiteSpace($RawValue)) { return $null }
$s = $RawValue.Trim()
if ($s.StartsWith('"')) {
$endQuote = $s.IndexOf('"', 1)
if ($endQuote -gt 0) { return $s.Substring(1, $endQuote - 1) }
}
if ($s -match '^(.*?\.exe)\b') { return $Matches[1] }
return $s
}
function Format-FileSize {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$script:PeExtensions = @('.exe', '.dll', '.sys', '.ocx', '.cpl', '.scr', '.drv', '.efi', '.msi', '.msp', '.msu')
function Test-IsPeFile {
param([string]$Extension)
return $script:PeExtensions -contains $Extension.ToLower()
}
function Get-SignatureInfo {
param([string]$Path, [string]$Extension)
if (-not (Test-IsPeFile -Extension $Extension)) {
return [PSCustomObject]@{ Signer = 'N/A (not PE)'; Status = 'NotApplicable'; Valid = $false }
}
$result = [PSCustomObject]@{ Signer = 'Unsigned'; Status = 'NotSigned'; Valid = $false }
try {
$sig = Get-AuthenticodeSignature -LiteralPath $Path -ErrorAction Stop
$result.Status = $sig.Status.ToString()
$result.Valid = ($sig.Status -eq 'Valid')
if ($sig.SignerCertificate) {
if ($sig.SignerCertificate.Subject -match 'CN=([^,]+)') { $result.Signer = $Matches[1].Trim('"') }
else { $result.Signer = $sig.SignerCertificate.Subject }
if (-not $result.Valid) { $result.Signer += " [INVALID: $($result.Status)]" }
} elseif ($sig.Status -eq 'NotSigned') {
$result.Signer = 'Unsigned'
} else {
$result.Signer = "Unknown [$($result.Status)]"
}
} catch {
$result.Signer = 'Verification error'
$result.Status = 'Error'
$result.Valid = $false
}
return $result
}
$rawApps = Get-ItemProperty -Path $uninstallPaths -ErrorAction SilentlyContinue |
Where-Object { $_.DisplayName -and $_.DisplayName.Trim() -ne '' } |
Select-Object @{Name = 'Name'; Expression = { $_.DisplayName } },
@{Name = 'Version'; Expression = { $_.DisplayVersion } },
@{Name = 'Publisher'; Expression = { $_.Publisher } },
@{Name = 'InstallFolder'; Expression = {
if ($_.InstallLocation -and $_.InstallLocation.Trim() -ne '') { $_.InstallLocation }
elseif ($_.UninstallString -match 'MsiExec\.exe.*?(\{[0-9A-Fa-f\-]{36}\})') {
$productCode = $Matches[1]
$msiLoc = Get-MsiInstallLocation -ProductCode $productCode
if ($msiLoc) { $msiLoc } else { "MSI: $productCode (location not found)" }
}
elseif ($_.UninstallString) { $_.UninstallString }
else { 'N/A' }
} } |
Sort-Object Name -Unique
foreach ($app in $rawApps) {
$versionText = if ($app.Version) { $app.Version } else { '?' }
$publisherText = if ($app.Publisher) { $app.Publisher } else { '?' }
Write-Host ""
Write-Host "<=== $($app.Name) [$versionText] ($publisherText) ===>"
if ($app.InstallFolder -eq 'N/A' -or $app.InstallFolder -match '^MSI: .* \(location not found\)$') {
Write-Host " Path: $($app.InstallFolder)"
continue
}
$cleanPath = Get-CleanPath -RawValue $app.InstallFolder
$exists = $false
try {
$exists = Test-Path -LiteralPath $cleanPath -ErrorAction Stop
} catch [System.UnauthorizedAccessException] {
Write-Host " Path: $cleanPath"
Write-Host " [ACCESS DENIED]"
continue
} catch {
Write-Host " Path: $cleanPath"
Write-Host " [ERROR] cannot access"
continue
}
if (-not $exists) {
Write-Host " Path: $cleanPath"
Write-Host " [NOT FOUND]"
continue
}
$rootItem = Get-Item -LiteralPath $cleanPath -Force
$created = $rootItem.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$modified = $rootItem.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
if ($rootItem.PSIsContainer) {
$subFolders = Get-ChildItem -LiteralPath $cleanPath -Directory -Force -ErrorAction SilentlyContinue
$gciParams = @{ LiteralPath = $cleanPath; File = $true; Force = $true; ErrorAction = 'SilentlyContinue' }
if ($Recurse) { $gciParams['Recurse'] = $true }
$allFiles = Get-ChildItem @gciParams
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: $($allFiles.Count) | Folders: $($subFolders.Count)"
foreach ($dir in $subFolders) {
$dCreated = $dir.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$dModified = $dir.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$dFileCount = (Get-ChildItem -LiteralPath $dir.FullName -File -Force -ErrorAction SilentlyContinue).Count
Write-Host (" [DIR] {0} - {1} - {2,10} - {3}" -f $dCreated, $dModified, "$dFileCount files", $dir.FullName)
}
} else {
$allFiles = @($rootItem)
Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: 1"
}
if ($allFiles.Count -eq 0) { continue }
$shown = $allFiles | Select-Object -First $MaxFilesPerApp
foreach ($f in $shown) {
$hash = 'N/A'
try { $hash = (Get-FileHash -LiteralPath $f.FullName -Algorithm SHA256 -ErrorAction Stop).Hash } catch { $hash = 'HASH-ERROR' }
$size = Format-FileSize -Bytes $f.Length
$fcreated = $f.CreationTime.ToString('dd/MM/yyyy HH:mm:ss')
$fmod = $f.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss')
$sigInfo = Get-SignatureInfo -Path $f.FullName -Extension $f.Extension
Write-Host (" [{0}] {1} - {2} - {3,10} - Signer: {4} - {5}" -f $hash, $fcreated, $fmod, $size, $sigInfo.Signer, $f.FullName)
}
}
EndPowerShell:
Comment: Remove unwanted files from common folders using native removal power of Farbar to include remove on reboot if needed. Please double check the user does not have any applications incorrectly installed in the directories listed below.
C:\ProgramData\*.csproj
C:\ProgramData\*.a3x
C:\ProgramData\*.ahk
C:\ProgramData\*.au3
C:\ProgramData\*.bat
C:\ProgramData\*.cab
C:\ProgramData\*.cmd
C:\ProgramData\*.com
C:\ProgramData\*.dll
C:\ProgramData\*.exe
C:\ProgramData\*.hta
C:\ProgramData\*.jar
C:\ProgramData\*.js
C:\ProgramData\*.jse
C:\ProgramData\*.lnk
C:\ProgramData\*.pif
C:\ProgramData\*.ps1
C:\ProgramData\*.py
C:\ProgramData\*.pyc
C:\ProgramData\*.pyd
C:\ProgramData\*.scr
C:\ProgramData\*.tmp
C:\ProgramData\*.vbe
C:\ProgramData\*.vbs
C:\ProgramData\*.wsf
C:\ProgramData\*.wsh
C:\ProgramData\*.zip
C:\ProgramData\*.rar
C:\ProgramData\*.7z
C:\Users\*\AppData\Roaming\*.csproj
C:\Users\*\AppData\Roaming\*.au3
C:\Users\*\AppData\Roaming\*.bat
C:\Users\*\AppData\Roaming\*.cab
C:\Users\*\AppData\Roaming\*.cmd
C:\Users\*\AppData\Roaming\*.com
C:\Users\*\AppData\Roaming\*.dll
C:\Users\*\AppData\Roaming\*.exe
C:\Users\*\AppData\Roaming\*.hta
C:\Users\*\AppData\Roaming\*.jar
C:\Users\*\AppData\Roaming\*.js
C:\Users\*\AppData\Roaming\*.jse
C:\Users\*\AppData\Roaming\*.lnk
C:\Users\*\AppData\Roaming\*.pif
C:\Users\*\AppData\Roaming\*.ps1
C:\Users\*\AppData\Roaming\*.py
C:\Users\*\AppData\Roaming\*.pyc
C:\Users\*\AppData\Roaming\*.pyd
C:\Users\*\AppData\Roaming\*.scr
C:\Users\*\AppData\Roaming\*.tmp
C:\Users\*\AppData\Roaming\*.vbe
C:\Users\*\AppData\Roaming\*.vbs
C:\Users\*\AppData\Roaming\*.wsf
C:\Users\*\AppData\Roaming\*.wsh
C:\Users\*\AppData\Roaming\*.zip
C:\Users\*\AppData\Roaming\*.rar
C:\Users\*\AppData\Roaming\*.7z
C:\Users\CurrentUserName\AppData\Local\*.csproj
C:\Users\CurrentUserName\AppData\Local\*.a3x
C:\Users\CurrentUserName\AppData\Local\*.ahk
C:\Users\CurrentUserName\AppData\Local\*.au3
C:\Users\CurrentUserName\AppData\Local\*.bat
C:\Users\CurrentUserName\AppData\Local\*.cab
C:\Users\CurrentUserName\AppData\Local\*.cmd
C:\Users\CurrentUserName\AppData\Local\*.com
C:\Users\CurrentUserName\AppData\Local\*.dll
C:\Users\CurrentUserName\AppData\Local\*.exe
C:\Users\CurrentUserName\AppData\Local\*.hta
C:\Users\CurrentUserName\AppData\Local\*.jar
C:\Users\CurrentUserName\AppData\Local\*.js
C:\Users\CurrentUserName\AppData\Local\*.jse
C:\Users\CurrentUserName\AppData\Local\*.lnk
C:\Users\CurrentUserName\AppData\Local\*.pif
C:\Users\CurrentUserName\AppData\Local\*.ps1
C:\Users\CurrentUserName\AppData\Local\*.py
C:\Users\CurrentUserName\AppData\Local\*.pyc
C:\Users\CurrentUserName\AppData\Local\*.pyd
C:\Users\CurrentUserName\AppData\Local\*.scr
C:\Users\CurrentUserName\AppData\Local\*.tmp
C:\Users\CurrentUserName\AppData\Local\*.vbe
C:\Users\CurrentUserName\AppData\Local\*.vbs
C:\Users\CurrentUserName\AppData\Local\*.wsf
C:\Users\CurrentUserName\AppData\Local\*.wsh
C:\Users\CurrentUserName\AppData\Local\*.zip
C:\Users\CurrentUserName\AppData\Local\*.rar
C:\Users\CurrentUserName\AppData\Local\*.7z
C:\Users\CurrentUserName\AppData\Roaming\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\*.a3x
C:\Users\CurrentUserName\AppData\Roaming\*.ahk
C:\Users\CurrentUserName\AppData\Roaming\*.au3
C:\Users\CurrentUserName\AppData\Roaming\*.bat
C:\Users\CurrentUserName\AppData\Roaming\*.cab
C:\Users\CurrentUserName\AppData\Roaming\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\*.com
C:\Users\CurrentUserName\AppData\Roaming\*.dll
C:\Users\CurrentUserName\AppData\Roaming\*.exe
C:\Users\CurrentUserName\AppData\Roaming\*.hta
C:\Users\CurrentUserName\AppData\Roaming\*.jar
C:\Users\CurrentUserName\AppData\Roaming\*.js
C:\Users\CurrentUserName\AppData\Roaming\*.jse
C:\Users\CurrentUserName\AppData\Roaming\*.lnk
C:\Users\CurrentUserName\AppData\Roaming\*.pif
C:\Users\CurrentUserName\AppData\Roaming\*.ps1
C:\Users\CurrentUserName\AppData\Roaming\*.py
C:\Users\CurrentUserName\AppData\Roaming\*.pyc
C:\Users\CurrentUserName\AppData\Roaming\*.pyd
C:\Users\CurrentUserName\AppData\Roaming\*.scr
C:\Users\CurrentUserName\AppData\Roaming\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\*.vbe
C:\Users\CurrentUserName\AppData\Roaming\*.vbs
C:\Users\CurrentUserName\AppData\Roaming\*.wsf
C:\Users\CurrentUserName\AppData\Roaming\*.wsh
C:\Users\CurrentUserName\AppData\Roaming\*.zip
C:\Users\CurrentUserName\AppData\Roaming\*.rar
C:\Users\CurrentUserName\AppData\Roaming\*.7z
Comment: RenPyLoader hollowed installed app generic removal
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cmd
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.props
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.targets
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.tmp
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.csproj
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.user
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cmd
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cache
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.config
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.bat
C:\Users\CurrentUserName\AppData\Local\NVIDIA\GeForce Experience Service\*.cfg
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\Caches\*.cfg
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\*.cfg
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\*.cfg
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.props
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.targets
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.tmp
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.csproj
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.user
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cmd
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.config
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.bat
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\WebCache\*.cfg
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.props
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.targets
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.tmp
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.csproj
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.user
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cmd
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cache
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.config
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.bat
C:\Users\CurrentUserName\AppData\Roaming\Microsoft\Crypto\*.cfg
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.props
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.targets
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.tmp
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.csproj
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cmd
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.user
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cache
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.config
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.bat
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\*.cfg
Comment: Remove cache
C:\Users\CurrentUserName\AppData\Local\Microsoft\Windows\INetCache\IE\
C:\Users\CurrentUserName\AppData\Local\Roblox\UniversalApp\WebView2\EBWebView\Default\Cache\Cache_Data\
C:\Users\CurrentUserName\AppData\Local\FortniteGame\Saved\webcache\
C:\Users\CurrentUserName\AppData\Local\FortniteGame\Saved\webcache_4147\
C:\Users\CurrentUserName\AppData\Local\FortniteGame\Saved\webcache_4430\
C:\Users\CurrentUserName\AppData\Roaming\discord\Cache\Cache_Data\
C:\Users\CurrentUserName\AppData\Roaming\obs-studio\plugin_config\obs-browser\Cache\Cache_Data\
StartPowerShell:
$ProfilesDirectory = (Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList').ProfilesDirectory
$DisplayNames = @{
"chrome" = "Chrome"
"firefox" = "Firefox"
"opera" = "Opera"
"operagx" = "Opera GX"
"brave" = "Brave"
"msedge" = "Edge"
"vivaldi" = "Vivaldi"
"librewolf" = "LibreWolf"
"mullvad" = "Mullvad Browser"
"zen" = "Zen"
}
$ProcessNameMap = @{
"operagx" = "opera"
"mullvad" = "mullvadbrowser"
}
$trueCacheNames = @("Cache", "Code Cache", "DawnCache", "GPUCache", "GrShaderCache", "ShaderCache", "Shared Dictionary\cache")
function Get-CacheDirs {
param([string]$BrowserName, [string]$ProfilesDirectory)
switch ($BrowserName) {
"chrome" {
$dir = "$ProfilesDirectory\*\AppData\Local\Google\Chrome\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"firefox" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mozilla\Firefox\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"opera" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"operagx" {
$dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software\Opera GX Stable"
$r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software\Opera GX Stable"
$r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
$r1 + $r2
}
"brave" {
$dir = "$ProfilesDirectory\*\AppData\Local\BraveSoftware\Brave-Browser\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"msedge" {
$dir = "$ProfilesDirectory\*\AppData\Local\Microsoft\Edge\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"vivaldi" {
$dir = "$ProfilesDirectory\*\AppData\Local\Vivaldi\User Data"
Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName }
}
"librewolf" {
$dir = "$ProfilesDirectory\*\AppData\Local\LibreWolf\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"mullvad" {
$dir = "$ProfilesDirectory\*\AppData\Local\Mullvad\MullvadBrowser\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
"zen" {
$dir = "$ProfilesDirectory\*\AppData\Local\zen\Profiles"
Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' }
}
}
}
function Format-Size {
param([long]$Bytes)
if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) }
if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) }
if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) }
return "$Bytes B"
}
$BrowserKeys = @('chrome', 'firefox', 'opera', 'operagx', 'brave', 'msedge', 'vivaldi', 'librewolf', 'mullvad', 'zen')
foreach ($key in $BrowserKeys) {
$procName = if ($ProcessNameMap.ContainsKey($key)) { $ProcessNameMap[$key] } else { $key }
Get-Process -Name $procName -ErrorAction SilentlyContinue | Stop-Process -Force -ErrorAction SilentlyContinue
}
Start-Sleep -Seconds 5
$grandBytes = 0L
$grandFiles = 0
$anyFound = $false
foreach ($key in $BrowserKeys) {
$cacheDirs = Get-CacheDirs -BrowserName $key -ProfilesDirectory $ProfilesDirectory
if (-not $cacheDirs -or $cacheDirs.Count -eq 0) { continue }
$anyFound = $true
$displayName = $DisplayNames[$key]
$browserBytes = 0L
$browserFiles = 0
foreach ($cacheDir in $cacheDirs) {
if (-not (Test-Path $cacheDir)) { continue }
$items = Get-ChildItem -Path $cacheDir -Force -Recurse -ErrorAction SilentlyContinue
$files = $items | Where-Object { -not $_.PSIsContainer }
$bytes = ($files | Measure-Object -Property Length -Sum).Sum
if (-not $bytes) { $bytes = 0 }
$browserFiles += $files.Count
$browserBytes += $bytes
Get-ChildItem -Path "$cacheDir\*" -Force -ErrorAction SilentlyContinue | Remove-Item -Force -Recurse -ErrorAction SilentlyContinue
}
$grandBytes += $browserBytes
$grandFiles += $browserFiles
Write-Host ("{0,-16} freed {1,10} ({2} files)" -f $displayName, (Format-Size $browserBytes), $browserFiles)
}
if (-not $anyFound) {
Write-Host "No cache found for any installed browser."
}
Write-Host ""
Write-Host ("Total freed: {0} ({1} files)" -f (Format-Size $grandBytes), $grandFiles)
EndPowerShell:
Comment: Windows Recovery Environment (Windows RE) status and enable
CMD: C:\Windows\System32\reagentc.exe /info
CMD: C:\Windows\System32\reagentc.exe /enable
Comment: Disable hidden file extensions
REG: reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "HideFileExt" /t REG_DWORD /d 0 /f
REG: reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt" /v "CheckedValue" /t REG_DWORD /d 0 /f
Comment: Verify WMI repository, repair & verify again
CMD: C:\Windows\System32\wbem\winmgmt.exe /verifyrepository
CMD: C:\Windows\System32\wbem\winmgmt.exe /salvagerepository
CMD: C:\Windows\System32\wbem\winmgmt.exe /verifyrepository
Comment: To rebuild the performance counter library values
StartBatch:
C:\Windows\System32\lodctr.exe" /R
C:\Windows\SysWOW64\lodctr.exe" /R
C:\Windows\System32\lodctr.exe /R
C:\Windows\SysWOW64\lodctr.exe /R
EndBatch:
Comment: Resync performance counter library values to WMI as well
CMD: C:\Windows\System32\wbem\winmgmt.exe /resyncperf
Comment: Force policy removal
C:\Windows\System32\GroupPolicyUsers
C:\Windows\System32\GroupPolicy
CMD: C:\Windows\System32\gpupdate.exe /force
Comment: Restores and hardens selected Microsoft Defender Antivirus preferences.
Comment: Tamper Protection must be temporarily disabled before applying these settings.
Comment: Thanks to AdvancedSetup from Malwarebytes
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows Defender|DisableAntiSpyware
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows Defender|DisableAntiVirus
StartPowerShell:
# Enable real-time and behavioral protection
Set-MpPreference -DisableRealtimeMonitoring $false
Set-MpPreference -DisableBehaviorMonitoring $false
# Enable potentially unwanted application blocking
Set-MpPreference -PUAProtection Enabled
# Enable cloud-delivered protection and automatic safe-sample submission
Set-MpPreference -MAPSReporting Advanced
Set-MpPreference -SubmitSamplesConsent SendSafeSamples
# Use Microsoft's recommended high cloud-blocking level
Set-MpPreference -CloudBlockLevel High
# Allow additional time for cloud analysis of suspicious files
Set-MpPreference -CloudExtendedTimeout 30
# Block connections to known malicious or untrusted network destinations
Set-MpPreference -EnableNetworkProtection Enabled
# Enable Block at First Sight
Set-MpPreference -DisableBlockAtFirstSeen $false
# Enable archive, removable-drive, network-file, download, and script scanning
Set-MpPreference -DisableArchiveScanning $false
Set-MpPreference -DisableRemovableDriveScanning $false
Set-MpPreference -DisableScanningNetworkFiles $false
Set-MpPreference -DisableIOAVProtection $false
Set-MpPreference -DisableScriptScanning $false
# Check for current security intelligence before starting a scan
Set-MpPreference -CheckForSignaturesBeforeRunningScan $true
# Enable supported DNS attack inspection and sinkholing when available
if ((Get-Command Set-MpPreference).Parameters.ContainsKey('EnableDnsSinkhole')) {
Set-MpPreference -EnableDnsSinkhole $true
}
# Sets signature update interval to 12 hours (default 24 hours)
Set-MpPreference -SignatureUpdateInterval 12
# Update Microsoft Defender security intelligence
Update-MpSignature
EndPowerShell:
Comment: List Windows Defender properties, settings
StartPowerShell:
function Write-Section {
param([string]$Title)
Write-Host ""
Write-Host "<=== $Title ===>"
}
Write-Section "Protection Status"
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntispywareEnabled, AntivirusEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, RealTimeProtectionEnabled, IsTamperProtected, NetworkProtectionStatus | Format-List
Write-Section "Signature / Engine Versions"
Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AntivirusSignatureVersion, AntispywareSignatureVersion | Format-List
Write-Section "Preferences / Configuration"
Get-MpPreference | Select-Object PUAProtection, MAPSReporting, SubmitSamplesConsent, CheckForSignaturesBeforeRunningScan, CloudBlockLevel, EnableNetworkProtection, DisableScriptScanning, DisableArchiveScanning, DisableRemovableDriveScanning, DisableScanningNetworkFiles, DisableScanningMappedNetworkDrivesForFullScan, DisableBlockAtFirstSeen, DisableHeuristics, DisableAutoExclusions | Format-List
Write-Section "Threat Detections"
$threats = Get-MpThreatDetection
if ($threats) {
$threats | Format-Table -AutoSize
} else {
Write-Host " (no threat detections found)"
}
EndPowerShell:
Comment: Enable recovery environment
CMD: C:\Windows\System32\bcdedit.exe /set {default} recoveryenabled yes
Comment: Restore original Windows services configuration
StartPowerShell:
Set-Service -Name "Netlogon" -StartupType Manual
Set-Service -Name "BITS" -StartupType Manual
Set-Service -Name "Dhcp" -StartupType Automatic
Set-Service -Name "EventLog" -StartupType Automatic
Set-Service -Name "EventSystem" -StartupType Automatic
Set-Service -Name "nsi" -StartupType Automatic
Set-Service -Name "RasMan" -StartupType Manual
Set-Service -Name "SDRSVC" -StartupType Manual
Set-Service -Name "SstpSvc" -StartupType Manual
Set-Service -Name "TrustedInstaller" -StartupType Manual
Set-Service -Name "VSS" -StartupType Manual
Set-Service -Name "Winmgmt" -StartupType Automatic
Set-Service -Name "wuauserv" -StartupType Manual
EndPowerShell:
Comment: BITS reset
Startbatch:
@echo off
C:\Windows\System32\net.exe stop BITS
C:\Windows\System32\ipconfig.exe /flushdns
ren "%programdata%\Microsoft\Network\Downloader\qmgr*.*" qmgr*.*.old
C:\Windows\System32\net.exe start BITS
Endbatch:
cmd: C:\Windows\System32\bitsadmin.exe /reset /allusers
Comment: Reset the Windows Update download cache and update catalog database
CMD: C:\Windows\System32\net.exe stop wuauserv /y
CMD: C:\Windows\System32\net.exe stop cryptSvc /y
CMD: C:\Windows\System32\net.exe stop bits /y
CMD: C:\Windows\System32\net.exe stop msiserver /y
Unlock: C:\Windows\SoftwareDistribution
CMD: ren C:\Windows\SoftwareDistribution SoftwareDistribution.old
Unlock: C:\Windows\System32\CatRoot2
CMD: ren C:\Windows\System32\CatRoot2 CatRoot2.old
CMD: C:\Windows\System32\net.exe start wuauserv /y
CMD: C:\Windows\System32\net.exe start cryptSvc /y
CMD: C:\Windows\System32\net.exe start bits /y
CMD: C:\Windows\System32\net.exe start msiserver /y
Comment: Resets icon cache
StartBatch:
del /a /q "%localappdata%\IconCache.db"
del /a /f /q "%localappdata%\Microsoft\Windows\Explorer\iconcache*"
del /a /f /q "%localappdata%\Microsoft\Windows\Explorer\thumbcache*"
EndBatch:
Comment: Disable automatic restart after a crash, enable automatic updates
StartRegedit:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl]
"AutoReboot"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"NoAutoUpdate"=-
EndRegedit:
Comment: Reset PowerShell execution policy
Powershell: Set-ExecutionPolicy Unrestricted -Scope CurrentUser -Force
Comment: Fully reset the Windows network stack, WinHTTP proxy settings, DNS cache, and BITS transfer queue.
Comment: Thanks to AdvancedSetup from Malwarebytes
StartBatch:
C:\Windows\System32\ipconfig.exe /flushdns
C:\Windows\System32\ipconfig.exe /release
C:\Windows\System32\netsh.exe winsock reset catalog
C:\Windows\System32\netsh.exe int ip reset
C:\Windows\System32\netsh.exe winhttp reset proxy
C:\Windows\System32\netsh.exe winhttp reset autoproxy
C:\Windows\System32\netsh.exe winhttp reset tracing
EndBatch:
Comment: Enable all firewall profiles
CMD: C:\Windows\System32\netsh.exe advfirewall set allprofiles state on
Comment: Additional temp file removal
C:\Windows\System32\config\systemprofile\AppData\Local\*.tmp
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
C:\Users\CurrentUserName\AppData\Local\Temp\*
C:\Windows\Temp\*
C:\Windows\SystemTemp\*
C:\Windows\Prefetch\*
CMD: C:\Windows\System32\taskkill.exe /f /im "msiexec.exe"
StartPowerShell:
Get-ChildItem C:\Windows\Installer -Directory -Force |
Where-Object { $_.Name -like 'MSI*.tmp-*' -or $_.Name -like 'MSI*.tmp-' } |
Remove-Item -Recurse -Force -Verbose
EndPowerShell:
StartBatch:
del /f /s /q "%temp%\*.*"
rd /s /q "%temp%"
md "%temp%"
EndBatch:
Comment: System repair commands
CMD: C:\Windows\System32\SFC.exe /scannow
CMD: C:\Windows\System32\DISM.exe /Online /Cleanup-image /Restorehealth
Comment: Remove set proxy servers
RemoveProxy:
Comment: Remove temporary files via FRST
EmptyTemp:
End::
Warning
Executing a Fixlist on the wrong system may permanently damage it. Continue only if this link was meant for you.
To view the content, acknowledge this warning.