From 23d7c7cb0ca27d1725a10cfc758d836d68e928f7 Mon Sep 17 00:00:00 2001 From: dyoder Date: Wed, 9 Sep 2020 14:56:33 -0400 Subject: [PATCH] overhaul with better file handling and speed --- Cleanup-SystemTempFiles.ps1 | 85 +++++++++++++++++++++++-------------- 1 file changed, 52 insertions(+), 33 deletions(-) diff --git a/Cleanup-SystemTempFiles.ps1 b/Cleanup-SystemTempFiles.ps1 index c5c3fdd..f4da79b 100644 --- a/Cleanup-SystemTempFiles.ps1 +++ b/Cleanup-SystemTempFiles.ps1 @@ -1,40 +1,59 @@ -$SysTemp = "${Env:SystemRoot}\TEMP" +## Path to the system temp folder +$SysTemp = "${Env:SystemRoot}\TEMP" -## Remove runaway AppX logs;n -If ( (IsWindowsVersion -ge "6.2") ) +## When deleting temp files en masse, only delete files/folders older than the number of days specified here +$OlderThan = 7 +$TimeDelta = New-TimeSpan -Days $OlderThan + +## Only run this section if we have administrative privileges +If ( IsAdmin ) { - Write-Output "Deleting old AppX log files from ${SysTemp}" - Get-ChildItem -Path $SysTemp | Where { $_.Name -like "AppXDeploymentServer_*.evtx" } | Remove-Item -Force -ErrorAction SilentlyContinue - Get-ChildItem -Path $SysTemp | Where { $_.Name -like "Microsoft-Windows-AppXDeploymentServer_*.evtx" } | Remove-Item -Force -ErrorAction SilentlyContinue - Get-ChildItem -Path $SysTemp | Where { $_.Name -like "AppxErrorReport_*.txt" } | Remove-Item -Force -ErrorAction SilentlyContinue - Get-ChildItem -Path $SysTemp | Where { $_.Name -like "AppXPackaging_*.evtx" } | Remove-Item -Force -ErrorAction SilentlyContinue + Write-Output "Running with administrative privileges" + + ## Remove all *.evtx files from $SysTemp + $EventLogs = Get-ChildItem -Path "${SysTemp}\*" -File -Filter *.evtx + If ( $EventLogs ) + { + Write-Output "Deleting all event logs from ${SysTemp}" + ForEach ( $EventLog in $EventLogs ) { Remove-Item $EventLog -Force -ErrorAction SilentlyContinue } + } + + ## Remove misc logs and error reports + $MiscLogs = Get-ChildItem -Path "${SysTemp}\*" -File -Include "${Env:COMPUTERNAME}-*.log", "AppxErrorReport_*.txt" + If ( $MiscLogs ) + { + Write-Output "Deleting misc logs from ${SysTemp}" + ForEach ( $MiscLog in $MiscLogs ) { Remove-Item $MiscLog -Force -ErrorAction SilentlyContinue } + } + + ## Remove archived CBS logs + $CBSLogs = Get-ChildItem -Path "${Env:SystemRoot}\Logs\CBS\*" -File -Include "CbsPersist_*.log", "CbsPersist_*.cab" + If ( $CBSLogs ) + { + Write-Output "Deleting archived CBS logs from ${Env:SystemRoot}\Logs\CBS" + ForEach ( $CBSLog in $CBSLogs ) { Remove-Item $CBSLog -Force -ErrorAction SilentlyContinue } + + } + + ## Remove all system temp files older than 7 days + $OldTempFiles = Get-ChildItem -Path $SysTemp | Where { $_.LastWriteTime -lt ((Get-Date) - $TimeDelta) } + If ( $OldTempFiles ) + { + Write-Output "Deleting all temp files not modified in ${OlderThan} day(s) from ${SysTemp}" + ForEach ( $OldTempFile in $OldTempFiles ) { Remove-Item $OldTempFile -Force -Recurse -ErrorAction SilentlyContinue } + } } -## Remove computer log files -Get-ChildItem -Path $SysTemp | Where { $_.Name -like "Microsoft-Windows-AppReadiness_*.evtx" } | Remove-Item -Force -ErrorAction SilentlyContinue -Get-ChildItem -Path $SysTemp | Where { $_.Name -like "${Env:COMPUTERNAME}-*.log" } | Remove-Item -Force -ErrorAction SilentlyContinue -Get-ChildItem -Path $SysTemp | Where { $_.Name -like "Application_*.evtx" } | Remove-Item -Force -ErrorAction SilentlyContinue -Get-ChildItem -Path $SysTemp | Where { $_.Name -like "System_*.evtx" } | Remove-Item -Force -ErrorAction SilentlyContinue -Get-ChildItem -Path $SysTemp | Where { $_.Name -like "Microsoft-Windows-WindowsUpdateClient_*.evtx" } | Remove-Item -Force -ErrorAction SilentlyContinue -Get-ChildItem -Path $SysTemp | Where { $_.Name -like "Microsoft-Windows-Store_*.evtx" } | Remove-Item -Force -ErrorAction SilentlyContinue -Get-ChildItem -Path $SysTemp | Where { $_.Name -like "Microsoft-Windows-StateRepository_*.evtx" } | Remove-Item -Force -ErrorAction SilentlyContinue -Get-ChildItem -Path $SysTemp | Where { $_.Name -like "Microsoft-Windows-SettingSync_*.evtx" } | Remove-Item -Force -ErrorAction SilentlyContinue - -## Remove runaway CBS logs -$CBSLogDir = "${Env:SystemRoot}\Logs\CBS" -If ( Test-Path $CBSLogDir ) +## Only run this section if we don't have administrative privileges +Else { - Write-Output "Deleting old CBS log files from ${CBSLogDir}" - Get-ChildItem -Path $CBSLogDir -File | Where { ( $_.Name -like "CbsPersist_*.log" ) -or ( $_.Name -like "CbsPersist_*.cab" ) } | Remove-Item -Force -ErrorAction SilentlyContinue -} - -## Remove all system temp files older than the specified number of days -$OlderThan=7 -$timedelta = New-TimeSpan -Days $OlderThan -Write-Output "Deleting all files more than ${OlderThan} day(s) old ${SysTemp}" -Foreach ( $item in (Get-ChildItem -Path "${SysTemp}") ) -{ - ## If it's older than the number of days specified, recursively delete the directory - If ( $item.LastWriteTime -lt ((Get-Date) - $timedelta) ) { Remove-Item $item.FullName -Recurse -ErrorAction SilentlyContinue -Force } + Write-Output "Running without administrative privileges" + ## Remove all system temp files older than 7 days + $OldTempFiles = Get-ChildItem -Path $Env:TEMP | Where { $_.LastWriteTime -lt ((Get-Date) - $TimeDelta) } + If ( $OldTempFiles ) + { + Write-Output "Deleting all temp files not modified in ${OlderThan} day(s) from ${Env:TEMP}" + ForEach ( $OldTempFile in $OldTempFiles ) { Remove-Item $OldTempFile -Force -Recurse -ErrorAction SilentlyContinue } + } }