This commit is contained in:
2020-08-14 14:19:37 -04:00
parent d18f8dad97
commit f2b358d8dd
24 changed files with 253 additions and 180 deletions
+63
View File
@@ -0,0 +1,63 @@
Function global:Cleanup-SystemPath
{
## Get contents of SYSTEM PATH environment variable
$REG_ENVVAR = 'HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Environment'
$CURRENT_PATH = (Get-Itemproperty -Path $REG_ENVVAR -Name Path).Path
$NEW_PATH = $null
$REMOVE_PATH =$null
## Verify each path
Foreach ( $path in $CURRENT_PATH.Split(";") )
{
If ( (Test-Path $path) -or ($path -like "*%*%*") )
{
If ( $NEW_PATH ) { $NEW_PATH += ";${path}" }
Else { $NEW_PATH = $path }
}
Else
{
If ( $REMOVE_PATH ) { $REMOVE_PATH += ";${path}" }
Else { $REMOVE_PATH = $path }
}
}
Write-Output "Removed Paths:`n`r${REMOVE_PATH}"
Set-ItemProperty -Path $REG_ENVVAR -Name Path -Value $NEW_PATH
}
## This script will remove runaway AppX temp files that can consume 100's of GB on an endpoint
Function global:Cleanup-AppXTempFiles
{
## Only run this script on Windows 8 or higher endpoints
$WindowsVersion = [double]("{0}.{1}" -f ([System.Environment]::OSVersion.Version).Major,([System.Environment]::OSVersion.Version).Minor)
If ( $WindowsVersion -ge 6.2 )
{
Get-ChildItem -Path "${Env:SystemRoot}\Temp" | Where { $_.Name -like "AppXDeploymentServer_*.evtx" }| Remove-Item -Force
Get-ChildItem -Path "${Env:SystemRoot}\Temp" | Where { $_.Name -like "AppxErrorReport_*.txt" } | Remove-Item -Force
Get-ChildItem -Path "${Env:SystemRoot}\Temp" | Where { $_.Name -like "AppXPackaging_*.evtx" }| Remove-Item -Force
}
}
## This script will delete runaway CBS logs that can take up 100's of GB on an endpoint
Function global:Cleanup-LogFiles
{
Get-ChildItem -Path "${Env:WINDIR}\Logs\CBS" -File | Where { ( $_.Name -like "CbsPersist_*.log" ) -or ( $_.Name -like "CbsPersist_*.cab" ) } | Remove-Item -Force
}
Function global:Cleanup-TempFiles
{
#[CmdletBinding()]
param([int]$OlderThan=7)
## Create a new timespan to compare with last write date of the target directory
$timedelta = New-TimeSpan -Days $OlderThan
## Remove all files and directories
Foreach ( $item in (Get-ChildItem -Path "${Env:WinDir}\TEMP") )
{
## If it's older than the number of days specified, recursively delete the directory
If ( $item.LastWriteTime -lt ((Get-Date) - $timedelta) ) { Remove-Item $item.FullName -Recurse -ErrorAction SilentlyContinue -Force }
}
}
+90
View File
@@ -0,0 +1,90 @@
Function global:Fix-WindowsScriptingComponents
{
## List of all scripting component DLL files
$DLL_FILES = @("${Env:WINDIR}\system32\vbscript.dll",
"${Env:WINDIR}\system32\jscript.dll",
"${Env:WINDIR}\system32\dispex.dll",
"${Env:WINDIR}\system32\scrobj.dll",
"${Env:WINDIR}\system32\scrrun.dll",
"${Env:WINDIR}\system32\wshext.dll"
"${Env:WINDIR}\system32\wshom.ocx",
"${Env:WINDIR}\syswow64\vbscript.dll",
"${Env:WINDIR}\syswow64\jscript.dll",
"${Env:WINDIR}\syswow64\dispex.dll",
"${Env:WINDIR}\syswow64\scrobj.dll",
"${Env:WINDIR}\syswow64\scrrun.dll",
"${Env:WINDIR}\syswow64\wshext.dll",
"${Env:WINDIR}\syswow64\wshom.ocx")
## Unregister all DLLs
ForEach ($dll in $DLL_FILES)
{
If ( Test-Path $dll )
{
If ( $dll -Match "syswow64" ) { $REGSVR32 = "${Env:WINDIR}\syswow64\regsvr32" } Else { $REGSVR32 = "regsvr32" }
Start-Process "${REGSVR32}" -ArgumentList "/u /s ${dll}" -Wait
}
}
## Register all DLLs
ForEach ($dll in $DLL_FILES)
{
If ( Test-Path $dll )
{
If ( $dll -Match "syswow64" )
{ $REGSVR32 = "${Env:WINDIR}\syswow64\regsvr32" } Else { $REGSVR32 = "regsvr32" }
Start-Process "${REGSVR32}" -ArgumentList "/s ${dll}" -Wait
}
}
}
Function global:Fix-SystemPrintQueue
{
## Make sure the spooler service isn't already stopped
If ( (Get-Service -Name spooler).Status -ne "Stopped" )
{
## Forcefully stop the spooler service
Stop-Service -Name spooler -Force
## Wait a few seconds to make sure it's stopped
Start-Sleep -Seconds 5
}
## Check to make sure the spooler service has stopped
If ((Get-Service -Name spooler).Status -eq "Stopped")
{
## Delete all print jobs, including secure prints
Remove-Item "${Env:WINDIR}\System32\spool\PRINTERS\*" -Recurse
## Start the spooler service again
Start-Service -Name spooler
}
## If the spooler service didn't stop on time, just return an error
Else { Write-Output "Could not clean ${Env:WINDIR}\System32\spool\PRINTERS\* because spooler service is running." }
}
Function global:Fix-WindowsUpdate
{
param([switch]$WSUS)
## Delete any existing folder from a previous execution of this script
If ( Test-Path "${Env:WinDir}\SoftwareDistribution.old" ) { Remove-Item "${Env:WinDir}\SoftwareDistribution.old" -Recurse -Force }
## Stop Background Intelligent Transfer Services and Windows Update
Stop-Service BITS
Stop-Service wuauserv
## Rename the SoftwareDistribution folder, forcing Windows Update to recreate all metrics and redownload all updates
Rename-Item -Path "${Env:WinDir}\SoftwareDistribution" -NewName "${Env:WinDir}\SoftwareDistribution.old" -Force
## Start Windows Update and Background Intelligent Transfer Services
Start-Service wuauserv
Start-Service BITS
## Delete SoftwareDistribution.old from this execution of this script
If ( Test-Path "${Env:WinDir}\SoftwareDistribution.old" ) { Remove-Item "${Env:WinDir}\SoftwareDistribution.old" -Recurse -Force }
## If using WSUS, reset authorization with server and detect new updates
If ( $WSUS ) { Start-Process "${Env:WinDir}\System32\wuauctl.exe" -ArgumentList "/resetauthorization /detectnow" }
}
+37
View File
@@ -0,0 +1,37 @@
Function global:Remediation-StopProcess
{
param([string]$Name,[switch]$Force=$false)
If ( $Name )
{
## Get all matching processes
$Processes = Get-Process | Where { $_.Name -ilike $Name }
## Get the total number of matching processes
$NumMatches = $Processes.Count
If ( $NumMatches -ge 1 )
{
## Forcefully close matching processes
If ( $Force )
{
Foreach ( $proc in $Processes ) { Stop-Process $proc -Force -ErrorAction SilentlyContinue }
Write-Output "Forcefully closed ${NumMatches} matching instance(s) of ${Name}"
}
## Gracefully close matching processes
Else
{
Foreach ( $proc in $Processes ) { $proc.CloseMainWindow() | Out-Null }
Write-Output "Gracefully closed ${NumMatches} matching instance(s) of ${Name}"
}
}
Else { Write-Output "No running processes match the name ${Name}" }
}
Else { Write-Output "No process name was specified!" }
}
Export-ModuleMember -Function Remediation-StopProcess
+19
View File
@@ -0,0 +1,19 @@
Function global:Remove-DeltekVision
{
## Stop the DeltekVision process
Remediation-StopProcess -Name "DeltekVision" -Force
## Set the path to Deltek Vision
$APP_PATH = "${Env:UserProfile}\AppData\Local\Apps\2.0"
## Test to make sure it's installed for the current user before continuing
If ( Test-Path $APP_PATH )
{
## Delete the existing installed app
Try { Remove-Item $APP_PATH -Recurse -Force }
Catch { Write-Output $_.Exception.Message }
} Else { Write-Output "${APP_PATH} does not exist!" }
}
Export-ModuleMember -Function Remove-DeltekVision
View File
Binary file not shown.