Windows NT KAMIDAKI 10.0 build 19045 (Windows 10) AMD64
Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.3.9
Server IP : 192.168.3.16 & Your IP : 216.73.216.204
Domains :
Cant Read [ /etc/named.conf ]
User : SISTEMA
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
C: /
Windows /
diagnostics /
system /
Apps /
Delete
Unzip
Name
Size
Permission
Date
Action
en-US
[ DIR ]
drwxrwxrwx
2023-03-23 12:54
pt-BR
[ DIR ]
drwxrwxrwx
2019-12-07 15:53
DiagPackage.diagpkg
14.47
KB
-rw-rw-rw-
2019-12-07 10:09
DiagPackage.dll
148.5
KB
-rw-rw-rw-
2019-12-07 10:09
RC_ConnectedAccount.ps1
1.19
KB
-rw-rw-rw-
2019-12-07 10:09
RC_TempInetFolder.ps1
2.15
KB
-rw-rw-rw-
2019-12-07 10:09
RC_TemporaryProfile.ps1
382
B
-rw-rw-rw-
2019-12-07 10:09
RC_UAC.ps1
1.44
KB
-rw-rw-rw-
2019-12-07 10:09
RC_WSReset.ps1
2.78
KB
-rw-rw-rw-
2019-12-07 10:09
RS_ConnectedAccount.ps1
347
B
-rw-rw-rw-
2019-12-07 10:09
RS_TempInetFolder.ps1
2.33
KB
-rw-rw-rw-
2019-12-07 10:09
RS_TemporaryProfile.ps1
370
B
-rw-rw-rw-
2019-12-07 10:09
RS_UAC.ps1
1.04
KB
-rw-rw-rw-
2019-12-07 10:09
RS_WSReset.ps1
362
B
-rw-rw-rw-
2019-12-07 10:09
TS_Main.ps1
1.76
KB
-rw-rw-rw-
2019-12-07 10:09
Utils_Apps.ps1
10.77
KB
-rw-rw-rw-
2019-12-07 10:09
VF_UAC.ps1
1.5
KB
-rw-rw-rw-
2019-12-07 10:09
VF_WSReset.ps1
2.73
KB
-rw-rw-rw-
2019-12-07 10:09
Save
Rename
# Copyright © 2017, Microsoft Corporation. All rights reserved. # :: ======================================================= :: PARAM($DateProblemDetected) #==================================================================================== # Initialize #==================================================================================== $APP_DELETE_EVENT_ID = 41 $APP_CREATE_EVENT_ID = 39 $APP_STATUS_EVENT_ID = 70 $PACKAGE_STATUS_MASK_BAD = @{0x00000001 = "LICENSE_ISSUE"; 0x00000002 = "MODIFIED_PACKAGE"; 0x00000100 = "MODIFIED_STATE"; 0x00000200 = "MODIFIED_DATA"; 0x00000004 = "TAMPERED"} function Get-AppContainerEvents([System.DateTime]$StartDate) { return Get-WinEvent -FilterHashtable @{logname='Microsoft-Windows-AppModel-Runtime/Admin';id=$APP_DELETE_EVENT_ID,$APP_CREATE_EVENT_ID,$APP_STATUS_EVENT_ID;StartTime=$StartDate} -ErrorAction SilentlyContinue } function Get-UniqueAppNames($Events) { $faultyApps = New-Object System.Collections.ArrayList if ($Events.Count -gt 0) { $i = 0 foreach ($event in $Events) { $i++ if ($event.Message -match ".*[ ](.*?)[.](.*?)_") { $faultyApps += "$($Matches[2])" } } } $faultyApps = $faultyApps | Select -Unique $faultyApps } function Get-AppResetComplete($Events, $AppName) { $AppDeleteEvent = $Events | Where-Object {$_.message.contains("$AppName") -eq $true -and $_.id -eq $APP_DELETE_EVENT_ID} $AppCreateEvent = $Events | Where-Object {$_.message.contains("$AppName") -eq $true -and $_.id -eq $APP_CREATE_EVENT_ID} $AppStatusEvent = $Events | Where-Object {$_.message.contains("$AppName") -eq $true -and $_.id -eq $APP_STATUS_EVENT_ID} | Sort-Object TimeCreated -Descending | Select-Object -first 1 # Compare current package status against bitmask $IsPackageDamaged = ($PACKAGE_STATUS_MASK_BAD.Keys | where { $_ -band $AppStatusEvent.Properties[2].value}).Count -gt 0 return ($AppDeleteEvent -ne $null -and $AppCreateEvent -ne $null -and $IsPackageDamaged -eq $false) } #==================================================================================== # Main #==================================================================================== $AppContainerEvents = Get-AppContainerEvents -StartDate $DateProblemDetected $UniqueAppNames = Get-UniqueAppNames $AppContainerEvents $AppRepairComplete = $false foreach ($AppName in $UniqueAppNames) { $AppRepairStatus = Get-AppResetComplete $AppContainerEvents $AppName if ($AppRepairStatus -eq $true) { $AppRepairComplete = $true break } } Update-DiagRootCause -Id 'RC_WSReset' -Detected (-not $AppRepairComplete)