|
2023-05-12 04:58:52,234 792 [DEBUG] - XmlConfiguration is now operational
|
|
2023-05-12 04:58:52,376 792 [DEBUG] - Adding new type 'WebPiService' for type 'ISourceRunner' from assembly 'choco'
|
|
2023-05-12 04:58:52,390 792 [DEBUG] - Adding new type 'WindowsFeatureService' for type 'ISourceRunner' from assembly 'choco'
|
|
2023-05-12 04:58:52,391 792 [DEBUG] - Adding new type 'CygwinService' for type 'ISourceRunner' from assembly 'choco'
|
|
2023-05-12 04:58:52,391 792 [DEBUG] - Adding new type 'PythonService' for type 'ISourceRunner' from assembly 'choco'
|
|
2023-05-12 04:58:52,391 792 [DEBUG] - Adding new type 'RubyGemsService' for type 'ISourceRunner' from assembly 'choco'
|
|
2023-05-12 04:58:52,391 792 [DEBUG] - Adding new type 'SystemStateValidation' for type 'IValidation' from assembly 'choco'
|
|
2023-05-12 04:58:52,688 792 [DEBUG] - Registering new command 'templates' in assembly 'choco'
|
|
2023-05-12 04:58:52,688 792 [DEBUG] - Registering new command 'upgrade' in assembly 'choco'
|
|
2023-05-12 04:58:52,703 792 [DEBUG] - Registering new command 'export' in assembly 'choco'
|
|
2023-05-12 04:58:52,703 792 [DEBUG] - Registering new command 'list' in assembly 'choco'
|
|
2023-05-12 04:58:52,703 792 [DEBUG] - Registering new command 'info' in assembly 'choco'
|
|
2023-05-12 04:58:52,703 792 [DEBUG] - Registering new command 'help' in assembly 'choco'
|
|
2023-05-12 04:58:52,719 792 [DEBUG] - Registering new command 'config' in assembly 'choco'
|
|
2023-05-12 04:58:52,719 792 [DEBUG] - Registering new command 'feature' in assembly 'choco'
|
|
2023-05-12 04:58:52,719 792 [DEBUG] - Registering new command 'new' in assembly 'choco'
|
|
2023-05-12 04:58:52,719 792 [DEBUG] - Registering new command 'outdated' in assembly 'choco'
|
|
2023-05-12 04:58:52,734 792 [DEBUG] - Registering new command 'pack' in assembly 'choco'
|
|
2023-05-12 04:58:52,734 792 [DEBUG] - Registering new command 'pin' in assembly 'choco'
|
|
2023-05-12 04:58:52,734 792 [DEBUG] - Registering new command 'push' in assembly 'choco'
|
|
2023-05-12 04:58:52,750 792 [DEBUG] - Registering new command 'apikey' in assembly 'choco'
|
|
2023-05-12 04:58:52,750 792 [DEBUG] - Registering new command 'sources' in assembly 'choco'
|
|
2023-05-12 04:58:52,750 792 [DEBUG] - Registering new command 'uninstall' in assembly 'choco'
|
|
2023-05-12 04:58:52,766 792 [DEBUG] - Registering new command 'unpackself' in assembly 'choco'
|
|
2023-05-12 04:58:52,766 792 [DEBUG] - Registering new command 'install' in assembly 'choco'
|
|
2023-05-12 04:58:53,078 792 [INFO ] - ============================================================
|
|
2023-05-12 04:58:53,438 792 [INFO ] - Chocolatey v1.3.0
|
|
2023-05-12 04:58:53,469 792 [DEBUG] - Chocolatey is running on Windows v 10.0.17763.0
|
|
2023-05-12 04:58:53,485 792 [DEBUG] - Attempting to delete file "C:/ProgramData/chocolatey/choco.exe.old".
|
|
2023-05-12 04:58:53,485 792 [DEBUG] - Attempting to delete file "C:\ProgramData\chocolatey\choco.exe.old".
|
|
2023-05-12 04:58:53,516 792 [DEBUG] - Command line: "C:\ProgramData\chocolatey\choco.exe" uninstall osquery --version 5.8.2 -dvy --execution-timeout=2700
|
|
2023-05-12 04:58:53,531 792 [DEBUG] - Received arguments: uninstall osquery --version 5.8.2 -dvy --execution-timeout=2700
|
|
2023-05-12 04:58:53,703 792 [DEBUG] - RemovePendingPackagesTask is now ready and waiting for PreRunMessage.
|
|
2023-05-12 04:58:53,735 792 [DEBUG] - Sending message 'PreRunMessage' out if there are subscribers...
|
|
2023-05-12 04:58:53,766 792 [DEBUG] - [Pending] Removing all pending packages that should not be considered installed...
|
|
2023-05-12 04:58:53,922 792 [DEBUG] - Performing validation checks.
|
|
2023-05-12 04:58:53,938 792 [DEBUG] - Global Configuration Validation Checks:
|
|
2023-05-12 04:58:53,953 792 [DEBUG] - - Package Exit Code / Exit On Reboot = Checked
|
|
2023-05-12 04:58:53,969 792 [DEBUG] - System State Validation Checks:
|
|
2023-05-12 04:58:53,969 792 [DEBUG] - Reboot Requirement Checks:
|
|
2023-05-12 04:58:53,984 792 [DEBUG] - - Pending Computer Rename = Checked
|
|
2023-05-12 04:58:54,000 792 [DEBUG] - - Pending Component Based Servicing = Checked
|
|
2023-05-12 04:58:54,000 792 [DEBUG] - - Pending Windows Auto Update = Checked
|
|
2023-05-12 04:58:54,016 792 [DEBUG] - - Pending File Rename Operations = Ignored
|
|
2023-05-12 04:58:54,016 792 [DEBUG] - - Pending Windows Package Installer = Checked
|
|
2023-05-12 04:58:54,031 792 [DEBUG] - - Pending Windows Package Installer SysWow64 = Checked
|
|
2023-05-12 04:58:54,046 792 [INFO ] - 2 validations performed. 2 success(es), 0 warning(s), and 0 error(s).
|
|
2023-05-12 04:58:54,094 792 [DEBUG] - The source 'c:\cached-packages;https://community.chocolatey.org/api/v2/' evaluated to a 'normal' source type
|
|
2023-05-12 04:58:54,094 792 [DEBUG] -
|
|
NOTE: Hiding sensitive configuration data! Please double and triple
|
|
check to be sure no sensitive data is shown, especially if copying
|
|
output to a gist for review.
|
|
2023-05-12 04:58:54,141 792 [DEBUG] - Configuration: CommandName='uninstall'|
|
|
CacheLocation='C:\Users\vagrant\AppData\Local\Temp\chocolatey'|
|
|
ContainsLegacyPackageInstalls='True'|
|
|
CommandExecutionTimeoutSeconds='2700'|WebRequestTimeoutSeconds='30'|
|
|
Sources='c:\cached-packages;https://community.chocolatey.org/api/v2/'|
|
|
SourceType='normal'|Debug='True'|Verbose='True'|Trace='False'|
|
|
Force='False'|Noop='False'|HelpRequested='False'|
|
|
UnsuccessfulParsing='False'|RegularOutput='True'|QuietOutput='False'|
|
|
PromptForConfirmation='False'|DisableCompatibilityChecks='False'|
|
|
AcceptLicense='True'|AllowUnofficialBuild='False'|Input='osquery'|
|
|
Version='5.8.2'|AllVersions='False'|SkipPackageInstallProvider='False'|
|
|
SkipHookScripts='False'|PackageNames='osquery'|Prerelease='False'|
|
|
ForceX86='False'|OverrideArguments='False'|NotSilent='False'|
|
|
ApplyPackageParametersToDependencies='False'|
|
|
ApplyInstallArgumentsToDependencies='False'|IgnoreDependencies='False'|
|
|
AllowMultipleVersions='False'|AllowDowngrade='False'|
|
|
ForceDependencies='False'|PinPackage='False'|
|
|
Information.PlatformType='Windows'|
|
|
Information.PlatformVersion='10.0.17763.0'|
|
|
Information.PlatformName='Windows Server 2016'|
|
|
Information.ChocolateyVersion='1.3.0.0'|
|
|
Information.ChocolateyProductVersion='1.3.0'|
|
|
Information.FullName='choco, Version=1.3.0.0, Culture=neutral, PublicKeyToken=79d02ea9cad655eb'|
|
|
|
|
Information.Is64BitOperatingSystem='True'|
|
|
Information.Is64BitProcess='True'|Information.IsInteractive='False'|
|
|
Information.UserName='vagrant'|
|
|
Information.UserDomainName='WIN-09H5881UP2A'|
|
|
Information.IsUserAdministrator='True'|
|
|
Information.IsUserSystemAccount='False'|
|
|
Information.IsUserRemoteDesktop='False'|
|
|
Information.IsUserRemote='True'|
|
|
Information.IsProcessElevated='True'|
|
|
Information.IsLicensedVersion='False'|Information.LicenseType='Foss'|
|
|
Information.CurrentDirectory='C:\Users\vagrant'|
|
|
Features.AutoUninstaller='True'|Features.ChecksumFiles='True'|
|
|
Features.AllowEmptyChecksums='False'|
|
|
Features.AllowEmptyChecksumsSecure='True'|
|
|
Features.FailOnAutoUninstaller='False'|
|
|
Features.FailOnStandardError='False'|Features.UsePowerShellHost='True'|
|
|
Features.LogEnvironmentValues='True'|Features.LogWithoutColor='False'|
|
|
Features.VirusCheck='False'|
|
|
Features.FailOnInvalidOrMissingLicense='False'|
|
|
Features.IgnoreInvalidOptionsSwitches='True'|
|
|
Features.UsePackageExitCodes='True'|
|
|
Features.UseEnhancedExitCodes='False'|
|
|
Features.UseFipsCompliantChecksums='False'|
|
|
Features.ShowNonElevatedWarnings='True'|
|
|
Features.ShowDownloadProgress='False'|
|
|
Features.StopOnFirstPackageFailure='False'|
|
|
Features.UseRememberedArgumentsForUpgrades='False'|
|
|
Features.IgnoreUnfoundPackagesOnUpgradeOutdated='False'|
|
|
Features.SkipPackageUpgradesWhenNotInstalled='False'|
|
|
Features.RemovePackageInformationOnUninstall='False'|
|
|
Features.ExitOnRebootDetected='False'|
|
|
Features.LogValidationResultsOnWarnings='True'|
|
|
Features.UsePackageRepositoryOptimizations='True'|
|
|
ListCommand.LocalOnly='False'|ListCommand.IdOnly='False'|
|
|
ListCommand.IncludeRegistryPrograms='False'|ListCommand.PageSize='25'|
|
|
ListCommand.Exact='False'|ListCommand.ByIdOnly='False'|
|
|
ListCommand.ByTagOnly='False'|ListCommand.IdStartsWith='False'|
|
|
ListCommand.OrderByPopularity='False'|ListCommand.ApprovedOnly='False'|
|
|
ListCommand.DownloadCacheAvailable='False'|
|
|
ListCommand.NotBroken='False'|
|
|
ListCommand.IncludeVersionOverrides='False'|
|
|
UpgradeCommand.FailOnUnfound='False'|
|
|
UpgradeCommand.FailOnNotInstalled='False'|
|
|
UpgradeCommand.NotifyOnlyAvailableUpgrades='False'|
|
|
UpgradeCommand.ExcludePrerelease='False'|
|
|
NewCommand.AutomaticPackage='False'|
|
|
NewCommand.UseOriginalTemplate='False'|SourceCommand.Command='unknown'|
|
|
SourceCommand.Priority='0'|SourceCommand.BypassProxy='False'|
|
|
SourceCommand.AllowSelfService='False'|
|
|
SourceCommand.VisibleToAdminsOnly='False'|
|
|
FeatureCommand.Command='unknown'|ConfigCommand.Command='unknown'|
|
|
ApiKeyCommand.Remove='False'|PinCommand.Command='unknown'|
|
|
OutdatedCommand.IgnorePinned='False'|
|
|
ExportCommand.IncludeVersionNumbers='False'|Proxy.BypassOnLocal='True'|
|
|
TemplateCommand.Command='unknown'|
|
|
2023-05-12 04:58:54,156 792 [DEBUG] - _ Chocolatey:ChocolateyUninstallCommand - Normal Run Mode _
|
|
2023-05-12 04:58:54,187 792 [INFO ] - Uninstalling the following packages:
|
|
2023-05-12 04:58:54,187 792 [INFO ] - osquery
|
|
2023-05-12 04:58:54,203 792 [DEBUG] - Current environment values (may contain sensitive data):
|
|
2023-05-12 04:58:54,219 792 [DEBUG] - * 'Path'='C:\Users\vagrant\AppData\Local\Microsoft\WindowsApps;' ('User')
|
|
2023-05-12 04:58:54,235 792 [DEBUG] - * 'TEMP'='C:\Users\vagrant\AppData\Local\Temp' ('User')
|
|
2023-05-12 04:58:54,235 792 [DEBUG] - * 'TMP'='C:\Users\vagrant\AppData\Local\Temp' ('User')
|
|
2023-05-12 04:58:54,250 792 [DEBUG] - * 'ChocolateyLastPathUpdate'='133283411157827122' ('User')
|
|
2023-05-12 04:58:54,250 792 [DEBUG] - * 'ComSpec'='C:\Windows\system32\cmd.exe' ('Machine')
|
|
2023-05-12 04:58:54,266 792 [DEBUG] - * 'DriverData'='C:\Windows\System32\Drivers\DriverData' ('Machine')
|
|
2023-05-12 04:58:54,266 792 [DEBUG] - * 'OS'='Windows_NT' ('Machine')
|
|
2023-05-12 04:58:54,281 792 [DEBUG] - * 'Path'='C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\ProgramData\chocolatey\bin;C:\Program Files\osquery;' ('Machine')
|
|
2023-05-12 04:58:54,281 792 [DEBUG] - * 'PATHEXT'='.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC' ('Machine')
|
|
2023-05-12 04:58:54,297 792 [DEBUG] - * 'PROCESSOR_ARCHITECTURE'='AMD64' ('Machine')
|
|
2023-05-12 04:58:54,297 792 [DEBUG] - * 'PSModulePath'='C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules' ('Machine')
|
|
2023-05-12 04:58:54,312 792 [DEBUG] - * 'TEMP'='C:\Windows\TEMP' ('Machine')
|
|
2023-05-12 04:58:54,312 792 [DEBUG] - * 'TMP'='C:\Windows\TEMP' ('Machine')
|
|
2023-05-12 04:58:54,328 792 [DEBUG] - * 'USERNAME'='SYSTEM' ('Machine')
|
|
2023-05-12 04:58:54,328 792 [DEBUG] - * 'windir'='C:\Windows' ('Machine')
|
|
2023-05-12 04:58:54,344 792 [DEBUG] - * 'NUMBER_OF_PROCESSORS'='1' ('Machine')
|
|
2023-05-12 04:58:54,344 792 [DEBUG] - * 'PROCESSOR_LEVEL'='6' ('Machine')
|
|
2023-05-12 04:58:54,344 792 [DEBUG] - * 'PROCESSOR_IDENTIFIER'='Intel64 Family 6 Model 158 Stepping 13, GenuineIntel' ('Machine')
|
|
2023-05-12 04:58:54,360 792 [DEBUG] - * 'PROCESSOR_REVISION'='9e0d' ('Machine')
|
|
2023-05-12 04:58:54,360 792 [DEBUG] - * 'ChocolateyInstall'='C:\ProgramData\chocolatey' ('Machine')
|
|
2023-05-12 04:58:54,516 792 [DEBUG] - Running list with the following filter = ''
|
|
2023-05-12 04:58:54,516 792 [DEBUG] - --- Start of List ---
|
|
2023-05-12 04:58:54,906 792 [DEBUG] - osquery 5.8.2
|
|
2023-05-12 04:58:54,922 792 [DEBUG] - --- End of List ---
|
|
2023-05-12 04:58:55,064 792 [DEBUG] - Setting installer args for osquery
|
|
2023-05-12 04:58:55,079 792 [DEBUG] - Setting package parameters for osquery
|
|
2023-05-12 04:58:55,079 792 [DEBUG] - Contents of 'C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyBeforeModify.ps1':
|
|
2023-05-12 04:58:55,110 792 [DEBUG] - # Copyright (c) 2014-present, The osquery authors |
|
# |
|
# This source code is licensed as defined by the LICENSE file found in the |
|
# root directory of this source tree. |
|
# |
|
# SPDX-License-Identifier: (Apache-2.0 OR GPL-2.0-only) |
|
|
|
# This library file contains constant definitions and helper functions |
|
|
|
#Requires -Version 3.0 |
|
|
|
. (Join-Path "$PSScriptRoot" "osquery_utils.ps1") |
|
|
|
# Ensure the service is stopped and processes are not running if exists. |
|
if ((Get-Service $serviceName -ErrorAction SilentlyContinue) -and ` |
|
(Get-Service $serviceName).Status -eq 'Running') { |
|
Stop-Service $serviceName |
|
# If we find zombie processes, ensure they're termintated |
|
$proc = Get-Process | Where-Object { $_.ProcessName -eq 'osqueryd' } |
|
if ($null -ne $proc) { |
|
Stop-Process -Force $proc -ErrorAction SilentlyContinue |
|
} |
|
} |
|
|
|
# Lastly, ensure that the Deny Write ACLs have been removed before modifying |
|
if (Test-Path $daemonFolder) { |
|
Set-DenyWriteAcl $daemonFolder 'Remove' |
|
} |
|
if (Test-Path $extensionsFolder) { |
|
Set-DenyWriteAcl $extensionsFolder 'Remove' |
|
} |
|
|
|
2023-05-12 04:58:55,173 792 [DEBUG] - Calling built-in PowerShell host with ['[System.Threading.Thread]::CurrentThread.CurrentCulture = '';[System.Threading.Thread]::CurrentThread.CurrentUICulture = ''; & import-module -name 'C:\ProgramData\chocolatey\helpers\chocolateyInstaller.psm1'; & 'C:\ProgramData\chocolatey\helpers\chocolateyScriptRunner.ps1' -packageScript 'C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyBeforeModify.ps1' -installArguments '' -packageParameters '' -preRunHookScripts $null -postRunHookScripts $null']
|
|
2023-05-12 04:58:55,188 792 [DEBUG] - Redirecting System.Management.Automation.resources, Version=3.0.0.0, Culture=en-US, PublicKeyToken=31bf3856ad364e35, requested by ''
|
|
2023-05-12 04:58:55,954 792 [DEBUG] - Host version is 5.1.17763.1, PowerShell Version is '5.1.17763.3770' and CLR Version is '4.0.30319.42000'.
|
|
2023-05-12 04:58:56,531 792 [INFO ] - VERBOSE: Exporting function 'Format-FileSize'.
|
|
2023-05-12 04:58:56,547 792 [INFO ] - VERBOSE: Exporting function 'Get-ChecksumValid'.
|
|
2023-05-12 04:58:56,547 792 [INFO ] - VERBOSE: Exporting function 'Get-ChocolateyPath'.
|
|
2023-05-12 04:58:56,562 792 [INFO ] - VERBOSE: Exporting function 'Get-ChocolateyUnzip'.
|
|
2023-05-12 04:58:56,562 792 [INFO ] - VERBOSE: Exporting function 'Get-ChocolateyWebFile'.
|
|
2023-05-12 04:58:56,578 792 [INFO ] - VERBOSE: Exporting function 'Get-EnvironmentVariable'.
|
|
2023-05-12 04:58:56,578 792 [INFO ] - VERBOSE: Exporting function 'Get-EnvironmentVariableNames'.
|
|
2023-05-12 04:58:56,593 792 [INFO ] - VERBOSE: Exporting function 'Get-FtpFile'.
|
|
2023-05-12 04:58:56,593 792 [INFO ] - VERBOSE: Exporting function 'Get-OSArchitectureWidth'.
|
|
2023-05-12 04:58:56,609 792 [INFO ] - VERBOSE: Exporting function 'Get-PackageParameters'.
|
|
2023-05-12 04:58:56,609 792 [INFO ] - VERBOSE: Exporting function 'Get-PackageParametersBuiltIn'.
|
|
2023-05-12 04:58:56,625 792 [INFO ] - VERBOSE: Exporting function 'Get-ToolsLocation'.
|
|
2023-05-12 04:58:56,625 792 [INFO ] - VERBOSE: Exporting function 'Get-UACEnabled'.
|
|
2023-05-12 04:58:56,641 792 [INFO ] - VERBOSE: Exporting function 'Get-UninstallRegistryKey'.
|
|
2023-05-12 04:58:56,641 792 [INFO ] - VERBOSE: Exporting function 'Get-VirusCheckValid'.
|
|
2023-05-12 04:58:56,656 792 [INFO ] - VERBOSE: Exporting function 'Get-WebFile'.
|
|
2023-05-12 04:58:56,656 792 [INFO ] - VERBOSE: Exporting function 'Get-WebFileName'.
|
|
2023-05-12 04:58:56,656 792 [INFO ] - VERBOSE: Exporting function 'Get-WebHeaders'.
|
|
2023-05-12 04:58:56,672 792 [INFO ] - VERBOSE: Exporting function 'Install-BinFile'.
|
|
2023-05-12 04:58:56,687 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyEnvironmentVariable'.
|
|
2023-05-12 04:58:56,687 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyExplorerMenuItem'.
|
|
2023-05-12 04:58:56,703 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyFileAssociation'.
|
|
2023-05-12 04:58:56,719 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyInstallPackage'.
|
|
2023-05-12 04:58:56,719 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPackage'.
|
|
2023-05-12 04:58:56,734 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPath'.
|
|
2023-05-12 04:58:56,734 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPinnedTaskBarItem'.
|
|
2023-05-12 04:58:56,750 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPowershellCommand'.
|
|
2023-05-12 04:58:56,750 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyShortcut'.
|
|
2023-05-12 04:58:56,766 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyVsixPackage'.
|
|
2023-05-12 04:58:56,782 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyZipPackage'.
|
|
2023-05-12 04:58:56,782 792 [INFO ] - VERBOSE: Exporting function 'Install-Vsix'.
|
|
2023-05-12 04:58:56,797 792 [INFO ] - VERBOSE: Exporting function 'Set-EnvironmentVariable'.
|
|
2023-05-12 04:58:56,797 792 [INFO ] - VERBOSE: Exporting function 'Set-PowerShellExitCode'.
|
|
2023-05-12 04:58:56,813 792 [INFO ] - VERBOSE: Exporting function 'Start-ChocolateyProcessAsAdmin'.
|
|
2023-05-12 04:58:56,813 792 [INFO ] - VERBOSE: Exporting function 'Test-ProcessAdminRights'.
|
|
2023-05-12 04:58:56,828 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-BinFile'.
|
|
2023-05-12 04:58:56,828 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-ChocolateyEnvironmentVariable'.
|
|
2023-05-12 04:58:56,844 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-ChocolateyPackage'.
|
|
2023-05-12 04:58:56,844 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-ChocolateyZipPackage'.
|
|
2023-05-12 04:58:56,860 792 [INFO ] - VERBOSE: Exporting function 'Update-SessionEnvironment'.
|
|
2023-05-12 04:58:56,860 792 [INFO ] - VERBOSE: Exporting function 'Write-FunctionCallLogMessage'.
|
|
2023-05-12 04:58:56,891 792 [INFO ] - VERBOSE: Exporting alias 'Get-ProcessorBits'.
|
|
2023-05-12 04:58:56,891 792 [INFO ] - VERBOSE: Exporting alias 'Get-OSBitness'.
|
|
2023-05-12 04:58:56,908 792 [INFO ] - VERBOSE: Exporting alias 'Get-InstallRegistryKey'.
|
|
2023-05-12 04:58:56,908 792 [INFO ] - VERBOSE: Exporting alias 'Generate-BinFile'.
|
|
2023-05-12 04:58:56,922 792 [INFO ] - VERBOSE: Exporting alias 'Add-BinFile'.
|
|
2023-05-12 04:58:56,922 792 [INFO ] - VERBOSE: Exporting alias 'Start-ChocolateyProcess'.
|
|
2023-05-12 04:58:56,937 792 [INFO ] - VERBOSE: Exporting alias 'Invoke-ChocolateyProcess'.
|
|
2023-05-12 04:58:56,937 792 [INFO ] - VERBOSE: Exporting alias 'Remove-BinFile'.
|
|
2023-05-12 04:58:56,953 792 [INFO ] - VERBOSE: Exporting alias 'refreshenv'.
|
|
2023-05-12 04:58:56,985 792 [DEBUG] - Loading community extensions
|
|
2023-05-12 04:58:57,032 792 [DEBUG] - Importing 'C:\ProgramData\chocolatey\extensions\chocolatey-windowsupdate\chocolatey-windowsupdate.psm1'
|
|
2023-05-12 04:58:57,048 792 [INFO ] - VERBOSE: Loading module from path 'C:\ProgramData\chocolatey\extensions\chocolatey-windowsupdate\chocolatey-windowsupdate.psm1'.
|
|
2023-05-12 04:58:57,173 792 [INFO ] - VERBOSE: Exporting function 'Install-WindowsUpdate'.
|
|
2023-05-12 04:58:57,188 792 [INFO ] - VERBOSE: Exporting function 'Test-WindowsUpdate'.
|
|
2023-05-12 04:58:57,188 792 [INFO ] - VERBOSE: Importing function 'Install-WindowsUpdate'.
|
|
2023-05-12 04:58:57,204 792 [INFO ] - VERBOSE: Importing function 'Test-WindowsUpdate'.
|
|
2023-05-12 04:58:57,204 792 [INFO ] - VERBOSE: Exporting function 'Format-FileSize'.
|
|
2023-05-12 04:58:57,220 792 [INFO ] - VERBOSE: Exporting function 'Get-ChecksumValid'.
|
|
2023-05-12 04:58:57,234 792 [INFO ] - VERBOSE: Exporting function 'Get-ChocolateyPath'.
|
|
2023-05-12 04:58:57,234 792 [INFO ] - VERBOSE: Exporting function 'Get-ChocolateyUnzip'.
|
|
2023-05-12 04:58:57,250 792 [INFO ] - VERBOSE: Exporting function 'Get-ChocolateyWebFile'.
|
|
2023-05-12 04:58:57,250 792 [INFO ] - VERBOSE: Exporting function 'Get-EnvironmentVariable'.
|
|
2023-05-12 04:58:57,265 792 [INFO ] - VERBOSE: Exporting function 'Get-EnvironmentVariableNames'.
|
|
2023-05-12 04:58:57,265 792 [INFO ] - VERBOSE: Exporting function 'Get-FtpFile'.
|
|
2023-05-12 04:58:57,281 792 [INFO ] - VERBOSE: Exporting function 'Get-OSArchitectureWidth'.
|
|
2023-05-12 04:58:57,281 792 [INFO ] - VERBOSE: Exporting function 'Get-PackageParameters'.
|
|
2023-05-12 04:58:57,297 792 [INFO ] - VERBOSE: Exporting function 'Get-PackageParametersBuiltIn'.
|
|
2023-05-12 04:58:57,297 792 [INFO ] - VERBOSE: Exporting function 'Get-ToolsLocation'.
|
|
2023-05-12 04:58:57,313 792 [INFO ] - VERBOSE: Exporting function 'Get-UACEnabled'.
|
|
2023-05-12 04:58:57,313 792 [INFO ] - VERBOSE: Exporting function 'Get-UninstallRegistryKey'.
|
|
2023-05-12 04:58:57,328 792 [INFO ] - VERBOSE: Exporting function 'Get-VirusCheckValid'.
|
|
2023-05-12 04:58:57,328 792 [INFO ] - VERBOSE: Exporting function 'Get-WebFile'.
|
|
2023-05-12 04:58:57,343 792 [INFO ] - VERBOSE: Exporting function 'Get-WebFileName'.
|
|
2023-05-12 04:58:57,343 792 [INFO ] - VERBOSE: Exporting function 'Get-WebHeaders'.
|
|
2023-05-12 04:58:57,343 792 [INFO ] - VERBOSE: Exporting function 'Install-BinFile'.
|
|
2023-05-12 04:58:57,359 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyEnvironmentVariable'.
|
|
2023-05-12 04:58:57,375 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyExplorerMenuItem'.
|
|
2023-05-12 04:58:57,375 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyFileAssociation'.
|
|
2023-05-12 04:58:57,390 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyInstallPackage'.
|
|
2023-05-12 04:58:57,390 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPackage'.
|
|
2023-05-12 04:58:57,406 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPath'.
|
|
2023-05-12 04:58:57,406 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPinnedTaskBarItem'.
|
|
2023-05-12 04:58:57,421 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPowershellCommand'.
|
|
2023-05-12 04:58:57,421 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyShortcut'.
|
|
2023-05-12 04:58:57,437 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyVsixPackage'.
|
|
2023-05-12 04:58:57,437 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyZipPackage'.
|
|
2023-05-12 04:58:57,453 792 [INFO ] - VERBOSE: Exporting function 'Install-Vsix'.
|
|
2023-05-12 04:58:57,453 792 [INFO ] - VERBOSE: Exporting function 'Set-EnvironmentVariable'.
|
|
2023-05-12 04:58:57,469 792 [INFO ] - VERBOSE: Exporting function 'Set-PowerShellExitCode'.
|
|
2023-05-12 04:58:57,469 792 [INFO ] - VERBOSE: Exporting function 'Start-ChocolateyProcessAsAdmin'.
|
|
2023-05-12 04:58:57,484 792 [INFO ] - VERBOSE: Exporting function 'Test-ProcessAdminRights'.
|
|
2023-05-12 04:58:57,484 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-BinFile'.
|
|
2023-05-12 04:58:57,500 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-ChocolateyEnvironmentVariable'.
|
|
2023-05-12 04:58:57,500 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-ChocolateyPackage'.
|
|
2023-05-12 04:58:57,516 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-ChocolateyZipPackage'.
|
|
2023-05-12 04:58:57,516 792 [INFO ] - VERBOSE: Exporting function 'Update-SessionEnvironment'.
|
|
2023-05-12 04:58:57,546 792 [INFO ] - VERBOSE: Exporting function 'Write-FunctionCallLogMessage'.
|
|
2023-05-12 04:58:57,546 792 [INFO ] - VERBOSE: Exporting function 'Install-WindowsUpdate'.
|
|
2023-05-12 04:58:57,546 792 [INFO ] - VERBOSE: Exporting function 'Test-WindowsUpdate'.
|
|
2023-05-12 04:58:57,562 792 [INFO ] - VERBOSE: Exporting alias 'Get-ProcessorBits'.
|
|
2023-05-12 04:58:57,562 792 [INFO ] - VERBOSE: Exporting alias 'Get-OSBitness'.
|
|
2023-05-12 04:58:57,578 792 [INFO ] - VERBOSE: Exporting alias 'Get-InstallRegistryKey'.
|
|
2023-05-12 04:58:57,593 792 [INFO ] - VERBOSE: Exporting alias 'Generate-BinFile'.
|
|
2023-05-12 04:58:57,593 792 [INFO ] - VERBOSE: Exporting alias 'Add-BinFile'.
|
|
2023-05-12 04:58:57,609 792 [INFO ] - VERBOSE: Exporting alias 'Start-ChocolateyProcess'.
|
|
2023-05-12 04:58:57,609 792 [INFO ] - VERBOSE: Exporting alias 'Invoke-ChocolateyProcess'.
|
|
2023-05-12 04:58:57,626 792 [INFO ] - VERBOSE: Exporting alias 'Remove-BinFile'.
|
|
2023-05-12 04:58:57,626 792 [INFO ] - VERBOSE: Exporting alias 'refreshenv'.
|
|
2023-05-12 04:58:57,641 792 [INFO ] - VERBOSE: Importing function 'Format-FileSize'.
|
|
2023-05-12 04:58:57,656 792 [INFO ] - VERBOSE: Importing function 'Get-ChecksumValid'.
|
|
2023-05-12 04:58:57,656 792 [INFO ] - VERBOSE: Importing function 'Get-ChocolateyPath'.
|
|
2023-05-12 04:58:57,672 792 [INFO ] - VERBOSE: Importing function 'Get-ChocolateyUnzip'.
|
|
2023-05-12 04:58:57,672 792 [INFO ] - VERBOSE: Importing function 'Get-ChocolateyWebFile'.
|
|
2023-05-12 04:58:57,687 792 [INFO ] - VERBOSE: Importing function 'Get-EnvironmentVariable'.
|
|
2023-05-12 04:58:57,687 792 [INFO ] - VERBOSE: Importing function 'Get-EnvironmentVariableNames'.
|
|
2023-05-12 04:58:57,703 792 [INFO ] - VERBOSE: Importing function 'Get-FtpFile'.
|
|
2023-05-12 04:58:57,703 792 [INFO ] - VERBOSE: Importing function 'Get-OSArchitectureWidth'.
|
|
2023-05-12 04:58:57,829 792 [INFO ] - VERBOSE: Importing function 'Get-PackageParameters'.
|
|
2023-05-12 04:58:57,845 792 [INFO ] - VERBOSE: Importing function 'Get-PackageParametersBuiltIn'.
|
|
2023-05-12 04:58:57,845 792 [INFO ] - VERBOSE: Importing function 'Get-ToolsLocation'.
|
|
2023-05-12 04:58:57,859 792 [INFO ] - VERBOSE: Importing function 'Get-UACEnabled'.
|
|
2023-05-12 04:58:57,859 792 [INFO ] - VERBOSE: Importing function 'Get-UninstallRegistryKey'.
|
|
2023-05-12 04:58:57,875 792 [INFO ] - VERBOSE: Importing function 'Get-VirusCheckValid'.
|
|
2023-05-12 04:58:57,875 792 [INFO ] - VERBOSE: Importing function 'Get-WebFile'.
|
|
2023-05-12 04:58:57,891 792 [INFO ] - VERBOSE: Importing function 'Get-WebFileName'.
|
|
2023-05-12 04:58:57,891 792 [INFO ] - VERBOSE: Importing function 'Get-WebHeaders'.
|
|
2023-05-12 04:58:57,906 792 [INFO ] - VERBOSE: Importing function 'Install-BinFile'.
|
|
2023-05-12 04:58:57,906 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyEnvironmentVariable'.
|
|
2023-05-12 04:58:57,921 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyExplorerMenuItem'.
|
|
2023-05-12 04:58:57,921 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyFileAssociation'.
|
|
2023-05-12 04:58:57,937 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyInstallPackage'.
|
|
2023-05-12 04:58:57,937 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyPackage'.
|
|
2023-05-12 04:58:57,953 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyPath'.
|
|
2023-05-12 04:58:57,969 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyPinnedTaskBarItem'.
|
|
2023-05-12 04:58:57,969 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyPowershellCommand'.
|
|
2023-05-12 04:58:57,984 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyShortcut'.
|
|
2023-05-12 04:58:57,984 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyVsixPackage'.
|
|
2023-05-12 04:58:58,000 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyZipPackage'.
|
|
2023-05-12 04:58:58,000 792 [INFO ] - VERBOSE: Importing function 'Install-Vsix'.
|
|
2023-05-12 04:58:58,015 792 [INFO ] - VERBOSE: Importing function 'Install-WindowsUpdate'.
|
|
2023-05-12 04:58:58,015 792 [INFO ] - VERBOSE: Importing function 'Set-EnvironmentVariable'.
|
|
2023-05-12 04:58:58,031 792 [INFO ] - VERBOSE: Importing function 'Set-PowerShellExitCode'.
|
|
2023-05-12 04:58:58,031 792 [INFO ] - VERBOSE: Importing function 'Start-ChocolateyProcessAsAdmin'.
|
|
2023-05-12 04:58:58,047 792 [INFO ] - VERBOSE: Importing function 'Test-ProcessAdminRights'.
|
|
2023-05-12 04:58:58,047 792 [INFO ] - VERBOSE: Importing function 'Test-WindowsUpdate'.
|
|
2023-05-12 04:58:58,062 792 [INFO ] - VERBOSE: Importing function 'Uninstall-BinFile'.
|
|
2023-05-12 04:58:58,062 792 [INFO ] - VERBOSE: Importing function 'Uninstall-ChocolateyEnvironmentVariable'.
|
|
2023-05-12 04:58:58,078 792 [INFO ] - VERBOSE: Importing function 'Uninstall-ChocolateyPackage'.
|
|
2023-05-12 04:58:58,078 792 [INFO ] - VERBOSE: Importing function 'Uninstall-ChocolateyZipPackage'.
|
|
2023-05-12 04:58:58,094 792 [INFO ] - VERBOSE: Importing function 'Update-SessionEnvironment'.
|
|
2023-05-12 04:58:58,094 792 [INFO ] - VERBOSE: Importing function 'Write-FunctionCallLogMessage'.
|
|
2023-05-12 04:58:58,109 792 [INFO ] - VERBOSE: Importing alias 'Add-BinFile'.
|
|
2023-05-12 04:58:58,109 792 [INFO ] - VERBOSE: Importing alias 'Generate-BinFile'.
|
|
2023-05-12 04:58:58,125 792 [INFO ] - VERBOSE: Importing alias 'Get-InstallRegistryKey'.
|
|
2023-05-12 04:58:58,125 792 [INFO ] - VERBOSE: Importing alias 'Get-OSBitness'.
|
|
2023-05-12 04:58:58,140 792 [INFO ] - VERBOSE: Importing alias 'Get-ProcessorBits'.
|
|
2023-05-12 04:58:58,140 792 [INFO ] - VERBOSE: Importing alias 'Invoke-ChocolateyProcess'.
|
|
2023-05-12 04:58:58,156 792 [INFO ] - VERBOSE: Importing alias 'refreshenv'.
|
|
2023-05-12 04:58:58,156 792 [INFO ] - VERBOSE: Importing alias 'Remove-BinFile'.
|
|
2023-05-12 04:58:58,172 792 [INFO ] - VERBOSE: Importing alias 'Start-ChocolateyProcess'.
|
|
2023-05-12 04:58:58,267 792 [DEBUG] - ---------------------------Script Execution---------------------------
|
|
2023-05-12 04:58:58,282 792 [DEBUG] - Running 'ChocolateyScriptRunner' for osquery v5.8.2 with packageScript 'C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyBeforeModify.ps1', packageFolder:'C:\ProgramData\chocolatey\lib\osquery', installArguments: '', packageParameters: '', preRunHookScripts: '', postRunHookScripts: '',
|
|
2023-05-12 04:58:58,360 792 [DEBUG] - Running package script 'C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyBeforeModify.ps1'
|
|
2023-05-12 04:58:58,610 792 [INFO ] - True
|
|
2023-05-12 04:58:58,625 792 [INFO ] - True
|
|
2023-05-12 04:58:58,672 792 [DEBUG] - ----------------------------------------------------------------------
|
|
2023-05-12 04:58:58,687 792 [DEBUG] - Built-in PowerShell host called with ['[System.Threading.Thread]::CurrentThread.CurrentCulture = '';[System.Threading.Thread]::CurrentThread.CurrentUICulture = ''; & import-module -name 'C:\ProgramData\chocolatey\helpers\chocolateyInstaller.psm1'; & 'C:\ProgramData\chocolatey\helpers\chocolateyScriptRunner.ps1' -packageScript 'C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyBeforeModify.ps1' -installArguments '' -packageParameters '' -preRunHookScripts $null -postRunHookScripts $null'] exited with '0'.
|
|
2023-05-12 04:58:58,860 792 [DEBUG] - Attempting to create directory "C:\ProgramData\chocolatey\lib-bkp".
|
|
2023-05-12 04:58:58,876 792 [DEBUG] - Backing up existing osquery prior to operation.
|
|
2023-05-12 04:58:58,891 792 [DEBUG] - Moving 'C:\ProgramData\chocolatey\lib\osquery'
|
|
to 'C:\ProgramData\chocolatey\lib-bkp\osquery'
|
|
2023-05-12 04:59:00,906 792 [DEBUG] - Attempting to create directory "C:\ProgramData\chocolatey\lib\osquery".
|
|
2023-05-12 04:59:00,906 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\LICENSE.txt"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\LICENSE.txt".
|
|
2023-05-12 04:59:00,923 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\manage-osqueryd.ps1"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\manage-osqueryd.ps1".
|
|
2023-05-12 04:59:00,923 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\osquery.conf"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\osquery.conf".
|
|
2023-05-12 04:59:00,938 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\osquery.flags"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\osquery.flags".
|
|
2023-05-12 04:59:00,953 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\osquery.man"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\osquery.man".
|
|
2023-05-12 04:59:00,953 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\osquery.nupkg"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\osquery.nupkg".
|
|
2023-05-12 04:59:00,985 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\osquery.nuspec"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\osquery.nuspec".
|
|
2023-05-12 04:59:01,001 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\osquery.png"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\osquery.png".
|
|
2023-05-12 04:59:01,001 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\osqueryi.exe"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\osqueryi.exe".
|
|
2023-05-12 04:59:01,049 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\osquery_utils.ps1"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\osquery_utils.ps1".
|
|
2023-05-12 04:59:01,063 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\VERIFICATION.txt"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\VERIFICATION.txt".
|
|
2023-05-12 04:59:01,079 792 [DEBUG] - Attempting to create directory "C:\ProgramData\chocolatey\lib\osquery\certs".
|
|
2023-05-12 04:59:01,079 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\certs\certs.pem"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\certs\certs.pem".
|
|
2023-05-12 04:59:01,094 792 [DEBUG] - Attempting to create directory "C:\ProgramData\chocolatey\lib\osquery\osqueryd".
|
|
2023-05-12 04:59:01,094 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\osqueryd\osqueryd.exe"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\osqueryd\osqueryd.exe".
|
|
2023-05-12 04:59:01,157 792 [DEBUG] - Attempting to create directory "C:\ProgramData\chocolatey\lib\osquery\packs".
|
|
2023-05-12 04:59:01,157 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\packs\hardware-monitoring.conf"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\packs\hardware-monitoring.conf".
|
|
2023-05-12 04:59:01,172 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\packs\incident-response.conf"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\packs\incident-response.conf".
|
|
2023-05-12 04:59:01,172 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\packs\it-compliance.conf"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\packs\it-compliance.conf".
|
|
2023-05-12 04:59:01,188 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\packs\osquery-monitoring.conf"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\packs\osquery-monitoring.conf".
|
|
2023-05-12 04:59:01,203 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\packs\ossec-rootkit.conf"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\packs\ossec-rootkit.conf".
|
|
2023-05-12 04:59:01,203 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\packs\osx-attacks.conf"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\packs\osx-attacks.conf".
|
|
2023-05-12 04:59:01,219 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\packs\unwanted-chrome-extensions.conf"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\packs\unwanted-chrome-extensions.conf".
|
|
2023-05-12 04:59:01,219 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\packs\vuln-management.conf"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\packs\vuln-management.conf".
|
|
2023-05-12 04:59:01,234 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\packs\windows-attacks.conf"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\packs\windows-attacks.conf".
|
|
2023-05-12 04:59:01,234 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\packs\windows-hardening.conf"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\packs\windows-hardening.conf".
|
|
2023-05-12 04:59:01,250 792 [DEBUG] - Attempting to create directory "C:\ProgramData\chocolatey\lib\osquery\tools".
|
|
2023-05-12 04:59:01,250 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\tools\chocolateyBeforeModify.ps1"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyBeforeModify.ps1".
|
|
2023-05-12 04:59:01,265 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\tools\chocolateyinstall.ps1"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyinstall.ps1".
|
|
2023-05-12 04:59:01,281 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\tools\chocolateyuninstall.ps1"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyuninstall.ps1".
|
|
2023-05-12 04:59:01,281 792 [DEBUG] - Attempting to copy "C:\ProgramData\chocolatey\lib-bkp\osquery\tools\osquery_utils.ps1"
|
|
to "C:\ProgramData\chocolatey\lib\osquery\tools\osquery_utils.ps1".
|
|
2023-05-12 04:59:02,813 792 [DEBUG] - Capturing package files in 'C:\ProgramData\chocolatey\lib\osquery'
|
|
2023-05-12 04:59:02,828 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\LICENSE.txt'
|
|
with checksum '0820FFE048483183320E2DAD339898F6'
|
|
2023-05-12 04:59:02,844 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\manage-osqueryd.ps1'
|
|
with checksum '3CCB09B60C319C2B6A43DF64360BD14F'
|
|
2023-05-12 04:59:02,844 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\osquery.conf'
|
|
with checksum '9027F1A3AF205ED3D209BE5F9AEA1842'
|
|
2023-05-12 04:59:02,844 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\osquery.flags'
|
|
with checksum 'D41D8CD98F00B204E9800998ECF8427E'
|
|
2023-05-12 04:59:02,859 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\osquery.man'
|
|
with checksum 'A4C03558EDB1FF1F5DC4B2194CF3A500'
|
|
2023-05-12 04:59:02,953 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\osquery.nupkg'
|
|
with checksum '7373DFE603C2FF707E7A04C9C5ADFF3E'
|
|
2023-05-12 04:59:02,953 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\osquery.nuspec'
|
|
with checksum 'CD69CB7DCD2CDDF6DB56A8F9294F9BDB'
|
|
2023-05-12 04:59:02,969 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\osquery.png'
|
|
with checksum '34A5C156791B25AB5D130BD97AECA98C'
|
|
2023-05-12 04:59:03,141 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\osqueryi.exe'
|
|
with checksum '97D7D6BA1BCFA0D3490F8617BB03DFDF'
|
|
2023-05-12 04:59:03,141 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\osquery_utils.ps1'
|
|
with checksum 'E851BB94C0F783653E3BFF527503A850'
|
|
2023-05-12 04:59:03,156 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\VERIFICATION.txt'
|
|
with checksum '77039304249AC12CA156465857B19382'
|
|
2023-05-12 04:59:03,156 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\certs\certs.pem'
|
|
with checksum '6C8779E5755D9DDDF677BF7A52D035CE'
|
|
2023-05-12 04:59:03,297 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\osqueryd\osqueryd.exe'
|
|
with checksum 'E243D9BC769E5576BCB4DE91F0BD5D95'
|
|
2023-05-12 04:59:03,297 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\packs\hardware-monitoring.conf'
|
|
with checksum '3501087ED8C14DC4CB417D6F749ACAD4'
|
|
2023-05-12 04:59:03,313 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\packs\incident-response.conf'
|
|
with checksum '9FAF35B5ED735847D0162E4EAA5EF128'
|
|
2023-05-12 04:59:03,313 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\packs\it-compliance.conf'
|
|
with checksum 'C90DCD8897F172B41770C2A658D4426A'
|
|
2023-05-12 04:59:03,328 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\packs\osquery-monitoring.conf'
|
|
with checksum '50B79815090F908C57B6317DD2F552BF'
|
|
2023-05-12 04:59:03,328 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\packs\ossec-rootkit.conf'
|
|
with checksum '788318DBABB9FDBC545315C4CA88FC40'
|
|
2023-05-12 04:59:03,344 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\packs\osx-attacks.conf'
|
|
with checksum 'EE9CDBF8F06E672092B14DE993117569'
|
|
2023-05-12 04:59:03,359 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\packs\unwanted-chrome-extensions.conf'
|
|
with checksum 'CF972DFC934DD8E09A628C6B0A3814DD'
|
|
2023-05-12 04:59:03,359 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\packs\vuln-management.conf'
|
|
with checksum 'F1C82E2A9E05DE6AD9DFD47E16461FA8'
|
|
2023-05-12 04:59:03,375 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\packs\windows-attacks.conf'
|
|
with checksum '5C705090F10185E33F87AC8A79C445FB'
|
|
2023-05-12 04:59:03,375 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\packs\windows-hardening.conf'
|
|
with checksum 'EBFB94E06E2914770A4EAEA4E5F83248'
|
|
2023-05-12 04:59:03,390 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyBeforeModify.ps1'
|
|
with checksum '289840CCC12B230068E229CDD37E3703'
|
|
2023-05-12 04:59:03,390 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyinstall.ps1'
|
|
with checksum '780C83D965D277E7A132A4E7208FD339'
|
|
2023-05-12 04:59:03,406 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyuninstall.ps1'
|
|
with checksum '3C79361CA6117F7D02C1FEDDF82F07C6'
|
|
2023-05-12 04:59:03,406 792 [DEBUG] - Found 'C:\ProgramData\chocolatey\lib\osquery\tools\osquery_utils.ps1'
|
|
with checksum 'E851BB94C0F783653E3BFF527503A850'
|
|
2023-05-12 04:59:04,954 792 [INFO ] - [NuGet] Uninstalling 'osquery 5.8.2'.
|
|
2023-05-12 04:59:04,985 792 [INFO ] -
|
|
osquery v5.8.2
|
|
2023-05-12 04:59:05,172 792 [DEBUG] - Removing shim for osqueryi.exe at 'C:\ProgramData\chocolatey\bin\osqueryi.exe
|
|
2023-05-12 04:59:05,187 792 [DEBUG] - Attempting to delete file "C:\ProgramData\chocolatey\bin\osqueryi.exe".
|
|
2023-05-12 04:59:05,187 792 [DEBUG] - Removing shim for osqueryd.exe at 'C:\ProgramData\chocolatey\bin\osqueryd.exe
|
|
2023-05-12 04:59:05,203 792 [DEBUG] - Attempting to delete file "C:\ProgramData\chocolatey\bin\osqueryd.exe".
|
|
2023-05-12 04:59:05,219 792 [DEBUG] - Setting installer args for osquery
|
|
2023-05-12 04:59:05,219 792 [DEBUG] - Setting package parameters for osquery
|
|
2023-05-12 04:59:05,219 792 [DEBUG] - Contents of 'C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyuninstall.ps1':
|
|
2023-05-12 04:59:05,235 792 [DEBUG] - # Copyright (c) 2014-present, The osquery authors |
|
# |
|
# This source code is licensed as defined by the LICENSE file found in the |
|
# root directory of this source tree. |
|
# |
|
# SPDX-License-Identifier: (Apache-2.0 OR GPL-2.0-only) |
|
|
|
# This library file contains constant definitions and helper functions |
|
|
|
#Requires -Version 3.0 |
|
|
|
. (Join-Path "$PSScriptRoot" "osquery_utils.ps1") |
|
|
|
# Remove the osquery path from the System PATH variable. Note: Here |
|
# we don't make use of our local vars, as Regex requires escaping the '\' |
|
$oldPath = [System.Environment]::GetEnvironmentVariable('Path', 'Machine') |
|
if ($oldPath -imatch [regex]::escape($targetFolder)) { |
|
$newPath = $oldPath -replace [regex]::escape($targetFolder), $NULL |
|
[System.Environment]::SetEnvironmentVariable('Path', $newPath, 'Machine') |
|
} |
|
|
|
if ((Get-Service $serviceName -ErrorAction SilentlyContinue)) { |
|
Stop-Service $serviceName |
|
|
|
# If we find zombie processes, ensure they're termintated |
|
$proc = Get-Process | Where-Object { $_.ProcessName -eq 'osqueryd' } |
|
if ($null -ne $proc) { |
|
Stop-Process -Force $proc -ErrorAction SilentlyContinue |
|
} |
|
|
|
Set-Service $serviceName -startuptype 'manual' |
|
Get-CimInstance -ClassName Win32_Service -Filter "Name='osqueryd'" | Invoke-CimMethod -methodName Delete |
|
} |
|
|
|
if (Test-Path $targetFolder) { |
|
Remove-Item -Force -Recurse $targetFolder |
|
} else { |
|
Write-Debug 'osquery was not found on the system. Nothing to do.' |
|
} |
|
|
|
2023-05-12 04:59:05,250 792 [DEBUG] - Calling built-in PowerShell host with ['[System.Threading.Thread]::CurrentThread.CurrentCulture = '';[System.Threading.Thread]::CurrentThread.CurrentUICulture = ''; & import-module -name 'C:\ProgramData\chocolatey\helpers\chocolateyInstaller.psm1'; & 'C:\ProgramData\chocolatey\helpers\chocolateyScriptRunner.ps1' -packageScript 'C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyuninstall.ps1' -installArguments '' -packageParameters '' -preRunHookScripts $null -postRunHookScripts $null']
|
|
2023-05-12 04:59:05,312 792 [DEBUG] - Redirecting Microsoft.WSMan.Management.resources, Version=3.0.0.0, Culture=en-US, PublicKeyToken=31bf3856ad364e35, requested by ''
|
|
2023-05-12 04:59:05,422 792 [DEBUG] - Host version is 5.1.17763.1, PowerShell Version is '5.1.17763.3770' and CLR Version is '4.0.30319.42000'.
|
|
2023-05-12 04:59:05,594 792 [INFO ] - VERBOSE: Exporting function 'Format-FileSize'.
|
|
2023-05-12 04:59:05,594 792 [INFO ] - VERBOSE: Exporting function 'Get-ChecksumValid'.
|
|
2023-05-12 04:59:05,610 792 [INFO ] - VERBOSE: Exporting function 'Get-ChocolateyPath'.
|
|
2023-05-12 04:59:05,610 792 [INFO ] - VERBOSE: Exporting function 'Get-ChocolateyUnzip'.
|
|
2023-05-12 04:59:05,625 792 [INFO ] - VERBOSE: Exporting function 'Get-ChocolateyWebFile'.
|
|
2023-05-12 04:59:05,625 792 [INFO ] - VERBOSE: Exporting function 'Get-EnvironmentVariable'.
|
|
2023-05-12 04:59:05,641 792 [INFO ] - VERBOSE: Exporting function 'Get-EnvironmentVariableNames'.
|
|
2023-05-12 04:59:05,657 792 [INFO ] - VERBOSE: Exporting function 'Get-FtpFile'.
|
|
2023-05-12 04:59:05,657 792 [INFO ] - VERBOSE: Exporting function 'Get-OSArchitectureWidth'.
|
|
2023-05-12 04:59:05,672 792 [INFO ] - VERBOSE: Exporting function 'Get-PackageParameters'.
|
|
2023-05-12 04:59:05,672 792 [INFO ] - VERBOSE: Exporting function 'Get-PackageParametersBuiltIn'.
|
|
2023-05-12 04:59:05,687 792 [INFO ] - VERBOSE: Exporting function 'Get-ToolsLocation'.
|
|
2023-05-12 04:59:05,687 792 [INFO ] - VERBOSE: Exporting function 'Get-UACEnabled'.
|
|
2023-05-12 04:59:05,704 792 [INFO ] - VERBOSE: Exporting function 'Get-UninstallRegistryKey'.
|
|
2023-05-12 04:59:05,704 792 [INFO ] - VERBOSE: Exporting function 'Get-VirusCheckValid'.
|
|
2023-05-12 04:59:05,719 792 [INFO ] - VERBOSE: Exporting function 'Get-WebFile'.
|
|
2023-05-12 04:59:05,719 792 [INFO ] - VERBOSE: Exporting function 'Get-WebFileName'.
|
|
2023-05-12 04:59:05,719 792 [INFO ] - VERBOSE: Exporting function 'Get-WebHeaders'.
|
|
2023-05-12 04:59:05,734 792 [INFO ] - VERBOSE: Exporting function 'Install-BinFile'.
|
|
2023-05-12 04:59:05,734 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyEnvironmentVariable'.
|
|
2023-05-12 04:59:05,750 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyExplorerMenuItem'.
|
|
2023-05-12 04:59:05,750 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyFileAssociation'.
|
|
2023-05-12 04:59:05,766 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyInstallPackage'.
|
|
2023-05-12 04:59:05,782 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPackage'.
|
|
2023-05-12 04:59:05,782 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPath'.
|
|
2023-05-12 04:59:05,797 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPinnedTaskBarItem'.
|
|
2023-05-12 04:59:05,812 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPowershellCommand'.
|
|
2023-05-12 04:59:05,813 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyShortcut'.
|
|
2023-05-12 04:59:05,828 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyVsixPackage'.
|
|
2023-05-12 04:59:05,828 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyZipPackage'.
|
|
2023-05-12 04:59:05,844 792 [INFO ] - VERBOSE: Exporting function 'Install-Vsix'.
|
|
2023-05-12 04:59:05,844 792 [INFO ] - VERBOSE: Exporting function 'Set-EnvironmentVariable'.
|
|
2023-05-12 04:59:05,860 792 [INFO ] - VERBOSE: Exporting function 'Set-PowerShellExitCode'.
|
|
2023-05-12 04:59:05,860 792 [INFO ] - VERBOSE: Exporting function 'Start-ChocolateyProcessAsAdmin'.
|
|
2023-05-12 04:59:05,875 792 [INFO ] - VERBOSE: Exporting function 'Test-ProcessAdminRights'.
|
|
2023-05-12 04:59:05,890 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-BinFile'.
|
|
2023-05-12 04:59:05,890 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-ChocolateyEnvironmentVariable'.
|
|
2023-05-12 04:59:05,890 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-ChocolateyPackage'.
|
|
2023-05-12 04:59:05,906 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-ChocolateyZipPackage'.
|
|
2023-05-12 04:59:05,906 792 [INFO ] - VERBOSE: Exporting function 'Update-SessionEnvironment'.
|
|
2023-05-12 04:59:05,923 792 [INFO ] - VERBOSE: Exporting function 'Write-FunctionCallLogMessage'.
|
|
2023-05-12 04:59:05,923 792 [INFO ] - VERBOSE: Exporting alias 'Get-ProcessorBits'.
|
|
2023-05-12 04:59:05,938 792 [INFO ] - VERBOSE: Exporting alias 'Get-OSBitness'.
|
|
2023-05-12 04:59:05,953 792 [INFO ] - VERBOSE: Exporting alias 'Get-InstallRegistryKey'.
|
|
2023-05-12 04:59:05,953 792 [INFO ] - VERBOSE: Exporting alias 'Generate-BinFile'.
|
|
2023-05-12 04:59:05,969 792 [INFO ] - VERBOSE: Exporting alias 'Add-BinFile'.
|
|
2023-05-12 04:59:05,984 792 [INFO ] - VERBOSE: Exporting alias 'Start-ChocolateyProcess'.
|
|
2023-05-12 04:59:06,000 792 [INFO ] - VERBOSE: Exporting alias 'Invoke-ChocolateyProcess'.
|
|
2023-05-12 04:59:06,000 792 [INFO ] - VERBOSE: Exporting alias 'Remove-BinFile'.
|
|
2023-05-12 04:59:06,000 792 [INFO ] - VERBOSE: Exporting alias 'refreshenv'.
|
|
2023-05-12 04:59:06,016 792 [DEBUG] - Loading community extensions
|
|
2023-05-12 04:59:06,032 792 [DEBUG] - Importing 'C:\ProgramData\chocolatey\extensions\chocolatey-windowsupdate\chocolatey-windowsupdate.psm1'
|
|
2023-05-12 04:59:06,032 792 [INFO ] - VERBOSE: Loading module from path 'C:\ProgramData\chocolatey\extensions\chocolatey-windowsupdate\chocolatey-windowsupdate.psm1'.
|
|
2023-05-12 04:59:06,095 792 [INFO ] - VERBOSE: Exporting function 'Install-WindowsUpdate'.
|
|
2023-05-12 04:59:06,095 792 [INFO ] - VERBOSE: Exporting function 'Test-WindowsUpdate'.
|
|
2023-05-12 04:59:06,110 792 [INFO ] - VERBOSE: Importing function 'Install-WindowsUpdate'.
|
|
2023-05-12 04:59:06,110 792 [INFO ] - VERBOSE: Importing function 'Test-WindowsUpdate'.
|
|
2023-05-12 04:59:06,125 792 [INFO ] - VERBOSE: Exporting function 'Format-FileSize'.
|
|
2023-05-12 04:59:06,125 792 [INFO ] - VERBOSE: Exporting function 'Get-ChecksumValid'.
|
|
2023-05-12 04:59:06,141 792 [INFO ] - VERBOSE: Exporting function 'Get-ChocolateyPath'.
|
|
2023-05-12 04:59:06,141 792 [INFO ] - VERBOSE: Exporting function 'Get-ChocolateyUnzip'.
|
|
2023-05-12 04:59:06,156 792 [INFO ] - VERBOSE: Exporting function 'Get-ChocolateyWebFile'.
|
|
2023-05-12 04:59:06,156 792 [INFO ] - VERBOSE: Exporting function 'Get-EnvironmentVariable'.
|
|
2023-05-12 04:59:06,172 792 [INFO ] - VERBOSE: Exporting function 'Get-EnvironmentVariableNames'.
|
|
2023-05-12 04:59:06,172 792 [INFO ] - VERBOSE: Exporting function 'Get-FtpFile'.
|
|
2023-05-12 04:59:06,187 792 [INFO ] - VERBOSE: Exporting function 'Get-OSArchitectureWidth'.
|
|
2023-05-12 04:59:06,187 792 [INFO ] - VERBOSE: Exporting function 'Get-PackageParameters'.
|
|
2023-05-12 04:59:06,203 792 [INFO ] - VERBOSE: Exporting function 'Get-PackageParametersBuiltIn'.
|
|
2023-05-12 04:59:06,203 792 [INFO ] - VERBOSE: Exporting function 'Get-ToolsLocation'.
|
|
2023-05-12 04:59:06,219 792 [INFO ] - VERBOSE: Exporting function 'Get-UACEnabled'.
|
|
2023-05-12 04:59:06,219 792 [INFO ] - VERBOSE: Exporting function 'Get-UninstallRegistryKey'.
|
|
2023-05-12 04:59:06,234 792 [INFO ] - VERBOSE: Exporting function 'Get-VirusCheckValid'.
|
|
2023-05-12 04:59:06,234 792 [INFO ] - VERBOSE: Exporting function 'Get-WebFile'.
|
|
2023-05-12 04:59:06,250 792 [INFO ] - VERBOSE: Exporting function 'Get-WebFileName'.
|
|
2023-05-12 04:59:06,266 792 [INFO ] - VERBOSE: Exporting function 'Get-WebHeaders'.
|
|
2023-05-12 04:59:06,266 792 [INFO ] - VERBOSE: Exporting function 'Install-BinFile'.
|
|
2023-05-12 04:59:06,282 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyEnvironmentVariable'.
|
|
2023-05-12 04:59:06,282 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyExplorerMenuItem'.
|
|
2023-05-12 04:59:06,297 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyFileAssociation'.
|
|
2023-05-12 04:59:06,297 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyInstallPackage'.
|
|
2023-05-12 04:59:06,297 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPackage'.
|
|
2023-05-12 04:59:06,313 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPath'.
|
|
2023-05-12 04:59:06,313 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPinnedTaskBarItem'.
|
|
2023-05-12 04:59:06,328 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyPowershellCommand'.
|
|
2023-05-12 04:59:06,344 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyShortcut'.
|
|
2023-05-12 04:59:06,344 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyVsixPackage'.
|
|
2023-05-12 04:59:06,360 792 [INFO ] - VERBOSE: Exporting function 'Install-ChocolateyZipPackage'.
|
|
2023-05-12 04:59:06,375 792 [INFO ] - VERBOSE: Exporting function 'Install-Vsix'.
|
|
2023-05-12 04:59:06,375 792 [INFO ] - VERBOSE: Exporting function 'Set-EnvironmentVariable'.
|
|
2023-05-12 04:59:06,390 792 [INFO ] - VERBOSE: Exporting function 'Set-PowerShellExitCode'.
|
|
2023-05-12 04:59:06,390 792 [INFO ] - VERBOSE: Exporting function 'Start-ChocolateyProcessAsAdmin'.
|
|
2023-05-12 04:59:06,406 792 [INFO ] - VERBOSE: Exporting function 'Test-ProcessAdminRights'.
|
|
2023-05-12 04:59:06,406 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-BinFile'.
|
|
2023-05-12 04:59:06,422 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-ChocolateyEnvironmentVariable'.
|
|
2023-05-12 04:59:06,422 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-ChocolateyPackage'.
|
|
2023-05-12 04:59:06,437 792 [INFO ] - VERBOSE: Exporting function 'Uninstall-ChocolateyZipPackage'.
|
|
2023-05-12 04:59:06,437 792 [INFO ] - VERBOSE: Exporting function 'Update-SessionEnvironment'.
|
|
2023-05-12 04:59:06,453 792 [INFO ] - VERBOSE: Exporting function 'Write-FunctionCallLogMessage'.
|
|
2023-05-12 04:59:06,453 792 [INFO ] - VERBOSE: Exporting function 'Install-WindowsUpdate'.
|
|
2023-05-12 04:59:06,468 792 [INFO ] - VERBOSE: Exporting function 'Test-WindowsUpdate'.
|
|
2023-05-12 04:59:06,484 792 [INFO ] - VERBOSE: Exporting alias 'Get-ProcessorBits'.
|
|
2023-05-12 04:59:06,499 792 [INFO ] - VERBOSE: Exporting alias 'Get-OSBitness'.
|
|
2023-05-12 04:59:06,500 792 [INFO ] - VERBOSE: Exporting alias 'Get-InstallRegistryKey'.
|
|
2023-05-12 04:59:06,500 792 [INFO ] - VERBOSE: Exporting alias 'Generate-BinFile'.
|
|
2023-05-12 04:59:06,516 792 [INFO ] - VERBOSE: Exporting alias 'Add-BinFile'.
|
|
2023-05-12 04:59:06,516 792 [INFO ] - VERBOSE: Exporting alias 'Start-ChocolateyProcess'.
|
|
2023-05-12 04:59:06,532 792 [INFO ] - VERBOSE: Exporting alias 'Invoke-ChocolateyProcess'.
|
|
2023-05-12 04:59:06,532 792 [INFO ] - VERBOSE: Exporting alias 'Remove-BinFile'.
|
|
2023-05-12 04:59:06,547 792 [INFO ] - VERBOSE: Exporting alias 'refreshenv'.
|
|
2023-05-12 04:59:06,625 792 [INFO ] - VERBOSE: Importing function 'Format-FileSize'.
|
|
2023-05-12 04:59:06,766 792 [INFO ] - VERBOSE: Importing function 'Get-ChecksumValid'.
|
|
2023-05-12 04:59:06,766 792 [INFO ] - VERBOSE: Importing function 'Get-ChocolateyPath'.
|
|
2023-05-12 04:59:06,781 792 [INFO ] - VERBOSE: Importing function 'Get-ChocolateyUnzip'.
|
|
2023-05-12 04:59:06,797 792 [INFO ] - VERBOSE: Importing function 'Get-ChocolateyWebFile'.
|
|
2023-05-12 04:59:06,797 792 [INFO ] - VERBOSE: Importing function 'Get-EnvironmentVariable'.
|
|
2023-05-12 04:59:06,797 792 [INFO ] - VERBOSE: Importing function 'Get-EnvironmentVariableNames'.
|
|
2023-05-12 04:59:06,812 792 [INFO ] - VERBOSE: Importing function 'Get-FtpFile'.
|
|
2023-05-12 04:59:06,812 792 [INFO ] - VERBOSE: Importing function 'Get-OSArchitectureWidth'.
|
|
2023-05-12 04:59:06,828 792 [INFO ] - VERBOSE: Importing function 'Get-PackageParameters'.
|
|
2023-05-12 04:59:06,828 792 [INFO ] - VERBOSE: Importing function 'Get-PackageParametersBuiltIn'.
|
|
2023-05-12 04:59:06,844 792 [INFO ] - VERBOSE: Importing function 'Get-ToolsLocation'.
|
|
2023-05-12 04:59:06,844 792 [INFO ] - VERBOSE: Importing function 'Get-UACEnabled'.
|
|
2023-05-12 04:59:06,860 792 [INFO ] - VERBOSE: Importing function 'Get-UninstallRegistryKey'.
|
|
2023-05-12 04:59:06,860 792 [INFO ] - VERBOSE: Importing function 'Get-VirusCheckValid'.
|
|
2023-05-12 04:59:06,875 792 [INFO ] - VERBOSE: Importing function 'Get-WebFile'.
|
|
2023-05-12 04:59:06,891 792 [INFO ] - VERBOSE: Importing function 'Get-WebFileName'.
|
|
2023-05-12 04:59:06,891 792 [INFO ] - VERBOSE: Importing function 'Get-WebHeaders'.
|
|
2023-05-12 04:59:06,906 792 [INFO ] - VERBOSE: Importing function 'Install-BinFile'.
|
|
2023-05-12 04:59:06,906 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyEnvironmentVariable'.
|
|
2023-05-12 04:59:06,922 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyExplorerMenuItem'.
|
|
2023-05-12 04:59:06,922 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyFileAssociation'.
|
|
2023-05-12 04:59:06,938 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyInstallPackage'.
|
|
2023-05-12 04:59:06,938 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyPackage'.
|
|
2023-05-12 04:59:06,953 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyPath'.
|
|
2023-05-12 04:59:06,953 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyPinnedTaskBarItem'.
|
|
2023-05-12 04:59:06,969 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyPowershellCommand'.
|
|
2023-05-12 04:59:06,969 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyShortcut'.
|
|
2023-05-12 04:59:06,985 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyVsixPackage'.
|
|
2023-05-12 04:59:06,985 792 [INFO ] - VERBOSE: Importing function 'Install-ChocolateyZipPackage'.
|
|
2023-05-12 04:59:07,000 792 [INFO ] - VERBOSE: Importing function 'Install-Vsix'.
|
|
2023-05-12 04:59:07,015 792 [INFO ] - VERBOSE: Importing function 'Install-WindowsUpdate'.
|
|
2023-05-12 04:59:07,015 792 [INFO ] - VERBOSE: Importing function 'Set-EnvironmentVariable'.
|
|
2023-05-12 04:59:07,032 792 [INFO ] - VERBOSE: Importing function 'Set-PowerShellExitCode'.
|
|
2023-05-12 04:59:07,047 792 [INFO ] - VERBOSE: Importing function 'Start-ChocolateyProcessAsAdmin'.
|
|
2023-05-12 04:59:07,047 792 [INFO ] - VERBOSE: Importing function 'Test-ProcessAdminRights'.
|
|
2023-05-12 04:59:07,047 792 [INFO ] - VERBOSE: Importing function 'Test-WindowsUpdate'.
|
|
2023-05-12 04:59:07,063 792 [INFO ] - VERBOSE: Importing function 'Uninstall-BinFile'.
|
|
2023-05-12 04:59:07,063 792 [INFO ] - VERBOSE: Importing function 'Uninstall-ChocolateyEnvironmentVariable'.
|
|
2023-05-12 04:59:07,078 792 [INFO ] - VERBOSE: Importing function 'Uninstall-ChocolateyPackage'.
|
|
2023-05-12 04:59:07,078 792 [INFO ] - VERBOSE: Importing function 'Uninstall-ChocolateyZipPackage'.
|
|
2023-05-12 04:59:07,094 792 [INFO ] - VERBOSE: Importing function 'Update-SessionEnvironment'.
|
|
2023-05-12 04:59:07,110 792 [INFO ] - VERBOSE: Importing function 'Write-FunctionCallLogMessage'.
|
|
2023-05-12 04:59:07,110 792 [INFO ] - VERBOSE: Importing alias 'Add-BinFile'.
|
|
2023-05-12 04:59:07,125 792 [INFO ] - VERBOSE: Importing alias 'Generate-BinFile'.
|
|
2023-05-12 04:59:07,125 792 [INFO ] - VERBOSE: Importing alias 'Get-InstallRegistryKey'.
|
|
2023-05-12 04:59:07,141 792 [INFO ] - VERBOSE: Importing alias 'Get-OSBitness'.
|
|
2023-05-12 04:59:07,141 792 [INFO ] - VERBOSE: Importing alias 'Get-ProcessorBits'.
|
|
2023-05-12 04:59:07,156 792 [INFO ] - VERBOSE: Importing alias 'Invoke-ChocolateyProcess'.
|
|
2023-05-12 04:59:07,156 792 [INFO ] - VERBOSE: Importing alias 'refreshenv'.
|
|
2023-05-12 04:59:07,172 792 [INFO ] - VERBOSE: Importing alias 'Remove-BinFile'.
|
|
2023-05-12 04:59:07,172 792 [INFO ] - VERBOSE: Importing alias 'Start-ChocolateyProcess'.
|
|
2023-05-12 04:59:07,188 792 [DEBUG] - ---------------------------Script Execution---------------------------
|
|
2023-05-12 04:59:07,203 792 [DEBUG] - Running 'ChocolateyScriptRunner' for osquery v5.8.2 with packageScript 'C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyuninstall.ps1', packageFolder:'C:\ProgramData\chocolatey\lib\osquery', installArguments: '', packageParameters: '', preRunHookScripts: '', postRunHookScripts: '',
|
|
2023-05-12 04:59:07,203 792 [DEBUG] - Running package script 'C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyuninstall.ps1'
|
|
2023-05-12 04:59:07,313 792 [DEBUG] - ----------------------------------------------------------------------
|
|
2023-05-12 04:59:07,328 792 [DEBUG] - Built-in PowerShell host called with ['[System.Threading.Thread]::CurrentThread.CurrentCulture = '';[System.Threading.Thread]::CurrentThread.CurrentUICulture = ''; & import-module -name 'C:\ProgramData\chocolatey\helpers\chocolateyInstaller.psm1'; & 'C:\ProgramData\chocolatey\helpers\chocolateyScriptRunner.ps1' -packageScript 'C:\ProgramData\chocolatey\lib\osquery\tools\chocolateyuninstall.ps1' -installArguments '' -packageParameters '' -preRunHookScripts $null -postRunHookScripts $null'] exited with '0'.
|
|
2023-05-12 04:59:07,375 792 [INFO ] - Skipping auto uninstaller - No registry snapshot.
|
|
2023-05-12 04:59:07,391 792 [DEBUG] - Calling command ['"C:\Windows\System32\shutdown.exe" /a']
|
|
2023-05-12 04:59:07,531 792 [DEBUG] - Command ['"C:\Windows\System32\shutdown.exe" /a'] exited with '1116'
|
|
2023-05-12 04:59:07,547 792 [DEBUG] - Attempting to delete directory "C:\ProgramData\chocolatey\lib-bkp\osquery".
|
|
2023-05-12 04:59:07,688 792 [DEBUG] - [NuGet] Removed file 'osqueryd.exe' to folder 'C:\ProgramData\chocolatey\lib\osquery\osqueryd'.
|
|
2023-05-12 04:59:07,703 792 [DEBUG] - [NuGet] Removed folder 'C:\ProgramData\chocolatey\lib\osquery\osqueryd'.
|
|
2023-05-12 04:59:07,719 792 [DEBUG] - [NuGet] Removed file 'certs.pem' to folder 'C:\ProgramData\chocolatey\lib\osquery\certs'.
|
|
2023-05-12 04:59:07,734 792 [DEBUG] - [NuGet] Removed folder 'C:\ProgramData\chocolatey\lib\osquery\certs'.
|
|
2023-05-12 04:59:07,734 792 [DEBUG] - [NuGet] Removed file 'hardware-monitoring.conf' to folder 'C:\ProgramData\chocolatey\lib\osquery\packs'.
|
|
2023-05-12 04:59:07,750 792 [DEBUG] - [NuGet] Removed file 'incident-response.conf' to folder 'C:\ProgramData\chocolatey\lib\osquery\packs'.
|
|
2023-05-12 04:59:07,750 792 [DEBUG] - [NuGet] Removed file 'it-compliance.conf' to folder 'C:\ProgramData\chocolatey\lib\osquery\packs'.
|
|
2023-05-12 04:59:07,765 792 [DEBUG] - [NuGet] Removed file 'osquery-monitoring.conf' to folder 'C:\ProgramData\chocolatey\lib\osquery\packs'.
|
|
2023-05-12 04:59:07,782 792 [DEBUG] - [NuGet] Removed file 'ossec-rootkit.conf' to folder 'C:\ProgramData\chocolatey\lib\osquery\packs'.
|
|
2023-05-12 04:59:07,782 792 [DEBUG] - [NuGet] Removed file 'osx-attacks.conf' to folder 'C:\ProgramData\chocolatey\lib\osquery\packs'.
|
|
2023-05-12 04:59:07,797 792 [DEBUG] - [NuGet] Removed file 'unwanted-chrome-extensions.conf' to folder 'C:\ProgramData\chocolatey\lib\osquery\packs'.
|
|
2023-05-12 04:59:07,797 792 [DEBUG] - [NuGet] Removed file 'vuln-management.conf' to folder 'C:\ProgramData\chocolatey\lib\osquery\packs'.
|
|
2023-05-12 04:59:07,813 792 [DEBUG] - [NuGet] Removed file 'windows-attacks.conf' to folder 'C:\ProgramData\chocolatey\lib\osquery\packs'.
|
|
2023-05-12 04:59:07,813 792 [DEBUG] - [NuGet] Removed file 'windows-hardening.conf' to folder 'C:\ProgramData\chocolatey\lib\osquery\packs'.
|
|
2023-05-12 04:59:07,828 792 [DEBUG] - [NuGet] Removed folder 'C:\ProgramData\chocolatey\lib\osquery\packs'.
|
|
2023-05-12 04:59:07,843 792 [DEBUG] - [NuGet] Removed file 'chocolateyBeforeModify.ps1' to folder 'C:\ProgramData\chocolatey\lib\osquery\tools'.
|
|
2023-05-12 04:59:07,843 792 [DEBUG] - [NuGet] Removed file 'chocolateyinstall.ps1' to folder 'C:\ProgramData\chocolatey\lib\osquery\tools'.
|
|
2023-05-12 04:59:07,859 792 [DEBUG] - [NuGet] Removed file 'chocolateyuninstall.ps1' to folder 'C:\ProgramData\chocolatey\lib\osquery\tools'.
|
|
2023-05-12 04:59:07,859 792 [DEBUG] - [NuGet] Removed file 'osquery_utils.ps1' to folder 'C:\ProgramData\chocolatey\lib\osquery\tools'.
|
|
2023-05-12 04:59:07,876 792 [DEBUG] - [NuGet] Removed folder 'C:\ProgramData\chocolatey\lib\osquery\tools'.
|
|
2023-05-12 04:59:07,891 792 [DEBUG] - [NuGet] Removed file 'LICENSE.txt' to folder 'C:\ProgramData\chocolatey\lib\osquery'.
|
|
2023-05-12 04:59:07,891 792 [DEBUG] - [NuGet] Removed file 'manage-osqueryd.ps1' to folder 'C:\ProgramData\chocolatey\lib\osquery'.
|
|
2023-05-12 04:59:07,906 792 [DEBUG] - [NuGet] Removed file 'osquery.conf' to folder 'C:\ProgramData\chocolatey\lib\osquery'.
|
|
2023-05-12 04:59:07,922 792 [DEBUG] - [NuGet] Removed file 'osquery.flags' to folder 'C:\ProgramData\chocolatey\lib\osquery'.
|
|
2023-05-12 04:59:07,922 792 [DEBUG] - [NuGet] Removed file 'osquery.man' to folder 'C:\ProgramData\chocolatey\lib\osquery'.
|
|
2023-05-12 04:59:07,937 792 [DEBUG] - [NuGet] Removed file 'osquery.png' to folder 'C:\ProgramData\chocolatey\lib\osquery'.
|
|
2023-05-12 04:59:08,002 792 [DEBUG] - [NuGet] Removed file 'osqueryi.exe' to folder 'C:\ProgramData\chocolatey\lib\osquery'.
|
|
2023-05-12 04:59:08,016 792 [DEBUG] - [NuGet] Removed file 'osquery_utils.ps1' to folder 'C:\ProgramData\chocolatey\lib\osquery'.
|
|
2023-05-12 04:59:08,016 792 [DEBUG] - [NuGet] Removed file 'VERIFICATION.txt' to folder 'C:\ProgramData\chocolatey\lib\osquery'.
|
|
2023-05-12 04:59:08,031 792 [DEBUG] - [NuGet] Removed file 'osquery.nuspec' to folder 'C:\ProgramData\chocolatey\lib\osquery'.
|
|
2023-05-12 04:59:08,046 792 [DEBUG] - [NuGet] Removed file 'osquery.nupkg' to folder 'C:\ProgramData\chocolatey\lib\osquery'.
|
|
2023-05-12 04:59:08,046 792 [DEBUG] - [NuGet] Removed folder 'C:\ProgramData\chocolatey\lib\osquery'.
|
|
2023-05-12 04:59:08,062 792 [INFO ] - [NuGet] Successfully uninstalled 'osquery 5.8.2'.
|
|
2023-05-12 04:59:08,078 792 [INFO ] - osquery has been successfully uninstalled.
|
|
2023-05-12 04:59:08,282 792 [DEBUG] - Removing nupkg if it still exists.
|
|
2023-05-12 04:59:08,297 792 [DEBUG] - Ensuring removal of installation files.
|
|
2023-05-12 04:59:08,297 792 [DEBUG] - Ensuring removal of package cache files.
|
|
2023-05-12 04:59:08,329 792 [WARN ] - Environment Vars (like PATH) have changed. Close/reopen your shell to
|
|
see the changes (or in powershell/cmd.exe just type `refreshenv`).
|
|
2023-05-12 04:59:08,344 792 [DEBUG] - The following values have been added/changed (may contain sensitive data):
|
|
2023-05-12 04:59:08,344 792 [DEBUG] - * Path='C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\ProgramData\chocolatey\bin;;' (Machine)
|
|
2023-05-12 04:59:08,376 792 [WARN ] -
|
|
Chocolatey uninstalled 1/1 packages.
|
|
See the log for details (C:\ProgramData\chocolatey\logs\chocolatey.log).
|
|
2023-05-12 04:59:08,391 792 [DEBUG] - Sending message 'PostRunMessage' out if there are subscribers...
|
|
2023-05-12 04:59:08,439 792 [DEBUG] - Exiting with 0
|