' ================================================================
' KazTech Quick Malware Triage
' Windows 10 / Windows 11
'
' READ-ONLY diagnostic tool.
' Makes NO changes to Windows.
'
' Checks:
'   - Startup programs
'   - Running processes
'   - Automatic services
'   - Scheduled tasks
'   - Proxy / PAC configuration
'   - HOSTS file modifications
'
' Highlights potentially suspicious persistence or execution paths.
'
' Output:
'   KazTech_Quick_Triage.txt on the Desktop
' ================================================================

Option Explicit

Dim fso, shell, wmi, report
Dim desktopPath, reportPath
Dim findingCount

Set fso = CreateObject("Scripting.FileSystemObject")
Set shell = CreateObject("WScript.Shell")
Set wmi = GetObject("winmgmts:\\.\root\cimv2")

desktopPath = shell.SpecialFolders("Desktop")
reportPath = desktopPath & "\KazTech_Quick_Triage.txt"

findingCount = 0

Set report = fso.CreateTextFile(reportPath, True, True)

WriteLine "=============================================================="
WriteLine " KAZTECH QUICK MALWARE TRIAGE"
WriteLine "=============================================================="
WriteLine ""
WriteLine "Computer: " & shell.ExpandEnvironmentStrings("%COMPUTERNAME%")
WriteLine "User:     " & shell.ExpandEnvironmentStrings("%USERNAME%")
WriteLine "Date:     " & Now
WriteLine ""
WriteLine "This report is READ-ONLY."
WriteLine "No files, settings, services, processes or registry entries"
WriteLine "have been changed."
WriteLine ""
WriteLine "IMPORTANT:"
WriteLine "Flagged items are NOT automatically malware."
WriteLine "They are entries that deserve closer inspection."
WriteLine ""

CheckStartup
CheckProcesses
CheckServices
CheckScheduledTasks
CheckProxy
CheckHosts

WriteLine ""
WriteLine "=============================================================="
WriteLine " TRIAGE SUMMARY"
WriteLine "=============================================================="
WriteLine ""

If findingCount = 0 Then

    WriteLine "No obvious suspicious persistence indicators were detected."

Else

    WriteLine "Items requiring review: " & findingCount
    WriteLine ""
    WriteLine "Review flagged items before deleting or disabling anything."

End If

WriteLine ""
WriteLine "Suggested next steps:"
WriteLine "  - Verify unknown executables with VirusTotal or another scanner."
WriteLine "  - Check digital signatures and file properties."
WriteLine "  - Confirm questionable startup items with the customer."
WriteLine "  - Run Microsoft Defender / your preferred malware scanner."
WriteLine ""
WriteLine "KazTech Quick Malware Triage completed."

report.Close

MsgBox "Malware triage completed." & vbCrLf & vbCrLf & _
       findingCount & " item(s) require review." & vbCrLf & vbCrLf & _
       "Report saved to:" & vbCrLf & reportPath, _
       vbInformation, "KazTech Quick Malware Triage"

Set report = Nothing
Set wmi = Nothing
Set shell = Nothing
Set fso = Nothing

WScript.Quit


' ================================================================
' STARTUP PROGRAMS
' ================================================================

Sub CheckStartup()

    Dim items, item
    Dim commandLine, reason

    Section "STARTUP PROGRAMS"

    On Error Resume Next

    Set items = wmi.ExecQuery( _
        "SELECT Name, Command, Location, User FROM Win32_StartupCommand")

    For Each item In items

        commandLine = SafeValue(item.Command)
        reason = GetSuspicionReason(commandLine)

        If reason <> "" Then

            AddFinding _
                "Startup", _
                SafeValue(item.Name), _
                commandLine, _
                reason

            WriteLine "Location: " & SafeValue(item.Location)
            WriteLine "User:     " & SafeValue(item.User)
            Separator

        End If

    Next

    On Error GoTo 0

End Sub


' ================================================================
' RUNNING PROCESSES
' ================================================================

Sub CheckProcesses()

    Dim items, item
    Dim commandLine, processPath, combined, reason

    Section "RUNNING PROCESSES"

    On Error Resume Next

    Set items = wmi.ExecQuery( _
        "SELECT Name, ProcessId, ExecutablePath, CommandLine " & _
        "FROM Win32_Process")

    For Each item In items

        processPath = SafeValue(item.ExecutablePath)
        commandLine = SafeValue(item.CommandLine)

        combined = processPath & " " & commandLine

        reason = GetSuspicionReason(combined)

        If reason <> "" Then

            AddFinding _
                "Process", _
                SafeValue(item.Name) & _
                " (PID " & SafeValue(item.ProcessId) & ")", _
                processPath, _
                reason

            If commandLine <> "(none)" Then
                WriteLine "Command: " & commandLine
            End If

            Separator

        End If

    Next

    On Error GoTo 0

End Sub


' ================================================================
' AUTOMATIC SERVICES
' ================================================================

Sub CheckServices()

    Dim items, item
    Dim servicePath, reason

    Section "AUTOMATIC SERVICES"

    On Error Resume Next

    Set items = wmi.ExecQuery( _
        "SELECT Name, DisplayName, State, PathName, StartName " & _
        "FROM Win32_Service WHERE StartMode='Auto'")

    For Each item In items

        servicePath = SafeValue(item.PathName)
        reason = GetSuspicionReason(servicePath)

        If reason <> "" Then

            AddFinding _
                "Service", _
                SafeValue(item.DisplayName), _
                servicePath, _
                reason

            WriteLine "Service: " & SafeValue(item.Name)
            WriteLine "State:   " & SafeValue(item.State)
            WriteLine "Account: " & SafeValue(item.StartName)
            Separator

        End If

    Next

    On Error GoTo 0

End Sub


' ================================================================
' SCHEDULED TASKS
' ================================================================

Sub CheckScheduledTasks()

    Dim taskService, rootFolder

    Section "SCHEDULED TASKS"

    On Error Resume Next

    Set taskService = CreateObject("Schedule.Service")

    If Err.Number <> 0 Then

        WriteLine "Unable to access Task Scheduler."
        WriteLine ""
        Err.Clear
        Exit Sub

    End If

    taskService.Connect

    Set rootFolder = taskService.GetFolder("\")

    ScanTaskFolder rootFolder

    Set rootFolder = Nothing
    Set taskService = Nothing

    On Error GoTo 0

End Sub


Sub ScanTaskFolder(taskFolder)

    Dim tasks, task
    Dim folders, subFolder
    Dim definition, actions, action
    Dim commandLine, reason

    On Error Resume Next

    Set tasks = taskFolder.GetTasks(1)

    For Each task In tasks

        Set definition = task.Definition
        Set actions = definition.Actions

        For Each action In actions

            ' TASK_ACTION_EXEC = 0
            If action.Type = 0 Then

                commandLine = _
                    SafeValue(action.Path) & " " & _
                    SafeValue(action.Arguments)

                reason = GetSuspicionReason(commandLine)

                If reason <> "" Then

                    AddFinding _
                        "Scheduled Task", _
                        SafeValue(task.Path), _
                        commandLine, _
                        reason

                    Separator

                End If

            End If

        Next

    Next

    Set folders = taskFolder.GetFolders(0)

    For Each subFolder In folders
        ScanTaskFolder subFolder
    Next

    On Error GoTo 0

End Sub


' ================================================================
' PROXY SETTINGS
' ================================================================

Sub CheckProxy()

    Dim proxyEnabled
    Dim proxyServer
    Dim autoConfig

    Section "PROXY / INTERNET SETTINGS"

    On Error Resume Next

    proxyEnabled = shell.RegRead( _
        "HKCU\Software\Microsoft\Windows\CurrentVersion\" & _
        "Internet Settings\ProxyEnable")

    If Err.Number <> 0 Then
        proxyEnabled = 0
        Err.Clear
    End If

    proxyServer = shell.RegRead( _
        "HKCU\Software\Microsoft\Windows\CurrentVersion\" & _
        "Internet Settings\ProxyServer")

    If Err.Number <> 0 Then
        proxyServer = ""
        Err.Clear
    End If

    autoConfig = shell.RegRead( _
        "HKCU\Software\Microsoft\Windows\CurrentVersion\" & _
        "Internet Settings\AutoConfigURL")

    If Err.Number <> 0 Then
        autoConfig = ""
        Err.Clear
    End If

    If CStr(proxyEnabled) = "1" Then

        findingCount = findingCount + 1

        WriteLine "[REVIEW] Proxy is enabled"
        WriteLine "Proxy server: " & SafeValue(proxyServer)
        WriteLine ""
        WriteLine "Verify that the user or organization intentionally"
        WriteLine "configured this proxy."
        Separator

    End If

    If Trim(CStr(autoConfig)) <> "" Then

        findingCount = findingCount + 1

        WriteLine "[REVIEW] Automatic proxy configuration detected"
        WriteLine "PAC URL: " & autoConfig
        WriteLine ""
        WriteLine "Verify that this AutoConfigURL is legitimate."
        Separator

    End If

    If CStr(proxyEnabled) <> "1" And _
       Trim(CStr(autoConfig)) = "" Then

        WriteLine "No active user proxy configuration detected."
        WriteLine ""

    End If

    On Error GoTo 0

End Sub


' ================================================================
' HOSTS FILE
' ================================================================

Sub CheckHosts()

    Dim hostsPath
    Dim hostsFile
    Dim line
    Dim trimmed
    Dim hostsFinding

    Section "WINDOWS HOSTS FILE"

    hostsPath = shell.ExpandEnvironmentStrings( _
        "%WINDIR%\System32\drivers\etc\hosts")

    hostsFinding = False

    On Error Resume Next

    If Not fso.FileExists(hostsPath) Then

        WriteLine "HOSTS file not found."
        WriteLine ""
        Exit Sub

    End If

    Set hostsFile = fso.OpenTextFile(hostsPath, 1)

    Do Until hostsFile.AtEndOfStream

        line = hostsFile.ReadLine
        trimmed = Trim(line)

        If trimmed <> "" Then

            If Left(trimmed, 1) <> "#" Then

                ' Ignore standard localhost entries
                If InStr(LCase(trimmed), "localhost") = 0 And _
                   InStr(trimmed, "255.255.255.255") = 0 And _
                   InStr(trimmed, "127.0.0.1") = 1 = False And _
                   InStr(trimmed, "::1") = 1 = False Then

                    If hostsFinding = False Then

                        findingCount = findingCount + 1

                        WriteLine "[REVIEW] Non-default HOSTS entries detected:"
                        WriteLine ""

                        hostsFinding = True

                    End If

                    WriteLine trimmed

                End If

            End If

        End If

    Loop

    hostsFile.Close

    If hostsFinding Then

        WriteLine ""
        WriteLine "Verify that these redirects were intentionally configured."
        Separator

    Else

        WriteLine "No unusual HOSTS entries detected."
        WriteLine ""

    End If

    On Error GoTo 0

End Sub


' ================================================================
' HEURISTIC CHECKS
' ================================================================

Function GetSuspicionReason(commandLine)

    Dim text
    Dim reason

    text = LCase(CStr(commandLine))
    reason = ""

    ' ------------------------------------------------------------
    ' Temporary locations
    ' ------------------------------------------------------------

    If InStr(text, "\appdata\local\temp\") > 0 Or _
       InStr(text, "\windows\temp\") > 0 Or _
       InStr(text, "\temp\") > 0 Then

        reason = AddReason(reason, _
            "Runs from a temporary directory")

    End If


    ' ------------------------------------------------------------
    ' Downloads
    ' ------------------------------------------------------------

    If InStr(text, "\downloads\") > 0 Then

        reason = AddReason(reason, _
            "Runs directly from the Downloads folder")

    End If


    ' ------------------------------------------------------------
    ' Recycle Bin
    ' ------------------------------------------------------------

    If InStr(text, "$recycle.bin") > 0 Then

        reason = AddReason(reason, _
            "Runs from the Recycle Bin")

    End If


    ' ------------------------------------------------------------
    ' Public user folders
    ' ------------------------------------------------------------

    If InStr(text, "\users\public\") > 0 Then

        reason = AddReason(reason, _
            "Runs from a Public user-writable folder")

    End If


    ' ------------------------------------------------------------
    ' AppData execution
    '
    ' Many legitimate applications use AppData, so this is
    ' intentionally classified only as something to REVIEW.
    ' ------------------------------------------------------------

    If InStr(text, "\appdata\roaming\") > 0 Then

        reason = AddReason(reason, _
            "Executable or script located in AppData\Roaming")

    End If


    ' ------------------------------------------------------------
    ' Encoded / obfuscated PowerShell
    ' ------------------------------------------------------------

    If InStr(text, "powershell") > 0 Then

        If InStr(text, "-enc ") > 0 Or _
           InStr(text, "-encodedcommand") > 0 Or _
           InStr(text, "frombase64string") > 0 Or _
           InStr(text, "invoke-expression") > 0 Or _
           InStr(text, "iex(") > 0 Or _
           InStr(text, "downloadstring") > 0 Then

            reason = AddReason(reason, _
                "Potential encoded or obfuscated PowerShell command")

        End If

    End If


    ' ------------------------------------------------------------
    ' MSHTA
    ' ------------------------------------------------------------

    If InStr(text, "mshta.exe") > 0 Or _
       InStr(text, "\mshta ") > 0 Then

        reason = AddReason(reason, _
            "Uses MSHTA script execution")

    End If


    ' ------------------------------------------------------------
    ' Rundll32 JavaScript execution
    ' ------------------------------------------------------------

    If InStr(text, "rundll32") > 0 And _
       InStr(text, "javascript:") > 0 Then

        reason = AddReason(reason, _
            "Rundll32 launching JavaScript")

    End If


    ' ------------------------------------------------------------
    ' Script hosts running files from suspicious/user locations
    ' ------------------------------------------------------------

    If InStr(text, "wscript.exe") > 0 Or _
       InStr(text, "cscript.exe") > 0 Then

        If InStr(text, "\appdata\") > 0 Or _
           InStr(text, "\temp\") > 0 Or _
           InStr(text, "\downloads\") > 0 Or _
           InStr(text, "\users\public\") > 0 Then

            reason = AddReason(reason, _
                "Windows Script Host executing from a user-writable location")

        End If

    End If


    ' ------------------------------------------------------------
    ' Remote HTTP / HTTPS command references combined with
    ' script execution tools
    ' ------------------------------------------------------------

    If InStr(text, "http://") > 0 Or _
       InStr(text, "https://") > 0 Then

        If InStr(text, "powershell") > 0 Or _
           InStr(text, "mshta") > 0 Or _
           InStr(text, "wscript") > 0 Or _
           InStr(text, "cscript") > 0 Then

            reason = AddReason(reason, _
                "Script command references a remote URL")

        End If

    End If

    GetSuspicionReason = reason

End Function


Function AddReason(existingReason, newReason)

    If existingReason = "" Then
        AddReason = newReason
    Else
        AddReason = existingReason & "; " & newReason
    End If

End Function


' ================================================================
' REPORT HELPERS
' ================================================================

Sub AddFinding(category, name, commandLine, reason)

    findingCount = findingCount + 1

    WriteLine "[REVIEW] " & category
    WriteLine "Name:    " & name
    WriteLine "Command: " & commandLine
    WriteLine "Reason:  " & reason

End Sub


Sub Section(title)

    WriteLine ""
    WriteLine "=============================================================="
    WriteLine " " & title
    WriteLine "=============================================================="
    WriteLine ""

End Sub


Sub Separator()

    WriteLine "--------------------------------------------------------------"
    WriteLine ""

End Sub


Sub WriteLine(text)

    report.WriteLine text

End Sub


Function SafeValue(value)

    If IsNull(value) Or IsEmpty(value) Then
        SafeValue = "(none)"
    ElseIf Trim(CStr(value)) = "" Then
        SafeValue = "(none)"
    Else
        SafeValue = CStr(value)
    End If

End Function