# Run as SYSTEM in 64-bit PowerShell. A stopped service is deliberately preserved. $ErrorActionPreference = 'Stop' $Portal = 'https://vpn.the-walkers-tech.com' try { if ([System.Security.Principal.WindowsIdentity]::GetCurrent().User.Value -ne 'S-1-5-18') { throw 'Run as SYSTEM.' } $service = Get-Service TwtVpnGuardian -ErrorAction SilentlyContinue if ($service -and $service.Status -ne 'Running') { Write-Output 'Preserved: service is stopped; no start or enable requested.'; exit 0 } $exe = Join-Path $env:ProgramFiles 'TWT VPN\TWT.Vpn.exe' if ($service -and (Test-Path $exe) -and (Get-AuthenticodeSignature $exe).Status -eq 'Valid') { Write-Output 'Guardian present and running. Its saved connection policy is unchanged.'; exit 0 } $manifest = Invoke-RestMethod "$Portal/download/manifest" $cache = Join-Path $env:ProgramData 'TWT\RmmRepair'; New-Item -ItemType Directory -Path $cache -Force | Out-Null $msi = Join-Path $cache 'TWT-VPN.msi' Invoke-WebRequest "$Portal/download/TWT-VPN.msi" -OutFile $msi -UseBasicParsing $signature = Get-AuthenticodeSignature $msi if ((Get-FileHash $msi -Algorithm SHA256).Hash -ne $manifest.sha256 -or $signature.Status -ne 'Valid' -or $signature.SignerCertificate.Thumbprint -ne $manifest.publisherThumbprint) { throw 'MSI hash or publisher verification failed.' } $args = "/i `"$msi`" /qn /norestart" if (Test-Path 'HKLM:\Software\TWT\VPN') { $args += ' REINSTALL=ALL REINSTALLMODE=vomus' } $install = Start-Process msiexec.exe -ArgumentList $args -Wait -PassThru -WindowStyle Hidden if ($install.ExitCode -notin 0,3010) { throw "MSI returned $($install.ExitCode)" } Write-Output 'Installed/repaired. Saved pause and enrollment state were retained where present.' } catch { Write-Output ('FAILED: ' + $_.Exception.Message); exit 1 }