pf100

v2.7.1-LockFiles.cmd

May 23rd, 2020
231
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.41 KB | None | 0 0
  1. # sledgehammer\bin\LockFiles.cmd
  2. ::Allow only LockFiles task to run this file::
  3. rem whoami /user /nh | find /i "S-1-5-18" || exit
  4. cd /d "%~dp0"
  5. ::::::::::::::::::::::::::::
  6. icacls C:\Windows\System32\SIHClient.exe >nul 2>&1
  7. if %errorlevel% neq 0 goto okay
  8. :: Update hijacker file permissions are not locked so remove permissions or rename them.
  9. ::::::::::::::::::::::::::::
  10. ::Set list (s32list) of update hijacker files to be disabled, then disable everything in the list.
  11. set s32list=EOSNotify.exe WaaSMedic.exe WaasMedicSvc.dll WaaSMedicPS.dll WaaSAssessment.dll UsoClient.exe
  12. set s32list=%s32list% SIHClient.exe MusNotificationUx.exe MusNotification.exe osrss.dll
  13. set s32=%systemroot%\System32
  14. ::If "s32list" files were previously renamed by script, restore original file names
  15. for %%# in (%s32list%) do (
  16. ren "%s32%\%%#"-backup "%%#"
  17. if exist "%s32%\%%#" del "%s32%\%%#"-backup /f /q
  18. )
  19. ::Lock files
  20. for %%# in (%s32list%) do (
  21. takeown /f "%s32%\%%#" /a
  22. icacls "%s32%\%%#" /reset
  23. if exist "%s32%\%%#" "%systemroot%\System32\icacls.exe" "%s32%\%%#" /inheritance:r /remove *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18
  24. )
  25. ::If files in "s32list" aren't locked for whatever reason, rename them.
  26. for %%# in (%s32list%) do (
  27. ren "%s32%\%%#" "%%#"-backup
  28. if exist "%s32%\%%#"-backup del "%s32%\%%#" /f /q
  29. )
  30. ::::::::::::::::::::::::::::
  31. :okay
  32. :: Update hijacker file permissions are locked. No action needed.
  33. exit
Advertisement
Add Comment
Please, Sign In to add comment