pf100

v2.6.1rc5-Sledgehammer.cmd

Mar 7th, 2020
502
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 32.06 KB | None | 0 0
  1. @echo off
  2. mode con cols=89 lines=34
  3. Title Sledgehammer 2.6.1 rc5
  4. Color 1F & goto start
  5. Original script by pf100 @ MDL with special thanks to rpo and abbodi1406 @ MDL for code improvements.
  6. Thanks to RetiredGeek at askwoody.com forum for original ideas on how to get MS-DEFCON rating.
  7. Project page and source code:
  8. https://forums.mydigitallife.net/threads/sledgehammer-windows-10-update-control.72203/
  9. ******************************************************************
  10. You may freely modify this script as you wish, I only request that you leave the credits and the
  11. link to the original script.
  12. ******************************************************************
  13. Don't move this script to another folder without running it again or the tasks won't work!
  14. This script provides manual updating for Windows 10 including Home versions.
  15. Update Windows 10 on your schedule, not Microsoft's!
  16. I originally wrote this script for personal use because of the lack of update options with the
  17. original RTM release of Windows 10 Pro. I wanted to update Windows 10 when I had the free time
  18. to manually update, just like I did with previous versions of Windows that allowed me to
  19. set updates to manual, not when Microsoft forced it on me while I was busy using my computer.
  20. *******************************************************************
  21. WUMT is available here: https://forums.mydigitallife.net/threads/64939-Windows-Update-MiniTool
  22. Windows Update Blocker is available here: http://sordum.org/files/windows-update-blocker/old/Wub_v1.0.zip
  23. Only use Windows Update Blocker v1.0 with this script, NOT v1.1!
  24. NSudo is available here: https://github.com/M2Team/NSudo/releases/tag/6.1
  25. *******************************************************************
  26. How it works: The script first checks if the OS is Windows 8.1 or older and if so
  27. it notifies the user, then exits. Windows 10 only!
  28. This script creates a smart Windows Defender Update task "WDU" that updates Windows
  29. Defender every 6 hours if it's running and enabled, and doesn't update it if it's not
  30. running and disabled, saving resources; auto-elevates, uninstalls and removes the
  31. Windows 10 Update Assistant, disables everything in the %programfiles%\rempl folder, resets and
  32. removes permissions from and disables these Update Hijackers:
  33. EOSNotify.exe
  34. WaaSMedic.exe
  35. WaasMedicSvc.dll
  36. WaaSMedicPS.dll
  37. WaaSAssessment.dll
  38. UsoClient.exe
  39. SIHClient.exe
  40. MusNotificationUx.exe
  41. MusNotification.exe
  42. osrss.dll
  43. %ProgramFiles%\rempl
  44. %systemroot%\UpdateAssistant
  45. %systemroot%\UpdateAssistantV2
  46. %systemdrive%\Windows10Upgrade
  47. disables all WindowsUpdate tasks
  48. makes sure the task "wub_task" is installed that runs wub at boot (to stop updates from turning
  49. updates back on), runs wub.exe and enables and starts the windows update service (wuauserv) if
  50. disabled, installs "WDU" Windows Defender Update task that runs every 2 hours (but doesn't update
  51. Defender if Defender is disabled), then runs the correct version of the Windows Update MiniTool in
  52. "auto search for updates" mode for your OS version's architecture (x86 or x64), then disables and
  53. stops wuauserv giving you full control. No more forced automatic updates or surprise reboots.
  54. This was written for Windows 10 Pro and Home, but works with all versions of Windows 10. Don't
  55. change any settings in lower left of WUMT while running the script.
  56. *******************************************************************
  57. I also included an uninstaller.cmd that deletes the "WDU" and "wub_task" tasks, deletes the WDU.cmd
  58. file used by WDU task, restores the rempl folder, resets Update Hijacker permissions to how they
  59. were originally, renables "WindowsUpdate" tasks, and turns off wub (if enabled) which turns the windows update service on automatic
  60. again, undoing everything done by the script. If you uninstall after having used the installer the
  61. script files are removed also.
  62. *******************************************************************
  63. Configurator leaves the Update Hijackers disabled, but gives you the option of turning on the windows
  64. update service temporarily to use the Store or any other operation that requires the windows update
  65. service, such as some DISM operations, installing dotNet 3.5, App Updates, etc.
  66. *******************************************************************
  67. :start
  68. ::::::::::::::::::::::::::::
  69. cd /d "%~dp0"
  70. :::::::::::::::::::::::::::::::::::::::::
  71. :: Automatically check & get admin rights
  72. :::::::::::::::::::::::::::::::::::::::::
  73. :: ECHO.
  74. :: ECHO =============================
  75. :: ECHO Running Admin shell
  76. :: ECHO =============================
  77. :: Check Privileges
  78. :: Get Privileges
  79. :: and
  80. :: Invoke UAC for Privilege Escalation
  81. :: Notify if error escalating
  82. :: and prevent looping if escalation fails
  83. ::::::::::::::::::::::::::::
  84. set "params=Problem_with_elevating_UAC_for_Administrator_Privileges"&if exist "%temp%\getadmin.vbs" del "%temp%\getadmin.vbs"
  85. fsutil dirty query %systemdrive% >nul 2>&1 && goto :GotPrivileges
  86. :: The following test is to avoid infinite looping if elevating UAC for Administrator Privileges failed
  87. If "%1"=="%params%" (echo Elevating UAC for Administrator Privileges failed&echo Right click on the script and select 'Run as administrator'&echo Press any key to exit...&pause>nul 2>&1&exit)
  88. cmd /u /c echo Set UAC = CreateObject^("Shell.Application"^) : UAC.ShellExecute "%~0", "%params%", "", "runas", 1 > "%temp%\getadmin.vbs"&cscript //nologo "%temp%\getadmin.vbs" && exit /b || (echo Elevating UAC for Administrator Privileges failed&echo Right click on the script and select 'Run as administrator'&echo Press any key to exit...&pause>nul 2>&1&exit)
  89. :GotPrivileges
  90. ::::::::::::::::::::::::::::
  91. ::Uninstall and remove Windows 10 Update assistant.
  92. ::Disable Windows Update Service until script menu screen.
  93. ::Reset (in case of wrong Permissions), remove Permissions from and
  94. ::disable "Update Hijackers"
  95. ::Install wub_task (prevents Windows Update service from starting after installing updates and rebooting).
  96. ::Install "WDU" task that only updates Defender if it's enabled. Otherwise it doesn't do anything.
  97. ::Enable and start the Windows Update Service (wuauserv).
  98. ::Run the correct version of WUMT for your architecture.
  99. ::Start WUMT in "auto-check for updates" mode.
  100. ::After updates are completed and WUMT is closed and/or the "reboot"
  101. ::button in WUMT is pressed, silently run wub.exe and disable and stop wuauserv
  102. ::::::::::::::::::::::::::::
  103. ::Test for Windows versions below Windows 10 and if so inform user, then exit...
  104. ::Get Windows OS build number
  105. for /f "tokens=2 delims==" %%a in ('wmic path Win32_OperatingSystem get BuildNumber /value') do (
  106. set /a WinBuild=%%a
  107. )
  108. if %winbuild% LEQ 9600 (
  109. echo.&echo This is not Windows 10. Press a key to exit...
  110. pause > nul
  111. exit
  112. )
  113. ::::::::::::::::::::::::::::
  114. ::Determine if running 32 or 64 bit Windows OS and set variables accordingly.
  115. wmic cpu get AddressWidth /value|find "32">nul&&set PROCESSOR_ARCHITECTURE=X86||set PROCESSOR_ARCHITECTURE=AMD64
  116. if %PROCESSOR_ARCHITECTURE%==AMD64 (
  117. set "nsudovar=.\bin\NSudoCx64.exe"
  118. set "wumt=.\bin\wumt_x64.exe"
  119. ) else (
  120. set "nsudovar=.\bin\NSudoc.exe"
  121. set "wumt=.\bin\wumt_x86.exe"
  122. )
  123. ::::::::::::::::::::::::::::
  124. ::Remove and/or lock Update Assistant
  125. if exist "%systemdrive%\Windows10Upgrade\Windows10UpgraderApp.exe" ( echo Windows 10 Update Assistant detected. Preparing to uninstall.
  126. echo The "Windows 10 Update Assistant has stopped working" dialog box may pop up.
  127. echo If so, just close it.
  128. echo.& echo Press a key to acknowledge this and please wait for the uninstall to finish.
  129. echo Script will continue after uninstall and removal is completed...
  130. pause > nul
  131. echo Uninstalling Windows 10 Update Assistant...
  132. %systemdrive%\Windows10Upgrade\Windows10UpgraderApp.exe /forceuninstall
  133. timeout /t 10 /nobreak
  134. cls)
  135. ::::::::::::::::::::::::::::
  136. :: Get MS-Defcon from askwoody.com
  137. powershell -Nologo -NoProfile -ExecutionPolicy Bypass "$progressPreference='silentlyContinue';Write-Output 'Sledgehammer is attempting to retrieve MS-DEFCON rating from askwoody.com...';Try{$WebResponse=Invoke-WebRequest 'https://www.askwoody.com/' -UseBasicParsing -TimeoutSec 10}Catch{$WebResponse=''};if ($WebResponse.Statuscode -ne 200){Clear-Host;\"`r`nUnable to retrieve MS-DEFCON rating from askwoody.com\"; exit};ForEach ($Image in $WebResponse.Images){$x=$Image.OuterHTML.ToString();If($x -like '*MS-DEFCON-*'){Clear-Host;\"`r`n MS-DEFCON = \"+$x.split('/')[8].split('.')[0].SubString(10,1);break}}
  138. echo. & echo :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  139. echo.&echo MS-DEFCON 1: Current Microsoft patches are causing havoc. Don't patch.
  140. echo.&echo MS-DEFCON 2: Patch reliability is unclear. Unless you have an immediate, pressing need
  141. echo to install a specific patch, don't do it.
  142. echo.&echo MS-DEFCON 3: Patch reliability is unclear, but widespread attacks make patching prudent.
  143. echo Go ahead and patch, but watch out for potential problems.
  144. echo.&echo MS-DEFCON 4: There are isolated problems with current patches, but they are well-known
  145. echo and documented here. Check this site to see if you're affected and if
  146. echo things look OK, go ahead and patch.
  147. echo.&echo MS-DEFCON 5: All's clear. Patch while it's safe.
  148. echo. & echo :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  149. echo.&echo More info at https://www.askwoody.com
  150. echo. & echo :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  151. ::::::::::::::::::::::::::::
  152. rem echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  153. echo. & echo Disabling update hijackers...
  154. echo Creating tasks...
  155. echo Disabling windows Update Service...
  156. echo. & echo :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  157. ::::::::::::::::::::::::::::
  158. ::Disable update service.
  159. call :wuauserv d
  160. ::::::::::::::::::::::::::::
  161. schtasks /delete /tn WDU >nul /f 2>&1
  162. schtasks /delete /tn Wub_task /f >nul 2>&1
  163. schtasks /Delete /Tn \Microsoft\WuWrapperScript\WDU /f >nul 2>&1
  164. schtasks /Delete /Tn \Microsoft\WuWrapperScript\Wub_task /f >nul 2>&1
  165. rmdir %SystemDrive%\Windows\System32\Tasks\Microsoft\WuWrapperScript /s /q >nul 2>&1
  166. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\WuWrapperScript" /f >nul 2>&1
  167. schtasks /Delete /Tn \Microsoft\Sledgehammer\WDU /f >nul 2>&1
  168. schtasks /Delete /Tn \Microsoft\Sledgehammer\Wub_task /f >nul 2>&1
  169. rmdir %SystemDrive%\Windows\System32\Tasks\Microsoft\Sledgehammer /s /q >nul 2>&1
  170. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Sledgehammer" /f >nul 2>&1
  171. ::::::::::::::::::::::::::::::::::
  172. takeown /f "%systemroot%\UpdateAssistant" /a >nul 2>&1
  173. icacls "%systemroot%\UpdateAssistant" /reset >nul 2>&1
  174. del %systemroot%\UpdateAssistant\*.* /f /q >nul 2>&1
  175. rmdir %systemroot%\UpdateAssistant /s /q >nul 2>&1
  176. md "%systemroot%\UpdateAssistant" >nul 2>&1
  177. attrib +s +h "%systemroot%\UpdateAssistant" >nul 2>&1
  178. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" %systemroot%\UpdateAssistant /inheritance:r /remove:g *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  179. takeown /f "%systemroot%\UpdateAssistantV2" /a >nul 2>&1
  180. icacls "%systemroot%\UpdateAssistantV2" /reset >nul 2>&1
  181. del %systemroot%\UpdateAssistantV2\*.* /f /q >nul 2>&1
  182. md "%systemroot%\UpdateAssistantV2" >nul 2>&1
  183. attrib +s +h "%systemroot%\UpdateAssistantV2" >nul 2>&1
  184. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" %systemroot%\UpdateAssistantV2 /inheritance:r /remove:g *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  185. takeown /f "%SystemDrive%\Windows10Upgrade" /a >nul 2>&1
  186. icacls "%SystemDrive%\Windows10Upgrade" /reset >nul 2>&1
  187. del %SystemDrive%\Windows10Upgrade\*.* /f /q >nul 2>&1
  188. rmdir %SystemDrive%\Windows10Upgrade /s /q >nul 2>&1
  189. md "%systemdrive%\Windows10Upgrade" >nul 2>&1
  190. attrib +s +h %systemdrive%\Windows10Upgrade >nul 2>&1
  191. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" %systemdrive%\Windows10Upgrade /inheritance:r /remove:g *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  192. ::::::::::::::::::::::::::::
  193. ::Disable rempl
  194. if not exist "%ProgramFiles%\rempl" goto norempl
  195. takeown /f "%ProgramFiles%\rempl" /a >nul 2>&1
  196. icacls "%ProgramFiles%\rempl" /reset >nul 2>&1
  197. for %%? in ("%ProgramFiles%\rempl\*") do (
  198. takeown /f "%%?" /a >nul 2>&1
  199. icacls "%%?" /reset >nul 2>&1
  200. )
  201. del %ProgramFiles%\rempl\*.* /f /q >nul 2>&1
  202. rmdir %ProgramFiles%\rempl /s /q >nul 2>&1
  203. :norempl
  204. ::The rempl folder doesn't exist, so create it and lock it from system access.
  205. md "%ProgramFiles%\rempl" >nul 2>&1
  206. attrib +s +h "%ProgramFiles%\rempl" >nul 2>&1
  207. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" "%ProgramFiles%\rempl" /inheritance:r /remove:g *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  208. ::::::::::::::::::::::::::::
  209. :: Disable all Language Components Installer tasks
  210. takeown /f "%systemroot%\System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\*" /a >nul 2>&1
  211. icacls "%systemroot%\System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\*" /q /c /t /reset >nul 2>&1
  212. for %%? in ("%systemroot%\System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\*") do schtasks /change /tn "Microsoft\Windows\LanguageComponentsInstaller\%%~nx?" /disable >nul 2>&1
  213. ::::::::::::::::::::::::::::
  214. :: Disable and lock all Windows Update tasks.
  215. takeown /f "%systemroot%\System32\Tasks\Microsoft\Windows\WindowsUpdate\*" /a >nul 2>&1
  216. icacls "%systemroot%\System32\Tasks\Microsoft\Windows\WindowsUpdate\*" /q /c /t /reset >nul 2>&1
  217. for %%? in ("%systemroot%\System32\Tasks\Microsoft\Windows\WindowsUpdate\*") do schtasks /change /tn "Microsoft\Windows\WindowsUpdate\%%~nx?" /disable >nul 2>&1
  218. icacls "%systemroot%\System32\Tasks\Microsoft\Windows\WindowsUpdate\*" /inheritance:r /remove *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  219. ::::::::::::::::::::::::::::
  220. ::Set list (s32list) of update hijacker files to be disabled, then disable everything in the list.
  221. set s32list=EOSNotify.exe WaaSMedic.exe WaasMedicSvc.dll WaaSMedicPS.dll WaaSAssessment.dll UsoClient.exe
  222. set s32list=%s32list% SIHClient.exe MusNotificationUx.exe MusNotification.exe osrss.dll
  223. set s32=%systemroot%\System32
  224. ::If "s32list" files were previously renamed by script, restore original file names
  225. for %%# in (%s32list%) do (
  226. ren "%s32%\%%#"-backup "%%#" >nul 2>&1
  227. if exist "%s32%\%%#" del "%s32%\%%#"-backup /f /q >nul 2>&1
  228. )
  229. ::Lock files
  230. for %%# in (%s32list%) do (
  231. takeown /f "%s32%\%%#" /a >nul 2>&1
  232. icacls "%s32%\%%#" /reset >nul 2>&1
  233. if exist "%s32%\%%#" %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" "%s32%\%%#" /inheritance:r /remove *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  234. )
  235. ::If files in "s32list" aren't locked for whatever reason, rename them.
  236. for %%# in (%s32list%) do (
  237. ren "%s32%\%%#" "%%#"-backup >nul 2>&1
  238. if exist "%s32%\%%#"-backup del "%s32%\%%#" /f /q >nul 2>&1
  239. )
  240. ::::::::::::::::::::::::::::
  241. :: Create WDU.cmd
  242. (
  243. echo ::Allow only WDU task to run this file::
  244. echo whoami /user /nh ^| find /i "S-1-5-18" ^|^| exit
  245. echo cd /d "%%~dp0"
  246. echo ::Wait 5 minutes to prevent resource hogging after reboot with missed update::
  247. echo timeout /t 300^>nul
  248. echo ::If WUMT or WuMgr are running, cancel Defender update and exit. If not, continue::
  249. echo tasklist ^| findstr /i "wumt_x86.exe wumt_x64.exe wumgr.exe" ^&^& exit 1
  250. echo ::If Windows Defender is running, update it. If not, cancel Defender update and exit::
  251. echo sc query ^| find /i "windefend" ^|^| exit 1
  252. echo ::Enable Windows Update service and update Defender, then disable Update Service::
  253. echo wub.exe /e
  254. echo timeout /t 10
  255. echo "%%ProgramFiles%%\Windows Defender\MpCmdRun.exe" -SignatureUpdate
  256. echo wub.exe /d /p
  257. echo exit /b %%errorlevel%%
  258. )>.\bin\wdu.cmd"
  259. ::::::::::::::::::::::::::::
  260. ::Create WDU task, and wub_task
  261. call :create_task WDU "Windows Defender Update"
  262. call :create_task Wub_task "Windows Update Blocker Auto-Renewal"
  263. ::::::::::::::::::::::::::::
  264. echo.&echo Windows 10 updates disabled.
  265. echo Close window ^(click "X"^) if done, or press a key to check for updates...
  266. pause >nul 2>&1
  267. :splash
  268. cls
  269. echo.
  270. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ::::::::::::::::::::::::::::::::
  271. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ : ^ Welcome to manual updates! ^ :
  272. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ::::::::::::::::::::::::::::::::
  273. echo.
  274. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ The Windows Update Service is now DISABLED and stopped.
  275. echo ^ ^ The tasks "WDU" (Windows Defender Update) and "wub_task" (Forces Update service off
  276. echo ^ ^ ^ ^ ^ ^ ^ ^ after reboot and login) have been (re)created.
  277. echo.
  278. echo ^ * ^ Update Hijackers are now disabled! (see readme for details)
  279. echo ^ * ^ If you just want to disable the Update Hijackers and not check for or install
  280. echo ^ ^ ^ ^ updates, you may close this screen now.
  281. echo.
  282. echo ^ * ^ If you choose to review any available Windows updates, the script enables and
  283. echo ^ ^ ^ ^ starts only the Windows Update Service, then runs the Windows update Manager
  284. echo ^ ^ ^ ^ (WuMgr) or the Windows Update MiniTool (WUMT) to find and then hide or install
  285. echo ^ ^ ^ ^ selected Windows updates. If you run WUMT, don't change WUMT settings while
  286. echo ^ ^ ^ ^ running this script. If WuMgr or WUMT is offering updates, you need to hide or
  287. echo ^ ^ ^ ^ install them before closing WuMgr or WUMT.
  288. echo.
  289. echo ^ * ^ After checking for updates, the script stops and disables the Windows Update service
  290. echo ^ ^ ^ ^ when WuMgr or WUMT is closed whether or not the service was previously enabled.
  291. echo.
  292. echo ^ * ^ If you choose to use the Store, you can enable update service in Configurator.
  293. echo ^ ^ ^ ^ After using the Store, then either 1) disable update service or 2) continue script to
  294. echo ^ ^ ^ ^ check for Windows updates with WuMgr or WUMT after which the update service will be
  295. echo ^ ^ ^ ^ disabled.
  296. echo.
  297. echo ^ * ^ If you move this script to another folder run it again so the tasks will work!
  298. echo.
  299. echo ^ * ^ The included uninstaller undoes script changes.
  300. echo.&echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ---^>^>^> Press any key to continue. ^<^<^<---
  301. pause > nul
  302. ::::::::::::::::::::::::::::
  303. ::Internet connection check
  304. cls
  305. set state=
  306. set servers=download.windowsupdate.com internetbeacon.msedge.net microsoft.com Bing.com 0x0.st baidu.com
  307. echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  308. echo.
  309. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Internet connection test...
  310. echo.
  311. for %%i in (%servers%) do (call :internetcheck %%i)
  312. call :internetcheckerror
  313. :internetcheck
  314. set state=up
  315. powershell -Nologo -NoProfile -ExecutionPolicy Bypass "$ProgressPreference='SilentlyContinue';exit (Test-NetConnection %1% -Port 80 -WarningAction SilentlyContinue -InformationLevel Quiet)"
  316. IF %ERRORLEVEL% EQU 0 (set state=down & cls) else (goto postinternetcheck)
  317. echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  318. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ %1 is %state%
  319. exit /b
  320. :internetcheckerror
  321. cls
  322. echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  323. echo ::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: & echo.
  324. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Internet connection test failed. &echo Microsoft Store or Windows Updates won't work without internet. &echo. &echo ---^>^>^> Press a key to continue if you're sure internet is working. ^<^<^<--- & echo.&echo It's safe to cancel now if needed. Your system will not be left in an unstable state.&echo ^(Ctrl-C, Alt-F4, or click "X" to cancel and exit^)&echo. &echo ::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: & pause > nul
  325. :postinternetcheck
  326. ::::::::::::::::::::::::::::
  327. ::Windows Update Service Configurator
  328. cls
  329. echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  330. echo. & echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Initializing Configurator...
  331. ::disable windows update service except when wumt is run.
  332. :wudisable
  333. call :wuauserv d
  334. cls
  335. echo.
  336. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  337. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ : ^ ^ ^ ^ Sledgehammer - Windows 10 Update Control Configurator ^ ^ ^ ^ :
  338. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  339. echo.
  340. echo ^ ^ ^ ^ ^ ^ ^ ^ ---^>^>^> Windows Update Service is DISABLED and stopped ^(default^) ^<^<^<---
  341. echo.
  342. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [E]nable Update Service temporarily to use Windows Store.
  343. echo.
  344. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [1] Continue script to run Windows Update Manager (WuMgr)
  345. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in auto mode and check for Windows Updates.
  346. echo.
  347. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [2] Continue script to run Windows Update Minitool (WUMT)
  348. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in auto mode and check for Windows Updates.
  349. echo.
  350. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [3] Continue script to run Windows Update Manager (WuMgr)
  351. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in automatic Offline Mode. *Warning: Wsusscn2.cab is
  352. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ over 500 MB. Download will start immediately.*
  353. echo.
  354. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [4] Continue script to run Windows Update Manager (WuMgr)
  355. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in Expert Mode.
  356. echo.
  357. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [Q]uit script, or "Alt + F4", or close window, if you're
  358. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ just verifying or are finished changing the update
  359. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ service setting. It stays how it's set above.
  360. echo.
  361. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ The Windows Update service will be automatically
  362. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ started and stopped.
  363. echo.&echo.
  364. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Please select [E], [1], [2], [3], [4], or [Q]
  365. CHOICE /C E1234Q /M "Your choice?:" >nul 2>&1
  366. if %errorlevel%==6 (exit)
  367. if %errorlevel%==5 call :startupdate bin\wumgr.exe 7971f918-a847-4430-9279-4a52d1efe18d -onclose close.cmd
  368. if %errorlevel%==4 call :startupdate bin\wumgr.exe -update -offline 7971f918-a847-4430-9279-4a52d1efe18d -onclose close.cmd
  369. if %errorlevel%==3 call :StartUpdate %wumt% -update "-onclose close.cmd"
  370. if %errorlevel%==2 call :StartUpdate bin\wumgr.exe -update -online 7971f918-a847-4430-9279-4a52d1efe18d -provisioned -onclose close.cmd
  371. cls
  372. echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  373. echo.&echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Please wait while Windows Update Service is enabled...
  374. ::enable windows update service
  375. :wuenable
  376. call :wuauserv e
  377. cls
  378. echo.&echo.
  379. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  380. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ : ^ ^ ^ ^ Sledgehammer - Windows 10 Update Control Configurator ^ ^ ^ ^ :
  381. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  382. echo.
  383. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ---^>^>^> Windows Update Service is ENABLED ^(for Store^) ^<^<^<---
  384. echo.
  385. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [D]isable Update Service when finished using Store.
  386. echo.
  387. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [1] Continue script to run Windows Update Manager (WuMgr)
  388. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in auto mode and check for Windows Updates.
  389. echo.
  390. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [2] Continue script to run Windows Update Minitool (WUMT)
  391. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in auto mode and check for Windows Updates.
  392. echo.
  393. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [3] Continue script to run Windows Update Manager (WuMgr)
  394. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in automatic Offline Mode. *Warning: Wsusscn2.cab is
  395. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ over 500 MB. Download will start immediately.*
  396. echo.
  397. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [4] Continue script to run Windows Update Manager (WuMgr)
  398. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in Expert Mode.
  399. echo.
  400. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ The Windows Update service will be automatically
  401. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ started and stopped.
  402. echo.
  403. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Please select [D], [1], [2], [3], or [4]
  404. echo.
  405. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  406. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :^ Don't close this window or update service will stay on!!!^ :
  407. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ : ^ ^ Don't worry. Just run the script again to turn it off ^ ^ :
  408. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  409. CHOICE /C D1234 /M "Your choice?:" >nul 2>&1
  410. if %errorlevel%==5 call :startupdate bin\wumgr.exe 7971f918-a847-4430-9279-4a52d1efe18d -onclose close.cmd
  411. if %errorlevel%==4 call :startupdate bin\wumgr.exe -update -offline 7971f918-a847-4430-9279-4a52d1efe18d -onclose close.cmd
  412. if %errorlevel%==3 call :StartUpdate %wumt% -update "-onclose close.cmd"
  413. if %errorlevel%==2 call :StartUpdate bin\wumgr.exe -update -online 7971f918-a847-4430-9279-4a52d1efe18d -provisioned -onclose close.cmd
  414. if %errorlevel%==1 (
  415. cls
  416. echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  417. echo.&echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Please wait while Windows Update Service is disabled...
  418. goto wudisable
  419. )
  420. ::::::::::::::::::::::::::::
  421. :create_task
  422. set "w=echo f.writeline "
  423. echo Set Fso=CreateObject^("Scripting.FileSystemObject"^):Set f=Fso.CreateTextFile^(fso.GetParentFolderName^(WScript.ScriptFullName^) ^& "\task.xml",True,True^)>task.vbs
  424. if /i %1==wdu (
  425. rem Create automatic Windows Defender Update "WDU" task that updates Defender only if it's enabled and running.
  426. rem Create WDU.xml
  427. rem
  428. rem
  429. rem Creating Windows Defender Update auto renewal task
  430. rem
  431. (
  432. %w%"<?xml version=""1.0"" encoding=""UTF-16""?>"
  433. %w%"<Task version=""1.2"" xmlns=""http://schemas.microsoft.com/windows/2004/02/mit/task"">"
  434. %w%"<RegistrationInfo>"
  435. %w%"<Date>2016-02-18T08:29:39</Date>"
  436. %w%"<Author>pf100\rpo</Author>"
  437. %w%"<URI>WindowsDefenderUpdate</URI>"
  438. %w%"</RegistrationInfo>"
  439. %w%"<Triggers>"
  440. %w%"<CalendarTrigger>"
  441. %w%"<StartBoundary>2016-01-01T00:01:00</StartBoundary>"
  442. %w%"<Enabled>true</Enabled>"
  443. %w%"<ScheduleByDay>"
  444. %w%"<DaysInterval>1</DaysInterval>"
  445. %w%"</ScheduleByDay>"
  446. %w%"</CalendarTrigger>"
  447. %w%"<CalendarTrigger>"
  448. %w%"<StartBoundary>2016-01-01T06:01:00</StartBoundary>"
  449. %w%"<Enabled>true</Enabled>"
  450. %w%"<ScheduleByDay>"
  451. %w%"<DaysInterval>1</DaysInterval>"
  452. %w%"</ScheduleByDay>"
  453. %w%"</CalendarTrigger>"
  454. %w%"<CalendarTrigger>"
  455. %w%"<StartBoundary>2016-01-01T12:01:00</StartBoundary>"
  456. %w%"<Enabled>true</Enabled>"
  457. %w%"<ScheduleByDay>"
  458. %w%"<DaysInterval>1</DaysInterval>"
  459. %w%"</ScheduleByDay>"
  460. %w%"</CalendarTrigger>"
  461. %w%"<CalendarTrigger>"
  462. %w%"<StartBoundary>2016-01-01T18:01:00</StartBoundary>"
  463. %w%"<Enabled>true</Enabled>"
  464. %w%"<ScheduleByDay>"
  465. %w%"<DaysInterval>1</DaysInterval>"
  466. %w%"</ScheduleByDay>"
  467. %w%"</CalendarTrigger>"
  468. %w%"<BootTrigger>"
  469. %w%"<Enabled>true</Enabled>"
  470. %w%"<Delay>PT10M</Delay>"
  471. %w%"</BootTrigger>"
  472. %w%"<LogonTrigger>"
  473. %w%"<Enabled>true</Enabled>"
  474. %w%"</LogonTrigger>"
  475. %w%"</Triggers>"
  476. %w%"<Principals>"
  477. %w%"<Principal id=""Author"">"
  478. %w%"<UserId>S-1-5-18</UserId>"
  479. %w%"<RunLevel>HighestAvailable</RunLevel>"
  480. %w%"</Principal>"
  481. %w%"</Principals>"
  482. %w%"<Settings>"
  483. %w%"<MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>"
  484. %w%"<DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>"
  485. %w%"<StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>"
  486. %w%"<AllowHardTerminate>true</AllowHardTerminate>"
  487. %w%"<StartWhenAvailable>false</StartWhenAvailable>"
  488. %w%"<RunOnlyIfNetworkAvailable>true</RunOnlyIfNetworkAvailable>"
  489. %w%"<IdleSettings>"
  490. %w%"<StopOnIdleEnd>false</StopOnIdleEnd>"
  491. %w%"<RestartOnIdle>false</RestartOnIdle>"
  492. %w%"</IdleSettings>"
  493. %w%"<AllowStartOnDemand>true</AllowStartOnDemand>"
  494. %w%"<Enabled>true</Enabled>"
  495. %w%"<Hidden>false</Hidden>"
  496. %w%"<RunOnlyIfIdle>false</RunOnlyIfIdle>"
  497. %w%"<WakeToRun>false</WakeToRun>"
  498. %w%"<ExecutionTimeLimit>P3D</ExecutionTimeLimit>"
  499. %w%"<Priority>7</Priority>"
  500. %w%"</Settings>"
  501. %w%"<Actions Context=""Author"">"
  502. %w%"<Exec>"
  503. %w%"<Command>""" ^& FSO.GetParentFolderName^(Wscript.ScriptFullName^) ^& "\bin\WDU.cmd" ^& """</Command>"
  504. %w%"</Exec>"
  505. %w%"</Actions>"
  506. %w%"</Task>"
  507. )>>task.vbs
  508. )
  509. if /i %1==wub_task (
  510. rem
  511. rem Create Windows Update Blocker "Wub_task" that sets your desired Windows Update service state at boot.
  512. rem
  513. rem Create Wub_task
  514. rem
  515. rem
  516. (
  517. %w%"<?xml version=""1.0"" encoding=""UTF-16""?>"
  518. %w%"<Task version=""1.2"" xmlns=""http://schemas.microsoft.com/windows/2004/02/mit/task"">"
  519. %w%"<RegistrationInfo>"
  520. %w%"<Date>2016-02-18T08:29:39</Date>"
  521. %w%"<Author>pf100\rpo</Author>"
  522. %w%"<URI>\wub_task</URI>"
  523. %w%"</RegistrationInfo>"
  524. %w%"<Triggers>"
  525. %w%"<BootTrigger>"
  526. %w%"<Enabled>true</Enabled>"
  527. %w%"</BootTrigger>"
  528. %w%"<LogonTrigger>"
  529. %w%"<Enabled>true</Enabled>"
  530. %w%"</LogonTrigger>"
  531. %w%"</Triggers>"
  532. %w%"<Principals>"
  533. %w%"<Principal id=""Author"">"
  534. %w%"<RunLevel>HighestAvailable</RunLevel>"
  535. %w%"</Principal>"
  536. %w%"</Principals>"
  537. %w%"<Settings>"
  538. %w%"<MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>"
  539. %w%"<DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>"
  540. %w%"<StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>"
  541. %w%"<AllowHardTerminate>true</AllowHardTerminate>"
  542. %w%"<StartWhenAvailable>true</StartWhenAvailable>"
  543. %w%"<RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>"
  544. %w%"<IdleSettings>"
  545. %w%"<StopOnIdleEnd>false</StopOnIdleEnd>"
  546. %w%"<RestartOnIdle>false</RestartOnIdle>"
  547. %w%"</IdleSettings>"
  548. %w%"<AllowStartOnDemand>true</AllowStartOnDemand>"
  549. %w%"<Enabled>true</Enabled>"
  550. %w%"<Hidden>false</Hidden>"
  551. %w%"<RunOnlyIfIdle>false</RunOnlyIfIdle>"
  552. %w%"<WakeToRun>false</WakeToRun>"
  553. %w%"<ExecutionTimeLimit>PT72H</ExecutionTimeLimit>"
  554. %w%"<Priority>7</Priority>"
  555. %w%"</Settings>"
  556. %w%"<Actions Context=""Author"">"
  557. %w%"<Exec>"
  558. %w%"<Command>""" ^& FSO.GetParentFolderName^(Wscript.ScriptFullName^) ^& "\bin\Wub.exe""</Command>"
  559. %w%"<Arguments>/d /p</Arguments>"
  560. %w%"</Exec>"
  561. %w%"</Actions>"
  562. %w%"</Task>"
  563. )>>task.vbs
  564. )
  565. echo f.Close>>task.vbs & task.vbs
  566. ::
  567. schtasks /delete /tn "%1" /f >nul 2>&1
  568. schtasks /create /tn "\Microsoft\Sledgehammer\%1" /ru "SYSTEM" /xml task.xml /F >nul 2>&1 || (
  569. cls&echo.&echo Creating %2 %1 task errored.&echo.&echo.&echo Press any key to exit... & pause > nul &exit)
  570. del task.vbs task.xml >nul 2>&1
  571. exit /b
  572. ::::::::::::::::::::::::::::
  573. :wuauserv
  574. if /i "%1"=="e" (set "wub=wub.exe /e" & set "status=True") else (set "wub=wub.exe /d /p" & set "status=False")
  575. .\bin\%wub%
  576. timeout -t 1 > nul
  577. set /a "max_retry=10" & set /a "i=0"
  578. :wuauserv1
  579. if %i%==%max_retry% (echo Operation did not complete within %max_retry% s. Press any key do exit...&pause>nul&exit)
  580. set /a "i+=1"
  581. WMIC Service WHERE "Name = 'Wuauserv'" GET Started | find /i "%status%" >nul && exit /b || (timeout /t 1 >nul & goto :wuauserv1)
  582. ::::::::::::::::::::::::::::
  583. :StartUpdate
  584. (
  585. echo @echo off
  586. echo :loop
  587. echo net start wuauserv
  588. echo timeout /t 10
  589. echo goto loop
  590. )>WU-keep-alive.cmd
  591. (
  592. echo @echo off
  593. echo cd /d "%%~dp0"
  594. echo del WU-keep-alive.cmd
  595. echo .\bin\wub.exe /d /p
  596. echo del close.cmd ^& exit
  597. )>close.cmd
  598. call :wuauserv e
  599. echo CreateObject^("WScript.Shell"^).Run "WU-keep-alive.cmd",0 >WU-keep-alive.vbs&WU-keep-alive.vbs&del WU-keep-alive.vbs
  600. Start "" %*
  601. exit
Advertisement
Add Comment
Please, Sign In to add comment