pf100

v2.7.0Sledgehammer.cmd

May 23rd, 2020
159
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 31.51 KB | None | 0 0
  1. @echo off
  2. mode con cols=89 lines=34
  3. Title Sledgehammer 2.7.0
  4. Color 1F & goto start
  5. Original script by pf100 @ MDL with special thanks to rpo and abbodi1406 @ MDL for code improvements.
  6. Thanks to RetiredGeek at askwoody.com forum for original ideas on how to get MS-DEFCON rating.
  7. Project page and source code:
  8. https://forums.mydigitallife.net/threads/sledgehammer-windows-10-update-control.72203/
  9. ******************************************************************
  10. You may freely modify this script as you wish, I only request that you leave the credits and the
  11. link to the original script.
  12. ******************************************************************
  13. Don't move this script to another folder without running it again or the tasks won't work!
  14. This script provides manual updating for Windows 10 including Home versions.
  15. Update Windows 10 on your schedule, not Microsoft's!
  16. I originally wrote this script for personal use because of the lack of update options with the
  17. original RTM release of Windows 10 Pro. I wanted to update Windows 10 when I had the free time
  18. to manually update, just like I did with previous versions of Windows that allowed me to
  19. set updates to manual, not when Microsoft forced it on me while I was busy using my computer.
  20. *******************************************************************
  21. WUMT is available here: https://forums.mydigitallife.net/threads/64939-Windows-Update-MiniTool
  22. Windows Update Blocker is available here: http://sordum.org/files/windows-update-blocker/old/Wub_v1.0.zip
  23. Only use Windows Update Blocker v1.0 with this script, NOT v1.1!
  24. NSudo is available here: https://github.com/M2Team/NSudo/releases/tag/6.1
  25. *******************************************************************
  26. How it works: The script first checks if the OS is Windows 8.1 or older and if so
  27. it notifies the user, then exits. Windows 10 only!
  28. This script creates a smart Windows Defender Update task "WDU" that updates Windows
  29. Defender every 6 hours if it's running and enabled, and doesn't update it if it's not
  30. running and disabled, saving resources; auto-elevates, uninstalls and removes the
  31. Windows 10 Update Assistant, disables everything in the %programfiles%\rempl folder, resets and
  32. removes permissions from and disables these Update Hijackers:
  33. EOSNotify.exe
  34. WaaSMedic.exe
  35. WaasMedicSvc.dll
  36. WaaSMedicPS.dll
  37. WaaSAssessment.dll
  38. UsoClient.exe
  39. SIHClient.exe
  40. MusNotificationUx.exe
  41. MusNotification.exe
  42. osrss.dll
  43. %ProgramFiles%\rempl
  44. %systemroot%\UpdateAssistant
  45. %systemroot%\UpdateAssistantV2
  46. %systemdrive%\Windows10Upgrade
  47. disables all WindowsUpdate tasks
  48. makes sure the task "wub_task" is installed that runs wub at boot (to stop updates from turning
  49. updates back on), runs wub.exe and enables and starts the windows update service (wuauserv) if
  50. disabled, installs "WDU" Windows Defender Update task that runs every 2 hours (but doesn't update
  51. Defender if Defender is disabled), then runs the correct version of the Windows Update MiniTool in
  52. "auto search for updates" mode for your OS version's architecture (x86 or x64), then disables and
  53. stops wuauserv giving you full control. No more forced automatic updates or surprise reboots.
  54. This was written for Windows 10 Pro and Home, but works with all versions of Windows 10. Don't
  55. change any settings in lower left of WUMT while running the script.
  56. *******************************************************************
  57. I also included an uninstaller.cmd that deletes the "WDU" and "wub_task" tasks, deletes the WDU.cmd
  58. file used by WDU task, restores the rempl folder, resets Update Hijacker permissions to how they
  59. were originally, renables "WindowsUpdate" tasks, and turns off wub (if enabled) which turns the windows update service on automatic
  60. again, undoing everything done by the script. If you uninstall after having used the installer the
  61. script files are removed also.
  62. *******************************************************************
  63. Configurator leaves the Update Hijackers disabled, but gives you the option of turning on the windows
  64. update service temporarily to use the Store or any other operation that requires the windows update
  65. service, such as some DISM operations, installing dotNet 3.5, App Updates, etc.
  66. *******************************************************************
  67. :start
  68. ::::::::::::::::::::::::::::
  69. cd /d "%~dp0"
  70. :::::::::::::::::::::::::::::::::::::::::
  71. :: Automatically check & get admin rights
  72. :::::::::::::::::::::::::::::::::::::::::
  73. :: ECHO.
  74. :: ECHO =============================
  75. :: ECHO Running Admin shell
  76. :: ECHO =============================
  77. :: Check Privileges
  78. :: Get Privileges
  79. :: and
  80. :: Invoke UAC for Privilege Escalation
  81. :: Notify if error escalating
  82. :: and prevent looping if escalation fails
  83. ::::::::::::::::::::::::::::
  84. set "params=Problem_with_elevating_UAC_for_Administrator_Privileges"&if exist "%temp%\getadmin.vbs" del "%temp%\getadmin.vbs"
  85. fsutil dirty query %systemdrive% >nul 2>&1 && goto :GotPrivileges
  86. :: The following test is to avoid infinite looping if elevating UAC for Administrator Privileges failed
  87. If "%1"=="%params%" (echo Elevating UAC for Administrator Privileges failed&echo Right click on the script and select 'Run as administrator'&echo Press any key to exit...&pause>nul 2>&1&exit)
  88. cmd /u /c echo Set UAC = CreateObject^("Shell.Application"^) : UAC.ShellExecute "%~0", "%params%", "", "runas", 1 > "%temp%\getadmin.vbs"&cscript //nologo "%temp%\getadmin.vbs" && exit /b || (echo Elevating UAC for Administrator Privileges failed&echo Right click on the script and select 'Run as administrator'&echo Press any key to exit...&pause>nul 2>&1&exit)
  89. :GotPrivileges
  90. ::::::::::::::::::::::::::::
  91. ::Uninstall and remove Windows 10 Update assistant.
  92. ::Disable Windows Update Service until script menu screen.
  93. ::Reset (in case of wrong Permissions), remove Permissions from and
  94. ::disable "Update Hijackers"
  95. ::Install wub_task (prevents Windows Update service from starting after installing updates and rebooting).
  96. ::Install "WDU" task that only updates Defender if it's enabled. Otherwise it doesn't do anything.
  97. ::Enable and start the Windows Update Service (wuauserv).
  98. ::Run the correct version of WUMT for your architecture.
  99. ::Start WUMT in "auto-check for updates" mode.
  100. ::After updates are completed and WUMT is closed and/or the "reboot"
  101. ::button in WUMT is pressed, silently run wub.exe and disable and stop wuauserv
  102. ::::::::::::::::::::::::::::
  103. ::Test for Windows versions below Windows 10 and if so inform user, then exit...
  104. ::Get Windows OS build number
  105. for /f "tokens=2 delims==" %%a in ('wmic path Win32_OperatingSystem get BuildNumber /value') do (
  106. set /a WinBuild=%%a
  107. )
  108. if %winbuild% LEQ 9600 (
  109. echo.&echo This is not Windows 10. Press a key to exit...
  110. pause > nul
  111. exit
  112. )
  113. ::::::::::::::::::::::::::::
  114. ::Determine if running 32 or 64 bit Windows OS and set variables accordingly.
  115. wmic cpu get AddressWidth /value|find "32">nul&&set PROCESSOR_ARCHITECTURE=X86||set PROCESSOR_ARCHITECTURE=AMD64
  116. if %PROCESSOR_ARCHITECTURE%==AMD64 (
  117. set "nsudovar=.\bin\NSudoCx64.exe"
  118. set "wumt=.\bin\wumt_x64.exe"
  119. ) else (
  120. set "nsudovar=.\bin\NSudoc.exe"
  121. set "wumt=.\bin\wumt_x86.exe"
  122. )
  123. ::::::::::::::::::::::::::::
  124. ::Remove and/or lock Update Assistant
  125. if exist "%systemdrive%\Windows10Upgrade\Windows10UpgraderApp.exe" ( echo Windows 10 Update Assistant detected. Preparing to uninstall.
  126. echo The "Windows 10 Update Assistant has stopped working" dialog box may pop up.
  127. echo If so, just close it.
  128. echo.& echo Press a key to acknowledge this and please wait for the uninstall to finish.
  129. echo Script will continue after uninstall and removal is completed...
  130. pause > nul
  131. echo Uninstalling Windows 10 Update Assistant...
  132. %systemdrive%\Windows10Upgrade\Windows10UpgraderApp.exe /forceuninstall
  133. timeout /t 10 /nobreak
  134. cls)
  135. ::::::::::::::::::::::::::::
  136. :: Get MS-Defcon from askwoody.com
  137. powershell -Nologo -NoProfile -ExecutionPolicy Bypass "$progressPreference='silentlyContinue';Write-Output 'Sledgehammer is attempting to retrieve MS-DEFCON rating from askwoody.com...';Try{$WebResponse=Invoke-WebRequest 'https://www.askwoody.com/' -UseBasicParsing -TimeoutSec 10}Catch{$WebResponse=''};if ($WebResponse.Statuscode -ne 200){Clear-Host;\"`r`nUnable to retrieve MS-DEFCON rating from askwoody.com\"; exit};ForEach ($Image in $WebResponse.Images){$x=$Image.OuterHTML.ToString();If($x -like '*MS-DEFCON-*'){Clear-Host;\"`r`n MS-DEFCON = \"+$x.split('/')[8].split('.')[0].SubString(10,1);break}}
  138. echo. & echo :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  139. echo.&echo MS-DEFCON 1: Current Microsoft patches are causing havoc. Don't patch.
  140. echo.&echo MS-DEFCON 2: Patch reliability is unclear. Unless you have an immediate, pressing need
  141. echo to install a specific patch, don't do it.
  142. echo.&echo MS-DEFCON 3: Patch reliability is unclear, but widespread attacks make patching prudent.
  143. echo Go ahead and patch, but watch out for potential problems.
  144. echo.&echo MS-DEFCON 4: There are isolated problems with current patches, but they are well-known
  145. echo and documented here. Check this site to see if you're affected and if
  146. echo things look OK, go ahead and patch.
  147. echo.&echo MS-DEFCON 5: All's clear. Patch while it's safe.
  148. echo. & echo :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  149. echo.&echo More info at https://www.askwoody.com
  150. echo. & echo :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  151. ::::::::::::::::::::::::::::
  152. rem echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  153. echo. & echo Disabling update hijackers...
  154. echo Creating tasks...
  155. echo Disabling windows Update Service...
  156. echo. & echo :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  157. ::::::::::::::::::::::::::::
  158. ::Disable update service.
  159. call :wuauserv d
  160. ::::::::::::::::::::::::::::
  161. schtasks /delete /tn WDU >nul /f 2>&1
  162. schtasks /delete /tn Wub_task /f >nul 2>&1
  163. schtasks /Delete /Tn \Microsoft\WuWrapperScript\WDU /f >nul 2>&1
  164. schtasks /Delete /Tn \Microsoft\WuWrapperScript\Wub_task /f >nul 2>&1
  165. rmdir %SystemDrive%\Windows\System32\Tasks\Microsoft\WuWrapperScript /s /q >nul 2>&1
  166. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\WuWrapperScript" /f >nul 2>&1
  167. schtasks /Delete /Tn \Microsoft\Sledgehammer\WDU /f >nul 2>&1
  168. schtasks /Delete /Tn \Microsoft\Sledgehammer\Wub_task /f >nul 2>&1
  169. rmdir %SystemDrive%\Windows\System32\Tasks\Microsoft\Sledgehammer /s /q >nul 2>&1
  170. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Sledgehammer" /f >nul 2>&1
  171. ::::::::::::::::::::::::::::::::::
  172. takeown /f "%systemroot%\UpdateAssistant" /a >nul 2>&1
  173. icacls "%systemroot%\UpdateAssistant" /reset >nul 2>&1
  174. del %systemroot%\UpdateAssistant\*.* /f /q >nul 2>&1
  175. rmdir %systemroot%\UpdateAssistant /s /q >nul 2>&1
  176. md "%systemroot%\UpdateAssistant" >nul 2>&1
  177. attrib +s +h "%systemroot%\UpdateAssistant" >nul 2>&1
  178. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" %systemroot%\UpdateAssistant /inheritance:r /remove:g *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  179. takeown /f "%systemroot%\UpdateAssistantV2" /a >nul 2>&1
  180. icacls "%systemroot%\UpdateAssistantV2" /reset >nul 2>&1
  181. del %systemroot%\UpdateAssistantV2\*.* /f /q >nul 2>&1
  182. md "%systemroot%\UpdateAssistantV2" >nul 2>&1
  183. attrib +s +h "%systemroot%\UpdateAssistantV2" >nul 2>&1
  184. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" %systemroot%\UpdateAssistantV2 /inheritance:r /remove:g *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  185. takeown /f "%SystemDrive%\Windows10Upgrade" /a >nul 2>&1
  186. icacls "%SystemDrive%\Windows10Upgrade" /reset >nul 2>&1
  187. del %SystemDrive%\Windows10Upgrade\*.* /f /q >nul 2>&1
  188. rmdir %SystemDrive%\Windows10Upgrade /s /q >nul 2>&1
  189. md "%systemdrive%\Windows10Upgrade" >nul 2>&1
  190. attrib +s +h %systemdrive%\Windows10Upgrade >nul 2>&1
  191. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" %systemdrive%\Windows10Upgrade /inheritance:r /remove:g *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  192. ::::::::::::::::::::::::::::
  193. ::Disable rempl
  194. if not exist "%ProgramFiles%\rempl" goto norempl
  195. takeown /f "%ProgramFiles%\rempl" /a >nul 2>&1
  196. icacls "%ProgramFiles%\rempl" /reset >nul 2>&1
  197. for %%? in ("%ProgramFiles%\rempl\*") do (
  198. takeown /f "%%?" /a >nul 2>&1
  199. icacls "%%?" /reset >nul 2>&1
  200. )
  201. del %ProgramFiles%\rempl\*.* /f /q >nul 2>&1
  202. rmdir %ProgramFiles%\rempl /s /q >nul 2>&1
  203. :norempl
  204. ::The rempl folder doesn't exist, so create it and lock it from system access.
  205. md "%ProgramFiles%\rempl" >nul 2>&1
  206. attrib +s +h "%ProgramFiles%\rempl" >nul 2>&1
  207. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" "%ProgramFiles%\rempl" /inheritance:r /remove:g *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  208. ::::::::::::::::::::::::::::
  209. :: Disable all Language Components Installer tasks
  210. takeown /f "%systemroot%\System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\*" /a >nul 2>&1
  211. icacls "%systemroot%\System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\*" /q /c /t /reset >nul 2>&1
  212. for %%? in ("%systemroot%\System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\*") do schtasks /change /tn "Microsoft\Windows\LanguageComponentsInstaller\%%~nx?" /disable >nul 2>&1
  213. ::::::::::::::::::::::::::::
  214. :: Disable and lock all Windows Update tasks.
  215. takeown /f "%systemroot%\System32\Tasks\Microsoft\Windows\WindowsUpdate\*" /a >nul 2>&1
  216. icacls "%systemroot%\System32\Tasks\Microsoft\Windows\WindowsUpdate\*" /q /c /t /reset >nul 2>&1
  217. for %%? in ("%systemroot%\System32\Tasks\Microsoft\Windows\WindowsUpdate\*") do schtasks /change /tn "Microsoft\Windows\WindowsUpdate\%%~nx?" /disable >nul 2>&1
  218. icacls "%systemroot%\System32\Tasks\Microsoft\Windows\WindowsUpdate\*" /inheritance:r /remove *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  219. ::::::::::::::::::::::::::::
  220. ::Set list (s32list) of update hijacker files to be disabled, then disable everything in the list.
  221. set s32list=EOSNotify.exe WaaSMedic.exe WaasMedicSvc.dll WaaSMedicPS.dll WaaSAssessment.dll UsoClient.exe
  222. set s32list=%s32list% SIHClient.exe MusNotificationUx.exe MusNotification.exe osrss.dll
  223. set s32=%systemroot%\System32
  224. ::If "s32list" files were previously renamed by script, restore original file names
  225. for %%# in (%s32list%) do (
  226. ren "%s32%\%%#"-backup "%%#" >nul 2>&1
  227. if exist "%s32%\%%#" del "%s32%\%%#"-backup /f /q >nul 2>&1
  228. )
  229. ::Lock files
  230. for %%# in (%s32list%) do (
  231. takeown /f "%s32%\%%#" /a >nul 2>&1
  232. icacls "%s32%\%%#" /reset >nul 2>&1
  233. if exist "%s32%\%%#" %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" "%s32%\%%#" /inheritance:r /remove *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  234. )
  235. ::If files in "s32list" aren't locked for whatever reason, rename them.
  236. for %%# in (%s32list%) do (
  237. ren "%s32%\%%#" "%%#"-backup >nul 2>&1
  238. if exist "%s32%\%%#"-backup del "%s32%\%%#" /f /q >nul 2>&1
  239. )
  240. ::::::::::::::::::::::::::::
  241. :: Create WDU.cmd
  242. (
  243. echo ::Allow only WDU task to run this file::
  244. echo whoami /user /nh ^| find /i "S-1-5-18" ^|^| exit
  245. echo cd /d "%%~dp0"
  246. echo ::Wait 5 minutes to prevent resource hogging after reboot with missed update::
  247. echo timeout /t 300^>nul
  248. echo ::If WUMT or WuMgr are running, cancel Defender update and exit. If not, continue::
  249. echo tasklist ^| findstr /i "wumt_x86.exe wumt_x64.exe wumgr.exe" ^&^& exit 1
  250. echo ::If Windows Defender is running, update it. If not, cancel Defender update and exit::
  251. echo sc query ^| find /i "windefend" ^|^| exit 1
  252. echo ::Enable Windows Update service and update Defender, then disable Update Service::
  253. echo wub.exe /e
  254. echo timeout /t 10
  255. echo "%%ProgramFiles%%\Windows Defender\MpCmdRun.exe" -SignatureUpdate
  256. echo wub.exe /d /p
  257. echo exit /b %%errorlevel%%
  258. )>.\bin\wdu.cmd"
  259. ::::::::::::::::::::::::::::
  260. ::Create WDU task, and wub_task
  261. call :create_task WDU "Windows Defender Update"
  262. call :create_task Wub_task "Windows Update Blocker Auto-Renewal"
  263. ::::::::::::::::::::::::::::
  264. echo.&echo Windows 10 updates disabled.
  265. echo Close window ^(click "X"^) if done, or press a key to check for updates...
  266. pause >nul 2>&1
  267. :splash
  268. cls
  269. echo.
  270. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ::::::::::::::::::::::::::::::::
  271. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ : ^ Welcome to manual updates! ^ :
  272. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ::::::::::::::::::::::::::::::::
  273. echo.
  274. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ The Windows Update Service is now DISABLED and stopped.
  275. echo ^ ^ The tasks "WDU" (Windows Defender Update) and "wub_task" (Forces Update service off
  276. echo ^ ^ ^ ^ ^ ^ ^ ^ after reboot and login) have been (re)created.
  277. echo.
  278. echo ^ * ^ Update Hijackers are now disabled! (see readme for details)
  279. echo ^ * ^ If you just want to disable the Update Hijackers and not check for or install
  280. echo ^ ^ ^ ^ updates, you may close this screen now.
  281. echo.
  282. echo ^ * ^ If you choose to review any available Windows updates, the script enables and
  283. echo ^ ^ ^ ^ starts only the Windows Update Service, then runs the Windows update Manager
  284. echo ^ ^ ^ ^ (WuMgr) or the Windows Update MiniTool (WUMT) to find and then hide or install
  285. echo ^ ^ ^ ^ selected Windows updates. If you run WUMT, don't change WUMT settings while
  286. echo ^ ^ ^ ^ running this script. If WuMgr or WUMT is offering updates, you need to hide or
  287. echo ^ ^ ^ ^ install them before closing WuMgr or WUMT.
  288. echo.
  289. echo ^ * ^ After checking for updates, the script stops and disables the Windows Update service
  290. echo ^ ^ ^ ^ when WuMgr or WUMT is closed whether or not the service was previously enabled.
  291. echo.
  292. echo ^ * ^ If you choose to use the Store, you can enable update service in Configurator.
  293. echo ^ ^ ^ ^ After using the Store, then either 1) disable update service or 2) continue script to
  294. echo ^ ^ ^ ^ check for Windows updates with WuMgr or WUMT after which the update service will be
  295. echo ^ ^ ^ ^ disabled.
  296. echo.
  297. echo ^ * ^ If you move this script to another folder run it again so the tasks will work!
  298. echo.
  299. echo ^ * ^ The included uninstaller undoes script changes.
  300. echo.&echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ---^>^>^> Press any key to continue. ^<^<^<---
  301. pause > nul
  302. ::::::::::::::::::::::::::::
  303. ::Internet connection check
  304. cls
  305. set divider=:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  306. powershell -nologo "If([Activator]::CreateInstance([Type]::GetTypeFromCLSID([Guid]'{DCB00C01-570F-4A9B-8D69-199FDBA5723B}')).IsConnectedToInternet){Exit 0}Else{Exit 1}"
  307. if %errorlevel%==0 (goto postinternetcheck)
  308. :internetcheckerror
  309. cls
  310. echo.&echo.&echo.&echo.&echo.&echo.
  311. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Internet connection test failed. &echo.&echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Microsoft Store or Windows Updates won't work without internet. &echo.&echo. & echo %divider% & echo.&echo.&echo. ^ ^ ^ ^ ^ ^ ^ ---^>^>^> Press a key to continue if you're sure internet is working. ^<^<^<--- & echo.&echo. & echo %divider% & echo.&echo ^ ^ It's safe to cancel now if needed. Your system will not be left in an unstable state.&echo.&echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^(Ctrl-C, Alt-F4, or click "X" to cancel and exit^)&echo. & pause > nul
  312. :postinternetcheck
  313. ::::::::::::::::::::::::::::
  314. ::Windows Update Service Configurator
  315. cls
  316. echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  317. echo. & echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Initializing Configurator...
  318. ::disable windows update service except when wumt is run.
  319. :wudisable
  320. timeout -t 1 > nul
  321. call :wuauserv d
  322. cls
  323. echo.
  324. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  325. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ : ^ ^ ^ ^ Sledgehammer - Windows 10 Update Control Configurator ^ ^ ^ ^ :
  326. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  327. echo.
  328. echo ^ ^ ^ ^ ^ ^ ^ ^ ---^>^>^> Windows Update Service is DISABLED and stopped ^(default^) ^<^<^<---
  329. echo.
  330. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [E]nable Update Service temporarily to use Windows Store.
  331. echo.
  332. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [1] Continue script to run Windows Update Manager (WuMgr)
  333. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in auto mode and check for Windows Updates.
  334. echo.
  335. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [2] Continue script to run Windows Update Minitool (WUMT)
  336. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in auto mode and check for Windows Updates.
  337. echo.
  338. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [3] Continue script to run Windows Update Manager (WuMgr)
  339. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in automatic Offline Mode. *Warning: Wsusscn2.cab is
  340. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ over 500 MB. Download will start immediately.*
  341. echo.
  342. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [4] Continue script to run Windows Update Manager (WuMgr)
  343. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in Expert Mode.
  344. echo.
  345. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [Q]uit script, or "Alt + F4", or close window, if you're
  346. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ just verifying or are finished changing the update
  347. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ service setting. It stays how it's set above.
  348. echo.
  349. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ The Windows Update service will be automatically
  350. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ started and stopped.
  351. echo.&echo.
  352. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Please select [E], [1], [2], [3], [4], or [Q]
  353. CHOICE /C E1234Q /M "Your choice?:" >nul 2>&1
  354. if %errorlevel%==6 (exit)
  355. if %errorlevel%==5 call :startupdate bin\wumgr.exe 7971f918-a847-4430-9279-4a52d1efe18d -onclose close.cmd
  356. if %errorlevel%==4 call :startupdate bin\wumgr.exe -update -offline 7971f918-a847-4430-9279-4a52d1efe18d -onclose close.cmd
  357. if %errorlevel%==3 call :StartUpdate %wumt% -update "-onclose close.cmd"
  358. if %errorlevel%==2 call :StartUpdate bin\wumgr.exe -update -online 7971f918-a847-4430-9279-4a52d1efe18d -provisioned -onclose close.cmd
  359. cls
  360. echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  361. echo.&echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Please wait while Windows Update Service is enabled...
  362. ::enable windows update service
  363. :wuenable
  364. call :wuauserv e
  365. cls
  366. echo.&echo.
  367. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  368. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ : ^ ^ ^ ^ Sledgehammer - Windows 10 Update Control Configurator ^ ^ ^ ^ :
  369. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  370. echo.
  371. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ---^>^>^> Windows Update Service is ENABLED ^(for Store^) ^<^<^<---
  372. echo.
  373. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [D]isable Update Service when finished using Store.
  374. echo.
  375. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [1] Continue script to run Windows Update Manager (WuMgr)
  376. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in auto mode and check for Windows Updates.
  377. echo.
  378. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [2] Continue script to run Windows Update Minitool (WUMT)
  379. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in auto mode and check for Windows Updates.
  380. echo.
  381. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [3] Continue script to run Windows Update Manager (WuMgr)
  382. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in automatic Offline Mode. *Warning: Wsusscn2.cab is
  383. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ over 500 MB. Download will start immediately.*
  384. echo.
  385. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [4] Continue script to run Windows Update Manager (WuMgr)
  386. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ in Expert Mode.
  387. echo.
  388. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ The Windows Update service will be automatically
  389. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ started and stopped.
  390. echo.
  391. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Please select [D], [1], [2], [3], or [4]
  392. echo.
  393. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  394. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :^ Don't close this window or update service will stay on!!!^ :
  395. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ : ^ ^ Don't worry. Just run the script again to turn it off ^ ^ :
  396. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  397. CHOICE /C D1234 /M "Your choice?:" >nul 2>&1
  398. if %errorlevel%==5 call :startupdate bin\wumgr.exe 7971f918-a847-4430-9279-4a52d1efe18d -onclose close.cmd
  399. if %errorlevel%==4 call :startupdate bin\wumgr.exe -update -offline 7971f918-a847-4430-9279-4a52d1efe18d -onclose close.cmd
  400. if %errorlevel%==3 call :StartUpdate %wumt% -update "-onclose close.cmd"
  401. if %errorlevel%==2 call :StartUpdate bin\wumgr.exe -update -online 7971f918-a847-4430-9279-4a52d1efe18d -provisioned -onclose close.cmd
  402. if %errorlevel%==1 (
  403. cls
  404. echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  405. echo.&echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Please wait while Windows Update Service is disabled...
  406. goto wudisable
  407. )
  408. ::::::::::::::::::::::::::::
  409. :create_task
  410. set "w=echo f.writeline "
  411. echo Set Fso=CreateObject^("Scripting.FileSystemObject"^):Set f=Fso.CreateTextFile^(fso.GetParentFolderName^(WScript.ScriptFullName^) ^& "\task.xml",True,True^)>task.vbs
  412. if /i %1==wdu (
  413. rem Create automatic Windows Defender Update "WDU" task that updates Defender only if it's enabled and running.
  414. rem Create WDU.xml
  415. rem
  416. rem
  417. rem Creating Windows Defender Update auto renewal task
  418. rem
  419. (
  420. %w%"<?xml version=""1.0"" encoding=""UTF-16""?>"
  421. %w%"<Task version=""1.2"" xmlns=""http://schemas.microsoft.com/windows/2004/02/mit/task"">"
  422. %w%"<RegistrationInfo>"
  423. %w%"<Date>2016-02-18T08:29:39</Date>"
  424. %w%"<Author>pf100\rpo</Author>"
  425. %w%"<URI>WindowsDefenderUpdate</URI>"
  426. %w%"</RegistrationInfo>"
  427. %w%"<Triggers>"
  428. %w%"<CalendarTrigger>"
  429. %w%"<StartBoundary>2016-01-01T00:01:00</StartBoundary>"
  430. %w%"<Enabled>true</Enabled>"
  431. %w%"<ScheduleByDay>"
  432. %w%"<DaysInterval>1</DaysInterval>"
  433. %w%"</ScheduleByDay>"
  434. %w%"</CalendarTrigger>"
  435. %w%"<CalendarTrigger>"
  436. %w%"<StartBoundary>2016-01-01T06:01:00</StartBoundary>"
  437. %w%"<Enabled>true</Enabled>"
  438. %w%"<ScheduleByDay>"
  439. %w%"<DaysInterval>1</DaysInterval>"
  440. %w%"</ScheduleByDay>"
  441. %w%"</CalendarTrigger>"
  442. %w%"<CalendarTrigger>"
  443. %w%"<StartBoundary>2016-01-01T12:01:00</StartBoundary>"
  444. %w%"<Enabled>true</Enabled>"
  445. %w%"<ScheduleByDay>"
  446. %w%"<DaysInterval>1</DaysInterval>"
  447. %w%"</ScheduleByDay>"
  448. %w%"</CalendarTrigger>"
  449. %w%"<CalendarTrigger>"
  450. %w%"<StartBoundary>2016-01-01T18:01:00</StartBoundary>"
  451. %w%"<Enabled>true</Enabled>"
  452. %w%"<ScheduleByDay>"
  453. %w%"<DaysInterval>1</DaysInterval>"
  454. %w%"</ScheduleByDay>"
  455. %w%"</CalendarTrigger>"
  456. %w%"<BootTrigger>"
  457. %w%"<Enabled>true</Enabled>"
  458. %w%"<Delay>PT10M</Delay>"
  459. %w%"</BootTrigger>"
  460. %w%"<LogonTrigger>"
  461. %w%"<Enabled>true</Enabled>"
  462. %w%"</LogonTrigger>"
  463. %w%"</Triggers>"
  464. %w%"<Principals>"
  465. %w%"<Principal id=""Author"">"
  466. %w%"<UserId>S-1-5-18</UserId>"
  467. %w%"<RunLevel>HighestAvailable</RunLevel>"
  468. %w%"</Principal>"
  469. %w%"</Principals>"
  470. %w%"<Settings>"
  471. %w%"<MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>"
  472. %w%"<DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>"
  473. %w%"<StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>"
  474. %w%"<AllowHardTerminate>true</AllowHardTerminate>"
  475. %w%"<StartWhenAvailable>false</StartWhenAvailable>"
  476. %w%"<RunOnlyIfNetworkAvailable>true</RunOnlyIfNetworkAvailable>"
  477. %w%"<IdleSettings>"
  478. %w%"<StopOnIdleEnd>false</StopOnIdleEnd>"
  479. %w%"<RestartOnIdle>false</RestartOnIdle>"
  480. %w%"</IdleSettings>"
  481. %w%"<AllowStartOnDemand>true</AllowStartOnDemand>"
  482. %w%"<Enabled>true</Enabled>"
  483. %w%"<Hidden>false</Hidden>"
  484. %w%"<RunOnlyIfIdle>false</RunOnlyIfIdle>"
  485. %w%"<WakeToRun>false</WakeToRun>"
  486. %w%"<ExecutionTimeLimit>P3D</ExecutionTimeLimit>"
  487. %w%"<Priority>7</Priority>"
  488. %w%"</Settings>"
  489. %w%"<Actions Context=""Author"">"
  490. %w%"<Exec>"
  491. %w%"<Command>""" ^& FSO.GetParentFolderName^(Wscript.ScriptFullName^) ^& "\bin\WDU.cmd" ^& """</Command>"
  492. %w%"</Exec>"
  493. %w%"</Actions>"
  494. %w%"</Task>"
  495. )>>task.vbs
  496. )
  497. if /i %1==wub_task (
  498. rem
  499. rem Create Windows Update Blocker "Wub_task" that sets your desired Windows Update service state at boot.
  500. rem
  501. rem Create Wub_task
  502. rem
  503. rem
  504. (
  505. %w%"<?xml version=""1.0"" encoding=""UTF-16""?>"
  506. %w%"<Task version=""1.2"" xmlns=""http://schemas.microsoft.com/windows/2004/02/mit/task"">"
  507. %w%"<RegistrationInfo>"
  508. %w%"<Date>2016-02-18T08:29:39</Date>"
  509. %w%"<Author>pf100\rpo</Author>"
  510. %w%"<URI>\wub_task</URI>"
  511. %w%"</RegistrationInfo>"
  512. %w%"<Triggers>"
  513. %w%"<BootTrigger>"
  514. %w%"<Enabled>true</Enabled>"
  515. %w%"</BootTrigger>"
  516. %w%"<LogonTrigger>"
  517. %w%"<Enabled>true</Enabled>"
  518. %w%"</LogonTrigger>"
  519. %w%"</Triggers>"
  520. %w%"<Principals>"
  521. %w%"<Principal id=""Author"">"
  522. %w%"<RunLevel>HighestAvailable</RunLevel>"
  523. %w%"</Principal>"
  524. %w%"</Principals>"
  525. %w%"<Settings>"
  526. %w%"<MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>"
  527. %w%"<DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>"
  528. %w%"<StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>"
  529. %w%"<AllowHardTerminate>true</AllowHardTerminate>"
  530. %w%"<StartWhenAvailable>true</StartWhenAvailable>"
  531. %w%"<RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>"
  532. %w%"<IdleSettings>"
  533. %w%"<StopOnIdleEnd>false</StopOnIdleEnd>"
  534. %w%"<RestartOnIdle>false</RestartOnIdle>"
  535. %w%"</IdleSettings>"
  536. %w%"<AllowStartOnDemand>true</AllowStartOnDemand>"
  537. %w%"<Enabled>true</Enabled>"
  538. %w%"<Hidden>false</Hidden>"
  539. %w%"<RunOnlyIfIdle>false</RunOnlyIfIdle>"
  540. %w%"<WakeToRun>false</WakeToRun>"
  541. %w%"<ExecutionTimeLimit>PT72H</ExecutionTimeLimit>"
  542. %w%"<Priority>7</Priority>"
  543. %w%"</Settings>"
  544. %w%"<Actions Context=""Author"">"
  545. %w%"<Exec>"
  546. %w%"<Command>""" ^& FSO.GetParentFolderName^(Wscript.ScriptFullName^) ^& "\bin\Wub.exe""</Command>"
  547. %w%"<Arguments>/d /p</Arguments>"
  548. %w%"</Exec>"
  549. %w%"</Actions>"
  550. %w%"</Task>"
  551. )>>task.vbs
  552. )
  553. echo f.Close>>task.vbs & task.vbs
  554. ::
  555. schtasks /delete /tn "%1" /f >nul 2>&1
  556. schtasks /create /tn "\Microsoft\Sledgehammer\%1" /ru "SYSTEM" /xml task.xml /F >nul 2>&1 || (
  557. cls&echo.&echo Creating %2 %1 task errored.&echo.&echo.&echo Press any key to exit... & pause > nul &exit)
  558. del task.vbs task.xml >nul 2>&1
  559. exit /b
  560. ::::::::::::::::::::::::::::
  561. :wuauserv
  562. if /i "%1"=="e" (set "wub=wub.exe /e" & set "status=True") else (set "wub=wub.exe /d /p" & set "status=False")
  563. .\bin\%wub%
  564. timeout -t 2 > nul
  565. set /a "max_retry=10" & set /a "i=0"
  566. :wuauserv1
  567. if %i%==%max_retry% (echo Operation did not complete within %max_retry% s. Press any key do exit...&pause>nul&exit)
  568. set /a "i+=1"
  569. WMIC Service WHERE "Name = 'Wuauserv'" GET Started | find /i "%status%" >nul && exit /b || (timeout /t 1 >nul & goto :wuauserv1)
  570. ::::::::::::::::::::::::::::
  571. :StartUpdate
  572. (
  573. echo @echo off
  574. echo :loop
  575. echo net start wuauserv
  576. echo timeout /t 10
  577. echo goto loop
  578. )>WU-keep-alive.cmd
  579. (
  580. echo @echo off
  581. echo cd /d "%%~dp0"
  582. echo del WU-keep-alive.cmd
  583. echo .\bin\wub.exe /d /p
  584. echo del close.cmd ^& exit
  585. )>close.cmd
  586. call :wuauserv e
  587. echo CreateObject^("WScript.Shell"^).Run "WU-keep-alive.cmd",0 >WU-keep-alive.vbs&WU-keep-alive.vbs&del WU-keep-alive.vbs
  588. Start "" %*
  589. exit
Advertisement
Add Comment
Please, Sign In to add comment