LaDEEKill3R

Windows Defender Firewall Tools v2

Mar 28th, 2022 (edited)
282
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Batch 4.57 KB | None | 0 0
  1. @Echo Off
  2. Title Reg Converter v1.2 & Color 1A
  3. cd %systemroot%\system32
  4. call :IsAdmin
  5.  
  6. Set "WDF=HKCR\exefile\shell\WDF"
  7. Reg.exe add "%WDF%" /v "SubCommands" /t REG_SZ /d "" /f
  8. Reg.exe add "%WDF%" /v "HasLUAShield" /t REG_SZ /d "" /f
  9. Reg.exe add "%WDF%" /v "Position" /t REG_SZ /d "Bottom" /f
  10. Reg.exe add "%WDF%" /v "MUIVerb" /t REG_SZ /d "&Windows Defender Firewall" /f
  11. Reg.exe add "%WDF%" /v "Icon" /t REG_SZ /d "mstscax.dll ,1" /f
  12. Reg.exe add "%WDF%" /v "Extended" /t REG_SZ /d "" /f
  13. Reg.exe add "%WDF%\Shell\1_Block_Out" /v "HasLUAShield" /t REG_SZ /d "" /f
  14. Reg.exe add "%WDF%\Shell\1_Block_Out" /v "MUIVerb" /t REG_SZ /d "&Block Out Windows Firewall" /f
  15. Reg.exe add "%WDF%\Shell\1_Block_Out" /v "Icon" /t REG_SZ /d "imageres.dll,-105" /f
  16. Reg.exe add "%WDF%\Shell\1_Block_Out\Command" /ve /t REG_SZ /d "\"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe\" -Executionpolicy ByPass -WindowStyle Hidden -NoLogo -Command \"start powershell -Verb runas -ArgumentList \\\"-NoLogo -WindowStyle Hidden -command `\\\"New-NetFirewallRule -DisplayName ([System.IO.Path]::GetFilenameWithoutExtension('%%1_Out')) -Name '%%1_Out' -Enabled True -Direction Outbound -Action Block -Program '%%1'`\\\"\\\"\"" /f
  17. Reg.exe add "%WDF%\Shell\1_Block_In" /v "HasLUAShield" /t REG_SZ /d "" /f
  18. Reg.exe add "%WDF%\Shell\1_Block_In" /v "MUIVerb" /t REG_SZ /d "&Block In Windows Firewall" /f
  19. Reg.exe add "%WDF%\Shell\1_Block_In" /v "Icon" /t REG_SZ /d "imageres.dll,-105" /f
  20. Reg.exe add "%WDF%\Shell\1_Block_In\Command" /ve /t REG_SZ /d "\"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe\" -Executionpolicy ByPass -WindowStyle Hidden -NoLogo -Command \"start powershell -Verb runas -ArgumentList \\\"-NoLogo -WindowStyle Hidden -command `\\\"New-NetFirewallRule -DisplayName ([System.IO.Path]::GetFilenameWithoutExtension('%%1_In')) -Name '%%1_In' -Enabled True -Direction Inbound -Action Block -Program '%%1'`\\\"\\\"\"" /f
  21. REM Reg.exe add "%WDF%\Shell\2_Remove_Out" /v "CommandFlags" /t REG_DWORD /d "32" /f
  22. Reg.exe add "%WDF%\Shell\2_Remove_Out" /v "Icon" /t REG_SZ /d "imageres.dll,-106" /f
  23. Reg.exe add "%WDF%\Shell\2_Remove_Out" /v "MUIVerb" /t REG_SZ /d "&Remove Out From Windows Firewall" /f
  24. Reg.exe add "%WDF%\Shell\2_Remove_Out" /v "HasLUAShield" /t REG_SZ /d "" /f
  25. Reg.exe add "%WDF%\Shell\2_Remove_Out\Command" /ve /t REG_SZ /d "\"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe\" -Executionpolicy ByPass -WindowStyle Hidden -NoLogo -Command \"start powershell -Verb runas -ArgumentList \\\"-NoLogo -WindowStyle Hidden -command `\\\"Remove-NetFirewallRule -Name '%%1_Out'`\\\"\\\"\"" /f
  26. Reg.exe add "%WDF%\Shell\2_Remove_In" /v "Icon" /t REG_SZ /d "imageres.dll,-106" /f
  27. Reg.exe add "%WDF%\Shell\2_Remove_In" /v "MUIVerb" /t REG_SZ /d "&Remove In From Windows Firewall" /f
  28. Reg.exe add "%WDF%\Shell\2_Remove_In" /v "HasLUAShield" /t REG_SZ /d "" /f
  29. Reg.exe add "%WDF%\Shell\2_Remove_In\Command" /ve /t REG_SZ /d "\"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe\" -Executionpolicy ByPass -WindowStyle Hidden -NoLogo -Command \"start powershell -Verb runas -ArgumentList \\\"-NoLogo -WindowStyle Hidden -command `\\\"Remove-NetFirewallRule -Name '%%1_In'`\\\"\\\"\"" /f
  30. Reg.exe add "%WDF%\Shell\3_Launch" /v "MUIVerb" /t REG_SZ /d "&Launch Windows Defender Firewall" /f
  31. Reg.exe add "%WDF%\Shell\3_Launch" /v "Icon" /t REG_SZ /d "imageres.dll,208" /f
  32. Reg.exe add "%WDF%\Shell\3_Launch" /v "HasLUAShield" /t REG_SZ /d "" /f
  33. Reg.exe add "%WDF%\Shell\3_Launch" /v "CommandFlags" /t REG_DWORD /d "32" /f
  34. Reg.exe add "%WDF%\Shell\3_Launch\Command" /ve /t REG_SZ /d "mmc wf.msc" /f
  35. Reg.exe add "%WDF%\Shell\4_Delete" /v "HasLUAShield" /t REG_SZ /d "" /f
  36. Reg.exe add "%WDF%\Shell\4_Delete" /v "CommandFlags" /t REG_DWORD /d "32" /f
  37. Reg.exe add "%WDF%\Shell\4_Delete" /v "MUIVerb" /t REG_SZ /d "&Delete Windows Defender Firewall Menu" /f
  38. Reg.exe add "%WDF%\Shell\4_Delete\Command" /ve /t REG_SZ /d "REG DELETE HKCR\exefile\shell\WDF /F /REG:64" /f
  39. Reg.exe add "%WDF%\Shell\5_GoToKey" /v "CommandFlags" /t REG_DWORD /d "32" /f
  40. Reg.exe add "%WDF%\Shell\5_GoToKey" /v "MUIVerb" /t REG_SZ /d "&GoTo Registry Directly to a Given Key" /f
  41. Reg.exe add "%WDF%\Shell\5_GoToKey" /v "HasLUAShield" /t REG_SZ /d "" /f
  42. Reg.exe add "%WDF%\Shell\5_GoToKey\Command" /ve /t REG_SZ /d "cmd /c REG ADD \"HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\" /v \"LastKey\" /d \"HKEY_CLASSES_ROOT\exefile\shell\WDF\" /f & start \"\" regedit & exit" /f
  43. Exit
  44.  
  45. :IsAdmin
  46. Reg.exe query "HKU\S-1-5-19\Environment"
  47. If Not %ERRORLEVEL% EQU 0 (
  48.  Cls & Echo You must have administrator rights to continue ...
  49.  Pause & Exit
  50. )
  51. Cls
  52. goto:eof
  53.  
Add Comment
Please, Sign In to add comment