pf100

v2.6.0v6Windows10UpdateControlWrapperScript.cmd

Mar 26th, 2019
333
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 28.60 KB | None | 0 0
  1. @echo off
  2. mode con cols=89 lines=34
  3. Title Windows 10 Update Control Wrapper Script 2.6.0
  4. Color 1F & goto start
  5. Original script by pf100 @ MDL with special thanks to rpo and abbodi1406 @ MDL for code improvements.
  6. Project page and source code:
  7. https://forums.mydigitallife.net/threads/72203-WUMT-Wrapper-script-controls-windows-update-service
  8. ******************************************************************
  9. You may freely modify this script as you wish, I only request that you leave the credits and the
  10. link to the original script.
  11. ******************************************************************
  12. Don't move this script to another folder without running it again or the tasks won't work!
  13. Script supports only English and other Western European language characters in path.
  14. See https://msdn.microsoft.com/en-us/library/cc195054.aspx for more information about allowed characters.
  15. This script provides manual updating for Windows 10 including Home versions.
  16. Update Windows 10 on your schedule, not Microsoft's!
  17. I originally wrote this script for personal use because of the lack of update options with the
  18. original RTM release of Windows 10 Pro. I wanted to update Windows 10 when I had the free time
  19. to manually update, just like I did with previous versions of Windows that allowed me to
  20. set updates to manual, not when Microsoft forced it on me while I was busy using my computer.
  21. *******************************************************************
  22. WUMT is available here: https://forums.mydigitallife.net/threads/64939-Windows-Update-MiniTool
  23. Windows Update Blocker is available here: http://sordum.org/files/windows-update-blocker/old/Wub_v1.0.zip
  24. Only use Windows Update Blocker v1.0 with this script, NOT v1.1!
  25. NSudo is available here: https://github.com/M2Team/NSudo/releases/tag/6.1
  26. *******************************************************************
  27. How it works: The script first checks if the OS is Windows 8.1 or older and if so
  28. it notifies the user, then exits. Windows 10 only!
  29. This script creates a smart Windows Defender Update task "WDU" that updates Windows
  30. Defender every 2 hours if it's running and enabled, and doesn't update it if it's not
  31. running and disabled, saving resources; auto-elevates, uninstalls and removes the
  32. Windows 10 Update Assistant, disables everything in the %programfiles%\rempl folder, resets and
  33. removes permissions from and disables these Update Hijackers:
  34. remsh.exe
  35. osrss.dll
  36. UsoClient.exe
  37. WaaSMedic.exe
  38. WaasMedicSvc.dll
  39. WaaSMedicPS.dll
  40. WaaSAssessment.dll
  41. MusNotification.exe
  42. MusNotificationUx.exe
  43. SIHClient.exe
  44. disables all WindowsUpdate tasks
  45. makes sure the task "wub_task" is installed that runs wub at boot (to stop updates from turning
  46. updates back on), runs wub.exe and enables and starts the windows update service (wuauserv) if
  47. disabled, installs "WDU" Windows Defender Update task that runs every 2 hours (but doesn't update
  48. Defender if Defender is disabled), then runs the correct version of the Windows Update MiniTool in
  49. "auto search for updates" mode for your OS version's architecture (x86 or x64), then disables and
  50. stops wuauserv giving you full control. No more forced automatic updates or surprise reboots.
  51. This was written for Windows 10 Pro and Home, but works with all versions of Windows 10. Don't
  52. change any settings in lower left of WUMT while running the script.
  53. *******************************************************************
  54. I also included an uninstaller.cmd that deletes the "WDU" and "wub_task" tasks, deletes the WDU.cmd
  55. file used by WDU task, restores the rempl folder, resets Update Hijacker permissions to how they
  56. were originally, renables "WindowsUpdate" tasks, and turns off wub (if enabled) which turns the windows update service on automatic
  57. again, undoing everything done by the script. If you uninstall after having used the installer the
  58. script files are removed also.
  59. *******************************************************************
  60. Configurator leaves the Update Hijackers disabled, but gives you the option of turning on the windows
  61. update service temporarily to use the Store or any other operation that requires the windows update
  62. service, such as some DISM operations, installing dotNet 3.5, App Updates, etc.
  63. *******************************************************************
  64. :start
  65. cd /d "%~dp0"
  66. :::::::::::::::::::::::::::::::::::::::::
  67. :: Automatically check & get admin rights
  68. :::::::::::::::::::::::::::::::::::::::::
  69. :: ECHO.
  70. :: ECHO =============================
  71. :: ECHO Running Admin shell
  72. :: ECHO =============================
  73. :: Check Privileges
  74. :: Get Privileges
  75. :: and
  76. :: Invoke UAC for Privilege Escalation
  77. :: Notify if error escalating
  78. :: and prevent looping if escalation fails
  79. ::::::::::::::::::::::::::::
  80. set "params=Problem_with_elevating_UAC_for_Administrator_Privileges"&if exist "%temp%\getadmin.vbs" del "%temp%\getadmin.vbs"
  81. fsutil dirty query %systemdrive% >nul 2>&1 && goto :GotPrivileges
  82. :: The following test is to avoid infinite looping if elevating UAC for Administrator Privileges failed
  83. If "%1"=="%params%" (echo Elevating UAC for Administrator Privileges failed&echo Right click on the script and select 'Run as administrator'&echo Press any key to exit...&pause>nul 2>&1&exit)
  84. cmd /u /c echo Set UAC = CreateObject^("Shell.Application"^) : UAC.ShellExecute "%~0", "%params%", "", "runas", 1 > "%temp%\getadmin.vbs"&cscript //nologo "%temp%\getadmin.vbs"&exit
  85. :GotPrivileges
  86. ::::::::::::::::::::::::::::
  87. ::Uninstall and remove Windows 10 Update assistant.
  88. ::Disable Windows Update Service until script menu screen.
  89. ::Reset (in case of wrong Permissions), remove Permissions from and
  90. ::disable "Update Hijackers"
  91. ::Install wub_task (prevents Windows Update service from starting after installing updates and rebooting).
  92. ::Install "WDU" task that only updates Defender if it's enabled. Otherwise it doesn't do anything.
  93. ::Enable and start the Windows Update Service (wuauserv).
  94. ::Run the correct version of WUMT for your architecture.
  95. ::Start WUMT in "auto-check for updates" mode.
  96. ::After updates are completed and WUMT is closed and/or the "reboot"
  97. ::button in WUMT is pressed, silently run wub.exe and disable and stop wuauserv
  98. ::::::::::::::::::::::::::::
  99. @echo off
  100. cls
  101. ::Test for Windows versions below Windows 10 and if so inform user, then exit...
  102. ::Get Windows OS build number
  103. for /f "tokens=2 delims==" %%a in ('wmic path Win32_OperatingSystem get BuildNumber /value') do (
  104. set /a WinBuild=%%a
  105. )
  106. if %winbuild% LEQ 9600 (
  107. echo.&echo This is not Windows 10. Press a key to exit...
  108. pause > nul
  109. exit
  110. )
  111. ::::::::::::::::::::::::::::
  112. (
  113. echo # Get MS-Defcon from askwoody.com
  114. echo clear-host
  115. echo $progressPreference = 'silentlyContinue'
  116. rem echo "`r`nPlease wait...`r`n"
  117. echo Try {$WebResponse = Invoke-WebRequest "https://www.askwoody.com/" -UseBasicParsing} Catch {$WebResponse=""}
  118. echo if ^($WebResponse.Statuscode -ne 200^){write-host "askwoody.com is down or internet is disconnected"; exit}
  119. echo ForEach ^($Image in $WebResponse.Images^) {
  120. echo $x = $Image.OuterHTML.ToString^(^)
  121. echo If ^($x -like "*MS-DEFCON-*"^) {
  122. echo "`r`nMS-DEFCON = " + $x.split^('/'^)[8].split^('.'^)[0].SubString^(10,1^)
  123. echo "`r`n::::::::::::::::::::::::::::"
  124. echo "`r`nMS-DEFCON 1: Current Microsoft patches are causing havoc. Don't patch.`r`n" + `
  125. echo "`r`nMS-DEFCON 2: Patch reliability is unclear. Unless you have an immediate, pressing need" + `
  126. echo "`r`n to install a specific patch, don't do it.`r`n" + `
  127. echo "`r`nMS-DEFCON 3: Patch reliability is unclear, but widespread attacks make patching prudent." + `
  128. echo "`r`n Go ahead and patch, but watch out for potential problems.`r`n" + `
  129. echo "`r`nMS-DEFCON 4: There are isolated problems with current patches, but they are well-known" + `
  130. echo "`r`n and documented here. Check this site to see if you're affected and if" + `
  131. echo "`r`n things look OK, go ahead and patch.`r`n" + `
  132. echo "`r`nMS-DEFCON 5: All's clear. Patch while it's safe.`r`n" + `
  133. echo "`r`nMore info at https://www.askwoody.com/patch-list-master/"
  134. echo exit
  135. echo }
  136. echo }
  137. )>"%temp%\awmsdc.ps1"
  138. PowerShell.exe -Nologo -NoProfile -ExecutionPolicy Bypass -command "%temp%\awmsdc.ps1"
  139. del "%temp%\awmsdc.ps1"
  140. ::::::::::::::::::::::::::::
  141. ::Determine if running 32 or 64 bit Windows OS and set variables accordingly.
  142. wmic cpu get AddressWidth /value|find "32">nul&&set PROCESSOR_ARCHITECTURE=X86||set PROCESSOR_ARCHITECTURE=AMD64
  143. if %PROCESSOR_ARCHITECTURE%==AMD64 (
  144. set "nsudovar=NSudoCx64.exe"
  145. set "wumt=wumt_x64.exe"
  146. ) else (
  147. set "nsudovar=NSudoc.exe"
  148. set "wumt=wumt_x86.exe"
  149. )
  150. ::::::::::::::::::::::::::::
  151. ::Remove and/or lock Update Assistant
  152. if exist "%systemdrive%\Windows10Upgrade\Windows10UpgraderApp.exe" ( echo Windows 10 Update Assistant detected. Preparing to uninstall.
  153. echo The "Windows 10 Update Assistant has stopped working" dialog box may pop up. If so, just close it.
  154. echo Press a key to acknowledge this and please wait for the uninstall to finish.
  155. echo Script will continue after uninstall and removal is completed...
  156. pause > nul
  157. echo Uninstalling Windows 10 Update Assistant...
  158. %systemdrive%\Windows10Upgrade\Windows10UpgraderApp.exe /forceuninstall
  159. timeout /t 10 /nobreak
  160. cls)
  161. ::::::::::::::::::::::::::::
  162. rem echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  163. echo.
  164. echo Disabling update hijackers...
  165. echo Creating tasks...
  166. echo Disabling windows Update Service...
  167. echo.
  168. ::::::::::::::::::::::::::::
  169. del %SystemDrive%\Windows10Upgrade\*.* /f /q >nul 2>&1
  170. rmdir %SystemDrive%\Windows10Upgrade /s /q >nul 2>&1
  171. del %systemroot%\UpdateAssistant\*.* /f /q >nul 2>&1
  172. if not exist %systemroot%\UpdateAssistant md "%systemroot%\UpdateAssistant" >nul 2>&1
  173. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" %systemroot%\UpdateAssistant /inheritance:r /remove:g *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  174. del %systemroot%\UpdateAssistantV2\*.* /f /q >nul 2>&1
  175. if not exist %systemroot%\UpdateAssistantV2 md "%systemroot%\UpdateAssistantV2" >nul 2>&1
  176. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" %systemroot%\UpdateAssistantV2 /inheritance:r /remove:g *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  177. if not exist %systemdrive%\Windows10Upgrade md "%systemdrive%\Windows10Upgrade" >nul 2>&1
  178. attrib +s +h %systemdrive%\Windows10Upgrade >nul 2>&1
  179. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" %systemdrive%\Windows10Upgrade /inheritance:r /remove:g *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  180. ::::::::::::::::::::::::::::
  181. :: Disable all Language Components Installer tasks
  182. takeown /f "%systemroot%\System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\*" /a >nul 2>&1
  183. icacls "%systemroot%\System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\*" /q /c /t /reset >nul 2>&1
  184. for %%? in ("%systemroot%\System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\*") do schtasks /change /tn "Microsoft\Windows\LanguageComponentsInstaller\%%~nx?" /disable >nul 2>&1
  185. ::::::::::::::::::::::::::::
  186. :: Disable and lock all Windows Update tasks.
  187. takeown /f "%systemroot%\System32\Tasks\Microsoft\Windows\WindowsUpdate\*" /a >nul 2>&1
  188. icacls "%systemroot%\System32\Tasks\Microsoft\Windows\WindowsUpdate\*" /q /c /t /reset >nul 2>&1
  189. for %%? in ("%systemroot%\System32\Tasks\Microsoft\Windows\WindowsUpdate\*") do schtasks /change /tn "Microsoft\Windows\WindowsUpdate\%%~nx?" /disable >nul 2>&1
  190. icacls "%systemroot%\System32\Tasks\Microsoft\Windows\WindowsUpdate\*" /inheritance:r /remove *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  191. ::::::::::::::::::::::::::::
  192. ::Set list (s32list) of update hijacker files to be disabled, then disable everything in the list.
  193. set s32list=EOSNotify.exe WaaSMedic.exe WaasMedicSvc.dll WaaSMedicPS.dll WaaSAssessment.dll UsoClient.exe
  194. set s32list=%s32list% SIHClient.exe MusNotificationUx.exe MusNotification.exe osrss.dll
  195. set s32=%systemroot%\System32
  196. ::If "s32list" files were previously renamed by script, restore original file names
  197. for %%# in (%s32list%) do (
  198. ren "%s32%\%%#"-backup "%%#" >nul 2>&1
  199. if exist "%s32%\%%#" del "%s32%\%%#"-backup /f /q >nul 2>&1
  200. )
  201. timeout /t 2 >nul 2>&1
  202. ::Lock files
  203. for %%# in (%s32list%) do (
  204. takeown /f "%s32%\%%#" /a >nul 2>&1
  205. icacls "%s32%\%%#" /reset >nul 2>&1
  206. if exist "%s32%\%%#" %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" "%s32%\%%#" /inheritance:r /remove *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  207. )
  208. timeout /t 2 >nul 2>&1
  209. ::If files in "s32list" aren't locked for whatever reason, rename them.
  210. for %%# in (%s32list%) do (
  211. ren "%s32%\%%#" "%%#"-backup >nul 2>&1
  212. if exist "%s32%\%%#"-backup del "%s32%\%%#" /f /q >nul 2>&1
  213. )
  214. ::::::::::::::::::::::::::::
  215. ::Disable files in rempl folder if folder exists, then lock rempl folder acess also.
  216. if not exist "%ProgramFiles%\rempl" goto norempl
  217. for %%? in ("%ProgramFiles%\rempl\*") do (
  218. takeown /f "%%?" /a >nul 2>&1
  219. icacls "%%?" /reset >nul 2>&1
  220. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" "%%?" /inheritance:r /remove *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  221. )
  222. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" "%ProgramFiles%\rempl" /inheritance:r /remove:g *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  223. ::::::::::::::::::::::::::::
  224. :norempl
  225. ::The rempl folder doesn't exist, so create it and lock it from system access.
  226. md "%ProgramFiles%\rempl" >nul 2>&1
  227. %nsudovar% -ShowWindowMode:Hide -Wait -U:T -P:E "%systemroot%\System32\icacls.exe" "%ProgramFiles%\rempl" /inheritance:r /remove:g *S-1-5-32-544 *S-1-5-11 *S-1-5-32-545 *S-1-5-18 >nul 2>&1
  228. ::::::::::::::::::::::::::::
  229. :: Create WDU.cmd
  230. (
  231. echo ::Allow only WDU task to run this file::
  232. echo whoami /user /nh ^| find /i "S-1-5-18" ^|^| exit
  233. echo cd /d "%%~dp0"
  234. echo ::Wait 5 minutes to prevent resource hogging after reboot with missed update::
  235. echo timeout /t 300^>nul
  236. echo ::If WUMT or WuMgr are running, cancel Defender update and exit. If not, continue::
  237. echo tasklist ^| findstr /i "wumt_x86.exe wumt_x64.exe wumgr.exe" ^&^& exit 1
  238. echo ::If Windows Defender is running, update it. If not, cancel Defender update and exit::
  239. echo sc query ^| find /i "windefend" ^|^| exit 1
  240. echo ::Enable Windows Update service and update Defender, then disable Update Service::
  241. echo wub.exe /e
  242. echo timeout /t 10
  243. echo "%%ProgramFiles%%\Windows Defender\MpCmdRun.exe" -SignatureUpdate
  244. echo wub.exe /d /p
  245. echo exit /b %%errorlevel%%
  246. )>wdu.cmd"
  247. ::::::::::::::::::::::::::::
  248. ::Create WDU task, and wub_task
  249. call :create_task WDU "Windows Defender Update"
  250. call :create_task Wub_task "Windows Update Blocker Auto-Renewal"
  251. ::::::::::::::::::::::::::::
  252. ::Disable update service.
  253. call :wuauserv d
  254. ::::::::::::::::::::::::::::
  255. echo Go to "https://www.askwoody.com/patch-list-master/" website? [Y]/[N]?
  256. CHOICE /C YN /M "Your choice?:" >nul 2>&1
  257. if %errorlevel%==2 (goto splash)
  258. start https://www.askwoody.com/patch-list-master/
  259. echo.&echo Press a key when ready to continue... & pause > nul
  260. :splash
  261. cls
  262. echo.
  263. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ::::::::::::::::::::::::::::::::
  264. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ : ^ Welcome to manual updates! ^ :
  265. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ::::::::::::::::::::::::::::::::
  266. echo.
  267. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ The Windows Update Service is now DISABLED and stopped.
  268. echo ^ ^ The tasks "WDU" (Windows Defender Update) and "wub_task" (Forces Update service off
  269. echo ^ ^ ^ ^ ^ ^ ^ ^ after reboot and login) have been (re)created.
  270. echo.
  271. echo ^ * ^ Update Hijackers are now disabled! (see readme for details)
  272. echo ^ * ^ If you just want to disable the Update Hijackers and not check for or install
  273. echo ^ ^ ^ ^ updates, you may close this screen now.
  274. echo.
  275. echo ^ * ^ If you choose to review any available Windows updates, the script enables and
  276. echo ^ ^ ^ ^ starts only the Windows Update Service, then runs the Windows update Manager
  277. echo ^ ^ ^ ^ (WuMgr) or the Windows Update MiniTool (WUMT) to find and then hide or install
  278. echo ^ ^ ^ ^ selected Windows updates. If you run WUMT, don't change WUMT settings while
  279. echo ^ ^ ^ ^ running this script. If WuMgr or WUMT is offering updates, you need to hide or
  280. echo ^ ^ ^ ^ install them before closing WuMgr or WUMT.
  281. echo.
  282. echo ^ * ^ After checking for updates, the script stops and disables the Windows Update service
  283. echo ^ ^ ^ ^ when WuMgr or WUMT is closed whether or not the service was previously enabled.
  284. echo.
  285. echo ^ * ^ If you choose to use the Store, you can enable update service in Configurator.
  286. echo ^ ^ ^ ^ After using the Store, then either 1) disable update service or 2) continue script to
  287. echo ^ ^ ^ ^ check for Windows updates with WuMgr or WUMT after which the update service will be
  288. echo ^ ^ ^ ^ disabled.
  289. echo.
  290. echo ^ * ^ If you move this script to another folder run it again so the tasks will work!
  291. echo.
  292. echo ^ * ^ The included uninstaller undoes script changes.
  293. echo.&echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ---^>^>^> Press any key to continue. ^<^<^<---
  294. pause > nul
  295. ::::::::::::::::::::::::::::
  296. ::Internet connection check
  297. cls
  298. echo Internet check.
  299. ping 8.8.8.8 > nul
  300. cls
  301. if errorlevel 1 (echo.&echo Internet connection test failed. & echo ^(tested with ping to 8.8.8.8. Please report if this IP is unavailable in your area.^)&echo.&echo ---^>^>^> Press a key to continue if you're sure internet is working. ^<^<^<--- & echo.&echo It's safe to cancel now if needed. Your system will not be left in an unstable state.&echo ^(Ctrl-C, Alt-F4, or click "X" to cancel and exit^)) else (goto ContinePostInternetCheck)
  302. pause > nul
  303. :ContinePostInternetCheck
  304. ::::::::::::::::::::::::::::
  305. ::Windows Update Service Configurator
  306. cls
  307. echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  308. echo. & echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Initializing Configurator...
  309. ::disable windows update service except when wumt is run.
  310. :wudisable
  311. call :wuauserv d
  312. cls
  313. echo.&echo.&echo.
  314. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  315. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ : ^Windows 10 Update Control Wrapper Script Service Configurator ^:
  316. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  317. echo.&echo.&echo.
  318. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ---^>^>^> Windows Update Service is DISABLED and stopped ^(default^) ^<^<^<---
  319. echo.&echo.&echo. ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [E]nable Update Service temporarily to use Windows Store.
  320. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ or
  321. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [1] Continue script to run Windows Update Manager (WuMgr)
  322. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ and check for Windows Updates.
  323. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ or
  324. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [2] Continue script to run Windows Update Minitool (WUMT)
  325. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ and check for Windows Updates.
  326. echo.&
  327. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ The Windows Update service will be automatically
  328. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ started and stopped.
  329. echo.&
  330. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [Q]uit script, or "Alt + F4", or close window, if you're just
  331. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ verifying or are finished changing the update service setting.
  332. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ It stays how it's set above.
  333. echo.&echo.&echo.&echo.
  334. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Please select [E], [1], [2], or [Q] (or close window)
  335. echo.&echo.&echo.
  336. CHOICE /C E12Q /M "Your choice?:" >nul 2>&1
  337. if %errorlevel%==4 (exit)
  338. if %errorlevel%==3 (goto :StartWUMT)
  339. if %errorlevel%==2 (set "WuMgr=Y"&goto :StartWUMT)
  340. cls
  341. echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  342. echo.&echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Please wait while Windows Update Service is enabled...
  343. ::enable windows update service
  344. :wuenable
  345. call :wuauserv e
  346. echo.&echo.
  347. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  348. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ : ^Windows 10 Update Control Wrapper Script Service Configurator ^:
  349. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: &echo.&echo.
  350. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ---^>^>^> Windows Update Service is ENABLED ^(for Store^) ^<^<^<---
  351. echo.&echo.&echo. ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [D]isable Update Service when finished using Store.
  352. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ or
  353. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [1] Continue script to run Windows Update Manager (WuMgr)
  354. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ and check for Windows Updates.
  355. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ or
  356. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ [2] Continue script to run Windows Update Minitool (WUMT)
  357. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ and check for Windows Updates.
  358. echo.
  359. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ *Update service will be disabled automatically after
  360. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ update check and WUMT/WuMgr is closed.*
  361. echo.&echo.&echo.&echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Please select [D], [1], or [2]
  362. echo.&echo.&echo.&echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  363. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :^ Don't close this window or update service will stay on!!!^ :
  364. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ : ^ ^ Don't worry. Just run the script again to turn it off ^ ^ :
  365. echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
  366. CHOICE /C D12 /M "Your choice?:" >nul 2>&1
  367. if %errorlevel%==3 (goto :StartWUMT)
  368. if %errorlevel%==2 (set "WuMgr=Y"&goto :StartWUMT)
  369. if %errorlevel%==1 (
  370. cls
  371. echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.&echo.
  372. echo.&echo ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ Please wait while Windows Update Service is disabled...
  373. goto wudisable
  374. )
  375. ::::::::::::::::::::::::::::
  376. :create_task
  377. set "w=echo f.writeline "
  378. echo Set Fso=CreateObject^("Scripting.FileSystemObject"^):Set f=Fso.CreateTextFile^(fso.GetParentFolderName^(WScript.ScriptFullName^) ^& "\task.xml",True,True^)>task.vbs
  379. if /i %1==wdu (
  380. rem Create automatic Windows Defender Update "WDU" task that updates Defender only if it's enabled and running.
  381. rem Create WDU.xml
  382. rem
  383. rem
  384. rem Creating Windows Defender Update auto renewal task
  385. rem
  386. (
  387. %w%"<?xml version=""1.0"" encoding=""UTF-16""?>"
  388. %w%"<Task version=""1.2"" xmlns=""http://schemas.microsoft.com/windows/2004/02/mit/task"">"
  389. %w%"<RegistrationInfo>"
  390. %w%"<Date>2016-02-18T08:29:39</Date>"
  391. %w%"<Author>pf100\rpo</Author>"
  392. %w%"<URI>WindowsDefenderUpdate</URI>"
  393. %w%"</RegistrationInfo>"
  394. %w%"<Triggers>"
  395. %w%"<CalendarTrigger>"
  396. %w%"<StartBoundary>2016-01-01T00:01:00</StartBoundary>"
  397. %w%"<Enabled>true</Enabled>"
  398. %w%"<ScheduleByDay>"
  399. %w%"<DaysInterval>1</DaysInterval>"
  400. %w%"</ScheduleByDay>"
  401. %w%"</CalendarTrigger>"
  402. %w%"<CalendarTrigger>"
  403. %w%"<StartBoundary>2016-01-01T06:01:00</StartBoundary>"
  404. %w%"<Enabled>true</Enabled>"
  405. %w%"<ScheduleByDay>"
  406. %w%"<DaysInterval>1</DaysInterval>"
  407. %w%"</ScheduleByDay>"
  408. %w%"</CalendarTrigger>"
  409. %w%"<CalendarTrigger>"
  410. %w%"<StartBoundary>2016-01-01T12:01:00</StartBoundary>"
  411. %w%"<Enabled>true</Enabled>"
  412. %w%"<ScheduleByDay>"
  413. %w%"<DaysInterval>1</DaysInterval>"
  414. %w%"</ScheduleByDay>"
  415. %w%"</CalendarTrigger>"
  416. %w%"<CalendarTrigger>"
  417. %w%"<StartBoundary>2016-01-01T18:01:00</StartBoundary>"
  418. %w%"<Enabled>true</Enabled>"
  419. %w%"<ScheduleByDay>"
  420. %w%"<DaysInterval>1</DaysInterval>"
  421. %w%"</ScheduleByDay>"
  422. %w%"</CalendarTrigger>"
  423. %w%"<BootTrigger>"
  424. %w%"<Enabled>true</Enabled>"
  425. %w%"<Delay>PT10M</Delay>"
  426. %w%"</BootTrigger>"
  427. %w%"</Triggers>"
  428. %w%"<Principals>"
  429. %w%"<Principal id=""Author"">"
  430. %w%"<UserId>S-1-5-18</UserId>"
  431. %w%"<RunLevel>HighestAvailable</RunLevel>"
  432. %w%"</Principal>"
  433. %w%"</Principals>"
  434. %w%"<Settings>"
  435. %w%"<MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>"
  436. %w%"<DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>"
  437. %w%"<StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>"
  438. %w%"<AllowHardTerminate>true</AllowHardTerminate>"
  439. %w%"<StartWhenAvailable>false</StartWhenAvailable>"
  440. %w%"<RunOnlyIfNetworkAvailable>true</RunOnlyIfNetworkAvailable>"
  441. %w%"<IdleSettings>"
  442. %w%"<StopOnIdleEnd>false</StopOnIdleEnd>"
  443. %w%"<RestartOnIdle>false</RestartOnIdle>"
  444. %w%"</IdleSettings>"
  445. %w%"<AllowStartOnDemand>true</AllowStartOnDemand>"
  446. %w%"<Enabled>true</Enabled>"
  447. %w%"<Hidden>false</Hidden>"
  448. %w%"<RunOnlyIfIdle>false</RunOnlyIfIdle>"
  449. %w%"<WakeToRun>false</WakeToRun>"
  450. %w%"<ExecutionTimeLimit>P3D</ExecutionTimeLimit>"
  451. %w%"<Priority>7</Priority>"
  452. %w%"</Settings>"
  453. %w%"<Actions Context=""Author"">"
  454. %w%"<Exec>"
  455. %w%"<Command>""" ^& FSO.GetParentFolderName^(Wscript.ScriptFullName^) ^& "\WDU.cmd" ^& """</Command>"
  456. %w%"</Exec>"
  457. %w%"</Actions>"
  458. %w%"</Task>"
  459. )>>task.vbs
  460. )
  461. if /i %1==wub_task (
  462. rem
  463. rem Create Windows Update Blocker "Wub_task" that sets your desired Windows Update service state at boot.
  464. rem
  465. rem Create Wub_task
  466. rem
  467. rem
  468. (
  469. %w%"<?xml version=""1.0"" encoding=""UTF-16""?>"
  470. %w%"<Task version=""1.2"" xmlns=""http://schemas.microsoft.com/windows/2004/02/mit/task"">"
  471. %w%"<RegistrationInfo>"
  472. %w%"<Date>2016-02-18T08:29:39</Date>"
  473. %w%"<Author>pf100\rpo</Author>"
  474. %w%"<URI>\wub_task</URI>"
  475. %w%"</RegistrationInfo>"
  476. %w%"<Triggers>"
  477. %w%"<BootTrigger>"
  478. %w%"<Enabled>true</Enabled>"
  479. %w%"</BootTrigger>"
  480. %w%"<LogonTrigger>"
  481. %w%"<Enabled>true</Enabled>"
  482. %w%"</LogonTrigger>"
  483. %w%"</Triggers>"
  484. %w%"<Principals>"
  485. %w%"<Principal id=""Author"">"
  486. %w%"<RunLevel>HighestAvailable</RunLevel>"
  487. %w%"</Principal>"
  488. %w%"</Principals>"
  489. %w%"<Settings>"
  490. %w%"<MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>"
  491. %w%"<DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>"
  492. %w%"<StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>"
  493. %w%"<AllowHardTerminate>true</AllowHardTerminate>"
  494. %w%"<StartWhenAvailable>true</StartWhenAvailable>"
  495. %w%"<RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>"
  496. %w%"<IdleSettings>"
  497. %w%"<StopOnIdleEnd>false</StopOnIdleEnd>"
  498. %w%"<RestartOnIdle>false</RestartOnIdle>"
  499. %w%"</IdleSettings>"
  500. %w%"<AllowStartOnDemand>true</AllowStartOnDemand>"
  501. %w%"<Enabled>true</Enabled>"
  502. %w%"<Hidden>false</Hidden>"
  503. %w%"<RunOnlyIfIdle>false</RunOnlyIfIdle>"
  504. %w%"<WakeToRun>false</WakeToRun>"
  505. %w%"<ExecutionTimeLimit>PT72H</ExecutionTimeLimit>"
  506. %w%"<Priority>7</Priority>"
  507. %w%"</Settings>"
  508. %w%"<Actions Context=""Author"">"
  509. %w%"<Exec>"
  510. %w%"<Command>""" ^& FSO.GetParentFolderName^(Wscript.ScriptFullName^) ^& "\Wub.exe""</Command>"
  511. %w%"<Arguments>/d /p</Arguments>"
  512. %w%"</Exec>"
  513. %w%"</Actions>"
  514. %w%"</Task>"
  515. )>>task.vbs
  516. )
  517. echo f.Close>>task.vbs & task.vbs
  518. ::
  519. schtasks /delete /tn "%1" /f >nul 2>&1
  520. schtasks /create /tn "\Microsoft\WuWrapperScript\%1" /ru "SYSTEM" /xml task.xml /F >nul 2>&1 || (
  521. cls&echo.&echo Creating %2 %1 task errored.&echo.&echo.&echo Press any key to exit... & pause > nul &exit)
  522. del task.vbs task.xml >nul 2>&1
  523. exit /b
  524. ::::::::::::::::::::::::::::
  525. :wuauserv
  526. if /i "%1"=="e" (set "wub=wub.exe /e" & set "status=True") else (set "wub=wub.exe /d /p" & set "status=False")
  527. timeout -t 1 > nul
  528. %wub%
  529. set /a "max_retry=10" & set /a "i=0"
  530. :wuauserv1
  531. if %i%==%max_retry% (echo Operation did not complete within %max_retry% s. Press any key do exit...&pause>nul&exit)
  532. set /a "i+=1"
  533. WMIC Service WHERE "Name = 'Wuauserv'" GET Started | find /i "%status%" >nul && exit /b || (timeout /t 1 >nul & goto :wuauserv1)
  534. ::::::::::::::::::::::::::::
  535. :StartWUMT
  536. cls
  537. (
  538. echo @echo off
  539. echo :loop
  540. echo net start wuauserv
  541. echo timeout /t 10
  542. echo goto loop
  543. )>WU-keep-alive.cmd
  544. (
  545. echo @echo off
  546. echo cd /d "%%~dp0"
  547. echo del WU-keep-alive.cmd
  548. echo wub.exe /d /p
  549. echo del close.cmd ^& exit
  550. )>close.cmd
  551. if not defined WuMgr (
  552. set check_updates="%wumt%" -update "-onclose close.cmd"
  553. ) else (
  554. set check_updates=wumgr.exe -update -online 7971f918-a847-4430-9279-4a52d1efe18d -provisioned -onclose close.cmd)
  555. call :wuauserv e
  556. echo CreateObject^("WScript.Shell"^).Run "WU-keep-alive.cmd",0 >WU-keep-alive.vbs&WU-keep-alive.vbs&del WU-keep-alive.vbs
  557. Start "" %check_updates%
  558. exit
Advertisement
Add Comment
Please, Sign In to add comment