Skip to content

Commit

Permalink
12.6.4 source code.
Browse files Browse the repository at this point in the history
  • Loading branch information
Ionuț Bara committed Jan 4, 2024
1 parent ecedbd4 commit 5e146c0
Show file tree
Hide file tree
Showing 3 changed files with 65 additions and 144 deletions.
52 changes: 26 additions & 26 deletions Remover/DDL.txt
Original file line number Diff line number Diff line change
@@ -1,26 +1,26 @@
C:\Program Files (x86)\Windows Defender
C:\Program Files (x86)\Windows Defender Advanced Threat Protection
C:\Program Files\Windows Defender
C:\Program Files\Windows Defender Advanced Threat Protection
C:\ProgramData\Microsoft\Windows Defender
C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection
C:\ProgramData\Microsoft\Windows Security Health
C:\WINDOWS\System32\drivers\wd
C:\Windows\GameBarPresenceWriter
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\Defender
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\DefenderPerformance
C:\Windows\System32\HealthAttestationClient
C:\Windows\System32\SecurityHealth
C:\Windows\System32\Sgrm
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Defender
C:\Windows\System32\Tasks_Migrated\Microsoft\Windows\Windows Defender
C:\Windows\System32\WebThreatDefSvc
C:\Windows\System32\WindowsPowerShell\v1.0\Modules\Defender
C:\Windows\System32\WindowsPowerShell\v1.0\Modules\DefenderPerformance
C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy
C:\Windows\WinSxS\amd64_security-octagon*
C:\Windows\WinSxS\amd64_windows-defender*
C:\Windows\WinSxS\wow64_windows-defender*
C:\Windows\WinSxS\x86_windows-defender*
C:\Windows\bcastdvr
C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy
"C:\Program Files (x86)\Windows Defender"
"C:\Program Files (x86)\Windows Defender Advanced Threat Protection"
"C:\Program Files\Windows Defender"
"C:\Program Files\Windows Defender Advanced Threat Protection"
"C:\ProgramData\Microsoft\Windows Defender"
"C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection"
"C:\ProgramData\Microsoft\Windows Security Health"
"C:\WINDOWS\System32\drivers\wd"
"C:\Windows\GameBarPresenceWriter"
"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\Defender"
"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\DefenderPerformance"
"C:\Windows\System32\HealthAttestationClient"
"C:\Windows\System32\SecurityHealth"
"C:\Windows\System32\Sgrm"
"C:\Windows\System32\Tasks\Microsoft\Windows\Windows Defender"
"C:\Windows\System32\Tasks_Migrated\Microsoft\Windows\Windows Defender"
"C:\Windows\System32\WebThreatDefSvc"
"C:\Windows\System32\WindowsPowerShell\v1.0\Modules\Defender"
"C:\Windows\System32\WindowsPowerShell\v1.0\Modules\DefenderPerformance"
"C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy"
"C:\Windows\WinSxS\amd64_security-octagon*"
"C:\Windows\WinSxS\amd64_windows-defender*"
"C:\Windows\WinSxS\wow64_windows-defender*"
"C:\Windows\WinSxS\x86_windows-defender*"
"C:\Windows\bcastdvr"
"C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy"
70 changes: 35 additions & 35 deletions Remover/FDL.txt
Original file line number Diff line number Diff line change
@@ -1,35 +1,35 @@
C:\Windows\SysWOW64\CompatTelRunner.exe
C:\Windows\SysWOW64\DeviceCensus.exe
C:\Windows\SysWOW64\GameBarPresenceWriter.exe
C:\Windows\SysWOW64\smartscreen.dll
C:\Windows\SysWOW64\smartscreen.exe
C:\Windows\System32\DWWIN.EXE
C:\Windows\System32\GameBarPresenceWriter.exe
C:\Windows\System32\SecurityAndMaintenance.png
C:\Windows\System32\SecurityAndMaintenance_Error.png
C:\Windows\System32\SecurityHealthAgent.dll
C:\Windows\System32\SecurityHealthCore.dll
C:\Windows\System32\SecurityHealthHost.exe
C:\Windows\System32\SecurityHealthProxyStub.dll
C:\Windows\System32\SecurityHealthService.exe
C:\Windows\System32\SecurityHealthSsoUdk.dll
C:\Windows\System32\SecurityHealthSystray.exe
C:\Windows\System32\SecurityHealthUdk.dll
C:\Windows\System32\drivers\SgrmAgent.sys
C:\Windows\System32\drivers\WdBoot.sys
C:\Windows\System32\drivers\WdDevFlt.sys
C:\Windows\System32\drivers\WdFilter.sys
C:\Windows\System32\drivers\WdNisDrv.sys
C:\Windows\system32\drivers\msseccore.sys
C:\Windows\System32\smartscreen.dll
C:\Windows\System32\smartscreen.exe
C:\Windows\System32\wscadminui.exe
C:\Windows\System32\wscapi.dll
C:\Windows\System32\wscisvif.dll
C:\Windows\System32\wscproxystub.dll
C:\Windows\System32\wscsvc.dll
C:\Windows\Containers\WindowsDefenderApplicationGuard.wim
C:\Windows\Containers\serviced\WindowsDefenderApplicationGuard.wim
C:\Windows\WinSxS\FileMaps\amd64_windows-defender*.manifest
C:\Windows\WinSxS\FileMaps\wow64_windows-defender*.manifest
C:\Windows\WinSxS\FileMaps\x86_windows-defender*.manifest
"C:\Windows\SysWOW64\CompatTelRunner.exe"
"C:\Windows\SysWOW64\DeviceCensus.exe"
"C:\Windows\SysWOW64\GameBarPresenceWriter.exe"
"C:\Windows\SysWOW64\smartscreen.dll"
"C:\Windows\SysWOW64\smartscreen.exe"
"C:\Windows\System32\DWWIN.EXE"
"C:\Windows\System32\GameBarPresenceWriter.exe"
"C:\Windows\System32\SecurityAndMaintenance.png"
"C:\Windows\System32\SecurityAndMaintenance_Error.png"
"C:\Windows\System32\SecurityHealthAgent.dll"
"C:\Windows\System32\SecurityHealthCore.dll"
"C:\Windows\System32\SecurityHealthHost.exe"
"C:\Windows\System32\SecurityHealthProxyStub.dll"
"C:\Windows\System32\SecurityHealthService.exe"
"C:\Windows\System32\SecurityHealthSsoUdk.dll"
"C:\Windows\System32\SecurityHealthSystray.exe"
"C:\Windows\System32\SecurityHealthUdk.dll"
"C:\Windows\System32\drivers\SgrmAgent.sys"
"C:\Windows\System32\drivers\WdBoot.sys"
"C:\Windows\System32\drivers\WdDevFlt.sys"
"C:\Windows\System32\drivers\WdFilter.sys"
"C:\Windows\System32\drivers\WdNisDrv.sys"
"C:\Windows\system32\drivers\msseccore.sys"
"C:\Windows\System32\smartscreen.dll"
"C:\Windows\System32\smartscreen.exe"
"C:\Windows\System32\wscadminui.exe"
"C:\Windows\System32\wscapi.dll"
"C:\Windows\System32\wscisvif.dll"
"C:\Windows\System32\wscproxystub.dll"
"C:\Windows\System32\wscsvc.dll"
"C:\Windows\Containers\WindowsDefenderApplicationGuard.wim"
"C:\Windows\Containers\serviced\WindowsDefenderApplicationGuard.wim"
"C:\Windows\WinSxS\FileMaps\amd64_windows-defender*.manifest"
"C:\Windows\WinSxS\FileMaps\wow64_windows-defender*.manifest"
"C:\Windows\WinSxS\FileMaps\x86_windows-defender*.manifest"
87 changes: 4 additions & 83 deletions Script_Run.bat
Original file line number Diff line number Diff line change
Expand Up @@ -6,34 +6,21 @@ IF "%1"== "/y" GOTO :removedef
IF "%1"== "/Y" GOTO :removedef
IF "%1"== "/N" GOTO :tweaksdef
IF "%1"== "/n" GOTO :tweaksdef
IF "%1"== "/e" GOTO :enabledefanti
IF "%1"== "/E" GOTO :enabledefanti
IF "%1"== "/M" GOTO :tweaksdefanti
IF "%1"== "/m" GOTO :tweaksdefanti
IF "%1"== "/R" GOTO :enabledef
IF "%1"== "/r" GOTO :enabledef
:--------------------------------------

:--------------------------------------
:menu
cls
echo ------Defender Remover Script , version 12.6------
echo ------Defender Remover Script , version 12.6.4------
echo Select an option:
echo.
echo Press (Y) for removing Defender and Security Components (old method, breaking Windows Updates/UWP in some version of Windows, removes files and unregisters classes)
echo Press (N) for disabling Defender and Security Components (safe)
echo Press (M) for disabling Defender Antivirus only (safe)
echo Press (E) for enabling Defender (restore actions where M is pressed)
echo Press (R) for enabling Defender and Security Components (restore actions where N is pressed)
echo.
echo Press (Y) for removing Defender and Security Components (old method, breaking Windows Updates/UWP in some version of Windows, removes files and unregisters classes) (working for new method)
echo Press (N) for toggle Defender and Security Components with Safe Method.
set /P c=Select one of the options to continue:

:: Check if the input is one of the valid keys
if /I "%c%" EQU "Y" goto :removedef
if /I "%c%" EQU "N" goto :tweaksdef
if /I "%c%" EQU "E" goto :enabledefanti
if /I "%c%" EQU "M" goto :tweaksdefanti
if /I "%c%" EQU "R" goto :enabledef

:: If none of the valid keys are pressed, do nothing
goto :eof
Expand All @@ -44,9 +31,6 @@ cls
echo Killing Tasks...
for /f "delims=" %%i in (Remover\TKL.txt) do (GetTrustedInstaller.exe "C:\Windows\System32\taskkill.exe /f /im ""%%i""") >nul
cls
echo Removing Windows Security UWP...
for /d %%f in ("C:\Program Files\WindowsApps\Microsoft.SecHealthUI*") do (GetTrustedInstaller.exe "C:\Windows\System32\cmd.exe /k rmdir /s /q ""%%f""") >nul
cls
echo Applying Registry Files...
for /r %%k in (Remover\REGS\*.reg) do (GetTrustedInstaller.exe "C:\Windows\regedit.exe /s ""%%k""") >nul
cls
Expand All @@ -61,70 +45,7 @@ goto :eof
:--------------------------------------

:tweaksdef
if "%SAFEBOOT_OPTION%"=="" goto error
CLS & echo Disable Defender and Security Components...
:: Disable Defender's Scheduled Tasks
GetTrustedInstaller.exe cmd.exe /k "schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Disable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Disable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Disable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Disable"
GetTrustedInstaller.exe regedit.exe /s "DisablerS\Disable.reg" >nul
GetTrustedInstaller.exe cmd.exe /k move /y "C:\Windows\System32\smartscreen.exe" "C:\Windows\System32\smartscreen.plm"
cls & echo Antivirus and Security Components Disabled. A reboot is needed!
echo To exit from safe mode you must open an cmd and write this command and reboot.
echo bcdedit /deletevalue {default} safeboot
pause
goto :eof
:--------------------------------------

:--------------------------------------
:enabledef
if "%SAFEBOOT_OPTION%"=="" goto error
CLS & echo Enable Defender and Security Components...
:: Enable Defender's Scheduled Tasks
GetTrustedInstaller.exe cmd.exe /k "schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Enable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Enable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Enable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Enable"
GetTrustedInstaller.exe regedit.exe /s "DisablerS\Enable.reg"
GetTrustedInstaller.exe cmd.exe /k move /y "C:\Windows\System32\smartscreen.plm" "C:\Windows\System32\smartscreen.exe"
cls & echo Antivirus and Windows Security Components Enabled. A reboot is needed!
echo To exit from safe mode you must open an cmd and write this command and reboot.
echo bcdedit /deletevalue {default} safeboot
pause
goto :eof
:--------------------------------------

:--------------------------------------
:tweaksdefanti
if "%SAFEBOOT_OPTION%"=="" goto error
CLS & echo Disabling Defender...
:: Disable Defender's Scheduled Tasks
GetTrustedInstaller.exe cmd.exe /k "schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Disable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Disable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Disable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Disable"
GetTrustedInstaller.exe regedit.exe /s "Disabler\Disable.reg" >nul
GetTrustedInstaller.exe cmd.exe /k move /y "C:\Windows\System32\smartscreen.exe" "C:\Windows\System32\smartscreen.plm"
cls & echo Antivirus disabled. A reboot is needed!
echo To exit from safe mode you must open an cmd and write this command and reboot.
echo bcdedit /deletevalue {default} safeboot
pause
goto :eof
:--------------------------------------

:--------------------------------------
:enabledefanti
if "%SAFEBOOT_OPTION%"=="" goto error
CLS & echo Enable Defender...
:: Enable Defender's Scheduled Tasks
GetTrustedInstaller.exe cmd.exe /k "schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Enable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Enable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Enable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Enable"
GetTrustedInstaller.exe regedit.exe /s "Disabler\Enable.reg"
GetTrustedInstaller.exe cmd.exe /k move /y "C:\Windows\System32\smartscreen.plm" "C:\Windows\System32\smartscreen.exe"
echo To exit from safe mode you must open an cmd and write this command and reboot.
echo bcdedit /deletevalue {default} safeboot
shutdown /r /f /t 0
:--------------------------------------

:--------------------------------------
:error
echo To disable/enable Windows Defender you MUST to be in Safe Mode. Go to CMD and run this command and reboot.
echo bcdedit /set {current} safeboot minimal
pause
exit
:--------------------------------------

"Safe_Method.bat"

:--------------------------------------
:eof
Expand Down

0 comments on commit 5e146c0

Please sign in to comment.