Skip to content

Commit 5e146c0

Browse files
author
Ionuț Bara
committed
12.6.4 source code.
1 parent ecedbd4 commit 5e146c0

File tree

3 files changed

+65
-144
lines changed

3 files changed

+65
-144
lines changed

Remover/DDL.txt

Lines changed: 26 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -1,26 +1,26 @@
1-
C:\Program Files (x86)\Windows Defender
2-
C:\Program Files (x86)\Windows Defender Advanced Threat Protection
3-
C:\Program Files\Windows Defender
4-
C:\Program Files\Windows Defender Advanced Threat Protection
5-
C:\ProgramData\Microsoft\Windows Defender
6-
C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection
7-
C:\ProgramData\Microsoft\Windows Security Health
8-
C:\WINDOWS\System32\drivers\wd
9-
C:\Windows\GameBarPresenceWriter
10-
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\Defender
11-
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\DefenderPerformance
12-
C:\Windows\System32\HealthAttestationClient
13-
C:\Windows\System32\SecurityHealth
14-
C:\Windows\System32\Sgrm
15-
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Defender
16-
C:\Windows\System32\Tasks_Migrated\Microsoft\Windows\Windows Defender
17-
C:\Windows\System32\WebThreatDefSvc
18-
C:\Windows\System32\WindowsPowerShell\v1.0\Modules\Defender
19-
C:\Windows\System32\WindowsPowerShell\v1.0\Modules\DefenderPerformance
20-
C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy
21-
C:\Windows\WinSxS\amd64_security-octagon*
22-
C:\Windows\WinSxS\amd64_windows-defender*
23-
C:\Windows\WinSxS\wow64_windows-defender*
24-
C:\Windows\WinSxS\x86_windows-defender*
25-
C:\Windows\bcastdvr
26-
C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy
1+
"C:\Program Files (x86)\Windows Defender"
2+
"C:\Program Files (x86)\Windows Defender Advanced Threat Protection"
3+
"C:\Program Files\Windows Defender"
4+
"C:\Program Files\Windows Defender Advanced Threat Protection"
5+
"C:\ProgramData\Microsoft\Windows Defender"
6+
"C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection"
7+
"C:\ProgramData\Microsoft\Windows Security Health"
8+
"C:\WINDOWS\System32\drivers\wd"
9+
"C:\Windows\GameBarPresenceWriter"
10+
"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\Defender"
11+
"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\DefenderPerformance"
12+
"C:\Windows\System32\HealthAttestationClient"
13+
"C:\Windows\System32\SecurityHealth"
14+
"C:\Windows\System32\Sgrm"
15+
"C:\Windows\System32\Tasks\Microsoft\Windows\Windows Defender"
16+
"C:\Windows\System32\Tasks_Migrated\Microsoft\Windows\Windows Defender"
17+
"C:\Windows\System32\WebThreatDefSvc"
18+
"C:\Windows\System32\WindowsPowerShell\v1.0\Modules\Defender"
19+
"C:\Windows\System32\WindowsPowerShell\v1.0\Modules\DefenderPerformance"
20+
"C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy"
21+
"C:\Windows\WinSxS\amd64_security-octagon*"
22+
"C:\Windows\WinSxS\amd64_windows-defender*"
23+
"C:\Windows\WinSxS\wow64_windows-defender*"
24+
"C:\Windows\WinSxS\x86_windows-defender*"
25+
"C:\Windows\bcastdvr"
26+
"C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy"

Remover/FDL.txt

Lines changed: 35 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -1,35 +1,35 @@
1-
C:\Windows\SysWOW64\CompatTelRunner.exe
2-
C:\Windows\SysWOW64\DeviceCensus.exe
3-
C:\Windows\SysWOW64\GameBarPresenceWriter.exe
4-
C:\Windows\SysWOW64\smartscreen.dll
5-
C:\Windows\SysWOW64\smartscreen.exe
6-
C:\Windows\System32\DWWIN.EXE
7-
C:\Windows\System32\GameBarPresenceWriter.exe
8-
C:\Windows\System32\SecurityAndMaintenance.png
9-
C:\Windows\System32\SecurityAndMaintenance_Error.png
10-
C:\Windows\System32\SecurityHealthAgent.dll
11-
C:\Windows\System32\SecurityHealthCore.dll
12-
C:\Windows\System32\SecurityHealthHost.exe
13-
C:\Windows\System32\SecurityHealthProxyStub.dll
14-
C:\Windows\System32\SecurityHealthService.exe
15-
C:\Windows\System32\SecurityHealthSsoUdk.dll
16-
C:\Windows\System32\SecurityHealthSystray.exe
17-
C:\Windows\System32\SecurityHealthUdk.dll
18-
C:\Windows\System32\drivers\SgrmAgent.sys
19-
C:\Windows\System32\drivers\WdBoot.sys
20-
C:\Windows\System32\drivers\WdDevFlt.sys
21-
C:\Windows\System32\drivers\WdFilter.sys
22-
C:\Windows\System32\drivers\WdNisDrv.sys
23-
C:\Windows\system32\drivers\msseccore.sys
24-
C:\Windows\System32\smartscreen.dll
25-
C:\Windows\System32\smartscreen.exe
26-
C:\Windows\System32\wscadminui.exe
27-
C:\Windows\System32\wscapi.dll
28-
C:\Windows\System32\wscisvif.dll
29-
C:\Windows\System32\wscproxystub.dll
30-
C:\Windows\System32\wscsvc.dll
31-
C:\Windows\Containers\WindowsDefenderApplicationGuard.wim
32-
C:\Windows\Containers\serviced\WindowsDefenderApplicationGuard.wim
33-
C:\Windows\WinSxS\FileMaps\amd64_windows-defender*.manifest
34-
C:\Windows\WinSxS\FileMaps\wow64_windows-defender*.manifest
35-
C:\Windows\WinSxS\FileMaps\x86_windows-defender*.manifest
1+
"C:\Windows\SysWOW64\CompatTelRunner.exe"
2+
"C:\Windows\SysWOW64\DeviceCensus.exe"
3+
"C:\Windows\SysWOW64\GameBarPresenceWriter.exe"
4+
"C:\Windows\SysWOW64\smartscreen.dll"
5+
"C:\Windows\SysWOW64\smartscreen.exe"
6+
"C:\Windows\System32\DWWIN.EXE"
7+
"C:\Windows\System32\GameBarPresenceWriter.exe"
8+
"C:\Windows\System32\SecurityAndMaintenance.png"
9+
"C:\Windows\System32\SecurityAndMaintenance_Error.png"
10+
"C:\Windows\System32\SecurityHealthAgent.dll"
11+
"C:\Windows\System32\SecurityHealthCore.dll"
12+
"C:\Windows\System32\SecurityHealthHost.exe"
13+
"C:\Windows\System32\SecurityHealthProxyStub.dll"
14+
"C:\Windows\System32\SecurityHealthService.exe"
15+
"C:\Windows\System32\SecurityHealthSsoUdk.dll"
16+
"C:\Windows\System32\SecurityHealthSystray.exe"
17+
"C:\Windows\System32\SecurityHealthUdk.dll"
18+
"C:\Windows\System32\drivers\SgrmAgent.sys"
19+
"C:\Windows\System32\drivers\WdBoot.sys"
20+
"C:\Windows\System32\drivers\WdDevFlt.sys"
21+
"C:\Windows\System32\drivers\WdFilter.sys"
22+
"C:\Windows\System32\drivers\WdNisDrv.sys"
23+
"C:\Windows\system32\drivers\msseccore.sys"
24+
"C:\Windows\System32\smartscreen.dll"
25+
"C:\Windows\System32\smartscreen.exe"
26+
"C:\Windows\System32\wscadminui.exe"
27+
"C:\Windows\System32\wscapi.dll"
28+
"C:\Windows\System32\wscisvif.dll"
29+
"C:\Windows\System32\wscproxystub.dll"
30+
"C:\Windows\System32\wscsvc.dll"
31+
"C:\Windows\Containers\WindowsDefenderApplicationGuard.wim"
32+
"C:\Windows\Containers\serviced\WindowsDefenderApplicationGuard.wim"
33+
"C:\Windows\WinSxS\FileMaps\amd64_windows-defender*.manifest"
34+
"C:\Windows\WinSxS\FileMaps\wow64_windows-defender*.manifest"
35+
"C:\Windows\WinSxS\FileMaps\x86_windows-defender*.manifest"

Script_Run.bat

Lines changed: 4 additions & 83 deletions
Original file line numberDiff line numberDiff line change
@@ -6,34 +6,21 @@ IF "%1"== "/y" GOTO :removedef
66
IF "%1"== "/Y" GOTO :removedef
77
IF "%1"== "/N" GOTO :tweaksdef
88
IF "%1"== "/n" GOTO :tweaksdef
9-
IF "%1"== "/e" GOTO :enabledefanti
10-
IF "%1"== "/E" GOTO :enabledefanti
11-
IF "%1"== "/M" GOTO :tweaksdefanti
12-
IF "%1"== "/m" GOTO :tweaksdefanti
13-
IF "%1"== "/R" GOTO :enabledef
14-
IF "%1"== "/r" GOTO :enabledef
159
:--------------------------------------
1610

1711
:--------------------------------------
1812
:menu
1913
cls
20-
echo ------Defender Remover Script , version 12.6------
14+
echo ------Defender Remover Script , version 12.6.4------
2115
echo Select an option:
2216
echo.
23-
echo Press (Y) for removing Defender and Security Components (old method, breaking Windows Updates/UWP in some version of Windows, removes files and unregisters classes)
24-
echo Press (N) for disabling Defender and Security Components (safe)
25-
echo Press (M) for disabling Defender Antivirus only (safe)
26-
echo Press (E) for enabling Defender (restore actions where M is pressed)
27-
echo Press (R) for enabling Defender and Security Components (restore actions where N is pressed)
28-
echo.
17+
echo Press (Y) for removing Defender and Security Components (old method, breaking Windows Updates/UWP in some version of Windows, removes files and unregisters classes) (working for new method)
18+
echo Press (N) for toggle Defender and Security Components with Safe Method.
2919
set /P c=Select one of the options to continue:
3020

3121
:: Check if the input is one of the valid keys
3222
if /I "%c%" EQU "Y" goto :removedef
3323
if /I "%c%" EQU "N" goto :tweaksdef
34-
if /I "%c%" EQU "E" goto :enabledefanti
35-
if /I "%c%" EQU "M" goto :tweaksdefanti
36-
if /I "%c%" EQU "R" goto :enabledef
3724

3825
:: If none of the valid keys are pressed, do nothing
3926
goto :eof
@@ -44,9 +31,6 @@ cls
4431
echo Killing Tasks...
4532
for /f "delims=" %%i in (Remover\TKL.txt) do (GetTrustedInstaller.exe "C:\Windows\System32\taskkill.exe /f /im ""%%i""") >nul
4633
cls
47-
echo Removing Windows Security UWP...
48-
for /d %%f in ("C:\Program Files\WindowsApps\Microsoft.SecHealthUI*") do (GetTrustedInstaller.exe "C:\Windows\System32\cmd.exe /k rmdir /s /q ""%%f""") >nul
49-
cls
5034
echo Applying Registry Files...
5135
for /r %%k in (Remover\REGS\*.reg) do (GetTrustedInstaller.exe "C:\Windows\regedit.exe /s ""%%k""") >nul
5236
cls
@@ -61,70 +45,7 @@ goto :eof
6145
:--------------------------------------
6246

6347
:tweaksdef
64-
if "%SAFEBOOT_OPTION%"=="" goto error
65-
CLS & echo Disable Defender and Security Components...
66-
:: Disable Defender's Scheduled Tasks
67-
GetTrustedInstaller.exe cmd.exe /k "schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Disable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Disable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Disable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Disable"
68-
GetTrustedInstaller.exe regedit.exe /s "DisablerS\Disable.reg" >nul
69-
GetTrustedInstaller.exe cmd.exe /k move /y "C:\Windows\System32\smartscreen.exe" "C:\Windows\System32\smartscreen.plm"
70-
cls & echo Antivirus and Security Components Disabled. A reboot is needed!
71-
echo To exit from safe mode you must open an cmd and write this command and reboot.
72-
echo bcdedit /deletevalue {default} safeboot
73-
pause
74-
goto :eof
75-
:--------------------------------------
76-
77-
:--------------------------------------
78-
:enabledef
79-
if "%SAFEBOOT_OPTION%"=="" goto error
80-
CLS & echo Enable Defender and Security Components...
81-
:: Enable Defender's Scheduled Tasks
82-
GetTrustedInstaller.exe cmd.exe /k "schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Enable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Enable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Enable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Enable"
83-
GetTrustedInstaller.exe regedit.exe /s "DisablerS\Enable.reg"
84-
GetTrustedInstaller.exe cmd.exe /k move /y "C:\Windows\System32\smartscreen.plm" "C:\Windows\System32\smartscreen.exe"
85-
cls & echo Antivirus and Windows Security Components Enabled. A reboot is needed!
86-
echo To exit from safe mode you must open an cmd and write this command and reboot.
87-
echo bcdedit /deletevalue {default} safeboot
88-
pause
89-
goto :eof
90-
:--------------------------------------
91-
92-
:--------------------------------------
93-
:tweaksdefanti
94-
if "%SAFEBOOT_OPTION%"=="" goto error
95-
CLS & echo Disabling Defender...
96-
:: Disable Defender's Scheduled Tasks
97-
GetTrustedInstaller.exe cmd.exe /k "schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Disable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Disable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Disable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Disable"
98-
GetTrustedInstaller.exe regedit.exe /s "Disabler\Disable.reg" >nul
99-
GetTrustedInstaller.exe cmd.exe /k move /y "C:\Windows\System32\smartscreen.exe" "C:\Windows\System32\smartscreen.plm"
100-
cls & echo Antivirus disabled. A reboot is needed!
101-
echo To exit from safe mode you must open an cmd and write this command and reboot.
102-
echo bcdedit /deletevalue {default} safeboot
103-
pause
104-
goto :eof
105-
:--------------------------------------
106-
107-
:--------------------------------------
108-
:enabledefanti
109-
if "%SAFEBOOT_OPTION%"=="" goto error
110-
CLS & echo Enable Defender...
111-
:: Enable Defender's Scheduled Tasks
112-
GetTrustedInstaller.exe cmd.exe /k "schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Enable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Enable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Enable & schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Enable"
113-
GetTrustedInstaller.exe regedit.exe /s "Disabler\Enable.reg"
114-
GetTrustedInstaller.exe cmd.exe /k move /y "C:\Windows\System32\smartscreen.plm" "C:\Windows\System32\smartscreen.exe"
115-
echo To exit from safe mode you must open an cmd and write this command and reboot.
116-
echo bcdedit /deletevalue {default} safeboot
117-
shutdown /r /f /t 0
118-
:--------------------------------------
119-
120-
:--------------------------------------
121-
:error
122-
echo To disable/enable Windows Defender you MUST to be in Safe Mode. Go to CMD and run this command and reboot.
123-
echo bcdedit /set {current} safeboot minimal
124-
pause
125-
exit
126-
:--------------------------------------
127-
48+
"Safe_Method.bat"
12849

12950
:--------------------------------------
13051
:eof

0 commit comments

Comments
 (0)