mirror of
https://github.com/es3n1n/defendnot.git
synced 2026-10-01 10:01:36 +00:00
Compare commits
11 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
525176a377 | ||
|
|
192b2d798c | ||
|
|
0d15ea6666 | ||
|
|
2acdf7724a | ||
|
|
0c9be5724f | ||
|
|
a46fdf49ab | ||
|
|
2d0badd5cb | ||
|
|
2d34fcca9e | ||
|
|
77fdc18545 | ||
|
|
50cceeab75 | ||
|
|
5e4a32c819 |
3
.github/workflows/build.yml
vendored
3
.github/workflows/build.yml
vendored
@@ -13,7 +13,7 @@ permissions:
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: windows-latest
|
||||
runs-on: windows-2022
|
||||
strategy:
|
||||
matrix:
|
||||
platform: [x64, x86, ARM64]
|
||||
@@ -59,6 +59,7 @@ jobs:
|
||||
Copy-Item -Path ".\out\$mappedPlatform\defendnot.pdb" -Destination ".\artifacts\$platform\" -Verbose
|
||||
Copy-Item -Path ".\out\$mappedPlatform\defendnot-loader.exe" -Destination ".\artifacts\$platform\" -Verbose
|
||||
Copy-Item -Path ".\out\$mappedPlatform\defendnot-loader.pdb" -Destination ".\artifacts\$platform\" -Verbose
|
||||
Copy-Item -Path ".\extra-strip.bat" -Destination ".\artifacts\$platform\" -Verbose
|
||||
shell: pwsh
|
||||
|
||||
- name: Upload artifacts
|
||||
|
||||
65
README.md
65
README.md
@@ -1,24 +1,27 @@
|
||||
# defendnot
|
||||
|
||||
<img src="https://i.imgur.com/F9gWA92.png" align="right" width="50%"/>
|
||||
|
||||
An even funnier way to disable windows defender.
|
||||
|
||||
Defendnot is a successor of [no-defender](https://github.com/es3n1n/no-defender).
|
||||
|
||||

|
||||
|
||||
> [!CAUTION]
|
||||
> **Permitted Use Notice**:
|
||||
>
|
||||
> Using this tool to facilitate malware distribution, cybercrime, unauthorized access, evading detection, or any illegal activity is strictly prohibited.
|
||||
> Using this tool to facilitate malware distribution, or any illegal activity is strictly prohibited.
|
||||
>
|
||||
> Users assume all legal responsibility for how they use this tool and any consequences thereof. You must comply with all applicable local, state, federal, and international laws when using this tool.
|
||||
> Users assume all legal responsibility for how they use this tool and any consequences thereof. You must comply with all applicable laws when using this tool.
|
||||
>
|
||||
> By downloading, installing, or using this tool, you acknowledge that you have read, understood, and agree to these terms.
|
||||
> By downloading, installing, or using this tool, you acknowledge that you agree to these terms.
|
||||
|
||||
## Installation
|
||||
|
||||
> [!TIP]
|
||||
> You may need to temporarily disable realtime and tamper protection before proceeding, otherwise defender will block `defendnot` binaries due to the `VirTool:Win64/Defnot.A` detection.
|
||||
> [!WARNING]
|
||||
> You may need to temporarily disable realtime and tamper protection before proceeding, otherwise defender will block defendnot binaries from running.
|
||||
>
|
||||
> On newer Windows 11 builds you may also have to turn off Smart App Control.
|
||||
>
|
||||
> - Real-time protection: `windowsdefender://threatsettings/`
|
||||
> - Smart App Control: `windowsdefender://appbrowser/`
|
||||
|
||||
### One-liner
|
||||
|
||||
@@ -28,19 +31,19 @@ Open the powershell as administrator and execute any of these:
|
||||
# Example 1: Basic installation
|
||||
irm https://dnot.sh/ | iex
|
||||
|
||||
# Example 2: With custom AV name
|
||||
& ([ScriptBlock]::Create((irm https://dnot.sh/))) --name "Custom AV name"
|
||||
# Example 2: With custom AV name and firewall
|
||||
& ([ScriptBlock]::Create((irm https://dnot.sh/))) --name "Custom AV name" --firewall
|
||||
|
||||
# Example 3: Without allocating console
|
||||
& ([ScriptBlock]::Create((irm https://dnot.sh/))) --silent
|
||||
|
||||
# Example 4: Run once, without allocating console
|
||||
& ([ScriptBlock]::Create((irm https://dnot.sh/))) --silent --disable-autorun
|
||||
|
||||
# Example 5: Uninstall
|
||||
& ([ScriptBlock]::Create((irm https://dnot.sh/))) --disable
|
||||
```
|
||||
|
||||
> [!NOTE]
|
||||
> As seen in examples 2 and 3, you can pass the commandline arguments to the installer script and it will forward them to `defendnot-loader`. For reference what commandline arguments are allowed, see the `Usage` section below.
|
||||
|
||||
> [!NOTE]
|
||||
> You can also directly use the 'longer' version of installer script url, which is `https://raw.githubusercontent.com/es3n1n/defendnot/refs/heads/master/install.ps1`
|
||||
|
||||
### Manual
|
||||
|
||||
Download the [latest](https://github.com/es3n1n/defendnot/releases/latest) release, extract it somewhere and launch `defendnot-loader`.
|
||||
@@ -48,7 +51,7 @@ Download the [latest](https://github.com/es3n1n/defendnot/releases/latest) relea
|
||||
## Usage
|
||||
|
||||
```commandline
|
||||
Usage: defendnot-loader [--help] [--version] [--name VAR] [--disable] [--verbose] [--silent] [--autorun-as-user] [--disable-autorun]
|
||||
Usage: defendnot-loader [--help] [--version] [--name VAR] [--disable] [--verbose] [--firewall] [--silent] [--autorun-as-user] [--disable-autorun]
|
||||
|
||||
Optional arguments:
|
||||
-h, --help prints help message and exits
|
||||
@@ -56,38 +59,22 @@ Optional arguments:
|
||||
-n, --name av display name [default: "dnot.sh"]
|
||||
-d, --disable disable defendnot
|
||||
-v, --verbose verbose logging
|
||||
--firewall also register a fake firewall
|
||||
--silent do not allocate console
|
||||
--autorun-as-user create autorun task as currently logged in user
|
||||
--disable-autorun disable autorun task creation
|
||||
```
|
||||
|
||||
## How it works
|
||||
## Stripping Defender out further (optional)
|
||||
|
||||
There's a WSC (Windows Security Center) service in Windows which is used by antiviruses to let Windows know that there's some other antivirus in the hood and it should disable Windows Defender.
|
||||
This WSC API is undocumented and furthermore requires people to sign an NDA with Microsoft to get its documentation.
|
||||
defendnot only registers a fake AV through WSC, but if you want to strip more Defender stuff out, run the optional `extra-strip.bat` as admin after defendnot is active. It disables a bunch more Defender policies in registry: real-time monitoring, behavior monitoring, cloud reporting, signature updates, etc.
|
||||
|
||||
The initial implementation of [no-defender](https://github.com/es3n1n/no-defender) used thirdparty code provided by other AVs to register itself in the WSC, while `defendnot` interacts with WSC directly.
|
||||
It's a separate script because the keys are finicky and undoing them on `--disable` would mean saving every value first somewhere and writing all of them back, which is _waaay_ more bookkeeping than I feel like implementing.
|
||||
|
||||
## Limitations
|
||||
|
||||
- **Needs to stay on disk:**
|
||||
To keep the AV registration persistent after reboot, `defendnot` adds itself to autorun. That means the binaries have to remain on your system for the Defender "disable" to stick. (Yeah, I wish it were more elegant too.)
|
||||
|
||||
- **No support for Windows Server:**
|
||||
The Windows Security Center (WSC) service doesn’t exist on Windows Server editions, so `defendnot` *won’t* work there. See [#17](https://github.com/es3n1n/defendnot/issues/17).
|
||||
|
||||
- **Defender Detection:**
|
||||
Not surprisingly, Windows Defender really doesn’t like `defendnot` and will flag or remove it as `VirTool:Win64/Defnot.A`. You’ll need to (temporarily) disable Defender’s real-time and tamper protection to install.
|
||||
|
||||
## Legitimate Use Cases
|
||||
|
||||
- Reducing resource consumption in development environments
|
||||
- Testing system performance under different security configurations
|
||||
- Educational research on Windows security mechanisms
|
||||
- Home lab experimentation and learning
|
||||
|
||||
> [!IMPORTANT]
|
||||
> If your intended usage falls outside these legitimate use cases, support in issues/DMs might be denied without any further explanations.
|
||||
To keep the AV registration after reboot, defendnot adds itself to autorun.
|
||||
|
||||
## Writeup
|
||||
|
||||
|
||||
@@ -9,6 +9,8 @@
|
||||
#include <source_location>
|
||||
#include <stdexcept>
|
||||
|
||||
#define COM_CALLCONV __stdcall
|
||||
|
||||
namespace com {
|
||||
inline HRESULT checked(HRESULT result, const std::source_location loc = std::source_location::current()) {
|
||||
if (result == 0) {
|
||||
@@ -94,11 +96,11 @@ namespace com {
|
||||
static constexpr GUID kIID = IID;
|
||||
|
||||
private:
|
||||
virtual HRESULT QueryInterface() = 0;
|
||||
virtual std::uint32_t AddRef() = 0;
|
||||
virtual HRESULT COM_CALLCONV QueryInterface() = 0;
|
||||
virtual std::uint32_t COM_CALLCONV AddRef() = 0;
|
||||
|
||||
public:
|
||||
virtual std::uint32_t Release() = 0;
|
||||
virtual std::uint32_t COM_CALLCONV Release() = 0;
|
||||
};
|
||||
|
||||
template <typename Ty>
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
|
||||
#include "shared/util.hpp"
|
||||
|
||||
#pragma pack(push, 1)
|
||||
namespace shared {
|
||||
constexpr std::size_t kMaxNameLength = 128;
|
||||
constexpr std::string_view kCtxPath = "ctx.bin";
|
||||
@@ -28,6 +29,7 @@ namespace shared {
|
||||
State state = State::ON;
|
||||
bool verbose = false;
|
||||
std::array<char, kMaxNameLength + 1> name = {0}; // +1 for the nullterm
|
||||
bool register_firewall = false;
|
||||
|
||||
void serialize() const {
|
||||
std::ofstream stream(detail::ctx_path(), std::ios::binary);
|
||||
@@ -50,3 +52,4 @@ namespace shared {
|
||||
|
||||
static_assert(std::is_trivially_copyable_v<Context>);
|
||||
} // namespace shared
|
||||
#pragma pack(pop)
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
namespace strings {
|
||||
constexpr std::string_view kProjectName = "defendnot";
|
||||
constexpr std::string_view kRepoUrl = "https://github.com/es3n1n/defendnot";
|
||||
constexpr std::string_view kVersion = "1.3.0";
|
||||
constexpr std::string_view kVersion = "1.6.0";
|
||||
|
||||
constexpr std::string_view kDefaultAVName = "dnot.sh";
|
||||
|
||||
|
||||
@@ -42,19 +42,19 @@ namespace loader {
|
||||
return false;
|
||||
}
|
||||
|
||||
hr = service->Connect(VARIANT{}, VARIANT{}, VARIANT{}, VARIANT{});
|
||||
hr = service->Connect(variant_t{}, variant_t{}, variant_t{}, variant_t{});
|
||||
if (FAILED(hr)) {
|
||||
return false;
|
||||
}
|
||||
|
||||
com::Ptr<ITaskFolder> root_folder;
|
||||
hr = service->GetFolder(BSTR(L"\\"), root_folder.ref_to_ptr());
|
||||
hr = service->GetFolder(bstr_t(L"\\"), root_folder.ref_to_ptr());
|
||||
if (FAILED(hr)) {
|
||||
return false;
|
||||
}
|
||||
|
||||
/// Cleanup our task, we will recreate it in the callback if needed
|
||||
root_folder->DeleteTask(BSTR(kTaskName.data()), 0);
|
||||
root_folder->DeleteTask(bstr_t(kTaskName.data()), 0);
|
||||
return callback(service.get(), root_folder.get());
|
||||
}
|
||||
} // namespace
|
||||
|
||||
@@ -2,6 +2,8 @@
|
||||
#include <string>
|
||||
#include <string_view>
|
||||
|
||||
#include "shared/ctx.hpp"
|
||||
|
||||
#include <Windows.h>
|
||||
|
||||
namespace loader {
|
||||
@@ -16,9 +18,17 @@ namespace loader {
|
||||
bool disable;
|
||||
bool alloc_console;
|
||||
bool verbose;
|
||||
bool register_firewall;
|
||||
bool from_autorun;
|
||||
AutorunType autorun_type;
|
||||
bool enable_autorun;
|
||||
|
||||
Config& operator=(const shared::Context& ctx) {
|
||||
verbose = ctx.verbose;
|
||||
register_firewall = ctx.register_firewall;
|
||||
name = ctx.name.data();
|
||||
return *this;
|
||||
}
|
||||
};
|
||||
|
||||
[[nodiscard]] HANDLE inject(std::string_view dll_path, std::string_view proc_name);
|
||||
|
||||
@@ -25,6 +25,7 @@ namespace {
|
||||
|
||||
shared::ctx.state = config.disable ? shared::State::OFF : shared::State::ON;
|
||||
shared::ctx.verbose = config.verbose;
|
||||
shared::ctx.register_firewall = config.register_firewall;
|
||||
std::ranges::copy(config.name, shared::ctx.name.data());
|
||||
|
||||
/// No need to overwrite ctx if we are called from autorun
|
||||
@@ -100,6 +101,7 @@ int main(int argc, char* argv[]) try {
|
||||
program.add_argument("-n", "--name").help("av display name").default_value(std::string(strings::kDefaultAVName)).nargs(1);
|
||||
program.add_argument("-d", "--disable").help(std::format("disable {}", strings::kProjectName)).default_value(false).implicit_value(true);
|
||||
program.add_argument("-v", "--verbose").help("verbose logging").default_value(false).implicit_value(true);
|
||||
program.add_argument("--firewall").help("also register a fake firewall").default_value(false).implicit_value(true);
|
||||
program.add_argument("--silent").help("do not allocate console").default_value(false).implicit_value(true);
|
||||
program.add_argument("--autorun-as-user").help("create autorun task as currently logged in user").default_value(false).implicit_value(true);
|
||||
program.add_argument("--disable-autorun").help("disable autorun task creation").default_value(false).implicit_value(true);
|
||||
@@ -120,6 +122,7 @@ int main(int argc, char* argv[]) try {
|
||||
.disable = program.get<bool>("-d"),
|
||||
.alloc_console = !program.get<bool>("--silent"),
|
||||
.verbose = program.get<bool>("-v"),
|
||||
.register_firewall = program.get<bool>("--firewall"),
|
||||
.from_autorun = program.get<bool>("--from-autorun"),
|
||||
.autorun_type = program.get<bool>("--autorun-as-user") ? /// As system on boot is the default value
|
||||
loader::AutorunType::AS_CURRENT_USER_ON_LOGIN :
|
||||
@@ -130,7 +133,7 @@ int main(int argc, char* argv[]) try {
|
||||
/// When running from autorun, we'll be missing all the cli arguments, so lets load some relevant ones
|
||||
if (config.from_autorun) {
|
||||
shared::ctx.deserialize();
|
||||
config.verbose = shared::ctx.verbose;
|
||||
config = shared::ctx;
|
||||
}
|
||||
|
||||
if (!config.alloc_console && config.verbose) {
|
||||
|
||||
@@ -8,27 +8,41 @@
|
||||
|
||||
namespace defendnot {
|
||||
namespace {
|
||||
void activate(const auto& step, IWscASStatus* inst) {
|
||||
step("update", inst->UpdateStatus(WSCSecurityProductState::ON, TRUE));
|
||||
}
|
||||
|
||||
void activate(const auto& step, IWscAVStatus4* inst) {
|
||||
step("update", inst->UpdateStatus(WSCSecurityProductState::ON, TRUE));
|
||||
step("scan_update", inst->UpdateScanSubstatus(WSCSecurityProductSubStatus::NO_ACTION));
|
||||
step("settings_update", inst->UpdateSettingsSubstatus(WSCSecurityProductSubStatus::NO_ACTION));
|
||||
step("prot_update", inst->UpdateProtectionUpdateSubstatus(WSCSecurityProductSubStatus::NO_ACTION));
|
||||
}
|
||||
|
||||
void activate(const auto& step, IWscFWStatus2* inst) {
|
||||
step("update", inst->UpdateStatus(WSCSecurityProductState::ON));
|
||||
step("domain_update", inst->UpdateDomainProfileSubstatus(WSCSecurityProductSubStatus::NO_ACTION));
|
||||
step("private_update", inst->UpdatePrivateProfileSubstatus(WSCSecurityProductSubStatus::NO_ACTION));
|
||||
step("public_update", inst->UpdatePublicProfileSubstatus(WSCSecurityProductSubStatus::NO_ACTION));
|
||||
}
|
||||
|
||||
template <com::ComObject Ty>
|
||||
void apply(const std::string_view log_prefix, const BSTR name) {
|
||||
void apply(const std::string_view log_prefix, const BSTR name, const bool should_register) {
|
||||
/// Get the WSC interface
|
||||
auto inst = com::query<Ty>();
|
||||
|
||||
/// This can fail if we dont have any products registered so no com_checked
|
||||
/// This can fail if we dont have any products registered so no com::checked
|
||||
logln("{}_unregister: {:#x}", log_prefix, com::retry_while_pending([&inst]() -> HRESULT { return inst->Unregister(); }) & 0xFFFFFFFF);
|
||||
if (shared::ctx.state == shared::State::OFF) {
|
||||
if (!should_register) {
|
||||
return;
|
||||
}
|
||||
|
||||
/// Register and activate
|
||||
logln("{}_register: {:#x}", log_prefix, com::checked(inst->Register(name, name, 0, 0)));
|
||||
logln("{}_update: {:#x}", log_prefix, com::checked(inst->UpdateStatus(WSCSecurityProductState::ON, static_cast<BOOL>(true))));
|
||||
|
||||
/// Update the substatuses, if the interface supports this
|
||||
if constexpr (std::is_same_v<Ty, IWscAVStatus4>) {
|
||||
logln("{}_scan_update: {:#x}", log_prefix, com::checked(inst->UpdateScanSubstatus(WSCSecurityProductSubStatus::NO_ACTION)));
|
||||
logln("{}_settings_update: {:#x}", log_prefix, com::checked(inst->UpdateSettingsSubstatus(WSCSecurityProductSubStatus::NO_ACTION)));
|
||||
logln("{}_prot_update: {:#x}", log_prefix, com::checked(inst->UpdateProtectionUpdateSubstatus(WSCSecurityProductSubStatus::NO_ACTION)));
|
||||
}
|
||||
const auto step = [&](const std::string_view what, const HRESULT hr) -> void {
|
||||
logln("{}_{}: {:#x}", log_prefix, what, com::checked(hr));
|
||||
};
|
||||
step("register", inst->Register(name, name, 0, 0));
|
||||
activate(step, inst.get());
|
||||
}
|
||||
} // namespace
|
||||
|
||||
@@ -45,12 +59,14 @@ namespace defendnot {
|
||||
|
||||
/// Convert to BSTR
|
||||
auto name = SysAllocString(name_w.c_str());
|
||||
defer->void {
|
||||
defer {
|
||||
SysFreeString(name);
|
||||
};
|
||||
|
||||
/// Register our stuff in the WSC interfaces
|
||||
apply<IWscASStatus>("IWscASStatus", name);
|
||||
apply<IWscAVStatus4>("IWscAVStatus4", name);
|
||||
const bool enabled = shared::ctx.state != shared::State::OFF;
|
||||
apply<IWscASStatus>("IWscASStatus", name, enabled);
|
||||
apply<IWscAVStatus4>("IWscAVStatus4", name, enabled);
|
||||
apply<IWscFWStatus2>("IWscFWStatus2", name, enabled && shared::ctx.register_firewall);
|
||||
}
|
||||
} // namespace defendnot
|
||||
|
||||
@@ -40,33 +40,43 @@ namespace defendnot {
|
||||
|
||||
class IWscAVStatus4 : public com::IBaseObject<detail::CLSID_WscIsv, detail::IID_IWscAVStatus4> {
|
||||
public:
|
||||
virtual HRESULT Register(BSTR path_to_signed_product_exe, BSTR display_name, std::uint32_t, std::uint32_t) = 0;
|
||||
virtual HRESULT Unregister() = 0;
|
||||
virtual HRESULT UpdateStatus(WSCSecurityProductState state, BOOL unk) = 0;
|
||||
virtual HRESULT InitiateOfflineCleaning(std::uint16_t*, std::uint16_t*) = 0;
|
||||
virtual HRESULT NotifyUserForNearExpiration(std::uint32_t) = 0;
|
||||
virtual HRESULT MakeDefaultProductRequest() = 0;
|
||||
virtual HRESULT IsDefaultProductEnforced(std::uint32_t* result) = 0;
|
||||
virtual HRESULT UpdateScanSubstatus(WSCSecurityProductSubStatus status) = 0;
|
||||
virtual HRESULT UpdateSettingsSubstatus(WSCSecurityProductSubStatus status) = 0;
|
||||
virtual HRESULT UpdateProtectionUpdateSubstatus(WSCSecurityProductSubStatus status) = 0;
|
||||
virtual HRESULT RegisterAV(std::uint16_t*, std::uint16_t*, std::uint32_t, std::uint32_t) = 0;
|
||||
virtual HRESULT UnregisterAV() = 0;
|
||||
virtual HRESULT UpdateStatusAV(WSCSecurityProductState state, BOOL unk) = 0;
|
||||
virtual HRESULT InitiateOfflineCleaningAV(std::uint16_t*, std::uint16_t*) = 0;
|
||||
virtual HRESULT NotifyUserForNearExpirationAV(std::uint32_t) = 0;
|
||||
virtual HRESULT RegisterFW(std::uint16_t*, std::uint16_t*, std::uint32_t, std::uint32_t) = 0;
|
||||
virtual HRESULT UnregisterFW() = 0;
|
||||
virtual HRESULT UpdateStatusFW(WSCSecurityProductState state) = 0;
|
||||
virtual HRESULT RegisterAS(std::uint16_t*, std::uint16_t*, std::uint32_t, std::uint32_t) = 0;
|
||||
virtual HRESULT UnregisterAS() = 0;
|
||||
virtual HRESULT UpdateStatusAS(WSCSecurityProductState state, BOOL unk) = 0;
|
||||
virtual HRESULT COM_CALLCONV Register(BSTR path_to_signed_product_exe, BSTR display_name, std::uint32_t, std::uint32_t) = 0;
|
||||
virtual HRESULT COM_CALLCONV Unregister() = 0;
|
||||
virtual HRESULT COM_CALLCONV UpdateStatus(WSCSecurityProductState state, BOOL unk) = 0;
|
||||
virtual HRESULT COM_CALLCONV InitiateOfflineCleaning(std::uint16_t*, std::uint16_t*) = 0;
|
||||
virtual HRESULT COM_CALLCONV NotifyUserForNearExpiration(std::uint32_t) = 0;
|
||||
virtual HRESULT COM_CALLCONV MakeDefaultProductRequest() = 0;
|
||||
virtual HRESULT COM_CALLCONV IsDefaultProductEnforced(std::uint32_t* result) = 0;
|
||||
virtual HRESULT COM_CALLCONV UpdateScanSubstatus(WSCSecurityProductSubStatus status) = 0;
|
||||
virtual HRESULT COM_CALLCONV UpdateSettingsSubstatus(WSCSecurityProductSubStatus status) = 0;
|
||||
virtual HRESULT COM_CALLCONV UpdateProtectionUpdateSubstatus(WSCSecurityProductSubStatus status) = 0;
|
||||
virtual HRESULT COM_CALLCONV RegisterAV(std::uint16_t*, std::uint16_t*, std::uint32_t, std::uint32_t) = 0;
|
||||
virtual HRESULT COM_CALLCONV UnregisterAV() = 0;
|
||||
virtual HRESULT COM_CALLCONV UpdateStatusAV(WSCSecurityProductState state, BOOL unk) = 0;
|
||||
virtual HRESULT COM_CALLCONV InitiateOfflineCleaningAV(std::uint16_t*, std::uint16_t*) = 0;
|
||||
virtual HRESULT COM_CALLCONV NotifyUserForNearExpirationAV(std::uint32_t) = 0;
|
||||
virtual HRESULT COM_CALLCONV RegisterFW(std::uint16_t*, std::uint16_t*, std::uint32_t, std::uint32_t) = 0;
|
||||
virtual HRESULT COM_CALLCONV UnregisterFW() = 0;
|
||||
virtual HRESULT COM_CALLCONV UpdateStatusFW(WSCSecurityProductState state) = 0;
|
||||
virtual HRESULT COM_CALLCONV RegisterAS(std::uint16_t*, std::uint16_t*, std::uint32_t, std::uint32_t) = 0;
|
||||
virtual HRESULT COM_CALLCONV UnregisterAS() = 0;
|
||||
virtual HRESULT COM_CALLCONV UpdateStatusAS(WSCSecurityProductState state, BOOL unk) = 0;
|
||||
};
|
||||
|
||||
class IWscASStatus : public com::IBaseObject<detail::CLSID_WscIsv, detail::IID_IWscASStatus> {
|
||||
public:
|
||||
virtual HRESULT Register(BSTR path_to_signed_product_exe, BSTR display_name, std::uint32_t, std::uint32_t) = 0;
|
||||
virtual HRESULT Unregister() = 0;
|
||||
virtual HRESULT UpdateStatus(WSCSecurityProductState state, BOOL unk) = 0;
|
||||
virtual HRESULT COM_CALLCONV Register(BSTR path_to_signed_product_exe, BSTR display_name, std::uint32_t, std::uint32_t) = 0;
|
||||
virtual HRESULT COM_CALLCONV Unregister() = 0;
|
||||
virtual HRESULT COM_CALLCONV UpdateStatus(WSCSecurityProductState state, BOOL unk) = 0;
|
||||
};
|
||||
|
||||
class IWscFWStatus2 : public com::IBaseObject<detail::CLSID_WscIsv, detail::IID_IWscFWStatus2> {
|
||||
public:
|
||||
virtual HRESULT COM_CALLCONV Register(BSTR path_to_signed_product_exe, BSTR display_name, std::uint32_t, std::uint32_t) = 0;
|
||||
virtual HRESULT COM_CALLCONV Unregister() = 0;
|
||||
virtual HRESULT COM_CALLCONV UpdateStatus(WSCSecurityProductState state) = 0;
|
||||
virtual HRESULT COM_CALLCONV UpdateDomainProfileSubstatus(WSCSecurityProductSubStatus status) = 0;
|
||||
virtual HRESULT COM_CALLCONV UpdatePrivateProfileSubstatus(WSCSecurityProductSubStatus status) = 0;
|
||||
virtual HRESULT COM_CALLCONV UpdatePublicProfileSubstatus(WSCSecurityProductSubStatus status) = 0;
|
||||
};
|
||||
} // namespace defendnot
|
||||
|
||||
30
extra-strip.bat
Normal file
30
extra-strip.bat
Normal file
@@ -0,0 +1,30 @@
|
||||
:: based on https://github.com/es3n1n/defendnot/issues/49 comments
|
||||
@echo off
|
||||
setlocal
|
||||
|
||||
net session >nul 2>&1
|
||||
if %errorlevel% neq 0 (
|
||||
echo This script needs administrator rights
|
||||
pause
|
||||
exit /b 1
|
||||
)
|
||||
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiVirus /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableRoutinelyTakingAction /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v ServiceKeepAlive /t REG_DWORD /d 00000000 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableBehaviorMonitoring /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableIntrusionPreventionSystem /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableIOAVProtection /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableOnAccessProtection /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRawWriteNotification /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealtimeMonitoring /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableScanOnRealtimeEnable /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Signature Updates" /v DisableUpdateOnStartupWithoutEngine /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Signature Updates" /v UpdateOnStartup /t REG_DWORD /d 00000000 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\SpyNet" /v DisableBlockAtFirstSeen /t REG_DWORD /d 00000001 /f
|
||||
reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\SpyNet" /v SpynetReporting /t REG_DWORD /d 00000000 /f
|
||||
|
||||
echo All done, please restart your machine to apply these changes
|
||||
pause
|
||||
endlocal
|
||||
Reference in New Issue
Block a user