-
Notifications
You must be signed in to change notification settings - Fork 21
/
SuperParanoid.bat
93 lines (61 loc) · 1.5 KB
/
SuperParanoid.bat
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
@echo off
net user administrator /active:yes
echo.
echo "Network Location Awareness"
sc config NlaSvc start= disabled
echo.
echo "Net List"
sc config netprofm start= disabled
echo.
echo "App V Client"
sc config AppVClient start= disabled
echo "Windows Event Collector"
sc config Wecsvc start= disabled
echo.
echo "Error Reporting Service"
sc config WerSvc start= disabled
echo.
echo "Event Log"
sc config EventLog start= disabled
echo.
echo "Remote Desktop can still be exploited, Lets fix that"
echo "RD Video Minport"
sc delete RdpVideoMiniport
echo.
echo "RD USB Hub Class Filter Driver"
sc delete tsusbflt
echo.
echo "RD USB Hub"
sc delete tsusbhub
echo.
echo "RD Generic USB Device"
sc delete TsUsbGD
echo.
echo "RD Device Redirector Driver"
sc delete RDPDR
echo.
echo "RD Device Redirector Bus Driver"
sc delete rdpbus
sc start rdpbus
sc stop rdpbus
echo "Remote Access PPPOE Driver"
sc delete RasPppoe
echo "Remote Access NDIS WAN Driver"
sc delete NdisWan
echo "Remote Access TAPI Wan Driver"
sc delete NdisTapi
echo "Remote Access LEGACY NDIS WAN Driver"
sc delete ndiswanlegacy
echo "Remote Access IPv6 ARP Driver"
sc delete wanarpv6
echo "Remote Access IP ARP Driver"
sc delete wanarp
echo "Remote Access Auto Connection Driver"
sc delete RasAcd
echo.
echo ".. TO/Delete of Device Redirector Driver Ignore if denied"
echo.
takeown /f C:\Windows\System32\drivers\rdpbus.sys
cacls C:\Windows\System32\drivers\rdpbus.sys /E /P %username%:F
del C:\Windows\System32\drivers\rdpbus.sys
pause