@echo off
net stop sharedaccess
net stop wscsvc

net stop msmpsvc


"C:\Program Files\Microsoft Security Client\Setup.exe" /x /q

pause

MsiExec.exe /quiet /X{36A345C9-0691-45A1-AEEF-29ECEC8B5014}


net stop wscsvc



echo Windows Registry Editor Version 5.00>>wscsvc.reg
echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc]>>wscsvc.reg
echo "Type"=dword:00000020>>wscsvc.reg
echo "Start"=dword:00000004>>wscsvc.reg
echo "ErrorControl"=dword:00000001>>wscsvc.reg
echo "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\>>wscsvc.reg
echo   74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\>>wscsvc.reg
echo   00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\>>wscsvc.reg
echo   6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00>>wscsvc.reg
echo "DisplayName"="Security Center">>wscsvc.reg
echo "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,77,00,69,00,6e,00,\>>wscsvc.reg
echo   6d,00,67,00,6d,00,74,00,00,00,00,00>>wscsvc.reg
echo "ObjectName"="LocalSystem">>wscsvc.reg
echo "Description"="Monitors system security settings and configurations.">>wscsvc.reg
echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Parameters]>>wscsvc.reg
echo "ServiceDll"=hex(2):25,00,53,00,59,00,53,00,54,00,45,00,4d,00,52,00,4f,00,4f,\>>wscsvc.reg
echo   00,54,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\>>wscsvc.reg
echo   77,00,73,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00>>wscsvc.reg
echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Security]>>wscsvc.reg
echo "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\>>wscsvc.reg
echo   00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\>>wscsvc.reg
echo   00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\>>wscsvc.reg
echo   05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\>>wscsvc.reg
echo   20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\>>wscsvc.reg
echo   00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\>>wscsvc.reg
echo   00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00>>wscsvc.reg
echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Enum]>>wscsvc.reg
echo "0"="Root\\LEGACY_WSCSVC\\0000">>wscsvc.reg
echo "Count"=dword:00000001>>wscsvc.reg
echo "NextInstance"=dword:00000001>>wscsvc.reg
echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess]>>wscsvc.reg
echo "Start"=dword:00000004>>wscsvc.reg



regedit /s wscsvc.reg
del wscsvc.reg



net stop wuauserv



echo Windows Registry Editor Version 5.00>>wuauserv.reg
echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv]>>wuauserv.reg
echo "Type"=dword:00000020>>wuauserv.reg
echo "Start"=dword:00000004>>wuauserv.reg
echo "ErrorControl"=dword:00000001>>wuauserv.reg
echo "ImagePath"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,\>>wuauserv.reg
echo   74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\>>wuauserv.reg
echo   00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\>>wuauserv.reg
echo   6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00>>wuauserv.reg
echo "DisplayName"="Automatic Updates">>wuauserv.reg
echo "ObjectName"="LocalSystem">>wuauserv.reg
echo "Description"="Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site.">>wuauserv.reg
echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters]>>wuauserv.reg
echo "ServiceDll"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\>>wuauserv.reg
echo   00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,75,00,\>>wuauserv.reg
echo   61,00,75,00,73,00,65,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00>>wuauserv.reg
echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security]>>wuauserv.reg
echo "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\>>wuauserv.reg
echo   00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\>>wuauserv.reg
echo   00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\>>wuauserv.reg
echo   05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\>>wuauserv.reg
echo   20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\>>wuauserv.reg
echo   00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\>>wuauserv.reg
echo   00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00>>wuauserv.reg
echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum]>>wuauserv.reg
echo "0"="Root\\LEGACY_WUAUSERV\\0000">>wuauserv.reg
echo "Count"=dword:00000001>>wuauserv.reg
echo "NextInstance"=dword:00000001>>wuauserv.reg



regedit /s wuauserv.reg
del wuauserv.reg
del %systemroot%\tasks\"microsoft windows*.job" /a
pause

clamav



