Removal

You might also like

Download as txt, pdf, or txt
Download as txt, pdf, or txt
You are on page 1of 2

#=======================================

$localadmin = @("")

#=======================================

$CheckAdminUsers = "Yes"
$AddLocalAdmin = "Yes"
$RemoveLocalAdmin = "No"

$CheckAndRemoveSEP = "Yes"
$CheckAndRemoveSavedOfficeCreds = "Yes"
$ActivateRemoteRegistry = "Yes"
$DisableWindowsFirewall = "Yes"

#=======================================
If ($CheckAdminUsers -eq "Yes") {

Foreach ($admins in $localadmin) {

$domain = "DIGICELGROUP"
$usersnameAdmin = $domain + "\" + $admins

# Adding user to Local Admin Group

Try {
If ((Get-LocalGroupMember -Group "Administrators" -Member
$usersnameAdmin -ErrorAction Stop).Name -ne $usernameAdmin) {
If ($RemoveLocalAdmin -eq "Yes") { Remove-LocalGroupMember -Group
"Administrators" -Member $usersnameAdmin }

}
}

Catch {
If ($AddLocalAdmin -eq "Yes") { Add-LocalGroupMember -Group
"Administrators" -Member $usersnameAdmin -ErrorAction Stop }

}
}

#=======================================

# Check and uninstall SEP.


If ($CheckAndRemoveSEP -eq "Yes") {

Try {
(Get-WmiObject -Class Win32_Product -Filter "Name='Symantec Endpoint
Protection'" -ComputerName . ).Uninstall()
#Get-Package -Name "Symantec Endpoint Protection" -ErrorAction Stop |
Uninstall-Package -ErrorAction SilentlyContinue

}
Catch { "Symantec has been removed. " }
}
#=======================================

# Remove all saved Credentials in Credential Manager

If ($CheckAndRemoveSavedOfficeCreds -eq "Yes") {


$targets = (cmdkey /list | Select-String -Pattern "target") -split "Target: "
foreach ($t in $targets) { & cmdkey.exe /delete:$t }
}

#=======================================

# Set StartType to Automatice and Status to Running for Remote Registry Services

If ($ActivateRemoteRegistry -eq "Yes") {


$remotereg = Get-Service -Name RemoteRegistry
$remotereg | Set-Service -StartupType Automatic
$remotereg | Set-Service -Status Running
}

#=======================================

# Turn off Windows Firewall for All Profiles (Domain,Public,Private)

If ( $DisableWindowsFirewall -eq "No" ) { Set-NetFirewallProfile -Profile Domain,


Public, Private -Enabled False }

#=======================================

$remotereg = Get-Service -Name RemoteRegistry


$remotereg | Select-Object -Property Name, Status, StartType

Get-LocalGroupMember -Group "Administrators"

You might also like