From d565fa78cd2f22a340504bea29bcbb97916ad2d0 Mon Sep 17 00:00:00 2001 From: chengr28 <chengr28@gmail.com> Date: Fri, 28 Nov 2014 20:32:28 +0800 Subject: [PATCH] 2014-11-28 Rename project and add some new certificates. --- README.md | 12 ++-- Windows/AntiChinaCerts_All.bat | 72 +++++++++++-------- Windows/AntiChinaCerts_Base.bat | 12 ++-- Windows/AntiChinaCerts_Extended.bat | 31 +++++--- Windows/AntiChinaCerts_Restore.bat | 26 ++++--- Windows/Certs/SZCA.crt | 19 +++++ Windows/Certs/SZCA_200307.crt | 21 ++++++ ...Agent_CA.crt => Suspicious_GoAgent_CA.crt} | 0 ...iduCom.crt => Suspicious_WaccBaiduCom.crt} | 0 9 files changed, 133 insertions(+), 60 deletions(-) create mode 100644 Windows/Certs/SZCA.crt create mode 100644 Windows/Certs/SZCA_200307.crt rename Windows/Certs/{Monitor_GoAgent_CA.crt => Suspicious_GoAgent_CA.crt} (100%) rename Windows/Certs/{Monitor_WaccBaiduCom.crt => Suspicious_WaccBaiduCom.crt} (100%) diff --git a/README.md b/README.md index ebb8068..70f629e 100644 --- a/README.md +++ b/README.md @@ -1,15 +1,15 @@ -AntiChinaCerts +RevokeChinaCerts ============== -Anti China Certifications.<br /> +Revoke China Certificates.<br /> 全自动å¯ç–‘è¯ä¹¦åŠé”€å·¥å…·/全自動å¯ç–‘æ†‘è‰æ’¤éз工具<br /> ### Updated -**2014-11-25** +**2014-11-28** ### Usage -* [English version](https://github.com/chengr28/AntiChinaCerts/wiki/ReadMe) -* [ç®€ä½“ä¸æ–‡ä½¿ç”¨è¯´æ˜Ž](https://github.com/chengr28/AntiChinaCerts/wiki/ReadMe(Chinese_Simplified)) -* [ç¹é«”䏿–‡ä½¿ç”¨èªªæ˜Ž](https://github.com/chengr28/AntiChinaCerts/wiki/ReadMe(Chinese_Traditional)) +* [English version](https://github.com/chengr28/RevokeChinaCerts/wiki/ReadMe) +* [ç®€ä½“ä¸æ–‡ä½¿ç”¨è¯´æ˜Ž](https://github.com/chengr28/RevokeChinaCerts/wiki/ReadMe(Chinese_Simplified)) +* [ç¹é«”䏿–‡ä½¿ç”¨èªªæ˜Ž](https://github.com/chengr28/RevokeChinaCerts/wiki/ReadMe(Chinese_Traditional)) ### 特别说明/特別說明 * **Extended** 版和 **All** 版会自动åŠé”€ GoAgent 自带的 `GoAgent CA` è¯ä¹¦ï¼Œä¸ºå…使用 GoAgent æ—¶å‡ºçŽ°é”™è¯¯åŒæ—¶ä¹Ÿä¸ºäº†ç³»ç»ŸåŠ å¯†è¿žæŽ¥çš„å®‰å…¨å¼ºçƒˆå»ºè®®æ›´æ¢å…¶è‡ªå¸¦çš„ CA æ ¹è¯ä¹¦ã€‚**关闿‰€æœ‰ GoAgent 程åºï¼Œè¿›å…¥å…¶ `local` ç›®å½•åˆ é™¤ `CA.crt` ä»¥åŠæ•´ä¸ª `certs` ç›®å½•ï¼Œç„¶åŽæ¸…空所有æµè§ˆå™¨æ•°æ®é‡å¯ GoAgent å’Œæµè§ˆå™¨å³å¯ã€‚** diff --git a/Windows/AntiChinaCerts_All.bat b/Windows/AntiChinaCerts_All.bat index b081df0..c4e2704 100644 --- a/Windows/AntiChinaCerts_All.bat +++ b/Windows/AntiChinaCerts_All.bat @@ -1,5 +1,5 @@ -:: AntiChinaCerts All batch -:: Anti China Certifications. +:: RevokeChinaCerts All batch +:: Revoke China Certificates. :: :: Author: JayXon, Chengr28 :: @@ -18,7 +18,7 @@ ::del /f /q %SystemPath%\TestPermission.log cd /d %~dp0 -:: Update certifications list of system. +:: Update certificates list of system. RootSUPD_201403_x86 ::cls @@ -28,7 +28,7 @@ cd /d %~dp0\Certs set CertMgr=CertMgr if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%CertMgr%_x86 -:: Delete certifications(Base) +:: Delete certificates(Base part) :: Fake GitHub.Com(2013-01-25) %CertMgr% -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine Root %CertMgr% -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine AuthRoot @@ -80,7 +80,8 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert :: Baidu WACC service [SCFWSE] %CertMgr% -del -c -sha1 561422647B89BE22F203EBCAEF52B5007227510A -s -r localMachine CA %CertMgr% -del -c -sha1 561422647B89BE22F203EBCAEF52B5007227510A -s -r CurrentUser CA -:: Delete certifications(Extended) + +:: Delete certificates(Extended part) :: CFCA GT CA(2011-06-13) %CertMgr% -del -c -sha1 EABDA240440ABBD694930A01D09764C6C2D77966 -s -r localMachine Root %CertMgr% -del -c -sha1 EABDA240440ABBD694930A01D09764C6C2D77966 -s -r localMachine AuthRoot @@ -121,7 +122,18 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -del -c -sha1 AB702CDF18EBE8B438C52869CD4A5DEF48B40E33 -s -r localMachine AuthRoot %CertMgr% -del -c -sha1 AB702CDF18EBE8B438C52869CD4A5DEF48B40E33 -s -r CurrentUser Root %CertMgr% -del -c -sha1 AB702CDF18EBE8B438C52869CD4A5DEF48B40E33 -s -r CurrentUser AuthRoot -:: Delete certifications(All) +:: SZCA [yfdyh000] +%CertMgr% -del -c -sha1 B0049D436F27237EE59C746A1EF3C96A8E1B54AC -s -r localMachine Root +%CertMgr% -del -c -sha1 B0049D436F27237EE59C746A1EF3C96A8E1B54AC -s -r localMachine AuthRoot +%CertMgr% -del -c -sha1 B0049D436F27237EE59C746A1EF3C96A8E1B54AC -s -r CurrentUser Root +%CertMgr% -del -c -sha1 B0049D436F27237EE59C746A1EF3C96A8E1B54AC -s -r CurrentUser AuthRoot +:: SZCA(2003-07-22) [yfdyh000] +%CertMgr% -del -c -sha1 90D7A97592F0A3E2165DE5DA23B57701D74A298D -s -r localMachine Root +%CertMgr% -del -c -sha1 90D7A97592F0A3E2165DE5DA23B57701D74A298D -s -r localMachine AuthRoot +%CertMgr% -del -c -sha1 90D7A97592F0A3E2165DE5DA23B57701D74A298D -s -r CurrentUser Root +%CertMgr% -del -c -sha1 90D7A97592F0A3E2165DE5DA23B57701D74A298D -s -r CurrentUser AuthRoot + +:: Delete certificates(All part) :: ROOTCA %CertMgr% -del -c -sha1 DBB84423C928ABE889D0E368FC3191D151DDB1AB -s -r localMachine Root %CertMgr% -del -c -sha1 DBB84423C928ABE889D0E368FC3191D151DDB1AB -s -r localMachine AuthRoot @@ -132,12 +144,12 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -del -c -sha1 AE3F2E66D48FC6BD1DF131E89D768D505DF14302 -s -r localMachine AuthRoot %CertMgr% -del -c -sha1 AE3F2E66D48FC6BD1DF131E89D768D505DF14302 -s -r CurrentUser Root %CertMgr% -del -c -sha1 AE3F2E66D48FC6BD1DF131E89D768D505DF14302 -s -r CurrentUser AuthRoot -:: Certification Authority of WoSign +:: Certificate Authority of WoSign %CertMgr% -del -c -sha1 B94294BF91EA8FB64BE61097C7FB001359B676CB -s -r localMachine Root %CertMgr% -del -c -sha1 B94294BF91EA8FB64BE61097C7FB001359B676CB -s -r localMachine AuthRoot %CertMgr% -del -c -sha1 B94294BF91EA8FB64BE61097C7FB001359B676CB -s -r CurrentUser Root %CertMgr% -del -c -sha1 B94294BF91EA8FB64BE61097C7FB001359B676CB -s -r CurrentUser AuthRoot -:: Certification Authority of WoSign(Chinese) +:: Certificate Authority of WoSign(Chinese) %CertMgr% -del -c -sha1 1632478D89F9213A92008563F5A4A7D312408AD6 -s -r localMachine Root %CertMgr% -del -c -sha1 1632478D89F9213A92008563F5A4A7D312408AD6 -s -r localMachine AuthRoot %CertMgr% -del -c -sha1 1632478D89F9213A92008563F5A4A7D312408AD6 -s -r CurrentUser Root @@ -147,10 +159,10 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -del -c -sha1 6A174570A916FBE84453EED3D070A1D8DA442829 -s -r localMachine AuthRoot %CertMgr% -del -c -sha1 6A174570A916FBE84453EED3D070A1D8DA442829 -s -r CurrentUser Root %CertMgr% -del -c -sha1 6A174570A916FBE84453EED3D070A1D8DA442829 -s -r CurrentUser AuthRoot -:: Certification Authority of WoSign(StartCom) +:: Certificate Authority of WoSign(StartCom) %CertMgr% -del -c -sha1 868241C8B85AF79E2DAC79EDADB723E82A36AFC3 -s -r localMachine CA %CertMgr% -del -c -sha1 868241C8B85AF79E2DAC79EDADB723E82A36AFC3 -s -r CurrentUser CA -:: Certification Authority of WoSign(USERTrust) [v998] +:: Certificate Authority of WoSign(USERTrust) [v998] %CertMgr% -del -c -sha1 56FAADDC596DCF78D585D83A35BC04B690D12736 -s -r localMachine CA %CertMgr% -del -c -sha1 56FAADDC596DCF78D585D83A35BC04B690D12736 -s -r CurrentUser CA :: WoSign Premium Server Authority(USERTrust) @@ -196,12 +208,12 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -del -c -sha1 D6DAA8208D09D2154D24B52FCB346EB258B28A58 -s -r localMachine AuthRoot %CertMgr% -del -c -sha1 D6DAA8208D09D2154D24B52FCB346EB258B28A58 -s -r CurrentUser Root %CertMgr% -del -c -sha1 D6DAA8208D09D2154D24B52FCB346EB258B28A58 -s -r CurrentUser AuthRoot -:: ePKI Root Certification Authority +:: ePKI Root Certificate Authority %CertMgr% -del -c -sha1 67650DF17E8E7E5B8240A4F4564BCFE23D69C6F0 -s -r localMachine Root %CertMgr% -del -c -sha1 67650DF17E8E7E5B8240A4F4564BCFE23D69C6F0 -s -r localMachine AuthRoot %CertMgr% -del -c -sha1 67650DF17E8E7E5B8240A4F4564BCFE23D69C6F0 -s -r CurrentUser Root %CertMgr% -del -c -sha1 67650DF17E8E7E5B8240A4F4564BCFE23D69C6F0 -s -r CurrentUser AuthRoot -:: Government Root Certification Authority +:: Government Root Certificate Authority %CertMgr% -del -c -sha1 F48B11BFDEABBE94542071E641DE6BBE882B40B9 -s -r localMachine Root %CertMgr% -del -c -sha1 F48B11BFDEABBE94542071E641DE6BBE882B40B9 -s -r localMachine AuthRoot %CertMgr% -del -c -sha1 F48B11BFDEABBE94542071E641DE6BBE882B40B9 -s -r CurrentUser Root @@ -211,12 +223,12 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -del -c -sha1 9CBB4853F6A4F6D352A4E83252556013F5ADAF65 -s -r localMachine AuthRoot %CertMgr% -del -c -sha1 9CBB4853F6A4F6D352A4E83252556013F5ADAF65 -s -r CurrentUser Root %CertMgr% -del -c -sha1 9CBB4853F6A4F6D352A4E83252556013F5ADAF65 -s -r CurrentUser AuthRoot -:: TWCA Root Certification Authority(1) +:: TWCA Root Certificate Authority(1) %CertMgr% -del -c -sha1 CF9E876DD3EBFC422697A3B5A37AA076A9062348 -s -r localMachine Root %CertMgr% -del -c -sha1 CF9E876DD3EBFC422697A3B5A37AA076A9062348 -s -r localMachine AuthRoot %CertMgr% -del -c -sha1 CF9E876DD3EBFC422697A3B5A37AA076A9062348 -s -r CurrentUser Root %CertMgr% -del -c -sha1 CF9E876DD3EBFC422697A3B5A37AA076A9062348 -s -r CurrentUser AuthRoot -:: TWCA Root Certification Authority(2) +:: TWCA Root Certificate Authority(2) %CertMgr% -del -c -sha1 DF646DCB7B0FD3A96AEE88C64E2D676711FF9D5F -s -r localMachine Root %CertMgr% -del -c -sha1 DF646DCB7B0FD3A96AEE88C64E2D676711FF9D5F -s -r localMachine AuthRoot %CertMgr% -del -c -sha1 DF646DCB7B0FD3A96AEE88C64E2D676711FF9D5F -s -r CurrentUser Root @@ -227,13 +239,13 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert :: TWCA Secure CA %CertMgr% -del -c -sha1 3F3E6C4B33802A2FEA46C5CACA14770A40018899 -s -r localMachine CA %CertMgr% -del -c -sha1 3F3E6C4B33802A2FEA46C5CACA14770A40018899 -s -r CurrentUser CA -:: TWCA Secure Certification Authority +:: TWCA Secure Certificate Authority %CertMgr% -del -c -sha1 339D811FEC673E7F731307A34C7C7523ABBE7DFE -s -r localMachine CA %CertMgr% -del -c -sha1 339D811FEC673E7F731307A34C7C7523ABBE7DFE -s -r CurrentUser CA @echo. -:: Add certifications to CRL(Base) +:: Add certificates to CRL(Base part) %CertMgr% -add -c Fake_GitHubCom_201301.crt -s Disallowed %CertMgr% -add -c Fake_GoogleCom_201407.crt -s Disallowed %CertMgr% -add -c Fake_GoogleCom_201409.crt -s Disallowed @@ -244,8 +256,8 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -add -c CNNIC_ROOT.crt -s Disallowed %CertMgr% -add -c China_Internet_Network_Information_Center_EV_Certificates_Root.crt -s Disallowed %CertMgr% -add -c CNNIC_SSL_Entrust.crt -s Disallowed -%CertMgr% -add -c Monitor_WaccBaiduCom.crt -s Disallowed -:: Add certifications to CRL(Extended) +%CertMgr% -add -c Suspicious_WaccBaiduCom.crt -s Disallowed +:: Add certificates to CRL(Extended part) %CertMgr% -add -c CFCA_GT_CA_201106.crt -s Disallowed %CertMgr% -add -c CFCA_GT_CA_201208.crt -s Disallowed %CertMgr% -add -c CFCA_EV_ROOT.crt -s Disallowed @@ -253,15 +265,17 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -add -c UCA_Root_200401.crt -s Disallowed %CertMgr% -add -c UCA_Extended_Validation_Root.crt -s Disallowed %CertMgr% -add -c UCA_ROOT_200101.crt -s Disallowed -%CertMgr% -add -c Monitor_GoAgent_CA.crt -s Disallowed -:: Add certifications to CRL(All) +%CertMgr% -add -c Suspicious_GoAgent_CA.crt -s Disallowed +%CertMgr% -add -c SZCA.crt -s Disallowed +%CertMgr% -add -c SZCA_200307.crt -s Disallowed +:: Add certificates to CRL(All part) %CertMgr% -add -c ROOTCA_OSCCA.crt -s Disallowed %CertMgr% -add -c SRCA.crt -s Disallowed -%CertMgr% -add -c Certification_Authority_Of_WoSign.crt -s Disallowed -%CertMgr% -add -c Certification_Authority_Of_WoSign_Chinese.crt -s Disallowed +%CertMgr% -add -c Certificate_Authority_Of_WoSign.crt -s Disallowed +%CertMgr% -add -c Certificate_Authority_Of_WoSign_Chinese.crt -s Disallowed %CertMgr% -add -c Class_1_Primary_CA.crt -s Disallowed -%CertMgr% -add -c Certification_Authority_Of_WoSign_StartCom.crt -s Disallowed -%CertMgr% -add -c Certification_Authority_Of_WoSign_USERTrust.crt -s Disallowed +%CertMgr% -add -c Certificate_Authority_Of_WoSign_StartCom.crt -s Disallowed +%CertMgr% -add -c Certificate_Authority_Of_WoSign_USERTrust.crt -s Disallowed %CertMgr% -add -c WoSign_Premium_Server_Authority_USERTrust.crt -s Disallowed %CertMgr% -add -c WoSign_Server_Authority_USERTrust.crt -s Disallowed %CertMgr% -add -c WoSign_SGC_Server_Authority_USERTrust.crt -s Disallowed @@ -273,14 +287,14 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -add -c China_Trust_Network_3.crt -s Disallowed %CertMgr% -add -c Hongkong_Post_Root_CA.crt -s Disallowed %CertMgr% -add -c Hongkong_Post_Root_CA_1.crt -s Disallowed -%CertMgr% -add -c ePKI_Root_Certification_Authority.crt -s Disallowed -%CertMgr% -add -c Government_Root_Certification_Authority.crt -s Disallowed +%CertMgr% -add -c ePKI_Root_Certificate_Authority.crt -s Disallowed +%CertMgr% -add -c Government_Root_Certificate_Authority.crt -s Disallowed %CertMgr% -add -c TWCA_Global_Root_CA.crt -s Disallowed -%CertMgr% -add -c TWCA_Root_Certification_Authority_1.crt -s Disallowed -%CertMgr% -add -c TWCA_Root_Certification_Authority_2.crt -s Disallowed +%CertMgr% -add -c TWCA_Root_Certificate_Authority_1.crt -s Disallowed +%CertMgr% -add -c TWCA_Root_Certificate_Authority_2.crt -s Disallowed %CertMgr% -add -c TaiCA_Secure_CA_GTE.crt -s Disallowed %CertMgr% -add -c TWCA_Secure_CA_Baltimore.crt -s Disallowed -%CertMgr% -add -c TWCA_Secure_Certification_Authority_USERTrust.crt -s Disallowed +%CertMgr% -add -c TWCA_Secure_Certificate_Authority_USERTrust.crt -s Disallowed :Exit :: Print to screen. diff --git a/Windows/AntiChinaCerts_Base.bat b/Windows/AntiChinaCerts_Base.bat index 67aacb3..5b541b4 100644 --- a/Windows/AntiChinaCerts_Base.bat +++ b/Windows/AntiChinaCerts_Base.bat @@ -1,5 +1,5 @@ -:: AntiChinaCerts Base batch -:: Anti China Certifications. +:: RevokeChinaCerts Base batch +:: Revoke China Certificates. :: :: Author: JayXon, Chengr28 :: @@ -18,7 +18,7 @@ ::del /f /q %SystemPath%\TestPermission.log cd /d %~dp0 -:: Update certifications list of system. +:: Update certificates list of system. RootSUPD_201403_x86 ::cls @@ -28,7 +28,7 @@ cd /d %~dp0\Certs set CertMgr=CertMgr if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%CertMgr%_x86 -:: Delete certifications(Base) +:: Delete certificates(Base part) :: Fake GitHub.Com(2013-01-25) %CertMgr% -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine Root %CertMgr% -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine AuthRoot @@ -83,7 +83,7 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert @echo. -:: Add certifications to CRL(Base) +:: Add certificates to CRL(Base part) %CertMgr% -add -c Fake_GitHubCom_201301.crt -s Disallowed %CertMgr% -add -c Fake_GoogleCom_201407.crt -s Disallowed %CertMgr% -add -c Fake_GoogleCom_201409.crt -s Disallowed @@ -94,7 +94,7 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -add -c CNNIC_ROOT.crt -s Disallowed %CertMgr% -add -c China_Internet_Network_Information_Center_EV_Certificates_Root.crt -s Disallowed %CertMgr% -add -c CNNIC_SSL_Entrust.crt -s Disallowed -%CertMgr% -add -c Monitor_WaccBaiduCom.crt -s Disallowed +%CertMgr% -add -c Suspicious_WaccBaiduCom.crt -s Disallowed :Exit :: Print to screen. diff --git a/Windows/AntiChinaCerts_Extended.bat b/Windows/AntiChinaCerts_Extended.bat index 8c4c5b9..437b633 100644 --- a/Windows/AntiChinaCerts_Extended.bat +++ b/Windows/AntiChinaCerts_Extended.bat @@ -1,5 +1,5 @@ -:: AntiChinaCerts Extended batch -:: Anti China Certifications. +:: RevokeChinaCerts Extended batch +:: Revoke China Certificates. :: :: Author: JayXon, Chengr28 :: @@ -18,7 +18,7 @@ ::del /f /q %SystemPath%\TestPermission.log cd /d %~dp0 -:: Update certifications list of system. +:: Update certificates list of system. RootSUPD_201403_x86 ::cls @@ -28,7 +28,7 @@ cd /d %~dp0\Certs set CertMgr=CertMgr if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%CertMgr%_x86 -:: Delete certifications(Base) +:: Delete certificates(Base part) :: Fake GitHub.Com(2013-01-25) %CertMgr% -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine Root %CertMgr% -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine AuthRoot @@ -80,7 +80,8 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert :: Baidu WACC service [SCFWSE] %CertMgr% -del -c -sha1 561422647B89BE22F203EBCAEF52B5007227510A -s -r localMachine CA %CertMgr% -del -c -sha1 561422647B89BE22F203EBCAEF52B5007227510A -s -r CurrentUser CA -:: Delete certifications(Extended) + +:: Delete certificates(Extended part) :: CFCA GT CA(2011-06-13) %CertMgr% -del -c -sha1 EABDA240440ABBD694930A01D09764C6C2D77966 -s -r localMachine Root %CertMgr% -del -c -sha1 EABDA240440ABBD694930A01D09764C6C2D77966 -s -r localMachine AuthRoot @@ -121,10 +122,20 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -del -c -sha1 AB702CDF18EBE8B438C52869CD4A5DEF48B40E33 -s -r localMachine AuthRoot %CertMgr% -del -c -sha1 AB702CDF18EBE8B438C52869CD4A5DEF48B40E33 -s -r CurrentUser Root %CertMgr% -del -c -sha1 AB702CDF18EBE8B438C52869CD4A5DEF48B40E33 -s -r CurrentUser AuthRoot +:: SZCA [yfdyh000] +%CertMgr% -del -c -sha1 B0049D436F27237EE59C746A1EF3C96A8E1B54AC -s -r localMachine Root +%CertMgr% -del -c -sha1 B0049D436F27237EE59C746A1EF3C96A8E1B54AC -s -r localMachine AuthRoot +%CertMgr% -del -c -sha1 B0049D436F27237EE59C746A1EF3C96A8E1B54AC -s -r CurrentUser Root +%CertMgr% -del -c -sha1 B0049D436F27237EE59C746A1EF3C96A8E1B54AC -s -r CurrentUser AuthRoot +:: SZCA(2003-07-22) [yfdyh000] +%CertMgr% -del -c -sha1 90D7A97592F0A3E2165DE5DA23B57701D74A298D -s -r localMachine Root +%CertMgr% -del -c -sha1 90D7A97592F0A3E2165DE5DA23B57701D74A298D -s -r localMachine AuthRoot +%CertMgr% -del -c -sha1 90D7A97592F0A3E2165DE5DA23B57701D74A298D -s -r CurrentUser Root +%CertMgr% -del -c -sha1 90D7A97592F0A3E2165DE5DA23B57701D74A298D -s -r CurrentUser AuthRoot @echo. -:: Add certifications to CRL(Base) +:: Add certificates to CRL(Base part) %CertMgr% -add -c Fake_GitHubCom_201301.crt -s Disallowed %CertMgr% -add -c Fake_GoogleCom_201407.crt -s Disallowed %CertMgr% -add -c Fake_GoogleCom_201409.crt -s Disallowed @@ -135,8 +146,8 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -add -c CNNIC_ROOT.crt -s Disallowed %CertMgr% -add -c China_Internet_Network_Information_Center_EV_Certificates_Root.crt -s Disallowed %CertMgr% -add -c CNNIC_SSL_Entrust.crt -s Disallowed -%CertMgr% -add -c Monitor_WaccBaiduCom.crt -s Disallowed -:: Add certifications to CRL(Extended) +%CertMgr% -add -c Suspicious_WaccBaiduCom.crt -s Disallowed +:: Add certificates to CRL(Extended part) :: Move to All version. :: %CertMgr% -add -c ROOTCA.crt -s Disallowed %CertMgr% -add -c CFCA_GT_CA_201106.crt -s Disallowed @@ -146,7 +157,9 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -add -c UCA_Root_200401.crt -s Disallowed %CertMgr% -add -c UCA_Extended_Validation_Root.crt -s Disallowed %CertMgr% -add -c UCA_ROOT_200101.crt -s Disallowed -%CertMgr% -add -c Monitor_GoAgent_CA.crt -s Disallowed +%CertMgr% -add -c Suspicious_GoAgent_CA.crt -s Disallowed +%CertMgr% -add -c SZCA.crt -s Disallowed +%CertMgr% -add -c SZCA_200307.crt -s Disallowed :Exit :: Print to screen. diff --git a/Windows/AntiChinaCerts_Restore.bat b/Windows/AntiChinaCerts_Restore.bat index 404f5f1..96a6200 100644 --- a/Windows/AntiChinaCerts_Restore.bat +++ b/Windows/AntiChinaCerts_Restore.bat @@ -1,5 +1,5 @@ -:: AntiChinaCerts Restore batch -:: Anti China Certifications. +:: RevokeChinaCerts Restore batch +:: Revoke China Certificates. :: :: Author: JayXon, Chengr28 :: @@ -18,7 +18,7 @@ ::del /f /q %SystemPath%\TestPermission.log cd /d %~dp0 -:: Update certifications list of system. +:: Update certificates list of system. RootSUPD_201403_x86 ::cls @@ -28,7 +28,7 @@ cd /d %~dp0\Certs set CertMgr=CertMgr if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%CertMgr%_x86 -:: Delete certifications(Base) +:: Restore certificates(Base part) :: Fake GitHub.Com(2013-01-25) %CertMgr% -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s Disallowed :: Fake Google.Com(2014-07-24) @@ -51,7 +51,8 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -del -c -sha1 6856BB1A6C4F76DACA362187CC2CCD484EDDC25D -s Disallowed :: Baidu WACC service [SCFWSE] %CertMgr% -del -c -sha1 561422647B89BE22F203EBCAEF52B5007227510A -s Disallowed -:: Delete certifications(Extended) + +:: Restore certificates(Extended part) :: CFCA GT CA(2011-06-13) %CertMgr% -del -c -sha1 EABDA240440ABBD694930A01D09764C6C2D77966 -s Disallowed :: CFCA GT CA(2012-08-21) [YFdyh000] @@ -68,20 +69,25 @@ if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" set CertMgr=%Cert %CertMgr% -del -c -sha1 3120F295417730075F8CD42D0CAE008EB5726EF8 -s Disallowed :: GoAgent CA [lenovo-me] %CertMgr% -del -c -sha1 AB702CDF18EBE8B438C52869CD4A5DEF48B40E33 -s Disallowed -:: Delete certifications(All) +:: SZCA [yfdyh000] +%CertMgr% -del -c -sha1 B0049D436F27237EE59C746A1EF3C96A8E1B54AC -s Disallowed +:: SZCA(2003-07-22) [yfdyh000] +%CertMgr% -del -c -sha1 90D7A97592F0A3E2165DE5DA23B57701D74A298D -s Disallowed + +:: Restore certificates(All part) :: ROOTCA %CertMgr% -del -c -sha1 DBB84423C928ABE889D0E368FC3191D151DDB1AB -s Disallowed :: SRCA %CertMgr% -del -c -sha1 AE3F2E66D48FC6BD1DF131E89D768D505DF14302 -s Disallowed -:: Certification_Authority_Of_WoSign +:: Certificate_Authority_Of_WoSign %CertMgr% -del -c -sha1 B94294BF91EA8FB64BE61097C7FB001359B676CB -s Disallowed -:: Certification_Authority_Of_WoSign(Chinese) +:: Certificate_Authority_Of_WoSign(Chinese) %CertMgr% -del -c -sha1 1632478D89F9213A92008563F5A4A7D312408AD6 -s Disallowed :: Class_1_Primary_CA %CertMgr% -del -c -sha1 6A174570A916FBE84453EED3D070A1D8DA442829 -s Disallowed -:: Certification Authority of WoSign(StartCom) +:: Certificate Authority of WoSign(StartCom) %CertMgr% -del -c -sha1 868241C8B85AF79E2DAC79EDADB723E82A36AFC3 -s Disallowed -:: Certification Authority of WoSign(USERTrust) +:: Certificate Authority of WoSign(USERTrust) %CertMgr% -del -c -sha1 56FAADDC596DCF78D585D83A35BC04B690D12736 -s Disallowed :: WoSign Premium Server Authority(USERTrust) %CertMgr% -del -c -sha1 E3D569137E603E7BACB6BCC66AE943850C8ADF38 -s Disallowed diff --git a/Windows/Certs/SZCA.crt b/Windows/Certs/SZCA.crt new file mode 100644 index 0000000..1de8131 --- /dev/null +++ b/Windows/Certs/SZCA.crt @@ -0,0 +1,19 @@ +-----BEGIN CERTIFICATE----- +MIIDCDCCAnGgAwIBAgIIKNj1cJQxM+IwDQYJKoZIhvcNAQEFBQAwezELMAkGA1UE +BhMCQ04xEjAQBgNVBAgTCUd1YW5nZG9uZzERMA8GA1UEBxMIU2hlbnpoZW4xJzAl +BgNVBAoTHlNoZW5aaGVuIENlcnRpZmljYXRlIEF1dGhvcml0eTENMAsGA1UECxME +c3pjYTENMAsGA1UEAxMEU1pDQTAeFw0xMzA0MTYwNDM3MTNaFw0zMzA0MTEwNDM3 +MTNaMHsxCzAJBgNVBAYTAkNOMRIwEAYDVQQIEwlHdWFuZ2RvbmcxETAPBgNVBAcT +CFNoZW56aGVuMScwJQYDVQQKEx5TaGVuWmhlbiBDZXJ0aWZpY2F0ZSBBdXRob3Jp +dHkxDTALBgNVBAsTBHN6Y2ExDTALBgNVBAMTBFNaQ0EwgZ8wDQYJKoZIhvcNAQEB +BQADgY0AMIGJAoGBAKuKOuBp4SLJ8SzOxCxCPIeeG+skihp9ug8cTH73xemUtPQk +lHEL6yDokE7OIsZs2dHp2dexJI67alUG0ASEVe05yeTIbqaQXFv++54ZQVrHdGwR +sp0G0uXFho9pxzrOejh6WIWVSFfTZf2DL8QPSwX9bK+ruJ/ZDvWgQTjeuye/AgMB +AAGjgZQwgZEwHwYDVR0jBBgwFoAUegUE169phelgrX+x7cxlQdBMA0YwDAYDVR0T +BAUwAwEB/zA0BgNVHR8ELTArMCmgJ6AlhiNodHRwOi8vMjAyLjEwMy4xNDQuOTg6 +ODAyOS9jcmwxLmNybDALBgNVHQ8EBAMCAf4wHQYDVR0OBBYEFHoFBNevaYXpYK1/ +se3MZUHQTANGMA0GCSqGSIb3DQEBBQUAA4GBAJuvcd4swSohkj220B3S11doa8Oq +8bMfIYyztdSJYRDEme/OqUMTKGJQUFVIigivpJ6EpTTl8u9fT6MxeukfzE4BTc8E +76uNetGnSO2JHwVbWrRTX47+/+bNxHTmgYEyjmu/t1ETrqRJ6yjDl+5ail078Han +LKIRlpnzzdAxY8Y4 +-----END CERTIFICATE----- diff --git a/Windows/Certs/SZCA_200307.crt b/Windows/Certs/SZCA_200307.crt new file mode 100644 index 0000000..5e80ced --- /dev/null +++ b/Windows/Certs/SZCA_200307.crt @@ -0,0 +1,21 @@ +-----BEGIN CERTIFICATE----- +MIIDdjCCAl6gAwIBAgIEh9YDGjANBgkqhkiG9w0BAQQFADBsMQswCQYDVQQGEwJD +TjESMBAGA1UECBMJR3Vhbmdkb25nMREwDwYDVQQHEwhTaGVuemhlbjEnMCUGA1UE +ChMeU2hlbnpoZW4gQ2VydGlmaWNhdGUgQXV0aG9yaXR5MQ0wCwYDVQQDEwRTWkNB +MB4XDTAzMDcyMjAyMjgyNFoXDTEzMDcxOTAyMjgyNFowbDELMAkGA1UEBhMCQ04x +EjAQBgNVBAgTCUd1YW5nZG9uZzERMA8GA1UEBxMIU2hlbnpoZW4xJzAlBgNVBAoT +HlNoZW56aGVuIENlcnRpZmljYXRlIEF1dGhvcml0eTENMAsGA1UEAxMEU1pDQTCC +ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALNxEinoQt5rqmy2+G9ysp04 +5N2kGty+HKpfhSO50sL9Z2uKzQ2do0Su5TbnOMZ0lWK91tyHctYE5Cl3O9VcK7lQ +ph7pjcBXOtpuq2sjZiIq+6m8r194I55YxnRlY852YdN+wGCb9VKS+iXaVWmRlFPV +UlRy+JO4h+Ef6SjWj9ULP79YaNnZZyqfXScoSSB+h6lY6L5eHuYTN6GklUcVQfuw +HJ5i1FrMes8kdDPh2L5IiUpe5XttE+8dVlAsFztMLS2xV4728Gg3gwJyPvJVt+VC +eoG6YvyxASECGyteA0BJ0jyOuOjxAnEXy32gbl4fEPVIkCJJsmGXJBTNynMl/lkC +AwEAAaMgMB4wCwYDVR0PBAQDAgEGMA8GA1UdEwQIMAYBAf8CAQMwDQYJKoZIhvcN +AQEEBQADggEBAFQNEyw0CduiJKXGHsnRX5L4zVrdU0Zn6uo87q6TZHm8Mx2iDQ6c +Ry3YWr8bIQPeTv9VnQaYxH93/ZDr5r2zZUQpJtqIpbGpPhJIZfrT3X+YofzIpveL +R3y8Awxetthdj7U7JZmvjts+3iV6SvA3dBz0W8DsGrv+jTQLrVk8XHCjwb6ynejn +wCN7ffqLComEOAaFyrw0Ho85Lro3W19TSBWdzQ8U0qk+l5CiRGpP3A11uM8VDwDD +szkX3HNsfSqFCZKPmam0PfjcoZRhv+SZcNRMa99yYbQ65mu5xQrcmgihny5ckx91 +pQTc61tbXWDLHsIVl9WMUiHeLmcSIIkScHU= +-----END CERTIFICATE----- diff --git a/Windows/Certs/Monitor_GoAgent_CA.crt b/Windows/Certs/Suspicious_GoAgent_CA.crt similarity index 100% rename from Windows/Certs/Monitor_GoAgent_CA.crt rename to Windows/Certs/Suspicious_GoAgent_CA.crt diff --git a/Windows/Certs/Monitor_WaccBaiduCom.crt b/Windows/Certs/Suspicious_WaccBaiduCom.crt similarity index 100% rename from Windows/Certs/Monitor_WaccBaiduCom.crt rename to Windows/Certs/Suspicious_WaccBaiduCom.crt -- GitLab