Wednesday, July 24, 2013

Force a script to relaunch w/ Admin perms

This used to happen all the time in our organization. A script would be provided to our service desk staff, their instructions are very clear "execute the script by right clicking on it and 'run as administrator'". And yet 6 outta 10 times, they couldn't handle that. They'd run the script by doubleclicking on it . .and then wonder why things didn't work.

There's an easy fix for this with a lovely bit of DOS code:

------------------Begin Code--------------------

Set _tempvbs=%LocalAppData%\getadmin.vbs
OPENFILES > nul

:: If error flag set, we do not have Admin.
If ERRORLEVEL 1 (GOTO :ELEVATE) ELSE (GOTO :RUNSCRIPT)
 
:ELEVATE

:: Create a temporary VBScript
   cls
   Echo Set objShell = CreateObject^("Shell.Application"^) > %_tempvbs%
   Echo objShell.ShellExecute "%~f0", "", "", "runas", 1 >> %_tempvbs%

:: Relaunch this script 'As Admin'
   cscript "%_tempvbs%" //nologo
   Exit /B


----------------Exit Code---------------------------


These dos commands when integrated into a script can be used to quickly determine if the script was launched w/ administrative credentials. If it wasn't, it will create a temporary VSB script which will be used to create a UAC prompt for credentials. Once credentials are entered in the prompt, the original script will be re-executed under the entered creds.

This means that service techs just need to doubleclick on a script file, and then enter credentials when prompted.

Very very handy. I am plagiarizing this code, as it was found on a message board, and I have lost track of where I found it. I will post the original link once I track it down. Props should be given to the originator of this concept . . very slickly done imho.

Friday, July 5, 2013

SysPrep script

Organizations with virtual infrastructures, clone servers. If you clone servers, you are familiar with the need to run / use sysprep. 

It's all fine and dandy to use templates, and have sysprep run when you build your templates. But what happens when you clone a server, then need to clone your clone, and are then asked to create a clone of the clone of your original clone. You are pushing up against the Windows activation limit, and you may not be able to boot that final clone due to sysprep limitations built into windows. 

Microsoft's answer is to re-install your OS. 

I'm sorry Microsoft but that doesn't work so well in the business world. 

The following script will reset the 'counter' on sysprep. If you encounter the situation listed above where windows believes it's hit it's activation limit, this script will allow sysprep to complete successfully on the machine. 

The script should be saved as a a CMD file and run as administrator. 

-Begin Script-

@echo off

c:
cd\

Reg Delete "hklm\SYSTEM\Setup\Status\SysprepStatus" /v GeneralizationState /f
Reg Delete "hklm\Software\Microsoft\windows NT\CurrentVersion\SoftwareProtectionPlatform" /v SkipRearm /f

Timeout /t 3 /NoBreak

Reg Add "hklm\SYSTEM\Setup\Status\SysprepStatus" /v GeneralizationState /t Reg_dword /d 7
Reg Add "hklm\Software\Microsoft\windows NT\CurrentVersion\SoftwareProtectionPlatform" /v SkipRearm /t Reg_dword /d 1

Timeout /t 2 /NoBreak

MSDTC -Uninstall

Timeout /t 2 /NoBreak

MSDTC -Install

cd "Windows\system32\sysprep"

Start "sysprep" sysprep.exe /oobe /generalize /reboot

-End Script-

Robocopy Script values

RoboCopy can be easily used in scripts by leveraging variables.

-Begin Script Sample-

@echo off
c:
cd\

SET LOG="C:\scriptlog.log"
SET SOURCE="\\networkserver\servershare\subfolder"
SET DEST="c:\localfolder\subfolder"
SET DATA=/E /MIR
SET OPTIONS=/R:1 /W:1 /Log:%LOG% /NP

Robocopy %SOURCE% %DEST% %DATA% %OPTIONS%
cls

exit

-End Script Sample-


Value in script that can by-pass UAC folder protections

In CMD / BAT scripts, the following line:

set __COMPAT_LAYER=RunAsInvoker

Can be used to allow the script to by-pass UAC folder restrictions.

An example is the MSOcache folder, this folder is a UAC protected folder causing most dos commands against it to fail.

-Begin Script Sample-

@echo off
c:
cd\
set __COMPAT_LAYER=RunAsInvoker
If Exist "C:\MSOcache" RD MSOCache /S /Q
exit

-End Script Sample-