Ohook Activation Method: Implementation Details in Microsoft-Activation-Scripts

The Ohook activation method permanently activates Microsoft Office by deploying a stub DLL that intercepts licensing calls through symbolic link redirection in the Windows Start Menu folder structure.

The Ohook activation method provides a persistent, file-system-based hook for Microsoft Office licensing components. As implemented in the massgravel/Microsoft-Activation-Scripts repository, this technique deploys a surrogate sppcs.dll to a specific Office startup path, redirecting activation validation without modifying protected system files or requiring ongoing background processes.

Core Files and Architecture

The implementation spans two primary locations in the repository:

  • MAS/Separate-Files-Version/Activators/Ohook_Activation_AIO.cmd — Standalone installer handling deployment and removal logic
  • MAS/All-In-One-Version-KL/MAS_AIO.cmd — Integrated wrapper providing menu-driven access via the :OhookActivation label
  • MAS/Separate-Files-Version/Check_Activation_Status.cmd — Status verification utility containing the CheckOhook function

Both the standalone and All-In-One versions target the same hook destination: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office, where the surrogate DLL intercepts Office's activation queries.

Installation Workflow

Invocation and Command-Line Interface

The script accepts activation commands through specific switch parameters. When invoked with /Ohook, the script sets an internal _act=1 flag; the /Ohook-Uninstall switch sets _rem=1 for removal operations.

In the All-In-One version, argument parsing occurs early in the execution flow:

if /i "%%A"=="/Ohook" set _act=1
if /i "%%A"=="/Ohook-Uninstall" set _rem=1

Users can also interact with a simple menu interface presenting two options:

  1. Install Ohook Office Activation
  2. Uninstall Ohook

Hook Destination and Pre-flight Validation

Before deployment, the script constructs a _hookPath variable pointing to the Office Start Menu folder. It performs existence checks for any existing hook files using conditional statements:

if exist "%_hookPath%\%%#" set ierror=already present

If existing hooks are detected, the script sets a descriptive ierror message and aborts, ensuring idempotent behavior that prevents corruption of previous installations.

DLL Deployment and Symbolic Linking

The installation process follows a precise three-step file system manipulation:

  1. Binary Copy: The bundled sppcs.dll stub is copied to the hook path using binary mode to preserve integrity:

    copy /y /b "sppcs.dll" "%_hookPath%\sppcs.dll"
  2. Hard Link Creation: A hard symbolic link is established via mklink /h, forcing Office to load the surrogate DLL transparently:

    mklink /h "%_hookPath%\sppcs.dll" "%target_dll%"
  3. Smart App Control Warning: At approximately line 604, the script warns users that Windows Smart App Control may block Office execution after hook installation:

    call :dk_color %Blue% "Smart App Control may prevent you..."

Success or failure is reported through colored console output using the :dk_color function, with %Green% indicating successful installation and %Red% displaying specific ierror codes when operations fail.

Uninstallation Process

The removal workflow mirrors installation logic. When _rem=1 is set, the script:

  1. Detects hook presence via if exist checks on the DLL and symbolic link
  2. Removes both the sppcs.dll file and its hard link from the hook path
  3. Reports "Ohook activation is not installed" if no hook is found
  4. Displays confirmation through colored status messages (%Green% for success, %Red% for failure)

Status Verification

The Check_Activation_Status.cmd script contains a CheckOhook function that queries the hook state without modifying system files:

CONOUT "===                Office Ohook Status                   ==="
$host.UI.WriteLine('Yellow', 'Black', "`r`nOhook for permanent Office activation is installed...")

This verification runs independently of the installer, allowing administrators to audit activation state without triggering installation routines.

Integration with Other Activation Methods

Ohook functions alongside other activation techniques such as HWID and TSforge. The All-In-One wrapper concatenates multiple flags into a single para variable, enabling combined operations:

MAS_AIO.cmd /HWID /Ohook

This interoperability allows simultaneous system and Office activation through a single command sequence, as implemented in the :OhookActivation label (lines 2454–2506).

Error Handling and Safety Mechanisms

The implementation employs defensive programming practices to prevent system instability:

  • File Lock Detection: Pre-installation checks verify no existing hooks occupy the target path
  • Descriptive Error Codes: The ierror variable captures specific failure modes (e.g., "Failed to copy", "Access denied")
  • Atomic Operations: Copy and linking operations occur sequentially with verification at each step
  • Non-Destructive: The method does not modify Office installation files or system registry hives, enabling clean removal without traces

Summary

  • The Ohook activation method deploys a sppcs.dll stub to C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office to intercept Office licensing calls
  • Installation requires administrator privileges to create hard symbolic links via mklink /h
  • The Ohook_Activation_AIO.cmd script provides both installation (/Ohook) and uninstallation (/Ohook-Uninstall) switches
  • Windows Smart App Control may interfere with Office execution after hook deployment
  • Status checking is available through Check_Activation_Status.cmd using the CheckOhook function
  • The method is idempotent and can be combined with HWID or TSforge activation in the All-In-One wrapper

Frequently Asked Questions

How does the Ohook activation method differ from KMS activation?

Ohook provides permanent activation by intercepting DLL calls locally through the sppcs.dll hook, whereas KMS requires periodic reactivation against a Key Management Service server. The Ohook method stores the activation hook in the file system, eliminating the need for network connectivity or scheduled renewal tasks while residing entirely in the user-space Start Menu folder.

Can Ohook be detected by Windows Defender or Smart App Control?

While the hook itself operates through standard file system mechanisms, Windows Smart App Control may block Office applications from launching after Ohook installation. The script explicitly warns users about this potential conflict at line 604 of the activation routine, displaying a blue notification that Smart App Control may prevent Office from running.

Is it safe to combine Ohook with other activation methods like TSforge?

Yes, the Microsoft-Activation-Scripts repository supports concurrent activation strategies without conflict. The All-In-One wrapper accepts multiple switches (e.g., /HWID /Ohook) and processes them sequentially, as each method targets different validation components—Ohook intercepts Office DLL calls while TSforge modifies system licensing tokens.

How do I completely remove the Ohook activation hook?

Run the uninstallation command with administrative privileges: Ohook_Activation_AIO.cmd /Ohook-Uninstall. This removes both the sppcs.dll file and its symbolic link from the Office Start Menu folder. Verify complete removal by running Check_Activation_Status.cmd, which should report that Ohook is not installed.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →