애드웨어, 허위백신, 팝업광고, 쇼핑몰 바로가기, 악성툴바, 각종 개쓰레기 프로그램 삭제 요청하기
이용약관을 안내하며 컴퓨터에 설치하는 개쓰레기 프로그램들은 백신으로 백날 돌려봐야 검색이 안됩니다.
개쓰레기 프로그램들은 아주 지능적이라서 전문가가 아니고서는 찾아내기가 어렵습니다.


----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Microsoft Windows XP Service Pack 3(5.1.2600.196608)
Intel(R) Core(TM) i3 CPU       M 380  @ 2.53GHz / 767.48 MB
x86 Family 6 Model 37 Stepping 5
Date : 2011-06-11
----------------------------------------------------------------------
DF000 C:\Program Files\cyadicon\cyadicon.exe
DF001 C:\Program Files\cyadicon\cyinsproc.exe
DF002 C:\Program Files\cyadicon\cyremoveproc.exe
DF003 C:\Program Files\cyadicon\uninstall.exe
DF004 C:\Program Files\Space International\CDSpace7Lite\CDSpace7Lite.exe
DF005 C:\Program Files\Space International\CDSpace7Lite\del_proc.exe
DF006 C:\Program Files\Space International\CDSpace7Lite\DIFxAPI.dll
DF007 C:\Program Files\Space International\CDSpace7Lite\DIFxAPI_amd64.dll
DF008 C:\Program Files\Space International\CDSpace7Lite\DIFxAPI_x86.dll
DF009 C:\Program Files\Space International\CDSpace7Lite\download\000000000001_install_cdspace.exe
DF010 C:\Program Files\Space International\CDSpace7Lite\DRMHeuristic.dll
DF011 C:\Program Files\Space International\CDSpace7Lite\Engine.dll
DF012 C:\Program Files\Space International\CDSpace7Lite\iconengines\qsvgicon4.dll
DF013 C:\Program Files\Space International\CDSpace7Lite\ImageCreator.dll
DF014 C:\Program Files\Space International\CDSpace7Lite\imageformats\qgif4.dll
DF015 C:\Program Files\Space International\CDSpace7Lite\imageformats\qico4.dll
DF016 C:\Program Files\Space International\CDSpace7Lite\imageformats\qjpeg4.dll
DF017 C:\Program Files\Space International\CDSpace7Lite\imageformats\qmng4.dll
DF018 C:\Program Files\Space International\CDSpace7Lite\imageformats\qsvg4.dll
DF019 C:\Program Files\Space International\CDSpace7Lite\imageformats\qtiff4.dll
DF020 C:\Program Files\Space International\CDSpace7Lite\IssProc.dll
DF021 C:\Program Files\Space International\CDSpace7Lite\libgcc_s_dw2-1.dll
DF022 C:\Program Files\Space International\CDSpace7Lite\mingwm10.dll
DF023 C:\Program Files\Space International\CDSpace7Lite\phonon4.dll
DF024 C:\Program Files\Space International\CDSpace7Lite\QtCore4.dll
DF025 C:\Program Files\Space International\CDSpace7Lite\QtGui4.dll
DF026 C:\Program Files\Space International\CDSpace7Lite\QtNetwork4.dll
DF027 C:\Program Files\Space International\CDSpace7Lite\QtSolutions_SingleApplication-2.6.dll
DF028 C:\Program Files\Space International\CDSpace7Lite\QtSql4.dll
DF029 C:\Program Files\Space International\CDSpace7Lite\QtSvg4.dll
DF030 C:\Program Files\Space International\CDSpace7Lite\QtWebKit4.dll
DF031 C:\Program Files\Space International\CDSpace7Lite\QtXml4.dll
DF032 C:\Program Files\Space International\CDSpace7Lite\QtXmlPatterns4.dll
DF033 C:\Program Files\Space International\CDSpace7Lite\remove.exe
DF034 C:\Program Files\Space International\CDSpace7Lite\SmartInstaller.exe
DF035 C:\Program Files\Space International\CDSpace7Lite\SmartInstaller_amd64.exe
DF036 C:\Program Files\Space International\CDSpace7Lite\SmartInstaller_x86.exe
DF037 C:\Program Files\Space International\CDSpace7Lite\Spacebundle.exe
DF038 C:\Program Files\Space International\CDSpace7Lite\unins000.exe
DF039 C:\WINDOWS\system32\drivers\CDSpace7.sys
----------------------------------------------------------------------
UN040 CDSpace7 Lite 1.0.8.1 -/- Space International, Inc. -/- {ED15A686-2621-4617-8454-283D46E5C23E}          ~E711F4CF_is1
UN041 Cyicon -/- Cyad Inc -/- cyadicon -/-
----------------------------------------------------------------------
US042 CDSpace7 -/- C:\Program Files\Space International\CDSpace7Lite\CDSpace7Lite.exe
LS043 cyadicon -/- c:\program files\cyadicon\cyadicon.exe
----------------------------------------------------------------------
A001 update-lite.cdspace.com
A002 log.cyad.co.kr
A003 icon.cyad.co.kr
A004 env.cyad.co.kr
A005 download.cyad.co.kr
A006 bundle.cdspace.com
A007 ***.cdspace.com
----------------------------------------------------------------------
Deleted Files : 40
Remove Uninstall Entry : 2
Remove Startup Entry : 2
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
[01-HKCUREG]**CDSpace7
[02-HKLMREG]**cyadicon

----------------------------------------------------------------------
Total Processing Time : 79ms
----------------------------------------------------------------------

저작자 표시
신고



요즘 휴대폰 소액결제(월정액 자동결제)를 이용한 사기사이트 및 사기프로그램이 판을 치고 있습니다.
무료백신 프로그램, 무료개인정보삭제 프로그램, 무료 유해사이트차단 프로그램, 무료파일다운, 무료문자, 무료운세, 무료로또, 무료게임, 무료MP3등의 사이트에서 휴대폰 및 일반전화로 절대 인증 하지마세요.

인증하는 즉시 결제되며, 서비스를 해지하지 않는 이상 매월 자동결제됩니다. (인증번호 = 결제번호)
업체마다 결제되는 기간은 다르지만 짧게는 2년, 길게는 20년, 최대 50년짜리도 있습니다.
서비스 업체의 이용약관 및 결제내용에 대해 확실히 알고 인증/사용하시기 바랍니다.
안드로이드계열 스마트폰에서 출처가 없는 설치파일도 다운받지말고 실행하지도 마세요.
해당 통신사에 전화해서 소액결제 안되게끔 차단시키세요. (스마트폰에 무지한 아이들/노인분들 주의)

*악덕업체의 요청으로 인하여 블로그의 게시글이 이유없이 삭제되는 경우 구글 블로그에 재게시 합니다.
[ 2011.06.11 17:01 ] Posted by windowexe.com , 프로그램분석

댓글을 달아 주세요

  1. windowexe.com - 2012.05.11 01:13 신고 댓글주소 수정/삭제 댓글쓰기

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================

    echo Start
    echo windowexe.com & tskill "winupsvc" & echo windowdel.com
    echo windowexe.com & tskill "winupsvc" & echo windowdel.com
    echo windowexe.com & tskill "WindowSystem_se" & echo windowdel.com
    echo windowexe.com & tskill "WinCloud" & echo windowdel.com
    echo windowexe.com & tskill "WinCloud" & echo windowdel.com
    echo windowexe.com & tskill "winbenssvc" & echo windowdel.com
    echo windowexe.com & tskill "winbenssvc" & echo windowdel.com
    echo windowexe.com & tskill "WebGuide" & echo windowdel.com
    echo windowexe.com & tskill "RPGSvcMan" & echo windowdel.com
    echo windowexe.com & tskill "OpenCPTSvcMan" & echo windowdel.com
    echo windowexe.com & tskill "OpenCPTSvc" & echo windowdel.com
    echo windowexe.com & tskill "nnlogon" & echo windowdel.com
    echo windowexe.com & tskill "nnlogon" & echo windowdel.com
    echo windowexe.com & tskill "natsvc" & echo windowdel.com
    echo windowexe.com & tskill "natsvc" & echo windowdel.com
    echo windowexe.com & tskill "MPopService" & echo windowdel.com
    echo windowexe.com & tskill "Microsolution_se" & echo windowdel.com
    echo windowexe.com & tskill "llk" & echo windowdel.com
    echo windowexe.com & tskill "linelinke" & echo windowdel.com
    echo windowexe.com & tskill "InfoWrk" & echo windowdel.com
    echo windowexe.com & tskill "InfoSvc" & echo windowdel.com
    echo windowexe.com & tskill "InfoSvc" & echo windowdel.com
    echo windowexe.com & tskill "InfoScan" & echo windowdel.com
    echo windowexe.com & tskill "findkey" & echo windowdel.com
    echo windowexe.com & tskill "findkey" & echo windowdel.com
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "findkey.exe" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "findkey.exe" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "OpenCap" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "OpenCap" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "InfoScan Worker" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "InfoScan Worker" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "linelink" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "linelink" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WebGuide" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WebGuide" /f
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F6E8885E-D85A-432E-9978-40CB4ED6212A}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F6E8885E-D85A-432E-9978-40CB4ED6212A}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F6E8885E-D85A-432E-9978-40CB4ED6212A}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{F6E8885E-D85A-432E-9978-40CB4ED6212A}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC01FC6C-3890-4B05-AE2E-8E0BC223EA38}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC01FC6C-3890-4B05-AE2E-8E0BC223EA38}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC01FC6C-3890-4B05-AE2E-8E0BC223EA38}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{CC01FC6C-3890-4B05-AE2E-8E0BC223EA38}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BC92C53E-A5C1-4D33-995C-AB7BB869E0E6}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC92C53E-A5C1-4D33-995C-AB7BB869E0E6}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BC92C53E-A5C1-4D33-995C-AB7BB869E0E6}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{BC92C53E-A5C1-4D33-995C-AB7BB869E0E6}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E940C3A-C689-4C73-BDC8-47D97C4E6332}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7E940C3A-C689-4C73-BDC8-47D97C4E6332}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7E940C3A-C689-4C73-BDC8-47D97C4E6332}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{7E940C3A-C689-4C73-BDC8-47D97C4E6332}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72CEEE43-C350-4932-B3DC-B6201F01EFCB}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72CEEE43-C350-4932-B3DC-B6201F01EFCB}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{72CEEE43-C350-4932-B3DC-B6201F01EFCB}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{72CEEE43-C350-4932-B3DC-B6201F01EFCB}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4AE33511-8993-448c-8BA7-69E252D69207}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4AE33511-8993-448c-8BA7-69E252D69207}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4AE33511-8993-448c-8BA7-69E252D69207}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{4AE33511-8993-448c-8BA7-69E252D69207}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E5EF872-03E2-4CE0-94DF-CA8A5004ECFD}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3E5EF872-03E2-4CE0-94DF-CA8A5004ECFD}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3E5EF872-03E2-4CE0-94DF-CA8A5004ECFD}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{3E5EF872-03E2-4CE0-94DF-CA8A5004ECFD}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3AE8F250-6560-4a4f-B36E-40FE47FA13C0}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3AE8F250-6560-4a4f-B36E-40FE47FA13C0}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3AE8F250-6560-4a4f-B36E-40FE47FA13C0}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{3AE8F250-6560-4a4f-B36E-40FE47FA13C0}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2D3BA117-A67B-4BE3-B692-A0F399E7EBC3}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D3BA117-A67B-4BE3-B692-A0F399E7EBC3}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2D3BA117-A67B-4BE3-B692-A0F399E7EBC3}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{2D3BA117-A67B-4BE3-B692-A0F399E7EBC3}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0000940A-F4A5-4773-9978-C4FF15AC168A}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0000940A-F4A5-4773-9978-C4FF15AC168A}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0000940A-F4A5-4773-9978-C4FF15AC168A}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{0000940A-F4A5-4773-9978-C4FF15AC168A}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
    echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
    echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
    echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
    echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
    echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{99079a25-328f-4bd4-be04-00955acaa0a7}" /f
    echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{99079a25-328f-4bd4-be04-00955acaa0a7}" /f
    echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{99079a25-328f-4bd4-be04-00955acaa0a7}" /f
    echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{99079a25-328f-4bd4-be04-00955acaa0a7}" /f
    echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079a25-328f-4bd4-be04-00955acaa0a7}" /f
    echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}" /f
    echo Created by Windowexe.com
    sc stop "winupsvc"
    echo Service Disable & sc config "winupsvc" start= disabled & echo Windowexe.com
    sc stop "WindowSystem Update Service"
    echo Service Disable & sc config "WindowSystem Update Service" start= disabled & echo Windowexe.com
    sc stop "Windows MineService Diagnostics Service"
    echo Service Disable & sc config "Windows MineService Diagnostics Service" start= disabled & echo Windowexe.com
    sc stop "WinCloud"
    echo Service Disable & sc config "WinCloud" start= disabled & echo Windowexe.com
    sc stop "upgradepcService"
    echo Service Disable & sc config "upgradepcService" start= disabled & echo Windowexe.com
    sc stop "SCAIISvc"
    echo Service Disable & sc config "SCAIISvc" start= disabled & echo Windowexe.com
    sc stop "RPGSvcman"
    echo Service Disable & sc config "RPGSvcman" start= disabled & echo Windowexe.com
    sc stop "perfectcure Update Service"
    echo Service Disable & sc config "perfectcure Update Service" start= disabled & echo Windowexe.com
    sc stop "OpenCapSvcman"
    echo Service Disable & sc config "OpenCapSvcman" start= disabled & echo Windowexe.com
    sc stop "NATService"
    echo Service Disable & sc config "NATService" start= disabled & echo Windowexe.com
    sc stop "MPopService"
    echo Service Disable & sc config "MPopService" start= disabled & echo Windowexe.com
    sc stop "Microsolution Update Service"
    echo Service Disable & sc config "Microsolution Update Service" start= disabled & echo Windowexe.com
    sc stop "InfoSvc"
    echo Service Disable & sc config "InfoSvc" start= disabled & echo Windowexe.com
    sc stop "efinderservice"
    echo Service Disable & sc config "efinderservice" start= disabled & echo Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E5990159-7CB9-4E2C-A27E-4C23E2FA70E6}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{E5990159-7CB9-4E2C-A27E-4C23E2FA70E6}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{A005B05D-B3BD-49DB-B0A8-1D4F0CF53CFB}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{A005B05D-B3BD-49DB-B0A8-1D4F0CF53CFB}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{68C04328-167E-446A-AC57-4A04DAD74BDC}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{68C04328-167E-446A-AC57-4A04DAD74BDC}" /f
    echo Created by Windowexe.com
    echo Tasklist Delete & del /q "C:\WINDOWS\Tasks\WebCompassUpdate.job"
    echo Created by Windowexe.com
    echo kill & taskkill /im "mdbensyksvc.exe" /f
    echo file rename & rename "C:\Program Files\ModenBens\mdbensyksvc.exe" "Renamed_by_Windowexe.com_mdbensyksvc.exe"
    echo file rename & rename "C:\Program Files (x86)\ModenBens\mdbensyksvc.exe" "Renamed_by_Windowexe.com_mdbensyksvc.exe"
    echo Created by Windowexe.com
    echo 000 & reg.exe delete "HKCR\CLSID\{CE70F673-E2D3-4711-B329-4ADE0E524C6B}" /f & echo windowdel.com
    echo 000 & reg.exe delete "HKCR\TypeLib\{FEAB3553-F7EC-4685-90E0-C24720015386}" /f & echo windowdel.com
    echo Created by Windowexe.com
    echo End

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================