애드웨어, 허위백신, 팝업광고, 쇼핑몰 바로가기, 악성툴바, 각종 개쓰레기 프로그램 삭제 요청하기
이용약관을 안내하며 컴퓨터에 설치하는 개쓰레기 프로그램들은 백신으로 백날 돌려봐야 검색이 안됩니다.
개쓰레기 프로그램들은 아주 지능적이라서 전문가가 아니고서는 찾아내기가 어렵습니다.


BabylonToolbar 프로그램 설치 로그입니다.
제작사에서도 배포하지만 스폰서프로그램으로 주로 설치됩니다.

----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Microsoft Windows XP Service Pack 3(5.1.2600.196608)
Intel(R) Core(TM) i3 CPU       M 380  @ 2.53GHz / 767.48 MB
x86 Family 6 Model 37 Stepping 5
Date : 2011-08-18
----------------------------------------------------------------------
DF000 C:\Documents and Settings\Administrator\Local Settings\Application Data\Babylon\Setup\BabylonTBUpdater.dll
DF001 C:\Documents and Settings\Administrator\Local Settings\Application Data\Babylon\Setup\BabylonTBUpdater.exe
DF002 C:\Documents and Settings\Administrator\Local Settings\Application Data\Babylon\Setup\Setup.exe
DF003 C:\Documents and Settings\Administrator\Local Settings\Application Data\Babylon\Setup\sqlite3.dll
DF004 C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarApp.dll
DF005 C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarEng.dll
DF006 C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarsrv.exe
DF007 C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll
DF008 C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll
DF009 C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.31.2\uninstall.exe
----------------------------------------------------------------------
UN227 Babylon toolbar on IE -/- - -/- BabylonToolbar -/- - -/- -
----------------------------------------------------------------------
BH231 Babylon toolbar helper -/- C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll -/- {2EECD738-5844-4a99-B4B6-146BF802613B}
----------------------------------------------------------------------
TB232 Babylon Toolbar -/- C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll -/- {98889811-442D-49dd-99D7-DC866BE87DBC}
----------------------------------------------------------------------
Remove Uninstall Entry : 1
Remove Browser Helper Object : 1
Remove Toolbar : 1
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
[03-BHOCLSD]**{2EECD738-5844-4a99-B4B6-146BF802613B}
[04-TOOLBAR]**{98889811-442D-49dd-99D7-DC866BE87DBC}
----------------------------------------------------------------------
Total Processing Time : 450ms
----------------------------------------------------------------------
위 로그 내용이 뭔지 이해할 필요는 없습니다.

아래링크에 삭제방법이 있으니 명령프롬프트에서 복사/붙여넣기만 하면 모두 삭제됩니다.
http://www.windowdel.com/bbs/board.php?bo_table=remove&wr_id=905
신고



요즘 휴대폰 소액결제(월정액 자동결제)를 이용한 사기사이트 및 사기프로그램이 판을 치고 있습니다.
무료백신 프로그램, 무료개인정보삭제 프로그램, 무료 유해사이트차단 프로그램, 무료파일다운, 무료문자, 무료운세, 무료로또, 무료게임, 무료MP3등의 사이트에서 휴대폰 및 일반전화로 절대 인증 하지마세요.

인증하는 즉시 결제되며, 서비스를 해지하지 않는 이상 매월 자동결제됩니다. (인증번호 = 결제번호)
업체마다 결제되는 기간은 다르지만 짧게는 2년, 길게는 20년, 최대 50년짜리도 있습니다.
서비스 업체의 이용약관 및 결제내용에 대해 확실히 알고 인증/사용하시기 바랍니다.
안드로이드계열 스마트폰에서 출처가 없는 설치파일도 다운받지말고 실행하지도 마세요.
해당 통신사에 전화해서 소액결제 안되게끔 차단시키세요. (스마트폰에 무지한 아이들/노인분들 주의)

*악덕업체의 요청으로 인하여 블로그의 게시글이 이유없이 삭제되는 경우 구글 블로그에 재게시 합니다.
[ 2011.08.18 17:20 ] Posted by windowexe.com , 프로그램분석

댓글을 달아 주세요

  1. windowexe.com - 2012.02.29 23:13 신고 댓글주소 수정/삭제 댓글쓰기

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================

    echo Start
    echo windowexe.com & tskill "comsvr" & echo windowdel.com
    echo windowexe.com & tskill "DirectKeyword2" & echo windowdel.com
    echo windowexe.com & tskill "EasyOn" & echo windowdel.com
    echo windowexe.com & tskill "findkey" & echo windowdel.com
    echo windowexe.com & tskill "FineTop" & echo windowdel.com
    echo windowexe.com & tskill "goormaUpdater" & echo windowdel.com
    echo windowexe.com & tskill "iesync" & echo windowdel.com
    echo windowexe.com & tskill "InfoScan" & echo windowdel.com
    echo windowexe.com & tskill "InfoSvc" & echo windowdel.com
    echo windowexe.com & tskill "InfoWrk" & echo windowdel.com
    echo windowexe.com & tskill "IPlusUpdate" & echo windowdel.com
    echo windowexe.com & tskill "MicroLabCon" & echo windowdel.com
    echo windowexe.com & tskill "MicroLabProc" & echo windowdel.com
    echo windowexe.com & tskill "OpenPot" & echo windowdel.com
    echo windowexe.com & tskill "pinomate" & echo windowdel.com
    echo windowexe.com & tskill "popsi" & echo windowdel.com
    echo windowexe.com & tskill "rpgchk" & echo windowdel.com
    echo windowexe.com & tskill "RPGManager" & echo windowdel.com
    echo windowexe.com & tskill "RPGSvcMan" & echo windowdel.com
    echo windowexe.com & tskill "SafeTerra" & echo windowdel.com
    echo windowexe.com & tskill "SafeTerraUpdate" & echo windowdel.com
    echo windowexe.com & tskill "SmartFindUpt" & echo windowdel.com
    echo windowexe.com & tskill "WallTab" & echo windowdel.com
    echo windowexe.com & tskill "WallTabUDF" & echo windowdel.com
    echo windowexe.com & tskill "wcmgr" & echo windowdel.com
    echo windowexe.com & tskill "winkucsvc" & echo windowdel.com
    echo windowexe.com & tskill "WTool" & echo windowdel.com
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroLabCon" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroLabCon" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "pinomate" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "pinomate" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Safeterra" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Safeterra" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "DirectKeyword2" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "DirectKeyword2" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "4shared Desktop" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "4shared Desktop" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Goorma" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Goorma" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WallTabUDF" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WallTabUDF" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WallTab" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WallTab" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "CommonSvr" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "CommonSvr" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "popsi" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "popsi" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "iPop" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "iPop" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "comsvr" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "comsvr" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "RapidGet" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "RapidGet" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "rpga" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "rpga" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "FineTop" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "FineTop" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "EasyOn" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "EasyOn" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "wcmgr.exe" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "wcmgr.exe" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WTool" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WTool" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SmartFind" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SmartFind" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "4shared Update" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "4shared Update" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "IPlusUpdate" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "IPlusUpdate" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "findkey.exe" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "findkey.exe" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "InfoScan Worker" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "InfoScan Worker" /f
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0000940A-F4A5-4773-9978-C4FF15AC168A}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0000940A-F4A5-4773-9978-C4FF15AC168A}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0000940A-F4A5-4773-9978-C4FF15AC168A}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{0000940A-F4A5-4773-9978-C4FF15AC168A}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0BAB0BFA-D4FA-4965-94E2-5269BB66CB6B}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0BAB0BFA-D4FA-4965-94E2-5269BB66CB6B}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0BAB0BFA-D4FA-4965-94E2-5269BB66CB6B}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{0BAB0BFA-D4FA-4965-94E2-5269BB66CB6B}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CE681DC-1190-40EF-85A9-ADE47098CF51}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CE681DC-1190-40EF-85A9-ADE47098CF51}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CE681DC-1190-40EF-85A9-ADE47098CF51}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{1CE681DC-1190-40EF-85A9-ADE47098CF51}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{23C7E613-D0B3-422D-884C-2B6173435214}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{23C7E613-D0B3-422D-884C-2B6173435214}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{23C7E613-D0B3-422D-884C-2B6173435214}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{23C7E613-D0B3-422D-884C-2B6173435214}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2D3BA117-A67B-4BE3-B692-A0F399E7EBC3}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D3BA117-A67B-4BE3-B692-A0F399E7EBC3}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2D3BA117-A67B-4BE3-B692-A0F399E7EBC3}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{2D3BA117-A67B-4BE3-B692-A0F399E7EBC3}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{37C80584-566A-45e7-8BBA-02D953F65732}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{37C80584-566A-45e7-8BBA-02D953F65732}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{37C80584-566A-45e7-8BBA-02D953F65732}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{37C80584-566A-45e7-8BBA-02D953F65732}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84395E42-9FF9-4B85-9264-B1762D069593}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{84395E42-9FF9-4B85-9264-B1762D069593}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{84395E42-9FF9-4B85-9264-B1762D069593}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{84395E42-9FF9-4B85-9264-B1762D069593}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{884EAA16-CA35-4666-845A-DC084DCDF356}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{884EAA16-CA35-4666-845A-DC084DCDF356}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{884EAA16-CA35-4666-845A-DC084DCDF356}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{884EAA16-CA35-4666-845A-DC084DCDF356}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE48C704-8876-4EB2-9227-6CA5382694C5}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE48C704-8876-4EB2-9227-6CA5382694C5}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE48C704-8876-4EB2-9227-6CA5382694C5}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{AE48C704-8876-4EB2-9227-6CA5382694C5}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BEA50D29-A4D4-49CD-81DE-A506F57363DC}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEA50D29-A4D4-49CD-81DE-A506F57363DC}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BEA50D29-A4D4-49CD-81DE-A506F57363DC}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{BEA50D29-A4D4-49CD-81DE-A506F57363DC}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CBF53489-AD8D-4637-965A-413861EEC7CF}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CBF53489-AD8D-4637-965A-413861EEC7CF}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CBF53489-AD8D-4637-965A-413861EEC7CF}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{CBF53489-AD8D-4637-965A-413861EEC7CF}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}" /f
    echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}" /f
    echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}" /f
    echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}" /f
    echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}" /f
    echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}" /f
    echo Created by Windowexe.com
    sc stop "Ez2pop"
    echo Service Disable & sc config "Ez2pop" start= disabled & echo Windowexe.com
    sc stop "InfoSvc"
    echo Service Disable & sc config "InfoSvc" start= disabled & echo Windowexe.com
    sc stop "RPGSvcman"
    echo Service Disable & sc config "RPGSvcman" start= disabled & echo Windowexe.com
    sc stop "Windows MineService Diagnostics Service"
    echo Service Disable & sc config "Windows MineService Diagnostics Service" start= disabled & echo Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{013BCEA5-8309-448b-8604-85F23D7861A5}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{013BCEA5-8309-448b-8604-85F23D7861A5}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{143BCEC5-C753-48eb-BD44-EEFFA37CEB5B}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{143BCEC5-C753-48eb-BD44-EEFFA37CEB5B}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{57D1CDEE-1880-484f-8361-55D7626D2679}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{57D1CDEE-1880-484f-8361-55D7626D2679}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{664290A3-9ADB-4e0d-9762-EF088688AD41}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{664290A3-9ADB-4e0d-9762-EF088688AD41}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{68C04328-167E-446A-AC57-4A04DAD74BDC}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{68C04328-167E-446A-AC57-4A04DAD74BDC}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{A005B05D-B3BD-49DB-B0A8-1D4F0CF53CFB}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{A005B05D-B3BD-49DB-B0A8-1D4F0CF53CFB}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D51609DD-8FD8-4eb1-9714-CA093C12A0B8}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{D51609DD-8FD8-4eb1-9714-CA093C12A0B8}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E5990159-7CB9-4E2C-A27E-4C23E2FA70E6}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{E5990159-7CB9-4E2C-A27E-4C23E2FA70E6}" /f
    echo Created by Windowexe.com
    echo schtasks Delete & schtasks /delete /tn "WebCompassUpdate" /f
    echo Created by Windowexe.com
    echo Tasklist Delete & del /q "C:\WINDOWS\Tasks\WebCompassUpdate.job"
    echo Created by Windowexe.com
    echo kill & taskkill /im "mdkucyesvc.exe" /f
    echo file rename & rename "C:\Program Files\ModenKuc\mdkucyesvc.exe" "Renamed_by_Windowexe.com_mdkucyesvc.exe"
    echo file rename & rename "C:\Program Files (x86)\ModenKuc\mdkucyesvc.exe" "Renamed_by_Windowexe.com_mdkucyesvc.exe"
    echo Created by Windowexe.com
    echo 000 & reg.exe delete "HKCR\CLSID\{CE70F673-E2D3-4711-B329-4ADE0E524C6B}" /f & echo windowdel.com
    echo 000 & reg.exe delete "HKCR\TypeLib\{FEAB3553-F7EC-4685-90E0-C24720015386}" /f & echo windowdel.com
    echo Created by Windowexe.com
    echo End

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================