애드웨어, 허위백신, 팝업광고, 쇼핑몰 바로가기, 악성툴바, 각종 개쓰레기 프로그램 삭제 요청하기
이용약관을 안내하며 컴퓨터에 설치하는 개쓰레기 프로그램들은 백신으로 백날 돌려봐야 검색이 안됩니다.
개쓰레기 프로그램들은 아주 지능적이라서 전문가가 아니고서는 찾아내기가 어렵습니다.


----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Microsoft Windows XP Service Pack 3(5.1.2600.196608)
Intel(R) Core(TM) i3 CPU       M 380  @ 2.53GHz / 767.48 MB
x86 Family 6 Model 37 Stepping 5
Date : 2011-12-08
----------------------------------------------------------------------
DF000 C:\Documents and Settings\Administrator\Application Data\RapidGet\RapidGet.exe
DF001 C:\Documents and Settings\Administrator\Application Data\RapidGet\RPDMgr.dll
DF002 C:\Documents and Settings\Administrator\Application Data\RapidGet\rpgchk.exe
DF003 C:\Documents and Settings\Administrator\Application Data\RapidGet\RPGManager.exe
DF004 C:\Documents and Settings\Administrator\Application Data\RapidGet\RPGSvcMan.exe
DF005 C:\Documents and Settings\Administrator\Application Data\RapidGet\RPGUnist.exe
DF006 C:\Documents and Settings\Administrator\Application Data\WerPingGood\WerPingGood.exe
DF007 C:\Documents and Settings\Administrator\Application Data\WerPingGood\WerPingHelper.dll
DF008 C:\Documents and Settings\Administrator\Application Data\WerPingGood\WPUninst.exe
DF009 C:\Documents and Settings\Administrator\Application Data\WerPingGood\WPUpdate.exe
DF010 C:\Documents and Settings\Administrator\My Documents\file_unlocker1.9.0.exe
DF011 C:\Program Files\DOWNLOAD LAUNCHER\pds_launcher.exe
DF012 C:\Program Files\DOWNLOAD LAUNCHER\uninst.exe
DF013 C:\Program Files\EasyOn\EasyOn.dll
DF014 C:\Program Files\EasyOn\EasyOn.exe
DF015 C:\Program Files\EasyOn\Uninstall.exe
DF016 C:\Program Files\FineTop\FineTop.dll
DF017 C:\Program Files\FineTop\FineTop.exe
DF018 C:\Program Files\FineTop\Uninstall.exe
DF019 C:\Program Files\microWebAD\microWebAD.exe
DF020 C:\Program Files\PostTip\PostTip.dll
DF021 C:\Program Files\PostTip\PostTip.exe
DF022 C:\Program Files\PostTip\uninstall.exe
DF023 C:\Program Files\WTool\Uninstall.exe
DF024 C:\Program Files\WTool\WTool.dll
DF025 C:\Program Files\WTool\WTool.exe
----------------------------------------------------------------------
SC026 RPGSvcman -/- RPGSvcman -/- - -/-  -/- C:\Documents and Settings\Administrator\Application Data\RapidGet\RPGSvcMan.exe
----------------------------------------------------------------------
UN027 DOWNLOAD LAUNCHER CTRL 1.0 -/- JE -/- DOWNLOAD LAUNCHER CTRL -/- - -/- -
UN028 EasyOn -/- - -/- EasyOn -/- - -/- -
UN029 FineTop -/- - -/- FineTop -/- - -/- -
UN030 MicroWebAD Installer 1.1 -/- MicroWebAD Installer 1.1 -/- microWebAD.exe -/- - -/-
UN031 PostTip -/- - -/- PostTip -/- - -/- -
UN032 Windows Download Manager RapidGet -/- - -/- RapidGet -/- - -/- -
UN033 WTL C++ Werping Manager -/- Werping -/- WerPingGood -/- - -/-
UN034 WTool -/- - -/- WTool -/- - -/- -
----------------------------------------------------------------------
LS035 DOWNLOAD LAUNCHER -/- C:\Program Files\DOWNLOAD LAUNCHER\pds_launcher.exe /up
LS036 microWebAD.exe -/- C:\Program Files\microWebAD\microWebAD.exe
LS037 PostTip -/- C:\Program Files\PostTip\PostTip.exe
LS038 WTool -/- C:\Program Files\WTool\WTool.exe
LS039 RapidGet -/- C:\Documents and Settings\Administrator\Application Data\RapidGet\RPGManager.exe
LS040 rpga -/- C:\Documents and Settings\Administrator\Application Data\RapidGet\rpgchk.exe
LS041 EasyOn -/- C:\Program Files\EasyOn\EasyOn.exe
LS042 FineTop -/- C:\Program Files\FineTop\FineTop.exe
----------------------------------------------------------------------
BH043 WerPingHelperCtrl Class -/- C:\Documents and Settings\Administrator\Application Data\WerPingGood\WerPingHelper.dll -/- {114EB2A5-9A65-4FC2-A6E3-9949666EBA72}
BH044 EasyOnHelper -/- C:\Program Files\EasyOn\EasyOn.dll -/- {1CE681DC-1190-40EF-85A9-ADE47098CF51}
BH045 WToolHelper -/- C:\Program Files\WTool\WTool.dll -/- {84395E42-9FF9-4B85-9264-B1762D069593}
BH046 PostTip -/- C:\Program Files\PostTip\PostTip.dll -/- {C4BF6897-41A2-454b-AC3B-437F30BEA671}
BH047 FineTop -/- C:\Program Files\FineTop\FineTop.dll -/- {CBF53489-AD8D-4637-965A-413861EEC7CF}
----------------------------------------------------------------------
Deleted Files : 26
Remove Service : 1
Remove Uninstall Entry : 8
Remove Startup Entry : 8
Remove Browser Helper Object : 5
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
[02-HKLMREG]**DOWNLOAD LAUNCHER
[02-HKLMREG]**microWebAD.exe
[02-HKLMREG]**PostTip
[02-HKLMREG]**WTool
[02-HKLMREG]**RapidGet
[02-HKLMREG]**rpga
[02-HKLMREG]**EasyOn
[02-HKLMREG]**FineTop
[03-BHOCLSD]**{114EB2A5-9A65-4FC2-A6E3-9949666EBA72}
[03-BHOCLSD]**{1CE681DC-1190-40EF-85A9-ADE47098CF51}
[03-BHOCLSD]**{84395E42-9FF9-4B85-9264-B1762D069593}
[03-BHOCLSD]**{C4BF6897-41A2-454b-AC3B-437F30BEA671}
[03-BHOCLSD]**{CBF53489-AD8D-4637-965A-413861EEC7CF}
[05-SERVICE]**RPGSvcman
----------------------------------------------------------------------
Total Processing Time : 53ms
----------------------------------------------------------------------
신고



요즘 휴대폰 소액결제(월정액 자동결제)를 이용한 사기사이트 및 사기프로그램이 판을 치고 있습니다.
무료백신 프로그램, 무료개인정보삭제 프로그램, 무료 유해사이트차단 프로그램, 무료파일다운, 무료문자, 무료운세, 무료로또, 무료게임, 무료MP3등의 사이트에서 휴대폰 및 일반전화로 절대 인증 하지마세요.

인증하는 즉시 결제되며, 서비스를 해지하지 않는 이상 매월 자동결제됩니다. (인증번호 = 결제번호)
업체마다 결제되는 기간은 다르지만 짧게는 2년, 길게는 20년, 최대 50년짜리도 있습니다.
서비스 업체의 이용약관 및 결제내용에 대해 확실히 알고 인증/사용하시기 바랍니다.
안드로이드계열 스마트폰에서 출처가 없는 설치파일도 다운받지말고 실행하지도 마세요.
해당 통신사에 전화해서 소액결제 안되게끔 차단시키세요. (스마트폰에 무지한 아이들/노인분들 주의)

*악덕업체의 요청으로 인하여 블로그의 게시글이 이유없이 삭제되는 경우 구글 블로그에 재게시 합니다.
[ 2011.12.09 01:46 ] Posted by windowexe.com , 프로그램분석

댓글을 달아 주세요

  1. windowexe.com - 2012.01.31 22:39 신고 댓글주소 수정/삭제 댓글쓰기


    ======================================================================
    ======================================================================

    echo Start
    echo windowexe.com & tskill "DirectKeyword2" & echo windowdel.com
    echo windowexe.com & tskill "EasyOn" & echo windowdel.com
    echo windowexe.com & tskill "GDownService" & echo windowdel.com
    echo windowexe.com & tskill "NateFinderUpt" & echo windowdel.com
    echo windowexe.com & tskill "natsvc" & echo windowdel.com
    echo windowexe.com & tskill "rpgchk" & echo windowdel.com
    echo windowexe.com & tskill "RPGManager" & echo windowdel.com
    echo windowexe.com & tskill "RPGSvcMan" & echo windowdel.com
    echo windowexe.com & tskill "SmartFindUpt" & echo windowdel.com
    echo windowexe.com & tskill "SmartPopSvc" & echo windowdel.com
    echo windowexe.com & tskill "SmartPopUpt" & echo windowdel.com
    echo windowexe.com & tskill "V3LFuns" & echo windowdel.com
    echo windowexe.com & tskill "WinAgt" & echo windowdel.com
    echo windowexe.com & tskill "WindowLivePot" & echo windowdel.com
    echo windowexe.com & tskill "winupsvc" & echo windowdel.com
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "AhnLiter" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "AhnLiter" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "howcodecopen" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "howcodecopen" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "howcodechper" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "howcodechper" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "howcodec" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "howcodec" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WindowLivePot" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WindowLivePot" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "DirectKeyword2" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "DirectKeyword2" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "smartsafer main" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "smartsafer main" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "howcodec" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "howcodec" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "howcodecopen" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "howcodecopen" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "EasyOn" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "EasyOn" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "RapidGet" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "RapidGet" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "rpga" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "rpga" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "NateFinder" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "NateFinder" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WinAgt" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WinAgt" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SmartPopUpdater" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SmartPopUpdater" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SmartFind" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SmartFind" /f
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0858F724-72F0-45C6-95FF-16FCB0744972}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0858F724-72F0-45C6-95FF-16FCB0744972}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0858F724-72F0-45C6-95FF-16FCB0744972}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{0858F724-72F0-45C6-95FF-16FCB0744972}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0A4ABCA7-7612-4BA1-B1D3-4D56D964D3F4}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0A4ABCA7-7612-4BA1-B1D3-4D56D964D3F4}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0A4ABCA7-7612-4BA1-B1D3-4D56D964D3F4}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{0A4ABCA7-7612-4BA1-B1D3-4D56D964D3F4}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15DFCC55-B9C5-42E3-BFFA-9BBB4E6F9CE0}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15DFCC55-B9C5-42E3-BFFA-9BBB4E6F9CE0}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{15DFCC55-B9C5-42E3-BFFA-9BBB4E6F9CE0}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{15DFCC55-B9C5-42E3-BFFA-9BBB4E6F9CE0}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CE681DC-1190-40EF-85A9-ADE47098CF51}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CE681DC-1190-40EF-85A9-ADE47098CF51}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CE681DC-1190-40EF-85A9-ADE47098CF51}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{1CE681DC-1190-40EF-85A9-ADE47098CF51}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21FFEC32-59FF-4A1F-BB42-7A315637617F}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{21FFEC32-59FF-4A1F-BB42-7A315637617F}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{21FFEC32-59FF-4A1F-BB42-7A315637617F}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{21FFEC32-59FF-4A1F-BB42-7A315637617F}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33299B97-2A31-4d1d-A3F2-DAA5A90F5894}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{33299B97-2A31-4d1d-A3F2-DAA5A90F5894}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{33299B97-2A31-4d1d-A3F2-DAA5A90F5894}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{33299B97-2A31-4d1d-A3F2-DAA5A90F5894}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{375A6AB2-FEEC-445D-B853-2139FB561F80}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{375A6AB2-FEEC-445D-B853-2139FB561F80}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{375A6AB2-FEEC-445D-B853-2139FB561F80}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{375A6AB2-FEEC-445D-B853-2139FB561F80}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5D19999A-E977-46A5-BD6A-6E816262F399}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D19999A-E977-46A5-BD6A-6E816262F399}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5D19999A-E977-46A5-BD6A-6E816262F399}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{5D19999A-E977-46A5-BD6A-6E816262F399}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67421A26-71F2-4E57-89B2-E49C6FD90DA1}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67421A26-71F2-4E57-89B2-E49C6FD90DA1}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{67421A26-71F2-4E57-89B2-E49C6FD90DA1}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{67421A26-71F2-4E57-89B2-E49C6FD90DA1}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7AE8CE5B-53AE-4824-84EF-800A0EC46BB8}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7AE8CE5B-53AE-4824-84EF-800A0EC46BB8}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7AE8CE5B-53AE-4824-84EF-800A0EC46BB8}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{7AE8CE5B-53AE-4824-84EF-800A0EC46BB8}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BF92C372-B2DC-4C05-A068-B90A4DD44710}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BF92C372-B2DC-4C05-A068-B90A4DD44710}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BF92C372-B2DC-4C05-A068-B90A4DD44710}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{BF92C372-B2DC-4C05-A068-B90A4DD44710}" /f
    echo Created by Windowexe.com
    sc stop "AuthExtractor"
    echo Service Disable & sc config "AuthExtractor" start= disabled & echo Windowexe.com
    sc stop "GDownService"
    echo Service Disable & sc config "GDownService" start= disabled & echo Windowexe.com
    sc stop "NATService"
    echo Service Disable & sc config "NATService" start= disabled & echo Windowexe.com
    sc stop "RPGSvcman"
    echo Service Disable & sc config "RPGSvcman" start= disabled & echo Windowexe.com
    sc stop "SmartPopService"
    echo Service Disable & sc config "SmartPopService" start= disabled & echo Windowexe.com
    sc stop "Windows MineService Diagnostics Service"
    echo Service Disable & sc config "Windows MineService Diagnostics Service" start= disabled & echo Windowexe.com
    sc stop "winupsvc"
    echo Service Disable & sc config "winupsvc" start= disabled & echo Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{013BCEA5-8309-448b-8604-85F23D7861A5}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{013BCEA5-8309-448b-8604-85F23D7861A5}" /f
    echo Created by Windowexe.com
    echo kill & taskkill /im "mbdenzauwsvc.exe" /f
    echo file rename & rename "C:\Program Files\MobinDenza\mbdenzauwsvc.exe" "Renamed_by_Windowexe.com_mbdenzauwsvc.exe"
    echo file rename & rename "C:\Program Files (x86)\MobinDenza\mbdenzauwsvc.exe" "Renamed_by_Windowexe.com_mbdenzauwsvc.exe"
    echo Created by Windowexe.com
    echo 000 & reg.exe delete "HKCR\CLSID\{CE70F673-E2D3-4711-B329-4ADE0E524C6B}" /f & echo windowdel.com
    echo 000 & reg.exe delete "HKCR\TypeLib\{FEAB3553-F7EC-4685-90E0-C24720015386}" /f & echo windowdel.com
    echo Created by Windowexe.com
    echo 000 & reg.exe add "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /d "http://kr.yahoo.com" /f & echo windowdel.com
    echo Created by Windowexe.com
    echo End

    ======================================================================
    ======================================================================