애드웨어, 허위백신, 팝업광고, 쇼핑몰 바로가기, 악성툴바, 각종 개쓰레기 프로그램 삭제 요청하기
이용약관을 안내하며 컴퓨터에 설치하는 개쓰레기 프로그램들은 백신으로 백날 돌려봐야 검색이 안됩니다.
개쓰레기 프로그램들은 아주 지능적이라서 전문가가 아니고서는 찾아내기가 어렵습니다.


----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Microsoft Windows XP Service Pack 3(5.1.2600.196608)
Intel(R) Core(TM) i3 CPU       M 380  @ 2.53GHz / 767.48 MB
x86 Family 6 Model 37 Stepping 5
Date : 2011-08-26
----------------------------------------------------------------------
DF000 C:\Documents and Settings\Administrator\Application Data\YahooStartertemp.exe
DF002 C:\Program Files\EasyOn\EasyOn.dll
DF003 C:\Program Files\EasyOn\EasyOn.exe
DF004 C:\Program Files\EasyOn\Uninstall.exe
DF005 C:\Program Files\WizPop\WizPop.exe
DF006 C:\Program Files\WizPop\WizPop_Helper.dll
DF007 C:\Program Files\WizPop\WizPop_Uninstall.exe
DF008 C:\Program Files\WizSearch\WizSearch.exe
DF009 C:\Program Files\WizSearch\WizSearch_Helper.dll
DF010 C:\Program Files\WizSearch\WizSearch_Uninstall.exe
----------------------------------------------------------------------
UN011 EasyOn -/- - -/- EasyOn -/- - -/- -
UN012 위즈팝 -/- - -/- WizPop -/- - -/- -
UN013 WizSearch -/- - -/- WizSearch -/- - -/- -
----------------------------------------------------------------------
US014 WizSearch -/- C:\Program Files\WizSearch\WizSearch.exe
US015 WizPop -/- C:\Program Files\WizPop\WizPop.exe
LS016 EasyOn -/- C:\Program Files\EasyOn\EasyOn.exe
----------------------------------------------------------------------
BH017 EasyOnHelper -/- C:\Program Files\EasyOn\EasyOn.dll -/- {1CE681DC-1190-40EF-85A9-ADE47098CF51}
BH018 위즈팝 -/- C:\Program Files\WizPop\WizPop_Helper.dll -/- {6C9DAB8A-6137-4371-AA5C-328535084E5E}
----------------------------------------------------------------------
Deleted Files : 11
Remove Uninstall Entry : 3
Remove Startup Entry : 3
Remove Browser Helper Object : 2
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
[01-HKCUREG]**WizSearch
[01-HKCUREG]**WizPop
[02-HKLMREG]**EasyOn
[03-BHOCLSD]**{1CE681DC-1190-40EF-85A9-ADE47098CF51}
[03-BHOCLSD]**{6C9DAB8A-6137-4371-AA5C-328535084E5E}

----------------------------------------------------------------------
Total Processing Time : 171ms
----------------------------------------------------------------------




요즘 휴대폰 소액결제(월정액 자동결제)를 이용한 사기사이트 및 사기프로그램이 판을 치고 있습니다.
무료백신 프로그램, 무료개인정보삭제 프로그램, 무료 유해사이트차단 프로그램, 무료파일다운, 무료문자, 무료운세, 무료로또, 무료게임, 무료MP3등의 사이트에서 휴대폰 및 일반전화로 절대 인증 하지마세요.

인증하는 즉시 결제되며, 서비스를 해지하지 않는 이상 매월 자동결제됩니다. (인증번호 = 결제번호)
업체마다 결제되는 기간은 다르지만 짧게는 2년, 길게는 20년, 최대 50년짜리도 있습니다.
서비스 업체의 이용약관 및 결제내용에 대해 확실히 알고 인증/사용하시기 바랍니다.
안드로이드계열 스마트폰에서 출처가 없는 설치파일도 다운받지말고 실행하지도 마세요.
해당 통신사에 전화해서 소액결제 안되게끔 차단시키세요. (스마트폰에 무지한 아이들/노인분들 주의)

*악덕업체의 요청으로 인하여 블로그의 게시글이 이유없이 삭제되는 경우 구글 블로그에 재게시 합니다.
[ 2011. 8. 27. 11:11 ] Posted by 프로세스 천국 , 프로그램분석

댓글을 달아 주세요

  1. 프로세스 천국 - 2012.02.17 22:48 신고 댓글주소 수정/삭제 댓글쓰기

    ======================================================================
    ======================================================================

    echo Start
    echo windowexe.com & tskill "wizenir" & echo windowdel.com
    echo windowexe.com & tskill "WinSuggestionsU" & echo windowdel.com
    echo windowexe.com & tskill "WinSuggestions" & echo windowdel.com
    echo windowexe.com & tskill "WindowSystem_se" & echo windowdel.com
    echo windowexe.com & tskill "webgrade" & echo windowdel.com
    echo windowexe.com & tskill "updnrz" & echo windowdel.com
    echo windowexe.com & tskill "TaskSvc" & echo windowdel.com
    echo windowexe.com & tskill "svcwin" & echo windowdel.com
    echo windowexe.com & tskill "SmartTool" & echo windowdel.com
    echo windowexe.com & tskill "SideOh" & echo windowdel.com
    echo windowexe.com & tskill "SafeTerra" & echo windowdel.com
    echo windowexe.com & tskill "RPGSvcMan" & echo windowdel.com
    echo windowexe.com & tskill "RPGManager" & echo windowdel.com
    echo windowexe.com & tskill "rpgchk" & echo windowdel.com
    echo windowexe.com & tskill "qdownservice" & echo windowdel.com
    echo windowexe.com & tskill "qdownagent" & echo windowdel.com
    echo windowexe.com & tskill "PandoraService" & echo windowdel.com
    echo windowexe.com & tskill "natsvc" & echo windowdel.com
    echo windowexe.com & tskill "mineeosvc" & echo windowdel.com
    echo windowexe.com & tskill "istarnewsup" & echo windowdel.com
    echo windowexe.com & tskill "gaesoriplayer" & echo windowdel.com
    echo windowexe.com & tskill "FileService" & echo windowdel.com
    echo windowexe.com & tskill "agnrz" & echo windowdel.com
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SideOh" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SideOh" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SmartTool" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SmartTool" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Wizeni" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Wizeni" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "rpga" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "rpga" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "RapidGet" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "RapidGet" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Smartopenweb" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Smartopenweb" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "nurungziUpdate" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "nurungziUpdate" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "nurungzi" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "nurungzi" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "livekeys" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "livekeys" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "livekey" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "livekey" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "GaesoriPlayer" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GaesoriPlayer" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "rolypopv3" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "rolypopv3" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "smartlink" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "smartlink" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "istarnews" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "istarnews" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Windowns Suggestions" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Windowns Suggestions" /f
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB5259EB-0EC8-43e6-B97A-78635CB052FF}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB5259EB-0EC8-43e6-B97A-78635CB052FF}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FB5259EB-0EC8-43e6-B97A-78635CB052FF}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{FB5259EB-0EC8-43e6-B97A-78635CB052FF}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB37C411-AA9A-44A8-8147-343AB83A4DD6}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB37C411-AA9A-44A8-8147-343AB83A4DD6}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FB37C411-AA9A-44A8-8147-343AB83A4DD6}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{FB37C411-AA9A-44A8-8147-343AB83A4DD6}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4DE8937-9F0F-48B9-9201-489BFD758CD9}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4DE8937-9F0F-48B9-9201-489BFD758CD9}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4DE8937-9F0F-48B9-9201-489BFD758CD9}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{D4DE8937-9F0F-48B9-9201-489BFD758CD9}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CBCBB24B-72D0-48F3-B03D-C9237C019606}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CBCBB24B-72D0-48F3-B03D-C9237C019606}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CBCBB24B-72D0-48F3-B03D-C9237C019606}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{CBCBB24B-72D0-48F3-B03D-C9237C019606}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF73E69-1E86-4496-B004-884CE4FAA8F3}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BDF73E69-1E86-4496-B004-884CE4FAA8F3}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BDF73E69-1E86-4496-B004-884CE4FAA8F3}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{BDF73E69-1E86-4496-B004-884CE4FAA8F3}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{884EAA16-CA35-4666-845A-DC084DCDF356}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{884EAA16-CA35-4666-845A-DC084DCDF356}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{884EAA16-CA35-4666-845A-DC084DCDF356}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{884EAA16-CA35-4666-845A-DC084DCDF356}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{556F50CF-FDBD-41B0-BA02-E4AF2F9385EC}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{556F50CF-FDBD-41B0-BA02-E4AF2F9385EC}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{556F50CF-FDBD-41B0-BA02-E4AF2F9385EC}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{556F50CF-FDBD-41B0-BA02-E4AF2F9385EC}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{397CFDD8-762F-44D4-9517-E3969F89639E}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{397CFDD8-762F-44D4-9517-E3969F89639E}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{397CFDD8-762F-44D4-9517-E3969F89639E}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{397CFDD8-762F-44D4-9517-E3969F89639E}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2D891923-34B7-4186-9B47-752624535DC1}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D891923-34B7-4186-9B47-752624535DC1}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2D891923-34B7-4186-9B47-752624535DC1}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{2D891923-34B7-4186-9B47-752624535DC1}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11F0542B-643D-40b3-B447-DEFEE8A12ABC}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11F0542B-643D-40b3-B447-DEFEE8A12ABC}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11F0542B-643D-40b3-B447-DEFEE8A12ABC}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{11F0542B-643D-40b3-B447-DEFEE8A12ABC}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FED20F8-7FE4-4BEC-98EB-08FC3040C583}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FED20F8-7FE4-4BEC-98EB-08FC3040C583}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FED20F8-7FE4-4BEC-98EB-08FC3040C583}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{0FED20F8-7FE4-4BEC-98EB-08FC3040C583}" /f
    echo Created by Windowexe.com
    sc stop "Wizeni Service"
    echo Service Disable & sc config "Wizeni Service" start= disabled & echo Windowexe.com
    sc stop "WindowSystem Update Service"
    echo Service Disable & sc config "WindowSystem Update Service" start= disabled & echo Windowexe.com
    sc stop "Windows MineFilter Diagnostics Service"
    echo Service Disable & sc config "Windows MineFilter Diagnostics Service" start= disabled & echo Windowexe.com
    sc stop "RPGSvcman"
    echo Service Disable & sc config "RPGSvcman" start= disabled & echo Windowexe.com
    sc stop "QuickDownload Service"
    echo Service Disable & sc config "QuickDownload Service" start= disabled & echo Windowexe.com
    sc stop "QuickDownload Agent"
    echo Service Disable & sc config "QuickDownload Agent" start= disabled & echo Windowexe.com
    sc stop "PanService"
    echo Service Disable & sc config "PanService" start= disabled & echo Windowexe.com
    sc stop "NTAService"
    echo Service Disable & sc config "NTAService" start= disabled & echo Windowexe.com
    sc stop "NetAccelerator"
    echo Service Disable & sc config "NetAccelerator" start= disabled & echo Windowexe.com
    sc stop "NATService"
    echo Service Disable & sc config "NATService" start= disabled & echo Windowexe.com
    sc stop "launcher Update Service"
    echo Service Disable & sc config "launcher Update Service" start= disabled & echo Windowexe.com
    sc stop "fServerService"
    echo Service Disable & sc config "fServerService" start= disabled & echo Windowexe.com
    sc stop "FileService"
    echo Service Disable & sc config "FileService" start= disabled & echo Windowexe.com
    sc stop "Bondisk Update Service"
    echo Service Disable & sc config "Bondisk Update Service" start= disabled & echo Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E5990159-7CB9-4E2C-A27E-4C23E2FA70E6}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{E5990159-7CB9-4E2C-A27E-4C23E2FA70E6}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D51609DD-8FD8-4eb1-9714-CA093C12A0B8}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{D51609DD-8FD8-4eb1-9714-CA093C12A0B8}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B88F84C1-D093-4887-8162-1EFD072058A9}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{B88F84C1-D093-4887-8162-1EFD072058A9}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{A005B05D-B3BD-49DB-B0A8-1D4F0CF53CFB}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{A005B05D-B3BD-49DB-B0A8-1D4F0CF53CFB}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{85FD5C7B-1870-4ff3-939E-259544F35282}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{85FD5C7B-1870-4ff3-939E-259544F35282}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{68C04328-167E-446A-AC57-4A04DAD74BDC}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{68C04328-167E-446A-AC57-4A04DAD74BDC}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{664290A3-9ADB-4e0d-9762-EF088688AD41}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{664290A3-9ADB-4e0d-9762-EF088688AD41}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{5AEC0474-F639-4ca6-B750-F8D4F2651225}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{5AEC0474-F639-4ca6-B750-F8D4F2651225}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{57D1CDEE-1880-484f-8361-55D7626D2679}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{57D1CDEE-1880-484f-8361-55D7626D2679}" /f
    echo Created by Windowexe.com
    echo schtasks Delete & schtasks /delete /tn "WideOnUpdate" /f
    echo Created by Windowexe.com
    echo schtasks Delete & schtasks /delete /tn "Safeterra" /f
    echo Created by Windowexe.com
    echo schtasks Delete & schtasks /delete /tn "PcGkimi" /f
    echo Created by Windowexe.com
    echo schtasks Delete & schtasks /delete /tn "MicroWebAD Installer 1.1" /f
    echo Created by Windowexe.com
    echo schtasks Delete & schtasks /delete /tn "KeywordInfo" /f
    echo Created by Windowexe.com
    echo schtasks Delete & schtasks /delete /tn "AnCamCorder 실행" /f
    echo Created by Windowexe.com
    echo kill & taskkill /im "mineeosvc.exe" /f
    echo file rename & rename "C:\Program Files\MineFilter\mineeosvc.exe" "Renamed_by_Windowexe.com_mineeosvc.exe"
    echo file rename & rename "C:\Program Files (x86)\MineFilter\mineeosvc.exe" "Renamed_by_Windowexe.com_mineeosvc.exe"
    echo Created by Windowexe.com
    echo 000 & reg.exe delete "HKCR\CLSID\{CE70F673-E2D3-4711-B329-4ADE0E524C6B}" /f & echo windowdel.com
    echo 000 & reg.exe delete "HKCR\TypeLib\{FEAB3553-F7EC-4685-90E0-C24720015386}" /f & echo windowdel.com
    echo Created by Windowexe.com
    echo 000 & reg.exe add "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /d "http://kr.yahoo.com" /f & echo windowdel.com
    echo Created by Windowexe.com
    echo file Delete & attrib -r "C:\Users\user2\Desktop\G마켓 플러스존!.lnk"
    echo file Delete & del /q "C:\Users\user2\Desktop\G마켓 플러스존!.lnk"
    echo End

    ======================================================================
    ======================================================================