Code : CtfSvS6lEhPOxaOJmL6wEUJ4JCjDHtZ8mjHqr7d7Hx0=
System Analyzer Report 2013, 03, 05
NA001 ======================================================================
NA002 echo Created by Windowexe.com / do not delete this label.
NA003 ======================================================================
NA004 echo Start
NA005 echo windowexe.com & tskill "appcon" & echo windowdel.com
NA006 echo windowexe.com & tskill "chicon" & echo windowdel.com
NA007 echo windowexe.com & tskill "ctpopsvc" & echo windowdel.com
NA008 echo windowexe.com & tskill "vaccinewebstart" & echo windowdel.com
NA009 echo windowexe.com & tskill "vaccinewebu" & echo windowdel.com
NA010 echo windowexe.com & tskill "WHelp" & echo windowdel.com
NA011 echo windowexe.com & tskill "intsfsrv" & echo windowdel.com
NA012 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WHelp\"" /f
NA013 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WHelp\"" /f
NA014 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WinKeyword_Up" /f
NA015 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WinKeyword_Up" /f
NA016 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WHelp" /f
NA017 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WHelp" /f
NA018 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "UtilZone" /f
NA019 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "UtilZone" /f
NA020 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "appsigntool" /f
NA021 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "appsigntool" /f
NA022 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "chicon" /f
NA023 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "chicon" /f
NA024 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "appcon" /f
NA025 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "appcon" /f
NA026 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "vaccineweb main" /f
NA027 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "vaccineweb main" /f
NA028 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "vaccinewebstart.exe" /f
NA029 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "vaccinewebstart.exe" /f
NA030 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroProProc" /f
NA031 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroProProc" /f
NA032 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F2CF04D-300B-49A2-A23B-407D27FB9BFB}" /f
NA033 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2F2CF04D-300B-49A2-A23B-407D27FB9BFB}" /f
NA034 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2F2CF04D-300B-49A2-A23B-407D27FB9BFB}" /f
NA035 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{2F2CF04D-300B-49A2-A23B-407D27FB9BFB}" /f
NA036 echo Created by Windowexe.com
NA037 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A14EAA16-CA35-4666-845A-DC084DCDF356}" /f
NA038 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A14EAA16-CA35-4666-845A-DC084DCDF356}" /f
NA039 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A14EAA16-CA35-4666-845A-DC084DCDF356}" /f
NA040 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{A14EAA16-CA35-4666-845A-DC084DCDF356}" /f
NA041 echo Created by Windowexe.com
NA042 sc stop "ctwopop"
NA043 echo Service Disable & sc config "ctwopop" start= disabled & echo Windowexe.com
NA044 sc stop "InternetSafer Protector"
NA045 echo Service Disable & sc config "InternetSafer Protector" start= disabled & echo Windowexe.com
NA046 sc stop "WindowsDriver"
NA047 echo Service Disable & sc config "WindowsDriver" start= disabled & echo Windowexe.com
NA048 echo schtasks Delete & schtasks /delete /tn "intsfad" /f
NA049 echo Created by Windowexe.com
NA050 echo change dir for x64
NA051 cd %windir%
NA052 cd syswow64
NA053 echo windowexe.com & tskill "appcon" & echo windowdel.com
NA054 echo windowexe.com & tskill "chicon" & echo windowdel.com
NA055 echo windowexe.com & tskill "ctpopsvc" & echo windowdel.com
NA056 echo windowexe.com & tskill "vaccinewebstart" & echo windowdel.com
NA057 echo windowexe.com & tskill "vaccinewebu" & echo windowdel.com
NA058 echo windowexe.com & tskill "WHelp" & echo windowdel.com
NA059 echo windowexe.com & tskill "intsfsrv" & echo windowdel.com
NA060 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WHelp\"" /f
NA061 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WHelp\"" /f
NA062 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WinKeyword_Up" /f
NA063 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WinKeyword_Up" /f
NA064 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WHelp" /f
NA065 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WHelp" /f
NA066 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "UtilZone" /f
NA067 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "UtilZone" /f
NA068 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "appsigntool" /f
NA069 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "appsigntool" /f
NA070 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "chicon" /f
NA071 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "chicon" /f
NA072 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "appcon" /f
NA073 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "appcon" /f
NA074 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "vaccineweb main" /f
NA075 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "vaccineweb main" /f
NA076 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "vaccinewebstart.exe" /f
NA077 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "vaccinewebstart.exe" /f
NA078 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroProProc" /f
NA079 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroProProc" /f
NA080 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F2CF04D-300B-49A2-A23B-407D27FB9BFB}" /f
NA081 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2F2CF04D-300B-49A2-A23B-407D27FB9BFB}" /f
NA082 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2F2CF04D-300B-49A2-A23B-407D27FB9BFB}" /f
NA083 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{2F2CF04D-300B-49A2-A23B-407D27FB9BFB}" /f
NA084 echo Created by Windowexe.com
NA085 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A14EAA16-CA35-4666-845A-DC084DCDF356}" /f
NA086 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A14EAA16-CA35-4666-845A-DC084DCDF356}" /f
NA087 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A14EAA16-CA35-4666-845A-DC084DCDF356}" /f
NA088 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{A14EAA16-CA35-4666-845A-DC084DCDF356}" /f
NA089 echo Created by Windowexe.com
NA090 sc stop "ctwopop"
NA091 echo Service Disable & sc config "ctwopop" start= disabled & echo Windowexe.com
NA092 sc stop "InternetSafer Protector"
NA093 echo Service Disable & sc config "InternetSafer Protector" start= disabled & echo Windowexe.com
NA094 sc stop "WindowsDriver"
NA095 echo Service Disable & sc config "WindowsDriver" start= disabled & echo Windowexe.com
NA096 echo schtasks Delete & schtasks /delete /tn "intsfad" /f
NA097 echo Created by Windowexe.com
NA098 echo End
NA099 ======================================================================
NA100 echo Created by Windowexe.com / do not delete this label.
NA101 ======================================================================