프로그램분석

Code : sFkYkTWSE7wsf2B5BSXlU+Eby1qs6qQkdByLiEQYfts=

프로세스 천국 2013. 4. 14. 22:18

Code : PlDdD2wHeG4=
NA000 ======================================================================
NA001 echo Created by Windowexe.com / do not delete this label.
NA002 ======================================================================
NA003 echo Start
NA004 echo windowexe.com & tskill "WindowServiceNT" & echo windowdel.com
NA005 echo windowexe.com & tskill "MicrowindowSearch" & echo windowdel.com
NA006 echo windowexe.com & tskill "catrootsz" & echo windowdel.com
NA007 echo windowexe.com & tskill "catroot" & echo windowdel.com
NA008 echo windowexe.com & tskill "upmxwho" & echo windowdel.com
NA009 echo windowexe.com & tskill "mxwho" & echo windowdel.com
NA010 echo windowexe.com & tskill "upmscryp" & echo windowdel.com
NA011 echo windowexe.com & tskill "mscryp" & echo windowdel.com
NA012 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "audlg" /f
NA013 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "audlg" /f
NA014 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "upmscryp" /f
NA015 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "upmscryp" /f
NA016 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "mscryp" /f
NA017 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "mscryp" /f
NA018 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "mxwho" /f
NA019 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "mxwho" /f
NA020 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "upmxwho" /f
NA021 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "upmxwho" /f
NA022 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "catroot" /f
NA023 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "catroot" /f
NA024 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicrowindowSearch" /f
NA025 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicrowindowSearch" /f
NA026 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicrowindowSearch" /f
NA027 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicrowindowSearch" /f
NA028 sc stop "smatsvc"
NA029 echo Service Disable & sc config "smatsvc" start= disabled & echo Windowexe.com
NA030 sc stop "RPGSvcman"
NA031 echo Service Disable & sc config "RPGSvcman" start= disabled & echo Windowexe.com
NA032 sc stop "Rokasoo"
NA033 echo Service Disable & sc config "Rokasoo" start= disabled & echo Windowexe.com
NA034 sc stop "Ijmeula"
NA035 echo Service Disable & sc config "Ijmeula" start= disabled & echo Windowexe.com
NA036 sc stop "Goderiazg"
NA037 echo Service Disable & sc config "Goderiazg" start= disabled & echo Windowexe.com
NA038 sc stop "ApplicationSpecialManagement"
NA039 echo Service Disable & sc config "ApplicationSpecialManagement" start= disabled & echo Windowexe.com
NA040 sc stop "ApplicationOffice"
NA041 echo Service Disable & sc config "ApplicationOffice" start= disabled & echo Windowexe.com
NA042 sc stop "AppCatroots"
NA043 echo Service Disable & sc config "AppCatroots" start= disabled & echo Windowexe.com
NA044 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{00000002-5499-47ed-A234-304F5258E596}" /f
NA045 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{00000002-5499-47ed-A234-304F5258E596}" /f
NA046 echo Created by Windowexe.com
NA047 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{00000001-5499-47ed-A234-304F5258E596}" /f
NA048 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{00000001-5499-47ed-A234-304F5258E596}" /f
NA049 echo Created by Windowexe.com
NA050 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{00000000-5499-47ed-A234-304F5258E596}" /f
NA051 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{00000000-5499-47ed-A234-304F5258E596}" /f
NA052 echo Created by Windowexe.com
NA053 echo Tasklist Delete & del /q "C:\WINDOWS\Tasks\IPopUpdate.job"
NA054 echo Created by Windowexe.com
NA055 echo Tasklist Delete & del /q "C:\WINDOWS\Tasks\AppIsUpdate.job"
NA056 echo Created by Windowexe.com
NA057 echo End
NA058 ======================================================================
NA059 echo Created by Windowexe.com / do not delete this label.
NA060 ======================================================================