System Analyzer Report 2012, 12, 29
NA001 ======================================================================
NA002 echo Created by Windowexe.com / do not delete this label.
NA003 ======================================================================
NA004 echo Start
NA005 echo windowexe.com & tskill "natsvc" & echo windowdel.com
NA006 echo windowexe.com & tskill "pcpoweroffmon" & echo windowdel.com
NA007 echo windowexe.com & tskill "pcpoweroffuc" & echo windowdel.com
NA008 echo windowexe.com & tskill "ShareBoxC" & echo windowdel.com
NA009 echo windowexe.com & tskill "iesignkey" & echo windowdel.com
NA010 echo windowexe.com & tskill "signkey" & echo windowdel.com
NA011 echo windowexe.com & tskill "ecomntsv" & echo windowdel.com
NA012 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "ShareBox" /f
NA013 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "ShareBox" /f
NA014 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "PCM Defender" /f
NA015 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "PCM Defender" /f
NA016 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "signkey" /f
NA017 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "signkey" /f
NA018 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "pcpoweroff" /f
NA019 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "pcpoweroff" /f
NA020 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "tabsync" /f
NA021 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "tabsync" /f
NA022 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SmartKeyUpdater" /f
NA023 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SmartKeyUpdater" /f
NA024 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SmartPopUpdater" /f
NA025 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SmartPopUpdater" /f
NA026 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "vaccineupdatestart.exe" /f
NA027 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "vaccineupdatestart.exe" /f
NA028 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "update.exe" /f
NA029 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "update.exe" /f
NA030 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "pcpoweroff" /f
NA031 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "pcpoweroff" /f
NA032 echo file Delete & attrib -r "C:\Users\halycon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pcpoweroffuc.lnk"
NA033 echo file Delete & del /q "C:\Users\halycon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pcpoweroffuc.lnk"
NA034 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA035 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA036 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA037 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA038 echo Created by Windowexe.com
NA039 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6F6C2391-3353-4424-9614-DB5868315F66}" /f
NA040 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6F6C2391-3353-4424-9614-DB5868315F66}" /f
NA041 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6F6C2391-3353-4424-9614-DB5868315F66}" /f
NA042 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{6F6C2391-3353-4424-9614-DB5868315F66}" /f
NA043 echo Created by Windowexe.com
NA044 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}" /f
NA045 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}" /f
NA046 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}" /f
NA047 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}" /f
NA048 echo Created by Windowexe.com
NA049 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E2E94F8D-4323-4943-A269-2E9EF6280434}" /f
NA050 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2E94F8D-4323-4943-A269-2E9EF6280434}" /f
NA051 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E2E94F8D-4323-4943-A269-2E9EF6280434}" /f
NA052 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{E2E94F8D-4323-4943-A269-2E9EF6280434}" /f
NA053 echo Created by Windowexe.com
NA054 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA055 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA056 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA057 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA058 echo Created by Windowexe.com
NA059 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA060 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA061 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA062 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA063 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA064 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA065 echo Created by Windowexe.com
NA066 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}" /f
NA067 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}" /f
NA068 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}" /f
NA069 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}" /f
NA070 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}" /f
NA071 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}" /f
NA072 echo Created by Windowexe.com
NA073 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA074 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA075 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA076 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA077 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA078 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA079 echo Created by Windowexe.com
NA080 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA081 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA082 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA083 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA084 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA085 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA086 echo Created by Windowexe.com
NA087 sc stop "monpcpoweroff"
NA088 echo Service Disable & sc config "monpcpoweroff" start= disabled & echo Windowexe.com
NA089 sc stop "NATService"
NA090 echo Service Disable & sc config "NATService" start= disabled & echo Windowexe.com
NA091 sc stop "wecomntsv"
NA092 echo Service Disable & sc config "wecomntsv" start= disabled & echo Windowexe.com
NA093 echo schtasks Delete & schtasks /delete /tn "MicroWebAD Installer 1.1" /f
NA094 echo Created by Windowexe.com
NA095 echo change dir for x64
NA096 cd %windir%
NA097 cd syswow64
NA098 echo windowexe.com & tskill "natsvc" & echo windowdel.com
NA099 echo windowexe.com & tskill "pcpoweroffmon" & echo windowdel.com
NA100 echo windowexe.com & tskill "pcpoweroffuc" & echo windowdel.com
NA101 echo windowexe.com & tskill "ShareBoxC" & echo windowdel.com
NA102 echo windowexe.com & tskill "iesignkey" & echo windowdel.com
NA103 echo windowexe.com & tskill "signkey" & echo windowdel.com
NA104 echo windowexe.com & tskill "ecomntsv" & echo windowdel.com
NA105 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "ShareBox" /f
NA106 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "ShareBox" /f
NA107 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "PCM Defender" /f
NA108 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "PCM Defender" /f
NA109 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "signkey" /f
NA110 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "signkey" /f
NA111 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "pcpoweroff" /f
NA112 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "pcpoweroff" /f
NA113 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "tabsync" /f
NA114 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "tabsync" /f
NA115 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SmartKeyUpdater" /f
NA116 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SmartKeyUpdater" /f
NA117 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SmartPopUpdater" /f
NA118 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SmartPopUpdater" /f
NA119 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "vaccineupdatestart.exe" /f
NA120 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "vaccineupdatestart.exe" /f
NA121 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "update.exe" /f
NA122 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "update.exe" /f
NA123 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "pcpoweroff" /f
NA124 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "pcpoweroff" /f
NA125 echo file Delete & attrib -r "C:\Users\halycon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pcpoweroffuc.lnk"
NA126 echo file Delete & del /q "C:\Users\halycon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pcpoweroffuc.lnk"
NA127 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA128 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA129 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA130 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA131 echo Created by Windowexe.com
NA132 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6F6C2391-3353-4424-9614-DB5868315F66}" /f
NA133 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6F6C2391-3353-4424-9614-DB5868315F66}" /f
NA134 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6F6C2391-3353-4424-9614-DB5868315F66}" /f
NA135 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{6F6C2391-3353-4424-9614-DB5868315F66}" /f
NA136 echo Created by Windowexe.com
NA137 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}" /f
NA138 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}" /f
NA139 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}" /f
NA140 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}" /f
NA141 echo Created by Windowexe.com
NA142 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E2E94F8D-4323-4943-A269-2E9EF6280434}" /f
NA143 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2E94F8D-4323-4943-A269-2E9EF6280434}" /f
NA144 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E2E94F8D-4323-4943-A269-2E9EF6280434}" /f
NA145 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{E2E94F8D-4323-4943-A269-2E9EF6280434}" /f
NA146 echo Created by Windowexe.com
NA147 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA148 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA149 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA150 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA151 echo Created by Windowexe.com
NA152 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA153 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA154 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA155 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA156 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA157 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA158 echo Created by Windowexe.com
NA159 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}" /f
NA160 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}" /f
NA161 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}" /f
NA162 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}" /f
NA163 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}" /f
NA164 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}" /f
NA165 echo Created by Windowexe.com
NA166 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA167 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA168 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA169 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA170 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA171 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{f34c9277-6577-4dff-b2d7-7d58092f272f}" /f
NA172 echo Created by Windowexe.com
NA173 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA174 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA175 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA176 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA177 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA178 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA179 echo Created by Windowexe.com
NA180 sc stop "monpcpoweroff"
NA181 echo Service Disable & sc config "monpcpoweroff" start= disabled & echo Windowexe.com
NA182 sc stop "NATService"
NA183 echo Service Disable & sc config "NATService" start= disabled & echo Windowexe.com
NA184 sc stop "wecomntsv"
NA185 echo Service Disable & sc config "wecomntsv" start= disabled & echo Windowexe.com
NA186 echo schtasks Delete & schtasks /delete /tn "MicroWebAD Installer 1.1" /f
NA187 echo Created by Windowexe.com
NA188 echo End
NA189 ======================================================================
NA190 echo Created by Windowexe.com / do not delete this label.
NA191 ======================================================================