System Analyzer Report 2013, 01, 18
NA002 ======================================================================
NA003 echo Created by Windowexe.com / do not delete this label.
NA004 ======================================================================
NA005 echo Start
NA006 echo windowexe.com & tskill "PGuideSC" & echo windowdel.com
NA007 echo windowexe.com & tskill "primead" & echo windowdel.com
NA008 echo windowexe.com & tskill "xenoup" & echo windowdel.com
NA009 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroProProc" /f
NA010 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroProProc" /f
NA011 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroLabProc" /f
NA012 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroLabProc" /f
NA013 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "GuardSupport" /f
NA014 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GuardSupport" /f
NA015 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Cwvlhjbyb" /f
NA016 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Cwvlhjbyb" /f
NA017 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Kp" /f
NA018 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Kp" /f
NA019 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "primead.exe" /f
NA020 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "primead.exe" /f
NA021 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "snslide" /f
NA022 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "snslide" /f
NA023 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "hitlink.exe" /f
NA024 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "hitlink.exe" /f
NA025 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "winmdnts" /f
NA026 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "winmdnts" /f
NA027 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "HiSch" /f
NA028 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "HiSch" /f
NA029 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE14A4CA-5CFA-4C05-9274-6006397B68C9}" /f
NA030 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE14A4CA-5CFA-4C05-9274-6006397B68C9}" /f
NA031 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE14A4CA-5CFA-4C05-9274-6006397B68C9}" /f
NA032 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{FE14A4CA-5CFA-4C05-9274-6006397B68C9}" /f
NA033 echo Created by Windowexe.com
NA034 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CDEE4BC9-A278-4C02-8D24-049641326690}" /f
NA035 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CDEE4BC9-A278-4C02-8D24-049641326690}" /f
NA036 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CDEE4BC9-A278-4C02-8D24-049641326690}" /f
NA037 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{CDEE4BC9-A278-4C02-8D24-049641326690}" /f
NA038 echo Created by Windowexe.com
NA039 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E273A92-9273-4B89-8A38-5DF2FD0F0D2E}" /f
NA040 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3E273A92-9273-4B89-8A38-5DF2FD0F0D2E}" /f
NA041 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3E273A92-9273-4B89-8A38-5DF2FD0F0D2E}" /f
NA042 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{3E273A92-9273-4B89-8A38-5DF2FD0F0D2E}" /f
NA043 echo Created by Windowexe.com
NA044 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{8A5FC7EA-6031-40BB-A609-5F022672438C}" /f
NA045 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{8A5FC7EA-6031-40BB-A609-5F022672438C}" /f
NA046 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{8A5FC7EA-6031-40BB-A609-5F022672438C}" /f
NA047 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8A5FC7EA-6031-40BB-A609-5F022672438C}" /f
NA048 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8A5FC7EA-6031-40BB-A609-5F022672438C}" /f
NA049 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{8A5FC7EA-6031-40BB-A609-5F022672438C}" /f
NA050 echo Created by Windowexe.com
NA051 sc stop "xeno64 update"
NA052 echo Service Disable & sc config "xeno64 update" start= disabled & echo Windowexe.com
NA053 sc stop "SearchN"
NA054 echo Service Disable & sc config "SearchN" start= disabled & echo Windowexe.com
NA055 sc stop "rhplinfqs"
NA056 echo Service Disable & sc config "rhplinfqs" start= disabled & echo Windowexe.com
NA057 sc stop "qfofzxoykn"
NA058 echo Service Disable & sc config "qfofzxoykn" start= disabled & echo Windowexe.com
NA059 sc stop "PGuide"
NA060 echo Service Disable & sc config "PGuide" start= disabled & echo Windowexe.com
NA061 sc stop "olctpopfrx"
NA062 echo Service Disable & sc config "olctpopfrx" start= disabled & echo Windowexe.com
NA063 sc stop "lgyuppg"
NA064 echo Service Disable & sc config "lgyuppg" start= disabled & echo Windowexe.com
NA065 sc stop "jnbitintoft"
NA066 echo Service Disable & sc config "jnbitintoft" start= disabled & echo Windowexe.com
NA067 sc stop "hdpvvuuccg"
NA068 echo Service Disable & sc config "hdpvvuuccg" start= disabled & echo Windowexe.com
NA069 sc stop "fmiciiwg"
NA070 echo Service Disable & sc config "fmiciiwg" start= disabled & echo Windowexe.com
NA071 sc stop "baockaxholu"
NA072 echo Service Disable & sc config "baockaxholu" start= disabled & echo Windowexe.com
NA073 sc stop "auxhazr"
NA074 echo Service Disable & sc config "auxhazr" start= disabled & echo Windowexe.com
NA075 sc stop "ajqzbwcvbxr"
NA076 echo Service Disable & sc config "ajqzbwcvbxr" start= disabled & echo Windowexe.com
NA077 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FA214B13-1A9F-480B-B749-94A566FC59D9}" /f
NA078 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{FA214B13-1A9F-480B-B749-94A566FC59D9}" /f
NA079 echo Created by Windowexe.com
NA080 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D64A7743-7E62-4002-90EA-80E0671F9902}" /f
NA081 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{D64A7743-7E62-4002-90EA-80E0671F9902}" /f
NA082 echo Created by Windowexe.com
NA083 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{8605E9B4-68C1-4ED9-B282-74C1AA3C312E}" /f
NA084 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{8605E9B4-68C1-4ED9-B282-74C1AA3C312E}" /f
NA085 echo Created by Windowexe.com
NA086 echo End
NA087 ======================================================================
NA088 echo Created by Windowexe.com / do not delete this label.
NA089 ======================================================================