프로그램분석

Code : lXjA97eZ9efKuq/m9vq3NFzWv6YxLozr

프로세스 천국 2013. 2. 7. 13:52

System Analyzer Report 2013, 02, 07

NA001 ======================================================================
NA002 echo Created by Windowexe.com / do not delete this label.
NA003 ======================================================================
NA004 echo Start
NA005 echo windowexe.com & tskill "ghghs" & echo windowdel.com
NA006 echo windowexe.com & tskill "update" & echo windowdel.com
NA007 echo windowexe.com & tskill "MultiAddress" & echo windowdel.com
NA008 echo windowexe.com & tskill "TCCheckAgent" & echo windowdel.com
NA009 echo windowexe.com & tskill "ctpopsvc" & echo windowdel.com
NA010 echo windowexe.com & tskill "direcon" & echo windowdel.com
NA011 echo windowexe.com & tskill "keycast" & echo windowdel.com
NA012 echo windowexe.com & tskill "MicroPCRecordHelper" & echo windowdel.com
NA013 echo windowexe.com & tskill "MicroPCRecordUdt" & echo windowdel.com
NA014 echo windowexe.com & tskill "natsvc" & echo windowdel.com
NA015 echo windowexe.com & tskill "netipviewer_mon" & echo windowdel.com
NA016 echo windowexe.com & tskill "netipviewer_uc" & echo windowdel.com
NA017 echo windowexe.com & tskill "OutMemoryUDS" & echo windowdel.com
NA018 echo windowexe.com & tskill "revealingdc" & echo windowdel.com
NA019 echo windowexe.com & tskill "revealingst" & echo windowdel.com
NA020 echo windowexe.com & tskill "revealingu" & echo windowdel.com
NA021 echo windowexe.com & tskill "SNChkSvc" & echo windowdel.com
NA022 echo windowexe.com & tskill "ShareBoxC" & echo windowdel.com
NA023 echo windowexe.com & tskill "UtilZone" & echo windowdel.com
NA024 echo windowexe.com & tskill "intsfsrv" & echo windowdel.com
NA025 echo windowexe.com & tskill "GuardConvert" & echo windowdel.com
NA026 echo windowexe.com & tskill "MicroProCon" & echo windowdel.com
NA027 echo windowexe.com & tskill "MicroProProc" & echo windowdel.com
NA028 echo windowexe.com & tskill "FBDSvcMan" & echo windowdel.com
NA029 echo windowexe.com & tskill "tabsync" & echo windowdel.com
NA030 echo windowexe.com & tskill "tabsyncu" & echo windowdel.com
NA031 echo windowexe.com & tskill "userwindowinfoconfig" & echo windowdel.com
NA032 echo windowexe.com & tskill "windowuserupdate" & echo windowdel.com
NA033 echo windowexe.com & tskill "ghgh" & echo windowdel.com
NA034 echo windowexe.com & tskill "wkwd_u_dll" & echo windowdel.com
NA035 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WHelp\"" /f
NA036 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WHelp\"" /f
NA037 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "ShareBox" /f
NA038 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "ShareBox" /f
NA039 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "OutMemoryS_Update" /f
NA040 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "OutMemoryS_Update" /f
NA041 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "tabsync" /f
NA042 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "tabsync" /f
NA043 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Pando Media Booster" /f
NA044 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Pando Media Booster" /f
NA045 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "netipviewer" /f
NA046 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "netipviewer" /f
NA047 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroPCRecord" /f
NA048 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroPCRecord" /f
NA049 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroPCRecordUdt" /f
NA050 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroPCRecordUdt" /f
NA051 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "revealing_u" /f
NA052 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "revealing_u" /f
NA053 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "revealing_st" /f
NA054 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "revealing_st" /f
NA055 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "revealing_dc" /f
NA056 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "revealing_dc" /f
NA057 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "IETab" /f
NA058 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "IETab" /f
NA059 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WHelp" /f
NA060 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WHelp" /f
NA061 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WHelp" /f
NA062 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WHelp" /f
NA063 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SpeedDownload" /f
NA064 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SpeedDownload" /f
NA065 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "rpga" /f
NA066 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "rpga" /f
NA067 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "UtilZone" /f
NA068 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "UtilZone" /f
NA069 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "appis.exe" /f
NA070 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "appis.exe" /f
NA071 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MultiAddress.exe" /f
NA072 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MultiAddress.exe" /f
NA073 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "netipviewer" /f
NA074 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "netipviewer" /f
NA075 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "direcon" /f
NA076 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "direcon" /f
NA077 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "GuardSupport" /f
NA078 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GuardSupport" /f
NA079 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroProCon" /f
NA080 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroProCon" /f
NA081 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroLabCon" /f
NA082 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroLabCon" /f
NA083 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroLabProc" /f
NA084 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroLabProc" /f
NA085 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroProProc" /f
NA086 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroProProc" /f
NA087 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA088 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA089 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA090 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA091 echo Created by Windowexe.com
NA092 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91A47E74-E5A9-4B77-936C-8335F7B62730}" /f
NA093 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{91A47E74-E5A9-4B77-936C-8335F7B62730}" /f
NA094 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{91A47E74-E5A9-4B77-936C-8335F7B62730}" /f
NA095 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{91A47E74-E5A9-4B77-936C-8335F7B62730}" /f
NA096 echo Created by Windowexe.com
NA097 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA098 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA099 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA100 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA101 echo Created by Windowexe.com
NA102 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA103 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA104 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA105 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA106 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA107 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA108 echo Created by Windowexe.com
NA109 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{41ED1FD7-8C37-4806-AF9E-D5238A30E56F}" /f
NA110 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{41ED1FD7-8C37-4806-AF9E-D5238A30E56F}" /f
NA111 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{41ED1FD7-8C37-4806-AF9E-D5238A30E56F}" /f
NA112 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{41ED1FD7-8C37-4806-AF9E-D5238A30E56F}" /f
NA113 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41ED1FD7-8C37-4806-AF9E-D5238A30E56F}" /f
NA114 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{41ED1FD7-8C37-4806-AF9E-D5238A30E56F}" /f
NA115 echo Created by Windowexe.com
NA116 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA117 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA118 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA119 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA120 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA121 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA122 echo Created by Windowexe.com
NA123 sc stop "autokwds"
NA124 echo Service Disable & sc config "autokwds" start= disabled & echo Windowexe.com
NA125 sc stop "ctwopop"
NA126 echo Service Disable & sc config "ctwopop" start= disabled & echo Windowexe.com
NA127 sc stop "dejenere"
NA128 echo Service Disable & sc config "dejenere" start= disabled & echo Windowexe.com
NA129 sc stop "FBDSvcman"
NA130 echo Service Disable & sc config "FBDSvcman" start= disabled & echo Windowexe.com
NA131 sc stop "InternetSafer Protector"
NA132 echo Service Disable & sc config "InternetSafer Protector" start= disabled & echo Windowexe.com
NA133 sc stop "internetserviceservice"
NA134 echo Service Disable & sc config "internetserviceservice" start= disabled & echo Windowexe.com
NA135 sc stop "liveupdaterservice"
NA136 echo Service Disable & sc config "liveupdaterservice" start= disabled & echo Windowexe.com
NA137 sc stop "NATService"
NA138 echo Service Disable & sc config "NATService" start= disabled & echo Windowexe.com
NA139 sc stop "rsrwqrip"
NA140 echo Service Disable & sc config "rsrwqrip" start= disabled & echo Windowexe.com
NA141 sc stop "SearchN"
NA142 echo Service Disable & sc config "SearchN" start= disabled & echo Windowexe.com
NA143 sc stop "SpeedPing Service"
NA144 echo Service Disable & sc config "SpeedPing Service" start= disabled & echo Windowexe.com
NA145 sc stop "speedwindow Update Service"
NA146 echo Service Disable & sc config "speedwindow Update Service" start= disabled & echo Windowexe.com
NA147 sc stop "systemviewservice"
NA148 echo Service Disable & sc config "systemviewservice" start= disabled & echo Windowexe.com
NA149 sc stop "TCCheckAgent"
NA150 echo Service Disable & sc config "TCCheckAgent" start= disabled & echo Windowexe.com
NA151 sc stop "windowcom Update Service"
NA152 echo Service Disable & sc config "windowcom Update Service" start= disabled & echo Windowexe.com
NA153 sc stop "WindowsDriver"
NA154 echo Service Disable & sc config "WindowsDriver" start= disabled & echo Windowexe.com
NA155 sc stop "xqdhslsdwg"
NA156 echo Service Disable & sc config "xqdhslsdwg" start= disabled & echo Windowexe.com
NA157 sc stop "ghgh1"
NA158 echo Service Disable & sc config "ghgh1" start= disabled & echo Windowexe.com
NA159 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{8605E9B4-68C1-4ED9-B282-74C1AA3C312E}" /f
NA160 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{8605E9B4-68C1-4ED9-B282-74C1AA3C312E}" /f
NA161 echo Created by Windowexe.com
NA162 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D64A7743-7E62-4002-90EA-80E0671F9902}" /f
NA163 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{D64A7743-7E62-4002-90EA-80E0671F9902}" /f
NA164 echo Created by Windowexe.com
NA165 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FA214B13-1A9F-480B-B749-94A566FC59D9}" /f
NA166 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{FA214B13-1A9F-480B-B749-94A566FC59D9}" /f
NA167 echo Created by Windowexe.com
NA168 echo schtasks Delete & schtasks /delete /tn "AppIs" /f
NA169 echo Created by Windowexe.com
NA170 echo schtasks Delete & schtasks /delete /tn "AppIsUpdate" /f
NA171 echo Created by Windowexe.com
NA172 echo schtasks Delete & schtasks /delete /tn "intsfad" /f
NA173 echo Created by Windowexe.com
NA174 echo schtasks Delete & schtasks /delete /tn "KeyCast" /f
NA175 echo Created by Windowexe.com
NA176 echo schtasks Delete & schtasks /delete /tn "mplus" /f
NA177 echo Created by Windowexe.com
NA178 echo schtasks Delete & schtasks /delete /tn "windows cloudpop Manager" /f
NA179 echo Created by Windowexe.com
NA180 echo schtasks Delete & schtasks /delete /tn "windows cloudpop Manager_" /f
NA181 echo Created by Windowexe.com
NA182 echo schtasks Delete & schtasks /delete /tn "Windows prime ad-pop" /f
NA183 echo Created by Windowexe.com
NA184 echo schtasks Delete & schtasks /delete /tn "Windows Visual ad php" /f
NA185 echo Created by Windowexe.com
NA186 echo 000 & reg.exe delete "HKCR\CLSID\{5121BCAB-14D5-40AD-A469-4437CC51F7AA}" /f & echo windowdel.com
NA187 echo Created by Windowexe.com
NA188 echo 000 & reg.exe delete "HKCR\CLSID\{A832F633-668F-4F8A-9EA1-A6375D1C1418}" /f & echo windowdel.com
NA189 echo Created by Windowexe.com
NA190 echo change dir for x64
NA191 cd %windir%
NA192 cd syswow64
NA193 echo windowexe.com & tskill "ghghs" & echo windowdel.com
NA194 echo windowexe.com & tskill "update" & echo windowdel.com
NA195 echo windowexe.com & tskill "MultiAddress" & echo windowdel.com
NA196 echo windowexe.com & tskill "TCCheckAgent" & echo windowdel.com
NA197 echo windowexe.com & tskill "ctpopsvc" & echo windowdel.com
NA198 echo windowexe.com & tskill "direcon" & echo windowdel.com
NA199 echo windowexe.com & tskill "keycast" & echo windowdel.com
NA200 echo windowexe.com & tskill "MicroPCRecordHelper" & echo windowdel.com
NA201 echo windowexe.com & tskill "MicroPCRecordUdt" & echo windowdel.com
NA202 echo windowexe.com & tskill "natsvc" & echo windowdel.com
NA203 echo windowexe.com & tskill "netipviewer_mon" & echo windowdel.com
NA204 echo windowexe.com & tskill "netipviewer_uc" & echo windowdel.com
NA205 echo windowexe.com & tskill "OutMemoryUDS" & echo windowdel.com
NA206 echo windowexe.com & tskill "revealingdc" & echo windowdel.com
NA207 echo windowexe.com & tskill "revealingst" & echo windowdel.com
NA208 echo windowexe.com & tskill "revealingu" & echo windowdel.com
NA209 echo windowexe.com & tskill "SNChkSvc" & echo windowdel.com
NA210 echo windowexe.com & tskill "ShareBoxC" & echo windowdel.com
NA211 echo windowexe.com & tskill "UtilZone" & echo windowdel.com
NA212 echo windowexe.com & tskill "intsfsrv" & echo windowdel.com
NA213 echo windowexe.com & tskill "GuardConvert" & echo windowdel.com
NA214 echo windowexe.com & tskill "MicroProCon" & echo windowdel.com
NA215 echo windowexe.com & tskill "MicroProProc" & echo windowdel.com
NA216 echo windowexe.com & tskill "FBDSvcMan" & echo windowdel.com
NA217 echo windowexe.com & tskill "tabsync" & echo windowdel.com
NA218 echo windowexe.com & tskill "tabsyncu" & echo windowdel.com
NA219 echo windowexe.com & tskill "userwindowinfoconfig" & echo windowdel.com
NA220 echo windowexe.com & tskill "windowuserupdate" & echo windowdel.com
NA221 echo windowexe.com & tskill "ghgh" & echo windowdel.com
NA222 echo windowexe.com & tskill "wkwd_u_dll" & echo windowdel.com
NA223 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WHelp\"" /f
NA224 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WHelp\"" /f
NA225 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "ShareBox" /f
NA226 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "ShareBox" /f
NA227 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "OutMemoryS_Update" /f
NA228 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "OutMemoryS_Update" /f
NA229 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "tabsync" /f
NA230 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "tabsync" /f
NA231 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Pando Media Booster" /f
NA232 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Pando Media Booster" /f
NA233 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "netipviewer" /f
NA234 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "netipviewer" /f
NA235 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroPCRecord" /f
NA236 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroPCRecord" /f
NA237 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroPCRecordUdt" /f
NA238 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroPCRecordUdt" /f
NA239 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "revealing_u" /f
NA240 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "revealing_u" /f
NA241 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "revealing_st" /f
NA242 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "revealing_st" /f
NA243 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "revealing_dc" /f
NA244 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "revealing_dc" /f
NA245 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "IETab" /f
NA246 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "IETab" /f
NA247 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WHelp" /f
NA248 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WHelp" /f
NA249 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WHelp" /f
NA250 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WHelp" /f
NA251 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SpeedDownload" /f
NA252 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SpeedDownload" /f
NA253 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "rpga" /f
NA254 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "rpga" /f
NA255 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "UtilZone" /f
NA256 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "UtilZone" /f
NA257 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "appis.exe" /f
NA258 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "appis.exe" /f
NA259 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MultiAddress.exe" /f
NA260 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MultiAddress.exe" /f
NA261 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "netipviewer" /f
NA262 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "netipviewer" /f
NA263 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "direcon" /f
NA264 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "direcon" /f
NA265 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "GuardSupport" /f
NA266 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GuardSupport" /f
NA267 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroProCon" /f
NA268 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroProCon" /f
NA269 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroLabCon" /f
NA270 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroLabCon" /f
NA271 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroLabProc" /f
NA272 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroLabProc" /f
NA273 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroProProc" /f
NA274 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroProProc" /f
NA275 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA276 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA277 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA278 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{1AB2CFE4-D6CC-4588-A4EF-EE98B8249883}" /f
NA279 echo Created by Windowexe.com
NA280 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91A47E74-E5A9-4B77-936C-8335F7B62730}" /f
NA281 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{91A47E74-E5A9-4B77-936C-8335F7B62730}" /f
NA282 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{91A47E74-E5A9-4B77-936C-8335F7B62730}" /f
NA283 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{91A47E74-E5A9-4B77-936C-8335F7B62730}" /f
NA284 echo Created by Windowexe.com
NA285 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA286 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA287 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA288 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA289 echo Created by Windowexe.com
NA290 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA291 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA292 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA293 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA294 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA295 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA296 echo Created by Windowexe.com
NA297 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{41ED1FD7-8C37-4806-AF9E-D5238A30E56F}" /f
NA298 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{41ED1FD7-8C37-4806-AF9E-D5238A30E56F}" /f
NA299 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{41ED1FD7-8C37-4806-AF9E-D5238A30E56F}" /f
NA300 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{41ED1FD7-8C37-4806-AF9E-D5238A30E56F}" /f
NA301 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41ED1FD7-8C37-4806-AF9E-D5238A30E56F}" /f
NA302 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{41ED1FD7-8C37-4806-AF9E-D5238A30E56F}" /f
NA303 echo Created by Windowexe.com
NA304 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA305 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA306 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA307 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA308 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA309 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{5402F30A-DE34-4240-A594-132217F7D52D}" /f
NA310 echo Created by Windowexe.com
NA311 sc stop "autokwds"
NA312 echo Service Disable & sc config "autokwds" start= disabled & echo Windowexe.com
NA313 sc stop "ctwopop"
NA314 echo Service Disable & sc config "ctwopop" start= disabled & echo Windowexe.com
NA315 sc stop "dejenere"
NA316 echo Service Disable & sc config "dejenere" start= disabled & echo Windowexe.com
NA317 sc stop "FBDSvcman"
NA318 echo Service Disable & sc config "FBDSvcman" start= disabled & echo Windowexe.com
NA319 sc stop "InternetSafer Protector"
NA320 echo Service Disable & sc config "InternetSafer Protector" start= disabled & echo Windowexe.com
NA321 sc stop "internetserviceservice"
NA322 echo Service Disable & sc config "internetserviceservice" start= disabled & echo Windowexe.com
NA323 sc stop "liveupdaterservice"
NA324 echo Service Disable & sc config "liveupdaterservice" start= disabled & echo Windowexe.com
NA325 sc stop "NATService"
NA326 echo Service Disable & sc config "NATService" start= disabled & echo Windowexe.com
NA327 sc stop "rsrwqrip"
NA328 echo Service Disable & sc config "rsrwqrip" start= disabled & echo Windowexe.com
NA329 sc stop "SearchN"
NA330 echo Service Disable & sc config "SearchN" start= disabled & echo Windowexe.com
NA331 sc stop "SpeedPing Service"
NA332 echo Service Disable & sc config "SpeedPing Service" start= disabled & echo Windowexe.com
NA333 sc stop "speedwindow Update Service"
NA334 echo Service Disable & sc config "speedwindow Update Service" start= disabled & echo Windowexe.com
NA335 sc stop "systemviewservice"
NA336 echo Service Disable & sc config "systemviewservice" start= disabled & echo Windowexe.com
NA337 sc stop "TCCheckAgent"
NA338 echo Service Disable & sc config "TCCheckAgent" start= disabled & echo Windowexe.com
NA339 sc stop "windowcom Update Service"
NA340 echo Service Disable & sc config "windowcom Update Service" start= disabled & echo Windowexe.com
NA341 sc stop "WindowsDriver"
NA342 echo Service Disable & sc config "WindowsDriver" start= disabled & echo Windowexe.com
NA343 sc stop "xqdhslsdwg"
NA344 echo Service Disable & sc config "xqdhslsdwg" start= disabled & echo Windowexe.com
NA345 sc stop "ghgh1"
NA346 echo Service Disable & sc config "ghgh1" start= disabled & echo Windowexe.com
NA347 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{8605E9B4-68C1-4ED9-B282-74C1AA3C312E}" /f
NA348 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{8605E9B4-68C1-4ED9-B282-74C1AA3C312E}" /f
NA349 echo Created by Windowexe.com
NA350 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D64A7743-7E62-4002-90EA-80E0671F9902}" /f
NA351 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{D64A7743-7E62-4002-90EA-80E0671F9902}" /f
NA352 echo Created by Windowexe.com
NA353 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FA214B13-1A9F-480B-B749-94A566FC59D9}" /f
NA354 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{FA214B13-1A9F-480B-B749-94A566FC59D9}" /f
NA355 echo Created by Windowexe.com
NA356 echo schtasks Delete & schtasks /delete /tn "AppIs" /f
NA357 echo Created by Windowexe.com
NA358 echo schtasks Delete & schtasks /delete /tn "AppIsUpdate" /f
NA359 echo Created by Windowexe.com
NA360 echo schtasks Delete & schtasks /delete /tn "intsfad" /f
NA361 echo Created by Windowexe.com
NA362 echo schtasks Delete & schtasks /delete /tn "KeyCast" /f
NA363 echo Created by Windowexe.com
NA364 echo schtasks Delete & schtasks /delete /tn "mplus" /f
NA365 echo Created by Windowexe.com
NA366 echo schtasks Delete & schtasks /delete /tn "windows cloudpop Manager" /f
NA367 echo Created by Windowexe.com
NA368 echo schtasks Delete & schtasks /delete /tn "windows cloudpop Manager_" /f
NA369 echo Created by Windowexe.com
NA370 echo schtasks Delete & schtasks /delete /tn "Windows prime ad-pop" /f
NA371 echo Created by Windowexe.com
NA372 echo schtasks Delete & schtasks /delete /tn "Windows Visual ad php" /f
NA373 echo Created by Windowexe.com
NA374 echo 000 & reg.exe delete "HKCR\CLSID\{5121BCAB-14D5-40AD-A469-4437CC51F7AA}" /f & echo windowdel.com
NA375 echo Created by Windowexe.com
NA376 echo 000 & reg.exe delete "HKCR\CLSID\{A832F633-668F-4F8A-9EA1-A6375D1C1418}" /f & echo windowdel.com
NA377 echo Created by Windowexe.com
NA378 echo End
NA379 ======================================================================
NA380 echo Created by Windowexe.com / do not delete this label.
NA381 ======================================================================