Logo Hardware.com.br
AcNeto
AcNeto Veterano Registrado
758 Mensagens 56 Curtidas

Como deletar os toolbars firefox e ie com .BAT?

#1 Por AcNeto 28/09/2012 - 21:27
Boa noite.

Fiz um extenso arquivo bat para fazer uma limpeza no sistema, desinstalando essas porqueiras que o baixaki e companhia estão colocando no pc da turma.

Criei uma Máquina virtual só para essa finalidade, mas cheguei em um ponto que esbarrei na falta de habilidade hehe.
Consigo remover vários programas, pastas, registros, mas no caso da pasta de extensão do firefox, aquela oculta não consigo porque o caminho muda de usuário para usuário.

Ex:
C:\Users\Virus\AppData\Roaming\Mozilla\Firefox\Profiles\p0y8in9i.default\extensions

Existe 2 dados únicos de cada pc, o nome do usuário que no caso ali em cima é "Virus", e a pasta "p0y8in9i.default"
O usuário é só trocar por "%USERNAME" mas a pasta "p0y8in9i.default" não consegui fazer algo do tipo, testei com curinga "*.default" não funcionou, não deleta os arquivos que desejo, mas se deixo "p0y8in9i.default" ai então deleta.

Se eu for no prompt e digitar
"cd C:\Users\%USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\*.default\" vou direto para a pasta "p0y8in9i.default"

Não sei como chegar até a pasta "extensions" para deletar os toolbars.

Outra dúvida é no registro, na maioria funciona colocar o comando "REG DELETE HKLM\SOFTWARE\PSafe /va /f "

Mas para deletar dentro da pasta "PSafe" no caso abaixo a "LockBox" tenho que adicionar até ela, só indicando a "PSafe" não elimina as subpastas, até ai tudo bem, mas se tiver alguma forma mais facil!!!!

REG DELETE HKLM\SOFTWARE\PSafe\LockBox /va /f

Isso não elimina as pastas citadas, mas elimina tudo que tem dentro delas.

Já no registro do internet explorer\toolbar, o comando não funciona para deletar o que tem la dentro, como faria nesse caso?

Outro lugar que não funciona é na chave HKLM\SOFTWARE\Microsoft\ShareTools\Msconfig, dentro tem as subpastas "startupfolder' e "starupreg" que é aquela do msconfig, quando limpa a inicialização, o que desmarcou lá aparece dentro destas pasta podendo ser excluído, mas o comando REG DELETE não funciona também.

Bom, seria isso que está faltando para deixar o ultra.bat funcionando mostrando_lingua.png

Abraço.
Placa Gigabyte 970-ud3p / Cooler Master TX3 Evo / Placa de vídeo GTX 750Ti
Processador FX 8320 / 16 GB Corsair Vengeance 1600
SSD OCZ 128 Sistemas (Win7 64/Mint 64)
HD 2 TB, 2 TB WD / HD 3 TB Seagate
Fonte corsair 520W /Dual Monitor LG 23"
Meyer!
Meyer! Ubbergeek Registrado
3.9K Mensagens 535 Curtidas
#2 Por Meyer!
28/09/2012 - 21:40
Pra chegar na pasta perfil do Firefox tenta algo assim:

cd %appdata%\Mozilla\Firefox\Profiles
cd *.default

Daí dá o CD para as pastas desejadas e usa o comando "DELETE".
Obs: O comando "CD" aceita curingas.

Em relação a chave do PSafe, não utilize o parâmetro "/va":

REG DELETE HKLM\SOFTWARE\PSafe /f
Quanto a última dúvida, talvez faltou colocar o caminho da chave entre parênteses:

reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\Msconfig\startupreg" /va /f
P.S.: Todos os 3 testados em uma VM com Windows XP...
AcNeto
AcNeto Veterano Registrado
758 Mensagens 56 Curtidas
#3 Por AcNeto
28/09/2012 - 21:59
Teste da forma que vc falou e não funcionou, até modifiquei aproveitando a forma que vc fez desta forma.

cd C:\Users\%USERNAME%\AppData\Roaming\Mozilla\Firefox\Profiles
cd *.default
DEL /s /q "\extensions\{C9B68337-E93A-44EA-94DC-CB300EC06444}"

E também rd /s /q "\extensions"

Fiz das duas formas, da sua e essa que postei e não deletou aquela extensão.

A do registro testo depois.

Abraço.
Placa Gigabyte 970-ud3p / Cooler Master TX3 Evo / Placa de vídeo GTX 750Ti
Processador FX 8320 / 16 GB Corsair Vengeance 1600
SSD OCZ 128 Sistemas (Win7 64/Mint 64)
HD 2 TB, 2 TB WD / HD 3 TB Seagate
Fonte corsair 520W /Dual Monitor LG 23"
Meyer!
Meyer! Ubbergeek Registrado
3.9K Mensagens 535 Curtidas
#4 Por Meyer!
28/09/2012 - 22:31
AcNeto disse:
Teste da forma que vc falou e não funcionou, até modifiquei aproveitando a forma que vc fez desta forma.

cd C:\Users\%USERNAME%\AppData\Roaming\Mozilla\Firefox\Profiles
cd *.default
DEL /s /q "\extensions\{C9B68337-E93A-44EA-94DC-CB300EC06444}"

E também rd /s /q "\extensions"

Fiz das duas formas, da sua e essa que postei e não deletou aquela extensão.

A do registro testo depois.

Abraço.

Um porém: Ao invés de usar "C:\Users\%username%\appdata\roaming" você usa "%appdata%\", pois no Windows XP a pasta "Appdata\Roaming" fica com nome diferente.

Para deletar pastas você usa o comando "RMDIR". Modificando ficaria assim para manter compatibilidade com o Windows XP:
cd %appdata%\Mozilla\Firefox\Profiles\*.default\extensions
rmdir /s /q "{C9B68337-E93A-44EA-94DC-CB300EC06444}"
OBS: Use o parâmetro "/s" para deletar a árvore inteira de pastas.
AcNeto
AcNeto Veterano Registrado
758 Mensagens 56 Curtidas
#5 Por AcNeto
29/09/2012 - 15:38
Meyer! disse:
Um porém: Ao invés de usar "C:\Users\%username%\appdata\roaming" você usa "%appdata%\", pois no Windows XP a pasta "Appdata\Roaming" fica com nome diferente.

Para deletar pastas você usa o comando "RMDIR". Modificando ficaria assim para manter compatibilidade com o Windows XP:
cd %appdata%\Mozilla\Firefox\Profiles\*.default\extensions
rmdir /s /q "{C9B68337-E93A-44EA-94DC-CB300EC06444}"
OBS: Use o parâmetro "/s" para deletar a árvore inteira de pastas.



Funcionou desta forma, fiz um teste com o rmdir para a pasta e o DEL para um aquivo e ambos funcionaram.

Já no registro os toolbars do internet consegui remover.
Aquela pasta do PSafe também foi excluída com sua dica, mas no msconfig não funcionou, tanto em Win 7 quanto Win xp.

Aproveitando essas compatibilidades que vc ensinou, existe também algum que faça compatibilidade na pasta arquivos de programas, no Win 7 é Programs files, no XP é Arquivos de programas.

Abraço.
Placa Gigabyte 970-ud3p / Cooler Master TX3 Evo / Placa de vídeo GTX 750Ti
Processador FX 8320 / 16 GB Corsair Vengeance 1600
SSD OCZ 128 Sistemas (Win7 64/Mint 64)
HD 2 TB, 2 TB WD / HD 3 TB Seagate
Fonte corsair 520W /Dual Monitor LG 23"
Meyer!
Meyer! Ubbergeek Registrado
3.9K Mensagens 535 Curtidas
#6 Por Meyer!
29/09/2012 - 15:55
AcNeto disse:
Funcionou desta forma, fiz um teste com o rmdir para a pasta e o DEL para um aquivo e ambos funcionaram.

Já no registro os toolbars do internet consegui remover.
Aquela pasta do PSafe também foi excluída com sua dica, mas no msconfig não funcionou, tanto em Win 7 quanto Win xp.

Aproveitando essas compatibilidades que vc ensinou, existe também algum que faça compatibilidade na pasta arquivos de programas, no Win 7 é Programs files, no XP é Arquivos de programas.

Abraço.

Você usa "%programfiles%" para manter compatibilidade. Porém, em sistemas 64 bits, a pasta dos programas 32 bits é "%programfiles(x86)%"
AcNeto
AcNeto Veterano Registrado
758 Mensagens 56 Curtidas
#7 Por AcNeto
29/09/2012 - 16:20
Meyer! disse:
Você usa "%programfiles%" para manter compatibilidade. Porém, em sistemas 64 bits, a pasta dos programas 32 bits é "%programfiles(x86)%"


Está me poupando alguns km de digitação hehe.
Aquela dica do appdata funciona bem mas tenho uma dúvida:
%appdata% = Roaming ou Dados de aplicativos
? = Local ou Configurações locais\Dados de aplicativos.
Placa Gigabyte 970-ud3p / Cooler Master TX3 Evo / Placa de vídeo GTX 750Ti
Processador FX 8320 / 16 GB Corsair Vengeance 1600
SSD OCZ 128 Sistemas (Win7 64/Mint 64)
HD 2 TB, 2 TB WD / HD 3 TB Seagate
Fonte corsair 520W /Dual Monitor LG 23"
AcNeto
AcNeto Veterano Registrado
758 Mensagens 56 Curtidas
#9 Por AcNeto
30/09/2012 - 01:06
Meyer! disse:
No Windows 7 é "%LOCALAPPDATA%", mas no XP não tem equivalente. Estou verificando e se eu conseguir retorno.


Já arrumei aqui os que eu já tinha feito desta forma que vc falou e está funcionando.

No geral está indo bem o bat, mas engraçado que tem chave do registro la da pasta uninstall que sem parênteses funciona outros já não, tem que colocar parênteses.
E o Msconfig não tem jeito, não consigo limpar a starupfolder e a outra, se eu adicionar manualmente a pasta que está dentro vai, mas como ali aparece cada coisa esquisita seria o ideal limpar ela por completo.

Outra coisa que não consegui fazer funcionar foi nesta pasta:

%localappdata%\google\chrome\user data\default\local storage

Dentro desta pasta fica alguns buscadores instalados no chrome, não consigo deletar o que está dentro dela, só faltou tentar o esquema igual do firefox, agora que me toquei.

Falta pouco para finalizar esse bat, então disponibilizo aqui para quem quiser testar e dar opinião.

Abraço.

Edit:
Mais um detalhe, teve um desses programas maravilhosos que vem de brinde que alterou o atalho dos navegadores, ele adicionava a url dele, e eu me matando procurando arquivo e era no atalho.
Como deleta atalhos da area de trabalho pelo bat?
Fica os atalhos dos programas desinstalados tendo que remover manualmente.

T+
Placa Gigabyte 970-ud3p / Cooler Master TX3 Evo / Placa de vídeo GTX 750Ti
Processador FX 8320 / 16 GB Corsair Vengeance 1600
SSD OCZ 128 Sistemas (Win7 64/Mint 64)
HD 2 TB, 2 TB WD / HD 3 TB Seagate
Fonte corsair 520W /Dual Monitor LG 23"
AcNeto
AcNeto Veterano Registrado
758 Mensagens 56 Curtidas
#10 Por AcNeto
01/10/2012 - 19:33
Meyer!
Aqui está um beta de onde quero chegar trabalho_duro.gif
Pode ter algum erro ai no meio, mas até que funciona bem.
Ainda falta ajustes tipo para sistema 64 e alguma pasta especifica do xp.


taskkill.exe /F /IM explorer.exe

#PSafe
taskkill.exe /F /IM PSafeSystray.exe
taskkill.exe /F /IM PSafeCategoryFinder.exe
taskkill.exe /F /IM PSafesvc.exe
taskkill.exe /F /IM PsafeWD.exe
taskkill.exe /F /IM psprotege.exe
taskkill.exe /F /IM PSafeWDS.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSafe" /f
rd /s /q "%programfiles%\PSafe"
rd /s /q "C:\ProgramData\PSafe"
rd /s /q "c:\users\%USERNAME%\PSafe"
REG DELETE "HKLM\SOFTWARE\PSafe" /f
REG DELETE "HKCR\PSafeEZNSE.RootFolder" /f

#AdvancedSystemProtector
taskkill.exe /f /im AdvancedSystemProtector.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Protector_is1" /f
rd /s /q "%programfiles%\Advanced System Protector"
rd /s /q "C:\ProgramData\Systweak"
rd /s /q "C:\ProgramData\Microsoft\Windows\Start Menu\Programs"
rd /s /q "%appdata%\Systweak"
DEL /s /q "C:\Users\Public\Desktop\Advanced System Protector.lnk"

#Baixaki
REG DELETE "HKCU\Software\Baixaki" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Baixaki" /f

#Babylon
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar" /f
rd /s /q "%programfiles%\BabylonToolbar"
rd /s /q "C:\ProgramData\Babylon"
rd /s /q "%appdata%\Babylon"
rd /s /q "%appdata%\BabylonToolbar"
rd /s /q "c:\users\%USERNAME%\appdata\LocalLow\BabylonToolbar"
REG DELETE "HKLM\SOFTWARE\Babylon" /f
REG DELETE "HKCU\Software\BabylonToolbar" /f
REG DELETE "HKCU\SOFTWARE\Microsoft\Babylon" /f
REG DELETE "HKLM\SOFTWARE\BabylonToolbar" /f
REG DELETE "HKCR\Babylon.dskBnd" /f
REG DELETE "HKCR\Babylon.dskBnd.1" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\BabylonToolbar\BabylonToolbar\user" /f

#BrowserCompanion
taskkill.exe /F /IM tbhcn.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion" /f
rd /s /q "%programfiles%\BrowserCompanion"
REG DELETE "HKLM\SOFTWARE\BrowserCompanion" /f
REG DELETE "HKLM\SOFTWARE\BrowserMngr" /f
rd /s /q "%appdata%\BrowserCompanion"

#Claro
taskkill.exe /f /im clarosrv.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\claro" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{069B290F-5398-4629-A009-85B4BCB4B1B9}" /f
REG DELETE "HKLM\SOFTWARE\Claro LTD" /f
REG DELETE "HKCU\Software\Claro LTD" /f
rd /s /q "%programfiles%\Claro LTD"
rd /s /q "%appdata%\Claro" /f
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\Claro LTD"
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Claro LTD" /f

#Conduit
REG DELETE "HKLM\SOFTWARE\Conduit" /f
rd /s /q "%programfiles%\Conduit"
rd /s /q "%appdata%\Conduit"
rd /s /q "%LOCALAPPDATA%\Conduit"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\Conduit"
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Conduit" /f

#Dealply
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly" /f
rd /s /q "%programfiles%\DealPly"
rd /s /q "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dealply"
REG DELETE "HKLM\SOFTWARE\DealPly" /f
REG DELETE "HKCU\Software\Dealply" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Dealply" /f

#Funmoods
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\funmoods" /f
rd /s /q "%programfiles%\Funmoods"
DEL /s /q "%LOCALAPPDATA%\funmoods.crx"
DEL /s /q "%LOCALAPPDATA%\funmoods-speeddial.crx"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\Funmoods"
REG DELETE "HKCR\funmoods.funmoodsHlpr" /f
REG DELETE "HKCR\funmoods.funmoodsHlpr.1" /f
REG DELETE "HKLM\SOFTWARE\Funmoods" /f
REG DELETE "HKCR\funmoodsApp.appCore" /f
REG DELETE "HKCR\funmoodsApp.appCore.1" /f
REG DELETE "HKCR\funmoods.dskBnd" /f
REG DELETE "HKCR\funmoods.dskBnd.1" /f

#Iminent
taskkill.exe /F /IM Iminent.exe
taskkill.exe /F /IM Iminent.Messengers.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A76AA284-E52D-47E6-9E4F-B85DBF8E35C3}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6E71E28-43CB-423E-B415-B7C00D77902E}" /f
rd /s /q "%programfiles%\Iminent"
rd /s /q "%programfiles%\Iminent Toolbar"
rd /s /q "C:\ProgramData\Iminent"
rd /s /q "%appdata%\Iminent"
rd /s /q "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Iminent"
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Iminent" /f
REG DELETE "HKLM\SOFTWARE\Iminent" /f
REG DELETE "HKLM\SOFTWARE\Loader" /f
REG DELETE "HKCU\Software\Iminent" /f

#Internet explorer
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /va /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0af350d9-3916-454b-ac53-0b0b65f41301}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{206A6E76-36B0-495C-BB71-63F3D1247425}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60295942-9E5F-4EE8-B785-3A655904D24F}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A14E2859-E39B-4EDE-ABF1-E19A029F57F3}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}" /f

#Msn Plus
taskkill.exe /F /IM Smartbar.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B0A46C35-38C8-4627-9F11-706B8EA36D03}" /f
rd /s /q "%appdata%\Smartbar"
rd /s /q "%LOCALAPPDATA%\Smartbar"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\Smartbar"
REG DELETE "HKCU\Software\Smartbar" /f
REG DELETE "HKCU\Software\SmartbarBackup" /f
REG DELETE "HKCU\Software\SmartbarLog" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Smartbar" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\SmartbarBackup" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\SmartbarLog" /f

#PcPerformer
taskkill.exe /F /IM PCPerformer.exe
taskkill.exe /F /IM pcpmngr.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Performer_is1" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" /f
REG DELETE "HKLM\SOFTWARE\bProtector" /f
REG DELETE "HKLM\SOFTWARE\PerformerSoft" /f
REG DELETE "HKCU\Software\bProtector" /f
REG DELETE "HKCU\Software\PerformerSoft" /f
rd /s /q "%programfiles%\PC Performer"
rd /s /q "%appdata%\PerformerSoft"
rd /s /q "%LOCALAPPDATA%\PC Performer Manager"
rd /s /q "%LOCALAPPDATA%\IBUpdaterService"
rd /s /q "c:\users\%USERNAME%\Start Menu\Programs\PC Performer"
rd /s /q "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Performer"
rd /s /q "C:\ProgramData\PC Performer Manager"
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\bProtector" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\PerformerSoft" /f

#Positivo Deskmedia
rd /s /q "C:\Positivo"
rd /s /q "%appdata%\Positivo"
REG DELETE "HKLM\SOFTWARE\Deskmedia" /f
REG DELETE "HKCU\Software\Deskmedia" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Deskmedia" /f

#SweetIM
taskkill.exe /F /IM SweetIM.exe
taskkill.exe /F /IM SweetPacksUpdateManager.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7683B745-6060-41FD-AA75-0BBB383FEAD4}" /f
rd /s /q "%programfiles%\SweetIM"
rd /s /q "C:\ProgramData\SweetIM"
del /s /q "C:\Users\%username%\Desktop\SweetPcFix.url"
REG DELETE "HKLM\SOFTWARE\SweetIM" /f
REG DELETE "HKCU\Software\SweetIM" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\SweetIM" /f

#SearchTheWeb
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP" /f

#Tuto4pc
taskkill.exe /F /IM tuto4pc_br_4.exe
taskkill.exe /F /IM upt4pc_br_4.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TUTO4PC_BR_4_is1" /f
rd /s /q "%programfiles%\TUTO4PC"
rd /s /q "%appdata%\tuto4pc_br_4"
rd /s /q "%appdata%\baidu"
rd /s /q "%LOCALAPPDATA%\tuto4pc_br_4"
rd /s /q "%LOCALAPPDATA%\CRE"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\Toolbar4"
REG DELETE "HKLM\SOFTWARE\TUTO4PC" /f
REG DELETE "HKCU\Software\Tutorials" /f
REG DELETE "HKCU\Software\TutoTag" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Tutorials" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\TutoTag" /f

#UtorrentTooblar
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentBar_PT Toolbar" /f
rd /s /q "%programfiles%\uTorrentBar_PT"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\uTorrentBar_PT"
REG DELETE "HKLM\SOFTWARE\uTorrentBar_PT" /f

#v9Soft
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\V9Software" /f
rd /s /q "%programfiles%\v9Soft"
REG DELETE "HKLM\SOFTWARE\V9Software" /f

#Outros
REG DELETE "HKCU\Software\Baidu" /f
REG DELETE "HKCU\Software\Softonic" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Baidu" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Softonic" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\AppDataLow\Software" /va /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Toolbar" /va /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\DataMngr" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\DataMngr_toolbar" /f
rd /s /q "%appdata%\Microsoft\Windows\Start Menu\Programs\Hao123"
del /s /q "C:\Users\%username%\Desktop\hao123.lnk"
del /s /q "C:\Users\%username%\Desktop\Google Chrome.lnk"
del /s /q "C:\Users\%username%\Desktop\Search the web.url"
del /s /q "C:\Users\%username%\Desktop\hao123.lnk"
del /s /q "C:\Users\Public\Desktop\PC Performer.lnk"
rd /s /q "C:\ProgramData\IBUpdaterService"
rd /s /q "%LOCALAPPDATA%\CRE"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\bbrs_002.tb"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\PriceGong"

#Temporários
rd /s /q "%LOCALAPPDATA%\Temp"
rd /s /q "%LOCALAPPDATA%\Microsoft\Windows\Temporary Internet Files"

#Google
REG DELETE "HKLM\SOFTWARE\WoW6432Node\Google\Chrome\Extensions" /va /f
DEL /s /q %LOCALAPPDATA%\Google\Chrome\User Data\Default\bProtector Web Data"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\bprotectorpreferences"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Storage" /va
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\dcillohgikpecbmgioknapdpcjofaafl"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\mdebcffgnijbblbinknkbefciofebcda"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}"
REG DELETE "HKCU\Software\Wow6432Node\Google\Chrome\Extensions" /va /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Wow6432Node\Google\Chrome\Extensions" /f
DEL /s /q /f "%LOCALAPPDATA%\Google\Update\GoogleUpdate.exe"

#Plugins firefox
DEL /s /q /f "%programfiles%\Mozilla Firefox\searchplugins\babylon.xml"
DEL /s /q /f "%programfiles%\Mozilla Firefox\searchplugins\SearchTheWeb.xml"
DEL /s /q /f "%programfiles%\Mozilla Firefox\searchplugins\v9.xml"
cd %appdata%\Mozilla\Firefox\Profiles\*.default
rmdir /s /q "CT2851643"
rmdir /s /q "smartbar"
rmdir /s /q "SweetPacksToolbarData"

cd %appdata%\Mozilla\Firefox\Profiles\*.default\extensions
rmdir /s /q "{C9B68337-E93A-44EA-94DC-CB300EC06444}"
rmdir /s /q "{e0301295-ab3e-4af3-979f-3d453c5f9f48}"
rmdir /s /q "{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}"
rmdir /s /q "{EEE6C361-6118-11DC-9C72-001320C79847}"
rmdir /s /q "bbrs_002@blabbers.com"
rmdir /s /q "ffxtlbr@claro.com"
rmdir /s /q "helperbar@helperbar.com"
rmdir /s /q "staged"
DEL /s /q "{EEE6C361-6118-11DC-9C72-001320C79847}.xpi"

cd %appdata%\Mozilla\Firefox\Profiles\*.default\Searchplugins
DEL /s /q "bProtect.xml"
DEL /s /q "conduit.xml"
DEL /s /q "Messenger Plus Smartbar Search.xml"
DEL /s /q "sweetim.xml"
del /s /q "C:\Users\Public\Desktop\Mozilla Firefox.lnk"
REG DELETE "HKCU\Software\mozilla\Firefox\Extensions" /va /f
REG DELETE "HKLM\SOFTWARE\Mozilla\Firefox\Extensions" /va /f

@echo off

rem configura o firefox

c:
cd C:\Users\%USERNAME%\AppData\Roaming\Mozilla\Firefox\Profiles\*.default
echo user_pref("browser.startup.homepage", "http://www.google.com.br" >>prefs.js

start explorer.exe

exit
Ainda não consigo excluir os buscadores no internet explorer, e o msconfig também não tem jeito, fiz um bat separado mas não consigo fazer funcionar.

Se tiver alguma sugestão será bem vinda.

Abraço.
Placa Gigabyte 970-ud3p / Cooler Master TX3 Evo / Placa de vídeo GTX 750Ti
Processador FX 8320 / 16 GB Corsair Vengeance 1600
SSD OCZ 128 Sistemas (Win7 64/Mint 64)
HD 2 TB, 2 TB WD / HD 3 TB Seagate
Fonte corsair 520W /Dual Monitor LG 23"
Meyer!
Meyer! Ubbergeek Registrado
3.9K Mensagens 535 Curtidas
#11 Por Meyer!
01/10/2012 - 21:23
AcNeto disse:
Meyer!
Aqui está um beta de onde quero chegar trabalho_duro.gif
Pode ter algum erro ai no meio, mas até que funciona bem.
Ainda falta ajustes tipo para sistema 64 e alguma pasta especifica do xp.


taskkill.exe /F /IM explorer.exe

#PSafe
taskkill.exe /F /IM PSafeSystray.exe
taskkill.exe /F /IM PSafeCategoryFinder.exe
taskkill.exe /F /IM PSafesvc.exe
taskkill.exe /F /IM PsafeWD.exe
taskkill.exe /F /IM psprotege.exe
taskkill.exe /F /IM PSafeWDS.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSafe" /f
rd /s /q "%programfiles%\PSafe"
rd /s /q "C:\ProgramData\PSafe"
rd /s /q "c:\users\%USERNAME%\PSafe"
REG DELETE "HKLM\SOFTWARE\PSafe" /f
REG DELETE "HKCR\PSafeEZNSE.RootFolder" /f

#AdvancedSystemProtector
taskkill.exe /f /im AdvancedSystemProtector.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Protector_is1" /f
rd /s /q "%programfiles%\Advanced System Protector"
rd /s /q "C:\ProgramData\Systweak"
rd /s /q "C:\ProgramData\Microsoft\Windows\Start Menu\Programs"
rd /s /q "%appdata%\Systweak"
DEL /s /q "C:\Users\Public\Desktop\Advanced System Protector.lnk"

#Baixaki
REG DELETE "HKCU\Software\Baixaki" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Baixaki" /f

#Babylon
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar" /f
rd /s /q "%programfiles%\BabylonToolbar"
rd /s /q "C:\ProgramData\Babylon"
rd /s /q "%appdata%\Babylon"
rd /s /q "%appdata%\BabylonToolbar"
rd /s /q "c:\users\%USERNAME%\appdata\LocalLow\BabylonToolbar"
REG DELETE "HKLM\SOFTWARE\Babylon" /f
REG DELETE "HKCU\Software\BabylonToolbar" /f
REG DELETE "HKCU\SOFTWARE\Microsoft\Babylon" /f
REG DELETE "HKLM\SOFTWARE\BabylonToolbar" /f
REG DELETE "HKCR\Babylon.dskBnd" /f
REG DELETE "HKCR\Babylon.dskBnd.1" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\BabylonToolbar\BabylonToolbar\user" /f

#BrowserCompanion
taskkill.exe /F /IM tbhcn.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion" /f
rd /s /q "%programfiles%\BrowserCompanion"
REG DELETE "HKLM\SOFTWARE\BrowserCompanion" /f
REG DELETE "HKLM\SOFTWARE\BrowserMngr" /f
rd /s /q "%appdata%\BrowserCompanion"

#Claro
taskkill.exe /f /im clarosrv.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\claro" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{069B290F-5398-4629-A009-85B4BCB4B1B9}" /f
REG DELETE "HKLM\SOFTWARE\Claro LTD" /f
REG DELETE "HKCU\Software\Claro LTD" /f
rd /s /q "%programfiles%\Claro LTD"
rd /s /q "%appdata%\Claro" /f
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\Claro LTD"
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Claro LTD" /f

#Conduit
REG DELETE "HKLM\SOFTWARE\Conduit" /f
rd /s /q "%programfiles%\Conduit"
rd /s /q "%appdata%\Conduit"
rd /s /q "%LOCALAPPDATA%\Conduit"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\Conduit"
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Conduit" /f

#Dealply
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly" /f
rd /s /q "%programfiles%\DealPly"
rd /s /q "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dealply"
REG DELETE "HKLM\SOFTWARE\DealPly" /f
REG DELETE "HKCU\Software\Dealply" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Dealply" /f

#Funmoods
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\funmoods" /f
rd /s /q "%programfiles%\Funmoods"
DEL /s /q "%LOCALAPPDATA%\funmoods.crx"
DEL /s /q "%LOCALAPPDATA%\funmoods-speeddial.crx"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\Funmoods"
REG DELETE "HKCR\funmoods.funmoodsHlpr" /f
REG DELETE "HKCR\funmoods.funmoodsHlpr.1" /f
REG DELETE "HKLM\SOFTWARE\Funmoods" /f
REG DELETE "HKCR\funmoodsApp.appCore" /f
REG DELETE "HKCR\funmoodsApp.appCore.1" /f
REG DELETE "HKCR\funmoods.dskBnd" /f
REG DELETE "HKCR\funmoods.dskBnd.1" /f

#Iminent
taskkill.exe /F /IM Iminent.exe
taskkill.exe /F /IM Iminent.Messengers.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A76AA284-E52D-47E6-9E4F-B85DBF8E35C3}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6E71E28-43CB-423E-B415-B7C00D77902E}" /f
rd /s /q "%programfiles%\Iminent"
rd /s /q "%programfiles%\Iminent Toolbar"
rd /s /q "C:\ProgramData\Iminent"
rd /s /q "%appdata%\Iminent"
rd /s /q "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Iminent"
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Iminent" /f
REG DELETE "HKLM\SOFTWARE\Iminent" /f
REG DELETE "HKLM\SOFTWARE\Loader" /f
REG DELETE "HKCU\Software\Iminent" /f

#Internet explorer
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /va /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0af350d9-3916-454b-ac53-0b0b65f41301}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{206A6E76-36B0-495C-BB71-63F3D1247425}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60295942-9E5F-4EE8-B785-3A655904D24F}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A14E2859-E39B-4EDE-ABF1-E19A029F57F3}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}" /f

#Msn Plus
taskkill.exe /F /IM Smartbar.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B0A46C35-38C8-4627-9F11-706B8EA36D03}" /f
rd /s /q "%appdata%\Smartbar"
rd /s /q "%LOCALAPPDATA%\Smartbar"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\Smartbar"
REG DELETE "HKCU\Software\Smartbar" /f
REG DELETE "HKCU\Software\SmartbarBackup" /f
REG DELETE "HKCU\Software\SmartbarLog" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Smartbar" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\SmartbarBackup" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\SmartbarLog" /f

#PcPerformer
taskkill.exe /F /IM PCPerformer.exe
taskkill.exe /F /IM pcpmngr.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Performer_is1" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" /f
REG DELETE "HKLM\SOFTWARE\bProtector" /f
REG DELETE "HKLM\SOFTWARE\PerformerSoft" /f
REG DELETE "HKCU\Software\bProtector" /f
REG DELETE "HKCU\Software\PerformerSoft" /f
rd /s /q "%programfiles%\PC Performer"
rd /s /q "%appdata%\PerformerSoft"
rd /s /q "%LOCALAPPDATA%\PC Performer Manager"
rd /s /q "%LOCALAPPDATA%\IBUpdaterService"
rd /s /q "c:\users\%USERNAME%\Start Menu\Programs\PC Performer"
rd /s /q "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Performer"
rd /s /q "C:\ProgramData\PC Performer Manager"
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\bProtector" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\PerformerSoft" /f

#Positivo Deskmedia
rd /s /q "C:\Positivo"
rd /s /q "%appdata%\Positivo"
REG DELETE "HKLM\SOFTWARE\Deskmedia" /f
REG DELETE "HKCU\Software\Deskmedia" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Deskmedia" /f

#SweetIM
taskkill.exe /F /IM SweetIM.exe
taskkill.exe /F /IM SweetPacksUpdateManager.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7683B745-6060-41FD-AA75-0BBB383FEAD4}" /f
rd /s /q "%programfiles%\SweetIM"
rd /s /q "C:\ProgramData\SweetIM"
del /s /q "C:\Users\%username%\Desktop\SweetPcFix.url"
REG DELETE "HKLM\SOFTWARE\SweetIM" /f
REG DELETE "HKCU\Software\SweetIM" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\SweetIM" /f

#SearchTheWeb
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP" /f

#Tuto4pc
taskkill.exe /F /IM tuto4pc_br_4.exe
taskkill.exe /F /IM upt4pc_br_4.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TUTO4PC_BR_4_is1" /f
rd /s /q "%programfiles%\TUTO4PC"
rd /s /q "%appdata%\tuto4pc_br_4"
rd /s /q "%appdata%\baidu"
rd /s /q "%LOCALAPPDATA%\tuto4pc_br_4"
rd /s /q "%LOCALAPPDATA%\CRE"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\Toolbar4"
REG DELETE "HKLM\SOFTWARE\TUTO4PC" /f
REG DELETE "HKCU\Software\Tutorials" /f
REG DELETE "HKCU\Software\TutoTag" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Tutorials" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\TutoTag" /f

#UtorrentTooblar
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentBar_PT Toolbar" /f
rd /s /q "%programfiles%\uTorrentBar_PT"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\uTorrentBar_PT"
REG DELETE "HKLM\SOFTWARE\uTorrentBar_PT" /f

#v9Soft
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\V9Software" /f
rd /s /q "%programfiles%\v9Soft"
REG DELETE "HKLM\SOFTWARE\V9Software" /f

#Outros
REG DELETE "HKCU\Software\Baidu" /f
REG DELETE "HKCU\Software\Softonic" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Baidu" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Softonic" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\AppDataLow\Software" /va /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Toolbar" /va /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\DataMngr" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\DataMngr_toolbar" /f
rd /s /q "%appdata%\Microsoft\Windows\Start Menu\Programs\Hao123"
del /s /q "C:\Users\%username%\Desktop\hao123.lnk"
del /s /q "C:\Users\%username%\Desktop\Google Chrome.lnk"
del /s /q "C:\Users\%username%\Desktop\Search the web.url"
del /s /q "C:\Users\%username%\Desktop\hao123.lnk"
del /s /q "C:\Users\Public\Desktop\PC Performer.lnk"
rd /s /q "C:\ProgramData\IBUpdaterService"
rd /s /q "%LOCALAPPDATA%\CRE"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\bbrs_002.tb"
rd /s /q "c:\users\%USERNAME%\AppData\LocalLow\PriceGong"

#Temporários
rd /s /q "%LOCALAPPDATA%\Temp"
rd /s /q "%LOCALAPPDATA%\Microsoft\Windows\Temporary Internet Files"

#Google
REG DELETE "HKLM\SOFTWARE\WoW6432Node\Google\Chrome\Extensions" /va /f
DEL /s /q %LOCALAPPDATA%\Google\Chrome\User Data\Default\bProtector Web Data"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\bprotectorpreferences"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Storage" /va
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\dcillohgikpecbmgioknapdpcjofaafl"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\mdebcffgnijbblbinknkbefciofebcda"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}"
REG DELETE "HKCU\Software\Wow6432Node\Google\Chrome\Extensions" /va /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Wow6432Node\Google\Chrome\Extensions" /f
DEL /s /q /f "%LOCALAPPDATA%\Google\Update\GoogleUpdate.exe"

#Plugins firefox
DEL /s /q /f "%programfiles%\Mozilla Firefox\searchplugins\babylon.xml"
DEL /s /q /f "%programfiles%\Mozilla Firefox\searchplugins\SearchTheWeb.xml"
DEL /s /q /f "%programfiles%\Mozilla Firefox\searchplugins\v9.xml"
cd %appdata%\Mozilla\Firefox\Profiles\*.default
rmdir /s /q "CT2851643"
rmdir /s /q "smartbar"
rmdir /s /q "SweetPacksToolbarData"

cd %appdata%\Mozilla\Firefox\Profiles\*.default\extensions
rmdir /s /q "{C9B68337-E93A-44EA-94DC-CB300EC06444}"
rmdir /s /q "{e0301295-ab3e-4af3-979f-3d453c5f9f48}"
rmdir /s /q "{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}"
rmdir /s /q "{EEE6C361-6118-11DC-9C72-001320C79847}"
rmdir /s /q "bbrs_002@blabbers.com"
rmdir /s /q "ffxtlbr@claro.com"
rmdir /s /q "helperbar@helperbar.com"
rmdir /s /q "staged"
DEL /s /q "{EEE6C361-6118-11DC-9C72-001320C79847}.xpi"

cd %appdata%\Mozilla\Firefox\Profiles\*.default\Searchplugins
DEL /s /q "bProtect.xml"
DEL /s /q "conduit.xml"
DEL /s /q "Messenger Plus Smartbar Search.xml"
DEL /s /q "sweetim.xml"
del /s /q "C:\Users\Public\Desktop\Mozilla Firefox.lnk"
REG DELETE "HKCU\Software\mozilla\Firefox\Extensions" /va /f
REG DELETE "HKLM\SOFTWARE\Mozilla\Firefox\Extensions" /va /f

@echo off

rem configura o firefox

c:
cd C:\Users\%USERNAME%\AppData\Roaming\Mozilla\Firefox\Profiles\*.default
echo user_pref("browser.startup.homepage", "http://www.google.com.br" >>prefs.js

start explorer.exe

exit
Ainda não consigo excluir os buscadores no internet explorer, e o msconfig também não tem jeito, fiz um bat separado mas não consigo fazer funcionar.

Se tiver alguma sugestão será bem vinda.

Abraço.

Amanhã vou dar uma revisada, pois estou ocupado estudando pra prova do Senai... Tem um monte de coisa já, com uns ajustes vai ficar bom.
Marcos FRM
Marcos FRM Highlander Registrado
10.3K Mensagens 712 Curtidas
#12 Por Marcos FRM
02/10/2012 - 08:24
Parabéns pelo tópico!

Eu sei que os desinstaladores destas desgraças nem sempre são honestos, ou seja, desisntalam tudo. Uma possível pesquisa a fazer seria tentar invocar o desinstalador de cada uma primeiro e vez o que ele faz (o que desinstala de verdade e os restos que deixa).

Numa cobaia com o SandBoxie e/ou Process Monitor dá para rastrear todos os passos deles.
...
Meyer!
Meyer! Ubbergeek Registrado
3.9K Mensagens 535 Curtidas
#13 Por Meyer!
02/10/2012 - 11:54
Dei uma revisada, falta testar ainda:
@echo on
setlocal enableextensions enabledelayedexpansion

taskkill.exe /F /IM explorer.exe


ver|find "5.1">nul
if errorlevel 0 goto 5152
ver|find "5.2">nul
if errorlevel 0 goto 5152
goto n5152

:5152
echo Set objShell = CreateObject^("Shell.Application"^)>>_getlap.vbs
echo WScript.Echo objShell.Namespace^(^&H1c^&^).Self.Path>>_getlap.vbs
:n5152
for /f "delims=" %%i in ('cscript /nologo _getlap.vbs') DO (
set LOCALAPPDATA=%%i
)
del /q _getlap.vbs
:n5152

rem #PSafe
taskkill.exe /F /IM PSafeSystray.exe
taskkill.exe /F /IM PSafeCategoryFinder.exe
taskkill.exe /F /IM PSafesvc.exe
taskkill.exe /F /IM PsafeWD.exe
taskkill.exe /F /IM psprotege.exe
taskkill.exe /F /IM PSafeWDS.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSafe" /f
rd /s /q "%programfiles%\PSafe"
rd /s /q "%SYSTEMDRIVE%\ProgramData\PSafe"
rd /s /q "%userprofile%\PSafe"
REG DELETE "HKLM\SOFTWARE\PSafe" /f
REG DELETE "HKCR\PSafeEZNSE.RootFolder" /f

rem #AdvancedSystemProtector
taskkill.exe /f /im AdvancedSystemProtector.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced System Protector_is1" /f
rd /s /q "%programfiles%\Advanced System Protector"
rd /s /q "%SYSTEMDRIVE%\ProgramData\Systweak"
rd /s /q "%SYSTEMDRIVE%\ProgramData\Microsoft\Windows\Start Menu\Programs"
rd /s /q "%appdata%\Systweak"
DEL /s /q "%SYSTEMDRIVE%\Users\Public\Desktop\Advanced System Protector.lnk"

rem #Baixaki
REG DELETE "HKCU\Software\Baixaki" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Baixaki" /f

rem #Babylon
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar" /f
rd /s /q "%programfiles%\BabylonToolbar"
rd /s /q "%SYSTEMDRIVE%\ProgramData\Babylon"
rd /s /q "%appdata%\Babylon"
rd /s /q "%appdata%\BabylonToolbar"
rd /s /q "%userprofile%\appdata\LocalLow\BabylonToolbar"
REG DELETE "HKLM\SOFTWARE\Babylon" /f
REG DELETE "HKCU\Software\BabylonToolbar" /f
REG DELETE "HKCU\SOFTWARE\Microsoft\Babylon" /f
REG DELETE "HKLM\SOFTWARE\BabylonToolbar" /f
REG DELETE "HKCR\Babylon.dskBnd" /f
REG DELETE "HKCR\Babylon.dskBnd.1" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\BabylonToolbar\BabylonToolbar\user" /f

rem #BrowserCompanion
taskkill.exe /F /IM tbhcn.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion" /f
rd /s /q "%programfiles%\BrowserCompanion"
REG DELETE "HKLM\SOFTWARE\BrowserCompanion" /f
REG DELETE "HKLM\SOFTWARE\BrowserMngr" /f
rd /s /q "%appdata%\BrowserCompanion"

rem #Claro
taskkill.exe /f /im clarosrv.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\claro" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{069B290F-5398-4629-A009-85B4BCB4B1B9}" /f
REG DELETE "HKLM\SOFTWARE\Claro LTD" /f
REG DELETE "HKCU\Software\Claro LTD" /f
rd /s /q "%programfiles%\Claro LTD"
rd /s /q "%appdata%\Claro" /f
rd /s /q "%userprofile%\AppData\LocalLow\Claro LTD"
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Claro LTD" /f

rem #Conduit
REG DELETE "HKLM\SOFTWARE\Conduit" /f
rd /s /q "%programfiles%\Conduit"
rd /s /q "%appdata%\Conduit"
rd /s /q "%LOCALAPPDATA%\Conduit"
rd /s /q "%userprofile%\AppData\LocalLow\Conduit"
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Conduit" /f

rem #Dealply
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly" /f
rd /s /q "%programfiles%\DealPly"
rd /s /q "%SYSTEMDRIVE%\ProgramData\Microsoft\Windows\Start Menu\Programs\Dealply"
REG DELETE "HKLM\SOFTWARE\DealPly" /f
REG DELETE "HKCU\Software\Dealply" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Dealply" /f

rem #Funmoods
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\funmoods" /f
rd /s /q "%programfiles%\Funmoods"
DEL /s /q "%LOCALAPPDATA%\funmoods.crx"
DEL /s /q "%LOCALAPPDATA%\funmoods-speeddial.crx"
rd /s /q "%userprofile%\AppData\LocalLow\Funmoods"
REG DELETE "HKCR\funmoods.funmoodsHlpr" /f
REG DELETE "HKCR\funmoods.funmoodsHlpr.1" /f
REG DELETE "HKLM\SOFTWARE\Funmoods" /f
REG DELETE "HKCR\funmoodsApp.appCore" /f
REG DELETE "HKCR\funmoodsApp.appCore.1" /f
REG DELETE "HKCR\funmoods.dskBnd" /f
REG DELETE "HKCR\funmoods.dskBnd.1" /f

rem #Iminent
taskkill.exe /F /IM Iminent.exe
taskkill.exe /F /IM Iminent.Messengers.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A76AA284-E52D-47E6-9E4F-B85DBF8E35C3}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6E71E28-43CB-423E-B415-B7C00D77902E}" /f
rd /s /q "%programfiles%\Iminent"
rd /s /q "%programfiles%\Iminent Toolbar"
rd /s /q "%SYSTEMDRIVE%\ProgramData\Iminent"
rd /s /q "%appdata%\Iminent"
rd /s /q "%SYSTEMDRIVE%\ProgramData\Microsoft\Windows\Start Menu\Programs\Iminent"
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Iminent" /f
REG DELETE "HKLM\SOFTWARE\Iminent" /f
REG DELETE "HKLM\SOFTWARE\Loader" /f
REG DELETE "HKCU\Software\Iminent" /f

rem #Internet explorer
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /va /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0af350d9-3916-454b-ac53-0b0b65f41301}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{206A6E76-36B0-495C-BB71-63F3D1247425}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60295942-9E5F-4EE8-B785-3A655904D24F}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A14E2859-E39B-4EDE-ABF1-E19A029F57F3}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}" /f

rem #Msn Plus
taskkill.exe /F /IM Smartbar.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B0A46C35-38C8-4627-9F11-706B8EA36D03}" /f
rd /s /q "%appdata%\Smartbar"
rd /s /q "%LOCALAPPDATA%\Smartbar"
rd /s /q "%userprofile%\AppData\LocalLow\Smartbar"
REG DELETE "HKCU\Software\Smartbar" /f
REG DELETE "HKCU\Software\SmartbarBackup" /f
REG DELETE "HKCU\Software\SmartbarLog" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Smartbar" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\SmartbarBackup" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\SmartbarLog" /f

rem #PcPerformer
taskkill.exe /F /IM PCPerformer.exe
taskkill.exe /F /IM pcpmngr.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Performer_is1" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" /f
REG DELETE "HKLM\SOFTWARE\bProtector" /f
REG DELETE "HKLM\SOFTWARE\PerformerSoft" /f
REG DELETE "HKCU\Software\bProtector" /f
REG DELETE "HKCU\Software\PerformerSoft" /f
rd /s /q "%programfiles%\PC Performer"
rd /s /q "%appdata%\PerformerSoft"
rd /s /q "%LOCALAPPDATA%\PC Performer Manager"
rd /s /q "%LOCALAPPDATA%\IBUpdaterService"
rd /s /q "%userprofile%\Start Menu\Programs\PC Performer"
rd /s /q "%SYSTEMDRIVE%\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Performer"
rd /s /q "%SYSTEMDRIVE%\ProgramData\PC Performer Manager"
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\bProtector" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\PerformerSoft" /f

rem #Positivo Deskmedia
rd /s /q "%SYSTEMDRIVE%\Positivo"
rd /s /q "%appdata%\Positivo"
REG DELETE "HKLM\SOFTWARE\Deskmedia" /f
REG DELETE "HKCU\Software\Deskmedia" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Deskmedia" /f

rem #SweetIM
taskkill.exe /F /IM SweetIM.exe
taskkill.exe /F /IM SweetPacksUpdateManager.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}" /f
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7683B745-6060-41FD-AA75-0BBB383FEAD4}" /f
rd /s /q "%programfiles%\SweetIM"
rd /s /q "%SYSTEMDRIVE%\ProgramData\SweetIM"
del /s /q "%userprofile%\Desktop\SweetPcFix.url"
REG DELETE "HKLM\SOFTWARE\SweetIM" /f
REG DELETE "HKCU\Software\SweetIM" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\SweetIM" /f

rem #SearchTheWeb
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP" /f

rem #Tuto4pc
taskkill.exe /F /IM tuto4pc_br_4.exe
taskkill.exe /F /IM upt4pc_br_4.exe
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TUTO4PC_BR_4_is1" /f
rd /s /q "%programfiles%\TUTO4PC"
rd /s /q "%appdata%\tuto4pc_br_4"
rd /s /q "%appdata%\baidu"
rd /s /q "%LOCALAPPDATA%\tuto4pc_br_4"
rd /s /q "%LOCALAPPDATA%\CRE"
rd /s /q "%userprofile%\AppData\LocalLow\Toolbar4"
REG DELETE "HKLM\SOFTWARE\TUTO4PC" /f
REG DELETE "HKCU\Software\Tutorials" /f
REG DELETE "HKCU\Software\TutoTag" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Tutorials" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\TutoTag" /f

rem #UtorrentTooblar
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentBar_PT Toolbar" /f
rd /s /q "%programfiles%\uTorrentBar_PT"
rd /s /q "%userprofile%\AppData\LocalLow\uTorrentBar_PT"
REG DELETE "HKLM\SOFTWARE\uTorrentBar_PT" /f

rem #v9Soft
REG DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\V9Software" /f
rd /s /q "%programfiles%\v9Soft"
REG DELETE "HKLM\SOFTWARE\V9Software" /f

rem #Outros
REG DELETE "HKCU\Software\Baidu" /f
REG DELETE "HKCU\Software\Softonic" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Baidu" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Softonic" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\AppDataLow\Software" /va /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Toolbar" /va /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\DataMngr" /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\DataMngr_toolbar" /f
rd /s /q "%appdata%\Microsoft\Windows\Start Menu\Programs\Hao123"
del /s /q "%userprofile%\Desktop\hao123.lnk"
del /s /q "%userprofile%\Desktop\Google Chrome.lnk"
del /s /q "%userprofile%\Desktop\Search the web.url"
del /s /q "%userprofile%\Desktop\hao123.lnk"
del /s /q "%SYSTEMDRIVE%\Users\Public\Desktop\PC Performer.lnk"
rd /s /q "%SYSTEMDRIVE%\ProgramData\IBUpdaterService"
rd /s /q "%LOCALAPPDATA%\CRE"
rd /s /q "%userprofile%\AppData\LocalLow\bbrs_002.tb"
rd /s /q "%userprofile%\AppData\LocalLow\PriceGong"

rem #Temporários
rd /s /q "%LOCALAPPDATA%\Temp"
rd /s /q "%LOCALAPPDATA%\Microsoft\Windows\Temporary Internet Files"

rem #Google
REG DELETE "HKLM\SOFTWARE\WoW6432Node\Google\Chrome\Extensions" /va /f
DEL /s /q %LOCALAPPDATA%\Google\Chrome\User Data\Default\bProtector Web Data"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\bprotectorpreferences"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Storage" /va
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\dcillohgikpecbmgioknapdpcjofaafl"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\mdebcffgnijbblbinknkbefciofebcda"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia"
rd /s /q "%LOCALAPPDATA%\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}"
REG DELETE "HKCU\Software\Wow6432Node\Google\Chrome\Extensions" /va /f
REG DELETE "HKU\S-1-5-21-1340266985-1482042653-2430154844-1000\Software\Wow6432Node\Google\Chrome\Extensions" /f
DEL /s /q /f "%LOCALAPPDATA%\Google\Update\GoogleUpdate.exe"

rem #Plugins firefox
DEL /s /q /f "%programfiles%\Mozilla Firefox\searchplugins\babylon.xml"
DEL /s /q /f "%programfiles%\Mozilla Firefox\searchplugins\SearchTheWeb.xml"
DEL /s /q /f "%programfiles%\Mozilla Firefox\searchplugins\v9.xml"
cd %appdata%\Mozilla\Firefox\Profiles\*.default
rmdir /s /q "CT2851643"
rmdir /s /q "smartbar"
rmdir /s /q "SweetPacksToolbarData"

cd %appdata%\Mozilla\Firefox\Profiles\*.default\extensions
rmdir /s /q "{C9B68337-E93A-44EA-94DC-CB300EC06444}"
rmdir /s /q "{e0301295-ab3e-4af3-979f-3d453c5f9f48}"
rmdir /s /q "{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}"
rmdir /s /q "{EEE6C361-6118-11DC-9C72-001320C79847}"
rmdir /s /q "bbrs_002@blabbers.com"
rmdir /s /q "ffxtlbr@claro.com"
rmdir /s /q "helperbar@helperbar.com"
rmdir /s /q "staged"
DEL /s /q "{EEE6C361-6118-11DC-9C72-001320C79847}.xpi"

cd %appdata%\Mozilla\Firefox\Profiles\*.default\Searchplugins
DEL /s /q "bProtect.xml"
DEL /s /q "conduit.xml"
DEL /s /q "Messenger Plus Smartbar Search.xml"
DEL /s /q "sweetim.xml"
del /s /q "%SYSTEMDRIVE%\Users\Public\Desktop\Mozilla Firefox.lnk"
REG DELETE "HKCU\Software\mozilla\Firefox\Extensions" /va /f
REG DELETE "HKLM\SOFTWARE\Mozilla\Firefox\Extensions" /va /f

rem configura o firefox

c:
cd %appdata%\Mozilla\Firefox\Profiles\*.default
echo user_pref("browser.startup.homepage", "http://www.google.com.br" >>prefs.js

start explorer.exe

exit


Adicionei um sistema que verifica se o sistema é XP (5.1) ou Server 2003/XP 64 (5.2). Se o resultado for positivo, o arquivo batch vai gerar um arquivo VBS que pega o caminho equivalente a %localappdata% no Vista/7, praticamente "simulando a variável %localappdata%". Tem mais coisas para fazer, mas agora irei testar gnomo.png
AcNeto
AcNeto Veterano Registrado
758 Mensagens 56 Curtidas
#14 Por AcNeto
02/10/2012 - 13:09
Marcos FRM, a verdade é que está absurdo o que está acontecendo, vem esses instaladores dizendo que é livre de spam e virus, mas a maquina fica inoperante.

Olha a foto dos que eu instalei na maquina virtual, no 3º tive que abrir o gerenciador e começar a matar processo senão não tinha mais condições.

http://i48.tinypic.com/m9mv4n.png

Usei o process explorer e o tasklist para monitorar o que estava ativo depois de tudo instalado, sei que falta coisa mas creio que vai ficar muito bom esse bat, o Meyer! está dando uma força enorme, eu mesmo não tenho tanta pericia com esses comandos, vou matando um leão a cada dia para aprender hehe

De noite vou repor a maquina virtual infectada para fazer teste e vou fazer uma com xp. Salvei porque ficar instalando tudo de novo não tem como, mais facil é salvar ela em outra pasta e trocar pela original.

Abraço.
Placa Gigabyte 970-ud3p / Cooler Master TX3 Evo / Placa de vídeo GTX 750Ti
Processador FX 8320 / 16 GB Corsair Vengeance 1600
SSD OCZ 128 Sistemas (Win7 64/Mint 64)
HD 2 TB, 2 TB WD / HD 3 TB Seagate
Fonte corsair 520W /Dual Monitor LG 23"
Meyer!
Meyer! Ubbergeek Registrado
3.9K Mensagens 535 Curtidas
#15 Por Meyer!
02/10/2012 - 18:02
AcNeto disse:
Marcos FRM, a verdade é que está absurdo o que está acontecendo, vem esses instaladores dizendo que é livre de spam e virus, mas a maquina fica inoperante.

Olha a foto dos que eu instalei na maquina virtual, no 3º tive que abrir o gerenciador e começar a matar processo senão não tinha mais condições.

http://i48.tinypic.com/m9mv4n.png

Usei o process explorer e o tasklist para monitorar o que estava ativo depois de tudo instalado, sei que falta coisa mas creio que vai ficar muito bom esse bat, o Meyer! está dando uma força enorme, eu mesmo não tenho tanta pericia com esses comandos, vou matando um leão a cada dia para aprender hehe

De noite vou repor a maquina virtual infectada para fazer teste e vou fazer uma com xp. Salvei porque ficar instalando tudo de novo não tem como, mais facil é salvar ela em outra pasta e trocar pela original.

Abraço.

Fazer snapshot se estiver usando o Virtualbox ou o VmWare pode ser bom também... Vou testar agora o script na minha máquina com o XP e o Thin PC...

Ao que parece o instalador do Baixaki é só para programas 32 bits... Para 64 bits não tem... E tem a opção de escolher se quer as barras...

EDIT: Não utilizem esse instalador do Baixaki aí, é muito suspeito:

http://oi45.tinypic.com/16h85xh.jpg

Essas entradas em azul aí foi o que eu marquei e que é muito suspeito mesmo, primeiro mexendo com o arquivo "SHELL32.DLL", um arquivo importante do modo usuário do Windows. Não consegui tirar mais fotos pois a VM parou (não foi BSOD, foi tipo puxar da tomada). Mas, um pouco embaixo dessas entradas, o instalador mexeu na "NTDLL.DLL" (DLL de nível do kernel NT, muito importante para o funcionamento do kernel e do modo usuário). Uma bomba mesmo isso...
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal