Care to make one for NOD32? lol.

Klint



Eldridge, Dave wrote:
Thanks Kurt I will look at it.
dave

-----Original Message-----
From: Kurt Buff [mailto:[EMAIL PROTECTED] Sent: Thursday, November 20, 2008 10:34 AM
To: NT System Admin Issues
Subject: The script...

This script is rough - and it's a steal from a web site, and we've
modified or added to it, heavily. It's also not a complete solution -
for instance, we've found that, for reasons we don't have nailed down
yet, the frameworkservice doesn't *always* disappear, though it does
over 80% of the time, so for now we've just been turning it off and
disabling it when we find that problem.

Don't blame me if it blows up your machine...

Several notes:

1) We launch this script remotely with 'psexec \\computername -c -f
c:\batchfile.cmd'

2) You'll note that we delete registry entries twice. This was much
more successful than removing them once. I don't know why.

3) This script works against Win2k and XP machines - we don't have Vista

4) Watch for line wrappage!

5) This script is very rough, feedback appreciated. I'm using this as
a teaching tool for the junior admin who found it and has modified it.
I have not reviewed all of it, though I answered lots of questions
while he modified it. He's learned a lot. Heh.

-----------Start Batch File----------
@echo
************************************************************************
*******
@echo ****** Copyright MYFIXES.COM
       *******
@echo ******                      TERMS AND CONDITIONS
       *******
@echo
************************************************************************
*******
@echo Author: Paul Ionescu
@echo.
@echo PLEASE READ CAREFULLY!
@echo.
@echo  This batch file is provided free of charge by MYFIXES.COM and
can be used
@echo  as long as the copyright note is not removed.
@echo.
@echo  MYFIXES.COM asumes no liability for any damage that this batch
program
@echo may cause to your computer and advises that it should be used as
directed
@echo by a technical support professional.
@echo.
@echo  The batch file will create an icon on your desktop to facilitate
@echo access to the MY FIXES website. You can delete this icon at any
time.
@echo.
@echo  Press any key to agree with these terms. By agreeing with these
terms you
@echo are releasing MYFIXES.COM and the creator of the batch file from
any
@echo responsability for the use of the batch file.
@echo If you don't agree close this window.
@echo.

@cd %userprofile%\Desktop
@echo [InternetShortcut] > "My Fixes.url"
@echo URL=http://www.myfixes.com >> "My Fixes.url"
@cls
@echo  If the Mcafee folders are in a different directory than
C:\PROGRAM FILES
@echo please type it in now or just hit Enter if you installed McAfee in
the
@echo default location.
@echo.
@set mcdir=c:\program files\network associates
rem @set /P mcdir=" Directory (Enter for default):"

@if "%mcdir%"=="" @set mcdir=C:\PROGRAM FILES\Network Associates

MsiExec.exe /x{59224777-298D-4E9C-9AEB-4A91BDA01B27} /quiet

MsiExec.exe /x{5DF3D1BB-894E-4DCD-8275-159AC9829B43} /quiet

@echo Stopping McAfee Services...


@net stop "Network Associates Task Manager"
@net stop "Network Associates McShield"
@net stop "McAfee Framework Service"

@echo Stopping McAfee Processes...

@tskill TBmon
@tskill shstat
@tskill UdaterUI
@tskill Mctray
@tskill mcvsshld
@tskill mcagent
@tskill MpfAgent
@tskill MpfTray
@tskill mscifapp
@tskill MSKAgent
@tskill McVSEscn
@tskill oasclnt
@tskill MCLogLch
@tskill MskAgent
@tskill mclogcln

@echo Deleting McAfee Registry Keys...

@reg delete HKLM\Software\McAfee /f
@reg delete HKCU\Software\McAfee /f

@reg delete HKLM\Software\McAfee.com /f
@reg delete HKLM\Software\McRem /f
@reg delete HKCU\Software\McAfee.com /f

@echo Deleting McAfee Add\Remove Programs Entries...

rem Below, are the registry keys that I have added manually.

@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
{5DF3D1BB-894E-4DCD-8275-159AC9829B43}"
/f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{0104BA4A-D33C-40AF-8FD3-C42512D43468}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{04D18721-749F-4140-AEB0-CAC099CA4741}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{056ADD67-DDB0-47BE-9F7D-DC652206F766}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{08815891-3400-4CD8-B644-23BE617ED6D6}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{0AA5BF4A-88BD-4E61-9968-BBF04701B5C6}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{0D7C69CB-CF5F-4594-8FEE-0B6DDA9F75D6}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{1161A96C-CBA5-4CA7-BB39-BC9280348E73}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{1A13B2E0-805B-44F7-94A8-8D3A2258D6A2}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{1FE25B89-B3E7-4FF8-B67A-300286F51E5F}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{221F3B81-CAD5-4EE1-82FE-65CAA21623DF}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{2D417134-0D48-4856-B6F5-04E63171E24C}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{2D4842EA-9F7B-4B6A-B157-41C6250DA148}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{3153E8D7-C724-47CC-A7FE-5C90EB4093A0}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{3AEC7772-2766-4C67-8487-4189C55DDE4E}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{3C9654E8-E7F6-491D-A674-85CB53573FEE}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{451D30D1-C1EB-4891-BD3A-5FD7E3001784}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{4EF17F94-3975-4ACF-B228-29485BDE5860}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{4F1078B1-41CB-4743-996B-ACD1913A239B}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{4F13CE9C-D753-422E-B897-BD70CC8CEA46}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{50CCECAC-7286-4CA0-9AD0-E309A2318482}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{5284E46B-63F2-4D12-9434-88B7899EA7DD}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{528F66A7-7891-4F6B-8F1E-5132CC80650C}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{6046FF06-6800-4F0E-B474-4BD5822105AA}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{6E389062-C540-4145-96B9-B8745CF7D856}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{70CABBFF-9D0B-4232-9F02-D1BD8298F037}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{8036105A-E89B-4D24-8319-FEA26195A569}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{8359000C-55B2-4076-A3C3-DDF39FEB14F5}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{83D7FBE7-E507-4486-8785-8D1776D498F4}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{97C51E13-6932-4092-88C9-E7B73FBE0FD5}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{9EEFDA4D-0326-41B6-A3EB-CD1A67837443}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{A5B589D5-CFB6-4E9A-9455-39963CBF74CB}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{cda2863e-2497-4c49-9b89-06840e070a87}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{D3580208-D4E1-46D4-876C-B45A328AF25A}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{D8D9EEBC-0640-47AC-84FF-97C3A6B2FC79}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{EF4CE8D8-1896-431C-AE4F-1ABE8B235ED6}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{F5F6647E-A36B-42BB-AD4E-A93753DE4DCD}" /f
@reg delete
"HKEY_CLASSES_ROOT\Installer\Products\BB1D3FD5E498DCD4285751A99C28B934"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{00D37BEE-2D29-4F3E-9AB2-5910EBAF7A69}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{1F8F276E-2CBC-4310-8BB3-1D8A72B647C7}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{22CE3FC4-4805-40CF-80E4-FEC207A77801}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{2BD91F0A-F900-477C-8401-AF0774A3EEE4}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{31E7F064-EB69-4771-8AAB-1D1642DACA76}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{365ADE60-0AB6-4260-A5F9-5F154E52E385}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{3B100745-A668-4D90-8EB2-A6E2E1387BF1}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{4238C1CE-0D7E-4A6D-8624-D53D2E276A05}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{46DC2A5D-4A7B-4184-B738-7EDF4D68526B}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{745BA2BA-9B0E-459E-8A9C-A47C6A0131F1}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{7576F677-3945-4DA2-B9F0-37850028A7E7}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{7DB1286A-CBEF-4823-96AA-27093A546741}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{801FC275-1246-4AD5-AB3D-07371BBF5BED}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{8C81B1EE-514E-4A20-BCCD-60648432C9FE}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{90969396-649F-48A2-A082-6DEBA7A51F50}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{AE4341EF-80A3-4D53-9735-1BCB78C118F3}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{B5FA7874-ACBF-46B3-BE2E-98381FDA9D44}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{B74F7591-F64C-43DF-945A-519DA50ABAFA}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{C83F84A8-241A-4837-A6BA-1C5131141743}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{F74008B3-A74D-4C9F-9D11-A9F9CFF1DDB6}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{FAAEEE57-F848-4E65-BFCE-A7B75E4133FB}"
/f
@reg delete
"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Me
nuOrder\Start
Menu\Programs\Network Associates" /f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A13B2E0-805B-44F7-94A8-8D3A
2258D6A2}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A13B2E0-805B-44F7-94A8-8D3A
2258D6A2}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A13B2E0-805B-44F7-94A8-8D3A
2258D6A2}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6E389062-C540-4145-96B9-B874
5CF7D856}"
/f

REM  I'm not 100% sure about the key below.
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BB1D3FD5E498DCD4
285751A99C28B934"
/f

@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{51199FE2-2D9C-4047-A61E-
81A9F6A0D806}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7A9ECE1F-5CAD-4017-999F-
552270E45D92}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{963B7D71-C519-4A5D-B8E7-
742B08628F5D}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9F9776B1-E151-41E0-90F8-
29A5C211A001}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A33F52E5-9F67-459C-95D3-
8420B50E7183}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D831533D-0324-4EA4-B3FD-
073AFEE85181}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ScriptSubSys.McAfeeScript" /f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ScriptSubSys.McAfeeScript.1" /f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\UpdateSubSys.McAfeeUpdate" /f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\UpdateSubSys.McAfeeUpdate.1" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\McAfeeAntiVirus" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\McAfeeFirewall" /f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\
UserData\S-1-5-18\Products\BB1D3FD5E498DCD4285751A99C28B934"
/f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\TVD\Shared
Components\Events\09\1725" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\TVD\Shared
Components\Events\09\1726" /f

REM  I'm not 100% sure about the key below.
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\TVD\Shared
Components\Framework" /f

@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\TVD\Shared
Components\On Access Scanner" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\ePolicy
Orchestrator\Application Plugins" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\TVD\Shared
Components\On Demand Scanner" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network
Associates\TVD\VirusScan Enterprise" /f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCAFEEFRAMEWOR
K"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCSHIELD"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCTASKMANAGER"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameter
s\FirewallPolicy\DomainProfile\AuthorizedApplications\List"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameter
s\FirewallPolicy\StandardProfile\AuthorizedApplications\List"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_MCAFEEFRAMEWOR
K"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_MCSHIELD"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_MCTASKMANAGER"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameter
s\FirewallPolicy\DomainProfile\AuthorizedApplications\List"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameter
s\FirewallPolicy\StandardProfile\AuthorizedApplications\List"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCAFEEFRAM
EWORK"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCSHIELD"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCTASKMANA
GER"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Param
eters\FirewallPolicy\DomainProfile\AuthorizedApplications\List"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Param
eters\FirewallPolicy\StandardProfile\AuthorizedApplications\List"
/f

REM  My manual entries stopped with the line above.

@echo Unregistering McAfee Dll's...

@dir /B /S "%mcdir%\mcafee.com\*.dll" > %temp%\mcafeedll.txt
@for /F "delims=" %%i in (%temp%\mcafeedll.txt) do @regsvr32 /U "%%i" /S

@regsvr32 jscript.dll /S
@regsvr32 vbscript.dll /S

@echo Removing Desktop Shortcuts...

@echo Removing Startup Entries...

@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
ShStatEXE /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
"Network Associates Error Reporting Service" /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
McAfeeUpdaterUI /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MCAgentExe /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MCUpdateExe /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MPFExe /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MPSExe /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MSKAGENTEXE /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MSKDetectorExe /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
OASClnt /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
"VirusScan Online" /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
VSOCheckTask /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
McLogLch_exe /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MskAgent /f

@echo Removing McAfee Services...

@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McTaskManager" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McShield" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McAfeeFramework" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\MPFIREWL" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\MpfService" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\MskService" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McDetect.exe" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McShield" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McTskshd.exe" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mcupdmgr.exe" /f

@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McAfee HackerWatch
Service" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McLogManagerService"
/f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mcmispupdmgr" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McNASvc" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McODS" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mcpromgr" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McProxy" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McRedirector" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McSysmon" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mcusrmgr" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mfeavfk" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mfebopk" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mfehidk" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mferkdk" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mfesmfk" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\Emproxy" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\MPS9" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\MSK80Service" /f

@echo Removing Other Registry Keys...

@reg delete "HKLM\SOFTWARE\Microsoft\Exchange\Client\Extensions" /v
"McAfee SpamKiller" /f
@reg delete "HKLM\SOFTWARE\Microsoft\Exchange\Client\Extensions" /v
"McAfee SpamKiller Exchange Extension" /f
@reg delete "HKLM\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{39FD89BF-D3F1-45b6-BB56-3582CCF489E1}" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Toolbar" /v "{0BF43445-2F28-4351-9252-17FE6E806AA0}" /f
@reg delete
"HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\McOlAddin.Connect" /f
@reg delete
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser
Helper Objects\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53}" /f
@reg delete
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSC" /f
@reg delete "HKU\.DEFAULT\Software\McAfee" /f

@echo Preparing Final Steps...

@echo rd /S/Q "%mcdir%\mcafee" > %temp%\mcrem.cmd
@echo rd /S/Q "%mcdir%\mcafee.com" >> %temp%\mcrem.cmd
@echo rd /S/Q "%allusersprofile%\Application Data\mcafee" >>
%temp%\mcrem.cmd
@echo rd /S/Q "%allusersprofile%\Application Data\mcafee.com" >>
%temp%\mcrem.cmd
@echo rd /S/Q "%allusersprofile%\Application Data\McAfee.com Personal
Firewall" >> %temp%\mcrem.cmd
@echo reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
/v mcrem /f >> %temp%\mcrem.cmd

@reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v mcrem
/t REG_SZ /d %temp%\mcrem.cmd /f

rmdir /S /Q "%allusersprofile%\Start Menu\Programs\Network Associates"
rmdir /S /Q "C:\Program Files\Network Associates"
rmdir /S /Q "C:\Program Files\Common Files\Network Associates"

@cls
@echo ALL STEPS WERE COMPLETED!
@echo YOU NEED TO RESTART THE COMPUTER TO COMPLETE THE REMOVAL PROCESS!
@echo IF AFTER THE COMPUTER RESTARTS YOU ARE GETTING MCAFEE ERRORS RUN
@echo THIS PROGRAM ONE MORE TIME!

MsiExec.exe /x{59224777-298D-4E9C-9AEB-4A91BDA01B27} /quiet /l*v
"c:\LuciusVerinus.txt"

MsiExec.exe /x{5DF3D1BB-894E-4DCD-8275-159AC9829B43} /quiet /l*v
"c:\TitusPullo.txt"

@echo Stopping McAfee Services...


@net stop "Network Associates Task Manager"
@net stop "Network Associates McShield"
@net stop "McAfee Framework Service"


@echo Stopping McAfee Processes...

@tskill TBmon
@tskill shstat
@tskill UdaterUI
@tskill Mctray
@tskill mcvsshld
@tskill mcagent
@tskill MpfAgent
@tskill MpfTray
@tskill mscifapp
@tskill MSKAgent
@tskill McVSEscn
@tskill oasclnt
@tskill MCLogLch
@tskill MskAgent
@tskill mclogcln

@echo Deleting McAfee Registry Keys...

@reg delete HKLM\Software\McAfee /f
@reg delete HKCU\Software\McAfee /f

@reg delete HKLM\Software\McAfee.com /f
@reg delete HKLM\Software\McRem /f
@reg delete HKCU\Software\McAfee.com /f

@echo Deleting McAfee Add\Remove Programs Entries...

rem Below, are the registry keys that I have added manually.

@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
{5DF3D1BB-894E-4DCD-8275-159AC9829B43}"
/f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{0104BA4A-D33C-40AF-8FD3-C42512D43468}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{04D18721-749F-4140-AEB0-CAC099CA4741}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{056ADD67-DDB0-47BE-9F7D-DC652206F766}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{08815891-3400-4CD8-B644-23BE617ED6D6}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{0AA5BF4A-88BD-4E61-9968-BBF04701B5C6}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{0D7C69CB-CF5F-4594-8FEE-0B6DDA9F75D6}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{1161A96C-CBA5-4CA7-BB39-BC9280348E73}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{1A13B2E0-805B-44F7-94A8-8D3A2258D6A2}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{1FE25B89-B3E7-4FF8-B67A-300286F51E5F}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{221F3B81-CAD5-4EE1-82FE-65CAA21623DF}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{2D417134-0D48-4856-B6F5-04E63171E24C}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{2D4842EA-9F7B-4B6A-B157-41C6250DA148}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{3153E8D7-C724-47CC-A7FE-5C90EB4093A0}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{3AEC7772-2766-4C67-8487-4189C55DDE4E}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{3C9654E8-E7F6-491D-A674-85CB53573FEE}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{451D30D1-C1EB-4891-BD3A-5FD7E3001784}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{4EF17F94-3975-4ACF-B228-29485BDE5860}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{4F1078B1-41CB-4743-996B-ACD1913A239B}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{4F13CE9C-D753-422E-B897-BD70CC8CEA46}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{50CCECAC-7286-4CA0-9AD0-E309A2318482}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{5284E46B-63F2-4D12-9434-88B7899EA7DD}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{528F66A7-7891-4F6B-8F1E-5132CC80650C}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{6046FF06-6800-4F0E-B474-4BD5822105AA}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{6E389062-C540-4145-96B9-B8745CF7D856}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{70CABBFF-9D0B-4232-9F02-D1BD8298F037}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{8036105A-E89B-4D24-8319-FEA26195A569}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{8359000C-55B2-4076-A3C3-DDF39FEB14F5}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{83D7FBE7-E507-4486-8785-8D1776D498F4}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{97C51E13-6932-4092-88C9-E7B73FBE0FD5}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{9EEFDA4D-0326-41B6-A3EB-CD1A67837443}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{A5B589D5-CFB6-4E9A-9455-39963CBF74CB}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{cda2863e-2497-4c49-9b89-06840e070a87}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{D3580208-D4E1-46D4-876C-B45A328AF25A}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{D8D9EEBC-0640-47AC-84FF-97C3A6B2FC79}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{EF4CE8D8-1896-431C-AE4F-1ABE8B235ED6}" /f
@reg delete
"HKEY_CLASSES_ROOT\CLSID\{F5F6647E-A36B-42BB-AD4E-A93753DE4DCD}" /f
@reg delete
"HKEY_CLASSES_ROOT\Installer\Products\BB1D3FD5E498DCD4285751A99C28B934"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{00D37BEE-2D29-4F3E-9AB2-5910EBAF7A69}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{1F8F276E-2CBC-4310-8BB3-1D8A72B647C7}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{22CE3FC4-4805-40CF-80E4-FEC207A77801}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{2BD91F0A-F900-477C-8401-AF0774A3EEE4}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{31E7F064-EB69-4771-8AAB-1D1642DACA76}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{365ADE60-0AB6-4260-A5F9-5F154E52E385}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{3B100745-A668-4D90-8EB2-A6E2E1387BF1}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{4238C1CE-0D7E-4A6D-8624-D53D2E276A05}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{46DC2A5D-4A7B-4184-B738-7EDF4D68526B}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{745BA2BA-9B0E-459E-8A9C-A47C6A0131F1}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{7576F677-3945-4DA2-B9F0-37850028A7E7}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{7DB1286A-CBEF-4823-96AA-27093A546741}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{801FC275-1246-4AD5-AB3D-07371BBF5BED}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{8C81B1EE-514E-4A20-BCCD-60648432C9FE}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{90969396-649F-48A2-A082-6DEBA7A51F50}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{AE4341EF-80A3-4D53-9735-1BCB78C118F3}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{B5FA7874-ACBF-46B3-BE2E-98381FDA9D44}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{B74F7591-F64C-43DF-945A-519DA50ABAFA}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{C83F84A8-241A-4837-A6BA-1C5131141743}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{F74008B3-A74D-4C9F-9D11-A9F9CFF1DDB6}"
/f
@reg delete
"HKEY_CLASSES_ROOT\TypeLib\{FAAEEE57-F848-4E65-BFCE-A7B75E4133FB}"
/f
@reg delete
"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Me
nuOrder\Start
Menu\Programs\Network Associates" /f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A13B2E0-805B-44F7-94A8-8D3A
2258D6A2}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A13B2E0-805B-44F7-94A8-8D3A
2258D6A2}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A13B2E0-805B-44F7-94A8-8D3A
2258D6A2}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6E389062-C540-4145-96B9-B874
5CF7D856}"
/f

rem I'm not 100% sure about the key below.
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BB1D3FD5E498DCD4
285751A99C28B934"
/f

@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{51199FE2-2D9C-4047-A61E-
81A9F6A0D806}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7A9ECE1F-5CAD-4017-999F-
552270E45D92}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{963B7D71-C519-4A5D-B8E7-
742B08628F5D}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9F9776B1-E151-41E0-90F8-
29A5C211A001}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A33F52E5-9F67-459C-95D3-
8420B50E7183}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D831533D-0324-4EA4-B3FD-
073AFEE85181}"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ScriptSubSys.McAfeeScript" /f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ScriptSubSys.McAfeeScript.1" /f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\UpdateSubSys.McAfeeUpdate" /f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\UpdateSubSys.McAfeeUpdate.1" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\McAfeeAntiVirus" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\McAfeeFirewall" /f
@reg delete
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\
UserData\S-1-5-18\Products\BB1D3FD5E498DCD4285751A99C28B934"
/f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\TVD\Shared
Components\Events\09\1725" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\TVD\Shared
Components\Events\09\1726" /f

rem I'm not 100% sure about the key below.
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\TVD\Shared
Components\Framework" /f

@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\TVD\Shared
Components\On Access Scanner" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\ePolicy
Orchestrator\Application Plugins" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\TVD\Shared
Components\On Demand Scanner" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Network
Associates\TVD\VirusScan Enterprise" /f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCAFEEFRAMEWOR
K"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCSHIELD"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCTASKMANAGER"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameter
s\FirewallPolicy\DomainProfile\AuthorizedApplications\List"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameter
s\FirewallPolicy\StandardProfile\AuthorizedApplications\List"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_MCAFEEFRAMEWOR
K"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_MCSHIELD"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_MCTASKMANAGER"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameter
s\FirewallPolicy\DomainProfile\AuthorizedApplications\List"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameter
s\FirewallPolicy\StandardProfile\AuthorizedApplications\List"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCAFEEFRAM
EWORK"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCSHIELD"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCTASKMANA
GER"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Param
eters\FirewallPolicy\DomainProfile\AuthorizedApplications\List"
/f
@reg delete
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Param
eters\FirewallPolicy\StandardProfile\AuthorizedApplications\List"
/f

rem My manual entries stopped with the line above.



"C:\Program Files\Network Associates\Common Framework\UdaterUI.exe"
/StartedFromRunKey

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCAFEEFRAMEWORK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCSHIELD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCTASKMANAGER
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\McAfeeFramework
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MCAFEEFRAMEWORK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MCSHIELD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MCTASKMANAGER
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\McAfeeFramework
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCAFEEFRAME
WORK
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCSHIELD
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCTASKMANAG
ER
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\McAfeeFramework

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{2A6D72F1-6E7E-4702-B99C-E40D3
DED33C3}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\FrameworkService.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0104BA4A-D33C-40AF-8FD3-C4251
2D43468}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04D18721-749F-4140-AEB0-CAC09
9CA4741}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{056ADD67-DDB0-47BE-9F7D-DC652
206F766}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08815891-3400-4CD8-B644-23BE6
17ED6D6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0AA5BF4A-88BD-4E61-9968-BBF04
701B5C6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D7C69CB-CF5F-4594-8FEE-0B6DD
A9F75D6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D7C69CB-CF5F-4594-8FEE-0B6DD
A9F75D6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1161A96C-CBA5-4CA7-BB39-BC928
0348E73}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A13B2E0-805B-44F7-94A8-8D3A2
258D6A2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1FE25B89-B3E7-4FF8-B67A-30028
6F51E5F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{221F3B81-CAD5-4EE1-82FE-65CAA
21623DF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D417134-0D48-4856-B6F5-04E63
171E24C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D4842EA-9F7B-4B6A-B157-41C62
50DA148}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3153E8D7-C724-47CC-A7FE-5C90E
B4093A0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3AEC7772-2766-4C67-8487-4189C
55DDE4E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C9654E8-E7F6-491D-A674-85CB5
3573FEE}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EF17F94-3975-4ACF-B228-29485
BDE5860}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F1078B1-41CB-4743-996B-ACD19
13A239B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F13CE9C-D753-422E-B897-BD70C
C8CEA46}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50CCECAC-7286-4CA0-9AD0-E309A
2318482}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5284E46B-63F2-4D12-9434-88B78
99EA7DD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{528F66A7-7891-4F6B-8F1E-5132C
C80650C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6046FF06-6800-4F0E-B474-4BD58
22105AA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6E389062-C540-4145-96B9-B8745
CF7D856}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70CABBFF-9D0B-4232-9F02-D1BD8
298F037}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8036105A-E89B-4D24-8319-FEA26
195A569}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8359000C-55B2-4076-A3C3-DDF39
FEB14F5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83D7FBE7-E507-4486-8785-8D177
6D498F4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{978C9E23-D4B0-11CE-BF2D-00AA0
03F40D0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EEFDA4D-0326-41B6-A3EB-CD1A6
7837443}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5B589D5-CFB6-4E9A-9455-39963
CBF74CB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D3580208-D4E1-46D4-876C-B45A3
28AF25A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D8D9EEBC-0640-47AC-84FF-97C3A
6B2FC79}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF4CE8D8-1896-431C-AE4F-1ABE8
B235ED6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F5F6647E-A36B-42BB-AD4E-A9375
3DE4DCD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00D37BEE-2D29-4F3E-9AB2-591
0EBAF7A69}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1F8F276E-2CBC-4310-8BB3-1D8
A72B647C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{22CE3FC4-4805-40CF-80E4-FEC
207A77801}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2BD91F0A-F900-477C-8401-AF0
774A3EEE4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{31E7F064-EB69-4771-8AAB-1D1
642DACA76}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{365ADE60-0AB6-4260-A5F9-5F1
54E52E385}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3B100745-A668-4D90-8EB2-A6E
2E1387BF1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4238C1CE-0D7E-4A6D-8624-D53
D2E276A05}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{46DC2A5D-4A7B-4184-B738-7ED
F4D68526B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{745BA2BA-9B0E-459E-8A9C-A47
C6A0131F1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7576F677-3945-4DA2-B9F0-378
50028A7E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7DB1286A-CBEF-4823-96AA-270
93A546741}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{801FC275-1246-4AD5-AB3D-073
71BBF5BED}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8C81B1EE-514E-4A20-BCCD-606
48432C9FE}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{90969396-649F-48A2-A082-6DE
BA7A51F50}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{AE4341EF-80A3-4D53-9735-1BC
B78C118F3}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5FA7874-ACBF-46B3-BE2E-983
81FDA9D44}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B74F7591-F64C-43DF-945A-519
DA50ABAFA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C83F84A8-241A-4837-A6BA-1C5
131141743}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F74008B3-A74D-4C9F-9D11-A9F
9CFF1DDB6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAAEEE57-F848-4E65-BFCE-A7B
75E4133FB}
HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCAFEEFRAMEWORK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCSHIELD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCTASKMANAGER
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\McAfeeFramework
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_MCAFEEFRAMEWORK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_MCSHIELD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_MCTASKMANAGER
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\McAfeeFramework
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCAFEEFRAME
WORK
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCSHIELD
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCTASKMANAG
ER
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\McAfeeFramework

rem The last line above is where I stopped with the manual additions.

@echo Unregistering McAfee Dll's...

@dir /B /S "%mcdir%\mcafee.com\*.dll" > %temp%\mcafeedll.txt
@for /F "delims=" %%i in (%temp%\mcafeedll.txt) do @regsvr32 /U "%%i" /S

@regsvr32 jscript.dll /S
@regsvr32 vbscript.dll /S

@echo Removing Desktop Shortcuts...

@echo Removing Startup Entries...

@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
ShStatEXE /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
Network Associates Error Reporting Service /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
McAfeeUpdaterUI /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MCAgentExe /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MCUpdateExe /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MPFExe /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MPSExe /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MSKAGENTEXE /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MSKDetectorExe /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
OASClnt /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
"VirusScan Online" /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
VSOCheckTask /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
McLogLch_exe /f
@reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v
MskAgent /f

@echo Removing McAfee Services...

@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McTaskManager" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McShield" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McAfeeFramework" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\MPFIREWL" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\MpfService" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\MskService" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McDetect.exe" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McShield" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McTskshd.exe" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mcupdmgr.exe" /f

@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McAfee HackerWatch
Service" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McLogManagerService"
/f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mcmispupdmgr" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McNASvc" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McODS" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mcpromgr" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McProxy" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McRedirector" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\McSysmon" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mcusrmgr" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mfeavfk" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mfebopk" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mfehidk" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mferkdk" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\mfesmfk" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\Emproxy" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\MPS9" /f
@reg delete "HKLM\SYSTEM\CurrentControlSet\Services\MSK80Service" /f

@echo Removing Other Registry Keys...

@reg delete "HKLM\SOFTWARE\Microsoft\Exchange\Client\Extensions" /v
"McAfee SpamKiller" /f
@reg delete "HKLM\SOFTWARE\Microsoft\Exchange\Client\Extensions" /v
"McAfee SpamKiller Exchange Extension" /f
@reg delete "HKLM\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{39FD89BF-D3F1-45b6-BB56-3582CCF489E1}" /f
@reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Toolbar" /v "{0BF43445-2F28-4351-9252-17FE6E806AA0}" /f
@reg delete
"HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\McOlAddin.Connect" /f
@reg delete
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser
Helper Objects\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53}" /f
@reg delete
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSC" /f
@reg delete "HKU\.DEFAULT\Software\McAfee" /f

@echo Preparing Final Steps...

@echo rd /S/Q "%mcdir%\mcafee" > %temp%\mcrem.cmd
@echo rd /S/Q "%mcdir%\mcafee.com" >> %temp%\mcrem.cmd
@echo rd /S/Q "%allusersprofile%\Application Data\mcafee" >>
%temp%\mcrem.cmd
@echo rd /S/Q "%allusersprofile%\Application Data\mcafee.com" >>
%temp%\mcrem.cmd
@echo rd /S/Q "%allusersprofile%\Application Data\McAfee.com Personal
Firewall" >> %temp%\mcrem.cmd
@echo reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
/v mcrem /f >> %temp%\mcrem.cmd

@reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v mcrem
/t REG_SZ /d %temp%\mcrem.cmd /f

rmdir /S /Q "%allusersprofile%\Start Menu\Programs\Network Associates"
rmdir /S /Q "C:\Program Files\Network Associates"
rmdir /S /Q "C:\Program Files\Common Files\Network Associates"

@cls
@echo ALL STEPS WERE COMPLETED!
@echo YOU NEED TO RESTART THE COMPUTER TO COMPLETE THE REMOVAL PROCESS!
@echo IF AFTER THE COMPUTER RESTARTS YOU ARE GETTING MCAFEE ERRORS RUN
@echo THIS PROGRAM ONE MORE TIME!

@shutdown -r -t 00 -f
----------End Batch File----------

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~


This message contains confidential information and is intended only for the 
intended recipient(s). If you are not the named recipient you should not read, 
distribute or copy this e-mail. Please notify the sender immediately via e-mail 
if you have received this e-mail by mistake; then, delete this e-mail from your 
system.

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~


~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to